On Fri, Sep 04, 2026 at 03:32:08AM +0000, Peng Fan (OSS) wrote:
> > Subject: [PATCH v2] remoteproc: imx_rproc: allow mappings ending at
> > region boundary
> >
> > From: Marcel Hofmann <[email protected]>
> >
> > The address range checks in imx_rproc_da_to_sys() and
> > imx_rproc_da_to_va() use a strict comparison for the exclusive end
> > address of the requested range.
> >
> > As a result, a valid request that ends exactly at the end of an address
> > translation or mapped memory region is rejected. For a region [start,
> > start + size), a request [addr, addr + len) is contained when:
> >
> >     addr >= start && addr + len <= start + size
> >
> > This occurs when a loadable ELF segment fills an entire mapped
> > memory region. This can be produced by a linker script that extends
> > the resource table section to the end of its designated region:
> >
> >     .resource_table :
> >     {
> >       . = ALIGN(8);
> >       KEEP(*(.resource_table)) /* Resource table */
> >       . = ALIGN(8);
> >       . = ORIGIN(m_rsc_tbl) + LENGTH(m_rsc_tbl);
> >     } > m_rsc_tbl =0x00
> >
> > This produces a ELF program header like:
> >
> >     LOAD  0x010000 0xa4220000 0xa4220000 0x01000 0x01000 R
> > 0x1000
> >
> > In this case, the segment size matches the mapped region size exactly,
> > causing the address translation to fail with:
> >
> >     bad phdr da 0xa4220000 mem 0x1000
> >
> > Rework the upper-bound checks to allow ranges ending exactly at the
> > region boundary while guarding against integer overflow.
> >
> > Fixes: a0ff4aa6f010 ("remoteproc: imx_rproc: add a NXP/Freescale
> > imx_rproc driver")
> > Signed-off-by: Marcel Hofmann <marcel.hofmann@ingenics-
> > digital.com>
> 
> Tested-by: Peng Fan <[email protected]>  #i.MX95-19x19-EVK
>

Applied.
 
> Thanks,
> Peng.
> 

Reply via email to