mirror of
https://github.com/BobTheBlinker/android_kernel_motorola_sm6375.git
synced 2026-10-07 20:33:58 -04:00
msm: cvp: avoid OOB write while accessing memory
Exclude 4 bytes which holds the size of the buffer while calculating the actual buffer size to avoid OOB write. Change-Id: I79704181e0bafc905064621d7cd6e682cca15982 Signed-off-by: suchawla <suchawla@codeaurora.org> Signed-off-by: Govindaraj Rajagopal <grajagop@codeaurora.org>
This commit is contained in:
parent
f3ed56f0e1
commit
4267dcfae7
1 changed files with 13 additions and 11 deletions
|
|
@ -2673,20 +2673,26 @@ skip_power_off:
|
|||
return -EAGAIN;
|
||||
}
|
||||
|
||||
static void __process_sys_error(struct iris_hfi_device *device)
|
||||
static void print_sfr_message(struct iris_hfi_device *device)
|
||||
{
|
||||
struct cvp_hfi_sfr_struct *vsfr = NULL;
|
||||
u32 vsfr_size = 0;
|
||||
void *p = NULL;
|
||||
|
||||
vsfr = (struct cvp_hfi_sfr_struct *)device->sfr.align_virtual_addr;
|
||||
if (vsfr) {
|
||||
void *p = memchr(vsfr->rg_data, '\0', vsfr->bufSize);
|
||||
if (vsfr->bufSize != device->sfr.mem_size) {
|
||||
dprintk(CVP_ERR, "Invalid SFR buf size %d actual %d\n",
|
||||
vsfr->bufSize, device->sfr.mem_size);
|
||||
return;
|
||||
}
|
||||
vsfr_size = vsfr->bufSize - sizeof(u32);
|
||||
p = memchr(vsfr->rg_data, '\0', vsfr_size);
|
||||
/*
|
||||
* SFR isn't guaranteed to be NULL terminated
|
||||
* since SYS_ERROR indicates that Iris is in the
|
||||
* process of crashing.
|
||||
*/
|
||||
if (p == NULL)
|
||||
vsfr->rg_data[vsfr->bufSize - 1] = '\0';
|
||||
vsfr->rg_data[vsfr_size - 1] = '\0';
|
||||
|
||||
dprintk(CVP_ERR, "SFR Message from FW: %s\n",
|
||||
vsfr->rg_data);
|
||||
|
|
@ -2810,7 +2816,7 @@ static void process_system_msg(struct msm_cvp_cb_info *info,
|
|||
|
||||
switch (info->response_type) {
|
||||
case HAL_SYS_ERROR:
|
||||
__process_sys_error(device);
|
||||
print_sfr_message(device);
|
||||
break;
|
||||
case HAL_SYS_RELEASE_RESOURCE_DONE:
|
||||
dprintk(CVP_DBG, "Received SYS_RELEASE_RESOURCE\n");
|
||||
|
|
@ -2919,8 +2925,6 @@ static int __response_handler(struct iris_hfi_device *device)
|
|||
}
|
||||
|
||||
if (device->intr_status & CVP_FATAL_INTR_BMSK) {
|
||||
struct cvp_hfi_sfr_struct *vsfr = (struct cvp_hfi_sfr_struct *)
|
||||
device->sfr.align_virtual_addr;
|
||||
struct msm_cvp_cb_info info = {
|
||||
.response_type = HAL_SYS_WATCHDOG_TIMEOUT,
|
||||
.response.cmd = {
|
||||
|
|
@ -2928,9 +2932,7 @@ static int __response_handler(struct iris_hfi_device *device)
|
|||
}
|
||||
};
|
||||
|
||||
if (vsfr)
|
||||
dprintk(CVP_ERR, "SFR Message from FW: %s\n",
|
||||
vsfr->rg_data);
|
||||
print_sfr_message(device);
|
||||
if (device->intr_status & CVP_WRAPPER_INTR_MASK_CPU_NOC_BMSK)
|
||||
dprintk(CVP_ERR, "Received Xtensa NOC error\n");
|
||||
|
||||
|
|
|
|||
Loading…
Reference in a new issue