msm: camera: common: Add conditions to catch invalid packet data

Add conditions to catch invalid cmd_desc, io buffers, and kmd buffers in
the packet payload.

CRs-Fixed: 3250331
Change-Id: I2db474572a8c5391ba9b9821de2da0db8f10eb4d
Signed-off-by: Ashish Bhimanpalliwar <quic_abhiman@quicinc.com>
This commit is contained in:
Ashish Bhimanpalliwar 2022-08-03 11:04:07 +05:30 • committed by Gerrit - the friendly Code Review server
commit 5685ecf200
7 changed files with 46 additions and 11 deletions

View file

@ -1,6 +1,7 @@
// SPDX-License-Identifier: GPL-2.0-only
/*
* Copyright (c) 2017-2020, The Linux Foundation. All rights reserved.
* Copyright (c) 2022 Qualcomm Innovation Center, Inc. All rights reserved.
*/
#include <linux/module.h>
@ -54,7 +55,7 @@ static int cam_fd_mgr_util_packet_validate(struct cam_packet *packet,
}
/* All buffers must come through io config, do not support patching */
if (packet->num_patches || !packet->num_io_configs) {
if (packet->num_patches || !packet->num_io_configs || !packet->num_cmd_buf) {
CAM_ERR(CAM_FD, "wrong number of cmd/patch info: %u %u",
packet->num_cmd_buf, packet->num_patches);
return -EINVAL;

View file

@ -4189,13 +4189,13 @@ static int cam_icp_mgr_pkt_validation(struct cam_packet *packet)
return -EINVAL;
}
if (packet->num_io_configs > IPE_IO_IMAGES_MAX) {
if (!packet->num_io_configs || packet->num_io_configs > IPE_IO_IMAGES_MAX) {
CAM_ERR(CAM_ICP, "Invalid number of io configs: %d %d",
IPE_IO_IMAGES_MAX, packet->num_io_configs);
return -EINVAL;
}
if (packet->num_cmd_buf > CAM_ICP_CTX_MAX_CMD_BUFFERS) {
if (!packet->num_cmd_buf || packet->num_cmd_buf > CAM_ICP_CTX_MAX_CMD_BUFFERS) {
CAM_ERR(CAM_ICP, "Invalid number of cmd buffers: %d %d",
CAM_ICP_CTX_MAX_CMD_BUFFERS, packet->num_cmd_buf);
return -EINVAL;

View file

@ -1,7 +1,7 @@
// SPDX-License-Identifier: GPL-2.0-only
/*
* Copyright (c) 2022 Qualcomm Innovation Center, Inc. All rights reserved.
* Copyright (c) 2017-2021, The Linux Foundation. All rights reserved.
* Copyright (c) 2022 Qualcomm Innovation Center, Inc. All rights reserved.
*/
#include <linux/uaccess.h>
@ -769,8 +769,9 @@ static int cam_jpeg_mgr_prepare_hw_update(void *hw_mgr_priv,
return rc;
}
if ((packet->num_cmd_buf > 5) || !packet->num_patches ||
!packet->num_io_configs ||
if (!packet->num_cmd_buf ||
(packet->num_cmd_buf > 5) ||
!packet->num_patches || !packet->num_io_configs ||
(packet->num_io_configs > CAM_JPEG_IMAGE_MAX)) {
CAM_ERR(CAM_JPEG,
"wrong number of cmd/patch/io_configs info: %u %u %u",

View file

@ -1,6 +1,7 @@
// SPDX-License-Identifier: GPL-2.0-only
/*
* Copyright (c) 2017-2020, The Linux Foundation. All rights reserved.
* Copyright (c) 2022 Qualcomm Innovation Center, Inc. All rights reserved.
*/
#include <linux/module.h>
@ -113,6 +114,11 @@ static int cam_lrme_mgr_util_packet_validate(struct cam_packet *packet,
return -EINVAL;
}
if (!packet->num_cmd_buf) {
CAM_ERR(CAM_LRME, "no cmd bufs");
return -EINVAL;
}
cmd_desc = (struct cam_cmd_buf_desc *)((uint8_t *)&packet->payload +
packet->cmd_buf_offset);

View file

@ -2379,13 +2379,15 @@ static int cam_ope_mgr_pkt_validation(struct cam_packet *packet)
return -EINVAL;
}
if (packet->num_io_configs > OPE_MAX_IO_BUFS) {
if (!packet->num_io_configs ||
packet->num_io_configs > OPE_MAX_IO_BUFS) {
CAM_ERR(CAM_OPE, "Invalid number of io configs: %d %d",
OPE_MAX_IO_BUFS, packet->num_io_configs);
return -EINVAL;
}
if (packet->num_cmd_buf > OPE_PACKET_MAX_CMD_BUFS) {
if (!packet->num_cmd_buf ||
packet->num_cmd_buf > OPE_PACKET_MAX_CMD_BUFS) {
CAM_ERR(CAM_OPE, "Invalid number of cmd buffers: %d %d",
OPE_PACKET_MAX_CMD_BUFS, packet->num_cmd_buf);
return -EINVAL;

View file

@ -393,9 +393,21 @@ int32_t cam_cmd_buf_parser(struct csiphy_device *csiphy_dev,
return rc;
}
cmd_desc = (struct cam_cmd_buf_desc *)
((uint32_t *)&csl_packet->payload +
csl_packet->cmd_buf_offset / 4);
if (csl_packet->num_cmd_buf)
cmd_desc = (struct cam_cmd_buf_desc *)
((uint32_t *)&csl_packet->payload +
csl_packet->cmd_buf_offset / 4);
else {
CAM_ERR(CAM_CSIPHY, "num_cmd_buffers = %d", csl_packet->num_cmd_buf);
rc = -EINVAL;
return rc;
}
rc = cam_packet_util_validate_cmd_desc(cmd_desc);
if (rc) {
CAM_ERR(CAM_CSIPHY, "Invalid cmd desc ret: %d", rc);
return rc;
}
rc = cam_mem_get_cpu_buf(cmd_desc->mem_handle,
&generic_ptr, &len);

View file

@ -1,6 +1,7 @@
// SPDX-License-Identifier: GPL-2.0-only
/*
* Copyright (c) 2017-2020, The Linux Foundation. All rights reserved.
* Copyright (c) 2022 Qualcomm Innovation Center, Inc. All rights reserved.
*/
#include <linux/types.h>
@ -40,6 +41,12 @@ int cam_packet_util_get_cmd_mem_addr(int handle, uint32_t **buf_addr,
int cam_packet_util_validate_cmd_desc(struct cam_cmd_buf_desc *cmd_desc)
{
if (!cmd_desc) {
CAM_ERR(CAM_UTIL, "Invalid cmd desc");
return -EINVAL;
}
if ((cmd_desc->length > cmd_desc->size) ||
(cmd_desc->mem_handle <= 0)) {
CAM_ERR(CAM_UTIL, "invalid cmd arg %d %d %d %d",
@ -80,6 +87,7 @@ int cam_packet_util_validate_packet(struct cam_packet *packet,
pkt_wo_payload = offsetof(struct cam_packet, payload);
if ((!packet->header.size) ||
((size_t)packet->header.size <= pkt_wo_payload) ||
((pkt_wo_payload + (size_t)packet->cmd_buf_offset +
sum_cmd_desc) > (size_t)packet->header.size) ||
((pkt_wo_payload + (size_t)packet->io_configs_offset +
@ -109,6 +117,11 @@ int cam_packet_util_get_kmd_buffer(struct cam_packet *packet,
return -EINVAL;
}
if (!packet->num_cmd_buf) {
CAM_ERR(CAM_UTIL, "Invalid num_cmd_buf = %d", packet->num_cmd_buf);
return -EINVAL;
}
if ((packet->kmd_cmd_buf_index < 0) ||
(packet->kmd_cmd_buf_index >= packet->num_cmd_buf)) {
CAM_ERR(CAM_UTIL, "Invalid kmd buf index: %d",