mirror of
https://github.com/BobTheBlinker/android_kernel_motorola_sm6375.git
synced 2026-10-07 04:12:04 -04:00
msm: camera: common: Add conditions to catch invalid packet data
Add conditions to catch invalid cmd_desc, io buffers, and kmd buffers in the packet payload. CRs-Fixed: 3250331 Change-Id: I2db474572a8c5391ba9b9821de2da0db8f10eb4d Signed-off-by: Ashish Bhimanpalliwar <quic_abhiman@quicinc.com>
This commit is contained in:
parent
a2b2dfab21
commit
5685ecf200
7 changed files with 46 additions and 11 deletions
|
|
@ -1,6 +1,7 @@
|
|||
// SPDX-License-Identifier: GPL-2.0-only
|
||||
/*
|
||||
* Copyright (c) 2017-2020, The Linux Foundation. All rights reserved.
|
||||
* Copyright (c) 2022 Qualcomm Innovation Center, Inc. All rights reserved.
|
||||
*/
|
||||
|
||||
#include <linux/module.h>
|
||||
|
|
@ -54,7 +55,7 @@ static int cam_fd_mgr_util_packet_validate(struct cam_packet *packet,
|
|||
}
|
||||
|
||||
/* All buffers must come through io config, do not support patching */
|
||||
if (packet->num_patches || !packet->num_io_configs) {
|
||||
if (packet->num_patches || !packet->num_io_configs || !packet->num_cmd_buf) {
|
||||
CAM_ERR(CAM_FD, "wrong number of cmd/patch info: %u %u",
|
||||
packet->num_cmd_buf, packet->num_patches);
|
||||
return -EINVAL;
|
||||
|
|
|
|||
|
|
@ -4189,13 +4189,13 @@ static int cam_icp_mgr_pkt_validation(struct cam_packet *packet)
|
|||
return -EINVAL;
|
||||
}
|
||||
|
||||
if (packet->num_io_configs > IPE_IO_IMAGES_MAX) {
|
||||
if (!packet->num_io_configs || packet->num_io_configs > IPE_IO_IMAGES_MAX) {
|
||||
CAM_ERR(CAM_ICP, "Invalid number of io configs: %d %d",
|
||||
IPE_IO_IMAGES_MAX, packet->num_io_configs);
|
||||
return -EINVAL;
|
||||
}
|
||||
|
||||
if (packet->num_cmd_buf > CAM_ICP_CTX_MAX_CMD_BUFFERS) {
|
||||
if (!packet->num_cmd_buf || packet->num_cmd_buf > CAM_ICP_CTX_MAX_CMD_BUFFERS) {
|
||||
CAM_ERR(CAM_ICP, "Invalid number of cmd buffers: %d %d",
|
||||
CAM_ICP_CTX_MAX_CMD_BUFFERS, packet->num_cmd_buf);
|
||||
return -EINVAL;
|
||||
|
|
|
|||
|
|
@ -1,7 +1,7 @@
|
|||
// SPDX-License-Identifier: GPL-2.0-only
|
||||
/*
|
||||
* Copyright (c) 2022 Qualcomm Innovation Center, Inc. All rights reserved.
|
||||
* Copyright (c) 2017-2021, The Linux Foundation. All rights reserved.
|
||||
* Copyright (c) 2022 Qualcomm Innovation Center, Inc. All rights reserved.
|
||||
*/
|
||||
|
||||
#include <linux/uaccess.h>
|
||||
|
|
@ -769,8 +769,9 @@ static int cam_jpeg_mgr_prepare_hw_update(void *hw_mgr_priv,
|
|||
return rc;
|
||||
}
|
||||
|
||||
if ((packet->num_cmd_buf > 5) || !packet->num_patches ||
|
||||
!packet->num_io_configs ||
|
||||
if (!packet->num_cmd_buf ||
|
||||
(packet->num_cmd_buf > 5) ||
|
||||
!packet->num_patches || !packet->num_io_configs ||
|
||||
(packet->num_io_configs > CAM_JPEG_IMAGE_MAX)) {
|
||||
CAM_ERR(CAM_JPEG,
|
||||
"wrong number of cmd/patch/io_configs info: %u %u %u",
|
||||
|
|
|
|||
|
|
@ -1,6 +1,7 @@
|
|||
// SPDX-License-Identifier: GPL-2.0-only
|
||||
/*
|
||||
* Copyright (c) 2017-2020, The Linux Foundation. All rights reserved.
|
||||
* Copyright (c) 2022 Qualcomm Innovation Center, Inc. All rights reserved.
|
||||
*/
|
||||
|
||||
#include <linux/module.h>
|
||||
|
|
@ -113,6 +114,11 @@ static int cam_lrme_mgr_util_packet_validate(struct cam_packet *packet,
|
|||
return -EINVAL;
|
||||
}
|
||||
|
||||
if (!packet->num_cmd_buf) {
|
||||
CAM_ERR(CAM_LRME, "no cmd bufs");
|
||||
return -EINVAL;
|
||||
}
|
||||
|
||||
cmd_desc = (struct cam_cmd_buf_desc *)((uint8_t *)&packet->payload +
|
||||
packet->cmd_buf_offset);
|
||||
|
||||
|
|
|
|||
|
|
@ -2379,13 +2379,15 @@ static int cam_ope_mgr_pkt_validation(struct cam_packet *packet)
|
|||
return -EINVAL;
|
||||
}
|
||||
|
||||
if (packet->num_io_configs > OPE_MAX_IO_BUFS) {
|
||||
if (!packet->num_io_configs ||
|
||||
packet->num_io_configs > OPE_MAX_IO_BUFS) {
|
||||
CAM_ERR(CAM_OPE, "Invalid number of io configs: %d %d",
|
||||
OPE_MAX_IO_BUFS, packet->num_io_configs);
|
||||
return -EINVAL;
|
||||
}
|
||||
|
||||
if (packet->num_cmd_buf > OPE_PACKET_MAX_CMD_BUFS) {
|
||||
if (!packet->num_cmd_buf ||
|
||||
packet->num_cmd_buf > OPE_PACKET_MAX_CMD_BUFS) {
|
||||
CAM_ERR(CAM_OPE, "Invalid number of cmd buffers: %d %d",
|
||||
OPE_PACKET_MAX_CMD_BUFS, packet->num_cmd_buf);
|
||||
return -EINVAL;
|
||||
|
|
|
|||
|
|
@ -393,9 +393,21 @@ int32_t cam_cmd_buf_parser(struct csiphy_device *csiphy_dev,
|
|||
return rc;
|
||||
}
|
||||
|
||||
cmd_desc = (struct cam_cmd_buf_desc *)
|
||||
((uint32_t *)&csl_packet->payload +
|
||||
csl_packet->cmd_buf_offset / 4);
|
||||
if (csl_packet->num_cmd_buf)
|
||||
cmd_desc = (struct cam_cmd_buf_desc *)
|
||||
((uint32_t *)&csl_packet->payload +
|
||||
csl_packet->cmd_buf_offset / 4);
|
||||
else {
|
||||
CAM_ERR(CAM_CSIPHY, "num_cmd_buffers = %d", csl_packet->num_cmd_buf);
|
||||
rc = -EINVAL;
|
||||
return rc;
|
||||
}
|
||||
|
||||
rc = cam_packet_util_validate_cmd_desc(cmd_desc);
|
||||
if (rc) {
|
||||
CAM_ERR(CAM_CSIPHY, "Invalid cmd desc ret: %d", rc);
|
||||
return rc;
|
||||
}
|
||||
|
||||
rc = cam_mem_get_cpu_buf(cmd_desc->mem_handle,
|
||||
&generic_ptr, &len);
|
||||
|
|
|
|||
|
|
@ -1,6 +1,7 @@
|
|||
// SPDX-License-Identifier: GPL-2.0-only
|
||||
/*
|
||||
* Copyright (c) 2017-2020, The Linux Foundation. All rights reserved.
|
||||
* Copyright (c) 2022 Qualcomm Innovation Center, Inc. All rights reserved.
|
||||
*/
|
||||
|
||||
#include <linux/types.h>
|
||||
|
|
@ -40,6 +41,12 @@ int cam_packet_util_get_cmd_mem_addr(int handle, uint32_t **buf_addr,
|
|||
|
||||
int cam_packet_util_validate_cmd_desc(struct cam_cmd_buf_desc *cmd_desc)
|
||||
{
|
||||
|
||||
if (!cmd_desc) {
|
||||
CAM_ERR(CAM_UTIL, "Invalid cmd desc");
|
||||
return -EINVAL;
|
||||
}
|
||||
|
||||
if ((cmd_desc->length > cmd_desc->size) ||
|
||||
(cmd_desc->mem_handle <= 0)) {
|
||||
CAM_ERR(CAM_UTIL, "invalid cmd arg %d %d %d %d",
|
||||
|
|
@ -80,6 +87,7 @@ int cam_packet_util_validate_packet(struct cam_packet *packet,
|
|||
pkt_wo_payload = offsetof(struct cam_packet, payload);
|
||||
|
||||
if ((!packet->header.size) ||
|
||||
((size_t)packet->header.size <= pkt_wo_payload) ||
|
||||
((pkt_wo_payload + (size_t)packet->cmd_buf_offset +
|
||||
sum_cmd_desc) > (size_t)packet->header.size) ||
|
||||
((pkt_wo_payload + (size_t)packet->io_configs_offset +
|
||||
|
|
@ -109,6 +117,11 @@ int cam_packet_util_get_kmd_buffer(struct cam_packet *packet,
|
|||
return -EINVAL;
|
||||
}
|
||||
|
||||
if (!packet->num_cmd_buf) {
|
||||
CAM_ERR(CAM_UTIL, "Invalid num_cmd_buf = %d", packet->num_cmd_buf);
|
||||
return -EINVAL;
|
||||
}
|
||||
|
||||
if ((packet->kmd_cmd_buf_index < 0) ||
|
||||
(packet->kmd_cmd_buf_index >= packet->num_cmd_buf)) {
|
||||
CAM_ERR(CAM_UTIL, "Invalid kmd buf index: %d",
|
||||
|
|
|
|||
Loading…
Reference in a new issue