mirror of
https://github.com/BobTheBlinker/android_kernel_motorola_sm6375.git
synced 2026-10-07 12:25:00 -04:00
msm: adsprpc: Fix array index underflow problem
Add check to restrict index underflow.This is to avoid that it does not access invalid index. Change-Id: Ib971033c5820ca4dab38ace3b106c7b1b42529e4 Acked-by: Gururaj Chalger <gchalger@qti.qualcomm.com> Signed-off-by: Mohammed Nayeem Ur Rahman <mohara@codeaurora.org>
This commit is contained in:
parent
bbc7f2d3ed
commit
5c50e1787c
1 changed files with 25 additions and 5 deletions
|
|
@ -954,12 +954,23 @@ static void fastrpc_mmap_free(struct fastrpc_mmap *map, uint32_t flags)
|
|||
{
|
||||
struct fastrpc_apps *me = &gfa;
|
||||
struct fastrpc_file *fl;
|
||||
int vmid;
|
||||
int vmid, cid = -1, err = 0;
|
||||
struct fastrpc_session_ctx *sess;
|
||||
|
||||
if (!map)
|
||||
return;
|
||||
fl = map->fl;
|
||||
if (fl && !(map->flags == ADSP_MMAP_HEAP_ADDR ||
|
||||
map->flags == ADSP_MMAP_REMOTE_HEAP_ADDR)) {
|
||||
cid = fl->cid;
|
||||
VERIFY(err, cid >= ADSP_DOMAIN_ID && cid < NUM_CHANNELS);
|
||||
if (err) {
|
||||
err = -ECHRNG;
|
||||
pr_err("adsprpc: ERROR:%s, Invalid channel id: %d, err:%d\n",
|
||||
__func__, cid, err);
|
||||
return;
|
||||
}
|
||||
}
|
||||
if (map->flags == ADSP_MMAP_HEAP_ADDR ||
|
||||
map->flags == ADSP_MMAP_REMOTE_HEAP_ADDR) {
|
||||
map->refs--;
|
||||
|
|
@ -2467,9 +2478,17 @@ static int fastrpc_invoke_send(struct smq_invoke_ctx *ctx,
|
|||
{
|
||||
struct smq_msg *msg = &ctx->msg;
|
||||
struct fastrpc_file *fl = ctx->fl;
|
||||
struct fastrpc_channel_ctx *channel_ctx = &fl->apps->channel[fl->cid];
|
||||
int err = 0;
|
||||
struct fastrpc_channel_ctx *channel_ctx = NULL;
|
||||
int err = 0, cid = -1;
|
||||
|
||||
cid = fl->cid;
|
||||
VERIFY(err, cid >= ADSP_DOMAIN_ID && cid < NUM_CHANNELS);
|
||||
if (err) {
|
||||
err = -ECHRNG;
|
||||
goto bail;
|
||||
}
|
||||
|
||||
channel_ctx = &fl->apps->channel[fl->cid];
|
||||
mutex_lock(&channel_ctx->smd_mutex);
|
||||
msg->pid = fl->tgid;
|
||||
msg->tid = current->pid;
|
||||
|
|
@ -2689,11 +2708,12 @@ static int fastrpc_internal_invoke(struct fastrpc_file *fl, uint32_t mode,
|
|||
{
|
||||
struct smq_invoke_ctx *ctx = NULL;
|
||||
struct fastrpc_ioctl_invoke *invoke = &inv->inv;
|
||||
int err = 0, interrupted = 0, cid = fl->cid;
|
||||
int err = 0, interrupted = 0, cid = -1;
|
||||
struct timespec64 invoket = {0};
|
||||
int64_t *perf_counter = NULL;
|
||||
bool isasyncinvoke = false;
|
||||
|
||||
cid = fl->cid;
|
||||
VERIFY(err, cid >= ADSP_DOMAIN_ID && cid < NUM_CHANNELS &&
|
||||
fl->sctx != NULL);
|
||||
if (err) {
|
||||
|
|
@ -4928,7 +4948,7 @@ static const struct file_operations debugfs_fops = {
|
|||
static int fastrpc_channel_open(struct fastrpc_file *fl)
|
||||
{
|
||||
struct fastrpc_apps *me = &gfa;
|
||||
int cid, err = 0;
|
||||
int cid = -1, err = 0;
|
||||
|
||||
VERIFY(err, fl && fl->sctx && fl->cid >= 0 && fl->cid < NUM_CHANNELS);
|
||||
if (err) {
|
||||
|
|
|
|||
Loading…
Reference in a new issue