Merge "msm: cvp:fix potential prop_array idx out range"

This commit is contained in:
qctecmdr 2020-07-02 22:46:57 -07:00 • committed by Gerrit - the friendly Code Review server
commit 92fd4ddff3
2 changed files with 8 additions and 4 deletions

View file

@ -111,9 +111,12 @@ static int cvp_wait_process_message(struct msm_cvp_inst *inst,
goto exit;
}
if (out)
memcpy(out, &msg->pkt, sizeof(struct cvp_hfi_msg_session_hdr));
if (!out) {
kmem_cache_free(cvp_driver->msg_cache, msg);
goto exit;
}
memcpy(out, &msg->pkt, sizeof(struct cvp_hfi_msg_session_hdr));
kmem_cache_free(cvp_driver->msg_cache, msg);
hdr = (struct cvp_hfi_msg_session_hdr *)out;
msm_cvp_unmap_frame(inst, hdr->client_data.kdata);
@ -1122,7 +1125,7 @@ static int msm_cvp_set_sysprop(struct msm_cvp_inst *inst,
return -EINVAL;
}
if (props->prop_num >= MAX_KMD_PROP_NUM) {
if (props->prop_num >= MAX_KMD_PROP_NUM_PER_PACKET) {
dprintk(CVP_ERR, "Too many properties %d to set\n",
props->prop_num);
return -E2BIG;

View file

@ -149,7 +149,8 @@ struct cvp_kmd_hfi_packet {
#define CVP_KMD_PROP_PWR_DDR_OP 0x1C
#define CVP_KMD_PROP_PWR_SYSCACHE_OP 0x1D
#define MAX_KMD_PROP_NUM (CVP_KMD_PROP_PWR_SYSCACHE_OP + 1)
#define MAX_KMD_PROP_NUM_PER_PACKET 8
#define MAX_KMD_PROP_TYPE (CVP_KMD_PROP_PWR_SYSCACHE_OP + 1)
struct cvp_kmd_sys_property {
__u32 prop_type;