From 250ab26be0ae815efe9cf04606d29bfef927b6b8 Mon Sep 17 00:00:00 2001 From: Pranav Sanwal Date: Mon, 30 Sep 2024 16:04:04 +0530 Subject: [PATCH] msm: camera: isp: Copy the userdata in kernel to avoid TOCTOU condition Userspace is still able to access blob data after submitting to kmd and can alter it's contents. This change copy the information in kernel space and then perform relevant checks and actions if the data is unaltered. CRs-Fixed: 3923843 Change-Id: I9ec3c95a3e04770ab0b00bc07c8a0d133f779ed1 Signed-off-by: Pranav Sanwal --- drivers/cam_isp/isp_hw_mgr/cam_ife_hw_mgr.c | 48 +++++++++++++++++---- 1 file changed, 40 insertions(+), 8 deletions(-) diff --git a/drivers/cam_isp/isp_hw_mgr/cam_ife_hw_mgr.c b/drivers/cam_isp/isp_hw_mgr/cam_ife_hw_mgr.c index c875fc67e0d7..829950936690 100644 --- a/drivers/cam_isp/isp_hw_mgr/cam_ife_hw_mgr.c +++ b/drivers/cam_isp/isp_hw_mgr/cam_ife_hw_mgr.c @@ -5993,7 +5993,9 @@ static int cam_isp_packet_generic_blob_handler(void *user_data, break; case CAM_ISP_GENERIC_BLOB_TYPE_BW_CONFIG: { struct cam_isp_bw_config *bw_config; + struct cam_isp_bw_config *bw_config_u; struct cam_isp_prepare_hw_update_data *prepare_hw_data; + size_t bw_config_size; CAM_WARN_RATE_LIMIT_CUSTOM(CAM_PERF, 300, 1, "Deprecated Blob TYPE_BW_CONFIG"); @@ -6002,10 +6004,24 @@ static int cam_isp_packet_generic_blob_handler(void *user_data, return -EINVAL; } - bw_config = (struct cam_isp_bw_config *)blob_data; + bw_config_u = (struct cam_isp_bw_config *)blob_data; - if (bw_config->num_rdi > CAM_IFE_RDI_NUM_MAX) { - CAM_ERR(CAM_ISP, "Invalid num_rdi %u in bw config", + if (bw_config_u->num_rdi > CAM_IFE_RDI_NUM_MAX || !bw_config_u->num_rdi) { + CAM_ERR(CAM_ISP, "Invalid num_rdi %u in bw config, ctx_idx: %u", + bw_config_u->num_rdi, ife_mgr_ctx->ctx_index); + return -EINVAL; + } + + bw_config_size = sizeof(struct cam_isp_bw_config) + ((bw_config_u->num_rdi-1)* + sizeof(struct cam_isp_bw_vote)); + + rc = cam_common_mem_kdup((void **)&bw_config, bw_config_u, bw_config_size); + if (rc) { + CAM_ERR(CAM_ISP, "Alloc and copy request bw_config failed"); + return rc; + } + if (bw_config_u->num_rdi != bw_config->num_rdi) { + CAM_ERR(CAM_ISP, "num_rdi changed,userspace:%d, kernel:%d", bw_config_u->num_rdi, bw_config->num_rdi); return -EINVAL; } @@ -6053,6 +6069,7 @@ static int cam_isp_packet_generic_blob_handler(void *user_data, case CAM_ISP_GENERIC_BLOB_TYPE_BW_CONFIG_V2: { size_t bw_config_size = 0; struct cam_isp_bw_config_v2 *bw_config; + struct cam_isp_bw_config_v2 *bw_config_u; struct cam_isp_prepare_hw_update_data *prepare_hw_data; if (blob_size < sizeof(struct cam_isp_bw_config_v2)) { @@ -6060,12 +6077,27 @@ static int cam_isp_packet_generic_blob_handler(void *user_data, return -EINVAL; } - bw_config = (struct cam_isp_bw_config_v2 *)blob_data; + bw_config_u = (struct cam_isp_bw_config_v2 *)blob_data; - if (bw_config->num_paths > CAM_ISP_MAX_PER_PATH_VOTES || - !bw_config->num_paths) { - CAM_ERR(CAM_ISP, "Invalid num paths %d", - bw_config->num_paths); + if (bw_config_u->num_paths > CAM_ISP_MAX_PER_PATH_VOTES || + !bw_config_u->num_paths) { + CAM_ERR(CAM_ISP, "Invalid num paths %d ctx_idx: %u", + bw_config_u->num_paths, ife_mgr_ctx->ctx_index); + return -EINVAL; + } + + bw_config_size = sizeof(struct cam_isp_bw_config_v2) + ((bw_config_u->num_paths-1)* + sizeof(struct cam_axi_per_path_bw_vote)); + + rc = cam_common_mem_kdup((void **)&bw_config, bw_config_u, bw_config_size); + if (rc) { + CAM_ERR(CAM_ISP, "Alloc and copy request bw_config failed"); + return rc; + } + + if (bw_config_u->num_paths != bw_config->num_paths) { + CAM_ERR(CAM_ISP, "num_paths changed,userspace:%d, kernel:%d", bw_config_u->num_paths, + bw_config->num_paths); return -EINVAL; }