Donate to e Foundation | Murena handsets with /e/OS | Own a part of Murena! Learn more

Commit b614a9db authored by Vikash Garodia's avatar Vikash Garodia
Browse files

BACKPORT: media: venus: hfi: add checks in capabilities from firmware



The hfi parser, parses the capabilities received from venus firmware and
copies them to core capabilities. Consider below api, for example,
fill_caps - In this api, caps in core structure gets updated with the
number of capabilities received in firmware data payload. If the same api
is called multiple times, there is a possibility of copying beyond the max
allocated size in core caps.
Similar possibilities in fill_raw_fmts and fill_profile_level functions.

commit 8d0b89398b7e ("media: venus: hfi: add checks to handle capabilities
from firmware").

Change-Id: Ib34d6d8dd77b3997bbbc7a25376b658dbcb6bac6
Cc: stable@vger.kernel.org
Fixes: 1a73374a ("media: venus: hfi_parser: add common capability parser")
Signed-off-by: default avatarStanimir Varbanov <stanimir.k.varbanov@gmail.com>
Signed-off-by: default avatarHans Verkuil <hverkuil-cisco@xs4all.nl>
Signed-off-by: default avatarVikash Garodia <quic_vgarodia@quicinc.com>
parent d156b798
Loading
Loading
Loading
Loading
+12 −0
Original line number Diff line number Diff line
@@ -86,6 +86,9 @@ static void fill_profile_level(struct venus_caps *cap, const void *data,
{
	const struct hfi_profile_level *pl = data;

	if (cap->num_pl + num >= HFI_MAX_PROFILE_COUNT)
		return;

	memcpy(&cap->pl[cap->num_pl], pl, num * sizeof(*pl));
	cap->num_pl += num;
}
@@ -111,6 +114,9 @@ fill_caps(struct venus_caps *cap, const void *data, unsigned int num)
{
	const struct hfi_capability *caps = data;

	if (cap->num_caps + num >= MAX_CAP_ENTRIES)
		return;

	memcpy(&cap->caps[cap->num_caps], caps, num * sizeof(*caps));
	cap->num_caps += num;
}
@@ -137,6 +143,9 @@ static void fill_raw_fmts(struct venus_caps *cap, const void *fmts,
{
	const struct raw_formats *formats = fmts;

	if (cap->num_fmts + num_fmts >= MAX_FMT_ENTRIES)
		return;

	memcpy(&cap->fmts[cap->num_fmts], formats, num_fmts * sizeof(*formats));
	cap->num_fmts += num_fmts;
}
@@ -159,6 +168,9 @@ parse_raw_formats(struct venus_core *core, u32 codecs, u32 domain, void *data)
		rawfmts[i].buftype = fmt->buffer_type;
		i++;

		if (i >= MAX_FMT_ENTRIES)
			return;

		if (pinfo->num_planes > MAX_PLANES)
			break;