All of lore.kernel.org
 help / color / mirror / Atom feed
From: "Péter Ujfalusi" <peter.ujfalusi@linux.intel.com>
To: Mark Brown <broonie@kernel.org>
Cc: vkoul@kernel.org, perex@perex.cz, tiwai@suse.com,
	lgirdwood@gmail.com, srinivas.kandagatla@oss.qualcomm.com,
	linux-sound@vger.kernel.org, kai.vehmanen@linux.intel.com,
	yung-chuan.liao@linux.intel.com, pierre-louis.bossart@linux.dev,
	daniel.baluta@nxp.com
Subject: Re: [PATCH v3 18/26] ASoC: SOF: ipc4/ipc4-loader: Add SOF_INFO and CODEC_INFO to fw_config_params
Date: Mon, 14 Sep 2026 10:28:41 +0300	[thread overview]
Message-ID: <30950a7e-25ea-4b32-94ee-70c7357ffcaf@linux.intel.com> (raw)
In-Reply-To: <aqRsL8fZercsabgU@sirena.org.uk>



On 12/09/2026 00:01, Mark Brown wrote:
> On Fri, Sep 11, 2026 at 02:21:44PM +0300, Peter Ujfalusi wrote:
> 
>> +static int sof_ipc4_query_sof_info(struct snd_sof_dev *sdev,
>> +				   void *sof_info_data, u32 sof_info_size)
>> +{
>> +	struct sof_ipc4_fw_data *ipc4_data = sdev->private;
>> +	struct sof_ipc4_tuple *tuple;
>> +	size_t tuple_size;
>> +	size_t offset = 0;
>> +	int ret = 0;
> 
>> +	while (offset < sof_info_size) {
> 
>> +		tuple = (struct sof_ipc4_tuple *)((u8 *)sof_info_data + offset);
>> +		tuple_size = sizeof(*tuple) + tuple->size;
>> +		if (tuple_size < sizeof(*tuple) || tuple_size > sof_info_size - offset) {
> 
> tuple->size can be 0...

It cannot be 0, the tuples are built in firmware and they are guarantied
to be correct.

I guess I have added this check based on comments, but I would rather
remove them.

s for the specific CODEC_INFO, it is also granted that the tuple->size
is not 0:
https://github.com/thesofproject/sof/blob/main/src/audio/base_fw.c#L111

In fact, all tuples are added in a way that the size cannot be 0, but
the check in the code is incorrect, it should be:
if (!tuple->size || tuple_size > sof_info_size - offset) {


> 
>> +		switch (tuple->type) {
>> +		case SOF_IPC4_SOF_CODEC_INFO:
>> +			ipc4_data->codec_info = devm_kmemdup(sdev->dev, tuple->value,
>> +							     tuple->size, GFP_KERNEL);
> 
> ...and devm_kmemdup() of 0 returns ZERO_SIZE_PTR which crucially is not
> NULL so things that later check that codec_info is set see that it is
> and try to dereference it.  We should probably also check that the count
> in the codec_info isn't oveflowing the buffer.

We trust  the firmware provided information. If we cannot trust that
then we cannot trust on the size / count it provides either and there is
nothing that we can validate.

We don't have tuple size checking for fw_config or hw_config either.

To have a compromised fw booted it involves obtaining a secret signing
key to sign the compromised fw and a root access to actually deploy to
the system.

-- 
Péter


  reply	other threads:[~2026-09-14  7:28 UTC|newest]

Thread overview: 34+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-11 11:21 [PATCH v3 00/26] ALSA compress / ASoC compress / SOF: Compressed audio support with IPC4 Peter Ujfalusi
2026-09-11 11:21 ` [PATCH v3 01/26] ALSA: compress: pin card module while stream is open Peter Ujfalusi
2026-09-11 11:21 ` [PATCH v3 02/26] ALSA: compress: register the open file with the card Peter Ujfalusi
2026-09-11 11:21 ` [PATCH v3 03/26] ALSA: compress: stop active streams on disconnect Peter Ujfalusi
2026-09-11 11:21 ` [PATCH v3 04/26] ASoC: soc-compress: Provide a runtime for the compressed FE substream Peter Ujfalusi
2026-09-11 11:21 ` [PATCH v3 05/26] ASoC: soc-compress: Implement trigger FE-BE sequencing as with normal PCMs Peter Ujfalusi
2026-09-11 11:21 ` [PATCH v3 06/26] ASoC: soc-compress: Stop running dpcm on free Peter Ujfalusi
2026-09-11 11:21 ` [PATCH v3 07/26] ASoC: SOF: compress: Move the IPC agnostic helpers to sof-audio.c Peter Ujfalusi
2026-09-11 11:21 ` [PATCH v3 08/26] ASoC: SOF: compress: Rename compress ops with ipc3 prefix Peter Ujfalusi
2026-09-11 11:21 ` [PATCH v3 09/26] ASoC: SOF: sof-audio: Fix the pipeline_list population Peter Ujfalusi
2026-09-11 11:21 ` [PATCH v3 10/26] ASoC: SOF: ipc4-pcm: Serialize the PCM free with the pipeline triggers Peter Ujfalusi
2026-09-11 11:21 ` [PATCH v3 11/26] ASoC: SOF: sof-audio: do not dereference swidget->spipe unconditionally on free Peter Ujfalusi
2026-09-11 11:21 ` [PATCH v3 12/26] ASoC: SOF: sof-audio: Expose a couple of functions Peter Ujfalusi
2026-09-11 11:21 ` [PATCH v3 13/26] ASoC: SOF: pcm: Modify the signature of a couple of PCM IPC ops Peter Ujfalusi
2026-09-11 11:21 ` [PATCH v3 14/26] ASoC: SOF: intel: hda-stream: Clear the current position when releasing stream Peter Ujfalusi
2026-09-11 11:21 ` [PATCH v3 15/26] ASoC: SOF: ipc4: Add definition of module data in init_ext object type Peter Ujfalusi
2026-09-11 11:21 ` [PATCH v3 16/26] ASoC: SOF: ipc4-topology: Support init_ext_module_data for process modules Peter Ujfalusi
2026-09-11 11:21 ` [PATCH v3 17/26] ASoC: SOF: ipc4-pcm: Make the timestamp info usable outside of ipc4-pcm.c Peter Ujfalusi
2026-09-11 11:21 ` [PATCH v3 18/26] ASoC: SOF: ipc4/ipc4-loader: Add SOF_INFO and CODEC_INFO to fw_config_params Peter Ujfalusi
2026-09-11 21:01   ` Mark Brown
2026-09-14  7:28     ` Péter Ujfalusi [this message]
2026-09-14  8:35       ` Péter Ujfalusi
2026-09-14 19:02       ` Mark Brown
2026-09-15  5:49         ` Péter Ujfalusi
2026-09-11 11:21 ` [PATCH v3 19/26] ASoC: SOF: ipc4-pcm: Handle COMPR DRAIN triggers as EOS pipeline state Peter Ujfalusi
2026-09-11 11:21 ` [PATCH v3 20/26] ASoC: SOF: ipc4-topology: Set FAST_MODE for host copier in compr mode Peter Ujfalusi
2026-09-11 11:21 ` [PATCH v3 21/26] ASoC: SOF: ops: Add new platform-specific ops for compress Peter Ujfalusi
2026-09-11 11:21 ` [PATCH v3 22/26] ASoC: SOF: Add support for IPC4 compressed Peter Ujfalusi
2026-09-11 20:50   ` Mark Brown
2026-09-14  7:48     ` Péter Ujfalusi
2026-09-11 11:21 ` [PATCH v3 23/26] ASoC: SOF: ipc4: Handle compressed drain done notification from firmware Peter Ujfalusi
2026-09-11 11:21 ` [PATCH v3 24/26] ASoC: SOF: Intel: Kconfig: Remove redundant IPC version selects Peter Ujfalusi
2026-09-11 11:21 ` [PATCH v3 25/26] ASoC: SOF: Intel: Kconfig: Select compress support for TGL+ platforms Peter Ujfalusi
2026-09-11 11:21 ` [PATCH v3 26/26] ASoC: SOF: topology: Add support for decoder and encoder widgets Peter Ujfalusi

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=30950a7e-25ea-4b32-94ee-70c7357ffcaf@linux.intel.com \
    --to=peter.ujfalusi@linux.intel.com \
    --cc=broonie@kernel.org \
    --cc=daniel.baluta@nxp.com \
    --cc=kai.vehmanen@linux.intel.com \
    --cc=lgirdwood@gmail.com \
    --cc=linux-sound@vger.kernel.org \
    --cc=perex@perex.cz \
    --cc=pierre-louis.bossart@linux.dev \
    --cc=srinivas.kandagatla@oss.qualcomm.com \
    --cc=tiwai@suse.com \
    --cc=vkoul@kernel.org \
    --cc=yung-chuan.liao@linux.intel.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.