* [PATCH 1/2] ASoC: ops: Fix bounds check for _sx controls
@ 2022-05-11 13:41 Mark Brown
2022-05-11 13:41 ` [PATCH 2/2] ASoC: ops: Check bounds for second channel in snd_soc_put_volsw_sx() Mark Brown
2022-05-12 14:12 ` [PATCH 1/2] ASoC: ops: Fix bounds check for _sx controls Mark Brown
0 siblings, 2 replies; 4+ messages in thread
From: Mark Brown @ 2022-05-11 13:41 UTC (permalink / raw)
To: Liam Girdwood; +Cc: alsa-devel, Mark Brown
For _sx controls the semantics of the max field is not the usual one, max
is the number of steps rather than the maximum value. This means that our
check in snd_soc_put_volsw_sx() needs to just check against the maximum
value.
Fixes: 4f1e50d6a9cf9c1b ("ASoC: ops: Reject out of bounds values in snd_soc_put_volsw_sx()")
Signed-off-by: Mark Brown <broonie@kernel.org>
---
sound/soc/soc-ops.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/sound/soc/soc-ops.c b/sound/soc/soc-ops.c
index e693070f51fe..1ac7e2ce31a1 100644
--- a/sound/soc/soc-ops.c
+++ b/sound/soc/soc-ops.c
@@ -435,7 +435,7 @@ int snd_soc_put_volsw_sx(struct snd_kcontrol *kcontrol,
val = ucontrol->value.integer.value[0];
if (mc->platform_max && val > mc->platform_max)
return -EINVAL;
- if (val > max - min)
+ if (val > max)
return -EINVAL;
val_mask = mask << shift;
val = (val + min) & mask;
--
2.30.2
^ permalink raw reply related [flat|nested] 4+ messages in thread
* [PATCH 2/2] ASoC: ops: Check bounds for second channel in snd_soc_put_volsw_sx()
2022-05-11 13:41 [PATCH 1/2] ASoC: ops: Fix bounds check for _sx controls Mark Brown
@ 2022-05-11 13:41 ` Mark Brown
2022-05-12 14:12 ` [PATCH 1/2] ASoC: ops: Fix bounds check for _sx controls Mark Brown
1 sibling, 0 replies; 4+ messages in thread
From: Mark Brown @ 2022-05-11 13:41 UTC (permalink / raw)
To: Liam Girdwood; +Cc: alsa-devel, Mark Brown
The bounds checks in snd_soc_put_volsw_sx() are only being applied to the
first channel, meaning it is possible to write out of bounds values to the
second channel in stereo controls. Add appropriate checks.
Signed-off-by: Mark Brown <broonie@kernel.org>
---
sound/soc/soc-ops.c | 6 ++++++
1 file changed, 6 insertions(+)
diff --git a/sound/soc/soc-ops.c b/sound/soc/soc-ops.c
index 1ac7e2ce31a1..7cac26a64e0c 100644
--- a/sound/soc/soc-ops.c
+++ b/sound/soc/soc-ops.c
@@ -451,6 +451,12 @@ int snd_soc_put_volsw_sx(struct snd_kcontrol *kcontrol,
val_mask = mask << rshift;
val2 = (ucontrol->value.integer.value[1] + min) & mask;
+
+ if (mc->platform_max && val2 > mc->platform_max)
+ return -EINVAL;
+ if (val2 > max)
+ return -EINVAL;
+
val2 = val2 << rshift;
err = snd_soc_component_update_bits(component, reg2, val_mask,
--
2.30.2
^ permalink raw reply related [flat|nested] 4+ messages in thread
* Re: [PATCH 1/2] ASoC: ops: Fix bounds check for _sx controls
2022-05-11 13:41 [PATCH 1/2] ASoC: ops: Fix bounds check for _sx controls Mark Brown
2022-05-11 13:41 ` [PATCH 2/2] ASoC: ops: Check bounds for second channel in snd_soc_put_volsw_sx() Mark Brown
@ 2022-05-12 14:12 ` Mark Brown
1 sibling, 0 replies; 4+ messages in thread
From: Mark Brown @ 2022-05-12 14:12 UTC (permalink / raw)
To: broonie, Liam Girdwood; +Cc: alsa-devel
On Wed, 11 May 2022 14:41:36 +0100, Mark Brown wrote:
> For _sx controls the semantics of the max field is not the usual one, max
> is the number of steps rather than the maximum value. This means that our
> check in snd_soc_put_volsw_sx() needs to just check against the maximum
> value.
>
>
Applied to
https://git.kernel.org/pub/scm/linux/kernel/git/broonie/sound.git for-next
Thanks!
[1/2] ASoC: ops: Fix bounds check for _sx controls
commit: 698813ba8c580efb356ace8dbf55f61dac6063a8
[2/2] ASoC: ops: Check bounds for second channel in snd_soc_put_volsw_sx()
commit: 97eea946b93961fffd29448dcda7398d0d51c4b2
All being well this means that it will be integrated into the linux-next
tree (usually sometime in the next 24 hours) and sent to Linus during
the next merge window (or sooner if it is a bug fix), however if
problems are discovered then the patch may be dropped or reverted.
You may get further e-mails resulting from automated or manual testing
and review of the tree, please engage with people reporting problems and
send followup patches addressing any issues that are reported if needed.
If any updates are required or you are submitting further changes they
should be sent as incremental updates against current git, existing
patches will not be replaced.
Please add any relevant lists and maintainers to the CCs when replying
to this mail.
Thanks,
Mark
^ permalink raw reply [flat|nested] 4+ messages in thread
* [PATCH 2/2] ASoC: ops: Check bounds for second channel in snd_soc_put_volsw_sx()
2022-11-25 15:48 [PATCH 0/2] SX control bounds check fixups Charles Keepax
@ 2022-11-25 15:48 ` Charles Keepax
0 siblings, 0 replies; 4+ messages in thread
From: Charles Keepax @ 2022-11-25 15:48 UTC (permalink / raw)
To: broonie; +Cc: patches, alsa-devel, guille.rodriguez, lgirdwood
From: Mark Brown <broonie@kernel.org>
The bounds checks in snd_soc_put_volsw_sx() are only being applied to the
first channel, meaning it is possible to write out of bounds values to the
second channel in stereo controls. Add appropriate checks.
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Charles Keepax <ckeepax@opensource.cirrus.com>
---
Slight fixup was made over your original version to make the check of
val2 > max be without the min and mask applied.
Thanks,
Charles
sound/soc/soc-ops.c | 9 +++++++--
1 file changed, 7 insertions(+), 2 deletions(-)
diff --git a/sound/soc/soc-ops.c b/sound/soc/soc-ops.c
index 47691119306fb..55b009d3c6815 100644
--- a/sound/soc/soc-ops.c
+++ b/sound/soc/soc-ops.c
@@ -464,10 +464,15 @@ int snd_soc_put_volsw_sx(struct snd_kcontrol *kcontrol,
ret = err;
if (snd_soc_volsw_is_stereo(mc)) {
- unsigned int val2;
+ unsigned int val2 = ucontrol->value.integer.value[1];
+
+ if (mc->platform_max && val2 > mc->platform_max)
+ return -EINVAL;
+ if (val2 > max)
+ return -EINVAL;
val_mask = mask << rshift;
- val2 = (ucontrol->value.integer.value[1] + min) & mask;
+ val2 = (val2 + min) & mask;
val2 = val2 << rshift;
err = snd_soc_component_update_bits(component, reg2, val_mask,
--
2.30.2
^ permalink raw reply related [flat|nested] 4+ messages in thread
end of thread, other threads:[~2022-11-25 15:49 UTC | newest]
Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2022-05-11 13:41 [PATCH 1/2] ASoC: ops: Fix bounds check for _sx controls Mark Brown
2022-05-11 13:41 ` [PATCH 2/2] ASoC: ops: Check bounds for second channel in snd_soc_put_volsw_sx() Mark Brown
2022-05-12 14:12 ` [PATCH 1/2] ASoC: ops: Fix bounds check for _sx controls Mark Brown
-- strict thread matches above, loose matches on Subject: below --
2022-11-25 15:48 [PATCH 0/2] SX control bounds check fixups Charles Keepax
2022-11-25 15:48 ` [PATCH 2/2] ASoC: ops: Check bounds for second channel in snd_soc_put_volsw_sx() Charles Keepax
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox