AMD-GFX Archive on lore.kernel.org
 help / color / mirror / Atom feed
From: "Chung, ChiaHsuan (Tom)" <chiahsuan.chung@amd.com>
To: Srinivasan Shanmugam <srinivasan.shanmugam@amd.com>,
	Aurabindo Pillai <aurabindo.pillai@amd.com>,
	Rodrigo Siqueira <Rodrigo.Siqueira@amd.com>
Cc: amd-gfx@lists.freedesktop.org,
	Vitaly Prosyak <vitaly.prosyak@amd.com>,
	Charlene Liu <Charlene.Liu@amd.com>,
	Harry Wentland <harry.wentland@amd.com>,
	Roman Li <roman.li@amd.com>
Subject: Re: [PATCH] drm/amd/display: Fix potential index out of bounds in color transformation function
Date: Mon, 11 Mar 2024 13:41:25 +0800	[thread overview]
Message-ID: <951b6dc0-8cf6-4b47-a16d-28e9d488348c@amd.com> (raw)
In-Reply-To: <20240228091728.3237681-1-srinivasan.shanmugam@amd.com>

Reviewed-by: Tom Chung <chiahsuan.chung@amd.com>

On 2/28/2024 5:17 PM, Srinivasan Shanmugam wrote:
> Fixes index out of bounds issue in the color transformation function.
> The issue could occur when the index 'i' exceeds the number of transfer
> function points (TRANSFER_FUNC_POINTS).
>
> The fix adds a check to ensure 'i' is within bounds before accessing the
> transfer function points. If 'i' is out of bounds, an error message is
> logged and the function returns false to indicate an error.
>
> Reported by smatch:
> drivers/gpu/drm/amd/amdgpu/../display/dc/dcn10/dcn10_cm_common.c:405 cm_helper_translate_curve_to_hw_format() error: buffer overflow 'output_tf->tf_pts.red' 1025 <= s32max
> drivers/gpu/drm/amd/amdgpu/../display/dc/dcn10/dcn10_cm_common.c:406 cm_helper_translate_curve_to_hw_format() error: buffer overflow 'output_tf->tf_pts.green' 1025 <= s32max
> drivers/gpu/drm/amd/amdgpu/../display/dc/dcn10/dcn10_cm_common.c:407 cm_helper_translate_curve_to_hw_format() error: buffer overflow 'output_tf->tf_pts.blue' 1025 <= s32max
>
> Fixes: b629596072e5 ("drm/amd/display: Build unity lut for shaper")
> Cc: Vitaly Prosyak <vitaly.prosyak@amd.com>
> Cc: Charlene Liu <Charlene.Liu@amd.com>
> Cc: Harry Wentland <harry.wentland@amd.com>
> Cc: Rodrigo Siqueira <Rodrigo.Siqueira@amd.com>
> Cc: Roman Li <roman.li@amd.com>
> Cc: Aurabindo Pillai <aurabindo.pillai@amd.com>
> Cc: Tom Chung <chiahsuan.chung@amd.com>
> Signed-off-by: Srinivasan Shanmugam <srinivasan.shanmugam@amd.com>
> ---
>   drivers/gpu/drm/amd/display/dc/dcn10/dcn10_cm_common.c | 5 +++++
>   1 file changed, 5 insertions(+)
>
> diff --git a/drivers/gpu/drm/amd/display/dc/dcn10/dcn10_cm_common.c b/drivers/gpu/drm/amd/display/dc/dcn10/dcn10_cm_common.c
> index b7e57aa27361..b0d192c6e63e 100644
> --- a/drivers/gpu/drm/amd/display/dc/dcn10/dcn10_cm_common.c
> +++ b/drivers/gpu/drm/amd/display/dc/dcn10/dcn10_cm_common.c
> @@ -402,6 +402,11 @@ bool cm_helper_translate_curve_to_hw_format(struct dc_context *ctx,
>   				i += increment) {
>   			if (j == hw_points - 1)
>   				break;
> +			if (i >= TRANSFER_FUNC_POINTS) {
> +				DC_LOG_ERROR("Index out of bounds: i=%d, TRANSFER_FUNC_POINTS=%d\n",
> +					     i, TRANSFER_FUNC_POINTS);
> +				return false;
> +			}
>   			rgb_resulted[j].red = output_tf->tf_pts.red[i];
>   			rgb_resulted[j].green = output_tf->tf_pts.green[i];
>   			rgb_resulted[j].blue = output_tf->tf_pts.blue[i];

      reply	other threads:[~2024-03-11  5:41 UTC|newest]

Thread overview: 2+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2024-02-28  9:17 [PATCH] drm/amd/display: Fix potential index out of bounds in color transformation function Srinivasan Shanmugam
2024-03-11  5:41 ` Chung, ChiaHsuan (Tom) [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=951b6dc0-8cf6-4b47-a16d-28e9d488348c@amd.com \
    --to=chiahsuan.chung@amd.com \
    --cc=Charlene.Liu@amd.com \
    --cc=Rodrigo.Siqueira@amd.com \
    --cc=amd-gfx@lists.freedesktop.org \
    --cc=aurabindo.pillai@amd.com \
    --cc=harry.wentland@amd.com \
    --cc=roman.li@amd.com \
    --cc=srinivasan.shanmugam@amd.com \
    --cc=vitaly.prosyak@amd.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox