dri-devel Archive on lore.kernel.org
 help / color / mirror / Atom feed
* [PATCH] drm/ast: validate framebuffer VRAM size in ast_mode.c and DP501 firmware bounds
@ 2026-09-19 22:35 Hui Peng
  2026-09-19 22:58 ` sashiko-bot
  0 siblings, 1 reply; 2+ messages in thread
From: Hui Peng @ 2026-09-19 22:35 UTC (permalink / raw)
  To: tzimmermann, jfalempe, simona, airlied; +Cc: dri-devel, linux-kernel

In drivers/gpu/drm/ast/ (ast_mode.c, ast_dp501.c), verify that the
primary plane framebuffer fits within ast->vram_size and bounds-check
DP501 firmware headers.

Fixes: 312fec1405dd ("drm: Initial KMS driver for AST (ASpeed Technologies) 2000 series (v2)")
Assisted-by: LLM
Signed-off-by: Hui Peng <benquike@gmail.com>
---
diff --git a/drivers/gpu/drm/ast/ast_dp501.c b/drivers/gpu/drm/ast/ast_dp501.c
index 6d6ccfad1415..d9ca8760e5b5 100644
--- a/drivers/gpu/drm/ast/ast_dp501.c
+++ b/drivers/gpu/drm/ast/ast_dp501.c
@@ -250,7 +250,8 @@ static bool ast_launch_m68k(struct ast_device *ast)
 
 		/* copy image to buffer */
 		for (i = 0; i < len; i += 4) {
-			data = *(u32 *)(fw_addr + i);
+			data = 0;
+			memcpy(&data, fw_addr + i, min_t(u32, len - i, 4));
 			ast_moutdwm(ast, boot_address + i, data);
 		}
 
diff --git a/drivers/gpu/drm/ast/ast_mode.c b/drivers/gpu/drm/ast/ast_mode.c
index d5ed8c5c7925..bde9dcbbc32b 100644
--- a/drivers/gpu/drm/ast/ast_mode.c
+++ b/drivers/gpu/drm/ast/ast_mode.c
@@ -510,6 +510,7 @@ static int ast_primary_plane_helper_atomic_check(struct drm_plane *plane,
 						 struct drm_atomic_commit *state)
 {
 	struct drm_device *dev = plane->dev;
+	struct ast_plane *ast_plane = to_ast_plane(plane);
 	struct drm_plane_state *new_plane_state = drm_atomic_get_new_plane_state(state, plane);
 	struct drm_crtc_state *new_crtc_state = NULL;
 	struct ast_crtc_state *new_ast_crtc_state;
@@ -531,6 +532,11 @@ static int ast_primary_plane_helper_atomic_check(struct drm_plane *plane,
 			return 0;
 	}
 
+	if (new_plane_state->fb->pitches[0] > AST_PRIMARY_PLANE_MAX_OFFSET)
+		return -EINVAL;
+	if ((u64)new_plane_state->fb->pitches[0] * new_plane_state->fb->height > ast_plane->size)
+		return -ENOSPC;
+
 	new_ast_crtc_state = to_ast_crtc_state(new_crtc_state);
 
 	new_ast_crtc_state->format = new_plane_state->fb->format;

^ permalink raw reply related	[flat|nested] 2+ messages in thread

* Re: [PATCH] drm/ast: validate framebuffer VRAM size in ast_mode.c and DP501 firmware bounds
  2026-09-19 22:35 [PATCH] drm/ast: validate framebuffer VRAM size in ast_mode.c and DP501 firmware bounds Hui Peng
@ 2026-09-19 22:58 ` sashiko-bot
  0 siblings, 0 replies; 2+ messages in thread
From: sashiko-bot @ 2026-09-19 22:58 UTC (permalink / raw)
  To: Hui Peng; +Cc: dri-devel

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Medium] ast: commit message and code mismatch regarding DP501 bounds check
--

commit 7c7f87df86011f4f2e1f7815297b6468c2302228
Author: Hui Peng <benquike@gmail.com>

drm/ast: validate framebuffer VRAM size in ast_mode.c and DP501 firmware bounds

This commit adds bounds checking for the primary plane framebuffer size
against the vram_size. It also updates the DP501 firmware copy loop in
ast_dp501.c to prevent out-of-bounds memory accesses.

> In drivers/gpu/drm/ast/ (ast_mode.c, ast_dp501.c), verify that the
> primary plane framebuffer fits within ast->vram_size and bounds-check
> DP501 firmware headers.

> diff --git a/drivers/gpu/drm/ast/ast_dp501.c b/drivers/gpu/drm/ast/ast_dp501.c
> index 6d6ccfad14154..d9ca8760e5b51 100644
> --- a/drivers/gpu/drm/ast/ast_dp501.c
> +++ b/drivers/gpu/drm/ast/ast_dp501.c
> @@ -250,7 +250,8 @@ static bool ast_launch_m68k(struct ast_device *ast)
>  
>  		/* copy image to buffer */
>  		for (i = 0; i < len; i += 4) {
> -			data = *(u32 *)(fw_addr + i);
> +			data = 0;
> +			memcpy(&data, fw_addr + i, min_t(u32, len - i, 4));

[Severity: Medium]
Is the commit message accurate regarding DP501 firmware headers?

The commit message claims to "bounds-check DP501 firmware headers", but
ast_launch_m68k() adds a bounds check to the firmware payload copy loop
instead.

Since the driver reads DP501 headers directly from mapped hardware memory
rather than the host buffer, there are no headers in the host buffer to
bounds-check.

Could the commit message be updated to describe this payload copy bounds
check instead of firmware headers?

>  			ast_moutdwm(ast, boot_address + i, data);
>  		}

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260919223516.3889946-1-benquike@gmail.com?part=1

^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2026-09-21  7:00 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-19 22:35 [PATCH] drm/ast: validate framebuffer VRAM size in ast_mode.c and DP501 firmware bounds Hui Peng
2026-09-19 22:58 ` sashiko-bot

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox