From: Laurent Pinchart <laurent.pinchart@ideasonboard.com>
To: Dan Scally <dan.scally@ideasonboard.com>
Cc: Sakari Ailus <sakari.ailus@iki.fi>,
linux-media@vger.kernel.org, devicetree@vger.kernel.org,
linux-arm-kernel@lists.infradead.org,
jacopo.mondi@ideasonboard.com, nayden.kanchev@arm.com,
robh+dt@kernel.org, mchehab@kernel.org,
krzysztof.kozlowski+dt@linaro.org, conor+dt@kernel.org,
jerome.forissier@linaro.org, kieran.bingham@ideasonboard.com
Subject: Re: [PATCH v5 15/16] media: platform: Add mali-c55 parameters video node
Date: Mon, 17 Jun 2024 00:32:06 +0300 [thread overview]
Message-ID: <20240616213206.GE7378@pendragon.ideasonboard.com> (raw)
In-Reply-To: <c0fcf014-ddec-4920-8a44-3cefd7e336ad@ideasonboard.com>
On Fri, Jun 14, 2024 at 10:49:37PM +0100, Daniel Scally wrote:
> On 14/06/2024 22:11, Sakari Ailus wrote:
> > On Fri, Jun 14, 2024 at 09:15:07PM +0100, Dan Scally wrote:
> >>>> +void mali_c55_params_write_config(struct mali_c55 *mali_c55)
> >>>> +{
> >>>> + struct mali_c55_params *params = &mali_c55->params;
> >>>> + enum vb2_buffer_state state = VB2_BUF_STATE_DONE;
> >>>> + struct mali_c55_params_buffer *config;
> >>>> + struct mali_c55_buffer *buf;
> >>>> + size_t block_offset = 0;
> >>>> +
> >>>> + spin_lock(¶ms->buffers.lock);
> >>>> +
> >>>> + buf = list_first_entry_or_null(¶ms->buffers.queue,
> >>>> + struct mali_c55_buffer, queue);
> >>>> + if (buf)
> >>>> + list_del(&buf->queue);
> >>>> + spin_unlock(¶ms->buffers.lock);
> >>>> +
> >>>> + if (!buf)
> >>>> + return;
> >>>> +
> >>>> + buf->vb.sequence = mali_c55->isp.frame_sequence;
> >>>> + config = vb2_plane_vaddr(&buf->vb.vb2_buf, 0);
> >>>> +
> >>>> + if (config->total_size > MALI_C55_PARAMS_MAX_SIZE) {
> >>>> + dev_dbg(mali_c55->dev, "Invalid parameters buffer size %lu\n",
> >>>> + config->total_size);
> >>>> + state = VB2_BUF_STATE_ERROR;
> >>>> + goto err_buffer_done;
> >>>> + }
> >>>> +
> >>>> + /* Walk the list of parameter blocks and process them. */
> >>>> + while (block_offset < config->total_size) {
> >>>> + const struct mali_c55_block_handler *block_handler;
> >>>> + struct mali_c55_params_block_header *block;
> >>>> +
> >>>> + block = (struct mali_c55_params_block_header *)
> >>>> + &config->data[block_offset];
> >>>
> >>> How do you ensure config->data does hold a full struct
> >>> mali_c33_params_block_header at block_offset (i.e. that the struct does not
> >>> exceed the memory available for config->data)?
> >>
> >> We don't currently...the data buffer is sized specifically to be large
> >> enough to accept a single instance of each possible struct that could be
> >> included, we could keep track of the blocks that we have seen already and
> >> ensure that none are seen twice...and that should guarantee that the
> >> remaining space is sufficient to hold whatever the last block is. Does that
> >> sound ok?
> >
> > Ḯ'd add an explicit check here.
>
> How would you do the check, sorry?
You could simply change the while() loop to
max_offset = config->total_size - sizeof(mali_c55_params_block_header);
while (block_offset <= max_offset) {
That would ensure that you always have enough space left for a header.
Within the loop, you will need to check that block->size doesn't go past
the end of the remaining space. Please also check the code for integer
overflows.
> > It's more simple way to ensure memory
> > safety here: relying on a complex machinery that can't be trivially
> > validated does risk having grave bugs, not only now but later on as well as
> > modifications to the code are done.
> >
> >>>> +
> >>>> + if (block->type >= MALI_C55_PARAM_BLOCK_SENTINEL) {
> >>>> + dev_dbg(mali_c55->dev, "Invalid parameters block type\n");
> >>>> + state = VB2_BUF_STATE_ERROR;
> >>>> + goto err_buffer_done;
> >>>> + }
> >>>> +
> >>>> + block_handler = &mali_c55_block_handlers[block->type];
> >>>> + if (block->size != block_handler->size) {
> >>>
> >>> How do you ensure config->data has room for the block?
> >>
> >> I think through the same proposal as above.
> >
> > Similarly here. You already even have the size of the blocks available
> > here.
--
Regards,
Laurent Pinchart
next prev parent reply other threads:[~2024-06-16 21:32 UTC|newest]
Thread overview: 58+ messages / expand[flat|nested] mbox.gz Atom feed top
2024-05-29 15:28 [PATCH v5 00/16] Add Arm Mali-C55 Image Signal Processor Driver Daniel Scally
2024-05-29 15:28 ` [PATCH v5 01/16] media: uapi: Add MEDIA_BUS_FMT_RGB202020_1X60 format code Daniel Scally
2024-05-29 18:14 ` Laurent Pinchart
2024-05-29 15:28 ` [PATCH v5 02/16] media: uapi: Add 20-bit bayer formats Daniel Scally
2024-05-29 18:18 ` Laurent Pinchart
2024-05-29 15:28 ` [PATCH v5 03/16] media: v4l2-common: Add RAW16 format info Daniel Scally
2024-05-29 18:20 ` Laurent Pinchart
2024-05-29 15:28 ` [PATCH v5 04/16] dt-bindings: media: Add bindings for ARM mali-c55 Daniel Scally
2024-05-29 18:21 ` Laurent Pinchart
2024-05-29 15:28 ` [PATCH v5 06/16] media: Documentation: Add Mali-C55 ISP Documentation Daniel Scally
2024-05-29 20:22 ` Laurent Pinchart
2024-05-29 20:35 ` Dan Scally
2024-05-29 20:51 ` Laurent Pinchart
2024-05-29 21:11 ` Dan Scally
2024-05-29 21:31 ` Dan Scally
2024-05-29 15:28 ` [PATCH v5 07/16] MAINTAINERS: Add entry for mali-c55 driver Daniel Scally
2024-05-29 18:25 ` Laurent Pinchart
2024-05-29 15:28 ` [PATCH v5 08/16] media: Add MALI_C55_3A_STATS meta format Daniel Scally
2024-05-30 21:49 ` Laurent Pinchart
2024-05-29 15:28 ` [PATCH v5 09/16] media: uapi: Add 3a stats buffer for mali-c55 Daniel Scally
2024-05-30 22:24 ` Laurent Pinchart
2024-05-29 15:28 ` [PATCH v5 10/16] media: platform: Add mali-c55 3a stats devnode Daniel Scally
2024-06-16 21:19 ` Laurent Pinchart
2024-06-20 15:10 ` Dan Scally
2024-06-29 15:04 ` Laurent Pinchart
2024-07-01 15:12 ` Dan Scally
2024-07-02 7:00 ` Dan Scally
2024-07-21 23:27 ` Laurent Pinchart
2024-05-29 15:28 ` [PATCH v5 11/16] media: platform: Fill stats buffer on ISP_START Daniel Scally
2024-05-29 15:28 ` [PATCH v5 12/16] Documentation: mali-c55: Add Statistics documentation Daniel Scally
2024-05-30 22:43 ` Laurent Pinchart
2024-05-29 15:28 ` [PATCH v5 13/16] media: mali-c55: Add image formats for Mali-C55 parameters buffer Daniel Scally
2024-05-30 22:44 ` Laurent Pinchart
2024-05-29 15:28 ` [PATCH v5 14/16] media: uapi: Add parameters structs to mali-c55-config.h Daniel Scally
2024-05-30 7:08 ` kernel test robot
2024-05-31 0:09 ` Laurent Pinchart
2024-05-31 7:30 ` Dan Scally
2024-06-02 0:24 ` Laurent Pinchart
2024-05-29 15:28 ` [PATCH v5 15/16] media: platform: Add mali-c55 parameters video node Daniel Scally
2024-05-30 7:18 ` kernel test robot
2024-05-30 12:54 ` kernel test robot
2024-06-14 18:53 ` Sakari Ailus
2024-06-14 20:15 ` Dan Scally
2024-06-14 21:11 ` Sakari Ailus
2024-06-14 21:49 ` Dan Scally
2024-06-16 21:32 ` Laurent Pinchart [this message]
2024-05-29 15:28 ` [PATCH v5 16/16] Documentation: mali-c55: Document the mali-c55 parameter setting Daniel Scally
2024-05-30 22:54 ` Laurent Pinchart
2024-05-29 23:27 ` [PATCH v5 00/16] Add Arm Mali-C55 Image Signal Processor Driver Laurent Pinchart
[not found] ` <20240529152858.183799-6-dan.scally@ideasonboard.com>
[not found] ` <20240530001507.GG10586@pendragon.ideasonboard.com>
[not found] ` <20240530214348.GA5213@pendragon.ideasonboard.com>
2024-06-06 12:47 ` [PATCH v5 05/16] media: mali-c55: Add Mali-C55 ISP driver Jacopo Mondi
2024-06-06 17:53 ` Laurent Pinchart
2024-06-06 19:10 ` Tomi Valkeinen
2024-06-09 6:21 ` Sakari Ailus
2024-06-16 20:38 ` Laurent Pinchart
2024-06-17 6:53 ` Sakari Ailus
2024-06-17 22:49 ` Laurent Pinchart
[not found] ` <6d0be0cf-ff77-4943-8505-f78ad922e3fb@ideasonboard.com>
2024-06-16 19:39 ` Laurent Pinchart
2024-06-17 6:31 ` Dan Scally
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20240616213206.GE7378@pendragon.ideasonboard.com \
--to=laurent.pinchart@ideasonboard.com \
--cc=conor+dt@kernel.org \
--cc=dan.scally@ideasonboard.com \
--cc=devicetree@vger.kernel.org \
--cc=jacopo.mondi@ideasonboard.com \
--cc=jerome.forissier@linaro.org \
--cc=kieran.bingham@ideasonboard.com \
--cc=krzysztof.kozlowski+dt@linaro.org \
--cc=linux-arm-kernel@lists.infradead.org \
--cc=linux-media@vger.kernel.org \
--cc=mchehab@kernel.org \
--cc=nayden.kanchev@arm.com \
--cc=robh+dt@kernel.org \
--cc=sakari.ailus@iki.fi \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).