From: sashiko-bot@kernel.org
To: "Sven Püschel" <s.pueschel@pengutronix.de>
Cc: devicetree@vger.kernel.org, conor+dt@kernel.org, robh@kernel.org
Subject: Re: [PATCH v7 22/28] media: rockchip: rga: remove size from rga_frame
Date: Wed, 20 May 2026 23:35:43 +0000 [thread overview]
Message-ID: <20260520233543.8FE9C1F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260521-spu-rga3-v7-22-3f33e8c7145f@pengutronix.de>
Thank you for your contribution! Sashiko AI review found 3 potential issue(s) to consider:
Pre-existing issues:
- [Critical] An off-by-one error in `fill_descriptors()` combined with memory under-allocation in `rga_buf_init()` causes an exploitable heap buffer overflow.
- [High] Plane DMA base addresses ignore the scatterlist intra-page offset, leading to incorrect hardware memory access for USERPTR and DMABUF buffers.
- [High] Missing early exits after `WARN_ON()` checks in `rga_isr()` lead to NULL pointer dereferences.
--
commit d8c810d4339b024a035832f04cb10cad2828d5e3
Author: Sven Püschel <s.pueschel@pengutronix.de>
media: rockchip: rga: remove size from rga_frame
This commit removes the size member from the rga_frame structure, as it is
only used for the MMU page table mapping. Instead, the driver now calculates
the size in place when needed, which also avoids the calculation entirely
when an external IOMMU is used.
> diff --git a/drivers/media/platform/rockchip/rga/rga-buf.c b/drivers/media/platform/rockchip/rga/rga-buf.c
> index cd6904d5fe5a6..092c2bdf6b672 100644
> --- a/drivers/media/platform/rockchip/rga/rga-buf.c
> +++ b/drivers/media/platform/rockchip/rga/rga-buf.c
> @@ -79,6 +79,8 @@ static int rga_buf_init(struct vb2_buffer *vb)
> struct rockchip_rga *rga = ctx->rga;
> struct rga_frame *f = rga_get_frame(ctx, vb->vb2_queue->type);
> size_t n_desc = 0;
> + u32 size = 0;
> + u8 i;
>
> if (IS_ERR(f))
> return PTR_ERR(f);
> @@ -86,7 +88,9 @@ static int rga_buf_init(struct vb2_buffer *vb)
> if (!rga_has_internal_iommu(rga))
> return 0;
>
> - n_desc = DIV_ROUND_UP(f->size, PAGE_SIZE);
> + for (i = 0; i < f->pix.num_planes; i++)
> + size += f->pix.plane_fmt[i].sizeimage;
> + n_desc = DIV_ROUND_UP(size, PAGE_SIZE);
[Severity: Critical]
This is a pre-existing issue, but can this memory allocation logic trigger a
heap buffer overflow when combined with fill_descriptors()?
Because multi-planar buffers have independent page alignments per plane,
the actual number of pages mapped in the SG tables can exceed the
calculation here: sum(DIV_ROUND_UP(size[i])) >= DIV_ROUND_UP(sum(size[i])).
Looking at fill_descriptors(), it checks if (n_desc > max_desc) return
-EINVAL. Since it uses > instead of >=, it permits exactly one out-of-bounds
write and then returns success.
In rga_buf_prepare(), if the first plane overflows by 1 page due to
under-allocation, fill_descriptors() silently corrupts the heap and returns
success. Then curr_desc increments past rbuf->n_desc.
For the next plane, max_desc is calculated as rbuf->n_desc - curr_desc,
which underflows to SIZE_MAX. Subsequent planes are then passed to
fill_descriptors() with max_desc = SIZE_MAX, completely disabling bounds
checks and allowing arbitrary-length out-of-bounds writes on the kernel
heap.
Could we update the allocation to calculate the number of descriptors per
plane, and fix the off-by-one error in fill_descriptors()?
>
> rbuf->n_desc = n_desc;
> rbuf->dma_desc = dma_alloc_coherent(rga->dev,
While reviewing this, I also noticed a couple of other pre-existing issues
in the surrounding code:
[Severity: High]
This is a pre-existing issue, but does this calculation ignore the
scatterlist intra-page offset?
drivers/media/platform/rockchip/rga/rga-buf.c:rga_buf_prepare() {
[ ... ]
if (rga_has_internal_iommu(ctx->rga)) {
/* Create local MMU table for RGA */
n_desc = fill_descriptors(&rbuf->dma_desc[curr_desc],
rbuf->n_desc - curr_desc,
vb2_dma_sg_plane_desc(vb, i));
if (n_desc < 0) {
v4l2_err(&ctx->rga->v4l2_dev,
"Failed to map video buffer to RGA\n");
return n_desc;
}
dma_addrs[i] = curr_desc << PAGE_SHIFT;
curr_desc += n_desc;
[ ... ]
}
When creating the local MMU table, the virtual base address for each plane
is calculated strictly as curr_desc << PAGE_SHIFT.
Buffers imported via USERPTR or DMABUF are not guaranteed to be page-aligned
and may have a non-zero intra-page offset (sgt->sgl->offset). By not adding
this offset to the DMA base address, does this instruct the hardware to start
reading/writing at the beginning of the mapped physical page rather than at
the actual start of the data?
[Severity: High]
This is a pre-existing issue, but could these missing early exits after
WARN_ON() checks lead to NULL pointer dereferences?
drivers/media/platform/rockchip/rga/rga.c:rga_isr() {
[ ... ]
WARN_ON(!ctx);
rga->curr = NULL;
src = v4l2_m2m_src_buf_remove(ctx->fh.m2m_ctx);
dst = v4l2_m2m_dst_buf_remove(ctx->fh.m2m_ctx);
WARN_ON(!src);
WARN_ON(!dst);
v4l2_m2m_buf_copy_metadata(src, dst);
[ ... ]
}
If a spurious interrupt or a shared interrupt mismatch causes ctx to be NULL,
the WARN_ON() fires, but the code immediately proceeds to call
v4l2_m2m_src_buf_remove(ctx->fh.m2m_ctx), which forcefully dereferences the
NULL pointer.
Similarly, it checks WARN_ON(!src) and WARN_ON(!dst) but still
unconditionally attempts to access them via
v4l2_m2m_buf_copy_metadata(src, dst) immediately afterward.
Should we return or skip the rest of the handler if any of these are NULL?
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260521-spu-rga3-v7-0-3f33e8c7145f@pengutronix.de?part=22
next prev parent reply other threads:[~2026-05-20 23:35 UTC|newest]
Thread overview: 49+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-05-20 22:44 [PATCH v7 00/28] media: platform: rga: Add RGA3 support Sven Püschel
2026-05-20 22:44 ` [PATCH v7 01/28] media: dt-bindings: media: rockchip-rga: add rockchip,rk3588-rga3 Sven Püschel
2026-05-20 22:44 ` [PATCH v7 02/28] media: v4l2-common: sort RGB formats in v4l2_format_info Sven Püschel
2026-05-20 22:44 ` [PATCH v7 03/28] media: v4l2-common: add missing 1 and 2 byte RGB formats to v4l2_format_info Sven Püschel
2026-05-20 22:44 ` [PATCH v7 04/28] media: v4l2-common: add has_alpha " Sven Püschel
2026-05-20 22:44 ` [PATCH v7 05/28] media: v4l2-common: add v4l2_fill_pixfmt_mp_aligned helper Sven Püschel
2026-05-20 23:48 ` Nicolas Dufresne
2026-05-20 22:44 ` [PATCH v7 06/28] media: rockchip: rga: fix too small buffer size Sven Püschel
2026-05-20 23:43 ` sashiko-bot
2026-05-20 22:44 ` [PATCH v7 07/28] media: rockchip: rga: use clk_bulk api Sven Püschel
2026-05-20 23:27 ` sashiko-bot
2026-05-20 22:44 ` [PATCH v7 08/28] media: rockchip: rga: use stride for offset calculation Sven Püschel
2026-05-20 23:38 ` sashiko-bot
2026-05-20 22:44 ` [PATCH v7 09/28] media: rockchip: rga: remove redundant rga_frame variables Sven Püschel
2026-05-20 23:37 ` sashiko-bot
2026-05-20 22:44 ` [PATCH v7 10/28] media: rockchip: rga: announce and sync colorimetry Sven Püschel
2026-05-20 23:45 ` sashiko-bot
2026-05-20 22:44 ` [PATCH v7 11/28] media: rockchip: rga: move hw specific parts to a dedicated struct Sven Püschel
2026-05-20 23:30 ` sashiko-bot
2026-05-20 22:44 ` [PATCH v7 12/28] media: rockchip: rga: avoid odd frame sizes for YUV formats Sven Püschel
2026-05-20 23:32 ` sashiko-bot
2026-05-20 22:44 ` [PATCH v7 13/28] media: rockchip: rga: calculate x_div/y_div using v4l2_format_info Sven Püschel
2026-05-20 22:44 ` [PATCH v7 14/28] media: rockchip: rga: move cmdbuf to rga_ctx Sven Püschel
2026-05-20 23:44 ` sashiko-bot
2026-05-20 22:44 ` [PATCH v7 15/28] media: rockchip: rga: align stride to 4 bytes Sven Püschel
2026-05-20 23:56 ` sashiko-bot
2026-05-20 22:44 ` [PATCH v7 16/28] media: rockchip: rga: reuse cmdbuf contents Sven Püschel
2026-05-20 23:30 ` sashiko-bot
2026-05-20 23:55 ` Nicolas Dufresne
2026-05-20 22:44 ` [PATCH v7 17/28] media: rockchip: rga: check scaling factor Sven Püschel
2026-05-20 23:42 ` sashiko-bot
2026-05-20 23:58 ` Nicolas Dufresne
2026-05-20 22:44 ` [PATCH v7 18/28] media: rockchip: rga: use card type to specify rga type Sven Püschel
2026-05-20 23:29 ` sashiko-bot
2026-05-20 22:44 ` [PATCH v7 19/28] media: rockchip: rga: change offset to dma_addresses Sven Püschel
2026-05-20 22:44 ` [PATCH v7 20/28] media: rockchip: rga: support external iommus Sven Püschel
2026-05-20 23:43 ` sashiko-bot
2026-05-20 22:44 ` [PATCH v7 21/28] media: rockchip: rga: share the interrupt when an external iommu is used Sven Püschel
2026-05-20 23:33 ` sashiko-bot
2026-05-20 22:44 ` [PATCH v7 22/28] media: rockchip: rga: remove size from rga_frame Sven Püschel
2026-05-20 23:35 ` sashiko-bot [this message]
2026-05-20 22:44 ` [PATCH v7 23/28] media: rockchip: rga: remove stride " Sven Püschel
2026-05-20 22:44 ` [PATCH v7 24/28] media: rockchip: rga: move rga_fmt to rga-hw.h Sven Püschel
2026-05-20 22:44 ` [PATCH v7 25/28] media: rockchip: rga: add feature flags Sven Püschel
2026-05-20 23:42 ` sashiko-bot
2026-05-20 22:44 ` [PATCH v7 26/28] media: rockchip: rga: disable multi-core support Sven Püschel
2026-05-20 22:44 ` [PATCH v7 27/28] media: rockchip: rga: add rga3 support Sven Püschel
2026-05-21 0:08 ` sashiko-bot
2026-05-20 22:44 ` [PATCH v7 28/28] arm64: dts: rockchip: add rga3 dt nodes Sven Püschel
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260520233543.8FE9C1F000E9@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=conor+dt@kernel.org \
--cc=devicetree@vger.kernel.org \
--cc=robh@kernel.org \
--cc=s.pueschel@pengutronix.de \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox