linux-media.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
From: Manik Bajpai <manik.bajpai@intel.com>
To: linux-media@vger.kernel.org
Cc: sakari.ailus@linux.intel.com, antti.laakso@linux.intel.com,
	sarang.sapre@intel.com
Subject: [PATCH v1 3/4] media: ipu6: Validate fw-com queue indices before use
Date: Mon, 28 Sep 2026 17:26:45 +0530	[thread overview]
Message-ID: <20260928115646.77399-4-manik.bajpai@intel.com> (raw)
In-Reply-To: <20260928115646.77399-1-manik.bajpai@intel.com>

ipu7_fw_com_get_token() reads read_index/write_index directly from
firmware-shared memory and uses them unchecked in pointer arithmetic
to compute a token address:

	token = queue_params->token_array_mem +
		read_index * queue_params->token_size_in_bytes;

If firmware ever writes a corrupted or out-of-range index into that
shared memory, this computes a pointer outside token_array_mem.

Reject indices that are not smaller than max_capacity before doing any
pointer arithmetic.

Assisted-by: Claude:claude-sonnet-5
Signed-off-by: Manik Bajpai <manik.bajpai@intel.com>
---
 drivers/media/pci/intel/ipu6/ipu7-fw-com.c  | 14 +++++++++++++-
 drivers/media/pci/intel/ipu6/ipu7-fw-com.h  |  5 ++++-
 drivers/media/pci/intel/ipu6/ipu7-fw-isys.c |  7 ++++---
 3 files changed, 21 insertions(+), 5 deletions(-)

diff --git a/drivers/media/pci/intel/ipu6/ipu7-fw-com.c b/drivers/media/pci/intel/ipu6/ipu7-fw-com.c
index 7dd1e683aa92..3d0a8fcac15e 100644
--- a/drivers/media/pci/intel/ipu6/ipu7-fw-com.c
+++ b/drivers/media/pci/intel/ipu6/ipu7-fw-com.c
@@ -3,6 +3,7 @@
  * Copyright (C) 2026 Intel Corporation
  */
 
+#include <linux/device.h>
 #include <linux/io.h>
 
 #include "ipu7-fw-com.h"
@@ -13,7 +14,8 @@ static void __iomem *ipu7_fw_com_get_indices(struct ipu7_fw_com_context *ctx,
 	return ctx->queue_indices + (q * sizeof(struct ipu7_fw_com_queue_indices));
 }
 
-void *ipu7_fw_com_get_token(struct ipu7_fw_com_context *ctx, int q)
+void *ipu7_fw_com_get_token(struct device *dev, struct ipu7_fw_com_context *ctx,
+			    int q)
 {
 	struct ipu7_fw_com_queue_config *queue_params = &ctx->queue_configs[q];
 	void __iomem *queue_indices = ipu7_fw_com_get_indices(ctx, q);
@@ -25,6 +27,16 @@ void *ipu7_fw_com_get_token(struct ipu7_fw_com_context *ctx, int q)
 					read_index));
 	void *token = NULL;
 
+	/* Indices come from firmware-shared memory; don't trust them blindly. */
+	if (read_index >= queue_params->max_capacity ||
+	    write_index >= queue_params->max_capacity) {
+		dev_err_once(dev,
+			     "ipu7-fw-com: bad queue %d index (r=%u w=%u cap=%u)\n",
+			     q, read_index, write_index,
+			     queue_params->max_capacity);
+		return NULL;
+	}
+
 	if (q < ctx->num_output_queues) {
 		/* Output queue */
 		bool empty = (write_index == read_index);
diff --git a/drivers/media/pci/intel/ipu6/ipu7-fw-com.h b/drivers/media/pci/intel/ipu6/ipu7-fw-com.h
index 097eaab99547..2921d097e580 100644
--- a/drivers/media/pci/intel/ipu6/ipu7-fw-com.h
+++ b/drivers/media/pci/intel/ipu6/ipu7-fw-com.h
@@ -6,6 +6,8 @@
 
 #include <linux/types.h>
 
+struct device;
+
 struct ipu7_fw_com_queue_config {
 	void *token_array_mem;
 	u32 queue_size;
@@ -46,7 +48,8 @@ struct ipu7_fw_com_queue_indices {
 };
 
 void ipu7_fw_com_put_token(struct ipu7_fw_com_context *ctx, int q);
-void *ipu7_fw_com_get_token(struct ipu7_fw_com_context *ctx, int q);
+void *ipu7_fw_com_get_token(struct device *dev, struct ipu7_fw_com_context *ctx,
+			    int q);
 struct ipu7_fw_com_queue_params_config *
 ipu7_fw_com_get_queue_config(struct ipu7_fw_com_config *config);
 
diff --git a/drivers/media/pci/intel/ipu6/ipu7-fw-isys.c b/drivers/media/pci/intel/ipu6/ipu7-fw-isys.c
index e74e2b2566aa..60e29e2d63a7 100644
--- a/drivers/media/pci/intel/ipu6/ipu7-fw-isys.c
+++ b/drivers/media/pci/intel/ipu6/ipu7-fw-isys.c
@@ -147,7 +147,8 @@ static int ipu7_fw_isys_init(struct ipu6_isys *isys, unsigned int num_streams)
 
 static struct ipu7_insys_resp *ipu7_fw_isys_get_resp(struct ipu6_isys *isys)
 {
-	return ipu7_fw_com_get_token(isys->fwctx, IPU7_INSYS_OUTPUT_MSG_QUEUE);
+	return ipu7_fw_com_get_token(&isys->adev->auxdev.dev, isys->fwctx,
+				     IPU7_INSYS_OUTPUT_MSG_QUEUE);
 }
 
 static void ipu7_fw_isys_put_resp(struct ipu6_isys *isys)
@@ -219,7 +220,6 @@ ipu7_fw_isys_send_cmd(struct ipu6_isys *isys, const unsigned int stream_handle,
 		      size_t size, u16 send_type)
 {
 	struct ipu7_fw_com_context *ctx = isys->fwctx;
-	/*struct device *dev = &isys->adev->auxdev.dev;*/
 	struct ipu7_insys_send_queue_token *token;
 
 	if (send_type >= N_IPU7_INSYS_SEND_TYPE)
@@ -228,7 +228,8 @@ ipu7_fw_isys_send_cmd(struct ipu6_isys *isys, const unsigned int stream_handle,
 	if (cpu_mapped_buf)
 		clflush_cache_range(cpu_mapped_buf, size);
 
-	token = ipu7_fw_com_get_token(ctx, stream_handle +
+	token = ipu7_fw_com_get_token(&isys->adev->auxdev.dev, ctx,
+				      stream_handle +
 				      IPU7_INSYS_INPUT_MSG_QUEUE);
 	if (!token)
 		return -EBUSY;
-- 
2.53.0


  parent reply	other threads:[~2026-09-28 11:57 UTC|newest]

Thread overview: 13+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-28 11:56 [PATCH v1 0/4] media: ipu6: A few defensive fixes for ipu7 buttress, fw-com and mmu paths Manik Bajpai
2026-09-28 11:56 ` [PATCH v1 1/4] media: ipu6: Free boot config on queue memory alloc failure Manik Bajpai
2026-09-28 11:56 ` [PATCH v1 2/4] media: ipu6: Always run cleanup in ipu7 power on/off on timeout Manik Bajpai
2026-09-28 11:56 ` Manik Bajpai [this message]
2026-09-28 11:56 ` [PATCH v1 4/4] media: ipu6: Fix NULL deref in ipu6_mmu_iova_to_phys() Manik Bajpai
2026-09-28 12:08   ` Sakari Ailus
2026-09-29  8:31     ` [PATCH v2 0/4] media: ipu6: A few defensive fixes for ipu7 buttress, fw-com and mmu paths Manik Bajpai
2026-09-29  8:31       ` [PATCH v2 1/4] media: ipu6: Free boot config on queue memory alloc failure Manik Bajpai
2026-09-30  8:53         ` Sakari Ailus
2026-09-29  8:31       ` [PATCH v2 2/4] media: ipu6: Always run cleanup in ipu7 power on/off on timeout Manik Bajpai
2026-09-30 13:17         ` Antti Laakso
2026-09-29  8:31       ` [PATCH v2 3/4] media: ipu6: Validate fw-com queue indices before use Manik Bajpai
2026-09-29  8:31       ` [PATCH v2 4/4] media: ipu6: Fix NULL deref in ipu6_mmu_iova_to_phys() Manik Bajpai

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260928115646.77399-4-manik.bajpai@intel.com \
    --to=manik.bajpai@intel.com \
    --cc=antti.laakso@linux.intel.com \
    --cc=linux-media@vger.kernel.org \
    --cc=sakari.ailus@linux.intel.com \
    --cc=sarang.sapre@intel.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).