From: Manik Bajpai <manik.bajpai@intel.com>
To: sakari.ailus@linux.intel.com
Cc: linux-media@vger.kernel.org, antti.laakso@linux.intel.com,
sarang.sapre@intel.com
Subject: [PATCH v2 3/4] media: ipu6: Validate fw-com queue indices before use
Date: Tue, 29 Sep 2026 14:01:29 +0530 [thread overview]
Message-ID: <20260929083130.88381-4-manik.bajpai@intel.com> (raw)
In-Reply-To: <20260929083130.88381-1-manik.bajpai@intel.com>
ipu7_fw_com_get_token() reads read_index/write_index directly from
firmware-shared memory and uses them unchecked in pointer arithmetic
to compute a token address:
token = queue_params->token_array_mem +
read_index * queue_params->token_size_in_bytes;
If firmware ever writes a corrupted or out-of-range index into that
shared memory, this computes a pointer outside token_array_mem.
Reject indices that are not smaller than max_capacity before doing any
pointer arithmetic.
Assisted-by: Claude:claude-sonnet-5
Signed-off-by: Manik Bajpai <manik.bajpai@intel.com>
---
drivers/media/pci/intel/ipu6/ipu7-fw-com.c | 14 +++++++++++++-
drivers/media/pci/intel/ipu6/ipu7-fw-com.h | 5 ++++-
drivers/media/pci/intel/ipu6/ipu7-fw-isys.c | 7 ++++---
3 files changed, 21 insertions(+), 5 deletions(-)
diff --git a/drivers/media/pci/intel/ipu6/ipu7-fw-com.c b/drivers/media/pci/intel/ipu6/ipu7-fw-com.c
index 7dd1e683aa92..3d0a8fcac15e 100644
--- a/drivers/media/pci/intel/ipu6/ipu7-fw-com.c
+++ b/drivers/media/pci/intel/ipu6/ipu7-fw-com.c
@@ -3,6 +3,7 @@
* Copyright (C) 2026 Intel Corporation
*/
+#include <linux/device.h>
#include <linux/io.h>
#include "ipu7-fw-com.h"
@@ -13,7 +14,8 @@ static void __iomem *ipu7_fw_com_get_indices(struct ipu7_fw_com_context *ctx,
return ctx->queue_indices + (q * sizeof(struct ipu7_fw_com_queue_indices));
}
-void *ipu7_fw_com_get_token(struct ipu7_fw_com_context *ctx, int q)
+void *ipu7_fw_com_get_token(struct device *dev, struct ipu7_fw_com_context *ctx,
+ int q)
{
struct ipu7_fw_com_queue_config *queue_params = &ctx->queue_configs[q];
void __iomem *queue_indices = ipu7_fw_com_get_indices(ctx, q);
@@ -25,6 +27,16 @@ void *ipu7_fw_com_get_token(struct ipu7_fw_com_context *ctx, int q)
read_index));
void *token = NULL;
+ /* Indices come from firmware-shared memory; don't trust them blindly. */
+ if (read_index >= queue_params->max_capacity ||
+ write_index >= queue_params->max_capacity) {
+ dev_err_once(dev,
+ "ipu7-fw-com: bad queue %d index (r=%u w=%u cap=%u)\n",
+ q, read_index, write_index,
+ queue_params->max_capacity);
+ return NULL;
+ }
+
if (q < ctx->num_output_queues) {
/* Output queue */
bool empty = (write_index == read_index);
diff --git a/drivers/media/pci/intel/ipu6/ipu7-fw-com.h b/drivers/media/pci/intel/ipu6/ipu7-fw-com.h
index 097eaab99547..2921d097e580 100644
--- a/drivers/media/pci/intel/ipu6/ipu7-fw-com.h
+++ b/drivers/media/pci/intel/ipu6/ipu7-fw-com.h
@@ -6,6 +6,8 @@
#include <linux/types.h>
+struct device;
+
struct ipu7_fw_com_queue_config {
void *token_array_mem;
u32 queue_size;
@@ -46,7 +48,8 @@ struct ipu7_fw_com_queue_indices {
};
void ipu7_fw_com_put_token(struct ipu7_fw_com_context *ctx, int q);
-void *ipu7_fw_com_get_token(struct ipu7_fw_com_context *ctx, int q);
+void *ipu7_fw_com_get_token(struct device *dev, struct ipu7_fw_com_context *ctx,
+ int q);
struct ipu7_fw_com_queue_params_config *
ipu7_fw_com_get_queue_config(struct ipu7_fw_com_config *config);
diff --git a/drivers/media/pci/intel/ipu6/ipu7-fw-isys.c b/drivers/media/pci/intel/ipu6/ipu7-fw-isys.c
index e74e2b2566aa..60e29e2d63a7 100644
--- a/drivers/media/pci/intel/ipu6/ipu7-fw-isys.c
+++ b/drivers/media/pci/intel/ipu6/ipu7-fw-isys.c
@@ -147,7 +147,8 @@ static int ipu7_fw_isys_init(struct ipu6_isys *isys, unsigned int num_streams)
static struct ipu7_insys_resp *ipu7_fw_isys_get_resp(struct ipu6_isys *isys)
{
- return ipu7_fw_com_get_token(isys->fwctx, IPU7_INSYS_OUTPUT_MSG_QUEUE);
+ return ipu7_fw_com_get_token(&isys->adev->auxdev.dev, isys->fwctx,
+ IPU7_INSYS_OUTPUT_MSG_QUEUE);
}
static void ipu7_fw_isys_put_resp(struct ipu6_isys *isys)
@@ -219,7 +220,6 @@ ipu7_fw_isys_send_cmd(struct ipu6_isys *isys, const unsigned int stream_handle,
size_t size, u16 send_type)
{
struct ipu7_fw_com_context *ctx = isys->fwctx;
- /*struct device *dev = &isys->adev->auxdev.dev;*/
struct ipu7_insys_send_queue_token *token;
if (send_type >= N_IPU7_INSYS_SEND_TYPE)
@@ -228,7 +228,8 @@ ipu7_fw_isys_send_cmd(struct ipu6_isys *isys, const unsigned int stream_handle,
if (cpu_mapped_buf)
clflush_cache_range(cpu_mapped_buf, size);
- token = ipu7_fw_com_get_token(ctx, stream_handle +
+ token = ipu7_fw_com_get_token(&isys->adev->auxdev.dev, ctx,
+ stream_handle +
IPU7_INSYS_INPUT_MSG_QUEUE);
if (!token)
return -EBUSY;
--
2.53.0
next prev parent reply other threads:[~2026-09-29 8:31 UTC|newest]
Thread overview: 13+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-28 11:56 [PATCH v1 0/4] media: ipu6: A few defensive fixes for ipu7 buttress, fw-com and mmu paths Manik Bajpai
2026-09-28 11:56 ` [PATCH v1 1/4] media: ipu6: Free boot config on queue memory alloc failure Manik Bajpai
2026-09-28 11:56 ` [PATCH v1 2/4] media: ipu6: Always run cleanup in ipu7 power on/off on timeout Manik Bajpai
2026-09-28 11:56 ` [PATCH v1 3/4] media: ipu6: Validate fw-com queue indices before use Manik Bajpai
2026-09-28 11:56 ` [PATCH v1 4/4] media: ipu6: Fix NULL deref in ipu6_mmu_iova_to_phys() Manik Bajpai
2026-09-28 12:08 ` Sakari Ailus
2026-09-29 8:31 ` [PATCH v2 0/4] media: ipu6: A few defensive fixes for ipu7 buttress, fw-com and mmu paths Manik Bajpai
2026-09-29 8:31 ` [PATCH v2 1/4] media: ipu6: Free boot config on queue memory alloc failure Manik Bajpai
2026-09-30 8:53 ` Sakari Ailus
2026-09-29 8:31 ` [PATCH v2 2/4] media: ipu6: Always run cleanup in ipu7 power on/off on timeout Manik Bajpai
2026-09-30 13:17 ` Antti Laakso
2026-09-29 8:31 ` Manik Bajpai [this message]
2026-09-29 8:31 ` [PATCH v2 4/4] media: ipu6: Fix NULL deref in ipu6_mmu_iova_to_phys() Manik Bajpai
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260929083130.88381-4-manik.bajpai@intel.com \
--to=manik.bajpai@intel.com \
--cc=antti.laakso@linux.intel.com \
--cc=linux-media@vger.kernel.org \
--cc=sakari.ailus@linux.intel.com \
--cc=sarang.sapre@intel.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox