From: Peter Ujfalusi <peter.ujfalusi@linux.intel.com>
To: vkoul@kernel.org, perex@perex.cz, tiwai@suse.com,
lgirdwood@gmail.com, broonie@kernel.org,
srinivas.kandagatla@oss.qualcomm.com
Cc: linux-sound@vger.kernel.org, kai.vehmanen@linux.intel.com,
yung-chuan.liao@linux.intel.com, pierre-louis.bossart@linux.dev,
daniel.baluta@nxp.com
Subject: [PATCH v5 23/28] ASoC: SOF: Check that the audio buffer fits into the page table
Date: Wed, 7 Oct 2026 11:49:50 +0300 [thread overview]
Message-ID: <20261007084955.1256-24-peter.ujfalusi@linux.intel.com> (raw)
In-Reply-To: <20261007084955.1256-1-peter.ujfalusi@linux.intel.com>
The page table describing the audio buffer for the firmware is a single
PAGE_SIZE allocation, but snd_sof_create_page_table() writes the
compressed PFNs into it without checking that they fit.
The PFNs are stored in 2.5 bytes each and the last one is written with a
32 bit access, so with 4K pages the table can hold 1638 PFNs, which is a
buffer of 6.4MB. A larger buffer corrupts memory past the end of the
page table.
The PCM path is not affected as the maximum buffer size is specified by
the topology, but the compressed streams can ask for larger buffers.
Pass the page table buffer to snd_sof_create_page_table() instead of only
its address and verify that the buffer can be described by it.
Signed-off-by: Peter Ujfalusi <peter.ujfalusi@linux.intel.com>
---
sound/soc/sof/ipc3-dtrace.c | 2 +-
sound/soc/sof/pcm.c | 2 +-
sound/soc/sof/sof-audio.c | 2 +-
sound/soc/sof/sof-utils.c | 12 ++++++++++--
sound/soc/sof/sof-utils.h | 11 ++++++++++-
5 files changed, 23 insertions(+), 6 deletions(-)
diff --git a/sound/soc/sof/ipc3-dtrace.c b/sound/soc/sof/ipc3-dtrace.c
index 22053357731a..e8c998c09dc3 100644
--- a/sound/soc/sof/ipc3-dtrace.c
+++ b/sound/soc/sof/ipc3-dtrace.c
@@ -534,7 +534,7 @@ static int ipc3_dtrace_init(struct snd_sof_dev *sdev)
/* create compressed page table for audio firmware */
ret = snd_sof_create_page_table(sdev->dev, &priv->dmatb,
- priv->dmatp.area, priv->dmatb.bytes);
+ &priv->dmatp, priv->dmatb.bytes);
if (ret < 0)
goto table_err;
diff --git a/sound/soc/sof/pcm.c b/sound/soc/sof/pcm.c
index 42738f12fa33..b4305dc43d61 100644
--- a/sound/soc/sof/pcm.c
+++ b/sound/soc/sof/pcm.c
@@ -194,7 +194,7 @@ static int sof_pcm_hw_params(struct snd_soc_component *component,
struct snd_dma_buffer *dmab = snd_pcm_get_dma_buf(substream);
ret = snd_sof_create_page_table(component->dev, dmab,
- spcm->stream[substream->stream].page_table.area,
+ &spcm->stream[substream->stream].page_table,
runtime->dma_bytes);
if (ret < 0)
return ret;
diff --git a/sound/soc/sof/sof-audio.c b/sound/soc/sof/sof-audio.c
index 9f9f18b3c935..8cbeca471542 100644
--- a/sound/soc/sof/sof-audio.c
+++ b/sound/soc/sof/sof-audio.c
@@ -1132,6 +1132,6 @@ int snd_sof_compr_create_page_table(struct snd_soc_component *component,
return -EINVAL;
return snd_sof_create_page_table(component->dev, dmab,
- spcm->stream[dir].page_table.area, size);
+ &spcm->stream[dir].page_table, size);
}
#endif
diff --git a/sound/soc/sof/sof-utils.c b/sound/soc/sof/sof-utils.c
index f70089317b8c..59dc10196958 100644
--- a/sound/soc/sof/sof-utils.c
+++ b/sound/soc/sof/sof-utils.c
@@ -24,12 +24,20 @@
int snd_sof_create_page_table(struct device *dev,
struct snd_dma_buffer *dmab,
- unsigned char *page_table, size_t size)
+ struct snd_dma_buffer *page_table, size_t size)
{
int i, pages;
pages = snd_sgbuf_aligned_pages(size);
+ if (pages < 1 || page_table->bytes < sizeof(u32) ||
+ pages > SOF_PAGE_TABLE_MAX_PFNS(page_table->bytes)) {
+ dev_err(dev,
+ "Can not store %d pages in a %zu bytes page table\n",
+ pages, page_table->bytes);
+ return -EINVAL;
+ }
+
dev_dbg(dev, "generating page table for %p size 0x%zx pages %d\n",
dmab->area, size, pages);
@@ -45,7 +53,7 @@ int snd_sof_create_page_table(struct device *dev,
u32 pfn = snd_sgbuf_get_addr(dmab, i * PAGE_SIZE) >> PAGE_SHIFT;
u8 *pg_table;
- pg_table = (u8 *)(page_table + idx);
+ pg_table = (u8 *)(page_table->area + idx);
/*
* pagetable compression:
diff --git a/sound/soc/sof/sof-utils.h b/sound/soc/sof/sof-utils.h
index 9ac6de9a6d6a..58e5822a63f0 100644
--- a/sound/soc/sof/sof-utils.h
+++ b/sound/soc/sof/sof-utils.h
@@ -12,8 +12,17 @@
struct snd_dma_buffer;
struct device;
+/*
+ * Number of PFNs which can be stored in a page table of @bytes size.
+ * The PFNs are compressed to 2.5 bytes each but they are written with 32 bit
+ * accesses, therefore the last PFN can reach up to 3 bytes past the space it
+ * needs for itself.
+ */
+#define SOF_PAGE_TABLE_MAX_PFNS(bytes) \
+ (((((bytes) - sizeof(u32)) << 1) + 1) / 5 + 1)
+
int snd_sof_create_page_table(struct device *dev,
struct snd_dma_buffer *dmab,
- unsigned char *page_table, size_t size);
+ struct snd_dma_buffer *page_table, size_t size);
#endif
--
2.56.0
next prev parent reply other threads:[~2026-10-07 8:50 UTC|newest]
Thread overview: 30+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-07 8:49 [PATCH v5 00/28] ALSA compress / ASoC compress / SOF: Compressed audio support with IPC4 Peter Ujfalusi
2026-10-07 8:49 ` [PATCH v5 01/28] ALSA: compress: pin card module while stream is open Peter Ujfalusi
2026-10-07 8:49 ` [PATCH v5 02/28] ALSA: compress: register the open file with the card Peter Ujfalusi
2026-10-07 8:49 ` [PATCH v5 03/28] ALSA: compress: stop active streams on disconnect Peter Ujfalusi
2026-10-07 8:49 ` [PATCH v5 04/28] ALSA: compress: Set the draining state before the drain trigger Peter Ujfalusi
2026-10-07 8:49 ` [PATCH v5 05/28] ASoC: soc-compress: Provide a runtime for the compressed FE substream Peter Ujfalusi
2026-10-07 8:49 ` [PATCH v5 06/28] ASoC: soc-compress: Implement trigger FE-BE sequencing as with normal PCMs Peter Ujfalusi
2026-10-07 8:49 ` [PATCH v5 07/28] ASoC: soc-compress: Stop running dpcm on free Peter Ujfalusi
2026-10-07 8:49 ` [PATCH v5 08/28] ASoC: SOF: compress: Move the IPC agnostic helpers to sof-audio.c Peter Ujfalusi
2026-10-07 8:49 ` [PATCH v5 09/28] ASoC: SOF: compress: Rename compress ops with ipc3 prefix Peter Ujfalusi
2026-10-07 8:49 ` [PATCH v5 10/28] ASoC: SOF: sof-audio: Fix the pipeline_list population Peter Ujfalusi
2026-10-07 8:49 ` [PATCH v5 11/28] ASoC: SOF: ipc4-pcm: Serialize the PCM free with the pipeline triggers Peter Ujfalusi
2026-10-07 8:49 ` [PATCH v5 12/28] ASoC: SOF: sof-audio: do not dereference swidget->spipe unconditionally on free Peter Ujfalusi
2026-10-07 8:49 ` [PATCH v5 13/28] ASoC: SOF: sof-audio: Expose a couple of functions Peter Ujfalusi
2026-10-07 8:49 ` [PATCH v5 14/28] ASoC: SOF: pcm: Modify the signature of a couple of PCM IPC ops Peter Ujfalusi
2026-10-07 8:49 ` [PATCH v5 15/28] ASoC: SOF: intel: hda-stream: Clear the current position when releasing stream Peter Ujfalusi
2026-10-07 8:49 ` [PATCH v5 16/28] ASoC: SOF: ipc4: Add definition of module data in init_ext object type Peter Ujfalusi
2026-10-07 8:49 ` [PATCH v5 17/28] ASoC: SOF: ipc4-topology: Support init_ext_module_data for process modules Peter Ujfalusi
2026-10-07 8:49 ` [PATCH v5 18/28] ASoC: SOF: ipc4-pcm: Make the timestamp info usable outside of ipc4-pcm.c Peter Ujfalusi
2026-10-07 8:49 ` [PATCH v5 19/28] ASoC: SOF: ipc4/ipc4-loader: Add SOF_INFO and CODEC_INFO to fw_config_params Peter Ujfalusi
2026-10-07 8:49 ` [PATCH v5 20/28] ASoC: SOF: ipc4-pcm: Handle COMPR DRAIN triggers as EOS pipeline state Peter Ujfalusi
2026-10-07 8:49 ` [PATCH v5 21/28] ASoC: SOF: ipc4-topology: Set FAST_MODE for host copier in compr mode Peter Ujfalusi
2026-10-07 8:49 ` [PATCH v5 22/28] ASoC: SOF: ops: Add new platform-specific ops for compress Peter Ujfalusi
2026-10-07 8:49 ` Peter Ujfalusi [this message]
2026-10-07 8:49 ` [PATCH v5 24/28] ASoC: SOF: Add support for IPC4 compressed Peter Ujfalusi
2026-10-07 8:49 ` [PATCH v5 25/28] ASoC: SOF: ipc4: Handle compressed drain done notification from firmware Peter Ujfalusi
2026-10-07 8:49 ` [PATCH v5 26/28] ASoC: SOF: Intel: Kconfig: Remove redundant IPC version selects Peter Ujfalusi
2026-10-07 8:49 ` [PATCH v5 27/28] ASoC: SOF: Intel: Kconfig: Select compress support for TGL+ platforms Peter Ujfalusi
2026-10-07 8:49 ` [PATCH v5 28/28] ASoC: SOF: topology: Add support for decoder and encoder widgets Peter Ujfalusi
2026-10-07 11:17 ` [PATCH v5 00/28] ALSA compress / ASoC compress / SOF: Compressed audio support with IPC4 Mark Brown
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261007084955.1256-24-peter.ujfalusi@linux.intel.com \
--to=peter.ujfalusi@linux.intel.com \
--cc=broonie@kernel.org \
--cc=daniel.baluta@nxp.com \
--cc=kai.vehmanen@linux.intel.com \
--cc=lgirdwood@gmail.com \
--cc=linux-sound@vger.kernel.org \
--cc=perex@perex.cz \
--cc=pierre-louis.bossart@linux.dev \
--cc=srinivas.kandagatla@oss.qualcomm.com \
--cc=tiwai@suse.com \
--cc=vkoul@kernel.org \
--cc=yung-chuan.liao@linux.intel.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox