[PATCH v2 01/10] gpu: nova-core: fsp: limit FSP receive message allocation size

Eliot Courtney <[email protected]>
Newsgroups dev.linux.lists.nova-gpu,org.freedesktop.lists.dri-devel,org.kernel.vger.linux-kernel,org.kernel.vger.rust-for-linux
Message-ID <[email protected]>
Currently, the FSP receive message code will try to allocate whatever
was sent without checking it at all. But the actual size allowed is
limited to 1024 anyway, so reject any messages over that size as bogus.

Signed-off-by: Eliot Courtney <[email protected]>
---
 drivers/gpu/nova-core/falcon/fsp.rs | 8 ++++++++
 1 file changed, 8 insertions(+)

diff --git a/drivers/gpu/nova-core/falcon/fsp.rs b/drivers/gpu/nova-core/falcon/fsp.rs
index 53b1079843ae..7cd9604d1f4d 100644
--- a/drivers/gpu/nova-core/falcon/fsp.rs
+++ b/drivers/gpu/nova-core/falcon/fsp.rs
@@ -34,6 +34,9 @@
 /// FSP message timeout in milliseconds.
 const FSP_MSG_TIMEOUT_MS: i64 = 2000;
 
+/// Size of the FSP EMEM channel 0 that we can use.
+const FSP_EMEM_CHANNEL_0_SIZE: usize = 1024;
+
 /// Type specifying the `Fsp` falcon engine. Cannot be instantiated.
 pub(crate) struct Fsp(());
 
@@ -159,6 +162,11 @@ pub(crate) fn recv_msg(&mut self) -> Result<KVec<u8>> {
         )
         .map(num::u32_as_usize)?;
 
+        // Don't blindly allocate more than the maximum we expect from FSP.
+        if msg_size > FSP_EMEM_CHANNEL_0_SIZE {
+            return Err(EMSGSIZE);
+        }
+
         let mut buffer = KVec::<u8>::new();
         buffer.resize(msg_size, 0, GFP_KERNEL)?;
 

-- 
2.54.0
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.