Received: by 2002:a05:6a10:206:0:0:0:0 with SMTP id 6csp3729079pxj; Tue, 1 Jun 2021 11:48:08 -0700 (PDT) X-Google-Smtp-Source: ABdhPJzxs3Pyhzj44zF2YEkFb7vIFJGJg3z5FjqEr+AU2VXcreia4HnUlLXNE1N/YnbRMI1NgPWj X-Received: by 2002:a17:906:48c8:: with SMTP id d8mr13664891ejt.176.1622573288200; Tue, 01 Jun 2021 11:48:08 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1622573288; cv=none; d=google.com; s=arc-20160816; b=r4tUTr6PNuzJcH85xwRJZ3wPaM1pA+Vj4PQujBDuiqlMWdBVRdODM+4a+kgPJgqRih fFpzKLfj9lm6D7t7I97x6CfHuIWhVP74CcV7G4oxypQT8NxKTuc+Zef2XU5G/76pV0j2 xNipYD7sqv4XBHimBASQF4S2HVNwzGAVEPiD/ftmmPKlTp95jxPi4cb0DL3fpZUQUm6Y lkD4dN3yOmRfJDc8n+i4SVYVnC77JA9O1pq215yaxRqRSHR6zV1ZeFUiBgsrZ0QYNiud e1IoE+ev6Ggjozo/d/7Uf7Urw6SToBvI8eQQ4OKLbzwuZ5hzu2QfL2iR9uQAtC+uwLSS O6XA== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:content-disposition:mime-version:message-id :subject:cc:to:from:date:dkim-signature; bh=W3WVjQrcniuP4/C02GWDTzOhHF2eHuoPp2a2pNgE1uk=; b=LssRMZorQQioMmWQzN+Hm8OTPVtkC3H+RhRU+PYpML5U80AdTmnFqhAMCOJtdvYnxu PmnnMYdIrS+0zrRIQrHRisCVQ0VXNREGx6JY8OSj+qZ24nZq+hEbcQYiAUR03iyea5uh mN1DnawgpuLMdItpCzTGUpJSVvns33GVvnrAf1BW6cKflDmMeoJk8pUiteXiUtd7/DwY FyrnTfgVkxM7VyA/HDXVi7UrSB9QrJJBVahW/8loYpokmfPLhQd+S9z+9DVV4b2GNhHc X9Vszj58ozq4htZ0Ts0YUKyUdMDfhcmz/Z0Qpw96+1kq4/0yd2ntDYqC/mZd+/ey5EXW MOQg== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@kernel.org header.s=k20201202 header.b=GX1Ri7Es; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=kernel.org Return-Path: Received: from vger.kernel.org (vger.kernel.org. [23.128.96.18]) by mx.google.com with ESMTP id f8si17091268edk.566.2021.06.01.11.47.45; Tue, 01 Jun 2021 11:48:08 -0700 (PDT) Received-SPF: pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) client-ip=23.128.96.18; Authentication-Results: mx.google.com; dkim=pass header.i=@kernel.org header.s=k20201202 header.b=GX1Ri7Es; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=kernel.org Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S234671AbhFASqw (ORCPT + 99 others); Tue, 1 Jun 2021 14:46:52 -0400 Received: from mail.kernel.org ([198.145.29.99]:44298 "EHLO mail.kernel.org" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S233970AbhFASqv (ORCPT ); Tue, 1 Jun 2021 14:46:51 -0400 Received: by mail.kernel.org (Postfix) with ESMTPSA id 55E4D60C3F; Tue, 1 Jun 2021 18:45:09 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=k20201202; t=1622573110; bh=/0v0BbCRmqQoHmuTHyO1LQsRp/5gRVDEfk7TG+cgMAU=; h=Date:From:To:Cc:Subject:From; b=GX1Ri7Es0XLMxlp5yqIYrNgrJydS9rfYAJya7Ivfel5l2otEsvwhZQBhRqmW6DMQF l1GaXoIeDqMwprPi65R5uapr7Qw1bva44ihRQULSjtPHPmetZvNBgqxFJzW7Z1Qq62 1syPGNkSqEjSsiAAXd0lVOql1jLrtkbZ7QG4KP786YrP5I3x6APRowuGPLM9YKk7KO A3JqXV/AnfwEZPVBHwkij6gApi6bE511mkhPnrrH3TwIlkBVTScPsaIJaCRX1e9g2F t3RRm4rvoEWvOTn+UMaZUqg6wStJ8Xz/vKZieFzZVlUysyoCqw2PwfmFguje4x94AC zEAsyx/PrpJpA== Date: Tue, 1 Jun 2021 13:46:16 -0500 From: "Gustavo A. R. Silva" To: Stanimir Varbanov , Andy Gross , Bjorn Andersson , Mauro Carvalho Chehab Cc: linux-media@vger.kernel.org, linux-arm-msm@vger.kernel.org, linux-kernel@vger.kernel.org, "Gustavo A. R. Silva" , linux-hardening@vger.kernel.org Subject: [PATCH][venus-for-next-v5.14] media: venus: hfi_cmds: Fix packet size calculation Message-ID: <20210601184616.GA23488@embeddedor> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org Now that a one-element array was replaced with a flexible-array member in struct hfi_sys_set_property_pkt, use the struct_size() helper to correctly calculate the packet size. Fixes: 701e10b3fd9f ("media: venus: hfi_cmds.h: Replace one-element array with flexible-array member") Signed-off-by: Gustavo A. R. Silva --- BTW... it seems that a similar problem is present in https://lore.kernel.org/linux-hardening/20210211001044.GA69612@embeddedor/ and that is what is causing the regression. I will send v2 of that patch, shortly. Thanks. drivers/media/platform/qcom/venus/hfi_cmds.c | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/drivers/media/platform/qcom/venus/hfi_cmds.c b/drivers/media/platform/qcom/venus/hfi_cmds.c index 11a8347e5f5c..c86279e5d6e8 100644 --- a/drivers/media/platform/qcom/venus/hfi_cmds.c +++ b/drivers/media/platform/qcom/venus/hfi_cmds.c @@ -27,7 +27,7 @@ void pkt_sys_idle_indicator(struct hfi_sys_set_property_pkt *pkt, u32 enable) { struct hfi_enable *hfi = (struct hfi_enable *)&pkt->data[1]; - pkt->hdr.size = sizeof(*pkt) + sizeof(*hfi) + sizeof(u32); + pkt->hdr.size = struct_size(pkt, data, 2) + sizeof(*hfi); pkt->hdr.pkt_type = HFI_CMD_SYS_SET_PROPERTY; pkt->num_properties = 1; pkt->data[0] = HFI_PROPERTY_SYS_IDLE_INDICATOR; @@ -39,7 +39,7 @@ void pkt_sys_debug_config(struct hfi_sys_set_property_pkt *pkt, u32 mode, { struct hfi_debug_config *hfi; - pkt->hdr.size = sizeof(*pkt) + sizeof(*hfi) + sizeof(u32); + pkt->hdr.size = struct_size(pkt, data, 2) + sizeof(*hfi); pkt->hdr.pkt_type = HFI_CMD_SYS_SET_PROPERTY; pkt->num_properties = 1; pkt->data[0] = HFI_PROPERTY_SYS_DEBUG_CONFIG; @@ -50,7 +50,7 @@ void pkt_sys_debug_config(struct hfi_sys_set_property_pkt *pkt, u32 mode, void pkt_sys_coverage_config(struct hfi_sys_set_property_pkt *pkt, u32 mode) { - pkt->hdr.size = sizeof(*pkt) + sizeof(u32); + pkt->hdr.size = struct_size(pkt, data, 2); pkt->hdr.pkt_type = HFI_CMD_SYS_SET_PROPERTY; pkt->num_properties = 1; pkt->data[0] = HFI_PROPERTY_SYS_CONFIG_COVERAGE; @@ -116,7 +116,7 @@ void pkt_sys_power_control(struct hfi_sys_set_property_pkt *pkt, u32 enable) { struct hfi_enable *hfi = (struct hfi_enable *)&pkt->data[1]; - pkt->hdr.size = sizeof(*pkt) + sizeof(*hfi) + sizeof(u32); + pkt->hdr.size = struct_size(pkt, data, 2) + sizeof(*hfi); pkt->hdr.pkt_type = HFI_CMD_SYS_SET_PROPERTY; pkt->num_properties = 1; pkt->data[0] = HFI_PROPERTY_SYS_CODEC_POWER_PLANE_CTRL; -- 2.27.0