aboutsummaryrefslogtreecommitdiffci
path: root/patches/remoteproc/0002-soc-qcom-smp2p-Ensure-there-is-enough-space-for-outb.patch
diff refs
from: back
to: back
| flip
diff options
context:
space:
mode:
authorGravatar Saya Andy <saya.andy@posteo.com> 2026-09-18 21:45:43 +0700
committerGravatar Saya Andy <saya.andy@posteo.com> 2026-09-18 21:45:43 +0700
commit1f2b96ab1a13be88c57c78be08168c0bb0080088 (patch)
treecb830075f52e08698d63f0e5c4e1359a063a62b8 /patches/remoteproc/0002-soc-qcom-smp2p-Ensure-there-is-enough-space-for-outb.patch
parentee8c44555b0c3d61bf1998ddf3a5823db04ae68f (diff)
downloadkernel-surface-1f2b96ab1a13be88c57c78be08168c0bb0080088.tar.gz
kernel-surface-1f2b96ab1a13be88c57c78be08168c0bb0080088.zip
fix: adapt patches for some 7.2.6 kernel updates to remoteproc and usbfedora-45-kernel-7.2.6-patchset-1
Diffstat (limited to 'patches/remoteproc/0002-soc-qcom-smp2p-Ensure-there-is-enough-space-for-outb.patch')
-rw-r--r--patches/remoteproc/0002-soc-qcom-smp2p-Ensure-there-is-enough-space-for-outb.patch25
1 files changed, 25 insertions, 0 deletions
diff --git a/patches/remoteproc/0002-soc-qcom-smp2p-Ensure-there-is-enough-space-for-outb.patch b/patches/remoteproc/0002-soc-qcom-smp2p-Ensure-there-is-enough-space-for-outb.patch
new file mode 100644
index 0000000..49e7de3
--- /dev/null
+++ b/patches/remoteproc/0002-soc-qcom-smp2p-Ensure-there-is-enough-space-for-outb.patch
@@ -0,0 +1,25 @@
+The SMP2P SMEM item has limited space for outbound entries, but the DT can
+specify any number of entries. Add a check to prevent out of bounds writes
+when an invalid DT specifies more entries than expected.
+
+Fixes: 50e99641413e ("soc: qcom: smp2p: Qualcomm Shared Memory Point to Point")
+Signed-off-by: Stephan Gerhold <stephan.gerhold@linaro.org>
+Signed-off-by: Abel Vesa <abel.vesa@oss.qualcomm.com>
+---
+ drivers/soc/qcom/smp2p.c | 3 +++
+ 1 file changed, 3 insertions(+)
+
+diff --git a/drivers/soc/qcom/smp2p.c b/drivers/soc/qcom/smp2p.c
+index 1ea4d35c6..876648d0b 100644
+--- a/drivers/soc/qcom/smp2p.c
++++ b/drivers/soc/qcom/smp2p.c
+@@ -441,6 +441,9 @@ static int qcom_smp2p_outbound_entry(struct qcom_smp2p *smp2p,
+ struct smp2p_smem_item *out = smp2p->out;
+ char buf[SMP2P_MAX_ENTRY_NAME] = {};
+
++ if (out->valid_entries == out->total_entries)
++ return -ENOMEM;
++
+ /* Allocate an entry from the smem item */
+ strscpy(buf, entry->name, SMP2P_MAX_ENTRY_NAME);
+ memcpy(out->entries[out->valid_entries].name, buf, SMP2P_MAX_ENTRY_NAME);