rpmsg: rpc: Validate and initialize server requests

The RPC callback does not receive the request length, so it may
inspect bytes beyond a short message. Those bytes currently come from
an uninitialized stack buffer. A message shorter than the function ID
can also make the dispatch path read uninitialized data.

Reject messages that do not contain a complete function ID and
zero-initialize the request buffer so callbacks never consume stale
stack contents from bytes omitted by the remote peer.

Signed-off-by: Ben Levinsky <ben.levinsky@amd.com>
Assisted-by: Codex:GPT-5
This commit is contained in:
Ben Levinsky
2026-09-21 09:54:50 +02:00
committed by Arnaud Pouliquen
parent 80284e3ac0
commit 372048d49d
+2 -2
View File
@@ -51,14 +51,14 @@ static int rpmsg_endpoint_server_cb(struct rpmsg_endpoint *ept, void *data,
size_t len, size_t len,
uint32_t src, void *priv) uint32_t src, void *priv)
{ {
unsigned char buf[MAX_BUF_LEN]; unsigned char buf[MAX_BUF_LEN] = { 0 };
unsigned int id; unsigned int id;
const struct rpmsg_rpc_services *service; const struct rpmsg_rpc_services *service;
struct rpmsg_rpc_svr *rpcs; struct rpmsg_rpc_svr *rpcs;
(void)priv; (void)priv;
(void)src; (void)src;
if (len > MAX_BUF_LEN) if (len < MAX_FUNC_ID_LEN || len > MAX_BUF_LEN)
return -EINVAL; return -EINVAL;
rpcs = metal_container_of(ept, struct rpmsg_rpc_svr, ept); rpcs = metal_container_of(ept, struct rpmsg_rpc_svr, ept);