mirror of
https://github.com/OpenAMP/open-amp.git
synced 2026-10-02 18:23:21 +08:00
rpmsg: rpc: Validate client request lengths
The RPC client copies caller-provided parameters into a fixed-size stack buffer without checking whether the complete request fits. Oversized requests can therefore overwrite the caller's stack frame. Reject requests that exceed the remaining parameter capacity before copying them, validate nonempty parameter pointers, and document the public API limit. Signed-off-by: Ben Levinsky <ben.levinsky@amd.com> Assisted-by: Codex:GPT-5
This commit is contained in:
committed by
Arnaud Pouliquen
parent
49780d11b4
commit
f7c918bf07
@@ -176,7 +176,8 @@ int rpmsg_rpc_server_init(struct rpmsg_rpc_svr *rpcs, struct rpmsg_device *rdev,
|
||||
* data
|
||||
* @param rpc_id Function id
|
||||
* @param request_param Pointer to request buffer
|
||||
* @param req_param_size Length of the request data
|
||||
* @param req_param_size Length of the request data; must not exceed
|
||||
* MAX_BUF_LEN - MAX_FUNC_ID_LEN
|
||||
*
|
||||
* @return Length of the received response, negative value for failure.
|
||||
*/
|
||||
|
||||
@@ -53,12 +53,16 @@ int rpmsg_rpc_client_send(struct rpmsg_rpc_clt *rpc,
|
||||
{
|
||||
unsigned char tmpbuf[MAX_BUF_LEN];
|
||||
|
||||
if (!rpc)
|
||||
if (!rpc || (!request_param && req_param_size != 0))
|
||||
return -EINVAL;
|
||||
/* Reserve space for the function ID before copying parameters. */
|
||||
if (req_param_size > MAX_BUF_LEN - MAX_FUNC_ID_LEN)
|
||||
return -EINVAL;
|
||||
|
||||
/* to optimize with the zero copy API */
|
||||
memcpy(tmpbuf, &rpc_id, MAX_FUNC_ID_LEN);
|
||||
memcpy(&tmpbuf[MAX_FUNC_ID_LEN], request_param, req_param_size);
|
||||
if (req_param_size != 0)
|
||||
memcpy(&tmpbuf[MAX_FUNC_ID_LEN], request_param, req_param_size);
|
||||
return rpmsg_send(&rpc->ept, tmpbuf, MAX_FUNC_ID_LEN + req_param_size);
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user