rpvdev->notify is called from four places in this file: virtqueue
notify, set_status, set_features, and write_config. None guarded
against notify being NULL, valid when no mailbox is configured, and
none checked the returned status. Add a shared rpvdev_notify()
helper used at all four sites: skip when notify is NULL, log a
warning via metal_log on nonzero return. Exported notify signature
is unchanged, per discussion in issue #343.
Assisted-by: Claude <noreply@anthropic.com>
Signed-off-by: Atul Akella <atul.akella@gmail.com>
Resource offsets from a copied firmware table are dereferenced without
bounds checks when no I/O region is present. Handlers can then access
memory beyond the table through a VDEV's flexible vring array.
Reject a NULL table, validate offset-array arithmetic, and require
every entry to remain inside the table before dispatch. Check fixed
sizes, VDEV vrings and config data, and vendor lengths using
overflow-safe subtraction.
Signed-off-by: Ben Levinsky <ben.levinsky@amd.com>
Assisted-by: Codex:GPT-5
The remote resource table controls the vring alignment, which is used
for pointer rounding without validation. vring_init() rounds the used
ring address with a ~(align - 1) mask, so a zero alignment leaves a
NULL used ring that is dereferenced later.
Reject a zero alignment before calculating the vring size and before
storing the vring metadata taken from the resource table.
Signed-off-by: Ben Levinsky <ben.levinsky@amd.com>
Assisted-by: Codex:GPT-5
_read() converts the peer-provided unsigned data length to a signed
integer and bounds it only against the caller's buffer size. Large
values can bypass that comparison or make memcpy() read beyond the
fixed response buffer.
Reject nonpositive destination sizes, retain the peer length as an
unsigned value, and clamp it to both the response payload capacity and
the caller's buffer before copying.
Signed-off-by: Ben Levinsky <ben.levinsky@amd.com>
Assisted-by: Codex:GPT-5
The RPC client copies caller-provided parameters into a fixed-size
stack buffer without checking whether the complete request fits.
Oversized requests can therefore overwrite the caller's stack frame.
Reject requests that exceed the remaining parameter capacity before
copying them, validate nonempty parameter pointers, and document the
public API limit.
Signed-off-by: Ben Levinsky <ben.levinsky@amd.com>
Assisted-by: Codex:GPT-5
The RPC client reads the reply ID and status without checking that the
remote message contains the fixed reply header. It also passes the
total message length to callbacks that receive a parameters pointer,
making the reported length include the header bytes.
Reject replies shorter than the fixed header and pass callbacks only
the number of bytes that follow it.
Signed-off-by: Ben Levinsky <ben.levinsky@amd.com>
Assisted-by: Codex:GPT-5
_write() copies a caller-controlled length into a fixed-size stack
buffer without checking that the RPC header and payload fit. Negative
lengths also become large unsigned memcpy() sizes, and the stdout NUL
terminator is written one byte beyond its intended position.
Reject invalid lengths before constructing the request. Include the
optional terminator in the capacity check and place the terminator
immediately after the copied payload.
Signed-off-by: Ben Levinsky <ben.levinsky@amd.com>
Assisted-by: Codex:GPT-5
The RPC callback does not receive the request length, so it may
inspect bytes beyond a short message. Those bytes currently come from
an uninitialized stack buffer. A message shorter than the function ID
can also make the dispatch path read uninitialized data.
Reject messages that do not contain a complete function ID and
zero-initialize the request buffer so callbacks never consume stale
stack contents from bytes omitted by the remote peer.
Signed-off-by: Ben Levinsky <ben.levinsky@amd.com>
Assisted-by: Codex:GPT-5
An application at device side might need to know if a buffer has been
marked as device-writable by the driver.
An example is the virtio SPI protocol, in which the direction of an
half-duplex communication can be determined by the device only by
checking if the buffer containing the data is writable or not.
Add a simple helper to test if a buffer is device-writable, that is,
if the VRING_DESC_F_WRITE flag is present on it.
Signed-off-by: Francesco Valla <francesco@valla.it>
Replace the non-seekable loader offset comparison that used offset + len
with an overflow-safe equivalent.
This preserves existing behavior for normal ranges while avoiding a
wraparound case when deciding whether required image data is contiguous
with the current chunk.
Signed-off-by: Ben Levinsky <ben.levinsky@amd.com>
Make ELF section-name lookup validate sh_name before reading from the
loaded section string table.
Skip malformed section names whose sh_name offset is outside the table
or whose string is not NUL-terminated within the remaining table bytes.
Use bounded comparison for valid candidates so .resource_table lookup
cannot read past the loaded string table.
Signed-off-by: Ben Levinsky <ben.levinsky@amd.com>
Store the loaded section string-table size in the ELF image information
for both ELF32 and ELF64 images.
Keeping the size alongside the string-table pointer allows later section
name lookups to validate sh_name offsets against the actual loaded table
bounds.
Signed-off-by: Ben Levinsky <ben.levinsky@amd.com>
Use overflow-safe range validation before copying the ELF section string
table from the firmware image.
The section string-table offset and size are read from untrusted section
headers. Validate that the full table is present in the current image
chunk without relying on wrapping offset arithmetic.
Signed-off-by: Ben Levinsky <ben.levinsky@amd.com>
Use checked multiplication when computing ELF program and section header
table sizes from e_phnum/e_phentsize and e_shnum/e_shentsize.
Also replace wrapping offset-plus-length range checks with overflow-safe
image chunk validation before allocation and memcpy. Malformed firmware
images with impossible table sizes now fail with -RPROC_EINVAL.
Signed-off-by: Ben Levinsky <ben.levinsky@amd.com>
Reject malformed ELF headers before using program or section table
metadata from the firmware image.
Validate the ELF class, ELF header size, program header entry size,
section header entry size, and section string-table index. Release an
image-info object allocated by this call if validation fails, while
leaving caller-owned objects untouched.
Signed-off-by: Ben Levinsky <ben.levinsky@amd.com>
Add generic checked addition, subtraction, and multiplication helpers
with consistent input validation across builtin and fallback
implementations.
Add a generic range-containment helper which reports arithmetic
overflow separately from non-containment. This lets the ELF loader
distinguish malformed ranges from data absent from the current image
chunk.
Signed-off-by: Ben Levinsky <ben.levinsky@amd.com>
Document that callers must zero-initialize the endpoint structure
before calling rpmsg_create_ept, including the release_cb field.
Fixes#659
Signed-off-by: Atul Akella <atul.akella@gmail.com>
Multiple lines of text are concatenated so use a code block for the
supported targets so they are on individual lines.
Signed-off-by: Sipke Vriend <sipke@direktembedded.com>
Use the markdown shell block instead of prepending $ to command so that
users can copy the block, as supported in github and IDEs.
Signed-off-by: Sipke Vriend <sipke@direktembedded.com>
Use the markdown shell block instead of prepending $ to command so that
users can copy the block, as supported in github and IDEs.
Signed-off-by: Sipke Vriend <sipke@direktembedded.com>
The function unconditionally returns true and neither call site
checks the return value. Remove the dead return and change the
return type to void.
Fixes: commit b32187e4fb ("openamp: change rx/tx buffer hold flag to count")
Signed-off-by: Chirag Shilwant <c-shilwant@ti.com>
The macro body references 'rp_hdr' instead of using the declared
parameter 'rphdr'. This causes the macro to ignore its argument and
always reference whatever 'rp_hdr' variable exists in the calling
scope. Fix by using the parameter name in the macro body.
Fixes: commit b32187e4fb ("openamp: change rx/tx buffer hold flag to count")
Signed-off-by: Chirag Shilwant <c-shilwant@ti.com>
Print the freespace so we can monitor how close we are to overflow.
Also allow manual trigger for main CI action.
Signed-off-by: Bill Mills <bill.mills@linaro.org>
Update the README contribution guidelines to document a consistent
Assisted-by tag format for AI-assisted patches.
Signed-off-by: Arnaud Pouliquen <arnaud.pouliquen@foss.st.com>
Since Zephyr 4.0, the command west packages pip --install must be run
before west zephyr-export.
Without this order, an error can occur when running west zephyr-export.
ModuleNotFoundError: No module named 'jsonschema'
Signed-off-by: Arnaud Pouliquen <arnaud.pouliquen@foss.st.com>
Zephyr 4.3 does not properly support CMake 4.x.
The command "west sdk install" fails because of some Zephyr CMake files.
The issue has been fixed in Zephyr 4.4. Upgrade to Zephyr 4.4
instead of trying to apply a temporary fix for Zephyr 4.3.
Signed-off-by: Arnaud Pouliquen <arnaud.pouliquen@foss.st.com>
Add a NULL check for vq before dereferencing it in
virtqueue_notification() to prevent a crash when vq is NULL.
Signed-off-by: Shichun Ma <masc2008@gmail.com>
We now use the "git checkout command" in the RTDs project settings.
This means we will use the .readthedocs.yaml and conf.py from the
openamp-docs repo and no longer need these files in the submodules.
See openamp-docs/.readthedocs.yaml for details.
Signed-off-by: Bill Mills <bill.mills@linaro.org>
Remove the split dcache CMake options from the README.
The options were removed by d183f24 after being deprecated in favor of
WITH_DCACHE. Document only WITH_DCACHE as the supported way to enable
cache operations for vrings, buffers and resource table.
Signed-off-by: Jiaqi Yao <yaojiaqi@lixiang.com>
There is nothing "zynqmp" specific in these files, rename them to generic
ARM names. Having only "zynqmp" files in platforms as before might give
the impression only ZynqMP platforms are supported by this project.
Signed-off-by: Andrew Davis <afd@ti.com>
These were used when this repo contained machine specific examples.
With those moved to the openamp-system-reference project, these CMake
variables are now unused. Remove them.
Signed-off-by: Andrew Davis <afd@ti.com>
The following configuration are deprecated since more than 2 years
(v2024.05):
- rpmsg_virtio_get_status
- rpmsg_virtio_get_features
- rpmsg_virtio_read_config
- virtio_write_config
- rpmsg_virtio_create_virtqueues
- rpmsg_virtio_delete_virtqueues
Signed-off-by: Arnaud Pouliquen <arnaud.pouliquen@foss.st.com>
The following configuration are deprecated since more than 2 years
(v2024.05):
- VIRTIO_DRIVER_ONLY
- VIRTIO_DEVICE_ONLY
Signed-off-by: Arnaud Pouliquen <arnaud.pouliquen@foss.st.com>
file used by doxygen is doc/Doxyfile.in so remove the Doxyfile file
from root folder to avoid confusion.
Signed-off-by: Sipke Vriend <sipke@direktembedded.com>
PERL_PATH and MSCGEN_PATH are no longer used, so remove from Doxyfile.in
to avoid warning:
to avoid warning
warning Tag 'PERL_PATH' ... has become obsolete.
warning: Tag 'MSCGEN_PATH' ... has become obsolete.
Signed-off-by: Sipke Vriend <sipke@direktembedded.com>
to provide access to maintainers information for this repository add it
to the input source files.
Signed-off-by: Sipke Vriend <sipke@direktembedded.com>
Clear the allocated bitmap in `remoteproc_shutdown()` to
prevent resource table parsing failures on repeated remoteproc
starts.
Signed-off-by: Li Zhiyuan <doitysf@hotmail.com>
On GitHub, this check is tagged as "Required."
However, if a PR only affects the following folders:.github, docs,
scripts, or cmake, the check is not executed (to avoid false positives),
resulting in the status "execution pending" + "required" on GitHub.
This commit forces the execution of the check but bypasses the
compliance.xml test when the PR only affects the listed folders.
If at least one update affects other folders, the compliance check
runs as usual.
In addition, the cmake folder is removed from the list, as there is
no reason to skip compliance tests on it.
Signed-off-by: Arnaud Pouliquen arnaud.pouliquen@foss.st.com
- bump to Zephyr 4.3
- use west packages pip --install
- use "west sdk install" command to install the expected sdk version.
- only install arm-zephyr-eabi compiler as build tested only on
arm targets
Signed-off-by: Arnaud Pouliquen <arnaud.pouliquen@foss.st.com>
The code contains redundant checks with both metal_assert(vdev) and if
(!vdev).
Moreover, if the assert is disabled, it may lead to dereferencing a null
pointer.
We should not rely on asserts for API validation. Instead, replace the
assert with an error message.
Signed-off-by: Arnaud Pouliquen <arnaud.pouliquen@foss.st.com>
Remove the following CMake options and associated definitions that have
been deprecated for over two years:
- WITH_DCACHE_VRINGS
- WITH_DCACHE_BUFFERS
- WITH_DCACHE_RSC_TABLE
- VIRTIO_CACHED_RSC_TABLE
- VIRTIO_CACHED_BUFFERS
- VIRTIO_CACHED_VRINGS
Signed-off-by: Arnaud Pouliquen <arnaud.pouliquen@foss.st.com>
The function rproc_virtio_wait_remote_ready does not return a value.
Remove the related @return field from the documentation.
Signed-off-by: Arnaud Pouliquen <arnaud.pouliquen@foss.st.com>
- removes CACHE_FLUSH macro clashing with internal QNX definition
- also removes CACHE_INVALIDATE macro for consistency
Signed-off-by: Deep Chordia <dchordia@blackberry.com>
review requested to use a table rather than a code snippet to define
the memory layout, so convert proposed struct to a table with
definition, size and description and explanation of padding between
available and used structures.
Signed-off-by: Sipke Vriend <sipke@direktembedded.com>