16 Commits
Author SHA1 Message Date
Ben Levinsky 22ddff1a4e remoteproc: Validate resource table entry bounds
Resource offsets from a copied firmware table are dereferenced without
bounds checks when no I/O region is present. Handlers can then access
memory beyond the table through a VDEV's flexible vring array.

Reject a NULL table, validate offset-array arithmetic, and require
every entry to remain inside the table before dispatch. Check fixed
sizes, VDEV vrings and config data, and vendor lengths using
overflow-safe subtraction.

Signed-off-by: Ben Levinsky <ben.levinsky@amd.com>
Assisted-by: Codex:GPT-5
2026-09-22 18:50:37 +02:00
Ben Levinsky 4d412df37f remoteproc: Validate virtqueue alignment
The remote resource table controls the vring alignment, which is used
for pointer rounding without validation. vring_init() rounds the used
ring address with a ~(align - 1) mask, so a zero alignment leaves a
NULL used ring that is dereferenced later.

Reject a zero alignment before calculating the vring size and before
storing the vring metadata taken from the resource table.

Signed-off-by: Ben Levinsky <ben.levinsky@amd.com>
Assisted-by: Codex:GPT-5
2026-09-22 18:50:37 +02:00
Ben Levinsky d0e5e0d376 proxy: Validate retarget read response length
_read() converts the peer-provided unsigned data length to a signed
integer and bounds it only against the caller's buffer size. Large
values can bypass that comparison or make memcpy() read beyond the
fixed response buffer.

Reject nonpositive destination sizes, retain the peer length as an
unsigned value, and clamp it to both the response payload capacity and
the caller's buffer before copying.

Signed-off-by: Ben Levinsky <ben.levinsky@amd.com>
Assisted-by: Codex:GPT-5
2026-09-21 09:54:50 +02:00
Ben Levinsky f7c918bf07 rpmsg: rpc: Validate client request lengths
The RPC client copies caller-provided parameters into a fixed-size
stack buffer without checking whether the complete request fits.
Oversized requests can therefore overwrite the caller's stack frame.

Reject requests that exceed the remaining parameter capacity before
copying them, validate nonempty parameter pointers, and document the
public API limit.

Signed-off-by: Ben Levinsky <ben.levinsky@amd.com>
Assisted-by: Codex:GPT-5
2026-09-21 09:54:50 +02:00
Ben Levinsky 49780d11b4 rpmsg: rpc: Validate client reply lengths
The RPC client reads the reply ID and status without checking that the
remote message contains the fixed reply header. It also passes the
total message length to callbacks that receive a parameters pointer,
making the reported length include the header bytes.

Reject replies shorter than the fixed header and pass callbacks only
the number of bytes that follow it.

Signed-off-by: Ben Levinsky <ben.levinsky@amd.com>
Assisted-by: Codex:GPT-5
2026-09-21 09:54:50 +02:00
Ben Levinsky 2b7013e733 proxy: Validate retarget write length
_write() copies a caller-controlled length into a fixed-size stack
buffer without checking that the RPC header and payload fit. Negative
lengths also become large unsigned memcpy() sizes, and the stdout NUL
terminator is written one byte beyond its intended position.

Reject invalid lengths before constructing the request. Include the
optional terminator in the capacity check and place the terminator
immediately after the copied payload.

Signed-off-by: Ben Levinsky <ben.levinsky@amd.com>
Assisted-by: Codex:GPT-5
2026-09-21 09:54:50 +02:00
Ben Levinsky 372048d49d rpmsg: rpc: Validate and initialize server requests
The RPC callback does not receive the request length, so it may
inspect bytes beyond a short message. Those bytes currently come from
an uninitialized stack buffer. A message shorter than the function ID
can also make the dispatch path read uninitialized data.

Reject messages that do not contain a complete function ID and
zero-initialize the request buffer so callbacks never consume stale
stack contents from bytes omitted by the remote peer.

Signed-off-by: Ben Levinsky <ben.levinsky@amd.com>
Assisted-by: Codex:GPT-5
2026-09-21 09:54:50 +02:00
Ben Levinsky 3ea751021e remoteproc: avoid wrapping loader offset comparison
Replace the non-seekable loader offset comparison that used offset + len
with an overflow-safe equivalent.

This preserves existing behavior for normal ranges while avoiding a
wraparound case when deciding whether required image data is contiguous
with the current chunk.

Signed-off-by: Ben Levinsky <ben.levinsky@amd.com>
2026-09-21 09:50:11 +02:00
Ben Levinsky 28b0a020c6 remoteproc: bound ELF section name lookups
Make ELF section-name lookup validate sh_name before reading from the
loaded section string table.

Skip malformed section names whose sh_name offset is outside the table
or whose string is not NUL-terminated within the remaining table bytes.
Use bounded comparison for valid candidates so .resource_table lookup
cannot read past the loaded string table.

Signed-off-by: Ben Levinsky <ben.levinsky@amd.com>
2026-09-21 09:50:11 +02:00
Ben Levinsky 08a45aca33 remoteproc: track loaded ELF section string-table size
Store the loaded section string-table size in the ELF image information
for both ELF32 and ELF64 images.

Keeping the size alongside the string-table pointer allows later section
name lookups to validate sh_name offsets against the actual loaded table
bounds.

Signed-off-by: Ben Levinsky <ben.levinsky@amd.com>
2026-09-21 09:50:11 +02:00
Ben Levinsky 872a4fcae7 remoteproc: harden ELF section string-table range checks
Use overflow-safe range validation before copying the ELF section string
table from the firmware image.

The section string-table offset and size are read from untrusted section
headers. Validate that the full table is present in the current image
chunk without relying on wrapping offset arithmetic.

Signed-off-by: Ben Levinsky <ben.levinsky@amd.com>
2026-09-21 09:50:11 +02:00
Ben Levinsky 8d245caca2 remoteproc: check ELF program and section table sizes
Use checked multiplication when computing ELF program and section header
table sizes from e_phnum/e_phentsize and e_shnum/e_shentsize.

Also replace wrapping offset-plus-length range checks with overflow-safe
image chunk validation before allocation and memcpy. Malformed firmware
images with impossible table sizes now fail with -RPROC_EINVAL.

Signed-off-by: Ben Levinsky <ben.levinsky@amd.com>
2026-09-21 09:50:11 +02:00
Ben Levinsky f3b110faff remoteproc: validate ELF header shape before table loading
Reject malformed ELF headers before using program or section table
metadata from the firmware image.

Validate the ELF class, ELF header size, program header entry size,
section header entry size, and section string-table index. Release an
image-info object allocated by this call if validation fails, while
leaving caller-owned objects untouched.

Signed-off-by: Ben Levinsky <ben.levinsky@amd.com>
2026-09-21 09:50:11 +02:00
Ben Levinsky 2ad0328fe6 remoteproc: add checked arithmetic helpers
Add generic checked addition, subtraction, and multiplication helpers
with consistent input validation across builtin and fallback
implementations.

Add a generic range-containment helper which reports arithmetic
overflow separately from non-containment. This lets the ELF loader
distinguish malformed ranges from data absent from the current image
chunk.

Signed-off-by: Ben Levinsky <ben.levinsky@amd.com>
2026-09-21 09:50:11 +02:00
Ben Levinsky 1697a15f47 apps: zynqmp: Add Versal_net IPI values.
Enable Linux demos to run on Versal_net by updating the IPI values that
are specific to this hardware platform.

Signed-off-by: Ben Levinsky <ben.levinsky@amd.com>
2023-05-22 09:38:28 +02:00
Ben Levinsky 7513776e35 openamp: fix remoteproc_load_noblock hasn't update rsc_io
This addressess issue https://github.com/OpenAMP/open-amp/issues/427

Signed-off-by: Ben Levinsky <ben.levinsky@amd.com>
2023-02-27 11:15:38 +01:00