firmware_loader: fix pre-allocated buf built-in firmware use

The firmware_loader can be used with a pre-allocated buffer
through the use of the API calls:

  o request_firmware_into_buf()
  o request_partial_firmware_into_buf()

If the firmware was built-in and present, our current check
for if the built-in firmware fits into the pre-allocated buffer
does not return any errors, and we proceed to tell the caller
that everything worked fine. It's a lie and no firmware would
end up being copied into the pre-allocated buffer. So if the
caller trust the result it may end up writing a bunch of 0's
to a device!

Fix this by making the function that checks for the pre-allocated
buffer return non-void. Since the typical use case is when no
pre-allocated buffer is provided make this return successfully
for that case. If the built-in firmware does *not* fit into the
pre-allocated buffer size return a failure as we should have
been doing before.

I'm not aware of users of the built-in firmware using the API
calls with a pre-allocated buffer, as such I doubt this fixes
any real life issue. But you never know... perhaps some oddball
private tree might use it.

In so far as upstream is concerned this just fixes our code for
correctness.

Signed-off-by: Luis Chamberlain <mcgrof@kernel.org>
Link: https://lore.kernel.org/r/20210917182226.3532898-2-mcgrof@kernel.org
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
This commit is contained in:
Luis Chamberlain 2021-09-17 11:22:13 -07:00 committed by Greg Kroah-Hartman
parent abcb948db3
commit f7a07f7b96
1 changed files with 7 additions and 6 deletions

View File

@ -100,12 +100,15 @@ static struct firmware_cache fw_cache;
extern struct builtin_fw __start_builtin_fw[]; extern struct builtin_fw __start_builtin_fw[];
extern struct builtin_fw __end_builtin_fw[]; extern struct builtin_fw __end_builtin_fw[];
static void fw_copy_to_prealloc_buf(struct firmware *fw, static bool fw_copy_to_prealloc_buf(struct firmware *fw,
void *buf, size_t size) void *buf, size_t size)
{ {
if (!buf || size < fw->size) if (!buf)
return; return true;
if (size < fw->size)
return false;
memcpy(buf, fw->data, fw->size); memcpy(buf, fw->data, fw->size);
return true;
} }
static bool fw_get_builtin_firmware(struct firmware *fw, const char *name, static bool fw_get_builtin_firmware(struct firmware *fw, const char *name,
@ -117,9 +120,7 @@ static bool fw_get_builtin_firmware(struct firmware *fw, const char *name,
if (strcmp(name, b_fw->name) == 0) { if (strcmp(name, b_fw->name) == 0) {
fw->size = b_fw->size; fw->size = b_fw->size;
fw->data = b_fw->data; fw->data = b_fw->data;
fw_copy_to_prealloc_buf(fw, buf, size); return fw_copy_to_prealloc_buf(fw, buf, size);
return true;
} }
} }