Skip to content

Commit 6bc961c

Browse files
committed
[drivers][virtio] Check input offsets before the remaining range
Name the queue bound and validate the offset before subtracting it. This keeps the accepted request range unchanged while following the order in which a reader checks an indexed copy.
1 parent 45be94b commit 6bc961c

1 file changed

Lines changed: 6 additions & 4 deletions

File tree

‎components/legacy/virtio/virtio_input.c‎

Lines changed: 6 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -142,9 +142,10 @@ static rt_err_t virtio_input_init(rt_device_t dev)
142142
static rt_ssize_t virtio_input_read(rt_device_t dev, rt_off_t pos, void *buffer, rt_size_t size)
143143
{
144144
struct virtio_input_device *virtio_input_dev = (struct virtio_input_device *)dev;
145-
rt_size_t num = virtio_input_dev->virtio_dev.queues[VIRTIO_INPUT_QUEUE_EVENT].num;
145+
rt_size_t queue_size = virtio_input_dev->virtio_dev.queues[VIRTIO_INPUT_QUEUE_EVENT].num;
146146

147-
if (buffer == RT_NULL || pos < 0 || size >= num || (rt_size_t)pos >= num - size)
147+
if (buffer == RT_NULL || pos < 0 || (rt_size_t)pos >= queue_size ||
148+
size >= queue_size - (rt_size_t)pos)
148149
{
149150
return 0;
150151
}
@@ -161,9 +162,10 @@ static rt_ssize_t virtio_input_read(rt_device_t dev, rt_off_t pos, void *buffer,
161162
static rt_ssize_t virtio_input_write(rt_device_t dev, rt_off_t pos, const void *buffer, rt_size_t size)
162163
{
163164
struct virtio_input_device *virtio_input_dev = (struct virtio_input_device *)dev;
164-
rt_size_t num = virtio_input_dev->virtio_dev.queues[VIRTIO_INPUT_QUEUE_EVENT].num;
165+
rt_size_t queue_size = virtio_input_dev->virtio_dev.queues[VIRTIO_INPUT_QUEUE_EVENT].num;
165166

166-
if (buffer == RT_NULL || pos < 0 || size >= num || (rt_size_t)pos >= num - size)
167+
if (buffer == RT_NULL || pos < 0 || (rt_size_t)pos >= queue_size ||
168+
size >= queue_size - (rt_size_t)pos)
167169
{
168170
return 0;
169171
}

0 commit comments

Comments
 (0)