mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Sasha Levin <sashal@kernel.org>
To: linux-kernel@vger.kernel.org, stable@vger.kernel.org
Cc: Richard Fitzgerald <rf@opensource.cirrus.com>,
	Pierre-Louis Bossart <pierre-louis.bossart@linux.intel.com>,
	Vinod Koul <vkoul@kernel.org>, Sasha Levin <sashal@kernel.org>,
	yung-chuan.liao@linux.intel.com, alsa-devel@alsa-project.org
Subject: [PATCH AUTOSEL 5.10 16/33] soundwire: cadence: Don't overwrite msg->buf during write commands
Date: Wed, 12 Oct 2022 20:23:15 -0400	[thread overview]
Message-ID: <20221013002334.1894749-16-sashal@kernel.org> (raw)
In-Reply-To: <20221013002334.1894749-1-sashal@kernel.org>

From: Richard Fitzgerald <rf@opensource.cirrus.com>

[ Upstream commit ba05b39d265bdd16913f7684600d9d41e2796745 ]

The buf passed in struct sdw_msg must only be written for a READ,
in that case the RDATA part of the response is the data value of the
register.

For a write command there is no RDATA, and buf should be assumed to
be const and unmodifable. The original caller should not expect its data
buffer to be corrupted by an sdw_nwrite().

Signed-off-by: Richard Fitzgerald <rf@opensource.cirrus.com>
Reviewed-by: Pierre-Louis Bossart <pierre-louis.bossart@linux.intel.com>
Link: https://lore.kernel.org/r/20220916103505.1562210-1-rf@opensource.cirrus.com
Signed-off-by: Vinod Koul <vkoul@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/soundwire/cadence_master.c | 9 ++++++---
 1 file changed, 6 insertions(+), 3 deletions(-)

diff --git a/drivers/soundwire/cadence_master.c b/drivers/soundwire/cadence_master.c
index c6d421a4b91b..a3247692ddc0 100644
--- a/drivers/soundwire/cadence_master.c
+++ b/drivers/soundwire/cadence_master.c
@@ -501,9 +501,12 @@ cdns_fill_msg_resp(struct sdw_cdns *cdns,
 		return SDW_CMD_IGNORED;
 	}
 
-	/* fill response */
-	for (i = 0; i < count; i++)
-		msg->buf[i + offset] = FIELD_GET(CDNS_MCP_RESP_RDATA, cdns->response_buf[i]);
+	if (msg->flags == SDW_MSG_FLAG_READ) {
+		/* fill response */
+		for (i = 0; i < count; i++)
+			msg->buf[i + offset] = FIELD_GET(CDNS_MCP_RESP_RDATA,
+							 cdns->response_buf[i]);
+	}
 
 	return SDW_CMD_OK;
 }
-- 
2.35.1


  parent reply	other threads:[~2022-10-13  0:53 UTC|newest]

Thread overview: 34+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2022-10-13  0:23 [PATCH AUTOSEL 5.10 01/33] clk: zynqmp: Fix stack-out-of-bounds in strncpy` Sasha Levin
2022-10-13  0:23 ` [PATCH AUTOSEL 5.10 02/33] media: cx88: Fix a null-ptr-deref bug in buffer_prepare() Sasha Levin
2022-10-13  0:23 ` [PATCH AUTOSEL 5.10 03/33] clk: zynqmp: pll: rectify rate rounding in zynqmp_pll_round_rate Sasha Levin
2022-10-13  0:23 ` [PATCH AUTOSEL 5.10 04/33] usb: host: xhci-plat: suspend and resume clocks Sasha Levin
2022-10-13  0:23 ` [PATCH AUTOSEL 5.10 05/33] usb: host: xhci-plat: suspend/resume clks for brcm Sasha Levin
2022-10-13  0:23 ` [PATCH AUTOSEL 5.10 06/33] dmaengine: ti: k3-udma: Reset UDMA_CHAN_RT byte counters to prevent overflow Sasha Levin
2022-10-13  0:23 ` [PATCH AUTOSEL 5.10 07/33] scsi: 3w-9xxx: Avoid disabling device if failing to enable it Sasha Levin
2022-10-13  0:23 ` [PATCH AUTOSEL 5.10 08/33] nbd: Fix hung when signal interrupts nbd_start_device_ioctl() Sasha Levin
2022-10-13  0:23 ` [PATCH AUTOSEL 5.10 09/33] staging: rtl8712: Fix return type for implementation of ndo_start_xmit Sasha Levin
2022-10-13  0:23 ` [PATCH AUTOSEL 5.10 10/33] staging: rtl8192e: " Sasha Levin
2022-10-18  9:48   ` Pavel Machek
2022-10-13  0:23 ` [PATCH AUTOSEL 5.10 11/33] power: supply: adp5061: fix out-of-bounds read in adp5061_get_chg_type() Sasha Levin
2022-10-13  0:23 ` [PATCH AUTOSEL 5.10 12/33] staging: vt6655: fix potential memory leak Sasha Levin
2022-10-13  0:23 ` [PATCH AUTOSEL 5.10 13/33] blk-throttle: prevent overflow while calculating wait time Sasha Levin
2022-10-13  0:23 ` [PATCH AUTOSEL 5.10 14/33] ata: libahci_platform: Sanity check the DT child nodes number Sasha Levin
2022-10-13  0:23 ` [PATCH AUTOSEL 5.10 15/33] bcache: fix set_at_max_writeback_rate() for multiple attached devices Sasha Levin
2022-10-13  0:23 ` Sasha Levin [this message]
2022-10-13  0:23 ` [PATCH AUTOSEL 5.10 17/33] soundwire: intel: fix error handling on dai registration issues Sasha Levin
2022-10-13  0:23 ` [PATCH AUTOSEL 5.10 18/33] hid: topre: Add driver fixing report descriptor Sasha Levin
2022-10-13  0:23 ` [PATCH AUTOSEL 5.10 19/33] HID: roccat: Fix use-after-free in roccat_read() Sasha Levin
2022-10-13  0:23 ` [PATCH AUTOSEL 5.10 20/33] HSI: ssi_protocol: fix potential resource leak in ssip_pn_open() Sasha Levin
2022-10-13  0:23 ` [PATCH AUTOSEL 5.10 21/33] md/raid5: Wait for MD_SB_CHANGE_PENDING in raid5d Sasha Levin
2022-10-13  0:23 ` [PATCH AUTOSEL 5.10 22/33] usb: host: xhci: Fix potential memory leak in xhci_alloc_stream_info() Sasha Levin
2022-10-13  0:23 ` [PATCH AUTOSEL 5.10 23/33] usb: musb: Fix musb_gadget.c rxstate overflow bug Sasha Levin
2022-10-13  0:23 ` [PATCH AUTOSEL 5.10 24/33] Revert "usb: storage: Add quirk for Samsung Fit flash" Sasha Levin
2022-10-13  0:23 ` [PATCH AUTOSEL 5.10 25/33] staging: rtl8723bs: fix a potential memory leak in rtw_init_cmd_priv() Sasha Levin
2022-10-13  0:23 ` [PATCH AUTOSEL 5.10 26/33] staging: rtl8192u: Fix return type of ieee80211_xmit Sasha Levin
2022-10-13  0:23 ` [PATCH AUTOSEL 5.10 27/33] staging: octeon: Fix return type of cvm_oct_xmit and cvm_oct_xmit_pow Sasha Levin
2022-10-13  0:23 ` [PATCH AUTOSEL 5.10 28/33] nvme: copy firmware_rev on each init Sasha Levin
2022-10-13  0:23 ` [PATCH AUTOSEL 5.10 29/33] nvmet-tcp: add bounds check on Transfer Tag Sasha Levin
2022-10-13  0:23 ` [PATCH AUTOSEL 5.10 30/33] usb: idmouse: fix an uninit-value in idmouse_open Sasha Levin
2022-10-13  0:23 ` [PATCH AUTOSEL 5.10 31/33] fsi: master-ast-cf: Fix missing of_node_put in fsi_master_acf_probe Sasha Levin
2022-10-13  0:23 ` [PATCH AUTOSEL 5.10 32/33] sbitmap: fix lockup while swapping Sasha Levin
2022-10-13  0:23 ` [PATCH AUTOSEL 5.10 33/33] clk: bcm2835: Make peripheral PLLC critical Sasha Levin

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20221013002334.1894749-16-sashal@kernel.org \
    --to=sashal@kernel.org \
    --cc=alsa-devel@alsa-project.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=pierre-louis.bossart@linux.intel.com \
    --cc=rf@opensource.cirrus.com \
    --cc=stable@vger.kernel.org \
    --cc=vkoul@kernel.org \
    --cc=yung-chuan.liao@linux.intel.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

Powered by JetHome