mirror of
git://nv-tegra.nvidia.com/linux-nvgpu.git
synced 2025-12-24 10:34:43 +03:00
gpu: nvgpu: check bl_size with imem size in bl_bootstrap
Currently nvgpu gets the destination offset in imem by directly subtra- cting bl_size from imem size however there can be underflow if bl_size is larger than imem size. Add check for that. JIRA NVGPU-1732 Change-Id: I88477beee273201fc6075c7ab8d77eb9b2a17ca5 Signed-off-by: Sagar Kamble <skamble@nvidia.com> Reviewed-on: https://git-master.nvidia.com/r/1989989 Reviewed-by: svc-mobile-coverity <svc-mobile-coverity@nvidia.com> Reviewed-by: svc-mobile-misra <svc-mobile-misra@nvidia.com> Reviewed-by: svc-misra-checker <svc-misra-checker@nvidia.com> Reviewed-by: Mahantesh Kumbar <mkumbar@nvidia.com> GVS: Gerrit_Virtual_Submit Reviewed-by: Alex Waterman <alexw@nvidia.com> Reviewed-by: mobile promotions <svcmobile_promotions@nvidia.com> Tested-by: mobile promotions <svcmobile_promotions@nvidia.com>
This commit is contained in:
committed by
mobile promotions
parent
32280be158
commit
9b114d628c
@@ -454,6 +454,7 @@ static int gk20a_falcon_bl_bootstrap(struct nvgpu_falcon *flcn,
|
||||
struct gk20a *g = flcn->g;
|
||||
u32 base_addr = flcn->flcn_base;
|
||||
u32 virt_addr = 0;
|
||||
u32 imem_size;
|
||||
u32 dst = 0;
|
||||
int err = 0;
|
||||
|
||||
@@ -465,8 +466,15 @@ static int gk20a_falcon_bl_bootstrap(struct nvgpu_falcon *flcn,
|
||||
}
|
||||
|
||||
/* copy bootloader to TOP of IMEM */
|
||||
dst = (falcon_falcon_hwcfg_imem_size_v(gk20a_readl(g,
|
||||
base_addr + falcon_falcon_hwcfg_r())) << 8) - bl_info->bl_size;
|
||||
imem_size = falcon_falcon_hwcfg_imem_size_v(gk20a_readl(g,
|
||||
base_addr + falcon_falcon_hwcfg_r())) << 8;
|
||||
|
||||
if (bl_info->bl_size > imem_size) {
|
||||
err = -EINVAL;
|
||||
goto exit;
|
||||
}
|
||||
|
||||
dst = imem_size - bl_info->bl_size;
|
||||
|
||||
err = gk20a_falcon_copy_to_imem(flcn, dst, (u8 *)(bl_info->bl_src),
|
||||
bl_info->bl_size, (u8)0, false, bl_info->bl_start_tag);
|
||||
|
||||
Reference in New Issue
Block a user