> Subject: [PATCH v2] remoteproc: imx_rproc: allow mappings ending at
> region boundary
>
> From: Marcel Hofmann <[email protected]>
>
> The address range checks in imx_rproc_da_to_sys() and
> imx_rproc_da_to_va() use a strict comparison for the exclusive end
> address of the requested range.
>
> As a result, a valid request that ends exactly at the end of an address
> translation or mapped memory region is rejected. For a region [start,
> start + size), a request [addr, addr + len) is contained when:
>
>     addr >= start && addr + len <= start + size
>
> This occurs when a loadable ELF segment fills an entire mapped
> memory region. This can be produced by a linker script that extends
> the resource table section to the end of its designated region:
>
>     .resource_table :
>     {
>       . = ALIGN(8);
>       KEEP(*(.resource_table)) /* Resource table */
>       . = ALIGN(8);
>       . = ORIGIN(m_rsc_tbl) + LENGTH(m_rsc_tbl);
>     } > m_rsc_tbl =0x00
>
> This produces a ELF program header like:
>
>     LOAD  0x010000 0xa4220000 0xa4220000 0x01000 0x01000 R
> 0x1000
>
> In this case, the segment size matches the mapped region size exactly,
> causing the address translation to fail with:
>
>     bad phdr da 0xa4220000 mem 0x1000
>
> Rework the upper-bound checks to allow ranges ending exactly at the
> region boundary while guarding against integer overflow.
>
> Fixes: a0ff4aa6f010 ("remoteproc: imx_rproc: add a NXP/Freescale
> imx_rproc driver")
> Signed-off-by: Marcel Hofmann <marcel.hofmann@ingenics-
> digital.com>

Tested-by: Peng Fan <[email protected]>  #i.MX95-19x19-EVK

Thanks,
Peng.

NXP Confidential

Reply via email to