diff options
Diffstat (limited to 'drm')
| -rw-r--r-- | drm/libmediadrm/CryptoHal.cpp | 25 |
1 files changed, 21 insertions, 4 deletions
diff --git a/drm/libmediadrm/CryptoHal.cpp b/drm/libmediadrm/CryptoHal.cpp index 1fdc6e1954..5dd25639ca 100644 --- a/drm/libmediadrm/CryptoHal.cpp +++ b/drm/libmediadrm/CryptoHal.cpp @@ -240,11 +240,12 @@ int32_t CryptoHal::setHeapBase(const sp<IMemoryHeap>& heap) { Mutex::Autolock autoLock(mLock); int32_t seqNum = mHeapSeqNum++; + int fd = heap->getHeapID(); nativeHandle->data[0] = fd; auto hidlHandle = hidl_handle(nativeHandle); auto hidlMemory = hidl_memory("ashmem", hidlHandle, heap->getSize()); - mHeapBases.add(seqNum, mNextBufferId); + mHeapBases.add(seqNum, HeapBase(mNextBufferId, heap->getSize())); Return<void> hResult = mPlugin->setSharedBufferBase(hidlMemory, mNextBufferId++); ALOGE_IF(!hResult.isOk(), "setSharedBufferBase(): remote call failed"); return seqNum; @@ -269,10 +270,26 @@ status_t CryptoHal::toSharedBuffer(const sp<IMemory>& memory, int32_t seqNum, :: return UNEXPECTED_NULL; } - // memory must be in the declared heap - CHECK(mHeapBases.indexOfKey(seqNum) >= 0); + // memory must be in one of the heaps that have been set + if (mHeapBases.indexOfKey(seqNum) < 0) { + return UNKNOWN_ERROR; + } + + // heap must be the same size as the one that was set in setHeapBase + if (mHeapBases.valueFor(seqNum).getSize() != heap->getSize()) { + android_errorWriteLog(0x534e4554, "76221123"); + return UNKNOWN_ERROR; + } + + // memory must be within the address space of the heap + if (memory->pointer() != static_cast<uint8_t *>(heap->getBase()) + memory->offset() || + heap->getSize() < memory->offset() + memory->size() || + SIZE_MAX - memory->offset() < memory->size()) { + android_errorWriteLog(0x534e4554, "76221123"); + return UNKNOWN_ERROR; + } - buffer->bufferId = mHeapBases.valueFor(seqNum); + buffer->bufferId = mHeapBases.valueFor(seqNum).getBufferId(); buffer->offset = offset >= 0 ? offset : 0; buffer->size = size; return OK; |
