You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit 19ca585
Browse filesBrowse the repository at this point in the historyBrowse files
audio: tdfb: Improve robustness for invalid configuration
Add validity checks against malformed configuration blobs and IPC
control payloads:
- Bound the blob length reported by comp_get_data_blob() to
[sizeof(*cd->config), SOF_TDFB_MAX_SIZE] in both tdfb_prepare and the
runtime new-blob path; store it in cd->config_size and require
config->size to match in tdfb_init_coef.
- Bump SOF_TDFB_MAX_SIZE 4096 -> 16384 to match the topology budget.
- Tie SOF_TDFB_MAX_MICROPHONES to PLATFORM_MAX_CHANNELS so num_mic_locations
cannot exceed the per-channel direction state arrays in tdfb_comp.h.
- Reject num_angles == 0, angle_enum_mult == 0, negative or out-of-range
filter_index, and negative input_channel_select[].
- Check cdata->num_elems vs. SOF_IPC_MAX_CHANNELS in the IPC3 GET handler.
Signed-off-by: Seppo Ingalsuo <seppo.ingalsuo@linux.intel.com>
0 commit comments