Skip to content

Commit a4315e5

Browse files
YooYong-Sumchehab
authored andcommitted
media: dvb_ca_en50221: fix a size write bug
The function of "dvb_ca_en50221_write_data" at source/drivers/media /dvb-core/dvb_ca_en50221.c is used for two cases. The first case is for writing APDU data in the function of "dvb_ca_en50221_io_write" at source/drivers/media/dvb-core/ dvb_ca_en50221.c. The second case is for writing the host link buf size on the Command Register in the function of "dvb_ca_en50221_link_init" at source/drivers/media/dvb-core/dvb_ca_en50221.c. In the second case, there exists a bug like following. In the function of the "dvb_ca_en50221_link_init", after a TV host calculates the host link buf_size, the TV host writes the calculated host link buf_size on the Size Register. Accroding to the en50221 Spec (the page 60 of https://dvb.org/wp-content/uploads/2020/02/En50221.V1.pdf), before this writing operation, the "SW(CMDREG_SW)" flag in the Command Register should be set. We can see this setting operation in the function of the "dvb_ca_en50221_link_init" like below. ... if ((ret = ca->pub->write_cam_control(ca->pub, slot, CTRLIF_COMMAND, IRQEN | CMDREG_SW)) != 0) return ret; ... But, after that, the real writing operation is implemented using the function of the "dvb_ca_en50221_write_data" in the function of "dvb_ca_en50221_link_init", and the "dvb_ca_en50221_write_data" includes the function of "ca->pub->write_cam_control", and the function of the "ca->pub->write_cam_control" in the function of the "dvb_ca_en50221_wrte_data" does not include "CMDREG_SW" flag like below. ... if ((status = ca->pub->write_cam_control(ca->pub, slot, CTRLIF_COMMAND, IRQEN | CMDREG_HC)) != 0) ... In the above source code, we can see only the "IRQEN | CMDREG_HC", but we cannot see the "CMDREG_SW". The "CMDREG_SW" flag which was set in the function of the "dvb_ca_en50221_link_init" was rollbacked by the follwoing function of the "dvb_ca_en50221_write_data". This is a bug. and this bug causes that the calculated host link buf_size is not properly written in the CI module. Through this patch, we fix this bug. Link: https://lore.kernel.org/linux-media/[email protected] Signed-off-by: YongSu Yoo <[email protected]> Signed-off-by: Mauro Carvalho Chehab <[email protected]>
1 parent e6ad623 commit a4315e5

File tree

1 file changed

+7
-5
lines changed

1 file changed

+7
-5
lines changed

drivers/media/dvb-core/dvb_ca_en50221.c

Lines changed: 7 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -187,7 +187,7 @@ static void dvb_ca_en50221_thread_wakeup(struct dvb_ca_private *ca);
187187
static int dvb_ca_en50221_read_data(struct dvb_ca_private *ca, int slot,
188188
u8 *ebuf, int ecount);
189189
static int dvb_ca_en50221_write_data(struct dvb_ca_private *ca, int slot,
190-
u8 *ebuf, int ecount);
190+
u8 *ebuf, int ecount, int size_write_flag);
191191

192192
/**
193193
* findstr - Safely find needle in haystack.
@@ -370,7 +370,7 @@ static int dvb_ca_en50221_link_init(struct dvb_ca_private *ca, int slot)
370370
ret = dvb_ca_en50221_wait_if_status(ca, slot, STATUSREG_FR, HZ / 10);
371371
if (ret)
372372
return ret;
373-
ret = dvb_ca_en50221_write_data(ca, slot, buf, 2);
373+
ret = dvb_ca_en50221_write_data(ca, slot, buf, 2, CMDREG_SW);
374374
if (ret != 2)
375375
return -EIO;
376376
ret = ca->pub->write_cam_control(ca->pub, slot, CTRLIF_COMMAND, IRQEN);
@@ -778,11 +778,13 @@ static int dvb_ca_en50221_read_data(struct dvb_ca_private *ca, int slot,
778778
* @buf: The data in this buffer is treated as a complete link-level packet to
779779
* be written.
780780
* @bytes_write: Size of ebuf.
781+
* @size_write_flag: A flag on Command Register which says whether the link size
782+
* information will be writen or not.
781783
*
782784
* return: Number of bytes written, or < 0 on error.
783785
*/
784786
static int dvb_ca_en50221_write_data(struct dvb_ca_private *ca, int slot,
785-
u8 *buf, int bytes_write)
787+
u8 *buf, int bytes_write, int size_write_flag)
786788
{
787789
struct dvb_ca_slot *sl = &ca->slot_info[slot];
788790
int status;
@@ -817,7 +819,7 @@ static int dvb_ca_en50221_write_data(struct dvb_ca_private *ca, int slot,
817819

818820
/* OK, set HC bit */
819821
status = ca->pub->write_cam_control(ca->pub, slot, CTRLIF_COMMAND,
820-
IRQEN | CMDREG_HC);
822+
IRQEN | CMDREG_HC | size_write_flag);
821823
if (status)
822824
goto exit;
823825

@@ -1508,7 +1510,7 @@ static ssize_t dvb_ca_en50221_io_write(struct file *file,
15081510

15091511
mutex_lock(&sl->slot_lock);
15101512
status = dvb_ca_en50221_write_data(ca, slot, fragbuf,
1511-
fraglen + 2);
1513+
fraglen + 2, 0);
15121514
mutex_unlock(&sl->slot_lock);
15131515
if (status == (fraglen + 2)) {
15141516
written = 1;

0 commit comments

Comments
 (0)