Show a patch.

GET /api/patches/27507/?format=api
HTTP 200 OK
Allow: GET, PUT, PATCH, HEAD, OPTIONS
Content-Type: application/json
Vary: Accept

{
    "id": 27507,
    "url": "https://patchwork.libcamera.org/api/patches/27507/?format=api",
    "web_url": "https://patchwork.libcamera.org/patch/27507/",
    "project": {
        "id": 1,
        "url": "https://patchwork.libcamera.org/api/projects/1/?format=api",
        "name": "libcamera",
        "link_name": "libcamera",
        "list_id": "libcamera_core",
        "list_email": "libcamera-devel@lists.libcamera.org",
        "web_url": "",
        "scm_url": "",
        "webscm_url": ""
    },
    "msgid": "<20260725131932.13509-1-magdum.foss@gmail.com>",
    "date": "2026-07-25T13:14:07",
    "name": "[v2,2/2] libcamera: Harden control serializer size and input validation",
    "commit_ref": null,
    "pull_url": null,
    "state": "new",
    "archived": false,
    "hash": "1db2156d1a4998db34abbe4acc9d6c8a0dfb8d33",
    "submitter": {
        "id": 453,
        "url": "https://patchwork.libcamera.org/api/people/453/?format=api",
        "name": "Magdum",
        "email": "magdum.foss@gmail.com"
    },
    "delegate": null,
    "mbox": "https://patchwork.libcamera.org/patch/27507/mbox/",
    "series": [
        {
            "id": 6082,
            "url": "https://patchwork.libcamera.org/api/series/6082/?format=api",
            "web_url": "https://patchwork.libcamera.org/project/libcamera/list/?series=6082",
            "date": "2026-07-25T13:14:07",
            "name": null,
            "version": 2,
            "mbox": "https://patchwork.libcamera.org/series/6082/mbox/"
        }
    ],
    "comments": "https://patchwork.libcamera.org/api/patches/27507/comments/",
    "check": "pending",
    "checks": "https://patchwork.libcamera.org/api/patches/27507/checks/",
    "tags": {},
    "headers": {
        "Return-Path": "<libcamera-devel-bounces@lists.libcamera.org>",
        "X-Original-To": "parsemail@patchwork.libcamera.org",
        "Delivered-To": "parsemail@patchwork.libcamera.org",
        "Received": [
            "from lancelot.ideasonboard.com (lancelot.ideasonboard.com\n\t[92.243.16.209])\n\tby patchwork.libcamera.org (Postfix) with ESMTPS id 03855BE080\n\tfor <parsemail@patchwork.libcamera.org>;\n\tSat, 25 Jul 2026 13:19:40 +0000 (UTC)",
            "from lancelot.ideasonboard.com (localhost [IPv6:::1])\n\tby lancelot.ideasonboard.com (Postfix) with ESMTP id 20F6167F4B;\n\tSat, 25 Jul 2026 15:19:40 +0200 (CEST)",
            "from mail-wm1-x331.google.com (mail-wm1-x331.google.com\n\t[IPv6:2a00:1450:4864:20::331])\n\tby lancelot.ideasonboard.com (Postfix) with ESMTPS id B95B767E5C\n\tfor <libcamera-devel@lists.libcamera.org>;\n\tSat, 25 Jul 2026 15:19:38 +0200 (CEST)",
            "by mail-wm1-x331.google.com with SMTP id\n\t5b1f17b1804b1-495590ba856so11711025e9.2\n\tfor <libcamera-devel@lists.libcamera.org>;\n\tSat, 25 Jul 2026 06:19:38 -0700 (PDT)",
            "from magdum-System-Product-Name.vodafone.ultrahub\n\t([2a02:810d:4b14:4600:4c66:91af:4d7a:df5e])\n\tby smtp.gmail.com with ESMTPSA id\n\t5b1f17b1804b1-496b49a6e17sm67431455e9.13.2026.07.25.06.19.36\n\t(version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256);\n\tSat, 25 Jul 2026 06:19:37 -0700 (PDT)"
        ],
        "Authentication-Results": "lancelot.ideasonboard.com; dkim=pass (2048-bit key;\n\tunprotected) header.d=gmail.com header.i=@gmail.com\n\theader.b=\"eGCRCX6y\"; dkim-atps=neutral",
        "DKIM-Signature": "v=1; a=rsa-sha256; c=relaxed/relaxed;\n\td=gmail.com; s=20251104; t=1784985578; x=1785590378;\n\tdarn=lists.libcamera.org; \n\th=content-transfer-encoding:content-type:mime-version:references\n\t:in-reply-to:message-id:date:subject:cc:to:from:from:to:cc:subject\n\t:date:message-id:reply-to:content-type;\n\tbh=+ZUxNNJ5Yj7xbJ5jiL5/jDB7p7bOZRI06MAE8OfhJM4=;\n\tb=eGCRCX6yKpk9OrtH/3P1BchRHThIBeBbZpjeMQNKmLSW/0lAKSG1YX7qukL36vX8F8\n\tvFYYcjTfUJlYRJH769qmjFfPFomQ0J6HSrwvMUfcXQmHYz7LD/be4yI4LwEs7wnKyjch\n\t6Quny3a4RWEQiRBh8OMosQCzoIY9/C2+2TddPB0Wzd/Buzxv5ksjltwtXkhfgHVDNNc0\n\tWpgbdCczKG0CAPdamLk28+D/p6OH5ELJnneu3MZHzq6/A2l9M5jCAxKGs0LPXwYRFwo+\n\tgdd/tVYgi+zJsrKhSYdQ7J6tLN92k8fLbStoOtk2wiDeqHBaIHzpqTBaop1Ga9so0U/S\n\tFi3w==",
        "X-Google-DKIM-Signature": "v=1; a=rsa-sha256; c=relaxed/relaxed;\n\td=1e100.net; s=20251104; t=1784985578; x=1785590378;\n\th=content-transfer-encoding:content-type:mime-version:references\n\t:in-reply-to:message-id:date:subject:cc:to:from:x-gm-gg\n\t:x-gm-message-state:from:to:cc:subject:date:message-id:reply-to\n\t:content-type;\n\tbh=+ZUxNNJ5Yj7xbJ5jiL5/jDB7p7bOZRI06MAE8OfhJM4=;\n\tb=sVnTPl16Lx0RtIEefPDCM5+zkXAhxzy6d2q3Y72NwMNNOLtod0G+/GZUPN6pb3I5KJ\n\taInE0T5tO0ZQ9R40U2GdlMXX8LW1H3i/lFQdG6/IGsbxwFvdLp+eYI2+vzlwo5a8PTcp\n\t3Sr0IrZkQMhrakA7WgAuSCRPB5cOnOS9J4/KJK1Vjw6s39afZ18vHDeJj3qFoUiZB7Ga\n\tbmK1bSX4eR9Q/16V0MCs4PSLx0wKsNK3F8hTTRFkCujwDrpW5G05lCSaHVgSojGDAX18\n\tEhYBFDX1Byjg+qZ40bLQCpAYi2sSXHMynos+CQg/8HHI47A+aE0keRkODdqZqM9RuU3S\n\tdrHg==",
        "X-Gm-Message-State": "AOJu0YwA+gQ1N/mA9gcOJbCRPvg2HPKMuuQapuN+tDarRKlJ+ZUDvmBZ\n\t2P9xYn3OkDOSOxQ5kfwExOs6fP/b2FzoP6uqOPwCtO2MWp+1gr9sV+yppphlHYcHX5Y=",
        "X-Gm-Gg": "AR+sD13O1KLc4mZW7MiDAZS0OvmvCYLQWp0VDiErECRvW5YmoA4pcagIVNBxU6IpiCm\n\tTSLyf4MdTiTjh26y72ZSF5PSftecTV8rjsg37CVVpFLmda0+D72zRcXi0leGiQn93ElCBeVQhFB\n\t5L5nyfk6MHicYGidh1MiCVV4TgUx/tbCslG3LWw5Cu92GsMkgUaCMJ/npyAjem3ni4rH6BYdjCI\n\tY/CDKR6wSP5MXljRZdxjx1uhS+1etQq14K3mqSVJ414/1RbtiUItK732GO5B194qCEgF5Nn1Yuq\n\tiOsTYNyFy4pebZ3y5ukO+sckEtTaVFphQwNoct2SUsDyhPOY1dYuuKOkaMoPwj+29efGBi1bzQ3\n\twuSWu+AYD9df1N5FmksLrZx6G7CY44/3AP3VnmkVdMEfVatH5B7rmmentfTS5OnSd0S+XWQu0BM\n\tCfwt8/s6Ox+QrDNkZ/xl+GiMjUc8BCMIoUknHrVlRH5+YM4MapfKeiOKdvg+jzrME=",
        "X-Received": "by 2002:a05:600c:3509:b0:495:64c6:84e9 with SMTP id\n\t5b1f17b1804b1-496b5648f38mr26903575e9.0.1784985577662; \n\tSat, 25 Jul 2026 06:19:37 -0700 (PDT)",
        "From": "Magdum <magdum.foss@gmail.com>",
        "To": "libcamera-devel@lists.libcamera.org",
        "Cc": "Magdum <magdum.foss@gmail.com>",
        "Subject": "[PATCH v2 2/2] libcamera: Harden control serializer size and input\n\tvalidation",
        "Date": "Sat, 25 Jul 2026 15:14:07 +0200",
        "Message-ID": "<20260725131932.13509-1-magdum.foss@gmail.com>",
        "X-Mailer": "git-send-email 2.43.0",
        "In-Reply-To": "<20260723174644.6580-3-magdum.foss@gmail.com>",
        "References": "<20260723174644.6580-3-magdum.foss@gmail.com>",
        "MIME-Version": "1.0",
        "Content-Type": "text/plain; charset=UTF-8",
        "Content-Transfer-Encoding": "8bit",
        "X-BeenThere": "libcamera-devel@lists.libcamera.org",
        "X-Mailman-Version": "2.1.29",
        "Precedence": "list",
        "List-Id": "<libcamera-devel.lists.libcamera.org>",
        "List-Unsubscribe": "<https://lists.libcamera.org/options/libcamera-devel>,\n\t<mailto:libcamera-devel-request@lists.libcamera.org?subject=unsubscribe>",
        "List-Archive": "<https://lists.libcamera.org/pipermail/libcamera-devel/>",
        "List-Post": "<mailto:libcamera-devel@lists.libcamera.org>",
        "List-Help": "<mailto:libcamera-devel-request@lists.libcamera.org?subject=help>",
        "List-Subscribe": "<https://lists.libcamera.org/listinfo/libcamera-devel>,\n\t<mailto:libcamera-devel-request@lists.libcamera.org?subject=subscribe>",
        "Errors-To": "libcamera-devel-bounces@lists.libcamera.org",
        "Sender": "\"libcamera-devel\" <libcamera-devel-bounces@lists.libcamera.org>"
    },
    "content": "Add overflow-safe size computations before writing 32-bit wire\nfields, centralize control-name size accounting, and validate\ndeserialized local control direction values. Strengthen tests\nwith alignment-safe packet mutation, deterministic malformed\nname-offset corruption, and max-length control-name boundary\ncoverage.\n\nSigned-off-by: Magdum <magdum.foss@gmail.com>\n---\n<<I feel like this function could go into the previous patch.\nAgreed. Moved serializedControlNameSize into the patch that first introduces it.\n\n<<You can adjust this:\n<<   if (rhs && lhs > std::numeric_limits<size_t>::max() / rhs)\n<<     return false;\n<< and drop the previous `if`.\nGood simplification — the rhs && guard makes the explicit zero-case branch unnecessary since lhs * 0 = 0 falls through correctly anyway.\n\n<<You can just say `return *out >= lhs;` and drop the `if`.\nDone\n\n<< But in any case I am a bit wary of these ad-hoc implementations here. Given that\n<<only clang and gcc are supported as compilers, I think it would be preferable to\n<<use the overflow checking builtins: https://gcc.gnu.org/onlinedocs/gcc/Integer-Overflow-Builtins.html\n<<Specifically `__builtin_{add,mul}_overflow`, possibly hidden inside some trivial\n<<wrappers in `utils.h`.\nGood call — replaced both ad-hoc implementations with __builtin_add_overflow / __builtin_mul_overflow wrapped as utils::addOverflow / utils::mulOverflow in utils.h, following the pattern of the existing utils helpers.\n\n<<You can use `utils::to_underlying()`.\nDone\n\n<<You can just say `case (kDirectionIn | kDirectionOut):` here\nDone\n\n<<But you can also simplify the function greatly, e.g.:\n<<   constexpr unsigned int valid = utils::to_underlying(ControlId::Direction::In) | utils::to_underlying(ControlId::Direction::Out);\n<<   return (direction & valid) && !(direction & ~valid);\nDone\n\n========================================================================\nCHANGELOG / COMMENTS FROM REPLY.TXT:\n========================================================================\n\n========================================================================\n include/libcamera/base/utils.h               |  12 ++\n src/libcamera/control_serializer.cpp         | 196 ++++++++++++++++---\n test/serialization/control_serialization.cpp |  86 ++++++--\n 3 files changed, 257 insertions(+), 37 deletions(-)",
    "diff": "diff --git a/include/libcamera/base/utils.h b/include/libcamera/base/utils.h\nindex 9835fd798..d73db428c 100644\n--- a/include/libcamera/base/utils.h\n+++ b/include/libcamera/base/utils.h\n@@ -449,6 +449,18 @@ constexpr details::defopt_t defopt;\n std::ostream &operator<<(std::ostream &os, const Duration &d);\n #endif\n \n+template<typename T>\n+bool addOverflow(T lhs, T rhs, T *result)\n+{\n+\treturn __builtin_add_overflow(lhs, rhs, result);\n+}\n+\n+template<typename T>\n+bool mulOverflow(T lhs, T rhs, T *result)\n+{\n+\treturn __builtin_mul_overflow(lhs, rhs, result);\n+}\n+\n } /* namespace utils */\n \n } /* namespace libcamera */\ndiff --git a/src/libcamera/control_serializer.cpp b/src/libcamera/control_serializer.cpp\nindex a420d4700..ceafff326 100644\n--- a/src/libcamera/control_serializer.cpp\n+++ b/src/libcamera/control_serializer.cpp\n@@ -8,11 +8,13 @@\n #include \"libcamera/internal/control_serializer.h\"\n \n #include <algorithm>\n+#include <limits>\n #include <memory>\n #include <vector>\n \n #include <libcamera/base/log.h>\n #include <libcamera/base/span.h>\n+#include <libcamera/base/utils.h>\n \n #include <libcamera/control_ids.h>\n #include <libcamera/controls.h>\n@@ -53,7 +55,31 @@ bool idMapRequiresLocalIds(enum ipa_controls_id_map_type idMapType)\n size_t serializedControlNameSize(const ControlId *id,\n \t\tenum ipa_controls_id_map_type idMapType)\n {\n-\treturn idMapRequiresLocalIds(idMapType) ? id->name().size() + 1 : 1;\n+\treturn idMapRequiresLocalIds(idMapType) ? id->name().size() : 1;\n+}\n+\n+bool fitsU32(size_t value)\n+{\n+\treturn value <= std::numeric_limits<uint32_t>::max();\n+}\n+\n+bool safeMulSizeT(size_t lhs, size_t rhs, size_t *out)\n+{\n+\treturn !utils::mulOverflow(lhs, rhs, out);\n+}\n+\n+bool safeAddSizeT(size_t lhs, size_t rhs, size_t *out)\n+{\n+\treturn !utils::addOverflow(lhs, rhs, out);\n+}\n+\n+bool isValidDirection(uint8_t direction)\n+{\n+\tconstexpr unsigned int valid =\n+\t\tutils::to_underlying(ControlId::Direction::In) |\n+\t\tutils::to_underlying(ControlId::Direction::Out);\n+\n+\treturn (direction & valid) && !(direction & ~valid);\n }\n \n } /* namespace */\n@@ -190,14 +216,27 @@ size_t ControlSerializer::binarySize(const ControlInfo &info)\n  */\n size_t ControlSerializer::binarySize(const ControlInfoMap &infoMap)\n {\n-\tsize_t size = sizeof(struct ipa_controls_header)\n-\t\t    + infoMap.size() * sizeof(struct ipa_control_info_entry);\n+\tsize_t entriesSize;\n+\tif (!safeMulSizeT(infoMap.size(), sizeof(struct ipa_control_info_entry),\n+\t\t\t  &entriesSize))\n+\t\treturn std::numeric_limits<size_t>::max();\n+\n+\tsize_t size;\n+\tif (!safeAddSizeT(sizeof(struct ipa_controls_header), entriesSize, &size))\n+\t\treturn std::numeric_limits<size_t>::max();\n+\n \tenum ipa_controls_id_map_type idMapType = idMapTypeFor(infoMap.idmap());\n \n \tfor (const auto &ctrl : infoMap) {\n-\t\tsize += binarySize(ctrl.second);\n-\n-\t\tsize += serializedControlNameSize(ctrl.first, idMapType);\n+\t\tsize_t nextSize;\n+\t\tif (!safeAddSizeT(size, binarySize(ctrl.second), &nextSize))\n+\t\t\treturn std::numeric_limits<size_t>::max();\n+\t\tsize = nextSize;\n+\n+\t\tsize_t nameSize = serializedControlNameSize(ctrl.first, idMapType);\n+\t\tif (!safeAddSizeT(size, nameSize, &nextSize))\n+\t\t\treturn std::numeric_limits<size_t>::max();\n+\t\tsize = nextSize;\n \t}\n \n \treturn size;\n@@ -214,10 +253,21 @@ size_t ControlSerializer::binarySize(const ControlInfoMap &infoMap)\n  */\n size_t ControlSerializer::binarySize(const ControlList &list)\n {\n-\tsize_t size = sizeof(struct ipa_controls_header) + list.size() * sizeof(struct ipa_control_list_entry);\n+\tsize_t entriesSize;\n+\tif (!safeMulSizeT(list.size(), sizeof(struct ipa_control_list_entry),\n+\t\t\t  &entriesSize))\n+\t\treturn std::numeric_limits<size_t>::max();\n+\n+\tsize_t size;\n+\tif (!safeAddSizeT(sizeof(struct ipa_controls_header), entriesSize, &size))\n+\t\treturn std::numeric_limits<size_t>::max();\n \n-\tfor (const auto &ctrl : list)\n-\t\tsize += binarySize(ctrl.second);\n+\tfor (const auto &ctrl : list) {\n+\t\tsize_t nextSize;\n+\t\tif (!safeAddSizeT(size, binarySize(ctrl.second), &nextSize))\n+\t\t\treturn std::numeric_limits<size_t>::max();\n+\t\tsize = nextSize;\n+\t}\n \n \treturn size;\n }\n@@ -264,23 +314,70 @@ int ControlSerializer::serialize(const ControlInfoMap &infoMap,\n \tenum ipa_controls_id_map_type idMapType = idMapTypeFor(infoMap.idmap());\n \n \t/* Compute entries and data required sizes. */\n-\tsize_t entriesSize = infoMap.size()\n-\t\t\t   * sizeof(struct ipa_control_info_entry);\n+\tsize_t entriesSize;\n+\tif (!safeMulSizeT(infoMap.size(), sizeof(struct ipa_control_info_entry),\n+\t\t\t  &entriesSize)) {\n+\t\tLOG(Serializer, Error)\n+\t\t\t<< \"ControlInfoMap entries size overflows\";\n+\t\treturn -E2BIG;\n+\t}\n+\n \tsize_t valuesSize = 0;\n \tfor (const auto &ctrl : infoMap) {\n-\t\tvaluesSize += binarySize(ctrl.second);\n-\t\tvaluesSize += idMapRequiresLocalIds(idMapType)\n-\t\t\t\t      ? ctrl.first->name().size()\n-\t\t\t\t      : 0;\n+\t\tsize_t valueSize = binarySize(ctrl.second);\n+\t\tsize_t nextValuesSize;\n+\t\tif (!safeAddSizeT(valuesSize, valueSize, &nextValuesSize)) {\n+\t\t\tLOG(Serializer, Error)\n+\t\t\t\t<< \"ControlInfoMap values size overflows\";\n+\t\t\treturn -E2BIG;\n+\t\t}\n+\t\tvaluesSize = nextValuesSize;\n+\n+\t\tsize_t nameSize = serializedControlNameSize(ctrl.first, idMapType);\n+\t\tif (!safeAddSizeT(valuesSize, nameSize, &nextValuesSize)) {\n+\t\t\tLOG(Serializer, Error)\n+\t\t\t\t<< \"ControlInfoMap names size overflows\";\n+\t\t\treturn -E2BIG;\n+\t\t}\n+\t\tvaluesSize = nextValuesSize;\n+\t}\n+\n+\tif (!fitsU32(infoMap.size()) || !fitsU32(entriesSize) ||\n+\t    !fitsU32(valuesSize)) {\n+\t\tLOG(Serializer, Error)\n+\t\t\t<< \"ControlInfoMap serialization size exceeds wire limits\";\n+\t\treturn -E2BIG;\n+\t}\n+\n+\tsize_t totalSize;\n+\tif (!safeAddSizeT(sizeof(struct ipa_controls_header), entriesSize,\n+\t\t\t  &totalSize) ||\n+\t    !safeAddSizeT(totalSize, valuesSize, &totalSize)) {\n+\t\tLOG(Serializer, Error)\n+\t\t\t<< \"ControlInfoMap packet size overflows\";\n+\t\treturn -E2BIG;\n+\t}\n+\n+\tsize_t dataOffset;\n+\tif (!safeAddSizeT(sizeof(struct ipa_controls_header), entriesSize,\n+\t\t\t  &dataOffset)) {\n+\t\tLOG(Serializer, Error)\n+\t\t\t<< \"ControlInfoMap data offset overflows\";\n+\t\treturn -E2BIG;\n+\t}\n+\tif (!fitsU32(totalSize) || !fitsU32(dataOffset)) {\n+\t\tLOG(Serializer, Error)\n+\t\t\t<< \"ControlInfoMap packet header exceeds wire limits\";\n+\t\treturn -E2BIG;\n \t}\n \n \t/* Prepare the packet header. */\n \tstruct ipa_controls_header hdr = {};\n \thdr.version = IPA_CONTROLS_FORMAT_VERSION;\n \thdr.handle = serial_;\n-\thdr.entries = infoMap.size();\n-\thdr.size = sizeof(hdr) + entriesSize + valuesSize;\n-\thdr.data_offset = sizeof(hdr) + entriesSize;\n+\thdr.entries = static_cast<uint32_t>(infoMap.size());\n+\thdr.size = static_cast<uint32_t>(totalSize);\n+\thdr.data_offset = static_cast<uint32_t>(dataOffset);\n \thdr.id_map_type = idMapType;\n \n \tbuffer.write(&hdr);\n@@ -389,18 +486,62 @@ int ControlSerializer::serialize(const ControlList &list,\n \telse\n \t\tidMapType = IPA_CONTROL_ID_MAP_V4L2;\n \n-\tsize_t entriesSize = list.size() * sizeof(struct ipa_control_list_entry);\n+\tsize_t entriesSize;\n+\tif (!safeMulSizeT(list.size(), sizeof(struct ipa_control_list_entry),\n+\t\t\t  &entriesSize)) {\n+\t\tLOG(Serializer, Error)\n+\t\t\t<< \"ControlList entries size overflows\";\n+\t\treturn -E2BIG;\n+\t}\n+\n \tsize_t valuesSize = 0;\n-\tfor (const auto &ctrl : list)\n-\t\tvaluesSize += binarySize(ctrl.second);\n+\tfor (const auto &ctrl : list) {\n+\t\tsize_t nextValuesSize;\n+\t\tif (!safeAddSizeT(valuesSize, binarySize(ctrl.second),\n+\t\t\t\t  &nextValuesSize)) {\n+\t\t\tLOG(Serializer, Error)\n+\t\t\t\t<< \"ControlList values size overflows\";\n+\t\t\treturn -E2BIG;\n+\t\t}\n+\t\tvaluesSize = nextValuesSize;\n+\t}\n+\n+\tif (!fitsU32(list.size()) || !fitsU32(entriesSize) ||\n+\t    !fitsU32(valuesSize)) {\n+\t\tLOG(Serializer, Error)\n+\t\t\t<< \"ControlList serialization size exceeds wire limits\";\n+\t\treturn -E2BIG;\n+\t}\n+\n+\tsize_t totalSize;\n+\tif (!safeAddSizeT(sizeof(struct ipa_controls_header), entriesSize,\n+\t\t\t  &totalSize) ||\n+\t    !safeAddSizeT(totalSize, valuesSize, &totalSize)) {\n+\t\tLOG(Serializer, Error)\n+\t\t\t<< \"ControlList packet size overflows\";\n+\t\treturn -E2BIG;\n+\t}\n+\n+\tsize_t dataOffset;\n+\tif (!safeAddSizeT(sizeof(struct ipa_controls_header), entriesSize,\n+\t\t\t  &dataOffset)) {\n+\t\tLOG(Serializer, Error)\n+\t\t\t<< \"ControlList data offset overflows\";\n+\t\treturn -E2BIG;\n+\t}\n+\tif (!fitsU32(totalSize) || !fitsU32(dataOffset)) {\n+\t\tLOG(Serializer, Error)\n+\t\t\t<< \"ControlList packet header exceeds wire limits\";\n+\t\treturn -E2BIG;\n+\t}\n \n \t/* Prepare the packet header. */\n \tstruct ipa_controls_header hdr = {};\n \thdr.version = IPA_CONTROLS_FORMAT_VERSION;\n \thdr.handle = infoMapHandle;\n-\thdr.entries = list.size();\n-\thdr.size = sizeof(hdr) + entriesSize + valuesSize;\n-\thdr.data_offset = sizeof(hdr) + entriesSize;\n+\thdr.entries = static_cast<uint32_t>(list.size());\n+\thdr.size = static_cast<uint32_t>(totalSize);\n+\thdr.data_offset = static_cast<uint32_t>(dataOffset);\n \thdr.id_map_type = idMapType;\n \n \tbuffer.write(&hdr);\n@@ -586,6 +727,13 @@ ControlInfoMap ControlSerializer::deserialize<ControlInfoMap>(ByteStreamBuffer &\n \n \t\t/* If we're using a local id map, populate it with the restored name. */\n \t\tif (localIdMap) {\n+\t\t\tif (!isValidDirection(entry->direction)) {\n+\t\t\t\tLOG(Serializer, Error)\n+\t\t\t\t\t<< \"Control direction is invalid: \"\n+\t\t\t\t\t<< static_cast<unsigned int>(entry->direction);\n+\t\t\t\treturn {};\n+\t\t\t}\n+\n \t\t\tstd::string ctrlName(reinterpret_cast<const char *>(nameData),\n \t\t\t\t\t     entry->name_len);\n \ndiff --git a/test/serialization/control_serialization.cpp b/test/serialization/control_serialization.cpp\nindex b1638db9f..1fb8cc8b7 100644\n--- a/test/serialization/control_serialization.cpp\n+++ b/test/serialization/control_serialization.cpp\n@@ -6,6 +6,7 @@\n  */\n \n #include <iostream>\n+#include <cstring>\n \n #include <libcamera/camera.h>\n #include <libcamera/control_ids.h>\n@@ -224,11 +225,13 @@ protected:\n \n \t\t/* Reject malformed packets with over-sized names. */\n \t\tvector<uint8_t> badNameLenData = infoData;\n-\t\tauto *badNameLenHeader =\n-\t\t\treinterpret_cast<ipa_controls_header *>(badNameLenData.data());\n-\t\tauto *badNameLenEntry = reinterpret_cast<ipa_control_info_entry *>(\n-\t\t\tbadNameLenData.data() + sizeof(*badNameLenHeader));\n-\t\tbadNameLenEntry->name_len = 2048;\n+\t\tipa_control_info_entry badNameLenEntry;\n+\t\tstd::memcpy(&badNameLenEntry,\n+\t\t\t    badNameLenData.data() + sizeof(ipa_controls_header),\n+\t\t\t    sizeof(badNameLenEntry));\n+\t\tbadNameLenEntry.name_len = 2048;\n+\t\tstd::memcpy(badNameLenData.data() + sizeof(ipa_controls_header),\n+\t\t\t    &badNameLenEntry, sizeof(badNameLenEntry));\n \n \t\tControlSerializer badNameLenDeserializer(ControlSerializer::Role::Worker);\n \t\tbuffer = ByteStreamBuffer(const_cast<const uint8_t *>(badNameLenData.data()),\n@@ -238,15 +241,31 @@ protected:\n \t\t\treturn TestFail;\n \t\t}\n \n-\t\t/* Reject malformed packets with non-null-terminated names. */\n-\t\tvector<uint8_t> badTermData = infoData;\n-\t\tbadTermData.back() = 'X';\n+\t\t/* Reject malformed packets with inconsistent name offsets. */\n+\t\tvector<uint8_t> badNameOffsetData = infoData;\n+\t\tipa_control_info_entry badNameOffsetEntry;\n+\t\tstd::memcpy(&badNameOffsetEntry,\n+\t\t\t    badNameOffsetData.data() + sizeof(ipa_controls_header),\n+\t\t\t    sizeof(badNameOffsetEntry));\n+\n+\t\tif (badNameOffsetEntry.id != kV4L2TestControlId ||\n+\t\t    badNameOffsetEntry.type != ControlTypeInteger32 ||\n+\t\t    badNameOffsetEntry.def.type != ControlTypeInteger32 ||\n+\t\t    badNameOffsetEntry.def.is_array || badNameOffsetEntry.def.count != 1 ||\n+\t\t    badNameOffsetEntry.name_len != kV4L2ControlName.size()) {\n+\t\t\tcerr << \"Malformed test packet layout for bad name offset test\" << endl;\n+\t\t\treturn TestFail;\n+\t\t}\n+\n+\t\tbadNameOffsetEntry.name_offset += 1;\n+\t\tstd::memcpy(badNameOffsetData.data() + sizeof(ipa_controls_header),\n+\t\t\t    &badNameOffsetEntry, sizeof(badNameOffsetEntry));\n \n-\t\tControlSerializer badTermDeserializer(ControlSerializer::Role::Worker);\n-\t\tbuffer = ByteStreamBuffer(const_cast<const uint8_t *>(badTermData.data()),\n-\t\t\t\t\t  badTermData.size());\n-\t\tif (!badTermDeserializer.deserialize<ControlInfoMap>(buffer).empty()) {\n-\t\t\tcerr << \"Control name without null terminator should be rejected\" << endl;\n+\t\tControlSerializer badNameOffsetDeserializer(ControlSerializer::Role::Worker);\n+\t\tbuffer = ByteStreamBuffer(const_cast<const uint8_t *>(badNameOffsetData.data()),\n+\t\t\t\t\t  badNameOffsetData.size());\n+\t\tif (!badNameOffsetDeserializer.deserialize<ControlInfoMap>(buffer).empty()) {\n+\t\t\tcerr << \"Control with inconsistent name offset should be rejected\" << endl;\n \t\t\treturn TestFail;\n \t\t}\n \n@@ -278,6 +297,47 @@ protected:\n \t\t\treturn TestFail;\n \t\t}\n \n+\t\t/* Accept names at the configured length limit. */\n+\t\tvector<unique_ptr<ControlId>> maxNameControlIds;\n+\t\tControlIdMap maxNameIdMap;\n+\t\tstring maxName(1024, 'm');\n+\n+\t\tmaxNameControlIds.emplace_back(std::make_unique<ControlId>(\n+\t\t\t0x009a2003, maxName, \"v4l2\", ControlTypeInteger32,\n+\t\t\tControlId::Direction::In));\n+\t\tmaxNameIdMap.emplace(0x009a2003, maxNameControlIds.back().get());\n+\n+\t\tControlInfoMap::Map maxNameInfo;\n+\t\tmaxNameInfo.emplace(maxNameControlIds.back().get(),\n+\t\t\t\t    ControlInfo(ControlValue(int32_t{ 0 }),\n+\t\t\t\t\t\tControlValue(int32_t{ 255 }),\n+\t\t\t\t\t\tControlValue(int32_t{ 16 })));\n+\t\tControlInfoMap maxNameInfoMap(std::move(maxNameInfo), maxNameIdMap);\n+\n+\t\tControlSerializer maxNameSerializer(ControlSerializer::Role::Proxy);\n+\t\tControlSerializer maxNameDeserializer(ControlSerializer::Role::Worker);\n+\n+\t\tsize = maxNameSerializer.binarySize(maxNameInfoMap);\n+\t\tinfoData.resize(size);\n+\t\tbuffer = ByteStreamBuffer(infoData.data(), infoData.size());\n+\n+\t\tret = maxNameSerializer.serialize(maxNameInfoMap, buffer);\n+\t\tif (ret < 0 || buffer.overflow()) {\n+\t\t\tcerr << \"Max-length control name should serialize successfully\" << endl;\n+\t\t\treturn TestFail;\n+\t\t}\n+\n+\t\tbuffer = ByteStreamBuffer(const_cast<const uint8_t *>(infoData.data()),\n+\t\t\t\t\t  infoData.size());\n+\t\tControlInfoMap maxNameInfoMapDes =\n+\t\t\tmaxNameDeserializer.deserialize<ControlInfoMap>(buffer);\n+\t\tauto maxNameIdIt = maxNameInfoMapDes.idmap().find(0x009a2003);\n+\t\tif (maxNameIdIt == maxNameInfoMapDes.idmap().end() ||\n+\t\t    maxNameIdIt->second->name() != maxName) {\n+\t\t\tcerr << \"Max-length control name round-trip failed\" << endl;\n+\t\t\treturn TestFail;\n+\t\t}\n+\n \t\treturn TestPass;\n \t}\n };\n",
    "prefixes": [
        "v2",
        "2/2"
    ]
}