Fix flash bounds check

This commit is contained in:
Kevin Thomas
2026-05-09 16:40:32 -04:00
parent 81a746346c
commit 8edeec2bd7
4 changed files with 42 additions and 12 deletions
+13 -6
View File
@@ -38,13 +38,15 @@
/**
* @brief Erase the containing sector(s) and program data to flash.
*
* The data buffer must reside in RAM (not flash). Interrupts
* are disabled for the duration of the erase/program cycle.
* The write length must be a multiple of FLASH_PAGE_SIZE
* (256 bytes); pad with 0xFF if necessary.
* The data buffer must reside in RAM (not flash). Guards against
* NULL @p data and out-of-range @p offset, returning immediately
* if either is invalid. If @p len would exceed the flash boundary
* it is clamped to the remaining space. Interrupts are disabled
* for the erase/program cycle. The write length must be a multiple
* of FLASH_PAGE_SIZE (256 bytes); pad with 0xFF if necessary.
*
* @param offset byte offset from the start of flash (sector-aligned)
* @param data pointer to the source buffer in RAM
* @param data pointer to the source buffer in RAM (must not be NULL)
* @param len number of bytes to write
* @retval None
*/
@@ -52,8 +54,13 @@ void flash_write(uint32_t offset, const uint8_t *data, uint32_t len);
/**
* @brief Read bytes from on-chip flash via the XIP memory map.
*
* Guards against NULL @p out and out-of-range @p offset, returning
* immediately if either is invalid. If @p len would exceed the flash
* boundary it is clamped to the remaining space before the read.
*
* @param offset byte offset from the start of flash
* @param out pointer to the destination buffer
* @param out pointer to the destination buffer (must not be NULL)
* @param len number of bytes to read
* @retval None
*/
@@ -123,6 +123,10 @@ static void flash_erase_program_ram(const FlashRomFns *fns, uint32_t offset,
void flash_write(uint32_t offset, const uint8_t *data, uint32_t len)
{
if (data == NULL || offset >= FLASH_SIZE)
return;
if (len > FLASH_SIZE - offset)
len = FLASH_SIZE - offset;
FlashRomFns fns;
lookup_rom_fns(&fns);
uint32_t primask;
@@ -134,6 +138,10 @@ void flash_write(uint32_t offset, const uint8_t *data, uint32_t len)
void flash_read(uint32_t offset, uint8_t *out, uint32_t len)
{
if (out == NULL || offset >= FLASH_SIZE)
return;
if (len > FLASH_SIZE - offset)
len = FLASH_SIZE - offset;
const uint8_t *src = (const uint8_t *)(XIP_BASE + offset);
for (uint32_t i = 0; i < len; i++)
out[i] = src[i];