summaryrefslogtreecommitdiff
path: root/src
diff options
context:
space:
mode:
authorJavid Khan <[email protected]>2026-07-30 14:13:50 +0530
committerJavid Khan <[email protected]>2026-07-30 14:13:50 +0530
commit15dd3120ac4a9dea0d979dc541ef8e0f52f5aa26 (patch)
treed17d56174bcd8862581075132cf921a0a291d783 /src
parenteef5af86aa26fe3d72e41156a586a6ed3ffce9f8 (diff)
clamp committed video payload size to streaming ep buffer
Signed-off-by: Javid Khan <[email protected]>
Diffstat (limited to 'src')
-rw-r--r--src/class/video/video_device.c6
1 files changed, 6 insertions, 0 deletions
diff --git a/src/class/video/video_device.c b/src/class/video/video_device.c
index 3797e6b2b..390349f13 100644
--- a/src/class/video/video_device.c
+++ b/src/class/video/video_device.c
@@ -1145,6 +1145,12 @@ static int handle_video_stm_cs_req(uint8_t rhport, uint8_t stage,
TU_VERIFY(_update_streaming_parameters(stm, param), VIDEO_ERROR_INVALID_VALUE_WITHIN_RANGE);
/* Set the negotiated value */
stm->max_payload_transfer_size = param->dwMaxPayloadTransferSize;
+ /* A host may commit before the parameters are fully negotiated, in which case
+ * _update_streaming_parameters returns early without capping the payload size.
+ * Clamp here so a bulk stream cannot overrun the endpoint buffer. */
+ if (CFG_TUD_VIDEO_STREAMING_EP_BUFSIZE < stm->max_payload_transfer_size) {
+ stm->max_payload_transfer_size = CFG_TUD_VIDEO_STREAMING_EP_BUFSIZE;
+ }
int ret = tud_video_commit_cb(stm->index_vc, stm->index_vs, param);
if (VIDEO_ERROR_NONE == ret) {
stm->state = VS_STATE_COMMITTED;