Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.kernel > #94144 > unrolled thread

Bug#1148364: riscv64: strnlen() returns a truncated length for very large count, breaking ACPI name resolution (AE_AML_NAME_NOT_FOUND flood at boot)

Started byAurelien Jarno <aurel32@debian.org>
First post2026-09-19 12:00 +0200
Last post2026-09-22 08:30 +0200
Articles 2 — 2 participants

Back to article view | Back to linux.debian.kernel

This discussion starts older than the indexed window; earlier articles aren't shown. The article labeled Started by below is the oldest one visible, not the original post.


Contents

  Bug#1148364: riscv64: strnlen() returns a truncated length for very large count, breaking ACPI name resolution (AE_AML_NAME_NOT_FOUND flood at boot) Aurelien Jarno <aurel32@debian.org> - 2026-09-19 12:00 +0200
    Bug#1148364: riscv64: strnlen() returns a truncated length for very large count, breaking ACPI name resolution (AE_AML_NAME_NOT_FOUND flood at boot) Troy Mitchell <me@troy-y.org> - 2026-09-22 08:30 +0200

#94144 — Bug#1148364: riscv64: strnlen() returns a truncated length for very large count, breaking ACPI name resolution (AE_AML_NAME_NOT_FOUND flood at boot)

FromAurelien Jarno <aurel32@debian.org>
Date2026-09-19 12:00 +0200
SubjectBug#1148364: riscv64: strnlen() returns a truncated length for very large count, breaking ACPI name resolution (AE_AML_NAME_NOT_FOUND flood at boot)
Message-ID<NF01s-wmw-9@gated-at.bofh.it>
control: forwarded -1 https://lore.kernel.org/all/20260915152656708z04s4oSYY2BGj34F36RZa@zte.com.cn/
control: forcemerge -1 1148365

Hi,

On 2026-09-19 16:49, Lufei Zheng wrote:
> Package: linux-image-7.1.13+deb14-riscv64
> Version: 7.1.13-1
> Severity: important
> Tags: upstream
> X-Debbugs-Cc: debian-riscv@lists.debian.org
> 
> Dear maintainers,
> 
> arch/riscv/lib/strnlen.S has an integer-overflow bug: for a very large `count` (in practice `(size_t)-1`) the address computation `s + count` wraps around 2^64, the loop bound becomes smaller than the start address, and strnlen() returns a length derived only from the first machine word(typically 8).  The same wrap exists in the byte-loop fallback.

The issue has been reported upstream with a patch [1], but it is still 
under review. If you can test it and send a Tested-by: that would help 
the patch to get accepted faster.

It will get added to the debian kernel once it get fixed upstream.

Regards
Aurelien

[1] https://lore.kernel.org/all/20260915152656708z04s4oSYY2BGj34F36RZa@zte.com.cn/

-- 
Aurelien Jarno                          GPG: 4096R/1DDD8C9B
aurelien@aurel32.net                     http://aurel32.net

[toc] | [next] | [standalone]


#94159

FromTroy Mitchell <me@troy-y.org>
Date2026-09-22 08:30 +0200
Message-ID<NG2aR-15gA-1@gated-at.bofh.it>
In reply to#94144
Hi Aurelien,

> The issue has been reported upstream with a patch [1], but it is still
> under review. If you can test it and send a Tested-by: that would help
> the patch to get accepted faster.

I tested v4 on QEMU 11.1.1 (riscv64), using a custom-configured kernel
built from Debian linux 7.2.6-1 sources and calling the kernel's
strnlen() directly.

With Zbb enabled, a 63-byte string with count=SIZE_MAX returned 8 before
the patch. With v4 applied, the same call correctly returned 63.
With count=1000, it returned 63 both before and after the patch.

The alignment and word/page-boundary cases I checked also returned the
expected results after applying v4. With Zbb disabled, I did not observe
incorrect results either before or after the patch.

I have sent my TB to the upstream v4 thread. I do not have access
to a V100, so I have not verified the reported ACPI boot errors on that
hardware.

-- 
Troy Mitchell

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.kernel


csiph-web