Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1491145 > unrolled thread

[PATCH 1/2] x86/RAS/mce_amd_inj: Fix signed wrap around when decrementing index i

Started byBorislav Petkov <bp@alien8.de>
First post2016-09-26 10:40 +0200
Last post2016-09-26 18:40 +0200
Articles 2 — 2 participants

Back to article view | Back to linux.kernel

This discussion starts older than the indexed window; earlier articles aren't shown. The article labeled Started by below is the oldest one visible, not the original post.


Contents

  [PATCH 1/2] x86/RAS/mce_amd_inj: Fix signed wrap around when decrementing index i Borislav Petkov <bp@alien8.de> - 2016-09-26 10:40 +0200
    [tip:ras/core] x86/RAS/mce_amd_inj: Fix signed wrap around when  decrementing index 'i' tip-bot for Colin Ian King <tipbot@zytor.com> - 2016-09-26 18:40 +0200

#1491145 — [PATCH 1/2] x86/RAS/mce_amd_inj: Fix signed wrap around when decrementing index i

FromBorislav Petkov <bp@alien8.de>
Date2016-09-26 10:40 +0200
Subject[PATCH 1/2] x86/RAS/mce_amd_inj: Fix signed wrap around when decrementing index i
Message-ID<slzCa-1yg-15@gated-at.bofh.it>
From: Colin Ian King <colin.king@canonical.com>

Change predecrement compare to post decrement compare to avoid an
unsigned integer wrap-around comparisomn when decrementing in the while
loop.

For example, if the debugfs_create_file() fails when i is zero, the
current situation will predecrement i in the while loop, wrapping i to
the maximum signed integer and cause multiple out of bounds reads on
dfs_fls[i].d as the loop interates to zero.

Also, as Borislav Petkov suggested, return -ENODEV rather than -ENOMEM
on the error condition.

Signed-off-by: Colin Ian King <colin.king@canonical.com>
Cc: Yazen Ghannam <Yazen.Ghannam@amd.com>
Cc: x86-ml <x86@kernel.org>
Link: http://lkml.kernel.org/r/20160917101750.6436-1-colin.king@canonical.com
Signed-off-by: Borislav Petkov <bp@suse.de>
---
 arch/x86/ras/mce_amd_inj.c | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

diff --git a/arch/x86/ras/mce_amd_inj.c b/arch/x86/ras/mce_amd_inj.c
index cd318d93099e..20b227f63407 100644
--- a/arch/x86/ras/mce_amd_inj.c
+++ b/arch/x86/ras/mce_amd_inj.c
@@ -464,13 +464,13 @@ static int __init init_mce_inject(void)
 	return 0;
 
 err_dfs_add:
-	while (--i >= 0)
+	while (i-- > 0)
 		debugfs_remove(dfs_fls[i].d);
 
 	debugfs_remove(dfs_inj);
 	dfs_inj = NULL;
 
-	return -ENOMEM;
+	return -ENODEV;
 }
 
 static void __exit exit_mce_inject(void)
-- 
2.10.0

[toc] | [next] | [standalone]


#1491424 — [tip:ras/core] x86/RAS/mce_amd_inj: Fix signed wrap around when decrementing index 'i'

Fromtip-bot for Colin Ian King <tipbot@zytor.com>
Date2016-09-26 18:40 +0200
Subject[tip:ras/core] x86/RAS/mce_amd_inj: Fix signed wrap around when decrementing index 'i'
Message-ID<slH6G-6aE-19@gated-at.bofh.it>
In reply to#1491145
Commit-ID:  8b44f00f8c952ab6eb658090383571b2ec7d253f
Gitweb:     http://git.kernel.org/tip/8b44f00f8c952ab6eb658090383571b2ec7d253f
Author:     Colin Ian King <colin.king@canonical.com>
AuthorDate: Mon, 26 Sep 2016 10:31:51 +0200
Committer:  Ingo Molnar <mingo@kernel.org>
CommitDate: Mon, 26 Sep 2016 11:13:17 +0200

x86/RAS/mce_amd_inj: Fix signed wrap around when decrementing index 'i'

Change predecrement compare to post decrement compare to avoid an
unsigned integer wrap-around comparisomn when decrementing in the while
loop.

For example, if the debugfs_create_file() fails when 'i' is zero, the
current situation will predecrement 'i' in the while loop, wrapping 'i' to
the maximum signed integer and cause multiple out of bounds reads on
dfs_fls[i].d as the loop interates to zero.

Also, as Borislav Petkov suggested, return -ENODEV rather than -ENOMEM
on the error condition.

Signed-off-by: Colin Ian King <colin.king@canonical.com>
Signed-off-by: Borislav Petkov <bp@suse.de>
Cc: Linus Torvalds <torvalds@linux-foundation.org>
Cc: Peter Zijlstra <peterz@infradead.org>
Cc: Thomas Gleixner <tglx@linutronix.de>
Cc: Yazen Ghannam <Yazen.Ghannam@amd.com>
Link: http://lkml.kernel.org/r/20160926083152.30848-2-bp@alien8.de
Signed-off-by: Ingo Molnar <mingo@kernel.org>
---
 arch/x86/ras/mce_amd_inj.c | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

diff --git a/arch/x86/ras/mce_amd_inj.c b/arch/x86/ras/mce_amd_inj.c
index cd318d9..20b227f 100644
--- a/arch/x86/ras/mce_amd_inj.c
+++ b/arch/x86/ras/mce_amd_inj.c
@@ -464,13 +464,13 @@ static int __init init_mce_inject(void)
 	return 0;
 
 err_dfs_add:
-	while (--i >= 0)
+	while (i-- > 0)
 		debugfs_remove(dfs_fls[i].d);
 
 	debugfs_remove(dfs_inj);
 	dfs_inj = NULL;
 
-	return -ENOMEM;
+	return -ENODEV;
 }
 
 static void __exit exit_mce_inject(void)

[toc] | [prev] | [standalone]


Back to top | Article view | linux.kernel


csiph-web