From: Doug Anderson <dianders@chromium.org>
To: u-boot@lists.denx.de
Subject: [U-Boot] [PATCH v4] bootm: Avoid 256-byte overflow in fixup_silent_linux()
Date: Tue, 17 Jan 2012 11:37:41 -0800 [thread overview]
Message-ID: <1326829061-4682-1-git-send-email-dianders@chromium.org> (raw)
In-Reply-To: <1326305992-27939-1-git-send-email-dianders@chromium.org>
This makes fixup_silent_linux() use malloc() to allocate its
working space, meaning that our maximum kernel command line
should only be limited by malloc(). Previously it was silently
overflowing the stack.
Note that nothing about this change increases the kernel's maximum
command line length. If you have a command line that is >256
bytes it's up to you to make sure that kernel can handle it.
Signed-off-by: Doug Anderson <dianders@chromium.org>
---
Changes in v2:
- Tried to trim down to just the minimum changes needed with
no extra helper code.
Changes in v3:
- Took Mike Frysinger's suggestion of removing strdup()
Changes in v4:
- Added in const
common/cmd_bootm.c | 41 +++++++++++++++++++++++++++++------------
1 files changed, 29 insertions(+), 12 deletions(-)
diff --git a/common/cmd_bootm.c b/common/cmd_bootm.c
index d5745b1..0a5ac81 100644
--- a/common/cmd_bootm.c
+++ b/common/cmd_bootm.c
@@ -1229,9 +1229,14 @@ U_BOOT_CMD(
/* helper routines */
/*******************************************************************/
#ifdef CONFIG_SILENT_CONSOLE
+
+#define CONSOLE_ARG "console="
+#define CONSOLE_ARG_LEN (sizeof(CONSOLE_ARG) - 1)
+
static void fixup_silent_linux(void)
{
- char buf[256], *start, *end;
+ char *buf;
+ const char *env_val;
char *cmdline = getenv("bootargs");
/* Only fix cmdline when requested */
@@ -1239,25 +1244,37 @@ static void fixup_silent_linux(void)
return;
debug("before silent fix-up: %s\n", cmdline);
- if (cmdline) {
- start = strstr(cmdline, "console=");
+ if (cmdline && (cmdline[0] != '\0')) {
+ char *start = strstr(cmdline, CONSOLE_ARG);
+
+ /* Allocate space for maximum possible new command line */
+ buf = malloc(strlen(cmdline) + 1 + CONSOLE_ARG_LEN + 1);
+ if (!buf) {
+ debug("%s: out of memory\n", __func__);
+ return;
+ }
+
if (start) {
- end = strchr(start, ' ');
- strncpy(buf, cmdline, (start - cmdline + 8));
+ char *end = strchr(start, ' ');
+ int num_start_bytes = start - cmdline + CONSOLE_ARG_LEN;
+
+ strncpy(buf, cmdline, num_start_bytes);
if (end)
- strcpy(buf + (start - cmdline + 8), end);
+ strcpy(buf + num_start_bytes, end);
else
- buf[start - cmdline + 8] = '\0';
+ buf[num_start_bytes] = '\0';
} else {
- strcpy(buf, cmdline);
- strcat(buf, " console=");
+ sprintf(buf, "%s %s", cmdline, CONSOLE_ARG);
}
+ env_val = buf;
} else {
- strcpy(buf, "console=");
+ buf = NULL;
+ env_val = CONSOLE_ARG;
}
- setenv("bootargs", buf);
- debug("after silent fix-up: %s\n", buf);
+ setenv("bootargs", env_val);
+ debug("after silent fix-up: %s\n", env_val);
+ free(buf);
}
#endif /* CONFIG_SILENT_CONSOLE */
--
1.7.7.3
next prev parent reply other threads:[~2012-01-17 19:37 UTC|newest]
Thread overview: 39+ messages / expand[flat|nested] mbox.gz Atom feed top
2011-10-19 22:30 [U-Boot] [PATCH 0/4] Fix fixup_silent_linux() buffer overrun Doug Anderson
2011-10-19 22:30 ` [U-Boot] [PATCH 1/4] cmdline: Add linux command line munging tools Doug Anderson
2011-10-19 22:46 ` Mike Frysinger
2011-10-20 1:23 ` Doug Anderson
2011-10-19 22:52 ` Mike Frysinger
2011-10-20 1:07 ` Doug Anderson
2011-10-20 1:37 ` Mike Frysinger
2011-10-20 14:36 ` Wolfgang Denk
2011-10-20 17:06 ` Doug Anderson
2011-10-20 17:15 ` Mike Frysinger
2011-10-20 18:23 ` Doug Anderson
2011-10-20 19:33 ` Wolfgang Denk
2011-10-20 19:03 ` Wolfgang Denk
2011-10-21 5:09 ` Doug Anderson
2011-10-19 22:30 ` [U-Boot] [PATCH 2/4] cosmetic: Fixup fixup_silent_linux() for checkpatch Doug Anderson
2011-10-20 14:38 ` Wolfgang Denk
2011-10-19 22:30 ` [U-Boot] [PATCH 3/4] bootm: Avoid 256-byte overflow in fixup_silent_linux() Doug Anderson
2011-10-19 22:51 ` Mike Frysinger
2011-10-20 14:40 ` Wolfgang Denk
2011-10-20 17:54 ` [U-Boot] [PATCH v2] " Doug Anderson
2012-01-10 22:28 ` Wolfgang Denk
2012-01-10 22:51 ` Doug Anderson
2012-01-10 23:31 ` Mike Frysinger
2012-01-10 23:30 ` Mike Frysinger
2012-01-11 18:19 ` Doug Anderson
2012-01-15 1:32 ` Mike Frysinger
2012-01-17 19:16 ` [U-Boot] [PATCH v3] " Doug Anderson
2012-01-17 19:27 ` Mike Frysinger
2012-01-17 19:33 ` Doug Anderson
2012-01-17 19:37 ` Doug Anderson [this message]
2012-01-17 19:55 ` [U-Boot] [PATCH v4] " Mike Frysinger
2013-05-22 14:59 ` [U-Boot] [U-Boot, " Tom Rini
2011-10-19 22:30 ` [U-Boot] [PATCH 4/4] bootm: Add earlyprintk to fixup_silent_linux Doug Anderson
2011-10-19 22:35 ` Mike Frysinger
2011-10-19 22:46 ` Doug Anderson
2011-10-19 23:11 ` Mike Frysinger
2011-10-20 14:42 ` Wolfgang Denk
2011-10-20 17:35 ` Doug Anderson
2011-10-20 19:26 ` Wolfgang Denk
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=1326829061-4682-1-git-send-email-dianders@chromium.org \
--to=dianders@chromium.org \
--cc=u-boot@lists.denx.de \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.