From: Wolfgang Denk <wd@denx.de>
To: u-boot@lists.denx.de
Subject: [U-Boot] [PATCH v2] bootm: Avoid 256-byte overflow in fixup_silent_linux()
Date: Tue, 10 Jan 2012 23:28:05 +0100 [thread overview]
Message-ID: <20120110222805.2A0AE1167AA4@gemini.denx.de> (raw)
In-Reply-To: <1319133298-30249-1-git-send-email-dianders@chromium.org>
Dear Doug Anderson,
In message <1319133298-30249-1-git-send-email-dianders@chromium.org> you wrote:
> This makes fixup_silent_linux() use malloc() to allocate its
> working space, meaning that our maximum kernel command line
> should only be limited by malloc(). Previously it was silently
> overflowing the stack.
...
> static void fixup_silent_linux(void)
> {
> - char buf[256], *start, *end;
Are you sure that the kernel's buffer is long enough?
For example on PowerPC, there is a current hard limit on 512
characters:
arch/powerpc/boot/ops.h:#define COMMAND_LINE_SIZE 512
arch/powerpc/kernel/setup-common.c:char cmd_line[COMMAND_LINE_SIZE];
On SPARC, we have 256 bytes hard limit, see arch/sparc/prom/bootstr_64.c:
#define BARG_LEN 256
...
prom_getstring(prom_chosen_node, "bootargs",
bootstr_info.bootstr_buf, BARG_LEN);
And so on for other architectures, for example:
arch/score/include/asm/setup.h:#define COMMAND_LINE_SIZE 256
arch/m68k/include/asm/setup.h:#define COMMAND_LINE_SIZE 256
arch/avr32/include/asm/setup.h:#define COMMAND_LINE_SIZE 256
arch/microblaze/include/asm/setup.h:#define COMMAND_LINE_SIZE 256
arch/mn10300/include/asm/param.h:#define COMMAND_LINE_SIZE 256
arch/sparc/include/asm/setup.h:# define COMMAND_LINE_SIZE 256
arch/cris/include/asm/setup.h:#define COMMAND_LINE_SIZE 256
arch/xtensa/include/asm/setup.h:#define COMMAND_LINE_SIZE 256
arch/alpha/include/asm/setup.h:#define COMMAND_LINE_SIZE 256
I think your patch is likely to break all these architectures?
Best regards,
Wolfgang Denk
--
DENX Software Engineering GmbH, MD: Wolfgang Denk & Detlev Zundel
HRB 165235 Munich, Office: Kirchenstr.5, D-82194 Groebenzell, Germany
Phone: (+49)-8142-66989-10 Fax: (+49)-8142-66989-80 Email: wd at denx.de
"The good Christian should beware of mathematicians and all those who
make empty prophecies. The danger already exists that mathematicians
have made a covenant with the devil to darken the spirit and confine
man in the bonds of Hell." - Saint Augustine
next prev parent reply other threads:[~2012-01-10 22:28 UTC|newest]
Thread overview: 39+ messages / expand[flat|nested] mbox.gz Atom feed top
2011-10-19 22:30 [U-Boot] [PATCH 0/4] Fix fixup_silent_linux() buffer overrun Doug Anderson
2011-10-19 22:30 ` [U-Boot] [PATCH 1/4] cmdline: Add linux command line munging tools Doug Anderson
2011-10-19 22:46 ` Mike Frysinger
2011-10-20 1:23 ` Doug Anderson
2011-10-19 22:52 ` Mike Frysinger
2011-10-20 1:07 ` Doug Anderson
2011-10-20 1:37 ` Mike Frysinger
2011-10-20 14:36 ` Wolfgang Denk
2011-10-20 17:06 ` Doug Anderson
2011-10-20 17:15 ` Mike Frysinger
2011-10-20 18:23 ` Doug Anderson
2011-10-20 19:33 ` Wolfgang Denk
2011-10-20 19:03 ` Wolfgang Denk
2011-10-21 5:09 ` Doug Anderson
2011-10-19 22:30 ` [U-Boot] [PATCH 2/4] cosmetic: Fixup fixup_silent_linux() for checkpatch Doug Anderson
2011-10-20 14:38 ` Wolfgang Denk
2011-10-19 22:30 ` [U-Boot] [PATCH 3/4] bootm: Avoid 256-byte overflow in fixup_silent_linux() Doug Anderson
2011-10-19 22:51 ` Mike Frysinger
2011-10-20 14:40 ` Wolfgang Denk
2011-10-20 17:54 ` [U-Boot] [PATCH v2] " Doug Anderson
2012-01-10 22:28 ` Wolfgang Denk [this message]
2012-01-10 22:51 ` Doug Anderson
2012-01-10 23:31 ` Mike Frysinger
2012-01-10 23:30 ` Mike Frysinger
2012-01-11 18:19 ` Doug Anderson
2012-01-15 1:32 ` Mike Frysinger
2012-01-17 19:16 ` [U-Boot] [PATCH v3] " Doug Anderson
2012-01-17 19:27 ` Mike Frysinger
2012-01-17 19:33 ` Doug Anderson
2012-01-17 19:37 ` [U-Boot] [PATCH v4] " Doug Anderson
2012-01-17 19:55 ` Mike Frysinger
2013-05-22 14:59 ` [U-Boot] [U-Boot, " Tom Rini
2011-10-19 22:30 ` [U-Boot] [PATCH 4/4] bootm: Add earlyprintk to fixup_silent_linux Doug Anderson
2011-10-19 22:35 ` Mike Frysinger
2011-10-19 22:46 ` Doug Anderson
2011-10-19 23:11 ` Mike Frysinger
2011-10-20 14:42 ` Wolfgang Denk
2011-10-20 17:35 ` Doug Anderson
2011-10-20 19:26 ` Wolfgang Denk
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20120110222805.2A0AE1167AA4@gemini.denx.de \
--to=wd@denx.de \
--cc=u-boot@lists.denx.de \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.