From mboxrd@z Thu Jan 1 00:00:00 1970 Received: by 2002:adf:c793:0:0:0:0:0 with SMTP id l19csp731472wrg; Thu, 16 May 2019 07:50:19 -0700 (PDT) X-Google-Smtp-Source: APXvYqw3cI4a6hdqLqk7l7AfmclKDgrKtD+LBQmVkcBpd5ajx3I8BgDUnikTJKdI30ERgQLZylaF X-Received: by 2002:a50:b487:: with SMTP id w7mr51972205edd.45.1558018219388; Thu, 16 May 2019 07:50:19 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1558018219; cv=none; d=google.com; s=arc-20160816; b=EotVZoX0vt0QDB1vdNr4D3asau22nQAbANOrskupmudsH0ykb3YurM+5ulXBfekm8D Uo/Can348SAw1fHAeeSH/V3bfJokVl955sD2VZLzTt+uN/tuQNSie68xYDkxYPRFSmxn THkdDDIWrhTynfcrPlC14qQa1QlJaL0fNBl65/VDiADoF7rg0mzPR+G3HCfCMSngn7BG xcHwzm296EXxDU8DBXY+KPDpsrDRPsxM1Rw4cXVNTiuGHb7Itlbk2lVqSqGF1c/govPo fKry4j3CzTFxT8g45egl6hoUhQ4L68Igy+30PRuooUetb8DW+8hZjpoEyZlG6+TIaMRK 0u7A== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=sender:errors-to:cc:list-subscribe:list-help:list-post:list-archive :list-unsubscribe:list-id:precedence:subject :content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:to:from:dkim-signature; bh=DgMhkLiABo0DJwU8oJ8YkfjP+Hk6v1roeqysC4eg468=; b=mNrjsXXxRwdgT2EQNbZE3ZrDXyo0VSfxPSShSYByqq6Z9nYMn2ybhRxGziW+gxm/nR 3tZayJ1SAhiS170kfifIDNittGrkrQ1InGhZobFMBww7NVwuJ4FuW+IGMTQ6Uese+ElD 9yuBCTF18phWUXtVRHVaz1+HQyDGAeFFV0i9dhv/vFl4b0CSmA1TDbvu4nnVZzGIk2NP SLBZI6XN3HQr8wNBs/qnkKzzpJ+9W2wZdkt+jpwlzzgUjZ7dVaRNNxBaEI10S1fWuIpu yrK78S2xB7oTV88Zg+qFoahE+jAV7OfvWCwBVSE3IA4Borz/11j6wLih5QtqzJwq+8p6 WDXg== ARC-Authentication-Results: i=1; mx.google.com; dkim=fail header.i=@linaro.org header.s=google header.b=SE+aDuN2; spf=pass (google.com: domain of qemu-devel-bounces+alex.bennee=linaro.org@nongnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom="qemu-devel-bounces+alex.bennee=linaro.org@nongnu.org"; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=linaro.org Return-Path: Received: from lists.gnu.org (lists.gnu.org. [209.51.188.17]) by mx.google.com with ESMTPS id q8si4486806eda.299.2019.05.16.07.50.19 for (version=TLS1 cipher=AES128-SHA bits=128/128); Thu, 16 May 2019 07:50:19 -0700 (PDT) Received-SPF: pass (google.com: domain of qemu-devel-bounces+alex.bennee=linaro.org@nongnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; Authentication-Results: mx.google.com; dkim=fail header.i=@linaro.org header.s=google header.b=SE+aDuN2; spf=pass (google.com: domain of qemu-devel-bounces+alex.bennee=linaro.org@nongnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom="qemu-devel-bounces+alex.bennee=linaro.org@nongnu.org"; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=linaro.org Received: from localhost ([127.0.0.1]:59435 helo=lists.gnu.org) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1hRHi6-0003oK-C0 for alex.bennee@linaro.org; Thu, 16 May 2019 10:50:18 -0400 Received: from eggs.gnu.org ([209.51.188.92]:58903) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1hRHfZ-0002au-7a for qemu-devel@nongnu.org; Thu, 16 May 2019 10:47:42 -0400 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1hRHfY-0008H6-5g for qemu-devel@nongnu.org; Thu, 16 May 2019 10:47:41 -0400 Received: from mail-wm1-x343.google.com ([2a00:1450:4864:20::343]:39957) by eggs.gnu.org with esmtps (TLS1.0:RSA_AES_128_CBC_SHA1:16) (Exim 4.71) (envelope-from ) id 1hRHfX-0008Eh-86 for qemu-devel@nongnu.org; Thu, 16 May 2019 10:47:39 -0400 Received: by mail-wm1-x343.google.com with SMTP id h11so3752880wmb.5 for ; Thu, 16 May 2019 07:47:39 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linaro.org; s=google; h=from:to:cc:subject:date:message-id:in-reply-to:references :mime-version:content-transfer-encoding; bh=DgMhkLiABo0DJwU8oJ8YkfjP+Hk6v1roeqysC4eg468=; b=SE+aDuN2LJ0lQpMoo3ZRFMPWP9p0Weq1dhOnfcYXLJ79rrxDtptgaDDry/xFsWUZqh eGBHZgrufeHGBGg8ZUruLfPOXSDTXPrDhA/iVRTm8gxN0vi+xvpPSnGtb+IdR3vvaOrg kxpGfZ3OvKEGOtcR352oxR76OHjU0B7Dpa1G/3CoLDW7Hbt4gxTXQbJfA0hivygq8P8s V0wEpSfveD1o3Z0yFyXJMoN6mK5UMIXdThhvM6YMXaKIJMAwk0uymPQ2KBL/H0kYXwyW +vGrU604TknDsnj9O+9Az3DG7WIxZ2meQfG/feuGmmQdTF+FOr7LSMyDpQm6YQCkRFP+ bn9A== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:to:cc:subject:date:message-id:in-reply-to :references:mime-version:content-transfer-encoding; bh=DgMhkLiABo0DJwU8oJ8YkfjP+Hk6v1roeqysC4eg468=; b=Kl6B5BcOlSIcjmipkYClOiAF/Wbl21VOWoJJI8F0nzSdrqMeLIZ9unVA2ZboSqshSb T5XnYv39+xjas5kNxKsvNfFZR5WEwuRhqrkGG504V9BZjKwl+1I6T7C4UXfjlz1ruqwn 937soYjLW+qebIw1YgyNXPezwD6I38Z7H42qEBNRAc7qVDd60uZlrICjjHR+1m7qYOrK eMopwC0fg7VkvvdFVGPQOVFxHXNStF25lYvn/cVWjaz3gJonToqjSyI64TzP5tBmMuXZ Oh/yKhLNCj7Mfkt4NxzqF04D2QSg13FYCONufzxKY76QYPfBLgA0L9vGb87NME/D8BzD qoqA== X-Gm-Message-State: APjAAAVh3Os9AX6Eype/jXKaT4bEawoHO33p5LZIycnye3OnAS2t/h9z ZTRVBHREFmpgTgYSrN5/ljrDgg== X-Received: by 2002:a1c:63d5:: with SMTP id x204mr11618190wmb.3.1558018058135; Thu, 16 May 2019 07:47:38 -0700 (PDT) Received: from orth.archaic.org.uk (orth.archaic.org.uk. [81.2.115.148]) by smtp.gmail.com with ESMTPSA id o8sm7629018wra.4.2019.05.16.07.47.37 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Thu, 16 May 2019 07:47:37 -0700 (PDT) From: Peter Maydell To: qemu-arm@nongnu.org, qemu-devel@nongnu.org Date: Thu, 16 May 2019 15:47:31 +0100 Message-Id: <20190516144733.32399-3-peter.maydell@linaro.org> X-Mailer: git-send-email 2.20.1 In-Reply-To: <20190516144733.32399-1-peter.maydell@linaro.org> References: <20190516144733.32399-1-peter.maydell@linaro.org> MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-detected-operating-system: by eggs.gnu.org: Genre and OS details not recognized. X-Received-From: 2a00:1450:4864:20::343 Subject: [Qemu-devel] [PATCH v2 2/4] hw/arm/boot: Diagnose layouts that put initrd or DTB off the end of RAM X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.21 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Cc: Mark Rutland , Richard Henderson Errors-To: qemu-devel-bounces+alex.bennee=linaro.org@nongnu.org Sender: "Qemu-devel" X-TUID: 3Efu8dHeqX0P We calculate the locations in memory where we want to put the initrd and the DTB based on the size of the kernel, since they come after it. Add some explicit checks that these aren't off the end of RAM entirely. (At the moment the way we calculate the initrd_start means that it can't ever be off the end of RAM, but that will change with the next commit.) Signed-off-by: Peter Maydell --- hw/arm/boot.c | 23 +++++++++++++++++++++++ 1 file changed, 23 insertions(+) diff --git a/hw/arm/boot.c b/hw/arm/boot.c index 0bb9a7d5b5c..935be3b92a5 100644 --- a/hw/arm/boot.c +++ b/hw/arm/boot.c @@ -1055,11 +1055,25 @@ static void arm_setup_direct_kernel_boot(ARMCPU *cpu, error_report("could not load kernel '%s'", info->kernel_filename); exit(1); } + + if (kernel_size > info->ram_size) { + error_report("kernel '%s' is too large to fit in RAM " + "(kernel size %d, RAM size %" PRId64 ")", + info->kernel_filename, kernel_size, info->ram_size); + exit(1); + } + info->entry = entry; if (is_linux) { uint32_t fixupcontext[FIXUP_MAX]; if (info->initrd_filename) { + + if (info->initrd_start >= ram_end) { + error_report("not enough space after kernel to load initrd"); + exit(1); + } + initrd_size = load_ramdisk_as(info->initrd_filename, info->initrd_start, ram_end - info->initrd_start, as); @@ -1075,6 +1089,11 @@ static void arm_setup_direct_kernel_boot(ARMCPU *cpu, info->initrd_filename); exit(1); } + if (info->initrd_start + initrd_size > info->ram_size) { + error_report("could not load initrd '%s': " + "too big to fit into RAM after the kernel", + info->initrd_filename); + } } else { initrd_size = 0; } @@ -1110,6 +1129,10 @@ static void arm_setup_direct_kernel_boot(ARMCPU *cpu, /* Place the DTB after the initrd in memory with alignment. */ info->dtb_start = QEMU_ALIGN_UP(info->initrd_start + initrd_size, align); + if (info->dtb_start >= ram_end) { + error_report("Not enough space for DTB after kernel/initrd"); + exit(1); + } fixupcontext[FIXUP_ARGPTR_LO] = info->dtb_start; fixupcontext[FIXUP_ARGPTR_HI] = info->dtb_start >> 32; } else { -- 2.20.1