All of lore.kernel.org
 help / color / mirror / Atom feed
From: Jiaxun Yang <jiaxun.yang@flygoat.com>
To: u-boot@lists.denx.de
Cc: Simon Glass <sjg@chromium.org>,
	 Alper Nebi Yasak <alpernebiyasak@gmail.com>,
	Tom Rini <trini@konsulko.com>,
	 Heinrich Schuchardt <xypron.glpk@gmx.de>,
	 Ilias Apalodimas <ilias.apalodimas@linaro.org>,
	 Aaron Williams <awilliams@marvell.com>,
	 Jiaxun Yang <jiaxun.yang@flygoat.com>
Subject: [PATCH 11/20] lib/charset & efi: Fix possible unaligned accesses
Date: Tue, 11 Jun 2024 22:04:10 +0100	[thread overview]
Message-ID: <20240611-docker-image-v1-11-51472eb70357@flygoat.com> (raw)
In-Reply-To: <20240611-docker-image-v1-0-51472eb70357@flygoat.com>

As per armv7 arch spec, for A-profile CPU if translation is disabled,
then the default memory type is Device(-nGnRnE) instead of Normal,
which requires that alignment be enforced.

This means in some cases we can't perform unaligned access even after
allow_unaligned is called.

We do have many platforms that didn't have translation enabled in U-Boot,
and QEMU started to enforce this since 9.0.

Fix by using unaligned access helper for UTF-16 memory read/write to
ensure we don't do any unaligned access in U-Boot.

Signed-off-by: Jiaxun Yang <jiaxun.yang@flygoat.com>
---
 lib/charset.c                    | 21 ++++++++++++---------
 lib/efi_loader/efi_device_path.c | 11 ++---------
 2 files changed, 14 insertions(+), 18 deletions(-)

diff --git a/lib/charset.c b/lib/charset.c
index 182c92a50c48..af5f3ad16d9b 100644
--- a/lib/charset.c
+++ b/lib/charset.c
@@ -11,6 +11,7 @@
 #include <efi_loader.h>
 #include <errno.h>
 #include <malloc.h>
+#include <asm/unaligned.h>
 
 /**
  * codepage_437 - Unicode to codepage 437 translation table
@@ -215,7 +216,7 @@ s32 utf16_get(const u16 **src)
 		return -1;
 	if (!**src)
 		return 0;
-	code = **src;
+	code = get_unaligned_le16(*src);
 	++*src;
 	if (code >= 0xDC00 && code <= 0xDFFF)
 		return -1;
@@ -242,12 +243,12 @@ int utf16_put(s32 code, u16 **dst)
 	if ((code >= 0xD800 && code <= 0xDFFF) || code >= 0x110000)
 		return -1;
 	if (code < 0x10000) {
-		**dst = code;
+		put_unaligned_le16(code, *dst);
 	} else {
 		code -= 0x10000;
-		**dst = code >> 10 | 0xD800;
+		put_unaligned_le16(code >> 10 | 0xD800, *dst);
 		++*dst;
-		**dst = (code & 0x3ff) | 0xDC00;
+		put_unaligned_le16((code & 0x3ff) | 0xDC00, *dst);
 	}
 	++*dst;
 	return 0;
@@ -392,7 +393,7 @@ int __efi_runtime u16_strncmp(const u16 *s1, const u16 *s2, size_t n)
 	int ret = 0;
 
 	for (; n; --n, ++s1, ++s2) {
-		ret = *s1 - *s2;
+		ret = get_unaligned_le16(s1) - get_unaligned_le16(s2);
 		if (ret || !*s1)
 			break;
 	}
@@ -403,7 +404,7 @@ int __efi_runtime u16_strncmp(const u16 *s1, const u16 *s2, size_t n)
 size_t __efi_runtime u16_strnlen(const u16 *in, size_t count)
 {
 	size_t i;
-	for (i = 0; count-- && in[i]; i++);
+	for (i = 0; count-- && get_unaligned_le16(in + i); i++);
 	return i;
 }
 
@@ -417,8 +418,10 @@ u16 *u16_strcpy(u16 *dest, const u16 *src)
 	u16 *tmp = dest;
 
 	for (;; dest++, src++) {
-		*dest = *src;
-		if (!*src)
+		u16 code = get_unaligned_le16(src);
+
+		put_unaligned_le16(code, dest);
+		if (!code)
 			break;
 	}
 
@@ -463,7 +466,7 @@ uint8_t *utf16_to_utf8(uint8_t *dest, const uint16_t *src, size_t size)
 	uint32_t code_high = 0;
 
 	while (size--) {
-		uint32_t code = *src++;
+		uint32_t code = get_unaligned_le16(src++);
 
 		if (code_high) {
 			if (code >= 0xDC00 && code <= 0xDFFF) {
diff --git a/lib/efi_loader/efi_device_path.c b/lib/efi_loader/efi_device_path.c
index aec224d84662..481f9effdb6d 100644
--- a/lib/efi_loader/efi_device_path.c
+++ b/lib/efi_loader/efi_device_path.c
@@ -18,7 +18,7 @@
 #include <efi_loader.h>
 #include <part.h>
 #include <uuid.h>
-#include <asm-generic/unaligned.h>
+#include <asm/unaligned.h>
 #include <linux/compat.h> /* U16_MAX */
 
 /* template END node: */
@@ -867,13 +867,6 @@ static void path_to_uefi(void *uefi, const char *src)
 {
 	u16 *pos = uefi;
 
-	/*
-	 * efi_set_bootdev() calls this routine indirectly before the UEFI
-	 * subsystem is initialized. So we cannot assume unaligned access to be
-	 * enabled.
-	 */
-	allow_unaligned();
-
 	while (*src) {
 		s32 code = utf8_get(&src);
 
@@ -883,7 +876,7 @@ static void path_to_uefi(void *uefi, const char *src)
 			code = '\\';
 		utf16_put(code, &pos);
 	}
-	*pos = 0;
+	put_unaligned_le16(0, pos);
 }
 
 /**

-- 
2.43.0


  parent reply	other threads:[~2024-06-11 21:06 UTC|newest]

Thread overview: 42+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2024-06-11 21:03 [PATCH 00/20] New CI image and fixes Jiaxun Yang
2024-06-11 21:04 ` [PATCH 01/20] py: Replace deprecated unittest APIs Jiaxun Yang
2024-06-11 21:04 ` [PATCH 02/20] binman: Replace pkg_resources with importlib.resources Jiaxun Yang
2024-06-11 21:04 ` [PATCH 03/20] py: Replace distutils.core with setuptools Jiaxun Yang
2024-06-11 21:04 ` [PATCH 04/20] py: Replace usage of configparser.read_fp Jiaxun Yang
2024-06-11 21:04 ` [PATCH 05/20] doc/sphinx: Remove usage of six Jiaxun Yang
2024-06-11 21:04 ` [PATCH 06/20] py: Remove unused entries in requirements.txt Jiaxun Yang
2024-06-11 21:04 ` [PATCH 07/20] py: Bump requirements versions Jiaxun Yang
2024-06-11 21:04 ` [PATCH 08/20] py: Bump pylint version and clear warnings Jiaxun Yang
2024-06-11 21:04 ` [PATCH 09/20] binman: Workaround lz4 cli padding in test cases Jiaxun Yang
2024-06-11 21:04 ` [PATCH 10/20] tests/test_event_dump: Relax match rule for output Jiaxun Yang
2024-06-11 21:04 ` Jiaxun Yang [this message]
2024-06-11 21:04 ` [PATCH 12/20] cyclic: Rise default CYCLIC_MAX_CPU_TIME_US to 5000 Jiaxun Yang
2024-06-12 16:00   ` Tom Rini
2024-06-12 16:13     ` Jiaxun Yang
2024-06-12 16:50       ` Tom Rini
2024-06-14 14:13         ` Stefan Roese
2024-06-17 23:29           ` Tom Rini
2024-06-18 14:00             ` Jiaxun Yang
2024-06-18 14:24               ` Stefan Roese
2024-06-18 14:31               ` Tom Rini
2024-06-18 21:03                 ` Tim Harvey
2024-06-19  8:21                   ` Rasmus Villemoes
2024-06-19 15:20                     ` Tom Rini
2024-06-18 14:01             ` Stefan Roese
2024-06-11 21:04 ` [PATCH 13/20] CI: Ensure pip install is always performed in venv Jiaxun Yang
2024-06-12 16:00   ` Tom Rini
2024-06-11 21:04 ` [PATCH 14/20] CI: GitLab: Split build_world tasks Jiaxun Yang
2024-06-12 16:01   ` Tom Rini
2024-06-12 16:14     ` Jiaxun Yang
2024-06-12 17:07       ` Tom Rini
2024-06-12 20:24         ` Simon Glass
2024-06-13 15:32           ` Tom Rini
2024-06-11 21:04 ` [PATCH 15/20] CI: Dockerfile: Set global git name & email config Jiaxun Yang
2024-06-11 21:04 ` [PATCH 16/20] CI: Dockerfile: Bump various software version Jiaxun Yang
2024-06-12 16:02   ` Tom Rini
2024-06-12 16:19     ` Jiaxun Yang
2024-06-11 21:04 ` [PATCH 17/20] CI: Dockerfile: Add LoongArch64 support Jiaxun Yang
2024-06-11 21:04 ` [PATCH 18/20] doc: ci: Document how to run pipeline on gitlab.com Jiaxun Yang
2024-06-11 21:04 ` [PATCH NFC 19/20] Use Jiaxun's CI Image Jiaxun Yang
2024-06-11 21:04 ` [PATCH NFC 20/20] CI: Dockerfile: Replace some URL with mirror sites Jiaxun Yang
2024-06-12 16:00 ` [PATCH 00/20] New CI image and fixes Tom Rini

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20240611-docker-image-v1-11-51472eb70357@flygoat.com \
    --to=jiaxun.yang@flygoat.com \
    --cc=alpernebiyasak@gmail.com \
    --cc=awilliams@marvell.com \
    --cc=ilias.apalodimas@linaro.org \
    --cc=sjg@chromium.org \
    --cc=trini@konsulko.com \
    --cc=u-boot@lists.denx.de \
    --cc=xypron.glpk@gmx.de \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.