From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pg1-f199.google.com (mail-pg1-f199.google.com [209.85.215.199]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 8ACC43D0905 for ; Tue, 18 Aug 2026 04:54:22 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.215.199 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787028863; cv=none; b=iz2UCRnkyIAvr+z+/GGqHSQQPMA3UOy6Aylq6Q870hVmzA7eXGGe6Ah/9tG4SnuF0Q/7PQN8X9zCpSuJfCKSmgUzbwdfkU1QI9YX54borsLWRdapdJ5ddqPSphpegpOeWczBqDHYS3xbSwxjrXqIQCqvEp1aiDvHsiG6ylKV0PI= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787028863; c=relaxed/simple; bh=oFDYDfLZz8roDQmR2mxVHM38tGy3cPZJeaV6TLWxiBU=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=Q4n6ozJZWVPDyDCW8vOqZdtdW5vxVo8kzWDVVROiMICreAbF7tyvG0zbfME4SZeMqBUXQh7Ye6jTiOHlWnSR/2yP7ewa3vvCzS1XzVFBZOTw6IvaLw3Rjox8/UpqjPp20u5m70VtIfRcSJM63WHij4i6c4iHlndefc2dldQksHY= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--wfelipe.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=pG3j2xs9; arc=none smtp.client-ip=209.85.215.199 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--wfelipe.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="pG3j2xs9" Received: by mail-pg1-f199.google.com with SMTP id 41be03b00d2f7-c85798977dcso6303101a12.0 for ; Mon, 17 Aug 2026 21:54:22 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1787028862; x=1787633662; darn=vger.kernel.org; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:from:to:cc:subject:date:message-id:reply-to :content-type; bh=Pn8stLbBVVBRD5K14nzDtlbeoqvHqUNDP/KvrF+10no=; b=pG3j2xs9cwjvyLmX8AvPX9zDll7cWT8iyMrMMxLCNjYKsZOus8RnQ0yi4hdo+xt126 MbmAvTKke9sf5YDCPYkG/MgD49zblUBhPFERUQaRv261Z9pHkDhvym9wNcrmP27amJF0 qgR+mFepdoluFrHa3QhudOzWnperX+8g+0q/B8KyiBw7KBMovK0+rg3ref8ZpUNy1yxX EYS8hV4APJqJKLwDAJ9dZaQ1s7PQ5dmXjoV+6wOWMEKQ0hwhNXh9Ethl1u8JEwPohX2b /Aw9lJBd3mrq5fDobO40+HBD4st/O9zIn0hw0go43gsA/Z2AlD38gD+ZW6IFAwFN33CF jZRQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787028862; x=1787633662; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=Pn8stLbBVVBRD5K14nzDtlbeoqvHqUNDP/KvrF+10no=; b=gQ7mE1BrUDLdzjhKLhiClgQEiMCqIUABoJu9jUBgNAbwvvPA/nEMJf5ocKnzbEVK5E VFACID4xXBfIwWlosiCAcn3I+A+AuO78rUl6SkUDaGgrLxY6tr+s0chndNlg66bJPqrO lc2SY/scHXkj6joPL7dJ3foR/BZcLVKagjcmr6z0Gjtbb4ZeM9dv+Zzm/WgCe57zYCMx 9aYX4EH0AgLhQBijXcvBJLLY+f4Vng4rAXksfziV40FaJJV9gljAMIp2R6xNzZLfvOVD aN2gN1zPQ+yYH/tUiuKddzK3hU4uTY6m0+au34zFdztZKNhmMv9Y5z2SMb6Sa8n8Xyxz BG8w== X-Gm-Message-State: AOJu0YxtIRWlvFdmalDSd9uchGtLdxX1mIi0hkc/0TGcbK9H/YlmqYKW 5AwABghAdu2RhUqGaCjXePQy+PRctUEj6pwQP4npPJpbjXZvX4knC3+oBIZ6xFjBor1Ks66btFR HX1nfsb1qoA== X-Received: from pfux38.prod.google.com ([2002:a05:6a00:be6:b0:848:416d:e7f3]) (user=wfelipe job=prod-delivery.src-stubby-dispatcher) by 2002:a05:6a00:4f91:b0:84f:37c1:f887 with SMTP id d2e1a72fcca58-84fddfdf5b0mr29107211b3a.12.1787028861604; Mon, 17 Aug 2026 21:54:21 -0700 (PDT) Date: Tue, 18 Aug 2026 04:53:47 +0000 In-Reply-To: <20260818045357.4123784-1-wfelipe@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260818045357.4123784-1-wfelipe@google.com> X-Mailer: git-send-email 2.55.0.699.gb54405d56f-goog Message-ID: <20260818045357.4123784-3-wfelipe@google.com> Subject: [PATCH 2/2] init/main: fix false-positive kernel panic on environment variable overwrite From: Wilson Felipe Pereira To: Andrew Morton Cc: linux-kernel@vger.kernel.org, Wilson Felipe Pereira Content-Type: text/plain; charset="UTF-8" In unknown_bootoption(), the limit checking for environment variables sets panic_later *before* checking if the variable already exists in envp_init. If a user passes exactly MAX_INIT_ENVS custom variables and then overwrites the final variable by matching its key, it causes a false-positive hard panic on boot despite not actually exceeding the array bounds or increasing the total variable count. Swapping the order of these checks allows the duplicate check to break out of the loop before the panic flag is erroneously latched. To verify, boot a VM with 31 custom variables (filling the array up to its limit of 32) and then overwrite the very last variable: ENV_VARS=$(for i in {1..31}; do echo -n "var$i=$i "; done) qemu-system-x86_64 -kernel bzImage -append "$ENV_VARS var31=overwrite" Without this patch, the kernel crashes instantly with: Kernel panic - not syncing: Too many boot env vars at 'var31=overwrite' With this patch, the kernel safely overwrites the variable and boots. Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2") Signed-off-by: Wilson Felipe Pereira --- init/main.c | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/init/main.c b/init/main.c index f02041a42111..577ae30570e0 100644 --- a/init/main.c +++ b/init/main.c @@ -539,12 +539,12 @@ static int __init unknown_bootoption(char *param, char *val, /* Environment option */ unsigned int i; for (i = 0; envp_init[i]; i++) { + if (!strncmp(param, envp_init[i], len+1)) + break; if (i == MAX_INIT_ENVS) { panic_later = "env"; panic_param = param; } - if (!strncmp(param, envp_init[i], len+1)) - break; } envp_init[i] = param; } else { -- 2.55.0.699.gb54405d56f-goog