All of lore.kernel.org
 help / color / mirror / Atom feed
From: Steve Rae <srae@broadcom.com>
To: u-boot@lists.denx.de
Subject: [U-Boot] [PATCH 3/3] usb: gadget: fastboot: terminate commands with NULL
Date: Wed, 1 Oct 2014 13:40:34 -0700	[thread overview]
Message-ID: <542C66C2.20800@broadcom.com> (raw)
In-Reply-To: <1412103942-28331-4-git-send-email-eric.nelson@boundarydevices.com>



On 14-09-30 12:05 PM, Eric Nelson wrote:
> Without NULL termination, various commands will read past the
> end of input. In particular, this was noticed with error()
> calls in cb_getvar and simple_strtoul() in cb_download.
>
> Since the download callback happens elsewhere, the 4k buffer
> should always be sufficient to handle command arguments.
>
> Signed-off-by: Eric Nelson <eric.nelson@boundarydevices.com>
> ---
>   drivers/usb/gadget/f_fastboot.c | 7 +++++++
>   1 file changed, 7 insertions(+)
>
> diff --git a/drivers/usb/gadget/f_fastboot.c b/drivers/usb/gadget/f_fastboot.c
> index 86700f5..0950ea8 100644
> --- a/drivers/usb/gadget/f_fastboot.c
> +++ b/drivers/usb/gadget/f_fastboot.c
> @@ -542,6 +542,13 @@ static void rx_handler_command(struct usb_ep *ep, struct usb_request *req)
>   		error("unknown command: %s\n", cmdbuf);
>   		fastboot_tx_write_str("FAILunknown command");
>   	} else {
> +		if (req->actual < req->length) {
> +			u8 *buf = (u8 *)req->buf;
> +			buf[req->actual] = 0;
> +			func_cb(ep, req);
> +		} else {
> +			error("buffer overflow\n");
                         fastboot_tx_write_str("FAILbuffer overflow");
ADD this line
> +		}
>   		func_cb(ep, req);
AND delete this line (otherwise the func_cb() is called twice!!!)
>   	}
>
>
I have not experienced this issue, however, if it is to be accepted, 
then please update these two lines.... Afterwards:
Tested-by: Steve Rae <srae@broadcom.com>

  reply	other threads:[~2014-10-01 20:40 UTC|newest]

Thread overview: 25+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2014-09-30 19:05 [U-Boot] [PATCH 0/3] usb: gadget: fastboot miscellaneous patches Eric Nelson
2014-09-30 19:05 ` [U-Boot] [PATCH 1/3] usb: gadget: fastboot: add max-download-size variable Eric Nelson
2014-10-01 20:38   ` Steve Rae
2014-10-02  2:37     ` Marek Vasut
2014-10-02 16:50       ` Steve Rae
2014-09-30 19:05 ` [U-Boot] [PATCH 2/3] usb: gadget: fastboot: explicitly set radix of maximum download size Eric Nelson
2014-10-01 20:39   ` Steve Rae
2014-09-30 19:05 ` [U-Boot] [PATCH 3/3] usb: gadget: fastboot: terminate commands with NULL Eric Nelson
2014-10-01 20:40   ` Steve Rae [this message]
2014-10-01 21:23     ` Eric Nelson
2014-10-01 21:30     ` [U-Boot] [PATCH V2 " Eric Nelson
2014-09-30 19:37 ` [U-Boot] [PATCH 0/3] usb: gadget: fastboot miscellaneous patches Marek Vasut
2014-09-30 19:47   ` Eric Nelson
2014-09-30 23:59     ` Marek Vasut
2014-10-01  2:03       ` Eric Nelson
2014-10-01 12:13         ` Marek Vasut
2014-10-01 20:44           ` Steve Rae
2014-10-03 20:16             ` Marek Vasut
2014-10-06  9:23               ` Lukasz Majewski
2014-10-06 12:50                 ` Marek Vasut
2014-10-06 15:49                   ` Eric Nelson
2014-10-06 19:07                     ` Marek Vasut
2014-10-06 20:01                       ` Eric Nelson
2014-10-06 21:44                         ` Marek Vasut
2014-10-06 17:00                   ` Lukasz Majewski

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=542C66C2.20800@broadcom.com \
    --to=srae@broadcom.com \
    --cc=u-boot@lists.denx.de \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.