All of lore.kernel.org
 help / color / mirror / Atom feed
From: Eric Nelson <eric.nelson@boundarydevices.com>
To: u-boot@lists.denx.de
Subject: [U-Boot] [PATCH 3/3] usb: gadget: fastboot: terminate commands with NULL
Date: Wed, 01 Oct 2014 14:23:51 -0700	[thread overview]
Message-ID: <542C70E7.6040802@boundarydevices.com> (raw)
In-Reply-To: <542C66C2.20800@broadcom.com>

Thanks Steve,

On 10/01/2014 01:40 PM, Steve Rae wrote:
> 
> 
> On 14-09-30 12:05 PM, Eric Nelson wrote:
>> Without NULL termination, various commands will read past the
>> end of input. In particular, this was noticed with error()
>> calls in cb_getvar and simple_strtoul() in cb_download.
>>
>> Since the download callback happens elsewhere, the 4k buffer
>> should always be sufficient to handle command arguments.
>>
>> Signed-off-by: Eric Nelson <eric.nelson@boundarydevices.com>
>> ---
>>   drivers/usb/gadget/f_fastboot.c | 7 +++++++
>>   1 file changed, 7 insertions(+)
>>
>> diff --git a/drivers/usb/gadget/f_fastboot.c
>> b/drivers/usb/gadget/f_fastboot.c
>> index 86700f5..0950ea8 100644
>> --- a/drivers/usb/gadget/f_fastboot.c
>> +++ b/drivers/usb/gadget/f_fastboot.c
>> @@ -542,6 +542,13 @@ static void rx_handler_command(struct usb_ep *ep,
>> struct usb_request *req)
>>           error("unknown command: %s\n", cmdbuf);
>>           fastboot_tx_write_str("FAILunknown command");
>>       } else {
>> +        if (req->actual < req->length) {
>> +            u8 *buf = (u8 *)req->buf;
>> +            buf[req->actual] = 0;
>> +            func_cb(ep, req);
>> +        } else {
>> +            error("buffer overflow\n");
>                         fastboot_tx_write_str("FAILbuffer overflow");
> ADD this line
>> +        }
>>           func_cb(ep, req);
> AND delete this line (otherwise the func_cb() is called twice!!!)
>>       }
>>

Ouch. It appears I pooched the patch when trying to make checkpatch
happy with the extra(neous) braces.

I'll forward V2 shortly.

Regards,


Eric

  reply	other threads:[~2014-10-01 21:23 UTC|newest]

Thread overview: 25+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2014-09-30 19:05 [U-Boot] [PATCH 0/3] usb: gadget: fastboot miscellaneous patches Eric Nelson
2014-09-30 19:05 ` [U-Boot] [PATCH 1/3] usb: gadget: fastboot: add max-download-size variable Eric Nelson
2014-10-01 20:38   ` Steve Rae
2014-10-02  2:37     ` Marek Vasut
2014-10-02 16:50       ` Steve Rae
2014-09-30 19:05 ` [U-Boot] [PATCH 2/3] usb: gadget: fastboot: explicitly set radix of maximum download size Eric Nelson
2014-10-01 20:39   ` Steve Rae
2014-09-30 19:05 ` [U-Boot] [PATCH 3/3] usb: gadget: fastboot: terminate commands with NULL Eric Nelson
2014-10-01 20:40   ` Steve Rae
2014-10-01 21:23     ` Eric Nelson [this message]
2014-10-01 21:30     ` [U-Boot] [PATCH V2 " Eric Nelson
2014-09-30 19:37 ` [U-Boot] [PATCH 0/3] usb: gadget: fastboot miscellaneous patches Marek Vasut
2014-09-30 19:47   ` Eric Nelson
2014-09-30 23:59     ` Marek Vasut
2014-10-01  2:03       ` Eric Nelson
2014-10-01 12:13         ` Marek Vasut
2014-10-01 20:44           ` Steve Rae
2014-10-03 20:16             ` Marek Vasut
2014-10-06  9:23               ` Lukasz Majewski
2014-10-06 12:50                 ` Marek Vasut
2014-10-06 15:49                   ` Eric Nelson
2014-10-06 19:07                     ` Marek Vasut
2014-10-06 20:01                       ` Eric Nelson
2014-10-06 21:44                         ` Marek Vasut
2014-10-06 17:00                   ` Lukasz Majewski

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=542C70E7.6040802@boundarydevices.com \
    --to=eric.nelson@boundarydevices.com \
    --cc=u-boot@lists.denx.de \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.