From: Neelesh Gupta <neelegup@linux.vnet.ibm.com>
To: minyard@acm.org, alistair@popple.id.au,
linuxppc-dev@lists.ozlabs.org, jk@ozlabs.org
Subject: Re: [PATCH] ipmi/powernv: Fix potential invalid pointer dereference
Date: Fri, 17 Jul 2015 14:12:07 +0530 [thread overview]
Message-ID: <55A8BFDF.2020601@linux.vnet.ibm.com> (raw)
In-Reply-To: <55A7C747.1050509@acm.org>
[-- Attachment #1: Type: text/plain, Size: 2206 bytes --]
Hi Corey,
On 07/16/2015 08:31 PM, Corey Minyard wrote:
> Ok, this looks fine. A couple of question...
>
> Do I need to send this upstream right now? How well has this been tested?
I would want either Jeremy or Alistair to review this patch before you
send this
upstream. There is also firmware piece
http://patchwork.ozlabs.org/patch/496645/
awaiting review.
In the testing front, I manually made the opal_ipmi_recv() function to
fail for testing
the error path and see if the driver recovers from it and subsequent
ipmi commands
work all good.
>
> Do you want this backported to 4.0 stable?
Yes, I want this to be be backported to 4.0 stable.
Thanks,
Neelesh.
>
> -corey
>
> On 07/16/2015 06:16 AM, Neelesh Gupta wrote:
>> If the OPAL call to receive the ipmi message fails, then we free up the
>> smi message and return. But, the driver still holds the reference to
>> old smi message in the 'cur_msg' which can potentially be accessed later
>> and freed again leading to kernel oops. To fix it up,
>>
>> The kernel driver should reset the 'cur_msg' and send reply to the user
>> in addition to freeing the message.
>>
>> Signed-off-by: Neelesh Gupta <neelegup@linux.vnet.ibm.com>
>> ---
>> drivers/char/ipmi/ipmi_powernv.c | 13 ++++++++++---
>> 1 file changed, 10 insertions(+), 3 deletions(-)
>>
>> diff --git a/drivers/char/ipmi/ipmi_powernv.c b/drivers/char/ipmi/ipmi_powernv.c
>> index 9b409c0..637486d 100644
>> --- a/drivers/char/ipmi/ipmi_powernv.c
>> +++ b/drivers/char/ipmi/ipmi_powernv.c
>> @@ -143,9 +143,16 @@ static int ipmi_powernv_recv(struct ipmi_smi_powernv *smi)
>> pr_devel("%s: -> %d (size %lld)\n", __func__,
>> rc, rc == 0 ? size : 0);
>> if (rc) {
>> - spin_unlock_irqrestore(&smi->msg_lock, flags);
>> - ipmi_free_smi_msg(msg);
>> - return 0;
>> + /* If came via the poll, and response was not yet ready */
>> + if (rc == OPAL_EMPTY) {
>> + spin_unlock_irqrestore(&smi->msg_lock, flags);
>> + return 0;
>> + } else {
>> + smi->cur_msg = NULL;
>> + spin_unlock_irqrestore(&smi->msg_lock, flags);
>> + send_error_reply(smi, msg, IPMI_ERR_UNSPECIFIED);
>> + return 0;
>> + }
>> }
>>
>> if (size < sizeof(*opal_msg)) {
>>
[-- Attachment #2: Type: text/html, Size: 3147 bytes --]
next prev parent reply other threads:[~2015-07-17 8:43 UTC|newest]
Thread overview: 5+ messages / expand[flat|nested] mbox.gz Atom feed top
2015-07-16 11:16 [PATCH] ipmi/powernv: Fix potential invalid pointer dereference Neelesh Gupta
2015-07-16 15:01 ` Corey Minyard
2015-07-17 8:42 ` Neelesh Gupta [this message]
[not found] ` <55B7342F.8080703@linux.vnet.ibm.com>
2015-07-28 17:51 ` Alistair Popple
2015-07-29 6:05 ` Neelesh Gupta
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=55A8BFDF.2020601@linux.vnet.ibm.com \
--to=neelegup@linux.vnet.ibm.com \
--cc=alistair@popple.id.au \
--cc=jk@ozlabs.org \
--cc=linuxppc-dev@lists.ozlabs.org \
--cc=minyard@acm.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.