From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from phobos.denx.de (phobos.denx.de [85.214.62.61]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.lore.kernel.org (Postfix) with ESMTPS id 2291DC001DE for ; Fri, 28 Jul 2023 04:52:38 +0000 (UTC) Received: from h2850616.stratoserver.net (localhost [IPv6:::1]) by phobos.denx.de (Postfix) with ESMTP id 832AA8622D; Fri, 28 Jul 2023 06:52:35 +0200 (CEST) Authentication-Results: phobos.denx.de; dmarc=pass (p=none dis=none) header.from=gmx.de Authentication-Results: phobos.denx.de; spf=pass smtp.mailfrom=u-boot-bounces@lists.denx.de Authentication-Results: phobos.denx.de; dkim=pass (2048-bit key; secure) header.d=gmx.de header.i=xypron.glpk@gmx.de header.b="IVzTCEyc"; dkim-atps=neutral Received: by phobos.denx.de (Postfix, from userid 109) id EF8B9863EE; Fri, 28 Jul 2023 06:52:32 +0200 (CEST) Received: from mout.gmx.net (mout.gmx.net [212.227.17.22]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)) (No client certificate requested) by phobos.denx.de (Postfix) with ESMTPS id 83C7E8622C for ; Fri, 28 Jul 2023 06:52:29 +0200 (CEST) Authentication-Results: phobos.denx.de; dmarc=pass (p=none dis=none) header.from=gmx.de Authentication-Results: phobos.denx.de; spf=pass smtp.mailfrom=xypron.glpk@gmx.de DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=gmx.de; s=s31663417; t=1690519947; x=1691124747; i=xypron.glpk@gmx.de; bh=ij7Su1olAnuPe7x/ENseT4SmOhxQYJlZrjT3uw3UeK4=; h=X-UI-Sender-Class:Date:From:To:CC:Subject:In-Reply-To:References; b=IVzTCEyc1xzyT1vv9uxd+V7vYkZWIOD31CAsdDXrwihusIHW1qpDxZ1H3wdPj7U/LfHCGPR Lj/TnwNkUynBgg/fA/jE1Xj3rnJr0LO7LTTwZcq1Mb0dAtlL+LOmuCwedEg1V6KElqEuyeIt3 xrApMZ/dYjZCJfUq2GIavacY2hND3vm1AhjG/YkAlwOu8cUVhAcJUMhl3jYtI5yZZpj1Wywj8 B19JlSpB4Y+DM4d09OI8QmRWFWZDb3VR3aHvGNN5i9TO+trjzbUKCS/HjxcQPc0r3Ql8vTRGr 0hJRvCqcX2xADWHzaLT5DkXp50iOVooGUv5x657pVwg/wVqq405A== X-UI-Sender-Class: 724b4f7f-cbec-4199-ad4e-598c01a50d3a Received: from [127.0.0.1] ([62.143.244.162]) by mail.gmx.net (mrgmx105 [212.227.17.168]) with ESMTPSA (Nemesis) id 1MKsj7-1qAbI616gH-00LEI0; Fri, 28 Jul 2023 06:52:27 +0200 Date: Fri, 28 Jul 2023 06:52:21 +0200 From: Heinrich Schuchardt To: Simon Glass , Dan Carpenter CC: Ilias Apalodimas , u-boot@lists.denx.de Subject: Re: [PATCH v2] efi_loader: Fix memory corruption on 32bit systems User-Agent: K-9 Mail for Android In-Reply-To: References: Message-ID: <80C02131-0BA9-487B-ACB3-EBC41FC09090@gmx.de> MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable X-Provags-ID: V03:K1:mfLAYRebtT8zQR7wjqeOFu4ykyJB8Bo+NSF5i1ypxixvG7uSqVx xuYwbyGCW3Pv2xlIVvkEAsFu2W2Ou10pTuf5Vbe7BJajj8jyJZTTT2yw40fs+8zLt8jjogY mFA98jvgp3gkqVMN1teYr/R/LxqvD6EwaeyeoewHRXiPuMor0G2j8cQOs3LzzBWyVydktEN F1isNLvoypKxDFsHXat7g== UI-OutboundReport: notjunk:1;M01:P0:6dfICBHah24=;zMhc6Rd3DfXyMuI1b4jNRt8APxN UQXfp6LOqbbfqC7iVnQZTOfD5mGO7972QUYcrTw75gGw5+X0kSusfRjejkATbCuEIGWgQhs13 zWC/rSqjqL92CIUOON32TXlKjJISCFjA/Xwqt+ZV9KX1i5kXUaGvCeYgBhT9V6Z1I3bMOs/CI KiLARprkLmua5v4mA3RoMVAXmke3b/Aw1fkP6UrP80cgjjjPAzsfHNFz7Of0i1vzGjaVTc92H fj9tjgTAztHEUWv5lF3dKo5AtLXJiJh4Qzmk+gzK9zKv3qZxsgbFT1xDCFGfbfMQjH3WQhjCL iZ2ZIpuwSPMs1USxfVvLagZdz9wW1mU66A/XWH2Bursa5KyKdn5dU2tw+QoxG3Su4LIGqNHCW reaSxSNXyWBsMGBeXuo9Q7ykDENUTAYa4GOaCaEDR6WPwaJ+lmI1zvuCs4k09UwSLY9CYDN3I AgOFOcD9Eb6YuMsTu6O7fFUMsZJ581LP3cdbik0/te1v64sNoTdhmLNhawvp5a6mG60pH1CMz SMoqAONtsZf1BPtF4ODhpKKEjBrieCdm5lBKwRHQ0us5NTTAtjgNJQhziU5e9Ic82/GywD1kY cx72nnwn14gSCxo8CgkshOgSYA+fAOIkM33eRbiFbHdV/VohA5U5ckCzbUrQ2nvQ7eZw1Lel8 lTnIvEFAyw17p8f6d+M7tpnIU8q1lEU9HOeC4ch0EfJTTDsqg0s0TkHBSuNQ2tkzRBXkf3STF ewnWdbABkcKRiqqvtIndaCNgEHJEhJ7sX3mYo4GTeOexxaDCAkxBjyveWah6WANj4Dj+6QURm 3+tWkLyvJt/bDyiDww4k0dWCWBtS/lZVDK27PsU3cadQQAC+h4dztuyz5TcPZjLKRdsK88A0i oDlh2q+DFkPhzLVXaPtmefhXCqYGRW/Ftnk6snVR6jzyC7qrJkZptFo0ft2eWpa33JjQbW7eK rgRRqLhxyqOadRXbehiMXbpKg48= X-BeenThere: u-boot@lists.denx.de X-Mailman-Version: 2.1.39 Precedence: list List-Id: U-Boot discussion List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: u-boot-bounces@lists.denx.de Sender: "U-Boot" X-Virus-Scanned: clamav-milter 0.103.8 at phobos.denx.de X-Virus-Status: Clean Am 28=2E Juli 2023 03:51:55 MESZ schrieb Simon Glass : >Hi, > >On Thu, 27 Jul 2023 at 08:36, Dan Carpenter wrote: >> >> On Thu, Jul 27, 2023 at 11:22:15AM +0300, Ilias Apalodimas wrote: >> > Hi Dan, >> > >> > [=2E=2E=2E] >> > >> > > @@ -313,7 +313,7 @@ static int cmp_pe_section(const void *arg1, con= st void *arg2) >> > > * >> > > * Return: valid pointer to a image, return NULL if allocation fai= ls=2E >> > > */ >> > > -void *efi_prepare_aligned_image(void *efi, u64 *efi_size) >> > > +void *efi_prepare_aligned_image(void *efi, size_t *efi_size) >> > > { >> > > size_t new_efi_size; >> > > void *new_efi; >> > > @@ -600,7 +600,7 @@ static bool efi_image_authenticate(void *efi, s= ize_t efi_size) >> > > if (!efi_secure_boot_enabled()) >> > > return true; >> > > >> > > - new_efi =3D efi_prepare_aligned_image(efi, (u64 *)&efi_size); >> > > + new_efi =3D efi_prepare_aligned_image(efi, &efi_size); >> > > if (!new_efi) >> > > return false; >> > > >> > > diff --git a/lib/efi_loader/efi_tcg2=2Ec b/lib/efi_loader/efi_tcg2= =2Ec >> > > index 49f8a5e77cbf=2E=2Ed57afd0c498b 100644 >> > > --- a/lib/efi_loader/efi_tcg2=2Ec >> > > +++ b/lib/efi_loader/efi_tcg2=2Ec >> > > @@ -882,7 +882,7 @@ out: >> > > * >> > > * Return: status code >> > > */ >> > > -static efi_status_t tcg2_hash_pe_image(void *efi, u64 efi_size, >> > > +static efi_status_t tcg2_hash_pe_image(void *efi, size_t efi_size, >> > > struct tpml_digest_values *diges= t_list) >> > >> > Unfortunately the rabbit hole is a bit deeper with this one=2E >> > tcg2_hash_pe_image() is called in >> > - tcg2_measure_pe_image()=2E This one is called in efi_load_pe() and = the type >> > is indeed a size_t there, so that's fine >> > - efi_tcg2_hash_log_extend_event(), this one is different=2E=2E=2E >> > The function is described by the EFI spec [0] which mandates a u64=2E= =2E=2E I >> > think that was the reason efi_prepare_aligned_image() is using a u64 = to >> > begin with=2E This one uses the size only though not the pointer, bu= t in a >> > 32bit platform it would truncate s size > UINT_MAX=2E >> > >> > [0] https://trustedcomputinggroup=2Eorg/wp-content/uploads/EFI-Protoc= ol-Specification-rev13-160330final=2Epdf >> >> I have maybe misread something=2E=2E=2E I don't think this is a real i= ssue=2E >> 32bit systems aren't going to be able to allocate that much memory >> anyway=2E Also there are a lot of size_t parameters already so it's no= t >> a new issue=2E > >We should really use ulong for addresses and malloc() sizes=2E Please, do not abuse long=2E According to the C specification the size of long is independent of the si= ze of pointers=2E Addresses should be pointers and sizes should be size_t=2E Best regards Heinrich