From: "Rui Qi" <qirui.001@bytedance.com>
To: <Yazen.Ghannam@amd.com>
Cc: <tony.luck@intel.com>, <bp@alien8.de>,
<linux-edac@vger.kernel.org>, <linux-kernel@vger.kernel.org>,
"Rui Qi" <qirui.001@bytedance.com>
Subject: [PATCH 1/4] RAS/amd/fmpm: Fix out-of-bounds read in for_each_fru macro
Date: Fri, 21 Aug 2026 17:47:45 +0800 [thread overview]
Message-ID: <20260821094748.145394-2-qirui.001@bytedance.com> (raw)
In-Reply-To: <20260821094748.145394-1-qirui.001@bytedance.com>
The for_each_fru macro evaluates the array access "rec = fru_records[i]"
before the bounds check "i < max_nr_fru" due to the comma operator's
left-to-right evaluation order. When the loop terminates, i equals
max_nr_fru, causing fru_records[max_nr_fru] to be read before the
condition is checked.
While the garbage pointer value assigned to rec is never dereferenced
(the loop exits immediately), this is technically undefined behavior
and would be flagged by UBSan and static analyzers.
Fix by using short-circuit evaluation with && to check the bound first,
only accessing the array when i is within range:
for (i = 0; i < max_nr_fru && ((rec = fru_records[i]), 1); i++)
Fixes: 6f15e617cc99 ("RAS: Introduce a FRU memory poison manager")
Signed-off-by: Rui Qi <qirui.001@bytedance.com>
---
drivers/ras/amd/fmpm.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/ras/amd/fmpm.c b/drivers/ras/amd/fmpm.c
index 4ccaaf7b70bf..91c49080873e 100644
--- a/drivers/ras/amd/fmpm.c
+++ b/drivers/ras/amd/fmpm.c
@@ -169,7 +169,7 @@ static unsigned int spa_nr_entries;
static DEFINE_MUTEX(fmpm_update_mutex);
#define for_each_fru(i, rec) \
- for (i = 0; rec = fru_records[i], i < max_nr_fru; i++)
+ for (i = 0; i < max_nr_fru && ((rec = fru_records[i]), 1); i++)
static inline u32 get_fmp_len(struct fru_rec *rec)
{
--
2.20.1
next prev parent reply other threads:[~2026-08-21 9:48 UTC|newest]
Thread overview: 14+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-21 9:47 [PATCH 0/4] RAS/amd/fmpm: Fix OOB, uninitialized data, and error-handling bugs Rui Qi
2026-08-21 9:47 ` Rui Qi [this message]
2026-08-25 17:14 ` [PATCH 1/4] RAS/amd/fmpm: Fix out-of-bounds read in for_each_fru macro Yazen Ghannam
2026-08-21 9:47 ` [PATCH 2/4] RAS/amd/fmpm: Clear new records bitmap before rollback Rui Qi
2026-08-25 19:56 ` Yazen Ghannam
2026-08-21 9:47 ` [PATCH 3/4] RAS/amd/fmpm: Make max_nr_entries read-only Rui Qi
2026-08-25 20:06 ` Yazen Ghannam
2026-08-21 9:47 ` [PATCH 4/4] RAS/amd/fmpm: Fix spurious BUG when ERST record enumeration fails Rui Qi
2026-08-25 20:21 ` Yazen Ghannam
2026-08-26 3:53 ` [PATCH v2 0/4] RAS/AMD/FMPM: Fix OOB, uninitialized data, and error-handling bugs Rui Qi
2026-08-26 3:53 ` [PATCH v2 1/4] RAS/AMD/FMPM: Fix out-of-bounds read in for_each_fru macro Rui Qi
2026-08-26 3:53 ` [PATCH v2 2/4] RAS/AMD/FMPM: Clear new records bitmap before rollback Rui Qi
2026-08-26 3:53 ` [PATCH v2 3/4] RAS/AMD/FMPM: Make max_nr_entries read-only Rui Qi
2026-08-26 3:53 ` [PATCH v2 4/4] RAS/AMD/FMPM: Fix spurious BUG when ERST record enumeration fails Rui Qi
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260821094748.145394-2-qirui.001@bytedance.com \
--to=qirui.001@bytedance.com \
--cc=Yazen.Ghannam@amd.com \
--cc=bp@alien8.de \
--cc=linux-edac@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=tony.luck@intel.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox