From: "Liuwenliang (Abbott Liu)" <liuwenliang@huawei.com>
To: "Guohanjun (Hanjun Guo)" <guohanjun@huawei.com>,
"tony.luck@intel.com" <tony.luck@intel.com>,
"bp@alien8.de" <bp@alien8.de>,
"jic23@kernel.org" <jic23@kernel.org>,
"ardb@kernel.org" <ardb@kernel.org>,
"rafael.j.wysocki@intel.com" <rafael.j.wysocki@intel.com>,
"mchehab+huawei@kernel.org" <mchehab+huawei@kernel.org>,
luoshengwei <luoshengwei@huawei.com>,
"jason@os.amperecomputing.com" <jason@os.amperecomputing.com>,
"danielf@os.amperecomputing.com" <danielf@os.amperecomputing.com>,
"linux-edac@vger.kernel.org" <linux-edac@vger.kernel.org>,
"linux-kernel@vger.kernel.org" <linux-kernel@vger.kernel.org>
Cc: "yangzhuohao (A)" <yangzhuohao1@huawei.com>,
douzhaolei <douzhaolei@huawei.com>,
zouyipeng <zouyipeng@huawei.com>, Wangbing <wangbing6@huawei.com>,
Nixiaoming <nixiaoming@huawei.com>
Subject: Re: [PATCH v2 1/2] RAS: Fix inverted context info bounds check in ARM processor errors
Date: Sat, 5 Sep 2026 13:11:21 +0000 [thread overview]
Message-ID: <7b4b9527a97b4f038009b18360fd7565@huawei.com> (raw)
Hi Hanjun, thinks for your review.
>Hi Abbott,
>
>On 2026/8/25 21:43, Abbott Liu wrote:
>> Commit 87880af2d24e ("APEI/GHES: ARM processor Error: don't go past
>> allocated memory") added bounds checks for malformed ARM processor
>> error records but contained a bug:
>>
>> In log_arm_hw_error(), the ctx_info bounds check is inverted. The
>> condition `sz + (long)ctx_info - (long)err >= err->section_length`
>> adds ctx_info->size when the context header is already past the end
>> of the section instead of when it is within bounds. So change the
>> comparison to <=.
>>
>> Fixes: 87880af2d24e ("APEI/GHES: ARM processor Error: don't go past allocated memory")
>>
>
>This empty line is not needed.
I am very sorry for making such a basic mistake; this issue will be resolved
in the next version.
>
>> Signed-off-by: Abbott Liu <liuwenliang@huawei.com>
>> ---
>> drivers/ras/ras.c | 2 +-
>> 1 file changed, 1 insertion(+), 1 deletion(-)
>>
>> diff --git a/drivers/ras/ras.c b/drivers/ras/ras.c
>> index 03df3db62334..2540538a16a8 100644
>> --- a/drivers/ras/ras.c
>> +++ b/drivers/ras/ras.c
>> @@ -74,7 +74,7 @@ void log_arm_hw_error(struct cper_sec_proc_arm *err, const u8 sev)
>> for (n = 0; n < err->context_info_num; n++) {
>> sz = sizeof(struct cper_arm_ctx_info);
>>
>> - if (sz + (long)ctx_info - (long)err >= err->section_length)
>> + if (sz + (long)ctx_info - (long)err <= err->section_length)
>> sz += ctx_info->size;
>
>sz is an int and ctx_info->size is u32, if ctx_info->size is big enough
>for example over 0x7fffffff, the sz will be negative.
>
>>
>> ctx_info = (struct cper_arm_ctx_info *)((long)ctx_info + sz);
>
>if the sz is negative, the ctx_info may pointer to a wrong place.
>
>ctx_info->size will not over 0x7fffffff in practical but should we
>consider the overflows?
I also think that it won't actually happen in practice, so there
isn't much need to consider this overflow issue. But even if we do
consider it, the code modifications wouldn't be too complex. I plan
to fix it in the next version.
>
>Thanks
>Hanjun
>
>>
>
next reply other threads:[~2026-09-05 13:11 UTC|newest]
Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-05 13:11 Liuwenliang (Abbott Liu) [this message]
-- strict thread matches above, loose matches on Subject: below --
2026-08-25 13:43 [PATCH v2 0/2] RAS: Fix ARM processor error bounds checking Abbott Liu
2026-08-25 13:43 ` [PATCH v2 1/2] RAS: Fix inverted context info bounds check in ARM processor errors Abbott Liu
2026-09-03 9:54 ` Hanjun Guo
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=7b4b9527a97b4f038009b18360fd7565@huawei.com \
--to=liuwenliang@huawei.com \
--cc=ardb@kernel.org \
--cc=bp@alien8.de \
--cc=danielf@os.amperecomputing.com \
--cc=douzhaolei@huawei.com \
--cc=guohanjun@huawei.com \
--cc=jason@os.amperecomputing.com \
--cc=jic23@kernel.org \
--cc=linux-edac@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=luoshengwei@huawei.com \
--cc=mchehab+huawei@kernel.org \
--cc=nixiaoming@huawei.com \
--cc=rafael.j.wysocki@intel.com \
--cc=tony.luck@intel.com \
--cc=wangbing6@huawei.com \
--cc=yangzhuohao1@huawei.com \
--cc=zouyipeng@huawei.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox