From: Finn Thain <fthain@linux-m68k.org>
To: Jens Axboe <axboe@kernel.dk>, Laurent Vivier <laurent@vivier.eu>
Cc: Geert Uytterhoeven <geert@linux-m68k.org>,
Joshua Thompson <funaho@jurai.org>,
linux-block@vger.kernel.org, linux-m68k@lists.linux-m68k.org,
linux-kernel@vger.kernel.org
Subject: [PATCH v3 17/33] swim: Fix buffer overflow
Date: Fri, 04 Sep 2026 19:26:36 +1000 [thread overview]
Message-ID: <d8fceda197b840f892d9b511175e824ca2549f01.1788513997.git.fthain@linux-m68k.org> (raw)
In-Reply-To: <cover.1788513996.git.fthain@linux-m68k.org>
The effect of this bug can be observed as swim_read_sector_data()
inexplicably returning -5, or an error flag indicating that a mark byte
was read from the data register, or other odd behviour.
When copying bytes from the chip FIFO to the read buffer, the driver
keeps count of the remaining buffer space using register %d4. A counter
in register %d2 serves as a timeout. The driver polls (%a2), the handshake
register, until flags indicate that byte(s) have arrived in the FIFO.
movel #sector_size-1, %d4
read_new_data:
movew #max_retry, %d2
read_data_loop:
moveb %a2@, %d5
andb #0xc0, %d5
dbne %d2, read_data_loop
beq data_exit
moveb %a5@, %a4@+
andb #0x40, %d5
dbne %d4, read_new_data
beq exit_loop
Note that the exit_loop branch depends upon a flag in the handshake
register and not on the remaining buffer space. Hence there may be no
branch to exit_loop after %d4 is decremented to -1 (i.e. full buffer).
moveb %a5@, %a4@+
dbra %d4, read_new_data
exit_loop:
Here is a second decrement of %d4 which can now reach -2. But the buffer
bounds check is a comparison with -1, which is now ineffective. Hence the
loop will continue copying until %d2 eventually reaches -1.
Fix this bug by terminating the loop as soon as %d4 or %d2 reach -1.
Reset the timeout whenever a byte is copied.
Fixes: 8852ecd97488 ("m68k: mac - Add SWIM floppy support")
Signed-off-by: Finn Thain <fthain@linux-m68k.org>
---
Changed since v1:
- Avoid jumping to a redundant AND.B.
- Avoid a second handshake register access when there's already a byte in
the FIFO.
Changed since v2:
- Dropped reviewed-by tag due to unreviewed changes made since v1.
---
drivers/block/swim_asm.S | 16 +++++++++-------
1 file changed, 9 insertions(+), 7 deletions(-)
diff --git a/drivers/block/swim_asm.S b/drivers/block/swim_asm.S
index 699f7c90dd1c..e06aadb411a1 100644
--- a/drivers/block/swim_asm.S
+++ b/drivers/block/swim_asm.S
@@ -43,6 +43,8 @@
.equ sector_size, 512
.equ .Lhr_crc_error, 0x02
+ .equ .Lhr_fifo_2bytes, 0x40
+ .equ .Lhr_fifo_1byte, 0x80
.global swim_read_sector_header
swim_read_sector_header:
@@ -189,20 +191,20 @@ wait_data_mark_byte:
/* read data */
movel #sector_size-1, %d4 /* sector size */
-read_new_data:
movew #max_retry, %d2
read_data_loop:
moveb %a2@, %d5
- andb #0xc0, %d5
+ andb #(.Lhr_fifo_1byte + .Lhr_fifo_2bytes), %d5
dbne %d2, read_data_loop
beq data_exit
+ moveq #max_retry, %d2
moveb %a5@, %a4@+
- andb #0x40, %d5
- dbne %d4, read_new_data
- beq exit_loop
+ dbra %d4, 1f
+ bra data_crc0
+1: andb #.Lhr_fifo_2bytes, %d5
+ beq read_data_loop
moveb %a5@, %a4@+
- dbra %d4, read_new_data
-exit_loop:
+ dbra %d4, read_data_loop
/* read CRC */
--
2.52.0
next prev parent reply other threads:[~2026-09-04 9:34 UTC|newest]
Thread overview: 34+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-04 9:26 [PATCH v3 00/33] block/swim: Fixes and improvements Finn Thain
2026-09-04 9:26 ` [PATCH v3 16/33] swim: Don't use the mark register to read data Finn Thain
2026-09-04 9:26 ` [PATCH v3 01/33] swim: Assert strobe with stable outputs Finn Thain
2026-09-04 9:26 ` [PATCH v3 33/33] swim: Unexport global symbols Finn Thain
2026-09-04 9:26 ` [PATCH v3 30/33] swim: Clean up whitespace Finn Thain
2026-09-04 9:26 ` [PATCH v3 14/33] swim: Check for CRC errors Finn Thain
2026-09-04 9:26 ` [PATCH v3 23/33] swim: Remove pointless mode0 register write Finn Thain
2026-09-04 9:26 ` [PATCH v3 07/33] swim: Refactor SWIM setup Finn Thain
2026-09-04 9:26 ` [PATCH v3 28/33] swim: Add some helpful references Finn Thain
2026-09-04 9:26 ` [PATCH v3 15/33] swim: Check error register during sector read Finn Thain
2026-09-04 9:26 ` [PATCH v3 21/33] swim: Check drive ready bit Finn Thain
2026-09-04 9:26 ` [PATCH v3 26/33] swim: Remove pointless specifiers Finn Thain
2026-09-04 9:26 ` [PATCH v3 31/33] swim: Define macros for constants Finn Thain
2026-09-04 9:26 ` [PATCH v3 13/33] swim: Simplify return value initialization Finn Thain
2026-09-04 9:26 ` [PATCH v3 22/33] swim: Revisit delays Finn Thain
2026-09-04 9:26 ` [PATCH v3 32/33] swim: Define symbols for constants Finn Thain
2026-09-04 9:26 ` [PATCH v3 08/33] swim: Enable clock divider only where appropriate Finn Thain
2026-09-04 9:26 ` [PATCH v3 29/33] swim: Remove unused macro definitions Finn Thain
2026-09-04 9:26 ` Finn Thain [this message]
2026-09-04 9:26 ` [PATCH v3 25/33] swim: Don't search beyond the first data mark Finn Thain
2026-09-04 9:26 ` [PATCH v3 09/33] swim: Don't start motor until medium is present Finn Thain
2026-09-04 9:26 ` [PATCH v3 19/33] swim: Remove redundant RELAX actions Finn Thain
2026-09-04 9:26 ` [PATCH v3 12/33] swim: Handle FIFO timeout error Finn Thain
2026-09-04 9:26 ` [PATCH v3 10/33] swim: Recalibrate when drive is probed Finn Thain
2026-09-04 9:26 ` [PATCH v3 27/33] swim: Move swd initialization Finn Thain
2026-09-04 9:26 ` [PATCH v3 18/33] swim: Convert to blocking queue Finn Thain
2026-09-04 9:26 ` [PATCH v3 05/33] swim: Perform ISM/IWM mode switching according to specs Finn Thain
2026-09-04 9:26 ` [PATCH v3 02/33] swim: Select appropriate drive once only Finn Thain
2026-09-04 9:26 ` [PATCH v3 11/33] swim: Add track zero recalibration delay Finn Thain
2026-09-04 9:26 ` [PATCH v3 06/33] swim: Configure parameter memory Finn Thain
2026-09-04 9:26 ` [PATCH v3 03/33] swim: Enable the drive when probing Finn Thain
2026-09-04 9:26 ` [PATCH v3 24/33] swim: Don't needlessly re-read sectors Finn Thain
2026-09-04 9:26 ` [PATCH v3 04/33] swim: Don't disable drive after every sector Finn Thain
2026-09-04 9:26 ` [PATCH v3 20/33] swim: Deduplicate polling loops Finn Thain
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=d8fceda197b840f892d9b511175e824ca2549f01.1788513997.git.fthain@linux-m68k.org \
--to=fthain@linux-m68k.org \
--cc=axboe@kernel.dk \
--cc=funaho@jurai.org \
--cc=geert@linux-m68k.org \
--cc=laurent@vivier.eu \
--cc=linux-block@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-m68k@lists.linux-m68k.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox