From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from phobos.denx.de (phobos.denx.de [85.214.62.61]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.lore.kernel.org (Postfix) with ESMTPS id 36A3CC433F5 for ; Wed, 6 Apr 2022 14:18:57 +0000 (UTC) Received: from h2850616.stratoserver.net (localhost [IPv6:::1]) by phobos.denx.de (Postfix) with ESMTP id AEEE7839D4; Wed, 6 Apr 2022 16:18:54 +0200 (CEST) Authentication-Results: phobos.denx.de; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: phobos.denx.de; spf=pass smtp.mailfrom=u-boot-bounces@lists.denx.de Authentication-Results: phobos.denx.de; dkim=pass (2048-bit key; unprotected) header.d=google.com header.i=@google.com header.b="RG1SHhtf"; dkim-atps=neutral Received: by phobos.denx.de (Postfix, from userid 109) id 9049383D2A; Wed, 6 Apr 2022 16:18:52 +0200 (CEST) Received: from mail-wr1-x42e.google.com (mail-wr1-x42e.google.com [IPv6:2a00:1450:4864:20::42e]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits)) (No client certificate requested) by phobos.denx.de (Postfix) with ESMTPS id 55B7C80331 for ; Wed, 6 Apr 2022 16:18:43 +0200 (CEST) Authentication-Results: phobos.denx.de; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: phobos.denx.de; spf=pass smtp.mailfrom=ptosi@google.com Received: by mail-wr1-x42e.google.com with SMTP id w4so3401670wrg.12 for ; Wed, 06 Apr 2022 07:18:43 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20210112; h=date:from:to:cc:subject:message-id:references:mime-version :content-disposition:in-reply-to; bh=B9SQcj1z/Wg+XZh31dD1UBT5Rf/l4XZxY3fds3Zicf0=; b=RG1SHhtfjeBzfJmJOyrdiSVPsx6ciqkzm/Gn32O3iMQtEYgJqIUSgzdZR49JcdTxaQ QJV24RxGFkxORcTupF49rNDjZ0eyi3LwfaeUiGM9+wIngqOpYJ2qVRbzuJQm7rJh3qgX G09sNM14LvxuXD/aaHBgaZAgsr+FXud/Y++m43WiRu3MEZLpsKZxlLcAU0apHBk5nWnP uysTHiNRr0IIaivpEoYXVEl62x7VrGWBKAFwEwXjk/7Un2Ize0lEeZTK5JFmnMsOaiiP 1/oJO5aWrbIQ85MAaVU33DhOyEp63sNJuL2moyMNRiZvw9Uq9qJAe9M018uh/5LByjpz YNRg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20210112; h=x-gm-message-state:date:from:to:cc:subject:message-id:references :mime-version:content-disposition:in-reply-to; bh=B9SQcj1z/Wg+XZh31dD1UBT5Rf/l4XZxY3fds3Zicf0=; b=cB/f2Qxm/Qxb5t0B8/3Yybez5jyaquCL4xOsZ3oV2SLqMsD/cNI6NCJLdvdORT74EN 0BLdieKz78GGP1ePPDRv844/mzLcw7+8ii0T/aFGTaW7fLjR6jlu2KUOb36pUvhL2yTI FEHT1hbfQcTXvDMzrBOwxndNf19ZNiSuZV/NssGgLdZGLPZHNyaMoo9nYkTFOTb4D0N7 r9Y66Fq5qRIMtYvWzoLJZoPIxkPxMODfh3JtTtwEyoG/kAZmUIUU9CB6ZuPKQhVoRpPm 6ZMs49Gu/WyoJ122wvoFVbkoJ/mTtblOs3+547FlHKbQc0/zz/eJ17LdErNirMTNsvM+ iy9g== X-Gm-Message-State: AOAM530DgqGI39F3r5aXh3WWIqr9UA5UjHNb7/dxSiKtM7Z/HChGJIpb cLDSbDuUKLChd2arxYylTLdU4A== X-Google-Smtp-Source: ABdhPJy2Uiaw9/Vk20QZUs4DTJpwJgz6ER4XMX/xKy6cZCGmfbQYeiAEaBAtINJB0mvtZeWBZ4BF6g== X-Received: by 2002:a5d:4885:0:b0:206:a05:232 with SMTP id g5-20020a5d4885000000b002060a050232mr6968860wrq.253.1649254722818; Wed, 06 Apr 2022 07:18:42 -0700 (PDT) Received: from google.com (203.75.199.104.bc.googleusercontent.com. [104.199.75.203]) by smtp.gmail.com with ESMTPSA id o19-20020a05600c511300b0038d0d8f67e5sm5027908wms.16.2022.04.06.07.18.41 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 06 Apr 2022 07:18:42 -0700 (PDT) Date: Wed, 6 Apr 2022 15:18:38 +0100 From: =?utf-8?Q?Pierre-Cl=C3=A9ment?= Tosi To: Andrew Scull Cc: u-boot@lists.denx.de, sjg@chromium.org, bmeng.cn@gmail.com, adelva@google.com, keirf@google.com, Sughosh Ganu Subject: Re: [PATCH 10/11] virtio: rng: Check length before copying Message-ID: <20220406141838.jctudjhaypgncdwu@google.com> References: <20220331100949.3637425-1-ascull@google.com> <20220331100949.3637425-11-ascull@google.com> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <20220331100949.3637425-11-ascull@google.com> X-BeenThere: u-boot@lists.denx.de X-Mailman-Version: 2.1.39 Precedence: list List-Id: U-Boot discussion List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: u-boot-bounces@lists.denx.de Sender: "U-Boot" X-Virus-Scanned: clamav-milter 0.103.5 at phobos.denx.de X-Virus-Status: Clean Hi, On Thu, Mar 31, 2022 at 10:09:48AM +0000, Andrew Scull wrote: > Check the length of data written by the device is consistent with the > size of the buffers to avoid out-of-bounds memory accesses in case > values aren't consistent. > > Signed-off-by: Andrew Scull > Cc: Sughosh Ganu > --- > drivers/virtio/virtio_rng.c | 3 +++ > 1 file changed, 3 insertions(+) > > diff --git a/drivers/virtio/virtio_rng.c b/drivers/virtio/virtio_rng.c > index 9314c0a03e..b85545c2ee 100644 > --- a/drivers/virtio/virtio_rng.c > +++ b/drivers/virtio/virtio_rng.c > @@ -41,6 +41,9 @@ static int virtio_rng_read(struct udevice *dev, void *data, size_t len) > while (!virtqueue_get_buf(priv->rng_vq, &rsize)) > ; > > + if (rsize > sg.length) > + return -EIO; > + Although this patch addresses a legitimate concern, could we instead aim for strengthening the lower-level virtio building blocks (e.g. virtqueue_get_buf()) so that higher-level virtio device drivers such as virtio-{rng,console,net,...} don't have to be littered with checks of this nature? Could this be achieved by using the shadow copy introduced in [PATCH 03/11]? > memcpy(ptr, buf, rsize); > len -= rsize; > ptr += rsize; > -- > 2.35.1.1094.g7c7d902a7c-goog > Thanks, -- Pierre