{"id":814488,"url":"http://patchwork.ozlabs.org/api/patches/814488/?format=json","web_url":"http://patchwork.ozlabs.org/project/qemu-devel/patch/20170916103523.1482-1-m.olbrich@pengutronix.de/","project":{"id":14,"url":"http://patchwork.ozlabs.org/api/projects/14/?format=json","name":"QEMU Development","link_name":"qemu-devel","list_id":"qemu-devel.nongnu.org","list_email":"qemu-devel@nongnu.org","web_url":"","scm_url":"","webscm_url":"","list_archive_url":"","list_archive_url_format":"","commit_url_format":""},"msgid":"<20170916103523.1482-1-m.olbrich@pengutronix.de>","list_archive_url":null,"date":"2017-09-16T10:35:23","name":"[v2] hw/sd: fix out-of-bounds check for multi block reads","commit_ref":null,"pull_url":null,"state":"new","archived":false,"hash":"78cd05bf10c5c9f98f9e515ad26f86bab07c5dae","submitter":{"id":64504,"url":"http://patchwork.ozlabs.org/api/people/64504/?format=json","name":"Michael Olbrich","email":"m.olbrich@pengutronix.de"},"delegate":null,"mbox":"http://patchwork.ozlabs.org/project/qemu-devel/patch/20170916103523.1482-1-m.olbrich@pengutronix.de/mbox/","series":[{"id":3429,"url":"http://patchwork.ozlabs.org/api/series/3429/?format=json","web_url":"http://patchwork.ozlabs.org/project/qemu-devel/list/?series=3429","date":"2017-09-16T10:35:23","name":"[v2] hw/sd: fix out-of-bounds check for multi block reads","version":2,"mbox":"http://patchwork.ozlabs.org/series/3429/mbox/"}],"comments":"http://patchwork.ozlabs.org/api/patches/814488/comments/","check":"pending","checks":"http://patchwork.ozlabs.org/api/patches/814488/checks/","tags":{},"related":[],"headers":{"Return-Path":"<qemu-devel-bounces+incoming=patchwork.ozlabs.org@nongnu.org>","X-Original-To":"incoming@patchwork.ozlabs.org","Delivered-To":"patchwork-incoming@bilbo.ozlabs.org","Authentication-Results":"ozlabs.org;\n\tspf=pass (mailfrom) smtp.mailfrom=nongnu.org\n\t(client-ip=2001:4830:134:3::11; helo=lists.gnu.org;\n\tenvelope-from=qemu-devel-bounces+incoming=patchwork.ozlabs.org@nongnu.org;\n\treceiver=<UNKNOWN>)","Received":["from lists.gnu.org (lists.gnu.org [IPv6:2001:4830:134:3::11])\n\t(using TLSv1 with cipher AES256-SHA (256/256 bits))\n\t(No client certificate requested)\n\tby ozlabs.org (Postfix) with ESMTPS id 3xvTFy67lQz9t2c\n\tfor <incoming@patchwork.ozlabs.org>;\n\tSat, 16 Sep 2017 20:36:19 +1000 (AEST)","from localhost ([::1]:56680 helo=lists.gnu.org)\n\tby lists.gnu.org with esmtp (Exim 4.71) (envelope-from\n\t<qemu-devel-bounces+incoming=patchwork.ozlabs.org@nongnu.org>)\n\tid 1dtASP-0004IP-7n\n\tfor incoming@patchwork.ozlabs.org; Sat, 16 Sep 2017 06:36:17 -0400","from eggs.gnu.org ([2001:4830:134:3::10]:46842)\n\tby lists.gnu.org with esmtp (Exim 4.71)\n\t(envelope-from <mol@pengutronix.de>) id 1dtARp-0004IF-6O\n\tfor qemu-devel@nongnu.org; Sat, 16 Sep 2017 06:35:42 -0400","from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71)\n\t(envelope-from <mol@pengutronix.de>) id 1dtARn-0005sR-V2\n\tfor qemu-devel@nongnu.org; Sat, 16 Sep 2017 06:35:41 -0400","from metis.ext.pengutronix.de\n\t([2001:67c:670:201:290:27ff:fe1d:cc33]:39857)\n\tby eggs.gnu.org with esmtps (TLS1.0:RSA_AES_128_CBC_SHA1:16)\n\t(Exim 4.71) (envelope-from <mol@pengutronix.de>) id 1dtARn-0005rh-MC\n\tfor qemu-devel@nongnu.org; Sat, 16 Sep 2017 06:35:39 -0400","from dude.hi.pengutronix.de ([2001:67c:670:100:1d::7])\n\tby metis.ext.pengutronix.de with esmtps\n\t(TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.84_2)\n\t(envelope-from <mol@pengutronix.de>)\n\tid 1dtARl-0003Zh-5T; Sat, 16 Sep 2017 12:35:37 +0200","from mol by dude.hi.pengutronix.de with local (Exim 4.89)\n\t(envelope-from <mol@pengutronix.de>)\n\tid 1dtARj-0000ks-HS; Sat, 16 Sep 2017 12:35:35 +0200"],"From":"Michael Olbrich <m.olbrich@pengutronix.de>","To":"qemu-devel@nongnu.org","Date":"Sat, 16 Sep 2017 12:35:23 +0200","Message-Id":"<20170916103523.1482-1-m.olbrich@pengutronix.de>","X-Mailer":"git-send-email 2.11.0","In-Reply-To":"<150555367996.36.15771330325496067998@69b6ddf88678>","References":"<150555367996.36.15771330325496067998@69b6ddf88678>","X-SA-Exim-Connect-IP":"2001:67c:670:100:1d::7","X-SA-Exim-Mail-From":"mol@pengutronix.de","X-SA-Exim-Scanned":"No (on metis.ext.pengutronix.de);\n\tSAEximRunCond expanded to false","X-PTX-Original-Recipient":"qemu-devel@nongnu.org","X-detected-operating-system":"by eggs.gnu.org: Genre and OS details not\n\trecognized.","X-Received-From":"2001:67c:670:201:290:27ff:fe1d:cc33","Subject":"[Qemu-devel] [PATCH v2] hw/sd: fix out-of-bounds check for multi\n\tblock reads","X-BeenThere":"qemu-devel@nongnu.org","X-Mailman-Version":"2.1.21","Precedence":"list","List-Id":"<qemu-devel.nongnu.org>","List-Unsubscribe":"<https://lists.nongnu.org/mailman/options/qemu-devel>,\n\t<mailto:qemu-devel-request@nongnu.org?subject=unsubscribe>","List-Archive":"<http://lists.nongnu.org/archive/html/qemu-devel/>","List-Post":"<mailto:qemu-devel@nongnu.org>","List-Help":"<mailto:qemu-devel-request@nongnu.org?subject=help>","List-Subscribe":"<https://lists.nongnu.org/mailman/listinfo/qemu-devel>,\n\t<mailto:qemu-devel-request@nongnu.org?subject=subscribe>","Cc":"Michael Olbrich <m.olbrich@pengutronix.de>","Errors-To":"qemu-devel-bounces+incoming=patchwork.ozlabs.org@nongnu.org","Sender":"\"Qemu-devel\"\n\t<qemu-devel-bounces+incoming=patchwork.ozlabs.org@nongnu.org>"},"content":"The current code checks if the next block exceeds the size of the card.\nThis generates an error while reading the last block of the card.\nDo the out-of-bounds check when starting to read a new block to fix this.\n\nThis issue became visible with increased error checking in Linux 4.13.\n\nSigned-off-by: Michael Olbrich <m.olbrich@pengutronix.de>\n---\n\nChanges in v2:\n - fixed warning\n\nI'm not quite sure if 0x00 is the correct return value, but it's used\nelsewhere in the same function when an error occurs, so it seems\nreasonable.\n\n hw/sd/sd.c | 12 ++++++------\n 1 file changed, 6 insertions(+), 6 deletions(-)","diff":"diff --git a/hw/sd/sd.c b/hw/sd/sd.c\nindex ba47bff4db80..35347a5bbcde 100644\n--- a/hw/sd/sd.c\n+++ b/hw/sd/sd.c\n@@ -1797,8 +1797,13 @@ uint8_t sd_read_data(SDState *sd)\n         break;\n \n     case 18:\t/* CMD18:  READ_MULTIPLE_BLOCK */\n-        if (sd->data_offset == 0)\n+        if (sd->data_offset == 0) {\n+            if (sd->data_start + io_len > sd->size) {\n+                sd->card_status |= ADDRESS_ERROR;\n+                return 0x00;\n+            }\n             BLK_READ_BLOCK(sd->data_start, io_len);\n+        }\n         ret = sd->data[sd->data_offset ++];\n \n         if (sd->data_offset >= io_len) {\n@@ -1812,11 +1817,6 @@ uint8_t sd_read_data(SDState *sd)\n                     break;\n                 }\n             }\n-\n-            if (sd->data_start + io_len > sd->size) {\n-                sd->card_status |= ADDRESS_ERROR;\n-                break;\n-            }\n         }\n         break;\n \n","prefixes":["v2"]}