Message ID | 153072701775.29016.13501175476729182702.stgit@jupiter.in.ibm.com (mailing list archive) |
---|---|
State | Accepted |
Commit | 74e96bf44f430cf7a01de19ba6cf49b361cdfd6e |
Headers | show |
Series | powerpc/pseries: Machine check handler improvements. | expand |
On Wed, 2018-07-04 at 17:57:02 UTC, Mahesh J Salgaonkar wrote: > From: Mahesh Salgaonkar <mahesh@linux.vnet.ibm.com> > > The global mce data buffer that used to copy rtas error log is of 2048 > (RTAS_ERROR_LOG_MAX) bytes in size. Before the copy we read > extended_log_length from rtas error log header, then use max of > extended_log_length and RTAS_ERROR_LOG_MAX as a size of data to be copied. > Ideally the platform (phyp) will never send extended error log with > size > 2048. But if that happens, then we have a risk of buffer overrun > and corruption. Fix this by using min_t instead. > > Fixes: d368514c3097 ("powerpc: Fix corruption when grabbing FWNMI data") > Reported-by: Michal Suchanek <msuchanek@suse.com> > Signed-off-by: Mahesh Salgaonkar <mahesh@linux.vnet.ibm.com> Applied to powerpc next, thanks. https://git.kernel.org/powerpc/c/74e96bf44f430cf7a01de19ba6cf49 cheers
diff --git a/arch/powerpc/platforms/pseries/ras.c b/arch/powerpc/platforms/pseries/ras.c index 5e1ef9150182..ef104144d4bc 100644 --- a/arch/powerpc/platforms/pseries/ras.c +++ b/arch/powerpc/platforms/pseries/ras.c @@ -371,7 +371,7 @@ static struct rtas_error_log *fwnmi_get_errinfo(struct pt_regs *regs) int len, error_log_length; error_log_length = 8 + rtas_error_extended_log_length(h); - len = max_t(int, error_log_length, RTAS_ERROR_LOG_MAX); + len = min_t(int, error_log_length, RTAS_ERROR_LOG_MAX); memset(global_mce_data_buf, 0, RTAS_ERROR_LOG_MAX); memcpy(global_mce_data_buf, h, len); errhdr = (struct rtas_error_log *)global_mce_data_buf;