From patchwork Wed Oct 29 16:09:32 2014 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ard Biesheuvel X-Patchwork-Id: 39788 Return-Path: X-Original-To: linaro@patches.linaro.org Delivered-To: linaro@patches.linaro.org Received: from mail-wg0-f69.google.com (mail-wg0-f69.google.com [74.125.82.69]) by ip-10-151-82-157.ec2.internal (Postfix) with ESMTPS id 9F6E924029 for ; Wed, 29 Oct 2014 16:09:55 +0000 (UTC) Received: by mail-wg0-f69.google.com with SMTP id m15sf1887725wgh.8 for ; Wed, 29 Oct 2014 09:09:54 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:mime-version:delivered-to:from:to:cc:subject :date:message-id:sender:precedence:list-id:x-original-sender :x-original-authentication-results:mailing-list:list-post:list-help :list-archive:list-unsubscribe; bh=+RjhzOks/ppnYBvIYOc+Vm6fgGRFTsKMyk40fFRv4gA=; b=RK+lqC+QXUa37BFlbdtFLT00uVVEz07wvp+SrMGK+HYn6Pl5V/ry7jb8IVRpqS5aJJ y0jlIRy3eHOqt8ryga7pltAP8aHmjrKYAXeVOOtQ+VbPTP0aZsWLCXEVCzZ9BWgwln25 e1yfIsYUvvb8ckxUyVmoh3AAVYZTvfvkOptUZdrEm8/LjT/H8nEzdN02S+q0wbw7YthE j7z1x7ge88A2a0acuVjyE1Ni6Jid0qaiqpfs3ARKxCJzu6ULt8zCmujBZhDHXgXD/6xF hHVtOsX5dD8+uvIqgXo1s0t7WlpBx4XDMTGPGU3E3TttXXM2AKgW26k9q0hK6o2vrKsh +tOw== X-Gm-Message-State: ALoCoQngu2XVGPZkJjp8VKgoS5asz/c/F1W9DS/Cg8McmBTLYrUKwmcyoRWfa5tn39KodDg7Q/xU X-Received: by 10.180.182.164 with SMTP id ef4mr2030112wic.0.1414598994423; Wed, 29 Oct 2014 09:09:54 -0700 (PDT) MIME-Version: 1.0 X-BeenThere: patchwork-forward@linaro.org Received: by 10.152.243.9 with SMTP id wu9ls218440lac.51.gmail; Wed, 29 Oct 2014 09:09:54 -0700 (PDT) X-Received: by 10.152.36.5 with SMTP id m5mr12323845laj.51.1414598994264; Wed, 29 Oct 2014 09:09:54 -0700 (PDT) Received: from mail-lb0-f175.google.com (mail-lb0-f175.google.com. [209.85.217.175]) by mx.google.com with ESMTPS id j9si7901054lab.13.2014.10.29.09.09.54 for (version=TLSv1 cipher=ECDHE-RSA-RC4-SHA bits=128/128); Wed, 29 Oct 2014 09:09:54 -0700 (PDT) Received-SPF: pass (google.com: domain of patch+caf_=patchwork-forward=linaro.org@linaro.org designates 209.85.217.175 as permitted sender) client-ip=209.85.217.175; Received: by mail-lb0-f175.google.com with SMTP id b6so2711828lbj.20 for ; Wed, 29 Oct 2014 09:09:54 -0700 (PDT) X-Received: by 10.112.140.5 with SMTP id rc5mr12321790lbb.32.1414598994125; Wed, 29 Oct 2014 09:09:54 -0700 (PDT) X-Forwarded-To: patchwork-forward@linaro.org X-Forwarded-For: patch@linaro.org patchwork-forward@linaro.org Delivered-To: patch@linaro.org Received: by 10.112.84.229 with SMTP id c5csp687781lbz; Wed, 29 Oct 2014 09:09:53 -0700 (PDT) X-Received: by 10.68.239.5 with SMTP id vo5mr11630864pbc.14.1414598992504; Wed, 29 Oct 2014 09:09:52 -0700 (PDT) Received: from vger.kernel.org (vger.kernel.org. [209.132.180.67]) by mx.google.com with ESMTP id et10si4341584pad.131.2014.10.29.09.09.51 for ; Wed, 29 Oct 2014 09:09:52 -0700 (PDT) Received-SPF: none (google.com: devicetree-owner@vger.kernel.org does not designate permitted sender hosts) client-ip=209.132.180.67; Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S933452AbaJ2QJv (ORCPT + 4 others); Wed, 29 Oct 2014 12:09:51 -0400 Received: from mail-wi0-f169.google.com ([209.85.212.169]:56381 "EHLO mail-wi0-f169.google.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S932994AbaJ2QJu (ORCPT ); Wed, 29 Oct 2014 12:09:50 -0400 Received: by mail-wi0-f169.google.com with SMTP id n3so1958193wiv.2 for ; Wed, 29 Oct 2014 09:09:49 -0700 (PDT) X-Received: by 10.194.206.106 with SMTP id ln10mr13724433wjc.90.1414598989301; Wed, 29 Oct 2014 09:09:49 -0700 (PDT) Received: from ards-macbook-pro.local (cag06-7-83-153-85-71.fbx.proxad.net. [83.153.85.71]) by mx.google.com with ESMTPSA id bq6sm4325393wib.1.2014.10.29.09.09.48 for (version=TLSv1.1 cipher=ECDHE-RSA-RC4-SHA bits=128/128); Wed, 29 Oct 2014 09:09:48 -0700 (PDT) From: Ard Biesheuvel To: grant.likely@linaro.org, rob.herring@linaro.org, devicetree@vger.kernel.org Cc: leif.lindholm@linaro.org, Ard Biesheuvel Subject: [PATCH] of: check for size < 0 after rounding in early_init_dt_add_memory_arch Date: Wed, 29 Oct 2014 17:09:32 +0100 Message-Id: <1414598972-22761-1-git-send-email-ard.biesheuvel@linaro.org> X-Mailer: git-send-email 1.8.3.2 Sender: devicetree-owner@vger.kernel.org Precedence: list List-ID: X-Mailing-List: devicetree@vger.kernel.org X-Removed-Original-Auth: Dkim didn't pass. X-Original-Sender: ard.biesheuvel@linaro.org X-Original-Authentication-Results: mx.google.com; spf=pass (google.com: domain of patch+caf_=patchwork-forward=linaro.org@linaro.org designates 209.85.217.175 as permitted sender) smtp.mail=patch+caf_=patchwork-forward=linaro.org@linaro.org Mailing-list: list patchwork-forward@linaro.org; contact patchwork-forward+owners@linaro.org X-Google-Group-Id: 836684582541 List-Post: , List-Help: , List-Archive: List-Unsubscribe: , Memory regions passed to early_init_dt_add_memory_arch() are rounded to PAGE_SIZE by subtracting the size of the leading fractional page from the 'size' argument. However, size being a u64 type, if its value is sufficiently small, the subtraction wraps around and produces a bogus value, potentially leading to crashes. Fix this by ignoring the memory range in such cases. Signed-off-by: Ard Biesheuvel --- drivers/of/fdt.c | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/drivers/of/fdt.c b/drivers/of/fdt.c index d1ffca8b34ea..3b423f5b99c6 100644 --- a/drivers/of/fdt.c +++ b/drivers/of/fdt.c @@ -930,6 +930,11 @@ void __init __weak early_init_dt_add_memory_arch(u64 base, u64 size) const u64 phys_offset = __pa(PAGE_OFFSET); if (!PAGE_ALIGNED(base)) { + if (size < PAGE_SIZE - (base & ~PAGE_MASK)) { + pr_warn("Ignoring memory block 0x%llx - 0x%llx\n", + base, base + size); + return; + } size -= PAGE_SIZE - (base & ~PAGE_MASK); base = PAGE_ALIGN(base); }