Page MenuHomeFreeBSD

nvme: bound the AER error log byte-swap by the fetched length
ClosedPublic

Authored by seuros on Sun, Sep 13, 8:46 AM.
Referenced Files
F174839374: D59626.diff
Tue, Oct 6, 10:02 AM
F174812065: D59626.diff
Tue, Oct 6, 3:52 AM
F174748451: D59626.id187516.diff
Mon, Oct 5, 5:30 PM
Unknown Object (File)
Mon, Oct 5, 6:00 AM
Unknown Object (File)
Fri, Oct 2, 8:25 AM
Unknown Object (File)
Thu, Oct 1, 2:03 PM
Unknown Object (File)
Tue, Sep 29, 5:43 PM
Unknown Object (File)
Sun, Sep 27, 7:12 PM
Subscribers

Details

Summary

The Get Log Page request for the error log is clamped to
NVME_MAX_AER_LOG_SIZE, but the byte-swap loop iterated ELPE + 1
entries. A controller reporting more than 63 entries makes the loop
overrun the 4 KiB log page buffer.

Diff Detail

Repository
rG FreeBSD src repository
Lint
Lint Not Applicable
Unit
Tests Not Applicable

Event Timeline

This revision is now accepted and ready to land.Tue, Sep 22, 3:40 AM
imp added inline comments.
sys/dev/nvme/nvme_ctrlr.c
1294

While this is right, we shouldn't be byte swapping the error log at all... there's too many formats and we can't know them all. It was a mistake to do this (one I tried to raise at the time, iirc, but there was so much else going on with the big endian patches)