Page MenuHomeFreeBSD

mpi3mr: Validate entry counts against payload length in topology events
Needs ReviewPublic

Authored by chandrakanth.patil_broadcom.com on Sun, Oct 4, 2:14 PM.
Tags
None
Referenced Files
F175270551: D60336.id188635.diff
Fri, Oct 9, 3:01 PM
F175258770: D60336.diff
Fri, Oct 9, 12:25 PM
Unknown Object (File)
Thu, Oct 8, 10:44 PM
Unknown Object (File)
Thu, Oct 8, 7:51 AM
Unknown Object (File)
Thu, Oct 8, 1:53 AM
Unknown Object (File)
Wed, Oct 7, 11:10 PM
Unknown Object (File)
Wed, Oct 7, 3:14 PM
Unknown Object (File)
Wed, Oct 7, 10:38 AM
Subscribers
None

Details

Summary

When the controller notifies the driver of SAS or PCIe topology changes,
the firmware event notification includes a payload length and an entry
count indicating the number of PHY or port descriptors attached to the
event. Previously, the top-half event handlers iterated over the entry
count without verifying whether the payload buffer was actually large
enough to contain all reported entries. A malformed event with an entry
count exceeding the buffer length would result in reading memory beyond
the event descriptor.

Validate that the reported event length covers the base topology header
and compute the maximum number of entries that fit within the payload.
If the entry count exceeds the available buffer, reject the event and
skip scheduling deferred bottom-half processing.

Test Plan
  • Clean build with WERROR=-Werror across FreeBSD 16, 15, and 14 with INVARIANTS/WITNESS enabled; git bisect verified.
  • Tested SAS and PCIe topology change events by cable hot-plugging expanders and drives on SAS4116/SAS5116 controllers.
  • Verified that valid topology change events are parsed accurately and that entry count bounds checking prevents out-of-bounds reads.

Diff Detail

Lint
Lint Skipped
Unit
Tests Skipped

Event Timeline

sys/dev/mpi3mr/mpi3mr.c
4193

sys/dev/mpi3mr/mpi/mpi30_ioc.h: U8 EventDataLength; /* 0x10 */
Since this is a 1 byte feild, this conversion is wrong on big endian, here and below.

sys/dev/mpi3mr/mpi3mr.c
4193

sys/dev/mpi3mr/mpi/mpi30_ioc.h: U8 EventDataLength; /* 0x10 */
Since this is a 1 byte feild, this conversion is wrong on big endian, here and below.

Thanks. I will remove le16toh() and use direct multiplication here and below in V2 patch.