Page MenuHomeFreeBSD

mpi3mr: Bound event payload and log data copies to allocated buffer sizes
Needs ReviewPublic

Authored by chandrakanth.patil_broadcom.com on Sun, Oct 4, 2:16 PM.

Details

Summary

When processing asynchronous event notifications from controller firmware,
the driver trusted the firmware-reported event data length without verifying
whether it fit within the physical reply buffer frame. If an event reported a
length exceeding the reply frame size, copying the payload into bottom-half
event queues or saving diagnostic log data caused memory reads beyond the
reply buffer boundaries.

In addition, when saving log data into the driver's circular logging buffer,
the copy size was bounded against the total slot size rather than the payload
capacity, failing to account for the entry header and causing writes to
overflow into adjacent buffer slots.

Clamp all event data copy lengths to the maximum capacity of the reply
buffer frame, and account for entry header overhead when saving log data to
prevent buffer overflows.

Test Plan
  • Clean build with WERROR=-Werror across FreeBSD 16, 15, and 14 with INVARIANTS/WITNESS enabled; git bisect verified.
  • Tested firmware event logging and diagnostic log capture under heavy event traffic on SAS4116/SAS5116 controllers.
  • Verified that event payloads and circular log entries are safely bounded without memory over-reads or slot overflows.

Diff Detail

Lint
Lint Skipped
Unit
Tests Skipped

Event Timeline

sys/dev/mpi3mr/mpi3mr.c
4574

sys/dev/mpi3mr/mpi/mpi30_ioc.h: U8 EventDataLength; /* 0x10 */
Since this is a 1 byte field, this conversion is wrong on big endian, here and below. There's even one existing instance of this.