Page MenuHomeFreeBSD

D60336.id188635.diff
No OneTemporary

D60336.id188635.diff

Index: sys/dev/mpi3mr/mpi3mr.c
===================================================================
--- sys/dev/mpi3mr/mpi3mr.c
+++ sys/dev/mpi3mr/mpi3mr.c
@@ -4179,7 +4179,7 @@
*
* Return: Nothing
*/
-static void mpi3mr_pcietopochg_evt_th(struct mpi3mr_softc *sc,
+static bool mpi3mr_pcietopochg_evt_th(struct mpi3mr_softc *sc,
Mpi3EventNotificationReply_t *event_reply)
{
Mpi3EventDataPcieTopologyChangeList_t *topo_evt =
@@ -4188,6 +4188,23 @@
U16 handle;
U8 reason_code;
struct mpi3mr_target *tgtdev = NULL;
+ U16 max_entries;
+
+ if ((U32)(le16toh(event_reply->EventDataLength) * 4) <
+ offsetof(Mpi3EventDataPcieTopologyChangeList_t, PortEntry)) {
+ mpi3mr_dprint(sc, MPI3MR_ERROR,
+ "PCIe topology event: event_data_length too small\n");
+ return (false);
+ }
+ max_entries = ((U32)(le16toh(event_reply->EventDataLength) * 4) -
+ offsetof(Mpi3EventDataPcieTopologyChangeList_t, PortEntry)) /
+ sizeof(topo_evt->PortEntry[0]);
+ if (topo_evt->NumEntries > max_entries) {
+ mpi3mr_dprint(sc, MPI3MR_ERROR,
+ "PCIe topology event: num_entries(%d) exceeds max(%d)\n",
+ topo_evt->NumEntries, max_entries);
+ return (false);
+ }
for (i = 0; i < topo_evt->NumEntries; i++) {
handle = le16toh(topo_evt->PortEntry[i].AttachedDevHandle);
@@ -4224,6 +4241,7 @@
break;
}
}
+ return (true);
}
/**
@@ -4238,7 +4256,7 @@
*
* Return: Nothing
*/
-static void mpi3mr_sastopochg_evt_th(struct mpi3mr_softc *sc,
+static bool mpi3mr_sastopochg_evt_th(struct mpi3mr_softc *sc,
Mpi3EventNotificationReply_t *event_reply)
{
Mpi3EventDataSasTopologyChangeList_t *topo_evt =
@@ -4247,6 +4265,23 @@
U16 handle;
U8 reason_code;
struct mpi3mr_target *tgtdev = NULL;
+ U16 max_entries;
+
+ if ((U32)(le16toh(event_reply->EventDataLength) * 4) <
+ offsetof(Mpi3EventDataSasTopologyChangeList_t, PhyEntry)) {
+ mpi3mr_dprint(sc, MPI3MR_ERROR,
+ "SAS topology event: event_data_length too small\n");
+ return (false);
+ }
+ max_entries = ((U32)(le16toh(event_reply->EventDataLength) * 4) -
+ offsetof(Mpi3EventDataSasTopologyChangeList_t, PhyEntry)) /
+ sizeof(topo_evt->PhyEntry[0]);
+ if (topo_evt->NumEntries > max_entries) {
+ mpi3mr_dprint(sc, MPI3MR_ERROR,
+ "SAS topology event: num_entries(%d) exceeds max(%d)\n",
+ topo_evt->NumEntries, max_entries);
+ return (false);
+ }
for (i = 0; i < topo_evt->NumEntries; i++) {
handle = le16toh(topo_evt->PhyEntry[i].AttachedDevHandle);
@@ -4283,7 +4318,7 @@
break;
}
}
-
+ return (true);
}
/**
* mpi3mr_devstatuschg_evt_th - DeviceStatusChange evt tophalf
@@ -4515,14 +4550,12 @@
}
case MPI3_EVENT_SAS_TOPOLOGY_CHANGE_LIST:
{
- process_evt_bh = 1;
- mpi3mr_sastopochg_evt_th(sc, event_reply);
+ process_evt_bh = mpi3mr_sastopochg_evt_th(sc, event_reply);
break;
}
case MPI3_EVENT_PCIE_TOPOLOGY_CHANGE_LIST:
{
- process_evt_bh = 1;
- mpi3mr_pcietopochg_evt_th(sc, event_reply);
+ process_evt_bh = mpi3mr_pcietopochg_evt_th(sc, event_reply);
break;
}
case MPI3_EVENT_PREPARE_FOR_RESET:

File Metadata

Mime Type
text/plain
Expires
Sat, Oct 10, 3:01 PM (4 h, 19 m)
Storage Engine
blob
Storage Format
Raw Data
Storage Handle
40346188
Default Alt Text
D60336.id188635.diff (3 KB)

Event Timeline