Page Menu
Home
FreeBSD
Search
Configure Global Search
Log In
Files
F175270551
D60336.id188635.diff
No One
Temporary
Actions
View File
Edit File
Delete File
View Transforms
Subscribe
Mute Notifications
Flag For Later
Award Token
Size
3 KB
Referenced Files
None
Subscribers
None
D60336.id188635.diff
View Options
Index: sys/dev/mpi3mr/mpi3mr.c
===================================================================
--- sys/dev/mpi3mr/mpi3mr.c
+++ sys/dev/mpi3mr/mpi3mr.c
@@ -4179,7 +4179,7 @@
*
* Return: Nothing
*/
-static void mpi3mr_pcietopochg_evt_th(struct mpi3mr_softc *sc,
+static bool mpi3mr_pcietopochg_evt_th(struct mpi3mr_softc *sc,
Mpi3EventNotificationReply_t *event_reply)
{
Mpi3EventDataPcieTopologyChangeList_t *topo_evt =
@@ -4188,6 +4188,23 @@
U16 handle;
U8 reason_code;
struct mpi3mr_target *tgtdev = NULL;
+ U16 max_entries;
+
+ if ((U32)(le16toh(event_reply->EventDataLength) * 4) <
+ offsetof(Mpi3EventDataPcieTopologyChangeList_t, PortEntry)) {
+ mpi3mr_dprint(sc, MPI3MR_ERROR,
+ "PCIe topology event: event_data_length too small\n");
+ return (false);
+ }
+ max_entries = ((U32)(le16toh(event_reply->EventDataLength) * 4) -
+ offsetof(Mpi3EventDataPcieTopologyChangeList_t, PortEntry)) /
+ sizeof(topo_evt->PortEntry[0]);
+ if (topo_evt->NumEntries > max_entries) {
+ mpi3mr_dprint(sc, MPI3MR_ERROR,
+ "PCIe topology event: num_entries(%d) exceeds max(%d)\n",
+ topo_evt->NumEntries, max_entries);
+ return (false);
+ }
for (i = 0; i < topo_evt->NumEntries; i++) {
handle = le16toh(topo_evt->PortEntry[i].AttachedDevHandle);
@@ -4224,6 +4241,7 @@
break;
}
}
+ return (true);
}
/**
@@ -4238,7 +4256,7 @@
*
* Return: Nothing
*/
-static void mpi3mr_sastopochg_evt_th(struct mpi3mr_softc *sc,
+static bool mpi3mr_sastopochg_evt_th(struct mpi3mr_softc *sc,
Mpi3EventNotificationReply_t *event_reply)
{
Mpi3EventDataSasTopologyChangeList_t *topo_evt =
@@ -4247,6 +4265,23 @@
U16 handle;
U8 reason_code;
struct mpi3mr_target *tgtdev = NULL;
+ U16 max_entries;
+
+ if ((U32)(le16toh(event_reply->EventDataLength) * 4) <
+ offsetof(Mpi3EventDataSasTopologyChangeList_t, PhyEntry)) {
+ mpi3mr_dprint(sc, MPI3MR_ERROR,
+ "SAS topology event: event_data_length too small\n");
+ return (false);
+ }
+ max_entries = ((U32)(le16toh(event_reply->EventDataLength) * 4) -
+ offsetof(Mpi3EventDataSasTopologyChangeList_t, PhyEntry)) /
+ sizeof(topo_evt->PhyEntry[0]);
+ if (topo_evt->NumEntries > max_entries) {
+ mpi3mr_dprint(sc, MPI3MR_ERROR,
+ "SAS topology event: num_entries(%d) exceeds max(%d)\n",
+ topo_evt->NumEntries, max_entries);
+ return (false);
+ }
for (i = 0; i < topo_evt->NumEntries; i++) {
handle = le16toh(topo_evt->PhyEntry[i].AttachedDevHandle);
@@ -4283,7 +4318,7 @@
break;
}
}
-
+ return (true);
}
/**
* mpi3mr_devstatuschg_evt_th - DeviceStatusChange evt tophalf
@@ -4515,14 +4550,12 @@
}
case MPI3_EVENT_SAS_TOPOLOGY_CHANGE_LIST:
{
- process_evt_bh = 1;
- mpi3mr_sastopochg_evt_th(sc, event_reply);
+ process_evt_bh = mpi3mr_sastopochg_evt_th(sc, event_reply);
break;
}
case MPI3_EVENT_PCIE_TOPOLOGY_CHANGE_LIST:
{
- process_evt_bh = 1;
- mpi3mr_pcietopochg_evt_th(sc, event_reply);
+ process_evt_bh = mpi3mr_pcietopochg_evt_th(sc, event_reply);
break;
}
case MPI3_EVENT_PREPARE_FOR_RESET:
File Metadata
Details
Attached
Mime Type
text/plain
Expires
Sat, Oct 10, 3:01 PM (4 h, 19 m)
Storage Engine
blob
Storage Format
Raw Data
Storage Handle
40346188
Default Alt Text
D60336.id188635.diff (3 KB)
Attached To
Mode
D60336: mpi3mr: Validate entry counts against payload length in topology events
Attached
Detach File
Event Timeline
Log In to Comment