Page MenuHomeFreeBSD

nvme: bound the AER error log byte-swap by the fetched length
ClosedPublic

Authored by seuros on Sun, Sep 13, 8:46 AM.
Referenced Files
F174980592: D59626.diff
Wed, Oct 7, 8:44 AM
F174958503: D59626.id187516.diff
Wed, Oct 7, 5:07 AM
Unknown Object (File)
Tue, Oct 6, 5:28 PM
Unknown Object (File)
Tue, Oct 6, 10:02 AM
Unknown Object (File)
Tue, Oct 6, 3:52 AM
Unknown Object (File)
Mon, Oct 5, 5:30 PM
Unknown Object (File)
Mon, Oct 5, 6:00 AM
Unknown Object (File)
Fri, Oct 2, 8:25 AM
Subscribers

Details

Summary

The Get Log Page request for the error log is clamped to
NVME_MAX_AER_LOG_SIZE, but the byte-swap loop iterated ELPE + 1
entries. A controller reporting more than 63 entries makes the loop
overrun the 4 KiB log page buffer.

Diff Detail

Repository
rG FreeBSD src repository
Lint
Lint Passed
Unit
No Test Coverage
Build Status
Buildable 76816
Build 73699: arc lint + arc unit

Event Timeline

This revision is now accepted and ready to land.Tue, Sep 22, 3:40 AM
imp added inline comments.
sys/dev/nvme/nvme_ctrlr.c
1294

While this is right, we shouldn't be byte swapping the error log at all... there's too many formats and we can't know them all. It was a mistake to do this (one I tried to raise at the time, iirc, but there was so much else going on with the big endian patches)