The Get Log Page request for the error log is clamped to
NVME_MAX_AER_LOG_SIZE, but the byte-swap loop iterated ELPE + 1
entries. A controller reporting more than 63 entries makes the loop
overrun the 4 KiB log page buffer.
Details
Details
Diff Detail
Diff Detail
- Repository
- rG FreeBSD src repository
- Lint
Lint Not Applicable - Unit
Tests Not Applicable
Event Timeline
| sys/dev/nvme/nvme_ctrlr.c | ||
|---|---|---|
| 1294 | While this is right, we shouldn't be byte swapping the error log at all... there's too many formats and we can't know them all. It was a mistake to do this (one I tried to raise at the time, iirc, but there was so much else going on with the big endian patches) | |