# git rev-parse -q --verify 6754297c2924cd55843499bc2bb338843177931f^{commit} 6754297c2924cd55843499bc2bb338843177931f already have revision, skipping fetch # git checkout -q -f -B kisskb 6754297c2924cd55843499bc2bb338843177931f # git clean -qxdf # < git log -1 # commit 6754297c2924cd55843499bc2bb338843177931f # Author: Daniel Axtens # Date: Mon Jun 3 16:56:57 2019 +1000 # # powerpc/pseries/hvconsole: Fix stack overread via udbg # # While developing KASAN for 64-bit book3s, I hit the following stack # over-read. # # It occurs because the hypercall to put characters onto the terminal # takes 2 longs (128 bits/16 bytes) of characters at a time, and so # hvc_put_chars() would unconditionally copy 16 bytes from the argument # buffer, regardless of supplied length. However, udbg_hvc_putc() can # call hvc_put_chars() with a single-byte buffer, leading to the error. # # ================================================================== # BUG: KASAN: stack-out-of-bounds in hvc_put_chars+0xdc/0x110 # Read of size 8 at addr c0000000023e7a90 by task swapper/0 # # CPU: 0 PID: 0 Comm: swapper Not tainted 5.2.0-rc2-next-20190528-02824-g048a6ab4835b #113 # Call Trace: # dump_stack+0x104/0x154 (unreliable) # print_address_description+0xa0/0x30c # __kasan_report+0x20c/0x224 # kasan_report+0x18/0x30 # __asan_report_load8_noabort+0x24/0x40 # hvc_put_chars+0xdc/0x110 # hvterm_raw_put_chars+0x9c/0x110 # udbg_hvc_putc+0x154/0x200 # udbg_write+0xf0/0x240 # console_unlock+0x868/0xd30 # register_console+0x970/0xe90 # register_early_udbg_console+0xf8/0x114 # setup_arch+0x108/0x790 # start_kernel+0x104/0x784 # start_here_common+0x1c/0x534 # # Memory state around the buggy address: # c0000000023e7980: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 # c0000000023e7a00: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 f1 f1 # >c0000000023e7a80: f1 f1 01 f2 f2 f2 00 00 00 00 00 00 00 00 00 00 # ^ # c0000000023e7b00: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 # c0000000023e7b80: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 # ================================================================== # # Document that a 16-byte buffer is requred, and provide it in udbg. # # Signed-off-by: Daniel Axtens # Signed-off-by: Michael Ellerman # < /opt/cross/kisskb/korg/gcc-8.1.0-nolibc/powerpc64-linux/bin/powerpc64-linux-gcc --version # < /opt/cross/kisskb/korg/gcc-8.1.0-nolibc/powerpc64-linux/bin/powerpc64-linux-ld --version # < git log --format=%s --max-count=1 6754297c2924cd55843499bc2bb338843177931f # < make -s -j 48 ARCH=powerpc O=/kisskb/build/powerpc-next_ppc6xx_defconfig_powerpc-gcc8 CROSS_COMPILE=/opt/cross/kisskb/korg/gcc-8.1.0-nolibc/powerpc64-linux/bin/powerpc64-linux- ppc6xx_defconfig # make -s -j 48 ARCH=powerpc O=/kisskb/build/powerpc-next_ppc6xx_defconfig_powerpc-gcc8 CROSS_COMPILE=/opt/cross/kisskb/korg/gcc-8.1.0-nolibc/powerpc64-linux/bin/powerpc64-linux- /kisskb/src/kernel/futex.c: In function 'do_futex': /kisskb/src/kernel/futex.c:1658:17: warning: 'oldval' may be used uninitialized in this function [-Wmaybe-uninitialized] return oldval == cmparg; ~~~~~~~^~~~~~~~~ /kisskb/src/kernel/futex.c:1633:6: note: 'oldval' was declared here int oldval, ret; ^~~~~~ In file included from /kisskb/src/sound/ppc/pmac.h:25, from /kisskb/src/sound/ppc/awacs.c:29: /kisskb/src/sound/ppc/awacs.c: In function 'snd_pmac_awacs_init': /kisskb/src/include/sound/control.h:223:9: warning: 'speaker_vol' may be used uninitialized in this function [-Wmaybe-uninitialized] return _snd_ctl_add_slave(master, slave, 0); ^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ /kisskb/src/sound/ppc/awacs.c:886:36: note: 'speaker_vol' was declared here struct snd_kcontrol *master_vol, *speaker_vol; ^~~~~~~~~~~ INFO: Uncompressed kernel (size 0xbbb984) overlaps the address of the wrapper(0x400000) INFO: Fixing the link_address of wrapper to (0xc00000) INFO: Uncompressed kernel (size 0xbbb984) overlaps the address of the wrapper(0x400000) INFO: Fixing the link_address of wrapper to (0xc00000) INFO: Uncompressed kernel (size 0xbbb984) overlaps the address of the wrapper(0x400000) INFO: Fixing the link_address of wrapper to (0xc00000) INFO: Uncompressed kernel (size 0xbbb984) overlaps the address of the wrapper(0x400000) INFO: Fixing the link_address of wrapper to (0xc00000) INFO: Uncompressed kernel (size 0xbbb984) overlaps the address of the wrapper(0x400000) INFO: Fixing the link_address of wrapper to (0xc00000) INFO: Uncompressed kernel (size 0xbbb984) overlaps the address of the wrapper(0x400000) INFO: Fixing the link_address of wrapper to (0xc00000) INFO: Uncompressed kernel (size 0xbbb984) overlaps the address of the wrapper(0x400000) INFO: Fixing the link_address of wrapper to (0xc00000) INFO: Uncompressed kernel (size 0xbbb984) overlaps the address of the wrapper(0x400000) INFO: Fixing the link_address of wrapper to (0xc00000) INFO: Uncompressed kernel (size 0xbbb984) overlaps the address of the wrapper(0x400000) INFO: Fixing the link_address of wrapper to (0xc00000) INFO: Uncompressed kernel (size 0xbab26c) overlaps the address of the wrapper(0x400000) INFO: Fixing the link_address of wrapper to (0xc00000) INFO: Uncompressed kernel (size 0xbab26c) overlaps the address of the wrapper(0x400000) INFO: Fixing the link_address of wrapper to (0xc00000) INFO: Uncompressed kernel (size 0xbbb984) overlaps the address of the wrapper(0x400000) INFO: Fixing the link_address of wrapper to (0xc00000) Image Name: Linux-5.2.0-rc2+ Created: Sat Jun 8 02:38:15 2019 Image Type: PowerPC Linux Kernel Image (gzip compressed) Data Size: 5587266 Bytes = 5456.31 KiB = 5.33 MiB Load Address: 00000000 Entry Point: 00000000 Image Name: Linux-5.2.0-rc2+ Created: Sat Jun 8 02:38:16 2019 Image Type: PowerPC Linux Kernel Image (gzip compressed) Data Size: 5622742 Bytes = 5490.96 KiB = 5.36 MiB Load Address: 00c00000 Entry Point: 00c002a4 Image Name: Linux-5.2.0-rc2+ Created: Sat Jun 8 02:38:17 2019 Image Type: PowerPC Linux Kernel Image (gzip compressed) Data Size: 5622965 Bytes = 5491.18 KiB = 5.36 MiB Load Address: 00c00000 Entry Point: 00c002a4 Image Name: Linux-5.2.0-rc2+ Created: Sat Jun 8 02:38:17 2019 Image Type: PowerPC Linux Kernel Image (gzip compressed) Data Size: 5623497 Bytes = 5491.70 KiB = 5.36 MiB Load Address: 00c00000 Entry Point: 00c00934 Image Name: Linux-5.2.0-rc2+ Created: Sat Jun 8 02:38:17 2019 Image Type: PowerPC Linux Kernel Image (gzip compressed) Data Size: 5622464 Bytes = 5490.69 KiB = 5.36 MiB Load Address: 00c00000 Entry Point: 00c002a4 Image Name: Linux-5.2.0-rc2+ Created: Sat Jun 8 02:38:17 2019 Image Type: PowerPC Linux Kernel Image (gzip compressed) Data Size: 5622292 Bytes = 5490.52 KiB = 5.36 MiB Load Address: 00c00000 Entry Point: 00c002a4 Image Name: Linux-5.2.0-rc2+ Created: Sat Jun 8 02:38:17 2019 Image Type: PowerPC Linux Kernel Image (gzip compressed) Data Size: 5623073 Bytes = 5491.28 KiB = 5.36 MiB Load Address: 00c00000 Entry Point: 00c002a4 Image Name: Linux-5.2.0-rc2+ Created: Sat Jun 8 02:38:18 2019 Image Type: PowerPC Linux Kernel Image (gzip compressed) Data Size: 5623665 Bytes = 5491.86 KiB = 5.36 MiB Load Address: 00c00000 Entry Point: 00c00934 Image Name: Linux-5.2.0-rc2+ Created: Sat Jun 8 02:38:18 2019 Image Type: PowerPC Linux Kernel Image (gzip compressed) Data Size: 5622846 Bytes = 5491.06 KiB = 5.36 MiB Load Address: 00c00000 Entry Point: 00c002a4 Completed OK # rm -rf /kisskb/build/powerpc-next_ppc6xx_defconfig_powerpc-gcc8 # Build took: 0:03:55.755975