mirror of
https://github.com/torvalds/linux.git
synced 2026-07-27 01:32:21 +02:00
chrome-platform-firmware: Updates for v7.2
* Improvements
- Add bound checks when iterating the coreboot table.
- Skip failing entries only instead of aborting the whole device
populate from the coreboot table.
-----BEGIN PGP SIGNATURE-----
iIkEABYKADEWIQS0yQeDP3cjLyifNRUrxTEGBto89AUCai9pAxMcdHp1bmdiaUBr
ZXJuZWwub3JnAAoJECvFMQYG2jz0Al8A/2+K6Up3CzuMZQyDJDOwkFb4Qx4CxfFu
iSecYI5xvUAqAQC28M9Tlg73QBl88ZOzcR9WGE8b7P+sW4UQ/Z8BQ1RTBg==
=HJUM
-----END PGP SIGNATURE-----
Merge tag 'chrome-platform-firmware-v7.2' of git://git.kernel.org/pub/scm/linux/kernel/git/chrome-platform/linux
Pull chrome-platform firmware updates from Tzung-Bi Shih:
- Add bound checks when iterating the coreboot table
- Skip failing entries only instead of aborting the whole device
populate from the coreboot table
* tag 'chrome-platform-firmware-v7.2' of git://git.kernel.org/pub/scm/linux/kernel/git/chrome-platform/linux:
firmware: google: Skip failing entries instead of aborting populate
firmware: google: Add bounds checks in coreboot_table_populate()
This commit is contained in:
commit
fd1878584d
|
|
@ -112,16 +112,20 @@ void coreboot_driver_unregister(struct coreboot_driver *driver)
|
|||
}
|
||||
EXPORT_SYMBOL(coreboot_driver_unregister);
|
||||
|
||||
static int coreboot_table_populate(struct device *dev, void *ptr)
|
||||
static int coreboot_table_populate(struct device *dev, void *ptr, resource_size_t len)
|
||||
{
|
||||
int i, ret;
|
||||
void *ptr_entry;
|
||||
struct coreboot_device *device;
|
||||
struct coreboot_table_entry *entry;
|
||||
struct coreboot_table_header *header = ptr;
|
||||
void *ptr_end;
|
||||
|
||||
ptr_end = ptr + len;
|
||||
ptr_entry = ptr + header->header_bytes;
|
||||
for (i = 0; i < header->table_entries; i++) {
|
||||
if (ptr_entry + sizeof(*entry) > ptr_end)
|
||||
return -EINVAL;
|
||||
entry = ptr_entry;
|
||||
|
||||
if (entry->size < sizeof(*entry)) {
|
||||
|
|
@ -129,6 +133,9 @@ static int coreboot_table_populate(struct device *dev, void *ptr)
|
|||
return -EINVAL;
|
||||
}
|
||||
|
||||
if (ptr_entry + entry->size > ptr_end)
|
||||
return -EINVAL;
|
||||
|
||||
device = kzalloc(sizeof(device->dev) + entry->size, GFP_KERNEL);
|
||||
if (!device)
|
||||
return -ENOMEM;
|
||||
|
|
@ -148,13 +155,13 @@ static int coreboot_table_populate(struct device *dev, void *ptr)
|
|||
break;
|
||||
}
|
||||
|
||||
ptr_entry += entry->size;
|
||||
|
||||
ret = device_register(&device->dev);
|
||||
if (ret) {
|
||||
dev_warn(dev, "failed to register coreboot device: %d\n", ret);
|
||||
put_device(&device->dev);
|
||||
return ret;
|
||||
}
|
||||
|
||||
ptr_entry += entry->size;
|
||||
}
|
||||
|
||||
return 0;
|
||||
|
|
@ -194,7 +201,7 @@ static int coreboot_table_probe(struct platform_device *pdev)
|
|||
if (!ptr)
|
||||
return -ENOMEM;
|
||||
|
||||
ret = coreboot_table_populate(dev, ptr);
|
||||
ret = coreboot_table_populate(dev, ptr, len);
|
||||
|
||||
memunmap(ptr);
|
||||
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user