[RFC 2/2] MIPS: relocate_code: fix barebox image memcpy() size

Oleksij Rempel linux at rempel-privat.de
Tue Jun 18 04:05:06 PDT 2019


Am 18.06.19 um 11:38 schrieb Antony Pavlov:
> In this relocate_code() piece 'length' is greater than 'barebox_image_size':
>
>      #define MAX_BSS_SIZE SZ_1M
>      ...
>      length = barebox_image_size + MAX_BSS_SIZE;
>      relocaddr = ALIGN_DOWN(ram_size - barebox_image_size, SZ_64K);
>      ...
>      memcpy((void *)relocaddr, __image_start, length);
>
> so 'ram_size' overflow occurs during memcpy().
>
> Signed-off-by: Antony Pavlov <antonynpavlov at gmail.com>

Thenk you!

This patch is fixing relocatable barebox for malta-qemu and ihas no regressions on ar9331 DPT-Module!

Tested-by: Oleksij Rempel <o.rempel at pengutronix.de>

> ---
>   arch/mips/lib/reloc.c | 11 +++++------
>   1 file changed, 5 insertions(+), 6 deletions(-)
>
> diff --git a/arch/mips/lib/reloc.c b/arch/mips/lib/reloc.c
> index 9756d61666..14ba6167dd 100644
> --- a/arch/mips/lib/reloc.c
> +++ b/arch/mips/lib/reloc.c
> @@ -40,8 +40,6 @@
>   #include <linux/sizes.h>
>   #include <asm-generic/memory_layout.h>
>
> -#define MAX_BSS_SIZE SZ_1M
> -
>   void main_entry(void *fdt, u32 fdt_size);
>   void relocate_code(void *fdt, u32 fdt_size, u32 relocaddr);
>
> @@ -127,8 +125,10 @@ void relocate_code(void *fdt, u32 fdt_size, u32 ram_size)
>   	unsigned int type;
>   	long off;
>
> -	length = barebox_image_size + MAX_BSS_SIZE;
> -	relocaddr = ALIGN_DOWN(ram_size - barebox_image_size, SZ_64K);
> +	bss_len = (unsigned long)&__bss_stop - (unsigned long)__bss_start;
> +
> +	length = barebox_image_size + bss_len;
> +	relocaddr = ALIGN_DOWN(ram_size - length, SZ_64K);
>   	relocaddr = KSEG0ADDR(relocaddr);
>   	new_stack = relocaddr - MALLOC_SIZE - 16;
>
> @@ -143,7 +143,7 @@ void relocate_code(void *fdt, u32 fdt_size, u32 ram_size)
>   		panic("Mis-aligned relocation\n");
>
>   	/* Copy Barebox to RAM */
> -	memcpy((void *)relocaddr, __image_start, length);
> +	memcpy((void *)relocaddr, __image_start, barebox_image_size);
>
>   	/* Now apply relocations to the copy in RAM */
>   	buf = __rel_start;
> @@ -162,7 +162,6 @@ void relocate_code(void *fdt, u32 fdt_size, u32 ram_size)
>
>   	/* Clear the .bss section */
>   	bss_start = (uint8_t *)((unsigned long)__bss_start + off);
> -	bss_len = (unsigned long)&__bss_stop - (unsigned long)__bss_start;
>   	memset(bss_start, 0, bss_len);
>
>   	 __asm__ __volatile__ (
>


--
Regards,
Oleksij



More information about the barebox mailing list