Received: by 10.213.65.68 with SMTP id h4csp2116888imn; Sun, 8 Apr 2018 20:07:53 -0700 (PDT) X-Google-Smtp-Source: AIpwx4+uKcaOtIEmr8L7M7TNqPc9HW/cmCcCRDFFoQjqh4bv/mrZUKwUQpq7KW9lj0C3XJXmx3dH X-Received: by 2002:a17:902:20ca:: with SMTP id v10-v6mr37713026plg.9.1523243273155; Sun, 08 Apr 2018 20:07:53 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1523243273; cv=none; d=google.com; s=arc-20160816; b=VZ4Q3KsSzSiS26EENv6Tr4vhU7XlS8G9VwJwRlIYJp7tgXuWOd3lytFVP8b0CJ59e7 CH2QSQo9cduRIfRTxI90gJiUnXiGhz5p3yTPdpht1ydaJ91+0RP7EUesodEZu276DH9J 5lZ0aidG1gRw2midV9uTrVC4TvUEM2cHF8MsXTd0/z5krJ7Zyxx5HKA+mouHjWx0Ze1v q0dJG3lrIBvlQHpA6arWnbJgJL4HNxFJeS2vVpXpGnsomoWK+6KoeIkXdh2vDrIClyxt 0dwOZly5o++rnahcSKW7BQiIpHx0oty7GIZesROfl+4avR3T8cBSS28/tXFZnhxELGzM z4Ug== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:sender:mime-version:content-transfer-encoding :spamdiagnosticmetadata:spamdiagnosticoutput:content-language :accept-language:in-reply-to:references:message-id:date:thread-index :thread-topic:subject:cc:to:from:dkim-signature :arc-authentication-results; bh=a+ryFzz2YoSYziBEr2r9Lv54Fq4fhTMgtWKKzRVGVnw=; b=F4cUgLA4DCA0Z/BXfVuyJR/xs/BVa8xWzqpB718VbqDaGnnMDPJYj+3ho0EiTIrPhy AWCWpQ1jWMqQ9dQhGbSvhhkz9FtyZNneq72gfAyl8OJyl41dVI3AlHkJlamqKETjyUte x6giuZbsqrZsMAujKiIwYfXdMyp+HwkwxbCY3X6yRfDXacaWDrVN6viVw2tskh55j5p4 4sUr/rdNHybowwDcWsn8AhX/6Rp58G9N+WRculO0xysXA3rcew1g2+zIeQi2Bcnedvph fqOI6iFBl51fxyhg3LhXBVPIWhQWzc+SRdmwWMQViMCGFHgBzha6ZaRkUWSrO/LV8Pi1 Ql3w== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@microsoft.com header.s=selector1 header.b=BjcH32S/; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=microsoft.com Return-Path: Received: from vger.kernel.org (vger.kernel.org. [209.132.180.67]) by mx.google.com with ESMTP id f1-v6si16204974pld.168.2018.04.08.20.07.14; Sun, 08 Apr 2018 20:07:53 -0700 (PDT) Received-SPF: pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) client-ip=209.132.180.67; Authentication-Results: mx.google.com; dkim=pass header.i=@microsoft.com header.s=selector1 header.b=BjcH32S/; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=microsoft.com Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1756693AbeDIBhA (ORCPT + 99 others); Sun, 8 Apr 2018 21:37:00 -0400 Received: from mail-sn1nam02on0094.outbound.protection.outlook.com ([104.47.36.94]:35040 "EHLO NAM02-SN1-obe.outbound.protection.outlook.com" rhost-flags-OK-OK-OK-FAIL) by vger.kernel.org with ESMTP id S1754839AbeDIAfF (ORCPT ); Sun, 8 Apr 2018 20:35:05 -0400 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version; bh=a+ryFzz2YoSYziBEr2r9Lv54Fq4fhTMgtWKKzRVGVnw=; b=BjcH32S/vPTsX5mtR7mnSADz7vgO+cQ0TEQFFFtJ+KWwMj6olvLzLdiOFmTjz2IiTZu+18uG4LrKX3SivjvL9punmmz9ExSGleVwPKtMnj5VHuZEOQpn7e2SAucWc5zkqLUQwBkzTmEHoNvoUDOfELLI+LWJ/jwpzpyF2yn/7GQ= Received: from DM5PR2101MB1032.namprd21.prod.outlook.com (52.132.128.13) by DM5PR2101MB1013.namprd21.prod.outlook.com (52.132.133.35) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.696.0; Mon, 9 Apr 2018 00:35:01 +0000 Received: from DM5PR2101MB1032.namprd21.prod.outlook.com ([fe80::8109:aef0:a777:7059]) by DM5PR2101MB1032.namprd21.prod.outlook.com ([fe80::8109:aef0:a777:7059%2]) with mapi id 15.20.0696.003; Mon, 9 Apr 2018 00:35:01 +0000 From: Sasha Levin To: "stable@vger.kernel.org" , "linux-kernel@vger.kernel.org" CC: Bob Moore , Lv Zheng , "Rafael J . Wysocki" , Sasha Levin Subject: [PATCH AUTOSEL for 4.4 019/162] ACPICA: Disassembler: Abort on an invalid/unknown AML opcode Thread-Topic: [PATCH AUTOSEL for 4.4 019/162] ACPICA: Disassembler: Abort on an invalid/unknown AML opcode Thread-Index: AQHTz5mbZRSPQNnwlk6WZ9G0lNmnBQ== Date: Mon, 9 Apr 2018 00:27:56 +0000 Message-ID: <20180409002738.163941-19-alexander.levin@microsoft.com> References: <20180409002738.163941-1-alexander.levin@microsoft.com> In-Reply-To: <20180409002738.163941-1-alexander.levin@microsoft.com> Accept-Language: en-US Content-Language: en-US X-MS-Has-Attach: X-MS-TNEF-Correlator: x-originating-ip: [52.168.54.252] x-ms-publictraffictype: Email x-microsoft-exchange-diagnostics: 1;DM5PR2101MB1013;7:WFjfwuf7KExNA+O8AMxUDYZSeno/mhimuiC/n1OmanlNM2D/2ggrbOWKLq6gNNi+92X0Xo9UoXZZB85IibboNjt8HrY9UwRjTeMfWN2ty8CmwlssXC9rNwe/cFSR/3UsilbOQUIRi5F7FBB5vR4jApy9d1xe5BJps2Kvo1wOQGjgA+sSlhA4Tjn8f/b/0WrYNqLSMt+634vnIxHSXlao3tktoTraR3J9mneg7YSX+dzOPVoEHJtovz5+zIjJ+1iZ;20:nMFYjk6CjXEOHA7vqIR1lkJxr7RTSCy4j09nSVtTT/lLHHTOGgZcTxtBWGWgj+KUW3XhT7ORphflry5f3DMkQqMhizBbU0UJPCA9HArULvegppWQFYD8ul+NlfTGVLXEiQev9Tm7yfsNFP4MEMTLEbHRGdkkoxakzSGihfycsDA= X-MS-Office365-Filtering-Correlation-Id: 3566ea9b-a940-4d40-f7b6-08d59db1badd x-ms-office365-filtering-ht: Tenant x-microsoft-antispam: UriScan:;BCL:0;PCL:0;RULEID:(7020095)(4652020)(4534165)(4627221)(201703031133081)(201702281549075)(5600026)(4604075)(3008032)(48565401081)(2017052603328)(7193020);SRVR:DM5PR2101MB1013; x-ms-traffictypediagnostic: DM5PR2101MB1013: authentication-results: spf=none (sender IP is ) smtp.mailfrom=Alexander.Levin@microsoft.com; x-microsoft-antispam-prvs: x-exchange-antispam-report-test: UriScan:(28532068793085)(89211679590171)(166708455590820)(228905959029699); x-exchange-antispam-report-cfa-test: BCL:0;PCL:0;RULEID:(8211001083)(61425038)(6040522)(2401047)(8121501046)(5005006)(3231221)(944501327)(52105095)(3002001)(93006095)(93001095)(10201501046)(6055026)(61426038)(61427038)(6041310)(20161123560045)(20161123564045)(20161123558120)(20161123562045)(201703131423095)(201702281528075)(20161123555045)(201703061421075)(201703061406153)(6072148)(201708071742011);SRVR:DM5PR2101MB1013;BCL:0;PCL:0;RULEID:;SRVR:DM5PR2101MB1013; x-forefront-prvs: 0637FCE711 x-forefront-antispam-report: SFV:NSPM;SFS:(10019020)(39380400002)(39860400002)(396003)(346002)(366004)(376002)(189003)(199004)(478600001)(10290500003)(6436002)(5250100002)(2501003)(14454004)(966005)(305945005)(4326008)(66066001)(99286004)(10090500001)(6506007)(36756003)(102836004)(54906003)(486006)(107886003)(76176011)(59450400001)(2900100001)(22452003)(316002)(110136005)(575784001)(86362001)(3660700001)(2906002)(81166006)(186003)(86612001)(81156014)(2616005)(8936002)(3280700002)(11346002)(53936002)(7736002)(476003)(446003)(72206003)(68736007)(6116002)(5660300001)(106356001)(6666003)(6486002)(8676002)(1076002)(105586002)(26005)(6306002)(6512007)(3846002)(97736004)(25786009)(22906009)(217873001);DIR:OUT;SFP:1102;SCL:1;SRVR:DM5PR2101MB1013;H:DM5PR2101MB1032.namprd21.prod.outlook.com;FPR:;SPF:None;LANG:en;PTR:InfoNoRecords;MX:1;A:1; received-spf: None (protection.outlook.com: microsoft.com does not designate permitted sender hosts) x-microsoft-antispam-message-info: M5fhbDU2s4YwdSFGp3CxdtbJFC6kCMjFIuw7IMmd65WoZms+oMbx6a+RecSOj/Vn5cvSmqyKLHzZBmST5m8e5meYeqMCNjUalZP0JvUNvwnn+izsXLGjBIypccNZpH77zgUZHQQCEbZ+PjJ0hK6EjWJOPv9HY9vEMGrTbAsREFENNqdA8rmwkcb8L710UXCPNaCGjbVwXnq2SWaq88LVtyW4W4duOWEfaC/RHZbGbWu8uv9tXRQAEQg+efwXrmHF7uwoLLAg1qfJ2+HjppASCeDNJZ7QDPqbkH0XQvdWuN3+v9waTYYsLcHYF2V45MYzfqotmd5fRrM5t+ET2waGxT67AcVcgKhLNXCRVJ2BwWda1bZqxs5A7vH/92n/aRh1QA57c74un/NqhcK2iGcYeCMG43Rn9zYbo38jpsP084A= spamdiagnosticoutput: 1:99 spamdiagnosticmetadata: NSPM Content-Type: text/plain; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable MIME-Version: 1.0 X-OriginatorOrg: microsoft.com X-MS-Exchange-CrossTenant-Network-Message-Id: 3566ea9b-a940-4d40-f7b6-08d59db1badd X-MS-Exchange-CrossTenant-originalarrivaltime: 09 Apr 2018 00:27:56.6766 (UTC) X-MS-Exchange-CrossTenant-fromentityheader: Hosted X-MS-Exchange-CrossTenant-id: 72f988bf-86f1-41af-91ab-2d7cd011db47 X-MS-Exchange-Transport-CrossTenantHeadersStamped: DM5PR2101MB1013 Sender: linux-kernel-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org From: Bob Moore [ Upstream commit 6f0527b77d9e0129dd8e50945b0d610ed943d6b2 ] ACPICA commit ed0389cb11a61e63c568ac1f67948fc6a7bd1aeb An invalid opcode indicates something seriously wrong with the input AML file. The AML parser is immediately confused and lost, causing the resulting parse tree to be ill-formed. The actual disassembly can then cause numerous unrelated errors and faults. This change aborts the disassembly upon discovery of such an opcode during the AML parse phase. Link: https://github.com/acpica/acpica/commit/ed0389cb Signed-off-by: Bob Moore Signed-off-by: Lv Zheng Signed-off-by: Rafael J. Wysocki Signed-off-by: Sasha Levin --- drivers/acpi/acpica/psobject.c | 14 ++++++++++++++ 1 file changed, 14 insertions(+) diff --git a/drivers/acpi/acpica/psobject.c b/drivers/acpi/acpica/psobject.= c index e54bc2aa7a88..a05b3b79b987 100644 --- a/drivers/acpi/acpica/psobject.c +++ b/drivers/acpi/acpica/psobject.c @@ -121,6 +121,9 @@ static acpi_status acpi_ps_get_aml_opcode(struct acpi_w= alk_state *walk_state) (u32)(aml_offset + sizeof(struct acpi_table_header))); =20 + ACPI_ERROR((AE_INFO, + "Aborting disassembly, AML byte code is corrupt")); + /* Dump the context surrounding the invalid opcode */ =20 acpi_ut_dump_buffer(((u8 *)walk_state->parser_state. @@ -129,6 +132,14 @@ static acpi_status acpi_ps_get_aml_opcode(struct acpi_= walk_state *walk_state) sizeof(struct acpi_table_header) - 16)); acpi_os_printf(" */\n"); + + /* + * Just abort the disassembly, cannot continue because the + * parser is essentially lost. The disassembler can then + * randomly fail because an ill-constructed parse tree + * can result. + */ + return_ACPI_STATUS(AE_AML_BAD_OPCODE); #endif } =20 @@ -293,6 +304,9 @@ acpi_ps_create_op(struct acpi_walk_state *walk_state, if (status =3D=3D AE_CTRL_PARSE_CONTINUE) { return_ACPI_STATUS(AE_CTRL_PARSE_CONTINUE); } + if (ACPI_FAILURE(status)) { + return_ACPI_STATUS(status); + } =20 /* Create Op structure and append to parent's argument list */ =20 --=20 2.15.1