Received: by 2002:a25:1985:0:0:0:0:0 with SMTP id 127csp120552ybz; Tue, 21 Apr 2020 06:00:01 -0700 (PDT) X-Google-Smtp-Source: APiQypKlT88hMUwKg9DFqpbrYXwE208bTo6/uRox0CNATS8yM84+Rke5TjR3U6pbzdSVmnaTWYFM X-Received: by 2002:a05:6402:1768:: with SMTP id da8mr18980003edb.216.1587474001573; Tue, 21 Apr 2020 06:00:01 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1587474001; cv=none; d=google.com; s=arc-20160816; b=W35GYN/GC0VbvqZAq1uiRZGmSQw/iemyCPdURXR+9nUutlJlQYEsPKmF+iQXIh527r rc9kmWK3TT7dQR9pivXKDOOU0ZcR0juM2OXYgwPm+nicfauWjDvf7erIeolF/gxU0a6h Ito5r6yoabgn6YDGcnUQUdiFLz0CXL2/DlSylSD8NcmSq88YYzkXN9GHsrcScOnYG3KU Ml2aOjysXfcWogmb9SBQmtO7OPkvy0saXYSMQV5SfoTKS529OAMUJ2n7nrZvCsZeoUn0 wVcUSuhAxnhD9XYTEQKPdHBa+R0/LG40LeaSkU4unoV6d5BxgBugs39bzu4v9a1JtW75 1L2w== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:sender:content-transfer-encoding:mime-version :references:in-reply-to:message-id:date:subject:cc:to:from; bh=CzVUK+8+Cyh1jLtMoHSeKW2urHEoxIGPwaTFRn76lTw=; b=o7tmQ9hcRRP5zXEu50mcYuG0k6ndWmZbaB5V3Yd/1950cQ7Yvt7QIPtp1Sf8p7xHmI pfSIr+XmaR6bcflCJl0a5UclAcChjhMzm7pFlo+ll6TAZLH6fzhntCRMR18zkTzTKZO0 4H8PwTMFrzzOw4xpX7h+C7zyMOePGDb1/z3m/sdXtmyBHXyIxC1enSncsYRynFgSiWeF xeP43qAMIrCO4zOUFj+KKmhy51iWYbXkD9xlfBzpbP4y0QAlPhhrUUJl8tasXh24627v EcyGiA1ExxPk+EsJUQHE0XDAIicPNYXudfzbxRIK7ryJY1OlStFwVwq925i+IyVqekP/ Qoww== ARC-Authentication-Results: i=1; mx.google.com; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org Return-Path: Received: from vger.kernel.org (vger.kernel.org. [23.128.96.18]) by mx.google.com with ESMTP id oy6si1516237ejb.383.2020.04.21.05.59.38; Tue, 21 Apr 2020 06:00:01 -0700 (PDT) Received-SPF: pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) client-ip=23.128.96.18; Authentication-Results: mx.google.com; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1728886AbgDUM6L (ORCPT + 99 others); Tue, 21 Apr 2020 08:58:11 -0400 Received: from mail-lj1-f194.google.com ([209.85.208.194]:41722 "EHLO mail-lj1-f194.google.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1728847AbgDUM6J (ORCPT ); Tue, 21 Apr 2020 08:58:09 -0400 Received: by mail-lj1-f194.google.com with SMTP id j3so13815857ljg.8; Tue, 21 Apr 2020 05:58:08 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:to:cc:subject:date:message-id:in-reply-to :references:mime-version:content-transfer-encoding; bh=CzVUK+8+Cyh1jLtMoHSeKW2urHEoxIGPwaTFRn76lTw=; b=j0OsekL5Osxppy2wDCC/PZmFUtKjWAGQJSgQNwmgKav/0QzwugYc8biG+e6IMqQUL1 fH02eqvLuYJBGNu/o538eXrPe0fXNRof40ARKNjWEqZ8/2jLVo1VT2413xOUmnNt5+rS sNnQGySkJXpvDzLrNbVY1biW7dJbUPwp/zNzhgV4JrU8l3CFH57LeFGGSbOaIohTefob gHuaT7EeGDpbdfbjc6dDJt06ocuiCg0/ljNbrdCvEMnvk/MWewvZyB2flshXsdGlLT4f V5TnehzGUbrKM1ezoNuXnwr3Irud0kowYr0EUstyQOx/RZ3F1971xBZ+n+rFdMqRl9+R C+VA== X-Gm-Message-State: AGi0PuaOZHqkwBjwY+pvDaafH+TR/QOVLf6AinkfRdg5JApHmnj0ubqs Oh5MA94eKU5qkC6DplgIZVPt4Nwsrfk= X-Received: by 2002:a2e:164b:: with SMTP id 11mr12901489ljw.23.1587473887028; Tue, 21 Apr 2020 05:58:07 -0700 (PDT) Received: from localhost.localdomain ([213.87.162.215]) by smtp.googlemail.com with ESMTPSA id z7sm1902268ljc.17.2020.04.21.05.58.02 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 21 Apr 2020 05:58:03 -0700 (PDT) From: Denis Efremov To: linux-block@vger.kernel.org Cc: Denis Efremov , Willy Tarreau , linux-kernel@vger.kernel.org Subject: [PATCH 3/3] floppy: suppress UBSAN warning in setup_rw_floppy() Date: Tue, 21 Apr 2020 15:57:22 +0300 Message-Id: <20200421125722.58959-4-efremov@linux.com> X-Mailer: git-send-email 2.25.3 In-Reply-To: <20200421125722.58959-1-efremov@linux.com> References: <20200421125722.58959-1-efremov@linux.com> MIME-Version: 1.0 Content-Transfer-Encoding: 8bit Sender: linux-kernel-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org UBSAN: array-index-out-of-bounds in drivers/block/floppy.c:1521:45 index 16 is out of range for type 'unsigned char [16]' Call Trace: ... setup_rw_floppy+0x5c3/0x7f0 floppy_ready+0x2be/0x13b0 process_one_work+0x2c1/0x5d0 worker_thread+0x56/0x5e0 kthread+0x122/0x170 ret_from_fork+0x35/0x40 From include/uapi/linux/fd.h: struct floppy_raw_cmd { ... unsigned char cmd_count; unsigned char cmd[16]; unsigned char reply_count; unsigned char reply[16]; ... } This out-of-bounds access is intentional. The command in struct floppy_raw_cmd may take up the space initially intended for the reply and the reply count. It is needed for long 82078 commands such as RESTORE, which takes 17 command bytes. Initial cmd size is not enough and since struct setup_rw_floppy is a part of uapi we check that cmd_count is in [0:16+1+16] in raw_cmd_copyin(). The patch replaces array subscript with pointer arithetic to suppress UBSAN warning. Signed-off-by: Denis Efremov --- drivers/block/floppy.c | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/drivers/block/floppy.c b/drivers/block/floppy.c index 2169df796d18..63981b1f8d4c 100644 --- a/drivers/block/floppy.c +++ b/drivers/block/floppy.c @@ -1518,7 +1518,10 @@ static void setup_rw_floppy(void) r = 0; for (i = 0; i < raw_cmd->cmd_count; i++) - r |= output_byte(current_fdc, raw_cmd->cmd[i]); + /* The command may take up the space initially intended for the + * reply and the reply count. + */ + r |= output_byte(current_fdc, *(raw_cmd->cmd + i)); debugt(__func__, "rw_command"); -- 2.25.3