提交 b79998fc 编写于 作者: N Nathan Fontenot 提交者: Paul Mackerras

powerpc: Zero fill the return values of rtas argument buffer

The kernel copy of the rtas args struct contains the return
value(s) for the specified rtas call.  These are copied back
to user space with the assumption that every value has been
set by the rtas call, which turns out to be not always true.
Thus userspace can see random values and think the call failed
when in fact it succeeded, but for some reason didn't set one
of the return values.

This fixes the problem by zeroing out the return value fields
of the rtas args struct before processing the rtas call.
Signed-off-by: NNathan Fontenot <nfont@austin.ibm.com>
Signed-off-by: NPaul Mackerras <paulus@samba.org>
上级 9ea7d5ad
...@@ -792,6 +792,9 @@ asmlinkage int ppc_rtas(struct rtas_args __user *uargs) ...@@ -792,6 +792,9 @@ asmlinkage int ppc_rtas(struct rtas_args __user *uargs)
if (args.token == RTAS_UNKNOWN_SERVICE) if (args.token == RTAS_UNKNOWN_SERVICE)
return -EINVAL; return -EINVAL;
args.rets = &args.args[nargs];
memset(args.rets, 0, args.nret * sizeof(rtas_arg_t));
/* Need to handle ibm,suspend_me call specially */ /* Need to handle ibm,suspend_me call specially */
if (args.token == ibm_suspend_me_token) { if (args.token == ibm_suspend_me_token) {
rc = rtas_ibm_suspend_me(&args); rc = rtas_ibm_suspend_me(&args);
...@@ -808,8 +811,6 @@ asmlinkage int ppc_rtas(struct rtas_args __user *uargs) ...@@ -808,8 +811,6 @@ asmlinkage int ppc_rtas(struct rtas_args __user *uargs)
enter_rtas(__pa(&rtas.args)); enter_rtas(__pa(&rtas.args));
args = rtas.args; args = rtas.args;
args.rets = &args.args[nargs];
/* A -1 return code indicates that the last command couldn't /* A -1 return code indicates that the last command couldn't
be completed due to a hardware error. */ be completed due to a hardware error. */
if (args.rets[0] == -1) if (args.rets[0] == -1)
......
Markdown is supported
0% .
You are about to add 0 people to the discussion. Proceed with caution.
先完成此消息的编辑!
想要评论请 注册