From nobody Sat Jul 25 02:11:43 2026 Received: from mail-pj1-f43.google.com (mail-pj1-f43.google.com [209.85.216.43]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 3F2FC43149C for ; Mon, 20 Jul 2026 14:50:10 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.216.43 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784559011; cv=none; b=pKING8Th344pwBNtauXEvd0UKW7HKTOwDagsQUT9qEn7T900YKjEefe0NvlJN6VD/YeyLegyDgfdSdPPLTd3GjlClkI8XUSkc4XzdomzZ3apdYHTreVi7ZHdWOgj0Ux9WrwkCfe98unSUTvC81seGo+RNADrchRRQhJrNRfn6II= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784559011; c=relaxed/simple; bh=05tdu8xXfXHy4jhsPmioMJmvslBVcSi1ayINl+djQcU=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=VlYPnZXj/OdM0HI968zOzodEStAWCNlyMIqI78d0dilyeDxFBRr2HAmWP6ZmLH91K9B/wE68NFBJdDqc/kuJVdTCsRl97wgNBqZ+c2QSCI0gPSEnKZi7LLBTf4a/kWxEYbqQrbrg03guk7M5Xu7yHS3jJmdbKGxlMD/XjZVk8ME= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=j45J6SkY; arc=none smtp.client-ip=209.85.216.43 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="j45J6SkY" Received: by mail-pj1-f43.google.com with SMTP id 98e67ed59e1d1-38dc4553f62so8556187a91.0 for ; Mon, 20 Jul 2026 07:50:10 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1784559010; x=1785163810; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=uXW5afWHCUsYPYjxZDTmpdu24u7Cm8paEwvLmru+ceE=; b=j45J6SkYFvq4tXqHrt5+7l3kfm9EKJg/o+rHAaFmGoKkJOSYvsz+cSN44oNnr4f957 9/yPjx2ZCiJ46e3KUVMk8yKoPMbfcY/osZApJRhyZDgW2yR8QNV/NVzUkj9AiPFAVwEY FLFvUfOvSjTlDFcTaYTjuCTEfCH5hAgPIdnK4NiW6sthda8NeFhjdNWF4tdG7t8BYEBR 7zeAD0+BE3pKsloDgbPmFLkRs781h+9ZNun4iERoqRNA1RJUTJlmaWE/9K4cOa4CZ1xA IythwqepZ8NkEh+U6hVMhmURbFxoLKRqWA7TksF1l9D2aC90ZSMcVFb1+BwfJDbu530E 4LHA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784559010; x=1785163810; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=uXW5afWHCUsYPYjxZDTmpdu24u7Cm8paEwvLmru+ceE=; b=eItSdmF0pLACNP6sCMdSRuvEHYElzhk3JSl8D/9qq8EK7PoIqWCiy2GWugk7+Yd+iw 4TGGig6e5YGTUc8aTMjaM1AC3mHSJhOM3mqHascwl/z9y93uaaGsy2p+qre/lD4Z+QmM Z/2b31aO6DZk1wWOXcswdEs+nUke3NtEkWY1YRYvV/alC3J/UFoNoSB5MBRSTkklVb2z fSSVXxqZD5LHPiQ7otBEec8LvambQbRJ21DwaIQh5TwEwjLjINqrrgRISux6Q+BcZiln MgF9CB2zktuBg1x1+cmpMTV0fOgXMehMi/FepNq6wx0XXNPJGMB40IYHInC/G9c4ma0G TWEw== X-Forwarded-Encrypted: i=1; AHgh+RpamU7Ju1OUjo/HB/inFhrsx6LN1+bt5wt+fjj/IMMtqlr+9tuxA2QLIPhrIDG3rnmojYUd8xwBORPXum4=@vger.kernel.org X-Gm-Message-State: AOJu0Yyv5Va/dGMQ6DxqhrXBR2vrtBGaiaUhozSaVaEbgvGAf3NULEuW yX03APSjt4yvSEVEoOtV1hgiRgmgqFrxFQFRIyG4l/zjxzJml8Qu0Z5u X-Gm-Gg: AR+sD11EDL1lXytYoYrk8mDnaOIOQ/UL2/aUOOm0Egm/z7He6GXgRJZHafwCVuoqXIi 75nuPRXheM2SU25HF5amXnK41d4ZZCku4u01vW1I6cqiYNGs0b4rS0S+vE+AQDbn/wSocNgCqWp O8q1yS4dX/DL4CPyyimfeUwfkVb46CSqzit7o5X0m+dKoZuAAd1TeCKDQROY7h3A/w4RjAD11t/ 89J6phuuf5aWMBkKFbJPdrR1Tg4vtsBDNyM/qafZ2VNu41TKijg7ZCq4EBo1rgYTKPSnzBv965I aXxOuDL+estdgk/sQLsk7XvGk+x5Wy/1VLt85U3MN5spQ4nYUvCE1BGiXXrMNJkU4ObzR0LKO/k L6rjVaO2mJ7D+lYLJEeJCZ0lyYmRavnCuVud7R57zOsBebG6dp2q23ZKqcw/D2mwEsSyEfJdbXo QLyXt6LZZrjlHg/Hf0zxoinz4f X-Received: by 2002:a17:90b:4f89:b0:381:152b:d596 with SMTP id 98e67ed59e1d1-38e4b40f926mr15296307a91.11.1784559009605; Mon, 20 Jul 2026 07:50:09 -0700 (PDT) Received: from localhost.localdomain ([103.178.204.93]) by smtp.gmail.com with ESMTPSA id a92af1059eb24-13ce29ffb13sm32206919c88.6.2026.07.20.07.50.07 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 20 Jul 2026 07:50:09 -0700 (PDT) From: Sreeraj S Kurup To: o-takashi@sakamocchi.jp Cc: linux1394-devel@lists.sourceforge.net, linux-kernel@vger.kernel.org, Sreeraj S Kurup Subject: [PATCH] firewire: core-card: fix ROM length mismatch and strengthen descriptor validation Date: Mon, 20 Jul 2026 14:49:13 +0000 Message-ID: <20260720144913.5840-1-sreekuttan2156239@gmail.com> X-Mailer: git-send-email 2.54.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" The FireWire core had two issues: 1. ROM length mismatch handling: Previously, generate_config_rom() only WARNed when the computed length differed from config_rom_length. This left the driver in an inconsistent state. Now we log a warning and resynchronize config_rom_length to the actual value. 2. Descriptor validation: fw_core_add_descriptor() only checked internal block consistency. We now reject empty descriptors and those exceeding 256 quadlets before parsing, preventing malformed input from corrupting the config ROM. These changes improve robustness of the FireWire core against invalid descriptors and ensure config ROM stays consistent. Signed-off-by: Sreeraj S Kurup --- drivers/firewire/core-card.c | 51 ++++++++++++++++++++---------------- 1 file changed, 29 insertions(+), 22 deletions(-) diff --git a/drivers/firewire/core-card.c b/drivers/firewire/core-card.c index a754c6366b97..97439da6f480 100644 --- a/drivers/firewire/core-card.c +++ b/drivers/firewire/core-card.c @@ -143,7 +143,11 @@ static void generate_config_rom(struct fw_card *card, = __be32 *config_rom) for (i =3D 0; i < j; i +=3D length + 1) length =3D fw_compute_block_crc(config_rom + i); =20 - WARN_ON(j !=3D config_rom_length); + if (j !=3D config_rom_length) { + pr_warn("FireWire ROM length mismatch: expected %zu, got %d\n", + config_rom_length, j); + config_rom_length =3D j; + } } =20 static void update_config_roms(void) @@ -165,33 +169,36 @@ static size_t required_space(struct fw_descriptor *de= sc) =20 int fw_core_add_descriptor(struct fw_descriptor *desc) { - size_t i; + size_t i; =20 - /* - * Check descriptor is valid; the length of all blocks in the - * descriptor has to add up to exactly the length of the - * block. - */ - i =3D 0; - while (i < desc->length) - i +=3D (desc->data[i] >> 16) + 1; + /* Extra validation: reject empty or oversized descriptors */ + if (desc->length =3D=3D 0 || desc->length > 256) + return -EINVAL; =20 - if (i !=3D desc->length) - return -EINVAL; + /* + * Check descriptor is valid, the length of all blocks in the + * descriptor has to add up to exactly the length of the block. + */ + i =3D 0; + while (i < desc->length) + i +=3D (desc->data[i] >> 16) + 1; =20 - guard(mutex)(&card_mutex); + if (i !=3D desc->length) + return -EINVAL; =20 - if (config_rom_length + required_space(desc) > 256) - return -EBUSY; + guard(mutex)(&card_mutex); =20 - list_add_tail(&desc->link, &descriptor_list); - config_rom_length +=3D required_space(desc); - descriptor_count++; - if (desc->immediate > 0) - descriptor_count++; - update_config_roms(); + if (config_rom_length + required_space(desc) > 256) + return -EBUSY; =20 - return 0; + list_add_tail(&desc->link, &descriptor_list); + config_rom_length +=3D required_space(desc); + descriptor_count++; + if (desc->immediate > 0) + descriptor_count++; + update_config_roms(); + + return 0; } EXPORT_SYMBOL(fw_core_add_descriptor); =20 --=20 2.54.0