From nobody Mon Sep 28 20:13:33 2026 Received: from mail-pj1-f71.google.com (mail-pj1-f71.google.com [209.85.216.71]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id DBBF826A08A for ; Tue, 18 Aug 2026 04:54:19 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.216.71 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787028861; cv=none; b=VZBigzcvrvD1rRWrSNZduWNbzAr/yumLoSxXqqLKntnR/xAnRLWPqXdsxDRyv7eclCzDv/4ndzbpbj/CJYRQEVKhsFZGp6dpr4xcRRcr3kChYGJaCEXlkQ4+AseXRHiTashCsC12zS9JhfW4lKx53kdHxFaYnZF3qF+oWfY/+H8= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787028861; c=relaxed/simple; bh=yJR+yoKG9pXKKyVRHjxz11VaSp5gR2lal3l0KA8rBk0=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=E3F+ly12IgoQtFmrmYH2FAcN/OQ6D8yTuRuTIg7EDMGth6r4Suyl/gxC8ySDREWdU+FeG7F8xsvuxNAf1qSjlH+9xz4vRQabp2f83v6ZhG30mtwX90CJQbK/oq/gUuz93RQoZ+EsShblF8jobpisvzWcfM+h4RaW+vqEdhm05Fs= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--wfelipe.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=shLRpubP; arc=none smtp.client-ip=209.85.216.71 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--wfelipe.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="shLRpubP" Received: by mail-pj1-f71.google.com with SMTP id 98e67ed59e1d1-38dbf293831so10627526a91.3 for ; Mon, 17 Aug 2026 21:54:19 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1787028859; x=1787633659; darn=vger.kernel.org; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:from:to:cc:subject:date:message-id:reply-to :content-type; bh=Txn7B8ugYadhPtvOokzEYTJGdZuCyvbbsYD589++790=; b=shLRpubPOU2AKg9KqmHjIpU6knGUIPECGOE14hqrAZaieapRXTC9BBj3nEW7e6eAPR Hb7Rvb9s5JEkFFCW0h00/GugZs0QmZbgix35Ur2G7PEXPjh07tmPiKWwCPKYiOiviHM9 l4yUD0KSqJwp4MNaITtaphmIACYGqq5EomKOB70JU4AHp/srHUJFPOk3Vs3nXE8u/B92 fq/K1OICWWRBjGmp/6s47nmae4u0lfC30WVRVRoquppfP1EQQLepzrxBEhTYZ1GTG5vq imG8EtSayVFrod6n2KSeBI0etOz6RA98qx7w8gzNxJzyPpujNQTXUrngOq3lCLF9mS6k Rx9w== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787028859; x=1787633659; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=Txn7B8ugYadhPtvOokzEYTJGdZuCyvbbsYD589++790=; b=fSSRgtKRZ/HkDSq2vLyOjhMpapHmbqyv2wBdy83pE8KH4h8EdlQp3FJZv10Sj2FAqU 3Aw/EOB07V7VOcybquEijEZasGGrQdDasZsG4gh0MEIOe0uDyTnSBgPiqPi8xeYQ70GV nOh9dh/J4J9K13yrdSXG3WpVadiGkaOHzCdkwPf7FafLCWGLRZb2FuArPi+7riSw5O5/ zE6YnQp0HWEhArbs6lSbuNdfihfYtSB8B0fjVN8fBWK/R6rggT5p8/gIrj7CTcuZ4qXm RFj3i7QiM0gxUKc8PDHif5NUA3TwHyvNOzzSVDTcw6nMm+lgrX7ML+xKaYqHZBjMcfKc zOGg== X-Gm-Message-State: AOJu0YxChuk0cWqvpMAmSJ9gEsYkDzbEPDhxccc/xs0a2iTHehRp+C1x al+wjvoC7If6jI182ZTLOzUdMFVODrnHKoA6XR3k6PHkJpIwB8Yh5wC7Fr7YwmhzVYkbDQMrC8X 8cB3FJGkTJw== X-Received: from pjzm24.prod.google.com ([2002:a17:90b:698:b0:38e:bc12:2b3d]) (user=wfelipe job=prod-delivery.src-stubby-dispatcher) by 2002:a17:90b:134c:b0:38d:ef48:b04 with SMTP id 98e67ed59e1d1-3933b8721a1mr32362654a91.10.1787028859066; Mon, 17 Aug 2026 21:54:19 -0700 (PDT) Date: Tue, 18 Aug 2026 04:53:46 +0000 In-Reply-To: <20260818045357.4123784-1-wfelipe@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260818045357.4123784-1-wfelipe@google.com> X-Mailer: git-send-email 2.55.0.699.gb54405d56f-goog Message-ID: <20260818045357.4123784-2-wfelipe@google.com> Subject: [PATCH 1/2] init/main: fix off-by-one in argv_init cleanup From: Wilson Felipe Pereira To: Andrew Morton Cc: linux-kernel@vger.kernel.org, Wilson Felipe Pereira Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" When cleaning up argv_init in init_setup() and rdinit_setup(), the loop terminates one element early due to using '<' instead of '<=3D'. Since argv_init is sized MAX_INIT_ARGS+2, index MAX_INIT_ARGS is a valid element that should be cleared to NULL. If exactly MAX_INIT_ARGS unknown arguments are passed before 'init=3D', the uncleared argv_init[MAX_INIT_ARGS] can act as a ghost argument to /sbin/init or cause a spurious kernel panic when later appended to. To verify the argument leak, boot a VM into a shell with 32 unknown kernel arguments, the init parameter, and 31 user arguments: STALE_ARGS=3D$(for i in {1..32}; do echo -n "stale$i "; done) USER_ARGS=3D$(for i in {1..31}; do echo -n "user$i "; done) qemu-system-x86_64 -kernel bzImage \ -append "$STALE_ARGS init=3D/bin/sh $USER_ARGS" Running `cat /proc/1/cmdline` inside the shell reveals that the 32nd kernel argument ('stale32') incorrectly leaked into the init process's command line. This patch zeroes the final slot, cleanly terminating the array. Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2") Fixes: ffdfc40976dd ("[PATCH] Add rdinit parameter to pick early userspace = init") Signed-off-by: Wilson Felipe Pereira --- init/main.c | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/init/main.c b/init/main.c index 92d34e496a33..f02041a42111 100644 --- a/init/main.c +++ b/init/main.c @@ -572,7 +572,7 @@ static int __init init_setup(char *str) * the shell think it should execute a script with such name. * So we ignore all arguments entered _before_ init=3D... [MJ] */ - for (i =3D 1; i < MAX_INIT_ARGS; i++) + for (i =3D 1; i <=3D MAX_INIT_ARGS; i++) argv_init[i] =3D NULL; return 1; } @@ -585,7 +585,7 @@ static int __init rdinit_setup(char *str) ramdisk_execute_command =3D str; ramdisk_execute_command_set =3D true; /* See "auto" comment in init_setup */ - for (i =3D 1; i < MAX_INIT_ARGS; i++) + for (i =3D 1; i <=3D MAX_INIT_ARGS; i++) argv_init[i] =3D NULL; return 1; } --=20 2.55.0.699.gb54405d56f-goog From nobody Mon Sep 28 20:13:33 2026 Received: from mail-pg1-f199.google.com (mail-pg1-f199.google.com [209.85.215.199]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 8ACC43D0905 for ; Tue, 18 Aug 2026 04:54:22 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.215.199 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787028863; cv=none; b=iz2UCRnkyIAvr+z+/GGqHSQQPMA3UOy6Aylq6Q870hVmzA7eXGGe6Ah/9tG4SnuF0Q/7PQN8X9zCpSuJfCKSmgUzbwdfkU1QI9YX54borsLWRdapdJ5ddqPSphpegpOeWczBqDHYS3xbSwxjrXqIQCqvEp1aiDvHsiG6ylKV0PI= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787028863; c=relaxed/simple; bh=oFDYDfLZz8roDQmR2mxVHM38tGy3cPZJeaV6TLWxiBU=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=Q4n6ozJZWVPDyDCW8vOqZdtdW5vxVo8kzWDVVROiMICreAbF7tyvG0zbfME4SZeMqBUXQh7Ye6jTiOHlWnSR/2yP7ewa3vvCzS1XzVFBZOTw6IvaLw3Rjox8/UpqjPp20u5m70VtIfRcSJM63WHij4i6c4iHlndefc2dldQksHY= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--wfelipe.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=pG3j2xs9; arc=none smtp.client-ip=209.85.215.199 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--wfelipe.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="pG3j2xs9" Received: by mail-pg1-f199.google.com with SMTP id 41be03b00d2f7-c85798977dcso6303101a12.0 for ; Mon, 17 Aug 2026 21:54:22 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1787028862; x=1787633662; darn=vger.kernel.org; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:from:to:cc:subject:date:message-id:reply-to :content-type; bh=Pn8stLbBVVBRD5K14nzDtlbeoqvHqUNDP/KvrF+10no=; b=pG3j2xs9cwjvyLmX8AvPX9zDll7cWT8iyMrMMxLCNjYKsZOus8RnQ0yi4hdo+xt126 MbmAvTKke9sf5YDCPYkG/MgD49zblUBhPFERUQaRv261Z9pHkDhvym9wNcrmP27amJF0 qgR+mFepdoluFrHa3QhudOzWnperX+8g+0q/B8KyiBw7KBMovK0+rg3ref8ZpUNy1yxX EYS8hV4APJqJKLwDAJ9dZaQ1s7PQ5dmXjoV+6wOWMEKQ0hwhNXh9Ethl1u8JEwPohX2b /Aw9lJBd3mrq5fDobO40+HBD4st/O9zIn0hw0go43gsA/Z2AlD38gD+ZW6IFAwFN33CF jZRQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787028862; x=1787633662; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=Pn8stLbBVVBRD5K14nzDtlbeoqvHqUNDP/KvrF+10no=; b=gQ7mE1BrUDLdzjhKLhiClgQEiMCqIUABoJu9jUBgNAbwvvPA/nEMJf5ocKnzbEVK5E VFACID4xXBfIwWlosiCAcn3I+A+AuO78rUl6SkUDaGgrLxY6tr+s0chndNlg66bJPqrO lc2SY/scHXkj6joPL7dJ3foR/BZcLVKagjcmr6z0Gjtbb4ZeM9dv+Zzm/WgCe57zYCMx 9aYX4EH0AgLhQBijXcvBJLLY+f4Vng4rAXksfziV40FaJJV9gljAMIp2R6xNzZLfvOVD aN2gN1zPQ+yYH/tUiuKddzK3hU4uTY6m0+au34zFdztZKNhmMv9Y5z2SMb6Sa8n8Xyxz BG8w== X-Gm-Message-State: AOJu0YxtIRWlvFdmalDSd9uchGtLdxX1mIi0hkc/0TGcbK9H/YlmqYKW 5AwABghAdu2RhUqGaCjXePQy+PRctUEj6pwQP4npPJpbjXZvX4knC3+oBIZ6xFjBor1Ks66btFR HX1nfsb1qoA== X-Received: from pfux38.prod.google.com ([2002:a05:6a00:be6:b0:848:416d:e7f3]) (user=wfelipe job=prod-delivery.src-stubby-dispatcher) by 2002:a05:6a00:4f91:b0:84f:37c1:f887 with SMTP id d2e1a72fcca58-84fddfdf5b0mr29107211b3a.12.1787028861604; Mon, 17 Aug 2026 21:54:21 -0700 (PDT) Date: Tue, 18 Aug 2026 04:53:47 +0000 In-Reply-To: <20260818045357.4123784-1-wfelipe@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260818045357.4123784-1-wfelipe@google.com> X-Mailer: git-send-email 2.55.0.699.gb54405d56f-goog Message-ID: <20260818045357.4123784-3-wfelipe@google.com> Subject: [PATCH 2/2] init/main: fix false-positive kernel panic on environment variable overwrite From: Wilson Felipe Pereira To: Andrew Morton Cc: linux-kernel@vger.kernel.org, Wilson Felipe Pereira Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" In unknown_bootoption(), the limit checking for environment variables sets panic_later *before* checking if the variable already exists in envp_init. If a user passes exactly MAX_INIT_ENVS custom variables and then overwrites the final variable by matching its key, it causes a false-positive hard panic on boot despite not actually exceeding the array bounds or increasing the total variable count. Swapping the order of these checks allows the duplicate check to break out of the loop before the panic flag is erroneously latched. To verify, boot a VM with 31 custom variables (filling the array up to its limit of 32) and then overwrite the very last variable: ENV_VARS=3D$(for i in {1..31}; do echo -n "var$i=3D$i "; done) qemu-system-x86_64 -kernel bzImage -append "$ENV_VARS var31=3Doverwrite" Without this patch, the kernel crashes instantly with: Kernel panic - not syncing: Too many boot env vars at 'var31=3Doverwrite' With this patch, the kernel safely overwrites the variable and boots. Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2") Signed-off-by: Wilson Felipe Pereira --- init/main.c | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/init/main.c b/init/main.c index f02041a42111..577ae30570e0 100644 --- a/init/main.c +++ b/init/main.c @@ -539,12 +539,12 @@ static int __init unknown_bootoption(char *param, cha= r *val, /* Environment option */ unsigned int i; for (i =3D 0; envp_init[i]; i++) { + if (!strncmp(param, envp_init[i], len+1)) + break; if (i =3D=3D MAX_INIT_ENVS) { panic_later =3D "env"; panic_param =3D param; } - if (!strncmp(param, envp_init[i], len+1)) - break; } envp_init[i] =3D param; } else { --=20 2.55.0.699.gb54405d56f-goog