[PATCH v2 0/4] soc: apple: rtkit: harden syslog shared-buffer handling

Laxman Acharya Padhya <[email protected]>
Newsgroups dev.linux.lists.asahi,org.infradead.lists.linux-arm-kernel,org.kernel.vger.linux-kernel,org.kernel.vger.stable
Message-ID <[email protected]>
Split the syslog hardening into focused changes as requested. The first
patch fixes the SYSLOG_INIT reinitialization leak. The second prevents
zero-sized messages and out-of-bounds shared-memory copies. The third
corrects the entry-count boundary, and the fourth rate limits validation
warnings controlled by the coprocessor.

The index-boundary change has not been tested on Apple hardware running
Linux. Asahi m1n1 describes the initialization field as COUNT, consistent
with the kernel's syslog_n_entries name, but patch 3 is kept independent so
it can be reverted without removing the shared-memory bounds protection.

Testing:
  - arm64 GCC build of drivers/soc/apple/rtkit.o with W=1 in Docker
  - scripts/checkpatch.pl --strict on each patch

Changes since v1:
  - inline the one-use shared-memory bounds check
  - use == 0 for the crashlog copy and < 0 for syslog copies
  - split the SYSLOG_INIT leak fix into patch 1
  - split the idx == n_entries change into patch 3
  - make the zero-size guard independent of the leak fix
  - rate limit existing malformed-syslog warnings in patch 4
  - rebase onto upstream commit 0a0d1d55dad5

Laxman Acharya Padhya (4):
  soc: apple: rtkit: free syslog buffer before reinitializing
  soc: apple: rtkit: bound syslog copies to the shared buffer
  soc: apple: rtkit: reject syslog indices outside the entry count
  soc: apple: rtkit: rate limit malformed syslog warnings

 drivers/soc/apple/rtkit.c | 75 +++++++++++++++++++++++++--------------
 1 file changed, 49 insertions(+), 26 deletions(-)


base-commit: 0a0d1d55dad570724bf8c7ea83409639cfb4be9b
-- 
2.51.2
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.