[PATCH 0/4] RAS/amd/fmpm: Fix OOB, uninitialized data, and error-handling bugs

"Rui Qi" <[email protected]>
Newsgroups org.kernel.vger.linux-edac,org.kernel.vger.linux-kernel
Message-ID <[email protected]>
Hi Yazen, Borislav, Tony,

This series fixes several bugs in the AMD FRU Memory Poison Manager
driver.

Patch 1 fixes an out-of-bounds read in the for_each_fru macro caused by
the comma operator evaluating the array access before the bounds check.
This is technically undefined behavior and would be flagged by UBSan.

Patch 2 fixes an uninitialized stack bitmap in save_new_records() that
could cause the rollback path to clear ERST records that were not created
in the current initialization pass.

Patch 3 makes the max_nr_entries module parameter read-only (0444),
preventing runtime writes that could exceed the allocated flexible array
size.

Patch 4 fixes a spurious BUG when erst_get_record_id_begin() fails,
because the error path unconditionally calls erst_get_record_id_end()
which triggers BUG_ON.

All four bugs have been present since the original introduction of the
AMD FMPM driver.

Rui Qi (4):
  RAS/amd/fmpm: Fix out-of-bounds read in for_each_fru macro
  RAS/amd/fmpm: Clear new records bitmap before rollback
  RAS/amd/fmpm: Make max_nr_entries read-only
  RAS/amd/fmpm: Fix spurious BUG when ERST record enumeration fails

 drivers/ras/amd/fmpm.c | 9 ++++++---
 1 file changed, 6 insertions(+), 3 deletions(-)

--
2.20.1
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.