Re: [PATCH 2/2] test: dm: nfs: add a regression test for an oversized NFS read length

Jerome Forissier <[email protected]>
Newsgroups org.u-boot-project.lists.u-boot
Message-ID <[email protected]>
Hi Shahriyar,

On 11/08/2026 20:15, Shahriyar Jalayeri wrote:
> Add a DM test that feeds nfs_pkt_recv() a crafted NFSv3 READ reply whose
> 32-bit count has the top bit set, with a read outstanding, and checks
> that nothing is stored. An out-of-range length reaches store_block() and
> drives a ~2 GB memcpy() out of the reply buffer, which CONFIG_ASAN
> reports as a stack-buffer-overflow.
> 
> Signed-off-by: Shahriyar Jalayeri <[email protected]>
> ---
>  test/dm/Makefile |  1 +
>  test/dm/nfs.c    | 55 +++++++++++++++++++++++++++++++++++++++++++++++++++++++
>  2 files changed, 56 insertions(+)
> 
> diff --git a/test/dm/Makefile b/test/dm/Makefile
> index fb3e6a7008f..cc51fd33079 100644
> --- a/test/dm/Makefile
> +++ b/test/dm/Makefile
> @@ -78,6 +78,7 @@ obj-$(CONFIG_MUX_MMIO) += mux-mmio.o
>  obj-y += fdtdec.o
>  obj-$(CONFIG_MTD_RAW_NAND) += nand.o
>  obj-$(CONFIG_IP_DEFRAG) += net_defrag.o
> +obj-$(CONFIG_CMD_NFS) += nfs.o
>  obj-$(CONFIG_UT_DM) += nop.o
>  obj-y += ofnode.o
>  obj-y += ofread.o
> diff --git a/test/dm/nfs.c b/test/dm/nfs.c
> new file mode 100644
> index 00000000000..abfa75f1941
> --- /dev/null
> +++ b/test/dm/nfs.c
> @@ -0,0 +1,55 @@
> +// SPDX-License-Identifier: GPL-2.0
> +/*
> + * Regression test for the NFS read-length check.
> + *
> + * A crafted NFSv3 READ reply whose 32-bit count has the top bit set is fed to
> + * the real nfs_pkt_recv() with a read outstanding. The signed length reaches
> + * store_block() as a ~2 GB memcpy() out of the reply buffer, flagged under
> + * AddressSanitizer; the fix rejects it and stores nothing.
> + */
> +
> +#include <net.h>
> +#include <string.h>
> +#include <test/ut.h>
> +#include <dm/test.h>
> +#include "../../net/nfs-common.h"
> +
> +static int dm_test_nfs_read_oob(struct unit_test_state *uts)
> +{
> +	int saved_state = nfs_state;
> +	unsigned long saved_id = rpc_id;
> +	int saved_offset = nfs_offset;
> +	enum nfs_version saved_version = choosen_nfs_version;
> +	u32 saved_size = net_boot_file_size;
> +	struct rpc_t reply;
> +
> +	/* Pretend a READ request is outstanding (NFSv3). */
> +	choosen_nfs_version = NFS_V3;
> +	nfs_state = STATE_READ_REQ;
> +	nfs_offset = 0;
> +	rpc_id = 0x11223344;
> +	net_boot_file_size = 0;
> +
> +	/* Accepted reply, matching xid, READ status OK, no attributes, then a
> +	 * count with the top bit set.
> +	 */
> +	memset(&reply, 0, sizeof(reply));
> +	reply.u.reply.id = htonl((u32)rpc_id);
> +	reply.u.reply.data[0] = 0;			/* nfsstat3: OK */
> +	reply.u.reply.data[1] = 0;			/* attributes_follow: no */
> +	reply.u.reply.data[2] = htonl(0x80000000);	/* count */
> +
> +	nfs_pkt_recv((uchar *)&reply.u.reply, sizeof(reply.u.reply));
> +
> +	/* Rejected: nothing stored. */
> +	ut_asserteq(0, net_boot_file_size);
> +
> +	nfs_state = saved_state;
> +	rpc_id = saved_id;
> +	nfs_offset = saved_offset;
> +	choosen_nfs_version = saved_version;
> +	net_boot_file_size = saved_size;
> +
> +	return 0;
> +}
> +DM_TEST(dm_test_nfs_read_oob, 0);
> 

With the series applied to for-main I got a CI error, see:
https://git.u-boot-project.org/u-boot/custodians/u-boot-net/-/jobs/68484

Thanks,
-- 
Jerome
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.