Re: [PATCH] tools: fwumdata: fix redundant metadata buffer overlap

Kory Maincent <[email protected]>
Newsgroups org.u-boot-project.lists.u-boot
Message-ID <[email protected]>

On 8/18/26 15:07, Patrice Chotard wrote:
> read_metadata() allocates a single buffer holding both metadata copies
> (calloc(2, mdata_size)) but accesses each copy through &mdata[id], where
> mdata is a "struct fwu_mdata *". That stride is sizeof(struct fwu_mdata),
> i.e. the 16-byte common header only, not mdata_size, so reading the
> second copy overwrites the body of the first and the two copies overlap.
> 
> When both copies are identical the overlap is harmless, but as soon as
> they differ (e.g. after an interrupted update, the exact case the tool is
> meant to recover) the primary is corrupted: for V2 the metadata_size
> check then reads garbage and the tool aborts with a bogus size mismatch,
> for V1 it silently operates on a mixed view and can write it back to both
> copies.
> 
> Index the copies by byte offset (mdata_size) through a small mdata_copy()
> helper instead of struct-typed pointer arithmetic. Both copies are
> guaranteed to share the same size (checked in parse_config()).

Reviewed-by: Kory Maincent <[email protected]>

Thank you!
-- 
Köry Maincent, Bootlin
Embedded Linux and kernel engineering
https://bootlin.com
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.