summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorToomas Soome <tsoome@me.com>2019-08-20 16:33:39 +0300
committerToomas Soome <tsoome@me.com>2019-09-17 23:14:03 +0300
commitcf691b2b138fb3e0396a16406094b82ec555610e (patch)
tree7cc86bc5a843e5a48ab6c1c0d3a642a6cd88c58f
parente141bae1eadd4373d692c722ab88dff7d998a3b8 (diff)
downloadillumos-joyent-cf691b2b138fb3e0396a16406094b82ec555610e.tar.gz
11587 loader.efi: comparison is always true due to limited range of data type
Reviewed by: Andrew Stormont <andyjstormont@gmail.com> Reviewed by: Robert Mustacchi <rm@fingolfin.org> Approved by: Dan McDonald <danmcd@joyent.com>
-rw-r--r--usr/src/boot/Makefile.version2
-rw-r--r--usr/src/boot/sys/boot/efi/loader/copy.c34
2 files changed, 24 insertions, 12 deletions
diff --git a/usr/src/boot/Makefile.version b/usr/src/boot/Makefile.version
index bb38843679..bda3f08ec7 100644
--- a/usr/src/boot/Makefile.version
+++ b/usr/src/boot/Makefile.version
@@ -33,4 +33,4 @@ LOADER_VERSION = 1.1
# Use date like formatting here, YYYY.MM.DD.XX, without leading zeroes.
# The version is processed from left to right, the version number can only
# be increased.
-BOOT_VERSION = $(LOADER_VERSION)-2019.09.09.1
+BOOT_VERSION = $(LOADER_VERSION)-2019.09.10.1
diff --git a/usr/src/boot/sys/boot/efi/loader/copy.c b/usr/src/boot/sys/boot/efi/loader/copy.c
index 93923500b2..0dd8e8a5cc 100644
--- a/usr/src/boot/sys/boot/efi/loader/copy.c
+++ b/usr/src/boot/sys/boot/efi/loader/copy.c
@@ -36,7 +36,6 @@
#include <efi.h>
#include <efilib.h>
-#include <assert.h>
#include "loader_efi.h"
@@ -48,7 +47,7 @@ addr_verify(multiboot_tag_module_t *module, vm_offset_t addr, size_t size)
{
vm_offset_t start, end;
- for (;module->mb_type == MULTIBOOT_TAG_TYPE_MODULE;
+ for (; module->mb_type == MULTIBOOT_TAG_TYPE_MODULE;
module = (multiboot_tag_module_t *)
roundup((uintptr_t)module + module->mb_size, MULTIBOOT_TAG_ALIGN)) {
@@ -154,7 +153,7 @@ efi_physaddr(multiboot_tag_module_t *module, vm_offset_t addr,
* about the order of the allocated blocks.
*/
vm_offset_t
-efi_loadaddr(u_int type, void *data, vm_offset_t addr)
+efi_loadaddr(uint_t type, void *data, vm_offset_t addr)
{
EFI_PHYSICAL_ADDRESS paddr;
struct stat st;
@@ -177,7 +176,7 @@ efi_loadaddr(u_int type, void *data, vm_offset_t addr)
pages = EFI_SIZE_TO_PAGES(size);
/* 4GB upper limit */
- paddr = 0x0000000100000000;
+ paddr = UINT32_MAX;
status = BS->AllocatePages(AllocateMaxAddress, EfiLoaderData,
pages, &paddr);
@@ -206,24 +205,37 @@ efi_translate(vm_offset_t ptr)
ssize_t
efi_copyin(const void *src, vm_offset_t dest, const size_t len)
{
- assert(dest < 0x100000000);
- bcopy(src, (void *)(uintptr_t)dest, len);
- return (len);
+ if (dest + len >= dest && (uint64_t)dest + len <= UINT32_MAX) {
+ bcopy(src, (void *)(uintptr_t)dest, len);
+ return (len);
+ } else {
+ errno = EFBIG;
+ return (-1);
+ }
}
ssize_t
efi_copyout(const vm_offset_t src, void *dest, const size_t len)
{
- assert(src < 0x100000000);
- bcopy((void *)(uintptr_t)src, dest, len);
- return (len);
+ if (src + len >= src && (uint64_t)src + len <= UINT32_MAX) {
+ bcopy((void *)(uintptr_t)src, dest, len);
+ return (len);
+ } else {
+ errno = EFBIG;
+ return (-1);
+ }
}
ssize_t
efi_readin(const int fd, vm_offset_t dest, const size_t len)
{
- return (read(fd, (void *)dest, len));
+ if (dest + len >= dest && (uint64_t)dest + len <= UINT32_MAX) {
+ return (read(fd, (void *)dest, len));
+ } else {
+ errno = EFBIG;
+ return (-1);
+ }
}
/*