mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [2.6.2-rc2, rivafb]: GeForce4 440 Go 64M overflows fb_fix_screeninfo.id
@ 2004-01-29 17:25 Guido Guenther
  2004-01-29 19:29 ` Petr Vandrovec
  0 siblings, 1 reply; 4+ messages in thread
From: Guido Guenther @ 2004-01-29 17:25 UTC (permalink / raw)
  To: James Simmons; +Cc: linux-kernel

[-- Attachment #1: Type: text/plain, Size: 642 bytes --]

Hi,
fb_fix_screeninfo has space for 15 characters but riva/fbdev.c tries to
copy more into it in case of the above card (and therefore corrupts
memory). The result looks like:
rivafb: PCI nVidia NV20 framebuffer ver 0.9.5b (nVidiaGeForce4-4\224, 32MB @ 0x94000000)
                                                               ^^^^^
Possible fix attached. This also overwrites the initial "nVidia" in
rivafb_fix.id making the output the same as in 2.4 (and using strlcpy
makes sure we don't overflow again). With this patch:

rivafb: PCI nVidia NV20 framebuffer ver 0.9.5b (GeForce4-440-GO-M64, 32MB @ 0x94000000)

Can this go in?
 -- Guido

[-- Attachment #2: rivafb-fix-ident.diff --]
[-- Type: text/plain, Size: 915 bytes --]

--- ../benh-rsync-2.6-clean/include/linux/fb.h	2003-12-24 11:31:18.000000000 +0100
+++ include/linux/fb.h	2004-01-28 20:35:24.000000000 +0100
@@ -114,7 +114,7 @@
 
 
 struct fb_fix_screeninfo {
-	char id[16];			/* identification string eg "TT Builtin" */
+	char id[32];			/* identification string eg "TT Builtin" */
 	unsigned long smem_start;	/* Start of frame buffer mem */
 					/* (physical address) */
 	__u32 smem_len;			/* Length of frame buffer mem */
--- ../benh-rsync-2.6-clean/drivers/video/riva/fbdev.c	2003-12-24 08:30:11.000000000 +0100
+++ drivers/video/riva/fbdev.c	2004-01-28 21:04:29.000000000 +0100
@@ -1867,7 +1867,7 @@
 		goto err_out_kfree1;
 	memset(info->pixmap.addr, 0, 64 * 1024);
 
-	strcat(rivafb_fix.id, rci->name);
+	strlcpy(rivafb_fix.id, rci->name, sizeof(rivafb_fix.id));
 	default_par->riva.Architecture = rci->arch_rev;
 
 	default_par->Chipset = (pd->vendor << 16) | pd->device;

^ permalink raw reply	[flat|nested] 4+ messages in thread

* Re: [2.6.2-rc2, rivafb]: GeForce4 440 Go 64M overflows fb_fix_screeninfo.id
  2004-01-29 17:25 [2.6.2-rc2, rivafb]: GeForce4 440 Go 64M overflows fb_fix_screeninfo.id Guido Guenther
@ 2004-01-29 19:29 ` Petr Vandrovec
  2004-01-29 19:33   ` James Simmons
  0 siblings, 1 reply; 4+ messages in thread
From: Petr Vandrovec @ 2004-01-29 19:29 UTC (permalink / raw)
  To: Guido Guenther; +Cc: James Simmons, linux-kernel

On Thu, Jan 29, 2004 at 06:25:11PM +0100, Guido Guenther wrote:
> Hi,
> fb_fix_screeninfo has space for 15 characters but riva/fbdev.c tries to
> copy more into it in case of the above card (and therefore corrupts
> memory). The result looks like:
> rivafb: PCI nVidia NV20 framebuffer ver 0.9.5b (nVidiaGeForce4-4\224, 32MB @ 0x94000000)
>                                                                ^^^^^
> Possible fix attached. This also overwrites the initial "nVidia" in
> rivafb_fix.id making the output the same as in 2.4 (and using strlcpy
> makes sure we don't overflow again). With this patch:
> 
> rivafb: PCI nVidia NV20 framebuffer ver 0.9.5b (GeForce4-440-GO-M64, 32MB @ 0x94000000)
> 
> Can this go in?

No way. Second part (riva/fbdev.c) is OK, but first part is wrong. fb_fix_screeninfo
is part of ABI, and as such cannot be changed. No fb application is going to work
on your system - try 'fbset -i' (unless you rebuilt fbset binary after doing this change).

You'll have to live with 'GeForce4-440-GO' name.
							Petr Vandrovec

>  -- Guido

> --- ../benh-rsync-2.6-clean/include/linux/fb.h	2003-12-24 11:31:18.000000000 +0100
> +++ include/linux/fb.h	2004-01-28 20:35:24.000000000 +0100
> @@ -114,7 +114,7 @@
>  
>  
>  struct fb_fix_screeninfo {
> -	char id[16];			/* identification string eg "TT Builtin" */
> +	char id[32];			/* identification string eg "TT Builtin" */
>  	unsigned long smem_start;	/* Start of frame buffer mem */
>  					/* (physical address) */
>  	__u32 smem_len;			/* Length of frame buffer mem */
> --- ../benh-rsync-2.6-clean/drivers/video/riva/fbdev.c	2003-12-24 08:30:11.000000000 +0100
> +++ drivers/video/riva/fbdev.c	2004-01-28 21:04:29.000000000 +0100
> @@ -1867,7 +1867,7 @@
>  		goto err_out_kfree1;
>  	memset(info->pixmap.addr, 0, 64 * 1024);
>  
> -	strcat(rivafb_fix.id, rci->name);
> +	strlcpy(rivafb_fix.id, rci->name, sizeof(rivafb_fix.id));
>  	default_par->riva.Architecture = rci->arch_rev;
>  
>  	default_par->Chipset = (pd->vendor << 16) | pd->device;


^ permalink raw reply	[flat|nested] 4+ messages in thread

* Re: [2.6.2-rc2, rivafb]: GeForce4 440 Go 64M overflows fb_fix_screeninfo.id
  2004-01-29 19:29 ` Petr Vandrovec
@ 2004-01-29 19:33   ` James Simmons
  2004-01-29 19:36     ` Guido Guenther
  0 siblings, 1 reply; 4+ messages in thread
From: James Simmons @ 2004-01-29 19:33 UTC (permalink / raw)
  To: Petr Vandrovec; +Cc: Guido Guenther, linux-kernel


> No way. Second part (riva/fbdev.c) is OK, but first part is wrong. fb_fix_screeninfo
> is part of ABI, and as such cannot be changed. No fb application is going to work
> on your system - try 'fbset -i' (unless you rebuilt fbset binary after doing this change).
> 
> You'll have to live with 'GeForce4-440-GO' name.

I applied the fbdev.c part but Petr is right. It would break userland.



^ permalink raw reply	[flat|nested] 4+ messages in thread

* Re: [2.6.2-rc2, rivafb]: GeForce4 440 Go 64M overflows fb_fix_screeninfo.id
  2004-01-29 19:33   ` James Simmons
@ 2004-01-29 19:36     ` Guido Guenther
  0 siblings, 0 replies; 4+ messages in thread
From: Guido Guenther @ 2004-01-29 19:36 UTC (permalink / raw)
  To: James Simmons; +Cc: Petr Vandrovec, linux-kernel

On Thu, Jan 29, 2004 at 07:33:07PM +0000, James Simmons wrote:
> I applied the fbdev.c part but Petr is right. It would break userland.
That's fine. Thanks,
 -- Guido

^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2004-01-29 19:38 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2004-01-29 17:25 [2.6.2-rc2, rivafb]: GeForce4 440 Go 64M overflows fb_fix_screeninfo.id Guido Guenther
2004-01-29 19:29 ` Petr Vandrovec
2004-01-29 19:33   ` James Simmons
2004-01-29 19:36     ` Guido Guenther

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®