From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pl1-f199.google.com (mail-pl1-f199.google.com [209.85.214.199]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 8FD42368D65 for ; Tue, 18 Aug 2026 04:54:13 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.214.199 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787028854; cv=none; b=ERIknn3p5kwq9ASEjdZ0rmJzI9gfYxtZqvqIjLN9ZwpW3PWtQKRKrKgBvxlBuMW2LdzZX4sYqc2RVmxe6ZT3Zum/3cZWEt/dVZ5qr1vxc9ywkNFbTIfn7Ksi+hp33Wmtqx1SPoH4Wgh+Pf9ZcyRyatr/oHkhjWl9vcG1fdgii/U= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787028854; c=relaxed/simple; bh=s3E59DEkTwmIFTz7MuzpmFxpBcghjoQ0VRBOBSPec04=; h=Date:Mime-Version:Message-ID:Subject:From:To:Cc:Content-Type; b=pz9Za0zXGlLFOdD42e9HxtbQ95bkPeHAqu0TY5Bq5RKPVqES4XJ/Z0pzXoGfMtlpz5jO3JiHyUVlPIbOJEqa2y1KhU2yGekKXXXbD/+yq0PZZTvBbHz7pt5unSMETm4igpDh1QpLQTcbj2N2lv0tU1P+obWgV7fpU7HAa4x6mgU= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--wfelipe.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=N/Zwhn4n; arc=none smtp.client-ip=209.85.214.199 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--wfelipe.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="N/Zwhn4n" Received: by mail-pl1-f199.google.com with SMTP id d9443c01a7336-2cc73f47bdcso53178705ad.3 for ; Mon, 17 Aug 2026 21:54:13 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1787028853; x=1787633653; darn=vger.kernel.org; h=content-type:cc:to:from:subject:message-id:mime-version:date:from :to:cc:subject:date:message-id:reply-to:content-type; bh=BrJkNG5NYV+2zgBwLZknrtqrv8W7GagmqRJwjgVdIYA=; b=N/Zwhn4nM7MS1aLMA+/uNxbi/ENwwAqpryGL8tT7O9dCVVxIla2pA3gWI+Yea9CMUk rUyHQ8lfFw57658/i0mfWp8pg0qcpjpuET8yrR1P3ITOHfjmVhsgKRkbKwxoi9yun7Ap G1nFaIhKXbH7c1IciIbun8HhREc7sat6LAVzoC834ZdDJBlxLb+yHA65DGZ5AFmK1GtJ S4z20HYw+ZyLah552loj9jN3bReLFBXefpnI2sEtTIaElCPwSYx0WQjtTmGfZYUljZfQ tC/caMN34cuLnTEFrqcIzzPYqbA+90FtaSUNTBBSYhmnRUkixYW4jqGmT2ERyE1tIdyc aMHQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787028853; x=1787633653; h=content-type:cc:to:from:subject:message-id:mime-version:date :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=BrJkNG5NYV+2zgBwLZknrtqrv8W7GagmqRJwjgVdIYA=; b=pkPgvD6i7IA1PIczDcBm7YrwS14a4gdT2DXyPcpUZiwrg//3FqFI62Xanw33Ij+nBE B8xaJM/xTMr4EgwV+k1UmXHQMLW067qvIi/o36Un5e571tE7mVJw0kU57ysvVLhm2z5G Qb8N3qIAEYOGdNzMTkkJwItmxHMNi6eOhM3Faw7ZUIyn8FV37F48nl2g2fkuQ4OMcked 0KmCnOXtYhTo4t1c8s5ssNepIcS9rl02nXHHJf8L4aofawkPK4O1dKR7NHt/EB2zyC/K MVRyjyo+r/yhA86w2nTeykYyz0tcIrKG3Z8D/vWMBEC4XoT2zfTRjJVAYQ5ljqcv+RG5 cVOg== X-Gm-Message-State: AOJu0YxqUTCsVyTNmWGHbV8xToU9Pulsf+cBOEGJCRkE7b/V0g7tek1W WkMg+65ncH0Pa8aMD2WqEz95yNL+3Otc5s+oro+TCgkbpRVzDSqiLgri9mUSBA4r1SqF3gEfTqB Mo5CQpihIqg== X-Received: from plbkn5.prod.google.com ([2002:a17:903:785:b0:2d0:c97:a4f2]) (user=wfelipe job=prod-delivery.src-stubby-dispatcher) by 2002:a17:903:1a2e:b0:2ca:9d5a:8b6c with SMTP id d9443c01a7336-2d5c4ee9bf2mr70443925ad.5.1787028852563; Mon, 17 Aug 2026 21:54:12 -0700 (PDT) Date: Tue, 18 Aug 2026 04:53:45 +0000 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 X-Mailer: git-send-email 2.55.0.699.gb54405d56f-goog Message-ID: <20260818045357.4123784-1-wfelipe@google.com> Subject: [PATCH 0/2] init: fix array boundary bugs in boot parameter parsing From: Wilson Felipe Pereira To: Andrew Morton Cc: linux-kernel@vger.kernel.org, Wilson Felipe Pereira Content-Type: text/plain; charset="UTF-8" This series fixes two distinct boundary logic edge-case bugs in `init/main.c` related to parsing boot command-line arguments and environment variables. Both bugs have been present since the early git history (Linux-2.6.12-rc2). 1. The first patch fixes an off-by-one error in `init_setup()` where the final slot of the `argv_init` array was left uncleared. This allowed a stale kernel parameter to leak into the `init` process's user-space command line if exactly `MAX_INIT_ARGS` unknown parameters were passed. 2. The second patch fixes a false-positive kernel panic in `unknown_bootoption()`. If a user filled the environment variable array up to its exact limit (32) and then attempted to overwrite the final variable, the kernel would panic before evaluating whether it was a harmless duplicate. Exact QEMU reproduction steps for both edge cases are documented inside their respective commit descriptions. Wilson Felipe Pereira (2): init/main: fix off-by-one in argv_init cleanup init/main: fix false-positive kernel panic on environment variable overwrite init/main.c | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) -- 2.55.0.699.gb54405d56f-goog