From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pj1-f71.google.com (mail-pj1-f71.google.com [209.85.216.71]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id DBBF826A08A for ; Tue, 18 Aug 2026 04:54:19 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.216.71 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787028861; cv=none; b=VZBigzcvrvD1rRWrSNZduWNbzAr/yumLoSxXqqLKntnR/xAnRLWPqXdsxDRyv7eclCzDv/4ndzbpbj/CJYRQEVKhsFZGp6dpr4xcRRcr3kChYGJaCEXlkQ4+AseXRHiTashCsC12zS9JhfW4lKx53kdHxFaYnZF3qF+oWfY/+H8= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787028861; c=relaxed/simple; bh=yJR+yoKG9pXKKyVRHjxz11VaSp5gR2lal3l0KA8rBk0=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=E3F+ly12IgoQtFmrmYH2FAcN/OQ6D8yTuRuTIg7EDMGth6r4Suyl/gxC8ySDREWdU+FeG7F8xsvuxNAf1qSjlH+9xz4vRQabp2f83v6ZhG30mtwX90CJQbK/oq/gUuz93RQoZ+EsShblF8jobpisvzWcfM+h4RaW+vqEdhm05Fs= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--wfelipe.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=shLRpubP; arc=none smtp.client-ip=209.85.216.71 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--wfelipe.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="shLRpubP" Received: by mail-pj1-f71.google.com with SMTP id 98e67ed59e1d1-38dbf293831so10627526a91.3 for ; Mon, 17 Aug 2026 21:54:19 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1787028859; x=1787633659; darn=vger.kernel.org; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:from:to:cc:subject:date:message-id:reply-to :content-type; bh=Txn7B8ugYadhPtvOokzEYTJGdZuCyvbbsYD589++790=; b=shLRpubPOU2AKg9KqmHjIpU6knGUIPECGOE14hqrAZaieapRXTC9BBj3nEW7e6eAPR Hb7Rvb9s5JEkFFCW0h00/GugZs0QmZbgix35Ur2G7PEXPjh07tmPiKWwCPKYiOiviHM9 l4yUD0KSqJwp4MNaITtaphmIACYGqq5EomKOB70JU4AHp/srHUJFPOk3Vs3nXE8u/B92 fq/K1OICWWRBjGmp/6s47nmae4u0lfC30WVRVRoquppfP1EQQLepzrxBEhTYZ1GTG5vq imG8EtSayVFrod6n2KSeBI0etOz6RA98qx7w8gzNxJzyPpujNQTXUrngOq3lCLF9mS6k Rx9w== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787028859; x=1787633659; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=Txn7B8ugYadhPtvOokzEYTJGdZuCyvbbsYD589++790=; b=fSSRgtKRZ/HkDSq2vLyOjhMpapHmbqyv2wBdy83pE8KH4h8EdlQp3FJZv10Sj2FAqU 3Aw/EOB07V7VOcybquEijEZasGGrQdDasZsG4gh0MEIOe0uDyTnSBgPiqPi8xeYQ70GV nOh9dh/J4J9K13yrdSXG3WpVadiGkaOHzCdkwPf7FafLCWGLRZb2FuArPi+7riSw5O5/ zE6YnQp0HWEhArbs6lSbuNdfihfYtSB8B0fjVN8fBWK/R6rggT5p8/gIrj7CTcuZ4qXm RFj3i7QiM0gxUKc8PDHif5NUA3TwHyvNOzzSVDTcw6nMm+lgrX7ML+xKaYqHZBjMcfKc zOGg== X-Gm-Message-State: AOJu0YxChuk0cWqvpMAmSJ9gEsYkDzbEPDhxccc/xs0a2iTHehRp+C1x al+wjvoC7If6jI182ZTLOzUdMFVODrnHKoA6XR3k6PHkJpIwB8Yh5wC7Fr7YwmhzVYkbDQMrC8X 8cB3FJGkTJw== X-Received: from pjzm24.prod.google.com ([2002:a17:90b:698:b0:38e:bc12:2b3d]) (user=wfelipe job=prod-delivery.src-stubby-dispatcher) by 2002:a17:90b:134c:b0:38d:ef48:b04 with SMTP id 98e67ed59e1d1-3933b8721a1mr32362654a91.10.1787028859066; Mon, 17 Aug 2026 21:54:19 -0700 (PDT) Date: Tue, 18 Aug 2026 04:53:46 +0000 In-Reply-To: <20260818045357.4123784-1-wfelipe@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260818045357.4123784-1-wfelipe@google.com> X-Mailer: git-send-email 2.55.0.699.gb54405d56f-goog Message-ID: <20260818045357.4123784-2-wfelipe@google.com> Subject: [PATCH 1/2] init/main: fix off-by-one in argv_init cleanup From: Wilson Felipe Pereira To: Andrew Morton Cc: linux-kernel@vger.kernel.org, Wilson Felipe Pereira Content-Type: text/plain; charset="UTF-8" When cleaning up argv_init in init_setup() and rdinit_setup(), the loop terminates one element early due to using '<' instead of '<='. Since argv_init is sized MAX_INIT_ARGS+2, index MAX_INIT_ARGS is a valid element that should be cleared to NULL. If exactly MAX_INIT_ARGS unknown arguments are passed before 'init=', the uncleared argv_init[MAX_INIT_ARGS] can act as a ghost argument to /sbin/init or cause a spurious kernel panic when later appended to. To verify the argument leak, boot a VM into a shell with 32 unknown kernel arguments, the init parameter, and 31 user arguments: STALE_ARGS=$(for i in {1..32}; do echo -n "stale$i "; done) USER_ARGS=$(for i in {1..31}; do echo -n "user$i "; done) qemu-system-x86_64 -kernel bzImage \ -append "$STALE_ARGS init=/bin/sh $USER_ARGS" Running `cat /proc/1/cmdline` inside the shell reveals that the 32nd kernel argument ('stale32') incorrectly leaked into the init process's command line. This patch zeroes the final slot, cleanly terminating the array. Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2") Fixes: ffdfc40976dd ("[PATCH] Add rdinit parameter to pick early userspace init") Signed-off-by: Wilson Felipe Pereira --- init/main.c | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/init/main.c b/init/main.c index 92d34e496a33..f02041a42111 100644 --- a/init/main.c +++ b/init/main.c @@ -572,7 +572,7 @@ static int __init init_setup(char *str) * the shell think it should execute a script with such name. * So we ignore all arguments entered _before_ init=... [MJ] */ - for (i = 1; i < MAX_INIT_ARGS; i++) + for (i = 1; i <= MAX_INIT_ARGS; i++) argv_init[i] = NULL; return 1; } @@ -585,7 +585,7 @@ static int __init rdinit_setup(char *str) ramdisk_execute_command = str; ramdisk_execute_command_set = true; /* See "auto" comment in init_setup */ - for (i = 1; i < MAX_INIT_ARGS; i++) + for (i = 1; i <= MAX_INIT_ARGS; i++) argv_init[i] = NULL; return 1; } -- 2.55.0.699.gb54405d56f-goog