mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH] ASoC: SOF: Bound the panic filename print to its array size
@ 2026-09-09 20:40 Ștefan Ghețu
  2026-09-09 20:40 ` [PATCH] ASoC: SOF: imx: Prevent stack OOB read in DSP panic dump Ștefan Ghețu
  2026-09-10 12:15 ` [PATCH] ASoC: SOF: Bound the panic filename print to its array size Péter Ujfalusi
  0 siblings, 2 replies; 5+ messages in thread
From: Ștefan Ghețu @ 2026-09-09 20:40 UTC (permalink / raw)
  To: Liam Girdwood, Peter Ujfalusi, Bard Liao, Daniel Baluta, Mark Brown
  Cc: Kai Vehmanen, Pierre-Louis Bossart, Vijendar Mukunda,
	Jaroslav Kysela, Takashi Iwai, Frank Li, Sascha Hauer,
	Pengutronix Kernel Team, Fabio Estevam, Ranjani Sridharan,
	sound-open-firmware, linux-sound, linux-kernel, imx,
	linux-arm-kernel, Ștefan Ghețu

struct sof_ipc_panic_info carries the panic location as a fixed 32 byte
array, and include/sound/sof/trace.h documents that the "filename array
will not include null terminator if fully filled".

sof_print_oops_and_stack() prints it with an unbounded %s, so firmware
that fills all 32 bytes leaves printk() with no terminator to stop at
within the array. It continues into the adjacent linenum field and, if
that holds no zero byte either, past the end of the structure into the
caller's stack frame, since every IPC3 dbg_dump callback passes a stack
allocated struct sof_ipc_panic_info.

Use %.*s with SOF_TRACE_FILENAME_SIZE so the print honours the
documented bound.

Fixes: c16211d6226d ("ASoC: SOF: Add Sound Open Firmware driver core")
Signed-off-by: Ștefan Ghețu <stefanghetu9@gmail.com>
---
 sound/soc/sof/core.c | 3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

diff --git a/sound/soc/sof/core.c b/sound/soc/sof/core.c
index 2d394389c945..9b0850e87bf6 100644
--- a/sound/soc/sof/core.c
+++ b/sound/soc/sof/core.c
@@ -152,7 +152,8 @@ void sof_print_oops_and_stack(struct snd_sof_dev *sdev, const char *level,
 	dev_printk(level, sdev->dev, "trace point: %#010x\n", tracep_code);
 
 out:
-	dev_printk(level, sdev->dev, "panic at %s:%d\n", panic_info->filename,
+	dev_printk(level, sdev->dev, "panic at %.*s:%d\n",
+		   SOF_TRACE_FILENAME_SIZE, panic_info->filename,
 		   panic_info->linenum);
 	sof_oops(sdev, level, oops);
 	sof_stack(sdev, level, oops, stack, stack_words);
-- 
2.53.0


^ permalink raw reply	[flat|nested] 5+ messages in thread

end of thread, other threads:[~2026-09-10 13:26 UTC | newest]

Thread overview: 5+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-09-09 20:40 [PATCH] ASoC: SOF: Bound the panic filename print to its array size Ștefan Ghețu
2026-09-09 20:40 ` [PATCH] ASoC: SOF: imx: Prevent stack OOB read in DSP panic dump Ștefan Ghețu
2026-09-10 13:17   ` Mark Brown
2026-09-10 13:26     ` Péter Ujfalusi
2026-09-10 12:15 ` [PATCH] ASoC: SOF: Bound the panic filename print to its array size Péter Ujfalusi

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®