From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from vger.kernel.org (vger.kernel.org [23.128.96.18]) by smtp.lore.kernel.org (Postfix) with ESMTP id 881B1C433F5 for ; Tue, 7 Dec 2021 08:00:57 +0000 (UTC) Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S231922AbhLGIE0 (ORCPT ); Tue, 7 Dec 2021 03:04:26 -0500 Received: from smtp-out2.suse.de ([195.135.220.29]:50966 "EHLO smtp-out2.suse.de" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S231896AbhLGIEZ (ORCPT ); Tue, 7 Dec 2021 03:04:25 -0500 Received: from relay2.suse.de (relay2.suse.de [149.44.160.134]) by smtp-out2.suse.de (Postfix) with ESMTP id 5FA5E1FD2F; Tue, 7 Dec 2021 08:00:54 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=suse.de; s=susede2_rsa; t=1638864054; h=from:from:reply-to:date:date:message-id:message-id:to:to:cc:cc: mime-version:mime-version:content-type:content-type: in-reply-to:in-reply-to:references:references; bh=WunL9IcKom/g+o4e32dvibfGKSiyLe40+462fTACWsg=; b=t3tHG/HoiLkECGDJLM3HxfPNdiujFEaWRR03HAESaWzxmQ2K3mnDTXv4lqoafzWwRukfbC jngbEbjsnrQVLRA2/R6E7dcM8434jDSaF77jIVaJnxzvwqimUtKxUzaox3om5NRMEswtZo auAFpC3bwx4s53pZd81Q/PgLw2edJGA= DKIM-Signature: v=1; a=ed25519-sha256; c=relaxed/relaxed; d=suse.de; s=susede2_ed25519; t=1638864054; h=from:from:reply-to:date:date:message-id:message-id:to:to:cc:cc: mime-version:mime-version:content-type:content-type: in-reply-to:in-reply-to:references:references; bh=WunL9IcKom/g+o4e32dvibfGKSiyLe40+462fTACWsg=; b=wMjgm9fEeBB6NJnAYeotB2CiqLCX5ZgF8f3A+zXSJ+Ql8mDUNrRbuXodmS9mx6ulXGoDYB Q2UllJTop6ILVMAg== Received: from alsa1.suse.de (alsa1.suse.de [10.160.4.42]) by relay2.suse.de (Postfix) with ESMTP id 548E4A3B87; Tue, 7 Dec 2021 08:00:54 +0000 (UTC) Date: Tue, 07 Dec 2021 09:00:54 +0100 Message-ID: From: Takashi Iwai To: Kees Cook Cc: Jaroslav Kysela , Takashi Iwai , linux-kernel@vger.kernel.org, alsa-devel@alsa-project.org, linux-hardening@vger.kernel.org Subject: Re: [PATCH] ALSA: mixart: Reduce size of mixart_timer_notify In-Reply-To: <20211207062941.2413679-1-keescook@chromium.org> References: <20211207062941.2413679-1-keescook@chromium.org> User-Agent: Wanderlust/2.15.9 (Almost Unreal) SEMI/1.14.6 (Maruoka) FLIM/1.14.9 (=?UTF-8?B?R29qxY0=?=) APEL/10.8 Emacs/25.3 (x86_64-suse-linux-gnu) MULE/6.0 (HANACHIRUSATO) MIME-Version: 1.0 (generated by SEMI 1.14.6 - "Maruoka") Content-Type: text/plain; charset=US-ASCII Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org On Tue, 07 Dec 2021 07:29:41 +0100, Kees Cook wrote: > > The mixart_timer_notify structure was larger than could be represented > by the mixart_msg_data array storage. Adjust the size to as large as > possible to fix the warning seen with -Warray-bounds builds: > > sound/pci/mixart/mixart_core.c: In function 'snd_mixart_threaded_irq': > sound/pci/mixart/mixart_core.c:447:50: error: array subscript 'struct mixart_timer_notify[0]' is partly outside array bounds of 'u32[128]' {aka 'unsigned int[128]'} [-Werror=array-bounds] > 447 | for(i=0; istream_count; i++) { > | ^~ > sound/pci/mixart/mixart_core.c:328:12: note: while referencing 'mixart_msg_data' > 328 | static u32 mixart_msg_data[MSG_DEFAULT_SIZE / 4]; > | ^~~~~~~~~~~~~~~ > > Signed-off-by: Kees Cook Thanks, applied now. > @@ -444,6 +442,7 @@ irqreturn_t snd_mixart_threaded_irq(int irq, void *dev_id) > struct mixart_timer_notify *notify; > notify = (struct mixart_timer_notify *)mixart_msg_data; > > + BUILD_BUG_ON(sizeof(notify) > sizeof(mixart_msg_data)); > for(i=0; istream_count; i++) { > > u32 buffer_id = notify->streams[i].buffer_id; I guess we should add the array boundary check of notify->stream_count, instead of fully relying on the hardware reply, too. Will submit the additional check. Takashi