]> git.ipfire.org Git - thirdparty/kernel/stable.git/commitdiff
tty: hvc: replace BUG_ON() with negative return value
authorJuergen Gross <jgross@suse.com>
Mon, 29 Nov 2021 15:02:34 +0000 (16:02 +0100)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Wed, 8 Dec 2021 07:44:07 +0000 (08:44 +0100)
commit e679004dec37566f658a255157d3aed9d762a2b7 upstream.

Xen frontends shouldn't BUG() in case of illegal data received from
their backends. So replace the BUG_ON()s when reading illegal data from
the ring page with negative return values.

Reviewed-by: Jan Beulich <jbeulich@suse.com>
Signed-off-by: Juergen Gross <jgross@suse.com>
Link: https://lore.kernel.org/r/20210707091045.460-1-jgross@suse.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
drivers/tty/hvc/hvc_xen.c

index 11725422dacb6d8766fbbb3a67e4d564105bb213..e503ad91a25a5cf832d274cbc92a78d410f01e76 100644 (file)
@@ -98,7 +98,11 @@ static int __write_console(struct xencons_info *xencons,
        cons = intf->out_cons;
        prod = intf->out_prod;
        mb();                   /* update queue values before going on */
-       BUG_ON((prod - cons) > sizeof(intf->out));
+
+       if ((prod - cons) > sizeof(intf->out)) {
+               pr_err_once("xencons: Illegal ring page indices");
+               return -EINVAL;
+       }
 
        while ((sent < len) && ((prod - cons) < sizeof(intf->out)))
                intf->out[MASK_XENCONS_IDX(prod++, intf->out)] = data[sent++];
@@ -126,7 +130,10 @@ static int domU_write_console(uint32_t vtermno, const char *data, int len)
         */
        while (len) {
                int sent = __write_console(cons, data, len);
-               
+
+               if (sent < 0)
+                       return sent;
+
                data += sent;
                len -= sent;
 
@@ -150,7 +157,11 @@ static int domU_read_console(uint32_t vtermno, char *buf, int len)
        cons = intf->in_cons;
        prod = intf->in_prod;
        mb();                   /* get pointers before reading ring */
-       BUG_ON((prod - cons) > sizeof(intf->in));
+
+       if ((prod - cons) > sizeof(intf->in)) {
+               pr_err_once("xencons: Illegal ring page indices");
+               return -EINVAL;
+       }
 
        while (cons != prod && recv < len)
                buf[recv++] = intf->in[MASK_XENCONS_IDX(cons++, intf->in)];