Attempting to parse the mtdsplit-fit device can lead in a out of bounds
read error, as the driver did not validate a fit was found at all.
This can happen if the fit size in the header at the last scan iteration
is non-zero. In this case, the dmesg reads:
[ 6.563676] Creating 6 MTD partitions on "
ec000000.nor":
[ 6.569058] 0x000000000000-0x000003d60000 : "firmware"
[ 6.579192] read error in "firmware" at offset 0x3d60000
[ 6.584534] Failed to parse subpartitions: -22
[ 6.589010] Deleting MTD partitions on "
ec000000.nor":
Validate after the scan loop if a fit image was found and abort in this
stage if it is not found.
Signed-off-by: David Bauer <mail@david-bauer.net>
struct mtd_partition *parts;
int ret, ndepth, noffset, images_noffset;
const void *img_data;
+ bool found_fit = false;
void *fit;
of_property_read_string(np, "openwrt,cmdline-match", &cmdline_match);
}
/* We found a FIT image. Let's keep going */
+ found_fit = true;
break;
}
+ if (!found_fit) {
+ pr_info("No FIT image found in \"%s\"\n", mtd->name);
+ return -ENOENT;
+ }
+
fit_offset = offset;
fit_size = be32_to_cpu(hdr.totalsize);