Commit c1cb8142 authored by Daniel Thompson's avatar Daniel Thompson

kdb: Fix the putarea helper function

Currently kdb_putarea_size() uses copy_from_kernel_nofault() to write *to*
arbitrary kernel memory. This is obviously wrong and means the memory
modify ('mm') command is a serious risk to debugger stability: if we poke
to a bad address we'll double-fault and lose our debug session.

Fix this the (very) obvious way.

Note that there are two Fixes: tags because the API was renamed and this
patch will only trivially backport as far as the rename (and this is
probably enough). Nevertheless Christoph's rename did not introduce this
problem so I wanted to record that!

Fixes: fe557319 ("maccess: rename probe_kernel_{read,write} to copy_{from,to}_kernel_nofault")
Fixes: 5d5314d6 ("kdb: core for kgdb back end (1 of 2)")
Signed-off-by: default avatarDaniel Thompson <daniel.thompson@linaro.org>
Reviewed-by: default avatarDouglas Anderson <dianders@chromium.org>
Link: https://lore.kernel.org/r/20220128144055.207267-1-daniel.thompson@linaro.org
parent 09688c01
...@@ -291,7 +291,7 @@ int kdb_getarea_size(void *res, unsigned long addr, size_t size) ...@@ -291,7 +291,7 @@ int kdb_getarea_size(void *res, unsigned long addr, size_t size)
*/ */
int kdb_putarea_size(unsigned long addr, void *res, size_t size) int kdb_putarea_size(unsigned long addr, void *res, size_t size)
{ {
int ret = copy_from_kernel_nofault((char *)addr, (char *)res, size); int ret = copy_to_kernel_nofault((char *)addr, (char *)res, size);
if (ret) { if (ret) {
if (!KDB_STATE(SUPPRESS)) { if (!KDB_STATE(SUPPRESS)) {
kdb_func_printf("Bad address 0x%lx\n", addr); kdb_func_printf("Bad address 0x%lx\n", addr);
......
Markdown is supported
0%
or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment