| From 2de821bf3569eed33947e9884f88ca37ce28577e Mon Sep 17 00:00:00 2001 |
| From: Sasha Levin <sashal@kernel.org> |
| Date: Mon, 21 Aug 2023 09:32:18 +0800 |
| Subject: alx: fix OOB-read compiler warning |
| MIME-Version: 1.0 |
| Content-Type: text/plain; charset=UTF-8 |
| Content-Transfer-Encoding: 8bit |
| |
| From: GONG, Ruiqi <gongruiqi1@huawei.com> |
| |
| [ Upstream commit 3a198c95c95da10ad844cbeade2fe40bdf14c411 ] |
| |
| The following message shows up when compiling with W=1: |
| |
| In function ‘fortify_memcpy_chk’, |
| inlined from ‘alx_get_ethtool_stats’ at drivers/net/ethernet/atheros/alx/ethtool.c:297:2: |
| ./include/linux/fortify-string.h:592:4: error: call to ‘__read_overflow2_field’ |
| declared with attribute warning: detected read beyond size of field (2nd parameter); |
| maybe use struct_group()? [-Werror=attribute-warning] |
| 592 | __read_overflow2_field(q_size_field, size); |
| | ^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ |
| |
| In order to get alx stats altogether, alx_get_ethtool_stats() reads |
| beyond hw->stats.rx_ok. Fix this warning by directly copying hw->stats, |
| and refactor the unnecessarily complicated BUILD_BUG_ON btw. |
| |
| Signed-off-by: GONG, Ruiqi <gongruiqi1@huawei.com> |
| Reviewed-by: Simon Horman <horms@kernel.org> |
| Link: https://lore.kernel.org/r/20230821013218.1614265-1-gongruiqi@huaweicloud.com |
| Signed-off-by: Paolo Abeni <pabeni@redhat.com> |
| Signed-off-by: Sasha Levin <sashal@kernel.org> |
| --- |
| drivers/net/ethernet/atheros/alx/ethtool.c | 5 ++--- |
| 1 file changed, 2 insertions(+), 3 deletions(-) |
| |
| diff --git a/drivers/net/ethernet/atheros/alx/ethtool.c b/drivers/net/ethernet/atheros/alx/ethtool.c |
| index 2f4eabf652e80..51e5aa2c74b34 100644 |
| --- a/drivers/net/ethernet/atheros/alx/ethtool.c |
| +++ b/drivers/net/ethernet/atheros/alx/ethtool.c |
| @@ -281,9 +281,8 @@ static void alx_get_ethtool_stats(struct net_device *netdev, |
| spin_lock(&alx->stats_lock); |
| |
| alx_update_hw_stats(hw); |
| - BUILD_BUG_ON(sizeof(hw->stats) - offsetof(struct alx_hw_stats, rx_ok) < |
| - ALX_NUM_STATS * sizeof(u64)); |
| - memcpy(data, &hw->stats.rx_ok, ALX_NUM_STATS * sizeof(u64)); |
| + BUILD_BUG_ON(sizeof(hw->stats) != ALX_NUM_STATS * sizeof(u64)); |
| + memcpy(data, &hw->stats, sizeof(hw->stats)); |
| |
| spin_unlock(&alx->stats_lock); |
| } |
| -- |
| 2.40.1 |
| |