[edk2-devel] [PATCH] MdeModulePkg/TerminalDxe [BUG]: Terminal fifo buffer overflow.

Wu, Hao A hao.a.wu at intel.com
Fri Jan 15 08:53:07 UTC 2021


> -----Original Message-----
> From: Gao, Zhichao <zhichao.gao at intel.com>
> Sent: Friday, January 15, 2021 4:49 PM
> To: devel at edk2.groups.io; Gao, Zhichao <zhichao.gao at intel.com>;
> gechao at greatwall.com.cn; Wu, Hao A <hao.a.wu at intel.com>; Wang, Jian J
> <jian.j.wang at intel.com>
> Cc: Ni, Ray <ray.ni at intel.com>
> Subject: RE: [edk2-devel] [PATCH] MdeModulePkg/TerminalDxe [BUG]:
> Terminal fifo buffer overflow.
> 
> Add Hao and Jian, who have the permission to merge the patch. CI result:
> https://github.com/tianocore/edk2/pull/1358


Hello Zhichao,

I have added the 'push' label for the PR.

Best Regards,
Hao Wu


> 
> Thanks,
> Zhichao
> 
> > -----Original Message-----
> > From: devel at edk2.groups.io <devel at edk2.groups.io> On Behalf Of Gao,
> > Zhichao
> > Sent: Thursday, January 14, 2021 2:35 PM
> > To: gechao at greatwall.com.cn
> > Cc: devel at edk2.groups.io; Ni, Ray <ray.ni at intel.com>
> > Subject: Re: [edk2-devel] [PATCH] MdeModulePkg/TerminalDxe [BUG]:
> > Terminal fifo buffer overflow.
> >
> > There is no need to add [BUG] in the title. I would remove it when I create
> the PR.
> > If you want to have a record for this bug, you can edit a Bugzilla and
> > add the link in the commit message.
> > Beside of that, Reviewed-by: Zhichao Gao <zhichao.gao at intel.com>
> >
> > Thanks,
> > Zhichao
> >
> > > -----Original Message-----
> > > From: gechao at greatwall.com.cn <gechao at greatwall.com.cn>
> > > Sent: Thursday, January 14, 2021 11:23 AM
> > > To: Gao, Zhichao <zhichao.gao at intel.com>
> > > Cc: devel at edk2.groups.io; Ni, Ray <ray.ni at intel.com>; gechao
> > > <gechao at greatwall.com.cn>
> > > Subject: [PATCH] MdeModulePkg/TerminalDxe [BUG]: Terminal fifo
> > > buffer overflow.
> > >
> > > From: gechao <gechao at greatwall.com.cn>
> > >
> > > Fix the bug of terminal fifo buffer overflow with UINT8 type.
> > >
> > > typedef struct {
> > >   UINT8 Head;
> > >   UINT8 Tail;
> > >   UINT8 Data[RAW_FIFO_MAX_NUMBER + 1]; } RAW_DATA_FIFO;
> > > RAW_FIFO_MAX_NUMBER is 256.
> > > the data buffer size is 257 (Index from 0 to 256), but the max value
> > > of the index, Head or Tail (UINT8), is 255. That means the last data
> > > of the data buffer would be always empty if we use Head/Tail to
> > > output/input the data correctly.  And because of the incorrect
> > > buffer size the FIFO full check "((Tail + 1) % (RAW_FIFO_MAX_NUMBER +
> 1)) == Head"
> > would never meet.
> > >
> > > Signed-off-by: gechao <gechao at greatwall.com.cn>
> > > ---
> > >  MdeModulePkg/Universal/Console/TerminalDxe/Terminal.h | 2 +-
> > >  1 file changed, 1 insertion(+), 1 deletion(-)
> > >
> > > diff --git a/MdeModulePkg/Universal/Console/TerminalDxe/Terminal.h
> > > b/MdeModulePkg/Universal/Console/TerminalDxe/Terminal.h
> > > index 378ace13ce..360e58e847 100644
> > > --- a/MdeModulePkg/Universal/Console/TerminalDxe/Terminal.h
> > > +++ b/MdeModulePkg/Universal/Console/TerminalDxe/Terminal.h
> > > @@ -37,7 +37,7 @@ SPDX-License-Identifier: BSD-2-Clause-Patent
> > > #include <Library/BaseLib.h>  -#define RAW_FIFO_MAX_NUMBER
> 256+#define
> > > RAW_FIFO_MAX_NUMBER 255 #define FIFO_MAX_NUMBER     128
> typedef
> > > struct {--
> > > 2.25.1
> >
> >
> >
> > 
> >



-=-=-=-=-=-=-=-=-=-=-=-
Groups.io Links: You receive all messages sent to this group.
View/Reply Online (#70395): https://edk2.groups.io/g/devel/message/70395
Mute This Topic: https://groups.io/mt/79670455/1813853
Group Owner: devel+owner at edk2.groups.io
Unsubscribe: https://edk2.groups.io/g/devel/unsub [edk2-devel-archive at redhat.com]
-=-=-=-=-=-=-=-=-=-=-=-






More information about the edk2-devel-archive mailing list