Merge branch '2022-04-29-fuzzing-and-asan-fixes'
To quote the author: I've been experimenting with ASAN on sandbox and turned up a few issues that are fixed in this series. Basic ASAN was easy to turn on, but integrating with dlmalloc was messier and fairly intrusive. Even when I had it working, there was only a small redzone between allocations which limits the usefulness. I saw another series on the list by Sean Anderson to enable valgrind which was finding a different set of issues, though there was one overlap that Sean is fixing with "[PATCH] IOMUX: Fix access past end of console_devices". With these issues fixed, I was able to run the dm tests without any ASAN issues. There are a couple of leaks reported at the end, but that's for another day.
This commit is contained in:
@@ -178,7 +178,7 @@ static int do_acpi_dump(struct cmd_tbl *cmdtp, int flag, int argc,
|
||||
printf("Table name '%s' must be four characters\n", name);
|
||||
return CMD_RET_FAILURE;
|
||||
}
|
||||
str_to_upper(name, sig, -1);
|
||||
str_to_upper(name, sig, ACPI_NAME_LEN);
|
||||
ret = dump_table_name(sig);
|
||||
if (ret) {
|
||||
printf("Table '%.*s' not found\n", ACPI_NAME_LEN, sig);
|
||||
|
||||
@@ -103,7 +103,7 @@ running with -D will produce different results.
|
||||
|
||||
You can easily use gdb on these tests, without needing --gdbserver::
|
||||
|
||||
$ gdb u-boot --args -T -c "ut dm gpio"
|
||||
$ gdb --args u-boot -T -c "ut dm gpio"
|
||||
...
|
||||
(gdb) break dm_test_gpio
|
||||
Breakpoint 1 at 0x1415bd: file test/dm/gpio.c, line 37.
|
||||
|
||||
@@ -37,6 +37,7 @@ static struct pci_bar {
|
||||
{ 0, 0 },
|
||||
{ 0, 0 },
|
||||
{ PCI_BASE_ADDRESS_SPACE_IO, 256 },
|
||||
{ 0, 0 },
|
||||
};
|
||||
|
||||
struct pmc_emul_priv {
|
||||
|
||||
@@ -25,13 +25,11 @@ void sound_create_square_wave(uint sample_rate, unsigned short *data, int size,
|
||||
int i, j;
|
||||
|
||||
for (i = 0; size && i < half; i++) {
|
||||
size -= 2;
|
||||
for (j = 0; j < channels; j++)
|
||||
for (j = 0; size && j < channels; j++, size -= 2)
|
||||
*data++ = amplitude;
|
||||
}
|
||||
for (i = 0; size && i < period - half; i++) {
|
||||
size -= 2;
|
||||
for (j = 0; j < channels; j++)
|
||||
for (j = 0; size && j < channels; j++, size -= 2)
|
||||
*data++ = -amplitude;
|
||||
}
|
||||
}
|
||||
|
||||
@@ -345,6 +345,8 @@ static int sandbox_flash_bulk(struct udevice *dev, struct usb_device *udev,
|
||||
} else {
|
||||
if (priv->alloc_len && len > priv->alloc_len)
|
||||
len = priv->alloc_len;
|
||||
if (len > sizeof(priv->buff))
|
||||
len = sizeof(priv->buff);
|
||||
memcpy(buff, priv->buff, len);
|
||||
priv->phase = PHASE_STATUS;
|
||||
}
|
||||
|
||||
@@ -15,13 +15,12 @@
|
||||
static int copy_to_unicode(char *buff, int length, const char *str)
|
||||
{
|
||||
int ptr;
|
||||
int i;
|
||||
|
||||
if (length < 2)
|
||||
return 0;
|
||||
buff[1] = USB_DT_STRING;
|
||||
for (ptr = 2, i = 0; ptr + 1 < length && *str; i++, ptr += 2) {
|
||||
buff[ptr] = str[i];
|
||||
for (ptr = 2; ptr + 1 < length && *str; str++, ptr += 2) {
|
||||
buff[ptr] = *str;
|
||||
buff[ptr + 1] = 0;
|
||||
}
|
||||
buff[0] = ptr;
|
||||
|
||||
@@ -178,11 +178,8 @@ static int dm_test_devres_phase(struct unit_test_state *uts)
|
||||
ut_asserteq(1, stats.allocs);
|
||||
ut_asserteq(TEST_DEVRES_SIZE, stats.total_size);
|
||||
|
||||
/* Unbinding removes the other. Note this access a freed pointer */
|
||||
/* Unbinding removes the other. */
|
||||
device_unbind(dev);
|
||||
devres_get_stats(dev, &stats);
|
||||
ut_asserteq(0, stats.allocs);
|
||||
ut_asserteq(0, stats.total_size);
|
||||
|
||||
return 0;
|
||||
}
|
||||
|
||||
@@ -286,8 +286,7 @@ U_BOOT_DRIVER(regmap_test) = {
|
||||
static int dm_test_devm_regmap(struct unit_test_state *uts)
|
||||
{
|
||||
int i = 0;
|
||||
u16 val;
|
||||
void *valp = &val;
|
||||
uint val;
|
||||
u16 pattern[REGMAP_TEST_BUF_SZ];
|
||||
u16 *buffer;
|
||||
struct udevice *dev;
|
||||
@@ -311,7 +310,7 @@ static int dm_test_devm_regmap(struct unit_test_state *uts)
|
||||
ut_assertok(regmap_write(priv->cfg_regmap, i, pattern[i]));
|
||||
}
|
||||
for (i = 0; i < REGMAP_TEST_BUF_SZ; i++) {
|
||||
ut_assertok(regmap_read(priv->cfg_regmap, i, valp));
|
||||
ut_assertok(regmap_read(priv->cfg_regmap, i, &val));
|
||||
ut_asserteq(val, buffer[i]);
|
||||
ut_asserteq(val, pattern[i]);
|
||||
}
|
||||
@@ -319,9 +318,9 @@ static int dm_test_devm_regmap(struct unit_test_state *uts)
|
||||
ut_asserteq(-ERANGE, regmap_write(priv->cfg_regmap, REGMAP_TEST_BUF_SZ,
|
||||
val));
|
||||
ut_asserteq(-ERANGE, regmap_read(priv->cfg_regmap, REGMAP_TEST_BUF_SZ,
|
||||
valp));
|
||||
&val));
|
||||
ut_asserteq(-ERANGE, regmap_write(priv->cfg_regmap, -1, val));
|
||||
ut_asserteq(-ERANGE, regmap_read(priv->cfg_regmap, -1, valp));
|
||||
ut_asserteq(-ERANGE, regmap_read(priv->cfg_regmap, -1, &val));
|
||||
|
||||
return 0;
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user