mirror of
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
synced 2026-08-30 16:53:20 -04:00
platform/x86: hp-bioscfg: advance elem past consumed array elements
The outer parsing loop in each attribute-type parser advances "elem" (the index into the ACPI package element array) by exactly one per iteration, but cases that consume multi-element arrays (PREREQUISITES, ENUM_POSSIBLE_VALUES, PSWD_ENCODINGS) read "size" consecutive elements without adjusting "elem" for the extra entries consumed beyond the first. The next outer iteration then re-reads a leftover element from the array just consumed instead of the next real property, and the type check fails on that stale element, aborting the parse with -EIO. This produces exactly the failure visible in dmesg on the test hardware, on every boot: Error expected type 2 for elem 13, but got type 1 instead hp_bioscfg: Returned error 0x3, "Invalid command value/Feature not supported" Fix by advancing "elem" by (size - 1) after each array-consuming loop, so the outer loop's own "elem++" lands on the correct next element. "eloc" is intentionally left alone: it indexes the logical property schema, not the physical element array, and each array case is still exactly one logical property regardless of how many physical elements it spans. The defect is identical across all five attribute-type parsers (enum, integer, string, ordered-list, password), which were copy-pasted from the same template when the driver was introduced. Fixes:6b2770bfd6("platform/x86: hp-bioscfg: enum-attributes") Fixes:6f2c06d5a4("platform/x86: hp-bioscfg: int-attributes") Fixes:e6c7b3e155("platform/x86: hp-bioscfg: string-attributes") Fixes:4b2672ec71("platform/x86: hp-bioscfg: order-list-attributes") Fixes:8646a3b5ee("platform/x86: hp-bioscfg: passwdobj-attributes") Cc: stable@vger.kernel.org Signed-off-by: Muhammad Bilal <meatuni001@gmail.com> Link: https://patch.msgid.link/20260812111829.172273-10-meatuni001@gmail.com Reviewed-by: Ilpo Järvinen <ilpo.jarvinen@linux.intel.com> Signed-off-by: Ilpo Järvinen <ilpo.jarvinen@linux.intel.com>
This commit is contained in:
committed by
Ilpo Järvinen
parent
cb6b1b0fb2
commit
05c808362e
@@ -228,6 +228,8 @@ static int hp_populate_enumeration_elements_from_package(union acpi_object *enum
|
||||
kfree(str_value);
|
||||
str_value = NULL;
|
||||
}
|
||||
if (size)
|
||||
elem += size - 1;
|
||||
break;
|
||||
|
||||
case SECURITY_LEVEL:
|
||||
@@ -281,6 +283,8 @@ static int hp_populate_enumeration_elements_from_package(union acpi_object *enum
|
||||
kfree(str_value);
|
||||
str_value = NULL;
|
||||
}
|
||||
if (size)
|
||||
elem += (size < MAX_VALUES_SIZE ? size : MAX_VALUES_SIZE) - 1;
|
||||
break;
|
||||
default:
|
||||
pr_warn("Invalid element: %d found in Enumeration attribute or data may be malformed\n", elem);
|
||||
|
||||
@@ -243,6 +243,8 @@ static int hp_populate_integer_elements_from_package(union acpi_object *integer_
|
||||
kfree(str_value);
|
||||
str_value = NULL;
|
||||
}
|
||||
if (size)
|
||||
elem += size - 1;
|
||||
break;
|
||||
|
||||
case SECURITY_LEVEL:
|
||||
|
||||
@@ -232,6 +232,8 @@ static int hp_populate_ordered_list_elements_from_package(union acpi_object *ord
|
||||
kfree(str_value);
|
||||
str_value = NULL;
|
||||
}
|
||||
if (size)
|
||||
elem += size - 1;
|
||||
break;
|
||||
|
||||
case SECURITY_LEVEL:
|
||||
|
||||
@@ -321,6 +321,8 @@ static int hp_populate_password_elements_from_package(union acpi_object *passwor
|
||||
str_value = NULL;
|
||||
|
||||
}
|
||||
if (size)
|
||||
elem += size - 1;
|
||||
break;
|
||||
case SECURITY_LEVEL:
|
||||
password_data->common.security_level = int_value;
|
||||
@@ -367,6 +369,8 @@ static int hp_populate_password_elements_from_package(union acpi_object *passwor
|
||||
str_value = NULL;
|
||||
|
||||
}
|
||||
if (size)
|
||||
elem += size - 1;
|
||||
break;
|
||||
case PSWD_IS_SET:
|
||||
password_data->is_enabled = int_value;
|
||||
|
||||
@@ -233,6 +233,8 @@ static int hp_populate_string_elements_from_package(union acpi_object *string_ob
|
||||
kfree(str_value);
|
||||
str_value = NULL;
|
||||
}
|
||||
if (size)
|
||||
elem += size - 1;
|
||||
break;
|
||||
|
||||
case SECURITY_LEVEL:
|
||||
|
||||
Reference in New Issue
Block a user