broadwell/me: Fix out-of-bounds array access error

Fix an issue where a broadwell machine without the ME
installed could result in an invalid status code being
reported. For certain values, this would result in the
intel_me_status function never returning. Fix has been
tested on a samus board w and w/o the ME blob installed.

Change-Id: I96667d3b89393f161e4d4efe0544efac98367e6c
Signed-off-by: Evan Lojewski <meklort@gmail.com>
Reviewed-on: https://review.coreboot.org/14409
Tested-by: build bot (Jenkins)
Reviewed-by: Duncan Laurie <dlaurie@google.com>
This commit is contained in:
Evan Lojewski 2016-04-18 20:19:03 -06:00 committed by Duncan Laurie
parent a41e030fbc
commit aa431c0e17
1 changed files with 37 additions and 13 deletions

View File

@ -23,6 +23,12 @@
#include <soc/me.h> #include <soc/me.h>
#include <delay.h> #include <delay.h>
#define ARRAY_TO_ELEMENT(__array__, __index__, __default__) \
(((__index__) < ARRAY_SIZE((__array__))) ? \
(__array__)[(__index__)] : \
(__default__))
static inline void me_read_dword_ptr(void *ptr, int offset) static inline void me_read_dword_ptr(void *ptr, int offset)
{ {
u32 dword = pci_read_config32(PCH_DEV_ME, offset); u32 dword = pci_read_config32(PCH_DEV_ME, offset);
@ -225,23 +231,37 @@ void intel_me_status(void)
printk(BIOS_DEBUG, "ME: Update In Progress : %s\n", printk(BIOS_DEBUG, "ME: Update In Progress : %s\n",
hfs->update_in_progress ? "YES" : "NO"); hfs->update_in_progress ? "YES" : "NO");
printk(BIOS_DEBUG, "ME: Current Working State : %s\n", printk(BIOS_DEBUG, "ME: Current Working State : %s\n",
me_cws_values[hfs->working_state]); ARRAY_TO_ELEMENT(me_cws_values,
hfs->working_state,
"Unknown (OOB)"));
printk(BIOS_DEBUG, "ME: Current Operation State : %s\n", printk(BIOS_DEBUG, "ME: Current Operation State : %s\n",
me_opstate_values[hfs->operation_state]); ARRAY_TO_ELEMENT(me_opstate_values,
hfs->operation_state,
"Unknown (OOB)"));
printk(BIOS_DEBUG, "ME: Current Operation Mode : %s\n", printk(BIOS_DEBUG, "ME: Current Operation Mode : %s\n",
me_opmode_values[hfs->operation_mode]); ARRAY_TO_ELEMENT(me_opmode_values,
hfs->operation_mode,
"Unknown (OOB)"));
printk(BIOS_DEBUG, "ME: Error Code : %s\n", printk(BIOS_DEBUG, "ME: Error Code : %s\n",
me_error_values[hfs->error_code]); ARRAY_TO_ELEMENT(me_error_values,
hfs->error_code,
"Unknown (OOB)"));
printk(BIOS_DEBUG, "ME: Progress Phase : %s\n", printk(BIOS_DEBUG, "ME: Progress Phase : %s\n",
me_progress_values[hfs2->progress_code]); ARRAY_TO_ELEMENT(me_progress_values,
hfs2->progress_code,
"Unknown (OOB)"));
printk(BIOS_DEBUG, "ME: Power Management Event : %s\n", printk(BIOS_DEBUG, "ME: Power Management Event : %s\n",
me_pmevent_values[hfs2->current_pmevent]); ARRAY_TO_ELEMENT(me_pmevent_values,
hfs2->current_pmevent,
"Unknown (OOB)"));
printk(BIOS_DEBUG, "ME: Progress Phase State : "); printk(BIOS_DEBUG, "ME: Progress Phase State : ");
switch (hfs2->progress_code) { switch (hfs2->progress_code) {
case ME_HFS2_PHASE_ROM: /* ROM Phase */ case ME_HFS2_PHASE_ROM: /* ROM Phase */
printk(BIOS_DEBUG, "%s", printk(BIOS_DEBUG, "%s",
me_progress_rom_values[hfs2->current_state]); ARRAY_TO_ELEMENT(me_progress_rom_values,
hfs2->current_state,
"Unknown (OOB)"));
break; break;
case ME_HFS2_PHASE_UKERNEL: /* uKernel Phase */ case ME_HFS2_PHASE_UKERNEL: /* uKernel Phase */
@ -249,19 +269,23 @@ void intel_me_status(void)
break; break;
case ME_HFS2_PHASE_BUP: /* Bringup Phase */ case ME_HFS2_PHASE_BUP: /* Bringup Phase */
if (hfs2->current_state < ARRAY_SIZE(me_progress_bup_values) if (ARRAY_TO_ELEMENT(me_progress_bup_values,
&& me_progress_bup_values[hfs2->current_state]) hfs2->current_state, NULL))
printk(BIOS_DEBUG, "%s", printk(BIOS_DEBUG, "%s",
me_progress_bup_values[hfs2->current_state]); ARRAY_TO_ELEMENT(me_progress_bup_values,
hfs2->current_state,
NULL));
else else
printk(BIOS_DEBUG, "0x%02x", hfs2->current_state); printk(BIOS_DEBUG, "0x%02x", hfs2->current_state);
break; break;
case ME_HFS2_PHASE_POLICY: /* Policy Module Phase */ case ME_HFS2_PHASE_POLICY: /* Policy Module Phase */
if (hfs2->current_state < ARRAY_SIZE(me_progress_policy_values) if (ARRAY_TO_ELEMENT(me_progress_policy_values,
&& me_progress_policy_values[hfs2->current_state]) hfs2->current_state, NULL))
printk(BIOS_DEBUG, "%s", printk(BIOS_DEBUG, "%s",
me_progress_policy_values[hfs2->current_state]); ARRAY_TO_ELEMENT(me_progress_policy_values,
hfs2->current_state,
NULL));
else else
printk(BIOS_DEBUG, "0x%02x", hfs2->current_state); printk(BIOS_DEBUG, "0x%02x", hfs2->current_state);
break; break;