diff options
| author | Wilson Felipe Pereira <wfelipe@google.com> | 2026-08-18 04:53:47 +0000 |
|---|---|---|
| committer | Andrew Morton <akpm@linux-foundation.org> | 2026-09-13 21:33:31 -0700 |
| commit | 22f1bdfd259b43e59d63a072cd87b24fa61841a7 (patch) | |
| tree | 376d1acb8dbf25e8fec389e7ed5caad9ed3ef885 /fs | |
| parent | eb983ac9e62cd618330340f56bba9d8b2053fd7a (diff) | |
| download | linux-next-22f1bdfd259b43e59d63a072cd87b24fa61841a7.tar.gz linux-next-22f1bdfd259b43e59d63a072cd87b24fa61841a7.zip | |
init/main: fix false-positive kernel panic on environment variable overwrite
In unknown_bootoption(), the limit checking for environment variables sets
panic_later *before* checking if the variable already exists in envp_init.
If a user passes exactly MAX_INIT_ENVS custom variables and then
overwrites the final variable by matching its key, it causes a
false-positive hard panic on boot despite not actually exceeding the array
bounds or increasing the total variable count.
Swapping the order of these checks allows the duplicate check to break out
of the loop before the panic flag is erroneously latched.
To verify, boot a VM with 31 custom variables (filling the array up to its
limit of 32) and then overwrite the very last variable:
ENV_VARS=$(for i in {1..31}; do echo -n "var$i=$i "; done)
qemu-system-x86_64 -kernel bzImage -append "$ENV_VARS var31=overwrite"
Without this patch, the kernel crashes instantly with:
Kernel panic - not syncing: Too many boot env vars at 'var31=overwrite'
With this patch, the kernel safely overwrites the variable and boots.
Link: https://lore.kernel.org/20260818045357.4123784-3-wfelipe@google.com
Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Signed-off-by: Wilson Felipe Pereira <wfelipe@google.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Diffstat (limited to 'fs')
0 files changed, 0 insertions, 0 deletions
