[roll] Roll fuchsia [kernel] Make sys_system_mexec() size the ZBI properly Previously, after having coalesced the kernel_vmo into physical memory, sys_system_mexec() would attempt to create a zbitl::View of the kernel_vmo in order to interpret and parse the contents as a ZBI. The strategy for constructing this view was to use the function zbitl::StorageFromRawHeader(), which trusts that the metadata of the ZBI accurately reflect the provenance of the pointer passed as an argument. However, since the caller has full control over the contents of the kernel_vmo, they could feign a ZBI much larger than the actual size of the vmo. This would lead to sys_system_mexec() using a zbitl::View with a larger size than has actually been allocated for the kernel_vmo. Then when it tries to iterate through the items of said view with a call to zbitl::CheckBootable(), the iterator would dereference unallocated memory, causing undefined behavior. Since vmo objects track their own size, we don't need to depend on zbitl::StorageFromRawHeader() to create the zbitl::View. This CL changes sys_system_mexec() to construct the zbitl::View from a span of bytes. This way, even if the contents of the ZBI purport a different total length, the zbitl::View::end() will accurately reflect the length of the allocation, preventing iterators from dereferencing out of bounds. mcgrathr@ provided the idea to use spans in the construction of the zbitl::View PAIR=mcgrathr@ Original-Original-Bug: 512234306 Original-Original-Reviewed-on: https://fuchsia-review.googlesource.com/c/fuchsia/+/1617468 Original-Original-Revision: 93221231e2e91c531454340f9a7f0f9c8407b4ce GitOrigin-RevId: 1df29038ac7e34273439cc4ea7b8605f902b7aed Change-Id: Ic93719918d92eb4faa0de1b2fbbaac2ac41ea49a Reviewed-on: https://fuchsia-review.googlesource.com/c/integration/+/1640098 Cr-Commit-Position: refs/heads/main@{#194158}
This repository contains Fuchsia's Global Integration manifest files.
All changes should be made to the internal version of this repository. Our infrastructure automatically updates this version when the internal one changes.
Currently all changes must be made by a Google employee. Non-Google employees wishing to make a change can ask for assistance in one of the communication channels documented at get involved.
First install Jiri.
Next run:
$ jiri init $ jiri import minimal https://fuchsia.googlesource.com/integration $ jiri update
Third party projects should have their own subdirectory in ./third_party.