summaryrefslogtreecommitdiff
path: root/chipset_enable.c
diff options
context:
space:
mode:
authorhailfinger <hailfinger@2b7e53f0-3cfb-0310-b3e9-8179ed1497e1>2010-07-13 00:04:52 +0000
committerhailfinger <hailfinger@2b7e53f0-3cfb-0310-b3e9-8179ed1497e1>2010-07-13 00:04:52 +0000
commitceea3121b7040d4ac73b9946d5a8cad73d4e5475 (patch)
tree1b6200a4cae2469118f434f59e4d7f74f85f9102 /chipset_enable.c
parentf735a7222cacdd87cd430ef9557567625fb5c67b (diff)
downloadflashrom-ceea3121b7040d4ac73b9946d5a8cad73d4e5475.tar.gz
Fix out-of-bounds ICH FREG permission printing. A bit was masked, but
not shifted, and that led to worst-case accesses of index 24 in an array with 4 members. I've improved readability in the variable declaration block as well. Thanks to Stephen Kou for reporting the bug. Signed-off-by: Carl-Daniel Hailfinger <c-d.hailfinger.devel.2006@gmx.net> Acked-by: Stephen Kou <stephen@hyarros.com> git-svn-id: https://code.coreboot.org/svn/flashrom/trunk@1076 2b7e53f0-3cfb-0310-b3e9-8179ed1497e1
Diffstat (limited to 'chipset_enable.c')
-rw-r--r--chipset_enable.c7
1 files changed, 4 insertions, 3 deletions
diff --git a/chipset_enable.c b/chipset_enable.c
index 5c16259..dc0e55f 100644
--- a/chipset_enable.c
+++ b/chipset_enable.c
@@ -452,10 +452,11 @@ static void do_ich9_spi_frap(uint32_t frap, int i)
"Flash Descriptor", "BIOS", "Management Engine",
"Gigabit Ethernet", "Platform Data"
};
- int rwperms = ((ICH_BRWA(frap) & (1 << i)) << 1) |
- ((ICH_BRRA(frap) & (1 << i)) << 0);
+ uint32_t base, limit;
+ int rwperms = (((ICH_BRWA(frap) >> i) & 1) << 1) |
+ (((ICH_BRRA(frap) >> i) & 1) << 0);
int offset = 0x54 + i * 4;
- uint32_t freg = mmio_readl(ich_spibar + offset), base, limit;
+ uint32_t freg = mmio_readl(ich_spibar + offset);
msg_pdbg("0x%02X: 0x%08x (FREG%i: %s)\n",
offset, freg, i, region_names[i]);