On Thu, Sep 10, 2026 at 12:54 AM Masami Hiramatsu (Google)
<[email protected]> wrote:
>
> From: Masami Hiramatsu (Google) <[email protected]>
>
> In xbc_verify_tree(), the loop iterating through all nodes to check that
> xbc_nodes[i].next < xbc_node_num and xbc_nodes[i].child < xbc_node_num
> is a defensive sanity check against implementation regressions (such
> an out-of-bounds index cannot be produced by malformed input).
>
> Running this check in the kernel adds unnecessary boot-time overhead.
> Split this check out into xbc_sanity_check_tree() for userspace, so
> that it continues to run during userspace bootconfig validation (e.g.
> when applying or testing bootconfig with tools/bootconfig), but is
> omitted in the kernel to speed up initialization.
>
> Reported-by: Sang-Heon Jeon <[email protected]>
> Closes: 
> https://lore.kernel.org/all/[email protected]/
> Signed-off-by: Masami Hiramatsu (Google) <[email protected]>
> ---
>  lib/bootconfig.c |   38 ++++++++++++++++++++++++++------------
>  1 file changed, 26 insertions(+), 12 deletions(-)
>
> diff --git a/lib/bootconfig.c b/lib/bootconfig.c
> index 0ec2874db9c7..884f186b1989 100644
> --- a/lib/bootconfig.c
> +++ b/lib/bootconfig.c
> @@ -1000,9 +1000,30 @@ static int __init xbc_close_brace(char **k, char *n)
>         return __xbc_close_brace(n - 1);
>  }
>
> +#ifndef __KERNEL__
> +/* Sanity check for regression: node indices must be within bounds */
> +static int __init xbc_sanity_check_tree(void)
> +{
> +       int i;
> +
> +       for (i = 0; i < xbc_node_num; i++) {
> +               if (xbc_nodes[i].next >= xbc_node_num) {
> +                       return xbc_parse_error("No closing brace",
> +                               xbc_node_get_data(xbc_nodes + i));
> +               }
> +               if (xbc_nodes[i].child >= xbc_node_num) {
> +                       return xbc_parse_error("Broken child node",
> +                               xbc_node_get_data(xbc_nodes + i));
> +               }
> +       }
> +
> +       return 0;
> +}
> +#endif
> +
>  static int __init xbc_verify_tree(void)
>  {
> -       int i, depth;
> +       int depth;
>         size_t len, wlen;
>         struct xbc_node *n, *m;
>
> @@ -1019,17 +1040,6 @@ static int __init xbc_verify_tree(void)
>                 return -ENOENT;
>         }
>
> -       for (i = 0; i < xbc_node_num; i++) {
> -               if (xbc_nodes[i].next >= xbc_node_num) {
> -                       return xbc_parse_error("No closing brace",
> -                               xbc_node_get_data(xbc_nodes + i));
> -               }
> -               if (xbc_nodes[i].child >= xbc_node_num) {
> -                       return xbc_parse_error("Broken child node",
> -                               xbc_node_get_data(xbc_nodes + i));
> -               }
> -       }
> -
>         /* Key tree limitation check */
>         n = &xbc_nodes[0];
>         depth = 1;
> @@ -1199,6 +1209,10 @@ int __init xbc_init(const char *data, size_t size, 
> const char **emsg, int *epos)
>         ret = xbc_parse_tree();
>         if (!ret)
>                 ret = xbc_verify_tree();
> +#ifndef __KERNEL__
> +       if (!ret)
> +               ret = xbc_sanity_check_tree();
> +#endif
>
>         if (ret < 0) {
>                 if (epos)
>

Thanks for doing this.

Reviewed-by: Sang-Heon Jeon <[email protected]>

Reply via email to