Date: Mon, 24 Nov 1997 12:14:25 -0800 (PST) From: Joel.Faedi@esial.u-nancy.fr To: freebsd-gnats-submit@FreeBSD.ORG Subject: kern/5140: very early kernel panic (bios32 detection) on some Compaq Prolinea Message-ID: <199711242014.MAA00815@hub.freebsd.org> Resent-Message-ID: <199711242020.MAA01439@hub.freebsd.org>
next in thread | raw e-mail | index | archive | help
>Number: 5140 >Category: kern >Synopsis: very early kernel panic (bios32 detection) on some Compaq Prolinea >Confidential: no >Severity: critical >Priority: high >Responsible: freebsd-bugs >State: open >Class: sw-bug >Submitter-Id: current-users >Arrival-Date: Mon Nov 24 12:20:00 PST 1997 >Last-Modified: >Originator: Joel Faedi >Organization: ESIAL - Nancy (France) >Release: 3.0-971123-SNAP (problem since bios32 is detected) >Environment: >Description: On Compaq Prolinea with Pentium CPU (Prolinea 575/590/5133/5150, I have only these models), all kernels will panic. The problem is due to due to a call at "bios32_SDCI" address. This addess is given bios_sigsearch function in bios.c (see fix) after a cast in bios32_SDheader structure and on Compaq Prolinea, this value is too big (perhaps coded diffently). >How-To-Repeat: Boot 3.0-971123-SNAP (or some more older versions) from boot floppy, kernel will panic very quickly. >Fix: Fix bios32_init function in /usr/src/sys/i386/i386/bios.c: very value of sdh->entry, I think in should be less than BIOS max address: /* get a virtual pointer to the structure */ sdh = (struct bios32_SDheader *)BIOS_PADDRTOVADDR(sigaddr); for (cv = (u_int8_t *)sdh, ck = 0, i = 0; i < (sdh->len * 16); i++) { ck += cv[i]; } /* If checksum is OK, enable use of the entrypoint */ if (ck == 0 && sdh->entry < (BIOS_START + BIOS_SIZE)) { <<<<- bios32_SDCI = (caddr_t)BIOS_PADDRTOVADDR(sdh->entry); >Audit-Trail: >Unformatted:
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?199711242014.MAA00815>