summaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorJuergen Beisert <jbe@pengutronix.de>2011-05-24 16:07:21 +0200
committerSascha Hauer <s.hauer@pengutronix.de>2011-05-25 21:16:49 +0200
commit46e72ec53370a127b4dfeff29e18631a6ded0020 (patch)
treec6da66a9b2ff15e67e1e72960dfa7587ee4f3a84
parent2fac6eb5c8e0234ff33392907f6546a7c9d39d67 (diff)
downloadbarebox-46e72ec53370a127b4dfeff29e18631a6ded0020.tar.gz
barebox-46e72ec53370a127b4dfeff29e18631a6ded0020.tar.xz
Always initialize oob_poi before writing OOB data
The following patch came across the mtd mailing list today. I thinks its also valid for barebox (it handles a special corner case, but maybe it can hit us, too): In nand_do_write_ops() code it is possible for a caller to provide ops.oobbuf populated and ops.mode == MTD_OOB_AUTO, which currently means that the chip->oob_poi buffer isn't initialised to all 0xFF. The nand_fill_oob() method then carries out the task of copying the provided OOB data to oob_poi, but with MTD_OOB_AUTO it skips areas marked as unavailable by the layout struct, including the bad block marker bytes. An example of this causing issues is when the last OOB data read was from the start of a bad block where the markers are not 0xFF, and the caller wishes to write new OOB data at the beginning of another block. In this scenario the caller would provide OOB data, but nand_fill_oob() would skip the bad block marker bytes in oob_poi before copying the OOB data provided by the caller. This means that when the OOB data is written back to NAND, the block is inadvertently marked as bad without the caller knowing. This has been witnessed when using YAFFS2 where tags are stored in the OOB. This patch changes the code so that oob_poi is always initialised to 0xFF to make sure no left over data is inadvertently written back to OOB data. The comment above is for the linux kernel, but the same is valid for barebox and CPUs writing the OOB date controlled in software (like the Samsung S3C2440 does). Signed-off-by: Adam Thomson <adam.thomson@alcatel-lucent.com> Signed-off-by: Juergen Beisert <jbe@pengutronix.de> Signed-off-by: Sascha Hauer <s.hauer@pengutronix.de>
-rw-r--r--drivers/mtd/nand/nand_write.c6
1 files changed, 3 insertions, 3 deletions
diff --git a/drivers/mtd/nand/nand_write.c b/drivers/mtd/nand/nand_write.c
index 89dc47b3..3ede8d02 100644
--- a/drivers/mtd/nand/nand_write.c
+++ b/drivers/mtd/nand/nand_write.c
@@ -303,9 +303,9 @@ int nand_do_write_ops(struct mtd_info *mtd, loff_t to,
(chip->pagebuf << chip->page_shift) < (to + ops->len))
chip->pagebuf = -1;
- /* If we're not given explicit OOB data, let it be 0xFF */
- if (likely(!oob))
- memset(chip->oob_poi, 0xff, mtd->oobsize);
+ /* Initialize to all 0xFF, to avoid the possibility of
+ left over OOB data from a previous OOB read. */
+ memset(chip->oob_poi, 0xff, mtd->oobsize);
while(1) {
int bytes = mtd->writesize;