From: Dan Magenheimer <dan.magenheimer@oracle.com>
To: Dan Carpenter <dan.carpenter@oracle.com>,
Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Cc: Konrad Wilk <konrad.wilk@oracle.com>,
devel@driverdev.osuosl.org, linux-mm@kvack.org,
kernel-janitors@vger.kernel.org
Subject: RE: [patch] staging: ramster: fix range checks in zcache_autocreate_pool()
Date: Thu, 6 Sep 2012 10:15:48 -0700 (PDT) [thread overview]
Message-ID: <8d085295-c15d-441c-8463-58cfc7ffc139@default> (raw)
In-Reply-To: <20120906124020.GA28946@elgon.mountain>
> From: Dan Carpenter
> Sent: Thursday, September 06, 2012 6:40 AM
> To: Greg Kroah-Hartman
> Cc: Dan Magenheimer; Konrad Rzeszutek Wilk; devel@driverdev.osuosl.org; linux-mm@kvack.org; kernel-
> janitors@vger.kernel.org
> Subject: [patch] staging: ramster: fix range checks in zcache_autocreate_pool()
>
> If "pool_id" is negative then it leads to a read before the start of the
> array. If "cli_id" is out of bounds then it leads to a NULL dereference
> of "cli". GCC would have warned about that bug except that we
> initialized the warning message away.
>
> Also it's better to put the parameter names into the function
> declaration in the .h file. It serves as a kind of documentation.
>
> Signed-off-by: Dan Carpenter <dan.carpenter@oracle.com>
Acked-by: Dan Magenheimer <dan.magenheimer@oracle.com>
Self-flagellated-by: Dan Magenheimer <dan.magenheimer@oracle.com>
> ---
> BTW, This file has a ton of GCC warnings. This function returns -1
> on error which is a nonsense return code but the return value is not
> checked anyway. *Grumble*.
>
> diff --git a/drivers/staging/ramster/zcache.h b/drivers/staging/ramster/zcache.h
> index c59666e..81722b3 100644
> --- a/drivers/staging/ramster/zcache.h
> +++ b/drivers/staging/ramster/zcache.h
> @@ -42,7 +42,7 @@ extern void zcache_decompress_to_page(char *, unsigned int, struct page *);
> #ifdef CONFIG_RAMSTER
> extern void *zcache_pampd_create(char *, unsigned int, bool, int,
> struct tmem_handle *);
> -extern int zcache_autocreate_pool(int, int, bool);
> +int zcache_autocreate_pool(unsigned int cli_id, unsigned int pool_id, bool eph);
> #endif
>
> #define MAX_POOLS_PER_CLIENT 16
> diff --git a/drivers/staging/ramster/zcache-main.c b/drivers/staging/ramster/zcache-main.c
> index 24b3d4a..86e19d6 100644
> --- a/drivers/staging/ramster/zcache-main.c
> +++ b/drivers/staging/ramster/zcache-main.c
> @@ -1338,10 +1338,10 @@ static int zcache_local_new_pool(uint32_t flags)
> return zcache_new_pool(LOCAL_CLIENT, flags);
> }
>
> -int zcache_autocreate_pool(int cli_id, int pool_id, bool eph)
> +int zcache_autocreate_pool(unsigned int cli_id, unsigned int pool_id, bool eph)
> {
> struct tmem_pool *pool;
> - struct zcache_client *cli = NULL;
> + struct zcache_client *cli;
> uint32_t flags = eph ? 0 : TMEM_POOL_PERSIST;
> int ret = -1;
>
> @@ -1350,8 +1350,10 @@ int zcache_autocreate_pool(int cli_id, int pool_id, bool eph)
> goto out;
> if (pool_id >= MAX_POOLS_PER_CLIENT)
> goto out;
> - else if ((unsigned int)cli_id < MAX_CLIENTS)
> - cli = &zcache_clients[cli_id];
> + if (cli_id >= MAX_CLIENTS)
> + goto out;
> +
> + cli = &zcache_clients[cli_id];
> if ((eph && disable_cleancache) || (!eph && disable_frontswap)) {
> pr_err("zcache_autocreate_pool: pool type disabled\n");
> goto out;
--
To unsubscribe, send a message with 'unsubscribe linux-mm' in
the body to majordomo@kvack.org. For more info on Linux MM,
see: http://www.linux-mm.org/ .
Don't email: <a href=mailto:"dont@kvack.org"> email@kvack.org </a>
prev parent reply other threads:[~2012-09-06 17:16 UTC|newest]
Thread overview: 5+ messages / expand[flat|nested] mbox.gz Atom feed top
2012-09-06 12:40 Dan Carpenter
2012-09-06 16:25 ` Greg Kroah-Hartman
2012-09-06 16:32 ` Dan Magenheimer
2012-09-06 17:13 ` Dan Magenheimer
2012-09-06 17:15 ` Dan Magenheimer [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=8d085295-c15d-441c-8463-58cfc7ffc139@default \
--to=dan.magenheimer@oracle.com \
--cc=dan.carpenter@oracle.com \
--cc=devel@driverdev.osuosl.org \
--cc=gregkh@linuxfoundation.org \
--cc=kernel-janitors@vger.kernel.org \
--cc=konrad.wilk@oracle.com \
--cc=linux-mm@kvack.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox