All of lore.kernel.org
 help / color / mirror / Atom feed
* [PATCH] nl802154: stricter input checking for boolean inputs
@ 2015-08-20 10:09 Stefan Schmidt
  2015-08-20 16:56 ` Alexander Aring
  2015-08-20 18:53 ` Marcel Holtmann
  0 siblings, 2 replies; 3+ messages in thread
From: Stefan Schmidt @ 2015-08-20 10:09 UTC (permalink / raw)
  To: linux-wpan; +Cc: Alexander Aring, Stefan Schmidt

So far we handled boolean input by forcing them with !! and assigning
them into a bool. This allowed userspace to send values > 1 which were
used as 1. We should be stricter here and return -EINVAL for all but
0 or 1.

Signed-off-by: Stefan Schmidt <stefan@osg.samsung.com>
---
 net/ieee802154/nl802154.c | 16 ++++++++++++----
 1 file changed, 12 insertions(+), 4 deletions(-)

diff --git a/net/ieee802154/nl802154.c b/net/ieee802154/nl802154.c
index 1b00a14..3f89c0a 100644
--- a/net/ieee802154/nl802154.c
+++ b/net/ieee802154/nl802154.c
@@ -1034,7 +1034,7 @@ static int nl802154_set_lbt_mode(struct sk_buff *skb, struct genl_info *info)
 	struct cfg802154_registered_device *rdev = info->user_ptr[0];
 	struct net_device *dev = info->user_ptr[1];
 	struct wpan_dev *wpan_dev = dev->ieee802154_ptr;
-	bool mode;
+	int mode;
 
 	if (netif_running(dev))
 		return -EBUSY;
@@ -1042,7 +1042,11 @@ static int nl802154_set_lbt_mode(struct sk_buff *skb, struct genl_info *info)
 	if (!info->attrs[NL802154_ATTR_LBT_MODE])
 		return -EINVAL;
 
-	mode = !!nla_get_u8(info->attrs[NL802154_ATTR_LBT_MODE]);
+	mode = nla_get_u8(info->attrs[NL802154_ATTR_LBT_MODE]);
+
+	if (mode != 0 && mode != 1)
+		return -EINVAL;
+
 	if (!wpan_phy_supported_bool(mode, rdev->wpan_phy.supported.lbt))
 		return -EINVAL;
 
@@ -1055,7 +1059,7 @@ nl802154_set_ackreq_default(struct sk_buff *skb, struct genl_info *info)
 	struct cfg802154_registered_device *rdev = info->user_ptr[0];
 	struct net_device *dev = info->user_ptr[1];
 	struct wpan_dev *wpan_dev = dev->ieee802154_ptr;
-	bool ackreq;
+	int ackreq;
 
 	if (netif_running(dev))
 		return -EBUSY;
@@ -1063,7 +1067,11 @@ nl802154_set_ackreq_default(struct sk_buff *skb, struct genl_info *info)
 	if (!info->attrs[NL802154_ATTR_ACKREQ_DEFAULT])
 		return -EINVAL;
 
-	ackreq = !!nla_get_u8(info->attrs[NL802154_ATTR_ACKREQ_DEFAULT]);
+	ackreq = nla_get_u8(info->attrs[NL802154_ATTR_ACKREQ_DEFAULT]);
+
+	if (ackreq != 0 && ackreq != 1)
+		return -EINVAL;
+
 	return rdev_set_ackreq_default(rdev, wpan_dev, ackreq);
 }
 
-- 
2.4.3


^ permalink raw reply related	[flat|nested] 3+ messages in thread

* Re: [PATCH] nl802154: stricter input checking for boolean inputs
  2015-08-20 10:09 [PATCH] nl802154: stricter input checking for boolean inputs Stefan Schmidt
@ 2015-08-20 16:56 ` Alexander Aring
  2015-08-20 18:53 ` Marcel Holtmann
  1 sibling, 0 replies; 3+ messages in thread
From: Alexander Aring @ 2015-08-20 16:56 UTC (permalink / raw)
  To: Stefan Schmidt; +Cc: linux-wpan

On Thu, Aug 20, 2015 at 12:09:47PM +0200, Stefan Schmidt wrote:
> So far we handled boolean input by forcing them with !! and assigning
> them into a bool. This allowed userspace to send values > 1 which were
> used as 1. We should be stricter here and return -EINVAL for all but
> 0 or 1.
> 
> Signed-off-by: Stefan Schmidt <stefan@osg.samsung.com>

Acked-by: Alexander Aring <alex.aring@gmail.com>

- Alex

^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: [PATCH] nl802154: stricter input checking for boolean inputs
  2015-08-20 10:09 [PATCH] nl802154: stricter input checking for boolean inputs Stefan Schmidt
  2015-08-20 16:56 ` Alexander Aring
@ 2015-08-20 18:53 ` Marcel Holtmann
  1 sibling, 0 replies; 3+ messages in thread
From: Marcel Holtmann @ 2015-08-20 18:53 UTC (permalink / raw)
  To: Stefan Schmidt; +Cc: linux-wpan, Alexander Aring

Hi Stefan,

> So far we handled boolean input by forcing them with !! and assigning
> them into a bool. This allowed userspace to send values > 1 which were
> used as 1. We should be stricter here and return -EINVAL for all but
> 0 or 1.
> 
> Signed-off-by: Stefan Schmidt <stefan@osg.samsung.com>
> ---
> net/ieee802154/nl802154.c | 16 ++++++++++++----
> 1 file changed, 12 insertions(+), 4 deletions(-)

patch has been applied to bluetooth-next tree.

Regards

Marcel


^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2015-08-20 18:53 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2015-08-20 10:09 [PATCH] nl802154: stricter input checking for boolean inputs Stefan Schmidt
2015-08-20 16:56 ` Alexander Aring
2015-08-20 18:53 ` Marcel Holtmann

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.