From: Stephen Hemminger <stephen@networkplumber.org>
To: Jiri Pirko <jiri@resnulli.us>
Cc: netdev@vger.kernel.org, sthemmin@microsoft.com,
dsahern@gmail.com, alexanderk@mellanox.com, mlxsw@mellanox.com
Subject: Re: [patch iproute2 1/2] tc: action: fix crash caused by incorrect *argv check
Date: Fri, 26 Jul 2019 12:00:01 -0700 [thread overview]
Message-ID: <20190726120001.73f0bdb6@hermes.lan> (raw)
In-Reply-To: <20190723193600.GA2315@nanopsycho.orion>
On Tue, 23 Jul 2019 21:36:00 +0200
Jiri Pirko <jiri@resnulli.us> wrote:
> Tue, Jul 23, 2019 at 07:54:01PM CEST, stephen@networkplumber.org wrote:
> >On Tue, 23 Jul 2019 13:25:37 +0200
> >Jiri Pirko <jiri@resnulli.us> wrote:
> >
> >> From: Jiri Pirko <jiri@mellanox.com>
> >>
> >> One cannot depend on *argv being null in case of no arg is left on the
> >> command line. For example in batch mode, this is not always true. Check
> >> argc instead to prevent crash.
> >>
> >> Reported-by: Alex Kushnarov <alexanderk@mellanox.com>
> >> Fixes: fd8b3d2c1b9b ("actions: Add support for user cookies")
> >> Signed-off-by: Jiri Pirko <jiri@mellanox.com>
> >
> >Actually makeargs does NULL terminate the last arg so what input
> >to batchmode is breaking this?
>
> Interesting, there must be another but out there then.
>
> My input is:
> filter add dev testdummy parent ffff: protocol all prio 11000 flower action drop
> filter add dev testdummy parent ffff: protocol ipv4 prio 1 flower dst_mac 11:22:33:44:55:66 action drop
This maybe related. Looks like the batchsize patches had issues.
# valgrind ./tc/tc -batch filter.bat
==27348== Memcheck, a memory error detector
==27348== Copyright (C) 2002-2017, and GNU GPL'd, by Julian Seward et al.
==27348== Using Valgrind-3.14.0 and LibVEX; rerun with -h for copyright info
==27348== Command: ./tc/tc -batch filter.bat
==27348==
==27348== Conditional jump or move depends on uninitialised value(s)
==27348== at 0x4EE9C0C: getdelim (iogetdelim.c:59)
==27348== by 0x152A37: getline (stdio.h:120)
==27348== by 0x152A37: getcmdline (utils.c:1311)
==27348== by 0x115543: batch (tc.c:358)
==27348== by 0x4E9D09A: (below main) (libc-start.c:308)
==27348==
==27348== Conditional jump or move depends on uninitialised value(s)
==27348== at 0x152BE4: makeargs (utils.c:1359)
==27348== by 0x115614: batch (tc.c:366)
==27348== by 0x4E9D09A: (below main) (libc-start.c:308)
==27348==
==27348== Conditional jump or move depends on uninitialised value(s)
==27348== at 0x11EBFD: parse_action (m_action.c:225)
==27348== by 0x13633E: flower_parse_opt (f_flower.c:1285)
==27348== by 0x1190EB: tc_filter_modify (tc_filter.c:217)
==27348== by 0x115674: batch (tc.c:404)
==27348== by 0x4E9D09A: (below main) (libc-start.c:308)
==27348==
==27348== Use of uninitialised value of size 8
==27348== at 0x11EC0B: parse_action (m_action.c:225)
==27348== by 0x13633E: flower_parse_opt (f_flower.c:1285)
==27348== by 0x1190EB: tc_filter_modify (tc_filter.c:217)
==27348== by 0x115674: batch (tc.c:404)
==27348== by 0x4E9D09A: (below main) (libc-start.c:308)
==27348==
Error: Parent Qdisc doesn't exists.
Error: Parent Qdisc doesn't exists.
Command failed filter.bat:1
next prev parent reply other threads:[~2019-07-26 19:00 UTC|newest]
Thread overview: 10+ messages / expand[flat|nested] mbox.gz Atom feed top
2019-07-23 11:25 [patch iproute2 1/2] tc: action: fix crash caused by incorrect *argv check Jiri Pirko
2019-07-23 11:25 ` [patch iproute2 2/2] tc: batch: fix line/line_next processing in batch Jiri Pirko
2019-07-26 21:35 ` Stephen Hemminger
2019-07-23 17:47 ` [patch iproute2 1/2] tc: action: fix crash caused by incorrect *argv check Stephen Hemminger
2019-07-23 17:54 ` Stephen Hemminger
2019-07-23 19:36 ` Jiri Pirko
2019-07-26 19:00 ` Stephen Hemminger [this message]
2019-07-24 9:07 ` David Laight
2019-07-26 19:47 ` Stephen Hemminger
2019-07-27 8:36 ` Jiri Pirko
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20190726120001.73f0bdb6@hermes.lan \
--to=stephen@networkplumber.org \
--cc=alexanderk@mellanox.com \
--cc=dsahern@gmail.com \
--cc=jiri@resnulli.us \
--cc=mlxsw@mellanox.com \
--cc=netdev@vger.kernel.org \
--cc=sthemmin@microsoft.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.