From: sashiko-bot@kernel.org
To: "Hangbin Liu" <hangbin.liu@linux.dev>
Cc: bpf@vger.kernel.org
Subject: Re: [PATCH net-next 2/6] tools: ynl: convert enum selector to string for sub-message parsing
Date: Fri, 18 Sep 2026 06:36:56 +0000 [thread overview]
Message-ID: <20260918063657.4D10F1F00899@smtp.kernel.org> (raw)
In-Reply-To: <20260917-ynl_rt_encap-v1-2-fbbe6e680571@kylinos.cn>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] ynl: NULL pointer dereference in generated sub-message parser
--
commit fe174a522fe7b9577c0684fb882e6edfa773326f
Author: Hangbin Liu <liuhangbin@kylinos.cn>
tools: ynl: convert enum selector to string for sub-message parsing
YNL sub-message parsing expects a string selector for strcmp(). So for
non-external enum selectors, convert the integer value to its string form
via the family's {enum}_str() helper. This enables correct decoding of
sub-messages keyed by enum values.
> diff --git a/tools/net/ynl/pyynl/ynl_gen_c.py b/tools/net/ynl/pyynl/ynl_gen_c.py
> index 2b3483db1b60c..45bd7bc834b49 100755
> --- a/tools/net/ynl/pyynl/ynl_gen_c.py
> +++ b/tools/net/ynl/pyynl/ynl_gen_c.py
> @@ -951,9 +951,17 @@ class TypeSubMessage(TypeNest):
> sel_var = f"_sel_{sel}"
> else:
> sel_var = f"{var}->{sel}"
> +
> + parse_sel = sel_var
> + if not self.selector.is_external() and self.selector.attr and \
> + "enum" in self.selector.attr.attr:
> + enum_name = self.selector.attr.attr["enum"]
> + str_fn = c_lower(self.family.ident_name + "-" + enum_name) + "_str"
> + parse_sel = f"{str_fn}({sel_var})"
> +
> get_lines = [f'if (!{sel_var})',
> f'return ynl_submsg_failed(yarg, "{self.name}", "{selector}");',
> - f"if ({self.nested_render_name}_parse(&parg, {sel_var}, attr))",
> + f"if ({self.nested_render_name}_parse(&parg, {parse_sel}, attr))",
[Severity: High]
Can this generated code cause a null pointer dereference in the user-space
client when it communicates with a newer kernel?
The generated code checks if (!sel_var) first, which only catches a 0 value.
However, if a non-zero unknown enum value is received, the auto-generated
{enum}_str(sel_var) helper returns a null pointer.
This null string is then passed into the sub-message's _parse() function as
the sel argument, where the generated code unconditionally evaluates it:
if (!strcmp(sel, "name")) {
...
}
Passing a null pointer to strcmp() will cause a segmentation fault in the
client when processing unrecognized enum selectors.
> "return YNL_PARSE_CB_ERROR;"]
> init_lines = [f"parg.rsp_policy = &{self.nested_render_name}_nest;",
> f"parg.data = &{var}->{self.c_name};"]
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260917-ynl_rt_encap-v1-0-fbbe6e680571@kylinos.cn?part=2
next prev parent reply other threads:[~2026-09-18 6:36 UTC|newest]
Thread overview: 20+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-17 6:35 [PATCH net-next 0/6] netlink: add lwtunnel encap sub-message support to rt-route Hangbin Liu
2026-09-17 6:35 ` [PATCH net-next 1/6] net: lwtunnel: change encap fill order Hangbin Liu
2026-09-18 6:36 ` sashiko-bot
2026-09-21 6:38 ` netdev-bot+sashiko
2026-09-17 6:35 ` [PATCH net-next 2/6] tools: ynl: convert enum selector to string for sub-message parsing Hangbin Liu
2026-09-18 6:36 ` sashiko-bot [this message]
2026-09-21 6:38 ` netdev-bot+sashiko
2026-09-17 6:35 ` [PATCH net-next 3/6] netlink: specs: rt-route: add lwtunnel encap sub-message support Hangbin Liu
2026-09-18 6:36 ` sashiko-bot
2026-09-21 6:38 ` netdev-bot+sashiko
2026-09-17 6:35 ` [PATCH net-next 4/6] netlink: specs: rt-route: describe lwtunnel IP options Hangbin Liu
2026-09-18 6:36 ` sashiko-bot
2026-09-21 6:38 ` netdev-bot+sashiko
2026-09-21 9:26 ` Hangbin Liu
2026-09-17 6:35 ` [PATCH net-next 5/6] netlink: specs: rt-route: describe lwt BPF program options Hangbin Liu
2026-09-18 6:36 ` sashiko-bot
2026-09-21 6:38 ` netdev-bot+sashiko
2026-09-21 9:46 ` Hangbin Liu
2026-09-17 6:35 ` [PATCH net-next 6/6] netlink: specs: rt-route: describe seg6-local actions, counters and flavors Hangbin Liu
2026-09-21 6:38 ` netdev-bot+sashiko
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260918063657.4D10F1F00899@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=bpf@vger.kernel.org \
--cc=hangbin.liu@linux.dev \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox