CEPH filesystem development
 help / color / mirror / Atom feed
From: scan-admin@coverity.com
To: ceph-devel@vger.kernel.org
Subject: New Defects reported by Coverity Scan for ceph
Date: Fri, 17 Oct 2014 06:27:56 -0700	[thread overview]
Message-ID: <5441195cf2b6c_26b7b5b314336ac@scan.coverity.com.mail> (raw)


Hi,

Please find the latest report on new defect(s) introduced to ceph found with Coverity Scan.

4 new defect(s) introduced to ceph found with Coverity Scan.


New defect(s) Reported-by: Coverity Scan
Showing 4 of 4 defect(s)


** CID 1247718:  Explicit null dereferenced  (FORWARD_NULL)
/mds/Server.cc: 3184 in Server::handle_client_file_setlock(std::tr1::shared_ptr<MDRequestImpl> &)()
/mds/Server.cc: 3184 in Server::handle_client_file_setlock(std::tr1::shared_ptr<MDRequestImpl> &)()
/mds/Server.cc: 3184 in Server::handle_client_file_setlock(std::tr1::shared_ptr<MDRequestImpl> &)()
/mds/Server.cc: 3184 in Server::handle_client_file_setlock(std::tr1::shared_ptr<MDRequestImpl> &)()

** CID 1247719:  Unintentional integer overflow  (OVERFLOW_BEFORE_WIDEN)
/osdc/Striper.cc: 221 in Striper::get_num_objects(const ceph_file_layout &, unsigned long)()

** CID 1247720:  Unintentional integer overflow  (OVERFLOW_BEFORE_WIDEN)
/osdc/Striper.cc: 225 in Striper::get_num_objects(const ceph_file_layout &, unsigned long)()

** CID 1247721:  Uncaught exception  (UNCAUGHT_EXCEPT)
/rbd.cc: 2071 in main()
/rbd.cc: 2071 in main()


________________________________________________________________________________________________________
*** CID 1247718:  Explicit null dereferenced  (FORWARD_NULL)
/mds/Server.cc: 3184 in Server::handle_client_file_setlock(std::tr1::shared_ptr<MDRequestImpl> &)()
3178       set_lock.pid = req->head.args.filelock_change.pid;
3179       set_lock.type = req->head.args.filelock_change.type;
3180       bool will_wait = req->head.args.filelock_change.wait;
3181     
3182       dout(10) << "handle_client_file_setlock: " << set_lock << dendl;
3183     
>>>     CID 1247718:  Explicit null dereferenced  (FORWARD_NULL)
>>>     Assigning: "lock_state" = "NULL".
3184       ceph_lock_state_t *lock_state = NULL;
3185       bool interrupt = false;
3186     
3187       // get the appropriate lock state
3188       switch (req->head.args.filelock_change.rule) {
3189       case CEPH_LOCK_FLOCK_INTR:
/mds/Server.cc: 3184 in Server::handle_client_file_setlock(std::tr1::shared_ptr<MDRequestImpl> &)()
3178       set_lock.pid = req->head.args.filelock_change.pid;
3179       set_lock.type = req->head.args.filelock_change.type;
3180       bool will_wait = req->head.args.filelock_change.wait;
3181     
3182       dout(10) << "handle_client_file_setlock: " << set_lock << dendl;
3183     
>>>     CID 1247718:  Explicit null dereferenced  (FORWARD_NULL)
>>>     Assigning: "lock_state" = "NULL".
3184       ceph_lock_state_t *lock_state = NULL;
3185       bool interrupt = false;
3186     
3187       // get the appropriate lock state
3188       switch (req->head.args.filelock_change.rule) {
3189       case CEPH_LOCK_FLOCK_INTR:
/mds/Server.cc: 3184 in Server::handle_client_file_setlock(std::tr1::shared_ptr<MDRequestImpl> &)()
3178       set_lock.pid = req->head.args.filelock_change.pid;
3179       set_lock.type = req->head.args.filelock_change.type;
3180       bool will_wait = req->head.args.filelock_change.wait;
3181     
3182       dout(10) << "handle_client_file_setlock: " << set_lock << dendl;
3183     
>>>     CID 1247718:  Explicit null dereferenced  (FORWARD_NULL)
>>>     Assigning: "lock_state" = "NULL".
3184       ceph_lock_state_t *lock_state = NULL;
3185       bool interrupt = false;
3186     
3187       // get the appropriate lock state
3188       switch (req->head.args.filelock_change.rule) {
3189       case CEPH_LOCK_FLOCK_INTR:
/mds/Server.cc: 3184 in Server::handle_client_file_setlock(std::tr1::shared_ptr<MDRequestImpl> &)()
3178       set_lock.pid = req->head.args.filelock_change.pid;
3179       set_lock.type = req->head.args.filelock_change.type;
3180       bool will_wait = req->head.args.filelock_change.wait;
3181     
3182       dout(10) << "handle_client_file_setlock: " << set_lock << dendl;
3183     
>>>     CID 1247718:  Explicit null dereferenced  (FORWARD_NULL)
>>>     Assigning: "lock_state" = "NULL".
3184       ceph_lock_state_t *lock_state = NULL;
3185       bool interrupt = false;
3186     
3187       // get the appropriate lock state
3188       switch (req->head.args.filelock_change.rule) {
3189       case CEPH_LOCK_FLOCK_INTR:

________________________________________________________________________________________________________
*** CID 1247719:  Unintentional integer overflow  (OVERFLOW_BEFORE_WIDEN)
/osdc/Striper.cc: 221 in Striper::get_num_objects(const ceph_file_layout &, unsigned long)()
215     }
216     uint64_t Striper::get_num_objects(const ceph_file_layout& layout, uint64_t size)
217     {
218       __u32 object_size = layout.fl_object_size;
219       __u32 stripe_unit = layout.fl_stripe_unit;
220       __u32 stripe_count = layout.fl_stripe_count;
>>>     CID 1247719:  Unintentional integer overflow  (OVERFLOW_BEFORE_WIDEN)
>>>     Potentially overflowing expression "stripe_count * object_size" with type "unsigned int" (32 bits, unsigned) is evaluated using 32-bit arithmetic before being used in a context which expects an expression of type "uint64_t" (64 bits, unsigned). To avoid overflow, cast either operand to "uint64_t" before performing the multiplication.
221       uint64_t period = stripe_count * object_size;
222       uint64_t num_periods = (size + period - 1) / period;
223       uint64_t remainder_bytes = size % period;
224       uint64_t remainder_objs = 0;
225       if ((remainder_bytes > 0) && (remainder_bytes < stripe_count * stripe_unit))
226         remainder_objs = stripe_count - ((remainder_bytes + stripe_unit - 1) / stripe_unit);

________________________________________________________________________________________________________
*** CID 1247720:  Unintentional integer overflow  (OVERFLOW_BEFORE_WIDEN)
/osdc/Striper.cc: 225 in Striper::get_num_objects(const ceph_file_layout &, unsigned long)()
219       __u32 stripe_unit = layout.fl_stripe_unit;
220       __u32 stripe_count = layout.fl_stripe_count;
221       uint64_t period = stripe_count * object_size;
222       uint64_t num_periods = (size + period - 1) / period;
223       uint64_t remainder_bytes = size % period;
224       uint64_t remainder_objs = 0;
>>>     CID 1247720:  Unintentional integer overflow  (OVERFLOW_BEFORE_WIDEN)
>>>     Potentially overflowing expression "stripe_count * stripe_unit" with type "unsigned int" (32 bits, unsigned) is evaluated using 32-bit arithmetic before being used in a context which expects an expression of type "uint64_t" (64 bits, unsigned). To avoid overflow, cast either operand to "uint64_t" before performing the multiplication.
225       if ((remainder_bytes > 0) && (remainder_bytes < stripe_count * stripe_unit))
226         remainder_objs = stripe_count - ((remainder_bytes + stripe_unit - 1) / stripe_unit);
227       return num_periods * stripe_count - remainder_objs;
228     }
229     
230     // StripedReadResult

________________________________________________________________________________________________________
*** CID 1247721:  Uncaught exception  (UNCAUGHT_EXCEPT)
/rbd.cc: 2071 in main()
2065         return false;
2066       return true;
2067     }
2068     
2069     bool size_set;
2070     
>>>     CID 1247721:  Uncaught exception  (UNCAUGHT_EXCEPT)
>>>     In function "main(int, char const **)" an exception of type "ceph::buffer::end_of_buffer" is thrown and never caught.
2071     int main(int argc, const char **argv)
2072     {
2073       librados::Rados rados;
2074       librbd::RBD rbd;
2075       librados::IoCtx io_ctx, dest_io_ctx;
2076       librbd::Image image;
/rbd.cc: 2071 in main()
2065         return false;
2066       return true;
2067     }
2068     
2069     bool size_set;
2070     
>>>     CID 1247721:  Uncaught exception  (UNCAUGHT_EXCEPT)
>>>     In function "main(int, char const **)" an exception of type "ceph::buffer::end_of_buffer" is thrown and never caught.
2071     int main(int argc, const char **argv)
2072     {
2073       librados::Rados rados;
2074       librbd::RBD rbd;
2075       librados::IoCtx io_ctx, dest_io_ctx;
2076       librbd::Image image;


________________________________________________________________________________________________________
To view the defects in Coverity Scan visit, http://scan.coverity.com/projects/25?tab=overview

To unsubscribe from the email notification for new defects, http://scan5.coverity.com/cgi-bin/unsubscribe.py




             reply	other threads:[~2014-10-17 13:27 UTC|newest]

Thread overview: 124+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2014-10-17 13:27 scan-admin [this message]
  -- strict thread matches above, loose matches on Subject: below --
2022-08-20 12:22 New Defects reported by Coverity Scan for ceph scan-admin
2022-08-20 13:17 ` Jeff Layton
2022-08-22  3:54   ` Brad Hubbard
2022-08-23 12:52     ` Jeff Layton
2018-01-04  3:32 scan-admin
2017-12-28  1:57 scan-admin
2017-12-21  1:54 scan-admin
2017-12-21  3:34 ` Jos Collin
2017-12-21  4:03   ` Brad Hubbard
2017-12-14  6:49 scan-admin
2017-12-01  2:25 scan-admin
2017-11-23  0:19 scan-admin
2017-11-16 11:35 scan-admin
2017-11-09 11:36 scan-admin
2017-11-02  2:11 scan-admin
2017-10-27  0:31 scan-admin
2017-10-19  3:54 scan-admin
2017-10-12  5:54 scan-admin
2017-10-05  5:08 scan-admin
2017-09-28  5:09 scan-admin
2017-09-21  6:44 scan-admin
2017-09-14  7:19 scan-admin
2017-09-07  5:08 scan-admin
2017-08-31  6:39 scan-admin
2017-08-24 23:32 scan-admin
2017-08-17  3:29 scan-admin
2017-08-10  3:50 scan-admin
2017-08-03  4:57 scan-admin
2017-07-27  3:50 scan-admin
2017-07-28 18:42 ` Gregory Farnum
2017-07-28 22:22   ` Brad Hubbard
2017-07-20  4:08 scan-admin
2017-07-13  5:11 scan-admin
2017-07-06  5:03 scan-admin
2017-06-29  4:08 scan-admin
2017-06-22  4:27 scan-admin
2017-06-15  9:50 scan-admin
2017-06-11 23:46 scan-admin
2017-06-01  4:33 scan-admin
2017-05-25  6:22 scan-admin
2017-05-18  1:44 scan-admin
2017-05-11  5:32 scan-admin
2017-05-04  2:45 scan-admin
2017-04-27  2:22 scan-admin
2017-04-20  5:34 scan-admin
2017-04-13  6:25 scan-admin
2017-04-06  9:40 scan-admin
2017-03-31  1:25 scan-admin
2017-03-23  7:58 scan-admin
2017-03-16  7:37 scan-admin
2017-03-09  6:12 scan-admin
2017-03-02  7:44 scan-admin
2017-02-23  9:09 scan-admin
2017-02-17  2:29 scan-admin
     [not found] ` <CAJE9aOMoxWjhq=g+25hfhMhxSCnHAOwAyNhXvkxS1wwBEd3j+A@mail.gmail.com>
2017-02-17  5:19   ` kefu chai
2017-02-05 10:08 scan-admin
2017-01-27 13:22 scan-admin
2017-01-17  3:01 scan-admin
2017-01-09 10:05 scan-admin
2016-12-30  8:33 scan-admin
2016-12-23  9:16 scan-admin
2016-12-16  8:54 scan-admin
2016-12-09 11:29 scan-admin
2016-12-02 11:08 scan-admin
2016-11-25  7:55 scan-admin
2016-03-19 17:58 scan-admin
2016-03-13 17:40 scan-admin
2016-03-12 18:04 scan-admin
2016-03-05 17:55 scan-admin
2016-03-07 20:59 ` Gregory Farnum
2016-02-27 18:07 scan-admin
2016-02-20 18:26 scan-admin
2016-02-18 20:32 scan-admin
2016-02-13 17:47 scan-admin
2016-02-11 17:57 scan-admin
2016-02-11 22:01 ` Gregory Farnum
2016-02-12 16:36   ` Adam C. Emerson
2016-02-04 20:39 scan-admin
2016-02-03 20:40 scan-admin
2015-05-02 14:37 scan-admin
2015-01-21  1:41 scan-admin
2015-01-16 14:39 scan-admin
2015-01-16 15:17 ` Gregory Farnum
2015-01-16 16:00   ` John Spray
2015-01-16 16:08   ` Sage Weil
     [not found] <54b528bef1f63_1b74f3532c63410@scan.coverity.com.mail>
2015-01-13 14:34 ` Sage Weil
2015-01-13 14:16 scan-admin
2015-01-10 14:36 scan-admin
2015-01-10 15:48 ` Haomai Wang
2015-01-09 14:30 scan-admin
2015-01-09 15:26 ` Sage Weil
2015-01-09 15:32   ` Danny Al-Gaaf
2015-01-04 14:14 scan-admin
2014-12-27 14:13 scan-admin
2014-12-28  6:03 ` Sage Weil
2014-12-26 14:19 scan-admin
2014-12-23 14:37 scan-admin
2014-12-21 14:13 scan-admin
2014-12-18 14:19 scan-admin
2014-12-14 14:17 scan-admin
2014-12-07 20:36 scan-admin
2014-12-05 14:11 scan-admin
2014-12-02 14:09 scan-admin
2014-11-25 14:09 scan-admin
2014-11-23 14:08 scan-admin
2014-11-20 14:20 scan-admin
2014-11-14 14:21 scan-admin
2014-11-13 14:21 scan-admin
2014-11-11 20:40 scan-admin
2014-11-09 14:12 scan-admin
2014-10-30 13:19 scan-admin
2014-10-30 16:08 ` Sage Weil
2014-10-28 13:16 scan-admin
2014-10-28 18:26 ` Danny Al-Gaaf
2014-10-26 13:17 scan-admin
2014-10-24 17:55 scan-admin
2014-10-24 17:59 ` Sage Weil
2014-10-09 13:23 scan-admin
2014-10-02 13:21 scan-admin
2014-09-25 13:18 scan-admin
2014-09-16 21:40 scan-admin
2014-08-16 21:31 scan-admin
2014-08-09 15:30 scan-admin

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=5441195cf2b6c_26b7b5b314336ac@scan.coverity.com.mail \
    --to=scan-admin@coverity.com \
    --cc=ceph-devel@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox