Linux Device Mapper development
 help / color / mirror / Atom feed
From: Heinz Mauelshagen <heinzm@redhat.com>
To: Mike Snitzer <snitzer@redhat.com>
Cc: dm-devel@redhat.com
Subject: Re: [PATCH v2] dm raid: fix parse_raid_params() variable range issue
Date: Thu, 22 Mar 2018 22:13:48 +0100	[thread overview]
Message-ID: <ac064103-c40b-544a-ef33-e0eaba9a8070@redhat.com> (raw)
In-Reply-To: <20180322194144.GA32294@redhat.com>

On 03/22/2018 08:41 PM, Mike Snitzer wrote:
> On Thu, Mar 22 2018 at  1:21pm -0400,
> Heinz Mauelshagen <heinzm@redhat.com> wrote:
>
>> This v2 addresses Mikulas' point about the variable range and folds in
>> "[PATCH] dm raid: use __within_range() more in parse_raid_params()":
>>
>> parse_raid_parames() compared variable "int value" with
>> INT_MAX to prevent overflow of mddev variables set.
>>
>> Change type to "long long value".
> Can you elaborate on the risk/issue that is being fixed here?

Fix addresses a coverity finding supporting the full,
positive range of the "struct mddev" int members
set here.  I.e. the "int" cast is compared with INT_MAX.

>
> User specifying a value that overflows an int?

No, kstroint() catches that.

>
> (also: see below for inline comment about last hunk)

See below...

>> Whilst on it, use __within_range() throughout and
>> add a sync min/max rate check.
>>
>> Signed-off-by: Heinz Mauelshagen <heinzm@redhat.com>
>> ---
>>   drivers/md/dm-raid.c | 16 +++++++++++-----
>>   1 file changed, 11 insertions(+), 5 deletions(-)
>>
>> diff --git a/drivers/md/dm-raid.c b/drivers/md/dm-raid.c
>> index c1d1034ff7b7..c0e3d2aa9346 100644
>> --- a/drivers/md/dm-raid.c
>> +++ b/drivers/md/dm-raid.c
>> @@ -1141,7 +1141,7 @@ static int validate_raid_redundancy(struct raid_set *rs)
>>   static int parse_raid_params(struct raid_set *rs, struct dm_arg_set *as,
>>   			     unsigned int num_raid_params)
>>   {
>> -	int value, raid10_format = ALGORITHM_RAID10_DEFAULT;
>> +	long long value, raid10_format = ALGORITHM_RAID10_DEFAULT;
>>   	unsigned int raid10_copies = 2;
>>   	unsigned int i, write_mostly = 0;
>>   	unsigned int region_size = 0;
>> @@ -1153,7 +1153,7 @@ static int parse_raid_params(struct raid_set *rs, struct dm_arg_set *as,
>>   	arg = dm_shift_arg(as);
>>   	num_raid_params--; /* Account for chunk_size argument */
>>   
>> -	if (kstrtoint(arg, 10, &value) < 0) {
>> +	if (kstrtoll(arg, 10, &value) < 0) {
>>   		rs->ti->error = "Bad numerical argument given for chunk_size";
>>   		return -EINVAL;
>>   	}
>> @@ -1315,7 +1315,7 @@ static int parse_raid_params(struct raid_set *rs, struct dm_arg_set *as,
>>   		/*
>>   		 * Parameters with number values from here on.
>>   		 */
>> -		if (kstrtoint(arg, 10, &value) < 0) {
>> +		if (kstrtoll(arg, 10, &value) < 0) {
>>   			rs->ti->error = "Bad numerical argument given in raid params";
>>   			return -EINVAL;
>>   		}
>> @@ -1430,7 +1430,7 @@ static int parse_raid_params(struct raid_set *rs, struct dm_arg_set *as,
>>   				rs->ti->error = "Only one min_recovery_rate argument pair allowed";
>>   				return -EINVAL;
>>   			}
>> -			if (value > INT_MAX) {
>> +			if (!__within_range(value, 0, INT_MAX)) {
>>   				rs->ti->error = "min_recovery_rate out of range";
>>   				return -EINVAL;
>>   			}
>> @@ -1440,7 +1440,7 @@ static int parse_raid_params(struct raid_set *rs, struct dm_arg_set *as,
>>   				rs->ti->error = "Only one max_recovery_rate argument pair allowed";
>>   				return -EINVAL;
>>   			}
>> -			if (value > INT_MAX) {
>> +			if (!__within_range(value, 0, INT_MAX)) {
>>   				rs->ti->error = "max_recovery_rate out of range";
>>   				return -EINVAL;
>>   			}
>> @@ -1472,6 +1472,12 @@ static int parse_raid_params(struct raid_set *rs, struct dm_arg_set *as,
>>   		}
>>   	}
>>   
>> +	if (rs->md.sync_speed_max &&
>> +	    rs->md.sync_speed_max < rs->md.sync_speed_min) {
>> +		rs->ti->error = "sync speed max smaller than min";
>> +		return -EINVAL;
>> +	}
>> +
>>   	if (test_bit(__CTR_FLAG_SYNC, &rs->ctr_flags) &&
>>   	    test_bit(__CTR_FLAG_NOSYNC, &rs->ctr_flags)) {
>>   		rs->ti->error = "sync and nosync are mutually exclusive";
>> -- 
>> 2.14.3
>>
> Isn't this last hunk unrelated?

No, once using __within_range to ensure positive values
for sync min/max, this hunk ensures that those are sane
if both are set.

Heinz

>
> --
> dm-devel mailing list
> dm-devel@redhat.com
> https://www.redhat.com/mailman/listinfo/dm-devel

--
dm-devel mailing list
dm-devel@redhat.com
https://www.redhat.com/mailman/listinfo/dm-devel

  reply	other threads:[~2018-03-22 21:13 UTC|newest]

Thread overview: 5+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2018-03-22 17:21 [PATCH v2] dm raid: fix parse_raid_params() variable range issue Heinz Mauelshagen
2018-03-22 19:41 ` Mike Snitzer
2018-03-22 21:13   ` Heinz Mauelshagen [this message]
2018-03-26 18:16     ` Mike Snitzer
2018-03-26 23:23       ` Mike Snitzer

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=ac064103-c40b-544a-ef33-e0eaba9a8070@redhat.com \
    --to=heinzm@redhat.com \
    --cc=dm-devel@redhat.com \
    --cc=snitzer@redhat.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox