From: Pengpeng Hou <pengpeng@iscas.ac.cn>
To: dev@dpdk.org
Cc: Praveen Shetty <praveen.shetty@intel.com>, pengpeng@iscas.ac.cn
Subject: [PATCH 2/2] net/cpfl: validate fieldvector offsets before copying keys
Date: Sat, 21 Mar 2026 10:16:34 +0800 [thread overview]
Message-ID: <20260321021634.96514-1-pengpeng@iscas.ac.cn> (raw)
The CPFL JSON parser accepts fieldvector offsets and SEM key sizes straight from the input description. Reject offsets that would write past the 64-byte SEM fieldvector storage and reject key sizes that would later overread the fixed source buffer or overflow the destination key buffer.
Signed-off-by: Pengpeng Hou <pengpeng@iscas.ac.cn>
---
drivers/net/intel/cpfl/cpfl_flow_engine_fxp.c | 6 ++++++
drivers/net/intel/cpfl/cpfl_flow_parser.c | 12 ++++++++++++
2 files changed, 18 insertions(+)
diff --git a/drivers/net/intel/cpfl/cpfl_flow_engine_fxp.c b/drivers/net/intel/cpfl/cpfl_flow_engine_fxp.c
index 361827c..d0bd909 100644
--- a/drivers/net/intel/cpfl/cpfl_flow_engine_fxp.c
+++ b/drivers/net/intel/cpfl/cpfl_flow_engine_fxp.c
@@ -173,6 +173,12 @@ cpfl_fxp_parse_pattern(const struct cpfl_flow_pr_action *pr_action,
if (pr_action->type == CPFL_JS_PR_ACTION_TYPE_SEM) {
struct cpfl_rule_info *rinfo = &rim->rules[i];
+ if (pr_action->sem.keysize > sizeof(pr_action->sem.cpfl_flow_pr_fv) ||
+ pr_action->sem.keysize > sizeof(rinfo->sem.key)) {
+ PMD_DRV_LOG(ERR, "Invalid SEM key size.");
+ return false;
+ }
+
rinfo->type = CPFL_RULE_TYPE_SEM;
rinfo->sem.prof_id = pr_action->sem.prof;
rinfo->sem.sub_prof_id = pr_action->sem.subprof;
diff --git a/drivers/net/intel/cpfl/cpfl_flow_parser.c b/drivers/net/intel/cpfl/cpfl_flow_parser.c
index e7deb61..7fb2e7e 100644
--- a/drivers/net/intel/cpfl/cpfl_flow_parser.c
+++ b/drivers/net/intel/cpfl/cpfl_flow_parser.c
@@ -323,6 +323,10 @@ cpfl_flow_js_pattern_act_fv_proto(json_t *ob_value, struct cpfl_flow_js_fv *js_f
PMD_DRV_LOG(ERR, "Can not parse 'offset'.");
return -EINVAL;
}
+ if (offset >= CPFL_JS_SEM_FV_KEY_NUM_MAX / 2) {
+ PMD_DRV_LOG(ERR, "The 'offset' is too large.");
+ return -EINVAL;
+ }
ret = cpfl_json_t_to_uint16(ob_value, "mask", &mask);
if (ret < 0) {
PMD_DRV_LOG(ERR, "Can not parse 'mask'.");
@@ -391,6 +395,10 @@ cpfl_flow_js_pattern_act_fv(json_t *ob_fvs, struct cpfl_flow_js_pr_action *js_ac
PMD_DRV_LOG(ERR, "Can not parse 'offset'.");
goto err;
}
+ if (offset >= CPFL_JS_SEM_FV_KEY_NUM_MAX / 2) {
+ PMD_DRV_LOG(ERR, "The 'offset' is too large.");
+ goto err;
+ }
js_fv->offset = offset;
type = cpfl_json_t_to_string(object, "type");
@@ -454,6 +462,10 @@ cpfl_flow_js_pattern_per_act(json_t *ob_per_act, struct cpfl_flow_js_pr_action *
PMD_DRV_LOG(ERR, "Can not parse 'keysize'.");
return -EINVAL;
}
+ if (js_act->sem.keysize > sizeof(js_act->sem.cpfl_flow_pr_fv)) {
+ PMD_DRV_LOG(ERR, "The 'keysize' is too large.");
+ return -EINVAL;
+ }
ob_fvs = json_object_get(ob_sem, "fieldvectors");
ret = cpfl_flow_js_pattern_act_fv(ob_fvs, js_act);
if (ret < 0)
--
2.50.1 (Apple Git-155)
next reply other threads:[~2026-03-23 8:19 UTC|newest]
Thread overview: 2+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-03-21 2:16 Pengpeng Hou [this message]
2026-08-16 22:33 ` [PATCH 2/2] net/cpfl: validate fieldvector offsets before copying keys Stephen Hemminger
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260321021634.96514-1-pengpeng@iscas.ac.cn \
--to=pengpeng@iscas.ac.cn \
--cc=dev@dpdk.org \
--cc=praveen.shetty@intel.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox