From mboxrd@z Thu Jan 1 00:00:00 1970 From: Ferruh Yigit Subject: Re: [RFC 1/5] bus/pci: fix allocation of pci device path Date: Thu, 22 Nov 2018 23:52:38 +0000 Message-ID: References: <20181106214901.1392-1-stephen@networkplumber.org> <20181106214901.1392-2-stephen@networkplumber.org> Mime-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 7bit To: Stephen Hemminger , dev@dpdk.org Return-path: Received: from mga06.intel.com (mga06.intel.com [134.134.136.31]) by dpdk.org (Postfix) with ESMTP id 30B2E1B477 for ; Fri, 23 Nov 2018 00:52:41 +0100 (CET) In-Reply-To: <20181106214901.1392-2-stephen@networkplumber.org> Content-Language: en-US List-Id: DPDK patches and discussions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: dev-bounces@dpdk.org Sender: "dev" On 11/6/2018 9:48 PM, Stephen Hemminger wrote: > The pci_resource_by_index called strlen() on uninitialized > memory which would lead to the wrong size of memory allocated > for the path portion of the resource map. This would either cause > excessively large allocation, or worse memory corruption. Yes this may corrupt memory, I wonder how nobody hit this. I am for including the fix for the release. > > Coverity Issue: 300868 > Fixes: ea9d56226e72 ("pci: introduce function to map uio resource by index") > Signed-off-by: Stephen Hemminger > --- > drivers/bus/pci/linux/pci_uio.c | 29 ++++++++++++++--------------- > 1 file changed, 14 insertions(+), 15 deletions(-) > > diff --git a/drivers/bus/pci/linux/pci_uio.c b/drivers/bus/pci/linux/pci_uio.c > index a7c14421aa79..112ac51dddcc 100644 > --- a/drivers/bus/pci/linux/pci_uio.c > +++ b/drivers/bus/pci/linux/pci_uio.c > @@ -295,14 +295,6 @@ pci_uio_map_resource_by_index(struct rte_pci_device *dev, int res_idx, > loc = &dev->addr; > maps = uio_res->maps; > > - /* allocate memory to keep path */ > - maps[map_idx].path = rte_malloc(NULL, strlen(devname) + 1, 0); > - if (maps[map_idx].path == NULL) { > - RTE_LOG(ERR, EAL, "Cannot allocate memory for path: %s\n", > - strerror(errno)); > - return -1; > - } What about simply: - maps[map_idx].path = rte_malloc(NULL, strlen(devname) + 1, 0); + maps[map_idx].path = rte_malloc(NULL, sizeof(devname) + 1, 0);