Linux NFS development
 help / color / mirror / Atom feed
* [PATCH 1/2] NFS:Prevent infinite loop in decode_attr_fs_locations.
@ 2008-10-17 22:52 Dean Hildebrand
  2008-10-17 22:52 ` [PATCH 2/2] NFS: Cleanup decode_attr_fs_locations function Dean Hildebrand
  0 siblings, 1 reply; 8+ messages in thread
From: Dean Hildebrand @ 2008-10-17 22:52 UTC (permalink / raw)
  To: linux-nfs; +Cc: Dean Hildebrand

An infinite loop could occur if n > NFS4_FS_LOCATIONS_MAXENTRIES.
or if m > NFS4_FS_LOCATION_MAXSERVERS.

Signed-off-by: Dean Hildebrand <dhildeb@us.ibm.com>
---
 fs/nfs/nfs4xdr.c |   49 ++++++++++++++++++++++++++++++-------------------
 1 files changed, 30 insertions(+), 19 deletions(-)

diff --git a/fs/nfs/nfs4xdr.c b/fs/nfs/nfs4xdr.c
index b916297..0b4c565 100644
--- a/fs/nfs/nfs4xdr.c
+++ b/fs/nfs/nfs4xdr.c
@@ -2577,14 +2577,31 @@ static int decode_attr_fs_locations(struct xdr_stream *xdr, uint32_t *bitmap, st
 	READ32(n);
 	if (n <= 0)
 		goto out_eio;
+
+	if (n > NFS4_FS_LOCATIONS_MAXENTRIES) {
+		dprintk("\n%s: Using first %u of %d fs locations\n",
+			__func__, NFS4_FS_LOCATIONS_MAXENTRIES, n);
+		n = NFS4_FS_LOCATIONS_MAXENTRIES;
+	}
+
 	res->nlocations = 0;
 	while (res->nlocations < n) {
 		u32 m;
+		unsigned int totalserv, i;
 		struct nfs4_fs_location *loc = &res->locations[res->nlocations];
 
 		READ_BUF(4);
 		READ32(m);
 
+		totalserv = m;
+		if (m >  NFS4_FS_LOCATION_MAXSERVERS) {
+			dprintk("\n%s: Using first %u of %u servers "
+				"returned for location %u\n",
+				__func__, NFS4_FS_LOCATION_MAXSERVERS,
+				m, res->nlocations);
+			m = NFS4_FS_LOCATION_MAXSERVERS;
+		}
+
 		loc->nservers = 0;
 		dprintk("%s: servers ", __func__);
 		while (loc->nservers < m) {
@@ -2593,29 +2610,23 @@ static int decode_attr_fs_locations(struct xdr_stream *xdr, uint32_t *bitmap, st
 			if (unlikely(status != 0))
 				goto out_eio;
 			dprintk("%s ", server->data);
-			if (loc->nservers < NFS4_FS_LOCATION_MAXSERVERS)
-				loc->nservers++;
-			else {
-				unsigned int i;
-				dprintk("%s: using first %u of %u servers "
-					"returned for location %u\n",
-						__func__,
-						NFS4_FS_LOCATION_MAXSERVERS,
-						m, res->nlocations);
-				for (i = loc->nservers; i < m; i++) {
-					unsigned int len;
-					char *data;
-					status = decode_opaque_inline(xdr, &len, &data);
-					if (unlikely(status != 0))
-						goto out_eio;
-				}
-			}
+			loc->nservers++;
 		}
+
+		/* Decode and ignore overflow servers */
+		for (i = loc->nservers; i < totalserv; i++) {
+			unsigned int len;
+			char *data;
+			status = decode_opaque_inline(xdr, &len, &data);
+			if (unlikely(status != 0))
+				goto out_eio;
+		}
+
 		status = decode_pathname(xdr, &loc->rootpath);
 		if (unlikely(status != 0))
 			goto out_eio;
-		if (res->nlocations < NFS4_FS_LOCATIONS_MAXENTRIES)
-			res->nlocations++;
+
+		res->nlocations++;
 	}
 out:
 	dprintk("%s: fs_locations done, error = %d\n", __func__, status);
-- 
1.5.3.3


^ permalink raw reply related	[flat|nested] 8+ messages in thread
* [PATCH 2/2] NFS: Cleanup decode_attr_fs_locations function.
@ 2008-10-28 17:32 Dean Hildebrand
  0 siblings, 0 replies; 8+ messages in thread
From: Dean Hildebrand @ 2008-10-28 17:32 UTC (permalink / raw)
  To: linux-nfs; +Cc: Dean Hildebrand

a) Use correct data types.
b) Use nloc and nserv instead of n and m variable names.
c) Try to clean up formatting of debugging statements.
d) Move while loops to for loops.

Signed-off-by: Dean Hildebrand <dhildeb@us.ibm.com>
---
 fs/nfs/nfs4xdr.c |   40 ++++++++++++++++++----------------------
 1 files changed, 18 insertions(+), 22 deletions(-)

diff --git a/fs/nfs/nfs4xdr.c b/fs/nfs/nfs4xdr.c
index 0b4c565..421609f 100644
--- a/fs/nfs/nfs4xdr.c
+++ b/fs/nfs/nfs4xdr.c
@@ -2560,7 +2560,7 @@ out_eio:
 
 static int decode_attr_fs_locations(struct xdr_stream *xdr, uint32_t *bitmap, struct nfs4_fs_locations *res)
 {
-	int n;
+	u32 nloc;
 	__be32 *p;
 	int status = -EIO;
 
@@ -2574,47 +2574,45 @@ static int decode_attr_fs_locations(struct xdr_stream *xdr, uint32_t *bitmap, st
 	if (unlikely(status != 0))
 		goto out;
 	READ_BUF(4);
-	READ32(n);
-	if (n <= 0)
+	READ32(nloc);
+	if (nloc <= 0)
 		goto out_eio;
 
-	if (n > NFS4_FS_LOCATIONS_MAXENTRIES) {
-		dprintk("\n%s: Using first %u of %d fs locations\n",
-			__func__, NFS4_FS_LOCATIONS_MAXENTRIES, n);
-		n = NFS4_FS_LOCATIONS_MAXENTRIES;
+	if (nloc > NFS4_FS_LOCATIONS_MAXENTRIES) {
+		dprintk("\n%s: Using first %u of %u fs locations\n",
+			__func__, NFS4_FS_LOCATIONS_MAXENTRIES, nloc);
+		nloc = NFS4_FS_LOCATIONS_MAXENTRIES;
 	}
 
-	res->nlocations = 0;
-	while (res->nlocations < n) {
-		u32 m;
-		unsigned int totalserv, i;
+	for (res->nlocations = 0; res->nlocations < nloc; res->nlocations++) {
+		u32 nserv;
+		unsigned int totalserv, j;
 		struct nfs4_fs_location *loc = &res->locations[res->nlocations];
 
 		READ_BUF(4);
-		READ32(m);
+		READ32(nserv);
 
-		totalserv = m;
-		if (m >  NFS4_FS_LOCATION_MAXSERVERS) {
+		totalserv = nserv;
+		if (nserv >  NFS4_FS_LOCATION_MAXSERVERS) {
 			dprintk("\n%s: Using first %u of %u servers "
 				"returned for location %u\n",
 				__func__, NFS4_FS_LOCATION_MAXSERVERS,
-				m, res->nlocations);
-			m = NFS4_FS_LOCATION_MAXSERVERS;
+				nserv, res->nlocations);
+			nserv = NFS4_FS_LOCATION_MAXSERVERS;
 		}
 
-		loc->nservers = 0;
 		dprintk("%s: servers ", __func__);
-		while (loc->nservers < m) {
+		for (loc->nservers = 0; loc->nservers < nserv; loc->nservers++) {
 			struct nfs4_string *server = &loc->servers[loc->nservers];
 			status = decode_opaque_inline(xdr, &server->len, &server->data);
 			if (unlikely(status != 0))
 				goto out_eio;
 			dprintk("%s ", server->data);
-			loc->nservers++;
 		}
+		dprintk("\n");
 
 		/* Decode and ignore overflow servers */
-		for (i = loc->nservers; i < totalserv; i++) {
+		for (j = loc->nservers; j < totalserv; j++) {
 			unsigned int len;
 			char *data;
 			status = decode_opaque_inline(xdr, &len, &data);
@@ -2625,8 +2623,6 @@ static int decode_attr_fs_locations(struct xdr_stream *xdr, uint32_t *bitmap, st
 		status = decode_pathname(xdr, &loc->rootpath);
 		if (unlikely(status != 0))
 			goto out_eio;
-
-		res->nlocations++;
 	}
 out:
 	dprintk("%s: fs_locations done, error = %d\n", __func__, status);
-- 
1.5.4.5


^ permalink raw reply related	[flat|nested] 8+ messages in thread
* [PATCH 1/2] NFS:Prevent infinite loop in decode_attr_fs_locations.
@ 2008-10-17 18:17 Dean Hildebrand
  2008-10-17 18:17 ` [PATCH 2/2] NFS: Cleanup decode_attr_fs_locations function Dean Hildebrand
  0 siblings, 1 reply; 8+ messages in thread
From: Dean Hildebrand @ 2008-10-17 18:17 UTC (permalink / raw)
  To: linux-nfs; +Cc: Dean Hildebrand

An infinite loop could occur if n > NFS4_FS_LOCATIONS_MAXENTRIES.

Signed-off-by: Dean Hildebrand <dhildeb@us.ibm.com>
---
 fs/nfs/nfs4xdr.c |   14 ++++++++++++--
 1 files changed, 12 insertions(+), 2 deletions(-)

diff --git a/fs/nfs/nfs4xdr.c b/fs/nfs/nfs4xdr.c
index b916297..5e59481 100644
--- a/fs/nfs/nfs4xdr.c
+++ b/fs/nfs/nfs4xdr.c
@@ -2577,6 +2577,16 @@ static int decode_attr_fs_locations(struct xdr_stream *xdr, uint32_t *bitmap, st
 	READ32(n);
 	if (n <= 0)
 		goto out_eio;
+
+	if (n > NFS4_FS_LOCATIONS_MAXENTRIES) {
+		dprintk("%s: using first %u of %d fs locations\n",
+			__func__, NFS4_FS_LOCATIONS_MAXENTRIES, n);
+		n = NFS4_FS_LOCATIONS_MAXENTRIES;
+	} else {
+		dprintk("%s: using %d fs locations\n",
+			__func__, n);
+	}
+
 	res->nlocations = 0;
 	while (res->nlocations < n) {
 		u32 m;
@@ -2614,8 +2624,8 @@ static int decode_attr_fs_locations(struct xdr_stream *xdr, uint32_t *bitmap, st
 		status = decode_pathname(xdr, &loc->rootpath);
 		if (unlikely(status != 0))
 			goto out_eio;
-		if (res->nlocations < NFS4_FS_LOCATIONS_MAXENTRIES)
-			res->nlocations++;
+
+		res->nlocations++;
 	}
 out:
 	dprintk("%s: fs_locations done, error = %d\n", __func__, status);
-- 
1.5.3.3


^ permalink raw reply related	[flat|nested] 8+ messages in thread

end of thread, other threads:[~2008-10-28 17:32 UTC | newest]

Thread overview: 8+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2008-10-17 22:52 [PATCH 1/2] NFS:Prevent infinite loop in decode_attr_fs_locations Dean Hildebrand
2008-10-17 22:52 ` [PATCH 2/2] NFS: Cleanup decode_attr_fs_locations function Dean Hildebrand
2008-10-19 10:38   ` Benny Halevy
2008-10-24 17:09     ` Dean Hildebrand
  -- strict thread matches above, loose matches on Subject: below --
2008-10-28 17:32 Dean Hildebrand
2008-10-17 18:17 [PATCH 1/2] NFS:Prevent infinite loop in decode_attr_fs_locations Dean Hildebrand
2008-10-17 18:17 ` [PATCH 2/2] NFS: Cleanup decode_attr_fs_locations function Dean Hildebrand
2008-10-17 18:55   ` J. Bruce Fields
2008-10-17 22:01     ` Dean Hildebrand

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox