From: Hangbin Liu <hangbin.liu@linux.dev>
To: sashiko-reviews@lists.linux.dev
Cc: netdev@vger.kernel.org
Subject: Re: [PATCH net-next 2/6] tools: ynl: convert enum selector to string for sub-message parsing
Date: Fri, 18 Sep 2026 17:29:12 +0800 [thread overview]
Message-ID: <aq0EaDMtiQehDGlt@fedora> (raw)
In-Reply-To: <20260918063657.4D10F1F00899@smtp.kernel.org>
On Fri, Sep 18, 2026 at 06:36:56AM +0000, sashiko-bot@kernel.org wrote:
> Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
> - [High] ynl: NULL pointer dereference in generated sub-message parser
> --
>
> commit fe174a522fe7b9577c0684fb882e6edfa773326f
> Author: Hangbin Liu <liuhangbin@kylinos.cn>
>
> tools: ynl: convert enum selector to string for sub-message parsing
>
> YNL sub-message parsing expects a string selector for strcmp(). So for
> non-external enum selectors, convert the integer value to its string form
> via the family's {enum}_str() helper. This enables correct decoding of
> sub-messages keyed by enum values.
>
> > diff --git a/tools/net/ynl/pyynl/ynl_gen_c.py b/tools/net/ynl/pyynl/ynl_gen_c.py
> > index 2b3483db1b60c..45bd7bc834b49 100755
> > --- a/tools/net/ynl/pyynl/ynl_gen_c.py
> > +++ b/tools/net/ynl/pyynl/ynl_gen_c.py
> > @@ -951,9 +951,17 @@ class TypeSubMessage(TypeNest):
> > sel_var = f"_sel_{sel}"
> > else:
> > sel_var = f"{var}->{sel}"
> > +
> > + parse_sel = sel_var
> > + if not self.selector.is_external() and self.selector.attr and \
> > + "enum" in self.selector.attr.attr:
> > + enum_name = self.selector.attr.attr["enum"]
> > + str_fn = c_lower(self.family.ident_name + "-" + enum_name) + "_str"
> > + parse_sel = f"{str_fn}({sel_var})"
> > +
> > get_lines = [f'if (!{sel_var})',
> > f'return ynl_submsg_failed(yarg, "{self.name}", "{selector}");',
> > - f"if ({self.nested_render_name}_parse(&parg, {sel_var}, attr))",
> > + f"if ({self.nested_render_name}_parse(&parg, {parse_sel}, attr))",
>
> [Severity: High]
> Can this generated code cause a null pointer dereference in the user-space
> client when it communicates with a newer kernel?
>
> The generated code checks if (!sel_var) first, which only catches a 0 value.
> However, if a non-zero unknown enum value is received, the auto-generated
> {enum}_str(sel_var) helper returns a null pointer.
Thanks, I will add a var to get the string first. And then check the new
parse_sel via 'if (!{parse_sel})'.
Hangbin
next prev parent reply other threads:[~2026-09-18 9:29 UTC|newest]
Thread overview: 19+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-17 6:35 [PATCH net-next 0/6] netlink: add lwtunnel encap sub-message support to rt-route Hangbin Liu
2026-09-17 6:35 ` [PATCH net-next 1/6] net: lwtunnel: change encap fill order Hangbin Liu
2026-09-21 6:38 ` netdev-bot+sashiko
2026-09-17 6:35 ` [PATCH net-next 2/6] tools: ynl: convert enum selector to string for sub-message parsing Hangbin Liu
[not found] ` <20260918063657.4D10F1F00899@smtp.kernel.org>
2026-09-18 9:29 ` Hangbin Liu [this message]
2026-09-21 6:38 ` netdev-bot+sashiko
2026-09-17 6:35 ` [PATCH net-next 3/6] netlink: specs: rt-route: add lwtunnel encap sub-message support Hangbin Liu
[not found] ` <20260918063656.953941F00898@smtp.kernel.org>
2026-09-18 7:51 ` Hangbin Liu
2026-09-21 6:38 ` netdev-bot+sashiko
2026-09-17 6:35 ` [PATCH net-next 4/6] netlink: specs: rt-route: describe lwtunnel IP options Hangbin Liu
[not found] ` <20260918063658.80E4F1F000FF@smtp.kernel.org>
2026-09-18 8:02 ` Hangbin Liu
2026-09-21 6:38 ` netdev-bot+sashiko
2026-09-21 9:26 ` Hangbin Liu
2026-09-17 6:35 ` [PATCH net-next 5/6] netlink: specs: rt-route: describe lwt BPF program options Hangbin Liu
[not found] ` <20260918063655.EA1DC1F00893@smtp.kernel.org>
2026-09-18 7:32 ` Hangbin Liu
2026-09-21 6:38 ` netdev-bot+sashiko
2026-09-21 9:46 ` Hangbin Liu
2026-09-17 6:35 ` [PATCH net-next 6/6] netlink: specs: rt-route: describe seg6-local actions, counters and flavors Hangbin Liu
2026-09-21 6:38 ` netdev-bot+sashiko
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=aq0EaDMtiQehDGlt@fedora \
--to=hangbin.liu@linux.dev \
--cc=netdev@vger.kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox