Re: [PATCH] 9p bug fix: return non-zero error value in p9_put_data

Previous thread: [Patch] Check hfs_bnode_find return value by Eric Sesterhenn on Tuesday, August 26, 2008 - 10:23 am. (3 messages)

Next thread: Re: [PATCH] serial 8250: tighten test for using backup timer by David Brownell on Tuesday, August 26, 2008 - 10:45 am. (5 messages)
From: Abhishek Kulkarni
Date: Tuesday, August 26, 2008 - 10:30 am

p9_put_data is called by p9_create_twrite which expects it to return a
non-zero value on error. This was the reason why every p9_client_write
was failing. This patch also adds a check for buffer overflow in
p9_put_data.

Signed-off-by: Abhishek Kulkarni <kulkarni@lanl.gov>
---
 net/9p/conv.c |    5 ++++-
 1 files changed, 4 insertions(+), 1 deletions(-)
diff --git a/net/9p/conv.c b/net/9p/conv.c
index 4454720..7f6db15 100644
--- a/net/9p/conv.c
+++ b/net/9p/conv.c
@@ -451,8 +451,11 @@ p9_put_data(struct cbuf *bufp, const char *data,
int count,
 		   unsigned char **pdata)
 {
 	*pdata = buf_alloc(bufp, count);
+	if (buf_check_overflow(bufp))
+		return -EIO;
+
 	memmove(*pdata, data, count);
-	return count;
+	return 0;
 }
 
 static int


Thanks,
 -- Abhishek

--

From: Latchesar Ionkov
Date: Tuesday, August 26, 2008 - 11:53 am

Acked-by: Latchesar Ionkov <lucho@ionkov.net>

--

From: Eric Van Hensbergen
Date: Thursday, August 28, 2008 - 11:10 am

I'm a bit confused about when this is even getting called -- O thought
all writes were following the p9_client_uwrite path?

Also, we do the bufoverflow check in p9_create_write -- so with your
patch aren't we doing this twice?

--

From: Abhishek Kulkarni
Date: Thursday, August 28, 2008 - 11:35 am

Yes, this bug didn't come up to the surface since p9_create_twrite is
not even being called anywhere in v9fs. I tripped over it when using 9p
Yes, but then that makes the "check for error in return value" in
p9_create_twrite useless since memmove is not going to return an error
in any case.

Going with the existing convention however, I think the bufoverflow
check is unnecessary in p9_put_data and so is the check for error on
return.

I'll resubmit a patch.


--

From: Abhishek Kulkarni
Date: Tuesday, September 2, 2008 - 12:04 pm

Resubmitting my previous 9p bug fix patch that removes the bogus return
value in p9_put_data which made every p9_client_write fail. 

Signed-off-by: Abhishek Kulkarni <kulkarni@lanl.gov>
---
 net/9p/conv.c |   12 +++---------
 1 files changed, 3 insertions(+), 9 deletions(-)

diff --git a/net/9p/conv.c b/net/9p/conv.c
index 4454720..08ec35a 100644
--- a/net/9p/conv.c
+++ b/net/9p/conv.c
@@ -446,13 +446,12 @@ p9_put_str(struct cbuf *bufp, char *data, struct
p9_str *str)
        }
 }

-static int
+static void
 p9_put_data(struct cbuf *bufp, const char *data, int count,
                   unsigned char **pdata)
 {
        *pdata = buf_alloc(bufp, count);
        memmove(*pdata, data, count);
-       return count;
 }

 static int
@@ -851,7 +850,7 @@ EXPORT_SYMBOL(p9_create_tread);
 struct p9_fcall *p9_create_twrite(u32 fid, u64 offset, u32 count,
                                      const char *data)
 {
-       int size, err;
+       int size;
        struct p9_fcall *fc;
        struct cbuf buffer;
        struct cbuf *bufp = &buffer;
@@ -865,12 +864,7 @@ struct p9_fcall *p9_create_twrite(u32 fid, u64
offset, u32 count,
        p9_put_int32(bufp, fid, &fc->params.twrite.fid);
        p9_put_int64(bufp, offset, &fc->params.twrite.offset);
        p9_put_int32(bufp, count, &fc->params.twrite.count);
-       err = p9_put_data(bufp, data, count, &fc->params.twrite.data);
-       if (err) {
-               kfree(fc);
-               fc = ERR_PTR(err);
-               goto error;
-       }
+       p9_put_data(bufp, data, count, &fc->params.twrite.data);

        if (buf_check_overflow(bufp)) {
                kfree(fc);
--
1.5.4.3




--

From: Eric Van Hensbergen
Date: Tuesday, September 23, 2008 - 1:33 pm

Hey - first of all, sorry for the long delay on responding to this,
I've just gotten back to my patch queue.


Please include the original description when resubmitting patches --

What happens if buf_alloc returns NULL?

Isn't the right behavior something more along the lines of:

static int
p9_put_data(struct cbuf *bufp, const char *data, int count,
                   unsigned char **pdata)
{
        *pdata = buf_alloc(bufp, count);'
        if(*pdata)
            memmove(*pdata, data, count);
            return 0;
        else
            return ENOMEM;
}

                  -eric
--

Previous thread: [Patch] Check hfs_bnode_find return value by Eric Sesterhenn on Tuesday, August 26, 2008 - 10:23 am. (3 messages)

Next thread: Re: [PATCH] serial 8250: tighten test for using backup timer by David Brownell on Tuesday, August 26, 2008 - 10:45 am. (5 messages)