From: Rasmus Villemoes <linux@rasmusvillemoes.dk>
To: Andrew Morton <akpm@linux-foundation.org>
Cc: Rasmus Villemoes <linux@rasmusvillemoes.dk>,
linux-kernel@vger.kernel.org
Subject: [PATCH 06/13] lib/vsprintf.c: warn about too large precisions and field widths
Date: Tue, 20 Oct 2015 22:30:06 +0200 [thread overview]
Message-ID: <1445373013-20207-7-git-send-email-linux@rasmusvillemoes.dk> (raw)
In-Reply-To: <1445373013-20207-1-git-send-email-linux@rasmusvillemoes.dk>
The field width is overloaded to pass some extra information for
some %p extensions (e.g. #bits for %pb). But we might silently
truncate the passed value when we stash it in struct printf_spec (see
e.g. "lib/vsprintf.c: expand field_width to 24 bits"). Hopefully 23
value bits should now be enough for everybody, but if not, let's make
some noise.
Do the same for the precision. In both cases, clamping seems more
sensible than truncating. A negative precision is the same as 0, so
use that as lower bound. For the field width, the smallest
representable value is actually -(1<<23), but a negative field width
means 'set the LEFT flag and use the absolute value', so we want the
absolute value to fit.
Signed-off-by: Rasmus Villemoes <linux@rasmusvillemoes.dk>
---
lib/vsprintf.c | 24 ++++++++++++++++++++++--
1 file changed, 22 insertions(+), 2 deletions(-)
diff --git a/lib/vsprintf.c b/lib/vsprintf.c
index 6d75a3364683..3e96cf45c681 100644
--- a/lib/vsprintf.c
+++ b/lib/vsprintf.c
@@ -386,6 +386,8 @@ struct printf_spec {
unsigned int base:8; /* number base, 8, 10 or 16 only */
signed int precision:16; /* # of digits/chars */
};
+#define FIELD_WIDTH_MAX ((1 << 23) - 1)
+#define PRECISION_MAX ((1 << 15) - 1)
extern char __check_printf_spec[1-2*(sizeof(struct printf_spec) != 8)];
static noinline_for_stack
@@ -1813,6 +1815,24 @@ qualifier:
return ++fmt - start;
}
+static inline void
+set_field_width(struct printf_spec *spec, int width)
+{
+ spec->field_width = width;
+ if (WARN_ONCE(spec->field_width != width, "field width %d too large", width)) {
+ spec->field_width = clamp(width, -FIELD_WIDTH_MAX, FIELD_WIDTH_MAX);
+ }
+}
+
+static inline void
+set_precision(struct printf_spec *spec, int prec)
+{
+ spec->precision = prec;
+ if (WARN_ONCE(spec->precision != prec, "precision %d too large", prec)) {
+ spec->precision = clamp(prec, 0, PRECISION_MAX);
+ }
+}
+
/**
* vsnprintf - Format a string and place it in a buffer
* @buf: The buffer to place the result into
@@ -1905,11 +1925,11 @@ int vsnprintf(char *buf, size_t size, const char *fmt, va_list args)
}
case FORMAT_TYPE_WIDTH:
- spec.field_width = va_arg(args, int);
+ set_field_width(&spec, va_arg(args, int));
break;
case FORMAT_TYPE_PRECISION:
- spec.precision = va_arg(args, int);
+ set_precision(&spec, va_arg(args, int));
break;
case FORMAT_TYPE_CHAR: {
--
2.6.1
next prev parent reply other threads:[~2015-10-20 20:32 UTC|newest]
Thread overview: 23+ messages / expand[flat|nested] mbox.gz Atom feed top
[not found] <1445373013-20207-1-git-send-email-linux@rasmusvillemoes.dk>
2015-10-20 20:30 ` [PATCH 01/13] lib/vsprintf.c: pull out padding code from dentry_name() Rasmus Villemoes
2015-10-20 20:30 ` [PATCH 02/13] lib/vsprintf.c: move string() below widen_string() Rasmus Villemoes
2015-10-20 20:30 ` [PATCH 03/13] lib/vsprintf.c: eliminate potential race in string() Rasmus Villemoes
2015-10-20 20:30 ` [PATCH 04/13] lib/vsprintf.c: expand field_width to 24 bits Rasmus Villemoes
2015-10-20 23:39 ` kbuild test robot
2015-10-21 8:54 ` Rasmus Villemoes
2015-10-21 8:59 ` [PATCH v2 " Rasmus Villemoes
2015-12-01 23:38 ` [PATCH " Andrew Morton
2015-12-13 0:46 ` Andy Shevchenko
2015-10-20 20:30 ` [PATCH 05/13] lib/vsprintf.c: help gcc make number() smaller Rasmus Villemoes
2015-10-20 20:30 ` Rasmus Villemoes [this message]
2015-10-20 20:30 ` [PATCH 07/13] lib/test_printf.c: don't BUG Rasmus Villemoes
2015-10-26 6:39 ` Kees Cook
2015-10-20 20:30 ` [PATCH 08/13] lib/test_printf.c: check for out-of-bound writes Rasmus Villemoes
2015-10-26 6:41 ` Kees Cook
2015-10-20 20:30 ` [PATCH 09/13] lib/test_printf.c: add a few string tests Rasmus Villemoes
2015-10-26 6:43 ` Kees Cook
2015-10-20 20:30 ` [PATCH 10/13] lib/test_printf.c: account for kvasprintf tests Rasmus Villemoes
2015-10-26 6:43 ` Kees Cook
2015-10-20 20:30 ` [PATCH 11/13] lib/test_printf.c: add test for large bitmaps Rasmus Villemoes
2015-10-26 6:45 ` Kees Cook
2015-10-20 20:30 ` [PATCH 12/13] lib/test_printf.c: test dentry printing Rasmus Villemoes
2015-10-20 20:30 ` [PATCH 13/13] lib/kasprintf.c: add sanity check to kvasprintf Rasmus Villemoes
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=1445373013-20207-7-git-send-email-linux@rasmusvillemoes.dk \
--to=linux@rasmusvillemoes.dk \
--cc=akpm@linux-foundation.org \
--cc=linux-kernel@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®