From: David Howells <dhowells@redhat.com>
To: vgoyal@redhat.com
Cc: dhowells@redhat.com, keyrings@linux-nfs.org,
linux-kernel@vger.kernel.org
Subject: Re: [PATCH 11/10] Check hex2bin()'s return when generating an asymmetric key ID
Date: Mon, 22 Sep 2014 00:32:19 +0100 [thread overview]
Message-ID: <22566.1411342339@warthog.procyon.org.uk> (raw)
In-Reply-To: <20140915204456.27499.40234.stgit@warthog.procyon.org.uk>
As it stands, the code to generate an asymmetric key ID prechecks the hex
string it is given whilst determining the length, before it allocates the
buffer for hex2bin() to translate into - which mean that checking the result of
hex2bin() is redundant.
Unfortunately, hex2bin() is marked as __must_check, which means that the
following warning may be generated if the return value isn't checked:
crypto/asymmetric_keys/asymmetric_type.c: In function
asymmetric_key_hex_to_key_id:
crypto/asymmetric_keys/asymmetric_type.c:110: warning: ignoring return
value of hex2bin, declared with attribute warn_unused_result
The warning can't be avoided by casting the result to void.
Instead, use strlen() to check the length of the string and ignore the fact
that the string might not be entirely valid hex until after the allocation has
been done - in which case we can use the result of hex2bin() for this.
Signed-off-by: David Howells <dhowells@redhat.com>
---
asymmetric_type.c | 15 ++++++++-------
1 file changed, 8 insertions(+), 7 deletions(-)
diff --git a/crypto/asymmetric_keys/asymmetric_type.c b/crypto/asymmetric_keys/asymmetric_type.c
index 718e779a010e..f0f2111d2c66 100644
--- a/crypto/asymmetric_keys/asymmetric_type.c
+++ b/crypto/asymmetric_keys/asymmetric_type.c
@@ -90,15 +90,12 @@ EXPORT_SYMBOL_GPL(asymmetric_match_key_ids);
struct asymmetric_key_id *asymmetric_key_hex_to_key_id(const char *id)
{
struct asymmetric_key_id *match_id;
- const char *p;
- ptrdiff_t hexlen;
+ size_t hexlen;
+ int ret;
if (!*id)
return ERR_PTR(-EINVAL);
- for (p = id; *p; p++)
- if (!isxdigit(*p))
- return ERR_PTR(-EINVAL);
- hexlen = p - id;
+ hexlen = strlen(id);
if (hexlen & 1)
return ERR_PTR(-EINVAL);
@@ -107,7 +104,11 @@ struct asymmetric_key_id *asymmetric_key_hex_to_key_id(const char *id)
if (!match_id)
return ERR_PTR(-ENOMEM);
match_id->len = hexlen / 2;
- (void)hex2bin(match_id->data, id, hexlen / 2);
+ ret = hex2bin(match_id->data, id, hexlen / 2);
+ if (ret < 0) {
+ kfree(match_id);
+ return ERR_PTR(-EINVAL);
+ }
return match_id;
}
prev parent reply other threads:[~2014-09-21 23:32 UTC|newest]
Thread overview: 13+ messages / expand[flat|nested] mbox.gz Atom feed top
2014-09-15 20:44 [PATCH 00/10] KEYS: Improve asymmetric key and PKCS#7 handling [ver #2] David Howells
2014-09-15 20:45 ` [PATCH 01/10] Provide a binary to hex conversion function " David Howells
2014-09-15 20:45 ` [PATCH 02/10] KEYS: Preparse match data " David Howells
2014-09-15 20:45 ` [PATCH 03/10] KEYS: Remove key_type::def_lookup_type " David Howells
2014-09-15 20:45 ` [PATCH 04/10] KEYS: Remove key_type::match in favour of overriding default by match_preparse " David Howells
2014-09-15 20:45 ` [PATCH 05/10] KEYS: Make the key matching functions return bool " David Howells
2014-09-15 20:45 ` [PATCH 06/10] KEYS: Update the keyrings documentation for match changes " David Howells
2014-09-15 20:45 ` [PATCH 07/10] KEYS: Implement binary asymmetric key ID handling " David Howells
2014-09-15 20:45 ` [PATCH 08/10] KEYS: Overhaul key identification when searching for asymmetric keys " David Howells
2014-09-15 20:45 ` [PATCH 09/10] PKCS#7: Better handling of unsupported crypto " David Howells
2014-09-15 20:45 ` [PATCH 10/10] PKCS#7: Handle PKCS#7 messages that contain no X.509 certs " David Howells
2014-09-15 22:30 ` [PATCH 09/10] PKCS#7: Better handling of unsupported crypto " David Howells
2014-09-21 23:32 ` David Howells [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=22566.1411342339@warthog.procyon.org.uk \
--to=dhowells@redhat.com \
--cc=keyrings@linux-nfs.org \
--cc=linux-kernel@vger.kernel.org \
--cc=vgoyal@redhat.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®