mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: "Nitin Gupta" <nitingupta910@gmail.com>
To: "Richard Purdie" <richard@openedhand.com>
Cc: linux-kernel@vger.kernel.org
Subject: Re: [RFC] LZO1X de/compression support
Date: Tue, 22 May 2007 14:49:51 +0530	[thread overview]
Message-ID: <4cefeab80705220219qeb00e09u47e992e884152b5b@mail.gmail.com> (raw)
In-Reply-To: <1179488817.5876.14.camel@localhost.localdomain>

Hi,

On 5/18/07, Richard Purdie <richard@openedhand.com> wrote:
> > This patch, as of yet, only gives 'non-safe' version of decompressor.
> > The 'safe' version  will be included soon.
>
> How are you planning to add that back?
>

Please see newer patch posted.

> The LZO author had some concerns about this code. The major issue he
> highlighted was that it was 64-bit unsafe. Have you addressed that
> problem?
I found certain parts which were 64-bit unsafe - corrected them. Now,
I couldn't see any more of such instances and posted as RFC :)

>  Has it been tested on 64bit?
No. I am still looking for some 64-bit machine to test on (also some
Big-endian machine).

>
> I'm worried that in converting this code the way you have, you've
> possibly introduced potential security holes. You've removed all bounds
> checking and are going to have to add that back to create the "safe"
> version of the decompression function. Until I mentioned it, you seemed
> unaware of the potential problem and the comments above suggest you
> don't understand this code as fully as I'd like with regard to
> overflows.

I just did the 'logical' porting work. I don't understand the
algorithm itself since I could not find any document that describes
the same.

>
> The version I submitted has at least been subject to userspace scrutiny
> over a period of time and is basically unchanged with regard to
> security. It is much uglier though.
>
> Richard

Yes. But it will be even better if we can verify/correct this
cleaned-up version - shouldn't be that hard for just ~500 LOC :-)


Thanks for your comments.

- Nitin

  reply	other threads:[~2007-05-22  9:20 UTC|newest]

Thread overview: 24+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2007-05-18  9:58 Nitin Gupta
2007-05-18 10:14 ` Heikki Orsila
2007-05-18 11:27   ` Nitin Gupta
2007-05-18 11:53     ` Richard Purdie
2007-05-18 10:42 ` Pekka Enberg
2007-05-18 10:53   ` Pekka Enberg
2007-05-22  8:54   ` Nitin Gupta
2007-05-22  8:59     ` Pekka Enberg
2007-05-22  9:10       ` Nitin Gupta
2007-05-22  9:34         ` Pekka Enberg
2007-05-18 11:11 ` Andrey Panin
2007-05-22  9:08   ` Nitin Gupta
2007-05-22 19:44     ` Jan Engelhardt
2007-05-22 21:24     ` Bernd Petrovitsch
2007-05-23 16:35       ` Jeremy Fitzhardinge
2007-05-18 11:46 ` Richard Purdie
2007-05-22  9:19   ` Nitin Gupta [this message]
2007-05-18 20:04 ` Matt Mackall
2007-05-18 21:14 ` Krzysztof Halasa
2007-05-19 18:55   ` Bill Rugolsky Jr.
2007-05-19 21:52     ` Richard Purdie
2007-05-22 19:40 ` Jan Engelhardt
2007-05-19 18:12 devzero
2007-05-20 11:42 Tomasz Chmielewski

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=4cefeab80705220219qeb00e09u47e992e884152b5b@mail.gmail.com \
    --to=nitingupta910@gmail.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=richard@openedhand.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®