From: Julia Lawall <julia@diku.dk>
To: Alasdair G Kergon <agk@redhat.com>
Cc: device-mapper development <dm-devel@redhat.com>,
linux-kernel@vger.kernel.org, kernel-janitors@vger.kernel.org
Subject: Re: [dm-devel] [PATCH 2/6] drivers/md: remove null pointer dereference
Date: Wed, 2 Jul 2008 13:51:41 +0200 (CEST) [thread overview]
Message-ID: <Pine.LNX.4.64.0807021351270.4854@ask.diku.dk> (raw)
In-Reply-To: <20080702105434.GF22522@agk.fab.redhat.com>
On Wed, 2 Jul 2008, Alasdair G Kergon wrote:
> On Mon, May 12, 2008 at 03:37:31PM +0200, Julia Lawall wrote:
> > If pgpath->pg->ps.type is NULL, it is not possible to access its name
> > field. So I have simply modified the error message to drop the printing of
> > the name field.
> >
> > This problem was found using the following semantic match
> > (http://www.emn.fr/x-info/coccinelle/)
>
> > --- a/drivers/md/dm-mpath.c 2008-04-16 13:27:57.000000000 +0200
> > +++ b/drivers/md/dm-mpath.c 2008-05-12 09:19:35.000000000 +0200
> > @@ -884,8 +884,7 @@ static int reinstate_path(struct pgpath
> > goto out;
> >
> > if (!pgpath->pg->ps.type) {
> > - DMWARN("Reinstate path not supported by path selector %s",
> > - pgpath->pg->ps.type->name);
> > + DMWARN("Reinstate path not supported by path selector");
> > r = -EINVAL;
> > goto out;
> > }
>
> Thanks for reporting this.
>
> A more-sophisticated checker might discover that the test can never fail
> - see parse_path_selector() - and so the real problem here is that it is
> the wrong test.
>
> The next line is:
> r = pgpath->pg->ps.type->reinstate_path(&pgpath->pg->ps, &pgpath->path);
> and the error message makes it clear that the intent was to ensure that
> the reinstate_path method exists before attempting to use it.
>
> IOW
> if (!pgpath->pg->ps.type->reinstate_path) {
Thanks for the suggestions.
In looking at it a little bit, it seems that ps.type is initialized in the
function stored in the ctr field of the target_type structure and this
function is called in the function stored in the message field of the same
structure. The function in the message structure seems to be only called
from the function target_message in dm-ioctl.c, but I don't see the
relation to an invocation of the ctr field. Is that guaranteed to be
invoked earlier?
julia
next prev parent reply other threads:[~2008-07-02 11:51 UTC|newest]
Thread overview: 4+ messages / expand[flat|nested] mbox.gz Atom feed top
2008-05-12 13:37 Julia Lawall
2008-07-02 10:54 ` [dm-devel] " Alasdair G Kergon
2008-07-02 11:51 ` Julia Lawall [this message]
2008-07-02 19:03 ` Alasdair G Kergon
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=Pine.LNX.4.64.0807021351270.4854@ask.diku.dk \
--to=julia@diku.dk \
--cc=agk@redhat.com \
--cc=dm-devel@redhat.com \
--cc=kernel-janitors@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®