Thread (32 messages) 32 messages, 5 authors, 2013-03-29

RE: [PATCH 3/3] powerpc/fsl: add MPIC timer wakeup support

flat view

From: Wang Dongsheng-B40534 <hidden>
Date: 2013-03-22 05:46:32

-----Original Message-----
From: Wood Scott-B07421
Sent: Thursday, March 21, 2013 5:49 AM
To: Wang Dongsheng-B40534
Cc: Wood Scott-B07421; Gala Kumar-B11780; linuxppc-dev@lists.ozlabs.org;
Zhao Chenhui-B35336; Li Yang-R58472
Subject: Re: [PATCH 3/3] powerpc/fsl: add MPIC timer wakeup support
=20
On 03/19/2013 10:48:53 PM, Wang Dongsheng-B40534 wrote:
quoted
quoted
-----Original Message-----
From: Wood Scott-B07421
Sent: Wednesday, March 20, 2013 6:55 AM
To: Wang Dongsheng-B40534
Cc: Wood Scott-B07421; Gala Kumar-B11780;
linuxppc-dev@lists.ozlabs.org;
quoted
Zhao Chenhui-B35336; Li Yang-R58472
Subject: Re: [PATCH 3/3] powerpc/fsl: add MPIC timer wakeup support

On 03/19/2013 01:25:42 AM, Wang Dongsheng-B40534 wrote:
quoted
quoted
-----Original Message-----
From: Wood Scott-B07421
Sent: Tuesday, March 19, 2013 8:31 AM
To: Wang Dongsheng-B40534
Cc: Gala Kumar-B11780; linuxppc-dev@lists.ozlabs.org; Wang
Dongsheng-
quoted
B40534; Zhao Chenhui-B35336; Li Yang-R58472
Subject: Re: [PATCH 3/3] powerpc/fsl: add MPIC timer wakeup
support
quoted
quoted
quoted
On 03/08/2013 01:38:47 AM, Wang Dongsheng wrote:
quoted
+static ssize_t fsl_timer_wakeup_store(struct device *dev,
+				struct device_attribute *attr,
+				const char *buf,
+				size_t count)
+{
+	struct timeval interval;
+	int ret;
+
+	interval.tv_usec =3D 0;
+	if (kstrtol(buf, 0, &interval.tv_sec))
+		return -EINVAL;
I don't think the buffer will NUL-terminated...  Ordinarily
there'll be
quoted
an LF terminator, but you can't rely on that (many other sysfs
attributes
quoted
seem to, though...).
I think we don't need to care about LF terminator.
The kstrtol--> _kstrtoull has been done.
My point is, what happens if userspace passes in a buffer that has
no
quoted
terminator of any sort?  kstrtol will continue reading beyond the
end of
quoted
the buffer.
Do not care about terminator.
=20
kstrtol() obviously *does* because it doesn't take the buffer length as
a parameter.
=20
quoted
kstrtol--> _kstrtoull--> _parse_integer

_kstrtoull(...) {
	...
	rv =3D _parse_integer(s, base, &_res);
	if (rv & KSTRTOX_OVERFLOW)
		return -ERANGE;
	rv &=3D ~KSTRTOX_OVERFLOW;
	if (rv =3D=3D 0)
		return -EINVAL;
	s +=3D rv;

	if (*s =3D=3D '\n')
		s++;
	if (*s)
		return -EINVAL;
	...
}

_parse_integer(...) {
	...
	while (*s) {
		if ('0' <=3D *s && *s <=3D '9')
			val =3D *s - '0';
		else if ('a' <=3D _tolower(*s) && _tolower(*s) <=3D 'f')
			val =3D _tolower(*s) - 'a' + 10;
		else
			break;	//this will break out to convert.
=20
Really?  How do you know that the next byte after the buffer isn't a
valid hex digit?  How do you even know that we won't take a fault
accessing it?
=20
Under what case is unsafe, please make sense.

"kstrtol" is used in almost of sysfs interface, I think it should be accept=
ed in defaule :).
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help