Thread (6 messages) flat view 6 messages, 4 authors, 2009-10-30

Re: [PATCH] ax25: unsigned cannot be less than 0 in ax25_ctl_ioctl()

From: Roel Kluin <hidden>
Date: 2009-10-12 19:02:28
Also in: linux-hams
Subsystem: networking [general], the rest · Maintainers: "David S. Miller", Eric Dumazet, Jakub Kicinski, Paolo Abeni, Linus Torvalds

Possibly related (same subject, not in this thread)

struct ax25_ctl_struct member `arg' is unsigned and cannot be less
than 0.

Signed-off-by: Roel Kluin <redacted>
---
quoted
If the ax25_ctl.arg limit is known to be lower, please suggest
other values.
what is about something like:

 tmp_arg=ax25_ctl.arg * HZ;

  if (arg == 0 || arg >  ULONG_MAX )
		goto einval_put;

re,
 wh
I'm not sure, I think this would only work if we made `arg' an
unsigned long long.

How about this?
diff --git a/net/ax25/af_ax25.c b/net/ax25/af_ax25.c
index f454607..20ff0f3 100644
--- a/net/ax25/af_ax25.c
+++ b/net/ax25/af_ax25.c
@@ -369,6 +369,9 @@ static int ax25_ctl_ioctl(const unsigned int cmd, void __user *arg)
 	if (ax25_ctl.digi_count > AX25_MAX_DIGIS)
 		return -EINVAL;
 
+	if (ax25_ctl.arg * HZ > ULONG_MAX && ax25_ctl.cmd != AX25_KILL)
+		return -EINVAL;
+
 	digi.ndigi = ax25_ctl.digi_count;
 	for (k = 0; k < digi.ndigi; k++)
 		digi.calls[k] = ax25_ctl.digi_addr[k];
@@ -418,14 +421,10 @@ static int ax25_ctl_ioctl(const unsigned int cmd, void __user *arg)
 		break;
 
 	case AX25_T3:
-		if (ax25_ctl.arg < 0)
-			goto einval_put;
 		ax25->t3 = ax25_ctl.arg * HZ;
 		break;
 
 	case AX25_IDLE:
-		if (ax25_ctl.arg < 0)
-			goto einval_put;
 		ax25->idle = ax25_ctl.arg * 60 * HZ;
 		break;
 
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help