From: Nicolas Dichtel <redacted>
Use the ISO C standard compliant form instead of the gcc extension.
Signed-off-by: Nicolas Dichtel <redacted>
---
include/uapi/linux/xfrm.h | 10 +++++-----
1 file changed, 5 insertions(+), 5 deletions(-)
@@ -93,27 +93,27 @@ struct xfrm_replay_state_esn {__u32oseq_hi;__u32seq_hi;__u32replay_window;-__u32bmp[0];+__u32bmp[];};structxfrm_algo{charalg_name[64];unsignedintalg_key_len;/* in bits */-charalg_key[0];+charalg_key[];};structxfrm_algo_auth{charalg_name[64];unsignedintalg_key_len;/* in bits */unsignedintalg_trunc_len;/* in bits */-charalg_key[0];+charalg_key[];};structxfrm_algo_aead{charalg_name[64];unsignedintalg_key_len;/* in bits */unsignedintalg_icv_len;/* in bits */-charalg_key[0];+charalg_key[];};structxfrm_stats{
On Tue, Oct 16, 2012 at 05:42:33PM +0200, nicolas.dichtel@6wind.com wrote:
quoted hunk
From: Nicolas Dichtel <redacted>
Use the ISO C standard compliant form instead of the gcc extension.
Signed-off-by: Nicolas Dichtel <redacted>
---
include/uapi/linux/xfrm.h | 10 +++++-----
1 file changed, 5 insertions(+), 5 deletions(-)
On Tue, Oct 16, 2012 at 05:42:33PM +0200, nicolas.dichtel@6wind.com wrote:
quoted
From: Nicolas Dichtel <redacted>
Use the ISO C standard compliant form instead of the gcc extension.
Signed-off-by: Nicolas Dichtel <redacted>
---
include/uapi/linux/xfrm.h | 10 +++++-----
1 file changed, 5 insertions(+), 5 deletions(-)
From: Nicolas Dichtel <hidden> Date: 2012-10-17 07:51:02
Le 17/10/2012 07:43, Steffen Klassert a écrit :
On Tue, Oct 16, 2012 at 05:42:33PM +0200, nicolas.dichtel@6wind.com wrote:
quoted
From: Nicolas Dichtel <redacted>
Use the ISO C standard compliant form instead of the gcc extension.
Signed-off-by: Nicolas Dichtel <redacted>
---
include/uapi/linux/xfrm.h | 10 +++++-----
1 file changed, 5 insertions(+), 5 deletions(-)
Hm, what's the benefit of such a change? The kernel source is full
of these foo[0] type arrays. I don't see a reason to change this
just for xfrm.
We got a problem with "ip xfrm state add" when compiled with gcc 4.4.6.
Error was "*** buffer overflow detected ***: ip terminated", because when we try to copy the key in struct xfrm_algo, the function strncpy() calls some builtin checks about the size of the destination buffer, which is 0. With the standard notation, there is no problem.
With gcc 4.7.0, there is no problem, I don't know exactly which version of gcc triggers the problem.
On Wed, Oct 17, 2012 at 09:50:58AM +0200, Nicolas Dichtel wrote:
We got a problem with "ip xfrm state add" when compiled with gcc 4.4.6.
Error was "*** buffer overflow detected ***: ip terminated", because
when we try to copy the key in struct xfrm_algo, the function
strncpy() calls some builtin checks about the size of the
destination buffer, which is 0. With the standard notation, there is
no problem.
This is likely to be a gcc FORITFY bug. Try to build iproute2 with
the -D_FORTIFY_SOURCE=0 flag.
From: Nicolas Dichtel <hidden> Date: 2012-10-17 09:03:17
Le 17/10/2012 10:27, Steffen Klassert a écrit :
On Wed, Oct 17, 2012 at 09:50:58AM +0200, Nicolas Dichtel wrote:
quoted
We got a problem with "ip xfrm state add" when compiled with gcc 4.4.6.
Error was "*** buffer overflow detected ***: ip terminated", because
when we try to copy the key in struct xfrm_algo, the function
strncpy() calls some builtin checks about the size of the
destination buffer, which is 0. With the standard notation, there is
no problem.
This is likely to be a gcc FORITFY bug. Try to build iproute2 with
the -D_FORTIFY_SOURCE=0 flag.