* [bug report] RDMA/mlx5: Add support in MEMIC operations
@ 2021-05-04 7:50 Dan Carpenter
2021-05-04 8:25 ` Leon Romanovsky
0 siblings, 1 reply; 2+ messages in thread
From: Dan Carpenter @ 2021-05-04 7:50 UTC (permalink / raw)
To: maorg; +Cc: linux-rdma
Hello Maor Gottlieb,
The patch cea85fa5dbc2: "RDMA/mlx5: Add support in MEMIC operations"
from Apr 11, 2021, leads to the following static checker warning:
drivers/infiniband/hw/mlx5/dm.c:220 mlx5_ib_handler_MLX5_IB_METHOD_DM_MAP_OP_ADDR()
error: undefined (user controlled) shift '(((1))) << op'
drivers/infiniband/hw/mlx5/dm.c
204 static int UVERBS_HANDLER(MLX5_IB_METHOD_DM_MAP_OP_ADDR)(
205 struct uverbs_attr_bundle *attrs)
206 {
207 struct ib_uobject *uobj = uverbs_attr_get_uobject(
208 attrs, MLX5_IB_ATTR_DM_MAP_OP_ADDR_REQ_HANDLE);
209 struct mlx5_ib_dev *dev = to_mdev(uobj->context->device);
210 struct ib_dm *ibdm = uobj->object;
211 struct mlx5_ib_dm_memic *dm = to_memic(ibdm);
212 struct mlx5_ib_dm_op_entry *op_entry;
213 int err;
214 u8 op;
215
216 err = uverbs_copy_from(&op, attrs, MLX5_IB_ATTR_DM_MAP_OP_ADDR_REQ_OP);
^^
op is user controlled and in the 0-255 range.
217 if (err)
218 return err;
219
220 if (!(MLX5_CAP_DEV_MEM(dev->mdev, memic_operations) & BIT(op)))
^^^^^^^
If it's more than 31 then this is undefined (shift wrapping generally).
Plus it might trigger a UBSan warning at run time.
221 return -EOPNOTSUPP;
222
223 mutex_lock(&dm->ops_xa_lock);
regards,
dan carpenter
^ permalink raw reply [flat|nested] 2+ messages in thread
* Re: [bug report] RDMA/mlx5: Add support in MEMIC operations
2021-05-04 7:50 [bug report] RDMA/mlx5: Add support in MEMIC operations Dan Carpenter
@ 2021-05-04 8:25 ` Leon Romanovsky
0 siblings, 0 replies; 2+ messages in thread
From: Leon Romanovsky @ 2021-05-04 8:25 UTC (permalink / raw)
To: Dan Carpenter; +Cc: maorg, linux-rdma
On Tue, May 04, 2021 at 10:50:44AM +0300, Dan Carpenter wrote:
> Hello Maor Gottlieb,
>
> The patch cea85fa5dbc2: "RDMA/mlx5: Add support in MEMIC operations"
> from Apr 11, 2021, leads to the following static checker warning:
>
> drivers/infiniband/hw/mlx5/dm.c:220 mlx5_ib_handler_MLX5_IB_METHOD_DM_MAP_OP_ADDR()
> error: undefined (user controlled) shift '(((1))) << op'
>
> drivers/infiniband/hw/mlx5/dm.c
> 204 static int UVERBS_HANDLER(MLX5_IB_METHOD_DM_MAP_OP_ADDR)(
> 205 struct uverbs_attr_bundle *attrs)
> 206 {
> 207 struct ib_uobject *uobj = uverbs_attr_get_uobject(
> 208 attrs, MLX5_IB_ATTR_DM_MAP_OP_ADDR_REQ_HANDLE);
> 209 struct mlx5_ib_dev *dev = to_mdev(uobj->context->device);
> 210 struct ib_dm *ibdm = uobj->object;
> 211 struct mlx5_ib_dm_memic *dm = to_memic(ibdm);
> 212 struct mlx5_ib_dm_op_entry *op_entry;
> 213 int err;
> 214 u8 op;
> 215
> 216 err = uverbs_copy_from(&op, attrs, MLX5_IB_ATTR_DM_MAP_OP_ADDR_REQ_OP);
> ^^
> op is user controlled and in the 0-255 range.
>
> 217 if (err)
> 218 return err;
> 219
> 220 if (!(MLX5_CAP_DEV_MEM(dev->mdev, memic_operations) & BIT(op)))
> ^^^^^^^
> If it's more than 31 then this is undefined (shift wrapping generally).
> Plus it might trigger a UBSan warning at run time.
Thanks Dan, we will prepare the proper patch.
It should be something like this:
diff --git a/drivers/infiniband/hw/mlx5/dm.c b/drivers/infiniband/hw/mlx5/dm.c
index 094bf85589db..dd4480aed1aa 100644
--- a/drivers/infiniband/hw/mlx5/dm.c
+++ b/drivers/infiniband/hw/mlx5/dm.c
@@ -217,6 +217,9 @@ static int UVERBS_HANDLER(MLX5_IB_METHOD_DM_MAP_OP_ADDR)(
if (err)
return err;
+ if (op > 31)
+ return -EINVAL;
+
if (!(MLX5_CAP_DEV_MEM(dev->mdev, memic_operations) & BIT(op)))
return -EOPNOTSUPP;
>
> 221 return -EOPNOTSUPP;
> 222
> 223 mutex_lock(&dm->ops_xa_lock);
>
> regards,
> dan carpenter
^ permalink raw reply related [flat|nested] 2+ messages in thread
end of thread, other threads:[~2021-05-04 8:25 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2021-05-04 7:50 [bug report] RDMA/mlx5: Add support in MEMIC operations Dan Carpenter
2021-05-04 8:25 ` Leon Romanovsky
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.