Patch Detail
get:
Show a patch.
patch:
Update a patch.
put:
Update a patch.
GET /api/patches/67262/?format=api
http://patchwork.dpdk.org/api/patches/67262/?format=api", "web_url": "http://patchwork.dpdk.org/project/dpdk/patch/20200327080955.19571-4-olivier.matz@6wind.com/", "project": { "id": 1, "url": "http://patchwork.dpdk.org/api/projects/1/?format=api", "name": "DPDK", "link_name": "dpdk", "list_id": "dev.dpdk.org", "list_email": "dev@dpdk.org", "web_url": "http://core.dpdk.org", "scm_url": "git://dpdk.org/dpdk", "webscm_url": "http://git.dpdk.org/dpdk", "list_archive_url": "https://inbox.dpdk.org/dev", "list_archive_url_format": "https://inbox.dpdk.org/dev/{}", "commit_url_format": "" }, "msgid": "<20200327080955.19571-4-olivier.matz@6wind.com>", "list_archive_url": "https://inbox.dpdk.org/dev/20200327080955.19571-4-olivier.matz@6wind.com", "date": "2020-03-27T08:09:55", "name": "[v2,3/3] kvargs: fix a heap buffer overflow when parsing list", "commit_ref": null, "pull_url": null, "state": "accepted", "archived": true, "hash": "333ab7db4886f8b1110e5d0ac4d4dc3b0cef6ffc", "submitter": { "id": 8, "url": "http://patchwork.dpdk.org/api/people/8/?format=api", "name": "Olivier Matz", "email": "olivier.matz@6wind.com" }, "delegate": { "id": 24651, "url": "http://patchwork.dpdk.org/api/users/24651/?format=api", "username": "dmarchand", "first_name": "David", "last_name": "Marchand", "email": "david.marchand@redhat.com" }, "mbox": "http://patchwork.dpdk.org/project/dpdk/patch/20200327080955.19571-4-olivier.matz@6wind.com/mbox/", "series": [ { "id": 9072, "url": "http://patchwork.dpdk.org/api/series/9072/?format=api", "web_url": "http://patchwork.dpdk.org/project/dpdk/list/?series=9072", "date": "2020-03-27T08:09:53", "name": "kvargs fixes", "version": 2, "mbox": "http://patchwork.dpdk.org/series/9072/mbox/" } ], "comments": "http://patchwork.dpdk.org/api/patches/67262/comments/", "check": "success", "checks": "http://patchwork.dpdk.org/api/patches/67262/checks/", "tags": {}, "related": [], "headers": { "Return-Path": "<dev-bounces@dpdk.org>", "X-Original-To": "patchwork@inbox.dpdk.org", "Delivered-To": "patchwork@inbox.dpdk.org", "Received": [ "from dpdk.org (dpdk.org [92.243.14.124])\n\tby inbox.dpdk.org (Postfix) with ESMTP id 31C59A057C;\n\tFri, 27 Mar 2020 09:11:18 +0100 (CET)", "from [92.243.14.124] (localhost [127.0.0.1])\n\tby dpdk.org (Postfix) with ESMTP id A3C7C1C0BC;\n\tFri, 27 Mar 2020 09:10:52 +0100 (CET)", "from proxy.6wind.com (host.76.145.23.62.rev.coltfrance.com\n [62.23.145.76]) by dpdk.org (Postfix) with ESMTP id 4B0B31C02E;\n Fri, 27 Mar 2020 09:10:46 +0100 (CET)", "from glumotte.dev.6wind.com. (unknown [10.16.0.195])\n by proxy.6wind.com (Postfix) with ESMTP id 27CCB3B1DF5;\n Fri, 27 Mar 2020 09:10:46 +0100 (CET)" ], "From": "Olivier Matz <olivier.matz@6wind.com>", "To": "wangyunjian@huawei.com", "Cc": "dev@dpdk.org, jerry.lilijun@huawei.com, olivier.matz@6wind.com,\n stable@dpdk.org, xudingke@huawei.com", "Date": "Fri, 27 Mar 2020 09:09:55 +0100", "Message-Id": "<20200327080955.19571-4-olivier.matz@6wind.com>", "X-Mailer": "git-send-email 2.25.1", "In-Reply-To": "<20200327080955.19571-1-olivier.matz@6wind.com>", "References": "<1584592680-14000-1-git-send-email-wangyunjian@huawei.com>\n <20200327080955.19571-1-olivier.matz@6wind.com>", "MIME-Version": "1.0", "Content-Transfer-Encoding": "8bit", "Subject": "[dpdk-dev] [PATCH v2 3/3] kvargs: fix a heap buffer overflow when\n\tparsing list", "X-BeenThere": "dev@dpdk.org", "X-Mailman-Version": "2.1.15", "Precedence": "list", "List-Id": "DPDK patches and discussions <dev.dpdk.org>", "List-Unsubscribe": "<https://mails.dpdk.org/options/dev>,\n <mailto:dev-request@dpdk.org?subject=unsubscribe>", "List-Archive": "<http://mails.dpdk.org/archives/dev/>", "List-Post": "<mailto:dev@dpdk.org>", "List-Help": "<mailto:dev-request@dpdk.org?subject=help>", "List-Subscribe": "<https://mails.dpdk.org/listinfo/dev>,\n <mailto:dev-request@dpdk.org?subject=subscribe>", "Errors-To": "dev-bounces@dpdk.org", "Sender": "\"dev\" <dev-bounces@dpdk.org>" }, "content": "From: Yunjian Wang <wangyunjian@huawei.com>\n\nWhen the input string is \"key=[\", the ending '\\0' is replaced\nby a ',', leading to a heap buffer overflow.\n\nCheck the content of ctx1 to avoid this problem.\n\nFixes: cc0579f2339a (\"kvargs: support list value\")\nCc: stable@dpdk.org\n\nSigned-off-by: Yunjian Wang <wangyunjian@huawei.com>\nSigned-off-by: Olivier Matz <olivier.matz@6wind.com>\n---\n app/test/test_kvargs.c | 1 +\n lib/librte_kvargs/rte_kvargs.c | 2 ++\n 2 files changed, 3 insertions(+)", "diff": "diff --git a/app/test/test_kvargs.c b/app/test/test_kvargs.c\nindex f823b771f..2a2dae43a 100644\n--- a/app/test/test_kvargs.c\n+++ b/app/test/test_kvargs.c\n@@ -217,6 +217,7 @@ static int test_invalid_kvargs(void)\n \t\t\"foo=1,=2\", /* no key */\n \t\t\"foo=[1,2\", /* no closing bracket in value */\n \t\t\",=\", /* also test with a smiley */\n+\t\t\"foo=[\", /* no value in list and no closing bracket */\n \t\tNULL };\n \tconst char **args;\n \tconst char *valid_keys_list[] = { \"foo\", \"check\", NULL };\ndiff --git a/lib/librte_kvargs/rte_kvargs.c b/lib/librte_kvargs/rte_kvargs.c\nindex d39332999..1d815dcd9 100644\n--- a/lib/librte_kvargs/rte_kvargs.c\n+++ b/lib/librte_kvargs/rte_kvargs.c\n@@ -50,6 +50,8 @@ rte_kvargs_tokenize(struct rte_kvargs *kvlist, const char *params)\n \t\t\t/* Find the end of the list. */\n \t\t\twhile (str[strlen(str) - 1] != ']') {\n \t\t\t\t/* Restore the comma erased by strtok_r(). */\n+\t\t\t\tif (ctx1[0] == '\\0')\n+\t\t\t\t\treturn -1; /* no closing bracket */\n \t\t\t\tstr[strlen(str)] = ',';\n \t\t\t\t/* Parse until next comma. */\n \t\t\t\tstr = strtok_r(NULL, RTE_KVARGS_PAIRS_DELIM, &ctx1);\n", "prefixes": [ "v2", "3/3" ] }{ "id": 67262, "url": "