[dpdk-dev] [PATCH] lib/librte_pipeline:fix the array index out of bound

Singh, Jasvinder jasvinder.singh at intel.com
Mon Sep 4 15:37:19 CEST 2017


Hi Xie,

-----Original Message-----
From: dev [mailto:dev-bounces at dpdk.org] On Behalf Of Rongqiang XIE
Sent: Wednesday, August 23, 2017 8:06 AM
To: Dumitrescu, Cristian <cristian.dumitrescu at intel.com>
Cc: dev at dpdk.org; Rongqiang XIE <xie.rongqiang at zte.com.cn>
Subject: [dpdk-dev] [PATCH] lib/librte_pipeline:fix the array index out of bound

In function rte_pipeline_compute_masks(), the value pos equal
p->entries[i]->action,type constraint p->entries[i]->action is
[0,4],but array action_mask1 size is 4,it possible attempt to access element 4 of array action_mask1.And also in function rte_pipeline_run(),it possible attempt to access element 4 of array action_mask0.

Signed-off-by: Rongqiang XIE <xie.rongqiang at zte.com.cn>
---
 lib/librte_pipeline/rte_pipeline.c | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

diff --git a/lib/librte_pipeline/rte_pipeline.c b/lib/librte_pipeline/rte_pipeline.c
index 7f8fbac..2914445 100644
--- a/lib/librte_pipeline/rte_pipeline.c
+++ b/lib/librte_pipeline/rte_pipeline.c
@@ -155,8 +155,8 @@ struct rte_pipeline {
 	/* Pipeline run structures */
 	struct rte_mbuf *pkts[RTE_PORT_IN_BURST_SIZE_MAX];
 	struct rte_pipeline_table_entry *entries[RTE_PORT_IN_BURST_SIZE_MAX];
-	uint64_t action_mask0[RTE_PIPELINE_ACTIONS];
-	uint64_t action_mask1[RTE_PIPELINE_ACTIONS];
+	uint64_t action_mask0[RTE_PIPELINE_ACTIONS + 1];
+	uint64_t action_mask1[RTE_PIPELINE_ACTIONS + 1];
 	uint64_t pkts_mask;
 	uint64_t n_pkts_ah_drop;
 	uint64_t pkts_drop_mask;


How about making library more robust by introducing some checks to make sure that action field value doesn't overshoot?
The action field value can be checked in the following functions meant for adding table entries. 
rte_pipeline_table_default_entry_add(),
rte_pipeline_table_entry_add(),
rte_pipeline_table_entry_add_bulk() 




More information about the dev mailing list