[PATCH v2 01/61] kvargs: add numeric conversion helpers
fengchengwen
fengchengwen at huawei.com
Wed Sep 30 02:49:27 CEST 2026
On 9/30/2026 12:36 AM, Stephen Hemminger wrote:
> Drivers which take numeric values in devargs each open code the
> conversion from string to integer, and often get it wrong.
> A survey of the tree finds at least fifteen separate
> implementations of "parse an unsigned integer devarg", of which two are
> exported from lib/ and byte for byte identical to each other.
>
> The recurring bugs are:
>
> - atoi() is used, so overflow is undefined and nothing is validated;
> - errno is checked without being reset first, so an unrelated earlier
> failure rejects a valid value;
> - errno is checked but endptr is not, so "foo" is silently accepted
> as zero;
> - endptr is checked but errno is not, so an overflowing value is
> accepted as ULLONG_MAX;
> - the result is stored into a narrower type with no range check, so
> nb_desc=65537 silently becomes 1;
> - strtoul() is used for an unsigned target, so a leading '-' is
> accepted and wrapped around, and dev_caps_mask=-1 enables
> everything;
> - the value is dereferenced without checking for NULL, so a key given
> with no value segfaults;
> - base 0 is passed, so a leading zero unexpectedly selects octal.
>
> Add a set of helpers matching arg_handler_t, so they can be passed
> straight to rte_kvargs_process(), covering the integer types drivers
> actually store into. Each validates the whole string and only writes
> the target on success, so a caller supplied default survives a bad
> argument.
>
> Add rte_kvargs_handle_bool for on/off style arguments. It accepts the
> word forms which only sfc supports today, and treats a key given
> without a value as true.
>
> Where a driver needs a range narrower than the target type, expose the
> underlying rte_kvargs_to_uint and rte_kvargs_to_int.
>
> Octal is deliberately not supported: no driver documents it, and
> reading "010" as eight has been a recurring surprise.
>
> Signed-off-by: Stephen Hemminger <stephen at networkplumber.org>
> ---
...
> +
> +/**
> + * @warning
> + * @b EXPERIMENTAL: this API may change without prior notice.
> + *
> + * Convert a string to a signed integer, checking it against a range.
> + *
> + * This is the signed counterpart of rte_kvargs_to_uint().
> + *
> + * @param value
> + * The string to convert. Must be non-NULL and non-empty. See
> + * rte_kvargs_handle_u8() for the accepted syntax.
> + * @param min
> + * Smallest acceptable value, inclusive.
> + * @param max
> + * Largest acceptable value, inclusive.
> + * @param result
> + * Where to store the converted value. Left unmodified on error.
> + *
> + * @return
> + * - 0 on success.
> + * - -EINVAL if the value is missing or malformed, or if @p result is NULL.
> + * - -ERANGE if the value is outside [@p min, @p max].
> + */
> +__rte_experimental
> +int rte_kvargs_to_int(const char *value, int64_t min, int64_t max,
> + int64_t *result);
How about rte_kvargs_handle_int_range() ?
> +
> #ifdef __cplusplus
> }
> #endif
More information about the dev
mailing list