Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.kernel > #1265711
| Path | csiph.com!news.mixmin.net!eternal-september.org!feeder.eternal-september.org!aioe.org!bofh.it!news.nic.it!robomod |
|---|---|
| From | Rasmus Villemoes <linux@rasmusvillemoes.dk> |
| Newsgroups | linux.kernel |
| Subject | Re: [GIT] Networking |
| Date | Mon, 09 Nov 2015 15:20:03 +0100 |
| Message-ID | <qsVsD-7v9-37@gated-at.bofh.it> (permalink) |
| References | <qosfv-7mx-3@gated-at.bofh.it> <qovwK-Sj-25@gated-at.bofh.it> <qowMa-1Rt-27@gated-at.bofh.it> <qoA3o-3Pi-17@gated-at.bofh.it> <qsTqO-6dw-27@gated-at.bofh.it> |
| X-Original-To | Hannes Frederic Sowa <hannes@stressinduktion.org> |
| Dkim-Signature | v=1; a=rsa-sha256; c=relaxed/relaxed; d=rasmusvillemoes.dk; s=google; h=from:to:cc:subject:organization:references:date:in-reply-to :message-id:user-agent:mime-version:content-type; bh=+VwaJZKB/LIZnMaLSGnBajtMSAGbQqiLMHp7+ccUqi4=; b=XmMTfU76zs1OBgUrzNr8DHI+tpdEbT9M9dStbaDE81GITVPX93k7FRhhwsnnk1/ga4 3vX6e7HJ6Vb5TMBF4WrBCm/01/ovJqPzgr9q4b6wxwKfSJARMzn0/zrbFZdLwKaa49aT CM7Pg7/O/RQwz5rrONwwwtwIWyu2AUr4kO7+k= |
| X-Google-Dkim-Signature | v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:from:to:cc:subject:organization:references:date :in-reply-to:message-id:user-agent:mime-version:content-type; bh=+VwaJZKB/LIZnMaLSGnBajtMSAGbQqiLMHp7+ccUqi4=; b=fJNhoF98g9N1oBztkYpt1cwVS+hLbLYgWTBJn7USdLGVa9FExHZCu4CoAglcRNf42O utQnJcgvrZlGjlYt39/VpJvu8OfE8QsQIJbLvUlurrlxlc75tqnSHtgL+SFWWENluguu nMSkaKGnVkvSNO3j97WtdfGHSAISnldqgHEYzKS7K8QK3uMR/u1OyRSGmrtPQsrSfLb2 grQf85bDJf970IcqXvbC01+gJ96dE6zBlv75LweNxhO5S25kDDABAxNV1kngohfzELKQ z8YvgGXb5YUgcuCZL/+Ly49qzmVq5R8L7DvS/4/4d620P5LO3jEw1KS97jFWDV04yktf a2zA== |
| X-Gm-Message-State | ALoCoQltTbEUq7gvWD6/PpovAM3SIH6Q22y3ZXd3s/xlYbuJHcNSPt1JesbexRXotEwGIBsHfQzi |
| X-Received | by 10.25.32.144 with SMTP id g138mr2235836lfg.26.1447078618575; Mon, 09 Nov 2015 06:16:58 -0800 (PST) |
| Organization | D03 |
| X-Hashcash | 1:20:151109:torvalds@linux-foundation.org::QU5UFZZA7fXPPW41:000000000000000000000000000000000p8V |
| X-Hashcash | 1:20:151109:linux-kernel@vger.kernel.org::++Zd/ZnPpE/3N1eE:0000000000000000000000000000000003Xk/ |
| X-Hashcash | 1:20:151109:hannes@stressinduktion.org::nBfSNGkE7uM/P6RJ:000000000000000000000000000000000004diz |
| X-Hashcash | 1:20:151109:netdev@vger.kernel.org::urcNQPQJJ/JzrKfw:0000000000000000000000000000000000000006W8J |
| X-Hashcash | 1:20:151109:akpm@linux-foundation.org::u/NMIqHhzed6lOXg:0000000000000000000000000000000000007cVk |
| X-Hashcash | 1:20:151109:davem@davemloft.net::55tvA4TIEQNm2DRV:000000000000000000000000000000000000000000E+ZM |
| User-Agent | Gnus/5.13 (Gnus v5.13) Emacs/24.3 (gnu/linux) |
| MIME-Version | 1.0 |
| Content-Type | text/plain |
| Sender | robomod@news.nic.it |
| List-ID | <linux-kernel.vger.kernel.org> |
| X-Mailing-List | linux-kernel@vger.kernel.org |
| Approved | robomod@news.nic.it |
| Lines | 70 |
| X-Original-Cc | Linus Torvalds <torvalds@linux-foundation.org>, David Miller <davem@davemloft.net>, Andrew Morton <akpm@linux-foundation.org>, Network Development <netdev@vger.kernel.org>, Linux Kernel Mailing List <linux-kernel@vger.kernel.org> |
| X-Original-Date | Mon, 09 Nov 2015 15:16:56 +0100 |
| X-Original-Message-ID | <87a8qnz293.fsf@rasmusvillemoes.dk> |
| X-Original-References | <20151027.233235.1641084823622810663.davem@davemloft.net> <CA+55aFx0o8e9J6ojHYjvOA5aRnKoW5j10fh76Ks1=VegPc4k6w@mail.gmail.com> <1446030209.105419.422375497.14563933@webmail.messagingengine.com> <87pozzvzj6.fsf@rasmusvillemoes.dk> <1447070962.399769.433652241.038FDB6A@webmail.messagingengine.com> |
| X-Original-Sender | linux-kernel-owner@vger.kernel.org |
| Xref | csiph.com linux.kernel:1265711 |
Show key headers only | View raw
On Mon, Nov 09 2015, Hannes Frederic Sowa <hannes@stressinduktion.org> wrote:
> Hi,
>
> On Wed, Oct 28, 2015, at 15:27, Rasmus Villemoes wrote:
>>
>> I agree - proper overflow checking can be really hard. Quick, assuming a
>> and b have the same unsigned integer type, is 'a+b<a' sufficient to
>> check overflow? Of course not (hint: promotion rules). And as you say,
>> it gets even more complicated for signed types.
>>
>> A few months ago I tried posting a complete set of fallbacks for older
>> compilers (https://lkml.org/lkml/2015/7/19/358), but nothing really
>> happened. Now I know where Linus stands, so I guess I can just delete
>> that branch.
>
> I actually like your approach of being type agnostic a bit more (in
> comparison to static inline functions), mostly because of one specific
> reason:
>
> The type agnostic __builtin_*_overflow function even do the correct
> things if you deal with types smaller than int. Imagine e.g. you want to
> add to unsigned chars a and b,
If you read my mail again you'll see that I mentioned exactly this :-)
so obviously I agree that this is a nice part of it.
> unsigned char a, b;
> if (a + b < a)
> goto overflow;
> else
> a += b;
>
> The overflow condition will never trigger, as the comparisons will
> always be done in the integer domain and a + b < a is never true. I
> actually think that this is easy to overlook and the functions should
> handle that.
Yes. While people very rarely use local u8 or u16 variables for
computations, I think one could imagine a and b being struct members,
which for one reason or another happens to be of a type narrower than
int (which would also make the issue much harder to spot since the
struct definition is far away). Something like
combine_packets(struct foo *a, const struct foo *b)
{
if (a->len + b->len < a->len)
return -EOVERFLOW;
/* ensure a->payload is big enough...*/
memcpy(a->payload + a->len, b->payload, b->len);
a->len += b->len;
...
}
which, depending on details, would either lead to memory corruption or
loss of parts of the packets.
I haven't actually found any instance of this in the kernel, but that
doesn't mean it couldn't get introduced (or that it doesn't exist).
Aside: It turns out clang is smart enough to optimize away the broken
overflow check, but gcc isn't. Neither issue a warning, despite the
intention being rather clear.
Rasmus
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/
Back to linux.kernel | Previous | Next — Previous in thread | Find similar | Unroll thread
Re: [GIT] Networking Hannes Frederic Sowa <hannes@stressinduktion.org> - 2015-11-09 13:10 +0100 Re: [GIT] Networking Rasmus Villemoes <linux@rasmusvillemoes.dk> - 2015-11-09 15:20 +0100
csiph-web