Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1408463 > unrolled thread

Re: [PATCH] ntb_tool: Fix infinite loop bug when writing spad/peer_spad file

Started byAllen Hubbe <allenbh@gmail.com>
First post2016-05-28 15:10 +0200
Last post2016-05-28 15:10 +0200
Articles 1 — 1 participant

Back to article view | Back to linux.kernel

This discussion starts older than the indexed window; earlier articles aren't shown. The article labeled Started by below is the oldest one visible, not the original post.


Contents

  Re: [PATCH] ntb_tool: Fix infinite loop bug when writing  spad/peer_spad file Allen Hubbe <allenbh@gmail.com> - 2016-05-28 15:10 +0200

#1408463 — Re: [PATCH] ntb_tool: Fix infinite loop bug when writing spad/peer_spad file

FromAllen Hubbe <allenbh@gmail.com>
Date2016-05-28 15:10 +0200
SubjectRe: [PATCH] ntb_tool: Fix infinite loop bug when writing spad/peer_spad file
Message-ID<rDMa5-Tn-1@gated-at.bofh.it>
On Fri, May 27, 2016 at 4:38 PM, Logan Gunthorpe <logang@deltatee.com> wrote:
> If you tried to write two spads in one line, as per the example:
>
> root@peer# echo '0 0x01010101 1 0x7f7f7f7f' > $DBG_DIR/peer_spad
>
> then the CPU would freeze in an infinite loop.
>
> This wasn't immediately obvious but 'pos' was not incrementing the
> buffer, so after reading the second pair of values, 'pos' would once
> again be 3 and it would re-read the second pair of values ad infinitum.
>
> Signed-off-by: Logan Gunthorpe <logang@deltatee.com>

Good catch.  Thanks Logan.

Acked-by: Allen Hubbe <Allen.Hubbe@emc.com>

> ---
>  drivers/ntb/test/ntb_tool.c | 9 +++++----
>  1 file changed, 5 insertions(+), 4 deletions(-)
>
> diff --git a/drivers/ntb/test/ntb_tool.c b/drivers/ntb/test/ntb_tool.c
> index 6f5dc6c..209ef7c 100644
> --- a/drivers/ntb/test/ntb_tool.c
> +++ b/drivers/ntb/test/ntb_tool.c
> @@ -268,7 +268,7 @@ static ssize_t tool_spadfn_write(struct tool_ctx *tc,
>  {
>         int spad_idx;
>         u32 spad_val;
> -       char *buf;
> +       char *buf, *buf_ptr;
>         int pos, n;
>         ssize_t rc;
>
> @@ -288,14 +288,15 @@ static ssize_t tool_spadfn_write(struct tool_ctx *tc,
>         }
>
>         buf[size] = 0;
> -
> -       n = sscanf(buf, "%d %i%n", &spad_idx, &spad_val, &pos);
> +       buf_ptr = buf;
> +       n = sscanf(buf_ptr, "%d %i%n", &spad_idx, &spad_val, &pos);
>         while (n == 2) {
> +               buf_ptr += pos;
>                 rc = spad_write_fn(tc->ntb, spad_idx, spad_val);
>                 if (rc)
>                         break;
>
> -               n = sscanf(buf + pos, "%d %i%n", &spad_idx, &spad_val, &pos);
> +               n = sscanf(buf_ptr, "%d %i%n", &spad_idx, &spad_val, &pos);
>         }
>
>         if (n < 0)
> --
> 2.1.4

[toc] | [standalone]


Back to top | Article view | linux.kernel


csiph-web