[PATCH] Fix buffer overflow and races in capi debug functions
The CAPI trace debug functions were using a fixed size buffer, which can be overflowed if wrong formatted CAPI messages were sent to the kernel capi layer. The code was also not protected against multiple callers. This fix bug 8028. Additionally the patch make the CAPI trace functions optional. Signed-off-by: Karsten Keil <kkeil@suse.de> Signed-off-by: Andrew Morton <akpm@linux-foundation.org> Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
This commit is contained in:
committed by
Linus Torvalds
parent
34bbd70405
commit
17f0cd2f35
@@ -174,9 +174,26 @@ char *capi_info2str(__u16 reason);
|
||||
/*
|
||||
* Debugging / Tracing functions
|
||||
*/
|
||||
|
||||
char *capi_cmd2str(__u8 cmd, __u8 subcmd);
|
||||
char *capi_cmsg2str(_cmsg * cmsg);
|
||||
char *capi_message2str(__u8 * msg);
|
||||
|
||||
typedef struct {
|
||||
u_char *buf;
|
||||
u_char *p;
|
||||
size_t size;
|
||||
size_t pos;
|
||||
} _cdebbuf;
|
||||
|
||||
#define CDEBUG_SIZE 1024
|
||||
#define CDEBUG_GSIZE 4096
|
||||
|
||||
_cdebbuf *cdebbuf_alloc(void);
|
||||
void cdebbuf_free(_cdebbuf *cdb);
|
||||
int cdebug_init(void);
|
||||
void cdebug_exit(void);
|
||||
|
||||
_cdebbuf *capi_cmsg2str(_cmsg *cmsg);
|
||||
_cdebbuf *capi_message2str(__u8 *msg);
|
||||
|
||||
/*-----------------------------------------------------------------------*/
|
||||
|
||||
|
Reference in New Issue
Block a user