Skip to content

Commit 172db56

Browse files
keeskuba-moo
authored andcommitted
netlink: Return unsigned value for nla_len()
The return value from nla_len() is never expected to be negative, and can never be more than struct nlattr::nla_len (a u16). Adjust the prototype on the function. This will let GCC's value range optimization passes know that the return can never be negative, and can never be larger than u16. As recently discussed[1], this silences the following warning in GCC 12+: net/wireless/nl80211.c: In function 'nl80211_set_cqm_rssi.isra': net/wireless/nl80211.c:12892:17: warning: 'memcpy' specified bound 18446744073709551615 exceeds maximum object size 9223372036854775807 [-Wstringop-overflow=] 12892 | memcpy(cqm_config->rssi_thresholds, thresholds, | ^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ 12893 | flex_array_size(cqm_config, rssi_thresholds, | ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ 12894 | n_thresholds)); | ~~~~~~~~~~~~~~ A future change would be to clamp the subtraction to make sure it never wraps around if nla_len is somehow less than NLA_HDRLEN, which would have the additional benefit of being defensive in the face of nlattr corruption or logic errors. Reported-by: kernel test robot <[email protected]> Closes: https://lore.kernel.org/oe-kbuild-all/[email protected]/ [1] Cc: Johannes Berg <[email protected]> Cc: Jeff Johnson <[email protected]> Cc: Michael Walle <[email protected]> Cc: Max Schulze <[email protected]> Link: https://lore.kernel.org/r/[email protected] Signed-off-by: Kees Cook <[email protected]> Link: https://lore.kernel.org/r/[email protected] Signed-off-by: Jakub Kicinski <[email protected]>
1 parent cf02bea commit 172db56

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

include/net/netlink.h

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1214,7 +1214,7 @@ static inline void *nla_data(const struct nlattr *nla)
12141214
* nla_len - length of payload
12151215
* @nla: netlink attribute
12161216
*/
1217-
static inline int nla_len(const struct nlattr *nla)
1217+
static inline u16 nla_len(const struct nlattr *nla)
12181218
{
12191219
return nla->nla_len - NLA_HDRLEN;
12201220
}

0 commit comments

Comments
 (0)