From nobody Sat Jul 25 23:05:42 2026 Received: from mail-qk1-f178.google.com (mail-qk1-f178.google.com [209.85.222.178]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 539022848AA for ; Sat, 11 Jul 2026 21:32:35 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.222.178 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783805556; cv=none; b=qcBZsYRUgKXbUnrp1ZnigZM0cJsfyLSG69sXw8MGhy/BtDxXzP8p8tkivp6Ldpb9VxB2Jk280JErFquQFNW6vrLwPpSpL8nNFZf9D08I2MibAmRN3/f8xZBCx4jn9b8B8wP801Nr5IQxoP/idBOmNcE6K0TjyHZLIyBoKgBKjrI= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783805556; c=relaxed/simple; bh=whHC7evA/Rki95/reKmWsGL3Q0GMWVKXtGV9avTnHqM=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=NtMi6lWzug2bhFxNhYoNleKiRcidaCWfTIOv6HNYsJTkB6/Y+vJBrqNdGk+dR49W7OkR7Cs+A2rUHNdt5o125mTDBMiyXdCUDWdeVuoNuf/iEt5ZOU4JULM5mNPvqgwmbLf4OR+rkHDnl0Wpimu+tw6oljvgEDYkAnFscocSTQo= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=trailofbits.com; spf=pass smtp.mailfrom=trailofbits.com; dkim=pass (2048-bit key) header.d=trailofbits.com header.i=@trailofbits.com header.b=ZCgtjST9; arc=none smtp.client-ip=209.85.222.178 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=trailofbits.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=trailofbits.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=trailofbits.com header.i=@trailofbits.com header.b="ZCgtjST9" Received: by mail-qk1-f178.google.com with SMTP id af79cd13be357-92e5d6f35c1so162531085a.0 for ; Sat, 11 Jul 2026 14:32:35 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=trailofbits.com; s=google; t=1783805554; x=1784410354; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=8UqbOjw1q3tH4t8WYE4rrBWgeX7dwDK+/vr1kT1JA74=; b=ZCgtjST9SAM6hTvElZID19sPCdShsJ47x79WkP8JB0DaKGW50vcB3d83G7Mq0s31f3 hr3wriN4D3Ddv31WvPxDnk27AT7c4dVJgvUW+swuvKDmZLuJ+twC0aY45+j0se5PLUla PwzkwTH7d1++K6NrMRJ91bmMYVP83aRZVvjw2E8C1ud0PxRP5pgPFSet/dAAurktIvaW rAr4RepWXxHvfV/x4MElpFV8oSfCOyZnZz/qUYIFMZ+gaI3BMViDXn2c2UM52akeil2v N85ZCx0pOah+362AaSERoIjE0Gb24sJJ60wM8irRctoQ6j3xRfvXHlSfmv/yd8SWVR7h 2hvA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1783805554; x=1784410354; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=8UqbOjw1q3tH4t8WYE4rrBWgeX7dwDK+/vr1kT1JA74=; b=DWrl2h2UdCD+n+bGxuLx6f3x24XiZJ/B5QQXZzOnnpLXxljk/FBoPrmswatdhZ8Qgs BmyFvGsBpnbYXaCrvR64tY1zT6cZAgvF9YBHHOlyWCYj5iPglCcvocgRBO2vZ6wH0nMU QlvRqnsEjUrmtFxM3kb4Vw+sHAOJPA9wmok49EufaVb7t5Bf+ZBaEY6KeLoWvZYHBl+I mDXtfRWcFwci/+bmq0JykRUKOFSR+DoDTbWYVauW0b+SMzr7zUcFPxFnGLEhJ1zLs7BT aJYkmR/Mc0M3XQwluO6UCNCDn5sZxJjSxgbKMU+ag6txgA9iJHlB5cj6GGbcpeQnOunG FZpA== X-Forwarded-Encrypted: i=1; AHgh+RovJJMNXjTEvjb5k/hHE77q06wCWAVWblYbsWQAZOFX1E23YcBHnt41Wd78aRVAXvUZf/pP1zDj/ul+E0Y=@vger.kernel.org X-Gm-Message-State: AOJu0Yx8fjWEpUo6WMloTAgKu91YlshZXGZsUwzgolCB+wsNgZYiDTN7 cYgeXMwJFKVDTXBNpDlPLy3QLsF46L16WuUp36pk35STvFv00xO2IkC1/dTJSd1sREEjyNRszWE 0tprr X-Gm-Gg: AfdE7cm+r60m4UlqYJKX2bhYyn1hQVRgcrRKGjOoF2BVvwhi1AI0nO+aYlf306mY7rn dty2kNjDlzjXALLwhGEZrDZlbAyekGbTyAiXMeazZ4YSmKLIYIH4zhfkESzw5etDoQID+dmVJl7 OhW2C3eo+o/oTqVDXQ4DOT9qsUW3G63JafDhLE30eBnM7mKR/woEAB+kbVakxA5O3wbT1m1V8ph 1qO47B/lEv/jVONzoqHlF4A0GEpBdEekZWLCkf/WnXHicqmGimb3j6z1k4DzQmOyuH3/7VkYJl5 fpzsumkE7jJoiMyyKHglcpZGMpDpubJrGd2gp6zhasqlSYEPXo7Ls212wNklA3FGAaTpGNbxlST +c3GRZK6C3r13Bimd0cKhznCnc0ydBsnUEd2J0n273pPkrXeE3FjRuhTxWw0FVrV4ZiNMMTQ3rC iPrWhRD9N08k3p259I X-Received: by 2002:a05:620a:29d3:b0:92e:c118:18b0 with SMTP id af79cd13be357-92ef2cd2b9cmr419919185a.79.1783805554202; Sat, 11 Jul 2026 14:32:34 -0700 (PDT) Received: from localhost ([161.35.96.86]) by smtp.gmail.com with UTF8SMTPSA id af79cd13be357-92ee5b492ebsm554484185a.9.2026.07.11.14.32.33 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Sat, 11 Jul 2026 14:32:33 -0700 (PDT) From: Samuel Moelius To: Alasdair Kergon Cc: Samuel Moelius , Mike Snitzer , Mikulas Patocka , Benjamin Marzinski , dm-devel@lists.linux.dev (open list:DEVICE-MAPPER (LVM)), linux-kernel@vger.kernel.org (open list) Subject: [PATCH v3] dm cache: parse invalidate_cblocks with kstrtouint() Date: Sat, 11 Jul 2026 21:28:54 +0000 Message-ID: <20260711212849.92086.ae319593b1e2.dm-cache-invalidate-cblock-truncation@trailofbits.com> X-Mailer: git-send-email 2.43.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" invalidate_cblocks parses cache block numbers with sscanf() and then stores them in the narrower dm_cblock_t type. Values larger than the cblock representation are truncated before invalidation, so a request for one cache block can invalidate a different block. Checking the parsed value after sscanf() is not sufficient because sscanf() does not reliably reject values beyond U64_MAX before storing into the destination. Such inputs can still be converted to a wrapped u64 value and then pass a later range check. Split ranges in place and parse each single value or range endpoint directly with kstrtouint() instead. This rejects malformed values and values that do not fit in dm_cblock_t before they can be converted to cblock values. The existing range validation continues to reject empty or out-of-cache ranges, including the single-value U32_MAX case whose exclusive end wraps to zero. Assisted-by: Codex:gpt-5.5-cyber-preview Signed-off-by: Samuel Moelius --- Changes in v3: - Parse begin once - Keep happy path unindented - Print rejected token when parsing fails Changes in v2: - Now splits in place and parses directly as u32 drivers/md/dm-cache-target.c | 54 ++++++++++++++++++------------------ 1 file changed, 27 insertions(+), 27 deletions(-) diff --git a/drivers/md/dm-cache-target.c b/drivers/md/dm-cache-target.c index 097315a9bf0f..3c08c12dee21 100644 --- a/drivers/md/dm-cache-target.c +++ b/drivers/md/dm-cache-target.c @@ -16,6 +16,7 @@ #include #include #include +#include #include #include #include @@ -3311,42 +3312,46 @@ struct cblock_range { dm_cblock_t end; }; =20 +static inline dm_cblock_t cblock_succ(dm_cblock_t b) +{ + return to_cblock(from_cblock(b) + 1); +} + /* * A cache block range can take two forms: * * i) A single cblock, eg. '3456' * ii) A begin and end cblock with a dash between, eg. 123-234 */ -static int parse_cblock_range(struct cache *cache, const char *str, +static int parse_cblock_range(struct cache *cache, char *str, struct cblock_range *result) { - char dummy; - uint64_t b, e; + char *blocknr =3D strsep(&str, "-"); + unsigned int b, e; int r; =20 - /* - * Try and parse form (ii) first. - */ - r =3D sscanf(str, "%llu-%llu%c", &b, &e, &dummy); + r =3D kstrtouint(blocknr, 10, &b); + if (r) + goto bad; =20 - if (r =3D=3D 2) { - result->begin =3D to_cblock(b); - result->end =3D to_cblock(e); - return 0; - } + result->begin =3D to_cblock(b); =20 - /* - * That didn't work, try form (i). - */ - r =3D sscanf(str, "%llu%c", &b, &dummy); + if (str) { + blocknr =3D str; + + r =3D kstrtouint(blocknr, 10, &e); + if (r) + goto bad; =20 - if (r =3D=3D 1) { - result->begin =3D to_cblock(b); - result->end =3D to_cblock(from_cblock(result->begin) + 1u); + result->end =3D to_cblock(e); return 0; } =20 - DMERR("%s: invalid cblock range '%s'", cache_device_name(cache), str); + result->end =3D cblock_succ(result->begin); + return 0; + +bad: + DMERR("%s: invalid cblock range '%s'", cache_device_name(cache), blocknr); return -EINVAL; } =20 @@ -3377,11 +3382,6 @@ static int validate_cblock_range(struct cache *cache= , struct cblock_range *range return 0; } =20 -static inline dm_cblock_t cblock_succ(dm_cblock_t b) -{ - return to_cblock(from_cblock(b) + 1); -} - static int request_invalidation(struct cache *cache, struct cblock_range *= range) { int r =3D 0; @@ -3405,7 +3405,7 @@ static int request_invalidation(struct cache *cache, = struct cblock_range *range) } =20 static int process_invalidate_cblocks_message(struct cache *cache, unsigne= d int count, - const char **cblock_ranges) + char **cblock_ranges) { int r =3D 0; unsigned int i; @@ -3460,7 +3460,7 @@ static int cache_message(struct dm_target *ti, unsign= ed int argc, char **argv, } =20 if (!strcasecmp(argv[0], "invalidate_cblocks")) - return process_invalidate_cblocks_message(cache, argc - 1, (const char *= *) argv + 1); + return process_invalidate_cblocks_message(cache, argc - 1, argv + 1); =20 if (argc !=3D 2) return -EINVAL; --=20 2.43.0