mirror of
https://github.com/torvalds/linux.git
synced 2026-07-28 01:55:51 +02:00
The pcache target parses optional arguments as name/value pairs. A
table that advertises one optional argument and supplies only a
recognized option name, for example "cache_mode", reaches
parse_cache_opts() with argc == 1. The parser consumes the name,
decrements argc to zero, then calls dm_shift_arg() again for the value.
dm_shift_arg() returns NULL when no arguments remain, and the following
strcmp() dereferences that NULL pointer.
Check that each recognized option has a value before consuming it. This
keeps valid "cache_mode writeback" and "data_crc true/false" tables
unchanged while making malformed tables fail during target construction
with a precise missing-value error.
Assisted-by: Codex:gpt-5.5-cyber-preview
Signed-off-by: Samuel Moelius <sam.moelius@trailofbits.com>
Reviewed-by: Zheng Gu <cengku@gmail.com>
Signed-off-by: Mikulas Patocka <mpatocka@redhat.com>
Fixes:
|
||
|---|---|---|
| .. | ||
| backing_dev.c | ||
| backing_dev.h | ||
| cache_dev.c | ||
| cache_dev.h | ||
| cache_gc.c | ||
| cache_key.c | ||
| cache_req.c | ||
| cache_segment.c | ||
| cache_writeback.c | ||
| cache.c | ||
| cache.h | ||
| dm_pcache.c | ||
| dm_pcache.h | ||
| Kconfig | ||
| Makefile | ||
| pcache_internal.h | ||
| segment.c | ||
| segment.h | ||