From a03936f3bc13d1992524d787f142447ad2f0f1e5 Mon Sep 17 00:00:00 2001 From: Vladislav Bolkhovitin Date: Thu, 29 Jan 2009 12:19:22 +0000 Subject: [PATCH] Merge with IET r169: From: Shreyansh Jain Subject: [Patch 1/1] Segfault in ietd buffer overrun in dump_line Fix a buffer overrun problem in __dump_line function in log.c file. It also removes a stray 'return' call in log_pdu function which was restricting a PDU dump call to complete log_pdu operation. Also, in log_pdu function, the first check for log_level against passed parameter for log was incorrect and would have forced a return even when the caller has set the logging level to acceptable level. Signed-off-by: Shreyansh Jain git-svn-id: http://svn.code.sf.net/p/scst/svn/trunk@647 d57e44dd-8a1f-0410-8b47-8ef2f437770f --- iscsi-scst/usr/log.c | 24 +++++++++++++++++------- 1 file changed, 17 insertions(+), 7 deletions(-) diff --git a/iscsi-scst/usr/log.c b/iscsi-scst/usr/log.c index aaf1aaedb..4202c173b 100644 --- a/iscsi-scst/usr/log.c +++ b/iscsi-scst/usr/log.c @@ -87,15 +87,24 @@ void log_debug(int level, const char *fmt, ...) } } +/* Definition for log_pdu buffer */ +#define BUFFER_SIZE 16 + +/* + * size required for a hex dump of BUFFER_SIZE bytes (' ' + 2 chars = 3 chars + * per byte) with a ' |' separator each 4th byte: + */ +#define LINE_SIZE (BUFFER_SIZE * 3 + BUFFER_SIZE / 4 * 2 + 1) + static void __dump_line(int level, unsigned char *buf, int *cp) { - char line[16*3+5], *lp = line; + char line[LINE_SIZE], *lp = line; int i, cnt; cnt = *cp; if (!cnt) return; - for (i = 0; i < 16; i++) { + for (i = 0; i < BUFFER_SIZE; i++) { if (i < cnt) lp += sprintf(lp, " %02x", buf[i]); else @@ -105,7 +114,9 @@ static void __dump_line(int level, unsigned char *buf, int *cp) if (i >= cnt || !isprint(buf[i])) buf[i] = ' '; } - log_debug(level, "%s %.16s |", line, buf); + + /* buf is not \0-terminated! */ + log_debug(level, "%s %.*s |", line, BUFFER_SIZE, buf); *cp = 0; } @@ -114,7 +125,7 @@ static void __dump_char(int level, unsigned char *buf, int *cp, int ch) int cnt = (*cp)++; buf[cnt] = ch; - if (cnt == 15) + if (cnt == BUFFER_SIZE - 1) __dump_line(level, buf, cp); } @@ -123,13 +134,12 @@ static void __dump_char(int level, unsigned char *buf, int *cp, int ch) void log_pdu(int level, struct PDU *pdu) { - unsigned char char_buf[16]; + unsigned char char_buf[BUFFER_SIZE]; int char_cnt = 0; unsigned char *buf; int i; - return; - if (log_level <= level) + if (log_level < level) return; buf = (void *)&pdu->bhs;