lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite for Android: free password hash cracker in your pocket
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <20120801145006.GG2528@krava.brq.redhat.com>
Date:	Wed, 1 Aug 2012 16:50:06 +0200
From:	Jiri Olsa <jolsa@...hat.com>
To:	David Ahern <dsahern@...il.com>
Cc:	acme@...hat.com, a.p.zijlstra@...llo.nl, mingo@...e.hu,
	paulus@...ba.org, cjashfor@...ux.vnet.ibm.com, fweisbec@...il.com,
	eranian@...gle.com, gorcunov@...nvz.org, tzanussi@...il.com,
	mhiramat@...hat.com, robert.richter@....com, fche@...hat.com,
	linux-kernel@...r.kernel.org, masami.hiramatsu.pt@...achi.com,
	drepper@...il.com, asharma@...com, benjamin.redelings@...cent.org
Subject: Re: [PATCH 13/13] perf, tool: Support for dwarf mode callchain on
 perf record

On Wed, Aug 01, 2012 at 08:26:11AM -0600, David Ahern wrote:
> On 8/1/12 4:11 AM, Jiri Olsa wrote:
> >+static int
> >+parse_callchain_opt(const struct option *opt __used, const char *arg,
> >+		    int unset)
> >+{
> >+	struct perf_record *rec = (struct perf_record *)opt->value;
> >+	char *tok, *name, *saveptr = NULL;
> >+	char buf[20];
> >+	int ret = -1;
> >+
> >+	/* --no-call-graph */
> >+	if (unset)
> >+		return 0;
> >+
> >+	/* We specified default option if none is provided. */
> >+	BUG_ON(!arg);
> >+
> >+	/* We need buffer that we know we can write to. */
> >+	snprintf(buf, 20, "%s", arg);
> 
> Isn't arg the user supplied string? What if the user messes up and
> passes in 20+ characters to -g argument?

  [jolsa@...p-26-214 perf]$ ./perf record -g dwarf123213214321432143214321432143214321432143214321 ls
  callchain: Unknown -g option value: dwarf12321321432143
  ...

hm, but if user specified it like this:

  [jolsa@...p-26-214 perf]$ ./perf record -vg 'dwarf,                    50000' ls
  callchain: Incorrect stack dump size (max 65528):              

then we're in trouble.. I'll send a fix

thanks,
jirka
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@...r.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ