Whamcloud - gitweb
LU-4423 ptlrpc: fix potential NULL pointer dereference 82/8682/2
authorOleg Drokin <oleg.drokin@intel.com>
Tue, 31 Dec 2013 01:50:28 +0000 (20:50 -0500)
committerOleg Drokin <oleg.drokin@intel.com>
Wed, 22 Jan 2014 02:08:21 +0000 (02:08 +0000)
The rest of the code seem to imply that rmf_dumper may indeed be
NULL.  Change the code so that dumping is not even considered if
rmf_dumper callback is not set.

Signed-off-by: Michal Nazarewicz <mina86@mina86.com>
Signed-off-by: Oleg Drokin <oleg.drokin@intel.com>
Change-Id: Iaea16aaf799976d08ebb51322021cc879db1c6d8
Reviewed-on: http://review.whamcloud.com/8682
Tested-by: Jenkins
Tested-by: Maloo <hpdd-maloo@intel.com>
Reviewed-by: Dmitry Eremin <dmitry.eremin@intel.com>
Reviewed-by: Emoly Liu <emoly.liu@intel.com>
Reviewed-by: Oleg Drokin <oleg.drokin@intel.com>
lustre/ptlrpc/layout.c

index 941c0e9..008f49d 100644 (file)
@@ -1908,8 +1908,11 @@ swabber_dumper_helper(struct req_capsule *pill,
         else
                 do_swab = 0;
 
         else
                 do_swab = 0;
 
+       if (!field->rmf_dumper)
+               dump = 0;
+
         if (!(field->rmf_flags & RMF_F_STRUCT_ARRAY)) {
         if (!(field->rmf_flags & RMF_F_STRUCT_ARRAY)) {
-                if (dump && field->rmf_dumper) {
+                if (dump) {
                         CDEBUG(D_RPCTRACE, "Dump of %sfield %s follows\n",
                                do_swab ? "unswabbed " : "", field->rmf_name);
                         field->rmf_dumper(value);
                         CDEBUG(D_RPCTRACE, "Dump of %sfield %s follows\n",
                                do_swab ? "unswabbed " : "", field->rmf_name);
                         field->rmf_dumper(value);
@@ -1918,7 +1921,7 @@ swabber_dumper_helper(struct req_capsule *pill,
                         return;
                 swabber(value);
                 ptlrpc_buf_set_swabbed(pill->rc_req, inout, offset);
                         return;
                 swabber(value);
                 ptlrpc_buf_set_swabbed(pill->rc_req, inout, offset);
-               if (dump && field->rmf_dumper) {
+               if (dump) {
                         CDEBUG(D_RPCTRACE, "Dump of swabbed field %s "
                                "follows\n", field->rmf_name);
                         field->rmf_dumper(value);
                         CDEBUG(D_RPCTRACE, "Dump of swabbed field %s "
                                "follows\n", field->rmf_name);
                         field->rmf_dumper(value);
@@ -1935,7 +1938,7 @@ swabber_dumper_helper(struct req_capsule *pill,
         for (p = value, i = 0, n = len / field->rmf_size;
              i < n;
              i++, p += field->rmf_size) {
         for (p = value, i = 0, n = len / field->rmf_size;
              i < n;
              i++, p += field->rmf_size) {
-                if (dump && field->rmf_dumper) {
+                if (dump) {
                         CDEBUG(D_RPCTRACE, "Dump of %sarray field %s, "
                                "element %d follows\n",
                                do_swab ? "unswabbed " : "", field->rmf_name, i);
                         CDEBUG(D_RPCTRACE, "Dump of %sarray field %s, "
                                "element %d follows\n",
                                do_swab ? "unswabbed " : "", field->rmf_name, i);
@@ -1944,7 +1947,7 @@ swabber_dumper_helper(struct req_capsule *pill,
                 if (!do_swab)
                         continue;
                 swabber(p);
                 if (!do_swab)
                         continue;
                 swabber(p);
-                if (dump && field->rmf_dumper) {
+                if (dump) {
                         CDEBUG(D_RPCTRACE, "Dump of swabbed array field %s, "
                                "element %d follows\n", field->rmf_name, i);
                         field->rmf_dumper(value);
                         CDEBUG(D_RPCTRACE, "Dump of swabbed array field %s, "
                                "element %d follows\n", field->rmf_name, i);
                         field->rmf_dumper(value);