[PATCH] app/testpmd: fix segfault in flow rule parser

Mohammad Shuab Siddique <[email protected]>
Newsgroups org.dpdk.dev
Message-ID <[email protected]>
From: Artin Davari <[email protected]>

Replace temporary stack arrays in the flow rule parser with static
arrays in three parse functions - prefix spec, RSS type, and RSS
queue handling - to prevent invalid pointer access during parsing
of complex flow rules.

Fixes: c439a84f1a ("app/testpmd: fix build with MSVC on non-constant initializer")
Cc: [email protected]

Signed-off-by: Artin Davari <[email protected]>
---
 app/test-pmd/cmdline_flow.c | 9 ++++++---
 1 file changed, 6 insertions(+), 3 deletions(-)

diff --git a/app/test-pmd/cmdline_flow.c b/app/test-pmd/cmdline_flow.c
index fbbe36233b..661a05f59f 100644
--- a/app/test-pmd/cmdline_flow.c
+++ b/app/test-pmd/cmdline_flow.c
@@ -8859,6 +8859,7 @@ parse_vc_spec(struct context *ctx, const struct token *token,
 	      const char *str, unsigned int len,
 	      void *buf, unsigned int size)
 {
+	static const enum index next_prefix[] = { COMMON_PREFIX, ZERO };
 	struct buffer *out = buf;
 	struct rte_flow_item *item;
 	uint32_t data_size;
@@ -8885,7 +8886,7 @@ parse_vc_spec(struct context *ctx, const struct token *token,
 		/* Modify next token to expect a prefix. */
 		if (ctx->next_num < 2)
 			return -1;
-		ctx->next[ctx->next_num - 2] = NEXT_ENTRY(COMMON_PREFIX);
+		ctx->next[ctx->next_num - 2] = next_prefix;
 		/* Fall through. */
 	case ITEM_PARAM_MASK:
 		index = 2;
@@ -9327,6 +9328,7 @@ parse_vc_action_rss_type(struct context *ctx, const struct token *token,
 			  const char *str, unsigned int len,
 			  void *buf, unsigned int size)
 {
+	static const enum index next_rss_type[] = { ACTION_RSS_TYPE, ZERO };
 	struct action_rss_data *action_rss_data;
 	unsigned int i;
 
@@ -9352,7 +9354,7 @@ parse_vc_action_rss_type(struct context *ctx, const struct token *token,
 	/* Repeat token. */
 	if (ctx->next_num == RTE_DIM(ctx->next))
 		return -1;
-	ctx->next[ctx->next_num++] = NEXT_ENTRY(ACTION_RSS_TYPE);
+	ctx->next[ctx->next_num++] = next_rss_type;
 	if (!ctx->object)
 		return len;
 	action_rss_data = ctx->object;
@@ -9370,6 +9372,7 @@ parse_vc_action_rss_queue(struct context *ctx, const struct token *token,
 			  const char *str, unsigned int len,
 			  void *buf, unsigned int size)
 {
+	static const enum index next_rss_queue[] = { ACTION_RSS_QUEUE, ZERO };
 	struct action_rss_data *action_rss_data;
 	const struct arg *arg;
 	int ret;
@@ -9402,7 +9405,7 @@ parse_vc_action_rss_queue(struct context *ctx, const struct token *token,
 	/* Repeat token. */
 	if (ctx->next_num == RTE_DIM(ctx->next))
 		return -1;
-	ctx->next[ctx->next_num++] = NEXT_ENTRY(ACTION_RSS_QUEUE);
+	ctx->next[ctx->next_num++] = next_rss_queue;
 end:
 	if (!ctx->object)
 		return len;
-- 
2.47.3
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.