Received: by 10.192.165.148 with SMTP id m20csp795945imm; Wed, 25 Apr 2018 07:49:27 -0700 (PDT) X-Google-Smtp-Source: AIpwx4+b8bzXgXpD4vrVeT1pt581CNup8e6LksoBji722TjA2gyiDSbX+vlyqMEOUxZXyrmEwGGk X-Received: by 2002:a17:902:2702:: with SMTP id c2-v6mr25159008plb.297.1524667767143; Wed, 25 Apr 2018 07:49:27 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1524667767; cv=none; d=google.com; s=arc-20160816; b=pOYlmJ/wp+QQEzmTuW5TDxNPOrW3vYOOJCyvSSt3mRqTKvfgw/DLorvMz3WNYtZoN3 dYDgty6BlwzLHA4TSEl7J6HBaimcooHMBf7+TREBheBVR800DY0hOQ8MNYjrQy3FtYTZ 4601pj5O1bFi821rPzpQ2Ct/xtkank5z4lGMYcMnOvtIzzxg8Wq3gWzdHzOCYfO1zYoo LhTY36BDyGPaOdZ1rX2z8ctszRvS83KZPiqH5O39cYMiZ+UPqALJoWooqTAw9F35BSIC 2sS9d5dufd1XT+73e6CtYtc4Lyaif4Oeop362rB80xyFrPuWAj3nuBGLBaMpTx/HVWah MTNQ== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:sender:content-disposition:mime-version :message-id:subject:cc:to:from:date:dkim-signature :arc-authentication-results; bh=2tQsBi2Tvy9BONFoyp+Kg7ZktJ0b81Z5QNCojos7+ZM=; b=BL/k/9sb+FDlAI2eXJ/rWKBpQ5aCf/fwZo8XSgekVVsqzDmRWqx88tPWR2SQ7FIJ/J AnYE18o24/iYNgiQ4POcaktHX+2RGEzGuXcm1RMSJ6l08Ym/RCmAd6Z08lpOn4VOBiTo I5jQd1DNJwAozSaY4M9dOpBOZBcMGWfX+swabM4Aq91uCHkTPSEsNw18zUrgE9Opvw11 FHATf5FS6mxoK/EMdbU2q/wPbQI8VVCQUk7HBEH+gjQRLv+R5z68WjjqbjUcnhdNghuo 3QagGEUBaGixLDMbMNr6KIdmHMgQrKFr+rhhNMZleWDJR5gogaoVwFujV0HBSbKB2KD+ /saQ== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@chromium.org header.s=google header.b=Iv0LWIpJ; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=chromium.org Return-Path: Received: from vger.kernel.org (vger.kernel.org. [209.132.180.67]) by mx.google.com with ESMTP id k2-v6si16496916plt.406.2018.04.25.07.49.12; Wed, 25 Apr 2018 07:49:27 -0700 (PDT) Received-SPF: pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) client-ip=209.132.180.67; Authentication-Results: mx.google.com; dkim=pass header.i=@chromium.org header.s=google header.b=Iv0LWIpJ; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=chromium.org Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1754757AbeDYOqr (ORCPT + 99 others); Wed, 25 Apr 2018 10:46:47 -0400 Received: from mail-pg0-f68.google.com ([74.125.83.68]:42250 "EHLO mail-pg0-f68.google.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1753571AbeDYOqm (ORCPT ); Wed, 25 Apr 2018 10:46:42 -0400 Received: by mail-pg0-f68.google.com with SMTP id e12so13500662pgn.9 for ; Wed, 25 Apr 2018 07:46:42 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=chromium.org; s=google; h=date:from:to:cc:subject:message-id:mime-version:content-disposition; bh=2tQsBi2Tvy9BONFoyp+Kg7ZktJ0b81Z5QNCojos7+ZM=; b=Iv0LWIpJ0oby74L/uohhFtfuoAqB4LIkO6/gbJ4h1yr/E9Vk7CL/oIVo3VIDFIJNxs EQGqNW/nHQh+x2yepCVZGQfS+2G95IH+XbHm3gNiBjz5nBirIftqqp0hCgF6jgk6S0g/ 6cYgG1DLAr9AdzeSS71fG12r3mKioliKCc+yc= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:date:from:to:cc:subject:message-id:mime-version :content-disposition; bh=2tQsBi2Tvy9BONFoyp+Kg7ZktJ0b81Z5QNCojos7+ZM=; b=shzl3O3790ac4pSq3MgtjX1aIP9rsZWjrNzzXk8D4jBJ+MnG8HRTv+/fRGhBRuy9Ga sHFl4c+f+sxcDpJTPTRRoNlVmkrCrX7beRSwQuBcvvNYJoLZNU085a/u8jIJNw5OL2Sr VVczKf3dpeYzNVOrJXv8glEmGovh80tlhaOVTK1XaO+IayNV1wBMwjJKJTtK3je1zsN1 SRKuPH9tcgcQID/tgXeWPf+ZJAkLe9eAmSonFZ4NucJsK30cf9PGT19adhHYnU7fPxfj eqngdwErIzvQ3Ayg2N99FoxS8YPc2JlEdY7juOHWsNfMAuseMByNXLy6/WOqbOhxkOH6 sdUA== X-Gm-Message-State: ALQs6tBE8kwBSU5YkUtEf9Bu3XGaMUvvaNd1Bp3qTZX0gLV5qp50rSyP lPYQO/aO2vm+aloDHgYzcfLJnw== X-Received: by 10.98.72.209 with SMTP id q78mr22822909pfi.70.1524667602141; Wed, 25 Apr 2018 07:46:42 -0700 (PDT) Received: from www.outflux.net (173-164-112-133-Oregon.hfc.comcastbusiness.net. [173.164.112.133]) by smtp.gmail.com with ESMTPSA id a76sm37028251pfc.97.2018.04.25.07.46.40 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Wed, 25 Apr 2018 07:46:40 -0700 (PDT) Date: Wed, 25 Apr 2018 07:46:39 -0700 From: Kees Cook To: Stefano Brivio Cc: Andreas Christoforou , kernel-hardening@lists.openwall.com, Steffen Klassert , Herbert Xu , "David S. Miller" , Alexey Kuznetsov , Hideaki YOSHIFUJI , netdev@vger.kernel.org, linux-kernel@vger.kernel.org Subject: [PATCH v4 ipsec-next] xfrm: remove VLA usage in __xfrm6_sort() Message-ID: <20180425144639.GA38350@beast> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline Sender: linux-kernel-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org In the quest to remove all stack VLA usage removed from the kernel[1], just use XFRM_MAX_DEPTH as already done for the "class" array. In one case, it'll do this loop up to 5, the other caller up to 6. [1] https://lkml.org/lkml/2018/3/7/621 Co-developed-by: Andreas Christoforou Signed-off-by: Kees Cook --- v4: - actually remove memset(). :) v3: - adjust Subject and commit log (Steffen) - use "= { }" instead of memset() (Stefano) v2: - use XFRM_MAX_DEPTH for "count" array (Steffen and Mathias). --- net/ipv6/xfrm6_state.c | 6 ++---- 1 file changed, 2 insertions(+), 4 deletions(-) diff --git a/net/ipv6/xfrm6_state.c b/net/ipv6/xfrm6_state.c index 16f434791763..5bdca3d5d6b7 100644 --- a/net/ipv6/xfrm6_state.c +++ b/net/ipv6/xfrm6_state.c @@ -60,11 +60,9 @@ xfrm6_init_temprop(struct xfrm_state *x, const struct xfrm_tmpl *tmpl, static int __xfrm6_sort(void **dst, void **src, int n, int (*cmp)(void *p), int maxclass) { - int i; + int count[XFRM_MAX_DEPTH] = { }; int class[XFRM_MAX_DEPTH]; - int count[maxclass]; - - memset(count, 0, sizeof(count)); + int i; for (i = 0; i < n; i++) { int c; -- 2.7.4 -- Kees Cook Pixel Security