Received: by 2002:a05:6358:11c7:b0:104:8066:f915 with SMTP id i7csp888189rwl; Fri, 24 Mar 2023 03:29:41 -0700 (PDT) X-Google-Smtp-Source: AKy350a3Jt+XBz2OJqay+mUTa8rRbIq6/WH01JBKN4PvgcKzlMk147WV6xS4xN19XAYt244QqF6D X-Received: by 2002:a17:907:1905:b0:8b1:3467:d71b with SMTP id ll5-20020a170907190500b008b13467d71bmr2379257ejc.48.1679653781085; Fri, 24 Mar 2023 03:29:41 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1679653781; cv=none; d=google.com; s=arc-20160816; b=xJfkMEKDwxLs9byD/s572lQsVMWDXX6wV4NGdg7uFrjqkoD2o8ezOmreRHwhutFRgZ tZG5LbqbdQ9i4W9eOG9ehVK+yaWxiOOc0g4uhOkPM0IkhLgrnfuRD2UihM+N+82s/50D yRwfiFas/936APswgkeTaBDks9F+D+vKJxzYD+A8H2js1rSK/00LjuR0ThvNeisVqPQw Hrs1Wkt45KnKLva8sv0lkLlDp9yREhHrhkJ+1G+F67EGdY/W2JkudEEEkicziG51cnGj ciMNxLwrbu1OKunl1IIUEEt5ocbJJuHyYkuPEmm3hNkl90VvkXPCYrzXC4sLeWaiQTUU Rmbw== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:in-reply-to:content-disposition:mime-version :references:message-id:subject:cc:to:from:date:dkim-signature; bh=VFdEpZgkMqY3jkdL4KU0Ps6zGuMFPWyX35+yWmsMQgk=; b=eVABbB1Y6jHo4qQ0RzaHXaIgHo6QAndeQONioeHKeatRx6elCVuIWDxTFdSFM7Jaqc iSRdMqPlMgkFZu/bpQA3ow5UskIZAss02A43dflQXh7zCxts+KaM80AiUFgGoF+kkf+5 xELgjgioLijIAPDqnTSC9wUdYooCS3xrxi2toZyMNPkfcjNbboB7WyLsOuj1NxaBYfVL 94Z1KE1IeGSaxpWnOFxlTo+Qux3APxB4kZXqoTJC/MGpRtpj5A3kyg2nLrER+OJUMybM rZeLT7cqkKr6xUt4nv0w7isKANNDifRWr+u6m8WJ1V6Vrul7duVBVgGvhOK9sCc2mR/L 4yHw== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@suse.com header.s=susede1 header.b="Xs+hNl/y"; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=QUARANTINE sp=QUARANTINE dis=NONE) header.from=suse.com Return-Path: Received: from out1.vger.email (out1.vger.email. [2620:137:e000::1:20]) by mx.google.com with ESMTP id oz31-20020a1709077d9f00b0093defbd6280si1820455ejc.1031.2023.03.24.03.29.14; Fri, 24 Mar 2023 03:29:41 -0700 (PDT) Received-SPF: pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) client-ip=2620:137:e000::1:20; Authentication-Results: mx.google.com; dkim=pass header.i=@suse.com header.s=susede1 header.b="Xs+hNl/y"; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=QUARANTINE sp=QUARANTINE dis=NONE) header.from=suse.com Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S231649AbjCXKQa (ORCPT + 99 others); Fri, 24 Mar 2023 06:16:30 -0400 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:55512 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S229536AbjCXKQ3 (ORCPT ); Fri, 24 Mar 2023 06:16:29 -0400 Received: from smtp-out2.suse.de (smtp-out2.suse.de [195.135.220.29]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id EA379136F3; Fri, 24 Mar 2023 03:16:27 -0700 (PDT) Received: from imap2.suse-dmz.suse.de (imap2.suse-dmz.suse.de [192.168.254.74]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-521) server-digest SHA512) (No client certificate requested) by smtp-out2.suse.de (Postfix) with ESMTPS id 7AAA21F898; Fri, 24 Mar 2023 10:16:26 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=suse.com; s=susede1; t=1679652986; h=from:from:reply-to:date:date:message-id:message-id:to:to:cc:cc: mime-version:mime-version:content-type:content-type: in-reply-to:in-reply-to:references:references; bh=VFdEpZgkMqY3jkdL4KU0Ps6zGuMFPWyX35+yWmsMQgk=; b=Xs+hNl/yRKg1wDMgjI39W1rFF/NLiFCJo8I8fqIgEc8No9Ouv0wCHOvK2/sNSPh0mxC5RK ZEnUBH90/GS1q3zhm/+pNwUc6EvZeGGbCHyfbNbMvMUFQwBx+eDiSWZAjJIYT0cd34E0IJ etx9CuLqw3wAHnb/xgzkkfjPodns7h8= Received: from imap2.suse-dmz.suse.de (imap2.suse-dmz.suse.de [192.168.254.74]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-521) server-digest SHA512) (No client certificate requested) by imap2.suse-dmz.suse.de (Postfix) with ESMTPS id 3D926138ED; Fri, 24 Mar 2023 10:16:26 +0000 (UTC) Received: from dovecot-director2.suse.de ([192.168.254.65]) by imap2.suse-dmz.suse.de with ESMTPSA id KV5VDXp4HWT1OgAAMHmgww (envelope-from ); Fri, 24 Mar 2023 10:16:26 +0000 Date: Fri, 24 Mar 2023 11:16:24 +0100 From: Michal =?utf-8?Q?Koutn=C3=BD?= To: Jens Axboe Cc: Josef Bacik , linux-block@vger.kernel.org, nbd@other.debian.org, linux-kernel@vger.kernel.org, Navid Emamdoost , Michal Kubecek Subject: Re: [PATCH RESEND v3] nbd_genl_status: null check for nla_nest_start Message-ID: <20230324101624.mnbagb3jxshucawq@blackpad> References: <20230323193032.28483-1-mkoutny@suse.com> <6c507b78-35fb-fe23-51f0-e5bb754679d0@kernel.dk> MIME-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-sha512; protocol="application/pgp-signature"; boundary="tly6jqa3p5uzjb5y" Content-Disposition: inline In-Reply-To: <6c507b78-35fb-fe23-51f0-e5bb754679d0@kernel.dk> X-Spam-Status: No, score=-2.5 required=5.0 tests=DKIM_SIGNED,DKIM_VALID, DKIM_VALID_AU,DKIM_VALID_EF,RCVD_IN_DNSWL_MED,SPF_HELO_NONE,SPF_PASS autolearn=unavailable autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on lindbergh.monkeyblade.net Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org --tly6jqa3p5uzjb5y Content-Type: text/plain; charset=utf-8 Content-Disposition: inline Content-Transfer-Encoding: quoted-printable Thanks for the reply. On Thu, Mar 23, 2023 at 04:51:17PM -0600, Jens Axboe wrot= e: > So please don't mix CVEs into any of this, they don't matter one bit. Do not shoot the messenger. (But I'll refrain from that numeric reference to disincentivize such trophy collecting.) > Never have, and never will. What's important is how the bug can be > triggered. =46rom my perspective it's pragmatic better-safe-than-sorry -- a proof may be conceived that rules out any triggering condition, it's less work to put the guard in though. My .02=E2=82=AC, Michal --tly6jqa3p5uzjb5y Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iHUEABYKAB0WIQTrXXag4J0QvXXBmkMkDQmsBEOquQUCZB14dgAKCRAkDQmsBEOq uQ71AQDGZxjMPEueZul0m/zsn0FkW1akNCWxkd5shBj5jiI4vAD/Ua8Gutx5iw+Y Sprxj5N+CO+W9Cw4P19YOI66IpM+wAQ= =4Dp8 -----END PGP SIGNATURE----- --tly6jqa3p5uzjb5y--