Received: by 2002:a05:6358:7058:b0:131:369:b2a3 with SMTP id 24csp1200432rwp; Thu, 13 Jul 2023 07:34:18 -0700 (PDT) X-Google-Smtp-Source: APBJJlENSA//UdukAVjVeLayHVt8Hb10w9IXC0gzEj/7kHIoizkJ0vnqi3b/P0NJiAdyBSO1tz/T X-Received: by 2002:a05:6a21:a101:b0:133:61e8:5350 with SMTP id aq1-20020a056a21a10100b0013361e85350mr816092pzc.22.1689258858195; Thu, 13 Jul 2023 07:34:18 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1689258858; cv=none; d=google.com; s=arc-20160816; b=xq/guR96qgKMo0xi10tJzz7uiYWekfNp42xeQBGoTNXKJ1oV2HYEPJlULjcw60XSoi +aPTtS1q3zn8SxU2nzkY0nIvSGzWaSOJB271wIgkVIHhoSGmY6OvkrCHgkc+yNXqEHse 2UsxT1LZOGtWoDEqnBEf24q1lUBBAeZ+4OP65clCJnehxKZy6Rogf8IZ7YPTjXX2gMNw yPTzGYniJ8kSFl4wi+5IcgtpGeJFlZeajvLmBSjthbvyoiG8xKxXgIYey1R+OJsfYY8j 7rzVNfWqChl5zIzWEIZeQ8sLaBIf16JqOPWxGwwL2JAEaFsFSvJeRAhUZP026RwfnclE HGIA== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:content-transfer-encoding:content-language :mime-version:accept-language:in-reply-to:references:message-id:date :thread-index:thread-topic:subject:cc:to:from; bh=1tWLZnL6TQkUUaLluwfSbzr34/D3RJ3hQRDQ94D4B38=; fh=rtxtJTM/qXt8hnZVJdqEIChmugwJ/9p6Us5ARnAoRUk=; b=Xdv8LAQHMtctruDezUqBCS0E/zmp+JkgWO6XnUyEdc5f7n0Dv9zGWgDppQY1TdM4aW k8IFIX8W+F2MXWwMldTRHUxMvhkl8dRwxeLTnNyklRvadSmAE0NNT3kyqMEWMcajgoLI njyenJbmvLGxvxDeApCnXnmUjFgDleuGNsyYm2T5OHLMF48x8JWNNthlSc3Re7z7m65j bDCkRMuaxWABi5gN0zwmeNreYoUIK5tDNj6GaqryGvKq6MYeiXaHaCn0kX80eb/SYuai JgZ7pemtl8eBhsot/LMO7u5QQ+qyzalZXTyHXHVynf1gcR9JXNOxH31MkP8I9OYixuzr gGgw== ARC-Authentication-Results: i=1; mx.google.com; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=aculab.com Return-Path: Received: from out1.vger.email (out1.vger.email. [2620:137:e000::1:20]) by mx.google.com with ESMTP id dw13-20020a056a00368d00b006785d3c33e9si5161227pfb.340.2023.07.13.07.34.05; Thu, 13 Jul 2023 07:34:18 -0700 (PDT) Received-SPF: pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) client-ip=2620:137:e000::1:20; Authentication-Results: mx.google.com; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=aculab.com Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S234813AbjGMOLM convert rfc822-to-8bit (ORCPT + 99 others); Thu, 13 Jul 2023 10:11:12 -0400 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:58594 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S233242AbjGMOLK (ORCPT ); Thu, 13 Jul 2023 10:11:10 -0400 Received: from eu-smtp-delivery-151.mimecast.com (eu-smtp-delivery-151.mimecast.com [185.58.85.151]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id C17FC2702 for ; Thu, 13 Jul 2023 07:11:06 -0700 (PDT) Received: from AcuMS.aculab.com (156.67.243.121 [156.67.243.121]) by relay.mimecast.com with ESMTP with both STARTTLS and AUTH (version=TLSv1.2, cipher=TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384) id uk-mta-144-1i9aKoPaM_W-GNyv47tB6g-1; Thu, 13 Jul 2023 15:11:03 +0100 X-MC-Unique: 1i9aKoPaM_W-GNyv47tB6g-1 Received: from AcuMS.Aculab.com (10.202.163.4) by AcuMS.aculab.com (10.202.163.4) with Microsoft SMTP Server (TLS) id 15.0.1497.48; Thu, 13 Jul 2023 15:11:02 +0100 Received: from AcuMS.Aculab.com ([::1]) by AcuMS.aculab.com ([::1]) with mapi id 15.00.1497.048; Thu, 13 Jul 2023 15:11:02 +0100 From: David Laight To: 'Dan Carpenter' , Linke Li CC: "linux-fsdevel@vger.kernel.org" , "linux-kernel@vger.kernel.org" , Jan Kara , Linke Li Subject: RE: [PATCH] isofs: fix undefined behavior in iso_date() Thread-Topic: [PATCH] isofs: fix undefined behavior in iso_date() Thread-Index: AQHZsxUvEtRKesRhGUaBvhjBmnh2ha+3wHiQ Date: Thu, 13 Jul 2023 14:11:02 +0000 Message-ID: References: <79582844-3178-451c-822e-a692bfd27e9c@moroto.mountain> In-Reply-To: <79582844-3178-451c-822e-a692bfd27e9c@moroto.mountain> Accept-Language: en-GB, en-US X-MS-Has-Attach: X-MS-TNEF-Correlator: x-ms-exchange-transport-fromentityheader: Hosted x-originating-ip: [10.202.205.107] MIME-Version: 1.0 X-Mimecast-Spam-Score: 0 X-Mimecast-Originator: aculab.com Content-Language: en-US Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8BIT X-Spam-Status: No, score=-1.9 required=5.0 tests=BAYES_00,PDS_BAD_THREAD_QP_64, RCVD_IN_DNSWL_BLOCKED,RCVD_IN_MSPIKE_H5,RCVD_IN_MSPIKE_WL, SPF_HELO_NONE,SPF_PASS,T_SCC_BODY_TEXT_LINE autolearn=ham autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on lindbergh.monkeyblade.net Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org From: Dan Carpenter > Sent: 10 July 2023 10:57 > > It looks like maybe there is an issue with "year" as well. > > fs/isofs/util.c > 19 int iso_date(u8 *p, int flag) > 20 { > 21 int year, month, day, hour, minute, second, tz; > 22 int crtime; > 23 > 24 year = p[0]; > ^^^^^ > year is 0-255. .... > 32 > 33 if (year < 0) { > ^^^^^^^^ > But this checks year for < 0 which is impossible. Should it be: > > year = (signed char)p[0];? Or not? What happens in 2027 ? I bet the value has to be treated an unsigned. > > 34 crtime = 0; > 35 } else { > 36 crtime = mktime64(year+1900, month, day, hour, minute, second); > 37 > 38 /* sign extend */ > 39 if (tz & 0x80) > 40 tz |= (-1 << 8); Just change the definition of tz from 'int' to 's8' and it will all happen 'by magic'. David - Registered Address Lakeside, Bramley Road, Mount Farm, Milton Keynes, MK1 1PT, UK Registration No: 1397386 (Wales)