From: Artin Davari <[email protected]>

Replace temporary stack arrays in the flow rule parser with static
arrays in three parse functions - prefix spec, RSS type, and RSS
queue handling - to prevent invalid pointer access during parsing
of complex flow rules.

NEXT_ENTRY() expands to a compound literal, which has automatic
storage duration when used inside a function body. The parser stores
the resulting pointer in ctx->next[], which is dereferenced after the
function returns, so the stack storage backing it is no longer valid
by the time it is accessed. Declaring the arrays 'static const' gives
them a lifetime that outlives the call, fixing the dangling pointer.

Fixes: c439a84f1a78 ("app/testpmd: fix build with MSVC on non-constant 
initializer")
Cc: [email protected]

Signed-off-by: Artin Davari <[email protected]>
---
 app/test-pmd/cmdline_flow.c | 9 ++++++---
 1 file changed, 6 insertions(+), 3 deletions(-)

diff --git a/app/test-pmd/cmdline_flow.c b/app/test-pmd/cmdline_flow.c
index fbbe36233b..661a05f59f 100644
--- a/app/test-pmd/cmdline_flow.c
+++ b/app/test-pmd/cmdline_flow.c
@@ -8859,6 +8859,7 @@ parse_vc_spec(struct context *ctx, const struct token 
*token,
              const char *str, unsigned int len,
              void *buf, unsigned int size)
 {
+       static const enum index next_prefix[] = { COMMON_PREFIX, ZERO };
        struct buffer *out = buf;
        struct rte_flow_item *item;
        uint32_t data_size;
@@ -8885,7 +8886,7 @@ parse_vc_spec(struct context *ctx, const struct token 
*token,
                /* Modify next token to expect a prefix. */
                if (ctx->next_num < 2)
                        return -1;
-               ctx->next[ctx->next_num - 2] = NEXT_ENTRY(COMMON_PREFIX);
+               ctx->next[ctx->next_num - 2] = next_prefix;
                /* Fall through. */
        case ITEM_PARAM_MASK:
                index = 2;
@@ -9327,6 +9328,7 @@ parse_vc_action_rss_type(struct context *ctx, const 
struct token *token,
                          const char *str, unsigned int len,
                          void *buf, unsigned int size)
 {
+       static const enum index next_rss_type[] = { ACTION_RSS_TYPE, ZERO };
        struct action_rss_data *action_rss_data;
        unsigned int i;
 
@@ -9352,7 +9354,7 @@ parse_vc_action_rss_type(struct context *ctx, const 
struct token *token,
        /* Repeat token. */
        if (ctx->next_num == RTE_DIM(ctx->next))
                return -1;
-       ctx->next[ctx->next_num++] = NEXT_ENTRY(ACTION_RSS_TYPE);
+       ctx->next[ctx->next_num++] = next_rss_type;
        if (!ctx->object)
                return len;
        action_rss_data = ctx->object;
@@ -9370,6 +9372,7 @@ parse_vc_action_rss_queue(struct context *ctx, const 
struct token *token,
                          const char *str, unsigned int len,
                          void *buf, unsigned int size)
 {
+       static const enum index next_rss_queue[] = { ACTION_RSS_QUEUE, ZERO };
        struct action_rss_data *action_rss_data;
        const struct arg *arg;
        int ret;
@@ -9402,7 +9405,7 @@ parse_vc_action_rss_queue(struct context *ctx, const 
struct token *token,
        /* Repeat token. */
        if (ctx->next_num == RTE_DIM(ctx->next))
                return -1;
-       ctx->next[ctx->next_num++] = NEXT_ENTRY(ACTION_RSS_QUEUE);
+       ctx->next[ctx->next_num++] = next_rss_queue;
 end:
        if (!ctx->object)
                return len;
-- 
2.47.3

Reply via email to