The node number was converted with strtol() and checked only for
trailing garbage, so any value in range was taken. A socket id above
RTE_MAX_NUMA_NODES was accepted and failed later in the allocation.

Convert with rte_kvargs_to_int() over the same range as
rte_kvargs_handle_socket_id(), so -1 keeps meaning SOCKET_ID_ANY and
anything above the last socket is rejected where it is parsed. The
handler cannot be used directly since the value is one field of
"name:node:action" rather than the whole devarg.

Report a strdup() failure as -ENOMEM instead of reusing the empty
parameter message.

Signed-off-by: Stephen Hemminger <[email protected]>
---
 drivers/net/ring/rte_eth_ring.c | 23 +++++++++++++----------
 1 file changed, 13 insertions(+), 10 deletions(-)

diff --git a/drivers/net/ring/rte_eth_ring.c b/drivers/net/ring/rte_eth_ring.c
index 533a4c1b6b..a2ac704a8d 100644
--- a/drivers/net/ring/rte_eth_ring.c
+++ b/drivers/net/ring/rte_eth_ring.c
@@ -579,21 +579,25 @@ static int parse_kvlist(const char *key __rte_unused,
                        const char *value, void *data)
 {
        struct node_action_list *info = data;
+       int64_t socket_val;
        int ret;
-       char *name;
+       char *name = NULL;
        char *action;
        char *node;
-       char *end;
-
-       name = strdup(value);
 
        ret = -EINVAL;
 
-       if (!name) {
+       if (value == NULL) {
                PMD_LOG(WARNING, "command line parameter is empty for ring 
pmd!");
                goto out;
        }
 
+       name = strdup(value);
+       if (!name) {
+               ret = -ENOMEM;
+               goto out;
+       }
+
        node = strchr(name, ':');
        if (!node) {
                PMD_LOG(WARNING, "could not parse node value from %s",
@@ -625,14 +629,13 @@ static int parse_kvlist(const char *key __rte_unused,
        else
                goto out;
 
-       errno = 0;
-       info->list[info->count].socket_id = strtol(node, &end, 10);
-
-       if ((errno != 0) || (*end != '\0')) {
+       /* -1 is SOCKET_ID_ANY, the range rte_kvargs_handle_socket_id() takes. 
*/
+       if (rte_kvargs_to_int(node, -1, RTE_MAX_NUMA_NODES - 1, &socket_val) < 
0) {
                PMD_LOG(WARNING,
-                       "node value %s is unparseable as a number", node);
+                       "node value %s is not a valid socket id", node);
                goto out;
        }
+       info->list[info->count].socket_id = socket_val;
 
        strlcpy(info->list[info->count].name, name,
                sizeof(info->list[info->count].name));
-- 
2.53.0

Reply via email to