if (buflen < sizeof(uint32_t)) {
return EMSGSIZE;
}
-
+ if (wire->length > buflen) {
+ return EMSGSIZE;
+ }
+ if (sizeof(uint32_t) + wire->length < sizeof(uint32_t)) {
+ return EMSGSIZE;
+ }
if (buflen < sizeof(uint32_t) + wire->length) {
return EMSGSIZE;
}
if (buflen < offsetof(struct ctdb_statistics_list_wire, stats)) {
return EMSGSIZE;
}
+ if (wire->num > buflen / sizeof(struct ctdb_statistics)) {
+ return EMSGSIZE;
+ }
+ if (offsetof(struct ctdb_statistics_list_wire, stats) +
+ wire->num * sizeof(struct ctdb_statistics) <
+ offsetof(struct ctdb_statistics_list_wire, stats)) {
+ return EMSGSIZE;
+ }
if (buflen < offsetof(struct ctdb_statistics_list_wire, stats) +
wire->num * sizeof(struct ctdb_statistics)) {
return EMSGSIZE;
if (buflen < offsetof(struct ctdb_vnn_map_wire, map)) {
return EMSGSIZE;
}
+ if (wire->size > buflen / sizeof(uint32_t)) {
+ return EMSGSIZE;
+ }
+ if (offsetof(struct ctdb_vnn_map_wire, map) +
+ wire->size * sizeof(uint32_t) <
+ offsetof(struct ctdb_vnn_map_wire, map)) {
+ return EMSGSIZE;
+ }
if (buflen < offsetof(struct ctdb_vnn_map_wire, map) +
wire->size * sizeof(uint32_t)) {
return EMSGSIZE;
if (buflen < sizeof(uint32_t)) {
return EMSGSIZE;
}
+ if (wire->num > buflen / sizeof(struct ctdb_dbid)) {
+ return EMSGSIZE;
+ }
+ if (sizeof(uint32_t) + wire->num * sizeof(struct ctdb_dbid) <
+ sizeof(uint32_t)) {
+ return EMSGSIZE;
+ }
if (buflen < sizeof(uint32_t) + wire->num * sizeof(struct ctdb_dbid)) {
return EMSGSIZE;
}
size_t *reclen)
{
struct ctdb_rec_data_wire *wire = (struct ctdb_rec_data_wire *)buf;
- size_t offset, n;
+ size_t offset;
if (buflen < offsetof(struct ctdb_rec_data_wire, data)) {
return EMSGSIZE;
}
- n = offsetof(struct ctdb_rec_data_wire, data) +
- wire->keylen + wire->datalen;
- if (buflen < n) {
+ if (wire->keylen > buflen || wire->datalen > buflen) {
+ return EMSGSIZE;
+ }
+ if (offsetof(struct ctdb_rec_data_wire, data) + wire->keylen <
+ offsetof(struct ctdb_rec_data_wire, data)) {
+ return EMSGSIZE;
+ }
+ if (offsetof(struct ctdb_rec_data_wire, data) +
+ wire->keylen + wire->datalen <
+ offsetof(struct ctdb_rec_data_wire, data)) {
+ return EMSGSIZE;
+ }
+ if (buflen < offsetof(struct ctdb_rec_data_wire, data) +
+ wire->keylen + wire->datalen) {
return EMSGSIZE;
}
data->dsize = wire->datalen;
data->dptr = &wire->data[offset];
- *reclen = n;
+ *reclen = offsetof(struct ctdb_rec_data_wire, data) +
+ wire->keylen + wire->datalen;
return 0;
}
if (buflen < offsetof(struct ctdb_tunable_wire, name)) {
return EMSGSIZE;
}
+ if (wire->length > buflen) {
+ return EMSGSIZE;
+ }
+ if (offsetof(struct ctdb_tunable_wire, name) + wire->length <
+ offsetof(struct ctdb_tunable_wire, name)) {
+ return EMSGSIZE;
+ }
if (buflen < offsetof(struct ctdb_tunable_wire, name) + wire->length) {
return EMSGSIZE;
}
if (buflen < sizeof(uint32_t)) {
return EMSGSIZE;
}
+ if (wire->length > buflen) {
+ return EMSGSIZE;
+ }
+ if (sizeof(uint32_t) + wire->length < sizeof(uint32_t)) {
+ return EMSGSIZE;
+ }
if (buflen < sizeof(uint32_t) + wire->length) {
return EMSGSIZE;
}
if (buflen < offsetof(struct ctdb_tickle_list_wire, conn)) {
return EMSGSIZE;
}
+ if (wire->num > buflen / sizeof(struct ctdb_connection)) {
+ return EMSGSIZE;
+ }
+ if (offsetof(struct ctdb_tickle_list_wire, conn) +
+ wire->num * sizeof(struct ctdb_connection) <
+ offsetof(struct ctdb_tickle_list_wire, conn)) {
+ return EMSGSIZE;
+ }
if (buflen < offsetof(struct ctdb_tickle_list_wire, conn) +
wire->num * sizeof(struct ctdb_connection)) {
return EMSGSIZE;
if (buflen < offsetof(struct ctdb_addr_info_wire, iface)) {
return EMSGSIZE;
}
+ if (wire->len > buflen) {
+ return EMSGSIZE;
+ }
+ if (offsetof(struct ctdb_addr_info_wire, iface) + wire->len <
+ offsetof(struct ctdb_addr_info_wire, iface)) {
+ return EMSGSIZE;
+ }
if (buflen < offsetof(struct ctdb_addr_info_wire, iface) + wire->len) {
return EMSGSIZE;
}
if (buflen < sizeof(uint32_t)) {
return EMSGSIZE;
}
+ if (wire->num > buflen / sizeof(struct ctdb_public_ip)) {
+ return EMSGSIZE;
+ }
+ if (sizeof(uint32_t) + wire->num * sizeof(struct ctdb_public_ip) <
+ sizeof(uint32_t)) {
+ return EMSGSIZE;
+ }
if (buflen < sizeof(uint32_t) +
wire->num * sizeof(struct ctdb_public_ip)) {
return EMSGSIZE;
int i;
bool ret;
+ if (buflen < sizeof(uint32_t)) {
+ return EMSGSIZE;
+ }
+ if (wire->num > buflen / sizeof(struct ctdb_node_and_flags)) {
+ return EMSGSIZE;
+ }
+ if (sizeof(uint32_t) + wire->num * sizeof(struct ctdb_node_and_flags) <
+ sizeof(uint32_t)) {
+ return EMSGSIZE;
+ }
+ if (buflen < sizeof(uint32_t) +
+ wire->num * sizeof(struct ctdb_node_and_flags)) {
+ return EMSGSIZE;
+ }
+
nodemap = talloc(mem_ctx, struct ctdb_node_map);
if (nodemap == NULL) {
return ENOMEM;
if (buflen < offset) {
return EMSGSIZE;
}
+ if (wire->num_scripts > buflen / sizeof(struct ctdb_script)) {
+ return EMSGSIZE;
+ }
+ if (offset + wire->num_scripts * sizeof(struct ctdb_script) < offset) {
+ return EMSGSIZE;
+ }
if (buflen < offset + wire->num_scripts * sizeof(struct ctdb_script)) {
return EMSGSIZE;
}
if (buflen < offsetof(struct ctdb_notify_data_wire, data)) {
return EMSGSIZE;
}
+ if (wire->len > buflen) {
+ return EMSGSIZE;
+ }
+ if (offsetof(struct ctdb_notify_data_wire, data) + wire->len <
+ offsetof(struct ctdb_notify_data_wire, data)) {
+ return EMSGSIZE;
+ }
if (buflen < offsetof(struct ctdb_notify_data_wire, data) + wire->len) {
return EMSGSIZE;
}
if (buflen < sizeof(uint32_t)) {
return EMSGSIZE;
}
+ if (wire->num > buflen / sizeof(struct ctdb_iface)) {
+ return EMSGSIZE;
+ }
+ if (sizeof(uint32_t) + wire->num * sizeof(struct ctdb_iface) <
+ sizeof(uint32_t)) {
+ return EMSGSIZE;
+ }
if (buflen < sizeof(uint32_t) + wire->num * sizeof(struct ctdb_iface)) {
return EMSGSIZE;
}
if (buflen < offsetof(struct ctdb_public_ip_info_wire, ifaces)) {
return EMSGSIZE;
}
+ if (wire->num > buflen / sizeof(struct ctdb_iface)) {
+ return EMSGSIZE;
+ }
+ if (offsetof(struct ctdb_public_ip_info_wire, ifaces) +
+ wire->num * sizeof(struct ctdb_iface) <
+ offsetof(struct ctdb_public_ip_info_wire, ifaces)) {
+ return EMSGSIZE;
+ }
+ if (buflen < offsetof(struct ctdb_public_ip_info_wire, ifaces) +
+ wire->num * sizeof(struct ctdb_iface)) {
+ return EMSGSIZE;
+ }
ipinfo = talloc(mem_ctx, struct ctdb_public_ip_info);
if (ipinfo == NULL) {
if (buflen < offsetof(struct ctdb_key_data_wire, key)) {
return EMSGSIZE;
}
+ if (wire->keylen > buflen) {
+ return EMSGSIZE;
+ }
+ if (offsetof(struct ctdb_key_data_wire, key) + wire->keylen <
+ offsetof(struct ctdb_key_data_wire, key)) {
+ return EMSGSIZE;
+ }
if (buflen < offsetof(struct ctdb_key_data_wire, key) + wire->keylen) {
return EMSGSIZE;
}
if (buflen < sizeof(struct ctdb_db_statistics)) {
return EMSGSIZE;
}
+
offset = 0;
for (i=0; i<wire->dbstats.num_hot_keys; i++) {
+ if (wire->dbstats.hot_keys[i].key.dsize > buflen) {
+ return EMSGSIZE;
+ }
+ if (offset + wire->dbstats.hot_keys[i].key.dsize < offset) {
+ return EMSGSIZE;
+ }
offset += wire->dbstats.hot_keys[i].key.dsize;
+ if (offset > buflen) {
+ return EMSGSIZE;
+ }
+ }
+ if (sizeof(struct ctdb_db_statistics) + offset <
+ sizeof(struct ctdb_db_statistics)) {
+ return EMSGSIZE;
}
if (buflen < sizeof(struct ctdb_db_statistics) + offset) {
return EMSGSIZE;