diff options
author | YueHaibing <yuehaibing@huawei.com> | 2018-12-29 14:45:23 +0800 |
---|---|---|
committer | David S. Miller <davem@davemloft.net> | 2018-12-30 12:57:04 -0800 |
commit | 58075ff523af85002bfeace07304d57c59251605 (patch) | |
tree | d28039797f42324090e196afe7073fb5b982cacb | |
parent | 178fe94405bffbd1acd83b6ff3b40211185ae9c9 (diff) | |
download | linux-58075ff523af85002bfeace07304d57c59251605.tar.bz2 |
ipv4: fib_rules: Fix possible infinite loop in fib_empty_table
gcc warn this:
net/ipv4/fib_rules.c:203 fib_empty_table() warn:
always true condition '(id <= 4294967295) => (0-u32max <= u32max)'
'id' is u32, which always not greater than RT_TABLE_MAX
(0xFFFFFFFF), So add a check to break while wrap around.
Signed-off-by: YueHaibing <yuehaibing@huawei.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
-rw-r--r-- | net/ipv4/fib_rules.c | 8 |
1 files changed, 6 insertions, 2 deletions
diff --git a/net/ipv4/fib_rules.c b/net/ipv4/fib_rules.c index f8eb78d042a4..cfec3af54c8d 100644 --- a/net/ipv4/fib_rules.c +++ b/net/ipv4/fib_rules.c @@ -198,11 +198,15 @@ static int fib4_rule_match(struct fib_rule *rule, struct flowi *fl, int flags) static struct fib_table *fib_empty_table(struct net *net) { - u32 id; + u32 id = 1; - for (id = 1; id <= RT_TABLE_MAX; id++) + while (1) { if (!fib_get_table(net, id)) return fib_new_table(net, id); + + if (id++ == RT_TABLE_MAX) + break; + } return NULL; } |