[build] Move various pointer assignments after their length checks - #1809
Merged
Conversation
When performing a length check on untrusted received data, it is preferable to assign the corresponding typed pointer only after validating that the length is sufficient to contain the dereferenced pointer type. This allows the compiler to catch any unintended dereferences before the length check has taken place, and so hardens the code against future potential changes. This pattern of assigning the pointer only after the corresponding length check is already fairly widespread, but there are still large swathes of older code that use the less safe idiom of assigning the pointer first (generally as part of the variable declaration). Move an assortment of pointer assignments after their corresponding length checks, and fix the few harmless premature dereferences that were discovered in the process (e.g. using a potentially non-existent IPv4 source address as a debug colour stream identifier). This is not intended to be a comprehensive update of all such pointer assignments, merely an improvement of those sites where assignments are easily identifiable and trivially hardened. Signed-off-by: Michael Brown <mcb30@ipxe.org>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
When performing a length check on untrusted received data, it is preferable to assign the corresponding typed pointer only after validating that the length is sufficient to contain the dereferenced pointer type. This allows the compiler to catch any unintended dereferences before the length check has taken place, and so hardens the code against future potential changes.
This pattern of assigning the pointer only after the corresponding length check is already fairly widespread, but there are still large swathes of older code that use the less safe idiom of assigning the pointer first (generally as part of the variable declaration).
Move an assortment of pointer assignments after their corresponding length checks, and fix the few harmless premature dereferences that were discovered in the process (e.g. using a potentially non-existent IPv4 source address as a debug colour stream identifier).
This is not intended to be a comprehensive update of all such pointer assignments, merely an improvement of those sites where assignments are easily identifiable and trivially hardened.