Skip to content

Bound bitmap list parsing by its declared size - #15453

Open
tamird wants to merge 1 commit into
google:masterfrom
tamird:bitmap-list-bounds
Open

tamird wants to merge 1 commit into
google:masterfrom
tamird:bitmap-list-bounds

Conversation

@tamird

@tamird tamird commented Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

ParseList treated its size argument as an allocation hint. Cgroup cpuset
writes therefore expanded user-supplied ranges before checking whether
their indices exceeded the available CPUs or memory nodes. A range
ending at the maximum uint32 value could also wrap the iteration
counter.

Make the size an exclusive bit limit and reject each range before adding
its bits. All callers already pass their available CPU or node counts.
Remove their late maximum checks, which also accepted an index equal to
the count.

Assisted-by: OpenAI Codex

ParseList treated its size argument as an allocation hint. Cgroup cpuset
writes therefore expanded user-supplied ranges before checking whether
their indices exceeded the available CPUs or memory nodes. A range ending
at the maximum uint32 value could also wrap the iteration counter.

Make the size an exclusive bit limit and reject each range before adding
its bits. All callers already pass their available CPU or node counts.
Remove their late maximum checks, which also accepted an index equal to
the count.

Assisted-by: OpenAI Codex
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant