<!-- 
RSS generated by JIRA (9.4.14#940014-sha1:734e6822bbf0d45eff9af51f82432957f73aa32c) at Sat Feb 10 01:27:34 UTC 2024

It is possible to restrict the fields that are returned in this document by specifying the 'field' parameter in your request.
For example, to request only the issue key and summary append 'field=key&field=summary' to the URL of your request.
-->
<rss version="0.92" >
<channel>
    <title>Whamcloud Community JIRA</title>
    <link>https://jira.whamcloud.com</link>
    <description>This file is an XML representation of an issue</description>
    <language>en-us</language>    <build-info>
        <version>9.4.14</version>
        <build-number>940014</build-number>
        <build-date>05-12-2023</build-date>
    </build-info>


<item>
            <title>[LU-2714] HSM: add sanity checks for incoming RPCs</title>
                <link>https://jira.whamcloud.com/browse/LU-2714</link>
                <project id="10000" key="LU">Lustre</project>
                    <description>&lt;p&gt;Recent HSM patches seem to blindly trust incoming network data.&lt;br/&gt;
Examples include mdt_hsm_action handling of the action list where we blindly trust number of items supplied without testing against provided buffer sizes, also allocating buffers not using OBD_ALLOC_LARGE which provides somewaht easy DoS avenue.&lt;br/&gt;
Another example is mdt_hsm_request handling of hr_itemcount.&lt;br/&gt;
I suspect there are more cases like this in other patches.&lt;/p&gt;

&lt;p&gt;Additionally sanity max values for all those item counts should be added in client side ioctl handlers to avoid easy local DoS avenues.&lt;/p&gt;</description>
                <environment></environment>
        <key id="17374">LU-2714</key>
            <summary>HSM: add sanity checks for incoming RPCs</summary>
                <type id="7" iconUrl="https://jira.whamcloud.com/images/icons/issuetypes/task_agile.png">Technical task</type>
                            <parent id="16195">LU-2061</parent>
                                    <priority id="1" iconUrl="https://jira.whamcloud.com/images/icons/priorities/blocker.svg">Blocker</priority>
                        <status id="6" iconUrl="https://jira.whamcloud.com/images/icons/statuses/closed.png" description="The issue is considered finished, the resolution is correct. Issues which are closed can be reopened.">Closed</status>
                    <statusCategory id="3" key="done" colorName="success"/>
                                    <resolution id="1">Fixed</resolution>
                                        <assignee username="jhammond">John Hammond</assignee>
                                    <reporter username="green">Oleg Drokin</reporter>
                        <labels>
                            <label>MB</label>
                    </labels>
                <created>Wed, 30 Jan 2013 18:14:11 +0000</created>
                <updated>Thu, 7 Mar 2013 13:39:09 +0000</updated>
                            <resolved>Thu, 7 Mar 2013 13:38:56 +0000</resolved>
                                    <version>Lustre 2.4.0</version>
                                    <fixVersion>Lustre 2.4.0</fixVersion>
                                        <due></due>
                            <votes>0</votes>
                                    <watches>5</watches>
                                                                            <comments>
                            <comment id="52803" author="pjones" created="Thu, 21 Feb 2013 10:33:44 +0000"  >&lt;p&gt;John&lt;/p&gt;

&lt;p&gt;Could you please look into this one?&lt;/p&gt;

&lt;p&gt;Thanks&lt;/p&gt;

&lt;p&gt;Peter&lt;/p&gt;</comment>
                            <comment id="52827" author="jhammond" created="Thu, 21 Feb 2013 14:21:43 +0000"  >&lt;p&gt;Oleg, can you suggest a reasonable upper limit on the amount of memory that the MDT allocate to serve a single HSM request?&lt;/p&gt;

&lt;p&gt;Also to make sure that I understand correctly, are you referring to master here? There are indeed some issues in master&apos;s hsm handlers, but if I look at mdt_hsm_action() then the allocations are all statically sized.&lt;/p&gt;</comment>
                            <comment id="52838" author="jhammond" created="Thu, 21 Feb 2013 17:48:38 +0000"  >&lt;p&gt;Please see &lt;a href=&quot;http://review.whamcloud.com/5507&quot; class=&quot;external-link&quot; target=&quot;_blank&quot; rel=&quot;nofollow noopener&quot;&gt;http://review.whamcloud.com/5507&lt;/a&gt;.&lt;/p&gt;</comment>
                            <comment id="53549" author="jhammond" created="Thu, 7 Mar 2013 13:38:56 +0000"  >&lt;p&gt;Patch landed.&lt;/p&gt;</comment>
                    </comments>
                    <attachments>
                    </attachments>
                <subtasks>
                    </subtasks>
                <customfields>
                                                                                                                                                                <customfield id="customfield_10890" key="com.atlassian.jira.plugins.jira-development-integration-plugin:devsummary">
                        <customfieldname>Development</customfieldname>
                        <customfieldvalues>
                            
                        </customfieldvalues>
                    </customfield>
                                                                                                                                                                                                                                                                                                                                                        <customfield id="customfield_10390" key="com.pyxis.greenhopper.jira:gh-lexo-rank">
                        <customfieldname>Rank</customfieldname>
                        <customfieldvalues>
                            <customfieldvalue>1|hzvi9r:</customfieldvalue>

                        </customfieldvalues>
                    </customfield>
                                                                <customfield id="customfield_10090" key="com.pyxis.greenhopper.jira:gh-global-rank">
                        <customfieldname>Rank (Obsolete)</customfieldname>
                        <customfieldvalues>
                            <customfieldvalue>6609</customfieldvalue>
                        </customfieldvalues>
                    </customfield>
                                                                                                                                                                                                                                                                                                                                                                                                                </customfields>
    </item>
</channel>
</rss>