• Jason A. Donenfeld's avatar
    treewide: use prandom_u32_max() when possible, part 1 · 81895a65
    Jason A. Donenfeld authored
    Rather than incurring a division or requesting too many random bytes for
    the given range, use the prandom_u32_max() function, which only takes
    the minimum required bytes from the RNG and avoids divisions. This was
    done mechanically with this coccinelle script:
    
    @basic@
    expression E;
    type T;
    identifier get_random_u32 =~ "get_random_int|prandom_u32|get_random_u32";
    typedef u64;
    @@
    (
    - ((T)get_random_u32() % (E))
    + prandom_u32_max(E)
    |
    - ((T)get_random_u32() & ((E) - 1))
    + prandom_u32_max(E * XXX_MAKE_SURE_E_IS_POW2)
    |
    - ((u64)(E) * get_random_u32() >> 32)
    + prandom_u32_max(E)
    |
    - ((T)get_random_u32() & ~PAGE_MASK)
    + prandom_u32_max(PAGE_SIZE)
    )
    
    @multi_line@
    identifier get_random_u32 =~ "get_random_int|prandom_u32|get_random_u32";
    identifier RAND;
    expression E;
    @@
    
    -       RAND = get_random_u32();
            ... when != RAND
    -       RAND %= (E);
    +       RAND = prandom_u32_max(E);
    
    // Find a potential literal
    @literal_mask@
    expression LITERAL;
    type T;
    identifier get_random_u32 =~ "get_random_int|prandom_u32|get_random_u32";
    position p;
    @@
    
            ((T)get_random_u32()@p & (LITERAL))
    
    // Add one to the literal.
    @script:python add_one@
    literal << literal_mask.LITERAL;
    RESULT;
    @@
    
    value = None
    if literal.startswith('0x'):
            value = int(literal, 16)
    elif literal[0] in '123456789':
            value = int(literal, 10)
    if value is None:
            print("I don't know how to handle %s" % (literal))
            cocci.include_match(False)
    elif value == 2**32 - 1 or value == 2**31 - 1 or value == 2**24 - 1 or value == 2**16 - 1 or value == 2**8 - 1:
            print("Skipping 0x%x for cleanup elsewhere" % (value))
            cocci.include_match(False)
    elif value & (value + 1) != 0:
            print("Skipping 0x%x because it's not a power of two minus one" % (value))
            cocci.include_match(False)
    elif literal.startswith('0x'):
            coccinelle.RESULT = cocci.make_expr("0x%x" % (value + 1))
    else:
            coccinelle.RESULT = cocci.make_expr("%d" % (value + 1))
    
    // Replace the literal mask with the calculated result.
    @plus_one@
    expression literal_mask.LITERAL;
    position literal_mask.p;
    expression add_one.RESULT;
    identifier FUNC;
    @@
    
    -       (FUNC()@p & (LITERAL))
    +       prandom_u32_max(RESULT)
    
    @collapse_ret@
    type T;
    identifier VAR;
    expression E;
    @@
    
     {
    -       T VAR;
    -       VAR = (E);
    -       return VAR;
    +       return E;
     }
    
    @drop_var@
    type T;
    identifier VAR;
    @@
    
     {
    -       T VAR;
            ... when != VAR
     }
    Reviewed-by: default avatarGreg Kroah-Hartman <gregkh@linuxfoundation.org>
    Reviewed-by: default avatarKees Cook <keescook@chromium.org>
    Reviewed-by: default avatarYury Norov <yury.norov@gmail.com>
    Reviewed-by: default avatarKP Singh <kpsingh@kernel.org>
    Reviewed-by: Jan Kara <jack@suse.cz> # for ext4 and sbitmap
    Reviewed-by: Christoph Böhmwalder <christoph.boehmwalder@linbit.com> # for drbd
    Acked-by: default avatarJakub Kicinski <kuba@kernel.org>
    Acked-by: Heiko Carstens <hca@linux.ibm.com> # for s390
    Acked-by: Ulf Hansson <ulf.hansson@linaro.org> # for mmc
    Acked-by: Darrick J. Wong <djwong@kernel.org> # for xfs
    Signed-off-by: default avatarJason A. Donenfeld <Jason@zx2c4.com>
    81895a65
process.c 6.25 KB