[PATCH v2 3/6] bitmap: bitmap_parselist(): reject trailing characters after group size
From: Shashank Mohan Jain
Date: Fri Sep 25 2026 - 21:27:47 EST
bitmap_parse_region() checks that every region ends at a separator
(',', whitespace, '\n' or '\0'), except in the "range:used/group" form:
after parsing the group size it returns the pointer to the following
character without looking at it. The caller then starts a new region
at that character.
Before 'N' and 'all' were accepted as region starts this happened to be
harmless, because any other character would fail to parse as a new
region. Now text directly following the group size is silently parsed
as another region:
"0-7:1/2N" -> bits 0,2,4,6,7 (nbits = 8), returns 0
"0-7:1/2all" -> all bits set, returns 0
while "0-7N", "5N" or "0-7:1/2x" are correctly rejected with -EINVAL.
bitmap_parselist() is documented to return -EINVAL for an invalid
character. It parses cpu lists from sysfs, cgroup cpuset files and
boot parameters such as isolcpus= and nohz_full=, so a typo there is
accepted and yields a different mask than intended.
Check for the end of the region after the group size as well, like the
other forms do.
Fixes: 2c4885d24e64 ("lib: bitmap: support "N" as an alias for size of bitmap")
Assisted-by: LLM
Signed-off-by: Shashank Mohan Jain <jain.sm@xxxxxxxxx>
---
lib/bitmap-str.c | 9 ++++++++-
1 file changed, 8 insertions(+), 1 deletion(-)
diff --git a/lib/bitmap-str.c b/lib/bitmap-str.c
index e02c5bc80951..b58966864657 100644
--- a/lib/bitmap-str.c
+++ b/lib/bitmap-str.c
@@ -299,7 +299,14 @@ static const char *bitmap_parse_region(const char *str, struct region *r)
if (*str != '/')
return ERR_PTR(-EINVAL);
- return bitmap_getnum(str + 1, &r->group_len, lastbit);
+ str = bitmap_getnum(str + 1, &r->group_len, lastbit);
+ if (IS_ERR(str))
+ return str;
+
+ if (!end_of_region(*str))
+ return ERR_PTR(-EINVAL);
+
+ return end_of_str(*str) ? NULL : str;
no_end:
r->end = r->start;
--
2.43.0