fixed coverity issue identified about tainted data read from command line
Costa Tsaousis (ktsaou) committed
May 5, 2017 at 21:47 UTC
652456470bd4715185a0fb9de2509f32eb8e79c7
1 file changed
+6
-7
src/freeipmi_plugin.c
+6
-7
@@ -242,7 +242,7 @@ _get_sensor_type_string (int sensor_type)
242
243
static int debug = 0;
244
245
-static int netdata_update_every = 5;
245
+static int netdata_update_every = 5; // this is the minimum update frequency
246
static int netdata_priority = 90000;
247
static int netdata_do_sel = 1;
248
@@ -1403,7 +1403,7 @@ int ipmi_detect_speed_secs(struct ipmi_monitoring_ipmi_config *ipmi_config) {
1403
// we find the average in microseconds
1404
// and we round-up to the closest second
1405
1406
- return (( total * 2 / checks / 1000000 ) + 1);
1406
+ return (int)(( total * 2 / checks / 1000000 ) + 1);
1407
}
1408
1409
int main (int argc, char **argv) {
@@ -1426,15 +1426,14 @@ int main (int argc, char **argv) {
1426
1427
int i, freq = 0;
1428
for(i = 1; i < argc ; i++) {
1429
- if(!freq) {
1429
+ if(isdigit(*argv[i]) && !freq) {
1430
int n = atoi(argv[i]);
1431
- if(n > 0) {
1431
+ if(n > 0 && freq < 86400) {
1432
freq = n;
1433
continue;
1434
}
1435
}
1436
-
1437
- if(strcmp("version", argv[i]) == 0 || strcmp("-v", argv[i]) == 0 || strcmp("-V", argv[i]) == 0) {
1436
+ else if(strcmp("version", argv[i]) == 0 || strcmp("-v", argv[i]) == 0 || strcmp("-V", argv[i]) == 0) {
1437
printf("freeipmi.plugin %s\n", VERSION);
1438
exit(0);
1439
}
@@ -1568,7 +1567,7 @@ int main (int argc, char **argv) {
1567
freq = ipmi_detect_speed_secs(&ipmi_config);
1568
if(debug) fprintf(stderr, "freeipmi.plugin: IPMI minimum update frequency was calculated to %d seconds.\n", freq);
1569
1571
- if(netdata_update_every < freq) {
1570
+ if(freq > netdata_update_every) {
1571
info("enforcing minimum data collection frequency, calculated to %d seconds.", freq);
1572
netdata_update_every = freq;
1573
}