mirror of
https://github.com/hardkernel/linux.git
synced 2026-06-05 10:31:46 +09:00
fs: Fix rw_hint validation
[ Upstream commit ec16b147a55bfa14e858234eb7b1a7c8e7cd5021 ]
Reject values that are valid rw_hints after truncation but not before
truncation by passing an untruncated value to rw_hint_valid().
Reviewed-by: Christoph Hellwig <hch@lst.de>
Reviewed-by: Kanchan Joshi <joshi.k@samsung.com>
Cc: Jeff Layton <jlayton@kernel.org>
Cc: Chuck Lever <chuck.lever@oracle.com>
Cc: Jens Axboe <axboe@kernel.dk>
Cc: Stephen Rothwell <sfr@canb.auug.org.au>
Fixes: 5657cb0797 ("fs/fcntl: use copy_to/from_user() for u64 types")
Signed-off-by: Bart Van Assche <bvanassche@acm.org>
Link: https://lore.kernel.org/r/20240202203926.2478590-2-bvanassche@acm.org
Signed-off-by: Christian Brauner <brauner@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
This commit is contained in:
committed by
Sasha Levin
parent
e6450d5e46
commit
7533ed7668
12
fs/fcntl.c
12
fs/fcntl.c
@@ -267,7 +267,7 @@ static int f_getowner_uids(struct file *filp, unsigned long arg)
|
|||||||
}
|
}
|
||||||
#endif
|
#endif
|
||||||
|
|
||||||
static bool rw_hint_valid(enum rw_hint hint)
|
static bool rw_hint_valid(u64 hint)
|
||||||
{
|
{
|
||||||
switch (hint) {
|
switch (hint) {
|
||||||
case RWH_WRITE_LIFE_NOT_SET:
|
case RWH_WRITE_LIFE_NOT_SET:
|
||||||
@@ -287,19 +287,17 @@ static long fcntl_rw_hint(struct file *file, unsigned int cmd,
|
|||||||
{
|
{
|
||||||
struct inode *inode = file_inode(file);
|
struct inode *inode = file_inode(file);
|
||||||
u64 __user *argp = (u64 __user *)arg;
|
u64 __user *argp = (u64 __user *)arg;
|
||||||
enum rw_hint hint;
|
u64 hint;
|
||||||
u64 h;
|
|
||||||
|
|
||||||
switch (cmd) {
|
switch (cmd) {
|
||||||
case F_GET_RW_HINT:
|
case F_GET_RW_HINT:
|
||||||
h = inode->i_write_hint;
|
hint = inode->i_write_hint;
|
||||||
if (copy_to_user(argp, &h, sizeof(*argp)))
|
if (copy_to_user(argp, &hint, sizeof(*argp)))
|
||||||
return -EFAULT;
|
return -EFAULT;
|
||||||
return 0;
|
return 0;
|
||||||
case F_SET_RW_HINT:
|
case F_SET_RW_HINT:
|
||||||
if (copy_from_user(&h, argp, sizeof(h)))
|
if (copy_from_user(&hint, argp, sizeof(hint)))
|
||||||
return -EFAULT;
|
return -EFAULT;
|
||||||
hint = (enum rw_hint) h;
|
|
||||||
if (!rw_hint_valid(hint))
|
if (!rw_hint_valid(hint))
|
||||||
return -EINVAL;
|
return -EINVAL;
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user