All of lore.kernel.org
 help / color / mirror / Atom feed
From: Andrei Warkentin <andreiw@vmware.com>
To: linux-kernel@vger.kernel.org
Cc: Andrei Warkentin <andreiw@vmware.com>, "H. Peter Anvin" <hpa@zytor.com>
Subject: [PATCH] /dev/mem: Fix wrong error on accessing beyond valid memory addresses.
Date: Wed,  9 Nov 2011 18:31:19 -0500	[thread overview]
Message-ID: <1320881479-16711-1-git-send-email-andreiw@vmware.com> (raw)

Currently this returns -EFAULT, but it really should be returning 0,
as in - 0 bytes read or written. This is what you would get by
opening a block device, seeking to the end, and trying to read
something. Additionally, make lseek() check the sought-to offset
to pass the valid_phys_addr_range test.

Cc: H. Peter Anvin <hpa@zytor.com>
Signed-off-by: Andrei Warkentin <andreiw@vmware.com>
---
 drivers/char/mem.c |    9 +++++++--
 1 files changed, 7 insertions(+), 2 deletions(-)

diff --git a/drivers/char/mem.c b/drivers/char/mem.c
index 8fc04b4..02d0b1a 100644
--- a/drivers/char/mem.c
+++ b/drivers/char/mem.c
@@ -98,7 +98,7 @@ static ssize_t read_mem(struct file *file, char __user *buf,
 	char *ptr;
 
 	if (!valid_phys_addr_range(p, count))
-		return -EFAULT;
+		return 0;
 	read = 0;
 #ifdef __ARCH_HAS_NO_PAGE_ZERO_MAPPED
 	/* we don't have page 0 mapped on sparc and m68k.. */
@@ -156,7 +156,7 @@ static ssize_t write_mem(struct file *file, const char __user *buf,
 	void *ptr;
 
 	if (!valid_phys_addr_range(p, count))
-		return -EFAULT;
+		return 0;
 
 	written = 0;
 
@@ -710,6 +710,11 @@ static loff_t memory_lseek(struct file *file, loff_t offset, int orig)
 	case SEEK_CUR:
 		offset += file->f_pos;
 	case SEEK_SET:
+		if (!valid_phys_addr_range(offset, 0)) {
+			ret = -EINVAL;
+			break;
+		}
+
 		/* to avoid userland mistaking f_pos=-9 as -EBADF=-9 */
 		if ((unsigned long long)offset >= ~0xFFFULL) {
 			ret = -EOVERFLOW;
-- 
1.7.4.1


             reply	other threads:[~2011-11-09 23:31 UTC|newest]

Thread overview: 6+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2011-11-09 23:31 Andrei Warkentin [this message]
2011-11-14 21:21 ` [PATCH] /dev/mem: Fix wrong error on accessing beyond valid memory addresses Andrei Warkentin
2011-11-14 21:59   ` H. Peter Anvin
2011-11-14 22:11     ` Andrei Warkentin
2011-11-14 22:12       ` H. Peter Anvin
2011-11-14 22:33         ` Andrei Warkentin

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=1320881479-16711-1-git-send-email-andreiw@vmware.com \
    --to=andreiw@vmware.com \
    --cc=hpa@zytor.com \
    --cc=linux-kernel@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.