From: "Serge E. Hallyn" <serge@hallyn.com>
To: Ben Dooks <ben.dooks@codethink.co.uk>
Cc: linux-security-module@vger.kernel.org,
linux-kernel@vger.kernel.org, serge@hallyn.com,
Paul Moore <paul@paul-moore.com>
Subject: Re: [PATCH] capabilities: fix sparse warning about __user access
Date: Mon, 19 Jun 2023 12:57:10 -0500 [thread overview]
Message-ID: <20230619175710.GA200481@mail.hallyn.com> (raw)
In-Reply-To: <20230619123535.324632-1-ben.dooks@codethink.co.uk>
On Mon, Jun 19, 2023 at 01:35:35PM +0100, Ben Dooks wrote:
> The two syscalls for capget and capset are producing sparse warnings
> as sparse is thinking that the "struct __user_cap_data_struct" is marked
> user, which seems to be down to the declaration and typedef at the same
> time.
>
> Fix the following warnings by splutting the struct declaration and then
> the user typedef into two:
I'm not a fan of making code changes to work around scanners'
shortcomings, mainly because eventually I assume the scanners
will learn to deal with it.
However, I don't like the all-in-one typedef+struct definition
either, so let's go with it :)
Paul, do you mind picking this up?
thanks,
-serge
> kernel/capability.c:191:35: warning: incorrect type in argument 2 (different address spaces)
> kernel/capability.c:191:35: expected void const *from
> kernel/capability.c:191:35: got struct __user_cap_data_struct [noderef] __user *
> kernel/capability.c:168:14: warning: dereference of noderef expression
> kernel/capability.c:168:45: warning: dereference of noderef expression
> kernel/capability.c:169:14: warning: dereference of noderef expression
> kernel/capability.c:169:45: warning: dereference of noderef expression
> kernel/capability.c:170:14: warning: dereference of noderef expression
> kernel/capability.c:170:45: warning: dereference of noderef expression
> kernel/capability.c:244:29: warning: incorrect type in argument 1 (different address spaces)
> kernel/capability.c:244:29: expected void *to
> kernel/capability.c:244:29: got struct __user_cap_data_struct [noderef] __user ( * )[2]
> kernel/capability.c:247:42: warning: dereference of noderef expression
> kernel/capability.c:247:64: warning: dereference of noderef expression
> kernel/capability.c:248:42: warning: dereference of noderef expression
> kernel/capability.c:248:64: warning: dereference of noderef expression
> kernel/capability.c:249:42: warning: dereference of noderef expression
> kernel/capability.c:249:64: warning: dereference of noderef expression
>
> Signed-off-by: Ben Dooks <ben.dooks@codethink.co.uk>
Reviewed-by: Serge Hallyn <serge@hallyn.com>
> ---
> include/uapi/linux/capability.h | 5 +++--
> 1 file changed, 3 insertions(+), 2 deletions(-)
>
> diff --git a/include/uapi/linux/capability.h b/include/uapi/linux/capability.h
> index 3d61a0ae055d..5bb906098697 100644
> --- a/include/uapi/linux/capability.h
> +++ b/include/uapi/linux/capability.h
> @@ -41,11 +41,12 @@ typedef struct __user_cap_header_struct {
> int pid;
> } __user *cap_user_header_t;
>
> -typedef struct __user_cap_data_struct {
> +struct __user_cap_data_struct {
> __u32 effective;
> __u32 permitted;
> __u32 inheritable;
> -} __user *cap_user_data_t;
> +};
> +typedef struct __user_cap_data_struct __user *cap_user_data_t;
>
>
> #define VFS_CAP_REVISION_MASK 0xFF000000
> --
> 2.39.2
next prev parent reply other threads:[~2023-06-19 17:57 UTC|newest]
Thread overview: 5+ messages / expand[flat|nested] mbox.gz Atom feed top
2023-06-19 12:35 [PATCH] capabilities: fix sparse warning about __user access Ben Dooks
2023-06-19 17:57 ` Serge E. Hallyn [this message]
2023-06-19 21:47 ` Paul Moore
2023-06-21 13:43 ` Serge Hallyn
2023-07-05 22:46 ` Paul Moore
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20230619175710.GA200481@mail.hallyn.com \
--to=serge@hallyn.com \
--cc=ben.dooks@codethink.co.uk \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-security-module@vger.kernel.org \
--cc=paul@paul-moore.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.