From: Dave Kleikamp <dave.kleikamp@oracle.com>
To: "Dr. David Alan Gilbert" <linux@treblig.org>,
Kees Cook <keescook@chromium.org>
Cc: jfs-discussion@lists.sourceforge.net,
linux-kernel@vger.kernel.org,
syzbot+5fc38b2ddbbca7f5c680@syzkaller.appspotmail.com
Subject: Re: [PATCH] jfs: Fix fortify moan in symlink
Date: Thu, 27 Oct 2022 17:18:29 -0500 [thread overview]
Message-ID: <63d4e019-8671-4f4c-f95d-acb8b2ab559b@oracle.com> (raw)
In-Reply-To: <Y1beLWto/J2W1Stu@gallifrey>
Applied.
Thanks,
Shaggy
On 10/24/22 1:49PM, Dr. David Alan Gilbert wrote:
> * Kees Cook (keescook@chromium.org) wrote:
>> On Sat, Oct 22, 2022 at 09:39:14PM +0100, linux@treblig.org wrote:
>>> From: "Dr. David Alan Gilbert" <linux@treblig.org>
>>>
>>> JFS has in jfs_incore.h:
>>>
>>> /* _inline may overflow into _inline_ea when needed */
>>> /* _inline_ea may overlay the last part of
>>> * file._xtroot if maxentry = XTROOTINITSLOT
>>> */
>>> union {
>>> struct {
>>> /* 128: inline symlink */
>>> unchar _inline[128];
>>> /* 128: inline extended attr */
>>> unchar _inline_ea[128];
>>> };
>>> unchar _inline_all[256];
>>>
>>> and currently the symlink code copies into _inline;
>>> if this is larger than 128 bytes it triggers a fortify warning of the
>>> form:
>>>
>>> memcpy: detected field-spanning write (size 132) of single field
>>> "ip->i_link" at fs/jfs/namei.c:950 (size 18446744073709551615)
>>
>> Which compiler are you using for this build?
>
> I think that report was the same on gcc on Fedora 37 and whatever
> syzkaller was running.
>
>> This size report (SIZE_MAX)
>> should be impossible to reach. But also, the size is just wrong --
>> i_inline is 128 bytes, not SIZE_MAX. So, the detection is working
>> (132 > 128), but the report is broken, and I can't see how...
>
> Yeh, and led me down a blind alley for a while thinking something had
> really managed to screwup the strlen somehow.
>
>>
>>>
>>> when it's actually OK.
>>>
>>> Copy it into _inline_all instead.
>>>
>>> Reported-by: syzbot+5fc38b2ddbbca7f5c680@syzkaller.appspotmail.com
>>> Signed-off-by: Dr. David Alan Gilbert <linux@treblig.org>
>>> ---
>>> fs/jfs/namei.c | 2 +-
>>> 1 file changed, 1 insertion(+), 1 deletion(-)
>>>
>>> diff --git a/fs/jfs/namei.c b/fs/jfs/namei.c
>>> index 9db4f5789c0ec..4fbbf88435e69 100644
>>> --- a/fs/jfs/namei.c
>>> +++ b/fs/jfs/namei.c
>>> @@ -946,7 +946,7 @@ static int jfs_symlink(struct user_namespace *mnt_userns, struct inode *dip,
>>> if (ssize <= IDATASIZE) {
>>> ip->i_op = &jfs_fast_symlink_inode_operations;
>>>
>>> - ip->i_link = JFS_IP(ip)->i_inline;
>>> + ip->i_link = JFS_IP(ip)->i_inline_all;
>>> memcpy(ip->i_link, name, ssize);
>>> ip->i_size = ssize - 1;
>>>
>>
>> Regardless, the fix looks correct to me!
>>
>> Reviewed-by: Kees Cook <keescook@chromium.org>
>
> Thanks!
>
> Dave
>
>> --
>> Kees Cook
next prev parent reply other threads:[~2022-10-27 22:19 UTC|newest]
Thread overview: 7+ messages / expand[flat|nested] mbox.gz Atom feed top
2022-10-22 20:39 [PATCH] jfs: Fix fortify moan in symlink linux
2022-10-24 17:28 ` Kees Cook
2022-10-24 18:49 ` Dr. David Alan Gilbert
2022-10-27 22:18 ` Dave Kleikamp [this message]
2022-10-28 22:56 ` Kees Cook
2022-10-29 12:48 ` Dr. David Alan Gilbert
2022-11-01 21:57 ` Kees Cook
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=63d4e019-8671-4f4c-f95d-acb8b2ab559b@oracle.com \
--to=dave.kleikamp@oracle.com \
--cc=jfs-discussion@lists.sourceforge.net \
--cc=keescook@chromium.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux@treblig.org \
--cc=syzbot+5fc38b2ddbbca7f5c680@syzkaller.appspotmail.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.