From mboxrd@z Thu Jan 1 00:00:00 1970 From: Eric Dumazet Subject: Re: [patch v2] fcntl: return -EFAULT if copy_to_user fails Date: Thu, 03 Jun 2010 14:38:03 +0200 Message-ID: <1275568683.2456.33.camel@edumazet-laptop> References: <20100603100402.GR5483@bicker> <4C07826A.6060302@oss.ntt.co.jp> <20100603103542.GV5483@bicker> <4C07990A.8080508@fusionio.com> <4C079D34.5010500@oss.ntt.co.jp> Mime-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: QUOTED-PRINTABLE Cc: Jens Axboe , Dan Carpenter , Matthew Wilcox , Alexander Viro , Andrew Morton , Oleg Nesterov , Greg Kroah-Hartman , Peter Zijlstra , linux-fsdevel@vger.kernel.org, linux-kernel@vger.kernel.org To: Takuya Yoshikawa Return-path: In-Reply-To: <4C079D34.5010500@oss.ntt.co.jp> Sender: linux-kernel-owner@vger.kernel.org List-Id: linux-fsdevel.vger.kernel.org Le jeudi 03 juin 2010 =C3=A0 21:16 +0900, Takuya Yoshikawa a =C3=A9crit= : > (2010/06/03 20:59), Jens Axboe wrote: > > On 2010-06-03 12:35, Dan Carpenter wrote: > >> copy_to_user() returns the number of bytes remaining, but we want = to > >> return -EFAULT. > >> ret =3D fcntl(fd, F_SETOWN_EX, NULL); > >> With the original code ret would be 8 here. > >> > >> V2: Takuya Yoshikawa pointed out a similar issue in f_getown_ex() > > > > Pretty basic bug, how long has this been there? >=20 > IIUC, from the beginning, when these were introduced. Maybe copy_to_user() was changed sometime to return a partial count instead of EFAULT ? I do think we should have a set of helper functions, instead of spreading special EFAULT cases in one housand places... This is really ugly. static inline int sec_copy_to_user(arg1, arg2, arg3) { int res =3D copy_to_user(arg1, arg2, arg3); return (res > 0) ? -EFAULT : res; }