From: Bart Van Assche <bvanassche@acm.org>
To: "Martin K . Petersen" <martin.petersen@oracle.com>
Cc: linux-scsi@vger.kernel.org, linux-block@vger.kernel.org,
linux-fsdevel@vger.kernel.org, Jens Axboe <axboe@kernel.dk>,
Christoph Hellwig <hch@lst.de>,
Daejun Park <daejun7.park@samsung.com>,
Kanchan Joshi <joshi.k@samsung.com>,
Bart Van Assche <bvanassche@acm.org>,
Jeff Layton <jlayton@kernel.org>,
Chuck Lever <chuck.lever@oracle.com>,
Stephen Rothwell <sfr@canb.auug.org.au>
Subject: [PATCH v5 01/17] fs: Fix rw_hint validation
Date: Wed, 29 Nov 2023 17:33:06 -0800 [thread overview]
Message-ID: <20231130013322.175290-2-bvanassche@acm.org> (raw)
In-Reply-To: <20231130013322.175290-1-bvanassche@acm.org>
Reject values that are valid rw_hints after truncation but not before
truncation by passing an untruncated value to rw_hint_valid().
Cc: Jeff Layton <jlayton@kernel.org>
Cc: Chuck Lever <chuck.lever@oracle.com>
Cc: Jens Axboe <axboe@kernel.dk>
Cc: Stephen Rothwell <sfr@canb.auug.org.au>
Fixes: 5657cb0797c4 ("fs/fcntl: use copy_to/from_user() for u64 types")
Signed-off-by: Bart Van Assche <bvanassche@acm.org>
---
fs/fcntl.c | 12 +++++-------
1 file changed, 5 insertions(+), 7 deletions(-)
diff --git a/fs/fcntl.c b/fs/fcntl.c
index c80a6acad742..3ff707bf2743 100644
--- a/fs/fcntl.c
+++ b/fs/fcntl.c
@@ -268,7 +268,7 @@ static int f_getowner_uids(struct file *filp, unsigned long arg)
}
#endif
-static bool rw_hint_valid(enum rw_hint hint)
+static bool rw_hint_valid(u64 hint)
{
switch (hint) {
case RWH_WRITE_LIFE_NOT_SET:
@@ -288,19 +288,17 @@ static long fcntl_rw_hint(struct file *file, unsigned int cmd,
{
struct inode *inode = file_inode(file);
u64 __user *argp = (u64 __user *)arg;
- enum rw_hint hint;
- u64 h;
+ u64 hint;
switch (cmd) {
case F_GET_RW_HINT:
- h = inode->i_write_hint;
- if (copy_to_user(argp, &h, sizeof(*argp)))
+ hint = inode->i_write_hint;
+ if (copy_to_user(argp, &hint, sizeof(*argp)))
return -EFAULT;
return 0;
case F_SET_RW_HINT:
- if (copy_from_user(&h, argp, sizeof(h)))
+ if (copy_from_user(&hint, argp, sizeof(hint)))
return -EFAULT;
- hint = (enum rw_hint) h;
if (!rw_hint_valid(hint))
return -EINVAL;
next prev parent reply other threads:[~2023-11-30 1:33 UTC|newest]
Thread overview: 32+ messages / expand[flat|nested] mbox.gz Atom feed top
2023-11-30 1:33 [PATCH v5 00/17] Pass data lifetime information to SCSI disk devices Bart Van Assche
2023-11-30 1:33 ` Bart Van Assche [this message]
2023-12-07 17:42 ` [PATCH v5 01/17] fs: Fix rw_hint validation Christoph Hellwig
2023-11-30 1:33 ` [PATCH v5 02/17] fs: Move enum rw_hint into a new header file Bart Van Assche
2023-12-07 17:44 ` Christoph Hellwig
2023-11-30 1:33 ` [PATCH v5 03/17] fs/f2fs: Restore the whint_mode mount option Bart Van Assche
2023-12-07 17:45 ` Christoph Hellwig
2023-12-07 19:39 ` Bart Van Assche
2023-12-11 16:44 ` Christoph Hellwig
2023-11-30 1:33 ` [PATCH v5 04/17] fs: Restore F_[GS]ET_FILE_RW_HINT support Bart Van Assche
2023-12-07 17:46 ` Christoph Hellwig
2023-12-07 19:37 ` Bart Van Assche
2023-12-11 16:45 ` Christoph Hellwig
2023-11-30 1:33 ` [PATCH v5 05/17] fs: Restore kiocb.ki_hint Bart Van Assche
2023-12-07 17:46 ` Christoph Hellwig
2023-12-07 23:40 ` Bart Van Assche
2023-12-11 16:46 ` Christoph Hellwig
2023-11-30 1:33 ` [PATCH v5 06/17] block: Restore the per-bio/request data lifetime fields Bart Van Assche
2023-11-30 1:33 ` [PATCH v5 07/17] block: Propagate write hints to the block device inode Bart Van Assche
2023-11-30 1:33 ` [PATCH v5 08/17] scsi: core: Query the Block Limits Extension VPD page Bart Van Assche
2023-11-30 12:21 ` Johannes Thumshirn
2023-11-30 1:33 ` [PATCH v5 09/17] scsi_proto: Add structures and constants related to I/O groups and streams Bart Van Assche
2023-11-30 13:19 ` Johannes Thumshirn
2023-12-01 1:46 ` Bart Van Assche
2023-11-30 1:33 ` [PATCH v5 10/17] sd: Translate data lifetime information Bart Van Assche
2023-11-30 1:33 ` [PATCH v5 11/17] scsi_debug: Reduce code duplication Bart Van Assche
2023-11-30 1:33 ` [PATCH v5 12/17] scsi_debug: Support the block limits extension VPD page Bart Van Assche
2023-11-30 1:33 ` [PATCH v5 13/17] scsi_debug: Rework page code error handling Bart Van Assche
2023-11-30 1:33 ` [PATCH v5 14/17] scsi_debug: Rework subpage " Bart Van Assche
2023-11-30 1:33 ` [PATCH v5 15/17] scsi_debug: Implement the IO Advice Hints Grouping mode page Bart Van Assche
2023-11-30 1:33 ` [PATCH v5 16/17] scsi_debug: Implement GET STREAM STATUS Bart Van Assche
2023-11-30 1:33 ` [PATCH v5 17/17] scsi_debug: Maintain write statistics per group number Bart Van Assche
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20231130013322.175290-2-bvanassche@acm.org \
--to=bvanassche@acm.org \
--cc=axboe@kernel.dk \
--cc=chuck.lever@oracle.com \
--cc=daejun7.park@samsung.com \
--cc=hch@lst.de \
--cc=jlayton@kernel.org \
--cc=joshi.k@samsung.com \
--cc=linux-block@vger.kernel.org \
--cc=linux-fsdevel@vger.kernel.org \
--cc=linux-scsi@vger.kernel.org \
--cc=martin.petersen@oracle.com \
--cc=sfr@canb.auug.org.au \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).