linux-fsdevel.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
From: Bart Van Assche <bvanassche@acm.org>
To: "Martin K . Petersen" <martin.petersen@oracle.com>
Cc: linux-scsi@vger.kernel.org, linux-block@vger.kernel.org,
	linux-fsdevel@vger.kernel.org, Jens Axboe <axboe@kernel.dk>,
	Christoph Hellwig <hch@lst.de>,
	Daejun Park <daejun7.park@samsung.com>,
	Kanchan Joshi <joshi.k@samsung.com>,
	Bart Van Assche <bvanassche@acm.org>,
	Jeff Layton <jlayton@kernel.org>,
	Chuck Lever <chuck.lever@oracle.com>,
	Stephen Rothwell <sfr@canb.auug.org.au>,
	Alexander Viro <viro@zeniv.linux.org.uk>,
	Christian Brauner <brauner@kernel.org>
Subject: [PATCH v9 01/19] fs: Fix rw_hint validation
Date: Tue, 30 Jan 2024 13:48:27 -0800	[thread overview]
Message-ID: <20240130214911.1863909-2-bvanassche@acm.org> (raw)
In-Reply-To: <20240130214911.1863909-1-bvanassche@acm.org>

Reject values that are valid rw_hints after truncation but not before
truncation by passing an untruncated value to rw_hint_valid().

Reviewed-by: Christoph Hellwig <hch@lst.de>
Cc: Jeff Layton <jlayton@kernel.org>
Cc: Chuck Lever <chuck.lever@oracle.com>
Cc: Jens Axboe <axboe@kernel.dk>
Cc: Stephen Rothwell <sfr@canb.auug.org.au>
Fixes: 5657cb0797c4 ("fs/fcntl: use copy_to/from_user() for u64 types")
Signed-off-by: Bart Van Assche <bvanassche@acm.org>
---
 fs/fcntl.c | 12 +++++-------
 1 file changed, 5 insertions(+), 7 deletions(-)

diff --git a/fs/fcntl.c b/fs/fcntl.c
index c80a6acad742..3ff707bf2743 100644
--- a/fs/fcntl.c
+++ b/fs/fcntl.c
@@ -268,7 +268,7 @@ static int f_getowner_uids(struct file *filp, unsigned long arg)
 }
 #endif
 
-static bool rw_hint_valid(enum rw_hint hint)
+static bool rw_hint_valid(u64 hint)
 {
 	switch (hint) {
 	case RWH_WRITE_LIFE_NOT_SET:
@@ -288,19 +288,17 @@ static long fcntl_rw_hint(struct file *file, unsigned int cmd,
 {
 	struct inode *inode = file_inode(file);
 	u64 __user *argp = (u64 __user *)arg;
-	enum rw_hint hint;
-	u64 h;
+	u64 hint;
 
 	switch (cmd) {
 	case F_GET_RW_HINT:
-		h = inode->i_write_hint;
-		if (copy_to_user(argp, &h, sizeof(*argp)))
+		hint = inode->i_write_hint;
+		if (copy_to_user(argp, &hint, sizeof(*argp)))
 			return -EFAULT;
 		return 0;
 	case F_SET_RW_HINT:
-		if (copy_from_user(&h, argp, sizeof(h)))
+		if (copy_from_user(&hint, argp, sizeof(hint)))
 			return -EFAULT;
-		hint = (enum rw_hint) h;
 		if (!rw_hint_valid(hint))
 			return -EINVAL;
 

  reply	other threads:[~2024-01-30 21:49 UTC|newest]

Thread overview: 42+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2024-01-30 21:48 [PATCH v9 00/19] Pass data lifetime information to SCSI disk devices Bart Van Assche
2024-01-30 21:48 ` Bart Van Assche [this message]
2024-01-31 13:56   ` [PATCH v9 01/19] fs: Fix rw_hint validation Christian Brauner
2024-01-31 21:07     ` Bart Van Assche
2024-02-22  2:46     ` Bart Van Assche
2024-02-22  8:51       ` Christian Brauner
2024-01-31 14:51   ` Kanchan Joshi
2024-01-30 21:48 ` [PATCH v9 02/19] fs: Verify write lifetime constants at compile time Bart Van Assche
2024-01-30 21:48 ` [PATCH v9 03/19] fs: Split fcntl_rw_hint() Bart Van Assche
2024-01-31 14:52   ` Kanchan Joshi
2024-01-30 21:48 ` [PATCH v9 04/19] fs: Move enum rw_hint into a new header file Bart Van Assche
2024-01-31  7:48   ` Chao Yu
2024-01-30 21:48 ` [PATCH v9 05/19] fs: Propagate write hints to the struct block_device inode Bart Van Assche
2024-01-31 14:55   ` Kanchan Joshi
2024-01-30 21:48 ` [PATCH v9 06/19] block, fs: Restore the per-bio/request data lifetime fields Bart Van Assche
2024-01-31 14:55   ` Kanchan Joshi
2024-01-30 21:48 ` [PATCH v9 07/19] fs/f2fs: Restore the whint_mode mount option Bart Van Assche
2024-02-01 10:27   ` Chao Yu
2024-01-30 21:48 ` [PATCH v9 08/19] fs/f2fs: Restore support for tracing data lifetimes Bart Van Assche
2024-02-01 10:27   ` Chao Yu
2024-01-30 21:48 ` [PATCH v9 09/19] scsi: core: Query the Block Limits Extension VPD page Bart Van Assche
2024-01-30 21:48 ` [PATCH v9 10/19] scsi: scsi_proto: Add structures and constants related to I/O groups and streams Bart Van Assche
2024-01-30 21:48 ` [PATCH v9 11/19] scsi: sd: Translate data lifetime information Bart Van Assche
2024-02-15 21:33   ` Martin K. Petersen
2024-02-15 21:51     ` Bart Van Assche
2024-02-15 22:00       ` Martin K. Petersen
2024-02-16  0:22         ` Bart Van Assche
2024-02-16  0:32           ` Martin K. Petersen
2024-06-11 20:57   ` Andy Shevchenko
2024-06-11 21:21     ` Christian Heusel
2024-06-11 23:08       ` Bart Van Assche
2024-06-12  1:48         ` Martin K. Petersen
2024-06-12  5:35         ` Andy Shevchenko
2024-06-12  5:42           ` Andy Shevchenko
2024-01-30 21:48 ` [PATCH v9 12/19] scsi: scsi_debug: Reduce code duplication Bart Van Assche
2024-01-30 21:48 ` [PATCH v9 13/19] scsi: scsi_debug: Support the block limits extension VPD page Bart Van Assche
2024-01-30 21:48 ` [PATCH v9 14/19] scsi: scsi_debug: Rework page code error handling Bart Van Assche
2024-01-30 21:48 ` [PATCH v9 15/19] scsi: scsi_debug: Rework subpage " Bart Van Assche
2024-01-30 21:48 ` [PATCH v9 16/19] scsi: scsi_debug: Allocate the MODE SENSE response from the heap Bart Van Assche
2024-01-30 21:48 ` [PATCH v9 17/19] scsi: scsi_debug: Implement the IO Advice Hints Grouping mode page Bart Van Assche
2024-01-30 21:48 ` [PATCH v9 18/19] scsi: scsi_debug: Implement GET STREAM STATUS Bart Van Assche
2024-01-30 21:48 ` [PATCH v9 19/19] scsi: scsi_debug: Maintain write statistics per group number Bart Van Assche

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20240130214911.1863909-2-bvanassche@acm.org \
    --to=bvanassche@acm.org \
    --cc=axboe@kernel.dk \
    --cc=brauner@kernel.org \
    --cc=chuck.lever@oracle.com \
    --cc=daejun7.park@samsung.com \
    --cc=hch@lst.de \
    --cc=jlayton@kernel.org \
    --cc=joshi.k@samsung.com \
    --cc=linux-block@vger.kernel.org \
    --cc=linux-fsdevel@vger.kernel.org \
    --cc=linux-scsi@vger.kernel.org \
    --cc=martin.petersen@oracle.com \
    --cc=sfr@canb.auug.org.au \
    --cc=viro@zeniv.linux.org.uk \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).