From: Mathieu Desnoyers <mathieu.desnoyers@efficios.com>
To: Matthew Wilcox <willy@linux.intel.com>
Cc: Matthew Wilcox <matthew.r.wilcox@intel.com>,
linux-fsdevel@vger.kernel.org, linux-mm@kvack.org,
linux-kernel@vger.kernel.org
Subject: Re: [PATCH v11 06/21] vfs: Add copy_to_iter(), copy_from_iter() and iov_iter_zero()
Date: Thu, 16 Oct 2014 14:12:06 +0000 (UTC) [thread overview]
Message-ID: <837939598.10389.1413468726146.JavaMail.zimbra@efficios.com> (raw)
In-Reply-To: <20141016135903.GA11522@wil.cx>
----- Original Message -----
> From: "Matthew Wilcox" <willy@linux.intel.com>
> To: "Mathieu Desnoyers" <mathieu.desnoyers@efficios.com>
> Cc: "Matthew Wilcox" <matthew.r.wilcox@intel.com>, linux-fsdevel@vger.kernel.org, linux-mm@kvack.org,
> linux-kernel@vger.kernel.org, "Matthew Wilcox" <willy@linux.intel.com>
> Sent: Thursday, October 16, 2014 3:59:03 PM
> Subject: Re: [PATCH v11 06/21] vfs: Add copy_to_iter(), copy_from_iter() and iov_iter_zero()
>
> On Thu, Oct 16, 2014 at 03:33:55PM +0200, Mathieu Desnoyers wrote:
> > > +static size_t copy_to_iter_iovec(void *from, size_t bytes, struct
> > > iov_iter *i)
> > > +{
> [...]
> > > + left = __copy_to_user(buf, from, copy);
> >
> > How comes this function uses __copy_to_user without any access_ok()
> > check ? This has security implications.
>
> The access_ok() check is done higher up the call-chain if it's appropriate.
> These functions can be (intentionally) called to access kernel addresses,
> so it wouldn't be appropriate to do that here.
If the access_ok() are expected to be already done higher in the call-chain,
we might want to rename e.g. copy_to_iter_iovec to
__copy_to_iter_iovec(). It helps clarifying the check expectations for the
caller.
>
> > > +static size_t copy_page_to_iter_bvec(struct page *page, size_t offset,
> > > + size_t bytes, struct iov_iter *i)
> > > +{
> > > + void *kaddr = kmap_atomic(page);
> > > + size_t wanted = copy_to_iter_bvec(kaddr + offset, bytes, i);
> >
> > missing newline.
> >
> > > + kunmap_atomic(kaddr);
> > > + return wanted;
> > > +}
>
> Are you seriously suggesting that:
>
> static size_t copy_page_to_iter_bvec(struct page *page, size_t offset,
> size_t bytes, struct iov_iter *i)
> {
> void *kaddr = kmap_atomic(page);
> size_t wanted = copy_to_iter_bvec(kaddr + offset, bytes, i);
>
> kunmap_atomic(kaddr);
> return wanted;
> }
>
> is more readable than without the newline? I can see the point of the
> rule for functions with a lot of variables, or a lot of lines, but I
> don't see the point of it for such a small function.
I usually find it easier to read when variables and code are split,
but I don't feel strongly about this in this particular case.
>
> In any case, this patch is now upstream, so I shan't be proposing any
> stylistic changes for it.
The leading __ prefix before the function names appears to be important
enough though, since it allows future changes of this code to take into
account the specific check expectations of those functions.
Thanks,
Mathieu
--
Mathieu Desnoyers
EfficiOS Inc.
http://www.efficios.com
--
To unsubscribe, send a message with 'unsubscribe linux-mm' in
the body to majordomo@kvack.org. For more info on Linux MM,
see: http://www.linux-mm.org/ .
Don't email: <a href=mailto:"dont@kvack.org"> email@kvack.org </a>
next prev parent reply other threads:[~2014-10-16 14:12 UTC|newest]
Thread overview: 88+ messages / expand[flat|nested] mbox.gz Atom feed top
2014-09-25 20:33 [PATCH v11 00/21] Add support for NV-DIMMs to ext4 Matthew Wilcox
2014-09-25 20:33 ` [PATCH v11 01/21] axonram: Fix bug in direct_access Matthew Wilcox
2014-10-16 7:52 ` Mathieu Desnoyers
2014-09-25 20:33 ` [PATCH v11 02/21] block: Change direct_access calling convention Matthew Wilcox
2014-10-16 8:45 ` Mathieu Desnoyers
2014-10-16 19:39 ` Matthew Wilcox
2014-09-25 20:33 ` [PATCH v11 03/21] mm: Fix XIP fault vs truncate race Matthew Wilcox
2014-10-16 8:56 ` Mathieu Desnoyers
2014-09-25 20:33 ` [PATCH v11 04/21] mm: Allow page fault handlers to perform the COW Matthew Wilcox
2014-10-16 9:12 ` Mathieu Desnoyers
2014-10-16 19:48 ` Matthew Wilcox
2014-10-17 15:35 ` Mathieu Desnoyers
2014-10-18 17:22 ` Matthew Wilcox
2014-09-25 20:33 ` [PATCH v11 05/21] vfs,ext2: Introduce IS_DAX(inode) Matthew Wilcox
2014-10-16 9:35 ` Mathieu Desnoyers
2014-09-25 20:33 ` [PATCH v11 06/21] vfs: Add copy_to_iter(), copy_from_iter() and iov_iter_zero() Matthew Wilcox
2014-10-16 13:33 ` Mathieu Desnoyers
2014-10-16 13:59 ` Matthew Wilcox
2014-10-16 14:12 ` Mathieu Desnoyers [this message]
2014-10-16 22:21 ` Matthew Wilcox
2014-10-17 15:39 ` Mathieu Desnoyers
2014-09-25 20:33 ` [PATCH v11 07/21] dax,ext2: Replace XIP read and write with DAX I/O Matthew Wilcox
2014-10-16 9:50 ` Mathieu Desnoyers
2014-10-16 19:51 ` Matthew Wilcox
2014-10-16 22:33 ` Matthew Wilcox
2014-10-17 15:52 ` Mathieu Desnoyers
2014-09-25 20:33 ` [PATCH v11 08/21] dax,ext2: Replace ext2_clear_xip_target with dax_clear_blocks Matthew Wilcox
2014-10-16 10:05 ` Mathieu Desnoyers
2014-10-16 21:22 ` Matthew Wilcox
2014-10-17 15:45 ` Mathieu Desnoyers
2014-09-25 20:33 ` [PATCH v11 09/21] dax,ext2: Replace the XIP page fault handler with the DAX page fault handler Matthew Wilcox
2014-10-16 10:20 ` Mathieu Desnoyers
2014-10-16 21:29 ` Matthew Wilcox
2014-09-25 20:33 ` [PATCH v11 10/21] dax,ext2: Replace xip_truncate_page with dax_truncate_page Matthew Wilcox
2014-10-16 10:28 ` Mathieu Desnoyers
2014-09-25 20:33 ` [PATCH v11 11/21] dax: Replace XIP documentation with DAX documentation Matthew Wilcox
2014-10-16 12:08 ` Mathieu Desnoyers
2014-09-25 20:33 ` [PATCH v11 12/21] vfs: Remove get_xip_mem Matthew Wilcox
2014-10-16 12:14 ` Mathieu Desnoyers
2014-10-16 21:44 ` Matthew Wilcox
2014-09-25 20:33 ` [PATCH v11 13/21] ext2: Remove ext2_xip_verify_sb() Matthew Wilcox
2014-10-16 12:18 ` Mathieu Desnoyers
2014-10-16 21:45 ` Matthew Wilcox
2014-09-25 20:33 ` [PATCH v11 14/21] ext2: Remove ext2_use_xip Matthew Wilcox
2014-10-16 12:20 ` Mathieu Desnoyers
2014-09-25 20:33 ` [PATCH v11 15/21] ext2: Remove xip.c and xip.h Matthew Wilcox
2014-10-16 12:21 ` Mathieu Desnoyers
2014-09-25 20:33 ` [PATCH v11 16/21] vfs,ext2: Remove CONFIG_EXT2_FS_XIP and rename CONFIG_FS_XIP to CONFIG_FS_DAX Matthew Wilcox
2014-10-16 12:26 ` Mathieu Desnoyers
2014-10-16 21:52 ` Matthew Wilcox
2014-09-25 20:33 ` [PATCH v11 17/21] ext2: Remove ext2_aops_xip Matthew Wilcox
2014-10-16 12:29 ` Mathieu Desnoyers
2014-09-25 20:33 ` [PATCH v11 18/21] ext2: Get rid of most mentions of XIP in ext2 Matthew Wilcox
2014-10-16 12:32 ` Mathieu Desnoyers
2014-09-25 20:33 ` [PATCH v11 19/21] dax: Add dax_zero_page_range Matthew Wilcox
2014-10-16 12:38 ` Mathieu Desnoyers
2014-10-16 22:01 ` Matthew Wilcox
2014-10-17 15:49 ` Mathieu Desnoyers
2014-10-18 17:41 ` Matthew Wilcox
2014-10-18 21:16 ` Mathieu Desnoyers
2014-09-25 20:33 ` [PATCH v11 20/21] ext4: Add DAX functionality Matthew Wilcox
2014-10-16 12:56 ` Mathieu Desnoyers
2014-10-16 22:16 ` Matthew Wilcox
2014-10-17 15:42 ` Mathieu Desnoyers
2014-09-25 20:33 ` [PATCH v11 21/21] brd: Rename XIP to DAX Matthew Wilcox
2014-10-16 13:00 ` Mathieu Desnoyers
2015-03-24 18:50 ` Matt Mullins
2015-03-25 3:25 ` Dave Chinner
2015-03-26 17:09 ` Should implementations of ->direct_access be allowed to sleep? Matthew Wilcox
2015-03-26 19:32 ` Dave Chinner
2015-03-29 8:02 ` Boaz Harrosh
2015-03-29 9:13 ` Boaz Harrosh
2014-09-25 20:47 ` [PATCH v11 00/21] Add support for NV-DIMMs to ext4 Matthew Wilcox
2014-09-30 9:45 ` Valdis.Kletnieks
2014-09-30 14:48 ` Matthew Wilcox
2014-09-30 14:53 ` Valdis.Kletnieks
2014-09-30 16:08 ` Matthew Wilcox
2014-09-30 17:10 ` Zuckerman, Boris
2014-09-30 19:24 ` Matthew Wilcox
2014-09-30 19:31 ` Zuckerman, Boris
2014-09-30 20:37 ` Valdis.Kletnieks
2014-09-30 21:25 ` Andreas Dilger
2014-09-30 21:52 ` Valdis.Kletnieks
2014-10-01 15:45 ` Jeff Moyer
2014-10-01 17:10 ` Valdis.Kletnieks
2014-10-01 17:17 ` Valdis.Kletnieks
2014-10-16 7:39 ` Mathieu Desnoyers
2014-10-16 14:11 ` Matthew Wilcox
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=837939598.10389.1413468726146.JavaMail.zimbra@efficios.com \
--to=mathieu.desnoyers@efficios.com \
--cc=linux-fsdevel@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-mm@kvack.org \
--cc=matthew.r.wilcox@intel.com \
--cc=willy@linux.intel.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).