* [PATCH] powerpc/nvram: use memdup_user
[not found] <4db2a0ba17dc68d7bcfbd7d47b0eb22ad9a220c2.1493381463.git.geliangtang@gmail.com>
@ 2017-04-29 1:45 ` Geliang Tang
2017-06-28 0:08 ` Kees Cook
2017-04-29 1:45 ` [PATCH] powerpc/powernv: " Geliang Tang
2017-04-29 1:45 ` [PATCH] powerpc/pseries: use memdup_user_nul Geliang Tang
2 siblings, 1 reply; 6+ messages in thread
From: Geliang Tang @ 2017-04-29 1:45 UTC (permalink / raw)
To: Benjamin Herrenschmidt, Paul Mackerras, Michael Ellerman,
Kees Cook
Cc: Geliang Tang, linuxppc-dev, linux-kernel
Use memdup_user() helper instead of open-coding to simplify the code.
Signed-off-by: Geliang Tang <geliangtang@gmail.com>
---
arch/powerpc/kernel/nvram_64.c | 14 +++++---------
1 file changed, 5 insertions(+), 9 deletions(-)
diff --git a/arch/powerpc/kernel/nvram_64.c b/arch/powerpc/kernel/nvram_64.c
index eae61b0..496d639 100644
--- a/arch/powerpc/kernel/nvram_64.c
+++ b/arch/powerpc/kernel/nvram_64.c
@@ -792,21 +792,17 @@ static ssize_t dev_nvram_write(struct file *file, const char __user *buf,
count = min_t(size_t, count, size - *ppos);
count = min(count, PAGE_SIZE);
- ret = -ENOMEM;
- tmp = kmalloc(count, GFP_KERNEL);
- if (!tmp)
- goto out;
-
- ret = -EFAULT;
- if (copy_from_user(tmp, buf, count))
+ tmp = memdup_user(buf, count);
+ if (IS_ERR(tmp)) {
+ ret = PTR_ERR(tmp);
goto out;
+ }
ret = ppc_md.nvram_write(tmp, count, ppos);
-out:
kfree(tmp);
+out:
return ret;
-
}
static long dev_nvram_ioctl(struct file *file, unsigned int cmd,
--
2.9.3
^ permalink raw reply related [flat|nested] 6+ messages in thread
* Re: [PATCH] powerpc/nvram: use memdup_user
2017-04-29 1:45 ` [PATCH] powerpc/nvram: use memdup_user Geliang Tang
@ 2017-06-28 0:08 ` Kees Cook
0 siblings, 0 replies; 6+ messages in thread
From: Kees Cook @ 2017-06-28 0:08 UTC (permalink / raw)
To: Geliang Tang
Cc: Benjamin Herrenschmidt, Paul Mackerras, Michael Ellerman,
linuxppc-dev@lists.ozlabs.org, LKML
On Fri, Apr 28, 2017 at 6:45 PM, Geliang Tang <geliangtang@gmail.com> wrote:
> Use memdup_user() helper instead of open-coding to simplify the code.
>
> Signed-off-by: Geliang Tang <geliangtang@gmail.com>
Thanks! Applied for -next.
-Kees
> ---
> arch/powerpc/kernel/nvram_64.c | 14 +++++---------
> 1 file changed, 5 insertions(+), 9 deletions(-)
>
> diff --git a/arch/powerpc/kernel/nvram_64.c b/arch/powerpc/kernel/nvram_64.c
> index eae61b0..496d639 100644
> --- a/arch/powerpc/kernel/nvram_64.c
> +++ b/arch/powerpc/kernel/nvram_64.c
> @@ -792,21 +792,17 @@ static ssize_t dev_nvram_write(struct file *file, const char __user *buf,
> count = min_t(size_t, count, size - *ppos);
> count = min(count, PAGE_SIZE);
>
> - ret = -ENOMEM;
> - tmp = kmalloc(count, GFP_KERNEL);
> - if (!tmp)
> - goto out;
> -
> - ret = -EFAULT;
> - if (copy_from_user(tmp, buf, count))
> + tmp = memdup_user(buf, count);
> + if (IS_ERR(tmp)) {
> + ret = PTR_ERR(tmp);
> goto out;
> + }
>
> ret = ppc_md.nvram_write(tmp, count, ppos);
>
> -out:
> kfree(tmp);
> +out:
> return ret;
> -
> }
>
> static long dev_nvram_ioctl(struct file *file, unsigned int cmd,
> --
> 2.9.3
>
--
Kees Cook
Pixel Security
^ permalink raw reply [flat|nested] 6+ messages in thread
* [PATCH] powerpc/powernv: use memdup_user
[not found] <4db2a0ba17dc68d7bcfbd7d47b0eb22ad9a220c2.1493381463.git.geliangtang@gmail.com>
2017-04-29 1:45 ` [PATCH] powerpc/nvram: use memdup_user Geliang Tang
@ 2017-04-29 1:45 ` Geliang Tang
2017-07-27 12:37 ` Michael Ellerman
2017-04-29 1:45 ` [PATCH] powerpc/pseries: use memdup_user_nul Geliang Tang
2 siblings, 1 reply; 6+ messages in thread
From: Geliang Tang @ 2017-04-29 1:45 UTC (permalink / raw)
To: Benjamin Herrenschmidt, Paul Mackerras, Michael Ellerman
Cc: Geliang Tang, linuxppc-dev, linux-kernel
Use memdup_user() helper instead of open-coding to simplify the code.
Signed-off-by: Geliang Tang <geliangtang@gmail.com>
---
arch/powerpc/platforms/powernv/opal-prd.c | 13 +++----------
1 file changed, 3 insertions(+), 10 deletions(-)
diff --git a/arch/powerpc/platforms/powernv/opal-prd.c b/arch/powerpc/platforms/powernv/opal-prd.c
index 2d6ee1c..de4dd09 100644
--- a/arch/powerpc/platforms/powernv/opal-prd.c
+++ b/arch/powerpc/platforms/powernv/opal-prd.c
@@ -241,15 +241,9 @@ static ssize_t opal_prd_write(struct file *file, const char __user *buf,
size = be16_to_cpu(hdr.size);
- msg = kmalloc(size, GFP_KERNEL);
- if (!msg)
- return -ENOMEM;
-
- rc = copy_from_user(msg, buf, size);
- if (rc) {
- size = -EFAULT;
- goto out_free;
- }
+ msg = memdup_user(buf, size);
+ if (IS_ERR(msg))
+ return PTR_ERR(msg);
rc = opal_prd_msg(msg);
if (rc) {
@@ -257,7 +251,6 @@ static ssize_t opal_prd_write(struct file *file, const char __user *buf,
size = -EIO;
}
-out_free:
kfree(msg);
return size;
--
2.9.3
^ permalink raw reply related [flat|nested] 6+ messages in thread
* [PATCH] powerpc/pseries: use memdup_user_nul
[not found] <4db2a0ba17dc68d7bcfbd7d47b0eb22ad9a220c2.1493381463.git.geliangtang@gmail.com>
2017-04-29 1:45 ` [PATCH] powerpc/nvram: use memdup_user Geliang Tang
2017-04-29 1:45 ` [PATCH] powerpc/powernv: " Geliang Tang
@ 2017-04-29 1:45 ` Geliang Tang
2017-07-27 12:37 ` Michael Ellerman
2 siblings, 1 reply; 6+ messages in thread
From: Geliang Tang @ 2017-04-29 1:45 UTC (permalink / raw)
To: Benjamin Herrenschmidt, Paul Mackerras, Michael Ellerman
Cc: Geliang Tang, linuxppc-dev, linux-kernel
Use memdup_user_nul() helper instead of open-coding to simplify the code.
Signed-off-by: Geliang Tang <geliangtang@gmail.com>
---
arch/powerpc/platforms/pseries/reconfig.c | 13 +++----------
1 file changed, 3 insertions(+), 10 deletions(-)
diff --git a/arch/powerpc/platforms/pseries/reconfig.c b/arch/powerpc/platforms/pseries/reconfig.c
index e5bf1e8..431f513 100644
--- a/arch/powerpc/platforms/pseries/reconfig.c
+++ b/arch/powerpc/platforms/pseries/reconfig.c
@@ -367,16 +367,9 @@ static ssize_t ofdt_write(struct file *file, const char __user *buf, size_t coun
char *kbuf;
char *tmp;
- if (!(kbuf = kmalloc(count + 1, GFP_KERNEL))) {
- rv = -ENOMEM;
- goto out;
- }
- if (copy_from_user(kbuf, buf, count)) {
- rv = -EFAULT;
- goto out;
- }
-
- kbuf[count] = '\0';
+ kbuf = memdup_user_nul(buf, count);
+ if (IS_ERR(kbuf))
+ return PTR_ERR(kbuf);
tmp = strchr(kbuf, ' ');
if (!tmp) {
--
2.9.3
^ permalink raw reply related [flat|nested] 6+ messages in thread