public inbox for ltp@lists.linux.it
 help / color / mirror / Atom feed
* [LTP] [PATCH] cve/cve-2016-10044.c: fix two errors
@ 2017-09-22  9:21 Xiao Yang
  2017-09-22 11:06 ` Richard Palethorpe
  0 siblings, 1 reply; 9+ messages in thread
From: Xiao Yang @ 2017-09-22  9:21 UTC (permalink / raw)
  To: ltp

1) If the number of nr_events exceeds the limit of available events
   defined in /proc/sys/fs/aio-max-nr, it returns EAGAIN.  We should
   call io_destroy() to cleanup the AIO context after finishing test.

   Steps to reproduce this error:
      #echo 4 > /proc/sys/fs/aio-max-nr
      # ./cve-2016-10044 -i 5
      tst_test.c:908: INFO: Timeout per run is 0h 05m 00s
      cve-2016-10044.c:62: FAIL: AIO mapping is executable: rwxs!
      cve-2016-10044.c:62: FAIL: AIO mapping is executable: rwxs!
      cve-2016-10044.c:62: FAIL: AIO mapping is executable: rwxs!
      cve-2016-10044.c:62: FAIL: AIO mapping is executable: rwxs!
      cve-2016-10044.c:49: BROK: Failed to create AIO context: EAGAIN/EWOULDBLOCK

2) The kernel created an AIO pseudo-fs and introduced cve-2016-10044
   by the following patch:
   '71ad7490c1f3("rework aio migrate pages to use aio fs")'

   We should return TCONF rather than TBROK when an AIO pseudo-fs is
   not found in /proc/self/maps.

Signed-off-by: Xiao Yang <yangx.jy@cn.fujitsu.com>
---
 testcases/cve/cve-2016-10044.c | 5 ++++-
 1 file changed, 4 insertions(+), 1 deletion(-)

diff --git a/testcases/cve/cve-2016-10044.c b/testcases/cve/cve-2016-10044.c
index 7928d27..a84590a 100644
--- a/testcases/cve/cve-2016-10044.c
+++ b/testcases/cve/cve-2016-10044.c
@@ -53,7 +53,7 @@ static void run(void)
 		if (strstr(line, "/[aio]") != NULL)
 			goto found_mapping;
 	}
-	tst_brk(TBROK, "Could not find mapping in /proc/self/maps");
+	tst_brk(TCONF, "Could not find mapping in /proc/self/maps");
 
 found_mapping:
 	if (sscanf(line, "%*x-%*x %s7", perms) < 0)
@@ -63,6 +63,9 @@ found_mapping:
 	else
 		tst_res(TPASS, "AIO mapping is not executable: %s", perms);
 
+	if (tst_syscall(__NR_io_destroy, ctx))
+		tst_brk(TBROK | TERRNO, "Failed to destroy AIO context");
+
 	SAFE_FCLOSE(f);
 	f = NULL;
 }
-- 
1.8.3.1




^ permalink raw reply related	[flat|nested] 9+ messages in thread

end of thread, other threads:[~2017-10-26 10:23 UTC | newest]

Thread overview: 9+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2017-09-22  9:21 [LTP] [PATCH] cve/cve-2016-10044.c: fix two errors Xiao Yang
2017-09-22 11:06 ` Richard Palethorpe
2017-09-25 10:47   ` Xiao Yang
2017-09-25 11:16     ` Richard Palethorpe
2017-09-26  2:04       ` [LTP] [PATCH v2] " Xiao Yang
2017-10-05  2:11         ` Xiao Yang
2017-10-13  7:48         ` Xiao Yang
2017-10-26  9:02         ` Xiao Yang
2017-10-26 10:23           ` Cyril Hrubis

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox