Netdev List
 help / color / mirror / Atom feed
* [PATCH 1/6] ip/ipnetns: prevent potential string buffer overflow
@ 2015-08-06 12:24 Phil Sutter
  2015-08-06 12:24 ` [PATCH 2/6] misc/ss: avoid NULL pointer dereference Phil Sutter
  2015-08-12 15:48 ` [PATCH 1/6] ip/ipnetns: prevent potential string buffer overflow Stephen Hemminger
  0 siblings, 2 replies; 8+ messages in thread
From: Phil Sutter @ 2015-08-06 12:24 UTC (permalink / raw)
  To: Stephen Hemminger; +Cc: netdev

Signed-off-by: Phil Sutter <phil@nwl.cc>
---
 ip/ipnetns.c | 3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

diff --git a/ip/ipnetns.c b/ip/ipnetns.c
index 3b704a4..32b0f51 100644
--- a/ip/ipnetns.c
+++ b/ip/ipnetns.c
@@ -178,7 +178,8 @@ static int netns_map_add(int nsid, char *name)
 		return -ENOMEM;
 	}
 	c->nsid = nsid;
-	strcpy(c->name, name);
+	strncpy(c->name, name, NAME_MAX);
+	c->name[NAME_MAX - 1] = '\0';
 
 	h = NSID_HASH_NSID(nsid);
 	hlist_add_head(&c->nsid_hash, &nsid_head[h]);
-- 
2.1.2

^ permalink raw reply related	[flat|nested] 8+ messages in thread

* [PATCH 2/6] misc/ss: avoid NULL pointer dereference
  2015-08-06 12:24 [PATCH 1/6] ip/ipnetns: prevent potential string buffer overflow Phil Sutter
@ 2015-08-06 12:24 ` Phil Sutter
  2015-08-06 12:24   ` [PATCH 3/6] misc/ss: simplify buffer realloc, fix checking realloc failure Phil Sutter
  2015-08-12 15:48 ` [PATCH 1/6] ip/ipnetns: prevent potential string buffer overflow Stephen Hemminger
  1 sibling, 1 reply; 8+ messages in thread
From: Phil Sutter @ 2015-08-06 12:24 UTC (permalink / raw)
  To: Stephen Hemminger; +Cc: netdev

This was working before, but only if realloc a) succeeded and b) did not
move the buffer to a different location. ''**buf = **new_buf' then
writes the value of *new_buf's first field into that of *buf.

Signed-off-by: Phil Sutter <phil@nwl.cc>
---
 misc/ss.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/misc/ss.c b/misc/ss.c
index f4c828c..af5a3c2 100644
--- a/misc/ss.c
+++ b/misc/ss.c
@@ -597,7 +597,7 @@ static int find_entry(unsigned ino, char **buf, int type)
 					fprintf(stderr, "ss: failed to malloc buffer\n");
 					abort();
 				}
-				**buf = **new_buf;
+				*buf = *new_buf;
 				buf_len = new_buf_len;
 				continue;
 			} else {
-- 
2.1.2

^ permalink raw reply related	[flat|nested] 8+ messages in thread

* [PATCH 3/6] misc/ss: simplify buffer realloc, fix checking realloc failure
  2015-08-06 12:24 ` [PATCH 2/6] misc/ss: avoid NULL pointer dereference Phil Sutter
@ 2015-08-06 12:24   ` Phil Sutter
  2015-08-06 12:24     ` [PATCH 4/6] misc/ss: add missing fclose() calls Phil Sutter
  0 siblings, 1 reply; 8+ messages in thread
From: Phil Sutter @ 2015-08-06 12:24 UTC (permalink / raw)
  To: Stephen Hemminger; +Cc: netdev

Signed-off-by: Phil Sutter <phil@nwl.cc>
---
 misc/ss.c | 6 +++---
 1 file changed, 3 insertions(+), 3 deletions(-)

diff --git a/misc/ss.c b/misc/ss.c
index af5a3c2..e77655a 100644
--- a/misc/ss.c
+++ b/misc/ss.c
@@ -550,7 +550,7 @@ static int find_entry(unsigned ino, char **buf, int type)
 	struct user_ent *p;
 	int cnt = 0;
 	char *ptr;
-	char **new_buf = buf;
+	char *new_buf;
 	int len, new_buf_len;
 	int buf_used = 0;
 	int buf_len = 0;
@@ -592,12 +592,12 @@ static int find_entry(unsigned ino, char **buf, int type)
 
 			if (len < 0 || len >= buf_len - buf_used) {
 				new_buf_len = buf_len + ENTRY_BUF_SIZE;
-				*new_buf = realloc(*buf, new_buf_len);
+				new_buf = realloc(*buf, new_buf_len);
 				if (!new_buf) {
 					fprintf(stderr, "ss: failed to malloc buffer\n");
 					abort();
 				}
-				*buf = *new_buf;
+				*buf = new_buf;
 				buf_len = new_buf_len;
 				continue;
 			} else {
-- 
2.1.2

^ permalink raw reply related	[flat|nested] 8+ messages in thread

* [PATCH 4/6] misc/ss: add missing fclose() calls
  2015-08-06 12:24   ` [PATCH 3/6] misc/ss: simplify buffer realloc, fix checking realloc failure Phil Sutter
@ 2015-08-06 12:24     ` Phil Sutter
  2015-08-06 12:24       ` [PATCH 5/6] lib/namespace: don't leak fd in error case Phil Sutter
  0 siblings, 1 reply; 8+ messages in thread
From: Phil Sutter @ 2015-08-06 12:24 UTC (permalink / raw)
  To: Stephen Hemminger; +Cc: netdev

Signed-off-by: Phil Sutter <phil@nwl.cc>
---
 misc/ss.c | 7 +++++--
 1 file changed, 5 insertions(+), 2 deletions(-)

diff --git a/misc/ss.c b/misc/ss.c
index e77655a..0c7c6d7 100644
--- a/misc/ss.c
+++ b/misc/ss.c
@@ -3025,6 +3025,7 @@ static int packet_show_line(char *buf, const struct filter *f, int fam)
 static int packet_show(struct filter *f)
 {
 	FILE *fp;
+	int rc = 0;
 
 	if (!filter_af_get(f, AF_PACKET) || !(f->states & (1 << SS_CLOSE)))
 		return 0;
@@ -3036,9 +3037,10 @@ static int packet_show(struct filter *f)
 	if ((fp = net_packet_open()) == NULL)
 		return -1;
 	if (generic_record_read(fp, packet_show_line, f, AF_PACKET))
-		return -1;
+		rc = -1;
 
-	return 0;
+	fclose(fp);
+	return rc;
 }
 
 static int netlink_show_one(struct filter *f,
@@ -3215,6 +3217,7 @@ static int netlink_show(struct filter *f)
 		netlink_show_one(f, prot, pid, groups, 0, 0, 0, rq, wq, sk, cb);
 	}
 
+	fclose(fp);
 	return 0;
 }
 
-- 
2.1.2

^ permalink raw reply related	[flat|nested] 8+ messages in thread

* [PATCH 5/6] lib/namespace: don't leak fd in error case
  2015-08-06 12:24     ` [PATCH 4/6] misc/ss: add missing fclose() calls Phil Sutter
@ 2015-08-06 12:24       ` Phil Sutter
  2015-08-06 12:24         ` [PATCH 6/6] misc/ss: fix memory leak in user_ent_hash_build() Phil Sutter
       [not found]         ` <b64bd55adf5d4f96b8f4d6e414161fad@BRMWP-EXMB11.corp.brocade.com>
  0 siblings, 2 replies; 8+ messages in thread
From: Phil Sutter @ 2015-08-06 12:24 UTC (permalink / raw)
  To: Stephen Hemminger; +Cc: netdev

Signed-off-by: Phil Sutter <phil@nwl.cc>
---
 lib/namespace.c | 13 ++++++++-----
 1 file changed, 8 insertions(+), 5 deletions(-)

diff --git a/lib/namespace.c b/lib/namespace.c
index a61feb6..8197165 100644
--- a/lib/namespace.c
+++ b/lib/namespace.c
@@ -58,32 +58,35 @@ int netns_switch(char *name)
 	if (setns(netns, CLONE_NEWNET) < 0) {
 		fprintf(stderr, "setting the network namespace \"%s\" failed: %s\n",
 			name, strerror(errno));
-		return -1;
+		goto fail_close;
 	}
 
 	if (unshare(CLONE_NEWNS) < 0) {
 		fprintf(stderr, "unshare failed: %s\n", strerror(errno));
-		return -1;
+		goto fail_close;
 	}
 	/* Don't let any mounts propagate back to the parent */
 	if (mount("", "/", "none", MS_SLAVE | MS_REC, NULL)) {
 		fprintf(stderr, "\"mount --make-rslave /\" failed: %s\n",
 			strerror(errno));
-		return -1;
+		goto fail_close;
 	}
 	/* Mount a version of /sys that describes the network namespace */
 	if (umount2("/sys", MNT_DETACH) < 0) {
 		fprintf(stderr, "umount of /sys failed: %s\n", strerror(errno));
-		return -1;
+		goto fail_close;
 	}
 	if (mount(name, "/sys", "sysfs", 0, NULL) < 0) {
 		fprintf(stderr, "mount of /sys failed: %s\n",strerror(errno));
-		return -1;
+		goto fail_close;
 	}
 
 	/* Setup bind mounts for config files in /etc */
 	bind_etc(name);
 	return 0;
+fail_close:
+	close(netns);
+	return -1;
 }
 
 int netns_get_fd(const char *name)
-- 
2.1.2

^ permalink raw reply related	[flat|nested] 8+ messages in thread

* [PATCH 6/6] misc/ss: fix memory leak in user_ent_hash_build()
  2015-08-06 12:24       ` [PATCH 5/6] lib/namespace: don't leak fd in error case Phil Sutter
@ 2015-08-06 12:24         ` Phil Sutter
       [not found]         ` <b64bd55adf5d4f96b8f4d6e414161fad@BRMWP-EXMB11.corp.brocade.com>
  1 sibling, 0 replies; 8+ messages in thread
From: Phil Sutter @ 2015-08-06 12:24 UTC (permalink / raw)
  To: Stephen Hemminger; +Cc: netdev

Signed-off-by: Phil Sutter <phil@nwl.cc>
---
 misc/ss.c | 4 +++-
 1 file changed, 3 insertions(+), 1 deletion(-)

diff --git a/misc/ss.c b/misc/ss.c
index 0c7c6d7..bba7009 100644
--- a/misc/ss.c
+++ b/misc/ss.c
@@ -483,8 +483,10 @@ static void user_ent_hash_build(void)
 
 		sprintf(name + nameoff, "%d/fd/", pid);
 		pos = strlen(name);
-		if ((dir1 = opendir(name)) == NULL)
+		if ((dir1 = opendir(name)) == NULL) {
+			free(pid_context);
 			continue;
+		}
 
 		process[0] = '\0';
 		p = process;
-- 
2.1.2

^ permalink raw reply related	[flat|nested] 8+ messages in thread

* Re: [PATCH 1/6] ip/ipnetns: prevent potential string buffer overflow
  2015-08-06 12:24 [PATCH 1/6] ip/ipnetns: prevent potential string buffer overflow Phil Sutter
  2015-08-06 12:24 ` [PATCH 2/6] misc/ss: avoid NULL pointer dereference Phil Sutter
@ 2015-08-12 15:48 ` Stephen Hemminger
  1 sibling, 0 replies; 8+ messages in thread
From: Stephen Hemminger @ 2015-08-12 15:48 UTC (permalink / raw)
  To: Phil Sutter; +Cc: netdev

Rather than chopping the string off, I decided to solve the problem by changing
network namespace cache to use variable length structure.

^ permalink raw reply	[flat|nested] 8+ messages in thread

* Re: [PATCH 6/6] misc/ss: fix memory leak in user_ent_hash_build()
       [not found]         ` <b64bd55adf5d4f96b8f4d6e414161fad@BRMWP-EXMB11.corp.brocade.com>
@ 2015-08-12 16:27           ` Stephen Hemminger
  0 siblings, 0 replies; 8+ messages in thread
From: Stephen Hemminger @ 2015-08-12 16:27 UTC (permalink / raw)
  To: Phil Sutter; +Cc: netdev@vger.kernel.org

On Thu, 6 Aug 2015 12:24:36 +0000
Phil Sutter <phil@nwl.cc> wrote:

> Signed-off-by: Phil Sutter <phil@nwl.cc>

I applied the rest of these as is.

^ permalink raw reply	[flat|nested] 8+ messages in thread

end of thread, other threads:[~2015-08-12 16:27 UTC | newest]

Thread overview: 8+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2015-08-06 12:24 [PATCH 1/6] ip/ipnetns: prevent potential string buffer overflow Phil Sutter
2015-08-06 12:24 ` [PATCH 2/6] misc/ss: avoid NULL pointer dereference Phil Sutter
2015-08-06 12:24   ` [PATCH 3/6] misc/ss: simplify buffer realloc, fix checking realloc failure Phil Sutter
2015-08-06 12:24     ` [PATCH 4/6] misc/ss: add missing fclose() calls Phil Sutter
2015-08-06 12:24       ` [PATCH 5/6] lib/namespace: don't leak fd in error case Phil Sutter
2015-08-06 12:24         ` [PATCH 6/6] misc/ss: fix memory leak in user_ent_hash_build() Phil Sutter
     [not found]         ` <b64bd55adf5d4f96b8f4d6e414161fad@BRMWP-EXMB11.corp.brocade.com>
2015-08-12 16:27           ` Stephen Hemminger
2015-08-12 15:48 ` [PATCH 1/6] ip/ipnetns: prevent potential string buffer overflow Stephen Hemminger

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox