From mboxrd@z Thu Jan 1 00:00:00 1970 From: Al Viro Subject: Re: [PATCH] socket: fix struct ifreq size in compat ioctl Date: Thu, 13 Sep 2018 13:13:53 +0100 Message-ID: <20180913121353.GR19965@ZenIV.linux.org.uk> References: <20180913114909.8331-1-johannes@sipsolutions.net> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Cc: netdev@vger.kernel.org, Robert O'Callahan , Johannes Berg To: Johannes Berg Return-path: Received: from zeniv.linux.org.uk ([195.92.253.2]:54140 "EHLO ZenIV.linux.org.uk" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1726919AbeIMRXH (ORCPT ); Thu, 13 Sep 2018 13:23:07 -0400 Content-Disposition: inline In-Reply-To: <20180913114909.8331-1-johannes@sipsolutions.net> Sender: netdev-owner@vger.kernel.org List-ID: On Thu, Sep 13, 2018 at 01:49:09PM +0200, Johannes Berg wrote: > From: Johannes Berg > > As reported by Reobert O'Callahan, since Viro's commit to kill > dev_ifsioc() we attempt to copy too much data in compat mode, > which may lead to EFAULT when the 32-bit version of struct ifreq > sits at/near the end of a page boundary, and the next page isn't > mapped. > > Fix this by passing whether or not we're doing a compat call and > copying the appropriate size in/out, as we did before. This works > because only the embedded "struct ifmap" has different size, and > this is only used in SIOCGIFMAP/SIOCSIFMAP which has a different > handler. All other parts of the union are naturally compatible. Might be better to pass explicit size instead of this bool compat...