From: David Laight <David.Laight@ACULAB.COM>
To: 'Peter Collingbourne' <pcc@google.com>,
"David S. Miller" <davem@davemloft.net>,
Jakub Kicinski <kuba@kernel.org>,
Colin Ian King <colin.king@canonical.com>,
Cong Wang <cong.wang@bytedance.com>,
Al Viro <viro@zeniv.linux.org.uk>
Cc: "netdev@vger.kernel.org" <netdev@vger.kernel.org>,
"linux-kernel@vger.kernel.org" <linux-kernel@vger.kernel.org>,
"stable@vger.kernel.org" <stable@vger.kernel.org>
Subject: RE: [PATCH] net: don't unconditionally copy_from_user a struct ifreq for socket ioctls
Date: Thu, 26 Aug 2021 08:12:27 +0000 [thread overview]
Message-ID: <11f72b27c12f46eb8bef1d1773980c54@AcuMS.aculab.com> (raw)
In-Reply-To: <20210826012722.3210359-1-pcc@google.com>
From: Peter Collingbourne
> Sent: 26 August 2021 02:27
>
> A common implementation of isatty(3) involves calling a ioctl passing
> a dummy struct argument and checking whether the syscall failed --
> bionic and glibc use TCGETS (passing a struct termios), and musl uses
> TIOCGWINSZ (passing a struct winsize). If the FD is a socket, we will
> copy sizeof(struct ifreq) bytes of data from the argument and return
> -EFAULT if that fails. The result is that the isatty implementations
> may return a non-POSIX-compliant value in errno in the case where part
> of the dummy struct argument is inaccessible, as both struct termios
> and struct winsize are smaller than struct ifreq (at least on arm64).
>
> Although there is usually enough stack space following the argument
> on the stack that this did not present a practical problem up to now,
> with MTE stack instrumentation it's more likely for the copy to fail,
> as the memory following the struct may have a different tag.
>
> Fix the problem by adding an early check for whether the ioctl is a
> valid socket ioctl, and return -ENOTTY if it isn't.
..
> +bool is_dev_ioctl_cmd(unsigned int cmd)
> +{
> + switch (cmd) {
> + case SIOCGIFNAME:
> + case SIOCGIFHWADDR:
> + case SIOCGIFFLAGS:
> + case SIOCGIFMETRIC:
> + case SIOCGIFMTU:
> + case SIOCGIFSLAVE:
> + case SIOCGIFMAP:
> + case SIOCGIFINDEX:
> + case SIOCGIFTXQLEN:
> + case SIOCETHTOOL:
> + case SIOCGMIIPHY:
> + case SIOCGMIIREG:
> + case SIOCSIFNAME:
> + case SIOCSIFMAP:
> + case SIOCSIFTXQLEN:
> + case SIOCSIFFLAGS:
> + case SIOCSIFMETRIC:
> + case SIOCSIFMTU:
> + case SIOCSIFHWADDR:
> + case SIOCSIFSLAVE:
> + case SIOCADDMULTI:
> + case SIOCDELMULTI:
> + case SIOCSIFHWBROADCAST:
> + case SIOCSMIIREG:
> + case SIOCBONDENSLAVE:
> + case SIOCBONDRELEASE:
> + case SIOCBONDSETHWADDR:
> + case SIOCBONDCHANGEACTIVE:
> + case SIOCBRADDIF:
> + case SIOCBRDELIF:
> + case SIOCSHWTSTAMP:
> + case SIOCBONDSLAVEINFOQUERY:
> + case SIOCBONDINFOQUERY:
> + case SIOCGIFMEM:
> + case SIOCSIFMEM:
> + case SIOCSIFLINK:
> + case SIOCWANDEV:
> + case SIOCGHWTSTAMP:
> + return true;
That is horrid.
Can't you at least use _IOC_TYPE() to check for socket ioctls.
Clearly it can succeed for 'random' driver ioctls, but will fail
for the tty ones.
The other sane thing is to check _IOC_SIZE().
Since all the SIOCxxxx have a correct _IOC_SIZE() that can be
used to check the user copy length.
(Unlike socket options the correct length is always supplied.
David
-
Registered Address Lakeside, Bramley Road, Mount Farm, Milton Keynes, MK1 1PT, UK
Registration No: 1397386 (Wales)
next prev parent reply other threads:[~2021-08-26 8:12 UTC|newest]
Thread overview: 8+ messages / expand[flat|nested] mbox.gz Atom feed top
2021-08-26 1:27 Peter Collingbourne
2021-08-26 6:39 ` Greg KH
2021-08-26 19:46 ` Peter Collingbourne
2021-08-26 8:12 ` David Laight [this message]
2021-08-26 19:46 ` Peter Collingbourne
2021-08-27 8:34 ` David Laight
2021-08-26 8:58 ` Arnd Bergmann
2021-08-26 19:46 ` Peter Collingbourne
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=11f72b27c12f46eb8bef1d1773980c54@AcuMS.aculab.com \
--to=david.laight@aculab.com \
--cc=colin.king@canonical.com \
--cc=cong.wang@bytedance.com \
--cc=davem@davemloft.net \
--cc=kuba@kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=netdev@vger.kernel.org \
--cc=pcc@google.com \
--cc=stable@vger.kernel.org \
--cc=viro@zeniv.linux.org.uk \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®