mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: David Laight <David.Laight@ACULAB.COM>
To: 'Peter Collingbourne' <pcc@google.com>,
	"David S. Miller" <davem@davemloft.net>,
	Jakub Kicinski <kuba@kernel.org>,
	Colin Ian King <colin.king@canonical.com>,
	Cong Wang <cong.wang@bytedance.com>,
	Al Viro <viro@zeniv.linux.org.uk>
Cc: "netdev@vger.kernel.org" <netdev@vger.kernel.org>,
	"linux-kernel@vger.kernel.org" <linux-kernel@vger.kernel.org>,
	"stable@vger.kernel.org" <stable@vger.kernel.org>
Subject: RE: [PATCH] net: don't unconditionally copy_from_user a struct ifreq for socket ioctls
Date: Thu, 26 Aug 2021 08:12:27 +0000	[thread overview]
Message-ID: <11f72b27c12f46eb8bef1d1773980c54@AcuMS.aculab.com> (raw)
In-Reply-To: <20210826012722.3210359-1-pcc@google.com>

From: Peter Collingbourne
> Sent: 26 August 2021 02:27
> 
> A common implementation of isatty(3) involves calling a ioctl passing
> a dummy struct argument and checking whether the syscall failed --
> bionic and glibc use TCGETS (passing a struct termios), and musl uses
> TIOCGWINSZ (passing a struct winsize). If the FD is a socket, we will
> copy sizeof(struct ifreq) bytes of data from the argument and return
> -EFAULT if that fails. The result is that the isatty implementations
> may return a non-POSIX-compliant value in errno in the case where part
> of the dummy struct argument is inaccessible, as both struct termios
> and struct winsize are smaller than struct ifreq (at least on arm64).
> 
> Although there is usually enough stack space following the argument
> on the stack that this did not present a practical problem up to now,
> with MTE stack instrumentation it's more likely for the copy to fail,
> as the memory following the struct may have a different tag.
> 
> Fix the problem by adding an early check for whether the ioctl is a
> valid socket ioctl, and return -ENOTTY if it isn't.
..
> +bool is_dev_ioctl_cmd(unsigned int cmd)
> +{
> +	switch (cmd) {
> +	case SIOCGIFNAME:
> +	case SIOCGIFHWADDR:
> +	case SIOCGIFFLAGS:
> +	case SIOCGIFMETRIC:
> +	case SIOCGIFMTU:
> +	case SIOCGIFSLAVE:
> +	case SIOCGIFMAP:
> +	case SIOCGIFINDEX:
> +	case SIOCGIFTXQLEN:
> +	case SIOCETHTOOL:
> +	case SIOCGMIIPHY:
> +	case SIOCGMIIREG:
> +	case SIOCSIFNAME:
> +	case SIOCSIFMAP:
> +	case SIOCSIFTXQLEN:
> +	case SIOCSIFFLAGS:
> +	case SIOCSIFMETRIC:
> +	case SIOCSIFMTU:
> +	case SIOCSIFHWADDR:
> +	case SIOCSIFSLAVE:
> +	case SIOCADDMULTI:
> +	case SIOCDELMULTI:
> +	case SIOCSIFHWBROADCAST:
> +	case SIOCSMIIREG:
> +	case SIOCBONDENSLAVE:
> +	case SIOCBONDRELEASE:
> +	case SIOCBONDSETHWADDR:
> +	case SIOCBONDCHANGEACTIVE:
> +	case SIOCBRADDIF:
> +	case SIOCBRDELIF:
> +	case SIOCSHWTSTAMP:
> +	case SIOCBONDSLAVEINFOQUERY:
> +	case SIOCBONDINFOQUERY:
> +	case SIOCGIFMEM:
> +	case SIOCSIFMEM:
> +	case SIOCSIFLINK:
> +	case SIOCWANDEV:
> +	case SIOCGHWTSTAMP:
> +		return true;

That is horrid.
Can't you at least use _IOC_TYPE() to check for socket ioctls.
Clearly it can succeed for 'random' driver ioctls, but will fail
for the tty ones.

The other sane thing is to check _IOC_SIZE().
Since all the SIOCxxxx have a correct _IOC_SIZE() that can be
used to check the user copy length.
(Unlike socket options the correct length is always supplied.

	David

-
Registered Address Lakeside, Bramley Road, Mount Farm, Milton Keynes, MK1 1PT, UK
Registration No: 1397386 (Wales)

  parent reply	other threads:[~2021-08-26  8:12 UTC|newest]

Thread overview: 8+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2021-08-26  1:27 Peter Collingbourne
2021-08-26  6:39 ` Greg KH
2021-08-26 19:46   ` Peter Collingbourne
2021-08-26  8:12 ` David Laight [this message]
2021-08-26 19:46   ` Peter Collingbourne
2021-08-27  8:34     ` David Laight
2021-08-26  8:58 ` Arnd Bergmann
2021-08-26 19:46   ` Peter Collingbourne

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=11f72b27c12f46eb8bef1d1773980c54@AcuMS.aculab.com \
    --to=david.laight@aculab.com \
    --cc=colin.king@canonical.com \
    --cc=cong.wang@bytedance.com \
    --cc=davem@davemloft.net \
    --cc=kuba@kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=netdev@vger.kernel.org \
    --cc=pcc@google.com \
    --cc=stable@vger.kernel.org \
    --cc=viro@zeniv.linux.org.uk \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®