From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1422714AbbEUV0l (ORCPT ); Thu, 21 May 2015 17:26:41 -0400 Received: from li271-223.members.linode.com ([178.79.152.223]:57745 "EHLO mail.mleia.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1755596AbbEUV0k (ORCPT ); Thu, 21 May 2015 17:26:40 -0400 X-Greylist: delayed 305 seconds by postgrey-1.27 at vger.kernel.org; Thu, 21 May 2015 17:26:39 EDT From: Vladimir Zapolskiy To: Greg Kroah-Hartman , Tejun Heo Cc: linux-kernel@vger.kernel.org Subject: [PATCH] fs: sysfs: don't pass count == 0 to bin file readers Date: Fri, 22 May 2015 00:21:16 +0300 Message-Id: <1432243276-27733-1-git-send-email-vz@mleia.com> X-Mailer: git-send-email 1.7.10.4 X-CRM114-Version: 20100106-BlameMichelson ( TRE 0.8.0 (BSD) ) MR-49551924 X-CRM114-CacheID: sfid-20150521_222355_854939_4A24BBC7 X-CRM114-Status: GOOD ( 12.16 ) Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org If count == 0 bytes are requested by a reader, sysfs_kf_bin_read() deliberately returns 0 without passing a potentially harmful value to some externally defined underlying battr->read() function. However in case of (pos == size && count) the next clause always sets count to 0 and this value is handed over to battr->read(). The change intends to make obsolete (and remove later) a redundant sanity check in battr->read(), if it is present, or add more protection to struct bin_attribute users, who does not care about input arguments. Signed-off-by: Vladimir Zapolskiy --- fs/sysfs/file.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/fs/sysfs/file.c b/fs/sysfs/file.c index 7c2867b..6c95628 100644 --- a/fs/sysfs/file.c +++ b/fs/sysfs/file.c @@ -90,7 +90,7 @@ static ssize_t sysfs_kf_bin_read(struct kernfs_open_file *of, char *buf, return 0; if (size) { - if (pos > size) + if (pos >= size) return 0; if (pos + count > size) count = size - pos; -- 1.7.10.4