From: Chris Metcalf <cmetcalf@ezchip.com>
To: Linus Torvalds <torvalds@linux-foundation.org>,
Ingo Molnar <mingo@kernel.org>,
Alexey Dobriyan <adobriyan@gmail.com>,
"Linux Kernel Mailing List" <linux-kernel@vger.kernel.org>
Cc: Chris Metcalf <cmetcalf@ezchip.com>
Subject: [PATCH] strscpy: zero any trailing garbage bytes in the destination
Date: Tue, 6 Oct 2015 12:47:14 -0400 [thread overview]
Message-ID: <1444150034-31729-1-git-send-email-cmetcalf@ezchip.com> (raw)
In-Reply-To: <CA+55aFwWd4BgQnpGRtNu1QAWQiZzdowbTYMPM4mOHL5+xwVsUA@mail.gmail.com>
It's possible that the destination can be shadowed in userspace
(as, for example, the perf buffers are now). So we should take
care not to leak data that could be inspected by userspace.
Signed-off-by: Chris Metcalf <cmetcalf@ezchip.com>
---
Ingo, can you test this change in your Fedora+strlcpy boot test?
I think it's correct but the more testing the better, particularly
if we're about to add the support for strlcpy to use it.
I did some light testing on big-endian tilegx and it appears
that zero_bytemask() is required and does the right thing.
On little-endian it's generally a no-op. This is pretty much
the same pattern that fs/namei.c uses now too.
lib/string.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/lib/string.c b/lib/string.c
index 8dbb7b1eab50..84775ba873b9 100644
--- a/lib/string.c
+++ b/lib/string.c
@@ -203,12 +203,13 @@ ssize_t strscpy(char *dest, const char *src, size_t count)
unsigned long c, data;
c = *(unsigned long *)(src+res);
- *(unsigned long *)(dest+res) = c;
if (has_zero(c, &data, &constants)) {
data = prep_zero_mask(c, data, &constants);
data = create_zero_mask(data);
+ *(unsigned long *)(dest+res) = c & zero_bytemask(data);
return res + find_zero(data);
}
+ *(unsigned long *)(dest+res) = c;
res += sizeof(unsigned long);
count -= sizeof(unsigned long);
max -= sizeof(unsigned long);
--
2.1.2
next prev parent reply other threads:[~2015-10-06 16:47 UTC|newest]
Thread overview: 13+ messages / expand[flat|nested] mbox.gz Atom feed top
2015-10-05 15:38 [PATCH] string: Improve the generic strlcpy() implementation Alexey Dobriyan
2015-10-05 16:11 ` Ingo Molnar
2015-10-05 16:13 ` Ingo Molnar
[not found] ` <CA+55aFyTVJfCt00gYJpiQW5kqPaRGJ93JmfRRni-73zCf5ivqg@mail.gmail.com>
2015-10-05 16:22 ` Ingo Molnar
2015-10-05 16:28 ` Ingo Molnar
2015-10-05 16:36 ` [PATCH] string: Fix strscpy() uninitialized data copy bug Ingo Molnar
2015-10-05 18:54 ` Chris Metcalf
2015-10-06 7:21 ` Ingo Molnar
2015-10-05 20:40 ` [PATCH] string: Improve the generic strlcpy() implementation Linus Torvalds
2015-10-06 16:47 ` Chris Metcalf [this message]
2015-10-06 16:59 ` [PATCH] strscpy: zero any trailing garbage bytes in the destination kbuild test robot
2015-10-06 17:34 ` Chris Metcalf
2015-10-07 7:28 ` Ingo Molnar
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=1444150034-31729-1-git-send-email-cmetcalf@ezchip.com \
--to=cmetcalf@ezchip.com \
--cc=adobriyan@gmail.com \
--cc=linux-kernel@vger.kernel.org \
--cc=mingo@kernel.org \
--cc=torvalds@linux-foundation.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®