From: R.E.Wolff@BitWizard.nl (Rogier Wolff)
To: Anton Altaparmakov <aia21@cus.cam.ac.uk>
Cc: Rogier Wolff <R.E.Wolff@BitWizard.nl>,
Alan Cox <alan@lxorguk.ukuu.org.uk>,
Linus Torvalds <Linus.Torvalds@Helsinki.FI>,
linux-kernel@vger.kernel.org
Subject: Re: [PATCH] NTFS comment expanded, small fix.
Date: Sun, 15 Apr 2001 20:16:02 +0200 (MEST) [thread overview]
Message-ID: <200104151816.UAA22871@cave.bitwizard.nl> (raw)
In-Reply-To: <Pine.SOL.3.96.1010415173424.19123A-100000@libra.cus.cam.ac.uk> from Anton Altaparmakov at "Apr 15, 2001 06:11:08 pm"
Anton Altaparmakov wrote:
> >Also, the "start" value that is read from the record, could be much
> larger than expected, which could lead to accessing random data. The
> fixup should fail then, and this is also patched below.
>
> No it can't (in theory). The volume would be corrupt if it was. That kind
> of check belongs in ntfs fsck utility but not in kernel code.
>
> In any case, the correct check, if you want one, would be:
>
> if (start + (count * 2) > size)
> return 0;
Hi Anton,
Of course this is the better check. I was being sloppy.
I disagree with your "this belongs in an fsck-program". If this
condition triggers, then indeed, the filesystem is corrupt. But if the
"start" pointer is dereferenced, the kernel could be accessing an area
that you don't want touched (e.g. if the buffer happens to be near
enough to the "end-of-memory", you could "Ooops" .
The kernel should validate all user-input as much as possible, and an
ntfs-formatted-floppy should count as such.
The "fixup" routine has a bunch of "return 0" conditions. These are
similar to mine: If they trigger, the filesystem must be corrupt.
It's a sanity check, which is neccesary to keep Linux stable.
Roger.
--
** R.E.Wolff@BitWizard.nl ** http://www.BitWizard.nl/ ** +31-15-2137555 **
*-- BitWizard writes Linux device drivers for any device you may have! --*
* There are old pilots, and there are bold pilots.
* There are also old, bald pilots.
next prev parent reply other threads:[~2001-04-15 18:16 UTC|newest]
Thread overview: 7+ messages / expand[flat|nested] mbox.gz Atom feed top
2001-04-15 17:11 Anton Altaparmakov
2001-04-15 18:16 ` Rogier Wolff [this message]
2001-04-15 20:56 ` Anton Altaparmakov
2001-04-15 22:11 ` Alan Cox
2001-04-15 23:52 ` Anton Altaparmakov
2001-04-16 0:18 ` Alan Cox
-- strict thread matches above, loose matches on Subject: below --
2001-04-15 12:53 Rogier Wolff
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=200104151816.UAA22871@cave.bitwizard.nl \
--to=r.e.wolff@bitwizard.nl \
--cc=Linus.Torvalds@Helsinki.FI \
--cc=aia21@cus.cam.ac.uk \
--cc=alan@lxorguk.ukuu.org.uk \
--cc=linux-kernel@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®