From: "Paulo Andre'" <fscked@iol.pt>
To: Jens Axboe <axboe@suse.de>
Cc: linux-kernel@vger.kernel.org
Subject: [PATCH] Check copy_*_user return value in drivers/block/scsi_ioctl.c
Date: Sun, 25 May 2003 17:25:49 +0100 [thread overview]
Message-ID: <20030525172549.7df834f9.fscked@iol.pt> (raw)
[-- Attachment #1: Type: text/plain, Size: 218 bytes --]
Hi Jens,
Please find attached a trivial patch that checks both
copy_to_user() and copy_from_user() returns values in scsi_ioctl.c,
returning accordinly in case of a transfer error.
Please review.
Paulo Andre'
[-- Attachment #2: patch-scsi_ioctl.c.diff --]
[-- Type: text/plain, Size: 1248 bytes --]
--- scsi_ioctl.c.orig 2003-05-25 16:42:22.000000000 +0100
+++ scsi_ioctl.c 2003-05-25 16:59:44.000000000 +0100
@@ -213,7 +213,8 @@
nr_sectors = bytes >> 9;
if (writing)
- copy_from_user(buffer,hdr.dxferp,hdr.dxfer_len);
+ if (copy_from_user(buffer,hdr.dxferp,hdr.dxfer_len))
+ goto efault;
else
memset(buffer, 0, hdr.dxfer_len);
}
@@ -225,7 +226,8 @@
* fill in request structure
*/
rq->cmd_len = hdr.cmd_len;
- copy_from_user(rq->cmd, hdr.cmdp, hdr.cmd_len);
+ if (copy_from_user(rq->cmd, hdr.cmdp, hdr.cmd_len))
+ goto efault;
if (sizeof(rq->cmd) != hdr.cmd_len)
memset(rq->cmd + hdr.cmd_len, 0, sizeof(rq->cmd) - hdr.cmd_len);
@@ -286,17 +288,23 @@
blk_put_request(rq);
- copy_to_user(uptr, &hdr, sizeof(*uptr));
+ if (copy_to_user(uptr, &hdr, sizeof(*uptr)))
+ goto efault;
if (buffer) {
if (reading)
- copy_to_user(hdr.dxferp, buffer, hdr.dxfer_len);
+ if (copy_to_user(hdr.dxferp, buffer, hdr.dxfer_len))
+ goto efault;
kfree(buffer);
}
/* may not have succeeded, but output values written to control
* structure (struct sg_io_hdr). */
return 0;
+efault:
+ if (buffer)
+ kfree(buffer);
+ return -EFAULT;
}
#define FORMAT_UNIT_TIMEOUT (2 * 60 * 60 * HZ)
next reply other threads:[~2003-05-25 16:12 UTC|newest]
Thread overview: 5+ messages / expand[flat|nested] mbox.gz Atom feed top
2003-05-25 16:25 Paulo Andre' [this message]
2003-05-25 16:28 ` Jens Axboe
2003-05-25 1:29 ` dan carpenter
2003-05-25 16:54 ` Oliver Neukum
2003-05-25 16:58 ` Paulo Andre'
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20030525172549.7df834f9.fscked@iol.pt \
--to=fscked@iol.pt \
--cc=axboe@suse.de \
--cc=linux-kernel@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®