* [PATCH 8/9] USB usbfs: missing lock in proc_getdriver
@ 2004-04-14 10:47 Duncan Sands
2004-04-14 11:04 ` [linux-usb-devel] " Oliver Neukum
0 siblings, 1 reply; 5+ messages in thread
From: Duncan Sands @ 2004-04-14 10:47 UTC (permalink / raw)
To: Greg KH; +Cc: linux-usb-devel, linux-kernel, Frederic Detienne
Protect against driver binding changes while reading the driver name.
devio.c | 14 ++++++++------
1 files changed, 8 insertions(+), 6 deletions(-)
diff -Nru a/drivers/usb/core/devio.c b/drivers/usb/core/devio.c
--- a/drivers/usb/core/devio.c Wed Apr 14 12:18:30 2004
+++ b/drivers/usb/core/devio.c Wed Apr 14 12:18:30 2004
@@ -709,12 +709,14 @@
if ((ret = findintfif(ps->dev, gd.interface)) < 0)
return ret;
interface = ps->dev->actconfig->interface[ret];
- if (!interface->dev.driver)
- return -ENODATA;
- strncpy(gd.driver, interface->dev.driver->name, sizeof(gd.driver));
- if (copy_to_user(arg, &gd, sizeof(gd)))
- return -EFAULT;
- return 0;
+ ret = -ENODATA;
+ down_read(&usb_bus_type.subsys.rwsem);
+ if (interface && interface->dev.driver) {
+ strncpy(gd.driver, interface->dev.driver->name, sizeof(gd.driver));
+ ret = copy_to_user(arg, &gd, sizeof(gd)) ? -EFAULT : 0;
+ }
+ up_read(&usb_bus_type.subsys.rwsem);
+ return ret;
}
static int proc_connectinfo(struct dev_state *ps, void __user *arg)
^ permalink raw reply [flat|nested] 5+ messages in thread
* Re: [linux-usb-devel] [PATCH 8/9] USB usbfs: missing lock in proc_getdriver
2004-04-14 10:47 [PATCH 8/9] USB usbfs: missing lock in proc_getdriver Duncan Sands
@ 2004-04-14 11:04 ` Oliver Neukum
2004-04-14 11:37 ` Duncan Sands
0 siblings, 1 reply; 5+ messages in thread
From: Oliver Neukum @ 2004-04-14 11:04 UTC (permalink / raw)
To: Duncan Sands, Greg KH; +Cc: linux-usb-devel, linux-kernel, Frederic Detienne
> + down_read(&usb_bus_type.subsys.rwsem);
> + if (interface && interface->dev.driver) {
> + strncpy(gd.driver, interface->dev.driver->name, sizeof(gd.driver));
> + ret = copy_to_user(arg, &gd, sizeof(gd)) ? -EFAULT : 0;
> + }
> + up_read(&usb_bus_type.subsys.rwsem);
> + return ret;
IMHO you should drop the lock before you copy to userspace.
Regards
Oliver
^ permalink raw reply [flat|nested] 5+ messages in thread
* Re: [linux-usb-devel] [PATCH 8/9] USB usbfs: missing lock in proc_getdriver
2004-04-14 11:04 ` [linux-usb-devel] " Oliver Neukum
@ 2004-04-14 11:37 ` Duncan Sands
2004-04-14 13:29 ` Oliver Neukum
0 siblings, 1 reply; 5+ messages in thread
From: Duncan Sands @ 2004-04-14 11:37 UTC (permalink / raw)
To: Oliver Neukum, Greg KH; +Cc: linux-usb-devel, linux-kernel, Frederic Detienne
On Wednesday 14 April 2004 13:04, Oliver Neukum wrote:
> > + down_read(&usb_bus_type.subsys.rwsem);
> > + if (interface && interface->dev.driver) {
> > + strncpy(gd.driver, interface->dev.driver->name, sizeof(gd.driver));
> > + ret = copy_to_user(arg, &gd, sizeof(gd)) ? -EFAULT : 0;
> > + }
> > + up_read(&usb_bus_type.subsys.rwsem);
> > + return ret;
>
> IMHO you should drop the lock before you copy to userspace.
Hi Oliver, I wasn't particularly worried about it since it's a rwsem taken for
reading and writing is a rare event. Do you think it really matters? If so,
how about this instead (compiles but otherwise untested):
@@ -702,13 +708,15 @@
return -EFAULT;
if ((ret = findintfif(ps->dev, gd.interface)) < 0)
return ret;
+ down_read(&usb_bus_type.subsys.rwsem);
interface = ps->dev->actconfig->interface[ret];
- if (!interface->dev.driver)
+ if (!interface || !interface->dev.driver) {
+ up_read(&usb_bus_type.subsys.rwsem);
return -ENODATA;
+ }
strncpy(gd.driver, interface->dev.driver->name, sizeof(gd.driver));
- if (copy_to_user(arg, &gd, sizeof(gd)))
- return -EFAULT;
- return 0;
+ up_read(&usb_bus_type.subsys.rwsem);
+ return copy_to_user(arg, &gd, sizeof(gd)) ? -EFAULT : 0;
}
static int proc_connectinfo(struct dev_state *ps, void __user *arg)
^ permalink raw reply [flat|nested] 5+ messages in thread
* Re: [linux-usb-devel] [PATCH 8/9] USB usbfs: missing lock in proc_getdriver
2004-04-14 11:37 ` Duncan Sands
@ 2004-04-14 13:29 ` Oliver Neukum
2004-04-14 14:04 ` Duncan Sands
0 siblings, 1 reply; 5+ messages in thread
From: Oliver Neukum @ 2004-04-14 13:29 UTC (permalink / raw)
To: Duncan Sands, Greg KH; +Cc: linux-usb-devel, linux-kernel, Frederic Detienne
Am Mittwoch, 14. April 2004 13:37 schrieb Duncan Sands:
> On Wednesday 14 April 2004 13:04, Oliver Neukum wrote:
> > > + down_read(&usb_bus_type.subsys.rwsem);
> > > + if (interface && interface->dev.driver) {
> > > + strncpy(gd.driver, interface->dev.driver->name, sizeof(gd.driver));
> > > + ret = copy_to_user(arg, &gd, sizeof(gd)) ? -EFAULT : 0;
> > > + }
> > > + up_read(&usb_bus_type.subsys.rwsem);
> > > + return ret;
> >
> > IMHO you should drop the lock before you copy to userspace.
>
> Hi Oliver, I wasn't particularly worried about it since it's a rwsem taken
> for reading and writing is a rare event. Do you think it really matters?
> If so, how about this instead (compiles but otherwise untested):
Hi,
I expect it to rarely matter, but it might matter now and then. It's
just a question of hygiene. If you are using a temporary buffer I'd
like to see it used to full advantage. So either drop the lock or do
a direct copy. I'd prefer the first option your patch implemented.
Regards
Oliver
^ permalink raw reply [flat|nested] 5+ messages in thread
* Re: [linux-usb-devel] [PATCH 8/9] USB usbfs: missing lock in proc_getdriver
2004-04-14 13:29 ` Oliver Neukum
@ 2004-04-14 14:04 ` Duncan Sands
0 siblings, 0 replies; 5+ messages in thread
From: Duncan Sands @ 2004-04-14 14:04 UTC (permalink / raw)
To: Oliver Neukum, Greg KH; +Cc: linux-usb-devel, linux-kernel, Frederic Detienne
Hi Oliver,
> I expect it to rarely matter, but it might matter now and then. It's
> just a question of hygiene. If you are using a temporary buffer I'd
> like to see it used to full advantage. So either drop the lock or do
> a direct copy. I'd prefer the first option your patch implemented.
I agree. Greg, please consider applying the updated patch:
--- gregkh-2.6/drivers/usb/core/devio.c.orig 2004-04-14 16:02:44.000000000 +0200
+++ gregkh-2.6/drivers/usb/core/devio.c 2004-04-14 16:03:12.000000000 +0200
@@ -702,13 +708,15 @@
return -EFAULT;
if ((ret = findintfif(ps->dev, gd.interface)) < 0)
return ret;
+ down_read(&usb_bus_type.subsys.rwsem);
interface = ps->dev->actconfig->interface[ret];
- if (!interface->dev.driver)
+ if (!interface || !interface->dev.driver) {
+ up_read(&usb_bus_type.subsys.rwsem);
return -ENODATA;
+ }
strncpy(gd.driver, interface->dev.driver->name, sizeof(gd.driver));
- if (copy_to_user(arg, &gd, sizeof(gd)))
- return -EFAULT;
- return 0;
+ up_read(&usb_bus_type.subsys.rwsem);
+ return copy_to_user(arg, &gd, sizeof(gd)) ? -EFAULT : 0;
}
static int proc_connectinfo(struct dev_state *ps, void __user *arg)
^ permalink raw reply [flat|nested] 5+ messages in thread
end of thread, other threads:[~2004-04-14 14:05 UTC | newest]
Thread overview: 5+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2004-04-14 10:47 [PATCH 8/9] USB usbfs: missing lock in proc_getdriver Duncan Sands
2004-04-14 11:04 ` [linux-usb-devel] " Oliver Neukum
2004-04-14 11:37 ` Duncan Sands
2004-04-14 13:29 ` Oliver Neukum
2004-04-14 14:04 ` Duncan Sands
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®