mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Chris Wright <chrisw@osdl.org>
To: linux-kernel@vger.kernel.org
Cc: akpm@osdl.org, torvalds@osdl.org, marcelo.tosatti@cyclades.com
Subject: [PATCH 9/11] add mq_attr_ok() helper
Date: Tue, 11 May 2004 02:00:02 -0700	[thread overview]
Message-ID: <20040511020002.H21045@build.pdx.osdl.net> (raw)
In-Reply-To: <20040511015833.G21045@build.pdx.osdl.net>; from chrisw@osdl.org on Tue, May 11, 2004 at 01:58:33AM -0700

Add helper function mq_attr_ok() to do mq_attr sanity checking, and do
some extra overlow checking.

--- 2.6-rlimit/ipc/mqueue.c~mqueue_rlimit	2004-05-10 22:28:43.137833864 -0700
+++ 2.6-rlimit/ipc/mqueue.c	2004-05-10 22:30:44.530379392 -0700
@@ -534,6 +534,28 @@
 	info->notify_owner = 0;
 }
 
+static int mq_attr_ok(struct mq_attr *attr)
+{
+	if (attr->mq_maxmsg <= 0 || attr->mq_msgsize <= 0)
+		return 0;
+	if (capable(CAP_SYS_RESOURCE)) {
+		if (attr->mq_maxmsg > HARD_MSGMAX)
+			return 0;
+	} else {
+		if (attr->mq_maxmsg > msg_max ||
+				attr->mq_msgsize > msgsize_max)
+			return 0;
+	}
+	/* check for overflow */
+	if (attr->mq_msgsize > ULONG_MAX/attr->mq_maxmsg)
+		return 0;
+	if ((unsigned long)(attr->mq_maxmsg * attr->mq_msgsize) +
+	    (attr->mq_maxmsg * sizeof (struct msg_msg *)) <
+	    (unsigned long)(attr->mq_maxmsg * attr->mq_msgsize))
+		return 0;
+	return 1;
+}
+
 /*
  * Invoked when creating a new queue via sys_mq_open
  */
@@ -547,17 +569,8 @@
 	if (u_attr != NULL) {
 		if (copy_from_user(&attr, u_attr, sizeof(attr)))
 			return ERR_PTR(-EFAULT);
-
-		if (attr.mq_maxmsg <= 0 || attr.mq_msgsize <= 0)
+		if (!mq_attr_ok(&attr))
 			return ERR_PTR(-EINVAL);
-		if (capable(CAP_SYS_RESOURCE)) {
-			if (attr.mq_maxmsg > HARD_MSGMAX)
-				return ERR_PTR(-EINVAL);
-		} else {
-			if (attr.mq_maxmsg > msg_max ||
-					attr.mq_msgsize > msgsize_max)
-				return ERR_PTR(-EINVAL);
-		}
 		/* store for use during create */
 		dentry->d_fsdata = &attr;
 	}

  reply	other threads:[~2004-05-11  9:03 UTC|newest]

Thread overview: 12+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2004-05-11  8:42 [PATCH 0/11] rlimits for both queued signals and POSIX mqueues Chris Wright
2004-05-11  8:45 ` [PATCH 1/11] add rlimit entry for controlling queued signals Chris Wright
2004-05-11  8:46   ` [PATCH 2/11] add sigpending field to user_struct Chris Wright
2004-05-11  8:48     ` [PATCH 3/11] pass task_struct in send_signal() Chris Wright
2004-05-11  8:50       ` [PATCH 4/11] add simple get_uid() helper Chris Wright
2004-05-11  8:52         ` [PATCH 5/11] enforce rlimits on queued signals Chris Wright
2004-05-11  8:53           ` [PATCH 6/11] remove unused queued_signals global accounting Chris Wright
2004-05-11  8:56             ` [PATCH 7/11] add rlimit entry for POSIX mqueue allocation Chris Wright
2004-05-11  8:58               ` [PATCH 8/11] add mq_bytes to user_struct Chris Wright
2004-05-11  9:00                 ` Chris Wright [this message]
2004-05-11  9:02                   ` [PATCH 10/11] enforce rlimits for POSIX mqueue allocation Chris Wright
2004-05-11  9:04                     ` [PATCH 11/11] adjust default mqueue sizes Chris Wright

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20040511020002.H21045@build.pdx.osdl.net \
    --to=chrisw@osdl.org \
    --cc=akpm@osdl.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=marcelo.tosatti@cyclades.com \
    --cc=torvalds@osdl.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®