From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S268069AbUHKO0H (ORCPT ); Wed, 11 Aug 2004 10:26:07 -0400 Received: (majordomo@vger.kernel.org) by vger.kernel.org id S268070AbUHKO0H (ORCPT ); Wed, 11 Aug 2004 10:26:07 -0400 Received: from castle.nmd.msu.ru ([193.232.112.53]:59919 "HELO castle.nmd.msu.ru") by vger.kernel.org with SMTP id S268069AbUHKO0E (ORCPT ); Wed, 11 Aug 2004 10:26:04 -0400 Message-ID: <20040811182602.A2055@castle.nmd.msu.ru> Date: Wed, 11 Aug 2004 18:26:02 +0400 From: Andrey Savochkin To: Marcelo Tosatti Cc: Jirka Kosina , Giuliano Pochini , linux-kernel@vger.kernel.org Subject: Re: FW: Linux kernel file offset pointer races References: <20040807171500.GA26084@logos.cnet> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii X-Mailer: Mutt 0.93.2i In-Reply-To: <20040807171500.GA26084@logos.cnet>; from "Marcelo Tosatti" on Sat, Aug 07, 2004 at 02:15:00PM Sender: linux-kernel-owner@vger.kernel.org X-Mailing-List: linux-kernel@vger.kernel.org BTW, f_pos assignments are non-atomic on IA-32 since it's a 64-bit value. The file position is protected by the BKL in llseek(), but I do not see any serialization neither in sys_read() nor in generic_file_read() and other methods. Have we accepted that the file position may be corrupted after crossing 2^32 boundary by 2 processes reading in parallel from the same file? Or am I missing something? Andrey On Sat, Aug 07, 2004 at 02:15:00PM -0300, Marcelo Tosatti wrote: > On Thu, Aug 05, 2004 at 12:30:23PM +0200, Jirka Kosina wrote: > > On Thu, 5 Aug 2004, Giuliano Pochini wrote: > > > > > I don't remember if this issue has already been discussed here: > > > -----FW: ----- > > > Date: Wed, 4 Aug 2004 12:22:42 +0200 (CEST) > > > From: Paul Starzetz > > > To: bugtraq@securityfocus.com, vulnwatch@vulnwatch.org, > > > full-disclosure@lists.netsys.com > > > Subject: Linux kernel file offset pointer races > > > > It hasn't been discussed here, but at > > http://linux.bkbits.net:8080/linux-2.4/gnupatch@411064f7uz3rKDb73dEb4vCqbjEIdw > > you can find a patchset fixing (some of) the mentioned problems. This > > patchset is from 2.4.27-rc5 > > "some of" ? > > Do you know any unfixed still broken piece of driver code ?