mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Sergey Vlasov <vsu@altlinux.ru>
To: Davi Arnaut <davi.arnaut@gmail.com>
Cc: torvalds@osdl.org, akpm@osdl.org, linux-kernel@vger.kernel.org
Subject: Re: [PATCH 0/2] strndup_user, v2
Date: Wed, 15 Feb 2006 23:54:01 +0300	[thread overview]
Message-ID: <20060215235401.381eea7c.vsu@altlinux.ru> (raw)
In-Reply-To: <20060215182258.03505613.davi.arnaut@gmail.com>

[-- Attachment #1: Type: text/plain, Size: 2953 bytes --]

On Wed, 15 Feb 2006 18:22:58 -0300 Davi Arnaut wrote:

> This patch series creates a strndup_user() function in order to avoid duplicated
> and error-prone (userspace modifying the string after the strlen_user()) code.
> 
> v2: Inline strdup_user and fixed a bogus strdup_user usage.
> 
> The diffstat:
> 
>  include/linux/string.h |    7 ++
>  kernel/module.c        |   19 +-------
>  mm/util.c              |   37 +++++++++++++++
>  security/keys/keyctl.c |  116 ++++++++++---------------------------------------
>  4 files changed, 72 insertions(+), 107 deletions(-)
> 
> 
> Signed-off-by: Davi Arnaut <davi.arnaut@gmail.com>
> --
> 
> diff --git a/include/linux/string.h b/include/linux/string.h
> index 369be32..8fbf139 100644
> --- a/include/linux/string.h
> +++ b/include/linux/string.h
> @@ -18,6 +18,13 @@ extern char * strsep(char **,const char 
>  extern __kernel_size_t strspn(const char *,const char *);
>  extern __kernel_size_t strcspn(const char *,const char *);
>  
> +extern char *strndup_user(const char __user *, long);
> +
> +static inline char *strdup_user(const char __user *s)
> +{
> +	return strndup_user(s, 4096);

PAGE_SIZE ?

> +}
> +
>  /*
>   * Include machine specific inline routines
>   */
> diff --git a/mm/util.c b/mm/util.c
> index 5f4bb59..09c2c3b 100644
> --- a/mm/util.c
> +++ b/mm/util.c
> @@ -1,6 +1,8 @@
>  #include <linux/slab.h>
>  #include <linux/string.h>
>  #include <linux/module.h>
> +#include <linux/err.h>
> +#include <asm/uaccess.h>
>  
>  /**
>   * kzalloc - allocate memory. The memory is set to zero.
> @@ -37,3 +39,38 @@ char *kstrdup(const char *s, gfp_t gfp)
>  	return buf;
>  }
>  EXPORT_SYMBOL(kstrdup);
> +
> +/*
> + * strndup_user - duplicate an existing string from user space
> + *
> + * @s: The string to duplicate
> + * @n: Maximum number of bytes to copy, including the trailing NUL.
> + */
> +char *strndup_user(const char __user *s, long n)
> +{
> +	char *p;
> +	long length;
> +
> +	length = strlen_user(s);

This should be strnlen_user(s, n) - no need to look at the whole
potentially huge string if you already have the limit.

> +
> +	if (!length)
> +		return ERR_PTR(-EFAULT);
> +
> +	if (length > n)
> +		length = n;

This silently truncates a too long string, which might not be proper
behavior (in fact, your patch #2 changes the behavior of keyctl
functions, which were rejecting too long strings with -EINVAL - this is
not good).

> +
> +	p = kmalloc(length, GFP_KERNEL);
> +
> +	if (!p)
> +		return ERR_PTR(-ENOMEM);
> +
> +	if (strncpy_from_user(p, s, length) < 0) {

This can be plain copy_from_user() - you already have the length, and
even if someone sneaks a NUL byte in the middle, copying bytes past it
will not matter.

> +		kfree(p);
> +		return ERR_PTR(-EFAULT);
> +	}
> +
> +	p[length - 1] = '\0';
> +
> +	return p;
> +}
> +EXPORT_SYMBOL(strndup_user);

[-- Attachment #2: Type: application/pgp-signature, Size: 190 bytes --]

  reply	other threads:[~2006-02-16 19:09 UTC|newest]

Thread overview: 5+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2006-02-15 21:22 Davi Arnaut
2006-02-15 20:54 ` Sergey Vlasov [this message]
2006-02-16  1:25 ` Alan Cox
2006-02-16  3:56   ` Davi Arnaut
2006-02-16 14:44     ` Alan Cox

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20060215235401.381eea7c.vsu@altlinux.ru \
    --to=vsu@altlinux.ru \
    --cc=akpm@osdl.org \
    --cc=davi.arnaut@gmail.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=torvalds@osdl.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

Powered by JetHome