From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1752693AbbH1PCz (ORCPT ); Fri, 28 Aug 2015 11:02:55 -0400 Received: from smtprelay0130.hostedemail.com ([216.40.44.130]:32986 "EHLO smtprelay.hostedemail.com" rhost-flags-OK-OK-OK-FAIL) by vger.kernel.org with ESMTP id S1751989AbbH1PCy (ORCPT ); Fri, 28 Aug 2015 11:02:54 -0400 X-Session-Marker: 726F737465647440676F6F646D69732E6F7267 X-Spam-Summary: 2,0,0,,d41d8cd98f00b204,rostedt@goodmis.org,:::::,RULES_HIT:41:355:379:541:599:800:960:973:988:989:1260:1277:1311:1313:1314:1345:1359:1437:1515:1516:1518:1534:1541:1593:1594:1711:1730:1747:1777:1792:2393:2553:2559:2562:3138:3139:3140:3141:3142:3352:3622:3865:3867:3868:3870:3871:3874:5007:6261:7875:8603:10004:10400:10848:10967:11026:11232:11473:11658:11914:12517:12519:12555:12740:13069:13255:13311:13357:14096:14097:21080,0,RBL:none,CacheIP:none,Bayesian:0.5,0.5,0.5,Netcheck:none,DomainCache:0,MSF:not bulk,SPF:fn,MSBL:0,DNSBL:none,Custom_rules:0:0:0 X-HE-Tag: shape36_19183632de925 X-Filterd-Recvd-Size: 2332 Date: Fri, 28 Aug 2015 11:02:51 -0400 From: Steven Rostedt To: Sasha Levin Cc: mingo@redhat.com, linux-kernel@vger.kernel.org Subject: Re: [PATCH] tracepoint: don't make assumptions about length of string on task rename Message-ID: <20150828110251.41b6b805@gandalf.local.home> In-Reply-To: <1440760018-1557-1-git-send-email-sasha.levin@oracle.com> References: <1440760018-1557-1-git-send-email-sasha.levin@oracle.com> X-Mailer: Claws Mail 3.11.1 (GTK+ 2.24.28; x86_64-pc-linux-gnu) MIME-Version: 1.0 Content-Type: text/plain; charset=US-ASCII Content-Transfer-Encoding: 7bit Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org On Fri, 28 Aug 2015 07:06:58 -0400 Sasha Levin wrote: > While the dest comm string size is assured to be at least TASK_COMM_LEN long, > doing a memcpy() also adds the assumption that the source is at least that > long as well, which isn't assured, and isn't true in cases such as: > > set_task_comm(worker->task, "kworker/dying"); > > This leads to accessing invalid memory. > > Signed-off-by: Sasha Levin Acked-by: Steven Rostedt Should this go to stable as well? Also, as the memcpy was just faster than a strcpy, the static length was used. Perhaps we should convert that to a dynamic length string. But that should be a separate patch as this one fixes a possible bug, and the conversion to a dynamic string is just an enhancement. -- Steve > --- > include/trace/events/task.h | 2 +- > 1 file changed, 1 insertion(+), 1 deletion(-) > > diff --git a/include/trace/events/task.h b/include/trace/events/task.h > index dee3bb1..2cca6cd 100644 > --- a/include/trace/events/task.h > +++ b/include/trace/events/task.h > @@ -46,7 +46,7 @@ TRACE_EVENT(task_rename, > TP_fast_assign( > __entry->pid = task->pid; > memcpy(entry->oldcomm, task->comm, TASK_COMM_LEN); > - memcpy(entry->newcomm, comm, TASK_COMM_LEN); > + strlcpy(entry->newcomm, comm, TASK_COMM_LEN); > __entry->oom_score_adj = task->signal->oom_score_adj; > ), >