From: Al Viro <viro@ZenIV.linux.org.uk>
To: linux-kernel@vger.kernel.org
Cc: Linus Torvalds <torvalds@linux-foundation.org>,
linux-fsdevel@vger.kernel.org,
Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Subject: [PATCH 18/20] usb: get rid of pointless access_ok() calls
Date: Sun, 10 May 2020 00:45:55 +0100 [thread overview]
Message-ID: <20200509234557.1124086-18-viro@ZenIV.linux.org.uk> (raw)
In-Reply-To: <20200509234557.1124086-1-viro@ZenIV.linux.org.uk>
From: Al Viro <viro@zeniv.linux.org.uk>
in all affected cases addresses are passed only to
copy_from()_user or copy_to_user().
Signed-off-by: Al Viro <viro@zeniv.linux.org.uk>
---
drivers/usb/core/devices.c | 2 --
drivers/usb/core/devio.c | 9 ---------
drivers/usb/gadget/function/f_hid.c | 6 ------
3 files changed, 17 deletions(-)
diff --git a/drivers/usb/core/devices.c b/drivers/usb/core/devices.c
index 44f28a114c2b..94b6fa6e585e 100644
--- a/drivers/usb/core/devices.c
+++ b/drivers/usb/core/devices.c
@@ -598,8 +598,6 @@ static ssize_t usb_device_read(struct file *file, char __user *buf,
return -EINVAL;
if (nbytes <= 0)
return 0;
- if (!access_ok(buf, nbytes))
- return -EFAULT;
mutex_lock(&usb_bus_idr_lock);
/* print devices for all busses */
diff --git a/drivers/usb/core/devio.c b/drivers/usb/core/devio.c
index 6833c918abce..544769807ab8 100644
--- a/drivers/usb/core/devio.c
+++ b/drivers/usb/core/devio.c
@@ -1127,11 +1127,6 @@ static int proc_control(struct usb_dev_state *ps, void __user *arg)
ctrl.bRequestType, ctrl.bRequest, ctrl.wValue,
ctrl.wIndex, ctrl.wLength);
if (ctrl.bRequestType & 0x80) {
- if (ctrl.wLength && !access_ok(ctrl.data,
- ctrl.wLength)) {
- ret = -EINVAL;
- goto done;
- }
pipe = usb_rcvctrlpipe(dev, 0);
snoop_urb(dev, NULL, pipe, ctrl.wLength, tmo, SUBMIT, NULL, 0);
@@ -1216,10 +1211,6 @@ static int proc_bulk(struct usb_dev_state *ps, void __user *arg)
}
tmo = bulk.timeout;
if (bulk.ep & 0x80) {
- if (len1 && !access_ok(bulk.data, len1)) {
- ret = -EINVAL;
- goto done;
- }
snoop_urb(dev, NULL, pipe, len1, tmo, SUBMIT, NULL, 0);
usb_unlock_device(dev);
diff --git a/drivers/usb/gadget/function/f_hid.c b/drivers/usb/gadget/function/f_hid.c
index f3816a5c861e..df671acdd464 100644
--- a/drivers/usb/gadget/function/f_hid.c
+++ b/drivers/usb/gadget/function/f_hid.c
@@ -252,9 +252,6 @@ static ssize_t f_hidg_read(struct file *file, char __user *buffer,
if (!count)
return 0;
- if (!access_ok(buffer, count))
- return -EFAULT;
-
spin_lock_irqsave(&hidg->read_spinlock, flags);
#define READ_COND (!list_empty(&hidg->completed_out_req))
@@ -339,9 +336,6 @@ static ssize_t f_hidg_write(struct file *file, const char __user *buffer,
unsigned long flags;
ssize_t status = -ENOMEM;
- if (!access_ok(buffer, count))
- return -EFAULT;
-
spin_lock_irqsave(&hidg->write_spinlock, flags);
#define WRITE_COND (!hidg->write_pending)
--
2.11.0
next prev parent reply other threads:[~2020-05-09 23:46 UTC|newest]
Thread overview: 42+ messages / expand[flat|nested] mbox.gz Atom feed top
2020-05-09 23:41 [PATCHES] uaccess simple access_ok() removals Al Viro
2020-05-09 23:45 ` [PATCH 01/20] dlmfs_file_write(): get rid of pointless access_ok() Al Viro
2020-05-09 23:45 ` [PATCH 02/20] fat_dir_ioctl(): hadn't needed that access_ok() for more than a decade Al Viro
2020-05-09 23:45 ` [PATCH 03/20] btrfs_ioctl_send(): don't bother with access_ok() Al Viro
2020-05-09 23:45 ` [PATCH 04/20] FIEMAP: " Al Viro
2020-05-10 7:02 ` Christoph Hellwig
2020-05-13 19:02 ` Al Viro
2020-05-13 19:38 ` Christoph Hellwig
2020-05-29 15:01 ` Al Viro
2020-05-09 23:45 ` [PATCH 05/20] tomoyo_write_control(): get rid of pointless access_ok() Al Viro
2020-05-10 0:50 ` Tetsuo Handa
2020-05-10 0:57 ` Linus Torvalds
2020-05-10 1:04 ` Tetsuo Handa
2020-05-10 3:01 ` Al Viro
2020-05-09 23:45 ` [PATCH 06/20] n_hdlc_tty_read(): remove " Al Viro
2020-05-15 10:53 ` Greg Kroah-Hartman
2020-05-09 23:45 ` [PATCH 07/20] nvram: drop useless access_ok() Al Viro
2020-05-15 10:54 ` Greg Kroah-Hartman
2020-05-09 23:45 ` [PATCH 08/20] cm4000_cs.c cmm_ioctl(): get rid of pointless access_ok() Al Viro
2020-05-09 23:45 ` [PATCH 09/20] drivers/fpga/dfl-fme-pr.c: " Al Viro
2020-05-09 23:45 ` [PATCH 10/20] drivers/fpga/dfl-afu-dma-region.c: " Al Viro
2020-05-09 23:45 ` [PATCH 11/20] amifb: get rid of pointless access_ok() calls Al Viro
2020-05-14 13:45 ` Bartlomiej Zolnierkiewicz
2020-05-14 14:07 ` Al Viro
2020-05-14 14:25 ` Bartlomiej Zolnierkiewicz
2020-05-14 17:41 ` Al Viro
2020-05-14 20:21 ` Geert Uytterhoeven
2020-05-09 23:45 ` [PATCH 12/20] omapfb: " Al Viro
2020-05-14 13:39 ` Bartlomiej Zolnierkiewicz
2020-05-09 23:45 ` [PATCH 13/20] drivers/crypto/ccp/sev-dev.c: get rid of pointless access_ok() Al Viro
2020-05-09 23:45 ` [PATCH 14/20] via-pmu: don't bother with access_ok() Al Viro
2020-05-09 23:45 ` [PATCH 15/20] drm_read(): get rid of pointless access_ok() Al Viro
2020-05-09 23:45 ` [PATCH 16/20] efi_test: " Al Viro
2020-05-09 23:45 ` [PATCH 17/20] lpfc_debugfs: " Al Viro
2020-05-09 23:45 ` Al Viro [this message]
2020-05-15 10:53 ` [PATCH 18/20] usb: get rid of pointless access_ok() calls Greg Kroah-Hartman
2020-05-09 23:45 ` [PATCH 19/20] hfi1: get rid of pointless access_ok() Al Viro
2020-05-09 23:45 ` [PATCH 4/4] vmci_host: " Al Viro
2020-05-15 10:53 ` Greg Kroah-Hartman
2020-05-10 0:34 ` [PATCHES] uaccess simple access_ok() removals Linus Torvalds
2020-05-10 3:27 ` Al Viro
2020-05-10 14:34 ` David Laight
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20200509234557.1124086-18-viro@ZenIV.linux.org.uk \
--to=viro@zeniv.linux.org.uk \
--cc=gregkh@linuxfoundation.org \
--cc=linux-fsdevel@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=torvalds@linux-foundation.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
Powered by JetHome