From: Sasha Levin <sashal@kernel.org>
To: linux-kernel@vger.kernel.org, stable@vger.kernel.org
Cc: Beau Belgrave <beaub@linux.microsoft.com>,
Mathieu Desnoyers <mathieu.desnoyers@efficios.com>,
Steven Rostedt <rostedt@goodmis.org>,
Sasha Levin <sashal@kernel.org>,
mingo@redhat.com
Subject: [PATCH AUTOSEL 5.19 16/29] tracing/user_events: Use WRITE instead of READ for io vector import
Date: Mon, 17 Oct 2022 20:08:25 -0400 [thread overview]
Message-ID: <20221018000839.2730954-16-sashal@kernel.org> (raw)
In-Reply-To: <20221018000839.2730954-1-sashal@kernel.org>
From: Beau Belgrave <beaub@linux.microsoft.com>
[ Upstream commit 95f187603dbff69bef19b2ab3bb54d2c060f556d ]
import_single_range expects the direction/rw to be where it came from,
not the protection/limit. Since the import is in a write path use WRITE.
Link: https://lkml.kernel.org/r/20220728233309.1896-3-beaub@linux.microsoft.com
Link: https://lore.kernel.org/all/2059213643.196683.1648499088753.JavaMail.zimbra@efficios.com/
Reported-by: Mathieu Desnoyers <mathieu.desnoyers@efficios.com>
Signed-off-by: Beau Belgrave <beaub@linux.microsoft.com>
Signed-off-by: Steven Rostedt (Google) <rostedt@goodmis.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
kernel/trace/trace_events_user.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/kernel/trace/trace_events_user.c b/kernel/trace/trace_events_user.c
index 706e1686b5eb..4c9f6c776618 100644
--- a/kernel/trace/trace_events_user.c
+++ b/kernel/trace/trace_events_user.c
@@ -1245,7 +1245,8 @@ static ssize_t user_events_write(struct file *file, const char __user *ubuf,
if (unlikely(*ppos != 0))
return -EFAULT;
- if (unlikely(import_single_range(READ, (char *)ubuf, count, &iov, &i)))
+ if (unlikely(import_single_range(WRITE, (char __user *)ubuf,
+ count, &iov, &i)))
return -EFAULT;
return user_events_write_core(file, &i);
--
2.35.1
next prev parent reply other threads:[~2022-10-18 0:13 UTC|newest]
Thread overview: 30+ messages / expand[flat|nested] mbox.gz Atom feed top
2022-10-18 0:08 [PATCH AUTOSEL 5.19 01/29] crypto: qcom-rng - Fix qcom_rng_of_match unused warning Sasha Levin
2022-10-18 0:08 ` [PATCH AUTOSEL 5.19 02/29] crypto: ccp - Add a quirk to firmware update Sasha Levin
2022-10-18 0:08 ` [PATCH AUTOSEL 5.19 03/29] crypto: ccp - Initialize PSP when reading psp data file failed Sasha Levin
2022-10-18 0:08 ` [PATCH AUTOSEL 5.19 04/29] gfs2: Switch from strlcpy to strscpy Sasha Levin
2022-10-18 0:08 ` [PATCH AUTOSEL 5.19 05/29] powerpc/hw_breakpoint: Avoid relying on caller synchronization Sasha Levin
2022-10-18 1:04 ` Marco Elver
2022-10-18 0:08 ` [PATCH AUTOSEL 5.19 06/29] cgroup: Remove data-race around cgrp_dfl_visible Sasha Levin
2022-10-18 0:08 ` [PATCH AUTOSEL 5.19 07/29] iommu/vt-d: Handle race between registration and device probe Sasha Levin
2022-10-18 0:08 ` [PATCH AUTOSEL 5.19 08/29] of/fdt: Don't calculate initrd size from DT if start > end Sasha Levin
2022-10-18 0:08 ` [PATCH AUTOSEL 5.19 09/29] objtool,x86: Teach decode about LOOP* instructions Sasha Levin
2022-10-18 0:08 ` [PATCH AUTOSEL 5.19 10/29] locking/rwsem: Disable preemption while trying for rwsem lock Sasha Levin
2022-10-18 0:08 ` [PATCH AUTOSEL 5.19 11/29] gfs2: Check sb_bsize_shift after reading superblock Sasha Levin
2022-10-18 0:08 ` [PATCH AUTOSEL 5.19 12/29] powerpc/64: don't refer nr_cpu_ids in asm code when it's undefined Sasha Levin
2022-10-18 0:08 ` [PATCH AUTOSEL 5.19 13/29] m68knommu: fix non-specific 68328 choice interrupt build failure Sasha Levin
2022-10-18 0:08 ` [PATCH AUTOSEL 5.19 14/29] m68knommu: fix non-mmu classic 68000 legacy timer tick selection Sasha Levin
2022-10-18 0:08 ` [PATCH AUTOSEL 5.19 15/29] kbuild: take into account DT_SCHEMA_FILES changes while checking dtbs Sasha Levin
2022-10-18 0:08 ` Sasha Levin [this message]
2022-10-18 0:08 ` [PATCH AUTOSEL 5.19 17/29] tracing/user_events: Ensure user provided strings are safely formatted Sasha Levin
2022-10-18 0:08 ` [PATCH AUTOSEL 5.19 18/29] of: Fix "dma-ranges" handling for bus controllers Sasha Levin
2022-10-18 0:08 ` [PATCH AUTOSEL 5.19 19/29] x86/hyperv: Replace kmap() with kmap_local_page() Sasha Levin
2022-10-18 0:08 ` [PATCH AUTOSEL 5.19 20/29] kmsan: disable instrumentation of unsupported common kernel code Sasha Levin
2022-10-18 0:08 ` [PATCH AUTOSEL 5.19 21/29] kmsan: disable physical page merging in biovec Sasha Levin
2022-10-18 0:08 ` [PATCH AUTOSEL 5.19 22/29] f2fs: fix wrong dirty page count when race between mmap and fallocate Sasha Levin
2022-10-18 0:08 ` [PATCH AUTOSEL 5.19 23/29] f2fs: code clean and fix a type error Sasha Levin
2022-10-18 0:08 ` [PATCH AUTOSEL 5.19 24/29] f2fs: fix to detect corrupted meta ino Sasha Levin
2022-10-18 0:08 ` [PATCH AUTOSEL 5.19 25/29] 9p: trans_fd/p9_conn_cancel: drop client lock earlier Sasha Levin
2022-10-18 0:08 ` [PATCH AUTOSEL 5.19 26/29] 9p/trans_fd: always use O_NONBLOCK read/write Sasha Levin
2022-10-18 0:08 ` [PATCH AUTOSEL 5.19 27/29] net/9p: use a dedicated spinlock for trans_fd Sasha Levin
2022-10-18 0:08 ` [PATCH AUTOSEL 5.19 28/29] virtio_pci: don't try to use intxif pin is zero Sasha Levin
2022-10-18 0:08 ` [PATCH AUTOSEL 5.19 29/29] cifs: replace kfree() with kfree_sensitive() for sensitive data Sasha Levin
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20221018000839.2730954-16-sashal@kernel.org \
--to=sashal@kernel.org \
--cc=beaub@linux.microsoft.com \
--cc=linux-kernel@vger.kernel.org \
--cc=mathieu.desnoyers@efficios.com \
--cc=mingo@redhat.com \
--cc=rostedt@goodmis.org \
--cc=stable@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®