From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pj1-f73.google.com (mail-pj1-f73.google.com [209.85.216.73]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 4ABE91F76AF for ; Tue, 7 Jan 2025 18:48:18 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.216.73 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1736275699; cv=none; b=PB6STsZp+tUUTlrTVld89bEIuWQQD0zI0OEAS6b0x46TR5pTxFSSja0nGRwQ4mag2qeYt5Jwcu+B83q5zjEw21rgEFzmZVDLoVVmjA3AYh08eiidgvwYfKhYAc6KLGzz1PfyxtBa01ET77tutQS2risOHGcpULbYYwfWO+ImxPI= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1736275699; c=relaxed/simple; bh=vZ8YfafbenCjiRlUYk/DzFVD85XiAFmCGR2IexFvjlQ=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=fcTyUx2fkQh742t3AG3En30h0HUdiczJnUkE9wIK6RwS76Els9mFT/sKNIdaI3HdDdrkCb9NmRzaFv9wVa4nTPLeHolTVOWcWAHU3XFLz6BTu1VRTqTzmenaSlUSOstUi3d+PmhadpCPnNKFbj9LsoSnUw+eo1ZM7VMbqL7puh0= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--isaacmanjarres.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=T0IcqUY6; arc=none smtp.client-ip=209.85.216.73 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--isaacmanjarres.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="T0IcqUY6" Received: by mail-pj1-f73.google.com with SMTP id 98e67ed59e1d1-2ee3206466aso107647a91.1 for ; Tue, 07 Jan 2025 10:48:18 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20230601; t=1736275697; x=1736880497; darn=vger.kernel.org; h=cc:to:from:subject:message-id:references:mime-version:in-reply-to :date:from:to:cc:subject:date:message-id:reply-to; bh=50lLEW9SKYc1xkD+PbF+LHJJKluSEdexAUkKUhuIKDk=; b=T0IcqUY6t1tx8nAVmWGoQCDGM6ocJplMVqfk/kjbqSO3oOdXFSAppXoEpFcRtfvJG8 Hw4xApvk4W2Std8sAgBsfo6qQR6IAPUpZCKxdZzTNAq4hmlo/gHikcgcRGGiEHs81ydf BdhuKDebTrL4OEQn7nfs/2jqkJi+rC/22GpyT4PF9qvnAs/9+7gFBR4AV5gxtqetOmKf mIv/BNM1QZia8HApdQq255VP8ywjo5bFEFlZJcBmiRORGOJ5FXrYtx69/HX8HnxJqAi9 zX47WfFY8xnJUHVXsXNgw/GrGXntr/ZNki9+UrQR2KtiATiwcJnclBWKIZG5pAm1bb0M PR3w== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1736275697; x=1736880497; h=cc:to:from:subject:message-id:references:mime-version:in-reply-to :date:x-gm-message-state:from:to:cc:subject:date:message-id:reply-to; bh=50lLEW9SKYc1xkD+PbF+LHJJKluSEdexAUkKUhuIKDk=; b=IoVN99gyYHxMEMJmCLdMa6rRLGt45KDrrOtydKlVbt6KtnpqkOfbNWBx2mWSeUX6c+ 9L5/kTG2mHeDn4ffIOwHibiQw7Y0olTOlw/eSGKsVJv9gskxZEdLl9p0mWmXit61qGIE 08M7HLhFT9Oq+nYXhQ7W6aIvu2g93VM1b7jFsGbo5reDykA+2s5SMCi2CVdzZtFmkVDe wpus0qw+VVBEy9pUHgpsj6/jZ1MixkhqvwmyknlxD/HQKhfH2vSbqBHomj1C0XKyLrqQ 4VZYDvYP1rHCQeN/hm3NY2rgqUQ+g2Orp6Q+FteesksBR/JXZlOz2ee4E8Fum6YKpCON 1NzA== X-Forwarded-Encrypted: i=1; AJvYcCWU51W8z1duKo/+5raujUJbq92ownzVHz95h2u/BTcN7yI/Rw5AZ4PosLPud1xbmlK3x7wjRAVUxSELV5M=@vger.kernel.org X-Gm-Message-State: AOJu0Ywp79OkmkPHS0P0ZzvWnAptdzH2Oyk2zlVLGlhiiWksxV/unVGK dYBlIWzzmPaDktG4qxPJNQUWt2t/aY0WfkSkW+8n5em1+eAAko/hHQEFmIOzlCt9qcOhAdWi+NL JDH9VR9p9FO8x9Zqtlzxlm/sB8uKJT7NLPw== X-Google-Smtp-Source: AGHT+IGHSFoGgESZy9nn6zzNByx2COlM3Gms6uDyLSzyV2qnHkKsirasdpXYNca+u/B/CV52aTS2q18lsuiCDMLSkxsbsw== X-Received: from pjbsl16.prod.google.com ([2002:a17:90b:2e10:b0:2ef:82a8:7171]) (user=isaacmanjarres job=prod-delivery.src-stubby-dispatcher) by 2002:a17:90b:5245:b0:2f2:a90e:74ef with SMTP id 98e67ed59e1d1-2f53cb837b7mr6272082a91.1.1736275697657; Tue, 07 Jan 2025 10:48:17 -0800 (PST) Date: Tue, 7 Jan 2025 10:48:02 -0800 In-Reply-To: <20250107184804.4074147-1-isaacmanjarres@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20250107184804.4074147-1-isaacmanjarres@google.com> X-Mailer: git-send-email 2.47.1.613.gc27f4b7a9f-goog Message-ID: <20250107184804.4074147-3-isaacmanjarres@google.com> Subject: [PATCH v2 2/2] mm/memfd: Use strncpy_from_user() to read memfd name From: "Isaac J. Manjarres" To: lorenzo.stoakes@oracle.com, Andrew Morton Cc: kaleshsingh@google.com, jstultz@google.com, aliceryhl@google.com, surenb@google.com, "Isaac J. Manjarres" , kernel-team@android.com, linux-mm@kvack.org, linux-kernel@vger.kernel.org Content-Type: text/plain; charset="UTF-8" The existing logic uses strnlen_user() to calculate the length of the memfd name from userspace and then copies the string into a buffer using copy_from_user(). This is error-prone, as the string length could have changed between the time when it was calculated and when the string was copied. The existing logic handles this by ensuring that the last byte in the buffer is the terminating zero. This handling is contrived and can better be handled by using strncpy_from_user(), which gets the length of the string and copies it in one shot. Therefore, simplify the logic for copying the memfd name by using strncpy_from_user(). No functional change. Signed-off-by: Isaac J. Manjarres --- mm/memfd.c | 20 ++++++-------------- 1 file changed, 6 insertions(+), 14 deletions(-) diff --git a/mm/memfd.c b/mm/memfd.c index a9430090bb20..babf6433cf7b 100644 --- a/mm/memfd.c +++ b/mm/memfd.c @@ -394,26 +394,18 @@ static char *memfd_create_name(const char __user *uname) char *name; long len; - /* length includes terminating zero */ - len = strnlen_user(uname, MFD_NAME_MAX_LEN + 1); - if (len <= 0) - return ERR_PTR(-EFAULT); - if (len > MFD_NAME_MAX_LEN + 1) - return ERR_PTR(-EINVAL); - - name = kmalloc(len + MFD_NAME_PREFIX_LEN, GFP_KERNEL); + name = kmalloc(MFD_NAME_PREFIX_LEN + MFD_NAME_MAX_LEN + 1, GFP_KERNEL); if (!name) return ERR_PTR(-ENOMEM); strcpy(name, MFD_NAME_PREFIX); - if (copy_from_user(&name[MFD_NAME_PREFIX_LEN], uname, len)) { + /* length does not include terminating zero */ + len = strncpy_from_user(name + MFD_NAME_PREFIX_LEN, uname, MFD_NAME_MAX_LEN + 1); + if (len < 0) { error = -EFAULT; goto err_name; - } - - /* terminating-zero may have changed after strnlen_user() returned */ - if (name[len + MFD_NAME_PREFIX_LEN - 1]) { - error = -EFAULT; + } else if (len > MFD_NAME_MAX_LEN) { + error = -EINVAL; goto err_name; } -- 2.47.1.613.gc27f4b7a9f-goog