mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH] x86: Fix x32 System V message queue syscalls
@ 2020-10-12  1:48 Jessica Clarke
  2020-10-12  3:02 ` Andy Lutomirski
  0 siblings, 1 reply; 26+ messages in thread
From: Jessica Clarke @ 2020-10-12  1:48 UTC (permalink / raw)
  To: linux-x86_64
  Cc: Jessica Clarke, Andy Lutomirski, Thomas Gleixner, Ingo Molnar,
	Borislav Petkov, x86, H. Peter Anvin, linux-kernel

POSIX specifies that the first field of the supplied msgp, namely mtype,
is a long, not a __kernel_long_t, and it's a user-defined struct due to
the variable-length mtext field so we can't even bend the spec and make
it a __kernel_long_t even if we wanted to. Thus we must use the compat
syscalls on x32 to avoid buffer overreads and overflows in msgsnd and
msgrcv respectively.

Due to erroneously including the first 4 bytes of mtext in the mtype
this would previously also cause non-zero msgtyp arguments for msgrcv to
search for the wrong messages, and if sharing message queues between x32
and non-x32 (i386 or x86_64) processes this would previously cause mtext
to "move" and, depending on the direction and ABI combination, lose the
first 4 bytes.

Signed-off-by: Jessica Clarke <jrtc27@jrtc27.com>
---
 arch/x86/entry/syscalls/syscall_64.tbl | 6 ++++--
 1 file changed, 4 insertions(+), 2 deletions(-)

diff --git a/arch/x86/entry/syscalls/syscall_64.tbl b/arch/x86/entry/syscalls/syscall_64.tbl
index f30d6ae9a..7ee40989e 100644
--- a/arch/x86/entry/syscalls/syscall_64.tbl
+++ b/arch/x86/entry/syscalls/syscall_64.tbl
@@ -77,8 +77,8 @@
 66	common	semctl			sys_semctl
 67	common	shmdt			sys_shmdt
 68	common	msgget			sys_msgget
-69	common	msgsnd			sys_msgsnd
-70	common	msgrcv			sys_msgrcv
+69	64	msgsnd			sys_msgsnd
+70	64	msgrcv			sys_msgrcv
 71	common	msgctl			sys_msgctl
 72	common	fcntl			sys_fcntl
 73	common	flock			sys_flock
@@ -404,3 +404,5 @@
 545	x32	execveat		compat_sys_execveat
 546	x32	preadv2			compat_sys_preadv64v2
 547	x32	pwritev2		compat_sys_pwritev64v2
+548	x32	msgsnd			compat_sys_msgsnd
+549	x32	msgrcv			compat_sys_msgrcv
-- 
2.28.0


^ permalink raw reply	[flat|nested] 26+ messages in thread

end of thread, other threads:[~2023-09-10 23:42 UTC | newest]

Thread overview: 26+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2020-10-12  1:48 [PATCH] x86: Fix x32 System V message queue syscalls Jessica Clarke
2020-10-12  3:02 ` Andy Lutomirski
2020-10-12  3:31   ` Jessica Clarke
2020-10-12 13:44     ` [PATCH v2] " Jessica Clarke
2020-10-30 19:21       ` Jessica Clarke
2020-10-31 23:30       ` Andy Lutomirski
2020-11-01  0:09         ` Jessica Clarke
2020-11-01  1:22         ` Rich Felker
2020-11-01  1:27           ` Jessica Clarke
2020-11-01  1:50             ` Rich Felker
2020-11-01 18:07               ` Andy Lutomirski
2020-11-01 18:15                 ` Jessica Clarke
2020-11-01 18:27                   ` Jessica Clarke
2020-11-01 21:01                     ` Rich Felker
2020-11-16  0:55                       ` Jessica Clarke
2020-12-06  0:01                         ` Jessica Clarke
2020-12-06 22:55                           ` Andy Lutomirski
2023-08-01  0:43                             ` Harald van Dijk
2023-08-01  1:38                               ` Jessica Clarke
2023-08-01  2:53                                 ` Rich Felker
2023-08-01 12:13                                   ` Harald van Dijk
2023-09-10 23:33                                 ` [PATCH 1/2] uapi: Stop using __kernel_long_t in struct msgbuf Harald van Dijk
2023-09-10 23:33                                 ` [PATCH 2/2] uapi: Remove struct msgbuf, struct ipc_kludge Harald van Dijk
2023-08-01  7:15                               ` [PATCH v2] x86: Fix x32 System V message queue syscalls Florian Weimer
2023-08-01 12:15                                 ` Harald van Dijk
2023-09-10 23:40                                   ` Harald van Dijk

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®