From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id ; Sun, 19 May 2002 22:03:07 -0400 Received: (majordomo@vger.kernel.org) by vger.kernel.org id ; Sun, 19 May 2002 22:03:06 -0400 Received: from sydney1.au.ibm.com ([202.135.142.193]:51979 "EHLO wagner.rustcorp.com.au") by vger.kernel.org with ESMTP id ; Sun, 19 May 2002 22:03:06 -0400 From: Rusty Russell To: Linus Torvalds Cc: Rusty Russell , linux-kernel@vger.kernel.org, alan@lxorguk.ukuu.org.uk Subject: Re: AUDIT: copy_from_user is a deathtrap. In-Reply-To: Your message of "Sun, 19 May 2002 11:29:06 MST." Date: Mon, 20 May 2002 12:06:07 +1000 Message-Id: Sender: linux-kernel-owner@vger.kernel.org X-Mailing-List: linux-kernel@vger.kernel.org In message you wri te: > > > On Sat, 18 May 2002, Benjamin Herrenschmidt wrote: > > > > Looking at generic_file_write(), it ignore the count returned by > > copy_from_user and always commit a write for the whole requested > > count, regardless of how much could actually be read from userland. > > The result of copy_from_user is only used as an error condition. > > And this is exactly what makes it re-startable. If read always returns the amount read (ignoring any copy_to_user errors), then you can repeat it by seeking backwards[1] and redoing the read. So copy_to_user can simply deliver a SIGSEGV and return "success", and everything will work (except sockets, pipes, etc). Is this satisfactory? I'd really like to get rid of 5,500 code paths in the kernel... BTW, SuSv3/POSIX.1.2001 says it's OK, Rusty. [1] No, this won't work on pipes & sockets, but the whole idea won't work on many devices anyway... -- Anyone who quotes me in their sig is an idiot. -- Rusty Russell.