mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Alexey Toptygin <alexeyt@freeshell.org>
To: linux-kernel@vger.kernel.org
Cc: ak@suse.de, tony.luck@intel.com
Subject: [PATCH] sendfile compat functions on x86_64 and ia64
Date: Fri, 5 May 2006 00:45:37 +0000 (UTC)	[thread overview]
Message-ID: <Pine.NEB.4.62.0605050030200.18795@norge.freeshell.org> (raw)


Hi,

I'm a kernel noob, so I apologise in advance if I completely misunderstood 
something. In arch/x86_64/ia32/sys_ia32.c there is this code:

sys32_sendfile(int out_fd, int in_fd, compat_off_t __user *offset, s32 count)
[snip]
	ret = sys_sendfile(out_fd, in_fd, offset ? &of : NULL, count);

However on ia32, count (a size_t) is u32. I think this is taking the u32 
value from the 32 bit userland, sign-extending it to 64 bits, then giving 
it to sys_sendfile in a u64. So, a count >= 1<<31 passed from the 32 bit 
app will become a count >= ((1<<33)-1)<<31 given to sys_sendfile.

Now, I don't think this actually hurts anything, because sys_sendfile 
passes a max of ((1<<31)-1) to do_sendfile, plus rw_verify_area will 
reject values that are negative when cast to ssize_t; but, this is 
certainly confusing.

Perhaps that s32 should be changed to a compat_size_t? ISTM that's 
what compat_size_t is for. And if so, the equivalent function in 
arch/ia64/ia32/sys_ia32.c:

sys32_sendfile (int out_fd, int in_fd, int __user *offset, unsigned int count)

should probably be changed as well? In case I'm not completely wrong, 
below is a patch. Please CC: me, I'm not on lkml.

Signed-off-by: Alexey Toptygin <alexeyt@freeshell.org>

diff -urpN linux-source-2.6.16/arch/ia64/ia32/sys_ia32.c linux-source-2.6.16-mine/arch/ia64/ia32/sys_ia32.c
--- linux-source-2.6.16/arch/ia64/ia32/sys_ia32.c	2006-03-20 00:53:29.000000000 -0500
+++ linux-source-2.6.16-mine/arch/ia64/ia32/sys_ia32.c	2006-05-04 20:20:44.000000000 -0400
@@ -2306,7 +2306,8 @@ sys32_pwrite (unsigned int fd, void __us
 }
 
 asmlinkage long
-sys32_sendfile (int out_fd, int in_fd, int __user *offset, unsigned int count)
+sys32_sendfile (int out_fd, int in_fd, compat_off_t __user *offset,
+							compat_size_t count)
 {
 	mm_segment_t old_fs = get_fs();
 	long ret;
diff -urpN linux-source-2.6.16/arch/x86_64/ia32/sys_ia32.c linux-source-2.6.16-mine/arch/x86_64/ia32/sys_ia32.c
--- linux-source-2.6.16/arch/x86_64/ia32/sys_ia32.c	2006-03-20 00:53:29.000000000 -0500
+++ linux-source-2.6.16-mine/arch/x86_64/ia32/sys_ia32.c	2006-05-04 20:19:35.000000000 -0400
@@ -760,7 +760,8 @@ sys32_personality(unsigned long personal
 }
 
 asmlinkage long
-sys32_sendfile(int out_fd, int in_fd, compat_off_t __user *offset, s32 count)
+sys32_sendfile(int out_fd, int in_fd, compat_off_t __user *offset,
+							compat_size_t count)
 {
 	mm_segment_t old_fs = get_fs();
 	int ret;

             reply	other threads:[~2006-05-05  0:45 UTC|newest]

Thread overview: 7+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2006-05-05  0:45 Alexey Toptygin [this message]
2006-05-05 20:38 ` Andi Kleen
2006-05-05 20:44   ` Alexey Toptygin
2006-05-05 21:28     ` Andi Kleen
2006-05-05 22:19       ` Alexey Toptygin
2006-05-06  8:46         ` Andi Kleen
2006-05-06 22:43           ` Alexey Toptygin

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=Pine.NEB.4.62.0605050030200.18795@norge.freeshell.org \
    --to=alexeyt@freeshell.org \
    --cc=ak@suse.de \
    --cc=linux-kernel@vger.kernel.org \
    --cc=tony.luck@intel.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®