| From ef4649d8f78599713d2699743924ca80da84b971 Mon Sep 17 00:00:00 2001 |
| From: Sasha Levin <sashal@kernel.org> |
| Date: Fri, 2 Feb 2024 12:39:20 -0800 |
| Subject: fs: Fix rw_hint validation |
| |
| From: Bart Van Assche <bvanassche@acm.org> |
| |
| [ Upstream commit ec16b147a55bfa14e858234eb7b1a7c8e7cd5021 ] |
| |
| Reject values that are valid rw_hints after truncation but not before |
| truncation by passing an untruncated value to rw_hint_valid(). |
| |
| Reviewed-by: Christoph Hellwig <hch@lst.de> |
| Reviewed-by: Kanchan Joshi <joshi.k@samsung.com> |
| Cc: Jeff Layton <jlayton@kernel.org> |
| Cc: Chuck Lever <chuck.lever@oracle.com> |
| Cc: Jens Axboe <axboe@kernel.dk> |
| Cc: Stephen Rothwell <sfr@canb.auug.org.au> |
| Fixes: 5657cb0797c4 ("fs/fcntl: use copy_to/from_user() for u64 types") |
| Signed-off-by: Bart Van Assche <bvanassche@acm.org> |
| Link: https://lore.kernel.org/r/20240202203926.2478590-2-bvanassche@acm.org |
| Signed-off-by: Christian Brauner <brauner@kernel.org> |
| Signed-off-by: Sasha Levin <sashal@kernel.org> |
| --- |
| fs/fcntl.c | 12 +++++------- |
| 1 file changed, 5 insertions(+), 7 deletions(-) |
| |
| diff --git a/fs/fcntl.c b/fs/fcntl.c |
| index c80a6acad742f..3ff707bf2743a 100644 |
| --- a/fs/fcntl.c |
| +++ b/fs/fcntl.c |
| @@ -268,7 +268,7 @@ static int f_getowner_uids(struct file *filp, unsigned long arg) |
| } |
| #endif |
| |
| -static bool rw_hint_valid(enum rw_hint hint) |
| +static bool rw_hint_valid(u64 hint) |
| { |
| switch (hint) { |
| case RWH_WRITE_LIFE_NOT_SET: |
| @@ -288,19 +288,17 @@ static long fcntl_rw_hint(struct file *file, unsigned int cmd, |
| { |
| struct inode *inode = file_inode(file); |
| u64 __user *argp = (u64 __user *)arg; |
| - enum rw_hint hint; |
| - u64 h; |
| + u64 hint; |
| |
| switch (cmd) { |
| case F_GET_RW_HINT: |
| - h = inode->i_write_hint; |
| - if (copy_to_user(argp, &h, sizeof(*argp))) |
| + hint = inode->i_write_hint; |
| + if (copy_to_user(argp, &hint, sizeof(*argp))) |
| return -EFAULT; |
| return 0; |
| case F_SET_RW_HINT: |
| - if (copy_from_user(&h, argp, sizeof(h))) |
| + if (copy_from_user(&hint, argp, sizeof(hint))) |
| return -EFAULT; |
| - hint = (enum rw_hint) h; |
| if (!rw_hint_valid(hint)) |
| return -EINVAL; |
| |
| -- |
| 2.43.0 |
| |