-
Notifications
You must be signed in to change notification settings - Fork 0
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Merge tag 'kallsyms_show_value-fix-v5.9-rc1' of git://git.kernel.org/…
…pub/scm/linux/kernel/git/kees/linux Pull sysfs module section fix from Kees Cook: "Fix sysfs module section output overflow. About a month after my kallsyms_show_value() refactoring landed, 0day noticed that there was a path through the kernfs binattr read handlers that did not have PAGE_SIZEd buffers, and the module "sections" read handler made a bad assumption about this, resulting in it stomping on memory when reached through small-sized splice() calls. I've added a set of tests to find these kinds of regressions more quickly in the future as well" Sefltests-acked-by: Shuah Khan <skhan@linuxfoundation.org> * tag 'kallsyms_show_value-fix-v5.9-rc1' of git://git.kernel.org/pub/scm/linux/kernel/git/kees/linux: selftests: splice: Check behavior of full and short splices module: Correctly truncate sysfs sections output
- Loading branch information
Showing
7 changed files
with
137 additions
and
5 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -1,2 +1,3 @@ | ||
# SPDX-License-Identifier: GPL-2.0-only | ||
default_file_splice_read | ||
splice_read |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -1,5 +1,5 @@ | ||
# SPDX-License-Identifier: GPL-2.0 | ||
TEST_PROGS := default_file_splice_read.sh | ||
TEST_GEN_PROGS_EXTENDED := default_file_splice_read | ||
TEST_PROGS := default_file_splice_read.sh short_splice_read.sh | ||
TEST_GEN_PROGS_EXTENDED := default_file_splice_read splice_read | ||
|
||
include ../lib.mk |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1 @@ | ||
CONFIG_TEST_LKM=m |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1 @@ | ||
timeout=5 |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,56 @@ | ||
#!/bin/sh | ||
# SPDX-License-Identifier: GPL-2.0 | ||
set -e | ||
|
||
ret=0 | ||
|
||
do_splice() | ||
{ | ||
filename="$1" | ||
bytes="$2" | ||
expected="$3" | ||
|
||
out=$(./splice_read "$filename" "$bytes" | cat) | ||
if [ "$out" = "$expected" ] ; then | ||
echo "ok: $filename $bytes" | ||
else | ||
echo "FAIL: $filename $bytes" | ||
ret=1 | ||
fi | ||
} | ||
|
||
test_splice() | ||
{ | ||
filename="$1" | ||
|
||
full=$(cat "$filename") | ||
two=$(echo "$full" | grep -m1 . | cut -c-2) | ||
|
||
# Make sure full splice has the same contents as a standard read. | ||
do_splice "$filename" 4096 "$full" | ||
|
||
# Make sure a partial splice see the first two characters. | ||
do_splice "$filename" 2 "$two" | ||
} | ||
|
||
# proc_single_open(), seq_read() | ||
test_splice /proc/$$/limits | ||
# special open, seq_read() | ||
test_splice /proc/$$/comm | ||
|
||
# proc_handler, proc_dointvec_minmax | ||
test_splice /proc/sys/fs/nr_open | ||
# proc_handler, proc_dostring | ||
test_splice /proc/sys/kernel/modprobe | ||
# proc_handler, special read | ||
test_splice /proc/sys/kernel/version | ||
|
||
if ! [ -d /sys/module/test_module/sections ] ; then | ||
modprobe test_module | ||
fi | ||
# kernfs, attr | ||
test_splice /sys/module/test_module/coresize | ||
# kernfs, binattr | ||
test_splice /sys/module/test_module/sections/.init.text | ||
|
||
exit $ret |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,57 @@ | ||
// SPDX-License-Identifier: GPL-2.0 | ||
#define _GNU_SOURCE | ||
#include <errno.h> | ||
#include <fcntl.h> | ||
#include <limits.h> | ||
#include <stdio.h> | ||
#include <stdlib.h> | ||
#include <unistd.h> | ||
#include <sys/types.h> | ||
#include <sys/stat.h> | ||
|
||
int main(int argc, char *argv[]) | ||
{ | ||
int fd; | ||
size_t size; | ||
ssize_t spliced; | ||
|
||
if (argc < 2) { | ||
fprintf(stderr, "Usage: %s INPUT [BYTES]\n", argv[0]); | ||
return EXIT_FAILURE; | ||
} | ||
|
||
fd = open(argv[1], O_RDONLY); | ||
if (fd < 0) { | ||
perror(argv[1]); | ||
return EXIT_FAILURE; | ||
} | ||
|
||
if (argc == 3) | ||
size = atol(argv[2]); | ||
else { | ||
struct stat statbuf; | ||
|
||
if (fstat(fd, &statbuf) < 0) { | ||
perror(argv[1]); | ||
return EXIT_FAILURE; | ||
} | ||
|
||
if (statbuf.st_size > INT_MAX) { | ||
fprintf(stderr, "%s: Too big\n", argv[1]); | ||
return EXIT_FAILURE; | ||
} | ||
|
||
size = statbuf.st_size; | ||
} | ||
|
||
/* splice(2) file to stdout. */ | ||
spliced = splice(fd, NULL, STDOUT_FILENO, NULL, | ||
size, SPLICE_F_MOVE); | ||
if (spliced < 0) { | ||
perror("splice"); | ||
return EXIT_FAILURE; | ||
} | ||
|
||
close(fd); | ||
return EXIT_SUCCESS; | ||
} |