mirror of
https://github.com/torvalds/linux.git
synced 2026-07-27 17:47:41 +02:00
liveupdate: fix GET_NAME ioctl argument validation
LIVEUPDATE_SESSION_GET_NAME was developed in the liveupdate/next branch while the session type validation change was carried in liveupdate-fixes. When the conflict between the two branches was resolved, the GET_NAME operation descriptor picked up the structure and last member from RETRIEVE_FD. This makes both its known size and minimum size 16 bytes rather than 72. A zero-initialized request still succeeds because luo_session_get_name() writes the full name before luo_ucmd_respond() copies the full GET_NAME response to userspace. However, copy_struct_from_user() treats the output-only name field as unknown trailing data and rejects the request with -E2BIG if any byte in that field is nonzero. Use the GET_NAME structure and its name field in the descriptor. Link: https://lore.kernel.org/all/ahWlYXNjGUbkKoHy@sirena.org.uk/ Assisted-by: Codex:gpt-5.6-sol Reviewed-by: Pratyush Yadav (Google) <pratyush@kernel.org> Signed-off-by: Jackie Liu <liuyun01@kylinos.cn> Link: https://patch.msgid.link/20260716012607.22020-1-liu.yun@linux.dev Signed-off-by: Mike Rapoport (Microsoft) <rppt@kernel.org>
This commit is contained in:
parent
dc59e4fea9
commit
4416f8a9ed
|
|
@ -378,7 +378,7 @@ static const struct luo_ioctl_op luo_session_ioctl_ops[] = {
|
|||
IOCTL_OP(LIVEUPDATE_SESSION_RETRIEVE_FD, luo_session_retrieve_fd,
|
||||
struct liveupdate_session_retrieve_fd, token, LUO_IOCTL_INCOMING),
|
||||
IOCTL_OP(LIVEUPDATE_SESSION_GET_NAME, luo_session_get_name,
|
||||
struct liveupdate_session_retrieve_fd, token, LUO_IOCTL_ALL),
|
||||
struct liveupdate_session_get_name, name, LUO_IOCTL_ALL),
|
||||
};
|
||||
|
||||
static bool luo_ioctl_type_valid(struct luo_session *session,
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user