mirror of
https://github.com/torvalds/linux.git
synced 2026-07-28 01:55:51 +02:00
Merge branch 'bpf-fix-sysctl-new-value-handling-in-__cgroup_bpf_run_filter_sysctl'
Dawei Feng says: ==================== bpf: fix sysctl new-value handling in __cgroup_bpf_run_filter_sysctl This series fixes three bugs in the sysctl write-buffer replacement path of __cgroup_bpf_run_filter_sysctl(). It resolves a kvzalloc()/kfree() mismatch, adds a missing NUL terminator to the replacement string, and updates a stale return value check to safely restore the replacement functionality. Patch Summary: - patch 1 NUL-terminates the replaced sysctl value - patch 2 uses kvfree() for the replaced sysctl write buffer - patch 3 restores sysctl new-value replacement Changelog: v2 -> v3: - reordered patches 1 and 2 - added the missing Reviewed-by/Acked-by tags to patches 2 and 3 - fixed the incorrect Fixes tag in patch 3 - simplified the dynamic test logs in patch 1 and 2, and updated titles ==================== Link: https://patch.msgid.link/20260603105317.944304-1-dawei.feng@seu.edu.cn Signed-off-by: Alexei Starovoitov <ast@kernel.org>
This commit is contained in:
commit
b403670b82
|
|
@ -1936,8 +1936,8 @@ int __cgroup_bpf_run_filter_sysctl(struct ctl_table_header *head,
|
|||
|
||||
kfree(ctx.cur_val);
|
||||
|
||||
if (ret == 1 && ctx.new_updated) {
|
||||
kfree(*buf);
|
||||
if (!ret && ctx.new_updated) {
|
||||
kvfree(*buf);
|
||||
*buf = ctx.new_val;
|
||||
*pcount = ctx.new_len;
|
||||
} else {
|
||||
|
|
@ -2343,6 +2343,7 @@ BPF_CALL_3(bpf_sysctl_set_new_value, struct bpf_sysctl_kern *, ctx,
|
|||
return -E2BIG;
|
||||
|
||||
memcpy(ctx->new_val, buf, buf_len);
|
||||
((char *)ctx->new_val)[buf_len] = '\0';
|
||||
ctx->new_len = buf_len;
|
||||
ctx->new_updated = 1;
|
||||
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user