mirror of
https://github.com/torvalds/linux.git
synced 2026-07-27 17:47:41 +02:00
Probes fixes for v7.2-rc4:
- tracing/probes: Avoid temporary buffer truncation in match_command_args() Compare argument name, delimiter, and comm expression directly instead of formatting into a stack buffer to prevent false matching failures. - tracing/probes: Prevent out-of-bounds write in __trace_probe_log_err() Return early when trace_probe_log.argc is zero to prevent out-of-bounds access when constructing the formatted error command string. - tracing/probes: Fix potential underflow in LEN_OR_ZERO macro Ensure buffer length is greater than current position before subtraction to prevent unsigned size underflow when formatting print strings. - tracing/eprobe: Fix exact system name matching in eprobe_dyn_event_match() Check system name null-termination to avoid partial prefix matching when comparing event probe target system names. -----BEGIN PGP SIGNATURE----- iQFPBAABCgA5FiEEh7BulGwFlgAOi5DV2/sHvwUrPxsFAmpfMPgbHG1hc2FtaS5o aXJhbWF0c3VAZ21haWwuY29tAAoJENv7B78FKz8bDm8IAJ3GuBwQOTcVyn1+7Poh fOtXOD9yMIV2YYoe6MDD/ZF1JCCnJgzgjPOqRbZjM4uGE8QbEuGnrwwu3zRiNON3 JU1R5aOxadflNhOnY7HxPjDHTwxJ5z+Ju10wPM+YE3M9gLKia8uzCabdEgYEly01 Rx6kpGKdsNgtJ/uAbrZlx++YtJCmBI1j+SdnRgNSejbcJUBtTmt+VYA+oh7ISF0f Fuhw6MuznpnA9JkLrPJaUI6KLiNLEoLQVS2gqhCD0PvrlDGF/h+b7Qbv9ML0C8YW W0p38Sq0Pc9lNlukYJlkh1A4H7lbAGpdGgZVoCvMQZt1ccy+H1QYfXzrFRlYyRWk n6g= =pC9O -----END PGP SIGNATURE----- Merge tag 'probes-fixes-v7.2-rc4' of git://git.kernel.org/pub/scm/linux/kernel/git/trace/linux-trace Pull probes fixes from Masami Hiramatsu: - Avoid temporary buffer truncation in match_command_args() Compare argument name, delimiter, and comm expression directly instead of formatting into a stack buffer to prevent false matching failures - Prevent out-of-bounds write in __trace_probe_log_err() Return early when trace_probe_log.argc is zero to prevent out-of-bounds access when constructing the formatted error command string - Fix potential underflow in LEN_OR_ZERO macro Ensure buffer length is greater than current position before subtraction to prevent unsigned size underflow when formatting print strings - Fix exact system name matching in eprobe_dyn_event_match() Check system name null-termination to avoid partial prefix matching when comparing event probe target system names * tag 'probes-fixes-v7.2-rc4' of git://git.kernel.org/pub/scm/linux/kernel/git/trace/linux-trace: tracing/eprobe: Fix exact system name matching in eprobe_dyn_event_match() tracing/probes: Fix potential underflow in LEN_OR_ZERO macro tracing/probes: Prevent out-of-bounds write in __trace_probe_log_err() tracing/probes: Avoid temporary buffer truncation in trace_probe_match_command_args()
This commit is contained in:
commit
cdb65777c4
|
|
@ -172,7 +172,8 @@ static bool eprobe_dyn_event_match(const char *system, const char *event,
|
|||
if (!slash)
|
||||
return false;
|
||||
|
||||
if (strncmp(ep->event_system, argv[0], slash - argv[0]))
|
||||
if (strncmp(ep->event_system, argv[0], slash - argv[0]) ||
|
||||
ep->event_system[slash - argv[0]] != '\0')
|
||||
return false;
|
||||
if (strcmp(ep->event_name, slash + 1))
|
||||
return false;
|
||||
|
|
|
|||
|
|
@ -188,7 +188,7 @@ void __trace_probe_log_err(int offset, int err_type)
|
|||
|
||||
lockdep_assert_held(&dyn_event_ops_mutex);
|
||||
|
||||
if (!trace_probe_log.argv)
|
||||
if (!trace_probe_log.argv || !trace_probe_log.argc)
|
||||
return;
|
||||
|
||||
/* Recalculate the length and allocate buffer */
|
||||
|
|
@ -2013,7 +2013,7 @@ int traceprobe_update_arg(struct probe_arg *arg)
|
|||
}
|
||||
|
||||
/* When len=0, we just calculate the needed length */
|
||||
#define LEN_OR_ZERO (len ? len - pos : 0)
|
||||
#define LEN_OR_ZERO (len > pos ? len - pos : 0)
|
||||
static int __set_print_fmt(struct trace_probe *tp, char *buf, int len,
|
||||
enum probe_print_type ptype)
|
||||
{
|
||||
|
|
@ -2338,16 +2338,17 @@ int trace_probe_compare_arg_type(struct trace_probe *a, struct trace_probe *b)
|
|||
bool trace_probe_match_command_args(struct trace_probe *tp,
|
||||
int argc, const char **argv)
|
||||
{
|
||||
char buf[MAX_ARGSTR_LEN + 1];
|
||||
int i;
|
||||
|
||||
if (tp->nr_args < argc)
|
||||
return false;
|
||||
|
||||
for (i = 0; i < argc; i++) {
|
||||
snprintf(buf, sizeof(buf), "%s=%s",
|
||||
tp->args[i].name, tp->args[i].comm);
|
||||
if (strcmp(buf, argv[i]))
|
||||
int len = strlen(tp->args[i].name);
|
||||
|
||||
if (strncmp(argv[i], tp->args[i].name, len) ||
|
||||
argv[i][len] != '=' ||
|
||||
strcmp(argv[i] + len + 1, tp->args[i].comm))
|
||||
return false;
|
||||
}
|
||||
return true;
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user