Skip to content

Commit 32a5ad9

Browse files
braunertorvalds
authored andcommitted
sysctl: handle overflow for file-max
Currently, when writing echo 18446744073709551616 > /proc/sys/fs/file-max /proc/sys/fs/file-max will overflow and be set to 0. That quickly crashes the system. This commit sets the max and min value for file-max. The max value is set to long int. Any higher value cannot currently be used as the percpu counters are long ints and not unsigned integers. Note that the file-max value is ultimately parsed via __do_proc_doulongvec_minmax(). This function does not report error when min or max are exceeded. Which means if a value largen that long int is written userspace will not receive an error instead the old value will be kept. There is an argument to be made that this should be changed and __do_proc_doulongvec_minmax() should return an error when a dedicated min or max value are exceeded. However this has the potential to break userspace so let's defer this to an RFC patch. Link: http://lkml.kernel.org/r/[email protected] Signed-off-by: Christian Brauner <[email protected]> Acked-by: Kees Cook <[email protected]> Cc: Alexey Dobriyan <[email protected]> Cc: Al Viro <[email protected]> Cc: Dominik Brodowski <[email protected]> Cc: "Eric W. Biederman" <[email protected]> Cc: Joe Lawrence <[email protected]> Cc: Luis Chamberlain <[email protected]> Cc: Waiman Long <[email protected]> [[email protected]: v4] Link: http://lkml.kernel.org/r/[email protected] Signed-off-by: Andrew Morton <[email protected]> Signed-off-by: Linus Torvalds <[email protected]>
1 parent 7f2923c commit 32a5ad9

File tree

1 file changed

+3
-0
lines changed

1 file changed

+3
-0
lines changed

kernel/sysctl.c

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -129,6 +129,7 @@ static int __maybe_unused one = 1;
129129
static int __maybe_unused two = 2;
130130
static int __maybe_unused four = 4;
131131
static unsigned long one_ul = 1;
132+
static unsigned long long_max = LONG_MAX;
132133
static int one_hundred = 100;
133134
static int one_thousand = 1000;
134135
#ifdef CONFIG_PRINTK
@@ -1749,6 +1750,8 @@ static struct ctl_table fs_table[] = {
17491750
.maxlen = sizeof(files_stat.max_files),
17501751
.mode = 0644,
17511752
.proc_handler = proc_doulongvec_minmax,
1753+
.extra1 = &zero,
1754+
.extra2 = &long_max,
17521755
},
17531756
{
17541757
.procname = "nr_open",

0 commit comments

Comments
 (0)