Skip to content

Commit 72e809e

Browse files
author
Al Viro
committed
iov_iter: sanity checks for copy to/from page primitives
for now - just that we don't attempt to cross out of compound page Signed-off-by: Al Viro <[email protected]>
1 parent aa28de2 commit 72e809e

File tree

1 file changed

+17
-0
lines changed

1 file changed

+17
-0
lines changed

lib/iov_iter.c

Lines changed: 17 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -639,9 +639,20 @@ bool _copy_from_iter_full_nocache(void *addr, size_t bytes, struct iov_iter *i)
639639
}
640640
EXPORT_SYMBOL(_copy_from_iter_full_nocache);
641641

642+
static inline bool page_copy_sane(struct page *page, size_t offset, size_t n)
643+
{
644+
size_t v = n + offset;
645+
if (likely(n <= v && v <= (PAGE_SIZE << compound_order(page))))
646+
return true;
647+
WARN_ON(1);
648+
return false;
649+
}
650+
642651
size_t copy_page_to_iter(struct page *page, size_t offset, size_t bytes,
643652
struct iov_iter *i)
644653
{
654+
if (unlikely(!page_copy_sane(page, offset, bytes)))
655+
return 0;
645656
if (i->type & (ITER_BVEC|ITER_KVEC)) {
646657
void *kaddr = kmap_atomic(page);
647658
size_t wanted = copy_to_iter(kaddr + offset, bytes, i);
@@ -657,6 +668,8 @@ EXPORT_SYMBOL(copy_page_to_iter);
657668
size_t copy_page_from_iter(struct page *page, size_t offset, size_t bytes,
658669
struct iov_iter *i)
659670
{
671+
if (unlikely(!page_copy_sane(page, offset, bytes)))
672+
return 0;
660673
if (unlikely(i->type & ITER_PIPE)) {
661674
WARN_ON(1);
662675
return 0;
@@ -713,6 +726,10 @@ size_t iov_iter_copy_from_user_atomic(struct page *page,
713726
struct iov_iter *i, unsigned long offset, size_t bytes)
714727
{
715728
char *kaddr = kmap_atomic(page), *p = kaddr + offset;
729+
if (unlikely(!page_copy_sane(page, offset, bytes))) {
730+
kunmap_atomic(kaddr);
731+
return 0;
732+
}
716733
if (unlikely(i->type & ITER_PIPE)) {
717734
kunmap_atomic(kaddr);
718735
WARN_ON(1);

0 commit comments

Comments
 (0)