Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1249433

Re: fs: out of bounds on stack in iov_iter_advance

Path csiph.com!eternal-september.org!feeder.eternal-september.org!aioe.org!bofh.it!news.nic.it!robomod
From Sasha Levin <sasha.levin@oracle.com>
Newsgroups linux.kernel
Subject Re: fs: out of bounds on stack in iov_iter_advance
Date Sat, 17 Oct 2015 21:30:02 +0200
Message-ID <qkFl0-6VB-13@gated-at.bofh.it> (permalink)
References <pWF2P-6ON-29@gated-at.bofh.it> <pXQ5P-3xm-1@gated-at.bofh.it> <pYoKd-2ZR-15@gated-at.bofh.it> <pZ4q6-59O-5@gated-at.bofh.it> <q9TAZ-5YM-1@gated-at.bofh.it> <qexgt-oR-1@gated-at.bofh.it>
X-Original-To Al Viro <viro@ZenIV.linux.org.uk>, Andrey Ryabinin <ryabinin.a.a@gmail.com>, willy@linux.intel.com
User-Agent Mozilla/5.0 (X11; Linux x86_64; rv:31.0) Gecko/20100101 Thunderbird/31.7.0
MIME-Version 1.0
Content-Type text/plain; charset=windows-1252
Content-Transfer-Encoding 7bit
X-Source-IP aserv0022.oracle.com [141.146.126.234]
Sender robomod@news.nic.it
List-ID <linux-kernel.vger.kernel.org>
X-Mailing-List linux-kernel@vger.kernel.org
Approved robomod@news.nic.it
Lines 41
Organization linux.* mail to news gateway
X-Original-Cc Chuck Ebbert <cebbert.lkml@gmail.com>, linux-fsdevel <linux-fsdevel@vger.kernel.org>, LKML <linux-kernel@vger.kernel.org>
X-Original-Date Sat, 17 Oct 2015 15:22:19 -0400
X-Original-Message-ID <56229FEB.2040501@oracle.com>
X-Original-References <55CB5484.6080000@oracle.com> <20150815161338.4ea210ff@as> <55D1A6D4.3080605@gmail.com> <20150819054650.GD18890@ZenIV.linux.org.uk> <55FB75D0.7060403@oracle.com> <560C5469.5010704@oracle.com>
X-Original-Sender linux-kernel-owner@vger.kernel.org
Xref csiph.com linux.kernel:1249433

Show key headers only | View raw


On 09/30/2015 05:30 PM, Sasha Levin wrote:
> On 09/17/2015 10:24 PM, Sasha Levin wrote:
>> On 08/19/2015 01:46 AM, Al Viro wrote:
>>>> or mapping->a_ops->direct_IO() returned more
>>>>> than 'count'.
>>> 	Was there DAX involved?  ->direct_IO() in there is blkdev_direct_IO(),
>>> which takes rather different paths in those cases...
>>>
>>
>> So I've traced this all the way back to dax_io(). I can trigger this with:
>>
>> diff --git a/fs/dax.c b/fs/dax.c
>> index 93bf2f9..2cdb8a5 100644
>> --- a/fs/dax.c
>> +++ b/fs/dax.c
>> @@ -178,6 +178,7 @@ static ssize_t dax_io(struct inode *inode, struct iov_iter *iter,
>>         if (need_wmb)
>>                 wmb_pmem();
>>
>> +       WARN_ON((pos == start) && (pos - start > iov_iter_count(iter)));
>>         return (pos == start) ? retval : pos - start;
>>  }
>>
>> So it seems that iter gets moved twice here: once in dax_io(), and once again
>> back at generic_file_read_iter().
>>
>> I don't see how it ever worked. Am I missing something?
> 
> Ping?

Ping?


Thanks,
Sasha

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

Back to linux.kernel | Previous | Next — Next in thread | Find similar | Unroll thread


Thread

Re: fs: out of bounds on stack in iov_iter_advance Sasha Levin <sasha.levin@oracle.com> - 2015-10-17 21:30 +0200
  Re: fs: out of bounds on stack in iov_iter_advance Ross Zwisler <ross.zwisler@linux.intel.com> - 2015-10-18 06:20 +0200

csiph-web