Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.kernel > #1675818
| From | Greg Kroah-Hartman <gregkh@linuxfoundation.org> |
|---|---|
| Newsgroups | linux.kernel |
| Subject | [PATCH 4.9 03/44] xen-blkback: dont leak stack data via response ring |
| Date | 2017-06-27 16:40 +0200 |
| Message-ID | <tWZOO-1NK-15@gated-at.bofh.it> (permalink) |
| References | <tWZvs-1FM-23@gated-at.bofh.it> |
| Organization | linux.* mail to news gateway |
4.9-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jan Beulich <jbeulich@suse.com>
commit 089bc0143f489bd3a4578bdff5f4ca68fb26f341 upstream.
Rather than constructing a local structure instance on the stack, fill
the fields directly on the shared ring, just like other backends do.
Build on the fact that all response structure flavors are actually
identical (the old code did make this assumption too).
This is XSA-216.
Signed-off-by: Jan Beulich <jbeulich@suse.com>
Reviewed-by: Konrad Rzeszutek Wilk <konrad.wilk@oracle.com>
Signed-off-by: Konrad Rzeszutek Wilk <konrad.wilk@oracle.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/block/xen-blkback/blkback.c | 23 ++++++++++++-----------
drivers/block/xen-blkback/common.h | 25 +++++--------------------
2 files changed, 17 insertions(+), 31 deletions(-)
--- a/drivers/block/xen-blkback/blkback.c
+++ b/drivers/block/xen-blkback/blkback.c
@@ -1436,34 +1436,35 @@ static int dispatch_rw_block_io(struct x
static void make_response(struct xen_blkif_ring *ring, u64 id,
unsigned short op, int st)
{
- struct blkif_response resp;
+ struct blkif_response *resp;
unsigned long flags;
union blkif_back_rings *blk_rings;
int notify;
- resp.id = id;
- resp.operation = op;
- resp.status = st;
-
spin_lock_irqsave(&ring->blk_ring_lock, flags);
blk_rings = &ring->blk_rings;
/* Place on the response ring for the relevant domain. */
switch (ring->blkif->blk_protocol) {
case BLKIF_PROTOCOL_NATIVE:
- memcpy(RING_GET_RESPONSE(&blk_rings->native, blk_rings->native.rsp_prod_pvt),
- &resp, sizeof(resp));
+ resp = RING_GET_RESPONSE(&blk_rings->native,
+ blk_rings->native.rsp_prod_pvt);
break;
case BLKIF_PROTOCOL_X86_32:
- memcpy(RING_GET_RESPONSE(&blk_rings->x86_32, blk_rings->x86_32.rsp_prod_pvt),
- &resp, sizeof(resp));
+ resp = RING_GET_RESPONSE(&blk_rings->x86_32,
+ blk_rings->x86_32.rsp_prod_pvt);
break;
case BLKIF_PROTOCOL_X86_64:
- memcpy(RING_GET_RESPONSE(&blk_rings->x86_64, blk_rings->x86_64.rsp_prod_pvt),
- &resp, sizeof(resp));
+ resp = RING_GET_RESPONSE(&blk_rings->x86_64,
+ blk_rings->x86_64.rsp_prod_pvt);
break;
default:
BUG();
}
+
+ resp->id = id;
+ resp->operation = op;
+ resp->status = st;
+
blk_rings->common.rsp_prod_pvt++;
RING_PUSH_RESPONSES_AND_CHECK_NOTIFY(&blk_rings->common, notify);
spin_unlock_irqrestore(&ring->blk_ring_lock, flags);
--- a/drivers/block/xen-blkback/common.h
+++ b/drivers/block/xen-blkback/common.h
@@ -75,9 +75,8 @@ extern unsigned int xenblk_max_queues;
struct blkif_common_request {
char dummy;
};
-struct blkif_common_response {
- char dummy;
-};
+
+/* i386 protocol version */
struct blkif_x86_32_request_rw {
uint8_t nr_segments; /* number of segments */
@@ -129,14 +128,6 @@ struct blkif_x86_32_request {
} u;
} __attribute__((__packed__));
-/* i386 protocol version */
-#pragma pack(push, 4)
-struct blkif_x86_32_response {
- uint64_t id; /* copied from request */
- uint8_t operation; /* copied from request */
- int16_t status; /* BLKIF_RSP_??? */
-};
-#pragma pack(pop)
/* x86_64 protocol version */
struct blkif_x86_64_request_rw {
@@ -193,18 +184,12 @@ struct blkif_x86_64_request {
} u;
} __attribute__((__packed__));
-struct blkif_x86_64_response {
- uint64_t __attribute__((__aligned__(8))) id;
- uint8_t operation; /* copied from request */
- int16_t status; /* BLKIF_RSP_??? */
-};
-
DEFINE_RING_TYPES(blkif_common, struct blkif_common_request,
- struct blkif_common_response);
+ struct blkif_response);
DEFINE_RING_TYPES(blkif_x86_32, struct blkif_x86_32_request,
- struct blkif_x86_32_response);
+ struct blkif_response __packed);
DEFINE_RING_TYPES(blkif_x86_64, struct blkif_x86_64_request,
- struct blkif_x86_64_response);
+ struct blkif_response);
union blkif_back_rings {
struct blkif_back_ring native;
Back to linux.kernel | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
[PATCH 4.9 00/44] 4.9.35-stable review Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-06-27 16:20 +0200
[PATCH 4.9 16/44] HID: Add quirk for Dell PIXART OEM mouse Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-06-27 16:20 +0200
[PATCH 4.9 14/44] CIFS: Improve readdir verbosity Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-06-27 16:20 +0200
[PATCH 4.9 42/44] net: phy: fix marvell phy status reading Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-06-27 16:20 +0200
[PATCH 4.9 10/44] perf/x86/intel: Add 1G DTLB load/store miss support for SKL Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-06-27 16:20 +0200
[PATCH 4.9 07/44] powerpc/perf: Fix oops when kthread execs user process Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-06-27 16:20 +0200
[PATCH 4.9 11/44] KVM: s390: gaccess: fix real-space designation asce handling for gmap shadows Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-06-27 16:20 +0200
[PATCH 4.9 21/44] brcmfmac: add parameter to pass error code in firmware callback Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-06-27 16:20 +0200
[PATCH 4.9 37/44] usb: gadget: f_fs: avoid out of bounds access on comp_desc Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-06-27 16:20 +0200
[PATCH 4.9 15/44] cxgb4: notify uP to route ctrlq compl to rdma rspq Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-06-27 16:20 +0200
[PATCH 4.9 35/44] of: Add check to of_scan_flat_dt() before accessing initial_boot_params Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-06-27 16:40 +0200
[PATCH 4.9 06/44] fs/exec.c: account for argv/envp pointers Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-06-27 16:40 +0200
[PATCH 4.9 27/44] target: Fix kref->refcount underflow in transport_cmd_finish_abort Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-06-27 16:40 +0200
[PATCH 4.9 12/44] KVM: PPC: Book3S HV: Preserve userspace HTM state properly Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-06-27 16:40 +0200
[PATCH 4.9 03/44] xen-blkback: dont leak stack data via response ring Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-06-27 16:40 +0200
[PATCH 4.9 09/44] lib/cmdline.c: fix get_options() overflow while parsing ranges Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-06-27 16:40 +0200
[PATCH 4.9 23/44] brcmfmac: unbind all devices upon failure in firmware callback Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-06-27 16:40 +0200
[PATCH 4.9 38/44] rt2x00: avoid introducing a USB dependency in the rt2x00lib module Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-06-27 16:40 +0200
[PATCH 4.9 28/44] iscsi-target: Fix delayed logout processing greater than SECONDS_FOR_LOGOUT_COMP Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-06-27 16:40 +0200
[PATCH 4.9 05/44] ALSA: pcm: Dont treat NULL chmap as a fatal error Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-06-27 16:40 +0200
[PATCH 4.9 30/44] drm/radeon: add a PX quirk for another K53TK variant Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-06-27 16:40 +0200
[PATCH 4.9 26/44] arm64/vdso: Fix nsec handling for CLOCK_MONOTONIC_RAW Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-06-27 16:40 +0200
[PATCH 4.9 22/44] brcmfmac: use firmware callback upon failure to load Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-06-27 16:40 +0200
[PATCH 4.9 04/44] ALSA: firewire-lib: Fix stall of process context at packet error Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-06-27 16:40 +0200
[PATCH 4.9 08/44] autofs: sanity check status reported with AUTOFS_DEV_IOCTL_FAIL Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-06-27 16:40 +0200
[PATCH 4.9 40/44] dmaengine: bcm2835: Fix cyclic DMA period splitting Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-06-27 16:40 +0200
[PATCH 4.9 31/44] drm/radeon: add a quirk for Toshiba Satellite L20-183 Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-06-27 16:40 +0200
[PATCH 4.9 19/44] powerpc/64s: Handle data breakpoints in Radix mode Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-06-27 16:40 +0200
[PATCH 4.9 39/44] net: phy: Initialize mdio clock at probe function Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-06-27 16:40 +0200
[PATCH 4.9 25/44] time: Fix CLOCK_MONOTONIC_RAW sub-nanosecond accounting Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-06-27 16:40 +0200
[PATCH 4.9 29/44] iscsi-target: Reject immediate data underflow larger than SCSI transfer length Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-06-27 16:40 +0200
[PATCH 4.9 20/44] Input: i8042 - add Fujitsu Lifebook AH544 to notimeout list Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-06-27 16:50 +0200
[PATCH 4.9 18/44] powerpc/kprobes: Pause function_graph tracing during jprobes handling Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-06-27 16:50 +0200
Re: [PATCH 4.9 00/44] 4.9.35-stable review Sumit Semwal <sumit.semwal@linaro.org> - 2017-06-27 19:40 +0200
Re: [PATCH 4.9 00/44] 4.9.35-stable review Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-06-28 14:10 +0200
Re: [PATCH 4.9 00/44] 4.9.35-stable review Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-06-27 20:40 +0200
Re: [PATCH 4.9 00/44] 4.9.35-stable review Guenter Roeck <linux@roeck-us.net> - 2017-06-27 21:10 +0200
Re: [PATCH 4.9 00/44] 4.9.35-stable review Shuah Khan <shuahkh@osg.samsung.com> - 2017-06-28 16:00 +0200
csiph-web