Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1332390 > unrolled thread

Re: [PATCH] af_unix: Don't set err in unix_stream_read_generic unless there was an error

Started byJoseph Salisbury <joseph.salisbury@canonical.com>
First post2016-02-11 22:40 +0100
Last post2016-02-12 14:40 +0100
Articles 2 — 2 participants

Back to article view | Back to linux.kernel

This discussion starts older than the indexed window; earlier articles aren't shown. The article labeled Started by below is the oldest one visible, not the original post.


Contents

  Re: [PATCH] af_unix: Don't set err in unix_stream_read_generic unless  there was an error Joseph Salisbury <joseph.salisbury@canonical.com> - 2016-02-11 22:40 +0100
    Re: [PATCH] af_unix: Don't set err in unix_stream_read_generic unless there was an error Rainer Weikusat <rweikusat@mobileactivedefense.com> - 2016-02-12 14:40 +0100

#1332390 — Re: [PATCH] af_unix: Don't set err in unix_stream_read_generic unless there was an error

FromJoseph Salisbury <joseph.salisbury@canonical.com>
Date2016-02-11 22:40 +0100
SubjectRe: [PATCH] af_unix: Don't set err in unix_stream_read_generic unless there was an error
Message-ID<r177Y-63k-19@gated-at.bofh.it>
On 02/05/2016 05:30 PM, Rainer Weikusat wrote:
> The present unix_stream_read_generic contains various code sequences of
> the form
>
> err = -EDISASTER;
> if (<test>)
> 	goto out;
>
> This has the unfortunate side effect of possibly causing the error code
> to bleed through to the final
>
> out:
> 	return copied ? : err;
>
> and then to be wrongly returned if no data was copied because the caller
> didn't supply a data buffer, as demonstrated by the program available at
>
> http://pad.lv/1540731
>
> Change it such that err is only set if an error condition was detected.
>
> Signed-off-by: Rainer Weikusat <rweikusat@mobileactivedefense.com>
> ---
>
> With proper subject this time (at least I hope so).
>
> diff --git a/net/unix/af_unix.c b/net/unix/af_unix.c
> index 49d5093..138787d 100644
> --- a/net/unix/af_unix.c
> +++ b/net/unix/af_unix.c
> @@ -2277,13 +2277,15 @@ static int unix_stream_read_generic(struct unix_stream_read_state *state)
>  	size_t size = state->size;
>  	unsigned int last_len;
>  
> -	err = -EINVAL;
> -	if (sk->sk_state != TCP_ESTABLISHED)
> +	if (sk->sk_state != TCP_ESTABLISHED) {
> +		err = -EINVAL;
>  		goto out;
> +	}
>  
> -	err = -EOPNOTSUPP;
> -	if (flags & MSG_OOB)
> +	if (flags & MSG_OOB) {
> +		err = -EOPNOTSUPP;
>  		goto out;
> +	}
>  
>  	target = sock_rcvlowat(sk, flags & MSG_WAITALL, size);
>  	timeo = sock_rcvtimeo(sk, noblock);
> @@ -2329,9 +2331,11 @@ again:
>  				goto unlock;
>  
>  			unix_state_unlock(sk);
> -			err = -EAGAIN;
> -			if (!timeo)
> +			if (!timeo) {
> +				err = -EAGAIN;
>  				break;
> +			}
> +
>  			mutex_unlock(&u->readlock);
>  
>  			timeo = unix_stream_data_wait(sk, timeo, last,
I tested your patch, Rainer.  I can confirm that it fixes the reported
bug[0].

Thanks for the quick response!

Joe

[0] http://pad.lv/1540731

[toc] | [next] | [standalone]


#1332736 — Re: [PATCH] af_unix: Don't set err in unix_stream_read_generic unless there was an error

FromRainer Weikusat <rweikusat@mobileactivedefense.com>
Date2016-02-12 14:40 +0100
SubjectRe: [PATCH] af_unix: Don't set err in unix_stream_read_generic unless there was an error
Message-ID<r1m70-7DG-7@gated-at.bofh.it>
In reply to#1332390
Joseph Salisbury <joseph.salisbury@canonical.com> writes:
> On 02/05/2016 05:30 PM, Rainer Weikusat wrote:
>> The present unix_stream_read_generic contains various code sequences of
>> the form
>>
>> err = -EDISASTER;
>> if (<test>)
>> 	goto out;

[...]

>> Change it such that err is only set if an error condition was detected.

[...]

> I tested your patch, Rainer.  I can confirm that it fixes the reported
> bug[0].

This is only a partial fix: The launchpad test case will no longer fail
with EOPNOTSUPP and it will actually receive the credentials because the
message they're attached to was available by the time of the
recvmsg. But if this isn't the case, ie, if the receiver has to wait for
a message, the continue in the do { } while (size) loop will cause the
loop to be terminated without copying the credential information as the
continue will cause the size (of the remaining 'receive area' which is
zero for this case) to be checked before any of the other loop code is
executed again.

I posted a test case for this and a patch addressing that elsewhere in
this thread.

[toc] | [prev] | [standalone]


Back to top | Article view | linux.kernel


csiph-web