Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1712697 > unrolled thread

[PATCH] sg: protect against races between mmap() and SG_SET_RESERVED_SIZE

Started byTodd Poynor <toddpoynor@google.com>
First post2017-08-16 07:50 +0200
Last post2017-08-23 04:30 +0200
Articles 3 — 3 participants

Back to article view | Back to linux.kernel


Contents

  [PATCH] sg: protect against races between mmap() and SG_SET_RESERVED_SIZE Todd Poynor <toddpoynor@google.com> - 2017-08-16 07:50 +0200
    Re: [PATCH] sg: protect against races between mmap() and  SG_SET_RESERVED_SIZE Douglas Gilbert <dgilbert@interlog.com> - 2017-08-23 03:50 +0200
    Re: [PATCH] sg: protect against races between mmap() and SG_SET_RESERVED_SIZE "Martin K. Petersen" <martin.petersen@oracle.com> - 2017-08-23 04:30 +0200

#1712697 — [PATCH] sg: protect against races between mmap() and SG_SET_RESERVED_SIZE

FromTodd Poynor <toddpoynor@google.com>
Date2017-08-16 07:50 +0200
Subject[PATCH] sg: protect against races between mmap() and SG_SET_RESERVED_SIZE
Message-ID<ueZnj-36e-7@gated-at.bofh.it>
Take f_mutex around mmap() processing to protect against races with
the SG_SET_RESERVED_SIZE ioctl.  Ensure the reserve buffer length
remains consistent during the mapping operation, and set the
"mmap called" flag to prevent further changes to the reserved buffer
size as an atomic operation with the mapping.

Signed-off-by: Todd Poynor <toddpoynor@google.com>
---
 drivers/scsi/sg.c | 12 +++++++++---
 1 file changed, 9 insertions(+), 3 deletions(-)

diff --git a/drivers/scsi/sg.c b/drivers/scsi/sg.c
index 3a44b4bc872b..a20718e9f1f4 100644
--- a/drivers/scsi/sg.c
+++ b/drivers/scsi/sg.c
@@ -1233,6 +1233,7 @@ sg_mmap(struct file *filp, struct vm_area_struct *vma)
 	unsigned long req_sz, len, sa;
 	Sg_scatter_hold *rsv_schp;
 	int k, length;
+        int ret = 0;
 
 	if ((!filp) || (!vma) || (!(sfp = (Sg_fd *) filp->private_data)))
 		return -ENXIO;
@@ -1243,8 +1244,11 @@ sg_mmap(struct file *filp, struct vm_area_struct *vma)
 	if (vma->vm_pgoff)
 		return -EINVAL;	/* want no offset */
 	rsv_schp = &sfp->reserve;
-	if (req_sz > rsv_schp->bufflen)
-		return -ENOMEM;	/* cannot map more than reserved buffer */
+	mutex_lock(&sfp->f_mutex);
+	if (req_sz > rsv_schp->bufflen) {
+		ret = -ENOMEM;	/* cannot map more than reserved buffer */
+		goto out;
+	}
 
 	sa = vma->vm_start;
 	length = 1 << (PAGE_SHIFT + rsv_schp->page_order);
@@ -1258,7 +1262,9 @@ sg_mmap(struct file *filp, struct vm_area_struct *vma)
 	vma->vm_flags |= VM_IO | VM_DONTEXPAND | VM_DONTDUMP;
 	vma->vm_private_data = sfp;
 	vma->vm_ops = &sg_mmap_vm_ops;
-	return 0;
+out:
+	mutex_unlock(&sfp->f_mutex);
+	return ret;
 }
 
 static void
-- 
2.14.1.480.gb18f417b89-goog

[toc] | [next] | [standalone]


#1717956 — Re: [PATCH] sg: protect against races between mmap() and SG_SET_RESERVED_SIZE

FromDouglas Gilbert <dgilbert@interlog.com>
Date2017-08-23 03:50 +0200
SubjectRe: [PATCH] sg: protect against races between mmap() and SG_SET_RESERVED_SIZE
Message-ID<uhsXU-2lI-9@gated-at.bofh.it>
In reply to#1712697
On 2017-08-16 01:41 AM, Todd Poynor wrote:
> Take f_mutex around mmap() processing to protect against races with
> the SG_SET_RESERVED_SIZE ioctl.  Ensure the reserve buffer length
> remains consistent during the mapping operation, and set the
> "mmap called" flag to prevent further changes to the reserved buffer
> size as an atomic operation with the mapping.
> 
> Signed-off-by: Todd Poynor <toddpoynor@google.com>
Acked-by: Douglas Gilbert <dgilbert@interlog.com>

Thanks.

> ---
>   drivers/scsi/sg.c | 12 +++++++++---
>   1 file changed, 9 insertions(+), 3 deletions(-)
> 
> diff --git a/drivers/scsi/sg.c b/drivers/scsi/sg.c
> index 3a44b4bc872b..a20718e9f1f4 100644
> --- a/drivers/scsi/sg.c
> +++ b/drivers/scsi/sg.c
> @@ -1233,6 +1233,7 @@ sg_mmap(struct file *filp, struct vm_area_struct *vma)
>   	unsigned long req_sz, len, sa;
>   	Sg_scatter_hold *rsv_schp;
>   	int k, length;
> +        int ret = 0;
>   
>   	if ((!filp) || (!vma) || (!(sfp = (Sg_fd *) filp->private_data)))
>   		return -ENXIO;
> @@ -1243,8 +1244,11 @@ sg_mmap(struct file *filp, struct vm_area_struct *vma)
>   	if (vma->vm_pgoff)
>   		return -EINVAL;	/* want no offset */
>   	rsv_schp = &sfp->reserve;
> -	if (req_sz > rsv_schp->bufflen)
> -		return -ENOMEM;	/* cannot map more than reserved buffer */
> +	mutex_lock(&sfp->f_mutex);
> +	if (req_sz > rsv_schp->bufflen) {
> +		ret = -ENOMEM;	/* cannot map more than reserved buffer */
> +		goto out;
> +	}
>   
>   	sa = vma->vm_start;
>   	length = 1 << (PAGE_SHIFT + rsv_schp->page_order);
> @@ -1258,7 +1262,9 @@ sg_mmap(struct file *filp, struct vm_area_struct *vma)
>   	vma->vm_flags |= VM_IO | VM_DONTEXPAND | VM_DONTDUMP;
>   	vma->vm_private_data = sfp;
>   	vma->vm_ops = &sg_mmap_vm_ops;
> -	return 0;
> +out:
> +	mutex_unlock(&sfp->f_mutex);
> +	return ret;
>   }
>   
>   static void
> 

[toc] | [prev] | [next] | [standalone]


#1717984

From"Martin K. Petersen" <martin.petersen@oracle.com>
Date2017-08-23 04:30 +0200
Message-ID<uhtAC-2W7-3@gated-at.bofh.it>
In reply to#1712697
Todd,

> Take f_mutex around mmap() processing to protect against races with
> the SG_SET_RESERVED_SIZE ioctl.  Ensure the reserve buffer length
> remains consistent during the mapping operation, and set the
> "mmap called" flag to prevent further changes to the reserved buffer
> size as an atomic operation with the mapping.

Applied to 4.14/scsi-queue (with a slight whitespace fix). Thanks!

-- 
Martin K. Petersen	Oracle Linux Engineering

[toc] | [prev] | [standalone]


Back to top | Article view | linux.kernel


csiph-web