net: remove sockptr_advance
authorChristoph Hellwig <hch@lst.de>
Tue, 28 Jul 2020 16:38:35 +0000 (18:38 +0200)
committerDavid S. Miller <davem@davemloft.net>
Tue, 28 Jul 2020 20:43:40 +0000 (13:43 -0700)
sockptr_advance never properly worked.  Replace it with _offset variants
of copy_from_sockptr and copy_to_sockptr.

Fixes: ba423fdaa589 ("net: add a new sockptr_t type")
Reported-by: Jason A. Donenfeld <Jason@zx2c4.com>
Reported-by: Ido Schimmel <idosch@idosch.org>
Signed-off-by: Christoph Hellwig <hch@lst.de>
Acked-by: Jason A. Donenfeld <Jason@zx2c4.com>
Tested-by: Ido Schimmel <idosch@mellanox.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
drivers/crypto/chelsio/chtls/chtls_main.c
include/linux/sockptr.h
net/dccp/proto.c
net/ipv4/netfilter/arp_tables.c
net/ipv4/netfilter/ip_tables.c
net/ipv4/tcp.c
net/ipv6/ip6_flowlabel.c
net/ipv6/netfilter/ip6_tables.c
net/netfilter/x_tables.c
net/tls/tls_main.c

index c3058dc..66d247e 100644 (file)
@@ -525,9 +525,9 @@ static int do_chtls_setsockopt(struct sock *sk, int optname,
                /* Obtain version and type from previous copy */
                crypto_info[0] = tmp_crypto_info;
                /* Now copy the following data */
-               sockptr_advance(optval, sizeof(*crypto_info));
-               rc = copy_from_sockptr((char *)crypto_info + sizeof(*crypto_info),
-                               optval,
+               rc = copy_from_sockptr_offset((char *)crypto_info +
+                               sizeof(*crypto_info),
+                               optval, sizeof(*crypto_info),
                                sizeof(struct tls12_crypto_info_aes_gcm_128)
                                - sizeof(*crypto_info));
 
@@ -542,9 +542,9 @@ static int do_chtls_setsockopt(struct sock *sk, int optname,
        }
        case TLS_CIPHER_AES_GCM_256: {
                crypto_info[0] = tmp_crypto_info;
-               sockptr_advance(optval, sizeof(*crypto_info));
-               rc = copy_from_sockptr((char *)crypto_info + sizeof(*crypto_info),
-                                   optval,
+               rc = copy_from_sockptr_offset((char *)crypto_info +
+                               sizeof(*crypto_info),
+                               optval, sizeof(*crypto_info),
                                sizeof(struct tls12_crypto_info_aes_gcm_256)
                                - sizeof(*crypto_info));
 
index b13ea14..9e6c81d 100644 (file)
@@ -69,19 +69,26 @@ static inline bool sockptr_is_null(sockptr_t sockptr)
        return !sockptr.user;
 }
 
-static inline int copy_from_sockptr(void *dst, sockptr_t src, size_t size)
+static inline int copy_from_sockptr_offset(void *dst, sockptr_t src,
+               size_t offset, size_t size)
 {
        if (!sockptr_is_kernel(src))
-               return copy_from_user(dst, src.user, size);
-       memcpy(dst, src.kernel, size);
+               return copy_from_user(dst, src.user + offset, size);
+       memcpy(dst, src.kernel + offset, size);
        return 0;
 }
 
-static inline int copy_to_sockptr(sockptr_t dst, const void *src, size_t size)
+static inline int copy_from_sockptr(void *dst, sockptr_t src, size_t size)
+{
+       return copy_from_sockptr_offset(dst, src, 0, size);
+}
+
+static inline int copy_to_sockptr_offset(sockptr_t dst, size_t offset,
+               const void *src, size_t size)
 {
        if (!sockptr_is_kernel(dst))
-               return copy_to_user(dst.user, src, size);
-       memcpy(dst.kernel, src, size);
+               return copy_to_user(dst.user + offset, src, size);
+       memcpy(dst.kernel + offset, src, size);
        return 0;
 }
 
@@ -112,14 +119,6 @@ static inline void *memdup_sockptr_nul(sockptr_t src, size_t len)
        return p;
 }
 
-static inline void sockptr_advance(sockptr_t sockptr, size_t len)
-{
-       if (sockptr_is_kernel(sockptr))
-               sockptr.kernel += len;
-       else
-               sockptr.user += len;
-}
-
 static inline long strncpy_from_sockptr(char *dst, sockptr_t src, size_t count)
 {
        if (sockptr_is_kernel(src)) {
index 2e9e844..d148ab1 100644 (file)
@@ -426,9 +426,8 @@ static int dccp_setsockopt_service(struct sock *sk, const __be32 service,
                        return -ENOMEM;
 
                sl->dccpsl_nr = optlen / sizeof(u32) - 1;
-               sockptr_advance(optval, sizeof(service));
-               if (copy_from_sockptr(sl->dccpsl_list, optval,
-                                     optlen - sizeof(service)) ||
+               if (copy_from_sockptr_offset(sl->dccpsl_list, optval,
+                               sizeof(service), optlen - sizeof(service)) ||
                    dccp_list_has_service(sl, DCCP_SERVICE_INVALID_VALUE)) {
                        kfree(sl);
                        return -EFAULT;
index 9a1567d..d1e04d2 100644 (file)
@@ -971,8 +971,8 @@ static int do_replace(struct net *net, sockptr_t arg, unsigned int len)
                return -ENOMEM;
 
        loc_cpu_entry = newinfo->entries;
-       sockptr_advance(arg, sizeof(tmp));
-       if (copy_from_sockptr(loc_cpu_entry, arg, tmp.size) != 0) {
+       if (copy_from_sockptr_offset(loc_cpu_entry, arg, sizeof(tmp),
+                       tmp.size) != 0) {
                ret = -EFAULT;
                goto free_newinfo;
        }
@@ -1267,8 +1267,8 @@ static int compat_do_replace(struct net *net, sockptr_t arg, unsigned int len)
                return -ENOMEM;
 
        loc_cpu_entry = newinfo->entries;
-       sockptr_advance(arg, sizeof(tmp));
-       if (copy_from_sockptr(loc_cpu_entry, arg, tmp.size) != 0) {
+       if (copy_from_sockptr_offset(loc_cpu_entry, arg, sizeof(tmp),
+                       tmp.size) != 0) {
                ret = -EFAULT;
                goto free_newinfo;
        }
index f2a9680..f15bc21 100644 (file)
@@ -1126,8 +1126,8 @@ do_replace(struct net *net, sockptr_t arg, unsigned int len)
                return -ENOMEM;
 
        loc_cpu_entry = newinfo->entries;
-       sockptr_advance(arg, sizeof(tmp));
-       if (copy_from_sockptr(loc_cpu_entry, arg, tmp.size) != 0) {
+       if (copy_from_sockptr_offset(loc_cpu_entry, arg, sizeof(tmp),
+                       tmp.size) != 0) {
                ret = -EFAULT;
                goto free_newinfo;
        }
@@ -1508,8 +1508,8 @@ compat_do_replace(struct net *net, sockptr_t arg, unsigned int len)
                return -ENOMEM;
 
        loc_cpu_entry = newinfo->entries;
-       sockptr_advance(arg, sizeof(tmp));
-       if (copy_from_sockptr(loc_cpu_entry, arg, tmp.size) != 0) {
+       if (copy_from_sockptr_offset(loc_cpu_entry, arg, sizeof(tmp),
+                       tmp.size) != 0) {
                ret = -EFAULT;
                goto free_newinfo;
        }
index 27de938..4afec55 100644 (file)
@@ -2801,12 +2801,13 @@ static int tcp_repair_options_est(struct sock *sk, sockptr_t optbuf,
 {
        struct tcp_sock *tp = tcp_sk(sk);
        struct tcp_repair_opt opt;
+       size_t offset = 0;
 
        while (len >= sizeof(opt)) {
-               if (copy_from_sockptr(&opt, optbuf, sizeof(opt)))
+               if (copy_from_sockptr_offset(&opt, optbuf, offset, sizeof(opt)))
                        return -EFAULT;
 
-               sockptr_advance(optbuf, sizeof(opt));
+               offset += sizeof(opt);
                len -= sizeof(opt);
 
                switch (opt.opt_code) {
index 215b6f5..2d65526 100644 (file)
@@ -401,8 +401,8 @@ fl_create(struct net *net, struct sock *sk, struct in6_flowlabel_req *freq,
                memset(fl->opt, 0, sizeof(*fl->opt));
                fl->opt->tot_len = sizeof(*fl->opt) + olen;
                err = -EFAULT;
-               sockptr_advance(optval, CMSG_ALIGN(sizeof(*freq)));
-               if (copy_from_sockptr(fl->opt + 1, optval, olen))
+               if (copy_from_sockptr_offset(fl->opt + 1, optval,
+                               CMSG_ALIGN(sizeof(*freq)), olen))
                        goto done;
 
                msg.msg_controllen = olen;
@@ -703,9 +703,10 @@ release:
                goto recheck;
 
        if (!freq->flr_label) {
-               sockptr_advance(optval,
-                               offsetof(struct in6_flowlabel_req, flr_label));
-               if (copy_to_sockptr(optval, &fl->label, sizeof(fl->label))) {
+               size_t offset = offsetof(struct in6_flowlabel_req, flr_label);
+
+               if (copy_to_sockptr_offset(optval, offset, &fl->label,
+                               sizeof(fl->label))) {
                        /* Intentionally ignore fault. */
                }
        }
index 1d52957..2e2119b 100644 (file)
@@ -1143,8 +1143,8 @@ do_replace(struct net *net, sockptr_t arg, unsigned int len)
                return -ENOMEM;
 
        loc_cpu_entry = newinfo->entries;
-       sockptr_advance(arg, sizeof(tmp));
-       if (copy_from_sockptr(loc_cpu_entry, arg, tmp.size) != 0) {
+       if (copy_from_sockptr_offset(loc_cpu_entry, arg, sizeof(tmp),
+                       tmp.size) != 0) {
                ret = -EFAULT;
                goto free_newinfo;
        }
@@ -1517,8 +1517,8 @@ compat_do_replace(struct net *net, sockptr_t arg, unsigned int len)
                return -ENOMEM;
 
        loc_cpu_entry = newinfo->entries;
-       sockptr_advance(arg, sizeof(tmp));
-       if (copy_from_sockptr(loc_cpu_entry, arg, tmp.size) != 0) {
+       if (copy_from_sockptr_offset(loc_cpu_entry, arg, sizeof(tmp),
+                       tmp.size) != 0) {
                ret = -EFAULT;
                goto free_newinfo;
        }
index b97eb4b..91bf663 100644 (file)
@@ -1050,6 +1050,7 @@ EXPORT_SYMBOL_GPL(xt_check_target);
 void *xt_copy_counters(sockptr_t arg, unsigned int len,
                       struct xt_counters_info *info)
 {
+       size_t offset;
        void *mem;
        u64 size;
 
@@ -1067,7 +1068,7 @@ void *xt_copy_counters(sockptr_t arg, unsigned int len,
 
                memcpy(info->name, compat_tmp.name, sizeof(info->name) - 1);
                info->num_counters = compat_tmp.num_counters;
-               sockptr_advance(arg, sizeof(compat_tmp));
+               offset = sizeof(compat_tmp);
        } else
 #endif
        {
@@ -1078,7 +1079,7 @@ void *xt_copy_counters(sockptr_t arg, unsigned int len,
                if (copy_from_sockptr(info, arg, sizeof(*info)) != 0)
                        return ERR_PTR(-EFAULT);
 
-               sockptr_advance(arg, sizeof(*info));
+               offset = sizeof(*info);
        }
        info->name[sizeof(info->name) - 1] = '\0';
 
@@ -1092,7 +1093,7 @@ void *xt_copy_counters(sockptr_t arg, unsigned int len,
        if (!mem)
                return ERR_PTR(-ENOMEM);
 
-       if (copy_from_sockptr(mem, arg, len) == 0)
+       if (copy_from_sockptr_offset(mem, arg, offset, len) == 0)
                return mem;
 
        vfree(mem);
index d77f7d8..bbc52b0 100644 (file)
@@ -522,9 +522,9 @@ static int do_tls_setsockopt_conf(struct sock *sk, sockptr_t optval,
                goto err_crypto_info;
        }
 
-       sockptr_advance(optval, sizeof(*crypto_info));
-       rc = copy_from_sockptr(crypto_info + 1, optval,
-                              optlen - sizeof(*crypto_info));
+       rc = copy_from_sockptr_offset(crypto_info + 1, optval,
+                                     sizeof(*crypto_info),
+                                     optlen - sizeof(*crypto_info));
        if (rc) {
                rc = -EFAULT;
                goto err_crypto_info;