[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: [Qemu-devel] [PATCH 06/12] linux-user: Detect Negative Message Sizes
From: |
Peter Maydell |
Subject: |
Re: [Qemu-devel] [PATCH 06/12] linux-user: Detect Negative Message Sizes in msgsnd System Call |
Date: |
Mon, 4 Aug 2014 18:26:23 +0100 |
On 4 August 2014 17:45, Tom Musta <address@hidden> wrote:
> The msgsnd system call takes an argument that describes the message
> size (msgsz) and is of type size_t. The system call should set
> errno to EINVAL in the event that a negative message size is passed.
>
> Signed-off-by: Tom Musta <address@hidden>
>
> diff --git a/linux-user/syscall.c b/linux-user/syscall.c
> index c0c0434..f524a39 100644
> --- a/linux-user/syscall.c
> +++ b/linux-user/syscall.c
> @@ -2870,12 +2870,16 @@ struct target_msgbuf {
> };
>
> static inline abi_long do_msgsnd(int msqid, abi_long msgp,
> - unsigned int msgsz, int msgflg)
> + ssize_t msgsz, int msgflg)
> {
> struct target_msgbuf *target_mb;
> struct msgbuf *host_mb;
> abi_long ret = 0;
>
> + if (msgsz < 0) {
> + return -TARGET_EINVAL;
> + }
> +
> if (!lock_user_struct(VERIFY_READ, target_mb, msgp, 0))
> return -TARGET_EFAULT;
> host_mb = malloc(msgsz+sizeof(long));
> --
This won't catch the case where the guest's abi_long is
64 bit but the host's ssize_t is only 32 bits and the guest
passed us a negative value with bit 31 zero, but we
probably don't really care about that.
Reviewed-by: Peter Maydell <address@hidden>
thanks
-- PMM
- [Qemu-devel] [PATCH 02/12] linux-user: Dereference Pointer Argument to ipc/semctl Sys Call, (continued)
- [Qemu-devel] [PATCH 02/12] linux-user: Dereference Pointer Argument to ipc/semctl Sys Call, Tom Musta, 2014/08/04
- [Qemu-devel] [PATCH 03/12] linux-user: Properly Handle semun Structure In Cross-Endian Situations, Tom Musta, 2014/08/04
- [Qemu-devel] [PATCH 04/12] linux-user: Make ipc syscall's third argument an abi_long, Tom Musta, 2014/08/04
- [Qemu-devel] [PATCH 05/12] linux-user: Conditionally Pass Attribute Pointer to mq_open(), Tom Musta, 2014/08/04
- [Qemu-devel] [PATCH 06/12] linux-user: Detect Negative Message Sizes in msgsnd System Call, Tom Musta, 2014/08/04
- Re: [Qemu-devel] [PATCH 06/12] linux-user: Detect Negative Message Sizes in msgsnd System Call,
Peter Maydell <=
- [Qemu-devel] [PATCH 07/12] linux-user: Handle NULL argument to sched_{get, set}param, Tom Musta, 2014/08/04
- [Qemu-devel] [PATCH 08/12] linux-user: Detect fault in sched_rr_get_interval, Tom Musta, 2014/08/04
- [Qemu-devel] [PATCH 09/12] linux-user: Minimum Sig Handler Stack Size for PPC64 ELF V2, Tom Musta, 2014/08/04
- [Qemu-devel] [PATCH 10/12] linux-user: clock_nanosleep errno Handling on PPC, Tom Musta, 2014/08/04