From nobody Wed Feb 16 16:52:42 2022 X-Original-To: dev-commits-src-branches@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 3494219BB05C; Wed, 16 Feb 2022 16:52:43 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "R3" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 4JzPCH0syzz4YBy; Wed, 16 Feb 2022 16:52:43 +0000 (UTC) (envelope-from git@FreeBSD.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1645030363; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=AHaq2bXbYE7KtJRS/EQ60KAjPawzTv41LnPjB47Ln2M=; b=Ha75wabOgpcbCHzCSKAM7wj+gcqSz8DVcsvxHUJ3jcZqC31FYccPI7rmem/68miSPolHti 7SFPuj+i8SUqmqLGUrw6/ggn6LdrhbsdJgXgQKHg0hh5pGAAbCx0Nx9uVzV/YzPaMMTuOd GxbfYDoEj8vp1jbbkT0ie3mSwfq2kIe9bYhuk8ez/uF16ygyLrYIR/R2YMfSPL7yV5KNZD R913PJUNA0J+fBjArizAXmc523Jc4ixlsUvBRyMYkQqEJ6HcMk6WYVPmeOBIRsASWnjIBE 2/sg5N4XmopAOlJYrn9R64HsOBAVVvQRYa2MOVMFvib1mrXO4GbH+fzjS7vEhw== Received: from gitrepo.freebsd.org (gitrepo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:5]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (Client did not present a certificate) by mxrelay.nyi.freebsd.org (Postfix) with ESMTPS id F18F019EE3; Wed, 16 Feb 2022 16:52:42 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from gitrepo.freebsd.org ([127.0.1.44]) by gitrepo.freebsd.org (8.16.1/8.16.1) with ESMTP id 21GGqgqJ068503; Wed, 16 Feb 2022 16:52:42 GMT (envelope-from git@gitrepo.freebsd.org) Received: (from git@localhost) by gitrepo.freebsd.org (8.16.1/8.16.1/Submit) id 21GGqgY1068502; Wed, 16 Feb 2022 16:52:42 GMT (envelope-from git) Date: Wed, 16 Feb 2022 16:52:42 GMT Message-Id: <202202161652.21GGqgY1068502@gitrepo.freebsd.org> To: src-committers@FreeBSD.org, dev-commits-src-all@FreeBSD.org, dev-commits-src-branches@FreeBSD.org From: Mark Johnston Subject: git: 7ac2a6354f35 - stable/13 - file: Make fget*() and getvnode*() consistent about initializing *fpp List-Id: Commits to the stable branches of the FreeBSD src repository List-Archive: https://lists.freebsd.org/archives/dev-commits-src-branches List-Help: List-Post: List-Subscribe: List-Unsubscribe: Sender: owner-dev-commits-src-branches@freebsd.org X-BeenThere: dev-commits-src-branches@freebsd.org MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Git-Committer: markj X-Git-Repository: src X-Git-Refname: refs/heads/stable/13 X-Git-Reftype: branch X-Git-Commit: 7ac2a6354f35b785f58a9330bcd0496d0f382137 Auto-Submitted: auto-generated ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1645030363; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=AHaq2bXbYE7KtJRS/EQ60KAjPawzTv41LnPjB47Ln2M=; b=kcguRXUdqtJD6Kh4+0BShJOLpmWLsayduZvAWw9tUI7k5ZNBHV8Yl3/sOj/o2Qs77vMrvZ hGyrvhKKfsUadsRvzicL9yDHLkV4kwlFkviKcHXYjs7dPY+lG/kfH7HLU7uq/vKZuTUipT F6DBlIXfpn9F/kK+qjTQmok4DirE3wd9AZnXLENifiRPRaf1xeNEYQGV1mvj0Urt1uIzdj uhlMmd/7ya8FOF1mGQAbyKi6uRz3toA1MgGlp72mx5dYHLWjJ7t8g5ONo9tOW/f3ya87JL dS8/gWJPE751K57OzYEbhQjR2MH2u8Frm9bsq6jZYYy7MMpMR1AQ7UfVme8obA== ARC-Seal: i=1; s=dkim; d=freebsd.org; t=1645030363; a=rsa-sha256; cv=none; b=ooV7Evx2F+MiqC9ItTu4ZRzAEARO3uR1yPS0AFf5S43UpZ4s97RWB2TQ7LYB8ZruHDsCwD GUqYscEKwZlGiA3D5SsckTtMoQZR2gtlz+cdcOaHJwvJ+nWx9WeIdMTQXA+FLZjfbnuq0f 6pL/68Rf+EMwfL5UiPYvNrEoNZeg0xbfUlL+ZK5Zge09d35hsSaznt4j08QggnCrElJQDG rJLDARLkjhIpudUQPETloqrF674evaGlTixnzVnLZiT45IV0LPcqL+QbD7JhaJcpG3HowT hztsgTtldR4BcXtxMuFlPJaQzkxDTC20Hk0n6/Zrj2VTqyTWoHzQVGkSn/X/4A== ARC-Authentication-Results: i=1; mx1.freebsd.org; none X-ThisMailContainsUnwantedMimeParts: N The branch stable/13 has been updated by markj: URL: https://cgit.FreeBSD.org/src/commit/?id=7ac2a6354f35b785f58a9330bcd0496d0f382137 commit 7ac2a6354f35b785f58a9330bcd0496d0f382137 Author: Mark Johnston AuthorDate: 2022-02-08 17:34:20 +0000 Commit: Mark Johnston CommitDate: 2022-02-16 16:52:31 +0000 file: Make fget*() and getvnode*() consistent about initializing *fpp Most fget*() functions initialize the output parameter to NULL. Make the externally visible interface behave consistently, and make fget_unlocked_seq() private to kern_descrip.c. This fixes at least one bug in a consumer, _filemon_wrapper_openat(), which assumes that getvnode() sets the output file pointer to NULL upon an error. Reported by: syzbot+01c0459408f896a5933a@syzkaller.appspotmail.com Reviewed by: kib Sponsored by: The FreeBSD Foundation (cherry picked from commit 300cfb96fc2253c3aff8d501d5599fcf811daa34) --- sys/kern/kern_descrip.c | 12 ++++++++++-- sys/kern/vfs_syscalls.c | 2 ++ sys/sys/filedesc.h | 3 --- 3 files changed, 12 insertions(+), 5 deletions(-) diff --git a/sys/kern/kern_descrip.c b/sys/kern/kern_descrip.c index f3dd675d806a..025259dd20f3 100644 --- a/sys/kern/kern_descrip.c +++ b/sys/kern/kern_descrip.c @@ -115,6 +115,8 @@ static void fdgrowtable(struct filedesc *fdp, int nfd); static void fdgrowtable_exp(struct filedesc *fdp, int nfd); static void fdunused(struct filedesc *fdp, int fd); static void fdused(struct filedesc *fdp, int fd); +static int fget_unlocked_seq(struct filedesc *fdp, int fd, + cap_rights_t *needrightsp, struct file **fpp, seqc_t *seqp); static int getmaxfd(struct thread *td); static u_long *filecaps_copy_prep(const struct filecaps *src); static void filecaps_copy_finish(const struct filecaps *src, @@ -2931,6 +2933,7 @@ fget_cap_locked(struct filedesc *fdp, int fd, cap_rights_t *needrightsp, FILEDESC_LOCK_ASSERT(fdp); + *fpp = NULL; fde = fdeget_locked(fdp, fd); if (fde == NULL) { error = EBADF; @@ -3102,7 +3105,7 @@ fgetvp_lookup_smr(int fd, struct nameidata *ndp, struct vnode **vpp, bool *fsear } #endif -int +static int fget_unlocked_seq(struct filedesc *fdp, int fd, cap_rights_t *needrightsp, struct file **fpp, seqc_t *seqp) { @@ -3200,8 +3203,10 @@ fget_unlocked(struct filedesc *fdp, int fd, cap_rights_t *needrightsp, #endif fdt = fdp->fd_files; - if (__predict_false((u_int)fd >= fdt->fdt_nfiles)) + if (__predict_false((u_int)fd >= fdt->fdt_nfiles)) { + *fpp = NULL; return (EBADF); + } #ifdef CAPABILITIES seq = seqc_read_notmodify(fd_seqc(fdt, fd)); fde = &fdt->fdt_ofiles[fd]; @@ -3236,6 +3241,7 @@ fget_unlocked(struct filedesc *fdp, int fd, cap_rights_t *needrightsp, out_fdrop: fdrop(fp, curthread); out_fallback: + *fpp = NULL; return (fget_unlocked_seq(fdp, fd, needrightsp, fpp, NULL)); } @@ -3261,6 +3267,7 @@ fget_only_user(struct filedesc *fdp, int fd, cap_rights_t *needrightsp, MPASS(FILEDESC_IS_ONLY_USER(fdp)); + *fpp = NULL; if (__predict_false(fd >= fdp->fd_nfiles)) return (EBADF); @@ -3286,6 +3293,7 @@ fget_only_user(struct filedesc *fdp, int fd, cap_rights_t *needrightsp, MPASS(FILEDESC_IS_ONLY_USER(fdp)); + *fpp = NULL; if (__predict_false(fd >= fdp->fd_nfiles)) return (EBADF); diff --git a/sys/kern/vfs_syscalls.c b/sys/kern/vfs_syscalls.c index 6dc6ca43a774..3d1e7d9c73fa 100644 --- a/sys/kern/vfs_syscalls.c +++ b/sys/kern/vfs_syscalls.c @@ -4306,6 +4306,7 @@ getvnode_path(struct thread *td, int fd, cap_rights_t *rightsp, */ if (fp->f_vnode == NULL || fp->f_ops == &badfileops) { fdrop(fp, td); + *fpp = NULL; return (EINVAL); } @@ -4331,6 +4332,7 @@ getvnode(struct thread *td, int fd, cap_rights_t *rightsp, struct file **fpp) */ if (error == 0 && (*fpp)->f_ops == &path_fileops) { fdrop(*fpp, td); + *fpp = NULL; error = EBADF; } diff --git a/sys/sys/filedesc.h b/sys/sys/filedesc.h index f17fdf601ba1..9ae7b543e4a1 100644 --- a/sys/sys/filedesc.h +++ b/sys/sys/filedesc.h @@ -273,10 +273,7 @@ int fget_cap_locked(struct filedesc *fdp, int fd, cap_rights_t *needrightsp, struct file **fpp, struct filecaps *havecapsp); int fget_cap(struct thread *td, int fd, cap_rights_t *needrightsp, struct file **fpp, struct filecaps *havecapsp); - /* Return a referenced file from an unlocked descriptor. */ -int fget_unlocked_seq(struct filedesc *fdp, int fd, cap_rights_t *needrightsp, - struct file **fpp, seqc_t *seqp); int fget_unlocked(struct filedesc *fdp, int fd, cap_rights_t *needrightsp, struct file **fpp); /* Return a file pointer without a ref. FILEDESC_IS_ONLY_USER must be true. */