From patchwork Thu Jun 20 16:23:02 2024 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Arnd Bergmann X-Patchwork-Id: 805992 Delivered-To: patch@linaro.org Received: by 2002:a5d:508d:0:b0:362:4979:7f74 with SMTP id a13csp377328wrt; Thu, 20 Jun 2024 09:23:57 -0700 (PDT) X-Forwarded-Encrypted: i=3; AJvYcCV8fVUv/ZlvFlSlUJS6jE2IWCAHurPMrjDD6iP17ogO7VHSo2gbgzEirW0xHjw/4c9PFbLJdBXyKZL0qoohpctJ X-Google-Smtp-Source: AGHT+IHx4v6YlQF+UqNiZ7q1jDWuZ1uIBsj6c9dCXe9YAAjtAi9NxQZOIuBQwMbPmKIvqBMTSk+H X-Received: by 2002:a05:6102:731:b0:48f:1adb:7e53 with SMTP id ada2fe7eead31-48f1adb7f43mr3931109137.19.1718900637025; Thu, 20 Jun 2024 09:23:57 -0700 (PDT) ARC-Seal: i=2; a=rsa-sha256; t=1718900637; cv=pass; d=google.com; s=arc-20160816; b=sDFQso9/Er08dw5z4/iAsSz8X93+725MTMsKcvHz1Dnj02bIt6ZicMXxY3sQP/Sx4S BblexK1naNhhXDaymJGbctWYoNeYedNHvv36Rt1SAd5gbw2HIlDdlbtvQtAYxjyFDw+L Vk7oIyU6n8/odNCsKWQ3VrHn8rrkLHxYS4lNn2wIRbUDPUFXAY1VSRsb+TaVidH+ZgAe PCe+EeRw5+LaWt0YuvX5w1Iae07qBCRt6gVe3P//ZjUjLgo/9s20bR3qJwJrvrXZlu+4 B2yCn70DBEOIjan6vbg22JdXhyfhkjkb0+FZrql8dFt6auVIpeU3kS3TqOzDMAaf6znC r1Dw== ARC-Message-Signature: i=2; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=errors-to:list-subscribe:list-help:list-post:list-archive :list-unsubscribe:list-id:precedence:content-transfer-encoding :mime-version:references:in-reply-to:message-id:date:subject:cc:to :from:dkim-signature:arc-filter:dmarc-filter:delivered-to; bh=freZwdYkoNbt2Gm5oN6bpYmbUQak+DSrOR1RtO0rwbk=; fh=z7WBpRnpEcajsi+eCrB9be3IBpnFpuOD2qMP8Shfqmo=; b=R1SXy11z7QCErMldbt/XTj6WBhAXPsk/CY/QhOS2P2tOYFO2z0gvq5pzlUs9EVAN/L vaGo9G84mJFvL+V5GSGgXXEFAbJPLbn/8tHDOfZ+j+fQGtvklK7Bw3Vf26IbArUwaXnV bk34idogQ3JGiisHOsuUGY3lOaaUuJDEOIseWJDWnevRhLjXDKXk2Bcc0G6hgvb5c9+n 1NpTtnoSmXNe9A01y+f9+B8Ae54gJzm2tHabz6HYASwvNd3O8YvwqfRTfiLPy2RYjkQy SBGo87H1nlp+H49/fhPXdk0sodqNlKTPBjynmgX1QTFcI2Qf0Ww34xxgeFr0kvZkwuxA awYg==; dara=google.com ARC-Authentication-Results: i=2; mx.google.com; dkim=pass header.i=@kernel.org header.s=k20201202 header.b=qFPMZFuI; arc=pass (i=1); spf=pass (google.com: domain of libc-alpha-bounces+patch=linaro.org@sourceware.org designates 2620:52:3:1:0:246e:9693:128c as permitted sender) smtp.mailfrom="libc-alpha-bounces+patch=linaro.org@sourceware.org"; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=kernel.org Return-Path: Received: from server2.sourceware.org (server2.sourceware.org. [2620:52:3:1:0:246e:9693:128c]) by mx.google.com with ESMTPS id ada2fe7eead31-48da43b86f2si2647195137.181.2024.06.20.09.23.55 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 20 Jun 2024 09:23:56 -0700 (PDT) Received-SPF: pass (google.com: domain of libc-alpha-bounces+patch=linaro.org@sourceware.org designates 2620:52:3:1:0:246e:9693:128c as permitted sender) client-ip=2620:52:3:1:0:246e:9693:128c; Authentication-Results: mx.google.com; dkim=pass header.i=@kernel.org header.s=k20201202 header.b=qFPMZFuI; arc=pass (i=1); spf=pass (google.com: domain of libc-alpha-bounces+patch=linaro.org@sourceware.org designates 2620:52:3:1:0:246e:9693:128c as permitted sender) smtp.mailfrom="libc-alpha-bounces+patch=linaro.org@sourceware.org"; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=kernel.org Received: from server2.sourceware.org (localhost [IPv6:::1]) by sourceware.org (Postfix) with ESMTP id 9D99A3893646 for ; Thu, 20 Jun 2024 16:23:55 +0000 (GMT) X-Original-To: libc-alpha@sourceware.org Delivered-To: libc-alpha@sourceware.org Received: from dfw.source.kernel.org (dfw.source.kernel.org [IPv6:2604:1380:4641:c500::1]) by sourceware.org (Postfix) with ESMTPS id 371AC3890431 for ; Thu, 20 Jun 2024 16:23:43 +0000 (GMT) DMARC-Filter: OpenDMARC Filter v1.4.2 sourceware.org 371AC3890431 Authentication-Results: sourceware.org; dmarc=pass (p=none dis=none) header.from=kernel.org Authentication-Results: sourceware.org; spf=pass smtp.mailfrom=kernel.org ARC-Filter: OpenARC Filter v1.0.0 sourceware.org 371AC3890431 Authentication-Results: server2.sourceware.org; arc=none smtp.remote-ip=2604:1380:4641:c500::1 ARC-Seal: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1718900624; cv=none; b=x+G0iKjT5kKGz/yEqKxFLXDqpgByDvJBuS9+1RcgsM/6gAf+syqabj6+Y1gCkYqIUyki7pT5lKSfn+zcY2Lq2Ag8V3RcZcegP3WvEYpsLmLTtZRkrlWNFsmRznPHcfbbrheTBTGsPBpzgHoWl89pcYHHmNofpHL/gXN0/uB1CzY= ARC-Message-Signature: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1718900624; c=relaxed/simple; bh=CGFeZxnM99WO8CUQsmcPRyeSqTluGP6wK4tt26wo7MA=; h=DKIM-Signature:From:To:Subject:Date:Message-Id:MIME-Version; b=buuWaeo31TI6m6Yf0YHyZivZJ2H+UGMHZPWNrKStcFEYEcbFxXP/V3fa9hEgfmyf79PPIBgX+WlpUd2QMTrwbFxGhGF/eUZIjI1hDaTAk6o1Q3/LMN2DpECJLkCxAr7WGsyyu6OIjJR7V8pEMRFK7CZc8u1C2ERu5QbV0hjVO/A= ARC-Authentication-Results: i=1; server2.sourceware.org Received: from smtp.kernel.org (transwarp.subspace.kernel.org [100.75.92.58]) by dfw.source.kernel.org (Postfix) with ESMTP id BBACF62097; Thu, 20 Jun 2024 16:23:42 +0000 (UTC) Received: by smtp.kernel.org (Postfix) with ESMTPSA id E2418C4AF09; Thu, 20 Jun 2024 16:23:35 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=k20201202; t=1718900622; bh=CGFeZxnM99WO8CUQsmcPRyeSqTluGP6wK4tt26wo7MA=; h=From:To:Cc:Subject:Date:In-Reply-To:References:From; b=qFPMZFuIa5R0Glf5ENc2BYFqZfPhYo8QIZnyrdimQlTBKvaHbuCtPvrIfomllEd9/ JpLNq2SDbtHqlJyuLH0dQP8moKiF8uhmumJYs9o2sBsCPGtMQKxsjkvFceJbD2sCe5 iqYfcls+BOXFi8S8pRjY7giMA82l1MsB4/7AAhWDtByCl8OAAtDGML8o/+To3bUkRa PuTTC4pDoNbmyoCTObOuXs8R+JSz0u0eYIhSXe0Dmh5XnqLbr+7IhR9P908xkYXNwP ZamhH6pESgfZ6DKzg3bZRZInz7WGQ0gGLigYJa47XVNNvrSHskhf5n0cIAxbD+morq YgXJDRrkqY+ZA== From: Arnd Bergmann To: linux-arch@vger.kernel.org, linux-kernel@vger.kernel.org Cc: Arnd Bergmann , Thomas Bogendoerfer , linux-mips@vger.kernel.org, Helge Deller , linux-parisc@vger.kernel.org, "David S. Miller" , Andreas Larsson , sparclinux@vger.kernel.org, Michael Ellerman , Nicholas Piggin , Christophe Leroy , "Naveen N . Rao" , linuxppc-dev@lists.ozlabs.org, Brian Cain , linux-hexagon@vger.kernel.org, Guo Ren , linux-csky@vger.kernel.org, Heiko Carstens , linux-s390@vger.kernel.org, Rich Felker , John Paul Adrian Glaubitz , linux-sh@vger.kernel.org, "H. Peter Anvin" , Alexander Viro , Christian Brauner , linux-fsdevel@vger.kernel.org, libc-alpha@sourceware.org, musl@lists.openwall.com, ltp@lists.linux.it, stable@vger.kernel.org Subject: [PATCH 01/15] ftruncate: pass a signed offset Date: Thu, 20 Jun 2024 18:23:02 +0200 Message-Id: <20240620162316.3674955-2-arnd@kernel.org> X-Mailer: git-send-email 2.39.2 In-Reply-To: <20240620162316.3674955-1-arnd@kernel.org> References: <20240620162316.3674955-1-arnd@kernel.org> MIME-Version: 1.0 X-Spam-Status: No, score=-10.6 required=5.0 tests=BAYES_00, DKIMWL_WL_HIGH, DKIM_SIGNED, DKIM_VALID, DKIM_VALID_AU, DKIM_VALID_EF, GIT_PATCH_0, SPF_HELO_NONE, SPF_PASS, TXREP, T_SCC_BODY_TEXT_LINE autolearn=ham autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on server2.sourceware.org X-BeenThere: libc-alpha@sourceware.org X-Mailman-Version: 2.1.30 Precedence: list List-Id: Libc-alpha mailing list List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: libc-alpha-bounces+patch=linaro.org@sourceware.org From: Arnd Bergmann The old ftruncate() syscall, using the 32-bit off_t misses a sign extension when called in compat mode on 64-bit architectures. As a result, passing a negative length accidentally succeeds in truncating to file size between 2GiB and 4GiB. Changing the type of the compat syscall to the signed compat_off_t changes the behavior so it instead returns -EINVAL. The native entry point, the truncate() syscall and the corresponding loff_t based variants are all correct already and do not suffer from this mistake. Fixes: 3f6d078d4acc ("fix compat truncate/ftruncate") Cc: stable@vger.kernel.org Signed-off-by: Arnd Bergmann Reviewed-by: Christian Brauner --- fs/open.c | 4 ++-- include/linux/compat.h | 2 +- include/linux/syscalls.h | 2 +- 3 files changed, 4 insertions(+), 4 deletions(-) diff --git a/fs/open.c b/fs/open.c index 89cafb572061..50e45bc7c4d8 100644 --- a/fs/open.c +++ b/fs/open.c @@ -202,13 +202,13 @@ long do_sys_ftruncate(unsigned int fd, loff_t length, int small) return error; } -SYSCALL_DEFINE2(ftruncate, unsigned int, fd, unsigned long, length) +SYSCALL_DEFINE2(ftruncate, unsigned int, fd, off_t, length) { return do_sys_ftruncate(fd, length, 1); } #ifdef CONFIG_COMPAT -COMPAT_SYSCALL_DEFINE2(ftruncate, unsigned int, fd, compat_ulong_t, length) +COMPAT_SYSCALL_DEFINE2(ftruncate, unsigned int, fd, compat_off_t, length) { return do_sys_ftruncate(fd, length, 1); } diff --git a/include/linux/compat.h b/include/linux/compat.h index 233f61ec8afc..56cebaff0c91 100644 --- a/include/linux/compat.h +++ b/include/linux/compat.h @@ -608,7 +608,7 @@ asmlinkage long compat_sys_fstatfs(unsigned int fd, asmlinkage long compat_sys_fstatfs64(unsigned int fd, compat_size_t sz, struct compat_statfs64 __user *buf); asmlinkage long compat_sys_truncate(const char __user *, compat_off_t); -asmlinkage long compat_sys_ftruncate(unsigned int, compat_ulong_t); +asmlinkage long compat_sys_ftruncate(unsigned int, compat_off_t); /* No generic prototype for truncate64, ftruncate64, fallocate */ asmlinkage long compat_sys_openat(int dfd, const char __user *filename, int flags, umode_t mode); diff --git a/include/linux/syscalls.h b/include/linux/syscalls.h index 9104952d323d..ba9337709878 100644 --- a/include/linux/syscalls.h +++ b/include/linux/syscalls.h @@ -418,7 +418,7 @@ asmlinkage long sys_listmount(const struct mnt_id_req __user *req, u64 __user *mnt_ids, size_t nr_mnt_ids, unsigned int flags); asmlinkage long sys_truncate(const char __user *path, long length); -asmlinkage long sys_ftruncate(unsigned int fd, unsigned long length); +asmlinkage long sys_ftruncate(unsigned int fd, off_t length); #if BITS_PER_LONG == 32 asmlinkage long sys_truncate64(const char __user *path, loff_t length); asmlinkage long sys_ftruncate64(unsigned int fd, loff_t length);