提交 4167a960 编写于 作者: G Gustavo A. R. Silva 提交者: David S. Miller

net/ipv4: Revert use of struct_size() helper

Revert the use of structr_size() and stay with IP_MSFILTER_SIZE() for
now, as in this case, the size of struct ip_msfilter didn't change with
the addition of the flexible array imsf_slist_flex[]. So, if we use
struct_size() we will be allocating and calculating the size of
struct ip_msfilter with one too many items for imsf_slist_flex[].

We might use struct_size() in the future, but for now let's stay
with IP_MSFILTER_SIZE().

Fixes: 	2d3e5caf ("net/ipv4: Replace one-element array with flexible-array member")
Signed-off-by: NGustavo A. R. Silva <gustavoars@kernel.org>
Signed-off-by: NDavid S. Miller <davem@davemloft.net>
上级 af352460
...@@ -2553,8 +2553,8 @@ int ip_mc_msfget(struct sock *sk, struct ip_msfilter *msf, ...@@ -2553,8 +2553,8 @@ int ip_mc_msfget(struct sock *sk, struct ip_msfilter *msf,
copycount = count < msf->imsf_numsrc ? count : msf->imsf_numsrc; copycount = count < msf->imsf_numsrc ? count : msf->imsf_numsrc;
len = flex_array_size(psl, sl_addr, copycount); len = flex_array_size(psl, sl_addr, copycount);
msf->imsf_numsrc = count; msf->imsf_numsrc = count;
if (put_user(struct_size(optval, imsf_slist_flex, copycount), optlen) || if (put_user(IP_MSFILTER_SIZE(copycount), optlen) ||
copy_to_user(optval, msf, struct_size(optval, imsf_slist_flex, 0))) { copy_to_user(optval, msf, IP_MSFILTER_SIZE(0))) {
return -EFAULT; return -EFAULT;
} }
if (len && if (len &&
......
...@@ -667,7 +667,7 @@ static int set_mcast_msfilter(struct sock *sk, int ifindex, ...@@ -667,7 +667,7 @@ static int set_mcast_msfilter(struct sock *sk, int ifindex,
struct sockaddr_in *psin; struct sockaddr_in *psin;
int err, i; int err, i;
msf = kmalloc(struct_size(msf, imsf_slist_flex, numsrc), GFP_KERNEL); msf = kmalloc(IP_MSFILTER_SIZE(numsrc), GFP_KERNEL);
if (!msf) if (!msf)
return -ENOBUFS; return -ENOBUFS;
...@@ -1228,7 +1228,7 @@ static int do_ip_setsockopt(struct sock *sk, int level, int optname, ...@@ -1228,7 +1228,7 @@ static int do_ip_setsockopt(struct sock *sk, int level, int optname,
{ {
struct ip_msfilter *msf; struct ip_msfilter *msf;
if (optlen < struct_size(msf, imsf_slist_flex, 0)) if (optlen < IP_MSFILTER_SIZE(0))
goto e_inval; goto e_inval;
if (optlen > sysctl_optmem_max) { if (optlen > sysctl_optmem_max) {
err = -ENOBUFS; err = -ENOBUFS;
...@@ -1246,8 +1246,7 @@ static int do_ip_setsockopt(struct sock *sk, int level, int optname, ...@@ -1246,8 +1246,7 @@ static int do_ip_setsockopt(struct sock *sk, int level, int optname,
err = -ENOBUFS; err = -ENOBUFS;
break; break;
} }
if (struct_size(msf, imsf_slist_flex, msf->imsf_numsrc) > if (IP_MSFILTER_SIZE(msf->imsf_numsrc) > optlen) {
optlen) {
kfree(msf); kfree(msf);
err = -EINVAL; err = -EINVAL;
break; break;
...@@ -1660,12 +1659,11 @@ static int do_ip_getsockopt(struct sock *sk, int level, int optname, ...@@ -1660,12 +1659,11 @@ static int do_ip_getsockopt(struct sock *sk, int level, int optname,
{ {
struct ip_msfilter msf; struct ip_msfilter msf;
if (len < struct_size(&msf, imsf_slist_flex, 0)) { if (len < IP_MSFILTER_SIZE(0)) {
err = -EINVAL; err = -EINVAL;
goto out; goto out;
} }
if (copy_from_user(&msf, optval, if (copy_from_user(&msf, optval, IP_MSFILTER_SIZE(0))) {
struct_size(&msf, imsf_slist_flex, 0))) {
err = -EFAULT; err = -EFAULT;
goto out; goto out;
} }
......
Markdown is supported
0% .
You are about to add 0 people to the discussion. Proceed with caution.
先完成此消息的编辑!
想要评论请 注册