提交 921a7acd 编写于 作者: C Changbin Du 提交者: Steven Rostedt (VMware)

tracing: Detect the string nul character when parsing user input string

User space can pass in a C nul character '\0' along with its input. The
function trace_get_user() will try to process it as a normal character,
and that will fail to parse.

open("/sys/kernel/debug/tracing//set_ftrace_pid", O_WRONLY|O_TRUNC) = 3
write(3, " \0", 2)                      = -1 EINVAL (Invalid argument)

while parse can handle spaces, so below works.

$ echo "" > set_ftrace_pid
$ echo " " > set_ftrace_pid
$ echo -n " " > set_ftrace_pid

Have the parser stop on '\0' and cease any further parsing. Only process
the characters up to the nul '\0' character and do not process it.

Link: http://lkml.kernel.org/r/1516093350-12045-2-git-send-email-changbin.du@intel.comAcked-by: NNamhyung Kim <namhyung@kernel.org>
Signed-off-by: NChangbin Du <changbin.du@intel.com>
Signed-off-by: NSteven Rostedt (VMware) <rostedt@goodmis.org>
上级 2ee5b92a
...@@ -1237,7 +1237,7 @@ int trace_get_user(struct trace_parser *parser, const char __user *ubuf, ...@@ -1237,7 +1237,7 @@ int trace_get_user(struct trace_parser *parser, const char __user *ubuf,
} }
/* only spaces were written */ /* only spaces were written */
if (isspace(ch)) { if (isspace(ch) || !ch) {
*ppos += read; *ppos += read;
ret = read; ret = read;
goto out; goto out;
...@@ -1247,7 +1247,7 @@ int trace_get_user(struct trace_parser *parser, const char __user *ubuf, ...@@ -1247,7 +1247,7 @@ int trace_get_user(struct trace_parser *parser, const char __user *ubuf,
} }
/* read the non-space input */ /* read the non-space input */
while (cnt && !isspace(ch)) { while (cnt && !isspace(ch) && ch) {
if (parser->idx < parser->size - 1) if (parser->idx < parser->size - 1)
parser->buffer[parser->idx++] = ch; parser->buffer[parser->idx++] = ch;
else { else {
...@@ -1262,7 +1262,7 @@ int trace_get_user(struct trace_parser *parser, const char __user *ubuf, ...@@ -1262,7 +1262,7 @@ int trace_get_user(struct trace_parser *parser, const char __user *ubuf,
} }
/* We either got finished input or we have to wait for another call. */ /* We either got finished input or we have to wait for another call. */
if (isspace(ch)) { if (isspace(ch) || !ch) {
parser->buffer[parser->idx] = 0; parser->buffer[parser->idx] = 0;
parser->cont = false; parser->cont = false;
} else if (parser->idx < parser->size - 1) { } else if (parser->idx < parser->size - 1) {
......
Markdown is supported
0% .
You are about to add 0 people to the discussion. Proceed with caution.
先完成此消息的编辑!
想要评论请 注册