1. 09 9月, 2005 2 次提交
  2. 08 9月, 2005 3 次提交
    • A
      [PATCH] Fix 32bit sendmsg() flaw · 8920e8f9
      Al Viro 提交于
      When we copy 32bit ->msg_control contents to kernel, we walk the same
      userland data twice without sanity checks on the second pass.
      
      Second version of this patch: the original broke with 64-bit arches
      running 32-bit-compat-mode executables doing sendmsg() syscalls with
      unaligned CMSG data areas
      
      Another thing is that we use kmalloc() to allocate and sock_kfree_s()
      to free afterwards; less serious, but also needs fixing.
      Signed-off-by: NAl Viro <viro@zeniv.linux.org.uk>
      Signed-off-by: NDavid Woodhouse <dwmw2@infradead.org>
      Signed-off-by: NChris Wright <chrisw@osdl.org>
      Signed-off-by: NLinus Torvalds <torvalds@osdl.org>
      8920e8f9
    • M
      [PATCH] sunrpc: print unsigned integers in stats · 49e31cba
      Max Kellermann 提交于
      The sunrpc stats are collected in unsigned integers, but they are printed
      with '%d'.  That can result in negative numbers in /proc/net/rpc when the
      highest bit of a counter is set.  The following patch changes '%d' to '%u'
      where appropriate.
      
      Cc: "David S. Miller" <davem@davemloft.net>
      Cc: Trond Myklebust <trond.myklebust@fys.uio.no>
      Signed-off-by: NAndrew Morton <akpm@osdl.org>
      Signed-off-by: NLinus Torvalds <torvalds@osdl.org>
      49e31cba
    • B
      [PATCH] sunrpc: cache_register can use wrong module reference · f35279d3
      Bruce Allan 提交于
      When registering an RPC cache, cache_register() always sets the owner as the
      sunrpc module.  However, there are RPC caches owned by other modules.  With
      the incorrect owner setting, the real owning module can be removed potentially
      with an open reference to the cache from userspace.
      
      For example, if one were to stop the nfs server and unmount the nfsd
      filesystem, the nfsd module could be removed eventhough rpc.idmapd had
      references to the idtoname and nametoid caches (i.e.
      /proc/net/rpc/nfs4.<cachename>/channel is still open).  This resulted in a
      system panic on one of our machines when attempting to restart the nfs
      services after reloading the nfsd module.
      
      The following patch adds a 'struct module *owner' field in struct
      cache_detail.  The owner is further assigned to the struct proc_dir_entry
      in cache_register() so that the module cannot be unloaded while user-space
      daemons have an open reference on the associated file under /proc.
      Signed-off-by: NBruce Allan <bwa@us.ibm.com>
      Cc: Trond Myklebust <trond.myklebust@fys.uio.no>
      Cc: Neil Brown <neilb@cse.unsw.edu.au>
      Signed-off-by: NAndrew Morton <akpm@osdl.org>
      Signed-off-by: NLinus Torvalds <torvalds@osdl.org>
      f35279d3
  3. 07 9月, 2005 18 次提交
  4. 06 9月, 2005 11 次提交
  5. 02 9月, 2005 6 次提交