提交 96107564 编写于 作者: R Rich Felker

workaround another sendmsg kernel bug on 64-bit machines

the kernel wrongly expects the cmsg length field to be size_t instead
of socklen_t. in order to work around the issue, we have to impose a
length limit and copy to a local buffer. the length limit should be
more than sufficient for any real-world use; these headers are only
used for passing file descriptors and permissions between processes
over unix sockets.
上级 90e123f4
...@@ -8,3 +8,10 @@ struct msghdr ...@@ -8,3 +8,10 @@ struct msghdr
socklen_t msg_controllen; socklen_t msg_controllen;
int msg_flags; int msg_flags;
}; };
struct cmsghdr
{
socklen_t cmsg_len;
int cmsg_level;
int cmsg_type;
};
...@@ -8,3 +8,10 @@ struct msghdr ...@@ -8,3 +8,10 @@ struct msghdr
socklen_t msg_controllen; socklen_t msg_controllen;
int msg_flags; int msg_flags;
}; };
struct cmsghdr
{
socklen_t cmsg_len;
int cmsg_level;
int cmsg_type;
};
...@@ -8,3 +8,10 @@ struct msghdr ...@@ -8,3 +8,10 @@ struct msghdr
socklen_t msg_controllen; socklen_t msg_controllen;
int msg_flags; int msg_flags;
}; };
struct cmsghdr
{
socklen_t cmsg_len;
int cmsg_level;
int cmsg_type;
};
...@@ -8,3 +8,11 @@ struct msghdr ...@@ -8,3 +8,11 @@ struct msghdr
socklen_t msg_controllen, __pad2; socklen_t msg_controllen, __pad2;
int msg_flags; int msg_flags;
}; };
struct cmsghdr
{
socklen_t cmsg_len;
int __pad1;
int cmsg_level;
int cmsg_type;
};
...@@ -17,13 +17,6 @@ extern "C" { ...@@ -17,13 +17,6 @@ extern "C" {
#include <bits/socket.h> #include <bits/socket.h>
struct cmsghdr
{
socklen_t cmsg_len;
int cmsg_level;
int cmsg_type;
};
struct ucred struct ucred
{ {
pid_t pid; pid_t pid;
......
#include <sys/socket.h> #include <sys/socket.h>
#include <limits.h> #include <limits.h>
#include <string.h>
#include <errno.h>
#include "syscall.h" #include "syscall.h"
#include "libc.h" #include "libc.h"
...@@ -7,10 +9,21 @@ ssize_t sendmsg(int fd, const struct msghdr *msg, int flags) ...@@ -7,10 +9,21 @@ ssize_t sendmsg(int fd, const struct msghdr *msg, int flags)
{ {
#if LONG_MAX > INT_MAX #if LONG_MAX > INT_MAX
struct msghdr h; struct msghdr h;
struct cmsghdr chbuf[1024/sizeof(struct cmsghdr)+1], *c;
if (msg) { if (msg) {
h = *msg; h = *msg;
h.__pad1 = h.__pad2 = 0; h.__pad1 = h.__pad2 = 0;
msg = &h; msg = &h;
if (h.msg_controllen) {
if (h.msg_controllen > 1024) {
errno = ENOMEM;
return -1;
}
memcpy(chbuf, h.msg_control, h.msg_controllen);
h.msg_control = chbuf;
for (c=CMSG_FIRSTHDR(&h); c; c=CMSG_NXTHDR(&h,c))
c->__pad1 = 0;
}
} }
#endif #endif
return socketcall_cp(sendmsg, fd, msg, flags, 0, 0, 0); return socketcall_cp(sendmsg, fd, msg, flags, 0, 0, 0);
......
Markdown is supported
0% .
You are about to add 0 people to the discussion. Proceed with caution.
先完成此消息的编辑!
想要评论请 注册