Thread (27 messages) 27 messages, 5 authors, 2016-01-12

[RESEND v4 2/6] remoteproc: debugfs: Add ability to boot remote processor using debugfs

From: Bjorn Andersson <hidden>
Date: 2015-12-28 18:38:09
Also in: linux-devicetree, lkml

On Fri, Dec 4, 2015 at 12:24 AM, Lee Jones [off-list ref] wrote:
On Thu, 03 Dec 2015, Arnd Bergmann wrote:
quoted
On Thursday 03 December 2015 17:28:30 Lee Jones wrote:
quoted
quoted
Ah, interesting. I haven't tried myself, and just tried to read the
code. Maybe glibc already catches zero-length writes before it gets
into the kernel, or I just missed the part of the syscall that checks
for this.
Glibc is responsible indeed:

  http://osxr.org/glibc/source/io/write.c
Ok, so an attacker can force the stack overflow by calling
syscall(__NR_write, fd, p, 0) if that has any potential value,
but normal users won't hit this case.
Right.  I have fixed the issue (and another one I found) anyway, if
only to rid the GCC warning.
Sorry, but I'm unable to find a new version of this patch, did I miss
it or could you resend it?


Also, as I looked at this again, we should probably return an error if
count >= sizeof(buf) rather than just acknowledging the input (same in
the other debugfs write function in this file).

Regards,
Bjorn
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help