Thread (9 messages) flat view 9 messages, 2 authors, 2017-01-09

Re: [PATCH nf-next 0/7] xtables: use dedicated copy_to_user helpers

From: Pablo Neira Ayuso <pablo@netfilter.org>
Date: 2017-01-09 16:31:01
Also in: netfilter-devel

On Mon, Jan 02, 2017 at 05:19:39PM -0500, Willem de Bruijn wrote:
From: Willem de Bruijn <willemb@google.com>

xtables list and save interfaces share xt_match and xt_target state
with userspace. The kernel and userspace definitions of these structs
differ. Currently, the structs are copied wholesale, then patched up.
The match and target structs contain a kernel pointer. Type-specific
data may contain additional kernel-only state.

Introduce xt_match_to_user and xt_target_to_user helper functions to
copy only fields intended to be shared with userspace.

Introduce xt_data_to_user to do the same for type-specific state. Add
a field .usersize to xt_match and xt_target to define the range of
bytes in .matchsize that should be shared with userspace. All matches
and targets that define kernel-only data store this at the tail of
their struct.
Series applied, thanks a lot Willem!
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help