Thread (8 messages) flat view 8 messages, 4 authors, 2018-06-25

Re: [PATCH] ipv6: avoid copy_from_user() via ipv6_renew_options_kern()

From: David Miller <davem@davemloft.net>
Date: 2018-06-24 07:48:43
Also in: linux-security-module, selinux

From: Al Viro <viro@ZenIV.linux.org.uk>
Date: Sat, 23 Jun 2018 23:21:07 +0100
BTW, I wonder if the life would be simpler with do_ipv6_setsockopt() doing
the copy-in and verifying ipv6_optlen(*hdr) <= newoptlen; that would've
simplified ipv6_renew_option{,s}() quite a bit and completely eliminated
ipv6_renew_options_kern()...
I agree that this makes things a lot simpler.

One thing that drives me crazy though is this inherit stuff:
+	ipv6_renew_option(newtype == IPV6_HOPOPTS ? newopt :
+				opt ? opt->hopopt : NULL,
Why don't we pass the type into ipv6_renew_option() and have it
do this pointer dance instead?

That's going to definitely be easier to read.

I don't know enough about this code to give feedback about the
option length handling wrt. copies, sorry.
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help