Thread (3 messages) 3 messages, 3 authors, 2022-09-30

Re: [PATCH] net: sched: cls_u32: Avoid memcpy() false-positive warning

From: Jamal Hadi Salim <jhs@mojatatu.com>
Date: 2022-09-29 10:19:32
Also in: linux-hardening, lkml

On Tue, Sep 27, 2022 at 11:37 AM Kees Cook [off-list ref] wrote:
To work around a misbehavior of the compiler's ability to see into
composite flexible array structs (as detailed in the coming memcpy()
hardening series[1]), use unsafe_memcpy(), as the sizing,
bounds-checking, and allocation are all very tightly coupled here.
This silences the false-positive reported by syzbot:

  memcpy: detected field-spanning write (size 80) of single field "&n->sel" at net/sched/cls_u32.c:1043 (size 16)

[1] https://lore.kernel.org/linux-hardening/20220901065914.1417829-2-keescook@chromium.org (local)

Cc: Jamal Hadi Salim <jhs@mojatatu.com>
Cc: Eric Dumazet <redacted>
Cc: Cong Wang <redacted>
Cc: Jiri Pirko <jiri@resnulli.us>
Cc: "David S. Miller" <davem@davemloft.net>
Cc: Jakub Kicinski <kuba@kernel.org>
Cc: Paolo Abeni <pabeni@redhat.com>
Cc: netdev@vger.kernel.org
Reported-by: syzbot+a2c4601efc75848ba321@syzkaller.appspotmail.com
Link: https://lore.kernel.org/lkml/000000000000a96c0b05e97f0444@google.com/ (local)
Signed-off-by: Kees Cook <redacted>
Reviewed-by: Jamal Hadi Salim <jhs@mojatatu.com>

cheers,
jamal
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help