浏览代码

sunrpc: return error if unsupported enctype or cksumtype is encountered

Return an error from gss_import_sec_context_kerberos if the
negotiated context contains encryption or checksum types not
supported by the kernel code.

This fixes an Oops because success was assumed and later code found
no internal_ctx_id.

Signed-off-by: Kevin Coffman <kwc@citi.umich.edu>
Signed-off-by: Trond Myklebust <Trond.Myklebust@netapp.com>
Kevin Coffman 17 年之前
父节点
当前提交
ef338bee3f
共有 2 个文件被更改,包括 7 次插入2 次删除
  1. 6 2
      net/sunrpc/auth_gss/gss_krb5_mech.c
  2. 1 0
      net/sunrpc/auth_gss/gss_krb5_seal.c

+ 6 - 2
net/sunrpc/auth_gss/gss_krb5_mech.c

@@ -147,13 +147,17 @@ gss_import_sec_context_kerberos(const void *p,
 	p = simple_get_bytes(p, end, &tmp, sizeof(tmp));
 	p = simple_get_bytes(p, end, &tmp, sizeof(tmp));
 	if (IS_ERR(p))
 	if (IS_ERR(p))
 		goto out_err_free_ctx;
 		goto out_err_free_ctx;
-	if (tmp != SGN_ALG_DES_MAC_MD5)
+	if (tmp != SGN_ALG_DES_MAC_MD5) {
+		p = ERR_PTR(-ENOSYS);
 		goto out_err_free_ctx;
 		goto out_err_free_ctx;
+	}
 	p = simple_get_bytes(p, end, &tmp, sizeof(tmp));
 	p = simple_get_bytes(p, end, &tmp, sizeof(tmp));
 	if (IS_ERR(p))
 	if (IS_ERR(p))
 		goto out_err_free_ctx;
 		goto out_err_free_ctx;
-	if (tmp != SEAL_ALG_DES)
+	if (tmp != SEAL_ALG_DES) {
+		p = ERR_PTR(-ENOSYS);
 		goto out_err_free_ctx;
 		goto out_err_free_ctx;
+	}
 	p = simple_get_bytes(p, end, &ctx->endtime, sizeof(ctx->endtime));
 	p = simple_get_bytes(p, end, &ctx->endtime, sizeof(ctx->endtime));
 	if (IS_ERR(p))
 	if (IS_ERR(p))
 		goto out_err_free_ctx;
 		goto out_err_free_ctx;

+ 1 - 0
net/sunrpc/auth_gss/gss_krb5_seal.c

@@ -83,6 +83,7 @@ gss_get_mic_kerberos(struct gss_ctx *gss_ctx, struct xdr_buf *text,
 	u32			seq_send;
 	u32			seq_send;
 
 
 	dprintk("RPC:       gss_krb5_seal\n");
 	dprintk("RPC:       gss_krb5_seal\n");
+	BUG_ON(ctx == NULL);
 
 
 	now = get_seconds();
 	now = get_seconds();