瀏覽代碼

[NET]: File descriptor loss while receiving SCM_RIGHTS

If more than one file descriptor was sent with an SCM_RIGHTS message,
and on the receiving end, after installing a nonzero (but not all)
file descritpors the process runs out of fds, then the already
installed fds will be lost (userspace will have no way of knowing
about them).

The following patch makes sure, that at least the already installed
fds are sent to userspace.  It doesn't solve the issue of losing file
descriptors in case of an EFAULT on the userspace buffer.

Signed-off-by: Miklos Szeredi <miklos@szeredi.hu>
Signed-off-by: David S. Miller <davem@davemloft.net>
Miklos Szeredi 18 年之前
父節點
當前提交
effee6a000
共有 2 個文件被更改,包括 2 次插入4 次删除
  1. 1 2
      net/compat.c
  2. 1 2
      net/core/scm.c

+ 1 - 2
net/compat.c

@@ -285,8 +285,7 @@ void scm_detach_fds_compat(struct msghdr *kmsg, struct scm_cookie *scm)
 
 
 	if (i > 0) {
 	if (i > 0) {
 		int cmlen = CMSG_COMPAT_LEN(i * sizeof(int));
 		int cmlen = CMSG_COMPAT_LEN(i * sizeof(int));
-		if (!err)
-			err = put_user(SOL_SOCKET, &cm->cmsg_level);
+		err = put_user(SOL_SOCKET, &cm->cmsg_level);
 		if (!err)
 		if (!err)
 			err = put_user(SCM_RIGHTS, &cm->cmsg_type);
 			err = put_user(SCM_RIGHTS, &cm->cmsg_type);
 		if (!err)
 		if (!err)

+ 1 - 2
net/core/scm.c

@@ -245,8 +245,7 @@ void scm_detach_fds(struct msghdr *msg, struct scm_cookie *scm)
 	if (i > 0)
 	if (i > 0)
 	{
 	{
 		int cmlen = CMSG_LEN(i*sizeof(int));
 		int cmlen = CMSG_LEN(i*sizeof(int));
-		if (!err)
-			err = put_user(SOL_SOCKET, &cm->cmsg_level);
+		err = put_user(SOL_SOCKET, &cm->cmsg_level);
 		if (!err)
 		if (!err)
 			err = put_user(SCM_RIGHTS, &cm->cmsg_type);
 			err = put_user(SCM_RIGHTS, &cm->cmsg_type);
 		if (!err)
 		if (!err)