Re: [PATCH 01/15] ftruncate: pass a signed offset
Christian Brauner <[email protected]>
| Newsgroups | gmane.linux.ports.hexagon,gmane.linux.kernel.cross-arch,gmane.linux.kernel,gmane.linux.ports.mips,gmane.linux.ports.parisc,gmane.linux.ports.sparc,gmane.linux.ports.ppc64.devel,gmane.linux.ports.sh.devel,gmane.linux.file-systems,gmane.comp.lib.glibc.alpha,gmane.linux.lib.musl.general,gmane.linux.ltp,gmane.linux.kernel.stable |
|---|---|
| Message-ID | <20240621-jeden-hinab-e265b0d0807a@brauner> |
On Thu, Jun 20, 2024 at 06:23:02PM GMT, Arnd Bergmann wrote: > From: Arnd Bergmann <[email protected]> > > The old ftruncate() syscall, using the 32-bit off_t misses a sign > extension when called in compat mode on 64-bit architectures. As a > result, passing a negative length accidentally succeeds in truncating > to file size between 2GiB and 4GiB. > > Changing the type of the compat syscall to the signed compat_off_t > changes the behavior so it instead returns -EINVAL. > > The native entry point, the truncate() syscall and the corresponding > loff_t based variants are all correct already and do not suffer > from this mistake. > > Fixes: 3f6d078d4acc ("fix compat truncate/ftruncate") > Cc: [email protected] > Signed-off-by: Arnd Bergmann <[email protected]> > --- Looks good to me, Reviewed-by: Christian Brauner <[email protected]>