Re: [PATCH 1/2] liveupdate: fix GET_NAME ioctl argument validation
Pratyush Yadav <[email protected]> Wed, 15 Jul 2026 16:10:06 +0200
| Newsgroups | org.infradead.lists.kexec |
|---|---|
| Message-ID | <[email protected]> |
Hi, > Cc: [email protected], [email protected], [email protected] Please run ./scripts/get_maintainer.pl *.patch to get the full list of people to Cc on the patch. You missed me and linux-kernel@. On Wed, Jul 15 2026, Jackie Liu wrote: > From: Jackie Liu <[email protected]> > > LIVEUPDATE_SESSION_GET_NAME was developed in the liveupdate/next branch > while the session type validation change was carried in liveupdate-fixes. > When the conflict between the two branches was resolved, the GET_NAME > operation descriptor picked up the structure and last member from > RETRIEVE_FD. > > This makes both its known size and minimum size 16 bytes rather than 72. > Consequently, copy_struct_from_user() treats most of a normal GET_NAME > argument as unknown trailing data and rejects it with -E2BIG when any of > those bytes are nonzero. It also accepts a 16-byte argument and returns > success after copying only a truncated session name. Nit: The second line doesn't seem to be true. The get_session_name selftest tries to create a session with 21 byte name and it passes. I think it works because luo_session_get_name assumes ucmd->cmd is struct liveupdate_session_get_name and so it tries to copy the whole thing via luo_ucmd_respond(), and if the user buffer it large enough, it will work. But yeah, the -E2BIG seems like a real problem. And anyway, that's a tricky bug and I missed it completely when I reviewed the final rebased version. So thanks for fixing it. Reviewed-by: Pratyush Yadav (Google) <[email protected]> > > Use the GET_NAME structure and its name field in the descriptor. > > Link: https://lore.kernel.org/all/[email protected]/ > Assisted-by: Codex:gpt-5.6-sol > Signed-off-by: Jackie Liu <[email protected]> > --- > kernel/liveupdate/luo_session.c | 2 +- > 1 file changed, 1 insertion(+), 1 deletion(-) > > diff --git a/kernel/liveupdate/luo_session.c b/kernel/liveupdate/luo_session.c > index b79b2a488974..f38b5b18f3f8 100644 > --- a/kernel/liveupdate/luo_session.c > +++ b/kernel/liveupdate/luo_session.c > @@ -378,7 +378,7 @@ static const struct luo_ioctl_op luo_session_ioctl_ops[] = { > IOCTL_OP(LIVEUPDATE_SESSION_RETRIEVE_FD, luo_session_retrieve_fd, > struct liveupdate_session_retrieve_fd, token, LUO_IOCTL_INCOMING), > IOCTL_OP(LIVEUPDATE_SESSION_GET_NAME, luo_session_get_name, > - struct liveupdate_session_retrieve_fd, token, LUO_IOCTL_ALL), > + struct liveupdate_session_get_name, name, LUO_IOCTL_ALL), > }; > > static bool luo_ioctl_type_valid(struct luo_session *session, -- Regards, Pratyush Yadav