2007-10-11 08:04:15

by Pierre Peiffer

[permalink] [raw]
Subject: [RFC][PATCH -mm] IPC: fix error checking in all new xxx_lock() functions


In the new implementation of the [sem|shm|msg]_lock[_check]() routines,
we use the return value of ipc_lock() in container_of() without any check.
But ipc_lock may return a errcode. The use of this errcode in container_of()
may alter this errcode, and we don't want this.

Today, there is no problem because the member used in these container_of()
is the first member of its container (offset == 0), the errcode isn't changed
then. But in the general case, we can't count on this assumption and this
may lead later to a real bug if we don't correct this.

In fact, the proposed solution is simple and correct. But it has the drawback
of adding one more check ('if' statement) in the chain: we do a first check in
ipc_lock(), now in xxx_lock() and then one later in the caller of xxx_lock()
That's why I send this as RFC, may be another approach could be considered.

Signed-off-by: Pierre Peiffer <[email protected]>

---
ipc/msg.c | 6 ++++++
ipc/sem.c | 6 ++++++
ipc/shm.c | 6 ++++++
3 files changed, 18 insertions(+)

Index: b/ipc/msg.c
===================================================================
--- a/ipc/msg.c
+++ b/ipc/msg.c
@@ -140,6 +140,9 @@ static inline struct msg_queue *msg_lock
{
struct kern_ipc_perm *ipcp = ipc_lock(&msg_ids(ns), id);

+ if (IS_ERR(ipcp))
+ return (struct msg_queue *)ipcp;
+
return container_of(ipcp, struct msg_queue, q_perm);
}

@@ -148,6 +151,9 @@ static inline struct msg_queue *msg_lock
{
struct kern_ipc_perm *ipcp = ipc_lock_check(&msg_ids(ns), id);

+ if (IS_ERR(ipcp))
+ return (struct msg_queue *)ipcp;
+
return container_of(ipcp, struct msg_queue, q_perm);
}

Index: b/ipc/sem.c
===================================================================
--- a/ipc/sem.c
+++ b/ipc/sem.c
@@ -178,6 +178,9 @@ static inline struct sem_array *sem_lock
{
struct kern_ipc_perm *ipcp = ipc_lock(&sem_ids(ns), id);

+ if (IS_ERR(ipcp))
+ return (struct sem_array *)ipcp;
+
return container_of(ipcp, struct sem_array, sem_perm);
}

@@ -186,6 +189,9 @@ static inline struct sem_array *sem_lock
{
struct kern_ipc_perm *ipcp = ipc_lock_check(&sem_ids(ns), id);

+ if (IS_ERR(ipcp))
+ return (struct sem_array *)ipcp;
+
return container_of(ipcp, struct sem_array, sem_perm);
}

Index: b/ipc/shm.c
===================================================================
--- a/ipc/shm.c
+++ b/ipc/shm.c
@@ -145,6 +145,9 @@ static inline struct shmid_kernel *shm_l
{
struct kern_ipc_perm *ipcp = ipc_lock(&shm_ids(ns), id);

+ if (IS_ERR(ipcp))
+ return (struct shmid_kernel *)ipcp;
+
return container_of(ipcp, struct shmid_kernel, shm_perm);
}

@@ -153,6 +156,9 @@ static inline struct shmid_kernel *shm_l
{
struct kern_ipc_perm *ipcp = ipc_lock_check(&shm_ids(ns), id);

+ if (IS_ERR(ipcp))
+ return (struct shmid_kernel *)ipcp;
+
return container_of(ipcp, struct shmid_kernel, shm_perm);
}



Pierre Peiffer


2007-10-11 08:14:10

by Nadia Derbey

[permalink] [raw]
Subject: Re: [RFC][PATCH -mm] IPC: fix error checking in all new xxx_lock() functions

Pierre Peiffer wrote:
> In the new implementation of the [sem|shm|msg]_lock[_check]() routines,
> we use the return value of ipc_lock() in container_of() without any check.
> But ipc_lock may return a errcode. The use of this errcode in container_of()
> may alter this errcode, and we don't want this.
>
> Today, there is no problem because the member used in these container_of()
> is the first member of its container (offset == 0), the errcode isn't changed
> then. But in the general case, we can't count on this assumption and this
> may lead later to a real bug if we don't correct this.
>
> In fact, the proposed solution is simple and correct. But it has the drawback
> of adding one more check ('if' statement) in the chain: we do a first check in
> ipc_lock(), now in xxx_lock() and then one later in the caller of xxx_lock()
> That's why I send this as RFC, may be another approach could be considered.
>

This is really what disturbs me this solution: the same check will be
done several times. But is true that we have to do something.
So why not simply adding a BIG COMMENT before the msg_queue, sem_array
and shmid_ds stating that the kern_ipc_perm should stay at the beinnign
of the structure?

Will try to look for another solution.

Regards,
Nadia