mirror of
https://git.proxmox.com/git/mirror_ubuntu-kernels.git
synced 2025-11-16 20:58:38 +00:00
syzkaller found a warning in packet_getname() [0], where we try to
copy 16 bytes to sockaddr_ll.sll_addr[8].
Some devices (ip6gre, vti6, ip6tnl) have 16 bytes address expressed
by struct in6_addr. Also, Infiniband has 32 bytes as MAX_ADDR_LEN.
The write seems to overflow, but actually not since we use struct
sockaddr_storage defined in __sys_getsockname() and its size is 128
(_K_SS_MAXSIZE) bytes. Thus, we have sufficient room after sll_addr[]
as __data[].
To avoid the warning, let's add a flex array member union-ed with
sll_addr.
Another option would be to use strncpy() and limit the copied length
to sizeof(sll_addr), but it will return the partial address and break
an application that passes sockaddr_storage to getsockname().
[0]:
memcpy: detected field-spanning write (size 16) of single field "sll->sll_addr" at net/packet/af_packet.c:3604 (size 8)
WARNING: CPU: 0 PID: 255 at net/packet/af_packet.c:3604 packet_getname+0x25c/0x3a0 net/packet/af_packet.c:3604
Modules linked in:
CPU: 0 PID: 255 Comm: syz-executor750 Not tainted 6.5.0-rc1-00330-g60cc1f7d0605 #4
Hardware name: linux,dummy-virt (DT)
pstate: 60400005 (nZCv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)
pc : packet_getname+0x25c/0x3a0 net/packet/af_packet.c:3604
lr : packet_getname+0x25c/0x3a0 net/packet/af_packet.c:3604
sp : ffff800089887bc0
x29: ffff800089887bc0 x28: ffff000010f80f80 x27: 0000000000000003
x26: dfff800000000000 x25: ffff700011310f80 x24: ffff800087d55000
x23: dfff800000000000 x22: ffff800089887c2c x21: 0000000000000010
x20: ffff00000de08310 x19: ffff800089887c20 x18: ffff800086ab1630
x17: 20646c6569662065 x16: 6c676e697320666f x15: 0000000000000001
x14: 1fffe0000d56d7ca x13: 0000000000000000 x12: 0000000000000000
x11: 0000000000000000 x10: 0000000000000000 x9 : 3e60944c3da92b00
x8 : 3e60944c3da92b00 x7 : 0000000000000001 x6 : 0000000000000001
x5 : ffff8000898874f8 x4 : ffff800086ac99e0 x3 : ffff8000803f8808
x2 : 0000000000000001 x1 : 0000000100000000 x0 : 0000000000000000
Call trace:
packet_getname+0x25c/0x3a0 net/packet/af_packet.c:3604
__sys_getsockname+0x168/0x24c net/socket.c:2042
__do_sys_getsockname net/socket.c:2057 [inline]
__se_sys_getsockname net/socket.c:2054 [inline]
__arm64_sys_getsockname+0x7c/0x94 net/socket.c:2054
__invoke_syscall arch/arm64/kernel/syscall.c:38 [inline]
invoke_syscall+0x98/0x2c0 arch/arm64/kernel/syscall.c:52
el0_svc_common+0x134/0x240 arch/arm64/kernel/syscall.c:139
do_el0_svc+0x64/0x198 arch/arm64/kernel/syscall.c:188
el0_svc+0x2c/0x7c arch/arm64/kernel/entry-common.c:647
el0t_64_sync_handler+0x84/0xfc arch/arm64/kernel/entry-common.c:665
el0t_64_sync+0x190/0x194 arch/arm64/kernel/entry.S:591
Fixes: df8fc4e934 ("kbuild: Enable -fstrict-flex-arrays=3")
Reported-by: syzkaller <syzkaller@googlegroups.com>
Suggested-by: Kees Cook <keescook@chromium.org>
Signed-off-by: Kuniyuki Iwashima <kuniyu@amazon.com>
Link: https://lore.kernel.org/r/20230724213425.22920-3-kuniyu@amazon.com
Reviewed-by: Simon Horman <simon.horman@corigine.com>
Reviewed-by: Kees Cook <keescook@chromium.org>
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
324 lines
8.2 KiB
C
324 lines
8.2 KiB
C
/* SPDX-License-Identifier: GPL-2.0 WITH Linux-syscall-note */
|
|
#ifndef __LINUX_IF_PACKET_H
|
|
#define __LINUX_IF_PACKET_H
|
|
|
|
#include <asm/byteorder.h>
|
|
#include <linux/types.h>
|
|
|
|
struct sockaddr_pkt {
|
|
unsigned short spkt_family;
|
|
unsigned char spkt_device[14];
|
|
__be16 spkt_protocol;
|
|
};
|
|
|
|
struct sockaddr_ll {
|
|
unsigned short sll_family;
|
|
__be16 sll_protocol;
|
|
int sll_ifindex;
|
|
unsigned short sll_hatype;
|
|
unsigned char sll_pkttype;
|
|
unsigned char sll_halen;
|
|
union {
|
|
unsigned char sll_addr[8];
|
|
/* Actual length is in sll_halen. */
|
|
__DECLARE_FLEX_ARRAY(unsigned char, sll_addr_flex);
|
|
};
|
|
};
|
|
|
|
/* Packet types */
|
|
|
|
#define PACKET_HOST 0 /* To us */
|
|
#define PACKET_BROADCAST 1 /* To all */
|
|
#define PACKET_MULTICAST 2 /* To group */
|
|
#define PACKET_OTHERHOST 3 /* To someone else */
|
|
#define PACKET_OUTGOING 4 /* Outgoing of any type */
|
|
#define PACKET_LOOPBACK 5 /* MC/BRD frame looped back */
|
|
#define PACKET_USER 6 /* To user space */
|
|
#define PACKET_KERNEL 7 /* To kernel space */
|
|
/* Unused, PACKET_FASTROUTE and PACKET_LOOPBACK are invisible to user space */
|
|
#define PACKET_FASTROUTE 6 /* Fastrouted frame */
|
|
|
|
/* Packet socket options */
|
|
|
|
#define PACKET_ADD_MEMBERSHIP 1
|
|
#define PACKET_DROP_MEMBERSHIP 2
|
|
#define PACKET_RECV_OUTPUT 3
|
|
/* Value 4 is still used by obsolete turbo-packet. */
|
|
#define PACKET_RX_RING 5
|
|
#define PACKET_STATISTICS 6
|
|
#define PACKET_COPY_THRESH 7
|
|
#define PACKET_AUXDATA 8
|
|
#define PACKET_ORIGDEV 9
|
|
#define PACKET_VERSION 10
|
|
#define PACKET_HDRLEN 11
|
|
#define PACKET_RESERVE 12
|
|
#define PACKET_TX_RING 13
|
|
#define PACKET_LOSS 14
|
|
#define PACKET_VNET_HDR 15
|
|
#define PACKET_TX_TIMESTAMP 16
|
|
#define PACKET_TIMESTAMP 17
|
|
#define PACKET_FANOUT 18
|
|
#define PACKET_TX_HAS_OFF 19
|
|
#define PACKET_QDISC_BYPASS 20
|
|
#define PACKET_ROLLOVER_STATS 21
|
|
#define PACKET_FANOUT_DATA 22
|
|
#define PACKET_IGNORE_OUTGOING 23
|
|
#define PACKET_VNET_HDR_SZ 24
|
|
|
|
#define PACKET_FANOUT_HASH 0
|
|
#define PACKET_FANOUT_LB 1
|
|
#define PACKET_FANOUT_CPU 2
|
|
#define PACKET_FANOUT_ROLLOVER 3
|
|
#define PACKET_FANOUT_RND 4
|
|
#define PACKET_FANOUT_QM 5
|
|
#define PACKET_FANOUT_CBPF 6
|
|
#define PACKET_FANOUT_EBPF 7
|
|
#define PACKET_FANOUT_FLAG_ROLLOVER 0x1000
|
|
#define PACKET_FANOUT_FLAG_UNIQUEID 0x2000
|
|
#define PACKET_FANOUT_FLAG_IGNORE_OUTGOING 0x4000
|
|
#define PACKET_FANOUT_FLAG_DEFRAG 0x8000
|
|
|
|
struct tpacket_stats {
|
|
unsigned int tp_packets;
|
|
unsigned int tp_drops;
|
|
};
|
|
|
|
struct tpacket_stats_v3 {
|
|
unsigned int tp_packets;
|
|
unsigned int tp_drops;
|
|
unsigned int tp_freeze_q_cnt;
|
|
};
|
|
|
|
struct tpacket_rollover_stats {
|
|
__aligned_u64 tp_all;
|
|
__aligned_u64 tp_huge;
|
|
__aligned_u64 tp_failed;
|
|
};
|
|
|
|
union tpacket_stats_u {
|
|
struct tpacket_stats stats1;
|
|
struct tpacket_stats_v3 stats3;
|
|
};
|
|
|
|
struct tpacket_auxdata {
|
|
__u32 tp_status;
|
|
__u32 tp_len;
|
|
__u32 tp_snaplen;
|
|
__u16 tp_mac;
|
|
__u16 tp_net;
|
|
__u16 tp_vlan_tci;
|
|
__u16 tp_vlan_tpid;
|
|
};
|
|
|
|
/* Rx ring - header status */
|
|
#define TP_STATUS_KERNEL 0
|
|
#define TP_STATUS_USER (1 << 0)
|
|
#define TP_STATUS_COPY (1 << 1)
|
|
#define TP_STATUS_LOSING (1 << 2)
|
|
#define TP_STATUS_CSUMNOTREADY (1 << 3)
|
|
#define TP_STATUS_VLAN_VALID (1 << 4) /* auxdata has valid tp_vlan_tci */
|
|
#define TP_STATUS_BLK_TMO (1 << 5)
|
|
#define TP_STATUS_VLAN_TPID_VALID (1 << 6) /* auxdata has valid tp_vlan_tpid */
|
|
#define TP_STATUS_CSUM_VALID (1 << 7)
|
|
#define TP_STATUS_GSO_TCP (1 << 8)
|
|
|
|
/* Tx ring - header status */
|
|
#define TP_STATUS_AVAILABLE 0
|
|
#define TP_STATUS_SEND_REQUEST (1 << 0)
|
|
#define TP_STATUS_SENDING (1 << 1)
|
|
#define TP_STATUS_WRONG_FORMAT (1 << 2)
|
|
|
|
/* Rx and Tx ring - header status */
|
|
#define TP_STATUS_TS_SOFTWARE (1 << 29)
|
|
#define TP_STATUS_TS_SYS_HARDWARE (1 << 30) /* deprecated, never set */
|
|
#define TP_STATUS_TS_RAW_HARDWARE (1U << 31)
|
|
|
|
/* Rx ring - feature request bits */
|
|
#define TP_FT_REQ_FILL_RXHASH 0x1
|
|
|
|
struct tpacket_hdr {
|
|
unsigned long tp_status;
|
|
unsigned int tp_len;
|
|
unsigned int tp_snaplen;
|
|
unsigned short tp_mac;
|
|
unsigned short tp_net;
|
|
unsigned int tp_sec;
|
|
unsigned int tp_usec;
|
|
};
|
|
|
|
#define TPACKET_ALIGNMENT 16
|
|
#define TPACKET_ALIGN(x) (((x)+TPACKET_ALIGNMENT-1)&~(TPACKET_ALIGNMENT-1))
|
|
#define TPACKET_HDRLEN (TPACKET_ALIGN(sizeof(struct tpacket_hdr)) + sizeof(struct sockaddr_ll))
|
|
|
|
struct tpacket2_hdr {
|
|
__u32 tp_status;
|
|
__u32 tp_len;
|
|
__u32 tp_snaplen;
|
|
__u16 tp_mac;
|
|
__u16 tp_net;
|
|
__u32 tp_sec;
|
|
__u32 tp_nsec;
|
|
__u16 tp_vlan_tci;
|
|
__u16 tp_vlan_tpid;
|
|
__u8 tp_padding[4];
|
|
};
|
|
|
|
struct tpacket_hdr_variant1 {
|
|
__u32 tp_rxhash;
|
|
__u32 tp_vlan_tci;
|
|
__u16 tp_vlan_tpid;
|
|
__u16 tp_padding;
|
|
};
|
|
|
|
struct tpacket3_hdr {
|
|
__u32 tp_next_offset;
|
|
__u32 tp_sec;
|
|
__u32 tp_nsec;
|
|
__u32 tp_snaplen;
|
|
__u32 tp_len;
|
|
__u32 tp_status;
|
|
__u16 tp_mac;
|
|
__u16 tp_net;
|
|
/* pkt_hdr variants */
|
|
union {
|
|
struct tpacket_hdr_variant1 hv1;
|
|
};
|
|
__u8 tp_padding[8];
|
|
};
|
|
|
|
struct tpacket_bd_ts {
|
|
unsigned int ts_sec;
|
|
union {
|
|
unsigned int ts_usec;
|
|
unsigned int ts_nsec;
|
|
};
|
|
};
|
|
|
|
struct tpacket_hdr_v1 {
|
|
__u32 block_status;
|
|
__u32 num_pkts;
|
|
__u32 offset_to_first_pkt;
|
|
|
|
/* Number of valid bytes (including padding)
|
|
* blk_len <= tp_block_size
|
|
*/
|
|
__u32 blk_len;
|
|
|
|
/*
|
|
* Quite a few uses of sequence number:
|
|
* 1. Make sure cache flush etc worked.
|
|
* Well, one can argue - why not use the increasing ts below?
|
|
* But look at 2. below first.
|
|
* 2. When you pass around blocks to other user space decoders,
|
|
* you can see which blk[s] is[are] outstanding etc.
|
|
* 3. Validate kernel code.
|
|
*/
|
|
__aligned_u64 seq_num;
|
|
|
|
/*
|
|
* ts_last_pkt:
|
|
*
|
|
* Case 1. Block has 'N'(N >=1) packets and TMO'd(timed out)
|
|
* ts_last_pkt == 'time-stamp of last packet' and NOT the
|
|
* time when the timer fired and the block was closed.
|
|
* By providing the ts of the last packet we can absolutely
|
|
* guarantee that time-stamp wise, the first packet in the
|
|
* next block will never precede the last packet of the
|
|
* previous block.
|
|
* Case 2. Block has zero packets and TMO'd
|
|
* ts_last_pkt = time when the timer fired and the block
|
|
* was closed.
|
|
* Case 3. Block has 'N' packets and NO TMO.
|
|
* ts_last_pkt = time-stamp of the last pkt in the block.
|
|
*
|
|
* ts_first_pkt:
|
|
* Is always the time-stamp when the block was opened.
|
|
* Case a) ZERO packets
|
|
* No packets to deal with but atleast you know the
|
|
* time-interval of this block.
|
|
* Case b) Non-zero packets
|
|
* Use the ts of the first packet in the block.
|
|
*
|
|
*/
|
|
struct tpacket_bd_ts ts_first_pkt, ts_last_pkt;
|
|
};
|
|
|
|
union tpacket_bd_header_u {
|
|
struct tpacket_hdr_v1 bh1;
|
|
};
|
|
|
|
struct tpacket_block_desc {
|
|
__u32 version;
|
|
__u32 offset_to_priv;
|
|
union tpacket_bd_header_u hdr;
|
|
};
|
|
|
|
#define TPACKET2_HDRLEN (TPACKET_ALIGN(sizeof(struct tpacket2_hdr)) + sizeof(struct sockaddr_ll))
|
|
#define TPACKET3_HDRLEN (TPACKET_ALIGN(sizeof(struct tpacket3_hdr)) + sizeof(struct sockaddr_ll))
|
|
|
|
enum tpacket_versions {
|
|
TPACKET_V1,
|
|
TPACKET_V2,
|
|
TPACKET_V3
|
|
};
|
|
|
|
/*
|
|
Frame structure:
|
|
|
|
- Start. Frame must be aligned to TPACKET_ALIGNMENT=16
|
|
- struct tpacket_hdr
|
|
- pad to TPACKET_ALIGNMENT=16
|
|
- struct sockaddr_ll
|
|
- Gap, chosen so that packet data (Start+tp_net) alignes to TPACKET_ALIGNMENT=16
|
|
- Start+tp_mac: [ Optional MAC header ]
|
|
- Start+tp_net: Packet data, aligned to TPACKET_ALIGNMENT=16.
|
|
- Pad to align to TPACKET_ALIGNMENT=16
|
|
*/
|
|
|
|
struct tpacket_req {
|
|
unsigned int tp_block_size; /* Minimal size of contiguous block */
|
|
unsigned int tp_block_nr; /* Number of blocks */
|
|
unsigned int tp_frame_size; /* Size of frame */
|
|
unsigned int tp_frame_nr; /* Total number of frames */
|
|
};
|
|
|
|
struct tpacket_req3 {
|
|
unsigned int tp_block_size; /* Minimal size of contiguous block */
|
|
unsigned int tp_block_nr; /* Number of blocks */
|
|
unsigned int tp_frame_size; /* Size of frame */
|
|
unsigned int tp_frame_nr; /* Total number of frames */
|
|
unsigned int tp_retire_blk_tov; /* timeout in msecs */
|
|
unsigned int tp_sizeof_priv; /* offset to private data area */
|
|
unsigned int tp_feature_req_word;
|
|
};
|
|
|
|
union tpacket_req_u {
|
|
struct tpacket_req req;
|
|
struct tpacket_req3 req3;
|
|
};
|
|
|
|
struct packet_mreq {
|
|
int mr_ifindex;
|
|
unsigned short mr_type;
|
|
unsigned short mr_alen;
|
|
unsigned char mr_address[8];
|
|
};
|
|
|
|
struct fanout_args {
|
|
#if defined(__LITTLE_ENDIAN_BITFIELD)
|
|
__u16 id;
|
|
__u16 type_flags;
|
|
#else
|
|
__u16 type_flags;
|
|
__u16 id;
|
|
#endif
|
|
__u32 max_num_members;
|
|
};
|
|
|
|
#define PACKET_MR_MULTICAST 0
|
|
#define PACKET_MR_PROMISC 1
|
|
#define PACKET_MR_ALLMULTI 2
|
|
#define PACKET_MR_UNICAST 3
|
|
|
|
#endif
|