royzah opened a new pull request, #20418: URL: https://github.com/apache/nuttx/pull/20418
Depends on #20412; its commits are included until it merges. ## Why The syscall gate checks the ioctl argument itself. Some ioctls carry a structure that holds further user pointers, which the driver then reads or writes with the kernel's rights. In a kernel build a process could point one of them at kernel memory. ## How `uaccess_ioctl` copies the outer structure into the kernel, checks each nested pointer and its length, and hands the driver the copy. | ioctl | Checked | | --- | --- | | `SIOCGIFCONF`, `SIOCGLIFCONF` | `ifc_buf` for `ifc_len` | | `MMC_IOC_CMD`, `MMC_IOC_MULTI_CMD` | each `data_ptr` for `blksz * blocks`, at least 512; at most `MMC_IOC_MAX_CMDS` | | `I2CIOC_TRANSFER` | each message buffer for its length | | `SPIIOC_TRANSFER` | each tx and rx buffer for `nwords` words of 1, 2 or 4 bytes | A pointer into kernel memory returns `EFAULT`. Flat and protected builds are unchanged. ## Tested | Where | Result | | --- | --- | | `qemu-armv8a:knsh` | `ostest` passes; `hello` | | `rv-virt:knsh64` | `hello`; `ostest` log identical to master's | | `qemu-armv8a:knsh` + NET, MMCSD, I2C_DRIVER, SPI_DRIVER | builds | | i.MX93, PX4 kernel build | see below | ``` SIOCGIFCONF into session keys: -1 errno 14, into its own buffer: 0, 56 bytes MMC_IOC_CMD into session keys: -1 errno 14, into its own buffer: -1 errno 25 Tests passed : 15 Tests failed : 0 ``` errno 25 is the driver's own `ENOTTY`: that board has `MMCSD_IOCSUPPORT` off, so the call reached it. `tools/checkpatch.sh -c -u -m -g` clean. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
