From ce12075aef4cef6eef96b0f950c0be1b881c5c3a Mon Sep 17 00:00:00 2001 From: Linus Torvalds Date: Sat, 7 Jan 2017 19:14:29 +0100 Subject: [PATCH] splice: introduce FMODE_SPLICE_READ and FMODE_SPLICE_WRITE Introduce FMODE_SPLICE_READ and FMODE_SPLICE_WRITE. These modes check whether it is legal to read or write a file using splice. Both get automatically set on regular files and are not checked when a 'struct fileoperations' includes the splice_{read,write} methods. Change-Id: Ice6a3fab20bf0ac131f8d908f4bb0f7dc34bf4e3 Suggested-by: Linus Torvalds Cc: Al Viro Signed-off-by: Johannes Thumshirn CVE-2016-9576 Signed-off-by: Kevin F. Haggerty --- fs/open.c | 4 ++++ fs/splice.c | 6 ++++++ include/linux/fs.h | 5 +++++ 3 files changed, 15 insertions(+) diff --git a/fs/open.c b/fs/open.c index c80f83f88b6..3f716e9b896 100644 --- a/fs/open.c +++ b/fs/open.c @@ -691,6 +691,10 @@ static struct file *__dentry_open(struct dentry *dentry, struct vfsmount *mnt, return f; } + if (S_ISREG(inode->i_mode)) + f->f_mode |= FMODE_SPLICE_WRITE | FMODE_SPLICE_READ; + + f->f_op = fops_get(inode->i_fop); error = security_dentry_open(f, cred); diff --git a/fs/splice.c b/fs/splice.c index f61382ed61e..8011d35684e 100644 --- a/fs/splice.c +++ b/fs/splice.c @@ -379,6 +379,9 @@ __generic_file_splice_read(struct file *in, loff_t *ppos, index++; } + if (unlikely(!(in->f_mode & FMODE_SPLICE_READ))) + return -EINVAL; + /* * Now loop over the map and see if we need to start IO on any * pages, fill in the partial map, etc. @@ -1073,6 +1076,9 @@ static ssize_t default_file_splice_write(struct pipe_inode_info *pipe, { ssize_t ret; + if (unlikely(!(out->f_mode & FMODE_SPLICE_WRITE))) + return -EINVAL; + ret = splice_from_pipe(pipe, out, ppos, len, flags, write_pipe_buf); if (ret > 0) *ppos += ret; diff --git a/include/linux/fs.h b/include/linux/fs.h index d279c9b50ae..ef6e82ce1c1 100644 --- a/include/linux/fs.h +++ b/include/linux/fs.h @@ -123,6 +123,11 @@ struct inodes_stat_t { /* File was opened by fanotify and shouldn't generate fanotify events */ #define FMODE_NONOTIFY ((__force fmode_t)0x1000000) +/* File can be read using splice */ +#define FMODE_SPLICE_READ ((__force fmode_t)0x8000000) +/* File can be written using splice */ +#define FMODE_SPLICE_WRITE ((__force fmode_t)0x10000000) + /* * The below are the various read and write types that we support. Some of * them include behavioral modifiers that send information down to the