royzah opened a new pull request, #20418:
URL: https://github.com/apache/nuttx/pull/20418

   Depends on #20412; its commits are included until it merges.
   
   ## Why
   
   The syscall gate checks the ioctl argument itself. Some ioctls carry a 
structure that holds further user pointers, which the driver then reads or 
writes with the kernel's rights. In a kernel build a process could point one of 
them at kernel memory.
   
   ## How
   
   `uaccess_ioctl` copies the outer structure into the kernel, checks each 
nested pointer and its length, and hands the driver the copy.
   
   | ioctl | Checked |
   | --- | --- |
   | `SIOCGIFCONF`, `SIOCGLIFCONF` | `ifc_buf` for `ifc_len` |
   | `MMC_IOC_CMD`, `MMC_IOC_MULTI_CMD` | each `data_ptr` for `blksz * blocks`, 
at least 512; at most `MMC_IOC_MAX_CMDS` |
   | `I2CIOC_TRANSFER` | each message buffer for its length |
   | `SPIIOC_TRANSFER` | each tx and rx buffer for `nwords` words of 1, 2 or 4 
bytes |
   
   A pointer into kernel memory returns `EFAULT`. Flat and protected builds are 
unchanged.
   
   ## Tested
   
   | Where | Result |
   | --- | --- |
   | `qemu-armv8a:knsh` | `ostest` passes; `hello` |
   | `rv-virt:knsh64` | `hello`; `ostest` log identical to master's |
   | `qemu-armv8a:knsh` + NET, MMCSD, I2C_DRIVER, SPI_DRIVER | builds |
   | i.MX93, PX4 kernel build | see below |
   
   ```
   SIOCGIFCONF into session keys: -1 errno 14, into its own buffer: 0, 56 bytes
   MMC_IOC_CMD into session keys: -1 errno 14, into its own buffer: -1 errno 25
   Tests passed :      15
   Tests failed :      0
   ```
   
   errno 25 is the driver's own `ENOTTY`: that board has `MMCSD_IOCSUPPORT` 
off, so the call reached it.
   
   `tools/checkpatch.sh -c -u -m -g` clean.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to