Alexander Bluhm wrote:
> On Sun, Aug 13, 2017 at 05:20:05PM -0400, Ted Unangst wrote:
> > -           if (nmp->nm_sotype != SOCK_STREAM)
> > -                   panic("nfscon sotype");
> > +   } else {
> > +           panic("nfscon sotype");
> 
> This panic can be reached from user land with a manipulated mount_nfs
> program.  This happens without you diff.

here's a new version that pulls the check higher.


Index: nfs_socket.c
===================================================================
RCS file: /cvs/src/sys/nfs/nfs_socket.c,v
retrieving revision 1.123
diff -u -p -r1.123 nfs_socket.c
--- nfs_socket.c        11 Aug 2017 21:24:20 -0000      1.123
+++ nfs_socket.c        14 Aug 2017 03:01:48 -0000
@@ -240,6 +240,11 @@ nfs_connect(struct nfsmount *nmp, struct
        struct sockaddr_in *sin;
        struct mbuf *m;
 
+       if (!(nmp->nm_sotype == SOCK_DGRAM || nmp->nm_sotype == SOCK_STREAM)) {
+               error = EINVAL;
+               goto bad;
+       }
+
        nmp->nm_so = NULL;
        saddr = mtod(nmp->nm_nam, struct sockaddr *);
        error = socreate(saddr->sa_family, &nmp->nm_so, nmp->nm_sotype, 
@@ -347,13 +352,7 @@ nfs_connect(struct nfsmount *nmp, struct
                sndreserve = nmp->nm_wsize + NFS_MAXPKTHDR;
                rcvreserve = (max(nmp->nm_rsize, nmp->nm_readdirsize) +
                    NFS_MAXPKTHDR) * 2;
-       } else if (nmp->nm_sotype == SOCK_SEQPACKET) {
-               sndreserve = (nmp->nm_wsize + NFS_MAXPKTHDR) * 2;
-               rcvreserve = (max(nmp->nm_rsize, nmp->nm_readdirsize) +
-                   NFS_MAXPKTHDR) * 2;
-       } else {
-               if (nmp->nm_sotype != SOCK_STREAM)
-                       panic("nfscon sotype");
+       } else if (nmp->nm_sotype == SOCK_STREAM) {
                if (so->so_proto->pr_flags & PR_CONNREQUIRED) {
                        MGET(m, M_WAIT, MT_SOOPTS);
                        *mtod(m, int32_t *) = 1;
@@ -478,10 +477,7 @@ nfs_send(struct socket *so, struct mbuf 
                sendnam = NULL;
        else
                sendnam = nam;
-       if (so->so_type == SOCK_SEQPACKET)
-               flags = MSG_EOR;
-       else
-               flags = 0;
+       flags = 0;
 
        error = sosend(so, sendnam, NULL, top, NULL, flags);
        if (error) {

Reply via email to