Alexander Bluhm wrote:
> On Sun, Aug 13, 2017 at 05:20:05PM -0400, Ted Unangst wrote:
> > - if (nmp->nm_sotype != SOCK_STREAM)
> > - panic("nfscon sotype");
> > + } else {
> > + panic("nfscon sotype");
>
> This panic can be reached from user land with a manipulated mount_nfs
> program. This happens without you diff.
here's a new version that pulls the check higher.
Index: nfs_socket.c
===================================================================
RCS file: /cvs/src/sys/nfs/nfs_socket.c,v
retrieving revision 1.123
diff -u -p -r1.123 nfs_socket.c
--- nfs_socket.c 11 Aug 2017 21:24:20 -0000 1.123
+++ nfs_socket.c 14 Aug 2017 03:01:48 -0000
@@ -240,6 +240,11 @@ nfs_connect(struct nfsmount *nmp, struct
struct sockaddr_in *sin;
struct mbuf *m;
+ if (!(nmp->nm_sotype == SOCK_DGRAM || nmp->nm_sotype == SOCK_STREAM)) {
+ error = EINVAL;
+ goto bad;
+ }
+
nmp->nm_so = NULL;
saddr = mtod(nmp->nm_nam, struct sockaddr *);
error = socreate(saddr->sa_family, &nmp->nm_so, nmp->nm_sotype,
@@ -347,13 +352,7 @@ nfs_connect(struct nfsmount *nmp, struct
sndreserve = nmp->nm_wsize + NFS_MAXPKTHDR;
rcvreserve = (max(nmp->nm_rsize, nmp->nm_readdirsize) +
NFS_MAXPKTHDR) * 2;
- } else if (nmp->nm_sotype == SOCK_SEQPACKET) {
- sndreserve = (nmp->nm_wsize + NFS_MAXPKTHDR) * 2;
- rcvreserve = (max(nmp->nm_rsize, nmp->nm_readdirsize) +
- NFS_MAXPKTHDR) * 2;
- } else {
- if (nmp->nm_sotype != SOCK_STREAM)
- panic("nfscon sotype");
+ } else if (nmp->nm_sotype == SOCK_STREAM) {
if (so->so_proto->pr_flags & PR_CONNREQUIRED) {
MGET(m, M_WAIT, MT_SOOPTS);
*mtod(m, int32_t *) = 1;
@@ -478,10 +477,7 @@ nfs_send(struct socket *so, struct mbuf
sendnam = NULL;
else
sendnam = nam;
- if (so->so_type == SOCK_SEQPACKET)
- flags = MSG_EOR;
- else
- flags = 0;
+ flags = 0;
error = sosend(so, sendnam, NULL, top, NULL, flags);
if (error) {