From 9af28a4d1313ffb1f5ef57a352ba77070b0977e1 Mon Sep 17 00:00:00 2001 From: "Dmitry V. Levin" Date: Sat, 24 Dec 2016 16:23:45 +0000 Subject: [PATCH] Fix decoding of sethostname syscall The second argument of sethostname syscall is not an unsigned long but unsigned int. The kernel does not look at the string argument when the length argument is too long. * hostname.c [HAVE_LINUX_UTSNAME_H]: Include . [!__NEW_UTS_LEN] (__NEW_UTS_LEN): Define. (SYS_FUNC(sethostname)): Treat the second argument as unsigned int. Print the first argument as a pointer when the second argument exceeds __NEW_UTS_LEN. * tests/sethostname.c [HAVE_LINUX_UTSNAME_H]: Include . [!__NEW_UTS_LEN] (__NEW_UTS_LEN): Define. (main): Use it. Check that the second argument of sethostname is handled as unsigned int. Check that the first argument is printed as a pointer when the second argument exceeds __NEW_UTS_LEN. --- hostname.c | 19 ++++++++++++-- tests/sethostname.c | 61 ++++++++++++++++++++++++++++++++++++++++++--- 2 files changed, 75 insertions(+), 5 deletions(-) diff --git a/hostname.c b/hostname.c index cc66f3ff..394fdf60 100644 --- a/hostname.c +++ b/hostname.c @@ -1,9 +1,24 @@ #include "defs.h" +#ifdef HAVE_LINUX_UTSNAME_H +# include +#endif + +#ifndef __NEW_UTS_LEN +# define __NEW_UTS_LEN 64 +#endif + SYS_FUNC(sethostname) { - printstrn(tcp, tcp->u_arg[0], tcp->u_arg[1]); - tprintf(", %lu", tcp->u_arg[1]); + unsigned int len = tcp->u_arg[1]; + + if (len > __NEW_UTS_LEN) { + printaddr(tcp->u_arg[0]); + } else { + printstrn(tcp, tcp->u_arg[0], len); + } + + tprintf(", %u", len); return RVAL_DECODED; } diff --git a/tests/sethostname.c b/tests/sethostname.c index dfa9d1a6..e1b2f069 100644 --- a/tests/sethostname.c +++ b/tests/sethostname.c @@ -1,3 +1,33 @@ +/* + * Check decoding of sethostname syscall. + * + * Copyright (c) 2016 Fei Jie + * Copyright (c) 2016 Dmitry V. Levin + * All rights reserved. + * + * Redistribution and use in source and binary forms, with or without + * modification, are permitted provided that the following conditions + * are met: + * 1. Redistributions of source code must retain the above copyright + * notice, this list of conditions and the following disclaimer. + * 2. Redistributions in binary form must reproduce the above copyright + * notice, this list of conditions and the following disclaimer in the + * documentation and/or other materials provided with the distribution. + * 3. The name of the author may not be used to endorse or promote products + * derived from this software without specific prior written permission. + * + * THIS SOFTWARE IS PROVIDED BY THE AUTHOR ``AS IS'' AND ANY EXPRESS OR + * IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES + * OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED. + * IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY DIRECT, INDIRECT, + * INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT + * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, + * DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY + * THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT + * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF + * THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. + */ + #include "tests.h" #include @@ -6,12 +36,37 @@ # include # include +#ifdef HAVE_LINUX_UTSNAME_H +# include +#endif + +#ifndef __NEW_UTS_LEN +# define __NEW_UTS_LEN 64 +#endif + int main(void) { - long rc = syscall(__NR_sethostname, 0, 63); - printf("sethostname(NULL, 63) = %ld %s (%m)\n", - rc, errno2name()); + kernel_ulong_t len; + long rc; + + len = __NEW_UTS_LEN; + rc = syscall(__NR_sethostname, 0, len); + printf("sethostname(NULL, %u) = %s\n", + (unsigned) len, sprintrc(rc)); + + if (F8ILL_KULONG_MASK) { + len |= F8ILL_KULONG_MASK; + rc = syscall(__NR_sethostname, 0, len); + printf("sethostname(NULL, %u) = %s\n", + (unsigned) len, sprintrc(rc)); + } + + len = __NEW_UTS_LEN + 1; + void *const p = tail_alloc(len); + rc = syscall(__NR_sethostname, p, len); + printf("sethostname(%p, %u) = %s\n", + p, (unsigned) len, sprintrc(rc)); puts("+++ exited with 0 +++"); return 0;