fix: don't allow userspace copy to read kernel memory
[lttng-modules.git] / probes / lttng-probe-user.c
1 /*
2 * lttng-probe-user.c
3 *
4 * Copyright (C) 2012 Mathieu Desnoyers <mathieu.desnoyers@efficios.com>
5 *
6 * This library is free software; you can redistribute it and/or
7 * modify it under the terms of the GNU Lesser General Public
8 * License as published by the Free Software Foundation; only
9 * version 2.1 of the License.
10 *
11 * This library is distributed in the hope that it will be useful,
12 * but WITHOUT ANY WARRANTY; without even the implied warranty of
13 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
14 * Lesser General Public License for more details.
15 *
16 * You should have received a copy of the GNU Lesser General Public
17 * License along with this library; if not, write to the Free Software
18 * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA
19 */
20
21 #include <linux/uaccess.h>
22 #include <linux/module.h>
23 #include <wrapper/uaccess.h>
24 #include <probes/lttng-probe-user.h>
25
26 /*
27 * Calculate string length. Include final null terminating character if there is
28 * one, or ends at first fault. Disabling page faults ensures that we can safely
29 * call this from pretty much any context, including those where the caller
30 * holds mmap_sem, or any lock which nests in mmap_sem.
31 */
32 long lttng_strlen_user_inatomic(const char *addr)
33 {
34 long count = 0;
35
36 if (!addr)
37 return 0;
38
39 pagefault_disable();
40 for (;;) {
41 char v;
42 unsigned long ret;
43
44 if (unlikely(!lttng_access_ok(VERIFY_READ,
45 (__force const char __user *) addr,
46 sizeof(v))))
47 break;
48 ret = __copy_from_user_inatomic(&v,
49 (__force const char __user *)(addr),
50 sizeof(v));
51 if (unlikely(ret > 0))
52 break;
53 count++;
54 if (unlikely(!v))
55 break;
56 addr++;
57 }
58 pagefault_enable();
59 return count;
60 }
61 EXPORT_SYMBOL_GPL(lttng_strlen_user_inatomic);
This page took 0.03669 seconds and 4 git commands to generate.