HardenedBSD src tree
Go to file
John Baldwin 8ce99bb405 Properly do a deep copy of the ioctls capability array for fget_cap().
fget_cap() tries to do a cheaper snapshot of a file descriptor without
holding the file descriptor lock.  This snapshot does not do a deep
copy of the ioctls capability array, but instead uses a different
return value to inform the caller to retry the copy with the lock
held.  However, filecaps_copy() was returning 1 to indicate that a
retry was required, and fget_cap() was checking for 0 (actually
'!filecaps_copy()').  As a result, fget_cap() did not do a deep copy
of the ioctls array and just reused the original pointer.  This cause
multiple file descriptor entries to think they owned the same pointer
and eventually resulted in duplicate frees.

The only code path that I'm aware of that triggers this is to create a
listen socket that has a restricted list of ioctls and then call
accept() which calls fget_cap() with a valid filecaps structure from
getsock_cap().

To fix, change the return value of filecaps_copy() to return true if
it succeeds in copying the caps and false if it fails because the lock
is required.  I find this more intuitive than fixing the caller in
this case.  While here, change the return type from 'int' to 'bool'.

Finally, make filecaps_copy() more robust in the failure case by not
copying any of the source filecaps structure over.  This avoids the
possibility of leaking a pointer into a structure if a similar future
caller doesn't properly handle the return value from filecaps_copy()
at the expense of one more branch.

I also added a test case that panics before this change and now passes.

Reviewed by:	kib
Discussed with:	mjg (not a fan of the extra branch)
MFC after:	1 week
Differential Revision:	https://reviews.freebsd.org/D15047
2018-04-17 18:07:40 +00:00
bin expr(1): Fix overflow detection when operand is INTMAX_MIN 2018-04-14 04:35:10 +00:00
cddl MFV man pages update from r329502: 7614 zfs device evacuation/removal. 2018-04-17 02:33:54 +00:00
contrib Don't put multiple names on a single .Nm line. This fixes apropos(1) 2018-04-17 09:05:46 +00:00
crypto Merge OpenSSL 1.0.2o. 2018-03-27 17:17:58 +00:00
etc Properly do a deep copy of the ioctls capability array for fget_cap(). 2018-04-17 18:07:40 +00:00
gnu i386 4/4G split. 2018-04-13 20:30:49 +00:00
include pthread.h: minor indentation cleanups. 2018-04-04 15:16:04 +00:00
kerberos5
lib libmd: Remove trailing whitespace from mdXhl.c 2018-04-17 17:23:47 +00:00
libexec tftpd: misc Coverity cleanup in the tests 2018-03-22 14:51:05 +00:00
release switch i386 memstick installer images to MBR 2018-04-12 19:00:22 +00:00
rescue
sbin Make lagg creation more fault tolerant 2018-04-17 12:54:58 +00:00
secure Merge OpenSSL 1.0.2o. 2018-03-27 17:17:58 +00:00
share Remove the unused fuwintr() and suiwintr() functions. 2018-04-17 18:04:28 +00:00
stand Regenerate FAT templates after r332561 2018-04-16 15:13:18 +00:00
sys Properly do a deep copy of the ioctls capability array for fget_cap(). 2018-04-17 18:07:40 +00:00
targets Add kernel and userspace code to dump the firmware state of supported 2018-03-08 15:21:56 +00:00
tests Properly do a deep copy of the ioctls capability array for fget_cap(). 2018-04-17 18:07:40 +00:00
tools Add (intmax_t) type casts to some printf parameters to keep i386 happy. 2018-04-08 07:18:29 +00:00
usr.bin quota(1): Fix calculation overflow and underflow 2018-04-16 19:33:04 +00:00
usr.sbin mountd: fix a crash when getgrouplist reports too many groups 2018-04-16 09:17:36 +00:00
.arcconfig
.arclint
.gitattributes
.gitignore
COPYRIGHT
LOCKS
MAINTAINERS MAINTAINERS: add myself for Allwinner and 64bits RockChip 2018-02-26 21:50:13 +00:00
Makefile Don't read SRC_ENV_CONF for MAKEOBJDIRPREFIX guard. 2018-03-03 23:23:23 +00:00
Makefile.inc1 Allow -DNO_CLEAN builds across r332443. 2018-04-12 18:24:00 +00:00
Makefile.libcompat
Makefile.sys.inc
ObsoleteFiles.inc Remove the unused fuwintr() and suiwintr() functions. 2018-04-17 18:04:28 +00:00
README
README.md Fix README.md formatting. 2018-03-02 14:42:08 +00:00
UPDATING Remove support for the Arcnet protocol. 2018-04-13 21:18:04 +00:00

FreeBSD Source:

This is the top level of the FreeBSD source directory. This file was last revised on: FreeBSD

For copyright information, please see the file COPYRIGHT in this directory (additional copyright information also exists for some sources in this tree - please see the specific source directories for more information).

The Makefile in this directory supports a number of targets for building components (or all) of the FreeBSD source tree. See build(7) and https://www.freebsd.org/doc/en_US.ISO8859-1/books/handbook/makeworld.html for more information, including setting make(1) variables.

The buildkernel and installkernel targets build and install the kernel and the modules (see below). Please see the top of the Makefile in this directory for more information on the standard build targets and compile-time flags.

Building a kernel is a somewhat more involved process. See build(7), config(8), and https://www.freebsd.org/doc/en_US.ISO8859-1/books/handbook/kernelconfig.html for more information.

Note: If you want to build and install the kernel with the buildkernel and installkernel targets, you might need to build world before. More information is available in the handbook.

The kernel configuration files reside in the sys/<arch>/conf sub-directory. GENERIC is the default configuration used in release builds. NOTES contains entries and documentation for all possible devices, not just those commonly used.

Source Roadmap:

bin		System/user commands.

cddl		Various commands and libraries under the Common Development
		and Distribution License.

contrib		Packages contributed by 3rd parties.

crypto		Cryptography stuff (see crypto/README).

etc		Template files for /etc.

gnu		Various commands and libraries under the GNU Public License.
		Please see gnu/COPYING* for more information.

include		System include files.

kerberos5	Kerberos5 (Heimdal) package.

lib		System libraries.

libexec		System daemons.

release		Release building Makefile & associated tools.

rescue		Build system for statically linked /rescue utilities.

sbin		System commands.

secure		Cryptographic libraries and commands.

share		Shared resources.

stand		Boot loader sources.

sys		Kernel sources.

tests		Regression tests which can be run by Kyua.  See tests/README
		for additional information.

tools		Utilities for regression testing and miscellaneous tasks.

usr.bin		User commands.

usr.sbin	System administration commands.

For information on synchronizing your source tree with one or more of the FreeBSD Project's development branches, please see:

https://www.freebsd.org/doc/en_US.ISO8859-1/books/handbook/current-stable.html