From nobody Thu Oct 30 00:20:55 2025 Delivered-To: importer@patchew.org Received-SPF: pass (zoho.com: domain of gnu.org designates 208.118.235.17 as permitted sender) client-ip=208.118.235.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists.gnu.org; Authentication-Results: mx.zohomail.com; dkim=fail; spf=pass (zoho.com: domain of gnu.org designates 208.118.235.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists.gnu.org (lists.gnu.org [208.118.235.17]) by mx.zohomail.com with SMTPS id 1500922798231567.4289818705774; Mon, 24 Jul 2017 11:59:58 -0700 (PDT) Received: from localhost ([::1]:56493 helo=lists.gnu.org) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1dZiaB-0001J0-Ne for importer@patchew.org; Mon, 24 Jul 2017 14:59:55 -0400 Received: from eggs.gnu.org ([2001:4830:134:3::10]:50789) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1dZi6m-00016u-1Y for qemu-devel@nongnu.org; Mon, 24 Jul 2017 14:29:33 -0400 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1dZi6l-0005hu-4a for qemu-devel@nongnu.org; Mon, 24 Jul 2017 14:29:32 -0400 Received: from mail-qk0-x243.google.com ([2607:f8b0:400d:c09::243]:37863) by eggs.gnu.org with esmtps (TLS1.0:RSA_AES_128_CBC_SHA1:16) (Exim 4.71) (envelope-from ) id 1dZi6l-0005hj-0t for qemu-devel@nongnu.org; Mon, 24 Jul 2017 14:29:31 -0400 Received: by mail-qk0-x243.google.com with SMTP id q130so10666159qka.4 for ; Mon, 24 Jul 2017 11:29:30 -0700 (PDT) Received: from yoga.offpageads.com ([138.117.48.223]) by smtp.gmail.com with ESMTPSA id t57sm9033799qtt.18.2017.07.24.11.29.28 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Mon, 24 Jul 2017 11:29:30 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=sender:from:to:cc:subject:date:message-id:in-reply-to:references :mime-version:content-transfer-encoding; bh=KaUgENye2EGjniRWSXD17NdzKeuegYgR5zw6McFyH4o=; b=iNOhI7fmGEwdXfGjL/ZMuF4BPqfo7gUyGh+hegcBlUujU9c0m3CsddKefIpt0rGvqh VBYTJg7Sw3lX/eGpUWb/nUsCkqrfQoK+PF1KdSqwBjhATXdG17GQ5ny/Q6KrWfvyt9uX zx8kzolEr34S2b80iF/671k9peT56xzjRDL/gCaTMgiYg3YHupWQEtZ/bj3xdwdzlBJn /cemSjWJ5AIodcPPQAwiwLSuC9oCHFiB/d5ASuoIFVGyK5oAbkVLt63X6ebNbY+SBG/u CQgc3ebIuTZD0lsTlPm7O5BnZiQtOIVHifMdG2Pomudr2nHlOaiyFbibYUaZSCP12DG8 guwg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:sender:from:to:cc:subject:date:message-id :in-reply-to:references:mime-version:content-transfer-encoding; bh=KaUgENye2EGjniRWSXD17NdzKeuegYgR5zw6McFyH4o=; b=Q6MCgXN/e3xzYz2rK86NnOYR9vLX2/P/qlkpqraLgCV8F1FHN80xeOw7bQEcqQPhcd AgdFx70FC3xUKg5YywU53etCsCJ2HkoVZHmhbBchGUnj5ho9oKo+AxQCdO+sFMAUQVkp XRUCvdaiwIApClHXgVFjodtXs9C7ViCJYGBuQQKIqStCmsimrzx6U3i0gaoTYNcrPhlA 8TcUigCKUDbJhsOgnC5Pj2KwatU8A1d5SBCOdRo55xZ1f0DZF1NFO8WsjlDXkzWBX83r G6Ew4qaOQpOr2ml74QWyRm0XFRCiKASA/eKnbi7UHEll6CuZ7uXCONBXGc1oeoDHmb6L XUrg== X-Gm-Message-State: AIVw112UkdUxyFtuPrkxS+NeQgK7n8ehMfgJwyTUukTb1MzIRl+z3syx djDWhyPHsjw7raNsFNi4LQ== X-Received: by 10.55.38.83 with SMTP id y80mr488936qkg.113.1500920970583; Mon, 24 Jul 2017 11:29:30 -0700 (PDT) From: =?UTF-8?q?Philippe=20Mathieu-Daud=C3=A9?= To: Eric Blake , =?UTF-8?q?Marc-Andr=C3=A9=20Lureau?= , Riku Voipio , Laurent Vivier Date: Mon, 24 Jul 2017 15:27:44 -0300 Message-Id: <20170724182751.18261-29-f4bug@amsat.org> X-Mailer: git-send-email 2.13.3 In-Reply-To: <20170724182751.18261-1-f4bug@amsat.org> References: <20170724182751.18261-1-f4bug@amsat.org> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable X-detected-operating-system: by eggs.gnu.org: Genre and OS details not recognized. X-Received-From: 2607:f8b0:400d:c09::243 Subject: [Qemu-devel] [PATCH for 2.10 28/35] syscall: check dup/dup2/dup3() errors, return EBADFD/EINVAL if required X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.21 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Cc: =?UTF-8?q?Philippe=20Mathieu-Daud=C3=A9?= , qemu-devel@nongnu.org Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: "Qemu-devel" X-ZohoMail-DKIM: fail (Header signature does not verify) X-ZohoMail: RDKM_2 RSF_0 Z_629925259 SPT_0 Linux dup(2) manpage: ERRORS EBADF newfd is out of the allowed range for file descriptors (like negative) EINVAL (dup3()) oldfd was equal to newfd Reported-by: Clang Static Analyzer Signed-off-by: Philippe Mathieu-Daud=C3=A9 --- linux-user/syscall.c | 32 +++++++++++++++++++++++--------- 1 file changed, 23 insertions(+), 9 deletions(-) diff --git a/linux-user/syscall.c b/linux-user/syscall.c index e79b5baec4..637270a02d 100644 --- a/linux-user/syscall.c +++ b/linux-user/syscall.c @@ -8336,9 +8336,13 @@ abi_long do_syscall(void *cpu_env, int num, abi_long= arg1, break; #endif case TARGET_NR_dup: - ret =3D get_errno(dup(arg1)); - if (ret >=3D 0) { - fd_trans_dup(arg1, ret); + if (arg1 < 0) { + ret =3D -TARGET_EBADFD; + } else { + ret =3D get_errno(dup(arg1)); + if (ret >=3D 0) { + fd_trans_dup(arg1, ret); + } } break; #ifdef TARGET_NR_pipe @@ -8436,17 +8440,27 @@ abi_long do_syscall(void *cpu_env, int num, abi_lon= g arg1, #endif #ifdef TARGET_NR_dup2 case TARGET_NR_dup2: - ret =3D get_errno(dup2(arg1, arg2)); - if (ret >=3D 0) { - fd_trans_dup(arg1, arg2); + if (arg1 < 0 || arg2 < 0) { + ret =3D -TARGET_EBADFD; + } else { + ret =3D get_errno(dup2(arg1, arg2)); + if (ret >=3D 0) { + fd_trans_dup(arg1, arg2); + } } break; #endif #if defined(CONFIG_DUP3) && defined(TARGET_NR_dup3) case TARGET_NR_dup3: - ret =3D get_errno(dup3(arg1, arg2, arg3)); - if (ret >=3D 0) { - fd_trans_dup(arg1, arg2); + if (arg1 < 0 || arg2 < 0) { + ret =3D -TARGET_EBADFD; + } else if (arg1 =3D=3D arg2) { + ret =3D -TARGET_EINVAL; + } else { + ret =3D get_errno(dup3(arg1, arg2, arg3)); + if (ret >=3D 0) { + fd_trans_dup(arg1, arg2); + } } break; #endif --=20 2.13.3