]> CyberLeo.Net >> Repos - FreeBSD/FreeBSD.git/commit
nfsclient: Copy only initialized fields in nfs_getattr()
authorMark Johnston <markj@FreeBSD.org>
Tue, 4 May 2021 12:53:57 +0000 (08:53 -0400)
committerMark Johnston <markj@FreeBSD.org>
Tue, 11 May 2021 00:28:22 +0000 (20:28 -0400)
commit2bad237ec94f701e3041c146db136f03e6c89324
treecbe466fafce45b337f808d2c4b2590a95ddb5548
parent852b394f6f607f02c3c504de3354731f44ecdc0d
nfsclient: Copy only initialized fields in nfs_getattr()

When loading attributes from the cache, the NFS client is careful to
copy only the fields that it initialized.  After fetching attributes
from the server, however, it would copy the entire vattr structure
initialized from the RPC response, so uninitialized stack bytes would
end up being copied to userspace.  In particular, va_birthtime (v2 and
v3) and va_gen (v3) had this problem.

Use a common subroutine to copy fields provided by the NFS client, and
ensure that we provide a dummy va_gen for the v3 case.

Reviewed by: rmacklem
Reported by: KMSAN
Sponsored by: The FreeBSD Foundation
Differential Revision: https://reviews.freebsd.org/D30090

(cherry picked from commit 8bde6d15d1fa9a947c2bdc5eddae36cfbb1076dc)
sys/fs/nfs/nfsport.h
sys/fs/nfsclient/nfs_clcomsubs.c
sys/fs/nfsclient/nfs_clport.c
sys/fs/nfsclient/nfs_clvnops.c