]> CyberLeo.Net >> Repos - FreeBSD/FreeBSD.git/commit
nfsclient: Copy only initialized fields in nfs_getattr()
authorMark Johnston <markj@FreeBSD.org>
Tue, 4 May 2021 12:53:57 +0000 (08:53 -0400)
committerMark Johnston <markj@FreeBSD.org>
Tue, 4 May 2021 12:53:57 +0000 (08:53 -0400)
commit8bde6d15d1fa9a947c2bdc5eddae36cfbb1076dc
treeb830dbd27f47e5eb5409971f8a2f7a016b012cdf
parentee384b229dc62b2b0c9180db8c71fa99f30144cf
nfsclient: Copy only initialized fields in nfs_getattr()

When loading attributes from the cache, the NFS client is careful to
copy only the fields that it initialized.  After fetching attributes
from the server, however, it would copy the entire vattr structure
initialized from the RPC response, so uninitialized stack bytes would
end up being copied to userspace.  In particular, va_birthtime (v2 and
v3) and va_gen (v3) had this problem.

Use a common subroutine to copy fields provided by the NFS client, and
ensure that we provide a dummy va_gen for the v3 case.

Reviewed by: rmacklem
Reported by: KMSAN
MFC after: 1 week
Sponsored by: The FreeBSD Foundation
Differential Revision: https://reviews.freebsd.org/D30090
sys/fs/nfs/nfsport.h
sys/fs/nfsclient/nfs_clcomsubs.c
sys/fs/nfsclient/nfs_clport.c
sys/fs/nfsclient/nfs_clvnops.c