signal: fix information leak in copy_siginfo_to_user
[linux-2.6-block.git] / fs / signalfd.c
CommitLineData
fba2afaa
DL
1/*
2 * fs/signalfd.c
3 *
4 * Copyright (C) 2003 Linus Torvalds
5 *
6 * Mon Mar 5, 2007: Davide Libenzi <davidel@xmailserver.org>
7 * Changed ->read() to return a siginfo strcture instead of signal number.
8 * Fixed locking in ->poll().
9 * Added sighand-detach notification.
10 * Added fd re-use in sys_signalfd() syscall.
11 * Now using anonymous inode source.
12 * Thanks to Oleg Nesterov for useful code review and suggestions.
13 * More comments and suggestions from Arnd Bergmann.
b8fceee1 14 * Sat May 19, 2007: Davi E. M. Arnaut <davi@haxent.com.br>
b3762bfc 15 * Retrieve multiple signals with one read() call
b8fceee1
DL
16 * Sun Jul 15, 2007: Davide Libenzi <davidel@xmailserver.org>
17 * Attach to the sighand only during read() and poll().
fba2afaa
DL
18 */
19
20#include <linux/file.h>
21#include <linux/poll.h>
22#include <linux/init.h>
23#include <linux/fs.h>
24#include <linux/sched.h>
5a0e3ad6 25#include <linux/slab.h>
fba2afaa
DL
26#include <linux/kernel.h>
27#include <linux/signal.h>
28#include <linux/list.h>
29#include <linux/anon_inodes.h>
30#include <linux/signalfd.h>
7ec37dfd 31#include <linux/syscalls.h>
138d22b5 32#include <linux/proc_fs.h>
7d197ed4 33#include <linux/compat.h>
fba2afaa 34
d80e731e
ON
35void signalfd_cleanup(struct sighand_struct *sighand)
36{
37 wait_queue_head_t *wqh = &sighand->signalfd_wqh;
971316f0
ON
38 /*
39 * The lockless check can race with remove_wait_queue() in progress,
40 * but in this case its caller should run under rcu_read_lock() and
41 * sighand_cachep is SLAB_DESTROY_BY_RCU, we can safely return.
42 */
d80e731e
ON
43 if (likely(!waitqueue_active(wqh)))
44 return;
45
46 /* wait_queue_t->func(POLLFREE) should do remove_wait_queue() */
47 wake_up_poll(wqh, POLLHUP | POLLFREE);
48}
49
fba2afaa 50struct signalfd_ctx {
fba2afaa 51 sigset_t sigmask;
fba2afaa
DL
52};
53
fba2afaa
DL
54static int signalfd_release(struct inode *inode, struct file *file)
55{
b8fceee1 56 kfree(file->private_data);
fba2afaa
DL
57 return 0;
58}
59
60static unsigned int signalfd_poll(struct file *file, poll_table *wait)
61{
62 struct signalfd_ctx *ctx = file->private_data;
63 unsigned int events = 0;
fba2afaa 64
b8fceee1 65 poll_wait(file, &current->sighand->signalfd_wqh, wait);
fba2afaa 66
b8fceee1
DL
67 spin_lock_irq(&current->sighand->siglock);
68 if (next_signal(&current->pending, &ctx->sigmask) ||
69 next_signal(&current->signal->shared_pending,
70 &ctx->sigmask))
fba2afaa 71 events |= POLLIN;
b8fceee1 72 spin_unlock_irq(&current->sighand->siglock);
fba2afaa
DL
73
74 return events;
75}
76
77/*
78 * Copied from copy_siginfo_to_user() in kernel/signal.c
79 */
80static int signalfd_copyinfo(struct signalfd_siginfo __user *uinfo,
81 siginfo_t const *kinfo)
82{
83 long err;
84
85 BUILD_BUG_ON(sizeof(struct signalfd_siginfo) != 128);
86
87 /*
14e4a0f2 88 * Unused members should be zero ...
fba2afaa
DL
89 */
90 err = __clear_user(uinfo, sizeof(*uinfo));
91
92 /*
93 * If you change siginfo_t structure, please be sure
94 * this code is fixed accordingly.
95 */
96358de6
DL
96 err |= __put_user(kinfo->si_signo, &uinfo->ssi_signo);
97 err |= __put_user(kinfo->si_errno, &uinfo->ssi_errno);
98 err |= __put_user((short) kinfo->si_code, &uinfo->ssi_code);
fba2afaa
DL
99 switch (kinfo->si_code & __SI_MASK) {
100 case __SI_KILL:
96358de6
DL
101 err |= __put_user(kinfo->si_pid, &uinfo->ssi_pid);
102 err |= __put_user(kinfo->si_uid, &uinfo->ssi_uid);
fba2afaa
DL
103 break;
104 case __SI_TIMER:
96358de6
DL
105 err |= __put_user(kinfo->si_tid, &uinfo->ssi_tid);
106 err |= __put_user(kinfo->si_overrun, &uinfo->ssi_overrun);
107 err |= __put_user((long) kinfo->si_ptr, &uinfo->ssi_ptr);
a2a20c41 108 err |= __put_user(kinfo->si_int, &uinfo->ssi_int);
fba2afaa
DL
109 break;
110 case __SI_POLL:
96358de6
DL
111 err |= __put_user(kinfo->si_band, &uinfo->ssi_band);
112 err |= __put_user(kinfo->si_fd, &uinfo->ssi_fd);
fba2afaa
DL
113 break;
114 case __SI_FAULT:
96358de6 115 err |= __put_user((long) kinfo->si_addr, &uinfo->ssi_addr);
fba2afaa 116#ifdef __ARCH_SI_TRAPNO
96358de6 117 err |= __put_user(kinfo->si_trapno, &uinfo->ssi_trapno);
b8aeec34
HS
118#endif
119#ifdef BUS_MCEERR_AO
120 /*
121 * Other callers might not initialize the si_lsb field,
122 * so check explicitly for the right codes here.
123 */
124 if (kinfo->si_code == BUS_MCEERR_AR ||
125 kinfo->si_code == BUS_MCEERR_AO)
126 err |= __put_user((short) kinfo->si_addr_lsb,
127 &uinfo->ssi_addr_lsb);
fba2afaa
DL
128#endif
129 break;
130 case __SI_CHLD:
96358de6
DL
131 err |= __put_user(kinfo->si_pid, &uinfo->ssi_pid);
132 err |= __put_user(kinfo->si_uid, &uinfo->ssi_uid);
133 err |= __put_user(kinfo->si_status, &uinfo->ssi_status);
134 err |= __put_user(kinfo->si_utime, &uinfo->ssi_utime);
135 err |= __put_user(kinfo->si_stime, &uinfo->ssi_stime);
fba2afaa
DL
136 break;
137 case __SI_RT: /* This is not generated by the kernel as of now. */
138 case __SI_MESGQ: /* But this is */
96358de6
DL
139 err |= __put_user(kinfo->si_pid, &uinfo->ssi_pid);
140 err |= __put_user(kinfo->si_uid, &uinfo->ssi_uid);
141 err |= __put_user((long) kinfo->si_ptr, &uinfo->ssi_ptr);
a2a20c41 142 err |= __put_user(kinfo->si_int, &uinfo->ssi_int);
fba2afaa 143 break;
0859ab59
DL
144 default:
145 /*
146 * This case catches also the signals queued by sigqueue().
147 */
96358de6
DL
148 err |= __put_user(kinfo->si_pid, &uinfo->ssi_pid);
149 err |= __put_user(kinfo->si_uid, &uinfo->ssi_uid);
0859ab59
DL
150 err |= __put_user((long) kinfo->si_ptr, &uinfo->ssi_ptr);
151 err |= __put_user(kinfo->si_int, &uinfo->ssi_int);
fba2afaa
DL
152 break;
153 }
154
155 return err ? -EFAULT: sizeof(*uinfo);
156}
157
b3762bfc
DA
158static ssize_t signalfd_dequeue(struct signalfd_ctx *ctx, siginfo_t *info,
159 int nonblock)
160{
161 ssize_t ret;
b3762bfc
DA
162 DECLARE_WAITQUEUE(wait, current);
163
b8fceee1
DL
164 spin_lock_irq(&current->sighand->siglock);
165 ret = dequeue_signal(current, &ctx->sigmask, info);
b3762bfc
DA
166 switch (ret) {
167 case 0:
168 if (!nonblock)
169 break;
170 ret = -EAGAIN;
171 default:
b8fceee1 172 spin_unlock_irq(&current->sighand->siglock);
b3762bfc
DA
173 return ret;
174 }
175
b8fceee1 176 add_wait_queue(&current->sighand->signalfd_wqh, &wait);
b3762bfc
DA
177 for (;;) {
178 set_current_state(TASK_INTERRUPTIBLE);
b8fceee1 179 ret = dequeue_signal(current, &ctx->sigmask, info);
b3762bfc
DA
180 if (ret != 0)
181 break;
182 if (signal_pending(current)) {
183 ret = -ERESTARTSYS;
184 break;
185 }
b8fceee1 186 spin_unlock_irq(&current->sighand->siglock);
b3762bfc 187 schedule();
b8fceee1 188 spin_lock_irq(&current->sighand->siglock);
b3762bfc 189 }
b8fceee1 190 spin_unlock_irq(&current->sighand->siglock);
b3762bfc 191
b8fceee1 192 remove_wait_queue(&current->sighand->signalfd_wqh, &wait);
b3762bfc
DA
193 __set_current_state(TASK_RUNNING);
194
195 return ret;
196}
197
fba2afaa 198/*
b8fceee1
DL
199 * Returns a multiple of the size of a "struct signalfd_siginfo", or a negative
200 * error code. The "count" parameter must be at least the size of a
201 * "struct signalfd_siginfo".
fba2afaa
DL
202 */
203static ssize_t signalfd_read(struct file *file, char __user *buf, size_t count,
204 loff_t *ppos)
205{
206 struct signalfd_ctx *ctx = file->private_data;
b3762bfc
DA
207 struct signalfd_siginfo __user *siginfo;
208 int nonblock = file->f_flags & O_NONBLOCK;
209 ssize_t ret, total = 0;
fba2afaa 210 siginfo_t info;
fba2afaa 211
b3762bfc
DA
212 count /= sizeof(struct signalfd_siginfo);
213 if (!count)
fba2afaa 214 return -EINVAL;
fba2afaa 215
b3762bfc 216 siginfo = (struct signalfd_siginfo __user *) buf;
b3762bfc
DA
217 do {
218 ret = signalfd_dequeue(ctx, &info, nonblock);
219 if (unlikely(ret <= 0))
220 break;
221 ret = signalfd_copyinfo(siginfo, &info);
222 if (ret < 0)
223 break;
224 siginfo++;
225 total += ret;
226 nonblock = 1;
227 } while (--count);
228
b8fceee1 229 return total ? total: ret;
fba2afaa
DL
230}
231
138d22b5 232#ifdef CONFIG_PROC_FS
a3816ab0 233static void signalfd_show_fdinfo(struct seq_file *m, struct file *f)
138d22b5
CG
234{
235 struct signalfd_ctx *ctx = f->private_data;
236 sigset_t sigmask;
237
238 sigmask = ctx->sigmask;
239 signotset(&sigmask);
240 render_sigset_t(m, "sigmask:\t", &sigmask);
138d22b5
CG
241}
242#endif
243
fba2afaa 244static const struct file_operations signalfd_fops = {
138d22b5
CG
245#ifdef CONFIG_PROC_FS
246 .show_fdinfo = signalfd_show_fdinfo,
247#endif
fba2afaa
DL
248 .release = signalfd_release,
249 .poll = signalfd_poll,
250 .read = signalfd_read,
6038f373 251 .llseek = noop_llseek,
fba2afaa
DL
252};
253
836f92ad
HC
254SYSCALL_DEFINE4(signalfd4, int, ufd, sigset_t __user *, user_mask,
255 size_t, sizemask, int, flags)
fba2afaa 256{
fba2afaa
DL
257 sigset_t sigmask;
258 struct signalfd_ctx *ctx;
fba2afaa 259
e38b36f3
UD
260 /* Check the SFD_* constants for consistency. */
261 BUILD_BUG_ON(SFD_CLOEXEC != O_CLOEXEC);
262 BUILD_BUG_ON(SFD_NONBLOCK != O_NONBLOCK);
263
5fb5e049 264 if (flags & ~(SFD_CLOEXEC | SFD_NONBLOCK))
9deb27ba
UD
265 return -EINVAL;
266
fba2afaa
DL
267 if (sizemask != sizeof(sigset_t) ||
268 copy_from_user(&sigmask, user_mask, sizeof(sigmask)))
f50cadaa 269 return -EINVAL;
fba2afaa
DL
270 sigdelsetmask(&sigmask, sigmask(SIGKILL) | sigmask(SIGSTOP));
271 signotset(&sigmask);
272
273 if (ufd == -1) {
274 ctx = kmalloc(sizeof(*ctx), GFP_KERNEL);
275 if (!ctx)
276 return -ENOMEM;
277
fba2afaa 278 ctx->sigmask = sigmask;
fba2afaa
DL
279
280 /*
281 * When we call this, the initialization must be complete, since
282 * anon_inode_getfd() will install the fd.
283 */
7d9dbca3 284 ufd = anon_inode_getfd("[signalfd]", &signalfd_fops, ctx,
628ff7c1 285 O_RDWR | (flags & (O_CLOEXEC | O_NONBLOCK)));
2030a42c
AV
286 if (ufd < 0)
287 kfree(ctx);
fba2afaa 288 } else {
2903ff01
AV
289 struct fd f = fdget(ufd);
290 if (!f.file)
fba2afaa 291 return -EBADF;
2903ff01
AV
292 ctx = f.file->private_data;
293 if (f.file->f_op != &signalfd_fops) {
294 fdput(f);
fba2afaa
DL
295 return -EINVAL;
296 }
b8fceee1
DL
297 spin_lock_irq(&current->sighand->siglock);
298 ctx->sigmask = sigmask;
299 spin_unlock_irq(&current->sighand->siglock);
300
301 wake_up(&current->sighand->signalfd_wqh);
2903ff01 302 fdput(f);
fba2afaa
DL
303 }
304
305 return ufd;
fba2afaa 306}
9deb27ba 307
836f92ad
HC
308SYSCALL_DEFINE3(signalfd, int, ufd, sigset_t __user *, user_mask,
309 size_t, sizemask)
9deb27ba
UD
310{
311 return sys_signalfd4(ufd, user_mask, sizemask, 0);
312}
7d197ed4
AV
313
314#ifdef CONFIG_COMPAT
315COMPAT_SYSCALL_DEFINE4(signalfd4, int, ufd,
316 const compat_sigset_t __user *,sigmask,
317 compat_size_t, sigsetsize,
318 int, flags)
319{
320 compat_sigset_t ss32;
321 sigset_t tmp;
322 sigset_t __user *ksigmask;
323
324 if (sigsetsize != sizeof(compat_sigset_t))
325 return -EINVAL;
326 if (copy_from_user(&ss32, sigmask, sizeof(ss32)))
327 return -EFAULT;
328 sigset_from_compat(&tmp, &ss32);
329 ksigmask = compat_alloc_user_space(sizeof(sigset_t));
330 if (copy_to_user(ksigmask, &tmp, sizeof(sigset_t)))
331 return -EFAULT;
332
333 return sys_signalfd4(ufd, ksigmask, sizeof(sigset_t), flags);
334}
335
336COMPAT_SYSCALL_DEFINE3(signalfd, int, ufd,
337 const compat_sigset_t __user *,sigmask,
338 compat_size_t, sigsetsize)
339{
340 return compat_sys_signalfd4(ufd, sigmask, sigsetsize, 0);
341}
342#endif