Skip to content

Commit cc25eaa

Browse files
kristovschulzdavem330
authored andcommitted
net: ppp: fix creating PPP pass and active filters
Commit 568f194 ("net: ppp: use sk_unattached_filter api") inadvertently changed the logic when setting PPP pass and active filters. This applies to both the generic PPP subsystem implemented by drivers/net/ppp/ppp_generic.c and the ISDN PPP subsystem implemented by drivers/isdn/i4l/isdn_ppp.c. The original code in ppp_ioctl() (or isdn_ppp_ioctl(), resp.) handling PPPIOCSPASS and PPPIOCSACTIVE allowed to remove a pass/active filter previously set by using a filter of length zero. However, with the new code this is not possible anymore as this case is not explicitly checked for, which leads to passing NULL as a filter to sk_unattached_filter_create(). This results in returning EINVAL to the caller. Additionally, the variables ppp->pass_filter and ppp->active_filter (or is->pass_filter and is->active_filter, resp.) are not reset to NULL, although the filters they point to may have been destroyed by sk_unattached_filter_destroy(), so in this EINVAL case dangling pointers are left behind (provided the pointers were previously non-NULL). This patch corrects both problems by checking whether the filter passed is empty or non-empty, and prevents sk_unattached_filter_create() from being called in the first case. Moreover, the pointers are always reset to NULL as soon as sk_unattached_filter_destroy() returns. Signed-off-by: Christoph Schulz <develop@kristov.de> Signed-off-by: David S. Miller <davem@davemloft.net>
1 parent 858e6c3 commit cc25eaa

File tree

2 files changed

+32
-10
lines changed

2 files changed

+32
-10
lines changed

drivers/isdn/i4l/isdn_ppp.c

Lines changed: 16 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -638,9 +638,15 @@ isdn_ppp_ioctl(int min, struct file *file, unsigned int cmd, unsigned long arg)
638638
fprog.len = len;
639639
fprog.filter = code;
640640

641-
if (is->pass_filter)
641+
if (is->pass_filter) {
642642
sk_unattached_filter_destroy(is->pass_filter);
643-
err = sk_unattached_filter_create(&is->pass_filter, &fprog);
643+
is->pass_filter = NULL;
644+
}
645+
if (fprog.filter != NULL)
646+
err = sk_unattached_filter_create(&is->pass_filter,
647+
&fprog);
648+
else
649+
err = 0;
644650
kfree(code);
645651

646652
return err;
@@ -657,9 +663,15 @@ isdn_ppp_ioctl(int min, struct file *file, unsigned int cmd, unsigned long arg)
657663
fprog.len = len;
658664
fprog.filter = code;
659665

660-
if (is->active_filter)
666+
if (is->active_filter) {
661667
sk_unattached_filter_destroy(is->active_filter);
662-
err = sk_unattached_filter_create(&is->active_filter, &fprog);
668+
is->active_filter = NULL;
669+
}
670+
if (fprog.filter != NULL)
671+
err = sk_unattached_filter_create(&is->active_filter,
672+
&fprog);
673+
else
674+
err = 0;
663675
kfree(code);
664676

665677
return err;

drivers/net/ppp/ppp_generic.c

Lines changed: 16 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -757,10 +757,15 @@ static long ppp_ioctl(struct file *file, unsigned int cmd, unsigned long arg)
757757
};
758758

759759
ppp_lock(ppp);
760-
if (ppp->pass_filter)
760+
if (ppp->pass_filter) {
761761
sk_unattached_filter_destroy(ppp->pass_filter);
762-
err = sk_unattached_filter_create(&ppp->pass_filter,
763-
&fprog);
762+
ppp->pass_filter = NULL;
763+
}
764+
if (fprog.filter != NULL)
765+
err = sk_unattached_filter_create(&ppp->pass_filter,
766+
&fprog);
767+
else
768+
err = 0;
764769
kfree(code);
765770
ppp_unlock(ppp);
766771
}
@@ -778,10 +783,15 @@ static long ppp_ioctl(struct file *file, unsigned int cmd, unsigned long arg)
778783
};
779784

780785
ppp_lock(ppp);
781-
if (ppp->active_filter)
786+
if (ppp->active_filter) {
782787
sk_unattached_filter_destroy(ppp->active_filter);
783-
err = sk_unattached_filter_create(&ppp->active_filter,
784-
&fprog);
788+
ppp->active_filter = NULL;
789+
}
790+
if (fprog.filter != NULL)
791+
err = sk_unattached_filter_create(&ppp->active_filter,
792+
&fprog);
793+
else
794+
err = 0;
785795
kfree(code);
786796
ppp_unlock(ppp);
787797
}

0 commit comments

Comments
 (0)