diff options
author | ache <ache@FreeBSD.org> | 2001-08-23 07:42:40 +0000 |
---|---|---|
committer | ache <ache@FreeBSD.org> | 2001-08-23 07:42:40 +0000 |
commit | 1905060cac646380cb34d8c69b70c28b52278798 (patch) | |
tree | a40321b4c9fc3cbca333408d363e903860701061 /sys/kern/kern_lockf.c | |
parent | 82ad2929ed2db5d8bff46224cb0984f6292b3ea9 (diff) | |
download | FreeBSD-src-1905060cac646380cb34d8c69b70c28b52278798.zip FreeBSD-src-1905060cac646380cb34d8c69b70c28b52278798.tar.gz |
Detect off_t EOVERFLOW of start/end offsets calculations for adv. lock,
as POSIX require.
Diffstat (limited to 'sys/kern/kern_lockf.c')
-rw-r--r-- | sys/kern/kern_lockf.c | 13 |
1 files changed, 12 insertions, 1 deletions
diff --git a/sys/kern/kern_lockf.c b/sys/kern/kern_lockf.c index ad3cb70..b93b541 100644 --- a/sys/kern/kern_lockf.c +++ b/sys/kern/kern_lockf.c @@ -39,6 +39,7 @@ #include "opt_debug_lockf.h" +#include <machine/limits.h> #include <sys/param.h> #include <sys/systm.h> #include <sys/kernel.h> @@ -105,6 +106,8 @@ lf_advlock(ap, head, size) off_t start, end; int error; + if (fl->l_len < 0) + return (EINVAL); /* * Convert the flock structure into a start and end. */ @@ -120,6 +123,9 @@ lf_advlock(ap, head, size) break; case SEEK_END: + /* size always >= 0 */ + if (fl->l_start > 0 && size > OFF_MAX - fl->l_start) + return (EOVERFLOW); start = size + fl->l_start; break; @@ -131,7 +137,12 @@ lf_advlock(ap, head, size) if (fl->l_len == 0) end = -1; else { - end = start + fl->l_len - 1; + off_t oadd = fl->l_len - 1; + + /* fl->l_len & start are non-negative */ + if (oadd > OFF_MAX - start) + return (EOVERFLOW); + end = start + oadd; if (end < start) return (EINVAL); } |