diff options
author | Todd Kjos <tkjos@google.com> | 2021-11-30 10:51:49 -0800 |
---|---|---|
committer | Greg Kroah-Hartman <gregkh@linuxfoundation.org> | 2021-12-03 14:29:39 +0100 |
commit | fe6b1869243f23a485a106c214bcfdc7aa0ed593 (patch) | |
tree | 907c75eaa9c532aec25c7d7e3ceb2491702bc234 /drivers/android/binder.c | |
parent | 690cfa20d02da5aca6e4c141ff34ef9529843280 (diff) | |
download | linux-stable-fe6b1869243f23a485a106c214bcfdc7aa0ed593.tar.gz linux-stable-fe6b1869243f23a485a106c214bcfdc7aa0ed593.tar.bz2 linux-stable-fe6b1869243f23a485a106c214bcfdc7aa0ed593.zip |
binder: fix handling of error during copy
If a memory copy function fails to copy the whole buffer,
a positive integar with the remaining bytes is returned.
In binder_translate_fd_array() this can result in an fd being
skipped due to the failed copy, but the loop continues
processing fds since the early return condition expects a
negative integer on error.
Fix by returning "ret > 0 ? -EINVAL : ret" to handle this case.
Fixes: bb4a2e48d510 ("binder: return errors from buffer copy functions")
Suggested-by: Dan Carpenter <dan.carpenter@oracle.com>
Acked-by: Christian Brauner <christian.brauner@ubuntu.com>
Signed-off-by: Todd Kjos <tkjos@google.com>
Link: https://lore.kernel.org/r/20211130185152.437403-2-tkjos@google.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Diffstat (limited to 'drivers/android/binder.c')
-rw-r--r-- | drivers/android/binder.c | 4 |
1 files changed, 2 insertions, 2 deletions
diff --git a/drivers/android/binder.c b/drivers/android/binder.c index 74ffb695a6c4..7cec5840cfcd 100644 --- a/drivers/android/binder.c +++ b/drivers/android/binder.c @@ -2269,8 +2269,8 @@ static int binder_translate_fd_array(struct binder_fd_array_object *fda, if (!ret) ret = binder_translate_fd(fd, offset, t, thread, in_reply_to); - if (ret < 0) - return ret; + if (ret) + return ret > 0 ? -EINVAL : ret; } return 0; } |