blob: 54d972d4befc8e569c117d0785f677058046c653 [file] [log] [blame]
Kees Cook5287b072020-10-02 10:38:16 -07001// SPDX-License-Identifier: GPL-2.0-only
2#include <linux/fs.h>
3#include <linux/fs_struct.h>
4#include <linux/kernel_read_file.h>
5#include <linux/security.h>
6#include <linux/vmalloc.h>
7
8int kernel_read_file(struct file *file, void **buf, loff_t *size,
9 loff_t max_size, enum kernel_read_file_id id)
10{
11 loff_t i_size, pos;
12 ssize_t bytes = 0;
13 void *allocated = NULL;
14 int ret;
15
16 if (!S_ISREG(file_inode(file)->i_mode) || max_size < 0)
17 return -EINVAL;
18
19 ret = deny_write_access(file);
20 if (ret)
21 return ret;
22
23 ret = security_kernel_read_file(file, id);
24 if (ret)
25 goto out;
26
27 i_size = i_size_read(file_inode(file));
28 if (i_size <= 0) {
29 ret = -EINVAL;
30 goto out;
31 }
32 if (i_size > SIZE_MAX || (max_size > 0 && i_size > max_size)) {
33 ret = -EFBIG;
34 goto out;
35 }
36
37 if (!*buf)
38 *buf = allocated = vmalloc(i_size);
39 if (!*buf) {
40 ret = -ENOMEM;
41 goto out;
42 }
43
44 pos = 0;
45 while (pos < i_size) {
46 bytes = kernel_read(file, *buf + pos, i_size - pos, &pos);
47 if (bytes < 0) {
48 ret = bytes;
49 goto out_free;
50 }
51
52 if (bytes == 0)
53 break;
54 }
55
56 if (pos != i_size) {
57 ret = -EIO;
58 goto out_free;
59 }
60
61 ret = security_kernel_post_read_file(file, *buf, i_size, id);
62 if (!ret)
63 *size = pos;
64
65out_free:
66 if (ret < 0) {
67 if (allocated) {
68 vfree(*buf);
69 *buf = NULL;
70 }
71 }
72
73out:
74 allow_write_access(file);
75 return ret;
76}
77EXPORT_SYMBOL_GPL(kernel_read_file);
78
79int kernel_read_file_from_path(const char *path, void **buf, loff_t *size,
80 loff_t max_size, enum kernel_read_file_id id)
81{
82 struct file *file;
83 int ret;
84
85 if (!path || !*path)
86 return -EINVAL;
87
88 file = filp_open(path, O_RDONLY, 0);
89 if (IS_ERR(file))
90 return PTR_ERR(file);
91
92 ret = kernel_read_file(file, buf, size, max_size, id);
93 fput(file);
94 return ret;
95}
96EXPORT_SYMBOL_GPL(kernel_read_file_from_path);
97
98int kernel_read_file_from_path_initns(const char *path, void **buf,
99 loff_t *size, loff_t max_size,
100 enum kernel_read_file_id id)
101{
102 struct file *file;
103 struct path root;
104 int ret;
105
106 if (!path || !*path)
107 return -EINVAL;
108
109 task_lock(&init_task);
110 get_fs_root(init_task.fs, &root);
111 task_unlock(&init_task);
112
113 file = file_open_root(root.dentry, root.mnt, path, O_RDONLY, 0);
114 path_put(&root);
115 if (IS_ERR(file))
116 return PTR_ERR(file);
117
118 ret = kernel_read_file(file, buf, size, max_size, id);
119 fput(file);
120 return ret;
121}
122EXPORT_SYMBOL_GPL(kernel_read_file_from_path_initns);
123
124int kernel_read_file_from_fd(int fd, void **buf, loff_t *size, loff_t max_size,
125 enum kernel_read_file_id id)
126{
127 struct fd f = fdget(fd);
128 int ret = -EBADF;
129
130 if (!f.file)
131 goto out;
132
133 ret = kernel_read_file(f.file, buf, size, max_size, id);
134out:
135 fdput(f);
136 return ret;
137}
138EXPORT_SYMBOL_GPL(kernel_read_file_from_fd);