From nobody Tue Sep 29 18:14:28 2026 X-Original-To: dev-commits-src-main@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4hvRCS3HGgz6tvPv for ; Tue, 29 Sep 2026 18:14:28 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "YR2" (not verified)) by mx1.freebsd.org (Postfix) with ESMTPS id 4hvRCS2nbbz4DfZ for ; Tue, 29 Sep 2026 18:14:28 +0000 (UTC) (envelope-from git@FreeBSD.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1790705668; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=WyBxtua0e6pNTqaJWd7q9x85SKtP1h24Z5nukponhVA=; b=VkquTWFvIAuydmDpYG1MJLCjiZpGq202vOXgaeb1SmM/MneENpe81eZM0un1hFMvSvCvod JLOXuI4lvSnmo4wzTYwUy68gQLQwV8NPc9YqauPwzvRuDCt5Er/XFPBh7n4/EjNnGWtrzM k+xMlsiivzoqcwno6hXhANMxxK7P3P9gVhaUAN72XRJaIe1LZ26T1Td8FwwQbZzp0laDjT vZXPBtCiUeR6zYAMTDcW6ukvq7N3NoXUoR1vr/iEKx1n3gP7n1sNCs5lNQ9OubAe4V6vSR 6E94VIs5bthP1FsFXGYEP9u8iU73DR/1KuVQDFUkQ9yfsjWFRVCprBFIwC1qng== ARC-Seal: i=1; a=rsa-sha256; d=freebsd.org; s=dkim; cv=none; t=1790705668; b=YZ0uuwAHYKzH/L44XV71SmbO1T2AOvxNPsY6PmWOGK51iHSUFBpEkfLIzwV7Kpuy5ltZqH sgt+wLxFVUOlXR5HZwrlYCX8OozeYsioTZAdPDoI9Q5KEaNP55UdBYStz0Lo+frf33mf3h YRlMxnUVIIJNja35LV8affjULyixMOL9JB3agL/K/l9VuLYHxGyvzsHY3iv3ZyekrFZggv 74QTkagmgAOOEsuMd5QmmahSmAzp11/EOjiFQwb9zTU+8O8vPwOQXTeMNiP/l8tINR/rs2 7oZMvPJXNcdW2Qn6LVZ5WAobTjhQU10kj47wFV3uGkUOv9DuwSpqDiKx9Jknmw== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1790705668; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=WyBxtua0e6pNTqaJWd7q9x85SKtP1h24Z5nukponhVA=; b=dp6KBKce8DQ9b8pA4p4+1caqmOhWxWkyY66W0iLyNnP1+P6HY/t3SR5a7tQmIsk713INC9 2z8/VoPaEzIEA7XUfIOrqUO8uN51VK2i8K6/7V6nFDt3iTA5G0onko4YrTmACwr2ptQHjr ptpsCC1k+eoEtvcubFDZ0N3wCrfyLdXq4KSh4N1uZFZiCoUp6GzQgL2SkIyjbCd4eJE6vL yl5mdSwfwSbU0egSw3OVbN5cj6Moe6L7TbNpNOIdPqz3hSRJmw4vNzmpmhOKx4R7fm9OpS Nw2t7X0ArD3FDHD5tYUFaRW7upJjBdXsjkK383vusDLdIeuK/as1J9vgXiT0gg== ARC-Authentication-Results: i=1; mx1.freebsd.org; none Received: from gitrepo.freebsd.org (gitrepo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:5]) by mxrelay.nyi.freebsd.org (Postfix) with ESMTP id 4hvRCS1rLBz1Nwj for ; Tue, 29 Sep 2026 18:14:28 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from git (uid 1279) (envelope-from git@FreeBSD.org) id 3d6a9 by gitrepo.freebsd.org (DragonFly Mail Agent v0.13+ on gitrepo.freebsd.org); Tue, 29 Sep 2026 18:14:28 +0000 To: src-committers@FreeBSD.org, dev-commits-src-all@FreeBSD.org, dev-commits-src-main@FreeBSD.org From: Brooks Davis Subject: git: afe41f1ab9f6 - main - sys/uio: add updateiov() List-Id: Commit messages for the main branch of the src repository List-Archive: https://lists.freebsd.org/archives/dev-commits-src-main List-Help: List-Post: List-Subscribe: List-Unsubscribe: X-BeenThere: dev-commits-src-main@freebsd.org Sender: owner-dev-commits-src-main@FreeBSD.org List-Id: List-Post: List-Help: List-Subscribe: List-Unsubscribe: List-Owner: Precedence: list MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Git-Committer: brooks X-Git-Repository: src X-Git-Refname: refs/heads/main X-Git-Reftype: branch X-Git-Commit: afe41f1ab9f6cbabf43f28446a61ed3fe1cd72a7 Auto-Submitted: auto-generated Date: Tue, 29 Sep 2026 18:14:28 +0000 Message-Id: <6abc0004.3d6a9.56f27326@gitrepo.freebsd.org> The branch main has been updated by brooks: URL: https://cgit.FreeBSD.org/src/commit/?id=afe41f1ab9f6cbabf43f28446a61ed3fe1cd72a7 commit afe41f1ab9f6cbabf43f28446a61ed3fe1cd72a7 Author: Brooks Davis AuthorDate: 2026-09-29 17:30:14 +0000 Commit: Brooks Davis CommitDate: 2026-09-29 18:14:06 +0000 sys/uio: add updateiov() This function take a struct uio previously created by copyinuio and and updates the lengths of the user-space iovec to match those in the uio. To reduce the risks of pointer leakage and cross-ABI pointer confusion, lengths are updated individually. Reviewed by: jamie, jhb Effort: CHERI upstreaming Sponsored by: DARPA, AFRL, Innovate UK Differential Revision: https://reviews.freebsd.org/D60025 --- sys/kern/subr_uio.c | 18 ++++++++++++++++++ sys/sys/syscallsubr.h | 7 +++++++ sys/sys/uio.h | 1 + 3 files changed, 26 insertions(+) diff --git a/sys/kern/subr_uio.c b/sys/kern/subr_uio.c index 51001aacf0c9..b7be8c55b512 100644 --- a/sys/kern/subr_uio.c +++ b/sys/kern/subr_uio.c @@ -468,6 +468,24 @@ copyinuio(const void *iovp, u_int iovcnt, struct uio **uiop) return (0); } +/* + * Update the lengths of a userspace iovec to match those in a struct uio's + * iovec (previously created by copyinuio). + */ +int +updateiov(const struct uio *uiop, void *uiovp) +{ + int i, error; + struct iovec *iovp = uiovp; + + for (i = 0; i < uiop->uio_iovcnt; i++) { + error = suword(&iovp[i].iov_len, uiop->uio_iov[i].iov_len); + if (error != 0) + return (EFAULT); + } + return (0); +} + struct uio * allocuio(u_int iovcnt) { diff --git a/sys/sys/syscallsubr.h b/sys/sys/syscallsubr.h index 3a30c9cd984d..d38d10880ec8 100644 --- a/sys/sys/syscallsubr.h +++ b/sys/sys/syscallsubr.h @@ -96,6 +96,13 @@ typedef int (copyin_hdtr_t)(const void *hdtrp, struct sf_hdtr *hdtr); typedef int (copyinuio_t)(const void *iovp, unsigned int iovcnt, struct uio **iov); +/* + * A updateiov_t takes a pointer to a struct uio previously created with + * copyinuio_t and a pointer to the corresponding iovec in userspace. + * It updates all lengths in userspace to match those in the uio. + */ +typedef int(updateiov_t)(const struct uio *uiop, void *iovp); + uint64_t at2cnpflags(u_int at_flags, u_int mask); int kern___getcwd(struct thread *td, char *buf, enum uio_seg bufseg, size_t buflen, size_t path_max); diff --git a/sys/sys/uio.h b/sys/sys/uio.h index 0e0d42d04144..6549a23314e3 100644 --- a/sys/sys/uio.h +++ b/sys/sys/uio.h @@ -99,6 +99,7 @@ int uiomove_fromphys(struct vm_page *ma[], vm_offset_t offset, int n, int uiomove_nofault(void *cp, int n, struct uio *uio); int uiomove_object(struct vm_object *obj, off_t obj_size, struct uio *uio); int uiomove_step(void *cp, void *base, size_t cnt, struct uio *uio); +int updateiov(const struct uio *uiop, void *iovp); #else /* !_KERNEL */