HomeFreeBSD

freebsd32: fix padding of computed control message length for recvmsg()

Description

freebsd32: fix padding of computed control message length for recvmsg()

Each control message region must be aligned on a 4-byte boundary on 32-bit
architectures. The 32-bit compat shim for recvmsg() gets the actual layout
right, but doesn't pad the payload length when computing msg_controllen for
the output message header. If a control message contains an unaligned
payload, such as the 1-byte TTL field in the example attached to PR 236737,
this can produce control message payload boundaries that extend beyond
the boundary reported by msg_controllen.

PR: 236737
Reported by: Yuval Pavel Zholkover <paulzhol@gmail.com>
Reviewed by: markj
MFC after: 1 week
Differential Revision: https://reviews.freebsd.org/D19768

Details

Committed
jahMar 30 2019, 11:43 PM
Reviewer
markj
Differential Revision
D19768: freebsd32: fix padding of computed control message length for recvmsg()
Parents
rS345740: Import the proof-of-concept fix in D19765
Branches
Unknown
Tags
Unknown