* [PATCH] Yama: use atomic allocations when reporting
@ 2016-05-04 14:18 Sasha Levin
2016-05-04 17:22 ` Kees Cook
0 siblings, 1 reply; 2+ messages in thread
From: Sasha Levin @ 2016-05-04 14:18 UTC (permalink / raw)
To: james.l.morris, serge
Cc: keescook, linux-security-module, linux-kernel, Sasha Levin
Access reporting often happens from atomic contexes. Avoid
lockups when allocating memory for command lines.
Fixes: 8a56038c2ae ("Yama: consolidate error reporting")
Signed-off-by: Sasha Levin <sasha.levin@oracle.com>
---
security/yama/yama_lsm.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/security/yama/yama_lsm.c b/security/yama/yama_lsm.c
index c19f6e5..9b756b1 100644
--- a/security/yama/yama_lsm.c
+++ b/security/yama/yama_lsm.c
@@ -47,8 +47,8 @@ static void report_access(const char *access, struct task_struct *target,
{
char *target_cmd, *agent_cmd;
- target_cmd = kstrdup_quotable_cmdline(target, GFP_KERNEL);
- agent_cmd = kstrdup_quotable_cmdline(agent, GFP_KERNEL);
+ target_cmd = kstrdup_quotable_cmdline(target, GFP_ATOMIC);
+ agent_cmd = kstrdup_quotable_cmdline(agent, GFP_ATOMIC);
pr_notice_ratelimited(
"ptrace %s of \"%s\"[%d] was attempted by \"%s\"[%d]\n",
--
1.9.1
^ permalink raw reply [flat|nested] 2+ messages in thread* Re: [PATCH] Yama: use atomic allocations when reporting
2016-05-04 14:18 [PATCH] Yama: use atomic allocations when reporting Sasha Levin
@ 2016-05-04 17:22 ` Kees Cook
0 siblings, 0 replies; 2+ messages in thread
From: Kees Cook @ 2016-05-04 17:22 UTC (permalink / raw)
To: Sasha Levin; +Cc: James Morris, Serge E. Hallyn, linux-security-module, LKML
On Wed, May 4, 2016 at 7:18 AM, Sasha Levin <sasha.levin@oracle.com> wrote:
> Access reporting often happens from atomic contexes. Avoid
> lockups when allocating memory for command lines.
>
> Fixes: 8a56038c2ae ("Yama: consolidate error reporting")
> Signed-off-by: Sasha Levin <sasha.levin@oracle.com>
Thanks for catching this! Applied.
-Kees
> ---
> security/yama/yama_lsm.c | 4 ++--
> 1 file changed, 2 insertions(+), 2 deletions(-)
>
> diff --git a/security/yama/yama_lsm.c b/security/yama/yama_lsm.c
> index c19f6e5..9b756b1 100644
> --- a/security/yama/yama_lsm.c
> +++ b/security/yama/yama_lsm.c
> @@ -47,8 +47,8 @@ static void report_access(const char *access, struct task_struct *target,
> {
> char *target_cmd, *agent_cmd;
>
> - target_cmd = kstrdup_quotable_cmdline(target, GFP_KERNEL);
> - agent_cmd = kstrdup_quotable_cmdline(agent, GFP_KERNEL);
> + target_cmd = kstrdup_quotable_cmdline(target, GFP_ATOMIC);
> + agent_cmd = kstrdup_quotable_cmdline(agent, GFP_ATOMIC);
>
> pr_notice_ratelimited(
> "ptrace %s of \"%s\"[%d] was attempted by \"%s\"[%d]\n",
> --
> 1.9.1
>
--
Kees Cook
Chrome OS & Brillo Security
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2016-05-04 17:22 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2016-05-04 14:18 [PATCH] Yama: use atomic allocations when reporting Sasha Levin
2016-05-04 17:22 ` Kees Cook
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®