From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1753737AbcFOPa7 (ORCPT ); Wed, 15 Jun 2016 11:30:59 -0400 Received: from mx1.redhat.com ([209.132.183.28]:53330 "EHLO mx1.redhat.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1753504AbcFOPa5 (ORCPT ); Wed, 15 Jun 2016 11:30:57 -0400 From: Prarit Bhargava To: linux-kernel@vger.kernel.org Cc: Prarit Bhargava , Andrew Morton , Thomas Gleixner , Yang Shi , Ingo Molnar , Mel Gorman , Rasmus Villemoes , Kees Cook , Yaowei Bai , Andrey Ryabinin Subject: [PATCH] init, allow blacklisting of module_init functions Date: Wed, 15 Jun 2016 11:30:52 -0400 Message-Id: <1466004652-27206-1-git-send-email-prarit@redhat.com> X-Greylist: Sender IP whitelisted, not delayed by milter-greylist-4.5.16 (mx1.redhat.com [10.5.110.39]); Wed, 15 Jun 2016 15:30:56 +0000 (UTC) Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org At some point I was 100% sure this worked. I do remember testing it against just a loadable module and had positive testing results. I went back to the time that it was commited (3.15-ish) and blacklisting a module init function didn't work there either, so something went wrong somewhere. In any case this is a trivial patch to add the functionality... P. ---8<--- sprint_symbol_no_offset() returns the string "function_name [module_name]" where [module_name] is not printed for built in kernel functions. This means that the blacklisting code will fail when comparing module function names with the extended string. This patch adds the functionality to block a module's module_init() function by finding the space in the string and truncating the comparison to that length. Signed-off-by: Prarit Bhargava Cc: Andrew Morton Cc: Thomas Gleixner Cc: Yang Shi Cc: Prarit Bhargava Cc: Ingo Molnar Cc: Mel Gorman Cc: Rasmus Villemoes Cc: Kees Cook Cc: Yaowei Bai Cc: Andrey Ryabinin --- init/main.c | 13 ++++++++++++- 1 file changed, 12 insertions(+), 1 deletion(-) diff --git a/init/main.c b/init/main.c index 4c17fda5c2ff..730d6a846216 100644 --- a/init/main.c +++ b/init/main.c @@ -708,14 +708,25 @@ static bool __init_or_module initcall_blacklisted(initcall_t fn) { struct blacklist_entry *entry; char fn_name[KSYM_SYMBOL_LEN]; + char *space; + int length; if (list_empty(&blacklisted_initcalls)) return false; sprint_symbol_no_offset(fn_name, (unsigned long)fn); + /* + * fn will be "function_name [module_name]" where [module_name] is not + * displayed for built-in init functions. Strip off the [module_name]. + */ + space = strchrnul(fn_name, ' '); + if (!space) + length = strlen(fn_name); + else + length = space - fn_name; list_for_each_entry(entry, &blacklisted_initcalls, next) { - if (!strcmp(fn_name, entry->buf)) { + if (!strncmp(fn_name, entry->buf, length)) { pr_debug("initcall %s blacklisted\n", fn_name); return true; } -- 1.7.9.3