From: Andrew Morton <akpm@osdl.org>
To: ebiederm@xmission.com (Eric W. Biederman)
Cc: linux-kernel@vger.kernel.org
Subject: Re: [PATCH] i386: Add a temporary to make put_user more type safe.
Date: Sat, 28 Jan 2006 23:51:13 -0800 [thread overview]
Message-ID: <20060128235113.697e3a2c.akpm@osdl.org> (raw)
In-Reply-To: <m17j8jfs03.fsf@ebiederm.dsl.xmission.com>
ebiederm@xmission.com (Eric W. Biederman) wrote:
>
> > Sounds sane. We could make it warn if typeof(x)!=typeof(*ptr) by adding
> > another temporary for the pointer, give it type typeof(x)*, but I haven't
> > tried it.
>
> I guess we could do that. However if we don't use the value we will probably
> get an unused variable warning.
No, that's OK, we can use the temporary.
Something like this:
--- devel/include/asm-i386/uaccess.h~x86-tighten-uaccess-type-checking 2006-01-28 23:45:16.000000000 -0800
+++ devel-akpm/include/asm-i386/uaccess.h 2006-01-28 23:48:31.000000000 -0800
@@ -149,14 +149,16 @@ extern void __get_user_4(void);
#define get_user(x,ptr) \
({ int __ret_gu; \
unsigned long __val_gu; \
+ __typeof__(x)*_p_; \
+ _p_ = ptr; \
__chk_user_ptr(ptr); \
- switch(sizeof (*(ptr))) { \
- case 1: __get_user_x(1,__ret_gu,__val_gu,ptr); break; \
- case 2: __get_user_x(2,__ret_gu,__val_gu,ptr); break; \
- case 4: __get_user_x(4,__ret_gu,__val_gu,ptr); break; \
- default: __get_user_x(X,__ret_gu,__val_gu,ptr); break; \
+ switch(sizeof (*(_p_))) { \
+ case 1: __get_user_x(1, __ret_gu, __val_gu, _p_); break; \
+ case 2: __get_user_x(2, __ret_gu, __val_gu, _p_); break; \
+ case 4: __get_user_x(4, __ret_gu, __val_gu, _p_); break; \
+ default: __get_user_x(X, __ret_gu, __val_gu, _p_); break; \
} \
- (x) = (__typeof__(*(ptr)))__val_gu; \
+ (x) = __val_gu; \
__ret_gu; \
})
@@ -198,13 +200,17 @@ extern void __put_user_8(void);
#define put_user(x,ptr) \
({ int __ret_pu; \
__chk_user_ptr(ptr); \
- __typeof__(*(ptr)) __pu_val = x; \
+ __typeof__(x)*_p_; \
+ __typeof__(x)__pu_val; \
+ \
+ _p_ = ptr; \
+ __pu_val = x; \
switch(sizeof(*(ptr))) { \
- case 1: __put_user_1(__pu_val, ptr); break; \
- case 2: __put_user_2(__pu_val, ptr); break; \
- case 4: __put_user_4(__pu_val, ptr); break; \
- case 8: __put_user_8(__pu_val, ptr); break; \
- default:__put_user_X(__pu_val, ptr); break; \
+ case 1: __put_user_1(__pu_val, _p_); break; \
+ case 2: __put_user_2(__pu_val, _p_); break; \
+ case 4: __put_user_4(__pu_val, _p_); break; \
+ case 8: __put_user_8(__pu_val, _p_); break; \
+ default:__put_user_X(__pu_val, _p_); break; \
} \
__ret_pu; \
})
_
It gives ~100 warnings on my usual test config. It's a bit awkward because
get_user/put_user/etc aren't allowed to evaluate their args multiple times
- code likes to do
get_user(v, p++);
I guess fixing those 100-odd warnings might find some warts -
compiler-caused truncation or sign-extension during uaccess copies is a bit
of a worry.
But I have enough things to be going on with :(
next prev parent reply other threads:[~2006-01-29 7:51 UTC|newest]
Thread overview: 20+ messages / expand[flat|nested] mbox.gz Atom feed top
2006-01-29 6:26 Eric W. Biederman
2006-01-29 6:39 ` Andrew Morton
2006-01-29 6:49 ` Eric W. Biederman
2006-01-29 7:51 ` Andrew Morton [this message]
[not found] ` <200601291620.28291.ioe-lkml@rameria.de>
2006-01-29 19:33 ` Andrew Morton
2006-01-29 20:04 ` [PATCH] i386: instead of poisoning .init zone, change protection bits to force a fault Eric Dumazet
2006-01-29 20:05 ` Benjamin LaHaise
2006-01-29 20:28 ` Eric Dumazet
2006-01-29 20:56 ` [PATCH, V2] " Eric Dumazet
2006-01-30 9:03 ` Questions about alloc_large_system_hash() and TLB entries Eric Dumazet
2006-01-30 9:22 ` David S. Miller
2006-01-30 10:22 ` Eric Dumazet
2006-02-04 22:41 ` [PATCH, V2] i386: instead of poisoning .init zone, change protection bits to force a fault Andrew Morton
2006-02-05 17:03 ` Eric Dumazet
2006-02-05 19:42 ` Andrew Morton
2006-02-06 8:53 ` Eric Dumazet
2006-02-06 9:02 ` Eric Dumazet
2006-02-06 9:28 ` Andrew Morton
2006-02-06 10:07 ` Eric Dumazet
2006-02-06 10:16 ` Andrew Morton
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20060128235113.697e3a2c.akpm@osdl.org \
--to=akpm@osdl.org \
--cc=ebiederm@xmission.com \
--cc=linux-kernel@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
Powered by JetHome