mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Sukadev Bhattiprolu <sukadev@linux.vnet.ibm.com>
To: Oren Laadan <orenl@librato.com>
Cc: linux-kernel@vger.kernel.org, randy.dunlap@oracle.com,
	arnd@arndb.de, Containers <containers@lists.linux-foundation.org>,
	Nathan Lynch <nathanl@austin.ibm.com>,
	Louis.Rilling@kerlabs.com,
	"Eric W. Biederman" <ebiederm@xmission.com>,
	kosaki.motohiro@jp.fujitsu.com, hpa@zytor.com, mingo@elte.hu,
	linux-api@vger.kernel.org, torvalds@linux-foundation.org,
	Alexey Dobriyan <adobriyan@gmail.com>,
	roland@redhat.com, Pavel Emelyanov <xemul@openvz.org>
Subject: Re: [RFC][v8][PATCH 7/10]: Check invalid clone flags
Date: Tue, 13 Oct 2009 16:38:50 -0700	[thread overview]
Message-ID: <20091013233850.GB24392@us.ibm.com> (raw)
In-Reply-To: <4AD4C88D.7040008@librato.com>

Oren Laadan [orenl@librato.com] wrote:
| 
| 
| Sukadev Bhattiprolu wrote:
| > 
| > Subject: [RFC][v8][PATCH 7/10]: Check invalid clone flags
| > 
| > As pointed out by Oren Laadan, we want to ensure that unused bits in the
| > clone-flags remain unused and available for future. To ensure this, define
| > a mask of clone-flags and check the flags in the clone() system calls.
| > 
| > Changelog[v8]:
| > 	- New patch in set
| > 
| > Signed-off-by: Sukadev Bhattiprolu <sukadev@linux.vnet.ibm.com>
| > 
| > ---
| >  include/linux/sched.h |   10 ++++++++++
| >  kernel/fork.c         |    3 +++
| >  2 files changed, 13 insertions(+)
| > 
| > Index: linux-2.6/include/linux/sched.h
| > ===================================================================
| > --- linux-2.6.orig/include/linux/sched.h	2009-10-02 18:53:55.000000000 -0700
| > +++ linux-2.6/include/linux/sched.h	2009-10-02 19:58:21.000000000 -0700
| > @@ -29,6 +29,16 @@
| >  #define CLONE_NEWNET		0x40000000	/* New network namespace */
| >  #define CLONE_IO		0x80000000	/* Clone io context */
| >  
| > +#define VALID_CLONE_FLAGS	(CSIGNAL | CLONE_VM | CLONE_FS | CLONE_FILES |\
| > +				 CLONE_SIGHAND | CLONE_PTRACE | CLONE_VFORK  |\
| > +				 CLONE_PARENT | CLONE_THREAD | CLONE_NEWNS   |\
| > +				 CLONE_SYSVSEM | CLONE_SETTLS                |\
| > +				 CLONE_PARENT_SETTID | CLONE_CHILD_CLEARTID  |\
| > +				 CLONE_DETACHED | CLONE_UNTRACED             |\
| > +				 CLONE_CHILD_SETTID | CLONE_STOPPED          |\
| > +				 CLONE_NEWUTS | CLONE_NEWIPC | CLONE_NEWUSER |\
| > +				 CLONE_NEWPID | CLONE_NEWNET| CLONE_IO)
| > +
| >  /*
| >   * Scheduling policies
| >   */
| > Index: linux-2.6/kernel/fork.c
| > ===================================================================
| > --- linux-2.6.orig/kernel/fork.c	2009-10-02 19:00:08.000000000 -0700
| > +++ linux-2.6/kernel/fork.c	2009-10-02 19:57:36.000000000 -0700
| > @@ -942,6 +942,9 @@ static struct task_struct *copy_process(
| >  	struct task_struct *p;
| >  	int cgroup_callbacks_done = 0;
| >  
| 
| We can safely apply these tests to clone3(), because it is a new syscall.
| 
| However, I don't know if applying it to clone() can break existing
| application that may already be (incorrectly) using invalid flags ?

Doing the check in copy_process() seems would apply to all architectures.

As for breaking an existing app, there is only one unused flag, 0x00001000
(bw CLONE_SIGHAND and CLONE_PTRACE). If an application could be using that
and we don't want to break it, maybe we can add following macro to the
VALID_CLONE_FLAGS list ?

	#define CLONE_UNUSED_BIT	0x00001000


  reply	other threads:[~2009-10-13 23:38 UTC|newest]

Thread overview: 91+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2009-10-13  4:49 [RFC][v8][PATCH 0/10] Implement clone3() system call Sukadev Bhattiprolu
2009-10-13  4:49 ` [RFC][v8][PATCH 1/10]: Factor out code to allocate pidmap page Sukadev Bhattiprolu
2009-10-13  4:50 ` [RFC][v8][PATCH 2/10]: Have alloc_pidmap() return actual error code Sukadev Bhattiprolu
2009-10-13  4:50 ` [RFC][v8][PATCH 3/10]: Make pid_max a pid_ns property Sukadev Bhattiprolu
2009-10-13  5:19   ` Alexey Dobriyan
2009-10-13 13:09   ` Pavel Emelyanov
2009-10-13 15:24     ` Serge E. Hallyn
2009-10-13 16:10       ` Pavel Emelyanov
2009-10-13 16:28         ` Serge E. Hallyn
2009-10-13  4:51 ` [RFC][v8][PATCH 4/10]: Add target_pid parameter to alloc_pidmap() Sukadev Bhattiprolu
2009-10-13 11:50   ` Pavel Emelyanov
2009-10-15  0:24     ` Sukadev Bhattiprolu
2009-10-13  4:51 ` [RFC][v8][PATCH 5/10]: Add target_pids parameter to alloc_pid() Sukadev Bhattiprolu
2009-10-13  4:52 ` [RFC][v8][PATCH 6/10]: Add target_pids parameter to copy_process() Sukadev Bhattiprolu
2009-10-13  4:52 ` [RFC][v8][PATCH 7/10]: Check invalid clone flags Sukadev Bhattiprolu
2009-10-13 18:35   ` Oren Laadan
2009-10-13 23:38     ` Sukadev Bhattiprolu [this message]
2009-10-13  4:52 ` [RFC][v8][PATCH 8/10]: Define do_fork_with_pids() Sukadev Bhattiprolu
2009-10-13  4:54 ` [RFC][v8][PATCH 9/10]: Define clone3() syscall Sukadev Bhattiprolu
2009-10-13 18:46   ` Oren Laadan
2009-10-16  4:20   ` Sukadev Bhattiprolu
2009-10-16  6:25     ` Michael Kerrisk
2009-10-16 18:06       ` Sukadev Bhattiprolu
2009-10-19 17:44         ` Matt Helsley
2009-10-19 21:31           ` H. Peter Anvin
2009-10-19 23:50             ` Matt Helsley
2009-10-21  4:26               ` Michael Kerrisk
2009-10-21 13:03                 ` H. Peter Anvin
2009-10-21 19:44                   ` Sukadev Bhattiprolu
2009-10-21 22:03                     ` H. Peter Anvin
2009-10-22 10:40                     ` Michael Kerrisk
2009-10-22 18:10                       ` Sukadev Bhattiprolu
2009-10-22 10:26                   ` Michael Kerrisk
2009-10-22 11:38                     ` H. Peter Anvin
2009-10-22 12:14                       ` Michael Kerrisk
2009-10-22 12:19                         ` H. Peter Anvin
2009-10-22 13:57                         ` Matt Helsley
2009-10-13  4:55 ` [RFC][v8][PATCH 10/10]: Document " Sukadev Bhattiprolu
2009-10-14 12:26   ` Arnd Bergmann
2009-10-14 18:39     ` Sukadev Bhattiprolu
2009-10-19 21:36   ` Pavel Machek
2009-10-21  8:37     ` Arnd Bergmann
2009-10-21  9:33       ` Pavel Machek
2009-10-21 13:26         ` Arnd Bergmann
2009-10-21 18:27     ` Sukadev Bhattiprolu
2009-10-13 20:50 ` [RFC][v8][PATCH 0/10] Implement clone3() system call Roland McGrath
2009-10-13 23:27   ` Sukadev Bhattiprolu
2009-10-13 23:53     ` Roland McGrath
2009-10-14  1:13       ` H. Peter Anvin
2009-10-14  4:36         ` Sukadev Bhattiprolu
2009-10-14  4:38           ` H. Peter Anvin
2009-10-14 22:36         ` Sukadev Bhattiprolu
2009-10-14 22:49           ` H. Peter Anvin
2009-10-15  0:17             ` Sukadev Bhattiprolu
2009-10-13 23:49 ` H. Peter Anvin
2009-10-14  1:39   ` Matt Helsley
2009-10-14  2:24     ` H. Peter Anvin
2009-10-14  4:40       ` Sukadev Bhattiprolu
2009-10-14  4:50         ` H. Peter Anvin
2009-10-14 16:07         ` Serge E. Hallyn
2009-10-16 19:22 ` Daniel Lezcano
2009-10-16 19:44   ` Sukadev Bhattiprolu
2009-10-19 20:34     ` Daniel Lezcano
2009-10-19 21:47       ` Oren Laadan
2009-10-20  0:51         ` Matt Helsley
2009-10-20  3:33           ` Eric W. Biederman
2009-10-20  4:03             ` Sukadev Bhattiprolu
2009-10-20 10:46               ` Eric W. Biederman
2009-10-20 14:16                 ` Serge E. Hallyn
2009-10-20 18:33                 ` Sukadev Bhattiprolu
2009-10-20 19:26                   ` Eric W. Biederman
2009-10-20 20:13                     ` Oren Laadan
2009-10-21  6:20                     ` Sukadev Bhattiprolu
2009-10-21  9:16                       ` Eric W. Biederman
2009-10-21 18:52                         ` Sukadev Bhattiprolu
2009-10-21 21:11                           ` Eric W. Biederman
2009-10-23  0:42                         ` Sukadev Bhattiprolu
2009-10-23  1:03                           ` Eric W. Biederman
2009-10-23  5:30                             ` Sukadev Bhattiprolu
2009-10-23  5:44                               ` Eric W. Biederman
2009-10-23 19:21                                 ` Sukadev Bhattiprolu
2009-10-23 20:48                                   ` Sukadev Bhattiprolu
2009-10-23 23:26                                     ` Eric W. Biederman
2009-10-24  3:38                                       ` Sukadev Bhattiprolu
2009-10-23 19:16                               ` Oren Laadan
2009-10-23 19:34                                 ` Oren Laadan
2009-10-23 23:12                                   ` Eric W. Biederman
2009-10-20 14:09             ` Serge E. Hallyn
2009-10-21 15:53         ` Daniel Lezcano
2009-10-21 18:45           ` Oren Laadan
2009-10-22 11:22             ` Daniel Lezcano

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20091013233850.GB24392@us.ibm.com \
    --to=sukadev@linux.vnet.ibm.com \
    --cc=Louis.Rilling@kerlabs.com \
    --cc=adobriyan@gmail.com \
    --cc=arnd@arndb.de \
    --cc=containers@lists.linux-foundation.org \
    --cc=ebiederm@xmission.com \
    --cc=hpa@zytor.com \
    --cc=kosaki.motohiro@jp.fujitsu.com \
    --cc=linux-api@vger.kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=mingo@elte.hu \
    --cc=nathanl@austin.ibm.com \
    --cc=orenl@librato.com \
    --cc=randy.dunlap@oracle.com \
    --cc=roland@redhat.com \
    --cc=torvalds@linux-foundation.org \
    --cc=xemul@openvz.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®