From: Josh Boyer <jwboyer@redhat.com>
To: Jiri Kosina <jkosina@suse.cz>
Cc: Nicolas Pitre <nicolas.pitre@linaro.org>,
Andrew Morton <akpm00@gmail.com>, Ingo Molnar <mingo@elte.hu>,
hongjiu.lu@intel.com, linux-kernel@vger.kernel.org,
Andrew Morton <akpm@linux-foundation.org>,
Russell King <rmk@arm.linux.org.uk>
Subject: Re: [PATCH v2] binfmt_elf: Fix PIE execution with randomization disabled (was Re: [RFC PATCH] binfmt_elf: Fix PIE execution with randomization disabled)
Date: Mon, 3 Oct 2011 11:42:09 -0400 [thread overview]
Message-ID: <20111003154208.GQ16720@zod.bos.redhat.com> (raw)
In-Reply-To: <alpine.LNX.2.00.1110031709230.31654@pobox.suse.cz>
On Mon, Oct 03, 2011 at 05:11:47PM +0200, Jiri Kosina wrote:
> > I was mostly just trying to adapt H.J.'s patch to account for the
> > PF_RANDOMIZE case. Looking at it a bit more, I'm not sure why they
> > would need to be different. H.J., do you recall why you made that
> > change originally?
>
> How about the patch below instead? It survives my testing, and I believe
> it handles both cases properly.
>
> Confirmation from the original bug reporter would obviously be a nice
> bonus too :)
I built an F15 kernel with this patch included. The testcase included
in the original bug report seems to run with and without randomization
enabled. Looking at the ldd output on the binary shows that both cases
are working appropriately as well.
I'm happy to add my Acked-by below, but it would be nice if H.J.
confirmed as well.
> From: Jiri Kosina <jkosina@suse.cz>
> Subject: [PATCH] binfmt_elf: fix PIE execution with randomization disabled
>
> The case of address space randomization being disabled in runtime through
> randomize_va_space sysctl is not treated properly in load_elf_binary(),
> resulting in SIGKILL coming at exec() time for certain PIE-linked binaries
> in case the randomization has been disabled at runtime prior to calling
> exec().
>
> Handle the randomize_va_space == 0 case the same way as if we were not
> supporting .text randomization at all.
>
> Based on original patch by H.J. Lu <hongjiu.lu@intel.com> and
> Josh Boyer <jwboyer@redhat.com>
>
> Cc: Ingo Molnar <mingo@elte.hu>
> Cc: Jiri Kosina <jkosina@suse.cz>
> Cc: Nicolas Pitre <nicolas.pitre@linaro.org>
> Cc: Russell King <rmk@arm.linux.org.uk>
> Signed-off-by: Jiri Kosina <jkosina@suse.cz>
Acked-by: Josh Boyer <jwboyer@redhat.com>
> ---
> fs/binfmt_elf.c | 5 ++++-
> 1 files changed, 4 insertions(+), 1 deletions(-)
>
> diff --git a/fs/binfmt_elf.c b/fs/binfmt_elf.c
> index dd0fdfc..bb11fe4 100644
> --- a/fs/binfmt_elf.c
> +++ b/fs/binfmt_elf.c
> @@ -795,7 +795,10 @@ static int load_elf_binary(struct linux_binprm *bprm, struct pt_regs *regs)
> * might try to exec. This is because the brk will
> * follow the loader, and is not movable. */
> #if defined(CONFIG_X86) || defined(CONFIG_ARM)
> - load_bias = 0;
> + if (current->flags & PF_RANDOMIZE)
> + load_bias = 0;
> + else
> + load_bias = ELF_PAGESTART(ELF_ET_DYN_BASE - vaddr);
> #else
> load_bias = ELF_PAGESTART(ELF_ET_DYN_BASE - vaddr);
> #endif
>
next prev parent reply other threads:[~2011-10-03 15:43 UTC|newest]
Thread overview: 19+ messages / expand[flat|nested] mbox.gz Atom feed top
2011-09-29 19:53 [RFC PATCH] binfmt_elf: Fix PIE execution with randomization disabled Josh Boyer
2011-09-29 21:19 ` Andrew Morton
2011-09-29 21:36 ` Lu, Hongjiu
2011-09-30 0:41 ` Nicolas Pitre
2011-09-30 2:16 ` Josh Boyer
2011-10-03 14:53 ` Jiri Kosina
2011-10-03 15:03 ` Josh Boyer
2011-10-03 15:11 ` [PATCH v2] binfmt_elf: Fix PIE execution with randomization disabled (was Re: [RFC PATCH] binfmt_elf: Fix PIE execution with randomization disabled) Jiri Kosina
2011-10-03 15:42 ` Josh Boyer [this message]
2011-10-03 15:56 ` Nicolas Pitre
2011-10-03 16:02 ` Lu, Hongjiu
2011-10-03 16:13 ` Nicolas Pitre
2011-10-03 21:14 ` Jiri Kosina
2011-10-03 22:03 ` Andrew Morton
2011-10-03 22:06 ` Jiri Kosina
2011-10-03 22:56 ` [PATCH v3] " Jiri Kosina
2011-10-08 22:35 ` [PATCH v2] " Jiri Kosina
2011-10-03 12:10 ` [RFC PATCH] binfmt_elf: Fix PIE execution with randomization disabled Jiri Kosina
2011-10-03 12:59 ` Josh Boyer
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20111003154208.GQ16720@zod.bos.redhat.com \
--to=jwboyer@redhat.com \
--cc=akpm00@gmail.com \
--cc=akpm@linux-foundation.org \
--cc=hongjiu.lu@intel.com \
--cc=jkosina@suse.cz \
--cc=linux-kernel@vger.kernel.org \
--cc=mingo@elte.hu \
--cc=nicolas.pitre@linaro.org \
--cc=rmk@arm.linux.org.uk \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®