From: Andrew Morton <akpm@linux-foundation.org>
To: Matthieu CASTET <matthieu.castet@parrot.com>
Cc: "linux-kernel@vger.kernel.org" <linux-kernel@vger.kernel.org>,
Al Viro <viro@zeniv.linux.org.uk>,
Oleg Nesterov <oleg@redhat.com>
Subject: Re: [PATCH] binfmt_elf: fix return value in case of interpreter load failure
Date: Mon, 15 Apr 2013 14:53:24 -0700 [thread overview]
Message-ID: <20130415145324.d63be917d438b3f4ec37f845@linux-foundation.org> (raw)
In-Reply-To: <51681F0E.1040900@parrot.com>
On Fri, 12 Apr 2013 16:49:50 +0200 Matthieu CASTET <matthieu.castet@parrot.com> wrote:
> Hi Andrew,
>
> thanks for your quick review.
>
> Andrew Morton a __crit :
> > On Thu, 11 Apr 2013 15:53:09 +0200 Matthieu CASTET <matthieu.castet@parrot.com> wrote:
> >
> >> The current code return the address instead of using PTR_ERR.
> >
> > I don't understand what you mean here - please describe this error in
> > much more detail. Help people to identify the section of code which
> > is being discussed.
>
> I was speaking of
>
>
> elf_entry = load_elf_interp(&loc->interp_elf_ex,
> interpreter,
> &interp_map_addr,
> load_bias);
> [...]
> if (BAD_ADDR(elf_entry)) {
> force_sig(SIGSEGV, current);
> retval = IS_ERR((void *)elf_entry) ?
> (int)elf_entry : -EINVAL;
> goto out_free_dentry;
> }
>
> and was expecting we should use PTR_ERR when IS_ERR is true to match what is
> done in [1].
>
> But didn't saw that PTR_ERR((void *)elf_entry) and (int)elf_entry are equivalent.
>
> >
> >> Also the check is done after adding e_entry. This can cause weird behaviour
> >> because -errno + loc->interp_elf_ex.e_entry can produce a valid address.
> >
> > Which check?
>
> I am really confused here. Reading again the code this can't happen because if
> load_elf_interp return -errno
>
>
> We don't enter this condition
> > if (!IS_ERR((void *)elf_entry)) {
> > /*
> > * load_elf_interp() returns relocation
> > * adjustment
> > */
> > interp_load_addr = elf_entry;
> > elf_entry += loc->interp_elf_ex.e_entry;
> > }
> we still have -errno here
> > if (BAD_ADDR(elf_entry)) {
> > force_sig(SIGSEGV, current);
> > retval = IS_ERR((void *)elf_entry) ?
> > (int)elf_entry : -EINVAL;
> > goto out_free_dentry;
> > }
>
>
> Sorry for my mistake.
>
> The only valid remaining part of my patch is to return SIGKILL when
> load_elf_interp fail (IS_ERR((void *)elf_entry) is true) (for example load
> address of linker is bad) instead of SIGSEGV. This will follow what is done when
> loading binary.
>
> But is it even worth doing?
SIGSEGV can be caught so that would be a user-visible change. I just
don't know what the implications of such a change would be :(
(hopefully cc's Oleg)
next prev parent reply other threads:[~2013-04-15 21:53 UTC|newest]
Thread overview: 5+ messages / expand[flat|nested] mbox.gz Atom feed top
2013-04-11 13:53 Matthieu CASTET
2013-04-11 22:04 ` Andrew Morton
2013-04-12 14:49 ` Matthieu CASTET
2013-04-15 21:53 ` Andrew Morton [this message]
2013-04-16 14:25 ` Oleg Nesterov
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20130415145324.d63be917d438b3f4ec37f845@linux-foundation.org \
--to=akpm@linux-foundation.org \
--cc=linux-kernel@vger.kernel.org \
--cc=matthieu.castet@parrot.com \
--cc=oleg@redhat.com \
--cc=viro@zeniv.linux.org.uk \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®