From: Borislav Petkov <bp@alien8.de>
To: Andy Lutomirski <luto@kernel.org>
Cc: x86@kernel.org, linux-kernel@vger.kernel.org,
"Frédéric Weisbecker" <fweisbec@gmail.com>,
"Rik van Riel" <riel@redhat.com>,
"Oleg Nesterov" <oleg@redhat.com>,
"Denys Vlasenko" <vda.linux@googlemail.com>,
"Kees Cook" <keescook@chromium.org>,
"Brian Gerst" <brgerst@gmail.com>,
paulmck@linux.vnet.ibm.com
Subject: Re: [PATCH v4 02/17] x86/entry/64/compat: Fix bad fast syscall arg failure path
Date: Tue, 30 Jun 2015 12:58:55 +0200 [thread overview]
Message-ID: <20150630105855.GB23297@pd.tnic> (raw)
In-Reply-To: <903010762c07a3d67df914fea2da84b52b0f8f1d.1435602481.git.luto@kernel.org>
On Mon, Jun 29, 2015 at 12:33:34PM -0700, Andy Lutomirski wrote:
> diff --git a/arch/x86/entry/entry_64_compat.S b/arch/x86/entry/entry_64_compat.S
> index bb187a6a877c..efe0b1e499fa 100644
> --- a/arch/x86/entry/entry_64_compat.S
> +++ b/arch/x86/entry/entry_64_compat.S
> @@ -425,8 +425,39 @@ cstar_tracesys:
> END(entry_SYSCALL_compat)
>
> ia32_badarg:
> - ASM_CLAC
> - movq $-EFAULT, RAX(%rsp)
> + /*
> + * So far, we've entered kernel mode, set AC, turned on IRQs, and
> + * saved C regs except r8-r11. We haven't done any of the other
> + * standard entry work, though. We want to bail, but we shouldn't
> + * treat this as a syscall entry since we don't even know what the
> + * args are. Instead, treat this as a non-syscall entry, finish
> + * the entry work, and immediately exit after setting AX = -EFAULT.
> + *
> + * We're really just being polite here. Killing the task outright
> + * would be a reasonable action, too. Given that the only valid
> + * way to have gotten here is through the vDSO, and we already know
> + * that the stack pointer is bad, the task isn't going to survive
> + * for long no matter what we do.
You mean something like
force_sig_info(SIGSEGV, &si, current);
?
I'd say we do it and not noodle unnecessarily with zeroing out pt_regs
if the task is going to die anyway. IOW, make it die faster. :)
> + */
> +
> + ASM_CLAC /* undo STAC */
> + movq $-EFAULT, RAX(%rsp) /* return -EFAULT if possible */
> +
> + /* Fill in the rest of pt_regs */
> + xorl %eax, %eax
> + movq %rax, R11(%rsp)
> + movq %rax, R10(%rsp)
> + movq %rax, R9(%rsp)
> + movq %rax, R8(%rsp)
> + SAVE_EXTRA_REGS
> +
> + /* Turn IRQs back off. */
> + DISABLE_INTERRUPTS(CLBR_NONE)
> + TRACE_IRQS_OFF
> +
> + /* And exit again. */
> + jmp retint_user
> +
> ia32_ret_from_sys_call:
> xorl %eax, %eax /* Do not leak kernel information */
> movq %rax, R11(%rsp)
> --
> 2.4.3
--
Regards/Gruss,
Boris.
ECO tip #101: Trim your mails when you reply.
--
next prev parent reply other threads:[~2015-06-30 10:59 UTC|newest]
Thread overview: 54+ messages / expand[flat|nested] mbox.gz Atom feed top
2015-06-29 19:33 [PATCH v4 00/17] x86: Rewrite exit-to-userspace code Andy Lutomirski
2015-06-29 19:33 ` [PATCH v4 01/17] selftests/x86: Add a test for 32-bit fast syscall arg faults Andy Lutomirski
2015-06-29 19:33 ` [PATCH v4 02/17] x86/entry/64/compat: Fix bad fast syscall arg failure path Andy Lutomirski
2015-06-30 10:58 ` Borislav Petkov [this message]
2015-06-30 11:06 ` Ingo Molnar
2015-06-30 16:04 ` Andy Lutomirski
2015-07-01 7:43 ` Ingo Molnar
2015-06-29 19:33 ` [PATCH v4 03/17] uml: Fix do_signal() prototype Andy Lutomirski
2015-06-29 20:47 ` Richard Weinberger
2015-06-29 19:33 ` [PATCH v4 04/17] context_tracking: Add ct_state and CT_WARN_ON Andy Lutomirski
2015-06-30 12:20 ` Borislav Petkov
2015-06-30 12:53 ` Ingo Molnar
2015-06-29 19:33 ` [PATCH v4 05/17] notifiers: Assert that RCU is watching in notify_die Andy Lutomirski
2015-06-29 19:33 ` [PATCH v4 06/17] x86: Move C entry and exit code to arch/x86/entry/common.c Andy Lutomirski
2015-06-30 16:32 ` Borislav Petkov
2015-06-29 19:33 ` [PATCH v4 07/17] x86/traps: Assert that we're in CONTEXT_KERNEL in exception entries Andy Lutomirski
2015-06-30 17:01 ` Borislav Petkov
2015-06-30 17:08 ` Andy Lutomirski
2015-06-30 17:15 ` Borislav Petkov
2015-06-29 19:33 ` [PATCH v4 08/17] x86/entry: Add enter_from_user_mode and use it in syscalls Andy Lutomirski
2015-07-01 10:24 ` Borislav Petkov
2015-06-29 19:33 ` [PATCH v4 09/17] x86/entry: Add new, comprehensible entry and exit hooks Andy Lutomirski
2015-07-02 9:48 ` Borislav Petkov
2015-07-02 16:03 ` Andy Lutomirski
2015-07-02 16:25 ` Borislav Petkov
2015-06-29 19:33 ` [PATCH v4 10/17] x86/entry/64: Really create an error-entry-from-usermode code path Andy Lutomirski
2015-07-02 10:25 ` Borislav Petkov
2015-07-02 15:33 ` Andy Lutomirski
2015-07-02 16:29 ` Borislav Petkov
2015-06-29 19:33 ` [PATCH v4 11/17] x86/entry/64: Migrate 64-bit and compat syscalls to new exit hooks Andy Lutomirski
2015-07-02 10:49 ` Borislav Petkov
2015-07-02 15:56 ` Andy Lutomirski
2015-07-02 16:56 ` Denys Vlasenko
2015-06-29 19:33 ` [PATCH v4 12/17] x86/asm/entry/64: Save all regs on interrupt entry Andy Lutomirski
2015-07-02 10:52 ` Borislav Petkov
2015-07-02 15:33 ` Andy Lutomirski
2015-06-29 19:33 ` [PATCH v4 13/17] x86/asm/entry/64: Simplify irq stack pt_regs handling Andy Lutomirski
2015-06-29 19:33 ` [PATCH v4 14/17] x86/asm/entry/64: Migrate error and interrupt exit work to C Andy Lutomirski
2015-07-02 12:09 ` Borislav Petkov
2015-07-02 16:09 ` Andy Lutomirski
2015-07-02 16:33 ` Borislav Petkov
2015-07-03 6:33 ` Ingo Molnar
2015-07-03 16:27 ` Andy Lutomirski
2015-07-03 16:29 ` Andy Lutomirski
2015-07-03 14:37 ` Denys Vlasenko
2015-07-03 16:24 ` Andy Lutomirski
2015-07-04 8:12 ` Ingo Molnar
2015-06-29 19:33 ` [PATCH v4 15/17] x86/entry: Remove exception_enter from most trap handlers Andy Lutomirski
2015-06-29 19:33 ` [PATCH v4 16/17] x86/entry: Remove SCHEDULE_USER and asm/context-tracking.h Andy Lutomirski
2015-06-29 19:33 ` [PATCH v4 17/17] x86/irq: Document how IRQ context tracking works and add an assertion Andy Lutomirski
2015-06-29 19:46 ` [PATCH v4 00/17] x86: Rewrite exit-to-userspace code Richard Weinberger
2015-06-29 20:14 ` Andy Lutomirski
2015-07-02 16:45 ` Borislav Petkov
2015-07-03 6:34 ` Ingo Molnar
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20150630105855.GB23297@pd.tnic \
--to=bp@alien8.de \
--cc=brgerst@gmail.com \
--cc=fweisbec@gmail.com \
--cc=keescook@chromium.org \
--cc=linux-kernel@vger.kernel.org \
--cc=luto@kernel.org \
--cc=oleg@redhat.com \
--cc=paulmck@linux.vnet.ibm.com \
--cc=riel@redhat.com \
--cc=vda.linux@googlemail.com \
--cc=x86@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
Powered by JetHome