From: Dave Hansen <dave@sr71.net>
To: linux-kernel@vger.kernel.org
Cc: x86@kernel.org, Dave Hansen <dave@sr71.net>, dave.hansen@linux.intel.com
Subject: [PATCH 1/2] x86, mpx: do proper get_user() when running 32-bit binaries on 64-bit
Date: Wed, 11 Nov 2015 10:19:31 -0800 [thread overview]
Message-ID: <20151111181931.3ACF6822@viggo.jf.intel.com> (raw)
In-Reply-To: <20151111181930.A06D71BF@viggo.jf.intel.com>
From: Dave Hansen <dave.hansen@linux.intel.com>
When you call get_user(foo, bar), you effectively do a
copy_from_user(&foo, bar, sizeof(*bar));
Note that the sizeof() is implicit.
When we reach out to userspace to try to zap an entire "bounds table"
we need to go read a "bounds directory entry" in order to locate the
table's address. The size of a "directory entry" depends on the
binary being run and is always the size of a pointer.
But, when we have a 64-bit kernel and a 32-bit application, the
directory entry is still only 32-bits long, but we fetch it with a
64-bit pointer which makes get_user() does a 64-bit fetch. Reading
4 extra bytes isn't harmful, unless we are at the end of and run off
the table. It might also cause the zero page to get faulted in
unnecessarily even if you are not at the end.
Fix it up by doing a special 32-bit get_user() via a cast when we
have 32-bit userspace.
Signed-off-by: Dave Hansen <dave.hansen@linux.intel.com>
---
b/arch/x86/mm/mpx.c | 25 ++++++++++++++++++++++++-
1 file changed, 24 insertions(+), 1 deletion(-)
diff -puN arch/x86/mm/mpx.c~get_bd_entry arch/x86/mm/mpx.c
--- a/arch/x86/mm/mpx.c~get_bd_entry 2015-11-11 10:18:49.615230106 -0800
+++ b/arch/x86/mm/mpx.c 2015-11-11 10:18:49.619230288 -0800
@@ -586,6 +586,29 @@ static unsigned long mpx_bd_entry_to_bt_
}
/*
+ * We only want to do a 4-byte get_user() on 32-bit. Otherwise,
+ * we might run off the end of the bounds table if we are on
+ * a 64-bit kernel and try to get 8 bytes.
+ */
+int get_user_bd_entry(struct mm_struct *mm, unsigned long *bd_entry_ret,
+ long __user *bd_entry_ptr)
+{
+ u32 bd_entry_32;
+ int ret;
+
+ if (is_64bit_mm(mm))
+ return get_user(*bd_entry_ret, bd_entry_ptr);
+
+ /*
+ * Note that get_user() uses the type of the *pointer* to
+ * establish the size of the get, not the destination.
+ */
+ ret = get_user(bd_entry_32, (u32 __user *)bd_entry_ptr);
+ *bd_entry_ret = bd_entry_32;
+ return ret;
+}
+
+/*
* Get the base of bounds tables pointed by specific bounds
* directory entry.
*/
@@ -605,7 +628,7 @@ static int get_bt_addr(struct mm_struct
int need_write = 0;
pagefault_disable();
- ret = get_user(bd_entry, bd_entry_ptr);
+ ret = get_user_bd_entry(mm, &bd_entry, bd_entry_ptr);
pagefault_enable();
if (!ret)
break;
_
next prev parent reply other threads:[~2015-11-11 18:19 UTC|newest]
Thread overview: 5+ messages / expand[flat|nested] mbox.gz Atom feed top
2015-11-11 18:19 [PATCH 0/2] x86, mpx: Fixes for 32-bit userspace Dave Hansen
2015-11-11 18:19 ` Dave Hansen [this message]
2015-11-12 13:27 ` [tip:x86/urgent] x86/mpx: Do proper get_user() when running 32-bit binaries on 64-bit kernels tip-bot for Dave Hansen
2015-11-11 18:19 ` [PATCH 2/2] x86, mpx: fix 32-bit address space calculation Dave Hansen
2015-11-12 13:27 ` [tip:x86/urgent] x86/mpx: Fix " tip-bot for Dave Hansen
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20151111181931.3ACF6822@viggo.jf.intel.com \
--to=dave@sr71.net \
--cc=dave.hansen@linux.intel.com \
--cc=linux-kernel@vger.kernel.org \
--cc=x86@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
Powered by JetHome