* [PATCH v3] x86/boot: Warn on future overlapping memcpy() use
@ 2016-04-28 23:46 Kees Cook
2016-04-28 23:49 ` Kees Cook
2016-04-28 23:56 ` kbuild test robot
0 siblings, 2 replies; 4+ messages in thread
From: Kees Cook @ 2016-04-28 23:46 UTC (permalink / raw)
To: linux-kernel; +Cc: H. Peter Anvin, Thomas Gleixner, Ingo Molnar, x86, Kees Cook
If an overlapping memcpy() is ever attempted, we should report it and
gracefully call memmove(). These cases can be found and fixed to use
memmove() correctly, but in the meantime, we will not break booting.
Suggested-by: Ingo Molnar <mingo@kernel.org>
Signed-off-by: Kees Cook <keescook@chromium.org>
---
arch/x86/boot/compressed/string.c | 15 +++++++++++++--
1 file changed, 13 insertions(+), 2 deletions(-)
diff --git a/arch/x86/boot/compressed/string.c b/arch/x86/boot/compressed/string.c
index 2befeca1aada..7402227fdfdb 100644
--- a/arch/x86/boot/compressed/string.c
+++ b/arch/x86/boot/compressed/string.c
@@ -8,7 +8,7 @@
#include "../string.c"
#ifdef CONFIG_X86_32
-void *memcpy(void *dest, const void *src, size_t n)
+static void *__memcpy(void *dest, const void *src, size_t n)
{
int d0, d1, d2;
asm volatile(
@@ -22,7 +22,7 @@ void *memcpy(void *dest, const void *src, size_t n)
return dest;
}
#else
-void *memcpy(void *dest, const void *src, size_t n)
+static void *__memcpy(void *dest, const void *src, size_t n)
{
long d0, d1, d2;
asm volatile(
@@ -60,3 +60,14 @@ void *memmove(void *dest, const void *src, size_t n)
return dest;
}
+
+/* Detect and warn about potential overlaps, but handle them with memmove. */
+void *memcpy(void *dest, const void *src, size_t n)
+{
+ if (dest > src && dest - src < n) {
+ warn("Avoiding potentially unsafe overlapping memcpy()!");
+ return memmove(dest, src, n);
+ }
+ return __memcpy(dest, src, n);
+}
+
--
2.6.3
--
Kees Cook
Chrome OS & Brillo Security
^ permalink raw reply [flat|nested] 4+ messages in thread* Re: [PATCH v3] x86/boot: Warn on future overlapping memcpy() use
2016-04-28 23:46 [PATCH v3] x86/boot: Warn on future overlapping memcpy() use Kees Cook
@ 2016-04-28 23:49 ` Kees Cook
2016-04-28 23:56 ` kbuild test robot
1 sibling, 0 replies; 4+ messages in thread
From: Kees Cook @ 2016-04-28 23:49 UTC (permalink / raw)
To: Ingo Molnar, Lasse Collin
Cc: H. Peter Anvin, Thomas Gleixner, Ingo Molnar, x86, LKML,
One Thousand Gnomes, Yinghai Lu, Baoquan He, Borislav Petkov
(Sorry, this v3 got sent to an incomplete CC list...)
On Thu, Apr 28, 2016 at 4:46 PM, Kees Cook <keescook@chromium.org> wrote:
> If an overlapping memcpy() is ever attempted, we should report it and
> gracefully call memmove(). These cases can be found and fixed to use
> memmove() correctly, but in the meantime, we will not break booting.
>
> Suggested-by: Ingo Molnar <mingo@kernel.org>
> Signed-off-by: Kees Cook <keescook@chromium.org>
> ---
> arch/x86/boot/compressed/string.c | 15 +++++++++++++--
> 1 file changed, 13 insertions(+), 2 deletions(-)
>
> diff --git a/arch/x86/boot/compressed/string.c b/arch/x86/boot/compressed/string.c
> index 2befeca1aada..7402227fdfdb 100644
> --- a/arch/x86/boot/compressed/string.c
> +++ b/arch/x86/boot/compressed/string.c
> @@ -8,7 +8,7 @@
> #include "../string.c"
>
> #ifdef CONFIG_X86_32
> -void *memcpy(void *dest, const void *src, size_t n)
> +static void *__memcpy(void *dest, const void *src, size_t n)
> {
> int d0, d1, d2;
> asm volatile(
> @@ -22,7 +22,7 @@ void *memcpy(void *dest, const void *src, size_t n)
> return dest;
> }
> #else
> -void *memcpy(void *dest, const void *src, size_t n)
> +static void *__memcpy(void *dest, const void *src, size_t n)
> {
> long d0, d1, d2;
> asm volatile(
> @@ -60,3 +60,14 @@ void *memmove(void *dest, const void *src, size_t n)
>
> return dest;
> }
> +
> +/* Detect and warn about potential overlaps, but handle them with memmove. */
> +void *memcpy(void *dest, const void *src, size_t n)
> +{
> + if (dest > src && dest - src < n) {
> + warn("Avoiding potentially unsafe overlapping memcpy()!");
> + return memmove(dest, src, n);
> + }
> + return __memcpy(dest, src, n);
> +}
> +
> --
> 2.6.3
>
>
> --
> Kees Cook
> Chrome OS & Brillo Security
--
Kees Cook
Chrome OS & Brillo Security
^ permalink raw reply [flat|nested] 4+ messages in thread* Re: [PATCH v3] x86/boot: Warn on future overlapping memcpy() use
2016-04-28 23:46 [PATCH v3] x86/boot: Warn on future overlapping memcpy() use Kees Cook
2016-04-28 23:49 ` Kees Cook
@ 2016-04-28 23:56 ` kbuild test robot
2016-04-29 0:15 ` Kees Cook
1 sibling, 1 reply; 4+ messages in thread
From: kbuild test robot @ 2016-04-28 23:56 UTC (permalink / raw)
To: Kees Cook
Cc: kbuild-all, linux-kernel, H. Peter Anvin, Thomas Gleixner,
Ingo Molnar, x86, Kees Cook
[-- Attachment #1: Type: text/plain, Size: 2370 bytes --]
Hi,
[auto build test ERROR on tip/auto-latest]
[cannot apply to tip/x86/core v4.6-rc5 next-20160428]
[if your patch is applied to the wrong git tree, please drop us a note to help improving the system]
url: https://github.com/0day-ci/linux/commits/Kees-Cook/x86-boot-Warn-on-future-overlapping-memcpy-use/20160429-075026
config: i386-tinyconfig (attached as .config)
reproduce:
# save the attached .config to linux build tree
make ARCH=i386
All error/warnings (new ones prefixed by >>):
arch/x86/boot/compressed/string.c: In function 'memmove':
>> arch/x86/boot/compressed/string.c:56:10: warning: implicit declaration of function 'memcpy' [-Wimplicit-function-declaration]
return memcpy(dest, src, n);
^
>> arch/x86/boot/compressed/string.c:56:10: warning: return makes pointer from integer without a cast [-Wint-conversion]
arch/x86/boot/compressed/string.c: At top level:
>> arch/x86/boot/compressed/string.c:65:7: error: conflicting types for 'memcpy'
void *memcpy(void *dest, const void *src, size_t n)
^
arch/x86/boot/compressed/string.c:56:10: note: previous implicit declaration of 'memcpy' was here
return memcpy(dest, src, n);
^
arch/x86/boot/compressed/string.c: In function 'memcpy':
>> arch/x86/boot/compressed/string.c:68:3: warning: implicit declaration of function 'warn' [-Wimplicit-function-declaration]
warn("Avoiding potentially unsafe overlapping memcpy()!");
^
vim +/memcpy +65 arch/x86/boot/compressed/string.c
50 void *memmove(void *dest, const void *src, size_t n)
51 {
52 unsigned char *d = dest;
53 const unsigned char *s = src;
54
55 if (d <= s || d - s >= n)
> 56 return memcpy(dest, src, n);
57
58 while (n-- > 0)
59 d[n] = s[n];
60
61 return dest;
62 }
63
64 /* Detect and warn about potential overlaps, but handle them with memmove. */
> 65 void *memcpy(void *dest, const void *src, size_t n)
66 {
67 if (dest > src && dest - src < n) {
> 68 warn("Avoiding potentially unsafe overlapping memcpy()!");
69 return memmove(dest, src, n);
70 }
71 return __memcpy(dest, src, n);
---
0-DAY kernel test infrastructure Open Source Technology Center
https://lists.01.org/pipermail/kbuild-all Intel Corporation
[-- Attachment #2: .config.gz --]
[-- Type: application/octet-stream, Size: 6283 bytes --]
^ permalink raw reply [flat|nested] 4+ messages in thread* Re: [PATCH v3] x86/boot: Warn on future overlapping memcpy() use
2016-04-28 23:56 ` kbuild test robot
@ 2016-04-29 0:15 ` Kees Cook
0 siblings, 0 replies; 4+ messages in thread
From: Kees Cook @ 2016-04-29 0:15 UTC (permalink / raw)
To: kbuild test robot
Cc: kbuild-all, LKML, H. Peter Anvin, Thomas Gleixner, Ingo Molnar, x86
Argh. I'm hating this patch. :)
Will fix with v4.
On Thu, Apr 28, 2016 at 4:56 PM, kbuild test robot <lkp@intel.com> wrote:
> Hi,
>
> [auto build test ERROR on tip/auto-latest]
> [cannot apply to tip/x86/core v4.6-rc5 next-20160428]
> [if your patch is applied to the wrong git tree, please drop us a note to help improving the system]
>
> url: https://github.com/0day-ci/linux/commits/Kees-Cook/x86-boot-Warn-on-future-overlapping-memcpy-use/20160429-075026
> config: i386-tinyconfig (attached as .config)
> reproduce:
> # save the attached .config to linux build tree
> make ARCH=i386
>
> All error/warnings (new ones prefixed by >>):
>
> arch/x86/boot/compressed/string.c: In function 'memmove':
>>> arch/x86/boot/compressed/string.c:56:10: warning: implicit declaration of function 'memcpy' [-Wimplicit-function-declaration]
> return memcpy(dest, src, n);
> ^
>>> arch/x86/boot/compressed/string.c:56:10: warning: return makes pointer from integer without a cast [-Wint-conversion]
> arch/x86/boot/compressed/string.c: At top level:
>>> arch/x86/boot/compressed/string.c:65:7: error: conflicting types for 'memcpy'
> void *memcpy(void *dest, const void *src, size_t n)
> ^
> arch/x86/boot/compressed/string.c:56:10: note: previous implicit declaration of 'memcpy' was here
> return memcpy(dest, src, n);
> ^
> arch/x86/boot/compressed/string.c: In function 'memcpy':
>>> arch/x86/boot/compressed/string.c:68:3: warning: implicit declaration of function 'warn' [-Wimplicit-function-declaration]
> warn("Avoiding potentially unsafe overlapping memcpy()!");
> ^
>
> vim +/memcpy +65 arch/x86/boot/compressed/string.c
>
> 50 void *memmove(void *dest, const void *src, size_t n)
> 51 {
> 52 unsigned char *d = dest;
> 53 const unsigned char *s = src;
> 54
> 55 if (d <= s || d - s >= n)
> > 56 return memcpy(dest, src, n);
> 57
> 58 while (n-- > 0)
> 59 d[n] = s[n];
> 60
> 61 return dest;
> 62 }
> 63
> 64 /* Detect and warn about potential overlaps, but handle them with memmove. */
> > 65 void *memcpy(void *dest, const void *src, size_t n)
> 66 {
> 67 if (dest > src && dest - src < n) {
> > 68 warn("Avoiding potentially unsafe overlapping memcpy()!");
> 69 return memmove(dest, src, n);
> 70 }
> 71 return __memcpy(dest, src, n);
>
> ---
> 0-DAY kernel test infrastructure Open Source Technology Center
> https://lists.01.org/pipermail/kbuild-all Intel Corporation
--
Kees Cook
Chrome OS & Brillo Security
^ permalink raw reply [flat|nested] 4+ messages in thread
end of thread, other threads:[~2016-04-29 0:15 UTC | newest]
Thread overview: 4+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2016-04-28 23:46 [PATCH v3] x86/boot: Warn on future overlapping memcpy() use Kees Cook
2016-04-28 23:49 ` Kees Cook
2016-04-28 23:56 ` kbuild test robot
2016-04-29 0:15 ` Kees Cook
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®