From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org X-Spam-Level: X-Spam-Status: No, score=-4.0 required=3.0 tests=HEADER_FROM_DIFFERENT_DOMAINS, MAILING_LIST_MULTI,SPF_HELO_NONE,SPF_PASS,USER_AGENT_GIT autolearn=no autolearn_force=no version=3.4.0 Received: from mail.kernel.org (mail.kernel.org [198.145.29.99]) by smtp.lore.kernel.org (Postfix) with ESMTP id 917F1C32792 for ; Mon, 30 Sep 2019 21:43:51 +0000 (UTC) Received: from vger.kernel.org (vger.kernel.org [209.132.180.67]) by mail.kernel.org (Postfix) with ESMTP id 69E62218DE for ; Mon, 30 Sep 2019 21:43:51 +0000 (UTC) Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1731556AbfI3Vnu (ORCPT ); Mon, 30 Sep 2019 17:43:50 -0400 Received: from mx2.suse.de ([195.135.220.15]:56848 "EHLO mx1.suse.de" rhost-flags-OK-OK-OK-FAIL) by vger.kernel.org with ESMTP id S1726005AbfI3Vnt (ORCPT ); Mon, 30 Sep 2019 17:43:49 -0400 X-Virus-Scanned: by amavisd-new at test-mx.suse.de Received: from relay2.suse.de (unknown [195.135.220.254]) by mx1.suse.de (Postfix) with ESMTP id 99B50B01F; Mon, 30 Sep 2019 19:16:28 +0000 (UTC) From: Aleksa Sarai To: Ingo Molnar , Peter Zijlstra , Alexander Shishkin , Jiri Olsa , Namhyung Kim , Christian Brauner , Kees Cook Cc: Aleksa Sarai , Rasmus Villemoes , Al Viro , Linus Torvalds , libc-alpha@sourceware.org, linux-api@vger.kernel.org, linux-kernel@vger.kernel.org Subject: [PATCH RESEND v3 0/4] lib: introduce copy_struct_from_user() helper Date: Tue, 1 Oct 2019 05:15:22 +1000 Message-Id: <20190930191526.19544-1-asarai@suse.de> X-Mailer: git-send-email 2.23.0 MIME-Version: 1.0 Content-Transfer-Encoding: 8bit Sender: linux-kernel-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org From: Aleksa Sarai Patch changelog: v3: [] * Rename is_zeroed_user() to check_zeroed_user(). [Christian Brauner] * Various minor cleanups. [Christian Brauner] * Add copy_struct_from_user() tests. v2: v1: This series was split off from the openat2(2) syscall discussion[1]. However, the copy_struct_to_user() helper has been dropped, because after some discussion it appears that there is no really obvious semantics for how copy_struct_to_user() should work on mixed-vintages (for instance, whether [2] is the correct semantics for all syscalls). A common pattern for syscall extensions is increasing the size of a struct passed from userspace, such that the zero-value of the new fields result in the old kernel behaviour (allowing for a mix of userspace and kernel vintages to operate on one another in most cases). Previously there was no common lib/ function that implemented the necessary extension-checking semantics (and different syscalls implemented them slightly differently or incompletely[3]). This series implements the helper and ports several syscalls to use it. Some in-kernel selftests are included in this patch. More complete self-tests for copy_struct_from_user() are included in the openat2() patchset. [1]: https://lore.kernel.org/lkml/20190904201933.10736-1-cyphar@cyphar.com/ [2]: commit 1251201c0d34 ("sched/core: Fix uclamp ABI bug, clean up and robustify sched_read_attr() ABI logic and code") [3]: For instance {sched_setattr,perf_event_open,clone3}(2) all do do similar checks to copy_struct_from_user() while rt_sigprocmask(2) always rejects differently-sized struct arguments. Aleksa Sarai (4): lib: introduce copy_struct_from_user() helper clone3: switch to copy_struct_from_user() sched_setattr: switch to copy_struct_from_user() perf_event_open: switch to copy_struct_from_user() include/linux/bitops.h | 7 ++ include/linux/uaccess.h | 4 ++ include/uapi/linux/sched.h | 2 + kernel/events/core.c | 47 +++---------- kernel/fork.c | 34 ++-------- kernel/sched/core.c | 43 ++---------- lib/strnlen_user.c | 8 +-- lib/test_user_copy.c | 133 +++++++++++++++++++++++++++++++++++-- lib/usercopy.c | 123 ++++++++++++++++++++++++++++++++++ 9 files changed, 287 insertions(+), 114 deletions(-) -- 2.23.0