From: Ben Hutchings <ben@decadent.org.uk>
To: linux-kernel@vger.kernel.org, stable@vger.kernel.org
Cc: akpm@linux-foundation.org, "Eric W. Biederman" <ebiederm@xmission.com>
Subject: [PATCH 3.2 03/61] fcntl: Don't use ambiguous SIG_POLL si_codes
Date: Wed, 22 Nov 2017 02:11:05 +0000 [thread overview]
Message-ID: <lsq.1511316665.197675207@decadent.org.uk> (raw)
In-Reply-To: <lsq.1511316665.221837797@decadent.org.uk>
3.2.96-rc1 review patch. If anyone has any objections, please let me know.
------------------
From: "Eric W. Biederman" <ebiederm@xmission.com>
commit d08477aa975e97f1dc64c0ae59cebf98520456ce upstream.
We have a weird and problematic intersection of features that when
they all come together result in ambiguous siginfo values, that
we can not support properly.
- Supporting fcntl(F_SETSIG,...) with arbitrary valid signals.
- Using positive values for POLL_IN, POLL_OUT, POLL_MSG, ..., etc
that imply they are signal specific si_codes and using the
aforementioned arbitrary signal to deliver them.
- Supporting injection of arbitrary siginfo values for debugging and
checkpoint/restore.
The result is that just looking at siginfo si_codes of 1 to 6 are
ambigious. It could either be a signal specific si_code or it could
be a generic si_code.
For most of the kernel this is a non-issue but for sending signals
with siginfo it is impossible to play back the kernel signals and
get the same result.
Strictly speaking when the si_code was changed from SI_SIGIO to
POLL_IN and friends between 2.2 and 2.4 this functionality was not
ambiguous, as only real time signals were supported. Before 2.4 was
released the kernel began supporting siginfo with non realtime signals
so they could give details of why the signal was sent.
The result is that if F_SETSIG is set to one of the signals with signal
specific si_codes then user space can not know why the signal was sent.
I grepped through a bunch of userspace programs using debian code
search to get a feel for how often people choose a signal that results
in an ambiguous si_code. I only found one program doing so and it was
using SIGCHLD to test the F_SETSIG functionality, and did not appear
to be a real world usage.
Therefore the ambiguity does not appears to be a real world problem in
practice. Remove the ambiguity while introducing the smallest chance
of breakage by changing the si_code to SI_SIGIO when signals with
signal specific si_codes are targeted.
Fixes: v2.3.40 -- Added support for queueing non-rt signals
Fixes: v2.3.21 -- Changed the si_code from SI_SIGIO
Signed-off-by: "Eric W. Biederman" <ebiederm@xmission.com>
[bwh: Backported to 3.2: adjust filename]
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
fs/fcntl.c | 13 ++++++++++++-
include/asm-generic/siginfo.h | 4 ++--
include/linux/signal.h | 8 ++++++++
3 files changed, 22 insertions(+), 3 deletions(-)
--- a/fs/fcntl.c
+++ b/fs/fcntl.c
@@ -565,10 +565,21 @@ static void send_sigio_to_task(struct ta
si.si_signo = signum;
si.si_errno = 0;
si.si_code = reason;
+ /*
+ * Posix definies POLL_IN and friends to be signal
+ * specific si_codes for SIG_POLL. Linux extended
+ * these si_codes to other signals in a way that is
+ * ambiguous if other signals also have signal
+ * specific si_codes. In that case use SI_SIGIO instead
+ * to remove the ambiguity.
+ */
+ if (sig_specific_sicodes(signum))
+ si.si_code = SI_SIGIO;
+
/* Make sure we are called with one of the POLL_*
reasons, otherwise we could leak kernel stack into
userspace. */
- BUG_ON((reason & __SI_MASK) != __SI_POLL);
+ BUG_ON((reason < POLL_IN) || ((reason - POLL_IN) >= NSIGPOLL));
if (reason - POLL_IN >= NSIGPOLL)
si.si_band = ~0L;
else
--- a/include/asm-generic/siginfo.h
+++ b/include/asm-generic/siginfo.h
@@ -148,7 +148,7 @@ typedef struct siginfo {
#define SI_TIMER __SI_CODE(__SI_TIMER,-2) /* sent by timer expiration */
#define SI_MESGQ __SI_CODE(__SI_MESGQ,-3) /* sent by real time mesq state change */
#define SI_ASYNCIO -4 /* sent by AIO completion */
-#define SI_SIGIO -5 /* sent by queued SIGIO */
+#define SI_SIGIO __SI_CODE(__SI_POLL,-5) /* sent by queued SIGIO */
#define SI_TKILL -6 /* sent by tkill system call */
#define SI_DETHREAD -7 /* sent by execve() killing subsidiary threads */
@@ -221,7 +221,7 @@ typedef struct siginfo {
#define NSIGCHLD 6
/*
- * SIGPOLL si_codes
+ * SIGPOLL (or any other signal without signal specific si_codes) si_codes
*/
#define POLL_IN (__SI_POLL|1) /* data input available */
#define POLL_OUT (__SI_POLL|2) /* output buffers available */
--- a/include/linux/signal.h
+++ b/include/linux/signal.h
@@ -368,10 +368,18 @@ int unhandled_signal(struct task_struct
rt_sigmask(SIGCONT) | rt_sigmask(SIGCHLD) | \
rt_sigmask(SIGWINCH) | rt_sigmask(SIGURG) )
+#define SIG_SPECIFIC_SICODES_MASK (\
+ rt_sigmask(SIGILL) | rt_sigmask(SIGFPE) | \
+ rt_sigmask(SIGSEGV) | rt_sigmask(SIGBUS) | \
+ rt_sigmask(SIGTRAP) | rt_sigmask(SIGCHLD) | \
+ rt_sigmask(SIGPOLL) | rt_sigmask(SIGSYS) | \
+ SIGEMT_MASK )
+
#define sig_kernel_only(sig) siginmask(sig, SIG_KERNEL_ONLY_MASK)
#define sig_kernel_coredump(sig) siginmask(sig, SIG_KERNEL_COREDUMP_MASK)
#define sig_kernel_ignore(sig) siginmask(sig, SIG_KERNEL_IGNORE_MASK)
#define sig_kernel_stop(sig) siginmask(sig, SIG_KERNEL_STOP_MASK)
+#define sig_specific_sicodes(sig) siginmask(sig, SIG_SPECIFIC_SICODES_MASK)
#define sig_user_defined(t, signr) \
(((t)->sighand->action[(signr)-1].sa.sa_handler != SIG_DFL) && \
next prev parent reply other threads:[~2017-11-22 3:06 UTC|newest]
Thread overview: 63+ messages / expand[flat|nested] mbox.gz Atom feed top
2017-11-22 2:11 [PATCH 3.2 00/61] 3.2.96-rc1 review Ben Hutchings
2017-11-22 2:11 ` [PATCH 3.2 02/61] signal: move the "sig < SIGRTMIN" check into siginmask(sig) Ben Hutchings
2017-11-22 2:11 ` [PATCH 3.2 04/61] powerpc/mm: Fix check of multiple 16G pages from device tree Ben Hutchings
2017-11-22 2:11 ` [PATCH 3.2 05/61] PCI: shpchp: Enable bridge bus mastering if MSI is enabled Ben Hutchings
2017-11-22 2:11 ` [PATCH 3.2 07/61] x86/fsgsbase/64: Report FSBASE and GSBASE correctly in core dumps Ben Hutchings
2017-11-22 2:11 ` Ben Hutchings [this message]
2017-11-22 2:11 ` [PATCH 3.2 06/61] dlm: avoid double-free on error path in dlm_device_{register,unregister} Ben Hutchings
2017-11-22 2:11 ` [PATCH 3.2 08/61] scsi: zfcp: fix queuecommand for scsi_eh commands when DIX enabled Ben Hutchings
2017-11-22 2:11 ` [PATCH 3.2 01/61] IB/core: Fix the validations of a multicast LID in attach or detach operations Ben Hutchings
2017-11-22 2:11 ` [PATCH 3.2 61/61] mac80211: Fix null dereference in ieee80211_key_link() Ben Hutchings
2017-11-22 2:11 ` [PATCH 3.2 15/61] scsi: mac_esp: Fix PIO transfers for MESSAGE IN phase Ben Hutchings
2017-11-22 2:11 ` [PATCH 3.2 48/61] smsc95xx: Configure pause time to 0xffff when tx flow control enabled Ben Hutchings
2017-11-22 2:11 ` [PATCH 3.2 23/61] usb: quirks: add delay init quirk for Corsair Strafe RGB keyboard Ben Hutchings
2017-11-22 2:11 ` [PATCH 3.2 29/61] [SCSI] qla2xxx: Add mutex around optrom calls to serialize accesses Ben Hutchings
2017-11-22 2:11 ` [PATCH 3.2 16/61] cs5536: add support for IDE controller variant Ben Hutchings
2017-11-22 2:11 ` [PATCH 3.2 51/61] Input: i8042 - add Gigabyte P57 to the keyboard reset table Ben Hutchings
2017-11-22 2:11 ` [PATCH 3.2 20/61] media: lirc_zilog: driver only sends LIRCCODE Ben Hutchings
2017-11-22 2:11 ` [PATCH 3.2 21/61] media: em28xx: calculate left volume level correctly Ben Hutchings
2017-11-22 2:11 ` [PATCH 3.2 55/61] USB: serial: console: fix use-after-free after failed setup Ben Hutchings
2017-11-22 2:11 ` [PATCH 3.2 43/61] ipv6: fix typo in fib6_net_exit() Ben Hutchings
2017-11-22 2:11 ` [PATCH 3.2 50/61] KVM: async_pf: Fix #DF due to inject "Page not Present" and "Page Ready" exceptions simultaneously Ben Hutchings
2017-11-22 2:11 ` [PATCH 3.2 24/61] usb: Add device quirk for Logitech HD Pro Webcam C920-C Ben Hutchings
2017-11-22 2:11 ` [PATCH 3.2 36/61] l2tp: prevent creation of sessions on terminated tunnels Ben Hutchings
2017-11-22 2:11 ` [PATCH 3.2 60/61] mac80211: don't compare TKIP TX MIC key in reinstall prevention Ben Hutchings
2017-11-22 2:11 ` [PATCH 3.2 53/61] ext4: fix fencepost in s_first_meta_bg validation Ben Hutchings
2017-11-22 2:11 ` [PATCH 3.2 10/61] scsi: zfcp: fix capping of unsuccessful GPN_FT SAN response trace records Ben Hutchings
2017-11-22 2:11 ` [PATCH 3.2 56/61] [media] cx231xx-cards: fix NULL-deref on missing association descriptor Ben Hutchings
2017-11-22 2:11 ` [PATCH 3.2 11/61] scsi: zfcp: fix passing fsf_req to SCSI trace on TMF to correlate with HBA Ben Hutchings
2017-11-22 2:11 ` [PATCH 3.2 49/61] KVM: SVM: Add a missing 'break' statement Ben Hutchings
2017-11-22 2:11 ` [PATCH 3.2 59/61] net: cdc_ether: fix divide by 0 on bad descriptors Ben Hutchings
2017-11-22 2:11 ` [PATCH 3.2 52/61] ext4: validate s_first_meta_bg at mount time Ben Hutchings
2017-11-22 2:11 ` [PATCH 3.2 40/61] mm/vmstat.c: fix wrong comment Ben Hutchings
2017-11-22 2:11 ` [PATCH 3.2 34/61] ftrace: Fix selftest goto location on error Ben Hutchings
2017-11-22 2:11 ` [PATCH 3.2 22/61] USB: core: Avoid race of async_completed() w/ usbdev_release() Ben Hutchings
2017-11-22 2:11 ` [PATCH 3.2 41/61] genirq: Make sparse_irq_lock protect what it should protect Ben Hutchings
2017-11-22 2:11 ` [PATCH 3.2 38/61] MIPS: AR7: allow NULL clock for clk_get_rate Ben Hutchings
2017-11-22 2:11 ` [PATCH 3.2 37/61] l2tp: pass tunnel pointer to ->session_create() Ben Hutchings
2017-11-22 2:11 ` [PATCH 3.2 30/61] scsi: qla2xxx: Fix an integer overflow in sysfs code Ben Hutchings
2017-11-22 2:11 ` [PATCH 3.2 26/61] net/mlx4_core: Make explicit conversion to 64bit value Ben Hutchings
2017-11-22 2:11 ` [PATCH 3.2 28/61] [SCSI] qla2xxx: Corrections to returned sysfs error codes Ben Hutchings
2017-11-22 2:11 ` [PATCH 3.2 32/61] powerpc: Correct instruction code for xxlor instruction Ben Hutchings
2017-11-22 2:11 ` [PATCH 3.2 57/61] media: imon: Fix null-ptr-deref in imon_probe Ben Hutchings
2017-11-22 2:11 ` [PATCH 3.2 27/61] scsi: aacraid: Fix command send race condition Ben Hutchings
2017-11-22 2:11 ` [PATCH 3.2 13/61] scsi: zfcp: fix payload with full FCP_RSP IU in SCSI trace records Ben Hutchings
2017-11-22 2:11 ` [PATCH 3.2 54/61] sctp: do not peel off an assoc from one netns to another one Ben Hutchings
2017-11-22 2:11 ` [PATCH 3.2 44/61] Input: xpad - add a few new VID/PID combinations Ben Hutchings
2017-11-22 2:11 ` [PATCH 3.2 47/61] Input: xpad - validate USB endpoint type during probe Ben Hutchings
2017-11-22 2:11 ` [PATCH 3.2 12/61] scsi: zfcp: fix missing trace records for early returns in TMF eh handlers Ben Hutchings
2017-11-22 2:11 ` [PATCH 3.2 19/61] media: uvcvideo: Prevent heap overflow when accessing mapped controls Ben Hutchings
2017-11-22 2:11 ` [PATCH 3.2 39/61] MIPS: BCM63XX: allow NULL clock for clk_get_rate Ben Hutchings
2017-11-22 2:11 ` [PATCH 3.2 58/61] Input: gtco - fix potential out-of-bound access Ben Hutchings
2017-11-22 2:11 ` [PATCH 3.2 09/61] scsi: zfcp: add handling for FCP_RESID_OVER to the fcp ingress path Ben Hutchings
2017-11-22 2:11 ` [PATCH 3.2 42/61] ipv6: fix memory leak with multiple tables during netns destruction Ben Hutchings
2017-11-22 2:11 ` [PATCH 3.2 45/61] Input: xpad - add support for Xbox One controllers Ben Hutchings
2017-11-22 2:11 ` [PATCH 3.2 17/61] drm/ttm: Fix accounting error when fail to get pages for pool Ben Hutchings
2017-11-22 2:11 ` [PATCH 3.2 14/61] scsi: zfcp: trace HBA FSF response by default on dismiss or timedout late response Ben Hutchings
2017-11-22 2:11 ` [PATCH 3.2 31/61] powerpc/44x: Fix mask and shift to zero bug Ben Hutchings
2017-11-22 2:11 ` [PATCH 3.2 25/61] IB/{qib, hfi1}: Avoid flow control testing for RDMA write operation Ben Hutchings
2017-11-22 2:11 ` [PATCH 3.2 33/61] driver core: bus: Fix a potential double free Ben Hutchings
2017-11-22 2:11 ` [PATCH 3.2 18/61] block: Relax a check in blk_start_queue() Ben Hutchings
2017-11-22 2:11 ` [PATCH 3.2 35/61] xfs: fix incorrect log_flushed on fsync Ben Hutchings
2017-11-22 2:11 ` [PATCH 3.2 46/61] Input: xpad - don't depend on endpoint order Ben Hutchings
2017-11-22 14:59 ` [PATCH 3.2 00/61] 3.2.96-rc1 review Guenter Roeck
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=lsq.1511316665.197675207@decadent.org.uk \
--to=ben@decadent.org.uk \
--cc=akpm@linux-foundation.org \
--cc=ebiederm@xmission.com \
--cc=linux-kernel@vger.kernel.org \
--cc=stable@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®