[PATCH 1/4] signals/sigaltstack: If SS_AUTODISARM, bypass on_sig_stack
STALE3793d
From: Andy Lutomirski <luto@kernel.org>
Date: 2016-05-03 17:32:12
Also in:
lkml
Subsystem:
scheduler, the rest · Maintainers:
Ingo Molnar, Peter Zijlstra, Juri Lelli, Vincent Guittot, Linus Torvalds
If a signal stack is set up with SS_AUTODISARM, then the kernel inherently avoids incorrectly resetting the signal stack if signals recurse: the signal stack will be reset on the first signal delivery. This means that we don't need check the stack pointer when delivering signals if SS_AUTODISARM is set. This will make segmented x86 programs more robust: currently there's a hole that could be triggered if ESP/RSP appears to point to the signal stack but actually doesn't due to a nonzero SS base. Signed-off-by: Stas Sergeev <redacted> Cc: Al Viro <viro@zeniv.linux.org.uk> Cc: Aleksa Sarai <redacted> Cc: Amanieu d'Antras <redacted> Cc: Andrea Arcangeli <redacted> Cc: Andrew Morton <akpm@linux-foundation.org> Cc: Andy Lutomirski <luto@amacapital.net> Cc: Borislav Petkov <bp@alien8.de> Cc: Brian Gerst <redacted> Cc: Denys Vlasenko <redacted> Cc: Eric W. Biederman <redacted> Cc: Frederic Weisbecker <redacted> Cc: H. Peter Anvin <hpa@zytor.com> Cc: Heinrich Schuchardt <redacted> Cc: Jason Low <redacted> Cc: Josh Triplett <josh@joshtriplett.org> Cc: Konstantin Khlebnikov <redacted> Cc: Linus Torvalds <torvalds@linux-foundation.org> Cc: Oleg Nesterov <oleg@redhat.com> Cc: Palmer Dabbelt <palmer@dabbelt.com> Cc: Paul Moore <redacted> Cc: Pavel Emelyanov <redacted> Cc: Peter Zijlstra <peterz@infradead.org> Cc: Richard Weinberger <richard@nod.at> Cc: Sasha Levin <redacted> Cc: Shuah Khan <redacted> Cc: Tejun Heo <tj@kernel.org> Cc: Thomas Gleixner <redacted> Cc: Vladimir Davydov <redacted> Cc: linux-api@vger.kernel.org Cc: linux-kernel@vger.kernel.org Signed-off-by: Andy Lutomirski <luto@kernel.org> --- include/linux/sched.h | 12 ++++++++++++ 1 file changed, 12 insertions(+)
diff --git a/include/linux/sched.h b/include/linux/sched.h
index 2950c5cd3005..8f03a93348b9 100644
--- a/include/linux/sched.h
+++ b/include/linux/sched.h@@ -2576,6 +2576,18 @@ static inline int kill_cad_pid(int sig, int priv) */ static inline int on_sig_stack(unsigned long sp) { + /* + * If the signal stack is AUTODISARM then, by construction, we + * can't be on the signal stack unless user code deliberately set + * SS_AUTODISARM when we were already on the it. + * + * This improve reliability: if user state gets corrupted such that + * the stack pointer points very close to the end of the signal stack, + * then this check will enable the signal to be handled anyway. + */ + if (current->sas_ss_flags & SS_AUTODISARM) + return 0; + #ifdef CONFIG_STACK_GROWSUP return sp >= current->sas_ss_sp && sp - current->sas_ss_sp < current->sas_ss_size;
--
2.5.5