Thread (17 messages) flat view 17 messages, 5 authors, 2018-06-29

Re: [RFC PATCH for 4.18 1/2] rseq: validate rseq_cs fields are < TASK_SIZE

From: Mathieu Desnoyers <mathieu.desnoyers@efficios.com>
Date: 2018-06-29 13:55:49
Also in: lkml

----- On Jun 28, 2018, at 7:29 PM, Andy Lutomirski luto@kernel.org wrote:
On Thu, Jun 28, 2018 at 2:22 PM, Linus Torvalds
[off-list ref] wrote:
quoted
On Thu, Jun 28, 2018 at 1:23 PM Andy Lutomirski [off-list ref] wrote:
quoted
This is okay with me for a fix outside the merge window.  Can you do a
followup for the next merge window that fixes it better, though?  In
particular, TASK_SIZE is generally garbage.  I think a better fix
would be something like adding a new arch-overridable helper like:

static inline unsigned long current_max_user_addr(void) { return TASK_SIZE; }
We already have that. It's called "user_addr_max()".
Nah, that one is more or less equivalent to TASK_SIZE_MAX, except that
it's different if set_fs() is used.
So which one would be right in this case ? AFAIU we want to ensure we don't
populate regs->ip with a bogus address that would make SYSRET or other return
to userspace instructions explode.

Is that guaranteed by TASK_SIZE or TASK_SIZE_MAX (aliased by user_addr_max()) ?

Thanks,

Mathieu

-- 
Mathieu Desnoyers
EfficiOS Inc.
http://www.efficios.com
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help