From: Andy Shevchenko <andriy.shevchenko@linux.intel.com>
To: Petr Mladek <pmladek@suse.com>
Cc: Rasmus Villemoes <linux@rasmusvillemoes.dk>,
"Tobin C . Harding" <me@tobin.cc>, Joe Perches <joe@perches.com>,
linux-kernel@vger.kernel.org,
Andrew Morton <akpm@linux-foundation.org>,
Michal Hocko <mhocko@suse.cz>
Subject: Re: [PATCH] vsprintf: Make "null" pointer dereference more robust
Date: Wed, 07 Mar 2018 20:18:09 +0200 [thread overview]
Message-ID: <1520446689.10722.493.camel@linux.intel.com> (raw)
In-Reply-To: <20180307155244.b45c3fb5vcxb4q2l@pathway.suse.cz>
On Wed, 2018-03-07 at 16:52 +0100, Petr Mladek wrote:
> On Tue 2018-03-06 11:56:25, Andy Shevchenko wrote:
> Anyway, I have discussed this with my colleagues. Different people had
> different opinions. But I liked the following.
I discussed as well, and...
> We already prevent crash when derefencing some obviously broken
> pointers. The handling is not consistent. Sometimes we print "(null)"
> only for pure NULL pointer, sometimes for pointers in the first
> page and sometimes also for pointers in the last page (error codes).
> In general, we should do our best to get useful message from printk().
> This patch tries to find a wide range of invalid strings using
> probe_kernel_read(). Also it makes the handling unified. We print:
...they are considering not crashing is a bad idea from debugging point
of view.
So, what is can be done is to:
- print "(null)" only for null pointers
- print error codes for IS_ERR() part
- crash on everything else
which partially what does my patch 1.
> Note that we could not print the exact pointer value from security
> reasons.
If it's invalid we need to fix the code, not to hide a problem, right?
> Developers need print the pointer using %px to get the real value.
But how developer will know (w/o traceback) where to look for?
> + if (probe_kernel_read(&byte, ptr, 1))
> + return "(efault)";
There is couple of flaws here:
- If we asked to print 0 bytes of the value of pointer or something
from extension (%*ph, %*pE, etc), we don't know if pointer valid or not,
because we are going to print nothing. So, for now there is a
ZERO_OR_NULL_PTR() check for them, but in reality I wouldn't know what
the best to do in such case. So, the question is what we would like to
know more: the pointer is invalid, or the spec.width is 0 and caller
doesn't care in this case?
- For IS_ERR() case it might be better to print an actual value of err,
(4 chars + parens + 2 chars left, like (e:dddd) or similar.
Unfortunately it doesn't scale good (ffff is a last error value we may
print). So, perhaps printing as %p in this case is a good enough and
scalable.
--
Andy Shevchenko <andriy.shevchenko@linux.intel.com>
Intel Finland Oy
next prev parent reply other threads:[~2018-03-07 18:18 UTC|newest]
Thread overview: 87+ messages / expand[flat|nested] mbox.gz Atom feed top
2018-02-16 21:07 [PATCH v2 1/9] lib/test_printf: Mark big constant with ULL Andy Shevchenko
2018-02-16 21:07 ` [PATCH v2 2/9] lib/vsprintf: Make dec_spec global Andy Shevchenko
2018-04-11 9:44 ` Petr Mladek
2018-02-16 21:07 ` [PATCH v2 3/9] lib/vsprintf: Make strspec global Andy Shevchenko
2018-04-11 9:44 ` Petr Mladek
2018-02-16 21:07 ` [PATCH v2 4/9] lib/vsprintf: Make flag_spec global Andy Shevchenko
2018-04-11 9:45 ` Petr Mladek
2018-02-16 21:07 ` [PATCH v2 5/9] lib/vsprintf: Move pointer_string() upper Andy Shevchenko
2018-04-11 9:45 ` Petr Mladek
2018-02-16 21:07 ` [PATCH v2 6/9] lib/vsprintf: Deduplicate pointer_string() Andy Shevchenko
2018-04-11 9:46 ` Petr Mladek
2018-02-16 21:07 ` [PATCH v2 7/9] lib/vsprintf: Replace space with '_' before crng is ready Andy Shevchenko
2018-02-20 2:57 ` [此邮件可能存在风险] " Yang, Shunyong
2018-04-11 9:47 ` Petr Mladek
2018-02-16 21:07 ` [PATCH v2 8/9] lib/vsprintf: Remove useless NULL checks Andy Shevchenko
2018-02-27 15:50 ` Petr Mladek
2018-02-27 17:35 ` Andy Shevchenko
2018-02-28 10:04 ` Petr Mladek
2018-02-28 10:42 ` Andy Shevchenko
2018-03-02 12:51 ` Petr Mladek
2018-03-02 12:53 ` [PATCH] vsprintf: Make "null" pointer dereference more robust Petr Mladek
2018-03-02 14:17 ` Andy Shevchenko
2018-03-05 14:53 ` Petr Mladek
2018-03-29 15:13 ` Petr Mladek
2018-03-29 16:11 ` Joe Perches
2018-03-05 15:16 ` Rasmus Villemoes
2018-03-05 15:25 ` Andy Shevchenko
2018-03-06 9:25 ` Petr Mladek
2018-03-06 9:56 ` Andy Shevchenko
2018-03-07 15:52 ` Petr Mladek
2018-03-07 18:18 ` Andy Shevchenko [this message]
2018-03-07 18:34 ` Linus Torvalds
2018-03-08 14:18 ` Petr Mladek
2018-03-08 16:45 ` Linus Torvalds
2018-03-08 17:26 ` Linus Torvalds
2018-03-09 15:01 ` Petr Mladek
2018-03-09 19:05 ` Linus Torvalds
2018-03-14 14:09 ` [PATCH v3] vsprintf: Prevent crash when dereferencing invalid pointers Petr Mladek
2018-03-14 22:12 ` Rasmus Villemoes
2018-03-15 15:07 ` Petr Mladek
2018-03-15 17:07 ` Steven Rostedt
2018-03-15 17:06 ` Steven Rostedt
2018-03-15 0:57 ` Sergey Senozhatsky
2018-03-15 7:58 ` Sergey Senozhatsky
2018-03-15 8:03 ` Sergey Senozhatsky
2018-03-15 17:01 ` Steven Rostedt
2018-03-16 1:18 ` Sergey Senozhatsky
2018-03-16 1:35 ` Linus Torvalds
2018-03-16 5:53 ` Sergey Senozhatsky
2018-03-16 8:55 ` Petr Mladek
2018-03-16 14:32 ` Steven Rostedt
2018-03-17 1:29 ` Sergey Senozhatsky
2018-03-15 13:07 ` Andy Shevchenko
2018-03-15 13:09 ` Andy Shevchenko
2018-03-15 15:26 ` Petr Mladek
2018-03-16 18:19 ` Andy Shevchenko
2018-03-29 14:53 ` Petr Mladek
2018-04-02 14:15 ` Andy Shevchenko
2018-04-03 1:12 ` Sergey Senozhatsky
2018-04-03 11:52 ` Petr Mladek
2018-04-03 11:56 ` Andy Shevchenko
2018-04-03 13:57 ` Sergey Senozhatsky
2018-04-03 11:46 ` Petr Mladek
2018-04-03 11:54 ` Andy Shevchenko
2018-04-03 13:13 ` Petr Mladek
2018-04-03 13:40 ` Andy Shevchenko
2018-04-03 14:50 ` Petr Mladek
2018-03-15 14:48 ` kbuild test robot
2018-03-15 20:26 ` kbuild test robot
2018-03-06 18:11 ` [PATCH 1/2] vsprintf: distinguish between (null), (err) and (invalid) pointer derefs Adam Borowski
2018-03-06 18:11 ` [PATCH 2/2] vsprintf: don't dereference pointers to the first or last page Adam Borowski
2018-03-07 13:22 ` Andy Shevchenko
2018-03-07 13:17 ` [PATCH 1/2] vsprintf: distinguish between (null), (err) and (invalid) pointer derefs Andy Shevchenko
2018-03-07 13:42 ` Adam Borowski
2018-03-07 13:29 ` Andy Shevchenko
2018-03-02 14:15 ` [PATCH v2 8/9] lib/vsprintf: Remove useless NULL checks Andy Shevchenko
2018-03-05 14:57 ` Petr Mladek
2018-02-28 10:44 ` Andy Shevchenko
2018-03-01 14:56 ` Andy Shevchenko
2018-02-16 21:07 ` [PATCH v2 9/9] lib/vsprintf: Mark expected switch fall-through Andy Shevchenko
2018-04-11 9:47 ` Petr Mladek
2018-02-18 12:58 ` [PATCH v2 1/9] lib/test_printf: Mark big constant with ULL Luc Van Oostenryck
2018-02-18 14:20 ` Andy Shevchenko
2018-02-19 15:24 ` Andy Shevchenko
2018-04-11 9:41 ` Petr Mladek
2018-02-18 21:52 ` Tobin C. Harding
2018-02-18 23:55 ` Andy Shevchenko
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=1520446689.10722.493.camel@linux.intel.com \
--to=andriy.shevchenko@linux.intel.com \
--cc=akpm@linux-foundation.org \
--cc=joe@perches.com \
--cc=linux-kernel@vger.kernel.org \
--cc=linux@rasmusvillemoes.dk \
--cc=me@tobin.cc \
--cc=mhocko@suse.cz \
--cc=pmladek@suse.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.