All of lore.kernel.org
 help / color / mirror / Atom feed
From: Greg KH <gregkh@suse.de>
To: linux-kernel@vger.kernel.org, stable@kernel.org
Cc: Justin Forbes <jmforbes@linuxtx.org>,
	Zwane Mwaikambo <zwane@arm.linux.org.uk>,
	"Theodore Ts'o" <tytso@mit.edu>,
	Randy Dunlap <rdunlap@xenotime.net>,
	Dave Jones <davej@redhat.com>,
	Chuck Wolber <chuckw@quantumlinux.com>,
	Chris Wedgwood <reviews@ml.cw.f00f.org>,
	Michael Krufky <mkrufky@linuxtv.org>,
	Chuck Ebbert <cebbert@redhat.com>,
	Domenico Andreoli <cavokz@gmail.com>, Willy Tarreau <w@1wt.eu>,
	Rodrigo Rubira Branco <rbranco@la.checkpoint.com>,
	Jake Edge <jake@lwn.net>, Eugene Teo <eteo@redhat.com>,
	torvalds@linux-foundation.org, akpm@linux-foundation.org,
	alan@lxorguk.ukuu.org.uk, benh@kernel.crashing.org,
	Josh Boyer <jwboyer@linux.vnet.ibm.com>
Subject: [patch 46/58] powerpc: Sanitize stack pointer in signal handling code
Date: Wed, 29 Apr 2009 15:07:45 -0700	[thread overview]
Message-ID: <20090429220929.842695986@mini.kroah.org> (raw)
In-Reply-To: <20090429221657.GA11765@kroah.com>

[-- Attachment #1: powerpc-sanitize-stack-pointer-in-signal-handling-code.patch --]
[-- Type: text/plain, Size: 3977 bytes --]

2.6.27-stable review patch.  If anyone has any objections, please let us know.

------------------

From: Josh Boyer <jwboyer@linux.vnet.ibm.com>

This has been backported to 2.6.27.x from commit efbda86098 in Linus' tree.

On powerpc64 machines running 32-bit userspace, we can get garbage bits in the
stack pointer passed into the kernel.  Most places handle this correctly, but
the signal handling code uses the passed value directly for allocating signal
stack frames.

This fixes the issue by introducing a get_clean_sp function that returns a
sanitized stack pointer.  For 32-bit tasks on a 64-bit kernel, the stack
pointer is masked correctly.  In all other cases, the stack pointer is simply
returned.

Additionally, we pass an 'is_32' parameter to get_sigframe now in order to
get the properly sanitized stack.  The callers are know to be 32 or 64-bit
statically.

Signed-off-by: Josh Boyer <jwboyer@linux.vnet.ibm.com>
Signed-off-by: Benjamin Herrenschmidt <benh@kernel.crashing.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>

---
 arch/powerpc/include/asm/processor.h |   19 +++++++++++++++++++
 arch/powerpc/kernel/signal.c         |    4 ++--
 arch/powerpc/kernel/signal.h         |    2 +-
 arch/powerpc/kernel/signal_32.c      |    4 ++--
 arch/powerpc/kernel/signal_64.c      |    2 +-
 5 files changed, 25 insertions(+), 6 deletions(-)

--- a/arch/powerpc/include/asm/processor.h
+++ b/arch/powerpc/include/asm/processor.h
@@ -309,6 +309,25 @@ static inline void prefetchw(const void 
 #define HAVE_ARCH_PICK_MMAP_LAYOUT
 #endif
 
+#ifdef CONFIG_PPC64
+static inline unsigned long get_clean_sp(struct pt_regs *regs, int is_32)
+{
+	unsigned long sp;
+
+	if (is_32)
+		sp = regs->gpr[1] & 0x0ffffffffUL;
+	else
+		sp = regs->gpr[1];
+
+	return sp;
+}
+#else
+static inline unsigned long get_clean_sp(struct pt_regs *regs, int is_32)
+{
+	return regs->gpr[1];
+}
+#endif
+
 #endif /* __KERNEL__ */
 #endif /* __ASSEMBLY__ */
 #endif /* _ASM_POWERPC_PROCESSOR_H */
--- a/arch/powerpc/kernel/signal_32.c
+++ b/arch/powerpc/kernel/signal_32.c
@@ -836,7 +836,7 @@ int handle_rt_signal32(unsigned long sig
 
 	/* Set up Signal Frame */
 	/* Put a Real Time Context onto stack */
-	rt_sf = get_sigframe(ka, regs, sizeof(*rt_sf));
+	rt_sf = get_sigframe(ka, regs, sizeof(*rt_sf), 1);
 	addr = rt_sf;
 	if (unlikely(rt_sf == NULL))
 		goto badframe;
@@ -1170,7 +1170,7 @@ int handle_signal32(unsigned long sig, s
 	unsigned long newsp = 0;
 
 	/* Set up Signal Frame */
-	frame = get_sigframe(ka, regs, sizeof(*frame));
+	frame = get_sigframe(ka, regs, sizeof(*frame), 1);
 	if (unlikely(frame == NULL))
 		goto badframe;
 	sc = (struct sigcontext __user *) &frame->sctx;
--- a/arch/powerpc/kernel/signal_64.c
+++ b/arch/powerpc/kernel/signal_64.c
@@ -404,7 +404,7 @@ int handle_rt_signal64(int signr, struct
 	unsigned long newsp = 0;
 	long err = 0;
 
-	frame = get_sigframe(ka, regs, sizeof(*frame));
+	frame = get_sigframe(ka, regs, sizeof(*frame), 0);
 	if (unlikely(frame == NULL))
 		goto badframe;
 
--- a/arch/powerpc/kernel/signal.c
+++ b/arch/powerpc/kernel/signal.c
@@ -26,12 +26,12 @@ int show_unhandled_signals = 0;
  * Allocate space for the signal frame
  */
 void __user * get_sigframe(struct k_sigaction *ka, struct pt_regs *regs,
-			   size_t frame_size)
+			   size_t frame_size, int is_32)
 {
         unsigned long oldsp, newsp;
 
         /* Default to using normal stack */
-        oldsp = regs->gpr[1];
+        oldsp = get_clean_sp(regs, is_32);
 
 	/* Check for alt stack */
 	if ((ka->sa.sa_flags & SA_ONSTACK) &&
--- a/arch/powerpc/kernel/signal.h
+++ b/arch/powerpc/kernel/signal.h
@@ -13,7 +13,7 @@
 #define _BLOCKABLE (~(sigmask(SIGKILL) | sigmask(SIGSTOP)))
 
 extern void __user * get_sigframe(struct k_sigaction *ka, struct pt_regs *regs,
-				  size_t frame_size);
+				  size_t frame_size, int is_32);
 extern void restore_sigmask(sigset_t *set);
 
 extern int handle_signal32(unsigned long sig, struct k_sigaction *ka,



  parent reply	other threads:[~2009-04-29 22:39 UTC|newest]

Thread overview: 65+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
     [not found] <20090429220659.339950874@mini.kroah.org>
     [not found] ` <20090429221657.GA11765-U8xfFu+wG4EAvxtiuMwx3w@public.gmane.org>
2009-04-29 22:07   ` [patch 29/58] sched: do not count frozen tasks toward load Greg KH
2009-04-29 22:07     ` Greg KH
2009-04-29 22:16 ` [patch 00/58] 2.6.27-stable review Greg KH
2009-04-29 22:07   ` [patch 01/58] USB: EHCI: add software retry for transaction errors Greg KH
2009-04-29 22:07   ` [patch 02/58] USB: fix USB_STORAGE_CYPRESS_ATACB Greg KH
2009-04-29 22:07   ` [patch 03/58] USB: usb-storage: increase max_sectors for tape drives Greg KH
2009-04-29 22:07   ` [patch 04/58] USB: gadget: fix rndis regression Greg KH
2009-04-29 22:07   ` [patch 05/58] cifs: fix buffer format byte on NT Rename/hardlink Greg KH
2009-04-29 22:07   ` [patch 06/58] b43: fix b43_plcp_get_bitrate_idx_ofdm return type Greg KH
2009-04-29 22:07   ` [patch 07/58] CIFS: Fix memory overwrite when saving nativeFileSystem field during mount Greg KH
2009-04-29 22:07   ` [patch 08/58] Add a missing unlock_kernel() in raw_open() Greg KH
2009-04-29 22:07   ` [patch 09/58] x86, PAT, PCI: Change vma prot in pci_mmap to reflect inherited prot Greg KH
2009-04-29 22:07   ` [patch 10/58] x86: mtrr: dont modify RdDram/WrDram bits of fixed MTRRs Greg KH
2009-04-29 22:07   ` [patch 11/58] bas_gigaset: correctly allocate USB interrupt transfer buffer Greg KH
2009-04-29 22:07   ` [patch 12/58] bonding: Fix updating of speed/duplex changes Greg KH
2009-04-29 22:07   ` [patch 13/58] bridge: bad error handling when adding invalid ether address Greg KH
2009-04-29 22:07   ` [patch 14/58] ipv6: dont use tw net when accounting for recycled tw Greg KH
2009-04-29 22:07   ` [patch 15/58] ipv6: Plug sk_buff leak in ipv6_rcv (net/ipv6/ip6_input.c) Greg KH
2009-04-29 22:07   ` [patch 16/58] netfilter: nf_conntrack_tcp: fix unaligned memory access in tcp_sack Greg KH
2009-04-29 22:07   ` [patch 17/58] net: fix sctp breakage Greg KH
2009-04-29 22:07   ` [patch 18/58] security/smack: fix oops when setting a size 0 SMACK64 xattr Greg KH
2009-04-29 22:07   ` [patch 19/58] x86, setup: mark %esi as clobbered in E820 BIOS call Greg KH
2009-04-29 22:07   ` [patch 20/58] mm: do_xip_mapping_read: fix length calculation Greg KH
2009-04-29 22:07   ` [patch 21/58] vfs: skip I_CLEAR state inodes Greg KH
2009-04-29 22:07   ` [patch 22/58] af_rose/x25: Sanity check the maximum user frame size Greg KH
2009-04-29 22:07   ` [patch 23/58] net/netrom: Fix socket locking Greg KH
2009-04-29 22:07   ` [patch 24/58] netfilter: {ip, ip6, arp}_tables: fix incorrect loop detection Greg KH
2009-04-29 22:07   ` [patch 25/58] splice: fix deadlock in splicing to file Greg KH
2009-04-29 22:07   ` [patch 26/58] ALSA: hda - add missing comma in ad1884_slave_vols Greg KH
2009-04-29 22:07   ` [patch 27/58] SCSI: libiscsi: fix iscsi pool error path Greg KH
2009-04-29 22:07   ` [patch 28/58] SCSI: libiscsi: fix iscsi pool error path again Greg KH
2009-04-29 22:07   ` [patch 29/58] sched: do not count frozen tasks toward load Greg KH
2009-04-29 22:07   ` [patch 30/58] add some long-missing capabilities to fs_mask Greg KH
2009-04-29 22:07   ` [patch 31/58] powerpc: Fix data-corrupting bug in __futex_atomic_op Greg KH
2009-04-29 22:07   ` [patch 32/58] hpt366: fix HPT370 DMA timeouts Greg KH
2009-04-29 22:07   ` [patch 33/58] pata_hpt37x: " Greg KH
2009-04-29 22:07   ` [patch 34/58] usb gadget: fix ethernet link reports to ethtool Greg KH
2009-04-29 22:07   ` [patch 35/58] USB: ftdi_sio: add vendor/project id for JETI specbos 1201 spectrometer Greg KH
2009-04-29 22:07   ` [patch 36/58] USB: fix oops in cdc-wdm in case of malformed descriptors Greg KH
2009-04-29 22:07   ` [patch 37/58] USB: usb-storage: augment unusual_devs entry for Simple Tech/Datafab Greg KH
2009-04-29 22:07   ` [patch 38/58] agp: zero pages before sending to userspace Greg KH
2009-04-29 22:07   ` [patch 39/58] hugetlbfs: return negative error code for bad mount option Greg KH
2009-04-29 22:07   ` [patch 40/58] kprobes: Fix locking imbalance in kretprobes Greg KH
2009-04-29 22:07   ` [patch 41/58] block: revert part of 18ce3751ccd488c78d3827e9f6bf54e6322676fb Greg KH
2009-04-29 22:07   ` [patch 42/58] r8169: Dont update statistics counters when interface is down Greg KH
2009-04-29 22:07   ` [patch 43/58] r8169: use hardware auto-padding Greg KH
2009-04-29 22:07   ` [patch 44/58] r8169: reset IntrStatus after chip reset Greg KH
2009-04-29 22:07   ` [patch 45/58] mm: check for no mmaps in exit_mmap() Greg KH
2009-04-29 22:07   ` Greg KH [this message]
2009-04-29 22:07   ` [ath9k-devel] [patch 47/58] ath9k: implement IO serialization Greg KH
2009-04-29 22:07     ` Greg KH
2009-04-29 22:07     ` Greg KH
2009-04-29 22:07   ` [ath9k-devel] [patch 48/58] ath9k: AR9280 PCI devices must serialize IO as well Greg KH
2009-04-29 22:07     ` Greg KH
2009-04-29 22:07     ` Greg KH
2009-04-29 22:07   ` [patch 49/58] b44: Use kernel DMA addresses for the kernel DMA API Greg KH
2009-04-29 22:07   ` [patch 50/58] crypto: ixp4xx - Fix handling of chained sg buffers Greg KH
2009-04-29 22:07   ` [patch 51/58] exit_notify: kill the wrong capable(CAP_KILL) check (CVE-2009-1337) Greg KH
2009-04-29 22:07   ` [patch 52/58] fix ptrace slowness Greg KH
2009-04-29 22:07   ` [patch 53/58] fs core fixes Greg KH
2009-04-29 22:07   ` [patch 54/58] PCI: fix incorrect mask of PM No_Soft_Reset bit Greg KH
2009-04-29 22:07   ` [patch 55/58] thinkpad-acpi: fix LED blinking through timer trigger Greg KH
2009-04-29 22:07   ` [patch 56/58] ACPI: EC: Add some basic check for ECDT data Greg KH
2009-04-29 22:07   ` [patch 57/58] ACPI: EC: fix compilation warning Greg KH
2009-04-29 22:07   ` [patch 58/58] unreached code in selinux_ip_postroute_iptables_compat() (CVE-2009-1184) Greg KH

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20090429220929.842695986@mini.kroah.org \
    --to=gregkh@suse.de \
    --cc=akpm@linux-foundation.org \
    --cc=alan@lxorguk.ukuu.org.uk \
    --cc=benh@kernel.crashing.org \
    --cc=cavokz@gmail.com \
    --cc=cebbert@redhat.com \
    --cc=chuckw@quantumlinux.com \
    --cc=davej@redhat.com \
    --cc=eteo@redhat.com \
    --cc=jake@lwn.net \
    --cc=jmforbes@linuxtx.org \
    --cc=jwboyer@linux.vnet.ibm.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=mkrufky@linuxtv.org \
    --cc=rbranco@la.checkpoint.com \
    --cc=rdunlap@xenotime.net \
    --cc=reviews@ml.cw.f00f.org \
    --cc=stable@kernel.org \
    --cc=torvalds@linux-foundation.org \
    --cc=tytso@mit.edu \
    --cc=w@1wt.eu \
    --cc=zwane@arm.linux.org.uk \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.