All of lore.kernel.org
 help / color / mirror / Atom feed
From: Sukadev Bhattiprolu <sukadev-23VcF4HTsmIX0ybBhKVfKdBPR1lH4CV8@public.gmane.org>
To: Andrew Morton <akpm-3NddpPZAyC0@public.gmane.org>
Cc: mtk.manpages-gM/Ye1E23mwN+BqQ9rBEUg@public.gmane.org,
	arnd-r2nGTMty4D4@public.gmane.org,
	Containers
	<containers-cunTk1MwBs9QetFLy7KEm3xJsTq8ys+cHZ5vskTnxNA@public.gmane.org>,
	Nathan Lynch <nathanl-V7BBcbaFuwjMbYB6QlFGEg@public.gmane.org>,
	matthltc-npbjlsIvGkV82hYKe6nXyg@public.gmane.org,
	"Eric W. Biederman"
	<ebiederm-aS9lmoZGLiVWk0Htik3J/w@public.gmane.org>,
	hpa-YMNOUZJC4hwAvxtiuMwx3w@public.gmane.org,
	linux-api-u79uwXL29TY76Z2rM5mHXA@public.gmane.org,
	Alexey Dobriyan
	<adobriyan-Re5JQEeQqe8AvxtiuMwx3w@public.gmane.org>,
	roland-H+wXaHxf7aLQT0dZR+AlfA@public.gmane.org,
	Pavel Emelyanov <xemul-GEFAQzZX7r8dnm+yROfE0A@public.gmane.org>,
	linux-kernel-u79uwXL29TY76Z2rM5mHXA@public.gmane.org
Subject: Re: [v12][PATCH 6/9] Check invalid clone flags
Date: Wed, 11 Nov 2009 14:40:20 -0800	[thread overview]
Message-ID: <20091111224020.GG24988@suka> (raw)
In-Reply-To: <20091111044422.GF11393@suka>

Cc: LKML

Sukadev Bhattiprolu [sukadev-23VcF4HTsmIX0ybBhKVfKdBPR1lH4CV8@public.gmane.org] wrote:
| 
| Subject: [v12][PATCH 6/9] Check invalid clone flags
| 
| As pointed out by Oren Laadan, we want to ensure that unused bits in the
| clone-flags remain unused and available for future. To ensure this, define
| a mask of clone-flags and check the flags in the clone() system calls.
| 
| Changelog[v9]:
| 	- Include the unused clone-flag (CLONE_UNUSED) to VALID_CLONE_FLAGS
| 	  to avoid breaking any applications that may have set it. IOW, this
| 	  patch/check only applies to clone-flags bits 33 and higher.
| 
| Changelog[v8]:
| 	- New patch in set
| 
| Signed-off-by: Sukadev Bhattiprolu <sukadev-23VcF4HTsmIX0ybBhKVfKdBPR1lH4CV8@public.gmane.org>
| Acked-by: Oren Laadan <orenl-eQaUEPhvms7ENvBUuze7eA@public.gmane.org>
| ---
|  include/linux/sched.h |   12 ++++++++++++
|  kernel/fork.c         |    3 +++
|  2 files changed, 15 insertions(+), 0 deletions(-)
| 
| diff --git a/include/linux/sched.h b/include/linux/sched.h
| index 75e6e60..a4d2c23 100644
| --- a/include/linux/sched.h
| +++ b/include/linux/sched.h
| @@ -29,6 +29,18 @@
|  #define CLONE_NEWNET		0x40000000	/* New network namespace */
|  #define CLONE_IO		0x80000000	/* Clone io context */
| 
| +#define CLONE_UNUSED        	0x00001000	/* Can be reused ? */
| +
| +#define VALID_CLONE_FLAGS	(CSIGNAL | CLONE_VM | CLONE_FS | CLONE_FILES |\
| +				 CLONE_SIGHAND | CLONE_UNUSED | CLONE_PTRACE |\
| +				 CLONE_VFORK  | CLONE_PARENT | CLONE_THREAD  |\
| +				 CLONE_NEWNS  | CLONE_SYSVSEM | CLONE_SETTLS |\
| +				 CLONE_PARENT_SETTID | CLONE_CHILD_CLEARTID  |\
| +				 CLONE_DETACHED | CLONE_UNTRACED             |\
| +				 CLONE_CHILD_SETTID | CLONE_STOPPED          |\
| +				 CLONE_NEWUTS | CLONE_NEWIPC | CLONE_NEWUSER |\
| +				 CLONE_NEWPID | CLONE_NEWNET | CLONE_IO)
| +
|  /*
|   * Scheduling policies
|   */
| diff --git a/kernel/fork.c b/kernel/fork.c
| index c8a06de..11f77ed 100644
| --- a/kernel/fork.c
| +++ b/kernel/fork.c
| @@ -982,6 +982,9 @@ static struct task_struct *copy_process(unsigned long clone_flags,
|  	struct task_struct *p;
|  	int cgroup_callbacks_done = 0;
| 
| +	if (clone_flags & ~VALID_CLONE_FLAGS)
| +		return ERR_PTR(-EINVAL);
| +
|  	if ((clone_flags & (CLONE_NEWNS|CLONE_FS)) == (CLONE_NEWNS|CLONE_FS))
|  		return ERR_PTR(-EINVAL);
| 
| -- 
| 1.6.0.4
| 
| _______________________________________________
| Containers mailing list
| Containers-cunTk1MwBs9QetFLy7KEm3xJsTq8ys+cHZ5vskTnxNA@public.gmane.org
| https://lists.linux-foundation.org/mailman/listinfo/containers

WARNING: multiple messages have this Message-ID (diff)
From: Sukadev Bhattiprolu <sukadev@linux.vnet.ibm.com>
To: Andrew Morton <akpm@osdl.org>
Cc: mtk.manpages@googlemail.com, arnd@arndb.de,
	Containers <containers@lists.linux-foundation.org>,
	Nathan Lynch <nathanl@austin.ibm.com>,
	matthltc@suka.localdomain,
	"Eric W. Biederman" <ebiederm@xmission.com>,
	hpa@zytor.com, linux-api@vger.kernel.org,
	Alexey Dobriyan <adobriyan@gmail.com>,
	roland@redhat.com, Pavel Emelyanov <xemul@openvz.org>,
	linux-kernel@vger.kernel.org
Subject: Re: [v12][PATCH 6/9] Check invalid clone flags
Date: Wed, 11 Nov 2009 14:40:20 -0800	[thread overview]
Message-ID: <20091111224020.GG24988@suka> (raw)
In-Reply-To: <20091111044422.GF11393@suka>

Cc: LKML

Sukadev Bhattiprolu [sukadev@linux.vnet.ibm.com] wrote:
| 
| Subject: [v12][PATCH 6/9] Check invalid clone flags
| 
| As pointed out by Oren Laadan, we want to ensure that unused bits in the
| clone-flags remain unused and available for future. To ensure this, define
| a mask of clone-flags and check the flags in the clone() system calls.
| 
| Changelog[v9]:
| 	- Include the unused clone-flag (CLONE_UNUSED) to VALID_CLONE_FLAGS
| 	  to avoid breaking any applications that may have set it. IOW, this
| 	  patch/check only applies to clone-flags bits 33 and higher.
| 
| Changelog[v8]:
| 	- New patch in set
| 
| Signed-off-by: Sukadev Bhattiprolu <sukadev@linux.vnet.ibm.com>
| Acked-by: Oren Laadan <orenl@cs.columbia.edu>
| ---
|  include/linux/sched.h |   12 ++++++++++++
|  kernel/fork.c         |    3 +++
|  2 files changed, 15 insertions(+), 0 deletions(-)
| 
| diff --git a/include/linux/sched.h b/include/linux/sched.h
| index 75e6e60..a4d2c23 100644
| --- a/include/linux/sched.h
| +++ b/include/linux/sched.h
| @@ -29,6 +29,18 @@
|  #define CLONE_NEWNET		0x40000000	/* New network namespace */
|  #define CLONE_IO		0x80000000	/* Clone io context */
| 
| +#define CLONE_UNUSED        	0x00001000	/* Can be reused ? */
| +
| +#define VALID_CLONE_FLAGS	(CSIGNAL | CLONE_VM | CLONE_FS | CLONE_FILES |\
| +				 CLONE_SIGHAND | CLONE_UNUSED | CLONE_PTRACE |\
| +				 CLONE_VFORK  | CLONE_PARENT | CLONE_THREAD  |\
| +				 CLONE_NEWNS  | CLONE_SYSVSEM | CLONE_SETTLS |\
| +				 CLONE_PARENT_SETTID | CLONE_CHILD_CLEARTID  |\
| +				 CLONE_DETACHED | CLONE_UNTRACED             |\
| +				 CLONE_CHILD_SETTID | CLONE_STOPPED          |\
| +				 CLONE_NEWUTS | CLONE_NEWIPC | CLONE_NEWUSER |\
| +				 CLONE_NEWPID | CLONE_NEWNET | CLONE_IO)
| +
|  /*
|   * Scheduling policies
|   */
| diff --git a/kernel/fork.c b/kernel/fork.c
| index c8a06de..11f77ed 100644
| --- a/kernel/fork.c
| +++ b/kernel/fork.c
| @@ -982,6 +982,9 @@ static struct task_struct *copy_process(unsigned long clone_flags,
|  	struct task_struct *p;
|  	int cgroup_callbacks_done = 0;
| 
| +	if (clone_flags & ~VALID_CLONE_FLAGS)
| +		return ERR_PTR(-EINVAL);
| +
|  	if ((clone_flags & (CLONE_NEWNS|CLONE_FS)) == (CLONE_NEWNS|CLONE_FS))
|  		return ERR_PTR(-EINVAL);
| 
| -- 
| 1.6.0.4
| 
| _______________________________________________
| Containers mailing list
| Containers@lists.linux-foundation.org
| https://lists.linux-foundation.org/mailman/listinfo/containers

  reply	other threads:[~2009-11-11 22:40 UTC|newest]

Thread overview: 54+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2009-11-11  4:34 [v12][PATCH 0/9] Implement eclone() syscall Sukadev Bhattiprolu
2009-11-11  4:42 ` [v12][PATCH 1/9] Factor out code to allocate pidmap page Sukadev Bhattiprolu
2009-11-11 22:38   ` Sukadev Bhattiprolu
2009-11-11 22:38   ` Sukadev Bhattiprolu
2009-11-11 22:38     ` Sukadev Bhattiprolu
2009-11-11  4:42 ` Sukadev Bhattiprolu
2009-11-11  4:43 ` [v12][PATCH 2/9] Have alloc_pidmap() return actual error code Sukadev Bhattiprolu
2009-11-11  4:43 ` Sukadev Bhattiprolu
2009-11-11 22:39   ` Sukadev Bhattiprolu
2009-11-11 22:39   ` Sukadev Bhattiprolu
2009-11-11 22:39     ` Sukadev Bhattiprolu
2009-11-11  4:43 ` [v12][PATCH 3/9] Define set_pidmap() function Sukadev Bhattiprolu
2009-11-11  4:43 ` Sukadev Bhattiprolu
2009-11-11 22:39   ` Sukadev Bhattiprolu
2009-11-11 22:39   ` Sukadev Bhattiprolu
2009-11-11  4:43 ` [v12][PATCH 4/9] Add target_pids parameter to alloc_pid() Sukadev Bhattiprolu
2009-11-11 22:39   ` Sukadev Bhattiprolu
2009-11-11 22:39     ` Sukadev Bhattiprolu
2009-11-11  4:43 ` Sukadev Bhattiprolu
2009-11-11  4:44 ` [v12][PATCH 5/9] Add target_pids parameter to copy_process() Sukadev Bhattiprolu
2009-11-11  4:44 ` Sukadev Bhattiprolu
2009-11-11 22:40   ` Sukadev Bhattiprolu
2009-11-11 22:40   ` Sukadev Bhattiprolu
2009-11-11  4:44 ` Sukadev Bhattiprolu
2009-11-11  4:44 ` [v12][PATCH 6/9] Check invalid clone flags Sukadev Bhattiprolu
2009-11-11  4:44 ` Sukadev Bhattiprolu
2009-11-11 22:40   ` Sukadev Bhattiprolu [this message]
2009-11-11 22:40     ` Sukadev Bhattiprolu
2009-11-11 22:40   ` Sukadev Bhattiprolu
2009-11-11  4:44 ` [v12][PATCH 7/9] Define do_fork_with_pids() Sukadev Bhattiprolu
2009-11-11 22:40   ` Sukadev Bhattiprolu
2009-11-11 22:40     ` Sukadev Bhattiprolu
2009-11-11  4:44 ` Sukadev Bhattiprolu
2009-11-11  4:45 ` [v12][PATCH 8/9] Define eclone() syscall Sukadev Bhattiprolu
2009-11-11 22:40   ` Sukadev Bhattiprolu
2009-11-11 22:40   ` Sukadev Bhattiprolu
2009-11-11 22:40     ` Sukadev Bhattiprolu
2009-11-13  0:43     ` Sukadev Bhattiprolu
     [not found]       ` <20091113004356.GA23615-r/Jw6+rmf7HQT0dZR+AlfA@public.gmane.org>
2009-11-13  1:12         ` Serge E. Hallyn
2009-11-13 17:27         ` Serge E. Hallyn
2009-11-11  4:45 ` Sukadev Bhattiprolu
2009-11-11  4:45 ` [v12][PATCH 9/9] Document " Sukadev Bhattiprolu
2009-11-11  4:45 ` Sukadev Bhattiprolu
2009-11-11 22:41   ` Sukadev Bhattiprolu
2009-11-11 22:41     ` Sukadev Bhattiprolu
2009-11-13  0:45     ` Sukadev Bhattiprolu
     [not found]       ` <20091113004531.GB23615-r/Jw6+rmf7HQT0dZR+AlfA@public.gmane.org>
2009-11-13  1:17         ` Serge E. Hallyn
2009-11-11 22:38 ` [v12][PATCH 0/9] Implement " Sukadev Bhattiprolu
2009-11-11 22:38 ` Sukadev Bhattiprolu
2009-11-19 14:20 ` Arnd Bergmann
     [not found]   ` <200911191520.46445.arnd-r2nGTMty4D4@public.gmane.org>
2009-11-19 23:56     ` Sukadev Bhattiprolu
2009-11-19 23:56     ` Sukadev Bhattiprolu
     [not found]       ` <20091119235644.GA18720-r/Jw6+rmf7HQT0dZR+AlfA@public.gmane.org>
2009-11-20  8:08         ` Arnd Bergmann
2009-11-20  8:08         ` Arnd Bergmann

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20091111224020.GG24988@suka \
    --to=sukadev-23vcf4htsmix0ybbhkvfkdbpr1lh4cv8@public.gmane.org \
    --cc=adobriyan-Re5JQEeQqe8AvxtiuMwx3w@public.gmane.org \
    --cc=akpm-3NddpPZAyC0@public.gmane.org \
    --cc=arnd-r2nGTMty4D4@public.gmane.org \
    --cc=containers-cunTk1MwBs9QetFLy7KEm3xJsTq8ys+cHZ5vskTnxNA@public.gmane.org \
    --cc=ebiederm-aS9lmoZGLiVWk0Htik3J/w@public.gmane.org \
    --cc=hpa-YMNOUZJC4hwAvxtiuMwx3w@public.gmane.org \
    --cc=linux-api-u79uwXL29TY76Z2rM5mHXA@public.gmane.org \
    --cc=linux-kernel-u79uwXL29TY76Z2rM5mHXA@public.gmane.org \
    --cc=matthltc-npbjlsIvGkV82hYKe6nXyg@public.gmane.org \
    --cc=mtk.manpages-gM/Ye1E23mwN+BqQ9rBEUg@public.gmane.org \
    --cc=nathanl-V7BBcbaFuwjMbYB6QlFGEg@public.gmane.org \
    --cc=roland-H+wXaHxf7aLQT0dZR+AlfA@public.gmane.org \
    --cc=xemul-GEFAQzZX7r8dnm+yROfE0A@public.gmane.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.