From: Greg KH <gregkh@linuxfoundation.org>
To: Liljestrand Hans <ishkamiel@gmail.com>
Cc: Peter Zijlstra <peterz@infradead.org>,
"Reshetova, Elena" <elena.reshetova@intel.com>,
"kernel-hardening@lists.openwall.com"
<kernel-hardening@lists.openwall.com>,
Kees Cook <keescook@chromium.org>,
"will.deacon@arm.com" <will.deacon@arm.com>,
Boqun Feng <boqun.feng@gmail.com>,
David Windsor <dwindsor@gmail.com>,
"aik@ozlabs.ru" <aik@ozlabs.ru>,
"david@gibson.dropbear.id.au" <david@gibson.dropbear.id.au>
Subject: [kernel-hardening] Re: Conversion from atomic_t to refcount_t: summary of issues
Date: Fri, 2 Dec 2016 17:14:15 +0100 [thread overview]
Message-ID: <20161202161415.GA6302@kroah.com> (raw)
In-Reply-To: <1480693474.28515.56.camel@cs-046.org.aalto.fi>
On Fri, Dec 02, 2016 at 05:44:34PM +0200, Liljestrand Hans wrote:
> Then there's cases that check for the first increment, like here (maybe
> something like inc_and_one could allow these without too much leeway?):
>
> http://lxr.free-electrons.com/source/drivers/tty/serial/zs.c#L764
>
> irq_guard = atomic_add_return(1, &scc->irq_guard);
> if (irq_guard == 1) {
That's horrid, let's fix it correctly, it just wants to know if the
driver has been initialized or not. Make it a real lock and a variable
and all is good.
> http://lxr.free-electrons.com/source/drivers/usb/gadget/function/f_fs.c#L1497
>
> if (atomic_add_return(1, &ffs->opened) == 1 &&
> ffs->state == FFS_DEACTIVATED) {
Another horrid hack to try to be "cute" about only allowing one open to
succeed. Again, let's do this correctly with a lock.
> And finally some cases with other uses/values:
>
> http://lxr.free-electrons.com/source/kernel/bpf/syscall.c#L231
>
> if (atomic_inc_return(&map->refcnt) > BPF_MAX_REFCNT) {
A "don't allow any more than X things through at once" type counter, a
normal atomic type should be fine for this, it's not a "real" reference
counter for a data structure.
> http://lxr.free-electrons.com/source/drivers/staging/lustre/lustre/ptlrpc/client.c#L3081
>
> if (atomic_inc_return(&req->rq_refcount) == 2)
lustre should never be used as an excuse for anything, except for how to
not do things. That's some messed up code that is slowly getting
better...
This audit is turning up good stuff, it will be nice to clean this crud
up!
thanks,
greg k-h
next prev parent reply other threads:[~2016-12-02 16:14 UTC|newest]
Thread overview: 48+ messages / expand[flat|nested] mbox.gz Atom feed top
2016-11-28 11:56 [kernel-hardening] Conversion from atomic_t to refcount_t: summary of issues Reshetova, Elena
2016-11-28 12:13 ` [kernel-hardening] " Peter Zijlstra
2016-11-28 12:44 ` Peter Zijlstra
2016-11-28 12:48 ` Peter Zijlstra
2016-11-28 14:12 ` [kernel-hardening] " Reshetova, Elena
2016-11-29 3:19 ` [kernel-hardening] " Alexey Kardashevskiy
2016-11-29 9:31 ` Peter Zijlstra
2016-11-30 0:23 ` Alexey Kardashevskiy
2016-11-29 15:35 ` [kernel-hardening] " Reshetova, Elena
2016-11-29 15:47 ` Peter Zijlstra
2016-12-01 19:15 ` [kernel-hardening] " Peter Zijlstra
2016-12-01 21:31 ` David Windsor
2016-12-01 23:03 ` Peter Zijlstra
2016-12-01 23:20 ` Kees Cook
2016-12-01 23:29 ` David Windsor
2016-12-02 1:17 ` Boqun Feng
2016-12-02 20:25 ` David Windsor
2016-12-07 13:24 ` Peter Zijlstra
2016-12-07 19:03 ` David Windsor
2016-12-09 14:48 ` David Windsor
2016-12-07 13:36 ` Peter Zijlstra
2016-12-01 23:20 ` David Windsor
2016-12-07 13:21 ` Peter Zijlstra
2016-12-02 15:44 ` Liljestrand Hans
2016-12-02 16:14 ` Greg KH [this message]
2016-12-07 13:52 ` Peter Zijlstra
2016-12-07 15:59 ` David Windsor
2016-12-07 16:26 ` Peter Zijlstra
2016-12-07 16:31 ` David Windsor
2016-12-16 12:10 ` [kernel-hardening] " Reshetova, Elena
2016-12-16 14:01 ` [kernel-hardening] " Peter Zijlstra
2016-12-19 7:55 ` [kernel-hardening] " Reshetova, Elena
2016-12-19 10:12 ` [kernel-hardening] " Peter Zijlstra
2016-12-20 9:13 ` [kernel-hardening] " Reshetova, Elena
2016-12-20 9:30 ` [kernel-hardening] " Greg KH
2016-12-20 9:40 ` [kernel-hardening] " Reshetova, Elena
2016-12-20 9:51 ` [kernel-hardening] " Greg KH
2016-12-20 9:55 ` [kernel-hardening] " Reshetova, Elena
2016-12-20 10:26 ` [kernel-hardening] " Greg KH
2016-12-20 9:41 ` Peter Zijlstra
2016-12-20 9:58 ` [kernel-hardening] " Reshetova, Elena
2016-12-20 10:55 ` [kernel-hardening] " Liljestrand Hans
2016-12-20 13:13 ` Peter Zijlstra
2016-12-20 13:35 ` Reshetova, Elena
2016-12-20 15:20 ` Liljestrand Hans
2016-12-20 15:52 ` Peter Zijlstra
2017-01-10 14:58 ` Peter Zijlstra
2016-12-07 14:13 ` Peter Zijlstra
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20161202161415.GA6302@kroah.com \
--to=gregkh@linuxfoundation.org \
--cc=aik@ozlabs.ru \
--cc=boqun.feng@gmail.com \
--cc=david@gibson.dropbear.id.au \
--cc=dwindsor@gmail.com \
--cc=elena.reshetova@intel.com \
--cc=ishkamiel@gmail.com \
--cc=keescook@chromium.org \
--cc=kernel-hardening@lists.openwall.com \
--cc=peterz@infradead.org \
--cc=will.deacon@arm.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.