From: mingo@kernel.org (Ingo Molnar)
To: linux-arm-kernel@lists.infradead.org
Subject: [PATCH v7 1/4] syscalls: Restore address limit after a syscall
Date: Wed, 26 Apr 2017 10:12:29 +0200 [thread overview]
Message-ID: <20170426081229.6wnugrs7w3at4xry@gmail.com> (raw)
In-Reply-To: <CAJcbSZH7Y6iBy3T3iWyh_AaFJ+TidP7E9iQEuCbShQrcTKGoyw@mail.gmail.com>
* Thomas Garnier <thgarnie@google.com> wrote:
> >> +#ifdef CONFIG_ARCH_NO_SYSCALL_VERIFY_PRE_USERMODE_STATE
> >> +/*
> >> + * This function is called when an architecture specific implementation detected
> >> + * an invalid address limit. The generic user-mode state checker will finish on
> >> + * the appropriate BUG_ON.
> >> + */
> >> +asmlinkage void address_limit_check_failed(void)
> >> +{
> >> + verify_pre_usermode_state();
> >> + panic("address_limit_check_failed called with a valid user-mode state");
> >
> > It's very unconstructive to unconditionally panic the system, just because some
> > kernel code leaked the address limit! Do a warn-once printout and kill the current
> > task (i.e. don't continue execution), but don't crash everything else!
>
> The original change did not crash the kernel for this exact reason.
> Through reviews, there was an overall agreement that the kernel should
> not continue in this state.
Ok, I guess we can try that - but the panic message is still pretty misleading:
panic("address_limit_check_failed called with a valid user-mode state");
... so it was called with a _valid_ user-mode state, and we crash due to something
valid? Huh?
( Also, the style rule applies to kernel messages as well: function names should
be referred to as "function_name()". )
Thanks,
Ingo
next prev parent reply other threads:[~2017-04-26 8:12 UTC|newest]
Thread overview: 15+ messages / expand[flat|nested] mbox.gz Atom feed top
2017-04-10 16:44 [PATCH v7 1/4] syscalls: Restore address limit after a syscall Thomas Garnier
2017-04-10 16:44 ` [PATCH v7 2/4] x86/syscalls: Architecture specific pre-usermode check Thomas Garnier
2017-04-10 16:44 ` [PATCH v7 3/4] arm/syscalls: " Thomas Garnier
2017-04-10 16:44 ` [PATCH v7 4/4] arm64/syscalls: " Thomas Garnier
2017-04-10 17:12 ` Catalin Marinas
2017-04-10 20:06 ` Thomas Garnier
2017-04-10 20:09 ` Thomas Garnier
2017-04-10 20:07 ` Thomas Garnier
2017-04-24 23:57 ` [PATCH v7 1/4] syscalls: Restore address limit after a syscall Kees Cook
2017-04-25 6:23 ` Ingo Molnar
2017-04-25 14:12 ` Thomas Garnier
2017-04-25 6:33 ` Ingo Molnar
2017-04-25 14:18 ` Thomas Garnier
2017-04-26 8:12 ` Ingo Molnar [this message]
2017-04-26 14:09 ` Thomas Garnier
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20170426081229.6wnugrs7w3at4xry@gmail.com \
--to=mingo@kernel.org \
--cc=linux-arm-kernel@lists.infradead.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).