From: james.morse@arm.com (James Morse)
To: linux-arm-kernel@lists.infradead.org
Subject: [PATCH v11 3/9] arm64: add copy_to/from_user to kprobes blacklist
Date: Tue, 15 Mar 2016 18:47:52 +0000 [thread overview]
Message-ID: <56E858D8.8030300@arm.com> (raw)
In-Reply-To: <1457501543-24197-4-git-send-email-dave.long@linaro.org>
Hi David,
On 09/03/16 05:32, David Long wrote:
> From: "David A. Long" <dave.long@linaro.org>
> diff --git a/arch/arm64/lib/copy_from_user.S b/arch/arm64/lib/copy_from_user.S
> index 4699cd7..0ac2131 100644
> --- a/arch/arm64/lib/copy_from_user.S
> +++ b/arch/arm64/lib/copy_from_user.S
> @@ -66,6 +66,7 @@
> .endm
>
> end .req x5
> + .section .kprobes.text,"ax",%progbits
> ENTRY(__copy_from_user)
> ALTERNATIVE("nop", __stringify(SET_PSTATE_PAN(0)), ARM64_HAS_PAN, \
> CONFIG_ARM64_PAN)
> diff --git a/arch/arm64/lib/copy_to_user.S b/arch/arm64/lib/copy_to_user.S
> index 7512bbb..e4eb84c 100644
> --- a/arch/arm64/lib/copy_to_user.S
> +++ b/arch/arm64/lib/copy_to_user.S
> @@ -65,6 +65,7 @@
> .endm
>
> end .req x5
> + .section .kprobes.text,"ax",%progbits
> ENTRY(__copy_to_user)
> ALTERNATIVE("nop", __stringify(SET_PSTATE_PAN(0)), ARM64_HAS_PAN, \
> CONFIG_ARM64_PAN)
>
If I understand this correctly - you can't kprobe these ldr/str instructions as
the fault handler wouldn't find kprobe's out-of line version of the instruction
in the exception table... but why only these two functions? (for library
functions, we also have clear_user() and copy_in_user()...)
The get_user()/put_user() stuff in uaccess.h gets inlined all over the kernel, I
don't think its feasible to put all of these in a separate section.
Is it feasible to search the exception table at runtime instead? If an
address-to-be-kprobed appears in the list, we know it could generate exceptions,
so we should report that we can't probe this address. That would catch all of
the library functions, all the places uaccess.h was inlined, and anything new
that gets invented in the future.
> Currrently taking exceptions when accessing user data from a kprobe'd
(Nit: Currently)
Thanks,
James
next prev parent reply other threads:[~2016-03-15 18:47 UTC|newest]
Thread overview: 38+ messages / expand[flat|nested] mbox.gz Atom feed top
2016-03-09 5:32 [PATCH v11 0/9] arm64: Add kernel probes (kprobes) support David Long
2016-03-09 5:32 ` [PATCH v11 1/9] arm64: Add HAVE_REGS_AND_STACK_ACCESS_API feature David Long
2016-03-11 18:07 ` James Morse
2016-03-18 13:06 ` David Long
2016-03-15 11:04 ` Marc Zyngier
2016-03-21 7:08 ` David Long
2016-03-09 5:32 ` [PATCH v11 2/9] arm64: Add more test functions to insn.c David Long
2016-03-09 5:32 ` [PATCH v11 3/9] arm64: add copy_to/from_user to kprobes blacklist David Long
2016-03-15 18:47 ` James Morse [this message]
2016-03-16 5:43 ` Pratyush Anand
2016-03-16 10:27 ` James Morse
2016-03-17 7:57 ` Pratyush Anand
2016-03-18 13:29 ` Pratyush Anand
2016-03-18 14:02 ` James Morse
2016-03-18 14:43 ` Pratyush Anand
2016-03-18 18:12 ` James Morse
2016-03-21 5:17 ` Pratyush Anand
2016-03-21 14:52 ` Will Deacon
2016-03-22 16:51 ` Pratyush Anand
2016-03-17 12:04 ` 平松雅巳 / HIRAMATU,MASAMI
2016-03-09 5:32 ` [PATCH v11 4/9] arm64: add conditional instruction simulation support David Long
2016-03-13 12:09 ` Marc Zyngier
2016-03-14 4:04 ` Pratyush Anand
2016-03-14 7:38 ` Marc Zyngier
2016-03-21 8:35 ` David Long
2016-03-09 5:32 ` [PATCH v11 5/9] arm64: Kprobes with single stepping support David Long
2016-04-20 1:29 ` Li Bin
2016-03-09 5:32 ` [PATCH v11 6/9] arm64: kprobes instruction simulation support David Long
2016-03-12 3:56 ` Marc Zyngier
2016-03-21 9:39 ` David Long
2016-03-09 5:32 ` [PATCH v11 7/9] arm64: Add trampoline code for kretprobes David Long
2016-03-13 13:52 ` Marc Zyngier
2016-03-21 13:30 ` David Long
2016-03-09 5:32 ` [PATCH v11 8/9] arm64: Add kernel return probes support (kretprobes) David Long
2016-03-17 12:22 ` 平松雅巳 / HIRAMATU,MASAMI
2016-03-17 12:58 ` 平松雅巳 / HIRAMATU,MASAMI
2016-03-21 13:33 ` David Long
2016-03-09 5:32 ` [PATCH v11 9/9] kprobes: Add arm64 case in kprobe example module David Long
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=56E858D8.8030300@arm.com \
--to=james.morse@arm.com \
--cc=linux-arm-kernel@lists.infradead.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).