From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from bombadil.infradead.org (bombadil.infradead.org [198.137.202.133]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.lore.kernel.org (Postfix) with ESMTPS id D067CC7EE23 for ; Thu, 1 Jun 2023 17:51:24 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.infradead.org; s=bombadil.20210309; h=Sender:List-Subscribe:List-Help :List-Post:List-Archive:List-Unsubscribe:List-Id:Content-Type:Subject:Cc:To: From:Date:References:In-Reply-To:Message-Id:Mime-Version:Reply-To: Content-Transfer-Encoding:Content-ID:Content-Description:Resent-Date: Resent-From:Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:List-Owner; bh=rIkHOu2cJZ+vhgMgLgXQFIzSc/FfETBAe+GmKBqE/d8=; b=2GiyBMe6h1ZyyVByGTa95PwsJc VtIGUTXmUDFPihm6D/ikaq4rHdE4G/dn5xcs/msQ8dSu+E43CXEB710fnLBlbo2Z38ZeyIs5omzPD TUdj6Q8RLQePHeXoHXU5wNFQYXuMt5S5tv6S7bDzJvk2IhFxA1jU4BYO8T4Cl4QBQEiDJ4hbt+iqf s3SYFJvrloOO0v3x7SxnJoM0fVx7s9jkADL8CR8w6KpggKycIFgeq3uAxTKsuWUJvwu7zKFURj6W9 2Ct12h3VfeP2WCX+1ZAP212kGnD50BrUPKeLTvw/a1A6EGEfNRqsmn96PAVuthYNRCNmoodbKg+3C qV1oxD5w==; Received: from localhost ([::1] helo=bombadil.infradead.org) by bombadil.infradead.org with esmtp (Exim 4.96 #2 (Red Hat Linux)) id 1q4mSA-004SzY-0v; Thu, 01 Jun 2023 17:51:14 +0000 Received: from wout5-smtp.messagingengine.com ([64.147.123.21]) by bombadil.infradead.org with esmtps (Exim 4.96 #2 (Red Hat Linux)) id 1q4mS6-004Sy2-17; Thu, 01 Jun 2023 17:51:12 +0000 Received: from compute6.internal (compute6.nyi.internal [10.202.2.47]) by mailout.west.internal (Postfix) with ESMTP id 5FF8832006F5; Thu, 1 Jun 2023 13:51:02 -0400 (EDT) Received: from imap51 ([10.202.2.101]) by compute6.internal (MEProxy); Thu, 01 Jun 2023 13:51:04 -0400 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=arndb.de; h=cc :cc:content-type:content-type:date:date:from:from:in-reply-to :in-reply-to:message-id:mime-version:references:reply-to:sender :subject:subject:to:to; s=fm3; t=1685641861; x=1685728261; bh=rI kHOu2cJZ+vhgMgLgXQFIzSc/FfETBAe+GmKBqE/d8=; b=YsbtSfmNvp2eXNoM+R izu+ChEdBnznPH+LsBdjf2+h6LdAHRujYmHDAet9DAX1gmlHLKguMCLBwmLdAHEO D+UVABb2eTTzqr0726+/7NHAOtmHqLCAXINuJsiG1IDxhjaITt017WqUNsBVChzh D90g8W2yX8ZoFDket0s7THCrhtfyEuY5C0Ndajkk/+9tv8wElxHd4U/Gn7Ea7xEx XbVfxHdS58S6O5Mq/yj2OHukD1a2RvVB62BOr0d3rvYg6DdO9l1EU2kX/KReg33O fPR6tKEUO0F7F771g7sulSQlHpOBfGP9yais1MeBS4eMz09WTiPZ3dXkonAtsOj3 MpDQ== DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= messagingengine.com; h=cc:cc:content-type:content-type:date:date :feedback-id:feedback-id:from:from:in-reply-to:in-reply-to :message-id:mime-version:references:reply-to:sender:subject :subject:to:to:x-me-proxy:x-me-proxy:x-me-sender:x-me-sender :x-sasl-enc; s=fm1; t=1685641861; x=1685728261; bh=rIkHOu2cJZ+vh gMgLgXQFIzSc/FfETBAe+GmKBqE/d8=; b=x278PMWMnWwyz8MB2+Pq6j4xDniu0 TlaDyapGkeiQFJNSM0ckJ1vVqYHPh1dpmpNaqeJMLl7g8wk5al2PlkQc7NvB9v+b GnN6504fYOB+Hl1GRaqPa+18Zkb5vE0BQjoUe3wngRik4cKBXar65yZzHfpoMhTt qksemY29jYOi6hdi0fsHGM5w4bTXLGf859Bz8PCzkDPKVPKbejaWAQPDdVsLH/fK p6meRZqBmViLevJg6759hN/hDoAdYDzWXmViGsF+HwJAAA/2GYyXAVdAVpvsFx8m N21D6im9GWBMQvaasV8H05L7MAuS6ST5q8RBgJocWC9hR3Er14DmqCocw== X-ME-Sender: X-ME-Proxy-Cause: gggruggvucftvghtrhhoucdtuddrgedvhedrfeeluddguddukecutefuodetggdotefrod ftvfcurfhrohhfihhlvgemucfhrghsthforghilhdpqfgfvfdpuffrtefokffrpgfnqfgh necuuegrihhlohhuthemuceftddtnecusecvtfgvtghiphhivghnthhsucdlqddutddtmd enucfjughrpefofgggkfgjfhffhffvvefutgesthdtredtreertdenucfhrhhomhepfdet rhhnugcuuegvrhhgmhgrnhhnfdcuoegrrhhnugesrghrnhgusgdruggvqeenucggtffrrg htthgvrhhnpeeigfeiieeiheejjeeiudekleevvddvffetieehteeikeeigeeiffdttdef tdeggfenucffohhmrghinhepghhnuhdrohhrghenucevlhhushhtvghrufhiiigvpedtne curfgrrhgrmhepmhgrihhlfhhrohhmpegrrhhnugesrghrnhgusgdruggv X-ME-Proxy: Feedback-ID: i56a14606:Fastmail Received: by mailuser.nyi.internal (Postfix, from userid 501) id 38825B60086; Thu, 1 Jun 2023 13:51:00 -0400 (EDT) X-Mailer: MessagingEngine.com Webmail Interface User-Agent: Cyrus-JMAP/3.9.0-alpha0-447-ge2460e13b3-fm-20230525.001-ge2460e13 Mime-Version: 1.0 Message-Id: In-Reply-To: <202306010909.89C4BED@keescook> References: <20230601151832.3632525-1-arnd@kernel.org> <202306010909.89C4BED@keescook> Date: Thu, 01 Jun 2023 19:50:38 +0200 From: "Arnd Bergmann" To: "Kees Cook" , "Arnd Bergmann" Cc: kasan-dev@googlegroups.com, "Andrey Ryabinin" , "Alexander Potapenko" , "Andrey Konovalov" , "Dmitry Vyukov" , "Vincenzo Frascino" , "Marco Elver" , linux-media@vger.kernel.org, linux-crypto@vger.kernel.org, "Herbert Xu" , "Ard Biesheuvel" , "Mauro Carvalho Chehab" , "Dan Carpenter" , "Matthias Brugger" , "AngeloGioacchino Del Regno" , "Nathan Chancellor" , "Nick Desaulniers" , "Tom Rix" , "Josh Poimboeuf" , linux-kernel@vger.kernel.org, linux-arm-kernel@lists.infradead.org, linux-mediatek@lists.infradead.org, llvm@lists.linux.dev Subject: Re: [PATCH] [RFC] ubsan: disallow bounds checking with gcov on broken gcc Content-Type: text/plain X-CRM114-Version: 20100106-BlameMichelson ( TRE 0.8.0 (BSD) ) MR-646709E3 X-CRM114-CacheID: sfid-20230601_105110_840119_3C8156A0 X-CRM114-Status: GOOD ( 13.03 ) X-BeenThere: linux-mediatek@lists.infradead.org X-Mailman-Version: 2.1.34 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Sender: "Linux-mediatek" Errors-To: linux-mediatek-bounces+linux-mediatek=archiver.kernel.org@lists.infradead.org On Thu, Jun 1, 2023, at 18:14, Kees Cook wrote: > On Thu, Jun 01, 2023 at 05:18:11PM +0200, Arnd Bergmann wrote: > > I think more production systems will have CONFIG_UBSAN_BOUNDS enabled > (e.g. Ubuntu has had it enabled for more than a year now) than GCOV, > so I'd prefer we maintain all*config coverage for the more commonly > used config. Fair enough, I can send that as v2, but let's see what the others think first. >> config CC_HAS_UBSAN_BOUNDS_STRICT >> def_bool $(cc-option,-fsanitize=bounds-strict) >> + # work around https://gcc.gnu.org/bugzilla/show_bug.cgi?id=110074 >> + depends on GCC_VERSION > 140000 || !GCOV_PROFILE_ALL >> help >> The -fsanitize=bounds-strict option is only available on GCC, >> but uses the more strict handling of arrays that includes knowledge > > Alternatively, how about falling back to -fsanitize=bounds instead, as > that (which has less coverage) wasn't triggering the stack frame > warnings? > > i.e. fall back through these: > -fsanitize=array-bounds (Clang) > -fsanitize=bounds-strict (!GCOV || bug fixed in GCC) > -fsanitize=bounds >From what I can tell, -fsanitize=bounds has the same problem as -fsanitize=bounds-strict, so that would not help. Arnd