From: "Russell King (Oracle)" <linux@armlinux.org.uk>
To: Josh Poimboeuf <jpoimboe@kernel.org>
Cc: Jiangfeng Xiao <xiaojiangfeng@huawei.com>,
Kees Cook <keescook@chromium.org>, Jann Horn <jannh@google.com>,
gustavoars@kernel.org, akpm@linux-foundation.org,
peterz@infradead.org, dave.hansen@linux.intel.com,
kirill.shutemov@linux.intel.com, linux-kernel@vger.kernel.org,
linux-hardening@vger.kernel.org, linux-mm@kvack.org,
nixiaoming@huawei.com, kepler.chenxin@huawei.com,
wangbing6@huawei.com, wangfangpeng1@huawei.com,
douzhaolei@huawei.com, linux-arm-kernel@lists.infradead.org,
Ard Biesheuvel <ardb@kernel.org>
Subject: Re: [PATCH] usercopy: delete __noreturn from usercopy_abort
Date: Wed, 6 Mar 2024 09:52:01 +0000 [thread overview]
Message-ID: <Zeg8wRYFemMjcCxG@shell.armlinux.org.uk> (raw)
In-Reply-To: <20240305175846.qnyiru7uaa7itqba@treble>
On Tue, Mar 05, 2024 at 09:58:46AM -0800, Josh Poimboeuf wrote:
> This is an off-by-one bug which is common in unwinders, due to the fact
> that the address on the stack points to the return address rather than
> the call address.
>
> So, for example, when the last instruction of a function is a function
> call (e.g., to a noreturn function), it can cause the unwinder to
> incorrectly try to unwind from the function *after* the callee.
I suppose this can only happen in __noreturn functions because that
can be:
foo:
...
bl bar
... end of function and thus next function ...
which results in LR pointing into the next function.
Would it make better sense to lookup the LR value winding it back by
one instruction like ORC on x86 does (as you mention) rather than
the patch you proposed which looks rather large and complicated?
--
RMK's Patch system: https://www.armlinux.org.uk/developer/patches/
FTTP is here! 80Mbps down 10Mbps up. Decent connectivity at last!
next prev parent reply other threads:[~2024-03-06 9:52 UTC|newest]
Thread overview: 42+ messages / expand[flat|nested] mbox.gz Atom feed top
2024-03-04 1:39 [PATCH] usercopy: delete __noreturn from usercopy_abort Jiangfeng Xiao
2024-03-04 15:15 ` Jann Horn
2024-03-04 17:40 ` Kees Cook
2024-03-05 3:31 ` Jiangfeng Xiao
2024-03-05 9:32 ` Kees Cook
2024-03-05 11:38 ` Jiangfeng Xiao
2024-03-05 17:58 ` Josh Poimboeuf
2024-03-06 4:00 ` Jiangfeng Xiao
2024-03-06 9:52 ` Russell King (Oracle) [this message]
2024-03-06 16:02 ` Josh Poimboeuf
2024-03-09 14:58 ` David Laight
2024-03-18 4:01 ` Jiangfeng Xiao
2024-03-05 2:54 ` Jiangfeng Xiao
2024-03-05 3:12 ` Jiangfeng Xiao
2024-03-20 2:19 ` [PATCH] ARM: unwind: improve unwinders for noreturn case Jiangfeng Xiao
2024-03-20 2:46 ` Kees Cook
2024-03-20 3:30 ` Jiangfeng Xiao
2024-03-20 3:34 ` Matthew Wilcox
2024-03-20 3:46 ` Jiangfeng Xiao
2024-03-20 3:44 ` [PATCH v2] " Jiangfeng Xiao
2024-03-20 8:45 ` Russell King (Oracle)
2024-03-20 15:30 ` Jiangfeng Xiao
2024-03-20 19:40 ` Russell King (Oracle)
2024-03-21 9:44 ` Jiangfeng Xiao
2024-03-21 10:22 ` David Laight
2024-03-21 11:23 ` Russell King (Oracle)
2024-03-21 12:07 ` David Laight
2024-03-21 12:22 ` Russell King (Oracle)
2024-03-21 12:57 ` David Laight
2024-03-21 13:08 ` Russell King (Oracle)
2024-03-21 14:37 ` David Laight
2024-03-21 14:56 ` Russell King (Oracle)
2024-03-21 15:20 ` David Laight
2024-03-21 15:33 ` Russell King (Oracle)
2024-03-21 22:43 ` Ard Biesheuvel
2024-03-22 0:08 ` Russell King (Oracle)
2024-03-22 9:24 ` David Laight
2024-03-22 9:52 ` Russell King (Oracle)
2024-03-22 12:54 ` Jiangfeng Xiao
2024-03-22 14:16 ` David Laight
2024-03-20 15:41 ` [PATCH v3] " Jiangfeng Xiao
2024-03-20 19:42 ` Russell King (Oracle)
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=Zeg8wRYFemMjcCxG@shell.armlinux.org.uk \
--to=linux@armlinux.org.uk \
--cc=akpm@linux-foundation.org \
--cc=ardb@kernel.org \
--cc=dave.hansen@linux.intel.com \
--cc=douzhaolei@huawei.com \
--cc=gustavoars@kernel.org \
--cc=jannh@google.com \
--cc=jpoimboe@kernel.org \
--cc=keescook@chromium.org \
--cc=kepler.chenxin@huawei.com \
--cc=kirill.shutemov@linux.intel.com \
--cc=linux-arm-kernel@lists.infradead.org \
--cc=linux-hardening@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-mm@kvack.org \
--cc=nixiaoming@huawei.com \
--cc=peterz@infradead.org \
--cc=wangbing6@huawei.com \
--cc=wangfangpeng1@huawei.com \
--cc=xiaojiangfeng@huawei.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).