From: Keith Owens <kaos@ocs.com.au>
To: Andreas Dilger <adilger@turbolinux.com>
Cc: Andi Kleen <ak@suse.de>, linux-kernel@vger.kernel.org
Subject: Re: [CHECKER] large stack variables (>=1K) in 2.4.4 and 2.4.4-ac8
Date: Fri, 25 May 2001 16:53:47 +1000 [thread overview]
Message-ID: <24688.990773627@kao2.melbourne.sgi.com> (raw)
In-Reply-To: Your message of "Fri, 25 May 2001 00:33:56 CST." <200105250633.f4P6Xuj2017833@webber.adilger.int>
On Fri, 25 May 2001 00:33:56 -0600 (MDT),
Andreas Dilger <adilger@turbolinux.com> wrote:
>Keith Owens writes:
>> You cannot recover from a kernel stack overflow even with kdb. The
>> exception handler and kdb use the stack that just overflowed.
>
>If it at least tells you that the stack has overflowed, and a backtrace
>of the stack up to that point, that would at least be useful for fixing
>the functions which caused the problem.
A small overflow of the kernel stack overwrites the struct task at the
bottom of the stack, recovery is dubious at best because we rely on
data in struct task. A large overflow of the kernel stack either
corrupts the storage below this task's stack, which could hit anything,
or it gets a stack fault.
If we take a stack fault on ix86, stack_segment() is invoked. Just
taking the fault and calling the routine uses the kernel stack which
has already overflowed, causing a double fault. The double fault
handler uses the kernel stack, generating a triple fault. The machine
is now dead.
The only way to avoid those problems is to move struct task out of the
kernel stack pages and to use a task gate for the stack fault and
double fault handlers, instead of a trap gate (all ix86 specific).
Those methods are expensive, at a minimum they require an extra page
for every process plus an extra stack per cpu. I have not even
considered the extra cost of using task gates for the interrupts nor
how this method would complicate methods for getting the current struct
task pointer. It is not worth the bother, we write better kernel code
than that.
next prev parent reply other threads:[~2001-05-25 6:54 UTC|newest]
Thread overview: 36+ messages / expand[flat|nested] mbox.gz Atom feed top
2001-05-24 21:10 [CHECKER] large stack variables (>=1K) in 2.4.4 and 2.4.4-ac8 Dawson Engler
2001-05-24 22:40 ` Anton Altaparmakov
2001-05-24 23:08 ` Andreas Dilger
2001-05-24 23:33 ` Andi Kleen
2001-05-25 5:20 ` Keith Owens
2001-05-25 6:33 ` Andreas Dilger
2001-05-25 6:53 ` Keith Owens [this message]
2001-05-25 8:20 ` Andi Kleen
2001-05-25 8:31 ` Keith Owens
2001-05-25 8:39 ` Andi Kleen
2001-05-25 14:03 ` Oliver Neukum
2001-05-25 14:07 ` Andi Kleen
2001-05-25 15:45 ` dean gaudet
2001-05-25 16:34 ` Jonathan Lundell
2001-05-25 18:37 ` dean gaudet
2001-05-25 17:49 ` Jeff Dike
2001-05-25 7:11 ` David Welch
2001-05-25 8:08 ` Keith Owens
2001-05-25 15:31 ` dean gaudet
2001-05-25 15:49 ` Keith Owens
2001-05-25 18:46 ` dean gaudet
2001-05-25 8:14 ` Andi Kleen
2001-05-25 8:25 ` Keith Owens
2001-05-25 8:27 ` Andi Kleen
2001-05-25 8:37 ` Keith Owens
2001-05-25 8:17 ` Andi Kleen
2001-05-25 11:52 ` Brian Gerst
2001-05-25 11:53 ` Andi Kleen
2001-05-25 12:07 ` Brian Gerst
2001-05-25 3:38 ` Andrew Morton
-- strict thread matches above, loose matches on Subject: below --
2001-05-24 23:01 Mikael Pettersson
2001-05-25 2:48 ` Dawson Engler
2001-05-25 3:00 ` Alexander Viro
2001-05-25 3:07 ` Dawson Engler
2001-05-25 4:23 Dunlap, Randy
2001-07-03 9:15 VDA
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=24688.990773627@kao2.melbourne.sgi.com \
--to=kaos@ocs.com.au \
--cc=adilger@turbolinux.com \
--cc=ak@suse.de \
--cc=linux-kernel@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox