public inbox for linux-kernel@vger.kernel.org
 help / color / mirror / Atom feed
From: Michal Simek <monstr@monstr.eu>
To: Arnd Bergmann <arnd@arndb.de>
Cc: Linux Kernel list <linux-kernel@vger.kernel.org>,
	LTP <ltp-list@lists.sourceforge.net>
Subject: Re: access_ok macor
Date: Tue, 14 Jul 2009 18:56:20 +0200	[thread overview]
Message-ID: <4A5CB8B4.7050108@monstr.eu> (raw)
In-Reply-To: <200907141843.05629.arnd@arndb.de>

Arnd Bergmann wrote:
> On Tuesday 14 July 2009, Michal Simek wrote:
>> Arnd Bergmann wrote:
> 
>>>>  r29=00000000, r30=00000000, r31=CE9759A4, rPC=C000123C
>>>>  msr=800045AE, ear=00000001, esr=000000B2, fsr=000080D0
>>>> Segmentation fault
>>>>
>>> I guess then you should check if 0xc000123c is in your
>>> exception table, or why it is not.
>> on that address is load instruction for unaligned exception because addr is odd number
>> that's why is called unaligned exception handler and from this function
>> is called load instruction which failed. :-(
>>
>> Currently this make more sense why that tests failed. If that pointers are
>> even number exception is not taken and exception sure don't have fixup for it because
>> this is generic code. :-(
>>
>> That's the problem because we are looking for regs->pc but this point to unaligned exception
>> handler.
> 
> Ok, that makes a lot of sense.
> 
> The solution then is to handle fixups from the unaligned exception handler
> if you come from the kernel. That should fix the three text cases.
> 
> I don't fully understand your exception handling there, but I think you
> also need to add code checking for __range_ok() to your unaligned handler,
> to prevent malicious user space code from accessing the kernel through
> unaligned pointers.

when the code tried to read/write from unaligned address (and in cpu is turn on unaligned exception)
then is caused unaligned exception and asm code assemble/return value which is on that unaligned
address. (Assemble it that read/write every byte separately). That will be harder to prevent all
this cases because unaligned exception is in generic code.
What do you mean add __range_ok? Range checking is ok. The problem is when in case get_user kernel
try to load unaligned addr - unaligned exception is perform and try to load that value separately.
If that page is not there, page fault handler is called and not find it, it is performed search
from exception table and that address is not there of course - because address in pc is generic
unaligned code. I think that handling this needs more code.
Maybe if the address with from unaligned exception handler (there are some address which can caused
it) and find out which aligned address is there and find out proper fixup for it.
I think that this could work.

What do you think?

Michal



> 
> 	Arnd <><


-- 
Michal Simek, Ing. (M.Eng)
w: www.monstr.eu p: +42-0-721842854

  reply	other threads:[~2009-07-14 16:56 UTC|newest]

Thread overview: 15+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2009-07-14 12:56 access_ok macor Michal Simek
2009-07-14 13:21 ` Arnd Bergmann
2009-07-14 13:45   ` Michal Simek
2009-07-14 14:45     ` Arnd Bergmann
2009-07-14 15:06       ` Michal Simek
     [not found] ` <200907141652.59049.arnd@arndb.de>
     [not found]   ` <4A5CAEFF.9080206@monstr.eu>
2009-07-14 16:43     ` Arnd Bergmann
2009-07-14 16:56       ` Michal Simek [this message]
2009-07-14 17:13         ` Arnd Bergmann
2009-07-14 17:45           ` Michal Simek
2009-07-15  9:21           ` Paul Mundt
2009-07-15 10:03             ` Michal Simek
     [not found]       ` <9e6f3dfd0907141811p512b4edp3f9dd0fdeae1123e@mail.gmail.com>
2009-07-15 10:14         ` Arnd Bergmann
2009-07-15 11:39           ` Michal Simek
2009-07-15 12:05           ` Ralf Baechle
2009-07-15 13:27             ` Arnd Bergmann

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=4A5CB8B4.7050108@monstr.eu \
    --to=monstr@monstr.eu \
    --cc=arnd@arndb.de \
    --cc=linux-kernel@vger.kernel.org \
    --cc=ltp-list@lists.sourceforge.net \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox