From: Xiao Yang <yangx.jy@cn.fujitsu.com>
To: ltp@lists.linux.it
Subject: [LTP] [PATCH] cve/cve-2016-10044.c: fix two errors
Date: Mon, 25 Sep 2017 18:47:36 +0800 [thread overview]
Message-ID: <59C8DEC8.7050908@cn.fujitsu.com> (raw)
In-Reply-To: <87lgl7yov6.fsf@our.domain.is.not.set>
On 2017/09/22 19:06, Richard Palethorpe wrote:
> Hello,
>
> Xiao Yang writes:
>
>> 1) If the number of nr_events exceeds the limit of available events
>> defined in /proc/sys/fs/aio-max-nr, it returns EAGAIN. We should
>> call io_destroy() to cleanup the AIO context after finishing test.
>>
>> Steps to reproduce this error:
>> #echo 4 > /proc/sys/fs/aio-max-nr
>> # ./cve-2016-10044 -i 5
>> tst_test.c:908: INFO: Timeout per run is 0h 05m 00s
>> cve-2016-10044.c:62: FAIL: AIO mapping is executable: rwxs!
>> cve-2016-10044.c:62: FAIL: AIO mapping is executable: rwxs!
>> cve-2016-10044.c:62: FAIL: AIO mapping is executable: rwxs!
>> cve-2016-10044.c:62: FAIL: AIO mapping is executable: rwxs!
>> cve-2016-10044.c:49: BROK: Failed to create AIO context: EAGAIN/EWOULDBLOCK
>>
>> 2) The kernel created an AIO pseudo-fs and introduced cve-2016-10044
>> by the following patch:
>> '71ad7490c1f3("rework aio migrate pages to use aio fs")'
>>
>> We should return TCONF rather than TBROK when an AIO pseudo-fs is
>> not found in /proc/self/maps.
> Maybe instead of doing this we could increase the required kernel
> version to 3.12 which appears to be where the patch was introduced?
>
> Otherwise we may fail with TCONF because the format of the file has
> slightly changed and I am worried that nobody will notice. I don't think
> this will have been backported to earlier versions:
> http://lkml.iu.edu/hypermail/linux/kernel/1312.0/04590.html
Hi Richard,
On RHEL7, the above patch has been backported to v3.10.0, so increasing
the required
kernel version to 3.12 does not seem better.
The old format of file is set to 'anon_inode:[aio]' by the following patch set:
'55708698c5f1("fs/anon_inode: Introduce a new lib function anon_inode_getfile_private()")'
'36bc08cc0170("fs/aio: Add support to aio ring pages migration")'
The current format of file is set to '/[aio]' by the following patch:
'71ad7490c1f3("rework aio migrate pages to use aio fs")'
Could we change the keyword into '[aio]' to match as many formats as possible, and
return TCONF if the mapping file does not exist.
Thanks,
Xiao Yang.
> The rest LGTM. Thanks.
>
>> Signed-off-by: Xiao Yang <yangx.jy@cn.fujitsu.com>
>> ---
>> testcases/cve/cve-2016-10044.c | 5 ++++-
>> 1 file changed, 4 insertions(+), 1 deletion(-)
>>
>> diff --git a/testcases/cve/cve-2016-10044.c b/testcases/cve/cve-2016-10044.c
>> index 7928d27..a84590a 100644
>> --- a/testcases/cve/cve-2016-10044.c
>> +++ b/testcases/cve/cve-2016-10044.c
>> @@ -53,7 +53,7 @@ static void run(void)
>> if (strstr(line, "/[aio]") != NULL)
>> goto found_mapping;
>> }
>> - tst_brk(TBROK, "Could not find mapping in /proc/self/maps");
>> + tst_brk(TCONF, "Could not find mapping in /proc/self/maps");
>>
>> found_mapping:
>> if (sscanf(line, "%*x-%*x %s7", perms) < 0)
>> @@ -63,6 +63,9 @@ found_mapping:
>> else
>> tst_res(TPASS, "AIO mapping is not executable: %s", perms);
>>
>> + if (tst_syscall(__NR_io_destroy, ctx))
>> + tst_brk(TBROK | TERRNO, "Failed to destroy AIO context");
>> +
>> SAFE_FCLOSE(f);
>> f = NULL;
>> }
>> --
>> 1.8.3.1
>
next prev parent reply other threads:[~2017-09-25 10:47 UTC|newest]
Thread overview: 9+ messages / expand[flat|nested] mbox.gz Atom feed top
2017-09-22 9:21 [LTP] [PATCH] cve/cve-2016-10044.c: fix two errors Xiao Yang
2017-09-22 11:06 ` Richard Palethorpe
2017-09-25 10:47 ` Xiao Yang [this message]
2017-09-25 11:16 ` Richard Palethorpe
2017-09-26 2:04 ` [LTP] [PATCH v2] " Xiao Yang
2017-10-05 2:11 ` Xiao Yang
2017-10-13 7:48 ` Xiao Yang
2017-10-26 9:02 ` Xiao Yang
2017-10-26 10:23 ` Cyril Hrubis
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=59C8DEC8.7050908@cn.fujitsu.com \
--to=yangx.jy@cn.fujitsu.com \
--cc=ltp@lists.linux.it \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox