public inbox for ltp@lists.linux.it
 help / color / mirror / Atom feed
* [LTP] [PATCH v2 0/3] safe_macros: Fix undefined behaviour in vararg handling
@ 2022-11-29 13:03 Tudor Cretu
  2022-11-29 13:03 ` [LTP] [PATCH v2 1/3] safe_open: " Tudor Cretu
                   ` (3 more replies)
  0 siblings, 4 replies; 9+ messages in thread
From: Tudor Cretu @ 2022-11-29 13:03 UTC (permalink / raw)
  To: ltp

Accessing elements in an empty va_list results in undefined behaviour[0]
that can include accessing arbitrary stack memory. While typically this
doesn't raise a fault, some new more security-oriented architectures
(e.g. CHERI[1] or Morello[2]) don't allow it.

Therefore, remove the variadicness from safe_* wrappers that always call
the functions with the optional argument included.

Adapt the respective SAFE_* macros to handle the change by passing a
default argument if they're omitted.

[0]: [ISO/IEC 9899:2011] Programming Languages—C, 3rd ed, paragraph 7.16.1.1
[1]: https://www.cl.cam.ac.uk/research/security/ctsrd/cheri/
[2]: https://www.morello-project.org/

v2..v1:
  - PATCH 1: Remove the NULL argument for mode from SAFE_OPEN instances
    to avoid the pointer to int conversion.

Tudor Cretu (3):
  safe_open: Fix undefined behaviour in vararg handling
  safe_openat: Fix undefined behaviour in vararg handling
  safe_semctl: Fix undefined behaviour in vararg handling

 include/old/safe_macros.h                         |  6 ++++--
 include/safe_macros_fn.h                          |  3 ++-
 include/tst_safe_file_at.h                        | 10 ++++++----
 include/tst_safe_macros.h                         |  6 ++++--
 include/tst_safe_sysv_ipc.h                       | 14 +++++++++-----
 lib/safe_macros.c                                 | 13 +------------
 lib/tst_cgroup.c                                  |  2 +-
 lib/tst_safe_file_at.c                            | 11 +++--------
 lib/tst_safe_sysv_ipc.c                           | 10 +---------
 testcases/kernel/syscalls/fgetxattr/fgetxattr01.c |  2 +-
 testcases/kernel/syscalls/fgetxattr/fgetxattr02.c |  2 +-
 testcases/kernel/syscalls/fgetxattr/fgetxattr03.c |  2 +-
 testcases/kernel/syscalls/fsetxattr/fsetxattr01.c |  2 +-
 testcases/kernel/syscalls/fsetxattr/fsetxattr02.c |  2 +-
 14 files changed, 36 insertions(+), 49 deletions(-)

-- 
2.25.1


-- 
Mailing list info: https://lists.linux.it/listinfo/ltp

^ permalink raw reply	[flat|nested] 9+ messages in thread

end of thread, other threads:[~2022-11-30 13:43 UTC | newest]

Thread overview: 9+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2022-11-29 13:03 [LTP] [PATCH v2 0/3] safe_macros: Fix undefined behaviour in vararg handling Tudor Cretu
2022-11-29 13:03 ` [LTP] [PATCH v2 1/3] safe_open: " Tudor Cretu
2022-11-29 13:03 ` [LTP] [PATCH v2 2/3] safe_openat: " Tudor Cretu
2022-11-29 13:03 ` [LTP] [PATCH v2 3/3] safe_semctl: " Tudor Cretu
2022-11-29 13:23 ` [LTP] [PATCH v2 0/3] safe_macros: " Richard Palethorpe
2022-11-29 13:59   ` Petr Vorel
2022-11-29 14:04     ` Tudor Cretu
2022-11-29 15:15       ` Petr Vorel
2022-11-30 13:43         ` Tudor Cretu

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox