From: Petr Vorel <pvorel@suse.cz>
To: Tudor Cretu <tudor.cretu@arm.com>
Cc: ltp@lists.linux.it
Subject: Re: [LTP] [PATCH v2 0/3] safe_macros: Fix undefined behaviour in vararg handling
Date: Tue, 29 Nov 2022 16:15:59 +0100 [thread overview]
Message-ID: <Y4YiL/Os2G+cZMFp@pevik> (raw)
In-Reply-To: <eff8f05f-fd4b-4cad-86bc-d039aab0a56a@arm.com>
> On 29-11-2022 13:59, Petr Vorel wrote:
> > Hi all,
> > > Hello,
> > > So I'm happy with this, but I think Cyril's comment deserves a response:
> Indeed, I noticed it too late after sending the v2.
> > +1
> > > > Looking at how glibc handles this, the code looks like:
> > > > int mode = 0;
> > > > if (__OPEN_NEEDS_MODE(oflag)) {
> > > > ..
> > > > mode = va_arg(arg, int);
> > > > ..
> > > > }
> > > > That sounds much easier than messing with the macros and should avoid
> > > > undefined behavior.
> I considered this and I think it's better to focus strictly on the handling
> the variadicness issue, and wanted to avoid duplicating logic from libcs.
> > +1
> > > I don't see why, __OPEN_NEEDS_MODE is going to be different between
> > > functions and libc/kernel versions.
> Haven't thought about that, that's a good point in my opinion.
> > Looking at glibc's __OPEN_NEEDS_MODE definition, the logic is obviously the same
> > as musl code for open (it just use O_TMPFILE instead of __O_TMPFILE therefore no
> > need to check for #ifdef __O_TMPFILE).
> I agree, for open/openat this approach would be fairly simple, there is
> semctl too though, I'll need to have a look how glibc and musl handle it.
Thanks a lot for your time Tudor!
Kind regards,
Petr
> Kind regards,
> Tudor
> > Kind regards,
> > Petr
> > > Reviewed-by: Richard Palethorpe <rpalethorpe@suse.com>
> > > Tudor Cretu <tudor.cretu@arm.com> writes:
> > > > Accessing elements in an empty va_list results in undefined behaviour[0]
> > > > that can include accessing arbitrary stack memory. While typically this
> > > > doesn't raise a fault, some new more security-oriented architectures
> > > > (e.g. CHERI[1] or Morello[2]) don't allow it.
> > > > Therefore, remove the variadicness from safe_* wrappers that always call
> > > > the functions with the optional argument included.
> > > > Adapt the respective SAFE_* macros to handle the change by passing a
> > > > default argument if they're omitted.
> > > > [0]: [ISO/IEC 9899:2011] Programming Languages—C, 3rd ed, paragraph 7.16.1.1
> > > > [1]: https://www.cl.cam.ac.uk/research/security/ctsrd/cheri/
> > > > [2]: https://www.morello-project.org/
> > > > v2..v1:
> > > > - PATCH 1: Remove the NULL argument for mode from SAFE_OPEN instances
> > > > to avoid the pointer to int conversion.
> > > > Tudor Cretu (3):
> > > > safe_open: Fix undefined behaviour in vararg handling
> > > > safe_openat: Fix undefined behaviour in vararg handling
> > > > safe_semctl: Fix undefined behaviour in vararg handling
> > > > include/old/safe_macros.h | 6 ++++--
> > > > include/safe_macros_fn.h | 3 ++-
> > > > include/tst_safe_file_at.h | 10 ++++++----
> > > > include/tst_safe_macros.h | 6 ++++--
> > > > include/tst_safe_sysv_ipc.h | 14 +++++++++-----
> > > > lib/safe_macros.c | 13 +------------
> > > > lib/tst_cgroup.c | 2 +-
> > > > lib/tst_safe_file_at.c | 11 +++--------
> > > > lib/tst_safe_sysv_ipc.c | 10 +---------
> > > > testcases/kernel/syscalls/fgetxattr/fgetxattr01.c | 2 +-
> > > > testcases/kernel/syscalls/fgetxattr/fgetxattr02.c | 2 +-
> > > > testcases/kernel/syscalls/fgetxattr/fgetxattr03.c | 2 +-
> > > > testcases/kernel/syscalls/fsetxattr/fsetxattr01.c | 2 +-
> > > > testcases/kernel/syscalls/fsetxattr/fsetxattr02.c | 2 +-
> > > > 14 files changed, 36 insertions(+), 49 deletions(-)
> > > > --
> > > > 2.25.1
--
Mailing list info: https://lists.linux.it/listinfo/ltp
next prev parent reply other threads:[~2022-11-29 15:16 UTC|newest]
Thread overview: 9+ messages / expand[flat|nested] mbox.gz Atom feed top
2022-11-29 13:03 [LTP] [PATCH v2 0/3] safe_macros: Fix undefined behaviour in vararg handling Tudor Cretu
2022-11-29 13:03 ` [LTP] [PATCH v2 1/3] safe_open: " Tudor Cretu
2022-11-29 13:03 ` [LTP] [PATCH v2 2/3] safe_openat: " Tudor Cretu
2022-11-29 13:03 ` [LTP] [PATCH v2 3/3] safe_semctl: " Tudor Cretu
2022-11-29 13:23 ` [LTP] [PATCH v2 0/3] safe_macros: " Richard Palethorpe
2022-11-29 13:59 ` Petr Vorel
2022-11-29 14:04 ` Tudor Cretu
2022-11-29 15:15 ` Petr Vorel [this message]
2022-11-30 13:43 ` Tudor Cretu
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=Y4YiL/Os2G+cZMFp@pevik \
--to=pvorel@suse.cz \
--cc=ltp@lists.linux.it \
--cc=tudor.cretu@arm.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox