Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1408066

Re: [PATCH 01/23] all: syscall wrappers: add documentation

From Catalin Marinas <catalin.marinas@arm.com>
Newsgroups linux.kernel
Subject Re: [PATCH 01/23] all: syscall wrappers: add documentation
Date 2016-05-27 15:10 +0200
Message-ID <rDpGy-3QJ-21@gated-at.bofh.it> (permalink)
References <rCNUB-5tm-3@gated-at.bofh.it> <rDlCV-18r-5@gated-at.bofh.it> <rDmpk-1Gr-25@gated-at.bofh.it> <rDnEJ-2mG-5@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


On Fri, May 27, 2016 at 12:49:11PM +0200, Arnd Bergmann wrote:
> On Friday, May 27, 2016 10:30:52 AM CEST Catalin Marinas wrote:
> > On Fri, May 27, 2016 at 10:42:59AM +0200, Arnd Bergmann wrote:
> > > On Friday, May 27, 2016 8:03:57 AM CEST Heiko Carstens wrote:
> > > > > > > > Cost wise, this seems like it all cancels out in the end, but what
> > > > > > > > do I know?
> > > > > > > 
> > > > > > > I think you know something, and I also think Heiko and other s390 guys
> > > > > > > know something as well. So I'd like to listen their arguments here.
> > > > 
> > > > If it comes to 64 bit arguments for compat system calls: s390 also has an
> > > > x32-like ABI extension which allows user space to use full 64 bit
> > > > registers. As far as I know hardly anybody ever made use of that.
> > > > 
> > > > However even if that would be widely used, to me it wouldn't make sense to
> > > > add new compat system calls which allow 64 bit arguments, simply because
> > > > something like
> > > > 
> > > > c = (u32)a | (u64)b << 32;
> > > > 
> > > > can be done with a single 1-cycle instruction. It's just not worth the
> > > > extra effort to maintain additional system call variants.
> > > 
> > > For reference, both tile and mips also have separate 32-bit ABIs that are
> > > only used on 64-bit kernels (aside from the normal 32-bit ABI). Tile
> > > does it like s390 and passes 64-bit arguments as pairs, while MIPS
> > > and x86 and pass them as single registers.
> > 
> > AFAIK, x32 also requires that the upper half of a 64-bit reg is zeroed
> > by the user when a 32-bit value is passed. We could require the same on
> > AArch64/ILP32 but I'm a bit uneasy on trusting a multitude of C
> > libraries on this.
> 
> It's not about trusting a C library, it's about ensuring malicious code
> cannot pass argumentst that the kernel code assumes will never happen.

At least for pointers and sizes, we have additional checks in place
already, like __access_ok(). Most of the syscalls should be safe since
they either go through some compat functions taking 32-bit arguments or
are routed to native functions which already need to cope with a full
random 64-bit value.

On arm64, I think the only risk comes from syscall handlers expecting
32-bit arguments but using 64-bit types. Apart from pointer types, I
don't expect this to happen but we could enforce it via a
BUILD_BUG_ON(sizeof(t) > 4 && !__TYPE_IS_PTR(t)) in __SC_DELOUSE as per
the s390 implementation. With ILP32 if we go for 64-bit off_t, those
syscalls would be routed directly to the native layer.

-- 
Catalin

Back to linux.kernel | Previous | NextPrevious in thread | Next in thread | Find similar | Unroll thread


Thread

[PATCH v6 00/21] ILP32 for ARM64 Yury Norov <ynorov@caviumnetworks.com> - 2016-05-24 02:20 +0200
  [PATCH 05/23] all: wrap needed syscalls in generic unistd Yury Norov <ynorov@caviumnetworks.com> - 2016-05-24 02:30 +0200
  Re: [PATCH v6 00/21] ILP32 for ARM64 Yury Norov <ynorov@caviumnetworks.com> - 2016-05-25 18:50 +0200
  Re: [PATCH 01/23] all: syscall wrappers: add documentation David Miller <davem@davemloft.net> - 2016-05-25 21:40 +0200
    Re: [PATCH 01/23] all: syscall wrappers: add documentation David Miller <davem@davemloft.net> - 2016-05-25 22:30 +0200
      Re: [PATCH 01/23] all: syscall wrappers: add documentation Arnd Bergmann <arnd@arndb.de> - 2016-05-25 22:50 +0200
        Re: [PATCH 01/23] all: syscall wrappers: add documentation David Miller <davem@davemloft.net> - 2016-05-25 23:00 +0200
          Re: [PATCH 01/23] all: syscall wrappers: add documentation Arnd Bergmann <arnd@arndb.de> - 2016-05-25 23:10 +0200
            Re: [PATCH 01/23] all: syscall wrappers: add documentation David Miller <davem@davemloft.net> - 2016-05-25 23:30 +0200
              Re: [PATCH 01/23] all: syscall wrappers: add documentation Catalin Marinas <catalin.marinas@arm.com> - 2016-05-26 16:30 +0200
                Re: [PATCH 01/23] all: syscall wrappers: add documentation Catalin Marinas <catalin.marinas@arm.com> - 2016-05-26 17:20 +0200
                Re: [PATCH 01/23] all: syscall wrappers: add documentation David Miller <davem@davemloft.net> - 2016-05-26 21:50 +0200
                Re: [PATCH 01/23] all: syscall wrappers: add documentation Catalin Marinas <catalin.marinas@arm.com> - 2016-05-27 12:20 +0200
              Re: [PATCH 01/23] all: syscall wrappers: add documentation Catalin Marinas <catalin.marinas@arm.com> - 2016-05-27 00:40 +0200
                Re: [PATCH 01/23] all: syscall wrappers: add documentation Heiko Carstens <heiko.carstens@de.ibm.com> - 2016-05-27 08:10 +0200
                Re: [PATCH 01/23] all: syscall wrappers: add documentation Arnd Bergmann <arnd@arndb.de> - 2016-05-27 10:50 +0200
                Re: [PATCH 01/23] all: syscall wrappers: add documentation Catalin Marinas <catalin.marinas@arm.com> - 2016-05-27 11:40 +0200
                Re: [PATCH 01/23] all: syscall wrappers: add documentation Arnd Bergmann <arnd@arndb.de> - 2016-05-27 13:00 +0200
                Re: [PATCH 01/23] all: syscall wrappers: add documentation Catalin Marinas <catalin.marinas@arm.com> - 2016-05-27 15:10 +0200
                Re: [PATCH 01/23] all: syscall wrappers: add documentation Catalin Marinas <catalin.marinas@arm.com> - 2016-05-27 19:40 +0200
                Re: [PATCH 01/23] all: syscall wrappers: add documentation Catalin Marinas <catalin.marinas@arm.com> - 2016-05-27 11:10 +0200
    Re: [PATCH 01/23] all: syscall wrappers: add documentation Heiko Carstens <heiko.carstens@de.ibm.com> - 2016-05-27 08:00 +0200
  Re: [PATCH 18/23] arm64: ilp32: add sys_ilp32.c and a separate table (in entry.S) to use it Arnd Bergmann <arnd@arndb.de> - 2016-05-25 22:30 +0200

csiph-web