Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.kernel > #1358190
| From | James Morse <james.morse@arm.com> |
|---|---|
| Newsgroups | linux.kernel |
| Subject | Re: [PATCH v11 3/9] arm64: add copy_to/from_user to kprobes blacklist |
| Date | 2016-03-15 19:50 +0100 |
| Message-ID | <rd2cx-5Y5-1@gated-at.bofh.it> (permalink) |
| References | <raF0J-3nW-5@gated-at.bofh.it> <raF0K-3nW-21@gated-at.bofh.it> |
| Organization | linux.* mail to news gateway |
Hi David,
On 09/03/16 05:32, David Long wrote:
> From: "David A. Long" <dave.long@linaro.org>
> diff --git a/arch/arm64/lib/copy_from_user.S b/arch/arm64/lib/copy_from_user.S
> index 4699cd7..0ac2131 100644
> --- a/arch/arm64/lib/copy_from_user.S
> +++ b/arch/arm64/lib/copy_from_user.S
> @@ -66,6 +66,7 @@
> .endm
>
> end .req x5
> + .section .kprobes.text,"ax",%progbits
> ENTRY(__copy_from_user)
> ALTERNATIVE("nop", __stringify(SET_PSTATE_PAN(0)), ARM64_HAS_PAN, \
> CONFIG_ARM64_PAN)
> diff --git a/arch/arm64/lib/copy_to_user.S b/arch/arm64/lib/copy_to_user.S
> index 7512bbb..e4eb84c 100644
> --- a/arch/arm64/lib/copy_to_user.S
> +++ b/arch/arm64/lib/copy_to_user.S
> @@ -65,6 +65,7 @@
> .endm
>
> end .req x5
> + .section .kprobes.text,"ax",%progbits
> ENTRY(__copy_to_user)
> ALTERNATIVE("nop", __stringify(SET_PSTATE_PAN(0)), ARM64_HAS_PAN, \
> CONFIG_ARM64_PAN)
>
If I understand this correctly - you can't kprobe these ldr/str instructions as
the fault handler wouldn't find kprobe's out-of line version of the instruction
in the exception table... but why only these two functions? (for library
functions, we also have clear_user() and copy_in_user()...)
The get_user()/put_user() stuff in uaccess.h gets inlined all over the kernel, I
don't think its feasible to put all of these in a separate section.
Is it feasible to search the exception table at runtime instead? If an
address-to-be-kprobed appears in the list, we know it could generate exceptions,
so we should report that we can't probe this address. That would catch all of
the library functions, all the places uaccess.h was inlined, and anything new
that gets invented in the future.
> Currrently taking exceptions when accessing user data from a kprobe'd
(Nit: Currently)
Thanks,
James
Back to linux.kernel | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
[PATCH v11 0/9] arm64: Add kernel probes (kprobes) support David Long <dave.long@linaro.org> - 2016-03-09 06:40 +0100
[PATCH v11 4/9] arm64: add conditional instruction simulation support David Long <dave.long@linaro.org> - 2016-03-09 06:40 +0100
Re: [PATCH v11 4/9] arm64: add conditional instruction simulation support Marc Zyngier <marc.zyngier@arm.com> - 2016-03-13 13:10 +0100
Re: [PATCH v11 4/9] arm64: add conditional instruction simulation support Pratyush Anand <panand@redhat.com> - 2016-03-14 05:10 +0100
Re: [PATCH v11 4/9] arm64: add conditional instruction simulation support Marc Zyngier <marc.zyngier@arm.com> - 2016-03-14 08:40 +0100
[PATCH v11 3/9] arm64: add copy_to/from_user to kprobes blacklist David Long <dave.long@linaro.org> - 2016-03-09 06:40 +0100
Re: [PATCH v11 3/9] arm64: add copy_to/from_user to kprobes blacklist James Morse <james.morse@arm.com> - 2016-03-15 19:50 +0100
Re: [PATCH v11 3/9] arm64: add copy_to/from_user to kprobes blacklist Pratyush Anand <panand@redhat.com> - 2016-03-16 06:50 +0100
Re: [PATCH v11 3/9] arm64: add copy_to/from_user to kprobes blacklist James Morse <james.morse@arm.com> - 2016-03-16 11:30 +0100
Re: [PATCH v11 3/9] arm64: add copy_to/from_user to kprobes blacklist Pratyush Anand <panand@redhat.com> - 2016-03-17 09:00 +0100
RE: [PATCH v11 3/9] arm64: add copy_to/from_user to kprobes blacklist 平松雅巳 / HIRAMATU,MASAMI <masami.hiramatsu.pt@hitachi.com> - 2016-03-17 13:10 +0100
[PATCH v11 5/9] arm64: Kprobes with single stepping support David Long <dave.long@linaro.org> - 2016-03-09 06:40 +0100
[PATCH v11 9/9] kprobes: Add arm64 case in kprobe example module David Long <dave.long@linaro.org> - 2016-03-09 06:40 +0100
[PATCH v11 2/9] arm64: Add more test functions to insn.c David Long <dave.long@linaro.org> - 2016-03-09 06:40 +0100
[PATCH v11 8/9] arm64: Add kernel return probes support (kretprobes) David Long <dave.long@linaro.org> - 2016-03-09 06:40 +0100
RE: [PATCH v11 8/9] arm64: Add kernel return probes support (kretprobes) 平松雅巳 / HIRAMATU,MASAMI <masami.hiramatsu.pt@hitachi.com> - 2016-03-17 13:30 +0100
RE: [PATCH v11 8/9] arm64: Add kernel return probes support (kretprobes) 平松雅巳 / HIRAMATU,MASAMI <masami.hiramatsu.pt@hitachi.com> - 2016-03-17 14:00 +0100
csiph-web