Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.kernel > #1358801
| From | James Morse <james.morse@arm.com> |
|---|---|
| Newsgroups | linux.kernel |
| Subject | Re: [PATCH v11 3/9] arm64: add copy_to/from_user to kprobes blacklist |
| Date | 2016-03-16 11:30 +0100 |
| Message-ID | <rdgSe-7Ep-13@gated-at.bofh.it> (permalink) |
| References | <raF0J-3nW-5@gated-at.bofh.it> <raF0K-3nW-21@gated-at.bofh.it> <rd2cx-5Y5-1@gated-at.bofh.it> <rdcvf-4sX-1@gated-at.bofh.it> |
| Organization | linux.* mail to news gateway |
Hi Pratyush, On 16/03/16 05:43, Pratyush Anand wrote: > On 15/03/2016:06:47:52 PM, James Morse wrote: >> If I understand this correctly - you can't kprobe these ldr/str instructions >> as the fault handler wouldn't find kprobe's out-of line version of the >> instruction in the exception table... but why only these two functions? (for >> library functions, we also have clear_user() and copy_in_user()...) > > May be not clear_user() because those are inlined, but may be __clear_user(). You're right - the other library functions in that same directory is what I meant.. >> Is it feasible to search the exception table at runtime instead? If an >> address-to-be-kprobed appears in the list, we know it could generate exceptions, >> so we should report that we can't probe this address. That would catch all of >> the library functions, all the places uaccess.h was inlined, and anything new >> that gets invented in the future. > > Sorry, probably I could not get it. How can an inlined addresses range be placed > in exception table or any other code area. Ah, not a section or code area, sorry I wasn't clear: When a fault happens in the kernel, the fault handler (/arch/arm64/mm/fault.c:do_page_fault()) calls search_exception_tables(regs->pc) to see if the faulting address has a 'fixup' registered. If it does, the fixup causes -EFAULT to be returned, if not it ends up in die(). The horrible block of assembler in arch/arm64/include/asm/uaccess.h:__get_user_asm() adds the address of the instruction that is allowed to fault to the __ex_table section: > .section __ex_table,"a" > .align 3 > .quad 1b, 3b > .previous Here 1b is the address of the instruction that can fault, and 3b is the fixup that moves -EFAULT into the return value. This works for get_user() and friends which are inlined all over the kernel. It even works for modules, as there is an exception table for each module which is searched by kernel/module.c:search_module_extables(). This list of addresses that can fault already exists, there is even an API function to check for a given address. Grabbing the nearest vmlinux, there are ~1300 entries in the __ex_table section, this patch blacklists two of them, using search_exception_tables() obviously blacklists them all. I've had a quick look at x86 and sparc, it looks like they allowed probed instructions to fault, do_page_fault()->kprobes_fault()->kprobe_fault_handler() - which uses the original probed address with search_exception_tables() to find and run the fixup. I doubt this is needed in an initial version of kprobes, (maybe its later in this series - I haven't read all the way through it yet). Thanks, James
Back to linux.kernel | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
[PATCH v11 0/9] arm64: Add kernel probes (kprobes) support David Long <dave.long@linaro.org> - 2016-03-09 06:40 +0100
[PATCH v11 4/9] arm64: add conditional instruction simulation support David Long <dave.long@linaro.org> - 2016-03-09 06:40 +0100
Re: [PATCH v11 4/9] arm64: add conditional instruction simulation support Marc Zyngier <marc.zyngier@arm.com> - 2016-03-13 13:10 +0100
Re: [PATCH v11 4/9] arm64: add conditional instruction simulation support Pratyush Anand <panand@redhat.com> - 2016-03-14 05:10 +0100
Re: [PATCH v11 4/9] arm64: add conditional instruction simulation support Marc Zyngier <marc.zyngier@arm.com> - 2016-03-14 08:40 +0100
[PATCH v11 3/9] arm64: add copy_to/from_user to kprobes blacklist David Long <dave.long@linaro.org> - 2016-03-09 06:40 +0100
Re: [PATCH v11 3/9] arm64: add copy_to/from_user to kprobes blacklist James Morse <james.morse@arm.com> - 2016-03-15 19:50 +0100
Re: [PATCH v11 3/9] arm64: add copy_to/from_user to kprobes blacklist Pratyush Anand <panand@redhat.com> - 2016-03-16 06:50 +0100
Re: [PATCH v11 3/9] arm64: add copy_to/from_user to kprobes blacklist James Morse <james.morse@arm.com> - 2016-03-16 11:30 +0100
Re: [PATCH v11 3/9] arm64: add copy_to/from_user to kprobes blacklist Pratyush Anand <panand@redhat.com> - 2016-03-17 09:00 +0100
RE: [PATCH v11 3/9] arm64: add copy_to/from_user to kprobes blacklist 平松雅巳 / HIRAMATU,MASAMI <masami.hiramatsu.pt@hitachi.com> - 2016-03-17 13:10 +0100
[PATCH v11 5/9] arm64: Kprobes with single stepping support David Long <dave.long@linaro.org> - 2016-03-09 06:40 +0100
[PATCH v11 9/9] kprobes: Add arm64 case in kprobe example module David Long <dave.long@linaro.org> - 2016-03-09 06:40 +0100
[PATCH v11 2/9] arm64: Add more test functions to insn.c David Long <dave.long@linaro.org> - 2016-03-09 06:40 +0100
[PATCH v11 8/9] arm64: Add kernel return probes support (kretprobes) David Long <dave.long@linaro.org> - 2016-03-09 06:40 +0100
RE: [PATCH v11 8/9] arm64: Add kernel return probes support (kretprobes) 平松雅巳 / HIRAMATU,MASAMI <masami.hiramatsu.pt@hitachi.com> - 2016-03-17 13:30 +0100
RE: [PATCH v11 8/9] arm64: Add kernel return probes support (kretprobes) 平松雅巳 / HIRAMATU,MASAMI <masami.hiramatsu.pt@hitachi.com> - 2016-03-17 14:00 +0100
csiph-web