Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.kernel > #1459826
| From | Oleg Nesterov <oleg@redhat.com> |
|---|---|
| Newsgroups | linux.kernel |
| Subject | Re: [PATCH v4] powerpc: Do not make the entire heap executable |
| Date | 2016-08-10 22:30 +0200 |
| Message-ID | <s4Iit-1wh-3@gated-at.bofh.it> (permalink) |
| References | <s4GTp-n4-51@gated-at.bofh.it> |
| Organization | linux.* mail to news gateway |
On 08/10, Denys Vlasenko wrote: > > Currently, to support 32-bit binaries with PLT in BSS kernel maps *entire > brk area* with executable rights for all binaries, even --secure-plt ones. > > Stop doing that. Can't really review this patch, but at least the change in mm/mmap.c looks technically correct to me... One nit below, feel free to ignore. > @@ -2668,7 +2668,7 @@ static int do_brk(unsigned long addr, unsigned long request) > if (!len) > return 0; > > - flags = VM_DATA_DEFAULT_FLAGS | VM_ACCOUNT | mm->def_flags; > + flags |= VM_DATA_DEFAULT_FLAGS | VM_ACCOUNT | mm->def_flags; OK. But note that we have mlock_future_check(mm->def_flags); a few lines below and after this change this _looks_ wrong because VM_LOCKED can come from the new "flags" argument passed to do_brk(). Nobody does this right now, still this looks wrong/confusing. I'd suggest to add another change - mlock_future_check(mm->def_flags); + mlock_future_check(flags); or add a sanity check at the start to deny VM_LOCKED and perhaps something else... The same for vm_brk_flags() which after your change does do_brk_flags(flags); populate = (mm->def_flags & VM_LOCKED); again, this is just a nit, I do not think it will be ever called with VM_LOCKED in "flags". Oleg.
Back to linux.kernel | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
[PATCH v4] powerpc: Do not make the entire heap executable Denys Vlasenko <dvlasenk@redhat.com> - 2016-08-10 21:00 +0200
Re: [PATCH v4] powerpc: Do not make the entire heap executable Oleg Nesterov <oleg@redhat.com> - 2016-08-10 22:30 +0200
Re: [PATCH v4] powerpc: Do not make the entire heap executable Denys Vlasenko <dvlasenk@redhat.com> - 2016-08-19 14:40 +0200
Re: [PATCH v4] powerpc: Do not make the entire heap executable "Aneesh Kumar K.V" <aneesh.kumar@linux.vnet.ibm.com> - 2016-08-21 17:50 +0200
Re: [PATCH v4] powerpc: Do not make the entire heap executable Denys Vlasenko <dvlasenk@redhat.com> - 2016-08-22 20:40 +0200
Re: [PATCH v4] powerpc: Do not make the entire heap executable Jason Gunthorpe <jgunthorpe@obsidianresearch.com> - 2016-08-22 21:30 +0200
csiph-web