Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.kernel > #1631476
| From | Thomas Garnier <thgarnie@google.com> |
|---|---|
| Newsgroups | linux.kernel |
| Subject | Re: [PATCH v7 1/4] syscalls: Restore address limit after a syscall |
| Date | 2017-04-26 16:10 +0200 |
| Message-ID | <tAvNM-3kF-11@gated-at.bofh.it> (permalink) |
| References | <tuL8T-3IQ-35@gated-at.bofh.it> <tA2iL-148-33@gated-at.bofh.it> <tA9tT-5Lr-1@gated-at.bofh.it> <tAql3-84y-1@gated-at.bofh.it> |
| Organization | linux.* mail to news gateway |
On Wed, Apr 26, 2017 at 1:12 AM, Ingo Molnar <mingo@kernel.org> wrote:
>
> * Thomas Garnier <thgarnie@google.com> wrote:
>
>> >> +#ifdef CONFIG_ARCH_NO_SYSCALL_VERIFY_PRE_USERMODE_STATE
>> >> +/*
>> >> + * This function is called when an architecture specific implementation detected
>> >> + * an invalid address limit. The generic user-mode state checker will finish on
>> >> + * the appropriate BUG_ON.
>> >> + */
>> >> +asmlinkage void address_limit_check_failed(void)
>> >> +{
>> >> + verify_pre_usermode_state();
>> >> + panic("address_limit_check_failed called with a valid user-mode state");
>> >
>> > It's very unconstructive to unconditionally panic the system, just because some
>> > kernel code leaked the address limit! Do a warn-once printout and kill the current
>> > task (i.e. don't continue execution), but don't crash everything else!
>>
>> The original change did not crash the kernel for this exact reason.
>> Through reviews, there was an overall agreement that the kernel should
>> not continue in this state.
>
> Ok, I guess we can try that - but the panic message is still pretty misleading:
>
> panic("address_limit_check_failed called with a valid user-mode state");
>
> ... so it was called with a _valid_ user-mode state, and we crash due to something
> valid? Huh?
Yes the message is accurate but I agree that it is misleading and I
will improve it. The address_limit_check_failed function is called by
assembly code on different architectures once the state was detected
as invalid. Instead of crashing at different places, we redirect to
the generic handler (verify_pre_usermode_state) that will crash on the
appropriate BUG_ON line. The address_limit_check_failed function is
not supposed to comeback, the panic call is just a safe guard.
>
> ( Also, the style rule applies to kernel messages as well: function names should
> be referred to as "function_name()". )
Will change.
>
> Thanks,
>
> Ingo
--
Thomas
Back to linux.kernel | Previous | Next — Previous in thread | Find similar | Unroll thread
Re: [PATCH v7 1/4] syscalls: Restore address limit after a syscall Ingo Molnar <mingo@kernel.org> - 2017-04-25 08:40 +0200
Re: [PATCH v7 1/4] syscalls: Restore address limit after a syscall Thomas Garnier <thgarnie@google.com> - 2017-04-25 16:20 +0200
Re: [PATCH v7 1/4] syscalls: Restore address limit after a syscall Ingo Molnar <mingo@kernel.org> - 2017-04-26 10:20 +0200
Re: [PATCH v7 1/4] syscalls: Restore address limit after a syscall Thomas Garnier <thgarnie@google.com> - 2017-04-26 16:10 +0200
csiph-web