Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.kernel > #1671997
| Path | csiph.com!eternal-september.org!feeder.eternal-september.org!aioe.org!bofh.it!news.nic.it!robomod |
|---|---|
| From | Kees Cook <keescook@chromium.org> |
| Newsgroups | linux.kernel |
| Subject | [PATCH v3] refcount: Create unchecked atomic_t implementation |
| Date | Wed, 21 Jun 2017 22:10:01 +0200 |
| Message-ID | <tUU6R-2DB-9@gated-at.bofh.it> (permalink) |
| Dkim-Signature | v=1; a=rsa-sha256; c=relaxed/relaxed; d=chromium.org; s=google; h=date:from:to:cc:subject:message-id:mime-version:content-disposition; bh=zMmGwPKXN5ekmFoP9/bZeMiwTPWnBtBvV11yVsNIUN4=; b=TwQ5JK4gOLaHlgZqGAPyZBfYmZXYYhpxIp9PkuGVazdpHftexueC0QUBwQNabPxGCl CZzA7/CLim5lP1yBqr/1ys6gra6IoihmEoh4DcR46zaZMtMFH9L43eW4+mChOj/KtdxT ujnh+ov7+lBnGgygDnaIVHXeOCmkSjTja/yKQ= |
| X-Google-Dkim-Signature | v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:date:from:to:cc:subject:message-id:mime-version :content-disposition; bh=zMmGwPKXN5ekmFoP9/bZeMiwTPWnBtBvV11yVsNIUN4=; b=dKZAkUZ8ieLI1ykrE0ioERV38Zg1h0YLrG9A8r0HjK7ZfWN5wlSywlt5JbYwOj6seF SmvoOLQnTfBD7UbbuPT3niCe5IhBi+ShwmQKBJuXbXlpI6ImEmxfJTwuLsELf/NPv1/a hX3Uf+DlDeOLEP/iwRdBdEyBw7UfCnFgAMIItZ0IxpV2E2MvZZQEoZN1lJ/4CigVoCJa 42k08WvJUjQY/rK/cw23lv/noBVQN970HKBVfy2bEu6lousyZUybi9jSglHkekInJ7vh hxkPBhuhtjylIT/op1xTmFv01Su9JhO2xp2qwXTeK7zf9Ipj1ifGBY1PPOBIfqlM5dKy QKVQ== |
| X-Gm-Message-State | AKS2vOw5HoxkfBIxNS9HdQiK6UX3vtVgUVe3OeC8LJZw2uJnQFV4ydkt tFNN2sbMFjCEZVtU |
| X-Received | by 10.99.104.136 with SMTP id d130mr38724342pgc.236.1498075227610; Wed, 21 Jun 2017 13:00:27 -0700 (PDT) |
| MIME-Version | 1.0 |
| Content-Type | text/plain; charset=us-ascii |
| Content-Disposition | inline |
| Sender | robomod@news.nic.it |
| List-ID | <linux-kernel.vger.kernel.org> |
| X-Mailing-List | linux-kernel@vger.kernel.org |
| Approved | robomod@news.nic.it |
| Lines | 124 |
| Organization | linux.* mail to news gateway |
| X-Original-Cc | linux-kernel@vger.kernel.org, Christoph Hellwig <hch@infradead.org>, Peter Zijlstra <peterz@infradead.org>, "Eric W. Biederman" <ebiederm@xmission.com>, Andrew Morton <akpm@linux-foundation.org>, Josh Poimboeuf <jpoimboe@redhat.com>, Jann Horn <jannh@google.com>, Eric Biggers <ebiggers3@gmail.com>, Elena Reshetova <elena.reshetova@intel.com>, Hans Liljestrand <ishkamiel@gmail.com>, David Windsor <dwindsor@gmail.com>, Greg KH <gregkh@linuxfoundation.org>, Ingo Molnar <mingo@redhat.com>, Alexey Dobriyan <adobriyan@gmail.com>, "Serge E. Hallyn" <serge@hallyn.com>, arozansk@redhat.com, Davidlohr Bueso <dave@stgolabs.net>, Manfred Spraul <manfred@colorfullife.com>, "axboe@kernel.dk" <axboe@kernel.dk>, James Bottomley <James.Bottomley@hansenpartnership.com>, "x86@kernel.org" <x86@kernel.org>, Arnd Bergmann <arnd@arndb.de>, "David S. Miller" <davem@davemloft.net>, Rik van Riel <riel@redhat.com>, linux-arch <linux-arch@vger.kernel.org> |
| X-Original-Date | Wed, 21 Jun 2017 13:00:26 -0700 |
| X-Original-Message-ID | <20170621200026.GA115679@beast> |
| X-Original-Sender | linux-kernel-owner@vger.kernel.org |
| Xref | csiph.com linux.kernel:1671997 |
Show key headers only | View raw
Many subsystems will not use refcount_t unless there is a way to build the
kernel so that there is no regression in speed compared to atomic_t. This
adds CONFIG_REFCOUNT_FULL to enable the full refcount_t implementation
which has the validation but is slightly slower. When not enabled,
refcount_t uses the basic unchecked atomic_t routines, which results in
no code changes compared to just using atomic_t directly.
Signed-off-by: Kees Cook <keescook@chromium.org>
Acked-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
v3: unbreak slightly long lines; Ingo. Add Greg's Ack.
v2: use better atomic ops; Elena and Peter.
---
arch/Kconfig | 9 +++++++++
include/linux/refcount.h | 42 ++++++++++++++++++++++++++++++++++++++++++
lib/refcount.c | 3 +++
3 files changed, 54 insertions(+)
diff --git a/arch/Kconfig b/arch/Kconfig
index 6c00e5b00f8b..fba3bf186728 100644
--- a/arch/Kconfig
+++ b/arch/Kconfig
@@ -867,4 +867,13 @@ config STRICT_MODULE_RWX
config ARCH_WANT_RELAX_ORDER
bool
+config REFCOUNT_FULL
+ bool "Perform full reference count validation at the expense of speed"
+ help
+ Enabling this switches the refcounting infrastructure from a fast
+ unchecked atomic_t implementation to a fully state checked
+ implementation, which can be slower but provides protections
+ against various use-after-free conditions that can be used in
+ security flaw exploits.
+
source "kernel/gcov/Kconfig"
diff --git a/include/linux/refcount.h b/include/linux/refcount.h
index b34aa649d204..bb71f2871dac 100644
--- a/include/linux/refcount.h
+++ b/include/linux/refcount.h
@@ -41,6 +41,7 @@ static inline unsigned int refcount_read(const refcount_t *r)
return atomic_read(&r->refs);
}
+#ifdef CONFIG_REFCOUNT_FULL
extern __must_check bool refcount_add_not_zero(unsigned int i, refcount_t *r);
extern void refcount_add(unsigned int i, refcount_t *r);
@@ -52,6 +53,47 @@ extern void refcount_sub(unsigned int i, refcount_t *r);
extern __must_check bool refcount_dec_and_test(refcount_t *r);
extern void refcount_dec(refcount_t *r);
+#else
+static inline __must_check bool refcount_add_not_zero(unsigned int i, refcount_t *r)
+{
+ return atomic_add_unless(&r->refs, i, 0);
+}
+
+static inline void refcount_add(unsigned int i, refcount_t *r)
+{
+ atomic_add(i, &r->refs);
+}
+
+static inline __must_check bool refcount_inc_not_zero(refcount_t *r)
+{
+ return atomic_add_unless(&r->refs, 1, 0);
+}
+
+static inline void refcount_inc(refcount_t *r)
+{
+ atomic_inc(&r->refs);
+}
+
+static inline __must_check bool refcount_sub_and_test(unsigned int i, refcount_t *r)
+{
+ return atomic_sub_and_test(i, &r->refs);
+}
+
+static inline void refcount_sub(unsigned int i, refcount_t *r)
+{
+ atomic_sub(i, &r->refs);
+}
+
+static inline __must_check bool refcount_dec_and_test(refcount_t *r)
+{
+ return atomic_dec_and_test(&r->refs);
+}
+
+static inline void refcount_dec(refcount_t *r)
+{
+ atomic_dec(&r->refs);
+}
+#endif /* CONFIG_REFCOUNT_FULL */
extern __must_check bool refcount_dec_if_one(refcount_t *r);
extern __must_check bool refcount_dec_not_one(refcount_t *r);
diff --git a/lib/refcount.c b/lib/refcount.c
index 9f906783987e..5d0582a9480c 100644
--- a/lib/refcount.c
+++ b/lib/refcount.c
@@ -37,6 +37,8 @@
#include <linux/refcount.h>
#include <linux/bug.h>
+#ifdef CONFIG_REFCOUNT_FULL
+
/**
* refcount_add_not_zero - add a value to a refcount unless it is 0
* @i: the value to add to the refcount
@@ -225,6 +227,7 @@ void refcount_dec(refcount_t *r)
WARN_ONCE(refcount_dec_and_test(r), "refcount_t: decrement hit 0; leaking memory.\n");
}
EXPORT_SYMBOL(refcount_dec);
+#endif /* CONFIG_REFCOUNT_FULL */
/**
* refcount_dec_if_one - decrement a refcount if it is 1
--
2.7.4
--
Kees Cook
Pixel Security
Back to linux.kernel | Previous | Next — Next in thread | Find similar | Unroll thread
[PATCH v3] refcount: Create unchecked atomic_t implementation Kees Cook <keescook@chromium.org> - 2017-06-21 22:10 +0200 [tip:locking/core] locking/refcount: Create unchecked atomic_t implementation tip-bot for Kees Cook <tipbot@zytor.com> - 2017-06-22 13:20 +0200 [tip:locking/core] locking/refcount: Create unchecked atomic_t implementation tip-bot for Kees Cook <tipbot@zytor.com> - 2017-06-28 20:00 +0200
csiph-web