Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1670038

[PATCH 14/23] fork: define usercopy region in thread_stack, task_struct, mm_struct slab caches

From Kees Cook <keescook@chromium.org>
Newsgroups linux.kernel
Subject [PATCH 14/23] fork: define usercopy region in thread_stack, task_struct, mm_struct slab caches
Date 2017-06-20 01:40 +0200
Message-ID <tUer0-QH-37@gated-at.bofh.it> (permalink)
References <tUeqZ-QH-7@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


From: David Windsor <dave@nullcore.net>

In support of usercopy hardening, this patch defines a region in
the thread_stack, task_struct and mm_struct slab caches in which
userspace copy operations are allowed. Since only a single whitelisted
buffer region is used, this moves the usercopyable fields next to each
other in task_struct so a single window can cover them.

This region is known as the slab cache's usercopy region.  Slab
caches can now check that each copy operation involving cache-managed
memory falls entirely within the slab's usercopy region.

This patch is modified from Brad Spengler/PaX Team's PAX_USERCOPY
whitelisting code in the last public patch of grsecurity/PaX based on my
understanding of the code. Changes or omissions from the original code are
mine and don't reflect the original grsecurity/PaX code.

Signed-off-by: David Windsor <dave@nullcore.net>
[kees: adjust commit log]
Signed-off-by: Kees Cook <keescook@chromium.org>
---
 include/linux/sched.h | 15 ++++++++++++---
 kernel/fork.c         | 18 +++++++++++++-----
 2 files changed, 25 insertions(+), 8 deletions(-)

diff --git a/include/linux/sched.h b/include/linux/sched.h
index 2b69fc650201..345db7983af1 100644
--- a/include/linux/sched.h
+++ b/include/linux/sched.h
@@ -745,10 +745,19 @@ struct task_struct {
 	/* Signal handlers: */
 	struct signal_struct		*signal;
 	struct sighand_struct		*sighand;
-	sigset_t			blocked;
 	sigset_t			real_blocked;
-	/* Restored if set_restore_sigmask() was used: */
-	sigset_t			saved_sigmask;
+
+	/*
+	 * Usercopy slab whitelisting needs blocked, saved_sigmask
+	 * to be adjacent.
+	 */
+	struct {
+		sigset_t blocked;
+
+		/* Restored if set_restore_sigmask() was used */
+		sigset_t saved_sigmask;
+	};
+
 	struct sigpending		pending;
 	unsigned long			sas_ss_sp;
 	size_t				sas_ss_size;
diff --git a/kernel/fork.c b/kernel/fork.c
index e53770d2bf95..172df19baeb5 100644
--- a/kernel/fork.c
+++ b/kernel/fork.c
@@ -282,8 +282,9 @@ static void free_thread_stack(struct task_struct *tsk)
 
 void thread_stack_cache_init(void)
 {
-	thread_stack_cache = kmem_cache_create("thread_stack", THREAD_SIZE,
-					      THREAD_SIZE, 0, NULL);
+	thread_stack_cache = kmem_cache_create_usercopy("thread_stack",
+					THREAD_SIZE, THREAD_SIZE, 0, 0,
+					THREAD_SIZE, NULL);
 	BUG_ON(thread_stack_cache == NULL);
 }
 # endif
@@ -467,9 +468,14 @@ void __init fork_init(void)
 	int align = max_t(int, L1_CACHE_BYTES, ARCH_MIN_TASKALIGN);
 
 	/* create a slab on which task_structs can be allocated */
-	task_struct_cachep = kmem_cache_create("task_struct",
+	task_struct_cachep = kmem_cache_create_usercopy("task_struct",
 			arch_task_struct_size, align,
-			SLAB_PANIC|SLAB_NOTRACK|SLAB_ACCOUNT, NULL);
+			SLAB_PANIC|SLAB_NOTRACK|SLAB_ACCOUNT,
+			offsetof(struct task_struct, blocked),
+			offsetof(struct task_struct, saved_sigmask) -
+				offsetof(struct task_struct, blocked) +
+				sizeof(init_task.saved_sigmask),
+			NULL);
 #endif
 
 	/* do the arch specific task caches init */
@@ -2208,9 +2214,11 @@ void __init proc_caches_init(void)
 	 * maximum number of CPU's we can ever have.  The cpumask_allocation
 	 * is at the end of the structure, exactly for that reason.
 	 */
-	mm_cachep = kmem_cache_create("mm_struct",
+	mm_cachep = kmem_cache_create_usercopy("mm_struct",
 			sizeof(struct mm_struct), ARCH_MIN_MMSTRUCT_ALIGN,
 			SLAB_HWCACHE_ALIGN|SLAB_PANIC|SLAB_NOTRACK|SLAB_ACCOUNT,
+			offsetof(struct mm_struct, saved_auxv),
+			sizeof_field(struct mm_struct, saved_auxv),
 			NULL);
 	vm_area_cachep = KMEM_CACHE(vm_area_struct, SLAB_PANIC|SLAB_ACCOUNT);
 	mmap_init();
-- 
2.7.4

Back to linux.kernel | Previous | NextPrevious in thread | Next in thread | Find similar | Unroll thread


Thread

[PATCH 00/23] Hardened usercopy whitelisting Kees Cook <keescook@chromium.org> - 2017-06-20 01:40 +0200
  [PATCH 13/23] ufs: define usercopy region in ufs_inode_cache slab cache Kees Cook <keescook@chromium.org> - 2017-06-20 01:40 +0200
  [PATCH 22/23] usercopy: split user-controlled slabs to separate caches Kees Cook <keescook@chromium.org> - 2017-06-20 01:40 +0200
    Re: [kernel-hardening] [PATCH 22/23] usercopy: split user-controlled  slabs to separate caches Eric Biggers <ebiggers3@gmail.com> - 2017-06-20 06:30 +0200
    Re: [kernel-hardening] [PATCH 22/23] usercopy: split user-controlled  slabs to separate caches Eric Biggers <ebiggers3@gmail.com> - 2017-06-20 06:50 +0200
      Re: [kernel-hardening] [PATCH 22/23] usercopy: split user-controlled  slabs to separate caches Kees Cook <keescook@chromium.org> - 2017-06-21 00:30 +0200
    Re: [PATCH 22/23] usercopy: split user-controlled slabs to separate  caches Laura Abbott <labbott@redhat.com> - 2017-06-20 22:30 +0200
      Re: [PATCH 22/23] usercopy: split user-controlled slabs to separate caches Kees Cook <keescook@chromium.org> - 2017-06-21 00:30 +0200
        Re: [PATCH 22/23] usercopy: split user-controlled slabs to separate  caches Michal Hocko <mhocko@kernel.org> - 2017-06-27 09:40 +0200
          Re: [PATCH 22/23] usercopy: split user-controlled slabs to separate caches Kees Cook <keescook@chromium.org> - 2017-06-28 00:10 +0200
            Re: [PATCH 22/23] usercopy: split user-controlled slabs to separate  caches Michal Hocko <mhocko@kernel.org> - 2017-06-28 11:00 +0200
  [PATCH 08/23] ext2: define usercopy region in ext2_inode_cache slab cache Kees Cook <keescook@chromium.org> - 2017-06-20 01:40 +0200
  [PATCH 15/23] net: define usercopy region in struct proto slab cache Kees Cook <keescook@chromium.org> - 2017-06-20 01:40 +0200
  [PATCH 14/23] fork: define usercopy region in thread_stack, task_struct, mm_struct slab caches Kees Cook <keescook@chromium.org> - 2017-06-20 01:40 +0200
  [PATCH 11/23] jfs: define usercopy region in jfs_ip slab cache Kees Cook <keescook@chromium.org> - 2017-06-20 01:40 +0200
  [PATCH 20/23] usercopy: convert kmalloc caches to usercopy caches Kees Cook <keescook@chromium.org> - 2017-06-20 01:50 +0200
  [PATCH 05/23] befs: define usercopy region in befs_inode_cache slab cache Kees Cook <keescook@chromium.org> - 2017-06-20 01:50 +0200
  [PATCH 23/23] mm: Allow slab_nomerge to be set at build time Kees Cook <keescook@chromium.org> - 2017-06-20 01:50 +0200
    Re: [kernel-hardening] [PATCH 23/23] mm: Allow slab_nomerge to be  set at build time Daniel Micay <danielmicay@gmail.com> - 2017-06-20 06:10 +0200
      Re: [kernel-hardening] [PATCH 23/23] mm: Allow slab_nomerge to be set  at build time Kees Cook <keescook@chromium.org> - 2017-06-21 01:00 +0200
    Re: [kernel-hardening] [PATCH 23/23] mm: Allow slab_nomerge to be  set at build time Eric Biggers <ebiggers3@gmail.com> - 2017-06-20 06:30 +0200
      Re: [kernel-hardening] [PATCH 23/23] mm: Allow slab_nomerge to be set  at build time Kees Cook <keescook@chromium.org> - 2017-06-21 01:20 +0200
  [PATCH 19/23] xfs: define usercopy region in xfs_inode slab cache Kees Cook <keescook@chromium.org> - 2017-06-20 01:50 +0200
  [PATCH 01/23] usercopy: Prepare for usercopy whitelisting Kees Cook <keescook@chromium.org> - 2017-06-20 01:50 +0200
  [PATCH 03/23] vfs: define usercopy region in names_cache slab caches Kees Cook <keescook@chromium.org> - 2017-06-20 01:50 +0200
  [PATCH 17/23] dcache: define usercopy region in dentry_cache slab cache Kees Cook <keescook@chromium.org> - 2017-06-20 01:50 +0200
    Re: [kernel-hardening] [PATCH 17/23] dcache: define usercopy region  in dentry_cache slab cache Eric Biggers <ebiggers3@gmail.com> - 2017-06-20 06:10 +0200
      Re: [kernel-hardening] [PATCH 17/23] dcache: define usercopy region  in dentry_cache slab cache Eric Biggers <ebiggers3@gmail.com> - 2017-06-28 20:00 +0200
      Re: [kernel-hardening] [PATCH 17/23] dcache: define usercopy region  in dentry_cache slab cache Kees Cook <keescook@chromium.org> - 2017-06-28 20:00 +0200
  [PATCH 04/23] vfs: copy struct mount.mnt_id to userspace using put_user() Kees Cook <keescook@chromium.org> - 2017-06-20 01:50 +0200
  [PATCH 06/23] cifs: define usercopy region in cifs_request slab cache Kees Cook <keescook@chromium.org> - 2017-06-20 01:50 +0200
  [PATCH 21/23] usercopy: Restrict non-usercopy caches to size 0 Kees Cook <keescook@chromium.org> - 2017-06-20 01:50 +0200
    Re: [kernel-hardening] [PATCH 21/23] usercopy: Restrict non-usercopy  caches to size 0 Eric Biggers <ebiggers3@gmail.com> - 2017-06-20 06:10 +0200
      Re: [kernel-hardening] [PATCH 21/23] usercopy: Restrict non-usercopy  caches to size 0 Kees Cook <keescook@chromium.org> - 2017-06-28 20:00 +0200
  [PATCH 18/23] scsi: define usercopy region in scsi_sense_cache slab cache Kees Cook <keescook@chromium.org> - 2017-06-20 01:50 +0200
  [PATCH 02/23] usercopy: Enforce slab cache usercopy region boundaries Kees Cook <keescook@chromium.org> - 2017-06-20 01:50 +0200
  Re: [kernel-hardening] [PATCH 00/23] Hardened usercopy whitelisting Rik van Riel <riel@redhat.com> - 2017-06-20 21:50 +0200

csiph-web