Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1684393

Re: [PATCH v2 1/8] exec: Correct comments about "point of no return"

From Kees Cook <keescook@chromium.org>
Newsgroups linux.kernel
Subject Re: [PATCH v2 1/8] exec: Correct comments about "point of no return"
Date 2017-07-10 18:10 +0200
Message-ID <u1Jq2-7dI-19@gated-at.bofh.it> (permalink)
References <u1BLP-2bz-7@gated-at.bofh.it> <u1BLP-2bz-5@gated-at.bofh.it> <u1CHX-2Lf-87@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


On Mon, Jul 10, 2017 at 1:46 AM, Eric W. Biederman
<ebiederm@xmission.com> wrote:
>
> But you miss it.
>
> The "point of no return" is the call to de_thread.  Or aguably anything in
> flush_old_exec.  Once anything in the current task is modified you can't
> return an error.
>
> It very much does not have anything to do with brpm.    It has
> everything to do with current.

Yes, but the thing that actually enforces this is the test of bprm->mm
and the SIGSEGV in search_binary_handlers().

-Kees

>
>
>> diff --git a/fs/exec.c b/fs/exec.c
>> index 904199086490..7842ae661e34 100644
>> --- a/fs/exec.c
>> +++ b/fs/exec.c
>> @@ -1285,7 +1285,14 @@ int flush_old_exec(struct linux_binprm * bprm)
>>       if (retval)
>>               goto out;
>>
>> -     bprm->mm = NULL;                /* We're using it now */
>> +     /*
>> +      * After clearing bprm->mm (to mark that current is using the
>> +      * prepared mm now), we are at the point of no return. If
>> +      * anything from here on returns an error, the check in
>> +      * search_binary_handler() will kill current (since the mm has
>> +      * been replaced).
>> +      */
>> +     bprm->mm = NULL;
>>
>>       set_fs(USER_DS);
>>       current->flags &= ~(PF_RANDOMIZE | PF_FORKNOEXEC | PF_KTHREAD |
>
> Eric



-- 
Kees Cook
Pixel Security

Back to linux.kernel | Previous | NextPrevious in thread | Next in thread | Find similar | Unroll thread


Thread

[PATCH v2 1/8] exec: Correct comments about "point of no return" Kees Cook <keescook@chromium.org> - 2017-07-10 10:00 +0200
  Re: [PATCH v2 1/8] exec: Correct comments about "point of no return" ebiederm@xmission.com (Eric W. Biederman) - 2017-07-10 11:00 +0200
    Re: [PATCH v2 1/8] exec: Correct comments about "point of no return" Kees Cook <keescook@chromium.org> - 2017-07-10 18:10 +0200
      Re: [PATCH v2 1/8] exec: Correct comments about "point of no return" Kees Cook <keescook@chromium.org> - 2017-07-18 08:40 +0200

csiph-web