Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1736995

Re: [kernel-hardening] Re: [PATCH v3 03/31] usercopy: Mark kmalloc caches as usercopy caches

Path csiph.com!news.redatomik.org!aioe.org!bofh.it!news.nic.it!robomod
From Kees Cook <keescook@chromium.org>
Newsgroups linux.kernel
Subject Re: [kernel-hardening] Re: [PATCH v3 03/31] usercopy: Mark kmalloc caches as usercopy caches
Date Thu, 21 Sep 2017 20:30:01 +0200
Message-ID <useox-4rm-7@gated-at.bofh.it> (permalink)
References <urU6t-818-3@gated-at.bofh.it> <urUpQ-8nU-21@gated-at.bofh.it> <usbAm-2Ne-17@gated-at.bofh.it> <usbTI-2TP-17@gated-at.bofh.it> <uscd3-3f6-7@gated-at.bofh.it>
X-Original-To Christopher Lameter <cl@linux.com>
Dkim-Signature v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20161025; h=mime-version:sender:in-reply-to:references:from:date:message-id :subject:to:cc; bh=3ee7/OmumcvfvMLGtr7owjKASU77O1jk6gLucUEr70U=; b=dy4Z/0qZ6XPFJG2PucRZICwWnSSLFbBaLMPHZKYxfC9AkDhgOqpdcQA96NWmcWFicR 4Vud4KTHxH/OrO150jqgbiBLXgUaHifmqFkiyjYLpoenEm6OeVo9YmckmdP1b4PC9LWU P4iG+VS342Ql4Jc9Ado02DCi8aLWepOx8laBkQ9tac2QwrfBSdxRDCCxrj4PP1i+JHUt su19kZqG2/cj7DXJrPeyzgOvf0i55XpF72xs9MNdioyY95F4aFw/KA8rwfGwgUEl4pI3 /cVSyCQFEIIl6FLliJYX8GufnC3FUIN/LEM+QLIEcaKZdKoneCelgpLemaFbtjZNg2+t T8oA==
Dkim-Signature v=1; a=rsa-sha256; c=relaxed/relaxed; d=chromium.org; s=google; h=mime-version:sender:in-reply-to:references:from:date:message-id :subject:to:cc; bh=3ee7/OmumcvfvMLGtr7owjKASU77O1jk6gLucUEr70U=; b=cAQFFezeFtLGtdqAeLGPoGBLOyiYMd/V3XnWVrxtX/KnAxcrTY9EpYkfaXHGNipSLa 3eA8tmKuM680YDtNQN+q/Cnd3nK845AG6o/Gs4CY4xWxWJCjnkFxYzvLZKs02w3qp+Ws I01TFJxSDltofSJ3bBd7FCEfZF49EyLBtXtSE=
X-Google-Dkim-Signature v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:sender:in-reply-to:references:from :date:message-id:subject:to:cc; bh=3ee7/OmumcvfvMLGtr7owjKASU77O1jk6gLucUEr70U=; b=LoN2A3p6oPhIVWGcFrpsmGSuNEmZwir5uoUtLCj+GoV38Y1n0XJjRNHxxYiopUAZtx XTc45/uoLseO+uuRV1Y+Op1WQ8posoksS9ajh/x5qoY5G4SaQJwOc79qeID/YQoIGxxM g5OFXTyoIc5YJngiHpJNNZQP2SSAlkAdN3p8W//DCiEL44nFVV7mAvyLZ+NDoStXCIR0 c5IPRLK/eHD/EK/vPMcxmrZwzECuw7S1SEoUoEvjcaF0CYgZ37Ng7NAH1dEHkYSJM9hj ILM0mFejdlHTIKFwjH9JoDaIg5mxqcOlxPLyPGjsPKtBn3RJD8GPEitYhZjDOg0jUMlV 6G5Q==
X-Gm-Message-State AHPjjUhLVOq9RYevkmthrsjCVZXl1BQ/i+Rtt5mcDN5Il5ek7AxAHtq2 DEA2IyinGZdI1I31TykwU6aWFrxmjDYEhkZwMny0bQ==
X-Google-SMTP-Source AOwi7QDYwP7eE4mDf5goXzs9ki3D4LWEv5+mHfuWw/eR9qwbSXyZldmTkauuKiD9Pxh/JSEm30WuGCgTu6+ab6ws73U=
X-Received by 10.107.137.74 with SMTP id l71mr469923iod.186.1506018404799; Thu, 21 Sep 2017 11:26:44 -0700 (PDT)
MIME-Version 1.0
X-Google-Sender-Auth oUNdyF0Fco1OMzmGI2omR2BaWag
Content-Type text/plain; charset="UTF-8"
Sender robomod@news.nic.it
List-ID <linux-kernel.vger.kernel.org>
X-Mailing-List linux-kernel@vger.kernel.org
Approved robomod@news.nic.it
Lines 42
Organization linux.* mail to news gateway
X-Original-Cc LKML <linux-kernel@vger.kernel.org>, David Windsor <dave@nullcore.net>, Pekka Enberg <penberg@kernel.org>, David Rientjes <rientjes@google.com>, Joonsoo Kim <iamjoonsoo.kim@lge.com>, Andrew Morton <akpm@linux-foundation.org>, Linux-MM <linux-mm@kvack.org>, linux-xfs@vger.kernel.org, "linux-fsdevel@vger.kernel.org" <linux-fsdevel@vger.kernel.org>, Network Development <netdev@vger.kernel.org>, "kernel-hardening@lists.openwall.com" <kernel-hardening@lists.openwall.com>
X-Original-Date Thu, 21 Sep 2017 11:26:43 -0700
X-Original-Message-ID <CAGXu5jKqWShVMqm6-moqgO7JUaJuFxw-9mMKak+WG1HgNJqc1Q@mail.gmail.com>
X-Original-References <1505940337-79069-1-git-send-email-keescook@chromium.org> <1505940337-79069-4-git-send-email-keescook@chromium.org> <alpine.DEB.2.20.1709211024120.14427@nuc-kabylake> <CAGXu5j+X6dWCGocG=P7pszTY-5OZ6Jmp-RsnDKox75M5rmVe4g@mail.gmail.com> <alpine.DEB.2.20.1709211102320.14742@nuc-kabylake>
X-Original-Sender linux-kernel-owner@vger.kernel.org
Xref csiph.com linux.kernel:1736995

Show key headers only | View raw


On Thu, Sep 21, 2017 at 9:04 AM, Christopher Lameter <cl@linux.com> wrote:
> On Thu, 21 Sep 2017, Kees Cook wrote:
>
>> > So what is the point of this patch?
>>
>> The DMA kmalloc caches are not whitelisted:
>
> The DMA kmalloc caches are pretty obsolete and mostly there for obscure
> drivers.
>
> ??

They may be obsolete, but they're still in the kernel, and they aren't
copied to userspace, so we can mark them.

>> >>                         kmalloc_dma_caches[i] = create_kmalloc_cache(n,
>> >> -                               size, SLAB_CACHE_DMA | flags);
>> >> +                               size, SLAB_CACHE_DMA | flags, 0, 0);
>>
>> So this is creating the distinction between the kmallocs that go to
>> userspace and those that don't. The expectation is that future work
>> can start to distinguish between "for userspace" and "only kernel"
>> kmalloc allocations, as is already done here for DMA.
>
> The creation of the kmalloc caches in earlier patches already setup the
> "whitelisting". Why do it twice?

Patch 1 is to allow for things to mark their whitelists. Patch 30
disables the full whitelisting, since then we've defined them all, so
the kmalloc caches need to mark themselves as whitelisted.

Patch 1 leaves unmarked things whitelisted so we can progressively
tighten the restriction and have a bisectable series. (i.e. if there
is something wrong with one of the whitelists in the series, it will
bisect to that one, not the one that removes the global whitelist from
patch 1.)

-Kees

-- 
Kees Cook
Pixel Security

Back to linux.kernel | Previous | NextPrevious in thread | Find similar | Unroll thread


Thread

[PATCH v3 00/31] Hardened usercopy whitelisting Kees Cook <keescook@chromium.org> - 2017-09-20 22:50 +0200
  [PATCH v3 26/31] fork: Provide usercopy whitelisting for task_struct Kees Cook <keescook@chromium.org> - 2017-09-20 23:00 +0200
  [PATCH v3 15/31] xfs: Define usercopy region in xfs_inode slab cache Kees Cook <keescook@chromium.org> - 2017-09-20 23:00 +0200
  [PATCH v3 07/31] ext4: Define usercopy region in ext4_inode_cache slab cache Kees Cook <keescook@chromium.org> - 2017-09-20 23:00 +0200
  [PATCH v3 29/31] arm: Implement thread_struct whitelist for hardened usercopy Kees Cook <keescook@chromium.org> - 2017-09-20 23:00 +0200
  [PATCH v3 25/31] fork: Define usercopy region in thread_stack slab caches Kees Cook <keescook@chromium.org> - 2017-09-20 23:00 +0200
  [PATCH v3 02/31] usercopy: Enforce slab cache usercopy region boundaries Kees Cook <keescook@chromium.org> - 2017-09-20 23:00 +0200
    Re: [PATCH v3 02/31] usercopy: Enforce slab cache usercopy region  boundaries Christopher Lameter <cl@linux.com> - 2017-09-21 17:30 +0200
  [PATCH v3 23/31] net: Restrict unwhitelisted proto caches to size 0 Kees Cook <keescook@chromium.org> - 2017-09-20 23:00 +0200
  [PATCH v3 17/31] scsi: Define usercopy region in scsi_sense_cache slab cache Kees Cook <keescook@chromium.org> - 2017-09-20 23:00 +0200
  [PATCH v3 19/31] ip: Define usercopy region in IP proto slab cache Kees Cook <keescook@chromium.org> - 2017-09-20 23:00 +0200
  [PATCH v3 28/31] arm64: Implement thread_struct whitelist for hardened usercopy Kees Cook <keescook@chromium.org> - 2017-09-20 23:00 +0200
  [PATCH v3 21/31] sctp: Define usercopy region in SCTP proto slab cache Kees Cook <keescook@chromium.org> - 2017-09-20 23:00 +0200
  [PATCH v3 31/31] lkdtm: Update usercopy tests for whitelisting Kees Cook <keescook@chromium.org> - 2017-09-20 23:00 +0200
  [PATCH v3 01/31] usercopy: Prepare for usercopy whitelisting Kees Cook <keescook@chromium.org> - 2017-09-20 23:00 +0200
    Re: [PATCH v3 01/31] usercopy: Prepare for usercopy whitelisting Christopher Lameter <cl@linux.com> - 2017-09-21 17:30 +0200
  [PATCH v3 08/31] ext2: Define usercopy region in ext2_inode_cache slab cache Kees Cook <keescook@chromium.org> - 2017-09-20 23:00 +0200
  [PATCH v3 18/31] net: Define usercopy region in struct proto slab cache Kees Cook <keescook@chromium.org> - 2017-09-20 23:00 +0200
  [PATCH v3 24/31] fork: Define usercopy region in mm_struct slab caches Kees Cook <keescook@chromium.org> - 2017-09-20 23:00 +0200
  [PATCH v3 04/31] dcache: Define usercopy region in dentry_cache slab cache Kees Cook <keescook@chromium.org> - 2017-09-20 23:10 +0200
  [PATCH v3 27/31] x86: Implement thread_struct whitelist for hardened usercopy Kees Cook <keescook@chromium.org> - 2017-09-20 23:10 +0200
  [PATCH v3 03/31] usercopy: Mark kmalloc caches as usercopy caches Kees Cook <keescook@chromium.org> - 2017-09-20 23:10 +0200
    Re: [PATCH v3 03/31] usercopy: Mark kmalloc caches as usercopy  caches Christopher Lameter <cl@linux.com> - 2017-09-21 17:30 +0200
      Re: [kernel-hardening] Re: [PATCH v3 03/31] usercopy: Mark kmalloc  caches as usercopy caches Kees Cook <keescook@chromium.org> - 2017-09-21 17:50 +0200
        Re: [kernel-hardening] Re: [PATCH v3 03/31] usercopy: Mark kmalloc  caches as usercopy caches Christopher Lameter <cl@linux.com> - 2017-09-21 18:10 +0200
          Re: [kernel-hardening] Re: [PATCH v3 03/31] usercopy: Mark kmalloc  caches as usercopy caches Kees Cook <keescook@chromium.org> - 2017-09-21 20:30 +0200

csiph-web