Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1739553

Re: [PATCH v4 4/9] em28xx: fix em28xx_dvb_init for KASAN

Path csiph.com!news.redatomik.org!aioe.org!bofh.it!news.nic.it!robomod
From Arnd Bergmann <arnd@arndb.de>
Newsgroups linux.kernel
Subject Re: [PATCH v4 4/9] em28xx: fix em28xx_dvb_init for KASAN
Date Tue, 26 Sep 2017 08:50:02 +0200
Message-ID <utRQS-150-11@gated-at.bofh.it> (permalink)
References <usDPX-2NY-5@gated-at.bofh.it> <usDPY-2NY-33@gated-at.bofh.it> <utCRP-7FH-1@gated-at.bofh.it> <utRHc-10R-3@gated-at.bofh.it>
Dkim-Signature v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=mime-version:sender:in-reply-to:references:from:date:message-id :subject:to:cc; bh=PsEvcK00qK+dsHmnfbLaEKGdKNgYLeXgWN70UJEPpfA=; b=DQwqO8+HJkvMlpLe/7G/N/vY47XqnHcMp049iF9AJIU4+hOnZQxkXv8LYGW5/ueNQz CD/DIqq8w4GDyUuLfkZSwH0892h79fMl3E9eaSvrYEtpcFmRAgwhbJTL1toAZm6wB0UC bxEUm5SnQ6vlhj9+psAHFeKKBmFis6fbAl8TQAKZJqAcFvLAOBKBaehsaJLgWc5wHkJT NwQYAY5Rnydqjctupivk98eLekIDIrh4hjJfaj6impHPJ+Ro1Z3otLggCGNh2bgLXDLl cE9ziBBr5+NKOOa4AgUxHwkW+TWgBgxly5nIkqZ0amfLkfUy5ZZByQsYLDWz9gTjj6qF UYSw==
X-Google-Dkim-Signature v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:sender:in-reply-to:references:from :date:message-id:subject:to:cc; bh=PsEvcK00qK+dsHmnfbLaEKGdKNgYLeXgWN70UJEPpfA=; b=DSNlfzDbemses6WfnW0wZpd9FVMFT2nFxb/GIvdGgBEfc+/XAS6u3fCN7MM8cmmRDW fUpf7Yp2p7LefywI6R+GQhdkt+cO92M8qAUU1GbEaD1UXT3ucyc3a+sBx8UysaZgEE7Z FUWUBNNKVejzVLi5LBiJaTNmaoq6SIbtG4LSHsMAcLL2188DSFHS9/Wyhim2DJV7Gsoj /YqpSUPJcd9P5xR+tMY47767ZlHriL5eDBqssTAwRY9aE0eOIE27cGRJ6G9u4mAeonnD lAgWbzxmumJSOqtzYYDLZEyJzFfvZqYCovnvQqVgV86ty34YOa0iHyj89DwqvVuwGdkD jSew==
X-Gm-Message-State AHPjjUgq+b3ts5ug680lJ+Zs+6pEwkti6G4dtIpEXlM0t3RSW/DuSVmq S4cKbNRYvElBSUTj8b9/8hwRmpfLP9cGtJmvU6Q=
X-Google-SMTP-Source AOwi7QBkoQsPGX6+KCsfW699jGWzlBa61+GWW4zbkSgT42+3Eyz8LKSkStsBOCjtNVGsDFGyRlnkzbsFDw7yAoQILBk=
X-Received by 10.202.185.9 with SMTP id j9mr12374546oif.45.1506408466182; Mon, 25 Sep 2017 23:47:46 -0700 (PDT)
MIME-Version 1.0
X-Google-Sender-Auth HQ_mIl9Uz7wWSjTodbVv7aMZaN0
Content-Type text/plain; charset="UTF-8"
Sender robomod@news.nic.it
List-ID <linux-kernel.vger.kernel.org>
X-Mailing-List linux-kernel@vger.kernel.org
Approved robomod@news.nic.it
Lines 44
Organization linux.* mail to news gateway
X-Original-Cc Mauro Carvalho Chehab <mchehab@kernel.org>, Jiri Pirko <jiri@resnulli.us>, Arend van Spriel <arend.vanspriel@broadcom.com>, Kalle Valo <kvalo@codeaurora.org>, "David S. Miller" <davem@davemloft.net>, Andrey Ryabinin <aryabinin@virtuozzo.com>, Alexander Potapenko <glider@google.com>, Dmitry Vyukov <dvyukov@google.com>, Masahiro Yamada <yamada.masahiro@socionext.com>, Michal Marek <mmarek@suse.com>, Andrew Morton <akpm@linux-foundation.org>, Kees Cook <keescook@chromium.org>, Geert Uytterhoeven <geert@linux-m68k.org>, Greg Kroah-Hartman <gregkh@linuxfoundation.org>, "linux-media@vger.kernel.org" <linux-media@vger.kernel.org>, "linux-kernel@vger.kernel.org" <linux-kernel@vger.kernel.org>, "netdev@vger.kernel.org" <netdev@vger.kernel.org>, "linux-wireless@vger.kernel.org" <linux-wireless@vger.kernel.org>, "brcm80211-dev-list.pdl@broadcom.com" <brcm80211-dev-list.pdl@broadcom.com>, "brcm80211-dev-list@cypress.com" <brcm80211-dev-list@cypress.com>, "kasan-dev@googlegroups.com" <kasan-dev@googlegroups.com>, "linux-kbuild@vger.kernel.org" <linux-kbuild@vger.kernel.org>, Jakub Jelinek <jakub@gcc.gnu.org>, Martin Liška <marxin@gcc.gnu.org>, "stable@vger.kernel.org" <stable@vger.kernel.org>
X-Original-Date Mon, 25 Sep 2017 23:47:45 -0700
X-Original-Message-ID <CAK8P3a37Ts5q7BvA2JWse87huyAp+=e18CUXEt8731RrBnB+Ow@mail.gmail.com>
X-Original-References <20170922212930.620249-1-arnd@arndb.de> <20170922212930.620249-5-arnd@arndb.de> <063D6719AE5E284EB5DD2968C1650D6DD007F521@AcuExch.aculab.com> <CAK8P3a1zxjMsQTBPijCo8FJjEU5aRVTr7n_NZ1YM2UnDPKoRLw@mail.gmail.com>
X-Original-Sender linux-kernel-owner@vger.kernel.org
Xref csiph.com linux.kernel:1739553

Show key headers only | View raw


On Mon, Sep 25, 2017 at 11:32 PM, Arnd Bergmann <arnd@arndb.de> wrote:
> On Mon, Sep 25, 2017 at 7:41 AM, David Laight <David.Laight@aculab.com> wrote:
>> From: Arnd Bergmann
>>> Sent: 22 September 2017 22:29
>> ...
>>> It seems that this is triggered in part by using strlcpy(), which the
>>> compiler doesn't recognize as copying at most 'len' bytes, since strlcpy
>>> is not part of the C standard.
>>
>> Neither is strncpy().
>>
>> It'll almost certainly be a marker in a header file somewhere,
>> so it should be possibly to teach it about other functions.
>
> I'm currently travelling and haven't investigated in detail, but from
> taking a closer look here, I found that the hardened 'strlcpy()'
> in include/linux/string.h triggers it. There is also a hardened
> (much shorted) 'strncpy()' that doesn't trigger it in the same file,
> and having only the extern declaration of strncpy also doesn't.

And a little more experimenting leads to this simple patch that fixes
the problem:

--- a/include/linux/string.h
+++ b/include/linux/string.h
@@ -254,7 +254,7 @@ __FORTIFY_INLINE size_t strlcpy(char *p, const
char *q, size_t size)
        size_t q_size = __builtin_object_size(q, 0);
        if (p_size == (size_t)-1 && q_size == (size_t)-1)
                return __real_strlcpy(p, q, size);
-       ret = strlen(q);
+       ret = __builtin_strlen(q);
        if (size) {
                size_t len = (ret >= size) ? size - 1 : ret;
                if (__builtin_constant_p(len) && len >= p_size)

The problem is apparently that the fortified strlcpy calls the fortified strlen,
which in turn calls strnlen and that ends up calling the extern '__real_strnlen'
that gcc cannot reduce to a constant expression for a constant input.

Not sure if that change is the best fix, but it seems to address the problem in
this driver and probably leads to better code in other places as well.

          Arnd

Back to linux.kernel | Previous | NextPrevious in thread | Next in thread | Find similar | Unroll thread


Thread

[PATCH v4 4/9] em28xx: fix em28xx_dvb_init for KASAN Arnd Bergmann <arnd@arndb.de> - 2017-09-22 23:40 +0200
  RE: [PATCH v4 4/9] em28xx: fix em28xx_dvb_init for KASAN David Laight <David.Laight@ACULAB.COM> - 2017-09-25 16:50 +0200
    Re: [PATCH v4 4/9] em28xx: fix em28xx_dvb_init for KASAN Arnd Bergmann <arnd@arndb.de> - 2017-09-26 08:40 +0200
      Re: [PATCH v4 4/9] em28xx: fix em28xx_dvb_init for KASAN Arnd Bergmann <arnd@arndb.de> - 2017-09-26 08:50 +0200
        Re: [PATCH v4 4/9] em28xx: fix em28xx_dvb_init for KASAN Arnd Bergmann <arnd@arndb.de> - 2017-09-27 15:30 +0200
          Re: [PATCH v4 4/9] em28xx: fix em28xx_dvb_init for KASAN Arnd Bergmann <arnd@arndb.de> - 2017-09-28 16:40 +0200
            Re: [PATCH v4 4/9] em28xx: fix em28xx_dvb_init for KASAN Arnd Bergmann <arnd@arndb.de> - 2017-10-02 10:40 +0200
              [PATCH] string.h: work around for increased stack usage Arnd Bergmann <arnd@arndb.de> - 2017-10-02 10:50 +0200
                Re: [PATCH] string.h: work around for increased stack usage Arnd Bergmann <arnd@arndb.de> - 2017-10-02 11:10 +0200

csiph-web