Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.kernel > #1541535 > unrolled thread
| Started by | Arnd Bergmann <arnd@arndb.de> |
|---|---|
| First post | 2016-12-13 22:40 +0100 |
| Last post | 2016-12-14 01:10 +0100 |
| Articles | 4 — 4 participants |
Back to article view | Back to linux.kernel
This discussion starts older than the indexed window; earlier articles aren't shown. The article labeled Started by
below is the oldest one visible, not the original post.
Re: /drivers/char/Kconfig Bug Kernel Patch Arnd Bergmann <arnd@arndb.de> - 2016-12-13 22:40 +0100
Re: /drivers/char/Kconfig Bug Kernel Patch Josh Triplett <josh@joshtriplett.org> - 2016-12-13 23:50 +0100
Re: /drivers/char/Kconfig Bug Kernel Patch Max Bires <jbires@google.com> - 2016-12-14 00:00 +0100
Re: /drivers/char/Kconfig Bug Kernel Patch Greg KH <gregkh@linuxfoundation.org> - 2016-12-14 01:10 +0100
| From | Arnd Bergmann <arnd@arndb.de> |
|---|---|
| Date | 2016-12-13 22:40 +0100 |
| Subject | Re: /drivers/char/Kconfig Bug Kernel Patch |
| Message-ID | <sO2XM-6i5-7@gated-at.bofh.it> |
On Tuesday, December 13, 2016 1:30:39 PM CET Max Bires wrote: > While trying to turn off the port device in defconfig, I ran into a bug > caused by the fact that the Kconfig for port didn't have a string after the > bool declaration. I fixed this in the attached patch (though I figure the > description might need tuning up). Let me know if there's anything else I > need to do. The change looks reasonable, however there are a few things to improve to get the patch applied: - clarify that the current behavior is not a bug, but was done intentionally. Making the option user-visible would help avoid a potential attack vector and make the kernel smaller, both of which are useful. - remove the "Change-id" line from the submission, it has no meaning in an upstream kernel - send the patch inline rather than as an attachment, this is usually done with git-send-email. Arnd
[toc] | [next] | [standalone]
| From | Josh Triplett <josh@joshtriplett.org> |
|---|---|
| Date | 2016-12-13 23:50 +0100 |
| Message-ID | <sO43v-6XO-7@gated-at.bofh.it> |
| In reply to | #1541535 |
> From c4a21c2ac0c587094000a3daeb13eec6056dc63f Mon Sep 17 00:00:00 2001 > From: Max <jbires@google.com> > Date: Fri, 9 Dec 2016 15:16:47 -0800 > Subject: [PATCH] char: lack of bool string made CONFIG_DEVPORT always on > > Without a bool string present, using "# CONFIG_DEVPORT is not set" in > defconfig files would not actually unset devport. This ensured that > /dev/port was always on, but there are reasons a user may wish to disable > it (smaller kernel, attack surface reduction) if it's not being used. Adding > a message here in order to make this user visible. > > Signed-off-by: Max Bires <jbires@google.com> This patch seems reasonable to me. > drivers/char/Kconfig | 5 ++++- > 1 file changed, 4 insertions(+), 1 deletion(-) > > diff --git a/drivers/char/Kconfig b/drivers/char/Kconfig > index 7ad3127..70e626c 100644 > --- a/drivers/char/Kconfig > +++ b/drivers/char/Kconfig > @@ -589,10 +589,13 @@ config TELCLOCK > controlling the behavior of this hardware. > > config DEVPORT > - bool > + bool "/dev/port character device" > depends on !M68K > depends on ISA || PCI > default y > + help > + Say Y here if you want to support the /dev/port device. The > + /dev/port device is similar to /dev/mem, but for I/O ports. > > config DCC_TTY > tristate "DCC tty driver" > -- > 2.8.0.rc3.226.g39d4020
[toc] | [prev] | [next] | [standalone]
| From | Max Bires <jbires@google.com> |
|---|---|
| Date | 2016-12-14 00:00 +0100 |
| Message-ID | <sO43v-6XO-9@gated-at.bofh.it> |
| In reply to | #1541535 |
On Tue, Dec 13, 2016 at 1:37 PM, Arnd Bergmann <arnd@arndb.de> wrote: > > On Tuesday, December 13, 2016 1:30:39 PM CET Max Bires wrote: > > While trying to turn off the port device in defconfig, I ran into a bug > > caused by the fact that the Kconfig for port didn't have a string after the > > bool declaration. I fixed this in the attached patch (though I figure the > > description might need tuning up). Let me know if there's anything else I > > need to do. > > The change looks reasonable, however there are a few things to improve > to get the patch applied: > > - clarify that the current behavior is not a bug, but was done intentionally. > Making the option user-visible would help avoid a potential attack vector > and make the kernel smaller, both of which are useful. > > - remove the "Change-id" line from the submission, it has no meaning in > an upstream kernel > > - send the patch inline rather than as an attachment, this is usually done > with git-send-email. > > Arnd -First and second points have been addressed; I had some trouble with send-email, so let me know if the following isn't acceptable inlining. From c4a21c2ac0c587094000a3daeb13eec6056dc63f Mon Sep 17 00:00:00 2001 From: Max <jbires@google.com> Date: Fri, 9 Dec 2016 15:16:47 -0800 Subject: [PATCH] char: lack of bool string made CONFIG_DEVPORT always on Without a bool string present, using "# CONFIG_DEVPORT is not set" in defconfig files would not actually unset devport. This ensured that /dev/port was always on, but there are reasons a user may wish to disable it (smaller kernel, attack surface reduction) if it's not being used. Adding a message here in order to make this user visible. Signed-off-by: Max Bires <jbires@google.com> --- drivers/char/Kconfig | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/drivers/char/Kconfig b/drivers/char/Kconfig index 7ad3127..70e626c 100644 --- a/drivers/char/Kconfig +++ b/drivers/char/Kconfig @@ -589,10 +589,13 @@ config TELCLOCK controlling the behavior of this hardware. config DEVPORT - bool + bool "/dev/port character device" depends on !M68K depends on ISA || PCI default y + help + Say Y here if you want to support the /dev/port device. The + /dev/port device is similar to /dev/mem, but for I/O ports. config DCC_TTY tristate "DCC tty driver" -- 2.8.0.rc3.226.g39d4020
[toc] | [prev] | [next] | [standalone]
| From | Greg KH <gregkh@linuxfoundation.org> |
|---|---|
| Date | 2016-12-14 01:10 +0100 |
| Message-ID | <sO5iW-7RZ-3@gated-at.bofh.it> |
| In reply to | #1541548 |
On Tue, Dec 13, 2016 at 02:42:18PM -0800, Max Bires wrote: > On Tue, Dec 13, 2016 at 1:37 PM, Arnd Bergmann <arnd@arndb.de> wrote: > > > > On Tuesday, December 13, 2016 1:30:39 PM CET Max Bires wrote: > > > While trying to turn off the port device in defconfig, I ran into a bug > > > caused by the fact that the Kconfig for port didn't have a string after the > > > bool declaration. I fixed this in the attached patch (though I figure the > > > description might need tuning up). Let me know if there's anything else I > > > need to do. > > > > The change looks reasonable, however there are a few things to improve > > to get the patch applied: > > > > - clarify that the current behavior is not a bug, but was done intentionally. > > Making the option user-visible would help avoid a potential attack vector > > and make the kernel smaller, both of which are useful. > > > > - remove the "Change-id" line from the submission, it has no meaning in > > an upstream kernel > > > > - send the patch inline rather than as an attachment, this is usually done > > with git-send-email. > > > > Arnd > -First and second points have been addressed; I had some trouble with > send-email, so let me know if the following isn't acceptable inlining. > > >From c4a21c2ac0c587094000a3daeb13eec6056dc63f Mon Sep 17 00:00:00 2001 > From: Max <jbires@google.com> > Date: Fri, 9 Dec 2016 15:16:47 -0800 > Subject: [PATCH] char: lack of bool string made CONFIG_DEVPORT always on > > Without a bool string present, using "# CONFIG_DEVPORT is not set" in > defconfig files would not actually unset devport. This ensured that > /dev/port was always on, but there are reasons a user may wish to disable > it (smaller kernel, attack surface reduction) if it's not being used. Adding > a message here in order to make this user visible. It's not ok, you don't see patches look like this on the mailing list, right? Please use git send-email to do this properly as a stand-alone patch/email. Also, your "From:" line doesn't match your signed-off-by line :( > Signed-off-by: Max Bires <jbires@google.com> > --- > drivers/char/Kconfig | 5 ++++- > 1 file changed, 4 insertions(+), 1 deletion(-) > > diff --git a/drivers/char/Kconfig b/drivers/char/Kconfig > index 7ad3127..70e626c 100644 > --- a/drivers/char/Kconfig > +++ b/drivers/char/Kconfig > @@ -589,10 +589,13 @@ config TELCLOCK > controlling the behavior of this hardware. > > config DEVPORT > - bool > + bool "/dev/port character device" > depends on !M68K > depends on ISA || PCI > default y > + help > + Say Y here if you want to support the /dev/port device. The No tabs? thanks, greg k-h
[toc] | [prev] | [standalone]
Back to top | Article view | linux.kernel
csiph-web