Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.kernel > #1584547 > unrolled thread
| Started by | Elena Reshetova <elena.reshetova@intel.com> |
|---|---|
| First post | 2017-02-20 12:40 +0100 |
| Last post | 2017-02-22 16:50 +0100 |
| Articles | 4 — 4 participants |
Back to article view | Back to linux.kernel
[PATCH 0/3] ipc subsystem refcounter conversions Elena Reshetova <elena.reshetova@intel.com> - 2017-02-20 12:40 +0100
Re: [PATCH 0/3] ipc subsystem refcounter conversions Andy Shevchenko <andy.shevchenko@gmail.com> - 2017-02-20 12:50 +0100
RE: [PATCH 0/3] ipc subsystem refcounter conversions "Reshetova, Elena" <elena.reshetova@intel.com> - 2017-02-20 13:40 +0100
Re: [PATCH 0/3] ipc subsystem refcounter conversions Davidlohr Bueso <dave@stgolabs.net> - 2017-02-22 16:50 +0100
| From | Elena Reshetova <elena.reshetova@intel.com> |
|---|---|
| Date | 2017-02-20 12:40 +0100 |
| Subject | [PATCH 0/3] ipc subsystem refcounter conversions |
| Message-ID | <tcUtX-453-3@gated-at.bofh.it> |
Now when new refcount_t type and API are finally merged (see include/linux/refcount.h), the following patches convert various refcounters in the ipc susystem from atomic_t to refcount_t. By doing this we prevent intentional or accidental underflows or overflows that can led to use-after-free vulnerabilities. The below patches are fully independent and can be cherry-picked separately. Since we convert all kernel subsystems in the same fashion, resulting in about 300 patches, we have to group them for sending at least in some fashion to be manageable. Please excuse the long cc list. Elena Reshetova (3): ipc: convert ipc_namespace.count from atomic_t to refcount_t ipc: convert sem_undo_list.refcnt from atomic_t to refcount_t ipc: convert ipc_rcu.refcount from atomic_t to refcount_t include/linux/ipc_namespace.h | 5 +++-- ipc/msgutil.c | 2 +- ipc/namespace.c | 4 ++-- ipc/sem.c | 8 ++++---- ipc/util.c | 6 +++--- ipc/util.h | 3 ++- 6 files changed, 15 insertions(+), 13 deletions(-) -- 2.7.4
[toc] | [next] | [standalone]
| From | Andy Shevchenko <andy.shevchenko@gmail.com> |
|---|---|
| Date | 2017-02-20 12:50 +0100 |
| Message-ID | <tcUDE-48G-25@gated-at.bofh.it> |
| In reply to | #1584547 |
On Mon, Feb 20, 2017 at 1:29 PM, Elena Reshetova <elena.reshetova@intel.com> wrote: > Now when new refcount_t type and API are finally merged > (see include/linux/refcount.h), the following > patches convert various refcounters in the ipc susystem from atomic_t > to refcount_t. By doing this we prevent intentional or accidental > underflows or overflows that can led to use-after-free vulnerabilities. > > The below patches are fully independent and can be cherry-picked separately. > Since we convert all kernel subsystems in the same fashion, resulting > in about 300 patches, we have to group them for sending at least in some > fashion to be manageable. Please excuse the long cc list. Is that done using coccinelle? Can I see the semantic patch (sorry if I missed it earlier)? -- With Best Regards, Andy Shevchenko
[toc] | [prev] | [next] | [standalone]
| From | "Reshetova, Elena" <elena.reshetova@intel.com> |
|---|---|
| Date | 2017-02-20 13:40 +0100 |
| Message-ID | <tcVq2-4F1-9@gated-at.bofh.it> |
| In reply to | #1584552 |
[Multipart message — attachments visible in raw view] — view raw
> On Mon, Feb 20, 2017 at 1:29 PM, Elena Reshetova > <elena.reshetova@intel.com> wrote: > > Now when new refcount_t type and API are finally merged > > (see include/linux/refcount.h), the following > > patches convert various refcounters in the ipc susystem from atomic_t > > to refcount_t. By doing this we prevent intentional or accidental > > underflows or overflows that can led to use-after-free vulnerabilities. > > > > The below patches are fully independent and can be cherry-picked separately. > > Since we convert all kernel subsystems in the same fashion, resulting > > in about 300 patches, we have to group them for sending at least in some > > fashion to be manageable. Please excuse the long cc list. > > Is that done using coccinelle? Yes and no. The *finding* of cases that should be converted was done using coccinelle, but actual conversion was done manually for each case and not via semantic patch. There were many false-positives and all kind of other issues, so we had to analyse each variable separately to the extend we understand the code. > > Can I see the semantic patch (sorry if I missed it earlier)? Attached is the one we used to initially find variables. Best Regards, Elena.
[toc] | [prev] | [next] | [standalone]
| From | Davidlohr Bueso <dave@stgolabs.net> |
|---|---|
| Date | 2017-02-22 16:50 +0100 |
| Message-ID | <tdHl0-3U4-15@gated-at.bofh.it> |
| In reply to | #1584547 |
On Mon, 20 Feb 2017, Elena Reshetova wrote: > include/linux/ipc_namespace.h | 5 +++-- > ipc/msgutil.c | 2 +- > ipc/namespace.c | 4 ++-- > ipc/sem.c | 8 ++++---- > ipc/util.c | 6 +++--- > ipc/util.h | 3 ++- > 6 files changed, 15 insertions(+), 13 deletions(-) The SoB list is a bit weird... otherwise, the conversion obviously makes sense: Acked-by: Davidlohr Bueso <dave@stgolabs.net>
[toc] | [prev] | [standalone]
Back to top | Article view | linux.kernel
csiph-web