提交 5a7b46b3 编写于 作者: O OGAWA Hirofumi 提交者: Linus Torvalds

[PATCH] Add more prevent_tail_call()

Those also break userland regs like following.

   00000000 <sys_chown16>:
      0:	0f b7 44 24 0c       	movzwl 0xc(%esp),%eax
      5:	83 ca ff             	or     $0xffffffff,%edx
      8:	0f b7 4c 24 08       	movzwl 0x8(%esp),%ecx
      d:	66 83 f8 ff          	cmp    $0xffffffff,%ax
     11:	0f 44 c2             	cmove  %edx,%eax
     14:	66 83 f9 ff          	cmp    $0xffffffff,%cx
     18:	0f 45 d1             	cmovne %ecx,%edx
     1b:	89 44 24 0c          	mov    %eax,0xc(%esp)
     1f:	89 54 24 08          	mov    %edx,0x8(%esp)
     23:	e9 fc ff ff ff       	jmp    24 <sys_chown16+0x24>

where the tailcall at the end overwrites the incoming stack-frame.
Signed-off-by: NOGAWA Hirofumi <hirofumi@mail.parknet.co.jp>
[ I would _really_ like to have a way to tell gcc about calling
  conventions. The "prevent_tail_call()" macro is pretty ugly ]
Signed-off-by: NLinus Torvalds <torvalds@osdl.org>
上级 52824b6b
...@@ -20,43 +20,67 @@ ...@@ -20,43 +20,67 @@
asmlinkage long sys_chown16(const char __user * filename, old_uid_t user, old_gid_t group) asmlinkage long sys_chown16(const char __user * filename, old_uid_t user, old_gid_t group)
{ {
return sys_chown(filename, low2highuid(user), low2highgid(group)); long ret = sys_chown(filename, low2highuid(user), low2highgid(group));
/* avoid REGPARM breakage on x86: */
prevent_tail_call(ret);
return ret;
} }
asmlinkage long sys_lchown16(const char __user * filename, old_uid_t user, old_gid_t group) asmlinkage long sys_lchown16(const char __user * filename, old_uid_t user, old_gid_t group)
{ {
return sys_lchown(filename, low2highuid(user), low2highgid(group)); long ret = sys_lchown(filename, low2highuid(user), low2highgid(group));
/* avoid REGPARM breakage on x86: */
prevent_tail_call(ret);
return ret;
} }
asmlinkage long sys_fchown16(unsigned int fd, old_uid_t user, old_gid_t group) asmlinkage long sys_fchown16(unsigned int fd, old_uid_t user, old_gid_t group)
{ {
return sys_fchown(fd, low2highuid(user), low2highgid(group)); long ret = sys_fchown(fd, low2highuid(user), low2highgid(group));
/* avoid REGPARM breakage on x86: */
prevent_tail_call(ret);
return ret;
} }
asmlinkage long sys_setregid16(old_gid_t rgid, old_gid_t egid) asmlinkage long sys_setregid16(old_gid_t rgid, old_gid_t egid)
{ {
return sys_setregid(low2highgid(rgid), low2highgid(egid)); long ret = sys_setregid(low2highgid(rgid), low2highgid(egid));
/* avoid REGPARM breakage on x86: */
prevent_tail_call(ret);
return ret;
} }
asmlinkage long sys_setgid16(old_gid_t gid) asmlinkage long sys_setgid16(old_gid_t gid)
{ {
return sys_setgid(low2highgid(gid)); long ret = sys_setgid(low2highgid(gid));
/* avoid REGPARM breakage on x86: */
prevent_tail_call(ret);
return ret;
} }
asmlinkage long sys_setreuid16(old_uid_t ruid, old_uid_t euid) asmlinkage long sys_setreuid16(old_uid_t ruid, old_uid_t euid)
{ {
return sys_setreuid(low2highuid(ruid), low2highuid(euid)); long ret = sys_setreuid(low2highuid(ruid), low2highuid(euid));
/* avoid REGPARM breakage on x86: */
prevent_tail_call(ret);
return ret;
} }
asmlinkage long sys_setuid16(old_uid_t uid) asmlinkage long sys_setuid16(old_uid_t uid)
{ {
return sys_setuid(low2highuid(uid)); long ret = sys_setuid(low2highuid(uid));
/* avoid REGPARM breakage on x86: */
prevent_tail_call(ret);
return ret;
} }
asmlinkage long sys_setresuid16(old_uid_t ruid, old_uid_t euid, old_uid_t suid) asmlinkage long sys_setresuid16(old_uid_t ruid, old_uid_t euid, old_uid_t suid)
{ {
return sys_setresuid(low2highuid(ruid), low2highuid(euid), long ret = sys_setresuid(low2highuid(ruid), low2highuid(euid),
low2highuid(suid)); low2highuid(suid));
/* avoid REGPARM breakage on x86: */
prevent_tail_call(ret);
return ret;
} }
asmlinkage long sys_getresuid16(old_uid_t __user *ruid, old_uid_t __user *euid, old_uid_t __user *suid) asmlinkage long sys_getresuid16(old_uid_t __user *ruid, old_uid_t __user *euid, old_uid_t __user *suid)
...@@ -72,8 +96,11 @@ asmlinkage long sys_getresuid16(old_uid_t __user *ruid, old_uid_t __user *euid, ...@@ -72,8 +96,11 @@ asmlinkage long sys_getresuid16(old_uid_t __user *ruid, old_uid_t __user *euid,
asmlinkage long sys_setresgid16(old_gid_t rgid, old_gid_t egid, old_gid_t sgid) asmlinkage long sys_setresgid16(old_gid_t rgid, old_gid_t egid, old_gid_t sgid)
{ {
return sys_setresgid(low2highgid(rgid), low2highgid(egid), long ret = sys_setresgid(low2highgid(rgid), low2highgid(egid),
low2highgid(sgid)); low2highgid(sgid));
/* avoid REGPARM breakage on x86: */
prevent_tail_call(ret);
return ret;
} }
asmlinkage long sys_getresgid16(old_gid_t __user *rgid, old_gid_t __user *egid, old_gid_t __user *sgid) asmlinkage long sys_getresgid16(old_gid_t __user *rgid, old_gid_t __user *egid, old_gid_t __user *sgid)
...@@ -89,12 +116,18 @@ asmlinkage long sys_getresgid16(old_gid_t __user *rgid, old_gid_t __user *egid, ...@@ -89,12 +116,18 @@ asmlinkage long sys_getresgid16(old_gid_t __user *rgid, old_gid_t __user *egid,
asmlinkage long sys_setfsuid16(old_uid_t uid) asmlinkage long sys_setfsuid16(old_uid_t uid)
{ {
return sys_setfsuid(low2highuid(uid)); long ret = sys_setfsuid(low2highuid(uid));
/* avoid REGPARM breakage on x86: */
prevent_tail_call(ret);
return ret;
} }
asmlinkage long sys_setfsgid16(old_gid_t gid) asmlinkage long sys_setfsgid16(old_gid_t gid)
{ {
return sys_setfsgid(low2highgid(gid)); long ret = sys_setfsgid(low2highgid(gid));
/* avoid REGPARM breakage on x86: */
prevent_tail_call(ret);
return ret;
} }
static int groups16_to_user(old_gid_t __user *grouplist, static int groups16_to_user(old_gid_t __user *grouplist,
......
Markdown is supported
0% .
You are about to add 0 people to the discussion. Proceed with caution.
先完成此消息的编辑!
想要评论请 注册