提交 d4311ff1 编写于 作者: A Aaron Tomlin 提交者: Ingo Molnar

init/main.c: Give init_task a canary

Tasks get their end of stack set to STACK_END_MAGIC with the
aim to catch stack overruns. Currently this feature does not
apply to init_task. This patch removes this restriction.

Note that a similar patch was posted by Prarit Bhargava
some time ago but was never merged:

  http://marc.info/?l=linux-kernel&m=127144305403241&w=2Signed-off-by: NAaron Tomlin <atomlin@redhat.com>
Signed-off-by: NPeter Zijlstra (Intel) <peterz@infradead.org>
Acked-by: NOleg Nesterov <oleg@redhat.com>
Acked-by: NMichael Ellerman <mpe@ellerman.id.au>
Cc: aneesh.kumar@linux.vnet.ibm.com
Cc: dzickus@redhat.com
Cc: bmr@redhat.com
Cc: jcastillo@redhat.com
Cc: jgh@redhat.com
Cc: minchan@kernel.org
Cc: tglx@linutronix.de
Cc: hannes@cmpxchg.org
Cc: Alex Thorlton <athorlton@sgi.com>
Cc: Andrew Morton <akpm@linux-foundation.org>
Cc: Benjamin Herrenschmidt <benh@kernel.crashing.org>
Cc: Daeseok Youn <daeseok.youn@gmail.com>
Cc: David Rientjes <rientjes@google.com>
Cc: Fabian Frederick <fabf@skynet.be>
Cc: Geert Uytterhoeven <geert@linux-m68k.org>
Cc: Jiri Olsa <jolsa@redhat.com>
Cc: Kees Cook <keescook@chromium.org>
Cc: Kirill A. Shutemov <kirill.shutemov@linux.intel.com>
Cc: Linus Torvalds <torvalds@linux-foundation.org>
Cc: Masami Hiramatsu <masami.hiramatsu.pt@hitachi.com>
Cc: Michael Opdenacker <michael.opdenacker@free-electrons.com>
Cc: Paul Mackerras <paulus@samba.org>
Cc: Prarit Bhargava <prarit@redhat.com>
Cc: Rik van Riel <riel@redhat.com>
Cc: Rusty Russell <rusty@rustcorp.com.au>
Cc: Seiji Aguchi <seiji.aguchi@hds.com>
Cc: Steven Rostedt <rostedt@goodmis.org>
Cc: Vladimir Davydov <vdavydov@parallels.com>
Cc: Yasuaki Ishimatsu <isimatu.yasuaki@jp.fujitsu.com>
Cc: linuxppc-dev@lists.ozlabs.org
Link: http://lkml.kernel.org/r/1410527779-8133-2-git-send-email-atomlin@redhat.comSigned-off-by: NIngo Molnar <mingo@kernel.org>
上级 a15b12ac
...@@ -30,7 +30,6 @@ ...@@ -30,7 +30,6 @@
#include <linux/kprobes.h> #include <linux/kprobes.h>
#include <linux/kdebug.h> #include <linux/kdebug.h>
#include <linux/perf_event.h> #include <linux/perf_event.h>
#include <linux/magic.h>
#include <linux/ratelimit.h> #include <linux/ratelimit.h>
#include <linux/context_tracking.h> #include <linux/context_tracking.h>
...@@ -538,7 +537,7 @@ void bad_page_fault(struct pt_regs *regs, unsigned long address, int sig) ...@@ -538,7 +537,7 @@ void bad_page_fault(struct pt_regs *regs, unsigned long address, int sig)
regs->nip); regs->nip);
stackend = end_of_stack(current); stackend = end_of_stack(current);
if (current != &init_task && *stackend != STACK_END_MAGIC) if (*stackend != STACK_END_MAGIC)
printk(KERN_ALERT "Thread overran stack, or stack corrupted\n"); printk(KERN_ALERT "Thread overran stack, or stack corrupted\n");
die("Kernel access of bad area", regs, sig); die("Kernel access of bad area", regs, sig);
......
...@@ -3,7 +3,6 @@ ...@@ -3,7 +3,6 @@
* Copyright (C) 2001, 2002 Andi Kleen, SuSE Labs. * Copyright (C) 2001, 2002 Andi Kleen, SuSE Labs.
* Copyright (C) 2008-2009, Red Hat Inc., Ingo Molnar * Copyright (C) 2008-2009, Red Hat Inc., Ingo Molnar
*/ */
#include <linux/magic.h> /* STACK_END_MAGIC */
#include <linux/sched.h> /* test_thread_flag(), ... */ #include <linux/sched.h> /* test_thread_flag(), ... */
#include <linux/kdebug.h> /* oops_begin/end, ... */ #include <linux/kdebug.h> /* oops_begin/end, ... */
#include <linux/module.h> /* search_exception_table */ #include <linux/module.h> /* search_exception_table */
...@@ -710,7 +709,7 @@ no_context(struct pt_regs *regs, unsigned long error_code, ...@@ -710,7 +709,7 @@ no_context(struct pt_regs *regs, unsigned long error_code,
show_fault_oops(regs, error_code, address); show_fault_oops(regs, error_code, address);
stackend = end_of_stack(tsk); stackend = end_of_stack(tsk);
if (tsk != &init_task && *stackend != STACK_END_MAGIC) if (*stackend != STACK_END_MAGIC)
printk(KERN_EMERG "Thread overran stack, or stack corrupted\n"); printk(KERN_EMERG "Thread overran stack, or stack corrupted\n");
tsk->thread.cr2 = address; tsk->thread.cr2 = address;
......
...@@ -57,6 +57,7 @@ struct sched_param { ...@@ -57,6 +57,7 @@ struct sched_param {
#include <linux/llist.h> #include <linux/llist.h>
#include <linux/uidgid.h> #include <linux/uidgid.h>
#include <linux/gfp.h> #include <linux/gfp.h>
#include <linux/magic.h>
#include <asm/processor.h> #include <asm/processor.h>
...@@ -2638,6 +2639,7 @@ static inline unsigned long stack_not_used(struct task_struct *p) ...@@ -2638,6 +2639,7 @@ static inline unsigned long stack_not_used(struct task_struct *p)
return (unsigned long)n - (unsigned long)end_of_stack(p); return (unsigned long)n - (unsigned long)end_of_stack(p);
} }
#endif #endif
extern void set_task_stack_end_magic(struct task_struct *tsk);
/* set thread flags in other task's structures /* set thread flags in other task's structures
* - see asm/thread_info.h for TIF_xxxx flags available * - see asm/thread_info.h for TIF_xxxx flags available
......
...@@ -508,6 +508,7 @@ asmlinkage __visible void __init start_kernel(void) ...@@ -508,6 +508,7 @@ asmlinkage __visible void __init start_kernel(void)
* lockdep hash: * lockdep hash:
*/ */
lockdep_init(); lockdep_init();
set_task_stack_end_magic(&init_task);
smp_setup_processor_id(); smp_setup_processor_id();
debug_objects_early_init(); debug_objects_early_init();
......
...@@ -294,11 +294,18 @@ int __weak arch_dup_task_struct(struct task_struct *dst, ...@@ -294,11 +294,18 @@ int __weak arch_dup_task_struct(struct task_struct *dst,
return 0; return 0;
} }
void set_task_stack_end_magic(struct task_struct *tsk)
{
unsigned long *stackend;
stackend = end_of_stack(tsk);
*stackend = STACK_END_MAGIC; /* for overflow detection */
}
static struct task_struct *dup_task_struct(struct task_struct *orig) static struct task_struct *dup_task_struct(struct task_struct *orig)
{ {
struct task_struct *tsk; struct task_struct *tsk;
struct thread_info *ti; struct thread_info *ti;
unsigned long *stackend;
int node = tsk_fork_get_node(orig); int node = tsk_fork_get_node(orig);
int err; int err;
...@@ -328,8 +335,7 @@ static struct task_struct *dup_task_struct(struct task_struct *orig) ...@@ -328,8 +335,7 @@ static struct task_struct *dup_task_struct(struct task_struct *orig)
setup_thread_stack(tsk, orig); setup_thread_stack(tsk, orig);
clear_user_return_notifier(tsk); clear_user_return_notifier(tsk);
clear_tsk_need_resched(tsk); clear_tsk_need_resched(tsk);
stackend = end_of_stack(tsk); set_task_stack_end_magic(tsk);
*stackend = STACK_END_MAGIC; /* for overflow detection */
#ifdef CONFIG_CC_STACKPROTECTOR #ifdef CONFIG_CC_STACKPROTECTOR
tsk->stack_canary = get_random_int(); tsk->stack_canary = get_random_int();
......
...@@ -13,7 +13,6 @@ ...@@ -13,7 +13,6 @@
#include <linux/sysctl.h> #include <linux/sysctl.h>
#include <linux/init.h> #include <linux/init.h>
#include <linux/fs.h> #include <linux/fs.h>
#include <linux/magic.h>
#include <asm/setup.h> #include <asm/setup.h>
...@@ -171,8 +170,7 @@ check_stack(unsigned long ip, unsigned long *stack) ...@@ -171,8 +170,7 @@ check_stack(unsigned long ip, unsigned long *stack)
i++; i++;
} }
if ((current != &init_task && if (*end_of_stack(current) != STACK_END_MAGIC) {
*(end_of_stack(current)) != STACK_END_MAGIC)) {
print_max_stack(); print_max_stack();
BUG(); BUG();
} }
......
Markdown is supported
0% .
You are about to add 0 people to the discussion. Proceed with caution.
先完成此消息的编辑!
想要评论请 注册