All of lore.kernel.org
 help / color / mirror / Atom feed
* [PATCH v2 0/5] bug: Provide toggle for BUG on data corruption
@ 2016-08-17  0:20 ` Kees Cook
  0 siblings, 0 replies; 28+ messages in thread
From: Kees Cook @ 2016-08-17  0:20 UTC (permalink / raw)
  To: Paul E . McKenney
  Cc: Kees Cook, Laura Abbott, Steven Rostedt, Stephen Boyd,
	Daniel Micay, Joe Perches, Arnd Bergmann, Greg Kroah-Hartman,
	Josh Triplett, Mathieu Desnoyers, Lai Jiangshan,
	Aneesh Kumar K.V, Kirill A. Shutemov, Michael Ellerman,
	Dan Williams, Andrew Morton, Ingo Molnar, Thomas Gleixner,
	Josef Bacik, Andrey Ryabinin, Tejun Heo, Nikolay Aleksandrov,
	Dmitry Vyukov, linux-kernel, kernel-hardening

This adds a CONFIG to trigger BUG()s when the kernel encounters
unexpected data structure integrity as currently detected with
CONFIG_DEBUG_LIST.

Specifically list operations have been a target for widening flaws to gain
"write anywhere" primitives for attackers, so this also consolidates the
debug checking to avoid code and check duplication (e.g. RCU list debug
was missing a check that got added to regular list debug). It also stops
manipulations when corruption is detected, since worsening the corruption
makes no sense. (Really, everyone should build with CONFIG_DEBUG_LIST
since the checks are so inexpensive.)

This is mostly a refactoring of similar code from PaX and Grsecurity,
along with MSM kernel changes by Stephen Boyd.

Along with the patches is a new lkdtm test to validate that setting
CONFIG_DEBUG_LIST actually does what is desired.

Thanks,

-Kees

^ permalink raw reply	[flat|nested] 28+ messages in thread

end of thread, other threads:[~2016-08-17 21:11 UTC | newest]

Thread overview: 28+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2016-08-17  0:20 [PATCH v2 0/5] bug: Provide toggle for BUG on data corruption Kees Cook
2016-08-17  0:20 ` [kernel-hardening] " Kees Cook
2016-08-17  0:20 ` [PATCH v2 1/5] list: Split list_add() debug checking into separate function Kees Cook
2016-08-17  0:20   ` [kernel-hardening] " Kees Cook
2016-08-17 13:16   ` Steven Rostedt
2016-08-17 13:16     ` [kernel-hardening] " Steven Rostedt
2016-08-17  0:20 ` [PATCH v2 2/5] rculist: Consolidate DEBUG_LIST for list_add_rcu() Kees Cook
2016-08-17  0:20   ` [kernel-hardening] " Kees Cook
2016-08-17  0:20 ` [PATCH v2 3/5] list: Split list_del() debug checking into separate function Kees Cook
2016-08-17  0:20   ` [kernel-hardening] " Kees Cook
2016-08-17  0:20 ` [PATCH v2 4/5] bug: Provide toggle for BUG on data corruption Kees Cook
2016-08-17  0:20   ` [kernel-hardening] " Kees Cook
2016-08-17  0:26   ` Joe Perches
2016-08-17  0:26     ` [kernel-hardening] " Joe Perches
2016-08-17  3:39     ` Kees Cook
2016-08-17  3:39       ` [kernel-hardening] " Kees Cook
2016-08-17 13:20   ` Steven Rostedt
2016-08-17 13:20     ` [kernel-hardening] " Steven Rostedt
2016-08-17  0:20 ` [PATCH v2 5/5] lkdtm: Add tests for struct list corruption Kees Cook
2016-08-17  0:20   ` [kernel-hardening] " Kees Cook
2016-08-17  0:55 ` [PATCH v2 0/5] bug: Provide toggle for BUG on data corruption Henrique de Moraes Holschuh
2016-08-17  0:55   ` [kernel-hardening] " Henrique de Moraes Holschuh
2016-08-17  3:37   ` Kees Cook
2016-08-17  3:37     ` [kernel-hardening] " Kees Cook
2016-08-17 20:17 ` Stephen Boyd
2016-08-17 20:17   ` [kernel-hardening] " Stephen Boyd
2016-08-17 21:11   ` Kees Cook
2016-08-17 21:11     ` [kernel-hardening] " Kees Cook

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.