All of lore.kernel.org
 help / color / mirror / Atom feed
* [PATCH v3 0/5] bug: Provide toggle for BUG on data corruption
@ 2016-08-17 21:42 ` Kees Cook
  0 siblings, 0 replies; 26+ messages in thread
From: Kees Cook @ 2016-08-17 21:42 UTC (permalink / raw)
  To: Paul E . McKenney
  Cc: Kees Cook, Laura Abbott, Steven Rostedt, Daniel Micay,
	Joe Perches, Stephen Boyd, Syed Rameez Mustafa, Arnd Bergmann,
	Greg Kroah-Hartman, Josh Triplett, Mathieu Desnoyers,
	Lai Jiangshan, Aneesh Kumar K.V, Kirill A. Shutemov,
	Michael Ellerman, Andrew Morton, Dan Williams, Jan Kara,
	Thomas Gleixner, Josef Bacik, Ingo Molnar, Tejun Heo,
	Andrey Ryabinin, Nikolay Aleksandrov, Dmitry Vyukov,
	linux-kernel, kernel-hardening

This adds CONFIG_BUG_ON_DATA_CORRUPTION to trigger BUG()s when the kernel
encounters unexpected data structure integrity as currently detected
with CONFIG_DEBUG_LIST.

Specifically list operations have been a target for widening flaws to gain
"write anywhere" primitives for attackers, so this also consolidates the
debug checking to avoid code and check duplication (e.g. RCU list debug
was missing a check that got added to regular list debug). It also stops
manipulations when corruption is detected, since worsening the corruption
makes no sense. (Really, everyone should build with CONFIG_DEBUG_LIST
since the checks are so inexpensive.)

This is mostly a refactoring of similar code from PaX and Grsecurity,
along with MSM kernel changes by Syed Rameez Mustafa.

Along with the patches is a new lkdtm test to validate that setting
CONFIG_DEBUG_LIST actually does what is desired.

Thanks,

-Kees

v3:
- fix MSM attribution, sboyd
- use pr_err, joe

v2:
- consolidate printk/WARN/BUG/return logic into a CONFIG-specific macro
- drop non-list BUGs, labbott

^ permalink raw reply	[flat|nested] 26+ messages in thread

end of thread, other threads:[~2016-08-22 22:32 UTC | newest]

Thread overview: 26+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2016-08-17 21:42 [PATCH v3 0/5] bug: Provide toggle for BUG on data corruption Kees Cook
2016-08-17 21:42 ` [kernel-hardening] " Kees Cook
2016-08-17 21:42 ` [PATCH v3 1/5] list: Split list_add() debug checking into separate function Kees Cook
2016-08-17 21:42   ` [kernel-hardening] " Kees Cook
2016-08-17 21:42 ` [PATCH v3 2/5] rculist: Consolidate DEBUG_LIST for list_add_rcu() Kees Cook
2016-08-17 21:42   ` [kernel-hardening] " Kees Cook
2016-08-17 21:42 ` [PATCH v3 3/5] list: Split list_del() debug checking into separate function Kees Cook
2016-08-17 21:42   ` [kernel-hardening] " Kees Cook
2016-08-17 21:42 ` [PATCH v3 4/5] bug: Provide toggle for BUG on data corruption Kees Cook
2016-08-17 21:42   ` [kernel-hardening] " Kees Cook
2016-08-22 13:15   ` Arnd Bergmann
2016-08-22 13:15     ` [kernel-hardening] " Arnd Bergmann
2016-08-22 17:53     ` Paul E. McKenney
2016-08-22 17:53       ` [kernel-hardening] " Paul E. McKenney
2016-08-22 22:32       ` Kees Cook
2016-08-22 22:32         ` Kees Cook
2016-08-17 21:42 ` [PATCH v3 5/5] lkdtm: Add tests for struct list corruption Kees Cook
2016-08-17 21:42   ` [kernel-hardening] " Kees Cook
2016-08-18 13:46 ` [PATCH v3 0/5] bug: Provide toggle for BUG on data corruption Steven Rostedt
2016-08-18 13:46   ` [kernel-hardening] " Steven Rostedt
2016-08-18 17:29   ` Paul E. McKenney
2016-08-18 17:29     ` [kernel-hardening] " Paul E. McKenney
2016-08-18 17:42 ` [kernel-hardening] " Rik van Riel
2016-08-18 20:57   ` Paul E. McKenney
2016-08-19  2:53     ` Rik van Riel
2016-08-19 17:46       ` Paul E. McKenney

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.