From: Andy Shevchenko <andriy.shevchenko@linux.intel.com>
To: Petr Mladek <pmladek@suse.com>
Cc: Rasmus Villemoes <linux@rasmusvillemoes.dk>,
"Tobin C . Harding" <me@tobin.cc>, Joe Perches <joe@perches.com>,
linux-kernel@vger.kernel.org,
Andrew Morton <akpm@linux-foundation.org>,
Michal Hocko <mhocko@suse.cz>
Subject: Re: [PATCH] vsprintf: Make "null" pointer dereference more robust
Date: Wed, 07 Mar 2018 20:18:09 +0200 [thread overview]
Message-ID: <1520446689.10722.493.camel@linux.intel.com> (raw)
In-Reply-To: <20180307155244.b45c3fb5vcxb4q2l@pathway.suse.cz>
On Wed, 2018-03-07 at 16:52 +0100, Petr Mladek wrote:
> On Tue 2018-03-06 11:56:25, Andy Shevchenko wrote:
> Anyway, I have discussed this with my colleagues. Different people had
> different opinions. But I liked the following.
I discussed as well, and...
> We already prevent crash when derefencing some obviously broken
> pointers. The handling is not consistent. Sometimes we print "(null)"
> only for pure NULL pointer, sometimes for pointers in the first
> page and sometimes also for pointers in the last page (error codes).
> In general, we should do our best to get useful message from printk().
> This patch tries to find a wide range of invalid strings using
> probe_kernel_read(). Also it makes the handling unified. We print:
...they are considering not crashing is a bad idea from debugging point
of view.
So, what is can be done is to:
- print "(null)" only for null pointers
- print error codes for IS_ERR() part
- crash on everything else
which partially what does my patch 1.
> Note that we could not print the exact pointer value from security
> reasons.
If it's invalid we need to fix the code, not to hide a problem, right?
> Developers need print the pointer using %px to get the real value.
But how developer will know (w/o traceback) where to look for?
> + if (probe_kernel_read(&byte, ptr, 1))
> + return "(efault)";
There is couple of flaws here:
- If we asked to print 0 bytes of the value of pointer or something
from extension (%*ph, %*pE, etc), we don't know if pointer valid or not,
because we are going to print nothing. So, for now there is a
ZERO_OR_NULL_PTR() check for them, but in reality I wouldn't know what
the best to do in such case. So, the question is what we would like to
know more: the pointer is invalid, or the spec.width is 0 and caller
doesn't care in this case?
- For IS_ERR() case it might be better to print an actual value of err,
(4 chars + parens + 2 chars left, like (e:dddd) or similar.
Unfortunately it doesn't scale good (ffff is a last error value we may
print). So, perhaps printing as %p in this case is a good enough and
scalable.
--
Andy Shevchenko <andriy.shevchenko@linux.intel.com>
Intel Finland Oy
next prev parent reply other threads:[~2018-03-07 18:18 UTC|newest]
Thread overview: 87+ messages / expand[flat|nested] mbox.gz Atom feed top
2018-02-16 21:07 [PATCH v2 1/9] lib/test_printf: Mark big constant with ULL Andy Shevchenko
2018-02-16 21:07 ` [PATCH v2 2/9] lib/vsprintf: Make dec_spec global Andy Shevchenko
2018-04-11 9:44 ` Petr Mladek
2018-02-16 21:07 ` [PATCH v2 3/9] lib/vsprintf: Make strspec global Andy Shevchenko
2018-04-11 9:44 ` Petr Mladek
2018-02-16 21:07 ` [PATCH v2 4/9] lib/vsprintf: Make flag_spec global Andy Shevchenko
2018-04-11 9:45 ` Petr Mladek
2018-02-16 21:07 ` [PATCH v2 5/9] lib/vsprintf: Move pointer_string() upper Andy Shevchenko
2018-04-11 9:45 ` Petr Mladek
2018-02-16 21:07 ` [PATCH v2 6/9] lib/vsprintf: Deduplicate pointer_string() Andy Shevchenko
2018-04-11 9:46 ` Petr Mladek
2018-02-16 21:07 ` [PATCH v2 7/9] lib/vsprintf: Replace space with '_' before crng is ready Andy Shevchenko
2018-02-20 2:57 ` [此邮件可能存在风险] " Yang, Shunyong
2018-04-11 9:47 ` Petr Mladek
2018-02-16 21:07 ` [PATCH v2 8/9] lib/vsprintf: Remove useless NULL checks Andy Shevchenko
2018-02-27 15:50 ` Petr Mladek
2018-02-27 17:35 ` Andy Shevchenko
2018-02-28 10:04 ` Petr Mladek
2018-02-28 10:42 ` Andy Shevchenko
2018-03-02 12:51 ` Petr Mladek
2018-03-02 12:53 ` [PATCH] vsprintf: Make "null" pointer dereference more robust Petr Mladek
2018-03-02 14:17 ` Andy Shevchenko
2018-03-05 14:53 ` Petr Mladek
2018-03-29 15:13 ` Petr Mladek
2018-03-29 16:11 ` Joe Perches
2018-03-05 15:16 ` Rasmus Villemoes
2018-03-05 15:25 ` Andy Shevchenko
2018-03-06 9:25 ` Petr Mladek
2018-03-06 9:56 ` Andy Shevchenko
2018-03-07 15:52 ` Petr Mladek
2018-03-07 18:18 ` Andy Shevchenko [this message]
2018-03-07 18:34 ` Linus Torvalds
2018-03-08 14:18 ` Petr Mladek
2018-03-08 16:45 ` Linus Torvalds
2018-03-08 17:26 ` Linus Torvalds
2018-03-09 15:01 ` Petr Mladek
2018-03-09 19:05 ` Linus Torvalds
2018-03-14 14:09 ` [PATCH v3] vsprintf: Prevent crash when dereferencing invalid pointers Petr Mladek
2018-03-14 22:12 ` Rasmus Villemoes
2018-03-15 15:07 ` Petr Mladek
2018-03-15 17:07 ` Steven Rostedt
2018-03-15 17:06 ` Steven Rostedt
2018-03-15 0:57 ` Sergey Senozhatsky
2018-03-15 7:58 ` Sergey Senozhatsky
2018-03-15 8:03 ` Sergey Senozhatsky
2018-03-15 17:01 ` Steven Rostedt
2018-03-16 1:18 ` Sergey Senozhatsky
2018-03-16 1:35 ` Linus Torvalds
2018-03-16 5:53 ` Sergey Senozhatsky
2018-03-16 8:55 ` Petr Mladek
2018-03-16 14:32 ` Steven Rostedt
2018-03-17 1:29 ` Sergey Senozhatsky
2018-03-15 13:07 ` Andy Shevchenko
2018-03-15 13:09 ` Andy Shevchenko
2018-03-15 15:26 ` Petr Mladek
2018-03-16 18:19 ` Andy Shevchenko
2018-03-29 14:53 ` Petr Mladek
2018-04-02 14:15 ` Andy Shevchenko
2018-04-03 1:12 ` Sergey Senozhatsky
2018-04-03 11:52 ` Petr Mladek
2018-04-03 11:56 ` Andy Shevchenko
2018-04-03 13:57 ` Sergey Senozhatsky
2018-04-03 11:46 ` Petr Mladek
2018-04-03 11:54 ` Andy Shevchenko
2018-04-03 13:13 ` Petr Mladek
2018-04-03 13:40 ` Andy Shevchenko
2018-04-03 14:50 ` Petr Mladek
2018-03-15 14:48 ` kbuild test robot
2018-03-15 20:26 ` kbuild test robot
2018-03-06 18:11 ` [PATCH 1/2] vsprintf: distinguish between (null), (err) and (invalid) pointer derefs Adam Borowski
2018-03-06 18:11 ` [PATCH 2/2] vsprintf: don't dereference pointers to the first or last page Adam Borowski
2018-03-07 13:22 ` Andy Shevchenko
2018-03-07 13:17 ` [PATCH 1/2] vsprintf: distinguish between (null), (err) and (invalid) pointer derefs Andy Shevchenko
2018-03-07 13:42 ` Adam Borowski
2018-03-07 13:29 ` Andy Shevchenko
2018-03-02 14:15 ` [PATCH v2 8/9] lib/vsprintf: Remove useless NULL checks Andy Shevchenko
2018-03-05 14:57 ` Petr Mladek
2018-02-28 10:44 ` Andy Shevchenko
2018-03-01 14:56 ` Andy Shevchenko
2018-02-16 21:07 ` [PATCH v2 9/9] lib/vsprintf: Mark expected switch fall-through Andy Shevchenko
2018-04-11 9:47 ` Petr Mladek
2018-02-18 12:58 ` [PATCH v2 1/9] lib/test_printf: Mark big constant with ULL Luc Van Oostenryck
2018-02-18 14:20 ` Andy Shevchenko
2018-02-19 15:24 ` Andy Shevchenko
2018-04-11 9:41 ` Petr Mladek
2018-02-18 21:52 ` Tobin C. Harding
2018-02-18 23:55 ` Andy Shevchenko
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=1520446689.10722.493.camel@linux.intel.com \
--to=andriy.shevchenko@linux.intel.com \
--cc=akpm@linux-foundation.org \
--cc=joe@perches.com \
--cc=linux-kernel@vger.kernel.org \
--cc=linux@rasmusvillemoes.dk \
--cc=me@tobin.cc \
--cc=mhocko@suse.cz \
--cc=pmladek@suse.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).