LKML Archive on lore.kernel.org help / color / mirror / Atom feed
From: Igor Stoppa <igor.stoppa@huawei.com> To: <david@fromorbit.com>, <willy@infradead.org>, <rppt@linux.vnet.ibm.com>, <keescook@chromium.org>, <mhocko@kernel.org> Cc: <labbott@redhat.com>, <linux-security-module@vger.kernel.org>, <linux-mm@kvack.org>, <linux-kernel@vger.kernel.org>, <kernel-hardening@lists.openwall.com>, Igor Stoppa <igor.stoppa@huawei.com> Subject: [PATCH 7/8] lkdtm: crash on overwriting protected pmalloc var Date: Tue, 13 Mar 2018 23:45:53 +0200 [thread overview] Message-ID: <20180313214554.28521-8-igor.stoppa@huawei.com> (raw) In-Reply-To: <20180313214554.28521-1-igor.stoppa@huawei.com> Verify that pmalloc read-only protection is in place: trying to overwrite a protected variable will crash the kernel. Signed-off-by: Igor Stoppa <igor.stoppa@huawei.com> --- drivers/misc/lkdtm.h | 1 + drivers/misc/lkdtm_core.c | 3 +++ drivers/misc/lkdtm_perms.c | 28 ++++++++++++++++++++++++++++ 3 files changed, 32 insertions(+) diff --git a/drivers/misc/lkdtm.h b/drivers/misc/lkdtm.h index 9e513dcfd809..dcda3ae76ceb 100644 --- a/drivers/misc/lkdtm.h +++ b/drivers/misc/lkdtm.h @@ -38,6 +38,7 @@ void lkdtm_READ_BUDDY_AFTER_FREE(void); void __init lkdtm_perms_init(void); void lkdtm_WRITE_RO(void); void lkdtm_WRITE_RO_AFTER_INIT(void); +void lkdtm_WRITE_RO_PMALLOC(void); void lkdtm_WRITE_KERN(void); void lkdtm_EXEC_DATA(void); void lkdtm_EXEC_STACK(void); diff --git a/drivers/misc/lkdtm_core.c b/drivers/misc/lkdtm_core.c index 2154d1bfd18b..c9fd42bda6ee 100644 --- a/drivers/misc/lkdtm_core.c +++ b/drivers/misc/lkdtm_core.c @@ -155,6 +155,9 @@ static const struct crashtype crashtypes[] = { CRASHTYPE(ACCESS_USERSPACE), CRASHTYPE(WRITE_RO), CRASHTYPE(WRITE_RO_AFTER_INIT), +#ifdef CONFIG_PROTECTABLE_MEMORY + CRASHTYPE(WRITE_RO_PMALLOC), +#endif CRASHTYPE(WRITE_KERN), CRASHTYPE(REFCOUNT_INC_OVERFLOW), CRASHTYPE(REFCOUNT_ADD_OVERFLOW), diff --git a/drivers/misc/lkdtm_perms.c b/drivers/misc/lkdtm_perms.c index 53b85c9d16b8..0ac9023fd2b0 100644 --- a/drivers/misc/lkdtm_perms.c +++ b/drivers/misc/lkdtm_perms.c @@ -9,6 +9,7 @@ #include <linux/vmalloc.h> #include <linux/mman.h> #include <linux/uaccess.h> +#include <linux/pmalloc.h> #include <asm/cacheflush.h> /* Whether or not to fill the target memory area with do_nothing(). */ @@ -104,6 +105,33 @@ void lkdtm_WRITE_RO_AFTER_INIT(void) *ptr ^= 0xabcd1234; } +#ifdef CONFIG_PROTECTABLE_MEMORY +void lkdtm_WRITE_RO_PMALLOC(void) +{ + struct gen_pool *pool; + int *i; + + pool = pmalloc_create_pool("pool", 0); + if (unlikely(!pool)) { + pr_info("Failed preparing pool for pmalloc test."); + return; + } + + i = (int *)pmalloc(pool, sizeof(int), GFP_KERNEL); + if (unlikely(!i)) { + pr_info("Failed allocating memory for pmalloc test."); + pmalloc_destroy_pool(pool); + return; + } + + *i = INT_MAX; + pmalloc_protect_pool(pool); + + pr_info("attempting bad pmalloc write at %p\n", i); + *i = 0; +} +#endif + void lkdtm_WRITE_KERN(void) { size_t size; -- 2.14.1
next prev parent reply other threads:[~2018-03-13 21:45 UTC|newest] Thread overview: 26+ messages / expand[flat|nested] mbox.gz Atom feed top 2018-03-13 21:45 [RFC PATCH v19 0/8] mm: security: ro protection for dynamic data Igor Stoppa 2018-03-13 21:45 ` [PATCH 1/8] genalloc: track beginning of allocations Igor Stoppa 2018-03-13 21:45 ` [PATCH 2/8] Add label to genalloc.rst for cross reference Igor Stoppa 2018-03-13 21:45 ` [PATCH 3/8] genalloc: selftest Igor Stoppa 2018-03-13 21:45 ` [PATCH 4/8] struct page: add field for vm_struct Igor Stoppa 2018-03-13 22:00 ` Matthew Wilcox 2018-03-14 17:43 ` J Freyensee 2018-03-15 9:38 ` Igor Stoppa 2018-03-15 18:51 ` J Freyensee 2018-03-13 21:45 ` [PATCH 5/8] Protectable Memory Igor Stoppa 2018-03-14 12:15 ` Matthew Wilcox 2018-03-14 13:02 ` Igor Stoppa 2018-03-14 17:40 ` J Freyensee 2018-03-13 21:45 ` [PATCH 6/8] Pmalloc selftest Igor Stoppa 2018-03-14 12:25 ` Matthew Wilcox 2018-03-25 1:32 ` Igor Stoppa 2018-03-13 21:45 ` Igor Stoppa [this message] 2018-03-13 21:45 ` [PATCH 8/8] Documentation for Pmalloc Igor Stoppa 2018-03-14 11:21 ` [RFC PATCH v19 0/8] mm: security: ro protection for dynamic data Igor Stoppa 2018-03-14 11:56 ` Matthew Wilcox 2018-03-14 12:55 ` Igor Stoppa 2018-03-14 13:04 ` Matthew Wilcox 2018-03-14 16:11 ` Igor Stoppa 2018-03-14 17:33 ` Matthew Wilcox 2018-03-15 13:43 ` Igor Stoppa 2018-03-19 18:04 ` Igor Stoppa
Reply instructions: You may reply publicly to this message via plain-text email using any one of the following methods: * Save the following mbox file, import it into your mail client, and reply-to-all from there: mbox Avoid top-posting and favor interleaved quoting: https://en.wikipedia.org/wiki/Posting_style#Interleaved_style * Reply using the --to, --cc, and --in-reply-to switches of git-send-email(1): git send-email \ --in-reply-to=20180313214554.28521-8-igor.stoppa@huawei.com \ --to=igor.stoppa@huawei.com \ --cc=david@fromorbit.com \ --cc=keescook@chromium.org \ --cc=kernel-hardening@lists.openwall.com \ --cc=labbott@redhat.com \ --cc=linux-kernel@vger.kernel.org \ --cc=linux-mm@kvack.org \ --cc=linux-security-module@vger.kernel.org \ --cc=mhocko@kernel.org \ --cc=rppt@linux.vnet.ibm.com \ --cc=willy@infradead.org \ /path/to/YOUR_REPLY https://kernel.org/pub/software/scm/git/docs/git-send-email.html * If your mail client supports setting the In-Reply-To header via mailto: links, try the mailto: linkBe sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions for how to clone and mirror all data and code used for this inbox; as well as URLs for NNTP newsgroup(s).