1930a6e739
This set of changes removes tracehook.h, moves modification of all of the ptrace fields inside of siglock to remove races, adds a missing permission check to ptrace.c The removal of tracehook.h is quite significant as it has been a major source of confusion in recent years. Much of that confusion was around task_work and TIF_NOTIFY_SIGNAL (which I have now decoupled making the semantics clearer). For people who don't know tracehook.h is a vestiage of an attempt to implement uprobes like functionality that was never fully merged, and was later superseeded by uprobes when uprobes was merged. For many years now we have been removing what tracehook functionaly a little bit at a time. To the point where now anything left in tracehook.h is some weird strange thing that is difficult to understand. Eric W. Biederman (15): ptrace: Move ptrace_report_syscall into ptrace.h ptrace/arm: Rename tracehook_report_syscall report_syscall ptrace: Create ptrace_report_syscall_{entry,exit} in ptrace.h ptrace: Remove arch_syscall_{enter,exit}_tracehook ptrace: Remove tracehook_signal_handler task_work: Remove unnecessary include from posix_timers.h task_work: Introduce task_work_pending task_work: Call tracehook_notify_signal from get_signal on all architectures task_work: Decouple TIF_NOTIFY_SIGNAL and task_work signal: Move set_notify_signal and clear_notify_signal into sched/signal.h resume_user_mode: Remove #ifdef TIF_NOTIFY_RESUME in set_notify_resume resume_user_mode: Move to resume_user_mode.h tracehook: Remove tracehook.h ptrace: Move setting/clearing ptrace_message into ptrace_stop ptrace: Return the signal to continue with from ptrace_stop Jann Horn (1): ptrace: Check PTRACE_O_SUSPEND_SECCOMP permission on PTRACE_SEIZE Yang Li (1): ptrace: Remove duplicated include in ptrace.c MAINTAINERS | 1 - arch/Kconfig | 5 +- arch/alpha/kernel/ptrace.c | 5 +- arch/alpha/kernel/signal.c | 4 +- arch/arc/kernel/ptrace.c | 5 +- arch/arc/kernel/signal.c | 4 +- arch/arm/kernel/ptrace.c | 12 +- arch/arm/kernel/signal.c | 4 +- arch/arm64/kernel/ptrace.c | 14 +-- arch/arm64/kernel/signal.c | 4 +- arch/csky/kernel/ptrace.c | 5 +- arch/csky/kernel/signal.c | 4 +- arch/h8300/kernel/ptrace.c | 5 +- arch/h8300/kernel/signal.c | 4 +- arch/hexagon/kernel/process.c | 4 +- arch/hexagon/kernel/signal.c | 1 - arch/hexagon/kernel/traps.c | 6 +- arch/ia64/kernel/process.c | 4 +- arch/ia64/kernel/ptrace.c | 6 +- arch/ia64/kernel/signal.c | 1 - arch/m68k/kernel/ptrace.c | 5 +- arch/m68k/kernel/signal.c | 4 +- arch/microblaze/kernel/ptrace.c | 5 +- arch/microblaze/kernel/signal.c | 4 +- arch/mips/kernel/ptrace.c | 5 +- arch/mips/kernel/signal.c | 4 +- arch/nds32/include/asm/syscall.h | 2 +- arch/nds32/kernel/ptrace.c | 5 +- arch/nds32/kernel/signal.c | 4 +- arch/nios2/kernel/ptrace.c | 5 +- arch/nios2/kernel/signal.c | 4 +- arch/openrisc/kernel/ptrace.c | 5 +- arch/openrisc/kernel/signal.c | 4 +- arch/parisc/kernel/ptrace.c | 7 +- arch/parisc/kernel/signal.c | 4 +- arch/powerpc/kernel/ptrace/ptrace.c | 8 +- arch/powerpc/kernel/signal.c | 4 +- arch/riscv/kernel/ptrace.c | 5 +- arch/riscv/kernel/signal.c | 4 +- arch/s390/include/asm/entry-common.h | 1 - arch/s390/kernel/ptrace.c | 1 - arch/s390/kernel/signal.c | 5 +- arch/sh/kernel/ptrace_32.c | 5 +- arch/sh/kernel/signal_32.c | 4 +- arch/sparc/kernel/ptrace_32.c | 5 +- arch/sparc/kernel/ptrace_64.c | 5 +- arch/sparc/kernel/signal32.c | 1 - arch/sparc/kernel/signal_32.c | 4 +- arch/sparc/kernel/signal_64.c | 4 +- arch/um/kernel/process.c | 4 +- arch/um/kernel/ptrace.c | 5 +- arch/x86/kernel/ptrace.c | 1 - arch/x86/kernel/signal.c | 5 +- arch/x86/mm/tlb.c | 1 + arch/xtensa/kernel/ptrace.c | 5 +- arch/xtensa/kernel/signal.c | 4 +- block/blk-cgroup.c | 2 +- fs/coredump.c | 1 - fs/exec.c | 1 - fs/io-wq.c | 6 +- fs/io_uring.c | 11 +- fs/proc/array.c | 1 - fs/proc/base.c | 1 - include/asm-generic/syscall.h | 2 +- include/linux/entry-common.h | 47 +------- include/linux/entry-kvm.h | 2 +- include/linux/posix-timers.h | 1 - include/linux/ptrace.h | 81 ++++++++++++- include/linux/resume_user_mode.h | 64 ++++++++++ include/linux/sched/signal.h | 17 +++ include/linux/task_work.h | 5 + include/linux/tracehook.h | 226 ----------------------------------- include/uapi/linux/ptrace.h | 2 +- kernel/entry/common.c | 19 +-- kernel/entry/kvm.c | 9 +- kernel/exit.c | 3 +- kernel/livepatch/transition.c | 1 - kernel/ptrace.c | 47 +++++--- kernel/seccomp.c | 1 - kernel/signal.c | 62 +++++----- kernel/task_work.c | 4 +- kernel/time/posix-cpu-timers.c | 1 + mm/memcontrol.c | 2 +- security/apparmor/domain.c | 1 - security/selinux/hooks.c | 1 - 85 files changed, 372 insertions(+), 495 deletions(-) Signed-off-by: "Eric W. Biederman" <ebiederm@xmission.com> -----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEEgjlraLDcwBA2B+6cC/v6Eiajj0AFAmJCQkoACgkQC/v6Eiaj j0DCWQ/5AZVFU+hX32obUNCLackHTwgcCtSOs3JNBmNA/zL/htPiYYG0ghkvtlDR Dw5J5DnxC6P7PVAdAqrpvx2uX2FebHYU0bRlyLx8LYUEP5dhyNicxX9jA882Z+vw Ud0Ue9EojwGWS76dC9YoKUj3slThMATbhA2r4GVEoof8fSNJaBxQIqath44t0FwU DinWa+tIOvZANGBZr6CUUINNIgqBIZCH/R4h6ArBhMlJpuQ5Ufk2kAaiWFwZCkX4 0LuuAwbKsCKkF8eap5I2KrIg/7zZVgxAg9O3cHOzzm8OPbKzRnNnQClcDe8perqp S6e/f3MgpE+eavd1EiLxevZ660cJChnmikXVVh8ZYYoefaMKGqBaBSsB38bNcLjY 3+f2dB+TNBFRnZs1aCujK3tWBT9QyjZDKtCBfzxDNWBpXGLhHH6j6lA5Lj+Cef5K /HNHFb+FuqedlFZh5m1Y+piFQ70hTgCa2u8b+FSOubI2hW9Zd+WzINV0ANaZ2LvZ 4YGtcyDNk1q1+c87lxP9xMRl/xi6rNg+B9T2MCo4IUnHgpSVP6VEB3osgUmrrrN0 eQlUI154G/AaDlqXLgmn1xhRmlPGfmenkxpok1AuzxvNJsfLKnpEwQSc13g3oiZr disZQxNY0kBO2Nv3G323Z6PLinhbiIIFez6cJzK5v0YJ2WtO3pY= =uEro -----END PGP SIGNATURE----- Merge tag 'ptrace-cleanups-for-v5.18' of git://git.kernel.org/pub/scm/linux/kernel/git/ebiederm/user-namespace Pull ptrace cleanups from Eric Biederman: "This set of changes removes tracehook.h, moves modification of all of the ptrace fields inside of siglock to remove races, adds a missing permission check to ptrace.c The removal of tracehook.h is quite significant as it has been a major source of confusion in recent years. Much of that confusion was around task_work and TIF_NOTIFY_SIGNAL (which I have now decoupled making the semantics clearer). For people who don't know tracehook.h is a vestiage of an attempt to implement uprobes like functionality that was never fully merged, and was later superseeded by uprobes when uprobes was merged. For many years now we have been removing what tracehook functionaly a little bit at a time. To the point where anything left in tracehook.h was some weird strange thing that was difficult to understand" * tag 'ptrace-cleanups-for-v5.18' of git://git.kernel.org/pub/scm/linux/kernel/git/ebiederm/user-namespace: ptrace: Remove duplicated include in ptrace.c ptrace: Check PTRACE_O_SUSPEND_SECCOMP permission on PTRACE_SEIZE ptrace: Return the signal to continue with from ptrace_stop ptrace: Move setting/clearing ptrace_message into ptrace_stop tracehook: Remove tracehook.h resume_user_mode: Move to resume_user_mode.h resume_user_mode: Remove #ifdef TIF_NOTIFY_RESUME in set_notify_resume signal: Move set_notify_signal and clear_notify_signal into sched/signal.h task_work: Decouple TIF_NOTIFY_SIGNAL and task_work task_work: Call tracehook_notify_signal from get_signal on all architectures task_work: Introduce task_work_pending task_work: Remove unnecessary include from posix_timers.h ptrace: Remove tracehook_signal_handler ptrace: Remove arch_syscall_{enter,exit}_tracehook ptrace: Create ptrace_report_syscall_{entry,exit} in ptrace.h ptrace/arm: Rename tracehook_report_syscall report_syscall ptrace: Move ptrace_report_syscall into ptrace.h
328 lines
8.5 KiB
C
328 lines
8.5 KiB
C
/*
|
|
* Copyright (C) 2013-2014 Altera Corporation
|
|
* Copyright (C) 2011-2012 Tobias Klauser <tklauser@distanz.ch>
|
|
* Copyright (C) 2004 Microtronix Datacom Ltd
|
|
* Copyright (C) 1991, 1992 Linus Torvalds
|
|
*
|
|
* This file is subject to the terms and conditions of the GNU General Public
|
|
* License. See the file COPYING in the main directory of this archive
|
|
* for more details.
|
|
*/
|
|
|
|
#include <linux/signal.h>
|
|
#include <linux/errno.h>
|
|
#include <linux/ptrace.h>
|
|
#include <linux/uaccess.h>
|
|
#include <linux/unistd.h>
|
|
#include <linux/personality.h>
|
|
#include <linux/resume_user_mode.h>
|
|
|
|
#include <asm/ucontext.h>
|
|
#include <asm/cacheflush.h>
|
|
|
|
#define _BLOCKABLE (~(sigmask(SIGKILL) | sigmask(SIGSTOP)))
|
|
|
|
/*
|
|
* Do a signal return; undo the signal stack.
|
|
*
|
|
* Keep the return code on the stack quadword aligned!
|
|
* That makes the cache flush below easier.
|
|
*/
|
|
|
|
struct rt_sigframe {
|
|
struct siginfo info;
|
|
struct ucontext uc;
|
|
};
|
|
|
|
static inline int rt_restore_ucontext(struct pt_regs *regs,
|
|
struct switch_stack *sw,
|
|
struct ucontext __user *uc, int *pr2)
|
|
{
|
|
int temp;
|
|
unsigned long __user *gregs = uc->uc_mcontext.gregs;
|
|
int err;
|
|
|
|
/* Always make any pending restarted system calls return -EINTR */
|
|
current->restart_block.fn = do_no_restart_syscall;
|
|
|
|
err = __get_user(temp, &uc->uc_mcontext.version);
|
|
if (temp != MCONTEXT_VERSION)
|
|
goto badframe;
|
|
/* restore passed registers */
|
|
err |= __get_user(regs->r1, &gregs[0]);
|
|
err |= __get_user(regs->r2, &gregs[1]);
|
|
err |= __get_user(regs->r3, &gregs[2]);
|
|
err |= __get_user(regs->r4, &gregs[3]);
|
|
err |= __get_user(regs->r5, &gregs[4]);
|
|
err |= __get_user(regs->r6, &gregs[5]);
|
|
err |= __get_user(regs->r7, &gregs[6]);
|
|
err |= __get_user(regs->r8, &gregs[7]);
|
|
err |= __get_user(regs->r9, &gregs[8]);
|
|
err |= __get_user(regs->r10, &gregs[9]);
|
|
err |= __get_user(regs->r11, &gregs[10]);
|
|
err |= __get_user(regs->r12, &gregs[11]);
|
|
err |= __get_user(regs->r13, &gregs[12]);
|
|
err |= __get_user(regs->r14, &gregs[13]);
|
|
err |= __get_user(regs->r15, &gregs[14]);
|
|
err |= __get_user(sw->r16, &gregs[15]);
|
|
err |= __get_user(sw->r17, &gregs[16]);
|
|
err |= __get_user(sw->r18, &gregs[17]);
|
|
err |= __get_user(sw->r19, &gregs[18]);
|
|
err |= __get_user(sw->r20, &gregs[19]);
|
|
err |= __get_user(sw->r21, &gregs[20]);
|
|
err |= __get_user(sw->r22, &gregs[21]);
|
|
err |= __get_user(sw->r23, &gregs[22]);
|
|
/* gregs[23] is handled below */
|
|
err |= __get_user(sw->fp, &gregs[24]); /* Verify, should this be
|
|
settable */
|
|
err |= __get_user(sw->gp, &gregs[25]); /* Verify, should this be
|
|
settable */
|
|
|
|
err |= __get_user(temp, &gregs[26]); /* Not really necessary no user
|
|
settable bits */
|
|
err |= __get_user(regs->ea, &gregs[27]);
|
|
|
|
err |= __get_user(regs->ra, &gregs[23]);
|
|
err |= __get_user(regs->sp, &gregs[28]);
|
|
|
|
regs->orig_r2 = -1; /* disable syscall checks */
|
|
|
|
err |= restore_altstack(&uc->uc_stack);
|
|
if (err)
|
|
goto badframe;
|
|
|
|
*pr2 = regs->r2;
|
|
return err;
|
|
|
|
badframe:
|
|
return 1;
|
|
}
|
|
|
|
asmlinkage int do_rt_sigreturn(struct switch_stack *sw)
|
|
{
|
|
struct pt_regs *regs = (struct pt_regs *)(sw + 1);
|
|
/* Verify, can we follow the stack back */
|
|
struct rt_sigframe __user *frame;
|
|
sigset_t set;
|
|
int rval;
|
|
|
|
frame = (struct rt_sigframe __user *) regs->sp;
|
|
if (!access_ok(frame, sizeof(*frame)))
|
|
goto badframe;
|
|
|
|
if (__copy_from_user(&set, &frame->uc.uc_sigmask, sizeof(set)))
|
|
goto badframe;
|
|
|
|
set_current_blocked(&set);
|
|
|
|
if (rt_restore_ucontext(regs, sw, &frame->uc, &rval))
|
|
goto badframe;
|
|
|
|
return rval;
|
|
|
|
badframe:
|
|
force_sig(SIGSEGV);
|
|
return 0;
|
|
}
|
|
|
|
static inline int rt_setup_ucontext(struct ucontext __user *uc, struct pt_regs *regs)
|
|
{
|
|
struct switch_stack *sw = (struct switch_stack *)regs - 1;
|
|
unsigned long __user *gregs = uc->uc_mcontext.gregs;
|
|
int err = 0;
|
|
|
|
err |= __put_user(MCONTEXT_VERSION, &uc->uc_mcontext.version);
|
|
err |= __put_user(regs->r1, &gregs[0]);
|
|
err |= __put_user(regs->r2, &gregs[1]);
|
|
err |= __put_user(regs->r3, &gregs[2]);
|
|
err |= __put_user(regs->r4, &gregs[3]);
|
|
err |= __put_user(regs->r5, &gregs[4]);
|
|
err |= __put_user(regs->r6, &gregs[5]);
|
|
err |= __put_user(regs->r7, &gregs[6]);
|
|
err |= __put_user(regs->r8, &gregs[7]);
|
|
err |= __put_user(regs->r9, &gregs[8]);
|
|
err |= __put_user(regs->r10, &gregs[9]);
|
|
err |= __put_user(regs->r11, &gregs[10]);
|
|
err |= __put_user(regs->r12, &gregs[11]);
|
|
err |= __put_user(regs->r13, &gregs[12]);
|
|
err |= __put_user(regs->r14, &gregs[13]);
|
|
err |= __put_user(regs->r15, &gregs[14]);
|
|
err |= __put_user(sw->r16, &gregs[15]);
|
|
err |= __put_user(sw->r17, &gregs[16]);
|
|
err |= __put_user(sw->r18, &gregs[17]);
|
|
err |= __put_user(sw->r19, &gregs[18]);
|
|
err |= __put_user(sw->r20, &gregs[19]);
|
|
err |= __put_user(sw->r21, &gregs[20]);
|
|
err |= __put_user(sw->r22, &gregs[21]);
|
|
err |= __put_user(sw->r23, &gregs[22]);
|
|
err |= __put_user(regs->ra, &gregs[23]);
|
|
err |= __put_user(sw->fp, &gregs[24]);
|
|
err |= __put_user(sw->gp, &gregs[25]);
|
|
err |= __put_user(regs->ea, &gregs[27]);
|
|
err |= __put_user(regs->sp, &gregs[28]);
|
|
return err;
|
|
}
|
|
|
|
static inline void __user *get_sigframe(struct ksignal *ksig,
|
|
struct pt_regs *regs,
|
|
size_t frame_size)
|
|
{
|
|
unsigned long usp;
|
|
|
|
/* Default to using normal stack. */
|
|
usp = regs->sp;
|
|
|
|
/* This is the X/Open sanctioned signal stack switching. */
|
|
usp = sigsp(usp, ksig);
|
|
|
|
/* Verify, is it 32 or 64 bit aligned */
|
|
return (void __user *)((usp - frame_size) & -8UL);
|
|
}
|
|
|
|
static int setup_rt_frame(struct ksignal *ksig, sigset_t *set,
|
|
struct pt_regs *regs)
|
|
{
|
|
struct rt_sigframe __user *frame;
|
|
int err = 0;
|
|
|
|
frame = get_sigframe(ksig, regs, sizeof(*frame));
|
|
|
|
if (ksig->ka.sa.sa_flags & SA_SIGINFO)
|
|
err |= copy_siginfo_to_user(&frame->info, &ksig->info);
|
|
|
|
/* Create the ucontext. */
|
|
err |= __put_user(0, &frame->uc.uc_flags);
|
|
err |= __put_user(0, &frame->uc.uc_link);
|
|
err |= __save_altstack(&frame->uc.uc_stack, regs->sp);
|
|
err |= rt_setup_ucontext(&frame->uc, regs);
|
|
err |= copy_to_user(&frame->uc.uc_sigmask, set, sizeof(*set));
|
|
|
|
if (err)
|
|
goto give_sigsegv;
|
|
|
|
/* Set up to return from userspace; jump to fixed address sigreturn
|
|
trampoline on kuser page. */
|
|
regs->ra = (unsigned long) (0x1044);
|
|
|
|
/* Set up registers for signal handler */
|
|
regs->sp = (unsigned long) frame;
|
|
regs->r4 = (unsigned long) ksig->sig;
|
|
regs->r5 = (unsigned long) &frame->info;
|
|
regs->r6 = (unsigned long) &frame->uc;
|
|
regs->ea = (unsigned long) ksig->ka.sa.sa_handler;
|
|
return 0;
|
|
|
|
give_sigsegv:
|
|
force_sigsegv(ksig->sig);
|
|
return -EFAULT;
|
|
}
|
|
|
|
/*
|
|
* OK, we're invoking a handler
|
|
*/
|
|
static void handle_signal(struct ksignal *ksig, struct pt_regs *regs)
|
|
{
|
|
int ret;
|
|
sigset_t *oldset = sigmask_to_save();
|
|
|
|
/* set up the stack frame */
|
|
ret = setup_rt_frame(ksig, oldset, regs);
|
|
|
|
signal_setup_done(ret, ksig, 0);
|
|
}
|
|
|
|
static int do_signal(struct pt_regs *regs)
|
|
{
|
|
unsigned int retval = 0, continue_addr = 0, restart_addr = 0;
|
|
int restart = 0;
|
|
struct ksignal ksig;
|
|
|
|
current->thread.kregs = regs;
|
|
|
|
/*
|
|
* If we were from a system call, check for system call restarting...
|
|
*/
|
|
if (regs->orig_r2 >= 0) {
|
|
continue_addr = regs->ea;
|
|
restart_addr = continue_addr - 4;
|
|
retval = regs->r2;
|
|
|
|
/*
|
|
* Prepare for system call restart. We do this here so that a
|
|
* debugger will see the already changed PC.
|
|
*/
|
|
switch (retval) {
|
|
case ERESTART_RESTARTBLOCK:
|
|
restart = -2;
|
|
fallthrough;
|
|
case ERESTARTNOHAND:
|
|
case ERESTARTSYS:
|
|
case ERESTARTNOINTR:
|
|
restart++;
|
|
regs->r2 = regs->orig_r2;
|
|
regs->r7 = regs->orig_r7;
|
|
regs->ea = restart_addr;
|
|
break;
|
|
}
|
|
}
|
|
|
|
if (get_signal(&ksig)) {
|
|
/* handler */
|
|
if (unlikely(restart && regs->ea == restart_addr)) {
|
|
if (retval == ERESTARTNOHAND ||
|
|
retval == ERESTART_RESTARTBLOCK ||
|
|
(retval == ERESTARTSYS
|
|
&& !(ksig.ka.sa.sa_flags & SA_RESTART))) {
|
|
regs->r2 = EINTR;
|
|
regs->r7 = 1;
|
|
regs->ea = continue_addr;
|
|
}
|
|
}
|
|
handle_signal(&ksig, regs);
|
|
return 0;
|
|
}
|
|
|
|
/*
|
|
* No handler present
|
|
*/
|
|
if (unlikely(restart) && regs->ea == restart_addr) {
|
|
regs->ea = continue_addr;
|
|
regs->r2 = __NR_restart_syscall;
|
|
}
|
|
|
|
/*
|
|
* If there's no signal to deliver, we just put the saved sigmask back.
|
|
*/
|
|
restore_saved_sigmask();
|
|
|
|
return restart;
|
|
}
|
|
|
|
asmlinkage int do_notify_resume(struct pt_regs *regs)
|
|
{
|
|
/*
|
|
* We want the common case to go fast, which is why we may in certain
|
|
* cases get here from kernel mode. Just return without doing anything
|
|
* if so.
|
|
*/
|
|
if (!user_mode(regs))
|
|
return 0;
|
|
|
|
if (test_thread_flag(TIF_SIGPENDING) ||
|
|
test_thread_flag(TIF_NOTIFY_SIGNAL)) {
|
|
int restart = do_signal(regs);
|
|
|
|
if (unlikely(restart)) {
|
|
/*
|
|
* Restart without handlers.
|
|
* Deal with it without leaving
|
|
* the kernel space.
|
|
*/
|
|
return restart;
|
|
}
|
|
} else if (test_thread_flag(TIF_NOTIFY_RESUME))
|
|
resume_user_mode_work(regs);
|
|
|
|
return 0;
|
|
}
|