cf77bf6988
The lkdtm selftest config fragment enables CONFIG_UBSAN_TRAP to make the
ARRAY_BOUNDS test kill the calling process when an out-of-bound access
is detected by UBSAN. However, after this [1] commit, UBSAN is triggered
under many new scenarios that weren't detected before, such as in struct
definitions with fixed-size trailing arrays used as flexible arrays. As
a result, CONFIG_UBSAN_TRAP=y has become a very aggressive option to
enable except for specific situations.
`make kselftest-merge` applies CONFIG_UBSAN_TRAP=y to the kernel config
for all selftests, which makes many of them fail because of system hangs
during boot.
This change removes the config option from the lkdtm kselftest and
configures the ARRAY_BOUNDS test to look for UBSAN reports rather than
relying on the calling process being killed.
[1] commit 2d47c6956a
("ubsan: Tighten UBSAN_BOUNDS on GCC")'
Signed-off-by: Ricardo Cañuelo <ricardo.canuelo@collabora.com>
Reviewed-by: Kees Cook <keescook@chromium.org>
Link: https://lore.kernel.org/r/20230802063252.1917997-1-ricardo.canuelo@collabora.com
Signed-off-by: Kees Cook <keescook@chromium.org>
15 lines
367 B
Plaintext
15 lines
367 B
Plaintext
CONFIG_LKDTM=y
|
|
CONFIG_DEBUG_LIST=y
|
|
CONFIG_SLAB_FREELIST_HARDENED=y
|
|
CONFIG_FORTIFY_SOURCE=y
|
|
CONFIG_GCC_PLUGIN_STACKLEAK=y
|
|
CONFIG_HARDENED_USERCOPY=y
|
|
CONFIG_RANDOMIZE_KSTACK_OFFSET_DEFAULT=y
|
|
CONFIG_INIT_ON_FREE_DEFAULT_ON=y
|
|
CONFIG_INIT_ON_ALLOC_DEFAULT_ON=y
|
|
CONFIG_UBSAN=y
|
|
CONFIG_UBSAN_BOUNDS=y
|
|
CONFIG_STACKPROTECTOR_STRONG=y
|
|
CONFIG_SLUB_DEBUG=y
|
|
CONFIG_SLUB_DEBUG_ON=y
|