memset((void *)buf, remaining & 0xFF, sizeof(buf)); if (!remaining)
ret = 0; else
ret = recursive_loop((int)buf[remaining % sizeof(buf)] - 1);
memzero_explicit((void *)buf, sizeof(buf)); return ret;
}
/* If the depth is negative, use the default, otherwise keep parameter. */ void __init lkdtm_bugs_init(int *recur_param)
{ if (*recur_param < 0)
*recur_param = recur_count; else
recur_count = *recur_param;
}
/* This should trip the stack canary, not corrupt the return address. */ static noinline void lkdtm_CORRUPT_STACK(void)
{ /* Use default char array length that triggers stack protection. */ char data[8] __aligned(sizeof(void *));
/* Same as above but will only get a canary with -fstack-protector-strong */ static noinline void lkdtm_CORRUPT_STACK_STRONG(void)
{ union { unsignedshort shorts[4]; unsignedlong *ptr;
} data __aligned(sizeof(void *));
pr_info("Corrupting stack containing union ...\n");
__lkdtm_CORRUPT_STACK((void *)&data);
}
/* Do our best to find the canary in a 16 word window ... */ for (i = 1; i < 16; i++) {
canary = (unsignedlong *)stack + i; #ifdef CONFIG_STACKPROTECTOR if (*canary == current->stack_canary)
current_offset = i; if (*canary == init_task.stack_canary)
init_offset = i; #endif
}
if (current_offset == 0) { /* *Ifthecanarydoesn'tmatchwhat'sinthetask_struct, *we'reeitherusingaglobalcanaryorthestackframe *layoutchanged.
*/ if (init_offset != 0) {
pr_err("FAIL: global stack canary found at offset %ld (canary for pid %d matches init_task's)!\n",
init_offset, pid);
} else {
pr_warn("FAIL: did not correctly locate stack canary :(\n");
pr_expected_config(CONFIG_STACKPROTECTOR);
}
return;
} elseif (init_offset != 0) {
pr_warn("WARNING: found both current and init_task canaries nearby?!\n");
}
canary = (unsignedlong *)stack + current_offset; if (stack_canary_pid == 0) {
stack_canary = *canary;
stack_canary_pid = pid;
stack_canary_offset = current_offset;
pr_info("Recorded stack canary for pid %d at offset %ld\n",
stack_canary_pid, stack_canary_offset);
} elseif (pid == stack_canary_pid) {
pr_warn("ERROR: saw pid %d again -- please use a new pid\n", pid);
} else { if (current_offset != stack_canary_offset) {
pr_warn("ERROR: canary offset changed from %ld to %ld!?\n",
stack_canary_offset, current_offset); return;
}
if (*canary == stack_canary) {
pr_warn("FAIL: canary identical for pid %d and pid %d at offset %ld!\n",
stack_canary_pid, pid, current_offset);
} else {
pr_info("ok: stack canaries differ between pid %d and pid %d at offset %ld.\n",
stack_canary_pid, pid, current_offset); /* Reset the test. */
stack_canary_pid = 0;
}
}
}
staticvoid lkdtm_SPINLOCKUP(void)
{ /* Must be called twice to trigger. */
spin_lock(&lock_me_up); /* Let sparse know we intended to exit holding the lock. */
__release(&lock_me_up);
}
pr_info("Array access within bounds ...\n"); /* For both, touch all bytes in the actual member size. */ for (i = 0; i < sizeof(checked->data); i++)
checked->data[i] = 'A'; /* *Fortheuninstrumentedflexarraymember,alsotouch1byte *beyondtoverifyitiscorrectlyuninstrumented.
*/ for (i = 0; i < 2; i++)
not_checked->data[i] = 'A';
pr_info("Array access beyond bounds ...\n"); for (i = 0; i < sizeof(checked->data) + 1; i++)
checked->data[i] = 'B';
pr_err("FAIL: survived access of invalid flexible array member index!\n");
if (!IS_ENABLED(CONFIG_CC_HAS_COUNTED_BY))
pr_warn("This is expected since this %s was built with a compiler that does not support __counted_by\n",
lkdtm_kernel_info); elseif (IS_ENABLED(CONFIG_UBSAN_BOUNDS))
pr_expected_config(CONFIG_UBSAN_TRAP); else
pr_expected_config(CONFIG_UBSAN_BOUNDS);
}
if (target[0] == NULL && target[1] == NULL)
pr_err("Overwrite did not happen, but no BUG?!\n"); else {
pr_err("list_add() corruption not detected!\n");
pr_expected_config(CONFIG_LIST_HARDENED);
}
}
pr_info("attempting good list removal\n");
list_del(&item.node);
pr_info("attempting corrupted list removal\n");
list_add(&item.node, &test_head);
/* As with the list_add() test above, this corrupts "next". */
item.node.next = redirection;
list_del(&item.node);
if (target[0] == NULL && target[1] == NULL)
pr_err("Overwrite did not happen, but no BUG?!\n"); else {
pr_err("list_del() corruption not detected!\n");
pr_expected_config(CONFIG_LIST_HARDENED);
}
}
/* Test that VMAP_STACK is actually allocating with a leading guard page */ staticvoid lkdtm_STACK_GUARD_PAGE_LEADING(void)
{ constunsignedchar *stack = task_stack_page(current); constunsignedchar *ptr = stack - 1; volatileunsignedchar byte;
pr_info("attempting bad read from page below current stack\n");
byte = *ptr;
pr_err("FAIL: accessed page before stack! (byte: %x)\n", byte);
}
/* Test that VMAP_STACK is actually allocating with a trailing guard page */ staticvoid lkdtm_STACK_GUARD_PAGE_TRAILING(void)
{ constunsignedchar *stack = task_stack_page(current); constunsignedchar *ptr = stack + THREAD_SIZE; volatileunsignedchar byte;
pr_info("attempting bad read from page above current stack\n");
byte = *ptr;
pr_err("FAIL: accessed page after stack! (byte: %x)\n", byte);
}
if (!IS_ENABLED(CONFIG_ARM64_PTR_AUTH_KERNEL))
pr_err("FAIL: kernel not built with CONFIG_ARM64_PTR_AUTH_KERNEL\n");
if (!system_supports_address_auth()) {
pr_err("FAIL: CPU lacks pointer authentication feature\n"); return;
}
pr_info("changing PAC parameters to force function return failure...\n"); /* *PACisahashvaluecomputedfrominputkeys,returnaddressand *stackpointer.Aspachasfewerbitssothereisachanceof *collision,soiteratefewtimestoreducethecollisionprobability.
*/ for (i = 0; i < CORRUPT_PAC_ITERATE; i++)
change_pac_parameters();
pr_err("FAIL: survived PAC changes! Kernel may be unstable from here\n"); #else
pr_err("XFAIL: this test is arm64-only\n"); #endif
}
Die Informationen auf dieser Webseite wurden
nach bestem Wissen sorgfältig zusammengestellt. Es wird jedoch weder Vollständigkeit, noch Richtigkeit,
noch Qualität der bereit gestellten Informationen zugesichert.
Bemerkung:
Die farbliche Syntaxdarstellung und die Messung sind noch experimentell.