]>
Commit | Line | Data |
---|---|---|
4dee9bd5 | 1 | diff -urNp linux-2.6.25.4/arch/alpha/kernel/module.c linux-2.6.25.4/arch/alpha/kernel/module.c |
2 | --- linux-2.6.25.4/arch/alpha/kernel/module.c 2008-05-15 11:00:12.000000000 -0400 | |
3 | +++ linux-2.6.25.4/arch/alpha/kernel/module.c 2008-05-18 13:33:13.000000000 -0400 | |
da5b3fc8 | 4 | @@ -176,7 +176,7 @@ apply_relocate_add(Elf64_Shdr *sechdrs, |
50425a20 | 5 | |
6 | /* The small sections were sorted to the end of the segment. | |
7 | The following should definitely cover them. */ | |
8 | - gp = (u64)me->module_core + me->core_size - 0x8000; | |
9 | + gp = (u64)me->module_core_rw + me->core_size_rw - 0x8000; | |
10 | got = sechdrs[me->arch.gotsecindex].sh_addr; | |
11 | ||
12 | for (i = 0; i < n; i++) { | |
4dee9bd5 | 13 | diff -urNp linux-2.6.25.4/arch/alpha/kernel/osf_sys.c linux-2.6.25.4/arch/alpha/kernel/osf_sys.c |
14 | --- linux-2.6.25.4/arch/alpha/kernel/osf_sys.c 2008-05-15 11:00:12.000000000 -0400 | |
15 | +++ linux-2.6.25.4/arch/alpha/kernel/osf_sys.c 2008-05-18 13:33:13.000000000 -0400 | |
8a4b4a5e | 16 | @@ -1288,6 +1288,10 @@ arch_get_unmapped_area(struct file *filp |
50425a20 | 17 | merely specific addresses, but regions of memory -- perhaps |
18 | this feature should be incorporated into all ports? */ | |
19 | ||
20 | +#ifdef CONFIG_PAX_RANDMMAP | |
21 | + if (!(current->mm->pax_flags & MF_PAX_RANDMMAP) || !filp) | |
22 | +#endif | |
23 | + | |
24 | if (addr) { | |
25 | addr = arch_get_unmapped_area_1 (PAGE_ALIGN(addr), len, limit); | |
26 | if (addr != (unsigned long) -ENOMEM) | |
8a4b4a5e | 27 | @@ -1295,8 +1299,8 @@ arch_get_unmapped_area(struct file *filp |
50425a20 | 28 | } |
29 | ||
30 | /* Next, try allocating at TASK_UNMAPPED_BASE. */ | |
31 | - addr = arch_get_unmapped_area_1 (PAGE_ALIGN(TASK_UNMAPPED_BASE), | |
32 | - len, limit); | |
33 | + addr = arch_get_unmapped_area_1 (PAGE_ALIGN(current->mm->mmap_base), len, limit); | |
34 | + | |
35 | if (addr != (unsigned long) -ENOMEM) | |
36 | return addr; | |
37 | ||
4dee9bd5 | 38 | diff -urNp linux-2.6.25.4/arch/alpha/kernel/ptrace.c linux-2.6.25.4/arch/alpha/kernel/ptrace.c |
39 | --- linux-2.6.25.4/arch/alpha/kernel/ptrace.c 2008-05-15 11:00:12.000000000 -0400 | |
40 | +++ linux-2.6.25.4/arch/alpha/kernel/ptrace.c 2008-05-18 13:33:13.000000000 -0400 | |
da5b3fc8 | 41 | @@ -15,6 +15,7 @@ |
50425a20 | 42 | #include <linux/security.h> |
43 | #include <linux/signal.h> | |
b79bc584 | 44 | #include <linux/vs_base.h> |
50425a20 | 45 | +#include <linux/grsecurity.h> |
46 | ||
47 | #include <asm/uaccess.h> | |
48 | #include <asm/pgtable.h> | |
da5b3fc8 | 49 | @@ -266,6 +267,9 @@ long arch_ptrace(struct task_struct *chi |
50 | size_t copied; | |
51 | long ret; | |
50425a20 | 52 | |
53 | + if (gr_handle_ptrace(child, request)) | |
da5b3fc8 | 54 | + return -EPERM; |
50425a20 | 55 | + |
da5b3fc8 | 56 | switch (request) { |
57 | /* When I and D space are separate, these will need to be fixed. */ | |
58 | case PTRACE_PEEKTEXT: /* read word at location addr. */ | |
4dee9bd5 | 59 | diff -urNp linux-2.6.25.4/arch/alpha/mm/fault.c linux-2.6.25.4/arch/alpha/mm/fault.c |
60 | --- linux-2.6.25.4/arch/alpha/mm/fault.c 2008-05-15 11:00:12.000000000 -0400 | |
61 | +++ linux-2.6.25.4/arch/alpha/mm/fault.c 2008-05-18 13:33:13.000000000 -0400 | |
8a4b4a5e | 62 | @@ -23,6 +23,7 @@ |
63 | #include <linux/smp.h> | |
50425a20 | 64 | #include <linux/interrupt.h> |
65 | #include <linux/module.h> | |
66 | +#include <linux/binfmts.h> | |
67 | ||
68 | #include <asm/system.h> | |
69 | #include <asm/uaccess.h> | |
8a4b4a5e | 70 | @@ -54,6 +55,124 @@ __load_new_mm_context(struct mm_struct * |
50425a20 | 71 | __reload_thread(pcb); |
72 | } | |
73 | ||
74 | +#ifdef CONFIG_PAX_PAGEEXEC | |
75 | +/* | |
76 | + * PaX: decide what to do with offenders (regs->pc = fault address) | |
77 | + * | |
78 | + * returns 1 when task should be killed | |
79 | + * 2 when patched PLT trampoline was detected | |
80 | + * 3 when unpatched PLT trampoline was detected | |
81 | + */ | |
82 | +static int pax_handle_fetch_fault(struct pt_regs *regs) | |
83 | +{ | |
84 | + | |
85 | +#ifdef CONFIG_PAX_EMUPLT | |
86 | + int err; | |
87 | + | |
88 | + do { /* PaX: patched PLT emulation #1 */ | |
89 | + unsigned int ldah, ldq, jmp; | |
90 | + | |
91 | + err = get_user(ldah, (unsigned int *)regs->pc); | |
92 | + err |= get_user(ldq, (unsigned int *)(regs->pc+4)); | |
93 | + err |= get_user(jmp, (unsigned int *)(regs->pc+8)); | |
94 | + | |
95 | + if (err) | |
96 | + break; | |
97 | + | |
98 | + if ((ldah & 0xFFFF0000U) == 0x277B0000U && | |
99 | + (ldq & 0xFFFF0000U) == 0xA77B0000U && | |
100 | + jmp == 0x6BFB0000U) | |
101 | + { | |
102 | + unsigned long r27, addr; | |
103 | + unsigned long addrh = (ldah | 0xFFFFFFFFFFFF0000UL) << 16; | |
104 | + unsigned long addrl = ldq | 0xFFFFFFFFFFFF0000UL; | |
105 | + | |
106 | + addr = regs->r27 + ((addrh ^ 0x80000000UL) + 0x80000000UL) + ((addrl ^ 0x8000UL) + 0x8000UL); | |
8a4b4a5e | 107 | + err = get_user(r27, (unsigned long *)addr); |
50425a20 | 108 | + if (err) |
109 | + break; | |
110 | + | |
111 | + regs->r27 = r27; | |
112 | + regs->pc = r27; | |
113 | + return 2; | |
114 | + } | |
115 | + } while (0); | |
116 | + | |
117 | + do { /* PaX: patched PLT emulation #2 */ | |
118 | + unsigned int ldah, lda, br; | |
119 | + | |
120 | + err = get_user(ldah, (unsigned int *)regs->pc); | |
121 | + err |= get_user(lda, (unsigned int *)(regs->pc+4)); | |
122 | + err |= get_user(br, (unsigned int *)(regs->pc+8)); | |
123 | + | |
124 | + if (err) | |
125 | + break; | |
126 | + | |
127 | + if ((ldah & 0xFFFF0000U) == 0x277B0000U && | |
128 | + (lda & 0xFFFF0000U) == 0xA77B0000U && | |
129 | + (br & 0xFFE00000U) == 0xC3E00000U) | |
130 | + { | |
131 | + unsigned long addr = br | 0xFFFFFFFFFFE00000UL; | |
132 | + unsigned long addrh = (ldah | 0xFFFFFFFFFFFF0000UL) << 16; | |
133 | + unsigned long addrl = lda | 0xFFFFFFFFFFFF0000UL; | |
134 | + | |
135 | + regs->r27 += ((addrh ^ 0x80000000UL) + 0x80000000UL) + ((addrl ^ 0x8000UL) + 0x8000UL); | |
136 | + regs->pc += 12 + (((addr ^ 0x00100000UL) + 0x00100000UL) << 2); | |
137 | + return 2; | |
138 | + } | |
139 | + } while (0); | |
140 | + | |
141 | + do { /* PaX: unpatched PLT emulation */ | |
142 | + unsigned int br; | |
143 | + | |
144 | + err = get_user(br, (unsigned int *)regs->pc); | |
145 | + | |
146 | + if (!err && (br & 0xFFE00000U) == 0xC3800000U) { | |
147 | + unsigned int br2, ldq, nop, jmp; | |
148 | + unsigned long addr = br | 0xFFFFFFFFFFE00000UL, resolver; | |
149 | + | |
150 | + addr = regs->pc + 4 + (((addr ^ 0x00100000UL) + 0x00100000UL) << 2); | |
151 | + err = get_user(br2, (unsigned int *)addr); | |
152 | + err |= get_user(ldq, (unsigned int *)(addr+4)); | |
153 | + err |= get_user(nop, (unsigned int *)(addr+8)); | |
154 | + err |= get_user(jmp, (unsigned int *)(addr+12)); | |
155 | + err |= get_user(resolver, (unsigned long *)(addr+16)); | |
156 | + | |
157 | + if (err) | |
158 | + break; | |
159 | + | |
160 | + if (br2 == 0xC3600000U && | |
161 | + ldq == 0xA77B000CU && | |
162 | + nop == 0x47FF041FU && | |
163 | + jmp == 0x6B7B0000U) | |
164 | + { | |
165 | + regs->r28 = regs->pc+4; | |
166 | + regs->r27 = addr+16; | |
167 | + regs->pc = resolver; | |
168 | + return 3; | |
169 | + } | |
170 | + } | |
171 | + } while (0); | |
172 | +#endif | |
173 | + | |
174 | + return 1; | |
175 | +} | |
176 | + | |
177 | +void pax_report_insns(void *pc, void *sp) | |
178 | +{ | |
179 | + unsigned long i; | |
180 | + | |
181 | + printk(KERN_ERR "PAX: bytes at PC: "); | |
182 | + for (i = 0; i < 5; i++) { | |
183 | + unsigned int c; | |
8a4b4a5e | 184 | + if (get_user(c, (unsigned int *)pc+i)) |
4dee9bd5 | 185 | + printk(KERN_CONT "???????? "); |
50425a20 | 186 | + else |
4dee9bd5 | 187 | + printk(KERN_CONT "%08x ", c); |
50425a20 | 188 | + } |
189 | + printk("\n"); | |
190 | +} | |
191 | +#endif | |
192 | ||
193 | /* | |
194 | * This routine handles page faults. It determines the address, | |
8a4b4a5e | 195 | @@ -131,8 +250,29 @@ do_page_fault(unsigned long address, uns |
50425a20 | 196 | good_area: |
197 | si_code = SEGV_ACCERR; | |
198 | if (cause < 0) { | |
199 | - if (!(vma->vm_flags & VM_EXEC)) | |
200 | + if (!(vma->vm_flags & VM_EXEC)) { | |
201 | + | |
202 | +#ifdef CONFIG_PAX_PAGEEXEC | |
203 | + if (!(mm->pax_flags & MF_PAX_PAGEEXEC) || address != regs->pc) | |
204 | + goto bad_area; | |
205 | + | |
206 | + up_read(&mm->mmap_sem); | |
8a4b4a5e | 207 | + switch (pax_handle_fetch_fault(regs)) { |
50425a20 | 208 | + |
209 | +#ifdef CONFIG_PAX_EMUPLT | |
210 | + case 2: | |
211 | + case 3: | |
212 | + return; | |
213 | +#endif | |
214 | + | |
215 | + } | |
8a4b4a5e | 216 | + pax_report_fault(regs, (void *)regs->pc, (void *)rdusp()); |
b7f09679 | 217 | + do_group_exit(SIGKILL); |
50425a20 | 218 | +#else |
219 | goto bad_area; | |
220 | +#endif | |
221 | + | |
222 | + } | |
223 | } else if (!cause) { | |
224 | /* Allow reads even for write-only mappings */ | |
225 | if (!(vma->vm_flags & (VM_READ | VM_WRITE))) | |
4dee9bd5 | 226 | diff -urNp linux-2.6.25.4/arch/arm/mm/mmap.c linux-2.6.25.4/arch/arm/mm/mmap.c |
227 | --- linux-2.6.25.4/arch/arm/mm/mmap.c 2008-05-15 11:00:12.000000000 -0400 | |
228 | +++ linux-2.6.25.4/arch/arm/mm/mmap.c 2008-05-18 13:33:13.000000000 -0400 | |
8a4b4a5e | 229 | @@ -60,6 +60,10 @@ arch_get_unmapped_area(struct file *filp |
50425a20 | 230 | if (len > TASK_SIZE) |
231 | return -ENOMEM; | |
232 | ||
233 | +#ifdef CONFIG_PAX_RANDMMAP | |
234 | + if (!(mm->pax_flags & MF_PAX_RANDMMAP) || !filp) | |
235 | +#endif | |
236 | + | |
237 | if (addr) { | |
238 | if (do_align) | |
239 | addr = COLOUR_ALIGN(addr, pgoff); | |
8a4b4a5e | 240 | @@ -72,10 +76,10 @@ arch_get_unmapped_area(struct file *filp |
241 | return addr; | |
242 | } | |
50425a20 | 243 | if (len > mm->cached_hole_size) { |
8a4b4a5e | 244 | - start_addr = addr = mm->free_area_cache; |
245 | + start_addr = addr = mm->free_area_cache; | |
50425a20 | 246 | } else { |
247 | - start_addr = addr = TASK_UNMAPPED_BASE; | |
8a4b4a5e | 248 | - mm->cached_hole_size = 0; |
249 | + start_addr = addr = mm->mmap_base; | |
250 | + mm->cached_hole_size = 0; | |
50425a20 | 251 | } |
252 | ||
8a4b4a5e | 253 | full_search: |
254 | @@ -91,8 +95,8 @@ full_search: | |
50425a20 | 255 | * Start a new search - just in case we missed |
256 | * some holes. | |
257 | */ | |
258 | - if (start_addr != TASK_UNMAPPED_BASE) { | |
259 | - start_addr = addr = TASK_UNMAPPED_BASE; | |
260 | + if (start_addr != mm->mmap_base) { | |
261 | + start_addr = addr = mm->mmap_base; | |
262 | mm->cached_hole_size = 0; | |
263 | goto full_search; | |
264 | } | |
4dee9bd5 | 265 | diff -urNp linux-2.6.25.4/arch/avr32/mm/fault.c linux-2.6.25.4/arch/avr32/mm/fault.c |
266 | --- linux-2.6.25.4/arch/avr32/mm/fault.c 2008-05-15 11:00:12.000000000 -0400 | |
267 | +++ linux-2.6.25.4/arch/avr32/mm/fault.c 2008-05-18 13:33:13.000000000 -0400 | |
8a4b4a5e | 268 | @@ -41,6 +41,23 @@ static inline int notify_page_fault(stru |
269 | ||
270 | int exception_trace = 1; | |
50425a20 | 271 | |
272 | +#ifdef CONFIG_PAX_PAGEEXEC | |
273 | +void pax_report_insns(void *pc, void *sp) | |
274 | +{ | |
275 | + unsigned long i; | |
276 | + | |
277 | + printk(KERN_ERR "PAX: bytes at PC: "); | |
278 | + for (i = 0; i < 20; i++) { | |
279 | + unsigned char c; | |
8a4b4a5e | 280 | + if (get_user(c, (unsigned char *)pc+i)) |
4dee9bd5 | 281 | + printk(KERN_CONT "???????? "); |
50425a20 | 282 | + else |
4dee9bd5 | 283 | + printk(KERN_CONT "%02x ", c); |
50425a20 | 284 | + } |
285 | + printk("\n"); | |
286 | +} | |
287 | +#endif | |
288 | + | |
289 | /* | |
290 | * This routine handles page faults. It determines the address and the | |
291 | * problem, and then passes it off to one of the appropriate routines. | |
da5b3fc8 | 292 | @@ -157,6 +174,16 @@ bad_area: |
50425a20 | 293 | up_read(&mm->mmap_sem); |
294 | ||
295 | if (user_mode(regs)) { | |
296 | + | |
297 | +#ifdef CONFIG_PAX_PAGEEXEC | |
298 | + if (mm->pax_flags & MF_PAX_PAGEEXEC) { | |
299 | + if (ecr == ECR_PROTECTION_X || ecr == ECR_TLB_MISS_X) { | |
8a4b4a5e | 300 | + pax_report_fault(regs, (void *)regs->pc, (void *)regs->sp); |
b7f09679 | 301 | + do_group_exit(SIGKILL); |
50425a20 | 302 | + } |
303 | + } | |
304 | +#endif | |
305 | + | |
8a4b4a5e | 306 | if (exception_trace && printk_ratelimit()) |
307 | printk("%s%s[%d]: segfault at %08lx pc %08lx " | |
308 | "sp %08lx ecr %lu\n", | |
4dee9bd5 | 309 | diff -urNp linux-2.6.25.4/arch/ia64/ia32/binfmt_elf32.c linux-2.6.25.4/arch/ia64/ia32/binfmt_elf32.c |
310 | --- linux-2.6.25.4/arch/ia64/ia32/binfmt_elf32.c 2008-05-15 11:00:12.000000000 -0400 | |
311 | +++ linux-2.6.25.4/arch/ia64/ia32/binfmt_elf32.c 2008-05-18 13:33:14.000000000 -0400 | |
da5b3fc8 | 312 | @@ -45,6 +45,13 @@ randomize_stack_top(unsigned long stack_ |
50425a20 | 313 | |
da5b3fc8 | 314 | #define elf_read_implies_exec(ex, have_pt_gnu_stack) (!(have_pt_gnu_stack)) |
50425a20 | 315 | |
da5b3fc8 | 316 | +#ifdef CONFIG_PAX_ASLR |
317 | +#define PAX_ELF_ET_DYN_BASE (current->personality == PER_LINUX32 ? 0x08048000UL : 0x4000000000000000UL) | |
50425a20 | 318 | + |
da5b3fc8 | 319 | +#define PAX_DELTA_MMAP_LEN (current->personality == PER_LINUX32 ? 16 : 3*PAGE_SHIFT - 13) |
320 | +#define PAX_DELTA_STACK_LEN (current->personality == PER_LINUX32 ? 16 : 3*PAGE_SHIFT - 13) | |
50425a20 | 321 | +#endif |
322 | + | |
da5b3fc8 | 323 | /* Ugly but avoids duplication */ |
324 | #include "../../../fs/binfmt_elf.c" | |
50425a20 | 325 | |
4dee9bd5 | 326 | diff -urNp linux-2.6.25.4/arch/ia64/ia32/ia32priv.h linux-2.6.25.4/arch/ia64/ia32/ia32priv.h |
327 | --- linux-2.6.25.4/arch/ia64/ia32/ia32priv.h 2008-05-15 11:00:12.000000000 -0400 | |
328 | +++ linux-2.6.25.4/arch/ia64/ia32/ia32priv.h 2008-05-18 13:33:14.000000000 -0400 | |
da5b3fc8 | 329 | @@ -303,7 +303,14 @@ struct old_linux32_dirent { |
330 | #define ELF_DATA ELFDATA2LSB | |
331 | #define ELF_ARCH EM_386 | |
83a957c9 | 332 | |
da5b3fc8 | 333 | -#define IA32_STACK_TOP IA32_PAGE_OFFSET |
334 | +#ifdef CONFIG_PAX_RANDUSTACK | |
335 | +#define __IA32_DELTA_STACK (current->mm->delta_stack) | |
336 | +#else | |
337 | +#define __IA32_DELTA_STACK 0UL | |
50425a20 | 338 | +#endif |
339 | + | |
da5b3fc8 | 340 | +#define IA32_STACK_TOP (IA32_PAGE_OFFSET - __IA32_DELTA_STACK) |
50425a20 | 341 | + |
da5b3fc8 | 342 | #define IA32_GATE_OFFSET IA32_PAGE_OFFSET |
343 | #define IA32_GATE_END IA32_PAGE_OFFSET + PAGE_SIZE | |
50425a20 | 344 | |
4dee9bd5 | 345 | diff -urNp linux-2.6.25.4/arch/ia64/kernel/module.c linux-2.6.25.4/arch/ia64/kernel/module.c |
346 | --- linux-2.6.25.4/arch/ia64/kernel/module.c 2008-05-15 11:00:12.000000000 -0400 | |
347 | +++ linux-2.6.25.4/arch/ia64/kernel/module.c 2008-05-18 13:33:14.000000000 -0400 | |
da5b3fc8 | 348 | @@ -321,7 +321,7 @@ module_alloc (unsigned long size) |
349 | void | |
350 | module_free (struct module *mod, void *module_region) | |
50425a20 | 351 | { |
da5b3fc8 | 352 | - if (mod->arch.init_unw_table && module_region == mod->module_init) { |
353 | + if (mod->arch.init_unw_table && module_region == mod->module_init_rx) { | |
354 | unw_remove_unwind_table(mod->arch.init_unw_table); | |
355 | mod->arch.init_unw_table = NULL; | |
356 | } | |
357 | @@ -499,15 +499,39 @@ module_frob_arch_sections (Elf_Ehdr *ehd | |
358 | } | |
89388fe1 | 359 | |
da5b3fc8 | 360 | static inline int |
361 | +in_init_rx (const struct module *mod, uint64_t addr) | |
362 | +{ | |
363 | + return addr - (uint64_t) mod->module_init_rx < mod->init_size_rx; | |
364 | +} | |
89388fe1 | 365 | + |
da5b3fc8 | 366 | +static inline int |
367 | +in_init_rw (const struct module *mod, uint64_t addr) | |
368 | +{ | |
369 | + return addr - (uint64_t) mod->module_init_rw < mod->init_size_rw; | |
370 | +} | |
8a4b4a5e | 371 | + |
da5b3fc8 | 372 | +static inline int |
373 | in_init (const struct module *mod, uint64_t addr) | |
374 | { | |
375 | - return addr - (uint64_t) mod->module_init < mod->init_size; | |
4dee9bd5 | 376 | + return in_init_rx(mod, addr) || in_init_rw(mod, addr); |
da5b3fc8 | 377 | +} |
50425a20 | 378 | + |
da5b3fc8 | 379 | +static inline int |
380 | +in_core_rx (const struct module *mod, uint64_t addr) | |
381 | +{ | |
382 | + return addr - (uint64_t) mod->module_core_rx < mod->core_size_rx; | |
383 | +} | |
50425a20 | 384 | + |
da5b3fc8 | 385 | +static inline int |
386 | +in_core_rw (const struct module *mod, uint64_t addr) | |
387 | +{ | |
388 | + return addr - (uint64_t) mod->module_core_rw < mod->core_size_rw; | |
50425a20 | 389 | } |
390 | ||
da5b3fc8 | 391 | static inline int |
392 | in_core (const struct module *mod, uint64_t addr) | |
50425a20 | 393 | { |
da5b3fc8 | 394 | - return addr - (uint64_t) mod->module_core < mod->core_size; |
395 | + return in_core_rx(mod, addr) || in_core_rw(mod, addr); | |
396 | } | |
50425a20 | 397 | |
da5b3fc8 | 398 | static inline int |
399 | @@ -691,7 +715,14 @@ do_reloc (struct module *mod, uint8_t r_ | |
400 | break; | |
8a4b4a5e | 401 | |
da5b3fc8 | 402 | case RV_BDREL: |
403 | - val -= (uint64_t) (in_init(mod, val) ? mod->module_init : mod->module_core); | |
404 | + if (in_init_rx(mod, val)) | |
405 | + val -= (uint64_t) mod->module_init_rx; | |
406 | + else if (in_init_rw(mod, val)) | |
407 | + val -= (uint64_t) mod->module_init_rw; | |
408 | + else if (in_core_rx(mod, val)) | |
409 | + val -= (uint64_t) mod->module_core_rx; | |
410 | + else if (in_core_rw(mod, val)) | |
411 | + val -= (uint64_t) mod->module_core_rw; | |
412 | break; | |
8a4b4a5e | 413 | |
da5b3fc8 | 414 | case RV_LTV: |
415 | @@ -825,15 +856,15 @@ apply_relocate_add (Elf64_Shdr *sechdrs, | |
416 | * addresses have been selected... | |
417 | */ | |
418 | uint64_t gp; | |
419 | - if (mod->core_size > MAX_LTOFF) | |
420 | + if (mod->core_size_rx + mod->core_size_rw > MAX_LTOFF) | |
421 | /* | |
422 | * This takes advantage of fact that SHF_ARCH_SMALL gets allocated | |
423 | * at the end of the module. | |
424 | */ | |
425 | - gp = mod->core_size - MAX_LTOFF / 2; | |
426 | + gp = mod->core_size_rx + mod->core_size_rw - MAX_LTOFF / 2; | |
427 | else | |
428 | - gp = mod->core_size / 2; | |
429 | - gp = (uint64_t) mod->module_core + ((gp + 7) & -8); | |
430 | + gp = (mod->core_size_rx + mod->core_size_rw) / 2; | |
431 | + gp = (uint64_t) mod->module_core_rx + ((gp + 7) & -8); | |
432 | mod->arch.gp = gp; | |
4dee9bd5 | 433 | DEBUGP("%s: placing gp at 0x%lx\n", __func__, gp); |
50425a20 | 434 | } |
4dee9bd5 | 435 | diff -urNp linux-2.6.25.4/arch/ia64/kernel/sys_ia64.c linux-2.6.25.4/arch/ia64/kernel/sys_ia64.c |
436 | --- linux-2.6.25.4/arch/ia64/kernel/sys_ia64.c 2008-05-15 11:00:12.000000000 -0400 | |
437 | +++ linux-2.6.25.4/arch/ia64/kernel/sys_ia64.c 2008-05-18 13:33:14.000000000 -0400 | |
da5b3fc8 | 438 | @@ -43,6 +43,13 @@ arch_get_unmapped_area (struct file *fil |
439 | if (REGION_NUMBER(addr) == RGN_HPAGE) | |
440 | addr = 0; | |
441 | #endif | |
50425a20 | 442 | + |
da5b3fc8 | 443 | +#ifdef CONFIG_PAX_RANDMMAP |
444 | + if ((mm->pax_flags & MF_PAX_RANDMMAP) && addr && filp) | |
445 | + addr = mm->free_area_cache; | |
446 | + else | |
50425a20 | 447 | +#endif |
448 | + | |
da5b3fc8 | 449 | if (!addr) |
450 | addr = mm->free_area_cache; | |
451 | ||
452 | @@ -61,9 +68,9 @@ arch_get_unmapped_area (struct file *fil | |
453 | for (vma = find_vma(mm, addr); ; vma = vma->vm_next) { | |
454 | /* At this point: (!vma || addr < vma->vm_end). */ | |
455 | if (TASK_SIZE - len < addr || RGN_MAP_LIMIT - len < REGION_OFFSET(addr)) { | |
456 | - if (start_addr != TASK_UNMAPPED_BASE) { | |
457 | + if (start_addr != mm->mmap_base) { | |
458 | /* Start a new search --- just in case we missed some holes. */ | |
459 | - addr = TASK_UNMAPPED_BASE; | |
460 | + addr = mm->mmap_base; | |
461 | goto full_search; | |
462 | } | |
463 | return -ENOMEM; | |
4dee9bd5 | 464 | diff -urNp linux-2.6.25.4/arch/ia64/mm/fault.c linux-2.6.25.4/arch/ia64/mm/fault.c |
465 | --- linux-2.6.25.4/arch/ia64/mm/fault.c 2008-05-15 11:00:12.000000000 -0400 | |
466 | +++ linux-2.6.25.4/arch/ia64/mm/fault.c 2008-05-18 13:33:14.000000000 -0400 | |
da5b3fc8 | 467 | @@ -10,6 +10,7 @@ |
da5b3fc8 | 468 | #include <linux/kprobes.h> |
469 | #include <linux/kdebug.h> | |
b79bc584 | 470 | #include <linux/vs_memory.h> |
da5b3fc8 | 471 | +#include <linux/binfmts.h> |
472 | ||
473 | #include <asm/pgtable.h> | |
474 | #include <asm/processor.h> | |
475 | @@ -72,6 +73,23 @@ mapped_kernel_page_is_present (unsigned | |
476 | return pte_present(pte); | |
477 | } | |
478 | ||
479 | +#ifdef CONFIG_PAX_PAGEEXEC | |
480 | +void pax_report_insns(void *pc, void *sp) | |
481 | +{ | |
482 | + unsigned long i; | |
50425a20 | 483 | + |
da5b3fc8 | 484 | + printk(KERN_ERR "PAX: bytes at PC: "); |
485 | + for (i = 0; i < 8; i++) { | |
486 | + unsigned int c; | |
487 | + if (get_user(c, (unsigned int *)pc+i)) | |
4dee9bd5 | 488 | + printk(KERN_CONT "???????? "); |
da5b3fc8 | 489 | + else |
4dee9bd5 | 490 | + printk(KERN_CONT "%08x ", c); |
da5b3fc8 | 491 | + } |
492 | + printk("\n"); | |
493 | +} | |
50425a20 | 494 | +#endif |
495 | + | |
da5b3fc8 | 496 | void __kprobes |
497 | ia64_do_page_fault (unsigned long address, unsigned long isr, struct pt_regs *regs) | |
498 | { | |
499 | @@ -145,9 +163,23 @@ ia64_do_page_fault (unsigned long addres | |
500 | mask = ( (((isr >> IA64_ISR_X_BIT) & 1UL) << VM_EXEC_BIT) | |
501 | | (((isr >> IA64_ISR_W_BIT) & 1UL) << VM_WRITE_BIT)); | |
50425a20 | 502 | |
da5b3fc8 | 503 | - if ((vma->vm_flags & mask) != mask) |
504 | + if ((vma->vm_flags & mask) != mask) { | |
50425a20 | 505 | + |
da5b3fc8 | 506 | +#ifdef CONFIG_PAX_PAGEEXEC |
507 | + if (!(vma->vm_flags & VM_EXEC) && (mask & VM_EXEC)) { | |
508 | + if (!(mm->pax_flags & MF_PAX_PAGEEXEC) || address != regs->cr_iip) | |
509 | + goto bad_area; | |
50425a20 | 510 | + |
da5b3fc8 | 511 | + up_read(&mm->mmap_sem); |
512 | + pax_report_fault(regs, (void *)regs->cr_iip, (void *)regs->r12); | |
b7f09679 | 513 | + do_group_exit(SIGKILL); |
da5b3fc8 | 514 | + } |
50425a20 | 515 | +#endif |
516 | + | |
da5b3fc8 | 517 | goto bad_area; |
518 | ||
519 | + } | |
50425a20 | 520 | + |
da5b3fc8 | 521 | survive: |
522 | /* | |
523 | * If for any reason at all we couldn't handle the fault, make | |
4dee9bd5 | 524 | diff -urNp linux-2.6.25.4/arch/ia64/mm/init.c linux-2.6.25.4/arch/ia64/mm/init.c |
525 | --- linux-2.6.25.4/arch/ia64/mm/init.c 2008-05-15 11:00:12.000000000 -0400 | |
526 | +++ linux-2.6.25.4/arch/ia64/mm/init.c 2008-05-18 13:33:14.000000000 -0400 | |
da5b3fc8 | 527 | @@ -20,8 +20,8 @@ |
528 | #include <linux/proc_fs.h> | |
529 | #include <linux/bitops.h> | |
530 | #include <linux/kexec.h> | |
531 | +#include <linux/a.out.h> | |
532 | ||
533 | -#include <asm/a.out.h> | |
534 | #include <asm/dma.h> | |
535 | #include <asm/ia32.h> | |
536 | #include <asm/io.h> | |
537 | @@ -128,6 +128,19 @@ ia64_init_addr_space (void) | |
538 | vma->vm_start = current->thread.rbs_bot & PAGE_MASK; | |
539 | vma->vm_end = vma->vm_start + PAGE_SIZE; | |
540 | vma->vm_flags = VM_DATA_DEFAULT_FLAGS|VM_GROWSUP|VM_ACCOUNT; | |
541 | + | |
542 | +#ifdef CONFIG_PAX_PAGEEXEC | |
543 | + if (current->mm->pax_flags & MF_PAX_PAGEEXEC) { | |
544 | + vm->vm_flags &= ~VM_EXEC; | |
545 | + | |
546 | +#ifdef CONFIG_PAX_MPROTECT | |
547 | + if (current->mm->pax_flags & MF_PAX_MPROTECT) | |
548 | + vma->vm_flags &= ~VM_MAYEXEC; | |
50425a20 | 549 | +#endif |
550 | + | |
da5b3fc8 | 551 | + } |
8a4b4a5e | 552 | +#endif |
553 | + | |
da5b3fc8 | 554 | vma->vm_page_prot = vm_get_page_prot(vma->vm_flags); |
555 | down_write(¤t->mm->mmap_sem); | |
556 | if (insert_vm_struct(current->mm, vma)) { | |
4dee9bd5 | 557 | diff -urNp linux-2.6.25.4/arch/mips/kernel/binfmt_elfn32.c linux-2.6.25.4/arch/mips/kernel/binfmt_elfn32.c |
558 | --- linux-2.6.25.4/arch/mips/kernel/binfmt_elfn32.c 2008-05-15 11:00:12.000000000 -0400 | |
559 | +++ linux-2.6.25.4/arch/mips/kernel/binfmt_elfn32.c 2008-05-18 13:33:14.000000000 -0400 | |
da5b3fc8 | 560 | @@ -50,6 +50,13 @@ typedef elf_fpreg_t elf_fpregset_t[ELF_N |
561 | #undef ELF_ET_DYN_BASE | |
562 | #define ELF_ET_DYN_BASE (TASK32_SIZE / 3 * 2) | |
8a4b4a5e | 563 | |
da5b3fc8 | 564 | +#ifdef CONFIG_PAX_ASLR |
565 | +#define PAX_ELF_ET_DYN_BASE ((current->thread.mflags & MF_32BIT_ADDR) ? 0x00400000UL : 0x00400000UL) | |
8a4b4a5e | 566 | + |
da5b3fc8 | 567 | +#define PAX_DELTA_MMAP_LEN ((current->thread.mflags & MF_32BIT_ADDR) ? 27-PAGE_SHIFT : 36-PAGE_SHIFT) |
568 | +#define PAX_DELTA_STACK_LEN ((current->thread.mflags & MF_32BIT_ADDR) ? 27-PAGE_SHIFT : 36-PAGE_SHIFT) | |
8a4b4a5e | 569 | +#endif |
570 | + | |
da5b3fc8 | 571 | #include <asm/processor.h> |
572 | #include <linux/module.h> | |
573 | #include <linux/elfcore.h> | |
4dee9bd5 | 574 | diff -urNp linux-2.6.25.4/arch/mips/kernel/binfmt_elfo32.c linux-2.6.25.4/arch/mips/kernel/binfmt_elfo32.c |
575 | --- linux-2.6.25.4/arch/mips/kernel/binfmt_elfo32.c 2008-05-15 11:00:12.000000000 -0400 | |
576 | +++ linux-2.6.25.4/arch/mips/kernel/binfmt_elfo32.c 2008-05-18 13:33:14.000000000 -0400 | |
da5b3fc8 | 577 | @@ -52,6 +52,13 @@ typedef elf_fpreg_t elf_fpregset_t[ELF_N |
578 | #undef ELF_ET_DYN_BASE | |
579 | #define ELF_ET_DYN_BASE (TASK32_SIZE / 3 * 2) | |
50425a20 | 580 | |
da5b3fc8 | 581 | +#ifdef CONFIG_PAX_ASLR |
582 | +#define PAX_ELF_ET_DYN_BASE ((current->thread.mflags & MF_32BIT_ADDR) ? 0x00400000UL : 0x00400000UL) | |
583 | + | |
584 | +#define PAX_DELTA_MMAP_LEN ((current->thread.mflags & MF_32BIT_ADDR) ? 27-PAGE_SHIFT : 36-PAGE_SHIFT) | |
585 | +#define PAX_DELTA_STACK_LEN ((current->thread.mflags & MF_32BIT_ADDR) ? 27-PAGE_SHIFT : 36-PAGE_SHIFT) | |
8a4b4a5e | 586 | +#endif |
587 | + | |
50425a20 | 588 | #include <asm/processor.h> |
da5b3fc8 | 589 | #include <linux/module.h> |
590 | #include <linux/elfcore.h> | |
4dee9bd5 | 591 | diff -urNp linux-2.6.25.4/arch/mips/kernel/syscall.c linux-2.6.25.4/arch/mips/kernel/syscall.c |
592 | --- linux-2.6.25.4/arch/mips/kernel/syscall.c 2008-05-15 11:00:12.000000000 -0400 | |
593 | +++ linux-2.6.25.4/arch/mips/kernel/syscall.c 2008-05-18 13:33:14.000000000 -0400 | |
da5b3fc8 | 594 | @@ -93,6 +93,11 @@ unsigned long arch_get_unmapped_area(str |
595 | do_color_align = 0; | |
596 | if (filp || (flags & MAP_SHARED)) | |
597 | do_color_align = 1; | |
50425a20 | 598 | + |
da5b3fc8 | 599 | +#ifdef CONFIG_PAX_RANDMMAP |
600 | + if (!(current->mm->pax_flags & MF_PAX_RANDMMAP) || !filp) | |
50425a20 | 601 | +#endif |
da5b3fc8 | 602 | + |
603 | if (addr) { | |
604 | if (do_color_align) | |
605 | addr = COLOUR_ALIGN(addr, pgoff); | |
606 | @@ -103,7 +108,7 @@ unsigned long arch_get_unmapped_area(str | |
607 | (!vmm || addr + len <= vmm->vm_start)) | |
608 | return addr; | |
609 | } | |
610 | - addr = TASK_UNMAPPED_BASE; | |
611 | + addr = current->mm->mmap_base; | |
612 | if (do_color_align) | |
613 | addr = COLOUR_ALIGN(addr, pgoff); | |
614 | else | |
4dee9bd5 | 615 | diff -urNp linux-2.6.25.4/arch/mips/mm/fault.c linux-2.6.25.4/arch/mips/mm/fault.c |
616 | --- linux-2.6.25.4/arch/mips/mm/fault.c 2008-05-15 11:00:12.000000000 -0400 | |
617 | +++ linux-2.6.25.4/arch/mips/mm/fault.c 2008-05-18 13:33:14.000000000 -0400 | |
da5b3fc8 | 618 | @@ -26,6 +26,23 @@ |
619 | #include <asm/ptrace.h> | |
620 | #include <asm/highmem.h> /* For VMALLOC_END */ | |
50425a20 | 621 | |
da5b3fc8 | 622 | +#ifdef CONFIG_PAX_PAGEEXEC |
623 | +void pax_report_insns(void *pc) | |
624 | +{ | |
625 | + unsigned long i; | |
626 | + | |
627 | + printk(KERN_ERR "PAX: bytes at PC: "); | |
628 | + for (i = 0; i < 5; i++) { | |
629 | + unsigned int c; | |
630 | + if (get_user(c, (unsigned int *)pc+i)) | |
4dee9bd5 | 631 | + printk(KERN_CONT "???????? "); |
da5b3fc8 | 632 | + else |
4dee9bd5 | 633 | + printk(KERN_CONT "%08x ", c); |
da5b3fc8 | 634 | + } |
635 | + printk("\n"); | |
636 | +} | |
637 | +#endif | |
638 | + | |
639 | /* | |
640 | * This routine handles page faults. It determines the address, | |
641 | * and the problem, and then passes it off to one of the appropriate | |
4dee9bd5 | 642 | diff -urNp linux-2.6.25.4/arch/parisc/kernel/module.c linux-2.6.25.4/arch/parisc/kernel/module.c |
643 | --- linux-2.6.25.4/arch/parisc/kernel/module.c 2008-05-15 11:00:12.000000000 -0400 | |
644 | +++ linux-2.6.25.4/arch/parisc/kernel/module.c 2008-05-18 13:33:14.000000000 -0400 | |
da5b3fc8 | 645 | @@ -73,16 +73,38 @@ |
8a4b4a5e | 646 | |
da5b3fc8 | 647 | /* three functions to determine where in the module core |
648 | * or init pieces the location is */ | |
649 | +static inline int in_init_rx(struct module *me, void *loc) | |
650 | +{ | |
651 | + return (loc >= me->module_init_rx && | |
652 | + loc < (me->module_init_rx + me->init_size_rx)); | |
653 | +} | |
654 | + | |
655 | +static inline int in_init_rw(struct module *me, void *loc) | |
656 | +{ | |
657 | + return (loc >= me->module_init_rw && | |
658 | + loc < (me->module_init_rw + me->init_size_rw)); | |
659 | +} | |
660 | + | |
661 | static inline int in_init(struct module *me, void *loc) | |
50425a20 | 662 | { |
da5b3fc8 | 663 | - return (loc >= me->module_init && |
664 | - loc <= (me->module_init + me->init_size)); | |
665 | + return in_init_rx(me, loc) || in_init_rw(me, loc); | |
666 | +} | |
667 | + | |
668 | +static inline int in_core_rx(struct module *me, void *loc) | |
669 | +{ | |
670 | + return (loc >= me->module_core_rx && | |
671 | + loc < (me->module_core_rx + me->core_size_rx)); | |
672 | +} | |
673 | + | |
674 | +static inline int in_core_rw(struct module *me, void *loc) | |
675 | +{ | |
676 | + return (loc >= me->module_core_rw && | |
677 | + loc < (me->module_core_rw + me->core_size_rw)); | |
678 | } | |
8a4b4a5e | 679 | |
da5b3fc8 | 680 | static inline int in_core(struct module *me, void *loc) |
8a4b4a5e | 681 | { |
da5b3fc8 | 682 | - return (loc >= me->module_core && |
683 | - loc <= (me->module_core + me->core_size)); | |
684 | + return in_core_rx(me, loc) || in_core_rw(me, loc); | |
685 | } | |
8a4b4a5e | 686 | |
da5b3fc8 | 687 | static inline int in_local(struct module *me, void *loc) |
688 | @@ -296,21 +318,21 @@ int module_frob_arch_sections(CONST Elf_ | |
689 | } | |
50425a20 | 690 | |
da5b3fc8 | 691 | /* align things a bit */ |
692 | - me->core_size = ALIGN(me->core_size, 16); | |
693 | - me->arch.got_offset = me->core_size; | |
694 | - me->core_size += gots * sizeof(struct got_entry); | |
695 | - | |
696 | - me->core_size = ALIGN(me->core_size, 16); | |
697 | - me->arch.fdesc_offset = me->core_size; | |
698 | - me->core_size += fdescs * sizeof(Elf_Fdesc); | |
699 | - | |
700 | - me->core_size = ALIGN(me->core_size, 16); | |
701 | - me->arch.stub_offset = me->core_size; | |
702 | - me->core_size += stubs * sizeof(struct stub_entry); | |
703 | - | |
704 | - me->init_size = ALIGN(me->init_size, 16); | |
705 | - me->arch.init_stub_offset = me->init_size; | |
706 | - me->init_size += init_stubs * sizeof(struct stub_entry); | |
707 | + me->core_size_rw = ALIGN(me->core_size_rw, 16); | |
708 | + me->arch.got_offset = me->core_size_rw; | |
709 | + me->core_size_rw += gots * sizeof(struct got_entry); | |
710 | + | |
711 | + me->core_size_rw = ALIGN(me->core_size_rw, 16); | |
712 | + me->arch.fdesc_offset = me->core_size_rw; | |
713 | + me->core_size_rw += fdescs * sizeof(Elf_Fdesc); | |
714 | + | |
715 | + me->core_size_rx = ALIGN(me->core_size_rx, 16); | |
716 | + me->arch.stub_offset = me->core_size_rx; | |
717 | + me->core_size_rx += stubs * sizeof(struct stub_entry); | |
718 | + | |
719 | + me->init_size_rx = ALIGN(me->init_size_rx, 16); | |
720 | + me->arch.init_stub_offset = me->init_size_rx; | |
721 | + me->init_size_rx += init_stubs * sizeof(struct stub_entry); | |
50425a20 | 722 | |
da5b3fc8 | 723 | me->arch.got_max = gots; |
724 | me->arch.fdesc_max = fdescs; | |
725 | @@ -330,7 +352,7 @@ static Elf64_Word get_got(struct module | |
50425a20 | 726 | |
da5b3fc8 | 727 | BUG_ON(value == 0); |
50425a20 | 728 | |
da5b3fc8 | 729 | - got = me->module_core + me->arch.got_offset; |
730 | + got = me->module_core_rw + me->arch.got_offset; | |
731 | for (i = 0; got[i].addr; i++) | |
732 | if (got[i].addr == value) | |
733 | goto out; | |
734 | @@ -348,7 +370,7 @@ static Elf64_Word get_got(struct module | |
735 | #ifdef CONFIG_64BIT | |
736 | static Elf_Addr get_fdesc(struct module *me, unsigned long value) | |
737 | { | |
738 | - Elf_Fdesc *fdesc = me->module_core + me->arch.fdesc_offset; | |
739 | + Elf_Fdesc *fdesc = me->module_core_rw + me->arch.fdesc_offset; | |
8a4b4a5e | 740 | |
da5b3fc8 | 741 | if (!value) { |
742 | printk(KERN_ERR "%s: zero OPD requested!\n", me->name); | |
743 | @@ -366,7 +388,7 @@ static Elf_Addr get_fdesc(struct module | |
8a4b4a5e | 744 | |
da5b3fc8 | 745 | /* Create new one */ |
746 | fdesc->addr = value; | |
747 | - fdesc->gp = (Elf_Addr)me->module_core + me->arch.got_offset; | |
748 | + fdesc->gp = (Elf_Addr)me->module_core_rw + me->arch.got_offset; | |
749 | return (Elf_Addr)fdesc; | |
8a4b4a5e | 750 | } |
da5b3fc8 | 751 | #endif /* CONFIG_64BIT */ |
752 | @@ -386,12 +408,12 @@ static Elf_Addr get_stub(struct module * | |
753 | if(init_section) { | |
754 | i = me->arch.init_stub_count++; | |
755 | BUG_ON(me->arch.init_stub_count > me->arch.init_stub_max); | |
756 | - stub = me->module_init + me->arch.init_stub_offset + | |
757 | + stub = me->module_init_rx + me->arch.init_stub_offset + | |
758 | i * sizeof(struct stub_entry); | |
759 | } else { | |
760 | i = me->arch.stub_count++; | |
761 | BUG_ON(me->arch.stub_count > me->arch.stub_max); | |
762 | - stub = me->module_core + me->arch.stub_offset + | |
763 | + stub = me->module_core_rx + me->arch.stub_offset + | |
764 | i * sizeof(struct stub_entry); | |
50425a20 | 765 | } |
50425a20 | 766 | |
da5b3fc8 | 767 | @@ -759,7 +781,7 @@ register_unwind_table(struct module *me, |
50425a20 | 768 | |
da5b3fc8 | 769 | table = (unsigned char *)sechdrs[me->arch.unwind_section].sh_addr; |
770 | end = table + sechdrs[me->arch.unwind_section].sh_size; | |
771 | - gp = (Elf_Addr)me->module_core + me->arch.got_offset; | |
772 | + gp = (Elf_Addr)me->module_core_rw + me->arch.got_offset; | |
50425a20 | 773 | |
da5b3fc8 | 774 | DEBUGP("register_unwind_table(), sect = %d at 0x%p - 0x%p (gp=0x%lx)\n", |
775 | me->arch.unwind_section, table, end, gp); | |
4dee9bd5 | 776 | diff -urNp linux-2.6.25.4/arch/parisc/kernel/sys_parisc.c linux-2.6.25.4/arch/parisc/kernel/sys_parisc.c |
777 | --- linux-2.6.25.4/arch/parisc/kernel/sys_parisc.c 2008-05-15 11:00:12.000000000 -0400 | |
778 | +++ linux-2.6.25.4/arch/parisc/kernel/sys_parisc.c 2008-05-18 13:33:14.000000000 -0400 | |
da5b3fc8 | 779 | @@ -111,7 +111,7 @@ unsigned long arch_get_unmapped_area(str |
780 | if (flags & MAP_FIXED) | |
781 | return addr; | |
782 | if (!addr) | |
783 | - addr = TASK_UNMAPPED_BASE; | |
784 | + addr = current->mm->mmap_base; | |
50425a20 | 785 | |
da5b3fc8 | 786 | if (filp) { |
787 | addr = get_shared_area(filp->f_mapping, addr, len, pgoff); | |
4dee9bd5 | 788 | diff -urNp linux-2.6.25.4/arch/parisc/kernel/traps.c linux-2.6.25.4/arch/parisc/kernel/traps.c |
789 | --- linux-2.6.25.4/arch/parisc/kernel/traps.c 2008-05-15 11:00:12.000000000 -0400 | |
790 | +++ linux-2.6.25.4/arch/parisc/kernel/traps.c 2008-05-18 13:33:14.000000000 -0400 | |
791 | @@ -732,9 +732,7 @@ void handle_interruption(int code, struc | |
50425a20 | 792 | |
da5b3fc8 | 793 | down_read(¤t->mm->mmap_sem); |
794 | vma = find_vma(current->mm,regs->iaoq[0]); | |
795 | - if (vma && (regs->iaoq[0] >= vma->vm_start) | |
796 | - && (vma->vm_flags & VM_EXEC)) { | |
797 | - | |
798 | + if (vma && (regs->iaoq[0] >= vma->vm_start)) { | |
799 | fault_address = regs->iaoq[0]; | |
800 | fault_space = regs->iasq[0]; | |
50425a20 | 801 | |
4dee9bd5 | 802 | diff -urNp linux-2.6.25.4/arch/parisc/mm/fault.c linux-2.6.25.4/arch/parisc/mm/fault.c |
803 | --- linux-2.6.25.4/arch/parisc/mm/fault.c 2008-05-15 11:00:12.000000000 -0400 | |
804 | +++ linux-2.6.25.4/arch/parisc/mm/fault.c 2008-05-18 13:33:14.000000000 -0400 | |
da5b3fc8 | 805 | @@ -16,6 +16,8 @@ |
806 | #include <linux/sched.h> | |
807 | #include <linux/interrupt.h> | |
808 | #include <linux/module.h> | |
809 | +#include <linux/unistd.h> | |
810 | +#include <linux/binfmts.h> | |
8a4b4a5e | 811 | |
da5b3fc8 | 812 | #include <asm/uaccess.h> |
813 | #include <asm/traps.h> | |
814 | @@ -53,7 +55,7 @@ DEFINE_PER_CPU(struct exception_data, ex | |
815 | static unsigned long | |
816 | parisc_acctyp(unsigned long code, unsigned int inst) | |
817 | { | |
818 | - if (code == 6 || code == 16) | |
819 | + if (code == 6 || code == 7 || code == 16) | |
820 | return VM_EXEC; | |
50425a20 | 821 | |
da5b3fc8 | 822 | switch (inst & 0xf0000000) { |
823 | @@ -139,6 +141,116 @@ parisc_acctyp(unsigned long code, unsign | |
824 | } | |
825 | #endif | |
50425a20 | 826 | |
da5b3fc8 | 827 | +#ifdef CONFIG_PAX_PAGEEXEC |
828 | +/* | |
829 | + * PaX: decide what to do with offenders (instruction_pointer(regs) = fault address) | |
830 | + * | |
831 | + * returns 1 when task should be killed | |
832 | + * 2 when rt_sigreturn trampoline was detected | |
833 | + * 3 when unpatched PLT trampoline was detected | |
834 | + */ | |
835 | +static int pax_handle_fetch_fault(struct pt_regs *regs) | |
836 | +{ | |
837 | + | |
838 | +#ifdef CONFIG_PAX_EMUPLT | |
839 | + int err; | |
840 | + | |
841 | + do { /* PaX: unpatched PLT emulation */ | |
842 | + unsigned int bl, depwi; | |
843 | + | |
844 | + err = get_user(bl, (unsigned int *)instruction_pointer(regs)); | |
845 | + err |= get_user(depwi, (unsigned int *)(instruction_pointer(regs)+4)); | |
846 | + | |
847 | + if (err) | |
848 | + break; | |
849 | + | |
850 | + if (bl == 0xEA9F1FDDU && depwi == 0xD6801C1EU) { | |
851 | + unsigned int ldw, bv, ldw2, addr = instruction_pointer(regs)-12; | |
852 | + | |
853 | + err = get_user(ldw, (unsigned int *)addr); | |
854 | + err |= get_user(bv, (unsigned int *)(addr+4)); | |
855 | + err |= get_user(ldw2, (unsigned int *)(addr+8)); | |
856 | + | |
857 | + if (err) | |
858 | + break; | |
859 | + | |
860 | + if (ldw == 0x0E801096U && | |
861 | + bv == 0xEAC0C000U && | |
862 | + ldw2 == 0x0E881095U) | |
863 | + { | |
864 | + unsigned int resolver, map; | |
865 | + | |
866 | + err = get_user(resolver, (unsigned int *)(instruction_pointer(regs)+8)); | |
867 | + err |= get_user(map, (unsigned int *)(instruction_pointer(regs)+12)); | |
868 | + if (err) | |
869 | + break; | |
870 | + | |
871 | + regs->gr[20] = instruction_pointer(regs)+8; | |
872 | + regs->gr[21] = map; | |
873 | + regs->gr[22] = resolver; | |
874 | + regs->iaoq[0] = resolver | 3UL; | |
875 | + regs->iaoq[1] = regs->iaoq[0] + 4; | |
876 | + return 3; | |
877 | + } | |
878 | + } | |
879 | + } while (0); | |
880 | +#endif | |
881 | + | |
882 | +#ifdef CONFIG_PAX_EMUTRAMP | |
883 | + | |
884 | +#ifndef CONFIG_PAX_EMUSIGRT | |
885 | + if (!(current->mm->pax_flags & MF_PAX_EMUTRAMP)) | |
886 | + return 1; | |
887 | +#endif | |
888 | + | |
889 | + do { /* PaX: rt_sigreturn emulation */ | |
890 | + unsigned int ldi1, ldi2, bel, nop; | |
891 | + | |
892 | + err = get_user(ldi1, (unsigned int *)instruction_pointer(regs)); | |
893 | + err |= get_user(ldi2, (unsigned int *)(instruction_pointer(regs)+4)); | |
894 | + err |= get_user(bel, (unsigned int *)(instruction_pointer(regs)+8)); | |
895 | + err |= get_user(nop, (unsigned int *)(instruction_pointer(regs)+12)); | |
896 | + | |
897 | + if (err) | |
898 | + break; | |
899 | + | |
900 | + if ((ldi1 == 0x34190000U || ldi1 == 0x34190002U) && | |
901 | + ldi2 == 0x3414015AU && | |
902 | + bel == 0xE4008200U && | |
903 | + nop == 0x08000240U) | |
904 | + { | |
905 | + regs->gr[25] = (ldi1 & 2) >> 1; | |
906 | + regs->gr[20] = __NR_rt_sigreturn; | |
907 | + regs->gr[31] = regs->iaoq[1] + 16; | |
908 | + regs->sr[0] = regs->iasq[1]; | |
909 | + regs->iaoq[0] = 0x100UL; | |
910 | + regs->iaoq[1] = regs->iaoq[0] + 4; | |
911 | + regs->iasq[0] = regs->sr[2]; | |
912 | + regs->iasq[1] = regs->sr[2]; | |
913 | + return 2; | |
914 | + } | |
915 | + } while (0); | |
916 | +#endif | |
917 | + | |
918 | + return 1; | |
919 | +} | |
920 | + | |
921 | +void pax_report_insns(void *pc, void *sp) | |
922 | +{ | |
923 | + unsigned long i; | |
924 | + | |
925 | + printk(KERN_ERR "PAX: bytes at PC: "); | |
926 | + for (i = 0; i < 5; i++) { | |
927 | + unsigned int c; | |
928 | + if (get_user(c, (unsigned int *)pc+i)) | |
4dee9bd5 | 929 | + printk(KERN_CONT "???????? "); |
da5b3fc8 | 930 | + else |
4dee9bd5 | 931 | + printk(KERN_CONT "%08x ", c); |
da5b3fc8 | 932 | + } |
933 | + printk("\n"); | |
934 | +} | |
935 | +#endif | |
936 | + | |
937 | void do_page_fault(struct pt_regs *regs, unsigned long code, | |
938 | unsigned long address) | |
50425a20 | 939 | { |
da5b3fc8 | 940 | @@ -165,8 +277,33 @@ good_area: |
8a4b4a5e | 941 | |
da5b3fc8 | 942 | acc_type = parisc_acctyp(code,regs->iir); |
50425a20 | 943 | |
da5b3fc8 | 944 | - if ((vma->vm_flags & acc_type) != acc_type) |
945 | + if ((vma->vm_flags & acc_type) != acc_type) { | |
946 | + | |
947 | +#ifdef CONFIG_PAX_PAGEEXEC | |
948 | + if ((mm->pax_flags & MF_PAX_PAGEEXEC) && (acc_type & VM_EXEC) && | |
949 | + (address & ~3UL) == instruction_pointer(regs)) | |
950 | + { | |
951 | + up_read(&mm->mmap_sem); | |
952 | + switch (pax_handle_fetch_fault(regs)) { | |
953 | + | |
954 | +#ifdef CONFIG_PAX_EMUPLT | |
955 | + case 3: | |
956 | + return; | |
957 | +#endif | |
958 | + | |
959 | +#ifdef CONFIG_PAX_EMUTRAMP | |
960 | + case 2: | |
961 | + return; | |
962 | +#endif | |
963 | + | |
964 | + } | |
965 | + pax_report_fault(regs, (void *)instruction_pointer(regs), (void *)regs->gr[30]); | |
b7f09679 | 966 | + do_group_exit(SIGKILL); |
da5b3fc8 | 967 | + } |
968 | +#endif | |
969 | + | |
970 | goto bad_area; | |
971 | + } | |
50425a20 | 972 | |
973 | /* | |
da5b3fc8 | 974 | * If for any reason at all we couldn't handle the fault, make |
4dee9bd5 | 975 | diff -urNp linux-2.6.25.4/arch/powerpc/kernel/module_32.c linux-2.6.25.4/arch/powerpc/kernel/module_32.c |
976 | --- linux-2.6.25.4/arch/powerpc/kernel/module_32.c 2008-05-15 11:00:12.000000000 -0400 | |
977 | +++ linux-2.6.25.4/arch/powerpc/kernel/module_32.c 2008-05-18 13:33:14.000000000 -0400 | |
978 | @@ -175,7 +175,7 @@ int module_frob_arch_sections(Elf32_Ehdr | |
da5b3fc8 | 979 | me->arch.core_plt_section = i; |
980 | } | |
981 | if (!me->arch.core_plt_section || !me->arch.init_plt_section) { | |
982 | - printk("Module doesn't contain .plt or .init.plt sections.\n"); | |
983 | + printk("Module %s doesn't contain .plt or .init.plt sections.\n", me->name); | |
984 | return -ENOEXEC; | |
985 | } | |
50425a20 | 986 | |
4dee9bd5 | 987 | @@ -216,11 +216,16 @@ static uint32_t do_plt_call(void *locati |
50425a20 | 988 | |
da5b3fc8 | 989 | DEBUGP("Doing plt for call to 0x%x at 0x%x\n", val, (unsigned int)location); |
990 | /* Init, or core PLT? */ | |
991 | - if (location >= mod->module_core | |
992 | - && location < mod->module_core + mod->core_size) | |
993 | + if ((location >= mod->module_core_rx && location < mod->module_core_rx + mod->core_size_rx) || | |
994 | + (location >= mod->module_core_rw && location < mod->module_core_rw + mod->core_size_rw)) | |
995 | entry = (void *)sechdrs[mod->arch.core_plt_section].sh_addr; | |
996 | - else | |
997 | + else if ((location >= mod->module_init_rx && location < mod->module_init_rx + mod->init_size_rx) || | |
998 | + (location >= mod->module_init_rw && location < mod->module_init_rw + mod->init_size_rw)) | |
999 | entry = (void *)sechdrs[mod->arch.init_plt_section].sh_addr; | |
1000 | + else { | |
1001 | + printk(KERN_ERR "%s: invalid R_PPC_REL24 entry found\n", mod->name); | |
1002 | + return ~0UL; | |
1003 | + } | |
50425a20 | 1004 | |
da5b3fc8 | 1005 | /* Find this entry, or if that fails, the next avail. entry */ |
1006 | while (entry->jump[0]) { | |
4dee9bd5 | 1007 | diff -urNp linux-2.6.25.4/arch/powerpc/kernel/signal_32.c linux-2.6.25.4/arch/powerpc/kernel/signal_32.c |
1008 | --- linux-2.6.25.4/arch/powerpc/kernel/signal_32.c 2008-05-15 11:00:12.000000000 -0400 | |
1009 | +++ linux-2.6.25.4/arch/powerpc/kernel/signal_32.c 2008-05-18 13:33:14.000000000 -0400 | |
1010 | @@ -730,7 +730,7 @@ int handle_rt_signal32(unsigned long sig | |
da5b3fc8 | 1011 | /* Save user registers on the stack */ |
1012 | frame = &rt_sf->uc.uc_mcontext; | |
1013 | addr = frame; | |
1014 | - if (vdso32_rt_sigtramp && current->mm->context.vdso_base) { | |
1015 | + if (vdso32_rt_sigtramp && current->mm->context.vdso_base != ~0UL) { | |
1016 | if (save_user_regs(regs, frame, 0)) | |
1017 | goto badframe; | |
1018 | regs->link = current->mm->context.vdso_base + vdso32_rt_sigtramp; | |
4dee9bd5 | 1019 | diff -urNp linux-2.6.25.4/arch/powerpc/kernel/signal_64.c linux-2.6.25.4/arch/powerpc/kernel/signal_64.c |
1020 | --- linux-2.6.25.4/arch/powerpc/kernel/signal_64.c 2008-05-15 11:00:12.000000000 -0400 | |
1021 | +++ linux-2.6.25.4/arch/powerpc/kernel/signal_64.c 2008-05-18 13:33:14.000000000 -0400 | |
da5b3fc8 | 1022 | @@ -369,7 +369,7 @@ int handle_rt_signal64(int signr, struct |
1023 | current->thread.fpscr.val = 0; | |
50425a20 | 1024 | |
da5b3fc8 | 1025 | /* Set up to return from userspace. */ |
1026 | - if (vdso64_rt_sigtramp && current->mm->context.vdso_base) { | |
1027 | + if (vdso64_rt_sigtramp && current->mm->context.vdso_base != ~0UL) { | |
1028 | regs->link = current->mm->context.vdso_base + vdso64_rt_sigtramp; | |
1029 | } else { | |
1030 | err |= setup_trampoline(__NR_rt_sigreturn, &frame->tramp[0]); | |
4dee9bd5 | 1031 | diff -urNp linux-2.6.25.4/arch/powerpc/kernel/vdso.c linux-2.6.25.4/arch/powerpc/kernel/vdso.c |
1032 | --- linux-2.6.25.4/arch/powerpc/kernel/vdso.c 2008-05-15 11:00:12.000000000 -0400 | |
1033 | +++ linux-2.6.25.4/arch/powerpc/kernel/vdso.c 2008-05-18 13:33:14.000000000 -0400 | |
da5b3fc8 | 1034 | @@ -211,7 +211,7 @@ int arch_setup_additional_pages(struct l |
1035 | vdso_base = VDSO32_MBASE; | |
1036 | #endif | |
50425a20 | 1037 | |
da5b3fc8 | 1038 | - current->mm->context.vdso_base = 0; |
1039 | + current->mm->context.vdso_base = ~0UL; | |
50425a20 | 1040 | |
da5b3fc8 | 1041 | /* vDSO has a problem and was disabled, just don't "enable" it for the |
1042 | * process | |
1043 | @@ -228,7 +228,7 @@ int arch_setup_additional_pages(struct l | |
50425a20 | 1044 | */ |
da5b3fc8 | 1045 | down_write(&mm->mmap_sem); |
1046 | vdso_base = get_unmapped_area(NULL, vdso_base, | |
1047 | - vdso_pages << PAGE_SHIFT, 0, 0); | |
1048 | + vdso_pages << PAGE_SHIFT, 0, MAP_PRIVATE | MAP_EXECUTABLE); | |
1049 | if (IS_ERR_VALUE(vdso_base)) { | |
1050 | rc = vdso_base; | |
1051 | goto fail_mmapsem; | |
4dee9bd5 | 1052 | diff -urNp linux-2.6.25.4/arch/powerpc/mm/fault.c linux-2.6.25.4/arch/powerpc/mm/fault.c |
1053 | --- linux-2.6.25.4/arch/powerpc/mm/fault.c 2008-05-15 11:00:12.000000000 -0400 | |
1054 | +++ linux-2.6.25.4/arch/powerpc/mm/fault.c 2008-05-18 13:33:14.000000000 -0400 | |
da5b3fc8 | 1055 | @@ -29,6 +29,12 @@ |
1056 | #include <linux/module.h> | |
1057 | #include <linux/kprobes.h> | |
1058 | #include <linux/kdebug.h> | |
1059 | +#include <linux/binfmts.h> | |
1060 | +#include <linux/slab.h> | |
1061 | +#include <linux/pagemap.h> | |
1062 | +#include <linux/compiler.h> | |
1063 | +#include <linux/binfmts.h> | |
1064 | +#include <linux/unistd.h> | |
50425a20 | 1065 | |
da5b3fc8 | 1066 | #include <asm/page.h> |
1067 | #include <asm/pgtable.h> | |
4dee9bd5 | 1068 | @@ -62,6 +68,366 @@ static inline int notify_page_fault(stru |
da5b3fc8 | 1069 | } |
50425a20 | 1070 | #endif |
1071 | ||
da5b3fc8 | 1072 | +#ifdef CONFIG_PAX_EMUSIGRT |
1073 | +void pax_syscall_close(struct vm_area_struct *vma) | |
1074 | +{ | |
1075 | + vma->vm_mm->call_syscall = 0UL; | |
1076 | +} | |
50425a20 | 1077 | + |
da5b3fc8 | 1078 | +static struct page *pax_syscall_nopage(struct vm_area_struct *vma, unsigned long address, int *type) |
1079 | +{ | |
1080 | + struct page *page; | |
1081 | + unsigned int *kaddr; | |
50425a20 | 1082 | + |
da5b3fc8 | 1083 | + page = alloc_page(GFP_HIGHUSER); |
1084 | + if (!page) | |
1085 | + return NOPAGE_OOM; | |
50425a20 | 1086 | + |
da5b3fc8 | 1087 | + kaddr = kmap(page); |
1088 | + memset(kaddr, 0, PAGE_SIZE); | |
1089 | + kaddr[0] = 0x44000002U; /* sc */ | |
1090 | + __flush_dcache_icache(kaddr); | |
1091 | + kunmap(page); | |
1092 | + if (type) | |
1093 | + *type = VM_FAULT_MAJOR; | |
1094 | + return page; | |
1095 | +} | |
50425a20 | 1096 | + |
da5b3fc8 | 1097 | +static struct vm_operations_struct pax_vm_ops = { |
1098 | + .close = pax_syscall_close, | |
1099 | + .nopage = pax_syscall_nopage, | |
1100 | +}; | |
50425a20 | 1101 | + |
da5b3fc8 | 1102 | +static int pax_insert_vma(struct vm_area_struct *vma, unsigned long addr) |
1103 | +{ | |
1104 | + int ret; | |
50425a20 | 1105 | + |
da5b3fc8 | 1106 | + vma->vm_mm = current->mm; |
1107 | + vma->vm_start = addr; | |
1108 | + vma->vm_end = addr + PAGE_SIZE; | |
1109 | + vma->vm_flags = VM_READ | VM_EXEC | VM_MAYREAD | VM_MAYEXEC; | |
1110 | + vma->vm_page_prot = vm_get_page_prot(vma->vm_flags); | |
1111 | + vma->vm_ops = &pax_vm_ops; | |
50425a20 | 1112 | + |
da5b3fc8 | 1113 | + ret = insert_vm_struct(current->mm, vma); |
1114 | + if (ret) | |
1115 | + return ret; | |
50425a20 | 1116 | + |
da5b3fc8 | 1117 | + ++current->mm->total_vm; |
1118 | + return 0; | |
1119 | +} | |
8a4b4a5e | 1120 | +#endif |
50425a20 | 1121 | + |
da5b3fc8 | 1122 | +#ifdef CONFIG_PAX_PAGEEXEC |
1123 | +/* | |
1124 | + * PaX: decide what to do with offenders (regs->nip = fault address) | |
1125 | + * | |
1126 | + * returns 1 when task should be killed | |
1127 | + * 2 when patched GOT trampoline was detected | |
1128 | + * 3 when patched PLT trampoline was detected | |
1129 | + * 4 when unpatched PLT trampoline was detected | |
1130 | + * 5 when sigreturn trampoline was detected | |
1131 | + * 6 when rt_sigreturn trampoline was detected | |
1132 | + */ | |
1133 | +static int pax_handle_fetch_fault(struct pt_regs *regs) | |
1134 | +{ | |
1135 | + | |
1136 | +#if defined(CONFIG_PAX_EMUPLT) || defined(CONFIG_PAX_EMUSIGRT) | |
1137 | + int err; | |
50425a20 | 1138 | +#endif |
1139 | + | |
da5b3fc8 | 1140 | +#ifdef CONFIG_PAX_EMUPLT |
1141 | + do { /* PaX: patched GOT emulation */ | |
1142 | + unsigned int blrl; | |
50425a20 | 1143 | + |
da5b3fc8 | 1144 | + err = get_user(blrl, (unsigned int *)regs->nip); |
50425a20 | 1145 | + |
da5b3fc8 | 1146 | + if (!err && blrl == 0x4E800021U) { |
1147 | + unsigned long temp = regs->nip; | |
50425a20 | 1148 | + |
da5b3fc8 | 1149 | + regs->nip = regs->link & 0xFFFFFFFCUL; |
1150 | + regs->link = temp + 4UL; | |
1151 | + return 2; | |
1152 | + } | |
1153 | + } while (0); | |
50425a20 | 1154 | + |
da5b3fc8 | 1155 | + do { /* PaX: patched PLT emulation #1 */ |
1156 | + unsigned int b; | |
50425a20 | 1157 | + |
da5b3fc8 | 1158 | + err = get_user(b, (unsigned int *)regs->nip); |
8a4b4a5e | 1159 | + |
da5b3fc8 | 1160 | + if (!err && (b & 0xFC000003U) == 0x48000000U) { |
1161 | + regs->nip += (((b | 0xFC000000UL) ^ 0x02000000UL) + 0x02000000UL); | |
1162 | + return 3; | |
1163 | + } | |
1164 | + } while (0); | |
50425a20 | 1165 | + |
da5b3fc8 | 1166 | + do { /* PaX: unpatched PLT emulation #1 */ |
1167 | + unsigned int li, b; | |
50425a20 | 1168 | + |
da5b3fc8 | 1169 | + err = get_user(li, (unsigned int *)regs->nip); |
1170 | + err |= get_user(b, (unsigned int *)(regs->nip+4)); | |
50425a20 | 1171 | + |
da5b3fc8 | 1172 | + if (!err && (li & 0xFFFF0000U) == 0x39600000U && (b & 0xFC000003U) == 0x48000000U) { |
1173 | + unsigned int rlwinm, add, li2, addis2, mtctr, li3, addis3, bctr; | |
1174 | + unsigned long addr = b | 0xFC000000UL; | |
50425a20 | 1175 | + |
da5b3fc8 | 1176 | + addr = regs->nip + 4 + ((addr ^ 0x02000000UL) + 0x02000000UL); |
1177 | + err = get_user(rlwinm, (unsigned int *)addr); | |
1178 | + err |= get_user(add, (unsigned int *)(addr+4)); | |
1179 | + err |= get_user(li2, (unsigned int *)(addr+8)); | |
1180 | + err |= get_user(addis2, (unsigned int *)(addr+12)); | |
1181 | + err |= get_user(mtctr, (unsigned int *)(addr+16)); | |
1182 | + err |= get_user(li3, (unsigned int *)(addr+20)); | |
1183 | + err |= get_user(addis3, (unsigned int *)(addr+24)); | |
1184 | + err |= get_user(bctr, (unsigned int *)(addr+28)); | |
50425a20 | 1185 | + |
da5b3fc8 | 1186 | + if (err) |
1187 | + break; | |
50425a20 | 1188 | + |
da5b3fc8 | 1189 | + if (rlwinm == 0x556C083CU && |
1190 | + add == 0x7D6C5A14U && | |
1191 | + (li2 & 0xFFFF0000U) == 0x39800000U && | |
1192 | + (addis2 & 0xFFFF0000U) == 0x3D8C0000U && | |
1193 | + mtctr == 0x7D8903A6U && | |
1194 | + (li3 & 0xFFFF0000U) == 0x39800000U && | |
1195 | + (addis3 & 0xFFFF0000U) == 0x3D8C0000U && | |
1196 | + bctr == 0x4E800420U) | |
1197 | + { | |
1198 | + regs->gpr[PT_R11] = 3 * (((li | 0xFFFF0000UL) ^ 0x00008000UL) + 0x00008000UL); | |
1199 | + regs->gpr[PT_R12] = (((li3 | 0xFFFF0000UL) ^ 0x00008000UL) + 0x00008000UL); | |
1200 | + regs->gpr[PT_R12] += (addis3 & 0xFFFFU) << 16; | |
1201 | + regs->ctr = (((li2 | 0xFFFF0000UL) ^ 0x00008000UL) + 0x00008000UL); | |
1202 | + regs->ctr += (addis2 & 0xFFFFU) << 16; | |
1203 | + regs->nip = regs->ctr; | |
1204 | + return 4; | |
1205 | + } | |
1206 | + } | |
1207 | + } while (0); | |
8a4b4a5e | 1208 | + |
da5b3fc8 | 1209 | +#if 0 |
1210 | + do { /* PaX: unpatched PLT emulation #2 */ | |
1211 | + unsigned int lis, lwzu, b, bctr; | |
8a4b4a5e | 1212 | + |
da5b3fc8 | 1213 | + err = get_user(lis, (unsigned int *)regs->nip); |
1214 | + err |= get_user(lwzu, (unsigned int *)(regs->nip+4)); | |
1215 | + err |= get_user(b, (unsigned int *)(regs->nip+8)); | |
1216 | + err |= get_user(bctr, (unsigned int *)(regs->nip+12)); | |
50425a20 | 1217 | + |
da5b3fc8 | 1218 | + if (err) |
1219 | + break; | |
50425a20 | 1220 | + |
da5b3fc8 | 1221 | + if ((lis & 0xFFFF0000U) == 0x39600000U && |
1222 | + (lwzu & 0xU) == 0xU && | |
1223 | + (b & 0xFC000003U) == 0x48000000U && | |
1224 | + bctr == 0x4E800420U) | |
1225 | + { | |
1226 | + unsigned int addis, addi, rlwinm, add, li2, addis2, mtctr, li3, addis3, bctr; | |
1227 | + unsigned long addr = b | 0xFC000000UL; | |
50425a20 | 1228 | + |
da5b3fc8 | 1229 | + addr = regs->nip + 12 + ((addr ^ 0x02000000UL) + 0x02000000UL); |
4dee9bd5 | 1230 | + err = get_user(addis, (unsigned int *)addr); |
1231 | + err |= get_user(addi, (unsigned int *)(addr+4)); | |
1232 | + err |= get_user(rlwinm, (unsigned int *)(addr+8)); | |
1233 | + err |= get_user(add, (unsigned int *)(addr+12)); | |
1234 | + err |= get_user(li2, (unsigned int *)(addr+16)); | |
1235 | + err |= get_user(addis2, (unsigned int *)(addr+20)); | |
1236 | + err |= get_user(mtctr, (unsigned int *)(addr+24)); | |
1237 | + err |= get_user(li3, (unsigned int *)(addr+28)); | |
1238 | + err |= get_user(addis3, (unsigned int *)(addr+32)); | |
1239 | + err |= get_user(bctr, (unsigned int *)(addr+36)); | |
8a4b4a5e | 1240 | + |
da5b3fc8 | 1241 | + if (err) |
1242 | + break; | |
8a4b4a5e | 1243 | + |
da5b3fc8 | 1244 | + if ((addis & 0xFFFF0000U) == 0x3D6B0000U && |
1245 | + (addi & 0xFFFF0000U) == 0x396B0000U && | |
1246 | + rlwinm == 0x556C083CU && | |
1247 | + add == 0x7D6C5A14U && | |
1248 | + (li2 & 0xFFFF0000U) == 0x39800000U && | |
1249 | + (addis2 & 0xFFFF0000U) == 0x3D8C0000U && | |
1250 | + mtctr == 0x7D8903A6U && | |
1251 | + (li3 & 0xFFFF0000U) == 0x39800000U && | |
1252 | + (addis3 & 0xFFFF0000U) == 0x3D8C0000U && | |
1253 | + bctr == 0x4E800420U) | |
1254 | + { | |
da5b3fc8 | 1255 | + regs->gpr[PT_R11] = 3 * (((li | 0xFFFF0000UL) ^ 0x00008000UL) + 0x00008000UL); |
1256 | + regs->gpr[PT_R12] = (((li3 | 0xFFFF0000UL) ^ 0x00008000UL) + 0x00008000UL); | |
1257 | + regs->gpr[PT_R12] += (addis3 & 0xFFFFU) << 16; | |
1258 | + regs->ctr = (((li2 | 0xFFFF0000UL) ^ 0x00008000UL) + 0x00008000UL); | |
1259 | + regs->ctr += (addis2 & 0xFFFFU) << 16; | |
1260 | + regs->nip = regs->ctr; | |
1261 | + return 4; | |
1262 | + } | |
1263 | + } | |
1264 | + } while (0); | |
1265 | +#endif | |
8a4b4a5e | 1266 | + |
da5b3fc8 | 1267 | + do { /* PaX: unpatched PLT emulation #3 */ |
1268 | + unsigned int li, b; | |
8a4b4a5e | 1269 | + |
da5b3fc8 | 1270 | + err = get_user(li, (unsigned int *)regs->nip); |
1271 | + err |= get_user(b, (unsigned int *)(regs->nip+4)); | |
8a4b4a5e | 1272 | + |
da5b3fc8 | 1273 | + if (!err && (li & 0xFFFF0000U) == 0x39600000U && (b & 0xFC000003U) == 0x48000000U) { |
1274 | + unsigned int addis, lwz, mtctr, bctr; | |
1275 | + unsigned long addr = b | 0xFC000000UL; | |
8a4b4a5e | 1276 | + |
da5b3fc8 | 1277 | + addr = regs->nip + 4 + ((addr ^ 0x02000000UL) + 0x02000000UL); |
1278 | + err = get_user(addis, (unsigned int *)addr); | |
1279 | + err |= get_user(lwz, (unsigned int *)(addr+4)); | |
1280 | + err |= get_user(mtctr, (unsigned int *)(addr+8)); | |
1281 | + err |= get_user(bctr, (unsigned int *)(addr+12)); | |
8a4b4a5e | 1282 | + |
da5b3fc8 | 1283 | + if (err) |
1284 | + break; | |
8a4b4a5e | 1285 | + |
da5b3fc8 | 1286 | + if ((addis & 0xFFFF0000U) == 0x3D6B0000U && |
1287 | + (lwz & 0xFFFF0000U) == 0x816B0000U && | |
1288 | + mtctr == 0x7D6903A6U && | |
1289 | + bctr == 0x4E800420U) | |
1290 | + { | |
1291 | + unsigned int r11; | |
50425a20 | 1292 | + |
da5b3fc8 | 1293 | + addr = (addis << 16) + (((li | 0xFFFF0000UL) ^ 0x00008000UL) + 0x00008000UL); |
1294 | + addr += (((lwz | 0xFFFF0000UL) ^ 0x00008000UL) + 0x00008000UL); | |
1295 | + | |
1296 | + err = get_user(r11, (unsigned int *)addr); | |
1297 | + if (err) | |
1298 | + break; | |
1299 | + | |
1300 | + regs->gpr[PT_R11] = r11; | |
1301 | + regs->ctr = r11; | |
1302 | + regs->nip = r11; | |
1303 | + return 4; | |
1304 | + } | |
1305 | + } | |
1306 | + } while (0); | |
8a4b4a5e | 1307 | +#endif |
50425a20 | 1308 | + |
da5b3fc8 | 1309 | +#ifdef CONFIG_PAX_EMUSIGRT |
1310 | + do { /* PaX: sigreturn emulation */ | |
1311 | + unsigned int li, sc; | |
83a957c9 | 1312 | + |
da5b3fc8 | 1313 | + err = get_user(li, (unsigned int *)regs->nip); |
1314 | + err |= get_user(sc, (unsigned int *)(regs->nip+4)); | |
83a957c9 | 1315 | + |
da5b3fc8 | 1316 | + if (!err && li == 0x38000000U + __NR_sigreturn && sc == 0x44000002U) { |
1317 | + struct vm_area_struct *vma; | |
1318 | + unsigned long call_syscall; | |
83a957c9 | 1319 | + |
da5b3fc8 | 1320 | + down_read(¤t->mm->mmap_sem); |
1321 | + call_syscall = current->mm->call_syscall; | |
1322 | + up_read(¤t->mm->mmap_sem); | |
1323 | + if (likely(call_syscall)) | |
1324 | + goto emulate; | |
83a957c9 | 1325 | + |
da5b3fc8 | 1326 | + vma = kmem_cache_zalloc(vm_area_cachep, GFP_KERNEL); |
83a957c9 | 1327 | + |
da5b3fc8 | 1328 | + down_write(¤t->mm->mmap_sem); |
1329 | + if (current->mm->call_syscall) { | |
1330 | + call_syscall = current->mm->call_syscall; | |
1331 | + up_write(¤t->mm->mmap_sem); | |
4dee9bd5 | 1332 | + if (vma) |
1333 | + kmem_cache_free(vm_area_cachep, vma); | |
da5b3fc8 | 1334 | + goto emulate; |
1335 | + } | |
83a957c9 | 1336 | + |
da5b3fc8 | 1337 | + call_syscall = get_unmapped_area(NULL, 0UL, PAGE_SIZE, 0UL, MAP_PRIVATE); |
1338 | + if (!vma || (call_syscall & ~PAGE_MASK)) { | |
1339 | + up_write(¤t->mm->mmap_sem); | |
4dee9bd5 | 1340 | + if (vma) |
1341 | + kmem_cache_free(vm_area_cachep, vma); | |
da5b3fc8 | 1342 | + return 1; |
1343 | + } | |
83a957c9 | 1344 | + |
da5b3fc8 | 1345 | + if (pax_insert_vma(vma, call_syscall)) { |
1346 | + up_write(¤t->mm->mmap_sem); | |
1347 | + kmem_cache_free(vm_area_cachep, vma); | |
1348 | + return 1; | |
1349 | + } | |
83a957c9 | 1350 | + |
da5b3fc8 | 1351 | + current->mm->call_syscall = call_syscall; |
1352 | + up_write(¤t->mm->mmap_sem); | |
83a957c9 | 1353 | + |
da5b3fc8 | 1354 | +emulate: |
1355 | + regs->gpr[PT_R0] = __NR_sigreturn; | |
1356 | + regs->nip = call_syscall; | |
1357 | + return 5; | |
1358 | + } | |
1359 | + } while (0); | |
83a957c9 | 1360 | + |
da5b3fc8 | 1361 | + do { /* PaX: rt_sigreturn emulation */ |
1362 | + unsigned int li, sc; | |
83a957c9 | 1363 | + |
da5b3fc8 | 1364 | + err = get_user(li, (unsigned int *)regs->nip); |
1365 | + err |= get_user(sc, (unsigned int *)(regs->nip+4)); | |
50425a20 | 1366 | + |
da5b3fc8 | 1367 | + if (!err && li == 0x38000000U + __NR_rt_sigreturn && sc == 0x44000002U) { |
1368 | + struct vm_area_struct *vma; | |
1369 | + unsigned int call_syscall; | |
50425a20 | 1370 | + |
da5b3fc8 | 1371 | + down_read(¤t->mm->mmap_sem); |
1372 | + call_syscall = current->mm->call_syscall; | |
1373 | + up_read(¤t->mm->mmap_sem); | |
1374 | + if (likely(call_syscall)) | |
1375 | + goto rt_emulate; | |
50425a20 | 1376 | + |
da5b3fc8 | 1377 | + vma = kmem_cache_zalloc(vm_area_cachep, GFP_KERNEL); |
50425a20 | 1378 | + |
da5b3fc8 | 1379 | + down_write(¤t->mm->mmap_sem); |
1380 | + if (current->mm->call_syscall) { | |
1381 | + call_syscall = current->mm->call_syscall; | |
1382 | + up_write(¤t->mm->mmap_sem); | |
4dee9bd5 | 1383 | + if (vma) |
1384 | + kmem_cache_free(vm_area_cachep, vma); | |
da5b3fc8 | 1385 | + goto rt_emulate; |
1386 | + } | |
50425a20 | 1387 | + |
da5b3fc8 | 1388 | + call_syscall = get_unmapped_area(NULL, 0UL, PAGE_SIZE, 0UL, MAP_PRIVATE); |
1389 | + if (!vma || (call_syscall & ~PAGE_MASK)) { | |
1390 | + up_write(¤t->mm->mmap_sem); | |
4dee9bd5 | 1391 | + if (vma) |
1392 | + kmem_cache_free(vm_area_cachep, vma); | |
da5b3fc8 | 1393 | + return 1; |
1394 | + } | |
50425a20 | 1395 | + |
da5b3fc8 | 1396 | + if (pax_insert_vma(vma, call_syscall)) { |
1397 | + up_write(¤t->mm->mmap_sem); | |
1398 | + kmem_cache_free(vm_area_cachep, vma); | |
1399 | + return 1; | |
1400 | + } | |
1401 | + | |
1402 | + current->mm->call_syscall = call_syscall; | |
1403 | + up_write(¤t->mm->mmap_sem); | |
1404 | + | |
1405 | +rt_emulate: | |
1406 | + regs->gpr[PT_R0] = __NR_rt_sigreturn; | |
1407 | + regs->nip = call_syscall; | |
1408 | + return 6; | |
1409 | + } | |
1410 | + } while (0); | |
50425a20 | 1411 | +#endif |
1412 | + | |
da5b3fc8 | 1413 | + return 1; |
1414 | +} | |
50425a20 | 1415 | + |
da5b3fc8 | 1416 | +void pax_report_insns(void *pc, void *sp) |
1417 | +{ | |
1418 | + unsigned long i; | |
1419 | + | |
1420 | + printk(KERN_ERR "PAX: bytes at PC: "); | |
1421 | + for (i = 0; i < 5; i++) { | |
1422 | + unsigned int c; | |
1423 | + if (get_user(c, (unsigned int *)pc+i)) | |
4dee9bd5 | 1424 | + printk(KERN_CONT "???????? "); |
da5b3fc8 | 1425 | + else |
4dee9bd5 | 1426 | + printk(KERN_CONT "%08x ", c); |
da5b3fc8 | 1427 | + } |
1428 | + printk("\n"); | |
1429 | +} | |
1430 | +#endif | |
1431 | + | |
1432 | /* | |
1433 | * Check whether the instruction at regs->nip is a store using | |
1434 | * an update addressing form which will update r1. | |
4dee9bd5 | 1435 | @@ -157,7 +523,7 @@ int __kprobes do_page_fault(struct pt_re |
da5b3fc8 | 1436 | * indicate errors in DSISR but can validly be set in SRR1. |
1437 | */ | |
1438 | if (trap == 0x400) | |
1439 | - error_code &= 0x48200000; | |
1440 | + error_code &= 0x58200000; | |
1441 | else | |
1442 | is_write = error_code & DSISR_ISSTORE; | |
50425a20 | 1443 | #else |
4dee9bd5 | 1444 | @@ -355,6 +721,37 @@ bad_area: |
da5b3fc8 | 1445 | bad_area_nosemaphore: |
1446 | /* User mode accesses cause a SIGSEGV */ | |
1447 | if (user_mode(regs)) { | |
50425a20 | 1448 | + |
da5b3fc8 | 1449 | +#ifdef CONFIG_PAX_PAGEEXEC |
1450 | + if (mm->pax_flags & MF_PAX_PAGEEXEC) { | |
1451 | +#ifdef CONFIG_PPC64 | |
1452 | + if (is_exec && (error_code & DSISR_PROTFAULT)) { | |
50425a20 | 1453 | +#else |
da5b3fc8 | 1454 | + if (is_exec && regs->nip == address) { |
50425a20 | 1455 | +#endif |
da5b3fc8 | 1456 | + switch (pax_handle_fetch_fault(regs)) { |
50425a20 | 1457 | + |
da5b3fc8 | 1458 | +#ifdef CONFIG_PAX_EMUPLT |
1459 | + case 2: | |
1460 | + case 3: | |
1461 | + case 4: | |
1462 | + return 0; | |
1463 | +#endif | |
50425a20 | 1464 | + |
da5b3fc8 | 1465 | +#ifdef CONFIG_PAX_EMUSIGRT |
1466 | + case 5: | |
1467 | + case 6: | |
1468 | + return 0; | |
1469 | +#endif | |
50425a20 | 1470 | + |
da5b3fc8 | 1471 | + } |
50425a20 | 1472 | + |
4dee9bd5 | 1473 | + pax_report_fault(regs, (void *)regs->nip, (void *)regs->gpr[PT_R1]); |
b7f09679 | 1474 | + do_group_exit(SIGKILL); |
da5b3fc8 | 1475 | + } |
1476 | + } | |
1477 | +#endif | |
1478 | + | |
1479 | _exception(SIGSEGV, regs, code, address); | |
1480 | return 0; | |
1481 | } | |
4dee9bd5 | 1482 | diff -urNp linux-2.6.25.4/arch/powerpc/mm/mmap.c linux-2.6.25.4/arch/powerpc/mm/mmap.c |
1483 | --- linux-2.6.25.4/arch/powerpc/mm/mmap.c 2008-05-15 11:00:12.000000000 -0400 | |
1484 | +++ linux-2.6.25.4/arch/powerpc/mm/mmap.c 2008-05-18 13:33:14.000000000 -0400 | |
da5b3fc8 | 1485 | @@ -75,10 +75,22 @@ void arch_pick_mmap_layout(struct mm_str |
1486 | */ | |
1487 | if (mmap_is_legacy()) { | |
1488 | mm->mmap_base = TASK_UNMAPPED_BASE; | |
1489 | + | |
1490 | +#ifdef CONFIG_PAX_RANDMMAP | |
1491 | + if (mm->pax_flags & MF_PAX_RANDMMAP) | |
1492 | + mm->mmap_base += mm->delta_mmap; | |
1493 | +#endif | |
1494 | + | |
1495 | mm->get_unmapped_area = arch_get_unmapped_area; | |
1496 | mm->unmap_area = arch_unmap_area; | |
1497 | } else { | |
1498 | mm->mmap_base = mmap_base(); | |
1499 | + | |
1500 | +#ifdef CONFIG_PAX_RANDMMAP | |
1501 | + if (mm->pax_flags & MF_PAX_RANDMMAP) | |
1502 | + mm->mmap_base -= mm->delta_mmap + mm->delta_stack; | |
50425a20 | 1503 | +#endif |
da5b3fc8 | 1504 | + |
1505 | mm->get_unmapped_area = arch_get_unmapped_area_topdown; | |
1506 | mm->unmap_area = arch_unmap_area_topdown; | |
1507 | } | |
4dee9bd5 | 1508 | diff -urNp linux-2.6.25.4/arch/ppc/mm/fault.c linux-2.6.25.4/arch/ppc/mm/fault.c |
1509 | --- linux-2.6.25.4/arch/ppc/mm/fault.c 2008-05-15 11:00:12.000000000 -0400 | |
1510 | +++ linux-2.6.25.4/arch/ppc/mm/fault.c 2008-05-18 13:33:14.000000000 -0400 | |
da5b3fc8 | 1511 | @@ -25,6 +25,11 @@ |
1512 | #include <linux/interrupt.h> | |
1513 | #include <linux/highmem.h> | |
1514 | #include <linux/module.h> | |
1515 | +#include <linux/slab.h> | |
1516 | +#include <linux/pagemap.h> | |
1517 | +#include <linux/compiler.h> | |
1518 | +#include <linux/binfmts.h> | |
1519 | +#include <linux/unistd.h> | |
50425a20 | 1520 | |
da5b3fc8 | 1521 | #include <asm/page.h> |
1522 | #include <asm/pgtable.h> | |
4dee9bd5 | 1523 | @@ -48,6 +53,366 @@ unsigned long pte_misses; /* updated by |
da5b3fc8 | 1524 | unsigned long pte_errors; /* updated by do_page_fault() */ |
1525 | unsigned int probingmem; | |
50425a20 | 1526 | |
da5b3fc8 | 1527 | +#ifdef CONFIG_PAX_EMUSIGRT |
1528 | +void pax_syscall_close(struct vm_area_struct *vma) | |
50425a20 | 1529 | +{ |
da5b3fc8 | 1530 | + vma->vm_mm->call_syscall = 0UL; |
1531 | +} | |
50425a20 | 1532 | + |
da5b3fc8 | 1533 | +static struct page *pax_syscall_nopage(struct vm_area_struct *vma, unsigned long address, int *type) |
1534 | +{ | |
1535 | + struct page *page; | |
1536 | + unsigned int *kaddr; | |
50425a20 | 1537 | + |
da5b3fc8 | 1538 | + page = alloc_page(GFP_HIGHUSER); |
1539 | + if (!page) | |
1540 | + return NOPAGE_OOM; | |
50425a20 | 1541 | + |
da5b3fc8 | 1542 | + kaddr = kmap(page); |
1543 | + memset(kaddr, 0, PAGE_SIZE); | |
1544 | + kaddr[0] = 0x44000002U; /* sc */ | |
1545 | + __flush_dcache_icache(kaddr); | |
1546 | + kunmap(page); | |
1547 | + if (type) | |
1548 | + *type = VM_FAULT_MAJOR; | |
1549 | + return page; | |
1550 | +} | |
50425a20 | 1551 | + |
da5b3fc8 | 1552 | +static struct vm_operations_struct pax_vm_ops = { |
1553 | + .close = pax_syscall_close, | |
1554 | + .nopage = pax_syscall_nopage, | |
1555 | +}; | |
50425a20 | 1556 | + |
da5b3fc8 | 1557 | +static int pax_insert_vma(struct vm_area_struct *vma, unsigned long addr) |
1558 | +{ | |
1559 | + int ret; | |
50425a20 | 1560 | + |
da5b3fc8 | 1561 | + vma->vm_mm = current->mm; |
1562 | + vma->vm_start = addr; | |
1563 | + vma->vm_end = addr + PAGE_SIZE; | |
1564 | + vma->vm_flags = VM_READ | VM_EXEC | VM_MAYREAD | VM_MAYEXEC; | |
1565 | + vma->vm_page_prot = vm_get_page_prot(vma->vm_flags); | |
1566 | + vma->vm_ops = &pax_vm_ops; | |
50425a20 | 1567 | + |
da5b3fc8 | 1568 | + ret = insert_vm_struct(current->mm, vma); |
1569 | + if (ret) | |
1570 | + return ret; | |
1571 | + | |
1572 | + ++current->mm->total_vm; | |
1573 | + return 0; | |
50425a20 | 1574 | +} |
1575 | +#endif | |
1576 | + | |
da5b3fc8 | 1577 | +#ifdef CONFIG_PAX_PAGEEXEC |
1578 | +/* | |
1579 | + * PaX: decide what to do with offenders (regs->nip = fault address) | |
1580 | + * | |
1581 | + * returns 1 when task should be killed | |
1582 | + * 2 when patched GOT trampoline was detected | |
1583 | + * 3 when patched PLT trampoline was detected | |
1584 | + * 4 when unpatched PLT trampoline was detected | |
1585 | + * 5 when sigreturn trampoline was detected | |
1586 | + * 6 when rt_sigreturn trampoline was detected | |
1587 | + */ | |
1588 | +static int pax_handle_fetch_fault(struct pt_regs *regs) | |
1589 | +{ | |
50425a20 | 1590 | + |
da5b3fc8 | 1591 | +#if defined(CONFIG_PAX_EMUPLT) || defined(CONFIG_PAX_EMUSIGRT) |
1592 | + int err; | |
50425a20 | 1593 | +#endif |
1594 | + | |
da5b3fc8 | 1595 | +#ifdef CONFIG_PAX_EMUPLT |
1596 | + do { /* PaX: patched GOT emulation */ | |
1597 | + unsigned int blrl; | |
50425a20 | 1598 | + |
da5b3fc8 | 1599 | + err = get_user(blrl, (unsigned int *)regs->nip); |
50425a20 | 1600 | + |
da5b3fc8 | 1601 | + if (!err && blrl == 0x4E800021U) { |
1602 | + unsigned long temp = regs->nip; | |
50425a20 | 1603 | + |
da5b3fc8 | 1604 | + regs->nip = regs->link & 0xFFFFFFFCUL; |
1605 | + regs->link = temp + 4UL; | |
1606 | + return 2; | |
1607 | + } | |
1608 | + } while (0); | |
50425a20 | 1609 | + |
da5b3fc8 | 1610 | + do { /* PaX: patched PLT emulation #1 */ |
1611 | + unsigned int b; | |
50425a20 | 1612 | + |
da5b3fc8 | 1613 | + err = get_user(b, (unsigned int *)regs->nip); |
50425a20 | 1614 | + |
da5b3fc8 | 1615 | + if (!err && (b & 0xFC000003U) == 0x48000000U) { |
1616 | + regs->nip += (((b | 0xFC000000UL) ^ 0x02000000UL) + 0x02000000UL); | |
1617 | + return 3; | |
1618 | + } | |
1619 | + } while (0); | |
8a4b4a5e | 1620 | + |
da5b3fc8 | 1621 | + do { /* PaX: unpatched PLT emulation #1 */ |
1622 | + unsigned int li, b; | |
8a4b4a5e | 1623 | + |
da5b3fc8 | 1624 | + err = get_user(li, (unsigned int *)regs->nip); |
1625 | + err |= get_user(b, (unsigned int *)(regs->nip+4)); | |
50425a20 | 1626 | + |
da5b3fc8 | 1627 | + if (!err && (li & 0xFFFF0000U) == 0x39600000U && (b & 0xFC000003U) == 0x48000000U) { |
1628 | + unsigned int rlwinm, add, li2, addis2, mtctr, li3, addis3, bctr; | |
1629 | + unsigned long addr = b | 0xFC000000UL; | |
50425a20 | 1630 | + |
da5b3fc8 | 1631 | + addr = regs->nip + 4 + ((addr ^ 0x02000000UL) + 0x02000000UL); |
1632 | + err = get_user(rlwinm, (unsigned int *)addr); | |
1633 | + err |= get_user(add, (unsigned int *)(addr+4)); | |
1634 | + err |= get_user(li2, (unsigned int *)(addr+8)); | |
1635 | + err |= get_user(addis2, (unsigned int *)(addr+12)); | |
1636 | + err |= get_user(mtctr, (unsigned int *)(addr+16)); | |
1637 | + err |= get_user(li3, (unsigned int *)(addr+20)); | |
1638 | + err |= get_user(addis3, (unsigned int *)(addr+24)); | |
1639 | + err |= get_user(bctr, (unsigned int *)(addr+28)); | |
50425a20 | 1640 | + |
da5b3fc8 | 1641 | + if (err) |
1642 | + break; | |
50425a20 | 1643 | + |
da5b3fc8 | 1644 | + if (rlwinm == 0x556C083CU && |
1645 | + add == 0x7D6C5A14U && | |
1646 | + (li2 & 0xFFFF0000U) == 0x39800000U && | |
1647 | + (addis2 & 0xFFFF0000U) == 0x3D8C0000U && | |
1648 | + mtctr == 0x7D8903A6U && | |
1649 | + (li3 & 0xFFFF0000U) == 0x39800000U && | |
1650 | + (addis3 & 0xFFFF0000U) == 0x3D8C0000U && | |
1651 | + bctr == 0x4E800420U) | |
1652 | + { | |
1653 | + regs->gpr[PT_R11] = 3 * (((li | 0xFFFF0000UL) ^ 0x00008000UL) + 0x00008000UL); | |
1654 | + regs->gpr[PT_R12] = (((li3 | 0xFFFF0000UL) ^ 0x00008000UL) + 0x00008000UL); | |
1655 | + regs->gpr[PT_R12] += (addis3 & 0xFFFFU) << 16; | |
1656 | + regs->ctr = (((li2 | 0xFFFF0000UL) ^ 0x00008000UL) + 0x00008000UL); | |
1657 | + regs->ctr += (addis2 & 0xFFFFU) << 16; | |
1658 | + regs->nip = regs->ctr; | |
1659 | + return 4; | |
1660 | + } | |
1661 | + } | |
1662 | + } while (0); | |
50425a20 | 1663 | + |
da5b3fc8 | 1664 | +#if 0 |
1665 | + do { /* PaX: unpatched PLT emulation #2 */ | |
1666 | + unsigned int lis, lwzu, b, bctr; | |
8a4b4a5e | 1667 | + |
da5b3fc8 | 1668 | + err = get_user(lis, (unsigned int *)regs->nip); |
1669 | + err |= get_user(lwzu, (unsigned int *)(regs->nip+4)); | |
1670 | + err |= get_user(b, (unsigned int *)(regs->nip+8)); | |
1671 | + err |= get_user(bctr, (unsigned int *)(regs->nip+12)); | |
8a4b4a5e | 1672 | + |
da5b3fc8 | 1673 | + if (err) |
1674 | + break; | |
8a4b4a5e | 1675 | + |
da5b3fc8 | 1676 | + if ((lis & 0xFFFF0000U) == 0x39600000U && |
1677 | + (lwzu & 0xU) == 0xU && | |
1678 | + (b & 0xFC000003U) == 0x48000000U && | |
1679 | + bctr == 0x4E800420U) | |
1680 | + { | |
1681 | + unsigned int addis, addi, rlwinm, add, li2, addis2, mtctr, li3, addis3, bctr; | |
1682 | + unsigned long addr = b | 0xFC000000UL; | |
8a4b4a5e | 1683 | + |
da5b3fc8 | 1684 | + addr = regs->nip + 12 + ((addr ^ 0x02000000UL) + 0x02000000UL); |
4dee9bd5 | 1685 | + err = get_user(addis, (unsigned int *)addr); |
1686 | + err |= get_user(addi, (unsigned int *)(addr+4)); | |
1687 | + err |= get_user(rlwinm, (unsigned int *)(addr+8)); | |
1688 | + err |= get_user(add, (unsigned int *)(addr+12)); | |
1689 | + err |= get_user(li2, (unsigned int *)(addr+16)); | |
1690 | + err |= get_user(addis2, (unsigned int *)(addr+20)); | |
1691 | + err |= get_user(mtctr, (unsigned int *)(addr+24)); | |
1692 | + err |= get_user(li3, (unsigned int *)(addr+28)); | |
1693 | + err |= get_user(addis3, (unsigned int *)(addr+32)); | |
1694 | + err |= get_user(bctr, (unsigned int *)(addr+36)); | |
8a4b4a5e | 1695 | + |
da5b3fc8 | 1696 | + if (err) |
1697 | + break; | |
50425a20 | 1698 | + |
da5b3fc8 | 1699 | + if ((addis & 0xFFFF0000U) == 0x3D6B0000U && |
1700 | + (addi & 0xFFFF0000U) == 0x396B0000U && | |
1701 | + rlwinm == 0x556C083CU && | |
1702 | + add == 0x7D6C5A14U && | |
1703 | + (li2 & 0xFFFF0000U) == 0x39800000U && | |
1704 | + (addis2 & 0xFFFF0000U) == 0x3D8C0000U && | |
1705 | + mtctr == 0x7D8903A6U && | |
1706 | + (li3 & 0xFFFF0000U) == 0x39800000U && | |
1707 | + (addis3 & 0xFFFF0000U) == 0x3D8C0000U && | |
1708 | + bctr == 0x4E800420U) | |
1709 | + { | |
da5b3fc8 | 1710 | + regs->gpr[PT_R11] = 3 * (((li | 0xFFFF0000UL) ^ 0x00008000UL) + 0x00008000UL); |
1711 | + regs->gpr[PT_R12] = (((li3 | 0xFFFF0000UL) ^ 0x00008000UL) + 0x00008000UL); | |
1712 | + regs->gpr[PT_R12] += (addis3 & 0xFFFFU) << 16; | |
1713 | + regs->ctr = (((li2 | 0xFFFF0000UL) ^ 0x00008000UL) + 0x00008000UL); | |
1714 | + regs->ctr += (addis2 & 0xFFFFU) << 16; | |
1715 | + regs->nip = regs->ctr; | |
1716 | + return 4; | |
1717 | + } | |
1718 | + } | |
1719 | + } while (0); | |
8a4b4a5e | 1720 | +#endif |
1721 | + | |
da5b3fc8 | 1722 | + do { /* PaX: unpatched PLT emulation #3 */ |
1723 | + unsigned int li, b; | |
8a4b4a5e | 1724 | + |
da5b3fc8 | 1725 | + err = get_user(li, (unsigned int *)regs->nip); |
1726 | + err |= get_user(b, (unsigned int *)(regs->nip+4)); | |
8a4b4a5e | 1727 | + |
da5b3fc8 | 1728 | + if (!err && (li & 0xFFFF0000U) == 0x39600000U && (b & 0xFC000003U) == 0x48000000U) { |
1729 | + unsigned int addis, lwz, mtctr, bctr; | |
1730 | + unsigned long addr = b | 0xFC000000UL; | |
8a4b4a5e | 1731 | + |
da5b3fc8 | 1732 | + addr = regs->nip + 4 + ((addr ^ 0x02000000UL) + 0x02000000UL); |
1733 | + err = get_user(addis, (unsigned int *)addr); | |
1734 | + err |= get_user(lwz, (unsigned int *)(addr+4)); | |
1735 | + err |= get_user(mtctr, (unsigned int *)(addr+8)); | |
1736 | + err |= get_user(bctr, (unsigned int *)(addr+12)); | |
8a4b4a5e | 1737 | + |
da5b3fc8 | 1738 | + if (err) |
1739 | + break; | |
8a4b4a5e | 1740 | + |
da5b3fc8 | 1741 | + if ((addis & 0xFFFF0000U) == 0x3D6B0000U && |
1742 | + (lwz & 0xFFFF0000U) == 0x816B0000U && | |
1743 | + mtctr == 0x7D6903A6U && | |
1744 | + bctr == 0x4E800420U) | |
1745 | + { | |
1746 | + unsigned int r11; | |
8a4b4a5e | 1747 | + |
da5b3fc8 | 1748 | + addr = (addis << 16) + (((li | 0xFFFF0000UL) ^ 0x00008000UL) + 0x00008000UL); |
1749 | + addr += (((lwz | 0xFFFF0000UL) ^ 0x00008000UL) + 0x00008000UL); | |
8a4b4a5e | 1750 | + |
da5b3fc8 | 1751 | + err = get_user(r11, (unsigned int *)addr); |
1752 | + if (err) | |
1753 | + break; | |
50425a20 | 1754 | + |
da5b3fc8 | 1755 | + regs->gpr[PT_R11] = r11; |
1756 | + regs->ctr = r11; | |
1757 | + regs->nip = r11; | |
1758 | + return 4; | |
1759 | + } | |
1760 | + } | |
1761 | + } while (0); | |
50425a20 | 1762 | +#endif |
1763 | + | |
da5b3fc8 | 1764 | +#ifdef CONFIG_PAX_EMUSIGRT |
1765 | + do { /* PaX: sigreturn emulation */ | |
1766 | + unsigned int li, sc; | |
8a4b4a5e | 1767 | + |
da5b3fc8 | 1768 | + err = get_user(li, (unsigned int *)regs->nip); |
1769 | + err |= get_user(sc, (unsigned int *)(regs->nip+4)); | |
8a4b4a5e | 1770 | + |
da5b3fc8 | 1771 | + if (!err && li == 0x38000000U + __NR_sigreturn && sc == 0x44000002U) { |
1772 | + struct vm_area_struct *vma; | |
1773 | + unsigned long call_syscall; | |
8a4b4a5e | 1774 | + |
da5b3fc8 | 1775 | + down_read(¤t->mm->mmap_sem); |
1776 | + call_syscall = current->mm->call_syscall; | |
1777 | + up_read(¤t->mm->mmap_sem); | |
1778 | + if (likely(call_syscall)) | |
1779 | + goto emulate; | |
8a4b4a5e | 1780 | + |
da5b3fc8 | 1781 | + vma = kmem_cache_zalloc(vm_area_cachep, GFP_KERNEL); |
50425a20 | 1782 | + |
da5b3fc8 | 1783 | + down_write(¤t->mm->mmap_sem); |
1784 | + if (current->mm->call_syscall) { | |
1785 | + call_syscall = current->mm->call_syscall; | |
1786 | + up_write(¤t->mm->mmap_sem); | |
4dee9bd5 | 1787 | + if (vma) |
1788 | + kmem_cache_free(vm_area_cachep, vma); | |
da5b3fc8 | 1789 | + goto emulate; |
1790 | + } | |
50425a20 | 1791 | + |
da5b3fc8 | 1792 | + call_syscall = get_unmapped_area(NULL, 0UL, PAGE_SIZE, 0UL, MAP_PRIVATE); |
1793 | + if (!vma || (call_syscall & ~PAGE_MASK)) { | |
1794 | + up_write(¤t->mm->mmap_sem); | |
4dee9bd5 | 1795 | + if (vma) |
1796 | + kmem_cache_free(vm_area_cachep, vma); | |
da5b3fc8 | 1797 | + return 1; |
1798 | + } | |
50425a20 | 1799 | + |
da5b3fc8 | 1800 | + if (pax_insert_vma(vma, call_syscall)) { |
1801 | + up_write(¤t->mm->mmap_sem); | |
1802 | + kmem_cache_free(vm_area_cachep, vma); | |
1803 | + return 1; | |
1804 | + } | |
8a4b4a5e | 1805 | + |
da5b3fc8 | 1806 | + current->mm->call_syscall = call_syscall; |
1807 | + up_write(¤t->mm->mmap_sem); | |
50425a20 | 1808 | + |
da5b3fc8 | 1809 | +emulate: |
1810 | + regs->gpr[PT_R0] = __NR_sigreturn; | |
1811 | + regs->nip = call_syscall; | |
1812 | + return 5; | |
1813 | + } | |
1814 | + } while (0); | |
50425a20 | 1815 | + |
da5b3fc8 | 1816 | + do { /* PaX: rt_sigreturn emulation */ |
1817 | + unsigned int li, sc; | |
50425a20 | 1818 | + |
da5b3fc8 | 1819 | + err = get_user(li, (unsigned int *)regs->nip); |
1820 | + err |= get_user(sc, (unsigned int *)(regs->nip+4)); | |
50425a20 | 1821 | + |
da5b3fc8 | 1822 | + if (!err && li == 0x38000000U + __NR_rt_sigreturn && sc == 0x44000002U) { |
1823 | + struct vm_area_struct *vma; | |
1824 | + unsigned int call_syscall; | |
50425a20 | 1825 | + |
da5b3fc8 | 1826 | + down_read(¤t->mm->mmap_sem); |
1827 | + call_syscall = current->mm->call_syscall; | |
1828 | + up_read(¤t->mm->mmap_sem); | |
1829 | + if (likely(call_syscall)) | |
1830 | + goto rt_emulate; | |
50425a20 | 1831 | + |
da5b3fc8 | 1832 | + vma = kmem_cache_zalloc(vm_area_cachep, GFP_KERNEL); |
50425a20 | 1833 | + |
da5b3fc8 | 1834 | + down_write(¤t->mm->mmap_sem); |
1835 | + if (current->mm->call_syscall) { | |
1836 | + call_syscall = current->mm->call_syscall; | |
1837 | + up_write(¤t->mm->mmap_sem); | |
4dee9bd5 | 1838 | + if (vma) |
1839 | + kmem_cache_free(vm_area_cachep, vma); | |
da5b3fc8 | 1840 | + goto rt_emulate; |
1841 | + } | |
50425a20 | 1842 | + |
da5b3fc8 | 1843 | + call_syscall = get_unmapped_area(NULL, 0UL, PAGE_SIZE, 0UL, MAP_PRIVATE); |
1844 | + if (!vma || (call_syscall & ~PAGE_MASK)) { | |
1845 | + up_write(¤t->mm->mmap_sem); | |
4dee9bd5 | 1846 | + if (vma) |
1847 | + kmem_cache_free(vm_area_cachep, vma); | |
da5b3fc8 | 1848 | + return 1; |
1849 | + } | |
50425a20 | 1850 | + |
da5b3fc8 | 1851 | + if (pax_insert_vma(vma, call_syscall)) { |
1852 | + up_write(¤t->mm->mmap_sem); | |
1853 | + kmem_cache_free(vm_area_cachep, vma); | |
1854 | + return 1; | |
1855 | + } | |
8a4b4a5e | 1856 | + |
da5b3fc8 | 1857 | + current->mm->call_syscall = call_syscall; |
1858 | + up_write(¤t->mm->mmap_sem); | |
50425a20 | 1859 | + |
da5b3fc8 | 1860 | +rt_emulate: |
1861 | + regs->gpr[PT_R0] = __NR_rt_sigreturn; | |
1862 | + regs->nip = call_syscall; | |
1863 | + return 6; | |
1864 | + } | |
1865 | + } while (0); | |
50425a20 | 1866 | +#endif |
1867 | + | |
da5b3fc8 | 1868 | + return 1; |
1869 | +} | |
50425a20 | 1870 | + |
da5b3fc8 | 1871 | +void pax_report_insns(void *pc, void *sp) |
1872 | +{ | |
1873 | + unsigned long i; | |
50425a20 | 1874 | + |
da5b3fc8 | 1875 | + printk(KERN_ERR "PAX: bytes at PC: "); |
1876 | + for (i = 0; i < 5; i++) { | |
1877 | + unsigned int c; | |
1878 | + if (get_user(c, (unsigned int *)pc+i)) | |
4dee9bd5 | 1879 | + printk(KERN_CONT "???????? "); |
da5b3fc8 | 1880 | + else |
4dee9bd5 | 1881 | + printk(KERN_CONT "%08x ", c); |
50425a20 | 1882 | + } |
da5b3fc8 | 1883 | + printk("\n"); |
1884 | +} | |
1885 | +#endif | |
50425a20 | 1886 | + |
da5b3fc8 | 1887 | /* |
1888 | * Check whether the instruction at regs->nip is a store using | |
1889 | * an update addressing form which will update r1. | |
4dee9bd5 | 1890 | @@ -109,7 +474,7 @@ int do_page_fault(struct pt_regs *regs, |
da5b3fc8 | 1891 | * indicate errors in DSISR but can validly be set in SRR1. |
1892 | */ | |
1893 | if (TRAP(regs) == 0x400) | |
1894 | - error_code &= 0x48200000; | |
1895 | + error_code &= 0x58200000; | |
1896 | else | |
1897 | is_write = error_code & 0x02000000; | |
1898 | #endif /* CONFIG_4xx || CONFIG_BOOKE */ | |
4dee9bd5 | 1899 | @@ -204,15 +569,14 @@ good_area: |
da5b3fc8 | 1900 | pte_t *ptep; |
1901 | pmd_t *pmdp; | |
1902 | ||
1903 | -#if 0 | |
1904 | +#if 1 | |
1905 | /* It would be nice to actually enforce the VM execute | |
1906 | permission on CPUs which can do so, but far too | |
1907 | much stuff in userspace doesn't get the permissions | |
1908 | right, so we let any page be executed for now. */ | |
1909 | if (! (vma->vm_flags & VM_EXEC)) | |
1910 | goto bad_area; | |
1911 | -#endif | |
1912 | - | |
1913 | +#else | |
1914 | /* Since 4xx/Book-E supports per-page execute permission, | |
1915 | * we lazily flush dcache to icache. */ | |
1916 | ptep = NULL; | |
4dee9bd5 | 1917 | @@ -235,6 +599,7 @@ good_area: |
da5b3fc8 | 1918 | pte_unmap_unlock(ptep, ptl); |
1919 | } | |
1920 | #endif | |
73ca38b2 | 1921 | +#endif |
da5b3fc8 | 1922 | /* a read */ |
1923 | } else { | |
1924 | /* protection fault */ | |
4dee9bd5 | 1925 | @@ -278,6 +643,33 @@ bad_area: |
da5b3fc8 | 1926 | |
1927 | /* User mode accesses cause a SIGSEGV */ | |
1928 | if (user_mode(regs)) { | |
73ca38b2 | 1929 | + |
da5b3fc8 | 1930 | +#ifdef CONFIG_PAX_PAGEEXEC |
1931 | + if (mm->pax_flags & MF_PAX_PAGEEXEC) { | |
1932 | + if ((TRAP(regs) == 0x400) && (regs->nip == address)) { | |
1933 | + switch (pax_handle_fetch_fault(regs)) { | |
50425a20 | 1934 | + |
da5b3fc8 | 1935 | +#ifdef CONFIG_PAX_EMUPLT |
1936 | + case 2: | |
1937 | + case 3: | |
1938 | + case 4: | |
1939 | + return 0; | |
50425a20 | 1940 | +#endif |
1941 | + | |
da5b3fc8 | 1942 | +#ifdef CONFIG_PAX_EMUSIGRT |
1943 | + case 5: | |
1944 | + case 6: | |
1945 | + return 0; | |
1946 | +#endif | |
8a4b4a5e | 1947 | + |
da5b3fc8 | 1948 | + } |
8a4b4a5e | 1949 | + |
da5b3fc8 | 1950 | + pax_report_fault(regs, (void *)regs->nip, (void *)regs->gpr[1]); |
b7f09679 | 1951 | + do_group_exit(SIGKILL); |
da5b3fc8 | 1952 | + } |
1953 | + } | |
8a4b4a5e | 1954 | +#endif |
83a957c9 | 1955 | + |
da5b3fc8 | 1956 | _exception(SIGSEGV, regs, code, address); |
1957 | return 0; | |
1958 | } | |
4dee9bd5 | 1959 | diff -urNp linux-2.6.25.4/arch/s390/kernel/module.c linux-2.6.25.4/arch/s390/kernel/module.c |
1960 | --- linux-2.6.25.4/arch/s390/kernel/module.c 2008-05-15 11:00:12.000000000 -0400 | |
1961 | +++ linux-2.6.25.4/arch/s390/kernel/module.c 2008-05-18 13:33:14.000000000 -0400 | |
da5b3fc8 | 1962 | @@ -166,11 +166,11 @@ module_frob_arch_sections(Elf_Ehdr *hdr, |
50425a20 | 1963 | |
da5b3fc8 | 1964 | /* Increase core size by size of got & plt and set start |
1965 | offsets for got and plt. */ | |
1966 | - me->core_size = ALIGN(me->core_size, 4); | |
1967 | - me->arch.got_offset = me->core_size; | |
1968 | - me->core_size += me->arch.got_size; | |
1969 | - me->arch.plt_offset = me->core_size; | |
1970 | - me->core_size += me->arch.plt_size; | |
1971 | + me->core_size_rw = ALIGN(me->core_size_rw, 4); | |
1972 | + me->arch.got_offset = me->core_size_rw; | |
1973 | + me->core_size_rw += me->arch.got_size; | |
1974 | + me->arch.plt_offset = me->core_size_rx; | |
1975 | + me->core_size_rx += me->arch.plt_size; | |
1976 | return 0; | |
1977 | } | |
50425a20 | 1978 | |
da5b3fc8 | 1979 | @@ -256,7 +256,7 @@ apply_rela(Elf_Rela *rela, Elf_Addr base |
1980 | if (info->got_initialized == 0) { | |
1981 | Elf_Addr *gotent; | |
50425a20 | 1982 | |
da5b3fc8 | 1983 | - gotent = me->module_core + me->arch.got_offset + |
1984 | + gotent = me->module_core_rw + me->arch.got_offset + | |
1985 | info->got_offset; | |
1986 | *gotent = val; | |
1987 | info->got_initialized = 1; | |
1988 | @@ -280,7 +280,7 @@ apply_rela(Elf_Rela *rela, Elf_Addr base | |
1989 | else if (r_type == R_390_GOTENT || | |
1990 | r_type == R_390_GOTPLTENT) | |
1991 | *(unsigned int *) loc = | |
1992 | - (val + (Elf_Addr) me->module_core - loc) >> 1; | |
1993 | + (val + (Elf_Addr) me->module_core_rw - loc) >> 1; | |
1994 | else if (r_type == R_390_GOT64 || | |
1995 | r_type == R_390_GOTPLT64) | |
1996 | *(unsigned long *) loc = val; | |
1997 | @@ -294,7 +294,7 @@ apply_rela(Elf_Rela *rela, Elf_Addr base | |
1998 | case R_390_PLTOFF64: /* 16 bit offset from GOT to PLT. */ | |
1999 | if (info->plt_initialized == 0) { | |
2000 | unsigned int *ip; | |
2001 | - ip = me->module_core + me->arch.plt_offset + | |
2002 | + ip = me->module_core_rx + me->arch.plt_offset + | |
2003 | info->plt_offset; | |
2004 | #ifndef CONFIG_64BIT | |
2005 | ip[0] = 0x0d105810; /* basr 1,0; l 1,6(1); br 1 */ | |
2006 | @@ -316,7 +316,7 @@ apply_rela(Elf_Rela *rela, Elf_Addr base | |
2007 | val = me->arch.plt_offset - me->arch.got_offset + | |
2008 | info->plt_offset + rela->r_addend; | |
2009 | else | |
2010 | - val = (Elf_Addr) me->module_core + | |
2011 | + val = (Elf_Addr) me->module_core_rx + | |
2012 | me->arch.plt_offset + info->plt_offset + | |
2013 | rela->r_addend - loc; | |
2014 | if (r_type == R_390_PLT16DBL) | |
2015 | @@ -336,7 +336,7 @@ apply_rela(Elf_Rela *rela, Elf_Addr base | |
2016 | case R_390_GOTOFF32: /* 32 bit offset to GOT. */ | |
2017 | case R_390_GOTOFF64: /* 64 bit offset to GOT. */ | |
2018 | val = val + rela->r_addend - | |
2019 | - ((Elf_Addr) me->module_core + me->arch.got_offset); | |
2020 | + ((Elf_Addr) me->module_core_rw + me->arch.got_offset); | |
2021 | if (r_type == R_390_GOTOFF16) | |
2022 | *(unsigned short *) loc = val; | |
2023 | else if (r_type == R_390_GOTOFF32) | |
2024 | @@ -346,7 +346,7 @@ apply_rela(Elf_Rela *rela, Elf_Addr base | |
2025 | break; | |
2026 | case R_390_GOTPC: /* 32 bit PC relative offset to GOT. */ | |
2027 | case R_390_GOTPCDBL: /* 32 bit PC rel. off. to GOT shifted by 1. */ | |
2028 | - val = (Elf_Addr) me->module_core + me->arch.got_offset + | |
2029 | + val = (Elf_Addr) me->module_core_rw + me->arch.got_offset + | |
2030 | rela->r_addend - loc; | |
2031 | if (r_type == R_390_GOTPC) | |
2032 | *(unsigned int *) loc = val; | |
4dee9bd5 | 2033 | diff -urNp linux-2.6.25.4/arch/sparc/kernel/sys_sparc.c linux-2.6.25.4/arch/sparc/kernel/sys_sparc.c |
2034 | --- linux-2.6.25.4/arch/sparc/kernel/sys_sparc.c 2008-05-15 11:00:12.000000000 -0400 | |
2035 | +++ linux-2.6.25.4/arch/sparc/kernel/sys_sparc.c 2008-05-18 13:33:14.000000000 -0400 | |
da5b3fc8 | 2036 | @@ -57,7 +57,7 @@ unsigned long arch_get_unmapped_area(str |
2037 | if (ARCH_SUN4C_SUN4 && len > 0x20000000) | |
2038 | return -ENOMEM; | |
2039 | if (!addr) | |
2040 | - addr = TASK_UNMAPPED_BASE; | |
2041 | + addr = current->mm->mmap_base; | |
50425a20 | 2042 | |
da5b3fc8 | 2043 | if (flags & MAP_SHARED) |
2044 | addr = COLOUR_ALIGN(addr); | |
4dee9bd5 | 2045 | diff -urNp linux-2.6.25.4/arch/sparc/Makefile linux-2.6.25.4/arch/sparc/Makefile |
2046 | --- linux-2.6.25.4/arch/sparc/Makefile 2008-05-15 11:00:12.000000000 -0400 | |
2047 | +++ linux-2.6.25.4/arch/sparc/Makefile 2008-05-18 13:33:14.000000000 -0400 | |
da5b3fc8 | 2048 | @@ -36,7 +36,7 @@ drivers-$(CONFIG_OPROFILE) += arch/sparc |
2049 | # Renaming is done to avoid confusing pattern matching rules in 2.5.45 (multy-) | |
2050 | INIT_Y := $(patsubst %/, %/built-in.o, $(init-y)) | |
2051 | CORE_Y := $(core-y) | |
2052 | -CORE_Y += kernel/ mm/ fs/ ipc/ security/ crypto/ block/ | |
2053 | +CORE_Y += kernel/ mm/ fs/ ipc/ security/ crypto/ block/ grsecurity/ | |
2054 | CORE_Y := $(patsubst %/, %/built-in.o, $(CORE_Y)) | |
2055 | DRIVERS_Y := $(patsubst %/, %/built-in.o, $(drivers-y)) | |
2056 | NET_Y := $(patsubst %/, %/built-in.o, $(net-y)) | |
4dee9bd5 | 2057 | diff -urNp linux-2.6.25.4/arch/sparc/mm/fault.c linux-2.6.25.4/arch/sparc/mm/fault.c |
2058 | --- linux-2.6.25.4/arch/sparc/mm/fault.c 2008-05-15 11:00:12.000000000 -0400 | |
2059 | +++ linux-2.6.25.4/arch/sparc/mm/fault.c 2008-05-18 13:33:14.000000000 -0400 | |
da5b3fc8 | 2060 | @@ -21,6 +21,10 @@ |
2061 | #include <linux/interrupt.h> | |
2062 | #include <linux/module.h> | |
2063 | #include <linux/kdebug.h> | |
2064 | +#include <linux/slab.h> | |
2065 | +#include <linux/pagemap.h> | |
2066 | +#include <linux/compiler.h> | |
2067 | +#include <linux/binfmts.h> | |
50425a20 | 2068 | |
da5b3fc8 | 2069 | #include <asm/system.h> |
2070 | #include <asm/page.h> | |
4dee9bd5 | 2071 | @@ -216,6 +220,253 @@ static unsigned long compute_si_addr(str |
da5b3fc8 | 2072 | return safe_compute_effective_address(regs, insn); |
2073 | } | |
50425a20 | 2074 | |
2075 | +#ifdef CONFIG_PAX_PAGEEXEC | |
da5b3fc8 | 2076 | +void pax_emuplt_close(struct vm_area_struct *vma) |
2077 | +{ | |
2078 | + vma->vm_mm->call_dl_resolve = 0UL; | |
2079 | +} | |
50425a20 | 2080 | + |
da5b3fc8 | 2081 | +static struct page *pax_emuplt_nopage(struct vm_area_struct *vma, unsigned long address, int *type) |
2082 | +{ | |
2083 | + struct page *page; | |
2084 | + unsigned int *kaddr; | |
50425a20 | 2085 | + |
da5b3fc8 | 2086 | + page = alloc_page(GFP_HIGHUSER); |
2087 | + if (!page) | |
2088 | + return NOPAGE_OOM; | |
50425a20 | 2089 | + |
da5b3fc8 | 2090 | + kaddr = kmap(page); |
2091 | + memset(kaddr, 0, PAGE_SIZE); | |
2092 | + kaddr[0] = 0x9DE3BFA8U; /* save */ | |
2093 | + flush_dcache_page(page); | |
2094 | + kunmap(page); | |
2095 | + if (type) | |
2096 | + *type = VM_FAULT_MAJOR; | |
50425a20 | 2097 | + |
da5b3fc8 | 2098 | + return page; |
2099 | +} | |
8a4b4a5e | 2100 | + |
da5b3fc8 | 2101 | +static struct vm_operations_struct pax_vm_ops = { |
2102 | + .close = pax_emuplt_close, | |
2103 | + .nopage = pax_emuplt_nopage, | |
2104 | +}; | |
50425a20 | 2105 | + |
da5b3fc8 | 2106 | +static int pax_insert_vma(struct vm_area_struct *vma, unsigned long addr) |
2107 | +{ | |
2108 | + int ret; | |
83a957c9 | 2109 | + |
da5b3fc8 | 2110 | + vma->vm_mm = current->mm; |
2111 | + vma->vm_start = addr; | |
2112 | + vma->vm_end = addr + PAGE_SIZE; | |
2113 | + vma->vm_flags = VM_READ | VM_EXEC | VM_MAYREAD | VM_MAYEXEC; | |
2114 | + vma->vm_page_prot = vm_get_page_prot(vma->vm_flags); | |
2115 | + vma->vm_ops = &pax_vm_ops; | |
50425a20 | 2116 | + |
da5b3fc8 | 2117 | + ret = insert_vm_struct(current->mm, vma); |
2118 | + if (ret) | |
2119 | + return ret; | |
50425a20 | 2120 | + |
da5b3fc8 | 2121 | + ++current->mm->total_vm; |
2122 | + return 0; | |
2123 | +} | |
50425a20 | 2124 | + |
da5b3fc8 | 2125 | +/* |
2126 | + * PaX: decide what to do with offenders (regs->pc = fault address) | |
2127 | + * | |
2128 | + * returns 1 when task should be killed | |
2129 | + * 2 when patched PLT trampoline was detected | |
2130 | + * 3 when unpatched PLT trampoline was detected | |
2131 | + */ | |
2132 | +static int pax_handle_fetch_fault(struct pt_regs *regs) | |
2133 | +{ | |
83a957c9 | 2134 | + |
da5b3fc8 | 2135 | +#ifdef CONFIG_PAX_EMUPLT |
2136 | + int err; | |
83a957c9 | 2137 | + |
da5b3fc8 | 2138 | + do { /* PaX: patched PLT emulation #1 */ |
2139 | + unsigned int sethi1, sethi2, jmpl; | |
83a957c9 | 2140 | + |
da5b3fc8 | 2141 | + err = get_user(sethi1, (unsigned int *)regs->pc); |
2142 | + err |= get_user(sethi2, (unsigned int *)(regs->pc+4)); | |
2143 | + err |= get_user(jmpl, (unsigned int *)(regs->pc+8)); | |
83a957c9 | 2144 | + |
da5b3fc8 | 2145 | + if (err) |
2146 | + break; | |
8a4b4a5e | 2147 | + |
da5b3fc8 | 2148 | + if ((sethi1 & 0xFFC00000U) == 0x03000000U && |
2149 | + (sethi2 & 0xFFC00000U) == 0x03000000U && | |
2150 | + (jmpl & 0xFFFFE000U) == 0x81C06000U) | |
2151 | + { | |
2152 | + unsigned int addr; | |
8a4b4a5e | 2153 | + |
da5b3fc8 | 2154 | + regs->u_regs[UREG_G1] = (sethi2 & 0x003FFFFFU) << 10; |
2155 | + addr = regs->u_regs[UREG_G1]; | |
2156 | + addr += (((jmpl | 0xFFFFE000U) ^ 0x00001000U) + 0x00001000U); | |
2157 | + regs->pc = addr; | |
2158 | + regs->npc = addr+4; | |
2159 | + return 2; | |
2160 | + } | |
2161 | + } while (0); | |
8a4b4a5e | 2162 | + |
da5b3fc8 | 2163 | + { /* PaX: patched PLT emulation #2 */ |
2164 | + unsigned int ba; | |
50425a20 | 2165 | + |
da5b3fc8 | 2166 | + err = get_user(ba, (unsigned int *)regs->pc); |
8a4b4a5e | 2167 | + |
da5b3fc8 | 2168 | + if (!err && (ba & 0xFFC00000U) == 0x30800000U) { |
2169 | + unsigned int addr; | |
8a4b4a5e | 2170 | + |
da5b3fc8 | 2171 | + addr = regs->pc + ((((ba | 0xFFC00000U) ^ 0x00200000U) + 0x00200000U) << 2); |
2172 | + regs->pc = addr; | |
2173 | + regs->npc = addr+4; | |
2174 | + return 2; | |
2175 | + } | |
50425a20 | 2176 | + } |
8a4b4a5e | 2177 | + |
da5b3fc8 | 2178 | + do { /* PaX: patched PLT emulation #3 */ |
2179 | + unsigned int sethi, jmpl, nop; | |
8a4b4a5e | 2180 | + |
da5b3fc8 | 2181 | + err = get_user(sethi, (unsigned int *)regs->pc); |
2182 | + err |= get_user(jmpl, (unsigned int *)(regs->pc+4)); | |
2183 | + err |= get_user(nop, (unsigned int *)(regs->pc+8)); | |
50425a20 | 2184 | + |
da5b3fc8 | 2185 | + if (err) |
2186 | + break; | |
50425a20 | 2187 | + |
da5b3fc8 | 2188 | + if ((sethi & 0xFFC00000U) == 0x03000000U && |
2189 | + (jmpl & 0xFFFFE000U) == 0x81C06000U && | |
2190 | + nop == 0x01000000U) | |
2191 | + { | |
2192 | + unsigned int addr; | |
50425a20 | 2193 | + |
da5b3fc8 | 2194 | + addr = (sethi & 0x003FFFFFU) << 10; |
2195 | + regs->u_regs[UREG_G1] = addr; | |
2196 | + addr += (((jmpl | 0xFFFFE000U) ^ 0x00001000U) + 0x00001000U); | |
2197 | + regs->pc = addr; | |
2198 | + regs->npc = addr+4; | |
2199 | + return 2; | |
2200 | + } | |
2201 | + } while (0); | |
50425a20 | 2202 | + |
da5b3fc8 | 2203 | + do { /* PaX: unpatched PLT emulation step 1 */ |
2204 | + unsigned int sethi, ba, nop; | |
50425a20 | 2205 | + |
da5b3fc8 | 2206 | + err = get_user(sethi, (unsigned int *)regs->pc); |
2207 | + err |= get_user(ba, (unsigned int *)(regs->pc+4)); | |
2208 | + err |= get_user(nop, (unsigned int *)(regs->pc+8)); | |
2209 | + | |
2210 | + if (err) | |
2211 | + break; | |
2212 | + | |
2213 | + if ((sethi & 0xFFC00000U) == 0x03000000U && | |
2214 | + ((ba & 0xFFC00000U) == 0x30800000U || (ba & 0xFFF80000U) == 0x30680000U) && | |
2215 | + nop == 0x01000000U) | |
2216 | + { | |
2217 | + unsigned int addr, save, call; | |
2218 | + | |
2219 | + if ((ba & 0xFFC00000U) == 0x30800000U) | |
2220 | + addr = regs->pc + 4 + ((((ba | 0xFFC00000U) ^ 0x00200000U) + 0x00200000U) << 2); | |
2221 | + else | |
2222 | + addr = regs->pc + 4 + ((((ba | 0xFFF80000U) ^ 0x00040000U) + 0x00040000U) << 2); | |
2223 | + | |
2224 | + err = get_user(save, (unsigned int *)addr); | |
2225 | + err |= get_user(call, (unsigned int *)(addr+4)); | |
2226 | + err |= get_user(nop, (unsigned int *)(addr+8)); | |
2227 | + if (err) | |
2228 | + break; | |
2229 | + | |
2230 | + if (save == 0x9DE3BFA8U && | |
2231 | + (call & 0xC0000000U) == 0x40000000U && | |
2232 | + nop == 0x01000000U) | |
2233 | + { | |
2234 | + struct vm_area_struct *vma; | |
2235 | + unsigned long call_dl_resolve; | |
2236 | + | |
2237 | + down_read(¤t->mm->mmap_sem); | |
2238 | + call_dl_resolve = current->mm->call_dl_resolve; | |
2239 | + up_read(¤t->mm->mmap_sem); | |
2240 | + if (likely(call_dl_resolve)) | |
2241 | + goto emulate; | |
2242 | + | |
2243 | + vma = kmem_cache_zalloc(vm_area_cachep, GFP_KERNEL); | |
2244 | + | |
2245 | + down_write(¤t->mm->mmap_sem); | |
2246 | + if (current->mm->call_dl_resolve) { | |
2247 | + call_dl_resolve = current->mm->call_dl_resolve; | |
2248 | + up_write(¤t->mm->mmap_sem); | |
4dee9bd5 | 2249 | + if (vma) |
2250 | + kmem_cache_free(vm_area_cachep, vma); | |
da5b3fc8 | 2251 | + goto emulate; |
2252 | + } | |
2253 | + | |
2254 | + call_dl_resolve = get_unmapped_area(NULL, 0UL, PAGE_SIZE, 0UL, MAP_PRIVATE); | |
2255 | + if (!vma || (call_dl_resolve & ~PAGE_MASK)) { | |
2256 | + up_write(¤t->mm->mmap_sem); | |
4dee9bd5 | 2257 | + if (vma) |
2258 | + kmem_cache_free(vm_area_cachep, vma); | |
da5b3fc8 | 2259 | + return 1; |
2260 | + } | |
2261 | + | |
2262 | + if (pax_insert_vma(vma, call_dl_resolve)) { | |
2263 | + up_write(¤t->mm->mmap_sem); | |
2264 | + kmem_cache_free(vm_area_cachep, vma); | |
2265 | + return 1; | |
2266 | + } | |
2267 | + | |
2268 | + current->mm->call_dl_resolve = call_dl_resolve; | |
2269 | + up_write(¤t->mm->mmap_sem); | |
2270 | + | |
2271 | +emulate: | |
2272 | + regs->u_regs[UREG_G1] = (sethi & 0x003FFFFFU) << 10; | |
2273 | + regs->pc = call_dl_resolve; | |
2274 | + regs->npc = addr+4; | |
2275 | + return 3; | |
2276 | + } | |
2277 | + } | |
2278 | + } while (0); | |
2279 | + | |
2280 | + do { /* PaX: unpatched PLT emulation step 2 */ | |
2281 | + unsigned int save, call, nop; | |
2282 | + | |
2283 | + err = get_user(save, (unsigned int *)(regs->pc-4)); | |
2284 | + err |= get_user(call, (unsigned int *)regs->pc); | |
2285 | + err |= get_user(nop, (unsigned int *)(regs->pc+4)); | |
2286 | + if (err) | |
2287 | + break; | |
2288 | + | |
2289 | + if (save == 0x9DE3BFA8U && | |
2290 | + (call & 0xC0000000U) == 0x40000000U && | |
2291 | + nop == 0x01000000U) | |
2292 | + { | |
2293 | + unsigned int dl_resolve = regs->pc + ((((call | 0xC0000000U) ^ 0x20000000U) + 0x20000000U) << 2); | |
2294 | + | |
2295 | + regs->u_regs[UREG_RETPC] = regs->pc; | |
2296 | + regs->pc = dl_resolve; | |
2297 | + regs->npc = dl_resolve+4; | |
2298 | + return 3; | |
2299 | + } | |
2300 | + } while (0); | |
50425a20 | 2301 | +#endif |
2302 | + | |
da5b3fc8 | 2303 | + return 1; |
2304 | +} | |
2305 | + | |
2306 | +void pax_report_insns(void *pc, void *sp) | |
2307 | +{ | |
2308 | + unsigned long i; | |
2309 | + | |
2310 | + printk(KERN_ERR "PAX: bytes at PC: "); | |
2311 | + for (i = 0; i < 5; i++) { | |
2312 | + unsigned int c; | |
2313 | + if (get_user(c, (unsigned int *)pc+i)) | |
4dee9bd5 | 2314 | + printk(KERN_CONT "???????? "); |
da5b3fc8 | 2315 | + else |
4dee9bd5 | 2316 | + printk(KERN_CONT "%08x ", c); |
50425a20 | 2317 | + } |
da5b3fc8 | 2318 | + printk("\n"); |
2319 | +} | |
2320 | +#endif | |
50425a20 | 2321 | + |
da5b3fc8 | 2322 | asmlinkage void do_sparc_fault(struct pt_regs *regs, int text_fault, int write, |
2323 | unsigned long address) | |
2324 | { | |
4dee9bd5 | 2325 | @@ -280,6 +531,24 @@ good_area: |
da5b3fc8 | 2326 | if(!(vma->vm_flags & VM_WRITE)) |
2327 | goto bad_area; | |
2328 | } else { | |
50425a20 | 2329 | + |
da5b3fc8 | 2330 | +#ifdef CONFIG_PAX_PAGEEXEC |
2331 | + if ((mm->pax_flags & MF_PAX_PAGEEXEC) && text_fault && !(vma->vm_flags & VM_EXEC)) { | |
2332 | + up_read(&mm->mmap_sem); | |
2333 | + switch (pax_handle_fetch_fault(regs)) { | |
50425a20 | 2334 | + |
da5b3fc8 | 2335 | +#ifdef CONFIG_PAX_EMUPLT |
2336 | + case 2: | |
2337 | + case 3: | |
2338 | + return; | |
50425a20 | 2339 | +#endif |
2340 | + | |
da5b3fc8 | 2341 | + } |
2342 | + pax_report_fault(regs, (void *)regs->pc, (void *)regs->u_regs[UREG_FP]); | |
b7f09679 | 2343 | + do_group_exit(SIGKILL); |
da5b3fc8 | 2344 | + } |
2345 | +#endif | |
2346 | + | |
2347 | /* Allow reads even for write-only mappings */ | |
2348 | if(!(vma->vm_flags & (VM_READ | VM_EXEC))) | |
2349 | goto bad_area; | |
4dee9bd5 | 2350 | diff -urNp linux-2.6.25.4/arch/sparc/mm/init.c linux-2.6.25.4/arch/sparc/mm/init.c |
2351 | --- linux-2.6.25.4/arch/sparc/mm/init.c 2008-05-15 11:00:12.000000000 -0400 | |
2352 | +++ linux-2.6.25.4/arch/sparc/mm/init.c 2008-05-18 13:33:14.000000000 -0400 | |
6778dfc1 | 2353 | @@ -311,6 +311,9 @@ extern void device_scan(void); |
2354 | pgprot_t PAGE_SHARED __read_mostly; | |
2355 | EXPORT_SYMBOL(PAGE_SHARED); | |
2356 | ||
2357 | +pgprot_t PAGE_SHARED_NOEXEC __read_mostly; | |
2358 | +EXPORT_SYMBOL(PAGE_SHARED_NOEXEC); | |
2359 | + | |
2360 | void __init paging_init(void) | |
2361 | { | |
2362 | switch(sparc_cpu_model) { | |
da5b3fc8 | 2363 | @@ -336,17 +336,17 @@ void __init paging_init(void) |
8a4b4a5e | 2364 | |
da5b3fc8 | 2365 | /* Initialize the protection map with non-constant, MMU dependent values. */ |
2366 | protection_map[0] = PAGE_NONE; | |
2367 | - protection_map[1] = PAGE_READONLY; | |
2368 | - protection_map[2] = PAGE_COPY; | |
2369 | - protection_map[3] = PAGE_COPY; | |
2370 | + protection_map[1] = PAGE_READONLY_NOEXEC; | |
2371 | + protection_map[2] = PAGE_COPY_NOEXEC; | |
2372 | + protection_map[3] = PAGE_COPY_NOEXEC; | |
2373 | protection_map[4] = PAGE_READONLY; | |
2374 | protection_map[5] = PAGE_READONLY; | |
2375 | protection_map[6] = PAGE_COPY; | |
2376 | protection_map[7] = PAGE_COPY; | |
2377 | protection_map[8] = PAGE_NONE; | |
2378 | - protection_map[9] = PAGE_READONLY; | |
2379 | - protection_map[10] = PAGE_SHARED; | |
2380 | - protection_map[11] = PAGE_SHARED; | |
2381 | + protection_map[9] = PAGE_READONLY_NOEXEC; | |
2382 | + protection_map[10] = PAGE_SHARED_NOEXEC; | |
2383 | + protection_map[11] = PAGE_SHARED_NOEXEC; | |
2384 | protection_map[12] = PAGE_READONLY; | |
2385 | protection_map[13] = PAGE_READONLY; | |
2386 | protection_map[14] = PAGE_SHARED; | |
4dee9bd5 | 2387 | diff -urNp linux-2.6.25.4/arch/sparc/mm/srmmu.c linux-2.6.25.4/arch/sparc/mm/srmmu.c |
2388 | --- linux-2.6.25.4/arch/sparc/mm/srmmu.c 2008-05-15 11:00:12.000000000 -0400 | |
2389 | +++ linux-2.6.25.4/arch/sparc/mm/srmmu.c 2008-05-18 13:33:14.000000000 -0400 | |
2390 | @@ -2160,6 +2160,13 @@ void __init ld_mmu_srmmu(void) | |
da5b3fc8 | 2391 | PAGE_SHARED = pgprot_val(SRMMU_PAGE_SHARED); |
2392 | BTFIXUPSET_INT(page_copy, pgprot_val(SRMMU_PAGE_COPY)); | |
2393 | BTFIXUPSET_INT(page_readonly, pgprot_val(SRMMU_PAGE_RDONLY)); | |
50425a20 | 2394 | + |
da5b3fc8 | 2395 | +#ifdef CONFIG_PAX_PAGEEXEC |
2396 | + PAGE_SHARED_NOEXEC = pgprot_val(SRMMU_PAGE_SHARED_NOEXEC); | |
2397 | + BTFIXUPSET_INT(page_copy_noexec, pgprot_val(SRMMU_PAGE_COPY_NOEXEC)); | |
2398 | + BTFIXUPSET_INT(page_readonly_noexec, pgprot_val(SRMMU_PAGE_RDONLY_NOEXEC)); | |
2399 | +#endif | |
50425a20 | 2400 | + |
da5b3fc8 | 2401 | BTFIXUPSET_INT(page_kernel, pgprot_val(SRMMU_PAGE_KERNEL)); |
2402 | page_kernel = pgprot_val(SRMMU_PAGE_KERNEL); | |
50425a20 | 2403 | |
4dee9bd5 | 2404 | diff -urNp linux-2.6.25.4/arch/sparc64/kernel/Makefile linux-2.6.25.4/arch/sparc64/kernel/Makefile |
2405 | --- linux-2.6.25.4/arch/sparc64/kernel/Makefile 2008-05-15 11:00:12.000000000 -0400 | |
2406 | +++ linux-2.6.25.4/arch/sparc64/kernel/Makefile 2008-05-18 13:33:14.000000000 -0400 | |
7bcbf78a | 2407 | @@ -3,7 +3,7 @@ |
2408 | # | |
2409 | ||
2410 | EXTRA_AFLAGS := -ansi | |
2411 | -EXTRA_CFLAGS := -Werror | |
2412 | +#EXTRA_CFLAGS := -Werror | |
2413 | ||
2414 | extra-y := head.o init_task.o vmlinux.lds | |
2415 | ||
4dee9bd5 | 2416 | diff -urNp linux-2.6.25.4/arch/sparc64/kernel/sys_sparc.c linux-2.6.25.4/arch/sparc64/kernel/sys_sparc.c |
2417 | --- linux-2.6.25.4/arch/sparc64/kernel/sys_sparc.c 2008-05-15 11:00:12.000000000 -0400 | |
2418 | +++ linux-2.6.25.4/arch/sparc64/kernel/sys_sparc.c 2008-05-18 13:33:14.000000000 -0400 | |
2419 | @@ -124,7 +124,7 @@ unsigned long arch_get_unmapped_area(str | |
da5b3fc8 | 2420 | /* We do not accept a shared mapping if it would violate |
2421 | * cache aliasing constraints. | |
2422 | */ | |
2423 | - if ((flags & MAP_SHARED) && | |
2424 | + if ((filp || (flags & MAP_SHARED)) && | |
2425 | ((addr - (pgoff << PAGE_SHIFT)) & (SHMLBA - 1))) | |
2426 | return -EINVAL; | |
2427 | return addr; | |
4dee9bd5 | 2428 | @@ -139,6 +139,10 @@ unsigned long arch_get_unmapped_area(str |
da5b3fc8 | 2429 | if (filp || (flags & MAP_SHARED)) |
2430 | do_color_align = 1; | |
50425a20 | 2431 | |
da5b3fc8 | 2432 | +#ifdef CONFIG_PAX_RANDMMAP |
2433 | + if (!(mm->pax_flags & MF_PAX_RANDMMAP) || !filp) | |
2434 | +#endif | |
2435 | + | |
2436 | if (addr) { | |
2437 | if (do_color_align) | |
2438 | addr = COLOUR_ALIGN(addr, pgoff); | |
4dee9bd5 | 2439 | @@ -152,9 +156,9 @@ unsigned long arch_get_unmapped_area(str |
da5b3fc8 | 2440 | } |
50425a20 | 2441 | |
da5b3fc8 | 2442 | if (len > mm->cached_hole_size) { |
2443 | - start_addr = addr = mm->free_area_cache; | |
2444 | + start_addr = addr = mm->free_area_cache; | |
2445 | } else { | |
2446 | - start_addr = addr = TASK_UNMAPPED_BASE; | |
2447 | + start_addr = addr = mm->mmap_base; | |
2448 | mm->cached_hole_size = 0; | |
2449 | } | |
50425a20 | 2450 | |
4dee9bd5 | 2451 | @@ -174,8 +178,8 @@ full_search: |
da5b3fc8 | 2452 | vma = find_vma(mm, VA_EXCLUDE_END); |
2453 | } | |
2454 | if (unlikely(task_size < addr)) { | |
2455 | - if (start_addr != TASK_UNMAPPED_BASE) { | |
2456 | - start_addr = addr = TASK_UNMAPPED_BASE; | |
2457 | + if (start_addr != mm->mmap_base) { | |
2458 | + start_addr = addr = mm->mmap_base; | |
2459 | mm->cached_hole_size = 0; | |
2460 | goto full_search; | |
2461 | } | |
4dee9bd5 | 2462 | @@ -215,7 +219,7 @@ arch_get_unmapped_area_topdown(struct fi |
da5b3fc8 | 2463 | /* We do not accept a shared mapping if it would violate |
2464 | * cache aliasing constraints. | |
2465 | */ | |
2466 | - if ((flags & MAP_SHARED) && | |
2467 | + if ((filp || (flags & MAP_SHARED)) && | |
2468 | ((addr - (pgoff << PAGE_SHIFT)) & (SHMLBA - 1))) | |
2469 | return -EINVAL; | |
2470 | return addr; | |
4dee9bd5 | 2471 | @@ -378,6 +382,12 @@ void arch_pick_mmap_layout(struct mm_str |
da5b3fc8 | 2472 | current->signal->rlim[RLIMIT_STACK].rlim_cur == RLIM_INFINITY || |
2473 | sysctl_legacy_va_layout) { | |
2474 | mm->mmap_base = TASK_UNMAPPED_BASE + random_factor; | |
50425a20 | 2475 | + |
da5b3fc8 | 2476 | +#ifdef CONFIG_PAX_RANDMMAP |
2477 | + if (mm->pax_flags & MF_PAX_RANDMMAP) | |
2478 | + mm->mmap_base += mm->delta_mmap; | |
50425a20 | 2479 | +#endif |
2480 | + | |
da5b3fc8 | 2481 | mm->get_unmapped_area = arch_get_unmapped_area; |
2482 | mm->unmap_area = arch_unmap_area; | |
2483 | } else { | |
4dee9bd5 | 2484 | @@ -392,6 +402,12 @@ void arch_pick_mmap_layout(struct mm_str |
da5b3fc8 | 2485 | gap = (task_size / 6 * 5); |
2486 | ||
2487 | mm->mmap_base = PAGE_ALIGN(task_size - gap - random_factor); | |
50425a20 | 2488 | + |
da5b3fc8 | 2489 | +#ifdef CONFIG_PAX_RANDMMAP |
2490 | + if (mm->pax_flags & MF_PAX_RANDMMAP) | |
2491 | + mm->mmap_base -= mm->delta_mmap + mm->delta_stack; | |
50425a20 | 2492 | +#endif |
2493 | + | |
da5b3fc8 | 2494 | mm->get_unmapped_area = arch_get_unmapped_area_topdown; |
2495 | mm->unmap_area = arch_unmap_area_topdown; | |
2496 | } | |
4dee9bd5 | 2497 | diff -urNp linux-2.6.25.4/arch/sparc64/mm/fault.c linux-2.6.25.4/arch/sparc64/mm/fault.c |
2498 | --- linux-2.6.25.4/arch/sparc64/mm/fault.c 2008-05-15 11:00:12.000000000 -0400 | |
2499 | +++ linux-2.6.25.4/arch/sparc64/mm/fault.c 2008-05-18 13:33:14.000000000 -0400 | |
da5b3fc8 | 2500 | @@ -20,6 +20,10 @@ |
2501 | #include <linux/kprobes.h> | |
2502 | #include <linux/kallsyms.h> | |
2503 | #include <linux/kdebug.h> | |
2504 | +#include <linux/slab.h> | |
2505 | +#include <linux/pagemap.h> | |
2506 | +#include <linux/compiler.h> | |
2507 | +#include <linux/binfmts.h> | |
2508 | ||
2509 | #include <asm/page.h> | |
2510 | #include <asm/pgtable.h> | |
4dee9bd5 | 2511 | @@ -262,6 +266,370 @@ cannot_handle: |
da5b3fc8 | 2512 | unhandled_fault (address, current, regs); |
2513 | } | |
2514 | ||
2515 | +#ifdef CONFIG_PAX_PAGEEXEC | |
2516 | +#ifdef CONFIG_PAX_EMUPLT | |
2517 | +static void pax_emuplt_close(struct vm_area_struct *vma) | |
2518 | +{ | |
2519 | + vma->vm_mm->call_dl_resolve = 0UL; | |
2520 | +} | |
50425a20 | 2521 | + |
da5b3fc8 | 2522 | +static struct page *pax_emuplt_nopage(struct vm_area_struct *vma, unsigned long address, int *type) |
2523 | +{ | |
2524 | + struct page *page; | |
2525 | + unsigned int *kaddr; | |
50425a20 | 2526 | + |
da5b3fc8 | 2527 | + page = alloc_page(GFP_HIGHUSER); |
2528 | + if (!page) | |
2529 | + return NOPAGE_OOM; | |
50425a20 | 2530 | + |
da5b3fc8 | 2531 | + kaddr = kmap(page); |
2532 | + memset(kaddr, 0, PAGE_SIZE); | |
2533 | + kaddr[0] = 0x9DE3BFA8U; /* save */ | |
2534 | + flush_dcache_page(page); | |
2535 | + kunmap(page); | |
2536 | + if (type) | |
2537 | + *type = VM_FAULT_MAJOR; | |
2538 | + return page; | |
2539 | +} | |
50425a20 | 2540 | + |
da5b3fc8 | 2541 | +static struct vm_operations_struct pax_vm_ops = { |
2542 | + .close = pax_emuplt_close, | |
2543 | + .nopage = pax_emuplt_nopage, | |
2544 | +}; | |
50425a20 | 2545 | + |
da5b3fc8 | 2546 | +static int pax_insert_vma(struct vm_area_struct *vma, unsigned long addr) |
2547 | +{ | |
2548 | + int ret; | |
50425a20 | 2549 | + |
da5b3fc8 | 2550 | + vma->vm_mm = current->mm; |
2551 | + vma->vm_start = addr; | |
2552 | + vma->vm_end = addr + PAGE_SIZE; | |
2553 | + vma->vm_flags = VM_READ | VM_EXEC | VM_MAYREAD | VM_MAYEXEC; | |
2554 | + vma->vm_page_prot = vm_get_page_prot(vma->vm_flags); | |
2555 | + vma->vm_ops = &pax_vm_ops; | |
50425a20 | 2556 | + |
da5b3fc8 | 2557 | + ret = insert_vm_struct(current->mm, vma); |
2558 | + if (ret) | |
2559 | + return ret; | |
2560 | + | |
2561 | + ++current->mm->total_vm; | |
2562 | + return 0; | |
2563 | +} | |
50425a20 | 2564 | +#endif |
2565 | + | |
da5b3fc8 | 2566 | +/* |
2567 | + * PaX: decide what to do with offenders (regs->tpc = fault address) | |
2568 | + * | |
2569 | + * returns 1 when task should be killed | |
2570 | + * 2 when patched PLT trampoline was detected | |
2571 | + * 3 when unpatched PLT trampoline was detected | |
2572 | + */ | |
2573 | +static int pax_handle_fetch_fault(struct pt_regs *regs) | |
2574 | +{ | |
50425a20 | 2575 | + |
da5b3fc8 | 2576 | +#ifdef CONFIG_PAX_EMUPLT |
2577 | + int err; | |
50425a20 | 2578 | + |
da5b3fc8 | 2579 | + do { /* PaX: patched PLT emulation #1 */ |
2580 | + unsigned int sethi1, sethi2, jmpl; | |
50425a20 | 2581 | + |
da5b3fc8 | 2582 | + err = get_user(sethi1, (unsigned int *)regs->tpc); |
2583 | + err |= get_user(sethi2, (unsigned int *)(regs->tpc+4)); | |
2584 | + err |= get_user(jmpl, (unsigned int *)(regs->tpc+8)); | |
50425a20 | 2585 | + |
da5b3fc8 | 2586 | + if (err) |
2587 | + break; | |
50425a20 | 2588 | + |
da5b3fc8 | 2589 | + if ((sethi1 & 0xFFC00000U) == 0x03000000U && |
2590 | + (sethi2 & 0xFFC00000U) == 0x03000000U && | |
2591 | + (jmpl & 0xFFFFE000U) == 0x81C06000U) | |
2592 | + { | |
2593 | + unsigned long addr; | |
50425a20 | 2594 | + |
da5b3fc8 | 2595 | + regs->u_regs[UREG_G1] = (sethi2 & 0x003FFFFFU) << 10; |
2596 | + addr = regs->u_regs[UREG_G1]; | |
2597 | + addr += (((jmpl | 0xFFFFFFFFFFFFE000UL) ^ 0x00001000UL) + 0x00001000UL); | |
2598 | + regs->tpc = addr; | |
2599 | + regs->tnpc = addr+4; | |
2600 | + return 2; | |
2601 | + } | |
2602 | + } while (0); | |
50425a20 | 2603 | + |
da5b3fc8 | 2604 | + { /* PaX: patched PLT emulation #2 */ |
2605 | + unsigned int ba; | |
50425a20 | 2606 | + |
da5b3fc8 | 2607 | + err = get_user(ba, (unsigned int *)regs->tpc); |
50425a20 | 2608 | + |
da5b3fc8 | 2609 | + if (!err && (ba & 0xFFC00000U) == 0x30800000U) { |
2610 | + unsigned long addr; | |
50425a20 | 2611 | + |
da5b3fc8 | 2612 | + addr = regs->tpc + ((((ba | 0xFFFFFFFFFFC00000UL) ^ 0x00200000UL) + 0x00200000UL) << 2); |
2613 | + regs->tpc = addr; | |
2614 | + regs->tnpc = addr+4; | |
2615 | + return 2; | |
2616 | + } | |
2617 | + } | |
50425a20 | 2618 | + |
da5b3fc8 | 2619 | + do { /* PaX: patched PLT emulation #3 */ |
2620 | + unsigned int sethi, jmpl, nop; | |
50425a20 | 2621 | + |
da5b3fc8 | 2622 | + err = get_user(sethi, (unsigned int *)regs->tpc); |
2623 | + err |= get_user(jmpl, (unsigned int *)(regs->tpc+4)); | |
2624 | + err |= get_user(nop, (unsigned int *)(regs->tpc+8)); | |
50425a20 | 2625 | + |
da5b3fc8 | 2626 | + if (err) |
2627 | + break; | |
50425a20 | 2628 | + |
da5b3fc8 | 2629 | + if ((sethi & 0xFFC00000U) == 0x03000000U && |
2630 | + (jmpl & 0xFFFFE000U) == 0x81C06000U && | |
2631 | + nop == 0x01000000U) | |
2632 | + { | |
2633 | + unsigned long addr; | |
50425a20 | 2634 | + |
da5b3fc8 | 2635 | + addr = (sethi & 0x003FFFFFU) << 10; |
2636 | + regs->u_regs[UREG_G1] = addr; | |
2637 | + addr += (((jmpl | 0xFFFFFFFFFFFFE000UL) ^ 0x00001000UL) + 0x00001000UL); | |
2638 | + regs->tpc = addr; | |
2639 | + regs->tnpc = addr+4; | |
2640 | + return 2; | |
2641 | + } | |
2642 | + } while (0); | |
8a4b4a5e | 2643 | + |
da5b3fc8 | 2644 | + do { /* PaX: patched PLT emulation #4 */ |
2645 | + unsigned int mov1, call, mov2; | |
2646 | + | |
2647 | + err = get_user(mov1, (unsigned int *)regs->tpc); | |
2648 | + err |= get_user(call, (unsigned int *)(regs->tpc+4)); | |
2649 | + err |= get_user(mov2, (unsigned int *)(regs->tpc+8)); | |
2650 | + | |
2651 | + if (err) | |
2652 | + break; | |
2653 | + | |
2654 | + if (mov1 == 0x8210000FU && | |
2655 | + (call & 0xC0000000U) == 0x40000000U && | |
2656 | + mov2 == 0x9E100001U) | |
2657 | + { | |
2658 | + unsigned long addr; | |
2659 | + | |
2660 | + regs->u_regs[UREG_G1] = regs->u_regs[UREG_RETPC]; | |
2661 | + addr = regs->tpc + 4 + ((((call | 0xFFFFFFFFC0000000UL) ^ 0x20000000UL) + 0x20000000UL) << 2); | |
2662 | + regs->tpc = addr; | |
2663 | + regs->tnpc = addr+4; | |
2664 | + return 2; | |
2665 | + } | |
2666 | + } while (0); | |
2667 | + | |
2668 | + do { /* PaX: patched PLT emulation #5 */ | |
2669 | + unsigned int sethi1, sethi2, or1, or2, sllx, jmpl, nop; | |
2670 | + | |
2671 | + err = get_user(sethi1, (unsigned int *)regs->tpc); | |
2672 | + err |= get_user(sethi2, (unsigned int *)(regs->tpc+4)); | |
2673 | + err |= get_user(or1, (unsigned int *)(regs->tpc+8)); | |
2674 | + err |= get_user(or2, (unsigned int *)(regs->tpc+12)); | |
2675 | + err |= get_user(sllx, (unsigned int *)(regs->tpc+16)); | |
2676 | + err |= get_user(jmpl, (unsigned int *)(regs->tpc+20)); | |
2677 | + err |= get_user(nop, (unsigned int *)(regs->tpc+24)); | |
2678 | + | |
2679 | + if (err) | |
2680 | + break; | |
2681 | + | |
2682 | + if ((sethi1 & 0xFFC00000U) == 0x03000000U && | |
2683 | + (sethi2 & 0xFFC00000U) == 0x0B000000U && | |
2684 | + (or1 & 0xFFFFE000U) == 0x82106000U && | |
2685 | + (or2 & 0xFFFFE000U) == 0x8A116000U && | |
2686 | + sllx == 0x83287020 && | |
2687 | + jmpl == 0x81C04005U && | |
2688 | + nop == 0x01000000U) | |
2689 | + { | |
2690 | + unsigned long addr; | |
2691 | + | |
2692 | + regs->u_regs[UREG_G1] = ((sethi1 & 0x003FFFFFU) << 10) | (or1 & 0x000003FFU); | |
2693 | + regs->u_regs[UREG_G1] <<= 32; | |
2694 | + regs->u_regs[UREG_G5] = ((sethi2 & 0x003FFFFFU) << 10) | (or2 & 0x000003FFU); | |
2695 | + addr = regs->u_regs[UREG_G1] + regs->u_regs[UREG_G5]; | |
2696 | + regs->tpc = addr; | |
2697 | + regs->tnpc = addr+4; | |
2698 | + return 2; | |
2699 | + } | |
2700 | + } while (0); | |
2701 | + | |
2702 | + do { /* PaX: patched PLT emulation #6 */ | |
2703 | + unsigned int sethi1, sethi2, sllx, or, jmpl, nop; | |
2704 | + | |
2705 | + err = get_user(sethi1, (unsigned int *)regs->tpc); | |
2706 | + err |= get_user(sethi2, (unsigned int *)(regs->tpc+4)); | |
2707 | + err |= get_user(sllx, (unsigned int *)(regs->tpc+8)); | |
2708 | + err |= get_user(or, (unsigned int *)(regs->tpc+12)); | |
2709 | + err |= get_user(jmpl, (unsigned int *)(regs->tpc+16)); | |
2710 | + err |= get_user(nop, (unsigned int *)(regs->tpc+20)); | |
2711 | + | |
2712 | + if (err) | |
2713 | + break; | |
2714 | + | |
2715 | + if ((sethi1 & 0xFFC00000U) == 0x03000000U && | |
2716 | + (sethi2 & 0xFFC00000U) == 0x0B000000U && | |
2717 | + sllx == 0x83287020 && | |
2718 | + (or & 0xFFFFE000U) == 0x8A116000U && | |
2719 | + jmpl == 0x81C04005U && | |
2720 | + nop == 0x01000000U) | |
2721 | + { | |
2722 | + unsigned long addr; | |
2723 | + | |
2724 | + regs->u_regs[UREG_G1] = (sethi1 & 0x003FFFFFU) << 10; | |
2725 | + regs->u_regs[UREG_G1] <<= 32; | |
2726 | + regs->u_regs[UREG_G5] = ((sethi2 & 0x003FFFFFU) << 10) | (or & 0x3FFU); | |
2727 | + addr = regs->u_regs[UREG_G1] + regs->u_regs[UREG_G5]; | |
2728 | + regs->tpc = addr; | |
2729 | + regs->tnpc = addr+4; | |
2730 | + return 2; | |
2731 | + } | |
2732 | + } while (0); | |
2733 | + | |
2734 | + do { /* PaX: patched PLT emulation #7 */ | |
2735 | + unsigned int sethi, ba, nop; | |
2736 | + | |
2737 | + err = get_user(sethi, (unsigned int *)regs->tpc); | |
2738 | + err |= get_user(ba, (unsigned int *)(regs->tpc+4)); | |
2739 | + err |= get_user(nop, (unsigned int *)(regs->tpc+8)); | |
2740 | + | |
2741 | + if (err) | |
2742 | + break; | |
2743 | + | |
2744 | + if ((sethi & 0xFFC00000U) == 0x03000000U && | |
2745 | + (ba & 0xFFF00000U) == 0x30600000U && | |
2746 | + nop == 0x01000000U) | |
2747 | + { | |
2748 | + unsigned long addr; | |
2749 | + | |
2750 | + addr = (sethi & 0x003FFFFFU) << 10; | |
2751 | + regs->u_regs[UREG_G1] = addr; | |
2752 | + addr = regs->tpc + ((((ba | 0xFFFFFFFFFFF80000UL) ^ 0x00040000UL) + 0x00040000UL) << 2); | |
2753 | + regs->tpc = addr; | |
2754 | + regs->tnpc = addr+4; | |
2755 | + return 2; | |
2756 | + } | |
2757 | + } while (0); | |
2758 | + | |
2759 | + do { /* PaX: unpatched PLT emulation step 1 */ | |
2760 | + unsigned int sethi, ba, nop; | |
2761 | + | |
2762 | + err = get_user(sethi, (unsigned int *)regs->tpc); | |
2763 | + err |= get_user(ba, (unsigned int *)(regs->tpc+4)); | |
2764 | + err |= get_user(nop, (unsigned int *)(regs->tpc+8)); | |
2765 | + | |
2766 | + if (err) | |
2767 | + break; | |
2768 | + | |
2769 | + if ((sethi & 0xFFC00000U) == 0x03000000U && | |
2770 | + ((ba & 0xFFC00000U) == 0x30800000U || (ba & 0xFFF80000U) == 0x30680000U) && | |
2771 | + nop == 0x01000000U) | |
2772 | + { | |
2773 | + unsigned long addr; | |
2774 | + unsigned int save, call; | |
2775 | + | |
2776 | + if ((ba & 0xFFC00000U) == 0x30800000U) | |
2777 | + addr = regs->tpc + 4 + ((((ba | 0xFFFFFFFFFFC00000UL) ^ 0x00200000UL) + 0x00200000UL) << 2); | |
2778 | + else | |
2779 | + addr = regs->tpc + 4 + ((((ba | 0xFFFFFFFFFFF80000UL) ^ 0x00040000UL) + 0x00040000UL) << 2); | |
2780 | + | |
2781 | + err = get_user(save, (unsigned int *)addr); | |
2782 | + err |= get_user(call, (unsigned int *)(addr+4)); | |
2783 | + err |= get_user(nop, (unsigned int *)(addr+8)); | |
2784 | + if (err) | |
2785 | + break; | |
2786 | + | |
2787 | + if (save == 0x9DE3BFA8U && | |
2788 | + (call & 0xC0000000U) == 0x40000000U && | |
2789 | + nop == 0x01000000U) | |
2790 | + { | |
2791 | + struct vm_area_struct *vma; | |
2792 | + unsigned long call_dl_resolve; | |
2793 | + | |
2794 | + down_read(¤t->mm->mmap_sem); | |
2795 | + call_dl_resolve = current->mm->call_dl_resolve; | |
2796 | + up_read(¤t->mm->mmap_sem); | |
2797 | + if (likely(call_dl_resolve)) | |
2798 | + goto emulate; | |
2799 | + | |
2800 | + vma = kmem_cache_zalloc(vm_area_cachep, GFP_KERNEL); | |
2801 | + | |
2802 | + down_write(¤t->mm->mmap_sem); | |
2803 | + if (current->mm->call_dl_resolve) { | |
2804 | + call_dl_resolve = current->mm->call_dl_resolve; | |
2805 | + up_write(¤t->mm->mmap_sem); | |
4dee9bd5 | 2806 | + if (vma) |
2807 | + kmem_cache_free(vm_area_cachep, vma); | |
da5b3fc8 | 2808 | + goto emulate; |
2809 | + } | |
2810 | + | |
2811 | + call_dl_resolve = get_unmapped_area(NULL, 0UL, PAGE_SIZE, 0UL, MAP_PRIVATE); | |
2812 | + if (!vma || (call_dl_resolve & ~PAGE_MASK)) { | |
2813 | + up_write(¤t->mm->mmap_sem); | |
4dee9bd5 | 2814 | + if (vma) |
2815 | + kmem_cache_free(vm_area_cachep, vma); | |
da5b3fc8 | 2816 | + return 1; |
2817 | + } | |
2818 | + | |
2819 | + if (pax_insert_vma(vma, call_dl_resolve)) { | |
2820 | + up_write(¤t->mm->mmap_sem); | |
2821 | + kmem_cache_free(vm_area_cachep, vma); | |
2822 | + return 1; | |
2823 | + } | |
2824 | + | |
2825 | + current->mm->call_dl_resolve = call_dl_resolve; | |
2826 | + up_write(¤t->mm->mmap_sem); | |
2827 | + | |
2828 | +emulate: | |
2829 | + regs->u_regs[UREG_G1] = (sethi & 0x003FFFFFU) << 10; | |
2830 | + regs->tpc = call_dl_resolve; | |
2831 | + regs->tnpc = addr+4; | |
2832 | + return 3; | |
2833 | + } | |
2834 | + } | |
2835 | + } while (0); | |
2836 | + | |
2837 | + do { /* PaX: unpatched PLT emulation step 2 */ | |
2838 | + unsigned int save, call, nop; | |
2839 | + | |
2840 | + err = get_user(save, (unsigned int *)(regs->tpc-4)); | |
2841 | + err |= get_user(call, (unsigned int *)regs->tpc); | |
2842 | + err |= get_user(nop, (unsigned int *)(regs->tpc+4)); | |
2843 | + if (err) | |
2844 | + break; | |
2845 | + | |
2846 | + if (save == 0x9DE3BFA8U && | |
2847 | + (call & 0xC0000000U) == 0x40000000U && | |
2848 | + nop == 0x01000000U) | |
2849 | + { | |
2850 | + unsigned long dl_resolve = regs->tpc + ((((call | 0xFFFFFFFFC0000000UL) ^ 0x20000000UL) + 0x20000000UL) << 2); | |
2851 | + | |
2852 | + regs->u_regs[UREG_RETPC] = regs->tpc; | |
2853 | + regs->tpc = dl_resolve; | |
2854 | + regs->tnpc = dl_resolve+4; | |
2855 | + return 3; | |
2856 | + } | |
2857 | + } while (0); | |
2858 | +#endif | |
2859 | + | |
2860 | + return 1; | |
2861 | +} | |
2862 | + | |
2863 | +void pax_report_insns(void *pc, void *sp) | |
2864 | +{ | |
2865 | + unsigned long i; | |
2866 | + | |
2867 | + printk(KERN_ERR "PAX: bytes at PC: "); | |
2868 | + for (i = 0; i < 5; i++) { | |
2869 | + unsigned int c; | |
2870 | + if (get_user(c, (unsigned int *)pc+i)) | |
4dee9bd5 | 2871 | + printk(KERN_CONT "???????? "); |
da5b3fc8 | 2872 | + else |
4dee9bd5 | 2873 | + printk(KERN_CONT "%08x ", c); |
da5b3fc8 | 2874 | + } |
2875 | + printk("\n"); | |
2876 | +} | |
2877 | +#endif | |
2878 | + | |
2879 | asmlinkage void __kprobes do_sparc64_fault(struct pt_regs *regs) | |
2880 | { | |
2881 | struct mm_struct *mm = current->mm; | |
4dee9bd5 | 2882 | @@ -303,8 +671,10 @@ asmlinkage void __kprobes do_sparc64_fau |
da5b3fc8 | 2883 | goto intr_or_no_mm; |
2884 | ||
2885 | if (test_thread_flag(TIF_32BIT)) { | |
2886 | - if (!(regs->tstate & TSTATE_PRIV)) | |
2887 | + if (!(regs->tstate & TSTATE_PRIV)) { | |
2888 | regs->tpc &= 0xffffffff; | |
2889 | + regs->tnpc &= 0xffffffff; | |
2890 | + } | |
2891 | address &= 0xffffffff; | |
2892 | } | |
2893 | ||
4dee9bd5 | 2894 | @@ -321,6 +691,29 @@ asmlinkage void __kprobes do_sparc64_fau |
da5b3fc8 | 2895 | if (!vma) |
2896 | goto bad_area; | |
2897 | ||
2898 | +#ifdef CONFIG_PAX_PAGEEXEC | |
2899 | + /* PaX: detect ITLB misses on non-exec pages */ | |
2900 | + if ((mm->pax_flags & MF_PAX_PAGEEXEC) && vma->vm_start <= address && | |
2901 | + !(vma->vm_flags & VM_EXEC) && (fault_code & FAULT_CODE_ITLB)) | |
2902 | + { | |
2903 | + if (address != regs->tpc) | |
2904 | + goto good_area; | |
2905 | + | |
2906 | + up_read(&mm->mmap_sem); | |
2907 | + switch (pax_handle_fetch_fault(regs)) { | |
2908 | + | |
2909 | +#ifdef CONFIG_PAX_EMUPLT | |
2910 | + case 2: | |
2911 | + case 3: | |
2912 | + return; | |
2913 | +#endif | |
2914 | + | |
2915 | + } | |
4dee9bd5 | 2916 | + pax_report_fault(regs, (void *)regs->tpc, (void *)(regs->u_regs[UREG_FP] + STACK_BIAS)); |
b7f09679 | 2917 | + do_group_exit(SIGKILL); |
da5b3fc8 | 2918 | + } |
2919 | +#endif | |
2920 | + | |
2921 | /* Pure DTLB misses do not tell us whether the fault causing | |
2922 | * load/store/atomic was a write or not, it only says that there | |
2923 | * was no match. So in such a case we (carefully) read the | |
4dee9bd5 | 2924 | diff -urNp linux-2.6.25.4/arch/sparc64/mm/Makefile linux-2.6.25.4/arch/sparc64/mm/Makefile |
2925 | --- linux-2.6.25.4/arch/sparc64/mm/Makefile 2008-05-15 11:00:12.000000000 -0400 | |
2926 | +++ linux-2.6.25.4/arch/sparc64/mm/Makefile 2008-05-18 13:33:14.000000000 -0400 | |
da5b3fc8 | 2927 | @@ -3,7 +3,7 @@ |
2928 | # | |
2929 | ||
2930 | EXTRA_AFLAGS := -ansi | |
2931 | -EXTRA_CFLAGS := -Werror | |
2932 | +#EXTRA_CFLAGS := -Werror | |
2933 | ||
2934 | obj-y := ultra.o tlb.o tsb.o fault.o init.o generic.o | |
2935 | ||
4dee9bd5 | 2936 | diff -urNp linux-2.6.25.4/arch/v850/kernel/module.c linux-2.6.25.4/arch/v850/kernel/module.c |
2937 | --- linux-2.6.25.4/arch/v850/kernel/module.c 2008-05-15 11:00:12.000000000 -0400 | |
2938 | +++ linux-2.6.25.4/arch/v850/kernel/module.c 2008-05-18 13:33:14.000000000 -0400 | |
da5b3fc8 | 2939 | @@ -150,8 +150,8 @@ static uint32_t do_plt_call (void *locat |
2940 | tramp[1] = ((val >> 16) & 0xffff) + 0x610000; /* ...; jmp r1 */ | |
2941 | ||
2942 | /* Init, or core PLT? */ | |
2943 | - if (location >= mod->module_core | |
2944 | - && location < mod->module_core + mod->core_size) | |
2945 | + if (location >= mod->module_core_rx | |
2946 | + && location < mod->module_core_rx + mod->core_size_rx) | |
2947 | entry = (void *)sechdrs[mod->arch.core_plt_section].sh_addr; | |
2948 | else | |
2949 | entry = (void *)sechdrs[mod->arch.init_plt_section].sh_addr; | |
4dee9bd5 | 2950 | diff -urNp linux-2.6.25.4/arch/x86/boot/bitops.h linux-2.6.25.4/arch/x86/boot/bitops.h |
2951 | --- linux-2.6.25.4/arch/x86/boot/bitops.h 2008-05-15 11:00:12.000000000 -0400 | |
2952 | +++ linux-2.6.25.4/arch/x86/boot/bitops.h 2008-05-18 13:33:14.000000000 -0400 | |
da5b3fc8 | 2953 | @@ -28,7 +28,7 @@ static inline int variable_test_bit(int |
2954 | u8 v; | |
2955 | const u32 *p = (const u32 *)addr; | |
2956 | ||
2957 | - asm("btl %2,%1; setc %0" : "=qm" (v) : "m" (*p), "Ir" (nr)); | |
2958 | + asm volatile("btl %2,%1; setc %0" : "=qm" (v) : "m" (*p), "Ir" (nr)); | |
2959 | return v; | |
2960 | } | |
2961 | ||
2962 | @@ -39,7 +39,7 @@ static inline int variable_test_bit(int | |
2963 | ||
2964 | static inline void set_bit(int nr, void *addr) | |
2965 | { | |
2966 | - asm("btsl %1,%0" : "+m" (*(u32 *)addr) : "Ir" (nr)); | |
2967 | + asm volatile("btsl %1,%0" : "+m" (*(u32 *)addr) : "Ir" (nr)); | |
2968 | } | |
2969 | ||
2970 | #endif /* BOOT_BITOPS_H */ | |
4dee9bd5 | 2971 | diff -urNp linux-2.6.25.4/arch/x86/boot/boot.h linux-2.6.25.4/arch/x86/boot/boot.h |
2972 | --- linux-2.6.25.4/arch/x86/boot/boot.h 2008-05-15 11:00:12.000000000 -0400 | |
2973 | +++ linux-2.6.25.4/arch/x86/boot/boot.h 2008-05-18 13:33:14.000000000 -0400 | |
da5b3fc8 | 2974 | @@ -78,7 +78,7 @@ static inline void io_delay(void) |
2975 | static inline u16 ds(void) | |
2976 | { | |
2977 | u16 seg; | |
2978 | - asm("movw %%ds,%0" : "=rm" (seg)); | |
2979 | + asm volatile("movw %%ds,%0" : "=rm" (seg)); | |
2980 | return seg; | |
2981 | } | |
2982 | ||
2983 | @@ -174,7 +174,7 @@ static inline void wrgs32(u32 v, addr_t | |
2984 | static inline int memcmp(const void *s1, const void *s2, size_t len) | |
2985 | { | |
2986 | u8 diff; | |
2987 | - asm("repe; cmpsb; setnz %0" | |
2988 | + asm volatile("repe; cmpsb; setnz %0" | |
2989 | : "=qm" (diff), "+D" (s1), "+S" (s2), "+c" (len)); | |
2990 | return diff; | |
2991 | } | |
4dee9bd5 | 2992 | diff -urNp linux-2.6.25.4/arch/x86/boot/compressed/head_32.S linux-2.6.25.4/arch/x86/boot/compressed/head_32.S |
2993 | --- linux-2.6.25.4/arch/x86/boot/compressed/head_32.S 2008-05-15 11:00:12.000000000 -0400 | |
2994 | +++ linux-2.6.25.4/arch/x86/boot/compressed/head_32.S 2008-05-18 13:33:14.000000000 -0400 | |
da5b3fc8 | 2995 | @@ -70,7 +70,7 @@ startup_32: |
2996 | addl $(CONFIG_PHYSICAL_ALIGN - 1), %ebx | |
2997 | andl $(~(CONFIG_PHYSICAL_ALIGN - 1)), %ebx | |
2998 | #else | |
2999 | - movl $LOAD_PHYSICAL_ADDR, %ebx | |
3000 | + movl $____LOAD_PHYSICAL_ADDR, %ebx | |
3001 | #endif | |
3002 | ||
3003 | /* Replace the compressed data size with the uncompressed size */ | |
3004 | @@ -105,7 +105,7 @@ startup_32: | |
3005 | addl $(CONFIG_PHYSICAL_ALIGN - 1), %ebp | |
3006 | andl $(~(CONFIG_PHYSICAL_ALIGN - 1)), %ebp | |
3007 | #else | |
3008 | - movl $LOAD_PHYSICAL_ADDR, %ebp | |
3009 | + movl $____LOAD_PHYSICAL_ADDR, %ebp | |
3010 | #endif | |
3011 | ||
3012 | /* | |
3013 | @@ -159,16 +159,15 @@ relocated: | |
3014 | * and where it was actually loaded. | |
3015 | */ | |
3016 | movl %ebp, %ebx | |
3017 | - subl $LOAD_PHYSICAL_ADDR, %ebx | |
3018 | + subl $____LOAD_PHYSICAL_ADDR, %ebx | |
3019 | jz 2f /* Nothing to be done if loaded at compiled addr. */ | |
3020 | /* | |
3021 | * Process relocations. | |
3022 | */ | |
3023 | ||
3024 | 1: subl $4, %edi | |
3025 | - movl 0(%edi), %ecx | |
3026 | - testl %ecx, %ecx | |
3027 | - jz 2f | |
3028 | + movl (%edi), %ecx | |
3029 | + jecxz 2f | |
3030 | addl %ebx, -__PAGE_OFFSET(%ebx, %ecx) | |
3031 | jmp 1b | |
3032 | 2: | |
4dee9bd5 | 3033 | diff -urNp linux-2.6.25.4/arch/x86/boot/compressed/misc.c linux-2.6.25.4/arch/x86/boot/compressed/misc.c |
3034 | --- linux-2.6.25.4/arch/x86/boot/compressed/misc.c 2008-05-15 11:00:12.000000000 -0400 | |
3035 | +++ linux-2.6.25.4/arch/x86/boot/compressed/misc.c 2008-05-18 13:33:14.000000000 -0400 | |
3036 | @@ -122,7 +122,8 @@ typedef unsigned char uch; | |
da5b3fc8 | 3037 | typedef unsigned short ush; |
3038 | typedef unsigned long ulg; | |
3039 | ||
3040 | -#define WSIZE 0x80000000 /* Window size must be at least 32k, | |
3041 | +#define WSIZE 0x80000000 | |
3042 | + /* Window size must be at least 32k, | |
3043 | * and a power of two | |
3044 | * We don't actually have a window just | |
3045 | * a huge output buffer so I report | |
4dee9bd5 | 3046 | @@ -400,7 +401,7 @@ asmlinkage void decompress_kernel(void * |
3047 | if (heap > ((-__PAGE_OFFSET-(512<<20)-1) & 0x7fffffff)) | |
da5b3fc8 | 3048 | error("Destination address too large"); |
3049 | #ifndef CONFIG_RELOCATABLE | |
3050 | - if ((u32)output != LOAD_PHYSICAL_ADDR) | |
3051 | + if ((u32)output != ____LOAD_PHYSICAL_ADDR) | |
3052 | error("Wrong destination address"); | |
3053 | #endif | |
4dee9bd5 | 3054 | #endif |
3055 | diff -urNp linux-2.6.25.4/arch/x86/boot/compressed/relocs.c linux-2.6.25.4/arch/x86/boot/compressed/relocs.c | |
3056 | --- linux-2.6.25.4/arch/x86/boot/compressed/relocs.c 2008-05-15 11:00:12.000000000 -0400 | |
3057 | +++ linux-2.6.25.4/arch/x86/boot/compressed/relocs.c 2008-05-18 13:33:14.000000000 -0400 | |
da5b3fc8 | 3058 | @@ -10,9 +10,13 @@ |
3059 | #define USE_BSD | |
3060 | #include <endian.h> | |
3061 | ||
3062 | +#include "../../../../include/linux/autoconf.h" | |
3063 | + | |
3064 | +#define MAX_PHDRS 100 | |
3065 | #define MAX_SHDRS 100 | |
3066 | #define ARRAY_SIZE(x) (sizeof(x) / sizeof((x)[0])) | |
3067 | static Elf32_Ehdr ehdr; | |
3068 | +static Elf32_Phdr phdr[MAX_PHDRS]; | |
3069 | static Elf32_Shdr shdr[MAX_SHDRS]; | |
3070 | static Elf32_Sym *symtab[MAX_SHDRS]; | |
3071 | static Elf32_Rel *reltab[MAX_SHDRS]; | |
4dee9bd5 | 3072 | @@ -241,6 +245,34 @@ static void read_ehdr(FILE *fp) |
da5b3fc8 | 3073 | } |
3074 | } | |
3075 | ||
3076 | +static void read_phdrs(FILE *fp) | |
3077 | +{ | |
3078 | + int i; | |
3079 | + if (ehdr.e_phnum > MAX_PHDRS) { | |
3080 | + die("%d program headers supported: %d\n", | |
3081 | + ehdr.e_phnum, MAX_PHDRS); | |
3082 | + } | |
3083 | + if (fseek(fp, ehdr.e_phoff, SEEK_SET) < 0) { | |
3084 | + die("Seek to %d failed: %s\n", | |
3085 | + ehdr.e_phoff, strerror(errno)); | |
3086 | + } | |
3087 | + if (fread(&phdr, sizeof(phdr[0]), ehdr.e_phnum, fp) != ehdr.e_phnum) { | |
3088 | + die("Cannot read ELF program headers: %s\n", | |
3089 | + strerror(errno)); | |
3090 | + } | |
3091 | + for(i = 0; i < ehdr.e_phnum; i++) { | |
3092 | + phdr[i].p_type = elf32_to_cpu(phdr[i].p_type); | |
3093 | + phdr[i].p_offset = elf32_to_cpu(phdr[i].p_offset); | |
3094 | + phdr[i].p_vaddr = elf32_to_cpu(phdr[i].p_vaddr); | |
3095 | + phdr[i].p_paddr = elf32_to_cpu(phdr[i].p_paddr); | |
3096 | + phdr[i].p_filesz = elf32_to_cpu(phdr[i].p_filesz); | |
3097 | + phdr[i].p_memsz = elf32_to_cpu(phdr[i].p_memsz); | |
3098 | + phdr[i].p_flags = elf32_to_cpu(phdr[i].p_flags); | |
3099 | + phdr[i].p_align = elf32_to_cpu(phdr[i].p_align); | |
3100 | + } | |
3101 | + | |
3102 | +} | |
3103 | + | |
3104 | static void read_shdrs(FILE *fp) | |
3105 | { | |
3106 | int i; | |
4dee9bd5 | 3107 | @@ -327,6 +359,8 @@ static void read_symtabs(FILE *fp) |
da5b3fc8 | 3108 | static void read_relocs(FILE *fp) |
3109 | { | |
3110 | int i,j; | |
3111 | + uint32_t base; | |
3112 | + | |
3113 | for(i = 0; i < ehdr.e_shnum; i++) { | |
3114 | if (shdr[i].sh_type != SHT_REL) { | |
3115 | continue; | |
4dee9bd5 | 3116 | @@ -344,8 +378,17 @@ static void read_relocs(FILE *fp) |
da5b3fc8 | 3117 | die("Cannot read symbol table: %s\n", |
3118 | strerror(errno)); | |
3119 | } | |
3120 | + base = 0; | |
3121 | + for (j = 0; j < ehdr.e_phnum; j++) { | |
3122 | + if (phdr[j].p_type != PT_LOAD ) | |
3123 | + continue; | |
3124 | + if (shdr[shdr[i].sh_info].sh_offset < phdr[j].p_offset || shdr[shdr[i].sh_info].sh_offset > phdr[j].p_offset + phdr[j].p_filesz) | |
3125 | + continue; | |
3126 | + base = CONFIG_PAGE_OFFSET + phdr[j].p_paddr - phdr[j].p_vaddr; | |
3127 | + break; | |
3128 | + } | |
3129 | for(j = 0; j < shdr[i].sh_size/sizeof(reltab[0][0]); j++) { | |
3130 | - reltab[i][j].r_offset = elf32_to_cpu(reltab[i][j].r_offset); | |
3131 | + reltab[i][j].r_offset = elf32_to_cpu(reltab[i][j].r_offset) + base; | |
3132 | reltab[i][j].r_info = elf32_to_cpu(reltab[i][j].r_info); | |
3133 | } | |
3134 | } | |
4dee9bd5 | 3135 | @@ -482,6 +525,23 @@ static void walk_relocs(void (*visit)(El |
da5b3fc8 | 3136 | if (sym->st_shndx == SHN_ABS) { |
3137 | continue; | |
3138 | } | |
3139 | + /* Don't relocate actual per-cpu variables, they are absolute indices, not addresses */ | |
4dee9bd5 | 3140 | + if (!strcmp(sec_name(sym->st_shndx), ".data.percpu") && strncmp(sym_name(sym_strtab, sym), "__per_cpu_", 10)) |
da5b3fc8 | 3141 | + continue; |
da5b3fc8 | 3142 | +#if defined(CONFIG_PAX_KERNEXEC) && defined(CONFIG_X86_32) |
3143 | + /* Don't relocate actual code, they are relocated implicitly by the base address of KERNEL_CS */ | |
4dee9bd5 | 3144 | + if (!strcmp(sec_name(sym->st_shndx), ".init.text")) |
da5b3fc8 | 3145 | + continue; |
4dee9bd5 | 3146 | + if (!strcmp(sec_name(sym->st_shndx), ".exit.text")) |
da5b3fc8 | 3147 | + continue; |
da5b3fc8 | 3148 | + if (!strcmp(sec_name(sym->st_shndx), ".text.head")) { |
3149 | + if (strcmp(sym_name(sym_strtab, sym), "__init_end") && | |
3150 | + strcmp(sym_name(sym_strtab, sym), "KERNEL_TEXT_OFFSET")) | |
3151 | + continue; | |
3152 | + } | |
4dee9bd5 | 3153 | + if (!strcmp(sec_name(sym->st_shndx), ".text")) |
da5b3fc8 | 3154 | + continue; |
da5b3fc8 | 3155 | +#endif |
3156 | if (r_type == R_386_PC32) { | |
3157 | /* PC relative relocations don't need to be adjusted */ | |
3158 | } | |
4dee9bd5 | 3159 | @@ -609,6 +669,7 @@ int main(int argc, char **argv) |
da5b3fc8 | 3160 | fname, strerror(errno)); |
3161 | } | |
3162 | read_ehdr(fp); | |
3163 | + read_phdrs(fp); | |
3164 | read_shdrs(fp); | |
3165 | read_strtabs(fp); | |
3166 | read_symtabs(fp); | |
4dee9bd5 | 3167 | diff -urNp linux-2.6.25.4/arch/x86/boot/cpucheck.c linux-2.6.25.4/arch/x86/boot/cpucheck.c |
3168 | --- linux-2.6.25.4/arch/x86/boot/cpucheck.c 2008-05-15 11:00:12.000000000 -0400 | |
3169 | +++ linux-2.6.25.4/arch/x86/boot/cpucheck.c 2008-05-18 13:33:14.000000000 -0400 | |
da5b3fc8 | 3170 | @@ -84,7 +84,7 @@ static int has_fpu(void) |
3171 | u16 fcw = -1, fsw = -1; | |
3172 | u32 cr0; | |
3173 | ||
3174 | - asm("movl %%cr0,%0" : "=r" (cr0)); | |
3175 | + asm volatile("movl %%cr0,%0" : "=r" (cr0)); | |
3176 | if (cr0 & (X86_CR0_EM|X86_CR0_TS)) { | |
3177 | cr0 &= ~(X86_CR0_EM|X86_CR0_TS); | |
3178 | asm volatile("movl %0,%%cr0" : : "r" (cr0)); | |
3179 | @@ -100,7 +100,7 @@ static int has_eflag(u32 mask) | |
3180 | { | |
3181 | u32 f0, f1; | |
3182 | ||
3183 | - asm("pushfl ; " | |
3184 | + asm volatile("pushfl ; " | |
3185 | "pushfl ; " | |
3186 | "popl %0 ; " | |
3187 | "movl %0,%1 ; " | |
3188 | @@ -125,7 +125,7 @@ static void get_flags(void) | |
3189 | set_bit(X86_FEATURE_FPU, cpu.flags); | |
3190 | ||
3191 | if (has_eflag(X86_EFLAGS_ID)) { | |
3192 | - asm("cpuid" | |
3193 | + asm volatile("cpuid" | |
3194 | : "=a" (max_intel_level), | |
3195 | "=b" (cpu_vendor[0]), | |
3196 | "=d" (cpu_vendor[1]), | |
3197 | @@ -134,7 +134,7 @@ static void get_flags(void) | |
3198 | ||
3199 | if (max_intel_level >= 0x00000001 && | |
3200 | max_intel_level <= 0x0000ffff) { | |
3201 | - asm("cpuid" | |
3202 | + asm volatile("cpuid" | |
3203 | : "=a" (tfms), | |
3204 | "=c" (cpu.flags[4]), | |
3205 | "=d" (cpu.flags[0]) | |
3206 | @@ -146,7 +146,7 @@ static void get_flags(void) | |
3207 | cpu.model += ((tfms >> 16) & 0xf) << 4; | |
3208 | } | |
3209 | ||
3210 | - asm("cpuid" | |
3211 | + asm volatile("cpuid" | |
3212 | : "=a" (max_amd_level) | |
3213 | : "a" (0x80000000) | |
3214 | : "ebx", "ecx", "edx"); | |
3215 | @@ -154,7 +154,7 @@ static void get_flags(void) | |
3216 | if (max_amd_level >= 0x80000001 && | |
3217 | max_amd_level <= 0x8000ffff) { | |
3218 | u32 eax = 0x80000001; | |
3219 | - asm("cpuid" | |
3220 | + asm volatile("cpuid" | |
3221 | : "+a" (eax), | |
3222 | "=c" (cpu.flags[6]), | |
3223 | "=d" (cpu.flags[1]) | |
3224 | @@ -213,9 +213,9 @@ int check_cpu(int *cpu_level_ptr, int *r | |
3225 | u32 ecx = MSR_K7_HWCR; | |
3226 | u32 eax, edx; | |
3227 | ||
3228 | - asm("rdmsr" : "=a" (eax), "=d" (edx) : "c" (ecx)); | |
3229 | + asm volatile("rdmsr" : "=a" (eax), "=d" (edx) : "c" (ecx)); | |
3230 | eax &= ~(1 << 15); | |
3231 | - asm("wrmsr" : : "a" (eax), "d" (edx), "c" (ecx)); | |
3232 | + asm volatile("wrmsr" : : "a" (eax), "d" (edx), "c" (ecx)); | |
3233 | ||
3234 | get_flags(); /* Make sure it really did something */ | |
3235 | err = check_flags(); | |
3236 | @@ -228,9 +228,9 @@ int check_cpu(int *cpu_level_ptr, int *r | |
3237 | u32 ecx = MSR_VIA_FCR; | |
3238 | u32 eax, edx; | |
3239 | ||
3240 | - asm("rdmsr" : "=a" (eax), "=d" (edx) : "c" (ecx)); | |
3241 | + asm volatile("rdmsr" : "=a" (eax), "=d" (edx) : "c" (ecx)); | |
3242 | eax |= (1<<1)|(1<<7); | |
3243 | - asm("wrmsr" : : "a" (eax), "d" (edx), "c" (ecx)); | |
3244 | + asm volatile("wrmsr" : : "a" (eax), "d" (edx), "c" (ecx)); | |
3245 | ||
3246 | set_bit(X86_FEATURE_CX8, cpu.flags); | |
3247 | err = check_flags(); | |
3248 | @@ -241,12 +241,12 @@ int check_cpu(int *cpu_level_ptr, int *r | |
3249 | u32 eax, edx; | |
3250 | u32 level = 1; | |
3251 | ||
3252 | - asm("rdmsr" : "=a" (eax), "=d" (edx) : "c" (ecx)); | |
3253 | - asm("wrmsr" : : "a" (~0), "d" (edx), "c" (ecx)); | |
3254 | - asm("cpuid" | |
3255 | + asm volatile("rdmsr" : "=a" (eax), "=d" (edx) : "c" (ecx)); | |
3256 | + asm volatile("wrmsr" : : "a" (~0), "d" (edx), "c" (ecx)); | |
3257 | + asm volatile("cpuid" | |
3258 | : "+a" (level), "=d" (cpu.flags[0]) | |
3259 | : : "ecx", "ebx"); | |
3260 | - asm("wrmsr" : : "a" (eax), "d" (edx), "c" (ecx)); | |
3261 | + asm volatile("wrmsr" : : "a" (eax), "d" (edx), "c" (ecx)); | |
3262 | ||
3263 | err = check_flags(); | |
3264 | } | |
4dee9bd5 | 3265 | diff -urNp linux-2.6.25.4/arch/x86/boot/edd.c linux-2.6.25.4/arch/x86/boot/edd.c |
3266 | --- linux-2.6.25.4/arch/x86/boot/edd.c 2008-05-15 11:00:12.000000000 -0400 | |
3267 | +++ linux-2.6.25.4/arch/x86/boot/edd.c 2008-05-18 13:33:14.000000000 -0400 | |
da5b3fc8 | 3268 | @@ -78,7 +78,7 @@ static int get_edd_info(u8 devno, struct |
3269 | ax = 0x4100; | |
3270 | bx = EDDMAGIC1; | |
3271 | dx = devno; | |
3272 | - asm("pushfl; stc; int $0x13; setc %%al; popfl" | |
3273 | + asm volatile("pushfl; stc; int $0x13; setc %%al; popfl" | |
3274 | : "+a" (ax), "+b" (bx), "=c" (cx), "+d" (dx) | |
3275 | : : "esi", "edi"); | |
3276 | ||
3277 | @@ -97,7 +97,7 @@ static int get_edd_info(u8 devno, struct | |
3278 | ei->params.length = sizeof(ei->params); | |
3279 | ax = 0x4800; | |
3280 | dx = devno; | |
3281 | - asm("pushfl; int $0x13; popfl" | |
3282 | + asm volatile("pushfl; int $0x13; popfl" | |
3283 | : "+a" (ax), "+d" (dx), "=m" (ei->params) | |
3284 | : "S" (&ei->params) | |
3285 | : "ebx", "ecx", "edi"); | |
3286 | @@ -108,7 +108,7 @@ static int get_edd_info(u8 devno, struct | |
3287 | ax = 0x0800; | |
3288 | dx = devno; | |
3289 | di = 0; | |
3290 | - asm("pushw %%es; " | |
3291 | + asm volatile("pushw %%es; " | |
3292 | "movw %%di,%%es; " | |
3293 | "pushfl; stc; int $0x13; setc %%al; popfl; " | |
3294 | "popw %%es" | |
4dee9bd5 | 3295 | diff -urNp linux-2.6.25.4/arch/x86/boot/main.c linux-2.6.25.4/arch/x86/boot/main.c |
3296 | --- linux-2.6.25.4/arch/x86/boot/main.c 2008-05-15 11:00:12.000000000 -0400 | |
3297 | +++ linux-2.6.25.4/arch/x86/boot/main.c 2008-05-18 13:33:14.000000000 -0400 | |
da5b3fc8 | 3298 | @@ -75,7 +75,7 @@ static void keyboard_set_repeat(void) |
3299 | */ | |
3300 | static void query_ist(void) | |
3301 | { | |
3302 | - asm("int $0x15" | |
3303 | + asm volatile("int $0x15" | |
3304 | : "=a" (boot_params.ist_info.signature), | |
3305 | "=b" (boot_params.ist_info.command), | |
3306 | "=c" (boot_params.ist_info.event), | |
4dee9bd5 | 3307 | diff -urNp linux-2.6.25.4/arch/x86/boot/mca.c linux-2.6.25.4/arch/x86/boot/mca.c |
3308 | --- linux-2.6.25.4/arch/x86/boot/mca.c 2008-05-15 11:00:12.000000000 -0400 | |
3309 | +++ linux-2.6.25.4/arch/x86/boot/mca.c 2008-05-18 13:33:14.000000000 -0400 | |
da5b3fc8 | 3310 | @@ -21,7 +21,7 @@ int query_mca(void) |
3311 | u8 err; | |
3312 | u16 es, bx, len; | |
3313 | ||
3314 | - asm("pushw %%es ; " | |
3315 | + asm volatile("pushw %%es ; " | |
3316 | "int $0x15 ; " | |
3317 | "setc %0 ; " | |
3318 | "movw %%es, %1 ; " | |
4dee9bd5 | 3319 | diff -urNp linux-2.6.25.4/arch/x86/boot/memory.c linux-2.6.25.4/arch/x86/boot/memory.c |
3320 | --- linux-2.6.25.4/arch/x86/boot/memory.c 2008-05-15 11:00:12.000000000 -0400 | |
3321 | +++ linux-2.6.25.4/arch/x86/boot/memory.c 2008-05-18 13:33:14.000000000 -0400 | |
da5b3fc8 | 3322 | @@ -32,7 +32,7 @@ static int detect_memory_e820(void) |
3323 | /* Important: %edx is clobbered by some BIOSes, | |
3324 | so it must be either used for the error output | |
3325 | or explicitly marked clobbered. */ | |
3326 | - asm("int $0x15; setc %0" | |
3327 | + asm volatile("int $0x15; setc %0" | |
3328 | : "=d" (err), "+b" (next), "=a" (id), "+c" (size), | |
3329 | "=m" (*desc) | |
3330 | : "D" (desc), "d" (SMAP), "a" (0xe820)); | |
4dee9bd5 | 3331 | @@ -67,7 +67,7 @@ static int detect_memory_e801(void) |
da5b3fc8 | 3332 | |
3333 | bx = cx = dx = 0; | |
3334 | ax = 0xe801; | |
3335 | - asm("stc; int $0x15; setc %0" | |
3336 | + asm volatile("stc; int $0x15; setc %0" | |
3337 | : "=m" (err), "+a" (ax), "+b" (bx), "+c" (cx), "+d" (dx)); | |
3338 | ||
3339 | if (err) | |
4dee9bd5 | 3340 | @@ -97,7 +97,7 @@ static int detect_memory_88(void) |
da5b3fc8 | 3341 | u8 err; |
3342 | ||
3343 | ax = 0x8800; | |
3344 | - asm("stc; int $0x15; setc %0" : "=bcdm" (err), "+a" (ax)); | |
3345 | + asm volatile("stc; int $0x15; setc %0" : "=bcdm" (err), "+a" (ax)); | |
3346 | ||
3347 | boot_params.screen_info.ext_mem_k = ax; | |
3348 | ||
4dee9bd5 | 3349 | diff -urNp linux-2.6.25.4/arch/x86/boot/video.c linux-2.6.25.4/arch/x86/boot/video.c |
3350 | --- linux-2.6.25.4/arch/x86/boot/video.c 2008-05-15 11:00:12.000000000 -0400 | |
3351 | +++ linux-2.6.25.4/arch/x86/boot/video.c 2008-05-18 13:33:14.000000000 -0400 | |
da5b3fc8 | 3352 | @@ -40,7 +40,7 @@ static void store_cursor_position(void) |
3353 | ||
3354 | ax = 0x0300; | |
3355 | bx = 0; | |
3356 | - asm(INT10 | |
3357 | + asm volatile(INT10 | |
3358 | : "=d" (curpos), "+a" (ax), "+b" (bx) | |
3359 | : : "ecx", "esi", "edi"); | |
3360 | ||
3361 | @@ -55,7 +55,7 @@ static void store_video_mode(void) | |
3362 | /* N.B.: the saving of the video page here is a bit silly, | |
3363 | since we pretty much assume page 0 everywhere. */ | |
3364 | ax = 0x0f00; | |
3365 | - asm(INT10 | |
3366 | + asm volatile(INT10 | |
3367 | : "+a" (ax), "=b" (page) | |
3368 | : : "ecx", "edx", "esi", "edi"); | |
3369 | ||
4dee9bd5 | 3370 | diff -urNp linux-2.6.25.4/arch/x86/boot/video-vesa.c linux-2.6.25.4/arch/x86/boot/video-vesa.c |
3371 | --- linux-2.6.25.4/arch/x86/boot/video-vesa.c 2008-05-15 11:00:12.000000000 -0400 | |
3372 | +++ linux-2.6.25.4/arch/x86/boot/video-vesa.c 2008-05-18 13:33:14.000000000 -0400 | |
3373 | @@ -39,7 +39,7 @@ static int vesa_probe(void) | |
da5b3fc8 | 3374 | |
3375 | ax = 0x4f00; | |
3376 | di = (size_t)&vginfo; | |
3377 | - asm(INT10 | |
3378 | + asm volatile(INT10 | |
3379 | : "+a" (ax), "+D" (di), "=m" (vginfo) | |
3380 | : : "ebx", "ecx", "edx", "esi"); | |
3381 | ||
4dee9bd5 | 3382 | @@ -66,7 +66,7 @@ static int vesa_probe(void) |
da5b3fc8 | 3383 | ax = 0x4f01; |
3384 | cx = mode; | |
3385 | di = (size_t)&vminfo; | |
3386 | - asm(INT10 | |
3387 | + asm volatile(INT10 | |
3388 | : "+a" (ax), "+c" (cx), "+D" (di), "=m" (vminfo) | |
3389 | : : "ebx", "edx", "esi"); | |
3390 | ||
4dee9bd5 | 3391 | @@ -121,7 +121,7 @@ static int vesa_set_mode(struct mode_inf |
da5b3fc8 | 3392 | ax = 0x4f01; |
3393 | cx = vesa_mode; | |
3394 | di = (size_t)&vminfo; | |
3395 | - asm(INT10 | |
3396 | + asm volatile(INT10 | |
3397 | : "+a" (ax), "+c" (cx), "+D" (di), "=m" (vminfo) | |
3398 | : : "ebx", "edx", "esi"); | |
3399 | ||
4dee9bd5 | 3400 | @@ -199,19 +199,20 @@ static void vesa_dac_set_8bits(void) |
da5b3fc8 | 3401 | /* Save the VESA protected mode info */ |
3402 | static void vesa_store_pm_info(void) | |
3403 | { | |
3404 | - u16 ax, bx, di, es; | |
3405 | + u16 ax, bx, cx, di, es; | |
3406 | ||
3407 | ax = 0x4f0a; | |
3408 | - bx = di = 0; | |
3409 | - asm("pushw %%es; "INT10"; movw %%es,%0; popw %%es" | |
3410 | - : "=d" (es), "+a" (ax), "+b" (bx), "+D" (di) | |
3411 | - : : "ecx", "esi"); | |
3412 | + bx = cx = di = 0; | |
3413 | + asm volatile("pushw %%es; "INT10"; movw %%es,%0; popw %%es" | |
3414 | + : "=d" (es), "+a" (ax), "+b" (bx), "+c" (cx), "+D" (di) | |
3415 | + : : "esi"); | |
3416 | ||
3417 | if (ax != 0x004f) | |
3418 | return; | |
3419 | ||
3420 | boot_params.screen_info.vesapm_seg = es; | |
3421 | boot_params.screen_info.vesapm_off = di; | |
3422 | + boot_params.screen_info.vesapm_size = cx; | |
3423 | } | |
3424 | ||
3425 | /* | |
4dee9bd5 | 3426 | @@ -265,7 +266,7 @@ void vesa_store_edid(void) |
da5b3fc8 | 3427 | /* Note: The VBE DDC spec is different from the main VESA spec; |
3428 | we genuinely have to assume all registers are destroyed here. */ | |
3429 | ||
3430 | - asm("pushw %%es; movw %2,%%es; "INT10"; popw %%es" | |
3431 | + asm volatile("pushw %%es; movw %2,%%es; "INT10"; popw %%es" | |
3432 | : "+a" (ax), "+b" (bx) | |
3433 | : "c" (cx), "D" (di) | |
3434 | : "esi"); | |
4dee9bd5 | 3435 | @@ -281,7 +282,7 @@ void vesa_store_edid(void) |
da5b3fc8 | 3436 | cx = 0; /* Controller 0 */ |
3437 | dx = 0; /* EDID block number */ | |
3438 | di =(size_t) &boot_params.edid_info; /* (ES:)Pointer to block */ | |
3439 | - asm(INT10 | |
3440 | + asm volatile(INT10 | |
3441 | : "+a" (ax), "+b" (bx), "+d" (dx), "=m" (boot_params.edid_info) | |
3442 | : "c" (cx), "D" (di) | |
3443 | : "esi"); | |
4dee9bd5 | 3444 | diff -urNp linux-2.6.25.4/arch/x86/boot/video-vga.c linux-2.6.25.4/arch/x86/boot/video-vga.c |
3445 | --- linux-2.6.25.4/arch/x86/boot/video-vga.c 2008-05-15 11:00:12.000000000 -0400 | |
3446 | +++ linux-2.6.25.4/arch/x86/boot/video-vga.c 2008-05-18 13:33:14.000000000 -0400 | |
da5b3fc8 | 3447 | @@ -225,7 +225,7 @@ static int vga_probe(void) |
3448 | }; | |
3449 | u8 vga_flag; | |
3450 | ||
3451 | - asm(INT10 | |
3452 | + asm volatile(INT10 | |
3453 | : "=b" (boot_params.screen_info.orig_video_ega_bx) | |
3454 | : "a" (0x1200), "b" (0x10) /* Check EGA/VGA */ | |
3455 | : "ecx", "edx", "esi", "edi"); | |
3456 | @@ -233,7 +233,7 @@ static int vga_probe(void) | |
3457 | /* If we have MDA/CGA/HGC then BL will be unchanged at 0x10 */ | |
3458 | if ((u8)boot_params.screen_info.orig_video_ega_bx != 0x10) { | |
3459 | /* EGA/VGA */ | |
3460 | - asm(INT10 | |
3461 | + asm volatile(INT10 | |
3462 | : "=a" (vga_flag) | |
3463 | : "a" (0x1a00) | |
3464 | : "ebx", "ecx", "edx", "esi", "edi"); | |
4dee9bd5 | 3465 | diff -urNp linux-2.6.25.4/arch/x86/boot/voyager.c linux-2.6.25.4/arch/x86/boot/voyager.c |
3466 | --- linux-2.6.25.4/arch/x86/boot/voyager.c 2008-05-15 11:00:12.000000000 -0400 | |
3467 | +++ linux-2.6.25.4/arch/x86/boot/voyager.c 2008-05-18 13:33:14.000000000 -0400 | |
3468 | @@ -25,7 +25,7 @@ int query_voyager(void) | |
da5b3fc8 | 3469 | |
3470 | data_ptr[0] = 0xff; /* Flag on config not found(?) */ | |
3471 | ||
3472 | - asm("pushw %%es ; " | |
3473 | + asm volatile("pushw %%es ; " | |
3474 | "int $0x15 ; " | |
3475 | "setc %0 ; " | |
3476 | "movw %%es, %1 ; " | |
4dee9bd5 | 3477 | diff -urNp linux-2.6.25.4/arch/x86/ia32/ia32_signal.c linux-2.6.25.4/arch/x86/ia32/ia32_signal.c |
3478 | --- linux-2.6.25.4/arch/x86/ia32/ia32_signal.c 2008-05-15 11:00:12.000000000 -0400 | |
3479 | +++ linux-2.6.25.4/arch/x86/ia32/ia32_signal.c 2008-05-18 13:33:14.000000000 -0400 | |
3480 | @@ -536,6 +536,7 @@ int ia32_setup_rt_frame(int sig, struct | |
3481 | __NR_ia32_rt_sigreturn, | |
3482 | 0x80cd, | |
3483 | 0, | |
3484 | + 0 | |
3485 | }; | |
da5b3fc8 | 3486 | |
4dee9bd5 | 3487 | frame = get_sigframe(ka, regs, sizeof(*frame)); |
3488 | diff -urNp linux-2.6.25.4/arch/x86/Kconfig linux-2.6.25.4/arch/x86/Kconfig | |
3489 | --- linux-2.6.25.4/arch/x86/Kconfig 2008-05-15 11:00:12.000000000 -0400 | |
3490 | +++ linux-2.6.25.4/arch/x86/Kconfig 2008-05-18 13:33:14.000000000 -0400 | |
3491 | @@ -828,7 +828,7 @@ config PAGE_OFFSET | |
da5b3fc8 | 3492 | hex |
3493 | default 0xB0000000 if VMSPLIT_3G_OPT | |
3494 | default 0x80000000 if VMSPLIT_2G | |
3495 | - default 0x78000000 if VMSPLIT_2G_OPT | |
3496 | + default 0x70000000 if VMSPLIT_2G_OPT | |
3497 | default 0x40000000 if VMSPLIT_1G | |
3498 | default 0xC0000000 | |
3499 | depends on X86_32 | |
4dee9bd5 | 3500 | @@ -1122,8 +1122,7 @@ config CRASH_DUMP |
da5b3fc8 | 3501 | config PHYSICAL_START |
3502 | hex "Physical address where the kernel is loaded" if (EMBEDDED || CRASH_DUMP) | |
3503 | default "0x1000000" if X86_NUMAQ | |
3504 | - default "0x200000" if X86_64 | |
3505 | - default "0x100000" | |
3506 | + default "0x200000" | |
3507 | help | |
3508 | This gives the physical address where the kernel is loaded. | |
3509 | ||
4dee9bd5 | 3510 | @@ -1215,9 +1214,9 @@ config HOTPLUG_CPU |
3511 | suspend. | |
da5b3fc8 | 3512 | |
3513 | config COMPAT_VDSO | |
4dee9bd5 | 3514 | - def_bool y |
3515 | + def_bool n | |
3516 | prompt "Compat VDSO support" | |
3517 | - depends on X86_32 || IA32_EMULATION | |
3518 | + depends on (X86_32 || IA32_EMULATION) && !PAX_NOEXEC | |
da5b3fc8 | 3519 | help |
4dee9bd5 | 3520 | Map the 32-bit VDSO to the predictable old-style address too. |
b2ee8b1e | 3521 | ---help--- |
4dee9bd5 | 3522 | @@ -1404,7 +1403,7 @@ config PCI |
da5b3fc8 | 3523 | choice |
3524 | prompt "PCI access mode" | |
3525 | depends on X86_32 && PCI && !X86_VISWS | |
3526 | - default PCI_GOANY | |
3527 | + default PCI_GODIRECT | |
3528 | ---help--- | |
3529 | On PCI systems, the BIOS can be used to detect the PCI devices and | |
3530 | determine their configuration. However, some old PCI motherboards | |
4dee9bd5 | 3531 | diff -urNp linux-2.6.25.4/arch/x86/Kconfig.cpu linux-2.6.25.4/arch/x86/Kconfig.cpu |
3532 | --- linux-2.6.25.4/arch/x86/Kconfig.cpu 2008-05-15 11:00:12.000000000 -0400 | |
3533 | +++ linux-2.6.25.4/arch/x86/Kconfig.cpu 2008-05-18 13:33:14.000000000 -0400 | |
3534 | @@ -335,7 +335,7 @@ config X86_PPRO_FENCE | |
da5b3fc8 | 3535 | |
3536 | config X86_F00F_BUG | |
4dee9bd5 | 3537 | def_bool y |
da5b3fc8 | 3538 | - depends on M586MMX || M586TSC || M586 || M486 || M386 |
3539 | + depends on (M586MMX || M586TSC || M586 || M486 || M386) && !PAX_KERNEXEC | |
da5b3fc8 | 3540 | |
3541 | config X86_WP_WORKS_OK | |
4dee9bd5 | 3542 | def_bool y |
3543 | @@ -355,7 +355,7 @@ config X86_POPAD_OK | |
da5b3fc8 | 3544 | |
3545 | config X86_ALIGNMENT_16 | |
4dee9bd5 | 3546 | def_bool y |
da5b3fc8 | 3547 | - depends on MWINCHIP3D || MWINCHIP2 || MWINCHIPC6 || MCYRIXIII || X86_ELAN || MK6 || M586MMX || M586TSC || M586 || M486 || MVIAC3_2 || MGEODEGX1 |
b7f09679 | 3548 | + depends on MWINCHIP3D || MWINCHIP2 || MWINCHIPC6 || MCYRIXIII || X86_ELAN || MK8 || MK7 || MK6 || MCORE2 || MPENTIUM4 || MPENTIUMIII || MPENTIUMII || M686 || M586MMX || M586TSC || M586 || M486 || MVIAC3_2 || MGEODEGX1 |
da5b3fc8 | 3549 | |
3550 | config X86_GOOD_APIC | |
4dee9bd5 | 3551 | def_bool y |
3552 | @@ -398,7 +398,7 @@ config X86_TSC | |
b7f09679 | 3553 | # generates cmov. |
3554 | config X86_CMOV | |
4dee9bd5 | 3555 | def_bool y |
b7f09679 | 3556 | - depends on (MK7 || MPENTIUM4 || MPENTIUMM || MPENTIUMIII || MPENTIUMII || M686 || MVIAC3_2 || MVIAC7) |
4dee9bd5 | 3557 | + depends on (MK8 || MK7 || MCORE2 || MPSC || MPENTIUM4 || MPENTIUMM || MPENTIUMIII || MPENTIUMII || M686 || MVIAC3_2 || MVIAC7) |
b7f09679 | 3558 | |
3559 | config X86_MINIMUM_CPU_FAMILY | |
4dee9bd5 | 3560 | int |
3561 | diff -urNp linux-2.6.25.4/arch/x86/Kconfig.debug linux-2.6.25.4/arch/x86/Kconfig.debug | |
3562 | --- linux-2.6.25.4/arch/x86/Kconfig.debug 2008-05-15 11:00:12.000000000 -0400 | |
3563 | +++ linux-2.6.25.4/arch/x86/Kconfig.debug 2008-05-18 13:33:14.000000000 -0400 | |
3564 | @@ -57,7 +57,7 @@ config DEBUG_PER_CPU_MAPS | |
da5b3fc8 | 3565 | config DEBUG_RODATA |
3566 | bool "Write protect kernel read-only data structures" | |
4dee9bd5 | 3567 | default y |
da5b3fc8 | 3568 | - depends on DEBUG_KERNEL |
3569 | + depends on DEBUG_KERNEL && BROKEN | |
3570 | help | |
3571 | Mark the kernel read-only data as write-protected in the pagetables, | |
3572 | in order to catch accidental (and incorrect) writes to such const | |
4dee9bd5 | 3573 | diff -urNp linux-2.6.25.4/arch/x86/kernel/acpi/boot.c linux-2.6.25.4/arch/x86/kernel/acpi/boot.c |
3574 | --- linux-2.6.25.4/arch/x86/kernel/acpi/boot.c 2008-05-15 11:00:12.000000000 -0400 | |
3575 | +++ linux-2.6.25.4/arch/x86/kernel/acpi/boot.c 2008-05-18 13:33:14.000000000 -0400 | |
3576 | @@ -1119,7 +1119,7 @@ static struct dmi_system_id __initdata a | |
da5b3fc8 | 3577 | DMI_MATCH(DMI_PRODUCT_NAME, "TravelMate 360"), |
3578 | }, | |
3579 | }, | |
3580 | - {} | |
3581 | + { NULL, NULL, {{0, NULL}}, NULL} | |
3582 | }; | |
3583 | ||
3584 | #endif /* __i386__ */ | |
4dee9bd5 | 3585 | diff -urNp linux-2.6.25.4/arch/x86/kernel/acpi/sleep_32.c linux-2.6.25.4/arch/x86/kernel/acpi/sleep_32.c |
3586 | --- linux-2.6.25.4/arch/x86/kernel/acpi/sleep_32.c 2008-05-15 11:00:12.000000000 -0400 | |
3587 | +++ linux-2.6.25.4/arch/x86/kernel/acpi/sleep_32.c 2008-05-18 13:33:14.000000000 -0400 | |
3588 | @@ -28,7 +28,7 @@ static __initdata struct dmi_system_id a | |
da5b3fc8 | 3589 | DMI_MATCH(DMI_PRODUCT_NAME, "S4030CDT/4.3"), |
3590 | }, | |
3591 | }, | |
3592 | - {} | |
3593 | + { NULL, NULL, {{0, NULL}}, NULL} | |
3594 | }; | |
3595 | ||
3596 | static int __init acpisleep_dmi_init(void) | |
4dee9bd5 | 3597 | diff -urNp linux-2.6.25.4/arch/x86/kernel/acpi/wakeup_32.S linux-2.6.25.4/arch/x86/kernel/acpi/wakeup_32.S |
3598 | --- linux-2.6.25.4/arch/x86/kernel/acpi/wakeup_32.S 2008-05-15 11:00:12.000000000 -0400 | |
3599 | +++ linux-2.6.25.4/arch/x86/kernel/acpi/wakeup_32.S 2008-05-18 13:33:14.000000000 -0400 | |
da5b3fc8 | 3600 | @@ -2,6 +2,7 @@ |
3601 | #include <linux/linkage.h> | |
3602 | #include <asm/segment.h> | |
3603 | #include <asm/page.h> | |
3604 | +#include <asm/msr-index.h> | |
3605 | ||
3606 | # | |
3607 | # wakeup_code runs in real mode, and at unknown address (determined at run-time). | |
3608 | @@ -79,7 +80,7 @@ wakeup_code: | |
3609 | # restore efer setting | |
3610 | movl real_save_efer_edx - wakeup_code, %edx | |
3611 | movl real_save_efer_eax - wakeup_code, %eax | |
3612 | - mov $0xc0000080, %ecx | |
3613 | + mov $MSR_EFER, %ecx | |
3614 | wrmsr | |
3615 | 4: | |
3616 | # make sure %cr4 is set correctly (features, etc) | |
3617 | @@ -196,13 +197,11 @@ wakeup_pmode_return: | |
3618 | # and restore the stack ... but you need gdt for this to work | |
3619 | movl saved_context_esp, %esp | |
3620 | ||
3621 | - movl %cs:saved_magic, %eax | |
3622 | - cmpl $0x12345678, %eax | |
3623 | + cmpl $0x12345678, saved_magic | |
3624 | jne bogus_magic | |
3625 | ||
3626 | # jump to place where we left off | |
3627 | - movl saved_eip,%eax | |
3628 | - jmp *%eax | |
3629 | + jmp *(saved_eip) | |
3630 | ||
3631 | bogus_magic: | |
3632 | jmp bogus_magic | |
3633 | @@ -233,7 +232,7 @@ ENTRY(acpi_copy_wakeup_routine) | |
3634 | # save efer setting | |
3635 | pushl %eax | |
3636 | movl %eax, %ebx | |
3637 | - mov $0xc0000080, %ecx | |
3638 | + mov $MSR_EFER, %ecx | |
3639 | rdmsr | |
3640 | movl %edx, real_save_efer_edx - wakeup_start (%ebx) | |
3641 | movl %eax, real_save_efer_eax - wakeup_start (%ebx) | |
4dee9bd5 | 3642 | diff -urNp linux-2.6.25.4/arch/x86/kernel/alternative.c linux-2.6.25.4/arch/x86/kernel/alternative.c |
3643 | --- linux-2.6.25.4/arch/x86/kernel/alternative.c 2008-05-15 11:00:12.000000000 -0400 | |
3644 | +++ linux-2.6.25.4/arch/x86/kernel/alternative.c 2008-05-18 13:33:14.000000000 -0400 | |
3645 | @@ -403,7 +403,7 @@ void apply_paravirt(struct paravirt_patc | |
b2ee8b1e | 3646 | |
3647 | BUG_ON(p->len > MAX_PATCH_LEN); | |
3648 | /* prep the buffer with the original instructions */ | |
3649 | - memcpy(insnbuf, p->instr, p->len); | |
3650 | + memcpy(insnbuf, ktla_ktva(p->instr), p->len); | |
3651 | used = pv_init_ops.patch(p->instrtype, p->clobbers, insnbuf, | |
3652 | (unsigned long)p->instr, p->len); | |
3653 | ||
4dee9bd5 | 3654 | @@ -485,7 +485,19 @@ void __init alternative_instructions(voi |
da5b3fc8 | 3655 | */ |
3656 | void __kprobes text_poke(void *addr, unsigned char *opcode, int len) | |
3657 | { | |
3658 | - memcpy(addr, opcode, len); | |
3659 | + | |
3660 | +#ifdef CONFIG_PAX_KERNEXEC | |
3661 | + unsigned long cr0; | |
3662 | + | |
3663 | + pax_open_kernel(cr0); | |
3664 | +#endif | |
3665 | + | |
3666 | + memcpy(ktla_ktva(addr), opcode, len); | |
3667 | + | |
3668 | +#ifdef CONFIG_PAX_KERNEXEC | |
3669 | + pax_close_kernel(cr0); | |
3670 | +#endif | |
3671 | + | |
3672 | sync_core(); | |
3673 | /* Could also do a CLFLUSH here to speed up CPU recovery; but | |
3674 | that causes hangs on some VIA CPUs. */ | |
4dee9bd5 | 3675 | diff -urNp linux-2.6.25.4/arch/x86/kernel/apm_32.c linux-2.6.25.4/arch/x86/kernel/apm_32.c |
3676 | --- linux-2.6.25.4/arch/x86/kernel/apm_32.c 2008-05-15 11:00:12.000000000 -0400 | |
3677 | +++ linux-2.6.25.4/arch/x86/kernel/apm_32.c 2008-05-18 13:33:14.000000000 -0400 | |
3678 | @@ -406,7 +406,7 @@ static DECLARE_WAIT_QUEUE_HEAD(apm_waitq | |
da5b3fc8 | 3679 | static DECLARE_WAIT_QUEUE_HEAD(apm_suspend_waitqueue); |
4dee9bd5 | 3680 | static struct apm_user *user_list; |
da5b3fc8 | 3681 | static DEFINE_SPINLOCK(user_list_lock); |
4dee9bd5 | 3682 | -static const struct desc_struct bad_bios_desc = { { { 0, 0x00409200 } } }; |
3683 | +static const struct desc_struct bad_bios_desc = { { { 0, 0x00409300 } } }; | |
da5b3fc8 | 3684 | |
4dee9bd5 | 3685 | static const char driver_version[] = "1.16ac"; /* no spaces */ |
da5b3fc8 | 3686 | |
3687 | @@ -601,19 +601,42 @@ static u8 apm_bios_call(u32 func, u32 eb | |
3688 | struct desc_struct save_desc_40; | |
3689 | struct desc_struct *gdt; | |
3690 | ||
3691 | +#ifdef CONFIG_PAX_KERNEXEC | |
3692 | + unsigned long cr0; | |
3693 | +#endif | |
3694 | + | |
3695 | cpus = apm_save_cpus(); | |
4dee9bd5 | 3696 | |
da5b3fc8 | 3697 | cpu = get_cpu(); |
3698 | gdt = get_cpu_gdt_table(cpu); | |
3699 | save_desc_40 = gdt[0x40 / 8]; | |
3700 | + | |
3701 | +#ifdef CONFIG_PAX_KERNEXEC | |
3702 | + pax_open_kernel(cr0); | |
3703 | +#endif | |
3704 | + | |
3705 | gdt[0x40 / 8] = bad_bios_desc; | |
3706 | ||
3707 | +#ifdef CONFIG_PAX_KERNEXEC | |
3708 | + pax_close_kernel(cr0); | |
3709 | +#endif | |
3710 | + | |
3711 | apm_irq_save(flags); | |
3712 | APM_DO_SAVE_SEGS; | |
3713 | apm_bios_call_asm(func, ebx_in, ecx_in, eax, ebx, ecx, edx, esi); | |
3714 | APM_DO_RESTORE_SEGS; | |
3715 | apm_irq_restore(flags); | |
3716 | + | |
3717 | +#ifdef CONFIG_PAX_KERNEXEC | |
3718 | + pax_open_kernel(cr0); | |
3719 | +#endif | |
3720 | + | |
3721 | gdt[0x40 / 8] = save_desc_40; | |
3722 | + | |
3723 | +#ifdef CONFIG_PAX_KERNEXEC | |
3724 | + pax_close_kernel(cr0); | |
3725 | +#endif | |
3726 | + | |
3727 | put_cpu(); | |
3728 | apm_restore_cpus(cpus); | |
4dee9bd5 | 3729 | |
da5b3fc8 | 3730 | @@ -644,19 +667,42 @@ static u8 apm_bios_call_simple(u32 func, |
3731 | struct desc_struct save_desc_40; | |
3732 | struct desc_struct *gdt; | |
3733 | ||
3734 | +#ifdef CONFIG_PAX_KERNEXEC | |
3735 | + unsigned long cr0; | |
3736 | +#endif | |
3737 | + | |
3738 | cpus = apm_save_cpus(); | |
4dee9bd5 | 3739 | |
da5b3fc8 | 3740 | cpu = get_cpu(); |
3741 | gdt = get_cpu_gdt_table(cpu); | |
3742 | save_desc_40 = gdt[0x40 / 8]; | |
3743 | + | |
3744 | +#ifdef CONFIG_PAX_KERNEXEC | |
3745 | + pax_open_kernel(cr0); | |
3746 | +#endif | |
3747 | + | |
3748 | gdt[0x40 / 8] = bad_bios_desc; | |
3749 | ||
3750 | +#ifdef CONFIG_PAX_KERNEXEC | |
3751 | + pax_close_kernel(cr0); | |
3752 | +#endif | |
3753 | + | |
3754 | apm_irq_save(flags); | |
3755 | APM_DO_SAVE_SEGS; | |
3756 | error = apm_bios_call_simple_asm(func, ebx_in, ecx_in, eax); | |
3757 | APM_DO_RESTORE_SEGS; | |
3758 | apm_irq_restore(flags); | |
3759 | + | |
3760 | +#ifdef CONFIG_PAX_KERNEXEC | |
3761 | + pax_open_kernel(cr0); | |
3762 | +#endif | |
3763 | + | |
3764 | gdt[0x40 / 8] = save_desc_40; | |
3765 | + | |
3766 | +#ifdef CONFIG_PAX_KERNEXEC | |
3767 | + pax_close_kernel(cr0); | |
3768 | +#endif | |
3769 | + | |
3770 | put_cpu(); | |
3771 | apm_restore_cpus(cpus); | |
3772 | return error; | |
4dee9bd5 | 3773 | @@ -925,7 +971,7 @@ recalc: |
3774 | ||
da5b3fc8 | 3775 | static void apm_power_off(void) |
3776 | { | |
4dee9bd5 | 3777 | - unsigned char po_bios_call[] = { |
3778 | + const unsigned char po_bios_call[] = { | |
da5b3fc8 | 3779 | 0xb8, 0x00, 0x10, /* movw $0x1000,ax */ |
3780 | 0x8e, 0xd0, /* movw ax,ss */ | |
3781 | 0xbc, 0x00, 0xf0, /* movw $0xf000,sp */ | |
4dee9bd5 | 3782 | @@ -1881,7 +1927,10 @@ static const struct file_operations apm_ |
da5b3fc8 | 3783 | static struct miscdevice apm_device = { |
3784 | APM_MINOR_DEV, | |
3785 | "apm_bios", | |
3786 | - &apm_bios_fops | |
3787 | + &apm_bios_fops, | |
3788 | + {NULL, NULL}, | |
3789 | + NULL, | |
3790 | + NULL | |
3791 | }; | |
3792 | ||
3793 | ||
4dee9bd5 | 3794 | @@ -2202,7 +2251,7 @@ static struct dmi_system_id __initdata a |
da5b3fc8 | 3795 | { DMI_MATCH(DMI_SYS_VENDOR, "IBM"), }, |
3796 | }, | |
3797 | ||
3798 | - { } | |
3799 | + { NULL, NULL, {DMI_MATCH(DMI_NONE, NULL)}, NULL} | |
3800 | }; | |
3801 | ||
3802 | /* | |
4dee9bd5 | 3803 | @@ -2221,6 +2270,10 @@ static int __init apm_init(void) |
da5b3fc8 | 3804 | struct desc_struct *gdt; |
3805 | int err; | |
3806 | ||
3807 | +#ifdef CONFIG_PAX_KERNEXEC | |
3808 | + unsigned long cr0; | |
3809 | +#endif | |
3810 | + | |
3811 | dmi_check_system(apm_dmi_table); | |
3812 | ||
3813 | if (apm_info.bios.version == 0 || paravirt_enabled()) { | |
4dee9bd5 | 3814 | @@ -2294,9 +2347,18 @@ static int __init apm_init(void) |
da5b3fc8 | 3815 | * This is for buggy BIOS's that refer to (real mode) segment 0x40 |
3816 | * even though they are called in protected mode. | |
3817 | */ | |
3818 | + | |
3819 | +#ifdef CONFIG_PAX_KERNEXEC | |
3820 | + pax_open_kernel(cr0); | |
3821 | +#endif | |
3822 | + | |
3823 | set_base(bad_bios_desc, __va((unsigned long)0x40 << 4)); | |
3824 | _set_limit((char *)&bad_bios_desc, 4095 - (0x40 << 4)); | |
3825 | ||
3826 | +#ifdef CONFIG_PAX_KERNEXEC | |
3827 | + pax_close_kernel(cr0); | |
3828 | +#endif | |
3829 | + | |
3830 | /* | |
3831 | * Set up the long jump entry point to the APM BIOS, which is called | |
3832 | * from inline assembly. | |
4dee9bd5 | 3833 | @@ -2315,6 +2377,11 @@ static int __init apm_init(void) |
da5b3fc8 | 3834 | * code to that CPU. |
3835 | */ | |
3836 | gdt = get_cpu_gdt_table(0); | |
3837 | + | |
3838 | +#ifdef CONFIG_PAX_KERNEXEC | |
3839 | + pax_open_kernel(cr0); | |
3840 | +#endif | |
3841 | + | |
3842 | set_base(gdt[APM_CS >> 3], | |
3843 | __va((unsigned long)apm_info.bios.cseg << 4)); | |
3844 | set_base(gdt[APM_CS_16 >> 3], | |
4dee9bd5 | 3845 | @@ -2322,6 +2389,10 @@ static int __init apm_init(void) |
da5b3fc8 | 3846 | set_base(gdt[APM_DS >> 3], |
3847 | __va((unsigned long)apm_info.bios.dseg << 4)); | |
3848 | ||
3849 | +#ifdef CONFIG_PAX_KERNEXEC | |
3850 | + pax_close_kernel(cr0); | |
3851 | +#endif | |
3852 | + | |
3853 | apm_proc = create_proc_entry("apm", 0, NULL); | |
3854 | if (apm_proc) | |
3855 | apm_proc->proc_fops = &apm_file_ops; | |
4dee9bd5 | 3856 | diff -urNp linux-2.6.25.4/arch/x86/kernel/asm-offsets_32.c linux-2.6.25.4/arch/x86/kernel/asm-offsets_32.c |
3857 | --- linux-2.6.25.4/arch/x86/kernel/asm-offsets_32.c 2008-05-15 11:00:12.000000000 -0400 | |
3858 | +++ linux-2.6.25.4/arch/x86/kernel/asm-offsets_32.c 2008-05-18 13:33:14.000000000 -0400 | |
3859 | @@ -107,6 +107,7 @@ void foo(void) | |
da5b3fc8 | 3860 | DEFINE(PTRS_PER_PTE, PTRS_PER_PTE); |
3861 | DEFINE(PTRS_PER_PMD, PTRS_PER_PMD); | |
3862 | DEFINE(PTRS_PER_PGD, PTRS_PER_PGD); | |
3863 | + DEFINE(PERCPU_MODULE_RESERVE, PERCPU_MODULE_RESERVE); | |
3864 | ||
4dee9bd5 | 3865 | OFFSET(crypto_tfm_ctx_offset, crypto_tfm, __crt_ctx); |
da5b3fc8 | 3866 | |
4dee9bd5 | 3867 | @@ -120,6 +121,7 @@ void foo(void) |
da5b3fc8 | 3868 | OFFSET(PV_CPU_iret, pv_cpu_ops, iret); |
4dee9bd5 | 3869 | OFFSET(PV_CPU_irq_enable_syscall_ret, pv_cpu_ops, irq_enable_syscall_ret); |
da5b3fc8 | 3870 | OFFSET(PV_CPU_read_cr0, pv_cpu_ops, read_cr0); |
3871 | + OFFSET(PV_CPU_write_cr0, pv_cpu_ops, write_cr0); | |
3872 | #endif | |
3873 | ||
3874 | #ifdef CONFIG_XEN | |
4dee9bd5 | 3875 | diff -urNp linux-2.6.25.4/arch/x86/kernel/asm-offsets_64.c linux-2.6.25.4/arch/x86/kernel/asm-offsets_64.c |
3876 | --- linux-2.6.25.4/arch/x86/kernel/asm-offsets_64.c 2008-05-15 11:00:12.000000000 -0400 | |
3877 | +++ linux-2.6.25.4/arch/x86/kernel/asm-offsets_64.c 2008-05-18 13:33:14.000000000 -0400 | |
3878 | @@ -124,6 +124,7 @@ int main(void) | |
da5b3fc8 | 3879 | ENTRY(cr8); |
3880 | BLANK(); | |
3881 | #undef ENTRY | |
3882 | + DEFINE(TSS_size, sizeof(struct tss_struct)); | |
4dee9bd5 | 3883 | DEFINE(TSS_ist, offsetof(struct tss_struct, x86_tss.ist)); |
da5b3fc8 | 3884 | BLANK(); |
3885 | DEFINE(crypto_tfm_ctx_offset, offsetof(struct crypto_tfm, __crt_ctx)); | |
4dee9bd5 | 3886 | diff -urNp linux-2.6.25.4/arch/x86/kernel/cpu/common.c linux-2.6.25.4/arch/x86/kernel/cpu/common.c |
3887 | --- linux-2.6.25.4/arch/x86/kernel/cpu/common.c 2008-05-15 11:00:12.000000000 -0400 | |
3888 | +++ linux-2.6.25.4/arch/x86/kernel/cpu/common.c 2008-05-18 13:33:14.000000000 -0400 | |
da5b3fc8 | 3889 | @@ -4,7 +4,6 @@ |
3890 | #include <linux/smp.h> | |
3891 | #include <linux/module.h> | |
3892 | #include <linux/percpu.h> | |
3893 | -#include <linux/bootmem.h> | |
3894 | #include <asm/semaphore.h> | |
3895 | #include <asm/processor.h> | |
3896 | #include <asm/i387.h> | |
4dee9bd5 | 3897 | @@ -21,42 +20,6 @@ |
da5b3fc8 | 3898 | |
3899 | #include "cpu.h" | |
3900 | ||
3901 | -DEFINE_PER_CPU(struct gdt_page, gdt_page) = { .gdt = { | |
4dee9bd5 | 3902 | - [GDT_ENTRY_KERNEL_CS] = { { { 0x0000ffff, 0x00cf9a00 } } }, |
3903 | - [GDT_ENTRY_KERNEL_DS] = { { { 0x0000ffff, 0x00cf9200 } } }, | |
3904 | - [GDT_ENTRY_DEFAULT_USER_CS] = { { { 0x0000ffff, 0x00cffa00 } } }, | |
3905 | - [GDT_ENTRY_DEFAULT_USER_DS] = { { { 0x0000ffff, 0x00cff200 } } }, | |
da5b3fc8 | 3906 | - /* |
3907 | - * Segments used for calling PnP BIOS have byte granularity. | |
3908 | - * They code segments and data segments have fixed 64k limits, | |
3909 | - * the transfer segment sizes are set at run time. | |
3910 | - */ | |
4dee9bd5 | 3911 | - /* 32-bit code */ |
3912 | - [GDT_ENTRY_PNPBIOS_CS32] = { { { 0x0000ffff, 0x00409a00 } } }, | |
3913 | - /* 16-bit code */ | |
3914 | - [GDT_ENTRY_PNPBIOS_CS16] = { { { 0x0000ffff, 0x00009a00 } } }, | |
3915 | - /* 16-bit data */ | |
3916 | - [GDT_ENTRY_PNPBIOS_DS] = { { { 0x0000ffff, 0x00009200 } } }, | |
3917 | - /* 16-bit data */ | |
3918 | - [GDT_ENTRY_PNPBIOS_TS1] = { { { 0x00000000, 0x00009200 } } }, | |
3919 | - /* 16-bit data */ | |
3920 | - [GDT_ENTRY_PNPBIOS_TS2] = { { { 0x00000000, 0x00009200 } } }, | |
da5b3fc8 | 3921 | - /* |
3922 | - * The APM segments have byte granularity and their bases | |
3923 | - * are set at run time. All have 64k limits. | |
3924 | - */ | |
4dee9bd5 | 3925 | - /* 32-bit code */ |
3926 | - [GDT_ENTRY_APMBIOS_BASE] = { { { 0x0000ffff, 0x00409a00 } } }, | |
da5b3fc8 | 3927 | - /* 16-bit code */ |
4dee9bd5 | 3928 | - [GDT_ENTRY_APMBIOS_BASE+1] = { { { 0x0000ffff, 0x00009a00 } } }, |
3929 | - /* data */ | |
3930 | - [GDT_ENTRY_APMBIOS_BASE+2] = { { { 0x0000ffff, 0x00409200 } } }, | |
da5b3fc8 | 3931 | - |
4dee9bd5 | 3932 | - [GDT_ENTRY_ESPFIX_SS] = { { { 0x00000000, 0x00c09200 } } }, |
3933 | - [GDT_ENTRY_PERCPU] = { { { 0x00000000, 0x00000000 } } }, | |
da5b3fc8 | 3934 | -} }; |
3935 | -EXPORT_PER_CPU_SYMBOL_GPL(gdt_page); | |
3936 | - | |
4dee9bd5 | 3937 | __u32 cleared_cpu_caps[NCAPINTS] __cpuinitdata; |
3938 | ||
da5b3fc8 | 3939 | static int cachesize_override __cpuinitdata = -1; |
4dee9bd5 | 3940 | @@ -478,6 +441,10 @@ void __cpuinit identify_cpu(struct cpuin |
3941 | * we do "generic changes." | |
3942 | */ | |
3943 | ||
3944 | +#if defined(CONFIG_PAX_SEGMEXEC) || defined(CONFIG_PAX_KERNEXEC) || defined(CONFIG_PAX_MEMORY_UDEREF) | |
3945 | + setup_clear_cpu_cap(X86_FEATURE_SEP); | |
da5b3fc8 | 3946 | +#endif |
4dee9bd5 | 3947 | + |
3948 | /* If the model name is still unset, do table lookup. */ | |
3949 | if ( !c->x86_model_id[0] ) { | |
3950 | char *p; | |
3951 | @@ -614,7 +581,7 @@ static __init int setup_disablecpuid(cha | |
3952 | } | |
3953 | __setup("clearcpuid=", setup_disablecpuid); | |
da5b3fc8 | 3954 | |
4dee9bd5 | 3955 | -cpumask_t cpu_initialized __cpuinitdata = CPU_MASK_NONE; |
3956 | +cpumask_t cpu_initialized = CPU_MASK_NONE; | |
da5b3fc8 | 3957 | |
4dee9bd5 | 3958 | /* This is hacky. :) |
3959 | * We're emulating future behavior. | |
3960 | @@ -650,7 +617,7 @@ void switch_to_new_gdt(void) | |
50425a20 | 3961 | { |
4dee9bd5 | 3962 | struct desc_ptr gdt_descr; |
da5b3fc8 | 3963 | |
3964 | - gdt_descr.address = (long)get_cpu_gdt_table(smp_processor_id()); | |
4dee9bd5 | 3965 | + gdt_descr.address = (unsigned long)get_cpu_gdt_table(smp_processor_id()); |
da5b3fc8 | 3966 | gdt_descr.size = GDT_SIZE - 1; |
3967 | load_gdt(&gdt_descr); | |
3968 | asm("mov %0, %%fs" : : "r" (__KERNEL_PERCPU) : "memory"); | |
4dee9bd5 | 3969 | @@ -666,7 +633,7 @@ void __cpuinit cpu_init(void) |
da5b3fc8 | 3970 | { |
3971 | int cpu = smp_processor_id(); | |
3972 | struct task_struct *curr = current; | |
3973 | - struct tss_struct * t = &per_cpu(init_tss, cpu); | |
3974 | + struct tss_struct *t = init_tss + cpu; | |
3975 | struct thread_struct *thread = &curr->thread; | |
3976 | ||
3977 | if (cpu_test_and_set(cpu, cpu_initialized)) { | |
4dee9bd5 | 3978 | @@ -721,7 +688,7 @@ void __cpuinit cpu_init(void) |
3979 | } | |
3980 | ||
3981 | #ifdef CONFIG_HOTPLUG_CPU | |
3982 | -void __cpuinit cpu_uninit(void) | |
3983 | +void cpu_uninit(void) | |
3984 | { | |
3985 | int cpu = raw_smp_processor_id(); | |
3986 | cpu_clear(cpu, cpu_initialized); | |
3987 | diff -urNp linux-2.6.25.4/arch/x86/kernel/cpu/cpufreq/acpi-cpufreq.c linux-2.6.25.4/arch/x86/kernel/cpu/cpufreq/acpi-cpufreq.c | |
3988 | --- linux-2.6.25.4/arch/x86/kernel/cpu/cpufreq/acpi-cpufreq.c 2008-05-15 11:00:12.000000000 -0400 | |
3989 | +++ linux-2.6.25.4/arch/x86/kernel/cpu/cpufreq/acpi-cpufreq.c 2008-05-18 13:33:14.000000000 -0400 | |
3990 | @@ -550,7 +550,7 @@ static const struct dmi_system_id sw_any | |
da5b3fc8 | 3991 | DMI_MATCH(DMI_PRODUCT_NAME, "X6DLP"), |
3992 | }, | |
3993 | }, | |
3994 | - { } | |
3995 | + { NULL, NULL, {DMI_MATCH(DMI_NONE, NULL)}, NULL } | |
3996 | }; | |
3997 | #endif | |
3998 | ||
4dee9bd5 | 3999 | diff -urNp linux-2.6.25.4/arch/x86/kernel/cpu/cpufreq/speedstep-centrino.c linux-2.6.25.4/arch/x86/kernel/cpu/cpufreq/speedstep-centrino.c |
4000 | --- linux-2.6.25.4/arch/x86/kernel/cpu/cpufreq/speedstep-centrino.c 2008-05-15 11:00:12.000000000 -0400 | |
4001 | +++ linux-2.6.25.4/arch/x86/kernel/cpu/cpufreq/speedstep-centrino.c 2008-05-18 13:33:14.000000000 -0400 | |
da5b3fc8 | 4002 | @@ -223,7 +223,7 @@ static struct cpu_model models[] = |
4003 | { &cpu_ids[CPU_MP4HT_D0], NULL, 0, NULL }, | |
4004 | { &cpu_ids[CPU_MP4HT_E0], NULL, 0, NULL }, | |
4005 | ||
4006 | - { NULL, } | |
4007 | + { NULL, NULL, 0, NULL} | |
4008 | }; | |
4009 | #undef _BANIAS | |
4010 | #undef BANIAS | |
4dee9bd5 | 4011 | diff -urNp linux-2.6.25.4/arch/x86/kernel/cpu/intel.c linux-2.6.25.4/arch/x86/kernel/cpu/intel.c |
4012 | --- linux-2.6.25.4/arch/x86/kernel/cpu/intel.c 2008-05-15 11:00:12.000000000 -0400 | |
4013 | +++ linux-2.6.25.4/arch/x86/kernel/cpu/intel.c 2008-05-18 13:33:14.000000000 -0400 | |
4014 | @@ -108,6 +108,7 @@ static void __cpuinit trap_init_f00f_bug | |
da5b3fc8 | 4015 | * it uses the read-only mapped virtual address. |
4016 | */ | |
4017 | idt_descr.address = fix_to_virt(FIX_F00F_IDT); | |
4018 | + idt_descr.address = (struct desc_struct *)fix_to_virt(FIX_F00F_IDT); | |
4019 | load_idt(&idt_descr); | |
8a4b4a5e | 4020 | } |
da5b3fc8 | 4021 | #endif |
4dee9bd5 | 4022 | diff -urNp linux-2.6.25.4/arch/x86/kernel/cpu/mcheck/mce_64.c linux-2.6.25.4/arch/x86/kernel/cpu/mcheck/mce_64.c |
4023 | --- linux-2.6.25.4/arch/x86/kernel/cpu/mcheck/mce_64.c 2008-05-15 11:00:12.000000000 -0400 | |
4024 | +++ linux-2.6.25.4/arch/x86/kernel/cpu/mcheck/mce_64.c 2008-05-18 13:33:14.000000000 -0400 | |
4025 | @@ -670,6 +670,7 @@ static struct miscdevice mce_log_device | |
da5b3fc8 | 4026 | MISC_MCELOG_MINOR, |
4027 | "mcelog", | |
4028 | &mce_chrdev_ops, | |
4029 | + {NULL, NULL}, NULL, NULL | |
4030 | }; | |
4031 | ||
4032 | static unsigned long old_cr4 __initdata; | |
4dee9bd5 | 4033 | diff -urNp linux-2.6.25.4/arch/x86/kernel/cpu/mtrr/generic.c linux-2.6.25.4/arch/x86/kernel/cpu/mtrr/generic.c |
4034 | --- linux-2.6.25.4/arch/x86/kernel/cpu/mtrr/generic.c 2008-05-15 11:00:12.000000000 -0400 | |
4035 | +++ linux-2.6.25.4/arch/x86/kernel/cpu/mtrr/generic.c 2008-05-18 13:33:14.000000000 -0400 | |
4036 | @@ -30,11 +30,11 @@ static struct fixed_range_block fixed_ra | |
da5b3fc8 | 4037 | { MTRRfix64K_00000_MSR, 1 }, /* one 64k MTRR */ |
4038 | { MTRRfix16K_80000_MSR, 2 }, /* two 16k MTRRs */ | |
4039 | { MTRRfix4K_C0000_MSR, 8 }, /* eight 4k MTRRs */ | |
4040 | - {} | |
4041 | + { 0, 0 } | |
4042 | }; | |
4043 | ||
4044 | static unsigned long smp_changes_mask; | |
4045 | -static struct mtrr_state mtrr_state = {}; | |
4046 | +static struct mtrr_state mtrr_state; | |
4047 | ||
4048 | #undef MODULE_PARAM_PREFIX | |
4049 | #define MODULE_PARAM_PREFIX "mtrr." | |
4dee9bd5 | 4050 | diff -urNp linux-2.6.25.4/arch/x86/kernel/crash.c linux-2.6.25.4/arch/x86/kernel/crash.c |
4051 | --- linux-2.6.25.4/arch/x86/kernel/crash.c 2008-05-15 11:00:12.000000000 -0400 | |
4052 | +++ linux-2.6.25.4/arch/x86/kernel/crash.c 2008-05-18 13:33:14.000000000 -0400 | |
da5b3fc8 | 4053 | @@ -62,7 +62,7 @@ static int crash_nmi_callback(struct not |
4054 | local_irq_disable(); | |
4055 | ||
4056 | #ifdef CONFIG_X86_32 | |
4057 | - if (!user_mode_vm(regs)) { | |
4058 | + if (!user_mode(regs)) { | |
4059 | crash_fixup_ss_esp(&fixed_regs, regs); | |
4060 | regs = &fixed_regs; | |
4061 | } | |
4dee9bd5 | 4062 | diff -urNp linux-2.6.25.4/arch/x86/kernel/doublefault_32.c linux-2.6.25.4/arch/x86/kernel/doublefault_32.c |
4063 | --- linux-2.6.25.4/arch/x86/kernel/doublefault_32.c 2008-05-15 11:00:12.000000000 -0400 | |
4064 | +++ linux-2.6.25.4/arch/x86/kernel/doublefault_32.c 2008-05-18 13:33:14.000000000 -0400 | |
4065 | @@ -11,7 +11,7 @@ | |
da5b3fc8 | 4066 | |
4067 | #define DOUBLEFAULT_STACKSIZE (1024) | |
4068 | static unsigned long doublefault_stack[DOUBLEFAULT_STACKSIZE]; | |
4069 | -#define STACK_START (unsigned long)(doublefault_stack+DOUBLEFAULT_STACKSIZE) | |
4070 | +#define STACK_START (unsigned long)(doublefault_stack+DOUBLEFAULT_STACKSIZE-2) | |
4071 | ||
4072 | #define ptr_ok(x) ((x) > PAGE_OFFSET && (x) < PAGE_OFFSET + MAXMEM) | |
4073 | ||
4dee9bd5 | 4074 | @@ -21,7 +21,7 @@ static void doublefault_fn(void) |
da5b3fc8 | 4075 | unsigned long gdt, tss; |
50425a20 | 4076 | |
da5b3fc8 | 4077 | store_gdt(&gdt_desc); |
4078 | - gdt = gdt_desc.address; | |
4079 | + gdt = (unsigned long)gdt_desc.address; | |
4080 | ||
4081 | printk(KERN_EMERG "PANIC: double fault, gdt at %08lx [%d bytes]\n", gdt, gdt_desc.size); | |
4082 | ||
4dee9bd5 | 4083 | @@ -60,10 +60,10 @@ struct tss_struct doublefault_tss __cach |
da5b3fc8 | 4084 | /* 0x2 bit is always set */ |
4dee9bd5 | 4085 | .flags = X86_EFLAGS_SF | 0x2, |
4086 | .sp = STACK_START, | |
da5b3fc8 | 4087 | - .es = __USER_DS, |
4088 | + .es = __KERNEL_DS, | |
4089 | .cs = __KERNEL_CS, | |
4090 | .ss = __KERNEL_DS, | |
4091 | - .ds = __USER_DS, | |
4092 | + .ds = __KERNEL_DS, | |
4093 | .fs = __KERNEL_PERCPU, | |
4094 | ||
4095 | .__cr3 = __pa(swapper_pg_dir) | |
4dee9bd5 | 4096 | diff -urNp linux-2.6.25.4/arch/x86/kernel/efi_32.c linux-2.6.25.4/arch/x86/kernel/efi_32.c |
4097 | --- linux-2.6.25.4/arch/x86/kernel/efi_32.c 2008-05-15 11:00:12.000000000 -0400 | |
4098 | +++ linux-2.6.25.4/arch/x86/kernel/efi_32.c 2008-05-18 13:33:14.000000000 -0400 | |
4099 | @@ -38,70 +38,37 @@ | |
4100 | */ | |
da5b3fc8 | 4101 | |
4102 | static unsigned long efi_rt_eflags; | |
da5b3fc8 | 4103 | -static pgd_t efi_bak_pg_dir_pointer[2]; |
4104 | +static pgd_t __initdata efi_bak_pg_dir_pointer[KERNEL_PGD_PTRS] __attribute__ ((aligned (4096))); | |
4105 | ||
4dee9bd5 | 4106 | -void efi_call_phys_prelog(void) |
4107 | +void __init efi_call_phys_prelog(void) | |
da5b3fc8 | 4108 | { |
4109 | - unsigned long cr4; | |
4110 | - unsigned long temp; | |
4dee9bd5 | 4111 | struct desc_ptr gdt_descr; |
da5b3fc8 | 4112 | |
da5b3fc8 | 4113 | local_irq_save(efi_rt_eflags); |
4114 | ||
4115 | - /* | |
4116 | - * If I don't have PSE, I should just duplicate two entries in page | |
4117 | - * directory. If I have PSE, I just need to duplicate one entry in | |
4118 | - * page directory. | |
4119 | - */ | |
4120 | - cr4 = read_cr4(); | |
4121 | - | |
4122 | - if (cr4 & X86_CR4_PSE) { | |
4123 | - efi_bak_pg_dir_pointer[0].pgd = | |
4124 | - swapper_pg_dir[pgd_index(0)].pgd; | |
4125 | - swapper_pg_dir[0].pgd = | |
4126 | - swapper_pg_dir[pgd_index(PAGE_OFFSET)].pgd; | |
4127 | - } else { | |
4128 | - efi_bak_pg_dir_pointer[0].pgd = | |
4129 | - swapper_pg_dir[pgd_index(0)].pgd; | |
4130 | - efi_bak_pg_dir_pointer[1].pgd = | |
4131 | - swapper_pg_dir[pgd_index(0x400000)].pgd; | |
4132 | - swapper_pg_dir[pgd_index(0)].pgd = | |
4133 | - swapper_pg_dir[pgd_index(PAGE_OFFSET)].pgd; | |
4134 | - temp = PAGE_OFFSET + 0x400000; | |
4135 | - swapper_pg_dir[pgd_index(0x400000)].pgd = | |
4136 | - swapper_pg_dir[pgd_index(temp)].pgd; | |
4137 | - } | |
4138 | + clone_pgd_range(efi_bak_pg_dir_pointer, swapper_pg_dir, KERNEL_PGD_PTRS); | |
4139 | + clone_pgd_range(swapper_pg_dir, swapper_pg_dir + USER_PGD_PTRS, | |
4140 | + min_t(unsigned long, KERNEL_PGD_PTRS, USER_PGD_PTRS)); | |
4141 | ||
4142 | /* | |
4143 | * After the lock is released, the original page table is restored. | |
b2ee8b1e | 4144 | */ |
4dee9bd5 | 4145 | __flush_tlb_all(); |
b2ee8b1e | 4146 | |
4147 | - gdt_descr.address = __pa(get_cpu_gdt_table(0)); | |
4148 | + gdt_descr.address = (struct desc_struct *)__pa(get_cpu_gdt_table(0)); | |
4149 | gdt_descr.size = GDT_SIZE - 1; | |
4150 | load_gdt(&gdt_descr); | |
4151 | } | |
da5b3fc8 | 4152 | |
4dee9bd5 | 4153 | -void efi_call_phys_epilog(void) |
4154 | +void __init efi_call_phys_epilog(void) | |
da5b3fc8 | 4155 | { |
4156 | - unsigned long cr4; | |
4dee9bd5 | 4157 | struct desc_ptr gdt_descr; |
da5b3fc8 | 4158 | |
4159 | - gdt_descr.address = (unsigned long)get_cpu_gdt_table(0); | |
4160 | + gdt_descr.address = get_cpu_gdt_table(0); | |
4161 | gdt_descr.size = GDT_SIZE - 1; | |
4162 | load_gdt(&gdt_descr); | |
4163 | ||
4164 | - cr4 = read_cr4(); | |
4165 | - | |
4166 | - if (cr4 & X86_CR4_PSE) { | |
4167 | - swapper_pg_dir[pgd_index(0)].pgd = | |
4168 | - efi_bak_pg_dir_pointer[0].pgd; | |
4169 | - } else { | |
4170 | - swapper_pg_dir[pgd_index(0)].pgd = | |
4171 | - efi_bak_pg_dir_pointer[0].pgd; | |
4172 | - swapper_pg_dir[pgd_index(0x400000)].pgd = | |
4173 | - efi_bak_pg_dir_pointer[1].pgd; | |
4174 | - } | |
4175 | + clone_pgd_range(swapper_pg_dir, efi_bak_pg_dir_pointer, KERNEL_PGD_PTRS); | |
4176 | ||
4177 | /* | |
4178 | * After the lock is released, the original page table is restored. | |
4dee9bd5 | 4179 | diff -urNp linux-2.6.25.4/arch/x86/kernel/efi_stub_32.S linux-2.6.25.4/arch/x86/kernel/efi_stub_32.S |
4180 | --- linux-2.6.25.4/arch/x86/kernel/efi_stub_32.S 2008-05-15 11:00:12.000000000 -0400 | |
4181 | +++ linux-2.6.25.4/arch/x86/kernel/efi_stub_32.S 2008-05-18 13:33:14.000000000 -0400 | |
da5b3fc8 | 4182 | @@ -6,6 +6,7 @@ |
4183 | */ | |
4184 | ||
4185 | #include <linux/linkage.h> | |
4186 | +#include <linux/init.h> | |
4187 | #include <asm/page.h> | |
4188 | ||
4189 | /* | |
4190 | @@ -20,7 +21,7 @@ | |
4191 | * service functions will comply with gcc calling convention, too. | |
4192 | */ | |
4193 | ||
4194 | -.text | |
4195 | +__INIT | |
4196 | ENTRY(efi_call_phys) | |
4197 | /* | |
4198 | * 0. The function can only be called in Linux kernel. So CS has been | |
4199 | @@ -36,9 +37,7 @@ ENTRY(efi_call_phys) | |
4200 | * The mapping of lower virtual memory has been created in prelog and | |
4201 | * epilog. | |
4202 | */ | |
4203 | - movl $1f, %edx | |
4204 | - subl $__PAGE_OFFSET, %edx | |
4205 | - jmp *%edx | |
4206 | + jmp 1f-__PAGE_OFFSET | |
4207 | 1: | |
4208 | ||
4209 | /* | |
4210 | @@ -47,14 +46,8 @@ ENTRY(efi_call_phys) | |
4211 | * parameter 2, ..., param n. To make things easy, we save the return | |
4212 | * address of efi_call_phys in a global variable. | |
4213 | */ | |
4214 | - popl %edx | |
4215 | - movl %edx, saved_return_addr | |
4216 | - /* get the function pointer into ECX*/ | |
4217 | - popl %ecx | |
4218 | - movl %ecx, efi_rt_function_ptr | |
4219 | - movl $2f, %edx | |
4220 | - subl $__PAGE_OFFSET, %edx | |
4221 | - pushl %edx | |
4222 | + popl (saved_return_addr) | |
4223 | + popl (efi_rt_function_ptr) | |
4224 | ||
4225 | /* | |
4226 | * 3. Clear PG bit in %CR0. | |
4227 | @@ -73,9 +66,8 @@ ENTRY(efi_call_phys) | |
4228 | /* | |
4229 | * 5. Call the physical function. | |
4230 | */ | |
4231 | - jmp *%ecx | |
4232 | + call *(efi_rt_function_ptr-__PAGE_OFFSET) | |
4233 | ||
4234 | -2: | |
4235 | /* | |
4236 | * 6. After EFI runtime service returns, control will return to | |
4237 | * following instruction. We'd better readjust stack pointer first. | |
4238 | @@ -88,34 +80,27 @@ ENTRY(efi_call_phys) | |
4239 | movl %cr0, %edx | |
4240 | orl $0x80000000, %edx | |
4241 | movl %edx, %cr0 | |
4242 | - jmp 1f | |
4243 | -1: | |
4244 | + | |
4245 | /* | |
4246 | * 8. Now restore the virtual mode from flat mode by | |
4247 | * adding EIP with PAGE_OFFSET. | |
4248 | */ | |
4249 | - movl $1f, %edx | |
4250 | - jmp *%edx | |
4251 | + jmp 1f+__PAGE_OFFSET | |
4252 | 1: | |
4253 | ||
4254 | /* | |
4255 | * 9. Balance the stack. And because EAX contain the return value, | |
4256 | * we'd better not clobber it. | |
4257 | */ | |
4258 | - leal efi_rt_function_ptr, %edx | |
4259 | - movl (%edx), %ecx | |
4260 | - pushl %ecx | |
4261 | + pushl (efi_rt_function_ptr) | |
4262 | ||
4263 | /* | |
4264 | - * 10. Push the saved return address onto the stack and return. | |
4265 | + * 10. Return to the saved return address. | |
4266 | */ | |
4267 | - leal saved_return_addr, %edx | |
4268 | - movl (%edx), %ecx | |
4269 | - pushl %ecx | |
4270 | - ret | |
4271 | + jmpl *(saved_return_addr) | |
4272 | .previous | |
4273 | ||
4274 | -.data | |
4275 | +__INITDATA | |
4276 | saved_return_addr: | |
4277 | .long 0 | |
4278 | efi_rt_function_ptr: | |
4dee9bd5 | 4279 | diff -urNp linux-2.6.25.4/arch/x86/kernel/entry_32.S linux-2.6.25.4/arch/x86/kernel/entry_32.S |
4280 | --- linux-2.6.25.4/arch/x86/kernel/entry_32.S 2008-05-15 11:00:12.000000000 -0400 | |
4281 | +++ linux-2.6.25.4/arch/x86/kernel/entry_32.S 2008-05-18 13:33:14.000000000 -0400 | |
da5b3fc8 | 4282 | @@ -97,7 +97,7 @@ VM_MASK = 0x00020000 |
4283 | #define resume_userspace_sig resume_userspace | |
4284 | #endif | |
4285 | ||
4286 | -#define SAVE_ALL \ | |
4287 | +#define __SAVE_ALL(_DS) \ | |
4288 | cld; \ | |
4289 | pushl %fs; \ | |
4290 | CFI_ADJUST_CFA_OFFSET 4;\ | |
4291 | @@ -129,12 +129,26 @@ VM_MASK = 0x00020000 | |
4292 | pushl %ebx; \ | |
4293 | CFI_ADJUST_CFA_OFFSET 4;\ | |
4294 | CFI_REL_OFFSET ebx, 0;\ | |
4295 | - movl $(__USER_DS), %edx; \ | |
4296 | + movl $(_DS), %edx; \ | |
4297 | movl %edx, %ds; \ | |
4298 | movl %edx, %es; \ | |
4299 | movl $(__KERNEL_PERCPU), %edx; \ | |
4300 | movl %edx, %fs | |
4301 | ||
4302 | +#ifdef CONFIG_PAX_KERNEXEC | |
4303 | +#define SAVE_ALL \ | |
4304 | + __SAVE_ALL(__KERNEL_DS); \ | |
4305 | + GET_CR0_INTO_EDX; \ | |
4306 | + movl %edx, %esi; \ | |
4307 | + orl $X86_CR0_WP, %edx; \ | |
4308 | + xorl %edx, %esi; \ | |
4309 | + SET_CR0_FROM_EDX | |
4310 | +#elif defined(CONFIG_PAX_PAGEEXEC) || defined(CONFIG_PAX_SEGMEXEC) || defined(CONFIG_PAX_MEMORY_UDEREF) | |
4311 | +#define SAVE_ALL __SAVE_ALL(__KERNEL_DS) | |
4312 | +#else | |
4313 | +#define SAVE_ALL __SAVE_ALL(__USER_DS) | |
4314 | +#endif | |
4315 | + | |
4316 | #define RESTORE_INT_REGS \ | |
4317 | popl %ebx; \ | |
4318 | CFI_ADJUST_CFA_OFFSET -4;\ | |
4319 | @@ -248,7 +262,17 @@ check_userspace: | |
4320 | movb PT_CS(%esp), %al | |
4321 | andl $(VM_MASK | SEGMENT_RPL_MASK), %eax | |
4322 | cmpl $USER_RPL, %eax | |
4323 | + | |
4324 | +#ifdef CONFIG_PAX_KERNEXEC | |
4325 | + jae resume_userspace | |
4326 | + | |
4327 | + GET_CR0_INTO_EDX | |
4328 | + xorl %esi, %edx | |
4329 | + SET_CR0_FROM_EDX | |
4330 | + jmp resume_kernel | |
4331 | +#else | |
4332 | jb resume_kernel # not returning to v8086 or userspace | |
4333 | +#endif | |
4334 | ||
4335 | ENTRY(resume_userspace) | |
4336 | LOCKDEP_SYS_EXIT | |
4337 | @@ -308,10 +332,9 @@ sysenter_past_esp: | |
4338 | /*CFI_REL_OFFSET cs, 0*/ | |
4339 | /* | |
4340 | * Push current_thread_info()->sysenter_return to the stack. | |
4341 | - * A tiny bit of offset fixup is necessary - 4*4 means the 4 words | |
4342 | - * pushed above; +8 corresponds to copy_thread's esp0 setting. | |
4343 | */ | |
4344 | - pushl (TI_sysenter_return-THREAD_SIZE+8+4*4)(%esp) | |
4345 | + GET_THREAD_INFO(%ebp) | |
4346 | + pushl TI_sysenter_return(%ebp) | |
4347 | CFI_ADJUST_CFA_OFFSET 4 | |
4348 | CFI_REL_OFFSET eip, 0 | |
4349 | ||
4350 | @@ -319,9 +342,17 @@ sysenter_past_esp: | |
4351 | * Load the potential sixth argument from user stack. | |
4352 | * Careful about security. | |
4353 | */ | |
4354 | + movl 12(%esp),%ebp | |
4355 | + | |
4356 | +#ifdef CONFIG_PAX_MEMORY_UDEREF | |
4357 | + mov 16(%esp),%ds | |
4358 | +1: movl %ds:(%ebp),%ebp | |
4359 | +#else | |
4360 | cmpl $__PAGE_OFFSET-3,%ebp | |
4361 | jae syscall_fault | |
4362 | 1: movl (%ebp),%ebp | |
4363 | +#endif | |
4364 | + | |
4365 | .section __ex_table,"a" | |
4366 | .align 4 | |
4367 | .long 1b,syscall_fault | |
4368 | @@ -345,20 +376,37 @@ sysenter_past_esp: | |
4369 | movl TI_flags(%ebp), %ecx | |
4370 | testw $_TIF_ALLWORK_MASK, %cx | |
4371 | jne syscall_exit_work | |
4372 | + | |
4373 | +#ifdef CONFIG_PAX_RANDKSTACK | |
4374 | + pushl %eax | |
4375 | + CFI_ADJUST_CFA_OFFSET 4 | |
4376 | + call pax_randomize_kstack | |
4377 | + popl %eax | |
4378 | + CFI_ADJUST_CFA_OFFSET -4 | |
4379 | +#endif | |
4380 | + | |
4381 | /* if something modifies registers it must also disable sysexit */ | |
4382 | movl PT_EIP(%esp), %edx | |
4383 | movl PT_OLDESP(%esp), %ecx | |
4384 | xorl %ebp,%ebp | |
4385 | TRACE_IRQS_ON | |
4386 | 1: mov PT_FS(%esp), %fs | |
4387 | +2: mov PT_DS(%esp), %ds | |
4388 | +3: mov PT_ES(%esp), %es | |
4dee9bd5 | 4389 | ENABLE_INTERRUPTS_SYSCALL_RET |
da5b3fc8 | 4390 | CFI_ENDPROC |
4391 | .pushsection .fixup,"ax" | |
4392 | -2: movl $0,PT_FS(%esp) | |
4393 | +4: movl $0,PT_FS(%esp) | |
4dee9bd5 | 4394 | + jmp 1b |
da5b3fc8 | 4395 | +5: movl $0,PT_DS(%esp) |
4dee9bd5 | 4396 | + jmp 1b |
da5b3fc8 | 4397 | +6: movl $0,PT_ES(%esp) |
4dee9bd5 | 4398 | jmp 1b |
da5b3fc8 | 4399 | .section __ex_table,"a" |
4400 | .align 4 | |
4401 | - .long 1b,2b | |
4402 | + .long 1b,4b | |
4403 | + .long 2b,5b | |
4404 | + .long 3b,6b | |
4405 | .popsection | |
4dee9bd5 | 4406 | ENDPROC(ia32_sysenter_target) |
da5b3fc8 | 4407 | |
4408 | @@ -392,6 +440,10 @@ no_singlestep: | |
4409 | testw $_TIF_ALLWORK_MASK, %cx # current->work | |
4410 | jne syscall_exit_work | |
4411 | ||
4412 | +#ifdef CONFIG_PAX_RANDKSTACK | |
4413 | + call pax_randomize_kstack | |
4414 | +#endif | |
4415 | + | |
4416 | restore_all: | |
4417 | movl PT_EFLAGS(%esp), %eax # mix EFLAGS, SS and CS | |
4418 | # Warning: PT_OLDSS(%esp) contains the wrong/random values if we | |
4dee9bd5 | 4419 | @@ -557,17 +609,24 @@ syscall_badsys: |
da5b3fc8 | 4420 | END(syscall_badsys) |
4421 | CFI_ENDPROC | |
4422 | ||
4423 | -#define FIXUP_ESPFIX_STACK \ | |
4424 | - /* since we are on a wrong stack, we cant make it a C code :( */ \ | |
4425 | - PER_CPU(gdt_page, %ebx); \ | |
4426 | - GET_DESC_BASE(GDT_ENTRY_ESPFIX_SS, %ebx, %eax, %ax, %al, %ah); \ | |
4427 | - addl %esp, %eax; \ | |
4428 | - pushl $__KERNEL_DS; \ | |
4429 | - CFI_ADJUST_CFA_OFFSET 4; \ | |
4430 | - pushl %eax; \ | |
4431 | - CFI_ADJUST_CFA_OFFSET 4; \ | |
4432 | - lss (%esp), %esp; \ | |
4433 | +.macro FIXUP_ESPFIX_STACK | |
4434 | + /* since we are on a wrong stack, we cant make it a C code :( */ | |
4435 | +#ifdef CONFIG_SMP | |
4436 | + movl PER_CPU_VAR(cpu_number), %ebx; | |
4437 | + shll $PAGE_SHIFT_asm, %ebx; | |
4438 | + addl $cpu_gdt_table, %ebx; | |
4439 | +#else | |
4440 | + movl $cpu_gdt_table, %ebx; | |
4441 | +#endif | |
4442 | + GET_DESC_BASE(GDT_ENTRY_ESPFIX_SS, %ebx, %eax, %ax, %al, %ah); | |
4443 | + addl %esp, %eax; | |
4444 | + pushl $__KERNEL_DS; | |
4445 | + CFI_ADJUST_CFA_OFFSET 4; | |
4446 | + pushl %eax; | |
4447 | + CFI_ADJUST_CFA_OFFSET 4; | |
4448 | + lss (%esp), %esp; | |
4449 | CFI_ADJUST_CFA_OFFSET -8; | |
4450 | +.endm | |
4451 | #define UNWIND_ESPFIX_STACK \ | |
4452 | movl %ss, %eax; \ | |
4453 | /* see if on espfix stack */ \ | |
4dee9bd5 | 4454 | @@ -584,7 +643,7 @@ END(syscall_badsys) |
da5b3fc8 | 4455 | * Build the entry stubs and pointer table with |
4456 | * some assembler magic. | |
50425a20 | 4457 | */ |
4dee9bd5 | 4458 | -.section .rodata,"a" |
da5b3fc8 | 4459 | +.section .rodata,"a",@progbits |
4460 | ENTRY(interrupt) | |
4461 | .text | |
50425a20 | 4462 | |
4dee9bd5 | 4463 | @@ -684,12 +743,21 @@ error_code: |
da5b3fc8 | 4464 | popl %ecx |
4465 | CFI_ADJUST_CFA_OFFSET -4 | |
4466 | /*CFI_REGISTER es, ecx*/ | |
4467 | + | |
4468 | +#ifdef CONFIG_PAX_KERNEXEC | |
4469 | + GET_CR0_INTO_EDX | |
4470 | + movl %edx, %esi | |
4471 | + orl $X86_CR0_WP, %edx | |
4472 | + xorl %edx, %esi | |
4473 | + SET_CR0_FROM_EDX | |
4474 | +#endif | |
50425a20 | 4475 | + |
da5b3fc8 | 4476 | movl PT_FS(%esp), %edi # get the function address |
4477 | movl PT_ORIG_EAX(%esp), %edx # get the error code | |
4478 | movl $-1, PT_ORIG_EAX(%esp) # no syscall to restart | |
4479 | mov %ecx, PT_FS(%esp) | |
4480 | /*CFI_REL_OFFSET fs, ES*/ | |
4481 | - movl $(__USER_DS), %ecx | |
4482 | + movl $(__KERNEL_DS), %ecx | |
4483 | movl %ecx, %ds | |
4484 | movl %ecx, %es | |
4485 | movl %esp,%eax # pt_regs pointer | |
4dee9bd5 | 4486 | @@ -823,6 +891,13 @@ nmi_stack_correct: |
da5b3fc8 | 4487 | xorl %edx,%edx # zero error code |
4488 | movl %esp,%eax # pt_regs pointer | |
4489 | call do_nmi | |
50425a20 | 4490 | + |
da5b3fc8 | 4491 | +#ifdef CONFIG_PAX_KERNEXEC |
4492 | + GET_CR0_INTO_EDX | |
4493 | + xorl %esi, %edx | |
4494 | + SET_CR0_FROM_EDX | |
4495 | +#endif | |
50425a20 | 4496 | + |
da5b3fc8 | 4497 | jmp restore_nocheck_notrace |
4498 | CFI_ENDPROC | |
4499 | ||
4dee9bd5 | 4500 | @@ -863,6 +938,13 @@ nmi_espfix_stack: |
da5b3fc8 | 4501 | FIXUP_ESPFIX_STACK # %eax == %esp |
4502 | xorl %edx,%edx # zero error code | |
4503 | call do_nmi | |
50425a20 | 4504 | + |
da5b3fc8 | 4505 | +#ifdef CONFIG_PAX_KERNEXEC |
4506 | + GET_CR0_INTO_EDX | |
4507 | + xorl %esi, %edx | |
4508 | + SET_CR0_FROM_EDX | |
4509 | +#endif | |
50425a20 | 4510 | + |
da5b3fc8 | 4511 | RESTORE_REGS |
4512 | lss 12+4(%esp), %esp # back to espfix stack | |
4513 | CFI_ADJUST_CFA_OFFSET -24 | |
4dee9bd5 | 4514 | @@ -1107,7 +1189,6 @@ ENDPROC(xen_failsafe_callback) |
50425a20 | 4515 | |
da5b3fc8 | 4516 | #endif /* CONFIG_XEN */ |
4517 | ||
4518 | -.section .rodata,"a" | |
4519 | #include "syscall_table_32.S" | |
4520 | ||
4521 | syscall_table_size=(.-sys_call_table) | |
4dee9bd5 | 4522 | diff -urNp linux-2.6.25.4/arch/x86/kernel/entry_64.S linux-2.6.25.4/arch/x86/kernel/entry_64.S |
4523 | --- linux-2.6.25.4/arch/x86/kernel/entry_64.S 2008-05-15 11:00:12.000000000 -0400 | |
4524 | +++ linux-2.6.25.4/arch/x86/kernel/entry_64.S 2008-05-18 13:33:14.000000000 -0400 | |
4525 | @@ -769,17 +769,18 @@ END(spurious_interrupt) | |
da5b3fc8 | 4526 | xorl %ebx,%ebx |
4527 | 1: | |
4528 | .if \ist | |
4529 | - movq %gs:pda_data_offset, %rbp | |
4530 | + imul $TSS_size, %gs:pda_cpunumber, %ebp | |
4531 | + lea init_tss(%rbp), %rbp | |
4532 | .endif | |
4533 | movq %rsp,%rdi | |
4534 | movq ORIG_RAX(%rsp),%rsi | |
4535 | movq $-1,ORIG_RAX(%rsp) | |
4536 | .if \ist | |
4537 | - subq $EXCEPTION_STKSZ, per_cpu__init_tss + TSS_ist + (\ist - 1) * 8(%rbp) | |
4538 | + subq $EXCEPTION_STKSZ, TSS_ist + (\ist - 1) * 8(%rbp) | |
4539 | .endif | |
4540 | call \sym | |
4541 | .if \ist | |
4542 | - addq $EXCEPTION_STKSZ, per_cpu__init_tss + TSS_ist + (\ist - 1) * 8(%rbp) | |
4543 | + addq $EXCEPTION_STKSZ, TSS_ist + (\ist - 1) * 8(%rbp) | |
4544 | .endif | |
4dee9bd5 | 4545 | DISABLE_INTERRUPTS(CLBR_NONE) |
da5b3fc8 | 4546 | .if \irqtrace |
4dee9bd5 | 4547 | diff -urNp linux-2.6.25.4/arch/x86/kernel/head_32.S linux-2.6.25.4/arch/x86/kernel/head_32.S |
4548 | --- linux-2.6.25.4/arch/x86/kernel/head_32.S 2008-05-15 11:00:12.000000000 -0400 | |
4549 | +++ linux-2.6.25.4/arch/x86/kernel/head_32.S 2008-05-18 13:33:14.000000000 -0400 | |
4550 | @@ -20,6 +20,7 @@ | |
da5b3fc8 | 4551 | #include <asm/asm-offsets.h> |
4552 | #include <asm/setup.h> | |
4dee9bd5 | 4553 | #include <asm/processor-flags.h> |
da5b3fc8 | 4554 | +#include <asm/msr-index.h> |
4555 | ||
4dee9bd5 | 4556 | /* Physical address */ |
4557 | #define pa(X) ((X) - __PAGE_OFFSET) | |
4558 | @@ -65,17 +66,22 @@ LOW_PAGES = 1<<(32-PAGE_SHIFT_asm) | |
da5b3fc8 | 4559 | LOW_PAGES = LOW_PAGES + 0x1000000 |
50425a20 | 4560 | #endif |
da5b3fc8 | 4561 | |
4562 | -#if PTRS_PER_PMD > 1 | |
4563 | -PAGE_TABLE_SIZE = (LOW_PAGES / PTRS_PER_PMD) + PTRS_PER_PGD | |
4564 | -#else | |
4565 | -PAGE_TABLE_SIZE = (LOW_PAGES / PTRS_PER_PGD) | |
4566 | -#endif | |
4567 | +PAGE_TABLE_SIZE = (LOW_PAGES / PTRS_PER_PTE) | |
4568 | BOOTBITMAP_SIZE = LOW_PAGES / 8 | |
4569 | ALLOCATOR_SLOP = 4 | |
4570 | ||
4571 | INIT_MAP_BEYOND_END = BOOTBITMAP_SIZE + (PAGE_TABLE_SIZE + ALLOCATOR_SLOP)*PAGE_SIZE_asm | |
4572 | ||
4573 | /* | |
4574 | + * Real beginning of normal "text" segment | |
4575 | + */ | |
4576 | +ENTRY(stext) | |
4577 | +ENTRY(_stext) | |
4578 | + | |
4579 | +.section .text.startup,"ax",@progbits | |
4580 | + ljmp $(__BOOT_CS),$phys_startup_32 | |
4581 | + | |
4582 | +/* | |
4583 | * 32-bit kernel entrypoint; only used by the boot CPU. On entry, | |
4584 | * %esi points to the real-mode code as a 32-bit pointer. | |
4585 | * CS and DS must be 4 GB flat segments, but we don't depend on | |
4dee9bd5 | 4586 | @@ -83,6 +89,12 @@ INIT_MAP_BEYOND_END = BOOTBITMAP_SIZE + |
da5b3fc8 | 4587 | * can. |
4588 | */ | |
4589 | .section .text.head,"ax",@progbits | |
4590 | + | |
4591 | +#ifdef CONFIG_PAX_KERNEXEC | |
4592 | +/* PaX: fill first page in .text with int3 to catch NULL derefs in kernel mode */ | |
4593 | +.fill 4096,1,0xcc | |
4594 | +#endif | |
4595 | + | |
4596 | ENTRY(startup_32) | |
4dee9bd5 | 4597 | /* test KEEP_SEGMENTS flag to see if the bootloader is asking |
4598 | us to not reload segments */ | |
4599 | @@ -100,6 +112,43 @@ ENTRY(startup_32) | |
da5b3fc8 | 4600 | movl %eax,%gs |
4601 | 2: | |
4602 | ||
4603 | + movl $__per_cpu_start,%eax | |
4604 | + movw %ax,(cpu_gdt_table - __PAGE_OFFSET + __KERNEL_PERCPU + 2) | |
4605 | + rorl $16,%eax | |
4606 | + movb %al,(cpu_gdt_table - __PAGE_OFFSET + __KERNEL_PERCPU + 4) | |
4607 | + movb %ah,(cpu_gdt_table - __PAGE_OFFSET + __KERNEL_PERCPU + 7) | |
4dee9bd5 | 4608 | + movl $__per_cpu_end + PERCPU_MODULE_RESERVE - 1,%eax |
da5b3fc8 | 4609 | + subl $__per_cpu_start,%eax |
4610 | + movw %ax,(cpu_gdt_table - __PAGE_OFFSET + __KERNEL_PERCPU + 0) | |
50425a20 | 4611 | + |
4612 | +#ifdef CONFIG_PAX_MEMORY_UDEREF | |
da5b3fc8 | 4613 | + /* check for VMware */ |
4614 | + movl $0x564d5868,%eax | |
4615 | + xorl %ebx,%ebx | |
4616 | + movl $0xa,%ecx | |
4617 | + movl $0x5658,%edx | |
4618 | + in (%dx),%eax | |
4619 | + cmpl $0x564d5868,%ebx | |
4620 | + jz 1f | |
50425a20 | 4621 | + |
da5b3fc8 | 4622 | + movl $((((__PAGE_OFFSET-1) & 0xf0000000) >> 12) | 0x00c09700),%eax |
4623 | + movl %eax,(cpu_gdt_table - __PAGE_OFFSET + GDT_ENTRY_KERNEL_DS * 8 + 4) | |
4624 | +1: | |
4625 | +#endif | |
50425a20 | 4626 | + |
da5b3fc8 | 4627 | +#ifdef CONFIG_PAX_KERNEXEC |
4628 | + movl $KERNEL_TEXT_OFFSET,%eax | |
4629 | + movw %ax,(cpu_gdt_table - __PAGE_OFFSET + __KERNEL_CS + 2) | |
4630 | + rorl $16,%eax | |
4631 | + movb %al,(cpu_gdt_table - __PAGE_OFFSET + __KERNEL_CS + 4) | |
4632 | + movb %ah,(cpu_gdt_table - __PAGE_OFFSET + __KERNEL_CS + 7) | |
4633 | + | |
4634 | + movb %al,(boot_gdt - __PAGE_OFFSET + __BOOT_CS + 4) | |
4635 | + movb %ah,(boot_gdt - __PAGE_OFFSET + __BOOT_CS + 7) | |
4636 | + rorl $16,%eax | |
4637 | + movw %ax,(boot_gdt - __PAGE_OFFSET + __BOOT_CS + 2) | |
50425a20 | 4638 | +#endif |
4639 | + | |
50425a20 | 4640 | /* |
da5b3fc8 | 4641 | * Clear BSS first so that there are no surprises... |
4642 | */ | |
4dee9bd5 | 4643 | @@ -143,9 +192,7 @@ ENTRY(startup_32) |
da5b3fc8 | 4644 | cmpl $num_subarch_entries, %eax |
4645 | jae bad_subarch | |
4646 | ||
4dee9bd5 | 4647 | - movl pa(subarch_entries)(,%eax,4), %eax |
da5b3fc8 | 4648 | - subl $__PAGE_OFFSET, %eax |
4649 | - jmp *%eax | |
4dee9bd5 | 4650 | + jmp *pa(subarch_entries)(,%eax,4) |
da5b3fc8 | 4651 | |
4652 | bad_subarch: | |
4653 | WEAK(lguest_entry) | |
4dee9bd5 | 4654 | @@ -157,9 +204,9 @@ WEAK(xen_entry) |
4655 | __INITDATA | |
4656 | ||
da5b3fc8 | 4657 | subarch_entries: |
4658 | - .long default_entry /* normal x86/PC */ | |
4659 | - .long lguest_entry /* lguest hypervisor */ | |
4660 | - .long xen_entry /* Xen hypervisor */ | |
4dee9bd5 | 4661 | + .long pa(default_entry) /* normal x86/PC */ |
4662 | + .long pa(lguest_entry) /* lguest hypervisor */ | |
4663 | + .long pa(xen_entry) /* Xen hypervisor */ | |
da5b3fc8 | 4664 | num_subarch_entries = (. - subarch_entries) / 4 |
4665 | .previous | |
4666 | #endif /* CONFIG_PARAVIRT */ | |
4dee9bd5 | 4667 | @@ -173,7 +220,7 @@ num_subarch_entries = (. - subarch_entri |
4668 | * | |
4669 | * Note that the stack is not yet set up! | |
50425a20 | 4670 | */ |
4dee9bd5 | 4671 | -#define PTE_ATTR 0x007 /* PRESENT+RW+USER */ |
4672 | +#define PTE_ATTR 0x067 /* PRESENT+RW+USER+DIRTY+ACCESSED */ | |
4673 | #define PDE_ATTR 0x067 /* PRESENT+RW+USER+DIRTY+ACCESSED */ | |
4674 | #define PGD_ATTR 0x001 /* PRESENT (no other attributes) */ | |
4675 | ||
4676 | @@ -222,8 +269,7 @@ default_entry: | |
4677 | movl %edi,pa(init_pg_tables_end) | |
4678 | ||
4679 | /* Do early initialization of the fixmap area */ | |
4680 | - movl $pa(swapper_pg_fixmap)+PDE_ATTR,%eax | |
4681 | - movl %eax,pa(swapper_pg_pmd+0x1000*KPMDS-8) | |
4682 | + movl $pa(swapper_pg_fixmap)+PDE_ATTR,pa(swapper_pg_pmd+0x1000*KPMDS-8) | |
4683 | #else /* Not PAE */ | |
4684 | ||
4685 | page_pde_offset = (__PAGE_OFFSET >> 20); | |
4686 | @@ -252,8 +298,7 @@ page_pde_offset = (__PAGE_OFFSET >> 20); | |
4687 | movl %edi,pa(init_pg_tables_end) | |
4688 | ||
4689 | /* Do early initialization of the fixmap area */ | |
4690 | - movl $pa(swapper_pg_fixmap)+PDE_ATTR,%eax | |
4691 | - movl %eax,pa(swapper_pg_dir+0xffc) | |
4692 | + movl $pa(swapper_pg_fixmap)+PDE_ATTR,pa(swapper_pg_dir+0xffc) | |
4693 | #endif | |
da5b3fc8 | 4694 | jmp 3f |
da5b3fc8 | 4695 | /* |
4dee9bd5 | 4696 | @@ -317,13 +362,16 @@ ENTRY(startup_32_smp) |
4697 | jnc 6f | |
da5b3fc8 | 4698 | |
4699 | /* Setup EFER (Extended Feature Enable Register) */ | |
4700 | - movl $0xc0000080, %ecx | |
4701 | + movl $MSR_EFER, %ecx | |
4702 | rdmsr | |
4703 | ||
4704 | btsl $11, %eax | |
4705 | /* Make changes effective */ | |
4706 | wrmsr | |
4707 | ||
4dee9bd5 | 4708 | + btsl $63-32,pa(__supported_pte_mask+4) |
4709 | + movl $1,pa(nx_enabled) | |
8a4b4a5e | 4710 | + |
4dee9bd5 | 4711 | 6: |
50425a20 | 4712 | |
da5b3fc8 | 4713 | /* |
4dee9bd5 | 4714 | @@ -349,9 +397,7 @@ ENTRY(startup_32_smp) |
da5b3fc8 | 4715 | |
4716 | #ifdef CONFIG_SMP | |
4dee9bd5 | 4717 | cmpb $0, ready |
da5b3fc8 | 4718 | - jz 1f /* Initial CPU cleans BSS */ |
4719 | - jmp checkCPUtype | |
4720 | -1: | |
4dee9bd5 | 4721 | + jnz checkCPUtype /* Initial CPU cleans BSS */ |
da5b3fc8 | 4722 | #endif /* CONFIG_SMP */ |
4723 | ||
4724 | /* | |
4dee9bd5 | 4725 | @@ -428,12 +474,12 @@ is386: movl $2,%ecx # set MP |
da5b3fc8 | 4726 | ljmp $(__KERNEL_CS),$1f |
4727 | 1: movl $(__KERNEL_DS),%eax # reload all the segment registers | |
4728 | movl %eax,%ss # after changing gdt. | |
4729 | - movl %eax,%fs # gets reset once there's real percpu | |
4730 | - | |
4731 | - movl $(__USER_DS),%eax # DS/ES contains default USER segment | |
4732 | movl %eax,%ds | |
4733 | movl %eax,%es | |
4734 | ||
4735 | + movl $(__KERNEL_PERCPU), %eax | |
4736 | + movl %eax,%fs # set this cpu's percpu | |
4737 | + | |
4738 | xorl %eax,%eax # Clear GS and LDT | |
4739 | movl %eax,%gs | |
4740 | lldt %ax | |
4dee9bd5 | 4741 | @@ -444,11 +490,7 @@ is386: movl $2,%ecx # set MP |
da5b3fc8 | 4742 | movb ready, %cl |
4743 | movb $1, ready | |
4744 | cmpb $0,%cl # the first CPU calls start_kernel | |
4745 | - je 1f | |
4746 | - movl $(__KERNEL_PERCPU), %eax | |
4747 | - movl %eax,%fs # set this cpu's percpu | |
4748 | - jmp initialize_secondary # all other CPUs call initialize_secondary | |
4749 | -1: | |
4750 | + jne initialize_secondary # all other CPUs call initialize_secondary | |
4751 | #endif /* CONFIG_SMP */ | |
4752 | jmp start_kernel | |
50425a20 | 4753 | |
4dee9bd5 | 4754 | @@ -534,8 +576,8 @@ early_page_fault: |
da5b3fc8 | 4755 | jmp early_fault |
50425a20 | 4756 | |
da5b3fc8 | 4757 | early_fault: |
4758 | - cld | |
4759 | #ifdef CONFIG_PRINTK | |
4760 | + cld | |
4761 | pusha | |
4762 | movl $(__KERNEL_DS),%eax | |
4763 | movl %eax,%ds | |
4dee9bd5 | 4764 | @@ -561,8 +603,8 @@ hlt_loop: |
da5b3fc8 | 4765 | /* This is the default interrupt "handler" :-) */ |
4766 | ALIGN | |
4767 | ignore_int: | |
4768 | - cld | |
4769 | #ifdef CONFIG_PRINTK | |
4770 | + cld | |
4771 | pushl %eax | |
4772 | pushl %ecx | |
4773 | pushl %edx | |
4dee9bd5 | 4774 | @@ -593,36 +635,41 @@ ignore_int: |
da5b3fc8 | 4775 | #endif |
4776 | iret | |
50425a20 | 4777 | |
da5b3fc8 | 4778 | -.section .text |
50425a20 | 4779 | -/* |
da5b3fc8 | 4780 | - * Real beginning of normal "text" segment |
50425a20 | 4781 | - */ |
da5b3fc8 | 4782 | -ENTRY(stext) |
4783 | -ENTRY(_stext) | |
50425a20 | 4784 | - |
50425a20 | 4785 | /* |
da5b3fc8 | 4786 | * BSS section |
50425a20 | 4787 | */ |
da5b3fc8 | 4788 | -.section ".bss.page_aligned","wa" |
4dee9bd5 | 4789 | - .align PAGE_SIZE_asm |
4790 | #ifdef CONFIG_X86_PAE | |
4791 | +.section .swapper_pg_pmd,"a",@progbits | |
4792 | swapper_pg_pmd: | |
4793 | .fill 1024*KPMDS,4,0 | |
4794 | #else | |
da5b3fc8 | 4795 | +.section .swapper_pg_dir,"a",@progbits |
da5b3fc8 | 4796 | ENTRY(swapper_pg_dir) |
da5b3fc8 | 4797 | .fill 1024,4,0 |
4dee9bd5 | 4798 | #endif |
4799 | swapper_pg_fixmap: | |
da5b3fc8 | 4800 | .fill 1024,4,0 |
4801 | + | |
4802 | +.section .empty_zero_page,"a",@progbits | |
4803 | ENTRY(empty_zero_page) | |
4804 | .fill 4096,1,0 | |
4dee9bd5 | 4805 | + |
4806 | +/* | |
da5b3fc8 | 4807 | + * The IDT has to be page-aligned to simplify the Pentium |
4808 | + * F0 0F bug workaround.. We have a special link segment | |
4809 | + * for this. | |
4810 | + */ | |
4811 | +.section .idt,"a",@progbits | |
4812 | +ENTRY(idt_table) | |
4813 | + .fill 256,8,0 | |
4814 | + | |
4dee9bd5 | 4815 | /* |
da5b3fc8 | 4816 | * This starts the data section. |
4817 | */ | |
4dee9bd5 | 4818 | +.data |
da5b3fc8 | 4819 | + |
4dee9bd5 | 4820 | #ifdef CONFIG_X86_PAE |
4821 | -.section ".data.page_aligned","wa" | |
4822 | - /* Page-aligned for the benefit of paravirt? */ | |
4823 | - .align PAGE_SIZE_asm | |
4824 | +.section .swapper_pg_dir,"a",@progbits | |
4825 | ENTRY(swapper_pg_dir) | |
4826 | .long pa(swapper_pg_pmd+PGD_ATTR),0 /* low identity map */ | |
4827 | # if KPMDS == 3 | |
4828 | @@ -643,9 +690,9 @@ ENTRY(swapper_pg_dir) | |
4829 | .align PAGE_SIZE_asm /* needs to be page-sized too */ | |
4830 | #endif | |
4831 | ||
4832 | -.data | |
da5b3fc8 | 4833 | +.section .rodata,"a",@progbits |
4834 | ENTRY(stack_start) | |
4835 | - .long init_thread_union+THREAD_SIZE | |
4836 | + .long init_thread_union+THREAD_SIZE-8 | |
4837 | .long __BOOT_DS | |
50425a20 | 4838 | |
da5b3fc8 | 4839 | ready: .byte 0 |
4dee9bd5 | 4840 | @@ -695,7 +742,7 @@ idt_descr: |
da5b3fc8 | 4841 | .word 0 # 32 bit align gdt_desc.address |
4842 | ENTRY(early_gdt_descr) | |
4843 | .word GDT_ENTRIES*8-1 | |
4844 | - .long per_cpu__gdt_page /* Overwritten for secondary CPUs */ | |
4845 | + .long cpu_gdt_table /* Overwritten for secondary CPUs */ | |
50425a20 | 4846 | |
da5b3fc8 | 4847 | /* |
4848 | * The boot_gdt must mirror the equivalent in setup.S and is | |
4dee9bd5 | 4849 | @@ -704,5 +751,61 @@ ENTRY(early_gdt_descr) |
da5b3fc8 | 4850 | .align L1_CACHE_BYTES |
4851 | ENTRY(boot_gdt) | |
4852 | .fill GDT_ENTRY_BOOT_CS,8,0 | |
4853 | - .quad 0x00cf9a000000ffff /* kernel 4GB code at 0x00000000 */ | |
4854 | - .quad 0x00cf92000000ffff /* kernel 4GB data at 0x00000000 */ | |
4855 | + .quad 0x00cf9b000000ffff /* kernel 4GB code at 0x00000000 */ | |
4856 | + .quad 0x00cf93000000ffff /* kernel 4GB data at 0x00000000 */ | |
4857 | + | |
4858 | + .align PAGE_SIZE_asm | |
4859 | +ENTRY(cpu_gdt_table) | |
4860 | + .quad 0x0000000000000000 /* NULL descriptor */ | |
4861 | + .quad 0x0000000000000000 /* 0x0b reserved */ | |
4862 | + .quad 0x0000000000000000 /* 0x13 reserved */ | |
4863 | + .quad 0x0000000000000000 /* 0x1b reserved */ | |
4864 | + .quad 0x0000000000000000 /* 0x20 unused */ | |
4865 | + .quad 0x0000000000000000 /* 0x28 unused */ | |
4866 | + .quad 0x0000000000000000 /* 0x33 TLS entry 1 */ | |
4867 | + .quad 0x0000000000000000 /* 0x3b TLS entry 2 */ | |
4868 | + .quad 0x0000000000000000 /* 0x43 TLS entry 3 */ | |
4869 | + .quad 0x0000000000000000 /* 0x4b reserved */ | |
4870 | + .quad 0x0000000000000000 /* 0x53 reserved */ | |
4871 | + .quad 0x0000000000000000 /* 0x5b reserved */ | |
4872 | + | |
4873 | + .quad 0x00cf9b000000ffff /* 0x60 kernel 4GB code at 0x00000000 */ | |
4874 | + .quad 0x00cf93000000ffff /* 0x68 kernel 4GB data at 0x00000000 */ | |
4875 | + .quad 0x00cffb000000ffff /* 0x73 user 4GB code at 0x00000000 */ | |
4876 | + .quad 0x00cff3000000ffff /* 0x7b user 4GB data at 0x00000000 */ | |
4877 | + | |
4878 | + .quad 0x0000000000000000 /* 0x80 TSS descriptor */ | |
4879 | + .quad 0x0000000000000000 /* 0x88 LDT descriptor */ | |
4880 | + | |
4881 | + /* | |
4882 | + * Segments used for calling PnP BIOS have byte granularity. | |
4883 | + * The code segments and data segments have fixed 64k limits, | |
4884 | + * the transfer segment sizes are set at run time. | |
4885 | + */ | |
4886 | + .quad 0x00409b000000ffff /* 0x90 32-bit code */ | |
4887 | + .quad 0x00009b000000ffff /* 0x98 16-bit code */ | |
4888 | + .quad 0x000093000000ffff /* 0xa0 16-bit data */ | |
4889 | + .quad 0x0000930000000000 /* 0xa8 16-bit data */ | |
4890 | + .quad 0x0000930000000000 /* 0xb0 16-bit data */ | |
4891 | + | |
4892 | + /* | |
4893 | + * The APM segments have byte granularity and their bases | |
4894 | + * are set at run time. All have 64k limits. | |
4895 | + */ | |
4896 | + .quad 0x00409b000000ffff /* 0xb8 APM CS code */ | |
4897 | + .quad 0x00009b000000ffff /* 0xc0 APM CS 16 code (16 bit) */ | |
4898 | + .quad 0x004093000000ffff /* 0xc8 APM DS data */ | |
4899 | + | |
4900 | + .quad 0x00c0930000000000 /* 0xd0 - ESPFIX SS */ | |
4901 | + .quad 0x0040930000000000 /* 0xd8 - PERCPU */ | |
4902 | + .quad 0x0000000000000000 /* 0xe0 - PCIBIOS_CS */ | |
4903 | + .quad 0x0000000000000000 /* 0xe8 - PCIBIOS_DS */ | |
4904 | + .quad 0x0000000000000000 /* 0xf0 - unused */ | |
4905 | + .quad 0x0000000000000000 /* 0xf8 - GDT entry 31: double-fault TSS */ | |
4906 | + | |
4907 | + /* Be sure this is zeroed to avoid false validations in Xen */ | |
4908 | + .fill PAGE_SIZE_asm - GDT_ENTRIES,1,0 | |
4909 | + | |
4910 | +#ifdef CONFIG_SMP | |
4911 | + .fill (NR_CPUS-1) * (PAGE_SIZE_asm),1,0 /* other CPU's GDT */ | |
4912 | +#endif | |
4dee9bd5 | 4913 | diff -urNp linux-2.6.25.4/arch/x86/kernel/head64.c linux-2.6.25.4/arch/x86/kernel/head64.c |
4914 | --- linux-2.6.25.4/arch/x86/kernel/head64.c 2008-05-15 11:00:12.000000000 -0400 | |
4915 | +++ linux-2.6.25.4/arch/x86/kernel/head64.c 2008-05-18 13:33:14.000000000 -0400 | |
4916 | @@ -88,6 +88,11 @@ void __init x86_64_start_kernel(char * r | |
da5b3fc8 | 4917 | /* Make NULL pointers segfault */ |
4918 | zap_identity_mappings(); | |
50425a20 | 4919 | |
4dee9bd5 | 4920 | + for (i = 0; i < NR_CPUS; i++) |
4921 | + cpu_pda(i) = &boot_cpu_pda[i]; | |
50425a20 | 4922 | + |
da5b3fc8 | 4923 | + pda_init(0); |
50425a20 | 4924 | + |
4dee9bd5 | 4925 | /* Cleanup the over mapped high alias */ |
4926 | cleanup_highmap(); | |
4927 | ||
4928 | @@ -102,10 +107,6 @@ void __init x86_64_start_kernel(char * r | |
da5b3fc8 | 4929 | |
4930 | early_printk("Kernel alive\n"); | |
4931 | ||
4932 | - for (i = 0; i < NR_CPUS; i++) | |
4933 | - cpu_pda(i) = &boot_cpu_pda[i]; | |
4934 | - | |
4935 | - pda_init(0); | |
4936 | copy_bootdata(__va(real_mode_data)); | |
4dee9bd5 | 4937 | |
4938 | reserve_early(__pa_symbol(&_text), __pa_symbol(&_end), "TEXT DATA BSS"); | |
4939 | diff -urNp linux-2.6.25.4/arch/x86/kernel/head_64.S linux-2.6.25.4/arch/x86/kernel/head_64.S | |
4940 | --- linux-2.6.25.4/arch/x86/kernel/head_64.S 2008-05-15 11:00:12.000000000 -0400 | |
4941 | +++ linux-2.6.25.4/arch/x86/kernel/head_64.S 2008-05-18 13:33:14.000000000 -0400 | |
4942 | @@ -185,6 +185,10 @@ ENTRY(secondary_startup_64) | |
da5b3fc8 | 4943 | btl $20,%edi /* No Execute supported? */ |
4944 | jnc 1f | |
4945 | btsl $_EFER_NX, %eax | |
4946 | + movq $(init_level4_pgt), %rdi | |
4947 | + addq phys_base(%rip), %rdi | |
4948 | + btsq $_PAGE_BIT_NX, 8*258(%rdi) | |
4949 | + btsq $_PAGE_BIT_NX, 8*388(%rdi) | |
4950 | 1: wrmsr /* Make changes effective */ | |
4951 | ||
4952 | /* Setup cr0 */ | |
4dee9bd5 | 4953 | @@ -254,6 +258,9 @@ ENTRY(secondary_startup_64) |
da5b3fc8 | 4954 | pushq %rax # target address in negative space |
4955 | lretq | |
4956 | ||
4957 | +bad_address: | |
4958 | + jmp bad_address | |
4959 | + | |
4960 | /* SMP bootup changes these two */ | |
4dee9bd5 | 4961 | __REFDATA |
da5b3fc8 | 4962 | .align 8 |
4dee9bd5 | 4963 | @@ -264,9 +271,7 @@ ENTRY(secondary_startup_64) |
4964 | ENTRY(init_rsp) | |
da5b3fc8 | 4965 | .quad init_thread_union+THREAD_SIZE-8 |
4966 | ||
4967 | -bad_address: | |
4968 | - jmp bad_address | |
4969 | - | |
4970 | + __INIT | |
4dee9bd5 | 4971 | #ifdef CONFIG_EARLY_PRINTK |
4972 | .macro early_idt_tramp first, last | |
4973 | .ifgt \last-\first | |
4974 | @@ -319,15 +324,18 @@ ENTRY(early_idt_handler) | |
da5b3fc8 | 4975 | jmp 1b |
4dee9bd5 | 4976 | |
4977 | #ifdef CONFIG_EARLY_PRINTK | |
da5b3fc8 | 4978 | + __INITDATA |
4979 | early_recursion_flag: | |
4980 | .long 0 | |
4981 | ||
4982 | + .section .rodata,"a",@progbits | |
4983 | early_idt_msg: | |
4dee9bd5 | 4984 | .asciz "PANIC: early exception %02lx rip %lx:%lx error %lx cr2 %lx\n" |
da5b3fc8 | 4985 | early_idt_ripmsg: |
4dee9bd5 | 4986 | .asciz "RIP %s\n" |
4987 | #endif /* CONFIG_EARLY_PRINTK */ | |
4988 | ||
4989 | + .section .rodata,"a",@progbits | |
4990 | .balign PAGE_SIZE | |
4991 | ||
4992 | #define NEXT_PAGE(name) \ | |
4993 | @@ -352,7 +360,9 @@ NEXT_PAGE(init_level4_pgt) | |
da5b3fc8 | 4994 | .quad level3_ident_pgt - __START_KERNEL_map + _KERNPG_TABLE |
4995 | .fill 257,8,0 | |
4996 | .quad level3_ident_pgt - __START_KERNEL_map + _KERNPG_TABLE | |
4997 | - .fill 252,8,0 | |
4998 | + .fill 129,8,0 | |
4999 | + .quad level3_vmalloc_pgt - __START_KERNEL_map + _KERNPG_TABLE | |
5000 | + .fill 122,8,0 | |
5001 | /* (2^48-(2*1024*1024*1024))/(2^39) = 511 */ | |
5002 | .quad level3_kernel_pgt - __START_KERNEL_map + _PAGE_TABLE | |
5003 | ||
4dee9bd5 | 5004 | @@ -360,6 +370,9 @@ NEXT_PAGE(level3_ident_pgt) |
da5b3fc8 | 5005 | .quad level2_ident_pgt - __START_KERNEL_map + _KERNPG_TABLE |
5006 | .fill 511,8,0 | |
5007 | ||
5008 | +NEXT_PAGE(level3_vmalloc_pgt) | |
5009 | + .fill 512,8,0 | |
5010 | + | |
5011 | NEXT_PAGE(level3_kernel_pgt) | |
5012 | .fill 510,8,0 | |
5013 | /* (2^48-(2*1024*1024*1024)-((2^39)*511))/(2^30) = 510 */ | |
4dee9bd5 | 5014 | @@ -401,19 +414,12 @@ NEXT_PAGE(level2_spare_pgt) |
da5b3fc8 | 5015 | #undef PMDS |
5016 | #undef NEXT_PAGE | |
5017 | ||
5018 | - .data | |
5019 | .align 16 | |
5020 | .globl cpu_gdt_descr | |
5021 | cpu_gdt_descr: | |
5022 | - .word gdt_end-cpu_gdt_table-1 | |
5023 | + .word GDT_SIZE-1 | |
5024 | gdt: | |
5025 | .quad cpu_gdt_table | |
5026 | -#ifdef CONFIG_SMP | |
5027 | - .rept NR_CPUS-1 | |
5028 | - .word 0 | |
5029 | - .quad 0 | |
5030 | - .endr | |
5031 | -#endif | |
5032 | ||
5033 | ENTRY(phys_base) | |
5034 | /* This must match the first entry in level2_kernel_pgt */ | |
4dee9bd5 | 5035 | @@ -423,8 +429,7 @@ ENTRY(phys_base) |
da5b3fc8 | 5036 | * IRET will check the segment types kkeil 2000/10/28 |
5037 | * Also sysret mandates a special GDT layout | |
5038 | */ | |
5039 | - | |
5040 | - .section .data.page_aligned, "aw" | |
5041 | + | |
5042 | .align PAGE_SIZE | |
5043 | ||
5044 | /* The TLS descriptors are currently at a different place compared to i386. | |
4dee9bd5 | 5045 | @@ -443,15 +448,15 @@ ENTRY(cpu_gdt_table) |
da5b3fc8 | 5046 | .quad 0,0 /* LDT */ |
5047 | .quad 0,0,0 /* three TLS descriptors */ | |
5048 | .quad 0x0000f40000000000 /* node/CPU stored in limit */ | |
5049 | -gdt_end: | |
5050 | /* asm/segment.h:GDT_ENTRIES must match this */ | |
5051 | /* This should be a multiple of the cache line size */ | |
5052 | - /* GDTs of other CPUs are now dynamically allocated */ | |
5053 | ||
5054 | /* zero the remaining page */ | |
5055 | .fill PAGE_SIZE / 8 - GDT_ENTRIES,8,0 | |
5056 | +#ifdef CONFIG_SMP | |
5057 | + .fill (NR_CPUS-1) * (PAGE_SIZE),1,0 /* other CPU's GDT */ | |
50425a20 | 5058 | +#endif |
8a4b4a5e | 5059 | |
da5b3fc8 | 5060 | - .section .bss, "aw", @nobits |
5061 | .align L1_CACHE_BYTES | |
5062 | ENTRY(idt_table) | |
5063 | .skip 256 * 16 | |
4dee9bd5 | 5064 | diff -urNp linux-2.6.25.4/arch/x86/kernel/hpet.c linux-2.6.25.4/arch/x86/kernel/hpet.c |
5065 | --- linux-2.6.25.4/arch/x86/kernel/hpet.c 2008-05-15 11:00:12.000000000 -0400 | |
5066 | +++ linux-2.6.25.4/arch/x86/kernel/hpet.c 2008-05-18 13:33:14.000000000 -0400 | |
5067 | @@ -138,7 +138,7 @@ static void hpet_reserve_platform_timers | |
da5b3fc8 | 5068 | hd.hd_irq[1] = HPET_LEGACY_RTC; |
50425a20 | 5069 | |
da5b3fc8 | 5070 | for (i = 2; i < nrtimers; timer++, i++) |
5071 | - hd.hd_irq[i] = (timer->hpet_config & Tn_INT_ROUTE_CNF_MASK) >> | |
5072 | + hd.hd_irq[i] = (readl(&timer->hpet_config) & Tn_INT_ROUTE_CNF_MASK) >> | |
5073 | Tn_INT_ROUTE_CNF_SHIFT; | |
50425a20 | 5074 | |
da5b3fc8 | 5075 | hpet_alloc(&hd); |
4dee9bd5 | 5076 | diff -urNp linux-2.6.25.4/arch/x86/kernel/i386_ksyms_32.c linux-2.6.25.4/arch/x86/kernel/i386_ksyms_32.c |
5077 | --- linux-2.6.25.4/arch/x86/kernel/i386_ksyms_32.c 2008-05-15 11:00:12.000000000 -0400 | |
5078 | +++ linux-2.6.25.4/arch/x86/kernel/i386_ksyms_32.c 2008-05-18 13:33:14.000000000 -0400 | |
da5b3fc8 | 5079 | @@ -4,12 +4,16 @@ |
5080 | #include <asm/desc.h> | |
5081 | #include <asm/pgtable.h> | |
50425a20 | 5082 | |
da5b3fc8 | 5083 | +EXPORT_SYMBOL_GPL(cpu_gdt_table); |
5084 | + | |
5085 | EXPORT_SYMBOL(__down_failed); | |
5086 | EXPORT_SYMBOL(__down_failed_interruptible); | |
5087 | EXPORT_SYMBOL(__down_failed_trylock); | |
5088 | EXPORT_SYMBOL(__up_wakeup); | |
5089 | /* Networking helper routines. */ | |
5090 | EXPORT_SYMBOL(csum_partial_copy_generic); | |
5091 | +EXPORT_SYMBOL(csum_partial_copy_generic_to_user); | |
5092 | +EXPORT_SYMBOL(csum_partial_copy_generic_from_user); | |
50425a20 | 5093 | |
da5b3fc8 | 5094 | EXPORT_SYMBOL(__get_user_1); |
5095 | EXPORT_SYMBOL(__get_user_2); | |
4dee9bd5 | 5096 | @@ -24,3 +28,7 @@ EXPORT_SYMBOL(strstr); |
da5b3fc8 | 5097 | |
5098 | EXPORT_SYMBOL(csum_partial); | |
5099 | EXPORT_SYMBOL(empty_zero_page); | |
5100 | + | |
5101 | +#ifdef CONFIG_PAX_KERNEXEC | |
5102 | +EXPORT_SYMBOL(KERNEL_TEXT_OFFSET); | |
5103 | +#endif | |
4dee9bd5 | 5104 | diff -urNp linux-2.6.25.4/arch/x86/kernel/init_task.c linux-2.6.25.4/arch/x86/kernel/init_task.c |
5105 | --- linux-2.6.25.4/arch/x86/kernel/init_task.c 2008-05-15 11:00:12.000000000 -0400 | |
5106 | +++ linux-2.6.25.4/arch/x86/kernel/init_task.c 2008-05-18 13:33:14.000000000 -0400 | |
4a96545f | 5107 | @@ -43,5 +43,5 @@ EXPORT_SYMBOL(init_task); |
da5b3fc8 | 5108 | * section. Since TSS's are completely CPU-local, we want them |
5109 | * on exact cacheline boundaries, to eliminate cacheline ping-pong. | |
5110 | */ | |
5111 | -DEFINE_PER_CPU_SHARED_ALIGNED(struct tss_struct, init_tss) = INIT_TSS; | |
5112 | - | |
5113 | +struct tss_struct init_tss[NR_CPUS] ____cacheline_internodealigned_in_smp = { [0 ... NR_CPUS-1] = INIT_TSS }; | |
4a96545f | 5114 | +EXPORT_SYMBOL(init_tss); |
4dee9bd5 | 5115 | diff -urNp linux-2.6.25.4/arch/x86/kernel/ioport.c linux-2.6.25.4/arch/x86/kernel/ioport.c |
5116 | --- linux-2.6.25.4/arch/x86/kernel/ioport.c 2008-05-15 11:00:12.000000000 -0400 | |
5117 | +++ linux-2.6.25.4/arch/x86/kernel/ioport.c 2008-05-18 13:33:14.000000000 -0400 | |
da5b3fc8 | 5118 | @@ -14,6 +14,7 @@ |
5119 | #include <linux/slab.h> | |
5120 | #include <linux/thread_info.h> | |
5121 | #include <linux/syscalls.h> | |
5122 | +#include <linux/grsecurity.h> | |
5123 | ||
5124 | /* Set EXTENT bits starting at BASE in BITMAP to value TURN_ON. */ | |
4dee9bd5 | 5125 | static void set_bitmap(unsigned long *bitmap, unsigned int base, |
5126 | @@ -40,6 +41,12 @@ asmlinkage long sys_ioperm(unsigned long | |
da5b3fc8 | 5127 | |
5128 | if ((from + num <= from) || (from + num > IO_BITMAP_BITS)) | |
5129 | return -EINVAL; | |
5130 | +#ifdef CONFIG_GRKERNSEC_IO | |
5131 | + if (turn_on) { | |
5132 | + gr_handle_ioperm(); | |
4dee9bd5 | 5133 | + return -EPERM; |
da5b3fc8 | 5134 | + } |
5135 | +#endif | |
4dee9bd5 | 5136 | if (turn_on && !capable(CAP_SYS_RAWIO)) |
5137 | return -EPERM; | |
5138 | ||
5139 | @@ -66,7 +73,7 @@ asmlinkage long sys_ioperm(unsigned long | |
da5b3fc8 | 5140 | * because the ->io_bitmap_max value must match the bitmap |
5141 | * contents: | |
50425a20 | 5142 | */ |
da5b3fc8 | 5143 | - tss = &per_cpu(init_tss, get_cpu()); |
5144 | + tss = init_tss + get_cpu(); | |
50425a20 | 5145 | |
da5b3fc8 | 5146 | set_bitmap(t->io_bitmap_ptr, from, num, !turn_on); |
5147 | ||
4dee9bd5 | 5148 | diff -urNp linux-2.6.25.4/arch/x86/kernel/irq_32.c linux-2.6.25.4/arch/x86/kernel/irq_32.c |
5149 | --- linux-2.6.25.4/arch/x86/kernel/irq_32.c 2008-05-15 11:00:12.000000000 -0400 | |
5150 | +++ linux-2.6.25.4/arch/x86/kernel/irq_32.c 2008-05-18 13:33:14.000000000 -0400 | |
5151 | @@ -115,7 +115,7 @@ unsigned int do_IRQ(struct pt_regs *regs | |
5152 | int arg1, arg2, bx; | |
50425a20 | 5153 | |
4dee9bd5 | 5154 | /* build the stack frame on the IRQ stack */ |
5155 | - isp = (u32*) ((char*)irqctx + sizeof(*irqctx)); | |
5156 | + isp = (u32*) ((char*)irqctx + sizeof(*irqctx) - 8); | |
5157 | irqctx->tinfo.task = curctx->tinfo.task; | |
5158 | irqctx->tinfo.previous_esp = current_stack_pointer; | |
da5b3fc8 | 5159 | |
5160 | @@ -211,7 +211,7 @@ asmlinkage void do_softirq(void) | |
5161 | irqctx->tinfo.previous_esp = current_stack_pointer; | |
5162 | ||
5163 | /* build the stack frame on the softirq stack */ | |
5164 | - isp = (u32*) ((char*)irqctx + sizeof(*irqctx)); | |
5165 | + isp = (u32*) ((char*)irqctx + sizeof(*irqctx) - 8); | |
5166 | ||
5167 | asm volatile( | |
5168 | " xchgl %%ebx,%%esp \n" | |
4dee9bd5 | 5169 | diff -urNp linux-2.6.25.4/arch/x86/kernel/kprobes.c linux-2.6.25.4/arch/x86/kernel/kprobes.c |
5170 | --- linux-2.6.25.4/arch/x86/kernel/kprobes.c 2008-05-15 11:00:12.000000000 -0400 | |
5171 | +++ linux-2.6.25.4/arch/x86/kernel/kprobes.c 2008-05-18 13:33:14.000000000 -0400 | |
5172 | @@ -166,9 +166,24 @@ static void __kprobes set_jmp_op(void *f | |
da5b3fc8 | 5173 | char op; |
4dee9bd5 | 5174 | s32 raddr; |
5175 | } __attribute__((packed)) * jop; | |
da5b3fc8 | 5176 | - jop = (struct __arch_jmp_op *)from; |
50425a20 | 5177 | + |
da5b3fc8 | 5178 | +#ifdef CONFIG_PAX_KERNEXEC |
5179 | + unsigned long cr0; | |
e36c1b33 | 5180 | +#endif |
50425a20 | 5181 | + |
da5b3fc8 | 5182 | + jop = (struct __arch_jmp_op *)(ktla_ktva(from)); |
50425a20 | 5183 | + |
da5b3fc8 | 5184 | +#ifdef CONFIG_PAX_KERNEXEC |
5185 | + pax_open_kernel(cr0); | |
50425a20 | 5186 | +#endif |
5187 | + | |
4dee9bd5 | 5188 | jop->raddr = (s32)((long)(to) - ((long)(from) + 5)); |
da5b3fc8 | 5189 | jop->op = RELATIVEJUMP_INSTRUCTION; |
50425a20 | 5190 | + |
da5b3fc8 | 5191 | +#ifdef CONFIG_PAX_KERNEXEC |
5192 | + pax_close_kernel(cr0); | |
50425a20 | 5193 | +#endif |
5194 | + | |
da5b3fc8 | 5195 | } |
5196 | ||
50425a20 | 5197 | /* |
4dee9bd5 | 5198 | @@ -342,16 +357,29 @@ static void __kprobes fix_riprel(struct |
50425a20 | 5199 | |
4dee9bd5 | 5200 | static void __kprobes arch_copy_kprobe(struct kprobe *p) |
da5b3fc8 | 5201 | { |
4dee9bd5 | 5202 | - memcpy(p->ainsn.insn, p->addr, MAX_INSN_SIZE * sizeof(kprobe_opcode_t)); |
50425a20 | 5203 | + |
da5b3fc8 | 5204 | +#ifdef CONFIG_PAX_KERNEXEC |
5205 | + unsigned long cr0; | |
50425a20 | 5206 | +#endif |
5207 | + | |
da5b3fc8 | 5208 | +#ifdef CONFIG_PAX_KERNEXEC |
5209 | + pax_open_kernel(cr0); | |
50425a20 | 5210 | +#endif |
5211 | + | |
da5b3fc8 | 5212 | + memcpy(p->ainsn.insn, ktla_ktva(p->addr), MAX_INSN_SIZE * sizeof(kprobe_opcode_t)); |
50425a20 | 5213 | + |
da5b3fc8 | 5214 | +#ifdef CONFIG_PAX_KERNEXEC |
5215 | + pax_close_kernel(cr0); | |
50425a20 | 5216 | +#endif |
4dee9bd5 | 5217 | |
5218 | fix_riprel(p); | |
5219 | ||
5220 | - if (can_boost(p->addr)) | |
5221 | + if (can_boost(ktla_ktva(p->addr))) | |
da5b3fc8 | 5222 | p->ainsn.boostable = 0; |
4dee9bd5 | 5223 | else |
da5b3fc8 | 5224 | p->ainsn.boostable = -1; |
4dee9bd5 | 5225 | |
5226 | - p->opcode = *p->addr; | |
5227 | + p->opcode = *(ktla_ktva(p->addr)); | |
5228 | } | |
5229 | ||
5230 | int __kprobes arch_prepare_kprobe(struct kprobe *p) | |
5231 | @@ -428,7 +456,7 @@ static void __kprobes prepare_singlestep | |
da5b3fc8 | 5232 | if (p->opcode == BREAKPOINT_INSTRUCTION) |
4dee9bd5 | 5233 | regs->ip = (unsigned long)p->addr; |
da5b3fc8 | 5234 | else |
4dee9bd5 | 5235 | - regs->ip = (unsigned long)p->ainsn.insn; |
5236 | + regs->ip = ktva_ktla((unsigned long)p->ainsn.insn); | |
da5b3fc8 | 5237 | } |
50425a20 | 5238 | |
da5b3fc8 | 5239 | /* Called with kretprobe_lock held */ |
4dee9bd5 | 5240 | @@ -450,7 +478,7 @@ static void __kprobes setup_singlestep(s |
5241 | if (p->ainsn.boostable == 1 && !p->post_handler) { | |
da5b3fc8 | 5242 | /* Boost up -- we can execute copied instructions directly */ |
5243 | reset_current_kprobe(); | |
4dee9bd5 | 5244 | - regs->ip = (unsigned long)p->ainsn.insn; |
5245 | + regs->ip = ktva_ktla((unsigned long)p->ainsn.insn); | |
da5b3fc8 | 5246 | preempt_enable_no_resched(); |
4dee9bd5 | 5247 | return; |
da5b3fc8 | 5248 | } |
4dee9bd5 | 5249 | @@ -772,7 +800,7 @@ static void __kprobes resume_execution(s |
da5b3fc8 | 5250 | struct pt_regs *regs, struct kprobe_ctlblk *kcb) |
5251 | { | |
4dee9bd5 | 5252 | unsigned long *tos = stack_addr(regs); |
5253 | - unsigned long copy_ip = (unsigned long)p->ainsn.insn; | |
5254 | + unsigned long copy_ip = ktva_ktla((unsigned long)p->ainsn.insn); | |
5255 | unsigned long orig_ip = (unsigned long)p->addr; | |
5256 | kprobe_opcode_t *insn = p->ainsn.insn; | |
5257 | ||
5258 | @@ -956,7 +984,7 @@ int __kprobes kprobe_exceptions_notify(s | |
5259 | struct die_args *args = data; | |
da5b3fc8 | 5260 | int ret = NOTIFY_DONE; |
8a4b4a5e | 5261 | |
da5b3fc8 | 5262 | - if (args->regs && user_mode_vm(args->regs)) |
5263 | + if (args->regs && user_mode(args->regs)) | |
5264 | return ret; | |
5265 | ||
5266 | switch (val) { | |
4dee9bd5 | 5267 | diff -urNp linux-2.6.25.4/arch/x86/kernel/ldt.c linux-2.6.25.4/arch/x86/kernel/ldt.c |
5268 | --- linux-2.6.25.4/arch/x86/kernel/ldt.c 2008-05-15 11:00:12.000000000 -0400 | |
5269 | +++ linux-2.6.25.4/arch/x86/kernel/ldt.c 2008-05-18 13:33:14.000000000 -0400 | |
5270 | @@ -65,7 +65,7 @@ static int alloc_ldt(mm_context_t *pc, i | |
da5b3fc8 | 5271 | cpumask_t mask; |
4dee9bd5 | 5272 | |
da5b3fc8 | 5273 | preempt_disable(); |
5274 | - load_LDT(pc); | |
5275 | + load_LDT_nolock(pc); | |
5276 | mask = cpumask_of_cpu(smp_processor_id()); | |
5277 | if (!cpus_equal(current->mm->cpu_vm_mask, mask)) | |
5278 | smp_call_function(flush_ldt, NULL, 1, 1); | |
4dee9bd5 | 5279 | @@ -110,6 +110,24 @@ int init_new_context(struct task_struct |
da5b3fc8 | 5280 | retval = copy_ldt(&mm->context, &old_mm->context); |
5281 | mutex_unlock(&old_mm->context.lock); | |
50425a20 | 5282 | } |
50425a20 | 5283 | + |
da5b3fc8 | 5284 | + if (tsk == current) { |
5285 | + mm->context.vdso = ~0UL; | |
73ca38b2 | 5286 | + |
4dee9bd5 | 5287 | +#ifdef CONFIG_X86_32 |
da5b3fc8 | 5288 | +#if defined(CONFIG_PAX_PAGEEXEC) || defined(CONFIG_PAX_SEGMEXEC) |
5289 | + mm->context.user_cs_base = 0UL; | |
5290 | + mm->context.user_cs_limit = ~0UL; | |
73ca38b2 | 5291 | + |
da5b3fc8 | 5292 | +#if defined(CONFIG_PAX_PAGEEXEC) && defined(CONFIG_SMP) |
5293 | + cpus_clear(mm->context.cpu_user_cs_mask); | |
5294 | +#endif | |
73ca38b2 | 5295 | + |
73ca38b2 | 5296 | +#endif |
4dee9bd5 | 5297 | +#endif |
73ca38b2 | 5298 | + |
da5b3fc8 | 5299 | + } |
5300 | + | |
5301 | return retval; | |
5302 | } | |
8a4b4a5e | 5303 | |
4dee9bd5 | 5304 | @@ -223,6 +241,13 @@ static int write_ldt(void __user *ptr, u |
da5b3fc8 | 5305 | } |
5306 | } | |
50425a20 | 5307 | |
50425a20 | 5308 | +#ifdef CONFIG_PAX_SEGMEXEC |
da5b3fc8 | 5309 | + if ((mm->pax_flags & MF_PAX_SEGMEXEC) && (ldt_info.contents & MODIFY_LDT_CONTENTS_CODE)) { |
5310 | + error = -EINVAL; | |
5311 | + goto out_unlock; | |
5312 | + } | |
50425a20 | 5313 | +#endif |
5314 | + | |
4dee9bd5 | 5315 | fill_ldt(&ldt, &ldt_info); |
da5b3fc8 | 5316 | if (oldmode) |
4dee9bd5 | 5317 | ldt.avl = 0; |
5318 | diff -urNp linux-2.6.25.4/arch/x86/kernel/machine_kexec_32.c linux-2.6.25.4/arch/x86/kernel/machine_kexec_32.c | |
5319 | --- linux-2.6.25.4/arch/x86/kernel/machine_kexec_32.c 2008-05-15 11:00:12.000000000 -0400 | |
5320 | +++ linux-2.6.25.4/arch/x86/kernel/machine_kexec_32.c 2008-05-18 13:33:14.000000000 -0400 | |
5321 | @@ -30,7 +30,7 @@ static u32 kexec_pmd1[1024] PAGE_ALIGNED | |
da5b3fc8 | 5322 | static u32 kexec_pte0[1024] PAGE_ALIGNED; |
5323 | static u32 kexec_pte1[1024] PAGE_ALIGNED; | |
50425a20 | 5324 | |
da5b3fc8 | 5325 | -static void set_idt(void *newidt, __u16 limit) |
5326 | +static void set_idt(struct desc_struct *newidt, __u16 limit) | |
5327 | { | |
4dee9bd5 | 5328 | struct desc_ptr curidt; |
50425a20 | 5329 | |
4dee9bd5 | 5330 | @@ -42,7 +42,7 @@ static void set_idt(void *newidt, __u16 |
da5b3fc8 | 5331 | }; |
50425a20 | 5332 | |
8a4b4a5e | 5333 | |
da5b3fc8 | 5334 | -static void set_gdt(void *newgdt, __u16 limit) |
5335 | +static void set_gdt(struct desc_struct *newgdt, __u16 limit) | |
8a4b4a5e | 5336 | { |
4dee9bd5 | 5337 | struct desc_ptr curgdt; |
50425a20 | 5338 | |
da5b3fc8 | 5339 | @@ -111,10 +111,10 @@ NORET_TYPE void machine_kexec(struct kim |
5340 | local_irq_disable(); | |
5341 | ||
5342 | control_page = page_address(image->control_code_page); | |
5343 | - memcpy(control_page, relocate_kernel, PAGE_SIZE); | |
5344 | + memcpy(control_page, ktla_ktva(relocate_kernel), PAGE_SIZE); | |
8a4b4a5e | 5345 | |
da5b3fc8 | 5346 | page_list[PA_CONTROL_PAGE] = __pa(control_page); |
5347 | - page_list[VA_CONTROL_PAGE] = (unsigned long)relocate_kernel; | |
5348 | + page_list[VA_CONTROL_PAGE] = ktla_ktva((unsigned long)relocate_kernel); | |
5349 | page_list[PA_PGD] = __pa(kexec_pgd); | |
5350 | page_list[VA_PGD] = (unsigned long)kexec_pgd; | |
5351 | #ifdef CONFIG_X86_PAE | |
4dee9bd5 | 5352 | diff -urNp linux-2.6.25.4/arch/x86/kernel/module_32.c linux-2.6.25.4/arch/x86/kernel/module_32.c |
5353 | --- linux-2.6.25.4/arch/x86/kernel/module_32.c 2008-05-15 11:00:12.000000000 -0400 | |
5354 | +++ linux-2.6.25.4/arch/x86/kernel/module_32.c 2008-05-18 13:33:14.000000000 -0400 | |
da5b3fc8 | 5355 | @@ -23,6 +23,8 @@ |
5356 | #include <linux/kernel.h> | |
5357 | #include <linux/bug.h> | |
50425a20 | 5358 | |
da5b3fc8 | 5359 | +#include <asm/desc.h> |
5360 | + | |
5361 | #if 0 | |
5362 | #define DEBUGP printk | |
5363 | #else | |
5364 | @@ -33,9 +35,30 @@ void *module_alloc(unsigned long size) | |
50425a20 | 5365 | { |
da5b3fc8 | 5366 | if (size == 0) |
5367 | return NULL; | |
50425a20 | 5368 | + |
da5b3fc8 | 5369 | +#ifdef CONFIG_PAX_KERNEXEC |
5370 | + return vmalloc(size); | |
50425a20 | 5371 | +#else |
da5b3fc8 | 5372 | return vmalloc_exec(size); |
50425a20 | 5373 | +#endif |
5374 | + | |
50425a20 | 5375 | } |
5376 | ||
da5b3fc8 | 5377 | +#ifdef CONFIG_PAX_KERNEXEC |
5378 | +void *module_alloc_exec(unsigned long size) | |
5379 | +{ | |
5380 | + struct vm_struct *area; | |
5381 | + | |
5382 | + if (size == 0) | |
5383 | + return NULL; | |
5384 | + | |
5385 | + area = __get_vm_area(size, VM_ALLOC, (unsigned long)&MODULES_VADDR, (unsigned long)&MODULES_END); | |
5386 | + if (area) | |
5387 | + return area->addr; | |
5388 | + | |
5389 | + return NULL; | |
5390 | +} | |
5391 | +#endif | |
50425a20 | 5392 | |
da5b3fc8 | 5393 | /* Free memory returned from module_alloc */ |
5394 | void module_free(struct module *mod, void *module_region) | |
5395 | @@ -45,6 +68,45 @@ void module_free(struct module *mod, voi | |
5396 | table entries. */ | |
5397 | } | |
50425a20 | 5398 | |
da5b3fc8 | 5399 | +#ifdef CONFIG_PAX_KERNEXEC |
5400 | +void module_free_exec(struct module *mod, void *module_region) | |
5401 | +{ | |
5402 | + struct vm_struct **p, *tmp; | |
50425a20 | 5403 | + |
da5b3fc8 | 5404 | + if (!module_region) |
5405 | + return; | |
5406 | + | |
5407 | + if ((PAGE_SIZE-1) & (unsigned long)module_region) { | |
5408 | + printk(KERN_ERR "Trying to module_free_exec() bad address (%p)\n", module_region); | |
5409 | + WARN_ON(1); | |
5410 | + return; | |
5411 | + } | |
5412 | + | |
5413 | + write_lock(&vmlist_lock); | |
5414 | + for (p = &vmlist; (tmp = *p) != NULL; p = &tmp->next) | |
5415 | + if (tmp->addr == module_region) | |
5416 | + break; | |
5417 | + | |
5418 | + if (tmp) { | |
5419 | + unsigned long cr0; | |
5420 | + | |
5421 | + pax_open_kernel(cr0); | |
5422 | + memset(tmp->addr, 0xCC, tmp->size); | |
5423 | + pax_close_kernel(cr0); | |
5424 | + | |
5425 | + *p = tmp->next; | |
5426 | + kfree(tmp); | |
5427 | + } | |
5428 | + write_unlock(&vmlist_lock); | |
5429 | + | |
5430 | + if (!tmp) { | |
5431 | + printk(KERN_ERR "Trying to module_free_exec() nonexistent vm area (%p)\n", | |
5432 | + module_region); | |
5433 | + WARN_ON(1); | |
5434 | + } | |
5435 | +} | |
50425a20 | 5436 | +#endif |
5437 | + | |
da5b3fc8 | 5438 | /* We don't need anything special. */ |
5439 | int module_frob_arch_sections(Elf_Ehdr *hdr, | |
5440 | Elf_Shdr *sechdrs, | |
5441 | @@ -63,14 +125,20 @@ int apply_relocate(Elf32_Shdr *sechdrs, | |
5442 | unsigned int i; | |
5443 | Elf32_Rel *rel = (void *)sechdrs[relsec].sh_addr; | |
5444 | Elf32_Sym *sym; | |
5445 | - uint32_t *location; | |
5446 | + uint32_t *plocation, location; | |
5447 | + | |
5448 | +#ifdef CONFIG_PAX_KERNEXEC | |
5449 | + unsigned long cr0; | |
5450 | +#endif | |
50425a20 | 5451 | |
da5b3fc8 | 5452 | DEBUGP("Applying relocate section %u to %u\n", relsec, |
5453 | sechdrs[relsec].sh_info); | |
5454 | for (i = 0; i < sechdrs[relsec].sh_size / sizeof(*rel); i++) { | |
5455 | /* This is where to make the change */ | |
5456 | - location = (void *)sechdrs[sechdrs[relsec].sh_info].sh_addr | |
5457 | - + rel[i].r_offset; | |
5458 | + plocation = (void *)sechdrs[sechdrs[relsec].sh_info].sh_addr + rel[i].r_offset; | |
5459 | + location = (uint32_t)plocation; | |
5460 | + if (sechdrs[sechdrs[relsec].sh_info].sh_flags & SHF_EXECINSTR) | |
5461 | + plocation = ktla_ktva((void *)plocation); | |
5462 | /* This is the symbol it is referring to. Note that all | |
5463 | undefined symbols have been resolved. */ | |
5464 | sym = (Elf32_Sym *)sechdrs[symindex].sh_addr | |
5465 | @@ -78,12 +146,32 @@ int apply_relocate(Elf32_Shdr *sechdrs, | |
50425a20 | 5466 | |
da5b3fc8 | 5467 | switch (ELF32_R_TYPE(rel[i].r_info)) { |
5468 | case R_386_32: | |
5469 | + | |
5470 | +#ifdef CONFIG_PAX_KERNEXEC | |
5471 | + pax_open_kernel(cr0); | |
5472 | +#endif | |
5473 | + | |
5474 | /* We add the value into the location given */ | |
5475 | - *location += sym->st_value; | |
5476 | + *plocation += sym->st_value; | |
5477 | + | |
5478 | +#ifdef CONFIG_PAX_KERNEXEC | |
5479 | + pax_close_kernel(cr0); | |
5480 | +#endif | |
5481 | + | |
5482 | break; | |
5483 | case R_386_PC32: | |
5484 | + | |
5485 | +#ifdef CONFIG_PAX_KERNEXEC | |
5486 | + pax_open_kernel(cr0); | |
5487 | +#endif | |
5488 | + | |
5489 | /* Add the value, subtract its postition */ | |
5490 | - *location += sym->st_value - (uint32_t)location; | |
5491 | + *plocation += sym->st_value - location; | |
5492 | + | |
5493 | +#ifdef CONFIG_PAX_KERNEXEC | |
5494 | + pax_close_kernel(cr0); | |
5495 | +#endif | |
5496 | + | |
5497 | break; | |
5498 | default: | |
5499 | printk(KERN_ERR "module %s: Unknown relocation: %u\n", | |
4dee9bd5 | 5500 | diff -urNp linux-2.6.25.4/arch/x86/kernel/module_64.c linux-2.6.25.4/arch/x86/kernel/module_64.c |
5501 | --- linux-2.6.25.4/arch/x86/kernel/module_64.c 2008-05-15 11:00:12.000000000 -0400 | |
5502 | +++ linux-2.6.25.4/arch/x86/kernel/module_64.c 2008-05-18 13:33:14.000000000 -0400 | |
da5b3fc8 | 5503 | @@ -39,7 +39,7 @@ void module_free(struct module *mod, voi |
5504 | table entries. */ | |
50425a20 | 5505 | } |
5506 | ||
da5b3fc8 | 5507 | -void *module_alloc(unsigned long size) |
5508 | +static void *__module_alloc(unsigned long size, pgprot_t prot) | |
50425a20 | 5509 | { |
da5b3fc8 | 5510 | struct vm_struct *area; |
50425a20 | 5511 | |
da5b3fc8 | 5512 | @@ -53,8 +53,31 @@ void *module_alloc(unsigned long size) |
5513 | if (!area) | |
5514 | return NULL; | |
5515 | ||
5516 | - return __vmalloc_area(area, GFP_KERNEL, PAGE_KERNEL_EXEC); | |
5517 | + return __vmalloc_area(area, GFP_KERNEL | __GFP_ZERO, prot); | |
5518 | +} | |
5519 | + | |
5520 | +#ifdef CONFIG_PAX_KERNEXEC | |
5521 | +void *module_alloc(unsigned long size) | |
5522 | +{ | |
5523 | + return __module_alloc(size, PAGE_KERNEL); | |
5524 | +} | |
5525 | + | |
5526 | +void module_free_exec(struct module *mod, void *module_region) | |
5527 | +{ | |
5528 | + module_free(mod, module_region); | |
5529 | +} | |
5530 | + | |
5531 | +void *module_alloc_exec(unsigned long size) | |
5532 | +{ | |
5533 | + return __module_alloc(size, PAGE_KERNEL_RX); | |
8a4b4a5e | 5534 | } |
da5b3fc8 | 5535 | +#else |
5536 | +void *module_alloc(unsigned long size) | |
5537 | +{ | |
5538 | + return __module_alloc(size, PAGE_KERNEL_EXEC); | |
5539 | +} | |
8a4b4a5e | 5540 | +#endif |
da5b3fc8 | 5541 | + |
5542 | #endif | |
8a4b4a5e | 5543 | |
da5b3fc8 | 5544 | /* We don't need anything special. */ |
5545 | @@ -76,7 +99,11 @@ int apply_relocate_add(Elf64_Shdr *sechd | |
5546 | Elf64_Rela *rel = (void *)sechdrs[relsec].sh_addr; | |
5547 | Elf64_Sym *sym; | |
5548 | void *loc; | |
5549 | - u64 val; | |
5550 | + u64 val; | |
5551 | + | |
5552 | +#ifdef CONFIG_PAX_KERNEXEC | |
5553 | + unsigned long cr0; | |
5554 | +#endif | |
50425a20 | 5555 | |
da5b3fc8 | 5556 | DEBUGP("Applying relocate section %u to %u\n", relsec, |
5557 | sechdrs[relsec].sh_info); | |
5558 | @@ -100,21 +127,61 @@ int apply_relocate_add(Elf64_Shdr *sechd | |
5559 | case R_X86_64_NONE: | |
5560 | break; | |
5561 | case R_X86_64_64: | |
5562 | + | |
5563 | +#ifdef CONFIG_PAX_KERNEXEC | |
5564 | + pax_open_kernel(cr0); | |
5565 | +#endif | |
5566 | + | |
5567 | *(u64 *)loc = val; | |
5568 | + | |
5569 | +#ifdef CONFIG_PAX_KERNEXEC | |
5570 | + pax_close_kernel(cr0); | |
5571 | +#endif | |
5572 | + | |
5573 | break; | |
5574 | case R_X86_64_32: | |
5575 | + | |
5576 | +#ifdef CONFIG_PAX_KERNEXEC | |
5577 | + pax_open_kernel(cr0); | |
5578 | +#endif | |
5579 | + | |
5580 | *(u32 *)loc = val; | |
5581 | + | |
5582 | +#ifdef CONFIG_PAX_KERNEXEC | |
5583 | + pax_close_kernel(cr0); | |
5584 | +#endif | |
5585 | + | |
5586 | if (val != *(u32 *)loc) | |
5587 | goto overflow; | |
5588 | break; | |
5589 | case R_X86_64_32S: | |
5590 | + | |
5591 | +#ifdef CONFIG_PAX_KERNEXEC | |
5592 | + pax_open_kernel(cr0); | |
5593 | +#endif | |
5594 | + | |
5595 | *(s32 *)loc = val; | |
5596 | + | |
5597 | +#ifdef CONFIG_PAX_KERNEXEC | |
5598 | + pax_close_kernel(cr0); | |
5599 | +#endif | |
5600 | + | |
5601 | if ((s64)val != *(s32 *)loc) | |
5602 | goto overflow; | |
5603 | break; | |
5604 | case R_X86_64_PC32: | |
5605 | val -= (u64)loc; | |
5606 | + | |
5607 | +#ifdef CONFIG_PAX_KERNEXEC | |
5608 | + pax_open_kernel(cr0); | |
5609 | +#endif | |
5610 | + | |
5611 | *(u32 *)loc = val; | |
5612 | + | |
5613 | +#ifdef CONFIG_PAX_KERNEXEC | |
5614 | + pax_close_kernel(cr0); | |
5615 | +#endif | |
5616 | + | |
5617 | #if 0 | |
5618 | if ((s64)val != *(s32 *)loc) | |
5619 | goto overflow; | |
4dee9bd5 | 5620 | diff -urNp linux-2.6.25.4/arch/x86/kernel/paravirt.c linux-2.6.25.4/arch/x86/kernel/paravirt.c |
5621 | --- linux-2.6.25.4/arch/x86/kernel/paravirt.c 2008-05-15 11:00:12.000000000 -0400 | |
5622 | +++ linux-2.6.25.4/arch/x86/kernel/paravirt.c 2008-05-18 13:33:14.000000000 -0400 | |
5623 | @@ -42,7 +42,7 @@ void _paravirt_nop(void) | |
b2ee8b1e | 5624 | { |
5625 | } | |
5626 | ||
5627 | -static void __init default_banner(void) | |
5628 | +static void default_banner(void) | |
5629 | { | |
5630 | printk(KERN_INFO "Booting paravirtualized kernel on %s\n", | |
5631 | pv_info.name); | |
4dee9bd5 | 5632 | @@ -159,7 +159,7 @@ unsigned paravirt_patch_insns(void *insn |
da5b3fc8 | 5633 | if (insn_len > len || start == NULL) |
5634 | insn_len = len; | |
5635 | else | |
5636 | - memcpy(insnbuf, start, insn_len); | |
5637 | + memcpy(insnbuf, ktla_ktva(start), insn_len); | |
50425a20 | 5638 | |
da5b3fc8 | 5639 | return insn_len; |
5640 | } | |
4dee9bd5 | 5641 | @@ -277,21 +277,21 @@ enum paravirt_lazy_mode paravirt_get_laz |
5642 | return __get_cpu_var(paravirt_lazy_mode); | |
50425a20 | 5643 | } |
5644 | ||
da5b3fc8 | 5645 | -struct pv_info pv_info = { |
5646 | +struct pv_info pv_info __read_only = { | |
5647 | .name = "bare hardware", | |
5648 | .paravirt_enabled = 0, | |
5649 | .kernel_rpl = 0, | |
5650 | .shared_kernel_pmd = 1, /* Only used when CONFIG_X86_PAE is set */ | |
5651 | }; | |
50425a20 | 5652 | |
da5b3fc8 | 5653 | -struct pv_init_ops pv_init_ops = { |
5654 | +struct pv_init_ops pv_init_ops __read_only = { | |
5655 | .patch = native_patch, | |
5656 | .banner = default_banner, | |
5657 | .arch_setup = paravirt_nop, | |
5658 | .memory_setup = machine_specific_memory_setup, | |
5659 | }; | |
50425a20 | 5660 | |
da5b3fc8 | 5661 | -struct pv_time_ops pv_time_ops = { |
5662 | +struct pv_time_ops pv_time_ops __read_only = { | |
5663 | .time_init = hpet_time_init, | |
5664 | .get_wallclock = native_get_wallclock, | |
5665 | .set_wallclock = native_set_wallclock, | |
4dee9bd5 | 5666 | @@ -299,7 +299,7 @@ struct pv_time_ops pv_time_ops = { |
da5b3fc8 | 5667 | .get_cpu_khz = native_calculate_cpu_khz, |
5668 | }; | |
50425a20 | 5669 | |
da5b3fc8 | 5670 | -struct pv_irq_ops pv_irq_ops = { |
5671 | +struct pv_irq_ops pv_irq_ops __read_only = { | |
5672 | .init_IRQ = native_init_IRQ, | |
5673 | .save_fl = native_save_fl, | |
5674 | .restore_fl = native_restore_fl, | |
4dee9bd5 | 5675 | @@ -309,7 +309,7 @@ struct pv_irq_ops pv_irq_ops = { |
da5b3fc8 | 5676 | .halt = native_halt, |
5677 | }; | |
50425a20 | 5678 | |
da5b3fc8 | 5679 | -struct pv_cpu_ops pv_cpu_ops = { |
5680 | +struct pv_cpu_ops pv_cpu_ops __read_only = { | |
5681 | .cpuid = native_cpuid, | |
5682 | .get_debugreg = native_get_debugreg, | |
5683 | .set_debugreg = native_set_debugreg, | |
4dee9bd5 | 5684 | @@ -355,7 +355,7 @@ struct pv_cpu_ops pv_cpu_ops = { |
da5b3fc8 | 5685 | }, |
5686 | }; | |
50425a20 | 5687 | |
da5b3fc8 | 5688 | -struct pv_apic_ops pv_apic_ops = { |
5689 | +struct pv_apic_ops pv_apic_ops __read_only = { | |
5690 | #ifdef CONFIG_X86_LOCAL_APIC | |
5691 | .apic_write = native_apic_write, | |
5692 | .apic_write_atomic = native_apic_write_atomic, | |
4dee9bd5 | 5693 | @@ -366,7 +366,7 @@ struct pv_apic_ops pv_apic_ops = { |
da5b3fc8 | 5694 | #endif |
5695 | }; | |
50425a20 | 5696 | |
da5b3fc8 | 5697 | -struct pv_mmu_ops pv_mmu_ops = { |
5698 | +struct pv_mmu_ops pv_mmu_ops __read_only = { | |
4dee9bd5 | 5699 | #ifndef CONFIG_X86_64 |
da5b3fc8 | 5700 | .pagetable_setup_start = native_pagetable_setup_start, |
5701 | .pagetable_setup_done = native_pagetable_setup_done, | |
4dee9bd5 | 5702 | diff -urNp linux-2.6.25.4/arch/x86/kernel/process_32.c linux-2.6.25.4/arch/x86/kernel/process_32.c |
5703 | --- linux-2.6.25.4/arch/x86/kernel/process_32.c 2008-05-15 11:00:12.000000000 -0400 | |
5704 | +++ linux-2.6.25.4/arch/x86/kernel/process_32.c 2008-05-18 13:33:14.000000000 -0400 | |
5705 | @@ -66,8 +66,10 @@ EXPORT_SYMBOL(boot_option_idle_override) | |
da5b3fc8 | 5706 | DEFINE_PER_CPU(struct task_struct *, current_task) = &init_task; |
5707 | EXPORT_PER_CPU_SYMBOL(current_task); | |
50425a20 | 5708 | |
da5b3fc8 | 5709 | +#ifdef CONFIG_SMP |
5710 | DEFINE_PER_CPU(int, cpu_number); | |
5711 | EXPORT_PER_CPU_SYMBOL(cpu_number); | |
5712 | +#endif | |
50425a20 | 5713 | |
da5b3fc8 | 5714 | /* |
5715 | * Return saved PC of a blocked thread. | |
4dee9bd5 | 5716 | @@ -75,6 +77,7 @@ EXPORT_PER_CPU_SYMBOL(cpu_number); |
da5b3fc8 | 5717 | unsigned long thread_saved_pc(struct task_struct *tsk) |
5718 | { | |
4dee9bd5 | 5719 | return ((unsigned long *)tsk->thread.sp)[3]; |
5720 | +//XXX return tsk->thread.eip; | |
da5b3fc8 | 5721 | } |
50425a20 | 5722 | |
da5b3fc8 | 5723 | /* |
4dee9bd5 | 5724 | @@ -314,7 +317,7 @@ void __show_registers(struct pt_regs *re |
5725 | unsigned long sp; | |
da5b3fc8 | 5726 | unsigned short ss, gs; |
50425a20 | 5727 | |
da5b3fc8 | 5728 | - if (user_mode_vm(regs)) { |
5729 | + if (user_mode(regs)) { | |
4dee9bd5 | 5730 | sp = regs->sp; |
5731 | ss = regs->ss & 0xffff; | |
da5b3fc8 | 5732 | savesegment(gs, gs); |
4dee9bd5 | 5733 | @@ -392,8 +395,8 @@ int kernel_thread(int (*fn)(void *), voi |
5734 | regs.bx = (unsigned long) fn; | |
5735 | regs.dx = (unsigned long) arg; | |
5736 | ||
5737 | - regs.ds = __USER_DS; | |
5738 | - regs.es = __USER_DS; | |
5739 | + regs.ds = __KERNEL_DS; | |
5740 | + regs.es = __KERNEL_DS; | |
5741 | regs.fs = __KERNEL_PERCPU; | |
5742 | regs.orig_ax = -1; | |
5743 | regs.ip = (unsigned long) kernel_thread_helper; | |
5744 | @@ -415,7 +418,7 @@ void exit_thread(void) | |
da5b3fc8 | 5745 | struct task_struct *tsk = current; |
5746 | struct thread_struct *t = &tsk->thread; | |
5747 | int cpu = get_cpu(); | |
5748 | - struct tss_struct *tss = &per_cpu(init_tss, cpu); | |
5749 | + struct tss_struct *tss = init_tss + cpu; | |
5750 | ||
5751 | kfree(t->io_bitmap_ptr); | |
5752 | t->io_bitmap_ptr = NULL; | |
4dee9bd5 | 5753 | @@ -436,6 +439,7 @@ void flush_thread(void) |
50425a20 | 5754 | { |
da5b3fc8 | 5755 | struct task_struct *tsk = current; |
5756 | ||
5757 | + __asm__("mov %0,%%gs\n" : : "r" (0) : "memory"); | |
4dee9bd5 | 5758 | tsk->thread.debugreg0 = 0; |
5759 | tsk->thread.debugreg1 = 0; | |
5760 | tsk->thread.debugreg2 = 0; | |
5761 | @@ -474,7 +478,7 @@ int copy_thread(int nr, unsigned long cl | |
da5b3fc8 | 5762 | struct task_struct *tsk; |
5763 | int err; | |
5764 | ||
5765 | - childregs = task_pt_regs(p); | |
5766 | + childregs = task_stack_page(p) + THREAD_SIZE - sizeof(struct pt_regs) - 8; | |
5767 | *childregs = *regs; | |
4dee9bd5 | 5768 | childregs->ax = 0; |
5769 | childregs->sp = sp; | |
5770 | @@ -503,6 +507,7 @@ int copy_thread(int nr, unsigned long cl | |
5771 | * Set a new TLS for the child thread? | |
5772 | */ | |
5773 | if (clone_flags & CLONE_SETTLS) | |
5774 | +//XXX needs set_fs()? | |
5775 | err = do_set_thread_area(p, -1, | |
5776 | (struct user_desc __user *)childregs->si, 0); | |
50425a20 | 5777 | |
4dee9bd5 | 5778 | @@ -649,7 +654,7 @@ struct task_struct * __switch_to(struct |
da5b3fc8 | 5779 | struct thread_struct *prev = &prev_p->thread, |
5780 | *next = &next_p->thread; | |
5781 | int cpu = smp_processor_id(); | |
5782 | - struct tss_struct *tss = &per_cpu(init_tss, cpu); | |
5783 | + struct tss_struct *tss = init_tss + cpu; | |
50425a20 | 5784 | |
da5b3fc8 | 5785 | /* never put a printk in __switch_to... printk() calls wake_up*() indirectly */ |
50425a20 | 5786 | |
4dee9bd5 | 5787 | @@ -677,6 +682,11 @@ struct task_struct * __switch_to(struct |
da5b3fc8 | 5788 | */ |
5789 | savesegment(gs, prev->gs); | |
50425a20 | 5790 | |
da5b3fc8 | 5791 | +#ifdef CONFIG_PAX_MEMORY_UDEREF |
5792 | + if (!segment_eq(task_thread_info(prev_p)->addr_limit, task_thread_info(next_p)->addr_limit)) | |
5793 | + __set_fs(task_thread_info(next_p)->addr_limit, cpu); | |
5794 | +#endif | |
5795 | + | |
5796 | /* | |
5797 | * Load the per-thread Thread-Local Storage descriptor. | |
5798 | */ | |
4dee9bd5 | 5799 | @@ -812,15 +822,27 @@ unsigned long get_wchan(struct task_stru |
da5b3fc8 | 5800 | return 0; |
5801 | } | |
5802 | ||
5803 | -unsigned long arch_align_stack(unsigned long sp) | |
5804 | +#ifdef CONFIG_PAX_RANDKSTACK | |
5805 | +asmlinkage void pax_randomize_kstack(void) | |
5806 | { | |
5807 | - if (!(current->personality & ADDR_NO_RANDOMIZE) && randomize_va_space) | |
5808 | - sp -= get_random_int() % 8192; | |
5809 | - return sp & ~0xf; | |
4dee9bd5 | 5810 | -} |
da5b3fc8 | 5811 | + struct thread_struct *thread = ¤t->thread; |
5812 | + unsigned long time; | |
4dee9bd5 | 5813 | |
5814 | -unsigned long arch_randomize_brk(struct mm_struct *mm) | |
5815 | -{ | |
5816 | - unsigned long range_end = mm->brk + 0x02000000; | |
5817 | - return randomize_range(mm->brk, range_end, 0) ? : mm->brk; | |
da5b3fc8 | 5818 | + if (!randomize_va_space) |
5819 | + return; | |
50425a20 | 5820 | + |
da5b3fc8 | 5821 | + rdtscl(time); |
50425a20 | 5822 | + |
da5b3fc8 | 5823 | + /* P4 seems to return a 0 LSB, ignore it */ |
5824 | +#ifdef CONFIG_MPENTIUM4 | |
5825 | + time &= 0x1EUL; | |
5826 | + time <<= 2; | |
5827 | +#else | |
5828 | + time &= 0xFUL; | |
5829 | + time <<= 3; | |
50425a20 | 5830 | +#endif |
5831 | + | |
4dee9bd5 | 5832 | + thread->sp0 ^= time; |
5833 | + load_sp0(init_tss + smp_processor_id(), thread); | |
da5b3fc8 | 5834 | } |
5835 | +#endif | |
4dee9bd5 | 5836 | diff -urNp linux-2.6.25.4/arch/x86/kernel/process_64.c linux-2.6.25.4/arch/x86/kernel/process_64.c |
5837 | --- linux-2.6.25.4/arch/x86/kernel/process_64.c 2008-05-15 11:00:12.000000000 -0400 | |
5838 | +++ linux-2.6.25.4/arch/x86/kernel/process_64.c 2008-05-18 13:33:14.000000000 -0400 | |
5839 | @@ -166,6 +166,8 @@ static inline void play_dead(void) | |
5840 | void cpu_idle(void) | |
da5b3fc8 | 5841 | { |
5842 | current_thread_info()->status |= TS_POLLING; | |
5843 | + current->stack_canary = pax_get_random_long(); | |
5844 | + write_pda(stack_canary, current->stack_canary); | |
5845 | /* endless idle loop with no priority at all */ | |
5846 | while (1) { | |
7bcbf78a | 5847 | tick_nohz_stop_sched_tick(); |
4dee9bd5 | 5848 | @@ -379,7 +381,7 @@ void exit_thread(void) |
da5b3fc8 | 5849 | struct thread_struct *t = &me->thread; |
5850 | ||
4dee9bd5 | 5851 | if (me->thread.io_bitmap_ptr) { |
da5b3fc8 | 5852 | - struct tss_struct *tss = &per_cpu(init_tss, get_cpu()); |
5853 | + struct tss_struct *tss = init_tss + get_cpu(); | |
50425a20 | 5854 | |
da5b3fc8 | 5855 | kfree(t->io_bitmap_ptr); |
5856 | t->io_bitmap_ptr = NULL; | |
4dee9bd5 | 5857 | @@ -603,7 +605,7 @@ __switch_to(struct task_struct *prev_p, |
da5b3fc8 | 5858 | struct thread_struct *prev = &prev_p->thread, |
5859 | *next = &next_p->thread; | |
4dee9bd5 | 5860 | int cpu = smp_processor_id(); |
da5b3fc8 | 5861 | - struct tss_struct *tss = &per_cpu(init_tss, cpu); |
5862 | + struct tss_struct *tss = init_tss + cpu; | |
8a4b4a5e | 5863 | |
da5b3fc8 | 5864 | /* we're going to use this soon, after a few expensive things */ |
5865 | if (next_p->fpu_counter>5) | |
4dee9bd5 | 5866 | @@ -678,7 +680,6 @@ __switch_to(struct task_struct *prev_p, |
da5b3fc8 | 5867 | write_pda(kernelstack, |
5868 | (unsigned long)task_stack_page(next_p) + THREAD_SIZE - PDA_STACKOFFSET); | |
5869 | #ifdef CONFIG_CC_STACKPROTECTOR | |
5870 | - write_pda(stack_canary, next_p->stack_canary); | |
5871 | /* | |
5872 | * Build time only check to make sure the stack_canary is at | |
5873 | * offset 40 in the pda; this is a gcc ABI requirement | |
4dee9bd5 | 5874 | @@ -889,16 +890,3 @@ long sys_arch_prctl(int code, unsigned l |
da5b3fc8 | 5875 | { |
4dee9bd5 | 5876 | return do_arch_prctl(current, code, addr); |
da5b3fc8 | 5877 | } |
5878 | - | |
5879 | -unsigned long arch_align_stack(unsigned long sp) | |
5880 | -{ | |
5881 | - if (!(current->personality & ADDR_NO_RANDOMIZE) && randomize_va_space) | |
5882 | - sp -= get_random_int() % 8192; | |
5883 | - return sp & ~0xf; | |
5884 | -} | |
4dee9bd5 | 5885 | - |
5886 | -unsigned long arch_randomize_brk(struct mm_struct *mm) | |
5887 | -{ | |
5888 | - unsigned long range_end = mm->brk + 0x02000000; | |
5889 | - return randomize_range(mm->brk, range_end, 0) ? : mm->brk; | |
5890 | -} | |
5891 | diff -urNp linux-2.6.25.4/arch/x86/kernel/ptrace.c linux-2.6.25.4/arch/x86/kernel/ptrace.c | |
5892 | --- linux-2.6.25.4/arch/x86/kernel/ptrace.c 2008-05-15 11:00:12.000000000 -0400 | |
5893 | +++ linux-2.6.25.4/arch/x86/kernel/ptrace.c 2008-05-18 13:33:14.000000000 -0400 | |
5894 | @@ -1447,7 +1447,7 @@ void send_sigtrap(struct task_struct *ts | |
da5b3fc8 | 5895 | info.si_code = TRAP_BRKPT; |
50425a20 | 5896 | |
4dee9bd5 | 5897 | /* User-mode ip? */ |
5898 | - info.si_addr = user_mode_vm(regs) ? (void __user *) regs->ip : NULL; | |
5899 | + info.si_addr = user_mode(regs) ? (void __user *) regs->ip : NULL; | |
8a4b4a5e | 5900 | |
da5b3fc8 | 5901 | /* Send us the fake SIGTRAP */ |
5902 | force_sig_info(SIGTRAP, &info, tsk); | |
4dee9bd5 | 5903 | diff -urNp linux-2.6.25.4/arch/x86/kernel/reboot.c linux-2.6.25.4/arch/x86/kernel/reboot.c |
5904 | --- linux-2.6.25.4/arch/x86/kernel/reboot.c 2008-05-15 11:00:12.000000000 -0400 | |
5905 | +++ linux-2.6.25.4/arch/x86/kernel/reboot.c 2008-05-18 13:33:14.000000000 -0400 | |
5906 | @@ -28,7 +28,7 @@ void (*pm_power_off)(void); | |
da5b3fc8 | 5907 | EXPORT_SYMBOL(pm_power_off); |
50425a20 | 5908 | |
4dee9bd5 | 5909 | static long no_idt[3]; |
da5b3fc8 | 5910 | -static int reboot_mode; |
5911 | +static unsigned short reboot_mode; | |
4dee9bd5 | 5912 | enum reboot_type reboot_type = BOOT_KBD; |
5913 | int reboot_force; | |
50425a20 | 5914 | |
4dee9bd5 | 5915 | @@ -186,7 +186,7 @@ static struct dmi_system_id __initdata r |
da5b3fc8 | 5916 | DMI_MATCH(DMI_PRODUCT_NAME, "HP Compaq"), |
50425a20 | 5917 | }, |
5918 | }, | |
da5b3fc8 | 5919 | - { } |
5920 | + { NULL, NULL, {{0, NULL}}, NULL} | |
50425a20 | 5921 | }; |
5922 | ||
da5b3fc8 | 5923 | static int __init reboot_init(void) |
4dee9bd5 | 5924 | @@ -202,16 +202,16 @@ core_initcall(reboot_init); |
5925 | controller to pulse the CPU reset line, which is more thorough, but | |
da5b3fc8 | 5926 | doesn't work with at least one type of 486 motherboard. It is easy |
5927 | to stop this code working; hence the copious comments. */ | |
da5b3fc8 | 5928 | -static unsigned long long |
5929 | -real_mode_gdt_entries [3] = | |
5930 | +static struct desc_struct | |
5931 | +real_mode_gdt_entries [3] __read_only = | |
50425a20 | 5932 | { |
da5b3fc8 | 5933 | - 0x0000000000000000ULL, /* Null descriptor */ |
5934 | - 0x00009a000000ffffULL, /* 16-bit real-mode 64k code at 0x00000000 */ | |
5935 | - 0x000092000100ffffULL /* 16-bit real-mode 64k data at 0x00000100 */ | |
4dee9bd5 | 5936 | + {{{0x00000000, 0x00000000}}}, /* Null descriptor */ |
5937 | + {{{0x0000ffff, 0x00009b00}}}, /* 16-bit real-mode 64k code at 0x00000000 */ | |
5938 | + {{{0x0100ffff, 0x00009300}}} /* 16-bit real-mode 64k data at 0x00000100 */ | |
50425a20 | 5939 | }; |
5940 | ||
4dee9bd5 | 5941 | -static struct desc_ptr |
da5b3fc8 | 5942 | -real_mode_gdt = { sizeof (real_mode_gdt_entries) - 1, (long)real_mode_gdt_entries }, |
4dee9bd5 | 5943 | +static const struct desc_ptr |
5944 | +real_mode_gdt = { sizeof (real_mode_gdt_entries) - 1, (long)__pa(real_mode_gdt_entries) }, | |
5945 | real_mode_idt = { 0x3ff, 0 }; | |
50425a20 | 5946 | |
da5b3fc8 | 5947 | /* This is 16-bit protected mode code to disable paging and the cache, |
4dee9bd5 | 5948 | @@ -232,7 +232,7 @@ real_mode_idt = { 0x3ff, 0 }; |
5949 | ||
da5b3fc8 | 5950 | More could be done here to set up the registers as if a CPU reset had |
5951 | occurred; hopefully real BIOSs don't assume much. */ | |
da5b3fc8 | 5952 | -static unsigned char real_mode_switch [] = |
5953 | +static const unsigned char real_mode_switch [] = | |
5954 | { | |
5955 | 0x66, 0x0f, 0x20, 0xc0, /* movl %cr0,%eax */ | |
5956 | 0x66, 0x83, 0xe0, 0x11, /* andl $0x00000011,%eax */ | |
4dee9bd5 | 5957 | @@ -246,7 +246,7 @@ static unsigned char real_mode_switch [] |
da5b3fc8 | 5958 | 0x24, 0x10, /* f: andb $0x10,al */ |
5959 | 0x66, 0x0f, 0x22, 0xc0 /* movl %eax,%cr0 */ | |
5960 | }; | |
5961 | -static unsigned char jump_to_bios [] = | |
5962 | +static const unsigned char jump_to_bios [] = | |
5963 | { | |
5964 | 0xea, 0x00, 0x00, 0xff, 0xff /* ljmp $0xffff,$0x0000 */ | |
5965 | }; | |
4dee9bd5 | 5966 | @@ -256,7 +256,7 @@ static unsigned char jump_to_bios [] = |
da5b3fc8 | 5967 | * specified by the code and length parameters. |
5968 | * We assume that length will aways be less that 100! | |
8a4b4a5e | 5969 | */ |
da5b3fc8 | 5970 | -void machine_real_restart(unsigned char *code, int length) |
5971 | +void machine_real_restart(const unsigned char *code, unsigned int length) | |
8a4b4a5e | 5972 | { |
da5b3fc8 | 5973 | local_irq_disable(); |
50425a20 | 5974 | |
4dee9bd5 | 5975 | @@ -276,8 +276,8 @@ void machine_real_restart(unsigned char |
5976 | /* Remap the kernel at virtual address zero, as well as offset zero | |
da5b3fc8 | 5977 | from the kernel segment. This assumes the kernel segment starts at |
5978 | virtual address PAGE_OFFSET. */ | |
4dee9bd5 | 5979 | - memcpy(swapper_pg_dir, swapper_pg_dir + USER_PGD_PTRS, |
5980 | - sizeof(swapper_pg_dir [0]) * KERNEL_PGD_PTRS); | |
da5b3fc8 | 5981 | + clone_pgd_range(swapper_pg_dir, swapper_pg_dir + USER_PGD_PTRS, |
5982 | + min_t(unsigned long, KERNEL_PGD_PTRS, USER_PGD_PTRS)); | |
5983 | ||
5984 | /* | |
5985 | * Use `swapper_pg_dir' as our page directory. | |
4dee9bd5 | 5986 | @@ -289,16 +289,15 @@ void machine_real_restart(unsigned char |
5987 | boot)". This seems like a fairly standard thing that gets set by | |
da5b3fc8 | 5988 | REBOOT.COM programs, and the previous reset routine did this |
5989 | too. */ | |
da5b3fc8 | 5990 | - *((unsigned short *)0x472) = reboot_mode; |
5991 | + *(unsigned short *)(__va(0x472)) = reboot_mode; | |
5992 | ||
5993 | /* For the switch to real mode, copy some code to low memory. It has | |
5994 | to be in the first 64k because it is running in 16-bit mode, and it | |
4dee9bd5 | 5995 | has to have the same physical and virtual address, because it turns |
da5b3fc8 | 5996 | off paging. Copy it near the end of the first page, out of the way |
5997 | of BIOS variables. */ | |
4dee9bd5 | 5998 | - memcpy((void *)(0x1000 - sizeof(real_mode_switch) - 100), |
da5b3fc8 | 5999 | - real_mode_switch, sizeof (real_mode_switch)); |
4dee9bd5 | 6000 | - memcpy((void *)(0x1000 - 100), code, length); |
da5b3fc8 | 6001 | + memcpy(__va(0x1000 - sizeof (real_mode_switch) - 100), real_mode_switch, sizeof (real_mode_switch)); |
6002 | + memcpy(__va(0x1000 - 100), code, length); | |
6003 | ||
6004 | /* Set up the IDT for real mode. */ | |
4dee9bd5 | 6005 | load_idt(&real_mode_idt); |
6006 | diff -urNp linux-2.6.25.4/arch/x86/kernel/setup_32.c linux-2.6.25.4/arch/x86/kernel/setup_32.c | |
6007 | --- linux-2.6.25.4/arch/x86/kernel/setup_32.c 2008-05-15 11:00:12.000000000 -0400 | |
6008 | +++ linux-2.6.25.4/arch/x86/kernel/setup_32.c 2008-05-18 13:33:14.000000000 -0400 | |
6009 | @@ -64,6 +64,7 @@ | |
da5b3fc8 | 6010 | #include <setup_arch.h> |
6011 | #include <bios_ebda.h> | |
6012 | #include <asm/cacheflush.h> | |
6013 | +#include <asm/boot.h> | |
6014 | ||
6015 | /* This value is set up by the early boot code to point to the value | |
6016 | immediately after the boot time page tables. It contains a *physical* | |
4dee9bd5 | 6017 | @@ -607,8 +608,8 @@ void __init setup_bootmem_allocator(void |
da5b3fc8 | 6018 | * the (very unlikely) case of us accidentally initializing the |
6019 | * bootmem allocator with an invalid RAM area. | |
6020 | */ | |
6021 | - reserve_bootmem(__pa_symbol(_text), (PFN_PHYS(min_low_pfn) + | |
4dee9bd5 | 6022 | - bootmap_size + PAGE_SIZE-1) - __pa_symbol(_text), |
da5b3fc8 | 6023 | + reserve_bootmem(LOAD_PHYSICAL_ADDR, (PFN_PHYS(min_low_pfn) + |
4dee9bd5 | 6024 | + bootmap_size + PAGE_SIZE-1) - LOAD_PHYSICAL_ADDR, |
6025 | BOOTMEM_DEFAULT); | |
da5b3fc8 | 6026 | |
6027 | /* | |
4dee9bd5 | 6028 | @@ -737,14 +738,14 @@ void __init setup_arch(char **cmdline_p) |
da5b3fc8 | 6029 | |
6030 | if (!boot_params.hdr.root_flags) | |
6031 | root_mountflags &= ~MS_RDONLY; | |
6032 | - init_mm.start_code = (unsigned long) _text; | |
6033 | - init_mm.end_code = (unsigned long) _etext; | |
6034 | + init_mm.start_code = ktla_ktva((unsigned long) _text); | |
6035 | + init_mm.end_code = ktla_ktva((unsigned long) _etext); | |
6036 | init_mm.end_data = (unsigned long) _edata; | |
6037 | init_mm.brk = init_pg_tables_end + PAGE_OFFSET; | |
6038 | ||
6039 | - code_resource.start = virt_to_phys(_text); | |
6040 | - code_resource.end = virt_to_phys(_etext)-1; | |
6041 | - data_resource.start = virt_to_phys(_etext); | |
6042 | + code_resource.start = virt_to_phys(ktla_ktva(_text)); | |
6043 | + code_resource.end = virt_to_phys(ktla_ktva(_etext))-1; | |
6044 | + data_resource.start = virt_to_phys(_data); | |
6045 | data_resource.end = virt_to_phys(_edata)-1; | |
6046 | bss_resource.start = virt_to_phys(&__bss_start); | |
6047 | bss_resource.end = virt_to_phys(&__bss_stop)-1; | |
4dee9bd5 | 6048 | diff -urNp linux-2.6.25.4/arch/x86/kernel/setup64.c linux-2.6.25.4/arch/x86/kernel/setup64.c |
6049 | --- linux-2.6.25.4/arch/x86/kernel/setup64.c 2008-05-15 11:00:12.000000000 -0400 | |
6050 | +++ linux-2.6.25.4/arch/x86/kernel/setup64.c 2008-05-18 13:33:14.000000000 -0400 | |
6051 | @@ -36,15 +36,13 @@ struct x8664_pda *_cpu_pda[NR_CPUS] __re | |
da5b3fc8 | 6052 | EXPORT_SYMBOL(_cpu_pda); |
6053 | struct x8664_pda boot_cpu_pda[NR_CPUS] __cacheline_aligned; | |
8a4b4a5e | 6054 | |
da5b3fc8 | 6055 | -struct desc_ptr idt_descr = { 256 * 16 - 1, (unsigned long) idt_table }; |
84cd3cb1 | 6056 | +struct desc_ptr idt_descr __read_only = { 256 * 16 - 1, (unsigned long) idt_table }; |
8a4b4a5e | 6057 | |
da5b3fc8 | 6058 | char boot_cpu_stack[IRQSTACKSIZE] __attribute__((section(".bss.page_aligned"))); |
8a4b4a5e | 6059 | |
da5b3fc8 | 6060 | unsigned long __supported_pte_mask __read_mostly = ~0UL; |
4dee9bd5 | 6061 | EXPORT_SYMBOL_GPL(__supported_pte_mask); |
8a4b4a5e | 6062 | |
4dee9bd5 | 6063 | -static int do_not_nx __cpuinitdata = 0; |
6064 | - | |
da5b3fc8 | 6065 | /* noexec=on|off |
6066 | Control non executable mappings for 64bit processes. | |
4dee9bd5 | 6067 | |
6068 | @@ -57,16 +55,14 @@ static int __init nonx_setup(char *str) | |
da5b3fc8 | 6069 | return -EINVAL; |
6070 | if (!strncmp(str, "on", 2)) { | |
6071 | __supported_pte_mask |= _PAGE_NX; | |
6072 | - do_not_nx = 0; | |
6073 | } else if (!strncmp(str, "off", 3)) { | |
6074 | - do_not_nx = 1; | |
6075 | __supported_pte_mask &= ~_PAGE_NX; | |
6076 | } | |
6077 | return 0; | |
6078 | } | |
6079 | early_param("noexec", nonx_setup); | |
8a4b4a5e | 6080 | |
da5b3fc8 | 6081 | -int force_personality32 = 0; |
6082 | +int force_personality32; | |
8a4b4a5e | 6083 | |
da5b3fc8 | 6084 | /* noexec32=on|off |
6085 | Control non executable heap for 32bit processes. | |
4dee9bd5 | 6086 | @@ -226,7 +222,7 @@ void __cpuinit check_efer(void) |
da5b3fc8 | 6087 | unsigned long efer; |
8a4b4a5e | 6088 | |
da5b3fc8 | 6089 | rdmsrl(MSR_EFER, efer); |
6090 | - if (!(efer & EFER_NX) || do_not_nx) { | |
6091 | + if (!(efer & EFER_NX)) { | |
6092 | __supported_pte_mask &= ~_PAGE_NX; | |
6093 | } | |
6094 | } | |
4dee9bd5 | 6095 | @@ -249,12 +245,13 @@ DEFINE_PER_CPU(struct orig_ist, orig_ist |
da5b3fc8 | 6096 | void __cpuinit cpu_init (void) |
6097 | { | |
6098 | int cpu = stack_smp_processor_id(); | |
6099 | - struct tss_struct *t = &per_cpu(init_tss, cpu); | |
6100 | + struct tss_struct *t = init_tss + cpu; | |
6101 | struct orig_ist *orig_ist = &per_cpu(orig_ist, cpu); | |
6102 | unsigned long v; | |
6103 | char *estacks = NULL; | |
6104 | struct task_struct *me; | |
6105 | int i; | |
6106 | + struct desc_ptr cpu_gdt_descr = { .size = GDT_SIZE - 1, .address = (unsigned long)cpu_gdt_table[cpu]}; | |
8a4b4a5e | 6107 | |
da5b3fc8 | 6108 | /* CPU 0 is initialised in head64.c */ |
6109 | if (cpu != 0) { | |
4dee9bd5 | 6110 | @@ -272,14 +269,12 @@ void __cpuinit cpu_init (void) |
da5b3fc8 | 6111 | clear_in_cr4(X86_CR4_VME|X86_CR4_PVI|X86_CR4_TSD|X86_CR4_DE); |
8a4b4a5e | 6112 | |
da5b3fc8 | 6113 | /* |
6114 | - * Initialize the per-CPU GDT with the boot GDT, | |
6115 | - * and set up the GDT descriptor: | |
6116 | + * Initialize the per-CPU GDT with the boot GDT: | |
6117 | */ | |
6118 | if (cpu) | |
4dee9bd5 | 6119 | memcpy(get_cpu_gdt_table(cpu), cpu_gdt_table, GDT_SIZE); |
da5b3fc8 | 6120 | |
6121 | - cpu_gdt_descr[cpu].size = GDT_SIZE; | |
6122 | - load_gdt((const struct desc_ptr *)&cpu_gdt_descr[cpu]); | |
6123 | + load_gdt(&cpu_gdt_descr); | |
6124 | load_idt((const struct desc_ptr *)&idt_descr); | |
6125 | ||
6126 | memset(me->thread.tls_array, 0, GDT_ENTRY_TLS_ENTRIES * 8); | |
4dee9bd5 | 6127 | diff -urNp linux-2.6.25.4/arch/x86/kernel/signal_32.c linux-2.6.25.4/arch/x86/kernel/signal_32.c |
6128 | --- linux-2.6.25.4/arch/x86/kernel/signal_32.c 2008-05-15 11:00:12.000000000 -0400 | |
6129 | +++ linux-2.6.25.4/arch/x86/kernel/signal_32.c 2008-05-18 13:33:14.000000000 -0400 | |
6130 | @@ -366,9 +366,9 @@ static int setup_frame(int sig, struct k | |
8a4b4a5e | 6131 | } |
6132 | ||
da5b3fc8 | 6133 | if (current->binfmt->hasvdso) |
4dee9bd5 | 6134 | - restorer = VDSO32_SYMBOL(current->mm->context.vdso, sigreturn); |
6135 | + restorer = (void __user *)VDSO32_SYMBOL(current->mm->context.vdso, sigreturn); | |
da5b3fc8 | 6136 | else |
4dee9bd5 | 6137 | - restorer = &frame->retcode; |
da5b3fc8 | 6138 | + restorer = (void __user *)&frame->retcode; |
6139 | if (ka->sa.sa_flags & SA_RESTORER) | |
6140 | restorer = ka->sa.sa_restorer; | |
8a4b4a5e | 6141 | |
4dee9bd5 | 6142 | @@ -463,7 +463,7 @@ static int setup_rt_frame(int sig, struc |
da5b3fc8 | 6143 | goto give_sigsegv; |
8a4b4a5e | 6144 | |
da5b3fc8 | 6145 | /* Set up to return from userspace. */ |
4dee9bd5 | 6146 | - restorer = VDSO32_SYMBOL(current->mm->context.vdso, rt_sigreturn); |
6147 | + restorer = (void __user *)VDSO32_SYMBOL(current->mm->context.vdso, rt_sigreturn); | |
da5b3fc8 | 6148 | if (ka->sa.sa_flags & SA_RESTORER) |
6149 | restorer = ka->sa.sa_restorer; | |
6150 | err |= __put_user(restorer, &frame->pretcode); | |
4dee9bd5 | 6151 | @@ -593,7 +593,7 @@ static void do_signal(struct pt_regs *re |
da5b3fc8 | 6152 | * before reaching here, so testing against kernel |
6153 | * CS suffices. | |
6154 | */ | |
6155 | - if (!user_mode(regs)) | |
6156 | + if (!user_mode_novm(regs)) | |
6157 | return; | |
8a4b4a5e | 6158 | |
da5b3fc8 | 6159 | if (test_thread_flag(TIF_RESTORE_SIGMASK)) |
4dee9bd5 | 6160 | diff -urNp linux-2.6.25.4/arch/x86/kernel/signal_64.c linux-2.6.25.4/arch/x86/kernel/signal_64.c |
6161 | --- linux-2.6.25.4/arch/x86/kernel/signal_64.c 2008-05-15 11:00:12.000000000 -0400 | |
6162 | +++ linux-2.6.25.4/arch/x86/kernel/signal_64.c 2008-05-18 13:33:14.000000000 -0400 | |
da5b3fc8 | 6163 | @@ -252,8 +252,8 @@ static int setup_rt_frame(int sig, struc |
6164 | err |= setup_sigcontext(&frame->uc.uc_mcontext, regs, set->sig[0], me); | |
6165 | err |= __put_user(fp, &frame->uc.uc_mcontext.fpstate); | |
6166 | if (sizeof(*set) == 16) { | |
6167 | - __put_user(set->sig[0], &frame->uc.uc_sigmask.sig[0]); | |
6168 | - __put_user(set->sig[1], &frame->uc.uc_sigmask.sig[1]); | |
6169 | + err |= __put_user(set->sig[0], &frame->uc.uc_sigmask.sig[0]); | |
6170 | + err |= __put_user(set->sig[1], &frame->uc.uc_sigmask.sig[1]); | |
6171 | } else | |
6172 | err |= __copy_to_user(&frame->uc.uc_sigmask, set, sizeof(*set)); | |
8a4b4a5e | 6173 | |
4dee9bd5 | 6174 | diff -urNp linux-2.6.25.4/arch/x86/kernel/smp_32.c linux-2.6.25.4/arch/x86/kernel/smp_32.c |
6175 | --- linux-2.6.25.4/arch/x86/kernel/smp_32.c 2008-05-15 11:00:12.000000000 -0400 | |
6176 | +++ linux-2.6.25.4/arch/x86/kernel/smp_32.c 2008-05-18 13:33:14.000000000 -0400 | |
da5b3fc8 | 6177 | @@ -104,7 +104,7 @@ |
6178 | * about nothing of note with C stepping upwards. | |
6179 | */ | |
8a4b4a5e | 6180 | |
da5b3fc8 | 6181 | -DEFINE_PER_CPU(struct tlb_state, cpu_tlbstate) ____cacheline_aligned = { &init_mm, 0, }; |
6182 | +DEFINE_PER_CPU(struct tlb_state, cpu_tlbstate) ____cacheline_aligned = { &init_mm, 0, {0} }; | |
8a4b4a5e | 6183 | |
da5b3fc8 | 6184 | /* |
6185 | * the following functions deal with sending IPIs between CPUs. | |
4dee9bd5 | 6186 | diff -urNp linux-2.6.25.4/arch/x86/kernel/smpboot_32.c linux-2.6.25.4/arch/x86/kernel/smpboot_32.c |
6187 | --- linux-2.6.25.4/arch/x86/kernel/smpboot_32.c 2008-05-15 11:00:12.000000000 -0400 | |
6188 | +++ linux-2.6.25.4/arch/x86/kernel/smpboot_32.c 2008-05-18 13:33:14.000000000 -0400 | |
6189 | @@ -768,6 +768,10 @@ static int __cpuinit do_boot_cpu(int api | |
da5b3fc8 | 6190 | unsigned long start_eip; |
6191 | unsigned short nmi_high = 0, nmi_low = 0; | |
6192 | ||
6193 | +#ifdef CONFIG_PAX_KERNEXEC | |
6194 | + unsigned long cr0; | |
8a4b4a5e | 6195 | +#endif |
6196 | + | |
da5b3fc8 | 6197 | /* |
6198 | * Save current MTRR state in case it was changed since early boot | |
6199 | * (e.g. by the ACPI SMI) to initialize new CPUs with MTRRs in sync: | |
4dee9bd5 | 6200 | @@ -784,8 +788,17 @@ static int __cpuinit do_boot_cpu(int api |
8a4b4a5e | 6201 | |
da5b3fc8 | 6202 | init_gdt(cpu); |
6203 | per_cpu(current_task, cpu) = idle; | |
83a957c9 | 6204 | + |
da5b3fc8 | 6205 | +#ifdef CONFIG_PAX_KERNEXEC |
6206 | + pax_open_kernel(cr0); | |
83a957c9 | 6207 | +#endif |
6208 | + | |
4dee9bd5 | 6209 | early_gdt_descr.address = (unsigned long)get_cpu_gdt_table(cpu); |
6210 | ||
da5b3fc8 | 6211 | +#ifdef CONFIG_PAX_KERNEXEC |
6212 | + pax_close_kernel(cr0); | |
8a4b4a5e | 6213 | +#endif |
4dee9bd5 | 6214 | + |
6215 | idle->thread.ip = (unsigned long) start_secondary; | |
da5b3fc8 | 6216 | /* start_eip had better be page-aligned! */ |
4dee9bd5 | 6217 | start_eip = setup_trampoline(); |
6218 | diff -urNp linux-2.6.25.4/arch/x86/kernel/smpboot_64.c linux-2.6.25.4/arch/x86/kernel/smpboot_64.c | |
6219 | --- linux-2.6.25.4/arch/x86/kernel/smpboot_64.c 2008-05-15 11:00:12.000000000 -0400 | |
6220 | +++ linux-2.6.25.4/arch/x86/kernel/smpboot_64.c 2008-05-18 13:33:14.000000000 -0400 | |
6221 | @@ -559,13 +559,6 @@ static int __cpuinit do_boot_cpu(int cpu | |
da5b3fc8 | 6222 | }; |
4dee9bd5 | 6223 | INIT_WORK(&c_idle.work, do_fork_idle); |
50425a20 | 6224 | |
da5b3fc8 | 6225 | - /* allocate memory for gdts of secondary cpus. Hotplug is considered */ |
6226 | - if (!cpu_gdt_descr[cpu].address && | |
6227 | - !(cpu_gdt_descr[cpu].address = get_zeroed_page(GFP_KERNEL))) { | |
6228 | - printk(KERN_ERR "Failed to allocate GDT for CPU %d\n", cpu); | |
6229 | - return -1; | |
6230 | - } | |
6231 | - | |
6232 | /* Allocate node local memory for AP pdas */ | |
6233 | if (cpu_pda(cpu) == &boot_cpu_pda[cpu]) { | |
6234 | struct x8664_pda *newpda, *pda; | |
4dee9bd5 | 6235 | @@ -624,7 +617,7 @@ do_rest: |
da5b3fc8 | 6236 | start_rip = setup_trampoline(); |
6237 | ||
4dee9bd5 | 6238 | init_rsp = c_idle.idle->thread.sp; |
6239 | - load_sp0(&per_cpu(init_tss, cpu), &c_idle.idle->thread); | |
6240 | + load_sp0(init_tss + cpu, &c_idle.idle->thread); | |
da5b3fc8 | 6241 | initial_code = start_secondary; |
6242 | clear_tsk_thread_flag(c_idle.idle, TIF_FORK); | |
6243 | ||
4dee9bd5 | 6244 | diff -urNp linux-2.6.25.4/arch/x86/kernel/smpcommon_32.c linux-2.6.25.4/arch/x86/kernel/smpcommon_32.c |
6245 | --- linux-2.6.25.4/arch/x86/kernel/smpcommon_32.c 2008-05-15 11:00:12.000000000 -0400 | |
6246 | +++ linux-2.6.25.4/arch/x86/kernel/smpcommon_32.c 2008-05-18 13:33:14.000000000 -0400 | |
84cd3cb1 | 6247 | @@ -3,8 +3,9 @@ |
da5b3fc8 | 6248 | */ |
6249 | #include <linux/module.h> | |
6250 | #include <asm/smp.h> | |
6251 | +#include <asm/sections.h> | |
6252 | ||
84cd3cb1 | 6253 | -DEFINE_PER_CPU(unsigned long, this_cpu_off); |
6254 | +DEFINE_PER_CPU(unsigned long, this_cpu_off) = (unsigned long)__per_cpu_start; | |
da5b3fc8 | 6255 | EXPORT_PER_CPU_SYMBOL(this_cpu_off); |
84cd3cb1 | 6256 | |
6257 | /* Initialize the CPU's GDT. This is either the boot CPU doing itself | |
6258 | @@ -12,15 +13,22 @@ EXPORT_PER_CPU_SYMBOL(this_cpu_off); | |
4dee9bd5 | 6259 | secondary which will soon come up. */ |
6260 | __cpuinit void init_gdt(int cpu) | |
da5b3fc8 | 6261 | { |
4dee9bd5 | 6262 | - struct desc_struct *gdt = get_cpu_gdt_table(cpu); |
6263 | + struct desc_struct d, *gdt = get_cpu_gdt_table(cpu); | |
6264 | + unsigned long base, limit; | |
da5b3fc8 | 6265 | |
4dee9bd5 | 6266 | - pack_descriptor(&gdt[GDT_ENTRY_PERCPU], |
da5b3fc8 | 6267 | - __per_cpu_offset[cpu], 0xFFFFF, |
4dee9bd5 | 6268 | - 0x2 | DESCTYPE_S, 0x8); |
da5b3fc8 | 6269 | + if (cpu) |
6270 | + memcpy(gdt, cpu_gdt_table, GDT_SIZE); | |
4dee9bd5 | 6271 | |
6272 | - gdt[GDT_ENTRY_PERCPU].s = 1; | |
6273 | + base = __per_cpu_offset[cpu] + (unsigned long)__per_cpu_start; | |
6274 | + limit = PERCPU_ENOUGH_ROOM - 1; | |
6275 | + if (limit < 64*1024) | |
6276 | + pack_descriptor(&d, base, limit, 0x80 | DESCTYPE_S | 0x3, 0x4); | |
da5b3fc8 | 6277 | + else |
4dee9bd5 | 6278 | + pack_descriptor(&d, base, limit >> PAGE_SHIFT, 0x80 | DESCTYPE_S | 0x3, 0xC); |
50425a20 | 6279 | |
84cd3cb1 | 6280 | - per_cpu(this_cpu_off, cpu) = __per_cpu_offset[cpu]; |
6281 | + write_gdt_entry(gdt, GDT_ENTRY_PERCPU, &d, DESCTYPE_S); | |
6282 | + | |
6283 | + per_cpu(this_cpu_off, cpu) = base; | |
da5b3fc8 | 6284 | per_cpu(cpu_number, cpu) = cpu; |
84cd3cb1 | 6285 | } |
6286 | ||
4dee9bd5 | 6287 | diff -urNp linux-2.6.25.4/arch/x86/kernel/step.c linux-2.6.25.4/arch/x86/kernel/step.c |
6288 | --- linux-2.6.25.4/arch/x86/kernel/step.c 2008-05-15 11:00:12.000000000 -0400 | |
6289 | +++ linux-2.6.25.4/arch/x86/kernel/step.c 2008-05-18 13:33:14.000000000 -0400 | |
6290 | @@ -23,22 +23,20 @@ unsigned long convert_ip_to_linear(struc | |
6291 | * and APM bios ones we just ignore here. | |
6292 | */ | |
6293 | if ((seg & SEGMENT_TI_MASK) == SEGMENT_LDT) { | |
6294 | - u32 *desc; | |
6295 | + struct desc_struct *desc; | |
6296 | unsigned long base; | |
50425a20 | 6297 | |
4dee9bd5 | 6298 | - seg &= ~7UL; |
6299 | + seg >>= 3; | |
6300 | ||
6301 | mutex_lock(&child->mm->context.lock); | |
6302 | - if (unlikely((seg >> 3) >= child->mm->context.size)) | |
6303 | - addr = -1L; /* bogus selector, access would fault */ | |
6304 | + if (unlikely(seg >= child->mm->context.size)) | |
6305 | + addr = -EINVAL; | |
6306 | else { | |
6307 | - desc = child->mm->context.ldt + seg; | |
6308 | - base = ((desc[0] >> 16) | | |
6309 | - ((desc[1] & 0xff) << 16) | | |
6310 | - (desc[1] & 0xff000000)); | |
6311 | + desc = &child->mm->context.ldt[seg]; | |
6312 | + base = (desc->a >> 16) | ((desc->b & 0xff) << 16) | (desc->b & 0xff000000); | |
50425a20 | 6313 | |
4dee9bd5 | 6314 | /* 16-bit code segment? */ |
6315 | - if (!((desc[1] >> 22) & 1)) | |
6316 | + if (!((desc->b >> 22) & 1)) | |
6317 | addr &= 0xffff; | |
6318 | addr += base; | |
6319 | } | |
6320 | @@ -54,6 +52,9 @@ static int is_setting_trap_flag(struct t | |
6321 | unsigned char opcode[15]; | |
6322 | unsigned long addr = convert_ip_to_linear(child, regs); | |
50425a20 | 6323 | |
4dee9bd5 | 6324 | + if (addr == -EINVAL) |
6325 | + return 0; | |
da5b3fc8 | 6326 | + |
4dee9bd5 | 6327 | copied = access_process_vm(child, addr, opcode, sizeof(opcode), 0); |
6328 | for (i = 0; i < copied; i++) { | |
6329 | switch (opcode[i]) { | |
6330 | diff -urNp linux-2.6.25.4/arch/x86/kernel/syscall_table_32.S linux-2.6.25.4/arch/x86/kernel/syscall_table_32.S | |
6331 | --- linux-2.6.25.4/arch/x86/kernel/syscall_table_32.S 2008-05-15 11:00:12.000000000 -0400 | |
6332 | +++ linux-2.6.25.4/arch/x86/kernel/syscall_table_32.S 2008-05-18 13:33:14.000000000 -0400 | |
da5b3fc8 | 6333 | @@ -1,3 +1,4 @@ |
6334 | +.section .rodata,"a",@progbits | |
6335 | ENTRY(sys_call_table) | |
6336 | .long sys_restart_syscall /* 0 - old "setup()" system call, used for restarting */ | |
6337 | .long sys_exit | |
4dee9bd5 | 6338 | diff -urNp linux-2.6.25.4/arch/x86/kernel/sys_i386_32.c linux-2.6.25.4/arch/x86/kernel/sys_i386_32.c |
6339 | --- linux-2.6.25.4/arch/x86/kernel/sys_i386_32.c 2008-05-15 11:00:12.000000000 -0400 | |
6340 | +++ linux-2.6.25.4/arch/x86/kernel/sys_i386_32.c 2008-05-18 13:33:14.000000000 -0400 | |
da5b3fc8 | 6341 | @@ -39,6 +39,21 @@ asmlinkage int sys_pipe(unsigned long __ |
6342 | return error; | |
50425a20 | 6343 | } |
6344 | ||
da5b3fc8 | 6345 | +int i386_mmap_check(unsigned long addr, unsigned long len, unsigned long flags) |
50425a20 | 6346 | +{ |
b7f09679 | 6347 | + unsigned long pax_task_size = TASK_SIZE; |
50425a20 | 6348 | + |
da5b3fc8 | 6349 | +#ifdef CONFIG_PAX_SEGMEXEC |
6350 | + if (current->mm->pax_flags & MF_PAX_SEGMEXEC) | |
b7f09679 | 6351 | + pax_task_size = SEGMEXEC_TASK_SIZE; |
50425a20 | 6352 | +#endif |
6353 | + | |
b7f09679 | 6354 | + if (len > pax_task_size || addr > pax_task_size - len) |
da5b3fc8 | 6355 | + return -EINVAL; |
6356 | + | |
6357 | + return 0; | |
6358 | +} | |
6359 | + | |
6360 | asmlinkage long sys_mmap2(unsigned long addr, unsigned long len, | |
6361 | unsigned long prot, unsigned long flags, | |
6362 | unsigned long fd, unsigned long pgoff) | |
6363 | @@ -98,6 +113,205 @@ out: | |
6364 | return err; | |
6365 | } | |
50425a20 | 6366 | |
da5b3fc8 | 6367 | +unsigned long |
6368 | +arch_get_unmapped_area(struct file *filp, unsigned long addr, | |
6369 | + unsigned long len, unsigned long pgoff, unsigned long flags) | |
6370 | +{ | |
6371 | + struct mm_struct *mm = current->mm; | |
6372 | + struct vm_area_struct *vma; | |
b7f09679 | 6373 | + unsigned long start_addr, pax_task_size = TASK_SIZE; |
50425a20 | 6374 | + |
da5b3fc8 | 6375 | +#ifdef CONFIG_PAX_SEGMEXEC |
6376 | + if (mm->pax_flags & MF_PAX_SEGMEXEC) | |
b7f09679 | 6377 | + pax_task_size = SEGMEXEC_TASK_SIZE; |
da5b3fc8 | 6378 | +#endif |
50425a20 | 6379 | + |
b7f09679 | 6380 | + if (len > pax_task_size) |
da5b3fc8 | 6381 | + return -ENOMEM; |
6382 | + | |
6383 | + if (flags & MAP_FIXED) | |
6384 | + return addr; | |
6385 | + | |
6386 | +#ifdef CONFIG_PAX_RANDMMAP | |
6387 | + if (!(mm->pax_flags & MF_PAX_RANDMMAP) || !filp) | |
50425a20 | 6388 | +#endif |
6389 | + | |
da5b3fc8 | 6390 | + if (addr) { |
6391 | + addr = PAGE_ALIGN(addr); | |
6392 | + vma = find_vma(mm, addr); | |
b7f09679 | 6393 | + if (pax_task_size - len >= addr && |
da5b3fc8 | 6394 | + (!vma || addr + len <= vma->vm_start)) |
6395 | + return addr; | |
6396 | + } | |
6397 | + if (len > mm->cached_hole_size) { | |
6398 | + start_addr = addr = mm->free_area_cache; | |
6399 | + } else { | |
6400 | + start_addr = addr = mm->mmap_base; | |
6401 | + mm->cached_hole_size = 0; | |
50425a20 | 6402 | + } |
6403 | + | |
da5b3fc8 | 6404 | +#ifdef CONFIG_PAX_PAGEEXEC |
6405 | + if (!nx_enabled && (mm->pax_flags & MF_PAX_PAGEEXEC) && (flags & MAP_EXECUTABLE) && start_addr >= mm->mmap_base) { | |
6406 | + start_addr = 0x00110000UL; | |
83a957c9 | 6407 | + |
da5b3fc8 | 6408 | +#ifdef CONFIG_PAX_RANDMMAP |
6409 | + if (mm->pax_flags & MF_PAX_RANDMMAP) | |
6410 | + start_addr += mm->delta_mmap & 0x03FFF000UL; | |
6411 | +#endif | |
83a957c9 | 6412 | + |
da5b3fc8 | 6413 | + if (mm->start_brk <= start_addr && start_addr < mm->mmap_base) |
6414 | + start_addr = addr = mm->mmap_base; | |
6415 | + else | |
6416 | + addr = start_addr; | |
6417 | + } | |
83a957c9 | 6418 | +#endif |
6419 | + | |
da5b3fc8 | 6420 | +full_search: |
6421 | + for (vma = find_vma(mm, addr); ; vma = vma->vm_next) { | |
6422 | + /* At this point: (!vma || addr < vma->vm_end). */ | |
b7f09679 | 6423 | + if (pax_task_size - len < addr) { |
da5b3fc8 | 6424 | + /* |
6425 | + * Start a new search - just in case we missed | |
6426 | + * some holes. | |
6427 | + */ | |
6428 | + if (start_addr != mm->mmap_base) { | |
6429 | + start_addr = addr = mm->mmap_base; | |
6430 | + mm->cached_hole_size = 0; | |
6431 | + goto full_search; | |
6432 | + } | |
6433 | + return -ENOMEM; | |
6434 | + } | |
6435 | + if (!vma || addr + len <= vma->vm_start) { | |
6436 | + /* | |
6437 | + * Remember the place where we stopped the search: | |
6438 | + */ | |
6439 | + mm->free_area_cache = addr + len; | |
6440 | + return addr; | |
6441 | + } | |
6442 | + if (addr + mm->cached_hole_size < vma->vm_start) | |
6443 | + mm->cached_hole_size = vma->vm_start - addr; | |
6444 | + addr = vma->vm_end; | |
6445 | + if (mm->start_brk <= addr && addr < mm->mmap_base) { | |
6446 | + start_addr = addr = mm->mmap_base; | |
6447 | + mm->cached_hole_size = 0; | |
6448 | + goto full_search; | |
6449 | + } | |
83a957c9 | 6450 | + } |
da5b3fc8 | 6451 | +} |
6452 | + | |
6453 | +unsigned long | |
6454 | +arch_get_unmapped_area_topdown(struct file *filp, const unsigned long addr0, | |
6455 | + const unsigned long len, const unsigned long pgoff, | |
6456 | + const unsigned long flags) | |
6457 | +{ | |
6458 | + struct vm_area_struct *vma; | |
6459 | + struct mm_struct *mm = current->mm; | |
b7f09679 | 6460 | + unsigned long base = mm->mmap_base, addr = addr0, pax_task_size = TASK_SIZE; |
da5b3fc8 | 6461 | + |
6462 | +#ifdef CONFIG_PAX_SEGMEXEC | |
6463 | + if (mm->pax_flags & MF_PAX_SEGMEXEC) | |
b7f09679 | 6464 | + pax_task_size = SEGMEXEC_TASK_SIZE; |
83a957c9 | 6465 | +#endif |
6466 | + | |
da5b3fc8 | 6467 | + /* requested length too big for entire address space */ |
b7f09679 | 6468 | + if (len > pax_task_size) |
da5b3fc8 | 6469 | + return -ENOMEM; |
6470 | + | |
6471 | + if (flags & MAP_FIXED) | |
6472 | + return addr; | |
6473 | + | |
6474 | +#ifdef CONFIG_PAX_PAGEEXEC | |
6475 | + if (!nx_enabled && (mm->pax_flags & MF_PAX_PAGEEXEC) && (flags & MAP_EXECUTABLE)) | |
6476 | + goto bottomup; | |
6477 | +#endif | |
6478 | + | |
6479 | +#ifdef CONFIG_PAX_RANDMMAP | |
6480 | + if (!(mm->pax_flags & MF_PAX_RANDMMAP) || !filp) | |
6481 | +#endif | |
6482 | + | |
6483 | + /* requesting a specific address */ | |
6484 | + if (addr) { | |
6485 | + addr = PAGE_ALIGN(addr); | |
6486 | + vma = find_vma(mm, addr); | |
b7f09679 | 6487 | + if (pax_task_size - len >= addr && |
da5b3fc8 | 6488 | + (!vma || addr + len <= vma->vm_start)) |
6489 | + return addr; | |
6490 | + } | |
6491 | + | |
6492 | + /* check if free_area_cache is useful for us */ | |
6493 | + if (len <= mm->cached_hole_size) { | |
6494 | + mm->cached_hole_size = 0; | |
6495 | + mm->free_area_cache = mm->mmap_base; | |
6496 | + } | |
6497 | + | |
6498 | + /* either no address requested or can't fit in requested address hole */ | |
6499 | + addr = mm->free_area_cache; | |
6500 | + | |
6501 | + /* make sure it can fit in the remaining address space */ | |
6502 | + if (addr > len) { | |
6503 | + vma = find_vma(mm, addr-len); | |
6504 | + if (!vma || addr <= vma->vm_start) | |
6505 | + /* remember the address as a hint for next time */ | |
6506 | + return (mm->free_area_cache = addr-len); | |
6507 | + } | |
6508 | + | |
6509 | + if (mm->mmap_base < len) | |
6510 | + goto bottomup; | |
6511 | + | |
6512 | + addr = mm->mmap_base-len; | |
6513 | + | |
6514 | + do { | |
6515 | + /* | |
6516 | + * Lookup failure means no vma is above this address, | |
6517 | + * else if new region fits below vma->vm_start, | |
6518 | + * return with success: | |
6519 | + */ | |
6520 | + vma = find_vma(mm, addr); | |
6521 | + if (!vma || addr+len <= vma->vm_start) | |
6522 | + /* remember the address as a hint for next time */ | |
6523 | + return (mm->free_area_cache = addr); | |
50425a20 | 6524 | + |
da5b3fc8 | 6525 | + /* remember the largest hole we saw so far */ |
6526 | + if (addr + mm->cached_hole_size < vma->vm_start) | |
6527 | + mm->cached_hole_size = vma->vm_start - addr; | |
50425a20 | 6528 | + |
da5b3fc8 | 6529 | + /* try just below the current vma->vm_start */ |
6530 | + addr = vma->vm_start-len; | |
6531 | + } while (len < vma->vm_start); | |
50425a20 | 6532 | + |
da5b3fc8 | 6533 | +bottomup: |
6534 | + /* | |
6535 | + * A failed mmap() very likely causes application failure, | |
6536 | + * so fall back to the bottom-up function here. This scenario | |
6537 | + * can happen with large stack limits and large mmap() | |
6538 | + * allocations. | |
6539 | + */ | |
6540 | + | |
6541 | +#ifdef CONFIG_PAX_SEGMEXEC | |
6542 | + if (mm->pax_flags & MF_PAX_SEGMEXEC) | |
6543 | + mm->mmap_base = SEGMEXEC_TASK_UNMAPPED_BASE; | |
6544 | + else | |
50425a20 | 6545 | +#endif |
6546 | + | |
da5b3fc8 | 6547 | + mm->mmap_base = TASK_UNMAPPED_BASE; |
50425a20 | 6548 | + |
6549 | +#ifdef CONFIG_PAX_RANDMMAP | |
da5b3fc8 | 6550 | + if (mm->pax_flags & MF_PAX_RANDMMAP) |
6551 | + mm->mmap_base += mm->delta_mmap; | |
50425a20 | 6552 | +#endif |
6553 | + | |
da5b3fc8 | 6554 | + mm->free_area_cache = mm->mmap_base; |
6555 | + mm->cached_hole_size = ~0UL; | |
6556 | + addr = arch_get_unmapped_area(filp, addr0, len, pgoff, flags); | |
6557 | + /* | |
6558 | + * Restore the topdown base: | |
6559 | + */ | |
6560 | + mm->mmap_base = base; | |
6561 | + mm->free_area_cache = base; | |
6562 | + mm->cached_hole_size = ~0UL; | |
50425a20 | 6563 | + |
da5b3fc8 | 6564 | + return addr; |
50425a20 | 6565 | +} |
50425a20 | 6566 | |
da5b3fc8 | 6567 | struct sel_arg_struct { |
6568 | unsigned long n; | |
4dee9bd5 | 6569 | diff -urNp linux-2.6.25.4/arch/x86/kernel/sys_x86_64.c linux-2.6.25.4/arch/x86/kernel/sys_x86_64.c |
6570 | --- linux-2.6.25.4/arch/x86/kernel/sys_x86_64.c 2008-05-15 11:00:12.000000000 -0400 | |
6571 | +++ linux-2.6.25.4/arch/x86/kernel/sys_x86_64.c 2008-05-18 13:33:14.000000000 -0400 | |
6572 | @@ -62,8 +62,8 @@ out: | |
da5b3fc8 | 6573 | return error; |
50425a20 | 6574 | } |
6575 | ||
da5b3fc8 | 6576 | -static void find_start_end(unsigned long flags, unsigned long *begin, |
6577 | - unsigned long *end) | |
6578 | +static void find_start_end(struct mm_struct *mm, unsigned long flags, | |
6579 | + unsigned long *begin, unsigned long *end) | |
50425a20 | 6580 | { |
da5b3fc8 | 6581 | if (!test_thread_flag(TIF_IA32) && (flags & MAP_32BIT)) { |
4dee9bd5 | 6582 | unsigned long new_begin; |
6583 | @@ -82,7 +82,7 @@ static void find_start_end(unsigned long | |
6584 | *begin = new_begin; | |
6585 | } | |
da5b3fc8 | 6586 | } else { |
6587 | - *begin = TASK_UNMAPPED_BASE; | |
6588 | + *begin = mm->mmap_base; | |
6589 | *end = TASK_SIZE; | |
50425a20 | 6590 | } |
da5b3fc8 | 6591 | } |
4dee9bd5 | 6592 | @@ -99,11 +99,15 @@ arch_get_unmapped_area(struct file *filp |
da5b3fc8 | 6593 | if (flags & MAP_FIXED) |
6594 | return addr; | |
50425a20 | 6595 | |
da5b3fc8 | 6596 | - find_start_end(flags, &begin, &end); |
6597 | + find_start_end(mm, flags, &begin, &end); | |
50425a20 | 6598 | |
da5b3fc8 | 6599 | if (len > end) |
6600 | return -ENOMEM; | |
50425a20 | 6601 | |
da5b3fc8 | 6602 | +#ifdef CONFIG_PAX_RANDMMAP |
6603 | + if (!(mm->pax_flags & MF_PAX_RANDMMAP) || !filp) | |
6604 | +#endif | |
6605 | + | |
6606 | if (addr) { | |
6607 | addr = PAGE_ALIGN(addr); | |
6608 | vma = find_vma(mm, addr); | |
4dee9bd5 | 6609 | @@ -158,7 +162,7 @@ arch_get_unmapped_area_topdown(struct fi |
6610 | { | |
6611 | struct vm_area_struct *vma; | |
6612 | struct mm_struct *mm = current->mm; | |
6613 | - unsigned long addr = addr0; | |
6614 | + unsigned long base = mm->mmap_base, addr = addr0; | |
6615 | ||
6616 | /* requested length too big for entire address space */ | |
6617 | if (len > TASK_SIZE) | |
6618 | @@ -171,6 +175,10 @@ arch_get_unmapped_area_topdown(struct fi | |
6619 | if (!test_thread_flag(TIF_IA32) && (flags & MAP_32BIT)) | |
6620 | goto bottomup; | |
6621 | ||
6622 | +#ifdef CONFIG_PAX_RANDMMAP | |
6623 | + if (!(mm->pax_flags & MF_PAX_RANDMMAP)) | |
6624 | +#endif | |
6625 | + | |
6626 | /* requesting a specific address */ | |
6627 | if (addr) { | |
6628 | addr = PAGE_ALIGN(addr); | |
6629 | @@ -228,13 +236,21 @@ bottomup: | |
6630 | * can happen with large stack limits and large mmap() | |
6631 | * allocations. | |
6632 | */ | |
6633 | + mm->mmap_base = TASK_UNMAPPED_BASE; | |
6634 | + | |
6635 | +#ifdef CONFIG_PAX_RANDMMAP | |
6636 | + if (mm->pax_flags & MF_PAX_RANDMMAP) | |
6637 | + mm->mmap_base += mm->delta_mmap; | |
6638 | +#endif | |
6639 | + | |
6640 | + mm->free_area_cache = mm->mmap_base; | |
6641 | mm->cached_hole_size = ~0UL; | |
6642 | - mm->free_area_cache = TASK_UNMAPPED_BASE; | |
6643 | addr = arch_get_unmapped_area(filp, addr0, len, pgoff, flags); | |
6644 | /* | |
6645 | * Restore the topdown base: | |
6646 | */ | |
6647 | - mm->free_area_cache = mm->mmap_base; | |
6648 | + mm->mmap_base = base; | |
6649 | + mm->free_area_cache = base; | |
6650 | mm->cached_hole_size = ~0UL; | |
6651 | ||
6652 | return addr; | |
6653 | diff -urNp linux-2.6.25.4/arch/x86/kernel/time_32.c linux-2.6.25.4/arch/x86/kernel/time_32.c | |
6654 | --- linux-2.6.25.4/arch/x86/kernel/time_32.c 2008-05-15 11:00:12.000000000 -0400 | |
6655 | +++ linux-2.6.25.4/arch/x86/kernel/time_32.c 2008-05-18 13:33:14.000000000 -0400 | |
6656 | @@ -52,20 +52,30 @@ unsigned long profile_pc(struct pt_regs | |
6657 | if (!v8086_mode(regs) && SEGMENT_IS_KERNEL_CODE(regs->cs) && | |
da5b3fc8 | 6658 | in_lock_functions(pc)) { |
6659 | #ifdef CONFIG_FRAME_POINTER | |
4dee9bd5 | 6660 | - return *(unsigned long *)(regs->bp + 4); |
6661 | + return ktla_ktva(*(unsigned long *)(regs->bp + 4)); | |
da5b3fc8 | 6662 | #else |
4dee9bd5 | 6663 | unsigned long *sp = (unsigned long *)®s->sp; |
50425a20 | 6664 | |
da5b3fc8 | 6665 | /* Return address is either directly at stack pointer |
4dee9bd5 | 6666 | or above a saved flags. Eflags has bits 22-31 zero, |
da5b3fc8 | 6667 | kernel addresses don't. */ |
6668 | + | |
6669 | +#ifdef CONFIG_PAX_KERNEXEC | |
6670 | + return ktla_ktva(sp[0]); | |
6671 | +#else | |
4dee9bd5 | 6672 | if (sp[0] >> 22) |
da5b3fc8 | 6673 | return sp[0]; |
6674 | if (sp[1] >> 22) | |
6675 | return sp[1]; | |
6676 | #endif | |
6677 | + | |
6678 | +#endif | |
50425a20 | 6679 | } |
da5b3fc8 | 6680 | #endif |
6681 | + | |
4dee9bd5 | 6682 | + if (!v8086_mode(regs) && SEGMENT_IS_KERNEL_CODE(regs->cs)) |
da5b3fc8 | 6683 | + pc = ktla_ktva(pc); |
6684 | + | |
6685 | return pc; | |
6686 | } | |
6687 | EXPORT_SYMBOL(profile_pc); | |
4dee9bd5 | 6688 | diff -urNp linux-2.6.25.4/arch/x86/kernel/tls.c linux-2.6.25.4/arch/x86/kernel/tls.c |
6689 | --- linux-2.6.25.4/arch/x86/kernel/tls.c 2008-05-15 11:00:12.000000000 -0400 | |
6690 | +++ linux-2.6.25.4/arch/x86/kernel/tls.c 2008-05-18 13:33:14.000000000 -0400 | |
6691 | @@ -84,6 +84,11 @@ int do_set_thread_area(struct task_struc | |
6692 | if (idx < GDT_ENTRY_TLS_MIN || idx > GDT_ENTRY_TLS_MAX) | |
6693 | return -EINVAL; | |
6694 | ||
6695 | +#ifdef CONFIG_PAX_SEGMEXEC | |
6696 | + if ((p->mm->pax_flags & MF_PAX_SEGMEXEC) && (info.contents & MODIFY_LDT_CONTENTS_CODE)) | |
6697 | + return -EINVAL; | |
6698 | +#endif | |
6699 | + | |
6700 | set_tls_desc(p, idx, &info, 1); | |
6701 | ||
6702 | return 0; | |
6703 | diff -urNp linux-2.6.25.4/arch/x86/kernel/traps_32.c linux-2.6.25.4/arch/x86/kernel/traps_32.c | |
6704 | --- linux-2.6.25.4/arch/x86/kernel/traps_32.c 2008-05-15 11:00:12.000000000 -0400 | |
6705 | +++ linux-2.6.25.4/arch/x86/kernel/traps_32.c 2008-05-18 13:33:14.000000000 -0400 | |
da5b3fc8 | 6706 | @@ -29,6 +29,7 @@ |
6707 | #include <linux/uaccess.h> | |
6708 | #include <linux/nmi.h> | |
6709 | #include <linux/bug.h> | |
6710 | +#include <linux/binfmts.h> | |
50425a20 | 6711 | |
da5b3fc8 | 6712 | #ifdef CONFIG_EISA |
6713 | #include <linux/ioport.h> | |
4dee9bd5 | 6714 | @@ -71,14 +72,6 @@ asmlinkage int system_call(void); |
da5b3fc8 | 6715 | /* Do we ignore FPU interrupts ? */ |
6716 | char ignore_fpu_irq = 0; | |
50425a20 | 6717 | |
da5b3fc8 | 6718 | -/* |
6719 | - * The IDT has to be page-aligned to simplify the Pentium | |
6720 | - * F0 0F bug workaround.. We have a special link segment | |
6721 | - * for this. | |
6722 | - */ | |
4dee9bd5 | 6723 | -gate_desc idt_table[256] |
6724 | - __attribute__((__section__(".data.idt"))) = { { { { 0, 0 } } }, }; | |
6725 | - | |
da5b3fc8 | 6726 | asmlinkage void divide_error(void); |
6727 | asmlinkage void debug(void); | |
4dee9bd5 | 6728 | asmlinkage void nmi(void); |
6729 | @@ -330,22 +323,23 @@ void show_registers(struct pt_regs *regs | |
da5b3fc8 | 6730 | * When in-kernel, we also print out the stack and code at the |
6731 | * time of the fault.. | |
6732 | */ | |
6733 | - if (!user_mode_vm(regs)) { | |
6734 | + if (!user_mode(regs)) { | |
4dee9bd5 | 6735 | u8 *ip; |
da5b3fc8 | 6736 | unsigned int code_prologue = code_bytes * 43 / 64; |
6737 | unsigned int code_len = code_bytes; | |
6738 | unsigned char c; | |
4dee9bd5 | 6739 | + unsigned long cs_base = get_desc_base(&get_cpu_gdt_table(smp_processor_id())[(0xffff & regs->cs) >> 3]); |
50425a20 | 6740 | |
da5b3fc8 | 6741 | printk("\n" KERN_EMERG "Stack: "); |
4dee9bd5 | 6742 | show_stack_log_lvl(NULL, regs, ®s->sp, 0, KERN_EMERG); |
50425a20 | 6743 | |
da5b3fc8 | 6744 | printk(KERN_EMERG "Code: "); |
50425a20 | 6745 | |
4dee9bd5 | 6746 | - ip = (u8 *)regs->ip - code_prologue; |
6747 | + ip = (u8 *)regs->ip - code_prologue + cs_base; | |
6748 | if (ip < (u8 *)PAGE_OFFSET || | |
6749 | probe_kernel_address(ip, c)) { | |
da5b3fc8 | 6750 | /* try starting at EIP */ |
4dee9bd5 | 6751 | - ip = (u8 *)regs->ip; |
6752 | + ip = (u8 *)regs->ip + cs_base; | |
da5b3fc8 | 6753 | code_len = code_len - code_prologue + 1; |
6754 | } | |
4dee9bd5 | 6755 | for (i = 0; i < code_len; i++, ip++) { |
6756 | @@ -354,7 +348,7 @@ void show_registers(struct pt_regs *regs | |
da5b3fc8 | 6757 | printk(" Bad EIP value."); |
6758 | break; | |
6759 | } | |
4dee9bd5 | 6760 | - if (ip == (u8 *)regs->ip) |
6761 | + if (ip == (u8 *)regs->ip + cs_base) | |
da5b3fc8 | 6762 | printk("<%02x> ", c); |
6763 | else | |
6764 | printk("%02x ", c); | |
4dee9bd5 | 6765 | @@ -367,6 +361,7 @@ int is_valid_bugaddr(unsigned long ip) |
da5b3fc8 | 6766 | { |
6767 | unsigned short ud2; | |
50425a20 | 6768 | |
4dee9bd5 | 6769 | + ip = ktla_ktva(ip); |
6770 | if (ip < PAGE_OFFSET) | |
da5b3fc8 | 6771 | return 0; |
4dee9bd5 | 6772 | if (probe_kernel_address((unsigned short *)ip, ud2)) |
6773 | @@ -476,7 +471,7 @@ void die(const char * str, struct pt_reg | |
50425a20 | 6774 | |
da5b3fc8 | 6775 | static inline void die_if_kernel(const char * str, struct pt_regs * regs, long err) |
50425a20 | 6776 | { |
da5b3fc8 | 6777 | - if (!user_mode_vm(regs)) |
6778 | + if (!user_mode(regs)) | |
6779 | die(str, regs, err); | |
6780 | } | |
50425a20 | 6781 | |
4dee9bd5 | 6782 | @@ -492,7 +487,7 @@ static void __kprobes do_trap(int trapnr |
da5b3fc8 | 6783 | goto trap_signal; |
6784 | } | |
6785 | ||
6786 | - if (!user_mode(regs)) | |
6787 | + if (!user_mode_novm(regs)) | |
6788 | goto kernel_trap; | |
6789 | ||
6790 | trap_signal: { | |
4dee9bd5 | 6791 | @@ -598,7 +593,7 @@ void __kprobes do_general_protection(str |
da5b3fc8 | 6792 | long error_code) |
6793 | { | |
6794 | int cpu = get_cpu(); | |
6795 | - struct tss_struct *tss = &per_cpu(init_tss, cpu); | |
6796 | + struct tss_struct *tss = &init_tss[cpu]; | |
6797 | struct thread_struct *thread = ¤t->thread; | |
6798 | ||
6799 | /* | |
4dee9bd5 | 6800 | @@ -631,9 +626,25 @@ void __kprobes do_general_protection(str |
6801 | if (regs->flags & VM_MASK) | |
da5b3fc8 | 6802 | goto gp_in_vm86; |
6803 | ||
6804 | - if (!user_mode(regs)) | |
6805 | + if (!user_mode_novm(regs)) | |
6806 | goto gp_in_kernel; | |
50425a20 | 6807 | |
6808 | +#ifdef CONFIG_PAX_PAGEEXEC | |
da5b3fc8 | 6809 | + if (!nx_enabled && current->mm && (current->mm->pax_flags & MF_PAX_PAGEEXEC)) { |
6810 | + struct mm_struct *mm = current->mm; | |
6811 | + unsigned long limit; | |
50425a20 | 6812 | + |
da5b3fc8 | 6813 | + down_write(&mm->mmap_sem); |
6814 | + limit = mm->context.user_cs_limit; | |
6815 | + if (limit < TASK_SIZE) { | |
6816 | + track_exec_limit(mm, limit, TASK_SIZE, VM_EXEC); | |
6817 | + up_write(&mm->mmap_sem); | |
6818 | + return; | |
6819 | + } | |
6820 | + up_write(&mm->mmap_sem); | |
6821 | + } | |
6822 | +#endif | |
50425a20 | 6823 | + |
da5b3fc8 | 6824 | current->thread.error_code = error_code; |
6825 | current->thread.trap_no = 13; | |
6826 | if (show_unhandled_signals && unhandled_signal(current, SIGSEGV) && | |
4dee9bd5 | 6827 | @@ -661,6 +672,13 @@ gp_in_kernel: |
da5b3fc8 | 6828 | if (notify_die(DIE_GPF, "general protection fault", regs, |
6829 | error_code, 13, SIGSEGV) == NOTIFY_STOP) | |
6830 | return; | |
50425a20 | 6831 | + |
da5b3fc8 | 6832 | +#ifdef CONFIG_PAX_KERNEXEC |
4dee9bd5 | 6833 | + if ((regs->cs & 0xFFFF) == __KERNEL_CS) |
da5b3fc8 | 6834 | + die("PAX: suspicious general protection fault", regs, error_code); |
6835 | + else | |
6836 | +#endif | |
50425a20 | 6837 | + |
da5b3fc8 | 6838 | die("general protection fault", regs, error_code); |
6839 | } | |
6840 | } | |
4dee9bd5 | 6841 | @@ -750,7 +768,7 @@ void __kprobes die_nmi(struct pt_regs *r |
da5b3fc8 | 6842 | /* If we are in kernel we are probably nested up pretty bad |
6843 | * and might aswell get out now while we still can. | |
6844 | */ | |
6845 | - if (!user_mode_vm(regs)) { | |
6846 | + if (!user_mode(regs)) { | |
6847 | current->thread.trap_no = 2; | |
6848 | crash_kexec(regs); | |
6849 | } | |
4dee9bd5 | 6850 | @@ -907,7 +925,7 @@ void __kprobes do_debug(struct pt_regs * |
da5b3fc8 | 6851 | * check for kernel mode by just checking the CPL |
6852 | * of CS. | |
6853 | */ | |
6854 | - if (!user_mode(regs)) | |
6855 | + if (!user_mode_novm(regs)) | |
6856 | goto clear_TF_reenable; | |
6857 | } | |
6858 | ||
4dee9bd5 | 6859 | @@ -1085,18 +1103,14 @@ void do_spurious_interrupt_bug(struct pt |
6860 | unsigned long patch_espfix_desc(unsigned long uesp, | |
da5b3fc8 | 6861 | unsigned long kesp) |
6862 | { | |
6863 | - struct desc_struct *gdt = __get_cpu_var(gdt_page).gdt; | |
6864 | unsigned long base = (kesp - uesp) & -THREAD_SIZE; | |
6865 | unsigned long new_kesp = kesp - base; | |
6866 | unsigned long lim_pages = (new_kesp | (THREAD_SIZE - 1)) >> PAGE_SHIFT; | |
6867 | - __u64 desc = *(__u64 *)&gdt[GDT_ENTRY_ESPFIX_SS]; | |
4dee9bd5 | 6868 | + struct desc_struct ss; |
50425a20 | 6869 | + |
da5b3fc8 | 6870 | /* Set up base for espfix segment */ |
6871 | - desc &= 0x00f0ff0000000000ULL; | |
6872 | - desc |= ((((__u64)base) << 16) & 0x000000ffffff0000ULL) | | |
6873 | - ((((__u64)base) << 32) & 0xff00000000000000ULL) | | |
6874 | - ((((__u64)lim_pages) << 32) & 0x000f000000000000ULL) | | |
6875 | - (lim_pages & 0xffff); | |
6876 | - *(__u64 *)&gdt[GDT_ENTRY_ESPFIX_SS] = desc; | |
4dee9bd5 | 6877 | + pack_descriptor(&ss, base, lim_pages, 0x93, 0xC); |
6878 | + write_gdt_entry(get_cpu_gdt_table(smp_processor_id()), GDT_ENTRY_ESPFIX_SS, &ss, DESCTYPE_S); | |
da5b3fc8 | 6879 | return new_kesp; |
6880 | } | |
6881 | ||
4dee9bd5 | 6882 | diff -urNp linux-2.6.25.4/arch/x86/kernel/tsc_32.c linux-2.6.25.4/arch/x86/kernel/tsc_32.c |
6883 | --- linux-2.6.25.4/arch/x86/kernel/tsc_32.c 2008-05-15 11:00:12.000000000 -0400 | |
6884 | +++ linux-2.6.25.4/arch/x86/kernel/tsc_32.c 2008-05-18 13:33:14.000000000 -0400 | |
6885 | @@ -339,7 +339,7 @@ static struct dmi_system_id __initdata b | |
da5b3fc8 | 6886 | DMI_MATCH(DMI_BOARD_NAME, "2635FA0"), |
6887 | }, | |
6888 | }, | |
6889 | - {} | |
6890 | + { NULL, NULL, {{0, NULL}}, NULL} | |
6891 | }; | |
6892 | ||
6893 | /* | |
4dee9bd5 | 6894 | diff -urNp linux-2.6.25.4/arch/x86/kernel/vm86_32.c linux-2.6.25.4/arch/x86/kernel/vm86_32.c |
6895 | --- linux-2.6.25.4/arch/x86/kernel/vm86_32.c 2008-05-15 11:00:12.000000000 -0400 | |
6896 | +++ linux-2.6.25.4/arch/x86/kernel/vm86_32.c 2008-05-18 13:33:14.000000000 -0400 | |
6897 | @@ -145,7 +145,7 @@ struct pt_regs * save_v86_state(struct k | |
da5b3fc8 | 6898 | do_exit(SIGSEGV); |
6899 | } | |
6900 | ||
6901 | - tss = &per_cpu(init_tss, get_cpu()); | |
6902 | + tss = init_tss + get_cpu(); | |
4dee9bd5 | 6903 | current->thread.sp0 = current->thread.saved_sp0; |
da5b3fc8 | 6904 | current->thread.sysenter_cs = __KERNEL_CS; |
4dee9bd5 | 6905 | load_sp0(tss, ¤t->thread); |
6906 | @@ -321,7 +321,7 @@ static void do_sys_vm86(struct kernel_vm | |
6907 | tsk->thread.saved_fs = info->regs32->fs; | |
da5b3fc8 | 6908 | savesegment(gs, tsk->thread.saved_gs); |
6909 | ||
6910 | - tss = &per_cpu(init_tss, get_cpu()); | |
6911 | + tss = init_tss + get_cpu(); | |
4dee9bd5 | 6912 | tsk->thread.sp0 = (unsigned long) &info->VM86_TSS_ESP0; |
da5b3fc8 | 6913 | if (cpu_has_sep) |
6914 | tsk->thread.sysenter_cs = 0; | |
4dee9bd5 | 6915 | diff -urNp linux-2.6.25.4/arch/x86/kernel/vmi_32.c linux-2.6.25.4/arch/x86/kernel/vmi_32.c |
6916 | --- linux-2.6.25.4/arch/x86/kernel/vmi_32.c 2008-05-15 11:00:12.000000000 -0400 | |
6917 | +++ linux-2.6.25.4/arch/x86/kernel/vmi_32.c 2008-05-18 13:33:14.000000000 -0400 | |
6918 | @@ -101,18 +101,43 @@ static unsigned patch_internal(int call, | |
da5b3fc8 | 6919 | { |
6920 | u64 reloc; | |
6921 | struct vmi_relocation_info *const rel = (struct vmi_relocation_info *)&reloc; | |
6922 | + | |
6923 | +#ifdef CONFIG_PAX_KERNEXEC | |
6924 | + unsigned long cr0; | |
50425a20 | 6925 | +#endif |
6926 | + | |
da5b3fc8 | 6927 | reloc = call_vrom_long_func(vmi_rom, get_reloc, call); |
6928 | switch(rel->type) { | |
6929 | case VMI_RELOCATION_CALL_REL: | |
6930 | BUG_ON(len < 5); | |
50425a20 | 6931 | + |
da5b3fc8 | 6932 | +#ifdef CONFIG_PAX_KERNEXEC |
6933 | + pax_open_kernel(cr0); | |
50425a20 | 6934 | +#endif |
6935 | + | |
da5b3fc8 | 6936 | *(char *)insnbuf = MNEM_CALL; |
4dee9bd5 | 6937 | patch_offset(insnbuf, ip, (unsigned long)rel->eip); |
50425a20 | 6938 | + |
da5b3fc8 | 6939 | +#ifdef CONFIG_PAX_KERNEXEC |
6940 | + pax_close_kernel(cr0); | |
6941 | +#endif | |
50425a20 | 6942 | + |
da5b3fc8 | 6943 | return 5; |
6944 | ||
6945 | case VMI_RELOCATION_JUMP_REL: | |
6946 | BUG_ON(len < 5); | |
50425a20 | 6947 | + |
da5b3fc8 | 6948 | +#ifdef CONFIG_PAX_KERNEXEC |
6949 | + pax_open_kernel(cr0); | |
50425a20 | 6950 | +#endif |
6951 | + | |
da5b3fc8 | 6952 | *(char *)insnbuf = MNEM_JMP; |
4dee9bd5 | 6953 | patch_offset(insnbuf, ip, (unsigned long)rel->eip); |
50425a20 | 6954 | + |
da5b3fc8 | 6955 | +#ifdef CONFIG_PAX_KERNEXEC |
6956 | + pax_close_kernel(cr0); | |
50425a20 | 6957 | +#endif |
6958 | + | |
da5b3fc8 | 6959 | return 5; |
6960 | ||
6961 | case VMI_RELOCATION_NOP: | |
4dee9bd5 | 6962 | @@ -515,14 +540,14 @@ static void vmi_set_pud(pud_t *pudp, pud |
da5b3fc8 | 6963 | |
6964 | static void vmi_pte_clear(struct mm_struct *mm, unsigned long addr, pte_t *ptep) | |
50425a20 | 6965 | { |
4dee9bd5 | 6966 | - const pte_t pte = { .pte = 0 }; |
da5b3fc8 | 6967 | + const pte_t pte = __pte(0ULL); |
6968 | vmi_check_page_type(__pa(ptep) >> PAGE_SHIFT, VMI_PAGE_PTE); | |
6969 | vmi_ops.set_pte(pte, ptep, vmi_flags_addr(mm, addr, VMI_PAGE_PT, 0)); | |
6970 | } | |
50425a20 | 6971 | |
da5b3fc8 | 6972 | static void vmi_pmd_clear(pmd_t *pmd) |
6973 | { | |
4dee9bd5 | 6974 | - const pte_t pte = { .pte = 0 }; |
da5b3fc8 | 6975 | + const pte_t pte = __pte(0ULL); |
6976 | vmi_check_page_type(__pa(pmd) >> PAGE_SHIFT, VMI_PAGE_PMD); | |
6977 | vmi_ops.set_pte(pte, (pte_t *)pmd, VMI_PAGE_PD); | |
6978 | } | |
4dee9bd5 | 6979 | @@ -551,8 +576,8 @@ vmi_startup_ipi_hook(int phys_apicid, un |
da5b3fc8 | 6980 | ap.ss = __KERNEL_DS; |
6981 | ap.esp = (unsigned long) start_esp; | |
50425a20 | 6982 | |
da5b3fc8 | 6983 | - ap.ds = __USER_DS; |
6984 | - ap.es = __USER_DS; | |
6985 | + ap.ds = __KERNEL_DS; | |
6986 | + ap.es = __KERNEL_DS; | |
6987 | ap.fs = __KERNEL_PERCPU; | |
6988 | ap.gs = 0; | |
6989 | ||
4dee9bd5 | 6990 | @@ -747,12 +772,20 @@ static inline int __init activate_vmi(vo |
da5b3fc8 | 6991 | u64 reloc; |
6992 | const struct vmi_relocation_info *rel = (struct vmi_relocation_info *)&reloc; | |
6993 | ||
6994 | +#ifdef CONFIG_PAX_KERNEXEC | |
6995 | + unsigned long cr0; | |
6996 | +#endif | |
50425a20 | 6997 | + |
da5b3fc8 | 6998 | if (call_vrom_func(vmi_rom, vmi_init) != 0) { |
6999 | printk(KERN_ERR "VMI ROM failed to initialize!"); | |
7000 | return 0; | |
7001 | } | |
7002 | savesegment(cs, kernel_cs); | |
7003 | ||
7004 | +#ifdef CONFIG_PAX_KERNEXEC | |
7005 | + pax_open_kernel(cr0); | |
50425a20 | 7006 | +#endif |
7007 | + | |
da5b3fc8 | 7008 | pv_info.paravirt_enabled = 1; |
7009 | pv_info.kernel_rpl = kernel_cs & SEGMENT_RPL_MASK; | |
7010 | pv_info.name = "vmi"; | |
4dee9bd5 | 7011 | @@ -943,6 +976,10 @@ static inline int __init activate_vmi(vo |
da5b3fc8 | 7012 | |
7013 | para_fill(pv_irq_ops.safe_halt, Halt); | |
7014 | ||
7015 | +#ifdef CONFIG_PAX_KERNEXEC | |
7016 | + pax_close_kernel(cr0); | |
50425a20 | 7017 | +#endif |
7018 | + | |
da5b3fc8 | 7019 | /* |
7020 | * Alternative instruction rewriting doesn't happen soon enough | |
7021 | * to convert VMI_IRET to a call instead of a jump; so we have | |
4dee9bd5 | 7022 | diff -urNp linux-2.6.25.4/arch/x86/kernel/vmlinux_32.lds.S linux-2.6.25.4/arch/x86/kernel/vmlinux_32.lds.S |
7023 | --- linux-2.6.25.4/arch/x86/kernel/vmlinux_32.lds.S 2008-05-15 11:00:12.000000000 -0400 | |
7024 | +++ linux-2.6.25.4/arch/x86/kernel/vmlinux_32.lds.S 2008-05-18 13:33:14.000000000 -0400 | |
7025 | @@ -15,6 +15,20 @@ | |
da5b3fc8 | 7026 | #include <asm/page.h> |
7027 | #include <asm/cache.h> | |
7028 | #include <asm/boot.h> | |
7029 | +#include <asm/segment.h> | |
7030 | + | |
7031 | +#ifdef CONFIG_X86_PAE | |
7032 | +#define PMD_SHIFT 21 | |
7033 | +#else | |
7034 | +#define PMD_SHIFT 22 | |
50425a20 | 7035 | +#endif |
da5b3fc8 | 7036 | +#define PMD_SIZE (1 << PMD_SHIFT) |
50425a20 | 7037 | + |
da5b3fc8 | 7038 | +#ifdef CONFIG_PAX_KERNEXEC |
7039 | +#define __KERNEL_TEXT_OFFSET (__PAGE_OFFSET + (((____LOAD_PHYSICAL_ADDR + 2*(PMD_SIZE - 1)) - 1) & ~(PMD_SIZE - 1))) | |
7040 | +#else | |
7041 | +#define __KERNEL_TEXT_OFFSET 0 | |
7042 | +#endif | |
50425a20 | 7043 | |
da5b3fc8 | 7044 | OUTPUT_FORMAT("elf32-i386", "elf32-i386", "elf32-i386") |
7045 | OUTPUT_ARCH(i386) | |
4dee9bd5 | 7046 | @@ -22,90 +36,23 @@ ENTRY(phys_startup_32) |
da5b3fc8 | 7047 | jiffies = jiffies_64; |
50425a20 | 7048 | |
da5b3fc8 | 7049 | PHDRS { |
7050 | - text PT_LOAD FLAGS(5); /* R_E */ | |
7051 | - data PT_LOAD FLAGS(7); /* RWE */ | |
7052 | - note PT_NOTE FLAGS(0); /* ___ */ | |
7053 | + initdata PT_LOAD FLAGS(6); /* RW_ */ | |
7054 | + percpu PT_LOAD FLAGS(6); /* RW_ */ | |
7055 | + inittext PT_LOAD FLAGS(5); /* R_E */ | |
7056 | + text PT_LOAD FLAGS(5); /* R_E */ | |
7057 | + rodata PT_LOAD FLAGS(4); /* R__ */ | |
7058 | + data PT_LOAD FLAGS(6); /* RW_ */ | |
7059 | + note PT_NOTE FLAGS(0); /* ___ */ | |
7060 | } | |
7061 | SECTIONS | |
7062 | { | |
7063 | - . = LOAD_OFFSET + LOAD_PHYSICAL_ADDR; | |
7064 | - phys_startup_32 = startup_32 - LOAD_OFFSET; | |
4dee9bd5 | 7065 | - |
7066 | - .text.head : AT(ADDR(.text.head) - LOAD_OFFSET) { | |
7067 | - _text = .; /* Text and read-only data */ | |
7068 | - *(.text.head) | |
7069 | - } :text = 0x9090 | |
7070 | - | |
7071 | - /* read-only */ | |
7072 | - .text : AT(ADDR(.text) - LOAD_OFFSET) { | |
7073 | - . = ALIGN(PAGE_SIZE); /* not really needed, already page aligned */ | |
7074 | - *(.text.page_aligned) | |
7075 | - TEXT_TEXT | |
7076 | - SCHED_TEXT | |
7077 | - LOCK_TEXT | |
7078 | - KPROBES_TEXT | |
7079 | - *(.fixup) | |
7080 | - *(.gnu.warning) | |
7081 | - _etext = .; /* End of text section */ | |
7082 | - } :text = 0x9090 | |
7083 | - | |
7084 | - . = ALIGN(16); /* Exception table */ | |
7085 | - __ex_table : AT(ADDR(__ex_table) - LOAD_OFFSET) { | |
7086 | - __start___ex_table = .; | |
7087 | - *(__ex_table) | |
7088 | - __stop___ex_table = .; | |
7089 | - } | |
7090 | - | |
7091 | - NOTES :text :note | |
7092 | - | |
7093 | - BUG_TABLE :text | |
7094 | - | |
7095 | - . = ALIGN(4); | |
7096 | - .tracedata : AT(ADDR(.tracedata) - LOAD_OFFSET) { | |
7097 | - __tracedata_start = .; | |
7098 | - *(.tracedata) | |
7099 | - __tracedata_end = .; | |
7100 | - } | |
da5b3fc8 | 7101 | + . = LOAD_OFFSET + ____LOAD_PHYSICAL_ADDR; |
4dee9bd5 | 7102 | |
7103 | - RODATA | |
7104 | - | |
7105 | - /* writeable */ | |
7106 | - . = ALIGN(PAGE_SIZE); | |
7107 | - .data : AT(ADDR(.data) - LOAD_OFFSET) { /* Data */ | |
7108 | - DATA_DATA | |
7109 | - CONSTRUCTORS | |
7110 | - } :data | |
7111 | - | |
7112 | - . = ALIGN(PAGE_SIZE); | |
7113 | - .data_nosave : AT(ADDR(.data_nosave) - LOAD_OFFSET) { | |
7114 | - __nosave_begin = .; | |
7115 | - *(.data.nosave) | |
7116 | - . = ALIGN(PAGE_SIZE); | |
7117 | - __nosave_end = .; | |
7118 | - } | |
7119 | - | |
7120 | - . = ALIGN(PAGE_SIZE); | |
7121 | - .data.page_aligned : AT(ADDR(.data.page_aligned) - LOAD_OFFSET) { | |
7122 | - *(.data.page_aligned) | |
7123 | - *(.data.idt) | |
7124 | - } | |
7125 | - | |
7126 | - . = ALIGN(32); | |
7127 | - .data.cacheline_aligned : AT(ADDR(.data.cacheline_aligned) - LOAD_OFFSET) { | |
7128 | - *(.data.cacheline_aligned) | |
7129 | - } | |
7130 | - | |
7131 | - /* rarely changed data like cpu maps */ | |
7132 | - . = ALIGN(32); | |
7133 | - .data.read_mostly : AT(ADDR(.data.read_mostly) - LOAD_OFFSET) { | |
7134 | - *(.data.read_mostly) | |
7135 | - _edata = .; /* End of data section */ | |
7136 | - } | |
7137 | - | |
7138 | - . = ALIGN(THREAD_SIZE); /* init_task */ | |
7139 | - .data.init_task : AT(ADDR(.data.init_task) - LOAD_OFFSET) { | |
7140 | - *(.data.init_task) | |
7141 | - } | |
da5b3fc8 | 7142 | + .text.startup : AT(ADDR(.text.startup) - LOAD_OFFSET) { |
7143 | + __LOAD_PHYSICAL_ADDR = . - LOAD_OFFSET; | |
7144 | + phys_startup_32 = startup_32 - LOAD_OFFSET + __KERNEL_TEXT_OFFSET; | |
7145 | + *(.text.startup) | |
7146 | + } :initdata | |
4dee9bd5 | 7147 | |
7148 | /* might get freed after init */ | |
7149 | . = ALIGN(PAGE_SIZE); | |
7150 | @@ -123,14 +70,8 @@ SECTIONS | |
7151 | . = ALIGN(PAGE_SIZE); | |
7152 | ||
7153 | /* will be freed after init */ | |
7154 | - . = ALIGN(PAGE_SIZE); /* Init code and data */ | |
7155 | - .init.text : AT(ADDR(.init.text) - LOAD_OFFSET) { | |
7156 | - __init_begin = .; | |
7157 | - _sinittext = .; | |
7158 | - INIT_TEXT | |
7159 | - _einittext = .; | |
7160 | - } | |
7161 | .init.data : AT(ADDR(.init.data) - LOAD_OFFSET) { | |
da5b3fc8 | 7162 | + __init_begin = .; |
4dee9bd5 | 7163 | INIT_DATA |
7164 | } | |
7165 | . = ALIGN(16); | |
7166 | @@ -165,11 +106,6 @@ SECTIONS | |
7167 | *(.parainstructions) | |
7168 | __parainstructions_end = .; | |
7169 | } | |
7170 | - /* .exit.text is discard at runtime, not link time, to deal with references | |
7171 | - from .altinstructions and .eh_frame */ | |
7172 | - .exit.text : AT(ADDR(.exit.text) - LOAD_OFFSET) { | |
7173 | - EXIT_TEXT | |
7174 | - } | |
7175 | .exit.data : AT(ADDR(.exit.data) - LOAD_OFFSET) { | |
7176 | EXIT_DATA | |
7177 | } | |
7178 | @@ -182,17 +118,144 @@ SECTIONS | |
7179 | } | |
7180 | #endif | |
7181 | . = ALIGN(PAGE_SIZE); | |
7182 | - .data.percpu : AT(ADDR(.data.percpu) - LOAD_OFFSET) { | |
7183 | - __per_cpu_start = .; | |
da5b3fc8 | 7184 | + per_cpu_start = .; |
7185 | + .data.percpu (0) : AT(ADDR(.data.percpu) - LOAD_OFFSET + per_cpu_start) { | |
7186 | + __per_cpu_start = . + per_cpu_start; | |
7187 | + LONG(0) | |
4dee9bd5 | 7188 | *(.data.percpu) |
7189 | *(.data.percpu.shared_aligned) | |
7190 | - __per_cpu_end = .; | |
7191 | - } | |
da5b3fc8 | 7192 | + __per_cpu_end = . + per_cpu_start; |
7193 | + } :percpu | |
7194 | + . += per_cpu_start; | |
4dee9bd5 | 7195 | . = ALIGN(PAGE_SIZE); |
7196 | /* freed after init ends here */ | |
7197 | ||
7198 | + . = ALIGN(PAGE_SIZE); /* Init code and data */ | |
da5b3fc8 | 7199 | + .init.text (. - __KERNEL_TEXT_OFFSET) : AT(ADDR(.init.text) - LOAD_OFFSET + __KERNEL_TEXT_OFFSET) { |
7200 | + _sinittext = .; | |
4dee9bd5 | 7201 | + INIT_TEXT |
da5b3fc8 | 7202 | + _einittext = .; |
7203 | + } :inittext | |
7204 | + | |
7205 | + /* .exit.text is discard at runtime, not link time, to deal with references | |
7206 | + from .altinstructions and .eh_frame */ | |
4dee9bd5 | 7207 | + .exit.text : AT(ADDR(.exit.text) - LOAD_OFFSET + __KERNEL_TEXT_OFFSET) { |
7208 | + EXIT_TEXT | |
7209 | + } | |
7210 | + | |
da5b3fc8 | 7211 | + .filler : AT(ADDR(.filler) - LOAD_OFFSET + __KERNEL_TEXT_OFFSET) { |
7212 | + BYTE(0) | |
7213 | + . = ALIGN(2*PMD_SIZE) - 1; | |
7214 | + } | |
7215 | + | |
7216 | + /* freed after init ends here */ | |
7217 | + | |
7218 | + .text.head : AT(ADDR(.text.head) - LOAD_OFFSET + __KERNEL_TEXT_OFFSET) { | |
7219 | + __init_end = . + __KERNEL_TEXT_OFFSET; | |
7220 | + KERNEL_TEXT_OFFSET = . + __KERNEL_TEXT_OFFSET; | |
7221 | + _text = .; /* Text and read-only data */ | |
4dee9bd5 | 7222 | + *(.text.head) |
7223 | + } :text = 0x9090 | |
7224 | + | |
7225 | + /* read-only */ | |
da5b3fc8 | 7226 | + .text : AT(ADDR(.text) - LOAD_OFFSET + __KERNEL_TEXT_OFFSET) { |
4dee9bd5 | 7227 | + . = ALIGN(PAGE_SIZE); /* not really needed, already page aligned */ |
7228 | + *(.text.page_aligned) | |
7229 | + TEXT_TEXT | |
7230 | + SCHED_TEXT | |
7231 | + LOCK_TEXT | |
7232 | + KPROBES_TEXT | |
7233 | + *(.fixup) | |
7234 | + *(.gnu.warning) | |
7235 | + _etext = .; /* End of text section */ | |
7236 | + } :text = 0x9090 | |
7237 | + | |
da5b3fc8 | 7238 | + . += __KERNEL_TEXT_OFFSET; |
7239 | + . = ALIGN(4096); /* Exception table */ | |
4dee9bd5 | 7240 | + __ex_table : AT(ADDR(__ex_table) - LOAD_OFFSET) { |
7241 | + __start___ex_table = .; | |
7242 | + *(__ex_table) | |
7243 | + __stop___ex_table = .; | |
da5b3fc8 | 7244 | + } :rodata |
4dee9bd5 | 7245 | + |
da5b3fc8 | 7246 | + NOTES :rodata :note |
4dee9bd5 | 7247 | + |
da5b3fc8 | 7248 | + BUG_TABLE :rodata |
b2ee8b1e | 7249 | + |
4dee9bd5 | 7250 | + . = ALIGN(4); |
7251 | + .tracedata : AT(ADDR(.tracedata) - LOAD_OFFSET) { | |
7252 | + __tracedata_start = .; | |
7253 | + *(.tracedata) | |
7254 | + __tracedata_end = .; | |
7255 | + } | |
7256 | + | |
7257 | + RO_DATA(PAGE_SIZE) | |
7258 | + | |
7259 | + . = ALIGN(PAGE_SIZE); | |
da5b3fc8 | 7260 | + .rodata.page_aligned : AT(ADDR(.rodata.page_aligned) - LOAD_OFFSET) { |
7261 | + *(.idt) | |
4dee9bd5 | 7262 | + . = ALIGN(PAGE_SIZE); |
da5b3fc8 | 7263 | + *(.empty_zero_page) |
4dee9bd5 | 7264 | + *(.swapper_pg_pmd) |
da5b3fc8 | 7265 | + *(.swapper_pg_dir) |
7266 | + } | |
50425a20 | 7267 | + |
da5b3fc8 | 7268 | +#ifdef CONFIG_PAX_KERNEXEC |
50425a20 | 7269 | + |
da5b3fc8 | 7270 | +#ifdef CONFIG_MODULES |
4dee9bd5 | 7271 | + . = ALIGN(PAGE_SIZE); |
da5b3fc8 | 7272 | + .module.text : AT(ADDR(.module.text) - LOAD_OFFSET) { |
7273 | + MODULES_VADDR = .; | |
7274 | + BYTE(0) | |
7275 | + . += (6 * 1024 * 1024); | |
7276 | + . = ALIGN( PMD_SIZE) - 1; | |
7277 | + MODULES_END = .; | |
7278 | + } | |
7279 | +#else | |
7280 | + . = ALIGN(PMD_SIZE) - 1; | |
7281 | +#endif | |
50425a20 | 7282 | + |
da5b3fc8 | 7283 | +#endif |
4dee9bd5 | 7284 | + |
7285 | + /* writeable */ | |
7286 | + . = ALIGN(PAGE_SIZE); | |
7287 | + .data : AT(ADDR(.data) - LOAD_OFFSET) { /* Data */ | |
da5b3fc8 | 7288 | + _data = .; |
4dee9bd5 | 7289 | + DATA_DATA |
7290 | + CONSTRUCTORS | |
7291 | + } :data | |
7292 | + | |
7293 | + . = ALIGN(PAGE_SIZE); | |
7294 | + .data_nosave : AT(ADDR(.data_nosave) - LOAD_OFFSET) { | |
7295 | + __nosave_begin = .; | |
7296 | + *(.data.nosave) | |
7297 | + . = ALIGN(PAGE_SIZE); | |
7298 | + __nosave_end = .; | |
7299 | + } | |
7300 | + | |
7301 | + . = ALIGN(PAGE_SIZE); | |
7302 | + .data.page_aligned : AT(ADDR(.data.page_aligned) - LOAD_OFFSET) { | |
7303 | + *(.data.page_aligned) | |
7304 | + } | |
7305 | + | |
7306 | + . = ALIGN(32); | |
7307 | + .data.cacheline_aligned : AT(ADDR(.data.cacheline_aligned) - LOAD_OFFSET) { | |
7308 | + *(.data.cacheline_aligned) | |
7309 | + } | |
7310 | + | |
7311 | + /* rarely changed data like cpu maps */ | |
7312 | + . = ALIGN(32); | |
7313 | + .data.read_mostly : AT(ADDR(.data.read_mostly) - LOAD_OFFSET) { | |
7314 | + *(.data.read_mostly) | |
7315 | + _edata = .; /* End of data section */ | |
7316 | + } | |
7317 | + | |
7318 | + . = ALIGN(THREAD_SIZE); /* init_task */ | |
7319 | + .data.init_task : AT(ADDR(.data.init_task) - LOAD_OFFSET) { | |
7320 | + *(.data.init_task) | |
7321 | + } | |
7322 | + | |
da5b3fc8 | 7323 | .bss : AT(ADDR(.bss) - LOAD_OFFSET) { |
7324 | - __init_end = .; | |
7325 | __bss_start = .; /* BSS */ | |
7326 | *(.bss.page_aligned) | |
7327 | *(.bss) | |
4dee9bd5 | 7328 | diff -urNp linux-2.6.25.4/arch/x86/kernel/vmlinux_64.lds.S linux-2.6.25.4/arch/x86/kernel/vmlinux_64.lds.S |
7329 | --- linux-2.6.25.4/arch/x86/kernel/vmlinux_64.lds.S 2008-05-15 11:00:12.000000000 -0400 | |
7330 | +++ linux-2.6.25.4/arch/x86/kernel/vmlinux_64.lds.S 2008-05-18 13:33:14.000000000 -0400 | |
da5b3fc8 | 7331 | @@ -16,8 +16,8 @@ jiffies_64 = jiffies; |
7332 | _proxy_pda = 1; | |
7333 | PHDRS { | |
7334 | text PT_LOAD FLAGS(5); /* R_E */ | |
7335 | - data PT_LOAD FLAGS(7); /* RWE */ | |
7336 | - user PT_LOAD FLAGS(7); /* RWE */ | |
7337 | + data PT_LOAD FLAGS(6); /* RW_ */ | |
7338 | + user PT_LOAD FLAGS(7); /* RWX */ | |
7339 | data.init PT_LOAD FLAGS(7); /* RWE */ | |
7340 | note PT_NOTE FLAGS(4); /* R__ */ | |
7341 | } | |
4dee9bd5 | 7342 | @@ -51,7 +51,7 @@ SECTIONS |
b2ee8b1e | 7343 | |
7344 | BUG_TABLE :text | |
7345 | ||
7346 | - RODATA | |
4dee9bd5 | 7347 | + RO_DATA(PAGE_SIZE) |
b2ee8b1e | 7348 | |
7349 | . = ALIGN(4); | |
7350 | .tracedata : AT(ADDR(.tracedata) - LOAD_OFFSET) { | |
4dee9bd5 | 7351 | @@ -60,15 +60,18 @@ SECTIONS |
da5b3fc8 | 7352 | __tracedata_end = .; |
7353 | } | |
7354 | ||
7355 | +#ifdef CONFIG_PAX_KERNEXEC | |
4dee9bd5 | 7356 | + . = ALIGN(2*1024*1024); /* Align data segment to PMD size boundary */ |
da5b3fc8 | 7357 | +#else |
4dee9bd5 | 7358 | . = ALIGN(PAGE_SIZE); /* Align data segment to page size boundary */ |
da5b3fc8 | 7359 | +#endif |
7360 | /* Data */ | |
7361 | + _data = .; | |
7362 | .data : AT(ADDR(.data) - LOAD_OFFSET) { | |
7363 | DATA_DATA | |
7364 | CONSTRUCTORS | |
7365 | } :data | |
7366 | ||
7367 | - _edata = .; /* End of data section */ | |
7368 | - | |
7369 | . = ALIGN(PAGE_SIZE); | |
7370 | . = ALIGN(CONFIG_X86_L1_CACHE_BYTES); | |
7371 | .data.cacheline_aligned : AT(ADDR(.data.cacheline_aligned) - LOAD_OFFSET) { | |
4dee9bd5 | 7372 | @@ -79,9 +82,27 @@ SECTIONS |
da5b3fc8 | 7373 | *(.data.read_mostly) |
7374 | } | |
7375 | ||
4dee9bd5 | 7376 | + . = ALIGN(THREAD_SIZE); /* init_task */ |
da5b3fc8 | 7377 | + .data.init_task : AT(ADDR(.data.init_task) - LOAD_OFFSET) { |
7378 | + *(.data.init_task) | |
4dee9bd5 | 7379 | + }:data.init |
50425a20 | 7380 | + |
4dee9bd5 | 7381 | + . = ALIGN(PAGE_SIZE); |
da5b3fc8 | 7382 | + .data.page_aligned : AT(ADDR(.data.page_aligned) - LOAD_OFFSET) { |
7383 | + *(.data.page_aligned) | |
7384 | + } | |
50425a20 | 7385 | + |
4dee9bd5 | 7386 | + . = ALIGN(PAGE_SIZE); |
da5b3fc8 | 7387 | + __nosave_begin = .; |
7388 | + .data_nosave : AT(ADDR(.data_nosave) - LOAD_OFFSET) { *(.data.nosave) } | |
4dee9bd5 | 7389 | + . = ALIGN(PAGE_SIZE); |
da5b3fc8 | 7390 | + __nosave_end = .; |
7391 | + | |
7392 | + _edata = .; /* End of data section */ | |
7393 | + | |
7394 | #define VSYSCALL_ADDR (-10*1024*1024) | |
7395 | -#define VSYSCALL_PHYS_ADDR ((LOADADDR(.data.read_mostly) + SIZEOF(.data.read_mostly) + 4095) & ~(4095)) | |
7396 | -#define VSYSCALL_VIRT_ADDR ((ADDR(.data.read_mostly) + SIZEOF(.data.read_mostly) + 4095) & ~(4095)) | |
b2ee8b1e | 7397 | +#define VSYSCALL_PHYS_ADDR ((LOADADDR(.data_nosave) + SIZEOF(.data_nosave) + 4095) & ~(4095)) |
7398 | +#define VSYSCALL_VIRT_ADDR ((ADDR(.data_nosave) + SIZEOF(.data_nosave) + 4095) & ~(4095)) | |
da5b3fc8 | 7399 | |
7400 | #define VLOAD_OFFSET (VSYSCALL_ADDR - VSYSCALL_PHYS_ADDR) | |
7401 | #define VLOAD(x) (ADDR(x) - VLOAD_OFFSET) | |
4dee9bd5 | 7402 | @@ -129,23 +150,13 @@ SECTIONS |
da5b3fc8 | 7403 | #undef VVIRT_OFFSET |
7404 | #undef VVIRT | |
7405 | ||
4dee9bd5 | 7406 | - . = ALIGN(THREAD_SIZE); /* init_task */ |
da5b3fc8 | 7407 | - .data.init_task : AT(ADDR(.data.init_task) - LOAD_OFFSET) { |
7408 | - *(.data.init_task) | |
7409 | - }:data.init | |
7410 | - | |
4dee9bd5 | 7411 | - . = ALIGN(PAGE_SIZE); |
da5b3fc8 | 7412 | - .data.page_aligned : AT(ADDR(.data.page_aligned) - LOAD_OFFSET) { |
7413 | - *(.data.page_aligned) | |
7414 | - } | |
7415 | - | |
7416 | /* might get freed after init */ | |
4dee9bd5 | 7417 | . = ALIGN(PAGE_SIZE); |
da5b3fc8 | 7418 | __smp_alt_begin = .; |
7419 | __smp_locks = .; | |
7420 | .smp_locks : AT(ADDR(.smp_locks) - LOAD_OFFSET) { | |
7421 | *(.smp_locks) | |
7422 | - } | |
7423 | + } :data.init | |
7424 | __smp_locks_end = .; | |
4dee9bd5 | 7425 | . = ALIGN(PAGE_SIZE); |
da5b3fc8 | 7426 | __smp_alt_end = .; |
4dee9bd5 | 7427 | @@ -222,12 +233,6 @@ SECTIONS |
7428 | . = ALIGN(PAGE_SIZE); | |
da5b3fc8 | 7429 | __init_end = .; |
7430 | ||
4dee9bd5 | 7431 | - . = ALIGN(PAGE_SIZE); |
da5b3fc8 | 7432 | - __nosave_begin = .; |
7433 | - .data_nosave : AT(ADDR(.data_nosave) - LOAD_OFFSET) { *(.data.nosave) } | |
4dee9bd5 | 7434 | - . = ALIGN(PAGE_SIZE); |
da5b3fc8 | 7435 | - __nosave_end = .; |
7436 | - | |
7437 | __bss_start = .; /* BSS */ | |
7438 | .bss : AT(ADDR(.bss) - LOAD_OFFSET) { | |
7439 | *(.bss.page_aligned) | |
4dee9bd5 | 7440 | @@ -235,6 +240,7 @@ SECTIONS |
da5b3fc8 | 7441 | } |
7442 | __bss_stop = .; | |
7443 | ||
7444 | + . = ALIGN(2*1024*1024); | |
7445 | _end = . ; | |
7446 | ||
7447 | /* Sections to be discarded */ | |
4dee9bd5 | 7448 | diff -urNp linux-2.6.25.4/arch/x86/kernel/vsyscall_64.c linux-2.6.25.4/arch/x86/kernel/vsyscall_64.c |
7449 | --- linux-2.6.25.4/arch/x86/kernel/vsyscall_64.c 2008-05-15 11:00:12.000000000 -0400 | |
7450 | +++ linux-2.6.25.4/arch/x86/kernel/vsyscall_64.c 2008-05-18 13:33:14.000000000 -0400 | |
7451 | @@ -235,13 +235,13 @@ static ctl_table kernel_table2[] = { | |
da5b3fc8 | 7452 | .data = &vsyscall_gtod_data.sysctl_enabled, .maxlen = sizeof(int), |
7453 | .mode = 0644, | |
7454 | .proc_handler = vsyscall_sysctl_change }, | |
7455 | - {} | |
7456 | + { 0, NULL, NULL, 0, 0, NULL, NULL, NULL, NULL, NULL, NULL } | |
7457 | }; | |
7458 | ||
7459 | static ctl_table kernel_root_table2[] = { | |
7460 | { .ctl_name = CTL_KERN, .procname = "kernel", .mode = 0555, | |
7461 | .child = kernel_table2 }, | |
7462 | - {} | |
7463 | + { 0, NULL, NULL, 0, 0, NULL, NULL, NULL, NULL, NULL, NULL } | |
7464 | }; | |
da5b3fc8 | 7465 | #endif |
4dee9bd5 | 7466 | |
7467 | @@ -251,6 +251,11 @@ static void __cpuinit vsyscall_set_cpu(i | |
da5b3fc8 | 7468 | { |
7469 | unsigned long *d; | |
7470 | unsigned long node = 0; | |
50425a20 | 7471 | + |
da5b3fc8 | 7472 | +#ifdef CONFIG_PAX_KERNEXEC |
7473 | + unsigned long cr0; | |
50425a20 | 7474 | +#endif |
7475 | + | |
da5b3fc8 | 7476 | #ifdef CONFIG_NUMA |
7477 | node = cpu_to_node(cpu); | |
7478 | #endif | |
4dee9bd5 | 7479 | @@ -261,10 +266,20 @@ static void __cpuinit vsyscall_set_cpu(i |
da5b3fc8 | 7480 | in user space in vgetcpu. |
7481 | 12 bits for the CPU and 8 bits for the node. */ | |
4dee9bd5 | 7482 | d = (unsigned long *)(get_cpu_gdt_table(cpu) + GDT_ENTRY_PER_CPU); |
50425a20 | 7483 | + |
da5b3fc8 | 7484 | +#ifdef CONFIG_PAX_KERNEXEC |
7485 | + pax_open_kernel(cr0); | |
50425a20 | 7486 | +#endif |
7487 | + | |
da5b3fc8 | 7488 | *d = 0x0f40000000000ULL; |
7489 | *d |= cpu; | |
7490 | *d |= (node & 0xf) << 12; | |
7491 | *d |= (node >> 4) << 48; | |
50425a20 | 7492 | + |
da5b3fc8 | 7493 | +#ifdef CONFIG_PAX_KERNEXEC |
7494 | + pax_close_kernel(cr0); | |
7495 | +#endif | |
50425a20 | 7496 | + |
da5b3fc8 | 7497 | } |
7498 | ||
7499 | static void __cpuinit cpu_vsyscall_init(void *arg) | |
4dee9bd5 | 7500 | diff -urNp linux-2.6.25.4/arch/x86/kvm/svm.c linux-2.6.25.4/arch/x86/kvm/svm.c |
7501 | --- linux-2.6.25.4/arch/x86/kvm/svm.c 2008-05-15 11:00:12.000000000 -0400 | |
7502 | +++ linux-2.6.25.4/arch/x86/kvm/svm.c 2008-05-18 13:33:14.000000000 -0400 | |
7503 | @@ -1329,8 +1329,20 @@ static void reload_tss(struct kvm_vcpu * | |
7504 | int cpu = raw_smp_processor_id(); | |
7505 | ||
7506 | struct svm_cpu_data *svm_data = per_cpu(svm_data, cpu); | |
7507 | + | |
7508 | +#ifdef CONFIG_PAX_KERNEXEC | |
7509 | + unsigned long cr0; | |
7510 | + | |
7511 | + pax_open_kernel(cr0); | |
7512 | +#endif | |
7513 | + | |
7514 | svm_data->tss_desc->type = 9; /* available 32/64-bit TSS */ | |
7515 | load_TR_desc(); | |
7516 | + | |
7517 | +#ifdef CONFIG_PAX_KERNEXEC | |
7518 | + pax_close_kernel(cr0); | |
7519 | +#endif | |
7520 | + | |
7521 | } | |
7522 | ||
7523 | static void pre_svm_run(struct vcpu_svm *svm) | |
7524 | diff -urNp linux-2.6.25.4/arch/x86/kvm/vmx.c linux-2.6.25.4/arch/x86/kvm/vmx.c | |
7525 | --- linux-2.6.25.4/arch/x86/kvm/vmx.c 2008-05-15 11:00:12.000000000 -0400 | |
7526 | +++ linux-2.6.25.4/arch/x86/kvm/vmx.c 2008-05-18 13:33:15.000000000 -0400 | |
7527 | @@ -355,10 +355,24 @@ static void reload_tss(void) | |
7528 | struct descriptor_table gdt; | |
7529 | struct segment_descriptor *descs; | |
7530 | ||
7531 | +#ifdef CONFIG_PAX_KERNEXEC | |
7532 | + unsigned long cr0; | |
7533 | +#endif | |
7534 | + | |
7535 | get_gdt(&gdt); | |
7536 | descs = (void *)gdt.base; | |
7537 | + | |
7538 | +#ifdef CONFIG_PAX_KERNEXEC | |
7539 | + pax_open_kernel(cr0); | |
7540 | +#endif | |
7541 | + | |
7542 | descs[GDT_ENTRY_TSS].type = 9; /* available TSS */ | |
7543 | load_TR_desc(); | |
7544 | + | |
7545 | +#ifdef CONFIG_PAX_KERNEXEC | |
7546 | + pax_close_kernel(cr0); | |
7547 | +#endif | |
7548 | + | |
7549 | } | |
7550 | ||
7551 | static void load_transition_efer(struct vcpu_vmx *vmx) | |
7552 | @@ -2464,7 +2478,7 @@ static void vmx_vcpu_run(struct kvm_vcpu | |
7553 | vcpu->arch.interrupt_window_open = | |
7554 | (vmcs_read32(GUEST_INTERRUPTIBILITY_INFO) & 3) == 0; | |
7555 | ||
7556 | - asm("mov %0, %%ds; mov %0, %%es" : : "r"(__USER_DS)); | |
7557 | + asm("mov %0, %%ds; mov %0, %%es" : : "r"(__KERNEL_DS)); | |
7558 | vmx->launched = 1; | |
7559 | ||
7560 | intr_info = vmcs_read32(VM_EXIT_INTR_INFO); | |
7561 | diff -urNp linux-2.6.25.4/arch/x86/kvm/x86.c linux-2.6.25.4/arch/x86/kvm/x86.c | |
7562 | --- linux-2.6.25.4/arch/x86/kvm/x86.c 2008-05-15 11:00:12.000000000 -0400 | |
7563 | +++ linux-2.6.25.4/arch/x86/kvm/x86.c 2008-05-18 13:33:15.000000000 -0400 | |
7564 | @@ -52,33 +52,33 @@ static int kvm_dev_ioctl_get_supported_c | |
7565 | struct kvm_x86_ops *kvm_x86_ops; | |
7566 | ||
7567 | struct kvm_stats_debugfs_item debugfs_entries[] = { | |
7568 | - { "pf_fixed", VCPU_STAT(pf_fixed) }, | |
7569 | - { "pf_guest", VCPU_STAT(pf_guest) }, | |
7570 | - { "tlb_flush", VCPU_STAT(tlb_flush) }, | |
7571 | - { "invlpg", VCPU_STAT(invlpg) }, | |
7572 | - { "exits", VCPU_STAT(exits) }, | |
7573 | - { "io_exits", VCPU_STAT(io_exits) }, | |
7574 | - { "mmio_exits", VCPU_STAT(mmio_exits) }, | |
7575 | - { "signal_exits", VCPU_STAT(signal_exits) }, | |
7576 | - { "irq_window", VCPU_STAT(irq_window_exits) }, | |
7577 | - { "halt_exits", VCPU_STAT(halt_exits) }, | |
7578 | - { "halt_wakeup", VCPU_STAT(halt_wakeup) }, | |
7579 | - { "request_irq", VCPU_STAT(request_irq_exits) }, | |
7580 | - { "irq_exits", VCPU_STAT(irq_exits) }, | |
7581 | - { "host_state_reload", VCPU_STAT(host_state_reload) }, | |
7582 | - { "efer_reload", VCPU_STAT(efer_reload) }, | |
7583 | - { "fpu_reload", VCPU_STAT(fpu_reload) }, | |
7584 | - { "insn_emulation", VCPU_STAT(insn_emulation) }, | |
7585 | - { "insn_emulation_fail", VCPU_STAT(insn_emulation_fail) }, | |
7586 | - { "mmu_shadow_zapped", VM_STAT(mmu_shadow_zapped) }, | |
7587 | - { "mmu_pte_write", VM_STAT(mmu_pte_write) }, | |
7588 | - { "mmu_pte_updated", VM_STAT(mmu_pte_updated) }, | |
7589 | - { "mmu_pde_zapped", VM_STAT(mmu_pde_zapped) }, | |
7590 | - { "mmu_flooded", VM_STAT(mmu_flooded) }, | |
7591 | - { "mmu_recycled", VM_STAT(mmu_recycled) }, | |
7592 | - { "mmu_cache_miss", VM_STAT(mmu_cache_miss) }, | |
7593 | - { "remote_tlb_flush", VM_STAT(remote_tlb_flush) }, | |
7594 | - { NULL } | |
7595 | + { "pf_fixed", VCPU_STAT(pf_fixed), NULL }, | |
7596 | + { "pf_guest", VCPU_STAT(pf_guest), NULL }, | |
7597 | + { "tlb_flush", VCPU_STAT(tlb_flush), NULL }, | |
7598 | + { "invlpg", VCPU_STAT(invlpg), NULL }, | |
7599 | + { "exits", VCPU_STAT(exits), NULL }, | |
7600 | + { "io_exits", VCPU_STAT(io_exits), NULL }, | |
7601 | + { "mmio_exits", VCPU_STAT(mmio_exits), NULL }, | |
7602 | + { "signal_exits", VCPU_STAT(signal_exits), NULL }, | |
7603 | + { "irq_window", VCPU_STAT(irq_window_exits), NULL }, | |
7604 | + { "halt_exits", VCPU_STAT(halt_exits), NULL }, | |
7605 | + { "halt_wakeup", VCPU_STAT(halt_wakeup), NULL }, | |
7606 | + { "request_irq", VCPU_STAT(request_irq_exits), NULL }, | |
7607 | + { "irq_exits", VCPU_STAT(irq_exits), NULL }, | |
7608 | + { "host_state_reload", VCPU_STAT(host_state_reload), NULL }, | |
7609 | + { "efer_reload", VCPU_STAT(efer_reload), NULL }, | |
7610 | + { "fpu_reload", VCPU_STAT(fpu_reload), NULL }, | |
7611 | + { "insn_emulation", VCPU_STAT(insn_emulation), NULL }, | |
7612 | + { "insn_emulation_fail", VCPU_STAT(insn_emulation_fail), NULL }, | |
7613 | + { "mmu_shadow_zapped", VM_STAT(mmu_shadow_zapped), NULL }, | |
7614 | + { "mmu_pte_write", VM_STAT(mmu_pte_write), NULL }, | |
7615 | + { "mmu_pte_updated", VM_STAT(mmu_pte_updated), NULL }, | |
7616 | + { "mmu_pde_zapped", VM_STAT(mmu_pde_zapped), NULL }, | |
7617 | + { "mmu_flooded", VM_STAT(mmu_flooded), NULL }, | |
7618 | + { "mmu_recycled", VM_STAT(mmu_recycled), NULL }, | |
7619 | + { "mmu_cache_miss", VM_STAT(mmu_cache_miss), NULL }, | |
7620 | + { "remote_tlb_flush", VM_STAT(remote_tlb_flush), NULL }, | |
7621 | + { NULL, 0, KVM_STAT_VM, NULL } | |
7622 | }; | |
7623 | ||
7624 | ||
7625 | @@ -1065,7 +1065,7 @@ static int kvm_vcpu_ioctl_set_lapic(stru | |
7626 | static int kvm_vcpu_ioctl_interrupt(struct kvm_vcpu *vcpu, | |
7627 | struct kvm_interrupt *irq) | |
7628 | { | |
7629 | - if (irq->irq < 0 || irq->irq >= 256) | |
7630 | + if (irq->irq >= 256) | |
7631 | return -EINVAL; | |
7632 | if (irqchip_in_kernel(vcpu->kvm)) | |
7633 | return -ENXIO; | |
7634 | diff -urNp linux-2.6.25.4/arch/x86/lib/checksum_32.S linux-2.6.25.4/arch/x86/lib/checksum_32.S | |
7635 | --- linux-2.6.25.4/arch/x86/lib/checksum_32.S 2008-05-15 11:00:12.000000000 -0400 | |
7636 | +++ linux-2.6.25.4/arch/x86/lib/checksum_32.S 2008-05-18 13:33:15.000000000 -0400 | |
da5b3fc8 | 7637 | @@ -28,7 +28,8 @@ |
7638 | #include <linux/linkage.h> | |
7639 | #include <asm/dwarf2.h> | |
7640 | #include <asm/errno.h> | |
7641 | - | |
7642 | +#include <asm/segment.h> | |
50425a20 | 7643 | + |
da5b3fc8 | 7644 | /* |
7645 | * computes a partial checksum, e.g. for TCP/UDP fragments | |
7646 | */ | |
7647 | @@ -304,9 +305,22 @@ unsigned int csum_partial_copy_generic ( | |
7648 | ||
7649 | #define ARGBASE 16 | |
7650 | #define FP 12 | |
7651 | - | |
7652 | -ENTRY(csum_partial_copy_generic) | |
50425a20 | 7653 | + |
da5b3fc8 | 7654 | +ENTRY(csum_partial_copy_generic_to_user) |
7655 | CFI_STARTPROC | |
7656 | + pushl $(__USER_DS) | |
7657 | + CFI_ADJUST_CFA_OFFSET 4 | |
7658 | + popl %es | |
7659 | + CFI_ADJUST_CFA_OFFSET -4 | |
7660 | + jmp csum_partial_copy_generic | |
50425a20 | 7661 | + |
da5b3fc8 | 7662 | +ENTRY(csum_partial_copy_generic_from_user) |
7663 | + pushl $(__USER_DS) | |
7664 | + CFI_ADJUST_CFA_OFFSET 4 | |
7665 | + popl %ds | |
7666 | + CFI_ADJUST_CFA_OFFSET -4 | |
50425a20 | 7667 | + |
da5b3fc8 | 7668 | +ENTRY(csum_partial_copy_generic) |
7669 | subl $4,%esp | |
7670 | CFI_ADJUST_CFA_OFFSET 4 | |
7671 | pushl %edi | |
7672 | @@ -331,7 +345,7 @@ ENTRY(csum_partial_copy_generic) | |
7673 | jmp 4f | |
7674 | SRC(1: movw (%esi), %bx ) | |
7675 | addl $2, %esi | |
7676 | -DST( movw %bx, (%edi) ) | |
7677 | +DST( movw %bx, %es:(%edi) ) | |
7678 | addl $2, %edi | |
7679 | addw %bx, %ax | |
7680 | adcl $0, %eax | |
7681 | @@ -343,30 +357,30 @@ DST( movw %bx, (%edi) ) | |
7682 | SRC(1: movl (%esi), %ebx ) | |
7683 | SRC( movl 4(%esi), %edx ) | |
7684 | adcl %ebx, %eax | |
7685 | -DST( movl %ebx, (%edi) ) | |
7686 | +DST( movl %ebx, %es:(%edi) ) | |
7687 | adcl %edx, %eax | |
7688 | -DST( movl %edx, 4(%edi) ) | |
7689 | +DST( movl %edx, %es:4(%edi) ) | |
7690 | ||
7691 | SRC( movl 8(%esi), %ebx ) | |
7692 | SRC( movl 12(%esi), %edx ) | |
7693 | adcl %ebx, %eax | |
7694 | -DST( movl %ebx, 8(%edi) ) | |
7695 | +DST( movl %ebx, %es:8(%edi) ) | |
7696 | adcl %edx, %eax | |
7697 | -DST( movl %edx, 12(%edi) ) | |
7698 | +DST( movl %edx, %es:12(%edi) ) | |
7699 | ||
7700 | SRC( movl 16(%esi), %ebx ) | |
7701 | SRC( movl 20(%esi), %edx ) | |
7702 | adcl %ebx, %eax | |
7703 | -DST( movl %ebx, 16(%edi) ) | |
7704 | +DST( movl %ebx, %es:16(%edi) ) | |
7705 | adcl %edx, %eax | |
7706 | -DST( movl %edx, 20(%edi) ) | |
7707 | +DST( movl %edx, %es:20(%edi) ) | |
7708 | ||
7709 | SRC( movl 24(%esi), %ebx ) | |
7710 | SRC( movl 28(%esi), %edx ) | |
7711 | adcl %ebx, %eax | |
7712 | -DST( movl %ebx, 24(%edi) ) | |
7713 | +DST( movl %ebx, %es:24(%edi) ) | |
7714 | adcl %edx, %eax | |
7715 | -DST( movl %edx, 28(%edi) ) | |
7716 | +DST( movl %edx, %es:28(%edi) ) | |
7717 | ||
7718 | lea 32(%esi), %esi | |
7719 | lea 32(%edi), %edi | |
7720 | @@ -380,7 +394,7 @@ DST( movl %edx, 28(%edi) ) | |
7721 | shrl $2, %edx # This clears CF | |
7722 | SRC(3: movl (%esi), %ebx ) | |
7723 | adcl %ebx, %eax | |
7724 | -DST( movl %ebx, (%edi) ) | |
7725 | +DST( movl %ebx, %es:(%edi) ) | |
7726 | lea 4(%esi), %esi | |
7727 | lea 4(%edi), %edi | |
7728 | dec %edx | |
7729 | @@ -392,12 +406,12 @@ DST( movl %ebx, (%edi) ) | |
7730 | jb 5f | |
7731 | SRC( movw (%esi), %cx ) | |
7732 | leal 2(%esi), %esi | |
7733 | -DST( movw %cx, (%edi) ) | |
7734 | +DST( movw %cx, %es:(%edi) ) | |
7735 | leal 2(%edi), %edi | |
7736 | je 6f | |
7737 | shll $16,%ecx | |
7738 | SRC(5: movb (%esi), %cl ) | |
7739 | -DST( movb %cl, (%edi) ) | |
7740 | +DST( movb %cl, %es:(%edi) ) | |
7741 | 6: addl %ecx, %eax | |
7742 | adcl $0, %eax | |
7743 | 7: | |
7744 | @@ -408,7 +422,7 @@ DST( movb %cl, (%edi) ) | |
7745 | ||
7746 | 6001: | |
7747 | movl ARGBASE+20(%esp), %ebx # src_err_ptr | |
7748 | - movl $-EFAULT, (%ebx) | |
7749 | + movl $-EFAULT, %ss:(%ebx) | |
7750 | ||
7751 | # zero the complete destination - computing the rest | |
7752 | # is too much work | |
7753 | @@ -421,11 +435,19 @@ DST( movb %cl, (%edi) ) | |
7754 | ||
7755 | 6002: | |
7756 | movl ARGBASE+24(%esp), %ebx # dst_err_ptr | |
7757 | - movl $-EFAULT,(%ebx) | |
7758 | + movl $-EFAULT,%ss:(%ebx) | |
7759 | jmp 5000b | |
7760 | ||
7761 | .previous | |
7762 | ||
7763 | + pushl %ss | |
7764 | + CFI_ADJUST_CFA_OFFSET 4 | |
7765 | + popl %ds | |
7766 | + CFI_ADJUST_CFA_OFFSET -4 | |
7767 | + pushl %ss | |
7768 | + CFI_ADJUST_CFA_OFFSET 4 | |
7769 | + popl %es | |
7770 | + CFI_ADJUST_CFA_OFFSET -4 | |
7771 | popl %ebx | |
7772 | CFI_ADJUST_CFA_OFFSET -4 | |
7773 | CFI_RESTORE ebx | |
7774 | @@ -439,26 +461,41 @@ DST( movb %cl, (%edi) ) | |
7775 | CFI_ADJUST_CFA_OFFSET -4 | |
7776 | ret | |
7777 | CFI_ENDPROC | |
7778 | -ENDPROC(csum_partial_copy_generic) | |
7779 | +ENDPROC(csum_partial_copy_generic_to_user) | |
7780 | ||
7781 | #else | |
7782 | ||
7783 | /* Version for PentiumII/PPro */ | |
7784 | ||
7785 | #define ROUND1(x) \ | |
7786 | + nop; nop; nop; \ | |
7787 | SRC(movl x(%esi), %ebx ) ; \ | |
7788 | addl %ebx, %eax ; \ | |
7789 | - DST(movl %ebx, x(%edi) ) ; | |
7790 | + DST(movl %ebx, %es:x(%edi)) ; | |
7791 | ||
7792 | #define ROUND(x) \ | |
7793 | + nop; nop; nop; \ | |
7794 | SRC(movl x(%esi), %ebx ) ; \ | |
7795 | adcl %ebx, %eax ; \ | |
7796 | - DST(movl %ebx, x(%edi) ) ; | |
7797 | + DST(movl %ebx, %es:x(%edi)) ; | |
7798 | ||
7799 | #define ARGBASE 12 | |
7800 | - | |
7801 | -ENTRY(csum_partial_copy_generic) | |
50425a20 | 7802 | + |
da5b3fc8 | 7803 | +ENTRY(csum_partial_copy_generic_to_user) |
7804 | CFI_STARTPROC | |
7805 | + pushl $(__USER_DS) | |
7806 | + CFI_ADJUST_CFA_OFFSET 4 | |
7807 | + popl %es | |
7808 | + CFI_ADJUST_CFA_OFFSET -4 | |
7809 | + jmp csum_partial_copy_generic | |
50425a20 | 7810 | + |
da5b3fc8 | 7811 | +ENTRY(csum_partial_copy_generic_from_user) |
7812 | + pushl $(__USER_DS) | |
7813 | + CFI_ADJUST_CFA_OFFSET 4 | |
7814 | + popl %ds | |
7815 | + CFI_ADJUST_CFA_OFFSET -4 | |
50425a20 | 7816 | + |
da5b3fc8 | 7817 | +ENTRY(csum_partial_copy_generic) |
7818 | pushl %ebx | |
7819 | CFI_ADJUST_CFA_OFFSET 4 | |
7820 | CFI_REL_OFFSET ebx, 0 | |
7821 | @@ -482,7 +519,7 @@ ENTRY(csum_partial_copy_generic) | |
7822 | subl %ebx, %edi | |
7823 | lea -1(%esi),%edx | |
7824 | andl $-32,%edx | |
7825 | - lea 3f(%ebx,%ebx), %ebx | |
7826 | + lea 3f(%ebx,%ebx,2), %ebx | |
7827 | testl %esi, %esi | |
7828 | jmp *%ebx | |
7829 | 1: addl $64,%esi | |
7830 | @@ -503,19 +540,19 @@ ENTRY(csum_partial_copy_generic) | |
7831 | jb 5f | |
7832 | SRC( movw (%esi), %dx ) | |
7833 | leal 2(%esi), %esi | |
7834 | -DST( movw %dx, (%edi) ) | |
7835 | +DST( movw %dx, %es:(%edi) ) | |
7836 | leal 2(%edi), %edi | |
7837 | je 6f | |
7838 | shll $16,%edx | |
7839 | 5: | |
7840 | SRC( movb (%esi), %dl ) | |
7841 | -DST( movb %dl, (%edi) ) | |
7842 | +DST( movb %dl, %es:(%edi) ) | |
7843 | 6: addl %edx, %eax | |
7844 | adcl $0, %eax | |
7845 | 7: | |
7846 | .section .fixup, "ax" | |
7847 | 6001: movl ARGBASE+20(%esp), %ebx # src_err_ptr | |
7848 | - movl $-EFAULT, (%ebx) | |
7849 | + movl $-EFAULT, %ss:(%ebx) | |
7850 | # zero the complete destination (computing the rest is too much work) | |
7851 | movl ARGBASE+8(%esp),%edi # dst | |
7852 | movl ARGBASE+12(%esp),%ecx # len | |
7853 | @@ -523,10 +560,18 @@ DST( movb %dl, (%edi) ) | |
7854 | rep; stosb | |
7855 | jmp 7b | |
7856 | 6002: movl ARGBASE+24(%esp), %ebx # dst_err_ptr | |
7857 | - movl $-EFAULT, (%ebx) | |
7858 | + movl $-EFAULT, %ss:(%ebx) | |
7859 | jmp 7b | |
7860 | .previous | |
7861 | ||
7862 | + pushl %ss | |
7863 | + CFI_ADJUST_CFA_OFFSET 4 | |
7864 | + popl %ds | |
7865 | + CFI_ADJUST_CFA_OFFSET -4 | |
7866 | + pushl %ss | |
7867 | + CFI_ADJUST_CFA_OFFSET 4 | |
7868 | + popl %es | |
7869 | + CFI_ADJUST_CFA_OFFSET -4 | |
7870 | popl %esi | |
7871 | CFI_ADJUST_CFA_OFFSET -4 | |
7872 | CFI_RESTORE esi | |
7873 | @@ -538,7 +583,7 @@ DST( movb %dl, (%edi) ) | |
7874 | CFI_RESTORE ebx | |
7875 | ret | |
7876 | CFI_ENDPROC | |
7877 | -ENDPROC(csum_partial_copy_generic) | |
7878 | +ENDPROC(csum_partial_copy_generic_to_user) | |
7879 | ||
7880 | #undef ROUND | |
7881 | #undef ROUND1 | |
4dee9bd5 | 7882 | diff -urNp linux-2.6.25.4/arch/x86/lib/clear_page_64.S linux-2.6.25.4/arch/x86/lib/clear_page_64.S |
7883 | --- linux-2.6.25.4/arch/x86/lib/clear_page_64.S 2008-05-15 11:00:12.000000000 -0400 | |
7884 | +++ linux-2.6.25.4/arch/x86/lib/clear_page_64.S 2008-05-18 13:33:15.000000000 -0400 | |
da5b3fc8 | 7885 | @@ -44,7 +44,7 @@ ENDPROC(clear_page) |
7886 | ||
7887 | #include <asm/cpufeature.h> | |
7888 | ||
7889 | - .section .altinstr_replacement,"ax" | |
7890 | + .section .altinstr_replacement,"a" | |
7891 | 1: .byte 0xeb /* jmp <disp8> */ | |
7892 | .byte (clear_page_c - clear_page) - (2f - 1b) /* offset */ | |
7893 | 2: | |
4dee9bd5 | 7894 | diff -urNp linux-2.6.25.4/arch/x86/lib/copy_page_64.S linux-2.6.25.4/arch/x86/lib/copy_page_64.S |
7895 | --- linux-2.6.25.4/arch/x86/lib/copy_page_64.S 2008-05-15 11:00:12.000000000 -0400 | |
7896 | +++ linux-2.6.25.4/arch/x86/lib/copy_page_64.S 2008-05-18 13:33:15.000000000 -0400 | |
da5b3fc8 | 7897 | @@ -104,7 +104,7 @@ ENDPROC(copy_page) |
7898 | ||
7899 | #include <asm/cpufeature.h> | |
7900 | ||
7901 | - .section .altinstr_replacement,"ax" | |
7902 | + .section .altinstr_replacement,"a" | |
7903 | 1: .byte 0xeb /* jmp <disp8> */ | |
7904 | .byte (copy_page_c - copy_page) - (2f - 1b) /* offset */ | |
7905 | 2: | |
4dee9bd5 | 7906 | diff -urNp linux-2.6.25.4/arch/x86/lib/copy_user_64.S linux-2.6.25.4/arch/x86/lib/copy_user_64.S |
7907 | --- linux-2.6.25.4/arch/x86/lib/copy_user_64.S 2008-05-15 11:00:12.000000000 -0400 | |
7908 | +++ linux-2.6.25.4/arch/x86/lib/copy_user_64.S 2008-05-18 13:33:15.000000000 -0400 | |
da5b3fc8 | 7909 | @@ -19,7 +19,7 @@ |
7910 | .byte 0xe9 /* 32bit jump */ | |
7911 | .long \orig-1f /* by default jump to orig */ | |
7912 | 1: | |
7913 | - .section .altinstr_replacement,"ax" | |
7914 | + .section .altinstr_replacement,"a" | |
7915 | 2: .byte 0xe9 /* near jump with 32bit immediate */ | |
7916 | .long \alt-1b /* offset */ /* or alternatively to alt */ | |
7917 | .previous | |
4dee9bd5 | 7918 | diff -urNp linux-2.6.25.4/arch/x86/lib/getuser_32.S linux-2.6.25.4/arch/x86/lib/getuser_32.S |
7919 | --- linux-2.6.25.4/arch/x86/lib/getuser_32.S 2008-05-15 11:00:12.000000000 -0400 | |
7920 | +++ linux-2.6.25.4/arch/x86/lib/getuser_32.S 2008-05-18 13:33:15.000000000 -0400 | |
da5b3fc8 | 7921 | @@ -11,7 +11,7 @@ |
7922 | #include <linux/linkage.h> | |
7923 | #include <asm/dwarf2.h> | |
7924 | #include <asm/thread_info.h> | |
7925 | - | |
7926 | +#include <asm/segment.h> | |
7927 | ||
7928 | /* | |
7929 | * __get_user_X | |
7930 | @@ -31,7 +31,11 @@ ENTRY(__get_user_1) | |
7931 | GET_THREAD_INFO(%edx) | |
7932 | cmpl TI_addr_limit(%edx),%eax | |
7933 | jae bad_get_user | |
7934 | + pushl $(__USER_DS) | |
7935 | + popl %ds | |
7936 | 1: movzbl (%eax),%edx | |
7937 | + pushl %ss | |
7938 | + pop %ds | |
7939 | xorl %eax,%eax | |
7940 | ret | |
7941 | CFI_ENDPROC | |
7942 | @@ -44,7 +48,11 @@ ENTRY(__get_user_2) | |
7943 | GET_THREAD_INFO(%edx) | |
7944 | cmpl TI_addr_limit(%edx),%eax | |
7945 | jae bad_get_user | |
7946 | + pushl $(__USER_DS) | |
7947 | + popl %ds | |
7948 | 2: movzwl -1(%eax),%edx | |
7949 | + pushl %ss | |
7950 | + pop %ds | |
7951 | xorl %eax,%eax | |
7952 | ret | |
7953 | CFI_ENDPROC | |
7954 | @@ -57,7 +65,11 @@ ENTRY(__get_user_4) | |
7955 | GET_THREAD_INFO(%edx) | |
7956 | cmpl TI_addr_limit(%edx),%eax | |
7957 | jae bad_get_user | |
7958 | + pushl $(__USER_DS) | |
7959 | + popl %ds | |
7960 | 3: movl -3(%eax),%edx | |
7961 | + pushl %ss | |
7962 | + pop %ds | |
7963 | xorl %eax,%eax | |
7964 | ret | |
7965 | CFI_ENDPROC | |
7966 | @@ -65,6 +77,8 @@ ENDPROC(__get_user_4) | |
7967 | ||
7968 | bad_get_user: | |
7969 | CFI_STARTPROC | |
7970 | + pushl %ss | |
7971 | + pop %ds | |
7972 | xorl %edx,%edx | |
7973 | movl $-14,%eax | |
7974 | ret | |
4dee9bd5 | 7975 | diff -urNp linux-2.6.25.4/arch/x86/lib/memcpy_64.S linux-2.6.25.4/arch/x86/lib/memcpy_64.S |
7976 | --- linux-2.6.25.4/arch/x86/lib/memcpy_64.S 2008-05-15 11:00:12.000000000 -0400 | |
7977 | +++ linux-2.6.25.4/arch/x86/lib/memcpy_64.S 2008-05-18 13:33:15.000000000 -0400 | |
da5b3fc8 | 7978 | @@ -114,7 +114,7 @@ ENDPROC(__memcpy) |
7979 | /* Some CPUs run faster using the string copy instructions. | |
7980 | It is also a lot simpler. Use this when possible */ | |
7981 | ||
7982 | - .section .altinstr_replacement,"ax" | |
7983 | + .section .altinstr_replacement,"a" | |
7984 | 1: .byte 0xeb /* jmp <disp8> */ | |
7985 | .byte (memcpy_c - memcpy) - (2f - 1b) /* offset */ | |
7986 | 2: | |
4dee9bd5 | 7987 | diff -urNp linux-2.6.25.4/arch/x86/lib/memset_64.S linux-2.6.25.4/arch/x86/lib/memset_64.S |
7988 | --- linux-2.6.25.4/arch/x86/lib/memset_64.S 2008-05-15 11:00:12.000000000 -0400 | |
7989 | +++ linux-2.6.25.4/arch/x86/lib/memset_64.S 2008-05-18 13:33:15.000000000 -0400 | |
da5b3fc8 | 7990 | @@ -118,7 +118,7 @@ ENDPROC(__memset) |
7991 | ||
7992 | #include <asm/cpufeature.h> | |
7993 | ||
7994 | - .section .altinstr_replacement,"ax" | |
7995 | + .section .altinstr_replacement,"a" | |
7996 | 1: .byte 0xeb /* jmp <disp8> */ | |
7997 | .byte (memset_c - memset) - (2f - 1b) /* offset */ | |
7998 | 2: | |
4dee9bd5 | 7999 | diff -urNp linux-2.6.25.4/arch/x86/lib/mmx_32.c linux-2.6.25.4/arch/x86/lib/mmx_32.c |
8000 | --- linux-2.6.25.4/arch/x86/lib/mmx_32.c 2008-05-15 11:00:12.000000000 -0400 | |
8001 | +++ linux-2.6.25.4/arch/x86/lib/mmx_32.c 2008-05-18 13:33:15.000000000 -0400 | |
8002 | @@ -31,6 +31,7 @@ void *_mmx_memcpy(void *to, const void * | |
da5b3fc8 | 8003 | { |
8004 | void *p; | |
8005 | int i; | |
8006 | + unsigned long cr0; | |
8007 | ||
8008 | if (unlikely(in_interrupt())) | |
8009 | return __memcpy(to, from, len); | |
4dee9bd5 | 8010 | @@ -41,46 +42,74 @@ void *_mmx_memcpy(void *to, const void * |
da5b3fc8 | 8011 | kernel_fpu_begin(); |
8012 | ||
8013 | __asm__ __volatile__ ( | |
8014 | - "1: prefetch (%0)\n" /* This set is 28 bytes */ | |
8015 | - " prefetch 64(%0)\n" | |
8016 | - " prefetch 128(%0)\n" | |
8017 | - " prefetch 192(%0)\n" | |
8018 | - " prefetch 256(%0)\n" | |
8019 | + "1: prefetch (%1)\n" /* This set is 28 bytes */ | |
8020 | + " prefetch 64(%1)\n" | |
8021 | + " prefetch 128(%1)\n" | |
8022 | + " prefetch 192(%1)\n" | |
8023 | + " prefetch 256(%1)\n" | |
8024 | "2: \n" | |
8025 | ".section .fixup, \"ax\"\n" | |
8026 | - "3: movw $0x1AEB, 1b\n" /* jmp on 26 bytes */ | |
8027 | + "3: \n" | |
50425a20 | 8028 | + |
da5b3fc8 | 8029 | +#ifdef CONFIG_PAX_KERNEXEC |
8030 | + " movl %%cr0, %0\n" | |
8031 | + " movl %0, %%eax\n" | |
8032 | + " andl $0xFFFEFFFF, %%eax\n" | |
8033 | + " movl %%eax, %%cr0\n" | |
8034 | +#endif | |
50425a20 | 8035 | + |
da5b3fc8 | 8036 | + " movw $0x1AEB, 1b\n" /* jmp on 26 bytes */ |
50425a20 | 8037 | + |
da5b3fc8 | 8038 | +#ifdef CONFIG_PAX_KERNEXEC |
8039 | + " movl %0, %%cr0\n" | |
8040 | +#endif | |
50425a20 | 8041 | + |
da5b3fc8 | 8042 | " jmp 2b\n" |
8043 | ".previous\n" | |
4dee9bd5 | 8044 | _ASM_EXTABLE(1b,3b) |
da5b3fc8 | 8045 | - : : "r" (from) ); |
8046 | + : "=&r" (cr0) : "r" (from) : "ax"); | |
8047 | ||
8048 | ||
8049 | for(; i>5; i--) | |
8050 | { | |
8051 | __asm__ __volatile__ ( | |
8052 | - "1: prefetch 320(%0)\n" | |
8053 | - "2: movq (%0), %%mm0\n" | |
8054 | - " movq 8(%0), %%mm1\n" | |
8055 | - " movq 16(%0), %%mm2\n" | |
8056 | - " movq 24(%0), %%mm3\n" | |
8057 | - " movq %%mm0, (%1)\n" | |
8058 | - " movq %%mm1, 8(%1)\n" | |
8059 | - " movq %%mm2, 16(%1)\n" | |
8060 | - " movq %%mm3, 24(%1)\n" | |
8061 | - " movq 32(%0), %%mm0\n" | |
8062 | - " movq 40(%0), %%mm1\n" | |
8063 | - " movq 48(%0), %%mm2\n" | |
8064 | - " movq 56(%0), %%mm3\n" | |
8065 | - " movq %%mm0, 32(%1)\n" | |
8066 | - " movq %%mm1, 40(%1)\n" | |
8067 | - " movq %%mm2, 48(%1)\n" | |
8068 | - " movq %%mm3, 56(%1)\n" | |
8069 | + "1: prefetch 320(%1)\n" | |
8070 | + "2: movq (%1), %%mm0\n" | |
8071 | + " movq 8(%1), %%mm1\n" | |
8072 | + " movq 16(%1), %%mm2\n" | |
8073 | + " movq 24(%1), %%mm3\n" | |
8074 | + " movq %%mm0, (%2)\n" | |
8075 | + " movq %%mm1, 8(%2)\n" | |
8076 | + " movq %%mm2, 16(%2)\n" | |
8077 | + " movq %%mm3, 24(%2)\n" | |
8078 | + " movq 32(%1), %%mm0\n" | |
8079 | + " movq 40(%1), %%mm1\n" | |
8080 | + " movq 48(%1), %%mm2\n" | |
8081 | + " movq 56(%1), %%mm3\n" | |
8082 | + " movq %%mm0, 32(%2)\n" | |
8083 | + " movq %%mm1, 40(%2)\n" | |
8084 | + " movq %%mm2, 48(%2)\n" | |
8085 | + " movq %%mm3, 56(%2)\n" | |
8086 | ".section .fixup, \"ax\"\n" | |
8087 | - "3: movw $0x05EB, 1b\n" /* jmp on 5 bytes */ | |
8088 | + "3:\n" | |
50425a20 | 8089 | + |
da5b3fc8 | 8090 | +#ifdef CONFIG_PAX_KERNEXEC |
8091 | + " movl %%cr0, %0\n" | |
8092 | + " movl %0, %%eax\n" | |
8093 | + " andl $0xFFFEFFFF, %%eax\n" | |
8094 | + " movl %%eax, %%cr0\n" | |
50425a20 | 8095 | +#endif |
8096 | + | |
da5b3fc8 | 8097 | + " movw $0x05EB, 1b\n" /* jmp on 5 bytes */ |
50425a20 | 8098 | + |
da5b3fc8 | 8099 | +#ifdef CONFIG_PAX_KERNEXEC |
8100 | + " movl %0, %%cr0\n" | |
8101 | +#endif | |
50425a20 | 8102 | + |
da5b3fc8 | 8103 | " jmp 2b\n" |
8104 | ".previous\n" | |
4dee9bd5 | 8105 | _ASM_EXTABLE(1b,3b) |
da5b3fc8 | 8106 | - : : "r" (from), "r" (to) : "memory"); |
8107 | + : "=&r" (cr0) : "r" (from), "r" (to) : "memory", "ax"); | |
8108 | from+=64; | |
8109 | to+=64; | |
8110 | } | |
4dee9bd5 | 8111 | @@ -159,6 +188,7 @@ static void fast_clear_page(void *page) |
da5b3fc8 | 8112 | static void fast_copy_page(void *to, void *from) |
8113 | { | |
8114 | int i; | |
8115 | + unsigned long cr0; | |
8116 | ||
8117 | kernel_fpu_begin(); | |
8118 | ||
4dee9bd5 | 8119 | @@ -166,45 +196,73 @@ static void fast_copy_page(void *to, voi |
da5b3fc8 | 8120 | * but that is for later. -AV |
8121 | */ | |
8122 | __asm__ __volatile__ ( | |
8123 | - "1: prefetch (%0)\n" | |
8124 | - " prefetch 64(%0)\n" | |
8125 | - " prefetch 128(%0)\n" | |
8126 | - " prefetch 192(%0)\n" | |
8127 | - " prefetch 256(%0)\n" | |
8128 | + "1: prefetch (%1)\n" | |
8129 | + " prefetch 64(%1)\n" | |
8130 | + " prefetch 128(%1)\n" | |
8131 | + " prefetch 192(%1)\n" | |
8132 | + " prefetch 256(%1)\n" | |
8133 | "2: \n" | |
8134 | ".section .fixup, \"ax\"\n" | |
8135 | - "3: movw $0x1AEB, 1b\n" /* jmp on 26 bytes */ | |
8136 | + "3: \n" | |
50425a20 | 8137 | + |
da5b3fc8 | 8138 | +#ifdef CONFIG_PAX_KERNEXEC |
8139 | + " movl %%cr0, %0\n" | |
8140 | + " movl %0, %%eax\n" | |
8141 | + " andl $0xFFFEFFFF, %%eax\n" | |
8142 | + " movl %%eax, %%cr0\n" | |
8143 | +#endif | |
50425a20 | 8144 | + |
da5b3fc8 | 8145 | + " movw $0x1AEB, 1b\n" /* jmp on 26 bytes */ |
50425a20 | 8146 | + |
da5b3fc8 | 8147 | +#ifdef CONFIG_PAX_KERNEXEC |
8148 | + " movl %0, %%cr0\n" | |
8149 | +#endif | |
50425a20 | 8150 | + |
da5b3fc8 | 8151 | " jmp 2b\n" |
8152 | ".previous\n" | |
4dee9bd5 | 8153 | _ASM_EXTABLE(1b,3b) |
da5b3fc8 | 8154 | - : : "r" (from) ); |
8155 | + : "=&r" (cr0) : "r" (from) : "ax"); | |
8156 | ||
8157 | for(i=0; i<(4096-320)/64; i++) | |
8158 | { | |
8159 | __asm__ __volatile__ ( | |
8160 | - "1: prefetch 320(%0)\n" | |
8161 | - "2: movq (%0), %%mm0\n" | |
8162 | - " movntq %%mm0, (%1)\n" | |
8163 | - " movq 8(%0), %%mm1\n" | |
8164 | - " movntq %%mm1, 8(%1)\n" | |
8165 | - " movq 16(%0), %%mm2\n" | |
8166 | - " movntq %%mm2, 16(%1)\n" | |
8167 | - " movq 24(%0), %%mm3\n" | |
8168 | - " movntq %%mm3, 24(%1)\n" | |
8169 | - " movq 32(%0), %%mm4\n" | |
8170 | - " movntq %%mm4, 32(%1)\n" | |
8171 | - " movq 40(%0), %%mm5\n" | |
8172 | - " movntq %%mm5, 40(%1)\n" | |
8173 | - " movq 48(%0), %%mm6\n" | |
8174 | - " movntq %%mm6, 48(%1)\n" | |
8175 | - " movq 56(%0), %%mm7\n" | |
8176 | - " movntq %%mm7, 56(%1)\n" | |
8177 | + "1: prefetch 320(%1)\n" | |
8178 | + "2: movq (%1), %%mm0\n" | |
8179 | + " movntq %%mm0, (%2)\n" | |
8180 | + " movq 8(%1), %%mm1\n" | |
8181 | + " movntq %%mm1, 8(%2)\n" | |
8182 | + " movq 16(%1), %%mm2\n" | |
8183 | + " movntq %%mm2, 16(%2)\n" | |
8184 | + " movq 24(%1), %%mm3\n" | |
8185 | + " movntq %%mm3, 24(%2)\n" | |
8186 | + " movq 32(%1), %%mm4\n" | |
8187 | + " movntq %%mm4, 32(%2)\n" | |
8188 | + " movq 40(%1), %%mm5\n" | |
8189 | + " movntq %%mm5, 40(%2)\n" | |
8190 | + " movq 48(%1), %%mm6\n" | |
8191 | + " movntq %%mm6, 48(%2)\n" | |
8192 | + " movq 56(%1), %%mm7\n" | |
8193 | + " movntq %%mm7, 56(%2)\n" | |
8194 | ".section .fixup, \"ax\"\n" | |
8195 | - "3: movw $0x05EB, 1b\n" /* jmp on 5 bytes */ | |
8196 | + "3:\n" | |
50425a20 | 8197 | + |
da5b3fc8 | 8198 | +#ifdef CONFIG_PAX_KERNEXEC |
8199 | + " movl %%cr0, %0\n" | |
8200 | + " movl %0, %%eax\n" | |
8201 | + " andl $0xFFFEFFFF, %%eax\n" | |
8202 | + " movl %%eax, %%cr0\n" | |
8203 | +#endif | |
50425a20 | 8204 | + |
da5b3fc8 | 8205 | + " movw $0x05EB, 1b\n" /* jmp on 5 bytes */ |
50425a20 | 8206 | + |
da5b3fc8 | 8207 | +#ifdef CONFIG_PAX_KERNEXEC |
8208 | + " movl %0, %%cr0\n" | |
8209 | +#endif | |
50425a20 | 8210 | + |
da5b3fc8 | 8211 | " jmp 2b\n" |
8212 | ".previous\n" | |
4dee9bd5 | 8213 | _ASM_EXTABLE(1b,3b) |
da5b3fc8 | 8214 | - : : "r" (from), "r" (to) : "memory"); |
8215 | + : "=&r" (cr0) : "r" (from), "r" (to) : "memory", "ax"); | |
8216 | from+=64; | |
8217 | to+=64; | |
8218 | } | |
4dee9bd5 | 8219 | @@ -285,50 +343,78 @@ static void fast_clear_page(void *page) |
da5b3fc8 | 8220 | static void fast_copy_page(void *to, void *from) |
8221 | { | |
8222 | int i; | |
8223 | - | |
8224 | - | |
8225 | + unsigned long cr0; | |
50425a20 | 8226 | + |
da5b3fc8 | 8227 | kernel_fpu_begin(); |
8228 | ||
8229 | __asm__ __volatile__ ( | |
8230 | - "1: prefetch (%0)\n" | |
8231 | - " prefetch 64(%0)\n" | |
8232 | - " prefetch 128(%0)\n" | |
8233 | - " prefetch 192(%0)\n" | |
8234 | - " prefetch 256(%0)\n" | |
8235 | + "1: prefetch (%1)\n" | |
8236 | + " prefetch 64(%1)\n" | |
8237 | + " prefetch 128(%1)\n" | |
8238 | + " prefetch 192(%1)\n" | |
8239 | + " prefetch 256(%1)\n" | |
8240 | "2: \n" | |
8241 | ".section .fixup, \"ax\"\n" | |
8242 | - "3: movw $0x1AEB, 1b\n" /* jmp on 26 bytes */ | |
8243 | + "3: \n" | |
50425a20 | 8244 | + |
da5b3fc8 | 8245 | +#ifdef CONFIG_PAX_KERNEXEC |
8246 | + " movl %%cr0, %0\n" | |
8247 | + " movl %0, %%eax\n" | |
8248 | + " andl $0xFFFEFFFF, %%eax\n" | |
8249 | + " movl %%eax, %%cr0\n" | |
8250 | +#endif | |
50425a20 | 8251 | + |
da5b3fc8 | 8252 | + " movw $0x1AEB, 1b\n" /* jmp on 26 bytes */ |
50425a20 | 8253 | + |
da5b3fc8 | 8254 | +#ifdef CONFIG_PAX_KERNEXEC |
8255 | + " movl %0, %%cr0\n" | |
8256 | +#endif | |
50425a20 | 8257 | + |
da5b3fc8 | 8258 | " jmp 2b\n" |
8259 | ".previous\n" | |
4dee9bd5 | 8260 | _ASM_EXTABLE(1b,3b) |
da5b3fc8 | 8261 | - : : "r" (from) ); |
8262 | + : "=&r" (cr0) : "r" (from) : "ax"); | |
8263 | ||
8264 | for(i=0; i<4096/64; i++) | |
8265 | { | |
8266 | __asm__ __volatile__ ( | |
8267 | - "1: prefetch 320(%0)\n" | |
8268 | - "2: movq (%0), %%mm0\n" | |
8269 | - " movq 8(%0), %%mm1\n" | |
8270 | - " movq 16(%0), %%mm2\n" | |
8271 | - " movq 24(%0), %%mm3\n" | |
8272 | - " movq %%mm0, (%1)\n" | |
8273 | - " movq %%mm1, 8(%1)\n" | |
8274 | - " movq %%mm2, 16(%1)\n" | |
8275 | - " movq %%mm3, 24(%1)\n" | |
8276 | - " movq 32(%0), %%mm0\n" | |
8277 | - " movq 40(%0), %%mm1\n" | |
8278 | - " movq 48(%0), %%mm2\n" | |
8279 | - " movq 56(%0), %%mm3\n" | |
8280 | - " movq %%mm0, 32(%1)\n" | |
8281 | - " movq %%mm1, 40(%1)\n" | |
8282 | - " movq %%mm2, 48(%1)\n" | |
8283 | - " movq %%mm3, 56(%1)\n" | |
8284 | + "1: prefetch 320(%1)\n" | |
8285 | + "2: movq (%1), %%mm0\n" | |
8286 | + " movq 8(%1), %%mm1\n" | |
8287 | + " movq 16(%1), %%mm2\n" | |
8288 | + " movq 24(%1), %%mm3\n" | |
8289 | + " movq %%mm0, (%2)\n" | |
8290 | + " movq %%mm1, 8(%2)\n" | |
8291 | + " movq %%mm2, 16(%2)\n" | |
8292 | + " movq %%mm3, 24(%2)\n" | |
8293 | + " movq 32(%1), %%mm0\n" | |
8294 | + " movq 40(%1), %%mm1\n" | |
8295 | + " movq 48(%1), %%mm2\n" | |
8296 | + " movq 56(%1), %%mm3\n" | |
8297 | + " movq %%mm0, 32(%2)\n" | |
8298 | + " movq %%mm1, 40(%2)\n" | |
8299 | + " movq %%mm2, 48(%2)\n" | |
8300 | + " movq %%mm3, 56(%2)\n" | |
8301 | ".section .fixup, \"ax\"\n" | |
8302 | - "3: movw $0x05EB, 1b\n" /* jmp on 5 bytes */ | |
8303 | + "3:\n" | |
50425a20 | 8304 | + |
da5b3fc8 | 8305 | +#ifdef CONFIG_PAX_KERNEXEC |
8306 | + " movl %%cr0, %0\n" | |
8307 | + " movl %0, %%eax\n" | |
8308 | + " andl $0xFFFEFFFF, %%eax\n" | |
8309 | + " movl %%eax, %%cr0\n" | |
8310 | +#endif | |
50425a20 | 8311 | + |
da5b3fc8 | 8312 | + " movw $0x05EB, 1b\n" /* jmp on 5 bytes */ |
50425a20 | 8313 | + |
da5b3fc8 | 8314 | +#ifdef CONFIG_PAX_KERNEXEC |
8315 | + " movl %0, %%cr0\n" | |
50425a20 | 8316 | +#endif |
8317 | + | |
da5b3fc8 | 8318 | " jmp 2b\n" |
8319 | ".previous\n" | |
4dee9bd5 | 8320 | _ASM_EXTABLE(1b,3b) |
da5b3fc8 | 8321 | - : : "r" (from), "r" (to) : "memory"); |
8322 | + : "=&r" (cr0) : "r" (from), "r" (to) : "memory", "ax"); | |
8323 | from+=64; | |
8324 | to+=64; | |
8325 | } | |
4dee9bd5 | 8326 | diff -urNp linux-2.6.25.4/arch/x86/lib/putuser_32.S linux-2.6.25.4/arch/x86/lib/putuser_32.S |
8327 | --- linux-2.6.25.4/arch/x86/lib/putuser_32.S 2008-05-15 11:00:12.000000000 -0400 | |
8328 | +++ linux-2.6.25.4/arch/x86/lib/putuser_32.S 2008-05-18 13:33:15.000000000 -0400 | |
da5b3fc8 | 8329 | @@ -11,7 +11,7 @@ |
8330 | #include <linux/linkage.h> | |
8331 | #include <asm/dwarf2.h> | |
8332 | #include <asm/thread_info.h> | |
8333 | - | |
8334 | +#include <asm/segment.h> | |
8335 | ||
8336 | /* | |
8337 | * __put_user_X | |
8338 | @@ -41,7 +41,11 @@ ENTRY(__put_user_1) | |
8339 | ENTER | |
8340 | cmpl TI_addr_limit(%ebx),%ecx | |
8341 | jae bad_put_user | |
8342 | + pushl $(__USER_DS) | |
8343 | + popl %ds | |
8344 | 1: movb %al,(%ecx) | |
8345 | + pushl %ss | |
8346 | + popl %ds | |
8347 | xorl %eax,%eax | |
8348 | EXIT | |
8349 | ENDPROC(__put_user_1) | |
8350 | @@ -52,7 +56,11 @@ ENTRY(__put_user_2) | |
8351 | subl $1,%ebx | |
8352 | cmpl %ebx,%ecx | |
8353 | jae bad_put_user | |
8354 | + pushl $(__USER_DS) | |
8355 | + popl %ds | |
8356 | 2: movw %ax,(%ecx) | |
8357 | + pushl %ss | |
8358 | + popl %ds | |
8359 | xorl %eax,%eax | |
8360 | EXIT | |
8361 | ENDPROC(__put_user_2) | |
8362 | @@ -63,7 +71,11 @@ ENTRY(__put_user_4) | |
8363 | subl $3,%ebx | |
8364 | cmpl %ebx,%ecx | |
8365 | jae bad_put_user | |
8366 | + pushl $(__USER_DS) | |
8367 | + popl %ds | |
8368 | 3: movl %eax,(%ecx) | |
8369 | + pushl %ss | |
8370 | + popl %ds | |
8371 | xorl %eax,%eax | |
8372 | EXIT | |
8373 | ENDPROC(__put_user_4) | |
8374 | @@ -74,8 +86,12 @@ ENTRY(__put_user_8) | |
8375 | subl $7,%ebx | |
8376 | cmpl %ebx,%ecx | |
8377 | jae bad_put_user | |
8378 | + pushl $(__USER_DS) | |
8379 | + popl %ds | |
8380 | 4: movl %eax,(%ecx) | |
8381 | 5: movl %edx,4(%ecx) | |
8382 | + pushl %ss | |
8383 | + popl %ds | |
8384 | xorl %eax,%eax | |
8385 | EXIT | |
8386 | ENDPROC(__put_user_8) | |
8387 | @@ -85,6 +101,10 @@ bad_put_user: | |
8388 | CFI_DEF_CFA esp, 2*4 | |
8389 | CFI_OFFSET eip, -1*4 | |
8390 | CFI_OFFSET ebx, -2*4 | |
8391 | + pushl %ss | |
8392 | + CFI_ADJUST_CFA_OFFSET 4 | |
8393 | + popl %ds | |
8394 | + CFI_ADJUST_CFA_OFFSET -4 | |
8395 | movl $-14,%eax | |
8396 | EXIT | |
8397 | END(bad_put_user) | |
4dee9bd5 | 8398 | diff -urNp linux-2.6.25.4/arch/x86/lib/usercopy_32.c linux-2.6.25.4/arch/x86/lib/usercopy_32.c |
8399 | --- linux-2.6.25.4/arch/x86/lib/usercopy_32.c 2008-05-15 11:00:12.000000000 -0400 | |
8400 | +++ linux-2.6.25.4/arch/x86/lib/usercopy_32.c 2008-05-18 13:33:15.000000000 -0400 | |
8401 | @@ -29,31 +29,38 @@ static inline int __movsl_is_ok(unsigned | |
da5b3fc8 | 8402 | * Copy a null terminated string from userspace. |
8403 | */ | |
8404 | ||
8405 | -#define __do_strncpy_from_user(dst,src,count,res) \ | |
8406 | -do { \ | |
8407 | - int __d0, __d1, __d2; \ | |
8408 | - might_sleep(); \ | |
8409 | - __asm__ __volatile__( \ | |
8410 | - " testl %1,%1\n" \ | |
8411 | - " jz 2f\n" \ | |
8412 | - "0: lodsb\n" \ | |
8413 | - " stosb\n" \ | |
8414 | - " testb %%al,%%al\n" \ | |
8415 | - " jz 1f\n" \ | |
8416 | - " decl %1\n" \ | |
8417 | - " jnz 0b\n" \ | |
8418 | - "1: subl %1,%0\n" \ | |
8419 | - "2:\n" \ | |
8420 | - ".section .fixup,\"ax\"\n" \ | |
8421 | - "3: movl %5,%0\n" \ | |
8422 | - " jmp 2b\n" \ | |
8423 | - ".previous\n" \ | |
4dee9bd5 | 8424 | - _ASM_EXTABLE(0b,3b) \ |
da5b3fc8 | 8425 | - : "=d"(res), "=c"(count), "=&a" (__d0), "=&S" (__d1), \ |
8426 | - "=&D" (__d2) \ | |
8427 | - : "i"(-EFAULT), "0"(count), "1"(count), "3"(src), "4"(dst) \ | |
8428 | - : "memory"); \ | |
8429 | -} while (0) | |
8430 | +static long __do_strncpy_from_user(char *dst, const char __user *src, long count) | |
8431 | +{ | |
8432 | + int __d0, __d1, __d2; | |
8433 | + long res = -EFAULT; | |
8434 | + | |
8435 | + might_sleep(); | |
8436 | + __asm__ __volatile__( | |
8437 | + " movw %w10,%%ds\n" | |
8438 | + " testl %1,%1\n" | |
8439 | + " jz 2f\n" | |
8440 | + "0: lodsb\n" | |
8441 | + " stosb\n" | |
8442 | + " testb %%al,%%al\n" | |
8443 | + " jz 1f\n" | |
8444 | + " decl %1\n" | |
8445 | + " jnz 0b\n" | |
8446 | + "1: subl %1,%0\n" | |
8447 | + "2:\n" | |
8448 | + " pushl %%ss\n" | |
8449 | + " popl %%ds\n" | |
8450 | + ".section .fixup,\"ax\"\n" | |
8451 | + "3: movl %5,%0\n" | |
8452 | + " jmp 2b\n" | |
8453 | + ".previous\n" | |
4dee9bd5 | 8454 | + _ASM_EXTABLE(0b,3b) |
da5b3fc8 | 8455 | + : "=d"(res), "=c"(count), "=&a" (__d0), "=&S" (__d1), |
8456 | + "=&D" (__d2) | |
8457 | + : "i"(-EFAULT), "0"(count), "1"(count), "3"(src), "4"(dst), | |
8458 | + "r"(__USER_DS) | |
8459 | + : "memory"); | |
8460 | + return res; | |
50425a20 | 8461 | +} |
da5b3fc8 | 8462 | |
8463 | /** | |
8464 | * __strncpy_from_user: - Copy a NUL terminated string from userspace, with less checking. | |
4dee9bd5 | 8465 | @@ -78,9 +85,7 @@ do { \ |
da5b3fc8 | 8466 | long |
8467 | __strncpy_from_user(char *dst, const char __user *src, long count) | |
8468 | { | |
8469 | - long res; | |
8470 | - __do_strncpy_from_user(dst, src, count, res); | |
8471 | - return res; | |
8472 | + return __do_strncpy_from_user(dst, src, count); | |
8473 | } | |
8474 | EXPORT_SYMBOL(__strncpy_from_user); | |
8475 | ||
4dee9bd5 | 8476 | @@ -107,7 +112,7 @@ strncpy_from_user(char *dst, const char |
da5b3fc8 | 8477 | { |
8478 | long res = -EFAULT; | |
8479 | if (access_ok(VERIFY_READ, src, 1)) | |
8480 | - __do_strncpy_from_user(dst, src, count, res); | |
8481 | + res = __do_strncpy_from_user(dst, src, count); | |
8482 | return res; | |
8483 | } | |
8484 | EXPORT_SYMBOL(strncpy_from_user); | |
4dee9bd5 | 8485 | @@ -116,24 +121,30 @@ EXPORT_SYMBOL(strncpy_from_user); |
da5b3fc8 | 8486 | * Zero Userspace |
8487 | */ | |
8488 | ||
8489 | -#define __do_clear_user(addr,size) \ | |
8490 | -do { \ | |
8491 | - int __d0; \ | |
8492 | - might_sleep(); \ | |
8493 | - __asm__ __volatile__( \ | |
8494 | - "0: rep; stosl\n" \ | |
8495 | - " movl %2,%0\n" \ | |
8496 | - "1: rep; stosb\n" \ | |
8497 | - "2:\n" \ | |
8498 | - ".section .fixup,\"ax\"\n" \ | |
8499 | - "3: lea 0(%2,%0,4),%0\n" \ | |
8500 | - " jmp 2b\n" \ | |
8501 | - ".previous\n" \ | |
4dee9bd5 | 8502 | - _ASM_EXTABLE(0b,3b) \ |
8503 | - _ASM_EXTABLE(1b,2b) \ | |
da5b3fc8 | 8504 | - : "=&c"(size), "=&D" (__d0) \ |
8505 | - : "r"(size & 3), "0"(size / 4), "1"(addr), "a"(0)); \ | |
8506 | -} while (0) | |
8507 | +static unsigned long __do_clear_user(void __user *addr, unsigned long size) | |
50425a20 | 8508 | +{ |
da5b3fc8 | 8509 | + int __d0; |
50425a20 | 8510 | + |
da5b3fc8 | 8511 | + might_sleep(); |
8512 | + __asm__ __volatile__( | |
8513 | + " movw %w6,%%es\n" | |
8514 | + "0: rep; stosl\n" | |
8515 | + " movl %2,%0\n" | |
8516 | + "1: rep; stosb\n" | |
8517 | + "2:\n" | |
8518 | + " pushl %%ss\n" | |
8519 | + " popl %%es\n" | |
8520 | + ".section .fixup,\"ax\"\n" | |
8521 | + "3: lea 0(%2,%0,4),%0\n" | |
8522 | + " jmp 2b\n" | |
8523 | + ".previous\n" | |
4dee9bd5 | 8524 | + _ASM_EXTABLE(0b,3b) |
8525 | + _ASM_EXTABLE(1b,2b) | |
da5b3fc8 | 8526 | + : "=&c"(size), "=&D" (__d0) |
8527 | + : "r"(size & 3), "0"(size / 4), "1"(addr), "a"(0), | |
8528 | + "r"(__USER_DS)); | |
8529 | + return size; | |
8530 | +} | |
8531 | ||
8532 | /** | |
8533 | * clear_user: - Zero a block of memory in user space. | |
4dee9bd5 | 8534 | @@ -150,7 +161,7 @@ clear_user(void __user *to, unsigned lon |
da5b3fc8 | 8535 | { |
8536 | might_sleep(); | |
8537 | if (access_ok(VERIFY_WRITE, to, n)) | |
8538 | - __do_clear_user(to, n); | |
8539 | + n = __do_clear_user(to, n); | |
8540 | return n; | |
8541 | } | |
8542 | EXPORT_SYMBOL(clear_user); | |
4dee9bd5 | 8543 | @@ -169,8 +180,7 @@ EXPORT_SYMBOL(clear_user); |
da5b3fc8 | 8544 | unsigned long |
8545 | __clear_user(void __user *to, unsigned long n) | |
8546 | { | |
8547 | - __do_clear_user(to, n); | |
8548 | - return n; | |
8549 | + return __do_clear_user(to, n); | |
8550 | } | |
8551 | EXPORT_SYMBOL(__clear_user); | |
8552 | ||
4dee9bd5 | 8553 | @@ -193,14 +203,17 @@ long strnlen_user(const char __user *s, |
da5b3fc8 | 8554 | might_sleep(); |
8555 | ||
8556 | __asm__ __volatile__( | |
8557 | + " movw %w8,%%es\n" | |
8558 | " testl %0, %0\n" | |
8559 | " jz 3f\n" | |
8560 | - " andl %0,%%ecx\n" | |
8561 | + " movl %0,%%ecx\n" | |
8562 | "0: repne; scasb\n" | |
8563 | " setne %%al\n" | |
8564 | " subl %%ecx,%0\n" | |
8565 | " addl %0,%%eax\n" | |
8566 | "1:\n" | |
8567 | + " pushl %%ss\n" | |
8568 | + " popl %%es\n" | |
8569 | ".section .fixup,\"ax\"\n" | |
8570 | "2: xorl %%eax,%%eax\n" | |
8571 | " jmp 1b\n" | |
4dee9bd5 | 8572 | @@ -212,7 +225,7 @@ long strnlen_user(const char __user *s, |
da5b3fc8 | 8573 | " .long 0b,2b\n" |
8574 | ".previous" | |
8575 | :"=r" (n), "=D" (s), "=a" (res), "=c" (tmp) | |
8576 | - :"0" (n), "1" (s), "2" (0), "3" (mask) | |
8577 | + :"0" (n), "1" (s), "2" (0), "3" (mask), "r" (__USER_DS) | |
8578 | :"cc"); | |
8579 | return res & mask; | |
8580 | } | |
4dee9bd5 | 8581 | @@ -220,10 +233,121 @@ EXPORT_SYMBOL(strnlen_user); |
da5b3fc8 | 8582 | |
8583 | #ifdef CONFIG_X86_INTEL_USERCOPY | |
8584 | static unsigned long | |
8585 | -__copy_user_intel(void __user *to, const void *from, unsigned long size) | |
8586 | +__generic_copy_to_user_intel(void __user *to, const void *from, unsigned long size) | |
8587 | +{ | |
8588 | + int d0, d1; | |
8589 | + __asm__ __volatile__( | |
8590 | + " movw %w6, %%es\n" | |
8591 | + " .align 2,0x90\n" | |
8592 | + "1: movl 32(%4), %%eax\n" | |
8593 | + " cmpl $67, %0\n" | |
8594 | + " jbe 3f\n" | |
8595 | + "2: movl 64(%4), %%eax\n" | |
8596 | + " .align 2,0x90\n" | |
8597 | + "3: movl 0(%4), %%eax\n" | |
8598 | + "4: movl 4(%4), %%edx\n" | |
8599 | + "5: movl %%eax, %%es:0(%3)\n" | |
8600 | + "6: movl %%edx, %%es:4(%3)\n" | |
8601 | + "7: movl 8(%4), %%eax\n" | |
8602 | + "8: movl 12(%4),%%edx\n" | |
8603 | + "9: movl %%eax, %%es:8(%3)\n" | |
8604 | + "10: movl %%edx, %%es:12(%3)\n" | |
8605 | + "11: movl 16(%4), %%eax\n" | |
8606 | + "12: movl 20(%4), %%edx\n" | |
8607 | + "13: movl %%eax, %%es:16(%3)\n" | |
8608 | + "14: movl %%edx, %%es:20(%3)\n" | |
8609 | + "15: movl 24(%4), %%eax\n" | |
8610 | + "16: movl 28(%4), %%edx\n" | |
8611 | + "17: movl %%eax, %%es:24(%3)\n" | |
8612 | + "18: movl %%edx, %%es:28(%3)\n" | |
8613 | + "19: movl 32(%4), %%eax\n" | |
8614 | + "20: movl 36(%4), %%edx\n" | |
8615 | + "21: movl %%eax, %%es:32(%3)\n" | |
8616 | + "22: movl %%edx, %%es:36(%3)\n" | |
8617 | + "23: movl 40(%4), %%eax\n" | |
8618 | + "24: movl 44(%4), %%edx\n" | |
8619 | + "25: movl %%eax, %%es:40(%3)\n" | |
8620 | + "26: movl %%edx, %%es:44(%3)\n" | |
8621 | + "27: movl 48(%4), %%eax\n" | |
8622 | + "28: movl 52(%4), %%edx\n" | |
8623 | + "29: movl %%eax, %%es:48(%3)\n" | |
8624 | + "30: movl %%edx, %%es:52(%3)\n" | |
8625 | + "31: movl 56(%4), %%eax\n" | |
8626 | + "32: movl 60(%4), %%edx\n" | |
8627 | + "33: movl %%eax, %%es:56(%3)\n" | |
8628 | + "34: movl %%edx, %%es:60(%3)\n" | |
8629 | + " addl $-64, %0\n" | |
8630 | + " addl $64, %4\n" | |
8631 | + " addl $64, %3\n" | |
8632 | + " cmpl $63, %0\n" | |
8633 | + " ja 1b\n" | |
8634 | + "35: movl %0, %%eax\n" | |
8635 | + " shrl $2, %0\n" | |
8636 | + " andl $3, %%eax\n" | |
8637 | + " cld\n" | |
8638 | + "99: rep; movsl\n" | |
8639 | + "36: movl %%eax, %0\n" | |
8640 | + "37: rep; movsb\n" | |
8641 | + "100:\n" | |
8642 | + " pushl %%ss\n" | |
8643 | + " popl %%es\n" | |
8644 | + ".section .fixup,\"ax\"\n" | |
8645 | + "101: lea 0(%%eax,%0,4),%0\n" | |
8646 | + " jmp 100b\n" | |
8647 | + ".previous\n" | |
8648 | + ".section __ex_table,\"a\"\n" | |
8649 | + " .align 4\n" | |
8650 | + " .long 1b,100b\n" | |
8651 | + " .long 2b,100b\n" | |
8652 | + " .long 3b,100b\n" | |
8653 | + " .long 4b,100b\n" | |
8654 | + " .long 5b,100b\n" | |
8655 | + " .long 6b,100b\n" | |
8656 | + " .long 7b,100b\n" | |
8657 | + " .long 8b,100b\n" | |
8658 | + " .long 9b,100b\n" | |
8659 | + " .long 10b,100b\n" | |
8660 | + " .long 11b,100b\n" | |
8661 | + " .long 12b,100b\n" | |
8662 | + " .long 13b,100b\n" | |
8663 | + " .long 14b,100b\n" | |
8664 | + " .long 15b,100b\n" | |
8665 | + " .long 16b,100b\n" | |
8666 | + " .long 17b,100b\n" | |
8667 | + " .long 18b,100b\n" | |
8668 | + " .long 19b,100b\n" | |
8669 | + " .long 20b,100b\n" | |
8670 | + " .long 21b,100b\n" | |
8671 | + " .long 22b,100b\n" | |
8672 | + " .long 23b,100b\n" | |
8673 | + " .long 24b,100b\n" | |
8674 | + " .long 25b,100b\n" | |
8675 | + " .long 26b,100b\n" | |
8676 | + " .long 27b,100b\n" | |
8677 | + " .long 28b,100b\n" | |
8678 | + " .long 29b,100b\n" | |
8679 | + " .long 30b,100b\n" | |
8680 | + " .long 31b,100b\n" | |
8681 | + " .long 32b,100b\n" | |
8682 | + " .long 33b,100b\n" | |
8683 | + " .long 34b,100b\n" | |
8684 | + " .long 35b,100b\n" | |
8685 | + " .long 36b,100b\n" | |
8686 | + " .long 37b,100b\n" | |
8687 | + " .long 99b,101b\n" | |
8688 | + ".previous" | |
8689 | + : "=&c"(size), "=&D" (d0), "=&S" (d1) | |
8690 | + : "1"(to), "2"(from), "0"(size), "r"(__USER_DS) | |
8691 | + : "eax", "edx", "memory"); | |
8692 | + return size; | |
50425a20 | 8693 | +} |
50425a20 | 8694 | + |
da5b3fc8 | 8695 | +static unsigned long |
8696 | +__generic_copy_from_user_intel(void *to, const void __user *from, unsigned long size) | |
8697 | { | |
8698 | int d0, d1; | |
8699 | __asm__ __volatile__( | |
8700 | + " movw %w6, %%ds\n" | |
8701 | " .align 2,0x90\n" | |
8702 | "1: movl 32(%4), %%eax\n" | |
8703 | " cmpl $67, %0\n" | |
4dee9bd5 | 8704 | @@ -232,36 +356,36 @@ __copy_user_intel(void __user *to, const |
da5b3fc8 | 8705 | " .align 2,0x90\n" |
8706 | "3: movl 0(%4), %%eax\n" | |
8707 | "4: movl 4(%4), %%edx\n" | |
8708 | - "5: movl %%eax, 0(%3)\n" | |
8709 | - "6: movl %%edx, 4(%3)\n" | |
8710 | + "5: movl %%eax, %%es:0(%3)\n" | |
8711 | + "6: movl %%edx, %%es:4(%3)\n" | |
8712 | "7: movl 8(%4), %%eax\n" | |
8713 | "8: movl 12(%4),%%edx\n" | |
8714 | - "9: movl %%eax, 8(%3)\n" | |
8715 | - "10: movl %%edx, 12(%3)\n" | |
8716 | + "9: movl %%eax, %%es:8(%3)\n" | |
8717 | + "10: movl %%edx, %%es:12(%3)\n" | |
8718 | "11: movl 16(%4), %%eax\n" | |
8719 | "12: movl 20(%4), %%edx\n" | |
8720 | - "13: movl %%eax, 16(%3)\n" | |
8721 | - "14: movl %%edx, 20(%3)\n" | |
8722 | + "13: movl %%eax, %%es:16(%3)\n" | |
8723 | + "14: movl %%edx, %%es:20(%3)\n" | |
8724 | "15: movl 24(%4), %%eax\n" | |
8725 | "16: movl 28(%4), %%edx\n" | |
8726 | - "17: movl %%eax, 24(%3)\n" | |
8727 | - "18: movl %%edx, 28(%3)\n" | |
8728 | + "17: movl %%eax, %%es:24(%3)\n" | |
8729 | + "18: movl %%edx, %%es:28(%3)\n" | |
8730 | "19: movl 32(%4), %%eax\n" | |
8731 | "20: movl 36(%4), %%edx\n" | |
8732 | - "21: movl %%eax, 32(%3)\n" | |
8733 | - "22: movl %%edx, 36(%3)\n" | |
8734 | + "21: movl %%eax, %%es:32(%3)\n" | |
8735 | + "22: movl %%edx, %%es:36(%3)\n" | |
8736 | "23: movl 40(%4), %%eax\n" | |
8737 | "24: movl 44(%4), %%edx\n" | |
8738 | - "25: movl %%eax, 40(%3)\n" | |
8739 | - "26: movl %%edx, 44(%3)\n" | |
8740 | + "25: movl %%eax, %%es:40(%3)\n" | |
8741 | + "26: movl %%edx, %%es:44(%3)\n" | |
8742 | "27: movl 48(%4), %%eax\n" | |
8743 | "28: movl 52(%4), %%edx\n" | |
8744 | - "29: movl %%eax, 48(%3)\n" | |
8745 | - "30: movl %%edx, 52(%3)\n" | |
8746 | + "29: movl %%eax, %%es:48(%3)\n" | |
8747 | + "30: movl %%edx, %%es:52(%3)\n" | |
8748 | "31: movl 56(%4), %%eax\n" | |
8749 | "32: movl 60(%4), %%edx\n" | |
8750 | - "33: movl %%eax, 56(%3)\n" | |
8751 | - "34: movl %%edx, 60(%3)\n" | |
8752 | + "33: movl %%eax, %%es:56(%3)\n" | |
8753 | + "34: movl %%edx, %%es:60(%3)\n" | |
8754 | " addl $-64, %0\n" | |
8755 | " addl $64, %4\n" | |
8756 | " addl $64, %3\n" | |
4dee9bd5 | 8757 | @@ -275,6 +399,8 @@ __copy_user_intel(void __user *to, const |
da5b3fc8 | 8758 | "36: movl %%eax, %0\n" |
8759 | "37: rep; movsb\n" | |
8760 | "100:\n" | |
8761 | + " pushl %%ss\n" | |
8762 | + " popl %%ds\n" | |
8763 | ".section .fixup,\"ax\"\n" | |
8764 | "101: lea 0(%%eax,%0,4),%0\n" | |
8765 | " jmp 100b\n" | |
4dee9bd5 | 8766 | @@ -321,7 +447,7 @@ __copy_user_intel(void __user *to, const |
da5b3fc8 | 8767 | " .long 99b,101b\n" |
8768 | ".previous" | |
8769 | : "=&c"(size), "=&D" (d0), "=&S" (d1) | |
8770 | - : "1"(to), "2"(from), "0"(size) | |
8771 | + : "1"(to), "2"(from), "0"(size), "r"(__USER_DS) | |
8772 | : "eax", "edx", "memory"); | |
8773 | return size; | |
8774 | } | |
4dee9bd5 | 8775 | @@ -331,6 +457,7 @@ __copy_user_zeroing_intel(void *to, cons |
da5b3fc8 | 8776 | { |
8777 | int d0, d1; | |
8778 | __asm__ __volatile__( | |
8779 | + " movw %w6, %%ds\n" | |
8780 | " .align 2,0x90\n" | |
8781 | "0: movl 32(%4), %%eax\n" | |
8782 | " cmpl $67, %0\n" | |
4dee9bd5 | 8783 | @@ -339,36 +466,36 @@ __copy_user_zeroing_intel(void *to, cons |
da5b3fc8 | 8784 | " .align 2,0x90\n" |
8785 | "2: movl 0(%4), %%eax\n" | |
8786 | "21: movl 4(%4), %%edx\n" | |
8787 | - " movl %%eax, 0(%3)\n" | |
8788 | - " movl %%edx, 4(%3)\n" | |
8789 | + " movl %%eax, %%es:0(%3)\n" | |
8790 | + " movl %%edx, %%es:4(%3)\n" | |
8791 | "3: movl 8(%4), %%eax\n" | |
8792 | "31: movl 12(%4),%%edx\n" | |
8793 | - " movl %%eax, 8(%3)\n" | |
8794 | - " movl %%edx, 12(%3)\n" | |
8795 | + " movl %%eax, %%es:8(%3)\n" | |
8796 | + " movl %%edx, %%es:12(%3)\n" | |
8797 | "4: movl 16(%4), %%eax\n" | |
8798 | "41: movl 20(%4), %%edx\n" | |
8799 | - " movl %%eax, 16(%3)\n" | |
8800 | - " movl %%edx, 20(%3)\n" | |
8801 | + " movl %%eax, %%es:16(%3)\n" | |
8802 | + " movl %%edx, %%es:20(%3)\n" | |
8803 | "10: movl 24(%4), %%eax\n" | |
8804 | "51: movl 28(%4), %%edx\n" | |
8805 | - " movl %%eax, 24(%3)\n" | |
8806 | - " movl %%edx, 28(%3)\n" | |
8807 | + " movl %%eax, %%es:24(%3)\n" | |
8808 | + " movl %%edx, %%es:28(%3)\n" | |
8809 | "11: movl 32(%4), %%eax\n" | |
8810 | "61: movl 36(%4), %%edx\n" | |
8811 | - " movl %%eax, 32(%3)\n" | |
8812 | - " movl %%edx, 36(%3)\n" | |
8813 | + " movl %%eax, %%es:32(%3)\n" | |
8814 | + " movl %%edx, %%es:36(%3)\n" | |
8815 | "12: movl 40(%4), %%eax\n" | |
8816 | "71: movl 44(%4), %%edx\n" | |
8817 | - " movl %%eax, 40(%3)\n" | |
8818 | - " movl %%edx, 44(%3)\n" | |
8819 | + " movl %%eax, %%es:40(%3)\n" | |
8820 | + " movl %%edx, %%es:44(%3)\n" | |
8821 | "13: movl 48(%4), %%eax\n" | |
8822 | "81: movl 52(%4), %%edx\n" | |
8823 | - " movl %%eax, 48(%3)\n" | |
8824 | - " movl %%edx, 52(%3)\n" | |
8825 | + " movl %%eax, %%es:48(%3)\n" | |
8826 | + " movl %%edx, %%es:52(%3)\n" | |
8827 | "14: movl 56(%4), %%eax\n" | |
8828 | "91: movl 60(%4), %%edx\n" | |
8829 | - " movl %%eax, 56(%3)\n" | |
8830 | - " movl %%edx, 60(%3)\n" | |
8831 | + " movl %%eax, %%es:56(%3)\n" | |
8832 | + " movl %%edx, %%es:60(%3)\n" | |
8833 | " addl $-64, %0\n" | |
8834 | " addl $64, %4\n" | |
8835 | " addl $64, %3\n" | |
4dee9bd5 | 8836 | @@ -382,6 +509,8 @@ __copy_user_zeroing_intel(void *to, cons |
da5b3fc8 | 8837 | " movl %%eax,%0\n" |
8838 | "7: rep; movsb\n" | |
8839 | "8:\n" | |
8840 | + " pushl %%ss\n" | |
8841 | + " popl %%ds\n" | |
8842 | ".section .fixup,\"ax\"\n" | |
8843 | "9: lea 0(%%eax,%0,4),%0\n" | |
8844 | "16: pushl %0\n" | |
4dee9bd5 | 8845 | @@ -416,7 +545,7 @@ __copy_user_zeroing_intel(void *to, cons |
da5b3fc8 | 8846 | " .long 7b,16b\n" |
8847 | ".previous" | |
8848 | : "=&c"(size), "=&D" (d0), "=&S" (d1) | |
8849 | - : "1"(to), "2"(from), "0"(size) | |
8850 | + : "1"(to), "2"(from), "0"(size), "r"(__USER_DS) | |
8851 | : "eax", "edx", "memory"); | |
8852 | return size; | |
8853 | } | |
4dee9bd5 | 8854 | @@ -432,6 +561,7 @@ static unsigned long __copy_user_zeroing |
da5b3fc8 | 8855 | int d0, d1; |
8856 | ||
8857 | __asm__ __volatile__( | |
8858 | + " movw %w6, %%ds\n" | |
8859 | " .align 2,0x90\n" | |
8860 | "0: movl 32(%4), %%eax\n" | |
8861 | " cmpl $67, %0\n" | |
4dee9bd5 | 8862 | @@ -440,36 +570,36 @@ static unsigned long __copy_user_zeroing |
da5b3fc8 | 8863 | " .align 2,0x90\n" |
8864 | "2: movl 0(%4), %%eax\n" | |
8865 | "21: movl 4(%4), %%edx\n" | |
8866 | - " movnti %%eax, 0(%3)\n" | |
8867 | - " movnti %%edx, 4(%3)\n" | |
8868 | + " movnti %%eax, %%es:0(%3)\n" | |
8869 | + " movnti %%edx, %%es:4(%3)\n" | |
8870 | "3: movl 8(%4), %%eax\n" | |
8871 | "31: movl 12(%4),%%edx\n" | |
8872 | - " movnti %%eax, 8(%3)\n" | |
8873 | - " movnti %%edx, 12(%3)\n" | |
8874 | + " movnti %%eax, %%es:8(%3)\n" | |
8875 | + " movnti %%edx, %%es:12(%3)\n" | |
8876 | "4: movl 16(%4), %%eax\n" | |
8877 | "41: movl 20(%4), %%edx\n" | |
8878 | - " movnti %%eax, 16(%3)\n" | |
8879 | - " movnti %%edx, 20(%3)\n" | |
8880 | + " movnti %%eax, %%es:16(%3)\n" | |
8881 | + " movnti %%edx, %%es:20(%3)\n" | |
8882 | "10: movl 24(%4), %%eax\n" | |
8883 | "51: movl 28(%4), %%edx\n" | |
8884 | - " movnti %%eax, 24(%3)\n" | |
8885 | - " movnti %%edx, 28(%3)\n" | |
8886 | + " movnti %%eax, %%es:24(%3)\n" | |
8887 | + " movnti %%edx, %%es:28(%3)\n" | |
8888 | "11: movl 32(%4), %%eax\n" | |
8889 | "61: movl 36(%4), %%edx\n" | |
8890 | - " movnti %%eax, 32(%3)\n" | |
8891 | - " movnti %%edx, 36(%3)\n" | |
8892 | + " movnti %%eax, %%es:32(%3)\n" | |
8893 | + " movnti %%edx, %%es:36(%3)\n" | |
8894 | "12: movl 40(%4), %%eax\n" | |
8895 | "71: movl 44(%4), %%edx\n" | |
8896 | - " movnti %%eax, 40(%3)\n" | |
8897 | - " movnti %%edx, 44(%3)\n" | |
8898 | + " movnti %%eax, %%es:40(%3)\n" | |
8899 | + " movnti %%edx, %%es:44(%3)\n" | |
8900 | "13: movl 48(%4), %%eax\n" | |
8901 | "81: movl 52(%4), %%edx\n" | |
8902 | - " movnti %%eax, 48(%3)\n" | |
8903 | - " movnti %%edx, 52(%3)\n" | |
8904 | + " movnti %%eax, %%es:48(%3)\n" | |
8905 | + " movnti %%edx, %%es:52(%3)\n" | |
8906 | "14: movl 56(%4), %%eax\n" | |
8907 | "91: movl 60(%4), %%edx\n" | |
8908 | - " movnti %%eax, 56(%3)\n" | |
8909 | - " movnti %%edx, 60(%3)\n" | |
8910 | + " movnti %%eax, %%es:56(%3)\n" | |
8911 | + " movnti %%edx, %%es:60(%3)\n" | |
8912 | " addl $-64, %0\n" | |
8913 | " addl $64, %4\n" | |
8914 | " addl $64, %3\n" | |
4dee9bd5 | 8915 | @@ -484,6 +614,8 @@ static unsigned long __copy_user_zeroing |
da5b3fc8 | 8916 | " movl %%eax,%0\n" |
8917 | "7: rep; movsb\n" | |
8918 | "8:\n" | |
8919 | + " pushl %%ss\n" | |
8920 | + " popl %%ds\n" | |
8921 | ".section .fixup,\"ax\"\n" | |
8922 | "9: lea 0(%%eax,%0,4),%0\n" | |
8923 | "16: pushl %0\n" | |
4dee9bd5 | 8924 | @@ -518,7 +650,7 @@ static unsigned long __copy_user_zeroing |
da5b3fc8 | 8925 | " .long 7b,16b\n" |
8926 | ".previous" | |
8927 | : "=&c"(size), "=&D" (d0), "=&S" (d1) | |
8928 | - : "1"(to), "2"(from), "0"(size) | |
8929 | + : "1"(to), "2"(from), "0"(size), "r"(__USER_DS) | |
8930 | : "eax", "edx", "memory"); | |
8931 | return size; | |
8932 | } | |
4dee9bd5 | 8933 | @@ -529,6 +661,7 @@ static unsigned long __copy_user_intel_n |
da5b3fc8 | 8934 | int d0, d1; |
50425a20 | 8935 | |
da5b3fc8 | 8936 | __asm__ __volatile__( |
8937 | + " movw %w6, %%ds\n" | |
8938 | " .align 2,0x90\n" | |
8939 | "0: movl 32(%4), %%eax\n" | |
8940 | " cmpl $67, %0\n" | |
4dee9bd5 | 8941 | @@ -537,36 +670,36 @@ static unsigned long __copy_user_intel_n |
da5b3fc8 | 8942 | " .align 2,0x90\n" |
8943 | "2: movl 0(%4), %%eax\n" | |
8944 | "21: movl 4(%4), %%edx\n" | |
8945 | - " movnti %%eax, 0(%3)\n" | |
8946 | - " movnti %%edx, 4(%3)\n" | |
8947 | + " movnti %%eax, %%es:0(%3)\n" | |
8948 | + " movnti %%edx, %%es:4(%3)\n" | |
8949 | "3: movl 8(%4), %%eax\n" | |
8950 | "31: movl 12(%4),%%edx\n" | |
8951 | - " movnti %%eax, 8(%3)\n" | |
8952 | - " movnti %%edx, 12(%3)\n" | |
8953 | + " movnti %%eax, %%es:8(%3)\n" | |
8954 | + " movnti %%edx, %%es:12(%3)\n" | |
8955 | "4: movl 16(%4), %%eax\n" | |
8956 | "41: movl 20(%4), %%edx\n" | |
8957 | - " movnti %%eax, 16(%3)\n" | |
8958 | - " movnti %%edx, 20(%3)\n" | |
8959 | + " movnti %%eax, %%es:16(%3)\n" | |
8960 | + " movnti %%edx, %%es:20(%3)\n" | |
8961 | "10: movl 24(%4), %%eax\n" | |
8962 | "51: movl 28(%4), %%edx\n" | |
8963 | - " movnti %%eax, 24(%3)\n" | |
8964 | - " movnti %%edx, 28(%3)\n" | |
8965 | + " movnti %%eax, %%es:24(%3)\n" | |
8966 | + " movnti %%edx, %%es:28(%3)\n" | |
8967 | "11: movl 32(%4), %%eax\n" | |
8968 | "61: movl 36(%4), %%edx\n" | |
8969 | - " movnti %%eax, 32(%3)\n" | |
8970 | - " movnti %%edx, 36(%3)\n" | |
8971 | + " movnti %%eax, %%es:32(%3)\n" | |
8972 | + " movnti %%edx, %%es:36(%3)\n" | |
8973 | "12: movl 40(%4), %%eax\n" | |
8974 | "71: movl 44(%4), %%edx\n" | |
8975 | - " movnti %%eax, 40(%3)\n" | |
8976 | - " movnti %%edx, 44(%3)\n" | |
8977 | + " movnti %%eax, %%es:40(%3)\n" | |
8978 | + " movnti %%edx, %%es:44(%3)\n" | |
8979 | "13: movl 48(%4), %%eax\n" | |
8980 | "81: movl 52(%4), %%edx\n" | |
8981 | - " movnti %%eax, 48(%3)\n" | |
8982 | - " movnti %%edx, 52(%3)\n" | |
8983 | + " movnti %%eax, %%es:48(%3)\n" | |
8984 | + " movnti %%edx, %%es:52(%3)\n" | |
8985 | "14: movl 56(%4), %%eax\n" | |
8986 | "91: movl 60(%4), %%edx\n" | |
8987 | - " movnti %%eax, 56(%3)\n" | |
8988 | - " movnti %%edx, 60(%3)\n" | |
8989 | + " movnti %%eax, %%es:56(%3)\n" | |
8990 | + " movnti %%edx, %%es:60(%3)\n" | |
8991 | " addl $-64, %0\n" | |
8992 | " addl $64, %4\n" | |
8993 | " addl $64, %3\n" | |
4dee9bd5 | 8994 | @@ -581,6 +714,8 @@ static unsigned long __copy_user_intel_n |
da5b3fc8 | 8995 | " movl %%eax,%0\n" |
8996 | "7: rep; movsb\n" | |
8997 | "8:\n" | |
8998 | + " pushl %%ss\n" | |
8999 | + " popl %%ds\n" | |
9000 | ".section .fixup,\"ax\"\n" | |
9001 | "9: lea 0(%%eax,%0,4),%0\n" | |
9002 | "16: jmp 8b\n" | |
4dee9bd5 | 9003 | @@ -609,7 +744,7 @@ static unsigned long __copy_user_intel_n |
da5b3fc8 | 9004 | " .long 7b,16b\n" |
9005 | ".previous" | |
9006 | : "=&c"(size), "=&D" (d0), "=&S" (d1) | |
9007 | - : "1"(to), "2"(from), "0"(size) | |
9008 | + : "1"(to), "2"(from), "0"(size), "r"(__USER_DS) | |
9009 | : "eax", "edx", "memory"); | |
9010 | return size; | |
9011 | } | |
4dee9bd5 | 9012 | @@ -622,90 +757,146 @@ static unsigned long __copy_user_intel_n |
da5b3fc8 | 9013 | */ |
9014 | unsigned long __copy_user_zeroing_intel(void *to, const void __user *from, | |
9015 | unsigned long size); | |
9016 | -unsigned long __copy_user_intel(void __user *to, const void *from, | |
9017 | +unsigned long __generic_copy_to_user_intel(void __user *to, const void *from, | |
9018 | + unsigned long size); | |
9019 | +unsigned long __generic_copy_from_user_intel(void *to, const void __user *from, | |
9020 | unsigned long size); | |
9021 | unsigned long __copy_user_zeroing_intel_nocache(void *to, | |
9022 | const void __user *from, unsigned long size); | |
9023 | #endif /* CONFIG_X86_INTEL_USERCOPY */ | |
50425a20 | 9024 | |
da5b3fc8 | 9025 | /* Generic arbitrary sized copy. */ |
9026 | -#define __copy_user(to,from,size) \ | |
9027 | -do { \ | |
9028 | - int __d0, __d1, __d2; \ | |
9029 | - __asm__ __volatile__( \ | |
9030 | - " cmp $7,%0\n" \ | |
9031 | - " jbe 1f\n" \ | |
9032 | - " movl %1,%0\n" \ | |
9033 | - " negl %0\n" \ | |
9034 | - " andl $7,%0\n" \ | |
9035 | - " subl %0,%3\n" \ | |
9036 | - "4: rep; movsb\n" \ | |
9037 | - " movl %3,%0\n" \ | |
9038 | - " shrl $2,%0\n" \ | |
9039 | - " andl $3,%3\n" \ | |
9040 | - " .align 2,0x90\n" \ | |
9041 | - "0: rep; movsl\n" \ | |
9042 | - " movl %3,%0\n" \ | |
9043 | - "1: rep; movsb\n" \ | |
9044 | - "2:\n" \ | |
9045 | - ".section .fixup,\"ax\"\n" \ | |
9046 | - "5: addl %3,%0\n" \ | |
9047 | - " jmp 2b\n" \ | |
9048 | - "3: lea 0(%3,%0,4),%0\n" \ | |
9049 | - " jmp 2b\n" \ | |
9050 | - ".previous\n" \ | |
9051 | - ".section __ex_table,\"a\"\n" \ | |
9052 | - " .align 4\n" \ | |
9053 | - " .long 4b,5b\n" \ | |
9054 | - " .long 0b,3b\n" \ | |
9055 | - " .long 1b,2b\n" \ | |
9056 | - ".previous" \ | |
9057 | - : "=&c"(size), "=&D" (__d0), "=&S" (__d1), "=r"(__d2) \ | |
9058 | - : "3"(size), "0"(size), "1"(to), "2"(from) \ | |
9059 | - : "memory"); \ | |
9060 | -} while (0) | |
9061 | - | |
9062 | -#define __copy_user_zeroing(to,from,size) \ | |
9063 | -do { \ | |
9064 | - int __d0, __d1, __d2; \ | |
9065 | - __asm__ __volatile__( \ | |
9066 | - " cmp $7,%0\n" \ | |
9067 | - " jbe 1f\n" \ | |
9068 | - " movl %1,%0\n" \ | |
9069 | - " negl %0\n" \ | |
9070 | - " andl $7,%0\n" \ | |
9071 | - " subl %0,%3\n" \ | |
9072 | - "4: rep; movsb\n" \ | |
9073 | - " movl %3,%0\n" \ | |
9074 | - " shrl $2,%0\n" \ | |
9075 | - " andl $3,%3\n" \ | |
9076 | - " .align 2,0x90\n" \ | |
9077 | - "0: rep; movsl\n" \ | |
9078 | - " movl %3,%0\n" \ | |
9079 | - "1: rep; movsb\n" \ | |
9080 | - "2:\n" \ | |
9081 | - ".section .fixup,\"ax\"\n" \ | |
9082 | - "5: addl %3,%0\n" \ | |
9083 | - " jmp 6f\n" \ | |
9084 | - "3: lea 0(%3,%0,4),%0\n" \ | |
9085 | - "6: pushl %0\n" \ | |
9086 | - " pushl %%eax\n" \ | |
9087 | - " xorl %%eax,%%eax\n" \ | |
9088 | - " rep; stosb\n" \ | |
9089 | - " popl %%eax\n" \ | |
9090 | - " popl %0\n" \ | |
9091 | - " jmp 2b\n" \ | |
9092 | - ".previous\n" \ | |
9093 | - ".section __ex_table,\"a\"\n" \ | |
9094 | - " .align 4\n" \ | |
9095 | - " .long 4b,5b\n" \ | |
9096 | - " .long 0b,3b\n" \ | |
9097 | - " .long 1b,6b\n" \ | |
9098 | - ".previous" \ | |
9099 | - : "=&c"(size), "=&D" (__d0), "=&S" (__d1), "=r"(__d2) \ | |
9100 | - : "3"(size), "0"(size), "1"(to), "2"(from) \ | |
9101 | - : "memory"); \ | |
9102 | -} while (0) | |
9103 | +static unsigned long | |
9104 | +__generic_copy_to_user(void __user *to, const void *from, unsigned long size) | |
50425a20 | 9105 | +{ |
da5b3fc8 | 9106 | + int __d0, __d1, __d2; |
50425a20 | 9107 | + |
da5b3fc8 | 9108 | + __asm__ __volatile__( |
9109 | + " movw %w8,%%es\n" | |
9110 | + " cmp $7,%0\n" | |
9111 | + " jbe 1f\n" | |
9112 | + " movl %1,%0\n" | |
9113 | + " negl %0\n" | |
9114 | + " andl $7,%0\n" | |
9115 | + " subl %0,%3\n" | |
9116 | + "4: rep; movsb\n" | |
9117 | + " movl %3,%0\n" | |
9118 | + " shrl $2,%0\n" | |
9119 | + " andl $3,%3\n" | |
9120 | + " .align 2,0x90\n" | |
9121 | + "0: rep; movsl\n" | |
9122 | + " movl %3,%0\n" | |
9123 | + "1: rep; movsb\n" | |
9124 | + "2:\n" | |
9125 | + " pushl %%ss\n" | |
9126 | + " popl %%es\n" | |
9127 | + ".section .fixup,\"ax\"\n" | |
9128 | + "5: addl %3,%0\n" | |
9129 | + " jmp 2b\n" | |
9130 | + "3: lea 0(%3,%0,4),%0\n" | |
9131 | + " jmp 2b\n" | |
9132 | + ".previous\n" | |
9133 | + ".section __ex_table,\"a\"\n" | |
9134 | + " .align 4\n" | |
9135 | + " .long 4b,5b\n" | |
9136 | + " .long 0b,3b\n" | |
9137 | + " .long 1b,2b\n" | |
9138 | + ".previous" | |
9139 | + : "=&c"(size), "=&D" (__d0), "=&S" (__d1), "=r"(__d2) | |
9140 | + : "3"(size), "0"(size), "1"(to), "2"(from), "r"(__USER_DS) | |
9141 | + : "memory"); | |
9142 | + return size; | |
50425a20 | 9143 | +} |
9144 | + | |
da5b3fc8 | 9145 | +static unsigned long |
9146 | +__generic_copy_from_user(void *to, const void __user *from, unsigned long size) | |
50425a20 | 9147 | +{ |
da5b3fc8 | 9148 | + int __d0, __d1, __d2; |
50425a20 | 9149 | + |
da5b3fc8 | 9150 | + __asm__ __volatile__( |
9151 | + " movw %w8,%%ds\n" | |
9152 | + " cmp $7,%0\n" | |
9153 | + " jbe 1f\n" | |
9154 | + " movl %1,%0\n" | |
9155 | + " negl %0\n" | |
9156 | + " andl $7,%0\n" | |
9157 | + " subl %0,%3\n" | |
9158 | + "4: rep; movsb\n" | |
9159 | + " movl %3,%0\n" | |
9160 | + " shrl $2,%0\n" | |
9161 | + " andl $3,%3\n" | |
9162 | + " .align 2,0x90\n" | |
9163 | + "0: rep; movsl\n" | |
9164 | + " movl %3,%0\n" | |
9165 | + "1: rep; movsb\n" | |
9166 | + "2:\n" | |
9167 | + " pushl %%ss\n" | |
9168 | + " popl %%ds\n" | |
9169 | + ".section .fixup,\"ax\"\n" | |
9170 | + "5: addl %3,%0\n" | |
9171 | + " jmp 2b\n" | |
9172 | + "3: lea 0(%3,%0,4),%0\n" | |
9173 | + " jmp 2b\n" | |
9174 | + ".previous\n" | |
9175 | + ".section __ex_table,\"a\"\n" | |
9176 | + " .align 4\n" | |
9177 | + " .long 4b,5b\n" | |
9178 | + " .long 0b,3b\n" | |
9179 | + " .long 1b,2b\n" | |
9180 | + ".previous" | |
9181 | + : "=&c"(size), "=&D" (__d0), "=&S" (__d1), "=r"(__d2) | |
9182 | + : "3"(size), "0"(size), "1"(to), "2"(from), "r"(__USER_DS) | |
9183 | + : "memory"); | |
9184 | + return size; | |
50425a20 | 9185 | +} |
50425a20 | 9186 | + |
da5b3fc8 | 9187 | +static unsigned long |
9188 | +__copy_user_zeroing(void *to, const void __user *from, unsigned long size) | |
50425a20 | 9189 | +{ |
da5b3fc8 | 9190 | + int __d0, __d1, __d2; |
50425a20 | 9191 | + |
da5b3fc8 | 9192 | + __asm__ __volatile__( |
9193 | + " movw %w8,%%ds\n" | |
9194 | + " cmp $7,%0\n" | |
9195 | + " jbe 1f\n" | |
9196 | + " movl %1,%0\n" | |
9197 | + " negl %0\n" | |
9198 | + " andl $7,%0\n" | |
9199 | + " subl %0,%3\n" | |
9200 | + "4: rep; movsb\n" | |
9201 | + " movl %3,%0\n" | |
9202 | + " shrl $2,%0\n" | |
9203 | + " andl $3,%3\n" | |
9204 | + " .align 2,0x90\n" | |
9205 | + "0: rep; movsl\n" | |
9206 | + " movl %3,%0\n" | |
9207 | + "1: rep; movsb\n" | |
9208 | + "2:\n" | |
9209 | + " pushl %%ss\n" | |
9210 | + " popl %%ds\n" | |
9211 | + ".section .fixup,\"ax\"\n" | |
9212 | + "5: addl %3,%0\n" | |
9213 | + " jmp 6f\n" | |
9214 | + "3: lea 0(%3,%0,4),%0\n" | |
9215 | + "6: pushl %0\n" | |
9216 | + " pushl %%eax\n" | |
9217 | + " xorl %%eax,%%eax\n" | |
9218 | + " rep; stosb\n" | |
9219 | + " popl %%eax\n" | |
9220 | + " popl %0\n" | |
9221 | + " jmp 2b\n" | |
9222 | + ".previous\n" | |
9223 | + ".section __ex_table,\"a\"\n" | |
9224 | + " .align 4\n" | |
9225 | + " .long 4b,5b\n" | |
9226 | + " .long 0b,3b\n" | |
9227 | + " .long 1b,6b\n" | |
9228 | + ".previous" | |
9229 | + : "=&c"(size), "=&D" (__d0), "=&S" (__d1), "=r"(__d2) | |
9230 | + : "3"(size), "0"(size), "1"(to), "2"(from), "r"(__USER_DS) | |
9231 | + : "memory"); | |
9232 | + return size; | |
9233 | +} | |
9234 | ||
9235 | unsigned long __copy_to_user_ll(void __user *to, const void *from, | |
9236 | unsigned long n) | |
4dee9bd5 | 9237 | @@ -768,9 +959,9 @@ survive: |
da5b3fc8 | 9238 | } |
9239 | #endif | |
9240 | if (movsl_is_ok(to, from, n)) | |
9241 | - __copy_user(to, from, n); | |
9242 | + n = __generic_copy_to_user(to, from, n); | |
9243 | else | |
9244 | - n = __copy_user_intel(to, from, n); | |
9245 | + n = __generic_copy_to_user_intel(to, from, n); | |
9246 | return n; | |
9247 | } | |
9248 | EXPORT_SYMBOL(__copy_to_user_ll); | |
4dee9bd5 | 9249 | @@ -779,7 +970,7 @@ unsigned long __copy_from_user_ll(void * |
da5b3fc8 | 9250 | unsigned long n) |
9251 | { | |
9252 | if (movsl_is_ok(to, from, n)) | |
9253 | - __copy_user_zeroing(to, from, n); | |
9254 | + n = __copy_user_zeroing(to, from, n); | |
9255 | else | |
9256 | n = __copy_user_zeroing_intel(to, from, n); | |
9257 | return n; | |
4dee9bd5 | 9258 | @@ -790,9 +981,9 @@ unsigned long __copy_from_user_ll_nozero |
da5b3fc8 | 9259 | unsigned long n) |
9260 | { | |
9261 | if (movsl_is_ok(to, from, n)) | |
9262 | - __copy_user(to, from, n); | |
9263 | + n = __generic_copy_from_user(to, from, n); | |
9264 | else | |
9265 | - n = __copy_user_intel((void __user *)to, | |
9266 | + n = __generic_copy_from_user_intel((void __user *)to, | |
9267 | (const void *)from, n); | |
9268 | return n; | |
9269 | } | |
4dee9bd5 | 9270 | @@ -803,11 +994,11 @@ unsigned long __copy_from_user_ll_nocach |
da5b3fc8 | 9271 | { |
9272 | #ifdef CONFIG_X86_INTEL_USERCOPY | |
9273 | if ( n > 64 && cpu_has_xmm2) | |
9274 | - n = __copy_user_zeroing_intel_nocache(to, from, n); | |
9275 | + n = __copy_user_zeroing_intel_nocache(to, from, n); | |
9276 | else | |
9277 | - __copy_user_zeroing(to, from, n); | |
9278 | + n = __copy_user_zeroing(to, from, n); | |
9279 | #else | |
4dee9bd5 | 9280 | - __copy_user_zeroing(to, from, n); |
9281 | + n = __copy_user_zeroing(to, from, n); | |
da5b3fc8 | 9282 | #endif |
4dee9bd5 | 9283 | return n; |
9284 | } | |
9285 | @@ -818,11 +1009,11 @@ unsigned long __copy_from_user_ll_nocach | |
da5b3fc8 | 9286 | { |
9287 | #ifdef CONFIG_X86_INTEL_USERCOPY | |
9288 | if ( n > 64 && cpu_has_xmm2) | |
9289 | - n = __copy_user_intel_nocache(to, from, n); | |
9290 | + n = __copy_user_intel_nocache(to, from, n); | |
9291 | else | |
9292 | - __copy_user(to, from, n); | |
9293 | + n = __generic_copy_from_user(to, from, n); | |
9294 | #else | |
9295 | - __copy_user(to, from, n); | |
9296 | + n = __generic_copy_from_user(to, from, n); | |
9297 | #endif | |
9298 | return n; | |
9299 | } | |
4dee9bd5 | 9300 | @@ -876,3 +1067,30 @@ copy_from_user(void *to, const void __us |
da5b3fc8 | 9301 | return n; |
9302 | } | |
9303 | EXPORT_SYMBOL(copy_from_user); | |
50425a20 | 9304 | + |
da5b3fc8 | 9305 | +#ifdef CONFIG_PAX_MEMORY_UDEREF |
9306 | +void __set_fs(mm_segment_t x, int cpu) | |
9307 | +{ | |
9308 | + unsigned long limit = x.seg; | |
4dee9bd5 | 9309 | + struct desc_struct d; |
50425a20 | 9310 | + |
da5b3fc8 | 9311 | + current_thread_info()->addr_limit = x; |
9312 | + if (likely(limit)) | |
9313 | + limit = (limit - 1UL) >> PAGE_SHIFT; | |
4dee9bd5 | 9314 | + pack_descriptor(&d, 0UL, limit, 0xF3, 0xC); |
9315 | + write_gdt_entry(get_cpu_gdt_table(cpu), GDT_ENTRY_DEFAULT_USER_DS, &d, DESCTYPE_S); | |
da5b3fc8 | 9316 | +} |
50425a20 | 9317 | + |
da5b3fc8 | 9318 | +void set_fs(mm_segment_t x) |
9319 | +{ | |
9320 | + __set_fs(x, get_cpu()); | |
9321 | + put_cpu_no_resched(); | |
9322 | +} | |
9323 | +#else | |
9324 | +void set_fs(mm_segment_t x) | |
9325 | +{ | |
9326 | + current_thread_info()->addr_limit = x; | |
9327 | +} | |
9328 | +#endif | |
50425a20 | 9329 | + |
da5b3fc8 | 9330 | +EXPORT_SYMBOL(set_fs); |
4dee9bd5 | 9331 | diff -urNp linux-2.6.25.4/arch/x86/mach-voyager/voyager_basic.c linux-2.6.25.4/arch/x86/mach-voyager/voyager_basic.c |
9332 | --- linux-2.6.25.4/arch/x86/mach-voyager/voyager_basic.c 2008-05-15 11:00:12.000000000 -0400 | |
9333 | +++ linux-2.6.25.4/arch/x86/mach-voyager/voyager_basic.c 2008-05-18 13:33:15.000000000 -0400 | |
9334 | @@ -125,7 +125,7 @@ int __init voyager_memory_detect(int reg | |
da5b3fc8 | 9335 | __u8 cmos[4]; |
9336 | ClickMap_t *map; | |
9337 | unsigned long map_addr; | |
9338 | - unsigned long old; | |
9339 | + pte_t old; | |
9340 | ||
4dee9bd5 | 9341 | if (region >= CLICK_ENTRIES) { |
da5b3fc8 | 9342 | printk("Voyager: Illegal ClickMap region %d\n", region); |
4dee9bd5 | 9343 | @@ -140,7 +140,7 @@ int __init voyager_memory_detect(int reg |
da5b3fc8 | 9344 | |
9345 | /* steal page 0 for this */ | |
9346 | old = pg0[0]; | |
9347 | - pg0[0] = ((map_addr & PAGE_MASK) | _PAGE_RW | _PAGE_PRESENT); | |
9348 | + pg0[0] = __pte((map_addr & PAGE_MASK) | _PAGE_RW | _PAGE_PRESENT); | |
9349 | local_flush_tlb(); | |
9350 | /* now clear everything out but page 0 */ | |
4dee9bd5 | 9351 | map = (ClickMap_t *) (map_addr & (~PAGE_MASK)); |
9352 | diff -urNp linux-2.6.25.4/arch/x86/mach-voyager/voyager_smp.c linux-2.6.25.4/arch/x86/mach-voyager/voyager_smp.c | |
9353 | --- linux-2.6.25.4/arch/x86/mach-voyager/voyager_smp.c 2008-05-15 11:00:12.000000000 -0400 | |
9354 | +++ linux-2.6.25.4/arch/x86/mach-voyager/voyager_smp.c 2008-05-18 13:33:15.000000000 -0400 | |
9355 | @@ -540,6 +540,10 @@ static void __init do_boot_cpu(__u8 cpu) | |
da5b3fc8 | 9356 | __u32 *hijack_vector; |
9357 | __u32 start_phys_address = setup_trampoline(); | |
9358 | ||
9359 | +#ifdef CONFIG_PAX_KERNEXEC | |
9360 | + unsigned long cr0; | |
9361 | +#endif | |
50425a20 | 9362 | + |
da5b3fc8 | 9363 | /* There's a clever trick to this: The linux trampoline is |
9364 | * compiled to begin at absolute location zero, so make the | |
9365 | * address zero but have the data segment selector compensate | |
4dee9bd5 | 9366 | @@ -559,7 +563,17 @@ static void __init do_boot_cpu(__u8 cpu) |
da5b3fc8 | 9367 | |
9368 | init_gdt(cpu); | |
4dee9bd5 | 9369 | per_cpu(current_task, cpu) = idle; |
da5b3fc8 | 9370 | - early_gdt_descr.address = (unsigned long)get_cpu_gdt_table(cpu); |
50425a20 | 9371 | + |
da5b3fc8 | 9372 | +#ifdef CONFIG_PAX_KERNEXEC |
9373 | + pax_open_kernel(cr0); | |
9374 | +#endif | |
50425a20 | 9375 | + |
da5b3fc8 | 9376 | + early_gdt_descr.address = get_cpu_gdt_table(cpu); |
50425a20 | 9377 | + |
da5b3fc8 | 9378 | +#ifdef CONFIG_PAX_KERNEXEC |
9379 | + pax_close_kernel(cr0); | |
50425a20 | 9380 | +#endif |
9381 | + | |
da5b3fc8 | 9382 | irq_ctx_init(cpu); |
9383 | ||
9384 | /* Note: Don't modify initial ss override */ | |
4dee9bd5 | 9385 | @@ -1242,7 +1256,7 @@ void smp_local_timer_interrupt(void) |
9386 | per_cpu(prof_counter, cpu); | |
da5b3fc8 | 9387 | } |
9388 | ||
9389 | - update_process_times(user_mode_vm(get_irq_regs())); | |
9390 | + update_process_times(user_mode(get_irq_regs())); | |
9391 | } | |
9392 | ||
4dee9bd5 | 9393 | if (((1 << cpu) & voyager_extended_vic_processors) == 0) |
9394 | diff -urNp linux-2.6.25.4/arch/x86/mm/extable.c linux-2.6.25.4/arch/x86/mm/extable.c | |
9395 | --- linux-2.6.25.4/arch/x86/mm/extable.c 2008-05-15 11:00:12.000000000 -0400 | |
9396 | +++ linux-2.6.25.4/arch/x86/mm/extable.c 2008-05-18 13:33:15.000000000 -0400 | |
9397 | @@ -1,14 +1,62 @@ | |
da5b3fc8 | 9398 | #include <linux/module.h> |
9399 | #include <linux/spinlock.h> | |
9400 | +#include <linux/sort.h> | |
9401 | #include <asm/uaccess.h> | |
9402 | ||
9403 | +/* | |
9404 | + * The exception table needs to be sorted so that the binary | |
9405 | + * search that we use to find entries in it works properly. | |
9406 | + * This is used both for the kernel exception table and for | |
9407 | + * the exception tables of modules that get loaded. | |
9408 | + */ | |
9409 | +static int cmp_ex(const void *a, const void *b) | |
9410 | +{ | |
9411 | + const struct exception_table_entry *x = a, *y = b; | |
50425a20 | 9412 | + |
da5b3fc8 | 9413 | + /* avoid overflow */ |
9414 | + if (x->insn > y->insn) | |
9415 | + return 1; | |
9416 | + if (x->insn < y->insn) | |
9417 | + return -1; | |
9418 | + return 0; | |
9419 | +} | |
50425a20 | 9420 | + |
da5b3fc8 | 9421 | +static void swap_ex(void *a, void *b, int size) |
9422 | +{ | |
9423 | + struct exception_table_entry t, *x = a, *y = b; | |
50425a20 | 9424 | + |
da5b3fc8 | 9425 | +#ifdef CONFIG_PAX_KERNEXEC |
9426 | + unsigned long cr0; | |
9427 | +#endif | |
50425a20 | 9428 | + |
da5b3fc8 | 9429 | + t = *x; |
50425a20 | 9430 | + |
da5b3fc8 | 9431 | +#ifdef CONFIG_PAX_KERNEXEC |
9432 | + pax_open_kernel(cr0); | |
9433 | +#endif | |
50425a20 | 9434 | + |
da5b3fc8 | 9435 | + *x = *y; |
9436 | + *y = t; | |
9437 | + | |
9438 | +#ifdef CONFIG_PAX_KERNEXEC | |
9439 | + pax_close_kernel(cr0); | |
50425a20 | 9440 | +#endif |
9441 | + | |
da5b3fc8 | 9442 | +} |
50425a20 | 9443 | + |
da5b3fc8 | 9444 | +void sort_extable(struct exception_table_entry *start, |
9445 | + struct exception_table_entry *finish) | |
9446 | +{ | |
9447 | + sort(start, finish - start, sizeof(struct exception_table_entry), | |
9448 | + cmp_ex, swap_ex); | |
9449 | +} | |
4dee9bd5 | 9450 | |
da5b3fc8 | 9451 | int fixup_exception(struct pt_regs *regs) |
9452 | { | |
9453 | const struct exception_table_entry *fixup; | |
9454 | ||
9455 | #ifdef CONFIG_PNPBIOS | |
4dee9bd5 | 9456 | - if (unlikely(SEGMENT_IS_PNP_CODE(regs->cs))) { |
b79bc584 | 9457 | + if (unlikely(!(regs->flags & VM_MASK) && SEGMENT_IS_PNP_CODE(regs->cs))) { |
da5b3fc8 | 9458 | extern u32 pnp_bios_fault_eip, pnp_bios_fault_esp; |
9459 | extern u32 pnp_bios_is_utter_crap; | |
4dee9bd5 | 9460 | pnp_bios_is_utter_crap = 1; |
9461 | diff -urNp linux-2.6.25.4/arch/x86/mm/fault.c linux-2.6.25.4/arch/x86/mm/fault.c | |
9462 | --- linux-2.6.25.4/arch/x86/mm/fault.c 2008-05-15 11:00:12.000000000 -0400 | |
9463 | +++ linux-2.6.25.4/arch/x86/mm/fault.c 2008-05-18 13:33:15.000000000 -0400 | |
9464 | @@ -25,6 +25,9 @@ | |
da5b3fc8 | 9465 | #include <linux/uaccess.h> |
9466 | #include <linux/kdebug.h> | |
b79bc584 | 9467 | #include <linux/suspend.h> |
da5b3fc8 | 9468 | +#include <linux/unistd.h> |
9469 | +#include <linux/compiler.h> | |
9470 | +#include <linux/binfmts.h> | |
9471 | ||
9472 | #include <asm/system.h> | |
9473 | #include <asm/desc.h> | |
4dee9bd5 | 9474 | @@ -34,6 +37,7 @@ |
9475 | #include <asm/tlbflush.h> | |
9476 | #include <asm/proto.h> | |
9477 | #include <asm-generic/sections.h> | |
da5b3fc8 | 9478 | +#include <asm/tlbflush.h> |
9479 | ||
4dee9bd5 | 9480 | /* |
9481 | * Page fault error code bits | |
9482 | @@ -55,11 +59,7 @@ static inline int notify_page_fault(stru | |
da5b3fc8 | 9483 | int ret = 0; |
9484 | ||
9485 | /* kprobe_running() needs smp_processor_id() */ | |
4dee9bd5 | 9486 | -#ifdef CONFIG_X86_32 |
da5b3fc8 | 9487 | - if (!user_mode_vm(regs)) { |
4dee9bd5 | 9488 | -#else |
9489 | if (!user_mode(regs)) { | |
9490 | -#endif | |
da5b3fc8 | 9491 | preempt_disable(); |
9492 | if (kprobe_running() && kprobe_fault_handler(regs, 14)) | |
9493 | ret = 1; | |
4dee9bd5 | 9494 | @@ -257,6 +257,30 @@ bad: |
9495 | #endif | |
9496 | } | |
da5b3fc8 | 9497 | |
4dee9bd5 | 9498 | +#ifdef CONFIG_PAX_EMUTRAMP |
da5b3fc8 | 9499 | +static int pax_handle_fetch_fault(struct pt_regs *regs); |
9500 | +#endif | |
50425a20 | 9501 | + |
da5b3fc8 | 9502 | +#ifdef CONFIG_PAX_PAGEEXEC |
9503 | +static inline pmd_t * pax_get_pmd(struct mm_struct *mm, unsigned long address) | |
9504 | +{ | |
9505 | + pgd_t *pgd; | |
9506 | + pud_t *pud; | |
9507 | + pmd_t *pmd; | |
50425a20 | 9508 | + |
da5b3fc8 | 9509 | + pgd = pgd_offset(mm, address); |
9510 | + if (!pgd_present(*pgd)) | |
9511 | + return NULL; | |
9512 | + pud = pud_offset(pgd, address); | |
9513 | + if (!pud_present(*pud)) | |
9514 | + return NULL; | |
9515 | + pmd = pmd_offset(pud, address); | |
9516 | + if (!pmd_present(*pmd)) | |
9517 | + return NULL; | |
9518 | + return pmd; | |
9519 | +} | |
9520 | +#endif | |
50425a20 | 9521 | + |
4dee9bd5 | 9522 | #ifdef CONFIG_X86_32 |
da5b3fc8 | 9523 | static inline pmd_t *vmalloc_sync_one(pgd_t *pgd, unsigned long address) |
9524 | { | |
4dee9bd5 | 9525 | @@ -380,17 +404,32 @@ static void show_fault_oops(struct pt_re |
9526 | #endif | |
9527 | ||
9528 | #ifdef CONFIG_X86_PAE | |
9529 | - if (error_code & PF_INSTR) { | |
9530 | + if (nx_enabled && (error_code & PF_INSTR)) { | |
9531 | unsigned int level; | |
9532 | pte_t *pte = lookup_address(address, &level); | |
9533 | ||
9534 | if (pte && pte_present(*pte) && !pte_exec(*pte)) | |
9535 | printk(KERN_CRIT "kernel tried to execute " | |
9536 | "NX-protected page - exploit attempt? " | |
9537 | - "(uid: %d)\n", current->uid); | |
9538 | + "(uid: %d, task: %s, pid: %d)\n", | |
9539 | + current->uid, current->comm, task_pid_nr(current)); | |
9540 | } | |
9541 | #endif | |
9542 | ||
9543 | +#ifdef CONFIG_PAX_KERNEXEC | |
9544 | +#ifdef CONFIG_MODULES | |
9545 | + if (init_mm.start_code <= address && address < (unsigned long)MODULES_END) | |
9546 | +#else | |
9547 | + if (init_mm.start_code <= address && address < init_mm.end_code) | |
9548 | +#endif | |
9549 | + if (current->signal->curr_ip) | |
9550 | + printk(KERN_ERR "PAX: From %u.%u.%u.%u: %s:%d, uid/euid: %u/%u, attempted to modify kernel code\n", | |
9551 | + NIPQUAD(current->signal->curr_ip), current->comm, task_pid_nr(current), current->uid, current->euid); | |
9552 | + else | |
9553 | + printk(KERN_ERR "PAX: %s:%d, uid/euid: %u/%u, attempted to modify kernel code\n", | |
9554 | + current->comm, task_pid_nr(current), current->uid, current->euid); | |
9555 | +#endif | |
9556 | + | |
9557 | printk(KERN_ALERT "BUG: unable to handle kernel "); | |
9558 | if (address < PAGE_SIZE) | |
9559 | printk(KERN_CONT "NULL pointer dereference"); | |
9560 | @@ -578,13 +617,22 @@ void __kprobes do_page_fault(struct pt_r | |
9561 | struct task_struct *tsk; | |
9562 | struct mm_struct *mm; | |
9563 | struct vm_area_struct *vma; | |
da5b3fc8 | 9564 | - unsigned long address; |
9565 | int write, si_code; | |
9566 | int fault; | |
4dee9bd5 | 9567 | #ifdef CONFIG_X86_64 |
9568 | unsigned long flags; | |
9569 | #endif | |
9570 | ||
9571 | +#if defined(CONFIG_X86_32) && defined(CONFIG_PAX_PAGEEXEC) | |
da5b3fc8 | 9572 | + pte_t *pte; |
da5b3fc8 | 9573 | + pmd_t *pmd; |
9574 | + spinlock_t *ptl; | |
9575 | + unsigned char pte_mask; | |
9576 | +#endif | |
9577 | + | |
9578 | + /* get the address */ | |
9579 | + const unsigned long address = read_cr2(); | |
4dee9bd5 | 9580 | + |
da5b3fc8 | 9581 | /* |
9582 | * We can fault from pretty much anywhere, with unknown IRQ state. | |
9583 | */ | |
4dee9bd5 | 9584 | @@ -594,9 +642,6 @@ void __kprobes do_page_fault(struct pt_r |
9585 | mm = tsk->mm; | |
9586 | prefetchw(&mm->mmap_sem); | |
da5b3fc8 | 9587 | |
9588 | - /* get the address */ | |
4dee9bd5 | 9589 | - address = read_cr2(); |
da5b3fc8 | 9590 | - |
da5b3fc8 | 9591 | si_code = SEGV_MAPERR; |
9592 | ||
4dee9bd5 | 9593 | if (notify_page_fault(regs)) |
9594 | @@ -647,7 +692,7 @@ void __kprobes do_page_fault(struct pt_r | |
9595 | * atomic region then we must not take the fault. | |
da5b3fc8 | 9596 | */ |
9597 | if (in_atomic() || !mm) | |
9598 | - goto bad_area_nosemaphore; | |
4dee9bd5 | 9599 | + goto bad_area_nopax; |
9600 | #else /* CONFIG_X86_64 */ | |
9601 | if (likely(regs->flags & X86_EFLAGS_IF)) | |
9602 | local_irq_enable(); | |
9603 | @@ -660,13 +705,13 @@ void __kprobes do_page_fault(struct pt_r | |
9604 | * atomic region then we must not take the fault. | |
9605 | */ | |
9606 | if (unlikely(in_atomic() || !mm)) | |
9607 | - goto bad_area_nosemaphore; | |
da5b3fc8 | 9608 | + goto bad_area_nopax; |
9609 | ||
4dee9bd5 | 9610 | /* |
9611 | * User-mode registers count as a user access even for any | |
9612 | * potential system fault or CPU buglet. | |
9613 | */ | |
9614 | - if (user_mode_vm(regs)) | |
9615 | + if (user_mode(regs)) | |
9616 | error_code |= PF_USER; | |
9617 | again: | |
9618 | #endif | |
9619 | @@ -688,10 +733,104 @@ again: | |
da5b3fc8 | 9620 | if (!down_read_trylock(&mm->mmap_sem)) { |
4dee9bd5 | 9621 | if ((error_code & PF_USER) == 0 && |
9622 | !search_exception_tables(regs->ip)) | |
da5b3fc8 | 9623 | - goto bad_area_nosemaphore; |
9624 | + goto bad_area_nopax; | |
9625 | down_read(&mm->mmap_sem); | |
9626 | } | |
9627 | ||
4dee9bd5 | 9628 | +#if defined(CONFIG_X86_32) && defined(CONFIG_PAX_PAGEEXEC) |
9629 | + if (nx_enabled || (error_code & 5) != 5 || (regs->flags & X86_EFLAGS_VM) || | |
da5b3fc8 | 9630 | + !(mm->pax_flags & MF_PAX_PAGEEXEC)) |
9631 | + goto not_pax_fault; | |
50425a20 | 9632 | + |
da5b3fc8 | 9633 | + /* PaX: it's our fault, let's handle it if we can */ |
50425a20 | 9634 | + |
da5b3fc8 | 9635 | + /* PaX: take a look at read faults before acquiring any locks */ |
4dee9bd5 | 9636 | + if (unlikely(!(error_code & 2) && (regs->ip == address))) { |
da5b3fc8 | 9637 | + /* instruction fetch attempt from a protected page in user mode */ |
9638 | + up_read(&mm->mmap_sem); | |
50425a20 | 9639 | + |
da5b3fc8 | 9640 | +#ifdef CONFIG_PAX_EMUTRAMP |
9641 | + switch (pax_handle_fetch_fault(regs)) { | |
9642 | + case 2: | |
9643 | + return; | |
50425a20 | 9644 | + } |
50425a20 | 9645 | +#endif |
9646 | + | |
4dee9bd5 | 9647 | + pax_report_fault(regs, (void *)regs->ip, (void *)regs->sp); |
b7f09679 | 9648 | + do_group_exit(SIGKILL); |
da5b3fc8 | 9649 | + } |
50425a20 | 9650 | + |
da5b3fc8 | 9651 | + pmd = pax_get_pmd(mm, address); |
9652 | + if (unlikely(!pmd)) | |
9653 | + goto not_pax_fault; | |
50425a20 | 9654 | + |
da5b3fc8 | 9655 | + pte = pte_offset_map_lock(mm, pmd, address, &ptl); |
9656 | + if (unlikely(!(pte_val(*pte) & _PAGE_PRESENT) || pte_user(*pte))) { | |
9657 | + pte_unmap_unlock(pte, ptl); | |
9658 | + goto not_pax_fault; | |
50425a20 | 9659 | + } |
50425a20 | 9660 | + |
da5b3fc8 | 9661 | + if (unlikely((error_code & 2) && !pte_write(*pte))) { |
9662 | + /* write attempt to a protected page in user mode */ | |
9663 | + pte_unmap_unlock(pte, ptl); | |
9664 | + goto not_pax_fault; | |
9665 | + } | |
9666 | + | |
9667 | +#ifdef CONFIG_SMP | |
4dee9bd5 | 9668 | + if (likely(address > get_limit(regs->cs) && cpu_isset(smp_processor_id(), mm->context.cpu_user_cs_mask))) |
50425a20 | 9669 | +#else |
da5b3fc8 | 9670 | + if (likely(address > get_limit(regs->xcs))) |
50425a20 | 9671 | +#endif |
da5b3fc8 | 9672 | + { |
9673 | + set_pte(pte, pte_mkread(*pte)); | |
9674 | + __flush_tlb_one(address); | |
9675 | + pte_unmap_unlock(pte, ptl); | |
9676 | + up_read(&mm->mmap_sem); | |
9677 | + return; | |
9678 | + } | |
50425a20 | 9679 | + |
da5b3fc8 | 9680 | + pte_mask = _PAGE_ACCESSED | _PAGE_USER | ((error_code & 2) << (_PAGE_BIT_DIRTY-1)); |
50425a20 | 9681 | + |
da5b3fc8 | 9682 | + /* |
9683 | + * PaX: fill DTLB with user rights and retry | |
9684 | + */ | |
9685 | + __asm__ __volatile__ ( | |
9686 | +#ifdef CONFIG_PAX_MEMORY_UDEREF | |
9687 | + "movw %w4,%%es\n" | |
50425a20 | 9688 | +#endif |
da5b3fc8 | 9689 | + "orb %2,(%1)\n" |
9690 | +#if defined(CONFIG_M586) || defined(CONFIG_M586TSC) | |
9691 | +/* | |
9692 | + * PaX: let this uncommented 'invlpg' remind us on the behaviour of Intel's | |
9693 | + * (and AMD's) TLBs. namely, they do not cache PTEs that would raise *any* | |
9694 | + * page fault when examined during a TLB load attempt. this is true not only | |
9695 | + * for PTEs holding a non-present entry but also present entries that will | |
9696 | + * raise a page fault (such as those set up by PaX, or the copy-on-write | |
9697 | + * mechanism). in effect it means that we do *not* need to flush the TLBs | |
9698 | + * for our target pages since their PTEs are simply not in the TLBs at all. | |
50425a20 | 9699 | + |
da5b3fc8 | 9700 | + * the best thing in omitting it is that we gain around 15-20% speed in the |
9701 | + * fast path of the page fault handler and can get rid of tracing since we | |
9702 | + * can no longer flush unintended entries. | |
9703 | + */ | |
9704 | + "invlpg (%0)\n" | |
50425a20 | 9705 | +#endif |
da5b3fc8 | 9706 | + "testb $0,%%es:(%0)\n" |
9707 | + "xorb %3,(%1)\n" | |
9708 | +#ifdef CONFIG_PAX_MEMORY_UDEREF | |
9709 | + "pushl %%ss\n" | |
9710 | + "popl %%es\n" | |
9711 | +#endif | |
9712 | + : | |
9713 | + : "r" (address), "r" (pte), "q" (pte_mask), "i" (_PAGE_USER), "r" (__USER_DS) | |
9714 | + : "memory", "cc"); | |
9715 | + pte_unmap_unlock(pte, ptl); | |
9716 | + up_read(&mm->mmap_sem); | |
9717 | + return; | |
50425a20 | 9718 | + |
da5b3fc8 | 9719 | +not_pax_fault: |
50425a20 | 9720 | +#endif |
9721 | + | |
da5b3fc8 | 9722 | vma = find_vma(mm, address); |
9723 | if (!vma) | |
9724 | goto bad_area; | |
4dee9bd5 | 9725 | @@ -709,6 +848,12 @@ again: |
9726 | if (address + 65536 + 32 * sizeof(unsigned long) < regs->sp) | |
da5b3fc8 | 9727 | goto bad_area; |
50425a20 | 9728 | } |
50425a20 | 9729 | + |
da5b3fc8 | 9730 | +#ifdef CONFIG_PAX_SEGMEXEC |
9731 | + if ((mm->pax_flags & MF_PAX_SEGMEXEC) && vma->vm_end - SEGMEXEC_TASK_SIZE - 1 < address - SEGMEXEC_TASK_SIZE - 1) | |
9732 | + goto bad_area; | |
9733 | +#endif | |
9734 | + | |
9735 | if (expand_stack(vma, address)) | |
9736 | goto bad_area; | |
9737 | /* | |
4dee9bd5 | 9738 | @@ -718,6 +863,8 @@ again: |
da5b3fc8 | 9739 | good_area: |
9740 | si_code = SEGV_ACCERR; | |
9741 | write = 0; | |
4dee9bd5 | 9742 | + if (nx_enabled && (error_code & PF_INSTR) && !(vma->vm_flags & VM_EXEC)) |
da5b3fc8 | 9743 | + goto bad_area; |
4dee9bd5 | 9744 | switch (error_code & (PF_PROT|PF_WRITE)) { |
9745 | default: /* 3: write, present */ | |
9746 | /* fall through */ | |
9747 | @@ -775,6 +922,49 @@ bad_area: | |
da5b3fc8 | 9748 | up_read(&mm->mmap_sem); |
50425a20 | 9749 | |
da5b3fc8 | 9750 | bad_area_nosemaphore: |
9751 | + | |
9752 | +#if defined(CONFIG_PAX_PAGEEXEC) || defined(CONFIG_PAX_SEGMEXEC) | |
4dee9bd5 | 9753 | + if (mm && (error_code & 4) && !(regs->flags & X86_EFLAGS_VM)) { |
da5b3fc8 | 9754 | + /* |
9755 | + * It's possible to have interrupts off here. | |
9756 | + */ | |
9757 | + local_irq_enable(); | |
9758 | + | |
50425a20 | 9759 | +#ifdef CONFIG_PAX_PAGEEXEC |
da5b3fc8 | 9760 | + if ((mm->pax_flags & MF_PAX_PAGEEXEC) && |
4dee9bd5 | 9761 | + ((nx_enabled && ((error_code & PF_INSTR) || !(error_code & (PF_PROT | PF_WRITE))) && (regs->ip == address)))) { |
50425a20 | 9762 | + |
da5b3fc8 | 9763 | +#ifdef CONFIG_PAX_EMUTRAMP |
9764 | + switch (pax_handle_fetch_fault(regs)) { | |
9765 | + case 2: | |
9766 | + return; | |
9767 | + } | |
9768 | +#endif | |
50425a20 | 9769 | + |
4dee9bd5 | 9770 | + pax_report_fault(regs, (void *)regs->ip, (void *)regs->sp); |
b7f09679 | 9771 | + do_group_exit(SIGKILL); |
da5b3fc8 | 9772 | + } |
9773 | +#endif | |
50425a20 | 9774 | + |
da5b3fc8 | 9775 | +#ifdef CONFIG_PAX_SEGMEXEC |
4dee9bd5 | 9776 | + if ((mm->pax_flags & MF_PAX_SEGMEXEC) && !(error_code & (PF_PROT | PF_WRITE)) && (regs->ip + SEGMEXEC_TASK_SIZE == address)) { |
50425a20 | 9777 | + |
da5b3fc8 | 9778 | +#ifdef CONFIG_PAX_EMUTRAMP |
9779 | + switch (pax_handle_fetch_fault(regs)) { | |
9780 | + case 2: | |
9781 | + return; | |
9782 | + } | |
9783 | +#endif | |
50425a20 | 9784 | + |
4dee9bd5 | 9785 | + pax_report_fault(regs, (void *)regs->ip, (void *)regs->sp); |
b7f09679 | 9786 | + do_group_exit(SIGKILL); |
da5b3fc8 | 9787 | + } |
9788 | +#endif | |
50425a20 | 9789 | + |
da5b3fc8 | 9790 | + } |
9791 | +#endif | |
50425a20 | 9792 | + |
da5b3fc8 | 9793 | +bad_area_nopax: |
9794 | /* User mode accesses just cause a SIGSEGV */ | |
4dee9bd5 | 9795 | if (error_code & PF_USER) { |
da5b3fc8 | 9796 | /* |
4dee9bd5 | 9797 | @@ -857,7 +1047,7 @@ no_context: |
9798 | #ifdef CONFIG_X86_32 | |
b7f09679 | 9799 | die("Oops", regs, error_code); |
9800 | bust_spinlocks(0); | |
9801 | - do_exit(SIGKILL); | |
9802 | + do_group_exit(SIGKILL); | |
4dee9bd5 | 9803 | #else |
9804 | if (__die("Oops", regs, error_code)) | |
9805 | regs = NULL; | |
9806 | @@ -871,17 +1061,17 @@ no_context: | |
b7f09679 | 9807 | * us unable to handle the page fault gracefully. |
9808 | */ | |
9809 | out_of_memory: | |
9810 | - up_read(&mm->mmap_sem); | |
9811 | if (is_global_init(tsk)) { | |
9812 | yield(); | |
4dee9bd5 | 9813 | #ifdef CONFIG_X86_32 |
b7f09679 | 9814 | - down_read(&mm->mmap_sem); |
9815 | goto survive; | |
4dee9bd5 | 9816 | #else |
9817 | + up_read(&mm->mmap_sem); | |
9818 | goto again; | |
9819 | #endif | |
b7f09679 | 9820 | } |
4dee9bd5 | 9821 | |
b7f09679 | 9822 | + up_read(&mm->mmap_sem); |
9823 | printk("VM: killing process %s\n", tsk->comm); | |
4dee9bd5 | 9824 | if (error_code & PF_USER) |
b7f09679 | 9825 | do_group_exit(SIGKILL); |
4dee9bd5 | 9826 | @@ -982,3 +1172,181 @@ void vmalloc_sync_all(void) |
9827 | (__START_KERNEL & PGDIR_MASK))); | |
9828 | #endif | |
da5b3fc8 | 9829 | } |
50425a20 | 9830 | + |
da5b3fc8 | 9831 | +#ifdef CONFIG_PAX_EMUTRAMP |
9832 | +static int pax_handle_fetch_fault_32(struct pt_regs *regs) | |
9833 | +{ | |
9834 | + int err; | |
9835 | + | |
9836 | + do { /* PaX: gcc trampoline emulation #1 */ | |
9837 | + unsigned char mov1, mov2; | |
9838 | + unsigned short jmp; | |
9839 | + unsigned int addr1, addr2; | |
50425a20 | 9840 | + |
4dee9bd5 | 9841 | +#ifdef CONFIG_X86_64 |
9842 | + if ((regs->ip + 11) >> 32) | |
da5b3fc8 | 9843 | + break; |
4dee9bd5 | 9844 | +#endif |
da5b3fc8 | 9845 | + |
4dee9bd5 | 9846 | + err = get_user(mov1, (unsigned char __user *)regs->ip); |
9847 | + err |= get_user(addr1, (unsigned int __user *)(regs->ip + 1)); | |
9848 | + err |= get_user(mov2, (unsigned char __user *)(regs->ip + 5)); | |
9849 | + err |= get_user(addr2, (unsigned int __user *)(regs->ip + 6)); | |
9850 | + err |= get_user(jmp, (unsigned short __user *)(regs->ip + 10)); | |
50425a20 | 9851 | + |
9852 | + if (err) | |
9853 | + break; | |
9854 | + | |
da5b3fc8 | 9855 | + if (mov1 == 0xB9 && mov2 == 0xB8 && jmp == 0xE0FF) { |
4dee9bd5 | 9856 | + regs->cx = addr1; |
9857 | + regs->ax = addr2; | |
9858 | + regs->ip = addr2; | |
50425a20 | 9859 | + return 2; |
9860 | + } | |
9861 | + } while (0); | |
9862 | + | |
da5b3fc8 | 9863 | + do { /* PaX: gcc trampoline emulation #2 */ |
9864 | + unsigned char mov, jmp; | |
9865 | + unsigned int addr1, addr2; | |
50425a20 | 9866 | + |
4dee9bd5 | 9867 | +#ifdef CONFIG_X86_64 |
9868 | + if ((regs->ip + 9) >> 32) | |
da5b3fc8 | 9869 | + break; |
4dee9bd5 | 9870 | +#endif |
50425a20 | 9871 | + |
4dee9bd5 | 9872 | + err = get_user(mov, (unsigned char __user *)regs->ip); |
9873 | + err |= get_user(addr1, (unsigned int __user *)(regs->ip + 1)); | |
9874 | + err |= get_user(jmp, (unsigned char __user *)(regs->ip + 5)); | |
9875 | + err |= get_user(addr2, (unsigned int __user *)(regs->ip + 6)); | |
50425a20 | 9876 | + |
da5b3fc8 | 9877 | + if (err) |
9878 | + break; | |
9879 | + | |
9880 | + if (mov == 0xB9 && jmp == 0xE9) { | |
4dee9bd5 | 9881 | + regs->cx = addr1; |
9882 | + regs->ip = (unsigned int)(regs->ip + addr2 + 10); | |
50425a20 | 9883 | + return 2; |
9884 | + } | |
da5b3fc8 | 9885 | + } while (0); |
50425a20 | 9886 | + |
da5b3fc8 | 9887 | + return 1; /* PaX in action */ |
9888 | +} | |
50425a20 | 9889 | + |
4dee9bd5 | 9890 | +#ifdef CONFIG_X86_64 |
da5b3fc8 | 9891 | +static int pax_handle_fetch_fault_64(struct pt_regs *regs) |
9892 | +{ | |
9893 | + int err; | |
9894 | + | |
9895 | + do { /* PaX: gcc trampoline emulation #1 */ | |
9896 | + unsigned short mov1, mov2, jmp1; | |
9897 | + unsigned char jmp2; | |
9898 | + unsigned int addr1; | |
9899 | + unsigned long addr2; | |
9900 | + | |
4dee9bd5 | 9901 | + err = get_user(mov1, (unsigned short __user *)regs->ip); |
9902 | + err |= get_user(addr1, (unsigned int __user *)(regs->ip + 2)); | |
9903 | + err |= get_user(mov2, (unsigned short __user *)(regs->ip + 6)); | |
9904 | + err |= get_user(addr2, (unsigned long __user *)(regs->ip + 8)); | |
9905 | + err |= get_user(jmp1, (unsigned short __user *)(regs->ip + 16)); | |
9906 | + err |= get_user(jmp2, (unsigned char __user *)(regs->ip + 18)); | |
50425a20 | 9907 | + |
9908 | + if (err) | |
9909 | + break; | |
9910 | + | |
da5b3fc8 | 9911 | + if (mov1 == 0xBB41 && mov2 == 0xBA49 && jmp1 == 0xFF49 && jmp2 == 0xE3) { |
9912 | + regs->r11 = addr1; | |
9913 | + regs->r10 = addr2; | |
4dee9bd5 | 9914 | + regs->ip = addr1; |
50425a20 | 9915 | + return 2; |
9916 | + } | |
9917 | + } while (0); | |
9918 | + | |
da5b3fc8 | 9919 | + do { /* PaX: gcc trampoline emulation #2 */ |
9920 | + unsigned short mov1, mov2, jmp1; | |
9921 | + unsigned char jmp2; | |
9922 | + unsigned long addr1, addr2; | |
50425a20 | 9923 | + |
4dee9bd5 | 9924 | + err = get_user(mov1, (unsigned short __user *)regs->ip); |
9925 | + err |= get_user(addr1, (unsigned long __user *)(regs->ip + 2)); | |
9926 | + err |= get_user(mov2, (unsigned short __user *)(regs->ip + 10)); | |
9927 | + err |= get_user(addr2, (unsigned long __user *)(regs->ip + 12)); | |
9928 | + err |= get_user(jmp1, (unsigned short __user *)(regs->ip + 20)); | |
9929 | + err |= get_user(jmp2, (unsigned char __user *)(regs->ip + 22)); | |
50425a20 | 9930 | + |
9931 | + if (err) | |
9932 | + break; | |
9933 | + | |
da5b3fc8 | 9934 | + if (mov1 == 0xBB49 && mov2 == 0xBA49 && jmp1 == 0xFF49 && jmp2 == 0xE3) { |
9935 | + regs->r11 = addr1; | |
9936 | + regs->r10 = addr2; | |
4dee9bd5 | 9937 | + regs->ip = addr1; |
da5b3fc8 | 9938 | + return 2; |
9939 | + } | |
9940 | + } while (0); | |
50425a20 | 9941 | + |
da5b3fc8 | 9942 | + return 1; /* PaX in action */ |
9943 | +} | |
4dee9bd5 | 9944 | +#endif |
50425a20 | 9945 | + |
da5b3fc8 | 9946 | +/* |
4dee9bd5 | 9947 | + * PaX: decide what to do with offenders (regs->ip = fault address) |
da5b3fc8 | 9948 | + * |
9949 | + * returns 1 when task should be killed | |
9950 | + * 2 when gcc trampoline was detected | |
9951 | + */ | |
9952 | +static int pax_handle_fetch_fault(struct pt_regs *regs) | |
9953 | +{ | |
4dee9bd5 | 9954 | + if (regs->flags & X86_EFLAGS_VM) |
da5b3fc8 | 9955 | + return 1; |
50425a20 | 9956 | + |
da5b3fc8 | 9957 | + if (!(current->mm->pax_flags & MF_PAX_EMUTRAMP)) |
9958 | + return 1; | |
50425a20 | 9959 | + |
4dee9bd5 | 9960 | +#ifdef CONFIG_X86_32 |
9961 | + return pax_handle_fetch_fault_32(regs); | |
9962 | +#else | |
da5b3fc8 | 9963 | + if (regs->cs == __USER32_CS || (regs->cs & (1<<2))) |
9964 | + return pax_handle_fetch_fault_32(regs); | |
9965 | + else | |
9966 | + return pax_handle_fetch_fault_64(regs); | |
4dee9bd5 | 9967 | +#endif |
da5b3fc8 | 9968 | +} |
9969 | +#endif | |
50425a20 | 9970 | + |
4dee9bd5 | 9971 | +#if defined(CONFIG_PAX_PAGEEXEC) || defined(CONFIG_PAX_SEGMEXEC) |
da5b3fc8 | 9972 | +void pax_report_insns(void *pc, void *sp) |
9973 | +{ | |
9974 | + long i; | |
50425a20 | 9975 | + |
da5b3fc8 | 9976 | + printk(KERN_ERR "PAX: bytes at PC: "); |
9977 | + for (i = 0; i < 20; i++) { | |
9978 | + unsigned char c; | |
9979 | + if (get_user(c, (unsigned char __user *)pc+i)) | |
4dee9bd5 | 9980 | + printk(KERN_CONT "?? "); |
da5b3fc8 | 9981 | + else |
4dee9bd5 | 9982 | + printk(KERN_CONT "%02x ", c); |
da5b3fc8 | 9983 | + } |
9984 | + printk("\n"); | |
50425a20 | 9985 | + |
4dee9bd5 | 9986 | +#ifdef CONFIG_X86_32 |
9987 | + printk(KERN_ERR "PAX: bytes at SP-4: "); | |
9988 | + for (i = -1; i < 20; i++) { | |
9989 | +#else | |
da5b3fc8 | 9990 | + printk(KERN_ERR "PAX: bytes at SP-8: "); |
9991 | + for (i = -1; i < 10; i++) { | |
4dee9bd5 | 9992 | +#endif |
da5b3fc8 | 9993 | + unsigned long c; |
9994 | + if (get_user(c, (unsigned long __user *)sp+i)) | |
4dee9bd5 | 9995 | +#ifdef CONFIG_X86_32 |
9996 | + printk(KERN_CONT "???????? "); | |
9997 | + else | |
9998 | + printk(KERN_CONT "%08lx ", c); | |
9999 | +#else | |
10000 | + printk(KERN_CONT "???????????????? "); | |
da5b3fc8 | 10001 | + else |
4dee9bd5 | 10002 | + printk(KERN_CONT "%016lx ", c); |
10003 | +#endif | |
da5b3fc8 | 10004 | + } |
10005 | + printk("\n"); | |
10006 | +} | |
10007 | +#endif | |
4dee9bd5 | 10008 | diff -urNp linux-2.6.25.4/arch/x86/mm/highmem_32.c linux-2.6.25.4/arch/x86/mm/highmem_32.c |
10009 | --- linux-2.6.25.4/arch/x86/mm/highmem_32.c 2008-05-15 11:00:12.000000000 -0400 | |
10010 | +++ linux-2.6.25.4/arch/x86/mm/highmem_32.c 2008-05-18 13:33:15.000000000 -0400 | |
10011 | @@ -74,6 +74,10 @@ void *kmap_atomic_prot(struct page *page | |
da5b3fc8 | 10012 | enum fixed_addresses idx; |
10013 | unsigned long vaddr; | |
10014 | ||
10015 | +#ifdef CONFIG_PAX_KERNEXEC | |
10016 | + unsigned long cr0; | |
10017 | +#endif | |
10018 | + | |
10019 | /* even !CONFIG_PREEMPT needs this, for in_atomic in do_page_fault */ | |
10020 | pagefault_disable(); | |
10021 | ||
4dee9bd5 | 10022 | @@ -85,7 +89,17 @@ void *kmap_atomic_prot(struct page *page |
da5b3fc8 | 10023 | idx = type + KM_TYPE_NR*smp_processor_id(); |
10024 | vaddr = __fix_to_virt(FIX_KMAP_BEGIN + idx); | |
10025 | BUG_ON(!pte_none(*(kmap_pte-idx))); | |
10026 | + | |
10027 | +#ifdef CONFIG_PAX_KERNEXEC | |
10028 | + pax_open_kernel(cr0); | |
10029 | +#endif | |
10030 | + | |
10031 | set_pte(kmap_pte-idx, mk_pte(page, prot)); | |
10032 | + | |
10033 | +#ifdef CONFIG_PAX_KERNEXEC | |
10034 | + pax_close_kernel(cr0); | |
10035 | +#endif | |
10036 | + | |
10037 | arch_flush_lazy_mmu_mode(); | |
10038 | ||
10039 | return (void *)vaddr; | |
4dee9bd5 | 10040 | @@ -101,15 +115,29 @@ void kunmap_atomic(void *kvaddr, enum km |
da5b3fc8 | 10041 | unsigned long vaddr = (unsigned long) kvaddr & PAGE_MASK; |
10042 | enum fixed_addresses idx = type + KM_TYPE_NR*smp_processor_id(); | |
10043 | ||
10044 | +#ifdef CONFIG_PAX_KERNEXEC | |
10045 | + unsigned long cr0; | |
10046 | +#endif | |
10047 | + | |
10048 | /* | |
10049 | * Force other mappings to Oops if they'll try to access this pte | |
10050 | * without first remap it. Keeping stale mappings around is a bad idea | |
10051 | * also, in case the page changes cacheability attributes or becomes | |
10052 | * a protected page in a hypervisor. | |
10053 | */ | |
10054 | - if (vaddr == __fix_to_virt(FIX_KMAP_BEGIN+idx)) | |
10055 | + if (vaddr == __fix_to_virt(FIX_KMAP_BEGIN+idx)) { | |
10056 | + | |
10057 | +#ifdef CONFIG_PAX_KERNEXEC | |
10058 | + pax_open_kernel(cr0); | |
10059 | +#endif | |
10060 | + | |
10061 | kpte_clear_flush(kmap_pte-idx, vaddr); | |
10062 | - else { | |
10063 | + | |
10064 | +#ifdef CONFIG_PAX_KERNEXEC | |
10065 | + pax_close_kernel(cr0); | |
10066 | +#endif | |
10067 | + | |
10068 | + } else { | |
10069 | #ifdef CONFIG_DEBUG_HIGHMEM | |
10070 | BUG_ON(vaddr < PAGE_OFFSET); | |
10071 | BUG_ON(vaddr >= (unsigned long)high_memory); | |
4dee9bd5 | 10072 | @@ -128,11 +156,25 @@ void *kmap_atomic_pfn(unsigned long pfn, |
da5b3fc8 | 10073 | enum fixed_addresses idx; |
10074 | unsigned long vaddr; | |
10075 | ||
10076 | +#ifdef CONFIG_PAX_KERNEXEC | |
10077 | + unsigned long cr0; | |
10078 | +#endif | |
10079 | + | |
10080 | pagefault_disable(); | |
10081 | ||
10082 | idx = type + KM_TYPE_NR*smp_processor_id(); | |
10083 | vaddr = __fix_to_virt(FIX_KMAP_BEGIN + idx); | |
10084 | + | |
10085 | +#ifdef CONFIG_PAX_KERNEXEC | |
10086 | + pax_open_kernel(cr0); | |
10087 | +#endif | |
50425a20 | 10088 | + |
da5b3fc8 | 10089 | set_pte(kmap_pte-idx, pfn_pte(pfn, kmap_prot)); |
50425a20 | 10090 | + |
da5b3fc8 | 10091 | +#ifdef CONFIG_PAX_KERNEXEC |
10092 | + pax_close_kernel(cr0); | |
10093 | +#endif | |
50425a20 | 10094 | + |
da5b3fc8 | 10095 | arch_flush_lazy_mmu_mode(); |
10096 | ||
10097 | return (void*) vaddr; | |
4dee9bd5 | 10098 | diff -urNp linux-2.6.25.4/arch/x86/mm/hugetlbpage.c linux-2.6.25.4/arch/x86/mm/hugetlbpage.c |
10099 | --- linux-2.6.25.4/arch/x86/mm/hugetlbpage.c 2008-05-15 11:00:12.000000000 -0400 | |
10100 | +++ linux-2.6.25.4/arch/x86/mm/hugetlbpage.c 2008-05-18 13:33:15.000000000 -0400 | |
10101 | @@ -230,13 +230,18 @@ static unsigned long hugetlb_get_unmappe | |
da5b3fc8 | 10102 | { |
10103 | struct mm_struct *mm = current->mm; | |
10104 | struct vm_area_struct *vma; | |
10105 | - unsigned long start_addr; | |
b7f09679 | 10106 | + unsigned long start_addr, pax_task_size = TASK_SIZE; |
50425a20 | 10107 | + |
da5b3fc8 | 10108 | +#ifdef CONFIG_PAX_SEGMEXEC |
10109 | + if (mm->pax_flags & MF_PAX_SEGMEXEC) | |
b7f09679 | 10110 | + pax_task_size = SEGMEXEC_TASK_SIZE; |
50425a20 | 10111 | +#endif |
da5b3fc8 | 10112 | |
10113 | if (len > mm->cached_hole_size) { | |
10114 | - start_addr = mm->free_area_cache; | |
10115 | + start_addr = mm->free_area_cache; | |
10116 | } else { | |
10117 | - start_addr = TASK_UNMAPPED_BASE; | |
10118 | - mm->cached_hole_size = 0; | |
10119 | + start_addr = mm->mmap_base; | |
10120 | + mm->cached_hole_size = 0; | |
10121 | } | |
10122 | ||
10123 | full_search: | |
4dee9bd5 | 10124 | @@ -244,13 +249,13 @@ full_search: |
da5b3fc8 | 10125 | |
10126 | for (vma = find_vma(mm, addr); ; vma = vma->vm_next) { | |
10127 | /* At this point: (!vma || addr < vma->vm_end). */ | |
10128 | - if (TASK_SIZE - len < addr) { | |
b7f09679 | 10129 | + if (pax_task_size - len < addr) { |
da5b3fc8 | 10130 | /* |
10131 | * Start a new search - just in case we missed | |
10132 | * some holes. | |
10133 | */ | |
10134 | - if (start_addr != TASK_UNMAPPED_BASE) { | |
10135 | - start_addr = TASK_UNMAPPED_BASE; | |
10136 | + if (start_addr != mm->mmap_base) { | |
10137 | + start_addr = mm->mmap_base; | |
10138 | mm->cached_hole_size = 0; | |
10139 | goto full_search; | |
10140 | } | |
4dee9bd5 | 10141 | @@ -272,9 +277,8 @@ static unsigned long hugetlb_get_unmappe |
da5b3fc8 | 10142 | { |
10143 | struct mm_struct *mm = current->mm; | |
10144 | struct vm_area_struct *vma, *prev_vma; | |
10145 | - unsigned long base = mm->mmap_base, addr = addr0; | |
10146 | + unsigned long base = mm->mmap_base, addr; | |
10147 | unsigned long largest_hole = mm->cached_hole_size; | |
10148 | - int first_time = 1; | |
10149 | ||
10150 | /* don't allow allocations above current base */ | |
10151 | if (mm->free_area_cache > base) | |
4dee9bd5 | 10152 | @@ -284,7 +288,7 @@ static unsigned long hugetlb_get_unmappe |
da5b3fc8 | 10153 | largest_hole = 0; |
10154 | mm->free_area_cache = base; | |
10155 | } | |
10156 | -try_again: | |
50425a20 | 10157 | + |
da5b3fc8 | 10158 | /* make sure it can fit in the remaining address space */ |
10159 | if (mm->free_area_cache < len) | |
10160 | goto fail; | |
4dee9bd5 | 10161 | @@ -326,22 +330,26 @@ try_again: |
da5b3fc8 | 10162 | |
10163 | fail: | |
10164 | /* | |
10165 | - * if hint left us with no space for the requested | |
10166 | - * mapping then try again: | |
10167 | - */ | |
10168 | - if (first_time) { | |
10169 | - mm->free_area_cache = base; | |
10170 | - largest_hole = 0; | |
10171 | - first_time = 0; | |
10172 | - goto try_again; | |
10173 | - } | |
10174 | - /* | |
10175 | * A failed mmap() very likely causes application failure, | |
10176 | * so fall back to the bottom-up function here. This scenario | |
10177 | * can happen with large stack limits and large mmap() | |
10178 | * allocations. | |
10179 | */ | |
10180 | - mm->free_area_cache = TASK_UNMAPPED_BASE; | |
50425a20 | 10181 | + |
da5b3fc8 | 10182 | +#ifdef CONFIG_PAX_SEGMEXEC |
10183 | + if (mm->pax_flags & MF_PAX_SEGMEXEC) | |
10184 | + mm->mmap_base = SEGMEXEC_TASK_UNMAPPED_BASE; | |
10185 | + else | |
10186 | +#endif | |
50425a20 | 10187 | + |
da5b3fc8 | 10188 | + mm->mmap_base = TASK_UNMAPPED_BASE; |
10189 | + | |
10190 | +#ifdef CONFIG_PAX_RANDMMAP | |
10191 | + if (mm->pax_flags & MF_PAX_RANDMMAP) | |
10192 | + mm->mmap_base += mm->delta_mmap; | |
50425a20 | 10193 | +#endif |
10194 | + | |
da5b3fc8 | 10195 | + mm->free_area_cache = mm->mmap_base; |
10196 | mm->cached_hole_size = ~0UL; | |
10197 | addr = hugetlb_get_unmapped_area_bottomup(file, addr0, | |
10198 | len, pgoff, flags); | |
4dee9bd5 | 10199 | @@ -349,6 +357,7 @@ fail: |
da5b3fc8 | 10200 | /* |
10201 | * Restore the topdown base: | |
10202 | */ | |
10203 | + mm->mmap_base = base; | |
10204 | mm->free_area_cache = base; | |
10205 | mm->cached_hole_size = ~0UL; | |
10206 | ||
4dee9bd5 | 10207 | @@ -361,10 +370,17 @@ hugetlb_get_unmapped_area(struct file *f |
50425a20 | 10208 | { |
da5b3fc8 | 10209 | struct mm_struct *mm = current->mm; |
10210 | struct vm_area_struct *vma; | |
b7f09679 | 10211 | + unsigned long pax_task_size = TASK_SIZE; |
da5b3fc8 | 10212 | |
10213 | if (len & ~HPAGE_MASK) | |
10214 | return -EINVAL; | |
10215 | - if (len > TASK_SIZE) | |
50425a20 | 10216 | + |
da5b3fc8 | 10217 | +#ifdef CONFIG_PAX_SEGMEXEC |
10218 | + if (mm->pax_flags & MF_PAX_SEGMEXEC) | |
b7f09679 | 10219 | + pax_task_size = SEGMEXEC_TASK_SIZE; |
da5b3fc8 | 10220 | +#endif |
50425a20 | 10221 | + |
b7f09679 | 10222 | + if (len > pax_task_size) |
da5b3fc8 | 10223 | return -ENOMEM; |
10224 | ||
10225 | if (flags & MAP_FIXED) { | |
4dee9bd5 | 10226 | @@ -376,7 +392,7 @@ hugetlb_get_unmapped_area(struct file *f |
da5b3fc8 | 10227 | if (addr) { |
10228 | addr = ALIGN(addr, HPAGE_SIZE); | |
10229 | vma = find_vma(mm, addr); | |
10230 | - if (TASK_SIZE - len >= addr && | |
b7f09679 | 10231 | + if (pax_task_size - len >= addr && |
da5b3fc8 | 10232 | (!vma || addr + len <= vma->vm_start)) |
10233 | return addr; | |
10234 | } | |
4dee9bd5 | 10235 | diff -urNp linux-2.6.25.4/arch/x86/mm/init_32.c linux-2.6.25.4/arch/x86/mm/init_32.c |
10236 | --- linux-2.6.25.4/arch/x86/mm/init_32.c 2008-05-15 11:00:12.000000000 -0400 | |
10237 | +++ linux-2.6.25.4/arch/x86/mm/init_32.c 2008-05-18 13:33:15.000000000 -0400 | |
10238 | @@ -48,6 +48,7 @@ | |
da5b3fc8 | 10239 | #include <asm/paravirt.h> |
4dee9bd5 | 10240 | #include <asm/setup.h> |
10241 | #include <asm/cacheflush.h> | |
da5b3fc8 | 10242 | +#include <asm/desc.h> |
10243 | ||
10244 | unsigned int __VMALLOC_RESERVE = 128 << 20; | |
10245 | ||
4dee9bd5 | 10246 | @@ -57,32 +58,6 @@ unsigned long highstart_pfn, highend_pfn |
10247 | static noinline int do_test_wp_bit(void); | |
da5b3fc8 | 10248 | |
10249 | /* | |
10250 | - * Creates a middle page table and puts a pointer to it in the | |
10251 | - * given global directory entry. This only returns the gd entry | |
10252 | - * in non-PAE compilation mode, since the middle layer is folded. | |
10253 | - */ | |
10254 | -static pmd_t * __init one_md_table_init(pgd_t *pgd) | |
10255 | -{ | |
10256 | - pud_t *pud; | |
10257 | - pmd_t *pmd_table; | |
4dee9bd5 | 10258 | - |
da5b3fc8 | 10259 | -#ifdef CONFIG_X86_PAE |
10260 | - if (!(pgd_val(*pgd) & _PAGE_PRESENT)) { | |
10261 | - pmd_table = (pmd_t *) alloc_bootmem_low_pages(PAGE_SIZE); | |
10262 | - | |
4dee9bd5 | 10263 | - paravirt_alloc_pd(&init_mm, __pa(pmd_table) >> PAGE_SHIFT); |
da5b3fc8 | 10264 | - set_pgd(pgd, __pgd(__pa(pmd_table) | _PAGE_PRESENT)); |
10265 | - pud = pud_offset(pgd, 0); | |
4dee9bd5 | 10266 | - BUG_ON(pmd_table != pmd_offset(pud, 0)); |
da5b3fc8 | 10267 | - } |
10268 | -#endif | |
10269 | - pud = pud_offset(pgd, 0); | |
10270 | - pmd_table = pmd_offset(pud, 0); | |
4dee9bd5 | 10271 | - |
da5b3fc8 | 10272 | - return pmd_table; |
10273 | -} | |
10274 | - | |
10275 | -/* | |
10276 | * Create a page table and place a pointer to it in a middle page | |
4dee9bd5 | 10277 | * directory entry: |
da5b3fc8 | 10278 | */ |
4dee9bd5 | 10279 | @@ -100,7 +75,11 @@ static pte_t * __init one_page_table_ini |
10280 | } | |
da5b3fc8 | 10281 | |
10282 | paravirt_alloc_pt(&init_mm, __pa(page_table) >> PAGE_SHIFT); | |
10283 | +#if defined(CONFIG_PAX_PAGEEXEC) || defined(CONFIG_PAX_SEGMEXEC) | |
10284 | + set_pmd(pmd, __pmd(__pa(page_table) | _KERNPG_TABLE)); | |
10285 | +#else | |
10286 | set_pmd(pmd, __pmd(__pa(page_table) | _PAGE_TABLE)); | |
10287 | +#endif | |
10288 | BUG_ON(page_table != pte_offset_kernel(pmd, 0)); | |
10289 | } | |
10290 | ||
4dee9bd5 | 10291 | @@ -122,6 +101,7 @@ page_table_range_init(unsigned long star |
10292 | int pgd_idx, pmd_idx; | |
10293 | unsigned long vaddr; | |
da5b3fc8 | 10294 | pgd_t *pgd; |
10295 | + pud_t *pud; | |
10296 | pmd_t *pmd; | |
4dee9bd5 | 10297 | |
10298 | vaddr = start; | |
10299 | @@ -130,8 +110,13 @@ page_table_range_init(unsigned long star | |
da5b3fc8 | 10300 | pgd = pgd_base + pgd_idx; |
10301 | ||
10302 | for ( ; (pgd_idx < PTRS_PER_PGD) && (vaddr != end); pgd++, pgd_idx++) { | |
10303 | - pmd = one_md_table_init(pgd); | |
10304 | - pmd = pmd + pmd_index(vaddr); | |
10305 | + pud = pud_offset(pgd, vaddr); | |
10306 | + pmd = pmd_offset(pud, vaddr); | |
10307 | + | |
10308 | +#ifdef CONFIG_X86_PAE | |
4dee9bd5 | 10309 | + paravirt_alloc_pd(&init_mm, __pa(pmd) >> PAGE_SHIFT); |
50425a20 | 10310 | +#endif |
10311 | + | |
4dee9bd5 | 10312 | for (; (pmd_idx < PTRS_PER_PMD) && (vaddr != end); |
10313 | pmd++, pmd_idx++) { | |
da5b3fc8 | 10314 | one_page_table_init(pmd); |
4dee9bd5 | 10315 | @@ -142,11 +127,23 @@ page_table_range_init(unsigned long star |
da5b3fc8 | 10316 | } |
10317 | } | |
10318 | ||
10319 | -static inline int is_kernel_text(unsigned long addr) | |
10320 | +static inline int is_kernel_text(unsigned long start, unsigned long end) | |
10321 | { | |
10322 | - if (addr >= PAGE_OFFSET && addr <= (unsigned long)__init_end) | |
10323 | - return 1; | |
10324 | - return 0; | |
10325 | + unsigned long etext; | |
10326 | + | |
10327 | +#if defined(CONFIG_MODULES) && defined(CONFIG_PAX_KERNEXEC) | |
10328 | + etext = ktva_ktla((unsigned long)&MODULES_END); | |
10329 | +#else | |
10330 | + etext = (unsigned long)&_etext; | |
50425a20 | 10331 | +#endif |
10332 | + | |
da5b3fc8 | 10333 | + if ((start > ktla_ktva(etext) || |
10334 | + end <= ktla_ktva((unsigned long)_stext)) && | |
10335 | + (start > ktla_ktva((unsigned long)_einittext) || | |
10336 | + end <= ktla_ktva((unsigned long)_sinittext)) && | |
10337 | + (start > (unsigned long)__va(0xfffff) || end <= (unsigned long)__va(0xc0000))) | |
10338 | + return 0; | |
10339 | + return 1; | |
10340 | } | |
50425a20 | 10341 | |
da5b3fc8 | 10342 | /* |
4dee9bd5 | 10343 | @@ -156,9 +153,10 @@ static inline int is_kernel_text(unsigne |
10344 | */ | |
10345 | static void __init kernel_physical_mapping_init(pgd_t *pgd_base) | |
da5b3fc8 | 10346 | { |
4dee9bd5 | 10347 | - int pgd_idx, pmd_idx, pte_ofs; |
10348 | + unsigned int pgd_idx, pmd_idx, pte_ofs; | |
da5b3fc8 | 10349 | unsigned long pfn; |
10350 | pgd_t *pgd; | |
10351 | + pud_t *pud; | |
10352 | pmd_t *pmd; | |
10353 | pte_t *pte; | |
da5b3fc8 | 10354 | |
4dee9bd5 | 10355 | @@ -166,29 +164,27 @@ static void __init kernel_physical_mappi |
da5b3fc8 | 10356 | pgd = pgd_base + pgd_idx; |
10357 | pfn = 0; | |
10358 | ||
10359 | - for (; pgd_idx < PTRS_PER_PGD; pgd++, pgd_idx++) { | |
10360 | - pmd = one_md_table_init(pgd); | |
10361 | - if (pfn >= max_low_pfn) | |
10362 | - continue; | |
10363 | + for (; pgd_idx < PTRS_PER_PGD && pfn < max_low_pfn; pgd++, pgd_idx++) { | |
10364 | + pud = pud_offset(pgd, 0); | |
10365 | + pmd = pmd_offset(pud, 0); | |
50425a20 | 10366 | + |
da5b3fc8 | 10367 | +#ifdef CONFIG_X86_PAE |
4dee9bd5 | 10368 | + paravirt_alloc_pd(&init_mm, __pa(pmd) >> PAGE_SHIFT); |
50425a20 | 10369 | +#endif |
4dee9bd5 | 10370 | |
10371 | for (pmd_idx = 0; | |
10372 | pmd_idx < PTRS_PER_PMD && pfn < max_low_pfn; | |
10373 | pmd++, pmd_idx++) { | |
10374 | - unsigned int addr = pfn * PAGE_SIZE + PAGE_OFFSET; | |
da5b3fc8 | 10375 | + unsigned long address = pfn * PAGE_SIZE + PAGE_OFFSET; |
50425a20 | 10376 | |
4dee9bd5 | 10377 | /* |
10378 | * Map with big pages if possible, otherwise | |
10379 | * create normal page tables: | |
10380 | */ | |
da5b3fc8 | 10381 | - if (cpu_has_pse) { |
4dee9bd5 | 10382 | - unsigned int addr2; |
da5b3fc8 | 10383 | + if (cpu_has_pse && address >= (unsigned long)__va(0x100000)) { |
4dee9bd5 | 10384 | pgprot_t prot = PAGE_KERNEL_LARGE; |
10385 | ||
10386 | - addr2 = (pfn + PTRS_PER_PTE-1) * PAGE_SIZE + | |
10387 | - PAGE_OFFSET + PAGE_SIZE-1; | |
10388 | - | |
10389 | - if (is_kernel_text(addr) || | |
10390 | - is_kernel_text(addr2)) | |
da5b3fc8 | 10391 | + if (is_kernel_text(address, address + PMD_SIZE)) |
4dee9bd5 | 10392 | prot = PAGE_KERNEL_LARGE_EXEC; |
10393 | ||
10394 | set_pmd(pmd, pfn_pmd(pfn, prot)); | |
10395 | @@ -200,10 +196,10 @@ static void __init kernel_physical_mappi | |
10396 | ||
10397 | for (pte_ofs = 0; | |
10398 | pte_ofs < PTRS_PER_PTE && pfn < max_low_pfn; | |
10399 | - pte++, pfn++, pte_ofs++, addr += PAGE_SIZE) { | |
10400 | + pte++, pfn++, pte_ofs++, address += PAGE_SIZE) { | |
10401 | pgprot_t prot = PAGE_KERNEL; | |
10402 | ||
10403 | - if (is_kernel_text(addr)) | |
10404 | + if (is_kernel_text(address, address + PAGE_SIZE)) | |
10405 | prot = PAGE_KERNEL_EXEC; | |
10406 | ||
10407 | set_pte(pte, pfn_pte(pfn, prot)); | |
10408 | @@ -323,10 +319,10 @@ static void __init set_highmem_pages_ini | |
10409 | # define set_highmem_pages_init(bad_ppro) do { } while (0) | |
da5b3fc8 | 10410 | #endif /* CONFIG_HIGHMEM */ |
50425a20 | 10411 | |
4dee9bd5 | 10412 | -pteval_t __PAGE_KERNEL = _PAGE_KERNEL; |
10413 | +pteval_t __PAGE_KERNEL __read_only = _PAGE_KERNEL; | |
da5b3fc8 | 10414 | EXPORT_SYMBOL(__PAGE_KERNEL); |
50425a20 | 10415 | |
4dee9bd5 | 10416 | -pteval_t __PAGE_KERNEL_EXEC = _PAGE_KERNEL_EXEC; |
10417 | +pteval_t __PAGE_KERNEL_EXEC __read_only = _PAGE_KERNEL_EXEC; | |
10418 | ||
da5b3fc8 | 10419 | void __init native_pagetable_setup_start(pgd_t *base) |
10420 | { | |
4dee9bd5 | 10421 | @@ -348,7 +344,7 @@ void __init native_pagetable_setup_start |
da5b3fc8 | 10422 | |
4dee9bd5 | 10423 | pud = pud_offset(pgd, va); |
10424 | pmd = pmd_offset(pud, va); | |
10425 | - if (!pmd_present(*pmd)) | |
10426 | + if (!pmd_present(*pmd) || pmd_huge(*pmd)) | |
10427 | break; | |
da5b3fc8 | 10428 | |
4dee9bd5 | 10429 | pte = pte_offset_kernel(pmd, va); |
10430 | @@ -424,12 +420,12 @@ static void __init pagetable_init(void) | |
10431 | * ACPI suspend needs this for resume, because things like the intel-agp | |
da5b3fc8 | 10432 | * driver might have split up a kernel 4MB mapping. |
10433 | */ | |
4dee9bd5 | 10434 | -char swsusp_pg_dir[PAGE_SIZE] |
10435 | +pgd_t swsusp_pg_dir[PTRS_PER_PGD] | |
10436 | __attribute__ ((aligned(PAGE_SIZE))); | |
da5b3fc8 | 10437 | |
10438 | static inline void save_pg_dir(void) | |
10439 | { | |
10440 | - memcpy(swsusp_pg_dir, swapper_pg_dir, PAGE_SIZE); | |
10441 | + clone_pgd_range(swsusp_pg_dir, swapper_pg_dir, PTRS_PER_PGD); | |
10442 | } | |
4dee9bd5 | 10443 | #else /* !CONFIG_ACPI_SLEEP */ |
da5b3fc8 | 10444 | static inline void save_pg_dir(void) |
4dee9bd5 | 10445 | @@ -461,13 +457,11 @@ void zap_low_mappings(void) |
da5b3fc8 | 10446 | |
4dee9bd5 | 10447 | int nx_enabled; |
da5b3fc8 | 10448 | |
4dee9bd5 | 10449 | -pteval_t __supported_pte_mask __read_mostly = ~_PAGE_NX; |
10450 | +pteval_t __supported_pte_mask __read_only = ~_PAGE_NX; | |
da5b3fc8 | 10451 | EXPORT_SYMBOL_GPL(__supported_pte_mask); |
10452 | ||
4dee9bd5 | 10453 | #ifdef CONFIG_X86_PAE |
10454 | ||
10455 | -static int disable_nx __initdata; | |
10456 | - | |
da5b3fc8 | 10457 | /* |
4dee9bd5 | 10458 | * noexec = on|off |
10459 | * | |
10460 | @@ -476,40 +470,33 @@ static int disable_nx __initdata; | |
da5b3fc8 | 10461 | * on Enable |
10462 | * off Disable | |
10463 | */ | |
10464 | +#if !defined(CONFIG_PAX_PAGEEXEC) | |
10465 | static int __init noexec_setup(char *str) | |
10466 | { | |
10467 | if (!str || !strcmp(str, "on")) { | |
10468 | - if (cpu_has_nx) { | |
10469 | - __supported_pte_mask |= _PAGE_NX; | |
10470 | - disable_nx = 0; | |
10471 | - } | |
10472 | + if (cpu_has_nx) | |
10473 | + nx_enabled = 1; | |
4dee9bd5 | 10474 | } else { |
10475 | - if (!strcmp(str, "off")) { | |
10476 | - disable_nx = 1; | |
10477 | - __supported_pte_mask &= ~_PAGE_NX; | |
10478 | - } else { | |
10479 | + if (!strcmp(str, "off")) | |
10480 | + nx_enabled = 0; | |
10481 | + else | |
10482 | return -EINVAL; | |
10483 | - } | |
10484 | } | |
10485 | ||
10486 | return 0; | |
da5b3fc8 | 10487 | } |
10488 | early_param("noexec", noexec_setup); | |
50425a20 | 10489 | +#endif |
da5b3fc8 | 10490 | |
10491 | static void __init set_nx(void) | |
10492 | { | |
10493 | - unsigned int v[4], l, h; | |
4dee9bd5 | 10494 | - |
10495 | - if (cpu_has_pae && (cpuid_eax(0x80000000) > 0x80000001)) { | |
10496 | - cpuid(0x80000001, &v[0], &v[1], &v[2], &v[3]); | |
da5b3fc8 | 10497 | + if (!nx_enabled && cpu_has_nx) { |
10498 | + unsigned l, h; | |
10499 | ||
da5b3fc8 | 10500 | - if ((v[3] & (1 << 20)) && !disable_nx) { |
10501 | - rdmsr(MSR_EFER, l, h); | |
10502 | - l |= EFER_NX; | |
10503 | - wrmsr(MSR_EFER, l, h); | |
10504 | - nx_enabled = 1; | |
10505 | - __supported_pte_mask |= _PAGE_NX; | |
10506 | - } | |
10507 | + __supported_pte_mask &= ~_PAGE_NX; | |
10508 | + rdmsr(MSR_EFER, l, h); | |
10509 | + l &= ~EFER_NX; | |
10510 | + wrmsr(MSR_EFER, l, h); | |
50425a20 | 10511 | } |
da5b3fc8 | 10512 | } |
4dee9bd5 | 10513 | #endif |
10514 | @@ -601,7 +588,7 @@ void __init mem_init(void) | |
da5b3fc8 | 10515 | set_highmem_pages_init(bad_ppro); |
10516 | ||
10517 | codesize = (unsigned long) &_etext - (unsigned long) &_text; | |
10518 | - datasize = (unsigned long) &_edata - (unsigned long) &_etext; | |
10519 | + datasize = (unsigned long) &_edata - (unsigned long) &_data; | |
10520 | initsize = (unsigned long) &__init_end - (unsigned long) &__init_begin; | |
50425a20 | 10521 | |
4dee9bd5 | 10522 | kclist_add(&kcore_mem, __va(0), max_low_pfn << PAGE_SHIFT); |
10523 | @@ -648,10 +635,10 @@ void __init mem_init(void) | |
10524 | ((unsigned long)&__init_end - | |
10525 | (unsigned long)&__init_begin) >> 10, | |
50425a20 | 10526 | |
4dee9bd5 | 10527 | - (unsigned long)&_etext, (unsigned long)&_edata, |
10528 | - ((unsigned long)&_edata - (unsigned long)&_etext) >> 10, | |
10529 | + (unsigned long)&_data, (unsigned long)&_edata, | |
10530 | + ((unsigned long)&_edata - (unsigned long)&_data) >> 10, | |
50425a20 | 10531 | |
4dee9bd5 | 10532 | - (unsigned long)&_text, (unsigned long)&_etext, |
10533 | + ktla_ktva((unsigned long)&_text), ktla_ktva((unsigned long)&_etext), | |
10534 | ((unsigned long)&_etext - (unsigned long)&_text) >> 10); | |
50425a20 | 10535 | |
da5b3fc8 | 10536 | #ifdef CONFIG_HIGHMEM |
4dee9bd5 | 10537 | @@ -794,6 +781,46 @@ void free_init_pages(char *what, unsigne |
da5b3fc8 | 10538 | |
10539 | void free_initmem(void) | |
10540 | { | |
50425a20 | 10541 | + |
da5b3fc8 | 10542 | +#ifdef CONFIG_PAX_KERNEXEC |
10543 | + /* PaX: limit KERNEL_CS to actual size */ | |
10544 | + unsigned long addr, limit; | |
4dee9bd5 | 10545 | + struct desc_struct d; |
da5b3fc8 | 10546 | + int cpu; |
10547 | + pgd_t *pgd; | |
10548 | + pud_t *pud; | |
10549 | + pmd_t *pmd; | |
50425a20 | 10550 | + |
da5b3fc8 | 10551 | +#ifdef CONFIG_MODULES |
10552 | + limit = ktva_ktla((unsigned long)&MODULES_END); | |
10553 | +#else | |
10554 | + limit = (unsigned long)&_etext; | |
50425a20 | 10555 | +#endif |
da5b3fc8 | 10556 | + limit = (limit - 1UL) >> PAGE_SHIFT; |
50425a20 | 10557 | + |
da5b3fc8 | 10558 | + for (cpu = 0; cpu < NR_CPUS; cpu++) { |
4dee9bd5 | 10559 | + pack_descriptor(&d, get_desc_base(&get_cpu_gdt_table(cpu)[GDT_ENTRY_KERNEL_CS]), limit, 0x9B, 0xC); |
10560 | + write_gdt_entry(get_cpu_gdt_table(cpu), GDT_ENTRY_KERNEL_CS, &d, DESCTYPE_S); | |
50425a20 | 10561 | + } |
10562 | + | |
da5b3fc8 | 10563 | + /* PaX: make KERNEL_CS read-only */ |
10564 | + for (addr = ktla_ktva((unsigned long)&_text); addr < (unsigned long)&_data; addr += PMD_SIZE) { | |
10565 | + pgd = pgd_offset_k(addr); | |
10566 | + pud = pud_offset(pgd, addr); | |
10567 | + pmd = pmd_offset(pud, addr); | |
10568 | + set_pmd(pmd, __pmd(pmd_val(*pmd) & ~_PAGE_RW)); | |
10569 | + } | |
10570 | +#ifdef CONFIG_X86_PAE | |
10571 | + for (addr = (unsigned long)&__init_begin; addr < (unsigned long)&__init_end; addr += PMD_SIZE) { | |
10572 | + pgd = pgd_offset_k(addr); | |
10573 | + pud = pud_offset(pgd, addr); | |
10574 | + pmd = pmd_offset(pud, addr); | |
10575 | + set_pmd(pmd, __pmd(pmd_val(*pmd) | (_PAGE_NX & __supported_pte_mask))); | |
10576 | + } | |
10577 | +#endif | |
10578 | + flush_tlb_all(); | |
10579 | +#endif | |
50425a20 | 10580 | + |
da5b3fc8 | 10581 | free_init_pages("unused kernel memory", |
10582 | (unsigned long)(&__init_begin), | |
10583 | (unsigned long)(&__init_end)); | |
4dee9bd5 | 10584 | diff -urNp linux-2.6.25.4/arch/x86/mm/init_64.c linux-2.6.25.4/arch/x86/mm/init_64.c |
10585 | --- linux-2.6.25.4/arch/x86/mm/init_64.c 2008-05-15 11:00:12.000000000 -0400 | |
10586 | +++ linux-2.6.25.4/arch/x86/mm/init_64.c 2008-05-18 13:33:15.000000000 -0400 | |
10587 | @@ -129,6 +129,10 @@ set_pte_phys(unsigned long vaddr, unsign | |
da5b3fc8 | 10588 | pmd_t *pmd; |
10589 | pte_t *pte, new_pte; | |
10590 | ||
10591 | +#ifdef CONFIG_PAX_KERNEXEC | |
10592 | + unsigned long cr0; | |
10593 | +#endif | |
50425a20 | 10594 | + |
4dee9bd5 | 10595 | pr_debug("set_pte_phys %lx to %lx\n", vaddr, phys); |
da5b3fc8 | 10596 | |
10597 | pgd = pgd_offset_k(vaddr); | |
4dee9bd5 | 10598 | @@ -140,7 +144,7 @@ set_pte_phys(unsigned long vaddr, unsign |
da5b3fc8 | 10599 | pud = pud_offset(pgd, vaddr); |
10600 | if (pud_none(*pud)) { | |
4dee9bd5 | 10601 | pmd = (pmd_t *) spp_getpage(); |
da5b3fc8 | 10602 | - set_pud(pud, __pud(__pa(pmd) | _KERNPG_TABLE | _PAGE_USER)); |
10603 | + set_pud(pud, __pud(__pa(pmd) | _PAGE_TABLE)); | |
10604 | if (pmd != pmd_offset(pud, 0)) { | |
4dee9bd5 | 10605 | printk(KERN_ERR "PAGETABLE BUG #01! %p <-> %p\n", |
10606 | pmd, pmd_offset(pud, 0)); | |
10607 | @@ -150,7 +154,7 @@ set_pte_phys(unsigned long vaddr, unsign | |
da5b3fc8 | 10608 | pmd = pmd_offset(pud, vaddr); |
10609 | if (pmd_none(*pmd)) { | |
10610 | pte = (pte_t *) spp_getpage(); | |
10611 | - set_pmd(pmd, __pmd(__pa(pte) | _KERNPG_TABLE | _PAGE_USER)); | |
10612 | + set_pmd(pmd, __pmd(__pa(pte) | _PAGE_TABLE)); | |
10613 | if (pte != pte_offset_kernel(pmd, 0)) { | |
4dee9bd5 | 10614 | printk(KERN_ERR "PAGETABLE BUG #02!\n"); |
da5b3fc8 | 10615 | return; |
4dee9bd5 | 10616 | @@ -162,8 +166,17 @@ set_pte_phys(unsigned long vaddr, unsign |
da5b3fc8 | 10617 | if (!pte_none(*pte) && |
10618 | pte_val(*pte) != (pte_val(new_pte) & __supported_pte_mask)) | |
10619 | pte_ERROR(*pte); | |
50425a20 | 10620 | + |
da5b3fc8 | 10621 | +#ifdef CONFIG_PAX_KERNEXEC |
10622 | + pax_open_kernel(cr0); | |
10623 | +#endif | |
50425a20 | 10624 | + |
da5b3fc8 | 10625 | set_pte(pte, new_pte); |
10626 | ||
10627 | +#ifdef CONFIG_PAX_KERNEXEC | |
10628 | + pax_close_kernel(cr0); | |
10629 | +#endif | |
50425a20 | 10630 | + |
da5b3fc8 | 10631 | /* |
10632 | * It's enough to flush this one mapping. | |
10633 | * (PGE mappings get flushed as well) | |
4dee9bd5 | 10634 | @@ -585,6 +598,39 @@ void free_init_pages(char *what, unsigne |
da5b3fc8 | 10635 | |
10636 | void free_initmem(void) | |
10637 | { | |
50425a20 | 10638 | + |
da5b3fc8 | 10639 | +#ifdef CONFIG_PAX_KERNEXEC |
10640 | + unsigned long addr, end; | |
10641 | + pgd_t *pgd; | |
10642 | + pud_t *pud; | |
10643 | + pmd_t *pmd; | |
50425a20 | 10644 | + |
da5b3fc8 | 10645 | + /* PaX: make kernel code/rodata read-only, rest non-executable */ |
4dee9bd5 | 10646 | + for (addr = __START_KERNEL_map; addr < __START_KERNEL_map + KERNEL_IMAGE_SIZE; addr += PMD_SIZE) { |
da5b3fc8 | 10647 | + pgd = pgd_offset_k(addr); |
10648 | + pud = pud_offset(pgd, addr); | |
10649 | + pmd = pmd_offset(pud, addr); | |
10650 | + if ((unsigned long)_text <= addr && addr < (unsigned long)_data) | |
10651 | + set_pmd(pmd, __pmd(pmd_val(*pmd) & ~_PAGE_RW)); | |
10652 | + else | |
10653 | + set_pmd(pmd, __pmd(pmd_val(*pmd) | (_PAGE_NX & __supported_pte_mask))); | |
10654 | + } | |
50425a20 | 10655 | + |
da5b3fc8 | 10656 | + addr = (unsigned long)__va(__pa(__START_KERNEL_map)); |
4dee9bd5 | 10657 | + end = addr + KERNEL_IMAGE_SIZE; |
da5b3fc8 | 10658 | + for (; addr < end; addr += PMD_SIZE) { |
10659 | + pgd = pgd_offset_k(addr); | |
10660 | + pud = pud_offset(pgd, addr); | |
10661 | + pmd = pmd_offset(pud, addr); | |
10662 | + if ((unsigned long)__va(__pa(_text)) <= addr && addr < (unsigned long)__va(__pa(_data))) | |
10663 | + set_pmd(pmd, __pmd(pmd_val(*pmd) & ~_PAGE_RW)); | |
10664 | + else | |
10665 | + set_pmd(pmd, __pmd(pmd_val(*pmd) | (_PAGE_NX & __supported_pte_mask))); | |
10666 | + } | |
50425a20 | 10667 | + |
da5b3fc8 | 10668 | + flush_tlb_all(); |
10669 | +#endif | |
50425a20 | 10670 | + |
da5b3fc8 | 10671 | free_init_pages("unused kernel memory", |
10672 | (unsigned long)(&__init_begin), | |
10673 | (unsigned long)(&__init_end)); | |
4dee9bd5 | 10674 | @@ -753,7 +799,7 @@ int in_gate_area_no_task(unsigned long a |
da5b3fc8 | 10675 | |
10676 | const char *arch_vma_name(struct vm_area_struct *vma) | |
10677 | { | |
10678 | - if (vma->vm_mm && vma->vm_start == (long)vma->vm_mm->context.vdso) | |
10679 | + if (vma->vm_mm && vma->vm_start == vma->vm_mm->context.vdso) | |
10680 | return "[vdso]"; | |
10681 | if (vma == &gate_vma) | |
10682 | return "[vsyscall]"; | |
4dee9bd5 | 10683 | diff -urNp linux-2.6.25.4/arch/x86/mm/ioremap.c linux-2.6.25.4/arch/x86/mm/ioremap.c |
10684 | --- linux-2.6.25.4/arch/x86/mm/ioremap.c 2008-05-15 11:00:12.000000000 -0400 | |
10685 | +++ linux-2.6.25.4/arch/x86/mm/ioremap.c 2008-05-18 13:33:15.000000000 -0400 | |
10686 | @@ -148,6 +148,8 @@ static void __iomem *__ioremap(resource_ | |
10687 | break; | |
da5b3fc8 | 10688 | } |
da5b3fc8 | 10689 | |
4dee9bd5 | 10690 | + prot = canon_pgprot(prot); |
50425a20 | 10691 | + |
da5b3fc8 | 10692 | /* |
10693 | * Mappings have to be page-aligned | |
10694 | */ | |
4dee9bd5 | 10695 | diff -urNp linux-2.6.25.4/arch/x86/mm/mmap.c linux-2.6.25.4/arch/x86/mm/mmap.c |
10696 | --- linux-2.6.25.4/arch/x86/mm/mmap.c 2008-05-15 11:00:12.000000000 -0400 | |
10697 | +++ linux-2.6.25.4/arch/x86/mm/mmap.c 2008-05-18 13:33:15.000000000 -0400 | |
10698 | @@ -36,7 +36,7 @@ | |
da5b3fc8 | 10699 | * Leave an at least ~128 MB hole. |
10700 | */ | |
10701 | #define MIN_GAP (128*1024*1024) | |
10702 | -#define MAX_GAP (TASK_SIZE/6*5) | |
b7f09679 | 10703 | +#define MAX_GAP (pax_task_size/6*5) |
da5b3fc8 | 10704 | |
4dee9bd5 | 10705 | /* |
10706 | * True on X86_32 or when emulating IA32 on X86_64 | |
10707 | @@ -81,27 +81,40 @@ static unsigned long mmap_rnd(void) | |
10708 | return rnd << PAGE_SHIFT; | |
10709 | } | |
10710 | ||
10711 | -static unsigned long mmap_base(void) | |
10712 | +static unsigned long mmap_base(struct mm_struct *mm) | |
da5b3fc8 | 10713 | { |
10714 | unsigned long gap = current->signal->rlim[RLIMIT_STACK].rlim_cur; | |
b7f09679 | 10715 | + unsigned long pax_task_size = TASK_SIZE; |
50425a20 | 10716 | + |
da5b3fc8 | 10717 | +#ifdef CONFIG_PAX_SEGMEXEC |
10718 | + if (mm->pax_flags & MF_PAX_SEGMEXEC) | |
b7f09679 | 10719 | + pax_task_size = SEGMEXEC_TASK_SIZE; |
da5b3fc8 | 10720 | +#endif |
10721 | ||
4dee9bd5 | 10722 | if (gap < MIN_GAP) |
10723 | gap = MIN_GAP; | |
da5b3fc8 | 10724 | else if (gap > MAX_GAP) |
10725 | gap = MAX_GAP; | |
10726 | ||
4dee9bd5 | 10727 | - return PAGE_ALIGN(TASK_SIZE - gap - mmap_rnd()); |
10728 | + return PAGE_ALIGN(pax_task_size - gap - mmap_rnd()); | |
da5b3fc8 | 10729 | } |
10730 | ||
10731 | /* | |
4dee9bd5 | 10732 | * Bottom-up (legacy) layout on X86_32 did not support randomization, X86_64 |
10733 | * does, but not when emulating X86_32 | |
10734 | */ | |
10735 | -static unsigned long mmap_legacy_base(void) | |
10736 | +static unsigned long mmap_legacy_base(struct mm_struct *mm) | |
10737 | { | |
10738 | - if (mmap_is_ia32()) | |
10739 | + if (mmap_is_ia32()) { | |
50425a20 | 10740 | + |
da5b3fc8 | 10741 | +#ifdef CONFIG_PAX_SEGMEXEC |
10742 | + if (mm->pax_flags & MF_PAX_SEGMEXEC) | |
4dee9bd5 | 10743 | + return SEGMEXEC_TASK_UNMAPPED_BASE; |
da5b3fc8 | 10744 | + else |
10745 | +#endif | |
50425a20 | 10746 | + |
4dee9bd5 | 10747 | return TASK_UNMAPPED_BASE; |
10748 | - else | |
10749 | + } else | |
10750 | return TASK_UNMAPPED_BASE + mmap_rnd(); | |
10751 | } | |
10752 | ||
10753 | @@ -112,11 +125,23 @@ static unsigned long mmap_legacy_base(vo | |
10754 | void arch_pick_mmap_layout(struct mm_struct *mm) | |
10755 | { | |
10756 | if (mmap_is_legacy()) { | |
10757 | - mm->mmap_base = mmap_legacy_base(); | |
10758 | + mm->mmap_base = mmap_legacy_base(mm); | |
50425a20 | 10759 | + |
da5b3fc8 | 10760 | +#ifdef CONFIG_PAX_RANDMMAP |
10761 | + if (mm->pax_flags & MF_PAX_RANDMMAP) | |
10762 | + mm->mmap_base += mm->delta_mmap; | |
10763 | +#endif | |
50425a20 | 10764 | + |
da5b3fc8 | 10765 | mm->get_unmapped_area = arch_get_unmapped_area; |
10766 | mm->unmap_area = arch_unmap_area; | |
10767 | } else { | |
4dee9bd5 | 10768 | - mm->mmap_base = mmap_base(); |
10769 | + mm->mmap_base = mmap_base(mm); | |
50425a20 | 10770 | + |
da5b3fc8 | 10771 | +#ifdef CONFIG_PAX_RANDMMAP |
10772 | + if (mm->pax_flags & MF_PAX_RANDMMAP) | |
10773 | + mm->mmap_base -= mm->delta_mmap + mm->delta_stack; | |
10774 | +#endif | |
50425a20 | 10775 | + |
da5b3fc8 | 10776 | mm->get_unmapped_area = arch_get_unmapped_area_topdown; |
10777 | mm->unmap_area = arch_unmap_area_topdown; | |
10778 | } | |
4dee9bd5 | 10779 | diff -urNp linux-2.6.25.4/arch/x86/mm/numa_64.c linux-2.6.25.4/arch/x86/mm/numa_64.c |
10780 | --- linux-2.6.25.4/arch/x86/mm/numa_64.c 2008-05-15 11:00:12.000000000 -0400 | |
10781 | +++ linux-2.6.25.4/arch/x86/mm/numa_64.c 2008-05-18 13:33:15.000000000 -0400 | |
10782 | @@ -21,7 +21,7 @@ | |
10783 | #include <asm/k8.h> | |
da5b3fc8 | 10784 | |
10785 | #ifndef Dprintk | |
10786 | -#define Dprintk(x...) | |
10787 | +#define Dprintk(x...) do {} while (0) | |
10788 | #endif | |
10789 | ||
10790 | struct pglist_data *node_data[MAX_NUMNODES] __read_mostly; | |
4dee9bd5 | 10791 | diff -urNp linux-2.6.25.4/arch/x86/mm/pageattr.c linux-2.6.25.4/arch/x86/mm/pageattr.c |
10792 | --- linux-2.6.25.4/arch/x86/mm/pageattr.c 2008-05-15 11:00:12.000000000 -0400 | |
10793 | +++ linux-2.6.25.4/arch/x86/mm/pageattr.c 2008-05-18 13:33:15.000000000 -0400 | |
10794 | @@ -17,6 +17,7 @@ | |
10795 | #include <asm/uaccess.h> | |
da5b3fc8 | 10796 | #include <asm/pgalloc.h> |
4dee9bd5 | 10797 | #include <asm/proto.h> |
da5b3fc8 | 10798 | +#include <asm/desc.h> |
10799 | ||
4dee9bd5 | 10800 | /* |
10801 | * The current flushing context - we pass it instead of 5 arguments: | |
10802 | @@ -168,7 +169,7 @@ static inline pgprot_t static_protection | |
10803 | * Does not cover __inittext since that is gone later on. On | |
10804 | * 64bit we do not enforce !NX on the low mapping | |
10805 | */ | |
10806 | - if (within(address, (unsigned long)_text, (unsigned long)_etext)) | |
10807 | + if (within(address, ktla_ktva((unsigned long)_text), ktla_ktva((unsigned long)_etext))) | |
10808 | pgprot_val(forbidden) |= _PAGE_NX; | |
da5b3fc8 | 10809 | |
4dee9bd5 | 10810 | /* |
10811 | @@ -229,8 +230,20 @@ pte_t *lookup_address(unsigned long addr | |
10812 | */ | |
10813 | static void __set_pmd_pte(pte_t *kpte, unsigned long address, pte_t pte) | |
10814 | { | |
50425a20 | 10815 | + |
da5b3fc8 | 10816 | +#ifdef CONFIG_PAX_KERNEXEC |
10817 | + unsigned long cr0; | |
50425a20 | 10818 | + |
da5b3fc8 | 10819 | + pax_open_kernel(cr0); |
10820 | +#endif | |
50425a20 | 10821 | + |
4dee9bd5 | 10822 | /* change init_mm */ |
10823 | set_pte_atomic(kpte, pte); | |
50425a20 | 10824 | + |
da5b3fc8 | 10825 | +#ifdef CONFIG_PAX_KERNEXEC |
10826 | + pax_close_kernel(cr0); | |
10827 | +#endif | |
50425a20 | 10828 | + |
4dee9bd5 | 10829 | #ifdef CONFIG_X86_32 |
10830 | if (!SHARED_KERNEL_PMD) { | |
10831 | struct page *page; | |
10832 | diff -urNp linux-2.6.25.4/arch/x86/mm/pgtable_32.c linux-2.6.25.4/arch/x86/mm/pgtable_32.c | |
10833 | --- linux-2.6.25.4/arch/x86/mm/pgtable_32.c 2008-05-15 11:00:12.000000000 -0400 | |
10834 | +++ linux-2.6.25.4/arch/x86/mm/pgtable_32.c 2008-05-18 13:33:15.000000000 -0400 | |
da5b3fc8 | 10835 | @@ -83,6 +83,10 @@ static void set_pte_pfn(unsigned long va |
10836 | pmd_t *pmd; | |
10837 | pte_t *pte; | |
10838 | ||
10839 | +#ifdef CONFIG_PAX_KERNEXEC | |
10840 | + unsigned long cr0; | |
50425a20 | 10841 | +#endif |
10842 | + | |
da5b3fc8 | 10843 | pgd = swapper_pg_dir + pgd_index(vaddr); |
10844 | if (pgd_none(*pgd)) { | |
10845 | BUG(); | |
10846 | @@ -99,11 +103,20 @@ static void set_pte_pfn(unsigned long va | |
10847 | return; | |
10848 | } | |
10849 | pte = pte_offset_kernel(pmd, vaddr); | |
50425a20 | 10850 | + |
da5b3fc8 | 10851 | +#ifdef CONFIG_PAX_KERNEXEC |
10852 | + pax_open_kernel(cr0); | |
10853 | +#endif | |
50425a20 | 10854 | + |
da5b3fc8 | 10855 | if (pgprot_val(flags)) |
10856 | set_pte_present(&init_mm, vaddr, pte, pfn_pte(pfn, flags)); | |
10857 | else | |
10858 | pte_clear(&init_mm, vaddr, pte); | |
10859 | ||
10860 | +#ifdef CONFIG_PAX_KERNEXEC | |
10861 | + pax_close_kernel(cr0); | |
50425a20 | 10862 | +#endif |
10863 | + | |
da5b3fc8 | 10864 | /* |
10865 | * It's enough to flush this one mapping. | |
10866 | * (PGE mappings get flushed as well) | |
4dee9bd5 | 10867 | diff -urNp linux-2.6.25.4/arch/x86/oprofile/backtrace.c linux-2.6.25.4/arch/x86/oprofile/backtrace.c |
10868 | --- linux-2.6.25.4/arch/x86/oprofile/backtrace.c 2008-05-15 11:00:12.000000000 -0400 | |
10869 | +++ linux-2.6.25.4/arch/x86/oprofile/backtrace.c 2008-05-18 13:33:15.000000000 -0400 | |
da5b3fc8 | 10870 | @@ -37,7 +37,7 @@ static void backtrace_address(void *data |
10871 | unsigned int *depth = data; | |
10872 | ||
10873 | if ((*depth)--) | |
10874 | - oprofile_add_trace(addr); | |
10875 | + oprofile_add_trace(ktla_ktva(addr)); | |
10876 | } | |
10877 | ||
10878 | static struct stacktrace_ops backtrace_ops = { | |
10879 | @@ -79,7 +79,7 @@ x86_backtrace(struct pt_regs * const reg | |
10880 | struct frame_head *head = (struct frame_head *)frame_pointer(regs); | |
4dee9bd5 | 10881 | unsigned long stack = kernel_trap_sp(regs); |
da5b3fc8 | 10882 | |
10883 | - if (!user_mode_vm(regs)) { | |
10884 | + if (!user_mode(regs)) { | |
10885 | if (depth) | |
4dee9bd5 | 10886 | dump_trace(NULL, regs, (unsigned long *)stack, 0, |
da5b3fc8 | 10887 | &backtrace_ops, &depth); |
4dee9bd5 | 10888 | diff -urNp linux-2.6.25.4/arch/x86/oprofile/op_model_p4.c linux-2.6.25.4/arch/x86/oprofile/op_model_p4.c |
10889 | --- linux-2.6.25.4/arch/x86/oprofile/op_model_p4.c 2008-05-15 11:00:12.000000000 -0400 | |
10890 | +++ linux-2.6.25.4/arch/x86/oprofile/op_model_p4.c 2008-05-18 13:33:15.000000000 -0400 | |
da5b3fc8 | 10891 | @@ -47,7 +47,7 @@ static inline void setup_num_counters(vo |
10892 | #endif | |
10893 | } | |
10894 | ||
10895 | -static int inline addr_increment(void) | |
10896 | +static inline int addr_increment(void) | |
50425a20 | 10897 | { |
da5b3fc8 | 10898 | #ifdef CONFIG_SMP |
10899 | return smp_num_siblings == 2 ? 2 : 1; | |
4dee9bd5 | 10900 | diff -urNp linux-2.6.25.4/arch/x86/pci/common.c linux-2.6.25.4/arch/x86/pci/common.c |
10901 | --- linux-2.6.25.4/arch/x86/pci/common.c 2008-05-15 11:00:12.000000000 -0400 | |
10902 | +++ linux-2.6.25.4/arch/x86/pci/common.c 2008-05-18 13:33:15.000000000 -0400 | |
10903 | @@ -369,7 +369,7 @@ static struct dmi_system_id __devinitdat | |
da5b3fc8 | 10904 | DMI_MATCH(DMI_PRODUCT_NAME, "ProLiant DL585 G2"), |
10905 | }, | |
10906 | }, | |
10907 | - {} | |
10908 | + { NULL, NULL, {DMI_MATCH(DMI_NONE, NULL)}, NULL} | |
10909 | }; | |
10910 | ||
4dee9bd5 | 10911 | void __init dmi_check_pciprobe(void) |
10912 | diff -urNp linux-2.6.25.4/arch/x86/pci/early.c linux-2.6.25.4/arch/x86/pci/early.c | |
10913 | --- linux-2.6.25.4/arch/x86/pci/early.c 2008-05-15 11:00:12.000000000 -0400 | |
10914 | +++ linux-2.6.25.4/arch/x86/pci/early.c 2008-05-18 13:33:15.000000000 -0400 | |
da5b3fc8 | 10915 | @@ -7,7 +7,7 @@ |
10916 | /* Direct PCI access. This is used for PCI accesses in early boot before | |
10917 | the PCI subsystem works. */ | |
10918 | ||
10919 | -#define PDprintk(x...) | |
10920 | +#define PDprintk(x...) do {} while (0) | |
10921 | ||
10922 | u32 read_pci_config(u8 bus, u8 slot, u8 func, u8 offset) | |
10923 | { | |
4dee9bd5 | 10924 | diff -urNp linux-2.6.25.4/arch/x86/pci/fixup.c linux-2.6.25.4/arch/x86/pci/fixup.c |
10925 | --- linux-2.6.25.4/arch/x86/pci/fixup.c 2008-05-15 11:00:12.000000000 -0400 | |
10926 | +++ linux-2.6.25.4/arch/x86/pci/fixup.c 2008-05-18 13:33:15.000000000 -0400 | |
10927 | @@ -364,7 +364,7 @@ static struct dmi_system_id __devinitdat | |
da5b3fc8 | 10928 | DMI_MATCH(DMI_PRODUCT_NAME, "MS-6702E"), |
10929 | }, | |
10930 | }, | |
10931 | - {} | |
10932 | + { NULL, NULL, {DMI_MATCH(DMI_NONE, NULL)}, NULL } | |
10933 | }; | |
10934 | ||
10935 | /* | |
4dee9bd5 | 10936 | @@ -435,7 +435,7 @@ static struct dmi_system_id __devinitdat |
da5b3fc8 | 10937 | DMI_MATCH(DMI_PRODUCT_VERSION, "PSA40U"), |
10938 | }, | |
10939 | }, | |
10940 | - { } | |
10941 | + { NULL, NULL, {DMI_MATCH(DMI_NONE, NULL)}, NULL } | |
10942 | }; | |
10943 | ||
10944 | static void __devinit pci_pre_fixup_toshiba_ohci1394(struct pci_dev *dev) | |
4dee9bd5 | 10945 | diff -urNp linux-2.6.25.4/arch/x86/pci/irq.c linux-2.6.25.4/arch/x86/pci/irq.c |
10946 | --- linux-2.6.25.4/arch/x86/pci/irq.c 2008-05-15 11:00:12.000000000 -0400 | |
10947 | +++ linux-2.6.25.4/arch/x86/pci/irq.c 2008-05-18 13:33:15.000000000 -0400 | |
10948 | @@ -540,7 +540,7 @@ static __init int intel_router_probe(str | |
da5b3fc8 | 10949 | static struct pci_device_id __initdata pirq_440gx[] = { |
10950 | { PCI_DEVICE(PCI_VENDOR_ID_INTEL, PCI_DEVICE_ID_INTEL_82443GX_0) }, | |
10951 | { PCI_DEVICE(PCI_VENDOR_ID_INTEL, PCI_DEVICE_ID_INTEL_82443GX_2) }, | |
10952 | - { }, | |
10953 | + { PCI_DEVICE(0, 0) } | |
10954 | }; | |
10955 | ||
10956 | /* 440GX has a proprietary PIRQ router -- don't use it */ | |
4dee9bd5 | 10957 | @@ -1106,7 +1106,7 @@ static struct dmi_system_id __initdata p |
da5b3fc8 | 10958 | DMI_MATCH(DMI_PRODUCT_NAME, "TravelMate 360"), |
10959 | }, | |
10960 | }, | |
10961 | - { } | |
10962 | + { NULL, NULL, {DMI_MATCH(DMI_NONE, NULL)}, NULL } | |
10963 | }; | |
50425a20 | 10964 | |
da5b3fc8 | 10965 | static int __init pcibios_irq_init(void) |
4dee9bd5 | 10966 | diff -urNp linux-2.6.25.4/arch/x86/pci/pcbios.c linux-2.6.25.4/arch/x86/pci/pcbios.c |
10967 | --- linux-2.6.25.4/arch/x86/pci/pcbios.c 2008-05-15 11:00:12.000000000 -0400 | |
10968 | +++ linux-2.6.25.4/arch/x86/pci/pcbios.c 2008-05-18 13:33:15.000000000 -0400 | |
10969 | @@ -57,50 +57,120 @@ union bios32 { | |
da5b3fc8 | 10970 | static struct { |
10971 | unsigned long address; | |
10972 | unsigned short segment; | |
10973 | -} bios32_indirect = { 0, __KERNEL_CS }; | |
10974 | +} bios32_indirect __read_only = { 0, __PCIBIOS_CS }; | |
50425a20 | 10975 | |
da5b3fc8 | 10976 | /* |
10977 | * Returns the entry point for the given service, NULL on error | |
10978 | */ | |
50425a20 | 10979 | |
da5b3fc8 | 10980 | -static unsigned long bios32_service(unsigned long service) |
10981 | +static unsigned long __devinit bios32_service(unsigned long service) | |
10982 | { | |
10983 | unsigned char return_code; /* %al */ | |
10984 | unsigned long address; /* %ebx */ | |
10985 | unsigned long length; /* %ecx */ | |
10986 | unsigned long entry; /* %edx */ | |
10987 | unsigned long flags; | |
4dee9bd5 | 10988 | + struct desc_struct d, *gdt; |
50425a20 | 10989 | + |
da5b3fc8 | 10990 | +#ifdef CONFIG_PAX_KERNEXEC |
10991 | + unsigned long cr0; | |
50425a20 | 10992 | +#endif |
da5b3fc8 | 10993 | |
10994 | local_irq_save(flags); | |
10995 | - __asm__("lcall *(%%edi); cld" | |
50425a20 | 10996 | + |
da5b3fc8 | 10997 | + gdt = get_cpu_gdt_table(smp_processor_id()); |
10998 | + | |
10999 | +#ifdef CONFIG_PAX_KERNEXEC | |
11000 | + pax_open_kernel(cr0); | |
50425a20 | 11001 | +#endif |
11002 | + | |
4dee9bd5 | 11003 | + pack_descriptor(&d, 0UL, 0xFFFFFUL, 0x9B, 0xC); |
11004 | + write_gdt_entry(gdt, GDT_ENTRY_PCIBIOS_CS, &d, DESCTYPE_S); | |
11005 | + pack_descriptor(&d, 0UL, 0xFFFFFUL, 0x93, 0xC); | |
11006 | + write_gdt_entry(gdt, GDT_ENTRY_PCIBIOS_DS, &d, DESCTYPE_S); | |
50425a20 | 11007 | + |
da5b3fc8 | 11008 | +#ifdef CONFIG_PAX_KERNEXEC |
11009 | + pax_close_kernel(cr0); | |
50425a20 | 11010 | +#endif |
11011 | + | |
da5b3fc8 | 11012 | + __asm__("movw %w7, %%ds; lcall *(%%edi); push %%ss; pop %%ds; cld" |
11013 | : "=a" (return_code), | |
11014 | "=b" (address), | |
11015 | "=c" (length), | |
11016 | "=d" (entry) | |
11017 | : "0" (service), | |
11018 | "1" (0), | |
11019 | - "D" (&bios32_indirect)); | |
11020 | + "D" (&bios32_indirect), | |
11021 | + "r"(__PCIBIOS_DS) | |
11022 | + : "memory"); | |
83a957c9 | 11023 | + |
da5b3fc8 | 11024 | +#ifdef CONFIG_PAX_KERNEXEC |
11025 | + pax_open_kernel(cr0); | |
83a957c9 | 11026 | +#endif |
11027 | + | |
da5b3fc8 | 11028 | + gdt[GDT_ENTRY_PCIBIOS_CS].a = 0; |
11029 | + gdt[GDT_ENTRY_PCIBIOS_CS].b = 0; | |
11030 | + gdt[GDT_ENTRY_PCIBIOS_DS].a = 0; | |
11031 | + gdt[GDT_ENTRY_PCIBIOS_DS].b = 0; | |
11032 | + | |
11033 | +#ifdef CONFIG_PAX_KERNEXEC | |
11034 | + pax_close_kernel(cr0); | |
83a957c9 | 11035 | +#endif |
11036 | + | |
da5b3fc8 | 11037 | local_irq_restore(flags); |
e36c1b33 | 11038 | |
da5b3fc8 | 11039 | switch (return_code) { |
11040 | - case 0: | |
11041 | - return address + entry; | |
11042 | - case 0x80: /* Not present */ | |
11043 | - printk(KERN_WARNING "bios32_service(0x%lx): not present\n", service); | |
11044 | - return 0; | |
11045 | - default: /* Shouldn't happen */ | |
11046 | - printk(KERN_WARNING "bios32_service(0x%lx): returned 0x%x -- BIOS bug!\n", | |
11047 | - service, return_code); | |
11048 | + case 0: { | |
11049 | + int cpu; | |
11050 | + unsigned char flags; | |
e36c1b33 | 11051 | + |
da5b3fc8 | 11052 | + printk(KERN_INFO "bios32_service: base:%08lx length:%08lx entry:%08lx\n", address, length, entry); |
6778dfc1 | 11053 | + if (address >= 0xFFFF0 || length > 0x100000 - address || length <= entry) { |
da5b3fc8 | 11054 | + printk(KERN_WARNING "bios32_service: not valid\n"); |
11055 | return 0; | |
11056 | + } | |
11057 | + address = address + PAGE_OFFSET; | |
11058 | + length += 16UL; /* some BIOSs underreport this... */ | |
11059 | + flags = 4; | |
11060 | + if (length >= 64*1024*1024) { | |
11061 | + length >>= PAGE_SHIFT; | |
11062 | + flags |= 8; | |
11063 | + } | |
50425a20 | 11064 | + |
da5b3fc8 | 11065 | +#ifdef CONFIG_PAX_KERNEXEC |
11066 | + pax_open_kernel(cr0); | |
50425a20 | 11067 | +#endif |
11068 | + | |
da5b3fc8 | 11069 | + for (cpu = 0; cpu < NR_CPUS; cpu++) { |
11070 | + gdt = get_cpu_gdt_table(cpu); | |
4dee9bd5 | 11071 | + pack_descriptor(&d, address, length, 0x9b, flags); |
11072 | + write_gdt_entry(gdt, GDT_ENTRY_PCIBIOS_CS, &d, DESCTYPE_S); | |
11073 | + pack_descriptor(&d, address, length, 0x93, flags); | |
11074 | + write_gdt_entry(gdt, GDT_ENTRY_PCIBIOS_DS, &d, DESCTYPE_S); | |
da5b3fc8 | 11075 | + } |
50425a20 | 11076 | + |
da5b3fc8 | 11077 | +#ifdef CONFIG_PAX_KERNEXEC |
11078 | + pax_close_kernel(cr0); | |
50425a20 | 11079 | +#endif |
11080 | + | |
da5b3fc8 | 11081 | + return entry; |
50425a20 | 11082 | + } |
da5b3fc8 | 11083 | + case 0x80: /* Not present */ |
11084 | + printk(KERN_WARNING "bios32_service(0x%lx): not present\n", service); | |
11085 | + return 0; | |
11086 | + default: /* Shouldn't happen */ | |
11087 | + printk(KERN_WARNING "bios32_service(0x%lx): returned 0x%x -- BIOS bug!\n", | |
11088 | + service, return_code); | |
11089 | + return 0; | |
50425a20 | 11090 | } |
50425a20 | 11091 | } |
50425a20 | 11092 | |
da5b3fc8 | 11093 | static struct { |
11094 | unsigned long address; | |
11095 | unsigned short segment; | |
11096 | -} pci_indirect = { 0, __KERNEL_CS }; | |
11097 | +} pci_indirect __read_only = { 0, __PCIBIOS_CS }; | |
50425a20 | 11098 | |
da5b3fc8 | 11099 | -static int pci_bios_present; |
11100 | +static int pci_bios_present __read_only; | |
50425a20 | 11101 | |
da5b3fc8 | 11102 | static int __devinit check_pcibios(void) |
11103 | { | |
4dee9bd5 | 11104 | @@ -109,11 +179,13 @@ static int __devinit check_pcibios(void) |
da5b3fc8 | 11105 | unsigned long flags, pcibios_entry; |
50425a20 | 11106 | |
da5b3fc8 | 11107 | if ((pcibios_entry = bios32_service(PCI_SERVICE))) { |
11108 | - pci_indirect.address = pcibios_entry + PAGE_OFFSET; | |
11109 | + pci_indirect.address = pcibios_entry; | |
50425a20 | 11110 | |
da5b3fc8 | 11111 | local_irq_save(flags); |
11112 | - __asm__( | |
11113 | - "lcall *(%%edi); cld\n\t" | |
11114 | + __asm__("movw %w6, %%ds\n\t" | |
11115 | + "lcall *%%ss:(%%edi); cld\n\t" | |
11116 | + "push %%ss\n\t" | |
11117 | + "pop %%ds\n\t" | |
11118 | "jc 1f\n\t" | |
11119 | "xor %%ah, %%ah\n" | |
11120 | "1:" | |
4dee9bd5 | 11121 | @@ -122,7 +194,8 @@ static int __devinit check_pcibios(void) |
da5b3fc8 | 11122 | "=b" (ebx), |
11123 | "=c" (ecx) | |
11124 | : "1" (PCIBIOS_PCI_BIOS_PRESENT), | |
11125 | - "D" (&pci_indirect) | |
11126 | + "D" (&pci_indirect), | |
11127 | + "r" (__PCIBIOS_DS) | |
11128 | : "memory"); | |
11129 | local_irq_restore(flags); | |
50425a20 | 11130 | |
4dee9bd5 | 11131 | @@ -158,7 +231,10 @@ static int __devinit pci_bios_find_devic |
da5b3fc8 | 11132 | unsigned short bx; |
11133 | unsigned short ret; | |
50425a20 | 11134 | |
da5b3fc8 | 11135 | - __asm__("lcall *(%%edi); cld\n\t" |
11136 | + __asm__("movw %w7, %%ds\n\t" | |
11137 | + "lcall *%%ss:(%%edi); cld\n\t" | |
11138 | + "push %%ss\n\t" | |
11139 | + "pop %%ds\n\t" | |
11140 | "jc 1f\n\t" | |
11141 | "xor %%ah, %%ah\n" | |
11142 | "1:" | |
4dee9bd5 | 11143 | @@ -168,7 +244,8 @@ static int __devinit pci_bios_find_devic |
da5b3fc8 | 11144 | "c" (device_id), |
11145 | "d" (vendor), | |
11146 | "S" ((int) index), | |
11147 | - "D" (&pci_indirect)); | |
11148 | + "D" (&pci_indirect), | |
11149 | + "r" (__PCIBIOS_DS)); | |
11150 | *bus = (bx >> 8) & 0xff; | |
11151 | *device_fn = bx & 0xff; | |
11152 | return (int) (ret & 0xff00) >> 8; | |
4dee9bd5 | 11153 | @@ -188,7 +265,10 @@ static int pci_bios_read(unsigned int se |
da5b3fc8 | 11154 | |
11155 | switch (len) { | |
11156 | case 1: | |
11157 | - __asm__("lcall *(%%esi); cld\n\t" | |
11158 | + __asm__("movw %w6, %%ds\n\t" | |
11159 | + "lcall *%%ss:(%%esi); cld\n\t" | |
11160 | + "push %%ss\n\t" | |
11161 | + "pop %%ds\n\t" | |
11162 | "jc 1f\n\t" | |
11163 | "xor %%ah, %%ah\n" | |
11164 | "1:" | |
4dee9bd5 | 11165 | @@ -197,7 +277,8 @@ static int pci_bios_read(unsigned int se |
da5b3fc8 | 11166 | : "1" (PCIBIOS_READ_CONFIG_BYTE), |
11167 | "b" (bx), | |
11168 | "D" ((long)reg), | |
11169 | - "S" (&pci_indirect)); | |
11170 | + "S" (&pci_indirect), | |
11171 | + "r" (__PCIBIOS_DS)); | |
4dee9bd5 | 11172 | /* |
11173 | * Zero-extend the result beyond 8 bits, do not trust the | |
11174 | * BIOS having done it: | |
11175 | @@ -205,7 +286,10 @@ static int pci_bios_read(unsigned int se | |
11176 | *value &= 0xff; | |
da5b3fc8 | 11177 | break; |
11178 | case 2: | |
11179 | - __asm__("lcall *(%%esi); cld\n\t" | |
11180 | + __asm__("movw %w6, %%ds\n\t" | |
11181 | + "lcall *%%ss:(%%esi); cld\n\t" | |
11182 | + "push %%ss\n\t" | |
11183 | + "pop %%ds\n\t" | |
11184 | "jc 1f\n\t" | |
11185 | "xor %%ah, %%ah\n" | |
11186 | "1:" | |
4dee9bd5 | 11187 | @@ -214,7 +298,8 @@ static int pci_bios_read(unsigned int se |
da5b3fc8 | 11188 | : "1" (PCIBIOS_READ_CONFIG_WORD), |
11189 | "b" (bx), | |
11190 | "D" ((long)reg), | |
11191 | - "S" (&pci_indirect)); | |
11192 | + "S" (&pci_indirect), | |
11193 | + "r" (__PCIBIOS_DS)); | |
4dee9bd5 | 11194 | /* |
11195 | * Zero-extend the result beyond 16 bits, do not trust the | |
11196 | * BIOS having done it: | |
11197 | @@ -222,7 +307,10 @@ static int pci_bios_read(unsigned int se | |
11198 | *value &= 0xffff; | |
da5b3fc8 | 11199 | break; |
11200 | case 4: | |
11201 | - __asm__("lcall *(%%esi); cld\n\t" | |
11202 | + __asm__("movw %w6, %%ds\n\t" | |
11203 | + "lcall *%%ss:(%%esi); cld\n\t" | |
11204 | + "push %%ss\n\t" | |
11205 | + "pop %%ds\n\t" | |
11206 | "jc 1f\n\t" | |
11207 | "xor %%ah, %%ah\n" | |
11208 | "1:" | |
4dee9bd5 | 11209 | @@ -231,7 +319,8 @@ static int pci_bios_read(unsigned int se |
da5b3fc8 | 11210 | : "1" (PCIBIOS_READ_CONFIG_DWORD), |
11211 | "b" (bx), | |
11212 | "D" ((long)reg), | |
11213 | - "S" (&pci_indirect)); | |
11214 | + "S" (&pci_indirect), | |
11215 | + "r" (__PCIBIOS_DS)); | |
11216 | break; | |
50425a20 | 11217 | } |
8a4b4a5e | 11218 | |
4dee9bd5 | 11219 | @@ -254,7 +343,10 @@ static int pci_bios_write(unsigned int s |
50425a20 | 11220 | |
da5b3fc8 | 11221 | switch (len) { |
11222 | case 1: | |
11223 | - __asm__("lcall *(%%esi); cld\n\t" | |
11224 | + __asm__("movw %w6, %%ds\n\t" | |
11225 | + "lcall *%%ss:(%%esi); cld\n\t" | |
11226 | + "push %%ss\n\t" | |
11227 | + "pop %%ds\n\t" | |
11228 | "jc 1f\n\t" | |
11229 | "xor %%ah, %%ah\n" | |
11230 | "1:" | |
4dee9bd5 | 11231 | @@ -263,10 +355,14 @@ static int pci_bios_write(unsigned int s |
da5b3fc8 | 11232 | "c" (value), |
11233 | "b" (bx), | |
11234 | "D" ((long)reg), | |
11235 | - "S" (&pci_indirect)); | |
11236 | + "S" (&pci_indirect), | |
11237 | + "r" (__PCIBIOS_DS)); | |
11238 | break; | |
11239 | case 2: | |
11240 | - __asm__("lcall *(%%esi); cld\n\t" | |
11241 | + __asm__("movw %w6, %%ds\n\t" | |
11242 | + "lcall *%%ss:(%%esi); cld\n\t" | |
11243 | + "push %%ss\n\t" | |
11244 | + "pop %%ds\n\t" | |
11245 | "jc 1f\n\t" | |
11246 | "xor %%ah, %%ah\n" | |
11247 | "1:" | |
4dee9bd5 | 11248 | @@ -275,10 +371,14 @@ static int pci_bios_write(unsigned int s |
da5b3fc8 | 11249 | "c" (value), |
11250 | "b" (bx), | |
11251 | "D" ((long)reg), | |
11252 | - "S" (&pci_indirect)); | |
11253 | + "S" (&pci_indirect), | |
11254 | + "r" (__PCIBIOS_DS)); | |
11255 | break; | |
11256 | case 4: | |
11257 | - __asm__("lcall *(%%esi); cld\n\t" | |
11258 | + __asm__("movw %w6, %%ds\n\t" | |
11259 | + "lcall *%%ss:(%%esi); cld\n\t" | |
11260 | + "push %%ss\n\t" | |
11261 | + "pop %%ds\n\t" | |
11262 | "jc 1f\n\t" | |
11263 | "xor %%ah, %%ah\n" | |
11264 | "1:" | |
4dee9bd5 | 11265 | @@ -287,7 +387,8 @@ static int pci_bios_write(unsigned int s |
da5b3fc8 | 11266 | "c" (value), |
11267 | "b" (bx), | |
11268 | "D" ((long)reg), | |
11269 | - "S" (&pci_indirect)); | |
11270 | + "S" (&pci_indirect), | |
11271 | + "r" (__PCIBIOS_DS)); | |
11272 | break; | |
11273 | } | |
50425a20 | 11274 | |
4dee9bd5 | 11275 | @@ -440,10 +541,13 @@ struct irq_routing_table * pcibios_get_i |
50425a20 | 11276 | |
da5b3fc8 | 11277 | DBG("PCI: Fetching IRQ routing table... "); |
11278 | __asm__("push %%es\n\t" | |
11279 | + "movw %w8, %%ds\n\t" | |
11280 | "push %%ds\n\t" | |
11281 | "pop %%es\n\t" | |
11282 | - "lcall *(%%esi); cld\n\t" | |
11283 | + "lcall *%%ss:(%%esi); cld\n\t" | |
11284 | "pop %%es\n\t" | |
11285 | + "push %%ss\n\t" | |
11286 | + "pop %%ds\n" | |
11287 | "jc 1f\n\t" | |
11288 | "xor %%ah, %%ah\n" | |
11289 | "1:" | |
4dee9bd5 | 11290 | @@ -454,7 +558,8 @@ struct irq_routing_table * pcibios_get_i |
da5b3fc8 | 11291 | "1" (0), |
11292 | "D" ((long) &opt), | |
11293 | "S" (&pci_indirect), | |
11294 | - "m" (opt) | |
11295 | + "m" (opt), | |
11296 | + "r" (__PCIBIOS_DS) | |
11297 | : "memory"); | |
11298 | DBG("OK ret=%d, size=%d, map=%x\n", ret, opt.size, map); | |
11299 | if (ret & 0xff00) | |
4dee9bd5 | 11300 | @@ -478,7 +583,10 @@ int pcibios_set_irq_routing(struct pci_d |
da5b3fc8 | 11301 | { |
11302 | int ret; | |
50425a20 | 11303 | |
da5b3fc8 | 11304 | - __asm__("lcall *(%%esi); cld\n\t" |
11305 | + __asm__("movw %w5, %%ds\n\t" | |
11306 | + "lcall *%%ss:(%%esi); cld\n\t" | |
11307 | + "push %%ss\n\t" | |
11308 | + "pop %%ds\n" | |
11309 | "jc 1f\n\t" | |
11310 | "xor %%ah, %%ah\n" | |
11311 | "1:" | |
4dee9bd5 | 11312 | @@ -486,7 +594,8 @@ int pcibios_set_irq_routing(struct pci_d |
da5b3fc8 | 11313 | : "0" (PCIBIOS_SET_PCI_HW_INT), |
11314 | "b" ((dev->bus->number << 8) | dev->devfn), | |
11315 | "c" ((irq << 8) | (pin + 10)), | |
11316 | - "S" (&pci_indirect)); | |
11317 | + "S" (&pci_indirect), | |
11318 | + "r" (__PCIBIOS_DS)); | |
11319 | return !(ret & 0xff00); | |
11320 | } | |
11321 | EXPORT_SYMBOL(pcibios_set_irq_routing); | |
4dee9bd5 | 11322 | diff -urNp linux-2.6.25.4/arch/x86/power/cpu_32.c linux-2.6.25.4/arch/x86/power/cpu_32.c |
11323 | --- linux-2.6.25.4/arch/x86/power/cpu_32.c 2008-05-15 11:00:12.000000000 -0400 | |
11324 | +++ linux-2.6.25.4/arch/x86/power/cpu_32.c 2008-05-18 13:33:15.000000000 -0400 | |
da5b3fc8 | 11325 | @@ -64,10 +64,20 @@ static void do_fpu_end(void) |
11326 | static void fix_processor_context(void) | |
11327 | { | |
11328 | int cpu = smp_processor_id(); | |
11329 | - struct tss_struct * t = &per_cpu(init_tss, cpu); | |
11330 | + struct tss_struct *t = init_tss + cpu; | |
50425a20 | 11331 | + |
da5b3fc8 | 11332 | +#ifdef CONFIG_PAX_KERNEXEC |
11333 | + unsigned long cr0; | |
50425a20 | 11334 | + |
da5b3fc8 | 11335 | + pax_open_kernel(cr0); |
11336 | +#endif | |
50425a20 | 11337 | |
da5b3fc8 | 11338 | set_tss_desc(cpu,t); /* This just modifies memory; should not be necessary. But... This is necessary, because 386 hardware has concept of busy TSS or some similar stupidity. */ |
11339 | ||
11340 | +#ifdef CONFIG_PAX_KERNEXEC | |
11341 | + pax_close_kernel(cr0); | |
50425a20 | 11342 | +#endif |
11343 | + | |
da5b3fc8 | 11344 | load_TR_desc(); /* This does ltr */ |
11345 | load_LDT(¤t->active_mm->context); /* This does lldt */ | |
11346 | ||
4dee9bd5 | 11347 | diff -urNp linux-2.6.25.4/arch/x86/power/cpu_64.c linux-2.6.25.4/arch/x86/power/cpu_64.c |
11348 | --- linux-2.6.25.4/arch/x86/power/cpu_64.c 2008-05-15 11:00:12.000000000 -0400 | |
11349 | +++ linux-2.6.25.4/arch/x86/power/cpu_64.c 2008-05-18 13:33:15.000000000 -0400 | |
11350 | @@ -136,7 +136,13 @@ void restore_processor_state(void) | |
11351 | static void fix_processor_context(void) | |
11352 | { | |
11353 | int cpu = smp_processor_id(); | |
11354 | - struct tss_struct *t = &per_cpu(init_tss, cpu); | |
11355 | + struct tss_struct *t = init_tss + cpu; | |
11356 | + | |
11357 | +#ifdef CONFIG_PAX_KERNEXEC | |
11358 | + unsigned long cr0; | |
11359 | + | |
11360 | + pax_open_kernel(cr0); | |
11361 | +#endif | |
11362 | ||
11363 | /* | |
11364 | * This just modifies memory; should not be necessary. But... This | |
11365 | @@ -147,6 +153,10 @@ static void fix_processor_context(void) | |
11366 | ||
11367 | get_cpu_gdt_table(cpu)[GDT_ENTRY_TSS].type = 9; | |
11368 | ||
11369 | +#ifdef CONFIG_PAX_KERNEXEC | |
11370 | + pax_close_kernel(cr0); | |
11371 | +#endif | |
11372 | + | |
11373 | syscall_init(); /* This sets MSR_*STAR and related */ | |
11374 | load_TR_desc(); /* This does ltr */ | |
11375 | load_LDT(¤t->active_mm->context); /* This does lldt */ | |
11376 | diff -urNp linux-2.6.25.4/arch/x86/vdso/vdso32-setup.c linux-2.6.25.4/arch/x86/vdso/vdso32-setup.c | |
11377 | --- linux-2.6.25.4/arch/x86/vdso/vdso32-setup.c 2008-05-15 11:00:12.000000000 -0400 | |
11378 | +++ linux-2.6.25.4/arch/x86/vdso/vdso32-setup.c 2008-05-18 13:33:15.000000000 -0400 | |
11379 | @@ -235,7 +235,7 @@ static inline void map_compat_vdso(int m | |
11380 | void enable_sep_cpu(void) | |
11381 | { | |
11382 | int cpu = get_cpu(); | |
11383 | - struct tss_struct *tss = &per_cpu(init_tss, cpu); | |
11384 | + struct tss_struct *tss = init_tss + cpu; | |
11385 | ||
11386 | if (!boot_cpu_has(X86_FEATURE_SEP)) { | |
11387 | put_cpu(); | |
11388 | @@ -258,7 +258,7 @@ static int __init gate_vma_init(void) | |
11389 | gate_vma.vm_start = FIXADDR_USER_START; | |
11390 | gate_vma.vm_end = FIXADDR_USER_END; | |
11391 | gate_vma.vm_flags = VM_READ | VM_MAYREAD | VM_EXEC | VM_MAYEXEC; | |
11392 | - gate_vma.vm_page_prot = __P101; | |
11393 | + gate_vma.vm_page_prot = vm_get_page_prot(gate_vma.vm_flags); | |
11394 | /* | |
11395 | * Make sure the vDSO gets into every core dump. | |
11396 | * Dumping its contents makes post-mortem fully interpretable later | |
11397 | @@ -336,7 +336,7 @@ int arch_setup_additional_pages(struct l | |
11398 | if (compat) | |
11399 | addr = VDSO_HIGH_BASE; | |
11400 | else { | |
11401 | - addr = get_unmapped_area(NULL, 0, PAGE_SIZE, 0, 0); | |
11402 | + addr = get_unmapped_area(NULL, 0, PAGE_SIZE, 0, MAP_EXECUTABLE); | |
11403 | if (IS_ERR_VALUE(addr)) { | |
11404 | ret = addr; | |
11405 | goto up_fail; | |
11406 | @@ -363,7 +363,7 @@ int arch_setup_additional_pages(struct l | |
11407 | goto up_fail; | |
11408 | } | |
11409 | ||
11410 | - current->mm->context.vdso = (void *)addr; | |
11411 | + current->mm->context.vdso = addr; | |
11412 | current_thread_info()->sysenter_return = | |
11413 | VDSO32_SYMBOL(addr, SYSENTER_RETURN); | |
11414 | ||
11415 | @@ -389,7 +389,7 @@ static ctl_table abi_table2[] = { | |
11416 | .mode = 0644, | |
11417 | .proc_handler = proc_dointvec | |
11418 | }, | |
11419 | - {} | |
11420 | + { 0, NULL, NULL, 0, 0, NULL, NULL, NULL, NULL, NULL, NULL } | |
11421 | }; | |
11422 | ||
11423 | static ctl_table abi_root_table2[] = { | |
11424 | @@ -399,7 +399,7 @@ static ctl_table abi_root_table2[] = { | |
11425 | .mode = 0555, | |
11426 | .child = abi_table2 | |
11427 | }, | |
11428 | - {} | |
11429 | + { 0, NULL, NULL, 0, 0, NULL, NULL, NULL, NULL, NULL, NULL } | |
11430 | }; | |
11431 | ||
11432 | static __init int ia32_binfmt_init(void) | |
11433 | @@ -414,8 +414,14 @@ __initcall(ia32_binfmt_init); | |
11434 | ||
11435 | const char *arch_vma_name(struct vm_area_struct *vma) | |
11436 | { | |
11437 | - if (vma->vm_mm && vma->vm_start == (long)vma->vm_mm->context.vdso) | |
11438 | + if (vma->vm_mm && vma->vm_start == vma->vm_mm->context.vdso) | |
11439 | return "[vdso]"; | |
11440 | + | |
11441 | +#ifdef CONFIG_PAX_SEGMEXEC | |
11442 | + if (vma->vm_mm && vma->vm_mirror && vma->vm_mirror->vm_start == vma->vm_mm->context.vdso) | |
11443 | + return "[vdso]"; | |
11444 | +#endif | |
11445 | + | |
11446 | return NULL; | |
11447 | } | |
11448 | ||
11449 | @@ -424,7 +430,7 @@ struct vm_area_struct *get_gate_vma(stru | |
11450 | struct mm_struct *mm = tsk->mm; | |
11451 | ||
11452 | /* Check to see if this task was created in compat vdso mode */ | |
11453 | - if (mm && mm->context.vdso == (void *)VDSO_HIGH_BASE) | |
11454 | + if (mm && mm->context.vdso == VDSO_HIGH_BASE) | |
11455 | return &gate_vma; | |
11456 | return NULL; | |
11457 | } | |
11458 | diff -urNp linux-2.6.25.4/arch/x86/vdso/vma.c linux-2.6.25.4/arch/x86/vdso/vma.c | |
11459 | --- linux-2.6.25.4/arch/x86/vdso/vma.c 2008-05-15 11:00:12.000000000 -0400 | |
11460 | +++ linux-2.6.25.4/arch/x86/vdso/vma.c 2008-05-18 13:33:15.000000000 -0400 | |
11461 | @@ -122,7 +122,7 @@ int arch_setup_additional_pages(struct l | |
da5b3fc8 | 11462 | if (ret) |
11463 | goto up_fail; | |
11464 | ||
11465 | - current->mm->context.vdso = (void *)addr; | |
11466 | + current->mm->context.vdso = addr; | |
11467 | up_fail: | |
11468 | up_write(&mm->mmap_sem); | |
11469 | return ret; | |
4dee9bd5 | 11470 | diff -urNp linux-2.6.25.4/arch/x86/xen/enlighten.c linux-2.6.25.4/arch/x86/xen/enlighten.c |
11471 | --- linux-2.6.25.4/arch/x86/xen/enlighten.c 2008-05-15 11:00:12.000000000 -0400 | |
11472 | +++ linux-2.6.25.4/arch/x86/xen/enlighten.c 2008-05-18 13:33:15.000000000 -0400 | |
11473 | @@ -293,7 +293,7 @@ static void xen_set_ldt(const void *addr | |
11474 | static void xen_load_gdt(const struct desc_ptr *dtr) | |
da5b3fc8 | 11475 | { |
11476 | unsigned long *frames; | |
11477 | - unsigned long va = dtr->address; | |
11478 | + unsigned long va = (unsigned long)dtr->address; | |
11479 | unsigned int size = dtr->size + 1; | |
11480 | unsigned pages = (size + PAGE_SIZE - 1) / PAGE_SIZE; | |
11481 | int f; | |
4dee9bd5 | 11482 | @@ -308,7 +308,7 @@ static void xen_load_gdt(const struct de |
da5b3fc8 | 11483 | mcs = xen_mc_entry(sizeof(*frames) * pages); |
11484 | frames = mcs.args; | |
11485 | ||
11486 | - for (f = 0; va < dtr->address + size; va += PAGE_SIZE, f++) { | |
11487 | + for (f = 0; va < (unsigned long)dtr->address + size; va += PAGE_SIZE, f++) { | |
11488 | frames[f] = virt_to_mfn(va); | |
11489 | make_lowmem_page_readonly((void *)va); | |
50425a20 | 11490 | } |
4dee9bd5 | 11491 | @@ -401,7 +401,7 @@ static void xen_write_idt_entry(gate_des |
da5b3fc8 | 11492 | |
11493 | preempt_disable(); | |
11494 | ||
11495 | - start = __get_cpu_var(idt_desc).address; | |
11496 | + start = (unsigned long)__get_cpu_var(idt_desc).address; | |
11497 | end = start + __get_cpu_var(idt_desc).size + 1; | |
11498 | ||
11499 | xen_mc_flush(); | |
4dee9bd5 | 11500 | diff -urNp linux-2.6.25.4/arch/x86/xen/smp.c linux-2.6.25.4/arch/x86/xen/smp.c |
11501 | --- linux-2.6.25.4/arch/x86/xen/smp.c 2008-05-15 11:00:12.000000000 -0400 | |
11502 | +++ linux-2.6.25.4/arch/x86/xen/smp.c 2008-05-18 13:33:15.000000000 -0400 | |
da5b3fc8 | 11503 | @@ -144,7 +144,7 @@ void __init xen_smp_prepare_boot_cpu(voi |
11504 | ||
11505 | /* We've switched to the "real" per-cpu gdt, so make sure the | |
11506 | old memory can be recycled */ | |
11507 | - make_lowmem_page_readwrite(&per_cpu__gdt_page); | |
11508 | + make_lowmem_page_readwrite(get_cpu_gdt_table(smp_processor_id())); | |
11509 | ||
4dee9bd5 | 11510 | for_each_possible_cpu(cpu) { |
da5b3fc8 | 11511 | cpus_clear(per_cpu(cpu_sibling_map, cpu)); |
11512 | @@ -208,7 +208,7 @@ static __cpuinit int | |
11513 | cpu_initialize_context(unsigned int cpu, struct task_struct *idle) | |
11514 | { | |
11515 | struct vcpu_guest_context *ctxt; | |
11516 | - struct gdt_page *gdt = &per_cpu(gdt_page, cpu); | |
11517 | + struct desc_struct *gdt = get_cpu_gdt_table(cpu); | |
11518 | ||
11519 | if (cpu_test_and_set(cpu, cpu_initialized_map)) | |
11520 | return 0; | |
11521 | @@ -218,8 +218,8 @@ cpu_initialize_context(unsigned int cpu, | |
11522 | return -ENOMEM; | |
11523 | ||
11524 | ctxt->flags = VGCF_IN_KERNEL; | |
11525 | - ctxt->user_regs.ds = __USER_DS; | |
11526 | - ctxt->user_regs.es = __USER_DS; | |
11527 | + ctxt->user_regs.ds = __KERNEL_DS; | |
11528 | + ctxt->user_regs.es = __KERNEL_DS; | |
11529 | ctxt->user_regs.fs = __KERNEL_PERCPU; | |
11530 | ctxt->user_regs.gs = 0; | |
11531 | ctxt->user_regs.ss = __KERNEL_DS; | |
11532 | @@ -232,11 +232,11 @@ cpu_initialize_context(unsigned int cpu, | |
11533 | ||
11534 | ctxt->ldt_ents = 0; | |
11535 | ||
11536 | - BUG_ON((unsigned long)gdt->gdt & ~PAGE_MASK); | |
11537 | - make_lowmem_page_readonly(gdt->gdt); | |
11538 | + BUG_ON((unsigned long)gdt & ~PAGE_MASK); | |
11539 | + make_lowmem_page_readonly(gdt); | |
11540 | ||
11541 | - ctxt->gdt_frames[0] = virt_to_mfn(gdt->gdt); | |
11542 | - ctxt->gdt_ents = ARRAY_SIZE(gdt->gdt); | |
11543 | + ctxt->gdt_frames[0] = virt_to_mfn(gdt); | |
11544 | + ctxt->gdt_ents = GDT_ENTRIES; | |
11545 | ||
11546 | ctxt->user_regs.cs = __KERNEL_CS; | |
4dee9bd5 | 11547 | ctxt->user_regs.esp = idle->thread.sp0 - sizeof(struct pt_regs); |
11548 | diff -urNp linux-2.6.25.4/crypto/async_tx/async_tx.c linux-2.6.25.4/crypto/async_tx/async_tx.c | |
11549 | --- linux-2.6.25.4/crypto/async_tx/async_tx.c 2008-05-15 11:00:12.000000000 -0400 | |
11550 | +++ linux-2.6.25.4/crypto/async_tx/async_tx.c 2008-05-18 13:33:15.000000000 -0400 | |
11551 | @@ -341,8 +341,8 @@ async_tx_init(void) | |
da5b3fc8 | 11552 | err: |
11553 | printk(KERN_ERR "async_tx: initialization failure\n"); | |
11554 | ||
11555 | - while (--cap >= 0) | |
11556 | - free_percpu(channel_table[cap]); | |
11557 | + while (cap) | |
11558 | + free_percpu(channel_table[--cap]); | |
11559 | ||
11560 | return 1; | |
50425a20 | 11561 | } |
4dee9bd5 | 11562 | diff -urNp linux-2.6.25.4/crypto/lrw.c linux-2.6.25.4/crypto/lrw.c |
11563 | --- linux-2.6.25.4/crypto/lrw.c 2008-05-15 11:00:12.000000000 -0400 | |
11564 | +++ linux-2.6.25.4/crypto/lrw.c 2008-05-18 13:33:15.000000000 -0400 | |
50425a20 | 11565 | @@ -54,7 +54,7 @@ static int setkey(struct crypto_tfm *par |
11566 | struct priv *ctx = crypto_tfm_ctx(parent); | |
11567 | struct crypto_cipher *child = ctx->child; | |
11568 | int err, i; | |
11569 | - be128 tmp = { 0 }; | |
11570 | + be128 tmp = { 0, 0 }; | |
11571 | int bsize = crypto_cipher_blocksize(child); | |
11572 | ||
11573 | crypto_cipher_clear_flags(child, CRYPTO_TFM_REQ_MASK); | |
4dee9bd5 | 11574 | diff -urNp linux-2.6.25.4/Documentation/dontdiff linux-2.6.25.4/Documentation/dontdiff |
11575 | --- linux-2.6.25.4/Documentation/dontdiff 2008-05-15 11:00:12.000000000 -0400 | |
11576 | +++ linux-2.6.25.4/Documentation/dontdiff 2008-05-18 13:33:15.000000000 -0400 | |
da5b3fc8 | 11577 | @@ -3,6 +3,7 @@ |
11578 | *.bin | |
11579 | *.cpio | |
11580 | *.css | |
11581 | +*.dbg | |
11582 | *.dvi | |
11583 | *.eps | |
11584 | *.gif | |
4dee9bd5 | 11585 | @@ -55,6 +56,7 @@ ChangeSet |
11586 | Image | |
11587 | Kerntypes | |
11588 | MODS.txt | |
11589 | +Module.markers | |
11590 | Module.symvers | |
11591 | PENDING | |
11592 | SCCS | |
11593 | @@ -89,6 +91,7 @@ config_data.gz* | |
11594 | conmakehash | |
11595 | consolemap_deftbl.c* | |
11596 | crc32table.h* | |
11597 | +cpustr.h | |
11598 | cscope.* | |
11599 | defkeymap.c* | |
11600 | devlist.h* | |
11601 | @@ -137,11 +140,13 @@ miboot* | |
11602 | mk_elfconfig | |
11603 | mkboot | |
11604 | mkbugboot | |
11605 | +mkcpustr | |
11606 | mkdep | |
11607 | mkprep | |
11608 | mktables | |
11609 | mktree | |
11610 | modpost | |
11611 | +modules.order | |
11612 | modversions.h* | |
11613 | offset.h | |
11614 | offsets.h | |
11615 | @@ -172,20 +177,24 @@ sm_tbl* | |
11616 | split-include | |
11617 | tags | |
11618 | tftpboot.img | |
11619 | +timeconst.h | |
11620 | times.h* | |
11621 | tkparse | |
11622 | trix_boot.h | |
11623 | utsrelease.h* | |
11624 | -vdso.lds | |
11625 | +vdso*.lds | |
11626 | version.h* | |
50425a20 | 11627 | vmlinux |
11628 | vmlinux-* | |
8a4b4a5e | 11629 | vmlinux.aout |
da5b3fc8 | 11630 | -vmlinux*.lds* |
50425a20 | 11631 | +vmlinux.bin.all |
da5b3fc8 | 11632 | +vmlinux*.lds |
50425a20 | 11633 | +vmlinux.relocs |
da5b3fc8 | 11634 | vmlinux*.scr |
11635 | -vsyscall.lds | |
11636 | +vsyscall*.lds | |
50425a20 | 11637 | wanxlfw.inc |
11638 | uImage | |
8a4b4a5e | 11639 | unifdef |
50425a20 | 11640 | +utsrelease.h |
8a4b4a5e | 11641 | zImage* |
11642 | zconf.hash.c | |
4dee9bd5 | 11643 | diff -urNp linux-2.6.25.4/drivers/acpi/blacklist.c linux-2.6.25.4/drivers/acpi/blacklist.c |
11644 | --- linux-2.6.25.4/drivers/acpi/blacklist.c 2008-05-15 11:00:12.000000000 -0400 | |
11645 | +++ linux-2.6.25.4/drivers/acpi/blacklist.c 2008-05-18 13:33:15.000000000 -0400 | |
11646 | @@ -71,7 +71,7 @@ static struct acpi_blacklist_item acpi_b | |
11647 | {"IBM ", "TP600E ", 0x00000105, ACPI_SIG_DSDT, less_than_or_equal, | |
11648 | "Incorrect _ADR", 1}, | |
50425a20 | 11649 | |
11650 | - {""} | |
11651 | + {"", "", 0, 0, 0, all_versions, 0} | |
11652 | }; | |
11653 | ||
11654 | #if CONFIG_ACPI_BLACKLIST_YEAR | |
4dee9bd5 | 11655 | diff -urNp linux-2.6.25.4/drivers/acpi/osl.c linux-2.6.25.4/drivers/acpi/osl.c |
11656 | --- linux-2.6.25.4/drivers/acpi/osl.c 2008-05-15 11:00:12.000000000 -0400 | |
11657 | +++ linux-2.6.25.4/drivers/acpi/osl.c 2008-05-18 13:33:15.000000000 -0400 | |
11658 | @@ -489,6 +489,8 @@ acpi_os_read_memory(acpi_physical_addres | |
da5b3fc8 | 11659 | void __iomem *virt_addr; |
11660 | ||
11661 | virt_addr = ioremap(phys_addr, width); | |
11662 | + if (!virt_addr) | |
11663 | + return AE_NO_MEMORY; | |
11664 | if (!value) | |
11665 | value = &dummy; | |
11666 | ||
4dee9bd5 | 11667 | @@ -517,6 +519,8 @@ acpi_os_write_memory(acpi_physical_addre |
da5b3fc8 | 11668 | void __iomem *virt_addr; |
11669 | ||
11670 | virt_addr = ioremap(phys_addr, width); | |
11671 | + if (!virt_addr) | |
11672 | + return AE_NO_MEMORY; | |
11673 | ||
11674 | switch (width) { | |
11675 | case 8: | |
4dee9bd5 | 11676 | diff -urNp linux-2.6.25.4/drivers/acpi/processor_core.c linux-2.6.25.4/drivers/acpi/processor_core.c |
11677 | --- linux-2.6.25.4/drivers/acpi/processor_core.c 2008-05-15 11:00:12.000000000 -0400 | |
11678 | +++ linux-2.6.25.4/drivers/acpi/processor_core.c 2008-05-18 13:33:15.000000000 -0400 | |
da5b3fc8 | 11679 | @@ -632,7 +632,7 @@ static int __cpuinit acpi_processor_star |
50425a20 | 11680 | return 0; |
11681 | } | |
11682 | ||
da5b3fc8 | 11683 | - BUG_ON((pr->id >= nr_cpu_ids) || (pr->id < 0)); |
11684 | + BUG_ON(pr->id >= nr_cpu_ids); | |
50425a20 | 11685 | |
11686 | /* | |
11687 | * Buggy BIOS check | |
4dee9bd5 | 11688 | diff -urNp linux-2.6.25.4/drivers/acpi/processor_idle.c linux-2.6.25.4/drivers/acpi/processor_idle.c |
11689 | --- linux-2.6.25.4/drivers/acpi/processor_idle.c 2008-05-15 11:00:12.000000000 -0400 | |
11690 | +++ linux-2.6.25.4/drivers/acpi/processor_idle.c 2008-05-18 13:33:15.000000000 -0400 | |
11691 | @@ -181,7 +181,7 @@ static struct dmi_system_id __cpuinitdat | |
50425a20 | 11692 | DMI_MATCH(DMI_BIOS_VENDOR,"Phoenix Technologies LTD"), |
11693 | DMI_MATCH(DMI_BIOS_VERSION,"SHE845M0.86C.0013.D.0302131307")}, | |
11694 | (void *)2}, | |
11695 | - {}, | |
11696 | + { NULL, NULL, {DMI_MATCH(DMI_NONE, NULL)}, NULL}, | |
11697 | }; | |
11698 | ||
11699 | static inline u32 ticks_elapsed(u32 t1, u32 t2) | |
4dee9bd5 | 11700 | diff -urNp linux-2.6.25.4/drivers/acpi/sleep/main.c linux-2.6.25.4/drivers/acpi/sleep/main.c |
11701 | --- linux-2.6.25.4/drivers/acpi/sleep/main.c 2008-05-15 11:00:12.000000000 -0400 | |
11702 | +++ linux-2.6.25.4/drivers/acpi/sleep/main.c 2008-05-18 13:33:15.000000000 -0400 | |
11703 | @@ -250,7 +250,7 @@ static struct dmi_system_id __initdata a | |
50425a20 | 11704 | .ident = "Toshiba Satellite 4030cdt", |
11705 | .matches = {DMI_MATCH(DMI_PRODUCT_NAME, "S4030CDT/4.3"),}, | |
11706 | }, | |
11707 | - {}, | |
11708 | + { NULL, NULL, {DMI_MATCH(DMI_NONE, NULL)}, NULL}, | |
11709 | }; | |
da5b3fc8 | 11710 | #endif /* CONFIG_SUSPEND */ |
50425a20 | 11711 | |
4dee9bd5 | 11712 | diff -urNp linux-2.6.25.4/drivers/acpi/tables/tbfadt.c linux-2.6.25.4/drivers/acpi/tables/tbfadt.c |
11713 | --- linux-2.6.25.4/drivers/acpi/tables/tbfadt.c 2008-05-15 11:00:12.000000000 -0400 | |
11714 | +++ linux-2.6.25.4/drivers/acpi/tables/tbfadt.c 2008-05-18 13:33:15.000000000 -0400 | |
50425a20 | 11715 | @@ -48,7 +48,7 @@ |
11716 | ACPI_MODULE_NAME("tbfadt") | |
11717 | ||
11718 | /* Local prototypes */ | |
11719 | -static void inline | |
11720 | +static inline void | |
11721 | acpi_tb_init_generic_address(struct acpi_generic_address *generic_address, | |
11722 | u8 bit_width, u64 address); | |
11723 | ||
11724 | @@ -122,7 +122,7 @@ static struct acpi_fadt_info fadt_info_t | |
11725 | * | |
11726 | ******************************************************************************/ | |
11727 | ||
11728 | -static void inline | |
11729 | +static inline void | |
11730 | acpi_tb_init_generic_address(struct acpi_generic_address *generic_address, | |
11731 | u8 bit_width, u64 address) | |
11732 | { | |
4dee9bd5 | 11733 | diff -urNp linux-2.6.25.4/drivers/acpi/tables/tbxface.c linux-2.6.25.4/drivers/acpi/tables/tbxface.c |
11734 | --- linux-2.6.25.4/drivers/acpi/tables/tbxface.c 2008-05-15 11:00:12.000000000 -0400 | |
11735 | +++ linux-2.6.25.4/drivers/acpi/tables/tbxface.c 2008-05-18 13:33:15.000000000 -0400 | |
da5b3fc8 | 11736 | @@ -540,7 +540,7 @@ static acpi_status acpi_tb_load_namespac |
11737 | acpi_tb_print_table_header(0, table); | |
11738 | ||
11739 | if (no_auto_ssdt == 0) { | |
11740 | - printk(KERN_WARNING "ACPI: DSDT override uses original SSDTs unless \"acpi_no_auto_ssdt\""); | |
11741 | + printk(KERN_WARNING "ACPI: DSDT override uses original SSDTs unless \"acpi_no_auto_ssdt\"\n"); | |
11742 | } | |
11743 | } | |
11744 | ||
4dee9bd5 | 11745 | diff -urNp linux-2.6.25.4/drivers/ata/ahci.c linux-2.6.25.4/drivers/ata/ahci.c |
11746 | --- linux-2.6.25.4/drivers/ata/ahci.c 2008-05-15 11:00:12.000000000 -0400 | |
11747 | +++ linux-2.6.25.4/drivers/ata/ahci.c 2008-05-18 13:33:15.000000000 -0400 | |
11748 | @@ -598,7 +598,7 @@ static const struct pci_device_id ahci_p | |
da5b3fc8 | 11749 | { PCI_ANY_ID, PCI_ANY_ID, PCI_ANY_ID, PCI_ANY_ID, |
11750 | PCI_CLASS_STORAGE_SATA_AHCI, 0xffffff, board_ahci }, | |
11751 | ||
11752 | - { } /* terminate list */ | |
11753 | + { 0, 0, 0, 0, 0, 0, 0 } /* terminate list */ | |
11754 | }; | |
11755 | ||
11756 | ||
4dee9bd5 | 11757 | diff -urNp linux-2.6.25.4/drivers/ata/ata_piix.c linux-2.6.25.4/drivers/ata/ata_piix.c |
11758 | --- linux-2.6.25.4/drivers/ata/ata_piix.c 2008-05-15 11:00:12.000000000 -0400 | |
11759 | +++ linux-2.6.25.4/drivers/ata/ata_piix.c 2008-05-18 13:33:15.000000000 -0400 | |
11760 | @@ -276,7 +276,7 @@ static const struct pci_device_id piix_p | |
11761 | /* SATA Controller IDE (ICH10) */ | |
11762 | { 0x8086, 0x3a26, PCI_ANY_ID, PCI_ANY_ID, 0, 0, ich8_2port_sata }, | |
50425a20 | 11763 | |
11764 | - { } /* terminate list */ | |
11765 | + { 0, 0, 0, 0, 0, 0, 0 } /* terminate list */ | |
11766 | }; | |
11767 | ||
11768 | static struct pci_driver piix_pci_driver = { | |
4dee9bd5 | 11769 | @@ -723,7 +723,7 @@ static const struct ich_laptop ich_lapto |
da5b3fc8 | 11770 | { 0x27DF, 0x103C, 0x30A1 }, /* ICH7 on HP Compaq nc2400 */ |
8a4b4a5e | 11771 | { 0x24CA, 0x1025, 0x0061 }, /* ICH4 on ACER Aspire 2023WLMi */ |
50425a20 | 11772 | /* end marker */ |
11773 | - { 0, } | |
11774 | + { 0, 0, 0 } | |
11775 | }; | |
11776 | ||
11777 | /** | |
4dee9bd5 | 11778 | @@ -1307,7 +1307,7 @@ static int piix_broken_suspend(void) |
da5b3fc8 | 11779 | }, |
11780 | }, | |
11781 | ||
11782 | - { } /* terminate list */ | |
11783 | + { NULL, NULL, {DMI_MATCH(DMI_NONE, NULL)}, NULL } /* terminate list */ | |
11784 | }; | |
11785 | static const char *oemstrs[] = { | |
11786 | "Tecra M3,", | |
4dee9bd5 | 11787 | diff -urNp linux-2.6.25.4/drivers/ata/libata-core.c linux-2.6.25.4/drivers/ata/libata-core.c |
11788 | --- linux-2.6.25.4/drivers/ata/libata-core.c 2008-05-15 11:00:12.000000000 -0400 | |
11789 | +++ linux-2.6.25.4/drivers/ata/libata-core.c 2008-05-18 13:33:15.000000000 -0400 | |
11790 | @@ -725,7 +725,7 @@ static const struct ata_xfer_ent { | |
11791 | { ATA_SHIFT_PIO, ATA_NR_PIO_MODES, XFER_PIO_0 }, | |
11792 | { ATA_SHIFT_MWDMA, ATA_NR_MWDMA_MODES, XFER_MW_DMA_0 }, | |
11793 | { ATA_SHIFT_UDMA, ATA_NR_UDMA_MODES, XFER_UDMA_0 }, | |
50425a20 | 11794 | - { -1, }, |
4dee9bd5 | 11795 | + { -1, 0, 0 } |
50425a20 | 11796 | }; |
11797 | ||
11798 | /** | |
4dee9bd5 | 11799 | @@ -3043,7 +3043,7 @@ static const struct ata_timing ata_timin |
11800 | { XFER_UDMA_5, 0, 0, 0, 0, 0, 0, 0, 20 }, | |
11801 | { XFER_UDMA_6, 0, 0, 0, 0, 0, 0, 0, 15 }, | |
50425a20 | 11802 | |
11803 | - { 0xFF } | |
11804 | + { 0xFF, 0, 0, 0, 0, 0, 0, 0, 0 } | |
11805 | }; | |
11806 | ||
da5b3fc8 | 11807 | #define ENOUGH(v, unit) (((v)-1)/(unit)+1) |
4dee9bd5 | 11808 | @@ -4453,7 +4453,7 @@ static const struct ata_blacklist_entry |
da5b3fc8 | 11809 | { "TSSTcorp CDDVDW SH-S202N", "SB01", ATA_HORKAGE_IVB, }, |
50425a20 | 11810 | |
11811 | /* End Marker */ | |
11812 | - { } | |
11813 | + { NULL, NULL, 0 } | |
11814 | }; | |
11815 | ||
da5b3fc8 | 11816 | static int strn_pattern_cmp(const char *patt, const char *name, int wildchar) |
4dee9bd5 | 11817 | diff -urNp linux-2.6.25.4/drivers/char/agp/frontend.c linux-2.6.25.4/drivers/char/agp/frontend.c |
11818 | --- linux-2.6.25.4/drivers/char/agp/frontend.c 2008-05-15 11:00:12.000000000 -0400 | |
11819 | +++ linux-2.6.25.4/drivers/char/agp/frontend.c 2008-05-18 13:33:15.000000000 -0400 | |
da5b3fc8 | 11820 | @@ -820,7 +820,7 @@ static int agpioc_reserve_wrap(struct ag |
50425a20 | 11821 | if (copy_from_user(&reserve, arg, sizeof(struct agp_region))) |
11822 | return -EFAULT; | |
11823 | ||
11824 | - if ((unsigned) reserve.seg_count >= ~0U/sizeof(struct agp_segment)) | |
11825 | + if ((unsigned) reserve.seg_count >= ~0U/sizeof(struct agp_segment_priv)) | |
11826 | return -EFAULT; | |
11827 | ||
11828 | client = agp_find_client_by_pid(reserve.pid); | |
4dee9bd5 | 11829 | diff -urNp linux-2.6.25.4/drivers/char/agp/intel-agp.c linux-2.6.25.4/drivers/char/agp/intel-agp.c |
11830 | --- linux-2.6.25.4/drivers/char/agp/intel-agp.c 2008-05-15 11:00:12.000000000 -0400 | |
11831 | +++ linux-2.6.25.4/drivers/char/agp/intel-agp.c 2008-05-18 13:33:15.000000000 -0400 | |
11832 | @@ -2254,7 +2254,7 @@ static struct pci_device_id agp_intel_pc | |
8a4b4a5e | 11833 | ID(PCI_DEVICE_ID_INTEL_Q35_HB), |
11834 | ID(PCI_DEVICE_ID_INTEL_Q33_HB), | |
4dee9bd5 | 11835 | ID(PCI_DEVICE_ID_INTEL_IGD_HB), |
50425a20 | 11836 | - { } |
11837 | + { 0, 0, 0, 0, 0, 0, 0 } | |
11838 | }; | |
11839 | ||
11840 | MODULE_DEVICE_TABLE(pci, agp_intel_pci_table); | |
4dee9bd5 | 11841 | diff -urNp linux-2.6.25.4/drivers/char/drm/drm_pciids.h linux-2.6.25.4/drivers/char/drm/drm_pciids.h |
11842 | --- linux-2.6.25.4/drivers/char/drm/drm_pciids.h 2008-05-15 11:00:12.000000000 -0400 | |
11843 | +++ linux-2.6.25.4/drivers/char/drm/drm_pciids.h 2008-05-18 13:33:15.000000000 -0400 | |
11844 | @@ -348,7 +348,7 @@ | |
50425a20 | 11845 | {0x8086, 0x7123, PCI_ANY_ID, PCI_ANY_ID, 0, 0, 0}, \ |
11846 | {0x8086, 0x7125, PCI_ANY_ID, PCI_ANY_ID, 0, 0, 0}, \ | |
11847 | {0x8086, 0x1132, PCI_ANY_ID, PCI_ANY_ID, 0, 0, 0}, \ | |
11848 | - {0, 0, 0} | |
11849 | + {0, 0, 0, 0, 0, 0, 0 } | |
11850 | ||
11851 | #define i830_PCI_IDS \ | |
11852 | {0x8086, 0x3577, PCI_ANY_ID, PCI_ANY_ID, 0, 0, 0}, \ | |
4dee9bd5 | 11853 | diff -urNp linux-2.6.25.4/drivers/char/hpet.c linux-2.6.25.4/drivers/char/hpet.c |
11854 | --- linux-2.6.25.4/drivers/char/hpet.c 2008-05-15 11:00:12.000000000 -0400 | |
11855 | +++ linux-2.6.25.4/drivers/char/hpet.c 2008-05-18 13:33:15.000000000 -0400 | |
11856 | @@ -953,7 +953,7 @@ static struct acpi_driver hpet_acpi_driv | |
50425a20 | 11857 | }, |
11858 | }; | |
11859 | ||
11860 | -static struct miscdevice hpet_misc = { HPET_MINOR, "hpet", &hpet_fops }; | |
11861 | +static struct miscdevice hpet_misc = { HPET_MINOR, "hpet", &hpet_fops, {NULL, NULL}, NULL, NULL }; | |
11862 | ||
11863 | static int __init hpet_init(void) | |
11864 | { | |
4dee9bd5 | 11865 | diff -urNp linux-2.6.25.4/drivers/char/keyboard.c linux-2.6.25.4/drivers/char/keyboard.c |
11866 | --- linux-2.6.25.4/drivers/char/keyboard.c 2008-05-15 11:00:12.000000000 -0400 | |
11867 | +++ linux-2.6.25.4/drivers/char/keyboard.c 2008-05-18 13:33:15.000000000 -0400 | |
11868 | @@ -630,6 +630,16 @@ static void k_spec(struct vc_data *vc, u | |
50425a20 | 11869 | kbd->kbdmode == VC_MEDIUMRAW) && |
11870 | value != KVAL(K_SAK)) | |
11871 | return; /* SAK is allowed even in raw mode */ | |
11872 | + | |
11873 | +#if defined(CONFIG_GRKERNSEC_PROC) || defined(CONFIG_GRKERNSEC_PROC_MEMMAP) | |
11874 | + { | |
11875 | + void *func = fn_handler[value]; | |
11876 | + if (func == fn_show_state || func == fn_show_ptregs || | |
11877 | + func == fn_show_mem) | |
11878 | + return; | |
11879 | + } | |
11880 | +#endif | |
11881 | + | |
11882 | fn_handler[value](vc); | |
11883 | } | |
11884 | ||
4dee9bd5 | 11885 | @@ -1384,7 +1394,7 @@ static const struct input_device_id kbd_ |
da5b3fc8 | 11886 | .evbit = { BIT_MASK(EV_SND) }, |
50425a20 | 11887 | }, |
11888 | ||
11889 | - { }, /* Terminating entry */ | |
11890 | + { 0 }, /* Terminating entry */ | |
11891 | }; | |
11892 | ||
11893 | MODULE_DEVICE_TABLE(input, kbd_ids); | |
4dee9bd5 | 11894 | diff -urNp linux-2.6.25.4/drivers/char/mem.c linux-2.6.25.4/drivers/char/mem.c |
11895 | --- linux-2.6.25.4/drivers/char/mem.c 2008-05-15 11:00:12.000000000 -0400 | |
11896 | +++ linux-2.6.25.4/drivers/char/mem.c 2008-05-18 13:33:15.000000000 -0400 | |
8a4b4a5e | 11897 | @@ -26,6 +26,7 @@ |
50425a20 | 11898 | #include <linux/bootmem.h> |
da5b3fc8 | 11899 | #include <linux/splice.h> |
50425a20 | 11900 | #include <linux/pfn.h> |
11901 | +#include <linux/grsecurity.h> | |
11902 | ||
11903 | #include <asm/uaccess.h> | |
11904 | #include <asm/io.h> | |
8a4b4a5e | 11905 | @@ -34,6 +35,10 @@ |
50425a20 | 11906 | # include <linux/efi.h> |
11907 | #endif | |
11908 | ||
11909 | +#ifdef CONFIG_GRKERNSEC | |
11910 | +extern struct file_operations grsec_fops; | |
11911 | +#endif | |
11912 | + | |
11913 | /* | |
11914 | * Architectures vary in how they handle caching for addresses | |
11915 | * outside of main memory. | |
da5b3fc8 | 11916 | @@ -180,6 +185,11 @@ static ssize_t write_mem(struct file * f |
50425a20 | 11917 | if (!valid_phys_addr_range(p, count)) |
11918 | return -EFAULT; | |
11919 | ||
11920 | +#ifdef CONFIG_GRKERNSEC_KMEM | |
11921 | + gr_handle_mem_write(); | |
11922 | + return -EPERM; | |
11923 | +#endif | |
11924 | + | |
11925 | written = 0; | |
11926 | ||
11927 | #ifdef __ARCH_HAS_NO_PAGE_ZERO_MAPPED | |
da5b3fc8 | 11928 | @@ -281,6 +291,11 @@ static int mmap_mem(struct file * file, |
50425a20 | 11929 | if (!private_mapping_ok(vma)) |
11930 | return -ENOSYS; | |
11931 | ||
11932 | +#ifdef CONFIG_GRKERNSEC_KMEM | |
11933 | + if (gr_handle_mem_mmap(vma->vm_pgoff << PAGE_SHIFT, vma)) | |
11934 | + return -EPERM; | |
11935 | +#endif | |
11936 | + | |
11937 | vma->vm_page_prot = phys_mem_access_prot(file, vma->vm_pgoff, | |
11938 | size, | |
11939 | vma->vm_page_prot); | |
da5b3fc8 | 11940 | @@ -512,6 +527,11 @@ static ssize_t write_kmem(struct file * |
50425a20 | 11941 | ssize_t written; |
11942 | char * kbuf; /* k-addr because vwrite() takes vmlist_lock rwlock */ | |
11943 | ||
11944 | +#ifdef CONFIG_GRKERNSEC_KMEM | |
11945 | + gr_handle_kmem_write(); | |
11946 | + return -EPERM; | |
11947 | +#endif | |
11948 | + | |
11949 | if (p < (unsigned long) high_memory) { | |
11950 | ||
11951 | wrote = count; | |
da5b3fc8 | 11952 | @@ -714,6 +734,16 @@ static loff_t memory_lseek(struct file * |
50425a20 | 11953 | |
11954 | static int open_port(struct inode * inode, struct file * filp) | |
11955 | { | |
11956 | +#ifdef CONFIG_GRKERNSEC_KMEM | |
11957 | + gr_handle_open_port(); | |
11958 | + return -EPERM; | |
11959 | +#endif | |
11960 | + | |
11961 | + return capable(CAP_SYS_RAWIO) ? 0 : -EPERM; | |
11962 | +} | |
11963 | + | |
11964 | +static int open_mem(struct inode * inode, struct file * filp) | |
11965 | +{ | |
11966 | return capable(CAP_SYS_RAWIO) ? 0 : -EPERM; | |
11967 | } | |
11968 | ||
da5b3fc8 | 11969 | @@ -721,7 +751,6 @@ static int open_port(struct inode * inod |
50425a20 | 11970 | #define full_lseek null_lseek |
11971 | #define write_zero write_null | |
11972 | #define read_full read_zero | |
11973 | -#define open_mem open_port | |
11974 | #define open_kmem open_mem | |
11975 | #define open_oldmem open_mem | |
11976 | ||
da5b3fc8 | 11977 | @@ -854,6 +883,11 @@ static int memory_open(struct inode * in |
50425a20 | 11978 | filp->f_op = &oldmem_fops; |
11979 | break; | |
11980 | #endif | |
11981 | +#ifdef CONFIG_GRKERNSEC | |
11982 | + case 13: | |
11983 | + filp->f_op = &grsec_fops; | |
11984 | + break; | |
11985 | +#endif | |
11986 | default: | |
11987 | return -ENXIO; | |
11988 | } | |
da5b3fc8 | 11989 | @@ -886,6 +920,9 @@ static const struct { |
50425a20 | 11990 | #ifdef CONFIG_CRASH_DUMP |
11991 | {12,"oldmem", S_IRUSR | S_IWUSR | S_IRGRP, &oldmem_fops}, | |
11992 | #endif | |
11993 | +#ifdef CONFIG_GRKERNSEC | |
11994 | + {13,"grsec", S_IRUSR | S_IWUGO, &grsec_fops}, | |
11995 | +#endif | |
11996 | }; | |
11997 | ||
11998 | static struct class *mem_class; | |
4dee9bd5 | 11999 | diff -urNp linux-2.6.25.4/drivers/char/nvram.c linux-2.6.25.4/drivers/char/nvram.c |
12000 | --- linux-2.6.25.4/drivers/char/nvram.c 2008-05-15 11:00:12.000000000 -0400 | |
12001 | +++ linux-2.6.25.4/drivers/char/nvram.c 2008-05-18 13:33:15.000000000 -0400 | |
da5b3fc8 | 12002 | @@ -430,7 +430,10 @@ static const struct file_operations nvra |
50425a20 | 12003 | static struct miscdevice nvram_dev = { |
12004 | NVRAM_MINOR, | |
12005 | "nvram", | |
12006 | - &nvram_fops | |
12007 | + &nvram_fops, | |
12008 | + {NULL, NULL}, | |
12009 | + NULL, | |
12010 | + NULL | |
12011 | }; | |
12012 | ||
12013 | static int __init | |
4dee9bd5 | 12014 | diff -urNp linux-2.6.25.4/drivers/char/random.c linux-2.6.25.4/drivers/char/random.c |
12015 | --- linux-2.6.25.4/drivers/char/random.c 2008-05-15 11:00:12.000000000 -0400 | |
12016 | +++ linux-2.6.25.4/drivers/char/random.c 2008-05-18 13:33:15.000000000 -0400 | |
50425a20 | 12017 | @@ -248,8 +248,13 @@ |
12018 | /* | |
12019 | * Configuration information | |
12020 | */ | |
12021 | +#ifdef CONFIG_GRKERNSEC_RANDNET | |
12022 | +#define INPUT_POOL_WORDS 512 | |
12023 | +#define OUTPUT_POOL_WORDS 128 | |
12024 | +#else | |
12025 | #define INPUT_POOL_WORDS 128 | |
12026 | #define OUTPUT_POOL_WORDS 32 | |
12027 | +#endif | |
12028 | #define SEC_XFER_SIZE 512 | |
12029 | ||
12030 | /* | |
12031 | @@ -286,10 +291,17 @@ static struct poolinfo { | |
12032 | int poolwords; | |
12033 | int tap1, tap2, tap3, tap4, tap5; | |
12034 | } poolinfo_table[] = { | |
12035 | +#ifdef CONFIG_GRKERNSEC_RANDNET | |
12036 | + /* x^512 + x^411 + x^308 + x^208 +x^104 + x + 1 -- 225 */ | |
12037 | + { 512, 411, 308, 208, 104, 1 }, | |
12038 | + /* x^128 + x^103 + x^76 + x^51 + x^25 + x + 1 -- 105 */ | |
12039 | + { 128, 103, 76, 51, 25, 1 }, | |
12040 | +#else | |
12041 | /* x^128 + x^103 + x^76 + x^51 +x^25 + x + 1 -- 105 */ | |
12042 | { 128, 103, 76, 51, 25, 1 }, | |
12043 | /* x^32 + x^26 + x^20 + x^14 + x^7 + x + 1 -- 15 */ | |
12044 | { 32, 26, 20, 14, 7, 1 }, | |
12045 | +#endif | |
12046 | #if 0 | |
12047 | /* x^2048 + x^1638 + x^1231 + x^819 + x^411 + x + 1 -- 115 */ | |
12048 | { 2048, 1638, 1231, 819, 411, 1 }, | |
4dee9bd5 | 12049 | @@ -1171,7 +1183,7 @@ EXPORT_SYMBOL(generate_random_uuid); |
da5b3fc8 | 12050 | #include <linux/sysctl.h> |
12051 | ||
12052 | static int min_read_thresh = 8, min_write_thresh; | |
12053 | -static int max_read_thresh = INPUT_POOL_WORDS * 32; | |
12054 | +static int max_read_thresh = OUTPUT_POOL_WORDS * 32; | |
12055 | static int max_write_thresh = INPUT_POOL_WORDS * 32; | |
12056 | static char sysctl_bootid[16]; | |
12057 | ||
4dee9bd5 | 12058 | diff -urNp linux-2.6.25.4/drivers/char/vt_ioctl.c linux-2.6.25.4/drivers/char/vt_ioctl.c |
12059 | --- linux-2.6.25.4/drivers/char/vt_ioctl.c 2008-05-15 11:00:12.000000000 -0400 | |
12060 | +++ linux-2.6.25.4/drivers/char/vt_ioctl.c 2008-05-18 13:33:15.000000000 -0400 | |
da5b3fc8 | 12061 | @@ -96,6 +96,12 @@ do_kdsk_ioctl(int cmd, struct kbentry __ |
50425a20 | 12062 | case KDSKBENT: |
12063 | if (!perm) | |
12064 | return -EPERM; | |
12065 | + | |
12066 | +#ifdef CONFIG_GRKERNSEC | |
12067 | + if (!capable(CAP_SYS_TTY_CONFIG)) | |
12068 | + return -EPERM; | |
12069 | +#endif | |
12070 | + | |
12071 | if (!i && v == K_NOSUCHMAP) { | |
12072 | /* deallocate map */ | |
12073 | key_map = key_maps[s]; | |
da5b3fc8 | 12074 | @@ -236,6 +242,13 @@ do_kdgkb_ioctl(int cmd, struct kbsentry |
50425a20 | 12075 | goto reterr; |
12076 | } | |
12077 | ||
12078 | +#ifdef CONFIG_GRKERNSEC | |
12079 | + if (!capable(CAP_SYS_TTY_CONFIG)) { | |
12080 | + ret = -EPERM; | |
12081 | + goto reterr; | |
12082 | + } | |
12083 | +#endif | |
12084 | + | |
12085 | q = func_table[i]; | |
12086 | first_free = funcbufptr + (funcbufsize - funcbufleft); | |
12087 | for (j = i+1; j < MAX_NR_FUNC && !func_table[j]; j++) | |
4dee9bd5 | 12088 | diff -urNp linux-2.6.25.4/drivers/edac/edac_core.h linux-2.6.25.4/drivers/edac/edac_core.h |
12089 | --- linux-2.6.25.4/drivers/edac/edac_core.h 2008-05-15 11:00:12.000000000 -0400 | |
12090 | +++ linux-2.6.25.4/drivers/edac/edac_core.h 2008-05-18 13:33:15.000000000 -0400 | |
da5b3fc8 | 12091 | @@ -86,11 +86,11 @@ extern int edac_debug_level; |
50425a20 | 12092 | |
da5b3fc8 | 12093 | #else /* !CONFIG_EDAC_DEBUG */ |
50425a20 | 12094 | |
12095 | -#define debugf0( ... ) | |
12096 | -#define debugf1( ... ) | |
12097 | -#define debugf2( ... ) | |
12098 | -#define debugf3( ... ) | |
12099 | -#define debugf4( ... ) | |
12100 | +#define debugf0( ... ) do {} while (0) | |
12101 | +#define debugf1( ... ) do {} while (0) | |
12102 | +#define debugf2( ... ) do {} while (0) | |
12103 | +#define debugf3( ... ) do {} while (0) | |
12104 | +#define debugf4( ... ) do {} while (0) | |
12105 | ||
da5b3fc8 | 12106 | #endif /* !CONFIG_EDAC_DEBUG */ |
12107 | ||
4dee9bd5 | 12108 | diff -urNp linux-2.6.25.4/drivers/firmware/dmi_scan.c linux-2.6.25.4/drivers/firmware/dmi_scan.c |
12109 | --- linux-2.6.25.4/drivers/firmware/dmi_scan.c 2008-05-15 11:00:12.000000000 -0400 | |
12110 | +++ linux-2.6.25.4/drivers/firmware/dmi_scan.c 2008-05-18 13:33:15.000000000 -0400 | |
12111 | @@ -379,11 +379,6 @@ void __init dmi_scan_machine(void) | |
da5b3fc8 | 12112 | } |
12113 | } | |
12114 | else { | |
12115 | - /* | |
12116 | - * no iounmap() for that ioremap(); it would be a no-op, but | |
12117 | - * it's so early in setup that sucker gets confused into doing | |
12118 | - * what it shouldn't if we actually call it. | |
12119 | - */ | |
12120 | p = dmi_ioremap(0xF0000, 0x10000); | |
12121 | if (p == NULL) | |
12122 | goto out; | |
4dee9bd5 | 12123 | diff -urNp linux-2.6.25.4/drivers/hwmon/fscpos.c linux-2.6.25.4/drivers/hwmon/fscpos.c |
12124 | --- linux-2.6.25.4/drivers/hwmon/fscpos.c 2008-05-15 11:00:12.000000000 -0400 | |
12125 | +++ linux-2.6.25.4/drivers/hwmon/fscpos.c 2008-05-18 13:33:15.000000000 -0400 | |
12126 | @@ -230,7 +230,6 @@ static ssize_t set_pwm(struct i2c_client | |
50425a20 | 12127 | unsigned long v = simple_strtoul(buf, NULL, 10); |
12128 | ||
12129 | /* Range: 0..255 */ | |
12130 | - if (v < 0) v = 0; | |
12131 | if (v > 255) v = 255; | |
12132 | ||
12133 | mutex_lock(&data->update_lock); | |
4dee9bd5 | 12134 | diff -urNp linux-2.6.25.4/drivers/hwmon/k8temp.c linux-2.6.25.4/drivers/hwmon/k8temp.c |
12135 | --- linux-2.6.25.4/drivers/hwmon/k8temp.c 2008-05-15 11:00:12.000000000 -0400 | |
12136 | +++ linux-2.6.25.4/drivers/hwmon/k8temp.c 2008-05-18 13:33:15.000000000 -0400 | |
50425a20 | 12137 | @@ -130,7 +130,7 @@ static DEVICE_ATTR(name, S_IRUGO, show_n |
12138 | ||
12139 | static struct pci_device_id k8temp_ids[] = { | |
12140 | { PCI_DEVICE(PCI_VENDOR_ID_AMD, PCI_DEVICE_ID_AMD_K8_NB_MISC) }, | |
12141 | - { 0 }, | |
12142 | + { 0, 0, 0, 0, 0, 0, 0 }, | |
12143 | }; | |
12144 | ||
12145 | MODULE_DEVICE_TABLE(pci, k8temp_ids); | |
4dee9bd5 | 12146 | diff -urNp linux-2.6.25.4/drivers/hwmon/sis5595.c linux-2.6.25.4/drivers/hwmon/sis5595.c |
12147 | --- linux-2.6.25.4/drivers/hwmon/sis5595.c 2008-05-15 11:00:12.000000000 -0400 | |
12148 | +++ linux-2.6.25.4/drivers/hwmon/sis5595.c 2008-05-18 13:33:15.000000000 -0400 | |
da5b3fc8 | 12149 | @@ -698,7 +698,7 @@ static struct sis5595_data *sis5595_upda |
50425a20 | 12150 | |
12151 | static struct pci_device_id sis5595_pci_ids[] = { | |
12152 | { PCI_DEVICE(PCI_VENDOR_ID_SI, PCI_DEVICE_ID_SI_503) }, | |
12153 | - { 0, } | |
12154 | + { 0, 0, 0, 0, 0, 0, 0 } | |
12155 | }; | |
12156 | ||
12157 | MODULE_DEVICE_TABLE(pci, sis5595_pci_ids); | |
4dee9bd5 | 12158 | diff -urNp linux-2.6.25.4/drivers/hwmon/via686a.c linux-2.6.25.4/drivers/hwmon/via686a.c |
12159 | --- linux-2.6.25.4/drivers/hwmon/via686a.c 2008-05-15 11:00:12.000000000 -0400 | |
12160 | +++ linux-2.6.25.4/drivers/hwmon/via686a.c 2008-05-18 13:33:15.000000000 -0400 | |
12161 | @@ -768,7 +768,7 @@ static struct via686a_data *via686a_upda | |
50425a20 | 12162 | |
12163 | static struct pci_device_id via686a_pci_ids[] = { | |
12164 | { PCI_DEVICE(PCI_VENDOR_ID_VIA, PCI_DEVICE_ID_VIA_82C686_4) }, | |
12165 | - { 0, } | |
12166 | + { 0, 0, 0, 0, 0, 0, 0 } | |
12167 | }; | |
12168 | ||
12169 | MODULE_DEVICE_TABLE(pci, via686a_pci_ids); | |
4dee9bd5 | 12170 | diff -urNp linux-2.6.25.4/drivers/hwmon/vt8231.c linux-2.6.25.4/drivers/hwmon/vt8231.c |
12171 | --- linux-2.6.25.4/drivers/hwmon/vt8231.c 2008-05-15 11:00:12.000000000 -0400 | |
12172 | +++ linux-2.6.25.4/drivers/hwmon/vt8231.c 2008-05-18 13:33:15.000000000 -0400 | |
12173 | @@ -698,7 +698,7 @@ static struct platform_driver vt8231_dri | |
50425a20 | 12174 | |
12175 | static struct pci_device_id vt8231_pci_ids[] = { | |
12176 | { PCI_DEVICE(PCI_VENDOR_ID_VIA, PCI_DEVICE_ID_VIA_8231_4) }, | |
12177 | - { 0, } | |
12178 | + { 0, 0, 0, 0, 0, 0, 0 } | |
12179 | }; | |
12180 | ||
12181 | MODULE_DEVICE_TABLE(pci, vt8231_pci_ids); | |
4dee9bd5 | 12182 | diff -urNp linux-2.6.25.4/drivers/hwmon/w83791d.c linux-2.6.25.4/drivers/hwmon/w83791d.c |
12183 | --- linux-2.6.25.4/drivers/hwmon/w83791d.c 2008-05-15 11:00:12.000000000 -0400 | |
12184 | +++ linux-2.6.25.4/drivers/hwmon/w83791d.c 2008-05-18 13:33:15.000000000 -0400 | |
12185 | @@ -290,8 +290,8 @@ static int w83791d_attach_adapter(struct | |
50425a20 | 12186 | static int w83791d_detect(struct i2c_adapter *adapter, int address, int kind); |
12187 | static int w83791d_detach_client(struct i2c_client *client); | |
12188 | ||
12189 | -static int w83791d_read(struct i2c_client *client, u8 register); | |
12190 | -static int w83791d_write(struct i2c_client *client, u8 register, u8 value); | |
12191 | +static int w83791d_read(struct i2c_client *client, u8 reg); | |
12192 | +static int w83791d_write(struct i2c_client *client, u8 reg, u8 value); | |
12193 | static struct w83791d_data *w83791d_update_device(struct device *dev); | |
12194 | ||
12195 | #ifdef DEBUG | |
4dee9bd5 | 12196 | diff -urNp linux-2.6.25.4/drivers/i2c/busses/i2c-i801.c linux-2.6.25.4/drivers/i2c/busses/i2c-i801.c |
12197 | --- linux-2.6.25.4/drivers/i2c/busses/i2c-i801.c 2008-05-15 11:00:12.000000000 -0400 | |
12198 | +++ linux-2.6.25.4/drivers/i2c/busses/i2c-i801.c 2008-05-18 13:33:15.000000000 -0400 | |
12199 | @@ -592,7 +592,7 @@ static struct pci_device_id i801_ids[] = | |
da5b3fc8 | 12200 | { PCI_DEVICE(PCI_VENDOR_ID_INTEL, PCI_DEVICE_ID_INTEL_TOLAPAI_1) }, |
4dee9bd5 | 12201 | { PCI_DEVICE(PCI_VENDOR_ID_INTEL, PCI_DEVICE_ID_INTEL_ICH10_4) }, |
12202 | { PCI_DEVICE(PCI_VENDOR_ID_INTEL, PCI_DEVICE_ID_INTEL_ICH10_5) }, | |
50425a20 | 12203 | - { 0, } |
12204 | + { 0, 0, 0, 0, 0, 0, 0 } | |
12205 | }; | |
12206 | ||
12207 | MODULE_DEVICE_TABLE (pci, i801_ids); | |
4dee9bd5 | 12208 | diff -urNp linux-2.6.25.4/drivers/i2c/busses/i2c-i810.c linux-2.6.25.4/drivers/i2c/busses/i2c-i810.c |
12209 | --- linux-2.6.25.4/drivers/i2c/busses/i2c-i810.c 2008-05-15 11:00:12.000000000 -0400 | |
12210 | +++ linux-2.6.25.4/drivers/i2c/busses/i2c-i810.c 2008-05-18 13:33:15.000000000 -0400 | |
50425a20 | 12211 | @@ -198,7 +198,7 @@ static struct pci_device_id i810_ids[] _ |
12212 | { PCI_DEVICE(PCI_VENDOR_ID_INTEL, PCI_DEVICE_ID_INTEL_82810E_IG) }, | |
12213 | { PCI_DEVICE(PCI_VENDOR_ID_INTEL, PCI_DEVICE_ID_INTEL_82815_CGC) }, | |
12214 | { PCI_DEVICE(PCI_VENDOR_ID_INTEL, PCI_DEVICE_ID_INTEL_82845G_IG) }, | |
12215 | - { 0, }, | |
12216 | + { 0, 0, 0, 0, 0, 0, 0 }, | |
12217 | }; | |
12218 | ||
12219 | MODULE_DEVICE_TABLE (pci, i810_ids); | |
4dee9bd5 | 12220 | diff -urNp linux-2.6.25.4/drivers/i2c/busses/i2c-piix4.c linux-2.6.25.4/drivers/i2c/busses/i2c-piix4.c |
12221 | --- linux-2.6.25.4/drivers/i2c/busses/i2c-piix4.c 2008-05-15 11:00:12.000000000 -0400 | |
12222 | +++ linux-2.6.25.4/drivers/i2c/busses/i2c-piix4.c 2008-05-18 13:33:15.000000000 -0400 | |
12223 | @@ -133,7 +133,7 @@ static struct dmi_system_id __devinitdat | |
50425a20 | 12224 | .ident = "IBM", |
12225 | .matches = { DMI_MATCH(DMI_SYS_VENDOR, "IBM"), }, | |
12226 | }, | |
12227 | - { }, | |
12228 | + { NULL, NULL, {DMI_MATCH(DMI_NONE, NULL)}, NULL }, | |
12229 | }; | |
12230 | ||
12231 | static int __devinit piix4_setup(struct pci_dev *PIIX4_dev, | |
4dee9bd5 | 12232 | @@ -428,7 +428,7 @@ static struct pci_device_id piix4_ids[] |
12233 | PCI_DEVICE_ID_SERVERWORKS_CSB6) }, | |
12234 | { PCI_DEVICE(PCI_VENDOR_ID_SERVERWORKS, | |
12235 | PCI_DEVICE_ID_SERVERWORKS_HT1000SB) }, | |
50425a20 | 12236 | - { 0, } |
12237 | + { 0, 0, 0, 0, 0, 0, 0 } | |
12238 | }; | |
12239 | ||
12240 | MODULE_DEVICE_TABLE (pci, piix4_ids); | |
4dee9bd5 | 12241 | diff -urNp linux-2.6.25.4/drivers/i2c/busses/i2c-sis630.c linux-2.6.25.4/drivers/i2c/busses/i2c-sis630.c |
12242 | --- linux-2.6.25.4/drivers/i2c/busses/i2c-sis630.c 2008-05-15 11:00:12.000000000 -0400 | |
12243 | +++ linux-2.6.25.4/drivers/i2c/busses/i2c-sis630.c 2008-05-18 13:33:15.000000000 -0400 | |
8a4b4a5e | 12244 | @@ -465,7 +465,7 @@ static struct i2c_adapter sis630_adapter |
12245 | static struct pci_device_id sis630_ids[] __devinitdata = { | |
12246 | { PCI_DEVICE(PCI_VENDOR_ID_SI, PCI_DEVICE_ID_SI_503) }, | |
12247 | { PCI_DEVICE(PCI_VENDOR_ID_SI, PCI_DEVICE_ID_SI_LPC) }, | |
12248 | - { 0, } | |
da5b3fc8 | 12249 | + { 0, 0, 0, 0, 0, 0, 0 } |
8a4b4a5e | 12250 | }; |
50425a20 | 12251 | |
8a4b4a5e | 12252 | MODULE_DEVICE_TABLE (pci, sis630_ids); |
4dee9bd5 | 12253 | diff -urNp linux-2.6.25.4/drivers/i2c/busses/i2c-sis96x.c linux-2.6.25.4/drivers/i2c/busses/i2c-sis96x.c |
12254 | --- linux-2.6.25.4/drivers/i2c/busses/i2c-sis96x.c 2008-05-15 11:00:12.000000000 -0400 | |
12255 | +++ linux-2.6.25.4/drivers/i2c/busses/i2c-sis96x.c 2008-05-18 13:33:15.000000000 -0400 | |
8a4b4a5e | 12256 | @@ -255,7 +255,7 @@ static struct i2c_adapter sis96x_adapter |
12257 | ||
12258 | static struct pci_device_id sis96x_ids[] = { | |
12259 | { PCI_DEVICE(PCI_VENDOR_ID_SI, PCI_DEVICE_ID_SI_SMBUS) }, | |
12260 | - { 0, } | |
da5b3fc8 | 12261 | + { 0, 0, 0, 0, 0, 0, 0 } |
50425a20 | 12262 | }; |
12263 | ||
8a4b4a5e | 12264 | MODULE_DEVICE_TABLE (pci, sis96x_ids); |
4dee9bd5 | 12265 | diff -urNp linux-2.6.25.4/drivers/ide/ide-cd.c linux-2.6.25.4/drivers/ide/ide-cd.c |
12266 | --- linux-2.6.25.4/drivers/ide/ide-cd.c 2008-05-15 11:00:12.000000000 -0400 | |
12267 | +++ linux-2.6.25.4/drivers/ide/ide-cd.c 2008-05-18 13:33:15.000000000 -0400 | |
12268 | @@ -182,8 +182,6 @@ void cdrom_analyze_sense_data(ide_drive_ | |
50425a20 | 12269 | sector &= ~(bio_sectors -1); |
12270 | valid = (sector - failed_command->sector) << 9; | |
12271 | ||
12272 | - if (valid < 0) | |
12273 | - valid = 0; | |
12274 | if (sector < get_capacity(info->disk) && | |
12275 | drive->probed_capacity - sector < 4 * 75) { | |
12276 | set_capacity(info->disk, sector); | |
4dee9bd5 | 12277 | diff -urNp linux-2.6.25.4/drivers/ieee1394/dv1394.c linux-2.6.25.4/drivers/ieee1394/dv1394.c |
12278 | --- linux-2.6.25.4/drivers/ieee1394/dv1394.c 2008-05-15 11:00:12.000000000 -0400 | |
12279 | +++ linux-2.6.25.4/drivers/ieee1394/dv1394.c 2008-05-18 13:33:15.000000000 -0400 | |
8a4b4a5e | 12280 | @@ -739,7 +739,7 @@ static void frame_prepare(struct video_c |
50425a20 | 12281 | based upon DIF section and sequence |
12282 | */ | |
12283 | ||
12284 | -static void inline | |
12285 | +static inline void | |
12286 | frame_put_packet (struct frame *f, struct packet *p) | |
12287 | { | |
12288 | int section_type = p->data[0] >> 5; /* section type is in bits 5 - 7 */ | |
8a4b4a5e | 12289 | @@ -918,7 +918,7 @@ static int do_dv1394_init(struct video_c |
50425a20 | 12290 | /* default SYT offset is 3 cycles */ |
12291 | init->syt_offset = 3; | |
12292 | ||
12293 | - if ( (init->channel > 63) || (init->channel < 0) ) | |
12294 | + if (init->channel > 63) | |
12295 | init->channel = 63; | |
12296 | ||
12297 | chan_mask = (u64)1 << init->channel; | |
8a4b4a5e | 12298 | @@ -2173,7 +2173,7 @@ static struct ieee1394_device_id dv1394_ |
50425a20 | 12299 | .specifier_id = AVC_UNIT_SPEC_ID_ENTRY & 0xffffff, |
12300 | .version = AVC_SW_VERSION_ENTRY & 0xffffff | |
12301 | }, | |
12302 | - { } | |
12303 | + { 0, 0, 0, 0, 0, 0 } | |
12304 | }; | |
12305 | ||
12306 | MODULE_DEVICE_TABLE(ieee1394, dv1394_id_table); | |
4dee9bd5 | 12307 | diff -urNp linux-2.6.25.4/drivers/ieee1394/eth1394.c linux-2.6.25.4/drivers/ieee1394/eth1394.c |
12308 | --- linux-2.6.25.4/drivers/ieee1394/eth1394.c 2008-05-15 11:00:12.000000000 -0400 | |
12309 | +++ linux-2.6.25.4/drivers/ieee1394/eth1394.c 2008-05-18 13:33:15.000000000 -0400 | |
da5b3fc8 | 12310 | @@ -451,7 +451,7 @@ static struct ieee1394_device_id eth1394 |
50425a20 | 12311 | .specifier_id = ETHER1394_GASP_SPECIFIER_ID, |
12312 | .version = ETHER1394_GASP_VERSION, | |
12313 | }, | |
12314 | - {} | |
12315 | + { 0, 0, 0, 0, 0, 0 } | |
12316 | }; | |
12317 | ||
12318 | MODULE_DEVICE_TABLE(ieee1394, eth1394_id_table); | |
4dee9bd5 | 12319 | diff -urNp linux-2.6.25.4/drivers/ieee1394/hosts.c linux-2.6.25.4/drivers/ieee1394/hosts.c |
12320 | --- linux-2.6.25.4/drivers/ieee1394/hosts.c 2008-05-15 11:00:12.000000000 -0400 | |
12321 | +++ linux-2.6.25.4/drivers/ieee1394/hosts.c 2008-05-18 13:33:15.000000000 -0400 | |
8a4b4a5e | 12322 | @@ -78,6 +78,7 @@ static int dummy_isoctl(struct hpsb_iso |
50425a20 | 12323 | } |
12324 | ||
12325 | static struct hpsb_host_driver dummy_driver = { | |
12326 | + .name = "dummy", | |
12327 | .transmit_packet = dummy_transmit_packet, | |
12328 | .devctl = dummy_devctl, | |
12329 | .isoctl = dummy_isoctl | |
4dee9bd5 | 12330 | diff -urNp linux-2.6.25.4/drivers/ieee1394/ohci1394.c linux-2.6.25.4/drivers/ieee1394/ohci1394.c |
12331 | --- linux-2.6.25.4/drivers/ieee1394/ohci1394.c 2008-05-15 11:00:12.000000000 -0400 | |
12332 | +++ linux-2.6.25.4/drivers/ieee1394/ohci1394.c 2008-05-18 13:33:15.000000000 -0400 | |
da5b3fc8 | 12333 | @@ -147,9 +147,9 @@ printk(level "%s: " fmt "\n" , OHCI1394_ |
50425a20 | 12334 | printk(level "%s: fw-host%d: " fmt "\n" , OHCI1394_DRIVER_NAME, ohci->host->id , ## args) |
12335 | ||
12336 | /* Module Parameters */ | |
12337 | -static int phys_dma = 1; | |
8a4b4a5e | 12338 | +static int phys_dma; |
50425a20 | 12339 | module_param(phys_dma, int, 0444); |
12340 | -MODULE_PARM_DESC(phys_dma, "Enable physical dma (default = 1)."); | |
12341 | +MODULE_PARM_DESC(phys_dma, "Enable physical dma (default = 0)."); | |
12342 | ||
12343 | static void dma_trm_tasklet(unsigned long data); | |
12344 | static void dma_trm_reset(struct dma_trm_ctx *d); | |
4dee9bd5 | 12345 | @@ -3400,7 +3400,7 @@ static struct pci_device_id ohci1394_pci |
50425a20 | 12346 | .subvendor = PCI_ANY_ID, |
12347 | .subdevice = PCI_ANY_ID, | |
12348 | }, | |
12349 | - { 0, }, | |
12350 | + { 0, 0, 0, 0, 0, 0, 0 }, | |
12351 | }; | |
12352 | ||
12353 | MODULE_DEVICE_TABLE(pci, ohci1394_pci_tbl); | |
4dee9bd5 | 12354 | diff -urNp linux-2.6.25.4/drivers/ieee1394/raw1394.c linux-2.6.25.4/drivers/ieee1394/raw1394.c |
12355 | --- linux-2.6.25.4/drivers/ieee1394/raw1394.c 2008-05-15 11:00:12.000000000 -0400 | |
12356 | +++ linux-2.6.25.4/drivers/ieee1394/raw1394.c 2008-05-18 13:33:15.000000000 -0400 | |
da5b3fc8 | 12357 | @@ -2952,7 +2952,7 @@ static struct ieee1394_device_id raw1394 |
50425a20 | 12358 | .match_flags = IEEE1394_MATCH_SPECIFIER_ID | IEEE1394_MATCH_VERSION, |
12359 | .specifier_id = CAMERA_UNIT_SPEC_ID_ENTRY & 0xffffff, | |
12360 | .version = (CAMERA_SW_VERSION_ENTRY + 2) & 0xffffff}, | |
12361 | - {} | |
12362 | + { 0, 0, 0, 0, 0, 0 } | |
12363 | }; | |
12364 | ||
12365 | MODULE_DEVICE_TABLE(ieee1394, raw1394_id_table); | |
4dee9bd5 | 12366 | diff -urNp linux-2.6.25.4/drivers/ieee1394/sbp2.c linux-2.6.25.4/drivers/ieee1394/sbp2.c |
12367 | --- linux-2.6.25.4/drivers/ieee1394/sbp2.c 2008-05-15 11:00:12.000000000 -0400 | |
12368 | +++ linux-2.6.25.4/drivers/ieee1394/sbp2.c 2008-05-18 13:33:15.000000000 -0400 | |
12369 | @@ -283,7 +283,7 @@ static struct ieee1394_device_id sbp2_id | |
50425a20 | 12370 | .match_flags = IEEE1394_MATCH_SPECIFIER_ID | IEEE1394_MATCH_VERSION, |
12371 | .specifier_id = SBP2_UNIT_SPEC_ID_ENTRY & 0xffffff, | |
12372 | .version = SBP2_SW_VERSION_ENTRY & 0xffffff}, | |
12373 | - {} | |
12374 | + { 0, 0, 0, 0, 0, 0 } | |
12375 | }; | |
12376 | MODULE_DEVICE_TABLE(ieee1394, sbp2_id_table); | |
12377 | ||
4dee9bd5 | 12378 | @@ -2108,7 +2108,7 @@ MODULE_DESCRIPTION("IEEE-1394 SBP-2 prot |
50425a20 | 12379 | MODULE_SUPPORTED_DEVICE(SBP2_DEVICE_NAME); |
12380 | MODULE_LICENSE("GPL"); | |
12381 | ||
12382 | -static int sbp2_module_init(void) | |
12383 | +static int __init sbp2_module_init(void) | |
12384 | { | |
12385 | int ret; | |
12386 | ||
4dee9bd5 | 12387 | diff -urNp linux-2.6.25.4/drivers/ieee1394/video1394.c linux-2.6.25.4/drivers/ieee1394/video1394.c |
12388 | --- linux-2.6.25.4/drivers/ieee1394/video1394.c 2008-05-15 11:00:12.000000000 -0400 | |
12389 | +++ linux-2.6.25.4/drivers/ieee1394/video1394.c 2008-05-18 13:33:15.000000000 -0400 | |
8a4b4a5e | 12390 | @@ -893,7 +893,7 @@ static long video1394_ioctl(struct file |
50425a20 | 12391 | if (unlikely(d == NULL)) |
12392 | return -EFAULT; | |
12393 | ||
12394 | - if (unlikely((v.buffer<0) || (v.buffer>=d->num_desc - 1))) { | |
12395 | + if (unlikely(v.buffer>=d->num_desc - 1)) { | |
12396 | PRINT(KERN_ERR, ohci->host->id, | |
12397 | "Buffer %d out of range",v.buffer); | |
12398 | return -EINVAL; | |
8a4b4a5e | 12399 | @@ -959,7 +959,7 @@ static long video1394_ioctl(struct file |
50425a20 | 12400 | if (unlikely(d == NULL)) |
12401 | return -EFAULT; | |
12402 | ||
12403 | - if (unlikely((v.buffer<0) || (v.buffer>d->num_desc - 1))) { | |
12404 | + if (unlikely(v.buffer>d->num_desc - 1)) { | |
12405 | PRINT(KERN_ERR, ohci->host->id, | |
12406 | "Buffer %d out of range",v.buffer); | |
12407 | return -EINVAL; | |
8a4b4a5e | 12408 | @@ -1030,7 +1030,7 @@ static long video1394_ioctl(struct file |
50425a20 | 12409 | d = find_ctx(&ctx->context_list, OHCI_ISO_TRANSMIT, v.channel); |
12410 | if (d == NULL) return -EFAULT; | |
12411 | ||
12412 | - if ((v.buffer<0) || (v.buffer>=d->num_desc - 1)) { | |
12413 | + if (v.buffer>=d->num_desc - 1) { | |
12414 | PRINT(KERN_ERR, ohci->host->id, | |
12415 | "Buffer %d out of range",v.buffer); | |
12416 | return -EINVAL; | |
8a4b4a5e | 12417 | @@ -1137,7 +1137,7 @@ static long video1394_ioctl(struct file |
50425a20 | 12418 | d = find_ctx(&ctx->context_list, OHCI_ISO_TRANSMIT, v.channel); |
12419 | if (d == NULL) return -EFAULT; | |
12420 | ||
12421 | - if ((v.buffer<0) || (v.buffer>=d->num_desc-1)) { | |
12422 | + if (v.buffer>=d->num_desc-1) { | |
12423 | PRINT(KERN_ERR, ohci->host->id, | |
12424 | "Buffer %d out of range",v.buffer); | |
12425 | return -EINVAL; | |
8a4b4a5e | 12426 | @@ -1309,7 +1309,7 @@ static struct ieee1394_device_id video13 |
50425a20 | 12427 | .specifier_id = CAMERA_UNIT_SPEC_ID_ENTRY & 0xffffff, |
12428 | .version = (CAMERA_SW_VERSION_ENTRY + 2) & 0xffffff | |
12429 | }, | |
12430 | - { } | |
12431 | + { 0, 0, 0, 0, 0, 0 } | |
12432 | }; | |
12433 | ||
12434 | MODULE_DEVICE_TABLE(ieee1394, video1394_id_table); | |
4dee9bd5 | 12435 | diff -urNp linux-2.6.25.4/drivers/input/keyboard/atkbd.c linux-2.6.25.4/drivers/input/keyboard/atkbd.c |
12436 | --- linux-2.6.25.4/drivers/input/keyboard/atkbd.c 2008-05-15 11:00:12.000000000 -0400 | |
12437 | +++ linux-2.6.25.4/drivers/input/keyboard/atkbd.c 2008-05-18 13:33:16.000000000 -0400 | |
12438 | @@ -1113,7 +1113,7 @@ static struct serio_device_id atkbd_seri | |
50425a20 | 12439 | .id = SERIO_ANY, |
12440 | .extra = SERIO_ANY, | |
12441 | }, | |
12442 | - { 0 } | |
12443 | + { 0, 0, 0, 0 } | |
12444 | }; | |
12445 | ||
12446 | MODULE_DEVICE_TABLE(serio, atkbd_serio_ids); | |
4dee9bd5 | 12447 | diff -urNp linux-2.6.25.4/drivers/input/mouse/lifebook.c linux-2.6.25.4/drivers/input/mouse/lifebook.c |
12448 | --- linux-2.6.25.4/drivers/input/mouse/lifebook.c 2008-05-15 11:00:12.000000000 -0400 | |
12449 | +++ linux-2.6.25.4/drivers/input/mouse/lifebook.c 2008-05-18 13:33:16.000000000 -0400 | |
da5b3fc8 | 12450 | @@ -110,7 +110,7 @@ static const struct dmi_system_id lifebo |
50425a20 | 12451 | DMI_MATCH(DMI_PRODUCT_NAME, "LifeBook B142"), |
12452 | }, | |
12453 | }, | |
12454 | - { } | |
12455 | + { NULL, NULL, {DMI_MATCH(DMI_NONE, NULL)}, NULL} | |
12456 | }; | |
12457 | ||
12458 | static psmouse_ret_t lifebook_process_byte(struct psmouse *psmouse) | |
4dee9bd5 | 12459 | diff -urNp linux-2.6.25.4/drivers/input/mouse/psmouse-base.c linux-2.6.25.4/drivers/input/mouse/psmouse-base.c |
12460 | --- linux-2.6.25.4/drivers/input/mouse/psmouse-base.c 2008-05-15 11:00:12.000000000 -0400 | |
12461 | +++ linux-2.6.25.4/drivers/input/mouse/psmouse-base.c 2008-05-18 13:33:16.000000000 -0400 | |
12462 | @@ -1328,7 +1328,7 @@ static struct serio_device_id psmouse_se | |
50425a20 | 12463 | .id = SERIO_ANY, |
12464 | .extra = SERIO_ANY, | |
12465 | }, | |
12466 | - { 0 } | |
12467 | + { 0, 0, 0, 0 } | |
12468 | }; | |
12469 | ||
12470 | MODULE_DEVICE_TABLE(serio, psmouse_serio_ids); | |
4dee9bd5 | 12471 | diff -urNp linux-2.6.25.4/drivers/input/mouse/synaptics.c linux-2.6.25.4/drivers/input/mouse/synaptics.c |
12472 | --- linux-2.6.25.4/drivers/input/mouse/synaptics.c 2008-05-15 11:00:12.000000000 -0400 | |
12473 | +++ linux-2.6.25.4/drivers/input/mouse/synaptics.c 2008-05-18 13:33:16.000000000 -0400 | |
8a4b4a5e | 12474 | @@ -417,7 +417,7 @@ static void synaptics_process_packet(str |
50425a20 | 12475 | break; |
12476 | case 2: | |
12477 | if (SYN_MODEL_PEN(priv->model_id)) | |
12478 | - ; /* Nothing, treat a pen as a single finger */ | |
12479 | + break; /* Nothing, treat a pen as a single finger */ | |
12480 | break; | |
12481 | case 4 ... 15: | |
12482 | if (SYN_CAP_PALMDETECT(priv->capabilities)) | |
da5b3fc8 | 12483 | @@ -624,7 +624,7 @@ static const struct dmi_system_id toshib |
50425a20 | 12484 | DMI_MATCH(DMI_PRODUCT_NAME, "PORTEGE M300"), |
12485 | }, | |
12486 | }, | |
12487 | - { } | |
12488 | + { NULL, NULL, {DMI_MATCH(DMI_NONE, NULL)}, NULL } | |
12489 | }; | |
12490 | #endif | |
12491 | ||
4dee9bd5 | 12492 | diff -urNp linux-2.6.25.4/drivers/input/mousedev.c linux-2.6.25.4/drivers/input/mousedev.c |
12493 | --- linux-2.6.25.4/drivers/input/mousedev.c 2008-05-15 11:00:12.000000000 -0400 | |
12494 | +++ linux-2.6.25.4/drivers/input/mousedev.c 2008-05-18 13:33:16.000000000 -0400 | |
da5b3fc8 | 12495 | @@ -1056,7 +1056,7 @@ static struct input_handler mousedev_han |
50425a20 | 12496 | |
12497 | #ifdef CONFIG_INPUT_MOUSEDEV_PSAUX | |
12498 | static struct miscdevice psaux_mouse = { | |
12499 | - PSMOUSE_MINOR, "psaux", &mousedev_fops | |
12500 | + PSMOUSE_MINOR, "psaux", &mousedev_fops, {NULL, NULL}, NULL, NULL | |
12501 | }; | |
12502 | static int psaux_registered; | |
12503 | #endif | |
4dee9bd5 | 12504 | diff -urNp linux-2.6.25.4/drivers/input/serio/i8042-x86ia64io.h linux-2.6.25.4/drivers/input/serio/i8042-x86ia64io.h |
12505 | --- linux-2.6.25.4/drivers/input/serio/i8042-x86ia64io.h 2008-05-15 11:00:12.000000000 -0400 | |
12506 | +++ linux-2.6.25.4/drivers/input/serio/i8042-x86ia64io.h 2008-05-18 13:33:16.000000000 -0400 | |
da5b3fc8 | 12507 | @@ -118,7 +118,7 @@ static struct dmi_system_id __initdata i |
12508 | DMI_MATCH(DMI_PRODUCT_VERSION, "VS2005R2"), | |
50425a20 | 12509 | }, |
12510 | }, | |
12511 | - { } | |
12512 | + { NULL, NULL, {DMI_MATCH(DMI_NONE, NULL)}, NULL } | |
12513 | }; | |
12514 | ||
12515 | /* | |
4dee9bd5 | 12516 | @@ -284,7 +284,7 @@ static struct dmi_system_id __initdata i |
12517 | DMI_MATCH(DMI_PRODUCT_VERSION, "3000 N100"), | |
50425a20 | 12518 | }, |
12519 | }, | |
12520 | - { } | |
12521 | + { NULL, NULL, {DMI_MATCH(DMI_NONE, NULL)}, NULL } | |
12522 | }; | |
12523 | ||
12524 | ||
4dee9bd5 | 12525 | diff -urNp linux-2.6.25.4/drivers/input/serio/serio_raw.c linux-2.6.25.4/drivers/input/serio/serio_raw.c |
12526 | --- linux-2.6.25.4/drivers/input/serio/serio_raw.c 2008-05-15 11:00:12.000000000 -0400 | |
12527 | +++ linux-2.6.25.4/drivers/input/serio/serio_raw.c 2008-05-18 13:33:16.000000000 -0400 | |
50425a20 | 12528 | @@ -369,7 +369,7 @@ static struct serio_device_id serio_raw_ |
12529 | .id = SERIO_ANY, | |
12530 | .extra = SERIO_ANY, | |
12531 | }, | |
12532 | - { 0 } | |
12533 | + { 0, 0, 0, 0 } | |
12534 | }; | |
12535 | ||
12536 | MODULE_DEVICE_TABLE(serio, serio_raw_serio_ids); | |
4dee9bd5 | 12537 | diff -urNp linux-2.6.25.4/drivers/md/bitmap.c linux-2.6.25.4/drivers/md/bitmap.c |
12538 | --- linux-2.6.25.4/drivers/md/bitmap.c 2008-05-15 11:00:12.000000000 -0400 | |
12539 | +++ linux-2.6.25.4/drivers/md/bitmap.c 2008-05-18 13:33:16.000000000 -0400 | |
50425a20 | 12540 | @@ -57,7 +57,7 @@ |
12541 | # if DEBUG > 0 | |
12542 | # define PRINTK(x...) printk(KERN_DEBUG x) | |
12543 | # else | |
12544 | -# define PRINTK(x...) | |
12545 | +# define PRINTK(x...) do {} while (0) | |
12546 | # endif | |
12547 | #endif | |
12548 | ||
4dee9bd5 | 12549 | diff -urNp linux-2.6.25.4/drivers/mtd/devices/doc2000.c linux-2.6.25.4/drivers/mtd/devices/doc2000.c |
12550 | --- linux-2.6.25.4/drivers/mtd/devices/doc2000.c 2008-05-15 11:00:12.000000000 -0400 | |
12551 | +++ linux-2.6.25.4/drivers/mtd/devices/doc2000.c 2008-05-18 13:33:16.000000000 -0400 | |
12552 | @@ -779,7 +779,7 @@ static int doc_write(struct mtd_info *mt | |
da5b3fc8 | 12553 | |
4dee9bd5 | 12554 | /* The ECC will not be calculated correctly if less than 512 is written */ |
12555 | /* DBB- | |
da5b3fc8 | 12556 | - if (len != 0x200 && eccbuf) |
12557 | + if (len != 0x200) | |
12558 | printk(KERN_WARNING | |
4dee9bd5 | 12559 | "ECC needs a full sector write (adr: %lx size %lx)\n", |
12560 | (long) to, (long) len); | |
12561 | diff -urNp linux-2.6.25.4/drivers/mtd/devices/doc2001.c linux-2.6.25.4/drivers/mtd/devices/doc2001.c | |
12562 | --- linux-2.6.25.4/drivers/mtd/devices/doc2001.c 2008-05-15 11:00:12.000000000 -0400 | |
12563 | +++ linux-2.6.25.4/drivers/mtd/devices/doc2001.c 2008-05-18 13:33:16.000000000 -0400 | |
8a4b4a5e | 12564 | @@ -398,6 +398,8 @@ static int doc_read (struct mtd_info *mt |
50425a20 | 12565 | /* Don't allow read past end of device */ |
12566 | if (from >= this->totlen) | |
12567 | return -EINVAL; | |
12568 | + if (!len) | |
12569 | + return -EINVAL; | |
12570 | ||
12571 | /* Don't allow a single read to cross a 512-byte block boundary */ | |
12572 | if (from + len > ((from | 0x1ff) + 1)) | |
4dee9bd5 | 12573 | diff -urNp linux-2.6.25.4/drivers/mtd/devices/slram.c linux-2.6.25.4/drivers/mtd/devices/slram.c |
12574 | --- linux-2.6.25.4/drivers/mtd/devices/slram.c 2008-05-15 11:00:12.000000000 -0400 | |
12575 | +++ linux-2.6.25.4/drivers/mtd/devices/slram.c 2008-05-18 13:33:16.000000000 -0400 | |
da5b3fc8 | 12576 | @@ -270,7 +270,7 @@ static int parse_cmdline(char *devname, |
12577 | } | |
12578 | T("slram: devname=%s, devstart=0x%lx, devlength=0x%lx\n", | |
12579 | devname, devstart, devlength); | |
12580 | - if ((devstart < 0) || (devlength < 0) || (devlength % SLRAM_BLK_SZ != 0)) { | |
12581 | + if (devlength % SLRAM_BLK_SZ != 0) { | |
12582 | E("slram: Illegal start / length parameter.\n"); | |
12583 | return(-EINVAL); | |
12584 | } | |
4dee9bd5 | 12585 | diff -urNp linux-2.6.25.4/drivers/mtd/ubi/build.c linux-2.6.25.4/drivers/mtd/ubi/build.c |
12586 | --- linux-2.6.25.4/drivers/mtd/ubi/build.c 2008-05-15 11:00:12.000000000 -0400 | |
12587 | +++ linux-2.6.25.4/drivers/mtd/ubi/build.c 2008-05-18 13:33:16.000000000 -0400 | |
12588 | @@ -1059,7 +1059,7 @@ static int __init bytes_str_to_int(const | |
da5b3fc8 | 12589 | unsigned long result; |
12590 | ||
12591 | result = simple_strtoul(str, &endp, 0); | |
12592 | - if (str == endp || result < 0) { | |
12593 | + if (str == endp) { | |
4dee9bd5 | 12594 | printk(KERN_ERR "UBI error: incorrect bytes count: \"%s\"\n", |
12595 | str); | |
da5b3fc8 | 12596 | return -EINVAL; |
4dee9bd5 | 12597 | diff -urNp linux-2.6.25.4/drivers/net/eepro100.c linux-2.6.25.4/drivers/net/eepro100.c |
12598 | --- linux-2.6.25.4/drivers/net/eepro100.c 2008-05-15 11:00:12.000000000 -0400 | |
12599 | +++ linux-2.6.25.4/drivers/net/eepro100.c 2008-05-18 13:33:16.000000000 -0400 | |
50425a20 | 12600 | @@ -47,7 +47,7 @@ static int rxdmacount /* = 0 */; |
12601 | # define rx_align(skb) skb_reserve((skb), 2) | |
12602 | # define RxFD_ALIGNMENT __attribute__ ((aligned (2), packed)) | |
12603 | #else | |
12604 | -# define rx_align(skb) | |
12605 | +# define rx_align(skb) do {} while (0) | |
12606 | # define RxFD_ALIGNMENT | |
12607 | #endif | |
12608 | ||
4dee9bd5 | 12609 | @@ -2334,33 +2334,33 @@ static void __devexit eepro100_remove_on |
50425a20 | 12610 | } |
12611 | ||
12612 | static struct pci_device_id eepro100_pci_tbl[] = { | |
12613 | - { PCI_VENDOR_ID_INTEL, 0x1229, PCI_ANY_ID, PCI_ANY_ID, }, | |
12614 | - { PCI_VENDOR_ID_INTEL, 0x1209, PCI_ANY_ID, PCI_ANY_ID, }, | |
12615 | - { PCI_VENDOR_ID_INTEL, 0x1029, PCI_ANY_ID, PCI_ANY_ID, }, | |
12616 | - { PCI_VENDOR_ID_INTEL, 0x1030, PCI_ANY_ID, PCI_ANY_ID, }, | |
12617 | - { PCI_VENDOR_ID_INTEL, 0x1031, PCI_ANY_ID, PCI_ANY_ID, }, | |
12618 | - { PCI_VENDOR_ID_INTEL, 0x1032, PCI_ANY_ID, PCI_ANY_ID, }, | |
12619 | - { PCI_VENDOR_ID_INTEL, 0x1033, PCI_ANY_ID, PCI_ANY_ID, }, | |
12620 | - { PCI_VENDOR_ID_INTEL, 0x1034, PCI_ANY_ID, PCI_ANY_ID, }, | |
12621 | - { PCI_VENDOR_ID_INTEL, 0x1035, PCI_ANY_ID, PCI_ANY_ID, }, | |
12622 | - { PCI_VENDOR_ID_INTEL, 0x1036, PCI_ANY_ID, PCI_ANY_ID, }, | |
12623 | - { PCI_VENDOR_ID_INTEL, 0x1037, PCI_ANY_ID, PCI_ANY_ID, }, | |
12624 | - { PCI_VENDOR_ID_INTEL, 0x1038, PCI_ANY_ID, PCI_ANY_ID, }, | |
12625 | - { PCI_VENDOR_ID_INTEL, 0x1039, PCI_ANY_ID, PCI_ANY_ID, }, | |
12626 | - { PCI_VENDOR_ID_INTEL, 0x103A, PCI_ANY_ID, PCI_ANY_ID, }, | |
12627 | - { PCI_VENDOR_ID_INTEL, 0x103B, PCI_ANY_ID, PCI_ANY_ID, }, | |
12628 | - { PCI_VENDOR_ID_INTEL, 0x103C, PCI_ANY_ID, PCI_ANY_ID, }, | |
12629 | - { PCI_VENDOR_ID_INTEL, 0x103D, PCI_ANY_ID, PCI_ANY_ID, }, | |
12630 | - { PCI_VENDOR_ID_INTEL, 0x103E, PCI_ANY_ID, PCI_ANY_ID, }, | |
12631 | - { PCI_VENDOR_ID_INTEL, 0x1050, PCI_ANY_ID, PCI_ANY_ID, }, | |
12632 | - { PCI_VENDOR_ID_INTEL, 0x1059, PCI_ANY_ID, PCI_ANY_ID, }, | |
12633 | - { PCI_VENDOR_ID_INTEL, 0x1227, PCI_ANY_ID, PCI_ANY_ID, }, | |
12634 | - { PCI_VENDOR_ID_INTEL, 0x2449, PCI_ANY_ID, PCI_ANY_ID, }, | |
12635 | - { PCI_VENDOR_ID_INTEL, 0x2459, PCI_ANY_ID, PCI_ANY_ID, }, | |
12636 | - { PCI_VENDOR_ID_INTEL, 0x245D, PCI_ANY_ID, PCI_ANY_ID, }, | |
12637 | - { PCI_VENDOR_ID_INTEL, 0x5200, PCI_ANY_ID, PCI_ANY_ID, }, | |
12638 | - { PCI_VENDOR_ID_INTEL, 0x5201, PCI_ANY_ID, PCI_ANY_ID, }, | |
12639 | - { 0,} | |
12640 | + { PCI_VENDOR_ID_INTEL, 0x1229, PCI_ANY_ID, PCI_ANY_ID, 0, 0, 0 }, | |
12641 | + { PCI_VENDOR_ID_INTEL, 0x1209, PCI_ANY_ID, PCI_ANY_ID, 0, 0, 0 }, | |
12642 | + { PCI_VENDOR_ID_INTEL, 0x1029, PCI_ANY_ID, PCI_ANY_ID, 0, 0, 0 }, | |
12643 | + { PCI_VENDOR_ID_INTEL, 0x1030, PCI_ANY_ID, PCI_ANY_ID, 0, 0, 0 }, | |
12644 | + { PCI_VENDOR_ID_INTEL, 0x1031, PCI_ANY_ID, PCI_ANY_ID, 0, 0, 0 }, | |
12645 | + { PCI_VENDOR_ID_INTEL, 0x1032, PCI_ANY_ID, PCI_ANY_ID, 0, 0, 0 }, | |
12646 | + { PCI_VENDOR_ID_INTEL, 0x1033, PCI_ANY_ID, PCI_ANY_ID, 0, 0, 0 }, | |
12647 | + { PCI_VENDOR_ID_INTEL, 0x1034, PCI_ANY_ID, PCI_ANY_ID, 0, 0, 0 }, | |
12648 | + { PCI_VENDOR_ID_INTEL, 0x1035, PCI_ANY_ID, PCI_ANY_ID, 0, 0, 0 }, | |
12649 | + { PCI_VENDOR_ID_INTEL, 0x1036, PCI_ANY_ID, PCI_ANY_ID, 0, 0, 0 }, | |
12650 | + { PCI_VENDOR_ID_INTEL, 0x1037, PCI_ANY_ID, PCI_ANY_ID, 0, 0, 0 }, | |
12651 | + { PCI_VENDOR_ID_INTEL, 0x1038, PCI_ANY_ID, PCI_ANY_ID, 0, 0, 0 }, | |
12652 | + { PCI_VENDOR_ID_INTEL, 0x1039, PCI_ANY_ID, PCI_ANY_ID, 0, 0, 0 }, | |
12653 | + { PCI_VENDOR_ID_INTEL, 0x103A, PCI_ANY_ID, PCI_ANY_ID, 0, 0, 0 }, | |
12654 | + { PCI_VENDOR_ID_INTEL, 0x103B, PCI_ANY_ID, PCI_ANY_ID, 0, 0, 0 }, | |
12655 | + { PCI_VENDOR_ID_INTEL, 0x103C, PCI_ANY_ID, PCI_ANY_ID, 0, 0, 0 }, | |
12656 | + { PCI_VENDOR_ID_INTEL, 0x103D, PCI_ANY_ID, PCI_ANY_ID, 0, 0, 0 }, | |
12657 | + { PCI_VENDOR_ID_INTEL, 0x103E, PCI_ANY_ID, PCI_ANY_ID, 0, 0, 0 }, | |
12658 | + { PCI_VENDOR_ID_INTEL, 0x1050, PCI_ANY_ID, PCI_ANY_ID, 0, 0, 0 }, | |
12659 | + { PCI_VENDOR_ID_INTEL, 0x1059, PCI_ANY_ID, PCI_ANY_ID, 0, 0, 0 }, | |
12660 | + { PCI_VENDOR_ID_INTEL, 0x1227, PCI_ANY_ID, PCI_ANY_ID, 0, 0, 0 }, | |
12661 | + { PCI_VENDOR_ID_INTEL, 0x2449, PCI_ANY_ID, PCI_ANY_ID, 0, 0, 0 }, | |
12662 | + { PCI_VENDOR_ID_INTEL, 0x2459, PCI_ANY_ID, PCI_ANY_ID, 0, 0, 0 }, | |
12663 | + { PCI_VENDOR_ID_INTEL, 0x245D, PCI_ANY_ID, PCI_ANY_ID, 0, 0, 0 }, | |
12664 | + { PCI_VENDOR_ID_INTEL, 0x5200, PCI_ANY_ID, PCI_ANY_ID, 0, 0, 0 }, | |
12665 | + { PCI_VENDOR_ID_INTEL, 0x5201, PCI_ANY_ID, PCI_ANY_ID, 0, 0, 0 }, | |
12666 | + { 0, 0, 0, 0, 0, 0, 0 } | |
12667 | }; | |
12668 | MODULE_DEVICE_TABLE(pci, eepro100_pci_tbl); | |
12669 | ||
4dee9bd5 | 12670 | diff -urNp linux-2.6.25.4/drivers/net/irda/vlsi_ir.c linux-2.6.25.4/drivers/net/irda/vlsi_ir.c |
12671 | --- linux-2.6.25.4/drivers/net/irda/vlsi_ir.c 2008-05-15 11:00:12.000000000 -0400 | |
12672 | +++ linux-2.6.25.4/drivers/net/irda/vlsi_ir.c 2008-05-18 13:33:16.000000000 -0400 | |
da5b3fc8 | 12673 | @@ -906,13 +906,12 @@ static int vlsi_hard_start_xmit(struct s |
12674 | /* no race - tx-ring already empty */ | |
12675 | vlsi_set_baud(idev, iobase); | |
12676 | netif_wake_queue(ndev); | |
12677 | - } | |
12678 | - else | |
12679 | - ; | |
12680 | + } else { | |
12681 | /* keep the speed change pending like it would | |
12682 | * for any len>0 packet. tx completion interrupt | |
12683 | * will apply it when the tx ring becomes empty. | |
12684 | */ | |
12685 | + } | |
12686 | spin_unlock_irqrestore(&idev->lock, flags); | |
12687 | dev_kfree_skb_any(skb); | |
12688 | return 0; | |
4dee9bd5 | 12689 | diff -urNp linux-2.6.25.4/drivers/net/pcnet32.c linux-2.6.25.4/drivers/net/pcnet32.c |
12690 | --- linux-2.6.25.4/drivers/net/pcnet32.c 2008-05-15 11:00:12.000000000 -0400 | |
12691 | +++ linux-2.6.25.4/drivers/net/pcnet32.c 2008-05-18 13:33:16.000000000 -0400 | |
50425a20 | 12692 | @@ -82,7 +82,7 @@ static int cards_found; |
12693 | /* | |
12694 | * VLB I/O addresses | |
12695 | */ | |
12696 | -static unsigned int pcnet32_portlist[] __initdata = | |
12697 | +static unsigned int pcnet32_portlist[] __devinitdata = | |
12698 | { 0x300, 0x320, 0x340, 0x360, 0 }; | |
12699 | ||
12700 | static int pcnet32_debug = 0; | |
4dee9bd5 | 12701 | diff -urNp linux-2.6.25.4/drivers/net/tg3.h linux-2.6.25.4/drivers/net/tg3.h |
12702 | --- linux-2.6.25.4/drivers/net/tg3.h 2008-05-15 11:00:12.000000000 -0400 | |
12703 | +++ linux-2.6.25.4/drivers/net/tg3.h 2008-05-18 13:33:16.000000000 -0400 | |
da5b3fc8 | 12704 | @@ -102,6 +102,7 @@ |
50425a20 | 12705 | #define CHIPREV_ID_5750_A0 0x4000 |
12706 | #define CHIPREV_ID_5750_A1 0x4001 | |
12707 | #define CHIPREV_ID_5750_A3 0x4003 | |
12708 | +#define CHIPREV_ID_5750_C1 0x4201 | |
12709 | #define CHIPREV_ID_5750_C2 0x4202 | |
12710 | #define CHIPREV_ID_5752_A0_HW 0x5000 | |
12711 | #define CHIPREV_ID_5752_A0 0x6000 | |
4dee9bd5 | 12712 | diff -urNp linux-2.6.25.4/drivers/pci/hotplug/cpqphp_nvram.c linux-2.6.25.4/drivers/pci/hotplug/cpqphp_nvram.c |
12713 | --- linux-2.6.25.4/drivers/pci/hotplug/cpqphp_nvram.c 2008-05-15 11:00:12.000000000 -0400 | |
12714 | +++ linux-2.6.25.4/drivers/pci/hotplug/cpqphp_nvram.c 2008-05-18 13:33:16.000000000 -0400 | |
83a957c9 | 12715 | @@ -425,9 +425,13 @@ static u32 store_HRT (void __iomem *rom_ |
12716 | ||
12717 | void compaq_nvram_init (void __iomem *rom_start) | |
12718 | { | |
12719 | + | |
12720 | +#ifndef CONFIG_PAX_KERNEXEC | |
12721 | if (rom_start) { | |
12722 | compaq_int15_entry_point = (rom_start + ROM_INT15_PHY_ADDR - ROM_PHY_ADDR); | |
12723 | } | |
12724 | +#endif | |
12725 | + | |
12726 | dbg("int15 entry = %p\n", compaq_int15_entry_point); | |
12727 | ||
12728 | /* initialize our int15 lock */ | |
4dee9bd5 | 12729 | diff -urNp linux-2.6.25.4/drivers/pci/pcie/aer/aerdrv.c linux-2.6.25.4/drivers/pci/pcie/aer/aerdrv.c |
12730 | --- linux-2.6.25.4/drivers/pci/pcie/aer/aerdrv.c 2008-05-15 11:00:12.000000000 -0400 | |
12731 | +++ linux-2.6.25.4/drivers/pci/pcie/aer/aerdrv.c 2008-05-18 13:33:16.000000000 -0400 | |
50425a20 | 12732 | @@ -58,7 +58,7 @@ static struct pcie_port_service_id aer_i |
12733 | .port_type = PCIE_RC_PORT, | |
12734 | .service_type = PCIE_PORT_SERVICE_AER, | |
12735 | }, | |
12736 | - { /* end: all zeroes */ } | |
12737 | + { 0, 0, 0, 0, 0, 0, 0, 0, 0 } | |
12738 | }; | |
12739 | ||
12740 | static struct pci_error_handlers aer_error_handlers = { | |
4dee9bd5 | 12741 | diff -urNp linux-2.6.25.4/drivers/pci/pcie/aer/aerdrv_core.c linux-2.6.25.4/drivers/pci/pcie/aer/aerdrv_core.c |
12742 | --- linux-2.6.25.4/drivers/pci/pcie/aer/aerdrv_core.c 2008-05-15 11:00:12.000000000 -0400 | |
12743 | +++ linux-2.6.25.4/drivers/pci/pcie/aer/aerdrv_core.c 2008-05-18 13:33:16.000000000 -0400 | |
da5b3fc8 | 12744 | @@ -661,7 +661,7 @@ static void aer_isr_one_error(struct pci |
50425a20 | 12745 | struct aer_err_source *e_src) |
12746 | { | |
12747 | struct device *s_device; | |
12748 | - struct aer_err_info e_info = {0, 0, 0,}; | |
12749 | + struct aer_err_info e_info = {0, 0, 0, {0, 0, 0, 0}}; | |
12750 | int i; | |
12751 | u16 id; | |
12752 | ||
4dee9bd5 | 12753 | diff -urNp linux-2.6.25.4/drivers/pci/pcie/portdrv_pci.c linux-2.6.25.4/drivers/pci/pcie/portdrv_pci.c |
12754 | --- linux-2.6.25.4/drivers/pci/pcie/portdrv_pci.c 2008-05-15 11:00:12.000000000 -0400 | |
12755 | +++ linux-2.6.25.4/drivers/pci/pcie/portdrv_pci.c 2008-05-18 13:33:16.000000000 -0400 | |
50425a20 | 12756 | @@ -265,7 +265,7 @@ static void pcie_portdrv_err_resume(stru |
12757 | static const struct pci_device_id port_pci_ids[] = { { | |
12758 | /* handle any PCI-Express port */ | |
12759 | PCI_DEVICE_CLASS(((PCI_CLASS_BRIDGE_PCI << 8) | 0x00), ~0), | |
12760 | - }, { /* end: all zeroes */ } | |
12761 | + }, { 0, 0, 0, 0, 0, 0, 0 } | |
12762 | }; | |
12763 | MODULE_DEVICE_TABLE(pci, port_pci_ids); | |
12764 | ||
4dee9bd5 | 12765 | diff -urNp linux-2.6.25.4/drivers/pci/proc.c linux-2.6.25.4/drivers/pci/proc.c |
12766 | --- linux-2.6.25.4/drivers/pci/proc.c 2008-05-15 11:00:12.000000000 -0400 | |
12767 | +++ linux-2.6.25.4/drivers/pci/proc.c 2008-05-18 13:33:16.000000000 -0400 | |
12768 | @@ -472,7 +472,15 @@ static int __init pci_proc_init(void) | |
50425a20 | 12769 | { |
12770 | struct proc_dir_entry *entry; | |
12771 | struct pci_dev *dev = NULL; | |
12772 | +#ifdef CONFIG_GRKERNSEC_PROC_ADD | |
12773 | +#ifdef CONFIG_GRKERNSEC_PROC_USER | |
12774 | + proc_bus_pci_dir = proc_mkdir_mode("pci", S_IRUSR | S_IXUSR, proc_bus); | |
b2ee8b1e | 12775 | +#elif defined(CONFIG_GRKERNSEC_PROC_USERGROUP) |
50425a20 | 12776 | + proc_bus_pci_dir = proc_mkdir_mode("pci", S_IRUSR | S_IXUSR | S_IRGRP | S_IXGRP, proc_bus); |
12777 | +#endif | |
12778 | +#else | |
12779 | proc_bus_pci_dir = proc_mkdir("pci", proc_bus); | |
12780 | +#endif | |
12781 | entry = create_proc_entry("devices", 0, proc_bus_pci_dir); | |
12782 | if (entry) | |
12783 | entry->proc_fops = &proc_bus_pci_dev_operations; | |
4dee9bd5 | 12784 | diff -urNp linux-2.6.25.4/drivers/pcmcia/ti113x.h linux-2.6.25.4/drivers/pcmcia/ti113x.h |
12785 | --- linux-2.6.25.4/drivers/pcmcia/ti113x.h 2008-05-15 11:00:12.000000000 -0400 | |
12786 | +++ linux-2.6.25.4/drivers/pcmcia/ti113x.h 2008-05-18 13:33:16.000000000 -0400 | |
50425a20 | 12787 | @@ -897,7 +897,7 @@ static struct pci_device_id ene_tune_tbl |
12788 | DEVID(PCI_VENDOR_ID_MOTOROLA, 0x3410, 0xECC0, PCI_ANY_ID, | |
12789 | ENE_TEST_C9_TLTENABLE | ENE_TEST_C9_PFENABLE, ENE_TEST_C9_TLTENABLE), | |
12790 | ||
12791 | - {} | |
12792 | + { 0, 0, 0, 0, 0, 0, 0 } | |
12793 | }; | |
12794 | ||
12795 | static void ene_tune_bridge(struct pcmcia_socket *sock, struct pci_bus *bus) | |
4dee9bd5 | 12796 | diff -urNp linux-2.6.25.4/drivers/pcmcia/yenta_socket.c linux-2.6.25.4/drivers/pcmcia/yenta_socket.c |
12797 | --- linux-2.6.25.4/drivers/pcmcia/yenta_socket.c 2008-05-15 11:00:12.000000000 -0400 | |
12798 | +++ linux-2.6.25.4/drivers/pcmcia/yenta_socket.c 2008-05-18 13:33:16.000000000 -0400 | |
50425a20 | 12799 | @@ -1358,7 +1358,7 @@ static struct pci_device_id yenta_table |
12800 | ||
12801 | /* match any cardbus bridge */ | |
12802 | CB_ID(PCI_ANY_ID, PCI_ANY_ID, DEFAULT), | |
12803 | - { /* all zeroes */ } | |
12804 | + { 0, 0, 0, 0, 0, 0, 0 } | |
12805 | }; | |
12806 | MODULE_DEVICE_TABLE(pci, yenta_table); | |
12807 | ||
4dee9bd5 | 12808 | diff -urNp linux-2.6.25.4/drivers/pnp/pnpbios/bioscalls.c linux-2.6.25.4/drivers/pnp/pnpbios/bioscalls.c |
12809 | --- linux-2.6.25.4/drivers/pnp/pnpbios/bioscalls.c 2008-05-15 11:00:12.000000000 -0400 | |
12810 | +++ linux-2.6.25.4/drivers/pnp/pnpbios/bioscalls.c 2008-05-18 13:33:16.000000000 -0400 | |
da5b3fc8 | 12811 | @@ -61,7 +61,7 @@ set_base(gdt[(selname) >> 3], (u32)(addr |
50425a20 | 12812 | set_limit(gdt[(selname) >> 3], size); \ |
12813 | } while(0) | |
12814 | ||
4dee9bd5 | 12815 | -static struct desc_struct bad_bios_desc; |
12816 | +static struct desc_struct bad_bios_desc __read_only; | |
50425a20 | 12817 | |
12818 | /* | |
12819 | * At some point we want to use this stack frame pointer to unwind | |
da5b3fc8 | 12820 | @@ -88,6 +88,10 @@ static inline u16 call_pnp_bios(u16 func |
50425a20 | 12821 | struct desc_struct save_desc_40; |
12822 | int cpu; | |
12823 | ||
12824 | +#ifdef CONFIG_PAX_KERNEXEC | |
12825 | + unsigned long cr0; | |
12826 | +#endif | |
12827 | + | |
12828 | /* | |
12829 | * PnP BIOSes are generally not terribly re-entrant. | |
12830 | * Also, don't rely on them to save everything correctly. | |
da5b3fc8 | 12831 | @@ -97,8 +101,17 @@ static inline u16 call_pnp_bios(u16 func |
12832 | ||
12833 | cpu = get_cpu(); | |
12834 | save_desc_40 = get_cpu_gdt_table(cpu)[0x40 / 8]; | |
12835 | + | |
12836 | +#ifdef CONFIG_PAX_KERNEXEC | |
12837 | + pax_open_kernel(cr0); | |
12838 | +#endif | |
12839 | + | |
12840 | get_cpu_gdt_table(cpu)[0x40 / 8] = bad_bios_desc; | |
12841 | ||
12842 | +#ifdef CONFIG_PAX_KERNEXEC | |
12843 | + pax_close_kernel(cr0); | |
12844 | +#endif | |
12845 | + | |
50425a20 | 12846 | /* On some boxes IRQ's during PnP BIOS calls are deadly. */ |
12847 | spin_lock_irqsave(&pnp_bios_lock, flags); | |
12848 | ||
da5b3fc8 | 12849 | @@ -135,7 +148,16 @@ static inline u16 call_pnp_bios(u16 func |
12850 | :"memory"); | |
12851 | spin_unlock_irqrestore(&pnp_bios_lock, flags); | |
12852 | ||
50425a20 | 12853 | +#ifdef CONFIG_PAX_KERNEXEC |
12854 | + pax_open_kernel(cr0); | |
12855 | +#endif | |
12856 | + | |
50425a20 | 12857 | get_cpu_gdt_table(cpu)[0x40 / 8] = save_desc_40; |
12858 | + | |
12859 | +#ifdef CONFIG_PAX_KERNEXEC | |
12860 | + pax_close_kernel(cr0); | |
12861 | +#endif | |
12862 | + | |
50425a20 | 12863 | put_cpu(); |
12864 | ||
12865 | /* If we get here and this is set then the PnP BIOS faulted on us. */ | |
4dee9bd5 | 12866 | @@ -469,16 +491,24 @@ int pnp_bios_read_escd(char *data, u32 n |
da5b3fc8 | 12867 | return status; |
12868 | } | |
8a4b4a5e | 12869 | |
12870 | -void pnpbios_calls_init(union pnp_bios_install_struct *header) | |
12871 | +void __init pnpbios_calls_init(union pnp_bios_install_struct *header) | |
12872 | { | |
12873 | int i; | |
da5b3fc8 | 12874 | |
8a4b4a5e | 12875 | +#ifdef CONFIG_PAX_KERNEXEC |
12876 | + unsigned long cr0; | |
12877 | +#endif | |
12878 | + | |
12879 | spin_lock_init(&pnp_bios_lock); | |
12880 | pnp_bios_callpoint.offset = header->fields.pm16offset; | |
12881 | pnp_bios_callpoint.segment = PNP_CS16; | |
12882 | ||
8a4b4a5e | 12883 | +#ifdef CONFIG_PAX_KERNEXEC |
12884 | + pax_open_kernel(cr0); | |
12885 | +#endif | |
12886 | + | |
4dee9bd5 | 12887 | bad_bios_desc.a = 0; |
12888 | - bad_bios_desc.b = 0x00409200; | |
12889 | + bad_bios_desc.b = 0x00409300; | |
12890 | ||
b7f09679 | 12891 | set_base(bad_bios_desc, __va((unsigned long)0x40 << 4)); |
12892 | _set_limit((char *)&bad_bios_desc, 4095 - (0x40 << 4)); | |
4dee9bd5 | 12893 | @@ -492,4 +522,9 @@ void pnpbios_calls_init(union pnp_bios_i |
da5b3fc8 | 12894 | set_base(gdt[GDT_ENTRY_PNPBIOS_DS], |
12895 | __va(header->fields.pm16dseg)); | |
12896 | } | |
8a4b4a5e | 12897 | + |
12898 | +#ifdef CONFIG_PAX_KERNEXEC | |
12899 | + pax_close_kernel(cr0); | |
12900 | +#endif | |
12901 | + | |
12902 | } | |
4dee9bd5 | 12903 | diff -urNp linux-2.6.25.4/drivers/pnp/quirks.c linux-2.6.25.4/drivers/pnp/quirks.c |
12904 | --- linux-2.6.25.4/drivers/pnp/quirks.c 2008-05-15 11:00:12.000000000 -0400 | |
12905 | +++ linux-2.6.25.4/drivers/pnp/quirks.c 2008-05-18 13:33:16.000000000 -0400 | |
12906 | @@ -201,7 +201,7 @@ static struct pnp_fixup pnp_fixups[] = { | |
da5b3fc8 | 12907 | {"CTL0045", quirk_sb16audio_resources}, |
4dee9bd5 | 12908 | {"PNP0c01", quirk_system_pci_resources}, |
12909 | {"PNP0c02", quirk_system_pci_resources}, | |
da5b3fc8 | 12910 | - {""} |
12911 | + {"", NULL} | |
50425a20 | 12912 | }; |
12913 | ||
12914 | void pnp_fixup_device(struct pnp_dev *dev) | |
4dee9bd5 | 12915 | diff -urNp linux-2.6.25.4/drivers/pnp/resource.c linux-2.6.25.4/drivers/pnp/resource.c |
12916 | --- linux-2.6.25.4/drivers/pnp/resource.c 2008-05-15 11:00:12.000000000 -0400 | |
12917 | +++ linux-2.6.25.4/drivers/pnp/resource.c 2008-05-18 13:33:16.000000000 -0400 | |
da5b3fc8 | 12918 | @@ -345,7 +345,7 @@ int pnp_check_irq(struct pnp_dev *dev, i |
50425a20 | 12919 | return 1; |
12920 | ||
12921 | /* check if the resource is valid */ | |
12922 | - if (*irq < 0 || *irq > 15) | |
12923 | + if (*irq > 15) | |
12924 | return 0; | |
12925 | ||
12926 | /* check if the resource is reserved */ | |
da5b3fc8 | 12927 | @@ -414,7 +414,7 @@ int pnp_check_dma(struct pnp_dev *dev, i |
50425a20 | 12928 | return 1; |
12929 | ||
12930 | /* check if the resource is valid */ | |
12931 | - if (*dma < 0 || *dma == 4 || *dma > 7) | |
12932 | + if (*dma == 4 || *dma > 7) | |
12933 | return 0; | |
12934 | ||
12935 | /* check if the resource is reserved */ | |
4dee9bd5 | 12936 | diff -urNp linux-2.6.25.4/drivers/scsi/scsi_logging.h linux-2.6.25.4/drivers/scsi/scsi_logging.h |
12937 | --- linux-2.6.25.4/drivers/scsi/scsi_logging.h 2008-05-15 11:00:12.000000000 -0400 | |
12938 | +++ linux-2.6.25.4/drivers/scsi/scsi_logging.h 2008-05-18 13:33:16.000000000 -0400 | |
50425a20 | 12939 | @@ -51,7 +51,7 @@ do { \ |
12940 | } while (0); \ | |
12941 | } while (0) | |
12942 | #else | |
12943 | -#define SCSI_CHECK_LOGGING(SHIFT, BITS, LEVEL, CMD) | |
12944 | +#define SCSI_CHECK_LOGGING(SHIFT, BITS, LEVEL, CMD) do {} while (0) | |
12945 | #endif /* CONFIG_SCSI_LOGGING */ | |
12946 | ||
12947 | /* | |
4dee9bd5 | 12948 | diff -urNp linux-2.6.25.4/drivers/serial/8250_pci.c linux-2.6.25.4/drivers/serial/8250_pci.c |
12949 | --- linux-2.6.25.4/drivers/serial/8250_pci.c 2008-05-15 11:00:12.000000000 -0400 | |
12950 | +++ linux-2.6.25.4/drivers/serial/8250_pci.c 2008-05-18 13:33:16.000000000 -0400 | |
12951 | @@ -2837,7 +2837,7 @@ static struct pci_device_id serial_pci_t | |
50425a20 | 12952 | PCI_ANY_ID, PCI_ANY_ID, |
12953 | PCI_CLASS_COMMUNICATION_MULTISERIAL << 8, | |
12954 | 0xffff00, pbn_default }, | |
12955 | - { 0, } | |
12956 | + { 0, 0, 0, 0, 0, 0, 0 } | |
12957 | }; | |
12958 | ||
12959 | static struct pci_driver serial_pci_driver = { | |
4dee9bd5 | 12960 | diff -urNp linux-2.6.25.4/drivers/usb/class/cdc-acm.c linux-2.6.25.4/drivers/usb/class/cdc-acm.c |
12961 | --- linux-2.6.25.4/drivers/usb/class/cdc-acm.c 2008-05-15 11:00:12.000000000 -0400 | |
12962 | +++ linux-2.6.25.4/drivers/usb/class/cdc-acm.c 2008-05-18 13:33:16.000000000 -0400 | |
12963 | @@ -1258,7 +1258,7 @@ static struct usb_device_id acm_ids[] = | |
50425a20 | 12964 | USB_CDC_ACM_PROTO_AT_CDMA) }, |
12965 | ||
12966 | /* NOTE: COMM/ACM/0xff is likely MSFT RNDIS ... NOT a modem!! */ | |
12967 | - { } | |
12968 | + { 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0 } | |
12969 | }; | |
12970 | ||
12971 | MODULE_DEVICE_TABLE (usb, acm_ids); | |
4dee9bd5 | 12972 | diff -urNp linux-2.6.25.4/drivers/usb/class/usblp.c linux-2.6.25.4/drivers/usb/class/usblp.c |
12973 | --- linux-2.6.25.4/drivers/usb/class/usblp.c 2008-05-15 11:00:12.000000000 -0400 | |
12974 | +++ linux-2.6.25.4/drivers/usb/class/usblp.c 2008-05-18 13:33:16.000000000 -0400 | |
da5b3fc8 | 12975 | @@ -227,7 +227,7 @@ static const struct quirk_printer_struct |
50425a20 | 12976 | { 0x0409, 0xf1be, USBLP_QUIRK_BIDIR }, /* NEC Picty800 (HP OEM) */ |
12977 | { 0x0482, 0x0010, USBLP_QUIRK_BIDIR }, /* Kyocera Mita FS 820, by zut <kernel@zut.de> */ | |
12978 | { 0x04b8, 0x0202, USBLP_QUIRK_BAD_CLASS }, /* Seiko Epson Receipt Printer M129C */ | |
12979 | - { 0, 0 } | |
12980 | + { 0, 0, 0 } | |
12981 | }; | |
12982 | ||
da5b3fc8 | 12983 | static int usblp_wwait(struct usblp *usblp, int nonblock); |
b2ee8b1e | 12984 | @@ -1401,7 +1401,7 @@ static struct usb_device_id usblp_ids [] |
50425a20 | 12985 | { USB_INTERFACE_INFO(7, 1, 2) }, |
12986 | { USB_INTERFACE_INFO(7, 1, 3) }, | |
12987 | { USB_DEVICE(0x04b8, 0x0202) }, /* Seiko Epson Receipt Printer M129C */ | |
12988 | - { } /* Terminating entry */ | |
12989 | + { 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0 } /* Terminating entry */ | |
12990 | }; | |
12991 | ||
12992 | MODULE_DEVICE_TABLE (usb, usblp_ids); | |
4dee9bd5 | 12993 | diff -urNp linux-2.6.25.4/drivers/usb/core/hub.c linux-2.6.25.4/drivers/usb/core/hub.c |
12994 | --- linux-2.6.25.4/drivers/usb/core/hub.c 2008-05-15 11:00:12.000000000 -0400 | |
12995 | +++ linux-2.6.25.4/drivers/usb/core/hub.c 2008-05-18 13:33:16.000000000 -0400 | |
12996 | @@ -2909,7 +2909,7 @@ static struct usb_device_id hub_id_table | |
50425a20 | 12997 | .bDeviceClass = USB_CLASS_HUB}, |
12998 | { .match_flags = USB_DEVICE_ID_MATCH_INT_CLASS, | |
12999 | .bInterfaceClass = USB_CLASS_HUB}, | |
13000 | - { } /* Terminating entry */ | |
13001 | + { 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0 } /* Terminating entry */ | |
13002 | }; | |
13003 | ||
13004 | MODULE_DEVICE_TABLE (usb, hub_id_table); | |
4dee9bd5 | 13005 | diff -urNp linux-2.6.25.4/drivers/usb/host/ehci-pci.c linux-2.6.25.4/drivers/usb/host/ehci-pci.c |
13006 | --- linux-2.6.25.4/drivers/usb/host/ehci-pci.c 2008-05-15 11:00:12.000000000 -0400 | |
13007 | +++ linux-2.6.25.4/drivers/usb/host/ehci-pci.c 2008-05-18 13:33:16.000000000 -0400 | |
13008 | @@ -389,7 +389,7 @@ static const struct pci_device_id pci_id | |
50425a20 | 13009 | PCI_DEVICE_CLASS(PCI_CLASS_SERIAL_USB_EHCI, ~0), |
13010 | .driver_data = (unsigned long) &ehci_pci_hc_driver, | |
13011 | }, | |
13012 | - { /* end: all zeroes */ } | |
13013 | + { 0, 0, 0, 0, 0, 0, 0 } | |
13014 | }; | |
13015 | MODULE_DEVICE_TABLE(pci, pci_ids); | |
13016 | ||
4dee9bd5 | 13017 | diff -urNp linux-2.6.25.4/drivers/usb/host/uhci-hcd.c linux-2.6.25.4/drivers/usb/host/uhci-hcd.c |
13018 | --- linux-2.6.25.4/drivers/usb/host/uhci-hcd.c 2008-05-15 11:00:12.000000000 -0400 | |
13019 | +++ linux-2.6.25.4/drivers/usb/host/uhci-hcd.c 2008-05-18 13:33:16.000000000 -0400 | |
da5b3fc8 | 13020 | @@ -893,7 +893,7 @@ static const struct pci_device_id uhci_p |
50425a20 | 13021 | /* handle any USB UHCI controller */ |
13022 | PCI_DEVICE_CLASS(PCI_CLASS_SERIAL_USB_UHCI, ~0), | |
13023 | .driver_data = (unsigned long) &uhci_driver, | |
13024 | - }, { /* end: all zeroes */ } | |
13025 | + }, { 0, 0, 0, 0, 0, 0, 0 } | |
13026 | }; | |
13027 | ||
13028 | MODULE_DEVICE_TABLE(pci, uhci_pci_ids); | |
4dee9bd5 | 13029 | diff -urNp linux-2.6.25.4/drivers/usb/storage/debug.h linux-2.6.25.4/drivers/usb/storage/debug.h |
13030 | --- linux-2.6.25.4/drivers/usb/storage/debug.h 2008-05-15 11:00:12.000000000 -0400 | |
13031 | +++ linux-2.6.25.4/drivers/usb/storage/debug.h 2008-05-18 13:33:16.000000000 -0400 | |
50425a20 | 13032 | @@ -56,9 +56,9 @@ void usb_stor_show_sense( unsigned char |
13033 | #define US_DEBUGPX(x...) printk( x ) | |
13034 | #define US_DEBUG(x) x | |
13035 | #else | |
13036 | -#define US_DEBUGP(x...) | |
13037 | -#define US_DEBUGPX(x...) | |
13038 | -#define US_DEBUG(x) | |
13039 | +#define US_DEBUGP(x...) do {} while (0) | |
13040 | +#define US_DEBUGPX(x...) do {} while (0) | |
13041 | +#define US_DEBUG(x) do {} while (0) | |
13042 | #endif | |
13043 | ||
13044 | #endif | |
4dee9bd5 | 13045 | diff -urNp linux-2.6.25.4/drivers/usb/storage/usb.c linux-2.6.25.4/drivers/usb/storage/usb.c |
13046 | --- linux-2.6.25.4/drivers/usb/storage/usb.c 2008-05-15 11:00:12.000000000 -0400 | |
13047 | +++ linux-2.6.25.4/drivers/usb/storage/usb.c 2008-05-18 13:33:16.000000000 -0400 | |
da5b3fc8 | 13048 | @@ -134,7 +134,7 @@ static struct usb_device_id storage_usb_ |
50425a20 | 13049 | #undef UNUSUAL_DEV |
13050 | #undef USUAL_DEV | |
13051 | /* Terminating entry */ | |
13052 | - { } | |
13053 | + { 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0 } | |
13054 | }; | |
13055 | ||
13056 | MODULE_DEVICE_TABLE (usb, storage_usb_ids); | |
da5b3fc8 | 13057 | @@ -174,7 +174,7 @@ static struct us_unusual_dev us_unusual_ |
50425a20 | 13058 | # undef USUAL_DEV |
13059 | ||
13060 | /* Terminating entry */ | |
13061 | - { NULL } | |
13062 | + { NULL, NULL, 0, 0, NULL } | |
13063 | }; | |
13064 | ||
13065 | ||
4dee9bd5 | 13066 | diff -urNp linux-2.6.25.4/drivers/video/fbcmap.c linux-2.6.25.4/drivers/video/fbcmap.c |
13067 | --- linux-2.6.25.4/drivers/video/fbcmap.c 2008-05-15 11:00:12.000000000 -0400 | |
13068 | +++ linux-2.6.25.4/drivers/video/fbcmap.c 2008-05-18 13:33:16.000000000 -0400 | |
da5b3fc8 | 13069 | @@ -250,8 +250,7 @@ int fb_set_user_cmap(struct fb_cmap_user |
50425a20 | 13070 | int rc, size = cmap->len * sizeof(u16); |
13071 | struct fb_cmap umap; | |
13072 | ||
13073 | - if (cmap->start < 0 || (!info->fbops->fb_setcolreg && | |
13074 | - !info->fbops->fb_setcmap)) | |
13075 | + if (!info->fbops->fb_setcolreg && !info->fbops->fb_setcmap) | |
13076 | return -EINVAL; | |
13077 | ||
13078 | memset(&umap, 0, sizeof(struct fb_cmap)); | |
4dee9bd5 | 13079 | diff -urNp linux-2.6.25.4/drivers/video/fbmem.c linux-2.6.25.4/drivers/video/fbmem.c |
13080 | --- linux-2.6.25.4/drivers/video/fbmem.c 2008-05-15 11:00:12.000000000 -0400 | |
13081 | +++ linux-2.6.25.4/drivers/video/fbmem.c 2008-05-18 13:33:16.000000000 -0400 | |
da5b3fc8 | 13082 | @@ -394,7 +394,7 @@ static void fb_do_show_logo(struct fb_in |
8a4b4a5e | 13083 | image->dx += image->width + 8; |
13084 | } | |
13085 | } else if (rotate == FB_ROTATE_UD) { | |
13086 | - for (x = 0; x < num && image->dx >= 0; x++) { | |
13087 | + for (x = 0; x < num && (__s32)image->dx >= 0; x++) { | |
13088 | info->fbops->fb_imageblit(info, image); | |
13089 | image->dx -= image->width + 8; | |
13090 | } | |
da5b3fc8 | 13091 | @@ -406,7 +406,7 @@ static void fb_do_show_logo(struct fb_in |
8a4b4a5e | 13092 | image->dy += image->height + 8; |
13093 | } | |
13094 | } else if (rotate == FB_ROTATE_CCW) { | |
13095 | - for (x = 0; x < num && image->dy >= 0; x++) { | |
13096 | + for (x = 0; x < num && (__s32)image->dy >= 0; x++) { | |
13097 | info->fbops->fb_imageblit(info, image); | |
13098 | image->dy -= image->height + 8; | |
13099 | } | |
da5b3fc8 | 13100 | @@ -1057,9 +1057,9 @@ fb_ioctl(struct inode *inode, struct fil |
50425a20 | 13101 | case FBIOPUT_CON2FBMAP: |
13102 | if (copy_from_user(&con2fb, argp, sizeof(con2fb))) | |
13103 | return - EFAULT; | |
13104 | - if (con2fb.console < 0 || con2fb.console > MAX_NR_CONSOLES) | |
13105 | + if (con2fb.console > MAX_NR_CONSOLES) | |
13106 | return -EINVAL; | |
13107 | - if (con2fb.framebuffer < 0 || con2fb.framebuffer >= FB_MAX) | |
13108 | + if (con2fb.framebuffer >= FB_MAX) | |
13109 | return -EINVAL; | |
13110 | #ifdef CONFIG_KMOD | |
13111 | if (!registered_fb[con2fb.framebuffer]) | |
4dee9bd5 | 13112 | diff -urNp linux-2.6.25.4/drivers/video/fbmon.c linux-2.6.25.4/drivers/video/fbmon.c |
13113 | --- linux-2.6.25.4/drivers/video/fbmon.c 2008-05-15 11:00:12.000000000 -0400 | |
13114 | +++ linux-2.6.25.4/drivers/video/fbmon.c 2008-05-18 13:33:16.000000000 -0400 | |
50425a20 | 13115 | @@ -45,7 +45,7 @@ |
13116 | #ifdef DEBUG | |
13117 | #define DPRINTK(fmt, args...) printk(fmt,## args) | |
13118 | #else | |
13119 | -#define DPRINTK(fmt, args...) | |
13120 | +#define DPRINTK(fmt, args...) do {} while (0) | |
13121 | #endif | |
13122 | ||
8a4b4a5e | 13123 | #define FBMON_FIX_HEADER 1 |
4dee9bd5 | 13124 | diff -urNp linux-2.6.25.4/drivers/video/i810/i810_accel.c linux-2.6.25.4/drivers/video/i810/i810_accel.c |
13125 | --- linux-2.6.25.4/drivers/video/i810/i810_accel.c 2008-05-15 11:00:12.000000000 -0400 | |
13126 | +++ linux-2.6.25.4/drivers/video/i810/i810_accel.c 2008-05-18 13:33:16.000000000 -0400 | |
50425a20 | 13127 | @@ -73,6 +73,7 @@ static inline int wait_for_space(struct |
13128 | } | |
13129 | } | |
13130 | printk("ringbuffer lockup!!!\n"); | |
13131 | + printk("head:%u tail:%u iring.size:%u space:%u\n", head, tail, par->iring.size, space); | |
13132 | i810_report_error(mmio); | |
13133 | par->dev_flags |= LOCKUP; | |
13134 | info->pixmap.scan_align = 1; | |
4dee9bd5 | 13135 | diff -urNp linux-2.6.25.4/drivers/video/i810/i810_main.c linux-2.6.25.4/drivers/video/i810/i810_main.c |
13136 | --- linux-2.6.25.4/drivers/video/i810/i810_main.c 2008-05-15 11:00:12.000000000 -0400 | |
13137 | +++ linux-2.6.25.4/drivers/video/i810/i810_main.c 2008-05-18 13:33:16.000000000 -0400 | |
50425a20 | 13138 | @@ -120,7 +120,7 @@ static struct pci_device_id i810fb_pci_t |
13139 | PCI_ANY_ID, PCI_ANY_ID, 0, 0, 4 }, | |
13140 | { PCI_VENDOR_ID_INTEL, PCI_DEVICE_ID_INTEL_82815_CGC, | |
13141 | PCI_ANY_ID, PCI_ANY_ID, 0, 0, 5 }, | |
13142 | - { 0 }, | |
13143 | + { 0, 0, 0, 0, 0, 0, 0 }, | |
13144 | }; | |
13145 | ||
13146 | static struct pci_driver i810fb_driver = { | |
13147 | @@ -1509,7 +1509,7 @@ static int i810fb_cursor(struct fb_info | |
13148 | int size = ((cursor->image.width + 7) >> 3) * | |
13149 | cursor->image.height; | |
13150 | int i; | |
13151 | - u8 *data = kmalloc(64 * 8, GFP_ATOMIC); | |
13152 | + u8 *data = kmalloc(64 * 8, GFP_KERNEL); | |
13153 | ||
13154 | if (data == NULL) | |
13155 | return -ENOMEM; | |
4dee9bd5 | 13156 | diff -urNp linux-2.6.25.4/drivers/video/modedb.c linux-2.6.25.4/drivers/video/modedb.c |
13157 | --- linux-2.6.25.4/drivers/video/modedb.c 2008-05-15 11:00:12.000000000 -0400 | |
13158 | +++ linux-2.6.25.4/drivers/video/modedb.c 2008-05-18 13:33:16.000000000 -0400 | |
da5b3fc8 | 13159 | @@ -37,232 +37,232 @@ static const struct fb_videomode modedb[ |
50425a20 | 13160 | { |
13161 | /* 640x400 @ 70 Hz, 31.5 kHz hsync */ | |
13162 | NULL, 70, 640, 400, 39721, 40, 24, 39, 9, 96, 2, | |
13163 | - 0, FB_VMODE_NONINTERLACED | |
13164 | + 0, FB_VMODE_NONINTERLACED, FB_MODE_IS_UNKNOWN | |
13165 | }, { | |
13166 | /* 640x480 @ 60 Hz, 31.5 kHz hsync */ | |
13167 | NULL, 60, 640, 480, 39721, 40, 24, 32, 11, 96, 2, | |
13168 | - 0, FB_VMODE_NONINTERLACED | |
13169 | + 0, FB_VMODE_NONINTERLACED, FB_MODE_IS_UNKNOWN | |
13170 | }, { | |
13171 | /* 800x600 @ 56 Hz, 35.15 kHz hsync */ | |
13172 | NULL, 56, 800, 600, 27777, 128, 24, 22, 1, 72, 2, | |
13173 | - 0, FB_VMODE_NONINTERLACED | |
13174 | + 0, FB_VMODE_NONINTERLACED, FB_MODE_IS_UNKNOWN | |
13175 | }, { | |
13176 | /* 1024x768 @ 87 Hz interlaced, 35.5 kHz hsync */ | |
13177 | NULL, 87, 1024, 768, 22271, 56, 24, 33, 8, 160, 8, | |
13178 | - 0, FB_VMODE_INTERLACED | |
13179 | + 0, FB_VMODE_INTERLACED, FB_MODE_IS_UNKNOWN | |
13180 | }, { | |
13181 | /* 640x400 @ 85 Hz, 37.86 kHz hsync */ | |
13182 | NULL, 85, 640, 400, 31746, 96, 32, 41, 1, 64, 3, | |
13183 | - FB_SYNC_VERT_HIGH_ACT, FB_VMODE_NONINTERLACED | |
13184 | + FB_SYNC_VERT_HIGH_ACT, FB_VMODE_NONINTERLACED, FB_MODE_IS_UNKNOWN | |
13185 | }, { | |
13186 | /* 640x480 @ 72 Hz, 36.5 kHz hsync */ | |
13187 | NULL, 72, 640, 480, 31746, 144, 40, 30, 8, 40, 3, | |
13188 | - 0, FB_VMODE_NONINTERLACED | |
13189 | + 0, FB_VMODE_NONINTERLACED, FB_MODE_IS_UNKNOWN | |
13190 | }, { | |
13191 | /* 640x480 @ 75 Hz, 37.50 kHz hsync */ | |
13192 | NULL, 75, 640, 480, 31746, 120, 16, 16, 1, 64, 3, | |
13193 | - 0, FB_VMODE_NONINTERLACED | |
13194 | + 0, FB_VMODE_NONINTERLACED, FB_MODE_IS_UNKNOWN | |
13195 | }, { | |
13196 | /* 800x600 @ 60 Hz, 37.8 kHz hsync */ | |
13197 | NULL, 60, 800, 600, 25000, 88, 40, 23, 1, 128, 4, | |
13198 | - FB_SYNC_HOR_HIGH_ACT|FB_SYNC_VERT_HIGH_ACT, FB_VMODE_NONINTERLACED | |
13199 | + FB_SYNC_HOR_HIGH_ACT|FB_SYNC_VERT_HIGH_ACT, FB_VMODE_NONINTERLACED, FB_MODE_IS_UNKNOWN | |
13200 | }, { | |
13201 | /* 640x480 @ 85 Hz, 43.27 kHz hsync */ | |
13202 | NULL, 85, 640, 480, 27777, 80, 56, 25, 1, 56, 3, | |
13203 | - 0, FB_VMODE_NONINTERLACED | |
13204 | + 0, FB_VMODE_NONINTERLACED, FB_MODE_IS_UNKNOWN | |
13205 | }, { | |
13206 | /* 1152x864 @ 89 Hz interlaced, 44 kHz hsync */ | |
da5b3fc8 | 13207 | NULL, 89, 1152, 864, 15384, 96, 16, 110, 1, 216, 10, |
50425a20 | 13208 | - 0, FB_VMODE_INTERLACED |
13209 | + 0, FB_VMODE_INTERLACED, FB_MODE_IS_UNKNOWN | |
13210 | }, { | |
13211 | /* 800x600 @ 72 Hz, 48.0 kHz hsync */ | |
13212 | NULL, 72, 800, 600, 20000, 64, 56, 23, 37, 120, 6, | |
13213 | - FB_SYNC_HOR_HIGH_ACT|FB_SYNC_VERT_HIGH_ACT, FB_VMODE_NONINTERLACED | |
13214 | + FB_SYNC_HOR_HIGH_ACT|FB_SYNC_VERT_HIGH_ACT, FB_VMODE_NONINTERLACED, FB_MODE_IS_UNKNOWN | |
13215 | }, { | |
13216 | /* 1024x768 @ 60 Hz, 48.4 kHz hsync */ | |
13217 | NULL, 60, 1024, 768, 15384, 168, 8, 29, 3, 144, 6, | |
13218 | - 0, FB_VMODE_NONINTERLACED | |
13219 | + 0, FB_VMODE_NONINTERLACED, FB_MODE_IS_UNKNOWN | |
13220 | }, { | |
13221 | /* 640x480 @ 100 Hz, 53.01 kHz hsync */ | |
13222 | NULL, 100, 640, 480, 21834, 96, 32, 36, 8, 96, 6, | |
13223 | - 0, FB_VMODE_NONINTERLACED | |
13224 | + 0, FB_VMODE_NONINTERLACED, FB_MODE_IS_UNKNOWN | |
13225 | }, { | |
13226 | /* 1152x864 @ 60 Hz, 53.5 kHz hsync */ | |
13227 | NULL, 60, 1152, 864, 11123, 208, 64, 16, 4, 256, 8, | |
13228 | - 0, FB_VMODE_NONINTERLACED | |
13229 | + 0, FB_VMODE_NONINTERLACED, FB_MODE_IS_UNKNOWN | |
13230 | }, { | |
13231 | /* 800x600 @ 85 Hz, 55.84 kHz hsync */ | |
13232 | NULL, 85, 800, 600, 16460, 160, 64, 36, 16, 64, 5, | |
13233 | - 0, FB_VMODE_NONINTERLACED | |
13234 | + 0, FB_VMODE_NONINTERLACED, FB_MODE_IS_UNKNOWN | |
13235 | }, { | |
13236 | /* 1024x768 @ 70 Hz, 56.5 kHz hsync */ | |
13237 | NULL, 70, 1024, 768, 13333, 144, 24, 29, 3, 136, 6, | |
13238 | - 0, FB_VMODE_NONINTERLACED | |
13239 | + 0, FB_VMODE_NONINTERLACED, FB_MODE_IS_UNKNOWN | |
13240 | }, { | |
13241 | /* 1280x1024 @ 87 Hz interlaced, 51 kHz hsync */ | |
13242 | NULL, 87, 1280, 1024, 12500, 56, 16, 128, 1, 216, 12, | |
13243 | - 0, FB_VMODE_INTERLACED | |
13244 | + 0, FB_VMODE_INTERLACED, FB_MODE_IS_UNKNOWN | |
13245 | }, { | |
13246 | /* 800x600 @ 100 Hz, 64.02 kHz hsync */ | |
13247 | NULL, 100, 800, 600, 14357, 160, 64, 30, 4, 64, 6, | |
13248 | - 0, FB_VMODE_NONINTERLACED | |
13249 | + 0, FB_VMODE_NONINTERLACED, FB_MODE_IS_UNKNOWN | |
13250 | }, { | |
13251 | /* 1024x768 @ 76 Hz, 62.5 kHz hsync */ | |
13252 | NULL, 76, 1024, 768, 11764, 208, 8, 36, 16, 120, 3, | |
13253 | - 0, FB_VMODE_NONINTERLACED | |
13254 | + 0, FB_VMODE_NONINTERLACED, FB_MODE_IS_UNKNOWN | |
13255 | }, { | |
13256 | /* 1152x864 @ 70 Hz, 62.4 kHz hsync */ | |
13257 | NULL, 70, 1152, 864, 10869, 106, 56, 20, 1, 160, 10, | |
13258 | - 0, FB_VMODE_NONINTERLACED | |
13259 | + 0, FB_VMODE_NONINTERLACED, FB_MODE_IS_UNKNOWN | |
13260 | }, { | |
13261 | /* 1280x1024 @ 61 Hz, 64.2 kHz hsync */ | |
13262 | NULL, 61, 1280, 1024, 9090, 200, 48, 26, 1, 184, 3, | |
13263 | - 0, FB_VMODE_NONINTERLACED | |
13264 | + 0, FB_VMODE_NONINTERLACED, FB_MODE_IS_UNKNOWN | |
13265 | }, { | |
13266 | /* 1400x1050 @ 60Hz, 63.9 kHz hsync */ | |
da5b3fc8 | 13267 | NULL, 60, 1400, 1050, 9259, 136, 40, 13, 1, 112, 3, |
50425a20 | 13268 | - 0, FB_VMODE_NONINTERLACED |
13269 | + 0, FB_VMODE_NONINTERLACED, FB_MODE_IS_UNKNOWN | |
13270 | }, { | |
13271 | /* 1400x1050 @ 75,107 Hz, 82,392 kHz +hsync +vsync*/ | |
da5b3fc8 | 13272 | NULL, 75, 1400, 1050, 7190, 120, 56, 23, 10, 112, 13, |
50425a20 | 13273 | - FB_SYNC_HOR_HIGH_ACT|FB_SYNC_VERT_HIGH_ACT, FB_VMODE_NONINTERLACED |
13274 | + FB_SYNC_HOR_HIGH_ACT|FB_SYNC_VERT_HIGH_ACT, FB_VMODE_NONINTERLACED, FB_MODE_IS_UNKNOWN | |
13275 | }, { | |
13276 | /* 1400x1050 @ 60 Hz, ? kHz +hsync +vsync*/ | |
13277 | NULL, 60, 1400, 1050, 9259, 128, 40, 12, 0, 112, 3, | |
13278 | - FB_SYNC_HOR_HIGH_ACT|FB_SYNC_VERT_HIGH_ACT, FB_VMODE_NONINTERLACED | |
13279 | + FB_SYNC_HOR_HIGH_ACT|FB_SYNC_VERT_HIGH_ACT, FB_VMODE_NONINTERLACED, FB_MODE_IS_UNKNOWN | |
13280 | }, { | |
13281 | /* 1024x768 @ 85 Hz, 70.24 kHz hsync */ | |
13282 | NULL, 85, 1024, 768, 10111, 192, 32, 34, 14, 160, 6, | |
13283 | - 0, FB_VMODE_NONINTERLACED | |
13284 | + 0, FB_VMODE_NONINTERLACED, FB_MODE_IS_UNKNOWN | |
13285 | }, { | |
13286 | /* 1152x864 @ 78 Hz, 70.8 kHz hsync */ | |
13287 | NULL, 78, 1152, 864, 9090, 228, 88, 32, 0, 84, 12, | |
13288 | - 0, FB_VMODE_NONINTERLACED | |
13289 | + 0, FB_VMODE_NONINTERLACED, FB_MODE_IS_UNKNOWN | |
13290 | }, { | |
13291 | /* 1280x1024 @ 70 Hz, 74.59 kHz hsync */ | |
13292 | NULL, 70, 1280, 1024, 7905, 224, 32, 28, 8, 160, 8, | |
13293 | - 0, FB_VMODE_NONINTERLACED | |
13294 | + 0, FB_VMODE_NONINTERLACED, FB_MODE_IS_UNKNOWN | |
13295 | }, { | |
13296 | /* 1600x1200 @ 60Hz, 75.00 kHz hsync */ | |
13297 | NULL, 60, 1600, 1200, 6172, 304, 64, 46, 1, 192, 3, | |
13298 | - FB_SYNC_HOR_HIGH_ACT|FB_SYNC_VERT_HIGH_ACT, FB_VMODE_NONINTERLACED | |
13299 | + FB_SYNC_HOR_HIGH_ACT|FB_SYNC_VERT_HIGH_ACT, FB_VMODE_NONINTERLACED, FB_MODE_IS_UNKNOWN | |
13300 | }, { | |
13301 | /* 1152x864 @ 84 Hz, 76.0 kHz hsync */ | |
13302 | NULL, 84, 1152, 864, 7407, 184, 312, 32, 0, 128, 12, | |
13303 | - 0, FB_VMODE_NONINTERLACED | |
13304 | + 0, FB_VMODE_NONINTERLACED, FB_MODE_IS_UNKNOWN | |
13305 | }, { | |
13306 | /* 1280x1024 @ 74 Hz, 78.85 kHz hsync */ | |
13307 | NULL, 74, 1280, 1024, 7407, 256, 32, 34, 3, 144, 3, | |
13308 | - 0, FB_VMODE_NONINTERLACED | |
13309 | + 0, FB_VMODE_NONINTERLACED, FB_MODE_IS_UNKNOWN | |
13310 | }, { | |
13311 | /* 1024x768 @ 100Hz, 80.21 kHz hsync */ | |
13312 | NULL, 100, 1024, 768, 8658, 192, 32, 21, 3, 192, 10, | |
13313 | - 0, FB_VMODE_NONINTERLACED | |
13314 | + 0, FB_VMODE_NONINTERLACED, FB_MODE_IS_UNKNOWN | |
13315 | }, { | |
13316 | /* 1280x1024 @ 76 Hz, 81.13 kHz hsync */ | |
13317 | NULL, 76, 1280, 1024, 7407, 248, 32, 34, 3, 104, 3, | |
13318 | - 0, FB_VMODE_NONINTERLACED | |
13319 | + 0, FB_VMODE_NONINTERLACED, FB_MODE_IS_UNKNOWN | |
13320 | }, { | |
13321 | /* 1600x1200 @ 70 Hz, 87.50 kHz hsync */ | |
13322 | NULL, 70, 1600, 1200, 5291, 304, 64, 46, 1, 192, 3, | |
13323 | - 0, FB_VMODE_NONINTERLACED | |
13324 | + 0, FB_VMODE_NONINTERLACED, FB_MODE_IS_UNKNOWN | |
13325 | }, { | |
13326 | /* 1152x864 @ 100 Hz, 89.62 kHz hsync */ | |
13327 | NULL, 100, 1152, 864, 7264, 224, 32, 17, 2, 128, 19, | |
13328 | - 0, FB_VMODE_NONINTERLACED | |
13329 | + 0, FB_VMODE_NONINTERLACED, FB_MODE_IS_UNKNOWN | |
13330 | }, { | |
13331 | /* 1280x1024 @ 85 Hz, 91.15 kHz hsync */ | |
13332 | NULL, 85, 1280, 1024, 6349, 224, 64, 44, 1, 160, 3, | |
13333 | - FB_SYNC_HOR_HIGH_ACT|FB_SYNC_VERT_HIGH_ACT, FB_VMODE_NONINTERLACED | |
13334 | + FB_SYNC_HOR_HIGH_ACT|FB_SYNC_VERT_HIGH_ACT, FB_VMODE_NONINTERLACED, FB_MODE_IS_UNKNOWN | |
13335 | }, { | |
13336 | /* 1600x1200 @ 75 Hz, 93.75 kHz hsync */ | |
13337 | NULL, 75, 1600, 1200, 4938, 304, 64, 46, 1, 192, 3, | |
13338 | - FB_SYNC_HOR_HIGH_ACT|FB_SYNC_VERT_HIGH_ACT, FB_VMODE_NONINTERLACED | |
13339 | + FB_SYNC_HOR_HIGH_ACT|FB_SYNC_VERT_HIGH_ACT, FB_VMODE_NONINTERLACED, FB_MODE_IS_UNKNOWN | |
13340 | }, { | |
13341 | /* 1680x1050 @ 60 Hz, 65.191 kHz hsync */ | |
13342 | NULL, 60, 1680, 1050, 6848, 280, 104, 30, 3, 176, 6, | |
13343 | - FB_SYNC_HOR_HIGH_ACT|FB_SYNC_VERT_HIGH_ACT, FB_VMODE_NONINTERLACED | |
13344 | + FB_SYNC_HOR_HIGH_ACT|FB_SYNC_VERT_HIGH_ACT, FB_VMODE_NONINTERLACED, FB_MODE_IS_UNKNOWN | |
13345 | }, { | |
13346 | /* 1600x1200 @ 85 Hz, 105.77 kHz hsync */ | |
13347 | NULL, 85, 1600, 1200, 4545, 272, 16, 37, 4, 192, 3, | |
13348 | - FB_SYNC_HOR_HIGH_ACT|FB_SYNC_VERT_HIGH_ACT, FB_VMODE_NONINTERLACED | |
13349 | + FB_SYNC_HOR_HIGH_ACT|FB_SYNC_VERT_HIGH_ACT, FB_VMODE_NONINTERLACED, FB_MODE_IS_UNKNOWN | |
13350 | }, { | |
13351 | /* 1280x1024 @ 100 Hz, 107.16 kHz hsync */ | |
13352 | NULL, 100, 1280, 1024, 5502, 256, 32, 26, 7, 128, 15, | |
13353 | - 0, FB_VMODE_NONINTERLACED | |
13354 | + 0, FB_VMODE_NONINTERLACED, FB_MODE_IS_UNKNOWN | |
13355 | }, { | |
13356 | /* 1800x1440 @ 64Hz, 96.15 kHz hsync */ | |
13357 | NULL, 64, 1800, 1440, 4347, 304, 96, 46, 1, 192, 3, | |
13358 | - FB_SYNC_HOR_HIGH_ACT|FB_SYNC_VERT_HIGH_ACT, FB_VMODE_NONINTERLACED | |
13359 | + FB_SYNC_HOR_HIGH_ACT|FB_SYNC_VERT_HIGH_ACT, FB_VMODE_NONINTERLACED, FB_MODE_IS_UNKNOWN | |
13360 | }, { | |
13361 | /* 1800x1440 @ 70Hz, 104.52 kHz hsync */ | |
13362 | NULL, 70, 1800, 1440, 4000, 304, 96, 46, 1, 192, 3, | |
13363 | - FB_SYNC_HOR_HIGH_ACT|FB_SYNC_VERT_HIGH_ACT, FB_VMODE_NONINTERLACED | |
13364 | + FB_SYNC_HOR_HIGH_ACT|FB_SYNC_VERT_HIGH_ACT, FB_VMODE_NONINTERLACED, FB_MODE_IS_UNKNOWN | |
13365 | }, { | |
13366 | /* 512x384 @ 78 Hz, 31.50 kHz hsync */ | |
13367 | NULL, 78, 512, 384, 49603, 48, 16, 16, 1, 64, 3, | |
13368 | - 0, FB_VMODE_NONINTERLACED | |
13369 | + 0, FB_VMODE_NONINTERLACED, FB_MODE_IS_UNKNOWN | |
13370 | }, { | |
13371 | /* 512x384 @ 85 Hz, 34.38 kHz hsync */ | |
13372 | NULL, 85, 512, 384, 45454, 48, 16, 16, 1, 64, 3, | |
13373 | - 0, FB_VMODE_NONINTERLACED | |
13374 | + 0, FB_VMODE_NONINTERLACED, FB_MODE_IS_UNKNOWN | |
13375 | }, { | |
13376 | /* 320x200 @ 70 Hz, 31.5 kHz hsync, 8:5 aspect ratio */ | |
13377 | NULL, 70, 320, 200, 79440, 16, 16, 20, 4, 48, 1, | |
13378 | - 0, FB_VMODE_DOUBLE | |
13379 | + 0, FB_VMODE_DOUBLE, FB_MODE_IS_UNKNOWN | |
13380 | }, { | |
13381 | /* 320x240 @ 60 Hz, 31.5 kHz hsync, 4:3 aspect ratio */ | |
13382 | NULL, 60, 320, 240, 79440, 16, 16, 16, 5, 48, 1, | |
13383 | - 0, FB_VMODE_DOUBLE | |
13384 | + 0, FB_VMODE_DOUBLE, FB_MODE_IS_UNKNOWN | |
13385 | }, { | |
13386 | /* 320x240 @ 72 Hz, 36.5 kHz hsync */ | |
13387 | NULL, 72, 320, 240, 63492, 16, 16, 16, 4, 48, 2, | |
13388 | - 0, FB_VMODE_DOUBLE | |
13389 | + 0, FB_VMODE_DOUBLE, FB_MODE_IS_UNKNOWN | |
13390 | }, { | |
13391 | /* 400x300 @ 56 Hz, 35.2 kHz hsync, 4:3 aspect ratio */ | |
13392 | NULL, 56, 400, 300, 55555, 64, 16, 10, 1, 32, 1, | |
13393 | - 0, FB_VMODE_DOUBLE | |
13394 | + 0, FB_VMODE_DOUBLE, FB_MODE_IS_UNKNOWN | |
13395 | }, { | |
13396 | /* 400x300 @ 60 Hz, 37.8 kHz hsync */ | |
13397 | NULL, 60, 400, 300, 50000, 48, 16, 11, 1, 64, 2, | |
13398 | - 0, FB_VMODE_DOUBLE | |
13399 | + 0, FB_VMODE_DOUBLE, FB_MODE_IS_UNKNOWN | |
13400 | }, { | |
13401 | /* 400x300 @ 72 Hz, 48.0 kHz hsync */ | |
13402 | NULL, 72, 400, 300, 40000, 32, 24, 11, 19, 64, 3, | |
13403 | - 0, FB_VMODE_DOUBLE | |
13404 | + 0, FB_VMODE_DOUBLE, FB_MODE_IS_UNKNOWN | |
13405 | }, { | |
13406 | /* 480x300 @ 56 Hz, 35.2 kHz hsync, 8:5 aspect ratio */ | |
13407 | NULL, 56, 480, 300, 46176, 80, 16, 10, 1, 40, 1, | |
13408 | - 0, FB_VMODE_DOUBLE | |
13409 | + 0, FB_VMODE_DOUBLE, FB_MODE_IS_UNKNOWN | |
13410 | }, { | |
13411 | /* 480x300 @ 60 Hz, 37.8 kHz hsync */ | |
13412 | NULL, 60, 480, 300, 41858, 56, 16, 11, 1, 80, 2, | |
13413 | - 0, FB_VMODE_DOUBLE | |
13414 | + 0, FB_VMODE_DOUBLE, FB_MODE_IS_UNKNOWN | |
13415 | }, { | |
13416 | /* 480x300 @ 63 Hz, 39.6 kHz hsync */ | |
13417 | NULL, 63, 480, 300, 40000, 56, 16, 11, 1, 80, 2, | |
13418 | - 0, FB_VMODE_DOUBLE | |
13419 | + 0, FB_VMODE_DOUBLE, FB_MODE_IS_UNKNOWN | |
13420 | }, { | |
13421 | /* 480x300 @ 72 Hz, 48.0 kHz hsync */ | |
13422 | NULL, 72, 480, 300, 33386, 40, 24, 11, 19, 80, 3, | |
13423 | - 0, FB_VMODE_DOUBLE | |
13424 | + 0, FB_VMODE_DOUBLE, FB_MODE_IS_UNKNOWN | |
13425 | }, { | |
13426 | /* 1920x1200 @ 60 Hz, 74.5 Khz hsync */ | |
13427 | NULL, 60, 1920, 1200, 5177, 128, 336, 1, 38, 208, 3, | |
13428 | FB_SYNC_HOR_HIGH_ACT | FB_SYNC_VERT_HIGH_ACT, | |
13429 | - FB_VMODE_NONINTERLACED | |
13430 | + FB_VMODE_NONINTERLACED, FB_MODE_IS_UNKNOWN | |
13431 | }, { | |
13432 | /* 1152x768, 60 Hz, PowerBook G4 Titanium I and II */ | |
da5b3fc8 | 13433 | NULL, 60, 1152, 768, 14047, 158, 26, 29, 3, 136, 6, |
50425a20 | 13434 | - FB_SYNC_HOR_HIGH_ACT|FB_SYNC_VERT_HIGH_ACT, FB_VMODE_NONINTERLACED |
13435 | + FB_SYNC_HOR_HIGH_ACT|FB_SYNC_VERT_HIGH_ACT, FB_VMODE_NONINTERLACED, FB_MODE_IS_UNKNOWN | |
13436 | }, { | |
13437 | /* 1366x768, 60 Hz, 47.403 kHz hsync, WXGA 16:9 aspect ratio */ | |
13438 | NULL, 60, 1366, 768, 13806, 120, 10, 14, 3, 32, 5, | |
13439 | - 0, FB_VMODE_NONINTERLACED | |
da5b3fc8 | 13440 | + 0, FB_VMODE_NONINTERLACED, FB_MODE_IS_UNKNOWN |
13441 | }, { | |
13442 | /* 1280x800, 60 Hz, 47.403 kHz hsync, WXGA 16:10 aspect ratio */ | |
13443 | NULL, 60, 1280, 800, 12048, 200, 64, 24, 1, 136, 3, | |
13444 | - 0, FB_VMODE_NONINTERLACED | |
50425a20 | 13445 | + 0, FB_VMODE_NONINTERLACED, FB_MODE_IS_UNKNOWN |
13446 | }, | |
13447 | }; | |
13448 | ||
4dee9bd5 | 13449 | diff -urNp linux-2.6.25.4/drivers/video/uvesafb.c linux-2.6.25.4/drivers/video/uvesafb.c |
13450 | --- linux-2.6.25.4/drivers/video/uvesafb.c 2008-05-15 11:00:12.000000000 -0400 | |
13451 | +++ linux-2.6.25.4/drivers/video/uvesafb.c 2008-05-18 13:33:16.000000000 -0400 | |
da5b3fc8 | 13452 | @@ -117,7 +117,7 @@ static int uvesafb_helper_start(void) |
13453 | NULL, | |
13454 | }; | |
13455 | ||
13456 | - return call_usermodehelper(v86d_path, argv, envp, 1); | |
13457 | + return call_usermodehelper(v86d_path, argv, envp, UMH_WAIT_PROC); | |
13458 | } | |
13459 | ||
13460 | /* | |
4dee9bd5 | 13461 | diff -urNp linux-2.6.25.4/drivers/video/vesafb.c linux-2.6.25.4/drivers/video/vesafb.c |
13462 | --- linux-2.6.25.4/drivers/video/vesafb.c 2008-05-15 11:00:12.000000000 -0400 | |
13463 | +++ linux-2.6.25.4/drivers/video/vesafb.c 2008-05-18 13:33:16.000000000 -0400 | |
83a957c9 | 13464 | @@ -9,6 +9,7 @@ |
13465 | */ | |
13466 | ||
13467 | #include <linux/module.h> | |
13468 | +#include <linux/moduleloader.h> | |
13469 | #include <linux/kernel.h> | |
13470 | #include <linux/errno.h> | |
13471 | #include <linux/string.h> | |
da5b3fc8 | 13472 | @@ -53,8 +54,8 @@ static int vram_remap __initdata; /* |
13473 | static int vram_total __initdata; /* Set total amount of memory */ | |
13474 | static int pmi_setpal __read_mostly = 1; /* pmi for palette changes ??? */ | |
13475 | static int ypan __read_mostly; /* 0..nothing, 1..ypan, 2..ywrap */ | |
13476 | -static void (*pmi_start)(void) __read_mostly; | |
13477 | -static void (*pmi_pal) (void) __read_mostly; | |
13478 | +static void (*pmi_start)(void) __read_only; | |
13479 | +static void (*pmi_pal) (void) __read_only; | |
13480 | static int depth __read_mostly; | |
13481 | static int vga_compat __read_mostly; | |
13482 | /* --------------------------------------------------------------------- */ | |
83a957c9 | 13483 | @@ -224,6 +225,7 @@ static int __init vesafb_probe(struct pl |
13484 | unsigned int size_vmode; | |
13485 | unsigned int size_remap; | |
13486 | unsigned int size_total; | |
13487 | + void *pmi_code = NULL; | |
13488 | ||
13489 | if (screen_info.orig_video_isVGA != VIDEO_TYPE_VLFB) | |
13490 | return -ENODEV; | |
13491 | @@ -266,10 +268,6 @@ static int __init vesafb_probe(struct pl | |
50425a20 | 13492 | size_remap = size_total; |
13493 | vesafb_fix.smem_len = size_remap; | |
13494 | ||
13495 | -#ifndef __i386__ | |
83a957c9 | 13496 | - screen_info.vesapm_seg = 0; |
13497 | -#endif | |
13498 | - | |
13499 | if (!request_mem_region(vesafb_fix.smem_start, size_total, "vesafb")) { | |
13500 | printk(KERN_WARNING | |
13501 | "vesafb: cannot reserve video memory at 0x%lx\n", | |
13502 | @@ -302,9 +300,21 @@ static int __init vesafb_probe(struct pl | |
13503 | printk(KERN_INFO "vesafb: mode is %dx%dx%d, linelength=%d, pages=%d\n", | |
13504 | vesafb_defined.xres, vesafb_defined.yres, vesafb_defined.bits_per_pixel, vesafb_fix.line_length, screen_info.pages); | |
50425a20 | 13505 | |
83a957c9 | 13506 | +#ifdef __i386__ |
13507 | + | |
da5b3fc8 | 13508 | +#if defined(CONFIG_MODULES) && defined(CONFIG_PAX_KERNEXEC) |
83a957c9 | 13509 | + pmi_code = module_alloc_exec(screen_info.vesapm_size); |
13510 | + if (!pmi_code) | |
da5b3fc8 | 13511 | +#elif !defined(CONFIG_PAX_KERNEXEC) |
83a957c9 | 13512 | + if (0) |
13513 | +#endif | |
13514 | + | |
13515 | +#endif | |
13516 | + screen_info.vesapm_seg = 0; | |
13517 | + | |
13518 | if (screen_info.vesapm_seg) { | |
13519 | - printk(KERN_INFO "vesafb: protected mode interface info at %04x:%04x\n", | |
13520 | - screen_info.vesapm_seg,screen_info.vesapm_off); | |
13521 | + printk(KERN_INFO "vesafb: protected mode interface info at %04x:%04x %04x bytes\n", | |
13522 | + screen_info.vesapm_seg,screen_info.vesapm_off,screen_info.vesapm_size); | |
13523 | } | |
13524 | ||
13525 | if (screen_info.vesapm_seg < 0xc000) | |
13526 | @@ -312,9 +322,29 @@ static int __init vesafb_probe(struct pl | |
13527 | ||
13528 | if (ypan || pmi_setpal) { | |
13529 | unsigned short *pmi_base; | |
13530 | - pmi_base = (unsigned short*)phys_to_virt(((unsigned long)screen_info.vesapm_seg << 4) + screen_info.vesapm_off); | |
13531 | - pmi_start = (void*)((char*)pmi_base + pmi_base[1]); | |
13532 | - pmi_pal = (void*)((char*)pmi_base + pmi_base[2]); | |
13533 | + | |
da5b3fc8 | 13534 | +#if defined(CONFIG_MODULES) && defined(CONFIG_PAX_KERNEXEC) |
83a957c9 | 13535 | + unsigned long cr0; |
13536 | +#endif | |
13537 | + | |
13538 | + pmi_base = (unsigned short*)phys_to_virt(((unsigned long)screen_info.vesapm_seg << 4) + screen_info.vesapm_off); | |
13539 | + | |
da5b3fc8 | 13540 | +#if defined(CONFIG_MODULES) && defined(CONFIG_PAX_KERNEXEC) |
83a957c9 | 13541 | + pax_open_kernel(cr0); |
13542 | + memcpy(pmi_code, pmi_base, screen_info.vesapm_size); | |
83a957c9 | 13543 | +#else |
13544 | + pmi_code = pmi_base; | |
13545 | +#endif | |
13546 | + | |
13547 | + pmi_start = (void*)((char*)pmi_code + pmi_base[1]); | |
13548 | + pmi_pal = (void*)((char*)pmi_code + pmi_base[2]); | |
13549 | + | |
da5b3fc8 | 13550 | +#if defined(CONFIG_MODULES) && defined(CONFIG_PAX_KERNEXEC) |
13551 | + pmi_start = ktva_ktla(pmi_start); | |
13552 | + pmi_pal = ktva_ktla(pmi_pal); | |
13553 | + pax_close_kernel(cr0); | |
83a957c9 | 13554 | +#endif |
13555 | + | |
13556 | printk(KERN_INFO "vesafb: pmi: set display start = %p, set palette = %p\n",pmi_start,pmi_pal); | |
13557 | if (pmi_base[3]) { | |
13558 | printk(KERN_INFO "vesafb: pmi: ports = "); | |
13559 | @@ -456,6 +486,11 @@ static int __init vesafb_probe(struct pl | |
13560 | info->node, info->fix.id); | |
13561 | return 0; | |
13562 | err: | |
13563 | + | |
da5b3fc8 | 13564 | +#if defined(CONFIG_MODULES) && defined(CONFIG_PAX_KERNEXEC) |
83a957c9 | 13565 | + module_free_exec(NULL, pmi_code); |
13566 | +#endif | |
13567 | + | |
13568 | if (info->screen_base) | |
13569 | iounmap(info->screen_base); | |
13570 | framebuffer_release(info); | |
4dee9bd5 | 13571 | diff -urNp linux-2.6.25.4/fs/9p/vfs_inode.c linux-2.6.25.4/fs/9p/vfs_inode.c |
13572 | --- linux-2.6.25.4/fs/9p/vfs_inode.c 2008-05-15 11:00:12.000000000 -0400 | |
13573 | +++ linux-2.6.25.4/fs/9p/vfs_inode.c 2008-05-18 13:33:16.000000000 -0400 | |
13574 | @@ -1001,7 +1001,7 @@ static void *v9fs_vfs_follow_link(struct | |
da5b3fc8 | 13575 | |
13576 | static void v9fs_vfs_put_link(struct dentry *dentry, struct nameidata *nd, void *p) | |
13577 | { | |
13578 | - char *s = nd_get_link(nd); | |
13579 | + const char *s = nd_get_link(nd); | |
13580 | ||
13581 | P9_DPRINTK(P9_DEBUG_VFS, " %s %s\n", dentry->d_name.name, s); | |
13582 | if (!IS_ERR(s)) | |
4dee9bd5 | 13583 | diff -urNp linux-2.6.25.4/fs/aio.c linux-2.6.25.4/fs/aio.c |
13584 | --- linux-2.6.25.4/fs/aio.c 2008-05-15 11:00:12.000000000 -0400 | |
13585 | +++ linux-2.6.25.4/fs/aio.c 2008-05-18 13:33:16.000000000 -0400 | |
da5b3fc8 | 13586 | @@ -114,7 +114,7 @@ static int aio_setup_ring(struct kioctx |
13587 | size += sizeof(struct io_event) * nr_events; | |
13588 | nr_pages = (size + PAGE_SIZE-1) >> PAGE_SHIFT; | |
13589 | ||
13590 | - if (nr_pages < 0) | |
13591 | + if (nr_pages <= 0) | |
13592 | return -EINVAL; | |
13593 | ||
13594 | nr_events = (PAGE_SIZE * nr_pages - sizeof(struct aio_ring)) / sizeof(struct io_event); | |
4dee9bd5 | 13595 | diff -urNp linux-2.6.25.4/fs/autofs4/symlink.c linux-2.6.25.4/fs/autofs4/symlink.c |
13596 | --- linux-2.6.25.4/fs/autofs4/symlink.c 2008-05-15 11:00:12.000000000 -0400 | |
13597 | +++ linux-2.6.25.4/fs/autofs4/symlink.c 2008-05-18 13:33:16.000000000 -0400 | |
da5b3fc8 | 13598 | @@ -15,7 +15,7 @@ |
13599 | static void *autofs4_follow_link(struct dentry *dentry, struct nameidata *nd) | |
13600 | { | |
13601 | struct autofs_info *ino = autofs4_dentry_ino(dentry); | |
13602 | - nd_set_link(nd, (char *)ino->u.symlink); | |
13603 | + nd_set_link(nd, ino->u.symlink); | |
13604 | return NULL; | |
13605 | } | |
13606 | ||
4dee9bd5 | 13607 | diff -urNp linux-2.6.25.4/fs/befs/linuxvfs.c linux-2.6.25.4/fs/befs/linuxvfs.c |
13608 | --- linux-2.6.25.4/fs/befs/linuxvfs.c 2008-05-15 11:00:12.000000000 -0400 | |
13609 | +++ linux-2.6.25.4/fs/befs/linuxvfs.c 2008-05-18 13:33:16.000000000 -0400 | |
13610 | @@ -489,7 +489,7 @@ static void befs_put_link(struct dentry | |
da5b3fc8 | 13611 | { |
13612 | befs_inode_info *befs_ino = BEFS_I(dentry->d_inode); | |
13613 | if (befs_ino->i_flags & BEFS_LONG_SYMLINK) { | |
13614 | - char *p = nd_get_link(nd); | |
13615 | + const char *p = nd_get_link(nd); | |
13616 | if (!IS_ERR(p)) | |
13617 | kfree(p); | |
13618 | } | |
4dee9bd5 | 13619 | diff -urNp linux-2.6.25.4/fs/binfmt_aout.c linux-2.6.25.4/fs/binfmt_aout.c |
13620 | --- linux-2.6.25.4/fs/binfmt_aout.c 2008-05-15 11:00:12.000000000 -0400 | |
13621 | +++ linux-2.6.25.4/fs/binfmt_aout.c 2008-05-18 13:33:16.000000000 -0400 | |
da5b3fc8 | 13622 | @@ -24,6 +24,7 @@ |
50425a20 | 13623 | #include <linux/personality.h> |
13624 | #include <linux/init.h> | |
b79bc584 | 13625 | #include <linux/vs_memory.h> |
50425a20 | 13626 | +#include <linux/grsecurity.h> |
13627 | ||
13628 | #include <asm/system.h> | |
13629 | #include <asm/uaccess.h> | |
4dee9bd5 | 13630 | @@ -124,18 +125,22 @@ static int aout_core_dump(long signr, st |
50425a20 | 13631 | /* If the size of the dump file exceeds the rlimit, then see what would happen |
13632 | if we wrote the stack, but not the data area. */ | |
13633 | #ifdef __sparc__ | |
da5b3fc8 | 13634 | + gr_learn_resource(current, RLIMIT_CORE, dump.u_dsize + dump.u_ssize, 1); |
13635 | if ((dump.u_dsize + dump.u_ssize) > limit) | |
50425a20 | 13636 | dump.u_dsize = 0; |
13637 | #else | |
da5b3fc8 | 13638 | + gr_learn_resource(current, RLIMIT_CORE, (dump.u_dsize + dump.u_ssize+1) * PAGE_SIZE, 1); |
13639 | if ((dump.u_dsize + dump.u_ssize+1) * PAGE_SIZE > limit) | |
50425a20 | 13640 | dump.u_dsize = 0; |
da5b3fc8 | 13641 | #endif |
50425a20 | 13642 | |
13643 | /* Make sure we have enough room to write the stack and data areas. */ | |
13644 | #ifdef __sparc__ | |
13645 | + gr_learn_resource(current, RLIMIT_CORE, dump.u_ssize, 1); | |
da5b3fc8 | 13646 | if (dump.u_ssize > limit) |
50425a20 | 13647 | dump.u_ssize = 0; |
13648 | #else | |
da5b3fc8 | 13649 | + gr_learn_resource(current, RLIMIT_CORE, (dump.u_ssize + 1) * PAGE_SIZE, 1); |
13650 | if ((dump.u_ssize + 1) * PAGE_SIZE > limit) | |
50425a20 | 13651 | dump.u_ssize = 0; |
da5b3fc8 | 13652 | #endif |
4dee9bd5 | 13653 | @@ -291,6 +296,8 @@ static int load_aout_binary(struct linux |
50425a20 | 13654 | rlim = current->signal->rlim[RLIMIT_DATA].rlim_cur; |
13655 | if (rlim >= RLIM_INFINITY) | |
13656 | rlim = ~0; | |
13657 | + | |
13658 | + gr_learn_resource(current, RLIMIT_DATA, ex.a_data + ex.a_bss, 1); | |
13659 | if (ex.a_data + ex.a_bss > rlim) | |
13660 | return -ENOMEM; | |
13661 | ||
4dee9bd5 | 13662 | @@ -322,6 +329,28 @@ static int load_aout_binary(struct linux |
da5b3fc8 | 13663 | |
50425a20 | 13664 | compute_creds(bprm); |
13665 | current->flags &= ~PF_FORKNOEXEC; | |
13666 | + | |
13667 | +#if defined(CONFIG_PAX_NOEXEC) || defined(CONFIG_PAX_ASLR) | |
13668 | + current->mm->pax_flags = 0UL; | |
13669 | +#endif | |
13670 | + | |
13671 | +#ifdef CONFIG_PAX_PAGEEXEC | |
13672 | + if (!(N_FLAGS(ex) & F_PAX_PAGEEXEC)) { | |
13673 | + current->mm->pax_flags |= MF_PAX_PAGEEXEC; | |
13674 | + | |
13675 | +#ifdef CONFIG_PAX_EMUTRAMP | |
13676 | + if (N_FLAGS(ex) & F_PAX_EMUTRAMP) | |
13677 | + current->mm->pax_flags |= MF_PAX_EMUTRAMP; | |
13678 | +#endif | |
13679 | + | |
13680 | +#ifdef CONFIG_PAX_MPROTECT | |
13681 | + if (!(N_FLAGS(ex) & F_PAX_MPROTECT)) | |
13682 | + current->mm->pax_flags |= MF_PAX_MPROTECT; | |
13683 | +#endif | |
13684 | + | |
13685 | + } | |
13686 | +#endif | |
13687 | + | |
13688 | #ifdef __sparc__ | |
13689 | if (N_MAGIC(ex) == NMAGIC) { | |
13690 | loff_t pos = fd_offset; | |
4dee9bd5 | 13691 | @@ -417,7 +446,7 @@ static int load_aout_binary(struct linux |
50425a20 | 13692 | |
13693 | down_write(¤t->mm->mmap_sem); | |
13694 | error = do_mmap(bprm->file, N_DATADDR(ex), ex.a_data, | |
13695 | - PROT_READ | PROT_WRITE | PROT_EXEC, | |
13696 | + PROT_READ | PROT_WRITE, | |
13697 | MAP_FIXED | MAP_PRIVATE | MAP_DENYWRITE | MAP_EXECUTABLE, | |
13698 | fd_offset + ex.a_text); | |
13699 | up_write(¤t->mm->mmap_sem); | |
4dee9bd5 | 13700 | diff -urNp linux-2.6.25.4/fs/binfmt_elf.c linux-2.6.25.4/fs/binfmt_elf.c |
13701 | --- linux-2.6.25.4/fs/binfmt_elf.c 2008-05-15 11:00:12.000000000 -0400 | |
13702 | +++ linux-2.6.25.4/fs/binfmt_elf.c 2008-05-18 13:33:16.000000000 -0400 | |
b2ee8b1e | 13703 | @@ -39,10 +39,16 @@ |
50425a20 | 13704 | #include <linux/elf.h> |
8a4b4a5e | 13705 | #include <linux/utsname.h> |
b79bc584 | 13706 | #include <linux/vs_memory.h> |
50425a20 | 13707 | +#include <linux/grsecurity.h> |
13708 | + | |
13709 | #include <asm/uaccess.h> | |
13710 | #include <asm/param.h> | |
13711 | #include <asm/page.h> | |
13712 | ||
13713 | +#ifdef CONFIG_PAX_SEGMEXEC | |
13714 | +#include <asm/desc.h> | |
13715 | +#endif | |
13716 | + | |
13717 | static int load_elf_binary(struct linux_binprm *bprm, struct pt_regs *regs); | |
13718 | static int load_elf_library(struct file *); | |
4dee9bd5 | 13719 | static unsigned long elf_map(struct file *, unsigned long, struct elf_phdr *, |
13720 | @@ -85,6 +91,8 @@ static struct linux_binfmt elf_format = | |
50425a20 | 13721 | |
13722 | static int set_brk(unsigned long start, unsigned long end) | |
13723 | { | |
13724 | + unsigned long e = end; | |
13725 | + | |
13726 | start = ELF_PAGEALIGN(start); | |
13727 | end = ELF_PAGEALIGN(end); | |
13728 | if (end > start) { | |
4dee9bd5 | 13729 | @@ -95,7 +103,7 @@ static int set_brk(unsigned long start, |
50425a20 | 13730 | if (BAD_ADDR(addr)) |
13731 | return addr; | |
13732 | } | |
13733 | - current->mm->start_brk = current->mm->brk = end; | |
13734 | + current->mm->start_brk = current->mm->brk = e; | |
13735 | return 0; | |
13736 | } | |
13737 | ||
4dee9bd5 | 13738 | @@ -352,10 +360,10 @@ static unsigned long load_elf_interp(str |
50425a20 | 13739 | { |
13740 | struct elf_phdr *elf_phdata; | |
13741 | struct elf_phdr *eppnt; | |
13742 | - unsigned long load_addr = 0; | |
4dee9bd5 | 13743 | + unsigned long load_addr = 0, pax_task_size = TASK_SIZE; |
13744 | int load_addr_set = 0; | |
50425a20 | 13745 | unsigned long last_bss = 0, elf_bss = 0; |
13746 | - unsigned long error = ~0UL; | |
13747 | + unsigned long error = -EINVAL; | |
4dee9bd5 | 13748 | unsigned long total_size; |
50425a20 | 13749 | int retval, i, size; |
13750 | ||
4dee9bd5 | 13751 | @@ -401,6 +409,11 @@ static unsigned long load_elf_interp(str |
50425a20 | 13752 | goto out_close; |
13753 | } | |
13754 | ||
13755 | +#ifdef CONFIG_PAX_SEGMEXEC | |
13756 | + if (current->mm->pax_flags & MF_PAX_SEGMEXEC) | |
b7f09679 | 13757 | + pax_task_size = SEGMEXEC_TASK_SIZE; |
50425a20 | 13758 | +#endif |
13759 | + | |
13760 | eppnt = elf_phdata; | |
50425a20 | 13761 | for (i = 0; i < interp_elf_ex->e_phnum; i++, eppnt++) { |
4dee9bd5 | 13762 | if (eppnt->p_type == PT_LOAD) { |
13763 | @@ -444,8 +457,8 @@ static unsigned long load_elf_interp(str | |
13764 | k = load_addr + eppnt->p_vaddr; | |
13765 | if (BAD_ADDR(k) || | |
13766 | eppnt->p_filesz > eppnt->p_memsz || | |
50425a20 | 13767 | - eppnt->p_memsz > TASK_SIZE || |
13768 | - TASK_SIZE - eppnt->p_memsz < k) { | |
4dee9bd5 | 13769 | + eppnt->p_memsz > pax_task_size || |
13770 | + pax_task_size - eppnt->p_memsz < k) { | |
13771 | error = -ENOMEM; | |
13772 | goto out_close; | |
13773 | } | |
13774 | @@ -499,6 +512,177 @@ out: | |
13775 | return error; | |
50425a20 | 13776 | } |
13777 | ||
13778 | +#if (defined(CONFIG_PAX_EI_PAX) || defined(CONFIG_PAX_PT_PAX_FLAGS)) && defined(CONFIG_PAX_SOFTMODE) | |
13779 | +static unsigned long pax_parse_softmode(const struct elf_phdr * const elf_phdata) | |
13780 | +{ | |
13781 | + unsigned long pax_flags = 0UL; | |
13782 | + | |
13783 | +#ifdef CONFIG_PAX_PAGEEXEC | |
13784 | + if (elf_phdata->p_flags & PF_PAGEEXEC) | |
13785 | + pax_flags |= MF_PAX_PAGEEXEC; | |
13786 | +#endif | |
13787 | + | |
13788 | +#ifdef CONFIG_PAX_SEGMEXEC | |
13789 | + if (elf_phdata->p_flags & PF_SEGMEXEC) | |
13790 | + pax_flags |= MF_PAX_SEGMEXEC; | |
13791 | +#endif | |
13792 | + | |
8a4b4a5e | 13793 | +#if defined(CONFIG_PAX_PAGEEXEC) && defined(CONFIG_PAX_SEGMEXEC) |
13794 | + if ((pax_flags & (MF_PAX_PAGEEXEC | MF_PAX_SEGMEXEC)) == (MF_PAX_PAGEEXEC | MF_PAX_SEGMEXEC)) { | |
13795 | + if (nx_enabled) | |
13796 | + pax_flags &= ~MF_PAX_SEGMEXEC; | |
13797 | + else | |
13798 | + pax_flags &= ~MF_PAX_PAGEEXEC; | |
13799 | + } | |
50425a20 | 13800 | +#endif |
13801 | + | |
13802 | +#ifdef CONFIG_PAX_EMUTRAMP | |
13803 | + if (elf_phdata->p_flags & PF_EMUTRAMP) | |
13804 | + pax_flags |= MF_PAX_EMUTRAMP; | |
13805 | +#endif | |
13806 | + | |
13807 | +#ifdef CONFIG_PAX_MPROTECT | |
13808 | + if (elf_phdata->p_flags & PF_MPROTECT) | |
13809 | + pax_flags |= MF_PAX_MPROTECT; | |
13810 | +#endif | |
13811 | + | |
13812 | +#if defined(CONFIG_PAX_RANDMMAP) || defined(CONFIG_PAX_RANDUSTACK) | |
13813 | + if (randomize_va_space && (elf_phdata->p_flags & PF_RANDMMAP)) | |
13814 | + pax_flags |= MF_PAX_RANDMMAP; | |
13815 | +#endif | |
13816 | + | |
13817 | + return pax_flags; | |
13818 | +} | |
13819 | +#endif | |
13820 | + | |
13821 | +#ifdef CONFIG_PAX_PT_PAX_FLAGS | |
13822 | +static unsigned long pax_parse_hardmode(const struct elf_phdr * const elf_phdata) | |
13823 | +{ | |
13824 | + unsigned long pax_flags = 0UL; | |
13825 | + | |
13826 | +#ifdef CONFIG_PAX_PAGEEXEC | |
13827 | + if (!(elf_phdata->p_flags & PF_NOPAGEEXEC)) | |
13828 | + pax_flags |= MF_PAX_PAGEEXEC; | |
13829 | +#endif | |
13830 | + | |
13831 | +#ifdef CONFIG_PAX_SEGMEXEC | |
13832 | + if (!(elf_phdata->p_flags & PF_NOSEGMEXEC)) | |
13833 | + pax_flags |= MF_PAX_SEGMEXEC; | |
13834 | +#endif | |
13835 | + | |
8a4b4a5e | 13836 | +#if defined(CONFIG_PAX_PAGEEXEC) && defined(CONFIG_PAX_SEGMEXEC) |
13837 | + if ((pax_flags & (MF_PAX_PAGEEXEC | MF_PAX_SEGMEXEC)) == (MF_PAX_PAGEEXEC | MF_PAX_SEGMEXEC)) { | |
13838 | + if (nx_enabled) | |
13839 | + pax_flags &= ~MF_PAX_SEGMEXEC; | |
13840 | + else | |
13841 | + pax_flags &= ~MF_PAX_PAGEEXEC; | |
13842 | + } | |
50425a20 | 13843 | +#endif |
13844 | + | |
13845 | +#ifdef CONFIG_PAX_EMUTRAMP | |
13846 | + if (!(elf_phdata->p_flags & PF_NOEMUTRAMP)) | |
13847 | + pax_flags |= MF_PAX_EMUTRAMP; | |
13848 | +#endif | |
13849 | + | |
13850 | +#ifdef CONFIG_PAX_MPROTECT | |
13851 | + if (!(elf_phdata->p_flags & PF_NOMPROTECT)) | |
13852 | + pax_flags |= MF_PAX_MPROTECT; | |
13853 | +#endif | |
13854 | + | |
13855 | +#if defined(CONFIG_PAX_RANDMMAP) || defined(CONFIG_PAX_RANDUSTACK) | |
13856 | + if (randomize_va_space && !(elf_phdata->p_flags & PF_NORANDMMAP)) | |
13857 | + pax_flags |= MF_PAX_RANDMMAP; | |
13858 | +#endif | |
13859 | + | |
13860 | + return pax_flags; | |
13861 | +} | |
13862 | +#endif | |
13863 | + | |
13864 | +#ifdef CONFIG_PAX_EI_PAX | |
13865 | +static unsigned long pax_parse_ei_pax(const struct elfhdr * const elf_ex) | |
13866 | +{ | |
13867 | + unsigned long pax_flags = 0UL; | |
13868 | + | |
13869 | +#ifdef CONFIG_PAX_PAGEEXEC | |
13870 | + if (!(elf_ex->e_ident[EI_PAX] & EF_PAX_PAGEEXEC)) | |
13871 | + pax_flags |= MF_PAX_PAGEEXEC; | |
13872 | +#endif | |
13873 | + | |
13874 | +#ifdef CONFIG_PAX_SEGMEXEC | |
13875 | + if (!(elf_ex->e_ident[EI_PAX] & EF_PAX_SEGMEXEC)) | |
13876 | + pax_flags |= MF_PAX_SEGMEXEC; | |
13877 | +#endif | |
13878 | + | |
8a4b4a5e | 13879 | +#if defined(CONFIG_PAX_PAGEEXEC) && defined(CONFIG_PAX_SEGMEXEC) |
13880 | + if ((pax_flags & (MF_PAX_PAGEEXEC | MF_PAX_SEGMEXEC)) == (MF_PAX_PAGEEXEC | MF_PAX_SEGMEXEC)) { | |
13881 | + if (nx_enabled) | |
13882 | + pax_flags &= ~MF_PAX_SEGMEXEC; | |
13883 | + else | |
13884 | + pax_flags &= ~MF_PAX_PAGEEXEC; | |
13885 | + } | |
50425a20 | 13886 | +#endif |
13887 | + | |
13888 | +#ifdef CONFIG_PAX_EMUTRAMP | |
13889 | + if ((pax_flags & (MF_PAX_PAGEEXEC | MF_PAX_SEGMEXEC)) && (elf_ex->e_ident[EI_PAX] & EF_PAX_EMUTRAMP)) | |
13890 | + pax_flags |= MF_PAX_EMUTRAMP; | |
13891 | +#endif | |
13892 | + | |
13893 | +#ifdef CONFIG_PAX_MPROTECT | |
13894 | + if ((pax_flags & (MF_PAX_PAGEEXEC | MF_PAX_SEGMEXEC)) && !(elf_ex->e_ident[EI_PAX] & EF_PAX_MPROTECT)) | |
13895 | + pax_flags |= MF_PAX_MPROTECT; | |
13896 | +#endif | |
13897 | + | |
13898 | +#ifdef CONFIG_PAX_ASLR | |
13899 | + if (randomize_va_space && !(elf_ex->e_ident[EI_PAX] & EF_PAX_RANDMMAP)) | |
13900 | + pax_flags |= MF_PAX_RANDMMAP; | |
13901 | +#endif | |
13902 | + | |
13903 | + return pax_flags; | |
13904 | +} | |
13905 | +#endif | |
13906 | + | |
13907 | +#if defined(CONFIG_PAX_EI_PAX) || defined(CONFIG_PAX_PT_PAX_FLAGS) | |
13908 | +static long pax_parse_elf_flags(const struct elfhdr * const elf_ex, const struct elf_phdr * const elf_phdata) | |
13909 | +{ | |
13910 | + unsigned long pax_flags = 0UL; | |
13911 | + | |
13912 | +#ifdef CONFIG_PAX_PT_PAX_FLAGS | |
13913 | + unsigned long i; | |
13914 | +#endif | |
13915 | + | |
13916 | +#ifdef CONFIG_PAX_EI_PAX | |
13917 | + pax_flags = pax_parse_ei_pax(elf_ex); | |
13918 | +#endif | |
13919 | + | |
13920 | +#ifdef CONFIG_PAX_PT_PAX_FLAGS | |
13921 | + for (i = 0UL; i < elf_ex->e_phnum; i++) | |
13922 | + if (elf_phdata[i].p_type == PT_PAX_FLAGS) { | |
13923 | + if (((elf_phdata[i].p_flags & PF_PAGEEXEC) && (elf_phdata[i].p_flags & PF_NOPAGEEXEC)) || | |
13924 | + ((elf_phdata[i].p_flags & PF_SEGMEXEC) && (elf_phdata[i].p_flags & PF_NOSEGMEXEC)) || | |
13925 | + ((elf_phdata[i].p_flags & PF_EMUTRAMP) && (elf_phdata[i].p_flags & PF_NOEMUTRAMP)) || | |
13926 | + ((elf_phdata[i].p_flags & PF_MPROTECT) && (elf_phdata[i].p_flags & PF_NOMPROTECT)) || | |
13927 | + ((elf_phdata[i].p_flags & PF_RANDMMAP) && (elf_phdata[i].p_flags & PF_NORANDMMAP))) | |
13928 | + return -EINVAL; | |
13929 | + | |
13930 | +#ifdef CONFIG_PAX_SOFTMODE | |
13931 | + if (pax_softmode) | |
13932 | + pax_flags = pax_parse_softmode(&elf_phdata[i]); | |
13933 | + else | |
13934 | +#endif | |
13935 | + | |
13936 | + pax_flags = pax_parse_hardmode(&elf_phdata[i]); | |
13937 | + break; | |
13938 | + } | |
13939 | +#endif | |
13940 | + | |
13941 | + if (0 > pax_check_flags(&pax_flags)) | |
13942 | + return -EINVAL; | |
13943 | + | |
13944 | + current->mm->pax_flags = pax_flags; | |
13945 | + return 0; | |
13946 | +} | |
13947 | +#endif | |
13948 | + | |
13949 | /* | |
13950 | * These are the functions used to load ELF style executables and shared | |
13951 | * libraries. There is no binary dependent code anywhere else. | |
b43ccab8 | 13952 | @@ -515,6 +697,11 @@ static unsigned long rando |
13953 | { | |
13954 | unsigned int random_variable = 0; | |
13955 | ||
13956 | +#ifdef CONFIG_PAX_RANDUSTACK | |
13957 | + if (randomize_va_space) | |
13958 | + return stack_top - current->mm->delta_stack; | |
13959 | +#endif | |
13960 | + | |
13961 | if ((current->flags & PF_RANDOMIZE) && | |
13962 | !(current->personality & ADDR_NO_RANDOMIZE)) { | |
13963 | random_variable = get_random_int() & STACK_RND_MASK; | |
4dee9bd5 | 13964 | @@ -533,7 +717,7 @@ static int load_elf_binary(struct linux_ |
13965 | unsigned long load_addr = 0, load_bias = 0; | |
13966 | int load_addr_set = 0; | |
50425a20 | 13967 | char * elf_interpreter = NULL; |
50425a20 | 13968 | - unsigned long error; |
13969 | + unsigned long error = 0; | |
13970 | struct elf_phdr *elf_ppnt, *elf_phdata; | |
13971 | unsigned long elf_bss, elf_brk; | |
13972 | int elf_exec_fileno; | |
4dee9bd5 | 13973 | @@ -545,12 +729,12 @@ static int load_elf_binary(struct linux_ |
13974 | unsigned long reloc_func_desc = 0; | |
8a4b4a5e | 13975 | struct files_struct *files; |
13976 | int executable_stack = EXSTACK_DEFAULT; | |
13977 | - unsigned long def_flags = 0; | |
13978 | struct { | |
13979 | struct elfhdr elf_ex; | |
50425a20 | 13980 | struct elfhdr interp_elf_ex; |
13981 | struct exec interp_ex; | |
13982 | } *loc; | |
b7f09679 | 13983 | + unsigned long pax_task_size = TASK_SIZE; |
50425a20 | 13984 | |
13985 | loc = kmalloc(sizeof(*loc), GFP_KERNEL); | |
13986 | if (!loc) { | |
4dee9bd5 | 13987 | @@ -736,7 +920,73 @@ static int load_elf_binary(struct linux_ |
da5b3fc8 | 13988 | |
13989 | /* OK, This is the point of no return */ | |
50425a20 | 13990 | current->flags &= ~PF_FORKNOEXEC; |
8a4b4a5e | 13991 | - current->mm->def_flags = def_flags; |
50425a20 | 13992 | + |
13993 | +#if defined(CONFIG_PAX_NOEXEC) || defined(CONFIG_PAX_ASLR) | |
13994 | + current->mm->pax_flags = 0UL; | |
13995 | +#endif | |
13996 | + | |
13997 | +#ifdef CONFIG_PAX_DLRESOLVE | |
13998 | + current->mm->call_dl_resolve = 0UL; | |
13999 | +#endif | |
14000 | + | |
14001 | +#if defined(CONFIG_PPC32) && defined(CONFIG_PAX_EMUSIGRT) | |
14002 | + current->mm->call_syscall = 0UL; | |
14003 | +#endif | |
14004 | + | |
14005 | +#ifdef CONFIG_PAX_ASLR | |
14006 | + current->mm->delta_mmap = 0UL; | |
50425a20 | 14007 | + current->mm->delta_stack = 0UL; |
14008 | +#endif | |
14009 | + | |
8a4b4a5e | 14010 | + current->mm->def_flags = 0; |
14011 | + | |
50425a20 | 14012 | +#if defined(CONFIG_PAX_EI_PAX) || defined(CONFIG_PAX_PT_PAX_FLAGS) |
14013 | + if (0 > pax_parse_elf_flags(&loc->elf_ex, elf_phdata)) { | |
14014 | + send_sig(SIGKILL, current, 0); | |
14015 | + goto out_free_dentry; | |
14016 | + } | |
14017 | +#endif | |
14018 | + | |
14019 | +#ifdef CONFIG_PAX_HAVE_ACL_FLAGS | |
14020 | + pax_set_initial_flags(bprm); | |
14021 | +#elif defined(CONFIG_PAX_HOOK_ACL_FLAGS) | |
14022 | + if (pax_set_initial_flags_func) | |
14023 | + (pax_set_initial_flags_func)(bprm); | |
14024 | +#endif | |
14025 | + | |
14026 | +#ifdef CONFIG_ARCH_TRACK_EXEC_LIMIT | |
8a4b4a5e | 14027 | + if ((current->mm->pax_flags & MF_PAX_PAGEEXEC) && !nx_enabled) { |
50425a20 | 14028 | + current->mm->context.user_cs_limit = PAGE_SIZE; |
8a4b4a5e | 14029 | + current->mm->def_flags |= VM_PAGEEXEC; |
14030 | + } | |
50425a20 | 14031 | +#endif |
14032 | + | |
14033 | +#ifdef CONFIG_PAX_SEGMEXEC | |
14034 | + if (current->mm->pax_flags & MF_PAX_SEGMEXEC) { | |
14035 | + current->mm->context.user_cs_base = SEGMEXEC_TASK_SIZE; | |
8a4b4a5e | 14036 | + current->mm->context.user_cs_limit = TASK_SIZE-SEGMEXEC_TASK_SIZE; |
b7f09679 | 14037 | + pax_task_size = SEGMEXEC_TASK_SIZE; |
50425a20 | 14038 | + } |
14039 | +#endif | |
14040 | + | |
14041 | +#if defined(CONFIG_ARCH_TRACK_EXEC_LIMIT) || defined(CONFIG_PAX_SEGMEXEC) | |
14042 | + if (current->mm->pax_flags & (MF_PAX_PAGEEXEC | MF_PAX_SEGMEXEC)) { | |
14043 | + set_user_cs(current->mm->context.user_cs_base, current->mm->context.user_cs_limit, get_cpu()); | |
14044 | + put_cpu_no_resched(); | |
14045 | + } | |
14046 | +#endif | |
14047 | + | |
14048 | +#ifdef CONFIG_PAX_ASLR | |
14049 | + if (current->mm->pax_flags & MF_PAX_RANDMMAP) { | |
8a4b4a5e | 14050 | + current->mm->delta_mmap = (pax_get_random_long() & ((1UL << PAX_DELTA_MMAP_LEN)-1)) << PAGE_SHIFT; |
14051 | + current->mm->delta_stack = (pax_get_random_long() & ((1UL << PAX_DELTA_STACK_LEN)-1)) << PAGE_SHIFT; | |
50425a20 | 14052 | + } |
14053 | +#endif | |
14054 | + | |
14055 | +#if defined(CONFIG_PAX_PAGEEXEC) || defined(CONFIG_PAX_SEGMEXEC) | |
14056 | + if (current->mm->pax_flags & (MF_PAX_PAGEEXEC | MF_PAX_SEGMEXEC)) | |
14057 | + executable_stack = EXSTACK_DEFAULT; | |
14058 | +#endif | |
8a4b4a5e | 14059 | |
50425a20 | 14060 | /* Do this immediately, since STACK_TOP as used in setup_arg_pages |
14061 | may depend on the personality. */ | |
4dee9bd5 | 14062 | @@ -821,6 +1071,20 @@ static int load_elf_binary(struct linux_ |
14063 | #else | |
50425a20 | 14064 | load_bias = ELF_PAGESTART(ELF_ET_DYN_BASE - vaddr); |
4dee9bd5 | 14065 | #endif |
50425a20 | 14066 | + |
14067 | +#ifdef CONFIG_PAX_RANDMMAP | |
14068 | + /* PaX: randomize base address at the default exe base if requested */ | |
8a4b4a5e | 14069 | + if ((current->mm->pax_flags & MF_PAX_RANDMMAP) && elf_interpreter) { |
14070 | +#ifdef CONFIG_SPARC64 | |
14071 | + load_bias = (pax_get_random_long() & ((1UL << PAX_DELTA_MMAP_LEN) - 1)) << (PAGE_SHIFT+1); | |
14072 | +#else | |
14073 | + load_bias = (pax_get_random_long() & ((1UL << PAX_DELTA_MMAP_LEN) - 1)) << PAGE_SHIFT; | |
14074 | +#endif | |
14075 | + load_bias = ELF_PAGESTART(PAX_ELF_ET_DYN_BASE - vaddr + load_bias); | |
50425a20 | 14076 | + elf_flags |= MAP_FIXED; |
14077 | + } | |
14078 | +#endif | |
14079 | + | |
14080 | } | |
14081 | ||
14082 | error = elf_map(bprm->file, load_bias + vaddr, elf_ppnt, | |
4dee9bd5 | 14083 | @@ -853,9 +1117,9 @@ static int load_elf_binary(struct linux_ |
50425a20 | 14084 | * allowed task size. Note that p_filesz must always be |
14085 | * <= p_memsz so it is only necessary to check p_memsz. | |
14086 | */ | |
14087 | - if (BAD_ADDR(k) || elf_ppnt->p_filesz > elf_ppnt->p_memsz || | |
14088 | - elf_ppnt->p_memsz > TASK_SIZE || | |
14089 | - TASK_SIZE - elf_ppnt->p_memsz < k) { | |
b7f09679 | 14090 | + if (k >= pax_task_size || elf_ppnt->p_filesz > elf_ppnt->p_memsz || |
14091 | + elf_ppnt->p_memsz > pax_task_size || | |
14092 | + pax_task_size - elf_ppnt->p_memsz < k) { | |
50425a20 | 14093 | /* set_brk can never work. Avoid overflows. */ |
14094 | send_sig(SIGKILL, current, 0); | |
8a4b4a5e | 14095 | retval = -EINVAL; |
4dee9bd5 | 14096 | @@ -883,6 +1147,11 @@ static int load_elf_binary(struct linux_ |
50425a20 | 14097 | start_data += load_bias; |
14098 | end_data += load_bias; | |
14099 | ||
14100 | +#ifdef CONFIG_PAX_RANDMMAP | |
14101 | + if (current->mm->pax_flags & MF_PAX_RANDMMAP) | |
8a4b4a5e | 14102 | + elf_brk += PAGE_SIZE + ((pax_get_random_long() & ~PAGE_MASK) << 4); |
50425a20 | 14103 | +#endif |
14104 | + | |
14105 | /* Calling set_brk effectively mmaps the pages that we need | |
14106 | * for the bss and break sections. We must do this before | |
14107 | * mapping in the interpreter, to make sure it doesn't wind | |
4dee9bd5 | 14108 | @@ -894,9 +1163,11 @@ static int load_elf_binary(struct linux_ |
8a4b4a5e | 14109 | goto out_free_dentry; |
14110 | } | |
14111 | if (likely(elf_bss != elf_brk) && unlikely(padzero(elf_bss))) { | |
14112 | - send_sig(SIGSEGV, current, 0); | |
14113 | - retval = -EFAULT; /* Nobody gets to see this, but.. */ | |
14114 | - goto out_free_dentry; | |
14115 | + /* | |
14116 | + * This bss-zeroing can fail if the ELF | |
14117 | + * file specifies odd protections. So | |
14118 | + * we don't check the return value | |
14119 | + */ | |
14120 | } | |
14121 | ||
14122 | if (elf_interpreter) { | |
4dee9bd5 | 14123 | @@ -1142,8 +1413,10 @@ static int dump_seek(struct file *file, |
8a4b4a5e | 14124 | unsigned long n = off; |
14125 | if (n > PAGE_SIZE) | |
14126 | n = PAGE_SIZE; | |
14127 | - if (!dump_write(file, buf, n)) | |
14128 | + if (!dump_write(file, buf, n)) { | |
14129 | + free_page((unsigned long)buf); | |
14130 | return 0; | |
14131 | + } | |
14132 | off -= n; | |
14133 | } | |
14134 | free_page((unsigned long)buf); | |
4dee9bd5 | 14135 | @@ -1155,7 +1428,7 @@ static int dump_seek(struct file *file, |
da5b3fc8 | 14136 | * Decide what to dump of a segment, part, all or none. |
50425a20 | 14137 | */ |
da5b3fc8 | 14138 | static unsigned long vma_dump_size(struct vm_area_struct *vma, |
14139 | - unsigned long mm_flags) | |
14140 | + unsigned long mm_flags, long signr) | |
50425a20 | 14141 | { |
14142 | /* The vma can be set up to tell us the answer directly. */ | |
14143 | if (vma->vm_flags & VM_ALWAYSDUMP) | |
4dee9bd5 | 14144 | @@ -1181,7 +1454,7 @@ static unsigned long vma_dump_size(struc |
da5b3fc8 | 14145 | if (vma->vm_file == NULL) |
50425a20 | 14146 | return 0; |
14147 | ||
da5b3fc8 | 14148 | - if (FILTER(MAPPED_PRIVATE)) |
14149 | + if (signr == SIGKILL || FILTER(MAPPED_PRIVATE)) | |
14150 | goto whole; | |
14151 | ||
14152 | /* | |
4dee9bd5 | 14153 | @@ -1267,8 +1540,11 @@ static int writenote(struct memelfnote * |
50425a20 | 14154 | #undef DUMP_WRITE |
14155 | ||
14156 | #define DUMP_WRITE(addr, nr) \ | |
14157 | + do { \ | |
14158 | + gr_learn_resource(current, RLIMIT_CORE, size + (nr), 1); \ | |
14159 | if ((size += (nr)) > limit || !dump_write(file, (addr), (nr))) \ | |
14160 | - goto end_coredump; | |
14161 | + goto end_coredump; \ | |
14162 | + } while (0); | |
14163 | #define DUMP_SEEK(off) \ | |
14164 | if (!dump_seek(file, (off))) \ | |
14165 | goto end_coredump; | |
4dee9bd5 | 14166 | @@ -1985,7 +2261,7 @@ static int elf_core_dump(long signr, str |
50425a20 | 14167 | phdr.p_offset = offset; |
14168 | phdr.p_vaddr = vma->vm_start; | |
14169 | phdr.p_paddr = 0; | |
da5b3fc8 | 14170 | - phdr.p_filesz = vma_dump_size(vma, mm_flags); |
14171 | + phdr.p_filesz = vma_dump_size(vma, mm_flags, signr); | |
14172 | phdr.p_memsz = vma->vm_end - vma->vm_start; | |
50425a20 | 14173 | offset += phdr.p_filesz; |
14174 | phdr.p_flags = vma->vm_flags & VM_READ ? PF_R : 0; | |
4dee9bd5 | 14175 | @@ -2017,7 +2293,7 @@ static int elf_core_dump(long signr, str |
50425a20 | 14176 | unsigned long addr; |
da5b3fc8 | 14177 | unsigned long end; |
50425a20 | 14178 | |
da5b3fc8 | 14179 | - end = vma->vm_start + vma_dump_size(vma, mm_flags); |
14180 | + end = vma->vm_start + vma_dump_size(vma, mm_flags, signr); | |
50425a20 | 14181 | |
da5b3fc8 | 14182 | for (addr = vma->vm_start; addr < end; addr += PAGE_SIZE) { |
14183 | struct page *page; | |
4dee9bd5 | 14184 | @@ -2037,6 +2313,7 @@ static int elf_core_dump(long signr, str |
50425a20 | 14185 | flush_cache_page(vma, addr, |
14186 | page_to_pfn(page)); | |
14187 | kaddr = kmap(page); | |
14188 | + gr_learn_resource(current, RLIMIT_CORE, size + PAGE_SIZE, 1); | |
14189 | if ((size += PAGE_SIZE) > limit || | |
14190 | !dump_write(file, kaddr, | |
14191 | PAGE_SIZE)) { | |
4dee9bd5 | 14192 | diff -urNp linux-2.6.25.4/fs/binfmt_flat.c linux-2.6.25.4/fs/binfmt_flat.c |
14193 | --- linux-2.6.25.4/fs/binfmt_flat.c 2008-05-15 11:00:12.000000000 -0400 | |
14194 | +++ linux-2.6.25.4/fs/binfmt_flat.c 2008-05-18 13:33:16.000000000 -0400 | |
14195 | @@ -560,7 +560,9 @@ static int load_flat_file(struct linux_b | |
50425a20 | 14196 | realdatastart = (unsigned long) -ENOMEM; |
14197 | printk("Unable to allocate RAM for process data, errno %d\n", | |
8a4b4a5e | 14198 | (int)-realdatastart); |
50425a20 | 14199 | + down_write(¤t->mm->mmap_sem); |
14200 | do_munmap(current->mm, textpos, text_len); | |
14201 | + up_write(¤t->mm->mmap_sem); | |
14202 | ret = realdatastart; | |
14203 | goto err; | |
14204 | } | |
4dee9bd5 | 14205 | @@ -582,8 +584,10 @@ static int load_flat_file(struct linux_b |
50425a20 | 14206 | } |
14207 | if (result >= (unsigned long)-4096) { | |
14208 | printk("Unable to read data+bss, errno %d\n", (int)-result); | |
14209 | + down_write(¤t->mm->mmap_sem); | |
14210 | do_munmap(current->mm, textpos, text_len); | |
14211 | do_munmap(current->mm, realdatastart, data_len + extra); | |
14212 | + up_write(¤t->mm->mmap_sem); | |
14213 | ret = result; | |
14214 | goto err; | |
14215 | } | |
4dee9bd5 | 14216 | @@ -656,8 +660,10 @@ static int load_flat_file(struct linux_b |
50425a20 | 14217 | } |
14218 | if (result >= (unsigned long)-4096) { | |
14219 | printk("Unable to read code+data+bss, errno %d\n",(int)-result); | |
14220 | + down_write(¤t->mm->mmap_sem); | |
14221 | do_munmap(current->mm, textpos, text_len + data_len + extra + | |
14222 | MAX_SHARED_LIBS * sizeof(unsigned long)); | |
14223 | + up_write(¤t->mm->mmap_sem); | |
14224 | ret = result; | |
14225 | goto err; | |
14226 | } | |
4dee9bd5 | 14227 | diff -urNp linux-2.6.25.4/fs/binfmt_misc.c linux-2.6.25.4/fs/binfmt_misc.c |
14228 | --- linux-2.6.25.4/fs/binfmt_misc.c 2008-05-15 11:00:12.000000000 -0400 | |
14229 | +++ linux-2.6.25.4/fs/binfmt_misc.c 2008-05-18 13:33:16.000000000 -0400 | |
50425a20 | 14230 | @@ -113,9 +113,11 @@ static int load_misc_binary(struct linux |
14231 | struct files_struct *files = NULL; | |
14232 | ||
14233 | retval = -ENOEXEC; | |
14234 | - if (!enabled) | |
14235 | + if (!enabled || bprm->misc) | |
14236 | goto _ret; | |
14237 | ||
14238 | + bprm->misc++; | |
14239 | + | |
14240 | /* to keep locking time low, we copy the interpreter string */ | |
14241 | read_lock(&entries_lock); | |
14242 | fmt = check_file(bprm); | |
da5b3fc8 | 14243 | @@ -720,7 +722,7 @@ static int bm_fill_super(struct super_bl |
50425a20 | 14244 | static struct tree_descr bm_files[] = { |
8a4b4a5e | 14245 | [2] = {"status", &bm_status_operations, S_IWUSR|S_IRUGO}, |
14246 | [3] = {"register", &bm_register_operations, S_IWUSR}, | |
50425a20 | 14247 | - /* last one */ {""} |
14248 | + /* last one */ {"", NULL, 0} | |
14249 | }; | |
14250 | int err = simple_fill_super(sb, 0x42494e4d, bm_files); | |
14251 | if (!err) | |
4dee9bd5 | 14252 | diff -urNp linux-2.6.25.4/fs/buffer.c linux-2.6.25.4/fs/buffer.c |
14253 | --- linux-2.6.25.4/fs/buffer.c 2008-05-15 11:00:12.000000000 -0400 | |
14254 | +++ linux-2.6.25.4/fs/buffer.c 2008-05-18 13:33:16.000000000 -0400 | |
8a4b4a5e | 14255 | @@ -41,6 +41,7 @@ |
50425a20 | 14256 | #include <linux/bitops.h> |
14257 | #include <linux/mpage.h> | |
14258 | #include <linux/bit_spinlock.h> | |
14259 | +#include <linux/grsecurity.h> | |
14260 | ||
14261 | static int fsync_buffers_list(spinlock_t *lock, struct list_head *list); | |
8a4b4a5e | 14262 | |
4dee9bd5 | 14263 | @@ -2188,6 +2189,7 @@ int generic_cont_expand_simple(struct in |
50425a20 | 14264 | |
14265 | err = -EFBIG; | |
14266 | limit = current->signal->rlim[RLIMIT_FSIZE].rlim_cur; | |
14267 | + gr_learn_resource(current, RLIMIT_FSIZE, (unsigned long) size, 1); | |
14268 | if (limit != RLIM_INFINITY && size > (loff_t)limit) { | |
14269 | send_sig(SIGXFSZ, current, 0); | |
14270 | goto out; | |
4dee9bd5 | 14271 | diff -urNp linux-2.6.25.4/fs/cifs/cifs_uniupr.h linux-2.6.25.4/fs/cifs/cifs_uniupr.h |
14272 | --- linux-2.6.25.4/fs/cifs/cifs_uniupr.h 2008-05-15 11:00:12.000000000 -0400 | |
14273 | +++ linux-2.6.25.4/fs/cifs/cifs_uniupr.h 2008-05-18 13:33:16.000000000 -0400 | |
50425a20 | 14274 | @@ -132,7 +132,7 @@ const struct UniCaseRange CifsUniUpperRa |
14275 | {0x0490, 0x04cc, UniCaseRangeU0490}, | |
14276 | {0x1e00, 0x1ffc, UniCaseRangeU1e00}, | |
14277 | {0xff40, 0xff5a, UniCaseRangeUff40}, | |
14278 | - {0} | |
14279 | + {0, 0, NULL} | |
14280 | }; | |
14281 | #endif | |
14282 | ||
4dee9bd5 | 14283 | diff -urNp linux-2.6.25.4/fs/cifs/link.c linux-2.6.25.4/fs/cifs/link.c |
14284 | --- linux-2.6.25.4/fs/cifs/link.c 2008-05-15 11:00:12.000000000 -0400 | |
14285 | +++ linux-2.6.25.4/fs/cifs/link.c 2008-05-18 13:33:16.000000000 -0400 | |
da5b3fc8 | 14286 | @@ -355,7 +355,7 @@ cifs_readlink(struct dentry *direntry, c |
14287 | ||
14288 | void cifs_put_link(struct dentry *direntry, struct nameidata *nd, void *cookie) | |
14289 | { | |
14290 | - char *p = nd_get_link(nd); | |
14291 | + const char *p = nd_get_link(nd); | |
14292 | if (!IS_ERR(p)) | |
14293 | kfree(p); | |
14294 | } | |
4dee9bd5 | 14295 | diff -urNp linux-2.6.25.4/fs/compat.c linux-2.6.25.4/fs/compat.c |
14296 | --- linux-2.6.25.4/fs/compat.c 2008-05-15 11:00:12.000000000 -0400 | |
14297 | +++ linux-2.6.25.4/fs/compat.c 2008-05-18 13:33:16.000000000 -0400 | |
8a4b4a5e | 14298 | @@ -50,6 +50,7 @@ |
50425a20 | 14299 | #include <linux/poll.h> |
14300 | #include <linux/mm.h> | |
14301 | #include <linux/eventpoll.h> | |
14302 | +#include <linux/grsecurity.h> | |
14303 | ||
8a4b4a5e | 14304 | #include <asm/uaccess.h> |
14305 | #include <asm/mmu_context.h> | |
4dee9bd5 | 14306 | @@ -1293,14 +1294,12 @@ static int compat_copy_strings(int argc, |
da5b3fc8 | 14307 | if (!kmapped_page || kpos != (pos & PAGE_MASK)) { |
14308 | struct page *page; | |
14309 | ||
14310 | -#ifdef CONFIG_STACK_GROWSUP | |
14311 | ret = expand_stack_downwards(bprm->vma, pos); | |
14312 | if (ret < 0) { | |
14313 | /* We've exceed the stack rlimit. */ | |
14314 | ret = -E2BIG; | |
14315 | goto out; | |
14316 | } | |
14317 | -#endif | |
14318 | ret = get_user_pages(current, bprm->mm, pos, | |
14319 | 1, 1, 1, &page, NULL); | |
14320 | if (ret <= 0) { | |
4dee9bd5 | 14321 | @@ -1346,6 +1345,11 @@ int compat_do_execve(char * filename, |
da5b3fc8 | 14322 | compat_uptr_t __user *envp, |
14323 | struct pt_regs * regs) | |
14324 | { | |
50425a20 | 14325 | +#ifdef CONFIG_GRKERNSEC |
14326 | + struct file *old_exec_file; | |
14327 | + struct acl_subject_label *old_acl; | |
14328 | + struct rlimit old_rlim[RLIM_NLIMITS]; | |
14329 | +#endif | |
da5b3fc8 | 14330 | struct linux_binprm *bprm; |
14331 | struct file *file; | |
14332 | int retval; | |
4dee9bd5 | 14333 | @@ -1366,6 +1370,14 @@ int compat_do_execve(char * filename, |
50425a20 | 14334 | bprm->filename = filename; |
14335 | bprm->interp = filename; | |
da5b3fc8 | 14336 | |
50425a20 | 14337 | + gr_learn_resource(current, RLIMIT_NPROC, atomic_read(¤t->user->processes), 1); |
14338 | + retval = -EAGAIN; | |
14339 | + if (gr_handle_nproc()) | |
14340 | + goto out_file; | |
14341 | + retval = -EACCES; | |
14342 | + if (!gr_acl_handle_execve(file->f_dentry, file->f_vfsmnt)) | |
14343 | + goto out_file; | |
14344 | + | |
da5b3fc8 | 14345 | retval = bprm_mm_init(bprm); |
14346 | if (retval) | |
14347 | goto out_file; | |
4dee9bd5 | 14348 | @@ -1399,8 +1411,36 @@ int compat_do_execve(char * filename, |
50425a20 | 14349 | if (retval < 0) |
14350 | goto out; | |
14351 | ||
14352 | + if (!gr_tpe_allow(file)) { | |
14353 | + retval = -EACCES; | |
14354 | + goto out; | |
14355 | + } | |
14356 | + | |
14357 | + if (gr_check_crash_exec(file)) { | |
14358 | + retval = -EACCES; | |
14359 | + goto out; | |
14360 | + } | |
14361 | + | |
14362 | + gr_log_chroot_exec(file->f_dentry, file->f_vfsmnt); | |
14363 | + | |
14364 | + gr_handle_exec_args(bprm, (char __user * __user *)argv); | |
14365 | + | |
14366 | +#ifdef CONFIG_GRKERNSEC | |
14367 | + old_acl = current->acl; | |
14368 | + memcpy(old_rlim, current->signal->rlim, sizeof(old_rlim)); | |
14369 | + old_exec_file = current->exec_file; | |
14370 | + get_file(file); | |
14371 | + current->exec_file = file; | |
14372 | +#endif | |
14373 | + | |
14374 | + gr_set_proc_label(file->f_dentry, file->f_vfsmnt); | |
14375 | + | |
14376 | retval = search_binary_handler(bprm, regs); | |
14377 | if (retval >= 0) { | |
50425a20 | 14378 | +#ifdef CONFIG_GRKERNSEC |
14379 | + if (old_exec_file) | |
14380 | + fput(old_exec_file); | |
14381 | +#endif | |
50425a20 | 14382 | /* execve success */ |
14383 | security_bprm_free(bprm); | |
14384 | acct_update_integrals(current); | |
4dee9bd5 | 14385 | @@ -1408,6 +1448,13 @@ int compat_do_execve(char * filename, |
50425a20 | 14386 | return retval; |
14387 | } | |
14388 | ||
14389 | +#ifdef CONFIG_GRKERNSEC | |
14390 | + current->acl = old_acl; | |
14391 | + memcpy(current->signal->rlim, old_rlim, sizeof(old_rlim)); | |
14392 | + fput(current->exec_file); | |
14393 | + current->exec_file = old_exec_file; | |
14394 | +#endif | |
14395 | + | |
14396 | out: | |
da5b3fc8 | 14397 | if (bprm->security) |
14398 | security_bprm_free(bprm); | |
4dee9bd5 | 14399 | diff -urNp linux-2.6.25.4/fs/compat_ioctl.c linux-2.6.25.4/fs/compat_ioctl.c |
14400 | --- linux-2.6.25.4/fs/compat_ioctl.c 2008-05-15 11:00:12.000000000 -0400 | |
14401 | +++ linux-2.6.25.4/fs/compat_ioctl.c 2008-05-18 13:33:16.000000000 -0400 | |
14402 | @@ -1889,15 +1889,15 @@ struct ioctl_trans { | |
da5b3fc8 | 14403 | }; |
14404 | ||
14405 | #define HANDLE_IOCTL(cmd,handler) \ | |
14406 | - { (cmd), (ioctl_trans_handler_t)(handler) }, | |
14407 | + { (cmd), (ioctl_trans_handler_t)(handler), NULL }, | |
14408 | ||
14409 | /* pointer to compatible structure or no argument */ | |
14410 | #define COMPATIBLE_IOCTL(cmd) \ | |
14411 | - { (cmd), do_ioctl32_pointer }, | |
14412 | + { (cmd), do_ioctl32_pointer, NULL }, | |
14413 | ||
14414 | /* argument is an unsigned long integer, not a pointer */ | |
14415 | #define ULONG_IOCTL(cmd) \ | |
14416 | - { (cmd), (ioctl_trans_handler_t)sys_ioctl }, | |
14417 | + { (cmd), (ioctl_trans_handler_t)sys_ioctl, NULL }, | |
14418 | ||
14419 | /* ioctl should not be warned about even if it's not implemented. | |
14420 | Valid reasons to use this: | |
4dee9bd5 | 14421 | diff -urNp linux-2.6.25.4/fs/debugfs/inode.c linux-2.6.25.4/fs/debugfs/inode.c |
14422 | --- linux-2.6.25.4/fs/debugfs/inode.c 2008-05-15 11:00:12.000000000 -0400 | |
14423 | +++ linux-2.6.25.4/fs/debugfs/inode.c 2008-05-18 13:33:16.000000000 -0400 | |
14424 | @@ -121,7 +121,7 @@ static inline int debugfs_positive(struc | |
50425a20 | 14425 | |
14426 | static int debug_fill_super(struct super_block *sb, void *data, int silent) | |
14427 | { | |
14428 | - static struct tree_descr debug_files[] = {{""}}; | |
14429 | + static struct tree_descr debug_files[] = {{"", NULL, 0}}; | |
14430 | ||
14431 | return simple_fill_super(sb, DEBUGFS_MAGIC, debug_files); | |
14432 | } | |
4dee9bd5 | 14433 | diff -urNp linux-2.6.25.4/fs/exec.c linux-2.6.25.4/fs/exec.c |
14434 | --- linux-2.6.25.4/fs/exec.c 2008-05-15 11:00:12.000000000 -0400 | |
14435 | +++ linux-2.6.25.4/fs/exec.c 2008-05-18 13:33:16.000000000 -0400 | |
da5b3fc8 | 14436 | @@ -51,6 +51,8 @@ |
14437 | #include <linux/tsacct_kern.h> | |
14438 | #include <linux/cn_proc.h> | |
50425a20 | 14439 | #include <linux/audit.h> |
14440 | +#include <linux/random.h> | |
14441 | +#include <linux/grsecurity.h> | |
14442 | ||
14443 | #include <asm/uaccess.h> | |
14444 | #include <asm/mmu_context.h> | |
b2ee8b1e | 14445 | @@ -60,6 +62,11 @@ |
14446 | #include <linux/kmod.h> | |
14447 | #endif | |
14448 | ||
14449 | +#ifdef CONFIG_PAX_HOOK_ACL_FLAGS | |
14450 | +void (*pax_set_initial_flags_func)(struct linux_binprm *bprm); | |
14451 | +EXPORT_SYMBOL(pax_set_initial_flags_func); | |
14452 | +#endif | |
14453 | + | |
14454 | int core_uses_pid; | |
14455 | char core_pattern[CORENAME_MAX_SIZE] = "core"; | |
14456 | int suid_dumpable = 0; | |
14457 | @@ -158,18 +165,10 @@ static struct page *get_arg_page(struct | |
da5b3fc8 | 14458 | int write) |
e36c1b33 | 14459 | { |
da5b3fc8 | 14460 | struct page *page; |
14461 | - int ret; | |
14462 | ||
14463 | -#ifdef CONFIG_STACK_GROWSUP | |
14464 | - if (write) { | |
14465 | - ret = expand_stack_downwards(bprm->vma, pos); | |
14466 | - if (ret < 0) | |
14467 | - return NULL; | |
14468 | - } | |
14469 | -#endif | |
14470 | - ret = get_user_pages(current, bprm->mm, pos, | |
14471 | - 1, write, 1, &page, NULL); | |
14472 | - if (ret <= 0) | |
14473 | + if (0 > expand_stack_downwards(bprm->vma, pos)) | |
14474 | + return NULL; | |
14475 | + if (0 >= get_user_pages(current, bprm->mm, pos, 1, write, 1, &page, NULL)) | |
14476 | return NULL; | |
14477 | ||
14478 | if (write) { | |
4dee9bd5 | 14479 | @@ -242,6 +241,11 @@ static int __bprm_mm_init(struct linux_b |
da5b3fc8 | 14480 | vma->vm_start = vma->vm_end - PAGE_SIZE; |
14481 | ||
14482 | vma->vm_flags = VM_STACK_FLAGS; | |
50425a20 | 14483 | + |
14484 | +#ifdef CONFIG_PAX_SEGMEXEC | |
da5b3fc8 | 14485 | + vma->vm_flags &= ~(VM_EXEC | VM_MAYEXEC); |
50425a20 | 14486 | +#endif |
14487 | + | |
da5b3fc8 | 14488 | vma->vm_page_prot = vm_get_page_prot(vma->vm_flags); |
14489 | err = insert_vm_struct(mm, vma); | |
14490 | if (err) { | |
4dee9bd5 | 14491 | @@ -254,6 +258,11 @@ static int __bprm_mm_init(struct linux_b |
da5b3fc8 | 14492 | |
14493 | bprm->p = vma->vm_end - sizeof(void *); | |
14494 | ||
14495 | +#ifdef CONFIG_PAX_RANDUSTACK | |
14496 | + if (randomize_va_space) | |
14497 | + bprm->p ^= (pax_get_random_long() & ~15) & ~PAGE_MASK; | |
14498 | +#endif | |
14499 | + | |
14500 | return 0; | |
e36c1b33 | 14501 | |
da5b3fc8 | 14502 | err: |
4dee9bd5 | 14503 | @@ -377,7 +386,7 @@ static int count(char __user * __user * |
da5b3fc8 | 14504 | if (!p) |
14505 | break; | |
14506 | argv++; | |
14507 | - if(++i > max) | |
14508 | + if (++i > max) | |
14509 | return -E2BIG; | |
14510 | cond_resched(); | |
14511 | } | |
4dee9bd5 | 14512 | @@ -517,6 +526,10 @@ static int shift_arg_pages(struct vm_are |
da5b3fc8 | 14513 | if (vma != find_vma(mm, new_start)) |
14514 | return -EFAULT; | |
50425a20 | 14515 | |
14516 | +#ifdef CONFIG_PAX_SEGMEXEC | |
da5b3fc8 | 14517 | + BUG_ON(pax_find_mirror_vma(vma)); |
50425a20 | 14518 | +#endif |
14519 | + | |
da5b3fc8 | 14520 | /* |
14521 | * cover the whole range: [new_start, old_end) | |
14522 | */ | |
4dee9bd5 | 14523 | @@ -605,8 +618,20 @@ int setup_arg_pages(struct linux_binprm |
da5b3fc8 | 14524 | bprm->exec -= stack_shift; |
14525 | ||
14526 | down_write(&mm->mmap_sem); | |
83a957c9 | 14527 | + |
da5b3fc8 | 14528 | + /* Move stack pages down in memory. */ |
14529 | + if (stack_shift) { | |
14530 | + ret = shift_arg_pages(vma, stack_shift); | |
14531 | + if (ret) | |
14532 | + goto out_unlock; | |
14533 | + } | |
14534 | + | |
14535 | vm_flags = vma->vm_flags; | |
14536 | ||
4dee9bd5 | 14537 | +#ifdef CONFIG_PAX_SEGMEXEC |
14538 | + vm_flags |= VM_STACK_FLAGS & (VM_EXEC | VM_MAYEXEC); | |
14539 | +#endif | |
14540 | + | |
da5b3fc8 | 14541 | /* |
4dee9bd5 | 14542 | * Adjust stack execute permissions; explicitly enable for |
14543 | * EXSTACK_ENABLE_X, disable for EXSTACK_DISABLE_X and leave alone | |
14544 | @@ -618,21 +643,24 @@ int setup_arg_pages(struct linux_binprm | |
da5b3fc8 | 14545 | vm_flags &= ~VM_EXEC; |
da5b3fc8 | 14546 | vm_flags |= mm->def_flags; |
14547 | ||
83a957c9 | 14548 | +#if defined(CONFIG_PAX_PAGEEXEC) || defined(CONFIG_PAX_SEGMEXEC) |
da5b3fc8 | 14549 | + if (mm->pax_flags & (MF_PAX_PAGEEXEC | MF_PAX_SEGMEXEC)) { |
14550 | + vm_flags &= ~VM_EXEC; | |
83a957c9 | 14551 | + |
14552 | +#ifdef CONFIG_PAX_MPROTECT | |
14553 | + if (mm->pax_flags & MF_PAX_MPROTECT) | |
da5b3fc8 | 14554 | + vm_flags &= ~VM_MAYEXEC; |
83a957c9 | 14555 | +#endif |
14556 | + | |
da5b3fc8 | 14557 | + } |
83a957c9 | 14558 | +#endif |
14559 | + | |
da5b3fc8 | 14560 | ret = mprotect_fixup(vma, &prev, vma->vm_start, vma->vm_end, |
14561 | vm_flags); | |
14562 | if (ret) | |
14563 | goto out_unlock; | |
14564 | BUG_ON(prev != vma); | |
14565 | ||
14566 | - /* Move stack pages down in memory. */ | |
14567 | - if (stack_shift) { | |
14568 | - ret = shift_arg_pages(vma, stack_shift); | |
14569 | - if (ret) { | |
14570 | - up_write(&mm->mmap_sem); | |
14571 | - return ret; | |
8a4b4a5e | 14572 | - } |
da5b3fc8 | 14573 | - } |
14574 | - | |
14575 | #ifdef CONFIG_STACK_GROWSUP | |
14576 | stack_base = vma->vm_end + EXTRA_STACK_VM_PAGES * PAGE_SIZE; | |
14577 | #else | |
4dee9bd5 | 14578 | @@ -644,7 +672,7 @@ int setup_arg_pages(struct linux_binprm |
da5b3fc8 | 14579 | |
14580 | out_unlock: | |
e36c1b33 | 14581 | up_write(&mm->mmap_sem); |
e36c1b33 | 14582 | - return 0; |
e36c1b33 | 14583 | + return ret; |
14584 | } | |
e36c1b33 | 14585 | EXPORT_SYMBOL(setup_arg_pages); |
da5b3fc8 | 14586 | |
4dee9bd5 | 14587 | @@ -663,7 +691,7 @@ struct file *open_exec(const char *name) |
14588 | struct inode *inode = nd.path.dentry->d_inode; | |
8a4b4a5e | 14589 | file = ERR_PTR(-EACCES); |
da5b3fc8 | 14590 | if (S_ISREG(inode->i_mode)) { |
8a4b4a5e | 14591 | - int err = vfs_permission(&nd, MAY_EXEC); |
14592 | + err = vfs_permission(&nd, MAY_EXEC); | |
14593 | file = ERR_PTR(err); | |
14594 | if (!err) { | |
4dee9bd5 | 14595 | file = nameidata_to_filp(&nd, |
14596 | @@ -1280,6 +1308,11 @@ int do_execve(char * filename, | |
da5b3fc8 | 14597 | char __user *__user *envp, |
14598 | struct pt_regs * regs) | |
14599 | { | |
50425a20 | 14600 | +#ifdef CONFIG_GRKERNSEC |
14601 | + struct file *old_exec_file; | |
14602 | + struct acl_subject_label *old_acl; | |
14603 | + struct rlimit old_rlim[RLIM_NLIMITS]; | |
14604 | +#endif | |
da5b3fc8 | 14605 | struct linux_binprm *bprm; |
14606 | struct file *file; | |
14607 | unsigned long env_p; | |
4dee9bd5 | 14608 | @@ -1295,6 +1328,20 @@ int do_execve(char * filename, |
50425a20 | 14609 | if (IS_ERR(file)) |
14610 | goto out_kfree; | |
14611 | ||
14612 | + gr_learn_resource(current, RLIMIT_NPROC, atomic_read(¤t->user->processes), 1); | |
14613 | + | |
14614 | + if (gr_handle_nproc()) { | |
14615 | + allow_write_access(file); | |
14616 | + fput(file); | |
14617 | + return -EAGAIN; | |
14618 | + } | |
14619 | + | |
14620 | + if (!gr_acl_handle_execve(file->f_dentry, file->f_vfsmnt)) { | |
14621 | + allow_write_access(file); | |
14622 | + fput(file); | |
14623 | + return -EACCES; | |
14624 | + } | |
14625 | + | |
14626 | sched_exec(); | |
14627 | ||
50425a20 | 14628 | bprm->file = file; |
4dee9bd5 | 14629 | @@ -1336,8 +1383,38 @@ int do_execve(char * filename, |
50425a20 | 14630 | goto out; |
da5b3fc8 | 14631 | bprm->argv_len = env_p - bprm->p; |
50425a20 | 14632 | |
14633 | + if (!gr_tpe_allow(file)) { | |
14634 | + retval = -EACCES; | |
14635 | + goto out; | |
14636 | + } | |
14637 | + | |
14638 | + if (gr_check_crash_exec(file)) { | |
14639 | + retval = -EACCES; | |
14640 | + goto out; | |
14641 | + } | |
14642 | + | |
14643 | + gr_log_chroot_exec(file->f_dentry, file->f_vfsmnt); | |
14644 | + | |
14645 | + gr_handle_exec_args(bprm, argv); | |
14646 | + | |
14647 | +#ifdef CONFIG_GRKERNSEC | |
14648 | + old_acl = current->acl; | |
14649 | + memcpy(old_rlim, current->signal->rlim, sizeof(old_rlim)); | |
14650 | + old_exec_file = current->exec_file; | |
14651 | + get_file(file); | |
14652 | + current->exec_file = file; | |
14653 | +#endif | |
14654 | + | |
14655 | + retval = gr_set_proc_label(file->f_dentry, file->f_vfsmnt); | |
14656 | + if (retval < 0) | |
14657 | + goto out_fail; | |
14658 | + | |
14659 | retval = search_binary_handler(bprm,regs); | |
14660 | if (retval >= 0) { | |
14661 | +#ifdef CONFIG_GRKERNSEC | |
14662 | + if (old_exec_file) | |
14663 | + fput(old_exec_file); | |
14664 | +#endif | |
50425a20 | 14665 | /* execve success */ |
da5b3fc8 | 14666 | free_arg_pages(bprm); |
14667 | security_bprm_free(bprm); | |
4dee9bd5 | 14668 | @@ -1346,6 +1423,14 @@ int do_execve(char * filename, |
50425a20 | 14669 | return retval; |
14670 | } | |
14671 | ||
14672 | +out_fail: | |
14673 | +#ifdef CONFIG_GRKERNSEC | |
14674 | + current->acl = old_acl; | |
14675 | + memcpy(current->signal->rlim, old_rlim, sizeof(old_rlim)); | |
14676 | + fput(current->exec_file); | |
14677 | + current->exec_file = old_exec_file; | |
14678 | +#endif | |
14679 | + | |
14680 | out: | |
da5b3fc8 | 14681 | free_arg_pages(bprm); |
14682 | if (bprm->security) | |
4dee9bd5 | 14683 | @@ -1510,6 +1595,116 @@ out: |
50425a20 | 14684 | return ispipe; |
14685 | } | |
14686 | ||
8a4b4a5e | 14687 | +int pax_check_flags(unsigned long *flags) |
50425a20 | 14688 | +{ |
14689 | + int retval = 0; | |
14690 | + | |
8a4b4a5e | 14691 | +#if !defined(CONFIG_X86_32) || !defined(CONFIG_PAX_SEGMEXEC) |
50425a20 | 14692 | + if (*flags & MF_PAX_SEGMEXEC) |
14693 | + { | |
14694 | + *flags &= ~MF_PAX_SEGMEXEC; | |
14695 | + retval = -EINVAL; | |
14696 | + } | |
14697 | +#endif | |
14698 | + | |
14699 | + if ((*flags & MF_PAX_PAGEEXEC) | |
14700 | + | |
14701 | +#ifdef CONFIG_PAX_PAGEEXEC | |
14702 | + && (*flags & MF_PAX_SEGMEXEC) | |
14703 | +#endif | |
14704 | + | |
14705 | + ) | |
14706 | + { | |
14707 | + *flags &= ~MF_PAX_PAGEEXEC; | |
14708 | + retval = -EINVAL; | |
14709 | + } | |
14710 | + | |
14711 | + if ((*flags & MF_PAX_MPROTECT) | |
14712 | + | |
14713 | +#ifdef CONFIG_PAX_MPROTECT | |
14714 | + && !(*flags & (MF_PAX_PAGEEXEC | MF_PAX_SEGMEXEC)) | |
14715 | +#endif | |
14716 | + | |
14717 | + ) | |
14718 | + { | |
14719 | + *flags &= ~MF_PAX_MPROTECT; | |
14720 | + retval = -EINVAL; | |
14721 | + } | |
14722 | + | |
14723 | + if ((*flags & MF_PAX_EMUTRAMP) | |
14724 | + | |
14725 | +#ifdef CONFIG_PAX_EMUTRAMP | |
14726 | + && !(*flags & (MF_PAX_PAGEEXEC | MF_PAX_SEGMEXEC)) | |
14727 | +#endif | |
14728 | + | |
14729 | + ) | |
14730 | + { | |
14731 | + *flags &= ~MF_PAX_EMUTRAMP; | |
14732 | + retval = -EINVAL; | |
14733 | + } | |
14734 | + | |
14735 | + return retval; | |
14736 | +} | |
14737 | + | |
14738 | +EXPORT_SYMBOL(pax_check_flags); | |
14739 | + | |
14740 | +#if defined(CONFIG_PAX_PAGEEXEC) || defined(CONFIG_PAX_SEGMEXEC) | |
14741 | +void pax_report_fault(struct pt_regs *regs, void *pc, void *sp) | |
14742 | +{ | |
14743 | + struct task_struct *tsk = current; | |
14744 | + struct mm_struct *mm = current->mm; | |
da5b3fc8 | 14745 | + char *buffer_exec = (char *)__get_free_page(GFP_KERNEL); |
14746 | + char *buffer_fault = (char *)__get_free_page(GFP_KERNEL); | |
8a4b4a5e | 14747 | + char *path_exec = NULL; |
14748 | + char *path_fault = NULL; | |
14749 | + unsigned long start = 0UL, end = 0UL, offset = 0UL; | |
50425a20 | 14750 | + |
14751 | + if (buffer_exec && buffer_fault) { | |
8a4b4a5e | 14752 | + struct vm_area_struct *vma, *vma_exec = NULL, *vma_fault = NULL; |
50425a20 | 14753 | + |
14754 | + down_read(&mm->mmap_sem); | |
14755 | + vma = mm->mmap; | |
14756 | + while (vma && (!vma_exec || !vma_fault)) { | |
14757 | + if ((vma->vm_flags & VM_EXECUTABLE) && vma->vm_file) | |
14758 | + vma_exec = vma; | |
14759 | + if (vma->vm_start <= (unsigned long)pc && (unsigned long)pc < vma->vm_end) | |
14760 | + vma_fault = vma; | |
14761 | + vma = vma->vm_next; | |
14762 | + } | |
14763 | + if (vma_exec) { | |
4dee9bd5 | 14764 | + struct path path = {vma_exec->vm_file->f_path.mnt, vma_exec->vm_file->f_path.dentry}; |
14765 | + path_exec = d_path(&path, buffer_exec, PAGE_SIZE); | |
50425a20 | 14766 | + if (IS_ERR(path_exec)) |
14767 | + path_exec = "<path too long>"; | |
14768 | + } | |
14769 | + if (vma_fault) { | |
14770 | + start = vma_fault->vm_start; | |
14771 | + end = vma_fault->vm_end; | |
14772 | + offset = vma_fault->vm_pgoff << PAGE_SHIFT; | |
14773 | + if (vma_fault->vm_file) { | |
4dee9bd5 | 14774 | + struct path path = {vma_fault->vm_file->f_path.mnt, vma_fault->vm_file->f_path.dentry}; |
14775 | + path_fault = d_path(&path, buffer_fault, PAGE_SIZE); | |
50425a20 | 14776 | + if (IS_ERR(path_fault)) |
14777 | + path_fault = "<path too long>"; | |
14778 | + } else | |
14779 | + path_fault = "<anonymous mapping>"; | |
14780 | + } | |
14781 | + up_read(&mm->mmap_sem); | |
14782 | + } | |
14783 | + if (tsk->signal->curr_ip) | |
8a4b4a5e | 14784 | + printk(KERN_ERR "PAX: From %u.%u.%u.%u: execution attempt in: %s, %08lx-%08lx %08lx\n", NIPQUAD(tsk->signal->curr_ip), path_fault, start, end, offset); |
50425a20 | 14785 | + else |
14786 | + printk(KERN_ERR "PAX: execution attempt in: %s, %08lx-%08lx %08lx\n", path_fault, start, end, offset); | |
14787 | + printk(KERN_ERR "PAX: terminating task: %s(%s):%d, uid/euid: %u/%u, " | |
da5b3fc8 | 14788 | + "PC: %p, SP: %p\n", path_exec, tsk->comm, task_pid_nr(tsk), |
50425a20 | 14789 | + tsk->uid, tsk->euid, pc, sp); |
14790 | + free_page((unsigned long)buffer_exec); | |
14791 | + free_page((unsigned long)buffer_fault); | |
14792 | + pax_report_insns(pc, sp); | |
14793 | + do_coredump(SIGKILL, SIGKILL, regs); | |
14794 | +} | |
14795 | +#endif | |
14796 | + | |
14797 | static void zap_process(struct task_struct *start) | |
14798 | { | |
14799 | struct task_struct *t; | |
4dee9bd5 | 14800 | @@ -1707,6 +1902,10 @@ int do_coredump(long signr, int exit_cod |
50425a20 | 14801 | */ |
14802 | clear_thread_flag(TIF_SIGPENDING); | |
14803 | ||
14804 | + if (signr == SIGKILL || signr == SIGILL) | |
14805 | + gr_handle_brute_attach(current); | |
50425a20 | 14806 | + gr_learn_resource(current, RLIMIT_CORE, binfmt->min_coredump, 1); |
da5b3fc8 | 14807 | + |
14808 | /* | |
14809 | * lock_kernel() because format_corename() is controlled by sysctl, which | |
14810 | * uses lock_kernel() | |
4dee9bd5 | 14811 | @@ -1727,6 +1926,8 @@ int do_coredump(long signr, int exit_cod |
b7f09679 | 14812 | |
14813 | if (ispipe) { | |
14814 | helper_argv = argv_split(GFP_KERNEL, corename+1, &helper_argc); | |
14815 | + if (!helper_argv) | |
14816 | + goto fail_unlock; | |
14817 | /* Terminate the string before the first option */ | |
14818 | delimit = strchr(corename, ' '); | |
14819 | if (delimit) | |
4dee9bd5 | 14820 | diff -urNp linux-2.6.25.4/fs/ext2/balloc.c linux-2.6.25.4/fs/ext2/balloc.c |
14821 | --- linux-2.6.25.4/fs/ext2/balloc.c 2008-05-15 11:00:12.000000000 -0400 | |
14822 | +++ linux-2.6.25.4/fs/ext2/balloc.c 2008-05-18 13:33:16.000000000 -0400 | |
14823 | @@ -1192,7 +1192,7 @@ static int ext2_has_free_blocks(struct e | |
da5b3fc8 | 14824 | |
14825 | free_blocks = percpu_counter_read_positive(&sbi->s_freeblocks_counter); | |
14826 | root_blocks = le32_to_cpu(sbi->s_es->s_r_blocks_count); | |
14827 | - if (free_blocks < root_blocks + 1 && !capable(CAP_SYS_RESOURCE) && | |
14828 | + if (free_blocks < root_blocks + 1 && !capable_nolog(CAP_SYS_RESOURCE) && | |
14829 | sbi->s_resuid != current->fsuid && | |
14830 | (sbi->s_resgid == 0 || !in_group_p (sbi->s_resgid))) { | |
14831 | return 0; | |
4dee9bd5 | 14832 | diff -urNp linux-2.6.25.4/fs/ext3/balloc.c linux-2.6.25.4/fs/ext3/balloc.c |
14833 | --- linux-2.6.25.4/fs/ext3/balloc.c 2008-05-15 11:00:12.000000000 -0400 | |
14834 | +++ linux-2.6.25.4/fs/ext3/balloc.c 2008-05-18 13:33:16.000000000 -0400 | |
b79bc584 | 14835 | @@ -1359,7 +1359,7 @@ static int ext3_has_free_blocks(struct e |
14836 | DLIMIT_ADJUST_BLOCK(sb, dx_current_tag(), &free_blocks, &root_blocks); | |
f6dbcbfc | 14837 | |
b79bc584 | 14838 | cond = (free_blocks < root_blocks + 1 && |
14839 | - !capable(CAP_SYS_RESOURCE) && | |
14840 | + !capable_nolog(CAP_SYS_RESOURCE) && | |
4dee9bd5 | 14841 | sbi->s_resuid != current->fsuid && |
b79bc584 | 14842 | (sbi->s_resgid == 0 || !in_group_p (sbi->s_resgid))); |
14843 | ||
4dee9bd5 | 14844 | diff -urNp linux-2.6.25.4/fs/ext3/namei.c linux-2.6.25.4/fs/ext3/namei.c |
14845 | --- linux-2.6.25.4/fs/ext3/namei.c 2008-05-15 11:00:12.000000000 -0400 | |
14846 | +++ linux-2.6.25.4/fs/ext3/namei.c 2008-05-18 13:33:16.000000000 -0400 | |
14847 | @@ -1166,9 +1166,9 @@ static struct ext3_dir_entry_2 *do_split | |
da5b3fc8 | 14848 | u32 hash2; |
14849 | struct dx_map_entry *map; | |
14850 | char *data1 = (*bh)->b_data, *data2; | |
14851 | - unsigned split, move, size, i; | |
14852 | + unsigned split, move, size; | |
14853 | struct ext3_dir_entry_2 *de = NULL, *de2; | |
14854 | - int err = 0; | |
14855 | + int i, err = 0; | |
14856 | ||
14857 | bh2 = ext3_append (handle, dir, &newblock, &err); | |
14858 | if (!(bh2)) { | |
4dee9bd5 | 14859 | diff -urNp linux-2.6.25.4/fs/ext3/xattr.c linux-2.6.25.4/fs/ext3/xattr.c |
14860 | --- linux-2.6.25.4/fs/ext3/xattr.c 2008-05-15 11:00:12.000000000 -0400 | |
14861 | +++ linux-2.6.25.4/fs/ext3/xattr.c 2008-05-18 13:33:16.000000000 -0400 | |
da5b3fc8 | 14862 | @@ -89,8 +89,8 @@ |
50425a20 | 14863 | printk("\n"); \ |
14864 | } while (0) | |
14865 | #else | |
14866 | -# define ea_idebug(f...) | |
14867 | -# define ea_bdebug(f...) | |
14868 | +# define ea_idebug(f...) do {} while (0) | |
14869 | +# define ea_bdebug(f...) do {} while (0) | |
14870 | #endif | |
14871 | ||
14872 | static void ext3_xattr_cache_insert(struct buffer_head *); | |
4dee9bd5 | 14873 | diff -urNp linux-2.6.25.4/fs/ext4/balloc.c linux-2.6.25.4/fs/ext4/balloc.c |
14874 | --- linux-2.6.25.4/fs/ext4/balloc.c 2008-05-15 11:00:12.000000000 -0400 | |
14875 | +++ linux-2.6.25.4/fs/ext4/balloc.c 2008-05-18 13:33:16.000000000 -0400 | |
b79bc584 | 14876 | @@ -1479,7 +1479,7 @@ static int ext4_has_free_blocks(struct e |
14877 | DLIMIT_ADJUST_BLOCK(sb, dx_current_tag(), &free_blocks, &root_blocks); | |
f6dbcbfc | 14878 | |
b79bc584 | 14879 | cond = (free_blocks < root_blocks + 1 && |
14880 | - !capable(CAP_SYS_RESOURCE) && | |
14881 | + !capable_nolog(CAP_SYS_RESOURCE) && | |
4dee9bd5 | 14882 | sbi->s_resuid != current->fsuid && |
b79bc584 | 14883 | (sbi->s_resgid == 0 || !in_group_p (sbi->s_resgid))); |
14884 | ||
4dee9bd5 | 14885 | diff -urNp linux-2.6.25.4/fs/ext4/namei.c linux-2.6.25.4/fs/ext4/namei.c |
14886 | --- linux-2.6.25.4/fs/ext4/namei.c 2008-05-15 11:00:12.000000000 -0400 | |
14887 | +++ linux-2.6.25.4/fs/ext4/namei.c 2008-05-18 13:33:16.000000000 -0400 | |
14888 | @@ -1168,9 +1168,9 @@ static struct ext4_dir_entry_2 *do_split | |
da5b3fc8 | 14889 | u32 hash2; |
14890 | struct dx_map_entry *map; | |
14891 | char *data1 = (*bh)->b_data, *data2; | |
14892 | - unsigned split, move, size, i; | |
14893 | + unsigned split, move, size; | |
14894 | struct ext4_dir_entry_2 *de = NULL, *de2; | |
14895 | - int err = 0; | |
14896 | + int i, err = 0; | |
14897 | ||
14898 | bh2 = ext4_append (handle, dir, &newblock, &err); | |
14899 | if (!(bh2)) { | |
4dee9bd5 | 14900 | diff -urNp linux-2.6.25.4/fs/fcntl.c linux-2.6.25.4/fs/fcntl.c |
14901 | --- linux-2.6.25.4/fs/fcntl.c 2008-05-15 11:00:12.000000000 -0400 | |
14902 | +++ linux-2.6.25.4/fs/fcntl.c 2008-05-18 13:33:16.000000000 -0400 | |
da5b3fc8 | 14903 | @@ -19,6 +19,7 @@ |
50425a20 | 14904 | #include <linux/rcupdate.h> |
da5b3fc8 | 14905 | #include <linux/pid_namespace.h> |
b79bc584 | 14906 | #include <linux/vs_limit.h> |
50425a20 | 14907 | +#include <linux/grsecurity.h> |
14908 | ||
14909 | #include <asm/poll.h> | |
14910 | #include <asm/siginfo.h> | |
db6fc088 | 14911 | @@ -64,6 +65,7 @@ static int locate_fd(struct files_struct |
50425a20 | 14912 | struct fdtable *fdt; |
14913 | ||
14914 | error = -EINVAL; | |
14915 | + gr_learn_resource(current, RLIMIT_NOFILE, orig_start, 0); | |
14916 | if (orig_start >= current->signal->rlim[RLIMIT_NOFILE].rlim_cur) | |
14917 | goto out; | |
14918 | ||
da5b3fc8 | 14919 | @@ -83,6 +85,7 @@ repeat: |
50425a20 | 14920 | fdt->max_fds, start); |
14921 | ||
14922 | error = -EMFILE; | |
14923 | + gr_learn_resource(current, RLIMIT_NOFILE, newfd, 0); | |
14924 | if (newfd >= current->signal->rlim[RLIMIT_NOFILE].rlim_cur) | |
14925 | goto out; | |
da5b3fc8 | 14926 | |
14927 | @@ -144,6 +147,8 @@ asmlinkage long sys_dup2(unsigned int ol | |
50425a20 | 14928 | struct files_struct * files = current->files; |
14929 | struct fdtable *fdt; | |
14930 | ||
14931 | + gr_learn_resource(current, RLIMIT_NOFILE, newfd, 0); | |
14932 | + | |
14933 | spin_lock(&files->file_lock); | |
14934 | if (!(file = fcheck(oldfd))) | |
14935 | goto out_unlock; | |
da5b3fc8 | 14936 | @@ -463,7 +468,8 @@ static inline int sigio_perm(struct task |
50425a20 | 14937 | return (((fown->euid == 0) || |
14938 | (fown->euid == p->suid) || (fown->euid == p->uid) || | |
14939 | (fown->uid == p->suid) || (fown->uid == p->uid)) && | |
14940 | - !security_file_send_sigiotask(p, fown, sig)); | |
14941 | + !security_file_send_sigiotask(p, fown, sig) && | |
14942 | + !gr_check_protected_task(p) && !gr_pid_is_chrooted(p)); | |
14943 | } | |
14944 | ||
14945 | static void send_sigio_to_task(struct task_struct *p, | |
4dee9bd5 | 14946 | diff -urNp linux-2.6.25.4/fs/fuse/control.c linux-2.6.25.4/fs/fuse/control.c |
14947 | --- linux-2.6.25.4/fs/fuse/control.c 2008-05-15 11:00:12.000000000 -0400 | |
14948 | +++ linux-2.6.25.4/fs/fuse/control.c 2008-05-18 13:33:16.000000000 -0400 | |
50425a20 | 14949 | @@ -159,7 +159,7 @@ void fuse_ctl_remove_conn(struct fuse_co |
14950 | ||
14951 | static int fuse_ctl_fill_super(struct super_block *sb, void *data, int silent) | |
14952 | { | |
14953 | - struct tree_descr empty_descr = {""}; | |
14954 | + struct tree_descr empty_descr = {"", NULL, 0}; | |
14955 | struct fuse_conn *fc; | |
14956 | int err; | |
14957 | ||
4dee9bd5 | 14958 | diff -urNp linux-2.6.25.4/fs/fuse/dir.c linux-2.6.25.4/fs/fuse/dir.c |
14959 | --- linux-2.6.25.4/fs/fuse/dir.c 2008-05-15 11:00:12.000000000 -0400 | |
14960 | +++ linux-2.6.25.4/fs/fuse/dir.c 2008-05-18 13:33:16.000000000 -0400 | |
14961 | @@ -1031,7 +1031,7 @@ static char *read_link(struct dentry *de | |
7bcbf78a | 14962 | return link; |
14963 | } | |
14964 | ||
14965 | -static void free_link(char *link) | |
14966 | +static void free_link(const char *link) | |
14967 | { | |
14968 | if (!IS_ERR(link)) | |
14969 | free_page((unsigned long) link); | |
4dee9bd5 | 14970 | diff -urNp linux-2.6.25.4/fs/hfs/inode.c linux-2.6.25.4/fs/hfs/inode.c |
14971 | --- linux-2.6.25.4/fs/hfs/inode.c 2008-05-15 11:00:12.000000000 -0400 | |
14972 | +++ linux-2.6.25.4/fs/hfs/inode.c 2008-05-18 13:33:16.000000000 -0400 | |
da5b3fc8 | 14973 | @@ -419,7 +419,7 @@ int hfs_write_inode(struct inode *inode, |
14974 | ||
14975 | if (S_ISDIR(main_inode->i_mode)) { | |
14976 | if (fd.entrylength < sizeof(struct hfs_cat_dir)) | |
14977 | - /* panic? */; | |
14978 | + {/* panic? */} | |
14979 | hfs_bnode_read(fd.bnode, &rec, fd.entryoffset, | |
14980 | sizeof(struct hfs_cat_dir)); | |
14981 | if (rec.type != HFS_CDR_DIR || | |
14982 | @@ -440,7 +440,7 @@ int hfs_write_inode(struct inode *inode, | |
14983 | sizeof(struct hfs_cat_file)); | |
14984 | } else { | |
14985 | if (fd.entrylength < sizeof(struct hfs_cat_file)) | |
14986 | - /* panic? */; | |
14987 | + {/* panic? */} | |
14988 | hfs_bnode_read(fd.bnode, &rec, fd.entryoffset, | |
14989 | sizeof(struct hfs_cat_file)); | |
14990 | if (rec.type != HFS_CDR_FIL || | |
4dee9bd5 | 14991 | diff -urNp linux-2.6.25.4/fs/hfsplus/inode.c linux-2.6.25.4/fs/hfsplus/inode.c |
14992 | --- linux-2.6.25.4/fs/hfsplus/inode.c 2008-05-15 11:00:12.000000000 -0400 | |
14993 | +++ linux-2.6.25.4/fs/hfsplus/inode.c 2008-05-18 13:33:16.000000000 -0400 | |
da5b3fc8 | 14994 | @@ -422,7 +422,7 @@ int hfsplus_cat_read_inode(struct inode |
14995 | struct hfsplus_cat_folder *folder = &entry.folder; | |
14996 | ||
14997 | if (fd->entrylength < sizeof(struct hfsplus_cat_folder)) | |
14998 | - /* panic? */; | |
14999 | + {/* panic? */} | |
15000 | hfs_bnode_read(fd->bnode, &entry, fd->entryoffset, | |
15001 | sizeof(struct hfsplus_cat_folder)); | |
15002 | hfsplus_get_perms(inode, &folder->permissions, 1); | |
15003 | @@ -439,7 +439,7 @@ int hfsplus_cat_read_inode(struct inode | |
15004 | struct hfsplus_cat_file *file = &entry.file; | |
15005 | ||
15006 | if (fd->entrylength < sizeof(struct hfsplus_cat_file)) | |
15007 | - /* panic? */; | |
15008 | + {/* panic? */} | |
15009 | hfs_bnode_read(fd->bnode, &entry, fd->entryoffset, | |
15010 | sizeof(struct hfsplus_cat_file)); | |
15011 | ||
15012 | @@ -495,7 +495,7 @@ int hfsplus_cat_write_inode(struct inode | |
15013 | struct hfsplus_cat_folder *folder = &entry.folder; | |
15014 | ||
15015 | if (fd.entrylength < sizeof(struct hfsplus_cat_folder)) | |
15016 | - /* panic? */; | |
15017 | + {/* panic? */} | |
15018 | hfs_bnode_read(fd.bnode, &entry, fd.entryoffset, | |
15019 | sizeof(struct hfsplus_cat_folder)); | |
15020 | /* simple node checks? */ | |
15021 | @@ -517,7 +517,7 @@ int hfsplus_cat_write_inode(struct inode | |
15022 | struct hfsplus_cat_file *file = &entry.file; | |
15023 | ||
15024 | if (fd.entrylength < sizeof(struct hfsplus_cat_file)) | |
15025 | - /* panic? */; | |
15026 | + {/* panic? */} | |
15027 | hfs_bnode_read(fd.bnode, &entry, fd.entryoffset, | |
15028 | sizeof(struct hfsplus_cat_file)); | |
15029 | hfsplus_inode_write_fork(inode, &file->data_fork); | |
4dee9bd5 | 15030 | diff -urNp linux-2.6.25.4/fs/jffs2/debug.h linux-2.6.25.4/fs/jffs2/debug.h |
15031 | --- linux-2.6.25.4/fs/jffs2/debug.h 2008-05-15 11:00:12.000000000 -0400 | |
15032 | +++ linux-2.6.25.4/fs/jffs2/debug.h 2008-05-18 13:33:16.000000000 -0400 | |
da5b3fc8 | 15033 | @@ -51,13 +51,13 @@ |
15034 | #if CONFIG_JFFS2_FS_DEBUG > 0 | |
15035 | #define D1(x) x | |
15036 | #else | |
15037 | -#define D1(x) | |
15038 | +#define D1(x) do {} while (0); | |
15039 | #endif | |
15040 | ||
15041 | #if CONFIG_JFFS2_FS_DEBUG > 1 | |
15042 | #define D2(x) x | |
15043 | #else | |
15044 | -#define D2(x) | |
15045 | +#define D2(x) do {} while (0); | |
15046 | #endif | |
15047 | ||
15048 | /* The prefixes of JFFS2 messages */ | |
15049 | @@ -113,68 +113,68 @@ | |
15050 | #ifdef JFFS2_DBG_READINODE_MESSAGES | |
15051 | #define dbg_readinode(fmt, ...) JFFS2_DEBUG(fmt, ##__VA_ARGS__) | |
15052 | #else | |
15053 | -#define dbg_readinode(fmt, ...) | |
15054 | +#define dbg_readinode(fmt, ...) do {} while (0) | |
15055 | #endif | |
15056 | ||
15057 | /* Fragtree build debugging messages */ | |
15058 | #ifdef JFFS2_DBG_FRAGTREE_MESSAGES | |
15059 | #define dbg_fragtree(fmt, ...) JFFS2_DEBUG(fmt, ##__VA_ARGS__) | |
15060 | #else | |
15061 | -#define dbg_fragtree(fmt, ...) | |
15062 | +#define dbg_fragtree(fmt, ...) do {} while (0) | |
15063 | #endif | |
15064 | #ifdef JFFS2_DBG_FRAGTREE2_MESSAGES | |
15065 | #define dbg_fragtree2(fmt, ...) JFFS2_DEBUG(fmt, ##__VA_ARGS__) | |
15066 | #else | |
15067 | -#define dbg_fragtree2(fmt, ...) | |
15068 | +#define dbg_fragtree2(fmt, ...) do {} while (0) | |
15069 | #endif | |
15070 | ||
15071 | /* Directory entry list manilulation debugging messages */ | |
15072 | #ifdef JFFS2_DBG_DENTLIST_MESSAGES | |
15073 | #define dbg_dentlist(fmt, ...) JFFS2_DEBUG(fmt, ##__VA_ARGS__) | |
15074 | #else | |
15075 | -#define dbg_dentlist(fmt, ...) | |
15076 | +#define dbg_dentlist(fmt, ...) do {} while (0) | |
15077 | #endif | |
15078 | ||
15079 | /* Print the messages about manipulating node_refs */ | |
15080 | #ifdef JFFS2_DBG_NODEREF_MESSAGES | |
15081 | #define dbg_noderef(fmt, ...) JFFS2_DEBUG(fmt, ##__VA_ARGS__) | |
15082 | #else | |
15083 | -#define dbg_noderef(fmt, ...) | |
15084 | +#define dbg_noderef(fmt, ...) do {} while (0) | |
15085 | #endif | |
15086 | ||
15087 | /* Manipulations with the list of inodes (JFFS2 inocache) */ | |
15088 | #ifdef JFFS2_DBG_INOCACHE_MESSAGES | |
15089 | #define dbg_inocache(fmt, ...) JFFS2_DEBUG(fmt, ##__VA_ARGS__) | |
15090 | #else | |
15091 | -#define dbg_inocache(fmt, ...) | |
15092 | +#define dbg_inocache(fmt, ...) do {} while (0) | |
15093 | #endif | |
15094 | ||
15095 | /* Summary debugging messages */ | |
15096 | #ifdef JFFS2_DBG_SUMMARY_MESSAGES | |
15097 | #define dbg_summary(fmt, ...) JFFS2_DEBUG(fmt, ##__VA_ARGS__) | |
15098 | #else | |
15099 | -#define dbg_summary(fmt, ...) | |
15100 | +#define dbg_summary(fmt, ...) do {} while (0) | |
15101 | #endif | |
15102 | ||
15103 | /* File system build messages */ | |
15104 | #ifdef JFFS2_DBG_FSBUILD_MESSAGES | |
15105 | #define dbg_fsbuild(fmt, ...) JFFS2_DEBUG(fmt, ##__VA_ARGS__) | |
15106 | #else | |
15107 | -#define dbg_fsbuild(fmt, ...) | |
15108 | +#define dbg_fsbuild(fmt, ...) do {} while (0) | |
15109 | #endif | |
15110 | ||
15111 | /* Watch the object allocations */ | |
15112 | #ifdef JFFS2_DBG_MEMALLOC_MESSAGES | |
15113 | #define dbg_memalloc(fmt, ...) JFFS2_DEBUG(fmt, ##__VA_ARGS__) | |
15114 | #else | |
15115 | -#define dbg_memalloc(fmt, ...) | |
15116 | +#define dbg_memalloc(fmt, ...) do {} while (0) | |
15117 | #endif | |
15118 | ||
15119 | /* Watch the XATTR subsystem */ | |
15120 | #ifdef JFFS2_DBG_XATTR_MESSAGES | |
15121 | #define dbg_xattr(fmt, ...) JFFS2_DEBUG(fmt, ##__VA_ARGS__) | |
15122 | #else | |
15123 | -#define dbg_xattr(fmt, ...) | |
15124 | +#define dbg_xattr(fmt, ...) do {} while (0) | |
15125 | #endif | |
15126 | ||
15127 | /* "Sanity" checks */ | |
4dee9bd5 | 15128 | diff -urNp linux-2.6.25.4/fs/jffs2/erase.c linux-2.6.25.4/fs/jffs2/erase.c |
15129 | --- linux-2.6.25.4/fs/jffs2/erase.c 2008-05-15 11:00:12.000000000 -0400 | |
15130 | +++ linux-2.6.25.4/fs/jffs2/erase.c 2008-05-18 13:33:16.000000000 -0400 | |
15131 | @@ -425,7 +425,8 @@ static void jffs2_mark_erased_block(stru | |
da5b3fc8 | 15132 | struct jffs2_unknown_node marker = { |
15133 | .magic = cpu_to_je16(JFFS2_MAGIC_BITMASK), | |
15134 | .nodetype = cpu_to_je16(JFFS2_NODETYPE_CLEANMARKER), | |
15135 | - .totlen = cpu_to_je32(c->cleanmarker_size) | |
15136 | + .totlen = cpu_to_je32(c->cleanmarker_size), | |
15137 | + .hdr_crc = cpu_to_je32(0) | |
15138 | }; | |
15139 | ||
15140 | jffs2_prealloc_raw_node_refs(c, jeb, 1); | |
4dee9bd5 | 15141 | diff -urNp linux-2.6.25.4/fs/jffs2/summary.h linux-2.6.25.4/fs/jffs2/summary.h |
15142 | --- linux-2.6.25.4/fs/jffs2/summary.h 2008-05-15 11:00:12.000000000 -0400 | |
15143 | +++ linux-2.6.25.4/fs/jffs2/summary.h 2008-05-18 13:33:16.000000000 -0400 | |
da5b3fc8 | 15144 | @@ -188,18 +188,18 @@ int jffs2_sum_scan_sumnode(struct jffs2_ |
15145 | ||
15146 | #define jffs2_sum_active() (0) | |
15147 | #define jffs2_sum_init(a) (0) | |
15148 | -#define jffs2_sum_exit(a) | |
15149 | -#define jffs2_sum_disable_collecting(a) | |
15150 | +#define jffs2_sum_exit(a) do {} while (0) | |
15151 | +#define jffs2_sum_disable_collecting(a) do {} while (0) | |
15152 | #define jffs2_sum_is_disabled(a) (0) | |
15153 | -#define jffs2_sum_reset_collected(a) | |
15154 | +#define jffs2_sum_reset_collected(a) do {} while (0) | |
15155 | #define jffs2_sum_add_kvec(a,b,c,d) (0) | |
15156 | -#define jffs2_sum_move_collected(a,b) | |
15157 | +#define jffs2_sum_move_collected(a,b) do {} while (0) | |
15158 | #define jffs2_sum_write_sumnode(a) (0) | |
15159 | -#define jffs2_sum_add_padding_mem(a,b) | |
15160 | -#define jffs2_sum_add_inode_mem(a,b,c) | |
15161 | -#define jffs2_sum_add_dirent_mem(a,b,c) | |
15162 | -#define jffs2_sum_add_xattr_mem(a,b,c) | |
15163 | -#define jffs2_sum_add_xref_mem(a,b,c) | |
15164 | +#define jffs2_sum_add_padding_mem(a,b) do {} while (0) | |
15165 | +#define jffs2_sum_add_inode_mem(a,b,c) do {} while (0) | |
15166 | +#define jffs2_sum_add_dirent_mem(a,b,c) do {} while (0) | |
15167 | +#define jffs2_sum_add_xattr_mem(a,b,c) do {} while (0) | |
15168 | +#define jffs2_sum_add_xref_mem(a,b,c) do {} while (0) | |
15169 | #define jffs2_sum_scan_sumnode(a,b,c,d,e) (0) | |
15170 | ||
15171 | #endif /* CONFIG_JFFS2_SUMMARY */ | |
4dee9bd5 | 15172 | diff -urNp linux-2.6.25.4/fs/jffs2/wbuf.c linux-2.6.25.4/fs/jffs2/wbuf.c |
15173 | --- linux-2.6.25.4/fs/jffs2/wbuf.c 2008-05-15 11:00:12.000000000 -0400 | |
15174 | +++ linux-2.6.25.4/fs/jffs2/wbuf.c 2008-05-18 13:33:16.000000000 -0400 | |
da5b3fc8 | 15175 | @@ -1015,7 +1015,8 @@ static const struct jffs2_unknown_node o |
15176 | { | |
15177 | .magic = constant_cpu_to_je16(JFFS2_MAGIC_BITMASK), | |
15178 | .nodetype = constant_cpu_to_je16(JFFS2_NODETYPE_CLEANMARKER), | |
15179 | - .totlen = constant_cpu_to_je32(8) | |
15180 | + .totlen = constant_cpu_to_je32(8), | |
15181 | + .hdr_crc = constant_cpu_to_je32(0) | |
15182 | }; | |
15183 | ||
15184 | /* | |
4dee9bd5 | 15185 | diff -urNp linux-2.6.25.4/fs/Kconfig linux-2.6.25.4/fs/Kconfig |
15186 | --- linux-2.6.25.4/fs/Kconfig 2008-05-15 11:00:12.000000000 -0400 | |
15187 | +++ linux-2.6.25.4/fs/Kconfig 2008-05-18 13:33:16.000000000 -0400 | |
15188 | @@ -899,7 +899,7 @@ config PROC_FS | |
50425a20 | 15189 | |
15190 | config PROC_KCORE | |
15191 | bool "/proc/kcore support" if !ARM | |
15192 | - depends on PROC_FS && MMU | |
15193 | + depends on PROC_FS && MMU && !GRKERNSEC_PROC_ADD | |
15194 | ||
15195 | config PROC_VMCORE | |
15196 | bool "/proc/vmcore support (EXPERIMENTAL)" | |
4dee9bd5 | 15197 | diff -urNp linux-2.6.25.4/fs/namei.c linux-2.6.25.4/fs/namei.c |
15198 | --- linux-2.6.25.4/fs/namei.c 2008-05-15 11:00:12.000000000 -0400 | |
15199 | +++ linux-2.6.25.4/fs/namei.c 2008-05-18 13:33:16.000000000 -0400 | |
da5b3fc8 | 15200 | @@ -30,6 +30,7 @@ |
b79bc584 | 15201 | #include <linux/vs_cowbl.h> |
15202 | #include <linux/vs_device.h> | |
15203 | #include <linux/vs_context.h> | |
50425a20 | 15204 | +#include <linux/grsecurity.h> |
15205 | #include <asm/namei.h> | |
15206 | #include <asm/uaccess.h> | |
15207 | ||
4dee9bd5 | 15208 | @@ -662,7 +663,7 @@ static __always_inline int __do_follow_l |
da5b3fc8 | 15209 | cookie = dentry->d_inode->i_op->follow_link(dentry, nd); |
15210 | error = PTR_ERR(cookie); | |
15211 | if (!IS_ERR(cookie)) { | |
15212 | - char *s = nd_get_link(nd); | |
15213 | + const char *s = nd_get_link(nd); | |
15214 | error = 0; | |
15215 | if (s) | |
15216 | error = __vfs_follow_link(nd, s); | |
4dee9bd5 | 15217 | @@ -693,6 +694,13 @@ static inline int do_follow_link(struct |
50425a20 | 15218 | err = security_inode_follow_link(path->dentry, nd); |
15219 | if (err) | |
15220 | goto loop; | |
15221 | + | |
15222 | + if (gr_handle_follow_link(path->dentry->d_parent->d_inode, | |
4dee9bd5 | 15223 | + path->dentry->d_inode, path->dentry, nd->path.mnt)) { |
50425a20 | 15224 | + err = -EACCES; |
15225 | + goto loop; | |
15226 | + } | |
15227 | + | |
15228 | current->link_count++; | |
15229 | current->total_link_count++; | |
15230 | nd->depth++; | |
4dee9bd5 | 15231 | @@ -1041,11 +1049,18 @@ return_reval: |
50425a20 | 15232 | break; |
15233 | } | |
15234 | return_base: | |
4dee9bd5 | 15235 | + if (!gr_acl_handle_hidden_file(nd->path.dentry, nd->path.mnt)) { |
15236 | + path_put(&nd->path); | |
50425a20 | 15237 | + return -ENOENT; |
15238 | + } | |
15239 | return 0; | |
15240 | out_dput: | |
4dee9bd5 | 15241 | path_put_conditional(&next, nd); |
50425a20 | 15242 | break; |
15243 | } | |
4dee9bd5 | 15244 | + if (!gr_acl_handle_hidden_file(nd->path.dentry, nd->path.mnt)) |
50425a20 | 15245 | + err = -ENOENT; |
15246 | + | |
4dee9bd5 | 15247 | path_put(&nd->path); |
50425a20 | 15248 | return_err: |
15249 | return err; | |
4dee9bd5 | 15250 | @@ -1683,9 +1698,17 @@ static int open_namei_create(struct name |
50425a20 | 15251 | int error; |
4dee9bd5 | 15252 | struct dentry *dir = nd->path.dentry; |
50425a20 | 15253 | |
4dee9bd5 | 15254 | + if (!gr_acl_handle_creat(path->dentry, nd->path.dentry, nd->path.mnt, flag, mode)) { |
50425a20 | 15255 | + error = -EACCES; |
15256 | + goto out_unlock_dput; | |
15257 | + } | |
15258 | + | |
15259 | if (!IS_POSIXACL(dir->d_inode)) | |
15260 | mode &= ~current->fs->umask; | |
15261 | error = vfs_create(dir->d_inode, path->dentry, mode, nd); | |
15262 | + if (!error) | |
4dee9bd5 | 15263 | + gr_handle_create(path->dentry, nd->path.mnt); |
50425a20 | 15264 | +out_unlock_dput: |
15265 | mutex_unlock(&dir->d_inode->i_mutex); | |
4dee9bd5 | 15266 | dput(nd->path.dentry); |
15267 | nd->path.dentry = path->dentry; | |
15268 | @@ -1736,6 +1759,17 @@ int open_namei(int dfd, const char *path | |
50425a20 | 15269 | nd, flag); |
15270 | if (error) | |
15271 | return error; | |
15272 | + | |
4dee9bd5 | 15273 | + if (gr_handle_rawio(nd->path.dentry->d_inode)) { |
50425a20 | 15274 | + error = -EPERM; |
15275 | + goto exit; | |
15276 | + } | |
15277 | + | |
4dee9bd5 | 15278 | + if (!gr_acl_handle_open(nd->path.dentry, nd->path.mnt, flag)) { |
50425a20 | 15279 | + error = -EACCES; |
15280 | + goto exit; | |
15281 | + } | |
15282 | + | |
15283 | goto ok; | |
15284 | } | |
15285 | ||
4dee9bd5 | 15286 | @@ -1785,6 +1819,23 @@ do_last: |
50425a20 | 15287 | /* |
15288 | * It already exists. | |
15289 | */ | |
15290 | + | |
15291 | + if (gr_handle_rawio(path.dentry->d_inode)) { | |
15292 | + mutex_unlock(&dir->d_inode->i_mutex); | |
15293 | + error = -EPERM; | |
15294 | + goto exit_dput; | |
15295 | + } | |
4dee9bd5 | 15296 | + if (!gr_acl_handle_open(path.dentry, nd->path.mnt, flag)) { |
50425a20 | 15297 | + mutex_unlock(&dir->d_inode->i_mutex); |
15298 | + error = -EACCES; | |
15299 | + goto exit_dput; | |
15300 | + } | |
4dee9bd5 | 15301 | + if (gr_handle_fifo(path.dentry, nd->path.mnt, dir, flag, acc_mode)) { |
50425a20 | 15302 | + mutex_unlock(&dir->d_inode->i_mutex); |
15303 | + error = -EACCES; | |
15304 | + goto exit_dput; | |
15305 | + } | |
15306 | + | |
15307 | mutex_unlock(&dir->d_inode->i_mutex); | |
da5b3fc8 | 15308 | audit_inode(pathname, path.dentry); |
50425a20 | 15309 | |
4dee9bd5 | 15310 | @@ -1840,6 +1891,13 @@ do_link: |
50425a20 | 15311 | error = security_inode_follow_link(path.dentry, nd); |
15312 | if (error) | |
15313 | goto exit_dput; | |
15314 | + | |
15315 | + if (gr_handle_follow_link(path.dentry->d_parent->d_inode, path.dentry->d_inode, | |
4dee9bd5 | 15316 | + path.dentry, nd->path.mnt)) { |
50425a20 | 15317 | + error = -EACCES; |
15318 | + goto exit_dput; | |
15319 | + } | |
15320 | + | |
15321 | error = __do_follow_link(&path, nd); | |
15322 | if (error) { | |
15323 | /* Does someone understand code flow here? Or it is only | |
4dee9bd5 | 15324 | @@ -1968,6 +2026,16 @@ asmlinkage long sys_mknodat(int dfd, con |
15325 | if (!IS_POSIXACL(nd.path.dentry->d_inode)) | |
50425a20 | 15326 | mode &= ~current->fs->umask; |
15327 | if (!IS_ERR(dentry)) { | |
4dee9bd5 | 15328 | + if (gr_handle_chroot_mknod(dentry, nd.path.mnt, mode)) { |
50425a20 | 15329 | + error = -EPERM; |
4dee9bd5 | 15330 | + goto out_free; |
50425a20 | 15331 | + } |
15332 | + | |
4dee9bd5 | 15333 | + if (!gr_acl_handle_mknod(dentry, nd.path.dentry, nd.path.mnt, mode)) { |
50425a20 | 15334 | + error = -EACCES; |
4dee9bd5 | 15335 | + goto out_free; |
50425a20 | 15336 | + } |
15337 | + | |
15338 | switch (mode & S_IFMT) { | |
15339 | case 0: case S_IFREG: | |
4dee9bd5 | 15340 | error = vfs_create(nd.path.dentry->d_inode,dentry,mode,&nd); |
15341 | @@ -1985,6 +2053,11 @@ asmlinkage long sys_mknodat(int dfd, con | |
50425a20 | 15342 | default: |
15343 | error = -EINVAL; | |
15344 | } | |
15345 | + | |
15346 | + if (!error) | |
4dee9bd5 | 15347 | + gr_handle_create(dentry, nd.path.mnt); |
50425a20 | 15348 | + |
4dee9bd5 | 15349 | +out_free: |
50425a20 | 15350 | dput(dentry); |
15351 | } | |
4dee9bd5 | 15352 | mutex_unlock(&nd.path.dentry->d_inode->i_mutex); |
15353 | @@ -2042,9 +2115,18 @@ asmlinkage long sys_mkdirat(int dfd, con | |
50425a20 | 15354 | if (IS_ERR(dentry)) |
15355 | goto out_unlock; | |
15356 | ||
4dee9bd5 | 15357 | + if (!gr_acl_handle_mkdir(dentry, nd.path.dentry, nd.path.mnt)) { |
50425a20 | 15358 | + error = -EACCES; |
15359 | + goto out_unlock_dput; | |
15360 | + } | |
15361 | + | |
4dee9bd5 | 15362 | if (!IS_POSIXACL(nd.path.dentry->d_inode)) |
50425a20 | 15363 | mode &= ~current->fs->umask; |
b79bc584 | 15364 | error = vfs_mkdir(nd.path.dentry->d_inode, dentry, mode, &nd); |
50425a20 | 15365 | + |
15366 | + if (!error) | |
4dee9bd5 | 15367 | + gr_handle_create(dentry, nd.path.mnt); |
50425a20 | 15368 | +out_unlock_dput: |
15369 | dput(dentry); | |
15370 | out_unlock: | |
4dee9bd5 | 15371 | mutex_unlock(&nd.path.dentry->d_inode->i_mutex); |
15372 | @@ -2126,6 +2208,8 @@ static long do_rmdir(int dfd, const char | |
50425a20 | 15373 | char * name; |
15374 | struct dentry *dentry; | |
15375 | struct nameidata nd; | |
15376 | + ino_t saved_ino = 0; | |
15377 | + dev_t saved_dev = 0; | |
15378 | ||
15379 | name = getname(pathname); | |
15380 | if(IS_ERR(name)) | |
4dee9bd5 | 15381 | @@ -2151,7 +2235,23 @@ static long do_rmdir(int dfd, const char |
50425a20 | 15382 | error = PTR_ERR(dentry); |
15383 | if (IS_ERR(dentry)) | |
15384 | goto exit2; | |
15385 | + | |
15386 | + if (dentry->d_inode != NULL) { | |
15387 | + if (dentry->d_inode->i_nlink <= 1) { | |
15388 | + saved_ino = dentry->d_inode->i_ino; | |
15389 | + saved_dev = dentry->d_inode->i_sb->s_dev; | |
15390 | + } | |
15391 | + | |
4dee9bd5 | 15392 | + if (!gr_acl_handle_rmdir(dentry, nd.path.mnt)) { |
50425a20 | 15393 | + error = -EACCES; |
15394 | + goto dput_exit2; | |
15395 | + } | |
15396 | + } | |
4dee9bd5 | 15397 | + |
b79bc584 | 15398 | error = vfs_rmdir(nd.path.dentry->d_inode, dentry, &nd); |
50425a20 | 15399 | + if (!error && (saved_dev || saved_ino)) |
15400 | + gr_handle_delete(saved_ino, saved_dev); | |
15401 | +dput_exit2: | |
15402 | dput(dentry); | |
15403 | exit2: | |
4dee9bd5 | 15404 | mutex_unlock(&nd.path.dentry->d_inode->i_mutex); |
15405 | @@ -2211,6 +2311,8 @@ static long do_unlinkat(int dfd, const c | |
50425a20 | 15406 | struct dentry *dentry; |
15407 | struct nameidata nd; | |
15408 | struct inode *inode = NULL; | |
15409 | + ino_t saved_ino = 0; | |
15410 | + dev_t saved_dev = 0; | |
15411 | ||
15412 | name = getname(pathname); | |
15413 | if(IS_ERR(name)) | |
4dee9bd5 | 15414 | @@ -2226,13 +2328,26 @@ static long do_unlinkat(int dfd, const c |
50425a20 | 15415 | dentry = lookup_hash(&nd); |
15416 | error = PTR_ERR(dentry); | |
15417 | if (!IS_ERR(dentry)) { | |
15418 | + error = 0; | |
15419 | /* Why not before? Because we want correct error value */ | |
15420 | if (nd.last.name[nd.last.len]) | |
15421 | goto slashes; | |
15422 | inode = dentry->d_inode; | |
15423 | - if (inode) | |
15424 | + if (inode) { | |
15425 | + if (inode->i_nlink <= 1) { | |
15426 | + saved_ino = inode->i_ino; | |
15427 | + saved_dev = inode->i_sb->s_dev; | |
15428 | + } | |
15429 | + | |
4dee9bd5 | 15430 | + if (!gr_acl_handle_unlink(dentry, nd.path.mnt)) |
50425a20 | 15431 | + error = -EACCES; |
15432 | + | |
15433 | atomic_inc(&inode->i_count); | |
b79bc584 | 15434 | - error = vfs_unlink(nd.path.dentry->d_inode, dentry, &nd); |
50425a20 | 15435 | + } |
15436 | + if (!error) | |
b79bc584 | 15437 | + error = vfs_unlink(nd.path.dentry->d_inode, dentry, &nd); |
50425a20 | 15438 | + if (!error && (saved_ino || saved_dev)) |
15439 | + gr_handle_delete(saved_ino, saved_dev); | |
15440 | exit2: | |
15441 | dput(dentry); | |
15442 | } | |
b79bc584 | 15443 | @@ -2313,8 +2428,18 @@ asmlinkage long sys_symlinkat(const char |
50425a20 | 15444 | if (IS_ERR(dentry)) |
15445 | goto out_unlock; | |
15446 | ||
4dee9bd5 | 15447 | + if (!gr_acl_handle_symlink(dentry, nd.path.dentry, nd.path.mnt, from)) { |
50425a20 | 15448 | + error = -EACCES; |
15449 | + goto out_dput_unlock; | |
15450 | + } | |
15451 | + | |
b79bc584 | 15452 | error = vfs_symlink(nd.path.dentry->d_inode, dentry, from, |
15453 | S_IALLUGO, &nd); | |
50425a20 | 15454 | + |
15455 | + if (!error) | |
4dee9bd5 | 15456 | + gr_handle_create(dentry, nd.path.mnt); |
15457 | + | |
50425a20 | 15458 | +out_dput_unlock: |
15459 | dput(dentry); | |
15460 | out_unlock: | |
4dee9bd5 | 15461 | mutex_unlock(&nd.path.dentry->d_inode->i_mutex); |
b79bc584 | 15462 | @@ -2408,8 +2533,27 @@ asmlinkage long sys_linkat(int olddfd, c |
50425a20 | 15463 | error = PTR_ERR(new_dentry); |
15464 | if (IS_ERR(new_dentry)) | |
15465 | goto out_unlock; | |
15466 | + | |
4dee9bd5 | 15467 | + if (gr_handle_hardlink(old_nd.path.dentry, old_nd.path.mnt, |
15468 | + old_nd.path.dentry->d_inode, | |
15469 | + old_nd.path.dentry->d_inode->i_mode, to)) { | |
50425a20 | 15470 | + error = -EACCES; |
15471 | + goto out_unlock_dput; | |
15472 | + } | |
15473 | + | |
4dee9bd5 | 15474 | + if (!gr_acl_handle_link(new_dentry, nd.path.dentry, nd.path.mnt, |
15475 | + old_nd.path.dentry, old_nd.path.mnt, to)) { | |
50425a20 | 15476 | + error = -EACCES; |
15477 | + goto out_unlock_dput; | |
15478 | + } | |
15479 | + | |
b79bc584 | 15480 | error = vfs_link(old_nd.path.dentry, nd.path.dentry->d_inode, |
15481 | new_dentry, &nd); | |
50425a20 | 15482 | + |
15483 | + if (!error) | |
4dee9bd5 | 15484 | + gr_handle_create(new_dentry, nd.path.mnt); |
15485 | + | |
50425a20 | 15486 | +out_unlock_dput: |
15487 | dput(new_dentry); | |
15488 | out_unlock: | |
4dee9bd5 | 15489 | mutex_unlock(&nd.path.dentry->d_inode->i_mutex); |
15490 | @@ -2634,8 +2778,16 @@ static int do_rename(int olddfd, const c | |
50425a20 | 15491 | if (new_dentry == trap) |
15492 | goto exit5; | |
15493 | ||
15494 | - error = vfs_rename(old_dir->d_inode, old_dentry, | |
4dee9bd5 | 15495 | + error = gr_acl_handle_rename(new_dentry, newnd.path.dentry, newnd.path.mnt, |
15496 | + old_dentry, old_dir->d_inode, oldnd.path.mnt, | |
50425a20 | 15497 | + newname); |
15498 | + | |
15499 | + if (!error) | |
15500 | + error = vfs_rename(old_dir->d_inode, old_dentry, | |
15501 | new_dir->d_inode, new_dentry); | |
15502 | + if (!error) | |
4dee9bd5 | 15503 | + gr_handle_rename(old_dir->d_inode, newnd.path.dentry->d_inode, old_dentry, |
15504 | + new_dentry, oldnd.path.mnt, new_dentry->d_inode ? 1 : 0); | |
50425a20 | 15505 | exit5: |
15506 | dput(new_dentry); | |
15507 | exit4: | |
4dee9bd5 | 15508 | diff -urNp linux-2.6.25.4/fs/namespace.c linux-2.6.25.4/fs/namespace.c |
15509 | --- linux-2.6.25.4/fs/namespace.c 2008-05-15 11:00:12.000000000 -0400 | |
15510 | +++ linux-2.6.25.4/fs/namespace.c 2008-05-18 13:33:16.000000000 -0400 | |
15511 | @@ -26,6 +26,7 @@ | |
b79bc584 | 15512 | #include <linux/vs_tag.h> |
15513 | #include <linux/vserver/space.h> | |
15514 | #include <linux/vserver/global.h> | |
50425a20 | 15515 | +#include <linux/grsecurity.h> |
15516 | #include <asm/uaccess.h> | |
15517 | #include <asm/unistd.h> | |
15518 | #include "pnode.h" | |
4dee9bd5 | 15519 | @@ -644,6 +645,8 @@ static int do_umount(struct vfsmount *mn |
50425a20 | 15520 | DQUOT_OFF(sb); |
15521 | retval = do_remount_sb(sb, MS_RDONLY, NULL, 0); | |
15522 | unlock_kernel(); | |
15523 | + | |
15524 | + gr_log_remount(mnt->mnt_devname, retval); | |
15525 | } | |
15526 | up_write(&sb->s_umount); | |
15527 | return retval; | |
4dee9bd5 | 15528 | @@ -667,6 +670,9 @@ static int do_umount(struct vfsmount *mn |
50425a20 | 15529 | security_sb_umount_busy(mnt); |
15530 | up_write(&namespace_sem); | |
15531 | release_mounts(&umount_list); | |
15532 | + | |
15533 | + gr_log_unmount(mnt->mnt_devname, retval); | |
15534 | + | |
15535 | return retval; | |
15536 | } | |
15537 | ||
4dee9bd5 | 15538 | @@ -1438,6 +1444,11 @@ long do_mount(char *dev_name, char *dir_ |
50425a20 | 15539 | if (retval) |
15540 | goto dput_out; | |
15541 | ||
4dee9bd5 | 15542 | + if (gr_handle_chroot_mount(nd.path.dentry, nd.path.mnt, dev_name)) { |
50425a20 | 15543 | + retval = -EPERM; |
15544 | + goto dput_out; | |
15545 | + } | |
15546 | + | |
15547 | if (flags & MS_REMOUNT) | |
15548 | retval = do_remount(&nd, flags & ~MS_REMOUNT, mnt_flags, | |
da5b3fc8 | 15549 | data_page); |
4dee9bd5 | 15550 | @@ -1452,6 +1463,9 @@ long do_mount(char *dev_name, char *dir_ |
50425a20 | 15551 | dev_name, data_page); |
15552 | dput_out: | |
4dee9bd5 | 15553 | path_put(&nd.path); |
50425a20 | 15554 | + |
15555 | + gr_log_mount(dev_name, dir_name, retval); | |
15556 | + | |
15557 | return retval; | |
15558 | } | |
15559 | ||
4dee9bd5 | 15560 | @@ -1681,6 +1695,9 @@ asmlinkage long sys_pivot_root(const cha |
50425a20 | 15561 | if (!capable(CAP_SYS_ADMIN)) |
15562 | return -EPERM; | |
15563 | ||
15564 | + if (gr_handle_chroot_pivot()) | |
15565 | + return -EPERM; | |
15566 | + | |
15567 | lock_kernel(); | |
15568 | ||
15569 | error = __user_walk(new_root, LOOKUP_FOLLOW | LOOKUP_DIRECTORY, | |
4dee9bd5 | 15570 | diff -urNp linux-2.6.25.4/fs/nfs/nfs4proc.c linux-2.6.25.4/fs/nfs/nfs4proc.c |
15571 | --- linux-2.6.25.4/fs/nfs/nfs4proc.c 2008-05-15 11:00:12.000000000 -0400 | |
15572 | +++ linux-2.6.25.4/fs/nfs/nfs4proc.c 2008-05-18 13:33:16.000000000 -0400 | |
15573 | @@ -653,7 +653,7 @@ static int _nfs4_do_open_reclaim(struct | |
da5b3fc8 | 15574 | static int nfs4_do_open_reclaim(struct nfs_open_context *ctx, struct nfs4_state *state) |
8a4b4a5e | 15575 | { |
15576 | struct nfs_server *server = NFS_SERVER(state->inode); | |
15577 | - struct nfs4_exception exception = { }; | |
15578 | + struct nfs4_exception exception = {0, 0}; | |
15579 | int err; | |
15580 | do { | |
1f8eda86 | 15581 | err = _nfs4_do_open_reclaim(ctx, state); |
4dee9bd5 | 15582 | @@ -695,7 +695,7 @@ static int _nfs4_open_delegation_recall( |
8a4b4a5e | 15583 | |
1f8eda86 | 15584 | int nfs4_open_delegation_recall(struct nfs_open_context *ctx, struct nfs4_state *state, const nfs4_stateid *stateid) |
8a4b4a5e | 15585 | { |
15586 | - struct nfs4_exception exception = { }; | |
15587 | + struct nfs4_exception exception = {0, 0}; | |
83a957c9 | 15588 | struct nfs_server *server = NFS_SERVER(state->inode); |
8a4b4a5e | 15589 | int err; |
15590 | do { | |
4dee9bd5 | 15591 | @@ -991,7 +991,7 @@ static int _nfs4_open_expired(struct nfs |
da5b3fc8 | 15592 | static inline int nfs4_do_open_expired(struct nfs_open_context *ctx, struct nfs4_state *state) |
8a4b4a5e | 15593 | { |
83a957c9 | 15594 | struct nfs_server *server = NFS_SERVER(state->inode); |
8a4b4a5e | 15595 | - struct nfs4_exception exception = { }; |
15596 | + struct nfs4_exception exception = {0, 0}; | |
15597 | int err; | |
15598 | ||
15599 | do { | |
4dee9bd5 | 15600 | @@ -1093,7 +1093,7 @@ out_err: |
da5b3fc8 | 15601 | |
15602 | static struct nfs4_state *nfs4_do_open(struct inode *dir, struct path *path, int flags, struct iattr *sattr, struct rpc_cred *cred) | |
15603 | { | |
15604 | - struct nfs4_exception exception = { }; | |
15605 | + struct nfs4_exception exception = {0, 0}; | |
15606 | struct nfs4_state *res; | |
15607 | int status; | |
15608 | ||
4dee9bd5 | 15609 | @@ -1182,7 +1182,7 @@ static int nfs4_do_setattr(struct inode |
8a4b4a5e | 15610 | struct iattr *sattr, struct nfs4_state *state) |
15611 | { | |
15612 | struct nfs_server *server = NFS_SERVER(inode); | |
15613 | - struct nfs4_exception exception = { }; | |
15614 | + struct nfs4_exception exception = {0, 0}; | |
15615 | int err; | |
15616 | do { | |
15617 | err = nfs4_handle_exception(server, | |
4dee9bd5 | 15618 | @@ -1495,7 +1495,7 @@ static int _nfs4_server_capabilities(str |
8a4b4a5e | 15619 | |
15620 | int nfs4_server_capabilities(struct nfs_server *server, struct nfs_fh *fhandle) | |
15621 | { | |
15622 | - struct nfs4_exception exception = { }; | |
15623 | + struct nfs4_exception exception = {0, 0}; | |
15624 | int err; | |
15625 | do { | |
15626 | err = nfs4_handle_exception(server, | |
4dee9bd5 | 15627 | @@ -1528,7 +1528,7 @@ static int _nfs4_lookup_root(struct nfs_ |
8a4b4a5e | 15628 | static int nfs4_lookup_root(struct nfs_server *server, struct nfs_fh *fhandle, |
15629 | struct nfs_fsinfo *info) | |
15630 | { | |
15631 | - struct nfs4_exception exception = { }; | |
15632 | + struct nfs4_exception exception = {0, 0}; | |
15633 | int err; | |
15634 | do { | |
15635 | err = nfs4_handle_exception(server, | |
4dee9bd5 | 15636 | @@ -1617,7 +1617,7 @@ static int _nfs4_proc_getattr(struct nfs |
8a4b4a5e | 15637 | |
15638 | static int nfs4_proc_getattr(struct nfs_server *server, struct nfs_fh *fhandle, struct nfs_fattr *fattr) | |
15639 | { | |
15640 | - struct nfs4_exception exception = { }; | |
15641 | + struct nfs4_exception exception = {0, 0}; | |
15642 | int err; | |
15643 | do { | |
15644 | err = nfs4_handle_exception(server, | |
4dee9bd5 | 15645 | @@ -1707,7 +1707,7 @@ static int nfs4_proc_lookupfh(struct nfs |
8a4b4a5e | 15646 | struct qstr *name, struct nfs_fh *fhandle, |
15647 | struct nfs_fattr *fattr) | |
15648 | { | |
15649 | - struct nfs4_exception exception = { }; | |
15650 | + struct nfs4_exception exception = {0, 0}; | |
15651 | int err; | |
15652 | do { | |
da5b3fc8 | 15653 | err = _nfs4_proc_lookupfh(server, dirfh, name, fhandle, fattr); |
4dee9bd5 | 15654 | @@ -1736,7 +1736,7 @@ static int _nfs4_proc_lookup(struct inod |
8a4b4a5e | 15655 | |
15656 | static int nfs4_proc_lookup(struct inode *dir, struct qstr *name, struct nfs_fh *fhandle, struct nfs_fattr *fattr) | |
15657 | { | |
15658 | - struct nfs4_exception exception = { }; | |
15659 | + struct nfs4_exception exception = {0, 0}; | |
15660 | int err; | |
15661 | do { | |
15662 | err = nfs4_handle_exception(NFS_SERVER(dir), | |
4dee9bd5 | 15663 | @@ -1800,7 +1800,7 @@ static int _nfs4_proc_access(struct inod |
8a4b4a5e | 15664 | |
15665 | static int nfs4_proc_access(struct inode *inode, struct nfs_access_entry *entry) | |
15666 | { | |
15667 | - struct nfs4_exception exception = { }; | |
15668 | + struct nfs4_exception exception = {0, 0}; | |
15669 | int err; | |
15670 | do { | |
15671 | err = nfs4_handle_exception(NFS_SERVER(inode), | |
4dee9bd5 | 15672 | @@ -1855,7 +1855,7 @@ static int _nfs4_proc_readlink(struct in |
8a4b4a5e | 15673 | static int nfs4_proc_readlink(struct inode *inode, struct page *page, |
15674 | unsigned int pgbase, unsigned int pglen) | |
15675 | { | |
15676 | - struct nfs4_exception exception = { }; | |
15677 | + struct nfs4_exception exception = {0, 0}; | |
15678 | int err; | |
15679 | do { | |
15680 | err = nfs4_handle_exception(NFS_SERVER(inode), | |
4dee9bd5 | 15681 | @@ -1951,7 +1951,7 @@ static int _nfs4_proc_remove(struct inod |
8a4b4a5e | 15682 | |
15683 | static int nfs4_proc_remove(struct inode *dir, struct qstr *name) | |
15684 | { | |
15685 | - struct nfs4_exception exception = { }; | |
15686 | + struct nfs4_exception exception = {0, 0}; | |
15687 | int err; | |
15688 | do { | |
15689 | err = nfs4_handle_exception(NFS_SERVER(dir), | |
4dee9bd5 | 15690 | @@ -2023,7 +2023,7 @@ static int _nfs4_proc_rename(struct inod |
8a4b4a5e | 15691 | static int nfs4_proc_rename(struct inode *old_dir, struct qstr *old_name, |
15692 | struct inode *new_dir, struct qstr *new_name) | |
15693 | { | |
15694 | - struct nfs4_exception exception = { }; | |
15695 | + struct nfs4_exception exception = {0, 0}; | |
15696 | int err; | |
15697 | do { | |
15698 | err = nfs4_handle_exception(NFS_SERVER(old_dir), | |
4dee9bd5 | 15699 | @@ -2070,7 +2070,7 @@ static int _nfs4_proc_link(struct inode |
8a4b4a5e | 15700 | |
15701 | static int nfs4_proc_link(struct inode *inode, struct inode *dir, struct qstr *name) | |
15702 | { | |
15703 | - struct nfs4_exception exception = { }; | |
15704 | + struct nfs4_exception exception = {0, 0}; | |
15705 | int err; | |
15706 | do { | |
15707 | err = nfs4_handle_exception(NFS_SERVER(inode), | |
4dee9bd5 | 15708 | @@ -2127,7 +2127,7 @@ static int _nfs4_proc_symlink(struct ino |
8a4b4a5e | 15709 | static int nfs4_proc_symlink(struct inode *dir, struct dentry *dentry, |
15710 | struct page *page, unsigned int len, struct iattr *sattr) | |
15711 | { | |
15712 | - struct nfs4_exception exception = { }; | |
15713 | + struct nfs4_exception exception = {0, 0}; | |
15714 | int err; | |
15715 | do { | |
15716 | err = nfs4_handle_exception(NFS_SERVER(dir), | |
4dee9bd5 | 15717 | @@ -2180,7 +2180,7 @@ static int _nfs4_proc_mkdir(struct inode |
8a4b4a5e | 15718 | static int nfs4_proc_mkdir(struct inode *dir, struct dentry *dentry, |
15719 | struct iattr *sattr) | |
15720 | { | |
15721 | - struct nfs4_exception exception = { }; | |
15722 | + struct nfs4_exception exception = {0, 0}; | |
15723 | int err; | |
15724 | do { | |
15725 | err = nfs4_handle_exception(NFS_SERVER(dir), | |
4dee9bd5 | 15726 | @@ -2229,7 +2229,7 @@ static int _nfs4_proc_readdir(struct den |
8a4b4a5e | 15727 | static int nfs4_proc_readdir(struct dentry *dentry, struct rpc_cred *cred, |
15728 | u64 cookie, struct page *page, unsigned int count, int plus) | |
15729 | { | |
15730 | - struct nfs4_exception exception = { }; | |
15731 | + struct nfs4_exception exception = {0, 0}; | |
15732 | int err; | |
15733 | do { | |
da5b3fc8 | 15734 | err = nfs4_handle_exception(NFS_SERVER(dentry->d_inode), |
4dee9bd5 | 15735 | @@ -2299,7 +2299,7 @@ static int _nfs4_proc_mknod(struct inode |
8a4b4a5e | 15736 | static int nfs4_proc_mknod(struct inode *dir, struct dentry *dentry, |
15737 | struct iattr *sattr, dev_t rdev) | |
15738 | { | |
15739 | - struct nfs4_exception exception = { }; | |
15740 | + struct nfs4_exception exception = {0, 0}; | |
15741 | int err; | |
15742 | do { | |
15743 | err = nfs4_handle_exception(NFS_SERVER(dir), | |
4dee9bd5 | 15744 | @@ -2328,7 +2328,7 @@ static int _nfs4_proc_statfs(struct nfs_ |
8a4b4a5e | 15745 | |
15746 | static int nfs4_proc_statfs(struct nfs_server *server, struct nfs_fh *fhandle, struct nfs_fsstat *fsstat) | |
15747 | { | |
15748 | - struct nfs4_exception exception = { }; | |
15749 | + struct nfs4_exception exception = {0, 0}; | |
15750 | int err; | |
15751 | do { | |
15752 | err = nfs4_handle_exception(server, | |
4dee9bd5 | 15753 | @@ -2356,7 +2356,7 @@ static int _nfs4_do_fsinfo(struct nfs_se |
8a4b4a5e | 15754 | |
15755 | static int nfs4_do_fsinfo(struct nfs_server *server, struct nfs_fh *fhandle, struct nfs_fsinfo *fsinfo) | |
15756 | { | |
15757 | - struct nfs4_exception exception = { }; | |
15758 | + struct nfs4_exception exception = {0, 0}; | |
15759 | int err; | |
15760 | ||
15761 | do { | |
4dee9bd5 | 15762 | @@ -2399,7 +2399,7 @@ static int _nfs4_proc_pathconf(struct nf |
8a4b4a5e | 15763 | static int nfs4_proc_pathconf(struct nfs_server *server, struct nfs_fh *fhandle, |
15764 | struct nfs_pathconf *pathconf) | |
15765 | { | |
15766 | - struct nfs4_exception exception = { }; | |
15767 | + struct nfs4_exception exception = {0, 0}; | |
15768 | int err; | |
15769 | ||
15770 | do { | |
4dee9bd5 | 15771 | @@ -2686,7 +2686,7 @@ out_free: |
8a4b4a5e | 15772 | |
15773 | static ssize_t nfs4_get_acl_uncached(struct inode *inode, void *buf, size_t buflen) | |
15774 | { | |
15775 | - struct nfs4_exception exception = { }; | |
15776 | + struct nfs4_exception exception = {0, 0}; | |
15777 | ssize_t ret; | |
15778 | do { | |
15779 | ret = __nfs4_get_acl_uncached(inode, buf, buflen); | |
4dee9bd5 | 15780 | @@ -2740,7 +2740,7 @@ static int __nfs4_proc_set_acl(struct in |
8a4b4a5e | 15781 | |
15782 | static int nfs4_proc_set_acl(struct inode *inode, const void *buf, size_t buflen) | |
15783 | { | |
15784 | - struct nfs4_exception exception = { }; | |
15785 | + struct nfs4_exception exception = {0, 0}; | |
15786 | int err; | |
15787 | do { | |
15788 | err = nfs4_handle_exception(NFS_SERVER(inode), | |
4dee9bd5 | 15789 | @@ -3032,7 +3032,7 @@ out: |
15790 | int nfs4_proc_delegreturn(struct inode *inode, struct rpc_cred *cred, const nfs4_stateid *stateid, int issync) | |
8a4b4a5e | 15791 | { |
15792 | struct nfs_server *server = NFS_SERVER(inode); | |
15793 | - struct nfs4_exception exception = { }; | |
15794 | + struct nfs4_exception exception = {0, 0}; | |
15795 | int err; | |
15796 | do { | |
4dee9bd5 | 15797 | err = _nfs4_proc_delegreturn(inode, cred, stateid, issync); |
15798 | @@ -3107,7 +3107,7 @@ out: | |
8a4b4a5e | 15799 | |
15800 | static int nfs4_proc_getlk(struct nfs4_state *state, int cmd, struct file_lock *request) | |
15801 | { | |
15802 | - struct nfs4_exception exception = { }; | |
15803 | + struct nfs4_exception exception = {0, 0}; | |
15804 | int err; | |
15805 | ||
15806 | do { | |
4dee9bd5 | 15807 | @@ -3453,7 +3453,7 @@ static int _nfs4_do_setlk(struct nfs4_st |
8a4b4a5e | 15808 | static int nfs4_lock_reclaim(struct nfs4_state *state, struct file_lock *request) |
15809 | { | |
15810 | struct nfs_server *server = NFS_SERVER(state->inode); | |
15811 | - struct nfs4_exception exception = { }; | |
15812 | + struct nfs4_exception exception = {0, 0}; | |
15813 | int err; | |
15814 | ||
15815 | do { | |
4dee9bd5 | 15816 | @@ -3471,7 +3471,7 @@ static int nfs4_lock_reclaim(struct nfs4 |
8a4b4a5e | 15817 | static int nfs4_lock_expired(struct nfs4_state *state, struct file_lock *request) |
15818 | { | |
15819 | struct nfs_server *server = NFS_SERVER(state->inode); | |
15820 | - struct nfs4_exception exception = { }; | |
15821 | + struct nfs4_exception exception = {0, 0}; | |
15822 | int err; | |
15823 | ||
15824 | err = nfs4_set_lock_state(state, request); | |
4dee9bd5 | 15825 | @@ -3532,7 +3532,7 @@ out: |
8a4b4a5e | 15826 | |
15827 | static int nfs4_proc_setlk(struct nfs4_state *state, int cmd, struct file_lock *request) | |
15828 | { | |
15829 | - struct nfs4_exception exception = { }; | |
15830 | + struct nfs4_exception exception = {0, 0}; | |
15831 | int err; | |
15832 | ||
15833 | do { | |
4dee9bd5 | 15834 | @@ -3582,7 +3582,7 @@ nfs4_proc_lock(struct file *filp, int cm |
8a4b4a5e | 15835 | int nfs4_lock_delegation_recall(struct nfs4_state *state, struct file_lock *fl) |
15836 | { | |
15837 | struct nfs_server *server = NFS_SERVER(state->inode); | |
15838 | - struct nfs4_exception exception = { }; | |
15839 | + struct nfs4_exception exception = {0, 0}; | |
15840 | int err; | |
15841 | ||
15842 | err = nfs4_set_lock_state(state, fl); | |
4dee9bd5 | 15843 | diff -urNp linux-2.6.25.4/fs/nfsd/export.c linux-2.6.25.4/fs/nfsd/export.c |
15844 | --- linux-2.6.25.4/fs/nfsd/export.c 2008-05-15 11:00:12.000000000 -0400 | |
15845 | +++ linux-2.6.25.4/fs/nfsd/export.c 2008-05-18 13:33:16.000000000 -0400 | |
15846 | @@ -472,7 +472,7 @@ static int secinfo_parse(char **mesg, ch | |
da5b3fc8 | 15847 | * probably discover the problem when someone fails to |
15848 | * authenticate. | |
15849 | */ | |
15850 | - if (f->pseudoflavor < 0) | |
15851 | + if ((s32)f->pseudoflavor < 0) | |
15852 | return -EINVAL; | |
15853 | err = get_int(mesg, &f->flags); | |
15854 | if (err) | |
4dee9bd5 | 15855 | diff -urNp linux-2.6.25.4/fs/nls/nls_base.c linux-2.6.25.4/fs/nls/nls_base.c |
15856 | --- linux-2.6.25.4/fs/nls/nls_base.c 2008-05-15 11:00:12.000000000 -0400 | |
15857 | +++ linux-2.6.25.4/fs/nls/nls_base.c 2008-05-18 13:33:16.000000000 -0400 | |
da5b3fc8 | 15858 | @@ -42,7 +42,7 @@ static const struct utf8_table utf8_tabl |
50425a20 | 15859 | {0xF8, 0xF0, 3*6, 0x1FFFFF, 0x10000, /* 4 byte sequence */}, |
15860 | {0xFC, 0xF8, 4*6, 0x3FFFFFF, 0x200000, /* 5 byte sequence */}, | |
15861 | {0xFE, 0xFC, 5*6, 0x7FFFFFFF, 0x4000000, /* 6 byte sequence */}, | |
15862 | - {0, /* end of table */} | |
15863 | + {0, 0, 0, 0, 0, /* end of table */} | |
15864 | }; | |
15865 | ||
15866 | int | |
4dee9bd5 | 15867 | diff -urNp linux-2.6.25.4/fs/ntfs/file.c linux-2.6.25.4/fs/ntfs/file.c |
15868 | --- linux-2.6.25.4/fs/ntfs/file.c 2008-05-15 11:00:12.000000000 -0400 | |
15869 | +++ linux-2.6.25.4/fs/ntfs/file.c 2008-05-18 13:33:16.000000000 -0400 | |
15870 | @@ -2291,6 +2291,6 @@ const struct inode_operations ntfs_file_ | |
50425a20 | 15871 | #endif /* NTFS_RW */ |
15872 | }; | |
15873 | ||
15874 | -const struct file_operations ntfs_empty_file_ops = {}; | |
15875 | +const struct file_operations ntfs_empty_file_ops; | |
15876 | ||
15877 | -const struct inode_operations ntfs_empty_inode_ops = {}; | |
15878 | +const struct inode_operations ntfs_empty_inode_ops; | |
4dee9bd5 | 15879 | diff -urNp linux-2.6.25.4/fs/open.c linux-2.6.25.4/fs/open.c |
15880 | --- linux-2.6.25.4/fs/open.c 2008-05-15 11:00:12.000000000 -0400 | |
15881 | +++ linux-2.6.25.4/fs/open.c 2008-05-18 13:33:16.000000000 -0400 | |
da5b3fc8 | 15882 | @@ -27,6 +27,7 @@ |
b79bc584 | 15883 | #include <linux/vs_dlimit.h> |
15884 | #include <linux/vs_tag.h> | |
15885 | #include <linux/vs_cowbl.h> | |
50425a20 | 15886 | +#include <linux/grsecurity.h> |
15887 | ||
15888 | int vfs_statfs(struct dentry *dentry, struct kstatfs *buf) | |
15889 | { | |
da5b3fc8 | 15890 | @@ -204,6 +205,9 @@ int do_truncate(struct dentry *dentry, l |
50425a20 | 15891 | if (length < 0) |
15892 | return -EINVAL; | |
15893 | ||
4dee9bd5 | 15894 | + if (filp && !gr_acl_handle_truncate(dentry, filp->f_path.mnt)) |
50425a20 | 15895 | + return -EACCES; |
15896 | + | |
15897 | newattrs.ia_size = length; | |
15898 | newattrs.ia_valid = ATTR_SIZE | time_attrs; | |
15899 | if (filp) { | |
da5b3fc8 | 15900 | @@ -461,6 +465,9 @@ asmlinkage long sys_faccessat(int dfd, c |
4dee9bd5 | 15901 | if(IS_RDONLY(nd.path.dentry->d_inode)) |
50425a20 | 15902 | res = -EROFS; |
15903 | ||
4dee9bd5 | 15904 | + if (!res && !gr_acl_handle_access(nd.path.dentry, nd.path.mnt, mode)) |
50425a20 | 15905 | + res = -EACCES; |
15906 | + | |
15907 | out_path_release: | |
4dee9bd5 | 15908 | path_put(&nd.path); |
50425a20 | 15909 | out: |
da5b3fc8 | 15910 | @@ -490,6 +497,8 @@ asmlinkage long sys_chdir(const char __u |
50425a20 | 15911 | if (error) |
15912 | goto dput_and_out; | |
15913 | ||
4dee9bd5 | 15914 | + gr_log_chdir(nd.path.dentry, nd.path.mnt); |
50425a20 | 15915 | + |
4dee9bd5 | 15916 | set_fs_pwd(current->fs, &nd.path); |
50425a20 | 15917 | |
15918 | dput_and_out: | |
4dee9bd5 | 15919 | @@ -516,6 +525,13 @@ asmlinkage long sys_fchdir(unsigned int |
50425a20 | 15920 | goto out_putf; |
15921 | ||
15922 | error = file_permission(file, MAY_EXEC); | |
15923 | + | |
4dee9bd5 | 15924 | + if (!error && !gr_chroot_fchdir(file->f_path.dentry, file->f_path.mnt)) |
50425a20 | 15925 | + error = -EPERM; |
15926 | + | |
15927 | + if (!error) | |
4dee9bd5 | 15928 | + gr_log_chdir(file->f_path.dentry, file->f_path.mnt); |
50425a20 | 15929 | + |
15930 | if (!error) | |
4dee9bd5 | 15931 | set_fs_pwd(current->fs, &file->f_path); |
50425a20 | 15932 | out_putf: |
4dee9bd5 | 15933 | @@ -541,8 +557,16 @@ asmlinkage long sys_chroot(const char __ |
50425a20 | 15934 | if (!capable(CAP_SYS_CHROOT)) |
15935 | goto dput_and_out; | |
15936 | ||
4dee9bd5 | 15937 | + if (gr_handle_chroot_chroot(nd.path.dentry, nd.path.mnt)) |
50425a20 | 15938 | + goto dput_and_out; |
15939 | + | |
4dee9bd5 | 15940 | set_fs_root(current->fs, &nd.path); |
50425a20 | 15941 | set_fs_altroot(); |
15942 | + | |
15943 | + gr_handle_chroot_caps(current); | |
15944 | + | |
4dee9bd5 | 15945 | + gr_handle_chroot_chdir(&nd.path); |
50425a20 | 15946 | + |
15947 | error = 0; | |
15948 | dput_and_out: | |
4dee9bd5 | 15949 | path_put(&nd.path); |
15950 | @@ -573,9 +597,22 @@ asmlinkage long sys_fchmod(unsigned int | |
50425a20 | 15951 | err = -EPERM; |
15952 | if (IS_IMMUTABLE(inode) || IS_APPEND(inode)) | |
15953 | goto out_putf; | |
15954 | + | |
4dee9bd5 | 15955 | + if (!gr_acl_handle_fchmod(dentry, file->f_path.mnt, mode)) { |
50425a20 | 15956 | + err = -EACCES; |
15957 | + goto out_putf; | |
15958 | + } | |
15959 | + | |
15960 | mutex_lock(&inode->i_mutex); | |
15961 | if (mode == (mode_t) -1) | |
15962 | mode = inode->i_mode; | |
15963 | + | |
4dee9bd5 | 15964 | + if (gr_handle_chroot_chmod(dentry, file->f_path.mnt, mode)) { |
50425a20 | 15965 | + err = -EPERM; |
15966 | + mutex_unlock(&inode->i_mutex); | |
15967 | + goto out_putf; | |
15968 | + } | |
15969 | + | |
15970 | newattrs.ia_mode = (mode & S_IALLUGO) | (inode->i_mode & ~S_IALLUGO); | |
15971 | newattrs.ia_valid = ATTR_MODE | ATTR_CTIME; | |
15972 | err = notify_change(dentry, &newattrs); | |
4dee9bd5 | 15973 | @@ -608,9 +645,21 @@ asmlinkage long sys_fchmodat(int dfd, co |
50425a20 | 15974 | if (IS_IMMUTABLE(inode) || IS_APPEND(inode)) |
15975 | goto dput_and_out; | |
15976 | ||
4dee9bd5 | 15977 | + if (!gr_acl_handle_chmod(nd.path.dentry, nd.path.mnt, mode)) { |
50425a20 | 15978 | + error = -EACCES; |
15979 | + goto dput_and_out; | |
15980 | + }; | |
15981 | + | |
15982 | mutex_lock(&inode->i_mutex); | |
15983 | if (mode == (mode_t) -1) | |
15984 | mode = inode->i_mode; | |
15985 | + | |
4dee9bd5 | 15986 | + if (gr_handle_chroot_chmod(nd.path.dentry, nd.path.mnt, mode)) { |
50425a20 | 15987 | + error = -EACCES; |
15988 | + mutex_unlock(&inode->i_mutex); | |
15989 | + goto dput_and_out; | |
15990 | + } | |
15991 | + | |
15992 | newattrs.ia_mode = (mode & S_IALLUGO) | (inode->i_mode & ~S_IALLUGO); | |
15993 | newattrs.ia_valid = ATTR_MODE | ATTR_CTIME; | |
4dee9bd5 | 15994 | error = notify_change(nd.path.dentry, &newattrs); |
4dee9bd5 | 15995 | @@ -644,6 +693,12 @@ static int chown_common(struct dentry * |
50425a20 | 15996 | error = -EPERM; |
15997 | if (IS_IMMUTABLE(inode) || IS_APPEND(inode)) | |
15998 | goto out; | |
15999 | + | |
16000 | + if (!gr_acl_handle_chown(dentry, mnt)) { | |
16001 | + error = -EACCES; | |
16002 | + goto out; | |
16003 | + } | |
16004 | + | |
16005 | newattrs.ia_valid = ATTR_CTIME; | |
16006 | if (user != (uid_t) -1) { | |
16007 | newattrs.ia_valid |= ATTR_UID; | |
4dee9bd5 | 16008 | @@ -948,6 +1003,7 @@ repeat: |
50425a20 | 16009 | * N.B. For clone tasks sharing a files structure, this test |
16010 | * will limit the total number of files that can be opened. | |
16011 | */ | |
16012 | + gr_learn_resource(current, RLIMIT_NOFILE, fd, 0); | |
16013 | if (fd >= current->signal->rlim[RLIMIT_NOFILE].rlim_cur) | |
16014 | goto out; | |
16015 | ||
4dee9bd5 | 16016 | diff -urNp linux-2.6.25.4/fs/partitions/efi.c linux-2.6.25.4/fs/partitions/efi.c |
16017 | --- linux-2.6.25.4/fs/partitions/efi.c 2008-05-15 11:00:12.000000000 -0400 | |
16018 | +++ linux-2.6.25.4/fs/partitions/efi.c 2008-05-18 13:33:16.000000000 -0400 | |
50425a20 | 16019 | @@ -99,7 +99,7 @@ |
16020 | #ifdef EFI_DEBUG | |
16021 | #define Dprintk(x...) printk(KERN_DEBUG x) | |
16022 | #else | |
16023 | -#define Dprintk(x...) | |
16024 | +#define Dprintk(x...) do {} while (0) | |
16025 | #endif | |
16026 | ||
16027 | /* This allows a kernel command line option 'gpt' to override | |
4dee9bd5 | 16028 | diff -urNp linux-2.6.25.4/fs/pipe.c linux-2.6.25.4/fs/pipe.c |
16029 | --- linux-2.6.25.4/fs/pipe.c 2008-05-15 11:00:12.000000000 -0400 | |
16030 | +++ linux-2.6.25.4/fs/pipe.c 2008-05-18 13:33:16.000000000 -0400 | |
16031 | @@ -885,7 +885,7 @@ void free_pipe_info(struct inode *inode) | |
50425a20 | 16032 | inode->i_pipe = NULL; |
16033 | } | |
16034 | ||
16035 | -static struct vfsmount *pipe_mnt __read_mostly; | |
16036 | +struct vfsmount *pipe_mnt __read_mostly; | |
16037 | static int pipefs_delete_dentry(struct dentry *dentry) | |
16038 | { | |
16039 | /* | |
4dee9bd5 | 16040 | diff -urNp linux-2.6.25.4/fs/proc/array.c linux-2.6.25.4/fs/proc/array.c |
16041 | --- linux-2.6.25.4/fs/proc/array.c 2008-05-15 11:00:12.000000000 -0400 | |
16042 | +++ linux-2.6.25.4/fs/proc/array.c 2008-05-18 13:33:16.000000000 -0400 | |
16043 | @@ -308,6 +308,21 @@ static inline void task_context_switch_c | |
16044 | p->nivcsw); | |
50425a20 | 16045 | } |
16046 | ||
16047 | +#if defined(CONFIG_PAX_NOEXEC) || defined(CONFIG_PAX_ASLR) | |
4dee9bd5 | 16048 | +static inline void task_pax(struct seq_file *m, struct task_struct *p) |
50425a20 | 16049 | +{ |
16050 | + if (p->mm) | |
4dee9bd5 | 16051 | + seq_printf(m, "PaX:\t%c%c%c%c%c\n", |
16052 | + p->mm->pax_flags & MF_PAX_PAGEEXEC ? 'P' : 'p', | |
16053 | + p->mm->pax_flags & MF_PAX_EMUTRAMP ? 'E' : 'e', | |
16054 | + p->mm->pax_flags & MF_PAX_MPROTECT ? 'M' : 'm', | |
16055 | + p->mm->pax_flags & MF_PAX_RANDMMAP ? 'R' : 'r', | |
16056 | + p->mm->pax_flags & MF_PAX_SEGMEXEC ? 'S' : 's'); | |
50425a20 | 16057 | + else |
4dee9bd5 | 16058 | + seq_printf(m, "PaX:\t-----\n"); |
50425a20 | 16059 | +} |
16060 | +#endif | |
16061 | + | |
b79bc584 | 16062 | int proc_pid_nsproxy(struct seq_file *m, struct pid_namespace *ns, |
4dee9bd5 | 16063 | struct pid *pid, struct task_struct *task) |
50425a20 | 16064 | { |
4dee9bd5 | 16065 | @@ -327,6 +342,11 @@ int proc_pid_status(struct seq_file *m, |
16066 | task_show_regs(m, task); | |
50425a20 | 16067 | #endif |
4dee9bd5 | 16068 | task_context_switch_counts(m, task); |
50425a20 | 16069 | + |
16070 | +#if defined(CONFIG_PAX_NOEXEC) || defined(CONFIG_PAX_ASLR) | |
4dee9bd5 | 16071 | + task_pax(m, task); |
50425a20 | 16072 | +#endif |
16073 | + | |
4dee9bd5 | 16074 | return 0; |
50425a20 | 16075 | } |
16076 | ||
4dee9bd5 | 16077 | @@ -389,6 +409,12 @@ static cputime_t task_gtime(struct task_ |
da5b3fc8 | 16078 | return p->gtime; |
16079 | } | |
16080 | ||
50425a20 | 16081 | +#ifdef CONFIG_GRKERNSEC_PROC_MEMMAP |
16082 | +#define PAX_RAND_FLAGS(_mm) (_mm != NULL && _mm != current->mm && \ | |
4dee9bd5 | 16083 | + (_mm->pax_flags & MF_PAX_RANDMMAP || \ |
16084 | + _mm->pax_flags & MF_PAX_SEGMEXEC)) | |
50425a20 | 16085 | +#endif |
16086 | + | |
4dee9bd5 | 16087 | static int do_task_stat(struct seq_file *m, struct pid_namespace *ns, |
16088 | struct pid *pid, struct task_struct *task, int whole) | |
50425a20 | 16089 | { |
4dee9bd5 | 16090 | @@ -481,6 +507,19 @@ static int do_task_stat(struct seq_file |
da5b3fc8 | 16091 | gtime = task_gtime(task); |
50425a20 | 16092 | } |
16093 | ||
16094 | +#ifdef CONFIG_GRKERNSEC_PROC_MEMMAP | |
16095 | + if (PAX_RAND_FLAGS(mm)) { | |
16096 | + eip = 0; | |
16097 | + esp = 0; | |
16098 | + wchan = 0; | |
16099 | + } | |
16100 | +#endif | |
16101 | +#ifdef CONFIG_GRKERNSEC_HIDESYM | |
16102 | + wchan = 0; | |
16103 | + eip =0; | |
16104 | + esp =0; | |
16105 | +#endif | |
16106 | + | |
16107 | /* scale priority and nice values from timeslices to -20..20 */ | |
16108 | /* to make it look like a "normal" Unix priority/nice value */ | |
16109 | priority = task_prio(task); | |
4dee9bd5 | 16110 | @@ -521,9 +560,15 @@ static int do_task_stat(struct seq_file |
50425a20 | 16111 | vsize, |
16112 | mm ? get_mm_rss(mm) : 0, | |
da5b3fc8 | 16113 | rsslim, |
50425a20 | 16114 | +#ifdef CONFIG_GRKERNSEC_PROC_MEMMAP |
16115 | + PAX_RAND_FLAGS(mm) ? 1 : (mm ? mm->start_code : 0), | |
16116 | + PAX_RAND_FLAGS(mm) ? 1 : (mm ? mm->end_code : 0), | |
16117 | + PAX_RAND_FLAGS(mm) ? 0 : (mm ? mm->start_stack : 0), | |
16118 | +#else | |
16119 | mm ? mm->start_code : 0, | |
16120 | mm ? mm->end_code : 0, | |
16121 | mm ? mm->start_stack : 0, | |
16122 | +#endif | |
16123 | esp, | |
16124 | eip, | |
16125 | /* The signal information here is obsolete. | |
4dee9bd5 | 16126 | @@ -576,3 +621,13 @@ int proc_pid_statm(struct seq_file *m, s |
16127 | ||
16128 | return 0; | |
50425a20 | 16129 | } |
16130 | + | |
16131 | +#ifdef CONFIG_GRKERNSEC_PROC_IPADDR | |
4dee9bd5 | 16132 | +int proc_pid_ipaddr(struct seq_file *m, struct pid_namespace *ns, |
16133 | + struct pid *pid, struct task_struct *task) | |
50425a20 | 16134 | +{ |
4dee9bd5 | 16135 | + seq_printf(m, "%u.%u.%u.%u\n", NIPQUAD(task->signal->curr_ip)); |
50425a20 | 16136 | + |
4dee9bd5 | 16137 | + return 0; |
50425a20 | 16138 | +} |
16139 | +#endif | |
4dee9bd5 | 16140 | diff -urNp linux-2.6.25.4/fs/proc/base.c linux-2.6.25.4/fs/proc/base.c |
16141 | --- linux-2.6.25.4/fs/proc/base.c 2008-05-15 11:00:12.000000000 -0400 | |
16142 | +++ linux-2.6.25.4/fs/proc/base.c 2008-05-18 13:33:16.000000000 -0400 | |
da5b3fc8 | 16143 | @@ -76,6 +76,8 @@ |
da5b3fc8 | 16144 | #include <linux/pid_namespace.h> |
b79bc584 | 16145 | #include <linux/vs_context.h> |
16146 | #include <linux/vs_network.h> | |
50425a20 | 16147 | +#include <linux/grsecurity.h> |
da5b3fc8 | 16148 | + |
50425a20 | 16149 | #include "internal.h" |
16150 | ||
da5b3fc8 | 16151 | /* NOTE: |
16152 | @@ -126,7 +128,7 @@ struct pid_entry { | |
4dee9bd5 | 16153 | NULL, &proc_single_file_operations, \ |
16154 | { .proc_show = &proc_##OTYPE } ) | |
8a4b4a5e | 16155 | |
16156 | -int maps_protect; | |
16157 | +int maps_protect = 1; | |
16158 | EXPORT_SYMBOL(maps_protect); | |
16159 | ||
16160 | static struct fs_struct *get_fs_struct(struct task_struct *task) | |
da5b3fc8 | 16161 | @@ -200,7 +202,7 @@ static int proc_root_link(struct inode * |
50425a20 | 16162 | (task->parent == current && \ |
16163 | (task->ptrace & PT_PTRACED) && \ | |
4dee9bd5 | 16164 | (task_is_stopped_or_traced(task)) && \ |
50425a20 | 16165 | - security_ptrace(current,task) == 0)) |
16166 | + security_ptrace(current,task) == 0 && !gr_handle_proc_ptrace(task))) | |
16167 | ||
da5b3fc8 | 16168 | struct mm_struct *mm_for_maps(struct task_struct *task) |
50425a20 | 16169 | { |
da5b3fc8 | 16170 | @@ -265,9 +267,9 @@ static int proc_pid_auxv(struct task_str |
8a4b4a5e | 16171 | struct mm_struct *mm = get_task_mm(task); |
16172 | if (mm) { | |
16173 | unsigned int nwords = 0; | |
16174 | - do | |
16175 | + do { | |
16176 | nwords += 2; | |
16177 | - while (mm->saved_auxv[nwords - 2] != 0); /* AT_NULL */ | |
16178 | + } while (mm->saved_auxv[nwords - 2] != 0); /* AT_NULL */ | |
16179 | res = nwords * sizeof(mm->saved_auxv[0]); | |
16180 | if (res > PAGE_SIZE) | |
16181 | res = PAGE_SIZE; | |
4dee9bd5 | 16182 | @@ -715,7 +717,7 @@ static ssize_t mem_read(struct file * fi |
50425a20 | 16183 | if (!task) |
16184 | goto out_no_task; | |
16185 | ||
16186 | - if (!MAY_PTRACE(task) || !ptrace_may_attach(task)) | |
16187 | + if (!MAY_PTRACE(task) || !ptrace_may_attach(task) || gr_acl_handle_procpidmem(task)) | |
16188 | goto out; | |
16189 | ||
16190 | ret = -ENOMEM; | |
4dee9bd5 | 16191 | @@ -785,7 +787,7 @@ static ssize_t mem_write(struct file * f |
50425a20 | 16192 | if (!task) |
16193 | goto out_no_task; | |
16194 | ||
16195 | - if (!MAY_PTRACE(task) || !ptrace_may_attach(task)) | |
16196 | + if (!MAY_PTRACE(task) || !ptrace_may_attach(task) || gr_acl_handle_procpidmem(task)) | |
16197 | goto out; | |
16198 | ||
16199 | copied = -ENOMEM; | |
4dee9bd5 | 16200 | @@ -1288,7 +1290,11 @@ static struct inode *proc_pid_make_inode |
50425a20 | 16201 | inode->i_gid = 0; |
16202 | if (task_dumpable(task)) { | |
16203 | inode->i_uid = task->euid; | |
16204 | +#ifdef CONFIG_GRKERNSEC_PROC_USERGROUP | |
16205 | + inode->i_gid = CONFIG_GRKERNSEC_PROC_GID; | |
16206 | +#else | |
16207 | inode->i_gid = task->egid; | |
16208 | +#endif | |
16209 | } | |
b79bc584 | 16210 | /* procfs is xid tagged */ |
16211 | inode->i_tag = (tag_t)vx_task_xid(task); | |
4dee9bd5 | 16212 | @@ -1304,17 +1310,45 @@ static int pid_getattr(struct vfsmount * |
50425a20 | 16213 | { |
16214 | struct inode *inode = dentry->d_inode; | |
16215 | struct task_struct *task; | |
16216 | +#if defined(CONFIG_GRKERNSEC_PROC_USER) || defined(CONFIG_GRKERNSEC_PROC_USERGROUP) | |
16217 | + struct task_struct *tmp = current; | |
16218 | +#endif | |
16219 | + | |
16220 | generic_fillattr(inode, stat); | |
16221 | ||
16222 | rcu_read_lock(); | |
16223 | stat->uid = 0; | |
16224 | stat->gid = 0; | |
16225 | task = pid_task(proc_pid(inode), PIDTYPE_PID); | |
16226 | - if (task) { | |
16227 | + | |
16228 | + if (task && (gr_pid_is_chrooted(task) || gr_check_hidden_task(task))) { | |
16229 | + rcu_read_unlock(); | |
16230 | + return -ENOENT; | |
16231 | + } | |
16232 | + | |
16233 | + | |
16234 | + if (task | |
16235 | +#if defined(CONFIG_GRKERNSEC_PROC_USER) || defined(CONFIG_GRKERNSEC_PROC_USERGROUP) | |
16236 | + && (!tmp->uid || (tmp->uid == task->uid) | |
16237 | +#ifdef CONFIG_GRKERNSEC_PROC_USERGROUP | |
16238 | + || in_group_p(CONFIG_GRKERNSEC_PROC_GID) | |
16239 | +#endif | |
16240 | + ) | |
16241 | +#endif | |
16242 | + ) { | |
16243 | if ((inode->i_mode == (S_IFDIR|S_IRUGO|S_IXUGO)) || | |
16244 | +#ifdef CONFIG_GRKERNSEC_PROC_USER | |
16245 | + (inode->i_mode == (S_IFDIR|S_IRUSR|S_IXUSR)) || | |
b2ee8b1e | 16246 | +#elif defined(CONFIG_GRKERNSEC_PROC_USERGROUP) |
50425a20 | 16247 | + (inode->i_mode == (S_IFDIR|S_IRUSR|S_IRGRP|S_IXUSR|S_IXGRP)) || |
16248 | +#endif | |
16249 | task_dumpable(task)) { | |
16250 | stat->uid = task->euid; | |
16251 | +#ifdef CONFIG_GRKERNSEC_PROC_USERGROUP | |
16252 | + stat->gid = CONFIG_GRKERNSEC_PROC_GID; | |
16253 | +#else | |
16254 | stat->gid = task->egid; | |
16255 | +#endif | |
16256 | } | |
16257 | } | |
16258 | rcu_read_unlock(); | |
4dee9bd5 | 16259 | @@ -1342,11 +1376,21 @@ static int pid_revalidate(struct dentry |
50425a20 | 16260 | { |
16261 | struct inode *inode = dentry->d_inode; | |
16262 | struct task_struct *task = get_proc_task(inode); | |
50425a20 | 16263 | + |
16264 | if (task) { | |
16265 | if ((inode->i_mode == (S_IFDIR|S_IRUGO|S_IXUGO)) || | |
16266 | +#ifdef CONFIG_GRKERNSEC_PROC_USER | |
16267 | + (inode->i_mode == (S_IFDIR|S_IRUSR|S_IXUSR)) || | |
b2ee8b1e | 16268 | +#elif defined(CONFIG_GRKERNSEC_PROC_USERGROUP) |
50425a20 | 16269 | + (inode->i_mode == (S_IFDIR|S_IRUSR|S_IRGRP|S_IXUSR|S_IXGRP)) || |
16270 | +#endif | |
16271 | task_dumpable(task)) { | |
16272 | inode->i_uid = task->euid; | |
16273 | +#ifdef CONFIG_GRKERNSEC_PROC_USERGROUP | |
16274 | + inode->i_gid = CONFIG_GRKERNSEC_PROC_GID; | |
16275 | +#else | |
16276 | inode->i_gid = task->egid; | |
16277 | +#endif | |
16278 | } else { | |
16279 | inode->i_uid = 0; | |
16280 | inode->i_gid = 0; | |
4dee9bd5 | 16281 | @@ -1717,12 +1761,22 @@ static int proc_fd_permission(struct ino |
b7f09679 | 16282 | struct nameidata *nd) |
16283 | { | |
16284 | int rv; | |
16285 | + struct task_struct *task; | |
50425a20 | 16286 | |
b7f09679 | 16287 | rv = generic_permission(inode, mask, NULL); |
16288 | - if (rv == 0) | |
16289 | - return 0; | |
16290 | + | |
16291 | if (task_pid(current) == proc_pid(inode)) | |
16292 | rv = 0; | |
16293 | + | |
16294 | + task = get_proc_task(inode); | |
16295 | + if (task == NULL) | |
16296 | + return rv; | |
16297 | + | |
50425a20 | 16298 | + if (gr_acl_handle_procpidmem(task)) |
b7f09679 | 16299 | + rv = -EACCES; |
50425a20 | 16300 | + |
b7f09679 | 16301 | + put_task_struct(task); |
16302 | + | |
16303 | return rv; | |
16304 | } | |
16305 | ||
4dee9bd5 | 16306 | @@ -1833,6 +1887,9 @@ static struct dentry *proc_pident_lookup |
da5b3fc8 | 16307 | if (!task) |
16308 | goto out_no_task; | |
50425a20 | 16309 | |
16310 | + if (gr_pid_is_chrooted(task) || gr_check_hidden_task(task)) | |
16311 | + goto out; | |
16312 | + | |
b79bc584 | 16313 | /* TODO: maybe we can come up with a generic approach? */ |
16314 | if (task_vx_flags(task, VXF_HIDE_VINFO, 0) && | |
16315 | (dentry->d_name.len == 5) && | |
4dee9bd5 | 16316 | @@ -1877,6 +1934,9 @@ static int proc_pident_readdir(struct fi |
50425a20 | 16317 | if (!task) |
16318 | goto out_no_task; | |
16319 | ||
16320 | + if (gr_pid_is_chrooted(task) || gr_check_hidden_task(task)) | |
16321 | + goto out; | |
16322 | + | |
16323 | ret = 0; | |
50425a20 | 16324 | i = filp->f_pos; |
da5b3fc8 | 16325 | switch (i) { |
4dee9bd5 | 16326 | @@ -2239,6 +2299,9 @@ static struct dentry *proc_base_lookup(s |
50425a20 | 16327 | if (p > last) |
16328 | goto out; | |
16329 | ||
16330 | + if (gr_pid_is_chrooted(task) || gr_check_hidden_task(task)) | |
16331 | + goto out; | |
16332 | + | |
16333 | error = proc_base_instantiate(dir, dentry, task, p); | |
16334 | ||
16335 | out: | |
4dee9bd5 | 16336 | @@ -2350,6 +2413,9 @@ static const struct pid_entry tgid_base_ |
50425a20 | 16337 | INF("io", S_IRUGO, pid_io_accounting), |
16338 | #endif | |
b79bc584 | 16339 | ONE("nsproxy", S_IRUGO, pid_nsproxy), |
50425a20 | 16340 | +#ifdef CONFIG_GRKERNSEC_PROC_IPADDR |
16341 | + INF("ipaddr", S_IRUSR, pid_ipaddr), | |
16342 | +#endif | |
16343 | }; | |
16344 | ||
16345 | static int proc_tgid_base_readdir(struct file * filp, | |
4dee9bd5 | 16346 | @@ -2479,7 +2545,14 @@ static struct dentry *proc_pid_instantia |
50425a20 | 16347 | if (!inode) |
16348 | goto out; | |
16349 | ||
16350 | +#ifdef CONFIG_GRKERNSEC_PROC_USER | |
16351 | + inode->i_mode = S_IFDIR|S_IRUSR|S_IXUSR; | |
b2ee8b1e | 16352 | +#elif defined(CONFIG_GRKERNSEC_PROC_USERGROUP) |
50425a20 | 16353 | + inode->i_gid = CONFIG_GRKERNSEC_PROC_GID; |
16354 | + inode->i_mode = S_IFDIR|S_IRUSR|S_IRGRP|S_IXUSR|S_IXGRP; | |
16355 | +#else | |
16356 | inode->i_mode = S_IFDIR|S_IRUGO|S_IXUGO; | |
16357 | +#endif | |
16358 | inode->i_op = &proc_tgid_base_inode_operations; | |
16359 | inode->i_fop = &proc_tgid_base_operations; | |
16360 | inode->i_flags|=S_IMMUTABLE; | |
4dee9bd5 | 16361 | @@ -2522,7 +2595,11 @@ struct dentry *proc_pid_lookup(struct in |
50425a20 | 16362 | if (!task) |
16363 | goto out; | |
16364 | ||
16365 | + if (gr_check_hidden_task(task)) | |
16366 | + goto out_put_task; | |
16367 | + | |
16368 | result = proc_pid_instantiate(dir, dentry, task, NULL); | |
16369 | +out_put_task: | |
16370 | put_task_struct(task); | |
16371 | out: | |
16372 | return result; | |
4dee9bd5 | 16373 | @@ -2587,6 +2664,9 @@ int proc_pid_readdir(struct file * filp, |
50425a20 | 16374 | { |
16375 | unsigned int nr = filp->f_pos - FIRST_PROCESS_ENTRY; | |
b79bc584 | 16376 | struct task_struct *reaper = get_proc_task_real(filp->f_path.dentry->d_inode); |
50425a20 | 16377 | +#if defined(CONFIG_GRKERNSEC_PROC_USER) || defined(CONFIG_GRKERNSEC_PROC_USERGROUP) |
16378 | + struct task_struct *tmp = current; | |
16379 | +#endif | |
da5b3fc8 | 16380 | struct tgid_iter iter; |
16381 | struct pid_namespace *ns; | |
50425a20 | 16382 | |
4dee9bd5 | 16383 | @@ -2605,6 +2685,17 @@ int proc_pid_readdir(struct file * filp, |
da5b3fc8 | 16384 | for (iter = next_tgid(ns, iter); |
16385 | iter.task; | |
16386 | iter.tgid += 1, iter = next_tgid(ns, iter)) { | |
16387 | + if (gr_pid_is_chrooted(iter.task) || gr_check_hidden_task(iter.task) | |
50425a20 | 16388 | +#if defined(CONFIG_GRKERNSEC_PROC_USER) || defined(CONFIG_GRKERNSEC_PROC_USERGROUP) |
da5b3fc8 | 16389 | + || (tmp->uid && (iter.task->uid != tmp->uid) |
50425a20 | 16390 | +#ifdef CONFIG_GRKERNSEC_PROC_USERGROUP |
da5b3fc8 | 16391 | + && !in_group_p(CONFIG_GRKERNSEC_PROC_GID) |
50425a20 | 16392 | +#endif |
16393 | + ) | |
16394 | +#endif | |
16395 | + ) | |
16396 | + continue; | |
16397 | + | |
da5b3fc8 | 16398 | filp->f_pos = iter.tgid + TGID_OFFSET; |
b79bc584 | 16399 | if (!vx_proc_task_visible(iter.task)) |
16400 | continue; | |
4dee9bd5 | 16401 | diff -urNp linux-2.6.25.4/fs/proc/inode.c linux-2.6.25.4/fs/proc/inode.c |
16402 | --- linux-2.6.25.4/fs/proc/inode.c 2008-05-15 11:00:12.000000000 -0400 | |
16403 | +++ linux-2.6.25.4/fs/proc/inode.c 2008-05-18 13:33:16.000000000 -0400 | |
16404 | @@ -406,7 +406,11 @@ struct inode *proc_get_inode(struct supe | |
16405 | if (de->mode) { | |
16406 | inode->i_mode = de->mode; | |
16407 | inode->i_uid = de->uid; | |
50425a20 | 16408 | +#ifdef CONFIG_GRKERNSEC_PROC_USERGROUP |
4dee9bd5 | 16409 | + inode->i_gid = CONFIG_GRKERNSEC_PROC_GID; |
50425a20 | 16410 | +#else |
4dee9bd5 | 16411 | inode->i_gid = de->gid; |
50425a20 | 16412 | +#endif |
4dee9bd5 | 16413 | } |
b79bc584 | 16414 | if (de->vx_flags) |
16415 | PROC_I(inode)->vx_flags = de->vx_flags; | |
4dee9bd5 | 16416 | diff -urNp linux-2.6.25.4/fs/proc/internal.h linux-2.6.25.4/fs/proc/internal.h |
16417 | --- linux-2.6.25.4/fs/proc/internal.h 2008-05-15 11:00:12.000000000 -0400 | |
16418 | +++ linux-2.6.25.4/fs/proc/internal.h 2008-05-18 13:33:16.000000000 -0400 | |
16419 | @@ -57,6 +57,10 @@ extern int proc_pid_status(struct seq_fi | |
16420 | struct pid *pid, struct task_struct *task); | |
b79bc584 | 16421 | extern int proc_pid_nsproxy(struct seq_file *m, struct pid_namespace *ns, |
4dee9bd5 | 16422 | struct pid *pid, struct task_struct *task); |
50425a20 | 16423 | +#ifdef CONFIG_GRKERNSEC_PROC_IPADDR |
4dee9bd5 | 16424 | +extern int proc_pid_ipaddr(struct seq_file *m, struct pid_namespace *ns, |
16425 | + struct pid *pid, struct task_struct *task); | |
50425a20 | 16426 | +#endif |
b79bc584 | 16427 | |
4dee9bd5 | 16428 | extern loff_t mem_lseek(struct file *file, loff_t offset, int orig); |
50425a20 | 16429 | |
4dee9bd5 | 16430 | diff -urNp linux-2.6.25.4/fs/proc/proc_misc.c linux-2.6.25.4/fs/proc/proc_misc.c |
16431 | --- linux-2.6.25.4/fs/proc/proc_misc.c 2008-05-15 11:00:12.000000000 -0400 | |
16432 | +++ linux-2.6.25.4/fs/proc/proc_misc.c 2008-05-18 13:33:16.000000000 -0400 | |
16433 | @@ -822,6 +822,8 @@ void create_seq_entry(char *name, mode_t | |
50425a20 | 16434 | |
16435 | void __init proc_misc_init(void) | |
16436 | { | |
16437 | + int gr_mode = 0; | |
16438 | + | |
16439 | static struct { | |
16440 | char *name; | |
16441 | int (*read_proc)(char*,char**,off_t,int,int*,void*); | |
4dee9bd5 | 16442 | @@ -837,13 +839,24 @@ void __init proc_misc_init(void) |
50425a20 | 16443 | {"stram", stram_read_proc}, |
16444 | #endif | |
16445 | {"filesystems", filesystems_read_proc}, | |
16446 | +#ifndef CONFIG_GRKERNSEC_PROC_ADD | |
16447 | {"cmdline", cmdline_read_proc}, | |
16448 | +#endif | |
50425a20 | 16449 | {"execdomains", execdomains_read_proc}, |
16450 | {NULL,} | |
da5b3fc8 | 16451 | }; |
50425a20 | 16452 | for (p = simple_ones; p->name; p++) |
16453 | create_proc_read_entry(p->name, 0, NULL, p->read_proc, NULL); | |
16454 | ||
16455 | +#ifdef CONFIG_GRKERNSEC_PROC_USER | |
16456 | + gr_mode = S_IRUSR; | |
16457 | +#elif defined(CONFIG_GRKERNSEC_PROC_USERGROUP) | |
16458 | + gr_mode = S_IRUSR | S_IRGRP; | |
16459 | +#endif | |
16460 | +#ifdef CONFIG_GRKERNSEC_PROC_ADD | |
16461 | + create_proc_read_entry("cmdline", gr_mode, NULL, &cmdline_read_proc, NULL); | |
16462 | +#endif | |
16463 | + | |
16464 | proc_symlink("mounts", NULL, "self/mounts"); | |
16465 | ||
16466 | /* And now for trickier ones */ | |
4dee9bd5 | 16467 | @@ -856,7 +869,11 @@ void __init proc_misc_init(void) |
50425a20 | 16468 | } |
16469 | #endif | |
da5b3fc8 | 16470 | create_seq_entry("locks", 0, &proc_locks_operations); |
50425a20 | 16471 | +#ifdef CONFIG_GRKERNSEC_PROC_ADD |
16472 | + create_seq_entry("devices", gr_mode, &proc_devinfo_operations); | |
16473 | +#else | |
16474 | create_seq_entry("devices", 0, &proc_devinfo_operations); | |
16475 | +#endif | |
16476 | create_seq_entry("cpuinfo", 0, &proc_cpuinfo_operations); | |
16477 | #ifdef CONFIG_BLOCK | |
16478 | create_seq_entry("partitions", 0, &proc_partitions_operations); | |
4dee9bd5 | 16479 | @@ -864,7 +881,11 @@ void __init proc_misc_init(void) |
50425a20 | 16480 | create_seq_entry("stat", 0, &proc_stat_operations); |
16481 | create_seq_entry("interrupts", 0, &proc_interrupts_operations); | |
da5b3fc8 | 16482 | #ifdef CONFIG_SLABINFO |
16483 | +#ifdef CONFIG_GRKRENSEC_PROC_ADD | |
50425a20 | 16484 | + create_seq_entry("slabinfo",S_IWUSR|gr_mode,&proc_slabinfo_operations); |
16485 | +#else | |
16486 | create_seq_entry("slabinfo",S_IWUSR|S_IRUGO,&proc_slabinfo_operations); | |
16487 | +#endif | |
16488 | #ifdef CONFIG_DEBUG_SLAB_LEAK | |
16489 | create_seq_entry("slab_allocators", 0 ,&proc_slabstats_operations); | |
16490 | #endif | |
4dee9bd5 | 16491 | @@ -882,7 +903,7 @@ void __init proc_misc_init(void) |
50425a20 | 16492 | #ifdef CONFIG_SCHEDSTATS |
16493 | create_seq_entry("schedstat", 0, &proc_schedstat_operations); | |
16494 | #endif | |
16495 | -#ifdef CONFIG_PROC_KCORE | |
16496 | +#if defined(CONFIG_PROC_KCORE) && !defined(CONFIG_GRKERNSEC_PROC_ADD) | |
16497 | proc_root_kcore = create_proc_entry("kcore", S_IRUSR, NULL); | |
16498 | if (proc_root_kcore) { | |
16499 | proc_root_kcore->proc_fops = &proc_kcore_operations; | |
4dee9bd5 | 16500 | diff -urNp linux-2.6.25.4/fs/proc/proc_net.c linux-2.6.25.4/fs/proc/proc_net.c |
16501 | --- linux-2.6.25.4/fs/proc/proc_net.c 2008-05-15 11:00:12.000000000 -0400 | |
16502 | +++ linux-2.6.25.4/fs/proc/proc_net.c 2008-05-18 13:33:41.000000000 -0400 | |
16503 | @@ -69,6 +69,14 @@ static struct net *get_proc_task_net(str | |
16504 | struct nsproxy *ns; | |
16505 | struct net *net = NULL; | |
da5b3fc8 | 16506 | |
da5b3fc8 | 16507 | +#ifdef CONFIG_GRKERNSEC_PROC_USER |
4dee9bd5 | 16508 | + if (current->fsuid) |
16509 | + return net; | |
da5b3fc8 | 16510 | +#elif defined(CONFIG_GRKERNSEC_PROC_USERGROUP) |
4dee9bd5 | 16511 | + if (current->fsuid && !in_group_p(CONFIG_GRKERNSEC_PROC_GID)) |
16512 | + return net; | |
da5b3fc8 | 16513 | +#endif |
4dee9bd5 | 16514 | + |
16515 | rcu_read_lock(); | |
16516 | task = pid_task(proc_pid(dir), PIDTYPE_PID); | |
16517 | if (task != NULL) { | |
16518 | diff -urNp linux-2.6.25.4/fs/proc/proc_sysctl.c linux-2.6.25.4/fs/proc/proc_sysctl.c | |
16519 | --- linux-2.6.25.4/fs/proc/proc_sysctl.c 2008-05-15 11:00:12.000000000 -0400 | |
16520 | +++ linux-2.6.25.4/fs/proc/proc_sysctl.c 2008-05-18 13:33:16.000000000 -0400 | |
f4251508 | 16521 | @@ -7,6 +7,8 @@ |
16522 | #include <linux/security.h> | |
16523 | #include "internal.h" | |
16524 | ||
16525 | +extern __u32 gr_handle_sysctl(const struct ctl_table *table, const int op); | |
16526 | + | |
16527 | static struct dentry_operations proc_sys_dentry_operations; | |
16528 | static const struct file_operations proc_sys_file_operations; | |
4dee9bd5 | 16529 | static const struct inode_operations proc_sys_inode_operations; |
f4251508 | 16530 | @@ -151,6 +153,9 @@ static struct dentry *proc_sys_lookup(st |
16531 | if (!table) | |
16532 | goto out; | |
16533 | ||
78fdc4fb | 16534 | + if (gr_handle_sysctl(table, 001)) |
f4251508 | 16535 | + goto out; |
16536 | + | |
16537 | err = ERR_PTR(-ENOMEM); | |
16538 | inode = proc_sys_make_inode(dir, table); | |
16539 | if (!inode) | |
da5b3fc8 | 16540 | @@ -360,6 +365,9 @@ static int proc_sys_readdir(struct file |
f4251508 | 16541 | if (pos < filp->f_pos) |
16542 | continue; | |
16543 | ||
78fdc4fb | 16544 | + if (gr_handle_sysctl(table, 0)) |
f4251508 | 16545 | + continue; |
16546 | + | |
16547 | if (proc_sys_fill_cache(filp, dirent, filldir, table) < 0) | |
16548 | goto out; | |
16549 | filp->f_pos = pos + 1; | |
da5b3fc8 | 16550 | @@ -422,6 +430,30 @@ out: |
f4251508 | 16551 | return error; |
16552 | } | |
16553 | ||
16554 | +/* Eric Biederman is to blame */ | |
16555 | +static int proc_sys_getattr(struct vfsmount *mnt, struct dentry *dentry, struct kstat *stat) | |
16556 | +{ | |
16557 | + int error = 0; | |
16558 | + struct ctl_table_header *head; | |
16559 | + struct ctl_table *table; | |
16560 | + | |
16561 | + table = do_proc_sys_lookup(dentry->d_parent, &dentry->d_name, &head); | |
16562 | + /* Has the sysctl entry disappeared on us? */ | |
16563 | + if (!table) | |
16564 | + goto out; | |
16565 | + | |
78fdc4fb | 16566 | + if (gr_handle_sysctl(table, 001)) { |
f4251508 | 16567 | + error = -ENOENT; |
16568 | + goto out; | |
16569 | + } | |
16570 | + | |
16571 | +out: | |
16572 | + sysctl_head_finish(head); | |
16573 | + | |
16574 | + generic_fillattr(dentry->d_inode, stat); | |
16575 | + | |
16576 | + return error; | |
16577 | +} | |
16578 | static int proc_sys_setattr(struct dentry *dentry, struct iattr *attr) | |
16579 | { | |
16580 | struct inode *inode = dentry->d_inode; | |
4dee9bd5 | 16581 | @@ -450,6 +482,7 @@ static const struct inode_operations pro |
f4251508 | 16582 | .lookup = proc_sys_lookup, |
16583 | .permission = proc_sys_permission, | |
16584 | .setattr = proc_sys_setattr, | |
16585 | + .getattr = proc_sys_getattr, | |
16586 | }; | |
16587 | ||
16588 | static int proc_sys_revalidate(struct dentry *dentry, struct nameidata *nd) | |
4dee9bd5 | 16589 | diff -urNp linux-2.6.25.4/fs/proc/root.c linux-2.6.25.4/fs/proc/root.c |
16590 | --- linux-2.6.25.4/fs/proc/root.c 2008-05-15 11:00:12.000000000 -0400 | |
16591 | +++ linux-2.6.25.4/fs/proc/root.c 2008-05-18 13:33:16.000000000 -0400 | |
da5b3fc8 | 16592 | @@ -137,7 +137,15 @@ void __init proc_root_init(void) |
50425a20 | 16593 | #ifdef CONFIG_PROC_DEVICETREE |
16594 | proc_device_tree_init(); | |
16595 | #endif | |
16596 | +#ifdef CONFIG_GRKERNSEC_PROC_ADD | |
16597 | +#ifdef CONFIG_GRKERNSEC_PROC_USER | |
16598 | + proc_bus = proc_mkdir_mode("bus", S_IRUSR | S_IXUSR, NULL); | |
16599 | +#elif defined(CONFIG_GRKERNSEC_PROC_USERGROUP) | |
16600 | + proc_bus = proc_mkdir_mode("bus", S_IRUSR | S_IXUSR | S_IRGRP | S_IXGRP, NULL); | |
16601 | +#endif | |
16602 | +#else | |
16603 | proc_bus = proc_mkdir("bus", NULL); | |
16604 | +#endif | |
b79bc584 | 16605 | proc_vx_init(); |
50425a20 | 16606 | proc_sys_init(); |
16607 | } | |
4dee9bd5 | 16608 | diff -urNp linux-2.6.25.4/fs/proc/task_mmu.c linux-2.6.25.4/fs/proc/task_mmu.c |
16609 | --- linux-2.6.25.4/fs/proc/task_mmu.c 2008-05-15 11:00:12.000000000 -0400 | |
16610 | +++ linux-2.6.25.4/fs/proc/task_mmu.c 2008-05-18 13:33:16.000000000 -0400 | |
16611 | @@ -48,15 +48,26 @@ void task_mem(struct seq_file *m, struct | |
50425a20 | 16612 | "VmStk:\t%8lu kB\n" |
16613 | "VmExe:\t%8lu kB\n" | |
16614 | "VmLib:\t%8lu kB\n" | |
16615 | - "VmPTE:\t%8lu kB\n", | |
16616 | - hiwater_vm << (PAGE_SHIFT-10), | |
16617 | + "VmPTE:\t%8lu kB\n" | |
16618 | + | |
16619 | +#ifdef CONFIG_ARCH_TRACK_EXEC_LIMIT | |
16620 | + "CsBase:\t%8lx\nCsLim:\t%8lx\n" | |
16621 | +#endif | |
16622 | + | |
16623 | + ,hiwater_vm << (PAGE_SHIFT-10), | |
16624 | (total_vm - mm->reserved_vm) << (PAGE_SHIFT-10), | |
16625 | mm->locked_vm << (PAGE_SHIFT-10), | |
16626 | hiwater_rss << (PAGE_SHIFT-10), | |
16627 | total_rss << (PAGE_SHIFT-10), | |
16628 | data << (PAGE_SHIFT-10), | |
16629 | mm->stack_vm << (PAGE_SHIFT-10), text, lib, | |
16630 | - (PTRS_PER_PTE*sizeof(pte_t)*mm->nr_ptes) >> 10); | |
16631 | + (PTRS_PER_PTE*sizeof(pte_t)*mm->nr_ptes) >> 10 | |
16632 | + | |
16633 | +#ifdef CONFIG_ARCH_TRACK_EXEC_LIMIT | |
16634 | + , mm->context.user_cs_base, mm->context.user_cs_limit | |
16635 | +#endif | |
16636 | + | |
16637 | + ); | |
50425a20 | 16638 | } |
16639 | ||
4dee9bd5 | 16640 | unsigned long task_vsize(struct mm_struct *mm) |
16641 | @@ -234,6 +245,12 @@ static int do_maps_open(struct inode *in | |
16642 | return ret; | |
16643 | } | |
50425a20 | 16644 | |
16645 | +#ifdef CONFIG_GRKERNSEC_PROC_MEMMAP | |
16646 | +#define PAX_RAND_FLAGS(_mm) (_mm != NULL && _mm != current->mm && \ | |
4dee9bd5 | 16647 | + (_mm->pax_flags & MF_PAX_RANDMMAP || \ |
16648 | + _mm->pax_flags & MF_PAX_SEGMEXEC)) | |
50425a20 | 16649 | +#endif |
16650 | + | |
4dee9bd5 | 16651 | static int show_map(struct seq_file *m, void *v) |
50425a20 | 16652 | { |
16653 | struct proc_maps_private *priv = m->private; | |
4dee9bd5 | 16654 | @@ -256,13 +273,22 @@ static int show_map(struct seq_file *m, |
50425a20 | 16655 | } |
16656 | ||
16657 | seq_printf(m, "%08lx-%08lx %c%c%c%c %08lx %02x:%02x %lu %n", | |
16658 | +#ifdef CONFIG_GRKERNSEC_PROC_MEMMAP | |
16659 | + PAX_RAND_FLAGS(mm) ? 0UL : vma->vm_start, | |
16660 | + PAX_RAND_FLAGS(mm) ? 0UL : vma->vm_end, | |
16661 | +#else | |
16662 | vma->vm_start, | |
16663 | vma->vm_end, | |
16664 | +#endif | |
16665 | flags & VM_READ ? 'r' : '-', | |
16666 | flags & VM_WRITE ? 'w' : '-', | |
16667 | flags & VM_EXEC ? 'x' : '-', | |
16668 | flags & VM_MAYSHARE ? 's' : 'p', | |
16669 | +#ifdef CONFIG_GRKERNSEC_PROC_MEMMAP | |
16670 | + PAX_RAND_FLAGS(mm) ? 0UL : vma->vm_pgoff << PAGE_SHIFT, | |
16671 | +#else | |
16672 | vma->vm_pgoff << PAGE_SHIFT, | |
16673 | +#endif | |
16674 | MAJOR(dev), MINOR(dev), ino, &len); | |
16675 | ||
16676 | /* | |
4dee9bd5 | 16677 | @@ -276,11 +302,11 @@ static int show_map(struct seq_file *m, |
50425a20 | 16678 | const char *name = arch_vma_name(vma); |
16679 | if (!name) { | |
16680 | if (mm) { | |
16681 | - if (vma->vm_start <= mm->start_brk && | |
16682 | - vma->vm_end >= mm->brk) { | |
16683 | + if (vma->vm_start <= mm->brk && vma->vm_end >= mm->start_brk) { | |
16684 | name = "[heap]"; | |
16685 | - } else if (vma->vm_start <= mm->start_stack && | |
16686 | - vma->vm_end >= mm->start_stack) { | |
16687 | + } else if ((vma->vm_flags & (VM_GROWSDOWN | VM_GROWSUP)) || | |
16688 | + (vma->vm_start <= mm->start_stack && | |
16689 | + vma->vm_end >= mm->start_stack)) { | |
16690 | name = "[stack]"; | |
16691 | } | |
16692 | } else { | |
4dee9bd5 | 16693 | @@ -404,10 +430,17 @@ static int show_smap(struct seq_file *m, |
16694 | int ret; | |
50425a20 | 16695 | |
4dee9bd5 | 16696 | memset(&mss, 0, sizeof mss); |
16697 | - mss.vma = vma; | |
16698 | - if (vma->vm_mm && !is_vm_hugetlb_page(vma)) | |
16699 | - walk_page_range(vma->vm_mm, vma->vm_start, vma->vm_end, | |
16700 | - &smaps_walk, &mss); | |
16701 | + | |
16702 | +#ifdef CONFIG_GRKERNSEC_PROC_MEMMAP | |
16703 | + if (!PAX_RAND_FLAGS(vma->vm_mm)) { | |
16704 | +#endif | |
16705 | + mss.vma = vma; | |
16706 | + if (vma->vm_mm && !is_vm_hugetlb_page(vma)) | |
16707 | + walk_page_range(vma->vm_mm, vma->vm_start, vma->vm_end, | |
16708 | + &smaps_walk, &mss); | |
16709 | +#ifdef CONFIG_GRKERNSEC_PROC_MEMMAP | |
16710 | + } | |
16711 | +#endif | |
16712 | ||
16713 | ret = show_map(m, v); | |
16714 | if (ret) | |
16715 | @@ -422,7 +455,11 @@ static int show_smap(struct seq_file *m, | |
16716 | "Private_Clean: %8lu kB\n" | |
16717 | "Private_Dirty: %8lu kB\n" | |
16718 | "Referenced: %8lu kB\n", | |
50425a20 | 16719 | +#ifdef CONFIG_GRKERNSEC_PROC_MEMMAP |
4dee9bd5 | 16720 | + PAX_RAND_FLAGS(vma->vm_mm) ? 0UL : (vma->vm_end - vma->vm_start) >> 10, |
16721 | +#else | |
16722 | (vma->vm_end - vma->vm_start) >> 10, | |
16723 | +#endif | |
16724 | mss.resident >> 10, | |
16725 | (unsigned long)(mss.pss >> (10 + PSS_SHIFT)), | |
16726 | mss.shared_clean >> 10, | |
16727 | diff -urNp linux-2.6.25.4/fs/readdir.c linux-2.6.25.4/fs/readdir.c | |
16728 | --- linux-2.6.25.4/fs/readdir.c 2008-05-15 11:00:12.000000000 -0400 | |
16729 | +++ linux-2.6.25.4/fs/readdir.c 2008-05-18 13:33:16.000000000 -0400 | |
50425a20 | 16730 | @@ -16,6 +16,8 @@ |
16731 | #include <linux/security.h> | |
16732 | #include <linux/syscalls.h> | |
16733 | #include <linux/unistd.h> | |
16734 | +#include <linux/namei.h> | |
16735 | +#include <linux/grsecurity.h> | |
16736 | ||
16737 | #include <asm/uaccess.h> | |
16738 | ||
4dee9bd5 | 16739 | @@ -67,6 +69,7 @@ struct old_linux_dirent { |
50425a20 | 16740 | |
16741 | struct readdir_callback { | |
16742 | struct old_linux_dirent __user * dirent; | |
16743 | + struct file * file; | |
16744 | int result; | |
16745 | }; | |
16746 | ||
4dee9bd5 | 16747 | @@ -82,6 +85,10 @@ static int fillonedir(void * __buf, cons |
50425a20 | 16748 | d_ino = ino; |
16749 | if (sizeof(d_ino) < sizeof(ino) && d_ino != ino) | |
16750 | return -EOVERFLOW; | |
16751 | + | |
16752 | + if (!gr_acl_handle_filldir(buf->file, name, namlen, ino)) | |
16753 | + return 0; | |
16754 | + | |
16755 | buf->result++; | |
16756 | dirent = buf->dirent; | |
16757 | if (!access_ok(VERIFY_WRITE, dirent, | |
4dee9bd5 | 16758 | @@ -113,6 +120,7 @@ asmlinkage long old_readdir(unsigned int |
50425a20 | 16759 | |
16760 | buf.result = 0; | |
16761 | buf.dirent = dirent; | |
16762 | + buf.file = file; | |
16763 | ||
16764 | error = vfs_readdir(file, fillonedir, &buf); | |
16765 | if (error >= 0) | |
4dee9bd5 | 16766 | @@ -139,6 +147,7 @@ struct linux_dirent { |
50425a20 | 16767 | struct getdents_callback { |
16768 | struct linux_dirent __user * current_dir; | |
16769 | struct linux_dirent __user * previous; | |
16770 | + struct file * file; | |
16771 | int count; | |
16772 | int error; | |
16773 | }; | |
4dee9bd5 | 16774 | @@ -157,6 +166,10 @@ static int filldir(void * __buf, const c |
50425a20 | 16775 | d_ino = ino; |
16776 | if (sizeof(d_ino) < sizeof(ino) && d_ino != ino) | |
16777 | return -EOVERFLOW; | |
16778 | + | |
16779 | + if (!gr_acl_handle_filldir(buf->file, name, namlen, ino)) | |
16780 | + return 0; | |
16781 | + | |
16782 | dirent = buf->previous; | |
16783 | if (dirent) { | |
16784 | if (__put_user(offset, &dirent->d_off)) | |
4dee9bd5 | 16785 | @@ -203,6 +216,7 @@ asmlinkage long sys_getdents(unsigned in |
50425a20 | 16786 | buf.previous = NULL; |
16787 | buf.count = count; | |
16788 | buf.error = 0; | |
16789 | + buf.file = file; | |
16790 | ||
16791 | error = vfs_readdir(file, filldir, &buf); | |
16792 | if (error < 0) | |
4dee9bd5 | 16793 | @@ -225,6 +239,7 @@ out: |
50425a20 | 16794 | struct getdents_callback64 { |
16795 | struct linux_dirent64 __user * current_dir; | |
16796 | struct linux_dirent64 __user * previous; | |
16797 | + struct file *file; | |
16798 | int count; | |
16799 | int error; | |
16800 | }; | |
4dee9bd5 | 16801 | @@ -239,6 +254,10 @@ static int filldir64(void * __buf, const |
50425a20 | 16802 | buf->error = -EINVAL; /* only used if we fail.. */ |
16803 | if (reclen > buf->count) | |
16804 | return -EINVAL; | |
16805 | + | |
16806 | + if (!gr_acl_handle_filldir(buf->file, name, namlen, ino)) | |
16807 | + return 0; | |
16808 | + | |
16809 | dirent = buf->previous; | |
16810 | if (dirent) { | |
16811 | if (__put_user(offset, &dirent->d_off)) | |
4dee9bd5 | 16812 | @@ -285,6 +304,7 @@ asmlinkage long sys_getdents64(unsigned |
50425a20 | 16813 | |
16814 | buf.current_dir = dirent; | |
16815 | buf.previous = NULL; | |
16816 | + buf.file = file; | |
16817 | buf.count = count; | |
16818 | buf.error = 0; | |
16819 | ||
4dee9bd5 | 16820 | diff -urNp linux-2.6.25.4/fs/smbfs/symlink.c linux-2.6.25.4/fs/smbfs/symlink.c |
16821 | --- linux-2.6.25.4/fs/smbfs/symlink.c 2008-05-15 11:00:12.000000000 -0400 | |
16822 | +++ linux-2.6.25.4/fs/smbfs/symlink.c 2008-05-18 13:33:16.000000000 -0400 | |
da5b3fc8 | 16823 | @@ -55,7 +55,7 @@ static void *smb_follow_link(struct dent |
16824 | ||
16825 | static void smb_put_link(struct dentry *dentry, struct nameidata *nd, void *p) | |
16826 | { | |
16827 | - char *s = nd_get_link(nd); | |
16828 | + const char *s = nd_get_link(nd); | |
16829 | if (!IS_ERR(s)) | |
16830 | __putname(s); | |
16831 | } | |
4dee9bd5 | 16832 | diff -urNp linux-2.6.25.4/fs/sysfs/symlink.c linux-2.6.25.4/fs/sysfs/symlink.c |
16833 | --- linux-2.6.25.4/fs/sysfs/symlink.c 2008-05-15 11:00:12.000000000 -0400 | |
16834 | +++ linux-2.6.25.4/fs/sysfs/symlink.c 2008-05-18 13:33:16.000000000 -0400 | |
16835 | @@ -168,7 +168,7 @@ static void *sysfs_follow_link(struct de | |
da5b3fc8 | 16836 | |
16837 | static void sysfs_put_link(struct dentry *dentry, struct nameidata *nd, void *cookie) | |
16838 | { | |
16839 | - char *page = nd_get_link(nd); | |
16840 | + const char *page = nd_get_link(nd); | |
16841 | if (!IS_ERR(page)) | |
16842 | free_page((unsigned long)page); | |
16843 | } | |
4dee9bd5 | 16844 | diff -urNp linux-2.6.25.4/fs/udf/balloc.c linux-2.6.25.4/fs/udf/balloc.c |
16845 | --- linux-2.6.25.4/fs/udf/balloc.c 2008-05-15 11:00:12.000000000 -0400 | |
16846 | +++ linux-2.6.25.4/fs/udf/balloc.c 2008-05-18 13:33:16.000000000 -0400 | |
16847 | @@ -170,9 +170,7 @@ static void udf_bitmap_free_blocks(struc | |
50425a20 | 16848 | unsigned long overflow; |
16849 | ||
16850 | mutex_lock(&sbi->s_alloc_mutex); | |
16851 | - if (bloc.logicalBlockNum < 0 || | |
4dee9bd5 | 16852 | - (bloc.logicalBlockNum + count) > |
16853 | - sbi->s_partmaps[bloc.partitionReferenceNum].s_partition_len) { | |
16854 | + if (bloc.logicalBlockNum + count > sbi->s_partmaps[bloc.partitionReferenceNum].s_partition_len) { | |
50425a20 | 16855 | udf_debug("%d < %d || %d + %d > %d\n", |
da5b3fc8 | 16856 | bloc.logicalBlockNum, 0, bloc.logicalBlockNum, count, |
4dee9bd5 | 16857 | sbi->s_partmaps[bloc.partitionReferenceNum]. |
16858 | @@ -240,7 +238,7 @@ static int udf_bitmap_prealloc_blocks(st | |
50425a20 | 16859 | |
16860 | mutex_lock(&sbi->s_alloc_mutex); | |
4dee9bd5 | 16861 | part_len = sbi->s_partmaps[partition].s_partition_len; |
16862 | - if (first_block < 0 || first_block >= part_len) | |
16863 | + if (first_block >= part_len) | |
50425a20 | 16864 | goto out; |
16865 | ||
4dee9bd5 | 16866 | if (first_block + block_count > part_len) |
16867 | @@ -301,7 +299,7 @@ static int udf_bitmap_new_block(struct s | |
50425a20 | 16868 | mutex_lock(&sbi->s_alloc_mutex); |
16869 | ||
16870 | repeat: | |
4dee9bd5 | 16871 | - if (goal < 0 || goal >= sbi->s_partmaps[partition].s_partition_len) |
16872 | + if (goal >= sbi->s_partmaps[partition].s_partition_len) | |
50425a20 | 16873 | goal = 0; |
16874 | ||
16875 | nr_groups = bitmap->s_nr_groups; | |
4dee9bd5 | 16876 | @@ -439,9 +437,7 @@ static void udf_table_free_blocks(struct |
16877 | struct udf_inode_info *iinfo; | |
50425a20 | 16878 | |
16879 | mutex_lock(&sbi->s_alloc_mutex); | |
16880 | - if (bloc.logicalBlockNum < 0 || | |
4dee9bd5 | 16881 | - (bloc.logicalBlockNum + count) > |
16882 | - sbi->s_partmaps[bloc.partitionReferenceNum].s_partition_len) { | |
16883 | + if (bloc.logicalBlockNum + count > sbi->s_partmaps[bloc.partitionReferenceNum].s_partition_len) { | |
50425a20 | 16884 | udf_debug("%d < %d || %d + %d > %d\n", |
da5b3fc8 | 16885 | bloc.logicalBlockNum, 0, bloc.logicalBlockNum, count, |
4dee9bd5 | 16886 | sbi->s_partmaps[bloc.partitionReferenceNum]. |
16887 | @@ -676,8 +672,7 @@ static int udf_table_prealloc_blocks(str | |
50425a20 | 16888 | int8_t etype = -1; |
4dee9bd5 | 16889 | struct udf_inode_info *iinfo; |
50425a20 | 16890 | |
4dee9bd5 | 16891 | - if (first_block < 0 || |
16892 | - first_block >= sbi->s_partmaps[partition].s_partition_len) | |
16893 | + if (first_block >= sbi->s_partmaps[partition].s_partition_len) | |
50425a20 | 16894 | return 0; |
16895 | ||
4dee9bd5 | 16896 | iinfo = UDF_I(table); |
16897 | @@ -755,7 +750,7 @@ static int udf_table_new_block(struct su | |
50425a20 | 16898 | return newblock; |
16899 | ||
16900 | mutex_lock(&sbi->s_alloc_mutex); | |
4dee9bd5 | 16901 | - if (goal < 0 || goal >= sbi->s_partmaps[partition].s_partition_len) |
16902 | + if (goal >= sbi->s_partmaps[partition].s_partition_len) | |
50425a20 | 16903 | goal = 0; |
16904 | ||
4dee9bd5 | 16905 | /* We search for the closest matching block to goal. If we find |
16906 | diff -urNp linux-2.6.25.4/fs/udf/inode.c linux-2.6.25.4/fs/udf/inode.c | |
16907 | --- linux-2.6.25.4/fs/udf/inode.c 2008-05-15 11:00:12.000000000 -0400 | |
16908 | +++ linux-2.6.25.4/fs/udf/inode.c 2008-05-18 13:33:16.000000000 -0400 | |
16909 | @@ -323,9 +323,6 @@ static int udf_get_block(struct inode *i | |
50425a20 | 16910 | |
16911 | lock_kernel(); | |
16912 | ||
16913 | - if (block < 0) | |
16914 | - goto abort_negative; | |
16915 | - | |
4dee9bd5 | 16916 | iinfo = UDF_I(inode); |
16917 | if (block == iinfo->i_next_alloc_block + 1) { | |
16918 | iinfo->i_next_alloc_block++; | |
16919 | @@ -347,10 +344,6 @@ static int udf_get_block(struct inode *i | |
50425a20 | 16920 | abort: |
16921 | unlock_kernel(); | |
16922 | return err; | |
16923 | - | |
16924 | -abort_negative: | |
16925 | - udf_warning(inode->i_sb, "udf_get_block", "block < 0"); | |
16926 | - goto abort; | |
16927 | } | |
16928 | ||
da5b3fc8 | 16929 | static struct buffer_head *udf_getblk(struct inode *inode, long block, |
4dee9bd5 | 16930 | diff -urNp linux-2.6.25.4/fs/ufs/inode.c linux-2.6.25.4/fs/ufs/inode.c |
16931 | --- linux-2.6.25.4/fs/ufs/inode.c 2008-05-15 11:00:12.000000000 -0400 | |
16932 | +++ linux-2.6.25.4/fs/ufs/inode.c 2008-05-18 13:33:16.000000000 -0400 | |
da5b3fc8 | 16933 | @@ -56,9 +56,7 @@ static int ufs_block_to_path(struct inod |
50425a20 | 16934 | |
16935 | ||
16936 | UFSD("ptrs=uspi->s_apb = %d,double_blocks=%ld \n",ptrs,double_blocks); | |
16937 | - if (i_block < 0) { | |
16938 | - ufs_warning(inode->i_sb, "ufs_block_to_path", "block < 0"); | |
16939 | - } else if (i_block < direct_blocks) { | |
16940 | + if (i_block < direct_blocks) { | |
16941 | offsets[n++] = i_block; | |
16942 | } else if ((i_block -= direct_blocks) < indirect_blocks) { | |
16943 | offsets[n++] = UFS_IND_BLOCK; | |
da5b3fc8 | 16944 | @@ -440,8 +438,6 @@ int ufs_getfrag_block(struct inode *inod |
50425a20 | 16945 | lock_kernel(); |
16946 | ||
16947 | UFSD("ENTER, ino %lu, fragment %llu\n", inode->i_ino, (unsigned long long)fragment); | |
16948 | - if (fragment < 0) | |
16949 | - goto abort_negative; | |
16950 | if (fragment > | |
16951 | ((UFS_NDADDR + uspi->s_apb + uspi->s_2apb + uspi->s_3apb) | |
16952 | << uspi->s_fpbshift)) | |
da5b3fc8 | 16953 | @@ -504,10 +500,6 @@ abort: |
50425a20 | 16954 | unlock_kernel(); |
16955 | return err; | |
16956 | ||
16957 | -abort_negative: | |
16958 | - ufs_warning(sb, "ufs_get_block", "block < 0"); | |
16959 | - goto abort; | |
16960 | - | |
16961 | abort_too_big: | |
16962 | ufs_warning(sb, "ufs_get_block", "block > big"); | |
16963 | goto abort; | |
4dee9bd5 | 16964 | diff -urNp linux-2.6.25.4/fs/utimes.c linux-2.6.25.4/fs/utimes.c |
16965 | --- linux-2.6.25.4/fs/utimes.c 2008-05-15 11:00:12.000000000 -0400 | |
16966 | +++ linux-2.6.25.4/fs/utimes.c 2008-05-18 13:33:16.000000000 -0400 | |
16967 | @@ -7,6 +7,7 @@ | |
4dee9bd5 | 16968 | #include <linux/syscalls.h> |
b79bc584 | 16969 | #include <linux/mount.h> |
16970 | #include <linux/vs_cowbl.h> | |
50425a20 | 16971 | +#include <linux/grsecurity.h> |
16972 | #include <asm/uaccess.h> | |
16973 | #include <asm/unistd.h> | |
16974 | ||
4dee9bd5 | 16975 | @@ -61,6 +62,7 @@ long do_utimes(int dfd, char __user *fil |
83a957c9 | 16976 | int error; |
16977 | struct nameidata nd; | |
16978 | struct dentry *dentry; | |
16979 | + struct vfsmount *mnt; | |
16980 | struct inode *inode; | |
16981 | struct iattr newattrs; | |
16982 | struct file *f = NULL; | |
b79bc584 | 16983 | @@ -84,6 +86,7 @@ long do_utimes(int dfd, char __user *fil |
83a957c9 | 16984 | if (!f) |
16985 | goto out; | |
16986 | dentry = f->f_path.dentry; | |
16987 | + mnt = f->f_path.mnt; | |
16988 | } else { | |
16989 | error = __user_walk_fd(dfd, filename, (flags & AT_SYMLINK_NOFOLLOW) ? 0 : LOOKUP_FOLLOW, &nd); | |
16990 | if (error) | |
b79bc584 | 16991 | @@ -90,6 +93,7 @@ long do_utimes(int dfd, char __user *fil |
16992 | if (error) | |
16993 | goto dput_and_out; | |
4dee9bd5 | 16994 | dentry = nd.path.dentry; |
16995 | + mnt = nd.path.mnt; | |
83a957c9 | 16996 | } |
16997 | ||
16998 | inode = dentry->d_inode; | |
4dee9bd5 | 16999 | @@ -144,6 +148,12 @@ long do_utimes(int dfd, char __user *fil |
8a4b4a5e | 17000 | } |
17001 | } | |
50425a20 | 17002 | } |
17003 | + | |
83a957c9 | 17004 | + if (!gr_acl_handle_utime(dentry, mnt)) { |
50425a20 | 17005 | + error = -EACCES; |
17006 | + goto dput_and_out; | |
17007 | + } | |
17008 | + | |
17009 | mutex_lock(&inode->i_mutex); | |
8a4b4a5e | 17010 | error = notify_change(dentry, &newattrs); |
50425a20 | 17011 | mutex_unlock(&inode->i_mutex); |
4dee9bd5 | 17012 | diff -urNp linux-2.6.25.4/fs/xfs/linux-2.6/xfs_iops.c linux-2.6.25.4/fs/xfs/linux-2.6/xfs_iops.c |
17013 | --- linux-2.6.25.4/fs/xfs/linux-2.6/xfs_iops.c 2008-05-15 11:00:12.000000000 -0400 | |
17014 | +++ linux-2.6.25.4/fs/xfs/linux-2.6/xfs_iops.c 2008-05-18 13:33:16.000000000 -0400 | |
17015 | @@ -547,7 +547,7 @@ xfs_vn_put_link( | |
da5b3fc8 | 17016 | struct nameidata *nd, |
17017 | void *p) | |
17018 | { | |
17019 | - char *s = nd_get_link(nd); | |
17020 | + const char *s = nd_get_link(nd); | |
17021 | ||
17022 | if (!IS_ERR(s)) | |
17023 | kfree(s); | |
4dee9bd5 | 17024 | diff -urNp linux-2.6.25.4/fs/xfs/xfs_bmap.c linux-2.6.25.4/fs/xfs/xfs_bmap.c |
17025 | --- linux-2.6.25.4/fs/xfs/xfs_bmap.c 2008-05-15 11:00:12.000000000 -0400 | |
17026 | +++ linux-2.6.25.4/fs/xfs/xfs_bmap.c 2008-05-18 13:33:16.000000000 -0400 | |
da5b3fc8 | 17027 | @@ -360,7 +360,7 @@ xfs_bmap_validate_ret( |
50425a20 | 17028 | int nmap, |
17029 | int ret_nmap); | |
17030 | #else | |
17031 | -#define xfs_bmap_validate_ret(bno,len,flags,mval,onmap,nmap) | |
17032 | +#define xfs_bmap_validate_ret(bno,len,flags,mval,onmap,nmap) do {} while (0) | |
17033 | #endif /* DEBUG */ | |
17034 | ||
17035 | #if defined(XFS_RW_TRACE) | |
4dee9bd5 | 17036 | diff -urNp linux-2.6.25.4/grsecurity/gracl_alloc.c linux-2.6.25.4/grsecurity/gracl_alloc.c |
17037 | --- linux-2.6.25.4/grsecurity/gracl_alloc.c 1969-12-31 19:00:00.000000000 -0500 | |
17038 | +++ linux-2.6.25.4/grsecurity/gracl_alloc.c 2008-05-18 13:33:16.000000000 -0400 | |
50425a20 | 17039 | @@ -0,0 +1,91 @@ |
17040 | +#include <linux/kernel.h> | |
17041 | +#include <linux/mm.h> | |
17042 | +#include <linux/slab.h> | |
17043 | +#include <linux/vmalloc.h> | |
17044 | +#include <linux/gracl.h> | |
17045 | +#include <linux/grsecurity.h> | |
17046 | + | |
17047 | +static unsigned long alloc_stack_next = 1; | |
17048 | +static unsigned long alloc_stack_size = 1; | |
17049 | +static void **alloc_stack; | |
17050 | + | |
17051 | +static __inline__ int | |
17052 | +alloc_pop(void) | |
17053 | +{ | |
17054 | + if (alloc_stack_next == 1) | |
17055 | + return 0; | |
17056 | + | |
17057 | + kfree(alloc_stack[alloc_stack_next - 2]); | |
17058 | + | |
17059 | + alloc_stack_next--; | |
17060 | + | |
17061 | + return 1; | |
17062 | +} | |
17063 | + | |
17064 | +static __inline__ void | |
17065 | +alloc_push(void *buf) | |
17066 | +{ | |
17067 | + if (alloc_stack_next >= alloc_stack_size) | |
17068 | + BUG(); | |
17069 | + | |
17070 | + alloc_stack[alloc_stack_next - 1] = buf; | |
17071 | + | |
17072 | + alloc_stack_next++; | |
17073 | + | |
17074 | + return; | |
17075 | +} | |
17076 | + | |
17077 | +void * | |
17078 | +acl_alloc(unsigned long len) | |
17079 | +{ | |
17080 | + void *ret; | |
17081 | + | |
17082 | + if (len > PAGE_SIZE) | |
17083 | + BUG(); | |
17084 | + | |
17085 | + ret = kmalloc(len, GFP_KERNEL); | |
17086 | + | |
17087 | + if (ret) | |
17088 | + alloc_push(ret); | |
17089 | + | |
17090 | + return ret; | |
17091 | +} | |
17092 | + | |
17093 | +void | |
17094 | +acl_free_all(void) | |
17095 | +{ | |
17096 | + if (gr_acl_is_enabled() || !alloc_stack) | |
17097 | + return; | |
17098 | + | |
17099 | + while (alloc_pop()) ; | |
17100 | + | |
17101 | + if (alloc_stack) { | |
17102 | + if ((alloc_stack_size * sizeof (void *)) <= PAGE_SIZE) | |
17103 | + kfree(alloc_stack); | |
17104 | + else | |
17105 | + vfree(alloc_stack); | |
17106 | + } | |
17107 | + | |
17108 | + alloc_stack = NULL; | |
17109 | + alloc_stack_size = 1; | |
17110 | + alloc_stack_next = 1; | |
17111 | + | |
17112 | + return; | |
17113 | +} | |
17114 | + | |
17115 | +int | |
17116 | +acl_alloc_stack_init(unsigned long size) | |
17117 | +{ | |
17118 | + if ((size * sizeof (void *)) <= PAGE_SIZE) | |
17119 | + alloc_stack = | |
17120 | + (void **) kmalloc(size * sizeof (void *), GFP_KERNEL); | |
17121 | + else | |
17122 | + alloc_stack = (void **) vmalloc(size * sizeof (void *)); | |
17123 | + | |
17124 | + alloc_stack_size = size; | |
17125 | + | |
17126 | + if (!alloc_stack) | |
17127 | + return 0; | |
17128 | + else | |
17129 | + return 1; | |
17130 | +} | |
4dee9bd5 | 17131 | diff -urNp linux-2.6.25.4/grsecurity/gracl.c linux-2.6.25.4/grsecurity/gracl.c |
17132 | --- linux-2.6.25.4/grsecurity/gracl.c 1969-12-31 19:00:00.000000000 -0500 | |
17133 | +++ linux-2.6.25.4/grsecurity/gracl.c 2008-05-18 13:33:16.000000000 -0400 | |
17134 | @@ -0,0 +1,3721 @@ | |
50425a20 | 17135 | +#include <linux/kernel.h> |
17136 | +#include <linux/module.h> | |
17137 | +#include <linux/sched.h> | |
17138 | +#include <linux/mm.h> | |
17139 | +#include <linux/file.h> | |
17140 | +#include <linux/fs.h> | |
17141 | +#include <linux/namei.h> | |
17142 | +#include <linux/mount.h> | |
17143 | +#include <linux/tty.h> | |
17144 | +#include <linux/proc_fs.h> | |
17145 | +#include <linux/smp_lock.h> | |
17146 | +#include <linux/slab.h> | |
17147 | +#include <linux/vmalloc.h> | |
17148 | +#include <linux/types.h> | |
50425a20 | 17149 | +#include <linux/sysctl.h> |
17150 | +#include <linux/netdevice.h> | |
17151 | +#include <linux/ptrace.h> | |
17152 | +#include <linux/gracl.h> | |
17153 | +#include <linux/gralloc.h> | |
17154 | +#include <linux/grsecurity.h> | |
17155 | +#include <linux/grinternal.h> | |
17156 | +#include <linux/pid_namespace.h> | |
17157 | +#include <linux/percpu.h> | |
17158 | + | |
17159 | +#include <asm/uaccess.h> | |
17160 | +#include <asm/errno.h> | |
17161 | +#include <asm/mman.h> | |
17162 | + | |
17163 | +static struct acl_role_db acl_role_set; | |
17164 | +static struct name_db name_set; | |
17165 | +static struct inodev_db inodev_set; | |
17166 | + | |
17167 | +/* for keeping track of userspace pointers used for subjects, so we | |
17168 | + can share references in the kernel as well | |
17169 | +*/ | |
17170 | + | |
17171 | +static struct dentry *real_root; | |
17172 | +static struct vfsmount *real_root_mnt; | |
17173 | + | |
17174 | +static struct acl_subj_map_db subj_map_set; | |
17175 | + | |
17176 | +static struct acl_role_label *default_role; | |
17177 | + | |
17178 | +static u16 acl_sp_role_value; | |
17179 | + | |
17180 | +extern char *gr_shared_page[4]; | |
17181 | +static DECLARE_MUTEX(gr_dev_sem); | |
17182 | +rwlock_t gr_inode_lock = RW_LOCK_UNLOCKED; | |
17183 | + | |
17184 | +struct gr_arg *gr_usermode; | |
17185 | + | |
17186 | +static unsigned int gr_status = GR_STATUS_INIT; | |
17187 | + | |
17188 | +extern int chkpw(struct gr_arg *entry, unsigned char *salt, unsigned char *sum); | |
17189 | +extern void gr_clear_learn_entries(void); | |
17190 | + | |
17191 | +#ifdef CONFIG_GRKERNSEC_RESLOG | |
17192 | +extern void gr_log_resource(const struct task_struct *task, | |
17193 | + const int res, const unsigned long wanted, const int gt); | |
17194 | +#endif | |
17195 | + | |
50425a20 | 17196 | +unsigned char *gr_system_salt; |
17197 | +unsigned char *gr_system_sum; | |
17198 | + | |
17199 | +static struct sprole_pw **acl_special_roles = NULL; | |
17200 | +static __u16 num_sprole_pws = 0; | |
17201 | + | |
17202 | +static struct acl_role_label *kernel_role = NULL; | |
17203 | + | |
17204 | +static unsigned int gr_auth_attempts = 0; | |
17205 | +static unsigned long gr_auth_expires = 0UL; | |
17206 | + | |
17207 | +extern struct vfsmount *sock_mnt; | |
17208 | +extern struct vfsmount *pipe_mnt; | |
17209 | +extern struct vfsmount *shm_mnt; | |
17210 | +static struct acl_object_label *fakefs_obj; | |
17211 | + | |
17212 | +extern int gr_init_uidset(void); | |
17213 | +extern void gr_free_uidset(void); | |
17214 | +extern void gr_remove_uid(uid_t uid); | |
17215 | +extern int gr_find_uid(uid_t uid); | |
17216 | + | |
17217 | +__inline__ int | |
17218 | +gr_acl_is_enabled(void) | |
17219 | +{ | |
17220 | + return (gr_status & GR_READY); | |
17221 | +} | |
17222 | + | |
17223 | +char gr_roletype_to_char(void) | |
17224 | +{ | |
17225 | + switch (current->role->roletype & | |
17226 | + (GR_ROLE_DEFAULT | GR_ROLE_USER | GR_ROLE_GROUP | | |
17227 | + GR_ROLE_SPECIAL)) { | |
17228 | + case GR_ROLE_DEFAULT: | |
17229 | + return 'D'; | |
17230 | + case GR_ROLE_USER: | |
17231 | + return 'U'; | |
17232 | + case GR_ROLE_GROUP: | |
17233 | + return 'G'; | |
17234 | + case GR_ROLE_SPECIAL: | |
17235 | + return 'S'; | |
17236 | + } | |
17237 | + | |
17238 | + return 'X'; | |
17239 | +} | |
17240 | + | |
17241 | +__inline__ int | |
17242 | +gr_acl_tpe_check(void) | |
17243 | +{ | |
17244 | + if (unlikely(!(gr_status & GR_READY))) | |
17245 | + return 0; | |
17246 | + if (current->role->roletype & GR_ROLE_TPE) | |
17247 | + return 1; | |
17248 | + else | |
17249 | + return 0; | |
17250 | +} | |
17251 | + | |
17252 | +int | |
17253 | +gr_handle_rawio(const struct inode *inode) | |
17254 | +{ | |
17255 | +#ifdef CONFIG_GRKERNSEC_CHROOT_CAPS | |
17256 | + if (inode && S_ISBLK(inode->i_mode) && | |
17257 | + grsec_enable_chroot_caps && proc_is_chrooted(current) && | |
17258 | + !capable(CAP_SYS_RAWIO)) | |
17259 | + return 1; | |
17260 | +#endif | |
17261 | + return 0; | |
17262 | +} | |
17263 | + | |
17264 | +static int | |
17265 | +gr_streq(const char *a, const char *b, const unsigned int lena, const unsigned int lenb) | |
17266 | +{ | |
17267 | + int i; | |
17268 | + unsigned long *l1; | |
17269 | + unsigned long *l2; | |
17270 | + unsigned char *c1; | |
17271 | + unsigned char *c2; | |
17272 | + int num_longs; | |
17273 | + | |
17274 | + if (likely(lena != lenb)) | |
17275 | + return 0; | |
17276 | + | |
17277 | + l1 = (unsigned long *)a; | |
17278 | + l2 = (unsigned long *)b; | |
17279 | + | |
17280 | + num_longs = lena / sizeof(unsigned long); | |
17281 | + | |
17282 | + for (i = num_longs; i--; l1++, l2++) { | |
17283 | + if (unlikely(*l1 != *l2)) | |
17284 | + return 0; | |
17285 | + } | |
17286 | + | |
17287 | + c1 = (unsigned char *) l1; | |
17288 | + c2 = (unsigned char *) l2; | |
17289 | + | |
17290 | + i = lena - (num_longs * sizeof(unsigned long)); | |
17291 | + | |
17292 | + for (; i--; c1++, c2++) { | |
17293 | + if (unlikely(*c1 != *c2)) | |
17294 | + return 0; | |
17295 | + } | |
17296 | + | |
17297 | + return 1; | |
17298 | +} | |
8a4b4a5e | 17299 | + |
17300 | +static char * __our_d_path(struct dentry *dentry, struct vfsmount *vfsmnt, | |
17301 | + struct dentry *root, struct vfsmount *rootmnt, | |
17302 | + char *buffer, int buflen) | |
50425a20 | 17303 | +{ |
8a4b4a5e | 17304 | + char * end = buffer+buflen; |
17305 | + char * retval; | |
17306 | + int namelen; | |
50425a20 | 17307 | + |
17308 | + *--end = '\0'; | |
8a4b4a5e | 17309 | + buflen--; |
50425a20 | 17310 | + |
8a4b4a5e | 17311 | + if (buflen < 1) |
17312 | + goto Elong; | |
17313 | + /* Get '/' right */ | |
17314 | + retval = end-1; | |
50425a20 | 17315 | + *retval = '/'; |
17316 | + | |
8a4b4a5e | 17317 | + for (;;) { |
17318 | + struct dentry * parent; | |
50425a20 | 17319 | + |
8a4b4a5e | 17320 | + if (dentry == root && vfsmnt == rootmnt) |
17321 | + break; | |
17322 | + if (dentry == vfsmnt->mnt_root || IS_ROOT(dentry)) { | |
17323 | + /* Global root? */ | |
17324 | + spin_lock(&vfsmount_lock); | |
17325 | + if (vfsmnt->mnt_parent == vfsmnt) { | |
17326 | + spin_unlock(&vfsmount_lock); | |
17327 | + goto global_root; | |
17328 | + } | |
17329 | + dentry = vfsmnt->mnt_mountpoint; | |
17330 | + vfsmnt = vfsmnt->mnt_parent; | |
17331 | + spin_unlock(&vfsmount_lock); | |
17332 | + continue; | |
17333 | + } | |
17334 | + parent = dentry->d_parent; | |
17335 | + prefetch(parent); | |
17336 | + namelen = dentry->d_name.len; | |
17337 | + buflen -= namelen + 1; | |
17338 | + if (buflen < 0) | |
17339 | + goto Elong; | |
17340 | + end -= namelen; | |
50425a20 | 17341 | + memcpy(end, dentry->d_name.name, namelen); |
8a4b4a5e | 17342 | + *--end = '/'; |
17343 | + retval = end; | |
17344 | + dentry = parent; | |
50425a20 | 17345 | + } |
17346 | + | |
17347 | + return retval; | |
8a4b4a5e | 17348 | + |
17349 | +global_root: | |
17350 | + namelen = dentry->d_name.len; | |
17351 | + buflen -= namelen; | |
17352 | + if (buflen < 0) | |
17353 | + goto Elong; | |
17354 | + retval -= namelen-1; /* hit the slash */ | |
17355 | + memcpy(retval, dentry->d_name.name, namelen); | |
17356 | + return retval; | |
17357 | +Elong: | |
17358 | + return ERR_PTR(-ENAMETOOLONG); | |
17359 | +} | |
17360 | + | |
17361 | +static char * | |
17362 | +gen_full_path(struct dentry *dentry, struct vfsmount *vfsmnt, | |
17363 | + struct dentry *root, struct vfsmount *rootmnt, char *buf, int buflen) | |
17364 | +{ | |
17365 | + char *retval; | |
17366 | + | |
bd5cefb4 | 17367 | + retval = __our_d_path(dentry, vfsmnt, root, rootmnt, buf, buflen); |
8a4b4a5e | 17368 | + if (unlikely(IS_ERR(retval))) |
17369 | + retval = strcpy(buf, "<path too long>"); | |
17370 | + else if (unlikely(retval[1] == '/' && retval[2] == '\0')) | |
17371 | + retval[1] = '\0'; | |
17372 | + | |
17373 | + return retval; | |
17374 | +} | |
50425a20 | 17375 | + |
17376 | +static char * | |
17377 | +__d_real_path(const struct dentry *dentry, const struct vfsmount *vfsmnt, | |
17378 | + char *buf, int buflen) | |
17379 | +{ | |
17380 | + char *res; | |
17381 | + | |
17382 | + /* we can use real_root, real_root_mnt, because this is only called | |
17383 | + by the RBAC system */ | |
17384 | + res = gen_full_path((struct dentry *)dentry, (struct vfsmount *)vfsmnt, real_root, real_root_mnt, buf, buflen); | |
17385 | + | |
17386 | + return res; | |
17387 | +} | |
17388 | + | |
17389 | +static char * | |
17390 | +d_real_path(const struct dentry *dentry, const struct vfsmount *vfsmnt, | |
17391 | + char *buf, int buflen) | |
17392 | +{ | |
17393 | + char *res; | |
17394 | + struct dentry *root; | |
17395 | + struct vfsmount *rootmnt; | |
da5b3fc8 | 17396 | + struct task_struct *reaper = current->nsproxy->pid_ns->child_reaper; |
50425a20 | 17397 | + |
17398 | + /* we can't use real_root, real_root_mnt, because they belong only to the RBAC system */ | |
17399 | + read_lock(&reaper->fs->lock); | |
4dee9bd5 | 17400 | + root = dget(reaper->fs->root.dentry); |
17401 | + rootmnt = mntget(reaper->fs->root.mnt); | |
50425a20 | 17402 | + read_unlock(&reaper->fs->lock); |
17403 | + | |
17404 | + spin_lock(&dcache_lock); | |
17405 | + res = gen_full_path((struct dentry *)dentry, (struct vfsmount *)vfsmnt, root, rootmnt, buf, buflen); | |
17406 | + spin_unlock(&dcache_lock); | |
17407 | + | |
17408 | + dput(root); | |
17409 | + mntput(rootmnt); | |
17410 | + return res; | |
17411 | +} | |
17412 | + | |
17413 | +static char * | |
17414 | +gr_to_filename_rbac(const struct dentry *dentry, const struct vfsmount *mnt) | |
17415 | +{ | |
17416 | + char *ret; | |
17417 | + spin_lock(&dcache_lock); | |
17418 | + ret = __d_real_path(dentry, mnt, per_cpu_ptr(gr_shared_page[0],smp_processor_id()), | |
17419 | + PAGE_SIZE); | |
17420 | + spin_unlock(&dcache_lock); | |
17421 | + return ret; | |
17422 | +} | |
17423 | + | |
17424 | +char * | |
17425 | +gr_to_filename_nolock(const struct dentry *dentry, const struct vfsmount *mnt) | |
17426 | +{ | |
17427 | + return __d_real_path(dentry, mnt, per_cpu_ptr(gr_shared_page[0],smp_processor_id()), | |
17428 | + PAGE_SIZE); | |
17429 | +} | |
17430 | + | |
17431 | +char * | |
17432 | +gr_to_filename(const struct dentry *dentry, const struct vfsmount *mnt) | |
17433 | +{ | |
17434 | + return d_real_path(dentry, mnt, per_cpu_ptr(gr_shared_page[0], smp_processor_id()), | |
17435 | + PAGE_SIZE); | |
17436 | +} | |
17437 | + | |
17438 | +char * | |
17439 | +gr_to_filename1(const struct dentry *dentry, const struct vfsmount *mnt) | |
17440 | +{ | |
17441 | + return d_real_path(dentry, mnt, per_cpu_ptr(gr_shared_page[1], smp_processor_id()), | |
17442 | + PAGE_SIZE); | |
17443 | +} | |
17444 | + | |
17445 | +char * | |
17446 | +gr_to_filename2(const struct dentry *dentry, const struct vfsmount *mnt) | |
17447 | +{ | |
17448 | + return d_real_path(dentry, mnt, per_cpu_ptr(gr_shared_page[2], smp_processor_id()), | |
17449 | + PAGE_SIZE); | |
17450 | +} | |
17451 | + | |
17452 | +char * | |
17453 | +gr_to_filename3(const struct dentry *dentry, const struct vfsmount *mnt) | |
17454 | +{ | |
17455 | + return d_real_path(dentry, mnt, per_cpu_ptr(gr_shared_page[3], smp_processor_id()), | |
17456 | + PAGE_SIZE); | |
17457 | +} | |
17458 | + | |
17459 | +__inline__ __u32 | |
17460 | +to_gr_audit(const __u32 reqmode) | |
17461 | +{ | |
17462 | + /* masks off auditable permission flags, then shifts them to create | |
17463 | + auditing flags, and adds the special case of append auditing if | |
17464 | + we're requesting write */ | |
da5b3fc8 | 17465 | + return (((reqmode & ~GR_AUDITS) << 10) | ((reqmode & GR_WRITE) ? GR_AUDIT_APPEND : 0)); |
50425a20 | 17466 | +} |
17467 | + | |
17468 | +struct acl_subject_label * | |
17469 | +lookup_subject_map(const struct acl_subject_label *userp) | |
17470 | +{ | |
17471 | + unsigned int index = shash(userp, subj_map_set.s_size); | |
17472 | + struct subject_map *match; | |
17473 | + | |
17474 | + match = subj_map_set.s_hash[index]; | |
17475 | + | |
17476 | + while (match && match->user != userp) | |
17477 | + match = match->next; | |
17478 | + | |
17479 | + if (match != NULL) | |
17480 | + return match->kernel; | |
17481 | + else | |
17482 | + return NULL; | |
17483 | +} | |
17484 | + | |
17485 | +static void | |
17486 | +insert_subj_map_entry(struct subject_map *subjmap) | |
17487 | +{ | |
17488 | + unsigned int index = shash(subjmap->user, subj_map_set.s_size); | |
17489 | + struct subject_map **curr; | |
17490 | + | |
17491 | + subjmap->prev = NULL; | |
17492 | + | |
17493 | + curr = &subj_map_set.s_hash[index]; | |
17494 | + if (*curr != NULL) | |
17495 | + (*curr)->prev = subjmap; | |
17496 | + | |
17497 | + subjmap->next = *curr; | |
17498 | + *curr = subjmap; | |
17499 | + | |
17500 | + return; | |
17501 | +} | |
17502 | + | |
17503 | +static struct acl_role_label * | |
17504 | +lookup_acl_role_label(const struct task_struct *task, const uid_t uid, | |
17505 | + const gid_t gid) | |
17506 | +{ | |
17507 | + unsigned int index = rhash(uid, GR_ROLE_USER, acl_role_set.r_size); | |
17508 | + struct acl_role_label *match; | |
17509 | + struct role_allowed_ip *ipp; | |
17510 | + unsigned int x; | |
17511 | + | |
17512 | + match = acl_role_set.r_hash[index]; | |
17513 | + | |
17514 | + while (match) { | |
17515 | + if ((match->roletype & (GR_ROLE_DOMAIN | GR_ROLE_USER)) == (GR_ROLE_DOMAIN | GR_ROLE_USER)) { | |
17516 | + for (x = 0; x < match->domain_child_num; x++) { | |
17517 | + if (match->domain_children[x] == uid) | |
17518 | + goto found; | |
17519 | + } | |
17520 | + } else if (match->uidgid == uid && match->roletype & GR_ROLE_USER) | |
17521 | + break; | |
17522 | + match = match->next; | |
17523 | + } | |
17524 | +found: | |
17525 | + if (match == NULL) { | |
17526 | + try_group: | |
17527 | + index = rhash(gid, GR_ROLE_GROUP, acl_role_set.r_size); | |
17528 | + match = acl_role_set.r_hash[index]; | |
17529 | + | |
17530 | + while (match) { | |
17531 | + if ((match->roletype & (GR_ROLE_DOMAIN | GR_ROLE_GROUP)) == (GR_ROLE_DOMAIN | GR_ROLE_GROUP)) { | |
17532 | + for (x = 0; x < match->domain_child_num; x++) { | |
17533 | + if (match->domain_children[x] == gid) | |
17534 | + goto found2; | |
17535 | + } | |
17536 | + } else if (match->uidgid == gid && match->roletype & GR_ROLE_GROUP) | |
17537 | + break; | |
17538 | + match = match->next; | |
17539 | + } | |
17540 | +found2: | |
17541 | + if (match == NULL) | |
17542 | + match = default_role; | |
17543 | + if (match->allowed_ips == NULL) | |
17544 | + return match; | |
17545 | + else { | |
17546 | + for (ipp = match->allowed_ips; ipp; ipp = ipp->next) { | |
17547 | + if (likely | |
17548 | + ((ntohl(task->signal->curr_ip) & ipp->netmask) == | |
17549 | + (ntohl(ipp->addr) & ipp->netmask))) | |
17550 | + return match; | |
17551 | + } | |
17552 | + match = default_role; | |
17553 | + } | |
17554 | + } else if (match->allowed_ips == NULL) { | |
17555 | + return match; | |
17556 | + } else { | |
17557 | + for (ipp = match->allowed_ips; ipp; ipp = ipp->next) { | |
17558 | + if (likely | |
17559 | + ((ntohl(task->signal->curr_ip) & ipp->netmask) == | |
17560 | + (ntohl(ipp->addr) & ipp->netmask))) | |
17561 | + return match; | |
17562 | + } | |
17563 | + goto try_group; | |
17564 | + } | |
17565 | + | |
17566 | + return match; | |
17567 | +} | |
17568 | + | |
17569 | +struct acl_subject_label * | |
17570 | +lookup_acl_subj_label(const ino_t ino, const dev_t dev, | |
17571 | + const struct acl_role_label *role) | |
17572 | +{ | |
17573 | + unsigned int index = fhash(ino, dev, role->subj_hash_size); | |
17574 | + struct acl_subject_label *match; | |
17575 | + | |
17576 | + match = role->subj_hash[index]; | |
17577 | + | |
17578 | + while (match && (match->inode != ino || match->device != dev || | |
17579 | + (match->mode & GR_DELETED))) { | |
17580 | + match = match->next; | |
17581 | + } | |
17582 | + | |
17583 | + if (match && !(match->mode & GR_DELETED)) | |
17584 | + return match; | |
17585 | + else | |
17586 | + return NULL; | |
17587 | +} | |
17588 | + | |
17589 | +static struct acl_object_label * | |
17590 | +lookup_acl_obj_label(const ino_t ino, const dev_t dev, | |
17591 | + const struct acl_subject_label *subj) | |
17592 | +{ | |
17593 | + unsigned int index = fhash(ino, dev, subj->obj_hash_size); | |
17594 | + struct acl_object_label *match; | |
17595 | + | |
17596 | + match = subj->obj_hash[index]; | |
17597 | + | |
17598 | + while (match && (match->inode != ino || match->device != dev || | |
17599 | + (match->mode & GR_DELETED))) { | |
17600 | + match = match->next; | |
17601 | + } | |
17602 | + | |
17603 | + if (match && !(match->mode & GR_DELETED)) | |
17604 | + return match; | |
17605 | + else | |
17606 | + return NULL; | |
17607 | +} | |
17608 | + | |
17609 | +static struct acl_object_label * | |
17610 | +lookup_acl_obj_label_create(const ino_t ino, const dev_t dev, | |
17611 | + const struct acl_subject_label *subj) | |
17612 | +{ | |
17613 | + unsigned int index = fhash(ino, dev, subj->obj_hash_size); | |
17614 | + struct acl_object_label *match; | |
17615 | + | |
17616 | + match = subj->obj_hash[index]; | |
17617 | + | |
17618 | + while (match && (match->inode != ino || match->device != dev || | |
17619 | + !(match->mode & GR_DELETED))) { | |
17620 | + match = match->next; | |
17621 | + } | |
17622 | + | |
17623 | + if (match && (match->mode & GR_DELETED)) | |
17624 | + return match; | |
17625 | + | |
17626 | + match = subj->obj_hash[index]; | |
17627 | + | |
17628 | + while (match && (match->inode != ino || match->device != dev || | |
17629 | + (match->mode & GR_DELETED))) { | |
17630 | + match = match->next; | |
17631 | + } | |
17632 | + | |
17633 | + if (match && !(match->mode & GR_DELETED)) | |
17634 | + return match; | |
17635 | + else | |
17636 | + return NULL; | |
17637 | +} | |
17638 | + | |
17639 | +static struct name_entry * | |
17640 | +lookup_name_entry(const char *name) | |
17641 | +{ | |
17642 | + unsigned int len = strlen(name); | |
17643 | + unsigned int key = full_name_hash(name, len); | |
17644 | + unsigned int index = key % name_set.n_size; | |
17645 | + struct name_entry *match; | |
17646 | + | |
17647 | + match = name_set.n_hash[index]; | |
17648 | + | |
17649 | + while (match && (match->key != key || !gr_streq(match->name, name, match->len, len))) | |
17650 | + match = match->next; | |
17651 | + | |
17652 | + return match; | |
17653 | +} | |
17654 | + | |
da5b3fc8 | 17655 | +static struct name_entry * |
17656 | +lookup_name_entry_create(const char *name) | |
17657 | +{ | |
17658 | + unsigned int len = strlen(name); | |
17659 | + unsigned int key = full_name_hash(name, len); | |
17660 | + unsigned int index = key % name_set.n_size; | |
17661 | + struct name_entry *match; | |
17662 | + | |
17663 | + match = name_set.n_hash[index]; | |
17664 | + | |
17665 | + while (match && (match->key != key || !gr_streq(match->name, name, match->len, len) || | |
17666 | + !match->deleted)) | |
17667 | + match = match->next; | |
17668 | + | |
17669 | + if (match && match->deleted) | |
17670 | + return match; | |
17671 | + | |
17672 | + match = name_set.n_hash[index]; | |
17673 | + | |
17674 | + while (match && (match->key != key || !gr_streq(match->name, name, match->len, len) || | |
17675 | + match->deleted)) | |
17676 | + match = match->next; | |
17677 | + | |
17678 | + if (match && !match->deleted) | |
17679 | + return match; | |
17680 | + else | |
17681 | + return NULL; | |
17682 | +} | |
17683 | + | |
50425a20 | 17684 | +static struct inodev_entry * |
17685 | +lookup_inodev_entry(const ino_t ino, const dev_t dev) | |
17686 | +{ | |
17687 | + unsigned int index = fhash(ino, dev, inodev_set.i_size); | |
17688 | + struct inodev_entry *match; | |
17689 | + | |
17690 | + match = inodev_set.i_hash[index]; | |
17691 | + | |
17692 | + while (match && (match->nentry->inode != ino || match->nentry->device != dev)) | |
17693 | + match = match->next; | |
17694 | + | |
17695 | + return match; | |
17696 | +} | |
17697 | + | |
17698 | +static void | |
17699 | +insert_inodev_entry(struct inodev_entry *entry) | |
17700 | +{ | |
17701 | + unsigned int index = fhash(entry->nentry->inode, entry->nentry->device, | |
17702 | + inodev_set.i_size); | |
17703 | + struct inodev_entry **curr; | |
17704 | + | |
17705 | + entry->prev = NULL; | |
17706 | + | |
17707 | + curr = &inodev_set.i_hash[index]; | |
17708 | + if (*curr != NULL) | |
17709 | + (*curr)->prev = entry; | |
17710 | + | |
17711 | + entry->next = *curr; | |
17712 | + *curr = entry; | |
17713 | + | |
17714 | + return; | |
17715 | +} | |
17716 | + | |
17717 | +static void | |
17718 | +__insert_acl_role_label(struct acl_role_label *role, uid_t uidgid) | |
17719 | +{ | |
17720 | + unsigned int index = | |
17721 | + rhash(uidgid, role->roletype & (GR_ROLE_USER | GR_ROLE_GROUP), acl_role_set.r_size); | |
17722 | + struct acl_role_label **curr; | |
17723 | + | |
17724 | + role->prev = NULL; | |
17725 | + | |
17726 | + curr = &acl_role_set.r_hash[index]; | |
17727 | + if (*curr != NULL) | |
17728 | + (*curr)->prev = role; | |
17729 | + | |
17730 | + role->next = *curr; | |
17731 | + *curr = role; | |
17732 | + | |
17733 | + return; | |
17734 | +} | |
17735 | + | |
17736 | +static void | |
17737 | +insert_acl_role_label(struct acl_role_label *role) | |
17738 | +{ | |
17739 | + int i; | |
17740 | + | |
17741 | + if (role->roletype & GR_ROLE_DOMAIN) { | |
17742 | + for (i = 0; i < role->domain_child_num; i++) | |
17743 | + __insert_acl_role_label(role, role->domain_children[i]); | |
17744 | + } else | |
17745 | + __insert_acl_role_label(role, role->uidgid); | |
17746 | +} | |
17747 | + | |
17748 | +static int | |
da5b3fc8 | 17749 | +insert_name_entry(char *name, const ino_t inode, const dev_t device, __u8 deleted) |
50425a20 | 17750 | +{ |
17751 | + struct name_entry **curr, *nentry; | |
17752 | + struct inodev_entry *ientry; | |
17753 | + unsigned int len = strlen(name); | |
17754 | + unsigned int key = full_name_hash(name, len); | |
17755 | + unsigned int index = key % name_set.n_size; | |
17756 | + | |
17757 | + curr = &name_set.n_hash[index]; | |
17758 | + | |
17759 | + while (*curr && ((*curr)->key != key || !gr_streq((*curr)->name, name, (*curr)->len, len))) | |
17760 | + curr = &((*curr)->next); | |
17761 | + | |
17762 | + if (*curr != NULL) | |
17763 | + return 1; | |
17764 | + | |
17765 | + nentry = acl_alloc(sizeof (struct name_entry)); | |
17766 | + if (nentry == NULL) | |
17767 | + return 0; | |
17768 | + ientry = acl_alloc(sizeof (struct inodev_entry)); | |
17769 | + if (ientry == NULL) | |
17770 | + return 0; | |
17771 | + ientry->nentry = nentry; | |
17772 | + | |
17773 | + nentry->key = key; | |
17774 | + nentry->name = name; | |
17775 | + nentry->inode = inode; | |
17776 | + nentry->device = device; | |
17777 | + nentry->len = len; | |
da5b3fc8 | 17778 | + nentry->deleted = deleted; |
50425a20 | 17779 | + |
17780 | + nentry->prev = NULL; | |
17781 | + curr = &name_set.n_hash[index]; | |
17782 | + if (*curr != NULL) | |
17783 | + (*curr)->prev = nentry; | |
17784 | + nentry->next = *curr; | |
17785 | + *curr = nentry; | |
17786 | + | |
17787 | + /* insert us into the table searchable by inode/dev */ | |
17788 | + insert_inodev_entry(ientry); | |
17789 | + | |
17790 | + return 1; | |
17791 | +} | |
17792 | + | |
17793 | +static void | |
17794 | +insert_acl_obj_label(struct acl_object_label *obj, | |
17795 | + struct acl_subject_label *subj) | |
17796 | +{ | |
17797 | + unsigned int index = | |
17798 | + fhash(obj->inode, obj->device, subj->obj_hash_size); | |
17799 | + struct acl_object_label **curr; | |
17800 | + | |
17801 | + | |
17802 | + obj->prev = NULL; | |
17803 | + | |
17804 | + curr = &subj->obj_hash[index]; | |
17805 | + if (*curr != NULL) | |
17806 | + (*curr)->prev = obj; | |
17807 | + | |
17808 | + obj->next = *curr; | |
17809 | + *curr = obj; | |
17810 | + | |
17811 | + return; | |
17812 | +} | |
17813 | + | |
17814 | +static void | |
17815 | +insert_acl_subj_label(struct acl_subject_label *obj, | |
17816 | + struct acl_role_label *role) | |
17817 | +{ | |
17818 | + unsigned int index = fhash(obj->inode, obj->device, role->subj_hash_size); | |
17819 | + struct acl_subject_label **curr; | |
17820 | + | |
17821 | + obj->prev = NULL; | |
17822 | + | |
17823 | + curr = &role->subj_hash[index]; | |
17824 | + if (*curr != NULL) | |
17825 | + (*curr)->prev = obj; | |
17826 | + | |
17827 | + obj->next = *curr; | |
17828 | + *curr = obj; | |
17829 | + | |
17830 | + return; | |
17831 | +} | |
17832 | + | |
17833 | +/* allocating chained hash tables, so optimal size is where lambda ~ 1 */ | |
17834 | + | |
17835 | +static void * | |
17836 | +create_table(__u32 * len, int elementsize) | |
17837 | +{ | |
17838 | + unsigned int table_sizes[] = { | |
17839 | + 7, 13, 31, 61, 127, 251, 509, 1021, 2039, 4093, 8191, 16381, | |
17840 | + 32749, 65521, 131071, 262139, 524287, 1048573, 2097143, | |
17841 | + 4194301, 8388593, 16777213, 33554393, 67108859, 134217689, | |
17842 | + 268435399, 536870909, 1073741789, 2147483647 | |
17843 | + }; | |
17844 | + void *newtable = NULL; | |
17845 | + unsigned int pwr = 0; | |
17846 | + | |
17847 | + while ((pwr < ((sizeof (table_sizes) / sizeof (table_sizes[0])) - 1)) && | |
17848 | + table_sizes[pwr] <= *len) | |
17849 | + pwr++; | |
17850 | + | |
17851 | + if (table_sizes[pwr] <= *len) | |
17852 | + return newtable; | |
17853 | + | |
17854 | + if ((table_sizes[pwr] * elementsize) <= PAGE_SIZE) | |
17855 | + newtable = | |
17856 | + kmalloc(table_sizes[pwr] * elementsize, GFP_KERNEL); | |
17857 | + else | |
17858 | + newtable = vmalloc(table_sizes[pwr] * elementsize); | |
17859 | + | |
17860 | + *len = table_sizes[pwr]; | |
17861 | + | |
17862 | + return newtable; | |
17863 | +} | |
17864 | + | |
17865 | +static int | |
17866 | +init_variables(const struct gr_arg *arg) | |
17867 | +{ | |
da5b3fc8 | 17868 | + struct task_struct *reaper = current->nsproxy->pid_ns->child_reaper; |
50425a20 | 17869 | + unsigned int stacksize; |
17870 | + | |
17871 | + subj_map_set.s_size = arg->role_db.num_subjects; | |
17872 | + acl_role_set.r_size = arg->role_db.num_roles + arg->role_db.num_domain_children; | |
17873 | + name_set.n_size = arg->role_db.num_objects; | |
17874 | + inodev_set.i_size = arg->role_db.num_objects; | |
17875 | + | |
17876 | + if (!subj_map_set.s_size || !acl_role_set.r_size || | |
17877 | + !name_set.n_size || !inodev_set.i_size) | |
17878 | + return 1; | |
17879 | + | |
17880 | + if (!gr_init_uidset()) | |
17881 | + return 1; | |
17882 | + | |
17883 | + /* set up the stack that holds allocation info */ | |
17884 | + | |
17885 | + stacksize = arg->role_db.num_pointers + 5; | |
17886 | + | |
17887 | + if (!acl_alloc_stack_init(stacksize)) | |
17888 | + return 1; | |
17889 | + | |
17890 | + /* grab reference for the real root dentry and vfsmount */ | |
17891 | + read_lock(&reaper->fs->lock); | |
4dee9bd5 | 17892 | + real_root_mnt = mntget(reaper->fs->root.mnt); |
17893 | + real_root = dget(reaper->fs->root.dentry); | |
50425a20 | 17894 | + read_unlock(&reaper->fs->lock); |
17895 | + | |
17896 | + fakefs_obj = acl_alloc(sizeof(struct acl_object_label)); | |
17897 | + if (fakefs_obj == NULL) | |
17898 | + return 1; | |
17899 | + fakefs_obj->mode = GR_FIND | GR_READ | GR_WRITE | GR_EXEC; | |
17900 | + | |
17901 | + subj_map_set.s_hash = | |
17902 | + (struct subject_map **) create_table(&subj_map_set.s_size, sizeof(void *)); | |
17903 | + acl_role_set.r_hash = | |
17904 | + (struct acl_role_label **) create_table(&acl_role_set.r_size, sizeof(void *)); | |
17905 | + name_set.n_hash = (struct name_entry **) create_table(&name_set.n_size, sizeof(void *)); | |
17906 | + inodev_set.i_hash = | |
17907 | + (struct inodev_entry **) create_table(&inodev_set.i_size, sizeof(void *)); | |
17908 | + | |
17909 | + if (!subj_map_set.s_hash || !acl_role_set.r_hash || | |
17910 | + !name_set.n_hash || !inodev_set.i_hash) | |
17911 | + return 1; | |
17912 | + | |
17913 | + memset(subj_map_set.s_hash, 0, | |
17914 | + sizeof(struct subject_map *) * subj_map_set.s_size); | |
17915 | + memset(acl_role_set.r_hash, 0, | |
17916 | + sizeof (struct acl_role_label *) * acl_role_set.r_size); | |
17917 | + memset(name_set.n_hash, 0, | |
17918 | + sizeof (struct name_entry *) * name_set.n_size); | |
17919 | + memset(inodev_set.i_hash, 0, | |
17920 | + sizeof (struct inodev_entry *) * inodev_set.i_size); | |
17921 | + | |
17922 | + return 0; | |
17923 | +} | |
17924 | + | |
17925 | +/* free information not needed after startup | |
17926 | + currently contains user->kernel pointer mappings for subjects | |
17927 | +*/ | |
17928 | + | |
17929 | +static void | |
17930 | +free_init_variables(void) | |
17931 | +{ | |
17932 | + __u32 i; | |
17933 | + | |
17934 | + if (subj_map_set.s_hash) { | |
17935 | + for (i = 0; i < subj_map_set.s_size; i++) { | |
17936 | + if (subj_map_set.s_hash[i]) { | |
17937 | + kfree(subj_map_set.s_hash[i]); | |
17938 | + subj_map_set.s_hash[i] = NULL; | |
17939 | + } | |
17940 | + } | |
17941 | + | |
17942 | + if ((subj_map_set.s_size * sizeof (struct subject_map *)) <= | |
17943 | + PAGE_SIZE) | |
17944 | + kfree(subj_map_set.s_hash); | |
17945 | + else | |
17946 | + vfree(subj_map_set.s_hash); | |
17947 | + } | |
17948 | + | |
17949 | + return; | |
17950 | +} | |
17951 | + | |
17952 | +static void | |
17953 | +free_variables(void) | |
17954 | +{ | |
17955 | + struct acl_subject_label *s; | |
17956 | + struct acl_role_label *r; | |
17957 | + struct task_struct *task, *task2; | |
17958 | + unsigned int i, x; | |
17959 | + | |
17960 | + gr_clear_learn_entries(); | |
17961 | + | |
17962 | + read_lock(&tasklist_lock); | |
17963 | + do_each_thread(task2, task) { | |
17964 | + task->acl_sp_role = 0; | |
17965 | + task->acl_role_id = 0; | |
17966 | + task->acl = NULL; | |
17967 | + task->role = NULL; | |
17968 | + } while_each_thread(task2, task); | |
17969 | + read_unlock(&tasklist_lock); | |
17970 | + | |
17971 | + /* release the reference to the real root dentry and vfsmount */ | |
17972 | + if (real_root) | |
17973 | + dput(real_root); | |
17974 | + real_root = NULL; | |
17975 | + if (real_root_mnt) | |
17976 | + mntput(real_root_mnt); | |
17977 | + real_root_mnt = NULL; | |
17978 | + | |
17979 | + /* free all object hash tables */ | |
17980 | + | |
17981 | + FOR_EACH_ROLE_START(r, i) | |
17982 | + if (r->subj_hash == NULL) | |
17983 | + break; | |
17984 | + FOR_EACH_SUBJECT_START(r, s, x) | |
17985 | + if (s->obj_hash == NULL) | |
17986 | + break; | |
17987 | + if ((s->obj_hash_size * sizeof (struct acl_object_label *)) <= PAGE_SIZE) | |
17988 | + kfree(s->obj_hash); | |
17989 | + else | |
17990 | + vfree(s->obj_hash); | |
17991 | + FOR_EACH_SUBJECT_END(s, x) | |
17992 | + FOR_EACH_NESTED_SUBJECT_START(r, s) | |
17993 | + if (s->obj_hash == NULL) | |
17994 | + break; | |
17995 | + if ((s->obj_hash_size * sizeof (struct acl_object_label *)) <= PAGE_SIZE) | |
17996 | + kfree(s->obj_hash); | |
17997 | + else | |
17998 | + vfree(s->obj_hash); | |
17999 | + FOR_EACH_NESTED_SUBJECT_END(s) | |
18000 | + if ((r->subj_hash_size * sizeof (struct acl_subject_label *)) <= PAGE_SIZE) | |
18001 | + kfree(r->subj_hash); | |
18002 | + else | |
18003 | + vfree(r->subj_hash); | |
18004 | + r->subj_hash = NULL; | |
18005 | + FOR_EACH_ROLE_END(r,i) | |
18006 | + | |
18007 | + acl_free_all(); | |
18008 | + | |
18009 | + if (acl_role_set.r_hash) { | |
18010 | + if ((acl_role_set.r_size * sizeof (struct acl_role_label *)) <= | |
18011 | + PAGE_SIZE) | |
18012 | + kfree(acl_role_set.r_hash); | |
18013 | + else | |
18014 | + vfree(acl_role_set.r_hash); | |
18015 | + } | |
18016 | + if (name_set.n_hash) { | |
18017 | + if ((name_set.n_size * sizeof (struct name_entry *)) <= | |
18018 | + PAGE_SIZE) | |
18019 | + kfree(name_set.n_hash); | |
18020 | + else | |
18021 | + vfree(name_set.n_hash); | |
18022 | + } | |
18023 | + | |
18024 | + if (inodev_set.i_hash) { | |
18025 | + if ((inodev_set.i_size * sizeof (struct inodev_entry *)) <= | |
18026 | + PAGE_SIZE) | |
18027 | + kfree(inodev_set.i_hash); | |
18028 | + else | |
18029 | + vfree(inodev_set.i_hash); | |
18030 | + } | |
18031 | + | |
18032 | + gr_free_uidset(); | |
18033 | + | |
18034 | + memset(&name_set, 0, sizeof (struct name_db)); | |
18035 | + memset(&inodev_set, 0, sizeof (struct inodev_db)); | |
18036 | + memset(&acl_role_set, 0, sizeof (struct acl_role_db)); | |
18037 | + memset(&subj_map_set, 0, sizeof (struct acl_subj_map_db)); | |
18038 | + | |
18039 | + default_role = NULL; | |
18040 | + | |
18041 | + return; | |
18042 | +} | |
18043 | + | |
18044 | +static __u32 | |
18045 | +count_user_objs(struct acl_object_label *userp) | |
18046 | +{ | |
18047 | + struct acl_object_label o_tmp; | |
18048 | + __u32 num = 0; | |
18049 | + | |
18050 | + while (userp) { | |
18051 | + if (copy_from_user(&o_tmp, userp, | |
18052 | + sizeof (struct acl_object_label))) | |
18053 | + break; | |
18054 | + | |
18055 | + userp = o_tmp.prev; | |
18056 | + num++; | |
18057 | + } | |
18058 | + | |
18059 | + return num; | |
18060 | +} | |
18061 | + | |
18062 | +static struct acl_subject_label * | |
18063 | +do_copy_user_subj(struct acl_subject_label *userp, struct acl_role_label *role); | |
18064 | + | |
18065 | +static int | |
18066 | +copy_user_glob(struct acl_object_label *obj) | |
18067 | +{ | |
18068 | + struct acl_object_label *g_tmp, **guser; | |
18069 | + unsigned int len; | |
18070 | + char *tmp; | |
18071 | + | |
18072 | + if (obj->globbed == NULL) | |
18073 | + return 0; | |
18074 | + | |
18075 | + guser = &obj->globbed; | |
18076 | + while (*guser) { | |
18077 | + g_tmp = (struct acl_object_label *) | |
18078 | + acl_alloc(sizeof (struct acl_object_label)); | |
18079 | + if (g_tmp == NULL) | |
18080 | + return -ENOMEM; | |
18081 | + | |
18082 | + if (copy_from_user(g_tmp, *guser, | |
18083 | + sizeof (struct acl_object_label))) | |
18084 | + return -EFAULT; | |
18085 | + | |
18086 | + len = strnlen_user(g_tmp->filename, PATH_MAX); | |
18087 | + | |
18088 | + if (!len || len >= PATH_MAX) | |
18089 | + return -EINVAL; | |
18090 | + | |
18091 | + if ((tmp = (char *) acl_alloc(len)) == NULL) | |
18092 | + return -ENOMEM; | |
18093 | + | |
18094 | + if (copy_from_user(tmp, g_tmp->filename, len)) | |
18095 | + return -EFAULT; | |
18096 | + | |
18097 | + g_tmp->filename = tmp; | |
18098 | + | |
18099 | + *guser = g_tmp; | |
18100 | + guser = &(g_tmp->next); | |
18101 | + } | |
18102 | + | |
18103 | + return 0; | |
18104 | +} | |
18105 | + | |
18106 | +static int | |
18107 | +copy_user_objs(struct acl_object_label *userp, struct acl_subject_label *subj, | |
18108 | + struct acl_role_label *role) | |
18109 | +{ | |
18110 | + struct acl_object_label *o_tmp; | |
18111 | + unsigned int len; | |
18112 | + int ret; | |
18113 | + char *tmp; | |
18114 | + | |
18115 | + while (userp) { | |
18116 | + if ((o_tmp = (struct acl_object_label *) | |
18117 | + acl_alloc(sizeof (struct acl_object_label))) == NULL) | |
18118 | + return -ENOMEM; | |
18119 | + | |
18120 | + if (copy_from_user(o_tmp, userp, | |
18121 | + sizeof (struct acl_object_label))) | |
18122 | + return -EFAULT; | |
18123 | + | |
18124 | + userp = o_tmp->prev; | |
18125 | + | |
18126 | + len = strnlen_user(o_tmp->filename, PATH_MAX); | |
18127 | + | |
18128 | + if (!len || len >= PATH_MAX) | |
18129 | + return -EINVAL; | |
18130 | + | |
18131 | + if ((tmp = (char *) acl_alloc(len)) == NULL) | |
18132 | + return -ENOMEM; | |
18133 | + | |
18134 | + if (copy_from_user(tmp, o_tmp->filename, len)) | |
18135 | + return -EFAULT; | |
18136 | + | |
18137 | + o_tmp->filename = tmp; | |
18138 | + | |
18139 | + insert_acl_obj_label(o_tmp, subj); | |
18140 | + if (!insert_name_entry(o_tmp->filename, o_tmp->inode, | |
da5b3fc8 | 18141 | + o_tmp->device, (o_tmp->mode & GR_DELETED) ? 1 : 0)) |
50425a20 | 18142 | + return -ENOMEM; |
18143 | + | |
18144 | + ret = copy_user_glob(o_tmp); | |
18145 | + if (ret) | |
18146 | + return ret; | |
18147 | + | |
18148 | + if (o_tmp->nested) { | |
18149 | + o_tmp->nested = do_copy_user_subj(o_tmp->nested, role); | |
18150 | + if (IS_ERR(o_tmp->nested)) | |
18151 | + return PTR_ERR(o_tmp->nested); | |
18152 | + | |
18153 | + /* insert into nested subject list */ | |
18154 | + o_tmp->nested->next = role->hash->first; | |
18155 | + role->hash->first = o_tmp->nested; | |
18156 | + } | |
18157 | + } | |
18158 | + | |
18159 | + return 0; | |
18160 | +} | |
18161 | + | |
18162 | +static __u32 | |
18163 | +count_user_subjs(struct acl_subject_label *userp) | |
18164 | +{ | |
18165 | + struct acl_subject_label s_tmp; | |
18166 | + __u32 num = 0; | |
18167 | + | |
18168 | + while (userp) { | |
18169 | + if (copy_from_user(&s_tmp, userp, | |
18170 | + sizeof (struct acl_subject_label))) | |
18171 | + break; | |
18172 | + | |
18173 | + userp = s_tmp.prev; | |
18174 | + /* do not count nested subjects against this count, since | |
18175 | + they are not included in the hash table, but are | |
18176 | + attached to objects. We have already counted | |
18177 | + the subjects in userspace for the allocation | |
18178 | + stack | |
18179 | + */ | |
18180 | + if (!(s_tmp.mode & GR_NESTED)) | |
18181 | + num++; | |
18182 | + } | |
18183 | + | |
18184 | + return num; | |
18185 | +} | |
18186 | + | |
18187 | +static int | |
18188 | +copy_user_allowedips(struct acl_role_label *rolep) | |
18189 | +{ | |
18190 | + struct role_allowed_ip *ruserip, *rtmp = NULL, *rlast; | |
18191 | + | |
18192 | + ruserip = rolep->allowed_ips; | |
18193 | + | |
18194 | + while (ruserip) { | |
18195 | + rlast = rtmp; | |
18196 | + | |
18197 | + if ((rtmp = (struct role_allowed_ip *) | |
18198 | + acl_alloc(sizeof (struct role_allowed_ip))) == NULL) | |
18199 | + return -ENOMEM; | |
18200 | + | |
18201 | + if (copy_from_user(rtmp, ruserip, | |
18202 | + sizeof (struct role_allowed_ip))) | |
18203 | + return -EFAULT; | |
18204 | + | |
18205 | + ruserip = rtmp->prev; | |
18206 | + | |
18207 | + if (!rlast) { | |
18208 | + rtmp->prev = NULL; | |
18209 | + rolep->allowed_ips = rtmp; | |
18210 | + } else { | |
18211 | + rlast->next = rtmp; | |
18212 | + rtmp->prev = rlast; | |
18213 | + } | |
18214 | + | |
18215 | + if (!ruserip) | |
18216 | + rtmp->next = NULL; | |
18217 | + } | |
18218 | + | |
18219 | + return 0; | |
18220 | +} | |
18221 | + | |
18222 | +static int | |
18223 | +copy_user_transitions(struct acl_role_label *rolep) | |
18224 | +{ | |
18225 | + struct role_transition *rusertp, *rtmp = NULL, *rlast; | |
18226 | + | |
18227 | + unsigned int len; | |
18228 | + char *tmp; | |
18229 | + | |
18230 | + rusertp = rolep->transitions; | |
18231 | + | |
18232 | + while (rusertp) { | |
18233 | + rlast = rtmp; | |
18234 | + | |
18235 | + if ((rtmp = (struct role_transition *) | |
18236 | + acl_alloc(sizeof (struct role_transition))) == NULL) | |
18237 | + return -ENOMEM; | |
18238 | + | |
18239 | + if (copy_from_user(rtmp, rusertp, | |
18240 | + sizeof (struct role_transition))) | |
18241 | + return -EFAULT; | |
18242 | + | |
18243 | + rusertp = rtmp->prev; | |
18244 | + | |
18245 | + len = strnlen_user(rtmp->rolename, GR_SPROLE_LEN); | |
18246 | + | |
18247 | + if (!len || len >= GR_SPROLE_LEN) | |
18248 | + return -EINVAL; | |
18249 | + | |
18250 | + if ((tmp = (char *) acl_alloc(len)) == NULL) | |
18251 | + return -ENOMEM; | |
18252 | + | |
18253 | + if (copy_from_user(tmp, rtmp->rolename, len)) | |
18254 | + return -EFAULT; | |
18255 | + | |
18256 | + rtmp->rolename = tmp; | |
18257 | + | |
18258 | + if (!rlast) { | |
18259 | + rtmp->prev = NULL; | |
18260 | + rolep->transitions = rtmp; | |
18261 | + } else { | |
18262 | + rlast->next = rtmp; | |
18263 | + rtmp->prev = rlast; | |
18264 | + } | |
18265 | + | |
18266 | + if (!rusertp) | |
18267 | + rtmp->next = NULL; | |
18268 | + } | |
18269 | + | |
18270 | + return 0; | |
18271 | +} | |
18272 | + | |
18273 | +static struct acl_subject_label * | |
18274 | +do_copy_user_subj(struct acl_subject_label *userp, struct acl_role_label *role) | |
18275 | +{ | |
18276 | + struct acl_subject_label *s_tmp = NULL, *s_tmp2; | |
18277 | + unsigned int len; | |
18278 | + char *tmp; | |
18279 | + __u32 num_objs; | |
18280 | + struct acl_ip_label **i_tmp, *i_utmp2; | |
18281 | + struct gr_hash_struct ghash; | |
18282 | + struct subject_map *subjmap; | |
18283 | + unsigned int i_num; | |
18284 | + int err; | |
18285 | + | |
18286 | + s_tmp = lookup_subject_map(userp); | |
18287 | + | |
18288 | + /* we've already copied this subject into the kernel, just return | |
18289 | + the reference to it, and don't copy it over again | |
18290 | + */ | |
18291 | + if (s_tmp) | |
18292 | + return(s_tmp); | |
18293 | + | |
18294 | + if ((s_tmp = (struct acl_subject_label *) | |
18295 | + acl_alloc(sizeof (struct acl_subject_label))) == NULL) | |
18296 | + return ERR_PTR(-ENOMEM); | |
18297 | + | |
18298 | + subjmap = (struct subject_map *)kmalloc(sizeof (struct subject_map), GFP_KERNEL); | |
18299 | + if (subjmap == NULL) | |
18300 | + return ERR_PTR(-ENOMEM); | |
18301 | + | |
18302 | + subjmap->user = userp; | |
18303 | + subjmap->kernel = s_tmp; | |
18304 | + insert_subj_map_entry(subjmap); | |
18305 | + | |
18306 | + if (copy_from_user(s_tmp, userp, | |
18307 | + sizeof (struct acl_subject_label))) | |
18308 | + return ERR_PTR(-EFAULT); | |
18309 | + | |
18310 | + len = strnlen_user(s_tmp->filename, PATH_MAX); | |
18311 | + | |
18312 | + if (!len || len >= PATH_MAX) | |
18313 | + return ERR_PTR(-EINVAL); | |
18314 | + | |
18315 | + if ((tmp = (char *) acl_alloc(len)) == NULL) | |
18316 | + return ERR_PTR(-ENOMEM); | |
18317 | + | |
18318 | + if (copy_from_user(tmp, s_tmp->filename, len)) | |
18319 | + return ERR_PTR(-EFAULT); | |
18320 | + | |
18321 | + s_tmp->filename = tmp; | |
18322 | + | |
18323 | + if (!strcmp(s_tmp->filename, "/")) | |
18324 | + role->root_label = s_tmp; | |
18325 | + | |
18326 | + if (copy_from_user(&ghash, s_tmp->hash, sizeof(struct gr_hash_struct))) | |
18327 | + return ERR_PTR(-EFAULT); | |
18328 | + | |
18329 | + /* copy user and group transition tables */ | |
18330 | + | |
18331 | + if (s_tmp->user_trans_num) { | |
18332 | + uid_t *uidlist; | |
18333 | + | |
18334 | + uidlist = (uid_t *)acl_alloc(s_tmp->user_trans_num * sizeof(uid_t)); | |
18335 | + if (uidlist == NULL) | |
18336 | + return ERR_PTR(-ENOMEM); | |
18337 | + if (copy_from_user(uidlist, s_tmp->user_transitions, s_tmp->user_trans_num * sizeof(uid_t))) | |
18338 | + return ERR_PTR(-EFAULT); | |
18339 | + | |
18340 | + s_tmp->user_transitions = uidlist; | |
18341 | + } | |
18342 | + | |
18343 | + if (s_tmp->group_trans_num) { | |
18344 | + gid_t *gidlist; | |
18345 | + | |
18346 | + gidlist = (gid_t *)acl_alloc(s_tmp->group_trans_num * sizeof(gid_t)); | |
18347 | + if (gidlist == NULL) | |
18348 | + return ERR_PTR(-ENOMEM); | |
18349 | + if (copy_from_user(gidlist, s_tmp->group_transitions, s_tmp->group_trans_num * sizeof(gid_t))) | |
18350 | + return ERR_PTR(-EFAULT); | |
18351 | + | |
18352 | + s_tmp->group_transitions = gidlist; | |
18353 | + } | |
18354 | + | |
18355 | + /* set up object hash table */ | |
18356 | + num_objs = count_user_objs(ghash.first); | |
18357 | + | |
18358 | + s_tmp->obj_hash_size = num_objs; | |
18359 | + s_tmp->obj_hash = | |
18360 | + (struct acl_object_label **) | |
18361 | + create_table(&(s_tmp->obj_hash_size), sizeof(void *)); | |
18362 | + | |
18363 | + if (!s_tmp->obj_hash) | |
18364 | + return ERR_PTR(-ENOMEM); | |
18365 | + | |
18366 | + memset(s_tmp->obj_hash, 0, | |
18367 | + s_tmp->obj_hash_size * | |
18368 | + sizeof (struct acl_object_label *)); | |
18369 | + | |
18370 | + /* add in objects */ | |
18371 | + err = copy_user_objs(ghash.first, s_tmp, role); | |
18372 | + | |
18373 | + if (err) | |
18374 | + return ERR_PTR(err); | |
18375 | + | |
18376 | + /* set pointer for parent subject */ | |
18377 | + if (s_tmp->parent_subject) { | |
18378 | + s_tmp2 = do_copy_user_subj(s_tmp->parent_subject, role); | |
18379 | + | |
18380 | + if (IS_ERR(s_tmp2)) | |
18381 | + return s_tmp2; | |
18382 | + | |
18383 | + s_tmp->parent_subject = s_tmp2; | |
18384 | + } | |
18385 | + | |
18386 | + /* add in ip acls */ | |
18387 | + | |
18388 | + if (!s_tmp->ip_num) { | |
18389 | + s_tmp->ips = NULL; | |
18390 | + goto insert; | |
18391 | + } | |
18392 | + | |
18393 | + i_tmp = | |
18394 | + (struct acl_ip_label **) acl_alloc(s_tmp->ip_num * | |
18395 | + sizeof (struct | |
18396 | + acl_ip_label *)); | |
18397 | + | |
18398 | + if (!i_tmp) | |
18399 | + return ERR_PTR(-ENOMEM); | |
18400 | + | |
18401 | + for (i_num = 0; i_num < s_tmp->ip_num; i_num++) { | |
18402 | + *(i_tmp + i_num) = | |
18403 | + (struct acl_ip_label *) | |
18404 | + acl_alloc(sizeof (struct acl_ip_label)); | |
18405 | + if (!*(i_tmp + i_num)) | |
18406 | + return ERR_PTR(-ENOMEM); | |
18407 | + | |
18408 | + if (copy_from_user | |
18409 | + (&i_utmp2, s_tmp->ips + i_num, | |
18410 | + sizeof (struct acl_ip_label *))) | |
18411 | + return ERR_PTR(-EFAULT); | |
18412 | + | |
18413 | + if (copy_from_user | |
18414 | + (*(i_tmp + i_num), i_utmp2, | |
18415 | + sizeof (struct acl_ip_label))) | |
18416 | + return ERR_PTR(-EFAULT); | |
18417 | + | |
18418 | + if ((*(i_tmp + i_num))->iface == NULL) | |
18419 | + continue; | |
18420 | + | |
18421 | + len = strnlen_user((*(i_tmp + i_num))->iface, IFNAMSIZ); | |
18422 | + if (!len || len >= IFNAMSIZ) | |
18423 | + return ERR_PTR(-EINVAL); | |
18424 | + tmp = acl_alloc(len); | |
18425 | + if (tmp == NULL) | |
18426 | + return ERR_PTR(-ENOMEM); | |
18427 | + if (copy_from_user(tmp, (*(i_tmp + i_num))->iface, len)) | |
18428 | + return ERR_PTR(-EFAULT); | |
18429 | + (*(i_tmp + i_num))->iface = tmp; | |
18430 | + } | |
18431 | + | |
18432 | + s_tmp->ips = i_tmp; | |
18433 | + | |
18434 | +insert: | |
18435 | + if (!insert_name_entry(s_tmp->filename, s_tmp->inode, | |
da5b3fc8 | 18436 | + s_tmp->device, (s_tmp->mode & GR_DELETED) ? 1 : 0)) |
50425a20 | 18437 | + return ERR_PTR(-ENOMEM); |
18438 | + | |
18439 | + return s_tmp; | |
18440 | +} | |
18441 | + | |
18442 | +static int | |
18443 | +copy_user_subjs(struct acl_subject_label *userp, struct acl_role_label *role) | |
18444 | +{ | |
18445 | + struct acl_subject_label s_pre; | |
18446 | + struct acl_subject_label * ret; | |
18447 | + int err; | |
18448 | + | |
18449 | + while (userp) { | |
18450 | + if (copy_from_user(&s_pre, userp, | |
18451 | + sizeof (struct acl_subject_label))) | |
18452 | + return -EFAULT; | |
18453 | + | |
18454 | + /* do not add nested subjects here, add | |
18455 | + while parsing objects | |
18456 | + */ | |
18457 | + | |
18458 | + if (s_pre.mode & GR_NESTED) { | |
18459 | + userp = s_pre.prev; | |
18460 | + continue; | |
18461 | + } | |
18462 | + | |
18463 | + ret = do_copy_user_subj(userp, role); | |
18464 | + | |
18465 | + err = PTR_ERR(ret); | |
18466 | + if (IS_ERR(ret)) | |
18467 | + return err; | |
18468 | + | |
18469 | + insert_acl_subj_label(ret, role); | |
18470 | + | |
18471 | + userp = s_pre.prev; | |
18472 | + } | |
18473 | + | |
18474 | + return 0; | |
18475 | +} | |
18476 | + | |
18477 | +static int | |
18478 | +copy_user_acl(struct gr_arg *arg) | |
18479 | +{ | |
18480 | + struct acl_role_label *r_tmp = NULL, **r_utmp, *r_utmp2; | |
18481 | + struct sprole_pw *sptmp; | |
18482 | + struct gr_hash_struct *ghash; | |
18483 | + uid_t *domainlist; | |
18484 | + unsigned int r_num; | |
18485 | + unsigned int len; | |
18486 | + char *tmp; | |
18487 | + int err = 0; | |
18488 | + __u16 i; | |
18489 | + __u32 num_subjs; | |
18490 | + | |
18491 | + /* we need a default and kernel role */ | |
18492 | + if (arg->role_db.num_roles < 2) | |
18493 | + return -EINVAL; | |
18494 | + | |
18495 | + /* copy special role authentication info from userspace */ | |
18496 | + | |
18497 | + num_sprole_pws = arg->num_sprole_pws; | |
18498 | + acl_special_roles = (struct sprole_pw **) acl_alloc(num_sprole_pws * sizeof(struct sprole_pw *)); | |
18499 | + | |
18500 | + if (!acl_special_roles) { | |
18501 | + err = -ENOMEM; | |
18502 | + goto cleanup; | |
18503 | + } | |
18504 | + | |
18505 | + for (i = 0; i < num_sprole_pws; i++) { | |
18506 | + sptmp = (struct sprole_pw *) acl_alloc(sizeof(struct sprole_pw)); | |
18507 | + if (!sptmp) { | |
18508 | + err = -ENOMEM; | |
18509 | + goto cleanup; | |
18510 | + } | |
18511 | + if (copy_from_user(sptmp, arg->sprole_pws + i, | |
18512 | + sizeof (struct sprole_pw))) { | |
18513 | + err = -EFAULT; | |
18514 | + goto cleanup; | |
18515 | + } | |
18516 | + | |
18517 | + len = | |
18518 | + strnlen_user(sptmp->rolename, GR_SPROLE_LEN); | |
18519 | + | |
18520 | + if (!len || len >= GR_SPROLE_LEN) { | |
18521 | + err = -EINVAL; | |
18522 | + goto cleanup; | |
18523 | + } | |
18524 | + | |
18525 | + if ((tmp = (char *) acl_alloc(len)) == NULL) { | |
18526 | + err = -ENOMEM; | |
18527 | + goto cleanup; | |
18528 | + } | |
18529 | + | |
18530 | + if (copy_from_user(tmp, sptmp->rolename, len)) { | |
18531 | + err = -EFAULT; | |
18532 | + goto cleanup; | |
18533 | + } | |
18534 | + | |
18535 | +#ifdef CONFIG_GRKERNSEC_ACL_DEBUG | |
18536 | + printk(KERN_ALERT "Copying special role %s\n", tmp); | |
18537 | +#endif | |
18538 | + sptmp->rolename = tmp; | |
18539 | + acl_special_roles[i] = sptmp; | |
18540 | + } | |
18541 | + | |
18542 | + r_utmp = (struct acl_role_label **) arg->role_db.r_table; | |
18543 | + | |
18544 | + for (r_num = 0; r_num < arg->role_db.num_roles; r_num++) { | |
18545 | + r_tmp = acl_alloc(sizeof (struct acl_role_label)); | |
18546 | + | |
18547 | + if (!r_tmp) { | |
18548 | + err = -ENOMEM; | |
18549 | + goto cleanup; | |
18550 | + } | |
18551 | + | |
18552 | + if (copy_from_user(&r_utmp2, r_utmp + r_num, | |
18553 | + sizeof (struct acl_role_label *))) { | |
18554 | + err = -EFAULT; | |
18555 | + goto cleanup; | |
18556 | + } | |
18557 | + | |
18558 | + if (copy_from_user(r_tmp, r_utmp2, | |
18559 | + sizeof (struct acl_role_label))) { | |
18560 | + err = -EFAULT; | |
18561 | + goto cleanup; | |
18562 | + } | |
18563 | + | |
18564 | + len = strnlen_user(r_tmp->rolename, GR_SPROLE_LEN); | |
18565 | + | |
18566 | + if (!len || len >= PATH_MAX) { | |
18567 | + err = -EINVAL; | |
18568 | + goto cleanup; | |
18569 | + } | |
18570 | + | |
18571 | + if ((tmp = (char *) acl_alloc(len)) == NULL) { | |
18572 | + err = -ENOMEM; | |
18573 | + goto cleanup; | |
18574 | + } | |
18575 | + if (copy_from_user(tmp, r_tmp->rolename, len)) { | |
18576 | + err = -EFAULT; | |
18577 | + goto cleanup; | |
18578 | + } | |
18579 | + r_tmp->rolename = tmp; | |
18580 | + | |
18581 | + if (!strcmp(r_tmp->rolename, "default") | |
18582 | + && (r_tmp->roletype & GR_ROLE_DEFAULT)) { | |
18583 | + default_role = r_tmp; | |
18584 | + } else if (!strcmp(r_tmp->rolename, ":::kernel:::")) { | |
18585 | + kernel_role = r_tmp; | |
18586 | + } | |
18587 | + | |
18588 | + if ((ghash = (struct gr_hash_struct *) acl_alloc(sizeof(struct gr_hash_struct))) == NULL) { | |
18589 | + err = -ENOMEM; | |
18590 | + goto cleanup; | |
18591 | + } | |
18592 | + if (copy_from_user(ghash, r_tmp->hash, sizeof(struct gr_hash_struct))) { | |
18593 | + err = -EFAULT; | |
18594 | + goto cleanup; | |
18595 | + } | |
18596 | + | |
18597 | + r_tmp->hash = ghash; | |
18598 | + | |
18599 | + num_subjs = count_user_subjs(r_tmp->hash->first); | |
18600 | + | |
18601 | + r_tmp->subj_hash_size = num_subjs; | |
18602 | + r_tmp->subj_hash = | |
18603 | + (struct acl_subject_label **) | |
18604 | + create_table(&(r_tmp->subj_hash_size), sizeof(void *)); | |
18605 | + | |
18606 | + if (!r_tmp->subj_hash) { | |
18607 | + err = -ENOMEM; | |
18608 | + goto cleanup; | |
18609 | + } | |
18610 | + | |
18611 | + err = copy_user_allowedips(r_tmp); | |
18612 | + if (err) | |
18613 | + goto cleanup; | |
18614 | + | |
18615 | + /* copy domain info */ | |
18616 | + if (r_tmp->domain_children != NULL) { | |
18617 | + domainlist = acl_alloc(r_tmp->domain_child_num * sizeof(uid_t)); | |
18618 | + if (domainlist == NULL) { | |
18619 | + err = -ENOMEM; | |
18620 | + goto cleanup; | |
18621 | + } | |
18622 | + if (copy_from_user(domainlist, r_tmp->domain_children, r_tmp->domain_child_num * sizeof(uid_t))) { | |
18623 | + err = -EFAULT; | |
18624 | + goto cleanup; | |
18625 | + } | |
18626 | + r_tmp->domain_children = domainlist; | |
18627 | + } | |
18628 | + | |
18629 | + err = copy_user_transitions(r_tmp); | |
18630 | + if (err) | |
18631 | + goto cleanup; | |
18632 | + | |
18633 | + memset(r_tmp->subj_hash, 0, | |
18634 | + r_tmp->subj_hash_size * | |
18635 | + sizeof (struct acl_subject_label *)); | |
18636 | + | |
18637 | + err = copy_user_subjs(r_tmp->hash->first, r_tmp); | |
18638 | + | |
18639 | + if (err) | |
18640 | + goto cleanup; | |
18641 | + | |
18642 | + /* set nested subject list to null */ | |
18643 | + r_tmp->hash->first = NULL; | |
18644 | + | |
18645 | + insert_acl_role_label(r_tmp); | |
18646 | + } | |
18647 | + | |
18648 | + goto return_err; | |
18649 | + cleanup: | |
18650 | + free_variables(); | |
18651 | + return_err: | |
18652 | + return err; | |
18653 | + | |
18654 | +} | |
18655 | + | |
18656 | +static int | |
18657 | +gracl_init(struct gr_arg *args) | |
18658 | +{ | |
18659 | + int error = 0; | |
18660 | + | |
18661 | + memcpy(gr_system_salt, args->salt, GR_SALT_LEN); | |
18662 | + memcpy(gr_system_sum, args->sum, GR_SHA_LEN); | |
18663 | + | |
18664 | + if (init_variables(args)) { | |
18665 | + gr_log_str(GR_DONT_AUDIT_GOOD, GR_INITF_ACL_MSG, GR_VERSION); | |
18666 | + error = -ENOMEM; | |
18667 | + free_variables(); | |
18668 | + goto out; | |
18669 | + } | |
18670 | + | |
18671 | + error = copy_user_acl(args); | |
18672 | + free_init_variables(); | |
18673 | + if (error) { | |
18674 | + free_variables(); | |
18675 | + goto out; | |
18676 | + } | |
18677 | + | |
18678 | + if ((error = gr_set_acls(0))) { | |
18679 | + free_variables(); | |
18680 | + goto out; | |
18681 | + } | |
18682 | + | |
18683 | + gr_status |= GR_READY; | |
18684 | + out: | |
18685 | + return error; | |
18686 | +} | |
18687 | + | |
18688 | +/* derived from glibc fnmatch() 0: match, 1: no match*/ | |
18689 | + | |
18690 | +static int | |
18691 | +glob_match(const char *p, const char *n) | |
18692 | +{ | |
18693 | + char c; | |
18694 | + | |
18695 | + while ((c = *p++) != '\0') { | |
18696 | + switch (c) { | |
18697 | + case '?': | |
18698 | + if (*n == '\0') | |
18699 | + return 1; | |
18700 | + else if (*n == '/') | |
18701 | + return 1; | |
18702 | + break; | |
18703 | + case '\\': | |
18704 | + if (*n != c) | |
18705 | + return 1; | |
18706 | + break; | |
18707 | + case '*': | |
18708 | + for (c = *p++; c == '?' || c == '*'; c = *p++) { | |
18709 | + if (*n == '/') | |
18710 | + return 1; | |
18711 | + else if (c == '?') { | |
18712 | + if (*n == '\0') | |
18713 | + return 1; | |
18714 | + else | |
18715 | + ++n; | |
18716 | + } | |
18717 | + } | |
18718 | + if (c == '\0') { | |
18719 | + return 0; | |
18720 | + } else { | |
18721 | + const char *endp; | |
18722 | + | |
18723 | + if ((endp = strchr(n, '/')) == NULL) | |
18724 | + endp = n + strlen(n); | |
18725 | + | |
18726 | + if (c == '[') { | |
18727 | + for (--p; n < endp; ++n) | |
18728 | + if (!glob_match(p, n)) | |
18729 | + return 0; | |
18730 | + } else if (c == '/') { | |
18731 | + while (*n != '\0' && *n != '/') | |
18732 | + ++n; | |
18733 | + if (*n == '/' && !glob_match(p, n + 1)) | |
18734 | + return 0; | |
18735 | + } else { | |
18736 | + for (--p; n < endp; ++n) | |
18737 | + if (*n == c && !glob_match(p, n)) | |
18738 | + return 0; | |
18739 | + } | |
18740 | + | |
18741 | + return 1; | |
18742 | + } | |
18743 | + case '[': | |
18744 | + { | |
18745 | + int not; | |
18746 | + char cold; | |
18747 | + | |
18748 | + if (*n == '\0' || *n == '/') | |
18749 | + return 1; | |
18750 | + | |
18751 | + not = (*p == '!' || *p == '^'); | |
18752 | + if (not) | |
18753 | + ++p; | |
18754 | + | |
18755 | + c = *p++; | |
18756 | + for (;;) { | |
18757 | + unsigned char fn = (unsigned char)*n; | |
18758 | + | |
18759 | + if (c == '\0') | |
18760 | + return 1; | |
18761 | + else { | |
18762 | + if (c == fn) | |
18763 | + goto matched; | |
18764 | + cold = c; | |
18765 | + c = *p++; | |
18766 | + | |
18767 | + if (c == '-' && *p != ']') { | |
18768 | + unsigned char cend = *p++; | |
18769 | + | |
18770 | + if (cend == '\0') | |
18771 | + return 1; | |
18772 | + | |
18773 | + if (cold <= fn && fn <= cend) | |
18774 | + goto matched; | |
18775 | + | |
18776 | + c = *p++; | |
18777 | + } | |
18778 | + } | |
18779 | + | |
18780 | + if (c == ']') | |
18781 | + break; | |
18782 | + } | |
18783 | + if (!not) | |
18784 | + return 1; | |
18785 | + break; | |
18786 | + matched: | |
18787 | + while (c != ']') { | |
18788 | + if (c == '\0') | |
18789 | + return 1; | |
18790 | + | |
18791 | + c = *p++; | |
18792 | + } | |
18793 | + if (not) | |
18794 | + return 1; | |
18795 | + } | |
18796 | + break; | |
18797 | + default: | |
18798 | + if (c != *n) | |
18799 | + return 1; | |
18800 | + } | |
18801 | + | |
18802 | + ++n; | |
18803 | + } | |
18804 | + | |
18805 | + if (*n == '\0') | |
18806 | + return 0; | |
18807 | + | |
18808 | + if (*n == '/') | |
18809 | + return 0; | |
18810 | + | |
18811 | + return 1; | |
18812 | +} | |
18813 | + | |
18814 | +static struct acl_object_label * | |
18815 | +chk_glob_label(struct acl_object_label *globbed, | |
18816 | + struct dentry *dentry, struct vfsmount *mnt, char **path) | |
18817 | +{ | |
18818 | + struct acl_object_label *tmp; | |
18819 | + | |
18820 | + if (*path == NULL) | |
18821 | + *path = gr_to_filename_nolock(dentry, mnt); | |
18822 | + | |
18823 | + tmp = globbed; | |
18824 | + | |
18825 | + while (tmp) { | |
18826 | + if (!glob_match(tmp->filename, *path)) | |
18827 | + return tmp; | |
18828 | + tmp = tmp->next; | |
18829 | + } | |
18830 | + | |
18831 | + return NULL; | |
18832 | +} | |
18833 | + | |
18834 | +static struct acl_object_label * | |
18835 | +__full_lookup(const struct dentry *orig_dentry, const struct vfsmount *orig_mnt, | |
18836 | + const ino_t curr_ino, const dev_t curr_dev, | |
18837 | + const struct acl_subject_label *subj, char **path) | |
18838 | +{ | |
18839 | + struct acl_subject_label *tmpsubj; | |
18840 | + struct acl_object_label *retval; | |
18841 | + struct acl_object_label *retval2; | |
18842 | + | |
18843 | + tmpsubj = (struct acl_subject_label *) subj; | |
18844 | + read_lock(&gr_inode_lock); | |
18845 | + do { | |
18846 | + retval = lookup_acl_obj_label(curr_ino, curr_dev, tmpsubj); | |
18847 | + if (retval) { | |
18848 | + if (retval->globbed) { | |
18849 | + retval2 = chk_glob_label(retval->globbed, (struct dentry *)orig_dentry, | |
18850 | + (struct vfsmount *)orig_mnt, path); | |
18851 | + if (retval2) | |
18852 | + retval = retval2; | |
18853 | + } | |
18854 | + break; | |
18855 | + } | |
18856 | + } while ((tmpsubj = tmpsubj->parent_subject)); | |
18857 | + read_unlock(&gr_inode_lock); | |
18858 | + | |
18859 | + return retval; | |
18860 | +} | |
18861 | + | |
18862 | +static __inline__ struct acl_object_label * | |
18863 | +full_lookup(const struct dentry *orig_dentry, const struct vfsmount *orig_mnt, | |
18864 | + const struct dentry *curr_dentry, | |
18865 | + const struct acl_subject_label *subj, char **path) | |
18866 | +{ | |
18867 | + return __full_lookup(orig_dentry, orig_mnt, | |
18868 | + curr_dentry->d_inode->i_ino, | |
18869 | + curr_dentry->d_inode->i_sb->s_dev, subj, path); | |
18870 | +} | |
18871 | + | |
18872 | +static struct acl_object_label * | |
18873 | +__chk_obj_label(const struct dentry *l_dentry, const struct vfsmount *l_mnt, | |
18874 | + const struct acl_subject_label *subj, char *path) | |
18875 | +{ | |
18876 | + struct dentry *dentry = (struct dentry *) l_dentry; | |
18877 | + struct vfsmount *mnt = (struct vfsmount *) l_mnt; | |
18878 | + struct acl_object_label *retval; | |
18879 | + | |
18880 | + spin_lock(&dcache_lock); | |
18881 | + | |
f4251508 | 18882 | + if (unlikely(mnt == shm_mnt || mnt == pipe_mnt || mnt == sock_mnt || |
18883 | + /* ignore Eric Biederman */ | |
18884 | + IS_PRIVATE(l_dentry->d_inode))) { | |
50425a20 | 18885 | + retval = fakefs_obj; |
18886 | + goto out; | |
18887 | + } | |
18888 | + | |
18889 | + for (;;) { | |
18890 | + if (dentry == real_root && mnt == real_root_mnt) | |
18891 | + break; | |
18892 | + | |
18893 | + if (dentry == mnt->mnt_root || IS_ROOT(dentry)) { | |
18894 | + if (mnt->mnt_parent == mnt) | |
18895 | + break; | |
18896 | + | |
18897 | + retval = full_lookup(l_dentry, l_mnt, dentry, subj, &path); | |
18898 | + if (retval != NULL) | |
18899 | + goto out; | |
18900 | + | |
18901 | + dentry = mnt->mnt_mountpoint; | |
18902 | + mnt = mnt->mnt_parent; | |
18903 | + continue; | |
18904 | + } | |
18905 | + | |
18906 | + retval = full_lookup(l_dentry, l_mnt, dentry, subj, &path); | |
18907 | + if (retval != NULL) | |
18908 | + goto out; | |
18909 | + | |
18910 | + dentry = dentry->d_parent; | |
18911 | + } | |
18912 | + | |
18913 | + retval = full_lookup(l_dentry, l_mnt, dentry, subj, &path); | |
18914 | + | |
18915 | + if (retval == NULL) | |
18916 | + retval = full_lookup(l_dentry, l_mnt, real_root, subj, &path); | |
18917 | +out: | |
18918 | + spin_unlock(&dcache_lock); | |
18919 | + return retval; | |
18920 | +} | |
18921 | + | |
18922 | +static __inline__ struct acl_object_label * | |
18923 | +chk_obj_label(const struct dentry *l_dentry, const struct vfsmount *l_mnt, | |
18924 | + const struct acl_subject_label *subj) | |
18925 | +{ | |
18926 | + char *path = NULL; | |
18927 | + return __chk_obj_label(l_dentry, l_mnt, subj, path); | |
18928 | +} | |
18929 | + | |
18930 | +static __inline__ struct acl_object_label * | |
18931 | +chk_obj_create_label(const struct dentry *l_dentry, const struct vfsmount *l_mnt, | |
18932 | + const struct acl_subject_label *subj, char *path) | |
18933 | +{ | |
18934 | + return __chk_obj_label(l_dentry, l_mnt, subj, path); | |
18935 | +} | |
18936 | + | |
18937 | +static struct acl_subject_label * | |
18938 | +chk_subj_label(const struct dentry *l_dentry, const struct vfsmount *l_mnt, | |
18939 | + const struct acl_role_label *role) | |
18940 | +{ | |
18941 | + struct dentry *dentry = (struct dentry *) l_dentry; | |
18942 | + struct vfsmount *mnt = (struct vfsmount *) l_mnt; | |
18943 | + struct acl_subject_label *retval; | |
18944 | + | |
18945 | + spin_lock(&dcache_lock); | |
18946 | + | |
18947 | + for (;;) { | |
18948 | + if (dentry == real_root && mnt == real_root_mnt) | |
18949 | + break; | |
18950 | + if (dentry == mnt->mnt_root || IS_ROOT(dentry)) { | |
18951 | + if (mnt->mnt_parent == mnt) | |
18952 | + break; | |
18953 | + | |
18954 | + read_lock(&gr_inode_lock); | |
18955 | + retval = | |
18956 | + lookup_acl_subj_label(dentry->d_inode->i_ino, | |
18957 | + dentry->d_inode->i_sb->s_dev, role); | |
18958 | + read_unlock(&gr_inode_lock); | |
18959 | + if (retval != NULL) | |
18960 | + goto out; | |
18961 | + | |
18962 | + dentry = mnt->mnt_mountpoint; | |
18963 | + mnt = mnt->mnt_parent; | |
18964 | + continue; | |
18965 | + } | |
18966 | + | |
18967 | + read_lock(&gr_inode_lock); | |
18968 | + retval = lookup_acl_subj_label(dentry->d_inode->i_ino, | |
18969 | + dentry->d_inode->i_sb->s_dev, role); | |
18970 | + read_unlock(&gr_inode_lock); | |
18971 | + if (retval != NULL) | |
18972 | + goto out; | |
18973 | + | |
18974 | + dentry = dentry->d_parent; | |
18975 | + } | |
18976 | + | |
18977 | + read_lock(&gr_inode_lock); | |
18978 | + retval = lookup_acl_subj_label(dentry->d_inode->i_ino, | |
18979 | + dentry->d_inode->i_sb->s_dev, role); | |
18980 | + read_unlock(&gr_inode_lock); | |
18981 | + | |
18982 | + if (unlikely(retval == NULL)) { | |
18983 | + read_lock(&gr_inode_lock); | |
18984 | + retval = lookup_acl_subj_label(real_root->d_inode->i_ino, | |
18985 | + real_root->d_inode->i_sb->s_dev, role); | |
18986 | + read_unlock(&gr_inode_lock); | |
18987 | + } | |
18988 | +out: | |
18989 | + spin_unlock(&dcache_lock); | |
18990 | + | |
18991 | + return retval; | |
18992 | +} | |
18993 | + | |
18994 | +static void | |
18995 | +gr_log_learn(const struct task_struct *task, const struct dentry *dentry, const struct vfsmount *mnt, const __u32 mode) | |
18996 | +{ | |
18997 | + security_learn(GR_LEARN_AUDIT_MSG, task->role->rolename, task->role->roletype, | |
4dee9bd5 | 18998 | + task->uid, task->gid, task->exec_file ? gr_to_filename1(task->exec_file->f_path.dentry, |
18999 | + task->exec_file->f_path.mnt) : task->acl->filename, task->acl->filename, | |
50425a20 | 19000 | + 1, 1, gr_to_filename(dentry, mnt), (unsigned long) mode, NIPQUAD(task->signal->curr_ip)); |
19001 | + | |
19002 | + return; | |
19003 | +} | |
19004 | + | |
19005 | +static void | |
f4251508 | 19006 | +gr_log_learn_sysctl(const struct task_struct *task, const char *path, const __u32 mode) |
19007 | +{ | |
19008 | + security_learn(GR_LEARN_AUDIT_MSG, task->role->rolename, task->role->roletype, | |
4dee9bd5 | 19009 | + task->uid, task->gid, task->exec_file ? gr_to_filename1(task->exec_file->f_path.dentry, |
19010 | + task->exec_file->f_path.mnt) : task->acl->filename, task->acl->filename, | |
f4251508 | 19011 | + 1, 1, path, (unsigned long) mode, NIPQUAD(task->signal->curr_ip)); |
19012 | + | |
19013 | + return; | |
19014 | +} | |
19015 | + | |
19016 | +static void | |
50425a20 | 19017 | +gr_log_learn_id_change(const struct task_struct *task, const char type, const unsigned int real, |
19018 | + const unsigned int effective, const unsigned int fs) | |
19019 | +{ | |
19020 | + security_learn(GR_ID_LEARN_MSG, task->role->rolename, task->role->roletype, | |
4dee9bd5 | 19021 | + task->uid, task->gid, task->exec_file ? gr_to_filename1(task->exec_file->f_path.dentry, |
19022 | + task->exec_file->f_path.mnt) : task->acl->filename, task->acl->filename, | |
50425a20 | 19023 | + type, real, effective, fs, NIPQUAD(task->signal->curr_ip)); |
19024 | + | |
19025 | + return; | |
19026 | +} | |
19027 | + | |
19028 | +__u32 | |
19029 | +gr_check_link(const struct dentry * new_dentry, | |
19030 | + const struct dentry * parent_dentry, | |
19031 | + const struct vfsmount * parent_mnt, | |
19032 | + const struct dentry * old_dentry, const struct vfsmount * old_mnt) | |
19033 | +{ | |
19034 | + struct acl_object_label *obj; | |
19035 | + __u32 oldmode, newmode; | |
19036 | + __u32 needmode; | |
19037 | + | |
19038 | + if (unlikely(!(gr_status & GR_READY))) | |
19039 | + return (GR_CREATE | GR_LINK); | |
19040 | + | |
19041 | + obj = chk_obj_label(old_dentry, old_mnt, current->acl); | |
19042 | + oldmode = obj->mode; | |
19043 | + | |
19044 | + if (current->acl->mode & (GR_LEARN | GR_INHERITLEARN)) | |
19045 | + oldmode |= (GR_CREATE | GR_LINK); | |
19046 | + | |
19047 | + needmode = GR_CREATE | GR_AUDIT_CREATE | GR_SUPPRESS; | |
19048 | + if (old_dentry->d_inode->i_mode & (S_ISUID | S_ISGID)) | |
19049 | + needmode |= GR_SETID | GR_AUDIT_SETID; | |
19050 | + | |
19051 | + newmode = | |
19052 | + gr_check_create(new_dentry, parent_dentry, parent_mnt, | |
19053 | + oldmode | needmode); | |
19054 | + | |
19055 | + needmode = newmode & (GR_FIND | GR_APPEND | GR_WRITE | GR_EXEC | | |
19056 | + GR_SETID | GR_READ | GR_FIND | GR_DELETE | | |
19057 | + GR_INHERIT | GR_AUDIT_INHERIT); | |
19058 | + | |
19059 | + if (old_dentry->d_inode->i_mode & (S_ISUID | S_ISGID) && !(newmode & GR_SETID)) | |
19060 | + goto bad; | |
19061 | + | |
19062 | + if ((oldmode & needmode) != needmode) | |
19063 | + goto bad; | |
19064 | + | |
19065 | + needmode = oldmode & (GR_NOPTRACE | GR_PTRACERD | GR_INHERIT | GR_AUDITS); | |
19066 | + if ((newmode & needmode) != needmode) | |
19067 | + goto bad; | |
19068 | + | |
19069 | + if ((newmode & (GR_CREATE | GR_LINK)) == (GR_CREATE | GR_LINK)) | |
19070 | + return newmode; | |
19071 | +bad: | |
19072 | + needmode = oldmode; | |
19073 | + if (old_dentry->d_inode->i_mode & (S_ISUID | S_ISGID)) | |
19074 | + needmode |= GR_SETID; | |
19075 | + | |
19076 | + if (current->acl->mode & (GR_LEARN | GR_INHERITLEARN)) { | |
19077 | + gr_log_learn(current, old_dentry, old_mnt, needmode); | |
19078 | + return (GR_CREATE | GR_LINK); | |
19079 | + } else if (newmode & GR_SUPPRESS) | |
19080 | + return GR_SUPPRESS; | |
19081 | + else | |
19082 | + return 0; | |
19083 | +} | |
19084 | + | |
19085 | +__u32 | |
19086 | +gr_search_file(const struct dentry * dentry, const __u32 mode, | |
19087 | + const struct vfsmount * mnt) | |
19088 | +{ | |
19089 | + __u32 retval = mode; | |
19090 | + struct acl_subject_label *curracl; | |
19091 | + struct acl_object_label *currobj; | |
19092 | + | |
19093 | + if (unlikely(!(gr_status & GR_READY))) | |
19094 | + return (mode & ~GR_AUDITS); | |
19095 | + | |
19096 | + curracl = current->acl; | |
19097 | + | |
19098 | + currobj = chk_obj_label(dentry, mnt, curracl); | |
19099 | + retval = currobj->mode & mode; | |
19100 | + | |
19101 | + if (unlikely | |
19102 | + ((curracl->mode & (GR_LEARN | GR_INHERITLEARN)) && !(mode & GR_NOPTRACE) | |
19103 | + && (retval != (mode & ~(GR_AUDITS | GR_SUPPRESS))))) { | |
19104 | + __u32 new_mode = mode; | |
19105 | + | |
19106 | + new_mode &= ~(GR_AUDITS | GR_SUPPRESS); | |
19107 | + | |
19108 | + retval = new_mode; | |
19109 | + | |
19110 | + if (new_mode & GR_EXEC && curracl->mode & GR_INHERITLEARN) | |
19111 | + new_mode |= GR_INHERIT; | |
19112 | + | |
19113 | + if (!(mode & GR_NOLEARN)) | |
19114 | + gr_log_learn(current, dentry, mnt, new_mode); | |
19115 | + } | |
19116 | + | |
19117 | + return retval; | |
19118 | +} | |
19119 | + | |
19120 | +__u32 | |
19121 | +gr_check_create(const struct dentry * new_dentry, const struct dentry * parent, | |
19122 | + const struct vfsmount * mnt, const __u32 mode) | |
19123 | +{ | |
19124 | + struct name_entry *match; | |
19125 | + struct acl_object_label *matchpo; | |
19126 | + struct acl_subject_label *curracl; | |
19127 | + char *path; | |
19128 | + __u32 retval; | |
19129 | + | |
19130 | + if (unlikely(!(gr_status & GR_READY))) | |
19131 | + return (mode & ~GR_AUDITS); | |
19132 | + | |
19133 | + preempt_disable(); | |
19134 | + path = gr_to_filename_rbac(new_dentry, mnt); | |
da5b3fc8 | 19135 | + match = lookup_name_entry_create(path); |
50425a20 | 19136 | + |
19137 | + if (!match) | |
19138 | + goto check_parent; | |
19139 | + | |
19140 | + curracl = current->acl; | |
19141 | + | |
19142 | + read_lock(&gr_inode_lock); | |
19143 | + matchpo = lookup_acl_obj_label_create(match->inode, match->device, curracl); | |
19144 | + read_unlock(&gr_inode_lock); | |
19145 | + | |
19146 | + if (matchpo) { | |
19147 | + if ((matchpo->mode & mode) != | |
19148 | + (mode & ~(GR_AUDITS | GR_SUPPRESS)) | |
19149 | + && curracl->mode & (GR_LEARN | GR_INHERITLEARN)) { | |
19150 | + __u32 new_mode = mode; | |
19151 | + | |
19152 | + new_mode &= ~(GR_AUDITS | GR_SUPPRESS); | |
19153 | + | |
19154 | + gr_log_learn(current, new_dentry, mnt, new_mode); | |
19155 | + | |
19156 | + preempt_enable(); | |
19157 | + return new_mode; | |
19158 | + } | |
19159 | + preempt_enable(); | |
19160 | + return (matchpo->mode & mode); | |
19161 | + } | |
19162 | + | |
19163 | + check_parent: | |
19164 | + curracl = current->acl; | |
19165 | + | |
19166 | + matchpo = chk_obj_create_label(parent, mnt, curracl, path); | |
19167 | + retval = matchpo->mode & mode; | |
19168 | + | |
19169 | + if ((retval != (mode & ~(GR_AUDITS | GR_SUPPRESS))) | |
19170 | + && (curracl->mode & (GR_LEARN | GR_INHERITLEARN))) { | |
19171 | + __u32 new_mode = mode; | |
19172 | + | |
19173 | + new_mode &= ~(GR_AUDITS | GR_SUPPRESS); | |
19174 | + | |
19175 | + gr_log_learn(current, new_dentry, mnt, new_mode); | |
19176 | + preempt_enable(); | |
19177 | + return new_mode; | |
19178 | + } | |
19179 | + | |
19180 | + preempt_enable(); | |
19181 | + return retval; | |
19182 | +} | |
19183 | + | |
19184 | +int | |
19185 | +gr_check_hidden_task(const struct task_struct *task) | |
19186 | +{ | |
19187 | + if (unlikely(!(gr_status & GR_READY))) | |
19188 | + return 0; | |
19189 | + | |
19190 | + if (!(task->acl->mode & GR_PROCFIND) && !(current->acl->mode & GR_VIEW)) | |
19191 | + return 1; | |
19192 | + | |
19193 | + return 0; | |
19194 | +} | |
19195 | + | |
19196 | +int | |
19197 | +gr_check_protected_task(const struct task_struct *task) | |
19198 | +{ | |
19199 | + if (unlikely(!(gr_status & GR_READY) || !task)) | |
19200 | + return 0; | |
19201 | + | |
19202 | + if ((task->acl->mode & GR_PROTECTED) && !(current->acl->mode & GR_KILL) && | |
19203 | + task->acl != current->acl) | |
19204 | + return 1; | |
19205 | + | |
19206 | + return 0; | |
19207 | +} | |
19208 | + | |
19209 | +void | |
19210 | +gr_copy_label(struct task_struct *tsk) | |
19211 | +{ | |
19212 | + tsk->signal->used_accept = 0; | |
19213 | + tsk->acl_sp_role = 0; | |
19214 | + tsk->acl_role_id = current->acl_role_id; | |
19215 | + tsk->acl = current->acl; | |
19216 | + tsk->role = current->role; | |
19217 | + tsk->signal->curr_ip = current->signal->curr_ip; | |
19218 | + if (current->exec_file) | |
19219 | + get_file(current->exec_file); | |
19220 | + tsk->exec_file = current->exec_file; | |
19221 | + tsk->is_writable = current->is_writable; | |
19222 | + if (unlikely(current->signal->used_accept)) | |
19223 | + current->signal->curr_ip = 0; | |
19224 | + | |
19225 | + return; | |
19226 | +} | |
19227 | + | |
19228 | +static void | |
19229 | +gr_set_proc_res(struct task_struct *task) | |
19230 | +{ | |
19231 | + struct acl_subject_label *proc; | |
19232 | + unsigned short i; | |
19233 | + | |
19234 | + proc = task->acl; | |
19235 | + | |
19236 | + if (proc->mode & (GR_LEARN | GR_INHERITLEARN)) | |
19237 | + return; | |
19238 | + | |
19239 | + for (i = 0; i < (GR_NLIMITS - 1); i++) { | |
19240 | + if (!(proc->resmask & (1 << i))) | |
19241 | + continue; | |
19242 | + | |
19243 | + task->signal->rlim[i].rlim_cur = proc->res[i].rlim_cur; | |
19244 | + task->signal->rlim[i].rlim_max = proc->res[i].rlim_max; | |
19245 | + } | |
19246 | + | |
19247 | + return; | |
19248 | +} | |
19249 | + | |
19250 | +int | |
19251 | +gr_check_user_change(int real, int effective, int fs) | |
19252 | +{ | |
19253 | + unsigned int i; | |
19254 | + __u16 num; | |
19255 | + uid_t *uidlist; | |
19256 | + int curuid; | |
19257 | + int realok = 0; | |
19258 | + int effectiveok = 0; | |
19259 | + int fsok = 0; | |
19260 | + | |
19261 | + if (unlikely(!(gr_status & GR_READY))) | |
19262 | + return 0; | |
19263 | + | |
19264 | + if (current->acl->mode & (GR_LEARN | GR_INHERITLEARN)) | |
19265 | + gr_log_learn_id_change(current, 'u', real, effective, fs); | |
19266 | + | |
19267 | + num = current->acl->user_trans_num; | |
19268 | + uidlist = current->acl->user_transitions; | |
19269 | + | |
19270 | + if (uidlist == NULL) | |
19271 | + return 0; | |
19272 | + | |
19273 | + if (real == -1) | |
19274 | + realok = 1; | |
19275 | + if (effective == -1) | |
19276 | + effectiveok = 1; | |
19277 | + if (fs == -1) | |
19278 | + fsok = 1; | |
19279 | + | |
19280 | + if (current->acl->user_trans_type & GR_ID_ALLOW) { | |
19281 | + for (i = 0; i < num; i++) { | |
19282 | + curuid = (int)uidlist[i]; | |
19283 | + if (real == curuid) | |
19284 | + realok = 1; | |
19285 | + if (effective == curuid) | |
19286 | + effectiveok = 1; | |
19287 | + if (fs == curuid) | |
19288 | + fsok = 1; | |
19289 | + } | |
19290 | + } else if (current->acl->user_trans_type & GR_ID_DENY) { | |
19291 | + for (i = 0; i < num; i++) { | |
19292 | + curuid = (int)uidlist[i]; | |
19293 | + if (real == curuid) | |
19294 | + break; | |
19295 | + if (effective == curuid) | |
19296 | + break; | |
19297 | + if (fs == curuid) | |
19298 | + break; | |
19299 | + } | |
19300 | + /* not in deny list */ | |
19301 | + if (i == num) { | |
19302 | + realok = 1; | |
19303 | + effectiveok = 1; | |
19304 | + fsok = 1; | |
19305 | + } | |
19306 | + } | |
19307 | + | |
19308 | + if (realok && effectiveok && fsok) | |
19309 | + return 0; | |
19310 | + else { | |
19311 | + gr_log_int(GR_DONT_AUDIT, GR_USRCHANGE_ACL_MSG, realok ? (effectiveok ? (fsok ? 0 : fs) : effective) : real); | |
19312 | + return 1; | |
19313 | + } | |
19314 | +} | |
19315 | + | |
19316 | +int | |
19317 | +gr_check_group_change(int real, int effective, int fs) | |
19318 | +{ | |
19319 | + unsigned int i; | |
19320 | + __u16 num; | |
19321 | + gid_t *gidlist; | |
19322 | + int curgid; | |
19323 | + int realok = 0; | |
19324 | + int effectiveok = 0; | |
19325 | + int fsok = 0; | |
19326 | + | |
19327 | + if (unlikely(!(gr_status & GR_READY))) | |
19328 | + return 0; | |
19329 | + | |
19330 | + if (current->acl->mode & (GR_LEARN | GR_INHERITLEARN)) | |
19331 | + gr_log_learn_id_change(current, 'g', real, effective, fs); | |
19332 | + | |
19333 | + num = current->acl->group_trans_num; | |
19334 | + gidlist = current->acl->group_transitions; | |
19335 | + | |
19336 | + if (gidlist == NULL) | |
19337 | + return 0; | |
19338 | + | |
19339 | + if (real == -1) | |
19340 | + realok = 1; | |
19341 | + if (effective == -1) | |
19342 | + effectiveok = 1; | |
19343 | + if (fs == -1) | |
19344 | + fsok = 1; | |
19345 | + | |
19346 | + if (current->acl->group_trans_type & GR_ID_ALLOW) { | |
19347 | + for (i = 0; i < num; i++) { | |
19348 | + curgid = (int)gidlist[i]; | |
19349 | + if (real == curgid) | |
19350 | + realok = 1; | |
19351 | + if (effective == curgid) | |
19352 | + effectiveok = 1; | |
19353 | + if (fs == curgid) | |
19354 | + fsok = 1; | |
19355 | + } | |
19356 | + } else if (current->acl->group_trans_type & GR_ID_DENY) { | |
19357 | + for (i = 0; i < num; i++) { | |
19358 | + curgid = (int)gidlist[i]; | |
19359 | + if (real == curgid) | |
19360 | + break; | |
19361 | + if (effective == curgid) | |
19362 | + break; | |
19363 | + if (fs == curgid) | |
19364 | + break; | |
19365 | + } | |
19366 | + /* not in deny list */ | |
19367 | + if (i == num) { | |
19368 | + realok = 1; | |
19369 | + effectiveok = 1; | |
19370 | + fsok = 1; | |
19371 | + } | |
19372 | + } | |
19373 | + | |
19374 | + if (realok && effectiveok && fsok) | |
19375 | + return 0; | |
19376 | + else { | |
19377 | + gr_log_int(GR_DONT_AUDIT, GR_GRPCHANGE_ACL_MSG, realok ? (effectiveok ? (fsok ? 0 : fs) : effective) : real); | |
19378 | + return 1; | |
19379 | + } | |
19380 | +} | |
19381 | + | |
19382 | +void | |
19383 | +gr_set_role_label(struct task_struct *task, const uid_t uid, const uid_t gid) | |
19384 | +{ | |
19385 | + struct acl_role_label *role = task->role; | |
19386 | + struct acl_subject_label *subj = NULL; | |
19387 | + struct acl_object_label *obj; | |
19388 | + struct file *filp; | |
19389 | + | |
19390 | + if (unlikely(!(gr_status & GR_READY))) | |
19391 | + return; | |
19392 | + | |
19393 | + filp = task->exec_file; | |
19394 | + | |
19395 | + /* kernel process, we'll give them the kernel role */ | |
19396 | + if (unlikely(!filp)) { | |
19397 | + task->role = kernel_role; | |
19398 | + task->acl = kernel_role->root_label; | |
19399 | + return; | |
19400 | + } else if (!task->role || !(task->role->roletype & GR_ROLE_SPECIAL)) | |
19401 | + role = lookup_acl_role_label(task, uid, gid); | |
19402 | + | |
19403 | + /* perform subject lookup in possibly new role | |
19404 | + we can use this result below in the case where role == task->role | |
19405 | + */ | |
4dee9bd5 | 19406 | + subj = chk_subj_label(filp->f_path.dentry, filp->f_path.mnt, role); |
50425a20 | 19407 | + |
19408 | + /* if we changed uid/gid, but result in the same role | |
19409 | + and are using inheritance, don't lose the inherited subject | |
19410 | + if current subject is other than what normal lookup | |
19411 | + would result in, we arrived via inheritance, don't | |
19412 | + lose subject | |
19413 | + */ | |
19414 | + if (role != task->role || (!(task->acl->mode & GR_INHERITLEARN) && | |
19415 | + (subj == task->acl))) | |
19416 | + task->acl = subj; | |
19417 | + | |
19418 | + task->role = role; | |
19419 | + | |
19420 | + task->is_writable = 0; | |
19421 | + | |
19422 | + /* ignore additional mmap checks for processes that are writable | |
19423 | + by the default ACL */ | |
4dee9bd5 | 19424 | + obj = chk_obj_label(filp->f_path.dentry, filp->f_path.mnt, default_role->root_label); |
50425a20 | 19425 | + if (unlikely(obj->mode & GR_WRITE)) |
19426 | + task->is_writable = 1; | |
4dee9bd5 | 19427 | + obj = chk_obj_label(filp->f_path.dentry, filp->f_path.mnt, task->role->root_label); |
50425a20 | 19428 | + if (unlikely(obj->mode & GR_WRITE)) |
19429 | + task->is_writable = 1; | |
19430 | + | |
19431 | +#ifdef CONFIG_GRKERNSEC_ACL_DEBUG | |
19432 | + printk(KERN_ALERT "Set role label for (%s:%d): role:%s, subject:%s\n", task->comm, task->pid, task->role->rolename, task->acl->filename); | |
19433 | +#endif | |
19434 | + | |
19435 | + gr_set_proc_res(task); | |
19436 | + | |
19437 | + return; | |
19438 | +} | |
19439 | + | |
19440 | +int | |
19441 | +gr_set_proc_label(const struct dentry *dentry, const struct vfsmount *mnt) | |
19442 | +{ | |
19443 | + struct task_struct *task = current; | |
19444 | + struct acl_subject_label *newacl; | |
19445 | + struct acl_object_label *obj; | |
19446 | + __u32 retmode; | |
19447 | + | |
19448 | + if (unlikely(!(gr_status & GR_READY))) | |
19449 | + return 0; | |
19450 | + | |
19451 | + newacl = chk_subj_label(dentry, mnt, task->role); | |
19452 | + | |
19453 | + task_lock(task); | |
19454 | + if (((task->ptrace & PT_PTRACED) && !(task->acl->mode & | |
19455 | + GR_POVERRIDE) && (task->acl != newacl) && | |
19456 | + !(task->role->roletype & GR_ROLE_GOD) && | |
19457 | + !gr_search_file(dentry, GR_PTRACERD, mnt) && | |
19458 | + !(task->acl->mode & (GR_LEARN | GR_INHERITLEARN))) || | |
19459 | + (atomic_read(&task->fs->count) > 1 || | |
19460 | + atomic_read(&task->files->count) > 1 || | |
19461 | + atomic_read(&task->sighand->count) > 1)) { | |
19462 | + task_unlock(task); | |
19463 | + gr_log_fs_generic(GR_DONT_AUDIT, GR_PTRACE_EXEC_ACL_MSG, dentry, mnt); | |
19464 | + return -EACCES; | |
19465 | + } | |
19466 | + task_unlock(task); | |
19467 | + | |
19468 | + obj = chk_obj_label(dentry, mnt, task->acl); | |
19469 | + retmode = obj->mode & (GR_INHERIT | GR_AUDIT_INHERIT); | |
19470 | + | |
19471 | + if (!(task->acl->mode & GR_INHERITLEARN) && | |
19472 | + ((newacl->mode & GR_LEARN) || !(retmode & GR_INHERIT))) { | |
19473 | + if (obj->nested) | |
19474 | + task->acl = obj->nested; | |
19475 | + else | |
19476 | + task->acl = newacl; | |
19477 | + } else if (retmode & GR_INHERIT && retmode & GR_AUDIT_INHERIT) | |
19478 | + gr_log_str_fs(GR_DO_AUDIT, GR_INHERIT_ACL_MSG, task->acl->filename, dentry, mnt); | |
19479 | + | |
19480 | + task->is_writable = 0; | |
19481 | + | |
19482 | + /* ignore additional mmap checks for processes that are writable | |
19483 | + by the default ACL */ | |
19484 | + obj = chk_obj_label(dentry, mnt, default_role->root_label); | |
19485 | + if (unlikely(obj->mode & GR_WRITE)) | |
19486 | + task->is_writable = 1; | |
19487 | + obj = chk_obj_label(dentry, mnt, task->role->root_label); | |
19488 | + if (unlikely(obj->mode & GR_WRITE)) | |
19489 | + task->is_writable = 1; | |
19490 | + | |
19491 | + gr_set_proc_res(task); | |
19492 | + | |
19493 | +#ifdef CONFIG_GRKERNSEC_ACL_DEBUG | |
19494 | + printk(KERN_ALERT "Set subject label for (%s:%d): role:%s, subject:%s\n", task->comm, task->pid, task->role->rolename, task->acl->filename); | |
19495 | +#endif | |
19496 | + return 0; | |
19497 | +} | |
19498 | + | |
da5b3fc8 | 19499 | +/* always called with valid inodev ptr */ |
50425a20 | 19500 | +static void |
da5b3fc8 | 19501 | +do_handle_delete(struct inodev_entry *inodev, const ino_t ino, const dev_t dev) |
50425a20 | 19502 | +{ |
19503 | + struct acl_object_label *matchpo; | |
19504 | + struct acl_subject_label *matchps; | |
19505 | + struct acl_subject_label *subj; | |
19506 | + struct acl_role_label *role; | |
19507 | + unsigned int i, x; | |
19508 | + | |
19509 | + FOR_EACH_ROLE_START(role, i) | |
19510 | + FOR_EACH_SUBJECT_START(role, subj, x) | |
19511 | + if ((matchpo = lookup_acl_obj_label(ino, dev, subj)) != NULL) | |
19512 | + matchpo->mode |= GR_DELETED; | |
19513 | + FOR_EACH_SUBJECT_END(subj,x) | |
19514 | + FOR_EACH_NESTED_SUBJECT_START(role, subj) | |
19515 | + if (subj->inode == ino && subj->device == dev) | |
19516 | + subj->mode |= GR_DELETED; | |
19517 | + FOR_EACH_NESTED_SUBJECT_END(subj) | |
19518 | + if ((matchps = lookup_acl_subj_label(ino, dev, role)) != NULL) | |
19519 | + matchps->mode |= GR_DELETED; | |
19520 | + FOR_EACH_ROLE_END(role,i) | |
19521 | + | |
da5b3fc8 | 19522 | + inodev->nentry->deleted = 1; |
19523 | + | |
50425a20 | 19524 | + return; |
19525 | +} | |
19526 | + | |
19527 | +void | |
19528 | +gr_handle_delete(const ino_t ino, const dev_t dev) | |
19529 | +{ | |
da5b3fc8 | 19530 | + struct inodev_entry *inodev; |
19531 | + | |
50425a20 | 19532 | + if (unlikely(!(gr_status & GR_READY))) |
19533 | + return; | |
19534 | + | |
19535 | + write_lock(&gr_inode_lock); | |
da5b3fc8 | 19536 | + inodev = lookup_inodev_entry(ino, dev); |
19537 | + if (inodev != NULL) | |
19538 | + do_handle_delete(inodev, ino, dev); | |
50425a20 | 19539 | + write_unlock(&gr_inode_lock); |
19540 | + | |
19541 | + return; | |
19542 | +} | |
19543 | + | |
19544 | +static void | |
19545 | +update_acl_obj_label(const ino_t oldinode, const dev_t olddevice, | |
19546 | + const ino_t newinode, const dev_t newdevice, | |
19547 | + struct acl_subject_label *subj) | |
19548 | +{ | |
19549 | + unsigned int index = fhash(oldinode, olddevice, subj->obj_hash_size); | |
19550 | + struct acl_object_label *match; | |
19551 | + | |
19552 | + match = subj->obj_hash[index]; | |
19553 | + | |
19554 | + while (match && (match->inode != oldinode || | |
19555 | + match->device != olddevice || | |
19556 | + !(match->mode & GR_DELETED))) | |
19557 | + match = match->next; | |
19558 | + | |
19559 | + if (match && (match->inode == oldinode) | |
19560 | + && (match->device == olddevice) | |
19561 | + && (match->mode & GR_DELETED)) { | |
19562 | + if (match->prev == NULL) { | |
19563 | + subj->obj_hash[index] = match->next; | |
19564 | + if (match->next != NULL) | |
19565 | + match->next->prev = NULL; | |
19566 | + } else { | |
19567 | + match->prev->next = match->next; | |
19568 | + if (match->next != NULL) | |
19569 | + match->next->prev = match->prev; | |
19570 | + } | |
19571 | + match->prev = NULL; | |
19572 | + match->next = NULL; | |
19573 | + match->inode = newinode; | |
19574 | + match->device = newdevice; | |
19575 | + match->mode &= ~GR_DELETED; | |
19576 | + | |
19577 | + insert_acl_obj_label(match, subj); | |
19578 | + } | |
19579 | + | |
19580 | + return; | |
19581 | +} | |
19582 | + | |
19583 | +static void | |
19584 | +update_acl_subj_label(const ino_t oldinode, const dev_t olddevice, | |
19585 | + const ino_t newinode, const dev_t newdevice, | |
19586 | + struct acl_role_label *role) | |
19587 | +{ | |
19588 | + unsigned int index = fhash(oldinode, olddevice, role->subj_hash_size); | |
19589 | + struct acl_subject_label *match; | |
19590 | + | |
19591 | + match = role->subj_hash[index]; | |
19592 | + | |
19593 | + while (match && (match->inode != oldinode || | |
19594 | + match->device != olddevice || | |
19595 | + !(match->mode & GR_DELETED))) | |
19596 | + match = match->next; | |
19597 | + | |
19598 | + if (match && (match->inode == oldinode) | |
19599 | + && (match->device == olddevice) | |
19600 | + && (match->mode & GR_DELETED)) { | |
19601 | + if (match->prev == NULL) { | |
19602 | + role->subj_hash[index] = match->next; | |
19603 | + if (match->next != NULL) | |
19604 | + match->next->prev = NULL; | |
19605 | + } else { | |
19606 | + match->prev->next = match->next; | |
19607 | + if (match->next != NULL) | |
19608 | + match->next->prev = match->prev; | |
19609 | + } | |
19610 | + match->prev = NULL; | |
19611 | + match->next = NULL; | |
19612 | + match->inode = newinode; | |
19613 | + match->device = newdevice; | |
19614 | + match->mode &= ~GR_DELETED; | |
19615 | + | |
19616 | + insert_acl_subj_label(match, role); | |
19617 | + } | |
19618 | + | |
19619 | + return; | |
19620 | +} | |
19621 | + | |
19622 | +static void | |
19623 | +update_inodev_entry(const ino_t oldinode, const dev_t olddevice, | |
19624 | + const ino_t newinode, const dev_t newdevice) | |
19625 | +{ | |
19626 | + unsigned int index = fhash(oldinode, olddevice, inodev_set.i_size); | |
19627 | + struct inodev_entry *match; | |
19628 | + | |
19629 | + match = inodev_set.i_hash[index]; | |
19630 | + | |
19631 | + while (match && (match->nentry->inode != oldinode || | |
da5b3fc8 | 19632 | + match->nentry->device != olddevice || !match->nentry->deleted)) |
50425a20 | 19633 | + match = match->next; |
19634 | + | |
19635 | + if (match && (match->nentry->inode == oldinode) | |
da5b3fc8 | 19636 | + && (match->nentry->device == olddevice) && |
19637 | + match->nentry->deleted) { | |
50425a20 | 19638 | + if (match->prev == NULL) { |
19639 | + inodev_set.i_hash[index] = match->next; | |
19640 | + if (match->next != NULL) | |
19641 | + match->next->prev = NULL; | |
19642 | + } else { | |
19643 | + match->prev->next = match->next; | |
19644 | + if (match->next != NULL) | |
19645 | + match->next->prev = match->prev; | |
19646 | + } | |
19647 | + match->prev = NULL; | |
19648 | + match->next = NULL; | |
19649 | + match->nentry->inode = newinode; | |
19650 | + match->nentry->device = newdevice; | |
da5b3fc8 | 19651 | + match->nentry->deleted = 0; |
50425a20 | 19652 | + |
19653 | + insert_inodev_entry(match); | |
19654 | + } | |
19655 | + | |
19656 | + return; | |
19657 | +} | |
19658 | + | |
19659 | +static void | |
19660 | +do_handle_create(const struct name_entry *matchn, const struct dentry *dentry, | |
19661 | + const struct vfsmount *mnt) | |
19662 | +{ | |
19663 | + struct acl_subject_label *subj; | |
19664 | + struct acl_role_label *role; | |
19665 | + unsigned int i, x; | |
19666 | + | |
19667 | + FOR_EACH_ROLE_START(role, i) | |
19668 | + update_acl_subj_label(matchn->inode, matchn->device, | |
19669 | + dentry->d_inode->i_ino, | |
19670 | + dentry->d_inode->i_sb->s_dev, role); | |
19671 | + | |
19672 | + FOR_EACH_NESTED_SUBJECT_START(role, subj) | |
19673 | + if ((subj->inode == dentry->d_inode->i_ino) && | |
19674 | + (subj->device == dentry->d_inode->i_sb->s_dev)) { | |
19675 | + subj->inode = dentry->d_inode->i_ino; | |
19676 | + subj->device = dentry->d_inode->i_sb->s_dev; | |
19677 | + } | |
19678 | + FOR_EACH_NESTED_SUBJECT_END(subj) | |
19679 | + FOR_EACH_SUBJECT_START(role, subj, x) | |
19680 | + update_acl_obj_label(matchn->inode, matchn->device, | |
19681 | + dentry->d_inode->i_ino, | |
19682 | + dentry->d_inode->i_sb->s_dev, subj); | |
19683 | + FOR_EACH_SUBJECT_END(subj,x) | |
19684 | + FOR_EACH_ROLE_END(role,i) | |
19685 | + | |
19686 | + update_inodev_entry(matchn->inode, matchn->device, | |
19687 | + dentry->d_inode->i_ino, dentry->d_inode->i_sb->s_dev); | |
19688 | + | |
19689 | + return; | |
19690 | +} | |
19691 | + | |
19692 | +void | |
19693 | +gr_handle_create(const struct dentry *dentry, const struct vfsmount *mnt) | |
19694 | +{ | |
19695 | + struct name_entry *matchn; | |
19696 | + | |
19697 | + if (unlikely(!(gr_status & GR_READY))) | |
19698 | + return; | |
19699 | + | |
19700 | + preempt_disable(); | |
19701 | + matchn = lookup_name_entry(gr_to_filename_rbac(dentry, mnt)); | |
19702 | + | |
19703 | + if (unlikely((unsigned long)matchn)) { | |
19704 | + write_lock(&gr_inode_lock); | |
19705 | + do_handle_create(matchn, dentry, mnt); | |
19706 | + write_unlock(&gr_inode_lock); | |
19707 | + } | |
19708 | + preempt_enable(); | |
19709 | + | |
19710 | + return; | |
19711 | +} | |
19712 | + | |
19713 | +void | |
19714 | +gr_handle_rename(struct inode *old_dir, struct inode *new_dir, | |
19715 | + struct dentry *old_dentry, | |
19716 | + struct dentry *new_dentry, | |
19717 | + struct vfsmount *mnt, const __u8 replace) | |
19718 | +{ | |
19719 | + struct name_entry *matchn; | |
da5b3fc8 | 19720 | + struct inodev_entry *inodev; |
19721 | + | |
19722 | + /* vfs_rename swaps the name and parent link for old_dentry and | |
19723 | + new_dentry | |
19724 | + at this point, old_dentry has the new name, parent link, and inode | |
19725 | + for the renamed file | |
19726 | + if a file is being replaced by a rename, new_dentry has the inode | |
19727 | + and name for the replaced file | |
19728 | + */ | |
50425a20 | 19729 | + |
19730 | + if (unlikely(!(gr_status & GR_READY))) | |
19731 | + return; | |
19732 | + | |
19733 | + preempt_disable(); | |
da5b3fc8 | 19734 | + matchn = lookup_name_entry(gr_to_filename_rbac(old_dentry, mnt)); |
50425a20 | 19735 | + |
19736 | + /* we wouldn't have to check d_inode if it weren't for | |
19737 | + NFS silly-renaming | |
19738 | + */ | |
19739 | + | |
19740 | + write_lock(&gr_inode_lock); | |
19741 | + if (unlikely(replace && new_dentry->d_inode)) { | |
da5b3fc8 | 19742 | + inodev = lookup_inodev_entry(new_dentry->d_inode->i_ino, |
19743 | + new_dentry->d_inode->i_sb->s_dev); | |
19744 | + if (inodev != NULL && (new_dentry->d_inode->i_nlink <= 1)) | |
19745 | + do_handle_delete(inodev, new_dentry->d_inode->i_ino, | |
50425a20 | 19746 | + new_dentry->d_inode->i_sb->s_dev); |
19747 | + } | |
19748 | + | |
da5b3fc8 | 19749 | + inodev = lookup_inodev_entry(old_dentry->d_inode->i_ino, |
19750 | + old_dentry->d_inode->i_sb->s_dev); | |
19751 | + if (inodev != NULL && (old_dentry->d_inode->i_nlink <= 1)) | |
19752 | + do_handle_delete(inodev, old_dentry->d_inode->i_ino, | |
50425a20 | 19753 | + old_dentry->d_inode->i_sb->s_dev); |
19754 | + | |
19755 | + if (unlikely((unsigned long)matchn)) | |
19756 | + do_handle_create(matchn, old_dentry, mnt); | |
19757 | + | |
19758 | + write_unlock(&gr_inode_lock); | |
19759 | + preempt_enable(); | |
19760 | + | |
19761 | + return; | |
19762 | +} | |
19763 | + | |
19764 | +static int | |
19765 | +lookup_special_role_auth(__u16 mode, const char *rolename, unsigned char **salt, | |
19766 | + unsigned char **sum) | |
19767 | +{ | |
19768 | + struct acl_role_label *r; | |
19769 | + struct role_allowed_ip *ipp; | |
19770 | + struct role_transition *trans; | |
19771 | + unsigned int i; | |
19772 | + int found = 0; | |
19773 | + | |
19774 | + /* check transition table */ | |
19775 | + | |
19776 | + for (trans = current->role->transitions; trans; trans = trans->next) { | |
19777 | + if (!strcmp(rolename, trans->rolename)) { | |
19778 | + found = 1; | |
19779 | + break; | |
19780 | + } | |
19781 | + } | |
19782 | + | |
19783 | + if (!found) | |
19784 | + return 0; | |
19785 | + | |
19786 | + /* handle special roles that do not require authentication | |
19787 | + and check ip */ | |
19788 | + | |
19789 | + FOR_EACH_ROLE_START(r, i) | |
19790 | + if (!strcmp(rolename, r->rolename) && | |
19791 | + (r->roletype & GR_ROLE_SPECIAL)) { | |
19792 | + found = 0; | |
19793 | + if (r->allowed_ips != NULL) { | |
19794 | + for (ipp = r->allowed_ips; ipp; ipp = ipp->next) { | |
19795 | + if ((ntohl(current->signal->curr_ip) & ipp->netmask) == | |
19796 | + (ntohl(ipp->addr) & ipp->netmask)) | |
19797 | + found = 1; | |
19798 | + } | |
19799 | + } else | |
19800 | + found = 2; | |
19801 | + if (!found) | |
19802 | + return 0; | |
19803 | + | |
19804 | + if (((mode == SPROLE) && (r->roletype & GR_ROLE_NOPW)) || | |
19805 | + ((mode == SPROLEPAM) && (r->roletype & GR_ROLE_PAM))) { | |
19806 | + *salt = NULL; | |
19807 | + *sum = NULL; | |
19808 | + return 1; | |
19809 | + } | |
19810 | + } | |
19811 | + FOR_EACH_ROLE_END(r,i) | |
19812 | + | |
19813 | + for (i = 0; i < num_sprole_pws; i++) { | |
19814 | + if (!strcmp(rolename, acl_special_roles[i]->rolename)) { | |
19815 | + *salt = acl_special_roles[i]->salt; | |
19816 | + *sum = acl_special_roles[i]->sum; | |
19817 | + return 1; | |
19818 | + } | |
19819 | + } | |
19820 | + | |
19821 | + return 0; | |
19822 | +} | |
19823 | + | |
19824 | +static void | |
19825 | +assign_special_role(char *rolename) | |
19826 | +{ | |
19827 | + struct acl_object_label *obj; | |
19828 | + struct acl_role_label *r; | |
19829 | + struct acl_role_label *assigned = NULL; | |
19830 | + struct task_struct *tsk; | |
19831 | + struct file *filp; | |
19832 | + unsigned int i; | |
19833 | + | |
19834 | + FOR_EACH_ROLE_START(r, i) | |
19835 | + if (!strcmp(rolename, r->rolename) && | |
19836 | + (r->roletype & GR_ROLE_SPECIAL)) | |
19837 | + assigned = r; | |
19838 | + FOR_EACH_ROLE_END(r,i) | |
19839 | + | |
19840 | + if (!assigned) | |
19841 | + return; | |
19842 | + | |
19843 | + read_lock(&tasklist_lock); | |
19844 | + read_lock(&grsec_exec_file_lock); | |
19845 | + | |
19846 | + tsk = current->parent; | |
19847 | + if (tsk == NULL) | |
19848 | + goto out_unlock; | |
19849 | + | |
19850 | + filp = tsk->exec_file; | |
19851 | + if (filp == NULL) | |
19852 | + goto out_unlock; | |
19853 | + | |
19854 | + tsk->is_writable = 0; | |
19855 | + | |
19856 | + tsk->acl_sp_role = 1; | |
19857 | + tsk->acl_role_id = ++acl_sp_role_value; | |
19858 | + tsk->role = assigned; | |
4dee9bd5 | 19859 | + tsk->acl = chk_subj_label(filp->f_path.dentry, filp->f_path.mnt, tsk->role); |
50425a20 | 19860 | + |
19861 | + /* ignore additional mmap checks for processes that are writable | |
19862 | + by the default ACL */ | |
4dee9bd5 | 19863 | + obj = chk_obj_label(filp->f_path.dentry, filp->f_path.mnt, default_role->root_label); |
50425a20 | 19864 | + if (unlikely(obj->mode & GR_WRITE)) |
19865 | + tsk->is_writable = 1; | |
4dee9bd5 | 19866 | + obj = chk_obj_label(filp->f_path.dentry, filp->f_path.mnt, tsk->role->root_label); |
50425a20 | 19867 | + if (unlikely(obj->mode & GR_WRITE)) |
19868 | + tsk->is_writable = 1; | |
19869 | + | |
19870 | +#ifdef CONFIG_GRKERNSEC_ACL_DEBUG | |
19871 | + printk(KERN_ALERT "Assigning special role:%s subject:%s to process (%s:%d)\n", tsk->role->rolename, tsk->acl->filename, tsk->comm, tsk->pid); | |
19872 | +#endif | |
19873 | + | |
19874 | +out_unlock: | |
19875 | + read_unlock(&grsec_exec_file_lock); | |
19876 | + read_unlock(&tasklist_lock); | |
19877 | + return; | |
19878 | +} | |
19879 | + | |
19880 | +int gr_check_secure_terminal(struct task_struct *task) | |
19881 | +{ | |
19882 | + struct task_struct *p, *p2, *p3; | |
19883 | + struct files_struct *files; | |
19884 | + struct fdtable *fdt; | |
19885 | + struct file *our_file = NULL, *file; | |
19886 | + int i; | |
19887 | + | |
19888 | + if (task->signal->tty == NULL) | |
19889 | + return 1; | |
19890 | + | |
19891 | + files = get_files_struct(task); | |
19892 | + if (files != NULL) { | |
19893 | + rcu_read_lock(); | |
19894 | + fdt = files_fdtable(files); | |
19895 | + for (i=0; i < fdt->max_fds; i++) { | |
19896 | + file = fcheck_files(files, i); | |
19897 | + if (file && (our_file == NULL) && (file->private_data == task->signal->tty)) { | |
19898 | + get_file(file); | |
19899 | + our_file = file; | |
19900 | + } | |
19901 | + } | |
19902 | + rcu_read_unlock(); | |
19903 | + put_files_struct(files); | |
19904 | + } | |
19905 | + | |
19906 | + if (our_file == NULL) | |
19907 | + return 1; | |
19908 | + | |
19909 | + read_lock(&tasklist_lock); | |
19910 | + do_each_thread(p2, p) { | |
19911 | + files = get_files_struct(p); | |
19912 | + if (files == NULL || | |
19913 | + (p->signal && p->signal->tty == task->signal->tty)) { | |
19914 | + if (files != NULL) | |
19915 | + put_files_struct(files); | |
19916 | + continue; | |
19917 | + } | |
19918 | + rcu_read_lock(); | |
19919 | + fdt = files_fdtable(files); | |
19920 | + for (i=0; i < fdt->max_fds; i++) { | |
19921 | + file = fcheck_files(files, i); | |
4dee9bd5 | 19922 | + if (file && S_ISCHR(file->f_path.dentry->d_inode->i_mode) && |
19923 | + file->f_path.dentry->d_inode->i_rdev == our_file->f_path.dentry->d_inode->i_rdev) { | |
50425a20 | 19924 | + p3 = task; |
19925 | + while (p3->pid > 0) { | |
19926 | + if (p3 == p) | |
19927 | + break; | |
19928 | + p3 = p3->parent; | |
19929 | + } | |
19930 | + if (p3 == p) | |
19931 | + break; | |
19932 | + gr_log_ttysniff(GR_DONT_AUDIT_GOOD, GR_TTYSNIFF_ACL_MSG, p); | |
19933 | + gr_handle_alertkill(p); | |
19934 | + rcu_read_unlock(); | |
19935 | + put_files_struct(files); | |
19936 | + read_unlock(&tasklist_lock); | |
19937 | + fput(our_file); | |
19938 | + return 0; | |
19939 | + } | |
19940 | + } | |
19941 | + rcu_read_unlock(); | |
19942 | + put_files_struct(files); | |
19943 | + } while_each_thread(p2, p); | |
19944 | + read_unlock(&tasklist_lock); | |
19945 | + | |
19946 | + fput(our_file); | |
19947 | + return 1; | |
19948 | +} | |
19949 | + | |
19950 | +ssize_t | |
19951 | +write_grsec_handler(struct file *file, const char * buf, size_t count, loff_t *ppos) | |
19952 | +{ | |
19953 | + struct gr_arg_wrapper uwrap; | |
19954 | + unsigned char *sprole_salt; | |
19955 | + unsigned char *sprole_sum; | |
19956 | + int error = sizeof (struct gr_arg_wrapper); | |
19957 | + int error2 = 0; | |
19958 | + | |
19959 | + down(&gr_dev_sem); | |
19960 | + | |
19961 | + if ((gr_status & GR_READY) && !(current->acl->mode & GR_KERNELAUTH)) { | |
19962 | + error = -EPERM; | |
19963 | + goto out; | |
19964 | + } | |
19965 | + | |
19966 | + if (count != sizeof (struct gr_arg_wrapper)) { | |
19967 | + gr_log_int_int(GR_DONT_AUDIT_GOOD, GR_DEV_ACL_MSG, (int)count, (int)sizeof(struct gr_arg_wrapper)); | |
19968 | + error = -EINVAL; | |
19969 | + goto out; | |
19970 | + } | |
19971 | + | |
19972 | + | |
19973 | + if (gr_auth_expires && time_after_eq(get_seconds(), gr_auth_expires)) { | |
19974 | + gr_auth_expires = 0; | |
19975 | + gr_auth_attempts = 0; | |
19976 | + } | |
19977 | + | |
19978 | + if (copy_from_user(&uwrap, buf, sizeof (struct gr_arg_wrapper))) { | |
19979 | + error = -EFAULT; | |
19980 | + goto out; | |
19981 | + } | |
19982 | + | |
19983 | + if ((uwrap.version != GRSECURITY_VERSION) || (uwrap.size != sizeof(struct gr_arg))) { | |
19984 | + error = -EINVAL; | |
19985 | + goto out; | |
19986 | + } | |
19987 | + | |
19988 | + if (copy_from_user(gr_usermode, uwrap.arg, sizeof (struct gr_arg))) { | |
19989 | + error = -EFAULT; | |
19990 | + goto out; | |
19991 | + } | |
19992 | + | |
19993 | + if (gr_usermode->mode != SPROLE && gr_usermode->mode != SPROLEPAM && | |
19994 | + gr_auth_attempts >= CONFIG_GRKERNSEC_ACL_MAXTRIES && | |
19995 | + time_after(gr_auth_expires, get_seconds())) { | |
19996 | + error = -EBUSY; | |
19997 | + goto out; | |
19998 | + } | |
19999 | + | |
20000 | + /* if non-root trying to do anything other than use a special role, | |
20001 | + do not attempt authentication, do not count towards authentication | |
20002 | + locking | |
20003 | + */ | |
20004 | + | |
20005 | + if (gr_usermode->mode != SPROLE && gr_usermode->mode != STATUS && | |
20006 | + gr_usermode->mode != UNSPROLE && gr_usermode->mode != SPROLEPAM && | |
20007 | + current->uid) { | |
20008 | + error = -EPERM; | |
20009 | + goto out; | |
20010 | + } | |
20011 | + | |
20012 | + /* ensure pw and special role name are null terminated */ | |
20013 | + | |
20014 | + gr_usermode->pw[GR_PW_LEN - 1] = '\0'; | |
20015 | + gr_usermode->sp_role[GR_SPROLE_LEN - 1] = '\0'; | |
20016 | + | |
20017 | + /* Okay. | |
20018 | + * We have our enough of the argument structure..(we have yet | |
20019 | + * to copy_from_user the tables themselves) . Copy the tables | |
20020 | + * only if we need them, i.e. for loading operations. */ | |
20021 | + | |
20022 | + switch (gr_usermode->mode) { | |
20023 | + case STATUS: | |
20024 | + if (gr_status & GR_READY) { | |
20025 | + error = 1; | |
20026 | + if (!gr_check_secure_terminal(current)) | |
20027 | + error = 3; | |
20028 | + } else | |
20029 | + error = 2; | |
20030 | + goto out; | |
20031 | + case SHUTDOWN: | |
20032 | + if ((gr_status & GR_READY) | |
20033 | + && !(chkpw(gr_usermode, gr_system_salt, gr_system_sum))) { | |
20034 | + gr_status &= ~GR_READY; | |
20035 | + gr_log_noargs(GR_DONT_AUDIT_GOOD, GR_SHUTS_ACL_MSG); | |
20036 | + free_variables(); | |
20037 | + memset(gr_usermode, 0, sizeof (struct gr_arg)); | |
20038 | + memset(gr_system_salt, 0, GR_SALT_LEN); | |
20039 | + memset(gr_system_sum, 0, GR_SHA_LEN); | |
20040 | + } else if (gr_status & GR_READY) { | |
20041 | + gr_log_noargs(GR_DONT_AUDIT, GR_SHUTF_ACL_MSG); | |
20042 | + error = -EPERM; | |
20043 | + } else { | |
20044 | + gr_log_noargs(GR_DONT_AUDIT_GOOD, GR_SHUTI_ACL_MSG); | |
20045 | + error = -EAGAIN; | |
20046 | + } | |
20047 | + break; | |
20048 | + case ENABLE: | |
20049 | + if (!(gr_status & GR_READY) && !(error2 = gracl_init(gr_usermode))) | |
20050 | + gr_log_str(GR_DONT_AUDIT_GOOD, GR_ENABLE_ACL_MSG, GR_VERSION); | |
20051 | + else { | |
20052 | + if (gr_status & GR_READY) | |
20053 | + error = -EAGAIN; | |
20054 | + else | |
20055 | + error = error2; | |
20056 | + gr_log_str(GR_DONT_AUDIT, GR_ENABLEF_ACL_MSG, GR_VERSION); | |
20057 | + } | |
20058 | + break; | |
20059 | + case RELOAD: | |
20060 | + if (!(gr_status & GR_READY)) { | |
20061 | + gr_log_str(GR_DONT_AUDIT_GOOD, GR_RELOADI_ACL_MSG, GR_VERSION); | |
20062 | + error = -EAGAIN; | |
20063 | + } else if (!(chkpw(gr_usermode, gr_system_salt, gr_system_sum))) { | |
20064 | + lock_kernel(); | |
20065 | + gr_status &= ~GR_READY; | |
20066 | + free_variables(); | |
20067 | + if (!(error2 = gracl_init(gr_usermode))) { | |
20068 | + unlock_kernel(); | |
20069 | + gr_log_str(GR_DONT_AUDIT_GOOD, GR_RELOAD_ACL_MSG, GR_VERSION); | |
20070 | + } else { | |
20071 | + unlock_kernel(); | |
20072 | + error = error2; | |
20073 | + gr_log_str(GR_DONT_AUDIT, GR_RELOADF_ACL_MSG, GR_VERSION); | |
20074 | + } | |
20075 | + } else { | |
20076 | + gr_log_str(GR_DONT_AUDIT, GR_RELOADF_ACL_MSG, GR_VERSION); | |
20077 | + error = -EPERM; | |
20078 | + } | |
20079 | + break; | |
20080 | + case SEGVMOD: | |
20081 | + if (unlikely(!(gr_status & GR_READY))) { | |
20082 | + gr_log_noargs(GR_DONT_AUDIT_GOOD, GR_SEGVMODI_ACL_MSG); | |
20083 | + error = -EAGAIN; | |
20084 | + break; | |
20085 | + } | |
20086 | + | |
20087 | + if (!(chkpw(gr_usermode, gr_system_salt, gr_system_sum))) { | |
20088 | + gr_log_noargs(GR_DONT_AUDIT_GOOD, GR_SEGVMODS_ACL_MSG); | |
20089 | + if (gr_usermode->segv_device && gr_usermode->segv_inode) { | |
20090 | + struct acl_subject_label *segvacl; | |
20091 | + segvacl = | |
20092 | + lookup_acl_subj_label(gr_usermode->segv_inode, | |
20093 | + gr_usermode->segv_device, | |
20094 | + current->role); | |
20095 | + if (segvacl) { | |
20096 | + segvacl->crashes = 0; | |
20097 | + segvacl->expires = 0; | |
20098 | + } | |
20099 | + } else if (gr_find_uid(gr_usermode->segv_uid) >= 0) { | |
20100 | + gr_remove_uid(gr_usermode->segv_uid); | |
20101 | + } | |
20102 | + } else { | |
20103 | + gr_log_noargs(GR_DONT_AUDIT, GR_SEGVMODF_ACL_MSG); | |
20104 | + error = -EPERM; | |
20105 | + } | |
20106 | + break; | |
20107 | + case SPROLE: | |
20108 | + case SPROLEPAM: | |
20109 | + if (unlikely(!(gr_status & GR_READY))) { | |
20110 | + gr_log_noargs(GR_DONT_AUDIT_GOOD, GR_SPROLEI_ACL_MSG); | |
20111 | + error = -EAGAIN; | |
20112 | + break; | |
20113 | + } | |
20114 | + | |
20115 | + if (current->role->expires && time_after_eq(get_seconds(), current->role->expires)) { | |
20116 | + current->role->expires = 0; | |
20117 | + current->role->auth_attempts = 0; | |
20118 | + } | |
20119 | + | |
20120 | + if (current->role->auth_attempts >= CONFIG_GRKERNSEC_ACL_MAXTRIES && | |
20121 | + time_after(current->role->expires, get_seconds())) { | |
20122 | + error = -EBUSY; | |
20123 | + goto out; | |
20124 | + } | |
20125 | + | |
20126 | + if (lookup_special_role_auth | |
20127 | + (gr_usermode->mode, gr_usermode->sp_role, &sprole_salt, &sprole_sum) | |
20128 | + && ((!sprole_salt && !sprole_sum) | |
20129 | + || !(chkpw(gr_usermode, sprole_salt, sprole_sum)))) { | |
20130 | + char *p = ""; | |
20131 | + assign_special_role(gr_usermode->sp_role); | |
20132 | + read_lock(&tasklist_lock); | |
20133 | + if (current->parent) | |
20134 | + p = current->parent->role->rolename; | |
20135 | + read_unlock(&tasklist_lock); | |
20136 | + gr_log_str_int(GR_DONT_AUDIT_GOOD, GR_SPROLES_ACL_MSG, | |
20137 | + p, acl_sp_role_value); | |
20138 | + } else { | |
20139 | + gr_log_str(GR_DONT_AUDIT, GR_SPROLEF_ACL_MSG, gr_usermode->sp_role); | |
20140 | + error = -EPERM; | |
20141 | + if(!(current->role->auth_attempts++)) | |
20142 | + current->role->expires = get_seconds() + CONFIG_GRKERNSEC_ACL_TIMEOUT; | |
20143 | + | |
20144 | + goto out; | |
20145 | + } | |
20146 | + break; | |
20147 | + case UNSPROLE: | |
20148 | + if (unlikely(!(gr_status & GR_READY))) { | |
20149 | + gr_log_noargs(GR_DONT_AUDIT_GOOD, GR_UNSPROLEI_ACL_MSG); | |
20150 | + error = -EAGAIN; | |
20151 | + break; | |
20152 | + } | |
20153 | + | |
20154 | + if (current->role->roletype & GR_ROLE_SPECIAL) { | |
20155 | + char *p = ""; | |
20156 | + int i = 0; | |
20157 | + | |
20158 | + read_lock(&tasklist_lock); | |
20159 | + if (current->parent) { | |
20160 | + p = current->parent->role->rolename; | |
20161 | + i = current->parent->acl_role_id; | |
20162 | + } | |
20163 | + read_unlock(&tasklist_lock); | |
20164 | + | |
20165 | + gr_log_str_int(GR_DONT_AUDIT_GOOD, GR_UNSPROLES_ACL_MSG, p, i); | |
20166 | + gr_set_acls(1); | |
20167 | + } else { | |
20168 | + gr_log_str(GR_DONT_AUDIT, GR_UNSPROLEF_ACL_MSG, current->role->rolename); | |
20169 | + error = -EPERM; | |
20170 | + goto out; | |
20171 | + } | |
20172 | + break; | |
20173 | + default: | |
20174 | + gr_log_int(GR_DONT_AUDIT, GR_INVMODE_ACL_MSG, gr_usermode->mode); | |
20175 | + error = -EINVAL; | |
20176 | + break; | |
20177 | + } | |
20178 | + | |
20179 | + if (error != -EPERM) | |
20180 | + goto out; | |
20181 | + | |
20182 | + if(!(gr_auth_attempts++)) | |
20183 | + gr_auth_expires = get_seconds() + CONFIG_GRKERNSEC_ACL_TIMEOUT; | |
20184 | + | |
20185 | + out: | |
20186 | + up(&gr_dev_sem); | |
20187 | + return error; | |
20188 | +} | |
20189 | + | |
20190 | +int | |
20191 | +gr_set_acls(const int type) | |
20192 | +{ | |
20193 | + struct acl_object_label *obj; | |
20194 | + struct task_struct *task, *task2; | |
20195 | + struct file *filp; | |
20196 | + struct acl_role_label *role = current->role; | |
20197 | + __u16 acl_role_id = current->acl_role_id; | |
20198 | + | |
20199 | + read_lock(&tasklist_lock); | |
20200 | + read_lock(&grsec_exec_file_lock); | |
20201 | + do_each_thread(task2, task) { | |
20202 | + /* check to see if we're called from the exit handler, | |
20203 | + if so, only replace ACLs that have inherited the admin | |
20204 | + ACL */ | |
20205 | + | |
20206 | + if (type && (task->role != role || | |
20207 | + task->acl_role_id != acl_role_id)) | |
20208 | + continue; | |
20209 | + | |
20210 | + task->acl_role_id = 0; | |
20211 | + task->acl_sp_role = 0; | |
20212 | + | |
20213 | + if ((filp = task->exec_file)) { | |
20214 | + task->role = lookup_acl_role_label(task, task->uid, task->gid); | |
20215 | + | |
20216 | + task->acl = | |
4dee9bd5 | 20217 | + chk_subj_label(filp->f_path.dentry, filp->f_path.mnt, |
50425a20 | 20218 | + task->role); |
20219 | + if (task->acl) { | |
20220 | + struct acl_subject_label *curr; | |
20221 | + curr = task->acl; | |
20222 | + | |
20223 | + task->is_writable = 0; | |
20224 | + /* ignore additional mmap checks for processes that are writable | |
20225 | + by the default ACL */ | |
4dee9bd5 | 20226 | + obj = chk_obj_label(filp->f_path.dentry, filp->f_path.mnt, default_role->root_label); |
50425a20 | 20227 | + if (unlikely(obj->mode & GR_WRITE)) |
20228 | + task->is_writable = 1; | |
4dee9bd5 | 20229 | + obj = chk_obj_label(filp->f_path.dentry, filp->f_path.mnt, task->role->root_label); |
50425a20 | 20230 | + if (unlikely(obj->mode & GR_WRITE)) |
20231 | + task->is_writable = 1; | |
20232 | + | |
20233 | + gr_set_proc_res(task); | |
20234 | + | |
20235 | +#ifdef CONFIG_GRKERNSEC_ACL_DEBUG | |
20236 | + printk(KERN_ALERT "gr_set_acls for (%s:%d): role:%s, subject:%s\n", task->comm, task->pid, task->role->rolename, task->acl->filename); | |
20237 | +#endif | |
20238 | + } else { | |
20239 | + read_unlock(&grsec_exec_file_lock); | |
20240 | + read_unlock(&tasklist_lock); | |
20241 | + gr_log_str_int(GR_DONT_AUDIT_GOOD, GR_DEFACL_MSG, task->comm, task->pid); | |
20242 | + return 1; | |
20243 | + } | |
20244 | + } else { | |
20245 | + // it's a kernel process | |
20246 | + task->role = kernel_role; | |
20247 | + task->acl = kernel_role->root_label; | |
20248 | +#ifdef CONFIG_GRKERNSEC_ACL_HIDEKERN | |
20249 | + task->acl->mode &= ~GR_PROCFIND; | |
20250 | +#endif | |
20251 | + } | |
20252 | + } while_each_thread(task2, task); | |
20253 | + read_unlock(&grsec_exec_file_lock); | |
20254 | + read_unlock(&tasklist_lock); | |
20255 | + return 0; | |
20256 | +} | |
20257 | + | |
20258 | +void | |
20259 | +gr_learn_resource(const struct task_struct *task, | |
20260 | + const int res, const unsigned long wanted, const int gt) | |
20261 | +{ | |
20262 | + struct acl_subject_label *acl; | |
20263 | + | |
20264 | + if (unlikely((gr_status & GR_READY) && | |
20265 | + task->acl && (task->acl->mode & (GR_LEARN | GR_INHERITLEARN)))) | |
20266 | + goto skip_reslog; | |
20267 | + | |
20268 | +#ifdef CONFIG_GRKERNSEC_RESLOG | |
20269 | + gr_log_resource(task, res, wanted, gt); | |
20270 | +#endif | |
20271 | + skip_reslog: | |
20272 | + | |
20273 | + if (unlikely(!(gr_status & GR_READY) || !wanted)) | |
20274 | + return; | |
20275 | + | |
20276 | + acl = task->acl; | |
20277 | + | |
20278 | + if (likely(!acl || !(acl->mode & (GR_LEARN | GR_INHERITLEARN)) || | |
20279 | + !(acl->resmask & (1 << (unsigned short) res)))) | |
20280 | + return; | |
20281 | + | |
20282 | + if (wanted >= acl->res[res].rlim_cur) { | |
20283 | + unsigned long res_add; | |
20284 | + | |
20285 | + res_add = wanted; | |
20286 | + switch (res) { | |
20287 | + case RLIMIT_CPU: | |
20288 | + res_add += GR_RLIM_CPU_BUMP; | |
20289 | + break; | |
20290 | + case RLIMIT_FSIZE: | |
20291 | + res_add += GR_RLIM_FSIZE_BUMP; | |
20292 | + break; | |
20293 | + case RLIMIT_DATA: | |
20294 | + res_add += GR_RLIM_DATA_BUMP; | |
20295 | + break; | |
20296 | + case RLIMIT_STACK: | |
20297 | + res_add += GR_RLIM_STACK_BUMP; | |
20298 | + break; | |
20299 | + case RLIMIT_CORE: | |
20300 | + res_add += GR_RLIM_CORE_BUMP; | |
20301 | + break; | |
20302 | + case RLIMIT_RSS: | |
20303 | + res_add += GR_RLIM_RSS_BUMP; | |
20304 | + break; | |
20305 | + case RLIMIT_NPROC: | |
20306 | + res_add += GR_RLIM_NPROC_BUMP; | |
20307 | + break; | |
20308 | + case RLIMIT_NOFILE: | |
20309 | + res_add += GR_RLIM_NOFILE_BUMP; | |
20310 | + break; | |
20311 | + case RLIMIT_MEMLOCK: | |
20312 | + res_add += GR_RLIM_MEMLOCK_BUMP; | |
20313 | + break; | |
20314 | + case RLIMIT_AS: | |
20315 | + res_add += GR_RLIM_AS_BUMP; | |
20316 | + break; | |
20317 | + case RLIMIT_LOCKS: | |
20318 | + res_add += GR_RLIM_LOCKS_BUMP; | |
20319 | + break; | |
20320 | + } | |
20321 | + | |
20322 | + acl->res[res].rlim_cur = res_add; | |
20323 | + | |
20324 | + if (wanted > acl->res[res].rlim_max) | |
20325 | + acl->res[res].rlim_max = res_add; | |
20326 | + | |
20327 | + security_learn(GR_LEARN_AUDIT_MSG, task->role->rolename, | |
20328 | + task->role->roletype, acl->filename, | |
20329 | + acl->res[res].rlim_cur, acl->res[res].rlim_max, | |
20330 | + "", (unsigned long) res); | |
20331 | + } | |
20332 | + | |
20333 | + return; | |
20334 | +} | |
20335 | + | |
20336 | +#ifdef CONFIG_PAX_HAVE_ACL_FLAGS | |
20337 | +void | |
20338 | +pax_set_initial_flags(struct linux_binprm *bprm) | |
20339 | +{ | |
20340 | + struct task_struct *task = current; | |
20341 | + struct acl_subject_label *proc; | |
20342 | + unsigned long flags; | |
20343 | + | |
20344 | + if (unlikely(!(gr_status & GR_READY))) | |
20345 | + return; | |
20346 | + | |
20347 | + flags = pax_get_flags(task); | |
20348 | + | |
20349 | + proc = task->acl; | |
20350 | + | |
20351 | + if (proc->pax_flags & GR_PAX_DISABLE_PAGEEXEC) | |
20352 | + flags &= ~MF_PAX_PAGEEXEC; | |
20353 | + if (proc->pax_flags & GR_PAX_DISABLE_SEGMEXEC) | |
20354 | + flags &= ~MF_PAX_SEGMEXEC; | |
20355 | + if (proc->pax_flags & GR_PAX_DISABLE_RANDMMAP) | |
20356 | + flags &= ~MF_PAX_RANDMMAP; | |
20357 | + if (proc->pax_flags & GR_PAX_DISABLE_EMUTRAMP) | |
20358 | + flags &= ~MF_PAX_EMUTRAMP; | |
20359 | + if (proc->pax_flags & GR_PAX_DISABLE_MPROTECT) | |
20360 | + flags &= ~MF_PAX_MPROTECT; | |
20361 | + | |
20362 | + if (proc->pax_flags & GR_PAX_ENABLE_PAGEEXEC) | |
20363 | + flags |= MF_PAX_PAGEEXEC; | |
20364 | + if (proc->pax_flags & GR_PAX_ENABLE_SEGMEXEC) | |
20365 | + flags |= MF_PAX_SEGMEXEC; | |
20366 | + if (proc->pax_flags & GR_PAX_ENABLE_RANDMMAP) | |
20367 | + flags |= MF_PAX_RANDMMAP; | |
20368 | + if (proc->pax_flags & GR_PAX_ENABLE_EMUTRAMP) | |
20369 | + flags |= MF_PAX_EMUTRAMP; | |
20370 | + if (proc->pax_flags & GR_PAX_ENABLE_MPROTECT) | |
20371 | + flags |= MF_PAX_MPROTECT; | |
20372 | + | |
20373 | + pax_set_flags(task, flags); | |
20374 | + | |
20375 | + return; | |
20376 | +} | |
20377 | +#endif | |
20378 | + | |
20379 | +#ifdef CONFIG_SYSCTL | |
e87b9006 | 20380 | +/* Eric Biederman likes breaking userland ABI and every inode-based security |
20381 | + system to save 35kb of memory */ | |
20382 | + | |
20383 | +/* we modify the passed in filename, but adjust it back before returning */ | |
20384 | +static struct acl_object_label *gr_lookup_by_name(char *name, unsigned int len) | |
20385 | +{ | |
20386 | + struct name_entry *nmatch; | |
20387 | + char *p, *lastp = NULL; | |
20388 | + struct acl_object_label *obj = NULL, *tmp; | |
20389 | + struct acl_subject_label *tmpsubj; | |
e87b9006 | 20390 | + char c = '\0'; |
20391 | + | |
20392 | + read_lock(&gr_inode_lock); | |
20393 | + | |
20394 | + p = name + len - 1; | |
20395 | + do { | |
20396 | + nmatch = lookup_name_entry(name); | |
20397 | + if (lastp != NULL) | |
20398 | + *lastp = c; | |
20399 | + | |
20400 | + if (nmatch == NULL) | |
20401 | + goto next_component; | |
20402 | + tmpsubj = current->acl; | |
20403 | + do { | |
20404 | + obj = lookup_acl_obj_label(nmatch->inode, nmatch->device, tmpsubj); | |
20405 | + if (obj != NULL) { | |
20406 | + tmp = obj->globbed; | |
20407 | + while (tmp) { | |
20408 | + if (!glob_match(tmp->filename, name)) { | |
20409 | + obj = tmp; | |
20410 | + goto found_obj; | |
20411 | + } | |
20412 | + tmp = tmp->next; | |
20413 | + } | |
20414 | + goto found_obj; | |
20415 | + } | |
20416 | + } while ((tmpsubj = tmpsubj->parent_subject)); | |
20417 | +next_component: | |
20418 | + /* end case */ | |
20419 | + if (p == name) | |
20420 | + break; | |
20421 | + | |
20422 | + while (*p != '/') | |
20423 | + p--; | |
20424 | + if (p == name) | |
20425 | + lastp = p + 1; | |
20426 | + else { | |
20427 | + lastp = p; | |
20428 | + p--; | |
20429 | + } | |
20430 | + c = *lastp; | |
20431 | + *lastp = '\0'; | |
20432 | + } while (1); | |
20433 | +found_obj: | |
20434 | + read_unlock(&gr_inode_lock); | |
20435 | + /* obj returned will always be non-null */ | |
20436 | + return obj; | |
20437 | +} | |
50425a20 | 20438 | + |
78fdc4fb | 20439 | +/* returns 0 when allowing, non-zero on error |
20440 | + op of 0 is used for readdir, so we don't log the names of hidden files | |
20441 | +*/ | |
50425a20 | 20442 | +__u32 |
e87b9006 | 20443 | +gr_handle_sysctl(const struct ctl_table *table, const int op) |
50425a20 | 20444 | +{ |
20445 | + ctl_table *tmp; | |
50425a20 | 20446 | + const char *proc_sys = "/proc/sys"; |
20447 | + char *path; | |
20448 | + struct acl_object_label *obj; | |
20449 | + unsigned short len = 0, pos = 0, depth = 0, i; | |
20450 | + __u32 err = 0; | |
78fdc4fb | 20451 | + __u32 mode = 0; |
50425a20 | 20452 | + |
20453 | + if (unlikely(!(gr_status & GR_READY))) | |
78fdc4fb | 20454 | + return 0; |
20455 | + | |
20456 | + /* for now, ignore operations on non-sysctl entries if it's not a | |
20457 | + readdir*/ | |
20458 | + if (table->child != NULL && op != 0) | |
20459 | + return 0; | |
20460 | + | |
20461 | + mode |= GR_FIND; | |
20462 | + /* it's only a read if it's an entry, read on dirs is for readdir */ | |
20463 | + if (op & 004) | |
20464 | + mode |= GR_READ; | |
20465 | + if (op & 002) | |
20466 | + mode |= GR_WRITE; | |
50425a20 | 20467 | + |
e87b9006 | 20468 | + preempt_disable(); |
20469 | + | |
50425a20 | 20470 | + path = per_cpu_ptr(gr_shared_page[0], smp_processor_id()); |
20471 | + | |
f4251508 | 20472 | + /* it's only a read/write if it's an actual entry, not a dir |
e87b9006 | 20473 | + (which are opened for readdir) |
20474 | + */ | |
78fdc4fb | 20475 | + |
50425a20 | 20476 | + /* convert the requested sysctl entry into a pathname */ |
20477 | + | |
2ea714d4 | 20478 | + for (tmp = (ctl_table *)table; tmp != NULL; tmp = tmp->parent) { |
50425a20 | 20479 | + len += strlen(tmp->procname); |
20480 | + len++; | |
20481 | + depth++; | |
20482 | + } | |
20483 | + | |
e87b9006 | 20484 | + if ((len + depth + strlen(proc_sys) + 1) > PAGE_SIZE) { |
78fdc4fb | 20485 | + /* deny */ |
e87b9006 | 20486 | + goto out; |
20487 | + } | |
50425a20 | 20488 | + |
20489 | + memset(path, 0, PAGE_SIZE); | |
20490 | + | |
20491 | + memcpy(path, proc_sys, strlen(proc_sys)); | |
20492 | + | |
20493 | + pos += strlen(proc_sys); | |
20494 | + | |
20495 | + for (; depth > 0; depth--) { | |
20496 | + path[pos] = '/'; | |
20497 | + pos++; | |
2ea714d4 | 20498 | + for (i = 1, tmp = (ctl_table *)table; tmp != NULL; tmp = tmp->parent) { |
50425a20 | 20499 | + if (depth == i) { |
20500 | + memcpy(path + pos, tmp->procname, | |
20501 | + strlen(tmp->procname)); | |
20502 | + pos += strlen(tmp->procname); | |
20503 | + } | |
20504 | + i++; | |
20505 | + } | |
20506 | + } | |
20507 | + | |
e87b9006 | 20508 | + obj = gr_lookup_by_name(path, pos); |
50425a20 | 20509 | + err = obj->mode & (mode | to_gr_audit(mode) | GR_SUPPRESS); |
20510 | + | |
20511 | + if (unlikely((current->acl->mode & (GR_LEARN | GR_INHERITLEARN)) && | |
20512 | + ((err & mode) != mode))) { | |
20513 | + __u32 new_mode = mode; | |
20514 | + | |
20515 | + new_mode &= ~(GR_AUDITS | GR_SUPPRESS); | |
20516 | + | |
78fdc4fb | 20517 | + err = 0; |
f4251508 | 20518 | + gr_log_learn_sysctl(current, path, new_mode); |
78fdc4fb | 20519 | + } else if (!(err & GR_FIND) && !(err & GR_SUPPRESS) && op != 0) { |
20520 | + gr_log_hidden_sysctl(GR_DONT_AUDIT, GR_HIDDEN_ACL_MSG, path); | |
20521 | + err = -ENOENT; | |
20522 | + } else if (!(err & GR_FIND)) { | |
20523 | + err = -ENOENT; | |
f4251508 | 20524 | + } else if (((err & mode) & ~GR_FIND) != (mode & ~GR_FIND) && !(err & GR_SUPPRESS)) { |
50425a20 | 20525 | + gr_log_str4(GR_DONT_AUDIT, GR_SYSCTL_ACL_MSG, "denied", |
20526 | + path, (mode & GR_READ) ? " reading" : "", | |
20527 | + (mode & GR_WRITE) ? " writing" : ""); | |
78fdc4fb | 20528 | + err = -EACCES; |
50425a20 | 20529 | + } else if ((err & mode) != mode) { |
78fdc4fb | 20530 | + err = -EACCES; |
f4251508 | 20531 | + } else if ((((err & mode) & ~GR_FIND) == (mode & ~GR_FIND)) && (err & GR_AUDITS)) { |
50425a20 | 20532 | + gr_log_str4(GR_DO_AUDIT, GR_SYSCTL_ACL_MSG, "successful", |
20533 | + path, (mode & GR_READ) ? " reading" : "", | |
20534 | + (mode & GR_WRITE) ? " writing" : ""); | |
78fdc4fb | 20535 | + err = 0; |
20536 | + } else | |
20537 | + err = 0; | |
50425a20 | 20538 | + |
50425a20 | 20539 | + out: |
e87b9006 | 20540 | + preempt_enable(); |
20541 | + | |
50425a20 | 20542 | + return err; |
20543 | +} | |
20544 | +#endif | |
20545 | + | |
20546 | +int | |
20547 | +gr_handle_proc_ptrace(struct task_struct *task) | |
20548 | +{ | |
20549 | + struct file *filp; | |
20550 | + struct task_struct *tmp = task; | |
20551 | + struct task_struct *curtemp = current; | |
20552 | + __u32 retmode; | |
20553 | + | |
20554 | + if (unlikely(!(gr_status & GR_READY))) | |
20555 | + return 0; | |
20556 | + | |
20557 | + read_lock(&tasklist_lock); | |
20558 | + read_lock(&grsec_exec_file_lock); | |
20559 | + filp = task->exec_file; | |
20560 | + | |
20561 | + while (tmp->pid > 0) { | |
20562 | + if (tmp == curtemp) | |
20563 | + break; | |
20564 | + tmp = tmp->parent; | |
20565 | + } | |
20566 | + | |
20567 | + if (!filp || (tmp->pid == 0 && !(current->acl->mode & GR_RELAXPTRACE))) { | |
20568 | + read_unlock(&grsec_exec_file_lock); | |
20569 | + read_unlock(&tasklist_lock); | |
20570 | + return 1; | |
20571 | + } | |
20572 | + | |
4dee9bd5 | 20573 | + retmode = gr_search_file(filp->f_path.dentry, GR_NOPTRACE, filp->f_path.mnt); |
50425a20 | 20574 | + read_unlock(&grsec_exec_file_lock); |
20575 | + read_unlock(&tasklist_lock); | |
20576 | + | |
20577 | + if (retmode & GR_NOPTRACE) | |
20578 | + return 1; | |
20579 | + | |
20580 | + if (!(current->acl->mode & GR_POVERRIDE) && !(current->role->roletype & GR_ROLE_GOD) | |
20581 | + && (current->acl != task->acl || (current->acl != current->role->root_label | |
20582 | + && current->pid != task->pid))) | |
20583 | + return 1; | |
20584 | + | |
20585 | + return 0; | |
20586 | +} | |
20587 | + | |
20588 | +int | |
20589 | +gr_handle_ptrace(struct task_struct *task, const long request) | |
20590 | +{ | |
20591 | + struct task_struct *tmp = task; | |
20592 | + struct task_struct *curtemp = current; | |
20593 | + __u32 retmode; | |
20594 | + | |
20595 | + if (unlikely(!(gr_status & GR_READY))) | |
20596 | + return 0; | |
20597 | + | |
20598 | + read_lock(&tasklist_lock); | |
20599 | + while (tmp->pid > 0) { | |
20600 | + if (tmp == curtemp) | |
20601 | + break; | |
20602 | + tmp = tmp->parent; | |
20603 | + } | |
20604 | + | |
20605 | + if (tmp->pid == 0 && !(current->acl->mode & GR_RELAXPTRACE)) { | |
20606 | + read_unlock(&tasklist_lock); | |
20607 | + gr_log_ptrace(GR_DONT_AUDIT, GR_PTRACE_ACL_MSG, task); | |
20608 | + return 1; | |
20609 | + } | |
20610 | + read_unlock(&tasklist_lock); | |
20611 | + | |
20612 | + read_lock(&grsec_exec_file_lock); | |
20613 | + if (unlikely(!task->exec_file)) { | |
20614 | + read_unlock(&grsec_exec_file_lock); | |
20615 | + return 0; | |
20616 | + } | |
20617 | + | |
4dee9bd5 | 20618 | + retmode = gr_search_file(task->exec_file->f_path.dentry, GR_PTRACERD | GR_NOPTRACE, task->exec_file->f_path.mnt); |
50425a20 | 20619 | + read_unlock(&grsec_exec_file_lock); |
20620 | + | |
20621 | + if (retmode & GR_NOPTRACE) { | |
20622 | + gr_log_ptrace(GR_DONT_AUDIT, GR_PTRACE_ACL_MSG, task); | |
20623 | + return 1; | |
20624 | + } | |
20625 | + | |
20626 | + if (retmode & GR_PTRACERD) { | |
20627 | + switch (request) { | |
20628 | + case PTRACE_POKETEXT: | |
20629 | + case PTRACE_POKEDATA: | |
20630 | + case PTRACE_POKEUSR: | |
20631 | +#if !defined(CONFIG_PPC32) && !defined(CONFIG_PPC64) && !defined(CONFIG_PARISC) && !defined(CONFIG_ALPHA) && !defined(CONFIG_IA64) | |
20632 | + case PTRACE_SETREGS: | |
20633 | + case PTRACE_SETFPREGS: | |
20634 | +#endif | |
20635 | +#ifdef CONFIG_X86 | |
20636 | + case PTRACE_SETFPXREGS: | |
20637 | +#endif | |
20638 | +#ifdef CONFIG_ALTIVEC | |
20639 | + case PTRACE_SETVRREGS: | |
20640 | +#endif | |
20641 | + return 1; | |
20642 | + default: | |
20643 | + return 0; | |
20644 | + } | |
20645 | + } else if (!(current->acl->mode & GR_POVERRIDE) && | |
20646 | + !(current->role->roletype & GR_ROLE_GOD) && | |
20647 | + (current->acl != task->acl)) { | |
20648 | + gr_log_ptrace(GR_DONT_AUDIT, GR_PTRACE_ACL_MSG, task); | |
20649 | + return 1; | |
20650 | + } | |
20651 | + | |
20652 | + return 0; | |
20653 | +} | |
20654 | + | |
20655 | +static int is_writable_mmap(const struct file *filp) | |
20656 | +{ | |
20657 | + struct task_struct *task = current; | |
20658 | + struct acl_object_label *obj, *obj2; | |
20659 | + | |
20660 | + if (gr_status & GR_READY && !(task->acl->mode & GR_OVERRIDE) && | |
4dee9bd5 | 20661 | + !task->is_writable && S_ISREG(filp->f_path.dentry->d_inode->i_mode)) { |
20662 | + obj = chk_obj_label(filp->f_path.dentry, filp->f_path.mnt, default_role->root_label); | |
20663 | + obj2 = chk_obj_label(filp->f_path.dentry, filp->f_path.mnt, | |
50425a20 | 20664 | + task->role->root_label); |
20665 | + if (unlikely((obj->mode & GR_WRITE) || (obj2->mode & GR_WRITE))) { | |
4dee9bd5 | 20666 | + gr_log_fs_generic(GR_DONT_AUDIT, GR_WRITLIB_ACL_MSG, filp->f_path.dentry, filp->f_path.mnt); |
50425a20 | 20667 | + return 1; |
20668 | + } | |
20669 | + } | |
20670 | + return 0; | |
20671 | +} | |
20672 | + | |
20673 | +int | |
20674 | +gr_acl_handle_mmap(const struct file *file, const unsigned long prot) | |
20675 | +{ | |
20676 | + __u32 mode; | |
20677 | + | |
20678 | + if (unlikely(!file || !(prot & PROT_EXEC))) | |
20679 | + return 1; | |
20680 | + | |
20681 | + if (is_writable_mmap(file)) | |
20682 | + return 0; | |
20683 | + | |
20684 | + mode = | |
4dee9bd5 | 20685 | + gr_search_file(file->f_path.dentry, |
50425a20 | 20686 | + GR_EXEC | GR_AUDIT_EXEC | GR_SUPPRESS, |
4dee9bd5 | 20687 | + file->f_path.mnt); |
50425a20 | 20688 | + |
20689 | + if (!gr_tpe_allow(file)) | |
20690 | + return 0; | |
20691 | + | |
20692 | + if (unlikely(!(mode & GR_EXEC) && !(mode & GR_SUPPRESS))) { | |
4dee9bd5 | 20693 | + gr_log_fs_rbac_generic(GR_DONT_AUDIT, GR_MMAP_ACL_MSG, file->f_path.dentry, file->f_path.mnt); |
50425a20 | 20694 | + return 0; |
20695 | + } else if (unlikely(!(mode & GR_EXEC))) { | |
20696 | + return 0; | |
20697 | + } else if (unlikely(mode & GR_EXEC && mode & GR_AUDIT_EXEC)) { | |
4dee9bd5 | 20698 | + gr_log_fs_rbac_generic(GR_DO_AUDIT, GR_MMAP_ACL_MSG, file->f_path.dentry, file->f_path.mnt); |
50425a20 | 20699 | + return 1; |
20700 | + } | |
20701 | + | |
20702 | + return 1; | |
20703 | +} | |
20704 | + | |
20705 | +int | |
20706 | +gr_acl_handle_mprotect(const struct file *file, const unsigned long prot) | |
20707 | +{ | |
20708 | + __u32 mode; | |
20709 | + | |
20710 | + if (unlikely(!file || !(prot & PROT_EXEC))) | |
20711 | + return 1; | |
20712 | + | |
20713 | + if (is_writable_mmap(file)) | |
20714 | + return 0; | |
20715 | + | |
20716 | + mode = | |
4dee9bd5 | 20717 | + gr_search_file(file->f_path.dentry, |
50425a20 | 20718 | + GR_EXEC | GR_AUDIT_EXEC | GR_SUPPRESS, |
4dee9bd5 | 20719 | + file->f_path.mnt); |
50425a20 | 20720 | + |
20721 | + if (!gr_tpe_allow(file)) | |
20722 | + return 0; | |
20723 | + | |
20724 | + if (unlikely(!(mode & GR_EXEC) && !(mode & GR_SUPPRESS))) { | |
4dee9bd5 | 20725 | + gr_log_fs_rbac_generic(GR_DONT_AUDIT, GR_MPROTECT_ACL_MSG, file->f_path.dentry, file->f_path.mnt); |
50425a20 | 20726 | + return 0; |
20727 | + } else if (unlikely(!(mode & GR_EXEC))) { | |
20728 | + return 0; | |
20729 | + } else if (unlikely(mode & GR_EXEC && mode & GR_AUDIT_EXEC)) { | |
4dee9bd5 | 20730 | + gr_log_fs_rbac_generic(GR_DO_AUDIT, GR_MPROTECT_ACL_MSG, file->f_path.dentry, file->f_path.mnt); |
50425a20 | 20731 | + return 1; |
20732 | + } | |
20733 | + | |
20734 | + return 1; | |
20735 | +} | |
20736 | + | |
20737 | +void | |
20738 | +gr_acl_handle_psacct(struct task_struct *task, const long code) | |
20739 | +{ | |
20740 | + unsigned long runtime; | |
20741 | + unsigned long cputime; | |
20742 | + unsigned int wday, cday; | |
20743 | + __u8 whr, chr; | |
20744 | + __u8 wmin, cmin; | |
20745 | + __u8 wsec, csec; | |
b2ee8b1e | 20746 | + struct timespec timeval; |
50425a20 | 20747 | + |
20748 | + if (unlikely(!(gr_status & GR_READY) || !task->acl || | |
20749 | + !(task->acl->mode & GR_PROCACCT))) | |
20750 | + return; | |
20751 | + | |
b2ee8b1e | 20752 | + do_posix_clock_monotonic_gettime(&timeval); |
20753 | + runtime = timeval.tv_sec - task->start_time.tv_sec; | |
50425a20 | 20754 | + wday = runtime / (3600 * 24); |
20755 | + runtime -= wday * (3600 * 24); | |
20756 | + whr = runtime / 3600; | |
20757 | + runtime -= whr * 3600; | |
20758 | + wmin = runtime / 60; | |
20759 | + runtime -= wmin * 60; | |
20760 | + wsec = runtime; | |
20761 | + | |
20762 | + cputime = (task->utime + task->stime) / HZ; | |
20763 | + cday = cputime / (3600 * 24); | |
20764 | + cputime -= cday * (3600 * 24); | |
20765 | + chr = cputime / 3600; | |
20766 | + cputime -= chr * 3600; | |
20767 | + cmin = cputime / 60; | |
20768 | + cputime -= cmin * 60; | |
20769 | + csec = cputime; | |
20770 | + | |
20771 | + gr_log_procacct(GR_DO_AUDIT, GR_ACL_PROCACCT_MSG, task, wday, whr, wmin, wsec, cday, chr, cmin, csec, code); | |
20772 | + | |
20773 | + return; | |
20774 | +} | |
20775 | + | |
20776 | +void gr_set_kernel_label(struct task_struct *task) | |
20777 | +{ | |
20778 | + if (gr_status & GR_READY) { | |
20779 | + task->role = kernel_role; | |
20780 | + task->acl = kernel_role->root_label; | |
20781 | + } | |
20782 | + return; | |
20783 | +} | |
20784 | + | |
20785 | +int gr_acl_handle_filldir(const struct file *file, const char *name, const unsigned int namelen, const ino_t ino) | |
20786 | +{ | |
20787 | + struct task_struct *task = current; | |
4dee9bd5 | 20788 | + struct dentry *dentry = file->f_path.dentry; |
20789 | + struct vfsmount *mnt = file->f_path.mnt; | |
50425a20 | 20790 | + struct acl_object_label *obj, *tmp; |
20791 | + struct acl_subject_label *subj; | |
20792 | + unsigned int bufsize; | |
20793 | + int is_not_root; | |
20794 | + char *path; | |
20795 | + | |
20796 | + if (unlikely(!(gr_status & GR_READY))) | |
20797 | + return 1; | |
20798 | + | |
20799 | + if (task->acl->mode & (GR_LEARN | GR_INHERITLEARN)) | |
20800 | + return 1; | |
20801 | + | |
f4251508 | 20802 | + /* ignore Eric Biederman */ |
20803 | + if (IS_PRIVATE(dentry->d_inode)) | |
20804 | + return 1; | |
20805 | + | |
50425a20 | 20806 | + subj = task->acl; |
20807 | + do { | |
20808 | + obj = lookup_acl_obj_label(ino, dentry->d_inode->i_sb->s_dev, subj); | |
20809 | + if (obj != NULL) | |
20810 | + return (obj->mode & GR_FIND) ? 1 : 0; | |
20811 | + } while ((subj = subj->parent_subject)); | |
20812 | + | |
20813 | + obj = chk_obj_label(dentry, mnt, task->acl); | |
20814 | + if (obj->globbed == NULL) | |
20815 | + return (obj->mode & GR_FIND) ? 1 : 0; | |
20816 | + | |
20817 | + is_not_root = ((obj->filename[0] == '/') && | |
20818 | + (obj->filename[1] == '\0')) ? 0 : 1; | |
20819 | + bufsize = PAGE_SIZE - namelen - is_not_root; | |
20820 | + | |
20821 | + /* check bufsize > PAGE_SIZE || bufsize == 0 */ | |
20822 | + if (unlikely((bufsize - 1) > (PAGE_SIZE - 1))) | |
20823 | + return 1; | |
20824 | + | |
20825 | + preempt_disable(); | |
20826 | + path = d_real_path(dentry, mnt, per_cpu_ptr(gr_shared_page[0], smp_processor_id()), | |
20827 | + bufsize); | |
20828 | + | |
20829 | + bufsize = strlen(path); | |
20830 | + | |
20831 | + /* if base is "/", don't append an additional slash */ | |
20832 | + if (is_not_root) | |
20833 | + *(path + bufsize) = '/'; | |
20834 | + memcpy(path + bufsize + is_not_root, name, namelen); | |
20835 | + *(path + bufsize + namelen + is_not_root) = '\0'; | |
20836 | + | |
20837 | + tmp = obj->globbed; | |
20838 | + while (tmp) { | |
20839 | + if (!glob_match(tmp->filename, path)) { | |
20840 | + preempt_enable(); | |
20841 | + return (tmp->mode & GR_FIND) ? 1 : 0; | |
20842 | + } | |
20843 | + tmp = tmp->next; | |
20844 | + } | |
20845 | + preempt_enable(); | |
20846 | + return (obj->mode & GR_FIND) ? 1 : 0; | |
20847 | +} | |
20848 | + | |
20849 | +EXPORT_SYMBOL(gr_learn_resource); | |
20850 | +EXPORT_SYMBOL(gr_set_kernel_label); | |
20851 | +#ifdef CONFIG_SECURITY | |
20852 | +EXPORT_SYMBOL(gr_check_user_change); | |
20853 | +EXPORT_SYMBOL(gr_check_group_change); | |
20854 | +#endif | |
20855 | + | |
4dee9bd5 | 20856 | diff -urNp linux-2.6.25.4/grsecurity/gracl_cap.c linux-2.6.25.4/grsecurity/gracl_cap.c |
20857 | --- linux-2.6.25.4/grsecurity/gracl_cap.c 1969-12-31 19:00:00.000000000 -0500 | |
20858 | +++ linux-2.6.25.4/grsecurity/gracl_cap.c 2008-05-18 13:33:16.000000000 -0400 | |
20859 | @@ -0,0 +1,129 @@ | |
50425a20 | 20860 | +#include <linux/kernel.h> |
20861 | +#include <linux/module.h> | |
20862 | +#include <linux/sched.h> | |
50425a20 | 20863 | +#include <linux/gracl.h> |
20864 | +#include <linux/grsecurity.h> | |
20865 | +#include <linux/grinternal.h> | |
20866 | + | |
20867 | +static const char *captab_log[] = { | |
20868 | + "CAP_CHOWN", | |
20869 | + "CAP_DAC_OVERRIDE", | |
20870 | + "CAP_DAC_READ_SEARCH", | |
20871 | + "CAP_FOWNER", | |
20872 | + "CAP_FSETID", | |
20873 | + "CAP_KILL", | |
20874 | + "CAP_SETGID", | |
20875 | + "CAP_SETUID", | |
20876 | + "CAP_SETPCAP", | |
20877 | + "CAP_LINUX_IMMUTABLE", | |
20878 | + "CAP_NET_BIND_SERVICE", | |
20879 | + "CAP_NET_BROADCAST", | |
20880 | + "CAP_NET_ADMIN", | |
20881 | + "CAP_NET_RAW", | |
20882 | + "CAP_IPC_LOCK", | |
20883 | + "CAP_IPC_OWNER", | |
20884 | + "CAP_SYS_MODULE", | |
20885 | + "CAP_SYS_RAWIO", | |
20886 | + "CAP_SYS_CHROOT", | |
20887 | + "CAP_SYS_PTRACE", | |
20888 | + "CAP_SYS_PACCT", | |
20889 | + "CAP_SYS_ADMIN", | |
20890 | + "CAP_SYS_BOOT", | |
20891 | + "CAP_SYS_NICE", | |
20892 | + "CAP_SYS_RESOURCE", | |
20893 | + "CAP_SYS_TIME", | |
20894 | + "CAP_SYS_TTY_CONFIG", | |
20895 | + "CAP_MKNOD", | |
8a4b4a5e | 20896 | + "CAP_LEASE", |
20897 | + "CAP_AUDIT_WRITE", | |
b7f09679 | 20898 | + "CAP_AUDIT_CONTROL", |
4dee9bd5 | 20899 | + "CAP_SETFCAP", |
20900 | + "CAP_MAC_OVERRIDE", | |
20901 | + "CAP_MAC_ADMIN" | |
50425a20 | 20902 | +}; |
20903 | + | |
20904 | +EXPORT_SYMBOL(gr_task_is_capable); | |
20905 | +EXPORT_SYMBOL(gr_is_capable_nolog); | |
20906 | + | |
20907 | +int | |
20908 | +gr_task_is_capable(struct task_struct *task, const int cap) | |
20909 | +{ | |
20910 | + struct acl_subject_label *curracl; | |
4dee9bd5 | 20911 | + kernel_cap_t cap_drop = __cap_empty_set, cap_mask = __cap_empty_set; |
50425a20 | 20912 | + |
20913 | + if (!gr_acl_is_enabled()) | |
20914 | + return 1; | |
20915 | + | |
20916 | + curracl = task->acl; | |
20917 | + | |
20918 | + cap_drop = curracl->cap_lower; | |
20919 | + cap_mask = curracl->cap_mask; | |
20920 | + | |
20921 | + while ((curracl = curracl->parent_subject)) { | |
4dee9bd5 | 20922 | + /* if the cap isn't specified in the current computed mask but is specified in the |
20923 | + current level subject, and is lowered in the current level subject, then add | |
20924 | + it to the set of dropped capabilities | |
20925 | + otherwise, add the current level subject's mask to the current computed mask | |
20926 | + */ | |
20927 | + if (!cap_raised(cap_mask, cap) && cap_raised(curracl->cap_mask, cap)) { | |
20928 | + cap_raise(cap_mask, cap); | |
20929 | + if (cap_raised(curracl->cap_lower, cap)) | |
20930 | + cap_raise(cap_drop, cap); | |
20931 | + } | |
50425a20 | 20932 | + } |
20933 | + | |
20934 | + if (!cap_raised(cap_drop, cap)) | |
20935 | + return 1; | |
20936 | + | |
20937 | + curracl = task->acl; | |
20938 | + | |
20939 | + if ((curracl->mode & (GR_LEARN | GR_INHERITLEARN)) | |
20940 | + && cap_raised(task->cap_effective, cap)) { | |
20941 | + security_learn(GR_LEARN_AUDIT_MSG, task->role->rolename, | |
20942 | + task->role->roletype, task->uid, | |
20943 | + task->gid, task->exec_file ? | |
4dee9bd5 | 20944 | + gr_to_filename(task->exec_file->f_path.dentry, |
20945 | + task->exec_file->f_path.mnt) : curracl->filename, | |
50425a20 | 20946 | + curracl->filename, 0UL, |
20947 | + 0UL, "", (unsigned long) cap, NIPQUAD(task->signal->curr_ip)); | |
20948 | + return 1; | |
20949 | + } | |
20950 | + | |
20951 | + if ((cap >= 0) && (cap < (sizeof(captab_log)/sizeof(captab_log[0]))) && cap_raised(task->cap_effective, cap)) | |
20952 | + gr_log_cap(GR_DONT_AUDIT, GR_CAP_ACL_MSG, task, captab_log[cap]); | |
20953 | + return 0; | |
20954 | +} | |
20955 | + | |
20956 | +int | |
20957 | +gr_is_capable_nolog(const int cap) | |
20958 | +{ | |
20959 | + struct acl_subject_label *curracl; | |
4dee9bd5 | 20960 | + kernel_cap_t cap_drop = __cap_empty_set, cap_mask = __cap_empty_set; |
50425a20 | 20961 | + |
20962 | + if (!gr_acl_is_enabled()) | |
20963 | + return 1; | |
20964 | + | |
20965 | + curracl = current->acl; | |
20966 | + | |
20967 | + cap_drop = curracl->cap_lower; | |
20968 | + cap_mask = curracl->cap_mask; | |
20969 | + | |
20970 | + while ((curracl = curracl->parent_subject)) { | |
4dee9bd5 | 20971 | + /* if the cap isn't specified in the current computed mask but is specified in the |
20972 | + current level subject, and is lowered in the current level subject, then add | |
20973 | + it to the set of dropped capabilities | |
20974 | + otherwise, add the current level subject's mask to the current computed mask | |
20975 | + */ | |
20976 | + if (!cap_raised(cap_mask, cap) && cap_raised(curracl->cap_mask, cap)) { | |
20977 | + cap_raise(cap_mask, cap); | |
20978 | + if (cap_raised(curracl->cap_lower, cap)) | |
20979 | + cap_raise(cap_drop, cap); | |
20980 | + } | |
50425a20 | 20981 | + } |
20982 | + | |
20983 | + if (!cap_raised(cap_drop, cap)) | |
20984 | + return 1; | |
20985 | + | |
20986 | + return 0; | |
20987 | +} | |
20988 | + | |
4dee9bd5 | 20989 | diff -urNp linux-2.6.25.4/grsecurity/gracl_fs.c linux-2.6.25.4/grsecurity/gracl_fs.c |
20990 | --- linux-2.6.25.4/grsecurity/gracl_fs.c 1969-12-31 19:00:00.000000000 -0500 | |
20991 | +++ linux-2.6.25.4/grsecurity/gracl_fs.c 2008-05-18 13:33:16.000000000 -0400 | |
50425a20 | 20992 | @@ -0,0 +1,423 @@ |
20993 | +#include <linux/kernel.h> | |
20994 | +#include <linux/sched.h> | |
20995 | +#include <linux/types.h> | |
20996 | +#include <linux/fs.h> | |
20997 | +#include <linux/file.h> | |
20998 | +#include <linux/stat.h> | |
20999 | +#include <linux/grsecurity.h> | |
21000 | +#include <linux/grinternal.h> | |
21001 | +#include <linux/gracl.h> | |
21002 | + | |
21003 | +__u32 | |
21004 | +gr_acl_handle_hidden_file(const struct dentry * dentry, | |
21005 | + const struct vfsmount * mnt) | |
21006 | +{ | |
21007 | + __u32 mode; | |
21008 | + | |
21009 | + if (unlikely(!dentry->d_inode)) | |
21010 | + return GR_FIND; | |
21011 | + | |
21012 | + mode = | |
21013 | + gr_search_file(dentry, GR_FIND | GR_AUDIT_FIND | GR_SUPPRESS, mnt); | |
21014 | + | |
21015 | + if (unlikely(mode & GR_FIND && mode & GR_AUDIT_FIND)) { | |
21016 | + gr_log_fs_rbac_generic(GR_DO_AUDIT, GR_HIDDEN_ACL_MSG, dentry, mnt); | |
21017 | + return mode; | |
21018 | + } else if (unlikely(!(mode & GR_FIND) && !(mode & GR_SUPPRESS))) { | |
21019 | + gr_log_fs_rbac_generic(GR_DONT_AUDIT, GR_HIDDEN_ACL_MSG, dentry, mnt); | |
21020 | + return 0; | |
21021 | + } else if (unlikely(!(mode & GR_FIND))) | |
21022 | + return 0; | |
21023 | + | |
21024 | + return GR_FIND; | |
21025 | +} | |
21026 | + | |
21027 | +__u32 | |
21028 | +gr_acl_handle_open(const struct dentry * dentry, const struct vfsmount * mnt, | |
21029 | + const int fmode) | |
21030 | +{ | |
21031 | + __u32 reqmode = GR_FIND; | |
21032 | + __u32 mode; | |
21033 | + | |
21034 | + if (unlikely(!dentry->d_inode)) | |
21035 | + return reqmode; | |
21036 | + | |
21037 | + if (unlikely(fmode & O_APPEND)) | |
21038 | + reqmode |= GR_APPEND; | |
21039 | + else if (unlikely(fmode & FMODE_WRITE)) | |
21040 | + reqmode |= GR_WRITE; | |
21041 | + if (likely((fmode & FMODE_READ) && !(fmode & O_DIRECTORY))) | |
21042 | + reqmode |= GR_READ; | |
21043 | + | |
21044 | + mode = | |
21045 | + gr_search_file(dentry, reqmode | to_gr_audit(reqmode) | GR_SUPPRESS, | |
21046 | + mnt); | |
21047 | + | |
21048 | + if (unlikely(((mode & reqmode) == reqmode) && mode & GR_AUDITS)) { | |
21049 | + gr_log_fs_rbac_mode2(GR_DO_AUDIT, GR_OPEN_ACL_MSG, dentry, mnt, | |
21050 | + reqmode & GR_READ ? " reading" : "", | |
21051 | + reqmode & GR_WRITE ? " writing" : reqmode & | |
21052 | + GR_APPEND ? " appending" : ""); | |
21053 | + return reqmode; | |
21054 | + } else | |
21055 | + if (unlikely((mode & reqmode) != reqmode && !(mode & GR_SUPPRESS))) | |
21056 | + { | |
21057 | + gr_log_fs_rbac_mode2(GR_DONT_AUDIT, GR_OPEN_ACL_MSG, dentry, mnt, | |
21058 | + reqmode & GR_READ ? " reading" : "", | |
21059 | + reqmode & GR_WRITE ? " writing" : reqmode & | |
21060 | + GR_APPEND ? " appending" : ""); | |
21061 | + return 0; | |
21062 | + } else if (unlikely((mode & reqmode) != reqmode)) | |
21063 | + return 0; | |
21064 | + | |
21065 | + return reqmode; | |
21066 | +} | |
21067 | + | |
21068 | +__u32 | |
21069 | +gr_acl_handle_creat(const struct dentry * dentry, | |
21070 | + const struct dentry * p_dentry, | |
21071 | + const struct vfsmount * p_mnt, const int fmode, | |
21072 | + const int imode) | |
21073 | +{ | |
21074 | + __u32 reqmode = GR_WRITE | GR_CREATE; | |
21075 | + __u32 mode; | |
21076 | + | |
21077 | + if (unlikely(fmode & O_APPEND)) | |
21078 | + reqmode |= GR_APPEND; | |
21079 | + if (unlikely((fmode & FMODE_READ) && !(fmode & O_DIRECTORY))) | |
21080 | + reqmode |= GR_READ; | |
21081 | + if (unlikely((fmode & O_CREAT) && (imode & (S_ISUID | S_ISGID)))) | |
21082 | + reqmode |= GR_SETID; | |
21083 | + | |
21084 | + mode = | |
21085 | + gr_check_create(dentry, p_dentry, p_mnt, | |
21086 | + reqmode | to_gr_audit(reqmode) | GR_SUPPRESS); | |
21087 | + | |
21088 | + if (unlikely(((mode & reqmode) == reqmode) && mode & GR_AUDITS)) { | |
21089 | + gr_log_fs_rbac_mode2(GR_DO_AUDIT, GR_CREATE_ACL_MSG, dentry, p_mnt, | |
21090 | + reqmode & GR_READ ? " reading" : "", | |
21091 | + reqmode & GR_WRITE ? " writing" : reqmode & | |
21092 | + GR_APPEND ? " appending" : ""); | |
21093 | + return reqmode; | |
21094 | + } else | |
21095 | + if (unlikely((mode & reqmode) != reqmode && !(mode & GR_SUPPRESS))) | |
21096 | + { | |
21097 | + gr_log_fs_rbac_mode2(GR_DONT_AUDIT, GR_CREATE_ACL_MSG, dentry, p_mnt, | |
21098 | + reqmode & GR_READ ? " reading" : "", | |
21099 | + reqmode & GR_WRITE ? " writing" : reqmode & | |
21100 | + GR_APPEND ? " appending" : ""); | |
21101 | + return 0; | |
21102 | + } else if (unlikely((mode & reqmode) != reqmode)) | |
21103 | + return 0; | |
21104 | + | |
21105 | + return reqmode; | |
21106 | +} | |
21107 | + | |
21108 | +__u32 | |
21109 | +gr_acl_handle_access(const struct dentry * dentry, const struct vfsmount * mnt, | |
21110 | + const int fmode) | |
21111 | +{ | |
21112 | + __u32 mode, reqmode = GR_FIND; | |
21113 | + | |
21114 | + if ((fmode & S_IXOTH) && !S_ISDIR(dentry->d_inode->i_mode)) | |
21115 | + reqmode |= GR_EXEC; | |
21116 | + if (fmode & S_IWOTH) | |
21117 | + reqmode |= GR_WRITE; | |
21118 | + if (fmode & S_IROTH) | |
21119 | + reqmode |= GR_READ; | |
21120 | + | |
21121 | + mode = | |
21122 | + gr_search_file(dentry, reqmode | to_gr_audit(reqmode) | GR_SUPPRESS, | |
21123 | + mnt); | |
21124 | + | |
21125 | + if (unlikely(((mode & reqmode) == reqmode) && mode & GR_AUDITS)) { | |
21126 | + gr_log_fs_rbac_mode3(GR_DO_AUDIT, GR_ACCESS_ACL_MSG, dentry, mnt, | |
21127 | + reqmode & GR_READ ? " reading" : "", | |
21128 | + reqmode & GR_WRITE ? " writing" : "", | |
21129 | + reqmode & GR_EXEC ? " executing" : ""); | |
21130 | + return reqmode; | |
21131 | + } else | |
21132 | + if (unlikely((mode & reqmode) != reqmode && !(mode & GR_SUPPRESS))) | |
21133 | + { | |
21134 | + gr_log_fs_rbac_mode3(GR_DONT_AUDIT, GR_ACCESS_ACL_MSG, dentry, mnt, | |
21135 | + reqmode & GR_READ ? " reading" : "", | |
21136 | + reqmode & GR_WRITE ? " writing" : "", | |
21137 | + reqmode & GR_EXEC ? " executing" : ""); | |
21138 | + return 0; | |
21139 | + } else if (unlikely((mode & reqmode) != reqmode)) | |
21140 | + return 0; | |
21141 | + | |
21142 | + return reqmode; | |
21143 | +} | |
21144 | + | |
21145 | +static __u32 generic_fs_handler(const struct dentry *dentry, const struct vfsmount *mnt, __u32 reqmode, const char *fmt) | |
21146 | +{ | |
21147 | + __u32 mode; | |
21148 | + | |
21149 | + mode = gr_search_file(dentry, reqmode | to_gr_audit(reqmode) | GR_SUPPRESS, mnt); | |
21150 | + | |
21151 | + if (unlikely(((mode & (reqmode)) == (reqmode)) && mode & GR_AUDITS)) { | |
21152 | + gr_log_fs_rbac_generic(GR_DO_AUDIT, fmt, dentry, mnt); | |
21153 | + return mode; | |
21154 | + } else if (unlikely((mode & (reqmode)) != (reqmode) && !(mode & GR_SUPPRESS))) { | |
21155 | + gr_log_fs_rbac_generic(GR_DONT_AUDIT, fmt, dentry, mnt); | |
21156 | + return 0; | |
21157 | + } else if (unlikely((mode & (reqmode)) != (reqmode))) | |
21158 | + return 0; | |
21159 | + | |
21160 | + return (reqmode); | |
21161 | +} | |
21162 | + | |
21163 | +__u32 | |
21164 | +gr_acl_handle_rmdir(const struct dentry * dentry, const struct vfsmount * mnt) | |
21165 | +{ | |
21166 | + return generic_fs_handler(dentry, mnt, GR_WRITE | GR_DELETE , GR_RMDIR_ACL_MSG); | |
21167 | +} | |
21168 | + | |
21169 | +__u32 | |
21170 | +gr_acl_handle_unlink(const struct dentry *dentry, const struct vfsmount *mnt) | |
21171 | +{ | |
21172 | + return generic_fs_handler(dentry, mnt, GR_WRITE | GR_DELETE , GR_UNLINK_ACL_MSG); | |
21173 | +} | |
21174 | + | |
21175 | +__u32 | |
21176 | +gr_acl_handle_truncate(const struct dentry *dentry, const struct vfsmount *mnt) | |
21177 | +{ | |
21178 | + return generic_fs_handler(dentry, mnt, GR_WRITE, GR_TRUNCATE_ACL_MSG); | |
21179 | +} | |
21180 | + | |
21181 | +__u32 | |
21182 | +gr_acl_handle_utime(const struct dentry *dentry, const struct vfsmount *mnt) | |
21183 | +{ | |
21184 | + return generic_fs_handler(dentry, mnt, GR_WRITE, GR_ATIME_ACL_MSG); | |
21185 | +} | |
21186 | + | |
21187 | +__u32 | |
21188 | +gr_acl_handle_fchmod(const struct dentry *dentry, const struct vfsmount *mnt, | |
21189 | + mode_t mode) | |
21190 | +{ | |
21191 | + if (unlikely(dentry->d_inode && S_ISSOCK(dentry->d_inode->i_mode))) | |
21192 | + return 1; | |
21193 | + | |
21194 | + if (unlikely((mode != (mode_t)-1) && (mode & (S_ISUID | S_ISGID)))) { | |
21195 | + return generic_fs_handler(dentry, mnt, GR_WRITE | GR_SETID, | |
21196 | + GR_FCHMOD_ACL_MSG); | |
21197 | + } else { | |
21198 | + return generic_fs_handler(dentry, mnt, GR_WRITE, GR_FCHMOD_ACL_MSG); | |
21199 | + } | |
21200 | +} | |
21201 | + | |
21202 | +__u32 | |
21203 | +gr_acl_handle_chmod(const struct dentry *dentry, const struct vfsmount *mnt, | |
21204 | + mode_t mode) | |
21205 | +{ | |
21206 | + if (unlikely((mode != (mode_t)-1) && (mode & (S_ISUID | S_ISGID)))) { | |
21207 | + return generic_fs_handler(dentry, mnt, GR_WRITE | GR_SETID, | |
21208 | + GR_CHMOD_ACL_MSG); | |
21209 | + } else { | |
21210 | + return generic_fs_handler(dentry, mnt, GR_WRITE, GR_CHMOD_ACL_MSG); | |
21211 | + } | |
21212 | +} | |
21213 | + | |
21214 | +__u32 | |
21215 | +gr_acl_handle_chown(const struct dentry *dentry, const struct vfsmount *mnt) | |
21216 | +{ | |
21217 | + return generic_fs_handler(dentry, mnt, GR_WRITE, GR_CHOWN_ACL_MSG); | |
21218 | +} | |
21219 | + | |
21220 | +__u32 | |
21221 | +gr_acl_handle_execve(const struct dentry *dentry, const struct vfsmount *mnt) | |
21222 | +{ | |
21223 | + return generic_fs_handler(dentry, mnt, GR_EXEC, GR_EXEC_ACL_MSG); | |
21224 | +} | |
21225 | + | |
21226 | +__u32 | |
21227 | +gr_acl_handle_unix(const struct dentry *dentry, const struct vfsmount *mnt) | |
21228 | +{ | |
21229 | + return generic_fs_handler(dentry, mnt, GR_READ | GR_WRITE, | |
21230 | + GR_UNIXCONNECT_ACL_MSG); | |
21231 | +} | |
21232 | + | |
21233 | +/* hardlinks require at minimum create permission, | |
21234 | + any additional privilege required is based on the | |
21235 | + privilege of the file being linked to | |
21236 | +*/ | |
21237 | +__u32 | |
21238 | +gr_acl_handle_link(const struct dentry * new_dentry, | |
21239 | + const struct dentry * parent_dentry, | |
21240 | + const struct vfsmount * parent_mnt, | |
21241 | + const struct dentry * old_dentry, | |
21242 | + const struct vfsmount * old_mnt, const char *to) | |
21243 | +{ | |
21244 | + __u32 mode; | |
21245 | + __u32 needmode = GR_CREATE | GR_LINK; | |
21246 | + __u32 needaudit = GR_AUDIT_CREATE | GR_AUDIT_LINK; | |
21247 | + | |
21248 | + mode = | |
21249 | + gr_check_link(new_dentry, parent_dentry, parent_mnt, old_dentry, | |
21250 | + old_mnt); | |
21251 | + | |
21252 | + if (unlikely(((mode & needmode) == needmode) && (mode & needaudit))) { | |
21253 | + gr_log_fs_rbac_str(GR_DO_AUDIT, GR_LINK_ACL_MSG, old_dentry, old_mnt, to); | |
21254 | + return mode; | |
21255 | + } else if (unlikely(((mode & needmode) != needmode) && !(mode & GR_SUPPRESS))) { | |
21256 | + gr_log_fs_rbac_str(GR_DONT_AUDIT, GR_LINK_ACL_MSG, old_dentry, old_mnt, to); | |
21257 | + return 0; | |
21258 | + } else if (unlikely((mode & needmode) != needmode)) | |
21259 | + return 0; | |
21260 | + | |
21261 | + return 1; | |
21262 | +} | |
21263 | + | |
21264 | +__u32 | |
21265 | +gr_acl_handle_symlink(const struct dentry * new_dentry, | |
21266 | + const struct dentry * parent_dentry, | |
21267 | + const struct vfsmount * parent_mnt, const char *from) | |
21268 | +{ | |
21269 | + __u32 needmode = GR_WRITE | GR_CREATE; | |
21270 | + __u32 mode; | |
21271 | + | |
21272 | + mode = | |
21273 | + gr_check_create(new_dentry, parent_dentry, parent_mnt, | |
21274 | + GR_CREATE | GR_AUDIT_CREATE | | |
21275 | + GR_WRITE | GR_AUDIT_WRITE | GR_SUPPRESS); | |
21276 | + | |
21277 | + if (unlikely(mode & GR_WRITE && mode & GR_AUDITS)) { | |
21278 | + gr_log_fs_str_rbac(GR_DO_AUDIT, GR_SYMLINK_ACL_MSG, from, new_dentry, parent_mnt); | |
21279 | + return mode; | |
21280 | + } else if (unlikely(((mode & needmode) != needmode) && !(mode & GR_SUPPRESS))) { | |
21281 | + gr_log_fs_str_rbac(GR_DONT_AUDIT, GR_SYMLINK_ACL_MSG, from, new_dentry, parent_mnt); | |
21282 | + return 0; | |
21283 | + } else if (unlikely((mode & needmode) != needmode)) | |
21284 | + return 0; | |
21285 | + | |
21286 | + return (GR_WRITE | GR_CREATE); | |
21287 | +} | |
21288 | + | |
21289 | +static __u32 generic_fs_create_handler(const struct dentry *new_dentry, const struct dentry *parent_dentry, const struct vfsmount *parent_mnt, __u32 reqmode, const char *fmt) | |
21290 | +{ | |
21291 | + __u32 mode; | |
21292 | + | |
21293 | + mode = gr_check_create(new_dentry, parent_dentry, parent_mnt, reqmode | to_gr_audit(reqmode) | GR_SUPPRESS); | |
21294 | + | |
21295 | + if (unlikely(((mode & (reqmode)) == (reqmode)) && mode & GR_AUDITS)) { | |
21296 | + gr_log_fs_rbac_generic(GR_DO_AUDIT, fmt, new_dentry, parent_mnt); | |
21297 | + return mode; | |
21298 | + } else if (unlikely((mode & (reqmode)) != (reqmode) && !(mode & GR_SUPPRESS))) { | |
21299 | + gr_log_fs_rbac_generic(GR_DONT_AUDIT, fmt, new_dentry, parent_mnt); | |
21300 | + return 0; | |
21301 | + } else if (unlikely((mode & (reqmode)) != (reqmode))) | |
21302 | + return 0; | |
21303 | + | |
21304 | + return (reqmode); | |
21305 | +} | |
21306 | + | |
21307 | +__u32 | |
21308 | +gr_acl_handle_mknod(const struct dentry * new_dentry, | |
21309 | + const struct dentry * parent_dentry, | |
21310 | + const struct vfsmount * parent_mnt, | |
21311 | + const int mode) | |
21312 | +{ | |
21313 | + __u32 reqmode = GR_WRITE | GR_CREATE; | |
21314 | + if (unlikely(mode & (S_ISUID | S_ISGID))) | |
21315 | + reqmode |= GR_SETID; | |
21316 | + | |
21317 | + return generic_fs_create_handler(new_dentry, parent_dentry, parent_mnt, | |
21318 | + reqmode, GR_MKNOD_ACL_MSG); | |
21319 | +} | |
21320 | + | |
21321 | +__u32 | |
21322 | +gr_acl_handle_mkdir(const struct dentry *new_dentry, | |
21323 | + const struct dentry *parent_dentry, | |
21324 | + const struct vfsmount *parent_mnt) | |
21325 | +{ | |
21326 | + return generic_fs_create_handler(new_dentry, parent_dentry, parent_mnt, | |
21327 | + GR_WRITE | GR_CREATE, GR_MKDIR_ACL_MSG); | |
21328 | +} | |
21329 | + | |
21330 | +#define RENAME_CHECK_SUCCESS(old, new) \ | |
21331 | + (((old & (GR_WRITE | GR_READ)) == (GR_WRITE | GR_READ)) && \ | |
21332 | + ((new & (GR_WRITE | GR_READ)) == (GR_WRITE | GR_READ))) | |
21333 | + | |
21334 | +int | |
21335 | +gr_acl_handle_rename(struct dentry *new_dentry, | |
21336 | + struct dentry *parent_dentry, | |
21337 | + const struct vfsmount *parent_mnt, | |
21338 | + struct dentry *old_dentry, | |
21339 | + struct inode *old_parent_inode, | |
21340 | + struct vfsmount *old_mnt, const char *newname) | |
21341 | +{ | |
21342 | + __u32 comp1, comp2; | |
21343 | + int error = 0; | |
21344 | + | |
21345 | + if (unlikely(!gr_acl_is_enabled())) | |
21346 | + return 0; | |
21347 | + | |
21348 | + if (!new_dentry->d_inode) { | |
21349 | + comp1 = gr_check_create(new_dentry, parent_dentry, parent_mnt, | |
21350 | + GR_READ | GR_WRITE | GR_CREATE | GR_AUDIT_READ | | |
21351 | + GR_AUDIT_WRITE | GR_AUDIT_CREATE | GR_SUPPRESS); | |
21352 | + comp2 = gr_search_file(old_dentry, GR_READ | GR_WRITE | | |
21353 | + GR_DELETE | GR_AUDIT_DELETE | | |
21354 | + GR_AUDIT_READ | GR_AUDIT_WRITE | | |
21355 | + GR_SUPPRESS, old_mnt); | |
21356 | + } else { | |
21357 | + comp1 = gr_search_file(new_dentry, GR_READ | GR_WRITE | | |
21358 | + GR_CREATE | GR_DELETE | | |
21359 | + GR_AUDIT_CREATE | GR_AUDIT_DELETE | | |
21360 | + GR_AUDIT_READ | GR_AUDIT_WRITE | | |
21361 | + GR_SUPPRESS, parent_mnt); | |
21362 | + comp2 = | |
21363 | + gr_search_file(old_dentry, | |
21364 | + GR_READ | GR_WRITE | GR_AUDIT_READ | | |
21365 | + GR_DELETE | GR_AUDIT_DELETE | | |
21366 | + GR_AUDIT_WRITE | GR_SUPPRESS, old_mnt); | |
21367 | + } | |
21368 | + | |
21369 | + if (RENAME_CHECK_SUCCESS(comp1, comp2) && | |
21370 | + ((comp1 & GR_AUDITS) || (comp2 & GR_AUDITS))) | |
21371 | + gr_log_fs_rbac_str(GR_DO_AUDIT, GR_RENAME_ACL_MSG, old_dentry, old_mnt, newname); | |
21372 | + else if (!RENAME_CHECK_SUCCESS(comp1, comp2) && !(comp1 & GR_SUPPRESS) | |
21373 | + && !(comp2 & GR_SUPPRESS)) { | |
21374 | + gr_log_fs_rbac_str(GR_DONT_AUDIT, GR_RENAME_ACL_MSG, old_dentry, old_mnt, newname); | |
21375 | + error = -EACCES; | |
21376 | + } else if (unlikely(!RENAME_CHECK_SUCCESS(comp1, comp2))) | |
21377 | + error = -EACCES; | |
21378 | + | |
21379 | + return error; | |
21380 | +} | |
21381 | + | |
21382 | +void | |
21383 | +gr_acl_handle_exit(void) | |
21384 | +{ | |
21385 | + u16 id; | |
21386 | + char *rolename; | |
21387 | + struct file *exec_file; | |
21388 | + | |
21389 | + if (unlikely(current->acl_sp_role && gr_acl_is_enabled())) { | |
21390 | + id = current->acl_role_id; | |
21391 | + rolename = current->role->rolename; | |
21392 | + gr_set_acls(1); | |
21393 | + gr_log_str_int(GR_DONT_AUDIT_GOOD, GR_SPROLEL_ACL_MSG, rolename, id); | |
21394 | + } | |
21395 | + | |
21396 | + write_lock(&grsec_exec_file_lock); | |
21397 | + exec_file = current->exec_file; | |
21398 | + current->exec_file = NULL; | |
21399 | + write_unlock(&grsec_exec_file_lock); | |
21400 | + | |
21401 | + if (exec_file) | |
21402 | + fput(exec_file); | |
21403 | +} | |
21404 | + | |
21405 | +int | |
21406 | +gr_acl_handle_procpidmem(const struct task_struct *task) | |
21407 | +{ | |
21408 | + if (unlikely(!gr_acl_is_enabled())) | |
21409 | + return 0; | |
21410 | + | |
b7f09679 | 21411 | + if (task != current && task->acl->mode & GR_PROTPROCFD) |
50425a20 | 21412 | + return -EACCES; |
21413 | + | |
21414 | + return 0; | |
21415 | +} | |
4dee9bd5 | 21416 | diff -urNp linux-2.6.25.4/grsecurity/gracl_ip.c linux-2.6.25.4/grsecurity/gracl_ip.c |
21417 | --- linux-2.6.25.4/grsecurity/gracl_ip.c 1969-12-31 19:00:00.000000000 -0500 | |
21418 | +++ linux-2.6.25.4/grsecurity/gracl_ip.c 2008-05-18 13:33:16.000000000 -0400 | |
50425a20 | 21419 | @@ -0,0 +1,313 @@ |
21420 | +#include <linux/kernel.h> | |
21421 | +#include <asm/uaccess.h> | |
21422 | +#include <asm/errno.h> | |
21423 | +#include <net/sock.h> | |
21424 | +#include <linux/file.h> | |
21425 | +#include <linux/fs.h> | |
21426 | +#include <linux/net.h> | |
21427 | +#include <linux/in.h> | |
21428 | +#include <linux/skbuff.h> | |
21429 | +#include <linux/ip.h> | |
21430 | +#include <linux/udp.h> | |
21431 | +#include <linux/smp_lock.h> | |
21432 | +#include <linux/types.h> | |
21433 | +#include <linux/sched.h> | |
21434 | +#include <linux/netdevice.h> | |
21435 | +#include <linux/inetdevice.h> | |
21436 | +#include <linux/gracl.h> | |
21437 | +#include <linux/grsecurity.h> | |
21438 | +#include <linux/grinternal.h> | |
21439 | + | |
21440 | +#define GR_BIND 0x01 | |
21441 | +#define GR_CONNECT 0x02 | |
21442 | +#define GR_INVERT 0x04 | |
21443 | + | |
21444 | +static const char * gr_protocols[256] = { | |
21445 | + "ip", "icmp", "igmp", "ggp", "ipencap", "st", "tcp", "cbt", | |
21446 | + "egp", "igp", "bbn-rcc", "nvp", "pup", "argus", "emcon", "xnet", | |
21447 | + "chaos", "udp", "mux", "dcn", "hmp", "prm", "xns-idp", "trunk-1", | |
21448 | + "trunk-2", "leaf-1", "leaf-2", "rdp", "irtp", "iso-tp4", "netblt", "mfe-nsp", | |
21449 | + "merit-inp", "sep", "3pc", "idpr", "xtp", "ddp", "idpr-cmtp", "tp++", | |
21450 | + "il", "ipv6", "sdrp", "ipv6-route", "ipv6-frag", "idrp", "rsvp", "gre", | |
21451 | + "mhrp", "bna", "ipv6-crypt", "ipv6-auth", "i-nlsp", "swipe", "narp", "mobile", | |
21452 | + "tlsp", "skip", "ipv6-icmp", "ipv6-nonxt", "ipv6-opts", "unknown:61", "cftp", "unknown:63", | |
21453 | + "sat-expak", "kryptolan", "rvd", "ippc", "unknown:68", "sat-mon", "visa", "ipcv", | |
21454 | + "cpnx", "cphb", "wsn", "pvp", "br-sat-mon", "sun-nd", "wb-mon", "wb-expak", | |
21455 | + "iso-ip", "vmtp", "secure-vmtp", "vines", "ttp", "nfsnet-igp", "dgp", "tcf", | |
21456 | + "eigrp", "ospf", "sprite-rpc", "larp", "mtp", "ax.25", "ipip", "micp", | |
21457 | + "scc-sp", "etherip", "encap", "unknown:99", "gmtp", "ifmp", "pnni", "pim", | |
21458 | + "aris", "scps", "qnx", "a/n", "ipcomp", "snp", "compaq-peer", "ipx-in-ip", | |
21459 | + "vrrp", "pgm", "unknown:114", "l2tp", "ddx", "iatp", "stp", "srp", | |
21460 | + "uti", "smp", "sm", "ptp", "isis", "fire", "crtp", "crdup", | |
21461 | + "sscopmce", "iplt", "sps", "pipe", "sctp", "fc", "unkown:134", "unknown:135", | |
21462 | + "unknown:136", "unknown:137", "unknown:138", "unknown:139", "unknown:140", "unknown:141", "unknown:142", "unknown:143", | |
21463 | + "unknown:144", "unknown:145", "unknown:146", "unknown:147", "unknown:148", "unknown:149", "unknown:150", "unknown:151", | |
21464 | + "unknown:152", "unknown:153", "unknown:154", "unknown:155", "unknown:156", "unknown:157", "unknown:158", "unknown:159", | |
21465 | + "unknown:160", "unknown:161", "unknown:162", "unknown:163", "unknown:164", "unknown:165", "unknown:166", "unknown:167", | |
21466 | + "unknown:168", "unknown:169", "unknown:170", "unknown:171", "unknown:172", "unknown:173", "unknown:174", "unknown:175", | |
21467 | + "unknown:176", "unknown:177", "unknown:178", "unknown:179", "unknown:180", "unknown:181", "unknown:182", "unknown:183", | |
21468 | + "unknown:184", "unknown:185", "unknown:186", "unknown:187", "unknown:188", "unknown:189", "unknown:190", "unknown:191", | |
21469 | + "unknown:192", "unknown:193", "unknown:194", "unknown:195", "unknown:196", "unknown:197", "unknown:198", "unknown:199", | |
21470 | + "unknown:200", "unknown:201", "unknown:202", "unknown:203", "unknown:204", "unknown:205", "unknown:206", "unknown:207", | |
21471 | + "unknown:208", "unknown:209", "unknown:210", "unknown:211", "unknown:212", "unknown:213", "unknown:214", "unknown:215", | |
21472 | + "unknown:216", "unknown:217", "unknown:218", "unknown:219", "unknown:220", "unknown:221", "unknown:222", "unknown:223", | |
21473 | + "unknown:224", "unknown:225", "unknown:226", "unknown:227", "unknown:228", "unknown:229", "unknown:230", "unknown:231", | |
21474 | + "unknown:232", "unknown:233", "unknown:234", "unknown:235", "unknown:236", "unknown:237", "unknown:238", "unknown:239", | |
21475 | + "unknown:240", "unknown:241", "unknown:242", "unknown:243", "unknown:244", "unknown:245", "unknown:246", "unknown:247", | |
21476 | + "unknown:248", "unknown:249", "unknown:250", "unknown:251", "unknown:252", "unknown:253", "unknown:254", "unknown:255", | |
21477 | + }; | |
21478 | + | |
21479 | +static const char * gr_socktypes[11] = { | |
21480 | + "unknown:0", "stream", "dgram", "raw", "rdm", "seqpacket", "unknown:6", | |
21481 | + "unknown:7", "unknown:8", "unknown:9", "packet" | |
21482 | + }; | |
21483 | + | |
21484 | +const char * | |
21485 | +gr_proto_to_name(unsigned char proto) | |
21486 | +{ | |
21487 | + return gr_protocols[proto]; | |
21488 | +} | |
21489 | + | |
21490 | +const char * | |
21491 | +gr_socktype_to_name(unsigned char type) | |
21492 | +{ | |
21493 | + return gr_socktypes[type]; | |
21494 | +} | |
21495 | + | |
21496 | +int | |
21497 | +gr_search_socket(const int domain, const int type, const int protocol) | |
21498 | +{ | |
21499 | + struct acl_subject_label *curr; | |
21500 | + | |
21501 | + if (unlikely(!gr_acl_is_enabled())) | |
21502 | + goto exit; | |
21503 | + | |
21504 | + if ((domain < 0) || (type < 0) || (protocol < 0) || (domain != PF_INET) | |
21505 | + || (domain >= NPROTO) || (type >= SOCK_MAX) || (protocol > 255)) | |
21506 | + goto exit; // let the kernel handle it | |
21507 | + | |
21508 | + curr = current->acl; | |
21509 | + | |
21510 | + if (!curr->ips) | |
21511 | + goto exit; | |
21512 | + | |
21513 | + if ((curr->ip_type & (1 << type)) && | |
21514 | + (curr->ip_proto[protocol / 32] & (1 << (protocol % 32)))) | |
21515 | + goto exit; | |
21516 | + | |
21517 | + if (curr->mode & (GR_LEARN | GR_INHERITLEARN)) { | |
21518 | + /* we don't place acls on raw sockets , and sometimes | |
21519 | + dgram/ip sockets are opened for ioctl and not | |
21520 | + bind/connect, so we'll fake a bind learn log */ | |
21521 | + if (type == SOCK_RAW || type == SOCK_PACKET) { | |
21522 | + __u32 fakeip = 0; | |
21523 | + security_learn(GR_IP_LEARN_MSG, current->role->rolename, | |
21524 | + current->role->roletype, current->uid, | |
21525 | + current->gid, current->exec_file ? | |
4dee9bd5 | 21526 | + gr_to_filename(current->exec_file->f_path.dentry, |
21527 | + current->exec_file->f_path.mnt) : | |
50425a20 | 21528 | + curr->filename, curr->filename, |
21529 | + NIPQUAD(fakeip), 0, type, | |
21530 | + protocol, GR_CONNECT, | |
21531 | +NIPQUAD(current->signal->curr_ip)); | |
21532 | + } else if ((type == SOCK_DGRAM) && (protocol == IPPROTO_IP)) { | |
21533 | + __u32 fakeip = 0; | |
21534 | + security_learn(GR_IP_LEARN_MSG, current->role->rolename, | |
21535 | + current->role->roletype, current->uid, | |
21536 | + current->gid, current->exec_file ? | |
4dee9bd5 | 21537 | + gr_to_filename(current->exec_file->f_path.dentry, |
21538 | + current->exec_file->f_path.mnt) : | |
50425a20 | 21539 | + curr->filename, curr->filename, |
21540 | + NIPQUAD(fakeip), 0, type, | |
21541 | + protocol, GR_BIND, NIPQUAD(current->signal->curr_ip)); | |
21542 | + } | |
21543 | + /* we'll log when they use connect or bind */ | |
21544 | + goto exit; | |
21545 | + } | |
21546 | + | |
21547 | + gr_log_str3(GR_DONT_AUDIT, GR_SOCK_MSG, "inet", | |
21548 | + gr_socktype_to_name(type), gr_proto_to_name(protocol)); | |
21549 | + | |
21550 | + return 0; | |
21551 | + exit: | |
21552 | + return 1; | |
21553 | +} | |
21554 | + | |
21555 | +int check_ip_policy(struct acl_ip_label *ip, __u32 ip_addr, __u16 ip_port, __u8 protocol, const int mode, const int type, __u32 our_addr, __u32 our_netmask) | |
21556 | +{ | |
21557 | + if ((ip->mode & mode) && | |
21558 | + (ip_port >= ip->low) && | |
21559 | + (ip_port <= ip->high) && | |
21560 | + ((ntohl(ip_addr) & our_netmask) == | |
21561 | + (ntohl(our_addr) & our_netmask)) | |
21562 | + && (ip->proto[protocol / 32] & (1 << (protocol % 32))) | |
21563 | + && (ip->type & (1 << type))) { | |
21564 | + if (ip->mode & GR_INVERT) | |
21565 | + return 2; // specifically denied | |
21566 | + else | |
21567 | + return 1; // allowed | |
21568 | + } | |
21569 | + | |
21570 | + return 0; // not specifically allowed, may continue parsing | |
21571 | +} | |
21572 | + | |
21573 | +static int | |
21574 | +gr_search_connectbind(const int mode, const struct sock *sk, | |
21575 | + const struct sockaddr_in *addr, const int type) | |
21576 | +{ | |
21577 | + char iface[IFNAMSIZ] = {0}; | |
21578 | + struct acl_subject_label *curr; | |
21579 | + struct acl_ip_label *ip; | |
21580 | + struct net_device *dev; | |
21581 | + struct in_device *idev; | |
21582 | + unsigned long i; | |
21583 | + int ret; | |
21584 | + __u32 ip_addr = 0; | |
21585 | + __u32 our_addr; | |
21586 | + __u32 our_netmask; | |
21587 | + char *p; | |
21588 | + __u16 ip_port = 0; | |
21589 | + | |
21590 | + if (unlikely(!gr_acl_is_enabled() || sk->sk_family != PF_INET)) | |
21591 | + return 1; | |
21592 | + | |
21593 | + curr = current->acl; | |
21594 | + | |
21595 | + if (!curr->ips) | |
21596 | + return 1; | |
21597 | + | |
21598 | + ip_addr = addr->sin_addr.s_addr; | |
21599 | + ip_port = ntohs(addr->sin_port); | |
21600 | + | |
21601 | + if (curr->mode & (GR_LEARN | GR_INHERITLEARN)) { | |
21602 | + security_learn(GR_IP_LEARN_MSG, current->role->rolename, | |
21603 | + current->role->roletype, current->uid, | |
21604 | + current->gid, current->exec_file ? | |
4dee9bd5 | 21605 | + gr_to_filename(current->exec_file->f_path.dentry, |
21606 | + current->exec_file->f_path.mnt) : | |
50425a20 | 21607 | + curr->filename, curr->filename, |
21608 | + NIPQUAD(ip_addr), ip_port, type, | |
21609 | + sk->sk_protocol, mode, NIPQUAD(current->signal->curr_ip)); | |
21610 | + return 1; | |
21611 | + } | |
21612 | + | |
21613 | + for (i = 0; i < curr->ip_num; i++) { | |
21614 | + ip = *(curr->ips + i); | |
21615 | + if (ip->iface != NULL) { | |
21616 | + strncpy(iface, ip->iface, IFNAMSIZ - 1); | |
21617 | + p = strchr(iface, ':'); | |
21618 | + if (p != NULL) | |
21619 | + *p = '\0'; | |
da5b3fc8 | 21620 | + dev = dev_get_by_name(sk->sk_net, iface); |
50425a20 | 21621 | + if (dev == NULL) |
21622 | + continue; | |
21623 | + idev = in_dev_get(dev); | |
21624 | + if (idev == NULL) { | |
21625 | + dev_put(dev); | |
21626 | + continue; | |
21627 | + } | |
21628 | + rcu_read_lock(); | |
21629 | + for_ifa(idev) { | |
21630 | + if (!strcmp(ip->iface, ifa->ifa_label)) { | |
21631 | + our_addr = ifa->ifa_address; | |
21632 | + our_netmask = 0xffffffff; | |
21633 | + ret = check_ip_policy(ip, ip_addr, ip_port, sk->sk_protocol, mode, type, our_addr, our_netmask); | |
21634 | + if (ret == 1) { | |
21635 | + rcu_read_unlock(); | |
21636 | + in_dev_put(idev); | |
21637 | + dev_put(dev); | |
21638 | + return 1; | |
21639 | + } else if (ret == 2) { | |
21640 | + rcu_read_unlock(); | |
21641 | + in_dev_put(idev); | |
21642 | + dev_put(dev); | |
21643 | + goto denied; | |
21644 | + } | |
21645 | + } | |
21646 | + } endfor_ifa(idev); | |
21647 | + rcu_read_unlock(); | |
21648 | + in_dev_put(idev); | |
21649 | + dev_put(dev); | |
21650 | + } else { | |
21651 | + our_addr = ip->addr; | |
21652 | + our_netmask = ip->netmask; | |
21653 | + ret = check_ip_policy(ip, ip_addr, ip_port, sk->sk_protocol, mode, type, our_addr, our_netmask); | |
21654 | + if (ret == 1) | |
21655 | + return 1; | |
21656 | + else if (ret == 2) | |
21657 | + goto denied; | |
21658 | + } | |
21659 | + } | |
21660 | + | |
21661 | +denied: | |
21662 | + if (mode == GR_BIND) | |
21663 | + gr_log_int5_str2(GR_DONT_AUDIT, GR_BIND_ACL_MSG, NIPQUAD(ip_addr), ip_port, gr_socktype_to_name(type), gr_proto_to_name(sk->sk_protocol)); | |
21664 | + else if (mode == GR_CONNECT) | |
21665 | + gr_log_int5_str2(GR_DONT_AUDIT, GR_CONNECT_ACL_MSG, NIPQUAD(ip_addr), ip_port, gr_socktype_to_name(type), gr_proto_to_name(sk->sk_protocol)); | |
21666 | + | |
21667 | + return 0; | |
21668 | +} | |
21669 | + | |
21670 | +int | |
21671 | +gr_search_connect(const struct socket *sock, const struct sockaddr_in *addr) | |
21672 | +{ | |
21673 | + return gr_search_connectbind(GR_CONNECT, sock->sk, addr, sock->type); | |
21674 | +} | |
21675 | + | |
21676 | +int | |
21677 | +gr_search_bind(const struct socket *sock, const struct sockaddr_in *addr) | |
21678 | +{ | |
21679 | + return gr_search_connectbind(GR_BIND, sock->sk, addr, sock->type); | |
21680 | +} | |
21681 | + | |
21682 | +int gr_search_listen(const struct socket *sock) | |
21683 | +{ | |
21684 | + struct sock *sk = sock->sk; | |
21685 | + struct sockaddr_in addr; | |
21686 | + | |
21687 | + addr.sin_addr.s_addr = inet_sk(sk)->saddr; | |
21688 | + addr.sin_port = inet_sk(sk)->sport; | |
21689 | + | |
21690 | + return gr_search_connectbind(GR_BIND, sock->sk, &addr, sock->type); | |
21691 | +} | |
21692 | + | |
21693 | +int gr_search_accept(const struct socket *sock) | |
21694 | +{ | |
21695 | + struct sock *sk = sock->sk; | |
21696 | + struct sockaddr_in addr; | |
21697 | + | |
21698 | + addr.sin_addr.s_addr = inet_sk(sk)->saddr; | |
21699 | + addr.sin_port = inet_sk(sk)->sport; | |
21700 | + | |
21701 | + return gr_search_connectbind(GR_BIND, sock->sk, &addr, sock->type); | |
21702 | +} | |
21703 | + | |
21704 | +int | |
21705 | +gr_search_udp_sendmsg(const struct sock *sk, const struct sockaddr_in *addr) | |
21706 | +{ | |
21707 | + if (addr) | |
21708 | + return gr_search_connectbind(GR_CONNECT, sk, addr, SOCK_DGRAM); | |
21709 | + else { | |
21710 | + struct sockaddr_in sin; | |
21711 | + const struct inet_sock *inet = inet_sk(sk); | |
21712 | + | |
21713 | + sin.sin_addr.s_addr = inet->daddr; | |
21714 | + sin.sin_port = inet->dport; | |
21715 | + | |
21716 | + return gr_search_connectbind(GR_CONNECT, sk, &sin, SOCK_DGRAM); | |
21717 | + } | |
21718 | +} | |
21719 | + | |
21720 | +int | |
21721 | +gr_search_udp_recvmsg(const struct sock *sk, const struct sk_buff *skb) | |
21722 | +{ | |
21723 | + struct sockaddr_in sin; | |
21724 | + | |
21725 | + if (unlikely(skb->len < sizeof (struct udphdr))) | |
21726 | + return 1; // skip this packet | |
21727 | + | |
8a4b4a5e | 21728 | + sin.sin_addr.s_addr = ip_hdr(skb)->saddr; |
21729 | + sin.sin_port = udp_hdr(skb)->source; | |
50425a20 | 21730 | + |
21731 | + return gr_search_connectbind(GR_CONNECT, sk, &sin, SOCK_DGRAM); | |
21732 | +} | |
4dee9bd5 | 21733 | diff -urNp linux-2.6.25.4/grsecurity/gracl_learn.c linux-2.6.25.4/grsecurity/gracl_learn.c |
21734 | --- linux-2.6.25.4/grsecurity/gracl_learn.c 1969-12-31 19:00:00.000000000 -0500 | |
21735 | +++ linux-2.6.25.4/grsecurity/gracl_learn.c 2008-05-18 13:33:16.000000000 -0400 | |
50425a20 | 21736 | @@ -0,0 +1,211 @@ |
21737 | +#include <linux/kernel.h> | |
21738 | +#include <linux/mm.h> | |
21739 | +#include <linux/sched.h> | |
21740 | +#include <linux/poll.h> | |
21741 | +#include <linux/smp_lock.h> | |
21742 | +#include <linux/string.h> | |
21743 | +#include <linux/file.h> | |
21744 | +#include <linux/types.h> | |
21745 | +#include <linux/vmalloc.h> | |
21746 | +#include <linux/grinternal.h> | |
21747 | + | |
21748 | +extern ssize_t write_grsec_handler(struct file * file, const char __user * buf, | |
21749 | + size_t count, loff_t *ppos); | |
21750 | +extern int gr_acl_is_enabled(void); | |
21751 | + | |
21752 | +static DECLARE_WAIT_QUEUE_HEAD(learn_wait); | |
21753 | +static int gr_learn_attached; | |
21754 | + | |
21755 | +/* use a 512k buffer */ | |
21756 | +#define LEARN_BUFFER_SIZE (512 * 1024) | |
21757 | + | |
21758 | +static spinlock_t gr_learn_lock = SPIN_LOCK_UNLOCKED; | |
21759 | +static DECLARE_MUTEX(gr_learn_user_sem); | |
21760 | + | |
21761 | +/* we need to maintain two buffers, so that the kernel context of grlearn | |
21762 | + uses a semaphore around the userspace copying, and the other kernel contexts | |
21763 | + use a spinlock when copying into the buffer, since they cannot sleep | |
21764 | +*/ | |
21765 | +static char *learn_buffer; | |
21766 | +static char *learn_buffer_user; | |
21767 | +static int learn_buffer_len; | |
21768 | +static int learn_buffer_user_len; | |
21769 | + | |
21770 | +static ssize_t | |
21771 | +read_learn(struct file *file, char __user * buf, size_t count, loff_t * ppos) | |
21772 | +{ | |
21773 | + DECLARE_WAITQUEUE(wait, current); | |
21774 | + ssize_t retval = 0; | |
21775 | + | |
21776 | + add_wait_queue(&learn_wait, &wait); | |
21777 | + set_current_state(TASK_INTERRUPTIBLE); | |
21778 | + do { | |
21779 | + down(&gr_learn_user_sem); | |
21780 | + spin_lock(&gr_learn_lock); | |
21781 | + if (learn_buffer_len) | |
21782 | + break; | |
21783 | + spin_unlock(&gr_learn_lock); | |
21784 | + up(&gr_learn_user_sem); | |
21785 | + if (file->f_flags & O_NONBLOCK) { | |
21786 | + retval = -EAGAIN; | |
21787 | + goto out; | |
21788 | + } | |
21789 | + if (signal_pending(current)) { | |
21790 | + retval = -ERESTARTSYS; | |
21791 | + goto out; | |
21792 | + } | |
21793 | + | |
21794 | + schedule(); | |
21795 | + } while (1); | |
21796 | + | |
21797 | + memcpy(learn_buffer_user, learn_buffer, learn_buffer_len); | |
21798 | + learn_buffer_user_len = learn_buffer_len; | |
21799 | + retval = learn_buffer_len; | |
21800 | + learn_buffer_len = 0; | |
21801 | + | |
21802 | + spin_unlock(&gr_learn_lock); | |
21803 | + | |
21804 | + if (copy_to_user(buf, learn_buffer_user, learn_buffer_user_len)) | |
21805 | + retval = -EFAULT; | |
21806 | + | |
21807 | + up(&gr_learn_user_sem); | |
21808 | +out: | |
21809 | + set_current_state(TASK_RUNNING); | |
21810 | + remove_wait_queue(&learn_wait, &wait); | |
21811 | + return retval; | |
21812 | +} | |
21813 | + | |
21814 | +static unsigned int | |
21815 | +poll_learn(struct file * file, poll_table * wait) | |
21816 | +{ | |
21817 | + poll_wait(file, &learn_wait, wait); | |
21818 | + | |
21819 | + if (learn_buffer_len) | |
21820 | + return (POLLIN | POLLRDNORM); | |
21821 | + | |
21822 | + return 0; | |
21823 | +} | |
21824 | + | |
21825 | +void | |
21826 | +gr_clear_learn_entries(void) | |
21827 | +{ | |
21828 | + char *tmp; | |
21829 | + | |
21830 | + down(&gr_learn_user_sem); | |
21831 | + if (learn_buffer != NULL) { | |
21832 | + spin_lock(&gr_learn_lock); | |
21833 | + tmp = learn_buffer; | |
21834 | + learn_buffer = NULL; | |
21835 | + spin_unlock(&gr_learn_lock); | |
21836 | + vfree(learn_buffer); | |
21837 | + } | |
21838 | + if (learn_buffer_user != NULL) { | |
21839 | + vfree(learn_buffer_user); | |
21840 | + learn_buffer_user = NULL; | |
21841 | + } | |
21842 | + learn_buffer_len = 0; | |
21843 | + up(&gr_learn_user_sem); | |
21844 | + | |
21845 | + return; | |
21846 | +} | |
21847 | + | |
21848 | +void | |
21849 | +gr_add_learn_entry(const char *fmt, ...) | |
21850 | +{ | |
21851 | + va_list args; | |
21852 | + unsigned int len; | |
21853 | + | |
21854 | + if (!gr_learn_attached) | |
21855 | + return; | |
21856 | + | |
21857 | + spin_lock(&gr_learn_lock); | |
21858 | + | |
21859 | + /* leave a gap at the end so we know when it's "full" but don't have to | |
21860 | + compute the exact length of the string we're trying to append | |
21861 | + */ | |
21862 | + if (learn_buffer_len > LEARN_BUFFER_SIZE - 16384) { | |
21863 | + spin_unlock(&gr_learn_lock); | |
21864 | + wake_up_interruptible(&learn_wait); | |
21865 | + return; | |
21866 | + } | |
21867 | + if (learn_buffer == NULL) { | |
21868 | + spin_unlock(&gr_learn_lock); | |
21869 | + return; | |
21870 | + } | |
21871 | + | |
21872 | + va_start(args, fmt); | |
21873 | + len = vsnprintf(learn_buffer + learn_buffer_len, LEARN_BUFFER_SIZE - learn_buffer_len, fmt, args); | |
21874 | + va_end(args); | |
21875 | + | |
21876 | + learn_buffer_len += len + 1; | |
21877 | + | |
21878 | + spin_unlock(&gr_learn_lock); | |
21879 | + wake_up_interruptible(&learn_wait); | |
21880 | + | |
21881 | + return; | |
21882 | +} | |
21883 | + | |
21884 | +static int | |
21885 | +open_learn(struct inode *inode, struct file *file) | |
21886 | +{ | |
21887 | + if (file->f_mode & FMODE_READ && gr_learn_attached) | |
21888 | + return -EBUSY; | |
21889 | + if (file->f_mode & FMODE_READ) { | |
21890 | + int retval = 0; | |
21891 | + down(&gr_learn_user_sem); | |
21892 | + if (learn_buffer == NULL) | |
21893 | + learn_buffer = vmalloc(LEARN_BUFFER_SIZE); | |
21894 | + if (learn_buffer_user == NULL) | |
21895 | + learn_buffer_user = vmalloc(LEARN_BUFFER_SIZE); | |
21896 | + if (learn_buffer == NULL) { | |
21897 | + retval = -ENOMEM; | |
21898 | + goto out_error; | |
21899 | + } | |
21900 | + if (learn_buffer_user == NULL) { | |
21901 | + retval = -ENOMEM; | |
21902 | + goto out_error; | |
21903 | + } | |
21904 | + learn_buffer_len = 0; | |
21905 | + learn_buffer_user_len = 0; | |
21906 | + gr_learn_attached = 1; | |
21907 | +out_error: | |
21908 | + up(&gr_learn_user_sem); | |
21909 | + return retval; | |
21910 | + } | |
21911 | + return 0; | |
21912 | +} | |
21913 | + | |
21914 | +static int | |
21915 | +close_learn(struct inode *inode, struct file *file) | |
21916 | +{ | |
21917 | + char *tmp; | |
21918 | + | |
21919 | + if (file->f_mode & FMODE_READ) { | |
21920 | + down(&gr_learn_user_sem); | |
21921 | + if (learn_buffer != NULL) { | |
21922 | + spin_lock(&gr_learn_lock); | |
21923 | + tmp = learn_buffer; | |
21924 | + learn_buffer = NULL; | |
21925 | + spin_unlock(&gr_learn_lock); | |
21926 | + vfree(tmp); | |
21927 | + } | |
21928 | + if (learn_buffer_user != NULL) { | |
21929 | + vfree(learn_buffer_user); | |
21930 | + learn_buffer_user = NULL; | |
21931 | + } | |
21932 | + learn_buffer_len = 0; | |
21933 | + learn_buffer_user_len = 0; | |
21934 | + gr_learn_attached = 0; | |
21935 | + up(&gr_learn_user_sem); | |
21936 | + } | |
21937 | + | |
21938 | + return 0; | |
21939 | +} | |
21940 | + | |
21941 | +struct file_operations grsec_fops = { | |
21942 | + .read = read_learn, | |
21943 | + .write = write_grsec_handler, | |
21944 | + .open = open_learn, | |
21945 | + .release = close_learn, | |
21946 | + .poll = poll_learn, | |
21947 | +}; | |
4dee9bd5 | 21948 | diff -urNp linux-2.6.25.4/grsecurity/gracl_res.c linux-2.6.25.4/grsecurity/gracl_res.c |
21949 | --- linux-2.6.25.4/grsecurity/gracl_res.c 1969-12-31 19:00:00.000000000 -0500 | |
21950 | +++ linux-2.6.25.4/grsecurity/gracl_res.c 2008-05-18 13:33:16.000000000 -0400 | |
50425a20 | 21951 | @@ -0,0 +1,45 @@ |
21952 | +#include <linux/kernel.h> | |
21953 | +#include <linux/sched.h> | |
21954 | +#include <linux/gracl.h> | |
21955 | +#include <linux/grinternal.h> | |
21956 | + | |
21957 | +static const char *restab_log[] = { | |
21958 | + [RLIMIT_CPU] = "RLIMIT_CPU", | |
21959 | + [RLIMIT_FSIZE] = "RLIMIT_FSIZE", | |
21960 | + [RLIMIT_DATA] = "RLIMIT_DATA", | |
21961 | + [RLIMIT_STACK] = "RLIMIT_STACK", | |
21962 | + [RLIMIT_CORE] = "RLIMIT_CORE", | |
21963 | + [RLIMIT_RSS] = "RLIMIT_RSS", | |
21964 | + [RLIMIT_NPROC] = "RLIMIT_NPROC", | |
21965 | + [RLIMIT_NOFILE] = "RLIMIT_NOFILE", | |
21966 | + [RLIMIT_MEMLOCK] = "RLIMIT_MEMLOCK", | |
21967 | + [RLIMIT_AS] = "RLIMIT_AS", | |
21968 | + [RLIMIT_LOCKS] = "RLIMIT_LOCKS", | |
21969 | + [RLIMIT_LOCKS + 1] = "RLIMIT_CRASH" | |
21970 | +}; | |
21971 | + | |
21972 | +void | |
21973 | +gr_log_resource(const struct task_struct *task, | |
21974 | + const int res, const unsigned long wanted, const int gt) | |
21975 | +{ | |
21976 | + if (res == RLIMIT_NPROC && | |
21977 | + (cap_raised(task->cap_effective, CAP_SYS_ADMIN) || | |
21978 | + cap_raised(task->cap_effective, CAP_SYS_RESOURCE))) | |
21979 | + return; | |
21980 | + else if (res == RLIMIT_MEMLOCK && | |
21981 | + cap_raised(task->cap_effective, CAP_IPC_LOCK)) | |
21982 | + return; | |
21983 | + | |
21984 | + if (!gr_acl_is_enabled() && !grsec_resource_logging) | |
21985 | + return; | |
21986 | + | |
21987 | + preempt_disable(); | |
21988 | + | |
21989 | + if (unlikely(((gt && wanted > task->signal->rlim[res].rlim_cur) || | |
21990 | + (!gt && wanted >= task->signal->rlim[res].rlim_cur)) && | |
21991 | + task->signal->rlim[res].rlim_cur != RLIM_INFINITY)) | |
21992 | + gr_log_res_ulong2_str(GR_DONT_AUDIT, GR_RESOURCE_MSG, task, wanted, restab_log[res], task->signal->rlim[res].rlim_cur); | |
21993 | + preempt_enable_no_resched(); | |
21994 | + | |
21995 | + return; | |
21996 | +} | |
4dee9bd5 | 21997 | diff -urNp linux-2.6.25.4/grsecurity/gracl_segv.c linux-2.6.25.4/grsecurity/gracl_segv.c |
21998 | --- linux-2.6.25.4/grsecurity/gracl_segv.c 1969-12-31 19:00:00.000000000 -0500 | |
21999 | +++ linux-2.6.25.4/grsecurity/gracl_segv.c 2008-05-18 13:33:16.000000000 -0400 | |
8a4b4a5e | 22000 | @@ -0,0 +1,301 @@ |
50425a20 | 22001 | +#include <linux/kernel.h> |
22002 | +#include <linux/mm.h> | |
22003 | +#include <asm/uaccess.h> | |
22004 | +#include <asm/errno.h> | |
22005 | +#include <asm/mman.h> | |
22006 | +#include <net/sock.h> | |
22007 | +#include <linux/file.h> | |
22008 | +#include <linux/fs.h> | |
22009 | +#include <linux/net.h> | |
22010 | +#include <linux/in.h> | |
22011 | +#include <linux/smp_lock.h> | |
22012 | +#include <linux/slab.h> | |
22013 | +#include <linux/types.h> | |
22014 | +#include <linux/sched.h> | |
22015 | +#include <linux/timer.h> | |
22016 | +#include <linux/gracl.h> | |
22017 | +#include <linux/grsecurity.h> | |
22018 | +#include <linux/grinternal.h> | |
22019 | + | |
22020 | +static struct crash_uid *uid_set; | |
22021 | +static unsigned short uid_used; | |
22022 | +static spinlock_t gr_uid_lock = SPIN_LOCK_UNLOCKED; | |
22023 | +extern rwlock_t gr_inode_lock; | |
22024 | +extern struct acl_subject_label * | |
22025 | + lookup_acl_subj_label(const ino_t inode, const dev_t dev, | |
22026 | + struct acl_role_label *role); | |
22027 | +extern int specific_send_sig_info(int sig, struct siginfo *info, struct task_struct *t); | |
22028 | + | |
22029 | +int | |
22030 | +gr_init_uidset(void) | |
22031 | +{ | |
22032 | + uid_set = | |
22033 | + kmalloc(GR_UIDTABLE_MAX * sizeof (struct crash_uid), GFP_KERNEL); | |
22034 | + uid_used = 0; | |
22035 | + | |
22036 | + return uid_set ? 1 : 0; | |
22037 | +} | |
22038 | + | |
22039 | +void | |
22040 | +gr_free_uidset(void) | |
22041 | +{ | |
22042 | + if (uid_set) | |
22043 | + kfree(uid_set); | |
22044 | + | |
22045 | + return; | |
22046 | +} | |
22047 | + | |
22048 | +int | |
22049 | +gr_find_uid(const uid_t uid) | |
22050 | +{ | |
22051 | + struct crash_uid *tmp = uid_set; | |
22052 | + uid_t buid; | |
22053 | + int low = 0, high = uid_used - 1, mid; | |
22054 | + | |
22055 | + while (high >= low) { | |
22056 | + mid = (low + high) >> 1; | |
22057 | + buid = tmp[mid].uid; | |
22058 | + if (buid == uid) | |
22059 | + return mid; | |
22060 | + if (buid > uid) | |
22061 | + high = mid - 1; | |
22062 | + if (buid < uid) | |
22063 | + low = mid + 1; | |
22064 | + } | |
22065 | + | |
22066 | + return -1; | |
22067 | +} | |
22068 | + | |
22069 | +static __inline__ void | |
22070 | +gr_insertsort(void) | |
22071 | +{ | |
22072 | + unsigned short i, j; | |
22073 | + struct crash_uid index; | |
22074 | + | |
22075 | + for (i = 1; i < uid_used; i++) { | |
22076 | + index = uid_set[i]; | |
22077 | + j = i; | |
22078 | + while ((j > 0) && uid_set[j - 1].uid > index.uid) { | |
22079 | + uid_set[j] = uid_set[j - 1]; | |
22080 | + j--; | |
22081 | + } | |
22082 | + uid_set[j] = index; | |
22083 | + } | |
22084 | + | |
22085 | + return; | |
22086 | +} | |
22087 | + | |
22088 | +static __inline__ void | |
22089 | +gr_insert_uid(const uid_t uid, const unsigned long expires) | |
22090 | +{ | |
22091 | + int loc; | |
22092 | + | |
22093 | + if (uid_used == GR_UIDTABLE_MAX) | |
22094 | + return; | |
22095 | + | |
22096 | + loc = gr_find_uid(uid); | |
22097 | + | |
22098 | + if (loc >= 0) { | |
22099 | + uid_set[loc].expires = expires; | |
22100 | + return; | |
22101 | + } | |
22102 | + | |
22103 | + uid_set[uid_used].uid = uid; | |
22104 | + uid_set[uid_used].expires = expires; | |
22105 | + uid_used++; | |
22106 | + | |
22107 | + gr_insertsort(); | |
22108 | + | |
22109 | + return; | |
22110 | +} | |
22111 | + | |
22112 | +void | |
22113 | +gr_remove_uid(const unsigned short loc) | |
22114 | +{ | |
22115 | + unsigned short i; | |
22116 | + | |
22117 | + for (i = loc + 1; i < uid_used; i++) | |
22118 | + uid_set[i - 1] = uid_set[i]; | |
22119 | + | |
22120 | + uid_used--; | |
22121 | + | |
22122 | + return; | |
22123 | +} | |
22124 | + | |
22125 | +int | |
22126 | +gr_check_crash_uid(const uid_t uid) | |
22127 | +{ | |
22128 | + int loc; | |
22129 | + int ret = 0; | |
22130 | + | |
22131 | + if (unlikely(!gr_acl_is_enabled())) | |
22132 | + return 0; | |
22133 | + | |
22134 | + spin_lock(&gr_uid_lock); | |
22135 | + loc = gr_find_uid(uid); | |
22136 | + | |
22137 | + if (loc < 0) | |
22138 | + goto out_unlock; | |
22139 | + | |
22140 | + if (time_before_eq(uid_set[loc].expires, get_seconds())) | |
22141 | + gr_remove_uid(loc); | |
22142 | + else | |
22143 | + ret = 1; | |
22144 | + | |
22145 | +out_unlock: | |
22146 | + spin_unlock(&gr_uid_lock); | |
22147 | + return ret; | |
22148 | +} | |
22149 | + | |
22150 | +static __inline__ int | |
22151 | +proc_is_setxid(const struct task_struct *task) | |
22152 | +{ | |
22153 | + if (task->uid != task->euid || task->uid != task->suid || | |
22154 | + task->uid != task->fsuid) | |
22155 | + return 1; | |
22156 | + if (task->gid != task->egid || task->gid != task->sgid || | |
22157 | + task->gid != task->fsgid) | |
22158 | + return 1; | |
22159 | + | |
22160 | + return 0; | |
22161 | +} | |
22162 | +static __inline__ int | |
22163 | +gr_fake_force_sig(int sig, struct task_struct *t) | |
22164 | +{ | |
22165 | + unsigned long int flags; | |
8a4b4a5e | 22166 | + int ret, blocked, ignored; |
22167 | + struct k_sigaction *action; | |
50425a20 | 22168 | + |
22169 | + spin_lock_irqsave(&t->sighand->siglock, flags); | |
8a4b4a5e | 22170 | + action = &t->sighand->action[sig-1]; |
22171 | + ignored = action->sa.sa_handler == SIG_IGN; | |
22172 | + blocked = sigismember(&t->blocked, sig); | |
22173 | + if (blocked || ignored) { | |
22174 | + action->sa.sa_handler = SIG_DFL; | |
22175 | + if (blocked) { | |
22176 | + sigdelset(&t->blocked, sig); | |
22177 | + recalc_sigpending_and_wake(t); | |
22178 | + } | |
50425a20 | 22179 | + } |
22180 | + ret = specific_send_sig_info(sig, (void*)1L, t); | |
22181 | + spin_unlock_irqrestore(&t->sighand->siglock, flags); | |
22182 | + | |
22183 | + return ret; | |
22184 | +} | |
22185 | + | |
22186 | +void | |
22187 | +gr_handle_crash(struct task_struct *task, const int sig) | |
22188 | +{ | |
22189 | + struct acl_subject_label *curr; | |
22190 | + struct acl_subject_label *curr2; | |
22191 | + struct task_struct *tsk, *tsk2; | |
22192 | + | |
22193 | + if (sig != SIGSEGV && sig != SIGKILL && sig != SIGBUS && sig != SIGILL) | |
22194 | + return; | |
22195 | + | |
22196 | + if (unlikely(!gr_acl_is_enabled())) | |
22197 | + return; | |
22198 | + | |
22199 | + curr = task->acl; | |
22200 | + | |
22201 | + if (!(curr->resmask & (1 << GR_CRASH_RES))) | |
22202 | + return; | |
22203 | + | |
22204 | + if (time_before_eq(curr->expires, get_seconds())) { | |
22205 | + curr->expires = 0; | |
22206 | + curr->crashes = 0; | |
22207 | + } | |
22208 | + | |
22209 | + curr->crashes++; | |
22210 | + | |
22211 | + if (!curr->expires) | |
22212 | + curr->expires = get_seconds() + curr->res[GR_CRASH_RES].rlim_max; | |
22213 | + | |
22214 | + if ((curr->crashes >= curr->res[GR_CRASH_RES].rlim_cur) && | |
22215 | + time_after(curr->expires, get_seconds())) { | |
22216 | + if (task->uid && proc_is_setxid(task)) { | |
22217 | + gr_log_crash1(GR_DONT_AUDIT, GR_SEGVSTART_ACL_MSG, task, curr->res[GR_CRASH_RES].rlim_max); | |
22218 | + spin_lock(&gr_uid_lock); | |
22219 | + gr_insert_uid(task->uid, curr->expires); | |
22220 | + spin_unlock(&gr_uid_lock); | |
22221 | + curr->expires = 0; | |
22222 | + curr->crashes = 0; | |
22223 | + read_lock(&tasklist_lock); | |
22224 | + do_each_thread(tsk2, tsk) { | |
22225 | + if (tsk != task && tsk->uid == task->uid) | |
22226 | + gr_fake_force_sig(SIGKILL, tsk); | |
22227 | + } while_each_thread(tsk2, tsk); | |
22228 | + read_unlock(&tasklist_lock); | |
22229 | + } else { | |
22230 | + gr_log_crash2(GR_DONT_AUDIT, GR_SEGVNOSUID_ACL_MSG, task, curr->res[GR_CRASH_RES].rlim_max); | |
22231 | + read_lock(&tasklist_lock); | |
22232 | + do_each_thread(tsk2, tsk) { | |
22233 | + if (likely(tsk != task)) { | |
22234 | + curr2 = tsk->acl; | |
22235 | + | |
22236 | + if (curr2->device == curr->device && | |
22237 | + curr2->inode == curr->inode) | |
22238 | + gr_fake_force_sig(SIGKILL, tsk); | |
22239 | + } | |
22240 | + } while_each_thread(tsk2, tsk); | |
22241 | + read_unlock(&tasklist_lock); | |
22242 | + } | |
22243 | + } | |
22244 | + | |
22245 | + return; | |
22246 | +} | |
22247 | + | |
22248 | +int | |
22249 | +gr_check_crash_exec(const struct file *filp) | |
22250 | +{ | |
22251 | + struct acl_subject_label *curr; | |
22252 | + | |
22253 | + if (unlikely(!gr_acl_is_enabled())) | |
22254 | + return 0; | |
22255 | + | |
22256 | + read_lock(&gr_inode_lock); | |
4dee9bd5 | 22257 | + curr = lookup_acl_subj_label(filp->f_path.dentry->d_inode->i_ino, |
22258 | + filp->f_path.dentry->d_inode->i_sb->s_dev, | |
50425a20 | 22259 | + current->role); |
22260 | + read_unlock(&gr_inode_lock); | |
22261 | + | |
22262 | + if (!curr || !(curr->resmask & (1 << GR_CRASH_RES)) || | |
22263 | + (!curr->crashes && !curr->expires)) | |
22264 | + return 0; | |
22265 | + | |
22266 | + if ((curr->crashes >= curr->res[GR_CRASH_RES].rlim_cur) && | |
22267 | + time_after(curr->expires, get_seconds())) | |
22268 | + return 1; | |
22269 | + else if (time_before_eq(curr->expires, get_seconds())) { | |
22270 | + curr->crashes = 0; | |
22271 | + curr->expires = 0; | |
22272 | + } | |
22273 | + | |
22274 | + return 0; | |
22275 | +} | |
22276 | + | |
22277 | +void | |
22278 | +gr_handle_alertkill(struct task_struct *task) | |
22279 | +{ | |
22280 | + struct acl_subject_label *curracl; | |
22281 | + __u32 curr_ip; | |
22282 | + struct task_struct *p, *p2; | |
22283 | + | |
22284 | + if (unlikely(!gr_acl_is_enabled())) | |
22285 | + return; | |
22286 | + | |
22287 | + curracl = task->acl; | |
22288 | + curr_ip = task->signal->curr_ip; | |
22289 | + | |
22290 | + if ((curracl->mode & GR_KILLIPPROC) && curr_ip) { | |
22291 | + read_lock(&tasklist_lock); | |
22292 | + do_each_thread(p2, p) { | |
22293 | + if (p->signal->curr_ip == curr_ip) | |
22294 | + gr_fake_force_sig(SIGKILL, p); | |
22295 | + } while_each_thread(p2, p); | |
22296 | + read_unlock(&tasklist_lock); | |
22297 | + } else if (curracl->mode & GR_KILLPROC) | |
22298 | + gr_fake_force_sig(SIGKILL, task); | |
22299 | + | |
22300 | + return; | |
22301 | +} | |
4dee9bd5 | 22302 | diff -urNp linux-2.6.25.4/grsecurity/gracl_shm.c linux-2.6.25.4/grsecurity/gracl_shm.c |
22303 | --- linux-2.6.25.4/grsecurity/gracl_shm.c 1969-12-31 19:00:00.000000000 -0500 | |
22304 | +++ linux-2.6.25.4/grsecurity/gracl_shm.c 2008-05-18 13:33:16.000000000 -0400 | |
50425a20 | 22305 | @@ -0,0 +1,33 @@ |
22306 | +#include <linux/kernel.h> | |
22307 | +#include <linux/mm.h> | |
22308 | +#include <linux/sched.h> | |
22309 | +#include <linux/file.h> | |
22310 | +#include <linux/ipc.h> | |
22311 | +#include <linux/gracl.h> | |
22312 | +#include <linux/grsecurity.h> | |
22313 | +#include <linux/grinternal.h> | |
22314 | + | |
22315 | +int | |
22316 | +gr_handle_shmat(const pid_t shm_cprid, const pid_t shm_lapid, | |
22317 | + const time_t shm_createtime, const uid_t cuid, const int shmid) | |
22318 | +{ | |
22319 | + struct task_struct *task; | |
22320 | + | |
22321 | + if (!gr_acl_is_enabled()) | |
22322 | + return 1; | |
22323 | + | |
22324 | + task = find_task_by_pid(shm_cprid); | |
22325 | + | |
22326 | + if (unlikely(!task)) | |
22327 | + task = find_task_by_pid(shm_lapid); | |
22328 | + | |
b2ee8b1e | 22329 | + if (unlikely(task && (time_before_eq((unsigned long)task->start_time.tv_sec, (unsigned long)shm_createtime) || |
50425a20 | 22330 | + (task->pid == shm_lapid)) && |
22331 | + (task->acl->mode & GR_PROTSHM) && | |
22332 | + (task->acl != current->acl))) { | |
22333 | + gr_log_int3(GR_DONT_AUDIT, GR_SHMAT_ACL_MSG, cuid, shm_cprid, shmid); | |
22334 | + return 0; | |
22335 | + } | |
22336 | + | |
22337 | + return 1; | |
22338 | +} | |
4dee9bd5 | 22339 | diff -urNp linux-2.6.25.4/grsecurity/grsec_chdir.c linux-2.6.25.4/grsecurity/grsec_chdir.c |
22340 | --- linux-2.6.25.4/grsecurity/grsec_chdir.c 1969-12-31 19:00:00.000000000 -0500 | |
22341 | +++ linux-2.6.25.4/grsecurity/grsec_chdir.c 2008-05-18 13:33:16.000000000 -0400 | |
50425a20 | 22342 | @@ -0,0 +1,19 @@ |
22343 | +#include <linux/kernel.h> | |
22344 | +#include <linux/sched.h> | |
22345 | +#include <linux/fs.h> | |
22346 | +#include <linux/file.h> | |
22347 | +#include <linux/grsecurity.h> | |
22348 | +#include <linux/grinternal.h> | |
22349 | + | |
22350 | +void | |
22351 | +gr_log_chdir(const struct dentry *dentry, const struct vfsmount *mnt) | |
22352 | +{ | |
22353 | +#ifdef CONFIG_GRKERNSEC_AUDIT_CHDIR | |
22354 | + if ((grsec_enable_chdir && grsec_enable_group && | |
22355 | + in_group_p(grsec_audit_gid)) || (grsec_enable_chdir && | |
22356 | + !grsec_enable_group)) { | |
22357 | + gr_log_fs_generic(GR_DO_AUDIT, GR_CHDIR_AUDIT_MSG, dentry, mnt); | |
22358 | + } | |
22359 | +#endif | |
22360 | + return; | |
22361 | +} | |
4dee9bd5 | 22362 | diff -urNp linux-2.6.25.4/grsecurity/grsec_chroot.c linux-2.6.25.4/grsecurity/grsec_chroot.c |
22363 | --- linux-2.6.25.4/grsecurity/grsec_chroot.c 1969-12-31 19:00:00.000000000 -0500 | |
22364 | +++ linux-2.6.25.4/grsecurity/grsec_chroot.c 2008-05-18 13:33:16.000000000 -0400 | |
22365 | @@ -0,0 +1,336 @@ | |
50425a20 | 22366 | +#include <linux/kernel.h> |
22367 | +#include <linux/module.h> | |
22368 | +#include <linux/sched.h> | |
22369 | +#include <linux/file.h> | |
22370 | +#include <linux/fs.h> | |
22371 | +#include <linux/mount.h> | |
22372 | +#include <linux/types.h> | |
22373 | +#include <linux/pid_namespace.h> | |
22374 | +#include <linux/grsecurity.h> | |
22375 | +#include <linux/grinternal.h> | |
22376 | + | |
22377 | +int | |
22378 | +gr_handle_chroot_unix(const pid_t pid) | |
22379 | +{ | |
22380 | +#ifdef CONFIG_GRKERNSEC_CHROOT_UNIX | |
22381 | + struct pid *spid = NULL; | |
22382 | + | |
22383 | + if (unlikely(!grsec_enable_chroot_unix)) | |
22384 | + return 1; | |
22385 | + | |
22386 | + if (likely(!proc_is_chrooted(current))) | |
22387 | + return 1; | |
22388 | + | |
22389 | + read_lock(&tasklist_lock); | |
22390 | + | |
22391 | + spid = find_pid(pid); | |
22392 | + if (spid) { | |
22393 | + struct task_struct *p; | |
22394 | + p = pid_task(spid, PIDTYPE_PID); | |
22395 | + task_lock(p); | |
22396 | + if (unlikely(!have_same_root(current, p))) { | |
22397 | + task_unlock(p); | |
22398 | + read_unlock(&tasklist_lock); | |
22399 | + gr_log_noargs(GR_DONT_AUDIT, GR_UNIX_CHROOT_MSG); | |
22400 | + return 0; | |
22401 | + } | |
22402 | + task_unlock(p); | |
22403 | + } | |
22404 | + read_unlock(&tasklist_lock); | |
22405 | +#endif | |
22406 | + return 1; | |
22407 | +} | |
22408 | + | |
22409 | +int | |
22410 | +gr_handle_chroot_nice(void) | |
22411 | +{ | |
22412 | +#ifdef CONFIG_GRKERNSEC_CHROOT_NICE | |
22413 | + if (grsec_enable_chroot_nice && proc_is_chrooted(current)) { | |
22414 | + gr_log_noargs(GR_DONT_AUDIT, GR_NICE_CHROOT_MSG); | |
22415 | + return -EPERM; | |
22416 | + } | |
22417 | +#endif | |
22418 | + return 0; | |
22419 | +} | |
22420 | + | |
22421 | +int | |
22422 | +gr_handle_chroot_setpriority(struct task_struct *p, const int niceval) | |
22423 | +{ | |
22424 | +#ifdef CONFIG_GRKERNSEC_CHROOT_NICE | |
22425 | + if (grsec_enable_chroot_nice && (niceval < task_nice(p)) | |
22426 | + && proc_is_chrooted(current)) { | |
22427 | + gr_log_str_int(GR_DONT_AUDIT, GR_PRIORITY_CHROOT_MSG, p->comm, p->pid); | |
22428 | + return -EACCES; | |
22429 | + } | |
22430 | +#endif | |
22431 | + return 0; | |
22432 | +} | |
22433 | + | |
22434 | +int | |
22435 | +gr_handle_chroot_rawio(const struct inode *inode) | |
22436 | +{ | |
22437 | +#ifdef CONFIG_GRKERNSEC_CHROOT_CAPS | |
22438 | + if (grsec_enable_chroot_caps && proc_is_chrooted(current) && | |
22439 | + inode && S_ISBLK(inode->i_mode) && !capable(CAP_SYS_RAWIO)) | |
22440 | + return 1; | |
22441 | +#endif | |
22442 | + return 0; | |
22443 | +} | |
22444 | + | |
22445 | +int | |
22446 | +gr_pid_is_chrooted(struct task_struct *p) | |
22447 | +{ | |
22448 | +#ifdef CONFIG_GRKERNSEC_CHROOT_FINDTASK | |
22449 | + if (!grsec_enable_chroot_findtask || !proc_is_chrooted(current) || p == NULL) | |
22450 | + return 0; | |
22451 | + | |
22452 | + task_lock(p); | |
22453 | + if ((p->exit_state & (EXIT_ZOMBIE | EXIT_DEAD)) || | |
22454 | + !have_same_root(current, p)) { | |
22455 | + task_unlock(p); | |
22456 | + return 1; | |
22457 | + } | |
22458 | + task_unlock(p); | |
22459 | +#endif | |
22460 | + return 0; | |
22461 | +} | |
22462 | + | |
22463 | +EXPORT_SYMBOL(gr_pid_is_chrooted); | |
22464 | + | |
22465 | +#if defined(CONFIG_GRKERNSEC_CHROOT_DOUBLE) || defined(CONFIG_GRKERNSEC_CHROOT_FCHDIR) | |
22466 | +int gr_is_outside_chroot(const struct dentry *u_dentry, const struct vfsmount *u_mnt) | |
22467 | +{ | |
22468 | + struct dentry *dentry = (struct dentry *)u_dentry; | |
22469 | + struct vfsmount *mnt = (struct vfsmount *)u_mnt; | |
22470 | + struct dentry *realroot; | |
22471 | + struct vfsmount *realrootmnt; | |
22472 | + struct dentry *currentroot; | |
22473 | + struct vfsmount *currentmnt; | |
da5b3fc8 | 22474 | + struct task_struct *reaper = current->nsproxy->pid_ns->child_reaper; |
50425a20 | 22475 | + int ret = 1; |
22476 | + | |
22477 | + read_lock(&reaper->fs->lock); | |
4dee9bd5 | 22478 | + realrootmnt = mntget(reaper->fs->root.mnt); |
22479 | + realroot = dget(reaper->fs->root.dentry); | |
50425a20 | 22480 | + read_unlock(&reaper->fs->lock); |
22481 | + | |
22482 | + read_lock(¤t->fs->lock); | |
4dee9bd5 | 22483 | + currentmnt = mntget(current->fs->root.mnt); |
22484 | + currentroot = dget(current->fs->root.dentry); | |
50425a20 | 22485 | + read_unlock(¤t->fs->lock); |
22486 | + | |
22487 | + spin_lock(&dcache_lock); | |
22488 | + for (;;) { | |
22489 | + if (unlikely((dentry == realroot && mnt == realrootmnt) | |
22490 | + || (dentry == currentroot && mnt == currentmnt))) | |
22491 | + break; | |
22492 | + if (unlikely(dentry == mnt->mnt_root || IS_ROOT(dentry))) { | |
22493 | + if (mnt->mnt_parent == mnt) | |
22494 | + break; | |
22495 | + dentry = mnt->mnt_mountpoint; | |
22496 | + mnt = mnt->mnt_parent; | |
22497 | + continue; | |
22498 | + } | |
22499 | + dentry = dentry->d_parent; | |
22500 | + } | |
22501 | + spin_unlock(&dcache_lock); | |
22502 | + | |
22503 | + dput(currentroot); | |
22504 | + mntput(currentmnt); | |
22505 | + | |
22506 | + /* access is outside of chroot */ | |
22507 | + if (dentry == realroot && mnt == realrootmnt) | |
22508 | + ret = 0; | |
22509 | + | |
22510 | + dput(realroot); | |
22511 | + mntput(realrootmnt); | |
22512 | + return ret; | |
22513 | +} | |
22514 | +#endif | |
22515 | + | |
22516 | +int | |
22517 | +gr_chroot_fchdir(struct dentry *u_dentry, struct vfsmount *u_mnt) | |
22518 | +{ | |
22519 | +#ifdef CONFIG_GRKERNSEC_CHROOT_FCHDIR | |
22520 | + if (!grsec_enable_chroot_fchdir) | |
22521 | + return 1; | |
22522 | + | |
22523 | + if (!proc_is_chrooted(current)) | |
22524 | + return 1; | |
22525 | + else if (!gr_is_outside_chroot(u_dentry, u_mnt)) { | |
22526 | + gr_log_fs_generic(GR_DONT_AUDIT, GR_CHROOT_FCHDIR_MSG, u_dentry, u_mnt); | |
22527 | + return 0; | |
22528 | + } | |
22529 | +#endif | |
22530 | + return 1; | |
22531 | +} | |
22532 | + | |
22533 | +int | |
22534 | +gr_chroot_shmat(const pid_t shm_cprid, const pid_t shm_lapid, | |
22535 | + const time_t shm_createtime) | |
22536 | +{ | |
22537 | +#ifdef CONFIG_GRKERNSEC_CHROOT_SHMAT | |
22538 | + struct pid *pid = NULL; | |
22539 | + time_t starttime; | |
22540 | + | |
22541 | + if (unlikely(!grsec_enable_chroot_shmat)) | |
22542 | + return 1; | |
22543 | + | |
22544 | + if (likely(!proc_is_chrooted(current))) | |
22545 | + return 1; | |
22546 | + | |
22547 | + read_lock(&tasklist_lock); | |
22548 | + | |
22549 | + pid = find_pid(shm_cprid); | |
22550 | + if (pid) { | |
22551 | + struct task_struct *p; | |
22552 | + p = pid_task(pid, PIDTYPE_PID); | |
22553 | + task_lock(p); | |
22554 | + starttime = p->start_time.tv_sec; | |
22555 | + if (unlikely(!have_same_root(current, p) && | |
b2ee8b1e | 22556 | + time_before_eq((unsigned long)starttime, (unsigned long)shm_createtime))) { |
50425a20 | 22557 | + task_unlock(p); |
22558 | + read_unlock(&tasklist_lock); | |
22559 | + gr_log_noargs(GR_DONT_AUDIT, GR_SHMAT_CHROOT_MSG); | |
22560 | + return 0; | |
22561 | + } | |
22562 | + task_unlock(p); | |
22563 | + } else { | |
22564 | + pid = find_pid(shm_lapid); | |
22565 | + if (pid) { | |
22566 | + struct task_struct *p; | |
22567 | + p = pid_task(pid, PIDTYPE_PID); | |
22568 | + task_lock(p); | |
22569 | + if (unlikely(!have_same_root(current, p))) { | |
22570 | + task_unlock(p); | |
22571 | + read_unlock(&tasklist_lock); | |
22572 | + gr_log_noargs(GR_DONT_AUDIT, GR_SHMAT_CHROOT_MSG); | |
22573 | + return 0; | |
22574 | + } | |
22575 | + task_unlock(p); | |
22576 | + } | |
22577 | + } | |
22578 | + | |
22579 | + read_unlock(&tasklist_lock); | |
22580 | +#endif | |
22581 | + return 1; | |
22582 | +} | |
22583 | + | |
22584 | +void | |
22585 | +gr_log_chroot_exec(const struct dentry *dentry, const struct vfsmount *mnt) | |
22586 | +{ | |
22587 | +#ifdef CONFIG_GRKERNSEC_CHROOT_EXECLOG | |
22588 | + if (grsec_enable_chroot_execlog && proc_is_chrooted(current)) | |
22589 | + gr_log_fs_generic(GR_DO_AUDIT, GR_EXEC_CHROOT_MSG, dentry, mnt); | |
22590 | +#endif | |
22591 | + return; | |
22592 | +} | |
22593 | + | |
22594 | +int | |
22595 | +gr_handle_chroot_mknod(const struct dentry *dentry, | |
22596 | + const struct vfsmount *mnt, const int mode) | |
22597 | +{ | |
22598 | +#ifdef CONFIG_GRKERNSEC_CHROOT_MKNOD | |
22599 | + if (grsec_enable_chroot_mknod && !S_ISFIFO(mode) && !S_ISREG(mode) && | |
22600 | + proc_is_chrooted(current)) { | |
22601 | + gr_log_fs_generic(GR_DONT_AUDIT, GR_MKNOD_CHROOT_MSG, dentry, mnt); | |
22602 | + return -EPERM; | |
22603 | + } | |
22604 | +#endif | |
22605 | + return 0; | |
22606 | +} | |
22607 | + | |
22608 | +int | |
22609 | +gr_handle_chroot_mount(const struct dentry *dentry, | |
22610 | + const struct vfsmount *mnt, const char *dev_name) | |
22611 | +{ | |
22612 | +#ifdef CONFIG_GRKERNSEC_CHROOT_MOUNT | |
22613 | + if (grsec_enable_chroot_mount && proc_is_chrooted(current)) { | |
22614 | + gr_log_str_fs(GR_DONT_AUDIT, GR_MOUNT_CHROOT_MSG, dev_name, dentry, mnt); | |
22615 | + return -EPERM; | |
22616 | + } | |
22617 | +#endif | |
22618 | + return 0; | |
22619 | +} | |
22620 | + | |
22621 | +int | |
22622 | +gr_handle_chroot_pivot(void) | |
22623 | +{ | |
22624 | +#ifdef CONFIG_GRKERNSEC_CHROOT_PIVOT | |
22625 | + if (grsec_enable_chroot_pivot && proc_is_chrooted(current)) { | |
22626 | + gr_log_noargs(GR_DONT_AUDIT, GR_PIVOT_CHROOT_MSG); | |
22627 | + return -EPERM; | |
22628 | + } | |
22629 | +#endif | |
22630 | + return 0; | |
22631 | +} | |
22632 | + | |
22633 | +int | |
22634 | +gr_handle_chroot_chroot(const struct dentry *dentry, const struct vfsmount *mnt) | |
22635 | +{ | |
22636 | +#ifdef CONFIG_GRKERNSEC_CHROOT_DOUBLE | |
22637 | + if (grsec_enable_chroot_double && proc_is_chrooted(current) && | |
22638 | + !gr_is_outside_chroot(dentry, mnt)) { | |
22639 | + gr_log_fs_generic(GR_DONT_AUDIT, GR_CHROOT_CHROOT_MSG, dentry, mnt); | |
22640 | + return -EPERM; | |
22641 | + } | |
22642 | +#endif | |
22643 | + return 0; | |
22644 | +} | |
22645 | + | |
22646 | +void | |
22647 | +gr_handle_chroot_caps(struct task_struct *task) | |
22648 | +{ | |
22649 | +#ifdef CONFIG_GRKERNSEC_CHROOT_CAPS | |
22650 | + if (grsec_enable_chroot_caps && proc_is_chrooted(task)) { | |
4dee9bd5 | 22651 | + kernel_cap_t chroot_caps = GR_CHROOT_CAPS; |
50425a20 | 22652 | + task->cap_permitted = |
4dee9bd5 | 22653 | + cap_drop(task->cap_permitted, chroot_caps); |
50425a20 | 22654 | + task->cap_inheritable = |
4dee9bd5 | 22655 | + cap_drop(task->cap_inheritable, chroot_caps); |
50425a20 | 22656 | + task->cap_effective = |
4dee9bd5 | 22657 | + cap_drop(task->cap_effective, chroot_caps); |
50425a20 | 22658 | + } |
22659 | +#endif | |
22660 | + return; | |
22661 | +} | |
22662 | + | |
22663 | +int | |
22664 | +gr_handle_chroot_sysctl(const int op) | |
22665 | +{ | |
22666 | +#ifdef CONFIG_GRKERNSEC_CHROOT_SYSCTL | |
22667 | + if (grsec_enable_chroot_sysctl && proc_is_chrooted(current) | |
22668 | + && (op & 002)) | |
22669 | + return -EACCES; | |
22670 | +#endif | |
22671 | + return 0; | |
22672 | +} | |
22673 | + | |
22674 | +void | |
4dee9bd5 | 22675 | +gr_handle_chroot_chdir(struct path *path) |
50425a20 | 22676 | +{ |
22677 | +#ifdef CONFIG_GRKERNSEC_CHROOT_CHDIR | |
22678 | + if (grsec_enable_chroot_chdir) | |
4dee9bd5 | 22679 | + set_fs_pwd(current->fs, path); |
50425a20 | 22680 | +#endif |
22681 | + return; | |
22682 | +} | |
22683 | + | |
22684 | +int | |
22685 | +gr_handle_chroot_chmod(const struct dentry *dentry, | |
22686 | + const struct vfsmount *mnt, const int mode) | |
22687 | +{ | |
22688 | +#ifdef CONFIG_GRKERNSEC_CHROOT_CHMOD | |
22689 | + if (grsec_enable_chroot_chmod && | |
22690 | + ((mode & S_ISUID) || ((mode & (S_ISGID | S_IXGRP)) == (S_ISGID | S_IXGRP))) && | |
22691 | + proc_is_chrooted(current)) { | |
22692 | + gr_log_fs_generic(GR_DONT_AUDIT, GR_CHMOD_CHROOT_MSG, dentry, mnt); | |
22693 | + return -EPERM; | |
22694 | + } | |
22695 | +#endif | |
22696 | + return 0; | |
22697 | +} | |
22698 | + | |
22699 | +#ifdef CONFIG_SECURITY | |
22700 | +EXPORT_SYMBOL(gr_handle_chroot_caps); | |
22701 | +#endif | |
4dee9bd5 | 22702 | diff -urNp linux-2.6.25.4/grsecurity/grsec_disabled.c linux-2.6.25.4/grsecurity/grsec_disabled.c |
22703 | --- linux-2.6.25.4/grsecurity/grsec_disabled.c 1969-12-31 19:00:00.000000000 -0500 | |
22704 | +++ linux-2.6.25.4/grsecurity/grsec_disabled.c 2008-05-18 13:33:16.000000000 -0400 | |
50425a20 | 22705 | @@ -0,0 +1,418 @@ |
22706 | +#include <linux/kernel.h> | |
22707 | +#include <linux/module.h> | |
22708 | +#include <linux/sched.h> | |
22709 | +#include <linux/file.h> | |
22710 | +#include <linux/fs.h> | |
22711 | +#include <linux/kdev_t.h> | |
22712 | +#include <linux/net.h> | |
22713 | +#include <linux/in.h> | |
22714 | +#include <linux/ip.h> | |
22715 | +#include <linux/skbuff.h> | |
22716 | +#include <linux/sysctl.h> | |
22717 | + | |
22718 | +#ifdef CONFIG_PAX_HAVE_ACL_FLAGS | |
22719 | +void | |
22720 | +pax_set_initial_flags(struct linux_binprm *bprm) | |
22721 | +{ | |
22722 | + return; | |
22723 | +} | |
22724 | +#endif | |
22725 | + | |
22726 | +#ifdef CONFIG_SYSCTL | |
22727 | +__u32 | |
e87b9006 | 22728 | +gr_handle_sysctl(const struct ctl_table * table, const int op) |
50425a20 | 22729 | +{ |
78fdc4fb | 22730 | + return 0; |
50425a20 | 22731 | +} |
22732 | +#endif | |
22733 | + | |
22734 | +int | |
22735 | +gr_acl_is_enabled(void) | |
22736 | +{ | |
22737 | + return 0; | |
22738 | +} | |
22739 | + | |
22740 | +int | |
22741 | +gr_handle_rawio(const struct inode *inode) | |
22742 | +{ | |
22743 | + return 0; | |
22744 | +} | |
22745 | + | |
22746 | +void | |
22747 | +gr_acl_handle_psacct(struct task_struct *task, const long code) | |
22748 | +{ | |
22749 | + return; | |
22750 | +} | |
22751 | + | |
22752 | +int | |
22753 | +gr_handle_ptrace(struct task_struct *task, const long request) | |
22754 | +{ | |
22755 | + return 0; | |
22756 | +} | |
22757 | + | |
22758 | +int | |
22759 | +gr_handle_proc_ptrace(struct task_struct *task) | |
22760 | +{ | |
22761 | + return 0; | |
22762 | +} | |
22763 | + | |
22764 | +void | |
22765 | +gr_learn_resource(const struct task_struct *task, | |
22766 | + const int res, const unsigned long wanted, const int gt) | |
22767 | +{ | |
22768 | + return; | |
22769 | +} | |
22770 | + | |
22771 | +int | |
22772 | +gr_set_acls(const int type) | |
22773 | +{ | |
22774 | + return 0; | |
22775 | +} | |
22776 | + | |
22777 | +int | |
22778 | +gr_check_hidden_task(const struct task_struct *tsk) | |
22779 | +{ | |
22780 | + return 0; | |
22781 | +} | |
22782 | + | |
22783 | +int | |
22784 | +gr_check_protected_task(const struct task_struct *task) | |
22785 | +{ | |
22786 | + return 0; | |
22787 | +} | |
22788 | + | |
22789 | +void | |
22790 | +gr_copy_label(struct task_struct *tsk) | |
22791 | +{ | |
22792 | + return; | |
22793 | +} | |
22794 | + | |
22795 | +void | |
22796 | +gr_set_pax_flags(struct task_struct *task) | |
22797 | +{ | |
22798 | + return; | |
22799 | +} | |
22800 | + | |
22801 | +int | |
22802 | +gr_set_proc_label(const struct dentry *dentry, const struct vfsmount *mnt) | |
22803 | +{ | |
22804 | + return 0; | |
22805 | +} | |
22806 | + | |
22807 | +void | |
22808 | +gr_handle_delete(const ino_t ino, const dev_t dev) | |
22809 | +{ | |
22810 | + return; | |
22811 | +} | |
22812 | + | |
22813 | +void | |
22814 | +gr_handle_create(const struct dentry *dentry, const struct vfsmount *mnt) | |
22815 | +{ | |
22816 | + return; | |
22817 | +} | |
22818 | + | |
22819 | +void | |
22820 | +gr_handle_crash(struct task_struct *task, const int sig) | |
22821 | +{ | |
22822 | + return; | |
22823 | +} | |
22824 | + | |
22825 | +int | |
22826 | +gr_check_crash_exec(const struct file *filp) | |
22827 | +{ | |
22828 | + return 0; | |
22829 | +} | |
22830 | + | |
22831 | +int | |
22832 | +gr_check_crash_uid(const uid_t uid) | |
22833 | +{ | |
22834 | + return 0; | |
22835 | +} | |
22836 | + | |
22837 | +void | |
22838 | +gr_handle_rename(struct inode *old_dir, struct inode *new_dir, | |
22839 | + struct dentry *old_dentry, | |
22840 | + struct dentry *new_dentry, | |
22841 | + struct vfsmount *mnt, const __u8 replace) | |
22842 | +{ | |
22843 | + return; | |
22844 | +} | |
22845 | + | |
22846 | +int | |
22847 | +gr_search_socket(const int family, const int type, const int protocol) | |
22848 | +{ | |
22849 | + return 1; | |
22850 | +} | |
22851 | + | |
22852 | +int | |
22853 | +gr_search_connectbind(const int mode, const struct socket *sock, | |
22854 | + const struct sockaddr_in *addr) | |
22855 | +{ | |
22856 | + return 1; | |
22857 | +} | |
22858 | + | |
22859 | +int | |
22860 | +gr_task_is_capable(struct task_struct *task, const int cap) | |
22861 | +{ | |
22862 | + return 1; | |
22863 | +} | |
22864 | + | |
22865 | +int | |
22866 | +gr_is_capable_nolog(const int cap) | |
22867 | +{ | |
22868 | + return 1; | |
22869 | +} | |
22870 | + | |
22871 | +void | |
22872 | +gr_handle_alertkill(struct task_struct *task) | |
22873 | +{ | |
22874 | + return; | |
22875 | +} | |
22876 | + | |
22877 | +__u32 | |
22878 | +gr_acl_handle_execve(const struct dentry * dentry, const struct vfsmount * mnt) | |
22879 | +{ | |
22880 | + return 1; | |
22881 | +} | |
22882 | + | |
22883 | +__u32 | |
22884 | +gr_acl_handle_hidden_file(const struct dentry * dentry, | |
22885 | + const struct vfsmount * mnt) | |
22886 | +{ | |
22887 | + return 1; | |
22888 | +} | |
22889 | + | |
22890 | +__u32 | |
22891 | +gr_acl_handle_open(const struct dentry * dentry, const struct vfsmount * mnt, | |
22892 | + const int fmode) | |
22893 | +{ | |
22894 | + return 1; | |
22895 | +} | |
22896 | + | |
22897 | +__u32 | |
22898 | +gr_acl_handle_rmdir(const struct dentry * dentry, const struct vfsmount * mnt) | |
22899 | +{ | |
22900 | + return 1; | |
22901 | +} | |
22902 | + | |
22903 | +__u32 | |
22904 | +gr_acl_handle_unlink(const struct dentry * dentry, const struct vfsmount * mnt) | |
22905 | +{ | |
22906 | + return 1; | |
22907 | +} | |
22908 | + | |
22909 | +int | |
22910 | +gr_acl_handle_mmap(const struct file *file, const unsigned long prot, | |
22911 | + unsigned int *vm_flags) | |
22912 | +{ | |
22913 | + return 1; | |
22914 | +} | |
22915 | + | |
22916 | +__u32 | |
22917 | +gr_acl_handle_truncate(const struct dentry * dentry, | |
22918 | + const struct vfsmount * mnt) | |
22919 | +{ | |
22920 | + return 1; | |
22921 | +} | |
22922 | + | |
22923 | +__u32 | |
22924 | +gr_acl_handle_utime(const struct dentry * dentry, const struct vfsmount * mnt) | |
22925 | +{ | |
22926 | + return 1; | |
22927 | +} | |
22928 | + | |
22929 | +__u32 | |
22930 | +gr_acl_handle_access(const struct dentry * dentry, | |
22931 | + const struct vfsmount * mnt, const int fmode) | |
22932 | +{ | |
22933 | + return 1; | |
22934 | +} | |
22935 | + | |
22936 | +__u32 | |
22937 | +gr_acl_handle_fchmod(const struct dentry * dentry, const struct vfsmount * mnt, | |
22938 | + mode_t mode) | |
22939 | +{ | |
22940 | + return 1; | |
22941 | +} | |
22942 | + | |
22943 | +__u32 | |
22944 | +gr_acl_handle_chmod(const struct dentry * dentry, const struct vfsmount * mnt, | |
22945 | + mode_t mode) | |
22946 | +{ | |
22947 | + return 1; | |
22948 | +} | |
22949 | + | |
22950 | +__u32 | |
22951 | +gr_acl_handle_chown(const struct dentry * dentry, const struct vfsmount * mnt) | |
22952 | +{ | |
22953 | + return 1; | |
22954 | +} | |
22955 | + | |
22956 | +void | |
22957 | +grsecurity_init(void) | |
22958 | +{ | |
22959 | + return; | |
22960 | +} | |
22961 | + | |
22962 | +__u32 | |
22963 | +gr_acl_handle_mknod(const struct dentry * new_dentry, | |
22964 | + const struct dentry * parent_dentry, | |
22965 | + const struct vfsmount * parent_mnt, | |
22966 | + const int mode) | |
22967 | +{ | |
22968 | + return 1; | |
22969 | +} | |
22970 | + | |
22971 | +__u32 | |
22972 | +gr_acl_handle_mkdir(const struct dentry * new_dentry, | |
22973 | + const struct dentry * parent_dentry, | |
22974 | + const struct vfsmount * parent_mnt) | |
22975 | +{ | |
22976 | + return 1; | |
22977 | +} | |
22978 | + | |
22979 | +__u32 | |
22980 | +gr_acl_handle_symlink(const struct dentry * new_dentry, | |
22981 | + const struct dentry * parent_dentry, | |
22982 | + const struct vfsmount * parent_mnt, const char *from) | |
22983 | +{ | |
22984 | + return 1; | |
22985 | +} | |
22986 | + | |
22987 | +__u32 | |
22988 | +gr_acl_handle_link(const struct dentry * new_dentry, | |
22989 | + const struct dentry * parent_dentry, | |
22990 | + const struct vfsmount * parent_mnt, | |
22991 | + const struct dentry * old_dentry, | |
22992 | + const struct vfsmount * old_mnt, const char *to) | |
22993 | +{ | |
22994 | + return 1; | |
22995 | +} | |
22996 | + | |
22997 | +int | |
22998 | +gr_acl_handle_rename(const struct dentry *new_dentry, | |
22999 | + const struct dentry *parent_dentry, | |
23000 | + const struct vfsmount *parent_mnt, | |
23001 | + const struct dentry *old_dentry, | |
23002 | + const struct inode *old_parent_inode, | |
23003 | + const struct vfsmount *old_mnt, const char *newname) | |
23004 | +{ | |
23005 | + return 0; | |
23006 | +} | |
23007 | + | |
23008 | +int | |
23009 | +gr_acl_handle_filldir(const struct file *file, const char *name, | |
23010 | + const int namelen, const ino_t ino) | |
23011 | +{ | |
23012 | + return 1; | |
23013 | +} | |
23014 | + | |
23015 | +int | |
23016 | +gr_handle_shmat(const pid_t shm_cprid, const pid_t shm_lapid, | |
23017 | + const time_t shm_createtime, const uid_t cuid, const int shmid) | |
23018 | +{ | |
23019 | + return 1; | |
23020 | +} | |
23021 | + | |
23022 | +int | |
23023 | +gr_search_bind(const struct socket *sock, const struct sockaddr_in *addr) | |
23024 | +{ | |
23025 | + return 1; | |
23026 | +} | |
23027 | + | |
23028 | +int | |
23029 | +gr_search_accept(const struct socket *sock) | |
23030 | +{ | |
23031 | + return 1; | |
23032 | +} | |
23033 | + | |
23034 | +int | |
23035 | +gr_search_listen(const struct socket *sock) | |
23036 | +{ | |
23037 | + return 1; | |
23038 | +} | |
23039 | + | |
23040 | +int | |
23041 | +gr_search_connect(const struct socket *sock, const struct sockaddr_in *addr) | |
23042 | +{ | |
23043 | + return 1; | |
23044 | +} | |
23045 | + | |
23046 | +__u32 | |
23047 | +gr_acl_handle_unix(const struct dentry * dentry, const struct vfsmount * mnt) | |
23048 | +{ | |
23049 | + return 1; | |
23050 | +} | |
23051 | + | |
23052 | +__u32 | |
23053 | +gr_acl_handle_creat(const struct dentry * dentry, | |
23054 | + const struct dentry * p_dentry, | |
23055 | + const struct vfsmount * p_mnt, const int fmode, | |
23056 | + const int imode) | |
23057 | +{ | |
23058 | + return 1; | |
23059 | +} | |
23060 | + | |
23061 | +void | |
23062 | +gr_acl_handle_exit(void) | |
23063 | +{ | |
23064 | + return; | |
23065 | +} | |
23066 | + | |
23067 | +int | |
23068 | +gr_acl_handle_mprotect(const struct file *file, const unsigned long prot) | |
23069 | +{ | |
23070 | + return 1; | |
23071 | +} | |
23072 | + | |
23073 | +void | |
23074 | +gr_set_role_label(const uid_t uid, const gid_t gid) | |
23075 | +{ | |
23076 | + return; | |
23077 | +} | |
23078 | + | |
23079 | +int | |
23080 | +gr_acl_handle_procpidmem(const struct task_struct *task) | |
23081 | +{ | |
23082 | + return 0; | |
23083 | +} | |
23084 | + | |
23085 | +int | |
23086 | +gr_search_udp_recvmsg(const struct sock *sk, const struct sk_buff *skb) | |
23087 | +{ | |
23088 | + return 1; | |
23089 | +} | |
23090 | + | |
23091 | +int | |
23092 | +gr_search_udp_sendmsg(const struct sock *sk, const struct sockaddr_in *addr) | |
23093 | +{ | |
23094 | + return 1; | |
23095 | +} | |
23096 | + | |
23097 | +void | |
23098 | +gr_set_kernel_label(struct task_struct *task) | |
23099 | +{ | |
23100 | + return; | |
23101 | +} | |
23102 | + | |
23103 | +int | |
23104 | +gr_check_user_change(int real, int effective, int fs) | |
23105 | +{ | |
23106 | + return 0; | |
23107 | +} | |
23108 | + | |
23109 | +int | |
23110 | +gr_check_group_change(int real, int effective, int fs) | |
23111 | +{ | |
23112 | + return 0; | |
23113 | +} | |
23114 | + | |
23115 | + | |
23116 | +EXPORT_SYMBOL(gr_task_is_capable); | |
23117 | +EXPORT_SYMBOL(gr_is_capable_nolog); | |
23118 | +EXPORT_SYMBOL(gr_learn_resource); | |
23119 | +EXPORT_SYMBOL(gr_set_kernel_label); | |
23120 | +#ifdef CONFIG_SECURITY | |
23121 | +EXPORT_SYMBOL(gr_check_user_change); | |
23122 | +EXPORT_SYMBOL(gr_check_group_change); | |
23123 | +#endif | |
4dee9bd5 | 23124 | diff -urNp linux-2.6.25.4/grsecurity/grsec_exec.c linux-2.6.25.4/grsecurity/grsec_exec.c |
23125 | --- linux-2.6.25.4/grsecurity/grsec_exec.c 1969-12-31 19:00:00.000000000 -0500 | |
23126 | +++ linux-2.6.25.4/grsecurity/grsec_exec.c 2008-05-18 13:33:16.000000000 -0400 | |
50425a20 | 23127 | @@ -0,0 +1,88 @@ |
23128 | +#include <linux/kernel.h> | |
23129 | +#include <linux/sched.h> | |
23130 | +#include <linux/file.h> | |
23131 | +#include <linux/binfmts.h> | |
23132 | +#include <linux/smp_lock.h> | |
23133 | +#include <linux/fs.h> | |
23134 | +#include <linux/types.h> | |
23135 | +#include <linux/grdefs.h> | |
23136 | +#include <linux/grinternal.h> | |
23137 | +#include <linux/capability.h> | |
23138 | + | |
23139 | +#include <asm/uaccess.h> | |
23140 | + | |
23141 | +#ifdef CONFIG_GRKERNSEC_EXECLOG | |
23142 | +static char gr_exec_arg_buf[132]; | |
23143 | +static DECLARE_MUTEX(gr_exec_arg_sem); | |
23144 | +#endif | |
23145 | + | |
23146 | +int | |
23147 | +gr_handle_nproc(void) | |
23148 | +{ | |
23149 | +#ifdef CONFIG_GRKERNSEC_EXECVE | |
23150 | + if (grsec_enable_execve && current->user && | |
23151 | + (atomic_read(¤t->user->processes) > | |
23152 | + current->signal->rlim[RLIMIT_NPROC].rlim_cur) && | |
23153 | + !capable(CAP_SYS_ADMIN) && !capable(CAP_SYS_RESOURCE)) { | |
23154 | + gr_log_noargs(GR_DONT_AUDIT, GR_NPROC_MSG); | |
23155 | + return -EAGAIN; | |
23156 | + } | |
23157 | +#endif | |
23158 | + return 0; | |
23159 | +} | |
23160 | + | |
23161 | +void | |
23162 | +gr_handle_exec_args(struct linux_binprm *bprm, const char __user *__user *argv) | |
23163 | +{ | |
23164 | +#ifdef CONFIG_GRKERNSEC_EXECLOG | |
23165 | + char *grarg = gr_exec_arg_buf; | |
23166 | + unsigned int i, x, execlen = 0; | |
23167 | + char c; | |
23168 | + | |
23169 | + if (!((grsec_enable_execlog && grsec_enable_group && | |
23170 | + in_group_p(grsec_audit_gid)) | |
23171 | + || (grsec_enable_execlog && !grsec_enable_group))) | |
23172 | + return; | |
23173 | + | |
23174 | + down(&gr_exec_arg_sem); | |
23175 | + memset(grarg, 0, sizeof(gr_exec_arg_buf)); | |
23176 | + | |
23177 | + if (unlikely(argv == NULL)) | |
23178 | + goto log; | |
23179 | + | |
23180 | + for (i = 0; i < bprm->argc && execlen < 128; i++) { | |
23181 | + const char __user *p; | |
23182 | + unsigned int len; | |
23183 | + | |
23184 | + if (copy_from_user(&p, argv + i, sizeof(p))) | |
23185 | + goto log; | |
23186 | + if (!p) | |
23187 | + goto log; | |
23188 | + len = strnlen_user(p, 128 - execlen); | |
23189 | + if (len > 128 - execlen) | |
23190 | + len = 128 - execlen; | |
23191 | + else if (len > 0) | |
23192 | + len--; | |
23193 | + if (copy_from_user(grarg + execlen, p, len)) | |
23194 | + goto log; | |
23195 | + | |
23196 | + /* rewrite unprintable characters */ | |
23197 | + for (x = 0; x < len; x++) { | |
23198 | + c = *(grarg + execlen + x); | |
23199 | + if (c < 32 || c > 126) | |
23200 | + *(grarg + execlen + x) = ' '; | |
23201 | + } | |
23202 | + | |
23203 | + execlen += len; | |
23204 | + *(grarg + execlen) = ' '; | |
23205 | + *(grarg + execlen + 1) = '\0'; | |
23206 | + execlen++; | |
23207 | + } | |
23208 | + | |
23209 | + log: | |
4dee9bd5 | 23210 | + gr_log_fs_str(GR_DO_AUDIT, GR_EXEC_AUDIT_MSG, bprm->file->f_path.dentry, |
23211 | + bprm->file->f_path.mnt, grarg); | |
50425a20 | 23212 | + up(&gr_exec_arg_sem); |
23213 | +#endif | |
23214 | + return; | |
23215 | +} | |
4dee9bd5 | 23216 | diff -urNp linux-2.6.25.4/grsecurity/grsec_fifo.c linux-2.6.25.4/grsecurity/grsec_fifo.c |
23217 | --- linux-2.6.25.4/grsecurity/grsec_fifo.c 1969-12-31 19:00:00.000000000 -0500 | |
23218 | +++ linux-2.6.25.4/grsecurity/grsec_fifo.c 2008-05-18 13:33:16.000000000 -0400 | |
50425a20 | 23219 | @@ -0,0 +1,22 @@ |
23220 | +#include <linux/kernel.h> | |
23221 | +#include <linux/sched.h> | |
23222 | +#include <linux/fs.h> | |
23223 | +#include <linux/file.h> | |
23224 | +#include <linux/grinternal.h> | |
23225 | + | |
23226 | +int | |
23227 | +gr_handle_fifo(const struct dentry *dentry, const struct vfsmount *mnt, | |
23228 | + const struct dentry *dir, const int flag, const int acc_mode) | |
23229 | +{ | |
23230 | +#ifdef CONFIG_GRKERNSEC_FIFO | |
23231 | + if (grsec_enable_fifo && S_ISFIFO(dentry->d_inode->i_mode) && | |
23232 | + !(flag & O_EXCL) && (dir->d_inode->i_mode & S_ISVTX) && | |
23233 | + (dentry->d_inode->i_uid != dir->d_inode->i_uid) && | |
23234 | + (current->fsuid != dentry->d_inode->i_uid)) { | |
23235 | + if (!generic_permission(dentry->d_inode, acc_mode, NULL)) | |
23236 | + gr_log_fs_int2(GR_DONT_AUDIT, GR_FIFO_MSG, dentry, mnt, dentry->d_inode->i_uid, dentry->d_inode->i_gid); | |
23237 | + return -EACCES; | |
23238 | + } | |
23239 | +#endif | |
23240 | + return 0; | |
23241 | +} | |
4dee9bd5 | 23242 | diff -urNp linux-2.6.25.4/grsecurity/grsec_fork.c linux-2.6.25.4/grsecurity/grsec_fork.c |
23243 | --- linux-2.6.25.4/grsecurity/grsec_fork.c 1969-12-31 19:00:00.000000000 -0500 | |
23244 | +++ linux-2.6.25.4/grsecurity/grsec_fork.c 2008-05-18 13:33:16.000000000 -0400 | |
50425a20 | 23245 | @@ -0,0 +1,15 @@ |
23246 | +#include <linux/kernel.h> | |
23247 | +#include <linux/sched.h> | |
23248 | +#include <linux/grsecurity.h> | |
23249 | +#include <linux/grinternal.h> | |
23250 | +#include <linux/errno.h> | |
23251 | + | |
23252 | +void | |
23253 | +gr_log_forkfail(const int retval) | |
23254 | +{ | |
23255 | +#ifdef CONFIG_GRKERNSEC_FORKFAIL | |
23256 | + if (grsec_enable_forkfail && retval != -ERESTARTNOINTR) | |
23257 | + gr_log_int(GR_DONT_AUDIT, GR_FAILFORK_MSG, retval); | |
23258 | +#endif | |
23259 | + return; | |
23260 | +} | |
4dee9bd5 | 23261 | diff -urNp linux-2.6.25.4/grsecurity/grsec_init.c linux-2.6.25.4/grsecurity/grsec_init.c |
23262 | --- linux-2.6.25.4/grsecurity/grsec_init.c 1969-12-31 19:00:00.000000000 -0500 | |
23263 | +++ linux-2.6.25.4/grsecurity/grsec_init.c 2008-05-18 13:33:16.000000000 -0400 | |
da5b3fc8 | 23264 | @@ -0,0 +1,226 @@ |
50425a20 | 23265 | +#include <linux/kernel.h> |
23266 | +#include <linux/sched.h> | |
23267 | +#include <linux/mm.h> | |
23268 | +#include <linux/smp_lock.h> | |
23269 | +#include <linux/gracl.h> | |
23270 | +#include <linux/slab.h> | |
23271 | +#include <linux/vmalloc.h> | |
23272 | +#include <linux/percpu.h> | |
23273 | + | |
50425a20 | 23274 | +int grsec_enable_link; |
23275 | +int grsec_enable_dmesg; | |
23276 | +int grsec_enable_fifo; | |
23277 | +int grsec_enable_execve; | |
23278 | +int grsec_enable_execlog; | |
23279 | +int grsec_enable_signal; | |
23280 | +int grsec_enable_forkfail; | |
23281 | +int grsec_enable_time; | |
23282 | +int grsec_enable_audit_textrel; | |
23283 | +int grsec_enable_group; | |
23284 | +int grsec_audit_gid; | |
23285 | +int grsec_enable_chdir; | |
23286 | +int grsec_enable_audit_ipc; | |
23287 | +int grsec_enable_mount; | |
23288 | +int grsec_enable_chroot_findtask; | |
23289 | +int grsec_enable_chroot_mount; | |
23290 | +int grsec_enable_chroot_shmat; | |
23291 | +int grsec_enable_chroot_fchdir; | |
23292 | +int grsec_enable_chroot_double; | |
23293 | +int grsec_enable_chroot_pivot; | |
23294 | +int grsec_enable_chroot_chdir; | |
23295 | +int grsec_enable_chroot_chmod; | |
23296 | +int grsec_enable_chroot_mknod; | |
23297 | +int grsec_enable_chroot_nice; | |
23298 | +int grsec_enable_chroot_execlog; | |
23299 | +int grsec_enable_chroot_caps; | |
23300 | +int grsec_enable_chroot_sysctl; | |
23301 | +int grsec_enable_chroot_unix; | |
23302 | +int grsec_enable_tpe; | |
23303 | +int grsec_tpe_gid; | |
23304 | +int grsec_enable_tpe_all; | |
23305 | +int grsec_enable_socket_all; | |
23306 | +int grsec_socket_all_gid; | |
23307 | +int grsec_enable_socket_client; | |
23308 | +int grsec_socket_client_gid; | |
23309 | +int grsec_enable_socket_server; | |
23310 | +int grsec_socket_server_gid; | |
23311 | +int grsec_resource_logging; | |
23312 | +int grsec_lock; | |
23313 | + | |
23314 | +spinlock_t grsec_alert_lock = SPIN_LOCK_UNLOCKED; | |
23315 | +unsigned long grsec_alert_wtime = 0; | |
23316 | +unsigned long grsec_alert_fyet = 0; | |
23317 | + | |
23318 | +spinlock_t grsec_audit_lock = SPIN_LOCK_UNLOCKED; | |
23319 | + | |
23320 | +rwlock_t grsec_exec_file_lock = RW_LOCK_UNLOCKED; | |
23321 | + | |
23322 | +char *gr_shared_page[4]; | |
23323 | + | |
23324 | +char *gr_alert_log_fmt; | |
23325 | +char *gr_audit_log_fmt; | |
23326 | +char *gr_alert_log_buf; | |
23327 | +char *gr_audit_log_buf; | |
23328 | + | |
23329 | +extern struct gr_arg *gr_usermode; | |
23330 | +extern unsigned char *gr_system_salt; | |
23331 | +extern unsigned char *gr_system_sum; | |
23332 | + | |
23333 | +void | |
23334 | +grsecurity_init(void) | |
23335 | +{ | |
23336 | + int j; | |
23337 | + /* create the per-cpu shared pages */ | |
23338 | + | |
50425a20 | 23339 | + for (j = 0; j < 4; j++) { |
23340 | + gr_shared_page[j] = (char *)__alloc_percpu(PAGE_SIZE); | |
23341 | + if (gr_shared_page[j] == NULL) { | |
23342 | + panic("Unable to allocate grsecurity shared page"); | |
23343 | + return; | |
23344 | + } | |
23345 | + } | |
50425a20 | 23346 | + |
23347 | + /* allocate log buffers */ | |
23348 | + gr_alert_log_fmt = kmalloc(512, GFP_KERNEL); | |
23349 | + if (!gr_alert_log_fmt) { | |
23350 | + panic("Unable to allocate grsecurity alert log format buffer"); | |
23351 | + return; | |
23352 | + } | |
23353 | + gr_audit_log_fmt = kmalloc(512, GFP_KERNEL); | |
23354 | + if (!gr_audit_log_fmt) { | |
23355 | + panic("Unable to allocate grsecurity audit log format buffer"); | |
23356 | + return; | |
23357 | + } | |
23358 | + gr_alert_log_buf = (char *) get_zeroed_page(GFP_KERNEL); | |
23359 | + if (!gr_alert_log_buf) { | |
23360 | + panic("Unable to allocate grsecurity alert log buffer"); | |
23361 | + return; | |
23362 | + } | |
23363 | + gr_audit_log_buf = (char *) get_zeroed_page(GFP_KERNEL); | |
23364 | + if (!gr_audit_log_buf) { | |
23365 | + panic("Unable to allocate grsecurity audit log buffer"); | |
23366 | + return; | |
23367 | + } | |
23368 | + | |
23369 | + /* allocate memory for authentication structure */ | |
23370 | + gr_usermode = kmalloc(sizeof(struct gr_arg), GFP_KERNEL); | |
23371 | + gr_system_salt = kmalloc(GR_SALT_LEN, GFP_KERNEL); | |
23372 | + gr_system_sum = kmalloc(GR_SHA_LEN, GFP_KERNEL); | |
23373 | + | |
23374 | + if (!gr_usermode || !gr_system_salt || !gr_system_sum) { | |
23375 | + panic("Unable to allocate grsecurity authentication structure"); | |
23376 | + return; | |
23377 | + } | |
23378 | + | |
23379 | +#if !defined(CONFIG_GRKERNSEC_SYSCTL) || defined(CONFIG_GRKERNSEC_SYSCTL_ON) | |
23380 | +#ifndef CONFIG_GRKERNSEC_SYSCTL | |
23381 | + grsec_lock = 1; | |
23382 | +#endif | |
50425a20 | 23383 | +#ifdef CONFIG_GRKERNSEC_AUDIT_TEXTREL |
23384 | + grsec_enable_audit_textrel = 1; | |
23385 | +#endif | |
23386 | +#ifdef CONFIG_GRKERNSEC_AUDIT_GROUP | |
23387 | + grsec_enable_group = 1; | |
23388 | + grsec_audit_gid = CONFIG_GRKERNSEC_AUDIT_GID; | |
23389 | +#endif | |
23390 | +#ifdef CONFIG_GRKERNSEC_AUDIT_CHDIR | |
23391 | + grsec_enable_chdir = 1; | |
23392 | +#endif | |
23393 | +#ifdef CONFIG_GRKERNSEC_AUDIT_IPC | |
23394 | + grsec_enable_audit_ipc = 1; | |
23395 | +#endif | |
23396 | +#ifdef CONFIG_GRKERNSEC_AUDIT_MOUNT | |
23397 | + grsec_enable_mount = 1; | |
23398 | +#endif | |
23399 | +#ifdef CONFIG_GRKERNSEC_LINK | |
23400 | + grsec_enable_link = 1; | |
23401 | +#endif | |
23402 | +#ifdef CONFIG_GRKERNSEC_DMESG | |
23403 | + grsec_enable_dmesg = 1; | |
23404 | +#endif | |
23405 | +#ifdef CONFIG_GRKERNSEC_FIFO | |
23406 | + grsec_enable_fifo = 1; | |
23407 | +#endif | |
23408 | +#ifdef CONFIG_GRKERNSEC_EXECVE | |
23409 | + grsec_enable_execve = 1; | |
23410 | +#endif | |
23411 | +#ifdef CONFIG_GRKERNSEC_EXECLOG | |
23412 | + grsec_enable_execlog = 1; | |
23413 | +#endif | |
23414 | +#ifdef CONFIG_GRKERNSEC_SIGNAL | |
23415 | + grsec_enable_signal = 1; | |
23416 | +#endif | |
23417 | +#ifdef CONFIG_GRKERNSEC_FORKFAIL | |
23418 | + grsec_enable_forkfail = 1; | |
23419 | +#endif | |
23420 | +#ifdef CONFIG_GRKERNSEC_TIME | |
23421 | + grsec_enable_time = 1; | |
23422 | +#endif | |
23423 | +#ifdef CONFIG_GRKERNSEC_RESLOG | |
23424 | + grsec_resource_logging = 1; | |
23425 | +#endif | |
23426 | +#ifdef CONFIG_GRKERNSEC_CHROOT_FINDTASK | |
23427 | + grsec_enable_chroot_findtask = 1; | |
23428 | +#endif | |
23429 | +#ifdef CONFIG_GRKERNSEC_CHROOT_UNIX | |
23430 | + grsec_enable_chroot_unix = 1; | |
23431 | +#endif | |
23432 | +#ifdef CONFIG_GRKERNSEC_CHROOT_MOUNT | |
23433 | + grsec_enable_chroot_mount = 1; | |
23434 | +#endif | |
23435 | +#ifdef CONFIG_GRKERNSEC_CHROOT_FCHDIR | |
23436 | + grsec_enable_chroot_fchdir = 1; | |
23437 | +#endif | |
23438 | +#ifdef CONFIG_GRKERNSEC_CHROOT_SHMAT | |
23439 | + grsec_enable_chroot_shmat = 1; | |
23440 | +#endif | |
23441 | +#ifdef CONFIG_GRKERNSEC_CHROOT_DOUBLE | |
23442 | + grsec_enable_chroot_double = 1; | |
23443 | +#endif | |
23444 | +#ifdef CONFIG_GRKERNSEC_CHROOT_PIVOT | |
23445 | + grsec_enable_chroot_pivot = 1; | |
23446 | +#endif | |
23447 | +#ifdef CONFIG_GRKERNSEC_CHROOT_CHDIR | |
23448 | + grsec_enable_chroot_chdir = 1; | |
23449 | +#endif | |
23450 | +#ifdef CONFIG_GRKERNSEC_CHROOT_CHMOD | |
23451 | + grsec_enable_chroot_chmod = 1; | |
23452 | +#endif | |
23453 | +#ifdef CONFIG_GRKERNSEC_CHROOT_MKNOD | |
23454 | + grsec_enable_chroot_mknod = 1; | |
23455 | +#endif | |
23456 | +#ifdef CONFIG_GRKERNSEC_CHROOT_NICE | |
23457 | + grsec_enable_chroot_nice = 1; | |
23458 | +#endif | |
23459 | +#ifdef CONFIG_GRKERNSEC_CHROOT_EXECLOG | |
23460 | + grsec_enable_chroot_execlog = 1; | |
23461 | +#endif | |
23462 | +#ifdef CONFIG_GRKERNSEC_CHROOT_CAPS | |
23463 | + grsec_enable_chroot_caps = 1; | |
23464 | +#endif | |
23465 | +#ifdef CONFIG_GRKERNSEC_CHROOT_SYSCTL | |
23466 | + grsec_enable_chroot_sysctl = 1; | |
23467 | +#endif | |
23468 | +#ifdef CONFIG_GRKERNSEC_TPE | |
23469 | + grsec_enable_tpe = 1; | |
23470 | + grsec_tpe_gid = CONFIG_GRKERNSEC_TPE_GID; | |
23471 | +#ifdef CONFIG_GRKERNSEC_TPE_ALL | |
23472 | + grsec_enable_tpe_all = 1; | |
23473 | +#endif | |
23474 | +#endif | |
23475 | +#ifdef CONFIG_GRKERNSEC_SOCKET_ALL | |
23476 | + grsec_enable_socket_all = 1; | |
23477 | + grsec_socket_all_gid = CONFIG_GRKERNSEC_SOCKET_ALL_GID; | |
23478 | +#endif | |
23479 | +#ifdef CONFIG_GRKERNSEC_SOCKET_CLIENT | |
23480 | + grsec_enable_socket_client = 1; | |
23481 | + grsec_socket_client_gid = CONFIG_GRKERNSEC_SOCKET_CLIENT_GID; | |
23482 | +#endif | |
23483 | +#ifdef CONFIG_GRKERNSEC_SOCKET_SERVER | |
23484 | + grsec_enable_socket_server = 1; | |
23485 | + grsec_socket_server_gid = CONFIG_GRKERNSEC_SOCKET_SERVER_GID; | |
23486 | +#endif | |
23487 | +#endif | |
23488 | + | |
23489 | + return; | |
23490 | +} | |
4dee9bd5 | 23491 | diff -urNp linux-2.6.25.4/grsecurity/grsec_ipc.c linux-2.6.25.4/grsecurity/grsec_ipc.c |
23492 | --- linux-2.6.25.4/grsecurity/grsec_ipc.c 1969-12-31 19:00:00.000000000 -0500 | |
23493 | +++ linux-2.6.25.4/grsecurity/grsec_ipc.c 2008-05-18 13:33:16.000000000 -0400 | |
50425a20 | 23494 | @@ -0,0 +1,81 @@ |
23495 | +#include <linux/kernel.h> | |
23496 | +#include <linux/sched.h> | |
23497 | +#include <linux/types.h> | |
23498 | +#include <linux/ipc.h> | |
23499 | +#include <linux/grsecurity.h> | |
23500 | +#include <linux/grinternal.h> | |
23501 | + | |
23502 | +void | |
23503 | +gr_log_msgget(const int ret, const int msgflg) | |
23504 | +{ | |
23505 | +#ifdef CONFIG_GRKERNSEC_AUDIT_IPC | |
23506 | + if (((grsec_enable_group && in_group_p(grsec_audit_gid) && | |
23507 | + grsec_enable_audit_ipc) || (grsec_enable_audit_ipc && | |
23508 | + !grsec_enable_group)) && (ret >= 0) | |
23509 | + && (msgflg & IPC_CREAT)) | |
23510 | + gr_log_noargs(GR_DO_AUDIT, GR_MSGQ_AUDIT_MSG); | |
23511 | +#endif | |
23512 | + return; | |
23513 | +} | |
23514 | + | |
23515 | +void | |
23516 | +gr_log_msgrm(const uid_t uid, const uid_t cuid) | |
23517 | +{ | |
23518 | +#ifdef CONFIG_GRKERNSEC_AUDIT_IPC | |
23519 | + if ((grsec_enable_group && in_group_p(grsec_audit_gid) && | |
23520 | + grsec_enable_audit_ipc) || | |
23521 | + (grsec_enable_audit_ipc && !grsec_enable_group)) | |
23522 | + gr_log_int_int(GR_DO_AUDIT, GR_MSGQR_AUDIT_MSG, uid, cuid); | |
23523 | +#endif | |
23524 | + return; | |
23525 | +} | |
23526 | + | |
23527 | +void | |
23528 | +gr_log_semget(const int err, const int semflg) | |
23529 | +{ | |
23530 | +#ifdef CONFIG_GRKERNSEC_AUDIT_IPC | |
23531 | + if (((grsec_enable_group && in_group_p(grsec_audit_gid) && | |
23532 | + grsec_enable_audit_ipc) || (grsec_enable_audit_ipc && | |
23533 | + !grsec_enable_group)) && (err >= 0) | |
23534 | + && (semflg & IPC_CREAT)) | |
23535 | + gr_log_noargs(GR_DO_AUDIT, GR_SEM_AUDIT_MSG); | |
23536 | +#endif | |
23537 | + return; | |
23538 | +} | |
23539 | + | |
23540 | +void | |
23541 | +gr_log_semrm(const uid_t uid, const uid_t cuid) | |
23542 | +{ | |
23543 | +#ifdef CONFIG_GRKERNSEC_AUDIT_IPC | |
23544 | + if ((grsec_enable_group && in_group_p(grsec_audit_gid) && | |
23545 | + grsec_enable_audit_ipc) || | |
23546 | + (grsec_enable_audit_ipc && !grsec_enable_group)) | |
23547 | + gr_log_int_int(GR_DO_AUDIT, GR_SEMR_AUDIT_MSG, uid, cuid); | |
23548 | +#endif | |
23549 | + return; | |
23550 | +} | |
23551 | + | |
23552 | +void | |
23553 | +gr_log_shmget(const int err, const int shmflg, const size_t size) | |
23554 | +{ | |
23555 | +#ifdef CONFIG_GRKERNSEC_AUDIT_IPC | |
23556 | + if (((grsec_enable_group && in_group_p(grsec_audit_gid) && | |
23557 | + grsec_enable_audit_ipc) || (grsec_enable_audit_ipc && | |
23558 | + !grsec_enable_group)) && (err >= 0) | |
23559 | + && (shmflg & IPC_CREAT)) | |
23560 | + gr_log_int(GR_DO_AUDIT, GR_SHM_AUDIT_MSG, size); | |
23561 | +#endif | |
23562 | + return; | |
23563 | +} | |
23564 | + | |
23565 | +void | |
23566 | +gr_log_shmrm(const uid_t uid, const uid_t cuid) | |
23567 | +{ | |
23568 | +#ifdef CONFIG_GRKERNSEC_AUDIT_IPC | |
23569 | + if ((grsec_enable_group && in_group_p(grsec_audit_gid) && | |
23570 | + grsec_enable_audit_ipc) || | |
23571 | + (grsec_enable_audit_ipc && !grsec_enable_group)) | |
23572 | + gr_log_int_int(GR_DO_AUDIT, GR_SHMR_AUDIT_MSG, uid, cuid); | |
23573 | +#endif | |
23574 | + return; | |
23575 | +} | |
4dee9bd5 | 23576 | diff -urNp linux-2.6.25.4/grsecurity/grsec_link.c linux-2.6.25.4/grsecurity/grsec_link.c |
23577 | --- linux-2.6.25.4/grsecurity/grsec_link.c 1969-12-31 19:00:00.000000000 -0500 | |
23578 | +++ linux-2.6.25.4/grsecurity/grsec_link.c 2008-05-18 13:33:16.000000000 -0400 | |
50425a20 | 23579 | @@ -0,0 +1,39 @@ |
23580 | +#include <linux/kernel.h> | |
23581 | +#include <linux/sched.h> | |
23582 | +#include <linux/fs.h> | |
23583 | +#include <linux/file.h> | |
23584 | +#include <linux/grinternal.h> | |
23585 | + | |
23586 | +int | |
23587 | +gr_handle_follow_link(const struct inode *parent, | |
23588 | + const struct inode *inode, | |
23589 | + const struct dentry *dentry, const struct vfsmount *mnt) | |
23590 | +{ | |
23591 | +#ifdef CONFIG_GRKERNSEC_LINK | |
23592 | + if (grsec_enable_link && S_ISLNK(inode->i_mode) && | |
23593 | + (parent->i_mode & S_ISVTX) && (parent->i_uid != inode->i_uid) && | |
23594 | + (parent->i_mode & S_IWOTH) && (current->fsuid != inode->i_uid)) { | |
23595 | + gr_log_fs_int2(GR_DONT_AUDIT, GR_SYMLINK_MSG, dentry, mnt, inode->i_uid, inode->i_gid); | |
23596 | + return -EACCES; | |
23597 | + } | |
23598 | +#endif | |
23599 | + return 0; | |
23600 | +} | |
23601 | + | |
23602 | +int | |
23603 | +gr_handle_hardlink(const struct dentry *dentry, | |
23604 | + const struct vfsmount *mnt, | |
23605 | + struct inode *inode, const int mode, const char *to) | |
23606 | +{ | |
23607 | +#ifdef CONFIG_GRKERNSEC_LINK | |
23608 | + if (grsec_enable_link && current->fsuid != inode->i_uid && | |
23609 | + (!S_ISREG(mode) || (mode & S_ISUID) || | |
23610 | + ((mode & (S_ISGID | S_IXGRP)) == (S_ISGID | S_IXGRP)) || | |
23611 | + (generic_permission(inode, MAY_READ | MAY_WRITE, NULL))) && | |
23612 | + !capable(CAP_FOWNER) && current->uid) { | |
23613 | + gr_log_fs_int2_str(GR_DONT_AUDIT, GR_HARDLINK_MSG, dentry, mnt, inode->i_uid, inode->i_gid, to); | |
23614 | + return -EPERM; | |
23615 | + } | |
23616 | +#endif | |
23617 | + return 0; | |
23618 | +} | |
4dee9bd5 | 23619 | diff -urNp linux-2.6.25.4/grsecurity/grsec_log.c linux-2.6.25.4/grsecurity/grsec_log.c |
23620 | --- linux-2.6.25.4/grsecurity/grsec_log.c 1969-12-31 19:00:00.000000000 -0500 | |
23621 | +++ linux-2.6.25.4/grsecurity/grsec_log.c 2008-05-18 13:33:16.000000000 -0400 | |
78fdc4fb | 23622 | @@ -0,0 +1,269 @@ |
50425a20 | 23623 | +#include <linux/kernel.h> |
23624 | +#include <linux/sched.h> | |
23625 | +#include <linux/file.h> | |
23626 | +#include <linux/tty.h> | |
23627 | +#include <linux/fs.h> | |
23628 | +#include <linux/grinternal.h> | |
23629 | + | |
23630 | +#define BEGIN_LOCKS(x) \ | |
23631 | + read_lock(&tasklist_lock); \ | |
23632 | + read_lock(&grsec_exec_file_lock); \ | |
23633 | + if (x != GR_DO_AUDIT) \ | |
23634 | + spin_lock(&grsec_alert_lock); \ | |
23635 | + else \ | |
23636 | + spin_lock(&grsec_audit_lock) | |
23637 | + | |
23638 | +#define END_LOCKS(x) \ | |
23639 | + if (x != GR_DO_AUDIT) \ | |
23640 | + spin_unlock(&grsec_alert_lock); \ | |
23641 | + else \ | |
23642 | + spin_unlock(&grsec_audit_lock); \ | |
23643 | + read_unlock(&grsec_exec_file_lock); \ | |
23644 | + read_unlock(&tasklist_lock); \ | |
23645 | + if (x == GR_DONT_AUDIT) \ | |
23646 | + gr_handle_alertkill(current) | |
23647 | + | |
23648 | +enum { | |
23649 | + FLOODING, | |
23650 | + NO_FLOODING | |
23651 | +}; | |
23652 | + | |
23653 | +extern char *gr_alert_log_fmt; | |
23654 | +extern char *gr_audit_log_fmt; | |
23655 | +extern char *gr_alert_log_buf; | |
23656 | +extern char *gr_audit_log_buf; | |
23657 | + | |
23658 | +static int gr_log_start(int audit) | |
23659 | +{ | |
23660 | + char *loglevel = (audit == GR_DO_AUDIT) ? KERN_INFO : KERN_ALERT; | |
23661 | + char *fmt = (audit == GR_DO_AUDIT) ? gr_audit_log_fmt : gr_alert_log_fmt; | |
23662 | + char *buf = (audit == GR_DO_AUDIT) ? gr_audit_log_buf : gr_alert_log_buf; | |
23663 | + | |
23664 | + if (audit == GR_DO_AUDIT) | |
23665 | + goto set_fmt; | |
23666 | + | |
23667 | + if (!grsec_alert_wtime || jiffies - grsec_alert_wtime > CONFIG_GRKERNSEC_FLOODTIME * HZ) { | |
23668 | + grsec_alert_wtime = jiffies; | |
23669 | + grsec_alert_fyet = 0; | |
23670 | + } else if ((jiffies - grsec_alert_wtime < CONFIG_GRKERNSEC_FLOODTIME * HZ) && (grsec_alert_fyet < CONFIG_GRKERNSEC_FLOODBURST)) { | |
23671 | + grsec_alert_fyet++; | |
23672 | + } else if (grsec_alert_fyet == CONFIG_GRKERNSEC_FLOODBURST) { | |
23673 | + grsec_alert_wtime = jiffies; | |
23674 | + grsec_alert_fyet++; | |
23675 | + printk(KERN_ALERT "grsec: more alerts, logging disabled for %d seconds\n", CONFIG_GRKERNSEC_FLOODTIME); | |
23676 | + return FLOODING; | |
23677 | + } else return FLOODING; | |
23678 | + | |
23679 | +set_fmt: | |
23680 | + memset(buf, 0, PAGE_SIZE); | |
23681 | + if (current->signal->curr_ip && gr_acl_is_enabled()) { | |
23682 | + sprintf(fmt, "%s%s", loglevel, "grsec: From %u.%u.%u.%u: (%.64s:%c:%.950s) "); | |
23683 | + snprintf(buf, PAGE_SIZE - 1, fmt, NIPQUAD(current->signal->curr_ip), current->role->rolename, gr_roletype_to_char(), current->acl->filename); | |
23684 | + } else if (current->signal->curr_ip) { | |
23685 | + sprintf(fmt, "%s%s", loglevel, "grsec: From %u.%u.%u.%u: "); | |
23686 | + snprintf(buf, PAGE_SIZE - 1, fmt, NIPQUAD(current->signal->curr_ip)); | |
23687 | + } else if (gr_acl_is_enabled()) { | |
23688 | + sprintf(fmt, "%s%s", loglevel, "grsec: (%.64s:%c:%.950s) "); | |
23689 | + snprintf(buf, PAGE_SIZE - 1, fmt, current->role->rolename, gr_roletype_to_char(), current->acl->filename); | |
23690 | + } else { | |
23691 | + sprintf(fmt, "%s%s", loglevel, "grsec: "); | |
23692 | + strcpy(buf, fmt); | |
23693 | + } | |
23694 | + | |
23695 | + return NO_FLOODING; | |
23696 | +} | |
23697 | + | |
23698 | +static void gr_log_middle(int audit, const char *msg, va_list ap) | |
23699 | +{ | |
23700 | + char *buf = (audit == GR_DO_AUDIT) ? gr_audit_log_buf : gr_alert_log_buf; | |
23701 | + unsigned int len = strlen(buf); | |
23702 | + | |
23703 | + vsnprintf(buf + len, PAGE_SIZE - len - 1, msg, ap); | |
23704 | + | |
23705 | + return; | |
23706 | +} | |
23707 | + | |
23708 | +static void gr_log_middle_varargs(int audit, const char *msg, ...) | |
23709 | +{ | |
23710 | + char *buf = (audit == GR_DO_AUDIT) ? gr_audit_log_buf : gr_alert_log_buf; | |
23711 | + unsigned int len = strlen(buf); | |
23712 | + va_list ap; | |
23713 | + | |
23714 | + va_start(ap, msg); | |
23715 | + vsnprintf(buf + len, PAGE_SIZE - len - 1, msg, ap); | |
23716 | + va_end(ap); | |
23717 | + | |
23718 | + return; | |
23719 | +} | |
23720 | + | |
23721 | +static void gr_log_end(int audit) | |
23722 | +{ | |
23723 | + char *buf = (audit == GR_DO_AUDIT) ? gr_audit_log_buf : gr_alert_log_buf; | |
23724 | + unsigned int len = strlen(buf); | |
23725 | + | |
23726 | + snprintf(buf + len, PAGE_SIZE - len - 1, DEFAULTSECMSG, DEFAULTSECARGS(current)); | |
23727 | + printk("%s\n", buf); | |
23728 | + | |
23729 | + return; | |
23730 | +} | |
23731 | + | |
23732 | +void gr_log_varargs(int audit, const char *msg, int argtypes, ...) | |
23733 | +{ | |
23734 | + int logtype; | |
23735 | + char *result = (audit == GR_DO_AUDIT) ? "successful" : "denied"; | |
23736 | + char *str1, *str2, *str3; | |
23737 | + int num1, num2; | |
23738 | + unsigned long ulong1, ulong2; | |
23739 | + struct dentry *dentry; | |
23740 | + struct vfsmount *mnt; | |
23741 | + struct file *file; | |
23742 | + struct task_struct *task; | |
23743 | + va_list ap; | |
23744 | + | |
23745 | + BEGIN_LOCKS(audit); | |
23746 | + logtype = gr_log_start(audit); | |
23747 | + if (logtype == FLOODING) { | |
23748 | + END_LOCKS(audit); | |
23749 | + return; | |
23750 | + } | |
23751 | + va_start(ap, argtypes); | |
23752 | + switch (argtypes) { | |
23753 | + case GR_TTYSNIFF: | |
23754 | + task = va_arg(ap, struct task_struct *); | |
23755 | + gr_log_middle_varargs(audit, msg, NIPQUAD(task->signal->curr_ip), gr_task_fullpath0(task), task->comm, task->pid, gr_parent_task_fullpath0(task), task->parent->comm, task->parent->pid); | |
23756 | + break; | |
78fdc4fb | 23757 | + case GR_SYSCTL_HIDDEN: |
23758 | + str1 = va_arg(ap, char *); | |
23759 | + gr_log_middle_varargs(audit, msg, result, str1); | |
23760 | + break; | |
50425a20 | 23761 | + case GR_RBAC: |
23762 | + dentry = va_arg(ap, struct dentry *); | |
23763 | + mnt = va_arg(ap, struct vfsmount *); | |
23764 | + gr_log_middle_varargs(audit, msg, result, gr_to_filename(dentry, mnt)); | |
23765 | + break; | |
23766 | + case GR_RBAC_STR: | |
23767 | + dentry = va_arg(ap, struct dentry *); | |
23768 | + mnt = va_arg(ap, struct vfsmount *); | |
23769 | + str1 = va_arg(ap, char *); | |
23770 | + gr_log_middle_varargs(audit, msg, result, gr_to_filename(dentry, mnt), str1); | |
23771 | + break; | |
23772 | + case GR_STR_RBAC: | |
23773 | + str1 = va_arg(ap, char *); | |
23774 | + dentry = va_arg(ap, struct dentry *); | |
23775 | + mnt = va_arg(ap, struct vfsmount *); | |
23776 | + gr_log_middle_varargs(audit, msg, result, str1, gr_to_filename(dentry, mnt)); | |
23777 | + break; | |
23778 | + case GR_RBAC_MODE2: | |
23779 | + dentry = va_arg(ap, struct dentry *); | |
23780 | + mnt = va_arg(ap, struct vfsmount *); | |
23781 | + str1 = va_arg(ap, char *); | |
23782 | + str2 = va_arg(ap, char *); | |
23783 | + gr_log_middle_varargs(audit, msg, result, gr_to_filename(dentry, mnt), str1, str2); | |
23784 | + break; | |
23785 | + case GR_RBAC_MODE3: | |
23786 | + dentry = va_arg(ap, struct dentry *); | |
23787 | + mnt = va_arg(ap, struct vfsmount *); | |
23788 | + str1 = va_arg(ap, char *); | |
23789 | + str2 = va_arg(ap, char *); | |
23790 | + str3 = va_arg(ap, char *); | |
23791 | + gr_log_middle_varargs(audit, msg, result, gr_to_filename(dentry, mnt), str1, str2, str3); | |
23792 | + break; | |
23793 | + case GR_FILENAME: | |
23794 | + dentry = va_arg(ap, struct dentry *); | |
23795 | + mnt = va_arg(ap, struct vfsmount *); | |
23796 | + gr_log_middle_varargs(audit, msg, gr_to_filename(dentry, mnt)); | |
23797 | + break; | |
23798 | + case GR_STR_FILENAME: | |
23799 | + str1 = va_arg(ap, char *); | |
23800 | + dentry = va_arg(ap, struct dentry *); | |
23801 | + mnt = va_arg(ap, struct vfsmount *); | |
23802 | + gr_log_middle_varargs(audit, msg, str1, gr_to_filename(dentry, mnt)); | |
23803 | + break; | |
23804 | + case GR_FILENAME_STR: | |
23805 | + dentry = va_arg(ap, struct dentry *); | |
23806 | + mnt = va_arg(ap, struct vfsmount *); | |
23807 | + str1 = va_arg(ap, char *); | |
23808 | + gr_log_middle_varargs(audit, msg, gr_to_filename(dentry, mnt), str1); | |
23809 | + break; | |
23810 | + case GR_FILENAME_TWO_INT: | |
23811 | + dentry = va_arg(ap, struct dentry *); | |
23812 | + mnt = va_arg(ap, struct vfsmount *); | |
23813 | + num1 = va_arg(ap, int); | |
23814 | + num2 = va_arg(ap, int); | |
23815 | + gr_log_middle_varargs(audit, msg, gr_to_filename(dentry, mnt), num1, num2); | |
23816 | + break; | |
23817 | + case GR_FILENAME_TWO_INT_STR: | |
23818 | + dentry = va_arg(ap, struct dentry *); | |
23819 | + mnt = va_arg(ap, struct vfsmount *); | |
23820 | + num1 = va_arg(ap, int); | |
23821 | + num2 = va_arg(ap, int); | |
23822 | + str1 = va_arg(ap, char *); | |
23823 | + gr_log_middle_varargs(audit, msg, gr_to_filename(dentry, mnt), num1, num2, str1); | |
23824 | + break; | |
23825 | + case GR_TEXTREL: | |
23826 | + file = va_arg(ap, struct file *); | |
23827 | + ulong1 = va_arg(ap, unsigned long); | |
23828 | + ulong2 = va_arg(ap, unsigned long); | |
4dee9bd5 | 23829 | + gr_log_middle_varargs(audit, msg, file ? gr_to_filename(file->f_path.dentry, file->f_path.mnt) : "<anonymous mapping>", ulong1, ulong2); |
50425a20 | 23830 | + break; |
23831 | + case GR_PTRACE: | |
23832 | + task = va_arg(ap, struct task_struct *); | |
4dee9bd5 | 23833 | + gr_log_middle_varargs(audit, msg, task->exec_file ? gr_to_filename(task->exec_file->f_path.dentry, task->exec_file->f_path.mnt) : "(none)", task->comm, task->pid); |
50425a20 | 23834 | + break; |
23835 | + case GR_RESOURCE: | |
23836 | + task = va_arg(ap, struct task_struct *); | |
23837 | + ulong1 = va_arg(ap, unsigned long); | |
23838 | + str1 = va_arg(ap, char *); | |
23839 | + ulong2 = va_arg(ap, unsigned long); | |
23840 | + gr_log_middle_varargs(audit, msg, ulong1, str1, ulong2, gr_task_fullpath(task), task->comm, task->pid, task->uid, task->euid, task->gid, task->egid, gr_parent_task_fullpath(task), task->parent->comm, task->parent->pid, task->parent->uid, task->parent->euid, task->parent->gid, task->parent->egid); | |
23841 | + break; | |
23842 | + case GR_CAP: | |
23843 | + task = va_arg(ap, struct task_struct *); | |
23844 | + str1 = va_arg(ap, char *); | |
23845 | + gr_log_middle_varargs(audit, msg, str1, gr_task_fullpath(task), task->comm, task->pid, task->uid, task->euid, task->gid, task->egid, gr_parent_task_fullpath(task), task->parent->comm, task->parent->pid, task->parent->uid, task->parent->euid, task->parent->gid, task->parent->egid); | |
23846 | + break; | |
23847 | + case GR_SIG: | |
23848 | + task = va_arg(ap, struct task_struct *); | |
23849 | + num1 = va_arg(ap, int); | |
23850 | + gr_log_middle_varargs(audit, msg, num1, gr_task_fullpath0(task), task->comm, task->pid, task->uid, task->euid, task->gid, task->egid, gr_parent_task_fullpath0(task), task->parent->comm, task->parent->pid, task->parent->uid, task->parent->euid, task->parent->gid, task->parent->egid); | |
23851 | + break; | |
23852 | + case GR_CRASH1: | |
23853 | + task = va_arg(ap, struct task_struct *); | |
23854 | + ulong1 = va_arg(ap, unsigned long); | |
23855 | + gr_log_middle_varargs(audit, msg, gr_task_fullpath(task), task->comm, task->pid, task->uid, task->euid, task->gid, task->egid, gr_parent_task_fullpath(task), task->parent->comm, task->parent->pid, task->parent->uid, task->parent->euid, task->parent->gid, task->parent->egid, task->uid, ulong1); | |
23856 | + break; | |
23857 | + case GR_CRASH2: | |
23858 | + task = va_arg(ap, struct task_struct *); | |
23859 | + ulong1 = va_arg(ap, unsigned long); | |
23860 | + gr_log_middle_varargs(audit, msg, gr_task_fullpath(task), task->comm, task->pid, task->uid, task->euid, task->gid, task->egid, gr_parent_task_fullpath(task), task->parent->comm, task->parent->pid, task->parent->uid, task->parent->euid, task->parent->gid, task->parent->egid, ulong1); | |
23861 | + break; | |
23862 | + case GR_PSACCT: | |
23863 | + { | |
23864 | + unsigned int wday, cday; | |
23865 | + __u8 whr, chr; | |
23866 | + __u8 wmin, cmin; | |
23867 | + __u8 wsec, csec; | |
23868 | + char cur_tty[64] = { 0 }; | |
23869 | + char parent_tty[64] = { 0 }; | |
23870 | + | |
23871 | + task = va_arg(ap, struct task_struct *); | |
23872 | + wday = va_arg(ap, unsigned int); | |
23873 | + cday = va_arg(ap, unsigned int); | |
23874 | + whr = va_arg(ap, int); | |
23875 | + chr = va_arg(ap, int); | |
23876 | + wmin = va_arg(ap, int); | |
23877 | + cmin = va_arg(ap, int); | |
23878 | + wsec = va_arg(ap, int); | |
23879 | + csec = va_arg(ap, int); | |
23880 | + ulong1 = va_arg(ap, unsigned long); | |
23881 | + | |
23882 | + gr_log_middle_varargs(audit, msg, gr_task_fullpath(task), task->comm, task->pid, NIPQUAD(task->signal->curr_ip), tty_name(task->signal->tty, cur_tty), task->uid, task->euid, task->gid, task->egid, wday, whr, wmin, wsec, cday, chr, cmin, csec, (task->flags & PF_SIGNALED) ? "killed by signal" : "exited", ulong1, gr_parent_task_fullpath(task), task->parent->comm, task->parent->pid, NIPQUAD(task->parent->signal->curr_ip), tty_name(task->parent->signal->tty, parent_tty), task->parent->uid, task->parent->euid, task->parent->gid, task->parent->egid); | |
23883 | + } | |
23884 | + break; | |
23885 | + default: | |
23886 | + gr_log_middle(audit, msg, ap); | |
23887 | + } | |
23888 | + va_end(ap); | |
23889 | + gr_log_end(audit); | |
23890 | + END_LOCKS(audit); | |
23891 | +} | |
4dee9bd5 | 23892 | diff -urNp linux-2.6.25.4/grsecurity/grsec_mem.c linux-2.6.25.4/grsecurity/grsec_mem.c |
23893 | --- linux-2.6.25.4/grsecurity/grsec_mem.c 1969-12-31 19:00:00.000000000 -0500 | |
23894 | +++ linux-2.6.25.4/grsecurity/grsec_mem.c 2008-05-18 13:33:16.000000000 -0400 | |
50425a20 | 23895 | @@ -0,0 +1,71 @@ |
23896 | +#include <linux/kernel.h> | |
23897 | +#include <linux/sched.h> | |
23898 | +#include <linux/mm.h> | |
23899 | +#include <linux/mman.h> | |
23900 | +#include <linux/grinternal.h> | |
23901 | + | |
23902 | +void | |
23903 | +gr_handle_ioperm(void) | |
23904 | +{ | |
23905 | + gr_log_noargs(GR_DONT_AUDIT, GR_IOPERM_MSG); | |
23906 | + return; | |
23907 | +} | |
23908 | + | |
23909 | +void | |
23910 | +gr_handle_iopl(void) | |
23911 | +{ | |
23912 | + gr_log_noargs(GR_DONT_AUDIT, GR_IOPL_MSG); | |
23913 | + return; | |
23914 | +} | |
23915 | + | |
23916 | +void | |
23917 | +gr_handle_mem_write(void) | |
23918 | +{ | |
23919 | + gr_log_noargs(GR_DONT_AUDIT, GR_MEM_WRITE_MSG); | |
23920 | + return; | |
23921 | +} | |
23922 | + | |
23923 | +void | |
23924 | +gr_handle_kmem_write(void) | |
23925 | +{ | |
23926 | + gr_log_noargs(GR_DONT_AUDIT, GR_KMEM_MSG); | |
23927 | + return; | |
23928 | +} | |
23929 | + | |
23930 | +void | |
23931 | +gr_handle_open_port(void) | |
23932 | +{ | |
23933 | + gr_log_noargs(GR_DONT_AUDIT, GR_PORT_OPEN_MSG); | |
23934 | + return; | |
23935 | +} | |
23936 | + | |
23937 | +int | |
23938 | +gr_handle_mem_mmap(const unsigned long offset, struct vm_area_struct *vma) | |
23939 | +{ | |
23940 | + unsigned long start, end; | |
23941 | + | |
23942 | + start = offset; | |
23943 | + end = start + vma->vm_end - vma->vm_start; | |
23944 | + | |
23945 | + if (start > end) { | |
23946 | + gr_log_noargs(GR_DONT_AUDIT, GR_MEM_MMAP_MSG); | |
23947 | + return -EPERM; | |
23948 | + } | |
23949 | + | |
23950 | + /* allowed ranges : ISA I/O BIOS */ | |
23951 | + if ((start >= __pa(high_memory)) | |
23952 | +#ifdef CONFIG_X86 | |
23953 | + || (start >= 0x000a0000 && end <= 0x00100000) | |
23954 | + || (start >= 0x00000000 && end <= 0x00001000) | |
23955 | +#endif | |
23956 | + ) | |
23957 | + return 0; | |
23958 | + | |
23959 | + if (vma->vm_flags & VM_WRITE) { | |
23960 | + gr_log_noargs(GR_DONT_AUDIT, GR_MEM_MMAP_MSG); | |
23961 | + return -EPERM; | |
23962 | + } else | |
23963 | + vma->vm_flags &= ~VM_MAYWRITE; | |
23964 | + | |
23965 | + return 0; | |
23966 | +} | |
4dee9bd5 | 23967 | diff -urNp linux-2.6.25.4/grsecurity/grsec_mount.c linux-2.6.25.4/grsecurity/grsec_mount.c |
23968 | --- linux-2.6.25.4/grsecurity/grsec_mount.c 1969-12-31 19:00:00.000000000 -0500 | |
23969 | +++ linux-2.6.25.4/grsecurity/grsec_mount.c 2008-05-18 13:33:16.000000000 -0400 | |
50425a20 | 23970 | @@ -0,0 +1,34 @@ |
23971 | +#include <linux/kernel.h> | |
23972 | +#include <linux/sched.h> | |
23973 | +#include <linux/grsecurity.h> | |
23974 | +#include <linux/grinternal.h> | |
23975 | + | |
23976 | +void | |
23977 | +gr_log_remount(const char *devname, const int retval) | |
23978 | +{ | |
23979 | +#ifdef CONFIG_GRKERNSEC_AUDIT_MOUNT | |
23980 | + if (grsec_enable_mount && (retval >= 0)) | |
23981 | + gr_log_str(GR_DO_AUDIT, GR_REMOUNT_AUDIT_MSG, devname ? devname : "none"); | |
23982 | +#endif | |
23983 | + return; | |
23984 | +} | |
23985 | + | |
23986 | +void | |
23987 | +gr_log_unmount(const char *devname, const int retval) | |
23988 | +{ | |
23989 | +#ifdef CONFIG_GRKERNSEC_AUDIT_MOUNT | |
23990 | + if (grsec_enable_mount && (retval >= 0)) | |
23991 | + gr_log_str(GR_DO_AUDIT, GR_UNMOUNT_AUDIT_MSG, devname ? devname : "none"); | |
23992 | +#endif | |
23993 | + return; | |
23994 | +} | |
23995 | + | |
23996 | +void | |
23997 | +gr_log_mount(const char *from, const char *to, const int retval) | |
23998 | +{ | |
23999 | +#ifdef CONFIG_GRKERNSEC_AUDIT_MOUNT | |
24000 | + if (grsec_enable_mount && (retval >= 0)) | |
24001 | + gr_log_str_str(GR_DO_AUDIT, GR_MOUNT_AUDIT_MSG, from, to); | |
24002 | +#endif | |
24003 | + return; | |
24004 | +} | |
4dee9bd5 | 24005 | diff -urNp linux-2.6.25.4/grsecurity/grsec_sig.c linux-2.6.25.4/grsecurity/grsec_sig.c |
24006 | --- linux-2.6.25.4/grsecurity/grsec_sig.c 1969-12-31 19:00:00.000000000 -0500 | |
24007 | +++ linux-2.6.25.4/grsecurity/grsec_sig.c 2008-05-18 13:33:16.000000000 -0400 | |
7bcbf78a | 24008 | @@ -0,0 +1,58 @@ |
50425a20 | 24009 | +#include <linux/kernel.h> |
24010 | +#include <linux/sched.h> | |
7bcbf78a | 24011 | +#include <linux/delay.h> |
50425a20 | 24012 | +#include <linux/grsecurity.h> |
24013 | +#include <linux/grinternal.h> | |
24014 | + | |
24015 | +void | |
24016 | +gr_log_signal(const int sig, const struct task_struct *t) | |
24017 | +{ | |
24018 | +#ifdef CONFIG_GRKERNSEC_SIGNAL | |
24019 | + if (grsec_enable_signal && ((sig == SIGSEGV) || (sig == SIGILL) || | |
24020 | + (sig == SIGABRT) || (sig == SIGBUS))) { | |
24021 | + if (t->pid == current->pid) { | |
24022 | + gr_log_int(GR_DONT_AUDIT_GOOD, GR_UNISIGLOG_MSG, sig); | |
24023 | + } else { | |
24024 | + gr_log_sig(GR_DONT_AUDIT_GOOD, GR_DUALSIGLOG_MSG, t, sig); | |
24025 | + } | |
24026 | + } | |
24027 | +#endif | |
24028 | + return; | |
24029 | +} | |
24030 | + | |
24031 | +int | |
24032 | +gr_handle_signal(const struct task_struct *p, const int sig) | |
24033 | +{ | |
24034 | +#ifdef CONFIG_GRKERNSEC | |
24035 | + if (current->pid > 1 && gr_check_protected_task(p)) { | |
24036 | + gr_log_sig(GR_DONT_AUDIT, GR_SIG_ACL_MSG, p, sig); | |
24037 | + return -EPERM; | |
24038 | + } else if (gr_pid_is_chrooted((struct task_struct *)p)) { | |
24039 | + return -EPERM; | |
24040 | + } | |
24041 | +#endif | |
24042 | + return 0; | |
24043 | +} | |
24044 | + | |
24045 | +void gr_handle_brute_attach(struct task_struct *p) | |
24046 | +{ | |
24047 | +#ifdef CONFIG_GRKERNSEC_BRUTE | |
24048 | + read_lock(&tasklist_lock); | |
24049 | + read_lock(&grsec_exec_file_lock); | |
24050 | + if (p->parent && p->parent->exec_file == p->exec_file) | |
24051 | + p->parent->brute = 1; | |
24052 | + read_unlock(&grsec_exec_file_lock); | |
24053 | + read_unlock(&tasklist_lock); | |
24054 | +#endif | |
24055 | + return; | |
24056 | +} | |
24057 | + | |
24058 | +void gr_handle_brute_check(void) | |
24059 | +{ | |
24060 | +#ifdef CONFIG_GRKERNSEC_BRUTE | |
7bcbf78a | 24061 | + if (current->brute) |
24062 | + msleep(30 * 1000); | |
50425a20 | 24063 | +#endif |
24064 | + return; | |
24065 | +} | |
24066 | + | |
4dee9bd5 | 24067 | diff -urNp linux-2.6.25.4/grsecurity/grsec_sock.c linux-2.6.25.4/grsecurity/grsec_sock.c |
24068 | --- linux-2.6.25.4/grsecurity/grsec_sock.c 1969-12-31 19:00:00.000000000 -0500 | |
24069 | +++ linux-2.6.25.4/grsecurity/grsec_sock.c 2008-05-18 13:33:16.000000000 -0400 | |
b2ee8b1e | 24070 | @@ -0,0 +1,274 @@ |
50425a20 | 24071 | +#include <linux/kernel.h> |
24072 | +#include <linux/module.h> | |
24073 | +#include <linux/sched.h> | |
24074 | +#include <linux/file.h> | |
24075 | +#include <linux/net.h> | |
24076 | +#include <linux/in.h> | |
24077 | +#include <linux/ip.h> | |
24078 | +#include <net/sock.h> | |
24079 | +#include <net/inet_sock.h> | |
24080 | +#include <linux/grsecurity.h> | |
24081 | +#include <linux/grinternal.h> | |
24082 | +#include <linux/gracl.h> | |
24083 | + | |
24084 | +#if defined(CONFIG_IP_NF_MATCH_STEALTH_MODULE) | |
24085 | +extern struct sock *udp_v4_lookup(u32 saddr, u16 sport, u32 daddr, u16 dport, int dif); | |
24086 | +EXPORT_SYMBOL(udp_v4_lookup); | |
24087 | +#endif | |
24088 | + | |
4dee9bd5 | 24089 | +kernel_cap_t gr_cap_rtnetlink(struct sock *sock); |
50425a20 | 24090 | +EXPORT_SYMBOL(gr_cap_rtnetlink); |
24091 | + | |
24092 | +extern int gr_search_udp_recvmsg(const struct sock *sk, const struct sk_buff *skb); | |
24093 | +extern int gr_search_udp_sendmsg(const struct sock *sk, const struct sockaddr_in *addr); | |
24094 | + | |
24095 | +EXPORT_SYMBOL(gr_search_udp_recvmsg); | |
24096 | +EXPORT_SYMBOL(gr_search_udp_sendmsg); | |
24097 | + | |
24098 | +#ifdef CONFIG_UNIX_MODULE | |
24099 | +EXPORT_SYMBOL(gr_acl_handle_unix); | |
24100 | +EXPORT_SYMBOL(gr_acl_handle_mknod); | |
24101 | +EXPORT_SYMBOL(gr_handle_chroot_unix); | |
24102 | +EXPORT_SYMBOL(gr_handle_create); | |
24103 | +#endif | |
24104 | + | |
24105 | +#ifdef CONFIG_GRKERNSEC | |
24106 | +#define gr_conn_table_size 32749 | |
24107 | +struct conn_table_entry { | |
24108 | + struct conn_table_entry *next; | |
24109 | + struct signal_struct *sig; | |
24110 | +}; | |
24111 | + | |
24112 | +struct conn_table_entry *gr_conn_table[gr_conn_table_size]; | |
24113 | +spinlock_t gr_conn_table_lock = SPIN_LOCK_UNLOCKED; | |
24114 | + | |
24115 | +extern const char * gr_socktype_to_name(unsigned char type); | |
24116 | +extern const char * gr_proto_to_name(unsigned char proto); | |
24117 | + | |
24118 | +static __inline__ int | |
24119 | +conn_hash(__u32 saddr, __u32 daddr, __u16 sport, __u16 dport, unsigned int size) | |
24120 | +{ | |
24121 | + return ((daddr + saddr + (sport << 8) + (dport << 16)) % size); | |
24122 | +} | |
24123 | + | |
24124 | +static __inline__ int | |
24125 | +conn_match(const struct signal_struct *sig, __u32 saddr, __u32 daddr, | |
24126 | + __u16 sport, __u16 dport) | |
24127 | +{ | |
24128 | + if (unlikely(sig->gr_saddr == saddr && sig->gr_daddr == daddr && | |
24129 | + sig->gr_sport == sport && sig->gr_dport == dport)) | |
24130 | + return 1; | |
24131 | + else | |
24132 | + return 0; | |
24133 | +} | |
24134 | + | |
24135 | +static void gr_add_to_task_ip_table_nolock(struct signal_struct *sig, struct conn_table_entry *newent) | |
24136 | +{ | |
24137 | + struct conn_table_entry **match; | |
24138 | + unsigned int index; | |
24139 | + | |
24140 | + index = conn_hash(sig->gr_saddr, sig->gr_daddr, | |
24141 | + sig->gr_sport, sig->gr_dport, | |
24142 | + gr_conn_table_size); | |
24143 | + | |
24144 | + newent->sig = sig; | |
24145 | + | |
24146 | + match = &gr_conn_table[index]; | |
24147 | + newent->next = *match; | |
24148 | + *match = newent; | |
24149 | + | |
24150 | + return; | |
24151 | +} | |
24152 | + | |
24153 | +static void gr_del_task_from_ip_table_nolock(struct signal_struct *sig) | |
24154 | +{ | |
24155 | + struct conn_table_entry *match, *last = NULL; | |
24156 | + unsigned int index; | |
24157 | + | |
24158 | + index = conn_hash(sig->gr_saddr, sig->gr_daddr, | |
24159 | + sig->gr_sport, sig->gr_dport, | |
24160 | + gr_conn_table_size); | |
24161 | + | |
24162 | + match = gr_conn_table[index]; | |
24163 | + while (match && !conn_match(match->sig, | |
24164 | + sig->gr_saddr, sig->gr_daddr, sig->gr_sport, | |
24165 | + sig->gr_dport)) { | |
24166 | + last = match; | |
24167 | + match = match->next; | |
24168 | + } | |
24169 | + | |
24170 | + if (match) { | |
24171 | + if (last) | |
24172 | + last->next = match->next; | |
24173 | + else | |
24174 | + gr_conn_table[index] = NULL; | |
24175 | + kfree(match); | |
24176 | + } | |
24177 | + | |
24178 | + return; | |
24179 | +} | |
24180 | + | |
24181 | +static struct signal_struct * gr_lookup_task_ip_table(__u32 saddr, __u32 daddr, | |
24182 | + __u16 sport, __u16 dport) | |
24183 | +{ | |
24184 | + struct conn_table_entry *match; | |
24185 | + unsigned int index; | |
24186 | + | |
24187 | + index = conn_hash(saddr, daddr, sport, dport, gr_conn_table_size); | |
24188 | + | |
24189 | + match = gr_conn_table[index]; | |
24190 | + while (match && !conn_match(match->sig, saddr, daddr, sport, dport)) | |
24191 | + match = match->next; | |
24192 | + | |
24193 | + if (match) | |
24194 | + return match->sig; | |
24195 | + else | |
24196 | + return NULL; | |
24197 | +} | |
24198 | + | |
24199 | +#endif | |
24200 | + | |
24201 | +void gr_update_task_in_ip_table(struct task_struct *task, const struct inet_sock *inet) | |
24202 | +{ | |
24203 | +#ifdef CONFIG_GRKERNSEC | |
24204 | + struct signal_struct *sig = task->signal; | |
24205 | + struct conn_table_entry *newent; | |
24206 | + | |
24207 | + newent = kmalloc(sizeof(struct conn_table_entry), GFP_ATOMIC); | |
24208 | + if (newent == NULL) | |
24209 | + return; | |
24210 | + /* no bh lock needed since we are called with bh disabled */ | |
24211 | + spin_lock(&gr_conn_table_lock); | |
24212 | + gr_del_task_from_ip_table_nolock(sig); | |
24213 | + sig->gr_saddr = inet->rcv_saddr; | |
24214 | + sig->gr_daddr = inet->daddr; | |
24215 | + sig->gr_sport = inet->sport; | |
24216 | + sig->gr_dport = inet->dport; | |
24217 | + gr_add_to_task_ip_table_nolock(sig, newent); | |
24218 | + spin_unlock(&gr_conn_table_lock); | |
24219 | +#endif | |
24220 | + return; | |
24221 | +} | |
24222 | + | |
24223 | +void gr_del_task_from_ip_table(struct task_struct *task) | |
24224 | +{ | |
24225 | +#ifdef CONFIG_GRKERNSEC | |
24226 | + spin_lock(&gr_conn_table_lock); | |
24227 | + gr_del_task_from_ip_table_nolock(task->signal); | |
24228 | + spin_unlock(&gr_conn_table_lock); | |
24229 | +#endif | |
24230 | + return; | |
24231 | +} | |
24232 | + | |
24233 | +void | |
24234 | +gr_attach_curr_ip(const struct sock *sk) | |
24235 | +{ | |
24236 | +#ifdef CONFIG_GRKERNSEC | |
24237 | + struct signal_struct *p, *set; | |
24238 | + const struct inet_sock *inet = inet_sk(sk); | |
24239 | + | |
24240 | + if (unlikely(sk->sk_protocol != IPPROTO_TCP)) | |
24241 | + return; | |
24242 | + | |
24243 | + set = current->signal; | |
24244 | + | |
24245 | + spin_lock_bh(&gr_conn_table_lock); | |
24246 | + p = gr_lookup_task_ip_table(inet->daddr, inet->rcv_saddr, | |
24247 | + inet->dport, inet->sport); | |
24248 | + if (unlikely(p != NULL)) { | |
24249 | + set->curr_ip = p->curr_ip; | |
24250 | + set->used_accept = 1; | |
24251 | + gr_del_task_from_ip_table_nolock(p); | |
24252 | + spin_unlock_bh(&gr_conn_table_lock); | |
24253 | + return; | |
24254 | + } | |
24255 | + spin_unlock_bh(&gr_conn_table_lock); | |
24256 | + | |
24257 | + set->curr_ip = inet->daddr; | |
24258 | + set->used_accept = 1; | |
24259 | +#endif | |
24260 | + return; | |
24261 | +} | |
24262 | + | |
24263 | +int | |
24264 | +gr_handle_sock_all(const int family, const int type, const int protocol) | |
24265 | +{ | |
24266 | +#ifdef CONFIG_GRKERNSEC_SOCKET_ALL | |
24267 | + if (grsec_enable_socket_all && in_group_p(grsec_socket_all_gid) && | |
24268 | + (family != AF_UNIX) && (family != AF_LOCAL)) { | |
24269 | + gr_log_int_str2(GR_DONT_AUDIT, GR_SOCK2_MSG, family, gr_socktype_to_name(type), gr_proto_to_name(protocol)); | |
24270 | + return -EACCES; | |
24271 | + } | |
24272 | +#endif | |
24273 | + return 0; | |
24274 | +} | |
24275 | + | |
24276 | +int | |
24277 | +gr_handle_sock_server(const struct sockaddr *sck) | |
24278 | +{ | |
24279 | +#ifdef CONFIG_GRKERNSEC_SOCKET_SERVER | |
24280 | + if (grsec_enable_socket_server && | |
24281 | + in_group_p(grsec_socket_server_gid) && | |
24282 | + sck && (sck->sa_family != AF_UNIX) && | |
24283 | + (sck->sa_family != AF_LOCAL)) { | |
24284 | + gr_log_noargs(GR_DONT_AUDIT, GR_BIND_MSG); | |
24285 | + return -EACCES; | |
24286 | + } | |
24287 | +#endif | |
24288 | + return 0; | |
24289 | +} | |
24290 | + | |
24291 | +int | |
24292 | +gr_handle_sock_server_other(const struct sock *sck) | |
24293 | +{ | |
24294 | +#ifdef CONFIG_GRKERNSEC_SOCKET_SERVER | |
24295 | + if (grsec_enable_socket_server && | |
24296 | + in_group_p(grsec_socket_server_gid) && | |
24297 | + sck && (sck->sk_family != AF_UNIX) && | |
24298 | + (sck->sk_family != AF_LOCAL)) { | |
24299 | + gr_log_noargs(GR_DONT_AUDIT, GR_BIND_MSG); | |
24300 | + return -EACCES; | |
24301 | + } | |
24302 | +#endif | |
24303 | + return 0; | |
24304 | +} | |
24305 | + | |
24306 | +int | |
24307 | +gr_handle_sock_client(const struct sockaddr *sck) | |
24308 | +{ | |
24309 | +#ifdef CONFIG_GRKERNSEC_SOCKET_CLIENT | |
24310 | + if (grsec_enable_socket_client && in_group_p(grsec_socket_client_gid) && | |
24311 | + sck && (sck->sa_family != AF_UNIX) && | |
24312 | + (sck->sa_family != AF_LOCAL)) { | |
24313 | + gr_log_noargs(GR_DONT_AUDIT, GR_CONNECT_MSG); | |
24314 | + return -EACCES; | |
24315 | + } | |
24316 | +#endif | |
24317 | + return 0; | |
24318 | +} | |
24319 | + | |
4dee9bd5 | 24320 | +kernel_cap_t |
b2ee8b1e | 24321 | +gr_cap_rtnetlink(struct sock *sock) |
50425a20 | 24322 | +{ |
24323 | +#ifdef CONFIG_GRKERNSEC | |
24324 | + if (!gr_acl_is_enabled()) | |
24325 | + return current->cap_effective; | |
b2ee8b1e | 24326 | + else if (sock->sk_protocol == NETLINK_ISCSI && |
24327 | + cap_raised(current->cap_effective, CAP_SYS_ADMIN) && | |
24328 | + gr_task_is_capable(current, CAP_SYS_ADMIN)) | |
24329 | + return current->cap_effective; | |
24330 | + else if (sock->sk_protocol == NETLINK_AUDIT && | |
24331 | + cap_raised(current->cap_effective, CAP_AUDIT_WRITE) && | |
24332 | + gr_task_is_capable(current, CAP_AUDIT_WRITE) && | |
24333 | + cap_raised(current->cap_effective, CAP_AUDIT_CONTROL) && | |
24334 | + gr_task_is_capable(current, CAP_AUDIT_CONTROL)) | |
24335 | + return current->cap_effective; | |
50425a20 | 24336 | + else if (cap_raised(current->cap_effective, CAP_NET_ADMIN) && |
24337 | + gr_task_is_capable(current, CAP_NET_ADMIN)) | |
24338 | + return current->cap_effective; | |
24339 | + else | |
4dee9bd5 | 24340 | + return __cap_empty_set; |
50425a20 | 24341 | +#else |
24342 | + return current->cap_effective; | |
24343 | +#endif | |
24344 | +} | |
4dee9bd5 | 24345 | diff -urNp linux-2.6.25.4/grsecurity/grsec_sysctl.c linux-2.6.25.4/grsecurity/grsec_sysctl.c |
24346 | --- linux-2.6.25.4/grsecurity/grsec_sysctl.c 1969-12-31 19:00:00.000000000 -0500 | |
24347 | +++ linux-2.6.25.4/grsecurity/grsec_sysctl.c 2008-05-18 13:33:16.000000000 -0400 | |
da5b3fc8 | 24348 | @@ -0,0 +1,435 @@ |
50425a20 | 24349 | +#include <linux/kernel.h> |
24350 | +#include <linux/sched.h> | |
24351 | +#include <linux/sysctl.h> | |
24352 | +#include <linux/grsecurity.h> | |
24353 | +#include <linux/grinternal.h> | |
24354 | + | |
24355 | +#ifdef CONFIG_GRKERNSEC_MODSTOP | |
24356 | +int grsec_modstop; | |
24357 | +#endif | |
24358 | + | |
24359 | +int | |
24360 | +gr_handle_sysctl_mod(const char *dirname, const char *name, const int op) | |
24361 | +{ | |
24362 | +#ifdef CONFIG_GRKERNSEC_SYSCTL | |
24363 | + if (!strcmp(dirname, "grsecurity") && grsec_lock && (op & 002)) { | |
24364 | + gr_log_str(GR_DONT_AUDIT, GR_SYSCTL_MSG, name); | |
24365 | + return -EACCES; | |
24366 | + } | |
24367 | +#endif | |
24368 | +#ifdef CONFIG_GRKERNSEC_MODSTOP | |
24369 | + if (!strcmp(dirname, "grsecurity") && !strcmp(name, "disable_modules") && | |
24370 | + grsec_modstop && (op & 002)) { | |
24371 | + gr_log_str(GR_DONT_AUDIT, GR_SYSCTL_MSG, name); | |
24372 | + return -EACCES; | |
24373 | + } | |
24374 | +#endif | |
24375 | + return 0; | |
24376 | +} | |
24377 | + | |
24378 | +#if defined(CONFIG_GRKERNSEC_SYSCTL) || defined(CONFIG_GRKERNSEC_MODSTOP) | |
50425a20 | 24379 | +ctl_table grsecurity_table[] = { |
24380 | +#ifdef CONFIG_GRKERNSEC_SYSCTL | |
24381 | +#ifdef CONFIG_GRKERNSEC_LINK | |
24382 | + { | |
da5b3fc8 | 24383 | + .ctl_name = CTL_UNNUMBERED, |
50425a20 | 24384 | + .procname = "linking_restrictions", |
24385 | + .data = &grsec_enable_link, | |
24386 | + .maxlen = sizeof(int), | |
24387 | + .mode = 0600, | |
24388 | + .proc_handler = &proc_dointvec, | |
24389 | + }, | |
24390 | +#endif | |
24391 | +#ifdef CONFIG_GRKERNSEC_FIFO | |
24392 | + { | |
da5b3fc8 | 24393 | + .ctl_name = CTL_UNNUMBERED, |
50425a20 | 24394 | + .procname = "fifo_restrictions", |
24395 | + .data = &grsec_enable_fifo, | |
24396 | + .maxlen = sizeof(int), | |
24397 | + .mode = 0600, | |
24398 | + .proc_handler = &proc_dointvec, | |
24399 | + }, | |
24400 | +#endif | |
24401 | +#ifdef CONFIG_GRKERNSEC_EXECVE | |
24402 | + { | |
da5b3fc8 | 24403 | + .ctl_name = CTL_UNNUMBERED, |
50425a20 | 24404 | + .procname = "execve_limiting", |
24405 | + .data = &grsec_enable_execve, | |
24406 | + .maxlen = sizeof(int), | |
24407 | + .mode = 0600, | |
24408 | + .proc_handler = &proc_dointvec, | |
24409 | + }, | |
24410 | +#endif | |
24411 | +#ifdef CONFIG_GRKERNSEC_EXECLOG | |
24412 | + { | |
da5b3fc8 | 24413 | + .ctl_name = CTL_UNNUMBERED, |
50425a20 | 24414 | + .procname = "exec_logging", |
24415 | + .data = &grsec_enable_execlog, | |
24416 | + .maxlen = sizeof(int), | |
24417 | + .mode = 0600, | |
24418 | + .proc_handler = &proc_dointvec, | |
24419 | + }, | |
24420 | +#endif | |
24421 | +#ifdef CONFIG_GRKERNSEC_SIGNAL | |
24422 | + { | |
da5b3fc8 | 24423 | + .ctl_name = CTL_UNNUMBERED, |
50425a20 | 24424 | + .procname = "signal_logging", |
24425 | + .data = &grsec_enable_signal, | |
24426 | + .maxlen = sizeof(int), | |
24427 | + .mode = 0600, | |
24428 | + .proc_handler = &proc_dointvec, | |
24429 | + }, | |
24430 | +#endif | |
24431 | +#ifdef CONFIG_GRKERNSEC_FORKFAIL | |
24432 | + { | |
da5b3fc8 | 24433 | + .ctl_name = CTL_UNNUMBERED, |
50425a20 | 24434 | + .procname = "forkfail_logging", |
24435 | + .data = &grsec_enable_forkfail, | |
24436 | + .maxlen = sizeof(int), | |
24437 | + .mode = 0600, | |
24438 | + .proc_handler = &proc_dointvec, | |
24439 | + }, | |
24440 | +#endif | |
24441 | +#ifdef CONFIG_GRKERNSEC_TIME | |
24442 | + { | |
da5b3fc8 | 24443 | + .ctl_name = CTL_UNNUMBERED, |
50425a20 | 24444 | + .procname = "timechange_logging", |
24445 | + .data = &grsec_enable_time, | |
24446 | + .maxlen = sizeof(int), | |
24447 | + .mode = 0600, | |
24448 | + .proc_handler = &proc_dointvec, | |
24449 | + }, | |
24450 | +#endif | |
24451 | +#ifdef CONFIG_GRKERNSEC_CHROOT_SHMAT | |
24452 | + { | |
da5b3fc8 | 24453 | + .ctl_name = CTL_UNNUMBERED, |
50425a20 | 24454 | + .procname = "chroot_deny_shmat", |
24455 | + .data = &grsec_enable_chroot_shmat, | |
24456 | + .maxlen = sizeof(int), | |
24457 | + .mode = 0600, | |
24458 | + .proc_handler = &proc_dointvec, | |
24459 | + }, | |
24460 | +#endif | |
24461 | +#ifdef CONFIG_GRKERNSEC_CHROOT_UNIX | |
24462 | + { | |
da5b3fc8 | 24463 | + .ctl_name = CTL_UNNUMBERED, |
50425a20 | 24464 | + .procname = "chroot_deny_unix", |
24465 | + .data = &grsec_enable_chroot_unix, | |
24466 | + .maxlen = sizeof(int), | |
24467 | + .mode = 0600, | |
24468 | + .proc_handler = &proc_dointvec, | |
24469 | + }, | |
24470 | +#endif | |
24471 | +#ifdef CONFIG_GRKERNSEC_CHROOT_MOUNT | |
24472 | + { | |
da5b3fc8 | 24473 | + .ctl_name = CTL_UNNUMBERED, |
50425a20 | 24474 | + .procname = "chroot_deny_mount", |
24475 | + .data = &grsec_enable_chroot_mount, | |
24476 | + .maxlen = sizeof(int), | |
24477 | + .mode = 0600, | |
24478 | + .proc_handler = &proc_dointvec, | |
24479 | + }, | |
24480 | +#endif | |
24481 | +#ifdef CONFIG_GRKERNSEC_CHROOT_FCHDIR | |
24482 | + { | |
da5b3fc8 | 24483 | + .ctl_name = CTL_UNNUMBERED, |
50425a20 | 24484 | + .procname = "chroot_deny_fchdir", |
24485 | + .data = &grsec_enable_chroot_fchdir, | |
24486 | + .maxlen = sizeof(int), | |
24487 | + .mode = 0600, | |
24488 | + .proc_handler = &proc_dointvec, | |
24489 | + }, | |
24490 | +#endif | |
24491 | +#ifdef CONFIG_GRKERNSEC_CHROOT_DOUBLE | |
24492 | + { | |
da5b3fc8 | 24493 | + .ctl_name = CTL_UNNUMBERED, |
50425a20 | 24494 | + .procname = "chroot_deny_chroot", |
24495 | + .data = &grsec_enable_chroot_double, | |
24496 | + .maxlen = sizeof(int), | |
24497 | + .mode = 0600, | |
24498 | + .proc_handler = &proc_dointvec, | |
24499 | + }, | |
24500 | +#endif | |
24501 | +#ifdef CONFIG_GRKERNSEC_CHROOT_PIVOT | |
24502 | + { | |
da5b3fc8 | 24503 | + .ctl_name = CTL_UNNUMBERED, |
50425a20 | 24504 | + .procname = "chroot_deny_pivot", |
24505 | + .data = &grsec_enable_chroot_pivot, | |
24506 | + .maxlen = sizeof(int), | |
24507 | + .mode = 0600, | |
24508 | + .proc_handler = &proc_dointvec, | |
24509 | + }, | |
24510 | +#endif | |
24511 | +#ifdef CONFIG_GRKERNSEC_CHROOT_CHDIR | |
24512 | + { | |
da5b3fc8 | 24513 | + .ctl_name = CTL_UNNUMBERED, |
50425a20 | 24514 | + .procname = "chroot_enforce_chdir", |
24515 | + .data = &grsec_enable_chroot_chdir, | |
24516 | + .maxlen = sizeof(int), | |
24517 | + .mode = 0600, | |
24518 | + .proc_handler = &proc_dointvec, | |
24519 | + }, | |
24520 | +#endif | |
24521 | +#ifdef CONFIG_GRKERNSEC_CHROOT_CHMOD | |
24522 | + { | |
da5b3fc8 | 24523 | + .ctl_name = CTL_UNNUMBERED, |
50425a20 | 24524 | + .procname = "chroot_deny_chmod", |
24525 | + .data = &grsec_enable_chroot_chmod, | |
24526 | + .maxlen = sizeof(int), | |
24527 | + .mode = 0600, | |
24528 | + .proc_handler = &proc_dointvec, | |
24529 | + }, | |
24530 | +#endif | |
24531 | +#ifdef CONFIG_GRKERNSEC_CHROOT_MKNOD | |
24532 | + { | |
da5b3fc8 | 24533 | + .ctl_name = CTL_UNNUMBERED, |
50425a20 | 24534 | + .procname = "chroot_deny_mknod", |
24535 | + .data = &grsec_enable_chroot_mknod, | |
24536 | + .maxlen = sizeof(int), | |
24537 | + .mode = 0600, | |
24538 | + .proc_handler = &proc_dointvec, | |
24539 | + }, | |
24540 | +#endif | |
24541 | +#ifdef CONFIG_GRKERNSEC_CHROOT_NICE | |
24542 | + { | |
da5b3fc8 | 24543 | + .ctl_name = CTL_UNNUMBERED, |
50425a20 | 24544 | + .procname = "chroot_restrict_nice", |
24545 | + .data = &grsec_enable_chroot_nice, | |
24546 | + .maxlen = sizeof(int), | |
24547 | + .mode = 0600, | |
24548 | + .proc_handler = &proc_dointvec, | |
24549 | + }, | |
24550 | +#endif | |
24551 | +#ifdef CONFIG_GRKERNSEC_CHROOT_EXECLOG | |
24552 | + { | |
da5b3fc8 | 24553 | + .ctl_name = CTL_UNNUMBERED, |
50425a20 | 24554 | + .procname = "chroot_execlog", |
24555 | + .data = &grsec_enable_chroot_execlog, | |
24556 | + .maxlen = sizeof(int), | |
24557 | + .mode = 0600, | |
24558 | + .proc_handler = &proc_dointvec, | |
24559 | + }, | |
24560 | +#endif | |
24561 | +#ifdef CONFIG_GRKERNSEC_CHROOT_CAPS | |
24562 | + { | |
da5b3fc8 | 24563 | + .ctl_name = CTL_UNNUMBERED, |
50425a20 | 24564 | + .procname = "chroot_caps", |
24565 | + .data = &grsec_enable_chroot_caps, | |
24566 | + .maxlen = sizeof(int), | |
24567 | + .mode = 0600, | |
24568 | + .proc_handler = &proc_dointvec, | |
24569 | + }, | |
24570 | +#endif | |
24571 | +#ifdef CONFIG_GRKERNSEC_CHROOT_SYSCTL | |
24572 | + { | |
da5b3fc8 | 24573 | + .ctl_name = CTL_UNNUMBERED, |
50425a20 | 24574 | + .procname = "chroot_deny_sysctl", |
24575 | + .data = &grsec_enable_chroot_sysctl, | |
24576 | + .maxlen = sizeof(int), | |
24577 | + .mode = 0600, | |
24578 | + .proc_handler = &proc_dointvec, | |
24579 | + }, | |
24580 | +#endif | |
24581 | +#ifdef CONFIG_GRKERNSEC_TPE | |
24582 | + { | |
da5b3fc8 | 24583 | + .ctl_name = CTL_UNNUMBERED, |
50425a20 | 24584 | + .procname = "tpe", |
24585 | + .data = &grsec_enable_tpe, | |
24586 | + .maxlen = sizeof(int), | |
24587 | + .mode = 0600, | |
24588 | + .proc_handler = &proc_dointvec, | |
24589 | + }, | |
24590 | + { | |
da5b3fc8 | 24591 | + .ctl_name = CTL_UNNUMBERED, |
50425a20 | 24592 | + .procname = "tpe_gid", |
24593 | + .data = &grsec_tpe_gid, | |
24594 | + .maxlen = sizeof(int), | |
24595 | + .mode = 0600, | |
24596 | + .proc_handler = &proc_dointvec, | |
24597 | + }, | |
24598 | +#endif | |
24599 | +#ifdef CONFIG_GRKERNSEC_TPE_ALL | |
24600 | + { | |
da5b3fc8 | 24601 | + .ctl_name = CTL_UNNUMBERED, |
50425a20 | 24602 | + .procname = "tpe_restrict_all", |
24603 | + .data = &grsec_enable_tpe_all, | |
24604 | + .maxlen = sizeof(int), | |
24605 | + .mode = 0600, | |
24606 | + .proc_handler = &proc_dointvec, | |
24607 | + }, | |
24608 | +#endif | |
24609 | +#ifdef CONFIG_GRKERNSEC_SOCKET_ALL | |
24610 | + { | |
da5b3fc8 | 24611 | + .ctl_name = CTL_UNNUMBERED, |
50425a20 | 24612 | + .procname = "socket_all", |
24613 | + .data = &grsec_enable_socket_all, | |
24614 | + .maxlen = sizeof(int), | |
24615 | + .mode = 0600, | |
24616 | + .proc_handler = &proc_dointvec, | |
24617 | + }, | |
24618 | + { | |
da5b3fc8 | 24619 | + .ctl_name = CTL_UNNUMBERED, |
50425a20 | 24620 | + .procname = "socket_all_gid", |
24621 | + .data = &grsec_socket_all_gid, | |
24622 | + .maxlen = sizeof(int), | |
24623 | + .mode = 0600, | |
24624 | + .proc_handler = &proc_dointvec, | |
24625 | + }, | |
24626 | +#endif | |
24627 | +#ifdef CONFIG_GRKERNSEC_SOCKET_CLIENT | |
24628 | + { | |
da5b3fc8 | 24629 | + .ctl_name = CTL_UNNUMBERED, |
50425a20 | 24630 | + .procname = "socket_client", |
24631 | + .data = &grsec_enable_socket_client, | |
24632 | + .maxlen = sizeof(int), | |
24633 | + .mode = 0600, | |
24634 | + .proc_handler = &proc_dointvec, | |
24635 | + }, | |
24636 | + { | |
da5b3fc8 | 24637 | + .ctl_name = CTL_UNNUMBERED, |
50425a20 | 24638 | + .procname = "socket_client_gid", |
24639 | + .data = &grsec_socket_client_gid, | |
24640 | + .maxlen = sizeof(int), | |
24641 | + .mode = 0600, | |
24642 | + .proc_handler = &proc_dointvec, | |
24643 | + }, | |
24644 | +#endif | |
24645 | +#ifdef CONFIG_GRKERNSEC_SOCKET_SERVER | |
24646 | + { | |
da5b3fc8 | 24647 | + .ctl_name = CTL_UNNUMBERED, |
50425a20 | 24648 | + .procname = "socket_server", |
24649 | + .data = &grsec_enable_socket_server, | |
24650 | + .maxlen = sizeof(int), | |
24651 | + .mode = 0600, | |
24652 | + .proc_handler = &proc_dointvec, | |
24653 | + }, | |
24654 | + { | |
da5b3fc8 | 24655 | + .ctl_name = CTL_UNNUMBERED, |
50425a20 | 24656 | + .procname = "socket_server_gid", |
24657 | + .data = &grsec_socket_server_gid, | |
24658 | + .maxlen = sizeof(int), | |
24659 | + .mode = 0600, | |
24660 | + .proc_handler = &proc_dointvec, | |
24661 | + }, | |
24662 | +#endif | |
24663 | +#ifdef CONFIG_GRKERNSEC_AUDIT_GROUP | |
24664 | + { | |
da5b3fc8 | 24665 | + .ctl_name = CTL_UNNUMBERED, |
50425a20 | 24666 | + .procname = "audit_group", |
24667 | + .data = &grsec_enable_group, | |
24668 | + .maxlen = sizeof(int), | |
24669 | + .mode = 0600, | |
24670 | + .proc_handler = &proc_dointvec, | |
24671 | + }, | |
24672 | + { | |
da5b3fc8 | 24673 | + .ctl_name = CTL_UNNUMBERED, |
50425a20 | 24674 | + .procname = "audit_gid", |
24675 | + .data = &grsec_audit_gid, | |
24676 | + .maxlen = sizeof(int), | |
24677 | + .mode = 0600, | |
24678 | + .proc_handler = &proc_dointvec, | |
24679 | + }, | |
24680 | +#endif | |
24681 | +#ifdef CONFIG_GRKERNSEC_AUDIT_CHDIR | |
24682 | + { | |
da5b3fc8 | 24683 | + .ctl_name = CTL_UNNUMBERED, |
50425a20 | 24684 | + .procname = "audit_chdir", |
24685 | + .data = &grsec_enable_chdir, | |
24686 | + .maxlen = sizeof(int), | |
24687 | + .mode = 0600, | |
24688 | + .proc_handler = &proc_dointvec, | |
24689 | + }, | |
24690 | +#endif | |
24691 | +#ifdef CONFIG_GRKERNSEC_AUDIT_MOUNT | |
24692 | + { | |
da5b3fc8 | 24693 | + .ctl_name = CTL_UNNUMBERED, |
50425a20 | 24694 | + .procname = "audit_mount", |
24695 | + .data = &grsec_enable_mount, | |
24696 | + .maxlen = sizeof(int), | |
24697 | + .mode = 0600, | |
24698 | + .proc_handler = &proc_dointvec, | |
24699 | + }, | |
24700 | +#endif | |
24701 | +#ifdef CONFIG_GRKERNSEC_AUDIT_IPC | |
24702 | + { | |
da5b3fc8 | 24703 | + .ctl_name = CTL_UNNUMBERED, |
50425a20 | 24704 | + .procname = "audit_ipc", |
24705 | + .data = &grsec_enable_audit_ipc, | |
24706 | + .maxlen = sizeof(int), | |
24707 | + .mode = 0600, | |
24708 | + .proc_handler = &proc_dointvec, | |
24709 | + }, | |
24710 | +#endif | |
24711 | +#ifdef CONFIG_GRKERNSEC_AUDIT_TEXTREL | |
24712 | + { | |
da5b3fc8 | 24713 | + .ctl_name = CTL_UNNUMBERED, |
50425a20 | 24714 | + .procname = "audit_textrel", |
24715 | + .data = &grsec_enable_audit_textrel, | |
24716 | + .maxlen = sizeof(int), | |
24717 | + .mode = 0600, | |
24718 | + .proc_handler = &proc_dointvec, | |
24719 | + }, | |
24720 | +#endif | |
24721 | +#ifdef CONFIG_GRKERNSEC_DMESG | |
24722 | + { | |
da5b3fc8 | 24723 | + .ctl_name = CTL_UNNUMBERED, |
24724 | + .procname = "dmesg", | |
24725 | + .data = &grsec_enable_dmesg, | |
50425a20 | 24726 | + .maxlen = sizeof(int), |
24727 | + .mode = 0600, | |
24728 | + .proc_handler = &proc_dointvec, | |
24729 | + }, | |
24730 | +#endif | |
da5b3fc8 | 24731 | +#ifdef CONFIG_GRKERNSEC_CHROOT_FINDTASK |
50425a20 | 24732 | + { |
da5b3fc8 | 24733 | + .ctl_name = CTL_UNNUMBERED, |
24734 | + .procname = "chroot_findtask", | |
24735 | + .data = &grsec_enable_chroot_findtask, | |
50425a20 | 24736 | + .maxlen = sizeof(int), |
24737 | + .mode = 0600, | |
24738 | + .proc_handler = &proc_dointvec, | |
24739 | + }, | |
24740 | +#endif | |
24741 | +#ifdef CONFIG_GRKERNSEC_RESLOG | |
24742 | + { | |
da5b3fc8 | 24743 | + .ctl_name = CTL_UNNUMBERED, |
50425a20 | 24744 | + .procname = "resource_logging", |
24745 | + .data = &grsec_resource_logging, | |
24746 | + .maxlen = sizeof(int), | |
24747 | + .mode = 0600, | |
24748 | + .proc_handler = &proc_dointvec, | |
24749 | + }, | |
24750 | +#endif | |
24751 | + { | |
da5b3fc8 | 24752 | + .ctl_name = CTL_UNNUMBERED, |
50425a20 | 24753 | + .procname = "grsec_lock", |
24754 | + .data = &grsec_lock, | |
24755 | + .maxlen = sizeof(int), | |
24756 | + .mode = 0600, | |
24757 | + .proc_handler = &proc_dointvec, | |
24758 | + }, | |
24759 | +#endif | |
24760 | +#ifdef CONFIG_GRKERNSEC_MODSTOP | |
24761 | + { | |
da5b3fc8 | 24762 | + .ctl_name = CTL_UNNUMBERED, |
50425a20 | 24763 | + .procname = "disable_modules", |
24764 | + .data = &grsec_modstop, | |
24765 | + .maxlen = sizeof(int), | |
24766 | + .mode = 0600, | |
24767 | + .proc_handler = &proc_dointvec, | |
24768 | + }, | |
24769 | +#endif | |
24770 | + { .ctl_name = 0 } | |
24771 | +}; | |
24772 | +#endif | |
24773 | + | |
24774 | +int gr_check_modstop(void) | |
24775 | +{ | |
24776 | +#ifdef CONFIG_GRKERNSEC_MODSTOP | |
24777 | + if (grsec_modstop == 1) { | |
24778 | + gr_log_noargs(GR_DONT_AUDIT, GR_STOPMOD_MSG); | |
24779 | + return 1; | |
24780 | + } | |
24781 | +#endif | |
24782 | + return 0; | |
24783 | +} | |
4dee9bd5 | 24784 | diff -urNp linux-2.6.25.4/grsecurity/grsec_textrel.c linux-2.6.25.4/grsecurity/grsec_textrel.c |
24785 | --- linux-2.6.25.4/grsecurity/grsec_textrel.c 1969-12-31 19:00:00.000000000 -0500 | |
24786 | +++ linux-2.6.25.4/grsecurity/grsec_textrel.c 2008-05-18 13:33:16.000000000 -0400 | |
50425a20 | 24787 | @@ -0,0 +1,16 @@ |
24788 | +#include <linux/kernel.h> | |
24789 | +#include <linux/sched.h> | |
24790 | +#include <linux/mm.h> | |
24791 | +#include <linux/file.h> | |
24792 | +#include <linux/grinternal.h> | |
24793 | +#include <linux/grsecurity.h> | |
24794 | + | |
24795 | +void | |
24796 | +gr_log_textrel(struct vm_area_struct * vma) | |
24797 | +{ | |
24798 | +#ifdef CONFIG_GRKERNSEC_AUDIT_TEXTREL | |
24799 | + if (grsec_enable_audit_textrel) | |
24800 | + gr_log_textrel_ulong_ulong(GR_DO_AUDIT, GR_TEXTREL_AUDIT_MSG, vma->vm_file, vma->vm_start, vma->vm_pgoff); | |
24801 | +#endif | |
24802 | + return; | |
24803 | +} | |
4dee9bd5 | 24804 | diff -urNp linux-2.6.25.4/grsecurity/grsec_time.c linux-2.6.25.4/grsecurity/grsec_time.c |
24805 | --- linux-2.6.25.4/grsecurity/grsec_time.c 1969-12-31 19:00:00.000000000 -0500 | |
24806 | +++ linux-2.6.25.4/grsecurity/grsec_time.c 2008-05-18 13:33:16.000000000 -0400 | |
50425a20 | 24807 | @@ -0,0 +1,13 @@ |
24808 | +#include <linux/kernel.h> | |
24809 | +#include <linux/sched.h> | |
24810 | +#include <linux/grinternal.h> | |
24811 | + | |
24812 | +void | |
24813 | +gr_log_timechange(void) | |
24814 | +{ | |
24815 | +#ifdef CONFIG_GRKERNSEC_TIME | |
24816 | + if (grsec_enable_time) | |
24817 | + gr_log_noargs(GR_DONT_AUDIT_GOOD, GR_TIME_MSG); | |
24818 | +#endif | |
24819 | + return; | |
24820 | +} | |
4dee9bd5 | 24821 | diff -urNp linux-2.6.25.4/grsecurity/grsec_tpe.c linux-2.6.25.4/grsecurity/grsec_tpe.c |
24822 | --- linux-2.6.25.4/grsecurity/grsec_tpe.c 1969-12-31 19:00:00.000000000 -0500 | |
24823 | +++ linux-2.6.25.4/grsecurity/grsec_tpe.c 2008-05-18 13:33:16.000000000 -0400 | |
50425a20 | 24824 | @@ -0,0 +1,37 @@ |
24825 | +#include <linux/kernel.h> | |
24826 | +#include <linux/sched.h> | |
24827 | +#include <linux/file.h> | |
24828 | +#include <linux/fs.h> | |
24829 | +#include <linux/grinternal.h> | |
24830 | + | |
24831 | +extern int gr_acl_tpe_check(void); | |
24832 | + | |
24833 | +int | |
24834 | +gr_tpe_allow(const struct file *file) | |
24835 | +{ | |
24836 | +#ifdef CONFIG_GRKERNSEC | |
4dee9bd5 | 24837 | + struct inode *inode = file->f_path.dentry->d_parent->d_inode; |
50425a20 | 24838 | + |
24839 | + if (current->uid && ((grsec_enable_tpe && | |
24840 | +#ifdef CONFIG_GRKERNSEC_TPE_INVERT | |
24841 | + !in_group_p(grsec_tpe_gid) | |
24842 | +#else | |
24843 | + in_group_p(grsec_tpe_gid) | |
24844 | +#endif | |
24845 | + ) || gr_acl_tpe_check()) && | |
24846 | + (inode->i_uid || (!inode->i_uid && ((inode->i_mode & S_IWGRP) || | |
24847 | + (inode->i_mode & S_IWOTH))))) { | |
4dee9bd5 | 24848 | + gr_log_fs_generic(GR_DONT_AUDIT, GR_EXEC_TPE_MSG, file->f_path.dentry, file->f_path.mnt); |
50425a20 | 24849 | + return 0; |
24850 | + } | |
24851 | +#ifdef CONFIG_GRKERNSEC_TPE_ALL | |
24852 | + if (current->uid && grsec_enable_tpe && grsec_enable_tpe_all && | |
24853 | + ((inode->i_uid && (inode->i_uid != current->uid)) || | |
24854 | + (inode->i_mode & S_IWGRP) || (inode->i_mode & S_IWOTH))) { | |
4dee9bd5 | 24855 | + gr_log_fs_generic(GR_DONT_AUDIT, GR_EXEC_TPE_MSG, file->f_path.dentry, file->f_path.mnt); |
50425a20 | 24856 | + return 0; |
24857 | + } | |
24858 | +#endif | |
24859 | +#endif | |
24860 | + return 1; | |
24861 | +} | |
4dee9bd5 | 24862 | diff -urNp linux-2.6.25.4/grsecurity/grsum.c linux-2.6.25.4/grsecurity/grsum.c |
24863 | --- linux-2.6.25.4/grsecurity/grsum.c 1969-12-31 19:00:00.000000000 -0500 | |
24864 | +++ linux-2.6.25.4/grsecurity/grsum.c 2008-05-18 13:33:16.000000000 -0400 | |
da5b3fc8 | 24865 | @@ -0,0 +1,59 @@ |
24866 | +#include <linux/err.h> | |
50425a20 | 24867 | +#include <linux/kernel.h> |
24868 | +#include <linux/sched.h> | |
24869 | +#include <linux/mm.h> | |
24870 | +#include <linux/scatterlist.h> | |
24871 | +#include <linux/crypto.h> | |
24872 | +#include <linux/gracl.h> | |
24873 | + | |
24874 | + | |
24875 | +#if !defined(CONFIG_CRYPTO) || defined(CONFIG_CRYPTO_MODULE) || !defined(CONFIG_CRYPTO_SHA256) || defined(CONFIG_CRYPTO_SHA256_MODULE) | |
24876 | +#error "crypto and sha256 must be built into the kernel" | |
24877 | +#endif | |
24878 | + | |
24879 | +int | |
24880 | +chkpw(struct gr_arg *entry, unsigned char *salt, unsigned char *sum) | |
24881 | +{ | |
24882 | + char *p; | |
24883 | + struct crypto_hash *tfm; | |
24884 | + struct hash_desc desc; | |
24885 | + struct scatterlist sg; | |
24886 | + unsigned char temp_sum[GR_SHA_LEN]; | |
24887 | + volatile int retval = 0; | |
24888 | + volatile int dummy = 0; | |
24889 | + unsigned int i; | |
24890 | + | |
24891 | + tfm = crypto_alloc_hash("sha256", 0, CRYPTO_ALG_ASYNC); | |
24892 | + if (IS_ERR(tfm)) { | |
24893 | + /* should never happen, since sha256 should be built in */ | |
24894 | + return 1; | |
24895 | + } | |
24896 | + | |
24897 | + desc.tfm = tfm; | |
24898 | + desc.flags = 0; | |
24899 | + | |
24900 | + crypto_hash_init(&desc); | |
24901 | + | |
24902 | + p = salt; | |
24903 | + sg_set_buf(&sg, p, GR_SALT_LEN); | |
24904 | + crypto_hash_update(&desc, &sg, sg.length); | |
24905 | + | |
24906 | + p = entry->pw; | |
24907 | + sg_set_buf(&sg, p, strlen(p)); | |
24908 | + | |
24909 | + crypto_hash_update(&desc, &sg, sg.length); | |
24910 | + | |
24911 | + crypto_hash_final(&desc, temp_sum); | |
24912 | + | |
24913 | + memset(entry->pw, 0, GR_PW_LEN); | |
24914 | + | |
24915 | + for (i = 0; i < GR_SHA_LEN; i++) | |
24916 | + if (sum[i] != temp_sum[i]) | |
24917 | + retval = 1; | |
24918 | + else | |
24919 | + dummy = 1; // waste a cycle | |
24920 | + | |
24921 | + crypto_free_hash(tfm); | |
24922 | + | |
24923 | + return retval; | |
24924 | +} | |
4dee9bd5 | 24925 | diff -urNp linux-2.6.25.4/grsecurity/Kconfig linux-2.6.25.4/grsecurity/Kconfig |
24926 | --- linux-2.6.25.4/grsecurity/Kconfig 1969-12-31 19:00:00.000000000 -0500 | |
24927 | +++ linux-2.6.25.4/grsecurity/Kconfig 2008-05-18 13:33:16.000000000 -0400 | |
7bcbf78a | 24928 | @@ -0,0 +1,861 @@ |
50425a20 | 24929 | +# |
24930 | +# grecurity configuration | |
24931 | +# | |
24932 | + | |
24933 | +menu "Grsecurity" | |
24934 | + | |
24935 | +config GRKERNSEC | |
24936 | + bool "Grsecurity" | |
24937 | + select CRYPTO | |
24938 | + select CRYPTO_SHA256 | |
7bcbf78a | 24939 | + select SECURITY |
24940 | + select SECURITY_CAPABILITIES | |
50425a20 | 24941 | + help |
24942 | + If you say Y here, you will be able to configure many features | |
24943 | + that will enhance the security of your system. It is highly | |
24944 | + recommended that you say Y here and read through the help | |
24945 | + for each option so that you fully understand the features and | |
24946 | + can evaluate their usefulness for your machine. | |
24947 | + | |
24948 | +choice | |
24949 | + prompt "Security Level" | |
da5b3fc8 | 24950 | + depends on GRKERNSEC |
50425a20 | 24951 | + default GRKERNSEC_CUSTOM |
24952 | + | |
24953 | +config GRKERNSEC_LOW | |
24954 | + bool "Low" | |
24955 | + select GRKERNSEC_LINK | |
24956 | + select GRKERNSEC_FIFO | |
24957 | + select GRKERNSEC_EXECVE | |
24958 | + select GRKERNSEC_RANDNET | |
24959 | + select GRKERNSEC_DMESG | |
24960 | + select GRKERNSEC_CHROOT_CHDIR | |
24961 | + select GRKERNSEC_MODSTOP if (MODULES) | |
24962 | + | |
24963 | + help | |
24964 | + If you choose this option, several of the grsecurity options will | |
24965 | + be enabled that will give you greater protection against a number | |
24966 | + of attacks, while assuring that none of your software will have any | |
24967 | + conflicts with the additional security measures. If you run a lot | |
24968 | + of unusual software, or you are having problems with the higher | |
24969 | + security levels, you should say Y here. With this option, the | |
24970 | + following features are enabled: | |
24971 | + | |
24972 | + - Linking restrictions | |
24973 | + - FIFO restrictions | |
24974 | + - Enforcing RLIMIT_NPROC on execve | |
24975 | + - Restricted dmesg | |
24976 | + - Enforced chdir("/") on chroot | |
24977 | + - Runtime module disabling | |
24978 | + | |
24979 | +config GRKERNSEC_MEDIUM | |
24980 | + bool "Medium" | |
24981 | + select PAX | |
24982 | + select PAX_EI_PAX | |
24983 | + select PAX_PT_PAX_FLAGS | |
24984 | + select PAX_HAVE_ACL_FLAGS | |
24985 | + select GRKERNSEC_PROC_MEMMAP if (PAX_NOEXEC || PAX_ASLR) | |
24986 | + select GRKERNSEC_CHROOT_SYSCTL | |
24987 | + select GRKERNSEC_LINK | |
24988 | + select GRKERNSEC_FIFO | |
24989 | + select GRKERNSEC_EXECVE | |
24990 | + select GRKERNSEC_DMESG | |
24991 | + select GRKERNSEC_RANDNET | |
24992 | + select GRKERNSEC_FORKFAIL | |
24993 | + select GRKERNSEC_TIME | |
24994 | + select GRKERNSEC_SIGNAL | |
24995 | + select GRKERNSEC_CHROOT | |
24996 | + select GRKERNSEC_CHROOT_UNIX | |
24997 | + select GRKERNSEC_CHROOT_MOUNT | |
24998 | + select GRKERNSEC_CHROOT_PIVOT | |
24999 | + select GRKERNSEC_CHROOT_DOUBLE | |
25000 | + select GRKERNSEC_CHROOT_CHDIR | |
25001 | + select GRKERNSEC_CHROOT_MKNOD | |
25002 | + select GRKERNSEC_PROC | |
25003 | + select GRKERNSEC_PROC_USERGROUP | |
25004 | + select GRKERNSEC_MODSTOP if (MODULES) | |
25005 | + select PAX_RANDUSTACK | |
25006 | + select PAX_ASLR | |
25007 | + select PAX_RANDMMAP | |
25008 | + | |
25009 | + help | |
25010 | + If you say Y here, several features in addition to those included | |
25011 | + in the low additional security level will be enabled. These | |
25012 | + features provide even more security to your system, though in rare | |
25013 | + cases they may be incompatible with very old or poorly written | |
25014 | + software. If you enable this option, make sure that your auth | |
25015 | + service (identd) is running as gid 1001. With this option, | |
25016 | + the following features (in addition to those provided in the | |
25017 | + low additional security level) will be enabled: | |
25018 | + | |
50425a20 | 25019 | + - Failed fork logging |
25020 | + - Time change logging | |
25021 | + - Signal logging | |
25022 | + - Deny mounts in chroot | |
25023 | + - Deny double chrooting | |
25024 | + - Deny sysctl writes in chroot | |
25025 | + - Deny mknod in chroot | |
25026 | + - Deny access to abstract AF_UNIX sockets out of chroot | |
25027 | + - Deny pivot_root in chroot | |
25028 | + - Denied writes of /dev/kmem, /dev/mem, and /dev/port | |
25029 | + - /proc restrictions with special GID set to 10 (usually wheel) | |
25030 | + - Address Space Layout Randomization (ASLR) | |
25031 | + | |
25032 | +config GRKERNSEC_HIGH | |
25033 | + bool "High" | |
25034 | + select GRKERNSEC_LINK | |
25035 | + select GRKERNSEC_FIFO | |
25036 | + select GRKERNSEC_EXECVE | |
25037 | + select GRKERNSEC_DMESG | |
25038 | + select GRKERNSEC_FORKFAIL | |
25039 | + select GRKERNSEC_TIME | |
25040 | + select GRKERNSEC_SIGNAL | |
25041 | + select GRKERNSEC_CHROOT_SHMAT | |
25042 | + select GRKERNSEC_CHROOT_UNIX | |
25043 | + select GRKERNSEC_CHROOT_MOUNT | |
25044 | + select GRKERNSEC_CHROOT_FCHDIR | |
25045 | + select GRKERNSEC_CHROOT_PIVOT | |
25046 | + select GRKERNSEC_CHROOT_DOUBLE | |
25047 | + select GRKERNSEC_CHROOT_CHDIR | |
25048 | + select GRKERNSEC_CHROOT_MKNOD | |
25049 | + select GRKERNSEC_CHROOT_CAPS | |
25050 | + select GRKERNSEC_CHROOT_SYSCTL | |
25051 | + select GRKERNSEC_CHROOT_FINDTASK | |
25052 | + select GRKERNSEC_PROC | |
25053 | + select GRKERNSEC_PROC_MEMMAP if (PAX_NOEXEC || PAX_ASLR) | |
25054 | + select GRKERNSEC_HIDESYM | |
25055 | + select GRKERNSEC_BRUTE | |
50425a20 | 25056 | + select GRKERNSEC_PROC_USERGROUP |
25057 | + select GRKERNSEC_KMEM | |
25058 | + select GRKERNSEC_RESLOG | |
25059 | + select GRKERNSEC_RANDNET | |
25060 | + select GRKERNSEC_PROC_ADD | |
25061 | + select GRKERNSEC_CHROOT_CHMOD | |
25062 | + select GRKERNSEC_CHROOT_NICE | |
25063 | + select GRKERNSEC_AUDIT_MOUNT | |
25064 | + select GRKERNSEC_MODSTOP if (MODULES) | |
25065 | + select PAX | |
25066 | + select PAX_RANDUSTACK | |
25067 | + select PAX_ASLR | |
25068 | + select PAX_RANDMMAP | |
25069 | + select PAX_NOEXEC | |
25070 | + select PAX_MPROTECT | |
25071 | + select PAX_EI_PAX | |
25072 | + select PAX_PT_PAX_FLAGS | |
25073 | + select PAX_HAVE_ACL_FLAGS | |
da5b3fc8 | 25074 | + select PAX_KERNEXEC if (X86 && !EFI && !COMPAT_VDSO && !PARAVIRT && (!X86_32 || X86_WP_WORKS_OK)) |
73ca38b2 | 25075 | + select PAX_MEMORY_UDEREF if (!X86_64 && !COMPAT_VDSO) |
50425a20 | 25076 | + select PAX_RANDKSTACK if (X86_TSC && !X86_64) |
25077 | + select PAX_SEGMEXEC if (X86 && !X86_64) | |
25078 | + select PAX_PAGEEXEC if (!X86) | |
25079 | + select PAX_EMUPLT if (ALPHA || PARISC || PPC32 || SPARC32 || SPARC64) | |
25080 | + select PAX_DLRESOLVE if (SPARC32 || SPARC64) | |
25081 | + select PAX_SYSCALL if (PPC32) | |
25082 | + select PAX_EMUTRAMP if (PARISC) | |
25083 | + select PAX_EMUSIGRT if (PARISC) | |
25084 | + select PAX_ETEXECRELOCS if (ALPHA || IA64 || PARISC) | |
25085 | + help | |
25086 | + If you say Y here, many of the features of grsecurity will be | |
25087 | + enabled, which will protect you against many kinds of attacks | |
25088 | + against your system. The heightened security comes at a cost | |
25089 | + of an increased chance of incompatibilities with rare software | |
25090 | + on your machine. Since this security level enables PaX, you should | |
25091 | + view <http://pax.grsecurity.net> and read about the PaX | |
25092 | + project. While you are there, download chpax and run it on | |
25093 | + binaries that cause problems with PaX. Also remember that | |
25094 | + since the /proc restrictions are enabled, you must run your | |
25095 | + identd as gid 1001. This security level enables the following | |
25096 | + features in addition to those listed in the low and medium | |
25097 | + security levels: | |
25098 | + | |
25099 | + - Additional /proc restrictions | |
25100 | + - Chmod restrictions in chroot | |
25101 | + - No signals, ptrace, or viewing of processes outside of chroot | |
25102 | + - Capability restrictions in chroot | |
25103 | + - Deny fchdir out of chroot | |
25104 | + - Priority restrictions in chroot | |
25105 | + - Segmentation-based implementation of PaX | |
25106 | + - Mprotect restrictions | |
25107 | + - Removal of addresses from /proc/<pid>/[smaps|maps|stat] | |
25108 | + - Kernel stack randomization | |
25109 | + - Mount/unmount/remount logging | |
25110 | + - Kernel symbol hiding | |
50425a20 | 25111 | + - Prevention of memory exhaustion-based exploits |
25112 | +config GRKERNSEC_CUSTOM | |
25113 | + bool "Custom" | |
25114 | + help | |
25115 | + If you say Y here, you will be able to configure every grsecurity | |
25116 | + option, which allows you to enable many more features that aren't | |
25117 | + covered in the basic security levels. These additional features | |
25118 | + include TPE, socket restrictions, and the sysctl system for | |
25119 | + grsecurity. It is advised that you read through the help for | |
25120 | + each option to determine its usefulness in your situation. | |
25121 | + | |
25122 | +endchoice | |
25123 | + | |
25124 | +menu "Address Space Protection" | |
25125 | +depends on GRKERNSEC | |
25126 | + | |
25127 | +config GRKERNSEC_KMEM | |
25128 | + bool "Deny writing to /dev/kmem, /dev/mem, and /dev/port" | |
25129 | + help | |
25130 | + If you say Y here, /dev/kmem and /dev/mem won't be allowed to | |
25131 | + be written to via mmap or otherwise to modify the running kernel. | |
25132 | + /dev/port will also not be allowed to be opened. If you have module | |
25133 | + support disabled, enabling this will close up four ways that are | |
25134 | + currently used to insert malicious code into the running kernel. | |
25135 | + Even with all these features enabled, we still highly recommend that | |
25136 | + you use the RBAC system, as it is still possible for an attacker to | |
25137 | + modify the running kernel through privileged I/O granted by ioperm/iopl. | |
25138 | + If you are not using XFree86, you may be able to stop this additional | |
25139 | + case by enabling the 'Disable privileged I/O' option. Though nothing | |
25140 | + legitimately writes to /dev/kmem, XFree86 does need to write to /dev/mem, | |
25141 | + but only to video memory, which is the only writing we allow in this | |
25142 | + case. If /dev/kmem or /dev/mem are mmaped without PROT_WRITE, they will | |
25143 | + not be allowed to mprotect it with PROT_WRITE later. | |
25144 | + It is highly recommended that you say Y here if you meet all the | |
25145 | + conditions above. | |
25146 | + | |
25147 | +config GRKERNSEC_IO | |
25148 | + bool "Disable privileged I/O" | |
25149 | + depends on X86 | |
25150 | + select RTC | |
25151 | + help | |
25152 | + If you say Y here, all ioperm and iopl calls will return an error. | |
25153 | + Ioperm and iopl can be used to modify the running kernel. | |
25154 | + Unfortunately, some programs need this access to operate properly, | |
25155 | + the most notable of which are XFree86 and hwclock. hwclock can be | |
25156 | + remedied by having RTC support in the kernel, so CONFIG_RTC is | |
25157 | + enabled if this option is enabled, to ensure that hwclock operates | |
25158 | + correctly. XFree86 still will not operate correctly with this option | |
25159 | + enabled, so DO NOT CHOOSE Y IF YOU USE XFree86. If you use XFree86 | |
25160 | + and you still want to protect your kernel against modification, | |
25161 | + use the RBAC system. | |
25162 | + | |
25163 | +config GRKERNSEC_PROC_MEMMAP | |
25164 | + bool "Remove addresses from /proc/<pid>/[smaps|maps|stat]" | |
25165 | + depends on PAX_NOEXEC || PAX_ASLR | |
25166 | + help | |
25167 | + If you say Y here, the /proc/<pid>/maps and /proc/<pid>/stat files will | |
25168 | + give no information about the addresses of its mappings if | |
25169 | + PaX features that rely on random addresses are enabled on the task. | |
25170 | + If you use PaX it is greatly recommended that you say Y here as it | |
25171 | + closes up a hole that makes the full ASLR useless for suid | |
25172 | + binaries. | |
25173 | + | |
25174 | +config GRKERNSEC_BRUTE | |
25175 | + bool "Deter exploit bruteforcing" | |
25176 | + help | |
25177 | + If you say Y here, attempts to bruteforce exploits against forking | |
25178 | + daemons such as apache or sshd will be deterred. When a child of a | |
25179 | + forking daemon is killed by PaX or crashes due to an illegal | |
25180 | + instruction, the parent process will be delayed 30 seconds upon every | |
25181 | + subsequent fork until the administrator is able to assess the | |
25182 | + situation and restart the daemon. It is recommended that you also | |
25183 | + enable signal logging in the auditing section so that logs are | |
25184 | + generated when a process performs an illegal instruction. | |
25185 | + | |
25186 | +config GRKERNSEC_MODSTOP | |
25187 | + bool "Runtime module disabling" | |
25188 | + depends on MODULES | |
25189 | + help | |
25190 | + If you say Y here, you will be able to disable the ability to (un)load | |
25191 | + modules at runtime. This feature is useful if you need the ability | |
25192 | + to load kernel modules at boot time, but do not want to allow an | |
25193 | + attacker to load a rootkit kernel module into the system, or to remove | |
25194 | + a loaded kernel module important to system functioning. You should | |
25195 | + enable the /dev/mem protection feature as well, since rootkits can be | |
25196 | + inserted into the kernel via other methods than kernel modules. Since | |
25197 | + an untrusted module could still be loaded by modifying init scripts and | |
25198 | + rebooting the system, it is also recommended that you enable the RBAC | |
25199 | + system. If you enable this option, a sysctl option with name | |
25200 | + "disable_modules" will be created. Setting this option to "1" disables | |
25201 | + module loading. After this option is set, no further writes to it are | |
25202 | + allowed until the system is rebooted. | |
25203 | + | |
25204 | +config GRKERNSEC_HIDESYM | |
25205 | + bool "Hide kernel symbols" | |
25206 | + help | |
25207 | + If you say Y here, getting information on loaded modules, and | |
25208 | + displaying all kernel symbols through a syscall will be restricted | |
25209 | + to users with CAP_SYS_MODULE. This option is only effective | |
25210 | + provided the following conditions are met: | |
25211 | + 1) The kernel using grsecurity is not precompiled by some distribution | |
25212 | + 2) You are using the RBAC system and hiding other files such as your | |
25213 | + kernel image and System.map | |
25214 | + 3) You have the additional /proc restrictions enabled, which removes | |
25215 | + /proc/kcore | |
25216 | + If the above conditions are met, this option will aid to provide a | |
25217 | + useful protection against local and remote kernel exploitation of | |
25218 | + overflows and arbitrary read/write vulnerabilities. | |
25219 | + | |
25220 | +endmenu | |
25221 | +menu "Role Based Access Control Options" | |
25222 | +depends on GRKERNSEC | |
25223 | + | |
25224 | +config GRKERNSEC_ACL_HIDEKERN | |
25225 | + bool "Hide kernel processes" | |
25226 | + help | |
25227 | + If you say Y here, all kernel threads will be hidden to all | |
25228 | + processes but those whose subject has the "view hidden processes" | |
25229 | + flag. | |
25230 | + | |
25231 | +config GRKERNSEC_ACL_MAXTRIES | |
25232 | + int "Maximum tries before password lockout" | |
25233 | + default 3 | |
25234 | + help | |
25235 | + This option enforces the maximum number of times a user can attempt | |
25236 | + to authorize themselves with the grsecurity RBAC system before being | |
25237 | + denied the ability to attempt authorization again for a specified time. | |
25238 | + The lower the number, the harder it will be to brute-force a password. | |
25239 | + | |
25240 | +config GRKERNSEC_ACL_TIMEOUT | |
25241 | + int "Time to wait after max password tries, in seconds" | |
25242 | + default 30 | |
25243 | + help | |
25244 | + This option specifies the time the user must wait after attempting to | |
25245 | + authorize to the RBAC system with the maximum number of invalid | |
25246 | + passwords. The higher the number, the harder it will be to brute-force | |
25247 | + a password. | |
25248 | + | |
25249 | +endmenu | |
25250 | +menu "Filesystem Protections" | |
25251 | +depends on GRKERNSEC | |
25252 | + | |
25253 | +config GRKERNSEC_PROC | |
25254 | + bool "Proc restrictions" | |
25255 | + help | |
25256 | + If you say Y here, the permissions of the /proc filesystem | |
25257 | + will be altered to enhance system security and privacy. You MUST | |
25258 | + choose either a user only restriction or a user and group restriction. | |
25259 | + Depending upon the option you choose, you can either restrict users to | |
25260 | + see only the processes they themselves run, or choose a group that can | |
25261 | + view all processes and files normally restricted to root if you choose | |
25262 | + the "restrict to user only" option. NOTE: If you're running identd as | |
25263 | + a non-root user, you will have to run it as the group you specify here. | |
25264 | + | |
25265 | +config GRKERNSEC_PROC_USER | |
25266 | + bool "Restrict /proc to user only" | |
25267 | + depends on GRKERNSEC_PROC | |
25268 | + help | |
25269 | + If you say Y here, non-root users will only be able to view their own | |
25270 | + processes, and restricts them from viewing network-related information, | |
25271 | + and viewing kernel symbol and module information. | |
25272 | + | |
25273 | +config GRKERNSEC_PROC_USERGROUP | |
25274 | + bool "Allow special group" | |
25275 | + depends on GRKERNSEC_PROC && !GRKERNSEC_PROC_USER | |
25276 | + help | |
25277 | + If you say Y here, you will be able to select a group that will be | |
25278 | + able to view all processes, network-related information, and | |
25279 | + kernel and symbol information. This option is useful if you want | |
25280 | + to run identd as a non-root user. | |
25281 | + | |
25282 | +config GRKERNSEC_PROC_GID | |
25283 | + int "GID for special group" | |
25284 | + depends on GRKERNSEC_PROC_USERGROUP | |
25285 | + default 1001 | |
25286 | + | |
25287 | +config GRKERNSEC_PROC_ADD | |
25288 | + bool "Additional restrictions" | |
25289 | + depends on GRKERNSEC_PROC_USER || GRKERNSEC_PROC_USERGROUP | |
25290 | + help | |
25291 | + If you say Y here, additional restrictions will be placed on | |
25292 | + /proc that keep normal users from viewing device information and | |
25293 | + slabinfo information that could be useful for exploits. | |
25294 | + | |
25295 | +config GRKERNSEC_LINK | |
25296 | + bool "Linking restrictions" | |
25297 | + help | |
25298 | + If you say Y here, /tmp race exploits will be prevented, since users | |
25299 | + will no longer be able to follow symlinks owned by other users in | |
25300 | + world-writable +t directories (i.e. /tmp), unless the owner of the | |
25301 | + symlink is the owner of the directory. users will also not be | |
25302 | + able to hardlink to files they do not own. If the sysctl option is | |
25303 | + enabled, a sysctl option with name "linking_restrictions" is created. | |
25304 | + | |
25305 | +config GRKERNSEC_FIFO | |
25306 | + bool "FIFO restrictions" | |
25307 | + help | |
25308 | + If you say Y here, users will not be able to write to FIFOs they don't | |
25309 | + own in world-writable +t directories (i.e. /tmp), unless the owner of | |
25310 | + the FIFO is the same owner of the directory it's held in. If the sysctl | |
25311 | + option is enabled, a sysctl option with name "fifo_restrictions" is | |
25312 | + created. | |
25313 | + | |
25314 | +config GRKERNSEC_CHROOT | |
25315 | + bool "Chroot jail restrictions" | |
25316 | + help | |
25317 | + If you say Y here, you will be able to choose several options that will | |
25318 | + make breaking out of a chrooted jail much more difficult. If you | |
25319 | + encounter no software incompatibilities with the following options, it | |
25320 | + is recommended that you enable each one. | |
25321 | + | |
25322 | +config GRKERNSEC_CHROOT_MOUNT | |
25323 | + bool "Deny mounts" | |
25324 | + depends on GRKERNSEC_CHROOT | |
25325 | + help | |
25326 | + If you say Y here, processes inside a chroot will not be able to | |
25327 | + mount or remount filesystems. If the sysctl option is enabled, a | |
25328 | + sysctl option with name "chroot_deny_mount" is created. | |
25329 | + | |
25330 | +config GRKERNSEC_CHROOT_DOUBLE | |
25331 | + bool "Deny double-chroots" | |
25332 | + depends on GRKERNSEC_CHROOT | |
25333 | + help | |
25334 | + If you say Y here, processes inside a chroot will not be able to chroot | |
25335 | + again outside the chroot. This is a widely used method of breaking | |
25336 | + out of a chroot jail and should not be allowed. If the sysctl | |
25337 | + option is enabled, a sysctl option with name | |
25338 | + "chroot_deny_chroot" is created. | |
25339 | + | |
25340 | +config GRKERNSEC_CHROOT_PIVOT | |
25341 | + bool "Deny pivot_root in chroot" | |
25342 | + depends on GRKERNSEC_CHROOT | |
25343 | + help | |
25344 | + If you say Y here, processes inside a chroot will not be able to use | |
25345 | + a function called pivot_root() that was introduced in Linux 2.3.41. It | |
25346 | + works similar to chroot in that it changes the root filesystem. This | |
25347 | + function could be misused in a chrooted process to attempt to break out | |
25348 | + of the chroot, and therefore should not be allowed. If the sysctl | |
25349 | + option is enabled, a sysctl option with name "chroot_deny_pivot" is | |
25350 | + created. | |
25351 | + | |
25352 | +config GRKERNSEC_CHROOT_CHDIR | |
25353 | + bool "Enforce chdir(\"/\") on all chroots" | |
25354 | + depends on GRKERNSEC_CHROOT | |
25355 | + help | |
25356 | + If you say Y here, the current working directory of all newly-chrooted | |
25357 | + applications will be set to the the root directory of the chroot. | |
25358 | + The man page on chroot(2) states: | |
25359 | + Note that this call does not change the current working | |
25360 | + directory, so that `.' can be outside the tree rooted at | |
25361 | + `/'. In particular, the super-user can escape from a | |
25362 | + `chroot jail' by doing `mkdir foo; chroot foo; cd ..'. | |
25363 | + | |
25364 | + It is recommended that you say Y here, since it's not known to break | |
25365 | + any software. If the sysctl option is enabled, a sysctl option with | |
25366 | + name "chroot_enforce_chdir" is created. | |
25367 | + | |
25368 | +config GRKERNSEC_CHROOT_CHMOD | |
25369 | + bool "Deny (f)chmod +s" | |
25370 | + depends on GRKERNSEC_CHROOT | |
25371 | + help | |
25372 | + If you say Y here, processes inside a chroot will not be able to chmod | |
25373 | + or fchmod files to make them have suid or sgid bits. This protects | |
25374 | + against another published method of breaking a chroot. If the sysctl | |
25375 | + option is enabled, a sysctl option with name "chroot_deny_chmod" is | |
25376 | + created. | |
25377 | + | |
25378 | +config GRKERNSEC_CHROOT_FCHDIR | |
25379 | + bool "Deny fchdir out of chroot" | |
25380 | + depends on GRKERNSEC_CHROOT | |
25381 | + help | |
25382 | + If you say Y here, a well-known method of breaking chroots by fchdir'ing | |
25383 | + to a file descriptor of the chrooting process that points to a directory | |
25384 | + outside the filesystem will be stopped. If the sysctl option | |
25385 | + is enabled, a sysctl option with name "chroot_deny_fchdir" is created. | |
25386 | + | |
25387 | +config GRKERNSEC_CHROOT_MKNOD | |
25388 | + bool "Deny mknod" | |
25389 | + depends on GRKERNSEC_CHROOT | |
25390 | + help | |
25391 | + If you say Y here, processes inside a chroot will not be allowed to | |
25392 | + mknod. The problem with using mknod inside a chroot is that it | |
25393 | + would allow an attacker to create a device entry that is the same | |
25394 | + as one on the physical root of your system, which could range from | |
25395 | + anything from the console device to a device for your harddrive (which | |
25396 | + they could then use to wipe the drive or steal data). It is recommended | |
25397 | + that you say Y here, unless you run into software incompatibilities. | |
25398 | + If the sysctl option is enabled, a sysctl option with name | |
25399 | + "chroot_deny_mknod" is created. | |
25400 | + | |
25401 | +config GRKERNSEC_CHROOT_SHMAT | |
25402 | + bool "Deny shmat() out of chroot" | |
25403 | + depends on GRKERNSEC_CHROOT | |
25404 | + help | |
25405 | + If you say Y here, processes inside a chroot will not be able to attach | |
25406 | + to shared memory segments that were created outside of the chroot jail. | |
25407 | + It is recommended that you say Y here. If the sysctl option is enabled, | |
25408 | + a sysctl option with name "chroot_deny_shmat" is created. | |
25409 | + | |
25410 | +config GRKERNSEC_CHROOT_UNIX | |
25411 | + bool "Deny access to abstract AF_UNIX sockets out of chroot" | |
25412 | + depends on GRKERNSEC_CHROOT | |
25413 | + help | |
25414 | + If you say Y here, processes inside a chroot will not be able to | |
25415 | + connect to abstract (meaning not belonging to a filesystem) Unix | |
25416 | + domain sockets that were bound outside of a chroot. It is recommended | |
25417 | + that you say Y here. If the sysctl option is enabled, a sysctl option | |
25418 | + with name "chroot_deny_unix" is created. | |
25419 | + | |
25420 | +config GRKERNSEC_CHROOT_FINDTASK | |
25421 | + bool "Protect outside processes" | |
25422 | + depends on GRKERNSEC_CHROOT | |
25423 | + help | |
25424 | + If you say Y here, processes inside a chroot will not be able to | |
25425 | + kill, send signals with fcntl, ptrace, capget, getpgid, getsid, | |
25426 | + or view any process outside of the chroot. If the sysctl | |
25427 | + option is enabled, a sysctl option with name "chroot_findtask" is | |
25428 | + created. | |
25429 | + | |
25430 | +config GRKERNSEC_CHROOT_NICE | |
25431 | + bool "Restrict priority changes" | |
25432 | + depends on GRKERNSEC_CHROOT | |
25433 | + help | |
25434 | + If you say Y here, processes inside a chroot will not be able to raise | |
25435 | + the priority of processes in the chroot, or alter the priority of | |
25436 | + processes outside the chroot. This provides more security than simply | |
25437 | + removing CAP_SYS_NICE from the process' capability set. If the | |
25438 | + sysctl option is enabled, a sysctl option with name "chroot_restrict_nice" | |
25439 | + is created. | |
25440 | + | |
25441 | +config GRKERNSEC_CHROOT_SYSCTL | |
25442 | + bool "Deny sysctl writes" | |
25443 | + depends on GRKERNSEC_CHROOT | |
25444 | + help | |
25445 | + If you say Y here, an attacker in a chroot will not be able to | |
25446 | + write to sysctl entries, either by sysctl(2) or through a /proc | |
25447 | + interface. It is strongly recommended that you say Y here. If the | |
25448 | + sysctl option is enabled, a sysctl option with name | |
25449 | + "chroot_deny_sysctl" is created. | |
25450 | + | |
25451 | +config GRKERNSEC_CHROOT_CAPS | |
25452 | + bool "Capability restrictions" | |
25453 | + depends on GRKERNSEC_CHROOT | |
25454 | + help | |
25455 | + If you say Y here, the capabilities on all root processes within a | |
25456 | + chroot jail will be lowered to stop module insertion, raw i/o, | |
25457 | + system and net admin tasks, rebooting the system, modifying immutable | |
25458 | + files, modifying IPC owned by another, and changing the system time. | |
25459 | + This is left an option because it can break some apps. Disable this | |
25460 | + if your chrooted apps are having problems performing those kinds of | |
25461 | + tasks. If the sysctl option is enabled, a sysctl option with | |
25462 | + name "chroot_caps" is created. | |
25463 | + | |
25464 | +endmenu | |
25465 | +menu "Kernel Auditing" | |
25466 | +depends on GRKERNSEC | |
25467 | + | |
25468 | +config GRKERNSEC_AUDIT_GROUP | |
25469 | + bool "Single group for auditing" | |
25470 | + help | |
25471 | + If you say Y here, the exec, chdir, (un)mount, and ipc logging features | |
25472 | + will only operate on a group you specify. This option is recommended | |
25473 | + if you only want to watch certain users instead of having a large | |
25474 | + amount of logs from the entire system. If the sysctl option is enabled, | |
25475 | + a sysctl option with name "audit_group" is created. | |
25476 | + | |
25477 | +config GRKERNSEC_AUDIT_GID | |
25478 | + int "GID for auditing" | |
25479 | + depends on GRKERNSEC_AUDIT_GROUP | |
25480 | + default 1007 | |
25481 | + | |
25482 | +config GRKERNSEC_EXECLOG | |
25483 | + bool "Exec logging" | |
25484 | + help | |
25485 | + If you say Y here, all execve() calls will be logged (since the | |
25486 | + other exec*() calls are frontends to execve(), all execution | |
25487 | + will be logged). Useful for shell-servers that like to keep track | |
25488 | + of their users. If the sysctl option is enabled, a sysctl option with | |
25489 | + name "exec_logging" is created. | |
25490 | + WARNING: This option when enabled will produce a LOT of logs, especially | |
25491 | + on an active system. | |
25492 | + | |
25493 | +config GRKERNSEC_RESLOG | |
25494 | + bool "Resource logging" | |
25495 | + help | |
25496 | + If you say Y here, all attempts to overstep resource limits will | |
25497 | + be logged with the resource name, the requested size, and the current | |
25498 | + limit. It is highly recommended that you say Y here. If the sysctl | |
25499 | + option is enabled, a sysctl option with name "resource_logging" is | |
25500 | + created. If the RBAC system is enabled, the sysctl value is ignored. | |
25501 | + | |
25502 | +config GRKERNSEC_CHROOT_EXECLOG | |
25503 | + bool "Log execs within chroot" | |
25504 | + help | |
25505 | + If you say Y here, all executions inside a chroot jail will be logged | |
25506 | + to syslog. This can cause a large amount of logs if certain | |
25507 | + applications (eg. djb's daemontools) are installed on the system, and | |
25508 | + is therefore left as an option. If the sysctl option is enabled, a | |
25509 | + sysctl option with name "chroot_execlog" is created. | |
25510 | + | |
25511 | +config GRKERNSEC_AUDIT_CHDIR | |
25512 | + bool "Chdir logging" | |
25513 | + help | |
25514 | + If you say Y here, all chdir() calls will be logged. If the sysctl | |
25515 | + option is enabled, a sysctl option with name "audit_chdir" is created. | |
25516 | + | |
25517 | +config GRKERNSEC_AUDIT_MOUNT | |
25518 | + bool "(Un)Mount logging" | |
25519 | + help | |
25520 | + If you say Y here, all mounts and unmounts will be logged. If the | |
25521 | + sysctl option is enabled, a sysctl option with name "audit_mount" is | |
25522 | + created. | |
25523 | + | |
25524 | +config GRKERNSEC_AUDIT_IPC | |
25525 | + bool "IPC logging" | |
25526 | + help | |
25527 | + If you say Y here, creation and removal of message queues, semaphores, | |
25528 | + and shared memory will be logged. If the sysctl option is enabled, a | |
25529 | + sysctl option with name "audit_ipc" is created. | |
25530 | + | |
25531 | +config GRKERNSEC_SIGNAL | |
25532 | + bool "Signal logging" | |
25533 | + help | |
25534 | + If you say Y here, certain important signals will be logged, such as | |
25535 | + SIGSEGV, which will as a result inform you of when a error in a program | |
25536 | + occurred, which in some cases could mean a possible exploit attempt. | |
25537 | + If the sysctl option is enabled, a sysctl option with name | |
25538 | + "signal_logging" is created. | |
25539 | + | |
25540 | +config GRKERNSEC_FORKFAIL | |
25541 | + bool "Fork failure logging" | |
25542 | + help | |
25543 | + If you say Y here, all failed fork() attempts will be logged. | |
25544 | + This could suggest a fork bomb, or someone attempting to overstep | |
25545 | + their process limit. If the sysctl option is enabled, a sysctl option | |
25546 | + with name "forkfail_logging" is created. | |
25547 | + | |
25548 | +config GRKERNSEC_TIME | |
25549 | + bool "Time change logging" | |
25550 | + help | |
25551 | + If you say Y here, any changes of the system clock will be logged. | |
25552 | + If the sysctl option is enabled, a sysctl option with name | |
25553 | + "timechange_logging" is created. | |
25554 | + | |
25555 | +config GRKERNSEC_PROC_IPADDR | |
25556 | + bool "/proc/<pid>/ipaddr support" | |
25557 | + help | |
25558 | + If you say Y here, a new entry will be added to each /proc/<pid> | |
25559 | + directory that contains the IP address of the person using the task. | |
25560 | + The IP is carried across local TCP and AF_UNIX stream sockets. | |
25561 | + This information can be useful for IDS/IPSes to perform remote response | |
25562 | + to a local attack. The entry is readable by only the owner of the | |
25563 | + process (and root if he has CAP_DAC_OVERRIDE, which can be removed via | |
25564 | + the RBAC system), and thus does not create privacy concerns. | |
25565 | + | |
25566 | +config GRKERNSEC_AUDIT_TEXTREL | |
25567 | + bool 'ELF text relocations logging (READ HELP)' | |
25568 | + depends on PAX_MPROTECT | |
25569 | + help | |
25570 | + If you say Y here, text relocations will be logged with the filename | |
25571 | + of the offending library or binary. The purpose of the feature is | |
25572 | + to help Linux distribution developers get rid of libraries and | |
25573 | + binaries that need text relocations which hinder the future progress | |
25574 | + of PaX. Only Linux distribution developers should say Y here, and | |
25575 | + never on a production machine, as this option creates an information | |
25576 | + leak that could aid an attacker in defeating the randomization of | |
25577 | + a single memory region. If the sysctl option is enabled, a sysctl | |
25578 | + option with name "audit_textrel" is created. | |
25579 | + | |
25580 | +endmenu | |
25581 | + | |
25582 | +menu "Executable Protections" | |
25583 | +depends on GRKERNSEC | |
25584 | + | |
25585 | +config GRKERNSEC_EXECVE | |
25586 | + bool "Enforce RLIMIT_NPROC on execs" | |
25587 | + help | |
25588 | + If you say Y here, users with a resource limit on processes will | |
25589 | + have the value checked during execve() calls. The current system | |
25590 | + only checks the system limit during fork() calls. If the sysctl option | |
25591 | + is enabled, a sysctl option with name "execve_limiting" is created. | |
25592 | + | |
50425a20 | 25593 | +config GRKERNSEC_DMESG |
25594 | + bool "Dmesg(8) restriction" | |
25595 | + help | |
25596 | + If you say Y here, non-root users will not be able to use dmesg(8) | |
25597 | + to view up to the last 4kb of messages in the kernel's log buffer. | |
25598 | + If the sysctl option is enabled, a sysctl option with name "dmesg" is | |
25599 | + created. | |
25600 | + | |
25601 | +config GRKERNSEC_TPE | |
25602 | + bool "Trusted Path Execution (TPE)" | |
25603 | + help | |
25604 | + If you say Y here, you will be able to choose a gid to add to the | |
25605 | + supplementary groups of users you want to mark as "untrusted." | |
25606 | + These users will not be able to execute any files that are not in | |
25607 | + root-owned directories writable only by root. If the sysctl option | |
25608 | + is enabled, a sysctl option with name "tpe" is created. | |
25609 | + | |
25610 | +config GRKERNSEC_TPE_ALL | |
25611 | + bool "Partially restrict non-root users" | |
25612 | + depends on GRKERNSEC_TPE | |
25613 | + help | |
25614 | + If you say Y here, All non-root users other than the ones in the | |
25615 | + group specified in the main TPE option will only be allowed to | |
25616 | + execute files in directories they own that are not group or | |
25617 | + world-writable, or in directories owned by root and writable only by | |
25618 | + root. If the sysctl option is enabled, a sysctl option with name | |
25619 | + "tpe_restrict_all" is created. | |
25620 | + | |
25621 | +config GRKERNSEC_TPE_INVERT | |
25622 | + bool "Invert GID option" | |
25623 | + depends on GRKERNSEC_TPE | |
25624 | + help | |
25625 | + If you say Y here, the group you specify in the TPE configuration will | |
25626 | + decide what group TPE restrictions will be *disabled* for. This | |
25627 | + option is useful if you want TPE restrictions to be applied to most | |
25628 | + users on the system. | |
25629 | + | |
25630 | +config GRKERNSEC_TPE_GID | |
25631 | + int "GID for untrusted users" | |
25632 | + depends on GRKERNSEC_TPE && !GRKERNSEC_TPE_INVERT | |
25633 | + default 1005 | |
25634 | + help | |
25635 | + If you have selected the "Invert GID option" above, setting this | |
25636 | + GID determines what group TPE restrictions will be *disabled* for. | |
25637 | + If you have not selected the "Invert GID option" above, setting this | |
25638 | + GID determines what group TPE restrictions will be *enabled* for. | |
25639 | + If the sysctl option is enabled, a sysctl option with name "tpe_gid" | |
25640 | + is created. | |
25641 | + | |
25642 | +config GRKERNSEC_TPE_GID | |
25643 | + int "GID for trusted users" | |
25644 | + depends on GRKERNSEC_TPE && GRKERNSEC_TPE_INVERT | |
25645 | + default 1005 | |
25646 | + help | |
25647 | + If you have selected the "Invert GID option" above, setting this | |
25648 | + GID determines what group TPE restrictions will be *disabled* for. | |
25649 | + If you have not selected the "Invert GID option" above, setting this | |
25650 | + GID determines what group TPE restrictions will be *enabled* for. | |
25651 | + If the sysctl option is enabled, a sysctl option with name "tpe_gid" | |
25652 | + is created. | |
25653 | + | |
25654 | +endmenu | |
25655 | +menu "Network Protections" | |
25656 | +depends on GRKERNSEC | |
25657 | + | |
25658 | +config GRKERNSEC_RANDNET | |
25659 | + bool "Larger entropy pools" | |
25660 | + help | |
25661 | + If you say Y here, the entropy pools used for many features of Linux | |
25662 | + and grsecurity will be doubled in size. Since several grsecurity | |
25663 | + features use additional randomness, it is recommended that you say Y | |
25664 | + here. Saying Y here has a similar effect as modifying | |
25665 | + /proc/sys/kernel/random/poolsize. | |
25666 | + | |
25667 | +config GRKERNSEC_SOCKET | |
25668 | + bool "Socket restrictions" | |
25669 | + help | |
25670 | + If you say Y here, you will be able to choose from several options. | |
25671 | + If you assign a GID on your system and add it to the supplementary | |
25672 | + groups of users you want to restrict socket access to, this patch | |
25673 | + will perform up to three things, based on the option(s) you choose. | |
25674 | + | |
25675 | +config GRKERNSEC_SOCKET_ALL | |
25676 | + bool "Deny any sockets to group" | |
25677 | + depends on GRKERNSEC_SOCKET | |
25678 | + help | |
25679 | + If you say Y here, you will be able to choose a GID of whose users will | |
25680 | + be unable to connect to other hosts from your machine or run server | |
25681 | + applications from your machine. If the sysctl option is enabled, a | |
25682 | + sysctl option with name "socket_all" is created. | |
25683 | + | |
25684 | +config GRKERNSEC_SOCKET_ALL_GID | |
25685 | + int "GID to deny all sockets for" | |
25686 | + depends on GRKERNSEC_SOCKET_ALL | |
25687 | + default 1004 | |
25688 | + help | |
25689 | + Here you can choose the GID to disable socket access for. Remember to | |
25690 | + add the users you want socket access disabled for to the GID | |
25691 | + specified here. If the sysctl option is enabled, a sysctl option | |
25692 | + with name "socket_all_gid" is created. | |
25693 | + | |
25694 | +config GRKERNSEC_SOCKET_CLIENT | |
25695 | + bool "Deny client sockets to group" | |
25696 | + depends on GRKERNSEC_SOCKET | |
25697 | + help | |
25698 | + If you say Y here, you will be able to choose a GID of whose users will | |
25699 | + be unable to connect to other hosts from your machine, but will be | |
25700 | + able to run servers. If this option is enabled, all users in the group | |
25701 | + you specify will have to use passive mode when initiating ftp transfers | |
25702 | + from the shell on your machine. If the sysctl option is enabled, a | |
25703 | + sysctl option with name "socket_client" is created. | |
25704 | + | |
25705 | +config GRKERNSEC_SOCKET_CLIENT_GID | |
25706 | + int "GID to deny client sockets for" | |
25707 | + depends on GRKERNSEC_SOCKET_CLIENT | |
25708 | + default 1003 | |
25709 | + help | |
25710 | + Here you can choose the GID to disable client socket access for. | |
25711 | + Remember to add the users you want client socket access disabled for to | |
25712 | + the GID specified here. If the sysctl option is enabled, a sysctl | |
25713 | + option with name "socket_client_gid" is created. | |
25714 | + | |
25715 | +config GRKERNSEC_SOCKET_SERVER | |
25716 | + bool "Deny server sockets to group" | |
25717 | + depends on GRKERNSEC_SOCKET | |
25718 | + help | |
25719 | + If you say Y here, you will be able to choose a GID of whose users will | |
25720 | + be unable to run server applications from your machine. If the sysctl | |
25721 | + option is enabled, a sysctl option with name "socket_server" is created. | |
25722 | + | |
25723 | +config GRKERNSEC_SOCKET_SERVER_GID | |
25724 | + int "GID to deny server sockets for" | |
25725 | + depends on GRKERNSEC_SOCKET_SERVER | |
25726 | + default 1002 | |
25727 | + help | |
25728 | + Here you can choose the GID to disable server socket access for. | |
25729 | + Remember to add the users you want server socket access disabled for to | |
25730 | + the GID specified here. If the sysctl option is enabled, a sysctl | |
25731 | + option with name "socket_server_gid" is created. | |
25732 | + | |
25733 | +endmenu | |
25734 | +menu "Sysctl support" | |
25735 | +depends on GRKERNSEC && SYSCTL | |
25736 | + | |
25737 | +config GRKERNSEC_SYSCTL | |
25738 | + bool "Sysctl support" | |
25739 | + help | |
25740 | + If you say Y here, you will be able to change the options that | |
25741 | + grsecurity runs with at bootup, without having to recompile your | |
25742 | + kernel. You can echo values to files in /proc/sys/kernel/grsecurity | |
25743 | + to enable (1) or disable (0) various features. All the sysctl entries | |
25744 | + are mutable until the "grsec_lock" entry is set to a non-zero value. | |
25745 | + All features enabled in the kernel configuration are disabled at boot | |
25746 | + if you do not say Y to the "Turn on features by default" option. | |
25747 | + All options should be set at startup, and the grsec_lock entry should | |
25748 | + be set to a non-zero value after all the options are set. | |
25749 | + *THIS IS EXTREMELY IMPORTANT* | |
25750 | + | |
25751 | +config GRKERNSEC_SYSCTL_ON | |
25752 | + bool "Turn on features by default" | |
25753 | + depends on GRKERNSEC_SYSCTL | |
25754 | + help | |
25755 | + If you say Y here, instead of having all features enabled in the | |
25756 | + kernel configuration disabled at boot time, the features will be | |
25757 | + enabled at boot time. It is recommended you say Y here unless | |
25758 | + there is some reason you would want all sysctl-tunable features to | |
25759 | + be disabled by default. As mentioned elsewhere, it is important | |
25760 | + to enable the grsec_lock entry once you have finished modifying | |
25761 | + the sysctl entries. | |
25762 | + | |
25763 | +endmenu | |
25764 | +menu "Logging Options" | |
25765 | +depends on GRKERNSEC | |
25766 | + | |
25767 | +config GRKERNSEC_FLOODTIME | |
25768 | + int "Seconds in between log messages (minimum)" | |
25769 | + default 10 | |
25770 | + help | |
25771 | + This option allows you to enforce the number of seconds between | |
25772 | + grsecurity log messages. The default should be suitable for most | |
25773 | + people, however, if you choose to change it, choose a value small enough | |
25774 | + to allow informative logs to be produced, but large enough to | |
25775 | + prevent flooding. | |
25776 | + | |
25777 | +config GRKERNSEC_FLOODBURST | |
25778 | + int "Number of messages in a burst (maximum)" | |
25779 | + default 4 | |
25780 | + help | |
25781 | + This option allows you to choose the maximum number of messages allowed | |
25782 | + within the flood time interval you chose in a separate option. The | |
25783 | + default should be suitable for most people, however if you find that | |
25784 | + many of your logs are being interpreted as flooding, you may want to | |
25785 | + raise this value. | |
25786 | + | |
25787 | +endmenu | |
25788 | + | |
25789 | +endmenu | |
4dee9bd5 | 25790 | diff -urNp linux-2.6.25.4/grsecurity/Makefile linux-2.6.25.4/grsecurity/Makefile |
25791 | --- linux-2.6.25.4/grsecurity/Makefile 1969-12-31 19:00:00.000000000 -0500 | |
25792 | +++ linux-2.6.25.4/grsecurity/Makefile 2008-05-18 13:33:16.000000000 -0400 | |
50425a20 | 25793 | @@ -0,0 +1,20 @@ |
25794 | +# grsecurity's ACL system was originally written in 2001 by Michael Dalton | |
25795 | +# during 2001-2005 it has been completely redesigned by Brad Spengler | |
25796 | +# into an RBAC system | |
25797 | +# | |
25798 | +# All code in this directory and various hooks inserted throughout the kernel | |
25799 | +# are copyright Brad Spengler, and released under the GPL v2 or higher | |
25800 | + | |
25801 | +obj-y = grsec_chdir.o grsec_chroot.o grsec_exec.o grsec_fifo.o grsec_fork.o \ | |
25802 | + grsec_mount.o grsec_sig.o grsec_sock.o grsec_sysctl.o \ | |
25803 | + grsec_time.o grsec_tpe.o grsec_ipc.o grsec_link.o grsec_textrel.o | |
25804 | + | |
25805 | +obj-$(CONFIG_GRKERNSEC) += grsec_init.o grsum.o gracl.o gracl_ip.o gracl_segv.o \ | |
25806 | + gracl_cap.o gracl_alloc.o gracl_shm.o grsec_mem.o gracl_fs.o \ | |
25807 | + gracl_learn.o grsec_log.o | |
25808 | +obj-$(CONFIG_GRKERNSEC_RESLOG) += gracl_res.o | |
25809 | + | |
25810 | +ifndef CONFIG_GRKERNSEC | |
25811 | +obj-y += grsec_disabled.o | |
25812 | +endif | |
25813 | + | |
4dee9bd5 | 25814 | diff -urNp linux-2.6.25.4/include/asm-alpha/elf.h linux-2.6.25.4/include/asm-alpha/elf.h |
25815 | --- linux-2.6.25.4/include/asm-alpha/elf.h 2008-05-15 11:00:12.000000000 -0400 | |
25816 | +++ linux-2.6.25.4/include/asm-alpha/elf.h 2008-05-18 13:33:16.000000000 -0400 | |
8a4b4a5e | 25817 | @@ -91,6 +91,13 @@ typedef elf_fpreg_t elf_fpregset_t[ELF_N |
50425a20 | 25818 | |
25819 | #define ELF_ET_DYN_BASE (TASK_UNMAPPED_BASE + 0x1000000) | |
25820 | ||
25821 | +#ifdef CONFIG_PAX_ASLR | |
8a4b4a5e | 25822 | +#define PAX_ELF_ET_DYN_BASE (current->personality & ADDR_LIMIT_32BIT ? 0x10000 : 0x120000000UL) |
50425a20 | 25823 | + |
8a4b4a5e | 25824 | +#define PAX_DELTA_MMAP_LEN (current->personality & ADDR_LIMIT_32BIT ? 14 : 28) |
25825 | +#define PAX_DELTA_STACK_LEN (current->personality & ADDR_LIMIT_32BIT ? 14 : 19) | |
50425a20 | 25826 | +#endif |
25827 | + | |
25828 | /* $0 is set by ld.so to a pointer to a function which might be | |
25829 | registered using atexit. This provides a mean for the dynamic | |
25830 | linker to call DT_FINI functions for shared libraries that have | |
4dee9bd5 | 25831 | diff -urNp linux-2.6.25.4/include/asm-alpha/kmap_types.h linux-2.6.25.4/include/asm-alpha/kmap_types.h |
25832 | --- linux-2.6.25.4/include/asm-alpha/kmap_types.h 2008-05-15 11:00:12.000000000 -0400 | |
25833 | +++ linux-2.6.25.4/include/asm-alpha/kmap_types.h 2008-05-18 13:33:17.000000000 -0400 | |
50425a20 | 25834 | @@ -24,7 +24,8 @@ D(9) KM_IRQ0, |
25835 | D(10) KM_IRQ1, | |
25836 | D(11) KM_SOFTIRQ0, | |
25837 | D(12) KM_SOFTIRQ1, | |
25838 | -D(13) KM_TYPE_NR | |
25839 | +D(13) KM_CLEARPAGE, | |
25840 | +D(14) KM_TYPE_NR | |
25841 | }; | |
25842 | ||
25843 | #undef D | |
4dee9bd5 | 25844 | diff -urNp linux-2.6.25.4/include/asm-alpha/pgtable.h linux-2.6.25.4/include/asm-alpha/pgtable.h |
25845 | --- linux-2.6.25.4/include/asm-alpha/pgtable.h 2008-05-15 11:00:12.000000000 -0400 | |
25846 | +++ linux-2.6.25.4/include/asm-alpha/pgtable.h 2008-05-18 13:33:17.000000000 -0400 | |
50425a20 | 25847 | @@ -101,6 +101,17 @@ struct vm_area_struct; |
25848 | #define PAGE_SHARED __pgprot(_PAGE_VALID | __ACCESS_BITS) | |
25849 | #define PAGE_COPY __pgprot(_PAGE_VALID | __ACCESS_BITS | _PAGE_FOW) | |
25850 | #define PAGE_READONLY __pgprot(_PAGE_VALID | __ACCESS_BITS | _PAGE_FOW) | |
25851 | + | |
25852 | +#ifdef CONFIG_PAX_PAGEEXEC | |
25853 | +# define PAGE_SHARED_NOEXEC __pgprot(_PAGE_VALID | __ACCESS_BITS | _PAGE_FOE) | |
25854 | +# define PAGE_COPY_NOEXEC __pgprot(_PAGE_VALID | __ACCESS_BITS | _PAGE_FOW | _PAGE_FOE) | |
25855 | +# define PAGE_READONLY_NOEXEC __pgprot(_PAGE_VALID | __ACCESS_BITS | _PAGE_FOW | _PAGE_FOE) | |
25856 | +#else | |
25857 | +# define PAGE_SHARED_NOEXEC PAGE_SHARED | |
25858 | +# define PAGE_COPY_NOEXEC PAGE_COPY | |
25859 | +# define PAGE_READONLY_NOEXEC PAGE_READONLY | |
25860 | +#endif | |
25861 | + | |
25862 | #define PAGE_KERNEL __pgprot(_PAGE_VALID | _PAGE_ASM | _PAGE_KRE | _PAGE_KWE) | |
25863 | ||
25864 | #define _PAGE_NORMAL(x) __pgprot(_PAGE_VALID | __ACCESS_BITS | (x)) | |
4dee9bd5 | 25865 | diff -urNp linux-2.6.25.4/include/asm-arm/elf.h linux-2.6.25.4/include/asm-arm/elf.h |
25866 | --- linux-2.6.25.4/include/asm-arm/elf.h 2008-05-15 11:00:12.000000000 -0400 | |
25867 | +++ linux-2.6.25.4/include/asm-arm/elf.h 2008-05-18 13:33:17.000000000 -0400 | |
25868 | @@ -87,7 +87,14 @@ extern char elf_platform[]; | |
da5b3fc8 | 25869 | the loader. We need to make sure that it is out of the way of the program |
25870 | that it will "exec", and that there is sufficient room for the brk. */ | |
50425a20 | 25871 | |
da5b3fc8 | 25872 | -#define ELF_ET_DYN_BASE (2 * TASK_SIZE / 3) |
25873 | +#define ELF_ET_DYN_BASE (TASK_SIZE / 3 * 2) | |
25874 | + | |
50425a20 | 25875 | +#ifdef CONFIG_PAX_ASLR |
8a4b4a5e | 25876 | +#define PAX_ELF_ET_DYN_BASE 0x00008000UL |
50425a20 | 25877 | + |
8a4b4a5e | 25878 | +#define PAX_DELTA_MMAP_LEN ((current->personality == PER_LINUX_32BIT) ? 16 : 10) |
25879 | +#define PAX_DELTA_STACK_LEN ((current->personality == PER_LINUX_32BIT) ? 16 : 10) | |
50425a20 | 25880 | +#endif |
da5b3fc8 | 25881 | |
50425a20 | 25882 | /* When the program starts, a1 contains a pointer to a function to be |
25883 | registered with atexit, as per the SVR4 ABI. A value of 0 means we | |
4dee9bd5 | 25884 | diff -urNp linux-2.6.25.4/include/asm-arm/kmap_types.h linux-2.6.25.4/include/asm-arm/kmap_types.h |
25885 | --- linux-2.6.25.4/include/asm-arm/kmap_types.h 2008-05-15 11:00:12.000000000 -0400 | |
25886 | +++ linux-2.6.25.4/include/asm-arm/kmap_types.h 2008-05-18 13:33:17.000000000 -0400 | |
50425a20 | 25887 | @@ -18,6 +18,7 @@ enum km_type { |
25888 | KM_IRQ1, | |
25889 | KM_SOFTIRQ0, | |
25890 | KM_SOFTIRQ1, | |
25891 | + KM_CLEARPAGE, | |
25892 | KM_TYPE_NR | |
25893 | }; | |
25894 | ||
4dee9bd5 | 25895 | diff -urNp linux-2.6.25.4/include/asm-avr32/elf.h linux-2.6.25.4/include/asm-avr32/elf.h |
25896 | --- linux-2.6.25.4/include/asm-avr32/elf.h 2008-05-15 11:00:12.000000000 -0400 | |
25897 | +++ linux-2.6.25.4/include/asm-avr32/elf.h 2008-05-18 13:33:17.000000000 -0400 | |
8a4b4a5e | 25898 | @@ -85,8 +85,14 @@ typedef struct user_fpu_struct elf_fpreg |
50425a20 | 25899 | the loader. We need to make sure that it is out of the way of the program |
25900 | that it will "exec", and that there is sufficient room for the brk. */ | |
25901 | ||
25902 | -#define ELF_ET_DYN_BASE (2 * TASK_SIZE / 3) | |
25903 | +#define ELF_ET_DYN_BASE (TASK_SIZE / 3 * 2) | |
25904 | ||
25905 | +#ifdef CONFIG_PAX_ASLR | |
8a4b4a5e | 25906 | +#define PAX_ELF_ET_DYN_BASE 0x00001000UL |
50425a20 | 25907 | + |
8a4b4a5e | 25908 | +#define PAX_DELTA_MMAP_LEN 15 |
25909 | +#define PAX_DELTA_STACK_LEN 15 | |
50425a20 | 25910 | +#endif |
25911 | ||
25912 | /* This yields a mask that user programs can use to figure out what | |
25913 | instruction set this CPU supports. This could be done in user space, | |
4dee9bd5 | 25914 | diff -urNp linux-2.6.25.4/include/asm-avr32/kmap_types.h linux-2.6.25.4/include/asm-avr32/kmap_types.h |
25915 | --- linux-2.6.25.4/include/asm-avr32/kmap_types.h 2008-05-15 11:00:12.000000000 -0400 | |
25916 | +++ linux-2.6.25.4/include/asm-avr32/kmap_types.h 2008-05-18 13:33:17.000000000 -0400 | |
8a4b4a5e | 25917 | @@ -22,7 +22,8 @@ D(10) KM_IRQ0, |
25918 | D(11) KM_IRQ1, | |
25919 | D(12) KM_SOFTIRQ0, | |
25920 | D(13) KM_SOFTIRQ1, | |
25921 | -D(14) KM_TYPE_NR | |
25922 | +D(14) KM_CLEARPAGE, | |
25923 | +D(15) KM_TYPE_NR | |
25924 | }; | |
25925 | ||
25926 | #undef D | |
4dee9bd5 | 25927 | diff -urNp linux-2.6.25.4/include/asm-blackfin/kmap_types.h linux-2.6.25.4/include/asm-blackfin/kmap_types.h |
25928 | --- linux-2.6.25.4/include/asm-blackfin/kmap_types.h 2008-05-15 11:00:12.000000000 -0400 | |
25929 | +++ linux-2.6.25.4/include/asm-blackfin/kmap_types.h 2008-05-18 13:33:17.000000000 -0400 | |
8a4b4a5e | 25930 | @@ -15,6 +15,7 @@ enum km_type { |
25931 | KM_IRQ1, | |
25932 | KM_SOFTIRQ0, | |
25933 | KM_SOFTIRQ1, | |
25934 | + KM_CLEARPAGE, | |
25935 | KM_TYPE_NR | |
25936 | }; | |
25937 | ||
4dee9bd5 | 25938 | diff -urNp linux-2.6.25.4/include/asm-cris/kmap_types.h linux-2.6.25.4/include/asm-cris/kmap_types.h |
25939 | --- linux-2.6.25.4/include/asm-cris/kmap_types.h 2008-05-15 11:00:12.000000000 -0400 | |
25940 | +++ linux-2.6.25.4/include/asm-cris/kmap_types.h 2008-05-18 13:33:17.000000000 -0400 | |
50425a20 | 25941 | @@ -19,6 +19,7 @@ enum km_type { |
25942 | KM_IRQ1, | |
25943 | KM_SOFTIRQ0, | |
25944 | KM_SOFTIRQ1, | |
25945 | + KM_CLEARPAGE, | |
25946 | KM_TYPE_NR | |
25947 | }; | |
25948 | ||
4dee9bd5 | 25949 | diff -urNp linux-2.6.25.4/include/asm-frv/kmap_types.h linux-2.6.25.4/include/asm-frv/kmap_types.h |
25950 | --- linux-2.6.25.4/include/asm-frv/kmap_types.h 2008-05-15 11:00:12.000000000 -0400 | |
25951 | +++ linux-2.6.25.4/include/asm-frv/kmap_types.h 2008-05-18 13:33:17.000000000 -0400 | |
50425a20 | 25952 | @@ -23,6 +23,7 @@ enum km_type { |
25953 | KM_IRQ1, | |
25954 | KM_SOFTIRQ0, | |
25955 | KM_SOFTIRQ1, | |
25956 | + KM_CLEARPAGE, | |
25957 | KM_TYPE_NR | |
25958 | }; | |
25959 | ||
4dee9bd5 | 25960 | diff -urNp linux-2.6.25.4/include/asm-generic/futex.h linux-2.6.25.4/include/asm-generic/futex.h |
25961 | --- linux-2.6.25.4/include/asm-generic/futex.h 2008-05-15 11:00:12.000000000 -0400 | |
25962 | +++ linux-2.6.25.4/include/asm-generic/futex.h 2008-05-18 13:33:17.000000000 -0400 | |
8a4b4a5e | 25963 | @@ -8,7 +8,7 @@ |
25964 | #include <asm/uaccess.h> | |
25965 | ||
25966 | static inline int | |
25967 | -futex_atomic_op_inuser (int encoded_op, int __user *uaddr) | |
25968 | +futex_atomic_op_inuser (int encoded_op, u32 __user *uaddr) | |
25969 | { | |
25970 | int op = (encoded_op >> 28) & 7; | |
25971 | int cmp = (encoded_op >> 24) & 15; | |
25972 | @@ -50,7 +50,7 @@ futex_atomic_op_inuser (int encoded_op, | |
25973 | } | |
25974 | ||
25975 | static inline int | |
25976 | -futex_atomic_cmpxchg_inatomic(int __user *uaddr, int oldval, int newval) | |
25977 | +futex_atomic_cmpxchg_inatomic(u32 __user *uaddr, int oldval, int newval) | |
25978 | { | |
25979 | return -ENOSYS; | |
25980 | } | |
4dee9bd5 | 25981 | diff -urNp linux-2.6.25.4/include/asm-generic/vmlinux.lds.h linux-2.6.25.4/include/asm-generic/vmlinux.lds.h |
25982 | --- linux-2.6.25.4/include/asm-generic/vmlinux.lds.h 2008-05-15 11:00:12.000000000 -0400 | |
25983 | +++ linux-2.6.25.4/include/asm-generic/vmlinux.lds.h 2008-05-18 13:33:17.000000000 -0400 | |
25984 | @@ -59,6 +59,7 @@ | |
8a4b4a5e | 25985 | .rodata : AT(ADDR(.rodata) - LOAD_OFFSET) { \ |
25986 | VMLINUX_SYMBOL(__start_rodata) = .; \ | |
25987 | *(.rodata) *(.rodata.*) \ | |
25988 | + *(.data.read_only) \ | |
25989 | *(__vermagic) /* Kernel version magic */ \ | |
da5b3fc8 | 25990 | *(__markers_strings) /* Markers: strings */ \ |
8a4b4a5e | 25991 | } \ |
4dee9bd5 | 25992 | diff -urNp linux-2.6.25.4/include/asm-h8300/kmap_types.h linux-2.6.25.4/include/asm-h8300/kmap_types.h |
25993 | --- linux-2.6.25.4/include/asm-h8300/kmap_types.h 2008-05-15 11:00:12.000000000 -0400 | |
25994 | +++ linux-2.6.25.4/include/asm-h8300/kmap_types.h 2008-05-18 13:33:17.000000000 -0400 | |
50425a20 | 25995 | @@ -15,6 +15,7 @@ enum km_type { |
25996 | KM_IRQ1, | |
25997 | KM_SOFTIRQ0, | |
25998 | KM_SOFTIRQ1, | |
25999 | + KM_CLEARPAGE, | |
26000 | KM_TYPE_NR | |
26001 | }; | |
26002 | ||
4dee9bd5 | 26003 | diff -urNp linux-2.6.25.4/include/asm-ia64/elf.h linux-2.6.25.4/include/asm-ia64/elf.h |
26004 | --- linux-2.6.25.4/include/asm-ia64/elf.h 2008-05-15 11:00:12.000000000 -0400 | |
26005 | +++ linux-2.6.25.4/include/asm-ia64/elf.h 2008-05-18 13:33:17.000000000 -0400 | |
da5b3fc8 | 26006 | @@ -162,7 +162,12 @@ typedef elf_greg_t elf_gregset_t[ELF_NGR |
26007 | typedef struct ia64_fpreg elf_fpreg_t; | |
26008 | typedef elf_fpreg_t elf_fpregset_t[ELF_NFPREG]; | |
50425a20 | 26009 | |
da5b3fc8 | 26010 | +#ifdef CONFIG_PAX_ASLR |
26011 | +#define PAX_ELF_ET_DYN_BASE (current->personality == PER_LINUX32 ? 0x08048000UL : 0x4000000000000000UL) | |
50425a20 | 26012 | |
da5b3fc8 | 26013 | +#define PAX_DELTA_MMAP_LEN (current->personality == PER_LINUX32 ? 16 : 3*PAGE_SHIFT - 13) |
26014 | +#define PAX_DELTA_STACK_LEN (current->personality == PER_LINUX32 ? 16 : 3*PAGE_SHIFT - 13) | |
26015 | +#endif | |
50425a20 | 26016 | |
da5b3fc8 | 26017 | struct pt_regs; /* forward declaration... */ |
26018 | extern void ia64_elf_core_copy_regs (struct pt_regs *src, elf_gregset_t dst); | |
4dee9bd5 | 26019 | diff -urNp linux-2.6.25.4/include/asm-ia64/kmap_types.h linux-2.6.25.4/include/asm-ia64/kmap_types.h |
26020 | --- linux-2.6.25.4/include/asm-ia64/kmap_types.h 2008-05-15 11:00:12.000000000 -0400 | |
26021 | +++ linux-2.6.25.4/include/asm-ia64/kmap_types.h 2008-05-18 13:33:17.000000000 -0400 | |
da5b3fc8 | 26022 | @@ -22,7 +22,8 @@ D(9) KM_IRQ0, |
26023 | D(10) KM_IRQ1, | |
26024 | D(11) KM_SOFTIRQ0, | |
26025 | D(12) KM_SOFTIRQ1, | |
26026 | -D(13) KM_TYPE_NR | |
26027 | +D(13) KM_CLEARPAGE, | |
26028 | +D(14) KM_TYPE_NR | |
26029 | }; | |
50425a20 | 26030 | |
da5b3fc8 | 26031 | #undef D |
4dee9bd5 | 26032 | diff -urNp linux-2.6.25.4/include/asm-ia64/pgtable.h linux-2.6.25.4/include/asm-ia64/pgtable.h |
26033 | --- linux-2.6.25.4/include/asm-ia64/pgtable.h 2008-05-15 11:00:12.000000000 -0400 | |
26034 | +++ linux-2.6.25.4/include/asm-ia64/pgtable.h 2008-05-18 13:33:17.000000000 -0400 | |
da5b3fc8 | 26035 | @@ -143,6 +143,17 @@ |
26036 | #define PAGE_READONLY __pgprot(__ACCESS_BITS | _PAGE_PL_3 | _PAGE_AR_R) | |
26037 | #define PAGE_COPY __pgprot(__ACCESS_BITS | _PAGE_PL_3 | _PAGE_AR_R) | |
26038 | #define PAGE_COPY_EXEC __pgprot(__ACCESS_BITS | _PAGE_PL_3 | _PAGE_AR_RX) | |
26039 | + | |
26040 | +#ifdef CONFIG_PAX_PAGEEXEC | |
26041 | +# define PAGE_SHARED_NOEXEC __pgprot(__ACCESS_BITS | _PAGE_PL_3 | _PAGE_AR_RW) | |
26042 | +# define PAGE_READONLY_NOEXEC __pgprot(__ACCESS_BITS | _PAGE_PL_3 | _PAGE_AR_R) | |
26043 | +# define PAGE_COPY_NOEXEC __pgprot(__ACCESS_BITS | _PAGE_PL_3 | _PAGE_AR_R) | |
50425a20 | 26044 | +#else |
da5b3fc8 | 26045 | +# define PAGE_SHARED_NOEXEC PAGE_SHARED |
26046 | +# define PAGE_READONLY_NOEXEC PAGE_READONLY | |
26047 | +# define PAGE_COPY_NOEXEC PAGE_COPY | |
50425a20 | 26048 | +#endif |
da5b3fc8 | 26049 | + |
26050 | #define PAGE_GATE __pgprot(__ACCESS_BITS | _PAGE_PL_0 | _PAGE_AR_X_RX) | |
26051 | #define PAGE_KERNEL __pgprot(__DIRTY_BITS | _PAGE_PL_0 | _PAGE_AR_RWX) | |
26052 | #define PAGE_KERNELRX __pgprot(__ACCESS_BITS | _PAGE_PL_0 | _PAGE_AR_RX) | |
4dee9bd5 | 26053 | diff -urNp linux-2.6.25.4/include/asm-m32r/kmap_types.h linux-2.6.25.4/include/asm-m32r/kmap_types.h |
26054 | --- linux-2.6.25.4/include/asm-m32r/kmap_types.h 2008-05-15 11:00:12.000000000 -0400 | |
26055 | +++ linux-2.6.25.4/include/asm-m32r/kmap_types.h 2008-05-18 13:33:17.000000000 -0400 | |
da5b3fc8 | 26056 | @@ -21,7 +21,8 @@ D(9) KM_IRQ0, |
26057 | D(10) KM_IRQ1, | |
26058 | D(11) KM_SOFTIRQ0, | |
26059 | D(12) KM_SOFTIRQ1, | |
26060 | -D(13) KM_TYPE_NR | |
26061 | +D(13) KM_CLEARPAGE, | |
26062 | +D(14) KM_TYPE_NR | |
26063 | }; | |
50425a20 | 26064 | |
da5b3fc8 | 26065 | #undef D |
4dee9bd5 | 26066 | diff -urNp linux-2.6.25.4/include/asm-m68k/kmap_types.h linux-2.6.25.4/include/asm-m68k/kmap_types.h |
26067 | --- linux-2.6.25.4/include/asm-m68k/kmap_types.h 2008-05-15 11:00:12.000000000 -0400 | |
26068 | +++ linux-2.6.25.4/include/asm-m68k/kmap_types.h 2008-05-18 13:33:17.000000000 -0400 | |
da5b3fc8 | 26069 | @@ -15,6 +15,7 @@ enum km_type { |
26070 | KM_IRQ1, | |
26071 | KM_SOFTIRQ0, | |
26072 | KM_SOFTIRQ1, | |
26073 | + KM_CLEARPAGE, | |
26074 | KM_TYPE_NR | |
26075 | }; | |
50425a20 | 26076 | |
4dee9bd5 | 26077 | diff -urNp linux-2.6.25.4/include/asm-m68knommu/kmap_types.h linux-2.6.25.4/include/asm-m68knommu/kmap_types.h |
26078 | --- linux-2.6.25.4/include/asm-m68knommu/kmap_types.h 2008-05-15 11:00:12.000000000 -0400 | |
26079 | +++ linux-2.6.25.4/include/asm-m68knommu/kmap_types.h 2008-05-18 13:33:17.000000000 -0400 | |
da5b3fc8 | 26080 | @@ -15,6 +15,7 @@ enum km_type { |
26081 | KM_IRQ1, | |
26082 | KM_SOFTIRQ0, | |
26083 | KM_SOFTIRQ1, | |
26084 | + KM_CLEARPAGE, | |
26085 | KM_TYPE_NR | |
26086 | }; | |
8a4b4a5e | 26087 | |
4dee9bd5 | 26088 | diff -urNp linux-2.6.25.4/include/asm-mips/elf.h linux-2.6.25.4/include/asm-mips/elf.h |
26089 | --- linux-2.6.25.4/include/asm-mips/elf.h 2008-05-15 11:00:12.000000000 -0400 | |
26090 | +++ linux-2.6.25.4/include/asm-mips/elf.h 2008-05-18 13:33:17.000000000 -0400 | |
26091 | @@ -368,4 +368,11 @@ extern int dump_task_fpu(struct task_str | |
26092 | #define ELF_ET_DYN_BASE (TASK_SIZE / 3 * 2) | |
8a4b4a5e | 26093 | #endif |
50425a20 | 26094 | |
da5b3fc8 | 26095 | +#ifdef CONFIG_PAX_ASLR |
26096 | +#define PAX_ELF_ET_DYN_BASE ((current->thread.mflags & MF_32BIT_ADDR) ? 0x00400000UL : 0x00400000UL) | |
50425a20 | 26097 | + |
da5b3fc8 | 26098 | +#define PAX_DELTA_MMAP_LEN ((current->thread.mflags & MF_32BIT_ADDR) ? 27-PAGE_SHIFT : 36-PAGE_SHIFT) |
26099 | +#define PAX_DELTA_STACK_LEN ((current->thread.mflags & MF_32BIT_ADDR) ? 27-PAGE_SHIFT : 36-PAGE_SHIFT) | |
26100 | +#endif | |
50425a20 | 26101 | + |
da5b3fc8 | 26102 | #endif /* _ASM_ELF_H */ |
4dee9bd5 | 26103 | diff -urNp linux-2.6.25.4/include/asm-mips/kmap_types.h linux-2.6.25.4/include/asm-mips/kmap_types.h |
26104 | --- linux-2.6.25.4/include/asm-mips/kmap_types.h 2008-05-15 11:00:12.000000000 -0400 | |
26105 | +++ linux-2.6.25.4/include/asm-mips/kmap_types.h 2008-05-18 13:33:17.000000000 -0400 | |
da5b3fc8 | 26106 | @@ -22,7 +22,8 @@ D(9) KM_IRQ0, |
26107 | D(10) KM_IRQ1, | |
26108 | D(11) KM_SOFTIRQ0, | |
26109 | D(12) KM_SOFTIRQ1, | |
26110 | -D(13) KM_TYPE_NR | |
26111 | +D(13) KM_CLEARPAGE, | |
26112 | +D(14) KM_TYPE_NR | |
26113 | }; | |
50425a20 | 26114 | |
da5b3fc8 | 26115 | #undef D |
4dee9bd5 | 26116 | diff -urNp linux-2.6.25.4/include/asm-mips/page.h linux-2.6.25.4/include/asm-mips/page.h |
26117 | --- linux-2.6.25.4/include/asm-mips/page.h 2008-05-15 11:00:12.000000000 -0400 | |
26118 | +++ linux-2.6.25.4/include/asm-mips/page.h 2008-05-18 13:33:17.000000000 -0400 | |
26119 | @@ -79,7 +79,7 @@ extern void copy_user_highpage(struct pa | |
da5b3fc8 | 26120 | #ifdef CONFIG_CPU_MIPS32 |
26121 | typedef struct { unsigned long pte_low, pte_high; } pte_t; | |
26122 | #define pte_val(x) ((x).pte_low | ((unsigned long long)(x).pte_high << 32)) | |
26123 | - #define __pte(x) ({ pte_t __pte = {(x), ((unsigned long long)(x)) >> 32}; __pte; }) | |
26124 | + #define __pte(x) ({ pte_t __pte = {(x), (x) >> 32}; __pte; }) | |
26125 | #else | |
26126 | typedef struct { unsigned long long pte; } pte_t; | |
26127 | #define pte_val(x) ((x).pte) | |
4dee9bd5 | 26128 | diff -urNp linux-2.6.25.4/include/asm-mips/system.h linux-2.6.25.4/include/asm-mips/system.h |
26129 | --- linux-2.6.25.4/include/asm-mips/system.h 2008-05-15 11:00:12.000000000 -0400 | |
26130 | +++ linux-2.6.25.4/include/asm-mips/system.h 2008-05-18 13:33:17.000000000 -0400 | |
da5b3fc8 | 26131 | @@ -215,6 +215,6 @@ extern void per_cpu_trap_init(void); |
26132 | */ | |
26133 | #define __ARCH_WANT_UNLOCKED_CTXSW | |
50425a20 | 26134 | |
da5b3fc8 | 26135 | -extern unsigned long arch_align_stack(unsigned long sp); |
26136 | +#define arch_align_stack(x) (x) | |
50425a20 | 26137 | |
da5b3fc8 | 26138 | #endif /* _ASM_SYSTEM_H */ |
4dee9bd5 | 26139 | diff -urNp linux-2.6.25.4/include/asm-parisc/elf.h linux-2.6.25.4/include/asm-parisc/elf.h |
26140 | --- linux-2.6.25.4/include/asm-parisc/elf.h 2008-05-15 11:00:12.000000000 -0400 | |
26141 | +++ linux-2.6.25.4/include/asm-parisc/elf.h 2008-05-18 13:33:17.000000000 -0400 | |
26142 | @@ -333,6 +333,13 @@ struct pt_regs; /* forward declaration.. | |
50425a20 | 26143 | |
da5b3fc8 | 26144 | #define ELF_ET_DYN_BASE (TASK_UNMAPPED_BASE + 0x01000000) |
8a4b4a5e | 26145 | |
da5b3fc8 | 26146 | +#ifdef CONFIG_PAX_ASLR |
26147 | +#define PAX_ELF_ET_DYN_BASE 0x10000UL | |
50425a20 | 26148 | + |
da5b3fc8 | 26149 | +#define PAX_DELTA_MMAP_LEN 16 |
26150 | +#define PAX_DELTA_STACK_LEN 16 | |
50425a20 | 26151 | +#endif |
26152 | + | |
da5b3fc8 | 26153 | /* This yields a mask that user programs can use to figure out what |
26154 | instruction set this CPU supports. This could be done in user space, | |
26155 | but it's not easy, and we've already done it here. */ | |
4dee9bd5 | 26156 | diff -urNp linux-2.6.25.4/include/asm-parisc/kmap_types.h linux-2.6.25.4/include/asm-parisc/kmap_types.h |
26157 | --- linux-2.6.25.4/include/asm-parisc/kmap_types.h 2008-05-15 11:00:12.000000000 -0400 | |
26158 | +++ linux-2.6.25.4/include/asm-parisc/kmap_types.h 2008-05-18 13:33:17.000000000 -0400 | |
da5b3fc8 | 26159 | @@ -22,7 +22,8 @@ D(9) KM_IRQ0, |
26160 | D(10) KM_IRQ1, | |
26161 | D(11) KM_SOFTIRQ0, | |
26162 | D(12) KM_SOFTIRQ1, | |
26163 | -D(13) KM_TYPE_NR | |
26164 | +D(13) KM_CLEARPAGE, | |
26165 | +D(14) KM_TYPE_NR | |
26166 | }; | |
26167 | ||
26168 | #undef D | |
4dee9bd5 | 26169 | diff -urNp linux-2.6.25.4/include/asm-parisc/pgtable.h linux-2.6.25.4/include/asm-parisc/pgtable.h |
26170 | --- linux-2.6.25.4/include/asm-parisc/pgtable.h 2008-05-15 11:00:12.000000000 -0400 | |
26171 | +++ linux-2.6.25.4/include/asm-parisc/pgtable.h 2008-05-18 13:33:17.000000000 -0400 | |
26172 | @@ -202,6 +202,17 @@ | |
da5b3fc8 | 26173 | #define PAGE_EXECREAD __pgprot(_PAGE_PRESENT | _PAGE_USER | _PAGE_READ | _PAGE_EXEC |_PAGE_ACCESSED) |
26174 | #define PAGE_COPY PAGE_EXECREAD | |
26175 | #define PAGE_RWX __pgprot(_PAGE_PRESENT | _PAGE_USER | _PAGE_READ | _PAGE_WRITE | _PAGE_EXEC |_PAGE_ACCESSED) | |
50425a20 | 26176 | + |
da5b3fc8 | 26177 | +#ifdef CONFIG_PAX_PAGEEXEC |
26178 | +# define PAGE_SHARED_NOEXEC __pgprot(_PAGE_PRESENT | _PAGE_USER | _PAGE_READ | _PAGE_WRITE | _PAGE_ACCESSED) | |
26179 | +# define PAGE_COPY_NOEXEC __pgprot(_PAGE_PRESENT | _PAGE_USER | _PAGE_READ | _PAGE_ACCESSED) | |
26180 | +# define PAGE_READONLY_NOEXEC __pgprot(_PAGE_PRESENT | _PAGE_USER | _PAGE_READ | _PAGE_ACCESSED) | |
26181 | +#else | |
26182 | +# define PAGE_SHARED_NOEXEC PAGE_SHARED | |
26183 | +# define PAGE_COPY_NOEXEC PAGE_COPY | |
26184 | +# define PAGE_READONLY_NOEXEC PAGE_READONLY | |
50425a20 | 26185 | +#endif |
26186 | + | |
da5b3fc8 | 26187 | #define PAGE_KERNEL __pgprot(_PAGE_KERNEL) |
26188 | #define PAGE_KERNEL_RO __pgprot(_PAGE_KERNEL & ~_PAGE_WRITE) | |
26189 | #define PAGE_KERNEL_UNC __pgprot(_PAGE_KERNEL | _PAGE_NO_CACHE) | |
4dee9bd5 | 26190 | diff -urNp linux-2.6.25.4/include/asm-powerpc/elf.h linux-2.6.25.4/include/asm-powerpc/elf.h |
26191 | --- linux-2.6.25.4/include/asm-powerpc/elf.h 2008-05-15 11:00:12.000000000 -0400 | |
26192 | +++ linux-2.6.25.4/include/asm-powerpc/elf.h 2008-05-18 13:33:17.000000000 -0400 | |
da5b3fc8 | 26193 | @@ -160,6 +160,18 @@ typedef elf_vrreg_t elf_vrregset_t[ELF_N |
26194 | typedef elf_vrreg_t elf_vrregset_t32[ELF_NVRREG32]; | |
26195 | #endif | |
50425a20 | 26196 | |
50425a20 | 26197 | +#ifdef CONFIG_PAX_ASLR |
da5b3fc8 | 26198 | +#define PAX_ELF_ET_DYN_BASE (0x10000000UL) |
50425a20 | 26199 | + |
da5b3fc8 | 26200 | +#ifdef __powerpc64__ |
26201 | +#define PAX_DELTA_MMAP_LEN (test_thread_flag(TIF_32BIT) ? 16 : 28) | |
26202 | +#define PAX_DELTA_STACK_LEN (test_thread_flag(TIF_32BIT) ? 16 : 28) | |
26203 | +#else | |
26204 | +#define PAX_DELTA_MMAP_LEN 15 | |
26205 | +#define PAX_DELTA_STACK_LEN 15 | |
50425a20 | 26206 | +#endif |
da5b3fc8 | 26207 | +#endif |
26208 | + | |
26209 | #ifdef __KERNEL__ | |
26210 | /* | |
26211 | * This is used to ensure we don't load something for the wrong architecture. | |
4dee9bd5 | 26212 | diff -urNp linux-2.6.25.4/include/asm-powerpc/kmap_types.h linux-2.6.25.4/include/asm-powerpc/kmap_types.h |
26213 | --- linux-2.6.25.4/include/asm-powerpc/kmap_types.h 2008-05-15 11:00:12.000000000 -0400 | |
26214 | +++ linux-2.6.25.4/include/asm-powerpc/kmap_types.h 2008-05-18 13:33:17.000000000 -0400 | |
da5b3fc8 | 26215 | @@ -26,6 +26,7 @@ enum km_type { |
26216 | KM_SOFTIRQ1, | |
26217 | KM_PPC_SYNC_PAGE, | |
26218 | KM_PPC_SYNC_ICACHE, | |
26219 | + KM_CLEARPAGE, | |
26220 | KM_TYPE_NR | |
26221 | }; | |
50425a20 | 26222 | |
4dee9bd5 | 26223 | diff -urNp linux-2.6.25.4/include/asm-powerpc/page_64.h linux-2.6.25.4/include/asm-powerpc/page_64.h |
26224 | --- linux-2.6.25.4/include/asm-powerpc/page_64.h 2008-05-15 11:00:12.000000000 -0400 | |
26225 | +++ linux-2.6.25.4/include/asm-powerpc/page_64.h 2008-05-18 13:33:17.000000000 -0400 | |
26226 | @@ -170,15 +170,18 @@ do { \ | |
da5b3fc8 | 26227 | * stack by default, so in the absense of a PT_GNU_STACK program header |
26228 | * we turn execute permission off. | |
26229 | */ | |
26230 | -#define VM_STACK_DEFAULT_FLAGS32 (VM_READ | VM_WRITE | VM_EXEC | \ | |
26231 | - VM_MAYREAD | VM_MAYWRITE | VM_MAYEXEC) | |
26232 | +#define VM_STACK_DEFAULT_FLAGS32 \ | |
4dee9bd5 | 26233 | + (((current->personality & READ_IMPLIES_EXEC) ? VM_EXEC : 0) | \ |
da5b3fc8 | 26234 | + VM_READ | VM_WRITE | VM_MAYREAD | VM_MAYWRITE | VM_MAYEXEC) |
50425a20 | 26235 | |
da5b3fc8 | 26236 | #define VM_STACK_DEFAULT_FLAGS64 (VM_READ | VM_WRITE | \ |
26237 | VM_MAYREAD | VM_MAYWRITE | VM_MAYEXEC) | |
8a4b4a5e | 26238 | |
da5b3fc8 | 26239 | +#ifndef CONFIG_PAX_PAGEEXEC |
26240 | #define VM_STACK_DEFAULT_FLAGS \ | |
26241 | (test_thread_flag(TIF_32BIT) ? \ | |
26242 | VM_STACK_DEFAULT_FLAGS32 : VM_STACK_DEFAULT_FLAGS64) | |
26243 | +#endif | |
50425a20 | 26244 | |
da5b3fc8 | 26245 | #include <asm-generic/page.h> |
50425a20 | 26246 | |
4dee9bd5 | 26247 | diff -urNp linux-2.6.25.4/include/asm-powerpc/page.h linux-2.6.25.4/include/asm-powerpc/page.h |
26248 | --- linux-2.6.25.4/include/asm-powerpc/page.h 2008-05-15 11:00:12.000000000 -0400 | |
26249 | +++ linux-2.6.25.4/include/asm-powerpc/page.h 2008-05-18 13:33:17.000000000 -0400 | |
26250 | @@ -70,8 +70,9 @@ | |
da5b3fc8 | 26251 | * and needs to be executable. This means the whole heap ends |
26252 | * up being executable. | |
26253 | */ | |
26254 | -#define VM_DATA_DEFAULT_FLAGS32 (VM_READ | VM_WRITE | VM_EXEC | \ | |
26255 | - VM_MAYREAD | VM_MAYWRITE | VM_MAYEXEC) | |
26256 | +#define VM_DATA_DEFAULT_FLAGS32 \ | |
4dee9bd5 | 26257 | + (((current->personality & READ_IMPLIES_EXEC) ? VM_EXEC : 0) | \ |
da5b3fc8 | 26258 | + VM_READ | VM_WRITE | VM_MAYREAD | VM_MAYWRITE | VM_MAYEXEC) |
50425a20 | 26259 | |
da5b3fc8 | 26260 | #define VM_DATA_DEFAULT_FLAGS64 (VM_READ | VM_WRITE | \ |
26261 | VM_MAYREAD | VM_MAYWRITE | VM_MAYEXEC) | |
4dee9bd5 | 26262 | diff -urNp linux-2.6.25.4/include/asm-ppc/mmu_context.h linux-2.6.25.4/include/asm-ppc/mmu_context.h |
26263 | --- linux-2.6.25.4/include/asm-ppc/mmu_context.h 2008-05-15 11:00:12.000000000 -0400 | |
26264 | +++ linux-2.6.25.4/include/asm-ppc/mmu_context.h 2008-05-18 13:33:17.000000000 -0400 | |
26265 | @@ -141,7 +141,8 @@ static inline void get_mmu_context(struc | |
da5b3fc8 | 26266 | static inline int init_new_context(struct task_struct *t, struct mm_struct *mm) |
8a4b4a5e | 26267 | { |
da5b3fc8 | 26268 | mm->context.id = NO_CONTEXT; |
26269 | - mm->context.vdso_base = 0; | |
26270 | + if (t == current) | |
26271 | + mm->context.vdso_base = ~0UL; | |
26272 | return 0; | |
8a4b4a5e | 26273 | } |
26274 | ||
4dee9bd5 | 26275 | diff -urNp linux-2.6.25.4/include/asm-ppc/pgtable.h linux-2.6.25.4/include/asm-ppc/pgtable.h |
26276 | --- linux-2.6.25.4/include/asm-ppc/pgtable.h 2008-05-15 11:00:12.000000000 -0400 | |
26277 | +++ linux-2.6.25.4/include/asm-ppc/pgtable.h 2008-05-18 13:33:17.000000000 -0400 | |
26278 | @@ -390,11 +390,21 @@ extern unsigned long ioremap_bot, iorema | |
50425a20 | 26279 | |
da5b3fc8 | 26280 | #define PAGE_NONE __pgprot(_PAGE_BASE) |
26281 | #define PAGE_READONLY __pgprot(_PAGE_BASE | _PAGE_USER) | |
26282 | -#define PAGE_READONLY_X __pgprot(_PAGE_BASE | _PAGE_USER | _PAGE_EXEC) | |
26283 | +#define PAGE_READONLY_X __pgprot(_PAGE_BASE | _PAGE_USER | _PAGE_EXEC | _PAGE_HWEXEC) | |
26284 | #define PAGE_SHARED __pgprot(_PAGE_BASE | _PAGE_USER | _PAGE_RW) | |
26285 | -#define PAGE_SHARED_X __pgprot(_PAGE_BASE | _PAGE_USER | _PAGE_RW | _PAGE_EXEC) | |
26286 | +#define PAGE_SHARED_X __pgprot(_PAGE_BASE | _PAGE_USER | _PAGE_RW | _PAGE_EXEC | _PAGE_HWEXEC) | |
26287 | #define PAGE_COPY __pgprot(_PAGE_BASE | _PAGE_USER) | |
26288 | -#define PAGE_COPY_X __pgprot(_PAGE_BASE | _PAGE_USER | _PAGE_EXEC) | |
26289 | +#define PAGE_COPY_X __pgprot(_PAGE_BASE | _PAGE_USER | _PAGE_EXEC | _PAGE_HWEXEC) | |
26290 | + | |
26291 | +#if defined(CONFIG_PAX_PAGEEXEC) && !defined(CONFIG_40x) && !defined(CONFIG_44x) | |
26292 | +# define PAGE_SHARED_NOEXEC __pgprot(_PAGE_BASE | _PAGE_USER | _PAGE_RW | _PAGE_GUARDED) | |
26293 | +# define PAGE_COPY_NOEXEC __pgprot(_PAGE_BASE | _PAGE_USER | _PAGE_GUARDED) | |
26294 | +# define PAGE_READONLY_NOEXEC __pgprot(_PAGE_BASE | _PAGE_USER | _PAGE_GUARDED) | |
26295 | +#else | |
26296 | +# define PAGE_SHARED_NOEXEC PAGE_SHARED | |
26297 | +# define PAGE_COPY_NOEXEC PAGE_COPY | |
26298 | +# define PAGE_READONLY_NOEXEC PAGE_READONLY | |
26299 | +#endif | |
50425a20 | 26300 | |
da5b3fc8 | 26301 | #define PAGE_KERNEL __pgprot(_PAGE_RAM) |
26302 | #define PAGE_KERNEL_NOCACHE __pgprot(_PAGE_IO) | |
4dee9bd5 | 26303 | @@ -406,21 +416,21 @@ extern unsigned long ioremap_bot, iorema |
da5b3fc8 | 26304 | * This is the closest we can get.. |
26305 | */ | |
26306 | #define __P000 PAGE_NONE | |
26307 | -#define __P001 PAGE_READONLY_X | |
26308 | -#define __P010 PAGE_COPY | |
26309 | -#define __P011 PAGE_COPY_X | |
26310 | -#define __P100 PAGE_READONLY | |
26311 | +#define __P001 PAGE_READONLY_NOEXEC | |
26312 | +#define __P010 PAGE_COPY_NOEXEC | |
26313 | +#define __P011 PAGE_COPY_NOEXEC | |
26314 | +#define __P100 PAGE_READONLY_X | |
26315 | #define __P101 PAGE_READONLY_X | |
26316 | -#define __P110 PAGE_COPY | |
26317 | +#define __P110 PAGE_COPY_X | |
26318 | #define __P111 PAGE_COPY_X | |
50425a20 | 26319 | |
da5b3fc8 | 26320 | #define __S000 PAGE_NONE |
26321 | -#define __S001 PAGE_READONLY_X | |
26322 | -#define __S010 PAGE_SHARED | |
26323 | -#define __S011 PAGE_SHARED_X | |
26324 | -#define __S100 PAGE_READONLY | |
26325 | +#define __S001 PAGE_READONLY_NOEXEC | |
26326 | +#define __S010 PAGE_SHARED_NOEXEC | |
26327 | +#define __S011 PAGE_SHARED_NOEXEC | |
26328 | +#define __S100 PAGE_READONLY_X | |
26329 | #define __S101 PAGE_READONLY_X | |
26330 | -#define __S110 PAGE_SHARED | |
26331 | +#define __S110 PAGE_SHARED_X | |
26332 | #define __S111 PAGE_SHARED_X | |
50425a20 | 26333 | |
da5b3fc8 | 26334 | #ifndef __ASSEMBLY__ |
4dee9bd5 | 26335 | diff -urNp linux-2.6.25.4/include/asm-s390/kmap_types.h linux-2.6.25.4/include/asm-s390/kmap_types.h |
26336 | --- linux-2.6.25.4/include/asm-s390/kmap_types.h 2008-05-15 11:00:12.000000000 -0400 | |
26337 | +++ linux-2.6.25.4/include/asm-s390/kmap_types.h 2008-05-18 13:33:17.000000000 -0400 | |
da5b3fc8 | 26338 | @@ -16,6 +16,7 @@ enum km_type { |
26339 | KM_IRQ1, | |
26340 | KM_SOFTIRQ0, | |
26341 | KM_SOFTIRQ1, | |
26342 | + KM_CLEARPAGE, | |
26343 | KM_TYPE_NR | |
26344 | }; | |
50425a20 | 26345 | |
4dee9bd5 | 26346 | diff -urNp linux-2.6.25.4/include/asm-sh/kmap_types.h linux-2.6.25.4/include/asm-sh/kmap_types.h |
26347 | --- linux-2.6.25.4/include/asm-sh/kmap_types.h 2008-05-15 11:00:12.000000000 -0400 | |
26348 | +++ linux-2.6.25.4/include/asm-sh/kmap_types.h 2008-05-18 13:33:17.000000000 -0400 | |
da5b3fc8 | 26349 | @@ -24,7 +24,8 @@ D(9) KM_IRQ0, |
50425a20 | 26350 | D(10) KM_IRQ1, |
26351 | D(11) KM_SOFTIRQ0, | |
26352 | D(12) KM_SOFTIRQ1, | |
26353 | -D(13) KM_TYPE_NR | |
26354 | +D(13) KM_CLEARPAGE, | |
26355 | +D(14) KM_TYPE_NR | |
26356 | }; | |
26357 | ||
26358 | #undef D | |
4dee9bd5 | 26359 | diff -urNp linux-2.6.25.4/include/asm-sparc/elf.h linux-2.6.25.4/include/asm-sparc/elf.h |
26360 | --- linux-2.6.25.4/include/asm-sparc/elf.h 2008-05-15 11:00:12.000000000 -0400 | |
26361 | +++ linux-2.6.25.4/include/asm-sparc/elf.h 2008-05-18 13:33:17.000000000 -0400 | |
26362 | @@ -120,6 +120,13 @@ typedef struct { | |
da5b3fc8 | 26363 | |
26364 | #define ELF_ET_DYN_BASE (TASK_UNMAPPED_BASE) | |
26365 | ||
26366 | +#ifdef CONFIG_PAX_ASLR | |
26367 | +#define PAX_ELF_ET_DYN_BASE 0x10000UL | |
50425a20 | 26368 | + |
da5b3fc8 | 26369 | +#define PAX_DELTA_MMAP_LEN 16 |
26370 | +#define PAX_DELTA_STACK_LEN 16 | |
50425a20 | 26371 | +#endif |
26372 | + | |
da5b3fc8 | 26373 | /* This yields a mask that user programs can use to figure out what |
26374 | instruction set this cpu supports. This can NOT be done in userspace | |
26375 | on Sparc. */ | |
4dee9bd5 | 26376 | diff -urNp linux-2.6.25.4/include/asm-sparc/kmap_types.h linux-2.6.25.4/include/asm-sparc/kmap_types.h |
26377 | --- linux-2.6.25.4/include/asm-sparc/kmap_types.h 2008-05-15 11:00:12.000000000 -0400 | |
26378 | +++ linux-2.6.25.4/include/asm-sparc/kmap_types.h 2008-05-18 13:33:17.000000000 -0400 | |
da5b3fc8 | 26379 | @@ -15,6 +15,7 @@ enum km_type { |
26380 | KM_IRQ1, | |
26381 | KM_SOFTIRQ0, | |
26382 | KM_SOFTIRQ1, | |
26383 | + KM_CLEARPAGE, | |
26384 | KM_TYPE_NR | |
26385 | }; | |
26386 | ||
4dee9bd5 | 26387 | diff -urNp linux-2.6.25.4/include/asm-sparc/pgtable.h linux-2.6.25.4/include/asm-sparc/pgtable.h |
26388 | --- linux-2.6.25.4/include/asm-sparc/pgtable.h 2008-05-15 11:00:12.000000000 -0400 | |
26389 | +++ linux-2.6.25.4/include/asm-sparc/pgtable.h 2008-05-18 13:33:17.000000000 -0400 | |
da5b3fc8 | 26390 | @@ -69,6 +69,16 @@ extern pgprot_t PAGE_SHARED; |
26391 | #define PAGE_COPY __pgprot(BTFIXUP_INT(page_copy)) | |
26392 | #define PAGE_READONLY __pgprot(BTFIXUP_INT(page_readonly)) | |
26393 | ||
50425a20 | 26394 | +#ifdef CONFIG_PAX_PAGEEXEC |
da5b3fc8 | 26395 | +extern pgprot_t PAGE_SHARED_NOEXEC; |
26396 | +# define PAGE_COPY_NOEXEC __pgprot(BTFIXUP_INT(page_copy_noexec)) | |
26397 | +# define PAGE_READONLY_NOEXEC __pgprot(BTFIXUP_INT(page_readonly_noexec)) | |
26398 | +#else | |
26399 | +# define PAGE_SHARED_NOEXEC PAGE_SHARED | |
26400 | +# define PAGE_COPY_NOEXEC PAGE_COPY | |
26401 | +# define PAGE_READONLY_NOEXEC PAGE_READONLY | |
50425a20 | 26402 | +#endif |
26403 | + | |
da5b3fc8 | 26404 | extern unsigned long page_kernel; |
26405 | ||
26406 | #ifdef MODULE | |
4dee9bd5 | 26407 | diff -urNp linux-2.6.25.4/include/asm-sparc/pgtsrmmu.h linux-2.6.25.4/include/asm-sparc/pgtsrmmu.h |
26408 | --- linux-2.6.25.4/include/asm-sparc/pgtsrmmu.h 2008-05-15 11:00:12.000000000 -0400 | |
26409 | +++ linux-2.6.25.4/include/asm-sparc/pgtsrmmu.h 2008-05-18 13:33:17.000000000 -0400 | |
da5b3fc8 | 26410 | @@ -115,6 +115,16 @@ |
26411 | SRMMU_EXEC | SRMMU_REF) | |
26412 | #define SRMMU_PAGE_RDONLY __pgprot(SRMMU_VALID | SRMMU_CACHE | \ | |
26413 | SRMMU_EXEC | SRMMU_REF) | |
26414 | + | |
8a4b4a5e | 26415 | +#ifdef CONFIG_PAX_PAGEEXEC |
da5b3fc8 | 26416 | +#define SRMMU_PAGE_SHARED_NOEXEC __pgprot(SRMMU_VALID | SRMMU_CACHE | \ |
26417 | + SRMMU_WRITE | SRMMU_REF) | |
26418 | +#define SRMMU_PAGE_COPY_NOEXEC __pgprot(SRMMU_VALID | SRMMU_CACHE | \ | |
26419 | + SRMMU_REF) | |
26420 | +#define SRMMU_PAGE_RDONLY_NOEXEC __pgprot(SRMMU_VALID | SRMMU_CACHE | \ | |
26421 | + SRMMU_REF) | |
50425a20 | 26422 | +#endif |
26423 | + | |
da5b3fc8 | 26424 | #define SRMMU_PAGE_KERNEL __pgprot(SRMMU_VALID | SRMMU_CACHE | SRMMU_PRIV | \ |
26425 | SRMMU_DIRTY | SRMMU_REF) | |
26426 | ||
4dee9bd5 | 26427 | diff -urNp linux-2.6.25.4/include/asm-sparc64/elf.h linux-2.6.25.4/include/asm-sparc64/elf.h |
26428 | --- linux-2.6.25.4/include/asm-sparc64/elf.h 2008-05-15 11:00:12.000000000 -0400 | |
26429 | +++ linux-2.6.25.4/include/asm-sparc64/elf.h 2008-05-18 13:33:17.000000000 -0400 | |
26430 | @@ -164,6 +164,12 @@ typedef struct { | |
26431 | #define ELF_ET_DYN_BASE 0x0000010000000000UL | |
26432 | #define COMPAT_ELF_ET_DYN_BASE 0x0000000070000000UL | |
da5b3fc8 | 26433 | |
26434 | +#ifdef CONFIG_PAX_ASLR | |
26435 | +#define PAX_ELF_ET_DYN_BASE (test_thread_flag(TIF_32BIT) ? 0x10000UL : 0x100000UL) | |
50425a20 | 26436 | + |
da5b3fc8 | 26437 | +#define PAX_DELTA_MMAP_LEN (test_thread_flag(TIF_32BIT) ? 14 : 28 ) |
26438 | +#define PAX_DELTA_STACK_LEN (test_thread_flag(TIF_32BIT) ? 15 : 29 ) | |
50425a20 | 26439 | +#endif |
50425a20 | 26440 | |
da5b3fc8 | 26441 | /* This yields a mask that user programs can use to figure out what |
26442 | instruction set this cpu supports. */ | |
4dee9bd5 | 26443 | diff -urNp linux-2.6.25.4/include/asm-sparc64/kmap_types.h linux-2.6.25.4/include/asm-sparc64/kmap_types.h |
26444 | --- linux-2.6.25.4/include/asm-sparc64/kmap_types.h 2008-05-15 11:00:12.000000000 -0400 | |
26445 | +++ linux-2.6.25.4/include/asm-sparc64/kmap_types.h 2008-05-18 13:33:17.000000000 -0400 | |
da5b3fc8 | 26446 | @@ -19,6 +19,7 @@ enum km_type { |
26447 | KM_IRQ1, | |
26448 | KM_SOFTIRQ0, | |
26449 | KM_SOFTIRQ1, | |
26450 | + KM_CLEARPAGE, | |
26451 | KM_TYPE_NR | |
26452 | }; | |
26453 | ||
4dee9bd5 | 26454 | diff -urNp linux-2.6.25.4/include/asm-um/kmap_types.h linux-2.6.25.4/include/asm-um/kmap_types.h |
26455 | --- linux-2.6.25.4/include/asm-um/kmap_types.h 2008-05-15 11:00:12.000000000 -0400 | |
26456 | +++ linux-2.6.25.4/include/asm-um/kmap_types.h 2008-05-18 13:33:17.000000000 -0400 | |
da5b3fc8 | 26457 | @@ -23,6 +23,7 @@ enum km_type { |
26458 | KM_IRQ1, | |
26459 | KM_SOFTIRQ0, | |
26460 | KM_SOFTIRQ1, | |
26461 | + KM_CLEARPAGE, | |
26462 | KM_TYPE_NR | |
26463 | }; | |
26464 | ||
4dee9bd5 | 26465 | diff -urNp linux-2.6.25.4/include/asm-v850/kmap_types.h linux-2.6.25.4/include/asm-v850/kmap_types.h |
26466 | --- linux-2.6.25.4/include/asm-v850/kmap_types.h 2008-05-15 11:00:12.000000000 -0400 | |
26467 | +++ linux-2.6.25.4/include/asm-v850/kmap_types.h 2008-05-18 13:33:17.000000000 -0400 | |
da5b3fc8 | 26468 | @@ -13,6 +13,7 @@ enum km_type { |
26469 | KM_PTE1, | |
26470 | KM_IRQ0, | |
26471 | KM_IRQ1, | |
26472 | + KM_CLEARPAGE, | |
26473 | KM_TYPE_NR | |
26474 | }; | |
26475 | ||
4dee9bd5 | 26476 | diff -urNp linux-2.6.25.4/include/asm-x86/alternative.h linux-2.6.25.4/include/asm-x86/alternative.h |
26477 | --- linux-2.6.25.4/include/asm-x86/alternative.h 2008-05-15 11:00:12.000000000 -0400 | |
26478 | +++ linux-2.6.25.4/include/asm-x86/alternative.h 2008-05-18 13:33:17.000000000 -0400 | |
da5b3fc8 | 26479 | @@ -94,7 +94,7 @@ static inline void alternatives_smp_swit |
4dee9bd5 | 26480 | " .byte 662b-661b\n" /* sourcelen */ \ |
26481 | " .byte 664f-663f\n" /* replacementlen */ \ | |
da5b3fc8 | 26482 | ".previous\n" \ |
26483 | - ".section .altinstr_replacement,\"ax\"\n" \ | |
26484 | + ".section .altinstr_replacement,\"a\"\n" \ | |
4dee9bd5 | 26485 | "663:\n\t" newinstr "\n664:\n" /* replacement */ \ |
da5b3fc8 | 26486 | ".previous" :: "i" (feature) : "memory") |
26487 | ||
26488 | @@ -118,7 +118,7 @@ static inline void alternatives_smp_swit | |
4dee9bd5 | 26489 | " .byte 662b-661b\n" /* sourcelen */ \ |
26490 | " .byte 664f-663f\n" /* replacementlen */ \ | |
da5b3fc8 | 26491 | ".previous\n" \ |
26492 | - ".section .altinstr_replacement,\"ax\"\n" \ | |
26493 | + ".section .altinstr_replacement,\"a\"\n" \ | |
4dee9bd5 | 26494 | "663:\n\t" newinstr "\n664:\n" /* replacement */ \ |
da5b3fc8 | 26495 | ".previous" :: "i" (feature), ##input) |
50425a20 | 26496 | |
da5b3fc8 | 26497 | @@ -133,7 +133,7 @@ static inline void alternatives_smp_swit |
4dee9bd5 | 26498 | " .byte 662b-661b\n" /* sourcelen */ \ |
26499 | " .byte 664f-663f\n" /* replacementlen */ \ | |
da5b3fc8 | 26500 | ".previous\n" \ |
26501 | - ".section .altinstr_replacement,\"ax\"\n" \ | |
26502 | + ".section .altinstr_replacement,\"a\"\n" \ | |
4dee9bd5 | 26503 | "663:\n\t" newinstr "\n664:\n" /* replacement */ \ |
da5b3fc8 | 26504 | ".previous" : output : [feat] "i" (feature), ##input) |
50425a20 | 26505 | |
4dee9bd5 | 26506 | diff -urNp linux-2.6.25.4/include/asm-x86/apic.h linux-2.6.25.4/include/asm-x86/apic.h |
26507 | --- linux-2.6.25.4/include/asm-x86/apic.h 2008-05-15 11:00:12.000000000 -0400 | |
26508 | +++ linux-2.6.25.4/include/asm-x86/apic.h 2008-05-18 13:33:17.000000000 -0400 | |
26509 | @@ -10,7 +10,7 @@ | |
50425a20 | 26510 | |
4dee9bd5 | 26511 | #define ARCH_APICTIMER_STOPS_ON_C3 1 |
da5b3fc8 | 26512 | |
26513 | -#define Dprintk(x...) | |
26514 | +#define Dprintk(x...) do {} while (0) | |
26515 | ||
26516 | /* | |
26517 | * Debugging macros | |
4dee9bd5 | 26518 | diff -urNp linux-2.6.25.4/include/asm-x86/boot.h linux-2.6.25.4/include/asm-x86/boot.h |
26519 | --- linux-2.6.25.4/include/asm-x86/boot.h 2008-05-15 11:00:12.000000000 -0400 | |
26520 | +++ linux-2.6.25.4/include/asm-x86/boot.h 2008-05-18 13:33:17.000000000 -0400 | |
da5b3fc8 | 26521 | @@ -13,8 +13,13 @@ |
26522 | #define ASK_VGA 0xfffd /* ask for it at bootup */ | |
26523 | ||
26524 | /* Physical address where kernel should be loaded. */ | |
26525 | -#define LOAD_PHYSICAL_ADDR ((CONFIG_PHYSICAL_START \ | |
26526 | +#define ____LOAD_PHYSICAL_ADDR ((CONFIG_PHYSICAL_START \ | |
26527 | + (CONFIG_PHYSICAL_ALIGN - 1)) \ | |
26528 | & ~(CONFIG_PHYSICAL_ALIGN - 1)) | |
50425a20 | 26529 | |
50425a20 | 26530 | +#ifndef __ASSEMBLY__ |
da5b3fc8 | 26531 | +extern unsigned char __LOAD_PHYSICAL_ADDR[]; |
26532 | +#define LOAD_PHYSICAL_ADDR ((unsigned long)__LOAD_PHYSICAL_ADDR) | |
50425a20 | 26533 | +#endif |
da5b3fc8 | 26534 | + |
26535 | #endif /* _ASM_BOOT_H */ | |
4dee9bd5 | 26536 | diff -urNp linux-2.6.25.4/include/asm-x86/cache.h linux-2.6.25.4/include/asm-x86/cache.h |
26537 | --- linux-2.6.25.4/include/asm-x86/cache.h 2008-05-15 11:00:12.000000000 -0400 | |
26538 | +++ linux-2.6.25.4/include/asm-x86/cache.h 2008-05-18 13:33:17.000000000 -0400 | |
da5b3fc8 | 26539 | @@ -6,6 +6,7 @@ |
26540 | #define L1_CACHE_BYTES (1 << L1_CACHE_SHIFT) | |
50425a20 | 26541 | |
da5b3fc8 | 26542 | #define __read_mostly __attribute__((__section__(".data.read_mostly"))) |
26543 | +#define __read_only __attribute__((__section__(".data.read_only"))) | |
50425a20 | 26544 | |
da5b3fc8 | 26545 | #ifdef CONFIG_X86_VSMP |
26546 | /* vSMP Internode cacheline shift */ | |
4dee9bd5 | 26547 | diff -urNp linux-2.6.25.4/include/asm-x86/checksum_32.h linux-2.6.25.4/include/asm-x86/checksum_32.h |
26548 | --- linux-2.6.25.4/include/asm-x86/checksum_32.h 2008-05-15 11:00:12.000000000 -0400 | |
26549 | +++ linux-2.6.25.4/include/asm-x86/checksum_32.h 2008-05-18 13:33:17.000000000 -0400 | |
da5b3fc8 | 26550 | @@ -30,6 +30,12 @@ asmlinkage __wsum csum_partial(const voi |
26551 | asmlinkage __wsum csum_partial_copy_generic(const void *src, void *dst, | |
26552 | int len, __wsum sum, int *src_err_ptr, int *dst_err_ptr); | |
26553 | ||
26554 | +asmlinkage __wsum csum_partial_copy_generic_to_user(const void *src, void *dst, | |
26555 | + int len, __wsum sum, int *src_err_ptr, int *dst_err_ptr); | |
50425a20 | 26556 | + |
da5b3fc8 | 26557 | +asmlinkage __wsum csum_partial_copy_generic_from_user(const void *src, void *dst, |
26558 | + int len, __wsum sum, int *src_err_ptr, int *dst_err_ptr); | |
26559 | + | |
26560 | /* | |
26561 | * Note: when you get a NULL pointer exception here this means someone | |
26562 | * passed in an incorrect kernel address to one of these functions. | |
26563 | @@ -49,7 +55,7 @@ __wsum csum_partial_copy_from_user(const | |
26564 | int len, __wsum sum, int *err_ptr) | |
26565 | { | |
26566 | might_sleep(); | |
26567 | - return csum_partial_copy_generic((__force void *)src, dst, | |
26568 | + return csum_partial_copy_generic_from_user((__force void *)src, dst, | |
26569 | len, sum, err_ptr, NULL); | |
26570 | } | |
50425a20 | 26571 | |
da5b3fc8 | 26572 | @@ -180,7 +186,7 @@ static __inline__ __wsum csum_and_copy_t |
26573 | { | |
26574 | might_sleep(); | |
26575 | if (access_ok(VERIFY_WRITE, dst, len)) | |
26576 | - return csum_partial_copy_generic(src, (__force void *)dst, len, sum, NULL, err_ptr); | |
26577 | + return csum_partial_copy_generic_to_user(src, (__force void *)dst, len, sum, NULL, err_ptr); | |
8a4b4a5e | 26578 | |
da5b3fc8 | 26579 | if (len) |
26580 | *err_ptr = -EFAULT; | |
4dee9bd5 | 26581 | diff -urNp linux-2.6.25.4/include/asm-x86/desc.h linux-2.6.25.4/include/asm-x86/desc.h |
26582 | --- linux-2.6.25.4/include/asm-x86/desc.h 2008-05-15 11:00:12.000000000 -0400 | |
26583 | +++ linux-2.6.25.4/include/asm-x86/desc.h 2008-05-18 13:33:17.000000000 -0400 | |
26584 | @@ -16,6 +16,7 @@ static inline void fill_ldt(struct desc_ | |
26585 | desc->base1 = (info->base_addr & 0x00ff0000) >> 16; | |
26586 | desc->type = (info->read_exec_only ^ 1) << 1; | |
26587 | desc->type |= info->contents << 2; | |
26588 | + desc->type |= info->seg_not_present ^ 1; | |
26589 | desc->s = 1; | |
26590 | desc->dpl = 0x3; | |
26591 | desc->p = info->seg_not_present ^ 1; | |
84cd3cb1 | 26592 | @@ -26,14 +27,15 @@ static inline void fill_ldt(struct desc_ |
4dee9bd5 | 26593 | } |
8a4b4a5e | 26594 | |
84cd3cb1 | 26595 | extern struct desc_ptr idt_descr; |
4dee9bd5 | 26596 | -extern gate_desc idt_table[]; |
4dee9bd5 | 26597 | +extern gate_desc idt_table[256]; |
8a4b4a5e | 26598 | |
4dee9bd5 | 26599 | -#ifdef CONFIG_X86_64 |
26600 | -extern struct desc_struct cpu_gdt_table[GDT_ENTRIES]; | |
26601 | -extern struct desc_ptr cpu_gdt_descr[]; | |
26602 | -/* the cpu gdt accessor */ | |
26603 | -#define get_cpu_gdt_table(x) ((struct desc_struct *)cpu_gdt_descr[x].address) | |
da5b3fc8 | 26604 | +extern struct desc_struct cpu_gdt_table[NR_CPUS][PAGE_SIZE / sizeof(struct desc_struct)]; |
4dee9bd5 | 26605 | +static inline struct desc_struct *get_cpu_gdt_table(unsigned int cpu) |
26606 | +{ | |
26607 | + return cpu_gdt_table[cpu]; | |
26608 | +} | |
8a4b4a5e | 26609 | |
4dee9bd5 | 26610 | +#ifdef CONFIG_X86_64 |
26611 | static inline void pack_gate(gate_desc *gate, unsigned type, unsigned long func, | |
26612 | unsigned dpl, unsigned ist, unsigned seg) | |
26613 | { | |
26614 | @@ -51,16 +53,6 @@ static inline void pack_gate(gate_desc * | |
26615 | } | |
26616 | ||
26617 | #else | |
26618 | -struct gdt_page { | |
da5b3fc8 | 26619 | - struct desc_struct gdt[GDT_ENTRIES]; |
26620 | -} __attribute__((aligned(PAGE_SIZE))); | |
26621 | -DECLARE_PER_CPU(struct gdt_page, gdt_page); | |
26622 | - | |
4dee9bd5 | 26623 | -static inline struct desc_struct *get_cpu_gdt_table(unsigned int cpu) |
26624 | -{ | |
da5b3fc8 | 26625 | - return per_cpu(gdt_page, cpu).gdt; |
4dee9bd5 | 26626 | -} |
26627 | - | |
26628 | static inline void pack_gate(gate_desc *gate, unsigned char type, | |
26629 | unsigned long base, unsigned dpl, unsigned flags, unsigned short seg) | |
8a4b4a5e | 26630 | |
4dee9bd5 | 26631 | @@ -69,7 +61,6 @@ static inline void pack_gate(gate_desc * |
26632 | gate->b = (base & 0xffff0000) | | |
26633 | (((0x80 | type | (dpl << 5)) & 0xff) << 8); | |
26634 | } | |
26635 | - | |
26636 | #endif | |
e36c1b33 | 26637 | |
4dee9bd5 | 26638 | static inline int desc_empty(const void *ptr) |
26639 | @@ -105,19 +96,48 @@ static inline int desc_empty(const void | |
26640 | static inline void native_write_idt_entry(gate_desc *idt, int entry, | |
26641 | const gate_desc *gate) | |
da5b3fc8 | 26642 | { |
26643 | + | |
26644 | +#ifdef CONFIG_PAX_KERNEXEC | |
26645 | + unsigned long cr0; | |
26646 | + | |
26647 | + pax_open_kernel(cr0); | |
26648 | +#endif | |
26649 | + | |
4dee9bd5 | 26650 | memcpy(&idt[entry], gate, sizeof(*gate)); |
da5b3fc8 | 26651 | + |
26652 | +#ifdef CONFIG_PAX_KERNEXEC | |
26653 | + pax_close_kernel(cr0); | |
26654 | +#endif | |
26655 | + | |
26656 | } | |
50425a20 | 26657 | |
4dee9bd5 | 26658 | static inline void native_write_ldt_entry(struct desc_struct *ldt, int entry, |
26659 | const void *desc) | |
da5b3fc8 | 26660 | { |
8a4b4a5e | 26661 | + |
26662 | +#ifdef CONFIG_PAX_KERNEXEC | |
26663 | + unsigned long cr0; | |
26664 | + | |
26665 | + pax_open_kernel(cr0); | |
26666 | +#endif | |
26667 | + | |
4dee9bd5 | 26668 | memcpy(&ldt[entry], desc, 8); |
8a4b4a5e | 26669 | + |
26670 | +#ifdef CONFIG_PAX_KERNEXEC | |
26671 | + pax_close_kernel(cr0); | |
26672 | +#endif | |
26673 | + | |
4dee9bd5 | 26674 | } |
da5b3fc8 | 26675 | |
4dee9bd5 | 26676 | static inline void native_write_gdt_entry(struct desc_struct *gdt, int entry, |
26677 | const void *desc, int type) | |
26678 | { | |
26679 | unsigned int size; | |
da5b3fc8 | 26680 | + |
8a4b4a5e | 26681 | +#ifdef CONFIG_PAX_KERNEXEC |
26682 | + unsigned long cr0; | |
da5b3fc8 | 26683 | +#endif |
8a4b4a5e | 26684 | + |
4dee9bd5 | 26685 | switch (type) { |
26686 | case DESC_TSS: | |
26687 | size = sizeof(tss_desc); | |
26688 | @@ -129,7 +149,17 @@ static inline void native_write_gdt_entr | |
26689 | size = sizeof(struct desc_struct); | |
26690 | break; | |
26691 | } | |
da5b3fc8 | 26692 | + |
26693 | +#ifdef CONFIG_PAX_KERNEXEC | |
8a4b4a5e | 26694 | + pax_open_kernel(cr0); |
26695 | +#endif | |
26696 | + | |
4dee9bd5 | 26697 | memcpy(&gdt[entry], desc, size); |
8a4b4a5e | 26698 | + |
26699 | +#ifdef CONFIG_PAX_KERNEXEC | |
26700 | + pax_close_kernel(cr0); | |
26701 | +#endif | |
26702 | + | |
26703 | } | |
da5b3fc8 | 26704 | |
4dee9bd5 | 26705 | static inline void pack_descriptor(struct desc_struct *desc, unsigned long base, |
26706 | @@ -236,8 +266,19 @@ static inline void native_load_tls(struc | |
da5b3fc8 | 26707 | unsigned int i; |
4dee9bd5 | 26708 | struct desc_struct *gdt = get_cpu_gdt_table(cpu); |
da5b3fc8 | 26709 | |
8a4b4a5e | 26710 | +#ifdef CONFIG_PAX_KERNEXEC |
26711 | + unsigned long cr0; | |
26712 | + | |
26713 | + pax_open_kernel(cr0); | |
26714 | +#endif | |
26715 | + | |
da5b3fc8 | 26716 | for (i = 0; i < GDT_ENTRY_TLS_ENTRIES; i++) |
4dee9bd5 | 26717 | gdt[GDT_ENTRY_TLS_MIN + i] = t->tls_array[i]; |
8a4b4a5e | 26718 | + |
26719 | +#ifdef CONFIG_PAX_KERNEXEC | |
26720 | + pax_close_kernel(cr0); | |
26721 | +#endif | |
26722 | + | |
da5b3fc8 | 26723 | } |
50425a20 | 26724 | |
4dee9bd5 | 26725 | #define _LDT_empty(info) (\ |
26726 | @@ -353,6 +394,18 @@ static inline void set_system_gate_ist(i | |
26727 | _set_gate(n, GATE_INTERRUPT, addr, 0x3, ist, __KERNEL_CS); | |
26728 | } | |
da5b3fc8 | 26729 | |
4dee9bd5 | 26730 | +#ifdef CONFIG_X86_32 |
26731 | +static inline void set_user_cs(unsigned long base, unsigned long limit, int cpu) | |
26732 | +{ | |
26733 | + struct desc_struct d; | |
26734 | + | |
26735 | + if (likely(limit)) | |
26736 | + limit = (limit - 1UL) >> PAGE_SHIFT; | |
26737 | + pack_descriptor(&d, base, limit, 0xFB, 0xC); | |
26738 | + write_gdt_entry(get_cpu_gdt_table(cpu), GDT_ENTRY_DEFAULT_USER_CS, &d, DESCTYPE_S); | |
26739 | +} | |
26740 | +#endif | |
26741 | + | |
26742 | #else | |
26743 | /* | |
26744 | * GET_DESC_BASE reads the descriptor base of the specified segment. | |
26745 | diff -urNp linux-2.6.25.4/include/asm-x86/elf.h linux-2.6.25.4/include/asm-x86/elf.h | |
26746 | --- linux-2.6.25.4/include/asm-x86/elf.h 2008-05-15 11:00:12.000000000 -0400 | |
26747 | +++ linux-2.6.25.4/include/asm-x86/elf.h 2008-05-18 13:33:17.000000000 -0400 | |
26748 | @@ -243,7 +243,25 @@ extern int force_personality32; | |
da5b3fc8 | 26749 | the loader. We need to make sure that it is out of the way of the program |
26750 | that it will "exec", and that there is sufficient room for the brk. */ | |
26751 | ||
26752 | +#ifdef CONFIG_PAX_SEGMEXEC | |
26753 | +#define ELF_ET_DYN_BASE ((current->mm->pax_flags & MF_PAX_SEGMEXEC) ? SEGMEXEC_TASK_SIZE/3*2 : TASK_SIZE/3*2) | |
26754 | +#else | |
26755 | #define ELF_ET_DYN_BASE (TASK_SIZE / 3 * 2) | |
50425a20 | 26756 | +#endif |
26757 | + | |
da5b3fc8 | 26758 | +#ifdef CONFIG_PAX_ASLR |
26759 | +#ifdef CONFIG_X86_32 | |
26760 | +#define PAX_ELF_ET_DYN_BASE 0x10000000UL | |
26761 | + | |
26762 | +#define PAX_DELTA_MMAP_LEN (current->mm->pax_flags & MF_PAX_SEGMEXEC ? 15 : 16) | |
26763 | +#define PAX_DELTA_STACK_LEN (current->mm->pax_flags & MF_PAX_SEGMEXEC ? 15 : 16) | |
26764 | +#else | |
26765 | +#define PAX_ELF_ET_DYN_BASE 0x400000UL | |
26766 | + | |
4dee9bd5 | 26767 | +#define PAX_DELTA_MMAP_LEN ((test_thread_flag(TIF_IA32)) ? 16 : 32) |
26768 | +#define PAX_DELTA_STACK_LEN ((test_thread_flag(TIF_IA32)) ? 16 : 32) | |
da5b3fc8 | 26769 | +#endif |
26770 | +#endif | |
50425a20 | 26771 | |
da5b3fc8 | 26772 | /* This yields a mask that user programs can use to figure out what |
26773 | instruction set this CPU supports. This could be done in user space, | |
4dee9bd5 | 26774 | @@ -292,7 +310,7 @@ do if (vdso_enabled) { \ |
50425a20 | 26775 | |
da5b3fc8 | 26776 | #define ARCH_DLINFO \ |
26777 | do if (vdso_enabled) { \ | |
26778 | - NEW_AUX_ENT(AT_SYSINFO_EHDR,(unsigned long)current->mm->context.vdso);\ | |
4dee9bd5 | 26779 | + NEW_AUX_ENT(AT_SYSINFO_EHDR,current->mm->context.vdso);\ |
da5b3fc8 | 26780 | } while (0) |
8a4b4a5e | 26781 | |
4dee9bd5 | 26782 | #define AT_SYSINFO 32 |
26783 | @@ -303,7 +321,7 @@ do if (vdso_enabled) { \ | |
26784 | ||
da5b3fc8 | 26785 | #endif /* !CONFIG_X86_32 */ |
8a4b4a5e | 26786 | |
4dee9bd5 | 26787 | -#define VDSO_CURRENT_BASE ((unsigned long)current->mm->context.vdso) |
26788 | +#define VDSO_CURRENT_BASE (current->mm->context.vdso) | |
26789 | ||
26790 | #define VDSO_ENTRY \ | |
26791 | ((unsigned long) VDSO32_SYMBOL(VDSO_CURRENT_BASE, vsyscall)) | |
26792 | @@ -317,7 +335,4 @@ extern int arch_setup_additional_pages(s | |
26793 | extern int syscall32_setup_pages(struct linux_binprm *, int exstack); | |
26794 | #define compat_arch_setup_additional_pages syscall32_setup_pages | |
26795 | ||
26796 | -extern unsigned long arch_randomize_brk(struct mm_struct *mm); | |
26797 | -#define arch_randomize_brk arch_randomize_brk | |
26798 | - | |
26799 | #endif | |
26800 | diff -urNp linux-2.6.25.4/include/asm-x86/futex.h linux-2.6.25.4/include/asm-x86/futex.h | |
26801 | --- linux-2.6.25.4/include/asm-x86/futex.h 2008-05-15 11:00:12.000000000 -0400 | |
26802 | +++ linux-2.6.25.4/include/asm-x86/futex.h 2008-05-18 13:33:17.000000000 -0400 | |
26803 | @@ -11,6 +11,41 @@ | |
26804 | #include <asm/system.h> | |
26805 | #include <asm/uaccess.h> | |
26806 | ||
26807 | +#ifdef CONFIG_X86_32 | |
26808 | +#define __futex_atomic_op1(insn, ret, oldval, uaddr, oparg) \ | |
26809 | + __asm__ __volatile( \ | |
26810 | + "movw %w6, %%ds\n" \ | |
26811 | +"1: " insn "\n" \ | |
26812 | +"2: pushl %%ss\n \ | |
26813 | + popl %%ds\n \ | |
26814 | + .section .fixup,\"ax\"\n \ | |
26815 | +3: mov %3, %1\n \ | |
26816 | + jmp 2b\n \ | |
26817 | + .previous\n" \ | |
26818 | + _ASM_EXTABLE(1b,3b) \ | |
26819 | + : "=r" (oldval), "=r" (ret), "+m" (*uaddr) \ | |
26820 | + : "i" (-EFAULT), "0" (oparg), "1" (0), "r" (__USER_DS)) | |
26821 | + | |
26822 | +#define __futex_atomic_op2(insn, ret, oldval, uaddr, oparg) \ | |
26823 | + __asm__ __volatile( \ | |
26824 | +" movw %w7, %%es\n \ | |
26825 | +1: movl %%es:%2, %0\n \ | |
26826 | + movl %0, %3\n" \ | |
26827 | + insn "\n" \ | |
26828 | +"2: lock; cmpxchgl %3, %%es:%2\n \ | |
26829 | + jnz 1b\n \ | |
26830 | +3: pushl %%ss\n \ | |
26831 | + popl %%es\n \ | |
26832 | + .section .fixup,\"ax\"\n \ | |
26833 | +4: mov %5, %1\n \ | |
26834 | + jmp 3b\n \ | |
26835 | + .previous\n" \ | |
26836 | + _ASM_EXTABLE(1b,4b) \ | |
26837 | + _ASM_EXTABLE(2b,4b) \ | |
26838 | + : "=&a" (oldval), "=&r" (ret), "+m" (*uaddr), \ | |
26839 | + "=&r" (tem) \ | |
26840 | + : "r" (oparg), "i" (-EFAULT), "1" (0), "r" (__USER_DS)) | |
26841 | +#else | |
26842 | #define __futex_atomic_op1(insn, ret, oldval, uaddr, oparg) \ | |
26843 | __asm__ __volatile( \ | |
26844 | "1: " insn "\n" \ | |
26845 | @@ -38,6 +73,7 @@ | |
da5b3fc8 | 26846 | : "=&a" (oldval), "=&r" (ret), "+m" (*uaddr), \ |
26847 | "=&r" (tem) \ | |
4dee9bd5 | 26848 | : "r" (oparg), "i" (-EFAULT), "1" (0)) |
26849 | +#endif | |
8a4b4a5e | 26850 | |
da5b3fc8 | 26851 | static inline int |
4dee9bd5 | 26852 | futex_atomic_op_inuser(int encoded_op, int __user *uaddr) |
26853 | @@ -64,11 +100,20 @@ futex_atomic_op_inuser(int encoded_op, i | |
da5b3fc8 | 26854 | |
4dee9bd5 | 26855 | switch (op) { |
26856 | case FUTEX_OP_SET: | |
26857 | +#ifdef CONFIG_X86_32 | |
da5b3fc8 | 26858 | + __futex_atomic_op1("xchgl %0, %%ds:%2", ret, oldval, uaddr, oparg); |
4dee9bd5 | 26859 | +#else |
26860 | __futex_atomic_op1("xchgl %0, %2", ret, oldval, uaddr, oparg); | |
26861 | +#endif | |
26862 | break; | |
26863 | case FUTEX_OP_ADD: | |
26864 | +#ifdef CONFIG_X86_32 | |
26865 | + __futex_atomic_op1("lock ; xaddl %0, %%ds:%2", ret, oldval, | |
26866 | + uaddr, oparg); | |
26867 | +#else | |
26868 | __futex_atomic_op1("lock; xaddl %0, %2", ret, oldval, | |
26869 | uaddr, oparg); | |
26870 | +#endif | |
26871 | break; | |
26872 | case FUTEX_OP_OR: | |
26873 | __futex_atomic_op2("orl %4, %3", ret, oldval, uaddr, oparg); | |
26874 | @@ -113,14 +158,26 @@ futex_atomic_cmpxchg_inatomic(int __user | |
da5b3fc8 | 26875 | return -EFAULT; |
26876 | ||
26877 | __asm__ __volatile__( | |
4dee9bd5 | 26878 | +#ifdef CONFIG_X86_32 |
da5b3fc8 | 26879 | + " movw %w5, %%ds \n" |
4dee9bd5 | 26880 | + "1: lock; cmpxchgl %3, %%ds:%1 \n" |
da5b3fc8 | 26881 | + "2: pushl %%ss \n" |
26882 | + " popl %%ds \n" | |
26883 | + " .section .fixup, \"ax\" \n" | |
4dee9bd5 | 26884 | +#else |
26885 | "1: lock; cmpxchgl %3, %1 \n" | |
26886 | "2: .section .fixup, \"ax\" \n" | |
26887 | +#endif | |
da5b3fc8 | 26888 | "3: mov %2, %0 \n" |
26889 | " jmp 2b \n" | |
26890 | " .previous \n" | |
4dee9bd5 | 26891 | _ASM_EXTABLE(1b,3b) |
da5b3fc8 | 26892 | : "=a" (oldval), "+m" (*uaddr) |
4dee9bd5 | 26893 | +#ifdef CONFIG_X86_32 |
da5b3fc8 | 26894 | + : "i" (-EFAULT), "r" (newval), "0" (oldval), "r" (__USER_DS) |
4dee9bd5 | 26895 | +#else |
26896 | : "i" (-EFAULT), "r" (newval), "0" (oldval) | |
26897 | +#endif | |
da5b3fc8 | 26898 | : "memory" |
26899 | ); | |
26900 | ||
4dee9bd5 | 26901 | diff -urNp linux-2.6.25.4/include/asm-x86/i387.h linux-2.6.25.4/include/asm-x86/i387.h |
26902 | --- linux-2.6.25.4/include/asm-x86/i387.h 2008-05-15 11:00:12.000000000 -0400 | |
26903 | +++ linux-2.6.25.4/include/asm-x86/i387.h 2008-05-18 13:33:17.000000000 -0400 | |
26904 | @@ -202,13 +202,8 @@ static inline void restore_fpu(struct ta | |
da5b3fc8 | 26905 | } |
26906 | ||
da5b3fc8 | 26907 | /* We need a safe address that is cheap to find and that is already |
26908 | - in L1 during context switch. The best choices are unfortunately | |
26909 | - different for UP and SMP */ | |
26910 | -#ifdef CONFIG_SMP | |
26911 | -#define safe_address (__per_cpu_offset[0]) | |
26912 | -#else | |
26913 | -#define safe_address (kstat_cpu(0).cpustat.user) | |
26914 | -#endif | |
26915 | + in L1 during context switch. */ | |
4dee9bd5 | 26916 | +#define safe_address (init_tss[smp_processor_id()].x86_tss.sp0) |
da5b3fc8 | 26917 | |
26918 | /* | |
26919 | * These must be called with preempt disabled | |
4dee9bd5 | 26920 | diff -urNp linux-2.6.25.4/include/asm-x86/io_64.h linux-2.6.25.4/include/asm-x86/io_64.h |
26921 | --- linux-2.6.25.4/include/asm-x86/io_64.h 2008-05-15 11:00:12.000000000 -0400 | |
26922 | +++ linux-2.6.25.4/include/asm-x86/io_64.h 2008-05-18 13:33:17.000000000 -0400 | |
26923 | @@ -143,6 +143,17 @@ static inline void * phys_to_virt(unsign | |
da5b3fc8 | 26924 | } |
26925 | #endif | |
8a4b4a5e | 26926 | |
da5b3fc8 | 26927 | +#define ARCH_HAS_VALID_PHYS_ADDR_RANGE |
26928 | +static inline int valid_phys_addr_range (unsigned long addr, size_t count) | |
8a4b4a5e | 26929 | +{ |
da5b3fc8 | 26930 | + return ((addr + count + PAGE_SIZE - 1) >> PAGE_SHIFT) < (1 << (boot_cpu_data.x86_phys_bits - PAGE_SHIFT)) ? 1 : 0; |
8a4b4a5e | 26931 | +} |
26932 | + | |
da5b3fc8 | 26933 | +static inline int valid_mmap_phys_addr_range (unsigned long pfn, size_t count) |
8a4b4a5e | 26934 | +{ |
da5b3fc8 | 26935 | + return (pfn + (count >> PAGE_SHIFT)) < (1 << (boot_cpu_data.x86_phys_bits - PAGE_SHIFT)) ? 1 : 0; |
8a4b4a5e | 26936 | +} |
26937 | + | |
8a4b4a5e | 26938 | /* |
da5b3fc8 | 26939 | * Change "struct page" to physical address. |
26940 | */ | |
4dee9bd5 | 26941 | diff -urNp linux-2.6.25.4/include/asm-x86/irqflags.h linux-2.6.25.4/include/asm-x86/irqflags.h |
26942 | --- linux-2.6.25.4/include/asm-x86/irqflags.h 2008-05-15 11:00:12.000000000 -0400 | |
26943 | +++ linux-2.6.25.4/include/asm-x86/irqflags.h 2008-05-18 13:33:17.000000000 -0400 | |
26944 | @@ -146,6 +146,8 @@ static inline unsigned long __raw_local_ | |
da5b3fc8 | 26945 | #define INTERRUPT_RETURN iret |
4dee9bd5 | 26946 | #define ENABLE_INTERRUPTS_SYSCALL_RET sti; sysexit |
da5b3fc8 | 26947 | #define GET_CR0_INTO_EAX movl %cr0, %eax |
26948 | +#define GET_CR0_INTO_EDX movl %cr0, %edx | |
26949 | +#define SET_CR0_FROM_EDX movl %edx, %cr0 | |
4dee9bd5 | 26950 | #endif |
50425a20 | 26951 | |
4dee9bd5 | 26952 | |
26953 | diff -urNp linux-2.6.25.4/include/asm-x86/kmap_types.h linux-2.6.25.4/include/asm-x86/kmap_types.h | |
26954 | --- linux-2.6.25.4/include/asm-x86/kmap_types.h 2008-05-15 11:00:12.000000000 -0400 | |
26955 | +++ linux-2.6.25.4/include/asm-x86/kmap_types.h 2008-05-18 13:33:17.000000000 -0400 | |
da5b3fc8 | 26956 | @@ -21,7 +21,8 @@ D(9) KM_IRQ0, |
26957 | D(10) KM_IRQ1, | |
26958 | D(11) KM_SOFTIRQ0, | |
26959 | D(12) KM_SOFTIRQ1, | |
26960 | -D(13) KM_TYPE_NR | |
26961 | +D(13) KM_CLEARPAGE, | |
26962 | +D(14) KM_TYPE_NR | |
26963 | }; | |
50425a20 | 26964 | |
da5b3fc8 | 26965 | #undef D |
4dee9bd5 | 26966 | diff -urNp linux-2.6.25.4/include/asm-x86/linkage.h linux-2.6.25.4/include/asm-x86/linkage.h |
26967 | --- linux-2.6.25.4/include/asm-x86/linkage.h 2008-05-15 11:00:12.000000000 -0400 | |
26968 | +++ linux-2.6.25.4/include/asm-x86/linkage.h 2008-05-18 13:33:17.000000000 -0400 | |
26969 | @@ -4,6 +4,11 @@ | |
26970 | #ifdef CONFIG_X86_64 | |
26971 | #define __ALIGN .p2align 4,,15 | |
26972 | #define __ALIGN_STR ".p2align 4,,15" | |
26973 | +#else | |
26974 | +#ifdef CONFIG_X86_ALIGNMENT_16 | |
26975 | +#define __ALIGN .align 16,0x90 | |
26976 | +#define __ALIGN_STR ".align 16,0x90" | |
26977 | +#endif | |
26978 | #endif | |
26979 | ||
26980 | #ifdef CONFIG_X86_32 | |
26981 | @@ -49,10 +54,5 @@ | |
26982 | ||
26983 | #endif | |
26984 | ||
26985 | -#ifdef CONFIG_X86_ALIGNMENT_16 | |
26986 | -#define __ALIGN .align 16,0x90 | |
26987 | -#define __ALIGN_STR ".align 16,0x90" | |
26988 | -#endif | |
26989 | - | |
26990 | #endif | |
26991 | ||
26992 | diff -urNp linux-2.6.25.4/include/asm-x86/mach-default/apm.h linux-2.6.25.4/include/asm-x86/mach-default/apm.h | |
26993 | --- linux-2.6.25.4/include/asm-x86/mach-default/apm.h 2008-05-15 11:00:12.000000000 -0400 | |
26994 | +++ linux-2.6.25.4/include/asm-x86/mach-default/apm.h 2008-05-18 13:33:17.000000000 -0400 | |
26995 | @@ -34,7 +34,7 @@ static inline void apm_bios_call_asm(u32 | |
da5b3fc8 | 26996 | __asm__ __volatile__(APM_DO_ZERO_SEGS |
26997 | "pushl %%edi\n\t" | |
26998 | "pushl %%ebp\n\t" | |
26999 | - "lcall *%%cs:apm_bios_entry\n\t" | |
27000 | + "lcall *%%ss:apm_bios_entry\n\t" | |
27001 | "setc %%al\n\t" | |
27002 | "popl %%ebp\n\t" | |
27003 | "popl %%edi\n\t" | |
4dee9bd5 | 27004 | @@ -58,7 +58,7 @@ static inline u8 apm_bios_call_simple_as |
da5b3fc8 | 27005 | __asm__ __volatile__(APM_DO_ZERO_SEGS |
27006 | "pushl %%edi\n\t" | |
27007 | "pushl %%ebp\n\t" | |
27008 | - "lcall *%%cs:apm_bios_entry\n\t" | |
27009 | + "lcall *%%ss:apm_bios_entry\n\t" | |
27010 | "setc %%bl\n\t" | |
27011 | "popl %%ebp\n\t" | |
27012 | "popl %%edi\n\t" | |
4dee9bd5 | 27013 | diff -urNp linux-2.6.25.4/include/asm-x86/mman.h linux-2.6.25.4/include/asm-x86/mman.h |
27014 | --- linux-2.6.25.4/include/asm-x86/mman.h 2008-05-15 11:00:12.000000000 -0400 | |
27015 | +++ linux-2.6.25.4/include/asm-x86/mman.h 2008-05-18 13:33:17.000000000 -0400 | |
da5b3fc8 | 27016 | @@ -16,4 +16,14 @@ |
27017 | #define MCL_CURRENT 1 /* lock all current mappings */ | |
27018 | #define MCL_FUTURE 2 /* lock all future mappings */ | |
50425a20 | 27019 | |
da5b3fc8 | 27020 | +#ifdef __KERNEL__ |
27021 | +#ifndef __ASSEMBLY__ | |
27022 | +#ifdef CONFIG_X86_32 | |
27023 | +#define arch_mmap_check i386_mmap_check | |
27024 | +int i386_mmap_check(unsigned long addr, unsigned long len, | |
27025 | + unsigned long flags); | |
27026 | +#endif | |
27027 | +#endif | |
50425a20 | 27028 | +#endif |
27029 | + | |
da5b3fc8 | 27030 | #endif /* _ASM_X86_MMAN_H */ |
4dee9bd5 | 27031 | diff -urNp linux-2.6.25.4/include/asm-x86/mmu_context_32.h linux-2.6.25.4/include/asm-x86/mmu_context_32.h |
27032 | --- linux-2.6.25.4/include/asm-x86/mmu_context_32.h 2008-05-15 11:00:12.000000000 -0400 | |
27033 | +++ linux-2.6.25.4/include/asm-x86/mmu_context_32.h 2008-05-18 13:33:17.000000000 -0400 | |
27034 | @@ -55,6 +55,22 @@ static inline void switch_mm(struct mm_s | |
da5b3fc8 | 27035 | */ |
27036 | if (unlikely(prev->context.ldt != next->context.ldt)) | |
27037 | load_LDT_nolock(&next->context); | |
27038 | + | |
27039 | +#if defined(CONFIG_PAX_PAGEEXEC) && defined(CONFIG_SMP) | |
27040 | + if (!nx_enabled) { | |
27041 | + smp_mb__before_clear_bit(); | |
27042 | + cpu_clear(cpu, prev->context.cpu_user_cs_mask); | |
27043 | + smp_mb__after_clear_bit(); | |
27044 | + cpu_set(cpu, next->context.cpu_user_cs_mask); | |
27045 | + } | |
73ca38b2 | 27046 | +#endif |
27047 | + | |
da5b3fc8 | 27048 | +#if defined(CONFIG_PAX_PAGEEXEC) || defined(CONFIG_PAX_SEGMEXEC) |
27049 | + if (unlikely(prev->context.user_cs_base != next->context.user_cs_base || | |
27050 | + prev->context.user_cs_limit != next->context.user_cs_limit)) | |
27051 | + set_user_cs(next->context.user_cs_base, next->context.user_cs_limit, cpu); | |
27052 | +#endif | |
50425a20 | 27053 | + |
da5b3fc8 | 27054 | } |
27055 | #ifdef CONFIG_SMP | |
27056 | else { | |
4dee9bd5 | 27057 | @@ -67,6 +83,19 @@ static inline void switch_mm(struct mm_s |
da5b3fc8 | 27058 | */ |
27059 | load_cr3(next->pgd); | |
27060 | load_LDT_nolock(&next->context); | |
27061 | + | |
27062 | +#ifdef CONFIG_PAX_PAGEEXEC | |
27063 | + if (!nx_enabled) | |
27064 | + cpu_set(cpu, next->context.cpu_user_cs_mask); | |
27065 | +#endif | |
27066 | + | |
27067 | +#if defined(CONFIG_PAX_PAGEEXEC) || defined(CONFIG_PAX_SEGMEXEC) | |
27068 | +#ifdef CONFIG_PAX_PAGEEXEC | |
27069 | + if (!((next->pax_flags & MF_PAX_PAGEEXEC) && nx_enabled)) | |
27070 | +#endif | |
27071 | + set_user_cs(next->context.user_cs_base, next->context.user_cs_limit, cpu); | |
27072 | +#endif | |
27073 | + | |
27074 | } | |
27075 | } | |
27076 | #endif | |
4dee9bd5 | 27077 | diff -urNp linux-2.6.25.4/include/asm-x86/mmu.h linux-2.6.25.4/include/asm-x86/mmu.h |
27078 | --- linux-2.6.25.4/include/asm-x86/mmu.h 2008-05-15 11:00:12.000000000 -0400 | |
27079 | +++ linux-2.6.25.4/include/asm-x86/mmu.h 2008-05-18 13:33:17.000000000 -0400 | |
da5b3fc8 | 27080 | @@ -11,13 +11,26 @@ |
27081 | * cpu_vm_mask is used to optimize ldt flushing. | |
50425a20 | 27082 | */ |
da5b3fc8 | 27083 | typedef struct { |
27084 | - void *ldt; | |
27085 | + struct desc_struct *ldt; | |
27086 | #ifdef CONFIG_X86_64 | |
27087 | rwlock_t ldtlock; | |
8a4b4a5e | 27088 | #endif |
da5b3fc8 | 27089 | int size; |
27090 | struct mutex lock; | |
27091 | - void *vdso; | |
27092 | + unsigned long vdso; | |
8a4b4a5e | 27093 | + |
da5b3fc8 | 27094 | +#ifdef CONFIG_X86_32 |
27095 | +#if defined(CONFIG_PAX_PAGEEXEC) || defined(CONFIG_PAX_SEGMEXEC) | |
27096 | + unsigned long user_cs_base; | |
27097 | + unsigned long user_cs_limit; | |
8a4b4a5e | 27098 | + |
da5b3fc8 | 27099 | +#if defined(CONFIG_PAX_PAGEEXEC) && defined(CONFIG_SMP) |
27100 | + cpumask_t cpu_user_cs_mask; | |
27101 | +#endif | |
27102 | + | |
27103 | +#endif | |
27104 | +#endif | |
27105 | + | |
27106 | } mm_context_t; | |
8a4b4a5e | 27107 | |
4dee9bd5 | 27108 | #ifdef CONFIG_SMP |
27109 | diff -urNp linux-2.6.25.4/include/asm-x86/module.h linux-2.6.25.4/include/asm-x86/module.h | |
27110 | --- linux-2.6.25.4/include/asm-x86/module.h 2008-05-15 11:00:12.000000000 -0400 | |
27111 | +++ linux-2.6.25.4/include/asm-x86/module.h 2008-05-18 13:33:17.000000000 -0400 | |
27112 | @@ -76,7 +76,12 @@ struct mod_arch_specific {}; | |
27113 | # else | |
27114 | # define MODULE_STACKSIZE "" | |
27115 | # endif | |
27116 | -# define MODULE_ARCH_VERMAGIC MODULE_PROC_FAMILY MODULE_STACKSIZE | |
27117 | +# ifdef CONFIG_GRKERNSEC | |
27118 | +# define MODULE_GRSEC "GRSECURITY " | |
27119 | +# else | |
27120 | +# define MODULE_GRSEC "" | |
27121 | +# endif | |
27122 | +# define MODULE_ARCH_VERMAGIC MODULE_PROC_FAMILY MODULE_STACKSIZE MODULE_GRSEC | |
da5b3fc8 | 27123 | #endif |
50425a20 | 27124 | |
4dee9bd5 | 27125 | #endif /* _ASM_MODULE_H */ |
27126 | diff -urNp linux-2.6.25.4/include/asm-x86/page_32.h linux-2.6.25.4/include/asm-x86/page_32.h | |
27127 | --- linux-2.6.25.4/include/asm-x86/page_32.h 2008-05-15 11:00:12.000000000 -0400 | |
27128 | +++ linux-2.6.25.4/include/asm-x86/page_32.h 2008-05-18 13:33:17.000000000 -0400 | |
27129 | @@ -13,6 +13,23 @@ | |
27130 | */ | |
27131 | #define __PAGE_OFFSET _AC(CONFIG_PAGE_OFFSET, UL) | |
50425a20 | 27132 | |
da5b3fc8 | 27133 | +#ifdef CONFIG_PAX_KERNEXEC |
27134 | +#ifndef __ASSEMBLY__ | |
27135 | +extern unsigned char MODULES_VADDR[]; | |
27136 | +extern unsigned char MODULES_END[]; | |
27137 | +extern unsigned char KERNEL_TEXT_OFFSET[]; | |
27138 | +#define ktla_ktva(addr) (addr + (unsigned long)KERNEL_TEXT_OFFSET) | |
27139 | +#define ktva_ktla(addr) (addr - (unsigned long)KERNEL_TEXT_OFFSET) | |
27140 | +#endif | |
27141 | +#else | |
27142 | +#define ktla_ktva(addr) (addr) | |
27143 | +#define ktva_ktla(addr) (addr) | |
27144 | +#endif | |
4dee9bd5 | 27145 | + |
da5b3fc8 | 27146 | +#ifdef CONFIG_PAX_PAGEEXEC |
27147 | +#define CONFIG_ARCH_TRACK_EXEC_LIMIT 1 | |
27148 | +#endif | |
27149 | + | |
4dee9bd5 | 27150 | #ifdef CONFIG_X86_PAE |
27151 | #define __PHYSICAL_MASK_SHIFT 36 | |
27152 | #define __VIRTUAL_MASK_SHIFT 32 | |
27153 | diff -urNp linux-2.6.25.4/include/asm-x86/page_64.h linux-2.6.25.4/include/asm-x86/page_64.h | |
27154 | --- linux-2.6.25.4/include/asm-x86/page_64.h 2008-05-15 11:00:12.000000000 -0400 | |
27155 | +++ linux-2.6.25.4/include/asm-x86/page_64.h 2008-05-18 13:33:17.000000000 -0400 | |
27156 | @@ -43,6 +43,9 @@ | |
27157 | #define __START_KERNEL (__START_KERNEL_map + __PHYSICAL_START) | |
da5b3fc8 | 27158 | #define __START_KERNEL_map _AC(0xffffffff80000000, UL) |
50425a20 | 27159 | |
da5b3fc8 | 27160 | +#define ktla_ktva(addr) (addr) |
27161 | +#define ktva_ktla(addr) (addr) | |
27162 | + | |
4dee9bd5 | 27163 | /* See Documentation/x86_64/mm.txt for a description of the memory map. */ |
27164 | #define __PHYSICAL_MASK_SHIFT 46 | |
27165 | #define __VIRTUAL_MASK_SHIFT 48 | |
27166 | @@ -87,5 +90,6 @@ typedef struct { pteval_t pte; } pte_t; | |
27167 | #define pfn_valid(pfn) ((pfn) < end_pfn) | |
27168 | #endif | |
27169 | ||
27170 | +#define nx_enabled (1) | |
50425a20 | 27171 | |
4dee9bd5 | 27172 | #endif /* _X86_64_PAGE_H */ |
27173 | diff -urNp linux-2.6.25.4/include/asm-x86/paravirt.h linux-2.6.25.4/include/asm-x86/paravirt.h | |
27174 | --- linux-2.6.25.4/include/asm-x86/paravirt.h 2008-05-15 11:00:12.000000000 -0400 | |
27175 | +++ linux-2.6.25.4/include/asm-x86/paravirt.h 2008-05-18 13:33:17.000000000 -0400 | |
27176 | @@ -1356,24 +1356,24 @@ static inline unsigned long __raw_local_ | |
50425a20 | 27177 | |
da5b3fc8 | 27178 | #define INTERRUPT_RETURN \ |
27179 | PARA_SITE(PARA_PATCH(pv_cpu_ops, PV_CPU_iret), CLBR_NONE, \ | |
27180 | - jmp *%cs:pv_cpu_ops+PV_CPU_iret) | |
27181 | + jmp *%ss:pv_cpu_ops+PV_CPU_iret) | |
50425a20 | 27182 | |
da5b3fc8 | 27183 | #define DISABLE_INTERRUPTS(clobbers) \ |
27184 | PARA_SITE(PARA_PATCH(pv_irq_ops, PV_IRQ_irq_disable), clobbers, \ | |
4dee9bd5 | 27185 | PV_SAVE_REGS; \ |
da5b3fc8 | 27186 | - call *%cs:pv_irq_ops+PV_IRQ_irq_disable; \ |
27187 | + call *%ss:pv_irq_ops+PV_IRQ_irq_disable; \ | |
4dee9bd5 | 27188 | PV_RESTORE_REGS;) \ |
50425a20 | 27189 | |
da5b3fc8 | 27190 | #define ENABLE_INTERRUPTS(clobbers) \ |
27191 | PARA_SITE(PARA_PATCH(pv_irq_ops, PV_IRQ_irq_enable), clobbers, \ | |
4dee9bd5 | 27192 | PV_SAVE_REGS; \ |
da5b3fc8 | 27193 | - call *%cs:pv_irq_ops+PV_IRQ_irq_enable; \ |
27194 | + call *%ss:pv_irq_ops+PV_IRQ_irq_enable; \ | |
4dee9bd5 | 27195 | PV_RESTORE_REGS;) |
27196 | ||
27197 | #define ENABLE_INTERRUPTS_SYSCALL_RET \ | |
27198 | PARA_SITE(PARA_PATCH(pv_cpu_ops, PV_CPU_irq_enable_syscall_ret),\ | |
27199 | CLBR_NONE, \ | |
27200 | - jmp *%cs:pv_cpu_ops+PV_CPU_irq_enable_syscall_ret) | |
27201 | + jmp *%ss:pv_cpu_ops+PV_CPU_irq_enable_syscall_ret) | |
27202 | ||
27203 | ||
27204 | #ifdef CONFIG_X86_32 | |
27205 | diff -urNp linux-2.6.25.4/include/asm-x86/pda.h linux-2.6.25.4/include/asm-x86/pda.h | |
27206 | --- linux-2.6.25.4/include/asm-x86/pda.h 2008-05-15 11:00:12.000000000 -0400 | |
27207 | +++ linux-2.6.25.4/include/asm-x86/pda.h 2008-05-18 13:33:17.000000000 -0400 | |
da5b3fc8 | 27208 | @@ -16,11 +16,9 @@ struct x8664_pda { |
4dee9bd5 | 27209 | unsigned long oldrsp; /* 24 user rsp for system call */ |
27210 | int irqcount; /* 32 Irq nesting counter. Starts -1 */ | |
27211 | unsigned int cpunumber; /* 36 Logical CPU number */ | |
da5b3fc8 | 27212 | -#ifdef CONFIG_CC_STACKPROTECTOR |
27213 | unsigned long stack_canary; /* 40 stack canary value */ | |
27214 | /* gcc-ABI: this canary MUST be at | |
27215 | offset 40!!! */ | |
27216 | -#endif | |
27217 | char *irqstackptr; | |
4dee9bd5 | 27218 | unsigned int nodenumber; /* number of current node */ |
da5b3fc8 | 27219 | unsigned int __softirq_pending; |
4dee9bd5 | 27220 | diff -urNp linux-2.6.25.4/include/asm-x86/percpu.h linux-2.6.25.4/include/asm-x86/percpu.h |
27221 | --- linux-2.6.25.4/include/asm-x86/percpu.h 2008-05-15 11:00:12.000000000 -0400 | |
27222 | +++ linux-2.6.25.4/include/asm-x86/percpu.h 2008-05-18 13:33:17.000000000 -0400 | |
84cd3cb1 | 27223 | @@ -67,6 +67,12 @@ DECLARE_PER_CPU(struct x8664_pda, pda); |
27224 | ||
27225 | #define __my_cpu_offset x86_read_percpu(this_cpu_off) | |
50425a20 | 27226 | |
4dee9bd5 | 27227 | +#include <asm-generic/sections.h> |
84cd3cb1 | 27228 | +#include <linux/threads.h> |
4dee9bd5 | 27229 | +#define __per_cpu_offset __per_cpu_offset |
27230 | +extern unsigned long __per_cpu_offset[NR_CPUS]; | |
27231 | +#define per_cpu_offset(x) (__per_cpu_offset[x] + (unsigned long)__per_cpu_start) | |
84cd3cb1 | 27232 | + |
4dee9bd5 | 27233 | /* fs segment starts at (positive) offset == __per_cpu_offset[cpu] */ |
27234 | #define __percpu_seg "%%fs:" | |
84cd3cb1 | 27235 | |
4dee9bd5 | 27236 | diff -urNp linux-2.6.25.4/include/asm-x86/pgalloc_32.h linux-2.6.25.4/include/asm-x86/pgalloc_32.h |
27237 | --- linux-2.6.25.4/include/asm-x86/pgalloc_32.h 2008-05-15 11:00:12.000000000 -0400 | |
27238 | +++ linux-2.6.25.4/include/asm-x86/pgalloc_32.h 2008-05-18 13:33:17.000000000 -0400 | |
27239 | @@ -21,7 +21,11 @@ static inline void pmd_populate_kernel(s | |
27240 | pmd_t *pmd, pte_t *pte) | |
27241 | { | |
27242 | paravirt_alloc_pt(mm, __pa(pte) >> PAGE_SHIFT); | |
da5b3fc8 | 27243 | +#ifdef CONFIG_COMPAT_VDSO |
4dee9bd5 | 27244 | set_pmd(pmd, __pmd(__pa(pte) | _PAGE_TABLE)); |
da5b3fc8 | 27245 | +#else |
4dee9bd5 | 27246 | + set_pmd(pmd, __pmd(__pa(pte) | _KERNPG_TABLE)); |
8a4b4a5e | 27247 | +#endif |
4dee9bd5 | 27248 | } |
50425a20 | 27249 | |
4dee9bd5 | 27250 | static inline void pmd_populate(struct mm_struct *mm, pmd_t *pmd, struct page *pte) |
27251 | diff -urNp linux-2.6.25.4/include/asm-x86/pgalloc_64.h linux-2.6.25.4/include/asm-x86/pgalloc_64.h | |
27252 | --- linux-2.6.25.4/include/asm-x86/pgalloc_64.h 2008-05-15 11:00:12.000000000 -0400 | |
27253 | +++ linux-2.6.25.4/include/asm-x86/pgalloc_64.h 2008-05-18 13:33:17.000000000 -0400 | |
da5b3fc8 | 27254 | @@ -6,7 +6,7 @@ |
27255 | #include <linux/mm.h> | |
27256 | ||
27257 | #define pmd_populate_kernel(mm, pmd, pte) \ | |
27258 | - set_pmd(pmd, __pmd(_PAGE_TABLE | __pa(pte))) | |
27259 | + set_pmd(pmd, __pmd(_KERNPG_TABLE | __pa(pte))) | |
27260 | #define pud_populate(mm, pud, pmd) \ | |
27261 | set_pud(pud, __pud(_PAGE_TABLE | __pa(pmd))) | |
27262 | #define pgd_populate(mm, pgd, pud) \ | |
4dee9bd5 | 27263 | diff -urNp linux-2.6.25.4/include/asm-x86/pgtable-2level.h linux-2.6.25.4/include/asm-x86/pgtable-2level.h |
27264 | --- linux-2.6.25.4/include/asm-x86/pgtable-2level.h 2008-05-15 11:00:12.000000000 -0400 | |
27265 | +++ linux-2.6.25.4/include/asm-x86/pgtable-2level.h 2008-05-18 13:33:17.000000000 -0400 | |
27266 | @@ -18,7 +18,19 @@ static inline void native_set_pte(pte_t | |
27267 | ||
da5b3fc8 | 27268 | static inline void native_set_pmd(pmd_t *pmdp, pmd_t pmd) |
27269 | { | |
27270 | + | |
27271 | +#ifdef CONFIG_PAX_KERNEXEC | |
27272 | + unsigned long cr0; | |
27273 | + | |
27274 | + pax_open_kernel(cr0); | |
27275 | +#endif | |
27276 | + | |
27277 | *pmdp = pmd; | |
27278 | + | |
27279 | +#ifdef CONFIG_PAX_KERNEXEC | |
27280 | + pax_close_kernel(cr0); | |
27281 | +#endif | |
27282 | + | |
27283 | } | |
4dee9bd5 | 27284 | |
27285 | static inline void native_set_pte_atomic(pte_t *ptep, pte_t pte) | |
27286 | diff -urNp linux-2.6.25.4/include/asm-x86/pgtable_32.h linux-2.6.25.4/include/asm-x86/pgtable_32.h | |
27287 | --- linux-2.6.25.4/include/asm-x86/pgtable_32.h 2008-05-15 11:00:12.000000000 -0400 | |
27288 | +++ linux-2.6.25.4/include/asm-x86/pgtable_32.h 2008-05-18 13:33:17.000000000 -0400 | |
27289 | @@ -25,8 +25,6 @@ | |
27290 | struct mm_struct; | |
27291 | struct vm_area_struct; | |
27292 | ||
da5b3fc8 | 27293 | -extern pgd_t swapper_pg_dir[1024]; |
4dee9bd5 | 27294 | - |
27295 | static inline void pgtable_cache_init(void) { } | |
27296 | static inline void check_pgt_cache(void) { } | |
27297 | void paging_init(void); | |
27298 | @@ -45,6 +43,11 @@ void paging_init(void); | |
da5b3fc8 | 27299 | # include <asm/pgtable-2level-defs.h> |
27300 | #endif | |
50425a20 | 27301 | |
da5b3fc8 | 27302 | +extern pgd_t swapper_pg_dir[PTRS_PER_PGD]; |
27303 | +#ifdef CONFIG_X86_PAE | |
27304 | +extern pmd_t swapper_pm_dir[PTRS_PER_PGD][PTRS_PER_PMD]; | |
50425a20 | 27305 | +#endif |
27306 | + | |
da5b3fc8 | 27307 | #define PGDIR_SIZE (1UL << PGDIR_SHIFT) |
27308 | #define PGDIR_MASK (~(PGDIR_SIZE-1)) | |
50425a20 | 27309 | |
4dee9bd5 | 27310 | @@ -83,7 +86,7 @@ void paging_init(void); |
da5b3fc8 | 27311 | #undef TEST_ACCESS_OK |
50425a20 | 27312 | |
da5b3fc8 | 27313 | /* The boot page tables (all created as a single array) */ |
27314 | -extern unsigned long pg0[]; | |
27315 | +extern pte_t pg0[]; | |
50425a20 | 27316 | |
da5b3fc8 | 27317 | #define pte_present(x) ((x).pte_low & (_PAGE_PRESENT | _PAGE_PROTNONE)) |
50425a20 | 27318 | |
4dee9bd5 | 27319 | @@ -113,7 +116,19 @@ extern unsigned long pg0[]; |
da5b3fc8 | 27320 | */ |
27321 | static inline void clone_pgd_range(pgd_t *dst, pgd_t *src, int count) | |
27322 | { | |
27323 | - memcpy(dst, src, count * sizeof(pgd_t)); | |
27324 | + | |
27325 | +#ifdef CONFIG_PAX_KERNEXEC | |
27326 | + unsigned long cr0; | |
27327 | + | |
27328 | + pax_open_kernel(cr0); | |
27329 | +#endif | |
27330 | + | |
27331 | + memcpy(dst, src, count * sizeof(pgd_t)); | |
27332 | + | |
27333 | +#ifdef CONFIG_PAX_KERNEXEC | |
27334 | + pax_close_kernel(cr0); | |
27335 | +#endif | |
27336 | + | |
27337 | } | |
50425a20 | 27338 | |
da5b3fc8 | 27339 | /* |
4dee9bd5 | 27340 | @@ -223,6 +238,9 @@ static inline void paravirt_pagetable_se |
50425a20 | 27341 | |
da5b3fc8 | 27342 | #endif /* !__ASSEMBLY__ */ |
50425a20 | 27343 | |
da5b3fc8 | 27344 | +#define HAVE_ARCH_UNMAPPED_AREA |
27345 | +#define HAVE_ARCH_UNMAPPED_AREA_TOPDOWN | |
50425a20 | 27346 | + |
4dee9bd5 | 27347 | /* |
27348 | * kern_addr_valid() is (1) for FLATMEM and (0) for | |
27349 | * SPARSEMEM and DISCONTIGMEM | |
27350 | diff -urNp linux-2.6.25.4/include/asm-x86/pgtable-3level.h linux-2.6.25.4/include/asm-x86/pgtable-3level.h | |
27351 | --- linux-2.6.25.4/include/asm-x86/pgtable-3level.h 2008-05-15 11:00:12.000000000 -0400 | |
27352 | +++ linux-2.6.25.4/include/asm-x86/pgtable-3level.h 2008-05-18 13:33:17.000000000 -0400 | |
27353 | @@ -64,11 +64,35 @@ static inline void native_set_pte_atomic | |
da5b3fc8 | 27354 | } |
27355 | static inline void native_set_pmd(pmd_t *pmdp, pmd_t pmd) | |
27356 | { | |
27357 | + | |
27358 | +#ifdef CONFIG_PAX_KERNEXEC | |
27359 | + unsigned long cr0; | |
27360 | + | |
27361 | + pax_open_kernel(cr0); | |
50425a20 | 27362 | +#endif |
27363 | + | |
da5b3fc8 | 27364 | set_64bit((unsigned long long *)(pmdp),native_pmd_val(pmd)); |
27365 | + | |
27366 | +#ifdef CONFIG_PAX_KERNEXEC | |
27367 | + pax_close_kernel(cr0); | |
27368 | +#endif | |
27369 | + | |
27370 | } | |
27371 | static inline void native_set_pud(pud_t *pudp, pud_t pud) | |
27372 | { | |
27373 | + | |
27374 | +#ifdef CONFIG_PAX_KERNEXEC | |
27375 | + unsigned long cr0; | |
27376 | + | |
27377 | + pax_open_kernel(cr0); | |
27378 | +#endif | |
27379 | + | |
4dee9bd5 | 27380 | set_64bit((unsigned long long *)(pudp),native_pud_val(pud)); |
da5b3fc8 | 27381 | + |
27382 | +#ifdef CONFIG_PAX_KERNEXEC | |
27383 | + pax_close_kernel(cr0); | |
27384 | +#endif | |
27385 | + | |
27386 | } | |
50425a20 | 27387 | |
da5b3fc8 | 27388 | /* |
4dee9bd5 | 27389 | diff -urNp linux-2.6.25.4/include/asm-x86/pgtable_64.h linux-2.6.25.4/include/asm-x86/pgtable_64.h |
27390 | --- linux-2.6.25.4/include/asm-x86/pgtable_64.h 2008-05-15 11:00:12.000000000 -0400 | |
27391 | +++ linux-2.6.25.4/include/asm-x86/pgtable_64.h 2008-05-18 13:33:17.000000000 -0400 | |
27392 | @@ -96,7 +96,19 @@ static inline pte_t native_ptep_get_and_ | |
da5b3fc8 | 27393 | |
4dee9bd5 | 27394 | static inline void native_set_pmd(pmd_t *pmdp, pmd_t pmd) |
da5b3fc8 | 27395 | { |
27396 | + | |
27397 | +#ifdef CONFIG_PAX_KERNEXEC | |
27398 | + unsigned long cr0; | |
27399 | + | |
27400 | + pax_open_kernel(cr0); | |
27401 | +#endif | |
50425a20 | 27402 | + |
4dee9bd5 | 27403 | *pmdp = pmd; |
da5b3fc8 | 27404 | + |
27405 | +#ifdef CONFIG_PAX_KERNEXEC | |
27406 | + pax_close_kernel(cr0); | |
50425a20 | 27407 | +#endif |
27408 | + | |
4dee9bd5 | 27409 | } |
50425a20 | 27410 | |
4dee9bd5 | 27411 | static inline void native_pmd_clear(pmd_t *pmd) |
27412 | @@ -148,17 +160,17 @@ static inline void native_pgd_clear(pgd_ | |
da5b3fc8 | 27413 | |
27414 | static inline unsigned long pgd_bad(pgd_t pgd) | |
27415 | { | |
27416 | - return pgd_val(pgd) & ~(PTE_MASK | _KERNPG_TABLE | _PAGE_USER); | |
27417 | + return pgd_val(pgd) & ~(PTE_MASK | _KERNPG_TABLE | _PAGE_USER | _PAGE_NX); | |
27418 | } | |
50425a20 | 27419 | |
da5b3fc8 | 27420 | static inline unsigned long pud_bad(pud_t pud) |
27421 | { | |
27422 | - return pud_val(pud) & ~(PTE_MASK | _KERNPG_TABLE | _PAGE_USER); | |
27423 | + return pud_val(pud) & ~(PTE_MASK | _KERNPG_TABLE | _PAGE_USER | _PAGE_NX); | |
27424 | } | |
50425a20 | 27425 | |
da5b3fc8 | 27426 | static inline unsigned long pmd_bad(pmd_t pmd) |
27427 | { | |
27428 | - return pmd_val(pmd) & ~(PTE_MASK | _KERNPG_TABLE | _PAGE_USER); | |
27429 | + return pmd_val(pmd) & ~(PTE_MASK | _KERNPG_TABLE | _PAGE_USER | _PAGE_NX); | |
27430 | } | |
50425a20 | 27431 | |
da5b3fc8 | 27432 | #define pte_none(x) (!pte_val(x)) |
4dee9bd5 | 27433 | diff -urNp linux-2.6.25.4/include/asm-x86/pgtable.h linux-2.6.25.4/include/asm-x86/pgtable.h |
27434 | --- linux-2.6.25.4/include/asm-x86/pgtable.h 2008-05-15 11:00:12.000000000 -0400 | |
27435 | +++ linux-2.6.25.4/include/asm-x86/pgtable.h 2008-05-18 13:33:17.000000000 -0400 | |
27436 | @@ -67,6 +67,9 @@ | |
27437 | #define PAGE_READONLY __pgprot(_PAGE_PRESENT | _PAGE_USER | _PAGE_ACCESSED | _PAGE_NX) | |
27438 | #define PAGE_READONLY_EXEC __pgprot(_PAGE_PRESENT | _PAGE_USER | _PAGE_ACCESSED) | |
50425a20 | 27439 | |
4dee9bd5 | 27440 | +#define PAGE_READONLY_NOEXEC PAGE_READONLY |
27441 | +#define PAGE_SHARED_NOEXEC PAGE_SHARED | |
27442 | + | |
27443 | #ifdef CONFIG_X86_32 | |
27444 | #define _PAGE_KERNEL_EXEC \ | |
27445 | (_PAGE_PRESENT | _PAGE_RW | _PAGE_DIRTY | _PAGE_ACCESSED) | |
27446 | @@ -87,7 +90,7 @@ extern pteval_t __PAGE_KERNEL, __PAGE_KE | |
27447 | #define __PAGE_KERNEL_NOCACHE (__PAGE_KERNEL | _PAGE_PCD | _PAGE_PWT) | |
27448 | #define __PAGE_KERNEL_UC_MINUS (__PAGE_KERNEL | _PAGE_PCD) | |
27449 | #define __PAGE_KERNEL_VSYSCALL (__PAGE_KERNEL_RX | _PAGE_USER) | |
27450 | -#define __PAGE_KERNEL_VSYSCALL_NOCACHE (__PAGE_KERNEL_VSYSCALL | _PAGE_PCD | _PAGE_PWT) | |
27451 | +#define __PAGE_KERNEL_VSYSCALL_NOCACHE (__PAGE_KERNEL_RO | _PAGE_PCD | _PAGE_PWT | _PAGE_USER) | |
27452 | #define __PAGE_KERNEL_LARGE (__PAGE_KERNEL | _PAGE_PSE) | |
27453 | #define __PAGE_KERNEL_LARGE_EXEC (__PAGE_KERNEL_EXEC | _PAGE_PSE) | |
27454 | ||
27455 | @@ -140,10 +143,13 @@ extern unsigned long empty_zero_page[PAG | |
27456 | extern spinlock_t pgd_lock; | |
27457 | extern struct list_head pgd_list; | |
50425a20 | 27458 | |
4dee9bd5 | 27459 | +extern pteval_t __supported_pte_mask; |
da5b3fc8 | 27460 | + |
4dee9bd5 | 27461 | /* |
27462 | * The following only work if pte_present() is true. | |
27463 | * Undefined behaviour if not.. | |
50425a20 | 27464 | */ |
4dee9bd5 | 27465 | +static inline int pte_user(pte_t pte) { return pte_val(pte) & _PAGE_USER; } |
27466 | static inline int pte_dirty(pte_t pte) { return pte_val(pte) & _PAGE_DIRTY; } | |
27467 | static inline int pte_young(pte_t pte) { return pte_val(pte) & _PAGE_ACCESSED; } | |
27468 | static inline int pte_write(pte_t pte) { return pte_val(pte) & _PAGE_RW; } | |
27469 | @@ -157,10 +163,31 @@ static inline int pmd_large(pmd_t pte) { | |
27470 | (_PAGE_PSE|_PAGE_PRESENT); | |
27471 | } | |
50425a20 | 27472 | |
4dee9bd5 | 27473 | +static inline pte_t pte_exprotect(pte_t pte) |
27474 | +{ | |
27475 | +#ifdef CONFIG_X86_PAE | |
27476 | + if (__supported_pte_mask & _PAGE_NX) | |
27477 | + return __pte(pte_val(pte) | _PAGE_NX); | |
27478 | + else | |
da5b3fc8 | 27479 | +#endif |
4dee9bd5 | 27480 | + return __pte(pte_val(pte) & ~_PAGE_USER); |
27481 | +} | |
da5b3fc8 | 27482 | + |
4dee9bd5 | 27483 | static inline pte_t pte_mkclean(pte_t pte) { return __pte(pte_val(pte) & ~(pteval_t)_PAGE_DIRTY); } |
27484 | static inline pte_t pte_mkold(pte_t pte) { return __pte(pte_val(pte) & ~(pteval_t)_PAGE_ACCESSED); } | |
27485 | static inline pte_t pte_wrprotect(pte_t pte) { return __pte(pte_val(pte) & ~(pteval_t)_PAGE_RW); } | |
27486 | -static inline pte_t pte_mkexec(pte_t pte) { return __pte(pte_val(pte) & ~(pteval_t)_PAGE_NX); } | |
27487 | +static inline pte_t pte_mkread(pte_t pte) { return __pte(pte_val(pte) | _PAGE_USER); } | |
27488 | + | |
27489 | +static inline pte_t pte_mkexec(pte_t pte) | |
27490 | +{ | |
27491 | +#ifdef CONFIG_X86_PAE | |
27492 | + if (__supported_pte_mask & _PAGE_NX) | |
27493 | + return __pte(pte_val(pte) & ~(pteval_t)_PAGE_NX); | |
27494 | + else | |
27495 | +#endif | |
27496 | + return __pte(pte_val(pte) | _PAGE_USER); | |
27497 | +} | |
27498 | + | |
27499 | static inline pte_t pte_mkdirty(pte_t pte) { return __pte(pte_val(pte) | _PAGE_DIRTY); } | |
27500 | static inline pte_t pte_mkyoung(pte_t pte) { return __pte(pte_val(pte) | _PAGE_ACCESSED); } | |
27501 | static inline pte_t pte_mkwrite(pte_t pte) { return __pte(pte_val(pte) | _PAGE_RW); } | |
27502 | @@ -169,8 +196,6 @@ static inline pte_t pte_clrhuge(pte_t pt | |
27503 | static inline pte_t pte_mkglobal(pte_t pte) { return __pte(pte_val(pte) | _PAGE_GLOBAL); } | |
27504 | static inline pte_t pte_clrglobal(pte_t pte) { return __pte(pte_val(pte) & ~(pteval_t)_PAGE_GLOBAL); } | |
50425a20 | 27505 | |
4dee9bd5 | 27506 | -extern pteval_t __supported_pte_mask; |
27507 | - | |
27508 | static inline pte_t pfn_pte(unsigned long page_nr, pgprot_t pgprot) | |
27509 | { | |
27510 | return __pte((((phys_addr_t)page_nr << PAGE_SHIFT) | | |
27511 | diff -urNp linux-2.6.25.4/include/asm-x86/processor.h linux-2.6.25.4/include/asm-x86/processor.h | |
27512 | --- linux-2.6.25.4/include/asm-x86/processor.h 2008-05-15 11:00:12.000000000 -0400 | |
27513 | +++ linux-2.6.25.4/include/asm-x86/processor.h 2008-05-18 13:33:17.000000000 -0400 | |
27514 | @@ -236,7 +236,7 @@ struct tss_struct { | |
27515 | unsigned long stack[64]; | |
27516 | } __attribute__((packed)); | |
da5b3fc8 | 27517 | |
4dee9bd5 | 27518 | -DECLARE_PER_CPU(struct tss_struct, init_tss); |
da5b3fc8 | 27519 | +extern struct tss_struct init_tss[NR_CPUS]; |
4dee9bd5 | 27520 | |
27521 | /* Save the original ist values for checking stack pointers during debugging */ | |
27522 | struct orig_ist { | |
27523 | @@ -714,11 +714,20 @@ static inline void prefetchw(const void | |
27524 | * User space process size: 3GB (default). | |
27525 | */ | |
27526 | #define TASK_SIZE (PAGE_OFFSET) | |
50425a20 | 27527 | + |
4dee9bd5 | 27528 | +#ifdef CONFIG_PAX_SEGMEXEC |
27529 | +#define SEGMEXEC_TASK_SIZE (TASK_SIZE / 2) | |
27530 | +#endif | |
27531 | + | |
27532 | +#ifdef CONFIG_PAX_SEGMEXEC | |
b43ccab8 | 27533 | +#define STACK_TOP ((current->mm->pax_flags & MF_PAX_SEGMEXEC)?SEGMEXEC_TASK_SIZE:TASK_SIZE) |
4dee9bd5 | 27534 | +#else |
b43ccab8 | 27535 | #define STACK_TOP TASK_SIZE |
27536 | -#define STACK_TOP_MAX STACK_TOP | |
4dee9bd5 | 27537 | +#endif |
b43ccab8 | 27538 | +#define STACK_TOP_MAX TASK_SIZE |
50425a20 | 27539 | |
da5b3fc8 | 27540 | #define INIT_THREAD { \ |
4dee9bd5 | 27541 | - .sp0 = sizeof(init_stack) + (long)&init_stack, \ |
27542 | + .sp0 = sizeof(init_stack) + (long)&init_stack - 8, \ | |
da5b3fc8 | 27543 | .vm86_info = NULL, \ |
27544 | .sysenter_cs = __KERNEL_CS, \ | |
27545 | .io_bitmap_ptr = NULL, \ | |
4dee9bd5 | 27546 | @@ -733,7 +742,7 @@ static inline void prefetchw(const void |
50425a20 | 27547 | */ |
da5b3fc8 | 27548 | #define INIT_TSS { \ |
27549 | .x86_tss = { \ | |
4dee9bd5 | 27550 | - .sp0 = sizeof(init_stack) + (long)&init_stack, \ |
27551 | + .sp0 = sizeof(init_stack) + (long)&init_stack - 8, \ | |
da5b3fc8 | 27552 | .ss0 = __KERNEL_DS, \ |
27553 | .ss1 = __KERNEL_CS, \ | |
27554 | .io_bitmap_base = INVALID_IO_BITMAP_OFFSET, \ | |
4dee9bd5 | 27555 | @@ -757,11 +766,7 @@ static inline void prefetchw(const void |
27556 | extern unsigned long thread_saved_pc(struct task_struct *tsk); | |
50425a20 | 27557 | |
da5b3fc8 | 27558 | #define THREAD_SIZE_LONGS (THREAD_SIZE/sizeof(unsigned long)) |
27559 | -#define KSTK_TOP(info) \ | |
27560 | -({ \ | |
27561 | - unsigned long *__ptr = (unsigned long *)(info); \ | |
27562 | - (unsigned long)(&__ptr[THREAD_SIZE_LONGS]); \ | |
27563 | -}) | |
4dee9bd5 | 27564 | +#define KSTK_TOP(info) ((info)->task.thread.sp0) |
50425a20 | 27565 | |
da5b3fc8 | 27566 | /* |
27567 | * The below -8 is to reserve 8 bytes on top of the ring0 stack. | |
4dee9bd5 | 27568 | @@ -776,7 +781,7 @@ extern unsigned long thread_saved_pc(str |
da5b3fc8 | 27569 | #define task_pt_regs(task) \ |
27570 | ({ \ | |
27571 | struct pt_regs *__regs__; \ | |
27572 | - __regs__ = (struct pt_regs *)(KSTK_TOP(task_stack_page(task))-8); \ | |
4dee9bd5 | 27573 | + __regs__ = (struct pt_regs *)((task)->thread.sp0); \ |
da5b3fc8 | 27574 | __regs__ - 1; \ |
27575 | }) | |
50425a20 | 27576 | |
4dee9bd5 | 27577 | @@ -792,7 +797,7 @@ extern unsigned long thread_saved_pc(str |
da5b3fc8 | 27578 | * space during mmap's. |
27579 | */ | |
4dee9bd5 | 27580 | #define IA32_PAGE_OFFSET ((current->personality & ADDR_LIMIT_3GB) ? \ |
27581 | - 0xc0000000 : 0xFFFFe000) | |
27582 | + 0xc0000000 : 0xFFFFf000) | |
50425a20 | 27583 | |
4dee9bd5 | 27584 | #define TASK_SIZE (test_thread_flag(TIF_IA32) ? \ |
27585 | IA32_PAGE_OFFSET : TASK_SIZE64) | |
27586 | @@ -837,6 +842,10 @@ extern unsigned long thread_saved_pc(str | |
27587 | */ | |
27588 | #define TASK_UNMAPPED_BASE (PAGE_ALIGN(TASK_SIZE / 3)) | |
50425a20 | 27589 | |
4dee9bd5 | 27590 | +#ifdef CONFIG_PAX_SEGMEXEC |
27591 | +#define SEGMEXEC_TASK_UNMAPPED_BASE (PAGE_ALIGN(SEGMEXEC_TASK_SIZE / 3)) | |
27592 | +#endif | |
27593 | + | |
27594 | #define KSTK_EIP(task) (task_pt_regs(task)->ip) | |
50425a20 | 27595 | |
4dee9bd5 | 27596 | #endif |
27597 | diff -urNp linux-2.6.25.4/include/asm-x86/ptrace.h linux-2.6.25.4/include/asm-x86/ptrace.h | |
27598 | --- linux-2.6.25.4/include/asm-x86/ptrace.h 2008-05-15 11:00:12.000000000 -0400 | |
27599 | +++ linux-2.6.25.4/include/asm-x86/ptrace.h 2008-05-18 13:33:17.000000000 -0400 | |
27600 | @@ -56,7 +56,6 @@ struct pt_regs { | |
27601 | }; | |
27602 | ||
27603 | #include <asm/vm86.h> | |
27604 | -#include <asm/segment.h> | |
27605 | ||
27606 | #endif /* __KERNEL__ */ | |
27607 | ||
27608 | @@ -129,6 +128,7 @@ struct pt_regs { | |
27609 | ||
27610 | /* the DS BTS struct is used for ptrace as well */ | |
27611 | #include <asm/ds.h> | |
27612 | +#include <asm/segment.h> | |
27613 | ||
27614 | struct task_struct; | |
27615 | ||
27616 | @@ -148,28 +148,29 @@ void signal_fault(struct pt_regs *regs, | |
27617 | #define regs_return_value(regs) ((regs)->ax) | |
50425a20 | 27618 | |
da5b3fc8 | 27619 | /* |
27620 | - * user_mode_vm(regs) determines whether a register set came from user mode. | |
27621 | + * user_mode(regs) determines whether a register set came from user mode. | |
27622 | * This is true if V8086 mode was enabled OR if the register set was from | |
27623 | * protected mode with RPL-3 CS value. This tricky test checks that with | |
27624 | * one comparison. Many places in the kernel can bypass this full check | |
27625 | - * if they have already ruled out V8086 mode, so user_mode(regs) can be used. | |
27626 | + * if they have already ruled out V8086 mode, so user_mode_novm(regs) can | |
27627 | + * be used. | |
27628 | */ | |
27629 | -static inline int user_mode(struct pt_regs *regs) | |
27630 | +static inline int user_mode_novm(struct pt_regs *regs) | |
27631 | { | |
4dee9bd5 | 27632 | #ifdef CONFIG_X86_32 |
27633 | return (regs->cs & SEGMENT_RPL_MASK) == USER_RPL; | |
27634 | #else | |
27635 | - return !!(regs->cs & 3); | |
27636 | + return !!(regs->cs & SEGMENT_RPL_MASK); | |
27637 | #endif | |
da5b3fc8 | 27638 | } |
4dee9bd5 | 27639 | |
da5b3fc8 | 27640 | -static inline int user_mode_vm(struct pt_regs *regs) |
27641 | +static inline int user_mode(struct pt_regs *regs) | |
27642 | { | |
4dee9bd5 | 27643 | #ifdef CONFIG_X86_32 |
27644 | return ((regs->cs & SEGMENT_RPL_MASK) | | |
27645 | (regs->flags & VM_MASK)) >= USER_RPL; | |
27646 | #else | |
27647 | - return user_mode(regs); | |
27648 | + return user_mode_novm(regs); | |
27649 | #endif | |
da5b3fc8 | 27650 | } |
4dee9bd5 | 27651 | |
27652 | diff -urNp linux-2.6.25.4/include/asm-x86/reboot.h linux-2.6.25.4/include/asm-x86/reboot.h | |
27653 | --- linux-2.6.25.4/include/asm-x86/reboot.h 2008-05-15 11:00:12.000000000 -0400 | |
27654 | +++ linux-2.6.25.4/include/asm-x86/reboot.h 2008-05-18 13:33:17.000000000 -0400 | |
da5b3fc8 | 27655 | @@ -15,6 +15,6 @@ struct machine_ops |
27656 | ||
27657 | extern struct machine_ops machine_ops; | |
50425a20 | 27658 | |
da5b3fc8 | 27659 | -void machine_real_restart(unsigned char *code, int length); |
27660 | +void machine_real_restart(const unsigned char *code, unsigned int length); | |
50425a20 | 27661 | |
da5b3fc8 | 27662 | #endif /* _ASM_REBOOT_H */ |
4dee9bd5 | 27663 | diff -urNp linux-2.6.25.4/include/asm-x86/segment.h linux-2.6.25.4/include/asm-x86/segment.h |
27664 | --- linux-2.6.25.4/include/asm-x86/segment.h 2008-05-15 11:00:12.000000000 -0400 | |
27665 | +++ linux-2.6.25.4/include/asm-x86/segment.h 2008-05-18 13:33:17.000000000 -0400 | |
27666 | @@ -83,13 +83,19 @@ | |
27667 | #define GDT_ENTRY_ESPFIX_SS (GDT_ENTRY_KERNEL_BASE + 14) | |
27668 | #define __ESPFIX_SS (GDT_ENTRY_ESPFIX_SS * 8) | |
27669 | ||
27670 | -#define GDT_ENTRY_PERCPU (GDT_ENTRY_KERNEL_BASE + 15) | |
27671 | +#define GDT_ENTRY_PERCPU (GDT_ENTRY_KERNEL_BASE + 15) | |
27672 | #ifdef CONFIG_SMP | |
27673 | #define __KERNEL_PERCPU (GDT_ENTRY_PERCPU * 8) | |
27674 | #else | |
da5b3fc8 | 27675 | #define __KERNEL_PERCPU 0 |
27676 | #endif | |
50425a20 | 27677 | |
4dee9bd5 | 27678 | +#define GDT_ENTRY_PCIBIOS_CS (GDT_ENTRY_KERNEL_BASE + 16) |
da5b3fc8 | 27679 | +#define __PCIBIOS_CS (GDT_ENTRY_PCIBIOS_CS * 8) |
50425a20 | 27680 | + |
4dee9bd5 | 27681 | +#define GDT_ENTRY_PCIBIOS_DS (GDT_ENTRY_KERNEL_BASE + 17) |
da5b3fc8 | 27682 | +#define __PCIBIOS_DS (GDT_ENTRY_PCIBIOS_DS * 8) |
50425a20 | 27683 | + |
da5b3fc8 | 27684 | #define GDT_ENTRY_DOUBLEFAULT_TSS 31 |
50425a20 | 27685 | |
da5b3fc8 | 27686 | /* |
4dee9bd5 | 27687 | @@ -130,10 +136,10 @@ |
da5b3fc8 | 27688 | #define SEGMENT_IS_KERNEL_CODE(x) (((x) & 0xfc) == GDT_ENTRY_KERNEL_CS * 8) |
50425a20 | 27689 | |
da5b3fc8 | 27690 | /* Matches __KERNEL_CS and __USER_CS (they must be 2 entries apart) */ |
27691 | -#define SEGMENT_IS_FLAT_CODE(x) (((x) & 0xec) == GDT_ENTRY_KERNEL_CS * 8) | |
27692 | +#define SEGMENT_IS_FLAT_CODE(x) (((x) & 0xFFFCU) == __KERNEL_CS || ((x) & 0xFFFCU) == __USER_CS) | |
50425a20 | 27693 | |
da5b3fc8 | 27694 | /* Matches PNP_CS32 and PNP_CS16 (they must be consecutive) */ |
27695 | -#define SEGMENT_IS_PNP_CODE(x) (((x) & 0xf4) == GDT_ENTRY_PNPBIOS_BASE * 8) | |
27696 | +#define SEGMENT_IS_PNP_CODE(x) (((x) & 0xFFFCU) == PNP_CS32 || ((x) & 0xFFFCU) == PNP_CS16) | |
50425a20 | 27697 | |
4dee9bd5 | 27698 | |
27699 | #else | |
27700 | diff -urNp linux-2.6.25.4/include/asm-x86/system.h linux-2.6.25.4/include/asm-x86/system.h | |
27701 | --- linux-2.6.25.4/include/asm-x86/system.h 2008-05-15 11:00:12.000000000 -0400 | |
27702 | +++ linux-2.6.25.4/include/asm-x86/system.h 2008-05-18 13:33:17.000000000 -0400 | |
27703 | @@ -70,6 +70,8 @@ struct task_struct *__switch_to(struct t | |
27704 | ".globl thread_return\n" \ | |
27705 | "thread_return:\n\t" \ | |
27706 | "movq %%gs:%P[pda_pcurrent],%%rsi\n\t" \ | |
27707 | + "movq %P[task_canary](%%rsi),%%r8\n\t" \ | |
27708 | + "movq %%r8,%%gs:%P[pda_canary]\n\t" \ | |
27709 | "movq %P[thread_info](%%rsi),%%r8\n\t" \ | |
27710 | LOCK_PREFIX "btr %[tif_fork],%P[ti_flags](%%r8)\n\t" \ | |
27711 | "movq %%rax,%%rdi\n\t" \ | |
27712 | @@ -81,7 +83,9 @@ struct task_struct *__switch_to(struct t | |
27713 | [ti_flags] "i" (offsetof(struct thread_info, flags)), \ | |
27714 | [tif_fork] "i" (TIF_FORK), \ | |
27715 | [thread_info] "i" (offsetof(struct task_struct, stack)), \ | |
27716 | - [pda_pcurrent] "i" (offsetof(struct x8664_pda, pcurrent)) \ | |
27717 | + [task_canary] "i" (offsetof(struct task_struct, stack_canary)), \ | |
27718 | + [pda_pcurrent] "i" (offsetof(struct x8664_pda, pcurrent)), \ | |
27719 | + [pda_canary] "i" (offsetof(struct x8664_pda, stack_canary))\ | |
27720 | : "memory", "cc" __EXTRA_CLOBBER) | |
da5b3fc8 | 27721 | #endif |
4dee9bd5 | 27722 | |
27723 | @@ -145,7 +149,7 @@ static inline unsigned long get_limit(un | |
27724 | unsigned long __limit; | |
27725 | __asm__("lsll %1,%0" | |
27726 | :"=r" (__limit):"r" (segment)); | |
27727 | - return __limit+1; | |
27728 | + return __limit; | |
27729 | } | |
27730 | ||
27731 | static inline void native_clts(void) | |
27732 | @@ -269,6 +273,21 @@ static inline void native_wbinvd(void) | |
27733 | ||
da5b3fc8 | 27734 | #define stts() write_cr0(8 | read_cr0()) |
27735 | ||
27736 | +#define pax_open_kernel(cr0) \ | |
27737 | +do { \ | |
27738 | + typecheck(unsigned long, cr0); \ | |
27739 | + preempt_disable(); \ | |
27740 | + cr0 = read_cr0(); \ | |
27741 | + write_cr0(cr0 & ~X86_CR0_WP); \ | |
27742 | +} while (0) | |
50425a20 | 27743 | + |
da5b3fc8 | 27744 | +#define pax_close_kernel(cr0) \ |
27745 | +do { \ | |
27746 | + typecheck(unsigned long, cr0); \ | |
27747 | + write_cr0(cr0); \ | |
27748 | + preempt_enable_no_resched(); \ | |
27749 | +} while (0) | |
50425a20 | 27750 | + |
4dee9bd5 | 27751 | #endif /* __KERNEL__ */ |
50425a20 | 27752 | |
4dee9bd5 | 27753 | static inline void clflush(volatile void *__p) |
27754 | @@ -276,6 +295,21 @@ static inline void clflush(volatile void | |
27755 | asm volatile("clflush %0" : "+m" (*(volatile char __force *)__p)); | |
da5b3fc8 | 27756 | } |
50425a20 | 27757 | |
da5b3fc8 | 27758 | +#define pax_open_kernel(cr0) \ |
27759 | +do { \ | |
27760 | + typecheck(unsigned long, cr0); \ | |
27761 | + preempt_disable(); \ | |
27762 | + cr0 = read_cr0(); \ | |
27763 | + write_cr0(cr0 & ~X86_CR0_WP); \ | |
27764 | +} while (0) | |
27765 | + | |
27766 | +#define pax_close_kernel(cr0) \ | |
27767 | +do { \ | |
27768 | + typecheck(unsigned long, cr0); \ | |
27769 | + write_cr0(cr0); \ | |
27770 | + preempt_enable_no_resched(); \ | |
27771 | +} while (0) | |
27772 | + | |
4dee9bd5 | 27773 | #define nop() __asm__ __volatile__ ("nop") |
8a4b4a5e | 27774 | |
4dee9bd5 | 27775 | void disable_hlt(void); |
27776 | @@ -284,7 +318,7 @@ void enable_hlt(void); | |
27777 | extern int es7000_plat; | |
da5b3fc8 | 27778 | void cpu_idle_wait(void); |
50425a20 | 27779 | |
da5b3fc8 | 27780 | -extern unsigned long arch_align_stack(unsigned long sp); |
27781 | +#define arch_align_stack(x) (x) | |
27782 | extern void free_init_pages(char *what, unsigned long begin, unsigned long end); | |
50425a20 | 27783 | |
4dee9bd5 | 27784 | void default_idle(void); |
27785 | diff -urNp linux-2.6.25.4/include/asm-x86/uaccess_32.h linux-2.6.25.4/include/asm-x86/uaccess_32.h | |
27786 | --- linux-2.6.25.4/include/asm-x86/uaccess_32.h 2008-05-15 11:00:12.000000000 -0400 | |
27787 | +++ linux-2.6.25.4/include/asm-x86/uaccess_32.h 2008-05-18 13:33:17.000000000 -0400 | |
27788 | @@ -10,6 +10,7 @@ | |
da5b3fc8 | 27789 | #include <linux/string.h> |
4dee9bd5 | 27790 | #include <asm/asm.h> |
da5b3fc8 | 27791 | #include <asm/page.h> |
27792 | +#include <asm/segment.h> | |
50425a20 | 27793 | |
da5b3fc8 | 27794 | #define VERIFY_READ 0 |
27795 | #define VERIFY_WRITE 1 | |
4dee9bd5 | 27796 | @@ -30,7 +31,8 @@ |
50425a20 | 27797 | |
da5b3fc8 | 27798 | #define get_ds() (KERNEL_DS) |
27799 | #define get_fs() (current_thread_info()->addr_limit) | |
27800 | -#define set_fs(x) (current_thread_info()->addr_limit = (x)) | |
27801 | +void __set_fs(mm_segment_t x, int cpu); | |
27802 | +void set_fs(mm_segment_t x); | |
8a4b4a5e | 27803 | |
da5b3fc8 | 27804 | #define segment_eq(a,b) ((a).seg == (b).seg) |
8a4b4a5e | 27805 | |
4dee9bd5 | 27806 | @@ -102,6 +104,7 @@ struct exception_table_entry |
50425a20 | 27807 | }; |
27808 | ||
da5b3fc8 | 27809 | extern int fixup_exception(struct pt_regs *regs); |
27810 | +#define ARCH_HAS_SORT_EXTABLE | |
50425a20 | 27811 | |
da5b3fc8 | 27812 | /* |
27813 | * These are the main single-value transfer routines. They automatically | |
4dee9bd5 | 27814 | @@ -281,9 +284,12 @@ extern void __put_user_8(void); |
50425a20 | 27815 | |
da5b3fc8 | 27816 | #define __put_user_u64(x, addr, err) \ |
27817 | __asm__ __volatile__( \ | |
27818 | - "1: movl %%eax,0(%2)\n" \ | |
27819 | - "2: movl %%edx,4(%2)\n" \ | |
27820 | + " movw %w5,%%ds\n" \ | |
27821 | + "1: movl %%eax,%%ds:0(%2)\n" \ | |
27822 | + "2: movl %%edx,%%ds:4(%2)\n" \ | |
27823 | "3:\n" \ | |
27824 | + " pushl %%ss\n" \ | |
27825 | + " popl %%ds\n" \ | |
27826 | ".section .fixup,\"ax\"\n" \ | |
27827 | "4: movl %3,%0\n" \ | |
27828 | " jmp 3b\n" \ | |
4dee9bd5 | 27829 | @@ -291,7 +297,8 @@ extern void __put_user_8(void); |
27830 | _ASM_EXTABLE(1b,4b) \ | |
27831 | _ASM_EXTABLE(2b,4b) \ | |
da5b3fc8 | 27832 | : "=r"(err) \ |
27833 | - : "A" (x), "r" (addr), "i"(-EFAULT), "0"(err)) | |
27834 | + : "A" (x), "r" (addr), "i"(-EFAULT), "0"(err), \ | |
27835 | + "r"(__USER_DS)) | |
27836 | ||
27837 | #ifdef CONFIG_X86_WP_WORKS_OK | |
27838 | ||
4dee9bd5 | 27839 | @@ -330,15 +337,19 @@ struct __large_struct { unsigned long bu |
da5b3fc8 | 27840 | */ |
27841 | #define __put_user_asm(x, addr, err, itype, rtype, ltype, errret) \ | |
27842 | __asm__ __volatile__( \ | |
27843 | - "1: mov"itype" %"rtype"1,%2\n" \ | |
27844 | + " movw %w5,%%ds\n" \ | |
27845 | + "1: mov"itype" %"rtype"1,%%ds:%2\n" \ | |
27846 | "2:\n" \ | |
27847 | + " pushl %%ss\n" \ | |
27848 | + " popl %%ds\n" \ | |
27849 | ".section .fixup,\"ax\"\n" \ | |
27850 | "3: movl %3,%0\n" \ | |
27851 | " jmp 2b\n" \ | |
4dee9bd5 | 27852 | ".previous\n" \ |
27853 | _ASM_EXTABLE(1b,3b) \ | |
da5b3fc8 | 27854 | : "=r"(err) \ |
27855 | - : ltype (x), "m"(__m(addr)), "i"(errret), "0"(err)) | |
27856 | + : ltype (x), "m"(__m(addr)), "i"(errret), "0"(err), \ | |
27857 | + "r"(__USER_DS)) | |
50425a20 | 27858 | |
50425a20 | 27859 | |
da5b3fc8 | 27860 | #define __get_user_nocheck(x,ptr,size) \ |
4dee9bd5 | 27861 | @@ -366,8 +377,11 @@ do { \ |
50425a20 | 27862 | |
da5b3fc8 | 27863 | #define __get_user_asm(x, addr, err, itype, rtype, ltype, errret) \ |
27864 | __asm__ __volatile__( \ | |
27865 | - "1: mov"itype" %2,%"rtype"1\n" \ | |
27866 | + " movw %w5,%%ds\n" \ | |
27867 | + "1: mov"itype" %%ds:%2,%"rtype"1\n" \ | |
27868 | "2:\n" \ | |
27869 | + " pushl %%ss\n" \ | |
27870 | + " popl %%ds\n" \ | |
27871 | ".section .fixup,\"ax\"\n" \ | |
27872 | "3: movl %3,%0\n" \ | |
27873 | " xor"itype" %"rtype"1,%"rtype"1\n" \ | |
4dee9bd5 | 27874 | @@ -375,7 +389,7 @@ do { \ |
27875 | ".previous\n" \ | |
27876 | _ASM_EXTABLE(1b,3b) \ | |
da5b3fc8 | 27877 | : "=r"(err), ltype (x) \ |
27878 | - : "m"(__m(addr)), "i"(errret), "0"(err)) | |
27879 | + : "m"(__m(addr)), "i"(errret), "0"(err), "r"(__USER_DS)) | |
50425a20 | 27880 | |
50425a20 | 27881 | |
da5b3fc8 | 27882 | unsigned long __must_check __copy_to_user_ll(void __user *to, |
4dee9bd5 | 27883 | diff -urNp linux-2.6.25.4/include/asm-x86/uaccess_64.h linux-2.6.25.4/include/asm-x86/uaccess_64.h |
27884 | --- linux-2.6.25.4/include/asm-x86/uaccess_64.h 2008-05-15 11:00:12.000000000 -0400 | |
27885 | +++ linux-2.6.25.4/include/asm-x86/uaccess_64.h 2008-05-18 13:33:17.000000000 -0400 | |
27886 | @@ -68,6 +68,7 @@ struct exception_table_entry | |
27887 | extern int fixup_exception(struct pt_regs *regs); | |
50425a20 | 27888 | |
da5b3fc8 | 27889 | #define ARCH_HAS_SEARCH_EXTABLE |
27890 | +#define ARCH_HAS_SORT_EXTABLE | |
50425a20 | 27891 | |
da5b3fc8 | 27892 | /* |
27893 | * These are the main single-value transfer routines. They automatically | |
4dee9bd5 | 27894 | diff -urNp linux-2.6.25.4/include/asm-xtensa/kmap_types.h linux-2.6.25.4/include/asm-xtensa/kmap_types.h |
27895 | --- linux-2.6.25.4/include/asm-xtensa/kmap_types.h 2008-05-15 11:00:12.000000000 -0400 | |
27896 | +++ linux-2.6.25.4/include/asm-xtensa/kmap_types.h 2008-05-18 13:33:17.000000000 -0400 | |
50425a20 | 27897 | @@ -25,6 +25,7 @@ enum km_type { |
27898 | KM_IRQ1, | |
27899 | KM_SOFTIRQ0, | |
27900 | KM_SOFTIRQ1, | |
27901 | + KM_CLEARPAGE, | |
27902 | KM_TYPE_NR | |
27903 | }; | |
27904 | ||
4dee9bd5 | 27905 | diff -urNp linux-2.6.25.4/include/linux/a.out.h linux-2.6.25.4/include/linux/a.out.h |
27906 | --- linux-2.6.25.4/include/linux/a.out.h 2008-05-15 11:00:12.000000000 -0400 | |
27907 | +++ linux-2.6.25.4/include/linux/a.out.h 2008-05-18 13:33:17.000000000 -0400 | |
4dee9bd5 | 27908 | @@ -41,6 +51,14 @@ enum machine_type { |
50425a20 | 27909 | M_MIPS2 = 152 /* MIPS R6000/R4000 binary */ |
27910 | }; | |
27911 | ||
27912 | +/* Constants for the N_FLAGS field */ | |
27913 | +#define F_PAX_PAGEEXEC 1 /* Paging based non-executable pages */ | |
27914 | +#define F_PAX_EMUTRAMP 2 /* Emulate trampolines */ | |
27915 | +#define F_PAX_MPROTECT 4 /* Restrict mprotect() */ | |
27916 | +#define F_PAX_RANDMMAP 8 /* Randomize mmap() base */ | |
27917 | +/*#define F_PAX_RANDEXEC 16*/ /* Randomize ET_EXEC base */ | |
27918 | +#define F_PAX_SEGMEXEC 32 /* Segmentation based non-executable pages */ | |
27919 | + | |
27920 | #if !defined (N_MAGIC) | |
27921 | #define N_MAGIC(exec) ((exec).a_info & 0xffff) | |
27922 | #endif | |
4dee9bd5 | 27923 | diff -urNp linux-2.6.25.4/include/linux/binfmts.h linux-2.6.25.4/include/linux/binfmts.h |
27924 | --- linux-2.6.25.4/include/linux/binfmts.h 2008-05-15 11:00:12.000000000 -0400 | |
27925 | +++ linux-2.6.25.4/include/linux/binfmts.h 2008-05-18 13:33:17.000000000 -0400 | |
da5b3fc8 | 27926 | @@ -49,6 +49,7 @@ struct linux_binprm{ |
50425a20 | 27927 | unsigned interp_data; |
27928 | unsigned long loader, exec; | |
da5b3fc8 | 27929 | unsigned long argv_len; |
50425a20 | 27930 | + int misc; |
27931 | }; | |
27932 | ||
27933 | #define BINPRM_FLAGS_ENFORCE_NONDUMP_BIT 0 | |
da5b3fc8 | 27934 | @@ -100,5 +101,8 @@ extern void compute_creds(struct linux_b |
50425a20 | 27935 | extern int do_coredump(long signr, int exit_code, struct pt_regs * regs); |
27936 | extern int set_binfmt(struct linux_binfmt *new); | |
27937 | ||
27938 | +void pax_report_fault(struct pt_regs *regs, void *pc, void *sp); | |
27939 | +void pax_report_insns(void *pc, void *sp); | |
27940 | + | |
27941 | #endif /* __KERNEL__ */ | |
27942 | #endif /* _LINUX_BINFMTS_H */ | |
4dee9bd5 | 27943 | diff -urNp linux-2.6.25.4/include/linux/cache.h linux-2.6.25.4/include/linux/cache.h |
27944 | --- linux-2.6.25.4/include/linux/cache.h 2008-05-15 11:00:12.000000000 -0400 | |
27945 | +++ linux-2.6.25.4/include/linux/cache.h 2008-05-18 13:33:17.000000000 -0400 | |
8a4b4a5e | 27946 | @@ -16,6 +16,10 @@ |
27947 | #define __read_mostly | |
27948 | #endif | |
27949 | ||
27950 | +#ifndef __read_only | |
da5b3fc8 | 27951 | +#define __read_only __read_mostly |
8a4b4a5e | 27952 | +#endif |
27953 | + | |
27954 | #ifndef ____cacheline_aligned | |
27955 | #define ____cacheline_aligned __attribute__((__aligned__(SMP_CACHE_BYTES))) | |
27956 | #endif | |
4dee9bd5 | 27957 | diff -urNp linux-2.6.25.4/include/linux/capability.h linux-2.6.25.4/include/linux/capability.h |
27958 | --- linux-2.6.25.4/include/linux/capability.h 2008-05-15 11:00:12.000000000 -0400 | |
27959 | +++ linux-2.6.25.4/include/linux/capability.h 2008-05-18 13:33:17.000000000 -0400 | |
27960 | @@ -488,6 +488,7 @@ extern const kernel_cap_t __cap_full_set | |
27961 | extern const kernel_cap_t __cap_init_eff_set; | |
50425a20 | 27962 | |
27963 | int capable(int cap); | |
27964 | +int capable_nolog(int cap); | |
27965 | int __capable(struct task_struct *t, int cap); | |
27966 | ||
4dee9bd5 | 27967 | extern long cap_prctl_drop(unsigned long cap); |
27968 | diff -urNp linux-2.6.25.4/include/linux/elf.h linux-2.6.25.4/include/linux/elf.h | |
27969 | --- linux-2.6.25.4/include/linux/elf.h 2008-05-15 11:00:12.000000000 -0400 | |
27970 | +++ linux-2.6.25.4/include/linux/elf.h 2008-05-18 13:33:17.000000000 -0400 | |
27971 | @@ -9,6 +9,10 @@ | |
50425a20 | 27972 | |
27973 | struct file; | |
27974 | ||
27975 | +#if defined(CONFIG_PAX_PAGEEXEC) || defined(CONFIG_PAX_SEGMEXEC) | |
27976 | +#undef elf_read_implies_exec | |
27977 | +#endif | |
27978 | + | |
27979 | #ifndef elf_read_implies_exec | |
27980 | /* Executables for which elf_read_implies_exec() returns TRUE will | |
27981 | have the READ_IMPLIES_EXEC personality flag set automatically. | |
4dee9bd5 | 27982 | @@ -50,6 +54,16 @@ typedef __s64 Elf64_Sxword; |
50425a20 | 27983 | |
27984 | #define PT_GNU_STACK (PT_LOOS + 0x474e551) | |
27985 | ||
27986 | +#define PT_PAX_FLAGS (PT_LOOS + 0x5041580) | |
27987 | + | |
27988 | +/* Constants for the e_flags field */ | |
27989 | +#define EF_PAX_PAGEEXEC 1 /* Paging based non-executable pages */ | |
27990 | +#define EF_PAX_EMUTRAMP 2 /* Emulate trampolines */ | |
27991 | +#define EF_PAX_MPROTECT 4 /* Restrict mprotect() */ | |
27992 | +#define EF_PAX_RANDMMAP 8 /* Randomize mmap() base */ | |
27993 | +/*#define EF_PAX_RANDEXEC 16*/ /* Randomize ET_EXEC base */ | |
27994 | +#define EF_PAX_SEGMEXEC 32 /* Segmentation based non-executable pages */ | |
27995 | + | |
27996 | /* These constants define the different elf file types */ | |
27997 | #define ET_NONE 0 | |
27998 | #define ET_REL 1 | |
4dee9bd5 | 27999 | @@ -84,6 +98,8 @@ typedef __s64 Elf64_Sxword; |
50425a20 | 28000 | #define DT_DEBUG 21 |
28001 | #define DT_TEXTREL 22 | |
28002 | #define DT_JMPREL 23 | |
28003 | +#define DT_FLAGS 30 | |
8a4b4a5e | 28004 | + #define DF_TEXTREL 0x00000004 |
28005 | #define DT_ENCODING 32 | |
28006 | #define OLD_DT_LOOS 0x60000000 | |
28007 | #define DT_LOOS 0x6000000d | |
4dee9bd5 | 28008 | @@ -230,6 +246,19 @@ typedef struct elf64_hdr { |
50425a20 | 28009 | #define PF_W 0x2 |
28010 | #define PF_X 0x1 | |
28011 | ||
28012 | +#define PF_PAGEEXEC (1U << 4) /* Enable PAGEEXEC */ | |
28013 | +#define PF_NOPAGEEXEC (1U << 5) /* Disable PAGEEXEC */ | |
28014 | +#define PF_SEGMEXEC (1U << 6) /* Enable SEGMEXEC */ | |
28015 | +#define PF_NOSEGMEXEC (1U << 7) /* Disable SEGMEXEC */ | |
28016 | +#define PF_MPROTECT (1U << 8) /* Enable MPROTECT */ | |
28017 | +#define PF_NOMPROTECT (1U << 9) /* Disable MPROTECT */ | |
28018 | +/*#define PF_RANDEXEC (1U << 10)*/ /* Enable RANDEXEC */ | |
28019 | +/*#define PF_NORANDEXEC (1U << 11)*/ /* Disable RANDEXEC */ | |
28020 | +#define PF_EMUTRAMP (1U << 12) /* Enable EMUTRAMP */ | |
28021 | +#define PF_NOEMUTRAMP (1U << 13) /* Disable EMUTRAMP */ | |
28022 | +#define PF_RANDMMAP (1U << 14) /* Enable RANDMMAP */ | |
28023 | +#define PF_NORANDMMAP (1U << 15) /* Disable RANDMMAP */ | |
28024 | + | |
28025 | typedef struct elf32_phdr{ | |
28026 | Elf32_Word p_type; | |
28027 | Elf32_Off p_offset; | |
4dee9bd5 | 28028 | @@ -322,6 +351,8 @@ typedef struct elf64_shdr { |
50425a20 | 28029 | #define EI_OSABI 7 |
28030 | #define EI_PAD 8 | |
28031 | ||
28032 | +#define EI_PAX 14 | |
28033 | + | |
28034 | #define ELFMAG0 0x7f /* EI_MAG */ | |
28035 | #define ELFMAG1 'E' | |
28036 | #define ELFMAG2 'L' | |
4dee9bd5 | 28037 | @@ -382,6 +413,7 @@ extern Elf32_Dyn _DYNAMIC []; |
50425a20 | 28038 | #define elf_phdr elf32_phdr |
28039 | #define elf_note elf32_note | |
28040 | #define elf_addr_t Elf32_Off | |
28041 | +#define elf_dyn Elf32_Dyn | |
28042 | ||
28043 | #else | |
28044 | ||
4dee9bd5 | 28045 | @@ -390,6 +422,7 @@ extern Elf64_Dyn _DYNAMIC []; |
50425a20 | 28046 | #define elf_phdr elf64_phdr |
28047 | #define elf_note elf64_note | |
28048 | #define elf_addr_t Elf64_Off | |
28049 | +#define elf_dyn Elf64_Dyn | |
28050 | ||
28051 | #endif | |
28052 | ||
4dee9bd5 | 28053 | diff -urNp linux-2.6.25.4/include/linux/ext4_fs_extents.h linux-2.6.25.4/include/linux/ext4_fs_extents.h |
28054 | --- linux-2.6.25.4/include/linux/ext4_fs_extents.h 2008-05-15 11:00:12.000000000 -0400 | |
28055 | +++ linux-2.6.25.4/include/linux/ext4_fs_extents.h 2008-05-18 13:33:17.000000000 -0400 | |
50425a20 | 28056 | @@ -50,7 +50,7 @@ |
28057 | #ifdef EXT_DEBUG | |
28058 | #define ext_debug(a...) printk(a) | |
28059 | #else | |
28060 | -#define ext_debug(a...) | |
28061 | +#define ext_debug(a...) do {} while (0) | |
28062 | #endif | |
28063 | ||
28064 | /* | |
4dee9bd5 | 28065 | diff -urNp linux-2.6.25.4/include/linux/gracl.h linux-2.6.25.4/include/linux/gracl.h |
28066 | --- linux-2.6.25.4/include/linux/gracl.h 1969-12-31 19:00:00.000000000 -0500 | |
28067 | +++ linux-2.6.25.4/include/linux/gracl.h 2008-05-18 13:33:17.000000000 -0400 | |
28068 | @@ -0,0 +1,318 @@ | |
50425a20 | 28069 | +#ifndef GR_ACL_H |
28070 | +#define GR_ACL_H | |
28071 | + | |
28072 | +#include <linux/grdefs.h> | |
28073 | +#include <linux/resource.h> | |
4dee9bd5 | 28074 | +#include <linux/capability.h> |
50425a20 | 28075 | +#include <linux/dcache.h> |
28076 | +#include <asm/resource.h> | |
28077 | + | |
28078 | +/* Major status information */ | |
28079 | + | |
4dee9bd5 | 28080 | +#define GR_VERSION "grsecurity 2.1.12" |
28081 | +#define GRSECURITY_VERSION 0x2112 | |
50425a20 | 28082 | + |
28083 | +enum { | |
28084 | + | |
28085 | + SHUTDOWN = 0, | |
28086 | + ENABLE = 1, | |
28087 | + SPROLE = 2, | |
28088 | + RELOAD = 3, | |
28089 | + SEGVMOD = 4, | |
28090 | + STATUS = 5, | |
28091 | + UNSPROLE = 6, | |
28092 | + PASSSET = 7, | |
28093 | + SPROLEPAM = 8 | |
28094 | +}; | |
28095 | + | |
28096 | +/* Password setup definitions | |
28097 | + * kernel/grhash.c */ | |
28098 | +enum { | |
28099 | + GR_PW_LEN = 128, | |
28100 | + GR_SALT_LEN = 16, | |
28101 | + GR_SHA_LEN = 32, | |
28102 | +}; | |
28103 | + | |
28104 | +enum { | |
28105 | + GR_SPROLE_LEN = 64, | |
28106 | +}; | |
28107 | + | |
28108 | +#define GR_NLIMITS (RLIMIT_LOCKS + 2) | |
28109 | + | |
28110 | +/* Begin Data Structures */ | |
28111 | + | |
28112 | +struct sprole_pw { | |
28113 | + unsigned char *rolename; | |
28114 | + unsigned char salt[GR_SALT_LEN]; | |
28115 | + unsigned char sum[GR_SHA_LEN]; /* 256-bit SHA hash of the password */ | |
28116 | +}; | |
28117 | + | |
28118 | +struct name_entry { | |
28119 | + __u32 key; | |
28120 | + ino_t inode; | |
28121 | + dev_t device; | |
28122 | + char *name; | |
28123 | + __u16 len; | |
da5b3fc8 | 28124 | + __u8 deleted; |
50425a20 | 28125 | + struct name_entry *prev; |
28126 | + struct name_entry *next; | |
28127 | +}; | |
28128 | + | |
28129 | +struct inodev_entry { | |
28130 | + struct name_entry *nentry; | |
28131 | + struct inodev_entry *prev; | |
28132 | + struct inodev_entry *next; | |
28133 | +}; | |
28134 | + | |
28135 | +struct acl_role_db { | |
28136 | + struct acl_role_label **r_hash; | |
28137 | + __u32 r_size; | |
28138 | +}; | |
28139 | + | |
28140 | +struct inodev_db { | |
28141 | + struct inodev_entry **i_hash; | |
28142 | + __u32 i_size; | |
28143 | +}; | |
28144 | + | |
28145 | +struct name_db { | |
28146 | + struct name_entry **n_hash; | |
28147 | + __u32 n_size; | |
28148 | +}; | |
28149 | + | |
28150 | +struct crash_uid { | |
28151 | + uid_t uid; | |
28152 | + unsigned long expires; | |
28153 | +}; | |
28154 | + | |
28155 | +struct gr_hash_struct { | |
28156 | + void **table; | |
28157 | + void **nametable; | |
28158 | + void *first; | |
28159 | + __u32 table_size; | |
28160 | + __u32 used_size; | |
28161 | + int type; | |
28162 | +}; | |
28163 | + | |
28164 | +/* Userspace Grsecurity ACL data structures */ | |
28165 | + | |
28166 | +struct acl_subject_label { | |
28167 | + char *filename; | |
28168 | + ino_t inode; | |
28169 | + dev_t device; | |
28170 | + __u32 mode; | |
4dee9bd5 | 28171 | + kernel_cap_t cap_mask; |
28172 | + kernel_cap_t cap_lower; | |
50425a20 | 28173 | + |
28174 | + struct rlimit res[GR_NLIMITS]; | |
28175 | + __u16 resmask; | |
28176 | + | |
28177 | + __u8 user_trans_type; | |
28178 | + __u8 group_trans_type; | |
28179 | + uid_t *user_transitions; | |
28180 | + gid_t *group_transitions; | |
28181 | + __u16 user_trans_num; | |
28182 | + __u16 group_trans_num; | |
28183 | + | |
28184 | + __u32 ip_proto[8]; | |
28185 | + __u32 ip_type; | |
28186 | + struct acl_ip_label **ips; | |
28187 | + __u32 ip_num; | |
28188 | + | |
28189 | + __u32 crashes; | |
28190 | + unsigned long expires; | |
28191 | + | |
28192 | + struct acl_subject_label *parent_subject; | |
28193 | + struct gr_hash_struct *hash; | |
28194 | + struct acl_subject_label *prev; | |
28195 | + struct acl_subject_label *next; | |
28196 | + | |
28197 | + struct acl_object_label **obj_hash; | |
28198 | + __u32 obj_hash_size; | |
28199 | + __u16 pax_flags; | |
28200 | +}; | |
28201 | + | |
28202 | +struct role_allowed_ip { | |
28203 | + __u32 addr; | |
28204 | + __u32 netmask; | |
28205 | + | |
28206 | + struct role_allowed_ip *prev; | |
28207 | + struct role_allowed_ip *next; | |
28208 | +}; | |
28209 | + | |
28210 | +struct role_transition { | |
28211 | + char *rolename; | |
28212 | + | |
28213 | + struct role_transition *prev; | |
28214 | + struct role_transition *next; | |
28215 | +}; | |
28216 | + | |
28217 | +struct acl_role_label { | |
28218 | + char *rolename; | |
28219 | + uid_t uidgid; | |
28220 | + __u16 roletype; | |
28221 | + | |
28222 | + __u16 auth_attempts; | |
28223 | + unsigned long expires; | |
28224 | + | |
28225 | + struct acl_subject_label *root_label; | |
28226 | + struct gr_hash_struct *hash; | |
28227 | + | |
28228 | + struct acl_role_label *prev; | |
28229 | + struct acl_role_label *next; | |
28230 | + | |
28231 | + struct role_transition *transitions; | |
28232 | + struct role_allowed_ip *allowed_ips; | |
28233 | + uid_t *domain_children; | |
28234 | + __u16 domain_child_num; | |
28235 | + | |
28236 | + struct acl_subject_label **subj_hash; | |
28237 | + __u32 subj_hash_size; | |
28238 | +}; | |
28239 | + | |
28240 | +struct user_acl_role_db { | |
28241 | + struct acl_role_label **r_table; | |
28242 | + __u32 num_pointers; /* Number of allocations to track */ | |
28243 | + __u32 num_roles; /* Number of roles */ | |
28244 | + __u32 num_domain_children; /* Number of domain children */ | |
28245 | + __u32 num_subjects; /* Number of subjects */ | |
28246 | + __u32 num_objects; /* Number of objects */ | |
28247 | +}; | |
28248 | + | |
28249 | +struct acl_object_label { | |
28250 | + char *filename; | |
28251 | + ino_t inode; | |
28252 | + dev_t device; | |
28253 | + __u32 mode; | |
28254 | + | |
28255 | + struct acl_subject_label *nested; | |
28256 | + struct acl_object_label *globbed; | |
28257 | + | |
28258 | + /* next two structures not used */ | |
28259 | + | |
28260 | + struct acl_object_label *prev; | |
28261 | + struct acl_object_label *next; | |
28262 | +}; | |
28263 | + | |
28264 | +struct acl_ip_label { | |
28265 | + char *iface; | |
28266 | + __u32 addr; | |
28267 | + __u32 netmask; | |
28268 | + __u16 low, high; | |
28269 | + __u8 mode; | |
28270 | + __u32 type; | |
28271 | + __u32 proto[8]; | |
28272 | + | |
28273 | + /* next two structures not used */ | |
28274 | + | |
28275 | + struct acl_ip_label *prev; | |
28276 | + struct acl_ip_label *next; | |
28277 | +}; | |
28278 | + | |
28279 | +struct gr_arg { | |
28280 | + struct user_acl_role_db role_db; | |
28281 | + unsigned char pw[GR_PW_LEN]; | |
28282 | + unsigned char salt[GR_SALT_LEN]; | |
28283 | + unsigned char sum[GR_SHA_LEN]; | |
28284 | + unsigned char sp_role[GR_SPROLE_LEN]; | |
28285 | + struct sprole_pw *sprole_pws; | |
28286 | + dev_t segv_device; | |
28287 | + ino_t segv_inode; | |
28288 | + uid_t segv_uid; | |
28289 | + __u16 num_sprole_pws; | |
28290 | + __u16 mode; | |
28291 | +}; | |
28292 | + | |
28293 | +struct gr_arg_wrapper { | |
28294 | + struct gr_arg *arg; | |
28295 | + __u32 version; | |
28296 | + __u32 size; | |
28297 | +}; | |
28298 | + | |
28299 | +struct subject_map { | |
28300 | + struct acl_subject_label *user; | |
28301 | + struct acl_subject_label *kernel; | |
28302 | + struct subject_map *prev; | |
28303 | + struct subject_map *next; | |
28304 | +}; | |
28305 | + | |
28306 | +struct acl_subj_map_db { | |
28307 | + struct subject_map **s_hash; | |
28308 | + __u32 s_size; | |
28309 | +}; | |
28310 | + | |
28311 | +/* End Data Structures Section */ | |
28312 | + | |
28313 | +/* Hash functions generated by empirical testing by Brad Spengler | |
28314 | + Makes good use of the low bits of the inode. Generally 0-1 times | |
28315 | + in loop for successful match. 0-3 for unsuccessful match. | |
28316 | + Shift/add algorithm with modulus of table size and an XOR*/ | |
28317 | + | |
28318 | +static __inline__ unsigned int | |
28319 | +rhash(const uid_t uid, const __u16 type, const unsigned int sz) | |
28320 | +{ | |
28321 | + return (((uid << type) + (uid ^ type)) % sz); | |
28322 | +} | |
28323 | + | |
28324 | + static __inline__ unsigned int | |
28325 | +shash(const struct acl_subject_label *userp, const unsigned int sz) | |
28326 | +{ | |
28327 | + return ((const unsigned long)userp % sz); | |
28328 | +} | |
28329 | + | |
28330 | +static __inline__ unsigned int | |
28331 | +fhash(const ino_t ino, const dev_t dev, const unsigned int sz) | |
28332 | +{ | |
28333 | + return (((ino + dev) ^ ((ino << 13) + (ino << 23) + (dev << 9))) % sz); | |
28334 | +} | |
28335 | + | |
28336 | +static __inline__ unsigned int | |
28337 | +nhash(const char *name, const __u16 len, const unsigned int sz) | |
28338 | +{ | |
28339 | + return full_name_hash(name, len) % sz; | |
28340 | +} | |
28341 | + | |
28342 | +#define FOR_EACH_ROLE_START(role,iter) \ | |
28343 | + role = NULL; \ | |
28344 | + iter = 0; \ | |
28345 | + while (iter < acl_role_set.r_size) { \ | |
28346 | + if (role == NULL) \ | |
28347 | + role = acl_role_set.r_hash[iter]; \ | |
28348 | + if (role == NULL) { \ | |
28349 | + iter++; \ | |
28350 | + continue; \ | |
28351 | + } | |
28352 | + | |
28353 | +#define FOR_EACH_ROLE_END(role,iter) \ | |
28354 | + role = role->next; \ | |
28355 | + if (role == NULL) \ | |
28356 | + iter++; \ | |
28357 | + } | |
28358 | + | |
28359 | +#define FOR_EACH_SUBJECT_START(role,subj,iter) \ | |
28360 | + subj = NULL; \ | |
28361 | + iter = 0; \ | |
28362 | + while (iter < role->subj_hash_size) { \ | |
28363 | + if (subj == NULL) \ | |
28364 | + subj = role->subj_hash[iter]; \ | |
28365 | + if (subj == NULL) { \ | |
28366 | + iter++; \ | |
28367 | + continue; \ | |
28368 | + } | |
28369 | + | |
28370 | +#define FOR_EACH_SUBJECT_END(subj,iter) \ | |
28371 | + subj = subj->next; \ | |
28372 | + if (subj == NULL) \ | |
28373 | + iter++; \ | |
28374 | + } | |
28375 | + | |
28376 | + | |
28377 | +#define FOR_EACH_NESTED_SUBJECT_START(role,subj) \ | |
28378 | + subj = role->hash->first; \ | |
28379 | + while (subj != NULL) { | |
28380 | + | |
28381 | +#define FOR_EACH_NESTED_SUBJECT_END(subj) \ | |
28382 | + subj = subj->next; \ | |
28383 | + } | |
28384 | + | |
28385 | +#endif | |
28386 | + | |
4dee9bd5 | 28387 | diff -urNp linux-2.6.25.4/include/linux/gralloc.h linux-2.6.25.4/include/linux/gralloc.h |
28388 | --- linux-2.6.25.4/include/linux/gralloc.h 1969-12-31 19:00:00.000000000 -0500 | |
28389 | +++ linux-2.6.25.4/include/linux/gralloc.h 2008-05-18 13:33:17.000000000 -0400 | |
50425a20 | 28390 | @@ -0,0 +1,8 @@ |
28391 | +#ifndef __GRALLOC_H | |
28392 | +#define __GRALLOC_H | |
28393 | + | |
28394 | +void acl_free_all(void); | |
28395 | +int acl_alloc_stack_init(unsigned long size); | |
28396 | +void *acl_alloc(unsigned long len); | |
28397 | + | |
28398 | +#endif | |
4dee9bd5 | 28399 | diff -urNp linux-2.6.25.4/include/linux/grdefs.h linux-2.6.25.4/include/linux/grdefs.h |
28400 | --- linux-2.6.25.4/include/linux/grdefs.h 1969-12-31 19:00:00.000000000 -0500 | |
28401 | +++ linux-2.6.25.4/include/linux/grdefs.h 2008-05-18 13:33:17.000000000 -0400 | |
50425a20 | 28402 | @@ -0,0 +1,131 @@ |
28403 | +#ifndef GRDEFS_H | |
28404 | +#define GRDEFS_H | |
28405 | + | |
28406 | +/* Begin grsecurity status declarations */ | |
28407 | + | |
28408 | +enum { | |
28409 | + GR_READY = 0x01, | |
28410 | + GR_STATUS_INIT = 0x00 // disabled state | |
28411 | +}; | |
28412 | + | |
28413 | +/* Begin ACL declarations */ | |
28414 | + | |
28415 | +/* Role flags */ | |
28416 | + | |
28417 | +enum { | |
28418 | + GR_ROLE_USER = 0x0001, | |
28419 | + GR_ROLE_GROUP = 0x0002, | |
28420 | + GR_ROLE_DEFAULT = 0x0004, | |
28421 | + GR_ROLE_SPECIAL = 0x0008, | |
28422 | + GR_ROLE_AUTH = 0x0010, | |
28423 | + GR_ROLE_NOPW = 0x0020, | |
28424 | + GR_ROLE_GOD = 0x0040, | |
28425 | + GR_ROLE_LEARN = 0x0080, | |
28426 | + GR_ROLE_TPE = 0x0100, | |
28427 | + GR_ROLE_DOMAIN = 0x0200, | |
28428 | + GR_ROLE_PAM = 0x0400 | |
28429 | +}; | |
28430 | + | |
28431 | +/* ACL Subject and Object mode flags */ | |
28432 | +enum { | |
28433 | + GR_DELETED = 0x80000000 | |
28434 | +}; | |
28435 | + | |
28436 | +/* ACL Object-only mode flags */ | |
28437 | +enum { | |
28438 | + GR_READ = 0x00000001, | |
28439 | + GR_APPEND = 0x00000002, | |
28440 | + GR_WRITE = 0x00000004, | |
28441 | + GR_EXEC = 0x00000008, | |
28442 | + GR_FIND = 0x00000010, | |
28443 | + GR_INHERIT = 0x00000020, | |
28444 | + GR_SETID = 0x00000040, | |
28445 | + GR_CREATE = 0x00000080, | |
28446 | + GR_DELETE = 0x00000100, | |
28447 | + GR_LINK = 0x00000200, | |
28448 | + GR_AUDIT_READ = 0x00000400, | |
28449 | + GR_AUDIT_APPEND = 0x00000800, | |
28450 | + GR_AUDIT_WRITE = 0x00001000, | |
28451 | + GR_AUDIT_EXEC = 0x00002000, | |
28452 | + GR_AUDIT_FIND = 0x00004000, | |
28453 | + GR_AUDIT_INHERIT= 0x00008000, | |
28454 | + GR_AUDIT_SETID = 0x00010000, | |
28455 | + GR_AUDIT_CREATE = 0x00020000, | |
28456 | + GR_AUDIT_DELETE = 0x00040000, | |
28457 | + GR_AUDIT_LINK = 0x00080000, | |
28458 | + GR_PTRACERD = 0x00100000, | |
28459 | + GR_NOPTRACE = 0x00200000, | |
28460 | + GR_SUPPRESS = 0x00400000, | |
28461 | + GR_NOLEARN = 0x00800000 | |
28462 | +}; | |
28463 | + | |
28464 | +#define GR_AUDITS (GR_AUDIT_READ | GR_AUDIT_WRITE | GR_AUDIT_APPEND | GR_AUDIT_EXEC | \ | |
28465 | + GR_AUDIT_FIND | GR_AUDIT_INHERIT | GR_AUDIT_SETID | \ | |
28466 | + GR_AUDIT_CREATE | GR_AUDIT_DELETE | GR_AUDIT_LINK) | |
28467 | + | |
28468 | +/* ACL subject-only mode flags */ | |
28469 | +enum { | |
28470 | + GR_KILL = 0x00000001, | |
28471 | + GR_VIEW = 0x00000002, | |
28472 | + GR_PROTECTED = 0x00000004, | |
28473 | + GR_LEARN = 0x00000008, | |
28474 | + GR_OVERRIDE = 0x00000010, | |
28475 | + /* just a placeholder, this mode is only used in userspace */ | |
28476 | + GR_DUMMY = 0x00000020, | |
28477 | + GR_PROTSHM = 0x00000040, | |
28478 | + GR_KILLPROC = 0x00000080, | |
28479 | + GR_KILLIPPROC = 0x00000100, | |
28480 | + /* just a placeholder, this mode is only used in userspace */ | |
28481 | + GR_NOTROJAN = 0x00000200, | |
28482 | + GR_PROTPROCFD = 0x00000400, | |
28483 | + GR_PROCACCT = 0x00000800, | |
28484 | + GR_RELAXPTRACE = 0x00001000, | |
28485 | + GR_NESTED = 0x00002000, | |
28486 | + GR_INHERITLEARN = 0x00004000, | |
28487 | + GR_PROCFIND = 0x00008000, | |
28488 | + GR_POVERRIDE = 0x00010000, | |
28489 | + GR_KERNELAUTH = 0x00020000, | |
28490 | +}; | |
28491 | + | |
28492 | +enum { | |
28493 | + GR_PAX_ENABLE_SEGMEXEC = 0x0001, | |
28494 | + GR_PAX_ENABLE_PAGEEXEC = 0x0002, | |
28495 | + GR_PAX_ENABLE_MPROTECT = 0x0004, | |
28496 | + GR_PAX_ENABLE_RANDMMAP = 0x0008, | |
28497 | + GR_PAX_ENABLE_EMUTRAMP = 0x0010, | |
28498 | + GR_PAX_DISABLE_SEGMEXEC = 0x0100, | |
28499 | + GR_PAX_DISABLE_PAGEEXEC = 0x0200, | |
28500 | + GR_PAX_DISABLE_MPROTECT = 0x0400, | |
28501 | + GR_PAX_DISABLE_RANDMMAP = 0x0800, | |
28502 | + GR_PAX_DISABLE_EMUTRAMP = 0x1000, | |
28503 | +}; | |
28504 | + | |
28505 | +enum { | |
28506 | + GR_ID_USER = 0x01, | |
28507 | + GR_ID_GROUP = 0x02, | |
28508 | +}; | |
28509 | + | |
28510 | +enum { | |
28511 | + GR_ID_ALLOW = 0x01, | |
28512 | + GR_ID_DENY = 0x02, | |
28513 | +}; | |
28514 | + | |
28515 | +#define GR_CRASH_RES 11 | |
28516 | +#define GR_UIDTABLE_MAX 500 | |
28517 | + | |
28518 | +/* begin resource learning section */ | |
28519 | +enum { | |
28520 | + GR_RLIM_CPU_BUMP = 60, | |
28521 | + GR_RLIM_FSIZE_BUMP = 50000, | |
28522 | + GR_RLIM_DATA_BUMP = 10000, | |
28523 | + GR_RLIM_STACK_BUMP = 1000, | |
28524 | + GR_RLIM_CORE_BUMP = 10000, | |
28525 | + GR_RLIM_RSS_BUMP = 500000, | |
28526 | + GR_RLIM_NPROC_BUMP = 1, | |
28527 | + GR_RLIM_NOFILE_BUMP = 5, | |
28528 | + GR_RLIM_MEMLOCK_BUMP = 50000, | |
28529 | + GR_RLIM_AS_BUMP = 500000, | |
28530 | + GR_RLIM_LOCKS_BUMP = 2 | |
28531 | +}; | |
28532 | + | |
28533 | +#endif | |
4dee9bd5 | 28534 | diff -urNp linux-2.6.25.4/include/linux/grinternal.h linux-2.6.25.4/include/linux/grinternal.h |
28535 | --- linux-2.6.25.4/include/linux/grinternal.h 1969-12-31 19:00:00.000000000 -0500 | |
28536 | +++ linux-2.6.25.4/include/linux/grinternal.h 2008-05-18 13:33:17.000000000 -0400 | |
78fdc4fb | 28537 | @@ -0,0 +1,210 @@ |
50425a20 | 28538 | +#ifndef __GRINTERNAL_H |
28539 | +#define __GRINTERNAL_H | |
28540 | + | |
28541 | +#ifdef CONFIG_GRKERNSEC | |
28542 | + | |
28543 | +#include <linux/fs.h> | |
28544 | +#include <linux/gracl.h> | |
28545 | +#include <linux/grdefs.h> | |
28546 | +#include <linux/grmsg.h> | |
28547 | + | |
28548 | +void gr_add_learn_entry(const char *fmt, ...); | |
28549 | +__u32 gr_search_file(const struct dentry *dentry, const __u32 mode, | |
28550 | + const struct vfsmount *mnt); | |
28551 | +__u32 gr_check_create(const struct dentry *new_dentry, | |
28552 | + const struct dentry *parent, | |
28553 | + const struct vfsmount *mnt, const __u32 mode); | |
28554 | +int gr_check_protected_task(const struct task_struct *task); | |
28555 | +__u32 to_gr_audit(const __u32 reqmode); | |
28556 | +int gr_set_acls(const int type); | |
28557 | + | |
28558 | +int gr_acl_is_enabled(void); | |
28559 | +char gr_roletype_to_char(void); | |
28560 | + | |
28561 | +void gr_handle_alertkill(struct task_struct *task); | |
28562 | +char *gr_to_filename(const struct dentry *dentry, | |
28563 | + const struct vfsmount *mnt); | |
28564 | +char *gr_to_filename1(const struct dentry *dentry, | |
28565 | + const struct vfsmount *mnt); | |
28566 | +char *gr_to_filename2(const struct dentry *dentry, | |
28567 | + const struct vfsmount *mnt); | |
28568 | +char *gr_to_filename3(const struct dentry *dentry, | |
28569 | + const struct vfsmount *mnt); | |
28570 | + | |
28571 | +extern int grsec_enable_link; | |
28572 | +extern int grsec_enable_fifo; | |
28573 | +extern int grsec_enable_execve; | |
28574 | +extern int grsec_enable_shm; | |
28575 | +extern int grsec_enable_execlog; | |
28576 | +extern int grsec_enable_signal; | |
28577 | +extern int grsec_enable_forkfail; | |
28578 | +extern int grsec_enable_time; | |
28579 | +extern int grsec_enable_chroot_shmat; | |
28580 | +extern int grsec_enable_chroot_findtask; | |
28581 | +extern int grsec_enable_chroot_mount; | |
28582 | +extern int grsec_enable_chroot_double; | |
28583 | +extern int grsec_enable_chroot_pivot; | |
28584 | +extern int grsec_enable_chroot_chdir; | |
28585 | +extern int grsec_enable_chroot_chmod; | |
28586 | +extern int grsec_enable_chroot_mknod; | |
28587 | +extern int grsec_enable_chroot_fchdir; | |
28588 | +extern int grsec_enable_chroot_nice; | |
28589 | +extern int grsec_enable_chroot_execlog; | |
28590 | +extern int grsec_enable_chroot_caps; | |
28591 | +extern int grsec_enable_chroot_sysctl; | |
28592 | +extern int grsec_enable_chroot_unix; | |
28593 | +extern int grsec_enable_tpe; | |
28594 | +extern int grsec_tpe_gid; | |
28595 | +extern int grsec_enable_tpe_all; | |
28596 | +extern int grsec_enable_sidcaps; | |
28597 | +extern int grsec_enable_socket_all; | |
28598 | +extern int grsec_socket_all_gid; | |
28599 | +extern int grsec_enable_socket_client; | |
28600 | +extern int grsec_socket_client_gid; | |
28601 | +extern int grsec_enable_socket_server; | |
28602 | +extern int grsec_socket_server_gid; | |
28603 | +extern int grsec_audit_gid; | |
28604 | +extern int grsec_enable_group; | |
28605 | +extern int grsec_enable_audit_ipc; | |
28606 | +extern int grsec_enable_audit_textrel; | |
28607 | +extern int grsec_enable_mount; | |
28608 | +extern int grsec_enable_chdir; | |
28609 | +extern int grsec_resource_logging; | |
28610 | +extern int grsec_lock; | |
28611 | + | |
28612 | +extern spinlock_t grsec_alert_lock; | |
28613 | +extern unsigned long grsec_alert_wtime; | |
28614 | +extern unsigned long grsec_alert_fyet; | |
28615 | + | |
28616 | +extern spinlock_t grsec_audit_lock; | |
28617 | + | |
28618 | +extern rwlock_t grsec_exec_file_lock; | |
28619 | + | |
28620 | +#define gr_task_fullpath(tsk) (tsk->exec_file ? \ | |
4dee9bd5 | 28621 | + gr_to_filename2(tsk->exec_file->f_path.dentry, \ |
50425a20 | 28622 | + tsk->exec_file->f_vfsmnt) : "/") |
28623 | + | |
28624 | +#define gr_parent_task_fullpath(tsk) (tsk->parent->exec_file ? \ | |
4dee9bd5 | 28625 | + gr_to_filename3(tsk->parent->exec_file->f_path.dentry, \ |
50425a20 | 28626 | + tsk->parent->exec_file->f_vfsmnt) : "/") |
28627 | + | |
28628 | +#define gr_task_fullpath0(tsk) (tsk->exec_file ? \ | |
4dee9bd5 | 28629 | + gr_to_filename(tsk->exec_file->f_path.dentry, \ |
50425a20 | 28630 | + tsk->exec_file->f_vfsmnt) : "/") |
28631 | + | |
28632 | +#define gr_parent_task_fullpath0(tsk) (tsk->parent->exec_file ? \ | |
4dee9bd5 | 28633 | + gr_to_filename1(tsk->parent->exec_file->f_path.dentry, \ |
50425a20 | 28634 | + tsk->parent->exec_file->f_vfsmnt) : "/") |
28635 | + | |
28636 | +#define proc_is_chrooted(tsk_a) ((tsk_a->pid > 1) && (tsk_a->fs != NULL) && \ | |
4dee9bd5 | 28637 | + ((tsk_a->fs->root.dentry->d_inode->i_sb->s_dev != \ |
28638 | + tsk_a->nsproxy->pid_ns->child_reaper->fs->root.dentry->d_inode->i_sb->s_dev) || \ | |
28639 | + (tsk_a->fs->root.dentry->d_inode->i_ino != \ | |
28640 | + tsk_a->nsproxy->pid_ns->child_reaper->fs->root.dentry->d_inode->i_ino))) | |
50425a20 | 28641 | + |
28642 | +#define have_same_root(tsk_a,tsk_b) ((tsk_a->fs != NULL) && (tsk_b->fs != NULL) && \ | |
4dee9bd5 | 28643 | + (tsk_a->fs->root.dentry->d_inode->i_sb->s_dev == \ |
28644 | + tsk_b->fs->root.dentry->d_inode->i_sb->s_dev) && \ | |
28645 | + (tsk_a->fs->root.dentry->d_inode->i_ino == \ | |
28646 | + tsk_b->fs->root.dentry->d_inode->i_ino)) | |
50425a20 | 28647 | + |
28648 | +#define DEFAULTSECARGS(task) gr_task_fullpath(task), task->comm, \ | |
28649 | + task->pid, task->uid, \ | |
28650 | + task->euid, task->gid, task->egid, \ | |
28651 | + gr_parent_task_fullpath(task), \ | |
28652 | + task->parent->comm, task->parent->pid, \ | |
28653 | + task->parent->uid, task->parent->euid, \ | |
28654 | + task->parent->gid, task->parent->egid | |
28655 | + | |
4dee9bd5 | 28656 | +#define GR_CHROOT_CAPS {{ \ |
50425a20 | 28657 | + CAP_TO_MASK(CAP_LINUX_IMMUTABLE) | CAP_TO_MASK(CAP_NET_ADMIN) | \ |
28658 | + CAP_TO_MASK(CAP_SYS_MODULE) | CAP_TO_MASK(CAP_SYS_RAWIO) | \ | |
28659 | + CAP_TO_MASK(CAP_SYS_PACCT) | CAP_TO_MASK(CAP_SYS_ADMIN) | \ | |
28660 | + CAP_TO_MASK(CAP_SYS_BOOT) | CAP_TO_MASK(CAP_SYS_TIME) | \ | |
28661 | + CAP_TO_MASK(CAP_NET_RAW) | CAP_TO_MASK(CAP_SYS_TTY_CONFIG) | \ | |
4dee9bd5 | 28662 | + CAP_TO_MASK(CAP_IPC_OWNER) , 0 }} |
50425a20 | 28663 | + |
28664 | +#define security_learn(normal_msg,args...) \ | |
28665 | +({ \ | |
28666 | + read_lock(&grsec_exec_file_lock); \ | |
28667 | + gr_add_learn_entry(normal_msg "\n", ## args); \ | |
28668 | + read_unlock(&grsec_exec_file_lock); \ | |
28669 | +}) | |
28670 | + | |
28671 | +enum { | |
28672 | + GR_DO_AUDIT, | |
28673 | + GR_DONT_AUDIT, | |
28674 | + GR_DONT_AUDIT_GOOD | |
28675 | +}; | |
28676 | + | |
28677 | +enum { | |
28678 | + GR_TTYSNIFF, | |
28679 | + GR_RBAC, | |
28680 | + GR_RBAC_STR, | |
28681 | + GR_STR_RBAC, | |
28682 | + GR_RBAC_MODE2, | |
28683 | + GR_RBAC_MODE3, | |
28684 | + GR_FILENAME, | |
78fdc4fb | 28685 | + GR_SYSCTL_HIDDEN, |
50425a20 | 28686 | + GR_NOARGS, |
28687 | + GR_ONE_INT, | |
28688 | + GR_ONE_INT_TWO_STR, | |
28689 | + GR_ONE_STR, | |
28690 | + GR_STR_INT, | |
28691 | + GR_TWO_INT, | |
28692 | + GR_THREE_INT, | |
28693 | + GR_FIVE_INT_TWO_STR, | |
28694 | + GR_TWO_STR, | |
28695 | + GR_THREE_STR, | |
28696 | + GR_FOUR_STR, | |
28697 | + GR_STR_FILENAME, | |
28698 | + GR_FILENAME_STR, | |
28699 | + GR_FILENAME_TWO_INT, | |
28700 | + GR_FILENAME_TWO_INT_STR, | |
28701 | + GR_TEXTREL, | |
28702 | + GR_PTRACE, | |
28703 | + GR_RESOURCE, | |
28704 | + GR_CAP, | |
28705 | + GR_SIG, | |
28706 | + GR_CRASH1, | |
28707 | + GR_CRASH2, | |
28708 | + GR_PSACCT | |
28709 | +}; | |
28710 | + | |
78fdc4fb | 28711 | +#define gr_log_hidden_sysctl(audit, msg, str) gr_log_varargs(audit, msg, GR_SYSCTL_HIDDEN, str) |
50425a20 | 28712 | +#define gr_log_ttysniff(audit, msg, task) gr_log_varargs(audit, msg, GR_TTYSNIFF, task) |
28713 | +#define gr_log_fs_rbac_generic(audit, msg, dentry, mnt) gr_log_varargs(audit, msg, GR_RBAC, dentry, mnt) | |
28714 | +#define gr_log_fs_rbac_str(audit, msg, dentry, mnt, str) gr_log_varargs(audit, msg, GR_RBAC_STR, dentry, mnt, str) | |
28715 | +#define gr_log_fs_str_rbac(audit, msg, str, dentry, mnt) gr_log_varargs(audit, msg, GR_STR_RBAC, str, dentry, mnt) | |
28716 | +#define gr_log_fs_rbac_mode2(audit, msg, dentry, mnt, str1, str2) gr_log_varargs(audit, msg, GR_RBAC_MODE2, dentry, mnt, str1, str2) | |
28717 | +#define gr_log_fs_rbac_mode3(audit, msg, dentry, mnt, str1, str2, str3) gr_log_varargs(audit, msg, GR_RBAC_MODE3, dentry, mnt, str1, str2, str3) | |
28718 | +#define gr_log_fs_generic(audit, msg, dentry, mnt) gr_log_varargs(audit, msg, GR_FILENAME, dentry, mnt) | |
28719 | +#define gr_log_noargs(audit, msg) gr_log_varargs(audit, msg, GR_NOARGS) | |
28720 | +#define gr_log_int(audit, msg, num) gr_log_varargs(audit, msg, GR_ONE_INT, num) | |
28721 | +#define gr_log_int_str2(audit, msg, num, str1, str2) gr_log_varargs(audit, msg, GR_ONE_INT_TWO_STR, num, str1, str2) | |
28722 | +#define gr_log_str(audit, msg, str) gr_log_varargs(audit, msg, GR_ONE_STR, str) | |
28723 | +#define gr_log_str_int(audit, msg, str, num) gr_log_varargs(audit, msg, GR_STR_INT, str, num) | |
28724 | +#define gr_log_int_int(audit, msg, num1, num2) gr_log_varargs(audit, msg, GR_TWO_INT, num1, num2) | |
28725 | +#define gr_log_int3(audit, msg, num1, num2, num3) gr_log_varargs(audit, msg, GR_THREE_INT, num1, num2, num3) | |
28726 | +#define gr_log_int5_str2(audit, msg, num1, num2, str1, str2) gr_log_varargs(audit, msg, GR_FIVE_INT_TWO_STR, num1, num2, str1, str2) | |
28727 | +#define gr_log_str_str(audit, msg, str1, str2) gr_log_varargs(audit, msg, GR_TWO_STR, str1, str2) | |
28728 | +#define gr_log_str3(audit, msg, str1, str2, str3) gr_log_varargs(audit, msg, GR_THREE_STR, str1, str2, str3) | |
28729 | +#define gr_log_str4(audit, msg, str1, str2, str3, str4) gr_log_varargs(audit, msg, GR_FOUR_STR, str1, str2, str3, str4) | |
28730 | +#define gr_log_str_fs(audit, msg, str, dentry, mnt) gr_log_varargs(audit, msg, GR_STR_FILENAME, str, dentry, mnt) | |
28731 | +#define gr_log_fs_str(audit, msg, dentry, mnt, str) gr_log_varargs(audit, msg, GR_FILENAME_STR, dentry, mnt, str) | |
28732 | +#define gr_log_fs_int2(audit, msg, dentry, mnt, num1, num2) gr_log_varargs(audit, msg, GR_FILENAME_TWO_INT, dentry, mnt, num1, num2) | |
28733 | +#define gr_log_fs_int2_str(audit, msg, dentry, mnt, num1, num2, str) gr_log_varargs(audit, msg, GR_FILENAME_TWO_INT_STR, dentry, mnt, num1, num2, str) | |
28734 | +#define gr_log_textrel_ulong_ulong(audit, msg, file, ulong1, ulong2) gr_log_varargs(audit, msg, GR_TEXTREL, file, ulong1, ulong2) | |
28735 | +#define gr_log_ptrace(audit, msg, task) gr_log_varargs(audit, msg, GR_PTRACE, task) | |
28736 | +#define gr_log_res_ulong2_str(audit, msg, task, ulong1, str, ulong2) gr_log_varargs(audit, msg, GR_RESOURCE, task, ulong1, str, ulong2) | |
28737 | +#define gr_log_cap(audit, msg, task, str) gr_log_varargs(audit, msg, GR_CAP, task, str) | |
28738 | +#define gr_log_sig(audit, msg, task, num) gr_log_varargs(audit, msg, GR_SIG, task, num) | |
28739 | +#define gr_log_crash1(audit, msg, task, ulong) gr_log_varargs(audit, msg, GR_CRASH1, task, ulong) | |
28740 | +#define gr_log_crash2(audit, msg, task, ulong1) gr_log_varargs(audit, msg, GR_CRASH2, task, ulong1) | |
28741 | +#define gr_log_procacct(audit, msg, task, num1, num2, num3, num4, num5, num6, num7, num8, num9) gr_log_varargs(audit, msg, GR_PSACCT, task, num1, num2, num3, num4, num5, num6, num7, num8, num9) | |
28742 | + | |
28743 | +void gr_log_varargs(int audit, const char *msg, int argtypes, ...); | |
28744 | + | |
28745 | +#endif | |
28746 | + | |
28747 | +#endif | |
4dee9bd5 | 28748 | diff -urNp linux-2.6.25.4/include/linux/grmsg.h linux-2.6.25.4/include/linux/grmsg.h |
28749 | --- linux-2.6.25.4/include/linux/grmsg.h 1969-12-31 19:00:00.000000000 -0500 | |
28750 | +++ linux-2.6.25.4/include/linux/grmsg.h 2008-05-18 13:33:17.000000000 -0400 | |
50425a20 | 28751 | @@ -0,0 +1,108 @@ |
28752 | +#define DEFAULTSECMSG "%.256s[%.16s:%d] uid/euid:%u/%u gid/egid:%u/%u, parent %.256s[%.16s:%d] uid/euid:%u/%u gid/egid:%u/%u" | |
28753 | +#define GR_ACL_PROCACCT_MSG "%.256s[%.16s:%d] IP:%u.%u.%u.%u TTY:%.64s uid/euid:%u/%u gid/egid:%u/%u run time:[%ud %uh %um %us] cpu time:[%ud %uh %um %us] %s with exit code %ld, parent %.256s[%.16s:%d] IP:%u.%u.%u.%u TTY:%.64s uid/euid:%u/%u gid/egid:%u/%u" | |
28754 | +#define GR_PTRACE_ACL_MSG "denied ptrace of %.950s(%.16s:%d) by " | |
28755 | +#define GR_STOPMOD_MSG "denied modification of module state by " | |
28756 | +#define GR_IOPERM_MSG "denied use of ioperm() by " | |
28757 | +#define GR_IOPL_MSG "denied use of iopl() by " | |
28758 | +#define GR_SHMAT_ACL_MSG "denied attach of shared memory of UID %u, PID %d, ID %u by " | |
28759 | +#define GR_UNIX_CHROOT_MSG "denied connect() to abstract AF_UNIX socket outside of chroot by " | |
28760 | +#define GR_SHMAT_CHROOT_MSG "denied attach of shared memory outside of chroot by " | |
28761 | +#define GR_KMEM_MSG "denied write of /dev/kmem by " | |
28762 | +#define GR_PORT_OPEN_MSG "denied open of /dev/port by " | |
28763 | +#define GR_MEM_WRITE_MSG "denied write of /dev/mem by " | |
28764 | +#define GR_MEM_MMAP_MSG "denied mmap write of /dev/[k]mem by " | |
28765 | +#define GR_SYMLINK_MSG "not following symlink %.950s owned by %d.%d by " | |
28766 | +#define GR_LEARN_AUDIT_MSG "%s\t%u\t%u\t%u\t%.4095s\t%.4095s\t%lu\t%lu\t%.4095s\t%lu\t%u.%u.%u.%u" | |
28767 | +#define GR_ID_LEARN_MSG "%s\t%u\t%u\t%u\t%.4095s\t%.4095s\t%c\t%d\t%d\t%d\t%u.%u.%u.%u" | |
28768 | +#define GR_HIDDEN_ACL_MSG "%s access to hidden file %.950s by " | |
28769 | +#define GR_OPEN_ACL_MSG "%s open of %.950s for%s%s by " | |
28770 | +#define GR_CREATE_ACL_MSG "%s create of %.950s for%s%s by " | |
28771 | +#define GR_FIFO_MSG "denied writing FIFO %.950s of %d.%d by " | |
28772 | +#define GR_MKNOD_CHROOT_MSG "denied mknod of %.950s from chroot by " | |
28773 | +#define GR_MKNOD_ACL_MSG "%s mknod of %.950s by " | |
28774 | +#define GR_UNIXCONNECT_ACL_MSG "%s connect() to the unix domain socket %.950s by " | |
28775 | +#define GR_TTYSNIFF_ACL_MSG "terminal being sniffed by IP:%u.%u.%u.%u %.480s[%.16s:%d], parent %.480s[%.16s:%d] against " | |
28776 | +#define GR_MKDIR_ACL_MSG "%s mkdir of %.950s by " | |
28777 | +#define GR_RMDIR_ACL_MSG "%s rmdir of %.950s by " | |
28778 | +#define GR_UNLINK_ACL_MSG "%s unlink of %.950s by " | |
28779 | +#define GR_SYMLINK_ACL_MSG "%s symlink from %.480s to %.480s by " | |
28780 | +#define GR_HARDLINK_MSG "denied hardlink of %.930s (owned by %d.%d) to %.30s for " | |
28781 | +#define GR_LINK_ACL_MSG "%s link of %.480s to %.480s by " | |
28782 | +#define GR_INHERIT_ACL_MSG "successful inherit of %.480s's ACL for %.480s by " | |
28783 | +#define GR_RENAME_ACL_MSG "%s rename of %.480s to %.480s by " | |
28784 | +#define GR_PTRACE_EXEC_ACL_MSG "denied ptrace of %.950s by " | |
28785 | +#define GR_NPROC_MSG "denied overstep of process limit by " | |
28786 | +#define GR_EXEC_ACL_MSG "%s execution of %.950s by " | |
28787 | +#define GR_EXEC_TPE_MSG "denied untrusted exec of %.950s by " | |
28788 | +#define GR_SEGVSTART_ACL_MSG "possible exploit bruteforcing on " DEFAULTSECMSG " banning uid %u from login for %lu seconds" | |
28789 | +#define GR_SEGVNOSUID_ACL_MSG "possible exploit bruteforcing on " DEFAULTSECMSG " banning execution for %lu seconds" | |
28790 | +#define GR_MOUNT_CHROOT_MSG "denied mount of %.30s as %.930s from chroot by " | |
28791 | +#define GR_PIVOT_CHROOT_MSG "denied pivot_root from chroot by " | |
28792 | +#define GR_TRUNCATE_ACL_MSG "%s truncate of %.950s by " | |
28793 | +#define GR_ATIME_ACL_MSG "%s access time change of %.950s by " | |
28794 | +#define GR_ACCESS_ACL_MSG "%s access of %.950s for%s%s%s by " | |
28795 | +#define GR_CHROOT_CHROOT_MSG "denied double chroot to %.950s by " | |
28796 | +#define GR_FCHMOD_ACL_MSG "%s fchmod of %.950s by " | |
28797 | +#define GR_CHMOD_CHROOT_MSG "denied chmod +s of %.950s by " | |
28798 | +#define GR_CHMOD_ACL_MSG "%s chmod of %.950s by " | |
28799 | +#define GR_CHROOT_FCHDIR_MSG "denied fchdir outside of chroot to %.950s by " | |
28800 | +#define GR_CHOWN_ACL_MSG "%s chown of %.950s by " | |
28801 | +#define GR_WRITLIB_ACL_MSG "denied load of writable library %.950s by " | |
28802 | +#define GR_INITF_ACL_MSG "init_variables() failed %s by " | |
28803 | +#define GR_DISABLED_ACL_MSG "Error loading %s, trying to run kernel with acls disabled. To disable acls at startup use <kernel image name> gracl=off from your boot loader" | |
28804 | +#define GR_DEV_ACL_MSG "/dev/grsec: %d bytes sent %d required, being fed garbaged by " | |
28805 | +#define GR_SHUTS_ACL_MSG "shutdown auth success for " | |
28806 | +#define GR_SHUTF_ACL_MSG "shutdown auth failure for " | |
28807 | +#define GR_SHUTI_ACL_MSG "ignoring shutdown for disabled RBAC system for " | |
28808 | +#define GR_SEGVMODS_ACL_MSG "segvmod auth success for " | |
28809 | +#define GR_SEGVMODF_ACL_MSG "segvmod auth failure for " | |
28810 | +#define GR_SEGVMODI_ACL_MSG "ignoring segvmod for disabled RBAC system for " | |
28811 | +#define GR_ENABLE_ACL_MSG "%s RBAC system loaded by " | |
28812 | +#define GR_ENABLEF_ACL_MSG "unable to load %s for " | |
28813 | +#define GR_RELOADI_ACL_MSG "ignoring reload request for disabled RBAC system" | |
28814 | +#define GR_RELOAD_ACL_MSG "%s RBAC system reloaded by " | |
28815 | +#define GR_RELOADF_ACL_MSG "failed reload of %s for " | |
28816 | +#define GR_SPROLEI_ACL_MSG "ignoring change to special role for disabled RBAC system for " | |
28817 | +#define GR_SPROLES_ACL_MSG "successful change to special role %s (id %d) by " | |
28818 | +#define GR_SPROLEL_ACL_MSG "special role %s (id %d) exited by " | |
28819 | +#define GR_SPROLEF_ACL_MSG "special role %s failure for " | |
28820 | +#define GR_UNSPROLEI_ACL_MSG "ignoring unauth of special role for disabled RBAC system for " | |
28821 | +#define GR_UNSPROLES_ACL_MSG "successful unauth of special role %s (id %d) by " | |
28822 | +#define GR_UNSPROLEF_ACL_MSG "special role unauth of %s failure for " | |
28823 | +#define GR_INVMODE_ACL_MSG "invalid mode %d by " | |
28824 | +#define GR_PRIORITY_CHROOT_MSG "denied priority change of process (%.16s:%d) by " | |
28825 | +#define GR_FAILFORK_MSG "failed fork with errno %d by " | |
28826 | +#define GR_NICE_CHROOT_MSG "denied priority change by " | |
28827 | +#define GR_UNISIGLOG_MSG "signal %d sent to " | |
28828 | +#define GR_DUALSIGLOG_MSG "signal %d sent to " DEFAULTSECMSG " by " | |
28829 | +#define GR_SIG_ACL_MSG "denied send of signal %d to protected task " DEFAULTSECMSG " by " | |
28830 | +#define GR_SYSCTL_MSG "denied modification of grsecurity sysctl value : %.32s by " | |
28831 | +#define GR_SYSCTL_ACL_MSG "%s sysctl of %.950s for%s%s by " | |
28832 | +#define GR_TIME_MSG "time set by " | |
28833 | +#define GR_DEFACL_MSG "fatal: unable to find subject for (%.16s:%d), loaded by " | |
28834 | +#define GR_MMAP_ACL_MSG "%s executable mmap of %.950s by " | |
28835 | +#define GR_MPROTECT_ACL_MSG "%s executable mprotect of %.950s by " | |
28836 | +#define GR_SOCK_MSG "denied socket(%.16s,%.16s,%.16s) by " | |
28837 | +#define GR_SOCK2_MSG "denied socket(%d,%.16s,%.16s) by " | |
28838 | +#define GR_BIND_MSG "denied bind() by " | |
28839 | +#define GR_CONNECT_MSG "denied connect() by " | |
28840 | +#define GR_BIND_ACL_MSG "denied bind() to %u.%u.%u.%u port %u sock type %.16s protocol %.16s by " | |
28841 | +#define GR_CONNECT_ACL_MSG "denied connect() to %u.%u.%u.%u port %u sock type %.16s protocol %.16s by " | |
28842 | +#define GR_IP_LEARN_MSG "%s\t%u\t%u\t%u\t%.4095s\t%.4095s\t%u.%u.%u.%u\t%u\t%u\t%u\t%u\t%u.%u.%u.%u" | |
28843 | +#define GR_EXEC_CHROOT_MSG "exec of %.980s within chroot by process " | |
28844 | +#define GR_CAP_ACL_MSG "use of %s denied for " | |
28845 | +#define GR_USRCHANGE_ACL_MSG "change to uid %u denied for " | |
28846 | +#define GR_GRPCHANGE_ACL_MSG "change to gid %u denied for " | |
28847 | +#define GR_REMOUNT_AUDIT_MSG "remount of %.30s by " | |
28848 | +#define GR_UNMOUNT_AUDIT_MSG "unmount of %.30s by " | |
28849 | +#define GR_MOUNT_AUDIT_MSG "mount of %.30s to %.64s by " | |
28850 | +#define GR_CHDIR_AUDIT_MSG "chdir to %.980s by " | |
28851 | +#define GR_EXEC_AUDIT_MSG "exec of %.930s (%.128s) by " | |
28852 | +#define GR_MSGQ_AUDIT_MSG "message queue created by " | |
28853 | +#define GR_MSGQR_AUDIT_MSG "message queue of uid:%u euid:%u removed by " | |
28854 | +#define GR_SEM_AUDIT_MSG "semaphore created by " | |
28855 | +#define GR_SEMR_AUDIT_MSG "semaphore of uid:%u euid:%u removed by " | |
28856 | +#define GR_SHM_AUDIT_MSG "shared memory of size %d created by " | |
28857 | +#define GR_SHMR_AUDIT_MSG "shared memory of uid:%u euid:%u removed by " | |
28858 | +#define GR_RESOURCE_MSG "denied resource overstep by requesting %lu for %.16s against limit %lu for " | |
28859 | +#define GR_TEXTREL_AUDIT_MSG "text relocation in %s, VMA:0x%08lx 0x%08lx by " | |
4dee9bd5 | 28860 | diff -urNp linux-2.6.25.4/include/linux/grsecurity.h linux-2.6.25.4/include/linux/grsecurity.h |
28861 | --- linux-2.6.25.4/include/linux/grsecurity.h 1969-12-31 19:00:00.000000000 -0500 | |
28862 | +++ linux-2.6.25.4/include/linux/grsecurity.h 2008-05-18 13:33:17.000000000 -0400 | |
b2ee8b1e | 28863 | @@ -0,0 +1,197 @@ |
50425a20 | 28864 | +#ifndef GR_SECURITY_H |
28865 | +#define GR_SECURITY_H | |
28866 | +#include <linux/fs.h> | |
28867 | +#include <linux/binfmts.h> | |
28868 | +#include <linux/gracl.h> | |
28869 | + | |
b2ee8b1e | 28870 | +/* notify of brain-dead configs */ |
28871 | +#if defined(CONFIG_PAX_NOEXEC) && !defined(CONFIG_PAX_PAGEEXEC) && !defined(CONFIG_PAX_SEGMEXEC) | |
28872 | +#error "CONFIG_PAX_NOEXEC enabled, but neither PAGEEXEC nor SEGMEXEC are enabled." | |
28873 | +#endif | |
28874 | +#if defined(CONFIG_PAX_NOEXEC) && !defined(CONFIG_PAX_EI_PAX) && !defined(CONFIG_PAX_PT_PAX_FLAGS) | |
28875 | +#error "CONFIG_PAX_NOEXEC enabled, but neither CONFIG_PAX_EI_PAX nor CONFIG_PAX_PT_PAX_FLAGS are enabled." | |
28876 | +#endif | |
28877 | +#if defined(CONFIG_PAX_ASLR) && !defined(CONFIG_PAX_RANDKSTACK) && !defined(CONFIG_PAX_RANDUSTACK) && !defined(CONFIG_PAX_RANDMMAP) | |
28878 | +#error "CONFIG_PAX_ASLR enabled, but RANDKSTACK, RANDUSTACK, and RANDMMAP are disabled." | |
28879 | +#endif | |
28880 | +#if defined(CONFIG_PAX) && !defined(CONFIG_PAX_NOEXEC) && !defined(CONFIG_PAX_ASLR) | |
28881 | +#error "CONFIG_PAX enabled, but no PaX options are enabled." | |
28882 | +#endif | |
28883 | + | |
50425a20 | 28884 | +void gr_handle_brute_attach(struct task_struct *p); |
28885 | +void gr_handle_brute_check(void); | |
28886 | + | |
28887 | +char gr_roletype_to_char(void); | |
28888 | + | |
28889 | +int gr_check_user_change(int real, int effective, int fs); | |
28890 | +int gr_check_group_change(int real, int effective, int fs); | |
28891 | + | |
28892 | +void gr_del_task_from_ip_table(struct task_struct *p); | |
28893 | + | |
28894 | +int gr_pid_is_chrooted(struct task_struct *p); | |
28895 | +int gr_handle_chroot_nice(void); | |
28896 | +int gr_handle_chroot_sysctl(const int op); | |
28897 | +int gr_handle_chroot_setpriority(struct task_struct *p, | |
28898 | + const int niceval); | |
28899 | +int gr_chroot_fchdir(struct dentry *u_dentry, struct vfsmount *u_mnt); | |
28900 | +int gr_handle_chroot_chroot(const struct dentry *dentry, | |
28901 | + const struct vfsmount *mnt); | |
28902 | +void gr_handle_chroot_caps(struct task_struct *task); | |
4dee9bd5 | 28903 | +void gr_handle_chroot_chdir(struct path *path); |
50425a20 | 28904 | +int gr_handle_chroot_chmod(const struct dentry *dentry, |
28905 | + const struct vfsmount *mnt, const int mode); | |
28906 | +int gr_handle_chroot_mknod(const struct dentry *dentry, | |
28907 | + const struct vfsmount *mnt, const int mode); | |
28908 | +int gr_handle_chroot_mount(const struct dentry *dentry, | |
28909 | + const struct vfsmount *mnt, | |
28910 | + const char *dev_name); | |
28911 | +int gr_handle_chroot_pivot(void); | |
28912 | +int gr_handle_chroot_unix(const pid_t pid); | |
28913 | + | |
28914 | +int gr_handle_rawio(const struct inode *inode); | |
28915 | +int gr_handle_nproc(void); | |
28916 | + | |
28917 | +void gr_handle_ioperm(void); | |
28918 | +void gr_handle_iopl(void); | |
28919 | + | |
28920 | +int gr_tpe_allow(const struct file *file); | |
28921 | + | |
28922 | +int gr_random_pid(void); | |
28923 | + | |
28924 | +void gr_log_forkfail(const int retval); | |
28925 | +void gr_log_timechange(void); | |
28926 | +void gr_log_signal(const int sig, const struct task_struct *t); | |
28927 | +void gr_log_chdir(const struct dentry *dentry, | |
28928 | + const struct vfsmount *mnt); | |
28929 | +void gr_log_chroot_exec(const struct dentry *dentry, | |
28930 | + const struct vfsmount *mnt); | |
28931 | +void gr_handle_exec_args(struct linux_binprm *bprm, char **argv); | |
28932 | +void gr_log_remount(const char *devname, const int retval); | |
28933 | +void gr_log_unmount(const char *devname, const int retval); | |
28934 | +void gr_log_mount(const char *from, const char *to, const int retval); | |
28935 | +void gr_log_msgget(const int ret, const int msgflg); | |
28936 | +void gr_log_msgrm(const uid_t uid, const uid_t cuid); | |
28937 | +void gr_log_semget(const int err, const int semflg); | |
28938 | +void gr_log_semrm(const uid_t uid, const uid_t cuid); | |
28939 | +void gr_log_shmget(const int err, const int shmflg, const size_t size); | |
28940 | +void gr_log_shmrm(const uid_t uid, const uid_t cuid); | |
28941 | +void gr_log_textrel(struct vm_area_struct *vma); | |
28942 | + | |
28943 | +int gr_handle_follow_link(const struct inode *parent, | |
28944 | + const struct inode *inode, | |
28945 | + const struct dentry *dentry, | |
28946 | + const struct vfsmount *mnt); | |
28947 | +int gr_handle_fifo(const struct dentry *dentry, | |
28948 | + const struct vfsmount *mnt, | |
28949 | + const struct dentry *dir, const int flag, | |
28950 | + const int acc_mode); | |
28951 | +int gr_handle_hardlink(const struct dentry *dentry, | |
28952 | + const struct vfsmount *mnt, | |
28953 | + struct inode *inode, | |
28954 | + const int mode, const char *to); | |
28955 | + | |
28956 | +int gr_task_is_capable(struct task_struct *task, const int cap); | |
28957 | +int gr_is_capable_nolog(const int cap); | |
28958 | +void gr_learn_resource(const struct task_struct *task, const int limit, | |
28959 | + const unsigned long wanted, const int gt); | |
28960 | +void gr_copy_label(struct task_struct *tsk); | |
28961 | +void gr_handle_crash(struct task_struct *task, const int sig); | |
28962 | +int gr_handle_signal(const struct task_struct *p, const int sig); | |
28963 | +int gr_check_crash_uid(const uid_t uid); | |
28964 | +int gr_check_protected_task(const struct task_struct *task); | |
28965 | +int gr_acl_handle_mmap(const struct file *file, | |
28966 | + const unsigned long prot); | |
28967 | +int gr_acl_handle_mprotect(const struct file *file, | |
28968 | + const unsigned long prot); | |
28969 | +int gr_check_hidden_task(const struct task_struct *tsk); | |
28970 | +__u32 gr_acl_handle_truncate(const struct dentry *dentry, | |
28971 | + const struct vfsmount *mnt); | |
28972 | +__u32 gr_acl_handle_utime(const struct dentry *dentry, | |
28973 | + const struct vfsmount *mnt); | |
28974 | +__u32 gr_acl_handle_access(const struct dentry *dentry, | |
28975 | + const struct vfsmount *mnt, const int fmode); | |
28976 | +__u32 gr_acl_handle_fchmod(const struct dentry *dentry, | |
28977 | + const struct vfsmount *mnt, mode_t mode); | |
28978 | +__u32 gr_acl_handle_chmod(const struct dentry *dentry, | |
28979 | + const struct vfsmount *mnt, mode_t mode); | |
28980 | +__u32 gr_acl_handle_chown(const struct dentry *dentry, | |
28981 | + const struct vfsmount *mnt); | |
28982 | +int gr_handle_ptrace(struct task_struct *task, const long request); | |
28983 | +int gr_handle_proc_ptrace(struct task_struct *task); | |
28984 | +__u32 gr_acl_handle_execve(const struct dentry *dentry, | |
28985 | + const struct vfsmount *mnt); | |
28986 | +int gr_check_crash_exec(const struct file *filp); | |
28987 | +int gr_acl_is_enabled(void); | |
28988 | +void gr_set_kernel_label(struct task_struct *task); | |
28989 | +void gr_set_role_label(struct task_struct *task, const uid_t uid, | |
28990 | + const gid_t gid); | |
28991 | +int gr_set_proc_label(const struct dentry *dentry, | |
28992 | + const struct vfsmount *mnt); | |
28993 | +__u32 gr_acl_handle_hidden_file(const struct dentry *dentry, | |
28994 | + const struct vfsmount *mnt); | |
28995 | +__u32 gr_acl_handle_open(const struct dentry *dentry, | |
28996 | + const struct vfsmount *mnt, const int fmode); | |
28997 | +__u32 gr_acl_handle_creat(const struct dentry *dentry, | |
28998 | + const struct dentry *p_dentry, | |
28999 | + const struct vfsmount *p_mnt, const int fmode, | |
29000 | + const int imode); | |
29001 | +void gr_handle_create(const struct dentry *dentry, | |
29002 | + const struct vfsmount *mnt); | |
29003 | +__u32 gr_acl_handle_mknod(const struct dentry *new_dentry, | |
29004 | + const struct dentry *parent_dentry, | |
29005 | + const struct vfsmount *parent_mnt, | |
29006 | + const int mode); | |
29007 | +__u32 gr_acl_handle_mkdir(const struct dentry *new_dentry, | |
29008 | + const struct dentry *parent_dentry, | |
29009 | + const struct vfsmount *parent_mnt); | |
29010 | +__u32 gr_acl_handle_rmdir(const struct dentry *dentry, | |
29011 | + const struct vfsmount *mnt); | |
29012 | +void gr_handle_delete(const ino_t ino, const dev_t dev); | |
29013 | +__u32 gr_acl_handle_unlink(const struct dentry *dentry, | |
29014 | + const struct vfsmount *mnt); | |
29015 | +__u32 gr_acl_handle_symlink(const struct dentry *new_dentry, | |
29016 | + const struct dentry *parent_dentry, | |
29017 | + const struct vfsmount *parent_mnt, | |
29018 | + const char *from); | |
29019 | +__u32 gr_acl_handle_link(const struct dentry *new_dentry, | |
29020 | + const struct dentry *parent_dentry, | |
29021 | + const struct vfsmount *parent_mnt, | |
29022 | + const struct dentry *old_dentry, | |
29023 | + const struct vfsmount *old_mnt, const char *to); | |
29024 | +int gr_acl_handle_rename(struct dentry *new_dentry, | |
29025 | + struct dentry *parent_dentry, | |
29026 | + const struct vfsmount *parent_mnt, | |
29027 | + struct dentry *old_dentry, | |
29028 | + struct inode *old_parent_inode, | |
29029 | + struct vfsmount *old_mnt, const char *newname); | |
29030 | +void gr_handle_rename(struct inode *old_dir, struct inode *new_dir, | |
29031 | + struct dentry *old_dentry, | |
29032 | + struct dentry *new_dentry, | |
29033 | + struct vfsmount *mnt, const __u8 replace); | |
29034 | +__u32 gr_check_link(const struct dentry *new_dentry, | |
29035 | + const struct dentry *parent_dentry, | |
29036 | + const struct vfsmount *parent_mnt, | |
29037 | + const struct dentry *old_dentry, | |
29038 | + const struct vfsmount *old_mnt); | |
29039 | +int gr_acl_handle_filldir(const struct file *file, const char *name, | |
29040 | + const unsigned int namelen, const ino_t ino); | |
29041 | + | |
29042 | +__u32 gr_acl_handle_unix(const struct dentry *dentry, | |
29043 | + const struct vfsmount *mnt); | |
29044 | +void gr_acl_handle_exit(void); | |
29045 | +void gr_acl_handle_psacct(struct task_struct *task, const long code); | |
29046 | +int gr_acl_handle_procpidmem(const struct task_struct *task); | |
50425a20 | 29047 | + |
50425a20 | 29048 | +#ifdef CONFIG_GRKERNSEC |
29049 | +void gr_handle_mem_write(void); | |
29050 | +void gr_handle_kmem_write(void); | |
29051 | +void gr_handle_open_port(void); | |
29052 | +int gr_handle_mem_mmap(const unsigned long offset, | |
29053 | + struct vm_area_struct *vma); | |
29054 | + | |
50425a20 | 29055 | +extern int grsec_enable_dmesg; |
29056 | +extern int grsec_enable_randsrc; | |
29057 | +extern int grsec_enable_shm; | |
29058 | +#endif | |
29059 | + | |
29060 | +#endif | |
4dee9bd5 | 29061 | diff -urNp linux-2.6.25.4/include/linux/highmem.h linux-2.6.25.4/include/linux/highmem.h |
29062 | --- linux-2.6.25.4/include/linux/highmem.h 2008-05-15 11:00:12.000000000 -0400 | |
29063 | +++ linux-2.6.25.4/include/linux/highmem.h 2008-05-18 13:33:17.000000000 -0400 | |
29064 | @@ -122,6 +122,13 @@ static inline void clear_highpage(struct | |
50425a20 | 29065 | kunmap_atomic(kaddr, KM_USER0); |
29066 | } | |
29067 | ||
29068 | +static inline void sanitize_highpage(struct page *page) | |
29069 | +{ | |
29070 | + void *kaddr = kmap_atomic(page, KM_CLEARPAGE); | |
29071 | + clear_page(kaddr); | |
29072 | + kunmap_atomic(kaddr, KM_CLEARPAGE); | |
29073 | +} | |
29074 | + | |
4dee9bd5 | 29075 | static inline void zero_user_segments(struct page *page, |
29076 | unsigned start1, unsigned end1, | |
29077 | unsigned start2, unsigned end2) | |
29078 | diff -urNp linux-2.6.25.4/include/linux/irqflags.h linux-2.6.25.4/include/linux/irqflags.h | |
29079 | --- linux-2.6.25.4/include/linux/irqflags.h 2008-05-15 11:00:12.000000000 -0400 | |
29080 | +++ linux-2.6.25.4/include/linux/irqflags.h 2008-05-18 13:33:17.000000000 -0400 | |
8a4b4a5e | 29081 | @@ -84,10 +84,10 @@ |
29082 | ||
29083 | #define irqs_disabled() \ | |
29084 | ({ \ | |
29085 | - unsigned long flags; \ | |
29086 | + unsigned long __flags; \ | |
29087 | \ | |
29088 | - raw_local_save_flags(flags); \ | |
29089 | - raw_irqs_disabled_flags(flags); \ | |
29090 | + raw_local_save_flags(__flags); \ | |
29091 | + raw_irqs_disabled_flags(__flags); \ | |
29092 | }) | |
29093 | ||
29094 | #define irqs_disabled_flags(flags) raw_irqs_disabled_flags(flags) | |
4dee9bd5 | 29095 | diff -urNp linux-2.6.25.4/include/linux/jbd2.h linux-2.6.25.4/include/linux/jbd2.h |
29096 | --- linux-2.6.25.4/include/linux/jbd2.h 2008-05-15 11:00:12.000000000 -0400 | |
29097 | +++ linux-2.6.25.4/include/linux/jbd2.h 2008-05-18 13:33:17.000000000 -0400 | |
da5b3fc8 | 29098 | @@ -68,7 +68,7 @@ extern u8 jbd2_journal_enable_debug; |
50425a20 | 29099 | } \ |
29100 | } while (0) | |
29101 | #else | |
29102 | -#define jbd_debug(f, a...) /**/ | |
29103 | +#define jbd_debug(f, a...) do {} while (0) | |
29104 | #endif | |
29105 | ||
da5b3fc8 | 29106 | static inline void *jbd2_alloc(size_t size, gfp_t flags) |
4dee9bd5 | 29107 | diff -urNp linux-2.6.25.4/include/linux/jbd.h linux-2.6.25.4/include/linux/jbd.h |
29108 | --- linux-2.6.25.4/include/linux/jbd.h 2008-05-15 11:00:12.000000000 -0400 | |
29109 | +++ linux-2.6.25.4/include/linux/jbd.h 2008-05-18 13:33:17.000000000 -0400 | |
29110 | @@ -68,7 +68,7 @@ extern u8 journal_enable_debug; | |
50425a20 | 29111 | } \ |
29112 | } while (0) | |
29113 | #else | |
29114 | -#define jbd_debug(f, a...) /**/ | |
29115 | +#define jbd_debug(f, a...) do {} while (0) | |
29116 | #endif | |
29117 | ||
da5b3fc8 | 29118 | static inline void *jbd_alloc(size_t size, gfp_t flags) |
4dee9bd5 | 29119 | diff -urNp linux-2.6.25.4/include/linux/libata.h linux-2.6.25.4/include/linux/libata.h |
29120 | --- linux-2.6.25.4/include/linux/libata.h 2008-05-15 11:00:12.000000000 -0400 | |
29121 | +++ linux-2.6.25.4/include/linux/libata.h 2008-05-18 13:33:17.000000000 -0400 | |
29122 | @@ -63,11 +63,11 @@ | |
8a4b4a5e | 29123 | #ifdef ATA_VERBOSE_DEBUG |
29124 | #define VPRINTK(fmt, args...) printk(KERN_ERR "%s: " fmt, __FUNCTION__, ## args) | |
29125 | #else | |
29126 | -#define VPRINTK(fmt, args...) | |
29127 | +#define VPRINTK(fmt, args...) do {} while (0) | |
29128 | #endif /* ATA_VERBOSE_DEBUG */ | |
29129 | #else | |
29130 | -#define DPRINTK(fmt, args...) | |
29131 | -#define VPRINTK(fmt, args...) | |
29132 | +#define DPRINTK(fmt, args...) do {} while (0) | |
29133 | +#define VPRINTK(fmt, args...) do {} while (0) | |
29134 | #endif /* ATA_DEBUG */ | |
29135 | ||
29136 | #define BPRINTK(fmt, args...) if (ap->flags & ATA_FLAG_DEBUGMSG) printk(KERN_ERR "%s: " fmt, __FUNCTION__, ## args) | |
4dee9bd5 | 29137 | diff -urNp linux-2.6.25.4/include/linux/mm.h linux-2.6.25.4/include/linux/mm.h |
29138 | --- linux-2.6.25.4/include/linux/mm.h 2008-05-15 11:00:12.000000000 -0400 | |
29139 | +++ linux-2.6.25.4/include/linux/mm.h 2008-05-18 13:33:17.000000000 -0400 | |
29140 | @@ -38,6 +38,7 @@ extern unsigned long mmap_min_addr; | |
50425a20 | 29141 | #include <asm/page.h> |
29142 | #include <asm/pgtable.h> | |
29143 | #include <asm/processor.h> | |
29144 | +#include <asm/mman.h> | |
29145 | ||
29146 | #define nth_page(page,n) pfn_to_page(page_to_pfn((page)) + (n)) | |
29147 | ||
4dee9bd5 | 29148 | @@ -108,6 +109,14 @@ extern unsigned int kobjsize(const void |
50425a20 | 29149 | |
da5b3fc8 | 29150 | #define VM_CAN_NONLINEAR 0x08000000 /* Has ->fault & does nonlinear pages */ |
50425a20 | 29151 | |
8a4b4a5e | 29152 | +#ifdef CONFIG_PAX_PAGEEXEC |
da5b3fc8 | 29153 | +#define VM_PAGEEXEC 0x10000000 /* vma->vm_page_prot needs special handling */ |
50425a20 | 29154 | +#endif |
29155 | + | |
29156 | +#ifdef CONFIG_PAX_MPROTECT | |
da5b3fc8 | 29157 | +#define VM_MAYNOTWRITE 0x20000000 /* vma cannot be granted VM_WRITE any more */ |
50425a20 | 29158 | +#endif |
50425a20 | 29159 | + |
29160 | #ifndef VM_STACK_DEFAULT_FLAGS /* arch can override this */ | |
29161 | #define VM_STACK_DEFAULT_FLAGS VM_DATA_DEFAULT_FLAGS | |
29162 | #endif | |
4dee9bd5 | 29163 | @@ -836,6 +845,8 @@ struct shrinker { |
da5b3fc8 | 29164 | extern void register_shrinker(struct shrinker *); |
29165 | extern void unregister_shrinker(struct shrinker *); | |
8a4b4a5e | 29166 | |
29167 | +pgprot_t vm_get_page_prot(unsigned long vm_flags); | |
29168 | + | |
da5b3fc8 | 29169 | int vma_wants_writenotify(struct vm_area_struct *vma); |
8a4b4a5e | 29170 | |
4dee9bd5 | 29171 | extern pte_t *get_locked_pte(struct mm_struct *mm, unsigned long addr, spinlock_t **ptl); |
29172 | @@ -1074,6 +1085,7 @@ out: | |
8a4b4a5e | 29173 | } |
29174 | ||
29175 | extern int do_munmap(struct mm_struct *, unsigned long, size_t); | |
29176 | +extern int __do_munmap(struct mm_struct *, unsigned long, size_t); | |
29177 | ||
29178 | extern unsigned long do_brk(unsigned long, unsigned long); | |
29179 | ||
4dee9bd5 | 29180 | @@ -1126,6 +1138,10 @@ extern struct vm_area_struct * find_vma( |
8a4b4a5e | 29181 | extern struct vm_area_struct * find_vma_prev(struct mm_struct * mm, unsigned long addr, |
29182 | struct vm_area_struct **pprev); | |
29183 | ||
29184 | +extern struct vm_area_struct *pax_find_mirror_vma(struct vm_area_struct *vma); | |
29185 | +extern void pax_mirror_vma(struct vm_area_struct *vma_m, struct vm_area_struct *vma); | |
29186 | +extern void pax_mirror_file_pte(struct vm_area_struct *vma, unsigned long address, struct page *page_m, spinlock_t *ptl); | |
29187 | + | |
29188 | /* Look up the first VMA which intersects the interval start_addr..end_addr-1, | |
29189 | NULL if none. Assume start_addr < end_addr. */ | |
29190 | static inline struct vm_area_struct * find_vma_intersection(struct mm_struct * mm, unsigned long start_addr, unsigned long end_addr) | |
4dee9bd5 | 29191 | @@ -1142,7 +1158,6 @@ static inline unsigned long vma_pages(st |
8a4b4a5e | 29192 | return (vma->vm_end - vma->vm_start) >> PAGE_SHIFT; |
50425a20 | 29193 | } |
29194 | ||
8a4b4a5e | 29195 | -pgprot_t vm_get_page_prot(unsigned long vm_flags); |
da5b3fc8 | 29196 | struct vm_area_struct *find_extend_vma(struct mm_struct *, unsigned long addr); |
4dee9bd5 | 29197 | int remap_pfn_range(struct vm_area_struct *, unsigned long addr, |
29198 | unsigned long pfn, unsigned long size, pgprot_t); | |
29199 | @@ -1230,5 +1245,11 @@ int vmemmap_populate_basepages(struct pa | |
da5b3fc8 | 29200 | unsigned long pages, int node); |
29201 | int vmemmap_populate(struct page *start_page, unsigned long pages, int node); | |
50425a20 | 29202 | |
29203 | +#ifdef CONFIG_ARCH_TRACK_EXEC_LIMIT | |
29204 | +extern void track_exec_limit(struct mm_struct *mm, unsigned long start, unsigned long end, unsigned long prot); | |
29205 | +#else | |
29206 | +static inline void track_exec_limit(struct mm_struct *mm, unsigned long start, unsigned long end, unsigned long prot) {} | |
29207 | +#endif | |
29208 | + | |
29209 | #endif /* __KERNEL__ */ | |
29210 | #endif /* _LINUX_MM_H */ | |
4dee9bd5 | 29211 | diff -urNp linux-2.6.25.4/include/linux/mm_types.h linux-2.6.25.4/include/linux/mm_types.h |
29212 | --- linux-2.6.25.4/include/linux/mm_types.h 2008-05-15 11:00:12.000000000 -0400 | |
29213 | +++ linux-2.6.25.4/include/linux/mm_types.h 2008-05-18 13:33:17.000000000 -0400 | |
29214 | @@ -154,6 +154,8 @@ struct vm_area_struct { | |
da5b3fc8 | 29215 | #ifdef CONFIG_NUMA |
29216 | struct mempolicy *vm_policy; /* NUMA policy for the VMA */ | |
29217 | #endif | |
29218 | + | |
29219 | + struct vm_area_struct *vm_mirror;/* PaX: mirror vma or NULL */ | |
29220 | }; | |
29221 | ||
29222 | struct mm_struct { | |
4dee9bd5 | 29223 | @@ -225,6 +227,24 @@ struct mm_struct { |
29224 | #ifdef CONFIG_CGROUP_MEM_RES_CTLR | |
29225 | struct mem_cgroup *mem_cgroup; | |
29226 | #endif | |
da5b3fc8 | 29227 | + |
29228 | +#if defined(CONFIG_PAX_EI_PAX) || defined(CONFIG_PAX_PT_PAX_FLAGS) || defined(CONFIG_PAX_NOEXEC) || defined(CONFIG_PAX_ASLR) | |
29229 | + unsigned long pax_flags; | |
29230 | +#endif | |
29231 | + | |
29232 | +#ifdef CONFIG_PAX_DLRESOLVE | |
29233 | + unsigned long call_dl_resolve; | |
29234 | +#endif | |
29235 | + | |
29236 | +#if defined(CONFIG_PPC32) && defined(CONFIG_PAX_EMUSIGRT) | |
29237 | + unsigned long call_syscall; | |
29238 | +#endif | |
29239 | + | |
29240 | +#ifdef CONFIG_PAX_ASLR | |
29241 | + unsigned long delta_mmap; /* randomized offset */ | |
29242 | + unsigned long delta_stack; /* randomized offset */ | |
29243 | +#endif | |
29244 | + | |
29245 | }; | |
29246 | ||
29247 | #endif /* _LINUX_MM_TYPES_H */ | |
4dee9bd5 | 29248 | diff -urNp linux-2.6.25.4/include/linux/module.h linux-2.6.25.4/include/linux/module.h |
29249 | --- linux-2.6.25.4/include/linux/module.h 2008-05-15 11:00:12.000000000 -0400 | |
29250 | +++ linux-2.6.25.4/include/linux/module.h 2008-05-18 13:33:17.000000000 -0400 | |
50425a20 | 29251 | @@ -296,16 +296,16 @@ struct module |
29252 | int (*init)(void); | |
29253 | ||
29254 | /* If this is non-NULL, vfree after init() returns */ | |
29255 | - void *module_init; | |
29256 | + void *module_init_rx, *module_init_rw; | |
29257 | ||
29258 | /* Here is the actual code + data, vfree'd on unload. */ | |
29259 | - void *module_core; | |
29260 | + void *module_core_rx, *module_core_rw; | |
29261 | ||
29262 | /* Here are the sizes of the init and core sections */ | |
29263 | - unsigned long init_size, core_size; | |
29264 | + unsigned long init_size_rw, core_size_rw; | |
29265 | ||
29266 | /* The size of the executable code in each section. */ | |
29267 | - unsigned long init_text_size, core_text_size; | |
29268 | + unsigned long init_size_rx, core_size_rx; | |
29269 | ||
29270 | /* The handle returned from unwind_add_table. */ | |
29271 | void *unwind_info; | |
4dee9bd5 | 29272 | diff -urNp linux-2.6.25.4/include/linux/moduleloader.h linux-2.6.25.4/include/linux/moduleloader.h |
29273 | --- linux-2.6.25.4/include/linux/moduleloader.h 2008-05-15 11:00:12.000000000 -0400 | |
29274 | +++ linux-2.6.25.4/include/linux/moduleloader.h 2008-05-18 13:33:17.000000000 -0400 | |
50425a20 | 29275 | @@ -17,9 +17,21 @@ int module_frob_arch_sections(Elf_Ehdr * |
29276 | sections. Returns NULL on failure. */ | |
29277 | void *module_alloc(unsigned long size); | |
29278 | ||
29279 | +#ifdef CONFIG_PAX_KERNEXEC | |
29280 | +void *module_alloc_exec(unsigned long size); | |
29281 | +#else | |
29282 | +#define module_alloc_exec(x) module_alloc(x) | |
29283 | +#endif | |
29284 | + | |
29285 | /* Free memory returned from module_alloc. */ | |
29286 | void module_free(struct module *mod, void *module_region); | |
29287 | ||
29288 | +#ifdef CONFIG_PAX_KERNEXEC | |
29289 | +void module_free_exec(struct module *mod, void *module_region); | |
29290 | +#else | |
29291 | +#define module_free_exec(x, y) module_free(x, y) | |
29292 | +#endif | |
29293 | + | |
29294 | /* Apply the given relocation to the (simplified) ELF. Return -error | |
29295 | or 0. */ | |
29296 | int apply_relocate(Elf_Shdr *sechdrs, | |
4dee9bd5 | 29297 | diff -urNp linux-2.6.25.4/include/linux/namei.h linux-2.6.25.4/include/linux/namei.h |
29298 | --- linux-2.6.25.4/include/linux/namei.h 2008-05-15 11:00:12.000000000 -0400 | |
29299 | +++ linux-2.6.25.4/include/linux/namei.h 2008-05-18 13:33:17.000000000 -0400 | |
da5b3fc8 | 29300 | @@ -21,7 +21,7 @@ struct nameidata { |
29301 | unsigned int flags; | |
29302 | int last_type; | |
29303 | unsigned depth; | |
29304 | - char *saved_names[MAX_NESTED_LINKS + 1]; | |
29305 | + const char *saved_names[MAX_NESTED_LINKS + 1]; | |
29306 | ||
29307 | /* Intent data */ | |
29308 | union { | |
4dee9bd5 | 29309 | @@ -83,12 +83,12 @@ extern int follow_up(struct vfsmount **, |
da5b3fc8 | 29310 | extern struct dentry *lock_rename(struct dentry *, struct dentry *); |
29311 | extern void unlock_rename(struct dentry *, struct dentry *); | |
29312 | ||
29313 | -static inline void nd_set_link(struct nameidata *nd, char *path) | |
29314 | +static inline void nd_set_link(struct nameidata *nd, const char *path) | |
29315 | { | |
29316 | nd->saved_names[nd->depth] = path; | |
29317 | } | |
29318 | ||
29319 | -static inline char *nd_get_link(struct nameidata *nd) | |
29320 | +static inline const char *nd_get_link(struct nameidata *nd) | |
29321 | { | |
29322 | return nd->saved_names[nd->depth]; | |
29323 | } | |
4dee9bd5 | 29324 | diff -urNp linux-2.6.25.4/include/linux/percpu.h linux-2.6.25.4/include/linux/percpu.h |
29325 | --- linux-2.6.25.4/include/linux/percpu.h 2008-05-15 11:00:12.000000000 -0400 | |
29326 | +++ linux-2.6.25.4/include/linux/percpu.h 2008-05-18 13:33:17.000000000 -0400 | |
29327 | @@ -38,7 +38,7 @@ | |
8a4b4a5e | 29328 | #endif |
29329 | ||
29330 | #define PERCPU_ENOUGH_ROOM \ | |
29331 | - (__per_cpu_end - __per_cpu_start + PERCPU_MODULE_RESERVE) | |
29332 | + ((unsigned long)(__per_cpu_end - __per_cpu_start + PERCPU_MODULE_RESERVE)) | |
29333 | #endif /* PERCPU_ENOUGH_ROOM */ | |
50425a20 | 29334 | |
8a4b4a5e | 29335 | /* |
4dee9bd5 | 29336 | diff -urNp linux-2.6.25.4/include/linux/poison.h linux-2.6.25.4/include/linux/poison.h |
29337 | --- linux-2.6.25.4/include/linux/poison.h 2008-05-15 11:00:12.000000000 -0400 | |
29338 | +++ linux-2.6.25.4/include/linux/poison.h 2008-05-18 13:33:17.000000000 -0400 | |
da5b3fc8 | 29339 | @@ -7,8 +7,8 @@ |
29340 | * under normal circumstances, used to verify that nobody uses | |
29341 | * non-initialized list entries. | |
29342 | */ | |
29343 | -#define LIST_POISON1 ((void *) 0x00100100) | |
29344 | -#define LIST_POISON2 ((void *) 0x00200200) | |
29345 | +#define LIST_POISON1 ((void *) 0xFF1001FFFF1001FFULL) | |
29346 | +#define LIST_POISON2 ((void *) 0xFF2002FFFF2002FFULL) | |
29347 | ||
29348 | /********** mm/slab.c **********/ | |
29349 | /* | |
4dee9bd5 | 29350 | diff -urNp linux-2.6.25.4/include/linux/random.h linux-2.6.25.4/include/linux/random.h |
29351 | --- linux-2.6.25.4/include/linux/random.h 2008-05-15 11:00:12.000000000 -0400 | |
29352 | +++ linux-2.6.25.4/include/linux/random.h 2008-05-18 13:33:17.000000000 -0400 | |
8a4b4a5e | 29353 | @@ -72,6 +72,11 @@ unsigned long randomize_range(unsigned l |
29354 | u32 random32(void); | |
29355 | void srandom32(u32 seed); | |
29356 | ||
29357 | +static inline unsigned long pax_get_random_long(void) | |
29358 | +{ | |
29359 | + return random32() + (sizeof(long) > 4 ? (unsigned long)random32() << 32 : 0); | |
29360 | +} | |
50425a20 | 29361 | + |
8a4b4a5e | 29362 | #endif /* __KERNEL___ */ |
50425a20 | 29363 | |
8a4b4a5e | 29364 | #endif /* _LINUX_RANDOM_H */ |
4dee9bd5 | 29365 | diff -urNp linux-2.6.25.4/include/linux/sched.h linux-2.6.25.4/include/linux/sched.h |
29366 | --- linux-2.6.25.4/include/linux/sched.h 2008-05-15 11:00:12.000000000 -0400 | |
29367 | +++ linux-2.6.25.4/include/linux/sched.h 2008-05-18 13:33:17.000000000 -0400 | |
29368 | @@ -97,6 +97,7 @@ struct exec_domain; | |
50425a20 | 29369 | struct futex_pi_state; |
4dee9bd5 | 29370 | struct robust_list_head; |
8a4b4a5e | 29371 | struct bio; |
50425a20 | 29372 | +struct linux_binprm; |
29373 | ||
29374 | /* | |
29375 | * List of flags we want to share for kernel threads, | |
4dee9bd5 | 29376 | @@ -542,6 +543,15 @@ struct signal_struct { |
da5b3fc8 | 29377 | unsigned audit_tty; |
29378 | struct tty_audit_buf *tty_audit_buf; | |
50425a20 | 29379 | #endif |
29380 | + | |
29381 | +#ifdef CONFIG_GRKERNSEC | |
29382 | + u32 curr_ip; | |
29383 | + u32 gr_saddr; | |
29384 | + u32 gr_daddr; | |
29385 | + u16 gr_sport; | |
29386 | + u16 gr_dport; | |
29387 | + u8 used_accept:1; | |
29388 | +#endif | |
29389 | }; | |
29390 | ||
29391 | /* Context switch must be unlocked if interrupts are to be enabled */ | |
4dee9bd5 | 29392 | @@ -993,7 +1003,7 @@ struct sched_rt_entity { |
da5b3fc8 | 29393 | |
29394 | struct task_struct { | |
29395 | volatile long state; /* -1 unrunnable, 0 runnable, >0 stopped */ | |
29396 | - void *stack; | |
4dee9bd5 | 29397 | + struct thread_info *stack; |
da5b3fc8 | 29398 | atomic_t usage; |
29399 | unsigned int flags; /* per process flags, defined below */ | |
29400 | unsigned int ptrace; | |
4dee9bd5 | 29401 | @@ -1063,10 +1073,9 @@ struct task_struct { |
da5b3fc8 | 29402 | pid_t pid; |
29403 | pid_t tgid; | |
29404 | ||
29405 | -#ifdef CONFIG_CC_STACKPROTECTOR | |
29406 | /* Canary value for the -fstack-protector gcc feature */ | |
29407 | unsigned long stack_canary; | |
29408 | -#endif | |
29409 | + | |
29410 | /* | |
29411 | * pointers to (original) parent process, youngest child, younger sibling, | |
29412 | * older sibling, respectively. (p->father can be replaced with | |
4dee9bd5 | 29413 | @@ -1087,8 +1096,8 @@ struct task_struct { |
8a4b4a5e | 29414 | struct list_head thread_group; |
29415 | ||
29416 | struct completion *vfork_done; /* for vfork() */ | |
29417 | - int __user *set_child_tid; /* CLONE_CHILD_SETTID */ | |
29418 | - int __user *clear_child_tid; /* CLONE_CHILD_CLEARTID */ | |
29419 | + pid_t __user *set_child_tid; /* CLONE_CHILD_SETTID */ | |
29420 | + pid_t __user *clear_child_tid; /* CLONE_CHILD_CLEARTID */ | |
29421 | ||
29422 | unsigned int rt_priority; | |
da5b3fc8 | 29423 | cputime_t utime, stime, utimescaled, stimescaled; |
4dee9bd5 | 29424 | @@ -1271,8 +1280,60 @@ struct task_struct { |
29425 | int latency_record_count; | |
29426 | struct latency_record latency_record[LT_SAVECOUNT]; | |
da5b3fc8 | 29427 | #endif |
da5b3fc8 | 29428 | + |
50425a20 | 29429 | +#ifdef CONFIG_GRKERNSEC |
29430 | + /* grsecurity */ | |
29431 | + struct acl_subject_label *acl; | |
29432 | + struct acl_role_label *role; | |
29433 | + struct file *exec_file; | |
29434 | + u16 acl_role_id; | |
da5b3fc8 | 29435 | + u8 acl_sp_role; |
29436 | + u8 is_writable; | |
29437 | + u8 brute; | |
50425a20 | 29438 | +#endif |
29439 | + | |
8a4b4a5e | 29440 | }; |
29441 | ||
29442 | +#define MF_PAX_PAGEEXEC 0x01000000 /* Paging based non-executable pages */ | |
29443 | +#define MF_PAX_EMUTRAMP 0x02000000 /* Emulate trampolines */ | |
29444 | +#define MF_PAX_MPROTECT 0x04000000 /* Restrict mprotect() */ | |
29445 | +#define MF_PAX_RANDMMAP 0x08000000 /* Randomize mmap() base */ | |
29446 | +/*#define MF_PAX_RANDEXEC 0x10000000*/ /* Randomize ET_EXEC base */ | |
29447 | +#define MF_PAX_SEGMEXEC 0x20000000 /* Segmentation based non-executable pages */ | |
29448 | + | |
29449 | +#ifdef CONFIG_PAX_SOFTMODE | |
29450 | +extern unsigned int pax_softmode; | |
29451 | +#endif | |
29452 | + | |
29453 | +extern int pax_check_flags(unsigned long *); | |
29454 | + | |
29455 | +/* if tsk != current then task_lock must be held on it */ | |
29456 | +#if defined(CONFIG_PAX_NOEXEC) || defined(CONFIG_PAX_ASLR) | |
29457 | +static inline unsigned long pax_get_flags(struct task_struct *tsk) | |
29458 | +{ | |
29459 | + if (likely(tsk->mm)) | |
29460 | + return tsk->mm->pax_flags; | |
29461 | + else | |
29462 | + return 0UL; | |
29463 | +} | |
29464 | + | |
29465 | +/* if tsk != current then task_lock must be held on it */ | |
29466 | +static inline long pax_set_flags(struct task_struct *tsk, unsigned long flags) | |
29467 | +{ | |
29468 | + if (likely(tsk->mm)) { | |
29469 | + tsk->mm->pax_flags = flags; | |
29470 | + return 0; | |
29471 | + } | |
29472 | + return -EINVAL; | |
29473 | +} | |
29474 | +#endif | |
29475 | + | |
29476 | +#ifdef CONFIG_PAX_HAVE_ACL_FLAGS | |
29477 | +extern void pax_set_initial_flags(struct linux_binprm *bprm); | |
29478 | +#elif defined(CONFIG_PAX_HOOK_ACL_FLAGS) | |
29479 | +extern void (*pax_set_initial_flags_func)(struct linux_binprm *bprm); | |
29480 | +#endif | |
29481 | + | |
da5b3fc8 | 29482 | /* |
29483 | * Priority of a process goes from 0..MAX_PRIO-1, valid RT | |
29484 | * priority is 0..MAX_RT_PRIO-1, and SCHED_NORMAL/SCHED_BATCH | |
4dee9bd5 | 29485 | @@ -1775,7 +1836,7 @@ extern void __cleanup_signal(struct sign |
b7f09679 | 29486 | extern void __cleanup_sighand(struct sighand_struct *); |
29487 | extern void exit_itimers(struct signal_struct *); | |
29488 | ||
29489 | -extern NORET_TYPE void do_group_exit(int); | |
29490 | +extern NORET_TYPE void do_group_exit(int) ATTRIB_NORET; | |
29491 | ||
29492 | extern void daemonize(const char *, ...); | |
29493 | extern int allow_signal(int); | |
4dee9bd5 | 29494 | @@ -1877,8 +1938,8 @@ static inline void unlock_task_sighand(s |
da5b3fc8 | 29495 | |
29496 | #ifndef __HAVE_THREAD_FUNCTIONS | |
29497 | ||
29498 | -#define task_thread_info(task) ((struct thread_info *)(task)->stack) | |
29499 | -#define task_stack_page(task) ((task)->stack) | |
4dee9bd5 | 29500 | +#define task_thread_info(task) ((task)->stack) |
da5b3fc8 | 29501 | +#define task_stack_page(task) ((void *)(task)->stack) |
29502 | ||
29503 | static inline void setup_thread_stack(struct task_struct *p, struct task_struct *org) | |
8a4b4a5e | 29504 | { |
4dee9bd5 | 29505 | @@ -2026,6 +2087,12 @@ extern void arch_pick_mmap_layout(struct |
50425a20 | 29506 | static inline void arch_pick_mmap_layout(struct mm_struct *mm) |
29507 | { | |
29508 | mm->mmap_base = TASK_UNMAPPED_BASE; | |
29509 | + | |
29510 | +#ifdef CONFIG_PAX_RANDMMAP | |
29511 | + if (mm->pax_flags & MF_PAX_RANDMMAP) | |
29512 | + mm->mmap_base += mm->delta_mmap; | |
29513 | +#endif | |
29514 | + | |
29515 | mm->get_unmapped_area = arch_get_unmapped_area; | |
29516 | mm->unmap_area = arch_unmap_area; | |
29517 | } | |
4dee9bd5 | 29518 | diff -urNp linux-2.6.25.4/include/linux/screen_info.h linux-2.6.25.4/include/linux/screen_info.h |
29519 | --- linux-2.6.25.4/include/linux/screen_info.h 2008-05-15 11:00:12.000000000 -0400 | |
29520 | +++ linux-2.6.25.4/include/linux/screen_info.h 2008-05-18 13:33:17.000000000 -0400 | |
da5b3fc8 | 29521 | @@ -42,7 +42,8 @@ struct screen_info { |
29522 | __u16 pages; /* 0x32 */ | |
29523 | __u16 vesa_attributes; /* 0x34 */ | |
29524 | __u32 capabilities; /* 0x36 */ | |
29525 | - __u8 _reserved[6]; /* 0x3a */ | |
29526 | + __u16 vesapm_size; /* 0x3a */ | |
29527 | + __u8 _reserved[4]; /* 0x3c */ | |
29528 | } __attribute__((packed)); | |
29529 | ||
29530 | #define VIDEO_TYPE_MDA 0x10 /* Monochrome Text Display */ | |
4dee9bd5 | 29531 | diff -urNp linux-2.6.25.4/include/linux/shm.h linux-2.6.25.4/include/linux/shm.h |
29532 | --- linux-2.6.25.4/include/linux/shm.h 2008-05-15 11:00:12.000000000 -0400 | |
29533 | +++ linux-2.6.25.4/include/linux/shm.h 2008-05-18 13:33:17.000000000 -0400 | |
29534 | @@ -95,6 +95,10 @@ struct shmid_kernel /* private to the ke | |
50425a20 | 29535 | pid_t shm_cprid; |
29536 | pid_t shm_lprid; | |
29537 | struct user_struct *mlock_user; | |
29538 | +#ifdef CONFIG_GRKERNSEC | |
29539 | + time_t shm_createtime; | |
29540 | + pid_t shm_lapid; | |
29541 | +#endif | |
29542 | }; | |
29543 | ||
29544 | /* shm_mode upper byte flags */ | |
4dee9bd5 | 29545 | diff -urNp linux-2.6.25.4/include/linux/sysctl.h linux-2.6.25.4/include/linux/sysctl.h |
29546 | --- linux-2.6.25.4/include/linux/sysctl.h 2008-05-15 11:00:12.000000000 -0400 | |
29547 | +++ linux-2.6.25.4/include/linux/sysctl.h 2008-05-18 13:33:17.000000000 -0400 | |
29548 | @@ -163,9 +163,21 @@ enum | |
50425a20 | 29549 | KERN_MAX_LOCK_DEPTH=74, |
29550 | KERN_NMI_WATCHDOG=75, /* int: enable/disable nmi watchdog */ | |
29551 | KERN_PANIC_ON_NMI=76, /* int: whether we will panic on an unrecovered */ | |
29552 | -}; | |
29553 | +#ifdef CONFIG_GRKERNSEC | |
29554 | + KERN_GRSECURITY=98, /* grsecurity */ | |
29555 | +#endif | |
29556 | + | |
29557 | +#ifdef CONFIG_PAX_SOFTMODE | |
29558 | + KERN_PAX=99, /* PaX control */ | |
29559 | +#endif | |
29560 | ||
29561 | +}; | |
29562 | ||
29563 | +#ifdef CONFIG_PAX_SOFTMODE | |
29564 | +enum { | |
29565 | + PAX_SOFTMODE=1 /* PaX: disable/enable soft mode */ | |
29566 | +}; | |
29567 | +#endif | |
29568 | ||
29569 | /* CTL_VM names: */ | |
29570 | enum | |
4dee9bd5 | 29571 | diff -urNp linux-2.6.25.4/include/linux/uaccess.h linux-2.6.25.4/include/linux/uaccess.h |
29572 | --- linux-2.6.25.4/include/linux/uaccess.h 2008-05-15 11:00:12.000000000 -0400 | |
29573 | +++ linux-2.6.25.4/include/linux/uaccess.h 2008-05-18 13:33:17.000000000 -0400 | |
50425a20 | 29574 | @@ -76,11 +76,11 @@ static inline unsigned long __copy_from_ |
29575 | long ret; \ | |
29576 | mm_segment_t old_fs = get_fs(); \ | |
29577 | \ | |
29578 | - set_fs(KERNEL_DS); \ | |
29579 | pagefault_disable(); \ | |
29580 | + set_fs(KERNEL_DS); \ | |
29581 | ret = __get_user(retval, (__force typeof(retval) __user *)(addr)); \ | |
29582 | - pagefault_enable(); \ | |
29583 | set_fs(old_fs); \ | |
29584 | + pagefault_enable(); \ | |
29585 | ret; \ | |
29586 | }) | |
29587 | ||
4dee9bd5 | 29588 | diff -urNp linux-2.6.25.4/include/linux/udf_fs.h linux-2.6.25.4/include/linux/udf_fs.h |
29589 | --- linux-2.6.25.4/include/linux/udf_fs.h 2008-05-15 11:00:12.000000000 -0400 | |
29590 | +++ linux-2.6.25.4/include/linux/udf_fs.h 2008-05-18 13:33:17.000000000 -0400 | |
29591 | @@ -42,7 +42,7 @@ | |
50425a20 | 29592 | printk (f, ##a); \ |
4dee9bd5 | 29593 | } while (0) |
50425a20 | 29594 | #else |
29595 | -#define udf_debug(f, a...) /**/ | |
29596 | +#define udf_debug(f, a...) do {} while (0) | |
29597 | #endif | |
29598 | ||
29599 | #define udf_info(f, a...) \ | |
4dee9bd5 | 29600 | diff -urNp linux-2.6.25.4/include/net/sctp/sctp.h linux-2.6.25.4/include/net/sctp/sctp.h |
29601 | --- linux-2.6.25.4/include/net/sctp/sctp.h 2008-05-15 11:00:12.000000000 -0400 | |
29602 | +++ linux-2.6.25.4/include/net/sctp/sctp.h 2008-05-18 13:33:17.000000000 -0400 | |
29603 | @@ -309,8 +309,8 @@ extern int sctp_debug_flag; | |
50425a20 | 29604 | |
29605 | #else /* SCTP_DEBUG */ | |
29606 | ||
29607 | -#define SCTP_DEBUG_PRINTK(whatever...) | |
29608 | -#define SCTP_DEBUG_PRINTK_IPADDR(whatever...) | |
29609 | +#define SCTP_DEBUG_PRINTK(whatever...) do {} while (0) | |
29610 | +#define SCTP_DEBUG_PRINTK_IPADDR(whatever...) do {} while (0) | |
29611 | #define SCTP_ENABLE_DEBUG | |
29612 | #define SCTP_DISABLE_DEBUG | |
29613 | #define SCTP_ASSERT(expr, str, func) | |
4dee9bd5 | 29614 | diff -urNp linux-2.6.25.4/include/sound/core.h linux-2.6.25.4/include/sound/core.h |
29615 | --- linux-2.6.25.4/include/sound/core.h 2008-05-15 11:00:12.000000000 -0400 | |
29616 | +++ linux-2.6.25.4/include/sound/core.h 2008-05-18 13:33:17.000000000 -0400 | |
29617 | @@ -406,9 +406,9 @@ void snd_verbose_printd(const char *file | |
50425a20 | 29618 | |
29619 | #else /* !CONFIG_SND_DEBUG */ | |
29620 | ||
29621 | -#define snd_printd(fmt, args...) /* nothing */ | |
29622 | +#define snd_printd(fmt, args...) do {} while (0) | |
29623 | #define snd_assert(expr, args...) (void)(expr) | |
29624 | -#define snd_BUG() /* nothing */ | |
29625 | +#define snd_BUG() do {} while (0) | |
29626 | ||
29627 | #endif /* CONFIG_SND_DEBUG */ | |
29628 | ||
4dee9bd5 | 29629 | @@ -422,7 +422,7 @@ void snd_verbose_printd(const char *file |
50425a20 | 29630 | */ |
29631 | #define snd_printdd(format, args...) snd_printk(format, ##args) | |
29632 | #else | |
29633 | -#define snd_printdd(format, args...) /* nothing */ | |
29634 | +#define snd_printdd(format, args...) do {} while (0) | |
29635 | #endif | |
29636 | ||
29637 | ||
4dee9bd5 | 29638 | diff -urNp linux-2.6.25.4/init/do_mounts.c linux-2.6.25.4/init/do_mounts.c |
29639 | --- linux-2.6.25.4/init/do_mounts.c 2008-05-15 11:00:12.000000000 -0400 | |
29640 | +++ linux-2.6.25.4/init/do_mounts.c 2008-05-18 13:33:17.000000000 -0400 | |
29641 | @@ -188,11 +188,11 @@ static void __init get_fs_names(char *pa | |
50425a20 | 29642 | |
29643 | static int __init do_mount_root(char *name, char *fs, int flags, void *data) | |
29644 | { | |
29645 | - int err = sys_mount(name, "/root", fs, flags, data); | |
29646 | + int err = sys_mount((char __user *)name, (char __user *)"/root", (char __user *)fs, flags, (void __user *)data); | |
29647 | if (err) | |
29648 | return err; | |
29649 | ||
29650 | - sys_chdir("/root"); | |
29651 | + sys_chdir((char __user *)"/root"); | |
4dee9bd5 | 29652 | ROOT_DEV = current->fs->pwd.mnt->mnt_sb->s_dev; |
50425a20 | 29653 | printk("VFS: Mounted root (%s filesystem)%s.\n", |
4dee9bd5 | 29654 | current->fs->pwd.mnt->mnt_sb->s_type->name, |
29655 | @@ -278,18 +278,18 @@ void __init change_floppy(char *fmt, ... | |
50425a20 | 29656 | va_start(args, fmt); |
29657 | vsprintf(buf, fmt, args); | |
29658 | va_end(args); | |
29659 | - fd = sys_open("/dev/root", O_RDWR | O_NDELAY, 0); | |
29660 | + fd = sys_open((char __user *)"/dev/root", O_RDWR | O_NDELAY, 0); | |
29661 | if (fd >= 0) { | |
29662 | sys_ioctl(fd, FDEJECT, 0); | |
29663 | sys_close(fd); | |
29664 | } | |
29665 | printk(KERN_NOTICE "VFS: Insert %s and press ENTER\n", buf); | |
29666 | - fd = sys_open("/dev/console", O_RDWR, 0); | |
29667 | + fd = sys_open((char __user *)"/dev/console", O_RDWR, 0); | |
29668 | if (fd >= 0) { | |
29669 | sys_ioctl(fd, TCGETS, (long)&termios); | |
29670 | termios.c_lflag &= ~ICANON; | |
29671 | sys_ioctl(fd, TCSETSF, (long)&termios); | |
29672 | - sys_read(fd, &c, 1); | |
29673 | + sys_read(fd, (char __user *)&c, 1); | |
29674 | termios.c_lflag |= ICANON; | |
29675 | sys_ioctl(fd, TCSETSF, (long)&termios); | |
29676 | sys_close(fd); | |
4dee9bd5 | 29677 | @@ -375,7 +375,7 @@ void __init prepare_namespace(void) |
50425a20 | 29678 | |
29679 | mount_root(); | |
29680 | out: | |
29681 | - sys_mount(".", "/", NULL, MS_MOVE, NULL); | |
29682 | - sys_chroot("."); | |
29683 | + sys_mount((char __user *)".", (char __user *)"/", NULL, MS_MOVE, NULL); | |
29684 | + sys_chroot((char __user *)"."); | |
50425a20 | 29685 | } |
29686 | ||
4dee9bd5 | 29687 | diff -urNp linux-2.6.25.4/init/do_mounts.h linux-2.6.25.4/init/do_mounts.h |
29688 | --- linux-2.6.25.4/init/do_mounts.h 2008-05-15 11:00:12.000000000 -0400 | |
29689 | +++ linux-2.6.25.4/init/do_mounts.h 2008-05-18 13:33:17.000000000 -0400 | |
50425a20 | 29690 | @@ -15,15 +15,15 @@ extern char *root_device_name; |
29691 | ||
29692 | static inline int create_dev(char *name, dev_t dev) | |
29693 | { | |
29694 | - sys_unlink(name); | |
29695 | - return sys_mknod(name, S_IFBLK|0600, new_encode_dev(dev)); | |
29696 | + sys_unlink((char __user *)name); | |
29697 | + return sys_mknod((char __user *)name, S_IFBLK|0600, new_encode_dev(dev)); | |
29698 | } | |
29699 | ||
29700 | #if BITS_PER_LONG == 32 | |
29701 | static inline u32 bstat(char *name) | |
29702 | { | |
29703 | struct stat64 stat; | |
29704 | - if (sys_stat64(name, &stat) != 0) | |
29705 | + if (sys_stat64((char __user *)name, (struct stat64 __user *)&stat) != 0) | |
29706 | return 0; | |
29707 | if (!S_ISBLK(stat.st_mode)) | |
29708 | return 0; | |
4dee9bd5 | 29709 | diff -urNp linux-2.6.25.4/init/do_mounts_md.c linux-2.6.25.4/init/do_mounts_md.c |
29710 | --- linux-2.6.25.4/init/do_mounts_md.c 2008-05-15 11:00:12.000000000 -0400 | |
29711 | +++ linux-2.6.25.4/init/do_mounts_md.c 2008-05-18 13:33:17.000000000 -0400 | |
50425a20 | 29712 | @@ -167,7 +167,7 @@ static void __init md_setup_drive(void) |
29713 | partitioned ? "_d" : "", minor, | |
29714 | md_setup_args[ent].device_names); | |
29715 | ||
29716 | - fd = sys_open(name, 0, 0); | |
29717 | + fd = sys_open((char __user *)name, 0, 0); | |
29718 | if (fd < 0) { | |
29719 | printk(KERN_ERR "md: open failed - cannot start " | |
29720 | "array %s\n", name); | |
29721 | @@ -230,7 +230,7 @@ static void __init md_setup_drive(void) | |
29722 | * array without it | |
29723 | */ | |
29724 | sys_close(fd); | |
29725 | - fd = sys_open(name, 0, 0); | |
29726 | + fd = sys_open((char __user *)name, 0, 0); | |
29727 | sys_ioctl(fd, BLKRRPART, 0); | |
29728 | } | |
29729 | sys_close(fd); | |
29730 | @@ -271,7 +271,7 @@ void __init md_run_setup(void) | |
29731 | if (raid_noautodetect) | |
29732 | printk(KERN_INFO "md: Skipping autodetection of RAID arrays. (raid=noautodetect)\n"); | |
29733 | else { | |
29734 | - int fd = sys_open("/dev/md0", 0, 0); | |
29735 | + int fd = sys_open((char __user *)"/dev/md0", 0, 0); | |
29736 | if (fd >= 0) { | |
29737 | sys_ioctl(fd, RAID_AUTORUN, raid_autopart); | |
29738 | sys_close(fd); | |
4dee9bd5 | 29739 | diff -urNp linux-2.6.25.4/init/initramfs.c linux-2.6.25.4/init/initramfs.c |
29740 | --- linux-2.6.25.4/init/initramfs.c 2008-05-15 11:00:12.000000000 -0400 | |
29741 | +++ linux-2.6.25.4/init/initramfs.c 2008-05-18 13:33:17.000000000 -0400 | |
50425a20 | 29742 | @@ -240,7 +240,7 @@ static int __init maybe_link(void) |
29743 | if (nlink >= 2) { | |
29744 | char *old = find_link(major, minor, ino, mode, collected); | |
29745 | if (old) | |
29746 | - return (sys_link(old, collected) < 0) ? -1 : 1; | |
29747 | + return (sys_link((char __user *)old, (char __user *)collected) < 0) ? -1 : 1; | |
29748 | } | |
29749 | return 0; | |
29750 | } | |
29751 | @@ -249,11 +249,11 @@ static void __init clean_path(char *path | |
29752 | { | |
29753 | struct stat st; | |
29754 | ||
29755 | - if (!sys_newlstat(path, &st) && (st.st_mode^mode) & S_IFMT) { | |
29756 | + if (!sys_newlstat((char __user *)path, (struct stat __user *)&st) && (st.st_mode^mode) & S_IFMT) { | |
29757 | if (S_ISDIR(st.st_mode)) | |
29758 | - sys_rmdir(path); | |
29759 | + sys_rmdir((char __user *)path); | |
29760 | else | |
29761 | - sys_unlink(path); | |
29762 | + sys_unlink((char __user *)path); | |
29763 | } | |
29764 | } | |
29765 | ||
29766 | @@ -276,7 +276,7 @@ static int __init do_name(void) | |
29767 | int openflags = O_WRONLY|O_CREAT; | |
29768 | if (ml != 1) | |
29769 | openflags |= O_TRUNC; | |
29770 | - wfd = sys_open(collected, openflags, mode); | |
29771 | + wfd = sys_open((char __user *)collected, openflags, mode); | |
29772 | ||
29773 | if (wfd >= 0) { | |
29774 | sys_fchown(wfd, uid, gid); | |
29775 | @@ -285,15 +285,15 @@ static int __init do_name(void) | |
29776 | } | |
29777 | } | |
29778 | } else if (S_ISDIR(mode)) { | |
29779 | - sys_mkdir(collected, mode); | |
29780 | - sys_chown(collected, uid, gid); | |
29781 | - sys_chmod(collected, mode); | |
29782 | + sys_mkdir((char __user *)collected, mode); | |
29783 | + sys_chown((char __user *)collected, uid, gid); | |
29784 | + sys_chmod((char __user *)collected, mode); | |
29785 | } else if (S_ISBLK(mode) || S_ISCHR(mode) || | |
29786 | S_ISFIFO(mode) || S_ISSOCK(mode)) { | |
29787 | if (maybe_link() == 0) { | |
29788 | - sys_mknod(collected, mode, rdev); | |
29789 | - sys_chown(collected, uid, gid); | |
29790 | - sys_chmod(collected, mode); | |
29791 | + sys_mknod((char __user *)collected, mode, rdev); | |
29792 | + sys_chown((char __user *)collected, uid, gid); | |
29793 | + sys_chmod((char __user *)collected, mode); | |
29794 | } | |
29795 | } | |
29796 | return 0; | |
29797 | @@ -302,13 +302,13 @@ static int __init do_name(void) | |
29798 | static int __init do_copy(void) | |
29799 | { | |
29800 | if (count >= body_len) { | |
29801 | - sys_write(wfd, victim, body_len); | |
29802 | + sys_write(wfd, (char __user *)victim, body_len); | |
29803 | sys_close(wfd); | |
29804 | eat(body_len); | |
29805 | state = SkipIt; | |
29806 | return 0; | |
29807 | } else { | |
29808 | - sys_write(wfd, victim, count); | |
29809 | + sys_write(wfd, (char __user *)victim, count); | |
29810 | body_len -= count; | |
29811 | eat(count); | |
29812 | return 1; | |
29813 | @@ -319,8 +319,8 @@ static int __init do_symlink(void) | |
29814 | { | |
29815 | collected[N_ALIGN(name_len) + body_len] = '\0'; | |
29816 | clean_path(collected, 0); | |
29817 | - sys_symlink(collected + N_ALIGN(name_len), collected); | |
29818 | - sys_lchown(collected, uid, gid); | |
29819 | + sys_symlink((char __user *)collected + N_ALIGN(name_len), (char __user *)collected); | |
29820 | + sys_lchown((char __user *)collected, uid, gid); | |
29821 | state = SkipIt; | |
29822 | next_state = Reset; | |
29823 | return 0; | |
4dee9bd5 | 29824 | diff -urNp linux-2.6.25.4/init/Kconfig linux-2.6.25.4/init/Kconfig |
29825 | --- linux-2.6.25.4/init/Kconfig 2008-05-15 11:00:12.000000000 -0400 | |
29826 | +++ linux-2.6.25.4/init/Kconfig 2008-05-18 13:33:17.000000000 -0400 | |
29827 | @@ -538,6 +538,7 @@ config SYSCTL_SYSCALL | |
50425a20 | 29828 | config KALLSYMS |
29829 | bool "Load all symbols for debugging/ksymoops" if EMBEDDED | |
29830 | default y | |
29831 | + depends on !GRKERNSEC_HIDESYM | |
29832 | help | |
29833 | Say Y here to let the kernel print out symbolic crash information and | |
29834 | symbolic stack backtraces. This increases the size of the kernel | |
4dee9bd5 | 29835 | diff -urNp linux-2.6.25.4/init/main.c linux-2.6.25.4/init/main.c |
29836 | --- linux-2.6.25.4/init/main.c 2008-05-15 11:00:12.000000000 -0400 | |
29837 | +++ linux-2.6.25.4/init/main.c 2008-05-18 13:33:17.000000000 -0400 | |
da5b3fc8 | 29838 | @@ -101,6 +101,7 @@ static inline void mark_rodata_ro(void) |
50425a20 | 29839 | #ifdef CONFIG_TC |
29840 | extern void tc_init(void); | |
29841 | #endif | |
29842 | +extern void grsecurity_init(void); | |
29843 | ||
29844 | enum system_states system_state; | |
29845 | EXPORT_SYMBOL(system_state); | |
b43ccab8 | 29846 | @@ -187,6 +188,40 @@ static int __init set_reset_devices(char |
50425a20 | 29847 | |
29848 | __setup("reset_devices", set_reset_devices); | |
29849 | ||
b43ccab8 | 29850 | +#if defined(CONFIG_PAX_MEMORY_UDEREF) && defined(CONFIG_X86_32) |
29851 | +static int __init setup_pax_nouderef(char *str) | |
29852 | +{ | |
29853 | + unsigned int cpu; | |
29854 | + | |
29855 | +#ifdef CONFIG_PAX_KERNEXEC | |
29856 | + unsigned long cr0; | |
29857 | + | |
29858 | + pax_open_kernel(cr0); | |
29859 | +#endif | |
29860 | + | |
29861 | + for (cpu = 0; cpu < NR_CPUS; cpu++) | |
29862 | + get_cpu_gdt_table(cpu)[GDT_ENTRY_KERNEL_DS].b = 0x00cf9300; | |
29863 | + | |
29864 | +#ifdef CONFIG_PAX_KERNEXEC | |
29865 | + pax_close_kernel(cr0); | |
29866 | +#endif | |
29867 | + | |
29868 | + return 1; | |
29869 | +} | |
29870 | +__setup("pax_nouderef", setup_pax_nouderef); | |
29871 | +#endif | |
29872 | + | |
50425a20 | 29873 | +#ifdef CONFIG_PAX_SOFTMODE |
89388fe1 | 29874 | +unsigned int pax_softmode; |
29875 | + | |
50425a20 | 29876 | +static int __init setup_pax_softmode(char *str) |
29877 | +{ | |
29878 | + get_option(&str, &pax_softmode); | |
29879 | + return 1; | |
29880 | +} | |
29881 | +__setup("pax_softmode=", setup_pax_softmode); | |
29882 | +#endif | |
29883 | + | |
29884 | static char * argv_init[MAX_INIT_ARGS+2] = { "init", NULL, }; | |
29885 | char * envp_init[MAX_INIT_ENVS+2] = { "HOME=/", "TERM=linux", NULL, }; | |
29886 | static const char *panic_later, *panic_param; | |
84cd3cb1 | 29887 | @@ -364,7 +375,7 @@ static inline void smp_prepare_cpus(unsi |
29888 | #else | |
29889 | ||
29890 | #ifndef CONFIG_HAVE_SETUP_PER_CPU_AREA | |
29891 | -unsigned long __per_cpu_offset[NR_CPUS] __read_mostly; | |
29892 | +unsigned long __per_cpu_offset[NR_CPUS] __read_only; | |
29893 | ||
29894 | EXPORT_SYMBOL(__per_cpu_offset); | |
29895 | ||
4dee9bd5 | 29896 | @@ -668,7 +680,7 @@ static void __init do_initcalls(void) |
29897 | ||
29898 | for (call = __initcall_start; call < __initcall_end; call++) { | |
29899 | ktime_t t0, t1, delta; | |
29900 | - char *msg = NULL; | |
29901 | + char *msg1 = NULL, *msg2 = NULL; | |
29902 | char msgbuf[40]; | |
29903 | int result; | |
29904 | ||
29905 | @@ -697,23 +709,23 @@ static void __init do_initcalls(void) | |
29906 | (unsigned long) *call); | |
29907 | } | |
29908 | ||
29909 | - if (result && result != -ENODEV && initcall_debug) { | |
29910 | - sprintf(msgbuf, "error code %d", result); | |
29911 | - msg = msgbuf; | |
29912 | - } | |
29913 | + msgbuf[0] = 0; | |
29914 | + if (result && result != -ENODEV && initcall_debug) | |
29915 | + sprintf(msgbuf, " error code %d", result); | |
29916 | if (preempt_count() != count) { | |
29917 | - msg = "preemption imbalance"; | |
29918 | + msg1 = " preemption imbalance"; | |
29919 | preempt_count() = count; | |
29920 | } | |
29921 | if (irqs_disabled()) { | |
29922 | - msg = "disabled interrupts"; | |
29923 | + msg2 = " disabled interrupts"; | |
29924 | local_irq_enable(); | |
29925 | } | |
29926 | - if (msg) { | |
29927 | + if (msgbuf[0] || msg1 || msg2) { | |
29928 | printk(KERN_WARNING "initcall at 0x%p", *call); | |
29929 | print_fn_descriptor_symbol(": %s()", | |
29930 | (unsigned long) *call); | |
29931 | - printk(": returned with %s\n", msg); | |
29932 | + printk(": returned with%s%s%s\n", | |
29933 | + msgbuf[0] ? msgbuf : "", msg1 ? msg1 : "", msg2 ? msg2 : ""); | |
29934 | } | |
29935 | } | |
29936 | ||
29937 | @@ -848,6 +860,8 @@ static int __init kernel_init(void * unu | |
50425a20 | 29938 | prepare_namespace(); |
29939 | } | |
29940 | ||
29941 | + grsecurity_init(); | |
29942 | + | |
29943 | /* | |
29944 | * Ok, we have completed the initial bootup, and | |
29945 | * we're essentially up and running. Get rid of the | |
4dee9bd5 | 29946 | diff -urNp linux-2.6.25.4/init/noinitramfs.c linux-2.6.25.4/init/noinitramfs.c |
29947 | --- linux-2.6.25.4/init/noinitramfs.c 2008-05-15 11:00:12.000000000 -0400 | |
29948 | +++ linux-2.6.25.4/init/noinitramfs.c 2008-05-18 13:33:17.000000000 -0400 | |
8a4b4a5e | 29949 | @@ -29,7 +29,7 @@ static int __init default_rootfs(void) |
29950 | { | |
29951 | int err; | |
29952 | ||
29953 | - err = sys_mkdir("/dev", 0755); | |
29954 | + err = sys_mkdir((const char __user *)"/dev", 0755); | |
29955 | if (err < 0) | |
29956 | goto out; | |
29957 | ||
29958 | @@ -39,7 +39,7 @@ static int __init default_rootfs(void) | |
29959 | if (err < 0) | |
29960 | goto out; | |
29961 | ||
29962 | - err = sys_mkdir("/root", 0700); | |
29963 | + err = sys_mkdir((const char __user *)"/root", 0700); | |
29964 | if (err < 0) | |
29965 | goto out; | |
29966 | ||
4dee9bd5 | 29967 | diff -urNp linux-2.6.25.4/ipc/ipc_sysctl.c linux-2.6.25.4/ipc/ipc_sysctl.c |
29968 | --- linux-2.6.25.4/ipc/ipc_sysctl.c 2008-05-15 11:00:12.000000000 -0400 | |
29969 | +++ linux-2.6.25.4/ipc/ipc_sysctl.c 2008-05-18 13:33:17.000000000 -0400 | |
29970 | @@ -158,7 +158,7 @@ static struct ctl_table ipc_kern_table[] | |
da5b3fc8 | 29971 | .proc_handler = proc_ipc_dointvec, |
29972 | .strategy = sysctl_ipc_data, | |
29973 | }, | |
29974 | - {} | |
29975 | + { 0, NULL, NULL, 0, 0, NULL, NULL, NULL, NULL, NULL, NULL } | |
29976 | }; | |
29977 | ||
29978 | static struct ctl_table ipc_root_table[] = { | |
4dee9bd5 | 29979 | @@ -168,7 +168,7 @@ static struct ctl_table ipc_root_table[] |
da5b3fc8 | 29980 | .mode = 0555, |
29981 | .child = ipc_kern_table, | |
29982 | }, | |
29983 | - {} | |
29984 | + { 0, NULL, NULL, 0, 0, NULL, NULL, NULL, NULL, NULL, NULL } | |
29985 | }; | |
29986 | ||
29987 | static int __init ipc_sysctl_init(void) | |
4dee9bd5 | 29988 | diff -urNp linux-2.6.25.4/ipc/msg.c linux-2.6.25.4/ipc/msg.c |
29989 | --- linux-2.6.25.4/ipc/msg.c 2008-05-15 11:00:12.000000000 -0400 | |
29990 | +++ linux-2.6.25.4/ipc/msg.c 2008-05-18 13:33:17.000000000 -0400 | |
29991 | @@ -37,6 +37,7 @@ | |
50425a20 | 29992 | #include <linux/nsproxy.h> |
4dee9bd5 | 29993 | #include <linux/ipc_namespace.h> |
b79bc584 | 29994 | #include <linux/vs_base.h> |
50425a20 | 29995 | +#include <linux/grsecurity.h> |
29996 | ||
29997 | #include <asm/current.h> | |
29998 | #include <asm/uaccess.h> | |
4dee9bd5 | 29999 | @@ -293,6 +294,7 @@ asmlinkage long sys_msgget(key_t key, in |
da5b3fc8 | 30000 | struct ipc_namespace *ns; |
30001 | struct ipc_ops msg_ops; | |
30002 | struct ipc_params msg_params; | |
30003 | + long err; | |
50425a20 | 30004 | |
da5b3fc8 | 30005 | ns = current->nsproxy->ipc_ns; |
30006 | ||
4dee9bd5 | 30007 | @@ -303,7 +305,11 @@ asmlinkage long sys_msgget(key_t key, in |
da5b3fc8 | 30008 | msg_params.key = key; |
30009 | msg_params.flg = msgflg; | |
30010 | ||
30011 | - return ipcget(ns, &msg_ids(ns), &msg_ops, &msg_params); | |
30012 | + err = ipcget(ns, &msg_ids(ns), &msg_ops, &msg_params); | |
50425a20 | 30013 | + |
da5b3fc8 | 30014 | + gr_log_msgget(err, msgflg); |
30015 | + | |
30016 | + return err; | |
50425a20 | 30017 | } |
30018 | ||
da5b3fc8 | 30019 | static inline unsigned long |
4dee9bd5 | 30020 | @@ -564,6 +570,7 @@ asmlinkage long sys_msgctl(int msqid, in |
50425a20 | 30021 | break; |
30022 | } | |
30023 | case IPC_RMID: | |
30024 | + gr_log_msgrm(ipcp->uid, ipcp->cuid); | |
4dee9bd5 | 30025 | freeque(ns, &msq->q_perm); |
50425a20 | 30026 | break; |
30027 | } | |
4dee9bd5 | 30028 | diff -urNp linux-2.6.25.4/ipc/sem.c linux-2.6.25.4/ipc/sem.c |
30029 | --- linux-2.6.25.4/ipc/sem.c 2008-05-15 11:00:12.000000000 -0400 | |
30030 | +++ linux-2.6.25.4/ipc/sem.c 2008-05-18 13:33:17.000000000 -0400 | |
30031 | @@ -83,6 +83,7 @@ | |
4dee9bd5 | 30032 | #include <linux/ipc_namespace.h> |
b79bc584 | 30033 | #include <linux/vs_base.h> |
30034 | #include <linux/vs_limit.h> | |
50425a20 | 30035 | +#include <linux/grsecurity.h> |
30036 | ||
30037 | #include <asm/uaccess.h> | |
30038 | #include "util.h" | |
4dee9bd5 | 30039 | @@ -312,6 +313,7 @@ asmlinkage long sys_semget(key_t key, in |
da5b3fc8 | 30040 | struct ipc_namespace *ns; |
30041 | struct ipc_ops sem_ops; | |
30042 | struct ipc_params sem_params; | |
30043 | + long err; | |
30044 | ||
30045 | ns = current->nsproxy->ipc_ns; | |
50425a20 | 30046 | |
4dee9bd5 | 30047 | @@ -326,7 +328,11 @@ asmlinkage long sys_semget(key_t key, in |
da5b3fc8 | 30048 | sem_params.flg = semflg; |
30049 | sem_params.u.nsems = nsems; | |
30050 | ||
30051 | - return ipcget(ns, &sem_ids(ns), &sem_ops, &sem_params); | |
30052 | + err = ipcget(ns, &sem_ids(ns), &sem_ops, &sem_params); | |
50425a20 | 30053 | + |
30054 | + gr_log_semget(err, semflg); | |
30055 | + | |
da5b3fc8 | 30056 | + return err; |
50425a20 | 30057 | } |
30058 | ||
da5b3fc8 | 30059 | /* Manage the doubly linked list sma->sem_pending as a FIFO: |
4dee9bd5 | 30060 | @@ -909,6 +915,7 @@ static int semctl_down(struct ipc_namesp |
50425a20 | 30061 | |
30062 | switch(cmd){ | |
30063 | case IPC_RMID: | |
30064 | + gr_log_semrm(ipcp->uid, ipcp->cuid); | |
4dee9bd5 | 30065 | freeary(ns, ipcp); |
50425a20 | 30066 | err = 0; |
30067 | break; | |
4dee9bd5 | 30068 | diff -urNp linux-2.6.25.4/ipc/shm.c linux-2.6.25.4/ipc/shm.c |
30069 | --- linux-2.6.25.4/ipc/shm.c 2008-05-15 11:00:12.000000000 -0400 | |
30070 | +++ linux-2.6.25.4/ipc/shm.c 2008-05-18 13:33:17.000000000 -0400 | |
30071 | @@ -39,6 +39,7 @@ | |
4dee9bd5 | 30072 | #include <linux/ipc_namespace.h> |
b79bc584 | 30073 | #include <linux/vs_context.h> |
30074 | #include <linux/vs_limit.h> | |
50425a20 | 30075 | +#include <linux/grsecurity.h> |
30076 | ||
30077 | #include <asm/uaccess.h> | |
30078 | ||
4dee9bd5 | 30079 | @@ -70,6 +71,14 @@ static void shm_destroy (struct ipc_name |
50425a20 | 30080 | static int sysvipc_shm_proc_show(struct seq_file *s, void *it); |
30081 | #endif | |
30082 | ||
30083 | +#ifdef CONFIG_GRKERNSEC | |
30084 | +extern int gr_handle_shmat(const pid_t shm_cprid, const pid_t shm_lapid, | |
30085 | + const time_t shm_createtime, const uid_t cuid, | |
30086 | + const int shmid); | |
30087 | +extern int gr_chroot_shmat(const pid_t shm_cprid, const pid_t shm_lapid, | |
30088 | + const time_t shm_createtime); | |
30089 | +#endif | |
30090 | + | |
4dee9bd5 | 30091 | void shm_init_ns(struct ipc_namespace *ns) |
50425a20 | 30092 | { |
4dee9bd5 | 30093 | ns->shm_ctlmax = SHMMAX; |
30094 | @@ -88,6 +97,8 @@ static void do_shm_rmid(struct ipc_names | |
30095 | struct shmid_kernel *shp; | |
30096 | shp = container_of(ipcp, struct shmid_kernel, shm_perm); | |
30097 | ||
50425a20 | 30098 | + gr_log_shmrm(shp->shm_perm.uid, shp->shm_perm.cuid); |
30099 | + | |
30100 | if (shp->shm_nattch){ | |
30101 | shp->shm_perm.mode |= SHM_DEST; | |
30102 | /* Do not find it any more */ | |
4dee9bd5 | 30103 | @@ -428,6 +439,14 @@ static int newseg(struct ipc_namespace * |
50425a20 | 30104 | shp->shm_lprid = 0; |
30105 | shp->shm_atim = shp->shm_dtim = 0; | |
30106 | shp->shm_ctim = get_seconds(); | |
30107 | +#ifdef CONFIG_GRKERNSEC | |
b2ee8b1e | 30108 | + { |
30109 | + struct timespec timeval; | |
30110 | + do_posix_clock_monotonic_gettime(&timeval); | |
30111 | + | |
30112 | + shp->shm_createtime = timeval.tv_sec; | |
30113 | + } | |
50425a20 | 30114 | +#endif |
30115 | shp->shm_segsz = size; | |
30116 | shp->shm_nattch = 0; | |
da5b3fc8 | 30117 | shp->shm_perm.id = shm_buildid(id, shp->shm_perm.seq); |
4dee9bd5 | 30118 | @@ -482,6 +501,7 @@ asmlinkage long sys_shmget (key_t key, s |
da5b3fc8 | 30119 | struct ipc_namespace *ns; |
30120 | struct ipc_ops shm_ops; | |
30121 | struct ipc_params shm_params; | |
30122 | + long err; | |
30123 | ||
30124 | ns = current->nsproxy->ipc_ns; | |
50425a20 | 30125 | |
4dee9bd5 | 30126 | @@ -493,7 +513,11 @@ asmlinkage long sys_shmget (key_t key, s |
da5b3fc8 | 30127 | shm_params.flg = shmflg; |
30128 | shm_params.u.size = size; | |
30129 | ||
30130 | - return ipcget(ns, &shm_ids(ns), &shm_ops, &shm_params); | |
30131 | + err = ipcget(ns, &shm_ids(ns), &shm_ops, &shm_params); | |
30132 | + | |
50425a20 | 30133 | + gr_log_shmget(err, shmflg, size); |
30134 | + | |
da5b3fc8 | 30135 | + return err; |
50425a20 | 30136 | } |
30137 | ||
da5b3fc8 | 30138 | static inline unsigned long copy_shmid_to_user(void __user *buf, struct shmid64_ds *in, int version) |
4dee9bd5 | 30139 | @@ -959,9 +983,21 @@ long do_shmat(int shmid, char __user *sh |
50425a20 | 30140 | if (err) |
30141 | goto out_unlock; | |
30142 | ||
b2ee8b1e | 30143 | +#ifdef CONFIG_GRKERNSEC |
50425a20 | 30144 | + if (!gr_handle_shmat(shp->shm_cprid, shp->shm_lapid, shp->shm_createtime, |
30145 | + shp->shm_perm.cuid, shmid) || | |
b2ee8b1e | 30146 | + !gr_chroot_shmat(shp->shm_cprid, shp->shm_lapid, shp->shm_createtime)) { |
50425a20 | 30147 | + err = -EACCES; |
30148 | + goto out_unlock; | |
30149 | + } | |
30150 | +#endif | |
30151 | + | |
30152 | path.dentry = dget(shp->shm_file->f_path.dentry); | |
da5b3fc8 | 30153 | path.mnt = shp->shm_file->f_path.mnt; |
50425a20 | 30154 | shp->shm_nattch++; |
30155 | +#ifdef CONFIG_GRKERNSEC | |
30156 | + shp->shm_lapid = current->pid; | |
30157 | +#endif | |
30158 | size = i_size_read(path.dentry->d_inode); | |
30159 | shm_unlock(shp); | |
30160 | ||
4dee9bd5 | 30161 | diff -urNp linux-2.6.25.4/kernel/acct.c linux-2.6.25.4/kernel/acct.c |
30162 | --- linux-2.6.25.4/kernel/acct.c 2008-05-15 11:00:12.000000000 -0400 | |
30163 | +++ linux-2.6.25.4/kernel/acct.c 2008-05-18 13:33:17.000000000 -0400 | |
30164 | @@ -519,7 +519,7 @@ static void do_acct_process(struct pid_n | |
da5b3fc8 | 30165 | */ |
50425a20 | 30166 | flim = current->signal->rlim[RLIMIT_FSIZE].rlim_cur; |
30167 | current->signal->rlim[RLIMIT_FSIZE].rlim_cur = RLIM_INFINITY; | |
30168 | - file->f_op->write(file, (char *)&ac, | |
30169 | + file->f_op->write(file, (char __user *)&ac, | |
30170 | sizeof(acct_t), &file->f_pos); | |
30171 | current->signal->rlim[RLIMIT_FSIZE].rlim_cur = flim; | |
30172 | set_fs(fs); | |
4dee9bd5 | 30173 | diff -urNp linux-2.6.25.4/kernel/capability.c linux-2.6.25.4/kernel/capability.c |
30174 | --- linux-2.6.25.4/kernel/capability.c 2008-05-15 11:00:12.000000000 -0400 | |
30175 | +++ linux-2.6.25.4/kernel/capability.c 2008-05-18 13:33:17.000000000 -0400 | |
da5b3fc8 | 30176 | @@ -13,6 +13,7 @@ |
50425a20 | 30177 | #include <linux/syscalls.h> |
da5b3fc8 | 30178 | #include <linux/pid_namespace.h> |
b79bc584 | 30179 | #include <linux/vs_context.h> |
50425a20 | 30180 | +#include <linux/grsecurity.h> |
30181 | #include <asm/uaccess.h> | |
30182 | ||
da5b3fc8 | 30183 | /* |
b79bc584 | 30184 | @@ -331,13 +332,22 @@ out: |
50425a20 | 30185 | |
50425a20 | 30186 | int __capable(struct task_struct *t, int cap) |
30187 | { | |
30188 | - if (security_capable(t, cap) == 0) { | |
30189 | + if ((security_capable(t, cap) == 0) && gr_task_is_capable(t, cap)) { | |
30190 | t->flags |= PF_SUPERPRIV; | |
30191 | return 1; | |
30192 | } | |
30193 | return 0; | |
30194 | } | |
da5b3fc8 | 30195 | |
50425a20 | 30196 | +int capable_nolog(int cap) |
30197 | +{ | |
30198 | + if ((security_capable(current, cap) == 0) && gr_is_capable_nolog(cap)) { | |
30199 | + current->flags |= PF_SUPERPRIV; | |
30200 | + return 1; | |
30201 | + } | |
30202 | + return 0; | |
30203 | +} | |
da5b3fc8 | 30204 | + |
b79bc584 | 30205 | #include <linux/vserver/base.h> |
da5b3fc8 | 30206 | int capable(int cap) |
30207 | { | |
b79bc584 | 30208 | @@ -347,3 +357,4 @@ int capable(int cap) |
50425a20 | 30209 | return __capable(current, cap); |
30210 | } | |
30211 | EXPORT_SYMBOL(capable); | |
30212 | +EXPORT_SYMBOL(capable_nolog); | |
4dee9bd5 | 30213 | diff -urNp linux-2.6.25.4/kernel/configs.c linux-2.6.25.4/kernel/configs.c |
30214 | --- linux-2.6.25.4/kernel/configs.c 2008-05-15 11:00:12.000000000 -0400 | |
30215 | +++ linux-2.6.25.4/kernel/configs.c 2008-05-18 13:33:17.000000000 -0400 | |
8a4b4a5e | 30216 | @@ -79,8 +79,16 @@ static int __init ikconfig_init(void) |
50425a20 | 30217 | struct proc_dir_entry *entry; |
30218 | ||
30219 | /* create the current config file */ | |
30220 | +#ifdef CONFIG_GRKERNSEC_PROC_ADD | |
30221 | +#ifdef CONFIG_GRKERNSEC_PROC_USER | |
30222 | + entry = create_proc_entry("config.gz", S_IFREG | S_IRUSR, &proc_root); | |
b2ee8b1e | 30223 | +#elif defined(CONFIG_GRKERNSEC_PROC_USERGROUP) |
50425a20 | 30224 | + entry = create_proc_entry("config.gz", S_IFREG | S_IRUSR | S_IRGRP, &proc_root); |
30225 | +#endif | |
30226 | +#else | |
30227 | entry = create_proc_entry("config.gz", S_IFREG | S_IRUGO, | |
30228 | &proc_root); | |
30229 | +#endif | |
30230 | if (!entry) | |
30231 | return -ENOMEM; | |
30232 | ||
4dee9bd5 | 30233 | diff -urNp linux-2.6.25.4/kernel/cpu.c linux-2.6.25.4/kernel/cpu.c |
30234 | --- linux-2.6.25.4/kernel/cpu.c 2008-05-15 11:00:12.000000000 -0400 | |
30235 | +++ linux-2.6.25.4/kernel/cpu.c 2008-05-18 13:33:17.000000000 -0400 | |
30236 | @@ -18,7 +18,7 @@ | |
30237 | /* Serializes the updates to cpu_online_map, cpu_present_map */ | |
b7f09679 | 30238 | static DEFINE_MUTEX(cpu_add_remove_lock); |
b7f09679 | 30239 | |
30240 | -static __cpuinitdata RAW_NOTIFIER_HEAD(cpu_chain); | |
30241 | +static RAW_NOTIFIER_HEAD(cpu_chain); | |
30242 | ||
30243 | /* If set, cpu_up and cpu_down will return -EBUSY and do nothing. | |
30244 | * Should always be manipulated under cpu_add_remove_lock | |
4dee9bd5 | 30245 | @@ -136,7 +136,7 @@ static void cpu_hotplug_done(void) |
30246 | mutex_unlock(&cpu_hotplug.lock); | |
30247 | } | |
b7f09679 | 30248 | /* Need to know about CPUs going up/down? */ |
30249 | -int __cpuinit register_cpu_notifier(struct notifier_block *nb) | |
30250 | +int register_cpu_notifier(struct notifier_block *nb) | |
30251 | { | |
30252 | int ret; | |
4dee9bd5 | 30253 | cpu_maps_update_begin(); |
30254 | diff -urNp linux-2.6.25.4/kernel/exit.c linux-2.6.25.4/kernel/exit.c | |
30255 | --- linux-2.6.25.4/kernel/exit.c 2008-05-15 11:00:12.000000000 -0400 | |
30256 | +++ linux-2.6.25.4/kernel/exit.c 2008-05-18 13:33:17.000000000 -0400 | |
8a4b4a5e | 30257 | @@ -44,6 +44,11 @@ |
b79bc584 | 30258 | #include <linux/vs_network.h> |
30259 | #include <linux/vs_pid.h> | |
30260 | #include <linux/vserver/global.h> | |
50425a20 | 30261 | +#include <linux/grsecurity.h> |
30262 | + | |
30263 | +#ifdef CONFIG_GRKERNSEC | |
30264 | +extern rwlock_t grsec_exec_file_lock; | |
30265 | +#endif | |
30266 | ||
30267 | #include <asm/uaccess.h> | |
30268 | #include <asm/unistd.h> | |
4dee9bd5 | 30269 | @@ -120,6 +125,7 @@ static void __exit_signal(struct task_st |
50425a20 | 30270 | |
30271 | __unhash_process(tsk); | |
30272 | ||
30273 | + gr_del_task_from_ip_table(tsk); | |
30274 | tsk->signal = NULL; | |
30275 | tsk->sighand = NULL; | |
30276 | spin_unlock(&sighand->siglock); | |
4dee9bd5 | 30277 | @@ -301,12 +307,23 @@ static void reparent_to_kthreadd(void) |
50425a20 | 30278 | { |
30279 | write_lock_irq(&tasklist_lock); | |
30280 | ||
30281 | +#ifdef CONFIG_GRKERNSEC | |
30282 | + write_lock(&grsec_exec_file_lock); | |
30283 | + if (current->exec_file) { | |
30284 | + fput(current->exec_file); | |
30285 | + current->exec_file = NULL; | |
30286 | + } | |
30287 | + write_unlock(&grsec_exec_file_lock); | |
30288 | +#endif | |
30289 | + | |
30290 | ptrace_unlink(current); | |
30291 | /* Reparent to init */ | |
30292 | remove_parent(current); | |
8a4b4a5e | 30293 | current->real_parent = current->parent = kthreadd_task; |
50425a20 | 30294 | add_parent(current); |
30295 | ||
30296 | + gr_set_kernel_label(current); | |
30297 | + | |
30298 | /* Set the exit signal to SIGCHLD so we signal init on exit */ | |
30299 | current->exit_signal = SIGCHLD; | |
30300 | ||
4dee9bd5 | 30301 | @@ -402,6 +419,17 @@ void daemonize(const char *name, ...) |
50425a20 | 30302 | vsnprintf(current->comm, sizeof(current->comm), name, args); |
30303 | va_end(args); | |
30304 | ||
30305 | +#ifdef CONFIG_GRKERNSEC | |
30306 | + write_lock(&grsec_exec_file_lock); | |
30307 | + if (current->exec_file) { | |
30308 | + fput(current->exec_file); | |
30309 | + current->exec_file = NULL; | |
30310 | + } | |
30311 | + write_unlock(&grsec_exec_file_lock); | |
30312 | +#endif | |
30313 | + | |
30314 | + gr_set_kernel_label(current); | |
30315 | + | |
30316 | /* | |
30317 | * If we were started as result of loading a module, close all of the | |
30318 | * user space pages. We don't need them, and if we didn't close them | |
4dee9bd5 | 30319 | @@ -962,6 +990,9 @@ NORET_TYPE void do_exit(long code) |
da5b3fc8 | 30320 | tsk->exit_code = code; |
50425a20 | 30321 | taskstats_exit(tsk, group_dead); |
30322 | ||
30323 | + gr_acl_handle_psacct(tsk, code); | |
30324 | + gr_acl_handle_exit(); | |
30325 | + | |
30326 | exit_mm(tsk); | |
30327 | ||
30328 | if (group_dead) | |
4dee9bd5 | 30329 | @@ -1171,7 +1202,7 @@ static int wait_task_zombie(struct task_ |
30330 | if (unlikely(noreap)) { | |
8a4b4a5e | 30331 | uid_t uid = p->uid; |
30332 | int exit_code = p->exit_code; | |
30333 | - int why, status; | |
30334 | + int why; | |
30335 | ||
4dee9bd5 | 30336 | get_task_struct(p); |
30337 | read_unlock(&tasklist_lock); | |
30338 | diff -urNp linux-2.6.25.4/kernel/fork.c linux-2.6.25.4/kernel/fork.c | |
30339 | --- linux-2.6.25.4/kernel/fork.c 2008-05-15 11:00:12.000000000 -0400 | |
30340 | +++ linux-2.6.25.4/kernel/fork.c 2008-05-18 13:33:17.000000000 -0400 | |
30341 | @@ -53,6 +53,7 @@ | |
b79bc584 | 30342 | #include <linux/vs_limit.h> |
30343 | #include <linux/vs_memory.h> | |
30344 | #include <linux/vserver/global.h> | |
50425a20 | 30345 | +#include <linux/grsecurity.h> |
30346 | ||
30347 | #include <asm/pgtable.h> | |
30348 | #include <asm/pgalloc.h> | |
4dee9bd5 | 30349 | @@ -194,7 +195,7 @@ static struct task_struct *dup_task_stru |
50425a20 | 30350 | setup_thread_stack(tsk, orig); |
30351 | ||
30352 | #ifdef CONFIG_CC_STACKPROTECTOR | |
30353 | - tsk->stack_canary = get_random_int(); | |
30354 | + tsk->stack_canary = pax_get_random_long(); | |
30355 | #endif | |
30356 | ||
30357 | /* One for us, one for whoever does the "release_task()" (usually parent) */ | |
4dee9bd5 | 30358 | @@ -226,8 +227,8 @@ static int dup_mmap(struct mm_struct *mm |
50425a20 | 30359 | mm->locked_vm = 0; |
30360 | mm->mmap = NULL; | |
30361 | mm->mmap_cache = NULL; | |
30362 | - mm->free_area_cache = oldmm->mmap_base; | |
30363 | - mm->cached_hole_size = ~0UL; | |
30364 | + mm->free_area_cache = oldmm->free_area_cache; | |
30365 | + mm->cached_hole_size = oldmm->cached_hole_size; | |
30366 | mm->map_count = 0; | |
b79bc584 | 30367 | __set_mm_counter(mm, file_rss, 0); |
30368 | __set_mm_counter(mm, anon_rss, 0); | |
4dee9bd5 | 30369 | @@ -264,6 +265,7 @@ static int dup_mmap(struct mm_struct *mm |
8a4b4a5e | 30370 | tmp->vm_flags &= ~VM_LOCKED; |
30371 | tmp->vm_mm = mm; | |
30372 | tmp->vm_next = NULL; | |
30373 | + tmp->vm_mirror = NULL; | |
30374 | anon_vma_link(tmp); | |
30375 | file = tmp->vm_file; | |
30376 | if (file) { | |
4dee9bd5 | 30377 | @@ -300,6 +302,31 @@ static int dup_mmap(struct mm_struct *mm |
8a4b4a5e | 30378 | if (retval) |
30379 | goto out; | |
30380 | } | |
30381 | + | |
30382 | +#ifdef CONFIG_PAX_SEGMEXEC | |
30383 | + if (oldmm->pax_flags & MF_PAX_SEGMEXEC) { | |
da5b3fc8 | 30384 | + struct vm_area_struct *mpnt_m; |
30385 | + | |
8a4b4a5e | 30386 | + for (mpnt = oldmm->mmap, mpnt_m = mm->mmap; mpnt; mpnt = mpnt->vm_next, mpnt_m = mpnt_m->vm_next) { |
30387 | + BUG_ON(!mpnt_m || mpnt_m->vm_mirror || mpnt->vm_mm != oldmm || mpnt_m->vm_mm != mm); | |
30388 | + | |
30389 | + if (!mpnt->vm_mirror) | |
30390 | + continue; | |
30391 | + | |
30392 | + if (mpnt->vm_end <= SEGMEXEC_TASK_SIZE) { | |
30393 | + BUG_ON(mpnt->vm_mirror->vm_mirror != mpnt); | |
30394 | + mpnt->vm_mirror = mpnt_m; | |
30395 | + } else { | |
30396 | + BUG_ON(mpnt->vm_mirror->vm_mirror == mpnt || mpnt->vm_mirror->vm_mirror->vm_mm != mm); | |
30397 | + mpnt_m->vm_mirror = mpnt->vm_mirror->vm_mirror; | |
30398 | + mpnt_m->vm_mirror->vm_mirror = mpnt_m; | |
30399 | + mpnt->vm_mirror->vm_mirror = mpnt; | |
30400 | + } | |
30401 | + } | |
30402 | + BUG_ON(mpnt_m); | |
30403 | + } | |
30404 | +#endif | |
30405 | + | |
30406 | /* a new mm has just been created */ | |
30407 | arch_dup_mmap(oldmm, mm); | |
30408 | retval = 0; | |
4dee9bd5 | 30409 | @@ -482,7 +509,7 @@ void mm_release(struct task_struct *tsk, |
8a4b4a5e | 30410 | if (tsk->clear_child_tid |
30411 | && !(tsk->flags & PF_SIGNALED) | |
30412 | && atomic_read(&mm->mm_users) > 1) { | |
30413 | - u32 __user * tidptr = tsk->clear_child_tid; | |
30414 | + pid_t __user * tidptr = tsk->clear_child_tid; | |
30415 | tsk->clear_child_tid = NULL; | |
30416 | ||
30417 | /* | |
4dee9bd5 | 30418 | @@ -490,7 +517,7 @@ void mm_release(struct task_struct *tsk, |
8a4b4a5e | 30419 | * not set up a proper pointer then tough luck. |
30420 | */ | |
30421 | put_user(0, tidptr); | |
30422 | - sys_futex(tidptr, FUTEX_WAKE, 1, NULL, NULL, 0); | |
30423 | + sys_futex((u32 __user *)tidptr, FUTEX_WAKE, 1, NULL, NULL, 0); | |
64b97ecb | 30424 | } |
8a4b4a5e | 30425 | } |
64b97ecb | 30426 | |
4dee9bd5 | 30427 | @@ -1046,6 +1073,9 @@ static struct task_struct *copy_process( |
b79bc584 | 30428 | DEBUG_LOCKS_WARN_ON(!p->hardirqs_enabled); |
da5b3fc8 | 30429 | DEBUG_LOCKS_WARN_ON(!p->softirqs_enabled); |
30430 | #endif | |
50425a20 | 30431 | + |
30432 | + gr_learn_resource(p, RLIMIT_NPROC, atomic_read(&p->user->processes), 0); | |
30433 | + | |
b79bc584 | 30434 | init_vx_info(&p->vx_info, current->vx_info); |
30435 | init_nx_info(&p->nx_info, current->nx_info); | |
30436 | ||
4dee9bd5 | 30437 | @@ -1212,6 +1242,8 @@ static struct task_struct *copy_process( |
da5b3fc8 | 30438 | if (clone_flags & CLONE_THREAD) |
30439 | p->tgid = current->tgid; | |
50425a20 | 30440 | |
30441 | + gr_copy_label(p); | |
30442 | + | |
30443 | p->set_child_tid = (clone_flags & CLONE_CHILD_SETTID) ? child_tidptr : NULL; | |
30444 | /* | |
30445 | * Clear TID on mm_release()? | |
4dee9bd5 | 30446 | @@ -1401,6 +1433,8 @@ bad_fork_cleanup_count: |
50425a20 | 30447 | bad_fork_free: |
30448 | free_task(p); | |
30449 | fork_out: | |
30450 | + gr_log_forkfail(retval); | |
30451 | + | |
30452 | return ERR_PTR(retval); | |
30453 | } | |
30454 | ||
4dee9bd5 | 30455 | @@ -1493,6 +1527,8 @@ long do_fork(unsigned long clone_flags, |
da5b3fc8 | 30456 | if (clone_flags & CLONE_PARENT_SETTID) |
30457 | put_user(nr, parent_tidptr); | |
50425a20 | 30458 | |
30459 | + gr_handle_brute_check(); | |
30460 | + | |
30461 | if (clone_flags & CLONE_VFORK) { | |
30462 | p->vfork_done = &vfork; | |
30463 | init_completion(&vfork); | |
4dee9bd5 | 30464 | diff -urNp linux-2.6.25.4/kernel/futex.c linux-2.6.25.4/kernel/futex.c |
30465 | --- linux-2.6.25.4/kernel/futex.c 2008-05-15 11:00:12.000000000 -0400 | |
30466 | +++ linux-2.6.25.4/kernel/futex.c 2008-05-18 13:33:17.000000000 -0400 | |
30467 | @@ -195,6 +195,11 @@ static int get_futex_key(u32 __user *uad | |
50425a20 | 30468 | struct page *page; |
30469 | int err; | |
30470 | ||
30471 | +#ifdef CONFIG_PAX_SEGMEXEC | |
da5b3fc8 | 30472 | + if ((mm->pax_flags & MF_PAX_SEGMEXEC) && address >= SEGMEXEC_TASK_SIZE) |
50425a20 | 30473 | + return -EFAULT; |
30474 | +#endif | |
30475 | + | |
30476 | /* | |
30477 | * The futex address must be "naturally" aligned. | |
30478 | */ | |
4dee9bd5 | 30479 | @@ -221,8 +226,8 @@ static int get_futex_key(u32 __user *uad |
50425a20 | 30480 | * The futex is hashed differently depending on whether |
30481 | * it's in a shared or private mapping. So check vma first. | |
30482 | */ | |
30483 | - vma = find_extend_vma(mm, address); | |
30484 | - if (unlikely(!vma)) | |
30485 | + vma = find_vma(mm, address); | |
30486 | + if (unlikely(!vma || address < vma->vm_start)) | |
30487 | return -EFAULT; | |
30488 | ||
30489 | /* | |
4dee9bd5 | 30490 | @@ -1979,7 +1984,7 @@ retry: |
8a4b4a5e | 30491 | */ |
30492 | static inline int fetch_robust_entry(struct robust_list __user **entry, | |
30493 | struct robust_list __user * __user *head, | |
30494 | - int *pi) | |
30495 | + unsigned int *pi) | |
30496 | { | |
30497 | unsigned long uentry; | |
30498 | ||
4dee9bd5 | 30499 | diff -urNp linux-2.6.25.4/kernel/irq/handle.c linux-2.6.25.4/kernel/irq/handle.c |
30500 | --- linux-2.6.25.4/kernel/irq/handle.c 2008-05-15 11:00:12.000000000 -0400 | |
30501 | +++ linux-2.6.25.4/kernel/irq/handle.c 2008-05-18 13:33:17.000000000 -0400 | |
8a4b4a5e | 30502 | @@ -55,7 +55,8 @@ struct irq_desc irq_desc[NR_IRQS] __cach |
50425a20 | 30503 | .depth = 1, |
30504 | .lock = __SPIN_LOCK_UNLOCKED(irq_desc->lock), | |
30505 | #ifdef CONFIG_SMP | |
30506 | - .affinity = CPU_MASK_ALL | |
30507 | + .affinity = CPU_MASK_ALL, | |
30508 | + .cpu = 0, | |
30509 | #endif | |
30510 | } | |
30511 | }; | |
4dee9bd5 | 30512 | diff -urNp linux-2.6.25.4/kernel/kallsyms.c linux-2.6.25.4/kernel/kallsyms.c |
30513 | --- linux-2.6.25.4/kernel/kallsyms.c 2008-05-15 11:00:12.000000000 -0400 | |
30514 | +++ linux-2.6.25.4/kernel/kallsyms.c 2008-05-18 13:33:17.000000000 -0400 | |
30515 | @@ -62,6 +62,19 @@ static inline int is_kernel_text(unsigne | |
50425a20 | 30516 | |
8a4b4a5e | 30517 | static inline int is_kernel(unsigned long addr) |
50425a20 | 30518 | { |
8a4b4a5e | 30519 | + |
30520 | +#ifdef CONFIG_PAX_KERNEXEC | |
89388fe1 | 30521 | + |
30522 | +#ifdef CONFIG_MODULES | |
da5b3fc8 | 30523 | + if ((unsigned long)MODULES_VADDR <= ktla_ktva(addr) && |
30524 | + ktla_ktva(addr) < (unsigned long)MODULES_END) | |
8a4b4a5e | 30525 | + return 0; |
89388fe1 | 30526 | +#endif |
30527 | + | |
8a4b4a5e | 30528 | + if (is_kernel_inittext(addr)) |
50425a20 | 30529 | + return 1; |
8a4b4a5e | 30530 | +#endif |
30531 | + | |
30532 | if (addr >= (unsigned long)_stext && addr <= (unsigned long)_end) | |
30533 | return 1; | |
30534 | return in_gate_area_no_task(addr); | |
4dee9bd5 | 30535 | @@ -366,7 +379,6 @@ static unsigned long get_ksymbol_core(st |
50425a20 | 30536 | |
30537 | static void reset_iter(struct kallsym_iter *iter, loff_t new_pos) | |
30538 | { | |
30539 | - iter->name[0] = '\0'; | |
30540 | iter->nameoff = get_symbol_offset(new_pos); | |
30541 | iter->pos = new_pos; | |
30542 | } | |
4dee9bd5 | 30543 | @@ -450,7 +462,7 @@ static int kallsyms_open(struct inode *i |
50425a20 | 30544 | struct kallsym_iter *iter; |
30545 | int ret; | |
30546 | ||
30547 | - iter = kmalloc(sizeof(*iter), GFP_KERNEL); | |
30548 | + iter = kzalloc(sizeof(*iter), GFP_KERNEL); | |
30549 | if (!iter) | |
30550 | return -ENOMEM; | |
30551 | reset_iter(iter, 0); | |
4dee9bd5 | 30552 | @@ -474,7 +486,15 @@ static int __init kallsyms_init(void) |
50425a20 | 30553 | { |
30554 | struct proc_dir_entry *entry; | |
30555 | ||
30556 | +#ifdef CONFIG_GRKERNSEC_PROC_ADD | |
30557 | +#ifdef CONFIG_GRKERNSEC_PROC_USER | |
30558 | + entry = create_proc_entry("kallsyms", S_IFREG | S_IRUSR, NULL); | |
b2ee8b1e | 30559 | +#elif defined(CONFIG_GRKERNSEC_PROC_USERGROUP) |
50425a20 | 30560 | + entry = create_proc_entry("kallsyms", S_IFREG | S_IRUSR | S_IRGRP, NULL); |
30561 | +#endif | |
30562 | +#else | |
30563 | entry = create_proc_entry("kallsyms", 0444, NULL); | |
30564 | +#endif | |
30565 | if (entry) | |
30566 | entry->proc_fops = &kallsyms_operations; | |
30567 | return 0; | |
4dee9bd5 | 30568 | diff -urNp linux-2.6.25.4/kernel/kmod.c linux-2.6.25.4/kernel/kmod.c |
30569 | --- linux-2.6.25.4/kernel/kmod.c 2008-05-15 11:00:12.000000000 -0400 | |
30570 | +++ linux-2.6.25.4/kernel/kmod.c 2008-05-18 13:33:17.000000000 -0400 | |
da5b3fc8 | 30571 | @@ -107,7 +107,7 @@ int request_module(const char *fmt, ...) |
30572 | return -ENOMEM; | |
30573 | } | |
30574 | ||
30575 | - ret = call_usermodehelper(modprobe_path, argv, envp, 1); | |
30576 | + ret = call_usermodehelper(modprobe_path, argv, envp, UMH_WAIT_PROC); | |
30577 | atomic_dec(&kmod_concurrent); | |
30578 | return ret; | |
30579 | } | |
4dee9bd5 | 30580 | diff -urNp linux-2.6.25.4/kernel/kprobes.c linux-2.6.25.4/kernel/kprobes.c |
30581 | --- linux-2.6.25.4/kernel/kprobes.c 2008-05-15 11:00:12.000000000 -0400 | |
30582 | +++ linux-2.6.25.4/kernel/kprobes.c 2008-05-18 13:33:17.000000000 -0400 | |
da5b3fc8 | 30583 | @@ -162,7 +162,7 @@ kprobe_opcode_t __kprobes *get_insn_slot |
50425a20 | 30584 | * kernel image and loaded module images reside. This is required |
30585 | * so x86_64 can correctly handle the %rip-relative fixups. | |
30586 | */ | |
30587 | - kip->insns = module_alloc(PAGE_SIZE); | |
30588 | + kip->insns = module_alloc_exec(PAGE_SIZE); | |
30589 | if (!kip->insns) { | |
30590 | kfree(kip); | |
30591 | return NULL; | |
da5b3fc8 | 30592 | @@ -194,7 +194,7 @@ static int __kprobes collect_one_slot(st |
83a957c9 | 30593 | hlist_add_head(&kip->hlist, |
30594 | &kprobe_insn_pages); | |
30595 | } else { | |
30596 | - module_free(NULL, kip->insns); | |
30597 | + module_free_exec(NULL, kip->insns); | |
30598 | kfree(kip); | |
30599 | } | |
30600 | return 1; | |
4dee9bd5 | 30601 | diff -urNp linux-2.6.25.4/kernel/lockdep.c linux-2.6.25.4/kernel/lockdep.c |
30602 | --- linux-2.6.25.4/kernel/lockdep.c 2008-05-15 11:00:12.000000000 -0400 | |
30603 | +++ linux-2.6.25.4/kernel/lockdep.c 2008-05-18 13:33:17.000000000 -0400 | |
b7f09679 | 30604 | @@ -598,6 +598,10 @@ static int static_obj(void *obj) |
30605 | int i; | |
30606 | #endif | |
30607 | ||
30608 | +#ifdef CONFIG_PAX_KERNEXEC | |
30609 | + start = (unsigned long )&_data; | |
30610 | +#endif | |
30611 | + | |
30612 | /* | |
30613 | * static variable? | |
30614 | */ | |
84cd3cb1 | 30615 | @@ -609,9 +613,12 @@ static int static_obj(void *obj) |
30616 | * percpu var? | |
30617 | */ | |
30618 | for_each_possible_cpu(i) { | |
30619 | +#ifdef CONFIG_X86_32 | |
30620 | + start = per_cpu_offset(i); | |
30621 | +#else | |
30622 | start = (unsigned long) &__per_cpu_start + per_cpu_offset(i); | |
30623 | - end = (unsigned long) &__per_cpu_start + PERCPU_ENOUGH_ROOM | |
30624 | - + per_cpu_offset(i); | |
30625 | +#endif | |
30626 | + end = start + PERCPU_ENOUGH_ROOM; | |
30627 | ||
30628 | if ((addr >= start) && (addr < end)) | |
30629 | return 1; | |
4dee9bd5 | 30630 | diff -urNp linux-2.6.25.4/kernel/module.c linux-2.6.25.4/kernel/module.c |
30631 | --- linux-2.6.25.4/kernel/module.c 2008-05-15 11:00:12.000000000 -0400 | |
30632 | +++ linux-2.6.25.4/kernel/module.c 2008-05-18 13:33:17.000000000 -0400 | |
da5b3fc8 | 30633 | @@ -45,6 +45,11 @@ |
50425a20 | 30634 | #include <asm/uaccess.h> |
30635 | #include <asm/semaphore.h> | |
30636 | #include <asm/cacheflush.h> | |
30637 | + | |
30638 | +#ifdef CONFIG_PAX_KERNEXEC | |
30639 | +#include <asm/desc.h> | |
30640 | +#endif | |
30641 | + | |
30642 | #include <linux/license.h> | |
4dee9bd5 | 30643 | #include <asm/sections.h> |
50425a20 | 30644 | |
4dee9bd5 | 30645 | @@ -71,6 +76,8 @@ static DECLARE_WAIT_QUEUE_HEAD(module_wq |
50425a20 | 30646 | |
30647 | static BLOCKING_NOTIFIER_HEAD(module_notify_list); | |
30648 | ||
30649 | +extern int gr_check_modstop(void); | |
30650 | + | |
30651 | int register_module_notifier(struct notifier_block * nb) | |
30652 | { | |
30653 | return blocking_notifier_chain_register(&module_notify_list, nb); | |
4dee9bd5 | 30654 | @@ -344,6 +351,8 @@ static inline unsigned int block_size(in |
30655 | return val; | |
30656 | } | |
30657 | ||
30658 | +EXPORT_SYMBOL(__per_cpu_start); | |
30659 | + | |
30660 | static void *percpu_modalloc(unsigned long size, unsigned long align, | |
30661 | const char *name) | |
30662 | { | |
30663 | @@ -351,7 +360,7 @@ static void *percpu_modalloc(unsigned lo | |
8a4b4a5e | 30664 | unsigned int i; |
30665 | void *ptr; | |
30666 | ||
30667 | - if (align > PAGE_SIZE) { | |
30668 | + if (align-1 >= PAGE_SIZE) { | |
30669 | printk(KERN_WARNING "%s: per-cpu alignment %li > %li\n", | |
30670 | name, align, PAGE_SIZE); | |
30671 | align = PAGE_SIZE; | |
84cd3cb1 | 30672 | @@ -433,7 +442,11 @@ static void percpu_modcopy(void *pcpudes |
30673 | int cpu; | |
30674 | ||
30675 | for_each_possible_cpu(cpu) | |
30676 | +#ifdef CONFIG_X86_32 | |
30677 | + memcpy(pcpudest + __per_cpu_offset[cpu], from, size); | |
30678 | +#else | |
30679 | memcpy(pcpudest + per_cpu_offset(cpu), from, size); | |
30680 | +#endif | |
30681 | } | |
30682 | ||
30683 | static int percpu_modinit(void) | |
4dee9bd5 | 30684 | @@ -684,6 +693,9 @@ sys_delete_module(const char __user *nam |
50425a20 | 30685 | char name[MODULE_NAME_LEN]; |
30686 | int ret, forced = 0; | |
30687 | ||
30688 | + if (gr_check_modstop()) | |
30689 | + return -EPERM; | |
30690 | + | |
30691 | if (!capable(CAP_SYS_MODULE)) | |
30692 | return -EPERM; | |
30693 | ||
4dee9bd5 | 30694 | @@ -1347,16 +1359,19 @@ static void free_module(struct module *m |
50425a20 | 30695 | module_unload_free(mod); |
30696 | ||
30697 | /* This may be NULL, but that's OK */ | |
30698 | - module_free(mod, mod->module_init); | |
30699 | + module_free(mod, mod->module_init_rw); | |
30700 | + module_free_exec(mod, mod->module_init_rx); | |
30701 | kfree(mod->args); | |
30702 | if (mod->percpu) | |
30703 | percpu_modfree(mod->percpu); | |
30704 | ||
30705 | /* Free lock-classes: */ | |
30706 | - lockdep_free_key_range(mod->module_core, mod->core_size); | |
30707 | + lockdep_free_key_range(mod->module_core_rx, mod->core_size_rx); | |
30708 | + lockdep_free_key_range(mod->module_core_rw, mod->core_size_rw); | |
30709 | ||
30710 | /* Finally, free the core (containing the module structure) */ | |
30711 | - module_free(mod, mod->module_core); | |
30712 | + module_free_exec(mod, mod->module_core_rx); | |
30713 | + module_free(mod, mod->module_core_rw); | |
30714 | } | |
30715 | ||
30716 | void *__symbol_get(const char *symbol) | |
4dee9bd5 | 30717 | @@ -1421,10 +1436,14 @@ static int simplify_symbols(Elf_Shdr *se |
da5b3fc8 | 30718 | struct module *mod) |
30719 | { | |
30720 | Elf_Sym *sym = (void *)sechdrs[symindex].sh_addr; | |
30721 | - unsigned long secbase; | |
30722 | + unsigned long secbase, symbol; | |
8a4b4a5e | 30723 | unsigned int i, n = sechdrs[symindex].sh_size / sizeof(Elf_Sym); |
30724 | int ret = 0; | |
30725 | ||
30726 | +#ifdef CONFIG_PAX_KERNEXEC | |
30727 | + unsigned long cr0; | |
30728 | +#endif | |
30729 | + | |
30730 | for (i = 1; i < n; i++) { | |
30731 | switch (sym[i].st_shndx) { | |
30732 | case SHN_COMMON: | |
4dee9bd5 | 30733 | @@ -1443,10 +1462,19 @@ static int simplify_symbols(Elf_Shdr *se |
8a4b4a5e | 30734 | break; |
30735 | ||
30736 | case SHN_UNDEF: | |
da5b3fc8 | 30737 | - sym[i].st_value |
30738 | - = resolve_symbol(sechdrs, versindex, | |
30739 | + symbol = resolve_symbol(sechdrs, versindex, | |
30740 | strtab + sym[i].st_name, mod); | |
30741 | ||
8a4b4a5e | 30742 | +#ifdef CONFIG_PAX_KERNEXEC |
30743 | + pax_open_kernel(cr0); | |
30744 | +#endif | |
30745 | + | |
da5b3fc8 | 30746 | + sym[i].st_value = symbol; |
30747 | + | |
8a4b4a5e | 30748 | +#ifdef CONFIG_PAX_KERNEXEC |
30749 | + pax_close_kernel(cr0); | |
30750 | +#endif | |
30751 | + | |
30752 | /* Ok if resolved. */ | |
4dee9bd5 | 30753 | if (!IS_ERR_VALUE(sym[i].st_value)) |
8a4b4a5e | 30754 | break; |
4dee9bd5 | 30755 | @@ -1461,11 +1489,27 @@ static int simplify_symbols(Elf_Shdr *se |
8a4b4a5e | 30756 | |
30757 | default: | |
30758 | /* Divert to percpu allocation if a percpu var. */ | |
30759 | - if (sym[i].st_shndx == pcpuindex) | |
30760 | + if (sym[i].st_shndx == pcpuindex) { | |
30761 | + | |
30762 | +#if defined(CONFIG_X86_32) && defined(CONFIG_SMP) | |
30763 | + secbase = (unsigned long)mod->percpu - (unsigned long)__per_cpu_start; | |
30764 | +#else | |
30765 | secbase = (unsigned long)mod->percpu; | |
30766 | - else | |
30767 | +#endif | |
30768 | + | |
30769 | + } else | |
30770 | secbase = sechdrs[sym[i].st_shndx].sh_addr; | |
30771 | + | |
30772 | +#ifdef CONFIG_PAX_KERNEXEC | |
30773 | + pax_open_kernel(cr0); | |
30774 | +#endif | |
30775 | + | |
30776 | sym[i].st_value += secbase; | |
30777 | + | |
30778 | +#ifdef CONFIG_PAX_KERNEXEC | |
30779 | + pax_close_kernel(cr0); | |
30780 | +#endif | |
30781 | + | |
30782 | break; | |
30783 | } | |
30784 | } | |
4dee9bd5 | 30785 | @@ -1517,11 +1561,14 @@ static void layout_sections(struct modul |
50425a20 | 30786 | || strncmp(secstrings + s->sh_name, |
30787 | ".init", 5) == 0) | |
30788 | continue; | |
30789 | - s->sh_entsize = get_offset(&mod->core_size, s); | |
30790 | + if ((s->sh_flags & SHF_WRITE) || !(s->sh_flags & SHF_ALLOC)) | |
30791 | + s->sh_entsize = get_offset(&mod->core_size_rw, s); | |
30792 | + else | |
30793 | + s->sh_entsize = get_offset(&mod->core_size_rx, s); | |
30794 | DEBUGP("\t%s\n", secstrings + s->sh_name); | |
30795 | } | |
30796 | if (m == 0) | |
30797 | - mod->core_text_size = mod->core_size; | |
30798 | + mod->core_size_rx = mod->core_size_rx; | |
30799 | } | |
30800 | ||
30801 | DEBUGP("Init section allocation order:\n"); | |
4dee9bd5 | 30802 | @@ -1535,12 +1582,15 @@ static void layout_sections(struct modul |
50425a20 | 30803 | || strncmp(secstrings + s->sh_name, |
30804 | ".init", 5) != 0) | |
30805 | continue; | |
30806 | - s->sh_entsize = (get_offset(&mod->init_size, s) | |
30807 | - | INIT_OFFSET_MASK); | |
30808 | + if ((s->sh_flags & SHF_WRITE) || !(s->sh_flags & SHF_ALLOC)) | |
30809 | + s->sh_entsize = get_offset(&mod->init_size_rw, s); | |
30810 | + else | |
30811 | + s->sh_entsize = get_offset(&mod->init_size_rx, s); | |
30812 | + s->sh_entsize |= INIT_OFFSET_MASK; | |
30813 | DEBUGP("\t%s\n", secstrings + s->sh_name); | |
30814 | } | |
30815 | if (m == 0) | |
30816 | - mod->init_text_size = mod->init_size; | |
30817 | + mod->init_size_rx = mod->init_size_rx; | |
30818 | } | |
30819 | } | |
30820 | ||
4dee9bd5 | 30821 | @@ -1667,14 +1717,31 @@ static void add_kallsyms(struct module * |
8a4b4a5e | 30822 | { |
30823 | unsigned int i; | |
30824 | ||
30825 | +#ifdef CONFIG_PAX_KERNEXEC | |
30826 | + unsigned long cr0; | |
30827 | +#endif | |
30828 | + | |
30829 | mod->symtab = (void *)sechdrs[symindex].sh_addr; | |
30830 | mod->num_symtab = sechdrs[symindex].sh_size / sizeof(Elf_Sym); | |
30831 | mod->strtab = (void *)sechdrs[strindex].sh_addr; | |
30832 | ||
30833 | /* Set types up while we still have access to sections. */ | |
da5b3fc8 | 30834 | - for (i = 0; i < mod->num_symtab; i++) |
30835 | - mod->symtab[i].st_info | |
30836 | - = elf_type(&mod->symtab[i], sechdrs, secstrings, mod); | |
30837 | + | |
30838 | + for (i = 0; i < mod->num_symtab; i++) { | |
30839 | + char type = elf_type(&mod->symtab[i], sechdrs, secstrings, mod); | |
8a4b4a5e | 30840 | + |
30841 | +#ifdef CONFIG_PAX_KERNEXEC | |
da5b3fc8 | 30842 | + pax_open_kernel(cr0); |
8a4b4a5e | 30843 | +#endif |
30844 | + | |
da5b3fc8 | 30845 | + mod->symtab[i].st_info = type; |
8a4b4a5e | 30846 | + |
30847 | +#ifdef CONFIG_PAX_KERNEXEC | |
da5b3fc8 | 30848 | + pax_close_kernel(cr0); |
8a4b4a5e | 30849 | +#endif |
da5b3fc8 | 30850 | + |
30851 | + } | |
8a4b4a5e | 30852 | + |
30853 | } | |
30854 | #else | |
30855 | static inline void add_kallsyms(struct module *mod, | |
4dee9bd5 | 30856 | @@ -1724,6 +1791,10 @@ static struct module *load_module(void _ |
50425a20 | 30857 | struct exception_table_entry *extable; |
30858 | mm_segment_t old_fs; | |
30859 | ||
30860 | +#ifdef CONFIG_PAX_KERNEXEC | |
30861 | + unsigned long cr0; | |
30862 | +#endif | |
30863 | + | |
30864 | DEBUGP("load_module: umod=%p, len=%lu, uargs=%p\n", | |
30865 | umod, len, uargs); | |
30866 | if (len < sizeof(*hdr)) | |
4dee9bd5 | 30867 | @@ -1882,21 +1953,57 @@ static struct module *load_module(void _ |
50425a20 | 30868 | layout_sections(mod, hdr, sechdrs, secstrings); |
30869 | ||
30870 | /* Do the allocs. */ | |
30871 | - ptr = module_alloc(mod->core_size); | |
30872 | + ptr = module_alloc(mod->core_size_rw); | |
30873 | if (!ptr) { | |
30874 | err = -ENOMEM; | |
30875 | goto free_percpu; | |
30876 | } | |
30877 | - memset(ptr, 0, mod->core_size); | |
30878 | - mod->module_core = ptr; | |
30879 | + memset(ptr, 0, mod->core_size_rw); | |
30880 | + mod->module_core_rw = ptr; | |
4dee9bd5 | 30881 | + |
50425a20 | 30882 | + ptr = module_alloc(mod->init_size_rw); |
30883 | + if (!ptr && mod->init_size_rw) { | |
30884 | + err = -ENOMEM; | |
30885 | + goto free_core_rw; | |
30886 | + } | |
30887 | + memset(ptr, 0, mod->init_size_rw); | |
30888 | + mod->module_init_rw = ptr; | |
84cd3cb1 | 30889 | |
30890 | - ptr = module_alloc(mod->init_size); | |
30891 | - if (!ptr && mod->init_size) { | |
50425a20 | 30892 | + ptr = module_alloc_exec(mod->core_size_rx); |
30893 | + if (!ptr) { | |
84cd3cb1 | 30894 | err = -ENOMEM; |
30895 | - goto free_core; | |
50425a20 | 30896 | + goto free_init_rw; |
84cd3cb1 | 30897 | } |
30898 | - memset(ptr, 0, mod->init_size); | |
30899 | - mod->module_init = ptr; | |
8a4b4a5e | 30900 | + |
50425a20 | 30901 | +#ifdef CONFIG_PAX_KERNEXEC |
30902 | + pax_open_kernel(cr0); | |
30903 | +#endif | |
30904 | + | |
30905 | + memset(ptr, 0, mod->core_size_rx); | |
da5b3fc8 | 30906 | + |
50425a20 | 30907 | +#ifdef CONFIG_PAX_KERNEXEC |
30908 | + pax_close_kernel(cr0); | |
30909 | +#endif | |
30910 | + | |
30911 | + mod->module_core_rx = ptr; | |
84cd3cb1 | 30912 | + |
50425a20 | 30913 | + ptr = module_alloc_exec(mod->init_size_rx); |
30914 | + if (!ptr && mod->init_size_rx) { | |
84cd3cb1 | 30915 | + err = -ENOMEM; |
50425a20 | 30916 | + goto free_core_rx; |
84cd3cb1 | 30917 | + } |
50425a20 | 30918 | + |
30919 | +#ifdef CONFIG_PAX_KERNEXEC | |
30920 | + pax_open_kernel(cr0); | |
30921 | +#endif | |
30922 | + | |
30923 | + memset(ptr, 0, mod->init_size_rx); | |
30924 | + | |
30925 | +#ifdef CONFIG_PAX_KERNEXEC | |
30926 | + pax_close_kernel(cr0); | |
30927 | +#endif | |
30928 | + | |
30929 | + mod->module_init_rx = ptr; | |
30930 | ||
30931 | /* Transfer each section which specifies SHF_ALLOC */ | |
30932 | DEBUGP("final section addresses:\n"); | |
4dee9bd5 | 30933 | @@ -1906,17 +2013,41 @@ static struct module *load_module(void _ |
50425a20 | 30934 | if (!(sechdrs[i].sh_flags & SHF_ALLOC)) |
30935 | continue; | |
30936 | ||
30937 | - if (sechdrs[i].sh_entsize & INIT_OFFSET_MASK) | |
30938 | - dest = mod->module_init | |
30939 | - + (sechdrs[i].sh_entsize & ~INIT_OFFSET_MASK); | |
30940 | - else | |
30941 | - dest = mod->module_core + sechdrs[i].sh_entsize; | |
30942 | + if (sechdrs[i].sh_entsize & INIT_OFFSET_MASK) { | |
30943 | + if ((sechdrs[i].sh_flags & SHF_WRITE) || !(sechdrs[i].sh_flags & SHF_ALLOC)) | |
30944 | + dest = mod->module_init_rw | |
30945 | + + (sechdrs[i].sh_entsize & ~INIT_OFFSET_MASK); | |
30946 | + else | |
30947 | + dest = mod->module_init_rx | |
30948 | + + (sechdrs[i].sh_entsize & ~INIT_OFFSET_MASK); | |
30949 | + } else { | |
30950 | + if ((sechdrs[i].sh_flags & SHF_WRITE) || !(sechdrs[i].sh_flags & SHF_ALLOC)) | |
30951 | + dest = mod->module_core_rw + sechdrs[i].sh_entsize; | |
30952 | + else | |
30953 | + dest = mod->module_core_rx + sechdrs[i].sh_entsize; | |
30954 | + } | |
8a4b4a5e | 30955 | |
30956 | - if (sechdrs[i].sh_type != SHT_NOBITS) | |
30957 | - memcpy(dest, (void *)sechdrs[i].sh_addr, | |
30958 | - sechdrs[i].sh_size); | |
da5b3fc8 | 30959 | + if (sechdrs[i].sh_type != SHT_NOBITS) { |
50425a20 | 30960 | + |
30961 | +#ifdef CONFIG_PAX_KERNEXEC | |
da5b3fc8 | 30962 | + if (!(sechdrs[i].sh_flags & SHF_WRITE) && (sechdrs[i].sh_flags & SHF_ALLOC)) { |
30963 | + pax_open_kernel(cr0); | |
30964 | + memcpy(dest, (void *)sechdrs[i].sh_addr, sechdrs[i].sh_size); | |
50425a20 | 30965 | + pax_close_kernel(cr0); |
da5b3fc8 | 30966 | + } else |
50425a20 | 30967 | +#endif |
30968 | + | |
da5b3fc8 | 30969 | + memcpy(dest, (void *)sechdrs[i].sh_addr, sechdrs[i].sh_size); |
50425a20 | 30970 | + } |
30971 | /* Update sh_addr to point to copy in image. */ | |
30972 | - sechdrs[i].sh_addr = (unsigned long)dest; | |
30973 | + | |
30974 | +#ifdef CONFIG_PAX_KERNEXEC | |
30975 | + if (sechdrs[i].sh_flags & SHF_EXECINSTR) | |
da5b3fc8 | 30976 | + sechdrs[i].sh_addr = ktva_ktla((unsigned long)dest); |
50425a20 | 30977 | + else |
30978 | +#endif | |
30979 | + | |
30980 | + sechdrs[i].sh_addr = (unsigned long)dest; | |
30981 | DEBUGP("\t0x%lx %s\n", sechdrs[i].sh_addr, secstrings + sechdrs[i].sh_name); | |
30982 | } | |
30983 | /* Module has been moved. */ | |
4dee9bd5 | 30984 | @@ -2057,12 +2188,12 @@ static struct module *load_module(void _ |
50425a20 | 30985 | * Do it before processing of module parameters, so the module |
30986 | * can provide parameter accessor functions of its own. | |
30987 | */ | |
30988 | - if (mod->module_init) | |
30989 | - flush_icache_range((unsigned long)mod->module_init, | |
30990 | - (unsigned long)mod->module_init | |
30991 | - + mod->init_size); | |
30992 | - flush_icache_range((unsigned long)mod->module_core, | |
30993 | - (unsigned long)mod->module_core + mod->core_size); | |
30994 | + if (mod->module_init_rx) | |
30995 | + flush_icache_range((unsigned long)mod->module_init_rx, | |
30996 | + (unsigned long)mod->module_init_rx | |
30997 | + + mod->init_size_rx); | |
30998 | + flush_icache_range((unsigned long)mod->module_core_rx, | |
30999 | + (unsigned long)mod->module_core_rx + mod->core_size_rx); | |
31000 | ||
31001 | set_fs(old_fs); | |
31002 | ||
4dee9bd5 | 31003 | @@ -2115,9 +2246,13 @@ static struct module *load_module(void _ |
31004 | kobject_put(&mod->mkobj.kobj); | |
31005 | free_unload: | |
50425a20 | 31006 | module_unload_free(mod); |
31007 | - module_free(mod, mod->module_init); | |
31008 | - free_core: | |
31009 | - module_free(mod, mod->module_core); | |
31010 | + module_free_exec(mod, mod->module_init_rx); | |
31011 | + free_core_rx: | |
31012 | + module_free_exec(mod, mod->module_core_rx); | |
31013 | + free_init_rw: | |
31014 | + module_free(mod, mod->module_init_rw); | |
31015 | + free_core_rw: | |
31016 | + module_free(mod, mod->module_core_rw); | |
31017 | free_percpu: | |
31018 | if (percpu) | |
31019 | percpu_modfree(percpu); | |
4dee9bd5 | 31020 | @@ -2142,6 +2277,9 @@ sys_init_module(void __user *umod, |
50425a20 | 31021 | struct module *mod; |
31022 | int ret = 0; | |
31023 | ||
31024 | + if (gr_check_modstop()) | |
31025 | + return -EPERM; | |
31026 | + | |
31027 | /* Must have permission */ | |
31028 | if (!capable(CAP_SYS_MODULE)) | |
31029 | return -EPERM; | |
4dee9bd5 | 31030 | @@ -2195,10 +2333,12 @@ sys_init_module(void __user *umod, |
50425a20 | 31031 | /* Drop initial reference. */ |
31032 | module_put(mod); | |
31033 | unwind_remove_table(mod->unwind_info, 1); | |
31034 | - module_free(mod, mod->module_init); | |
31035 | - mod->module_init = NULL; | |
31036 | - mod->init_size = 0; | |
31037 | - mod->init_text_size = 0; | |
31038 | + module_free(mod, mod->module_init_rw); | |
31039 | + module_free_exec(mod, mod->module_init_rx); | |
31040 | + mod->module_init_rw = NULL; | |
31041 | + mod->module_init_rx = NULL; | |
31042 | + mod->init_size_rw = 0; | |
31043 | + mod->init_size_rx = 0; | |
31044 | mutex_unlock(&module_mutex); | |
31045 | ||
31046 | return 0; | |
4dee9bd5 | 31047 | @@ -2206,6 +2346,13 @@ sys_init_module(void __user *umod, |
8a4b4a5e | 31048 | |
31049 | static inline int within(unsigned long addr, void *start, unsigned long size) | |
31050 | { | |
31051 | + | |
31052 | +#ifdef CONFIG_PAX_KERNEXEC | |
da5b3fc8 | 31053 | + if (ktla_ktva(addr) >= (unsigned long)start && |
31054 | + ktla_ktva(addr) < (unsigned long)start + size) | |
8a4b4a5e | 31055 | + return 1; |
31056 | +#endif | |
31057 | + | |
31058 | return ((void *)addr >= start && (void *)addr < start + size); | |
31059 | } | |
31060 | ||
4dee9bd5 | 31061 | @@ -2229,10 +2376,14 @@ static const char *get_ksymbol(struct mo |
50425a20 | 31062 | unsigned long nextval; |
31063 | ||
31064 | /* At worse, next value is at end of module */ | |
31065 | - if (within(addr, mod->module_init, mod->init_size)) | |
31066 | - nextval = (unsigned long)mod->module_init+mod->init_text_size; | |
50425a20 | 31067 | + if (within(addr, mod->module_init_rx, mod->init_size_rx)) |
8a4b4a5e | 31068 | + nextval = (unsigned long)mod->module_init_rx+mod->init_size_rx; |
50425a20 | 31069 | + else if (within(addr, mod->module_init_rw, mod->init_size_rw)) |
8a4b4a5e | 31070 | + nextval = (unsigned long)mod->module_init_rw+mod->init_size_rw; |
50425a20 | 31071 | + else if (within(addr, mod->module_core_rx, mod->core_size_rx)) |
8a4b4a5e | 31072 | + nextval = (unsigned long)mod->module_core_rx+mod->core_size_rx; |
da5b3fc8 | 31073 | else |
31074 | - nextval = (unsigned long)mod->module_core+mod->core_text_size; | |
50425a20 | 31075 | + nextval = (unsigned long)mod->module_core_rw+mod->core_size_rw; |
31076 | ||
31077 | /* Scan for closest preceeding symbol, and next symbol. (ELF | |
da5b3fc8 | 31078 | starts real symbols at 1). */ |
4dee9bd5 | 31079 | @@ -2277,8 +2428,10 @@ const char *module_address_lookup(unsign |
50425a20 | 31080 | |
da5b3fc8 | 31081 | preempt_disable(); |
50425a20 | 31082 | list_for_each_entry(mod, &modules, list) { |
31083 | - if (within(addr, mod->module_init, mod->init_size) | |
31084 | - || within(addr, mod->module_core, mod->core_size)) { | |
8a4b4a5e | 31085 | + if (within(addr, mod->module_init_rx, mod->init_size_rx) || |
31086 | + within(addr, mod->module_init_rw, mod->init_size_rw) || | |
31087 | + within(addr, mod->module_core_rx, mod->core_size_rx) || | |
31088 | + within(addr, mod->module_core_rw, mod->core_size_rw)) { | |
50425a20 | 31089 | if (modname) |
31090 | *modname = mod->name; | |
da5b3fc8 | 31091 | ret = get_ksymbol(mod, addr, size, offset); |
4dee9bd5 | 31092 | @@ -2300,8 +2453,10 @@ int lookup_module_symbol_name(unsigned l |
8a4b4a5e | 31093 | |
da5b3fc8 | 31094 | preempt_disable(); |
8a4b4a5e | 31095 | list_for_each_entry(mod, &modules, list) { |
31096 | - if (within(addr, mod->module_init, mod->init_size) || | |
31097 | - within(addr, mod->module_core, mod->core_size)) { | |
31098 | + if (within(addr, mod->module_init_rx, mod->init_size_rx) || | |
31099 | + within(addr, mod->module_init_rw, mod->init_size_rw) || | |
31100 | + within(addr, mod->module_core_rx, mod->core_size_rx) || | |
31101 | + within(addr, mod->module_core_rw, mod->core_size_rw)) { | |
31102 | const char *sym; | |
31103 | ||
31104 | sym = get_ksymbol(mod, addr, NULL, NULL); | |
4dee9bd5 | 31105 | @@ -2324,8 +2479,10 @@ int lookup_module_symbol_attrs(unsigned |
8a4b4a5e | 31106 | |
da5b3fc8 | 31107 | preempt_disable(); |
8a4b4a5e | 31108 | list_for_each_entry(mod, &modules, list) { |
31109 | - if (within(addr, mod->module_init, mod->init_size) || | |
31110 | - within(addr, mod->module_core, mod->core_size)) { | |
31111 | + if (within(addr, mod->module_init_rx, mod->init_size_rx) || | |
31112 | + within(addr, mod->module_init_rw, mod->init_size_rw) || | |
31113 | + within(addr, mod->module_core_rx, mod->core_size_rx) || | |
31114 | + within(addr, mod->module_core_rw, mod->core_size_rw)) { | |
31115 | const char *sym; | |
31116 | ||
31117 | sym = get_ksymbol(mod, addr, size, offset); | |
4dee9bd5 | 31118 | @@ -2456,7 +2613,7 @@ static int m_show(struct seq_file *m, vo |
50425a20 | 31119 | char buf[8]; |
31120 | ||
31121 | seq_printf(m, "%s %lu", | |
31122 | - mod->name, mod->init_size + mod->core_size); | |
31123 | + mod->name, mod->init_size_rx + mod->init_size_rw + mod->core_size_rx + mod->core_size_rw); | |
31124 | print_unload_info(m, mod); | |
31125 | ||
31126 | /* Informative for users. */ | |
4dee9bd5 | 31127 | @@ -2465,7 +2622,7 @@ static int m_show(struct seq_file *m, vo |
50425a20 | 31128 | mod->state == MODULE_STATE_COMING ? "Loading": |
31129 | "Live"); | |
31130 | /* Used by oprofile and other similar tools. */ | |
31131 | - seq_printf(m, " 0x%p", mod->module_core); | |
31132 | + seq_printf(m, " 0x%p 0x%p", mod->module_core_rx, mod->module_core_rw); | |
31133 | ||
31134 | /* Taints info */ | |
31135 | if (mod->taints) | |
4dee9bd5 | 31136 | @@ -2521,7 +2678,8 @@ int is_module_address(unsigned long addr |
da5b3fc8 | 31137 | preempt_disable(); |
50425a20 | 31138 | |
31139 | list_for_each_entry(mod, &modules, list) { | |
31140 | - if (within(addr, mod->module_core, mod->core_size)) { | |
31141 | + if (within(addr, mod->module_core_rx, mod->core_size_rx) || | |
31142 | + within(addr, mod->module_core_rw, mod->core_size_rw)) { | |
da5b3fc8 | 31143 | preempt_enable(); |
50425a20 | 31144 | return 1; |
31145 | } | |
4dee9bd5 | 31146 | @@ -2539,8 +2697,8 @@ struct module *__module_text_address(uns |
50425a20 | 31147 | struct module *mod; |
31148 | ||
31149 | list_for_each_entry(mod, &modules, list) | |
31150 | - if (within(addr, mod->module_init, mod->init_text_size) | |
31151 | - || within(addr, mod->module_core, mod->core_text_size)) | |
31152 | + if (within(addr, mod->module_init_rx, mod->init_size_rx) | |
31153 | + || within(addr, mod->module_core_rx, mod->core_size_rx)) | |
31154 | return mod; | |
31155 | return NULL; | |
31156 | } | |
4dee9bd5 | 31157 | diff -urNp linux-2.6.25.4/kernel/mutex.c linux-2.6.25.4/kernel/mutex.c |
31158 | --- linux-2.6.25.4/kernel/mutex.c 2008-05-15 11:00:12.000000000 -0400 | |
31159 | +++ linux-2.6.25.4/kernel/mutex.c 2008-05-18 13:33:17.000000000 -0400 | |
da5b3fc8 | 31160 | @@ -82,7 +82,7 @@ __mutex_lock_slowpath(atomic_t *lock_cou |
50425a20 | 31161 | * |
31162 | * This function is similar to (but not equivalent to) down(). | |
31163 | */ | |
4dee9bd5 | 31164 | -void inline __sched mutex_lock(struct mutex *lock) |
31165 | +inline void __sched mutex_lock(struct mutex *lock) | |
50425a20 | 31166 | { |
31167 | might_sleep(); | |
31168 | /* | |
4dee9bd5 | 31169 | diff -urNp linux-2.6.25.4/kernel/panic.c linux-2.6.25.4/kernel/panic.c |
31170 | --- linux-2.6.25.4/kernel/panic.c 2008-05-15 11:00:12.000000000 -0400 | |
31171 | +++ linux-2.6.25.4/kernel/panic.c 2008-05-18 13:33:17.000000000 -0400 | |
31172 | @@ -323,6 +323,8 @@ EXPORT_SYMBOL(warn_on_slowpath); | |
da5b3fc8 | 31173 | */ |
31174 | void __stack_chk_fail(void) | |
31175 | { | |
31176 | + print_symbol("stack corrupted in: %s\n", (unsigned long)__builtin_return_address(0)); | |
31177 | + dump_stack(); | |
31178 | panic("stack-protector: Kernel stack is corrupted"); | |
31179 | } | |
31180 | EXPORT_SYMBOL(__stack_chk_fail); | |
4dee9bd5 | 31181 | diff -urNp linux-2.6.25.4/kernel/pid.c linux-2.6.25.4/kernel/pid.c |
31182 | --- linux-2.6.25.4/kernel/pid.c 2008-05-15 11:00:12.000000000 -0400 | |
31183 | +++ linux-2.6.25.4/kernel/pid.c 2008-05-18 13:33:17.000000000 -0400 | |
da5b3fc8 | 31184 | @@ -35,6 +35,7 @@ |
da5b3fc8 | 31185 | #include <linux/syscalls.h> |
b79bc584 | 31186 | #include <linux/vs_pid.h> |
31187 | #include <linux/vserver/global.h> | |
50425a20 | 31188 | +#include <linux/grsecurity.h> |
31189 | ||
da5b3fc8 | 31190 | #define pid_hashfn(nr, ns) \ |
31191 | hash_long((unsigned long)nr + (unsigned long)ns, pidhash_shift) | |
4dee9bd5 | 31192 | @@ -44,7 +45,7 @@ struct pid init_struct_pid = INIT_STRUCT |
50425a20 | 31193 | |
31194 | int pid_max = PID_MAX_DEFAULT; | |
31195 | ||
31196 | -#define RESERVED_PIDS 300 | |
31197 | +#define RESERVED_PIDS 500 | |
31198 | ||
31199 | int pid_max_min = RESERVED_PIDS + 1; | |
31200 | int pid_max_max = PID_MAX_LIMIT; | |
4dee9bd5 | 31201 | @@ -375,7 +376,14 @@ EXPORT_SYMBOL(pid_task); |
da5b3fc8 | 31202 | struct task_struct *find_task_by_pid_type_ns(int type, int nr, |
31203 | struct pid_namespace *ns) | |
31204 | { | |
31205 | - return pid_task(find_pid_ns(nr, ns), type); | |
31206 | + struct task_struct *task; | |
31207 | + | |
31208 | + task = pid_task(find_pid_ns(nr, ns), type); | |
8a4b4a5e | 31209 | + |
50425a20 | 31210 | + if (gr_pid_is_chrooted(task)) |
31211 | + return NULL; | |
8a4b4a5e | 31212 | + |
da5b3fc8 | 31213 | + return task; |
31214 | } | |
31215 | ||
31216 | EXPORT_SYMBOL(find_task_by_pid_type_ns); | |
4dee9bd5 | 31217 | diff -urNp linux-2.6.25.4/kernel/posix-cpu-timers.c linux-2.6.25.4/kernel/posix-cpu-timers.c |
31218 | --- linux-2.6.25.4/kernel/posix-cpu-timers.c 2008-05-15 11:00:12.000000000 -0400 | |
31219 | +++ linux-2.6.25.4/kernel/posix-cpu-timers.c 2008-05-18 13:33:17.000000000 -0400 | |
50425a20 | 31220 | @@ -6,6 +6,7 @@ |
31221 | #include <linux/posix-timers.h> | |
31222 | #include <asm/uaccess.h> | |
31223 | #include <linux/errno.h> | |
31224 | +#include <linux/grsecurity.h> | |
31225 | ||
31226 | static int check_clock(const clockid_t which_clock) | |
31227 | { | |
4dee9bd5 | 31228 | @@ -1174,6 +1175,7 @@ static void check_process_timers(struct |
50425a20 | 31229 | __group_send_sig_info(SIGKILL, SEND_SIG_PRIV, tsk); |
31230 | return; | |
31231 | } | |
31232 | + gr_learn_resource(tsk, RLIMIT_CPU, psecs, 1); | |
31233 | if (psecs >= sig->rlim[RLIMIT_CPU].rlim_cur) { | |
31234 | /* | |
31235 | * At the soft limit, send a SIGXCPU every second. | |
4dee9bd5 | 31236 | diff -urNp linux-2.6.25.4/kernel/power/poweroff.c linux-2.6.25.4/kernel/power/poweroff.c |
31237 | --- linux-2.6.25.4/kernel/power/poweroff.c 2008-05-15 11:00:12.000000000 -0400 | |
31238 | +++ linux-2.6.25.4/kernel/power/poweroff.c 2008-05-18 13:33:17.000000000 -0400 | |
50425a20 | 31239 | @@ -35,7 +35,7 @@ static struct sysrq_key_op sysrq_powerof |
31240 | .enable_mask = SYSRQ_ENABLE_BOOT, | |
31241 | }; | |
31242 | ||
31243 | -static int pm_sysrq_init(void) | |
31244 | +static int __init pm_sysrq_init(void) | |
31245 | { | |
31246 | register_sysrq_key('o', &sysrq_poweroff_op); | |
31247 | return 0; | |
4dee9bd5 | 31248 | diff -urNp linux-2.6.25.4/kernel/printk.c linux-2.6.25.4/kernel/printk.c |
31249 | --- linux-2.6.25.4/kernel/printk.c 2008-05-15 11:00:12.000000000 -0400 | |
31250 | +++ linux-2.6.25.4/kernel/printk.c 2008-05-18 13:33:17.000000000 -0400 | |
31251 | @@ -32,6 +32,7 @@ | |
4dee9bd5 | 31252 | #include <linux/bootmem.h> |
da5b3fc8 | 31253 | #include <linux/syscalls.h> |
b79bc584 | 31254 | #include <linux/vs_cvirt.h> |
50425a20 | 31255 | +#include <linux/grsecurity.h> |
31256 | ||
31257 | #include <asm/uaccess.h> | |
31258 | ||
4dee9bd5 | 31259 | @@ -299,6 +300,11 @@ int do_syslog(int type, char __user *buf |
50425a20 | 31260 | char c; |
b79bc584 | 31261 | int error; |
50425a20 | 31262 | |
31263 | +#ifdef CONFIG_GRKERNSEC_DMESG | |
31264 | + if (grsec_enable_dmesg && !capable(CAP_SYS_ADMIN)) | |
31265 | + return -EPERM; | |
31266 | +#endif | |
31267 | + | |
31268 | error = security_syslog(type); | |
31269 | if (error) | |
31270 | return error; | |
4dee9bd5 | 31271 | diff -urNp linux-2.6.25.4/kernel/ptrace.c linux-2.6.25.4/kernel/ptrace.c |
31272 | --- linux-2.6.25.4/kernel/ptrace.c 2008-05-15 11:00:12.000000000 -0400 | |
31273 | +++ linux-2.6.25.4/kernel/ptrace.c 2008-05-18 13:33:17.000000000 -0400 | |
31274 | @@ -21,6 +21,7 @@ | |
da5b3fc8 | 31275 | #include <linux/pid_namespace.h> |
4dee9bd5 | 31276 | #include <linux/syscalls.h> |
b79bc584 | 31277 | #include <linux/vs_context.h> |
50425a20 | 31278 | +#include <linux/grsecurity.h> |
31279 | ||
31280 | #include <asm/pgtable.h> | |
31281 | #include <asm/uaccess.h> | |
4dee9bd5 | 31282 | @@ -140,12 +141,12 @@ int __ptrace_may_attach(struct task_stru |
50425a20 | 31283 | (current->uid != task->uid) || |
31284 | (current->gid != task->egid) || | |
31285 | (current->gid != task->sgid) || | |
31286 | - (current->gid != task->gid)) && !capable(CAP_SYS_PTRACE)) | |
31287 | + (current->gid != task->gid)) && !capable_nolog(CAP_SYS_PTRACE)) | |
31288 | return -EPERM; | |
31289 | smp_rmb(); | |
31290 | if (task->mm) | |
da5b3fc8 | 31291 | dumpable = get_dumpable(task->mm); |
50425a20 | 31292 | - if (!dumpable && !capable(CAP_SYS_PTRACE)) |
31293 | + if (!dumpable && !capable_nolog(CAP_SYS_PTRACE)) | |
31294 | return -EPERM; | |
b79bc584 | 31295 | if (!vx_check(task->xid, VS_ADMIN_P|VS_IDENT)) |
31296 | return -EPERM; | |
b2ee8b1e | 31297 | @@ -203,7 +204,7 @@ repeat: |
4dee9bd5 | 31298 | |
b2ee8b1e | 31299 | /* Go */ |
4dee9bd5 | 31300 | task->ptrace |= PT_PTRACED; |
b2ee8b1e | 31301 | - if (capable(CAP_SYS_PTRACE)) |
31302 | + if (capable_nolog(CAP_SYS_PTRACE)) | |
31303 | task->ptrace |= PT_PTRACE_CAP; | |
31304 | ||
31305 | __ptrace_link(task, current); | |
4dee9bd5 | 31306 | @@ -577,6 +578,11 @@ asmlinkage long sys_ptrace(long request, |
50425a20 | 31307 | if (ret < 0) |
31308 | goto out_put_task_struct; | |
31309 | ||
31310 | + if (gr_handle_ptrace(child, request)) { | |
31311 | + ret = -EPERM; | |
31312 | + goto out_put_task_struct; | |
31313 | + } | |
31314 | + | |
31315 | ret = arch_ptrace(child, request, addr, data); | |
31316 | if (ret < 0) | |
31317 | goto out_put_task_struct; | |
4dee9bd5 | 31318 | diff -urNp linux-2.6.25.4/kernel/relay.c linux-2.6.25.4/kernel/relay.c |
31319 | --- linux-2.6.25.4/kernel/relay.c 2008-05-15 11:00:12.000000000 -0400 | |
31320 | +++ linux-2.6.25.4/kernel/relay.c 2008-05-18 13:33:17.000000000 -0400 | |
31321 | @@ -1140,7 +1140,7 @@ static int subbuf_splice_actor(struct fi | |
da5b3fc8 | 31322 | return 0; |
31323 | ||
31324 | ret = *nonpad_ret = splice_to_pipe(pipe, &spd); | |
31325 | - if (ret < 0 || ret < total_len) | |
31326 | + if ((int)ret < 0 || ret < total_len) | |
31327 | return ret; | |
31328 | ||
31329 | if (read_start + ret == nonpad_end) | |
4dee9bd5 | 31330 | diff -urNp linux-2.6.25.4/kernel/resource.c linux-2.6.25.4/kernel/resource.c |
31331 | --- linux-2.6.25.4/kernel/resource.c 2008-05-15 11:00:12.000000000 -0400 | |
31332 | +++ linux-2.6.25.4/kernel/resource.c 2008-05-18 13:33:17.000000000 -0400 | |
50425a20 | 31333 | @@ -133,10 +133,27 @@ static int __init ioresources_init(void) |
31334 | { | |
31335 | struct proc_dir_entry *entry; | |
31336 | ||
31337 | +#ifdef CONFIG_GRKERNSEC_PROC_ADD | |
31338 | +#ifdef CONFIG_GRKERNSEC_PROC_USER | |
31339 | + entry = create_proc_entry("ioports", S_IRUSR, NULL); | |
b2ee8b1e | 31340 | +#elif defined(CONFIG_GRKERNSEC_PROC_USERGROUP) |
50425a20 | 31341 | + entry = create_proc_entry("ioports", S_IRUSR | S_IRGRP, NULL); |
31342 | +#endif | |
31343 | +#else | |
31344 | entry = create_proc_entry("ioports", 0, NULL); | |
31345 | +#endif | |
31346 | if (entry) | |
31347 | entry->proc_fops = &proc_ioports_operations; | |
31348 | + | |
31349 | +#ifdef CONFIG_GRKERNSEC_PROC_ADD | |
31350 | +#ifdef CONFIG_GRKERNSEC_PROC_USER | |
31351 | + entry = create_proc_entry("iomem", S_IRUSR, NULL); | |
b2ee8b1e | 31352 | +#elif defined(CONFIG_GRKERNSEC_PROC_USERGROUP) |
50425a20 | 31353 | + entry = create_proc_entry("iomem", S_IRUSR | S_IRGRP, NULL); |
31354 | +#endif | |
31355 | +#else | |
31356 | entry = create_proc_entry("iomem", 0, NULL); | |
31357 | +#endif | |
31358 | if (entry) | |
31359 | entry->proc_fops = &proc_iomem_operations; | |
31360 | return 0; | |
4dee9bd5 | 31361 | diff -urNp linux-2.6.25.4/kernel/sched.c linux-2.6.25.4/kernel/sched.c |
31362 | --- linux-2.6.25.4/kernel/sched.c 2008-05-15 11:00:12.000000000 -0400 | |
31363 | +++ linux-2.6.25.4/kernel/sched.c 2008-05-18 13:33:17.000000000 -0400 | |
31364 | @@ -66,6 +66,7 @@ | |
4dee9bd5 | 31365 | #include <linux/hrtimer.h> |
b79bc584 | 31366 | #include <linux/vs_sched.h> |
31367 | #include <linux/vs_cvirt.h> | |
50425a20 | 31368 | +#include <linux/grsecurity.h> |
50425a20 | 31369 | |
8a4b4a5e | 31370 | #include <asm/tlb.h> |
da5b3fc8 | 31371 | #include <asm/irq_regs.h> |
4dee9bd5 | 31372 | @@ -4499,7 +4500,8 @@ asmlinkage long sys_nice(int increment) |
50425a20 | 31373 | if (nice > 19) |
31374 | nice = 19; | |
31375 | ||
31376 | - if (increment < 0 && !can_nice(current, nice)) | |
31377 | + if (increment < 0 && (!can_nice(current, nice) || | |
31378 | + gr_handle_chroot_nice())) | |
b79bc584 | 31379 | return vx_flags(VXF_IGNEG_NICE, 0) ? 0 : -EPERM; |
50425a20 | 31380 | |
31381 | retval = security_task_setnice(current, nice); | |
4dee9bd5 | 31382 | @@ -5741,7 +5743,7 @@ static struct ctl_table sd_ctl_dir[] = { |
da5b3fc8 | 31383 | .procname = "sched_domain", |
31384 | .mode = 0555, | |
31385 | }, | |
31386 | - {0, }, | |
4dee9bd5 | 31387 | + { 0, NULL, NULL, 0, 0, NULL, NULL, NULL, NULL, NULL, NULL } |
da5b3fc8 | 31388 | }; |
31389 | ||
31390 | static struct ctl_table sd_ctl_root[] = { | |
4dee9bd5 | 31391 | @@ -5751,7 +5753,7 @@ static struct ctl_table sd_ctl_root[] = |
da5b3fc8 | 31392 | .mode = 0555, |
31393 | .child = sd_ctl_dir, | |
31394 | }, | |
31395 | - {0, }, | |
4dee9bd5 | 31396 | + { 0, NULL, NULL, 0, 0, NULL, NULL, NULL, NULL, NULL, NULL } |
da5b3fc8 | 31397 | }; |
31398 | ||
31399 | static struct ctl_table *sd_alloc_ctl_entry(int n) | |
4dee9bd5 | 31400 | diff -urNp linux-2.6.25.4/kernel/signal.c linux-2.6.25.4/kernel/signal.c |
31401 | --- linux-2.6.25.4/kernel/signal.c 2008-05-15 11:00:12.000000000 -0400 | |
31402 | +++ linux-2.6.25.4/kernel/signal.c 2008-05-18 13:33:17.000000000 -0400 | |
50425a20 | 31403 | @@ -25,6 +25,7 @@ |
31404 | #include <linux/capability.h> | |
31405 | #include <linux/freezer.h> | |
31406 | #include <linux/pid_namespace.h> | |
31407 | +#include <linux/grsecurity.h> | |
31408 | #include <linux/nsproxy.h> | |
b79bc584 | 31409 | #include <linux/vs_context.h> |
31410 | #include <linux/vs_pid.h> | |
da5b3fc8 | 31411 | @@ -540,7 +541,9 @@ static int check_kill_permission(int sig |
31412 | && (current->euid ^ t->suid) && (current->euid ^ t->uid) | |
31413 | && (current->uid ^ t->suid) && (current->uid ^ t->uid) | |
31414 | && !capable(CAP_KILL)) | |
31415 | - return error; | |
31416 | + return error; | |
31417 | + if (gr_handle_signal(t, sig)) | |
31418 | + return error; | |
31419 | } | |
50425a20 | 31420 | |
b79bc584 | 31421 | error = -ESRCH; |
da5b3fc8 | 31422 | @@ -757,7 +760,7 @@ static int __init setup_print_fatal_sign |
50425a20 | 31423 | |
da5b3fc8 | 31424 | __setup("print-fatal-signals=", setup_print_fatal_signals); |
50425a20 | 31425 | |
31426 | -static int | |
31427 | +int | |
31428 | specific_send_sig_info(int sig, struct siginfo *info, struct task_struct *t) | |
31429 | { | |
31430 | int ret = 0; | |
da5b3fc8 | 31431 | @@ -811,8 +814,12 @@ force_sig_info(int sig, struct siginfo * |
50425a20 | 31432 | } |
31433 | } | |
31434 | ret = specific_send_sig_info(sig, info, t); | |
31435 | + | |
da5b3fc8 | 31436 | spin_unlock_irqrestore(&t->sighand->siglock, flags); |
31437 | ||
50425a20 | 31438 | + gr_log_signal(sig, t); |
31439 | + gr_handle_crash(t, sig); | |
31440 | + | |
50425a20 | 31441 | return ret; |
da5b3fc8 | 31442 | } |
31443 | ||
4dee9bd5 | 31444 | diff -urNp linux-2.6.25.4/kernel/softirq.c linux-2.6.25.4/kernel/softirq.c |
31445 | --- linux-2.6.25.4/kernel/softirq.c 2008-05-15 11:00:12.000000000 -0400 | |
31446 | +++ linux-2.6.25.4/kernel/softirq.c 2008-05-18 13:33:17.000000000 -0400 | |
31447 | @@ -475,9 +475,9 @@ void tasklet_kill(struct tasklet_struct | |
8a4b4a5e | 31448 | printk("Attempt to kill tasklet from interrupt\n"); |
31449 | ||
31450 | while (test_and_set_bit(TASKLET_STATE_SCHED, &t->state)) { | |
31451 | - do | |
31452 | + do { | |
31453 | yield(); | |
31454 | - while (test_bit(TASKLET_STATE_SCHED, &t->state)); | |
31455 | + } while (test_bit(TASKLET_STATE_SCHED, &t->state)); | |
31456 | } | |
31457 | tasklet_unlock_wait(t); | |
31458 | clear_bit(TASKLET_STATE_SCHED, &t->state); | |
4dee9bd5 | 31459 | diff -urNp linux-2.6.25.4/kernel/sys.c linux-2.6.25.4/kernel/sys.c |
31460 | --- linux-2.6.25.4/kernel/sys.c 2008-05-15 11:00:12.000000000 -0400 | |
31461 | +++ linux-2.6.25.4/kernel/sys.c 2008-05-18 13:33:17.000000000 -0400 | |
da5b3fc8 | 31462 | @@ -33,6 +33,7 @@ |
8a4b4a5e | 31463 | #include <linux/task_io_accounting_ops.h> |
da5b3fc8 | 31464 | #include <linux/seccomp.h> |
31465 | #include <linux/cpu.h> | |
50425a20 | 31466 | +#include <linux/grsecurity.h> |
31467 | ||
31468 | #include <linux/compat.h> | |
31469 | #include <linux/syscalls.h> | |
da5b3fc8 | 31470 | @@ -119,6 +120,12 @@ static int set_one_prio(struct task_stru |
31471 | error = -EACCES; | |
50425a20 | 31472 | goto out; |
31473 | } | |
31474 | + | |
31475 | + if (gr_handle_chroot_setpriority(p, niceval)) { | |
31476 | + error = -EACCES; | |
31477 | + goto out; | |
31478 | + } | |
31479 | + | |
31480 | no_nice = security_task_setnice(p, niceval); | |
31481 | if (no_nice) { | |
31482 | error = no_nice; | |
da5b3fc8 | 31483 | @@ -175,10 +182,10 @@ asmlinkage long sys_setpriority(int whic |
31484 | if ((who != current->uid) && !(user = find_user(who))) | |
8a4b4a5e | 31485 | goto out_unlock; /* No processes for this user */ |
31486 | ||
31487 | - do_each_thread(g, p) | |
31488 | + do_each_thread(g, p) { | |
31489 | if (p->uid == who) | |
31490 | error = set_one_prio(p, niceval, error); | |
31491 | - while_each_thread(g, p); | |
31492 | + } while_each_thread(g, p); | |
31493 | if (who != current->uid) | |
31494 | free_uid(user); /* For find_user() */ | |
31495 | break; | |
da5b3fc8 | 31496 | @@ -237,13 +244,13 @@ asmlinkage long sys_getpriority(int whic |
31497 | if ((who != current->uid) && !(user = find_user(who))) | |
8a4b4a5e | 31498 | goto out_unlock; /* No processes for this user */ |
31499 | ||
31500 | - do_each_thread(g, p) | |
31501 | + do_each_thread(g, p) { | |
31502 | if (p->uid == who) { | |
31503 | niceval = 20 - task_nice(p); | |
31504 | if (niceval > retval) | |
31505 | retval = niceval; | |
31506 | } | |
31507 | - while_each_thread(g, p); | |
31508 | + } while_each_thread(g, p); | |
31509 | if (who != current->uid) | |
31510 | free_uid(user); /* for find_user() */ | |
31511 | break; | |
4dee9bd5 | 31512 | @@ -508,6 +515,10 @@ asmlinkage long sys_setregid(gid_t rgid, |
31513 | else | |
31514 | return -EPERM; | |
31515 | } | |
31516 | + | |
31517 | + if (gr_check_group_change(new_rgid, new_egid, -1)) | |
31518 | + return -EPERM; | |
31519 | + | |
31520 | if (new_egid != old_egid) { | |
31521 | set_dumpable(current->mm, suid_dumpable); | |
31522 | smp_wmb(); | |
31523 | @@ -515,6 +526,9 @@ asmlinkage long sys_setregid(gid_t rgid, | |
50425a20 | 31524 | if (rgid != (gid_t) -1 || |
31525 | (egid != (gid_t) -1 && egid != old_rgid)) | |
31526 | current->sgid = new_egid; | |
31527 | + | |
31528 | + gr_set_role_label(current, current->uid, new_rgid); | |
31529 | + | |
31530 | current->fsgid = new_egid; | |
31531 | current->egid = new_egid; | |
31532 | current->gid = new_rgid; | |
4dee9bd5 | 31533 | @@ -537,11 +551,17 @@ asmlinkage long sys_setgid(gid_t gid) |
31534 | if (retval) | |
31535 | return retval; | |
31536 | ||
31537 | + if (gr_check_group_change(gid, gid, gid)) | |
31538 | + return -EPERM; | |
31539 | + | |
31540 | if (capable(CAP_SETGID)) { | |
31541 | if (old_egid != gid) { | |
da5b3fc8 | 31542 | set_dumpable(current->mm, suid_dumpable); |
50425a20 | 31543 | smp_wmb(); |
31544 | } | |
31545 | + | |
31546 | + gr_set_role_label(current, current->uid, gid); | |
31547 | + | |
31548 | current->gid = current->egid = current->sgid = current->fsgid = gid; | |
31549 | } else if ((gid == current->gid) || (gid == current->sgid)) { | |
31550 | if (old_egid != gid) { | |
4dee9bd5 | 31551 | @@ -579,6 +599,9 @@ static int set_user(uid_t new_ruid, int |
da5b3fc8 | 31552 | set_dumpable(current->mm, suid_dumpable); |
50425a20 | 31553 | smp_wmb(); |
31554 | } | |
31555 | + | |
31556 | + gr_set_role_label(current, new_ruid, current->gid); | |
31557 | + | |
31558 | current->uid = new_ruid; | |
31559 | return 0; | |
31560 | } | |
4dee9bd5 | 31561 | @@ -628,6 +651,9 @@ asmlinkage long sys_setreuid(uid_t ruid, |
31562 | return -EPERM; | |
31563 | } | |
50425a20 | 31564 | |
4dee9bd5 | 31565 | + if (gr_check_user_change(new_ruid, new_euid, -1)) |
31566 | + return -EPERM; | |
31567 | + | |
31568 | if (new_ruid != old_ruid && set_user(new_ruid, new_euid != old_euid) < 0) | |
31569 | return -EAGAIN; | |
31570 | ||
31571 | @@ -674,6 +700,12 @@ asmlinkage long sys_setuid(uid_t uid) | |
31572 | old_suid = current->suid; | |
31573 | new_suid = old_suid; | |
31574 | ||
50425a20 | 31575 | + if (gr_check_crash_uid(uid)) |
31576 | + return -EPERM; | |
31577 | + | |
4dee9bd5 | 31578 | + if (gr_check_user_change(uid, uid, uid)) |
31579 | + return -EPERM; | |
31580 | + | |
31581 | if (capable(CAP_SETUID)) { | |
31582 | if (uid != old_ruid && set_user(uid, old_euid != uid) < 0) | |
31583 | return -EAGAIN; | |
31584 | @@ -721,6 +753,10 @@ asmlinkage long sys_setresuid(uid_t ruid | |
31585 | (suid != current->euid) && (suid != current->suid)) | |
31586 | return -EPERM; | |
31587 | } | |
31588 | + | |
31589 | + if (gr_check_user_change(ruid, euid, -1)) | |
31590 | + return -EPERM; | |
31591 | + | |
31592 | if (ruid != (uid_t) -1) { | |
31593 | if (ruid != current->uid && set_user(ruid, euid != current->euid) < 0) | |
31594 | return -EAGAIN; | |
31595 | @@ -775,6 +811,10 @@ asmlinkage long sys_setresgid(gid_t rgid | |
31596 | (sgid != current->egid) && (sgid != current->sgid)) | |
31597 | return -EPERM; | |
31598 | } | |
31599 | + | |
31600 | + if (gr_check_group_change(rgid, egid, -1)) | |
31601 | + return -EPERM; | |
31602 | + | |
31603 | if (egid != (gid_t) -1) { | |
31604 | if (egid != current->egid) { | |
31605 | set_dumpable(current->mm, suid_dumpable); | |
31606 | @@ -783,8 +823,10 @@ asmlinkage long sys_setresgid(gid_t rgid | |
50425a20 | 31607 | current->egid = egid; |
31608 | } | |
31609 | current->fsgid = current->egid; | |
31610 | - if (rgid != (gid_t) -1) | |
31611 | + if (rgid != (gid_t) -1) { | |
31612 | + gr_set_role_label(current, current->uid, rgid); | |
31613 | current->gid = rgid; | |
31614 | + } | |
31615 | if (sgid != (gid_t) -1) | |
31616 | current->sgid = sgid; | |
31617 | ||
4dee9bd5 | 31618 | @@ -819,6 +861,9 @@ asmlinkage long sys_setfsuid(uid_t uid) |
31619 | if (security_task_setuid(uid, (uid_t)-1, (uid_t)-1, LSM_SETID_FS)) | |
31620 | return old_fsuid; | |
31621 | ||
31622 | + if (gr_check_user_change(-1, -1, uid)) | |
31623 | + return old_fsuid; | |
31624 | + | |
31625 | if (uid == current->uid || uid == current->euid || | |
31626 | uid == current->suid || uid == current->fsuid || | |
31627 | capable(CAP_SETUID)) { | |
31628 | @@ -851,6 +896,9 @@ asmlinkage long sys_setfsgid(gid_t gid) | |
31629 | if (gid == current->gid || gid == current->egid || | |
31630 | gid == current->sgid || gid == current->fsgid || | |
31631 | capable(CAP_SETGID)) { | |
31632 | + if (gr_check_group_change(-1, -1, gid)) | |
31633 | + return old_fsgid; | |
31634 | + | |
31635 | if (gid != old_fsgid) { | |
31636 | set_dumpable(current->mm, suid_dumpable); | |
31637 | smp_wmb(); | |
31638 | @@ -932,7 +980,10 @@ asmlinkage long sys_setpgid(pid_t pid, p | |
50425a20 | 31639 | write_lock_irq(&tasklist_lock); |
31640 | ||
31641 | err = -ESRCH; | |
4dee9bd5 | 31642 | - p = find_task_by_vpid(pid); |
31643 | + /* grsec: replaced find_task_by_vpid with equivalent call which | |
da5b3fc8 | 31644 | + lacks the chroot restriction |
50425a20 | 31645 | + */ |
4dee9bd5 | 31646 | + p = pid_task(find_pid_ns(pid, current->nsproxy->pid_ns), PIDTYPE_PID); |
50425a20 | 31647 | if (!p) |
31648 | goto out; | |
31649 | ||
4dee9bd5 | 31650 | @@ -1647,7 +1698,7 @@ asmlinkage long sys_prctl(int option, un |
da5b3fc8 | 31651 | error = get_dumpable(current->mm); |
50425a20 | 31652 | break; |
31653 | case PR_SET_DUMPABLE: | |
31654 | - if (arg2 < 0 || arg2 > 1) { | |
31655 | + if (arg2 > 1) { | |
31656 | error = -EINVAL; | |
31657 | break; | |
31658 | } | |
4dee9bd5 | 31659 | diff -urNp linux-2.6.25.4/kernel/sysctl.c linux-2.6.25.4/kernel/sysctl.c |
31660 | --- linux-2.6.25.4/kernel/sysctl.c 2008-05-15 11:00:12.000000000 -0400 | |
31661 | +++ linux-2.6.25.4/kernel/sysctl.c 2008-05-18 13:33:17.000000000 -0400 | |
da5b3fc8 | 31662 | @@ -58,6 +58,13 @@ |
31663 | static int deprecated_sysctl_warning(struct __sysctl_args *args); | |
50425a20 | 31664 | |
31665 | #if defined(CONFIG_SYSCTL) | |
31666 | +#include <linux/grsecurity.h> | |
31667 | +#include <linux/grinternal.h> | |
31668 | + | |
e87b9006 | 31669 | +extern __u32 gr_handle_sysctl(const ctl_table *table, const int op); |
50425a20 | 31670 | +extern int gr_handle_sysctl_mod(const char *dirname, const char *name, |
31671 | + const int op); | |
31672 | +extern int gr_handle_chroot_sysctl(const int op); | |
31673 | ||
31674 | /* External variables not in a header file. */ | |
31675 | extern int C_A_D; | |
4dee9bd5 | 31676 | @@ -156,6 +163,7 @@ static int proc_do_cad_pid(struct ctl_ta |
da5b3fc8 | 31677 | static int proc_dointvec_taint(struct ctl_table *table, int write, struct file *filp, |
31678 | void __user *buffer, size_t *lenp, loff_t *ppos); | |
31679 | #endif | |
31680 | +extern ctl_table grsecurity_table[]; | |
50425a20 | 31681 | |
da5b3fc8 | 31682 | static struct ctl_table root_table[]; |
4dee9bd5 | 31683 | static struct ctl_table_root sysctl_table_root; |
31684 | @@ -183,6 +191,21 @@ extern struct ctl_table inotify_table[]; | |
50425a20 | 31685 | int sysctl_legacy_va_layout; |
31686 | #endif | |
31687 | ||
31688 | +#ifdef CONFIG_PAX_SOFTMODE | |
31689 | +static ctl_table pax_table[] = { | |
31690 | + { | |
da5b3fc8 | 31691 | + .ctl_name = CTL_UNNUMBERED, |
50425a20 | 31692 | + .procname = "softmode", |
31693 | + .data = &pax_softmode, | |
31694 | + .maxlen = sizeof(unsigned int), | |
31695 | + .mode = 0600, | |
31696 | + .proc_handler = &proc_dointvec, | |
31697 | + }, | |
31698 | + | |
31699 | + { .ctl_name = 0 } | |
31700 | +}; | |
31701 | +#endif | |
da5b3fc8 | 31702 | + |
31703 | extern int prove_locking; | |
31704 | extern int lock_stat; | |
50425a20 | 31705 | |
4dee9bd5 | 31706 | @@ -219,6 +242,7 @@ static struct ctl_table root_table[] = { |
50425a20 | 31707 | .mode = 0555, |
31708 | .child = dev_table, | |
31709 | }, | |
50425a20 | 31710 | + |
da5b3fc8 | 31711 | /* |
31712 | * NOTE: do not add new entries to this table unless you have read | |
31713 | * Documentation/sysctl/ctl_unnumbered.txt | |
4dee9bd5 | 31714 | @@ -820,6 +844,24 @@ static struct ctl_table kern_table[] = { |
da5b3fc8 | 31715 | .proc_handler = &proc_dostring, |
31716 | .strategy = &sysctl_string, | |
31717 | }, | |
31718 | +#if defined(CONFIG_GRKERNSEC_SYSCTL) || defined(CONFIG_GRKERNSEC_MODSTOP) | |
31719 | + { | |
31720 | + .ctl_name = CTL_UNNUMBERED, | |
31721 | + .procname = "grsecurity", | |
31722 | + .mode = 0500, | |
31723 | + .child = grsecurity_table, | |
31724 | + }, | |
31725 | +#endif | |
4dee9bd5 | 31726 | + |
31727 | +#ifdef CONFIG_PAX_SOFTMODE | |
31728 | + { | |
31729 | + .ctl_name = CTL_UNNUMBERED, | |
31730 | + .procname = "pax", | |
31731 | + .mode = 0500, | |
31732 | + .child = pax_table, | |
31733 | + }, | |
31734 | +#endif | |
31735 | + | |
da5b3fc8 | 31736 | /* |
31737 | * NOTE: do not add new entries to this table unless you have read | |
31738 | * Documentation/sysctl/ctl_unnumbered.txt | |
4dee9bd5 | 31739 | @@ -1507,6 +1549,25 @@ static int test_perm(int mode, int op) |
da5b3fc8 | 31740 | int sysctl_perm(struct ctl_table *table, int op) |
50425a20 | 31741 | { |
31742 | int error; | |
31743 | + if (table->parent != NULL && table->parent->procname != NULL && | |
31744 | + table->procname != NULL && | |
31745 | + gr_handle_sysctl_mod(table->parent->procname, table->procname, op)) | |
31746 | + return -EACCES; | |
31747 | + if (gr_handle_chroot_sysctl(op)) | |
31748 | + return -EACCES; | |
78fdc4fb | 31749 | + error = gr_handle_sysctl(table, op); |
31750 | + if (error) | |
31751 | + return error; | |
e87b9006 | 31752 | + error = security_sysctl(table, op); |
31753 | + if (error) | |
31754 | + return error; | |
31755 | + return test_perm(table->mode, op); | |
31756 | +} | |
31757 | + | |
31758 | +int sysctl_perm_nochk(ctl_table *table, int op) | |
31759 | +{ | |
31760 | + int error; | |
31761 | + | |
50425a20 | 31762 | error = security_sysctl(table, op); |
31763 | if (error) | |
31764 | return error; | |
4dee9bd5 | 31765 | @@ -1531,13 +1592,14 @@ repeat: |
e87b9006 | 31766 | if (n == table->ctl_name) { |
31767 | int error; | |
31768 | if (table->child) { | |
31769 | - if (sysctl_perm(table, 001)) | |
31770 | + if (sysctl_perm_nochk(table, 001)) | |
31771 | return -EPERM; | |
31772 | name++; | |
31773 | nlen--; | |
50425a20 | 31774 | table = table->child; |
31775 | goto repeat; | |
31776 | } | |
50425a20 | 31777 | + |
31778 | error = do_sysctl_strategy(table, name, nlen, | |
31779 | oldval, oldlenp, | |
31780 | newval, newlen); | |
4dee9bd5 | 31781 | diff -urNp linux-2.6.25.4/kernel/time.c linux-2.6.25.4/kernel/time.c |
31782 | --- linux-2.6.25.4/kernel/time.c 2008-05-15 11:00:12.000000000 -0400 | |
31783 | +++ linux-2.6.25.4/kernel/time.c 2008-05-18 13:33:17.000000000 -0400 | |
8a4b4a5e | 31784 | @@ -35,6 +35,7 @@ |
da5b3fc8 | 31785 | #include <linux/syscalls.h> |
50425a20 | 31786 | #include <linux/security.h> |
31787 | #include <linux/fs.h> | |
50425a20 | 31788 | +#include <linux/grsecurity.h> |
31789 | ||
31790 | #include <asm/uaccess.h> | |
31791 | #include <asm/unistd.h> | |
4dee9bd5 | 31792 | @@ -90,6 +91,9 @@ asmlinkage long sys_stime(time_t __user |
50425a20 | 31793 | return err; |
31794 | ||
b79bc584 | 31795 | vx_settimeofday(&tv); |
50425a20 | 31796 | + |
31797 | + gr_log_timechange(); | |
31798 | + | |
31799 | return 0; | |
31800 | } | |
31801 | ||
4dee9bd5 | 31802 | @@ -198,6 +202,8 @@ asmlinkage long sys_settimeofday(struct |
50425a20 | 31803 | return -EFAULT; |
31804 | } | |
31805 | ||
31806 | + gr_log_timechange(); | |
31807 | + | |
31808 | return do_sys_settimeofday(tv ? &new_ts : NULL, tz ? &new_tz : NULL); | |
31809 | } | |
31810 | ||
4dee9bd5 | 31811 | @@ -236,7 +242,7 @@ EXPORT_SYMBOL(current_fs_time); |
8a4b4a5e | 31812 | * Avoid unnecessary multiplications/divisions in the |
31813 | * two most common HZ cases: | |
31814 | */ | |
31815 | -unsigned int inline jiffies_to_msecs(const unsigned long j) | |
31816 | +inline unsigned int jiffies_to_msecs(const unsigned long j) | |
31817 | { | |
31818 | #if HZ <= MSEC_PER_SEC && !(MSEC_PER_SEC % HZ) | |
31819 | return (MSEC_PER_SEC / HZ) * j; | |
4dee9bd5 | 31820 | @@ -252,7 +258,7 @@ unsigned int inline jiffies_to_msecs(con |
8a4b4a5e | 31821 | } |
31822 | EXPORT_SYMBOL(jiffies_to_msecs); | |
31823 | ||
31824 | -unsigned int inline jiffies_to_usecs(const unsigned long j) | |
31825 | +inline unsigned int jiffies_to_usecs(const unsigned long j) | |
31826 | { | |
31827 | #if HZ <= USEC_PER_SEC && !(USEC_PER_SEC % HZ) | |
31828 | return (USEC_PER_SEC / HZ) * j; | |
4dee9bd5 | 31829 | diff -urNp linux-2.6.25.4/kernel/utsname_sysctl.c linux-2.6.25.4/kernel/utsname_sysctl.c |
31830 | --- linux-2.6.25.4/kernel/utsname_sysctl.c 2008-05-15 11:00:12.000000000 -0400 | |
31831 | +++ linux-2.6.25.4/kernel/utsname_sysctl.c 2008-05-18 13:33:17.000000000 -0400 | |
da5b3fc8 | 31832 | @@ -125,7 +125,7 @@ static struct ctl_table uts_kern_table[] |
31833 | .proc_handler = proc_do_uts_string, | |
31834 | .strategy = sysctl_uts_string, | |
31835 | }, | |
31836 | - {} | |
31837 | + { 0, NULL, NULL, 0, 0, NULL, NULL, NULL, NULL, NULL, NULL } | |
31838 | }; | |
31839 | ||
31840 | static struct ctl_table uts_root_table[] = { | |
31841 | @@ -135,7 +135,7 @@ static struct ctl_table uts_root_table[] | |
31842 | .mode = 0555, | |
31843 | .child = uts_kern_table, | |
31844 | }, | |
31845 | - {} | |
31846 | + { 0, NULL, NULL, 0, 0, NULL, NULL, NULL, NULL, NULL, NULL } | |
31847 | }; | |
8a4b4a5e | 31848 | |
da5b3fc8 | 31849 | static int __init utsname_sysctl_init(void) |
4dee9bd5 | 31850 | diff -urNp linux-2.6.25.4/lib/radix-tree.c linux-2.6.25.4/lib/radix-tree.c |
31851 | --- linux-2.6.25.4/lib/radix-tree.c 2008-05-15 11:00:12.000000000 -0400 | |
31852 | +++ linux-2.6.25.4/lib/radix-tree.c 2008-05-18 13:33:17.000000000 -0400 | |
da5b3fc8 | 31853 | @@ -81,7 +81,7 @@ struct radix_tree_preload { |
50425a20 | 31854 | int nr; |
31855 | struct radix_tree_node *nodes[RADIX_TREE_MAX_PATH]; | |
31856 | }; | |
31857 | -DEFINE_PER_CPU(struct radix_tree_preload, radix_tree_preloads) = { 0, }; | |
31858 | +DEFINE_PER_CPU(struct radix_tree_preload, radix_tree_preloads) = { 0, {NULL} }; | |
31859 | ||
31860 | static inline gfp_t root_gfp_mask(struct radix_tree_root *root) | |
31861 | { | |
4dee9bd5 | 31862 | diff -urNp linux-2.6.25.4/localversion-grsec linux-2.6.25.4/localversion-grsec |
31863 | --- linux-2.6.25.4/localversion-grsec 1969-12-31 19:00:00.000000000 -0500 | |
31864 | +++ linux-2.6.25.4/localversion-grsec 2008-05-18 13:33:17.000000000 -0400 | |
50425a20 | 31865 | @@ -0,0 +1 @@ |
31866 | +-grsec | |
4dee9bd5 | 31867 | diff -urNp linux-2.6.25.4/Makefile linux-2.6.25.4/Makefile |
31868 | --- linux-2.6.25.4/Makefile 2008-05-15 11:00:12.000000000 -0400 | |
31869 | +++ linux-2.6.25.4/Makefile 2008-05-18 13:33:17.000000000 -0400 | |
da5b3fc8 | 31870 | @@ -214,7 +214,7 @@ CONFIG_SHELL := $(shell if [ -x "$$BASH" |
31871 | ||
31872 | HOSTCC = gcc | |
31873 | HOSTCXX = g++ | |
31874 | -HOSTCFLAGS = -Wall -Wstrict-prototypes -O2 -fomit-frame-pointer | |
31875 | +HOSTCFLAGS = -Wall -W -Wno-unused -Wno-sign-compare -Wstrict-prototypes -O2 -fomit-frame-pointer | |
31876 | HOSTCXXFLAGS = -O2 | |
31877 | ||
31878 | # Decide whether to build built-in, modular, or both. | |
4dee9bd5 | 31879 | @@ -603,7 +603,7 @@ export mod_strip_cmd |
50425a20 | 31880 | |
31881 | ||
31882 | ifeq ($(KBUILD_EXTMOD),) | |
31883 | -core-y += kernel/ mm/ fs/ ipc/ security/ crypto/ block/ | |
31884 | +core-y += kernel/ mm/ fs/ ipc/ security/ crypto/ block/ grsecurity/ | |
31885 | ||
31886 | vmlinux-dirs := $(patsubst %/,%,$(filter %/, $(init-y) $(init-m) \ | |
31887 | $(core-y) $(core-m) $(drivers-y) $(drivers-m) \ | |
4dee9bd5 | 31888 | diff -urNp linux-2.6.25.4/mm/filemap.c linux-2.6.25.4/mm/filemap.c |
31889 | --- linux-2.6.25.4/mm/filemap.c 2008-05-15 11:00:12.000000000 -0400 | |
31890 | +++ linux-2.6.25.4/mm/filemap.c 2008-05-18 13:33:17.000000000 -0400 | |
da5b3fc8 | 31891 | @@ -33,6 +33,7 @@ |
50425a20 | 31892 | #include <linux/cpuset.h> |
da5b3fc8 | 31893 | #include <linux/hardirq.h> /* for BUG_ON(!in_atomic()) only */ |
4dee9bd5 | 31894 | #include <linux/memcontrol.h> |
50425a20 | 31895 | +#include <linux/grsecurity.h> |
50425a20 | 31896 | #include "internal.h" |
31897 | ||
da5b3fc8 | 31898 | /* |
4dee9bd5 | 31899 | @@ -1481,7 +1482,7 @@ int generic_file_mmap(struct file * file |
50425a20 | 31900 | struct address_space *mapping = file->f_mapping; |
31901 | ||
31902 | if (!mapping->a_ops->readpage) | |
31903 | - return -ENOEXEC; | |
31904 | + return -ENODEV; | |
50425a20 | 31905 | file_accessed(file); |
31906 | vma->vm_ops = &generic_file_vm_ops; | |
da5b3fc8 | 31907 | vma->vm_flags |= VM_CAN_NONLINEAR; |
4dee9bd5 | 31908 | @@ -1841,6 +1842,7 @@ inline int generic_write_checks(struct f |
50425a20 | 31909 | *pos = i_size_read(inode); |
31910 | ||
31911 | if (limit != RLIM_INFINITY) { | |
31912 | + gr_learn_resource(current, RLIMIT_FSIZE,*pos, 0); | |
31913 | if (*pos >= limit) { | |
31914 | send_sig(SIGXFSZ, current, 0); | |
31915 | return -EFBIG; | |
4dee9bd5 | 31916 | diff -urNp linux-2.6.25.4/mm/fremap.c linux-2.6.25.4/mm/fremap.c |
31917 | --- linux-2.6.25.4/mm/fremap.c 2008-05-15 11:00:12.000000000 -0400 | |
31918 | +++ linux-2.6.25.4/mm/fremap.c 2008-05-18 13:33:17.000000000 -0400 | |
da5b3fc8 | 31919 | @@ -150,6 +150,13 @@ asmlinkage long sys_remap_file_pages(uns |
8a4b4a5e | 31920 | retry: |
31921 | vma = find_vma(mm, start); | |
31922 | ||
50425a20 | 31923 | +#ifdef CONFIG_PAX_SEGMEXEC |
8a4b4a5e | 31924 | + if (vma && (mm->pax_flags & MF_PAX_SEGMEXEC) && (vma->vm_flags & VM_MAYEXEC)) { |
31925 | + up_read(&mm->mmap_sem); | |
31926 | + return err; | |
50425a20 | 31927 | + } |
8a4b4a5e | 31928 | +#endif |
31929 | + | |
31930 | /* | |
31931 | * Make sure the vma is shared, that it supports prefaulting, | |
31932 | * and that the remapped range is valid and fully within | |
4dee9bd5 | 31933 | diff -urNp linux-2.6.25.4/mm/hugetlb.c linux-2.6.25.4/mm/hugetlb.c |
31934 | --- linux-2.6.25.4/mm/hugetlb.c 2008-05-15 11:00:12.000000000 -0400 | |
31935 | +++ linux-2.6.25.4/mm/hugetlb.c 2008-05-18 13:33:17.000000000 -0400 | |
31936 | @@ -843,6 +843,26 @@ void unmap_hugepage_range(struct vm_area | |
8a4b4a5e | 31937 | } |
31938 | } | |
31939 | ||
31940 | +#ifdef CONFIG_PAX_SEGMEXEC | |
31941 | +static void pax_mirror_huge_pte(struct vm_area_struct *vma, unsigned long address, struct page *page_m) | |
31942 | +{ | |
31943 | + struct mm_struct *mm = vma->vm_mm; | |
31944 | + struct vm_area_struct *vma_m; | |
31945 | + unsigned long address_m; | |
31946 | + pte_t *ptep_m; | |
31947 | + | |
31948 | + vma_m = pax_find_mirror_vma(vma); | |
31949 | + if (!vma_m) | |
31950 | + return; | |
50425a20 | 31951 | + |
8a4b4a5e | 31952 | + BUG_ON(address >= SEGMEXEC_TASK_SIZE); |
31953 | + address_m = address + SEGMEXEC_TASK_SIZE; | |
31954 | + ptep_m = huge_pte_offset(mm, address_m & HPAGE_MASK); | |
31955 | + get_page(page_m); | |
31956 | + set_huge_pte_at(mm, address_m, ptep_m, make_huge_pte(vma_m, page_m, 0)); | |
50425a20 | 31957 | +} |
8a4b4a5e | 31958 | +#endif |
50425a20 | 31959 | + |
8a4b4a5e | 31960 | static int hugetlb_cow(struct mm_struct *mm, struct vm_area_struct *vma, |
31961 | unsigned long address, pte_t *ptep, pte_t pte) | |
31962 | { | |
4dee9bd5 | 31963 | @@ -877,6 +897,11 @@ static int hugetlb_cow(struct mm_struct |
8a4b4a5e | 31964 | /* Break COW */ |
31965 | set_huge_pte_at(mm, address, ptep, | |
31966 | make_huge_pte(vma, new_page, 1)); | |
31967 | + | |
31968 | +#ifdef CONFIG_PAX_SEGMEXEC | |
31969 | + pax_mirror_huge_pte(vma, address, new_page); | |
50425a20 | 31970 | +#endif |
8a4b4a5e | 31971 | + |
31972 | /* Make the old page be freed below */ | |
31973 | new_page = old_page; | |
31974 | } | |
4dee9bd5 | 31975 | @@ -949,6 +974,10 @@ retry: |
8a4b4a5e | 31976 | && (vma->vm_flags & VM_SHARED))); |
31977 | set_huge_pte_at(mm, address, ptep, new_pte); | |
31978 | ||
31979 | +#ifdef CONFIG_PAX_SEGMEXEC | |
31980 | + pax_mirror_huge_pte(vma, address, page); | |
31981 | +#endif | |
31982 | + | |
31983 | if (write_access && !(vma->vm_flags & VM_SHARED)) { | |
31984 | /* Optimization, do the COW without a second fault */ | |
31985 | ret = hugetlb_cow(mm, vma, address, ptep, new_pte); | |
4dee9bd5 | 31986 | @@ -974,6 +1003,27 @@ int hugetlb_fault(struct mm_struct *mm, |
8a4b4a5e | 31987 | int ret; |
31988 | static DEFINE_MUTEX(hugetlb_instantiation_mutex); | |
31989 | ||
31990 | +#ifdef CONFIG_PAX_SEGMEXEC | |
31991 | + struct vm_area_struct *vma_m; | |
31992 | + | |
31993 | + vma_m = pax_find_mirror_vma(vma); | |
31994 | + if (vma_m) { | |
31995 | + unsigned long address_m; | |
31996 | + | |
31997 | + if (vma->vm_start > vma_m->vm_start) { | |
31998 | + address_m = address; | |
31999 | + address -= SEGMEXEC_TASK_SIZE; | |
32000 | + vma = vma_m; | |
32001 | + } else | |
32002 | + address_m = address + SEGMEXEC_TASK_SIZE; | |
32003 | + | |
32004 | + if (!huge_pte_alloc(mm, address_m)) | |
32005 | + return VM_FAULT_OOM; | |
32006 | + address_m &= HPAGE_MASK; | |
32007 | + unmap_hugepage_range(vma, address_m, address_m + HPAGE_SIZE); | |
32008 | + } | |
32009 | +#endif | |
32010 | + | |
32011 | ptep = huge_pte_alloc(mm, address); | |
32012 | if (!ptep) | |
32013 | return VM_FAULT_OOM; | |
4dee9bd5 | 32014 | diff -urNp linux-2.6.25.4/mm/madvise.c linux-2.6.25.4/mm/madvise.c |
32015 | --- linux-2.6.25.4/mm/madvise.c 2008-05-15 11:00:12.000000000 -0400 | |
32016 | +++ linux-2.6.25.4/mm/madvise.c 2008-05-18 13:33:17.000000000 -0400 | |
8a4b4a5e | 32017 | @@ -43,6 +43,10 @@ static long madvise_behavior(struct vm_a |
32018 | pgoff_t pgoff; | |
32019 | int new_flags = vma->vm_flags; | |
32020 | ||
32021 | +#ifdef CONFIG_PAX_SEGMEXEC | |
32022 | + struct vm_area_struct *vma_m; | |
32023 | +#endif | |
32024 | + | |
32025 | switch (behavior) { | |
32026 | case MADV_NORMAL: | |
32027 | new_flags = new_flags & ~VM_RAND_READ & ~VM_SEQ_READ; | |
32028 | @@ -92,6 +96,13 @@ success: | |
32029 | /* | |
32030 | * vm_flags is protected by the mmap_sem held in write mode. | |
32031 | */ | |
32032 | + | |
32033 | +#ifdef CONFIG_PAX_SEGMEXEC | |
32034 | + vma_m = pax_find_mirror_vma(vma); | |
32035 | + if (vma_m) | |
32036 | + vma_m->vm_flags = new_flags & ~(VM_WRITE | VM_MAYWRITE | VM_ACCOUNT); | |
32037 | +#endif | |
32038 | + | |
32039 | vma->vm_flags = new_flags; | |
32040 | ||
32041 | out: | |
32042 | @@ -236,6 +247,17 @@ madvise_vma(struct vm_area_struct *vma, | |
32043 | ||
32044 | case MADV_DONTNEED: | |
32045 | error = madvise_dontneed(vma, prev, start, end); | |
32046 | + | |
32047 | +#ifdef CONFIG_PAX_SEGMEXEC | |
32048 | + if (!error) { | |
32049 | + struct vm_area_struct *vma_m, *prev_m; | |
32050 | + | |
32051 | + vma_m = pax_find_mirror_vma(vma); | |
32052 | + if (vma_m) | |
32053 | + error = madvise_dontneed(vma_m, &prev_m, start + SEGMEXEC_TASK_SIZE, end + SEGMEXEC_TASK_SIZE); | |
32054 | + } | |
32055 | +#endif | |
32056 | + | |
32057 | break; | |
32058 | ||
32059 | default: | |
da5b3fc8 | 32060 | @@ -308,6 +330,16 @@ asmlinkage long sys_madvise(unsigned lon |
8a4b4a5e | 32061 | if (end < start) |
32062 | goto out; | |
32063 | ||
32064 | +#ifdef CONFIG_PAX_SEGMEXEC | |
32065 | + if (current->mm->pax_flags & MF_PAX_SEGMEXEC) { | |
32066 | + if (end > SEGMEXEC_TASK_SIZE) | |
32067 | + goto out; | |
32068 | + } else | |
32069 | +#endif | |
32070 | + | |
32071 | + if (end > TASK_SIZE) | |
32072 | + goto out; | |
32073 | + | |
32074 | error = 0; | |
32075 | if (end == start) | |
32076 | goto out; | |
4dee9bd5 | 32077 | diff -urNp linux-2.6.25.4/mm/memory.c linux-2.6.25.4/mm/memory.c |
32078 | --- linux-2.6.25.4/mm/memory.c 2008-05-15 11:00:12.000000000 -0400 | |
32079 | +++ linux-2.6.25.4/mm/memory.c 2008-05-18 13:33:17.000000000 -0400 | |
32080 | @@ -51,6 +51,7 @@ | |
50425a20 | 32081 | #include <linux/init.h> |
32082 | #include <linux/writeback.h> | |
4dee9bd5 | 32083 | #include <linux/memcontrol.h> |
50425a20 | 32084 | +#include <linux/grsecurity.h> |
32085 | ||
32086 | #include <asm/pgalloc.h> | |
32087 | #include <asm/uaccess.h> | |
4dee9bd5 | 32088 | @@ -999,11 +1000,11 @@ int get_user_pages(struct task_struct *t |
da5b3fc8 | 32089 | vm_flags &= force ? (VM_MAYREAD | VM_MAYWRITE) : (VM_READ | VM_WRITE); |
32090 | i = 0; | |
50425a20 | 32091 | |
da5b3fc8 | 32092 | - do { |
32093 | + while (len) { | |
50425a20 | 32094 | struct vm_area_struct *vma; |
32095 | unsigned int foll_flags; | |
32096 | ||
32097 | - vma = find_extend_vma(mm, start); | |
32098 | + vma = find_vma(mm, start); | |
32099 | if (!vma && in_gate_area(tsk, start)) { | |
32100 | unsigned long pg = start & PAGE_MASK; | |
32101 | struct vm_area_struct *gate_vma = get_gate_vma(tsk); | |
4dee9bd5 | 32102 | @@ -1043,7 +1044,7 @@ int get_user_pages(struct task_struct *t |
50425a20 | 32103 | continue; |
32104 | } | |
32105 | ||
32106 | - if (!vma || (vma->vm_flags & (VM_IO | VM_PFNMAP)) | |
32107 | + if (!vma || start < vma->vm_start || (vma->vm_flags & (VM_IO | VM_PFNMAP)) | |
32108 | || !(vm_flags & vma->vm_flags)) | |
32109 | return i ? : -EFAULT; | |
32110 | ||
4dee9bd5 | 32111 | @@ -1116,7 +1117,7 @@ int get_user_pages(struct task_struct *t |
da5b3fc8 | 32112 | start += PAGE_SIZE; |
32113 | len--; | |
32114 | } while (len && start < vma->vm_end); | |
32115 | - } while (len); | |
32116 | + } | |
32117 | return i; | |
32118 | } | |
32119 | EXPORT_SYMBOL(get_user_pages); | |
4dee9bd5 | 32120 | @@ -1542,6 +1543,186 @@ static inline void cow_user_page(struct |
32121 | copy_user_highpage(dst, src, va, vma); | |
50425a20 | 32122 | } |
32123 | ||
32124 | +#ifdef CONFIG_PAX_SEGMEXEC | |
8a4b4a5e | 32125 | +static void pax_unmap_mirror_pte(struct vm_area_struct *vma, unsigned long address, pmd_t *pmd) |
32126 | +{ | |
32127 | + struct mm_struct *mm = vma->vm_mm; | |
32128 | + spinlock_t *ptl; | |
32129 | + pte_t *pte, entry; | |
32130 | + | |
32131 | + pte = pte_offset_map_lock(mm, pmd, address, &ptl); | |
32132 | + entry = *pte; | |
32133 | + if (!pte_present(entry)) { | |
32134 | + if (!pte_none(entry)) { | |
32135 | + BUG_ON(pte_file(entry)); | |
8a4b4a5e | 32136 | + free_swap_and_cache(pte_to_swp_entry(entry)); |
83a957c9 | 32137 | + pte_clear_not_present_full(mm, address, pte, 0); |
8a4b4a5e | 32138 | + } |
32139 | + } else { | |
32140 | + struct page *page; | |
32141 | + | |
b7f09679 | 32142 | + flush_cache_page(vma, address, pte_pfn(entry)); |
32143 | + entry = ptep_clear_flush(vma, address, pte); | |
8a4b4a5e | 32144 | + BUG_ON(pte_dirty(entry)); |
b7f09679 | 32145 | + page = vm_normal_page(vma, address, entry); |
8a4b4a5e | 32146 | + if (page) { |
32147 | + update_hiwater_rss(mm); | |
32148 | + if (PageAnon(page)) | |
32149 | + dec_mm_counter(mm, anon_rss); | |
32150 | + else | |
32151 | + dec_mm_counter(mm, file_rss); | |
32152 | + page_remove_rmap(page, vma); | |
32153 | + page_cache_release(page); | |
32154 | + } | |
32155 | + } | |
32156 | + pte_unmap_unlock(pte, ptl); | |
32157 | +} | |
32158 | + | |
50425a20 | 32159 | +/* PaX: if vma is mirrored, synchronize the mirror's PTE |
32160 | + * | |
32161 | + * the ptl of the lower mapped page is held on entry and is not released on exit | |
32162 | + * or inside to ensure atomic changes to the PTE states (swapout, mremap, munmap, etc) | |
32163 | + */ | |
8a4b4a5e | 32164 | +static void pax_mirror_anon_pte(struct vm_area_struct *vma, unsigned long address, struct page *page_m, spinlock_t *ptl) |
50425a20 | 32165 | +{ |
32166 | + struct mm_struct *mm = vma->vm_mm; | |
8a4b4a5e | 32167 | + unsigned long address_m; |
32168 | + spinlock_t *ptl_m; | |
32169 | + struct vm_area_struct *vma_m; | |
32170 | + pmd_t *pmd_m; | |
32171 | + pte_t *pte_m, entry_m; | |
50425a20 | 32172 | + |
8a4b4a5e | 32173 | + BUG_ON(!page_m || !PageAnon(page_m)); |
50425a20 | 32174 | + |
8a4b4a5e | 32175 | + vma_m = pax_find_mirror_vma(vma); |
32176 | + if (!vma_m) | |
50425a20 | 32177 | + return; |
50425a20 | 32178 | + |
8a4b4a5e | 32179 | + BUG_ON(!PageLocked(page_m)); |
32180 | + BUG_ON(address >= SEGMEXEC_TASK_SIZE); | |
32181 | + address_m = address + SEGMEXEC_TASK_SIZE; | |
32182 | + pmd_m = pmd_offset(pud_offset(pgd_offset(mm, address_m), address_m), address_m); | |
32183 | + pte_m = pte_offset_map_nested(pmd_m, address_m); | |
32184 | + ptl_m = pte_lockptr(mm, pmd_m); | |
32185 | + if (ptl != ptl_m) { | |
32186 | + spin_lock_nested(ptl_m, SINGLE_DEPTH_NESTING); | |
b7f09679 | 32187 | + if (!pte_none(*pte_m)) |
32188 | + goto out; | |
50425a20 | 32189 | + } |
32190 | + | |
8a4b4a5e | 32191 | + entry_m = pfn_pte(page_to_pfn(page_m), vma_m->vm_page_prot); |
32192 | + page_cache_get(page_m); | |
32193 | + page_add_anon_rmap(page_m, vma_m, address_m); | |
32194 | + inc_mm_counter(mm, anon_rss); | |
50425a20 | 32195 | + set_pte_at(mm, address_m, pte_m, entry_m); |
32196 | + update_mmu_cache(vma_m, address_m, entry_m); | |
b7f09679 | 32197 | +out: |
8a4b4a5e | 32198 | + if (ptl != ptl_m) |
32199 | + spin_unlock(ptl_m); | |
50425a20 | 32200 | + pte_unmap_nested(pte_m); |
8a4b4a5e | 32201 | + unlock_page(page_m); |
50425a20 | 32202 | +} |
50425a20 | 32203 | + |
8a4b4a5e | 32204 | +void pax_mirror_file_pte(struct vm_area_struct *vma, unsigned long address, struct page *page_m, spinlock_t *ptl) |
32205 | +{ | |
32206 | + struct mm_struct *mm = vma->vm_mm; | |
da5b3fc8 | 32207 | + unsigned long address_m; |
8a4b4a5e | 32208 | + spinlock_t *ptl_m; |
32209 | + struct vm_area_struct *vma_m; | |
32210 | + pmd_t *pmd_m; | |
32211 | + pte_t *pte_m, entry_m; | |
50425a20 | 32212 | + |
8a4b4a5e | 32213 | + BUG_ON(!page_m || PageAnon(page_m)); |
32214 | + | |
32215 | + vma_m = pax_find_mirror_vma(vma); | |
32216 | + if (!vma_m) | |
32217 | + return; | |
32218 | + | |
32219 | + BUG_ON(address >= SEGMEXEC_TASK_SIZE); | |
32220 | + address_m = address + SEGMEXEC_TASK_SIZE; | |
32221 | + pmd_m = pmd_offset(pud_offset(pgd_offset(mm, address_m), address_m), address_m); | |
32222 | + pte_m = pte_offset_map_nested(pmd_m, address_m); | |
32223 | + ptl_m = pte_lockptr(mm, pmd_m); | |
32224 | + if (ptl != ptl_m) { | |
32225 | + spin_lock_nested(ptl_m, SINGLE_DEPTH_NESTING); | |
b7f09679 | 32226 | + if (!pte_none(*pte_m)) |
32227 | + goto out; | |
8a4b4a5e | 32228 | + } |
32229 | + | |
32230 | + entry_m = pfn_pte(page_to_pfn(page_m), vma_m->vm_page_prot); | |
32231 | + page_cache_get(page_m); | |
32232 | + page_add_file_rmap(page_m); | |
32233 | + inc_mm_counter(mm, file_rss); | |
32234 | + set_pte_at(mm, address_m, pte_m, entry_m); | |
32235 | + update_mmu_cache(vma_m, address_m, entry_m); | |
b7f09679 | 32236 | +out: |
8a4b4a5e | 32237 | + if (ptl != ptl_m) |
32238 | + spin_unlock(ptl_m); | |
32239 | + pte_unmap_nested(pte_m); | |
32240 | +} | |
32241 | + | |
32242 | +static void pax_mirror_pfn_pte(struct vm_area_struct *vma, unsigned long address, unsigned long pfn_m, spinlock_t *ptl) | |
32243 | +{ | |
32244 | + struct mm_struct *mm = vma->vm_mm; | |
32245 | + unsigned long address_m; | |
32246 | + spinlock_t *ptl_m; | |
32247 | + struct vm_area_struct *vma_m; | |
32248 | + pmd_t *pmd_m; | |
32249 | + pte_t *pte_m, entry_m; | |
32250 | + | |
32251 | + vma_m = pax_find_mirror_vma(vma); | |
32252 | + if (!vma_m) | |
32253 | + return; | |
32254 | + | |
32255 | + BUG_ON(address >= SEGMEXEC_TASK_SIZE); | |
32256 | + address_m = address + SEGMEXEC_TASK_SIZE; | |
32257 | + pmd_m = pmd_offset(pud_offset(pgd_offset(mm, address_m), address_m), address_m); | |
32258 | + pte_m = pte_offset_map_nested(pmd_m, address_m); | |
32259 | + ptl_m = pte_lockptr(mm, pmd_m); | |
32260 | + if (ptl != ptl_m) { | |
32261 | + spin_lock_nested(ptl_m, SINGLE_DEPTH_NESTING); | |
b7f09679 | 32262 | + if (!pte_none(*pte_m)) |
32263 | + goto out; | |
8a4b4a5e | 32264 | + } |
32265 | + | |
32266 | + entry_m = pfn_pte(pfn_m, vma_m->vm_page_prot); | |
32267 | + set_pte_at(mm, address_m, pte_m, entry_m); | |
b7f09679 | 32268 | +out: |
8a4b4a5e | 32269 | + if (ptl != ptl_m) |
32270 | + spin_unlock(ptl_m); | |
32271 | + pte_unmap_nested(pte_m); | |
32272 | +} | |
32273 | + | |
da5b3fc8 | 32274 | +static void pax_mirror_pte(struct vm_area_struct *vma, unsigned long address, pte_t *pte, pmd_t *pmd, spinlock_t *ptl) |
8a4b4a5e | 32275 | +{ |
32276 | + struct page *page_m; | |
32277 | + pte_t entry; | |
32278 | + | |
32279 | + if (!(vma->vm_mm->pax_flags & MF_PAX_SEGMEXEC)) | |
da5b3fc8 | 32280 | + goto out; |
8a4b4a5e | 32281 | + |
32282 | + entry = *pte; | |
32283 | + page_m = vm_normal_page(vma, address, entry); | |
32284 | + if (!page_m) | |
32285 | + pax_mirror_pfn_pte(vma, address, pte_pfn(entry), ptl); | |
da5b3fc8 | 32286 | + else if (PageAnon(page_m)) { |
32287 | + if (pax_find_mirror_vma(vma)) { | |
32288 | + pte_unmap_unlock(pte, ptl); | |
32289 | + lock_page(page_m); | |
32290 | + pte = pte_offset_map_lock(vma->vm_mm, pmd, address, &ptl); | |
32291 | + if (pte_same(entry, *pte)) | |
32292 | + pax_mirror_anon_pte(vma, address, page_m, ptl); | |
32293 | + else | |
32294 | + unlock_page(page_m); | |
32295 | + } | |
8a4b4a5e | 32296 | + } else |
32297 | + pax_mirror_file_pte(vma, address, page_m, ptl); | |
da5b3fc8 | 32298 | + |
32299 | +out: | |
32300 | + pte_unmap_unlock(pte, ptl); | |
8a4b4a5e | 32301 | +} |
50425a20 | 32302 | +#endif |
32303 | + | |
8a4b4a5e | 32304 | /* |
32305 | * This routine handles present pages, when users try to write | |
32306 | * to a shared page. It is done by copying the page to a new address | |
4dee9bd5 | 32307 | @@ -1658,6 +1839,12 @@ gotten: |
83a957c9 | 32308 | */ |
32309 | page_table = pte_offset_map_lock(mm, pmd, address, &ptl); | |
32310 | if (likely(pte_same(*page_table, orig_pte))) { | |
32311 | + | |
8a4b4a5e | 32312 | +#ifdef CONFIG_PAX_SEGMEXEC |
83a957c9 | 32313 | + if (pax_find_mirror_vma(vma)) |
32314 | + BUG_ON(TestSetPageLocked(new_page)); | |
8a4b4a5e | 32315 | +#endif |
32316 | + | |
83a957c9 | 32317 | if (old_page) { |
32318 | page_remove_rmap(old_page, vma); | |
32319 | if (!PageAnon(old_page)) { | |
4dee9bd5 | 32320 | @@ -1681,6 +1868,10 @@ gotten: |
8a4b4a5e | 32321 | lru_cache_add_active(new_page); |
32322 | page_add_new_anon_rmap(new_page, vma, address); | |
32323 | ||
32324 | +#ifdef CONFIG_PAX_SEGMEXEC | |
32325 | + pax_mirror_anon_pte(vma, address, new_page, ptl); | |
32326 | +#endif | |
32327 | + | |
32328 | /* Free the old page.. */ | |
32329 | new_page = old_page; | |
32330 | ret |= VM_FAULT_WRITE; | |
4dee9bd5 | 32331 | @@ -1940,6 +2131,7 @@ int vmtruncate(struct inode * inode, lof |
32332 | unsigned long limit; | |
32333 | ||
32334 | limit = current->signal->rlim[RLIMIT_FSIZE].rlim_cur; | |
32335 | + gr_learn_resource(current, RLIMIT_FSIZE, offset, 1); | |
32336 | if (limit != RLIM_INFINITY && offset > limit) | |
32337 | goto out_sig; | |
32338 | if (offset > inode->i_sb->s_maxbytes) | |
32339 | @@ -2090,6 +2282,11 @@ static int do_swap_page(struct mm_struct | |
8a4b4a5e | 32340 | swap_free(entry); |
32341 | if (vm_swap_full()) | |
32342 | remove_exclusive_swap_page(page); | |
32343 | + | |
32344 | +#ifdef CONFIG_PAX_SEGMEXEC | |
32345 | + if (write_access || !pax_find_mirror_vma(vma)) | |
32346 | +#endif | |
32347 | + | |
32348 | unlock_page(page); | |
32349 | ||
32350 | if (write_access) { | |
4dee9bd5 | 32351 | @@ -2101,6 +2298,11 @@ static int do_swap_page(struct mm_struct |
da5b3fc8 | 32352 | |
50425a20 | 32353 | /* No need to invalidate - it was non-present before */ |
32354 | update_mmu_cache(vma, address, pte); | |
50425a20 | 32355 | + |
32356 | +#ifdef CONFIG_PAX_SEGMEXEC | |
8a4b4a5e | 32357 | + pax_mirror_anon_pte(vma, address, page, ptl); |
50425a20 | 32358 | +#endif |
32359 | + | |
32360 | unlock: | |
32361 | pte_unmap_unlock(page_table, ptl); | |
32362 | out: | |
4dee9bd5 | 32363 | @@ -2145,6 +2347,12 @@ static int do_anonymous_page(struct mm_s |
da5b3fc8 | 32364 | page_table = pte_offset_map_lock(mm, pmd, address, &ptl); |
32365 | if (!pte_none(*page_table)) | |
32366 | goto release; | |
8a4b4a5e | 32367 | + |
32368 | +#ifdef CONFIG_PAX_SEGMEXEC | |
da5b3fc8 | 32369 | + if (pax_find_mirror_vma(vma)) |
32370 | + BUG_ON(TestSetPageLocked(page)); | |
8a4b4a5e | 32371 | +#endif |
32372 | + | |
da5b3fc8 | 32373 | inc_mm_counter(mm, anon_rss); |
32374 | lru_cache_add_active(page); | |
32375 | page_add_new_anon_rmap(page, vma, address); | |
4dee9bd5 | 32376 | @@ -2152,6 +2360,11 @@ static int do_anonymous_page(struct mm_s |
da5b3fc8 | 32377 | |
50425a20 | 32378 | /* No need to invalidate - it was non-present before */ |
32379 | update_mmu_cache(vma, address, entry); | |
50425a20 | 32380 | + |
32381 | +#ifdef CONFIG_PAX_SEGMEXEC | |
da5b3fc8 | 32382 | + pax_mirror_anon_pte(vma, address, page, ptl); |
50425a20 | 32383 | +#endif |
32384 | + | |
32385 | unlock: | |
32386 | pte_unmap_unlock(page_table, ptl); | |
da5b3fc8 | 32387 | return 0; |
4dee9bd5 | 32388 | @@ -2293,6 +2506,12 @@ static int __do_fault(struct mm_struct * |
83a957c9 | 32389 | */ |
32390 | /* Only go through if we didn't race with anybody else... */ | |
da5b3fc8 | 32391 | if (likely(pte_same(*page_table, orig_pte))) { |
83a957c9 | 32392 | + |
1b12b5bc | 32393 | +#ifdef CONFIG_PAX_SEGMEXEC |
da5b3fc8 | 32394 | + if (anon && pax_find_mirror_vma(vma)) |
32395 | + BUG_ON(TestSetPageLocked(page)); | |
1b12b5bc | 32396 | +#endif |
32397 | + | |
da5b3fc8 | 32398 | flush_icache_page(vma, page); |
32399 | entry = mk_pte(page, vma->vm_page_prot); | |
32400 | if (flags & FAULT_FLAG_WRITE) | |
4dee9bd5 | 32401 | @@ -2313,6 +2532,14 @@ static int __do_fault(struct mm_struct * |
da5b3fc8 | 32402 | |
32403 | /* no need to invalidate: a not-present page won't be cached */ | |
32404 | update_mmu_cache(vma, address, entry); | |
50425a20 | 32405 | + |
32406 | +#ifdef CONFIG_PAX_SEGMEXEC | |
da5b3fc8 | 32407 | + if (anon) |
32408 | + pax_mirror_anon_pte(vma, address, page, ptl); | |
32409 | + else | |
32410 | + pax_mirror_file_pte(vma, address, page, ptl); | |
50425a20 | 32411 | +#endif |
32412 | + | |
da5b3fc8 | 32413 | } else { |
4dee9bd5 | 32414 | mem_cgroup_uncharge_page(page); |
da5b3fc8 | 32415 | if (anon) |
4dee9bd5 | 32416 | @@ -2396,6 +2623,11 @@ static noinline int do_no_pfn(struct mm_ |
8a4b4a5e | 32417 | if (write_access) |
32418 | entry = maybe_mkwrite(pte_mkdirty(entry), vma); | |
32419 | set_pte_at(mm, address, page_table, entry); | |
32420 | + | |
32421 | +#ifdef CONFIG_PAX_SEGMEXEC | |
32422 | + pax_mirror_pfn_pte(vma, address, pfn, ptl); | |
32423 | +#endif | |
32424 | + | |
32425 | } | |
32426 | pte_unmap_unlock(page_table, ptl); | |
da5b3fc8 | 32427 | return 0; |
4dee9bd5 | 32428 | @@ -2498,6 +2730,12 @@ static inline int handle_pte_fault(struc |
8a4b4a5e | 32429 | if (write_access) |
50425a20 | 32430 | flush_tlb_page(vma, address); |
32431 | } | |
50425a20 | 32432 | + |
32433 | +#ifdef CONFIG_PAX_SEGMEXEC | |
da5b3fc8 | 32434 | + pax_mirror_pte(vma, address, pte, pmd, ptl); |
32435 | + return 0; | |
50425a20 | 32436 | +#endif |
32437 | + | |
8a4b4a5e | 32438 | unlock: |
50425a20 | 32439 | pte_unmap_unlock(pte, ptl); |
da5b3fc8 | 32440 | return 0; |
4dee9bd5 | 32441 | @@ -2514,6 +2752,10 @@ int handle_mm_fault(struct mm_struct *mm |
8a4b4a5e | 32442 | pmd_t *pmd; |
32443 | pte_t *pte; | |
32444 | ||
32445 | +#ifdef CONFIG_PAX_SEGMEXEC | |
32446 | + struct vm_area_struct *vma_m; | |
32447 | +#endif | |
32448 | + | |
32449 | __set_current_state(TASK_RUNNING); | |
32450 | ||
32451 | count_vm_event(PGFAULT); | |
4dee9bd5 | 32452 | @@ -2521,6 +2763,34 @@ int handle_mm_fault(struct mm_struct *mm |
50425a20 | 32453 | if (unlikely(is_vm_hugetlb_page(vma))) |
32454 | return hugetlb_fault(mm, vma, address, write_access); | |
32455 | ||
32456 | +#ifdef CONFIG_PAX_SEGMEXEC | |
8a4b4a5e | 32457 | + vma_m = pax_find_mirror_vma(vma); |
32458 | + if (vma_m) { | |
50425a20 | 32459 | + unsigned long address_m; |
50425a20 | 32460 | + pgd_t *pgd_m; |
32461 | + pud_t *pud_m; | |
32462 | + pmd_t *pmd_m; | |
32463 | + | |
8a4b4a5e | 32464 | + if (vma->vm_start > vma_m->vm_start) { |
32465 | + address_m = address; | |
32466 | + address -= SEGMEXEC_TASK_SIZE; | |
50425a20 | 32467 | + vma = vma_m; |
8a4b4a5e | 32468 | + } else |
32469 | + address_m = address + SEGMEXEC_TASK_SIZE; | |
50425a20 | 32470 | + |
50425a20 | 32471 | + pgd_m = pgd_offset(mm, address_m); |
32472 | + pud_m = pud_alloc(mm, pgd_m, address_m); | |
32473 | + if (!pud_m) | |
32474 | + return VM_FAULT_OOM; | |
32475 | + pmd_m = pmd_alloc(mm, pud_m, address_m); | |
32476 | + if (!pmd_m) | |
32477 | + return VM_FAULT_OOM; | |
32478 | + if (!pmd_present(*pmd_m) && __pte_alloc(mm, pmd_m, address_m)) | |
32479 | + return VM_FAULT_OOM; | |
8a4b4a5e | 32480 | + pax_unmap_mirror_pte(vma_m, address_m, pmd_m); |
50425a20 | 32481 | + } |
32482 | +#endif | |
32483 | + | |
32484 | pgd = pgd_offset(mm, address); | |
32485 | pud = pud_alloc(mm, pgd, address); | |
32486 | if (!pud) | |
4dee9bd5 | 32487 | @@ -2614,7 +2884,7 @@ static int __init gate_vma_init(void) |
8a4b4a5e | 32488 | gate_vma.vm_start = FIXADDR_USER_START; |
32489 | gate_vma.vm_end = FIXADDR_USER_END; | |
32490 | gate_vma.vm_flags = VM_READ | VM_MAYREAD | VM_EXEC | VM_MAYEXEC; | |
32491 | - gate_vma.vm_page_prot = __P101; | |
32492 | + gate_vma.vm_page_prot = vm_get_page_prot(gate_vma.vm_flags); | |
32493 | /* | |
32494 | * Make sure the vDSO gets into every core dump. | |
32495 | * Dumping its contents makes post-mortem fully interpretable later | |
4dee9bd5 | 32496 | diff -urNp linux-2.6.25.4/mm/mempolicy.c linux-2.6.25.4/mm/mempolicy.c |
32497 | --- linux-2.6.25.4/mm/mempolicy.c 2008-05-15 11:00:12.000000000 -0400 | |
32498 | +++ linux-2.6.25.4/mm/mempolicy.c 2008-05-18 13:33:17.000000000 -0400 | |
32499 | @@ -433,6 +433,10 @@ static int mbind_range(struct vm_area_st | |
8a4b4a5e | 32500 | struct vm_area_struct *next; |
32501 | int err; | |
32502 | ||
32503 | +#ifdef CONFIG_PAX_SEGMEXEC | |
32504 | + struct vm_area_struct *vma_m; | |
32505 | +#endif | |
32506 | + | |
32507 | err = 0; | |
32508 | for (; vma && vma->vm_start < end; vma = next) { | |
32509 | next = vma->vm_next; | |
4dee9bd5 | 32510 | @@ -444,6 +448,16 @@ static int mbind_range(struct vm_area_st |
8a4b4a5e | 32511 | err = policy_vma(vma, new); |
32512 | if (err) | |
32513 | break; | |
50425a20 | 32514 | + |
32515 | +#ifdef CONFIG_PAX_SEGMEXEC | |
8a4b4a5e | 32516 | + vma_m = pax_find_mirror_vma(vma); |
32517 | + if (vma_m) { | |
32518 | + err = policy_vma(vma_m, new); | |
32519 | + if (err) | |
32520 | + break; | |
32521 | + } | |
50425a20 | 32522 | +#endif |
32523 | + | |
8a4b4a5e | 32524 | } |
32525 | return err; | |
32526 | } | |
4dee9bd5 | 32527 | @@ -809,6 +823,17 @@ static long do_mbind(unsigned long start |
8a4b4a5e | 32528 | |
32529 | if (end < start) | |
32530 | return -EINVAL; | |
32531 | + | |
32532 | +#ifdef CONFIG_PAX_SEGMEXEC | |
32533 | + if (mm->pax_flags & MF_PAX_SEGMEXEC) { | |
32534 | + if (end > SEGMEXEC_TASK_SIZE) | |
32535 | + return -EINVAL; | |
32536 | + } else | |
32537 | +#endif | |
32538 | + | |
32539 | + if (end > TASK_SIZE) | |
32540 | + return -EINVAL; | |
32541 | + | |
32542 | if (end == start) | |
32543 | return 0; | |
32544 | ||
4dee9bd5 | 32545 | diff -urNp linux-2.6.25.4/mm/mlock.c linux-2.6.25.4/mm/mlock.c |
32546 | --- linux-2.6.25.4/mm/mlock.c 2008-05-15 11:00:12.000000000 -0400 | |
32547 | +++ linux-2.6.25.4/mm/mlock.c 2008-05-18 13:33:17.000000000 -0400 | |
da5b3fc8 | 32548 | @@ -12,6 +12,7 @@ |
8a4b4a5e | 32549 | #include <linux/sched.h> |
32550 | #include <linux/module.h> | |
b79bc584 | 32551 | #include <linux/vs_memory.h> |
50425a20 | 32552 | +#include <linux/grsecurity.h> |
32553 | ||
8a4b4a5e | 32554 | int can_do_mlock(void) |
50425a20 | 32555 | { |
73ca38b2 | 32556 | @@ -95,6 +96,17 @@ static int do_mlock(unsigned long start, |
50425a20 | 32557 | return -EINVAL; |
32558 | if (end == start) | |
32559 | return 0; | |
32560 | + | |
32561 | +#ifdef CONFIG_PAX_SEGMEXEC | |
32562 | + if (current->mm->pax_flags & MF_PAX_SEGMEXEC) { | |
32563 | + if (end > SEGMEXEC_TASK_SIZE) | |
32564 | + return -EINVAL; | |
32565 | + } else | |
32566 | +#endif | |
32567 | + | |
32568 | + if (end > TASK_SIZE) | |
32569 | + return -EINVAL; | |
32570 | + | |
32571 | vma = find_vma_prev(current->mm, start, &prev); | |
32572 | if (!vma || vma->vm_start > start) | |
32573 | return -ENOMEM; | |
da5b3fc8 | 32574 | @@ -152,6 +164,7 @@ asmlinkage long sys_mlock(unsigned long |
50425a20 | 32575 | lock_limit >>= PAGE_SHIFT; |
32576 | ||
32577 | /* check against resource limits */ | |
32578 | + gr_learn_resource(current, RLIMIT_MEMLOCK, (current->mm->locked_vm << PAGE_SHIFT) + len, 1); | |
32579 | if ((locked <= lock_limit) || capable(CAP_IPC_LOCK)) | |
32580 | error = do_mlock(start, len, 1); | |
b79bc584 | 32581 | out: |
da5b3fc8 | 32582 | @@ -173,10 +186,10 @@ asmlinkage long sys_munlock(unsigned lon |
8a4b4a5e | 32583 | static int do_mlockall(int flags) |
32584 | { | |
32585 | struct vm_area_struct * vma, * prev = NULL; | |
32586 | - unsigned int def_flags = 0; | |
32587 | + unsigned int def_flags = current->mm->def_flags & ~VM_LOCKED; | |
32588 | ||
32589 | if (flags & MCL_FUTURE) | |
32590 | - def_flags = VM_LOCKED; | |
32591 | + def_flags |= VM_LOCKED; | |
32592 | current->mm->def_flags = def_flags; | |
32593 | if (flags == MCL_FUTURE) | |
32594 | goto out; | |
73ca38b2 | 32595 | @@ -184,6 +197,12 @@ static int do_mlockall(int flags) |
50425a20 | 32596 | for (vma = current->mm->mmap; vma ; vma = prev->vm_next) { |
32597 | unsigned int newflags; | |
32598 | ||
73ca38b2 | 32599 | +#ifdef CONFIG_PAX_SEGMEXEC |
32600 | + if ((current->mm->pax_flags & MF_PAX_SEGMEXEC) && (vma->vm_start >= SEGMEXEC_TASK_SIZE)) | |
32601 | + break; | |
32602 | +#endif | |
32603 | + | |
8a4b4a5e | 32604 | + BUG_ON(vma->vm_end > TASK_SIZE); |
50425a20 | 32605 | newflags = vma->vm_flags | VM_LOCKED; |
32606 | if (!(flags & MCL_CURRENT)) | |
32607 | newflags &= ~VM_LOCKED; | |
da5b3fc8 | 32608 | @@ -213,6 +232,7 @@ asmlinkage long sys_mlockall(int flags) |
50425a20 | 32609 | lock_limit >>= PAGE_SHIFT; |
32610 | ||
32611 | ret = -ENOMEM; | |
32612 | + gr_learn_resource(current, RLIMIT_MEMLOCK, current->mm->total_vm, 1); | |
b79bc584 | 32613 | if (!vx_vmlocked_avail(current->mm, current->mm->total_vm)) |
32614 | goto out; | |
50425a20 | 32615 | if (!(flags & MCL_CURRENT) || (current->mm->total_vm <= lock_limit) || |
4dee9bd5 | 32616 | diff -urNp linux-2.6.25.4/mm/mmap.c linux-2.6.25.4/mm/mmap.c |
32617 | --- linux-2.6.25.4/mm/mmap.c 2008-05-15 11:00:12.000000000 -0400 | |
32618 | +++ linux-2.6.25.4/mm/mmap.c 2008-05-18 13:33:17.000000000 -0400 | |
da5b3fc8 | 32619 | @@ -26,6 +26,7 @@ |
50425a20 | 32620 | #include <linux/mount.h> |
32621 | #include <linux/mempolicy.h> | |
32622 | #include <linux/rmap.h> | |
32623 | +#include <linux/grsecurity.h> | |
32624 | ||
32625 | #include <asm/uaccess.h> | |
32626 | #include <asm/cacheflush.h> | |
4dee9bd5 | 32627 | @@ -40,6 +41,16 @@ |
32628 | #define arch_rebalance_pgtables(addr, len) (addr) | |
da5b3fc8 | 32629 | #endif |
32630 | ||
32631 | +static inline void verify_mm_writelocked(struct mm_struct *mm) | |
32632 | +{ | |
32633 | +#if defined(CONFIG_DEBUG_VM) || defined(CONFIG_PAX) | |
32634 | + if (unlikely(down_read_trylock(&mm->mmap_sem))) { | |
32635 | + up_read(&mm->mmap_sem); | |
32636 | + BUG(); | |
32637 | + } | |
32638 | +#endif | |
32639 | +} | |
32640 | + | |
32641 | static void unmap_region(struct mm_struct *mm, | |
32642 | struct vm_area_struct *vma, struct vm_area_struct *prev, | |
32643 | unsigned long start, unsigned long end); | |
4dee9bd5 | 32644 | @@ -65,15 +76,23 @@ static void unmap_region(struct mm_struc |
8a4b4a5e | 32645 | * x: (no) no x: (no) yes x: (no) yes x: (yes) yes |
32646 | * | |
32647 | */ | |
32648 | -pgprot_t protection_map[16] = { | |
32649 | +pgprot_t protection_map[16] __read_only = { | |
32650 | __P000, __P001, __P010, __P011, __P100, __P101, __P110, __P111, | |
32651 | __S000, __S001, __S010, __S011, __S100, __S101, __S110, __S111 | |
32652 | }; | |
32653 | ||
32654 | pgprot_t vm_get_page_prot(unsigned long vm_flags) | |
32655 | { | |
32656 | - return protection_map[vm_flags & | |
32657 | - (VM_READ|VM_WRITE|VM_EXEC|VM_SHARED)]; | |
32658 | + pgprot_t prot = protection_map[vm_flags & (VM_READ|VM_WRITE|VM_EXEC|VM_SHARED)]; | |
32659 | + | |
32660 | +#if defined(CONFIG_PAX_PAGEEXEC) && defined(CONFIG_X86_32) | |
32661 | + if (!nx_enabled && | |
32662 | + (vm_flags & (VM_PAGEEXEC | VM_EXEC)) == VM_PAGEEXEC && | |
32663 | + (vm_flags & (VM_READ | VM_WRITE))) | |
32664 | + prot = __pgprot(pte_val(pte_exprotect(__pte(pgprot_val(prot))))); | |
32665 | +#endif | |
32666 | + | |
32667 | + return prot; | |
32668 | } | |
32669 | EXPORT_SYMBOL(vm_get_page_prot); | |
32670 | ||
4dee9bd5 | 32671 | @@ -228,6 +247,7 @@ static struct vm_area_struct *remove_vma |
8a4b4a5e | 32672 | struct vm_area_struct *next = vma->vm_next; |
32673 | ||
32674 | might_sleep(); | |
32675 | + BUG_ON(vma->vm_mirror); | |
32676 | if (vma->vm_ops && vma->vm_ops->close) | |
32677 | vma->vm_ops->close(vma); | |
32678 | if (vma->vm_file) | |
4dee9bd5 | 32679 | @@ -255,6 +275,7 @@ asmlinkage unsigned long sys_brk(unsigne |
50425a20 | 32680 | * not page aligned -Ram Gupta |
32681 | */ | |
32682 | rlim = current->signal->rlim[RLIMIT_DATA].rlim_cur; | |
4dee9bd5 | 32683 | + gr_learn_resource(current, RLIMIT_DATA, (brk - mm->start_brk) + (mm->end_data - mm->start_data), 1); |
32684 | if (rlim < RLIM_INFINITY && (brk - mm->start_brk) + | |
32685 | (mm->end_data - mm->start_data) > rlim) | |
50425a20 | 32686 | goto out; |
4dee9bd5 | 32687 | @@ -356,8 +377,12 @@ find_vma_prepare(struct mm_struct *mm, u |
8a4b4a5e | 32688 | |
32689 | if (vma_tmp->vm_end > addr) { | |
32690 | vma = vma_tmp; | |
32691 | - if (vma_tmp->vm_start <= addr) | |
32692 | - return vma; | |
32693 | + if (vma_tmp->vm_start <= addr) { | |
32694 | +//printk("PAX: prep: %08lx-%08lx %08lx pr:%p l:%p pa:%p ", | |
32695 | +//vma->vm_start, vma->vm_end, addr, *pprev, *rb_link, *rb_parent); | |
32696 | +//__print_symbol("%s\n", __builtin_extract_return_addr(__builtin_return_address(0))); | |
32697 | + break; | |
32698 | + } | |
32699 | __rb_link = &__rb_parent->rb_left; | |
32700 | } else { | |
32701 | rb_prev = __rb_parent; | |
4dee9bd5 | 32702 | @@ -681,6 +706,12 @@ static int |
8a4b4a5e | 32703 | can_vma_merge_before(struct vm_area_struct *vma, unsigned long vm_flags, |
32704 | struct anon_vma *anon_vma, struct file *file, pgoff_t vm_pgoff) | |
32705 | { | |
32706 | + | |
50425a20 | 32707 | +#ifdef CONFIG_PAX_SEGMEXEC |
8a4b4a5e | 32708 | + if ((vma->vm_mm->pax_flags & MF_PAX_SEGMEXEC) && vma->vm_start == SEGMEXEC_TASK_SIZE) |
32709 | + return 0; | |
50425a20 | 32710 | +#endif |
8a4b4a5e | 32711 | + |
32712 | if (is_mergeable_vma(vma, file, vm_flags) && | |
32713 | is_mergeable_anon_vma(anon_vma, vma->anon_vma)) { | |
32714 | if (vma->vm_pgoff == vm_pgoff) | |
4dee9bd5 | 32715 | @@ -700,6 +731,12 @@ static int |
8a4b4a5e | 32716 | can_vma_merge_after(struct vm_area_struct *vma, unsigned long vm_flags, |
32717 | struct anon_vma *anon_vma, struct file *file, pgoff_t vm_pgoff) | |
50425a20 | 32718 | { |
8a4b4a5e | 32719 | + |
32720 | +#ifdef CONFIG_PAX_SEGMEXEC | |
32721 | + if ((vma->vm_mm->pax_flags & MF_PAX_SEGMEXEC) && vma->vm_end == SEGMEXEC_TASK_SIZE) | |
50425a20 | 32722 | + return 0; |
8a4b4a5e | 32723 | +#endif |
32724 | + | |
32725 | if (is_mergeable_vma(vma, file, vm_flags) && | |
32726 | is_mergeable_anon_vma(anon_vma, vma->anon_vma)) { | |
32727 | pgoff_t vm_pglen; | |
4dee9bd5 | 32728 | @@ -742,12 +779,19 @@ can_vma_merge_after(struct vm_area_struc |
8a4b4a5e | 32729 | struct vm_area_struct *vma_merge(struct mm_struct *mm, |
32730 | struct vm_area_struct *prev, unsigned long addr, | |
32731 | unsigned long end, unsigned long vm_flags, | |
32732 | - struct anon_vma *anon_vma, struct file *file, | |
32733 | + struct anon_vma *anon_vma, struct file *file, | |
32734 | pgoff_t pgoff, struct mempolicy *policy) | |
50425a20 | 32735 | { |
8a4b4a5e | 32736 | pgoff_t pglen = (end - addr) >> PAGE_SHIFT; |
32737 | struct vm_area_struct *area, *next; | |
50425a20 | 32738 | |
32739 | +#ifdef CONFIG_PAX_SEGMEXEC | |
8a4b4a5e | 32740 | + unsigned long addr_m = addr + SEGMEXEC_TASK_SIZE, end_m = end + SEGMEXEC_TASK_SIZE; |
32741 | + struct vm_area_struct *area_m = NULL, *next_m = NULL, *prev_m = NULL; | |
50425a20 | 32742 | + |
8a4b4a5e | 32743 | + BUG_ON((mm->pax_flags & MF_PAX_SEGMEXEC) && SEGMEXEC_TASK_SIZE < end); |
32744 | +#endif | |
50425a20 | 32745 | + |
8a4b4a5e | 32746 | /* |
32747 | * We later require that vma->vm_flags == vm_flags, | |
32748 | * so this tests vma->vm_flags & VM_SPECIAL, too. | |
4dee9bd5 | 32749 | @@ -763,6 +807,15 @@ struct vm_area_struct *vma_merge(struct |
8a4b4a5e | 32750 | if (next && next->vm_end == end) /* cases 6, 7, 8 */ |
32751 | next = next->vm_next; | |
32752 | ||
32753 | +#ifdef CONFIG_PAX_SEGMEXEC | |
528970d3 | 32754 | + if (prev) |
32755 | + prev_m = pax_find_mirror_vma(prev); | |
32756 | + if (area) | |
32757 | + area_m = pax_find_mirror_vma(area); | |
32758 | + if (next) | |
32759 | + next_m = pax_find_mirror_vma(next); | |
8a4b4a5e | 32760 | +#endif |
50425a20 | 32761 | + |
8a4b4a5e | 32762 | /* |
32763 | * Can it merge with the predecessor? | |
32764 | */ | |
4dee9bd5 | 32765 | @@ -782,9 +835,24 @@ struct vm_area_struct *vma_merge(struct |
8a4b4a5e | 32766 | /* cases 1, 6 */ |
32767 | vma_adjust(prev, prev->vm_start, | |
32768 | next->vm_end, prev->vm_pgoff, NULL); | |
32769 | - } else /* cases 2, 5, 7 */ | |
50425a20 | 32770 | + |
8a4b4a5e | 32771 | +#ifdef CONFIG_PAX_SEGMEXEC |
528970d3 | 32772 | + if (prev_m) |
8a4b4a5e | 32773 | + vma_adjust(prev_m, prev_m->vm_start, |
32774 | + next_m->vm_end, prev_m->vm_pgoff, NULL); | |
32775 | +#endif | |
50425a20 | 32776 | + |
8a4b4a5e | 32777 | + } else { /* cases 2, 5, 7 */ |
32778 | vma_adjust(prev, prev->vm_start, | |
32779 | end, prev->vm_pgoff, NULL); | |
50425a20 | 32780 | + |
8a4b4a5e | 32781 | +#ifdef CONFIG_PAX_SEGMEXEC |
528970d3 | 32782 | + if (prev_m) |
8a4b4a5e | 32783 | + vma_adjust(prev_m, prev_m->vm_start, |
32784 | + end_m, prev_m->vm_pgoff, NULL); | |
50425a20 | 32785 | +#endif |
32786 | + | |
50425a20 | 32787 | + } |
8a4b4a5e | 32788 | return prev; |
32789 | } | |
32790 | ||
4dee9bd5 | 32791 | @@ -795,12 +863,43 @@ struct vm_area_struct *vma_merge(struct |
8a4b4a5e | 32792 | mpol_equal(policy, vma_policy(next)) && |
32793 | can_vma_merge_before(next, vm_flags, | |
32794 | anon_vma, file, pgoff+pglen)) { | |
32795 | - if (prev && addr < prev->vm_end) /* case 4 */ | |
32796 | + if (prev && addr < prev->vm_end) { /* case 4 */ | |
32797 | vma_adjust(prev, prev->vm_start, | |
32798 | addr, prev->vm_pgoff, NULL); | |
32799 | - else /* cases 3, 8 */ | |
50425a20 | 32800 | + |
8a4b4a5e | 32801 | +#ifdef CONFIG_PAX_SEGMEXEC |
528970d3 | 32802 | + if (prev_m) |
8a4b4a5e | 32803 | + vma_adjust(prev_m, prev_m->vm_start, |
32804 | + addr_m, prev_m->vm_pgoff, NULL); | |
32805 | +#endif | |
50425a20 | 32806 | + |
8a4b4a5e | 32807 | + } else { /* cases 3, 8 */ |
32808 | vma_adjust(area, addr, next->vm_end, | |
32809 | next->vm_pgoff - pglen, NULL); | |
32810 | + | |
32811 | +#ifdef CONFIG_PAX_SEGMEXEC | |
528970d3 | 32812 | + if (area_m) |
8a4b4a5e | 32813 | + vma_adjust(area_m, addr_m, next_m->vm_end, |
32814 | + next_m->vm_pgoff - pglen, NULL); | |
da5b3fc8 | 32815 | + else if (next_m) { |
32816 | + vma_adjust(next_m, addr_m, next_m->vm_end, | |
32817 | + next_m->vm_pgoff - pglen, NULL); | |
32818 | + BUG_ON(area == next); | |
32819 | + BUG_ON(area->vm_mirror); | |
32820 | + BUG_ON(next_m->anon_vma && next_m->anon_vma != area->anon_vma); | |
32821 | + BUG_ON(area->vm_file != next_m->vm_file); | |
32822 | + BUG_ON(area->vm_end - area->vm_start != next_m->vm_end - next_m->vm_start); | |
32823 | + BUG_ON(area->vm_pgoff != next_m->vm_pgoff); | |
32824 | + area->vm_mirror = next_m; | |
32825 | + next_m->vm_mirror = area; | |
32826 | + if (area->anon_vma && !next_m->anon_vma) { | |
32827 | + next_m->anon_vma = area->anon_vma; | |
32828 | + anon_vma_link(next_m); | |
32829 | + } | |
32830 | + } | |
50425a20 | 32831 | +#endif |
8a4b4a5e | 32832 | + |
32833 | + } | |
32834 | return area; | |
32835 | } | |
32836 | ||
4dee9bd5 | 32837 | @@ -875,14 +974,11 @@ none: |
8a4b4a5e | 32838 | void vm_stat_account(struct mm_struct *mm, unsigned long flags, |
32839 | struct file *file, long pages) | |
32840 | { | |
32841 | - const unsigned long stack_flags | |
32842 | - = VM_STACK_FLAGS & (VM_GROWSUP|VM_GROWSDOWN); | |
32843 | - | |
32844 | if (file) { | |
32845 | mm->shared_vm += pages; | |
32846 | if ((flags & (VM_EXEC|VM_WRITE)) == VM_EXEC) | |
32847 | mm->exec_vm += pages; | |
32848 | - } else if (flags & stack_flags) | |
32849 | + } else if (flags & (VM_GROWSUP|VM_GROWSDOWN)) | |
32850 | mm->stack_vm += pages; | |
32851 | if (flags & (VM_RESERVED|VM_IO)) | |
32852 | mm->reserved_vm += pages; | |
4dee9bd5 | 32853 | @@ -910,7 +1006,7 @@ unsigned long do_mmap_pgoff(struct file |
50425a20 | 32854 | * (the exception is when the underlying filesystem is noexec |
32855 | * mounted, in which case we dont add PROT_EXEC.) | |
32856 | */ | |
32857 | - if ((prot & PROT_READ) && (current->personality & READ_IMPLIES_EXEC)) | |
32858 | + if ((prot & (PROT_READ | PROT_WRITE)) && (current->personality & READ_IMPLIES_EXEC)) | |
32859 | if (!(file && (file->f_path.mnt->mnt_flags & MNT_NOEXEC))) | |
32860 | prot |= PROT_EXEC; | |
32861 | ||
4dee9bd5 | 32862 | @@ -920,15 +1016,15 @@ unsigned long do_mmap_pgoff(struct file |
da5b3fc8 | 32863 | if (!(flags & MAP_FIXED)) |
32864 | addr = round_hint_to_min(addr); | |
8a4b4a5e | 32865 | |
32866 | - error = arch_mmap_check(addr, len, flags); | |
32867 | - if (error) | |
32868 | - return error; | |
32869 | - | |
32870 | /* Careful about overflows.. */ | |
32871 | len = PAGE_ALIGN(len); | |
32872 | if (!len || len > TASK_SIZE) | |
32873 | return -ENOMEM; | |
32874 | ||
32875 | + error = arch_mmap_check(addr, len, flags); | |
32876 | + if (error) | |
32877 | + return error; | |
32878 | + | |
32879 | /* offset overflow? */ | |
32880 | if ((pgoff + (len >> PAGE_SHIFT)) < pgoff) | |
32881 | return -EOVERFLOW; | |
4dee9bd5 | 32882 | @@ -940,7 +1036,7 @@ unsigned long do_mmap_pgoff(struct file |
50425a20 | 32883 | /* Obtain the address to map to. we verify (or select) it and ensure |
32884 | * that it represents a valid section of the address space. | |
32885 | */ | |
32886 | - addr = get_unmapped_area(file, addr, len, pgoff, flags); | |
32887 | + addr = get_unmapped_area(file, addr, len, pgoff, flags | ((prot & PROT_EXEC) ? MAP_EXECUTABLE : 0)); | |
32888 | if (addr & ~PAGE_MASK) | |
32889 | return addr; | |
32890 | ||
4dee9bd5 | 32891 | @@ -951,6 +1047,26 @@ unsigned long do_mmap_pgoff(struct file |
50425a20 | 32892 | vm_flags = calc_vm_prot_bits(prot) | calc_vm_flag_bits(flags) | |
32893 | mm->def_flags | VM_MAYREAD | VM_MAYWRITE | VM_MAYEXEC; | |
32894 | ||
32895 | +#if defined(CONFIG_PAX_PAGEEXEC) || defined(CONFIG_PAX_SEGMEXEC) | |
32896 | + if (mm->pax_flags & (MF_PAX_PAGEEXEC | MF_PAX_SEGMEXEC)) { | |
32897 | + | |
32898 | +#ifdef CONFIG_PAX_MPROTECT | |
32899 | + if (mm->pax_flags & MF_PAX_MPROTECT) { | |
32900 | + if ((prot & (PROT_WRITE | PROT_EXEC)) != PROT_EXEC) | |
32901 | + vm_flags &= ~(VM_EXEC | VM_MAYEXEC); | |
32902 | + else | |
32903 | + vm_flags &= ~(VM_WRITE | VM_MAYWRITE); | |
32904 | + } | |
32905 | +#endif | |
32906 | + | |
32907 | + } | |
32908 | +#endif | |
8a4b4a5e | 32909 | + |
32910 | +#if defined(CONFIG_PAX_PAGEEXEC) && defined(CONFIG_X86_32) | |
32911 | + if ((mm->pax_flags & MF_PAX_PAGEEXEC) && file) | |
32912 | + vm_flags &= ~VM_PAGEEXEC; | |
32913 | +#endif | |
50425a20 | 32914 | + |
32915 | if (flags & MAP_LOCKED) { | |
32916 | if (!can_do_mlock()) | |
32917 | return -EPERM; | |
4dee9bd5 | 32918 | @@ -963,6 +1079,7 @@ unsigned long do_mmap_pgoff(struct file |
50425a20 | 32919 | locked += mm->locked_vm; |
32920 | lock_limit = current->signal->rlim[RLIMIT_MEMLOCK].rlim_cur; | |
32921 | lock_limit >>= PAGE_SHIFT; | |
32922 | + gr_learn_resource(current, RLIMIT_MEMLOCK, locked << PAGE_SHIFT, 1); | |
32923 | if (locked > lock_limit && !capable(CAP_IPC_LOCK)) | |
32924 | return -EAGAIN; | |
32925 | } | |
4dee9bd5 | 32926 | @@ -1031,6 +1148,9 @@ unsigned long do_mmap_pgoff(struct file |
50425a20 | 32927 | if (error) |
32928 | return error; | |
da5b3fc8 | 32929 | |
50425a20 | 32930 | + if (!gr_acl_handle_mmap(file, prot)) |
32931 | + return -EACCES; | |
da5b3fc8 | 32932 | + |
32933 | return mmap_region(file, addr, len, flags, vm_flags, pgoff, | |
32934 | accountable); | |
32935 | } | |
4dee9bd5 | 32936 | @@ -1044,10 +1164,10 @@ EXPORT_SYMBOL(do_mmap_pgoff); |
da5b3fc8 | 32937 | */ |
32938 | int vma_wants_writenotify(struct vm_area_struct *vma) | |
32939 | { | |
32940 | - unsigned int vm_flags = vma->vm_flags; | |
32941 | + unsigned long vm_flags = vma->vm_flags; | |
32942 | ||
32943 | /* If it was private or non-writable, the write bit is already clear */ | |
32944 | - if ((vm_flags & (VM_WRITE|VM_SHARED)) != ((VM_WRITE|VM_SHARED))) | |
32945 | + if ((vm_flags & (VM_WRITE|VM_SHARED)) != (VM_WRITE|VM_SHARED)) | |
32946 | return 0; | |
32947 | ||
32948 | /* The backer wishes to know when pages are first written to? */ | |
4dee9bd5 | 32949 | @@ -1082,14 +1202,24 @@ unsigned long mmap_region(struct file *f |
da5b3fc8 | 32950 | unsigned long charged = 0; |
32951 | struct inode *inode = file ? file->f_path.dentry->d_inode : NULL; | |
32952 | ||
32953 | +#ifdef CONFIG_PAX_SEGMEXEC | |
32954 | + struct vm_area_struct *vma_m = NULL; | |
32955 | +#endif | |
32956 | + | |
32957 | + /* | |
32958 | + * mm->mmap_sem is required to protect against another thread | |
32959 | + * changing the mappings in case we sleep. | |
32960 | + */ | |
32961 | + verify_mm_writelocked(mm); | |
50425a20 | 32962 | + |
32963 | /* Clear old maps */ | |
32964 | error = -ENOMEM; | |
32965 | -munmap_back: | |
32966 | vma = find_vma_prepare(mm, addr, &prev, &rb_link, &rb_parent); | |
32967 | if (vma && vma->vm_start < addr + len) { | |
32968 | if (do_munmap(mm, addr, len)) | |
32969 | return -ENOMEM; | |
32970 | - goto munmap_back; | |
32971 | + vma = find_vma_prepare(mm, addr, &prev, &rb_link, &rb_parent); | |
32972 | + BUG_ON(vma && vma->vm_start < addr + len); | |
32973 | } | |
32974 | ||
32975 | /* Check against address space limit. */ | |
4dee9bd5 | 32976 | @@ -1133,6 +1263,16 @@ munmap_back: |
8a4b4a5e | 32977 | goto unacct_error; |
50425a20 | 32978 | } |
32979 | ||
32980 | +#ifdef CONFIG_PAX_SEGMEXEC | |
8a4b4a5e | 32981 | + if ((mm->pax_flags & MF_PAX_SEGMEXEC) && (vm_flags & VM_EXEC)) { |
32982 | + vma_m = kmem_cache_zalloc(vm_area_cachep, GFP_KERNEL); | |
32983 | + if (!vma_m) { | |
8a4b4a5e | 32984 | + error = -ENOMEM; |
da5b3fc8 | 32985 | + goto free_vma; |
8a4b4a5e | 32986 | + } |
50425a20 | 32987 | + } |
32988 | +#endif | |
32989 | + | |
8a4b4a5e | 32990 | vma->vm_mm = mm; |
32991 | vma->vm_start = addr; | |
32992 | vma->vm_end = addr + len; | |
4dee9bd5 | 32993 | @@ -1155,6 +1295,14 @@ munmap_back: |
8a4b4a5e | 32994 | error = file->f_op->mmap(file, vma); |
32995 | if (error) | |
32996 | goto unmap_and_free_vma; | |
50425a20 | 32997 | + |
32998 | +#if defined(CONFIG_PAX_PAGEEXEC) && defined(CONFIG_X86_32) | |
8a4b4a5e | 32999 | + if ((mm->pax_flags & MF_PAX_PAGEEXEC) && !(vma->vm_flags & VM_SPECIAL)) { |
33000 | + vma->vm_flags |= VM_PAGEEXEC; | |
33001 | + vma->vm_page_prot = vm_get_page_prot(vma->vm_flags); | |
33002 | + } | |
50425a20 | 33003 | +#endif |
33004 | + | |
8a4b4a5e | 33005 | } else if (vm_flags & VM_SHARED) { |
33006 | error = shmem_zero_setup(vma); | |
33007 | if (error) | |
4dee9bd5 | 33008 | @@ -1185,6 +1333,12 @@ munmap_back: |
50425a20 | 33009 | vma->vm_flags, NULL, file, pgoff, vma_policy(vma))) { |
8a4b4a5e | 33010 | file = vma->vm_file; |
33011 | vma_link(mm, vma, prev, rb_link, rb_parent); | |
33012 | + | |
33013 | +#ifdef CONFIG_PAX_SEGMEXEC | |
33014 | + if (vma_m) | |
33015 | + pax_mirror_vma(vma_m, vma); | |
33016 | +#endif | |
33017 | + | |
33018 | if (correct_wcount) | |
33019 | atomic_inc(&inode->i_writecount); | |
33020 | } else { | |
4dee9bd5 | 33021 | @@ -1195,10 +1349,18 @@ munmap_back: |
8a4b4a5e | 33022 | } |
33023 | mpol_free(vma_policy(vma)); | |
33024 | kmem_cache_free(vm_area_cachep, vma); | |
33025 | + vma = NULL; | |
da5b3fc8 | 33026 | + |
33027 | +#ifdef CONFIG_PAX_SEGMEXEC | |
4dee9bd5 | 33028 | + if (vma_m) |
da5b3fc8 | 33029 | + kmem_cache_free(vm_area_cachep, vma_m); |
da5b3fc8 | 33030 | +#endif |
33031 | + | |
8a4b4a5e | 33032 | } |
50425a20 | 33033 | out: |
b79bc584 | 33034 | vx_vmpages_add(mm, len >> PAGE_SHIFT); |
50425a20 | 33035 | vm_stat_account(mm, vm_flags, file, len >> PAGE_SHIFT); |
33036 | + track_exec_limit(mm, addr, addr + len, vm_flags); | |
33037 | if (vm_flags & VM_LOCKED) { | |
b79bc584 | 33038 | vx_vmlocked_add(mm, len >> PAGE_SHIFT); |
50425a20 | 33039 | make_pages_present(addr, addr + len); |
4dee9bd5 | 33040 | @@ -1217,6 +1379,12 @@ unmap_and_free_vma: |
8a4b4a5e | 33041 | unmap_region(mm, vma, prev, vma->vm_start, vma->vm_end); |
33042 | charged = 0; | |
33043 | free_vma: | |
33044 | + | |
33045 | +#ifdef CONFIG_PAX_SEGMEXEC | |
33046 | + if (vma_m) | |
33047 | + kmem_cache_free(vm_area_cachep, vma_m); | |
33048 | +#endif | |
33049 | + | |
33050 | kmem_cache_free(vm_area_cachep, vma); | |
33051 | unacct_error: | |
33052 | if (charged) | |
4dee9bd5 | 33053 | @@ -1250,6 +1418,10 @@ arch_get_unmapped_area(struct file *filp |
8a4b4a5e | 33054 | if (flags & MAP_FIXED) |
33055 | return addr; | |
50425a20 | 33056 | |
33057 | +#ifdef CONFIG_PAX_RANDMMAP | |
33058 | + if (!(mm->pax_flags & MF_PAX_RANDMMAP)) | |
33059 | +#endif | |
33060 | + | |
33061 | if (addr) { | |
33062 | addr = PAGE_ALIGN(addr); | |
33063 | vma = find_vma(mm, addr); | |
4dee9bd5 | 33064 | @@ -1258,10 +1430,10 @@ arch_get_unmapped_area(struct file *filp |
8a4b4a5e | 33065 | return addr; |
33066 | } | |
50425a20 | 33067 | if (len > mm->cached_hole_size) { |
8a4b4a5e | 33068 | - start_addr = addr = mm->free_area_cache; |
33069 | + start_addr = addr = mm->free_area_cache; | |
50425a20 | 33070 | } else { |
33071 | - start_addr = addr = TASK_UNMAPPED_BASE; | |
8a4b4a5e | 33072 | - mm->cached_hole_size = 0; |
33073 | + start_addr = addr = mm->mmap_base; | |
33074 | + mm->cached_hole_size = 0; | |
50425a20 | 33075 | } |
33076 | ||
8a4b4a5e | 33077 | full_search: |
4dee9bd5 | 33078 | @@ -1272,9 +1444,8 @@ full_search: |
50425a20 | 33079 | * Start a new search - just in case we missed |
33080 | * some holes. | |
33081 | */ | |
33082 | - if (start_addr != TASK_UNMAPPED_BASE) { | |
33083 | - addr = TASK_UNMAPPED_BASE; | |
33084 | - start_addr = addr; | |
33085 | + if (start_addr != mm->mmap_base) { | |
33086 | + start_addr = addr = mm->mmap_base; | |
33087 | mm->cached_hole_size = 0; | |
33088 | goto full_search; | |
33089 | } | |
4dee9bd5 | 33090 | @@ -1296,10 +1467,16 @@ full_search: |
8a4b4a5e | 33091 | |
33092 | void arch_unmap_area(struct mm_struct *mm, unsigned long addr) | |
33093 | { | |
33094 | + | |
33095 | +#ifdef CONFIG_PAX_SEGMEXEC | |
33096 | + if ((mm->pax_flags & MF_PAX_SEGMEXEC) && SEGMEXEC_TASK_SIZE <= addr) | |
33097 | + return; | |
33098 | +#endif | |
33099 | + | |
50425a20 | 33100 | /* |
33101 | * Is this a new hole at the lowest possible address? | |
33102 | */ | |
33103 | - if (addr >= TASK_UNMAPPED_BASE && addr < mm->free_area_cache) { | |
33104 | + if (addr >= mm->mmap_base && addr < mm->free_area_cache) { | |
33105 | mm->free_area_cache = addr; | |
33106 | mm->cached_hole_size = ~0UL; | |
33107 | } | |
4dee9bd5 | 33108 | @@ -1317,7 +1494,7 @@ arch_get_unmapped_area_topdown(struct fi |
50425a20 | 33109 | { |
33110 | struct vm_area_struct *vma; | |
33111 | struct mm_struct *mm = current->mm; | |
33112 | - unsigned long addr = addr0; | |
33113 | + unsigned long base = mm->mmap_base, addr = addr0; | |
33114 | ||
33115 | /* requested length too big for entire address space */ | |
33116 | if (len > TASK_SIZE) | |
4dee9bd5 | 33117 | @@ -1326,6 +1503,10 @@ arch_get_unmapped_area_topdown(struct fi |
8a4b4a5e | 33118 | if (flags & MAP_FIXED) |
33119 | return addr; | |
50425a20 | 33120 | |
33121 | +#ifdef CONFIG_PAX_RANDMMAP | |
33122 | + if (!(mm->pax_flags & MF_PAX_RANDMMAP)) | |
33123 | +#endif | |
33124 | + | |
33125 | /* requesting a specific address */ | |
33126 | if (addr) { | |
33127 | addr = PAGE_ALIGN(addr); | |
4dee9bd5 | 33128 | @@ -1383,13 +1564,21 @@ bottomup: |
50425a20 | 33129 | * can happen with large stack limits and large mmap() |
33130 | * allocations. | |
33131 | */ | |
33132 | + mm->mmap_base = TASK_UNMAPPED_BASE; | |
33133 | + | |
33134 | +#ifdef CONFIG_PAX_RANDMMAP | |
33135 | + if (mm->pax_flags & MF_PAX_RANDMMAP) | |
33136 | + mm->mmap_base += mm->delta_mmap; | |
33137 | +#endif | |
33138 | + | |
33139 | + mm->free_area_cache = mm->mmap_base; | |
33140 | mm->cached_hole_size = ~0UL; | |
33141 | - mm->free_area_cache = TASK_UNMAPPED_BASE; | |
33142 | addr = arch_get_unmapped_area(filp, addr0, len, pgoff, flags); | |
33143 | /* | |
33144 | * Restore the topdown base: | |
33145 | */ | |
33146 | - mm->free_area_cache = mm->mmap_base; | |
33147 | + mm->mmap_base = base; | |
33148 | + mm->free_area_cache = base; | |
33149 | mm->cached_hole_size = ~0UL; | |
33150 | ||
33151 | return addr; | |
4dee9bd5 | 33152 | @@ -1398,6 +1587,12 @@ bottomup: |
8a4b4a5e | 33153 | |
33154 | void arch_unmap_area_topdown(struct mm_struct *mm, unsigned long addr) | |
33155 | { | |
33156 | + | |
33157 | +#ifdef CONFIG_PAX_SEGMEXEC | |
33158 | + if ((mm->pax_flags & MF_PAX_SEGMEXEC) && SEGMEXEC_TASK_SIZE <= addr) | |
33159 | + return; | |
33160 | +#endif | |
33161 | + | |
33162 | /* | |
33163 | * Is this a new hole at the highest possible address? | |
33164 | */ | |
4dee9bd5 | 33165 | @@ -1405,8 +1600,10 @@ void arch_unmap_area_topdown(struct mm_s |
50425a20 | 33166 | mm->free_area_cache = addr; |
33167 | ||
33168 | /* dont allow allocations above current base */ | |
33169 | - if (mm->free_area_cache > mm->mmap_base) | |
33170 | + if (mm->free_area_cache > mm->mmap_base) { | |
33171 | mm->free_area_cache = mm->mmap_base; | |
33172 | + mm->cached_hole_size = ~0UL; | |
33173 | + } | |
33174 | } | |
33175 | ||
33176 | unsigned long | |
4dee9bd5 | 33177 | @@ -1506,6 +1703,33 @@ out: |
8a4b4a5e | 33178 | return prev ? prev->vm_next : vma; |
33179 | } | |
33180 | ||
33181 | +#ifdef CONFIG_PAX_SEGMEXEC | |
33182 | +struct vm_area_struct *pax_find_mirror_vma(struct vm_area_struct *vma) | |
33183 | +{ | |
33184 | + struct vm_area_struct *vma_m; | |
33185 | + | |
33186 | + BUG_ON(!vma || vma->vm_start >= vma->vm_end); | |
33187 | + if (!(vma->vm_mm->pax_flags & MF_PAX_SEGMEXEC) || !(vma->vm_flags & VM_EXEC)) { | |
33188 | + BUG_ON(vma->vm_mirror); | |
33189 | + return NULL; | |
33190 | + } | |
73ca38b2 | 33191 | + BUG_ON(vma->vm_end - SEGMEXEC_TASK_SIZE - 1 < vma->vm_start - SEGMEXEC_TASK_SIZE - 1); |
8a4b4a5e | 33192 | + vma_m = vma->vm_mirror; |
33193 | + BUG_ON(!vma_m || vma_m->vm_mirror != vma); | |
da5b3fc8 | 33194 | + BUG_ON(vma->vm_file != vma_m->vm_file); |
8a4b4a5e | 33195 | + BUG_ON(vma->vm_end - vma->vm_start != vma_m->vm_end - vma_m->vm_start); |
33196 | + BUG_ON(vma->vm_pgoff != vma_m->vm_pgoff || vma->anon_vma != vma_m->anon_vma); | |
83a957c9 | 33197 | + |
33198 | +#ifdef CONFIG_PAX_MPROTECT | |
73ca38b2 | 33199 | + BUG_ON((vma->vm_flags ^ vma_m->vm_flags) & ~(VM_WRITE | VM_MAYWRITE | VM_ACCOUNT | VM_LOCKED | VM_MAYNOTWRITE)); |
83a957c9 | 33200 | +#else |
73ca38b2 | 33201 | + BUG_ON((vma->vm_flags ^ vma_m->vm_flags) & ~(VM_WRITE | VM_MAYWRITE | VM_ACCOUNT | VM_LOCKED)); |
83a957c9 | 33202 | +#endif |
33203 | + | |
8a4b4a5e | 33204 | + return vma_m; |
33205 | +} | |
33206 | +#endif | |
33207 | + | |
33208 | /* | |
33209 | * Verify that the stack growth is acceptable and | |
33210 | * update accounting. This is shared with both the | |
4dee9bd5 | 33211 | @@ -1522,6 +1746,7 @@ static int acct_stack_growth(struct vm_a |
50425a20 | 33212 | return -ENOMEM; |
33213 | ||
33214 | /* Stack limit test */ | |
33215 | + gr_learn_resource(current, RLIMIT_STACK, size, 1); | |
33216 | if (size > rlim[RLIMIT_STACK].rlim_cur) | |
33217 | return -ENOMEM; | |
33218 | ||
4dee9bd5 | 33219 | @@ -1531,6 +1756,7 @@ static int acct_stack_growth(struct vm_a |
50425a20 | 33220 | unsigned long limit; |
33221 | locked = mm->locked_vm + grow; | |
33222 | limit = rlim[RLIMIT_MEMLOCK].rlim_cur >> PAGE_SHIFT; | |
33223 | + gr_learn_resource(current, RLIMIT_MEMLOCK, locked << PAGE_SHIFT, 1); | |
33224 | if (locked > limit && !capable(CAP_IPC_LOCK)) | |
33225 | return -ENOMEM; | |
33226 | } | |
4dee9bd5 | 33227 | @@ -1545,7 +1771,7 @@ static int acct_stack_growth(struct vm_a |
da5b3fc8 | 33228 | * Overcommit.. This must be the final test, as it will |
33229 | * update security statistics. | |
33230 | */ | |
33231 | - if (security_vm_enough_memory(grow)) | |
33232 | + if (security_vm_enough_memory_mm(mm, grow)) | |
33233 | return -ENOMEM; | |
33234 | ||
33235 | /* Ok, everything looks good - let it rip */ | |
4dee9bd5 | 33236 | @@ -1566,35 +1792,40 @@ static inline |
da5b3fc8 | 33237 | #endif |
33238 | int expand_upwards(struct vm_area_struct *vma, unsigned long address) | |
50425a20 | 33239 | { |
da5b3fc8 | 33240 | - int error; |
33241 | + int error, locknext; | |
33242 | ||
33243 | if (!(vma->vm_flags & VM_GROWSUP)) | |
33244 | return -EFAULT; | |
33245 | ||
33246 | + /* Also guard against wrapping around to address 0. */ | |
33247 | + if (address < PAGE_ALIGN(address+1)) | |
33248 | + address = PAGE_ALIGN(address+1); | |
33249 | + else | |
33250 | + return -ENOMEM; | |
33251 | + | |
33252 | /* | |
33253 | * We must make sure the anon_vma is allocated | |
33254 | * so that the anon_vma locking is not a noop. | |
33255 | */ | |
33256 | if (unlikely(anon_vma_prepare(vma))) | |
33257 | return -ENOMEM; | |
33258 | + locknext = vma->vm_next && (vma->vm_next->vm_flags & VM_GROWSDOWN); | |
33259 | + if (locknext && unlikely(anon_vma_prepare(vma->vm_next))) | |
33260 | + return -ENOMEM; | |
33261 | anon_vma_lock(vma); | |
33262 | + if (locknext) | |
33263 | + anon_vma_lock(vma->vm_next); | |
33264 | ||
33265 | /* | |
33266 | * vma->vm_start/vm_end cannot change under us because the caller | |
33267 | * is required to hold the mmap_sem in read mode. We need the | |
33268 | - * anon_vma lock to serialize against concurrent expand_stacks. | |
33269 | - * Also guard against wrapping around to address 0. | |
33270 | + * anon_vma locks to serialize against concurrent expand_stacks | |
33271 | + * and expand_upwards. | |
33272 | */ | |
33273 | - if (address < PAGE_ALIGN(address+4)) | |
33274 | - address = PAGE_ALIGN(address+4); | |
33275 | - else { | |
33276 | - anon_vma_unlock(vma); | |
33277 | - return -ENOMEM; | |
50425a20 | 33278 | - } |
da5b3fc8 | 33279 | error = 0; |
33280 | ||
33281 | /* Somebody else might have raced and expanded it already */ | |
33282 | - if (address > vma->vm_end) { | |
33283 | + if (address > vma->vm_end && (!locknext || vma->vm_next->vm_start >= address)) { | |
33284 | unsigned long size, grow; | |
33285 | ||
33286 | size = address - vma->vm_start; | |
4dee9bd5 | 33287 | @@ -1604,6 +1835,8 @@ int expand_upwards(struct vm_area_struct |
da5b3fc8 | 33288 | if (!error) |
33289 | vma->vm_end = address; | |
33290 | } | |
33291 | + if (locknext) | |
33292 | + anon_vma_unlock(vma->vm_next); | |
33293 | anon_vma_unlock(vma); | |
33294 | return error; | |
33295 | } | |
4dee9bd5 | 33296 | @@ -1615,7 +1848,8 @@ int expand_upwards(struct vm_area_struct |
da5b3fc8 | 33297 | static inline int expand_downwards(struct vm_area_struct *vma, |
33298 | unsigned long address) | |
33299 | { | |
33300 | - int error; | |
33301 | + int error, lockprev = 0; | |
33302 | + struct vm_area_struct *prev = NULL; | |
33303 | ||
33304 | /* | |
33305 | * We must make sure the anon_vma is allocated | |
4dee9bd5 | 33306 | @@ -1629,6 +1863,15 @@ static inline int expand_downwards(struc |
da5b3fc8 | 33307 | if (error) |
33308 | return error; | |
33309 | ||
33310 | +#if defined(CONFIG_STACK_GROWSUP) || defined(CONFIG_IA64) | |
4dee9bd5 | 33311 | + find_vma_prev(vma->vm_mm, address, &prev); |
da5b3fc8 | 33312 | + lockprev = prev && (prev->vm_flags & VM_GROWSUP); |
33313 | +#endif | |
33314 | + if (lockprev && unlikely(anon_vma_prepare(prev))) | |
33315 | + return -ENOMEM; | |
33316 | + if (lockprev) | |
33317 | + anon_vma_lock(prev); | |
33318 | + | |
33319 | anon_vma_lock(vma); | |
33320 | ||
33321 | /* | |
4dee9bd5 | 33322 | @@ -1638,9 +1881,15 @@ static inline int expand_downwards(struc |
da5b3fc8 | 33323 | */ |
33324 | ||
33325 | /* Somebody else might have raced and expanded it already */ | |
33326 | - if (address < vma->vm_start) { | |
33327 | + if (address < vma->vm_start && (!lockprev || prev->vm_end <= address)) { | |
50425a20 | 33328 | unsigned long size, grow; |
33329 | ||
33330 | +#ifdef CONFIG_PAX_SEGMEXEC | |
8a4b4a5e | 33331 | + struct vm_area_struct *vma_m; |
33332 | + | |
33333 | + vma_m = pax_find_mirror_vma(vma); | |
50425a20 | 33334 | +#endif |
33335 | + | |
33336 | size = vma->vm_end - address; | |
33337 | grow = (vma->vm_start - address) >> PAGE_SHIFT; | |
33338 | ||
4dee9bd5 | 33339 | @@ -1648,9 +1897,20 @@ static inline int expand_downwards(struc |
50425a20 | 33340 | if (!error) { |
33341 | vma->vm_start = address; | |
33342 | vma->vm_pgoff -= grow; | |
33343 | + track_exec_limit(vma->vm_mm, vma->vm_start, vma->vm_end, vma->vm_flags); | |
33344 | + | |
33345 | +#ifdef CONFIG_PAX_SEGMEXEC | |
33346 | + if (vma_m) { | |
8a4b4a5e | 33347 | + vma_m->vm_start -= grow << PAGE_SHIFT; |
50425a20 | 33348 | + vma_m->vm_pgoff -= grow; |
33349 | + } | |
33350 | +#endif | |
33351 | + | |
33352 | } | |
33353 | } | |
33354 | anon_vma_unlock(vma); | |
da5b3fc8 | 33355 | + if (lockprev) |
33356 | + anon_vma_unlock(prev); | |
50425a20 | 33357 | return error; |
33358 | } | |
50425a20 | 33359 | |
4dee9bd5 | 33360 | @@ -1722,6 +1982,13 @@ static void remove_vma_list(struct mm_st |
73ca38b2 | 33361 | do { |
33362 | long nrpages = vma_pages(vma); | |
33363 | ||
33364 | +#ifdef CONFIG_PAX_SEGMEXEC | |
da5b3fc8 | 33365 | + if ((mm->pax_flags & MF_PAX_SEGMEXEC) && (vma->vm_start >= SEGMEXEC_TASK_SIZE)) { |
33366 | + vma = remove_vma(vma); | |
33367 | + continue; | |
33368 | + } | |
73ca38b2 | 33369 | +#endif |
33370 | + | |
b79bc584 | 33371 | vx_vmpages_sub(mm, nrpages); |
73ca38b2 | 33372 | if (vma->vm_flags & VM_LOCKED) |
b79bc584 | 33373 | vx_vmlocked_sub(mm, nrpages); |
4dee9bd5 | 33374 | @@ -1768,6 +2035,16 @@ detach_vmas_to_be_unmapped(struct mm_str |
8a4b4a5e | 33375 | |
33376 | insertion_point = (prev ? &prev->vm_next : &mm->mmap); | |
33377 | do { | |
33378 | + | |
33379 | +#ifdef CONFIG_PAX_SEGMEXEC | |
33380 | + if (vma->vm_mirror) { | |
33381 | + BUG_ON(!vma->vm_mirror->vm_mirror || vma->vm_mirror->vm_mirror != vma); | |
33382 | + vma->vm_mirror->vm_mirror = NULL; | |
528970d3 | 33383 | + vma->vm_mirror->vm_flags &= ~VM_EXEC; |
8a4b4a5e | 33384 | + vma->vm_mirror = NULL; |
33385 | + } | |
33386 | +#endif | |
33387 | + | |
33388 | rb_erase(&vma->vm_rb, &mm->mm_rb); | |
33389 | mm->map_count--; | |
33390 | tail_vma = vma; | |
4dee9bd5 | 33391 | @@ -1787,6 +2064,102 @@ detach_vmas_to_be_unmapped(struct mm_str |
8a4b4a5e | 33392 | * Split a vma into two pieces at address 'addr', a new vma is allocated |
33393 | * either for the first part or the tail. | |
50425a20 | 33394 | */ |
8a4b4a5e | 33395 | + |
50425a20 | 33396 | +#ifdef CONFIG_PAX_SEGMEXEC |
8a4b4a5e | 33397 | +int split_vma(struct mm_struct * mm, struct vm_area_struct * vma, |
33398 | + unsigned long addr, int new_below) | |
33399 | +{ | |
4dee9bd5 | 33400 | + struct mempolicy *pol; |
8a4b4a5e | 33401 | + struct vm_area_struct *new, *vma_m, *new_m = NULL; |
33402 | + unsigned long addr_m = addr + SEGMEXEC_TASK_SIZE; | |
50425a20 | 33403 | + |
8a4b4a5e | 33404 | + if (is_vm_hugetlb_page(vma) && (addr & ~HPAGE_MASK)) |
33405 | + return -EINVAL; | |
33406 | + | |
33407 | + vma_m = pax_find_mirror_vma(vma); | |
33408 | + if (vma_m) { | |
33409 | + BUG_ON(vma->vm_end > SEGMEXEC_TASK_SIZE); | |
33410 | + if (mm->map_count >= sysctl_max_map_count-1) | |
33411 | + return -ENOMEM; | |
33412 | + } else if (mm->map_count >= sysctl_max_map_count) | |
33413 | + return -ENOMEM; | |
33414 | + | |
33415 | + new = kmem_cache_alloc(vm_area_cachep, GFP_KERNEL); | |
33416 | + if (!new) | |
33417 | + return -ENOMEM; | |
33418 | + | |
33419 | + if (vma_m) { | |
33420 | + new_m = kmem_cache_alloc(vm_area_cachep, GFP_KERNEL); | |
33421 | + if (!new_m) { | |
33422 | + kmem_cache_free(vm_area_cachep, new); | |
33423 | + return -ENOMEM; | |
33424 | + } | |
50425a20 | 33425 | + } |
33426 | + | |
8a4b4a5e | 33427 | + /* most fields are the same, copy all, and then fixup */ |
33428 | + *new = *vma; | |
33429 | + | |
33430 | + if (new_below) | |
33431 | + new->vm_end = addr; | |
33432 | + else { | |
33433 | + new->vm_start = addr; | |
33434 | + new->vm_pgoff += ((addr - vma->vm_start) >> PAGE_SHIFT); | |
33435 | + } | |
33436 | + | |
33437 | + if (vma_m) { | |
33438 | + *new_m = *vma_m; | |
33439 | + new_m->vm_mirror = new; | |
33440 | + new->vm_mirror = new_m; | |
50425a20 | 33441 | + |
8a4b4a5e | 33442 | + if (new_below) |
33443 | + new_m->vm_end = addr_m; | |
33444 | + else { | |
33445 | + new_m->vm_start = addr_m; | |
33446 | + new_m->vm_pgoff += ((addr_m - vma_m->vm_start) >> PAGE_SHIFT); | |
33447 | + } | |
33448 | + } | |
33449 | + | |
33450 | + pol = mpol_copy(vma_policy(vma)); | |
33451 | + if (IS_ERR(pol)) { | |
33452 | + if (new_m) | |
33453 | + kmem_cache_free(vm_area_cachep, new_m); | |
33454 | + kmem_cache_free(vm_area_cachep, new); | |
33455 | + return PTR_ERR(pol); | |
33456 | + } | |
8a4b4a5e | 33457 | + vma_set_policy(new, pol); |
33458 | + | |
33459 | + if (new->vm_file) | |
33460 | + get_file(new->vm_file); | |
33461 | + | |
33462 | + if (new->vm_ops && new->vm_ops->open) | |
33463 | + new->vm_ops->open(new); | |
33464 | + | |
33465 | + if (new_below) | |
33466 | + vma_adjust(vma, addr, vma->vm_end, vma->vm_pgoff + | |
33467 | + ((addr - new->vm_start) >> PAGE_SHIFT), new); | |
33468 | + else | |
33469 | + vma_adjust(vma, vma->vm_start, addr, vma->vm_pgoff, new); | |
33470 | + | |
33471 | + if (vma_m) { | |
4dee9bd5 | 33472 | + mpol_get(pol); |
33473 | + vma_set_policy(new_m, pol); | |
8a4b4a5e | 33474 | + |
33475 | + if (new_m->vm_file) | |
33476 | + get_file(new_m->vm_file); | |
33477 | + | |
33478 | + if (new_m->vm_ops && new_m->vm_ops->open) | |
33479 | + new_m->vm_ops->open(new_m); | |
33480 | + | |
33481 | + if (new_below) | |
33482 | + vma_adjust(vma_m, addr_m, vma_m->vm_end, vma_m->vm_pgoff + | |
33483 | + ((addr_m - new_m->vm_start) >> PAGE_SHIFT), new_m); | |
33484 | + else | |
33485 | + vma_adjust(vma_m, vma_m->vm_start, addr_m, vma_m->vm_pgoff, new_m); | |
33486 | + } | |
33487 | + | |
33488 | + return 0; | |
33489 | +} | |
50425a20 | 33490 | +#else |
8a4b4a5e | 33491 | int split_vma(struct mm_struct * mm, struct vm_area_struct * vma, |
33492 | unsigned long addr, int new_below) | |
33493 | { | |
4dee9bd5 | 33494 | @@ -1834,17 +2207,37 @@ int split_vma(struct mm_struct * mm, str |
8a4b4a5e | 33495 | |
33496 | return 0; | |
33497 | } | |
50425a20 | 33498 | +#endif |
8a4b4a5e | 33499 | |
33500 | /* Munmap is split into 2 main parts -- this part which finds | |
33501 | * what needs doing, and the areas themselves, which do the | |
33502 | * work. This now handles partial unmappings. | |
33503 | * Jeremy Fitzhardinge <jeremy@goop.org> | |
33504 | */ | |
33505 | +#ifdef CONFIG_PAX_SEGMEXEC | |
4dee9bd5 | 33506 | int do_munmap(struct mm_struct *mm, unsigned long start, size_t len) |
33507 | { | |
8a4b4a5e | 33508 | + int ret = __do_munmap(mm, start, len); |
33509 | + if (ret || !(mm->pax_flags & MF_PAX_SEGMEXEC)) | |
33510 | + return ret; | |
33511 | + | |
33512 | + return __do_munmap(mm, start + SEGMEXEC_TASK_SIZE, len); | |
33513 | +} | |
33514 | + | |
33515 | +int __do_munmap(struct mm_struct *mm, unsigned long start, size_t len) | |
33516 | +#else | |
4dee9bd5 | 33517 | +int do_munmap(struct mm_struct *mm, unsigned long start, size_t len) |
8a4b4a5e | 33518 | +#endif |
4dee9bd5 | 33519 | +{ |
50425a20 | 33520 | unsigned long end; |
33521 | struct vm_area_struct *vma, *prev, *last; | |
528970d3 | 33522 | |
da5b3fc8 | 33523 | + /* |
33524 | + * mm->mmap_sem is required to protect against another thread | |
33525 | + * changing the mappings in case we sleep. | |
33526 | + */ | |
33527 | + verify_mm_writelocked(mm); | |
33528 | + | |
33529 | if ((start & ~PAGE_MASK) || start > TASK_SIZE || len > TASK_SIZE-start) | |
33530 | return -EINVAL; | |
33531 | ||
4dee9bd5 | 33532 | @@ -1894,6 +2287,8 @@ int do_munmap(struct mm_struct *mm, unsi |
50425a20 | 33533 | /* Fix up all other VM information */ |
33534 | remove_vma_list(mm, vma); | |
33535 | ||
33536 | + track_exec_limit(mm, start, end, 0UL); | |
33537 | + | |
33538 | return 0; | |
33539 | } | |
33540 | ||
4dee9bd5 | 33541 | @@ -1906,22 +2301,18 @@ asmlinkage long sys_munmap(unsigned long |
50425a20 | 33542 | |
33543 | profile_munmap(addr); | |
33544 | ||
33545 | +#ifdef CONFIG_PAX_SEGMEXEC | |
33546 | + if ((mm->pax_flags & MF_PAX_SEGMEXEC) && | |
33547 | + (len > SEGMEXEC_TASK_SIZE || addr > SEGMEXEC_TASK_SIZE-len)) | |
33548 | + return -EINVAL; | |
33549 | +#endif | |
8a4b4a5e | 33550 | + |
33551 | down_write(&mm->mmap_sem); | |
33552 | ret = do_munmap(mm, addr, len); | |
33553 | up_write(&mm->mmap_sem); | |
da5b3fc8 | 33554 | return ret; |
33555 | } | |
33556 | ||
33557 | -static inline void verify_mm_writelocked(struct mm_struct *mm) | |
33558 | -{ | |
33559 | -#ifdef CONFIG_DEBUG_VM | |
33560 | - if (unlikely(down_read_trylock(&mm->mmap_sem))) { | |
33561 | - WARN_ON(1); | |
33562 | - up_read(&mm->mmap_sem); | |
33563 | - } | |
33564 | -#endif | |
33565 | -} | |
33566 | - | |
33567 | /* | |
33568 | * this is really a simplified "do_mmap". it only handles | |
33569 | * anonymous maps. eventually we may be able to do some | |
4dee9bd5 | 33570 | @@ -1935,6 +2326,11 @@ unsigned long do_brk(unsigned long addr, |
50425a20 | 33571 | struct rb_node ** rb_link, * rb_parent; |
33572 | pgoff_t pgoff = addr >> PAGE_SHIFT; | |
33573 | int error; | |
8a4b4a5e | 33574 | + unsigned long charged; |
33575 | + | |
50425a20 | 33576 | +#ifdef CONFIG_PAX_SEGMEXEC |
8a4b4a5e | 33577 | + struct vm_area_struct *vma_m = NULL; |
50425a20 | 33578 | +#endif |
50425a20 | 33579 | |
8a4b4a5e | 33580 | len = PAGE_ALIGN(len); |
33581 | if (!len) | |
4dee9bd5 | 33582 | @@ -1952,19 +2348,34 @@ unsigned long do_brk(unsigned long addr, |
50425a20 | 33583 | |
33584 | flags = VM_DATA_DEFAULT_FLAGS | VM_ACCOUNT | mm->def_flags; | |
33585 | ||
33586 | +#if defined(CONFIG_PAX_PAGEEXEC) || defined(CONFIG_PAX_SEGMEXEC) | |
33587 | + if (mm->pax_flags & (MF_PAX_PAGEEXEC | MF_PAX_SEGMEXEC)) { | |
33588 | + flags &= ~VM_EXEC; | |
33589 | + | |
33590 | +#ifdef CONFIG_PAX_MPROTECT | |
33591 | + if (mm->pax_flags & MF_PAX_MPROTECT) | |
33592 | + flags &= ~VM_MAYEXEC; | |
33593 | +#endif | |
33594 | + | |
33595 | + } | |
33596 | +#endif | |
33597 | + | |
33598 | error = arch_mmap_check(addr, len, flags); | |
33599 | if (error) | |
33600 | return error; | |
8a4b4a5e | 33601 | |
33602 | + charged = len >> PAGE_SHIFT; | |
33603 | + | |
33604 | /* | |
33605 | * mlock MCL_FUTURE? | |
33606 | */ | |
33607 | if (mm->def_flags & VM_LOCKED) { | |
33608 | unsigned long locked, lock_limit; | |
33609 | - locked = len >> PAGE_SHIFT; | |
33610 | + locked = charged; | |
50425a20 | 33611 | locked += mm->locked_vm; |
33612 | lock_limit = current->signal->rlim[RLIMIT_MEMLOCK].rlim_cur; | |
33613 | lock_limit >>= PAGE_SHIFT; | |
33614 | + gr_learn_resource(current, RLIMIT_MEMLOCK, locked << PAGE_SHIFT, 1); | |
33615 | if (locked > lock_limit && !capable(CAP_IPC_LOCK)) | |
33616 | return -EAGAIN; | |
4dee9bd5 | 33617 | } |
b79bc584 | 33618 | @@ -1978,23 +2389,23 @@ unsigned long do_brk(unsigned long addr, |
50425a20 | 33619 | /* |
33620 | * Clear old maps. this also does some error checking for us | |
33621 | */ | |
33622 | - munmap_back: | |
33623 | vma = find_vma_prepare(mm, addr, &prev, &rb_link, &rb_parent); | |
33624 | if (vma && vma->vm_start < addr + len) { | |
33625 | if (do_munmap(mm, addr, len)) | |
33626 | return -ENOMEM; | |
33627 | - goto munmap_back; | |
33628 | + vma = find_vma_prepare(mm, addr, &prev, &rb_link, &rb_parent); | |
33629 | + BUG_ON(vma && vma->vm_start < addr + len); | |
33630 | } | |
33631 | ||
33632 | /* Check against address space limits *after* clearing old maps... */ | |
8a4b4a5e | 33633 | - if (!may_expand_vm(mm, len >> PAGE_SHIFT)) |
33634 | + if (!may_expand_vm(mm, charged)) | |
33635 | return -ENOMEM; | |
33636 | ||
33637 | if (mm->map_count > sysctl_max_map_count) | |
33638 | return -ENOMEM; | |
33639 | ||
b79bc584 | 33640 | - if (security_vm_enough_memory(len >> PAGE_SHIFT) || |
33641 | - !vx_vmpages_avail(mm, len >> PAGE_SHIFT)) | |
33642 | + if (security_vm_enough_memory(charged) || | |
33643 | + !vx_vmpages_avail(mm, charged)) | |
8a4b4a5e | 33644 | return -ENOMEM; |
33645 | ||
33646 | /* Can we just expand an old private anonymous mapping? */ | |
4dee9bd5 | 33647 | @@ -2006,10 +2417,21 @@ unsigned long do_brk(unsigned long addr, |
8a4b4a5e | 33648 | */ |
33649 | vma = kmem_cache_zalloc(vm_area_cachep, GFP_KERNEL); | |
33650 | if (!vma) { | |
33651 | - vm_unacct_memory(len >> PAGE_SHIFT); | |
33652 | + vm_unacct_memory(charged); | |
33653 | return -ENOMEM; | |
33654 | } | |
33655 | ||
33656 | +#ifdef CONFIG_PAX_SEGMEXEC | |
33657 | + if ((mm->pax_flags & MF_PAX_SEGMEXEC) && (flags & VM_EXEC)) { | |
33658 | + vma_m = kmem_cache_zalloc(vm_area_cachep, GFP_KERNEL); | |
33659 | + if (!vma_m) { | |
33660 | + kmem_cache_free(vm_area_cachep, vma); | |
33661 | + vm_unacct_memory(charged); | |
33662 | + return -ENOMEM; | |
33663 | + } | |
33664 | + } | |
33665 | +#endif | |
33666 | + | |
33667 | vma->vm_mm = mm; | |
33668 | vma->vm_start = addr; | |
50425a20 | 33669 | vma->vm_end = addr + len; |
4dee9bd5 | 33670 | @@ -2017,12 +2439,19 @@ unsigned long do_brk(unsigned long addr, |
50425a20 | 33671 | vma->vm_flags = flags; |
da5b3fc8 | 33672 | vma->vm_page_prot = vm_get_page_prot(flags); |
8a4b4a5e | 33673 | vma_link(mm, vma, prev, rb_link, rb_parent); |
50425a20 | 33674 | + |
8a4b4a5e | 33675 | +#ifdef CONFIG_PAX_SEGMEXEC |
33676 | + if (vma_m) | |
33677 | + pax_mirror_vma(vma_m, vma); | |
50425a20 | 33678 | +#endif |
33679 | + | |
8a4b4a5e | 33680 | out: |
b79bc584 | 33681 | - vx_vmpages_add(mm, len >> PAGE_SHIFT); |
33682 | + vx_vmpages_add(mm, charged); | |
8a4b4a5e | 33683 | if (flags & VM_LOCKED) { |
b79bc584 | 33684 | - vx_vmlocked_add(mm, len >> PAGE_SHIFT); |
33685 | + vx_vmlocked_add(mm, charged); | |
50425a20 | 33686 | make_pages_present(addr, addr + len); |
33687 | } | |
33688 | + track_exec_limit(mm, addr, addr + len, flags); | |
33689 | return addr; | |
33690 | } | |
33691 | ||
4dee9bd5 | 33692 | @@ -2053,8 +2482,10 @@ void exit_mmap(struct mm_struct *mm) |
8a4b4a5e | 33693 | * Walk the list again, actually closing and freeing it, |
33694 | * with preemption enabled, without holding any MM locks. | |
33695 | */ | |
33696 | - while (vma) | |
33697 | + while (vma) { | |
33698 | + vma->vm_mirror = NULL; | |
33699 | vma = remove_vma(vma); | |
33700 | + } | |
33701 | ||
33702 | BUG_ON(mm->nr_ptes > (FIRST_USER_ADDRESS+PMD_SIZE-1)>>PMD_SHIFT); | |
33703 | } | |
4dee9bd5 | 33704 | @@ -2068,6 +2499,10 @@ int insert_vm_struct(struct mm_struct * |
8a4b4a5e | 33705 | struct vm_area_struct * __vma, * prev; |
33706 | struct rb_node ** rb_link, * rb_parent; | |
33707 | ||
33708 | +#ifdef CONFIG_PAX_SEGMEXEC | |
33709 | + struct vm_area_struct *vma_m = NULL; | |
33710 | +#endif | |
33711 | + | |
33712 | /* | |
33713 | * The vm_pgoff of a purely anonymous vma should be irrelevant | |
33714 | * until its first write fault, when page's anon_vma and index | |
4dee9bd5 | 33715 | @@ -2090,7 +2525,22 @@ int insert_vm_struct(struct mm_struct * |
da5b3fc8 | 33716 | if ((vma->vm_flags & VM_ACCOUNT) && |
33717 | security_vm_enough_memory_mm(mm, vma_pages(vma))) | |
8a4b4a5e | 33718 | return -ENOMEM; |
33719 | + | |
33720 | +#ifdef CONFIG_PAX_SEGMEXEC | |
33721 | + if ((mm->pax_flags & MF_PAX_SEGMEXEC) && (vma->vm_flags & VM_EXEC)) { | |
33722 | + vma_m = kmem_cache_zalloc(vm_area_cachep, GFP_KERNEL); | |
33723 | + if (!vma_m) | |
33724 | + return -ENOMEM; | |
33725 | + } | |
33726 | +#endif | |
33727 | + | |
33728 | vma_link(mm, vma, prev, rb_link, rb_parent); | |
33729 | + | |
33730 | +#ifdef CONFIG_PAX_SEGMEXEC | |
33731 | + if (vma_m) | |
33732 | + pax_mirror_vma(vma_m, vma); | |
33733 | +#endif | |
33734 | + | |
33735 | return 0; | |
33736 | } | |
33737 | ||
4dee9bd5 | 33738 | @@ -2108,6 +2558,8 @@ struct vm_area_struct *copy_vma(struct v |
da5b3fc8 | 33739 | struct rb_node **rb_link, *rb_parent; |
33740 | struct mempolicy *pol; | |
33741 | ||
33742 | + BUG_ON(vma->vm_mirror); | |
33743 | + | |
33744 | /* | |
33745 | * If anonymous vma has not yet been faulted, update new pgoff | |
33746 | * to match new location, to increase its chance of merging. | |
4dee9bd5 | 33747 | @@ -2148,6 +2600,35 @@ struct vm_area_struct *copy_vma(struct v |
8a4b4a5e | 33748 | return new_vma; |
33749 | } | |
33750 | ||
33751 | +#ifdef CONFIG_PAX_SEGMEXEC | |
33752 | +void pax_mirror_vma(struct vm_area_struct *vma_m, struct vm_area_struct *vma) | |
33753 | +{ | |
33754 | + struct vm_area_struct *prev_m; | |
33755 | + struct rb_node **rb_link_m, *rb_parent_m; | |
da5b3fc8 | 33756 | + struct mempolicy *pol_m; |
8a4b4a5e | 33757 | + |
33758 | + BUG_ON(!(vma->vm_mm->pax_flags & MF_PAX_SEGMEXEC) || !(vma->vm_flags & VM_EXEC)); | |
da5b3fc8 | 33759 | + BUG_ON(vma->vm_mirror || vma_m->vm_mirror); |
33760 | + BUG_ON(!vma_mpol_equal(vma, vma_m)); | |
8a4b4a5e | 33761 | + *vma_m = *vma; |
4dee9bd5 | 33762 | + pol_m = vma_policy(vma); |
33763 | + mpol_get(pol_m); | |
da5b3fc8 | 33764 | + vma_set_policy(vma_m, pol_m); |
8a4b4a5e | 33765 | + vma_m->vm_start += SEGMEXEC_TASK_SIZE; |
33766 | + vma_m->vm_end += SEGMEXEC_TASK_SIZE; | |
73ca38b2 | 33767 | + vma_m->vm_flags &= ~(VM_WRITE | VM_MAYWRITE | VM_ACCOUNT | VM_LOCKED); |
8a4b4a5e | 33768 | + vma_m->vm_page_prot = vm_get_page_prot(vma_m->vm_flags); |
33769 | + if (vma_m->vm_file) | |
33770 | + get_file(vma_m->vm_file); | |
33771 | + if (vma_m->vm_ops && vma_m->vm_ops->open) | |
33772 | + vma_m->vm_ops->open(vma_m); | |
33773 | + find_vma_prepare(vma->vm_mm, vma_m->vm_start, &prev_m, &rb_link_m, &rb_parent_m); | |
33774 | + vma_link(vma->vm_mm, vma_m, prev_m, rb_link_m, rb_parent_m); | |
33775 | + vma_m->vm_mirror = vma; | |
33776 | + vma->vm_mirror = vma_m; | |
33777 | +} | |
33778 | +#endif | |
33779 | + | |
33780 | /* | |
33781 | * Return true if the calling process may expand its vm space by the passed | |
33782 | * number of pages | |
4dee9bd5 | 33783 | @@ -2158,7 +2639,7 @@ int may_expand_vm(struct mm_struct *mm, |
50425a20 | 33784 | unsigned long lim; |
33785 | ||
33786 | lim = current->signal->rlim[RLIMIT_AS].rlim_cur >> PAGE_SHIFT; | |
33787 | - | |
33788 | + gr_learn_resource(current, RLIMIT_AS, (cur + npages) << PAGE_SHIFT, 1); | |
33789 | if (cur + npages > lim) | |
33790 | return 0; | |
da5b3fc8 | 33791 | return 1; |
4dee9bd5 | 33792 | @@ -2227,6 +2708,15 @@ int install_special_mapping(struct mm_st |
8a4b4a5e | 33793 | vma->vm_start = addr; |
33794 | vma->vm_end = addr + len; | |
50425a20 | 33795 | |
8a4b4a5e | 33796 | +#ifdef CONFIG_PAX_MPROTECT |
33797 | + if (mm->pax_flags & MF_PAX_MPROTECT) { | |
33798 | + if ((vm_flags & (VM_WRITE | VM_EXEC)) != VM_EXEC) | |
33799 | + vm_flags &= ~(VM_EXEC | VM_MAYEXEC); | |
33800 | + else | |
33801 | + vm_flags &= ~(VM_WRITE | VM_MAYWRITE); | |
50425a20 | 33802 | + } |
33803 | +#endif | |
33804 | + | |
da5b3fc8 | 33805 | vma->vm_flags = vm_flags | mm->def_flags | VM_DONTEXPAND; |
33806 | vma->vm_page_prot = vm_get_page_prot(vma->vm_flags); | |
50425a20 | 33807 | |
4dee9bd5 | 33808 | diff -urNp linux-2.6.25.4/mm/mprotect.c linux-2.6.25.4/mm/mprotect.c |
33809 | --- linux-2.6.25.4/mm/mprotect.c 2008-05-15 11:00:12.000000000 -0400 | |
33810 | +++ linux-2.6.25.4/mm/mprotect.c 2008-05-18 13:33:17.000000000 -0400 | |
50425a20 | 33811 | @@ -21,10 +21,17 @@ |
33812 | #include <linux/syscalls.h> | |
33813 | #include <linux/swap.h> | |
33814 | #include <linux/swapops.h> | |
33815 | +#include <linux/grsecurity.h> | |
33816 | + | |
33817 | +#ifdef CONFIG_PAX_MPROTECT | |
33818 | +#include <linux/elf.h> | |
33819 | +#endif | |
33820 | + | |
33821 | #include <asm/uaccess.h> | |
33822 | #include <asm/pgtable.h> | |
33823 | #include <asm/cacheflush.h> | |
33824 | #include <asm/tlbflush.h> | |
33825 | +#include <asm/mmu_context.h> | |
33826 | ||
33827 | static void change_pte_range(struct mm_struct *mm, pmd_t *pmd, | |
33828 | unsigned long addr, unsigned long end, pgprot_t newprot, | |
da5b3fc8 | 33829 | @@ -127,6 +134,48 @@ static void change_protection(struct vm_ |
50425a20 | 33830 | flush_tlb_range(vma, start, end); |
33831 | } | |
33832 | ||
33833 | +#ifdef CONFIG_ARCH_TRACK_EXEC_LIMIT | |
da5b3fc8 | 33834 | +/* called while holding the mmap semaphor for writing except stack expansion */ |
50425a20 | 33835 | +void track_exec_limit(struct mm_struct *mm, unsigned long start, unsigned long end, unsigned long prot) |
33836 | +{ | |
33837 | + unsigned long oldlimit, newlimit = 0UL; | |
33838 | + | |
8a4b4a5e | 33839 | + if (!(mm->pax_flags & MF_PAX_PAGEEXEC) || nx_enabled) |
50425a20 | 33840 | + return; |
33841 | + | |
33842 | + spin_lock(&mm->page_table_lock); | |
33843 | + oldlimit = mm->context.user_cs_limit; | |
33844 | + if ((prot & VM_EXEC) && oldlimit < end) | |
33845 | + /* USER_CS limit moved up */ | |
33846 | + newlimit = end; | |
33847 | + else if (!(prot & VM_EXEC) && start < oldlimit && oldlimit <= end) | |
33848 | + /* USER_CS limit moved down */ | |
33849 | + newlimit = start; | |
33850 | + | |
33851 | + if (newlimit) { | |
33852 | + mm->context.user_cs_limit = newlimit; | |
33853 | + | |
33854 | +#ifdef CONFIG_SMP | |
33855 | + wmb(); | |
33856 | + cpus_clear(mm->context.cpu_user_cs_mask); | |
33857 | + cpu_set(smp_processor_id(), mm->context.cpu_user_cs_mask); | |
33858 | +#endif | |
33859 | + | |
33860 | + set_user_cs(mm->context.user_cs_base, mm->context.user_cs_limit, smp_processor_id()); | |
33861 | + } | |
33862 | + spin_unlock(&mm->page_table_lock); | |
da5b3fc8 | 33863 | + if (newlimit == end) { |
33864 | + struct vm_area_struct *vma = find_vma(mm, oldlimit); | |
33865 | + | |
33866 | + for (; vma && vma->vm_start < end; vma = vma->vm_next) | |
33867 | + if (is_vm_hugetlb_page(vma)) | |
33868 | + hugetlb_change_protection(vma, vma->vm_start, vma->vm_end, vma->vm_page_prot); | |
33869 | + else | |
33870 | + change_protection(vma, vma->vm_start, vma->vm_end, vma->vm_page_prot, vma_wants_writenotify(vma)); | |
33871 | + } | |
50425a20 | 33872 | +} |
33873 | +#endif | |
33874 | + | |
da5b3fc8 | 33875 | int |
8a4b4a5e | 33876 | mprotect_fixup(struct vm_area_struct *vma, struct vm_area_struct **pprev, |
33877 | unsigned long start, unsigned long end, unsigned long newflags) | |
da5b3fc8 | 33878 | @@ -139,11 +188,41 @@ mprotect_fixup(struct vm_area_struct *vm |
8a4b4a5e | 33879 | int error; |
33880 | int dirty_accountable = 0; | |
33881 | ||
50425a20 | 33882 | +#ifdef CONFIG_PAX_SEGMEXEC |
8a4b4a5e | 33883 | + struct vm_area_struct *vma_m = NULL; |
33884 | + unsigned long start_m, end_m; | |
50425a20 | 33885 | + |
8a4b4a5e | 33886 | + start_m = start + SEGMEXEC_TASK_SIZE; |
33887 | + end_m = end + SEGMEXEC_TASK_SIZE; | |
33888 | +#endif | |
50425a20 | 33889 | + |
8a4b4a5e | 33890 | if (newflags == oldflags) { |
33891 | *pprev = vma; | |
33892 | return 0; | |
33893 | } | |
33894 | ||
33895 | +#ifdef CONFIG_PAX_SEGMEXEC | |
33896 | + if (pax_find_mirror_vma(vma) && !(newflags & VM_EXEC)) { | |
33897 | + if (start != vma->vm_start) { | |
33898 | + error = split_vma(mm, vma, start, 1); | |
33899 | + if (error) | |
33900 | + return -ENOMEM; | |
da5b3fc8 | 33901 | + BUG_ON(!*pprev || (*pprev)->vm_next == vma); |
33902 | + *pprev = (*pprev)->vm_next; | |
8a4b4a5e | 33903 | + } |
50425a20 | 33904 | + |
8a4b4a5e | 33905 | + if (end != vma->vm_end) { |
33906 | + error = split_vma(mm, vma, end, 0); | |
50425a20 | 33907 | + if (error) |
8a4b4a5e | 33908 | + return -ENOMEM; |
50425a20 | 33909 | + } |
50425a20 | 33910 | + |
8a4b4a5e | 33911 | + error = __do_munmap(mm, start_m, end_m - start_m); |
33912 | + if (error) | |
33913 | + return -ENOMEM; | |
33914 | + } | |
33915 | +#endif | |
50425a20 | 33916 | + |
8a4b4a5e | 33917 | /* |
33918 | * If we make a private mapping writable we increase our commit; | |
33919 | * but (without finer accounting) cannot reduce our commit if we | |
4dee9bd5 | 33920 | @@ -186,6 +265,16 @@ mprotect_fixup(struct vm_area_struct *vm |
8a4b4a5e | 33921 | goto fail; |
50425a20 | 33922 | } |
50425a20 | 33923 | |
8a4b4a5e | 33924 | +#ifdef CONFIG_PAX_SEGMEXEC |
33925 | + if ((mm->pax_flags & MF_PAX_SEGMEXEC) && !(oldflags & VM_EXEC) && (newflags & VM_EXEC)) { | |
33926 | + vma_m = kmem_cache_zalloc(vm_area_cachep, GFP_KERNEL); | |
33927 | + if (!vma_m) { | |
33928 | + error = -ENOMEM; | |
33929 | + goto fail; | |
33930 | + } | |
33931 | + } | |
33932 | +#endif | |
33933 | + | |
33934 | success: | |
50425a20 | 33935 | /* |
8a4b4a5e | 33936 | * vm_flags and vm_page_prot are protected by the mmap_sem |
4dee9bd5 | 33937 | @@ -202,6 +291,12 @@ success: |
8a4b4a5e | 33938 | hugetlb_change_protection(vma, start, end, vma->vm_page_prot); |
33939 | else | |
33940 | change_protection(vma, start, end, vma->vm_page_prot, dirty_accountable); | |
50425a20 | 33941 | + |
8a4b4a5e | 33942 | +#ifdef CONFIG_PAX_SEGMEXEC |
33943 | + if (vma_m) | |
33944 | + pax_mirror_vma(vma_m, vma); | |
50425a20 | 33945 | +#endif |
33946 | + | |
8a4b4a5e | 33947 | vm_stat_account(mm, oldflags, vma->vm_file, -nrpages); |
33948 | vm_stat_account(mm, newflags, vma->vm_file, nrpages); | |
33949 | return 0; | |
4dee9bd5 | 33950 | @@ -211,6 +306,70 @@ fail: |
50425a20 | 33951 | return error; |
33952 | } | |
33953 | ||
33954 | +#ifdef CONFIG_PAX_MPROTECT | |
33955 | +/* PaX: non-PIC ELF libraries need relocations on their executable segments | |
33956 | + * therefore we'll grant them VM_MAYWRITE once during their life. | |
33957 | + * | |
33958 | + * The checks favour ld-linux.so behaviour which operates on a per ELF segment | |
33959 | + * basis because we want to allow the common case and not the special ones. | |
33960 | + */ | |
8a4b4a5e | 33961 | +static inline void pax_handle_maywrite(struct vm_area_struct *vma, unsigned long start) |
50425a20 | 33962 | +{ |
33963 | + struct elfhdr elf_h; | |
8a4b4a5e | 33964 | + struct elf_phdr elf_p; |
33965 | + elf_addr_t dyn_offset = 0UL; | |
50425a20 | 33966 | + elf_dyn dyn; |
33967 | + unsigned long i, j = 65536UL / sizeof(struct elf_phdr); | |
33968 | + | |
33969 | +#ifndef CONFIG_PAX_NOELFRELOCS | |
33970 | + if ((vma->vm_start != start) || | |
33971 | + !vma->vm_file || | |
33972 | + !(vma->vm_flags & VM_MAYEXEC) || | |
33973 | + (vma->vm_flags & VM_MAYNOTWRITE)) | |
33974 | +#endif | |
33975 | + | |
33976 | + return; | |
33977 | + | |
8a4b4a5e | 33978 | + if (sizeof(elf_h) != kernel_read(vma->vm_file, 0UL, (char *)&elf_h, sizeof(elf_h)) || |
50425a20 | 33979 | + memcmp(elf_h.e_ident, ELFMAG, SELFMAG) || |
33980 | + | |
33981 | +#ifdef CONFIG_PAX_ETEXECRELOCS | |
33982 | + (elf_h.e_type != ET_DYN && elf_h.e_type != ET_EXEC) || | |
33983 | +#else | |
33984 | + elf_h.e_type != ET_DYN || | |
33985 | +#endif | |
33986 | + | |
33987 | + !elf_check_arch(&elf_h) || | |
33988 | + elf_h.e_phentsize != sizeof(struct elf_phdr) || | |
33989 | + elf_h.e_phnum > j) | |
33990 | + return; | |
33991 | + | |
33992 | + for (i = 0UL; i < elf_h.e_phnum; i++) { | |
8a4b4a5e | 33993 | + if (sizeof(elf_p) != kernel_read(vma->vm_file, elf_h.e_phoff + i*sizeof(elf_p), (char *)&elf_p, sizeof(elf_p))) |
50425a20 | 33994 | + return; |
33995 | + if (elf_p.p_type == PT_DYNAMIC) { | |
8a4b4a5e | 33996 | + dyn_offset = elf_p.p_offset; |
50425a20 | 33997 | + j = i; |
33998 | + } | |
33999 | + } | |
34000 | + if (elf_h.e_phnum <= j) | |
34001 | + return; | |
34002 | + | |
34003 | + i = 0UL; | |
34004 | + do { | |
8a4b4a5e | 34005 | + if (sizeof(dyn) != kernel_read(vma->vm_file, dyn_offset + i*sizeof(dyn), (char *)&dyn, sizeof(dyn))) |
50425a20 | 34006 | + return; |
34007 | + if (dyn.d_tag == DT_TEXTREL || (dyn.d_tag == DT_FLAGS && (dyn.d_un.d_val & DF_TEXTREL))) { | |
da5b3fc8 | 34008 | + vma->vm_flags |= VM_MAYWRITE | VM_MAYNOTWRITE; |
4dee9bd5 | 34009 | + gr_log_textrel(vma); |
50425a20 | 34010 | + return; |
34011 | + } | |
34012 | + i++; | |
34013 | + } while (dyn.d_tag != DT_NULL); | |
34014 | + return; | |
34015 | +} | |
34016 | +#endif | |
34017 | + | |
34018 | asmlinkage long | |
34019 | sys_mprotect(unsigned long start, size_t len, unsigned long prot) | |
34020 | { | |
4dee9bd5 | 34021 | @@ -230,6 +389,17 @@ sys_mprotect(unsigned long start, size_t |
50425a20 | 34022 | end = start + len; |
34023 | if (end <= start) | |
34024 | return -ENOMEM; | |
34025 | + | |
34026 | +#ifdef CONFIG_PAX_SEGMEXEC | |
34027 | + if (current->mm->pax_flags & MF_PAX_SEGMEXEC) { | |
34028 | + if (end > SEGMEXEC_TASK_SIZE) | |
34029 | + return -EINVAL; | |
34030 | + } else | |
34031 | +#endif | |
34032 | + | |
34033 | + if (end > TASK_SIZE) | |
34034 | + return -EINVAL; | |
34035 | + | |
34036 | if (prot & ~(PROT_READ | PROT_WRITE | PROT_EXEC | PROT_SEM)) | |
34037 | return -EINVAL; | |
34038 | ||
4dee9bd5 | 34039 | @@ -237,7 +407,7 @@ sys_mprotect(unsigned long start, size_t |
50425a20 | 34040 | /* |
34041 | * Does the application expect PROT_READ to imply PROT_EXEC: | |
34042 | */ | |
34043 | - if ((prot & PROT_READ) && (current->personality & READ_IMPLIES_EXEC)) | |
34044 | + if ((prot & (PROT_READ | PROT_WRITE)) && (current->personality & READ_IMPLIES_EXEC)) | |
34045 | prot |= PROT_EXEC; | |
34046 | ||
34047 | vm_flags = calc_vm_prot_bits(prot); | |
4dee9bd5 | 34048 | @@ -269,6 +439,16 @@ sys_mprotect(unsigned long start, size_t |
50425a20 | 34049 | if (start > vma->vm_start) |
34050 | prev = vma; | |
34051 | ||
34052 | + if (!gr_acl_handle_mprotect(vma->vm_file, prot)) { | |
34053 | + error = -EACCES; | |
34054 | + goto out; | |
34055 | + } | |
34056 | + | |
34057 | +#ifdef CONFIG_PAX_MPROTECT | |
34058 | + if ((vma->vm_mm->pax_flags & MF_PAX_MPROTECT) && (prot & PROT_WRITE)) | |
34059 | + pax_handle_maywrite(vma, start); | |
34060 | +#endif | |
34061 | + | |
34062 | for (nstart = start ; ; ) { | |
34063 | unsigned long newflags; | |
34064 | ||
4dee9bd5 | 34065 | @@ -282,6 +462,12 @@ sys_mprotect(unsigned long start, size_t |
50425a20 | 34066 | goto out; |
34067 | } | |
34068 | ||
34069 | +#ifdef CONFIG_PAX_MPROTECT | |
34070 | + /* PaX: disallow write access after relocs are done, hopefully noone else needs it... */ | |
34071 | + if ((vma->vm_mm->pax_flags & MF_PAX_MPROTECT) && !(prot & PROT_WRITE) && (vma->vm_flags & VM_MAYNOTWRITE)) | |
34072 | + newflags &= ~VM_MAYWRITE; | |
34073 | +#endif | |
34074 | + | |
34075 | error = security_file_mprotect(vma, reqprot, prot); | |
34076 | if (error) | |
34077 | goto out; | |
4dee9bd5 | 34078 | @@ -292,6 +478,9 @@ sys_mprotect(unsigned long start, size_t |
8a4b4a5e | 34079 | error = mprotect_fixup(vma, &prev, nstart, tmp, newflags); |
34080 | if (error) | |
50425a20 | 34081 | goto out; |
50425a20 | 34082 | + |
8a4b4a5e | 34083 | + track_exec_limit(current->mm, nstart, tmp, vm_flags); |
50425a20 | 34084 | + |
8a4b4a5e | 34085 | nstart = tmp; |
34086 | ||
34087 | if (nstart < prev->vm_end) | |
4dee9bd5 | 34088 | diff -urNp linux-2.6.25.4/mm/mremap.c linux-2.6.25.4/mm/mremap.c |
34089 | --- linux-2.6.25.4/mm/mremap.c 2008-05-15 11:00:12.000000000 -0400 | |
34090 | +++ linux-2.6.25.4/mm/mremap.c 2008-05-18 13:33:17.000000000 -0400 | |
50425a20 | 34091 | @@ -106,6 +106,12 @@ static void move_ptes(struct vm_area_str |
34092 | continue; | |
34093 | pte = ptep_clear_flush(vma, old_addr, old_pte); | |
34094 | pte = move_pte(pte, new_vma->vm_page_prot, old_addr, new_addr); | |
34095 | + | |
34096 | +#ifdef CONFIG_ARCH_TRACK_EXEC_LIMIT | |
8a4b4a5e | 34097 | + if (!nx_enabled && (new_vma->vm_flags & (VM_PAGEEXEC | VM_EXEC)) == VM_PAGEEXEC) |
34098 | + pte = pte_exprotect(pte); | |
50425a20 | 34099 | +#endif |
34100 | + | |
34101 | set_pte_at(mm, new_addr, new_pte, pte); | |
34102 | } | |
34103 | ||
34104 | @@ -254,6 +260,7 @@ unsigned long do_mremap(unsigned long ad | |
34105 | struct vm_area_struct *vma; | |
34106 | unsigned long ret = -EINVAL; | |
34107 | unsigned long charged = 0; | |
b7f09679 | 34108 | + unsigned long pax_task_size = TASK_SIZE; |
50425a20 | 34109 | |
34110 | if (flags & ~(MREMAP_FIXED | MREMAP_MAYMOVE)) | |
34111 | goto out; | |
34112 | @@ -272,6 +279,15 @@ unsigned long do_mremap(unsigned long ad | |
34113 | if (!new_len) | |
34114 | goto out; | |
34115 | ||
34116 | +#ifdef CONFIG_PAX_SEGMEXEC | |
34117 | + if (current->mm->pax_flags & MF_PAX_SEGMEXEC) | |
b7f09679 | 34118 | + pax_task_size = SEGMEXEC_TASK_SIZE; |
50425a20 | 34119 | +#endif |
34120 | + | |
b7f09679 | 34121 | + if (new_len > pax_task_size || addr > pax_task_size-new_len || |
34122 | + old_len > pax_task_size || addr > pax_task_size-old_len) | |
50425a20 | 34123 | + goto out; |
34124 | + | |
34125 | /* new_addr is only valid if MREMAP_FIXED is specified */ | |
34126 | if (flags & MREMAP_FIXED) { | |
34127 | if (new_addr & ~PAGE_MASK) | |
34128 | @@ -279,16 +295,13 @@ unsigned long do_mremap(unsigned long ad | |
34129 | if (!(flags & MREMAP_MAYMOVE)) | |
34130 | goto out; | |
34131 | ||
34132 | - if (new_len > TASK_SIZE || new_addr > TASK_SIZE - new_len) | |
b7f09679 | 34133 | + if (new_addr > pax_task_size - new_len) |
50425a20 | 34134 | goto out; |
34135 | ||
34136 | /* Check if the location we're moving into overlaps the | |
34137 | * old location at all, and fail if it does. | |
34138 | */ | |
34139 | - if ((new_addr <= addr) && (new_addr+new_len) > addr) | |
34140 | - goto out; | |
34141 | - | |
34142 | - if ((addr <= new_addr) && (addr+old_len) > new_addr) | |
34143 | + if (addr + old_len > new_addr && new_addr + new_len > addr) | |
34144 | goto out; | |
34145 | ||
da5b3fc8 | 34146 | ret = security_file_mmap(NULL, 0, 0, 0, new_addr, 1); |
34147 | @@ -326,6 +339,14 @@ unsigned long do_mremap(unsigned long ad | |
50425a20 | 34148 | ret = -EINVAL; |
34149 | goto out; | |
34150 | } | |
34151 | + | |
34152 | +#ifdef CONFIG_PAX_SEGMEXEC | |
8a4b4a5e | 34153 | + if (pax_find_mirror_vma(vma)) { |
50425a20 | 34154 | + ret = -EINVAL; |
34155 | + goto out; | |
34156 | + } | |
34157 | +#endif | |
34158 | + | |
34159 | /* We can't remap across vm area boundaries */ | |
34160 | if (old_len > vma->vm_end - addr) | |
34161 | goto out; | |
da5b3fc8 | 34162 | @@ -359,7 +380,7 @@ unsigned long do_mremap(unsigned long ad |
50425a20 | 34163 | if (old_len == vma->vm_end - addr && |
34164 | !((flags & MREMAP_FIXED) && (addr != new_addr)) && | |
34165 | (old_len != new_len || !(flags & MREMAP_MAYMOVE))) { | |
34166 | - unsigned long max_addr = TASK_SIZE; | |
b7f09679 | 34167 | + unsigned long max_addr = pax_task_size; |
50425a20 | 34168 | if (vma->vm_next) |
34169 | max_addr = vma->vm_next->vm_start; | |
34170 | /* can we just expand the current mapping? */ | |
da5b3fc8 | 34171 | @@ -377,6 +398,7 @@ unsigned long do_mremap(unsigned long ad |
50425a20 | 34172 | addr + new_len); |
34173 | } | |
34174 | ret = addr; | |
34175 | + track_exec_limit(vma->vm_mm, vma->vm_start, addr + new_len, vma->vm_flags); | |
34176 | goto out; | |
34177 | } | |
34178 | } | |
da5b3fc8 | 34179 | @@ -387,8 +409,8 @@ unsigned long do_mremap(unsigned long ad |
50425a20 | 34180 | */ |
34181 | ret = -ENOMEM; | |
34182 | if (flags & MREMAP_MAYMOVE) { | |
34183 | + unsigned long map_flags = 0; | |
34184 | if (!(flags & MREMAP_FIXED)) { | |
34185 | - unsigned long map_flags = 0; | |
34186 | if (vma->vm_flags & VM_MAYSHARE) | |
34187 | map_flags |= MAP_SHARED; | |
34188 | ||
da5b3fc8 | 34189 | @@ -403,7 +425,12 @@ unsigned long do_mremap(unsigned long ad |
34190 | if (ret) | |
50425a20 | 34191 | goto out; |
34192 | } | |
34193 | + map_flags = vma->vm_flags; | |
34194 | ret = move_vma(vma, addr, old_len, new_len, new_addr); | |
34195 | + if (!(ret & ~PAGE_MASK)) { | |
34196 | + track_exec_limit(current->mm, addr, addr + old_len, 0UL); | |
34197 | + track_exec_limit(current->mm, new_addr, new_addr + new_len, map_flags); | |
34198 | + } | |
34199 | } | |
34200 | out: | |
34201 | if (ret & ~PAGE_MASK) | |
4dee9bd5 | 34202 | diff -urNp linux-2.6.25.4/mm/nommu.c linux-2.6.25.4/mm/nommu.c |
34203 | --- linux-2.6.25.4/mm/nommu.c 2008-05-15 11:00:12.000000000 -0400 | |
34204 | +++ linux-2.6.25.4/mm/nommu.c 2008-05-18 13:33:17.000000000 -0400 | |
34205 | @@ -405,15 +405,6 @@ struct vm_area_struct *find_vma(struct m | |
da5b3fc8 | 34206 | } |
50425a20 | 34207 | EXPORT_SYMBOL(find_vma); |
34208 | ||
da5b3fc8 | 34209 | -/* |
50425a20 | 34210 | - * find a VMA |
34211 | - * - we don't extend stack VMAs under NOMMU conditions | |
34212 | - */ | |
34213 | -struct vm_area_struct *find_extend_vma(struct mm_struct *mm, unsigned long addr) | |
34214 | -{ | |
34215 | - return find_vma(mm, addr); | |
34216 | -} | |
34217 | - | |
da5b3fc8 | 34218 | int expand_stack(struct vm_area_struct *vma, unsigned long address) |
34219 | { | |
34220 | return -ENOMEM; | |
4dee9bd5 | 34221 | diff -urNp linux-2.6.25.4/mm/page_alloc.c linux-2.6.25.4/mm/page_alloc.c |
34222 | --- linux-2.6.25.4/mm/page_alloc.c 2008-05-15 11:00:12.000000000 -0400 | |
34223 | +++ linux-2.6.25.4/mm/page_alloc.c 2008-05-18 13:33:17.000000000 -0400 | |
34224 | @@ -514,9 +514,20 @@ static void free_pages_bulk(struct zone | |
50425a20 | 34225 | |
da5b3fc8 | 34226 | static void free_one_page(struct zone *zone, struct page *page, int order) |
34227 | { | |
34228 | + | |
34229 | +#ifdef CONFIG_PAX_MEMORY_SANITIZE | |
34230 | + unsigned long index = 1UL << order; | |
34231 | +#endif | |
34232 | + | |
34233 | spin_lock(&zone->lock); | |
34234 | zone_clear_flag(zone, ZONE_ALL_UNRECLAIMABLE); | |
34235 | zone->pages_scanned = 0; | |
34236 | + | |
50425a20 | 34237 | +#ifdef CONFIG_PAX_MEMORY_SANITIZE |
da5b3fc8 | 34238 | + for (; index; --index) |
50425a20 | 34239 | + sanitize_highpage(page + index - 1); |
34240 | +#endif | |
34241 | + | |
da5b3fc8 | 34242 | __free_one_page(page, zone, order); |
34243 | spin_unlock(&zone->lock); | |
34244 | } | |
4dee9bd5 | 34245 | @@ -641,8 +652,10 @@ static int prep_new_page(struct page *pa |
da5b3fc8 | 34246 | arch_alloc_page(page, order); |
34247 | kernel_map_pages(page, 1 << order, 1); | |
34248 | ||
34249 | +#ifndef CONFIG_PAX_MEMORY_SANITIZE | |
34250 | if (gfp_flags & __GFP_ZERO) | |
34251 | prep_zero_page(page, order, gfp_flags); | |
34252 | +#endif | |
34253 | ||
34254 | if (order && (gfp_flags & __GFP_COMP)) | |
34255 | prep_compound_page(page, order); | |
4dee9bd5 | 34256 | @@ -1009,6 +1022,11 @@ static void free_hot_cold_page(struct pa |
34257 | list_add(&page->lru, &pcp->list); | |
da5b3fc8 | 34258 | set_page_private(page, get_pageblock_migratetype(page)); |
34259 | pcp->count++; | |
34260 | + | |
34261 | +#ifdef CONFIG_PAX_MEMORY_SANITIZE | |
34262 | + sanitize_highpage(page); | |
34263 | +#endif | |
34264 | + | |
34265 | if (pcp->count >= pcp->high) { | |
34266 | free_pages_bulk(zone, pcp->batch, &pcp->list, 0); | |
34267 | pcp->count -= pcp->batch; | |
4dee9bd5 | 34268 | diff -urNp linux-2.6.25.4/mm/rmap.c linux-2.6.25.4/mm/rmap.c |
34269 | --- linux-2.6.25.4/mm/rmap.c 2008-05-15 11:00:12.000000000 -0400 | |
34270 | +++ linux-2.6.25.4/mm/rmap.c 2008-05-18 13:33:17.000000000 -0400 | |
da5b3fc8 | 34271 | @@ -64,6 +64,10 @@ int anon_vma_prepare(struct vm_area_stru |
8a4b4a5e | 34272 | struct mm_struct *mm = vma->vm_mm; |
34273 | struct anon_vma *allocated, *locked; | |
34274 | ||
34275 | +#ifdef CONFIG_PAX_SEGMEXEC | |
34276 | + struct vm_area_struct *vma_m; | |
34277 | +#endif | |
34278 | + | |
34279 | anon_vma = find_mergeable_anon_vma(vma); | |
34280 | if (anon_vma) { | |
50425a20 | 34281 | allocated = NULL; |
da5b3fc8 | 34282 | @@ -80,6 +84,15 @@ int anon_vma_prepare(struct vm_area_stru |
8a4b4a5e | 34283 | /* page_table_lock to protect against threads */ |
34284 | spin_lock(&mm->page_table_lock); | |
34285 | if (likely(!vma->anon_vma)) { | |
50425a20 | 34286 | + |
34287 | +#ifdef CONFIG_PAX_SEGMEXEC | |
8a4b4a5e | 34288 | + vma_m = pax_find_mirror_vma(vma); |
34289 | + if (vma_m) { | |
50425a20 | 34290 | + vma_m->anon_vma = anon_vma; |
34291 | + __anon_vma_link(vma_m); | |
34292 | + } | |
34293 | +#endif | |
34294 | + | |
8a4b4a5e | 34295 | vma->anon_vma = anon_vma; |
34296 | list_add_tail(&vma->anon_vma_node, &anon_vma->head); | |
34297 | allocated = NULL; | |
4dee9bd5 | 34298 | diff -urNp linux-2.6.25.4/mm/shmem.c linux-2.6.25.4/mm/shmem.c |
34299 | --- linux-2.6.25.4/mm/shmem.c 2008-05-15 11:00:12.000000000 -0400 | |
34300 | +++ linux-2.6.25.4/mm/shmem.c 2008-05-18 13:33:17.000000000 -0400 | |
34301 | @@ -2517,7 +2517,7 @@ static struct file_system_type tmpfs_fs_ | |
50425a20 | 34302 | .get_sb = shmem_get_sb, |
34303 | .kill_sb = kill_litter_super, | |
34304 | }; | |
34305 | -static struct vfsmount *shm_mnt; | |
34306 | +struct vfsmount *shm_mnt; | |
34307 | ||
34308 | static int __init init_tmpfs(void) | |
34309 | { | |
4dee9bd5 | 34310 | diff -urNp linux-2.6.25.4/mm/slab.c linux-2.6.25.4/mm/slab.c |
34311 | --- linux-2.6.25.4/mm/slab.c 2008-05-15 11:00:12.000000000 -0400 | |
34312 | +++ linux-2.6.25.4/mm/slab.c 2008-05-18 13:33:17.000000000 -0400 | |
da5b3fc8 | 34313 | @@ -305,7 +305,7 @@ struct kmem_list3 { |
50425a20 | 34314 | * Need this for bootstrapping a per node allocator. |
34315 | */ | |
da5b3fc8 | 34316 | #define NUM_INIT_LISTS (3 * MAX_NUMNODES) |
50425a20 | 34317 | -struct kmem_list3 __initdata initkmem_list3[NUM_INIT_LISTS]; |
34318 | +struct kmem_list3 initkmem_list3[NUM_INIT_LISTS]; | |
34319 | #define CACHE_CACHE 0 | |
da5b3fc8 | 34320 | #define SIZE_AC MAX_NUMNODES |
34321 | #define SIZE_L3 (2 * MAX_NUMNODES) | |
34322 | @@ -654,14 +654,14 @@ struct cache_names { | |
50425a20 | 34323 | static struct cache_names __initdata cache_names[] = { |
34324 | #define CACHE(x) { .name = "size-" #x, .name_dma = "size-" #x "(DMA)" }, | |
34325 | #include <linux/kmalloc_sizes.h> | |
34326 | - {NULL,} | |
34327 | + {NULL, NULL} | |
34328 | #undef CACHE | |
34329 | }; | |
34330 | ||
34331 | static struct arraycache_init initarray_cache __initdata = | |
34332 | - { {0, BOOT_CPUCACHE_ENTRIES, 1, 0} }; | |
34333 | + { {0, BOOT_CPUCACHE_ENTRIES, 1, 0}, {NULL} }; | |
34334 | static struct arraycache_init initarray_generic = | |
34335 | - { {0, BOOT_CPUCACHE_ENTRIES, 1, 0} }; | |
34336 | + { {0, BOOT_CPUCACHE_ENTRIES, 1, 0}, {NULL} }; | |
34337 | ||
34338 | /* internal cache of cache description objs */ | |
34339 | static struct kmem_cache cache_cache = { | |
4dee9bd5 | 34340 | @@ -3007,7 +3007,7 @@ retry: |
8a4b4a5e | 34341 | * there must be at least one object available for |
34342 | * allocation. | |
34343 | */ | |
34344 | - BUG_ON(slabp->inuse < 0 || slabp->inuse >= cachep->num); | |
34345 | + BUG_ON(slabp->inuse >= cachep->num); | |
34346 | ||
34347 | while (slabp->inuse < cachep->num && batchcount--) { | |
34348 | STATS_INC_ALLOCED(cachep); | |
4dee9bd5 | 34349 | diff -urNp linux-2.6.25.4/mm/swap.c linux-2.6.25.4/mm/swap.c |
34350 | --- linux-2.6.25.4/mm/swap.c 2008-05-15 11:00:12.000000000 -0400 | |
34351 | +++ linux-2.6.25.4/mm/swap.c 2008-05-18 13:33:17.000000000 -0400 | |
34352 | @@ -34,9 +34,9 @@ | |
da5b3fc8 | 34353 | /* How many pages do we try to swap or page in/out together? */ |
34354 | int page_cluster; | |
34355 | ||
50425a20 | 34356 | -static DEFINE_PER_CPU(struct pagevec, lru_add_pvecs) = { 0, }; |
34357 | -static DEFINE_PER_CPU(struct pagevec, lru_add_active_pvecs) = { 0, }; | |
da5b3fc8 | 34358 | -static DEFINE_PER_CPU(struct pagevec, lru_rotate_pvecs) = { 0, }; |
50425a20 | 34359 | +static DEFINE_PER_CPU(struct pagevec, lru_add_pvecs) = { 0, 0, {NULL} }; |
34360 | +static DEFINE_PER_CPU(struct pagevec, lru_add_active_pvecs) = { 0, 0, {NULL} }; | |
da5b3fc8 | 34361 | +static DEFINE_PER_CPU(struct pagevec, lru_rotate_pvecs) = { 0, 0, {NULL} }; |
50425a20 | 34362 | |
da5b3fc8 | 34363 | /* |
34364 | * This path almost never happens for VM activity - pages are normally | |
4dee9bd5 | 34365 | diff -urNp linux-2.6.25.4/mm/tiny-shmem.c linux-2.6.25.4/mm/tiny-shmem.c |
34366 | --- linux-2.6.25.4/mm/tiny-shmem.c 2008-05-15 11:00:12.000000000 -0400 | |
34367 | +++ linux-2.6.25.4/mm/tiny-shmem.c 2008-05-18 13:33:17.000000000 -0400 | |
50425a20 | 34368 | @@ -26,7 +26,7 @@ static struct file_system_type tmpfs_fs_ |
34369 | .kill_sb = kill_litter_super, | |
34370 | }; | |
34371 | ||
34372 | -static struct vfsmount *shm_mnt; | |
34373 | +struct vfsmount *shm_mnt; | |
34374 | ||
34375 | static int __init init_tmpfs(void) | |
34376 | { | |
4dee9bd5 | 34377 | diff -urNp linux-2.6.25.4/mm/vmalloc.c linux-2.6.25.4/mm/vmalloc.c |
34378 | --- linux-2.6.25.4/mm/vmalloc.c 2008-05-15 11:00:12.000000000 -0400 | |
34379 | +++ linux-2.6.25.4/mm/vmalloc.c 2008-05-18 13:33:17.000000000 -0400 | |
34380 | @@ -246,20 +246,15 @@ static struct vm_struct *__get_vm_area_n | |
34381 | (unsigned long)tmp->addr, align); | |
34382 | continue; | |
34383 | } | |
34384 | - if ((size + addr) < addr) | |
34385 | - goto out; | |
50425a20 | 34386 | if (size + addr <= (unsigned long)tmp->addr) |
4dee9bd5 | 34387 | - goto found; |
34388 | + break; | |
50425a20 | 34389 | addr = ALIGN(tmp->size + (unsigned long)tmp->addr, align); |
34390 | - if (addr > end - size) | |
34391 | - goto out; | |
34392 | } | |
4dee9bd5 | 34393 | if ((size + addr) < addr) |
34394 | goto out; | |
34395 | if (addr > end - size) | |
34396 | goto out; | |
50425a20 | 34397 | |
4dee9bd5 | 34398 | -found: |
34399 | area->next = *p; | |
34400 | *p = area; | |
34401 | ||
34402 | diff -urNp linux-2.6.25.4/net/bridge/br_stp_if.c linux-2.6.25.4/net/bridge/br_stp_if.c | |
34403 | --- linux-2.6.25.4/net/bridge/br_stp_if.c 2008-05-15 11:00:12.000000000 -0400 | |
34404 | +++ linux-2.6.25.4/net/bridge/br_stp_if.c 2008-05-18 13:33:17.000000000 -0400 | |
da5b3fc8 | 34405 | @@ -148,7 +148,7 @@ static void br_stp_stop(struct net_bridg |
34406 | char *envp[] = { NULL }; | |
34407 | ||
34408 | if (br->stp_enabled == BR_USER_STP) { | |
34409 | - r = call_usermodehelper(BR_STP_PROG, argv, envp, 1); | |
34410 | + r = call_usermodehelper(BR_STP_PROG, argv, envp, UMH_WAIT_PROC); | |
34411 | printk(KERN_INFO "%s: userspace STP stopped, return code %d\n", | |
34412 | br->dev->name, r); | |
34413 | ||
4dee9bd5 | 34414 | diff -urNp linux-2.6.25.4/net/core/flow.c linux-2.6.25.4/net/core/flow.c |
34415 | --- linux-2.6.25.4/net/core/flow.c 2008-05-15 11:00:12.000000000 -0400 | |
34416 | +++ linux-2.6.25.4/net/core/flow.c 2008-05-18 13:33:17.000000000 -0400 | |
50425a20 | 34417 | @@ -40,7 +40,7 @@ atomic_t flow_cache_genid = ATOMIC_INIT( |
34418 | ||
34419 | static u32 flow_hash_shift; | |
34420 | #define flow_hash_size (1 << flow_hash_shift) | |
34421 | -static DEFINE_PER_CPU(struct flow_cache_entry **, flow_tables) = { NULL }; | |
34422 | +static DEFINE_PER_CPU(struct flow_cache_entry **, flow_tables); | |
34423 | ||
34424 | #define flow_table(cpu) (per_cpu(flow_tables, cpu)) | |
34425 | ||
34426 | @@ -53,7 +53,7 @@ struct flow_percpu_info { | |
34427 | u32 hash_rnd; | |
34428 | int count; | |
4dee9bd5 | 34429 | }; |
50425a20 | 34430 | -static DEFINE_PER_CPU(struct flow_percpu_info, flow_hash_info) = { 0 }; |
34431 | +static DEFINE_PER_CPU(struct flow_percpu_info, flow_hash_info); | |
34432 | ||
34433 | #define flow_hash_rnd_recalc(cpu) \ | |
34434 | (per_cpu(flow_hash_info, cpu).hash_rnd_recalc) | |
34435 | @@ -70,7 +70,7 @@ struct flow_flush_info { | |
34436 | atomic_t cpuleft; | |
34437 | struct completion completion; | |
34438 | }; | |
34439 | -static DEFINE_PER_CPU(struct tasklet_struct, flow_flush_tasklets) = { NULL }; | |
34440 | +static DEFINE_PER_CPU(struct tasklet_struct, flow_flush_tasklets); | |
34441 | ||
34442 | #define flow_flush_tasklet(cpu) (&per_cpu(flow_flush_tasklets, cpu)) | |
34443 | ||
4dee9bd5 | 34444 | diff -urNp linux-2.6.25.4/net/dccp/ccids/ccid3.c linux-2.6.25.4/net/dccp/ccids/ccid3.c |
34445 | --- linux-2.6.25.4/net/dccp/ccids/ccid3.c 2008-05-15 11:00:12.000000000 -0400 | |
34446 | +++ linux-2.6.25.4/net/dccp/ccids/ccid3.c 2008-05-18 13:33:17.000000000 -0400 | |
34447 | @@ -43,7 +43,7 @@ | |
50425a20 | 34448 | static int ccid3_debug; |
34449 | #define ccid3_pr_debug(format, a...) DCCP_PR_DEBUG(ccid3_debug, format, ##a) | |
34450 | #else | |
34451 | -#define ccid3_pr_debug(format, a...) | |
34452 | +#define ccid3_pr_debug(format, a...) do {} while (0) | |
34453 | #endif | |
34454 | ||
4dee9bd5 | 34455 | /* |
34456 | diff -urNp linux-2.6.25.4/net/dccp/dccp.h linux-2.6.25.4/net/dccp/dccp.h | |
34457 | --- linux-2.6.25.4/net/dccp/dccp.h 2008-05-15 11:00:12.000000000 -0400 | |
34458 | +++ linux-2.6.25.4/net/dccp/dccp.h 2008-05-18 13:33:17.000000000 -0400 | |
da5b3fc8 | 34459 | @@ -43,8 +43,8 @@ extern int dccp_debug; |
50425a20 | 34460 | #define dccp_pr_debug(format, a...) DCCP_PR_DEBUG(dccp_debug, format, ##a) |
34461 | #define dccp_pr_debug_cat(format, a...) DCCP_PRINTK(dccp_debug, format, ##a) | |
34462 | #else | |
34463 | -#define dccp_pr_debug(format, a...) | |
34464 | -#define dccp_pr_debug_cat(format, a...) | |
34465 | +#define dccp_pr_debug(format, a...) do {} while (0) | |
34466 | +#define dccp_pr_debug_cat(format, a...) do {} while (0) | |
34467 | #endif | |
34468 | ||
34469 | extern struct inet_hashinfo dccp_hashinfo; | |
4dee9bd5 | 34470 | diff -urNp linux-2.6.25.4/net/ipv4/inet_connection_sock.c linux-2.6.25.4/net/ipv4/inet_connection_sock.c |
34471 | --- linux-2.6.25.4/net/ipv4/inet_connection_sock.c 2008-05-15 11:00:12.000000000 -0400 | |
34472 | +++ linux-2.6.25.4/net/ipv4/inet_connection_sock.c 2008-05-18 13:33:17.000000000 -0400 | |
50425a20 | 34473 | @@ -15,6 +15,7 @@ |
34474 | ||
34475 | #include <linux/module.h> | |
34476 | #include <linux/jhash.h> | |
34477 | +#include <linux/grsecurity.h> | |
34478 | ||
34479 | #include <net/inet_connection_sock.h> | |
34480 | #include <net/inet_hashtables.h> | |
4dee9bd5 | 34481 | diff -urNp linux-2.6.25.4/net/ipv4/inet_hashtables.c linux-2.6.25.4/net/ipv4/inet_hashtables.c |
34482 | --- linux-2.6.25.4/net/ipv4/inet_hashtables.c 2008-05-15 11:00:12.000000000 -0400 | |
34483 | +++ linux-2.6.25.4/net/ipv4/inet_hashtables.c 2008-05-18 13:33:17.000000000 -0400 | |
b79bc584 | 34484 | @@ -18,12 +18,15 @@ |
50425a20 | 34485 | #include <linux/sched.h> |
34486 | #include <linux/slab.h> | |
34487 | #include <linux/wait.h> | |
34488 | +#include <linux/grsecurity.h> | |
34489 | ||
34490 | #include <net/inet_connection_sock.h> | |
34491 | #include <net/inet_hashtables.h> | |
b79bc584 | 34492 | #include <net/route.h> |
50425a20 | 34493 | #include <net/ip.h> |
34494 | ||
34495 | +extern void gr_update_task_in_ip_table(struct task_struct *task, const struct inet_sock *inet); | |
34496 | + | |
34497 | /* | |
34498 | * Allocate and initialize a new local port bind bucket. | |
34499 | * The bindhash mutex for snum's hash chain must be held here. | |
4dee9bd5 | 34500 | @@ -467,6 +470,8 @@ ok: |
50425a20 | 34501 | } |
34502 | spin_unlock(&head->lock); | |
34503 | ||
34504 | + gr_update_task_in_ip_table(current, inet_sk(sk)); | |
34505 | + | |
34506 | if (tw) { | |
34507 | inet_twsk_deschedule(tw, death_row); | |
34508 | inet_twsk_put(tw); | |
4dee9bd5 | 34509 | diff -urNp linux-2.6.25.4/net/ipv4/netfilter/ipt_stealth.c linux-2.6.25.4/net/ipv4/netfilter/ipt_stealth.c |
34510 | --- linux-2.6.25.4/net/ipv4/netfilter/ipt_stealth.c 1969-12-31 19:00:00.000000000 -0500 | |
34511 | +++ linux-2.6.25.4/net/ipv4/netfilter/ipt_stealth.c 2008-05-18 13:33:17.000000000 -0400 | |
0c54d671 | 34512 | @@ -0,0 +1,114 @@ |
50425a20 | 34513 | +/* Kernel module to add stealth support. |
34514 | + * | |
34515 | + * Copyright (C) 2002-2006 Brad Spengler <spender@grsecurity.net> | |
34516 | + * | |
34517 | + */ | |
34518 | + | |
34519 | +#include <linux/kernel.h> | |
34520 | +#include <linux/module.h> | |
34521 | +#include <linux/skbuff.h> | |
34522 | +#include <linux/net.h> | |
34523 | +#include <linux/sched.h> | |
34524 | +#include <linux/inet.h> | |
34525 | +#include <linux/stddef.h> | |
34526 | + | |
34527 | +#include <net/ip.h> | |
34528 | +#include <net/sock.h> | |
34529 | +#include <net/tcp.h> | |
34530 | +#include <net/udp.h> | |
34531 | +#include <net/route.h> | |
34532 | +#include <net/inet_common.h> | |
34533 | + | |
34534 | +#include <linux/netfilter_ipv4/ip_tables.h> | |
34535 | + | |
34536 | +MODULE_LICENSE("GPL"); | |
34537 | + | |
4dee9bd5 | 34538 | +extern struct sock *udp_v4_lookup(struct net *net, u32 saddr, u16 sport, u32 daddr, u16 dport, int dif); |
50425a20 | 34539 | + |
4dee9bd5 | 34540 | +static bool |
50425a20 | 34541 | +match(const struct sk_buff *skb, |
34542 | + const struct net_device *in, | |
34543 | + const struct net_device *out, | |
34544 | + const struct xt_match *match, | |
34545 | + const void *matchinfo, | |
34546 | + int offset, | |
34547 | + unsigned int protoff, | |
4dee9bd5 | 34548 | + bool *hotdrop) |
50425a20 | 34549 | +{ |
8a4b4a5e | 34550 | + struct iphdr *ip = ip_hdr(skb); |
50425a20 | 34551 | + struct tcphdr th; |
34552 | + struct udphdr uh; | |
34553 | + struct sock *sk = NULL; | |
34554 | + | |
4dee9bd5 | 34555 | + if (!ip || offset) return false; |
50425a20 | 34556 | + |
34557 | + switch(ip->protocol) { | |
34558 | + case IPPROTO_TCP: | |
8a4b4a5e | 34559 | + if (skb_copy_bits(skb, (ip_hdr(skb))->ihl*4, &th, sizeof(th)) < 0) { |
4dee9bd5 | 34560 | + *hotdrop = true; |
34561 | + return false; | |
50425a20 | 34562 | + } |
4dee9bd5 | 34563 | + if (!(th.syn && !th.ack)) return false; |
34564 | + sk = inet_lookup_listener(skb->dev->nd_net, &tcp_hashinfo, ip->daddr, th.dest, inet_iif(skb)); | |
50425a20 | 34565 | + break; |
34566 | + case IPPROTO_UDP: | |
8a4b4a5e | 34567 | + if (skb_copy_bits(skb, (ip_hdr(skb))->ihl*4, &uh, sizeof(uh)) < 0) { |
4dee9bd5 | 34568 | + *hotdrop = true; |
34569 | + return false; | |
50425a20 | 34570 | + } |
4dee9bd5 | 34571 | + sk = udp_v4_lookup(skb->dev->nd_net, ip->saddr, uh.source, ip->daddr, uh.dest, skb->dev->ifindex); |
50425a20 | 34572 | + break; |
34573 | + default: | |
4dee9bd5 | 34574 | + return false; |
50425a20 | 34575 | + } |
34576 | + | |
34577 | + if(!sk) // port is being listened on, match this | |
4dee9bd5 | 34578 | + return true; |
50425a20 | 34579 | + else { |
34580 | + sock_put(sk); | |
4dee9bd5 | 34581 | + return false; |
50425a20 | 34582 | + } |
34583 | +} | |
34584 | + | |
34585 | +/* Called when user tries to insert an entry of this type. */ | |
4dee9bd5 | 34586 | +static bool |
50425a20 | 34587 | +checkentry(const char *tablename, |
34588 | + const void *nip, | |
34589 | + const struct xt_match *match, | |
34590 | + void *matchinfo, | |
34591 | + unsigned int hook_mask) | |
34592 | +{ | |
34593 | + const struct ipt_ip *ip = (const struct ipt_ip *)nip; | |
34594 | + | |
34595 | + if(((ip->proto == IPPROTO_TCP && !(ip->invflags & IPT_INV_PROTO)) || | |
34596 | + ((ip->proto == IPPROTO_UDP) && !(ip->invflags & IPT_INV_PROTO))) | |
4dee9bd5 | 34597 | + && (hook_mask & (1 << NF_INET_LOCAL_IN))) |
34598 | + return true; | |
50425a20 | 34599 | + |
34600 | + printk("stealth: Only works on TCP and UDP for the INPUT chain.\n"); | |
34601 | + | |
4dee9bd5 | 34602 | + return false; |
50425a20 | 34603 | +} |
34604 | + | |
34605 | + | |
4dee9bd5 | 34606 | +static struct xt_match stealth_match __read_mostly = { |
50425a20 | 34607 | + .name = "stealth", |
0c54d671 | 34608 | + .family = AF_INET, |
50425a20 | 34609 | + .match = match, |
34610 | + .checkentry = checkentry, | |
34611 | + .destroy = NULL, | |
34612 | + .me = THIS_MODULE | |
34613 | +}; | |
34614 | + | |
34615 | +static int __init init(void) | |
34616 | +{ | |
0c54d671 | 34617 | + return xt_register_match(&stealth_match); |
50425a20 | 34618 | +} |
34619 | + | |
34620 | +static void __exit fini(void) | |
34621 | +{ | |
0c54d671 | 34622 | + xt_unregister_match(&stealth_match); |
50425a20 | 34623 | +} |
34624 | + | |
34625 | +module_init(init); | |
34626 | +module_exit(fini); | |
4dee9bd5 | 34627 | diff -urNp linux-2.6.25.4/net/ipv4/netfilter/Kconfig linux-2.6.25.4/net/ipv4/netfilter/Kconfig |
34628 | --- linux-2.6.25.4/net/ipv4/netfilter/Kconfig 2008-05-15 11:00:12.000000000 -0400 | |
34629 | +++ linux-2.6.25.4/net/ipv4/netfilter/Kconfig 2008-05-18 13:33:17.000000000 -0400 | |
34630 | @@ -111,6 +111,21 @@ config IP_NF_MATCH_ADDRTYPE | |
50425a20 | 34631 | If you want to compile it as a module, say M here and read |
da5b3fc8 | 34632 | <file:Documentation/kbuild/modules.txt>. If unsure, say `N'. |
50425a20 | 34633 | |
34634 | +config IP_NF_MATCH_STEALTH | |
34635 | + tristate "stealth match support" | |
34636 | + depends on IP_NF_IPTABLES | |
34637 | + help | |
34638 | + Enabling this option will drop all syn packets coming to unserved tcp | |
34639 | + ports as well as all packets coming to unserved udp ports. If you | |
34640 | + are using your system to route any type of packets (ie. via NAT) | |
34641 | + you should put this module at the end of your ruleset, since it will | |
34642 | + drop packets that aren't going to ports that are listening on your | |
34643 | + machine itself, it doesn't take into account that the packet might be | |
34644 | + destined for someone on your internal network if you're using NAT for | |
34645 | + instance. | |
34646 | + | |
34647 | + To compile it as a module, choose M here. If unsure, say N. | |
34648 | + | |
34649 | # `filter', generic and specific targets | |
34650 | config IP_NF_FILTER | |
34651 | tristate "Packet filtering" | |
4dee9bd5 | 34652 | @@ -380,4 +395,3 @@ config IP_NF_ARP_MANGLE |
50425a20 | 34653 | hardware and network addresses. |
34654 | ||
34655 | endmenu | |
34656 | - | |
4dee9bd5 | 34657 | diff -urNp linux-2.6.25.4/net/ipv4/netfilter/Makefile linux-2.6.25.4/net/ipv4/netfilter/Makefile |
34658 | --- linux-2.6.25.4/net/ipv4/netfilter/Makefile 2008-05-15 11:00:12.000000000 -0400 | |
34659 | +++ linux-2.6.25.4/net/ipv4/netfilter/Makefile 2008-05-18 13:33:17.000000000 -0400 | |
34660 | @@ -55,6 +55,7 @@ obj-$(CONFIG_IP_NF_TARGET_MASQUERADE) += | |
34661 | obj-$(CONFIG_IP_NF_TARGET_NETMAP) += ipt_NETMAP.o | |
34662 | obj-$(CONFIG_IP_NF_TARGET_REDIRECT) += ipt_REDIRECT.o | |
34663 | obj-$(CONFIG_IP_NF_TARGET_REJECT) += ipt_REJECT.o | |
50425a20 | 34664 | +obj-$(CONFIG_IP_NF_MATCH_STEALTH) += ipt_stealth.o |
4dee9bd5 | 34665 | obj-$(CONFIG_IP_NF_TARGET_TTL) += ipt_TTL.o |
34666 | obj-$(CONFIG_IP_NF_TARGET_ULOG) += ipt_ULOG.o | |
34667 | ||
34668 | diff -urNp linux-2.6.25.4/net/ipv4/tcp.c linux-2.6.25.4/net/ipv4/tcp.c | |
34669 | --- linux-2.6.25.4/net/ipv4/tcp.c 2008-05-15 11:00:12.000000000 -0400 | |
34670 | +++ linux-2.6.25.4/net/ipv4/tcp.c 2008-05-18 13:33:17.000000000 -0400 | |
34671 | @@ -1206,7 +1206,8 @@ int tcp_read_sock(struct sock *sk, read_ | |
da5b3fc8 | 34672 | return -ENOTCONN; |
34673 | while ((skb = tcp_recv_skb(sk, seq, &offset)) != NULL) { | |
34674 | if (offset < skb->len) { | |
34675 | - size_t used, len; | |
34676 | + int used; | |
34677 | + size_t len; | |
34678 | ||
34679 | len = skb->len - offset; | |
34680 | /* Stop reading if we hit a patch of urgent data */ | |
4dee9bd5 | 34681 | diff -urNp linux-2.6.25.4/net/ipv4/tcp_ipv4.c linux-2.6.25.4/net/ipv4/tcp_ipv4.c |
34682 | --- linux-2.6.25.4/net/ipv4/tcp_ipv4.c 2008-05-15 11:00:12.000000000 -0400 | |
34683 | +++ linux-2.6.25.4/net/ipv4/tcp_ipv4.c 2008-05-18 13:33:17.000000000 -0400 | |
50425a20 | 34684 | @@ -61,6 +61,7 @@ |
34685 | #include <linux/jhash.h> | |
34686 | #include <linux/init.h> | |
34687 | #include <linux/times.h> | |
34688 | +#include <linux/grsecurity.h> | |
34689 | ||
da5b3fc8 | 34690 | #include <net/net_namespace.h> |
50425a20 | 34691 | #include <net/icmp.h> |
4dee9bd5 | 34692 | diff -urNp linux-2.6.25.4/net/ipv4/udp.c linux-2.6.25.4/net/ipv4/udp.c |
34693 | --- linux-2.6.25.4/net/ipv4/udp.c 2008-05-15 11:00:12.000000000 -0400 | |
34694 | +++ linux-2.6.25.4/net/ipv4/udp.c 2008-05-18 13:33:17.000000000 -0400 | |
34695 | @@ -99,6 +99,7 @@ | |
1f8eda86 | 34696 | #include <linux/skbuff.h> |
50425a20 | 34697 | #include <linux/proc_fs.h> |
34698 | #include <linux/seq_file.h> | |
34699 | +#include <linux/grsecurity.h> | |
da5b3fc8 | 34700 | #include <net/net_namespace.h> |
50425a20 | 34701 | #include <net/icmp.h> |
34702 | #include <net/route.h> | |
4dee9bd5 | 34703 | @@ -106,6 +107,11 @@ |
50425a20 | 34704 | #include <net/xfrm.h> |
34705 | #include "udp_impl.h" | |
34706 | ||
34707 | +extern int gr_search_udp_recvmsg(const struct sock *sk, | |
34708 | + const struct sk_buff *skb); | |
34709 | +extern int gr_search_udp_sendmsg(const struct sock *sk, | |
34710 | + const struct sockaddr_in *addr); | |
50425a20 | 34711 | + |
34712 | /* | |
34713 | * Snmp MIB for the UDP layer | |
34714 | */ | |
4dee9bd5 | 34715 | @@ -314,6 +320,13 @@ static struct sock *__udp4_lib_lookup(st |
50425a20 | 34716 | return result; |
34717 | } | |
34718 | ||
4dee9bd5 | 34719 | +struct sock *udp_v4_lookup(struct net *net, __be32 saddr, __be16 sport, |
50425a20 | 34720 | + __be32 daddr, __be16 dport, int dif) |
34721 | +{ | |
4dee9bd5 | 34722 | + return __udp4_lib_lookup(net, saddr, sport, daddr, dport, dif, udp_hash); |
50425a20 | 34723 | +} |
34724 | + | |
34725 | + | |
34726 | static inline struct sock *udp_v4_mcast_next(struct sock *sk, | |
34727 | __be16 loc_port, __be32 loc_addr, | |
34728 | __be16 rmt_port, __be32 rmt_addr, | |
4dee9bd5 | 34729 | @@ -600,9 +613,16 @@ int udp_sendmsg(struct kiocb *iocb, stru |
50425a20 | 34730 | dport = usin->sin_port; |
34731 | if (dport == 0) | |
34732 | return -EINVAL; | |
34733 | + | |
34734 | + if (!gr_search_udp_sendmsg(sk, usin)) | |
34735 | + return -EPERM; | |
34736 | } else { | |
34737 | if (sk->sk_state != TCP_ESTABLISHED) | |
34738 | return -EDESTADDRREQ; | |
34739 | + | |
34740 | + if (!gr_search_udp_sendmsg(sk, NULL)) | |
34741 | + return -EPERM; | |
34742 | + | |
34743 | daddr = inet->daddr; | |
34744 | dport = inet->dport; | |
34745 | /* Open fast path for connected socket. | |
4dee9bd5 | 34746 | @@ -864,6 +884,11 @@ try_again: |
50425a20 | 34747 | if (!skb) |
34748 | goto out; | |
34749 | ||
34750 | + if (!gr_search_udp_recvmsg(sk, skb)) { | |
34751 | + err = -EPERM; | |
34752 | + goto out_free; | |
34753 | + } | |
34754 | + | |
8a4b4a5e | 34755 | ulen = skb->len - sizeof(struct udphdr); |
34756 | copied = len; | |
34757 | if (copied > ulen) | |
4dee9bd5 | 34758 | diff -urNp linux-2.6.25.4/net/ipv6/exthdrs.c linux-2.6.25.4/net/ipv6/exthdrs.c |
34759 | --- linux-2.6.25.4/net/ipv6/exthdrs.c 2008-05-15 11:00:12.000000000 -0400 | |
34760 | +++ linux-2.6.25.4/net/ipv6/exthdrs.c 2008-05-18 13:33:17.000000000 -0400 | |
34761 | @@ -626,7 +626,7 @@ static struct tlvtype_proc tlvprochopopt | |
50425a20 | 34762 | .type = IPV6_TLV_JUMBO, |
34763 | .func = ipv6_hop_jumbo, | |
34764 | }, | |
34765 | - { -1, } | |
34766 | + { -1, NULL } | |
34767 | }; | |
34768 | ||
da5b3fc8 | 34769 | int ipv6_parse_hopopts(struct sk_buff *skb) |
4dee9bd5 | 34770 | diff -urNp linux-2.6.25.4/net/ipv6/raw.c linux-2.6.25.4/net/ipv6/raw.c |
34771 | --- linux-2.6.25.4/net/ipv6/raw.c 2008-05-15 11:00:12.000000000 -0400 | |
34772 | +++ linux-2.6.25.4/net/ipv6/raw.c 2008-05-18 13:33:17.000000000 -0400 | |
34773 | @@ -617,7 +617,7 @@ out: | |
50425a20 | 34774 | return err; |
34775 | } | |
34776 | ||
34777 | -static int rawv6_send_hdrinc(struct sock *sk, void *from, int length, | |
34778 | +static int rawv6_send_hdrinc(struct sock *sk, void *from, unsigned int length, | |
34779 | struct flowi *fl, struct rt6_info *rt, | |
34780 | unsigned int flags) | |
34781 | { | |
4dee9bd5 | 34782 | diff -urNp linux-2.6.25.4/net/irda/ircomm/ircomm_tty.c linux-2.6.25.4/net/irda/ircomm/ircomm_tty.c |
34783 | --- linux-2.6.25.4/net/irda/ircomm/ircomm_tty.c 2008-05-15 11:00:12.000000000 -0400 | |
34784 | +++ linux-2.6.25.4/net/irda/ircomm/ircomm_tty.c 2008-05-18 13:33:17.000000000 -0400 | |
8a4b4a5e | 34785 | @@ -371,7 +371,7 @@ static int ircomm_tty_open(struct tty_st |
34786 | IRDA_DEBUG(2, "%s()\n", __FUNCTION__ ); | |
34787 | ||
34788 | line = tty->index; | |
34789 | - if ((line < 0) || (line >= IRCOMM_TTY_PORTS)) { | |
34790 | + if (line >= IRCOMM_TTY_PORTS) { | |
34791 | return -ENODEV; | |
34792 | } | |
34793 | ||
4dee9bd5 | 34794 | diff -urNp linux-2.6.25.4/net/mac80211/regdomain.c linux-2.6.25.4/net/mac80211/regdomain.c |
34795 | --- linux-2.6.25.4/net/mac80211/regdomain.c 2008-05-15 11:00:12.000000000 -0400 | |
34796 | +++ linux-2.6.25.4/net/mac80211/regdomain.c 2008-05-18 13:33:17.000000000 -0400 | |
da5b3fc8 | 34797 | @@ -61,14 +61,14 @@ static const struct ieee80211_channel_ra |
8a4b4a5e | 34798 | { 5180, 5240, 17, 6 } /* IEEE 802.11a, channels 36..48 */, |
34799 | { 5260, 5320, 23, 6 } /* IEEE 802.11a, channels 52..64 */, | |
34800 | { 5745, 5825, 30, 6 } /* IEEE 802.11a, channels 149..165, outdoor */, | |
34801 | - { 0 } | |
34802 | + { 0, 0, 0, 0 } | |
34803 | }; | |
34804 | ||
34805 | static const struct ieee80211_channel_range ieee80211_mkk_channels[] = { | |
34806 | { 2412, 2472, 20, 6 } /* IEEE 802.11b/g, channels 1..13 */, | |
34807 | { 5170, 5240, 20, 6 } /* IEEE 802.11a, channels 34..48 */, | |
34808 | { 5260, 5320, 20, 6 } /* IEEE 802.11a, channels 52..64 */, | |
34809 | - { 0 } | |
34810 | + { 0, 0, 0, 0 } | |
34811 | }; | |
34812 | ||
34813 | ||
4dee9bd5 | 34814 | diff -urNp linux-2.6.25.4/net/sctp/socket.c linux-2.6.25.4/net/sctp/socket.c |
34815 | --- linux-2.6.25.4/net/sctp/socket.c 2008-05-15 11:00:12.000000000 -0400 | |
34816 | +++ linux-2.6.25.4/net/sctp/socket.c 2008-05-18 13:33:17.000000000 -0400 | |
34817 | @@ -1391,7 +1391,7 @@ SCTP_STATIC int sctp_sendmsg(struct kioc | |
50425a20 | 34818 | struct sctp_sndrcvinfo *sinfo; |
34819 | struct sctp_initmsg *sinit; | |
34820 | sctp_assoc_t associd = 0; | |
34821 | - sctp_cmsgs_t cmsgs = { NULL }; | |
34822 | + sctp_cmsgs_t cmsgs = { NULL, NULL }; | |
34823 | int err; | |
34824 | sctp_scope_t scope; | |
34825 | long timeo; | |
4dee9bd5 | 34826 | diff -urNp linux-2.6.25.4/net/socket.c linux-2.6.25.4/net/socket.c |
34827 | --- linux-2.6.25.4/net/socket.c 2008-05-15 11:00:12.000000000 -0400 | |
34828 | +++ linux-2.6.25.4/net/socket.c 2008-05-18 13:33:17.000000000 -0400 | |
da5b3fc8 | 34829 | @@ -85,6 +85,7 @@ |
50425a20 | 34830 | #include <linux/audit.h> |
34831 | #include <linux/wireless.h> | |
da5b3fc8 | 34832 | #include <linux/nsproxy.h> |
50425a20 | 34833 | +#include <linux/in.h> |
34834 | ||
34835 | #include <asm/uaccess.h> | |
34836 | #include <asm/unistd.h> | |
da5b3fc8 | 34837 | @@ -94,6 +95,21 @@ |
34838 | #include <net/sock.h> | |
34839 | #include <linux/netfilter.h> | |
50425a20 | 34840 | |
34841 | +extern void gr_attach_curr_ip(const struct sock *sk); | |
34842 | +extern int gr_handle_sock_all(const int family, const int type, | |
34843 | + const int protocol); | |
34844 | +extern int gr_handle_sock_server(const struct sockaddr *sck); | |
34845 | +extern int gr_handle_sock_server_other(const struct socket *sck); | |
34846 | +extern int gr_handle_sock_client(const struct sockaddr *sck); | |
34847 | +extern int gr_search_connect(const struct socket * sock, | |
34848 | + const struct sockaddr_in * addr); | |
34849 | +extern int gr_search_bind(const struct socket * sock, | |
34850 | + const struct sockaddr_in * addr); | |
34851 | +extern int gr_search_listen(const struct socket * sock); | |
34852 | +extern int gr_search_accept(const struct socket * sock); | |
34853 | +extern int gr_search_socket(const int domain, const int type, | |
34854 | + const int protocol); | |
34855 | + | |
34856 | static int sock_no_open(struct inode *irrelevant, struct file *dontcare); | |
34857 | static ssize_t sock_aio_read(struct kiocb *iocb, const struct iovec *iov, | |
34858 | unsigned long nr_segs, loff_t pos); | |
4dee9bd5 | 34859 | @@ -297,7 +313,7 @@ static int sockfs_get_sb(struct file_sys |
50425a20 | 34860 | mnt); |
34861 | } | |
34862 | ||
34863 | -static struct vfsmount *sock_mnt __read_mostly; | |
34864 | +struct vfsmount *sock_mnt __read_mostly; | |
34865 | ||
34866 | static struct file_system_type sock_fs_type = { | |
34867 | .name = "sockfs", | |
4dee9bd5 | 34868 | @@ -1218,6 +1234,16 @@ asmlinkage long sys_socket(int family, i |
50425a20 | 34869 | int retval; |
34870 | struct socket *sock; | |
34871 | ||
34872 | + if(!gr_search_socket(family, type, protocol)) { | |
34873 | + retval = -EACCES; | |
34874 | + goto out; | |
34875 | + } | |
34876 | + | |
34877 | + if (gr_handle_sock_all(family, type, protocol)) { | |
34878 | + retval = -EACCES; | |
34879 | + goto out; | |
34880 | + } | |
34881 | + | |
34882 | retval = sock_create(family, type, protocol, &sock); | |
34883 | if (retval < 0) | |
34884 | goto out; | |
4dee9bd5 | 34885 | @@ -1348,6 +1374,12 @@ asmlinkage long sys_bind(int fd, struct |
8a4b4a5e | 34886 | if (sock) { |
50425a20 | 34887 | err = move_addr_to_kernel(umyaddr, addrlen, address); |
34888 | if (err >= 0) { | |
8a4b4a5e | 34889 | + if (!gr_search_bind(sock, (struct sockaddr_in *)address) || |
34890 | + gr_handle_sock_server((struct sockaddr *)address)) { | |
50425a20 | 34891 | + err = -EACCES; |
34892 | + goto error; | |
34893 | + } | |
34894 | + | |
34895 | err = security_socket_bind(sock, | |
34896 | (struct sockaddr *)address, | |
34897 | addrlen); | |
4dee9bd5 | 34898 | @@ -1356,6 +1388,7 @@ asmlinkage long sys_bind(int fd, struct |
50425a20 | 34899 | (struct sockaddr *) |
34900 | address, addrlen); | |
34901 | } | |
34902 | +error: | |
34903 | fput_light(sock->file, fput_needed); | |
34904 | } | |
34905 | return err; | |
4dee9bd5 | 34906 | @@ -1379,10 +1412,17 @@ asmlinkage long sys_listen(int fd, int b |
34907 | if ((unsigned)backlog > somaxconn) | |
34908 | backlog = somaxconn; | |
50425a20 | 34909 | |
34910 | + if (gr_handle_sock_server_other(sock) || | |
34911 | + !gr_search_listen(sock)) { | |
34912 | + err = -EPERM; | |
34913 | + goto error; | |
34914 | + } | |
34915 | + | |
34916 | err = security_socket_listen(sock, backlog); | |
34917 | if (!err) | |
34918 | err = sock->ops->listen(sock, backlog); | |
34919 | ||
34920 | +error: | |
34921 | fput_light(sock->file, fput_needed); | |
34922 | } | |
34923 | return err; | |
4dee9bd5 | 34924 | @@ -1419,6 +1459,13 @@ asmlinkage long sys_accept(int fd, struc |
50425a20 | 34925 | newsock->type = sock->type; |
34926 | newsock->ops = sock->ops; | |
34927 | ||
34928 | + if (gr_handle_sock_server_other(sock) || | |
34929 | + !gr_search_accept(sock)) { | |
34930 | + err = -EPERM; | |
34931 | + sock_release(newsock); | |
34932 | + goto out_put; | |
34933 | + } | |
34934 | + | |
34935 | /* | |
34936 | * We don't need try_module_get here, as the listening socket (sock) | |
34937 | * has the protocol module (sock->ops->owner) held. | |
4dee9bd5 | 34938 | @@ -1462,6 +1509,7 @@ asmlinkage long sys_accept(int fd, struc |
50425a20 | 34939 | err = newfd; |
34940 | ||
34941 | security_socket_post_accept(sock, newsock); | |
34942 | + gr_attach_curr_ip(newsock->sk); | |
34943 | ||
34944 | out_put: | |
34945 | fput_light(sock->file, fput_needed); | |
4dee9bd5 | 34946 | @@ -1495,6 +1543,7 @@ asmlinkage long sys_connect(int fd, stru |
50425a20 | 34947 | { |
34948 | struct socket *sock; | |
34949 | char address[MAX_SOCK_ADDR]; | |
34950 | + struct sockaddr *sck; | |
34951 | int err, fput_needed; | |
34952 | ||
34953 | sock = sockfd_lookup_light(fd, &err, &fput_needed); | |
4dee9bd5 | 34954 | @@ -1504,6 +1553,13 @@ asmlinkage long sys_connect(int fd, stru |
50425a20 | 34955 | if (err < 0) |
34956 | goto out_put; | |
34957 | ||
34958 | + sck = (struct sockaddr *)address; | |
34959 | + if (!gr_search_connect(sock, (struct sockaddr_in *)sck) || | |
34960 | + gr_handle_sock_client(sck)) { | |
34961 | + err = -EACCES; | |
34962 | + goto out_put; | |
34963 | + } | |
34964 | + | |
34965 | err = | |
34966 | security_socket_connect(sock, (struct sockaddr *)address, addrlen); | |
34967 | if (err) | |
4dee9bd5 | 34968 | @@ -1770,6 +1826,7 @@ asmlinkage long sys_shutdown(int fd, int |
50425a20 | 34969 | err = sock->ops->shutdown(sock, how); |
34970 | fput_light(sock->file, fput_needed); | |
34971 | } | |
34972 | + | |
34973 | return err; | |
34974 | } | |
34975 | ||
4dee9bd5 | 34976 | diff -urNp linux-2.6.25.4/net/unix/af_unix.c linux-2.6.25.4/net/unix/af_unix.c |
34977 | --- linux-2.6.25.4/net/unix/af_unix.c 2008-05-15 11:00:12.000000000 -0400 | |
34978 | +++ linux-2.6.25.4/net/unix/af_unix.c 2008-05-18 13:33:17.000000000 -0400 | |
da5b3fc8 | 34979 | @@ -116,6 +116,7 @@ |
50425a20 | 34980 | #include <linux/security.h> |
b79bc584 | 34981 | #include <linux/vs_context.h> |
34982 | #include <linux/vs_limit.h> | |
50425a20 | 34983 | +#include <linux/grsecurity.h> |
34984 | ||
4dee9bd5 | 34985 | static struct hlist_head unix_socket_table[UNIX_HASH_SIZE + 1]; |
34986 | static DEFINE_SPINLOCK(unix_table_lock); | |
34987 | @@ -720,6 +721,12 @@ static struct sock *unix_find_other(stru | |
34988 | err = -ECONNREFUSED; | |
34989 | if (!S_ISSOCK(nd.path.dentry->d_inode->i_mode)) | |
50425a20 | 34990 | goto put_fail; |
4dee9bd5 | 34991 | + |
34992 | + if (!gr_acl_handle_unix(nd.path.dentry, nd.path.mnt)) { | |
50425a20 | 34993 | + err = -EACCES; |
34994 | + goto put_fail; | |
34995 | + } | |
34996 | + | |
4dee9bd5 | 34997 | u = unix_find_socket_byinode(net, nd.path.dentry->d_inode); |
34998 | if (!u) | |
50425a20 | 34999 | goto put_fail; |
4dee9bd5 | 35000 | @@ -740,6 +747,13 @@ static struct sock *unix_find_other(stru |
50425a20 | 35001 | if (u) { |
35002 | struct dentry *dentry; | |
35003 | dentry = unix_sk(u)->dentry; | |
35004 | + | |
35005 | + if (!gr_handle_chroot_unix(u->sk_peercred.pid)) { | |
35006 | + err = -EPERM; | |
35007 | + sock_put(u); | |
35008 | + goto fail; | |
35009 | + } | |
35010 | + | |
35011 | if (dentry) | |
35012 | touch_atime(unix_sk(u)->mnt, dentry); | |
35013 | } else | |
4dee9bd5 | 35014 | @@ -819,9 +833,18 @@ static int unix_bind(struct socket *sock |
50425a20 | 35015 | */ |
35016 | mode = S_IFSOCK | | |
35017 | (SOCK_INODE(sock)->i_mode & ~current->fs->umask); | |
35018 | + | |
4dee9bd5 | 35019 | + if (!gr_acl_handle_mknod(dentry, nd.path.dentry, nd.path.mnt, mode)) { |
50425a20 | 35020 | + err = -EACCES; |
35021 | + goto out_mknod_dput; | |
35022 | + } | |
35023 | + | |
b79bc584 | 35024 | err = vfs_mknod(nd.path.dentry->d_inode, dentry, mode, 0, NULL); |
50425a20 | 35025 | if (err) |
35026 | goto out_mknod_dput; | |
35027 | + | |
4dee9bd5 | 35028 | + gr_handle_create(dentry, nd.path.mnt); |
50425a20 | 35029 | + |
4dee9bd5 | 35030 | mutex_unlock(&nd.path.dentry->d_inode->i_mutex); |
35031 | dput(nd.path.dentry); | |
35032 | nd.path.dentry = dentry; | |
35033 | @@ -839,6 +862,10 @@ static int unix_bind(struct socket *sock | |
50425a20 | 35034 | goto out_unlock; |
35035 | } | |
35036 | ||
35037 | +#ifdef CONFIG_GRKERNSEC_CHROOT_UNIX | |
35038 | + sk->sk_peercred.pid = current->pid; | |
35039 | +#endif | |
35040 | + | |
35041 | list = &unix_socket_table[addr->hash]; | |
35042 | } else { | |
35043 | list = &unix_socket_table[dentry->d_inode->i_ino & (UNIX_HASH_SIZE-1)]; | |
4dee9bd5 | 35044 | diff -urNp linux-2.6.25.4/scripts/pnmtologo.c linux-2.6.25.4/scripts/pnmtologo.c |
35045 | --- linux-2.6.25.4/scripts/pnmtologo.c 2008-05-15 11:00:12.000000000 -0400 | |
35046 | +++ linux-2.6.25.4/scripts/pnmtologo.c 2008-05-18 13:33:17.000000000 -0400 | |
50425a20 | 35047 | @@ -237,14 +237,14 @@ static void write_header(void) |
35048 | fprintf(out, " * Linux logo %s\n", logoname); | |
35049 | fputs(" */\n\n", out); | |
35050 | fputs("#include <linux/linux_logo.h>\n\n", out); | |
35051 | - fprintf(out, "static unsigned char %s_data[] __initdata = {\n", | |
35052 | + fprintf(out, "static unsigned char %s_data[] = {\n", | |
35053 | logoname); | |
35054 | } | |
35055 | ||
35056 | static void write_footer(void) | |
35057 | { | |
35058 | fputs("\n};\n\n", out); | |
35059 | - fprintf(out, "struct linux_logo %s __initdata = {\n", logoname); | |
35060 | + fprintf(out, "struct linux_logo %s = {\n", logoname); | |
35061 | fprintf(out, " .type\t= %s,\n", logo_types[logo_type]); | |
35062 | fprintf(out, " .width\t= %d,\n", logo_width); | |
35063 | fprintf(out, " .height\t= %d,\n", logo_height); | |
35064 | @@ -374,7 +374,7 @@ static void write_logo_clut224(void) | |
35065 | fputs("\n};\n\n", out); | |
35066 | ||
35067 | /* write logo clut */ | |
35068 | - fprintf(out, "static unsigned char %s_clut[] __initdata = {\n", | |
35069 | + fprintf(out, "static unsigned char %s_clut[] = {\n", | |
35070 | logoname); | |
35071 | write_hex_cnt = 0; | |
35072 | for (i = 0; i < logo_clutsize; i++) { | |
4dee9bd5 | 35073 | diff -urNp linux-2.6.25.4/security/commoncap.c linux-2.6.25.4/security/commoncap.c |
35074 | --- linux-2.6.25.4/security/commoncap.c 2008-05-15 11:00:12.000000000 -0400 | |
35075 | +++ linux-2.6.25.4/security/commoncap.c 2008-05-18 13:33:17.000000000 -0400 | |
35076 | @@ -24,15 +24,18 @@ | |
da5b3fc8 | 35077 | #include <linux/mount.h> |
35078 | #include <linux/sched.h> | |
b79bc584 | 35079 | #include <linux/vs_context.h> |
50425a20 | 35080 | +#include <linux/grsecurity.h> |
35081 | ||
4dee9bd5 | 35082 | /* Global security state */ |
35083 | ||
b2ee8b1e | 35084 | unsigned securebits = SECUREBITS_DEFAULT; /* systemwide security settings */ |
35085 | EXPORT_SYMBOL(securebits); | |
da5b3fc8 | 35086 | |
4dee9bd5 | 35087 | +extern kernel_cap_t gr_cap_rtnetlink(struct sock *sk); |
b2ee8b1e | 35088 | + |
50425a20 | 35089 | int cap_netlink_send(struct sock *sk, struct sk_buff *skb) |
35090 | { | |
b79bc584 | 35091 | - NETLINK_CB(skb).eff_cap = vx_mbcaps(current->cap_effective); |
4dee9bd5 | 35092 | + NETLINK_CB(skb).eff_cap = gr_cap_rtnetlink(sk); |
50425a20 | 35093 | return 0; |
35094 | } | |
35095 | ||
4dee9bd5 | 35096 | @@ -54,7 +57,15 @@ EXPORT_SYMBOL(cap_netlink_recv); |
50425a20 | 35097 | int cap_capable (struct task_struct *tsk, int cap) |
35098 | { | |
35099 | /* Derived from include/linux/sched.h:capable. */ | |
b79bc584 | 35100 | - if (vx_cap_raised(vxi, tsk->cap_effective, cap)) |
35101 | + if (vx_cap_raised (vxi, tsk->cap_effective, cap)) | |
50425a20 | 35102 | + return 0; |
35103 | + return -EPERM; | |
35104 | +} | |
35105 | + | |
35106 | +int cap_capable_nolog (struct task_struct *tsk, int cap) | |
35107 | +{ | |
35108 | + /* tsk = current for all callers */ | |
b79bc584 | 35109 | + if (vx_cap_raised(tsk->vx_info, tsk->cap_effective, cap) && gr_is_capable_nolog(cap)) |
50425a20 | 35110 | return 0; |
35111 | return -EPERM; | |
35112 | } | |
4dee9bd5 | 35113 | @@ -352,8 +363,11 @@ void cap_bprm_apply_creds (struct linux_ |
50425a20 | 35114 | } |
35115 | } | |
35116 | ||
35117 | - current->suid = current->euid = current->fsuid = bprm->e_uid; | |
35118 | - current->sgid = current->egid = current->fsgid = bprm->e_gid; | |
35119 | + if (!gr_check_user_change(-1, bprm->e_uid, bprm->e_uid)) | |
35120 | + current->suid = current->euid = current->fsuid = bprm->e_uid; | |
35121 | + | |
35122 | + if (!gr_check_group_change(-1, bprm->e_gid, bprm->e_gid)) | |
35123 | + current->sgid = current->egid = current->fsgid = bprm->e_gid; | |
35124 | ||
35125 | /* For init, we want to retain the capabilities set | |
35126 | * in the init_task struct. Thus we skip the usual | |
4dee9bd5 | 35127 | @@ -366,6 +380,8 @@ void cap_bprm_apply_creds (struct linux_ |
35128 | cap_clear(current->cap_effective); | |
50425a20 | 35129 | } |
35130 | ||
35131 | + gr_handle_chroot_caps(current); | |
35132 | + | |
35133 | /* AUD: Audit candidate if current->cap_effective is set */ | |
35134 | ||
35135 | current->keep_capabilities = 0; | |
4dee9bd5 | 35136 | @@ -592,7 +608,7 @@ int cap_vm_enough_memory(struct mm_struc |
50425a20 | 35137 | { |
35138 | int cap_sys_admin = 0; | |
35139 | ||
35140 | - if (cap_capable(current, CAP_SYS_ADMIN) == 0) | |
35141 | + if (cap_capable_nolog(current, CAP_SYS_ADMIN) == 0) | |
35142 | cap_sys_admin = 1; | |
da5b3fc8 | 35143 | return __vm_enough_memory(mm, pages, cap_sys_admin); |
50425a20 | 35144 | } |
4dee9bd5 | 35145 | diff -urNp linux-2.6.25.4/security/dummy.c linux-2.6.25.4/security/dummy.c |
35146 | --- linux-2.6.25.4/security/dummy.c 2008-05-15 11:00:12.000000000 -0400 | |
35147 | +++ linux-2.6.25.4/security/dummy.c 2008-05-18 13:33:17.000000000 -0400 | |
da5b3fc8 | 35148 | @@ -27,6 +27,7 @@ |
50425a20 | 35149 | #include <linux/ptrace.h> |
35150 | #include <linux/file.h> | |
b79bc584 | 35151 | #include <linux/vs_context.h> |
50425a20 | 35152 | +#include <linux/grsecurity.h> |
35153 | ||
35154 | static int dummy_ptrace (struct task_struct *parent, struct task_struct *child) | |
35155 | { | |
4dee9bd5 | 35156 | @@ -140,8 +141,11 @@ static void dummy_bprm_apply_creds (stru |
50425a20 | 35157 | } |
35158 | } | |
35159 | ||
35160 | - current->suid = current->euid = current->fsuid = bprm->e_uid; | |
35161 | - current->sgid = current->egid = current->fsgid = bprm->e_gid; | |
35162 | + if (!gr_check_user_change(-1, bprm->e_uid, bprm->e_uid)) | |
35163 | + current->suid = current->euid = current->fsuid = bprm->e_uid; | |
35164 | + | |
35165 | + if (!gr_check_group_change(-1, bprm->e_gid, bprm->e_gid)) | |
35166 | + current->sgid = current->egid = current->fsgid = bprm->e_gid; | |
35167 | ||
35168 | dummy_capget(current, ¤t->cap_effective, ¤t->cap_inheritable, ¤t->cap_permitted); | |
35169 | } | |
4dee9bd5 | 35170 | diff -urNp linux-2.6.25.4/security/Kconfig linux-2.6.25.4/security/Kconfig |
35171 | --- linux-2.6.25.4/security/Kconfig 2008-05-15 11:00:12.000000000 -0400 | |
35172 | +++ linux-2.6.25.4/security/Kconfig 2008-05-18 13:33:17.000000000 -0400 | |
8a4b4a5e | 35173 | @@ -4,6 +4,429 @@ |
50425a20 | 35174 | |
35175 | menu "Security options" | |
35176 | ||
35177 | +source grsecurity/Kconfig | |
35178 | + | |
35179 | +menu "PaX" | |
35180 | + | |
35181 | +config PAX | |
35182 | + bool "Enable various PaX features" | |
953b9b0c | 35183 | + depends on GRKERNSEC && (ALPHA || ARM || AVR32 || IA64 || MIPS32 || MIPS64 || PARISC || PPC32 || PPC64 || SPARC32 || SPARC64 || X86 || X86_64) |
50425a20 | 35184 | + help |
35185 | + This allows you to enable various PaX features. PaX adds | |
35186 | + intrusion prevention mechanisms to the kernel that reduce | |
35187 | + the risks posed by exploitable memory corruption bugs. | |
35188 | + | |
35189 | +menu "PaX Control" | |
35190 | + depends on PAX | |
35191 | + | |
35192 | +config PAX_SOFTMODE | |
35193 | + bool 'Support soft mode' | |
35194 | + help | |
35195 | + Enabling this option will allow you to run PaX in soft mode, that | |
35196 | + is, PaX features will not be enforced by default, only on executables | |
35197 | + marked explicitly. You must also enable PT_PAX_FLAGS support as it | |
35198 | + is the only way to mark executables for soft mode use. | |
35199 | + | |
35200 | + Soft mode can be activated by using the "pax_softmode=1" kernel command | |
35201 | + line option on boot. Furthermore you can control various PaX features | |
35202 | + at runtime via the entries in /proc/sys/kernel/pax. | |
35203 | + | |
35204 | +config PAX_EI_PAX | |
35205 | + bool 'Use legacy ELF header marking' | |
35206 | + help | |
35207 | + Enabling this option will allow you to control PaX features on | |
35208 | + a per executable basis via the 'chpax' utility available at | |
35209 | + http://pax.grsecurity.net/. The control flags will be read from | |
35210 | + an otherwise reserved part of the ELF header. This marking has | |
35211 | + numerous drawbacks (no support for soft-mode, toolchain does not | |
35212 | + know about the non-standard use of the ELF header) therefore it | |
35213 | + has been deprecated in favour of PT_PAX_FLAGS support. | |
35214 | + | |
35215 | + If you have applications not marked by the PT_PAX_FLAGS ELF | |
35216 | + program header then you MUST enable this option otherwise they | |
35217 | + will not get any protection. | |
35218 | + | |
35219 | + Note that if you enable PT_PAX_FLAGS marking support as well, | |
35220 | + the PT_PAX_FLAG marks will override the legacy EI_PAX marks. | |
35221 | + | |
35222 | +config PAX_PT_PAX_FLAGS | |
35223 | + bool 'Use ELF program header marking' | |
35224 | + help | |
35225 | + Enabling this option will allow you to control PaX features on | |
35226 | + a per executable basis via the 'paxctl' utility available at | |
35227 | + http://pax.grsecurity.net/. The control flags will be read from | |
35228 | + a PaX specific ELF program header (PT_PAX_FLAGS). This marking | |
35229 | + has the benefits of supporting both soft mode and being fully | |
35230 | + integrated into the toolchain (the binutils patch is available | |
35231 | + from http://pax.grsecurity.net). | |
35232 | + | |
35233 | + If you have applications not marked by the PT_PAX_FLAGS ELF | |
35234 | + program header then you MUST enable the EI_PAX marking support | |
35235 | + otherwise they will not get any protection. | |
35236 | + | |
35237 | + Note that if you enable the legacy EI_PAX marking support as well, | |
35238 | + the EI_PAX marks will be overridden by the PT_PAX_FLAGS marks. | |
35239 | + | |
35240 | +choice | |
35241 | + prompt 'MAC system integration' | |
35242 | + default PAX_HAVE_ACL_FLAGS | |
35243 | + help | |
35244 | + Mandatory Access Control systems have the option of controlling | |
35245 | + PaX flags on a per executable basis, choose the method supported | |
35246 | + by your particular system. | |
35247 | + | |
35248 | + - "none": if your MAC system does not interact with PaX, | |
83a957c9 | 35249 | + - "direct": if your MAC system defines pax_set_initial_flags() itself, |
35250 | + - "hook": if your MAC system uses the pax_set_initial_flags_func callback. | |
50425a20 | 35251 | + |
35252 | + NOTE: this option is for developers/integrators only. | |
35253 | + | |
da5b3fc8 | 35254 | + config PAX_NO_ACL_FLAGS |
35255 | + bool 'none' | |
50425a20 | 35256 | + |
da5b3fc8 | 35257 | + config PAX_HAVE_ACL_FLAGS |
35258 | + bool 'direct' | |
50425a20 | 35259 | + |
da5b3fc8 | 35260 | + config PAX_HOOK_ACL_FLAGS |
35261 | + bool 'hook' | |
50425a20 | 35262 | +endchoice |
35263 | + | |
35264 | +endmenu | |
35265 | + | |
35266 | +menu "Non-executable pages" | |
35267 | + depends on PAX | |
35268 | + | |
35269 | +config PAX_NOEXEC | |
35270 | + bool "Enforce non-executable pages" | |
35271 | + depends on (PAX_EI_PAX || PAX_PT_PAX_FLAGS || PAX_HAVE_ACL_FLAGS || PAX_HOOK_ACL_FLAGS) && (ALPHA || IA64 || MIPS32 || MIPS64 || PARISC || PPC32 || PPC64 || SPARC32 || SPARC64 || X86 || X86_64) | |
35272 | + help | |
35273 | + By design some architectures do not allow for protecting memory | |
35274 | + pages against execution or even if they do, Linux does not make | |
35275 | + use of this feature. In practice this means that if a page is | |
35276 | + readable (such as the stack or heap) it is also executable. | |
35277 | + | |
35278 | + There is a well known exploit technique that makes use of this | |
35279 | + fact and a common programming mistake where an attacker can | |
35280 | + introduce code of his choice somewhere in the attacked program's | |
35281 | + memory (typically the stack or the heap) and then execute it. | |
35282 | + | |
35283 | + If the attacked program was running with different (typically | |
35284 | + higher) privileges than that of the attacker, then he can elevate | |
35285 | + his own privilege level (e.g. get a root shell, write to files for | |
35286 | + which he does not have write access to, etc). | |
35287 | + | |
35288 | + Enabling this option will let you choose from various features | |
35289 | + that prevent the injection and execution of 'foreign' code in | |
35290 | + a program. | |
35291 | + | |
35292 | + This will also break programs that rely on the old behaviour and | |
35293 | + expect that dynamically allocated memory via the malloc() family | |
35294 | + of functions is executable (which it is not). Notable examples | |
35295 | + are the XFree86 4.x server, the java runtime and wine. | |
35296 | + | |
35297 | +config PAX_PAGEEXEC | |
35298 | + bool "Paging based non-executable pages" | |
4dee9bd5 | 35299 | + depends on !COMPAT_VDSO && PAX_NOEXEC && (!X86_32 || M586 || M586TSC || M586MMX || M686 || MPENTIUMII || MPENTIUMIII || MPENTIUMM || MCORE2 || MPENTIUM4 || MPSC || MK7 || MK8 || MWINCHIPC6 || MWINCHIP2 || MWINCHIP3D || MVIAC3_2 || MVIAC7) |
50425a20 | 35300 | + help |
35301 | + This implementation is based on the paging feature of the CPU. | |
8a4b4a5e | 35302 | + On i386 without hardware non-executable bit support there is a |
35303 | + variable but usually low performance impact, however on Intel's | |
35304 | + P4 core based CPUs it is very high so you should not enable this | |
35305 | + for kernels meant to be used on such CPUs. | |
35306 | + | |
35307 | + On alpha, avr32, ia64, parisc, sparc, sparc64, x86_64 and i386 | |
35308 | + with hardware non-executable bit support there is no performance | |
35309 | + impact, on ppc the impact is negligible. | |
35310 | + | |
35311 | + Note that several architectures require various emulations due to | |
35312 | + badly designed userland ABIs, this will cause a performance impact | |
35313 | + but will disappear as soon as userland is fixed (e.g., ppc users | |
35314 | + can make use of the secure-plt feature found in binutils). | |
50425a20 | 35315 | + |
35316 | +config PAX_SEGMEXEC | |
35317 | + bool "Segmentation based non-executable pages" | |
35318 | + depends on !COMPAT_VDSO && PAX_NOEXEC && X86_32 | |
35319 | + help | |
35320 | + This implementation is based on the segmentation feature of the | |
8a4b4a5e | 35321 | + CPU and has a very small performance impact, however applications |
35322 | + will be limited to a 1.5 GB address space instead of the normal | |
35323 | + 3 GB. | |
50425a20 | 35324 | + |
35325 | +config PAX_EMUTRAMP | |
da5b3fc8 | 35326 | + bool "Emulate trampolines" if (PAX_PAGEEXEC || PAX_SEGMEXEC) && (PARISC || PPC32 || X86) |
50425a20 | 35327 | + default y if PARISC || PPC32 |
35328 | + help | |
35329 | + There are some programs and libraries that for one reason or | |
35330 | + another attempt to execute special small code snippets from | |
35331 | + non-executable memory pages. Most notable examples are the | |
35332 | + signal handler return code generated by the kernel itself and | |
35333 | + the GCC trampolines. | |
35334 | + | |
35335 | + If you enabled CONFIG_PAX_PAGEEXEC or CONFIG_PAX_SEGMEXEC then | |
35336 | + such programs will no longer work under your kernel. | |
35337 | + | |
35338 | + As a remedy you can say Y here and use the 'chpax' or 'paxctl' | |
35339 | + utilities to enable trampoline emulation for the affected programs | |
35340 | + yet still have the protection provided by the non-executable pages. | |
35341 | + | |
35342 | + On parisc and ppc you MUST enable this option and EMUSIGRT as | |
35343 | + well, otherwise your system will not even boot. | |
35344 | + | |
35345 | + Alternatively you can say N here and use the 'chpax' or 'paxctl' | |
35346 | + utilities to disable CONFIG_PAX_PAGEEXEC and CONFIG_PAX_SEGMEXEC | |
35347 | + for the affected files. | |
35348 | + | |
35349 | + NOTE: enabling this feature *may* open up a loophole in the | |
35350 | + protection provided by non-executable pages that an attacker | |
35351 | + could abuse. Therefore the best solution is to not have any | |
35352 | + files on your system that would require this option. This can | |
35353 | + be achieved by not using libc5 (which relies on the kernel | |
35354 | + signal handler return code) and not using or rewriting programs | |
35355 | + that make use of the nested function implementation of GCC. | |
35356 | + Skilled users can just fix GCC itself so that it implements | |
35357 | + nested function calls in a way that does not interfere with PaX. | |
35358 | + | |
35359 | +config PAX_EMUSIGRT | |
35360 | + bool "Automatically emulate sigreturn trampolines" | |
35361 | + depends on PAX_EMUTRAMP && (PARISC || PPC32) | |
35362 | + default y | |
35363 | + help | |
35364 | + Enabling this option will have the kernel automatically detect | |
35365 | + and emulate signal return trampolines executing on the stack | |
35366 | + that would otherwise lead to task termination. | |
35367 | + | |
35368 | + This solution is intended as a temporary one for users with | |
35369 | + legacy versions of libc (libc5, glibc 2.0, uClibc before 0.9.17, | |
35370 | + Modula-3 runtime, etc) or executables linked to such, basically | |
35371 | + everything that does not specify its own SA_RESTORER function in | |
35372 | + normal executable memory like glibc 2.1+ does. | |
35373 | + | |
35374 | + On parisc and ppc you MUST enable this option, otherwise your | |
35375 | + system will not even boot. | |
35376 | + | |
35377 | + NOTE: this feature cannot be disabled on a per executable basis | |
35378 | + and since it *does* open up a loophole in the protection provided | |
35379 | + by non-executable pages, the best solution is to not have any | |
35380 | + files on your system that would require this option. | |
35381 | + | |
35382 | +config PAX_MPROTECT | |
35383 | + bool "Restrict mprotect()" | |
35384 | + depends on (PAX_PAGEEXEC || PAX_SEGMEXEC) && !PPC64 | |
35385 | + help | |
35386 | + Enabling this option will prevent programs from | |
35387 | + - changing the executable status of memory pages that were | |
35388 | + not originally created as executable, | |
35389 | + - making read-only executable pages writable again, | |
35390 | + - creating executable pages from anonymous memory. | |
35391 | + | |
35392 | + You should say Y here to complete the protection provided by | |
35393 | + the enforcement of non-executable pages. | |
35394 | + | |
35395 | + NOTE: you can use the 'chpax' or 'paxctl' utilities to control | |
35396 | + this feature on a per file basis. | |
35397 | + | |
35398 | +config PAX_NOELFRELOCS | |
35399 | + bool "Disallow ELF text relocations" | |
35400 | + depends on PAX_MPROTECT && !PAX_ETEXECRELOCS && (IA64 || X86 || X86_64) | |
35401 | + help | |
35402 | + Non-executable pages and mprotect() restrictions are effective | |
35403 | + in preventing the introduction of new executable code into an | |
35404 | + attacked task's address space. There remain only two venues | |
35405 | + for this kind of attack: if the attacker can execute already | |
35406 | + existing code in the attacked task then he can either have it | |
35407 | + create and mmap() a file containing his code or have it mmap() | |
35408 | + an already existing ELF library that does not have position | |
35409 | + independent code in it and use mprotect() on it to make it | |
35410 | + writable and copy his code there. While protecting against | |
35411 | + the former approach is beyond PaX, the latter can be prevented | |
35412 | + by having only PIC ELF libraries on one's system (which do not | |
35413 | + need to relocate their code). If you are sure this is your case, | |
35414 | + then enable this option otherwise be careful as you may not even | |
35415 | + be able to boot or log on your system (for example, some PAM | |
35416 | + modules are erroneously compiled as non-PIC by default). | |
35417 | + | |
35418 | + NOTE: if you are using dynamic ELF executables (as suggested | |
35419 | + when using ASLR) then you must have made sure that you linked | |
35420 | + your files using the PIC version of crt1 (the et_dyn.tar.gz package | |
35421 | + referenced there has already been updated to support this). | |
35422 | + | |
35423 | +config PAX_ETEXECRELOCS | |
35424 | + bool "Allow ELF ET_EXEC text relocations" | |
35425 | + depends on PAX_MPROTECT && (ALPHA || IA64 || PARISC) | |
35426 | + default y | |
35427 | + help | |
35428 | + On some architectures there are incorrectly created applications | |
35429 | + that require text relocations and would not work without enabling | |
35430 | + this option. If you are an alpha, ia64 or parisc user, you should | |
35431 | + enable this option and disable it once you have made sure that | |
35432 | + none of your applications need it. | |
35433 | + | |
35434 | +config PAX_EMUPLT | |
35435 | + bool "Automatically emulate ELF PLT" | |
35436 | + depends on PAX_MPROTECT && (ALPHA || PARISC || PPC32 || SPARC32 || SPARC64) | |
35437 | + default y | |
35438 | + help | |
35439 | + Enabling this option will have the kernel automatically detect | |
35440 | + and emulate the Procedure Linkage Table entries in ELF files. | |
35441 | + On some architectures such entries are in writable memory, and | |
35442 | + become non-executable leading to task termination. Therefore | |
8a4b4a5e | 35443 | + it is mandatory that you enable this option on alpha, parisc, |
35444 | + ppc (if secure-plt is not used throughout in userland), sparc | |
35445 | + and sparc64, otherwise your system would not even boot. | |
50425a20 | 35446 | + |
35447 | + NOTE: this feature *does* open up a loophole in the protection | |
35448 | + provided by the non-executable pages, therefore the proper | |
35449 | + solution is to modify the toolchain to produce a PLT that does | |
35450 | + not need to be writable. | |
35451 | + | |
35452 | +config PAX_DLRESOLVE | |
35453 | + bool | |
35454 | + depends on PAX_EMUPLT && (SPARC32 || SPARC64) | |
35455 | + default y | |
35456 | + | |
35457 | +config PAX_SYSCALL | |
35458 | + bool | |
35459 | + depends on PAX_PAGEEXEC && PPC32 | |
35460 | + default y | |
35461 | + | |
35462 | +config PAX_KERNEXEC | |
35463 | + bool "Enforce non-executable kernel pages" | |
da5b3fc8 | 35464 | + depends on PAX_NOEXEC && X86 && !EFI && !COMPAT_VDSO && (!X86_32 || X86_WP_WORKS_OK) && !PARAVIRT |
50425a20 | 35465 | + help |
35466 | + This is the kernel land equivalent of PAGEEXEC and MPROTECT, | |
35467 | + that is, enabling this option will make it harder to inject | |
35468 | + and execute 'foreign' code in kernel memory itself. | |
35469 | + | |
35470 | +endmenu | |
35471 | + | |
35472 | +menu "Address Space Layout Randomization" | |
35473 | + depends on PAX | |
35474 | + | |
35475 | +config PAX_ASLR | |
35476 | + bool "Address Space Layout Randomization" | |
35477 | + depends on PAX_EI_PAX || PAX_PT_PAX_FLAGS || PAX_HAVE_ACL_FLAGS || PAX_HOOK_ACL_FLAGS | |
35478 | + help | |
35479 | + Many if not most exploit techniques rely on the knowledge of | |
35480 | + certain addresses in the attacked program. The following options | |
35481 | + will allow the kernel to apply a certain amount of randomization | |
35482 | + to specific parts of the program thereby forcing an attacker to | |
35483 | + guess them in most cases. Any failed guess will most likely crash | |
35484 | + the attacked program which allows the kernel to detect such attempts | |
35485 | + and react on them. PaX itself provides no reaction mechanisms, | |
35486 | + instead it is strongly encouraged that you make use of Nergal's | |
35487 | + segvguard (ftp://ftp.pl.openwall.com/misc/segvguard/) or grsecurity's | |
35488 | + (http://www.grsecurity.net/) built-in crash detection features or | |
35489 | + develop one yourself. | |
35490 | + | |
35491 | + By saying Y here you can choose to randomize the following areas: | |
35492 | + - top of the task's kernel stack | |
35493 | + - top of the task's userland stack | |
35494 | + - base address for mmap() requests that do not specify one | |
35495 | + (this includes all libraries) | |
35496 | + - base address of the main executable | |
35497 | + | |
35498 | + It is strongly recommended to say Y here as address space layout | |
35499 | + randomization has negligible impact on performance yet it provides | |
35500 | + a very effective protection. | |
35501 | + | |
35502 | + NOTE: you can use the 'chpax' or 'paxctl' utilities to control | |
35503 | + this feature on a per file basis. | |
35504 | + | |
35505 | +config PAX_RANDKSTACK | |
35506 | + bool "Randomize kernel stack base" | |
35507 | + depends on PAX_ASLR && X86_TSC && X86_32 | |
35508 | + help | |
35509 | + By saying Y here the kernel will randomize every task's kernel | |
35510 | + stack on every system call. This will not only force an attacker | |
35511 | + to guess it but also prevent him from making use of possible | |
35512 | + leaked information about it. | |
35513 | + | |
35514 | + Since the kernel stack is a rather scarce resource, randomization | |
35515 | + may cause unexpected stack overflows, therefore you should very | |
35516 | + carefully test your system. Note that once enabled in the kernel | |
35517 | + configuration, this feature cannot be disabled on a per file basis. | |
35518 | + | |
35519 | +config PAX_RANDUSTACK | |
35520 | + bool "Randomize user stack base" | |
35521 | + depends on PAX_ASLR | |
35522 | + help | |
35523 | + By saying Y here the kernel will randomize every task's userland | |
35524 | + stack. The randomization is done in two steps where the second | |
35525 | + one may apply a big amount of shift to the top of the stack and | |
35526 | + cause problems for programs that want to use lots of memory (more | |
35527 | + than 2.5 GB if SEGMEXEC is not active, or 1.25 GB when it is). | |
35528 | + For this reason the second step can be controlled by 'chpax' or | |
35529 | + 'paxctl' on a per file basis. | |
35530 | + | |
35531 | +config PAX_RANDMMAP | |
35532 | + bool "Randomize mmap() base" | |
35533 | + depends on PAX_ASLR | |
35534 | + help | |
35535 | + By saying Y here the kernel will use a randomized base address for | |
35536 | + mmap() requests that do not specify one themselves. As a result | |
35537 | + all dynamically loaded libraries will appear at random addresses | |
35538 | + and therefore be harder to exploit by a technique where an attacker | |
35539 | + attempts to execute library code for his purposes (e.g. spawn a | |
35540 | + shell from an exploited program that is running at an elevated | |
35541 | + privilege level). | |
35542 | + | |
35543 | + Furthermore, if a program is relinked as a dynamic ELF file, its | |
35544 | + base address will be randomized as well, completing the full | |
35545 | + randomization of the address space layout. Attacking such programs | |
35546 | + becomes a guess game. You can find an example of doing this at | |
35547 | + http://pax.grsecurity.net/et_dyn.tar.gz and practical samples at | |
35548 | + http://www.grsecurity.net/grsec-gcc-specs.tar.gz . | |
35549 | + | |
35550 | + NOTE: you can use the 'chpax' or 'paxctl' utilities to control this | |
35551 | + feature on a per file basis. | |
35552 | + | |
35553 | +endmenu | |
35554 | + | |
35555 | +menu "Miscellaneous hardening features" | |
35556 | + | |
35557 | +config PAX_MEMORY_SANITIZE | |
35558 | + bool "Sanitize all freed memory" | |
35559 | + help | |
35560 | + By saying Y here the kernel will erase memory pages as soon as they | |
35561 | + are freed. This in turn reduces the lifetime of data stored in the | |
35562 | + pages, making it less likely that sensitive information such as | |
35563 | + passwords, cryptographic secrets, etc stay in memory for too long. | |
35564 | + | |
35565 | + This is especially useful for programs whose runtime is short, long | |
35566 | + lived processes and the kernel itself benefit from this as long as | |
35567 | + they operate on whole memory pages and ensure timely freeing of pages | |
35568 | + that may hold sensitive information. | |
35569 | + | |
35570 | + The tradeoff is performance impact, on a single CPU system kernel | |
35571 | + compilation sees a 3% slowdown, other systems and workloads may vary | |
35572 | + and you are advised to test this feature on your expected workload | |
35573 | + before deploying it. | |
35574 | + | |
35575 | + Note that this feature does not protect data stored in live pages, | |
35576 | + e.g., process memory swapped to disk may stay there for a long time. | |
35577 | + | |
35578 | +config PAX_MEMORY_UDEREF | |
35579 | + bool "Prevent invalid userland pointer dereference" | |
35580 | + depends on X86_32 && !COMPAT_VDSO | |
35581 | + help | |
35582 | + By saying Y here the kernel will be prevented from dereferencing | |
35583 | + userland pointers in contexts where the kernel expects only kernel | |
35584 | + pointers. This is both a useful runtime debugging feature and a | |
35585 | + security measure that prevents exploiting a class of kernel bugs. | |
35586 | + | |
35587 | + The tradeoff is that some virtualization solutions may experience | |
35588 | + a huge slowdown and therefore you should not enable this feature | |
35589 | + for kernels meant to run in such environments. Whether a given VM | |
35590 | + solution is affected or not is best determined by simply trying it | |
35591 | + out, the performance impact will be obvious right on boot as this | |
35592 | + mechanism engages from very early on. A good rule of thumb is that | |
35593 | + VMs running on CPUs without hardware virtualization support (i.e., | |
35594 | + the majority of IA-32 CPUs) will likely experience the slowdown. | |
35595 | + | |
35596 | +endmenu | |
35597 | + | |
35598 | +endmenu | |
35599 | + | |
35600 | config KEYS | |
35601 | bool "Enable access key retention support" | |
da5b3fc8 | 35602 | help |
4dee9bd5 | 35603 | diff -urNp linux-2.6.25.4/sound/core/oss/pcm_oss.c linux-2.6.25.4/sound/core/oss/pcm_oss.c |
35604 | --- linux-2.6.25.4/sound/core/oss/pcm_oss.c 2008-05-15 11:00:12.000000000 -0400 | |
35605 | +++ linux-2.6.25.4/sound/core/oss/pcm_oss.c 2008-05-18 13:33:17.000000000 -0400 | |
35606 | @@ -2911,8 +2911,8 @@ static void snd_pcm_oss_proc_done(struct | |
50425a20 | 35607 | } |
35608 | } | |
35609 | #else /* !CONFIG_SND_VERBOSE_PROCFS */ | |
35610 | -#define snd_pcm_oss_proc_init(pcm) | |
35611 | -#define snd_pcm_oss_proc_done(pcm) | |
35612 | +#define snd_pcm_oss_proc_init(pcm) do {} while (0) | |
35613 | +#define snd_pcm_oss_proc_done(pcm) do {} while (0) | |
35614 | #endif /* CONFIG_SND_VERBOSE_PROCFS */ | |
35615 | ||
35616 | /* | |
4dee9bd5 | 35617 | diff -urNp linux-2.6.25.4/sound/core/seq/seq_lock.h linux-2.6.25.4/sound/core/seq/seq_lock.h |
35618 | --- linux-2.6.25.4/sound/core/seq/seq_lock.h 2008-05-15 11:00:12.000000000 -0400 | |
35619 | +++ linux-2.6.25.4/sound/core/seq/seq_lock.h 2008-05-18 13:33:17.000000000 -0400 | |
50425a20 | 35620 | @@ -23,10 +23,10 @@ void snd_use_lock_sync_helper(snd_use_lo |
35621 | #else /* SMP || CONFIG_SND_DEBUG */ | |
35622 | ||
35623 | typedef spinlock_t snd_use_lock_t; /* dummy */ | |
35624 | -#define snd_use_lock_init(lockp) /**/ | |
35625 | -#define snd_use_lock_use(lockp) /**/ | |
35626 | -#define snd_use_lock_free(lockp) /**/ | |
35627 | -#define snd_use_lock_sync(lockp) /**/ | |
35628 | +#define snd_use_lock_init(lockp) do {} while (0) | |
35629 | +#define snd_use_lock_use(lockp) do {} while (0) | |
35630 | +#define snd_use_lock_free(lockp) do {} while (0) | |
35631 | +#define snd_use_lock_sync(lockp) do {} while (0) | |
35632 | ||
35633 | #endif /* SMP || CONFIG_SND_DEBUG */ | |
35634 | ||
4dee9bd5 | 35635 | diff -urNp linux-2.6.25.4/sound/pci/ac97/ac97_patch.c linux-2.6.25.4/sound/pci/ac97/ac97_patch.c |
35636 | --- linux-2.6.25.4/sound/pci/ac97/ac97_patch.c 2008-05-15 11:00:12.000000000 -0400 | |
35637 | +++ linux-2.6.25.4/sound/pci/ac97/ac97_patch.c 2008-05-18 13:33:17.000000000 -0400 | |
35638 | @@ -1486,7 +1486,7 @@ static const struct snd_ac97_res_table a | |
50425a20 | 35639 | { AC97_VIDEO, 0x9f1f }, |
35640 | { AC97_AUX, 0x9f1f }, | |
35641 | { AC97_PCM, 0x9f1f }, | |
35642 | - { } /* terminator */ | |
8a4b4a5e | 35643 | + { 0, 0 } /* terminator */ |
50425a20 | 35644 | }; |
35645 | ||
8a4b4a5e | 35646 | static int patch_ad1819(struct snd_ac97 * ac97) |
4dee9bd5 | 35647 | @@ -3544,7 +3544,7 @@ static struct snd_ac97_res_table lm4550_ |
50425a20 | 35648 | { AC97_AUX, 0x1f1f }, |
35649 | { AC97_PCM, 0x1f1f }, | |
35650 | { AC97_REC_GAIN, 0x0f0f }, | |
35651 | - { } /* terminator */ | |
35652 | + { 0, 0 } /* terminator */ | |
35653 | }; | |
35654 | ||
8a4b4a5e | 35655 | static int patch_lm4550(struct snd_ac97 *ac97) |
4dee9bd5 | 35656 | diff -urNp linux-2.6.25.4/sound/pci/ens1370.c linux-2.6.25.4/sound/pci/ens1370.c |
35657 | --- linux-2.6.25.4/sound/pci/ens1370.c 2008-05-15 11:00:12.000000000 -0400 | |
35658 | +++ linux-2.6.25.4/sound/pci/ens1370.c 2008-05-18 13:33:17.000000000 -0400 | |
35659 | @@ -452,7 +452,7 @@ static struct pci_device_id snd_audiopci | |
50425a20 | 35660 | { 0x1274, 0x5880, PCI_ANY_ID, PCI_ANY_ID, 0, 0, 0, }, /* ES1373 - CT5880 */ |
35661 | { 0x1102, 0x8938, PCI_ANY_ID, PCI_ANY_ID, 0, 0, 0, }, /* Ectiva EV1938 */ | |
35662 | #endif | |
35663 | - { 0, } | |
35664 | + { 0, 0, 0, 0, 0, 0, 0 } | |
35665 | }; | |
35666 | ||
35667 | MODULE_DEVICE_TABLE(pci, snd_audiopci_ids); | |
4dee9bd5 | 35668 | diff -urNp linux-2.6.25.4/sound/pci/intel8x0.c linux-2.6.25.4/sound/pci/intel8x0.c |
35669 | --- linux-2.6.25.4/sound/pci/intel8x0.c 2008-05-15 11:00:12.000000000 -0400 | |
35670 | +++ linux-2.6.25.4/sound/pci/intel8x0.c 2008-05-18 13:33:17.000000000 -0400 | |
35671 | @@ -435,7 +435,7 @@ static struct pci_device_id snd_intel8x0 | |
50425a20 | 35672 | { 0x1022, 0x746d, PCI_ANY_ID, PCI_ANY_ID, 0, 0, DEVICE_INTEL }, /* AMD8111 */ |
35673 | { 0x1022, 0x7445, PCI_ANY_ID, PCI_ANY_ID, 0, 0, DEVICE_INTEL }, /* AMD768 */ | |
35674 | { 0x10b9, 0x5455, PCI_ANY_ID, PCI_ANY_ID, 0, 0, DEVICE_ALI }, /* Ali5455 */ | |
35675 | - { 0, } | |
35676 | + { 0, 0, 0, 0, 0, 0, 0 } | |
35677 | }; | |
35678 | ||
35679 | MODULE_DEVICE_TABLE(pci, snd_intel8x0_ids); | |
4dee9bd5 | 35680 | @@ -2057,7 +2057,7 @@ static struct ac97_quirk ac97_quirks[] _ |
50425a20 | 35681 | .type = AC97_TUNE_HP_ONLY |
35682 | }, | |
35683 | #endif | |
35684 | - { } /* terminator */ | |
35685 | + { 0, 0, 0, 0, NULL, 0 } /* terminator */ | |
35686 | }; | |
35687 | ||
35688 | static int __devinit snd_intel8x0_mixer(struct intel8x0 *chip, int ac97_clock, | |
4dee9bd5 | 35689 | diff -urNp linux-2.6.25.4/sound/pci/intel8x0m.c linux-2.6.25.4/sound/pci/intel8x0m.c |
35690 | --- linux-2.6.25.4/sound/pci/intel8x0m.c 2008-05-15 11:00:12.000000000 -0400 | |
35691 | +++ linux-2.6.25.4/sound/pci/intel8x0m.c 2008-05-18 13:33:17.000000000 -0400 | |
35692 | @@ -239,7 +239,7 @@ static struct pci_device_id snd_intel8x0 | |
50425a20 | 35693 | { 0x1022, 0x746d, PCI_ANY_ID, PCI_ANY_ID, 0, 0, DEVICE_INTEL }, /* AMD8111 */ |
35694 | { 0x10b9, 0x5455, PCI_ANY_ID, PCI_ANY_ID, 0, 0, DEVICE_ALI }, /* Ali5455 */ | |
35695 | #endif | |
35696 | - { 0, } | |
35697 | + { 0, 0, 0, 0, 0, 0, 0 } | |
35698 | }; | |
35699 | ||
35700 | MODULE_DEVICE_TABLE(pci, snd_intel8x0m_ids); | |
4dee9bd5 | 35701 | @@ -1260,7 +1260,7 @@ static struct shortname_table { |
50425a20 | 35702 | { 0x5455, "ALi M5455" }, |
35703 | { 0x746d, "AMD AMD8111" }, | |
35704 | #endif | |
35705 | - { 0 }, | |
35706 | + { 0, NULL }, | |
35707 | }; | |
35708 | ||
35709 | static int __devinit snd_intel8x0m_probe(struct pci_dev *pci, | |
4dee9bd5 | 35710 | diff -urNp linux-2.6.25.4/virt/kvm/kvm_main.c linux-2.6.25.4/virt/kvm/kvm_main.c |
35711 | --- linux-2.6.25.4/virt/kvm/kvm_main.c 2008-05-15 11:00:12.000000000 -0400 | |
35712 | +++ linux-2.6.25.4/virt/kvm/kvm_main.c 2008-05-18 13:33:17.000000000 -0400 | |
35713 | @@ -1077,6 +1077,9 @@ static struct miscdevice kvm_dev = { | |
35714 | KVM_MINOR, | |
35715 | "kvm", | |
35716 | &kvm_chardev_ops, | |
35717 | + {NULL, NULL}, | |
35718 | + NULL, | |
35719 | + NULL | |
35720 | }; | |
35721 | ||
35722 | static void hardware_enable(void *junk) | |
6778dfc1 | 35723 | --- e/include/asm-sparc/pgtable.h~ 2008-04-17 04:49:44.000000000 +0200 |
35724 | +++ e/include/asm-sparc/pgtable.h 2008-05-24 01:10:57.509956255 +0200 | |
35725 | @@ -50,6 +50,12 @@ BTFIXUPDEF_INT(page_copy) | |
35726 | BTFIXUPDEF_INT(page_readonly) | |
35727 | BTFIXUPDEF_INT(page_kernel) | |
35728 | ||
35729 | +#ifdef CONFIG_PAX_PAGEEXEC | |
35730 | +BTFIXUPDEF_INT(page_shared_noexec) | |
35731 | +BTFIXUPDEF_INT(page_copy_noexec) | |
35732 | +BTFIXUPDEF_INT(page_readonly_noexec) | |
35733 | +#endif | |
35734 | + | |
35735 | #define PMD_SHIFT SUN4C_PMD_SHIFT | |
35736 | #define PMD_SIZE (1UL << PMD_SHIFT) | |
35737 | #define PMD_MASK (~(PMD_SIZE-1)) |