Page MenuHomeFreeBSD

kern: add primitive checked versions of copyin/copyout
Needs ReviewPublic

Authored by kevans on Tue, Oct 6, 8:41 PM.
Tags
None
Referenced Files
F175465629: D60421.diff
Sun, Oct 11, 1:45 AM
F175462279: D60421.diff
Sun, Oct 11, 1:11 AM
Unknown Object (File)
Sat, Oct 10, 6:26 AM
Unknown Object (File)
Fri, Oct 9, 7:40 PM
Unknown Object (File)
Fri, Oct 9, 5:53 PM
Unknown Object (File)
Fri, Oct 9, 4:46 PM
Unknown Object (File)
Fri, Oct 9, 4:45 PM
Unknown Object (File)
Fri, Oct 9, 4:05 PM

Details

Reviewers
markj
kib
andrew
manu
Group Reviewers
srcmgr
Summary

If __builtin_object_size can determine the size of the object that we
are copying to/from, then we can detect some classes of stack disclosure
or overflow if runtime is suitably exercised. That's obviously only as
useful as the tests we write (or fuzzing that we do), but we previously
didn't really have any mechanisms to detect these failure modes except,
presumably, under KMSAN.

Note that we have to use bos 0 here to allow copies to cover any
containing object, for cases like exterr that might copy from one member
to a later part of the containing struct.

Diff Detail

Repository
rG FreeBSD src repository
Lint
Lint Passed
Unit
No Test Coverage
Build Status
Buildable 77781
Build 74664: arc lint + arc unit

Event Timeline

kevans requested review of this revision.Tue, Oct 6, 8:41 PM
sys/sys/systm.h
365

Is it possible we are losing the __nodiscard annotation here?

sys/sys/systm.h
365

I... have no idea if it'll get properly propagated or not. I'll double-check that. @andrew also had a suggestion for turning these into an error at compile-time in case the supplied len is a constant expression that I'd like to incorporate.