From patchwork Thu Sep 7 01:18:08 2023 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Greg Ungerer X-Patchwork-Id: 13376060 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from kanga.kvack.org (kanga.kvack.org [205.233.56.17]) by smtp.lore.kernel.org (Postfix) with ESMTP id 55E14EE14AA for ; Thu, 7 Sep 2023 01:18:37 +0000 (UTC) Received: by kanga.kvack.org (Postfix) id 92AB2280026; Wed, 6 Sep 2023 21:18:36 -0400 (EDT) Received: by kanga.kvack.org (Postfix, from userid 40) id 8D987280025; Wed, 6 Sep 2023 21:18:36 -0400 (EDT) X-Delivered-To: int-list-linux-mm@kvack.org Received: by kanga.kvack.org (Postfix, from userid 63042) id 7C837280026; Wed, 6 Sep 2023 21:18:36 -0400 (EDT) X-Delivered-To: linux-mm@kvack.org Received: from relay.hostedemail.com (smtprelay0016.hostedemail.com [216.40.44.16]) by kanga.kvack.org (Postfix) with ESMTP id 6CEA5280025 for ; Wed, 6 Sep 2023 21:18:36 -0400 (EDT) Received: from smtpin30.hostedemail.com (a10.router.float.18 [10.200.18.1]) by unirelay05.hostedemail.com (Postfix) with ESMTP id 40B4C40EE8 for ; Thu, 7 Sep 2023 01:18:36 +0000 (UTC) X-FDA: 81208041432.30.6B83551 Received: from sin.source.kernel.org (sin.source.kernel.org [145.40.73.55]) by imf25.hostedemail.com (Postfix) with ESMTP id 288A9A000C for ; Thu, 7 Sep 2023 01:18:32 +0000 (UTC) Authentication-Results: imf25.hostedemail.com; dkim=pass header.d=kernel.org header.s=k20201202 header.b=cYWTQpyu; spf=pass (imf25.hostedemail.com: domain of gerg@kernel.org designates 145.40.73.55 as permitted sender) smtp.mailfrom=gerg@kernel.org; dmarc=pass (policy=none) header.from=kernel.org ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=hostedemail.com; s=arc-20220608; t=1694049513; h=from:from:sender:reply-to:subject:subject:date:date: message-id:message-id:to:to:cc:cc:mime-version:mime-version: content-type:content-transfer-encoding:content-transfer-encoding: in-reply-to:references:dkim-signature; bh=Mr6h9G0qcU3dBEuoPPDiZty8B5MCm6PllDxWvGfxNco=; b=U+I7ibZkqcG06+jf56sisOtsQJZ6P/yChkOEK0DIfdd4BC7UFvbL9dTFOAoAuAXQ1zkg01 9byC5SWp/ne+kgVmmZ22Oi1iGFLRNbBKjEmNr8mjnlZm9dOvcak+AihEFfLU6G3Q3mXUsk izXeL1e5zvczJxms6kgCnW2vc6CW24c= ARC-Seal: i=1; s=arc-20220608; d=hostedemail.com; t=1694049513; a=rsa-sha256; cv=none; b=tg88we/vhqrNggqPFPCo5p3UfQ6TqwnZQRJWAIL49VuNWswz/lvpsFKlaPWnSn34peHumc lXuUqCgv6aI+zjEW0bomaOUPpT/i0/qoJFYhH316y/uwmjREqkRlpa6MR/jtILwhoQ53fD tMP3kKbt9VXKXaA9L9P+1FefWKW25Ow= ARC-Authentication-Results: i=1; imf25.hostedemail.com; dkim=pass header.d=kernel.org header.s=k20201202 header.b=cYWTQpyu; spf=pass (imf25.hostedemail.com: domain of gerg@kernel.org designates 145.40.73.55 as permitted sender) smtp.mailfrom=gerg@kernel.org; dmarc=pass (policy=none) header.from=kernel.org Received: from smtp.kernel.org (relay.kernel.org [52.25.139.140]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits)) (No client certificate requested) by sin.source.kernel.org (Postfix) with ESMTPS id AC40DCE1867; Thu, 7 Sep 2023 01:18:29 +0000 (UTC) Received: by smtp.kernel.org (Postfix) with ESMTPSA id CE0C4C433C7; Thu, 7 Sep 2023 01:18:25 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=k20201202; t=1694049508; bh=BeOcAfqz6CSc1uyYqrlte5iokIu2e62KSauO75vYKJ4=; h=From:To:Cc:Subject:Date:From; b=cYWTQpyumk7mQ7cEikaoDdx1Jh9PLmDLRqHqicm4G4fLdYqkPTe8pBXH45YwN3Lc2 AtIVWrbVueM+5SPGOVCfFj9PhyarGhjQfYpLPJZ338+PXgf02TUXbZcjoC2H42LtyY LdxiMXyRbP8LsFbyP/QxpALAPKibolLa6q8dAokmKfSy4nV8uO1uX44/E8wpm8J6zQ F/oeezDmfqNSqrPt8+lCbRPxPem3h1XVa9afRZvr8lmnEx4wTFkf5D9NG2FZeL61cY E5wMXjkBvjqBLOw0BMo/p9yDoe4Fu4mzzSxjNxb+92ULbaLHk1V+g9jd5gNvpbTd9H 5iKUyzc3J4etw== From: Greg Ungerer To: linux-arm@lists.infradead.org, linux-mm@kvack.org, linux-fsdevel@vger.kernel.org Cc: linux-kernel@vger.kernel.org, eescook@chromium.org, ebiederm@xmission.com, brauner@kernel.org, viro@zeniv.linux.org.uk, Greg Ungerer Subject: [PATCH v2] fs: binfmt_elf_efpic: fix personality for ELF-FDPIC Date: Thu, 7 Sep 2023 11:18:08 +1000 Message-Id: <20230907011808.2985083-1-gerg@kernel.org> X-Mailer: git-send-email 2.25.1 MIME-Version: 1.0 X-Rspamd-Queue-Id: 288A9A000C X-Rspam-User: X-Rspamd-Server: rspam11 X-Stat-Signature: naw3ki9zchnqft4k7xbtxi1y6o7t6ezq X-HE-Tag: 1694049512-77276 X-HE-Meta: U2FsdGVkX19/MLkWVEj/mPrOZcyXix+vTRDVc/IZj5uSPQYcXkvuDxegl96hU0ILuyDIRW5XTZPDssswxyE1LNFvDLkVZXHDeDj7erxZG4z40RXzK7xDZq6oua/u99YWBZlFRPrOzLVwxAlWJws1uDNLG/JvJd7a/qxUaYjrnKQrmZW9C74ouyaxcC4rUe2BTk1tQzPiU9ajIJ6/3gFSNruGxPCa2zMhMIlWIo36C/LUvX10ZIWX1UxAB4uUfKsViAXHQMl0JudnLgayojoMrCH1rT03OjGjkR5+67LrCxa8ecHLeAantwxUInyk4TasI6dbmo1UcaOdiO48NGTe2EC7h7Z4HK7DfC82Fuw8AFrPiLLXfK2u1WO7eMOlHRO2um8UIRXS3q/jYL0wgzI+ErCovqe4U1O5lVdke+SG/L51/LPlny7BklpCFtlrCvw+lNnD11qozYszBf9EgrXQtN5OHfl/TxygcM5uFHINnhIu+I9XoBgZrSaAFqzqZHtKJ8dowoLJn33XYci4ZJ4U7ZIk3k/NABVDV6ZOQZHhzEHsm4slqDswQ3eaz7RY26W9+35WrdG0TQqwpF5sko7LIb/Ta4PXVySMJdvlL5grs0eSBRNyoE+ltlLLki1UF3/3xWW/EtJSR1xPTEaL5M4RvACALaPonopKaFH4jacse9aEEHdJOEELojATugkLNAuxzK+ToQ1ZB6Kdak9eGwSdn3jpWvBZJda4AcaXVwfeuW3qYz2inKaEHm0JaBDt39ZKpUVOzdxPmsdGUnINAig69hIES+dtUskoprRlaboWirm3sfY4IVVM027mEQdk/IIT71byctdW9TjUPdPZ0jvhfUDfvLSaNO2KeI7C0OCtWF2gn4+XGd0ZWdCHNeuVKeSIQXPOb8C2PuiXGUg63k7NRRxFdQGT+/Q9uR4ek4QmLVVE1FsgcghY10/swSUzQ0MSzhMcbOT7fb9RMcNZFag DGD8JThA kfc9RyobGBBX1NUTRtCtbRI0DUZCFBeGWN0jwNdniiSEkQnfdlU2qTi6KNBj76AxAFadmOjVte8F99yTLndYpy5MAwslluurrsl18SwZJSFuTIVan1oQIihLPKpTQCrk6v4mii+oVYZr10LEMGiJ4/O1JNFLcUTpCTyk+n5bYk0p206QZscnsfj8cBCqZD2HS3NReRWCG/fAcOZSHW3OcT7U+btTuOqb4MsfTpAx8sl4DEJnKB7X/V/H1p/+lHrDVLI42u4YiiNXFnaRM6zD9a5EjW3RKe+VHlrcWhnR1mxwLAiVtD/TeF6n3taQfzIPzGJgDoeGDPcq9xD+r/6uF4K5HUH82vUSye7KHQm+pUmTtAWwaopVcqS4ia1QEL2kZe6eK X-Bogosity: Ham, tests=bogofilter, spamicity=0.000000, version=1.2.4 Sender: owner-linux-mm@kvack.org Precedence: bulk X-Loop: owner-majordomo@kvack.org List-ID: The elf-fdpic loader hard sets the process personality to either PER_LINUX_FDPIC for true elf-fdpic binaries or to PER_LINUX for normal ELF binaries (in this case they would be constant displacement compiled with -pie for example). The problem with that is that it will lose any other bits that may be in the ELF header personality (such as the "bug emulation" bits). On the ARM architecture the ADDR_LIMIT_32BIT flag is used to signify a normal 32bit binary - as opposed to a legacy 26bit address binary. This matters since start_thread() will set the ARM CPSR register as required based on this flag. If the elf-fdpic loader loses this bit the process will be mis-configured and crash out pretty quickly. Modify elf-fdpic loader personality setting so that it preserves the upper three bytes by using the SET_PERSONALITY macro to set it. This macro in the generic case sets PER_LINUX and preserves the upper bytes. Architectures can override this for their specific use case, and ARM does exactly this. The problem shows up quite easily running under qemu using the ARM architecture, but not necessarily on all types of real ARM hardware. If the underlying ARM processor does not support the legacy 26-bit addressing mode then everything will work as expected. Signed-off-by: Greg Ungerer --- fs/binfmt_elf_fdpic.c | 5 ++--- 1 file changed, 2 insertions(+), 3 deletions(-) v2: fixes the elf-fdpic binary case as well I have done more extensive testing, and in particular on the true elf-fdpic case. It was broken for that too (as expected). diff --git a/fs/binfmt_elf_fdpic.c b/fs/binfmt_elf_fdpic.c index 43b2a2851ba3..206812ce544a 100644 --- a/fs/binfmt_elf_fdpic.c +++ b/fs/binfmt_elf_fdpic.c @@ -345,10 +345,9 @@ static int load_elf_fdpic_binary(struct linux_binprm *bprm) /* there's now no turning back... the old userspace image is dead, * defunct, deceased, etc. */ + SET_PERSONALITY(exec_params.hdr); if (elf_check_fdpic(&exec_params.hdr)) - set_personality(PER_LINUX_FDPIC); - else - set_personality(PER_LINUX); + current->personality |= PER_LINUX_FDPIC; if (elf_read_implies_exec(&exec_params.hdr, executable_stack)) current->personality |= READ_IMPLIES_EXEC;