diff mbox series

lkdtm/bugs: Don't expect thread termination without CONFIG_UBSAN_TRAP

Message ID 7c2d2a48034223a95cf4346c5a2255a0b9b25670.1649688637.git.christophe.leroy@csgroup.eu (mailing list archive)
State New
Headers show
Series lkdtm/bugs: Don't expect thread termination without CONFIG_UBSAN_TRAP | expand

Commit Message

Christophe Leroy April 11, 2022, 2:56 p.m. UTC
When you don't select CONFIG_UBSAN_TRAP, you get:

  # echo ARRAY_BOUNDS > /sys/kernel/debug/provoke-crash/DIRECT
[  102.265827] ================================================================================
[  102.278433] UBSAN: array-index-out-of-bounds in drivers/misc/lkdtm/bugs.c:342:16
[  102.287207] index 8 is out of range for type 'char [8]'
[  102.298722] ================================================================================
[  102.313712] lkdtm: FAIL: survived array bounds overflow!
[  102.318770] lkdtm: Unexpected! This kernel (5.16.0-rc1-s3k-dev-01884-g720dcf79314a ppc) was built with CONFIG_UBSAN_BOUNDS=y

It is not correct because when CONFIG_UBSAN_TRAP is not selected
you can't expect array bounds overflow to kill the thread.

Modify the logic so that when the kernel is built with
CONFIG_UBSAN_BOUNDS but without CONFIG_UBSAN_TRAP, you get a warning
about CONFIG_UBSAN_TRAP not been selected instead.

Fixes: c75be56e35b2 ("lkdtm/bugs: Add ARRAY_BOUNDS to selftests")
Signed-off-by: Christophe Leroy <christophe.leroy@csgroup.eu>
---
 drivers/misc/lkdtm/bugs.c | 5 ++++-
 1 file changed, 4 insertions(+), 1 deletion(-)

Comments

kernel test robot April 11, 2022, 5:53 p.m. UTC | #1
Hi Christophe,

I love your patch! Yet something to improve:

[auto build test ERROR on char-misc/char-misc-testing]
[also build test ERROR on kees/for-next/pstore soc/for-next linus/master v5.18-rc2 next-20220411]
[If your patch is applied to the wrong git tree, kindly drop us a note.
And when submitting patch, we suggest to use '--base' as documented in
https://git-scm.com/docs/git-format-patch]

url:    https://github.com/intel-lab-lkp/linux/commits/Christophe-Leroy/lkdtm-bugs-Don-t-expect-thread-termination-without-CONFIG_UBSAN_TRAP/20220411-225758
base:   https://git.kernel.org/pub/scm/linux/kernel/git/gregkh/char-misc.git 3123109284176b1532874591f7c81f3837bbdc17
config: microblaze-buildonly-randconfig-r002-20220411 (https://download.01.org/0day-ci/archive/20220412/202204120139.6efSg72F-lkp@intel.com/config)
compiler: microblaze-linux-gcc (GCC) 11.2.0
reproduce (this is a W=1 build):
        wget https://raw.githubusercontent.com/intel/lkp-tests/master/sbin/make.cross -O ~/bin/make.cross
        chmod +x ~/bin/make.cross
        # https://github.com/intel-lab-lkp/linux/commit/50ed7d4c37c2080e281638b783a912193a02eed9
        git remote add linux-review https://github.com/intel-lab-lkp/linux
        git fetch --no-tags linux-review Christophe-Leroy/lkdtm-bugs-Don-t-expect-thread-termination-without-CONFIG_UBSAN_TRAP/20220411-225758
        git checkout 50ed7d4c37c2080e281638b783a912193a02eed9
        # save the config file to linux build tree
        mkdir build_dir
        COMPILER_INSTALL_PATH=$HOME/0day COMPILER=gcc-11.2.0 make.cross O=build_dir ARCH=microblaze SHELL=/bin/bash drivers/misc/lkdtm/

If you fix the issue, kindly add following tag as appropriate
Reported-by: kernel test robot <lkp@intel.com>

All errors (new ones prefixed by >>):

   drivers/misc/lkdtm/bugs.c: In function 'lkdtm_ARRAY_BOUNDS':
>> drivers/misc/lkdtm/bugs.c:351:9: error: 'else' without a previous 'if'
     351 |         else
         |         ^~~~


vim +351 drivers/misc/lkdtm/bugs.c

   321	
   322	void lkdtm_ARRAY_BOUNDS(void)
   323	{
   324		struct array_bounds_flex_array *not_checked;
   325		struct array_bounds *checked;
   326		volatile int i;
   327	
   328		not_checked = kmalloc(sizeof(*not_checked) * 2, GFP_KERNEL);
   329		checked = kmalloc(sizeof(*checked) * 2, GFP_KERNEL);
   330	
   331		pr_info("Array access within bounds ...\n");
   332		/* For both, touch all bytes in the actual member size. */
   333		for (i = 0; i < sizeof(checked->data); i++)
   334			checked->data[i] = 'A';
   335		/*
   336		 * For the uninstrumented flex array member, also touch 1 byte
   337		 * beyond to verify it is correctly uninstrumented.
   338		 */
   339		for (i = 0; i < sizeof(not_checked->data) + 1; i++)
   340			not_checked->data[i] = 'A';
   341	
   342		pr_info("Array access beyond bounds ...\n");
   343		for (i = 0; i < sizeof(checked->data) + 1; i++)
   344			checked->data[i] = 'B';
   345	
   346		kfree(not_checked);
   347		kfree(checked);
   348		pr_err("FAIL: survived array bounds overflow!\n");
   349		if (IS_ENABLED(CONFIG_UBSAN_BOUNDS))
   350			pr_expected_config(CONFIG_UBSAN_TRAP);
 > 351		else
   352			pr_expected_config(CONFIG_UBSAN_BOUNDS);
   353	}
   354
diff mbox series

Patch

diff --git a/drivers/misc/lkdtm/bugs.c b/drivers/misc/lkdtm/bugs.c
index f21854ac5cc2..0f4dd9621b75 100644
--- a/drivers/misc/lkdtm/bugs.c
+++ b/drivers/misc/lkdtm/bugs.c
@@ -346,7 +346,10 @@  void lkdtm_ARRAY_BOUNDS(void)
 	kfree(not_checked);
 	kfree(checked);
 	pr_err("FAIL: survived array bounds overflow!\n");
-	pr_expected_config(CONFIG_UBSAN_BOUNDS);
+	if (IS_ENABLED(CONFIG_UBSAN_BOUNDS))
+		pr_expected_config(CONFIG_UBSAN_TRAP);
+	else
+		pr_expected_config(CONFIG_UBSAN_BOUNDS);
 }
 
 void lkdtm_CORRUPT_LIST_ADD(void)