# git rev-parse -q --verify 7b55851367136b1efd84d98fea81ba57a98304cf^{commit} 7b55851367136b1efd84d98fea81ba57a98304cf already have revision, skipping fetch # git checkout -q -f -B kisskb 7b55851367136b1efd84d98fea81ba57a98304cf # git clean -qxdf # < git log -1 # commit 7b55851367136b1efd84d98fea81ba57a98304cf # Author: David Herrmann # Date: Tue Jan 8 13:58:52 2019 +0100 # # fork: record start_time late # # This changes the fork(2) syscall to record the process start_time after # initializing the basic task structure but still before making the new # process visible to user-space. # # Technically, we could record the start_time anytime during fork(2). But # this might lead to scenarios where a start_time is recorded long before # a process becomes visible to user-space. For instance, with # userfaultfd(2) and TLS, user-space can delay the execution of fork(2) # for an indefinite amount of time (and will, if this causes network # access, or similar). # # By recording the start_time late, it much closer reflects the point in # time where the process becomes live and can be observed by other # processes. # # Lastly, this makes it much harder for user-space to predict and control # the start_time they get assigned. Previously, user-space could fork a # process and stall it in copy_thread_tls() before its pid is allocated, # but after its start_time is recorded. This can be misused to later-on # cycle through PIDs and resume the stalled fork(2) yielding a process # that has the same pid and start_time as a process that existed before. # This can be used to circumvent security systems that identify processes # by their pid+start_time combination. # # Even though user-space was always aware that start_time recording is # flaky (but several projects are known to still rely on start_time-based # identification), changing the start_time to be recorded late will help # mitigate existing attacks and make it much harder for user-space to # control the start_time a process gets assigned. # # Reported-by: Jann Horn # Signed-off-by: Tom Gundersen # Signed-off-by: David Herrmann # Signed-off-by: Linus Torvalds # < /opt/cross/kisskb/br-mipsel-o32-full-2016.08-613-ge98b4dd/bin/mipsel-linux-gcc --version # < /opt/cross/kisskb/br-mipsel-o32-full-2016.08-613-ge98b4dd/bin/mipsel-linux-ld --version # < git log --format=%s --max-count=1 7b55851367136b1efd84d98fea81ba57a98304cf # < make -s -j 8 ARCH=mips O=/kisskb/build/linus_mips-defconfig_mipsel CROSS_COMPILE=/opt/cross/kisskb/br-mipsel-o32-full-2016.08-613-ge98b4dd/bin/mipsel-linux- defconfig # make -s -j 8 ARCH=mips O=/kisskb/build/linus_mips-defconfig_mipsel CROSS_COMPILE=/opt/cross/kisskb/br-mipsel-o32-full-2016.08-613-ge98b4dd/bin/mipsel-linux- /kisskb/src/arch/mips/boot/dts/xilfpga/nexys4ddr.dts:109.16-112.8: Warning (i2c_bus_reg): /i2c@10A00000/ad7420@4B: I2C bus unit address format error, expected "4b" FIT description: Linux 5.0.0-rc1-g7b5585136713 Created: Wed Jan 9 15:43:19 2019 Image 0 (kernel@0) Description: Linux 5.0.0-rc1-g7b5585136713 Created: Wed Jan 9 15:43:19 2019 Type: Kernel Image Compression: gzip compressed Data Size: 4499723 Bytes = 4394.26 KiB = 4.29 MiB Architecture: MIPS OS: Linux Load Address: 0x80100000 Entry Point: 0x808543b0 Hash algo: sha1 Hash value: c538dba72dd663a7d73a9d7e17f306adc4e6cc38 Image 1 (fdt@boston) Description: img,boston Device Tree Created: Wed Jan 9 15:43:19 2019 Type: Flat Device Tree Compression: uncompressed Data Size: 3793 Bytes = 3.70 KiB = 0.00 MiB Architecture: MIPS Hash algo: sha1 Hash value: 4799f50d688573234da6e9d7701234d394759ef4 Image 2 (fdt@ni169445) Description: NI 169445 device tree Created: Wed Jan 9 15:43:19 2019 Type: Flat Device Tree Compression: uncompressed Data Size: 1871 Bytes = 1.83 KiB = 0.00 MiB Architecture: MIPS Hash algo: sha1 Hash value: 51b89b31605ee62038c8468c429af091dfc75ec7 Image 3 (fdt@xilfpga) Description: MIPSfpga (xilfpga) Device Tree Created: Wed Jan 9 15:43:19 2019 Type: Flat Device Tree Compression: uncompressed Data Size: 2708 Bytes = 2.64 KiB = 0.00 MiB Architecture: MIPS Hash algo: sha1 Hash value: 509ce58e44c561d54539e64e9d4b47054e696fc6 Default Configuration: 'conf@default' Configuration 0 (conf@default) Description: Generic Linux kernel Kernel: kernel@0 Configuration 1 (conf@boston) Description: Boston Linux kernel Kernel: kernel@0 FDT: fdt@boston Configuration 2 (conf@ni169445) Description: NI 169445 Linux Kernel Kernel: kernel@0 FDT: fdt@ni169445 Configuration 3 (conf@xilfpga) Description: MIPSfpga Linux kernel Kernel: kernel@0 FDT: fdt@xilfpga Completed OK # rm -rf /kisskb/build/linus_mips-defconfig_mipsel # Build took: 0:02:07.826755