# git rev-parse -q --verify 21d4120ec6f5b5992b01b96ac484701163917b63^{commit} 21d4120ec6f5b5992b01b96ac484701163917b63 already have revision, skipping fetch # git checkout -q -f -B kisskb 21d4120ec6f5b5992b01b96ac484701163917b63 # git clean -qxdf # < git log -1 # commit 21d4120ec6f5b5992b01b96ac484701163917b63 # Author: Eric Biggers # Date: Tue Jul 2 14:17:00 2019 -0700 # # crypto: user - prevent operating on larval algorithms # # Michal Suchanek reported [1] that running the pcrypt_aead01 test from # LTP [2] in a loop and holding Ctrl-C causes a NULL dereference of # alg->cra_users.next in crypto_remove_spawns(), via crypto_del_alg(). # The test repeatedly uses CRYPTO_MSG_NEWALG and CRYPTO_MSG_DELALG. # # The crash occurs when the instance that CRYPTO_MSG_DELALG is trying to # unregister isn't a real registered algorithm, but rather is a "test # larval", which is a special "algorithm" added to the algorithms list # while the real algorithm is still being tested. Larvals don't have # initialized cra_users, so that causes the crash. Normally pcrypt_aead01 # doesn't trigger this because CRYPTO_MSG_NEWALG waits for the algorithm # to be tested; however, CRYPTO_MSG_NEWALG returns early when interrupted. # # Everything else in the "crypto user configuration" API has this same bug # too, i.e. it inappropriately allows operating on larval algorithms # (though it doesn't look like the other cases can cause a crash). # # Fix this by making crypto_alg_match() exclude larval algorithms. # # [1] https://lkml.kernel.org/r/20190625071624.27039-1-msuchanek@suse.de # [2] https://github.com/linux-test-project/ltp/blob/20190517/testcases/kernel/crypto/pcrypt_aead01.c # # Reported-by: Michal Suchanek # Fixes: a38f7907b926 ("crypto: Add userspace configuration API") # Cc: # v3.2+ # Cc: Steffen Klassert # Signed-off-by: Eric Biggers # Signed-off-by: Herbert Xu # < /opt/cross/kisskb/gcc-4.6.3-nolibc/powerpc-linux/bin/powerpc-linux-gcc --version # < /opt/cross/kisskb/gcc-4.6.3-nolibc/powerpc-linux/bin/powerpc-linux-ld --version # < git log --format=%s --max-count=1 21d4120ec6f5b5992b01b96ac484701163917b63 # < make -s -j 48 ARCH=powerpc O=/kisskb/build/crypto_ppc64e_defconfig_powerpc-gcc4.6 CROSS_COMPILE=/opt/cross/kisskb/gcc-4.6.3-nolibc/powerpc-linux/bin/powerpc-linux- ppc64e_defconfig # make -s -j 48 ARCH=powerpc O=/kisskb/build/crypto_ppc64e_defconfig_powerpc-gcc4.6 CROSS_COMPILE=/opt/cross/kisskb/gcc-4.6.3-nolibc/powerpc-linux/bin/powerpc-linux- :1478:2: warning: #warning syscall pidfd_send_signal not implemented [-Wcpp] :1481:2: warning: #warning syscall io_uring_setup not implemented [-Wcpp] :1484:2: warning: #warning syscall io_uring_enter not implemented [-Wcpp] :1487:2: warning: #warning syscall io_uring_register not implemented [-Wcpp] /kisskb/src/kernel/printk/printk.c: In function 'devkmsg_sysctl_set_loglvl': /kisskb/src/kernel/printk/printk.c:187:16: warning: 'old' may be used uninitialized in this function [-Wuninitialized] /kisskb/src/kernel/trace/trace_dynevent.c: In function 'create_dyn_event': /kisskb/src/kernel/trace/trace_dynevent.c:89:5: warning: 'ret' may be used uninitialized in this function [-Wuninitialized] /kisskb/src/fs/proc/inode.c: In function 'proc_reg_open': /kisskb/src/include/linux/list.h:65:12: warning: 'pdeo' may be used uninitialized in this function [-Wuninitialized] /kisskb/src/fs/proc/inode.c:337:21: note: 'pdeo' was declared here /kisskb/src/fs/nfsd/nfs4xdr.c: In function 'nfsd4_encode_components_esc': /kisskb/src/fs/nfsd/nfs4xdr.c:2076:9: warning: 'str' may be used uninitialized in this function [-Wuninitialized] /kisskb/src/net/bridge/br_netlink.c: In function 'br_afspec.isra.28': /kisskb/src/net/bridge/br_netlink.c:652:7: warning: 'err' may be used uninitialized in this function [-Wuninitialized] /kisskb/src/fs/udf/unicode.c: In function 'udf_name_conv_char': /kisskb/src/fs/udf/unicode.c:132:8: warning: 'c' may be used uninitialized in this function [-Wuninitialized] /kisskb/src/drivers/tty/serial/8250/8250_core.c: In function 'univ8250_release_irq': /kisskb/src/drivers/tty/serial/8250/8250_core.c:247:18: warning: 'i' may be used uninitialized in this function [-Wuninitialized] /kisskb/src/drivers/tty/serial/8250/8250_core.c:227:19: note: 'i' was declared here /kisskb/src/drivers/net/tun.c: In function 'tun_get_user': /kisskb/src/drivers/net/tun.c:1845:30: warning: 'copylen' may be used uninitialized in this function [-Wuninitialized] /kisskb/src/drivers/net/tun.c:1755:46: warning: 'linear' may be used uninitialized in this function [-Wuninitialized] /kisskb/src/net/sunrpc/xprtsock.c: In function 'xs_read_stream.constprop.18': /kisskb/src/net/sunrpc/xprtsock.c:529:2: warning: 'read' may be used uninitialized in this function [-Wuninitialized] /kisskb/src/net/sunrpc/xprtsock.c:498:15: note: 'read' was declared here /kisskb/src/net/sunrpc/xprtsock.c:529:2: warning: 'ret' may be used uninitialized in this function [-Wuninitialized] /kisskb/src/net/sunrpc/xprtsock.c:499:10: note: 'ret' was declared here /kisskb/src/net/netfilter/nf_nat_masquerade.c:15:21: warning: 'masq_refcnt6' defined but not used [-Wunused-variable] WARNING: vmlinux.o (.PPC.EMB.apuinfo): unexpected non-allocatable section. Did you forget to use "ax"/"aw" in a .S file? Note that for example contains section definitions for use in .S files. INFO: Uncompressed kernel (size 0xc5eba8) overlaps the address of the wrapper(0x400000) INFO: Fixing the link_address of wrapper to (0xd00000) Image Name: Linux-5.1.0-rc1-g21d4120ec6f5 Created: Thu Jul 4 01:02:56 2019 Image Type: PowerPC Linux Kernel Image (gzip compressed) Data Size: 5282409 Bytes = 5158.60 KiB = 5.04 MiB Load Address: 00000000 Entry Point: 00000000 Completed OK # rm -rf /kisskb/build/crypto_ppc64e_defconfig_powerpc-gcc4.6 # Build took: 0:01:32.570696