royzah opened a new pull request, #20412:
URL: https://github.com/apache/nuttx/pull/20412

   ## Why
   
   In a kernel build a syscall trusts every pointer a process passes. A process 
can hand the kernel a kernel address and have it read out (`write()` from 
kernel memory into a pipe), written to (`ioctl(FIONREAD)` into kernel data), or 
followed through a nested pointer (`writev()`, `sendmsg()`). `BIOC_XIPBASE` and 
`DIOC_GETPRIV` also hand kernel addresses back.
   
   ## How
   
   | Commit | Does |
   | --- | --- |
   | nxstyle | the files below pass the check; no code change |
   | `sched/addrenv` | `uaccess_ok()`, `uaccess_check()` (kills the caller), 
`uaccess_nested()` |
   | arm64, risc-v | refuse a kernel mapping that overlaps the user window, so 
a user address is never also a kernel one |
   | risc-v, x86_64 | `up_addrenv_va_to_pa()`; x86_64 also 
`up_addrenv_user_vaddr()`, which `arch.h` already declares |
   | `syscall` | generated stubs check every pointer argument; iovecs and 
msghdrs are copied in first; `ioctl`, `fcntl`, `boardctl` arguments only the 
kernel can reach get `EFAULT`; user `syslog` is formatted in the caller |
   | `syscall` | `BIOC_XIPBASE`, `DIOC_GETPRIV`, `CAIOC_REGISTERCB` from user 
space get `EPERM` |
   
   Flat and protected builds are unchanged: everything is under 
`CONFIG_BUILD_KERNEL`.
   
   ## Tested
   
   i.MX93, kernel build, a process aiming each call at kernel memory:
   
   | Call | Result |
   | --- | --- |
   | load from kernel, page pool, key storage | process killed |
   | `write()` from kernel memory | process killed |
   | `writev()` with a kernel `iov_base` | process killed |
   | `ioctl(FIONREAD)` into kernel memory | `EFAULT` |
   | `BIOC_XIPBASE`, `DIOC_GETPRIV` | `EPERM`, no pointer returned |
   
   QEMU, the same user process on master and this branch:
   
   | Config | `hello` | `ostest` |
   | --- | --- | --- |
   | `qemu-armv8a:knsh` | pass | `Exiting with status 0` |
   | `rv-virt:knsh64` | pass | log identical to master's |
   | `qemu-intel64:knsh_romfs` | builds and links | master stops at 
`nx_bringup.c:370` in QEMU too, so not compared |
   
   `tools/checkpatch.sh` clean.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to