From patchwork Wed Jan 24 15:15:06 2024 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: David Malcolm X-Patchwork-Id: 191613 Return-Path: Delivered-To: ouuuleilei@gmail.com Received: by 2002:a05:7300:2553:b0:103:945f:af90 with SMTP id p19csp1055781dyi; Wed, 24 Jan 2024 07:16:09 -0800 (PST) X-Google-Smtp-Source: AGHT+IEqGuB4+yE/pM8gPB7RrdYMzrOEIC6U1+0ZVVR+8zhKHxERovLoA+xvtLChy82x877SepQE X-Received: by 2002:ac8:7f4d:0:b0:42a:53f4:3198 with SMTP id g13-20020ac87f4d000000b0042a53f43198mr2293917qtk.99.1706109368841; Wed, 24 Jan 2024 07:16:08 -0800 (PST) ARC-Seal: i=2; a=rsa-sha256; t=1706109368; cv=pass; d=google.com; s=arc-20160816; b=Eg6HiCho6JiMXpjm1KfShyOvYjj5f/ismCy4QIBCUVPG+YnJ4sNN9jZj50Zt/Sm0BN s22nj8HFK7Gwu3/aa616DTGQHFQU5LSjO243g4w3SKR4iQvvP+/ELU3Jd5ut+2ISpMxB L2AI+Lp5BEKac/y7WqRQ1QEzR4by33ZInyNIP7VbjxYZoJ3UBJm6BW8pDvWSLGOWhmT4 1/N6CBFVkpIjjfGxnByeRv3stlP6uFzBiUYyFaAmJCrng1v3Cg9S0GFlOgUZHJiUITcZ ixFP6qD7SXIijzOJ0KoLjsFSlcrAgOaBtZVuSBA4f3dwVcAHIvbl+DGRYqgeHyt16wxY 0p/Q== ARC-Message-Signature: i=2; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=errors-to:list-subscribe:list-help:list-post:list-archive :list-unsubscribe:list-id:precedence:content-transfer-encoding :mime-version:message-id:date:subject:cc:to:from:dkim-signature :arc-filter:dmarc-filter:delivered-to; bh=aTL0ub/9BUBG19t19dFVwIqTcgXJoZCYaud3GQnmC18=; fh=NXemEfxTRbZtBxUkxR2ehQUaYlcDfMdzPkO8MChVQE4=; b=Htvqw/5X1VcMNCX5bVuk3DaFcbtJOl1zdrwO3C/W2vrHOJmW/GS9W9WEC7PPblL0ii f43pmwqMF6Bw9fhQDBwNax8qDYaumlO8Za8eiFJRnxxGyiN8LcWD9X7cmzpP9unnsX0T QbMldnfoy5W7kqQIC3gtMdzn3LcFAUnOisDQBFEIOqSkqWhOUcb82zCYUyZQuMzCyTk4 F+TPpwtEVwDZ8BWKF3mRyWrHn08X17uCzU1tqQvqunIyaq+AYp51V+7vJWUZLXsHs3VD HAzVvRCaWlURM80nEXCsud4YN16PJsvedKPxElHuZ7d31LoJOr9F75kRgYbs4553lDly vf8Q== ARC-Authentication-Results: i=2; mx.google.com; dkim=pass header.i=@redhat.com header.s=mimecast20190719 header.b=ShchWlA6; arc=pass (i=1); spf=pass (google.com: domain of gcc-patches-bounces+ouuuleilei=gmail.com@gcc.gnu.org designates 2620:52:3:1:0:246e:9693:128c as permitted sender) smtp.mailfrom="gcc-patches-bounces+ouuuleilei=gmail.com@gcc.gnu.org"; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=redhat.com Received: from server2.sourceware.org (server2.sourceware.org. [2620:52:3:1:0:246e:9693:128c]) by mx.google.com with ESMTPS id u20-20020ac858d4000000b0042a43f454aasi6052156qta.187.2024.01.24.07.16.08 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 24 Jan 2024 07:16:08 -0800 (PST) Received-SPF: pass (google.com: domain of gcc-patches-bounces+ouuuleilei=gmail.com@gcc.gnu.org designates 2620:52:3:1:0:246e:9693:128c as permitted sender) client-ip=2620:52:3:1:0:246e:9693:128c; Authentication-Results: mx.google.com; dkim=pass header.i=@redhat.com header.s=mimecast20190719 header.b=ShchWlA6; arc=pass (i=1); spf=pass (google.com: domain of gcc-patches-bounces+ouuuleilei=gmail.com@gcc.gnu.org designates 2620:52:3:1:0:246e:9693:128c as permitted sender) smtp.mailfrom="gcc-patches-bounces+ouuuleilei=gmail.com@gcc.gnu.org"; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=redhat.com Received: from server2.sourceware.org (localhost [IPv6:::1]) by sourceware.org (Postfix) with ESMTP id 8A8003858008 for ; Wed, 24 Jan 2024 15:16:08 +0000 (GMT) X-Original-To: gcc-patches@gcc.gnu.org Delivered-To: gcc-patches@gcc.gnu.org Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.133.124]) by sourceware.org (Postfix) with ESMTPS id CCEAB3858C66 for ; Wed, 24 Jan 2024 15:15:10 +0000 (GMT) DMARC-Filter: OpenDMARC Filter v1.4.2 sourceware.org CCEAB3858C66 Authentication-Results: sourceware.org; dmarc=pass (p=none dis=none) header.from=redhat.com Authentication-Results: sourceware.org; spf=pass smtp.mailfrom=redhat.com ARC-Filter: OpenARC Filter v1.0.0 sourceware.org CCEAB3858C66 Authentication-Results: server2.sourceware.org; arc=none smtp.remote-ip=170.10.133.124 ARC-Seal: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1706109312; cv=none; b=HCdUhrYVaWQynk54RHCmOMHZgWGnGpVmPGpMR8Z6bBnVH0wgmLPRhdx/S9Aqvf/A5myYpTgDNRUh+uyc3W5OfCMLHIMsGPV1MiIipHAmciOi1TrGIXVUQhksbJIorvuYcuZRCyYVjL84wBoUTzu1mbfVU1CBY6gO5JL30tKCsgE= ARC-Message-Signature: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1706109312; c=relaxed/simple; bh=yAUw1fiwBEpLJv0UCQqr/qypo9mm4jm/1McevUrJCDo=; h=DKIM-Signature:From:To:Subject:Date:Message-Id:MIME-Version; b=T+LY0WtIoLL5FTxjnGG3y2R2rIvg0d6OtvuMERg+jfkQ2+OW203EcLJaRozoxjl/3TgUES/ZieCUef/IMrVAzAAcHDeUY/ac+9vEUdPuP1Y2KDQHleExYHRSRsdrzYol+ab/jz2NV9dOp3xu+WJ/CQAn2AdMyMLAH9AVVYigEZw= ARC-Authentication-Results: i=1; server2.sourceware.org DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1706109310; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=aTL0ub/9BUBG19t19dFVwIqTcgXJoZCYaud3GQnmC18=; b=ShchWlA6cgvuRF49wcTvx2wlfO7kNaDT4X0SoDHGzKmueqFfXg4yZ3cLYhtPtSk50I3/3U wvCbP5rOZFVsb6tl7jDXMXm42lIiCX6x5VrVJXfco91v2DXhzDOtYqANSdIrOyINI18H6L ghA3UsjjO5iVuUdK5edAjC4pw9TPpsA= Received: from mimecast-mx02.redhat.com (mimecast-mx02.redhat.com [66.187.233.88]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-536-rUu_C-aKMH2Vgg8d2TlNDQ-1; Wed, 24 Jan 2024 10:15:08 -0500 X-MC-Unique: rUu_C-aKMH2Vgg8d2TlNDQ-1 Received: from smtp.corp.redhat.com (int-mx07.intmail.prod.int.rdu2.redhat.com [10.11.54.7]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mimecast-mx02.redhat.com (Postfix) with ESMTPS id 94DA0185A785 for ; Wed, 24 Jan 2024 15:15:08 +0000 (UTC) Received: from t14s.localdomain.com (unknown [10.22.32.139]) by smtp.corp.redhat.com (Postfix) with ESMTP id 694C41C060AF; Wed, 24 Jan 2024 15:15:08 +0000 (UTC) From: David Malcolm To: gcc-patches@gcc.gnu.org Cc: David Malcolm Subject: [pushed] analyzer kernel plugin: implement __check_object_size [PR112927] Date: Wed, 24 Jan 2024 10:15:06 -0500 Message-Id: <20240124151506.1538189-1-dmalcolm@redhat.com> MIME-Version: 1.0 X-Scanned-By: MIMEDefang 3.4.1 on 10.11.54.7 X-Mimecast-Spam-Score: 0 X-Mimecast-Originator: redhat.com X-Spam-Status: No, score=-12.2 required=5.0 tests=BAYES_00, DKIMWL_WL_HIGH, DKIM_SIGNED, DKIM_VALID, DKIM_VALID_AU, DKIM_VALID_EF, GIT_PATCH_0, RCVD_IN_DNSWL_NONE, RCVD_IN_MSPIKE_H3, RCVD_IN_MSPIKE_WL, SPF_HELO_NONE, SPF_NONE, TXREP, T_SCC_BODY_TEXT_LINE autolearn=ham autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on server2.sourceware.org X-BeenThere: gcc-patches@gcc.gnu.org X-Mailman-Version: 2.1.30 Precedence: list List-Id: Gcc-patches mailing list List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: gcc-patches-bounces+ouuuleilei=gmail.com@gcc.gnu.org X-getmail-retrieved-from-mailbox: INBOX X-GMAIL-THRID: 1788985337025413021 X-GMAIL-MSGID: 1788985337025413021 PR analyzer/112927 reports a false positive from -Wanalyzer-tainted-size seen on the Linux kernel's drivers/char/ipmi/ipmi_devintf.c with the analyzer kernel plugin. The issue is that in: (A): if (msg->data_len > 272) { return -90; } (B): n = msg->data_len; __check_object_size(to, n); n = copy_from_user(to, from, n); the analyzer is treating __check_object_size as having arbitrary side effects, and, in particular could modify msg->data_len. Hence the sanitization that occurs at (A) above is treated as being for a different value than the size obtained at (B), hence the bogus warning at the call to copy_from_user. Fixed by extending the analyzer kernel plugin to "teach" it that __check_object_size has no side effects. Successfully bootstrapped & regrtested on x86_64-pc-linux-gnu. Successful run of analyzer integration tests on x86_64-pc-linux-gnu. Pushed to trunk as r14-8390-gb6e537571c21d8. gcc/testsuite/ChangeLog: PR analyzer/112927 * gcc.dg/plugin/analyzer_kernel_plugin.c (class known_function___check_object_size): New. (kernel_analyzer_init_cb): Register it. * gcc.dg/plugin/plugin.exp: Add taint-pr112927.c. * gcc.dg/plugin/taint-pr112927.c: New test. Signed-off-by: David Malcolm --- .../gcc.dg/plugin/analyzer_kernel_plugin.c | 18 +++++++ gcc/testsuite/gcc.dg/plugin/plugin.exp | 3 +- gcc/testsuite/gcc.dg/plugin/taint-pr112927.c | 49 +++++++++++++++++++ 3 files changed, 69 insertions(+), 1 deletion(-) create mode 100644 gcc/testsuite/gcc.dg/plugin/taint-pr112927.c diff --git a/gcc/testsuite/gcc.dg/plugin/analyzer_kernel_plugin.c b/gcc/testsuite/gcc.dg/plugin/analyzer_kernel_plugin.c index 02dba7a3234..5a32f8cc620 100644 --- a/gcc/testsuite/gcc.dg/plugin/analyzer_kernel_plugin.c +++ b/gcc/testsuite/gcc.dg/plugin/analyzer_kernel_plugin.c @@ -209,6 +209,22 @@ public: } }; +/* Implementation of "__check_object_size". */ + +class known_function___check_object_size : public known_function +{ + public: + bool matches_call_types_p (const call_details &cd) const final override + { + return cd.num_args () == 2; + } + + void impl_call_pre (const call_details &) const final override + { + /* No-op. */ + } +}; + /* Callback handler for the PLUGIN_ANALYZER_INIT event. */ static void @@ -224,6 +240,8 @@ kernel_analyzer_init_cb (void *gcc_data, void */*user_data*/) make_unique ()); iface->register_known_function ("copy_to_user", make_unique ()); + iface->register_known_function ("__check_object_size", + make_unique ()); } } // namespace ana diff --git a/gcc/testsuite/gcc.dg/plugin/plugin.exp b/gcc/testsuite/gcc.dg/plugin/plugin.exp index b3782f9c575..a5a72daac1a 100644 --- a/gcc/testsuite/gcc.dg/plugin/plugin.exp +++ b/gcc/testsuite/gcc.dg/plugin/plugin.exp @@ -169,7 +169,8 @@ set plugin_test_list [list \ taint-pr112850.c \ taint-pr112850-precise.c \ taint-pr112850-too-complex.c \ - taint-pr112850-unsanitized.c } \ + taint-pr112850-unsanitized.c \ + taint-pr112927.c } \ { analyzer_cpython_plugin.c \ cpython-plugin-test-no-Python-h.c \ cpython-plugin-test-PyList_Append.c \ diff --git a/gcc/testsuite/gcc.dg/plugin/taint-pr112927.c b/gcc/testsuite/gcc.dg/plugin/taint-pr112927.c new file mode 100644 index 00000000000..9c3f7ab6708 --- /dev/null +++ b/gcc/testsuite/gcc.dg/plugin/taint-pr112927.c @@ -0,0 +1,49 @@ +/* Reduced from false positive in Linux kernel + in drivers/char/ipmi/ipmi_devintf.c. */ + +/* { dg-do compile } */ +/* { dg-options "-fanalyzer -O2 -Wno-attributes" } */ +/* { dg-require-effective-target analyzer } */ + +typedef __SIZE_TYPE__ size_t; +extern void +__check_object_size(const void* ptr, unsigned long n); + +extern unsigned long +copy_from_user(void*, const void*, unsigned long); + +__attribute__((__always_inline__)) unsigned long +call_copy_from_user(void* to, const void* from, unsigned long n) +{ + __check_object_size(to, n); + n = copy_from_user(to, from, n); /* { dg-bogus "use of attacker-controlled value as size without upper-bounds checking" } */ + return n; +} +struct ipmi_msg +{ + unsigned short data_len; + unsigned char* data; +}; + +static int +handle_send_req(struct ipmi_msg* msg) +{ + char buf[273]; + if (msg->data_len > 272) { + return -90; + } + if (call_copy_from_user(buf, msg->data, msg->data_len)) { + return -14; + } + return 0; +} +long +ipmi_ioctl(void* arg) +{ + struct ipmi_msg msg; + if (call_copy_from_user(&msg, arg, sizeof(msg))) { + return -14; + } + + return handle_send_req(&msg); +}