NetBSD Problem Report #45312
From www@NetBSD.org Tue Aug 30 01:37:10 2011
Return-Path: <www@NetBSD.org>
Received: from mail.netbsd.org (mail.netbsd.org [204.152.190.11])
by www.NetBSD.org (Postfix) with ESMTP id DAFA363C780
for <gnats-bugs@gnats.NetBSD.org>; Tue, 30 Aug 2011 01:37:09 +0000 (UTC)
Message-Id: <20110830013709.2CEFA63C0E2@www.NetBSD.org>
Date: Tue, 30 Aug 2011 01:37:09 +0000 (UTC)
From: jmcneill@invisible.ca
Reply-To: jmcneill@invisible.ca
To: gnats-bugs@NetBSD.org
Subject: ptrace: PT_SETREGS can't alter system calls
X-Send-Pr-Version: www-1.0
>Number: 45312
>Category: kern
>Synopsis: ptrace: PT_SETREGS can't alter system calls
>Confidential: no
>Severity: non-critical
>Priority: medium
>Responsible: kern-bug-people
>State: closed
>Class: sw-bug
>Submitter-Id: net
>Arrival-Date: Tue Aug 30 01:40:01 +0000 2011
>Closed-Date: Sun Jun 17 19:45:45 +0000 2012
>Last-Modified: Sun Jun 17 19:45:45 +0000 2012
>Originator: Jared McNeill
>Release: 5.1_STABLE
>Organization:
>Environment:
NetBSD ironhide 5.1_STABLE NetBSD 5.1_STABLE (GENERIC) #0: Mon Aug 29 14:18:51 EDT 2011 jmcneill@ramjet.invisible.ca:/home/jmcneill/branches/netbsd-5/src/sys/arch/i386/compile/obj/GENERIC i386
>Description:
It's not possible using a combination of PT_SYSCALL / PT_GETREGS / PT_SETREGS to catch and modify a system call. Try capturing a syscall, change the syscall number (f.e. "regs.r_eax = SYS_getpid" on i386) and see that the original syscall isn't intercepted.
It looks like the same issue was present in FreeBSD. Here's the relevent problem report:
http://www.freebsd.org/cgi/query-pr.cgi?pr=142958&cat=
The test case in that bug report reproduces the problem on NetBSD also.
>How-To-Repeat:
$ ftp http://alip.github.com/code/ptrace-freebsd-deny.c
$ cc ptrace-freebsd-deny.c
$ ./a.out
sorry, pid 2900 was killed: orphaned traced process
$ ls -l foo.bar
--wsr----- 1 jmcneill users 0 Aug 29 21:36 foo.bar
This file shouldn't have been created.
>Fix:
>Release-Note:
>Audit-Trail:
From: "Jared D. McNeill" <jmcneill@netbsd.org>
To: gnats-bugs@gnats.NetBSD.org
Cc:
Subject: PR/45312 CVS commit: src/sys
Date: Wed, 31 Aug 2011 22:58:39 +0000
Module Name: src
Committed By: jmcneill
Date: Wed Aug 31 22:58:39 UTC 2011
Modified Files:
src/sys/kern: kern_subr.c sys_process.c
src/sys/sys: proc.h ptrace.h
Log Message:
PR# kern/45312: ptrace: PT_SETREGS can't alter system calls
Add a new PT_SYSCALLEMU request that cancels the current syscall, for
use with PT_SYSCALL.
To generate a diff of this commit:
cvs rdiff -u -r1.209 -r1.210 src/sys/kern/kern_subr.c
cvs rdiff -u -r1.159 -r1.160 src/sys/kern/sys_process.c
cvs rdiff -u -r1.308 -r1.309 src/sys/sys/proc.h
cvs rdiff -u -r1.42 -r1.43 src/sys/sys/ptrace.h
Please note that diffs are not public domain; they are subject to the
copyright notices on the relevant files.
State-Changed-From-To: open->pending-pullups
State-Changed-By: dholland@NetBSD.org
State-Changed-When: Sat, 05 Nov 2011 16:32:08 +0000
State-Changed-Why:
this is or should be part of pullup-5 #1668
From: "Manuel Bouyer" <bouyer@netbsd.org>
To: gnats-bugs@gnats.NetBSD.org
Cc:
Subject: PR/45312 CVS commit: [netbsd-5] src/sys
Date: Sat, 4 Feb 2012 16:58:00 +0000
Module Name: src
Committed By: bouyer
Date: Sat Feb 4 16:58:00 UTC 2012
Modified Files:
src/sys/arch/amd64/amd64 [netbsd-5]: syscall.c
src/sys/arch/i386/i386 [netbsd-5]: syscall.c trap.c
src/sys/kern [netbsd-5]: kern_sig.c kern_sleepq.c kern_subr.c
sys_process.c
src/sys/secmodel/bsd44 [netbsd-5]: secmodel_bsd44_suser.c
src/sys/sys [netbsd-5]: proc.h ptrace.h
Log Message:
Apply patch, requested by jmcneill in ticket #1668:
sys/arch/amd64/amd64/syscall.c patch
sys/arch/i386/i386/syscall.c patch
sys/arch/i386/i386/trap.c patch
sys/kern/kern_sig.c patch
sys/kern/kern_sleepq.c patch
sys/kern/kern_subr.c patch
sys/kern/sys_process.c patch
sys/secmodel/bsd44/secmodel_bsd44_suser.c patch
sys/sys/proc.h patch
sys/sys/ptrace.h patch
arch/i386/i386/machdep.c, arch/amd64/amd64/machdep.c (from
arch/x86/x86/machdep.c) by christos:
Remove code that was used to avoid register spills. setcontext(2) can change
the registers, so re-fetching will produce the wrong result for trace_exit().
arch/i386/i386/trap.c by reinoud:
Fix the illegal instruction return address. It was using the value of the
cpu's %cr2 register but thats not valid:
CR2 Contains a value called Page Fault Linear Address (PFLA). When a page
fault occurs, the address the program attempted to access is stored in the CR2
register.
And this is thus NOT the illegal instruction address!
kern/kern_sig.c by christos:
PR kern/45327: Jared McNeill: ptrace: siginfo doesn't work with traced processes
When saving the signal in p->p_xstat, clear it from the pending mask, but
don't remove it from the siginfo queue, so that next time the debugger
delivers it, the original information is found.
When posting a signal from the debugger l->l_sigpendset is not set, so we
use the process pending signal and add it back to the process pending set.
Split sigget into sigget() and siggetinfo(). When a signal comes from the
debugger (l->l_sigpendset == NULL), using siggetinfo() try to fetch the
siginfo information from l->l_sigpend and then from p->p_sigpend if it
was not found. This allows us to pass siginfo information for traps from
the debugger.
don't delete signal from the debugger.
kern/kern_sleepq.c by christos:
PR kern/40594: Antti Kantee: Don't call issignal() here to determine what errno
to set for the interrupted syscall, because issignal() will consume the signal
and it will not be delivered to the process afterwards. Instead call
sigispending() (which now returns the first pending signal) and does not
consume the signal.
We need to process SA_STOP signals immediately, and not deliver them to
the process. Instead of re-structuring the code to do that, call issignal()
like before in that case. (tail -F /file^Zfg should not get interrupted).
kern/kern_subr.c by jmcneill, christos:
PR kern/45312: ptrace: PT_SETREGS can't alter system calls
Add a new PT_SYSCALLEMU request that cancels the current syscall, for
use with PT_SYSCALL.
For PT_SYSCALLEMU, no need to stop again on syscall exit.
ifdef unused variable with -UPTRACE
kern/sys_process.c, sys/proc.h, sys/ptrace.h, secmodel/bsd44/secmodel_bsd44_suser.c by jmcneill, christos:
PR kern/43681: PT_SYSCALL appears to be broken
sys_ptrace: For PT_CONTINUE/PT_SYSCALL/PT_DETACH, modify the p_trace_enabled
flag of the target process, not the calling process.
Process the signal now, otherwise calling issignal() and ignoring
the return will lose the signal if it came from the debugger
(issignal() clears p->p_xstat)
PR kern/45312: ptrace: PT_SETREGS can't alter system calls
Add a new PT_SYSCALLEMU request that cancels the current syscall, for
use with PT_SYSCALL.
PR kern/45330: ptrace: signals can alter syscall return values
process_stoptrace: defer signal processing to userret, ok christos@
To generate a diff of this commit:
cvs rdiff -u -r1.44 -r1.44.4.1 src/sys/arch/amd64/amd64/syscall.c
cvs rdiff -u -r1.57 -r1.57.4.1 src/sys/arch/i386/i386/syscall.c
cvs rdiff -u -r1.241.4.3 -r1.241.4.4 src/sys/arch/i386/i386/trap.c
cvs rdiff -u -r1.289.4.6 -r1.289.4.7 src/sys/kern/kern_sig.c
cvs rdiff -u -r1.35 -r1.35.4.1 src/sys/kern/kern_sleepq.c
cvs rdiff -u -r1.192.4.1 -r1.192.4.2 src/sys/kern/kern_subr.c
cvs rdiff -u -r1.143.4.1 -r1.143.4.2 src/sys/kern/sys_process.c
cvs rdiff -u -r1.59 -r1.59.4.1 src/sys/secmodel/bsd44/secmodel_bsd44_suser.c
cvs rdiff -u -r1.282 -r1.282.4.1 src/sys/sys/proc.h
cvs rdiff -u -r1.40 -r1.40.20.1 src/sys/sys/ptrace.h
Please note that diffs are not public domain; they are subject to the
copyright notices on the relevant files.
State-Changed-From-To: pending-pullups->closed
State-Changed-By: dholland@NetBSD.org
State-Changed-When: Sun, 17 Jun 2012 19:45:45 +0000
State-Changed-Why:
pullup was done in february and I've been behind on cleaning up
>Unformatted:
(Contact us)
$NetBSD: query-full-pr,v 1.39 2013/11/01 18:47:49 spz Exp $
$NetBSD: gnats_config.sh,v 1.8 2006/05/07 09:23:38 tsutsui Exp $
Copyright © 1994-2007
The NetBSD Foundation, Inc. ALL RIGHTS RESERVED.