Shashiko correctly pointed out this fork bug, the report is below. This
patch fixes it by checking for the child and error conditions
explicitly.
[ ... ]
> +int test_ptrace(void)
> +{
> + unsigned long saved_ssp, ssp = 0;
> + struct sigaction sa = {};
> + struct iovec iov;
> + int status;
> + int pid;
> +
> + iov.iov_base = &ssp;
> + iov.iov_len = sizeof(ssp);
> +
> + pid = fork();
> + if (!pid) {
[Severity: High]
This is a pre-existing issue, but could this code broadcast SIGKILL to
all user processes if fork() fails?
If fork() returns -1 due to resource limits, execution will proceed with
pid = -1. When ptrace() subsequently fails, the error path is triggered:
out_kill:
kill(pid, SIGKILL);
return 1;
Since pid is -1, POSIX specifies that this will kill all processes the
current user has permission to terminate, potentially crashing the host
environment.
Signed-off-by: Bill Roberts <[email protected]>
---
tools/testing/selftests/x86/test_shadow_stack.c | 5 +++++
1 file changed, 5 insertions(+)
diff --git a/tools/testing/selftests/x86/test_shadow_stack.c
b/tools/testing/selftests/x86/test_shadow_stack.c
index 3d6ca33edba4..b52c5420c137 100644
--- a/tools/testing/selftests/x86/test_shadow_stack.c
+++ b/tools/testing/selftests/x86/test_shadow_stack.c
@@ -971,6 +971,11 @@ int test_ptrace(void)
iov.iov_len = sizeof(ssp);
pid = fork();
+ if (pid < 0) {
+ printf("[FAIL]\tFork failed for %s\n", __func__);
+ return 1;
+ }
+
if (!pid) {
ssp = get_ssp();
--
2.55.0