From patchwork Sat Nov 13 20:37:29 2021 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: David Malcolm X-Patchwork-Id: 47621 X-Patchwork-Delegate: dmalcolm@redhat.com Return-Path: X-Original-To: patchwork@sourceware.org Delivered-To: patchwork@sourceware.org Received: from server2.sourceware.org (localhost [IPv6:::1]) by sourceware.org (Postfix) with ESMTP id 681293858430 for ; Sat, 13 Nov 2021 20:40:13 +0000 (GMT) DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org 681293858430 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gcc.gnu.org; s=default; t=1636836013; bh=7Jc4vTFEauI0fg4rb+yUh8Oa0FeV0Ap+TCd+JueEUPM=; h=To:Subject:Date:In-Reply-To:References:List-Id:List-Unsubscribe: List-Archive:List-Post:List-Help:List-Subscribe:From:Reply-To: From; b=uKCX+BrOv6H6j+Whw6h7rR/hzU8wlV4QJF8fuD0s3j8hi67gfN1dfMYtoF5jebKlG CJcofbEbOcJM98ZeQOTbOvZpRub/VUImntmCSL+20QqhMbJazCafQCZBKUjO8PGDC9 bB/rNmH2prmj+plyAeAkNKMYWPP+DzKgRYSkZkSI= X-Original-To: gcc-patches@gcc.gnu.org Delivered-To: gcc-patches@gcc.gnu.org Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.133.124]) by sourceware.org (Postfix) with ESMTPS id 24F473858410 for ; Sat, 13 Nov 2021 20:37:47 +0000 (GMT) DMARC-Filter: OpenDMARC Filter v1.4.1 sourceware.org 24F473858410 Received: from mimecast-mx01.redhat.com (mimecast-mx01.redhat.com [209.132.183.4]) (Using TLS) by relay.mimecast.com with ESMTP id us-mta-48-zXbd1EhlNZCIj21MvjUnVw-1; Sat, 13 Nov 2021 15:37:43 -0500 X-MC-Unique: zXbd1EhlNZCIj21MvjUnVw-1 Received: from smtp.corp.redhat.com (int-mx08.intmail.prod.int.phx2.redhat.com [10.5.11.23]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by mimecast-mx01.redhat.com (Postfix) with ESMTPS id D1DF9875048; Sat, 13 Nov 2021 20:37:42 +0000 (UTC) Received: from t14s.localdomain.com (ovpn-113-54.phx2.redhat.com [10.3.113.54]) by smtp.corp.redhat.com (Postfix) with ESMTP id 65D5919D9D; Sat, 13 Nov 2021 20:37:42 +0000 (UTC) To: gcc-patches@gcc.gnu.org, linux-toolchains@vger.kernel.org Subject: [PATCH 4a/6] analyzer: implement region::untrusted_p in terms of custom address spaces Date: Sat, 13 Nov 2021 15:37:29 -0500 Message-Id: <20211113203732.2098220-6-dmalcolm@redhat.com> In-Reply-To: <20211113203732.2098220-1-dmalcolm@redhat.com> References: <20211113203732.2098220-1-dmalcolm@redhat.com> MIME-Version: 1.0 X-Scanned-By: MIMEDefang 2.84 on 10.5.11.23 X-Mimecast-Spam-Score: 0 X-Mimecast-Originator: redhat.com X-Spam-Status: No, score=-13.4 required=5.0 tests=BAYES_00, DKIMWL_WL_HIGH, DKIM_SIGNED, DKIM_VALID, DKIM_VALID_AU, DKIM_VALID_EF, GIT_PATCH_0, RCVD_IN_DNSWL_LOW, RCVD_IN_MSPIKE_H2, SPF_HELO_NONE, SPF_NONE, TXREP autolearn=ham autolearn_force=no version=3.4.4 X-Spam-Checker-Version: SpamAssassin 3.4.4 (2020-01-24) on server2.sourceware.org X-BeenThere: gcc-patches@gcc.gnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: Gcc-patches mailing list List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-Patchwork-Original-From: David Malcolm via Gcc-patches From: David Malcolm Reply-To: David Malcolm Errors-To: gcc-patches-bounces+patchwork=sourceware.org@gcc.gnu.org Sender: "Gcc-patches" gcc/analyzer/ChangeLog: (region::untrusted_p): New. gcc/testsuite/ChangeLog: * gcc.dg/analyzer/test-uaccess.h: New header. Signed-off-by: David Malcolm --- gcc/analyzer/region.cc | 13 +++++++++++++ gcc/testsuite/gcc.dg/analyzer/test-uaccess.h | 19 +++++++++++++++++++ 2 files changed, 32 insertions(+) create mode 100644 gcc/testsuite/gcc.dg/analyzer/test-uaccess.h diff --git a/gcc/analyzer/region.cc b/gcc/analyzer/region.cc index bb4f53b8802..b84504dbe42 100644 --- a/gcc/analyzer/region.cc +++ b/gcc/analyzer/region.cc @@ -666,6 +666,19 @@ region::symbolic_for_unknown_ptr_p () const return false; } +/* Return true if accessing this region crosses a trust boundary + e.g. user-space memory as seen by an OS kernel. */ + +bool +region::untrusted_p () const +{ + addr_space_t as = get_addr_space (); + /* FIXME: treat all non-generic address spaces as untrusted for now. */ + if (!ADDR_SPACE_GENERIC_P (as)) + return true; + return false; +} + /* region's ctor. */ region::region (complexity c, unsigned id, const region *parent, tree type) diff --git a/gcc/testsuite/gcc.dg/analyzer/test-uaccess.h b/gcc/testsuite/gcc.dg/analyzer/test-uaccess.h new file mode 100644 index 00000000000..0500e20b22b --- /dev/null +++ b/gcc/testsuite/gcc.dg/analyzer/test-uaccess.h @@ -0,0 +1,19 @@ +/* Shared header for testcases for copy_from_user/copy_to_user. */ + +/* Adapted from include/linux/compiler.h */ + +#pragma GCC custom_address_space(__user) + +/* Adapted from include/asm-generic/uaccess.h */ + +extern int copy_from_user(void *to, const void __user *from, long n) + __attribute__((access (write_only, 1, 3), + access (read_only, 2, 3), + returns_zero_on_success + )); + +extern long copy_to_user(void __user *to, const void *from, unsigned long n) + __attribute__((access (write_only, 1, 3), + access (read_only, 2, 3), + returns_zero_on_success + ));