Received: by 2002:a05:6a10:16a7:0:0:0:0 with SMTP id gp39csp1365831pxb; Fri, 20 Nov 2020 07:50:57 -0800 (PST) X-Google-Smtp-Source: ABdhPJybxv+codtcYfOOaJsOaxlTHcruo5XaeYXNjbBrmrDG6xtweFSgBFBfNQdJTBCv725A8JGv X-Received: by 2002:aa7:d286:: with SMTP id w6mr10203612edq.93.1605887456981; Fri, 20 Nov 2020 07:50:56 -0800 (PST) ARC-Seal: i=1; a=rsa-sha256; t=1605887456; cv=none; d=google.com; s=arc-20160816; b=BuA714/E5Q0TG0x+TcWyQLYEMF/eLrrnR0FL4ZT5KY2/JfUQjUZ3DahhkuNdnIhKd/ Yzcrb0pr87eAfHqPCeWfjQ3++HQoanPHAMEcEMrHUG8voXJudfI9w0lWiUgDwxCs/8m+ N2oDoT6G3a47mHyD6QYqVu+vnkbdVsGiVMYRGbtUggdjBLx8XkJMLi2XC77itD2Ynr1z y/LOPtNthhc/g05qXWCAJ5Grln7ZmFWMNnjc6hIbM5McsWHQGysrdpdjQBJNEQf5Kmr1 6wpfFNkTNPrT5fnkh2h4T6XtsMP7tGXD4RkWVSuWOXQnn5Bwv4LacdAFqqnVqQrMjmSE TQwQ== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:cc:to:subject:message-id:date:from:in-reply-to :references:mime-version:dkim-signature; bh=Yps1e5KzrIWuWLTz7SlzGPsEJ9zx8qv8vtiS4Y+fzRs=; b=mjFWcXNEgqx3Y0CP/qpI3xmdJWh1XvlHGf9YWtx6ViWzv3YWoQLw1QpkhPdAlZlw75 SNIHNkNICwfYde9cK7P2ppFNJJPZVhHuurAjnW6zw1XGJbUw4sQaQn8K8v4T+002g9uu t+rsB8Wl+kTNvDR1XSftOxOMvamDrJRq+85tAZZZO8+gHKvmIaaqMNVIPOAqBt8zsjBb FY6yxZc3w/QcyyHYiP6fa/B+j1+zhZRfYz1BeMoCnlc+/jHnGWVhU2/7O0c8pEu3hA0w ostnizXO6ZBguCyKYwj8qPFBQq6ac4YuJX6ChVtbjKM2bH2SheHxhinj8wcxik4bvQBr udeg== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@google.com header.s=20161025 header.b=rCTDRbJf; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=google.com Return-Path: Received: from vger.kernel.org (vger.kernel.org. [23.128.96.18]) by mx.google.com with ESMTP id y1si1859350edm.279.2020.11.20.07.50.33; Fri, 20 Nov 2020 07:50:56 -0800 (PST) Received-SPF: pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) client-ip=23.128.96.18; Authentication-Results: mx.google.com; dkim=pass header.i=@google.com header.s=20161025 header.b=rCTDRbJf; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=google.com Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1728334AbgKTPqP (ORCPT + 99 others); Fri, 20 Nov 2020 10:46:15 -0500 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:44204 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1728234AbgKTPqO (ORCPT ); Fri, 20 Nov 2020 10:46:14 -0500 Received: from mail-lf1-x143.google.com (mail-lf1-x143.google.com [IPv6:2a00:1450:4864:20::143]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id 710E4C0613CF for ; Fri, 20 Nov 2020 07:46:14 -0800 (PST) Received: by mail-lf1-x143.google.com with SMTP id j205so14063651lfj.6 for ; Fri, 20 Nov 2020 07:46:14 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20161025; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=Yps1e5KzrIWuWLTz7SlzGPsEJ9zx8qv8vtiS4Y+fzRs=; b=rCTDRbJfZOnUWWo5y33U/5YZehyzFwE68YkK2VrRXJBFoHAjkpD+g/l4cHSC7NeZZ+ 0YdW7KZNJiLLSMjnhI/QJa+HnUTyqF4HibOUOLQpcAj9pY4vYWR5nKmFdyqx7U2ZiFbr +zpxSQ68zHlODo2Nqu/+4QkqHkHRvflqrzcniIdhcfbfrTtBZOaQttJu36xcRZxKnEK0 o8CZtUmcjVvZU0gNLITvw/RemOvT7mRKtsR1dbgulsKKC5NM7TiG2d0EvnZUByN3cVDV 6EjCnzhFD5ao5TOIXEIc6sHCkGfCLDbvnK+CQgFZEcL+em1/BlARllGspl6BLvu84RCJ K0sw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=Yps1e5KzrIWuWLTz7SlzGPsEJ9zx8qv8vtiS4Y+fzRs=; b=DDYw60QIxy9qI8N124wktGXpv77ToF090SxoR58l4u2SUWLZFzEGB6QpJGRU5IHNo7 396vhZJ2K3545WNKieecr1oAwiC4YWjiDYQuAb6uq602Bz9BkGQn83hmhezFA4CF9ZkS 6nmtb1wr6wlCqSNBsFeJBBil+t4xBGTTVnwMaxnyr4q3gI0gs9OWp6KUSTMnMwhWsksR sfkysfdDBm9akCT/nFtJgyVXTPGyMTQQGjvTSCr84+HKYo6lOVgBSCJ8uDCtpliaoC7c HNe0LNihAyEp33fBjb8Cd3pX4C93R/Jx1toketp1N2YwKufgDqjdibX1JFj1+evPzs2W ptjg== X-Gm-Message-State: AOAM530+7AwkWw8j/k7IHSY47Qo7pvOgNIMHBdDyWx9SFkXuwLDtjWNw /+jNsk4/WF1zv65u6dZhFVam62kRjBfcTk5ZVVnIZQ== X-Received: by 2002:a19:686:: with SMTP id 128mr7865344lfg.198.1605887172681; Fri, 20 Nov 2020 07:46:12 -0800 (PST) MIME-Version: 1.0 References: <20201120015913.1375667-1-jannh@google.com> <20201120153559.GA4119@sequoia> In-Reply-To: <20201120153559.GA4119@sequoia> From: Jann Horn Date: Fri, 20 Nov 2020 16:45:46 +0100 Message-ID: Subject: Re: [PATCH] seccomp: Remove bogus __user annotations To: Tyler Hicks Cc: Kees Cook , Andy Lutomirski , Will Drewry , kernel list Content-Type: text/plain; charset="UTF-8" Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org On Fri, Nov 20, 2020 at 4:36 PM Tyler Hicks wrote: > Hey Jann - Thanks for cleaning this up! > > On 2020-11-20 02:59:13, Jann Horn wrote: > > Buffers that are passed to read_actions_logged() and write_actions_logged() > > are in kernel memory; the sysctl core takes care of copying from/to > > userspace. > > > > Fixes: 0ddec0fc8900 ("seccomp: Sysctl to configure actions that are allowed to be logged") > > After tracing back through the code, I was struggling to understand why > I thought the __user annotation was needed back then. It turns out that > __user was correct when I wrote 0ddec0fc8900 and that the Fixes tag > should be changed to this: > > Fixes: 32927393dc1c ("sysctl: pass kernel pointers to ->proc_handler") > > If you agree, please adjust and resubmit with: > > Reviewed-by: Tyler Hicks > > Thank you! Aaaah, that makes sense. Thanks, will do.