lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Message-ID: <ZR+fcY+W5CBODmfX@gauss3.secunet.de> Date: Fri, 6 Oct 2023 07:47:29 +0200 From: Steffen Klassert <steffen.klassert@...unet.com> To: Kees Cook <keescook@...omium.org> CC: Herbert Xu <herbert@...dor.apana.org.au>, "David S. Miller" <davem@...emloft.net>, <netdev@...r.kernel.org>, "Gustavo A. R. Silva" <gustavoars@...nel.org>, Nathan Chancellor <nathan@...nel.org>, "Nick Desaulniers" <ndesaulniers@...gle.com>, Tom Rix <trix@...hat.com>, <linux-kernel@...r.kernel.org>, <linux-hardening@...r.kernel.org>, <llvm@...ts.linux.dev> Subject: Re: [PATCH] xfrm: Annotate struct xfrm_sec_ctx with __counted_by On Tue, Oct 03, 2023 at 04:18:28PM -0700, Kees Cook wrote: > Prepare for the coming implementation by GCC and Clang of the __counted_by > attribute. Flexible array members annotated with __counted_by can have > their accesses bounds-checked at run-time via CONFIG_UBSAN_BOUNDS (for > array indexing) and CONFIG_FORTIFY_SOURCE (for strcpy/memcpy-family > functions). > > As found with Coccinelle[1], add __counted_by for struct xfrm_sec_ctx. > > Cc: Steffen Klassert <steffen.klassert@...unet.com> > Cc: Herbert Xu <herbert@...dor.apana.org.au> > Cc: "David S. Miller" <davem@...emloft.net> > Cc: netdev@...r.kernel.org > Link: https://github.com/kees/kernel-tools/blob/trunk/coccinelle/examples/counted_by.cocci [1] > Signed-off-by: Kees Cook <keescook@...omium.org> Applied to ipsec-next, thanks!
Powered by blists - more mailing lists