Linus Torvalds
050e9baa9d
Kbuild: rename CC_STACKPROTECTOR[_STRONG] config variables
...
The changes to automatically test for working stack protector compiler
support in the Kconfig files removed the special STACKPROTECTOR_AUTO
option that picked the strongest stack protector that the compiler
supported.
That was all a nice cleanup - it makes no sense to have the AUTO case
now that the Kconfig phase can just determine the compiler support
directly.
HOWEVER.
It also meant that doing "make oldconfig" would now _disable_ the strong
stackprotector if you had AUTO enabled, because in a legacy config file,
the sane stack protector configuration would look like
CONFIG_HAVE_CC_STACKPROTECTOR=y
# CONFIG_CC_STACKPROTECTOR_NONE is not set
# CONFIG_CC_STACKPROTECTOR_REGULAR is not set
# CONFIG_CC_STACKPROTECTOR_STRONG is not set
CONFIG_CC_STACKPROTECTOR_AUTO=y
and when you ran this through "make oldconfig" with the Kbuild changes,
it would ask you about the regular CONFIG_CC_STACKPROTECTOR (that had
been renamed from CONFIG_CC_STACKPROTECTOR_REGULAR to just
CONFIG_CC_STACKPROTECTOR), but it would think that the STRONG version
used to be disabled (because it was really enabled by AUTO), and would
disable it in the new config, resulting in:
CONFIG_HAVE_CC_STACKPROTECTOR=y
CONFIG_CC_HAS_STACKPROTECTOR_NONE=y
CONFIG_CC_STACKPROTECTOR=y
# CONFIG_CC_STACKPROTECTOR_STRONG is not set
CONFIG_CC_HAS_SANE_STACKPROTECTOR=y
That's dangerously subtle - people could suddenly find themselves with
the weaker stack protector setup without even realizing.
The solution here is to just rename not just the old RECULAR stack
protector option, but also the strong one. This does that by just
removing the CC_ prefix entirely for the user choices, because it really
is not about the compiler support (the compiler support now instead
automatially impacts _visibility_ of the options to users).
This results in "make oldconfig" actually asking the user for their
choice, so that we don't have any silent subtle security model changes.
The end result would generally look like this:
CONFIG_HAVE_CC_STACKPROTECTOR=y
CONFIG_CC_HAS_STACKPROTECTOR_NONE=y
CONFIG_STACKPROTECTOR=y
CONFIG_STACKPROTECTOR_STRONG=y
CONFIG_CC_HAS_SANE_STACKPROTECTOR=y
where the "CC_" versions really are about internal compiler
infrastructure, not the user selections.
Acked-by: Masahiro Yamada <yamada.masahiro@socionext.com>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
2018-06-14 12:21:18 +09:00
..
bpf
treewide: Use array_size() in vzalloc()
2018-06-12 16:19:22 -07:00
cgroup
treewide: Use array_size() in vmalloc()
2018-06-12 16:19:22 -07:00
configs
Kbuild: rename CC_STACKPROTECTOR[_STRONG] config variables
2018-06-14 12:21:18 +09:00
debug
treewide: kzalloc() -> kcalloc()
2018-06-12 16:19:22 -07:00
events
treewide: kzalloc_node() -> kcalloc_node()
2018-06-12 16:19:22 -07:00
gcov
gcov: remove CONFIG_GCOV_FORMAT_AUTODETECT
2018-06-08 18:56:02 +09:00
irq
Merge branch 'x86-urgent-for-linus' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip
2018-06-10 09:44:53 -07:00
livepatch
livepatch: Allow to call a custom callback when freeing shadow variables
2018-04-17 13:42:48 +02:00
locking
treewide: kzalloc() -> kcalloc()
2018-06-12 16:19:22 -07:00
power
treewide: Use array_size() in vmalloc()
2018-06-12 16:19:22 -07:00
printk
Printk changes for 4.18
2018-06-06 16:04:55 -07:00
rcu
treewide: Use array_size() in vmalloc()
2018-06-12 16:19:22 -07:00
sched
treewide: kzalloc() -> kcalloc()
2018-06-12 16:19:22 -07:00
time
Power management updates for 4.18-rc1
2018-06-05 09:38:39 -07:00
trace
treewide: Use array_size() in vmalloc()
2018-06-12 16:19:22 -07:00
.gitignore
acct.c
kernel/acct.c: fix the acct->needcheck check in check_free_space()
2018-01-04 16:45:09 -08:00
async.c
kernel/async.c: revert "async: simplify lowest_in_progress()"
2018-02-06 18:32:44 -08:00
audit.c
audit: use inline function to get audit context
2018-05-14 17:24:18 -04:00
audit.h
audit: track the owner of the command mutex ourselves
2018-02-23 11:22:22 -05:00
audit_fsnotify.c
audit_tree.c
audit: track the owner of the command mutex ourselves
2018-02-23 11:22:22 -05:00
audit_watch.c
audit: use inline function to get audit context
2018-05-14 17:24:18 -04:00
auditfilter.c
audit: use existing session info function
2018-05-18 15:47:54 -04:00
auditsc.c
audit: Fix wrong task in comparison of session ID
2018-05-21 14:27:43 -04:00
backtracetest.c
bounds.c
capability.c
compat.c
Merge branch 'timers-core-for-linus' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip
2018-06-04 20:27:54 -07:00
configs.c
context_tracking.c
cpu.c
cpu/hotplug: Fix unused function warning
2018-03-15 20:34:40 +01:00
cpu_pm.c
crash_core.c
mm: split page_type out from _mapcount
2018-06-07 17:34:37 -07:00
crash_dump.c
cred.c
delayacct.c
delayacct: Use raw_spinlocks
2018-04-27 14:34:51 +02:00
dma.c
proc: introduce proc_create_single{,_data}
2018-05-16 07:23:35 +02:00
elfcore.c
exec_domain.c
proc: introduce proc_create_single{,_data}
2018-05-16 07:23:35 +02:00
exit.c
kernel: use kernel_wait4() instead of sys_wait4()
2018-04-02 20:14:51 +02:00
extable.c
extable: Make init_kernel_text() global
2018-02-21 16:54:06 +01:00
fail_function.c
treewide: kmalloc() -> kmalloc_array()
2018-06-12 16:19:22 -07:00
fork.c
Kbuild: rename CC_STACKPROTECTOR[_STRONG] config variables
2018-06-14 12:21:18 +09:00
freezer.c
futex.c
pids: introduce find_get_task_by_vpid() helper
2018-02-06 18:32:46 -08:00
futex_compat.c
groups.c
kernel: make groups_sort calling a responsibility group_info allocators
2017-12-14 16:00:49 -08:00
hung_task.c
kernel/hung_task.c: show all hung tasks before panic
2018-06-07 17:34:39 -07:00
iomem.c
memremap: split devm_memremap_pages() and memremap() infrastructure
2018-05-15 23:08:33 -07:00
irq_work.c
irq/work: Improve the flag definitions
2018-01-08 19:43:15 +01:00
jump_label.c
jump_label: Disable jump labels in __exit code
2018-03-20 08:57:17 +01:00
kallsyms.c
Merge branch 'for-linus' of git://git.kernel.org/pub/scm/linux/kernel/git/pmladek/printk
2018-02-01 13:36:15 -08:00
kcmp.c
Kconfig.freezer
Kconfig.hz
Kconfig.locks
Kconfig.preempt
kcov.c
kcov: detect double association with a single task
2018-02-06 18:32:46 -08:00
kexec.c
kexec: call do_kexec_load() in compat syscall directly
2018-04-02 20:15:01 +02:00
kexec_core.c
kexec_file.c
treewide: Use array_size() in vzalloc()
2018-06-12 16:19:22 -07:00
kexec_internal.h
kmod.c
kprobes.c
kprobes: Fix random address output of blacklist file
2018-04-25 10:27:56 -04:00
ksysfs.c
kthread.c
kthread: Allow kthread_park() on a parked kthread
2018-05-25 08:03:51 +02:00
latencytop.c
Makefile
Merge branch 'core-rseq-for-linus' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip
2018-06-10 10:17:09 -07:00
memremap.c
mm: introduce MEMORY_DEVICE_FS_DAX and CONFIG_DEV_PAGEMAP_OPS
2018-05-22 06:59:39 -07:00
module-internal.h
module.c
- Introduce arithmetic overflow test helper functions (Rasmus)
2018-06-06 17:27:14 -07:00
module_signing.c
notifier.c
nsproxy.c
padata.c
padata: add SPDX identifier
2018-01-05 18:43:00 +11:00
panic.c
Kbuild: rename CC_STACKPROTECTOR[_STRONG] config variables
2018-06-14 12:21:18 +09:00
params.c
kernel/params.c: downgrade warning for unsafe parameters
2018-04-11 10:28:37 -07:00
pid.c
xarray: add the xa_lock to the radix_tree_root
2018-04-11 10:28:39 -07:00
pid_namespace.c
Merge branch 'userns-linus' of git://git.kernel.org/pub/scm/linux/kernel/git/ebiederm/user-namespace
2018-04-03 19:15:32 -07:00
profile.c
ptrace.c
pids: introduce find_get_task_by_vpid() helper
2018-02-06 18:32:46 -08:00
range.c
reboot.c
relay.c
treewide: kmalloc() -> kmalloc_array()
2018-06-12 16:19:22 -07:00
resource.c
libnvdimm for 4.18
2018-06-08 17:21:52 -07:00
rseq.c
rseq: Introduce restartable sequences system call
2018-06-06 11:58:31 +02:00
seccomp.c
audit/stable-4.18 PR 20180605
2018-06-06 16:34:00 -07:00
signal.c
signal: Remove no longer required irqsave/restore
2018-06-10 06:14:01 +02:00
smp.c
smpboot.c
smpboot.h
softirq.c
Merge branch 'irq-core-for-linus' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip
2018-06-04 19:59:22 -07:00
stacktrace.c
stop_machine.c
Linux 4.17-rc5
2018-05-15 08:10:50 +02:00
sys.c
mm: introduce arg_lock to protect arg_start|end and env_start|end in mm_struct
2018-06-07 17:34:34 -07:00
sys_ni.c
Merge branch 'core-rseq-for-linus' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip
2018-06-10 10:17:09 -07:00
sysctl.c
treewide: kzalloc() -> kcalloc()
2018-06-12 16:19:22 -07:00
sysctl_binary.c
staging: irda: remove remaining remants of irda code removal
2018-04-16 11:26:49 +02:00
task_work.c
locking/barriers: Convert users of lockless_dereference() to READ_ONCE()
2017-12-17 13:57:15 +01:00
taskstats.c
pids: introduce find_get_task_by_vpid() helper
2018-02-06 18:32:46 -08:00
test_kprobes.c
torture.c
rcu: Rename cond_resched_rcu_qs() to cond_resched_tasks_rcu_qs()
2018-05-15 10:27:29 -07:00
tracepoint.c
tracepoints: Fix the descriptions of tracepoint_probe_register{_prio}
2018-05-28 12:49:51 -04:00
tsacct.c
ucount.c
headers: untangle kmemleak.h from mm.h
2018-04-05 21:36:27 -07:00
uid16.c
fs: add do_fchownat(), ksys_fchown() helpers and ksys_{,l}chown() wrappers
2018-04-02 20:15:59 +02:00
uid16.h
kernel: provide ksys_*() wrappers for syscalls called by kernel/uid16.c
2018-04-02 20:15:30 +02:00
umh.c
umh: fix race condition
2018-06-07 16:56:28 -04:00
up.c
user-return-notifier.c
user.c
efivarfs: Limit the rate for non-root to read files
2018-02-22 10:21:02 -08:00
user_namespace.c
treewide: kmalloc() -> kmalloc_array()
2018-06-12 16:19:22 -07:00
utsname.c
uts: create "struct uts_namespace" from kmem_cache
2018-04-11 10:28:35 -07:00
utsname_sysctl.c
watchdog.c
watchdog_hld.c
workqueue.c
treewide: kzalloc() -> kcalloc()
2018-06-12 16:19:22 -07:00
workqueue_internal.h
workqueue: Set worker->desc to workqueue name by default
2018-05-18 08:47:13 -07:00