Go to file
Alan Somers 69be211061 MFC r323314, r323338, r328849
r323314:
Audit userspace geom code for leaking memory to disk

Any geom class using g_metadata_store, as well as geom_virstor which
duplicated g_metadata_store internally, would dump sectorsize - mdsize bytes
of userspace memory following the metadata block stored. This is most or all
geom classes (gcache, gconcat, geli, gjournal, glabel, gmirror, gmultipath,
graid3, gshsec, gstripe, and geom_virstor).

PR:		222077 (comment #3)
Reported by:	Maxim Khitrov <max AT mxcrypt.com>
Reviewed by:	des
Security:	yes
Sponsored by:	Dell EMC Isilon
Differential Revision:	https://reviews.freebsd.org/D12269

r323338:
Fix information leak in geli(8) integrity mode

In integrity mode, a larger logical sector (e.g., 4096 bytes) spans several
physical sectors (e.g., 512 bytes) on the backing device.  Due to hash
overhead, a 4096 byte logical sector takes 8.5625 512-byte physical sectors.
This means that only 288 bytes (256 data + 32 hash) of the last 512 byte
sector are used.

The memory allocation used to store the encrypted data to be written to the
physical sectors comes from malloc(9) and does not use M_ZERO.

Previously, nothing initialized the final physical sector backing each
logical sector, aside from the hash + encrypted data portion.  So 224 bytes
of kernel heap memory was leaked to every block :-(.

This patch addresses the issue by initializing the trailing portion of the
physical sector in every logical sector to zeros before use.  A much simpler
but higher overhead fix would be to tag the entire allocation M_ZERO.

PR:		222077
Reported by:	Maxim Khitrov <max AT mxcrypt.com>
Reviewed by:	emaste
Security:	yes
Sponsored by:	Dell EMC Isilon
Differential Revision:	https://reviews.freebsd.org/D12272

r328849:
geom: don't write stack garbage in disk labels

Most consumers of g_metadata_store were passing in partially unallocated
memory, resulting in stack garbage being written to disk labels. Fix them by
zeroing the memory first.

gvirstor repeated the same mistake, but in the kernel.

Also, glabel's label contained a fixed-size string that wasn't
initialized to zero.

PR:		222077
Reported by:	Maxim Khitrov <max@mxcrypt.com>
Reviewed by:	cem
X-MFC-With:	323314
X-MFC-With:	323338
Differential Revision:	https://reviews.freebsd.org/D14164
2018-03-10 04:17:01 +00:00
bin MFC r323275, r324112 2017-11-28 18:18:39 +00:00
cddl MFC r329067: 2018-03-10 04:02:51 +00:00
contrib MFC r316339,317396,317829,326010,329554: less v530. 2018-03-07 06:39:00 +00:00
crypto Revert a local change and sync. with head. No functional change. 2018-01-29 18:21:50 +00:00
etc MFC r328895: Correct Russia spelling in regdomain.xml 2018-02-10 22:36:42 +00:00
games MFC r267667: 2016-10-16 22:02:50 +00:00
gnu MFC: r306375 2017-08-05 12:33:00 +00:00
include Sync (make same) the offsetof macro definition in include/ with the 2017-10-29 04:33:50 +00:00
kerberos5 MFC r322112: 2017-09-18 00:13:48 +00:00
lib MFC 328630: 2018-02-28 22:39:47 +00:00
libexec MFC r327289: 2018-01-10 21:24:03 +00:00
release Document EN-18:01, EN-18:02, SA-18:01, SA-18:02. 2018-03-07 15:02:13 +00:00
rescue MFC r315654: 2017-03-23 04:47:43 +00:00
sbin MFC r323314, r323338, r328849 2018-03-10 04:17:01 +00:00
secure Upgrade OpenSSH to 7.3p1. 2017-09-01 22:52:18 +00:00
share MFC r330304: imcsmb(4): Intel integrated Memory Controller (iMC) SMBus 2018-03-09 02:55:27 +00:00
sys MFC r323314, r323338, r328849 2018-03-10 04:17:01 +00:00
tests MFC 287600,287602: Fixes for fork following tests. 2018-01-25 00:08:13 +00:00
tools MFC r325897: 2017-12-04 09:54:03 +00:00
usr.bin MFC r316339,317396,317829,326010,329554: less v530. 2018-03-07 06:39:00 +00:00
usr.sbin MFC r330245: 2018-03-09 14:45:47 +00:00
.arcconfig MFC r265842,r266120,r266121,r266959,r267148,r269985,r281789,r282261,r285064: 2015-12-29 18:22:06 +00:00
.arclint MFC r265842,r266120,r266121,r266959,r267148,r269985,r281789,r282261,r285064: 2015-12-29 18:22:06 +00:00
.gitattributes MFC r327183: 2018-01-06 05:00:30 +00:00
.gitignore MFC r327183: 2018-01-06 05:00:30 +00:00
COPYRIGHT Bump copyright year. 2016-12-31 12:52:58 +00:00
LOCKS
MAINTAINERS MFH (r263160): remove lukemftpd 2014-08-23 15:07:09 +00:00
Makefile MFC r320273: 2017-07-21 17:58:06 +00:00
Makefile.inc1 MFC r324248: 2017-12-13 20:15:23 +00:00
ObsoleteFiles.inc MFC r326558, r326566: 2017-12-17 06:00:49 +00:00
README MFC r318294: 2017-05-18 12:27:41 +00:00
UPDATING MFC r324248: 2017-12-13 20:15:23 +00:00

This is the top level of the FreeBSD source directory.  This file
was last revised on:
$FreeBSD$

For copyright information, please see the file COPYRIGHT in this
directory (additional copyright information also exists for some
sources in this tree - please see the specific source directories for
more information).

The Makefile in this directory supports a number of targets for
building components (or all) of the FreeBSD source tree, the most
commonly used one being ``world'', which rebuilds and installs
everything in the FreeBSD system from the source tree except the
kernel, the kernel-modules and the contents of /etc.  The ``world''
target should only be used in cases where the source tree has not
changed from the currently running version.  See:
http://www.freebsd.org/doc/en_US.ISO8859-1/books/handbook/makeworld.html
for more information, including setting make(1) variables.

The ``buildkernel'' and ``installkernel'' targets build and install
the kernel and the modules (see below).  Please see the top of
the Makefile in this directory for more information on the
standard build targets and compile-time flags.

Building a kernel is a somewhat more involved process, documentation
for which can be found at:
   http://www.freebsd.org/doc/en_US.ISO8859-1/books/handbook/kernelconfig.html
And in the config(8) man page.
Note: If you want to build and install the kernel with the
``buildkernel'' and ``installkernel'' targets, you might need to build
world before.  More information is available in the handbook.

The sample kernel configuration files reside in the sys/<arch>/conf
sub-directory (assuming that you've installed the kernel sources), the
file named GENERIC being the one used to build your initial installation
kernel.  The file NOTES contains entries and documentation for all possible
devices, not just those commonly used.  It is the successor of the ancient
LINT file, but in contrast to LINT, it is not buildable as a kernel but a
pure reference and documentation file.


Source Roadmap:
---------------
bin		System/user commands.

cddl		Various commands and libraries under the Common Development
		and Distribution License.

contrib		Packages contributed by 3rd parties.

crypto		Cryptography stuff (see crypto/README).

etc		Template files for /etc.

games		Amusements.

gnu		Various commands and libraries under the GNU Public License.
		Please see gnu/COPYING* for more information.

include		System include files.

kerberos5	Kerberos5 (Heimdal) package.

lib		System libraries.

libexec		System daemons.

release		Release building Makefile & associated tools.

rescue		Build system for statically linked /rescue utilities.

sbin		System commands.

secure		Cryptographic libraries and commands.

share		Shared resources.

sys		Kernel sources.

tools		Utilities for regression testing and miscellaneous tasks.

usr.bin		User commands.

usr.sbin	System administration commands.


For information on synchronizing your source tree with one or more of
the FreeBSD Project's development branches, please see:

  https://www.freebsd.org/doc/en_US.ISO8859-1/books/handbook/updating-src.html