• Linus Torvalds's avatar
    Merge tag 'hardening-v6.3-rc1' of git://git.kernel.org/pub/scm/linux/kernel/git/kees/linux · 4a7d37e8
    Linus Torvalds authored
    Pull hardening updates from Kees Cook:
     "Beyond some specific LoadPin, UBSAN, and fortify features, there are
      other fixes scattered around in various subsystems where maintainers
      were okay with me carrying them in my tree or were non-responsive but
      the patches were reviewed by others:
    
       - Replace 0-length and 1-element arrays with flexible arrays in
         various subsystems (Paulo Miguel Almeida, Stephen Rothwell, Kees
         Cook)
    
       - randstruct: Disable Clang 15 support (Eric Biggers)
    
       - GCC plugins: Drop -std=gnu++11 flag (Sam James)
    
       - strpbrk(): Refactor to use strchr() (Andy Shevchenko)
    
       - LoadPin LSM: Allow root filesystem switching when non-enforcing
    
       - fortify: Use dynamic object size hints when available
    
       - ext4: Fix CFI function prototype mismatch
    
       - Nouveau: Fix DP buffer size arguments
    
       - hisilicon: Wipe entire crypto DMA pool on error
    
       - coda: Fully allocate sig_inputArgs
    
       - UBSAN: Improve arm64 trap code reporting
    
       - copy_struct_from_user(): Add minimum bounds check on kernel buffer
         size"
    
    * tag 'hardening-v6.3-rc1' of git://git.kernel.org/pub/scm/linux/kernel/git/kees/linux:
      randstruct: disable Clang 15 support
      uaccess: Add minimum bounds check on kernel buffer size
      arm64: Support Clang UBSAN trap codes for better reporting
      coda: Avoid partial allocation of sig_inputArgs
      gcc-plugins: drop -std=gnu++11 to fix GCC 13 build
      lib/string: Use strchr() in strpbrk()
      crypto: hisilicon: Wipe entire pool on error
      net/i40e: Replace 0-length array with flexible array
      io_uring: Replace 0-length array with flexible array
      ext4: Fix function prototype mismatch for ext4_feat_ktype
      i915/gvt: Replace one-element array with flexible-array member
      drm/nouveau/disp: Fix nvif_outp_acquire_dp() argument size
      LoadPin: Allow filesystem switch when not enforcing
      LoadPin: Move pin reporting cleanly out of locking
      LoadPin: Refactor sysctl initialization
      LoadPin: Refactor read-only check into a helper
      ARM: ixp4xx: Replace 0-length arrays with flexible arrays
      fortify: Use __builtin_dynamic_object_size() when available
      rxrpc: replace zero-lenth array with DECLARE_FLEX_ARRAY() helper
    4a7d37e8
ubsan.c 11.6 KB