From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from kanga.kvack.org (kanga.kvack.org [205.233.56.17]) by smtp.lore.kernel.org (Postfix) with ESMTP id 7931DC77B60 for ; Fri, 28 Apr 2023 16:51:59 +0000 (UTC) Received: by kanga.kvack.org (Postfix) id D2F286B0071; Fri, 28 Apr 2023 12:51:58 -0400 (EDT) Received: by kanga.kvack.org (Postfix, from userid 40) id CDD936B0072; Fri, 28 Apr 2023 12:51:58 -0400 (EDT) X-Delivered-To: int-list-linux-mm@kvack.org Received: by kanga.kvack.org (Postfix, from userid 63042) id B7F076B0074; Fri, 28 Apr 2023 12:51:58 -0400 (EDT) X-Delivered-To: linux-mm@kvack.org Received: from relay.hostedemail.com (smtprelay0011.hostedemail.com [216.40.44.11]) by kanga.kvack.org (Postfix) with ESMTP id AC09C6B0071 for ; Fri, 28 Apr 2023 12:51:58 -0400 (EDT) Received: from smtpin06.hostedemail.com (a10.router.float.18 [10.200.18.1]) by unirelay10.hostedemail.com (Postfix) with ESMTP id 7CEE3C02A2 for ; Fri, 28 Apr 2023 16:51:58 +0000 (UTC) X-FDA: 80731391916.06.A3897D0 Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.133.124]) by imf30.hostedemail.com (Postfix) with ESMTP id 4E46980008 for ; Fri, 28 Apr 2023 16:51:56 +0000 (UTC) Authentication-Results: imf30.hostedemail.com; dkim=pass header.d=redhat.com header.s=mimecast20190719 header.b=Ldh3Jk9k; spf=pass (imf30.hostedemail.com: domain of david@redhat.com designates 170.10.133.124 as permitted sender) smtp.mailfrom=david@redhat.com; dmarc=pass (policy=none) header.from=redhat.com ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=hostedemail.com; s=arc-20220608; t=1682700716; h=from:from:sender:reply-to:subject:subject:date:date: message-id:message-id:to:to:cc:cc:mime-version:mime-version: content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references:dkim-signature; bh=9UJtOJNRjK11X6Ax3/YkWZBfom69VzTQrdhUY1o0X2A=; b=BObi9v/2bHZ/fHTG0FvfltQFW7lltsm0MOqwmgIl3wT2QHgCg90VZ3CYQQ7srRP8XGvaUU EY8cLnKIFGuCsRS7X4mI1fWRUQ74sMqREid3j4KpBClYDlwBmtFp6BfInwzLSMcC2QkO5e 0BTfPi+xoC+oIKcjGc4K605KAUwjqcM= ARC-Authentication-Results: i=1; imf30.hostedemail.com; dkim=pass header.d=redhat.com header.s=mimecast20190719 header.b=Ldh3Jk9k; spf=pass (imf30.hostedemail.com: domain of david@redhat.com designates 170.10.133.124 as permitted sender) smtp.mailfrom=david@redhat.com; dmarc=pass (policy=none) header.from=redhat.com ARC-Seal: i=1; s=arc-20220608; d=hostedemail.com; t=1682700716; a=rsa-sha256; cv=none; b=18rLuS+cJA0A/HPoCp9L6HYsljeqSpRrjXsY+7bcSIuGM13gT6KW00o4bwQy9Fy4UEP5qP in43xPAAnaGvBp8ITZiP5nayRyaB/x/cXrjj4m50PWRI5vBfjGkcdM0lu9Js3FU0TAvaXP WdDXrsF6+aZRPUfr4BZ+MEDVV+p0gDw= DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1682700715; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=9UJtOJNRjK11X6Ax3/YkWZBfom69VzTQrdhUY1o0X2A=; b=Ldh3Jk9kL3Bpy6xXRCyw7Ut138qhcc8eFm0dnzn+rDcZtVIcbubuYQySqQSWcFhh/4MtNI KmdzvfMUPalKI7RHAKMOPVBpal7K8ELtGIIIT1axt1xEBinqF+48KXmEHdfIZDZwrPKjxZ PanqLqP4VltmlaM3RmbIn/rV8skuWb4= Received: from mail-wm1-f72.google.com (mail-wm1-f72.google.com [209.85.128.72]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-376-nKg-WmcmPruclsgXtVHQ6g-1; Fri, 28 Apr 2023 12:51:51 -0400 X-MC-Unique: nKg-WmcmPruclsgXtVHQ6g-1 Received: by mail-wm1-f72.google.com with SMTP id 5b1f17b1804b1-3f3157128b4so44655505e9.0 for ; Fri, 28 Apr 2023 09:51:51 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20221208; t=1682700710; x=1685292710; h=content-transfer-encoding:in-reply-to:subject:organization:from :references:cc:to:content-language:user-agent:mime-version:date :message-id:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to; bh=9UJtOJNRjK11X6Ax3/YkWZBfom69VzTQrdhUY1o0X2A=; b=OgA/6ksnkYjNQGFN5F0x0Yz3sW7Lyio4s8nNXJ0GW2t8+K5ZwP+bWysbSzFRERikmU p/gKYYYMaZhXcn6RIcnwPAQJSUmhG0u1AvZ2F7rg/2ttRdyBZRr12dx2GPcwZ3Ht/A5m X5XEedM/lNmDzSHFgfeziVsPW2iA4QFRRPf9gNJmcWmUjmWLLJ1CP6ExTWmCb5TCPIxP kPM1fXlQCEj90ptcj6eb9N4/Ztc72mGXy9i3/yo4S4pJ6O859CzLC5CY5kSC/glWuCh2 ASamQOmwFywn5xfbYlA/VxQH5jFdWZWEcP8oLY+KYvkyWGD6LpYquzkB6Nq7wE9Q8J8u jK7Q== X-Gm-Message-State: AC+VfDz3tdLyIXxXKFLU/wfcYTdezmGMdUgVRE4SvkpelNn0s53J+Q/r Pas2fTKmAfcdhkTbSR6c1NJCg15Ycqhau2awl8Wpp5GIKdU7AYxtY0FUUNErQp6Y/Ff6KvF2yBH cFMskGpqpQMw= X-Received: by 2002:a05:600c:350c:b0:3ee:93d2:c915 with SMTP id h12-20020a05600c350c00b003ee93d2c915mr7076542wmq.6.1682700709887; Fri, 28 Apr 2023 09:51:49 -0700 (PDT) X-Google-Smtp-Source: ACHHUZ60Cqp35VglescQbd9Qlua4PQaNkjEb7zMR9lmAYMkPHuIxZahgFKPYNKGQ/ziaWLb1VaUG8g== X-Received: by 2002:a05:600c:350c:b0:3ee:93d2:c915 with SMTP id h12-20020a05600c350c00b003ee93d2c915mr7076499wmq.6.1682700709524; Fri, 28 Apr 2023 09:51:49 -0700 (PDT) Received: from ?IPV6:2003:cb:c726:9300:1711:356:6550:7502? (p200300cbc72693001711035665507502.dip0.t-ipconnect.de. [2003:cb:c726:9300:1711:356:6550:7502]) by smtp.gmail.com with ESMTPSA id k18-20020a05600c0b5200b003edf2dc7ca3sm24690362wmr.34.2023.04.28.09.51.47 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Fri, 28 Apr 2023 09:51:48 -0700 (PDT) Message-ID: <173337c0-14f4-3246-15ff-7fbf03861c94@redhat.com> Date: Fri, 28 Apr 2023 18:51:46 +0200 MIME-Version: 1.0 User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:102.0) Gecko/20100101 Thunderbird/102.10.0 To: Peter Xu , "Kirill A . Shutemov" Cc: Lorenzo Stoakes , Jason Gunthorpe , linux-mm@kvack.org, linux-kernel@vger.kernel.org, Andrew Morton , Jens Axboe , Matthew Wilcox , Dennis Dalessandro , Leon Romanovsky , Christian Benvenuti , Nelson Escobar , Bernard Metzler , Peter Zijlstra , Ingo Molnar , Arnaldo Carvalho de Melo , Mark Rutland , Alexander Shishkin , Jiri Olsa , Namhyung Kim , Ian Rogers , Adrian Hunter , Bjorn Topel , Magnus Karlsson , Maciej Fijalkowski , Jonathan Lemon , "David S . Miller" , Eric Dumazet , Jakub Kicinski , Paolo Abeni , Christian Brauner , Richard Cochran , Alexei Starovoitov , Daniel Borkmann , Jesper Dangaard Brouer , John Fastabend , linux-fsdevel@vger.kernel.org, linux-perf-users@vger.kernel.org, netdev@vger.kernel.org, bpf@vger.kernel.org, Oleg Nesterov , John Hubbard , Jan Kara , Pavel Begunkov , Mika Penttila , David Howells , Christoph Hellwig References: <094d2074-5b69-5d61-07f7-9f962014fa68@redhat.com> <400da248-a14e-46a4-420a-a3e075291085@redhat.com> <077c4b21-8806-455f-be98-d7052a584259@lucifer.local> <62ec50da-5f73-559c-c4b3-bde4eb215e08@redhat.com> <6ddc7ac4-4091-632a-7b2c-df2005438ec4@redhat.com> <20230428160925.5medjfxkyvmzfyhq@box.shutemov.name> <39cc0f26-8fc2-79dd-2e84-62238d27fd98@redhat.com> <20230428162207.o3ejmcz7rzezpt6n@box.shutemov.name> From: David Hildenbrand Organization: Red Hat Subject: Re: [PATCH v5] mm/gup: disallow GUP writing to file-backed mappings by default In-Reply-To: X-Mimecast-Spam-Score: 0 X-Mimecast-Originator: redhat.com Content-Language: en-US Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 7bit X-Stat-Signature: q3tmphfopfd7sufxpmn3f8mq69gj1a5n X-Rspam-User: X-Rspamd-Queue-Id: 4E46980008 X-Rspamd-Server: rspam06 X-HE-Tag: 1682700716-211802 X-HE-Meta: U2FsdGVkX18U1VwB0UhTsiG7OW7NtYGnJgf98iwduGr1jovUpxMv8OO963Rjk6VjKtwwTOLZNwE63m6XfkNCuGDOl3nLx18MVfL67LeYy2Y4xbkH4Ra9IZ1E++Tgv8dM+fbSV1H7hJFg8jlhdvifR9SXnp3WRyrbZxEsYwxWZApysyGWhKDvUJJLc6bJwoks0JOP0TblKv4nJ2xpz9ihGzj0t2/InOrOU1btGZDpLkxMr49UHlqZxVUgWR2aPewxV59I6ViiylUc+xtkCWFSdILcvQRQupknHpdLBg5GEJ5VyfzkTmtnHf7cLdiUFsfTqeC9XkmjynaL0jWlCHLvJvW/BzuVvqDSgTjd2WIujaCGrW3oe9GHacVwR9AmnSy9hqfpbFqXt4ZEEIQATpjOzcXeD+WFFnTyHLpikUJtPqW60Ci1c9hnDimddWnR8YFWrTEE0ASACacdIn9FadZe5PwBDu7fzRbICy0Yv7ERNC+voeOHUajvqmN7WGnqw2dHlIXQltySJIOUuXgw8zbgFly71HXF1zeSWGASnWfXd7EKOt59hrjPfSynW2ek8EFBKplqYXEfYa93aFzVYc0WC5Py1WOAft5xGLJl2KhDAsZZ2Y6RckSsRVTIyyzTYGlwzhkUYXzpIlIEcHSYuDWv9HC59nECReXTi/s7KYMAMeoXl1oMbq1rVpvT61j3Pf5dmBcRVectp7pw5RkVMFM0NgIKX5xGanG0Tv3hzrSxMkHHdIyoefmWD4PAgBxT1lSqT7cLyhc/VFoLUdPOSJczxCr1Ryst+B31THxidSnMo4fT4T3etwobZSwlxXWQhcEMEjXJWnbJ17+F/3LGAtearz09JVt52PyZQDx7ff7+HWUFrK+AZ4krJX/I3G8d2beX95bOs6z/tFNhjM6oUWfd8h8gs1F5Ga4RV7SlhWzqvO8QzJdx420yvUNWbtG1Zz9bIv2nH16ZeqWZZTZlBA9 HWQo6gBu gKSMZOedFUU5sLzMq7h81YkE8vqxlWU25MNeknyiQbFDllFFG2U2W+pz7YPhSKNHBe3qgAyBrFikxxNYCHJugUBUd4d1P/+7bThm2VnqH4TWOsy1zQJ43mR1IL6OhwnQWBPga+dPXLemrcuHGgkugVic2PJ1dhbrIZzFQqUJfgxSfVoHvABkyetZAgLy6e0aWK2TTCnGyQGJhIwaCd8+ybSiDO8C1ujl+vWMaNvLMc5hxdz5IUvx0PGJuvulRtlT86ILHxSTjD8bSkHUOn0cKJKZCcHyouLG8UgM60JcNxJfWVwwJwMgQN8CIvfrcuOAQl8a3pLdgiMSbJjxYxhYwsKb0OAlLo3Stg4E2ehPvzJXb2QzEkvBWqPClBg0DX8NR0N3QjCsdsA8u3Hyd9MCVp2rMSaT1LjhVdq75n64m+SMWJmXn5s6QDGEknFxjHfmmIDWiB7oISbm41fs= X-Bogosity: Ham, tests=bogofilter, spamicity=0.000000, version=1.2.4 Sender: owner-linux-mm@kvack.org Precedence: bulk X-Loop: owner-majordomo@kvack.org List-ID: On 28.04.23 18:39, Peter Xu wrote: > On Fri, Apr 28, 2023 at 07:22:07PM +0300, Kirill A . Shutemov wrote: >> On Fri, Apr 28, 2023 at 06:13:03PM +0200, David Hildenbrand wrote: >>> On 28.04.23 18:09, Kirill A . Shutemov wrote: >>>> On Fri, Apr 28, 2023 at 05:43:52PM +0200, David Hildenbrand wrote: >>>>> On 28.04.23 17:34, David Hildenbrand wrote: >>>>>> On 28.04.23 17:33, Lorenzo Stoakes wrote: >>>>>>> On Fri, Apr 28, 2023 at 05:23:29PM +0200, David Hildenbrand wrote: >>>>>>>>>> >>>>>>>>>> Security is the primary case where we have historically closed uAPI >>>>>>>>>> items. >>>>>>>>> >>>>>>>>> As this patch >>>>>>>>> >>>>>>>>> 1) Does not tackle GUP-fast >>>>>>>>> 2) Does not take care of !FOLL_LONGTERM >>>>>>>>> >>>>>>>>> I am not convinced by the security argument in regard to this patch. >>>>>>>>> >>>>>>>>> >>>>>>>>> If we want to sells this as a security thing, we have to block it >>>>>>>>> *completely* and then CC stable. >>>>>>>> >>>>>>>> Regarding GUP-fast, to fix the issue there as well, I guess we could do >>>>>>>> something similar as I did in gup_must_unshare(): >>>>>>>> >>>>>>>> If we're in GUP-fast (no VMA), and want to pin a !anon page writable, >>>>>>>> fallback to ordinary GUP. IOW, if we don't know, better be safe. >>>>>>> >>>>>>> How do we determine it's non-anon in the first place? The check is on the >>>>>>> VMA. We could do it by following page tables down to folio and checking >>>>>>> folio->mapping for PAGE_MAPPING_ANON I suppose? >>>>>> >>>>>> PageAnon(page) can be called from GUP-fast after grabbing a reference. >>>>>> See gup_must_unshare(). >>>>> >>>>> IIRC, PageHuge() can also be called from GUP-fast and could special-case >>>>> hugetlb eventually, as it's table while we hold a (temporary) reference. >>>>> Shmem might be not so easy ... >>>> >>>> page->mapping->a_ops should be enough to whitelist whatever fs you want. >>>> >>> >>> The issue is how to stabilize that from GUP-fast, such that we can safely >>> dereference the mapping. Any idea? >>> >>> At least for anon page I know that page->mapping only gets cleared when >>> freeing the page, and we don't dereference the mapping but only check a >>> single flag stored alongside the mapping. Therefore, PageAnon() is fine in >>> GUP-fast context. >> >> What codepath you are worry about that clears ->mapping on pages with >> non-zero refcount? >> >> I can only think of truncate (and punch hole). READ_ONCE(page->mapping) >> and fail GUP_fast if it is NULL should be fine, no? >> >> I guess we should consider if the inode can be freed from under us and the >> mapping pointer becomes dangling. But I think we should be fine here too: >> VMA pins inode and VMA cannot go away from under GUP. > > Can vma still go away if during a fast-gup? > So, after we grabbed the page and made sure the the PTE didn't change (IOW, the PTE was stable while we processed it), the page can get unmapped (but not freed, because we hold a reference) and the VMA can theoretically go away (and as far as I understand, nothing stops the file from getting deleted, truncated etc). So we might be looking at folio->mapping and the VMA is no longer there. Maybe even the file is no longer there. -- Thanks, David / dhildenb