From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from mail-ot0-f197.google.com (mail-ot0-f197.google.com [74.125.82.197]) by kanga.kvack.org (Postfix) with ESMTP id 1D7F06B0003 for ; Thu, 8 Mar 2018 06:21:15 -0500 (EST) Received: by mail-ot0-f197.google.com with SMTP id 45so2999945otf.1 for ; Thu, 08 Mar 2018 03:21:15 -0800 (PST) Received: from foss.arm.com (foss.arm.com. [217.140.101.70]) by mx.google.com with ESMTP id i2si6009181ote.527.2018.03.08.03.21.12 for ; Thu, 08 Mar 2018 03:21:13 -0800 (PST) Date: Thu, 8 Mar 2018 11:20:58 +0000 From: Mark Rutland Subject: Re: [RFC PATCH 07/14] khwasan: add tag related helper functions Message-ID: <20180308112057.dsxhm3s2yzrld5yq@lakrids.cambridge.arm.com> References: <226055ec7c1a01dd8211ca9a8b34c07162be37fa.1520017438.git.andreyknvl@google.com> <20180305143246.o7bass2rhbksneqb@lakrids.cambridge.arm.com> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: Sender: owner-linux-mm@kvack.org List-ID: To: Andrey Konovalov Cc: Andrey Ryabinin , Alexander Potapenko , Dmitry Vyukov , Jonathan Corbet , Catalin Marinas , Will Deacon , Theodore Ts'o , Jan Kara , Christopher Li , Christoph Lameter , Pekka Enberg , David Rientjes , Joonsoo Kim , Andrew Morton , Masahiro Yamada , Michal Marek , Ard Biesheuvel , Yury Norov , Nick Desaulniers , Marc Zyngier , Bob Picco , Suzuki K Poulose , Kristina Martsenko , Punit Agrawal , Dave Martin , James Morse , Julien Thierry , Michael Weiser , Steve Capper , Ingo Molnar , Thomas Gleixner , Sandipan Das , Paul Lawrence , David Woodhouse , Kees Cook , Geert Uytterhoeven , Josh Poimboeuf , Arnd Bergmann , kasan-dev , linux-doc@vger.kernel.org, LKML , Linux ARM , linux-ext4@vger.kernel.org, linux-sparse@vger.kernel.org, Linux Memory Management List , Linux Kbuild mailing list , Kostya Serebryany , Evgeniy Stepanov , Lee Smith , Ramana Radhakrishnan , Jacob Bramley , Ruben Ayrapetyan , Kees Cook , Jann Horn , Mark Brand On Tue, Mar 06, 2018 at 07:31:16PM +0100, Andrey Konovalov wrote: > On Mon, Mar 5, 2018 at 3:32 PM, Mark Rutland wrote: > > On Fri, Mar 02, 2018 at 08:44:26PM +0100, Andrey Konovalov wrote: > >> +static DEFINE_PER_CPU(u32, prng_state); > >> + > >> +void khwasan_init(void) > >> +{ > >> + int cpu; > >> + > >> + for_each_possible_cpu(cpu) { > >> + per_cpu(prng_state, cpu) = get_random_u32(); > >> + } > >> + WRITE_ONCE(khwasan_enabled, 1); > >> +} > >> + > >> +static inline u8 khwasan_random_tag(void) > >> +{ > >> + u32 state = this_cpu_read(prng_state); > >> + > >> + state = 1664525 * state + 1013904223; > >> + this_cpu_write(prng_state, state); > >> + > >> + return (u8)state; > >> +} > > > > Have you considered preemption here? Is the assumption that it happens > > sufficiently rarely that cross-contaminating the prng state isn't a > > problem? > > Hi Mark! > > Yes, I have. If a preemption happens between this_cpu_read and > this_cpu_write, the only side effect is that we'll give a few > allocated in different contexts objects the same tag. Sine KHWASAN is > meant to be used a probabilistic bug-detection debug feature, this > doesn't seem to have serious negative impact. Sure, just wanted to check that was the intent. > I'll add a comment about this though. That would be great! Thanks, Mark.