From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from mail-oi0-f72.google.com (mail-oi0-f72.google.com [209.85.218.72]) by kanga.kvack.org (Postfix) with ESMTP id 12CE46B0005 for ; Fri, 9 Mar 2018 14:00:04 -0500 (EST) Received: by mail-oi0-f72.google.com with SMTP id u74so5093483oif.19 for ; Fri, 09 Mar 2018 11:00:04 -0800 (PST) Received: from foss.arm.com (foss.arm.com. [217.140.101.70]) by mx.google.com with ESMTP id c137si461221oig.205.2018.03.09.11.00.02 for ; Fri, 09 Mar 2018 11:00:02 -0800 (PST) Date: Fri, 9 Mar 2018 18:59:48 +0000 From: Mark Rutland Subject: Re: [RFC PATCH 06/14] khwasan: enable top byte ignore for the kernel Message-ID: <20180309185947.tk6vg3nplvg7ll52@lakrids.cambridge.arm.com> References: <739eecf573b6342fc41c4f89d7f64eb8c183e312.1520017438.git.andreyknvl@google.com> <20180305143625.vtrfvsbw7loxngaj@lakrids.cambridge.arm.com> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: Sender: owner-linux-mm@kvack.org List-ID: To: Andrey Konovalov Cc: Andrey Ryabinin , Alexander Potapenko , Dmitry Vyukov , Jonathan Corbet , Catalin Marinas , Will Deacon , Theodore Ts'o , Jan Kara , Christopher Li , Christoph Lameter , Pekka Enberg , David Rientjes , Joonsoo Kim , Andrew Morton , Masahiro Yamada , Michal Marek , Ard Biesheuvel , Yury Norov , Nick Desaulniers , Marc Zyngier , Suzuki K Poulose , Kristina Martsenko , Punit Agrawal , Dave Martin , James Morse , Julien Thierry , Michael Weiser , Steve Capper , Ingo Molnar , Thomas Gleixner , Sandipan Das , Paul Lawrence , David Woodhouse , Kees Cook , Geert Uytterhoeven , Josh Poimboeuf , Arnd Bergmann , kasan-dev , linux-doc@vger.kernel.org, LKML , Linux ARM , linux-ext4@vger.kernel.org, linux-sparse@vger.kernel.org, Linux Memory Management List , Linux Kbuild mailing list , Kostya Serebryany , Evgeniy Stepanov , Lee Smith , Ramana Radhakrishnan , Jacob Bramley , Ruben Ayrapetyan , Kees Cook , Jann Horn , Mark Brand On Fri, Mar 09, 2018 at 07:17:14PM +0100, Andrey Konovalov wrote: > On Mon, Mar 5, 2018 at 3:36 PM, Mark Rutland wrote: > > On Fri, Mar 02, 2018 at 08:44:25PM +0100, Andrey Konovalov wrote: > >> KHWASAN uses the Top Byte Ignore feature of arm64 CPUs to store a pointer > >> tag in the top byte of each pointer. This commit enables the TCR_TBI1 bit, > >> which enables Top Byte Ignore for the kernel, when KHWASAN is used. > >> --- > >> arch/arm64/include/asm/pgtable-hwdef.h | 1 + > >> arch/arm64/mm/proc.S | 8 +++++++- > >> 2 files changed, 8 insertions(+), 1 deletion(-) > > > > Before it's safe to do this, I also think you'll need to fix up at > > least: > > * access_ok() > > This is used for accessing user addresses, and they are not tagged. Am > I missing something? No, I just confused myself. ;) I was converned that a kernel address with the top byte clear might spuriously pass access_ok(), but I was mistaken. Bit 55 of the address would be set, and this would fall outside of USER_DS (which is TASK_SIZE_64 - 1). So access_ok() should be fine as-is. Sorry for the noise! Mark.