From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from kanga.kvack.org (kanga.kvack.org [205.233.56.17]) by smtp.lore.kernel.org (Postfix) with ESMTP id 2AC2BC6FA91 for ; Fri, 16 Sep 2022 19:57:29 +0000 (UTC) Received: by kanga.kvack.org (Postfix) id 776E28D0002; Fri, 16 Sep 2022 15:57:28 -0400 (EDT) Received: by kanga.kvack.org (Postfix, from userid 40) id 726118D0001; Fri, 16 Sep 2022 15:57:28 -0400 (EDT) X-Delivered-To: int-list-linux-mm@kvack.org Received: by kanga.kvack.org (Postfix, from userid 63042) id 6163A8D0002; Fri, 16 Sep 2022 15:57:28 -0400 (EDT) X-Delivered-To: linux-mm@kvack.org Received: from relay.hostedemail.com (smtprelay0013.hostedemail.com [216.40.44.13]) by kanga.kvack.org (Postfix) with ESMTP id 4E8DA8D0001 for ; Fri, 16 Sep 2022 15:57:28 -0400 (EDT) Received: from smtpin01.hostedemail.com (a10.router.float.18 [10.200.18.1]) by unirelay02.hostedemail.com (Postfix) with ESMTP id 25124121BED for ; Fri, 16 Sep 2022 19:57:28 +0000 (UTC) X-FDA: 79919008176.01.8A2ED9E Received: from ams.source.kernel.org (ams.source.kernel.org [145.40.68.75]) by imf18.hostedemail.com (Postfix) with ESMTP id C102F1C00A1 for ; Fri, 16 Sep 2022 19:57:27 +0000 (UTC) Received: from smtp.kernel.org (relay.kernel.org [52.25.139.140]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ams.source.kernel.org (Postfix) with ESMTPS id F0F13B82919; Fri, 16 Sep 2022 19:57:25 +0000 (UTC) Received: by smtp.kernel.org (Postfix) with ESMTPSA id 4599FC433D6; Fri, 16 Sep 2022 19:57:24 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=linux-foundation.org; s=korg; t=1663358244; bh=toDD/DKP6ej2h13IFCfqAwO2xnElND7IEzQWcWOhAqI=; h=Date:From:To:Cc:Subject:In-Reply-To:References:From; b=fhlmuao9gEG+AEm6I2K7+XKwGMFg0YwspJcIDXhJE3SqUlTamt3OveKskBKFPKz7e 7vt/kU0mHM9Nzc0uzQSp9mKiWSIbf+Mbfsy6aLoW1h0glwmkKUk8EaeFBHea3rxm0I QJQ64gI3IHdtu9eZ+E6nOBptuTupvwO0jn6Rffoc= Date: Fri, 16 Sep 2022 12:57:23 -0700 From: Andrew Morton To: Kees Cook Cc: Matthew Wilcox , Uladzislau Rezki , Yu Zhao , dev@der-flo.net, Peter Zijlstra , Ingo Molnar , linux-kernel@vger.kernel.org, x86@kernel.org, linux-perf-users@vger.kernel.org, linux-mm@kvack.org, linux-hardening@vger.kernel.org, linux-arch@vger.kernel.org Subject: Re: [PATCH 0/3] x86/dumpstack: Inline copy_from_user_nmi() Message-Id: <20220916125723.b4c189d09bcd8fd211a73c32@linux-foundation.org> In-Reply-To: <20220916135953.1320601-1-keescook@chromium.org> References: <20220916135953.1320601-1-keescook@chromium.org> X-Mailer: Sylpheed 3.7.0 (GTK+ 2.24.33; x86_64-redhat-linux-gnu) Mime-Version: 1.0 Content-Type: text/plain; charset=US-ASCII Content-Transfer-Encoding: 7bit ARC-Seal: i=1; s=arc-20220608; d=hostedemail.com; t=1663358247; a=rsa-sha256; cv=none; b=Gug8at5BtuLuXevzOso4ET8B1f9q8eEyADZdZUroXYRsXorOrkCdud1mcPVYQ607gsPWRm Y5mXKpn8bkryVVFisWc1FRvySMsSAmhc1d84im5Pr5kFFRHqF2vHc/YIhQqGLXvz+lr+8a A79UssoNw/3/zbuYkhugkJB7bUj75Uo= ARC-Authentication-Results: i=1; imf18.hostedemail.com; dkim=pass header.d=linux-foundation.org header.s=korg header.b=fhlmuao9; dmarc=none; spf=pass (imf18.hostedemail.com: domain of akpm@linux-foundation.org designates 145.40.68.75 as permitted sender) smtp.mailfrom=akpm@linux-foundation.org ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=hostedemail.com; s=arc-20220608; t=1663358247; h=from:from:sender:reply-to:subject:subject:date:date: message-id:message-id:to:to:cc:cc:mime-version:mime-version: content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references:dkim-signature; bh=nQiZQlIKsNMJqFpT/YREVjugeQ575M078tD5ZErHTy4=; b=gD9iTK98ViPs+mZBJEFdytLG575J6SWyZnrgNsaaBRrc3fKAaNWUvUlb23lIJ+C8PodVio xUAMh/NWcLVR5F9qkNmdFFsFUNj8nf+rRpciTzuUdDG5jzhMHae2A2VNyrRRO7/fasNhYK xnKcrSBvg7ZND4oWIVdFTFGLeC6CD0Y= X-Stat-Signature: 4njipkpfay3n4npf17bo65qy1y3ue53f X-Rspamd-Queue-Id: C102F1C00A1 Authentication-Results: imf18.hostedemail.com; dkim=pass header.d=linux-foundation.org header.s=korg header.b=fhlmuao9; dmarc=none; spf=pass (imf18.hostedemail.com: domain of akpm@linux-foundation.org designates 145.40.68.75 as permitted sender) smtp.mailfrom=akpm@linux-foundation.org X-Rspam-User: X-Rspamd-Server: rspam10 X-HE-Tag: 1663358247-743541 X-Bogosity: Ham, tests=bogofilter, spamicity=0.000000, version=1.2.4 Sender: owner-linux-mm@kvack.org Precedence: bulk X-Loop: owner-majordomo@kvack.org List-ID: On Fri, 16 Sep 2022 06:59:51 -0700 Kees Cook wrote: > Hi, > > This fixes a find_vmap_area() deadlock. The main fix is patch 2, repeated here: > > The check_object_size() helper under CONFIG_HARDENED_USERCOPY is > designed to skip any checks where the length is known at compile time as > a reasonable heuristic to avoid "likely known-good" cases. However, it can > only do this when the copy_*_user() helpers are, themselves, inline too. > > Using find_vmap_area() requires taking a spinlock. The check_object_size() > helper can call find_vmap_area() when the destination is in vmap memory. > If show_regs() is called in interrupt context, it will attempt a call to > copy_from_user_nmi(), which may call check_object_size() and then > find_vmap_area(). If something in normal context happens to be in the > middle of calling find_vmap_area() (with the spinlock held), the interrupt > handler will hang forever. > > The copy_from_user_nmi() call is actually being called with a fixed-size > length, so check_object_size() should never have been called in the > first place. In order for check_object_size() to see that the length is > a fixed size, inline copy_from_user_nmi(), as already done with all the > other uaccess helpers. > Why is this so complicated. There's virtually zero value in running all those debug checks from within copy_from_user_nmi(). --- a/arch/x86/lib/usercopy.c~a +++ a/arch/x86/lib/usercopy.c @@ -44,7 +44,7 @@ copy_from_user_nmi(void *to, const void * called from other contexts. */ pagefault_disable(); - ret = __copy_from_user_inatomic(to, from, n); + ret = raw_copy_from_user(to, from, n); pagefault_enable(); return ret; _