From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from kanga.kvack.org (kanga.kvack.org [205.233.56.17]) by smtp.lore.kernel.org (Postfix) with ESMTP id 86F96C48BEB for ; Wed, 21 Feb 2024 23:05:40 +0000 (UTC) Received: by kanga.kvack.org (Postfix) id C47206B006E; Wed, 21 Feb 2024 18:05:39 -0500 (EST) Received: by kanga.kvack.org (Postfix, from userid 40) id BF6E96B0071; Wed, 21 Feb 2024 18:05:39 -0500 (EST) X-Delivered-To: int-list-linux-mm@kvack.org Received: by kanga.kvack.org (Postfix, from userid 63042) id A96BF6B0072; Wed, 21 Feb 2024 18:05:39 -0500 (EST) X-Delivered-To: linux-mm@kvack.org Received: from relay.hostedemail.com (smtprelay0013.hostedemail.com [216.40.44.13]) by kanga.kvack.org (Postfix) with ESMTP id 981216B006E for ; Wed, 21 Feb 2024 18:05:39 -0500 (EST) Received: from smtpin17.hostedemail.com (a10.router.float.18 [10.200.18.1]) by unirelay03.hostedemail.com (Postfix) with ESMTP id 68837A0330 for ; Wed, 21 Feb 2024 23:05:39 +0000 (UTC) X-FDA: 81817344798.17.4EBE56E Received: from mail-pg1-f181.google.com (mail-pg1-f181.google.com [209.85.215.181]) by imf01.hostedemail.com (Postfix) with ESMTP id E18C340022 for ; Wed, 21 Feb 2024 23:05:34 +0000 (UTC) Authentication-Results: imf01.hostedemail.com; dkim=pass header.d=chromium.org header.s=google header.b=Zcr7r918; dmarc=pass (policy=none) header.from=chromium.org; spf=pass (imf01.hostedemail.com: domain of keescook@chromium.org designates 209.85.215.181 as permitted sender) smtp.mailfrom=keescook@chromium.org ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=hostedemail.com; s=arc-20220608; t=1708556735; h=from:from:sender:reply-to:subject:subject:date:date: message-id:message-id:to:to:cc:cc:mime-version:mime-version: content-type:content-type:content-transfer-encoding: in-reply-to:in-reply-to:references:references:dkim-signature; bh=IaQv6IYiHqQsQRwxagN42nrCoy2L36X/io0NIlSKpEE=; b=jjSa6pSB0A7K97aM/LfT7FU48K5J70n1WnAzqZlHG32ay/+CY52T9bYg4kNrpqS/GjyvM4 GjrpWE717H5PAHkYL2jFG4veqYvXISkf3euClvay+wLOWbHFHH+9zugKDpiT/s4ju2mgv7 3TDa9kDLqVq9OTizLxU1FSwA5AkFkFw= ARC-Authentication-Results: i=1; imf01.hostedemail.com; dkim=pass header.d=chromium.org header.s=google header.b=Zcr7r918; dmarc=pass (policy=none) header.from=chromium.org; spf=pass (imf01.hostedemail.com: domain of keescook@chromium.org designates 209.85.215.181 as permitted sender) smtp.mailfrom=keescook@chromium.org ARC-Seal: i=1; s=arc-20220608; d=hostedemail.com; t=1708556735; a=rsa-sha256; cv=none; b=jrrk01YDKctbnizgou4+uePFCwqnLTkbTj4TmpZAuXSD4S47w54hcCsP7wR3macqspIDSd h3Wv3AnnAAPKDbVrxMRAul1YEVvkNsTO0jVzyQNkHfxWxTJicyh4bRAyxlTi3w5+N4HOaq A/zulGG83xiP1AOUrvqaS3xLERElFpk= Received: by mail-pg1-f181.google.com with SMTP id 41be03b00d2f7-5c6bd3100fcso4263495a12.3 for ; Wed, 21 Feb 2024 15:05:34 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=chromium.org; s=google; t=1708556733; x=1709161533; darn=kvack.org; h=in-reply-to:content-disposition:mime-version:references:message-id :subject:cc:to:from:date:from:to:cc:subject:date:message-id:reply-to; bh=IaQv6IYiHqQsQRwxagN42nrCoy2L36X/io0NIlSKpEE=; b=Zcr7r918z6lMKpVuz1SixzGkecbHV7hDH/LRf5NRTWkttb0vjxbeLpnCo7keSu1Dj5 SQ5YmKypZ3obQ7iOhrugAzwkudTDMuTjYKzCPFt8lXZ7UGVqmtXd3xYpNWAlHSEcF8R+ dxFKxqAT2/J+td6jTjK17V2b4Iv6m3PkYc2ho= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1708556733; x=1709161533; h=in-reply-to:content-disposition:mime-version:references:message-id :subject:cc:to:from:date:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to; bh=IaQv6IYiHqQsQRwxagN42nrCoy2L36X/io0NIlSKpEE=; b=MDMXsR8xX+mvQEu7xLkOGOQB3N+iUGyfOtQncKDYIuvDfAcUOvlTMt6YHkHbYpacjq diwFYkdZ3Pjn1I013I5KCUFoHD3z1QmmMHR8cYCewS31EVeOsrv4qjHf3oW1skrZ7cA/ 4V85m8RXvlew30VdC4iquS190nYmnvE4R12jTsTg/3k7yQX/CA2iu273bKDGLAjXX95i qm7KiK7LCmCfNN4LwWhNVqslVq6hGHxlDm6/k4qAHTSsEWGtrBEi+XEExkfE8lSO8XYY 9bdQ+31jpxWbDWC7+WypUsDC0F+5sjwpyWIzvjvftAVL7re2Ca8EQBGXwio/qBY0JJZI CdlQ== X-Forwarded-Encrypted: i=1; AJvYcCUu4XckYdBr3ptfmSjeWyG6IR/xzY06zPcpCDR70onplVkBrfFKH0B2DbSHjr7QwkL22suOXhrfNt+CBAKKXGKsogg= X-Gm-Message-State: AOJu0YzEu3M2GSDviN94Vw5jpUVlAfhFxhODqsW1fUbnPE18/IzJM/Cp EMpcQNZGEO2R43u0p/gI7s0j4gcDVTuOzBMoSPdeRrkkOiJZU1vtAsoo3miAFQ== X-Google-Smtp-Source: AGHT+IH+teXEsGu6GLq183PkmXmTfSxTSQurKQ+iB3a4w+eOyy2Uq5GD7YKws1ss74yQ/PCAb0TDsw== X-Received: by 2002:a05:6a20:9586:b0:1a0:d25b:aaac with SMTP id iu6-20020a056a20958600b001a0d25baaacmr450464pzb.32.1708556733595; Wed, 21 Feb 2024 15:05:33 -0800 (PST) Received: from www.outflux.net ([198.0.35.241]) by smtp.gmail.com with ESMTPSA id h15-20020a170902f7cf00b001db7ed47968sm8631428plw.30.2024.02.21.15.05.32 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 21 Feb 2024 15:05:33 -0800 (PST) Date: Wed, 21 Feb 2024 15:05:32 -0800 From: Kees Cook To: Suren Baghdasaryan Cc: akpm@linux-foundation.org, kent.overstreet@linux.dev, mhocko@suse.com, vbabka@suse.cz, hannes@cmpxchg.org, roman.gushchin@linux.dev, mgorman@suse.de, dave@stgolabs.net, willy@infradead.org, liam.howlett@oracle.com, penguin-kernel@i-love.sakura.ne.jp, corbet@lwn.net, void@manifault.com, peterz@infradead.org, juri.lelli@redhat.com, catalin.marinas@arm.com, will@kernel.org, arnd@arndb.de, tglx@linutronix.de, mingo@redhat.com, dave.hansen@linux.intel.com, x86@kernel.org, peterx@redhat.com, david@redhat.com, axboe@kernel.dk, mcgrof@kernel.org, masahiroy@kernel.org, nathan@kernel.org, dennis@kernel.org, tj@kernel.org, muchun.song@linux.dev, rppt@kernel.org, paulmck@kernel.org, pasha.tatashin@soleen.com, yosryahmed@google.com, yuzhao@google.com, dhowells@redhat.com, hughd@google.com, andreyknvl@gmail.com, ndesaulniers@google.com, vvvvvv@google.com, gregkh@linuxfoundation.org, ebiggers@google.com, ytcoode@gmail.com, vincent.guittot@linaro.org, dietmar.eggemann@arm.com, rostedt@goodmis.org, bsegall@google.com, bristot@redhat.com, vschneid@redhat.com, cl@linux.com, penberg@kernel.org, iamjoonsoo.kim@lge.com, 42.hyeyoo@gmail.com, glider@google.com, elver@google.com, dvyukov@google.com, shakeelb@google.com, songmuchun@bytedance.com, jbaron@akamai.com, rientjes@google.com, minchan@google.com, kaleshsingh@google.com, kernel-team@android.com, linux-doc@vger.kernel.org, linux-kernel@vger.kernel.org, iommu@lists.linux.dev, linux-arch@vger.kernel.org, linux-fsdevel@vger.kernel.org, linux-mm@kvack.org, linux-modules@vger.kernel.org, kasan-dev@googlegroups.com, cgroups@vger.kernel.org Subject: Re: [PATCH v4 14/36] lib: add allocation tagging support for memory allocation profiling Message-ID: <202402211449.401382D2AF@keescook> References: <20240221194052.927623-1-surenb@google.com> <20240221194052.927623-15-surenb@google.com> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <20240221194052.927623-15-surenb@google.com> X-Rspam-User: X-Stat-Signature: xydxm6ugjpqwct3q1x9bekzt5pb1yats X-Rspamd-Server: rspam07 X-Rspamd-Queue-Id: E18C340022 X-HE-Tag: 1708556734-74617 X-HE-Meta: U2FsdGVkX19LRNS1cB40HkdS11BsZJgjI5uaM7A0/V/5SY0fav4vu+SogT3BhNnMrOvjOauYH/bIdr/bL1af/mWiQINOdxh5ecDe4AYHv63kh2EoYwsXKel9k8KjpTtgyImkyrJiABj9Mpmg3RVCldmoDu+BStcE4/xMSc+PX3zNztD6E7lh2V4B+9woH96ncr2JTGwCrOE93IEL3Liixepw4S4E3UdAXRg8F7WrtMt/b+AJHRbATTqZLpVe/Qrxu2oq0DspXNaB5h1H6MtFpTcZAa8cpNtouAj280zvpSPichD5YgzugaOG8IUgaPJrIn2974p6Nb6ee4m/RTkQq8iKtDbREPhAKLZzO4/sOIIs7yT1GHrY1fE4vgOISxHGdlhm3NqO7+KRgOlwzDimR9auOnAoC0TLFzlEcIR4AQSHFdRCB4O2O0r9mVSBI/GfSAVLgg3yHjpsVnxH6FhKa1rKutETqhhyF8Kbd245sl/zE9OKikg4l4iYNBrgtPr4x5I5ocJV68qo3eG6UZyQapn7cG3VqdInxL+0Rr/sy/XxPHsvCj/Qomvl4v6Gt/DI4VZ10ZibzascI0JVJXYU5dBFPHTOAJOeSkjsBAF+vTo8+Dj7mTS+BN2Nqj2feQLh1kja3bUMV+H2bOJnD2f/8Afc14eoyCAu40Ph2gkO2KUY/Vm/w2OfDMO10WJ7KrWN4EJzxamITeoayQVz+Z5J86XPLJ9KRkd/s7VwCHH2/1wZFSE0n3dkmDhrmYJCIJxVPDGh2yJgUmYYZsG9IbXZvNfd9WTp9H9ZPsAnvR9pM/wzEtbXjuP7FN4oKM8SnOgKn/tvXHLe8caf3P44NRYnFdzfIYPwPSsHcry+9oPIUlM4u6bfD+1H5QC9dc8EbHfG3ZJ1qHcbi8w1/DCl1ljkAgVlhiFsl2gbpwCkvTLSsAVn9uvQ7p6rE+rGmi8dHSCCGgkDCJ37LSl+nugwMEM LxHV+l5N MdEetQxkXsvHJOt5ouPv5jups8vypxc1xjT5KvlQIPMmbyy6Von/PmrOSEgzlkzsDefcZ3BWF3UKvjf7r2Layh9//Yg/KBZ6JGCSuV+lPj6t76yOVxmzfzGQh77yHwucaLO8z876AFB02xOzCOu4XBX55OgjGPpnsggbL/Qn9nvwGvvif1BY8DDJV7HHlxBWPZ03gMXwpPO2R5Etc3v39vtmEEp72TPXDbm4LB+ctOUS96AMxaTEeCXi2t62deALmIKMXaU8nnCNX+SfkuW8P37UDeRUfBTqlwxqlpHgDxD3FCAqx8ozebPu9QYnB5tSbkO31GO3AVgD0pyE7doXtjajoXW2cI7gOFGwGNE/pPTSIZRNSPEQbkIeM6gWHy+PLV6Mhbga4dY1aOvbw233ZAiHpn1cbhRGJVjcclZlhJr0QHvE= X-Bogosity: Ham, tests=bogofilter, spamicity=0.000000, version=1.2.4 Sender: owner-linux-mm@kvack.org Precedence: bulk X-Loop: owner-majordomo@kvack.org List-ID: List-Subscribe: List-Unsubscribe: On Wed, Feb 21, 2024 at 11:40:27AM -0800, Suren Baghdasaryan wrote: > [...] > +struct alloc_tag { > + struct codetag ct; > + struct alloc_tag_counters __percpu *counters; > +} __aligned(8); > [...] > +#define DEFINE_ALLOC_TAG(_alloc_tag) \ > + static DEFINE_PER_CPU(struct alloc_tag_counters, _alloc_tag_cntr); \ > + static struct alloc_tag _alloc_tag __used __aligned(8) \ > + __section("alloc_tags") = { \ > + .ct = CODE_TAG_INIT, \ > + .counters = &_alloc_tag_cntr }; > [...] > +static inline struct alloc_tag *alloc_tag_save(struct alloc_tag *tag) > +{ > + swap(current->alloc_tag, tag); > + return tag; > +} Future security hardening improvement idea based on this infrastructure: it should be possible to implement per-allocation-site kmem caches. For example, we could create: struct alloc_details { u32 flags; union { u32 size; /* not valid after __init completes */ struct kmem_cache *cache; }; }; - add struct alloc_details to struct alloc_tag - move the tags section into .ro_after_init - extend alloc_hooks() to populate flags and size: .flags = __builtin_constant_p(size) ? KMALLOC_ALLOCATE_FIXED : KMALLOC_ALLOCATE_BUCKETS; .size = __builtin_constant_p(size) ? size : SIZE_MAX; - during kernel start or module init, walk the alloc_tag list and create either a fixed-size kmem_cache or to allocate a full set of kmalloc-buckets, and update the "cache" member. - adjust kmalloc core routines to use current->alloc_tag->cache instead of using the global buckets. This would get us fully separated allocations, producing better than type-based levels of granularity, exceeding what we have currently with CONFIG_RANDOM_KMALLOC_CACHES. Does this look possible, or am I misunderstanding something in the infrastructure being created here? -- Kees Cook