From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from kanga.kvack.org (kanga.kvack.org [205.233.56.17]) by smtp.lore.kernel.org (Postfix) with ESMTP id 3C69DE77188 for ; Tue, 14 Jan 2025 21:29:52 +0000 (UTC) Received: by kanga.kvack.org (Postfix) id C1147280006; Tue, 14 Jan 2025 16:29:51 -0500 (EST) Received: by kanga.kvack.org (Postfix, from userid 40) id BC0FC280003; Tue, 14 Jan 2025 16:29:51 -0500 (EST) X-Delivered-To: int-list-linux-mm@kvack.org Received: by kanga.kvack.org (Postfix, from userid 63042) id A88BB280006; Tue, 14 Jan 2025 16:29:51 -0500 (EST) X-Delivered-To: linux-mm@kvack.org Received: from relay.hostedemail.com (smtprelay0016.hostedemail.com [216.40.44.16]) by kanga.kvack.org (Postfix) with ESMTP id 8CA54280003 for ; Tue, 14 Jan 2025 16:29:51 -0500 (EST) Received: from smtpin08.hostedemail.com (a10.router.float.18 [10.200.18.1]) by unirelay10.hostedemail.com (Postfix) with ESMTP id 322F3C0DF2 for ; Tue, 14 Jan 2025 21:29:51 +0000 (UTC) X-FDA: 83007349782.08.B9B9BBE Received: from dfw.source.kernel.org (dfw.source.kernel.org [139.178.84.217]) by imf18.hostedemail.com (Postfix) with ESMTP id 8603B1C000D for ; Tue, 14 Jan 2025 21:29:49 +0000 (UTC) Authentication-Results: imf18.hostedemail.com; dkim=pass header.d=kernel.org header.s=k20201202 header.b=lyPyx6Fc; spf=pass (imf18.hostedemail.com: domain of kees@kernel.org designates 139.178.84.217 as permitted sender) smtp.mailfrom=kees@kernel.org; dmarc=pass (policy=quarantine) header.from=kernel.org ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=hostedemail.com; s=arc-20220608; t=1736890189; h=from:from:sender:reply-to:subject:subject:date:date: message-id:message-id:to:to:cc:cc:mime-version:mime-version: content-type:content-type:content-transfer-encoding: in-reply-to:in-reply-to:references:references:dkim-signature; bh=nqOZ7n9xBAzfcFDgyWYpwROWXg3KboJIz5HbXqNUAn4=; b=pCIPgsvQJtBmVoLVRl0GnHUxP56Tz6HPFCTyBxkU2KEqTIcX8CrD+k3Co466aUHW7frjZt udCw15ZoyQibbFGPMqBLDOzOKFPeG04sZ/CwrJ1LsRwvpblyKnE5zmA1PXEBGeiah/xeHM SlwNaG8VU86s857suelpQTySEl/kqUc= ARC-Authentication-Results: i=1; imf18.hostedemail.com; dkim=pass header.d=kernel.org header.s=k20201202 header.b=lyPyx6Fc; spf=pass (imf18.hostedemail.com: domain of kees@kernel.org designates 139.178.84.217 as permitted sender) smtp.mailfrom=kees@kernel.org; dmarc=pass (policy=quarantine) header.from=kernel.org ARC-Seal: i=1; s=arc-20220608; d=hostedemail.com; t=1736890189; a=rsa-sha256; cv=none; b=gWaDTfXeX/++jGXFIkOA0RYZ2Ws+wf2U3MKgIRGMGFuB8GMTu1oLgx8eZRe6IgzxdI29f3 VeQzGEjdBZTvYH2VqNplJOOukzDs4TVH/pueDoxr8XPiDDMyCtvBAHHyp2du3aAaeH82jz kHi849+yDpjDbdGiEhSUfYza4fnN7vU= Received: from smtp.kernel.org (transwarp.subspace.kernel.org [100.75.92.58]) by dfw.source.kernel.org (Postfix) with ESMTP id 1C8F65C01B5; Tue, 14 Jan 2025 21:29:06 +0000 (UTC) Received: by smtp.kernel.org (Postfix) with ESMTPSA id 7722FC4CEDD; Tue, 14 Jan 2025 21:29:46 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=k20201202; t=1736890186; bh=GDCH+gXK17HExiT6MBZmGoMVMGZ0xZVZIB80Lo0ibpw=; h=Date:From:To:Cc:Subject:References:In-Reply-To:From; b=lyPyx6FcucZYtWR/w+1lVsusiOjnoFt2yPh6drz+yvZ1dfhQfmzo9hi+8oshpz970 7G+TX3wWYj17ec/evgLifYYH4+MQyUTr7yremtOTWMcktWDY92RfDFnjY1ESW0vjzY Tu+2TD2/sDDtaVIvCdCmG0aFD+arog21YVO6ISQWskBLViQ5uOkXTTuQ6RYYIY+/eJ LFV7mHO19kaAAmiuod3cU1EKzcZHpvgVyIWQPOKeA7aTmVPoQVMcpotAhUMIdrF0tq cy7du9LMt8L/sIDZd+IxtZxBreH8wjTD6XsMma10Xs+Te+r4A+mehbmqJQK0QOEfYf eF7+l/WOPGQ3A== Date: Tue, 14 Jan 2025 13:29:44 -0800 From: Kees Cook To: Isaac Manjarres Cc: Jeff Xu , Lorenzo Stoakes , Jann Horn , Andrew Morton , Jeff Layton , Chuck Lever , Alexander Aring , "Liam R. Howlett" , Vlastimil Babka , Shuah Khan , kernel-team@android.com, linux-mm@kvack.org, linux-kernel@vger.kernel.org, linux-fsdevel@vger.kernel.org, linux-kselftest@vger.kernel.org, Suren Baghdasaryan , Kalesh Singh , John Stultz Subject: Re: [RFC PATCH v1 1/2] mm/memfd: Add support for F_SEAL_FUTURE_EXEC to memfd Message-ID: <202501141326.E81023D@keescook> References: <20241206010930.3871336-1-isaacmanjarres@google.com> <20241206010930.3871336-2-isaacmanjarres@google.com> <0ff1c9d9-85f0-489e-a3f7-fa4cef5bb7e5@lucifer.local> <202501061643.986D9453@keescook> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: X-Rspamd-Queue-Id: 8603B1C000D X-Stat-Signature: corrwb1ug85zz1qwzszo4jdnberr1tmt X-Rspam-User: X-Rspamd-Server: rspam11 X-HE-Tag: 1736890189-113089 X-HE-Meta: U2FsdGVkX1+ARKppxvqnJeM5o68heGlrjAqfxwBmAuNfpObdHMHIM0CKq9c9satn/FD2I07Sw6Iy2A47SqE0izBop/05HFQ6o0rt2uq73RMzGGqlbbGCjkMwPBaIbB/vqVCgahVHf26SCUd1JCad0GGiMNXh8dbx8q1vC5Vo0mfDwJZtkOXC8LvJxI2xBKJ7vpiifJ9MajvTJn9GCgk7z3eWbvPHMQ1tNweg1WdOjA/y+wJ6PjzJu2yLdm/A4KwRWdtvEOF0uhTGWmIcBnWYqR5vfoUkUdEjNHRnQ04xoL6jLLQ84G2pVcSwVw+QYiw1uali32EFbCgBPyou0PUBrbxiJuPI0Eb62xPyiyabkRH3yqix2Mgk/NfE/jWrRp1dEpkDUHfDlkiuFHxEq0KlmZKgApu92cjv//ayyoSaRL7SP2h6bylsWSaUTmgIhuSBv7VXSOmnWQjBiIt+bneIqSXMl9XXMIvZfuLDGLRBLxXimppZ8k1G9lkOed+BELlM6L8v2h6ZPbsUfCEL6sW1YZV1TlxTTY1XFsNvjSZDn4CkdFMrVZz7Fo/6Yg7U9P61IShbAuAHJd0PnRVc7wI7PqDfkDcSHS5DNPRZERZTEbdt+qv8atTCR2HY2ixpQ5pPsJDn9jviKnqeoD7wBQg/rXGNqRW6IjdcDi9B2Rpv3Sgw2pYYiIO4lWBqQyJZ9cp4u22m84odIQQiZ9Fa6o+RZys6VachAXsNeYWgdpBOXiQ5rW4OmoSENVfo8dG6Bgvg7gOpRfrMq1Y6tfSevtqc4FhUlTnNG248LheAtXJYLy/fLuaeHGk+UDGhuNwRL1j2PL+Y4E6oiJEe0Ee7kGvKVZmJ1JSphB4QemEu7NOmJAAKAEl8JQEuwYVgDJdGcbygNAllJfPGzHYxzXcHEVaJR2Twe/Dd2M+sgehj4rGWfOKJzoB1eepXpUl6soB+C91vMYq8x7JVSJDvKlWvP7o q/jQFi7a 4Ttq+5yoXoWADbt+Q9Vx1QqS6jgwXy2FbBnfke4j+5hEF3PS5roTEjht2srEXRJHK79TFDN5jpC9OMO/z4nicZOxfL3kKW+IsYAiJDz4PzZZhJZ57jtZd7MxTmwapOrUY9spmqbtUvjyQFA8WrsTE/mnK/AXl6NsWypyfSt66Nx0Apno/VhszIvuTfw5mnmkHyr/4D9lDxsRRYZC4d7y6Mv7e2f3fi7IiTV3CHIXH9dSy/JUf2XwF0O1Z8FCM9OQGiKScci/RlvKaD0uo2Z5u5C4ldx/Fmo3doXkm3t4jkV/2T2YfoZ4cTyDJRnQ5k9oolk/X7+efWNnEptklv1Mo66kqXXKrSz/y0y0MAqPO1hbsvzEoorGyOhzG5Q== X-Bogosity: Ham, tests=bogofilter, spamicity=0.009028, version=1.2.4 Sender: owner-linux-mm@kvack.org Precedence: bulk X-Loop: owner-majordomo@kvack.org List-ID: List-Subscribe: List-Unsubscribe: On Tue, Jan 14, 2025 at 12:02:28PM -0800, Isaac Manjarres wrote: > I think the main issue in the threat model that I described is that > an attacking process can gain control of a more priveleged process. I understood it to be about an attacker gaining execution control through a rewritten function pointer, not that they already have arbitrary execution control. (i.e. taking a "jump anywhere" primitive and upgrading it to "execute anything".) Is the expectation that existing ROP/JOP techniques make protecting memfd irrelevant? -- Kees Cook