From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from kanga.kvack.org (kanga.kvack.org [205.233.56.17]) by smtp.lore.kernel.org (Postfix) with ESMTP id 3E8BBC47DDB for ; Thu, 1 Feb 2024 09:21:58 +0000 (UTC) Received: by kanga.kvack.org (Postfix) id C00966B007E; Thu, 1 Feb 2024 04:21:57 -0500 (EST) Received: by kanga.kvack.org (Postfix, from userid 40) id BB1E06B0080; Thu, 1 Feb 2024 04:21:57 -0500 (EST) X-Delivered-To: int-list-linux-mm@kvack.org Received: by kanga.kvack.org (Postfix, from userid 63042) id A78986B0081; Thu, 1 Feb 2024 04:21:57 -0500 (EST) X-Delivered-To: linux-mm@kvack.org Received: from relay.hostedemail.com (smtprelay0017.hostedemail.com [216.40.44.17]) by kanga.kvack.org (Postfix) with ESMTP id 949EE6B007E for ; Thu, 1 Feb 2024 04:21:57 -0500 (EST) Received: from smtpin16.hostedemail.com (a10.router.float.18 [10.200.18.1]) by unirelay08.hostedemail.com (Postfix) with ESMTP id 14436140DCC for ; Thu, 1 Feb 2024 09:21:57 +0000 (UTC) X-FDA: 81742693074.16.324C5B7 Received: from foss.arm.com (foss.arm.com [217.140.110.172]) by imf19.hostedemail.com (Postfix) with ESMTP id 4626D1A001B for ; Thu, 1 Feb 2024 09:21:54 +0000 (UTC) Authentication-Results: imf19.hostedemail.com; dkim=none; dmarc=pass (policy=none) header.from=arm.com; spf=pass (imf19.hostedemail.com: domain of anshuman.khandual@arm.com designates 217.140.110.172 as permitted sender) smtp.mailfrom=anshuman.khandual@arm.com ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=hostedemail.com; s=arc-20220608; t=1706779315; h=from:from:sender:reply-to:subject:subject:date:date: message-id:message-id:to:to:cc:cc:mime-version:mime-version: content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=XBcDQPnzWQmUsKvfw8ejw+VJudYsIhViPSbA6LREA1A=; b=wz4UKhmSZmLgp5oii9o9jmMdVDHYhOWKXCcT1nJSe4n2q8ppagZiFfPahVhoj/9jDRZgTk WTYey+exNfCSAjU2jxfpLRuAu9qee/x7WcyCp7dkhdQwCYc9GEQkFlwpvvaNhJ49Wx7ISu SJkTMg3YPLFVXknh2B6gqbTCQjJ0vu8= ARC-Authentication-Results: i=1; imf19.hostedemail.com; dkim=none; dmarc=pass (policy=none) header.from=arm.com; spf=pass (imf19.hostedemail.com: domain of anshuman.khandual@arm.com designates 217.140.110.172 as permitted sender) smtp.mailfrom=anshuman.khandual@arm.com ARC-Seal: i=1; s=arc-20220608; d=hostedemail.com; t=1706779315; a=rsa-sha256; cv=none; b=8b9Tq3wwB4nurploXld+xoSqz80XL6HO8IGR6oOUWXFdCD+0yZrlNZIKJugJWYbtdNqdzq 2a8cO4ms2QsfVV8TKi/AZqhKVCpfdm7bYlKptJtSRd751OgZf1CYcaAypj2SGjWFKl7lnI NDOSmXn2ZnCdd1KaCeJ4JiTVCZsv1vQ= Received: from usa-sjc-imap-foss1.foss.arm.com (unknown [10.121.207.14]) by usa-sjc-mx-foss1.foss.arm.com (Postfix) with ESMTP id E1878DA7; Thu, 1 Feb 2024 01:22:35 -0800 (PST) Received: from [10.162.42.11] (a077893.blr.arm.com [10.162.42.11]) by usa-sjc-imap-foss1.foss.arm.com (Postfix) with ESMTPSA id 48A343F738; Thu, 1 Feb 2024 01:21:41 -0800 (PST) Message-ID: <30278898-c4b2-4dd6-ba68-a19575f81a65@arm.com> Date: Thu, 1 Feb 2024 14:51:39 +0530 MIME-Version: 1.0 User-Agent: Mozilla Thunderbird Subject: Re: [PATCH RFC v3 30/35] arm64: mte: ptrace: Handle pages with missing tag storage Content-Language: en-US To: Alexandru Elisei , catalin.marinas@arm.com, will@kernel.org, oliver.upton@linux.dev, maz@kernel.org, james.morse@arm.com, suzuki.poulose@arm.com, yuzenghui@huawei.com, arnd@arndb.de, akpm@linux-foundation.org, mingo@redhat.com, peterz@infradead.org, juri.lelli@redhat.com, vincent.guittot@linaro.org, dietmar.eggemann@arm.com, rostedt@goodmis.org, bsegall@google.com, mgorman@suse.de, bristot@redhat.com, vschneid@redhat.com, mhiramat@kernel.org, rppt@kernel.org, hughd@google.com Cc: pcc@google.com, steven.price@arm.com, vincenzo.frascino@arm.com, david@redhat.com, eugenis@google.com, kcc@google.com, hyesoo.yu@samsung.com, linux-arm-kernel@lists.infradead.org, linux-kernel@vger.kernel.org, kvmarm@lists.linux.dev, linux-fsdevel@vger.kernel.org, linux-arch@vger.kernel.org, linux-mm@kvack.org, linux-trace-kernel@vger.kernel.org References: <20240125164256.4147-1-alexandru.elisei@arm.com> <20240125164256.4147-31-alexandru.elisei@arm.com> From: Anshuman Khandual In-Reply-To: <20240125164256.4147-31-alexandru.elisei@arm.com> Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit X-Rspam-User: X-Rspamd-Server: rspam12 X-Rspamd-Queue-Id: 4626D1A001B X-Stat-Signature: zpacwsfum5c46meh6gczhhd5hpzzkigb X-HE-Tag: 1706779314-323591 X-HE-Meta: U2FsdGVkX18l95WXLC086CyR8YuudtuHloNEXsM1IEUJDfG3i6BCuTb5GQIWqw6qTr5VptCaj0RvGccE8KtkKR/SU7zO3mt2cZwmYlXZsyugXzJq/Uml4C8ugGssmdc63HYA/ePmXqZtta4JU4jVOf8wwAX16zauvcjy51KQBEc1CYlj6CeFqBQmNXl21lTN+gfa2dpAHYHgFm6OK6/Ip6T2gXOL5+OJfDXWWgYDK7n7Cpa+MeuKgSXhxnmKahI+9NmAoxDgJakGmwImRih73WBW49pN/LmUMteLeuhqc6cOAbON2DLRKkGOHv3/IFisRXsIlX04fygMiYOQ7832Lx4cBYDzJfYyOYFlnJBAh92+ZGa+nTnguQjlGLK2rh5OWbwT9S6yAcFHGRqgiJoYMCIa7SkbBJZnzEghAAGJYbQaAHpeqLwDs6miWRXDifuc6efstOmY2Cn/z4D2Gtyfyf+OqVBa2Vc0kgojVU8P8G8xfY3em4ItfKx6ct2ndjgokM86MZWXdl9mY93QtXqtm4ZfMhp496zqzN6LuQ3xtv4JSbGZQCNrhJSQ0SOoX8hSQEYx+BkB3M2jDpk4XdgaupmnVAGOdDZrlxLTE/kt6UOs0M9dbxFWacDccXwUlsxdvFLlqVKFLcHLgqmFkhPY/IFsKbcfrvpR0IJ+WIm4hpMgCevwKUrizQ90HvBSxgOxW/RMtdeQl1bsmIBEzpVxZAz7AwbGxQ8vJPcwwO/HVhfg9sd6fGhd6MVopwqpzBUtNJ08Gdy9gh4ugsbxTo1REkD81p+ZiJ/bW6czJ497+ywNQcmujJqeHGtVjqyWOl04EPTa4WBkUBIVufPyzaQuH4cvoEEr8raBk4XCuPZR2ygkoN+c4N8wCAu5Nqnuz7/XfaoguqZnRbknvgvPUD3zL7GUgg9OZvVklGX97xQYZ+qHbvfaUe818jpqRghZDiFCqaOUjeZ0rKIKc2cAxsA ULLHI2Dy 0LqknRL6PPT1dyHq8ur84SqVDK0qoP0LMzIyKjZdEnNEQVd7YXjD2/kGXAipUuGOHnZjn1/u1bQ8yDKpqKG6iOwG5r4lvuj+90vD8fPQpBsoROz7rJBPnIJ/j9br3lIrgiGoN2vm431YLRpGxdx0kiig1xq9CU8QFlDTCgHeI7cGKuUggzk0ddvwcEMc8RO+boKOCmuviafDut/4= X-Bogosity: Ham, tests=bogofilter, spamicity=0.000000, version=1.2.4 Sender: owner-linux-mm@kvack.org Precedence: bulk X-Loop: owner-majordomo@kvack.org List-ID: List-Subscribe: List-Unsubscribe: On 1/25/24 22:12, Alexandru Elisei wrote: > A page can end up mapped in a MTE enabled VMA without the corresponding tag > storage block reserved. Tag accesses made by ptrace in this case can lead > to the wrong tags being read or memory corruption for the process that is > using the tag storage memory as data. > > Reserve tag storage by treating ptrace accesses like a fault. > > Signed-off-by: Alexandru Elisei > --- > > Changes since rfc v2: > > * New patch, issue reported by Peter Collingbourne. > > arch/arm64/kernel/mte.c | 26 ++++++++++++++++++++++++-- > 1 file changed, 24 insertions(+), 2 deletions(-) > > diff --git a/arch/arm64/kernel/mte.c b/arch/arm64/kernel/mte.c > index faf09da3400a..b1fa02dad4fd 100644 > --- a/arch/arm64/kernel/mte.c > +++ b/arch/arm64/kernel/mte.c > @@ -412,10 +412,13 @@ static int __access_remote_tags(struct mm_struct *mm, unsigned long addr, > while (len) { > struct vm_area_struct *vma; > unsigned long tags, offset; > + unsigned int fault_flags; > + struct page *page; > + vm_fault_t ret; > void *maddr; > - struct page *page = get_user_page_vma_remote(mm, addr, > - gup_flags, &vma); > > +get_page: > + page = get_user_page_vma_remote(mm, addr, gup_flags, &vma); But if there is valid page returned here in the first GUP attempt, will there still be a subsequent handle_mm_fault() on the same vma and addr ? > if (IS_ERR(page)) { > err = PTR_ERR(page); > break; > @@ -433,6 +436,25 @@ static int __access_remote_tags(struct mm_struct *mm, unsigned long addr, > put_page(page); > break; > } > + > + if (tag_storage_enabled() && !page_tag_storage_reserved(page)) { Should not '!page' be checked here as well ? > + fault_flags = FAULT_FLAG_DEFAULT | \ > + FAULT_FLAG_USER | \ > + FAULT_FLAG_REMOTE | \ > + FAULT_FLAG_ALLOW_RETRY | \ > + FAULT_FLAG_RETRY_NOWAIT; > + if (write) > + fault_flags |= FAULT_FLAG_WRITE; > + > + put_page(page); > + ret = handle_mm_fault(vma, addr, fault_flags, NULL); > + if (ret & VM_FAULT_ERROR) { > + err = -EFAULT; > + break; > + } > + goto get_page; > + } > + > WARN_ON_ONCE(!page_mte_tagged(page)); > > /* limit access to the end of the page */