From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org X-Spam-Level: X-Spam-Status: No, score=-14.4 required=3.0 tests=DKIMWL_WL_MED,DKIM_SIGNED, DKIM_VALID,DKIM_VALID_AU,HEADER_FROM_DIFFERENT_DOMAINS,INCLUDES_PATCH, MAILING_LIST_MULTI,SIGNED_OFF_BY,SPF_HELO_NONE,SPF_PASS,USER_IN_DEF_DKIM_WL autolearn=ham autolearn_force=no version=3.4.0 Received: from mail.kernel.org (mail.kernel.org [198.145.29.99]) by smtp.lore.kernel.org (Postfix) with ESMTP id 2A09EC43215 for ; Fri, 29 Nov 2019 15:07:43 +0000 (UTC) Received: from kanga.kvack.org (kanga.kvack.org [205.233.56.17]) by mail.kernel.org (Postfix) with ESMTP id C163F216F4 for ; Fri, 29 Nov 2019 15:07:42 +0000 (UTC) Authentication-Results: mail.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="kAittuPH" DMARC-Filter: OpenDMARC Filter v1.3.2 mail.kernel.org C163F216F4 Authentication-Results: mail.kernel.org; dmarc=fail (p=reject dis=none) header.from=google.com Authentication-Results: mail.kernel.org; spf=pass smtp.mailfrom=owner-linux-mm@kvack.org Received: by kanga.kvack.org (Postfix) id 6952C6B0599; Fri, 29 Nov 2019 10:07:42 -0500 (EST) Received: by kanga.kvack.org (Postfix, from userid 40) id 646A86B059A; Fri, 29 Nov 2019 10:07:42 -0500 (EST) X-Delivered-To: int-list-linux-mm@kvack.org Received: by kanga.kvack.org (Postfix, from userid 63042) id 535D16B059B; Fri, 29 Nov 2019 10:07:42 -0500 (EST) X-Delivered-To: linux-mm@kvack.org Received: from forelay.hostedemail.com (smtprelay0214.hostedemail.com [216.40.44.214]) by kanga.kvack.org (Postfix) with ESMTP id 3D1C06B0599 for ; Fri, 29 Nov 2019 10:07:42 -0500 (EST) Received: from smtpin10.hostedemail.com (10.5.19.251.rfc1918.com [10.5.19.251]) by forelay03.hostedemail.com (Postfix) with SMTP id E338E824D196 for ; Fri, 29 Nov 2019 15:07:41 +0000 (UTC) X-FDA: 76209644322.10.twig10_8d6eed8dc85c X-HE-Tag: twig10_8d6eed8dc85c X-Filterd-Recvd-Size: 11162 Received: from mail-pg1-f194.google.com (mail-pg1-f194.google.com [209.85.215.194]) by imf36.hostedemail.com (Postfix) with ESMTP for ; Fri, 29 Nov 2019 15:07:40 +0000 (UTC) Received: by mail-pg1-f194.google.com with SMTP id x8so766262pgk.8 for ; Fri, 29 Nov 2019 07:07:40 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20161025; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=MpsYk/F/beinhSYgUQbUncSMA98O5C0hWXKlu6y2xxs=; b=kAittuPH6RVoEM02CV/N+/d7cRJXIwkRjtcuUOylbM6kAqCtUbpJSMLRnWZqbh2e2s B2Hu1tBxXgbxIN14VGYF7fZH9PanYOUcOAzUsIWo4c+Kx4i++ZxiLolqnYtiIkfV6KHl XD/dyIE/3iEIGaU06nQv8hHlChF/iEmq7m40RTL7vkA+ZiuSKcBgJThXp8kNSC4K+1oB MHgFazKRed2ZMCCaroipEcU0rVUnCRvu6q0u69Wy6cDuTYc1mKyltLa3J9mUca6rgtGs ztcnehYSLn99Lp1JlbRd5tRRkPH03GlVvdKdet6N5D7naSHQ7c7CC6EqTr1xjk822I90 Skyg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=MpsYk/F/beinhSYgUQbUncSMA98O5C0hWXKlu6y2xxs=; b=RE+cuFOXZr5YBTW2lmuQRFbco47v5yqe/yopmhnUQVieDAKBesL22NXHvuPyQXYPV8 b8F7O5228iGqq5l9kEkeigDKtd7RGL/hgLyLcf0R2XlM4yC7bSZ3xilsIt/dIhRiQD95 j9OyuizsTCFxynwQpchEiQRGz+e5qqSNUq6+nYCJGWtPLvwdp4VC+MmqSsvSztwPtLo2 zYrgpNPiMBWnu10bD2D/YBvoojtvy390LhlKSp2pmUiCDdzXaA6ITYCPFA+k9AL2BD+P BPmm3rZTfv4lrzDESbzc/YhBOgeZ2sfNq+4Ki5pYYuGpbj27gYQGsFFOvSAILmdEiBt4 xqMA== X-Gm-Message-State: APjAAAWJG8B6R0o2eMfzksU/wazFEvQnoVpJM2u1kQ1sQAS6vvezjbhw ACeh3tiRY5Foee7gjST5mhUoukXvoW7onAgTzzANdw== X-Google-Smtp-Source: APXvYqzFyXlWCOjLbTW6h388TLVodVzAlqOmiYkNdyoN9wJRhwKokyTmcIkmpf/OnYlV+tKTGsLCEuHzmQtAIrxc1H4= X-Received: by 2002:a62:53c6:: with SMTP id h189mr57580228pfb.93.1575040059121; Fri, 29 Nov 2019 07:07:39 -0800 (PST) MIME-Version: 1.0 References: <20191122112621.204798-1-glider@google.com> <20191122112621.204798-22-glider@google.com> In-Reply-To: <20191122112621.204798-22-glider@google.com> From: Andrey Konovalov Date: Fri, 29 Nov 2019 16:07:28 +0100 Message-ID: Subject: Re: [PATCH RFC v3 21/36] kmsan: disable KMSAN instrumentation for certain kernel parts To: Alexander Potapenko Cc: Ard Biesheuvel , Thomas Gleixner , Vegard Nossum , Dmitry Vyukov , Linux Memory Management List , Alexander Viro , Andreas Dilger , Andrew Morton , Andrey Ryabinin , Andy Lutomirski , Arnd Bergmann , Christoph Hellwig , Christoph Hellwig , darrick.wong@oracle.com, "David S. Miller" , Dmitry Torokhov , Eric Biggers , Eric Dumazet , ericvh@gmail.com, Greg Kroah-Hartman , harry.wentland@amd.com, Herbert Xu , iii@linux.ibm.com, mingo@elte.hu, Jason Wang , Jens Axboe , Marek Szyprowski , Marco Elver , Mark Rutland , "Martin K. Petersen" , Martin Schwidefsky , Matthew Wilcox , "Michael S . Tsirkin" , Michal Simek , pmladek@suse.com, Qian Cai , Randy Dunlap , Robin Murphy , sergey.senozhatsky@gmail.com, Steven Rostedt , Takashi Iwai , "Theodore Ts'o" , gor@linux.ibm.com, wsa@the-dreams.de Content-Type: text/plain; charset="UTF-8" X-Bogosity: Ham, tests=bogofilter, spamicity=0.000000, version=1.2.4 Sender: owner-linux-mm@kvack.org Precedence: bulk X-Loop: owner-majordomo@kvack.org List-ID: On Fri, Nov 22, 2019 at 12:27 PM wrote: > > Instrumenting some files with KMSAN will result in kernel being unable > to link, boot or crashing at runtime for various reasons (e.g. infinite > recursion caused by instrumentation hooks calling instrumented code again). > > Disable KMSAN in the following places: > - arch/x86/boot and arch/x86/realmode/rm, as KMSAN doesn't work for i386; > - arch/x86/entry/vdso, which isn't linked with KMSAN runtime; > - three files in arch/x86/kernel - boot problems; > - arch/x86/mm/cpu_entry_area.c - recursion; > - EFI stub - build failures; > - kcov, stackdepot - recursion. It makes sense to unify comments explaining the reasons for KMSAN_SANITIZE := n with KCSAN patches: https://patchwork.kernel.org/patch/11244145/ https://patchwork.kernel.org/patch/11244161/ > > Signed-off-by: Alexander Potapenko > To: Alexander Potapenko > Cc: Ard Biesheuvel > Cc: Thomas Gleixner > Cc: Vegard Nossum > Cc: Dmitry Vyukov > Cc: linux-mm@kvack.org > --- > > Change-Id: I90961eabf2dcb9ae992aed259088953bad5e4d6d > --- > arch/x86/boot/Makefile | 2 ++ > arch/x86/boot/compressed/Makefile | 2 ++ > arch/x86/entry/vdso/Makefile | 3 +++ > arch/x86/kernel/Makefile | 4 ++++ > arch/x86/kernel/cpu/Makefile | 1 + > arch/x86/mm/Makefile | 2 ++ > arch/x86/realmode/rm/Makefile | 2 ++ > drivers/firmware/efi/libstub/Makefile | 1 + > kernel/Makefile | 1 + > lib/Makefile | 1 + > 10 files changed, 19 insertions(+) > > diff --git a/arch/x86/boot/Makefile b/arch/x86/boot/Makefile > index e2839b5c246c..c039abd4c81f 100644 > --- a/arch/x86/boot/Makefile > +++ b/arch/x86/boot/Makefile > @@ -10,6 +10,8 @@ > # > > KASAN_SANITIZE := n > +# KMSAN doesn't work for i386 > +KMSAN_SANITIZE := n > OBJECT_FILES_NON_STANDARD := y > > # Kernel does not boot with kcov instrumentation here. > diff --git a/arch/x86/boot/compressed/Makefile b/arch/x86/boot/compressed/Makefile > index 6b84afdd7538..9efe2d9fca4c 100644 > --- a/arch/x86/boot/compressed/Makefile > +++ b/arch/x86/boot/compressed/Makefile > @@ -18,6 +18,8 @@ > # compressed vmlinux.bin.all + u32 size of vmlinux.bin.all > > KASAN_SANITIZE := n > +# KMSAN doesn't work for i386 > +KMSAN_SANITIZE := n > OBJECT_FILES_NON_STANDARD := y > > # Prevents link failures: __sanitizer_cov_trace_pc() is not linked in. > diff --git a/arch/x86/entry/vdso/Makefile b/arch/x86/entry/vdso/Makefile > index 0f2154106d01..000467a1a4f2 100644 > --- a/arch/x86/entry/vdso/Makefile > +++ b/arch/x86/entry/vdso/Makefile > @@ -11,6 +11,9 @@ include $(srctree)/lib/vdso/Makefile > > KBUILD_CFLAGS += $(DISABLE_LTO) > KASAN_SANITIZE := n > +# Undefined references to KMSAN hooks. > +KMSAN_SANITIZE_vclock_gettime.o := n > +KMSAN_SANITIZE_vgetcpu.o := n > UBSAN_SANITIZE := n > OBJECT_FILES_NON_STANDARD := y > > diff --git a/arch/x86/kernel/Makefile b/arch/x86/kernel/Makefile > index 3578ad248bc9..ce39972a7edf 100644 > --- a/arch/x86/kernel/Makefile > +++ b/arch/x86/kernel/Makefile > @@ -28,6 +28,10 @@ KASAN_SANITIZE_dumpstack_$(BITS).o := n > KASAN_SANITIZE_stacktrace.o := n > KASAN_SANITIZE_paravirt.o := n > > +# Work around reboot loop. > +KMSAN_SANITIZE_head$(BITS).o := n > +KMSAN_SANITIZE_nmi.o := n > + > OBJECT_FILES_NON_STANDARD_relocate_kernel_$(BITS).o := y > OBJECT_FILES_NON_STANDARD_test_nx.o := y > OBJECT_FILES_NON_STANDARD_paravirt_patch.o := y > diff --git a/arch/x86/kernel/cpu/Makefile b/arch/x86/kernel/cpu/Makefile > index d7a1e5a9331c..41f4f8f2f2f0 100644 > --- a/arch/x86/kernel/cpu/Makefile > +++ b/arch/x86/kernel/cpu/Makefile > @@ -12,6 +12,7 @@ endif > # If these files are instrumented, boot hangs during the first second. > KCOV_INSTRUMENT_common.o := n > KCOV_INSTRUMENT_perf_event.o := n > +KMSAN_SANITIZE_common.o := n > > # Make sure load_percpu_segment has no stackprotector > nostackp := $(call cc-option, -fno-stack-protector) > diff --git a/arch/x86/mm/Makefile b/arch/x86/mm/Makefile > index 84373dc9b341..42cb3a6409b0 100644 > --- a/arch/x86/mm/Makefile > +++ b/arch/x86/mm/Makefile > @@ -7,6 +7,8 @@ KCOV_INSTRUMENT_mem_encrypt_identity.o := n > KASAN_SANITIZE_mem_encrypt.o := n > KASAN_SANITIZE_mem_encrypt_identity.o := n > > +KMSAN_SANITIZE_cpu_entry_area.o := n > + > ifdef CONFIG_FUNCTION_TRACER > CFLAGS_REMOVE_mem_encrypt.o = -pg > CFLAGS_REMOVE_mem_encrypt_identity.o = -pg > diff --git a/arch/x86/realmode/rm/Makefile b/arch/x86/realmode/rm/Makefile > index f60501a384f9..27e7bc0bbdde 100644 > --- a/arch/x86/realmode/rm/Makefile > +++ b/arch/x86/realmode/rm/Makefile > @@ -7,6 +7,8 @@ > # > # > KASAN_SANITIZE := n > +# KMSAN doesn't work for i386 > +KMSAN_SANITIZE := n > OBJECT_FILES_NON_STANDARD := y > > # Prevents link failures: __sanitizer_cov_trace_pc() is not linked in. > diff --git a/drivers/firmware/efi/libstub/Makefile b/drivers/firmware/efi/libstub/Makefile > index 0460c7581220..11869c17a64c 100644 > --- a/drivers/firmware/efi/libstub/Makefile > +++ b/drivers/firmware/efi/libstub/Makefile > @@ -32,6 +32,7 @@ KBUILD_CFLAGS := $(cflags-y) -DDISABLE_BRANCH_PROFILING \ > > GCOV_PROFILE := n > KASAN_SANITIZE := n > +KMSAN_SANITIZE := n > UBSAN_SANITIZE := n > OBJECT_FILES_NON_STANDARD := y > > diff --git a/kernel/Makefile b/kernel/Makefile > index daad787fb795..5fd6fbca2592 100644 > --- a/kernel/Makefile > +++ b/kernel/Makefile > @@ -30,6 +30,7 @@ KCOV_INSTRUMENT_extable.o := n > # Don't self-instrument. > KCOV_INSTRUMENT_kcov.o := n > KASAN_SANITIZE_kcov.o := n > +KMSAN_SANITIZE_kcov.o := n > CFLAGS_kcov.o := $(call cc-option, -fno-conserve-stack -fno-stack-protector) > > # cond_syscall is currently not LTO compatible > diff --git a/lib/Makefile b/lib/Makefile > index 08fcb37499a0..ae6e57d857b0 100644 > --- a/lib/Makefile > +++ b/lib/Makefile > @@ -222,6 +222,7 @@ obj-$(CONFIG_IRQ_POLL) += irq_poll.o > CFLAGS_stackdepot.o += -fno-builtin > obj-$(CONFIG_STACKDEPOT) += stackdepot.o > KASAN_SANITIZE_stackdepot.o := n > +KMSAN_SANITIZE_stackdepot.o := n > KCOV_INSTRUMENT_stackdepot.o := n > > libfdt_files = fdt.o fdt_ro.o fdt_wip.o fdt_rw.o fdt_sw.o fdt_strerror.o \ > -- > 2.24.0.432.g9d3f5f5b63-goog >