From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org X-Spam-Level: X-Spam-Status: No, score=-14.4 required=3.0 tests=DKIMWL_WL_MED,DKIM_SIGNED, DKIM_VALID,DKIM_VALID_AU,HEADER_FROM_DIFFERENT_DOMAINS,INCLUDES_PATCH, MAILING_LIST_MULTI,SIGNED_OFF_BY,SPF_HELO_NONE,SPF_PASS,USER_IN_DEF_DKIM_WL autolearn=ham autolearn_force=no version=3.4.0 Received: from mail.kernel.org (mail.kernel.org [198.145.29.99]) by smtp.lore.kernel.org (Postfix) with ESMTP id BA59AC2D0EA for ; Wed, 8 Apr 2020 16:03:21 +0000 (UTC) Received: from kanga.kvack.org (kanga.kvack.org [205.233.56.17]) by mail.kernel.org (Postfix) with ESMTP id 7C26D2082F for ; Wed, 8 Apr 2020 16:03:21 +0000 (UTC) Authentication-Results: mail.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="DQr2P1wI" DMARC-Filter: OpenDMARC Filter v1.3.2 mail.kernel.org 7C26D2082F Authentication-Results: mail.kernel.org; dmarc=fail (p=reject dis=none) header.from=google.com Authentication-Results: mail.kernel.org; spf=pass smtp.mailfrom=owner-linux-mm@kvack.org Received: by kanga.kvack.org (Postfix) id 031868E000E; Wed, 8 Apr 2020 12:03:21 -0400 (EDT) Received: by kanga.kvack.org (Postfix, from userid 40) id F21238E0006; Wed, 8 Apr 2020 12:03:20 -0400 (EDT) X-Delivered-To: int-list-linux-mm@kvack.org Received: by kanga.kvack.org (Postfix, from userid 63042) id E0F688E000E; Wed, 8 Apr 2020 12:03:20 -0400 (EDT) X-Delivered-To: linux-mm@kvack.org Received: from forelay.hostedemail.com (smtprelay0089.hostedemail.com [216.40.44.89]) by kanga.kvack.org (Postfix) with ESMTP id C35A68E0006 for ; Wed, 8 Apr 2020 12:03:20 -0400 (EDT) Received: from smtpin12.hostedemail.com (10.5.19.251.rfc1918.com [10.5.19.251]) by forelay03.hostedemail.com (Postfix) with ESMTP id 81B2B80170C6 for ; Wed, 8 Apr 2020 16:03:20 +0000 (UTC) X-FDA: 76685157360.12.party03_746e22b65e562 X-HE-Tag: party03_746e22b65e562 X-Filterd-Recvd-Size: 6775 Received: from mail-pg1-f193.google.com (mail-pg1-f193.google.com [209.85.215.193]) by imf27.hostedemail.com (Postfix) with ESMTP for ; Wed, 8 Apr 2020 16:03:19 +0000 (UTC) Received: by mail-pg1-f193.google.com with SMTP id c23so3521904pgj.3 for ; Wed, 08 Apr 2020 09:03:19 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20161025; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=lJ7L4g5z00swgIarS2Gg66y01Ub7DERcxKnaSrpYlWg=; b=DQr2P1wI52plMIyopH2BpCvVbjrFQ+83br92KFdnnBVkA22YyUv/MjNTCYTNQrgFp3 s90kMBvRn+wuWZgqeJSxyavKj5vUtwwjf78rCm+TdGQhehTjjXA94E+Ts/5OaBbNcNNA zNVfb2avyxrpeYLyWNYefEm+hJhBqYQgRC3h/fNl4hMxqAdT7i++mGm2jtwipJV9TLX4 FlpgBZ4jc9dbzHEUG0OFaAleqjqeQqCwxedskWJkb32BqeUQVZNGvlPbHi4V5WwzQkDW kfrksj6zZgXuyUbKOFtAgmuGra+0tjDUF1av7I/O2UHssByHEoYAn8M5KSpib2q7O4hS 81Gw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=lJ7L4g5z00swgIarS2Gg66y01Ub7DERcxKnaSrpYlWg=; b=Qjwc8N6awlfRh1O7D3Lsu1tKfhFMYwBSldeSJ/7pdHWngheX0dZ14mb0bTf/Fb8w8u AlbaK82JN/28GI2l6OTv8okxdFLoGU0A722Fv7tBQkv/gp3BORGNuKp47Xp51A2EHb+/ vbx7b7wxCCpm2yQ7i+PE3Qegl7ABQui6COrxmq2Mxtonyt1hgakWGdGlGWN/G0W6PGzT gbzuxp6xzXXilFsOon/gNecjasm41gRgvjTLsU7SbsU4vRt03X6wpTa0A24S1vUhU11Z E+VDT3Jz93JwBypeM3/+yA3+oMzSKu0GZVDKGBbG8JIZSnGm4slgVWhH+Flq1TjT01W/ rxWA== X-Gm-Message-State: AGi0PubySvi5oWhBBovzgbDKj7chjnTnr/r4ETkpWLAu015btOVpzCZS nTohCe/Dodfnufpu4CSYRaHsSuoKnF/Wte7tnv1OQg== X-Google-Smtp-Source: APiQypJQiGS6BY5Z65Y4pK+dZWoJtXrNVkwh8I+2xg18v8mCIOIMONDKN98P85Q4n3Jw3u6VKGbvTPz8pkmEpLHdD3o= X-Received: by 2002:aa7:8183:: with SMTP id g3mr7993719pfi.306.1586361798561; Wed, 08 Apr 2020 09:03:18 -0700 (PDT) MIME-Version: 1.0 References: <20200325161249.55095-1-glider@google.com> <20200325161249.55095-31-glider@google.com> In-Reply-To: <20200325161249.55095-31-glider@google.com> From: Andrey Konovalov Date: Wed, 8 Apr 2020 18:03:07 +0200 Message-ID: Subject: Re: [PATCH v5 30/38] kmsan: handle /dev/[u]random To: Alexander Potapenko Cc: Andrew Morton , Jens Axboe , "Theodore Ts'o" , Dmitry Torokhov , "Martin K. Petersen" , "Michael S. Tsirkin" , Christoph Hellwig , Eric Dumazet , Eric Van Hensbergen , Takashi Iwai , Vegard Nossum , Dmitry Vyukov , Marco Elver , Matthew Wilcox , Linux Memory Management List , Alexander Viro , Andreas Dilger , Andrey Ryabinin , Andy Lutomirski , Ard Biesheuvel , Arnd Bergmann , Christoph Hellwig , "Darrick J. Wong" , "David S. Miller" , Eric Biggers , Greg Kroah-Hartman , Harry Wentland , Herbert Xu , Ilya Leoshkevich , Ingo Molnar , Jason Wang , Marek Szyprowski , Mark Rutland , Martin Schwidefsky , Michal Hocko , Michal Simek , Petr Mladek , Qian Cai , Randy Dunlap , Robin Murphy , Sergey Senozhatsky , Steven Rostedt , Thomas Gleixner , Vasily Gorbik , Wolfram Sang Content-Type: text/plain; charset="UTF-8" X-Bogosity: Ham, tests=bogofilter, spamicity=0.000000, version=1.2.4 Sender: owner-linux-mm@kvack.org Precedence: bulk X-Loop: owner-majordomo@kvack.org List-ID: On Wed, Mar 25, 2020 at 5:14 PM wrote: > > The random number generator may use uninitialized memory, but it may not > return uninitialized values. Unpoison the output buffer in > _extract_crng() to prevent false reports. > > Signed-off-by: Alexander Potapenko > To: Alexander Potapenko > Cc: Andrew Morton > Cc: Jens Axboe > Cc: "Theodore Ts'o" > Cc: Dmitry Torokhov > Cc: Martin K. Petersen > Cc: "Michael S. Tsirkin" > Cc: Christoph Hellwig > Cc: Eric Dumazet > Cc: Eric Van Hensbergen > Cc: Takashi Iwai > Cc: Vegard Nossum > Cc: Dmitry Vyukov > Cc: Marco Elver > Cc: Andrey Konovalov > Cc: Matthew Wilcox > Cc: linux-mm@kvack.org Reviewed-by: Andrey Konovalov > > --- > This patch was previously known as "kmsan: unpoisoning buffers from > devices etc.", but it turned out to be possible to drop most of the > annotations from that patch, so it only relates to /dev/random now. > > Change-Id: Id460e7a86ce564f1357469f53d0c7410ca08f0e9 > --- > drivers/char/random.c | 6 ++++++ > 1 file changed, 6 insertions(+) > > diff --git a/drivers/char/random.c b/drivers/char/random.c > index 0d10e31fd342f..7cd36c726b045 100644 > --- a/drivers/char/random.c > +++ b/drivers/char/random.c > @@ -322,6 +322,7 @@ > #include > #include > #include > +#include > #include > #include > #include > @@ -1007,6 +1008,11 @@ static void _extract_crng(struct crng_state *crng, > spin_lock_irqsave(&crng->lock, flags); > if (arch_get_random_long(&v)) > crng->state[14] ^= v; > + /* > + * Regardless of where the random data comes from, KMSAN should treat > + * it as initialized. > + */ > + kmsan_unpoison_shadow(crng->state, sizeof(crng->state)); > chacha20_block(&crng->state[0], out); > if (crng->state[12] == 0) > crng->state[13]++; > -- > 2.25.1.696.g5e7596f4ac-goog >