From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org X-Spam-Level: X-Spam-Status: No, score=-11.3 required=3.0 tests=BAYES_00,DKIMWL_WL_MED, DKIM_SIGNED,DKIM_VALID,DKIM_VALID_AU,HEADER_FROM_DIFFERENT_DOMAINS, MAILING_LIST_MULTI,SPF_HELO_NONE,SPF_PASS,URIBL_BLOCKED,USER_IN_DEF_DKIM_WL autolearn=no autolearn_force=no version=3.4.0 Received: from mail.kernel.org (mail.kernel.org [198.145.29.99]) by smtp.lore.kernel.org (Postfix) with ESMTP id 7419FC43457 for ; Fri, 16 Oct 2020 15:52:57 +0000 (UTC) Received: from kanga.kvack.org (kanga.kvack.org [205.233.56.17]) by mail.kernel.org (Postfix) with ESMTP id CE55B21D41 for ; Fri, 16 Oct 2020 15:52:56 +0000 (UTC) Authentication-Results: mail.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="odYcfxCn" DMARC-Filter: OpenDMARC Filter v1.3.2 mail.kernel.org CE55B21D41 Authentication-Results: mail.kernel.org; dmarc=fail (p=reject dis=none) header.from=google.com Authentication-Results: mail.kernel.org; spf=pass smtp.mailfrom=owner-linux-mm@kvack.org Received: by kanga.kvack.org (Postfix) id 1E3846B0073; Fri, 16 Oct 2020 11:52:56 -0400 (EDT) Received: by kanga.kvack.org (Postfix, from userid 40) id 195276B0074; Fri, 16 Oct 2020 11:52:56 -0400 (EDT) X-Delivered-To: int-list-linux-mm@kvack.org Received: by kanga.kvack.org (Postfix, from userid 63042) id 082876B0075; Fri, 16 Oct 2020 11:52:56 -0400 (EDT) X-Delivered-To: linux-mm@kvack.org Received: from forelay.hostedemail.com (smtprelay0239.hostedemail.com [216.40.44.239]) by kanga.kvack.org (Postfix) with ESMTP id CD4236B0073 for ; Fri, 16 Oct 2020 11:52:55 -0400 (EDT) Received: from smtpin22.hostedemail.com (10.5.19.251.rfc1918.com [10.5.19.251]) by forelay01.hostedemail.com (Postfix) with ESMTP id 44AE1180AD807 for ; Fri, 16 Oct 2020 15:52:55 +0000 (UTC) X-FDA: 77378231910.22.form91_5f0e91a2721e Received: from filter.hostedemail.com (10.5.16.251.rfc1918.com [10.5.16.251]) by smtpin22.hostedemail.com (Postfix) with ESMTP id 1E08B18038E68 for ; Fri, 16 Oct 2020 15:52:55 +0000 (UTC) X-HE-Tag: form91_5f0e91a2721e X-Filterd-Recvd-Size: 5463 Received: from mail-pj1-f68.google.com (mail-pj1-f68.google.com [209.85.216.68]) by imf36.hostedemail.com (Postfix) with ESMTP for ; Fri, 16 Oct 2020 15:52:54 +0000 (UTC) Received: by mail-pj1-f68.google.com with SMTP id a1so1754826pjd.1 for ; Fri, 16 Oct 2020 08:52:54 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20161025; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=3kC6Vgkm0RSxbZXaUeBWqyQrYh34yUHxn1mWSex6aQg=; b=odYcfxCnyO63/MjMhL7cfs6jP1gja2pd9uJY5C3fTUJvDuBt0YH3tRVq2JKVNtzeCI D8vfHkPSsL6N9G38+hY4l/69kTSE47p7QnVn6NZrEQqPwtkJgl4oXDQUJdkA6FXqSgBs bE82uQBBlxMgsk3ztKAXTZm0cBg8H8ZOVMpPl6yAIPq8nqdbCIUi4sPLe0vPV4stzKaE XitSrlYOTBRuvkq5vqUx1CfWPy1tH+knwUMt365htcT6qN0bcO8BI/WVt4aioRIDEo71 fJNGIEGke2MNKIf89Zef56tb0PVAWGgJESO4H/AI65+Zrny/Gy6A7UglDOlZ6PABluYl 8cXQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=3kC6Vgkm0RSxbZXaUeBWqyQrYh34yUHxn1mWSex6aQg=; b=ThXYdmcOYr9XDsjzBwJBbGFya1XUDW2WwL0zna9fS9LapALgNifz20y6S8SPSpyUl9 kvdSyAJapxnQ0oEuV3v6apgRhOv/nJe6pZLAKbSsrbXUUK1zRXD8nY15m/Uj8XpY75qD lJ7Z8mMblJkqh7TQKNtjb4+a//QZC4Mndd1tY3FElTngZjOhKkaajzxE/jJ7InMN3RAQ 65xu+i+AvQD2HP8T6oIFbeZF2gppdliMwQxRwkXV5NUuiRmjCayMAEFyglQLaRa7C3RH S3giJ3BJTYNFBnl90q9fIpAqzME2b+QXum+fPOG9L1GmAR0sBVyn59qfmjcRVkcqXYXO HhlQ== X-Gm-Message-State: AOAM533RzRtLKok5jpN2S0eCy6tx/s2MqbkX5OgV55qTeTxNI4gHpc4a YsOg0mj9mH1IpZ36F9Pqie5f6gLE1lZq2F6WFzex2g== X-Google-Smtp-Source: ABdhPJzKFeWn8NGVQGEWxrgVRNhUiZShFKnnEiZzZe+Jnc142Ha42SGDGOCAYbMH9nbVAab1yfOBMAbJHsGnjAJlvv8= X-Received: by 2002:a17:902:5992:b029:d5:c794:3595 with SMTP id p18-20020a1709025992b02900d5c7943595mr3319246pli.57.1602863573590; Fri, 16 Oct 2020 08:52:53 -0700 (PDT) MIME-Version: 1.0 References: In-Reply-To: From: Andrey Konovalov Date: Fri, 16 Oct 2020 17:52:42 +0200 Message-ID: Subject: Re: [PATCH RFC 0/8] kasan: hardware tag-based mode for production use on arm64 To: Kostya Serebryany , Serban Constantinescu Cc: Catalin Marinas , Will Deacon , Vincenzo Frascino , Dmitry Vyukov , Alexander Potapenko , Evgenii Stepanov , Andrey Ryabinin , Elena Petrova , Branislav Rankov , Kevin Brodsky , Andrew Morton , kasan-dev , Linux ARM , Linux Memory Management List , LKML , Marco Elver Content-Type: text/plain; charset="UTF-8" X-Bogosity: Ham, tests=bogofilter, spamicity=0.000000, version=1.2.4 Sender: owner-linux-mm@kvack.org Precedence: bulk X-Loop: owner-majordomo@kvack.org List-ID: On Fri, Oct 16, 2020 at 3:31 PM Marco Elver wrote: > > On Fri, 16 Oct 2020 at 15:17, 'Andrey Konovalov' via kasan-dev > wrote: > [...] > > > > The intention with this kind of a high level switch is to hide the > > > > implementation details. Arguably, we could add multiple switches that allow > > > > to separately control each KASAN or MTE feature, but I'm not sure there's > > > > much value in that. > > > > > > > > Does this make sense? Any preference regarding the name of the parameter > > > > and its values? > > > > > > KASAN itself used to be a debugging tool only. So introducing an "on" > > > mode which no longer follows this convention may be confusing. > > > > Yeah, perhaps "on" is not the best name here. > > > > > Instead, maybe the following might be less confusing: > > > > > > "full" - current "debug", normal KASAN, all debugging help available. > > > "opt" - current "on", optimized mode for production. > > > > How about "prod" here? > > SGTM. > > [...] > > > > > > Should we somehow control whether to panic the kernel on a tag fault? > > > > Another boot time parameter perhaps? > > > > > > It already respects panic_on_warn, correct? > > > > Yes, but Android is unlikely to enable panic_on_warn as they have > > warnings happening all over. AFAIR Pixel 3/4 kernels actually have a > > custom patch that enables kernel panic for KASAN crashes specifically > > (even though they don't obviously use KASAN in production), and I > > think it's better to provide a similar facility upstream. Maybe call > > it panic_on_kasan or something? > > Best would be if kasan= can take another option, e.g. > "kasan=prod,panic". I think you can change the strcmp() to a > str_has_prefix() for the checks for full/prod/on/off, and then check > if what comes after it is ",panic". > > Thanks, > -- Marco CC Kostya and Serban.