linux-mm.kvack.org archive mirror
 help / color / mirror / Atom feed
From: Alexander Potapenko <glider@google.com>
To: "Kirill A. Shutemov" <kirill.shutemov@linux.intel.com>
Cc: Dave Hansen <dave.hansen@linux.intel.com>,
	Andy Lutomirski <luto@kernel.org>,
	 Peter Zijlstra <peterz@infradead.org>,
	"the arch/x86 maintainers" <x86@kernel.org>,
	 Kostya Serebryany <kcc@google.com>,
	Andrey Ryabinin <ryabinin.a.a@gmail.com>,
	 Andrey Konovalov <andreyknvl@gmail.com>,
	Dmitry Vyukov <dvyukov@google.com>,
	 "H . J . Lu" <hjl.tools@gmail.com>,
	Andi Kleen <ak@linux.intel.com>,
	 Rick Edgecombe <rick.p.edgecombe@intel.com>,
	 Linux Memory Management List <linux-mm@kvack.org>,
	LKML <linux-kernel@vger.kernel.org>
Subject: Re: [PATCHv4 3/8] mm: Pass down mm_struct to untagged_addr()
Date: Thu, 7 Jul 2022 10:56:53 +0200	[thread overview]
Message-ID: <CAG_fn=Ut8OaQ40VmNvG8HtJ7Cb4M03ce3ihFPrmj+PNQB0tF3A@mail.gmail.com> (raw)
In-Reply-To: <20220706231349.4ghhewbfpzjln56u@black.fi.intel.com>

On Thu, Jul 7, 2022 at 1:14 AM Kirill A. Shutemov
<kirill.shutemov@linux.intel.com> wrote:
>
> On Tue, Jul 05, 2022 at 05:42:21PM +0200, Alexander Potapenko wrote:
> > Kirill,
> >
> >
> > > diff --git a/lib/strnlen_user.c b/lib/strnlen_user.c
> > > index feeb935a2299..abc096a68f05 100644
> > > --- a/lib/strnlen_user.c
> > > +++ b/lib/strnlen_user.c
> > > @@ -97,7 +97,7 @@ long strnlen_user(const char __user *str, long count)
> > >                 return 0;
> > >
> > >         max_addr = TASK_SIZE_MAX;
> > > -       src_addr = (unsigned long)untagged_addr(str);
> > > +       src_addr = (unsigned long)untagged_addr(current->mm, str);
> >
> > In a downstream kernel with LAM disabled I'm seeing current->mm being
> > NULL at this point, because strnlen_user() is being called by
> > kdevtmpfs.
> > IIUC current->mm is only guaranteed to be non-NULL in the userspace
> > process context, whereas untagged_addr() may get called in random
> > places.
> >
> > Am I missing something?
>
> Hm. Could you show a traceback?
>
> As strnlen_user() intended to be used on an user string I expected it to
> be called from a process context. I guess I'm wrong, but I don't yet
> understand why.

Oh, I see now. The old implementation of devtmpfsd()
(https://elixir.bootlin.com/linux/v5.4/source/drivers/base/devtmpfs.c#L397)
uses ksys_mount(), which assumes that the strings must be copied from
the userspace, whereas they are actually constants in kernel .rodata

Wonder if the validity of mm->current for userspace accesses is
actually enforced anyhow in newer kernels.

> --
>  Kirill A. Shutemov



-- 
Alexander Potapenko
Software Engineer

Google Germany GmbH
Erika-Mann-Straße, 33
80636 München

Geschäftsführer: Paul Manicle, Liana Sebastian
Registergericht und -nummer: Hamburg, HRB 86891
Sitz der Gesellschaft: Hamburg


  reply	other threads:[~2022-07-07  8:57 UTC|newest]

Thread overview: 19+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2022-06-22 16:22 [PATCHv4 0/8] Linear Address Masking enabling Kirill A. Shutemov
2022-06-22 16:22 ` [PATCHv4 1/8] x86/mm: Fix CR3_ADDR_MASK Kirill A. Shutemov
2022-06-22 16:22 ` [PATCHv4 2/8] x86: CPUID and CR3/CR4 flags for Linear Address Masking Kirill A. Shutemov
2022-06-22 16:22 ` [PATCHv4 3/8] mm: Pass down mm_struct to untagged_addr() Kirill A. Shutemov
2022-07-05 15:42   ` Alexander Potapenko
2022-07-06 23:13     ` Kirill A. Shutemov
2022-07-07  8:56       ` Alexander Potapenko [this message]
2022-07-07 11:58         ` Kirill A. Shutemov
2022-06-22 16:22 ` [PATCHv4 4/8] x86/mm: Handle LAM on context switch Kirill A. Shutemov
2022-06-30  8:36   ` Alexander Potapenko
2022-06-22 16:22 ` [PATCHv4 5/8] x86/uaccess: Provide untagged_addr() and remove tags before address check Kirill A. Shutemov
2022-06-22 16:22 ` [PATCHv4 6/8] x86/mm: Provide ARCH_GET_UNTAG_MASK and ARCH_ENABLE_TAGGED_ADDR Kirill A. Shutemov
2022-07-12 13:12   ` Alexander Potapenko
2022-07-12 17:14     ` Kirill A. Shutemov
2022-07-14 14:28       ` Alexander Potapenko
2022-07-14 18:12         ` Kirill A. Shutemov
2022-06-22 16:22 ` [PATCHv4 7/8] x86: Expose untagging mask in /proc/$PID/arch_status Kirill A. Shutemov
2022-06-22 16:22 ` [PATCHv4 OPTIONAL 8/8] x86/mm: Extend LAM to support to LAM_U48 Kirill A. Shutemov
2022-06-30 10:06   ` Alexander Potapenko

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to='CAG_fn=Ut8OaQ40VmNvG8HtJ7Cb4M03ce3ihFPrmj+PNQB0tF3A@mail.gmail.com' \
    --to=glider@google.com \
    --cc=ak@linux.intel.com \
    --cc=andreyknvl@gmail.com \
    --cc=dave.hansen@linux.intel.com \
    --cc=dvyukov@google.com \
    --cc=hjl.tools@gmail.com \
    --cc=kcc@google.com \
    --cc=kirill.shutemov@linux.intel.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-mm@kvack.org \
    --cc=luto@kernel.org \
    --cc=peterz@infradead.org \
    --cc=rick.p.edgecombe@intel.com \
    --cc=ryabinin.a.a@gmail.com \
    --cc=x86@kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox