From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from kanga.kvack.org (kanga.kvack.org [205.233.56.17]) by smtp.lore.kernel.org (Postfix) with ESMTP id B597AC4345F for ; Mon, 15 Apr 2024 09:44:48 +0000 (UTC) Received: by kanga.kvack.org (Postfix) id 3AAD66B0089; Mon, 15 Apr 2024 05:44:48 -0400 (EDT) Received: by kanga.kvack.org (Postfix, from userid 40) id 35A0E6B009D; Mon, 15 Apr 2024 05:44:48 -0400 (EDT) X-Delivered-To: int-list-linux-mm@kvack.org Received: by kanga.kvack.org (Postfix, from userid 63042) id 221936B009E; Mon, 15 Apr 2024 05:44:48 -0400 (EDT) X-Delivered-To: linux-mm@kvack.org Received: from relay.hostedemail.com (smtprelay0012.hostedemail.com [216.40.44.12]) by kanga.kvack.org (Postfix) with ESMTP id 02E216B0089 for ; Mon, 15 Apr 2024 05:44:47 -0400 (EDT) Received: from smtpin19.hostedemail.com (a10.router.float.18 [10.200.18.1]) by unirelay05.hostedemail.com (Postfix) with ESMTP id B4F1B402E8 for ; Mon, 15 Apr 2024 09:44:47 +0000 (UTC) X-FDA: 82011281814.19.10CC8E7 Received: from mail-vk1-f175.google.com (mail-vk1-f175.google.com [209.85.221.175]) by imf30.hostedemail.com (Postfix) with ESMTP id 266F280012 for ; Mon, 15 Apr 2024 09:44:46 +0000 (UTC) Authentication-Results: imf30.hostedemail.com; dkim=pass header.d=google.com header.s=20230601 header.b=zU3o9oue; spf=pass (imf30.hostedemail.com: domain of aliceryhl@google.com designates 209.85.221.175 as permitted sender) smtp.mailfrom=aliceryhl@google.com; dmarc=pass (policy=reject) header.from=google.com ARC-Seal: i=1; s=arc-20220608; d=hostedemail.com; t=1713174286; a=rsa-sha256; cv=none; b=lHJmKNWSY0zAoJXeFJ8JJCd4Aq+mTjWztZ+U2bFB1JJY4WWrjDVVmIyalhqJF1oftvS1/R qeX1rgtbKRd3MpuvHatTJqhu5JymbBwdLxHW/GqkMHMzAawAQPVFkG/W/g7e2jb3DtLKoU OmBHWsuKRsm5nwmKNj9Mn5U0YeEyjzY= ARC-Authentication-Results: i=1; imf30.hostedemail.com; dkim=pass header.d=google.com header.s=20230601 header.b=zU3o9oue; spf=pass (imf30.hostedemail.com: domain of aliceryhl@google.com designates 209.85.221.175 as permitted sender) smtp.mailfrom=aliceryhl@google.com; dmarc=pass (policy=reject) header.from=google.com ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=hostedemail.com; s=arc-20220608; t=1713174286; h=from:from:sender:reply-to:subject:subject:date:date: message-id:message-id:to:to:cc:cc:mime-version:mime-version: content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references:dkim-signature; bh=CSLoiB2mZ+syImFaap979pBovjFFHgK5JL5uKJwM15M=; b=PRDhnUH66OK7FIk/vPXNHSJoVwn5Wy8WooGU2/Oi/AmlSq3ZSFLy9300QG9C8s01PwOZfp r8e57TRHDrccDVDCpLDeaLRyKmKTZfjZkaVfd06S6/35jIgWojM+8YikjuLWoTNRrOGjje lUlGasj+M+3kRedONl9jgXqnUt3zb9g= Received: by mail-vk1-f175.google.com with SMTP id 71dfb90a1353d-4dac3cbc8fdso1182858e0c.0 for ; Mon, 15 Apr 2024 02:44:45 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20230601; t=1713174285; x=1713779085; darn=kvack.org; h=content-transfer-encoding:cc:to:subject:message-id:date:from :in-reply-to:references:mime-version:from:to:cc:subject:date :message-id:reply-to; bh=CSLoiB2mZ+syImFaap979pBovjFFHgK5JL5uKJwM15M=; b=zU3o9oueW22IzbLuSWpiDlVrDXYWcU/tmz4VcllmELtMH1fd5Cv35WOk1NcthqORBf 5jKxgbV+vFvIqEFNxJ3p2Lb4kC3eZmn9EzmISD898dzE9KC8wMgM1yRVZYafCK4mAF8H ZyJjiqK9Z4g3DofKVmmahrPQ4lgw/qAIJV7m/CPDxbEylDLV8HIvnqjjdbyjFrC/3PeX eeHZ6es4VSDpyA80Pn1dsPuprD3bSMp7/+51FAwbj5nh+3ACfZHeVjE/vygmkXwsNa2e +EKCqT20kAwaRoiEXPUOEVWrMvjfKWB0Hj+sUuuSI4h/a/MdoB9xByF3AFKpsDY7HIee NBxw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1713174285; x=1713779085; h=content-transfer-encoding:cc:to:subject:message-id:date:from :in-reply-to:references:mime-version:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to; bh=CSLoiB2mZ+syImFaap979pBovjFFHgK5JL5uKJwM15M=; b=UH4kfU+q1NulL8mCf8PH7pk2gMk/VZ7o5ch+ltMw9Ypn1+8F/d6mHgJOdzfWhAX70x oFi5hBbcWHvspa8CARETMGWNxArXrQDfH8mIB3SOgRESAaNgPZ5tEmy0WoQdkoehsAnC 7aqS7QbfdfF3OK6TMDQO4ErMVO50C/sucEnpmirpujzgmx4nVON25NAMyYnoXJYAEDLb 0U/bVTjimdtE/YoFVLsK5KmSDw3bChLXE3xpkElKzDrp3JpcUKiJ1H6rbvysTVg0J7ut N3rIluQ2GWuTlvmlSs/1a4FZCVdVR1sCsz1hAKSvPXD8cPKq19bic76ZF9LB41HyWVYP nDfw== X-Forwarded-Encrypted: i=1; AJvYcCXHQ3kNAvLH3fwx4jOJa221DPdPVCZ/k1QG8GUzVP+i3oL08wX5G8rYT8oCYi2P+z0wElsKnj4kyq0AWtK1xdZgBII= X-Gm-Message-State: AOJu0YyuJMH4k3rry+QDJFlJY5FSs20SxSljgIdUpiEI23tqf3RMZ12H 4e/9Qlp8r3X3dZRTPps6/9/dLtbcJ7H94Igey4uJdqaP6E6kw9ksQnxWMbOZQZlTHp4Fdwryzan m5SPbWj5xdBmmOKqskTNT5pTvtKzjmJJyK6xo X-Google-Smtp-Source: AGHT+IEkhwcc26gJYhEUGK0Rz98TITLvdkASwy8xab0jVCJOyrzEUfOPadfPmhxaylFC0rFqS6AhEhBJ09WImT7Whzc= X-Received: by 2002:a05:6122:3681:b0:4d8:74a2:6d35 with SMTP id ec1-20020a056122368100b004d874a26d35mr7925511vkb.9.1713174285085; Mon, 15 Apr 2024 02:44:45 -0700 (PDT) MIME-Version: 1.0 References: <20240415-alice-mm-v5-0-6f55e4d8ef51@google.com> <20240415-alice-mm-v5-1-6f55e4d8ef51@google.com> <2cae6fd4-906c-44ad-88be-0dfed090d07c@proton.me> In-Reply-To: <2cae6fd4-906c-44ad-88be-0dfed090d07c@proton.me> From: Alice Ryhl Date: Mon, 15 Apr 2024 11:44:33 +0200 Message-ID: Subject: Re: [PATCH v5 1/4] rust: uaccess: add userspace pointers To: Benno Lossin Cc: Miguel Ojeda , Matthew Wilcox , Al Viro , Andrew Morton , Kees Cook , Alex Gaynor , Wedson Almeida Filho , Boqun Feng , Gary Guo , =?UTF-8?Q?Bj=C3=B6rn_Roy_Baron?= , Andreas Hindborg , Greg Kroah-Hartman , =?UTF-8?B?QXJ2ZSBIasO4bm5ldsOlZw==?= , Todd Kjos , Martijn Coenen , Joel Fernandes , Carlos Llamas , Suren Baghdasaryan , Arnd Bergmann , linux-mm@kvack.org, linux-kernel@vger.kernel.org, rust-for-linux@vger.kernel.org, Christian Brauner Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable X-Rspamd-Server: rspam08 X-Rspamd-Queue-Id: 266F280012 X-Stat-Signature: d3eqr4qhx9n49bpjasoa3ip1yrnyrmqw X-Rspam-User: X-HE-Tag: 1713174285-674760 X-HE-Meta: U2FsdGVkX1/a5vE8yD36MONRS5azdNhAUfhdNqPEkgRHSDOZ6qr0QSQMEFmP/fkjTettVLg1T6AMRpPURaeUsnzYfns7/o1j4YSWrXT0PrWxccVgcsmnWNLI2t46LFDcODRHDxDoWy7qENnbENm0MxMtKgUGLSxGP97ddOb+kBdqRTAA9OWSJggFtDvngA9Aw4NrMEUDKfoBhP7upoP98uut6oihyaFgZuFNuFX5thQbylGd64kYsTXoq3uWKBybOylZiwZk4yyrPpmOHs6NzufXKC7Yt0U6JvYhuZeDNEyBk/a7FNuowpe0N+o2VTI+aZN2f3DmaOAAEf8eNWhZjVA8Jch0/Im/k/1rg09PZY7maL9jKjfzXFGkY+7M32labh8G70gzYk8rLu4gFwzgSm56iHU4rlp6fZybCGllezmUrMvxJiT2YFxqi0CmVS4wA+ixWwp8sYPvd/w6amasm7Zn9KoEYLDLRXq8iCwGW+SFcxwg72AKI84ulGHDjLWK8T7EAmAwcXOFRekhX88hrLWyiGaNtWCHdsL1qZ/l4+Xet5pLcWvoY2mutlylbgTKfOWSWpMkkNoyXF3/tMHIBGhX8cB5Wa4GuhMi2J7UARQVdhjXL+9bnBFfsFyUzZZ5c5GPhDe3N4ibpCBxif0ZozDokGve8TP3iRRgy1SUF7kuvHk0dW0VfIwazmK0pfL3GH4XYjGQ+nZD98hEeT5MCbq9T7UcenaeUxEsN65hSfV4d1rF0vHyj96Ryq9bix5YrHIbiebSaPmsgbSTAnzx+PqJMawbaeFUQk9FY5EY5FLpDYnC+iaPuJ06XV7SlyA5/+BMCwH5IwceF5pGfGmyEBkhx4GfFDrucdh0ODOJcIdJ8UFeqweVX3iplKbN85DASQ0s4V8e9BjZIoVM+MyPEt5okAw386SSfjc+DB0as2AlxSAx6qarKcLCv/SPm3AOkKyQq2f88HucP4bSSj0 XsZxBU/B cjwEWz5FnmAIo7JPRIyQ2InzI7xoTYc9kXiwVSCVv+CJA7U/sx5In4EHP6ObbiPQkCyVh X-Bogosity: Ham, tests=bogofilter, spamicity=0.000282, version=1.2.4 Sender: owner-linux-mm@kvack.org Precedence: bulk X-Loop: owner-majordomo@kvack.org List-ID: List-Subscribe: List-Unsubscribe: On Mon, Apr 15, 2024 at 11:37=E2=80=AFAM Benno Lossin wrote: > > On 15.04.24 09:13, Alice Ryhl wrote: > > +impl UserSlice { > > + /// Constructs a user slice from a raw pointer and a length in byt= es. > > + /// > > + /// Constructing a [`UserSlice`] performs no checks on the provide= d address and length, it can > > + /// safely be constructed inside a kernel thread with no current u= serspace process. Reads and > > + /// writes wrap the kernel APIs `copy_from_user` and `copy_to_user= `, which check the memory map > > + /// of the current process and enforce that the address range is w= ithin the user range (no > > + /// additional calls to `access_ok` are needed). > > + /// > > + /// Callers must be careful to avoid time-of-check-time-of-use (TO= CTOU) issues. The simplest way > > + /// is to create a single instance of [`UserSlice`] per user memor= y block as it reads each byte > > + /// at most once. > > + pub fn new(ptr: *mut c_void, length: usize) -> Self { > > What would happen if I call this with a kernel pointer and then > read/write to it? For example > > let mut arr =3D [MaybeUninit::uninit(); 64]; > let ptr: *mut [MaybeUninit] =3D &mut arr; > let ptr =3D ptr.cast::(); > > let slice =3D UserSlice::new(ptr, 64); > let (mut r, mut w) =3D slice.reader_writer(); > > r.read_raw(&mut arr)?; > // SAFETY: `arr` was initialized above. > w.write_slice(unsafe { MaybeUninit::slice_assume_init_ref(&arr) })?; > > I think this would violate the exclusivity of `&mut` without any > `unsafe` code. (the `unsafe` block at the end cannot possibly be wrong) This will fail with an EFAULT error. There is a check on the C side that verifies that the address is in userspace. (The access_ok call.) Alice