From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org X-Spam-Level: X-Spam-Status: No, score=-3.8 required=3.0 tests=BAYES_00,DKIM_SIGNED, DKIM_VALID,DKIM_VALID_AU,HEADER_FROM_DIFFERENT_DOMAINS,MAILING_LIST_MULTI, SPF_HELO_NONE,SPF_PASS,URIBL_BLOCKED autolearn=no autolearn_force=no version=3.4.0 Received: from mail.kernel.org (mail.kernel.org [198.145.29.99]) by smtp.lore.kernel.org (Postfix) with ESMTP id E32D2C43467 for ; Fri, 9 Oct 2020 17:52:20 +0000 (UTC) Received: from kanga.kvack.org (kanga.kvack.org [205.233.56.17]) by mail.kernel.org (Postfix) with ESMTP id CC57422365 for ; Fri, 9 Oct 2020 17:52:19 +0000 (UTC) Authentication-Results: mail.kernel.org; dkim=pass (1024-bit key) header.d=ffwll.ch header.i=@ffwll.ch header.b="L4kTmlRV" DMARC-Filter: OpenDMARC Filter v1.3.2 mail.kernel.org CC57422365 Authentication-Results: mail.kernel.org; dmarc=none (p=none dis=none) header.from=ffwll.ch Authentication-Results: mail.kernel.org; spf=pass smtp.mailfrom=owner-linux-mm@kvack.org Received: by kanga.kvack.org (Postfix) id 0B5DB6B006C; Fri, 9 Oct 2020 13:52:19 -0400 (EDT) Received: by kanga.kvack.org (Postfix, from userid 40) id 03EC76B0070; Fri, 9 Oct 2020 13:52:18 -0400 (EDT) X-Delivered-To: int-list-linux-mm@kvack.org Received: by kanga.kvack.org (Postfix, from userid 63042) id E49256B0071; Fri, 9 Oct 2020 13:52:18 -0400 (EDT) X-Delivered-To: linux-mm@kvack.org Received: from forelay.hostedemail.com (smtprelay0010.hostedemail.com [216.40.44.10]) by kanga.kvack.org (Postfix) with ESMTP id A70EA6B006C for ; Fri, 9 Oct 2020 13:52:18 -0400 (EDT) Received: from smtpin18.hostedemail.com (10.5.19.251.rfc1918.com [10.5.19.251]) by forelay02.hostedemail.com (Postfix) with ESMTP id 512693629 for ; Fri, 9 Oct 2020 17:52:18 +0000 (UTC) X-FDA: 77353131156.18.mind81_17087d9271e2 Received: from filter.hostedemail.com (10.5.16.251.rfc1918.com [10.5.16.251]) by smtpin18.hostedemail.com (Postfix) with ESMTP id 28E2F1019F35F for ; Fri, 9 Oct 2020 17:52:18 +0000 (UTC) X-HE-Tag: mind81_17087d9271e2 X-Filterd-Recvd-Size: 5975 Received: from mail-ot1-f67.google.com (mail-ot1-f67.google.com [209.85.210.67]) by imf40.hostedemail.com (Postfix) with ESMTP for ; Fri, 9 Oct 2020 17:52:17 +0000 (UTC) Received: by mail-ot1-f67.google.com with SMTP id i12so9783473ota.5 for ; Fri, 09 Oct 2020 10:52:17 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ffwll.ch; s=google; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=Chc8637Rd8yI9tLS7AREeItMweAw4M0AE06Zuj7bhU0=; b=L4kTmlRVcZoe/avVgvgJLaWOs03iPF87kjF+Wg5Dr1BO68grQeWij+sKeGLbjkKVnS uWxXV8aahQlRlzimSn7k7/L57rwPuRVe9l/HoPbmKuzL42kNzmiAubvKP93NNRPozIcb M7wzXGB/zvSu+un9zoWu7yVJIqeg+g4rBMVIc= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=Chc8637Rd8yI9tLS7AREeItMweAw4M0AE06Zuj7bhU0=; b=cvkMJPTUpatihGNR2BjcPub4NONpfQP7UyJXJSV3lnotGhE6fo4ziK0mHOnonbvey2 5Tz3pgoz2gbkwF/wtDdjoFPc8kP2HxLXH3SraBaD/0CupXj2TlizEl49JJMCZj4EkxLW hMwAPd+HOHjnOeHT6Q9hEk91HPjpezeH+jH7LzhkmXCPy1x5WIUo5k3tDuYh6ykRJO2+ Sz0pKPcsEYBROpG9qiQ/VF0uYWgBlcozR329YO4YVHlRFdEYxqiHHMsRbzZifxTLTz5e flIauTGyDwwER9MyjVaDL5H/zADm+IUt6cHVHYAqJ0k6v7w2/iQiJ1ILoDk8roDDMq20 bTCw== X-Gm-Message-State: AOAM532Mmi/jwBGD4s8TlKwk2fhrg51uPCM86putBuwi6TH1SSQxFKhE tZLsUfkl0MzG8mcG7UPED//fUmdXYJII16iX2lLecg== X-Google-Smtp-Source: ABdhPJxFnmBLRj+lrjXy7n2SbqbKqfPXOoR4PVOcPvoZoMGu71c5Uydzax6ZExKmO8/pv5qIPQDGfl3spZzjZBbiaDw= X-Received: by 2002:a05:6830:1647:: with SMTP id h7mr10168614otr.281.1602265936612; Fri, 09 Oct 2020 10:52:16 -0700 (PDT) MIME-Version: 1.0 References: <20201009075934.3509076-1-daniel.vetter@ffwll.ch> <20201009075934.3509076-10-daniel.vetter@ffwll.ch> <20201009123421.67a80d72@coco.lan> <20201009122111.GN5177@ziepe.ca> <20201009143723.45609bfb@coco.lan> <20201009124850.GP5177@ziepe.ca> In-Reply-To: <20201009124850.GP5177@ziepe.ca> From: Daniel Vetter Date: Fri, 9 Oct 2020 19:52:05 +0200 Message-ID: Subject: Re: [PATCH v2 09/17] mm: Add unsafe_follow_pfn To: Jason Gunthorpe Cc: Mauro Carvalho Chehab , DRI Development , LKML , KVM list , Linux MM , Linux ARM , linux-samsung-soc , "open list:DMA BUFFER SHARING FRAMEWORK" , linux-s390 , Daniel Vetter , Kees Cook , Dan Williams , Andrew Morton , John Hubbard , =?UTF-8?B?SsOpcsO0bWUgR2xpc3Nl?= , Jan Kara , Linus Torvalds Content-Type: text/plain; charset="UTF-8" X-Bogosity: Ham, tests=bogofilter, spamicity=0.000000, version=1.2.4 Sender: owner-linux-mm@kvack.org Precedence: bulk X-Loop: owner-majordomo@kvack.org List-ID: On Fri, Oct 9, 2020 at 2:48 PM Jason Gunthorpe wrote: > > On Fri, Oct 09, 2020 at 02:37:23PM +0200, Mauro Carvalho Chehab wrote: > > > I'm not a mm/ expert, but, from what I understood from Daniel's patch > > description is that this is unsafe *only if* __GFP_MOVABLE is used. > > No, it is unconditionally unsafe. The CMA movable mappings are > specific VMAs that will have bad issues here, but there are other > types too. > > The only way to do something at a VMA level is to have a list of OK > VMAs, eg because they were creatd via a special mmap helper from the > media subsystem. > > > Well, no drivers inside the media subsystem uses such flag, although > > they may rely on some infrastructure that could be using it behind > > the bars. > > It doesn't matter, nothing prevents the user from calling media APIs > on mmaps it gets from other subsystems. I think a good first step would be to disable userptr of non struct page backed storage going forward for any new hw support. Even on existing drivers. dma-buf sharing has been around for long enough now that this shouldn't be a problem. Unfortunately right now this doesn't seem to exist, so the entire problem keeps getting perpetuated. > > If this is the case, the proper fix seems to have a GFP_NOT_MOVABLE > > flag that it would be denying the core mm code to set __GFP_MOVABLE. > > We can't tell from the VMA these kinds of details.. > > It has to go the other direction, evey mmap that might be used as a > userptr here has to be found and the VMA specially created to allow > its use. At least that is a kernel only change, but will need people > with the HW to do this work. I think the only reasonable way to keep this working is: - add a struct dma_buf *vma_tryget_dma_buf(struct vm_area_struct *vma); - add dma-buf export support to fbdev and v4l - roll this out everywhere we still need it. Realistically this just isn't going to happen. And anything else just reimplements half of dma-buf, which is kinda pointless (you need minimally refcounting and some way to get at a promise of a permanent sg list for dma. Plus probably the vmap for kernel cpu access. > > Please let address the issue on this way, instead of broken an > > userspace API that it is there since 1991. > > It has happened before :( It took 4 years for RDMA to undo the uAPI > breakage caused by a security fix for something that was a 15 years > old bug. Yeah we have a bunch of these on the drm side too. Some of them are really just "you have to upgrade userspace", and there's no real fix for the security nightmare without that. -Daniel -- Daniel Vetter Software Engineer, Intel Corporation http://blog.ffwll.ch