From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from kanga.kvack.org (kanga.kvack.org [205.233.56.17]) by smtp.lore.kernel.org (Postfix) with ESMTP id E21C0C47258 for ; Thu, 25 Jan 2024 10:31:59 +0000 (UTC) Received: by kanga.kvack.org (Postfix) id 3B1F4280004; Thu, 25 Jan 2024 05:31:59 -0500 (EST) Received: by kanga.kvack.org (Postfix, from userid 40) id 36153280002; Thu, 25 Jan 2024 05:31:59 -0500 (EST) X-Delivered-To: int-list-linux-mm@kvack.org Received: by kanga.kvack.org (Postfix, from userid 63042) id 22AA3280004; Thu, 25 Jan 2024 05:31:59 -0500 (EST) X-Delivered-To: linux-mm@kvack.org Received: from relay.hostedemail.com (smtprelay0013.hostedemail.com [216.40.44.13]) by kanga.kvack.org (Postfix) with ESMTP id 13567280002 for ; Thu, 25 Jan 2024 05:31:59 -0500 (EST) Received: from smtpin12.hostedemail.com (a10.router.float.18 [10.200.18.1]) by unirelay09.hostedemail.com (Postfix) with ESMTP id A58138041B for ; Thu, 25 Jan 2024 10:31:58 +0000 (UTC) X-FDA: 81717467916.12.B47C4F5 Received: from mail-ed1-f51.google.com (mail-ed1-f51.google.com [209.85.208.51]) by imf22.hostedemail.com (Postfix) with ESMTP id D66F9C001C for ; Thu, 25 Jan 2024 10:31:56 +0000 (UTC) Authentication-Results: imf22.hostedemail.com; dkim=pass header.d=google.com header.s=20230601 header.b=SJ45wbOE; spf=pass (imf22.hostedemail.com: domain of edumazet@google.com designates 209.85.208.51 as permitted sender) smtp.mailfrom=edumazet@google.com; dmarc=pass (policy=reject) header.from=google.com ARC-Seal: i=1; s=arc-20220608; d=hostedemail.com; t=1706178716; a=rsa-sha256; cv=none; b=Z1IJyPyRTZgMAV6TP+TNrpfND5puMydBDxMdMpahV7qheq/izomvYy/HsPHxAbw35VoBWO Lsdcxri9NpEkWfbLtHyptbvY5IAxjiEks2fCR8It0YegCQwLINozzdPz0b59uP/5b1FFtp Ytejap6GGPOit1NBdl+gtOHZJYusWzk= ARC-Authentication-Results: i=1; imf22.hostedemail.com; dkim=pass header.d=google.com header.s=20230601 header.b=SJ45wbOE; spf=pass (imf22.hostedemail.com: domain of edumazet@google.com designates 209.85.208.51 as permitted sender) smtp.mailfrom=edumazet@google.com; dmarc=pass (policy=reject) header.from=google.com ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=hostedemail.com; s=arc-20220608; t=1706178716; h=from:from:sender:reply-to:subject:subject:date:date: message-id:message-id:to:to:cc:cc:mime-version:mime-version: content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references:dkim-signature; bh=cWf6jbJM4bTIZZq86/kL7elUKyQFSEDd12/W/Q8QCyI=; b=VDGDR/u6ymXRKctyvD+hGFkEiuU1tVHMTE3dLJdXhNQJyJgJu2hxivzVu1fflU0mBYxQZ6 Znz0NVIX2/FaO2HbvEBKZKSWyINvzi4FNjSuSDwCXz+gnMCka7g3AAU5VOLrA3cJXPoigY nyed121q8IwT4gI/TPSA1rhjYCQKF4A= Received: by mail-ed1-f51.google.com with SMTP id 4fb4d7f45d1cf-55cc794291cso7252a12.1 for ; Thu, 25 Jan 2024 02:31:56 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20230601; t=1706178715; x=1706783515; darn=kvack.org; h=content-transfer-encoding:cc:to:subject:message-id:date:from :in-reply-to:references:mime-version:from:to:cc:subject:date :message-id:reply-to; bh=cWf6jbJM4bTIZZq86/kL7elUKyQFSEDd12/W/Q8QCyI=; b=SJ45wbOEy6ikIhVHAJ5svCgroqdL5gX3DdpnbakK+okyZaYNw2hXA+EgKXghSfLXjf 1shNaa9t6nQG8iPOB1b1ji3FB9YztMaKKTkiP9djcpQEs8S4q2hXSAAYAnVHaqukMVR4 QiiieqBki7VMyrCXA0yPsDopfXyamrXYl5jL0NUiHKw1iBn02Zvbcc2z2VGQeQJt7/oh Yk3F8/KNpruMuqxUsSCB2jwQ3uGSkDpuP2pc4JeaBP/qcSp9BKIw7L2RdVZ0F6MZnHUI KudTjJ9uAIkvr5wNAxH8+ZkCjq2E4FDCgklm3wB+vzglvNsHrm9fLltSabmTWnRLa52d Fy1A== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1706178715; x=1706783515; h=content-transfer-encoding:cc:to:subject:message-id:date:from :in-reply-to:references:mime-version:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to; bh=cWf6jbJM4bTIZZq86/kL7elUKyQFSEDd12/W/Q8QCyI=; b=uwhs8fvN2pwb4ku6he/HLvE/PETGShY+ajFBO8G6SRCyJ4d0gQiT8Ln6aOJ4mqVnsq 7MhgHLbNTRu4+/PmxIluABgEKb8ZklQ0aUaNdrEQxrKmk7zPYP7fBk8nUECEOL2PLPLb JHYJQ/CvG54IQ3r1Aummg3PV62Oh4hmlda4THyBP6kYLHd+zTVs0g+HMJUU7sEvvfmu1 Z0Spj3VAhZf4ErXNfYDtOvG33YhSYsozxAmbNMToDyBQJ/k3lGn9YAq+jl4U1UNWfRxm hSfnKDRSWb+3Hsw/UqK4zfF8fCbu+RBHDhKsPjnwjpNcUU5HrloImaeGyt9IWIQ8g72q LQxg== X-Gm-Message-State: AOJu0YxFlGcFCrsb1Vsd1NDhYyrVaLkAY8Md+dTxn54IHXOlAWSA37p/ xjDGFd9fGYSnx3RiSpogClxw+c8ps+C2FlLwxgIblncF4fItzTqGgAO5Hm+LbwcS3jmfMK8PSe9 mCKi0Pau8dLhHgIqSZh9tTOyHSmt0t5RFjJkV X-Google-Smtp-Source: AGHT+IHtqUYvp4/VdtenInel7W+JfvX7Hf8VwjhjBJFEhAw9CuJLqpo7Ij201tiBjQxKUPCTaH7PXQp8tVrb6IBxWEM= X-Received: by 2002:a05:6402:22a1:b0:55c:2131:56cf with SMTP id cx1-20020a05640222a100b0055c213156cfmr118666edb.7.1706178714987; Thu, 25 Jan 2024 02:31:54 -0800 (PST) MIME-Version: 1.0 References: <20240119092024.193066-1-zhangpeng362@huawei.com> <5106a58e-04da-372a-b836-9d3d0bd2507b@huawei.com> <4f78fea2-ced6-fc5a-c7f2-b33fcd226f06@huawei.com> <531c536d-a7d1-2be5-10aa-8d6eb4dcb5c9@huawei.com> In-Reply-To: <531c536d-a7d1-2be5-10aa-8d6eb4dcb5c9@huawei.com> From: Eric Dumazet Date: Thu, 25 Jan 2024 11:31:42 +0100 Message-ID: Subject: Re: SECURITY PROBLEM: Any user can crash the kernel with TCP ZEROCOPY To: "zhangpeng (AS)" Cc: Matthew Wilcox , linux-mm@kvack.org, linux-fsdevel@vger.kernel.org, netdev@vger.kernel.org, akpm@linux-foundation.org, davem@davemloft.net, dsahern@kernel.org, kuba@kernel.org, pabeni@redhat.com, arjunroy@google.com, wangkefeng.wang@huawei.com Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable X-Rspamd-Server: rspam08 X-Rspamd-Queue-Id: D66F9C001C X-Stat-Signature: 19ggbqp9jhrnrz1pwmydk66gokcmb7om X-Rspam-User: X-HE-Tag: 1706178716-224332 X-HE-Meta: U2FsdGVkX1/J902U8aUKlhFKSfVwlwcfn7x8fWwSMDHTddBx6KFvcPxdc2Q6CoI/VKcyYkNM++j4WCrJEi3c97wWfguHJjgQXSP/Zy5qy/QNQga5b5SeCBIFcKK6i4Ty3fDuHJ7eI6WOAE2Uyb61lYCJ7jZ5ehH0IelA00zY8QRuAuyZe8eH0fFkClQdb9g25wbzGI/5qUpv7tDvgtjdYpRJ24Uxic9xEwExFl4ggPq0k9dVldGDGn6CzcQw9E/sCsmfySEWaucNG8iMAnEqmpDw2ixHn9Pyk6sbXquBjvzwsDA/ZRR05wetp0rLzRI0ZpragTnOdNo9xl4uJ50rtjZ+qsPeN0kxJnev9eFZpPp7x4Lp9wXHAkOoPZRkNBVDvAtU5kuJ7qcJuMDh4IhT/cHqToFo4PTReNMQEwHkIiNO/p4UIWbTaL4Q5wHqcIJCxVtxUBS+bjMl+rb58+UTsJqR37+E32ZLly/l5/N0pOzfjgckITJtqOJsNousURfcAOPjhomY0010fG/mqdhd00MFdURqFq8PSgOuSAcjq20/owZThMQ6fed7fWy9R0HFjP3IhHWSWlne4jfFRgKVve7NqQkmigodNUH8ticG+O3OgmuQNNg9mqFoGzTnWQX14iJLDWyi6AkdklB0IJE9qMFWEy7RCvjvdFVPIn0FbNSJhoFngP4b86475HIb6HCrq1qeKbMlV6Yb6YnaEuMx0akfPZljowyJKl50zvdjbQcSmJtY/0QzWs5n5AofPRM6C2WwaH7D9iAuJdMYREebOmfCDv7b1M8la08Lll+VjT+k921EzViki8ldqQAJlw/j+MItcoPYPSTccY7YdBKLZ04dNokUqKFRVhlREldulHzNDW5eIY1vtlq/B6T7YHJn/JBRRnt8wnlo/kasKq5ferdLwI6Tu4PvsZPNZ7OOfnFsAIGQXII8mYHK3DDKAM1vXX8sI2XYBxyf1K2WEri 1367XVw2 R9AIXrY/SyAN3jFCG2+psPD6Jrqy76vsVDZsQKG2uX3Xkxb6a//pNWecd3MDPl/7Y5Mc/tinngiyop6da7Ry4b8upeBwAA+5fOsw8k8NZGJwNc+Dbn9gvLuENFyG/rHBQEHMCWzolzi49uBNZPKq83t8lYBsTVixBr4hZNsUCASPUNr9eOpGK5mBfGJt/c7i/RINplqABevYwJAIaHvWlbGSzbNW52JElyRCBZ30QqL3O31tgk4THITnEjg== X-Bogosity: Ham, tests=bogofilter, spamicity=0.008844, version=1.2.4 Sender: owner-linux-mm@kvack.org Precedence: bulk X-Loop: owner-majordomo@kvack.org List-ID: List-Subscribe: List-Unsubscribe: On Thu, Jan 25, 2024 at 10:22=E2=80=AFAM zhangpeng (AS) wrote: > > > This patch can fix this issue. > > Great, I will submit this patch for review then, thanks a lot ! > > If all the pages that need to be inserted by TCP zerocopy are > page->mapping =3D=3D NULL, this solution could be used. At least the patch looks sane for stable submission. If we need to extend functionality, it can be done in future kernels.