From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org X-Spam-Level: X-Spam-Status: No, score=-11.8 required=3.0 tests=HEADER_FROM_DIFFERENT_DOMAINS,INCLUDES_PATCH,MAILING_LIST_MULTI, MENTIONS_GIT_HOSTING,SIGNED_OFF_BY,SPF_HELO_NONE,SPF_PASS,URIBL_BLOCKED autolearn=ham autolearn_force=no version=3.4.0 Received: from mail.kernel.org (mail.kernel.org [198.145.29.99]) by smtp.lore.kernel.org (Postfix) with ESMTP id 6CB85C2BA19 for ; Tue, 14 Apr 2020 15:50:47 +0000 (UTC) Received: from kanga.kvack.org (kanga.kvack.org [205.233.56.17]) by mail.kernel.org (Postfix) with ESMTP id 27098206D5 for ; Tue, 14 Apr 2020 15:50:47 +0000 (UTC) DMARC-Filter: OpenDMARC Filter v1.3.2 mail.kernel.org 27098206D5 Authentication-Results: mail.kernel.org; dmarc=none (p=none dis=none) header.from=rowland.harvard.edu Authentication-Results: mail.kernel.org; spf=pass smtp.mailfrom=owner-linux-mm@kvack.org Received: by kanga.kvack.org (Postfix) id 9DA198E002C; Tue, 14 Apr 2020 11:50:46 -0400 (EDT) Received: by kanga.kvack.org (Postfix, from userid 40) id 9B0E08E0007; Tue, 14 Apr 2020 11:50:46 -0400 (EDT) X-Delivered-To: int-list-linux-mm@kvack.org Received: by kanga.kvack.org (Postfix, from userid 63042) id 8EF388E002C; Tue, 14 Apr 2020 11:50:46 -0400 (EDT) X-Delivered-To: linux-mm@kvack.org Received: from forelay.hostedemail.com (smtprelay0102.hostedemail.com [216.40.44.102]) by kanga.kvack.org (Postfix) with ESMTP id 741798E0007 for ; Tue, 14 Apr 2020 11:50:46 -0400 (EDT) Received: from smtpin13.hostedemail.com (10.5.19.251.rfc1918.com [10.5.19.251]) by forelay04.hostedemail.com (Postfix) with ESMTP id 321174DA6 for ; Tue, 14 Apr 2020 15:50:46 +0000 (UTC) X-FDA: 76706898492.13.story27_40dc26f488054 X-HE-Tag: story27_40dc26f488054 X-Filterd-Recvd-Size: 6058 Received: from netrider.rowland.org (netrider.rowland.org [192.131.102.5]) by imf24.hostedemail.com (Postfix) with SMTP for ; Tue, 14 Apr 2020 15:50:45 +0000 (UTC) Received: (qmail 14817 invoked by uid 500); 14 Apr 2020 11:50:44 -0400 Received: from localhost (sendmail-bs@127.0.0.1) by localhost with SMTP; 14 Apr 2020 11:50:44 -0400 Date: Tue, 14 Apr 2020 11:50:44 -0400 (EDT) From: Alan Stern X-X-Sender: stern@netrider.rowland.org To: Andrey Konovalov cc: Alexander Potapenko , Andrew Morton , Greg Kroah-Hartman , Eric Dumazet , Wolfram Sang , Petr Mladek , Vegard Nossum , Dmitry Vyukov , Marco Elver , Linux Memory Management List , Alexander Viro , Andreas Dilger , Andrey Ryabinin , Andy Lutomirski , Ard Biesheuvel , Arnd Bergmann , Christoph Hellwig , Christoph Hellwig , "Darrick J. Wong" , "David S. Miller" , Dmitry Torokhov , Eric Biggers , Eric Van Hensbergen , Harry Wentland , Herbert Xu , Ilya Leoshkevich , Ingo Molnar , Jason Wang , Jens Axboe , Marek Szyprowski , Mark Rutland , "Martin K. Petersen" , Martin Schwidefsky , Matthew Wilcox , "Michael S . Tsirkin" , Michal Hocko , Michal Simek , Qian Cai , Randy Dunlap , Robin Murphy , Sergey Senozhatsky , Steven Rostedt , Takashi Iwai , Theodore Ts'o , Thomas Gleixner , Vasily Gorbik Subject: Re: [PATCH v5 20/38] kmsan: handle memory sent to/from USB In-Reply-To: Message-ID: MIME-Version: 1.0 Content-Type: TEXT/PLAIN; charset=US-ASCII X-Bogosity: Ham, tests=bogofilter, spamicity=0.000000, version=1.2.4 Sender: owner-linux-mm@kvack.org Precedence: bulk X-Loop: owner-majordomo@kvack.org List-ID: On Tue, 14 Apr 2020, Andrey Konovalov wrote: > On Wed, Mar 25, 2020 at 5:14 PM wrote: > > > > Depending on the value of is_out kmsan_handle_urb() KMSAN either > > marks the data copied to the kernel from a USB device as initialized, > > or checks the data sent to the device for being initialized. > > > > Signed-off-by: Alexander Potapenko > > To: Alexander Potapenko > > Cc: Andrew Morton > > Cc: Greg Kroah-Hartman > > Cc: Eric Dumazet > > Cc: Wolfram Sang > > Cc: Petr Mladek > > Cc: Vegard Nossum > > Cc: Dmitry Vyukov > > Cc: Marco Elver > > Cc: Andrey Konovalov > > Cc: linux-mm@kvack.org > > > > --- > > > > This patch was previously called "kmsan: call KMSAN hooks where needed" > > > > v4: > > - split this patch away > > > > Change-Id: Idd0f8ce858975112285706ffb7286f570bd3007b > > --- > > drivers/usb/core/urb.c | 2 ++ > > 1 file changed, 2 insertions(+) > > > > diff --git a/drivers/usb/core/urb.c b/drivers/usb/core/urb.c > > index da923ec176122..4a0b0ac0f52f9 100644 > > --- a/drivers/usb/core/urb.c > > +++ b/drivers/usb/core/urb.c > > @@ -8,6 +8,7 @@ > > #include > > #include > > #include > > +#include > > #include > > #include > > #include > > @@ -402,6 +403,7 @@ int usb_submit_urb(struct urb *urb, gfp_t mem_flags) > > URB_SETUP_MAP_SINGLE | URB_SETUP_MAP_LOCAL | > > URB_DMA_SG_COMBINED); > > urb->transfer_flags |= (is_out ? URB_DIR_OUT : URB_DIR_IN); > > + kmsan_handle_urb(urb, is_out); > > I guess this could simply accept urb and then check > urb->transfer_flags instead of also accepting is_out? > > Alan, do you think this is a good place for a call to > kmsan_handle_urb(), which is supposed to check that the memory we pass > to a USB device is initialized (so we don't leak uninitialized memory) > and mark memory received from the device as initialized? You can find > the implementation here: > > https://github.com/google/kmsan/commit/491a67cf03fa9e0f240fd6eb53a6074e4bfd1a2c#diff-020c941e2b8fc67f5ddca598cd954d57R322 This has got a couple of problems. Firstly, for control URBs it doesn't check urb->setup_packet, which should always be initialized regardless of the direction because it always gets sent to the device. Secondly, some URBs use scatter-gather transfers, and they don't always store the buffer address in urb->transfer_buffer (indeed, sometimes the buffer is located outside of the kernel's address map). Instead they use urb->sg and urb->num_sgs. To get an idea for how it all works, look at usb_hcd_map_urb_for_dma() in hcd.c. Thirdly, the information we get back from the device doesn't always cover the entire transfer buffer; sometimes the device sends less data than we asked for. Perhaps you don't care very much about this case. Alan Stern