From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from kanga.kvack.org (kanga.kvack.org [205.233.56.17]) by smtp.lore.kernel.org (Postfix) with ESMTP id 331ADC41535 for ; Fri, 7 Oct 2022 17:56:47 +0000 (UTC) Received: by kanga.kvack.org (Postfix) id 6BF056B0072; Fri, 7 Oct 2022 13:56:46 -0400 (EDT) Received: by kanga.kvack.org (Postfix, from userid 40) id 647AA6B0073; Fri, 7 Oct 2022 13:56:46 -0400 (EDT) X-Delivered-To: int-list-linux-mm@kvack.org Received: by kanga.kvack.org (Postfix, from userid 63042) id 44C2D6B0074; Fri, 7 Oct 2022 13:56:46 -0400 (EDT) X-Delivered-To: linux-mm@kvack.org Received: from relay.hostedemail.com (smtprelay0013.hostedemail.com [216.40.44.13]) by kanga.kvack.org (Postfix) with ESMTP id 294936B0072 for ; Fri, 7 Oct 2022 13:56:46 -0400 (EDT) Received: from smtpin08.hostedemail.com (a10.router.float.18 [10.200.18.1]) by unirelay09.hostedemail.com (Postfix) with ESMTP id E927280DCE for ; Fri, 7 Oct 2022 17:56:45 +0000 (UTC) X-FDA: 79994908770.08.D39E905 Received: from ams.source.kernel.org (ams.source.kernel.org [145.40.68.75]) by imf08.hostedemail.com (Postfix) with ESMTP id 43B10160026 for ; Fri, 7 Oct 2022 17:56:43 +0000 (UTC) Received: from smtp.kernel.org (relay.kernel.org [52.25.139.140]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ams.source.kernel.org (Postfix) with ESMTPS id 5F174B818F6; Fri, 7 Oct 2022 17:56:41 +0000 (UTC) Received: by smtp.kernel.org (Postfix) with ESMTPSA id B63F0C433D7; Fri, 7 Oct 2022 17:56:33 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=zx2c4.com; s=20210105; t=1665165391; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=nK/H0hVDBIBg7GodmLmaWI9qS4fvsGkmZJoRHEB4Sqs=; b=f8gITOWuIwqHaHfAd2Ip5iMe8yRrocgJ4MTv+syk8BIYaorE//Q+fvXw/I7Wb9QIt67mY7 sXmAQixgC0HtGsR77BaUpuASQ/P2J6ViTMRZs6w1NXyDA3Tn8jOyTwjjjCV8bnJYFxdwV5 RGF0qzBCT4wpILO3WXYw3dx9t9cPRE4= Received: by mail.zx2c4.com (ZX2C4 Mail Server) with ESMTPSA id 1a87e0a2 (TLSv1.3:TLS_AES_256_GCM_SHA384:256:NO); Fri, 7 Oct 2022 17:56:31 +0000 (UTC) Date: Fri, 7 Oct 2022 11:56:18 -0600 From: "Jason A. Donenfeld" To: Kees Cook Cc: Christophe Leroy , "linux-kernel@vger.kernel.org" , "patches@lists.linux.dev" , Andreas Noever , Andrew Morton , Andy Shevchenko , Borislav Petkov , Catalin Marinas , Christoph =?utf-8?Q?B=C3=B6hmwalder?= , Christoph Hellwig , Daniel Borkmann , Dave Airlie , Dave Hansen , "David S . Miller" , Eric Dumazet , Florian Westphal , Greg Kroah-Hartman , "H . Peter Anvin" , Heiko Carstens , Helge Deller , Herbert Xu , Huacai Chen , Hugh Dickins , Jakub Kicinski , "James E . J . Bottomley" , Jan Kara , Jason Gunthorpe , Jens Axboe , Johannes Berg , Jonathan Corbet , Jozsef Kadlecsik , KP Singh , Marco Elver , Mauro Carvalho Chehab , Michael Ellerman , Pablo Neira Ayuso , Paolo Abeni , Peter Zijlstra , Richard Weinberger , Russell King , Theodore Ts'o , Thomas Bogendoerfer , Thomas Gleixner , Thomas Graf , Ulf Hansson , Vignesh Raghavendra , WANG Xuerui , Will Deacon , Yury Norov , "dri-devel@lists.freedesktop.org" , "kasan-dev@googlegroups.com" , "kernel-janitors@vger.kernel.org" , "linux-arm-kernel@lists.infradead.org" , "linux-block@vger.kernel.org" , "linux-crypto@vger.kernel.org" , "linux-doc@vger.kernel.org" , "linux-fsdevel@vger.kernel.org" , "linux-media@vger.kernel.org" , "linux-mips@vger.kernel.org" , "linux-mm@kvack.org" , "linux-mmc@vger.kernel.org" , "linux-mtd@lists.infradead.org" , "linux-nvme@lists.infradead.org" , "linux-parisc@vger.kernel.org" , "linux-rdma@vger.kernel.org" , "linux-s390@vger.kernel.org" , "linux-um@lists.infradead.org" , "linux-usb@vger.kernel.org" , "linux-wireless@vger.kernel.org" , "linuxppc-dev@lists.ozlabs.org" , "loongarch@lists.linux.dev" , "netdev@vger.kernel.org" , "sparclinux@vger.kernel.org" , "x86@kernel.org" , Toke =?utf-8?Q?H=C3=B8iland-J=C3=B8rgensen?= , Chuck Lever , Jan Kara Subject: Re: [PATCH v3 3/5] treewide: use get_random_u32() when possible Message-ID: References: <20221006165346.73159-1-Jason@zx2c4.com> <20221006165346.73159-4-Jason@zx2c4.com> <848ed24c-13ef-6c38-fd13-639b33809194@csgroup.eu> <6396875c-146a-acf5-dd9e-7f93ba1b4bc3@csgroup.eu> <501b0fc3-6c67-657f-781e-25ee0283bc2e@csgroup.eu> <202210071010.52C672FA9@keescook> MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Disposition: inline Content-Transfer-Encoding: 8bit In-Reply-To: <202210071010.52C672FA9@keescook> ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=hostedemail.com; s=arc-20220608; t=1665165403; h=from:from:sender:reply-to:subject:subject:date:date: message-id:message-id:to:to:cc:cc:mime-version:mime-version: content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references:dkim-signature; bh=nK/H0hVDBIBg7GodmLmaWI9qS4fvsGkmZJoRHEB4Sqs=; b=rlVgwoC/OKmkUiMALLiRhwdu40opiXs+MQYKLPbtD3zfqICLnCQrcqvCOPgYCCCLgAa7Ob ieYSLMXe0cdFfZlI86wkQjWXtr0iXWwRoSyYhkHWpkZzYHkvwjc2sEcAqyuq/UMTpK7gvS UU1TPZ/q6MSwdd3jTKeRZlMVv5rgJQ0= ARC-Authentication-Results: i=1; imf08.hostedemail.com; dkim=pass header.d=zx2c4.com header.s=20210105 header.b=f8gITOWu; dmarc=pass (policy=quarantine) header.from=zx2c4.com; spf=pass (imf08.hostedemail.com: domain of "SRS0=JVfI=2I=zx2c4.com=Jason@kernel.org" designates 145.40.68.75 as permitted sender) smtp.mailfrom="SRS0=JVfI=2I=zx2c4.com=Jason@kernel.org" ARC-Seal: i=1; s=arc-20220608; d=hostedemail.com; t=1665165403; a=rsa-sha256; cv=none; b=7V63mA1OvcrW36GZDZ59wkZw3kknkOE56FX8eN9QBYSyPQqcYQO/v088Dqwi88btamsn8S IEKozq7E8Phu1ikWAqhYLrjkhL8InBCr3HqKfSEaNYaGZPJ3meiBKo+/ZcDfbDydC4dU9o RgZmWM3zc5ooQYCYpglsEb/bFj8xkJg= Authentication-Results: imf08.hostedemail.com; dkim=pass header.d=zx2c4.com header.s=20210105 header.b=f8gITOWu; dmarc=pass (policy=quarantine) header.from=zx2c4.com; spf=pass (imf08.hostedemail.com: domain of "SRS0=JVfI=2I=zx2c4.com=Jason@kernel.org" designates 145.40.68.75 as permitted sender) smtp.mailfrom="SRS0=JVfI=2I=zx2c4.com=Jason@kernel.org" X-Stat-Signature: urybkr8hn71m61tpughm64ufxc65311r X-Rspamd-Queue-Id: 43B10160026 X-Rspam-User: X-Rspamd-Server: rspam06 X-HE-Tag: 1665165403-122628 X-Bogosity: Ham, tests=bogofilter, spamicity=0.000000, version=1.2.4 Sender: owner-linux-mm@kvack.org Precedence: bulk X-Loop: owner-majordomo@kvack.org List-ID: On Fri, Oct 07, 2022 at 10:12:42AM -0700, Kees Cook wrote: > On Fri, Oct 07, 2022 at 08:07:58AM -0600, Jason A. Donenfeld wrote: > > On Fri, Oct 07, 2022 at 04:57:24AM +0000, Christophe Leroy wrote: > > > > > > > > > Le 07/10/2022 à 01:36, Jason A. Donenfeld a écrit : > > > > On 10/6/22, Christophe Leroy wrote: > > > >> > > > >> > > > >> Le 06/10/2022 à 19:31, Christophe Leroy a écrit : > > > >>> > > > >>> > > > >>> Le 06/10/2022 à 19:24, Jason A. Donenfeld a écrit : > > > >>>> Hi Christophe, > > > >>>> > > > >>>> On Thu, Oct 6, 2022 at 11:21 AM Christophe Leroy > > > >>>> wrote: > > > >>>>> Le 06/10/2022 à 18:53, Jason A. Donenfeld a écrit : > > > >>>>>> The prandom_u32() function has been a deprecated inline wrapper around > > > >>>>>> get_random_u32() for several releases now, and compiles down to the > > > >>>>>> exact same code. Replace the deprecated wrapper with a direct call to > > > >>>>>> the real function. The same also applies to get_random_int(), which is > > > >>>>>> just a wrapper around get_random_u32(). > > > >>>>>> > > > >>>>>> Reviewed-by: Kees Cook > > > >>>>>> Acked-by: Toke Høiland-Jørgensen # for sch_cake > > > >>>>>> Acked-by: Chuck Lever # for nfsd > > > >>>>>> Reviewed-by: Jan Kara # for ext4 > > > >>>>>> Signed-off-by: Jason A. Donenfeld > > > >>>>>> --- > > > >>>>> > > > >>>>>> diff --git a/arch/powerpc/kernel/process.c > > > >>>>>> b/arch/powerpc/kernel/process.c > > > >>>>>> index 0fbda89cd1bb..9c4c15afbbe8 100644 > > > >>>>>> --- a/arch/powerpc/kernel/process.c > > > >>>>>> +++ b/arch/powerpc/kernel/process.c > > > >>>>>> @@ -2308,6 +2308,6 @@ void notrace __ppc64_runlatch_off(void) > > > >>>>>> unsigned long arch_align_stack(unsigned long sp) > > > >>>>>> { > > > >>>>>> if (!(current->personality & ADDR_NO_RANDOMIZE) && > > > >>>>>> randomize_va_space) > > > >>>>>> - sp -= get_random_int() & ~PAGE_MASK; > > > >>>>>> + sp -= get_random_u32() & ~PAGE_MASK; > > > >>>>>> return sp & ~0xf; > > > >>>>> > > > >>>>> Isn't that a candidate for prandom_u32_max() ? > > > >>>>> > > > >>>>> Note that sp is deemed to be 16 bytes aligned at all time. > > > >>>> > > > >>>> Yes, probably. It seemed non-trivial to think about, so I didn't. But > > > >>>> let's see here... maybe it's not too bad: > > > >>>> > > > >>>> If PAGE_MASK is always ~(PAGE_SIZE-1), then ~PAGE_MASK is > > > >>>> (PAGE_SIZE-1), so prandom_u32_max(PAGE_SIZE) should yield the same > > > >>>> thing? Is that accurate? And holds across platforms (this comes up a > > > >>>> few places)? If so, I'll do that for a v4. > > > >>>> > > > >>> > > > >>> On powerpc it is always (from arch/powerpc/include/asm/page.h) : > > > >>> > > > >>> /* > > > >>> * Subtle: (1 << PAGE_SHIFT) is an int, not an unsigned long. So if we > > > >>> * assign PAGE_MASK to a larger type it gets extended the way we want > > > >>> * (i.e. with 1s in the high bits) > > > >>> */ > > > >>> #define PAGE_MASK (~((1 << PAGE_SHIFT) - 1)) > > > >>> > > > >>> #define PAGE_SIZE (1UL << PAGE_SHIFT) > > > >>> > > > >>> > > > >>> So it would work I guess. > > > >> > > > >> But taking into account that sp must remain 16 bytes aligned, would it > > > >> be better to do something like ? > > > >> > > > >> sp -= prandom_u32_max(PAGE_SIZE >> 4) << 4; > > > >> > > > >> return sp; > > > > > > > > Does this assume that sp is already aligned at the beginning of the > > > > function? I'd assume from the function's name that this isn't the > > > > case? > > > > > > Ah you are right, I overlooked it. > > > > So I think to stay on the safe side, I'm going to go with > > `prandom_u32_max(PAGE_SIZE)`. Sound good? > > Given these kinds of less mechanical changes, it may make sense to split > these from the "trivial" conversions in a treewide patch. The chance of > needing a revert from the simple 1:1 conversions is much lower than the > need to revert by-hand changes. > > The Cocci script I suggested in my v1 review gets 80% of the first > patch, for example. I'll split things up into a mechanical step and a non-mechanical step. Good idea. Jason