From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from kanga.kvack.org (kanga.kvack.org [205.233.56.17]) by smtp.lore.kernel.org (Postfix) with ESMTP id 21AE2C43334 for ; Mon, 20 Jun 2022 08:08:35 +0000 (UTC) Received: by kanga.kvack.org (Postfix) id 9158F6B0071; Mon, 20 Jun 2022 04:08:34 -0400 (EDT) Received: by kanga.kvack.org (Postfix, from userid 40) id 89D366B0073; Mon, 20 Jun 2022 04:08:34 -0400 (EDT) X-Delivered-To: int-list-linux-mm@kvack.org Received: by kanga.kvack.org (Postfix, from userid 63042) id 716F48E0001; Mon, 20 Jun 2022 04:08:34 -0400 (EDT) X-Delivered-To: linux-mm@kvack.org Received: from relay.hostedemail.com (smtprelay0014.hostedemail.com [216.40.44.14]) by kanga.kvack.org (Postfix) with ESMTP id 5FA406B0071 for ; Mon, 20 Jun 2022 04:08:34 -0400 (EDT) Received: from smtpin03.hostedemail.com (a10.router.float.18 [10.200.18.1]) by unirelay06.hostedemail.com (Postfix) with ESMTP id 37688344D3 for ; Mon, 20 Jun 2022 08:08:34 +0000 (UTC) X-FDA: 79597887348.03.B3A9B75 Received: from mail-pl1-f172.google.com (mail-pl1-f172.google.com [209.85.214.172]) by imf16.hostedemail.com (Postfix) with ESMTP id 94224180011 for ; Mon, 20 Jun 2022 08:08:33 +0000 (UTC) Received: by mail-pl1-f172.google.com with SMTP id r1so9051965plo.10 for ; Mon, 20 Jun 2022 01:08:33 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20210112; h=date:from:to:cc:subject:message-id:references:mime-version :content-disposition:in-reply-to; bh=uriAeiH4qg5XncDUJuNLP2HtDsR716HbwJN/IyBG1F4=; b=gIxQ4X/wcsAOpXXyQYiXt3yvlFufYNthVR6Z5oagWQLfZTmJf6gfNJdw4RUy4RaYGz pTriOWPnd1u7ilL/08k43Y1Ab3FWADriiw5XZlKBYFHrPvDhIkRaoptJFEIj9BUBHSWG cAMa7KAnluppmGviiOQ4flYGIkCv1nWvxdcefguiIulW3yjseSlqMZHC8YfwdRhmROpA IIGnzPGT8hjnXxh3paumapeM1wwyvLiuNNebvIICU/Mhcqd6I5om2ZGIWWl8tcuDl9+r 9XjQrxBVd5etQQr6+P9gnwaK4NdF7qYQDwNzl0THGTfE8gqJZq253I2FmH4DgydWwHqX VNqA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20210112; h=x-gm-message-state:date:from:to:cc:subject:message-id:references :mime-version:content-disposition:in-reply-to; bh=uriAeiH4qg5XncDUJuNLP2HtDsR716HbwJN/IyBG1F4=; b=3nVji2DhKBa7duAwtwzcViIUoKQM/ZXj2gDnC8vHVf4rz3OtJLxEe7nw2nYfzn8zVZ 2Yfabvbb1MJKM/R6EjilXl9oqkbmTLTXQM0DKS3QcbqipKRlJ4hqIBBMjDQOkEaYSheX tiQ1I93LN3peMa/mtKXIwPPRXPqWEQeNjhtaDplRVM2m0unz0TeHdMzQ7zkkQrVXC95C lHfXdwAHzZpztlhIg1E3FrPO4LX0k1ztYc8s/RquimDrKJO8jMsScF1Fb/IQs7YC9f2s jAnyX6HLBYpVlt3INkVo+h1X3zQXvEU04dJqQNBr6ZXAXaN1Jm6HTJ6G8ao2mhd4qxdE UX/A== X-Gm-Message-State: AJIora9oGJG6+RBsdNTpQExLSrTRY6sNxhZvXU78JS2PBHe542zifVxX A8YBhZs+iJdfDazIBB3Xsic= X-Google-Smtp-Source: AGRyM1su38yC3t4HeH5YE+V5NyM9fnE+dKceLVdnHfrYCVu/hd34kzpnEERckixdRu7DWWDq5IRt+A== X-Received: by 2002:a17:902:7204:b0:16a:22f1:f87 with SMTP id ba4-20020a170902720400b0016a22f10f87mr4873876plb.3.1655712512454; Mon, 20 Jun 2022 01:08:32 -0700 (PDT) Received: from hyeyoo ([114.29.24.243]) by smtp.gmail.com with ESMTPSA id c9-20020a62f849000000b00522d32a6a38sm8239483pfm.121.2022.06.20.01.08.27 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 20 Jun 2022 01:08:31 -0700 (PDT) Date: Mon, 20 Jun 2022 17:08:24 +0900 From: Hyeonggon Yoo <42.hyeyoo@gmail.com> To: Dave Hansen Cc: Dave Hansen , Andy Lutomirski , Peter Zijlstra , Thomas Gleixner , Ingo Molnar , "H . Peter Anvin" , Dan Williams , Paolo Bonzini , Jane Chu , "Aneesh Kumar K . V" , Sean Christopherson , Tianyu Lan , Mike Rapoport , Rick Edgecombe , linux-mm@kvack.org, Borislav Petkov , x86@kernel.org Subject: Re: [RFC 1/2] x86/mm/cpa: always fail when user address is passed Message-ID: References: <20220614063933.13030-1-42.hyeyoo@gmail.com> <20220614063933.13030-2-42.hyeyoo@gmail.com> <660a5c93-e8cb-1c2f-5b27-c5e341de0bcd@intel.com> <1d6cfffd-582b-b3fa-75b2-5bf21519071b@intel.com> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <1d6cfffd-582b-b3fa-75b2-5bf21519071b@intel.com> ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=hostedemail.com; s=arc-20220608; t=1655712513; h=from:from:sender:reply-to:subject:subject:date:date: message-id:message-id:to:to:cc:cc:mime-version:mime-version: content-type:content-type:content-transfer-encoding: in-reply-to:in-reply-to:references:references:dkim-signature; bh=uriAeiH4qg5XncDUJuNLP2HtDsR716HbwJN/IyBG1F4=; b=RfVsSxHBhzLk/CxjjDisOG39PzNTKUG1HoriNEJSKr5N6dg7R/yFiCmeyRHaailoSzPJX+ irybtyAtmxelQN95K89NeZdntyvQVs/e8oFMcnaaw1ee06Sg6c2X+ZC3TPDN9PVwKcWkVd 1unIqKocmEAlDlAA5UhwC2nXHLWShEc= ARC-Seal: i=1; s=arc-20220608; d=hostedemail.com; t=1655712513; a=rsa-sha256; cv=none; b=43QF+EVyYIcdhl+E/e9kAnTTTMogLpN4vmleXLMOb1dWB9YXA6Qc16kpx0ZOg8Oh20YhE1 V8u9XsyELX2kv+1Gq8a1joipUmjThdh/pOn3wTH3rvVmxt4POTW2g8WgBtVtRY5azbPm3F arXfctQuS5wD9oDN9LedHRcaJQ76tkQ= ARC-Authentication-Results: i=1; imf16.hostedemail.com; dkim=pass header.d=gmail.com header.s=20210112 header.b="gIxQ4X/w"; spf=pass (imf16.hostedemail.com: domain of 42.hyeyoo@gmail.com designates 209.85.214.172 as permitted sender) smtp.mailfrom=42.hyeyoo@gmail.com; dmarc=pass (policy=none) header.from=gmail.com X-Stat-Signature: 7pmcwrraidawmppmu8k1u3c93ztwffwz Authentication-Results: imf16.hostedemail.com; dkim=pass header.d=gmail.com header.s=20210112 header.b="gIxQ4X/w"; spf=pass (imf16.hostedemail.com: domain of 42.hyeyoo@gmail.com designates 209.85.214.172 as permitted sender) smtp.mailfrom=42.hyeyoo@gmail.com; dmarc=pass (policy=none) header.from=gmail.com X-Rspamd-Queue-Id: 94224180011 X-Rspamd-Server: rspam02 X-Rspam-User: X-HE-Tag: 1655712513-754878 X-Bogosity: Ham, tests=bogofilter, spamicity=0.000000, version=1.2.4 Sender: owner-linux-mm@kvack.org Precedence: bulk X-Loop: owner-majordomo@kvack.org List-ID: On Thu, Jun 16, 2022 at 07:20:09AM -0700, Dave Hansen wrote: > On 6/16/22 01:49, Hyeonggon Yoo wrote: > > On Tue, Jun 14, 2022 at 11:31:48AM -0700, Dave Hansen wrote: > >> On 6/13/22 23:39, Hyeonggon Yoo wrote: > >>> @@ -1514,6 +1515,11 @@ static int __change_page_attr(struct cpa_data *cpa, int primary) > >>> pte_t *kpte, old_pte; > >>> > >>> address = __cpa_addr(cpa, cpa->curpage); > >>> + > >>> + if (WARN((IS_ENABLED(CONFIG_EFI) ? cpa->pgd != efi_mm.pgd : true) > >>> + && address <= TASK_SIZE_MAX, > >>> + KERN_WARNING "CPA: Got a user address")) > >>> + return -EINVAL; > >> > >> I was expecting this to actually go after _PAGE_USER, not necessarily > >> userspace addresses themselves. > > > > userspace ptes may not have _PAGE_USER set. (e.g. swap entry) > > I think it's more accurate to go after user addresses. > > It would, of course, have to be paired with _PAGE_PRESENT checks. This > works both on the way in and out of the set_memory code. It shouldn't > clear other bits a PTE with _PAGE_PRESENT|_PAGE_USER and You mean nothing should not use set_memory code for PTEs with _PAGE_USER|_PAGE_PRESENT but set_memory can still be used to clear _PAGE_USER|_PAGE_PRESENT? Can't we just simply deny any PTE/PMDs with _PAGE_PRESENT|_PAGE_USER? > also shouldn't > *result* in _PAGE_USER|_PAGE_PRESENT PTEs, even if those PTEs are in the > kernel address space. Makes sense. > Filtering on the addresses also makes sense. > > >> What does and should happen with the VDSO, for instance? It's a > >> _PAGE_USER mapping, but it's >TASK_SIZE. > > > > you mean vsyscall? AFAIK address of mapped vDSO image is < TASK_SIZE. > > (or please tell me I'm wrong) > > You're right. That was a silly thinko. > > >> Should set_page_attr() work on it? > > > > vsyscall does not need CPA functionalities. > > So I don't think it (__change_page_attr()) should work on vsyscall. > > Agreed. -- Thanks, Hyeonggon