From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from kanga.kvack.org (kanga.kvack.org [205.233.56.17]) by smtp.lore.kernel.org (Postfix) with ESMTP id 03AFCC7618E for ; Mon, 24 Apr 2023 12:28:15 +0000 (UTC) Received: by kanga.kvack.org (Postfix) id 624C56B0071; Mon, 24 Apr 2023 08:28:15 -0400 (EDT) Received: by kanga.kvack.org (Postfix, from userid 40) id 5ACD56B0074; Mon, 24 Apr 2023 08:28:15 -0400 (EDT) X-Delivered-To: int-list-linux-mm@kvack.org Received: by kanga.kvack.org (Postfix, from userid 63042) id 426A96B0075; Mon, 24 Apr 2023 08:28:15 -0400 (EDT) X-Delivered-To: linux-mm@kvack.org Received: from relay.hostedemail.com (smtprelay0012.hostedemail.com [216.40.44.12]) by kanga.kvack.org (Postfix) with ESMTP id 301F16B0071 for ; Mon, 24 Apr 2023 08:28:15 -0400 (EDT) Received: from smtpin13.hostedemail.com (a10.router.float.18 [10.200.18.1]) by unirelay07.hostedemail.com (Postfix) with ESMTP id EDDA2160190 for ; Mon, 24 Apr 2023 12:28:14 +0000 (UTC) X-FDA: 80716212108.13.79D070C Received: from NAM12-BN8-obe.outbound.protection.outlook.com (mail-bn8nam12on2070.outbound.protection.outlook.com [40.107.237.70]) by imf08.hostedemail.com (Postfix) with ESMTP id 1BB76160016 for ; Mon, 24 Apr 2023 12:28:11 +0000 (UTC) Authentication-Results: imf08.hostedemail.com; dkim=pass header.d=Nvidia.com header.s=selector2 header.b=rdDgs3Ha; spf=pass (imf08.hostedemail.com: domain of jgg@nvidia.com designates 40.107.237.70 as permitted sender) smtp.mailfrom=jgg@nvidia.com; dmarc=pass (policy=reject) header.from=nvidia.com; arc=pass ("microsoft.com:s=arcselector9901:i=1") ARC-Seal: i=2; s=arc-20220608; d=hostedemail.com; t=1682339292; a=rsa-sha256; cv=pass; b=cBMjkYEMngnliDidrBmqcw0QYmHX1/LjoRJjDAsWvb2+gwlsMzfsdlYY9V5UpbZQu9EI82 T3M3d6MphT1T3L1iUEbu8TrxMgwLhqY7BtDjH64gmACVjvpRN5xQfBGlUdM9Kv6YfXw+hj ekoQgsGAPuNwcMcKPRa+S8a0BxDWA7E= ARC-Authentication-Results: i=2; imf08.hostedemail.com; dkim=pass header.d=Nvidia.com header.s=selector2 header.b=rdDgs3Ha; spf=pass (imf08.hostedemail.com: domain of jgg@nvidia.com designates 40.107.237.70 as permitted sender) smtp.mailfrom=jgg@nvidia.com; dmarc=pass (policy=reject) header.from=nvidia.com; arc=pass ("microsoft.com:s=arcselector9901:i=1") ARC-Message-Signature: i=2; a=rsa-sha256; c=relaxed/relaxed; d=hostedemail.com; s=arc-20220608; t=1682339292; h=from:from:sender:reply-to:subject:subject:date:date: message-id:message-id:to:to:cc:cc:mime-version:mime-version: content-type:content-type:content-transfer-encoding: in-reply-to:in-reply-to:references:references:dkim-signature; bh=3Yywi1v4yxEyvAeodHfSd7JjtRF1MOcdgR30iZgKri8=; b=2m/vL14Ogr8V+V3rzquRCDLswH+KAgWeR4H093q75I8QBlDz+U69XS1v5XYZ2Cs+EvcuIN jH5AHtIdB6HxVh07eUz2O1AdwoVjB9CffzSuhv96DPm7VE2NXhhoirOpdhPSQ0OsCcXHGa Sp8Hm18nYUKACSg++BId3L81t+yBOT8= ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=iLwT8ouulF/tPAm6209wUXHekVdE9w+n8mV98cMBq1kXdvgwQTvmG2Dj1CDlMvFOLjEw7yyY7A+BQd/x15vHkIFGz6oWUdox3GrEwTGdUnoxT1zIas9W2Os3mpB7h2fsEB991tPBOh5OUcodf8L2LSUtEdK1OH1jRQXFS7aZS/TAZEkHu8xOOrrB6KfrrkkUchW9dycIq9sc87NnsqiIpSwfXDlkEEoR+87SNR33/uoltnVrmQor9+9A92jKFvHNko+VjO5xoVOUUgP9SM5PH1pyeCwJ3AhxUVGt1dAsugKkCnuT91ra1NL2RELqkDpRa+evgVxZt+ghmOzs4QW1uw== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=3Yywi1v4yxEyvAeodHfSd7JjtRF1MOcdgR30iZgKri8=; b=kbWIiFakVqSwZAM8z9j/GE0sms8OkCflcYL+wkTcC4/JEOKIAnMkdrcMyda3s0Su4XoWe7Oi8jaWN/3wD844G4pMjMMIrflrBSW1/AAmHvxKdUULA94UvXd2uX97wGhH9c8FOSBlvdGqD1PivTmC+WNEs9q8eYDDFzgzSFTTNe/C1bw7qWuCbw4ao8N0H6o4YC1DYDAK3LPofTerYCVB49CxUZZj5mf9LkE2UMZ0hL4U9HrUl/nu/taiCdHLMVwY7LVBQfhPG1CvbKtgujG1nc320fcyvlIxeA3A0RQ8egPIUXaZnSLx8PM6Bslrx0I4rd//cPZ9d9zsl32caqzyLQ== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=nvidia.com; dmarc=pass action=none header.from=nvidia.com; dkim=pass header.d=nvidia.com; arc=none DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=Nvidia.com; s=selector2; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=3Yywi1v4yxEyvAeodHfSd7JjtRF1MOcdgR30iZgKri8=; b=rdDgs3HaB/Pn/fW5jYI+rH7bfX3pR99hSYjMe7qd/ccrCFUi1OgPL5uVCigaWSRcmdgqb8WcaYjIzfvaftb8Yk4H/l8JplBzhXozpgO9R7g8bdGH7LLgdBIda0TsL8Uc4x6nVtO7MTEgLws1NO3TrG7wwGHfPi2fObDQUkVCkKafDNjvcwR7C5fkr6vEDjSzLrq/Mp8Rq8OrEaIz8RCBU52FXfjI4jQW52F46/u0i8jqRe/YWjAz7JNKIoZkYWJ62k3eP8apxrWWgAaMiHy20qtyD26a2/+dovQnptZ1gi4z6Dz2awVXKbVcIrQKB4lZq7TjlL66hidBE452JOrMAg== Received: from LV2PR12MB5869.namprd12.prod.outlook.com (2603:10b6:408:176::16) by SN7PR12MB7323.namprd12.prod.outlook.com (2603:10b6:806:29a::5) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.6319.33; Mon, 24 Apr 2023 12:28:09 +0000 Received: from LV2PR12MB5869.namprd12.prod.outlook.com ([fe80::f7a7:a561:87e9:5fab]) by LV2PR12MB5869.namprd12.prod.outlook.com ([fe80::f7a7:a561:87e9:5fab%5]) with mapi id 15.20.6319.033; Mon, 24 Apr 2023 12:28:09 +0000 Date: Mon, 24 Apr 2023 09:28:07 -0300 From: Jason Gunthorpe To: Lorenzo Stoakes Cc: Christoph Hellwig , linux-mm@kvack.org, linux-kernel@vger.kernel.org, Andrew Morton , Jens Axboe , Matthew Wilcox , Dennis Dalessandro , Leon Romanovsky , Christian Benvenuti , Nelson Escobar , Bernard Metzler , Peter Zijlstra , Ingo Molnar , Arnaldo Carvalho de Melo , Mark Rutland , Alexander Shishkin , Jiri Olsa , Namhyung Kim , Ian Rogers , Adrian Hunter , Bjorn Topel , Magnus Karlsson , Maciej Fijalkowski , Jonathan Lemon , "David S . Miller" , Eric Dumazet , Jakub Kicinski , Paolo Abeni , Christian Brauner , Richard Cochran , Alexei Starovoitov , Daniel Borkmann , Jesper Dangaard Brouer , John Fastabend , linux-fsdevel@vger.kernel.org, linux-perf-users@vger.kernel.org, netdev@vger.kernel.org, bpf@vger.kernel.org, Oleg Nesterov Subject: Re: [PATCH v2] mm/gup: disallow GUP writing to file-backed mappings by default Message-ID: References: <90a54439-5d30-4711-8a86-eba816782a66@lucifer.local> Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <90a54439-5d30-4711-8a86-eba816782a66@lucifer.local> X-ClientProxiedBy: MN2PR01CA0032.prod.exchangelabs.com (2603:10b6:208:10c::45) To LV2PR12MB5869.namprd12.prod.outlook.com (2603:10b6:408:176::16) MIME-Version: 1.0 X-MS-PublicTrafficType: Email X-MS-TrafficTypeDiagnostic: LV2PR12MB5869:EE_|SN7PR12MB7323:EE_ X-MS-Office365-Filtering-Correlation-Id: d3f43c0a-5527-469d-bb84-08db44bf5cd6 X-MS-Exchange-SenderADCheck: 1 X-MS-Exchange-AntiSpam-Relay: 0 X-Microsoft-Antispam: BCL:0; X-Microsoft-Antispam-Message-Info: wf7gcm6tA5NbF+SAUsUeLCOl8p9tspDKE7TeWv2z3iyliupkH4mMahFAmzKP0sWj/jUbZ1znRaqFKMiU2VZMCcDWMS+cdyVaFciLyY+FDLO+TYVdeg9+yooE9LwLUXKakUVe+bx2PbFWkwm90XWN47maHZQayqkiXMmQItuOYMdKCLSXjkZ4sSLQwUeHhlvyFoQhVe+cVCn6hFMXC/nikmxeghRmXwe9LbnQFvBB0j19/FymIusDnMQKAb4I3PNqrnMvNqkwZFDoUjyqi+lxi1TdbfaDL/HuP/eIKxZFKv+7tVDQWQEm6XOmSb7gQtKJGy06zVQdaDgCiloSyecYN79l4GOrB07M7/qSyf1jLDZx+hvOd5ayeSeCHcfpHIWPQjyqCG8C0zhcSPKeTIfoccwAMiXFWV300u1t7IeVnkr43LYzig8LytKbW9ygaaK3gzxnUQ/ETGhYrYmF6ynM5znkyVizkGS6eGKyCg5FTUL4jq9+j2/LSioVshVoEz9uDJed6C2zx7yWCLUynVBchcRqINvPhJf/D5/iH6lzSVlyuTFTHqxfIZuW+2c6v76n X-Forefront-Antispam-Report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:LV2PR12MB5869.namprd12.prod.outlook.com;PTR:;CAT:NONE;SFS:(13230028)(4636009)(346002)(366004)(136003)(39860400002)(376002)(396003)(451199021)(6486002)(66556008)(66476007)(66946007)(6916009)(2906002)(6506007)(8936002)(83380400001)(186003)(8676002)(2616005)(41300700001)(26005)(6512007)(5660300002)(316002)(7406005)(7416002)(86362001)(54906003)(36756003)(38100700002)(4326008)(478600001);DIR:OUT;SFP:1101; X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 1 X-MS-Exchange-AntiSpam-MessageData-0: =?us-ascii?Q?j174vHmSMr+YHea+C1ouuWHGwxBl3a3p+cxK1v2QKinaIDzLRQHJbfVNiahu?= =?us-ascii?Q?njtpR5R9zJLW1Ki9R0J65DljOVRWZ4OzFGRC10wqaTK2Yj0mFG7/SWS0kVer?= =?us-ascii?Q?QZNbdm9UOV/nR7ni3tPj5LHBjFUsw12n2oZm8OsyXyIN+tmBP5CykqbiWuS0?= =?us-ascii?Q?+jVYRRvwg0p31JxHcczmWaErFTNmeYZsf/3/W+YpopVnaXn14JEN3uBPKQPc?= =?us-ascii?Q?EOqa6WBAwWwEPdoiDYE5n3zk9MM2FwIY8nNZDjZXteVeGAwUFiAWx16XYh04?= =?us-ascii?Q?UvWRRyI8tOT9bcYcGpGUv6IMQSGbMIcxtosaF6Y6ejyv4yr8NR1SoJ8jeMGH?= =?us-ascii?Q?hZ/YfQH5SY/NNStJpgowmdbWT1aLh3egn5DcUQyRYfXxG0jiK1WUYHsScI5F?= =?us-ascii?Q?TSAjyg6AGLDh0jtj2w5oz4XuYw6XOS0a7sO/Ui05677mqYh4rBasNXC9MXET?= =?us-ascii?Q?mlx/dex+lF9HVYgT/NpMd9Y1F2Lw/eEVw3DWdw+tYTNF45YAENd5rXwAj8gg?= =?us-ascii?Q?9yOhgmQPe8VDidaHrfcXqqbv3aWzNm8AmT8dswdH6Heuc8TBYLTmh79933DG?= =?us-ascii?Q?dlIoM20A15wYSPT5T1Df+Of9OkR11ytzXCkyKHFVYBoeaK964DSF+CSW3ewi?= =?us-ascii?Q?tYE7mWqbye0nsax0p3B8//U7WN1Xig1Unr1mOAqIQ0j5n+viEppjVUKklIEf?= =?us-ascii?Q?IdkcuOvlWtO1aUoWa3qdNoHyv+sYsbDrGdvuRmb3m8Ds0cpvfJt49Q7MIhtn?= =?us-ascii?Q?o27Y+siSvNeSWYelOmgId18XLE0ItVT2QoTwLfrEUAV0PV2OiCP93TYYKlnE?= =?us-ascii?Q?x4pYA6Ygs7NVzoiQnxd8ZJCBqiftebsOhqznssEBc1UugzPU6YjlF/aTZ4nb?= =?us-ascii?Q?RetgkwQdHcV9+l7h1yaKkCNcNPD2jord8CLflmO/v/w3/Be31yGhb5RbAG8J?= =?us-ascii?Q?8gT+AuiUNXfpRYAFs6uDBdMgmoAsAzXgso/KSxAm2ICTomAPxJ96h8cTynso?= =?us-ascii?Q?D3tvGq4QOZnfEpaX81gPr5RfSlrdAILsj3Ola41uHU3DBz0Aro6FYDUvRW6C?= =?us-ascii?Q?eD0f1RS9DzNSx12TQVoxkaiXimiYrkiEw5rbRp+RlhkRDeP0lJNhpxTpCeza?= =?us-ascii?Q?AkFVni10KinokSuA2hWjR3dbEbCPrGpYzCA6W23U49G7EBTfLdveKF3spnId?= =?us-ascii?Q?oLzxtIUGaHnhB+zOhfVnIR+NPkdIPzWU5ysC6VuAGuXa+ayz0shiyMT5tvfQ?= =?us-ascii?Q?RI/xvNgALI4e+qOWXKJF6/g8gcYDSQ83mxLpLZcABKh1swngkwpwa+oYW18x?= =?us-ascii?Q?M46taJR68G0D6oBfGYvP0TN2jJlj7zRBkQrr+QJKghrMLI2KZw9Z6Zdpp5wx?= =?us-ascii?Q?Q8UWtYcAG4l+c9uImn2GF7bCCBnkjuYtEjEpSzpIAsB6NGR+eNXgXub3LWxM?= =?us-ascii?Q?MMM11MfT5bHfzmkq2uZI4PM91Hr01B5eLETqNBIt1SqcP52txLClMuSMBw+b?= =?us-ascii?Q?cTfYiCpWq/D9ubIrZytcfdMFYkW2zb3QSnlmJqu5a+3MThEla5T1bpaRt3eR?= =?us-ascii?Q?2vVbd9wrEmya/uJjQX8=3D?= X-OriginatorOrg: Nvidia.com X-MS-Exchange-CrossTenant-Network-Message-Id: d3f43c0a-5527-469d-bb84-08db44bf5cd6 X-MS-Exchange-CrossTenant-AuthSource: LV2PR12MB5869.namprd12.prod.outlook.com X-MS-Exchange-CrossTenant-AuthAs: Internal X-MS-Exchange-CrossTenant-OriginalArrivalTime: 24 Apr 2023 12:28:09.2049 (UTC) X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted X-MS-Exchange-CrossTenant-Id: 43083d15-7273-40c1-b7db-39efd9ccc17a X-MS-Exchange-CrossTenant-MailboxType: HOSTED X-MS-Exchange-CrossTenant-UserPrincipalName: KKRODEFt0zDz2AFUpABDX0IKQuqU3lU5UpVwX9KwKM2jUfy+BXGxn9rxcj4tPMIK X-MS-Exchange-Transport-CrossTenantHeadersStamped: SN7PR12MB7323 X-Rspam-User: X-Rspamd-Queue-Id: 1BB76160016 X-Rspamd-Server: rspam01 X-Stat-Signature: gsjbgwwzjn6yj687isxdn4mt3e4n75zi X-HE-Tag: 1682339291-356020 X-HE-Meta: U2FsdGVkX1+Ywqm9NgGXOiSLl4khDezxoxUaasnfBN1ZKBjxRHnBV4viviULSkXlJnQzcR0eNQ22M9z/mIpARDbFuIdoKCdYfrIbjpARWX2V2cENUPUkqpNGoFfSqb+ykMUalCEk+zw4f8VZ8TNM82EtWkqqWgt9CKUGDURA0DLZu3+b8MUbQAnz74tC8VSVYUVD60iDxbC1Xd1iQBzjBGZyOmudiTrOJ4qEEUBH4MtBXGLEbQNOS0gIGUrhdb+X8bMazYwUARqqvy/mh45T7fgU3SpZZHO7xe+jsf1a4cOj2ZEB4UUZTVAggWaAG/w8yStDtfj14j2+Ru/6qiqAF3T3mUoIiNcdMTjimsJuFt0paoAbPdDqHP9pNd95JXsr4slAKOtwKnvRUeQpUEM9VpTfh6Tzf8kNTpD/BTKGMsNs8jpgaH2yP/iyMRKH3E4kyKSU4op00aWv0Dv9FxVxQK4JOiEHc03h/YjYgn2jyh0R7jZPWd15WbHtB/5yl2d7a9UtJ3kSb1HKyhRGsOGar9BqX2b6TyyDhII+tvZVJoQse8CV64fN13wZC1QISye7OiQfJo5wHAAz42jclB1IiFLnB431Bzy6sgBPSkZ3u5rvBZ+mm/6YRP0SFUa+aWe426bN4CZ8VfzDiRmrTSFh0wMgl/QI3JUGrQvpm4qRb0aOpKyPaOOMnSsYG3L9g2Knj1pteave7oU/QCZUuB66a+BSLzlFeOM00qlAu7CZpUURUNZ/OX4NTIqEl+dysis2NNlqi4K1Zq83HuJeQqSOwSKGkKSg0gQVU+mGSAdEFrHvlb9Y1rwO7EH487HaB/UIgwoPSfEJYpmviXedKv7qCy/FdSrIgLX/lX6PqMT3UyueeibtbdL9R9ertobtfgT4mOr/J2lcTQlvtwS8S3SJe34PgGW8883EoQLitccBbQBxQlo7CXv+niVkE8Cce059PNCxor3I1kriwyQ330V Gxy2kPI5 eGsm2/0RO0BfYA96qv1oGU4FakSnblx0wduMc4fMBDSq+oy/u9v6gdnFFKJFC7y7P9e/f5D4+0QWkV4/gQ8cI6rqJnO6hnMU8ZAGROuQfV8FLh3PGHzpdQ2vNH7hlga3LT9F/1ZMVN//jQYtFoGXeXDQ3+4sQes1WbHu4DW1iSdc/18s9NEQN8TMDzKmQR9xC+XKqndYQgFK/Ev3g5Hs8AHZ7rRV+Uz8pdA2+BdcAe2gOr6Bk17DmV/WBPyXUAPmYRER5r7AeUVBdGDj1y/LYpTdWreoVNQYIMbOq X-Bogosity: Ham, tests=bogofilter, spamicity=0.000000, version=1.2.4 Sender: owner-linux-mm@kvack.org Precedence: bulk X-Loop: owner-majordomo@kvack.org List-ID: On Mon, Apr 24, 2023 at 11:17:55AM +0100, Lorenzo Stoakes wrote: > On Mon, Apr 24, 2023 at 02:43:56AM -0700, Christoph Hellwig wrote: > > I'm pretty sure DIRECT I/O reads that write into file backed mappings > > are out there in the wild. I wonder if that is really the case? I know people tried this with RDMA and it didn't get very far before testing uncovered data corruption and kernel crashes.. Maybe O_DIRECT has a much smaller race window so people can get away with it? > I know Jason is keen on fixing this at a fundamental level and this flag is > ultimately his suggestion, so it certainly doesn't stand in the way of this > work moving forward. Yeah, the point is to close it off, because while we wish it was fixed properly, it isn't. We are still who knows how far away from it. In the mean time this is a fairly simple way to oops the kernel, especially with cases like io_uring and RDMA. So, I view it as a security problem. My general dislike was that io_uring protected itself from the security problem and we left all the rest of the GUP users out to dry. So, my suggestion was to mark the places where we want to allow this, eg O_DIRECT, and block everwhere else. Lorenzo, I would significantly par back the list you have. I also suggest we force block it at some kernel lockdown level.. Alternatively, perhaps we abuse FOLL_LONGTERM and prevent it from working with filebacked pages since, I think, the ease of triggering a bug goes up the longer the pages are pinned. Jason