From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from kanga.kvack.org (kanga.kvack.org [205.233.56.17]) by smtp.lore.kernel.org (Postfix) with ESMTP id 8AD86C77B75 for ; Tue, 16 May 2023 12:54:17 +0000 (UTC) Received: by kanga.kvack.org (Postfix) id 09A7F900006; Tue, 16 May 2023 08:54:17 -0400 (EDT) Received: by kanga.kvack.org (Postfix, from userid 40) id 048F7900002; Tue, 16 May 2023 08:54:16 -0400 (EDT) X-Delivered-To: int-list-linux-mm@kvack.org Received: by kanga.kvack.org (Postfix, from userid 63042) id E79DE900006; Tue, 16 May 2023 08:54:16 -0400 (EDT) X-Delivered-To: linux-mm@kvack.org Received: from relay.hostedemail.com (smtprelay0013.hostedemail.com [216.40.44.13]) by kanga.kvack.org (Postfix) with ESMTP id D4332900002 for ; Tue, 16 May 2023 08:54:16 -0400 (EDT) Received: from smtpin30.hostedemail.com (a10.router.float.18 [10.200.18.1]) by unirelay04.hostedemail.com (Postfix) with ESMTP id A7E461A0270 for ; Tue, 16 May 2023 12:54:16 +0000 (UTC) X-FDA: 80796111312.30.7209EF5 Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.133.124]) by imf25.hostedemail.com (Postfix) with ESMTP id 6B18FA0006 for ; Tue, 16 May 2023 12:54:13 +0000 (UTC) Authentication-Results: imf25.hostedemail.com; dkim=pass header.d=redhat.com header.s=mimecast20190719 header.b="QIcXQ/Sh"; spf=pass (imf25.hostedemail.com: domain of david@redhat.com designates 170.10.133.124 as permitted sender) smtp.mailfrom=david@redhat.com; dmarc=pass (policy=none) header.from=redhat.com ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=hostedemail.com; s=arc-20220608; t=1684241653; h=from:from:sender:reply-to:subject:subject:date:date: message-id:message-id:to:to:cc:cc:mime-version:mime-version: content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references:dkim-signature; bh=z1qCVHKGyMmBkvSwj8jD8xadePPBV5y07Cbb6BpzJk0=; b=FXM2YEwqPgQ+1wnV9AY9A1E5Whx9oH4chiRNr28ZsPqwSd9KD3FUexyK+xIRzywiG0kvMS M38euWBzHiQlE2myugP5Hf+ckSUfnJHbeLK+Yj36vZgAe786lNBCya2boaAOTX4U5GFerM HkKes8CBVtTNhGo81/q2Sew9UTT3KP0= ARC-Authentication-Results: i=1; imf25.hostedemail.com; dkim=pass header.d=redhat.com header.s=mimecast20190719 header.b="QIcXQ/Sh"; spf=pass (imf25.hostedemail.com: domain of david@redhat.com designates 170.10.133.124 as permitted sender) smtp.mailfrom=david@redhat.com; dmarc=pass (policy=none) header.from=redhat.com ARC-Seal: i=1; s=arc-20220608; d=hostedemail.com; t=1684241653; a=rsa-sha256; cv=none; b=bMnUwpIb3UvYdejegdSz3Ty/TVPptPbXaUzd5Bcg6J0AGl8brXZ2ne3WZVDHDM29v7k1yR ti2vL9oMr0+J4qVnvd9xAbm8rTwYsGyOmBKN+LWhTOgtbmEYMOOOkoa/cUAIRYRBHbwfeI whOlxxYk9GxCSSreFmIuu2QBv7iWsgM= DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1684241652; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=z1qCVHKGyMmBkvSwj8jD8xadePPBV5y07Cbb6BpzJk0=; b=QIcXQ/Sh040nOtwhpmsFOg/PxpUwS5wJJwYFckJ16xxNb3/3WTEb4ZGP3GL7nXRDforqLt FfDffZqIHjmzvCclBvlkhK/Tp0XymxsoItbIvvImEnPFnavYxfGtfAsEpR0/SNrgWYUlCb ZAq0ip3xSDu/zsk7j+VsTyYourXCLq4= Received: from mail-wm1-f70.google.com (mail-wm1-f70.google.com [209.85.128.70]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-520-oqc_RNOANhKSHpj-rPEoWw-1; Tue, 16 May 2023 08:54:08 -0400 X-MC-Unique: oqc_RNOANhKSHpj-rPEoWw-1 Received: by mail-wm1-f70.google.com with SMTP id 5b1f17b1804b1-3f509037a45so18716825e9.1 for ; Tue, 16 May 2023 05:54:08 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20221208; t=1684241647; x=1686833647; h=content-transfer-encoding:in-reply-to:organization:from:references :cc:to:content-language:subject:user-agent:mime-version:date :message-id:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to; bh=z1qCVHKGyMmBkvSwj8jD8xadePPBV5y07Cbb6BpzJk0=; b=LrIkLvJKETYXYBM8W/EZilESPB6DtCi0Wwco/YykRHCXOrMZMSYha+w8aueNZn2df+ WopFW2UnAbwLSbNrJ+69ildFHwJtKydTI9Cl3iRozOAUoNsklgSfPq+E2ciRNQ31z3NH uMvwctKVk8tbq55Xlx1FR+xnjgORoceVb6dAWiRuE+xqAem4lQyrB8qAGdjnEEJQEvnk Pkf2R5yO7ee7xmSKN/HyHtcKTcOVMLWPiRY2LoiS+IoZtIDgzIQ2Fe/dbuZyqqQbDbRj TTHKdEssHlRLcZYPZ5PWVYZ6wWThfx9RbfOjTpekm5pNhiMLm6K7ihvcDus0cdQL3f1D SfTQ== X-Gm-Message-State: AC+VfDzwsgxMErUw3flFBkx68gomAHMlBFGwG9utg7Lp+XW99bhr7LwU N/LF7rFdQJG9pEFrVQSJa6y8wkfWEedVt3nMUGCzS/VTDSPjtXZZKZHpzwbN+mjZMr3Ze/olciC 1qCFAaRl7gTo= X-Received: by 2002:adf:feca:0:b0:2fb:92c7:b169 with SMTP id q10-20020adffeca000000b002fb92c7b169mr29878254wrs.10.1684241646773; Tue, 16 May 2023 05:54:06 -0700 (PDT) X-Google-Smtp-Source: ACHHUZ5E3HQhNNLuXMmrsn3WJ8GykAt/5MVJ7LuTbKLv8blwYpd6a7g3VYLzeJsCM48zuxrgXN/dEQ== X-Received: by 2002:adf:feca:0:b0:2fb:92c7:b169 with SMTP id q10-20020adffeca000000b002fb92c7b169mr29878230wrs.10.1684241646425; Tue, 16 May 2023 05:54:06 -0700 (PDT) Received: from ?IPV6:2003:cb:c74f:2500:1e3a:9ee0:5180:cc13? (p200300cbc74f25001e3a9ee05180cc13.dip0.t-ipconnect.de. [2003:cb:c74f:2500:1e3a:9ee0:5180:cc13]) by smtp.gmail.com with ESMTPSA id w12-20020a05600c474c00b003f07ef4e3e0sm34062325wmo.0.2023.05.16.05.54.05 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Tue, 16 May 2023 05:54:06 -0700 (PDT) Message-ID: Date: Tue, 16 May 2023 14:54:04 +0200 MIME-Version: 1.0 User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:102.0) Gecko/20100101 Thunderbird/102.11.0 Subject: Re: [PATCH v2 4/4] mm: page_table_check: Ensure user pages are not slab pages To: Ruihan Li , Pasha Tatashin Cc: linux-mm@kvack.org, linux-usb@vger.kernel.org, linux-kernel@vger.kernel.org, Matthew Wilcox , Andrew Morton , Christoph Hellwig , Alan Stern , Greg Kroah-Hartman , syzbot+fcf1a817ceb50935ce99@syzkaller.appspotmail.com, stable@vger.kernel.org References: <20230515130958.32471-1-lrh2000@pku.edu.cn> <20230515130958.32471-5-lrh2000@pku.edu.cn> From: David Hildenbrand Organization: Red Hat In-Reply-To: X-Mimecast-Spam-Score: 0 X-Mimecast-Originator: redhat.com Content-Language: en-US Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 8bit X-Rspam-User: X-Rspamd-Server: rspam01 X-Rspamd-Queue-Id: 6B18FA0006 X-Stat-Signature: wiwrdftiijdejah6aqpdiubmfa4qtgh5 X-HE-Tag: 1684241653-529847 X-HE-Meta: U2FsdGVkX1/hHEE652CuBe6aOMg+D7QlpxYSvHNTspDK/ABfUCcykpPbVuPEIvA+W54PNWBsuMLV3qZc7CVLiIGXO8f563ZcMhUatbRHQ2neba50QpOVTzTbEfNdv0ELprwSE++d+8nwU/4BYete+cTRaYn+k+NWjFTpD6Old5kaF5Hm2UpIGeWI9N7QrCYa7kFnElGhVQygLe8y86pZgFgxUk0X21qzJuP8895LdCbvP2Tjl9Ao4C2FQEJCx6BwOnc5+/uLVwWXRnnUX04JpvXAO1FnShOw85GdmYrwoHkzoXtoCat8w/i18gNdCBWbuI5a93JpcnAG0xiMyJam/5nH9odLM8PeuQ/DRjG9g4BEzd4WPrXWL5oHwCpJ3/H9PhvhJkjYdwBGJXnIcYLv10xs/SFG9LrOu3zuPjroEApJ0fjcGUVdnKNmI635Ic31knNIYoba6qWFgTrWBMqqed37R01KFJAlVK0H9teY/G2KWV5ckXxZizJWSuJWjDdpPyEY5J2nS1HOM/d8KA2H1GAg86yxDc8fqK7t+IOz1yt1sTyyYUwJatpkFUY3swoT5XA3KXRL6CCbHvl003ffqqeylrC1WBPwAM6+RSwW7wspq+Ow2dJ6Tr2VG/J0XbWbCvLTWaXrk2Usi1qlQp2PZ7uzbZRX4vIVjkHyrC1O7eYHarK698owTeAamxwk5fx3LKPkoT+ZJvX4vEu1Cq5M1VDSD7Ho4A7K4R2CZjqtDyfEMsDhZ4NvgxMTYu8lcORyklU5sknPIfdJ5IQiBmUZcqT4B2iRsuyJSkBfA58gbQT8fWtLASsFjdZqnLxZwlwqIOZMOuMoNLg4uM18SHnOCVM5NrZmE4ryV1r95FCKPr0kJEoY0oCnIYj2OtN+2ECl7GAo7+b98HTreWw4n8NuT1Swp5XOY2yo3sKgj3uXwyJzrXT9D6GcFLkt0aa6FVbLyIk9U1FQ5ci+0x8kMsX im4kI090 12MurcDg5O1qBUQZxRSKbQosCeyoI8cwPBZUyVFL3tcRkyNH4sdx9eMy99r5TbgJ2TuE09dWWZKqFDJ0tGV67icgzpcEMrHZgS5eFNjTSdo71sQzTHgcmeJqfXADGRtKMXNDlY4bQuMd1hRI1VpLOD5mQFPuf9gUxOLBXekN3p1rDvh0ftF7UkMUVtyE82OetXGToHTvFirTXswszbjNGzQxpa9nhgfDvz1VGAgSlN1eg8F/nkm1nfQRveLHmhBKjrQgaq85SY6dil0lsIlRi/x10D2crGzbo/rdwP0WQxeUFWWFN4C5exsQ++dwYUY/lXHd1D1HMTR7leB0CayHqL7654vpeaEfXCXvWd4otLYCaioT9UIL1YWfT90Tld8MU+aT/XOCIYqFyGEW6LjL3Sb8BRLqOn6Xuhk4G4QuVA4IMz1MCHgtz4WnDKIGwnBxlWQYR2N+j4rBbS9n5139RQjnlsN45f5kUO4ShmdbEOr+2SiGwdQrhGIYYod3M5oZx+NexugKykcjymLtvn6b76E7xwm7MJn7qKaUEHkTdiUcYjF/UPz1dbiF7X30+cDtcTS0oWeZBtYLMwv61an9WW1hsFa/fQkTcltJgduc2NKDTtkMrsMKWAcuUPi7hBby0gXqYxh1YTmqMHlSV4h12tyV4S/HHsXRrBRXF5+H2zbzOaIisqHroB7/xw58Q+di61rr2mPq+SQNLVtwkE2yya6gbc+uvYZgskJ3p X-Bogosity: Ham, tests=bogofilter, spamicity=0.000000, version=1.2.4 Sender: owner-linux-mm@kvack.org Precedence: bulk X-Loop: owner-majordomo@kvack.org List-ID: On 16.05.23 13:51, Ruihan Li wrote: > On Mon, May 15, 2023 at 12:28:54PM -0400, Pasha Tatashin wrote: >> >> On Mon, May 15, 2023 at 9:10 AM Ruihan Li wrote: >>> >>> The current uses of PageAnon in page table check functions can lead to >>> type confusion bugs between struct page and slab [1], if slab pages are >>> accidentally mapped into the user space. This is because slab reuses the >>> bits in struct page to store its internal states, which renders PageAnon >>> ineffective on slab pages. >>> >>> Since slab pages are not expected to be mapped into the user space, this >>> patch adds BUG_ON(PageSlab(page)) checks to make sure that slab pages >>> are not inadvertently mapped. Otherwise, there must be some bugs in the >>> kernel. >>> >>> Reported-by: syzbot+fcf1a817ceb50935ce99@syzkaller.appspotmail.com >>> Closes: https://lore.kernel.org/lkml/000000000000258e5e05fae79fc1@google.com/ [1] >>> Fixes: df4e817b7108 ("mm: page table check") >>> Cc: # 5.17 >>> Signed-off-by: Ruihan Li >> >> Acked-by: Pasha Tatashin >> >> I would also update order in mm/memory.c >> static int validate_page_before_insert(struct page *page) >> { >> if (PageAnon(page) || PageSlab(page) || page_has_type(page)) >> >> It is not strictly a bug there, as it works by accident, but >> PageSlab() should go before PageAnon(), because without checking if >> this is PageSlab() we should not be testing for PageAnon(). > > Right. Perhaps it would be better to send another patch for this > separately. Probably not really worth it IMHO. With PageSlab() we might have PageAnon() false-positives. Either will take the same path here ... On a related note, stable_page_flags() checks PageKsm()/PageAnon() without caring about PageSlab(). At least it's just a debugging interface and will indicate KPF_SLAB in any case as well ... -- Thanks, David / dhildenb