From patchwork Mon Feb 26 08:19:44 2018 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Alex Shi X-Patchwork-Id: 10241527 Return-Path: Received: from mail.wl.linuxfoundation.org (pdx-wl-mail.web.codeaurora.org [172.30.200.125]) by pdx-korg-patchwork.web.codeaurora.org (Postfix) with ESMTP id E163B602DC for ; Mon, 26 Feb 2018 08:30:47 +0000 (UTC) Received: from mail.wl.linuxfoundation.org (localhost [127.0.0.1]) by mail.wl.linuxfoundation.org (Postfix) with ESMTP id C867429D40 for ; Mon, 26 Feb 2018 08:30:47 +0000 (UTC) Received: by mail.wl.linuxfoundation.org (Postfix, from userid 486) id 8E18929DB9; Mon, 26 Feb 2018 08:30:47 +0000 (UTC) X-Spam-Checker-Version: SpamAssassin 3.3.1 (2010-03-16) on pdx-wl-mail.web.codeaurora.org X-Spam-Level: X-Spam-Status: No, score=-1.9 required=2.0 tests=BAYES_00,DKIM_SIGNED, DKIM_VALID autolearn=unavailable version=3.3.1 Received: from bombadil.infradead.org (bombadil.infradead.org [198.137.202.133]) (using TLSv1.2 with cipher AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mail.wl.linuxfoundation.org (Postfix) with ESMTPS id 5F24629DCC for ; Mon, 26 Feb 2018 08:30:45 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.infradead.org; s=bombadil.20170209; h=Sender: Content-Transfer-Encoding:Content-Type:MIME-Version:Cc:List-Subscribe: List-Help:List-Post:List-Archive:List-Unsubscribe:List-Id:References: In-Reply-To:Message-Id:Date:Subject:To:From:Reply-To:Content-ID: Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc :Resent-Message-ID:List-Owner; bh=57ZW7ZVbnd22lmuBpW01kpzHIQobdl47M3mZpe6vID0=; b=Mk+DJcavu8/pvslp9o8Gi1Cvkr 0QxFFsowTNkiFjoYXSXc3nk4FYdsa0o04AyZlSXcJQKvnXDDidpzCJAt+4GLl1pXDef7V2dP3SoWU mmJo9KA7QuPyCUupMXkIpVdX9mcT2DXuFHPCCFeZ50ipOuFzmbVd40HfbKoXzUsEbxzlyppZT7SFx V5eEc2+F1WGFRLW0mAoNRpq0T8ecwgOb6BV1kMdK/Y69hF+w1mTzl2VSyhby3/HDCZI+FCHO0nY3r pVMwomCQGhNAIOrxNrYXmEnDHl7wCqa/BX62pmhLEYJWIeMC7kaEmILJ690Jc6qD2n0X2wmbVEE3u edOQ44XA==; Received: from localhost ([127.0.0.1] helo=bombadil.infradead.org) by bombadil.infradead.org with esmtp (Exim 4.89 #1 (Red Hat Linux)) id 1eqEB4-0007WO-I5; Mon, 26 Feb 2018 08:30:30 +0000 Received: from mail-pg0-x241.google.com ([2607:f8b0:400e:c05::241]) by bombadil.infradead.org with esmtps (Exim 4.89 #1 (Red Hat Linux)) id 1eqE3K-0000hK-Cy for linux-arm-kernel@lists.infradead.org; Mon, 26 Feb 2018 08:23:04 +0000 Received: by mail-pg0-x241.google.com with SMTP id g12so5910964pgs.0 for ; Mon, 26 Feb 2018 00:22:20 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linaro.org; s=google; h=from:to:cc:subject:date:message-id:in-reply-to:references; bh=i4j5LLlcJTrNi6a03osuM7FMBFfhyS0MAdksfWz86sU=; b=JAXXbMCFb1ywC7DpCbKF9Md+/6NZLBeBNU/5p9nQW44JJHgLVsijAuPprSsoWWT8r8 Iez3tDbLbtVRIlMjyyubTxKSFyo1KXxFHWg9bs9MiCS8MP60KANfh02NIvU40WIgXj3u u3o4rkybMjWSWGC0O3qTMC+AurxbDZkQL15Xs= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:to:cc:subject:date:message-id:in-reply-to :references; bh=i4j5LLlcJTrNi6a03osuM7FMBFfhyS0MAdksfWz86sU=; b=mn97hgNEat165B5Z8+/QrhwVtYQ8wFOZaxAE7qmYomoNeVdM/vGIjK3Yezo8eJXaZ1 76a9iYC/zC5eVbBk2gdm+UZNDUly7+0polJcecDbs7PQtx9IJQbSous+WaUDZs8JqiY4 gw0fXSi//isVQdmY4LA0Hof4hvuWGc6SPSAErnvwSW7k8fJPNPWEpOLu63VdmKTYXLHZ Y2xUZbTwKp/m7vwE9uT0/tazbqfQsqgZavjlNtDMssgqtbcMJXRWcg/96mN5Z42B7j4J CLWRGZ0JbuyZ5UiY/vzZHLmyUqf/fvU1NmRZ8nsVG7uFYwC8mcmCRdTztQ9OK0CloIrR ho/w== X-Gm-Message-State: APf1xPC263NVU7gUSEm14Pun8yL2V74pRstDzURkOhGR3mdP5SnC6HBT Ha7I4FNFUq7YumyXrs0+nPMWsA== X-Google-Smtp-Source: AH8x2240v9HJxH7eArEAuo+3ebxf9m37afhAiJHH6uqC9ak7tcWxn+nteuodgO7OODWSgXs2ki9+Iw== X-Received: by 10.101.99.205 with SMTP id n13mr7925896pgv.345.1519633339675; Mon, 26 Feb 2018 00:22:19 -0800 (PST) Received: from localhost.localdomain (176.122.172.82.16clouds.com. [176.122.172.82]) by smtp.gmail.com with ESMTPSA id o86sm1422706pfi.87.2018.02.26.00.22.13 (version=TLS1_2 cipher=ECDHE-RSA-AES128-SHA bits=128/128); Mon, 26 Feb 2018 00:22:19 -0800 (PST) From: Alex Shi To: Marc Zyngier , Will Deacon , Ard Biesheuvel , Catalin Marinas , stable@vger.kernel.org, linux-arm-kernel@lists.infradead.org (moderated list:ARM64 PORT (AARCH64 ARCHITECTURE)), linux-kernel@vger.kernel.org (open list) Subject: [PATCH 10/52] arm64: Use pointer masking to limit uaccess speculation Date: Mon, 26 Feb 2018 16:19:44 +0800 Message-Id: <1519633227-29832-11-git-send-email-alex.shi@linaro.org> X-Mailer: git-send-email 2.7.4 In-Reply-To: <1519633227-29832-1-git-send-email-alex.shi@linaro.org> References: <1519633227-29832-1-git-send-email-alex.shi@linaro.org> X-CRM114-Version: 20100106-BlameMichelson ( TRE 0.8.0 (BSD) ) MR-646709E3 X-CRM114-CacheID: sfid-20180226_002231_125916_908299A0 X-CRM114-Status: GOOD ( 13.25 ) X-BeenThere: linux-arm-kernel@lists.infradead.org X-Mailman-Version: 2.1.21 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Cc: Robin Murphy MIME-Version: 1.0 Sender: "linux-arm-kernel" Errors-To: linux-arm-kernel-bounces+patchwork-linux-arm=patchwork.kernel.org@lists.infradead.org X-Virus-Scanned: ClamAV using ClamSMTP From: Robin Murphy commit 4d8efc2d5ee4 upstream. Similarly to x86, mitigate speculation past an access_ok() check by masking the pointer against the address limit before use. Even if we don't expect speculative writes per se, it is plausible that a CPU may still speculate at least as far as fetching a cache line for writing, hence we also harden put_user() and clear_user() for peace of mind. Signed-off-by: Robin Murphy Signed-off-by: Will Deacon Signed-off-by: Catalin Marinas --- arch/arm64/include/asm/uaccess.h | 26 +++++++++++++++++++++++--- 1 file changed, 23 insertions(+), 3 deletions(-) diff --git a/arch/arm64/include/asm/uaccess.h b/arch/arm64/include/asm/uaccess.h index 7b1eb49..3531fec 100644 --- a/arch/arm64/include/asm/uaccess.h +++ b/arch/arm64/include/asm/uaccess.h @@ -170,6 +170,26 @@ static inline void uaccess_enable_not_uao(void) } /* + * Sanitise a uaccess pointer such that it becomes NULL if above the + * current addr_limit. + */ +#define uaccess_mask_ptr(ptr) (__typeof__(ptr))__uaccess_mask_ptr(ptr) +static inline void __user *__uaccess_mask_ptr(const void __user *ptr) +{ + void __user *safe_ptr; + + asm volatile( + " bics xzr, %1, %2\n" + " csel %0, %1, xzr, eq\n" + : "=&r" (safe_ptr) + : "r" (ptr), "r" (current_thread_info()->addr_limit) + : "cc"); + + csdb(); + return safe_ptr; +} + +/* * The "__xxx" versions of the user access functions do not verify the address * space - it must have been done previously with a separate "access_ok()" * call. @@ -241,7 +261,7 @@ do { \ __typeof__(*(ptr)) __user *__p = (ptr); \ might_fault(); \ access_ok(VERIFY_READ, __p, sizeof(*__p)) ? \ - __get_user((x), __p) : \ + __p = uaccess_mask_ptr(__p), __get_user((x), __p) : \ ((x) = 0, -EFAULT); \ }) @@ -307,7 +327,7 @@ do { \ __typeof__(*(ptr)) __user *__p = (ptr); \ might_fault(); \ access_ok(VERIFY_WRITE, __p, sizeof(*__p)) ? \ - __put_user((x), __p) : \ + __p = uaccess_mask_ptr(__p), __put_user((x), __p) : \ -EFAULT; \ }) @@ -368,7 +388,7 @@ static inline unsigned long __must_check copy_in_user(void __user *to, const voi static inline unsigned long __must_check clear_user(void __user *to, unsigned long n) { if (access_ok(VERIFY_WRITE, to, n)) - n = __clear_user(to, n); + n = __clear_user(__uaccess_mask_ptr(to), n); return n; }