From patchwork Wed Nov 4 23:18:57 2020 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Andrey Konovalov X-Patchwork-Id: 11883099 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org X-Spam-Level: X-Spam-Status: No, score=-12.7 required=3.0 tests=BAYES_00,DKIMWL_WL_HIGH, DKIM_ADSP_CUSTOM_MED,DKIM_SIGNED,DKIM_VALID,HEADER_FROM_DIFFERENT_DOMAINS, INCLUDES_PATCH,MAILING_LIST_MULTI,SIGNED_OFF_BY,SPF_HELO_NONE,SPF_PASS, URIBL_BLOCKED,USER_AGENT_GIT autolearn=unavailable autolearn_force=no version=3.4.0 Received: from mail.kernel.org (mail.kernel.org [198.145.29.99]) by smtp.lore.kernel.org (Postfix) with ESMTP id 50088C00A89 for ; Thu, 5 Nov 2020 04:13:24 +0000 (UTC) Received: from merlin.infradead.org (merlin.infradead.org [205.233.59.134]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mail.kernel.org (Postfix) with ESMTPS id A9A7720732 for ; Thu, 5 Nov 2020 04:13:23 +0000 (UTC) Authentication-Results: mail.kernel.org; dkim=pass (2048-bit key) header.d=lists.infradead.org header.i=@lists.infradead.org header.b="kuLZ/IuL"; dkim=fail reason="signature verification failed" (2048-bit key) header.d=infradead.org header.i=@infradead.org header.b="XoAzVuaP"; dkim=fail reason="signature verification failed" (2048-bit key) header.d=google.com header.i=@google.com header.b="VtBS5tip" DMARC-Filter: OpenDMARC Filter v1.3.2 mail.kernel.org A9A7720732 Authentication-Results: mail.kernel.org; dmarc=fail (p=reject dis=none) header.from=google.com Authentication-Results: mail.kernel.org; spf=none smtp.mailfrom=linux-arm-kernel-bounces+linux-arm-kernel=archiver.kernel.org@lists.infradead.org DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.infradead.org; s=merlin.20170209; h=Sender:Content-Transfer-Encoding: Content-Type:Cc:List-Subscribe:List-Help:List-Post:List-Archive: List-Unsubscribe:List-Id:To:From:Subject:References:Mime-Version:Message-Id: In-Reply-To:Date:Reply-To:Content-ID:Content-Description:Resent-Date: Resent-From:Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:List-Owner; bh=Pyii5edlYysODA1+jooM63XX/AXW7D4IzzVVZgToMu0=; b=kuLZ/IuLNRl8E6dZGfuL51OFc 29Se6a5+3+gmAj4bC17mmTtMT8q5EEnM/8t2oNeiPJvMpJ4YKtVzLr2xiq59vw3iez2P+or5T2hxB InyjIXWO6B8Hz+WIb9fEBXa6Zfx4eymd5F5ZrrovpS1RK+Czl5BuGc4VHHAQN+KbCgoskzh1hCnvc mSI+hw4qznbRWRzH8grOOsVFG/hWn7golbPWv+T8bFH4WUxVxBS1f3cOZ86LxCI3TEX0vWMmUiuwG THYdzL20Sl/v5EeRQuu3CHk4g8Z+mG5veHvdVqzIb6wsGvp8TLURBNze3VYNEDs8OFoFK/6QSwL81 7N8jAVEbA==; Received: from localhost ([::1] helo=merlin.infradead.org) by merlin.infradead.org with esmtp (Exim 4.92.3 #3 (Red Hat Linux)) id 1kaWcz-0004dS-Q5; Thu, 05 Nov 2020 04:12:01 +0000 Received: from casper.infradead.org ([2001:8b0:10b:1236::1]) by merlin.infradead.org with esmtps (Exim 4.92.3 #3 (Red Hat Linux)) id 1kaW50-000145-He for linux-arm-kernel@merlin.infradead.org; Thu, 05 Nov 2020 03:36:54 +0000 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=infradead.org; s=casper.20170209; h=Content-Type:Cc:To:From:Subject: References:Mime-Version:Message-Id:In-Reply-To:Date:Sender:Reply-To: Content-Transfer-Encoding:Content-ID:Content-Description; bh=b9SnV6dyF/NNz3ylZbPzVHyY+ZwsvRStMTdcsqRrxIk=; b=XoAzVuaPXfhom3Mq7+Yj1SzeKJ 4TvBfJ9SMV+AwaWuOixE0cauUmpIxuSWUlzdrYvgT2XtBy7qiryWFFaNPwafHTYvj6ETZ9KT1tcz8 hVFp4trc5gQ2vpqQT+2fWeE9tTpdXMfhvyIUwzgMZilXfoI6TdG+TDl8rhBcpVa5t3/NB+P7oKzN3 SlZ4q87V37SdUBuRgLD3HCiicFuJzCtZi6xYy2/JIl5ffZAOFL5eJI9jSNla+rUTUL3eppp0h2yp/ fOqcEl+IvRU/yWi1NUExfwnbTWMP5DI0NzzykI1rHWjQ10+8I1CaX7icY2F20uMC9eAZiIh/34KIa nsHZf1Uw==; Received: from mail-wr1-x44a.google.com ([2a00:1450:4864:20::44a]) by casper.infradead.org with esmtps (Exim 4.92.3 #3 (Red Hat Linux)) id 1kaS6C-0004Kr-4A for linux-arm-kernel@lists.infradead.org; Wed, 04 Nov 2020 23:21:56 +0000 Received: by mail-wr1-x44a.google.com with SMTP id t14so51369wrs.2 for ; Wed, 04 Nov 2020 15:21:51 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20161025; h=sender:date:in-reply-to:message-id:mime-version:references:subject :from:to:cc; bh=b9SnV6dyF/NNz3ylZbPzVHyY+ZwsvRStMTdcsqRrxIk=; b=VtBS5tiprgeBqyQFeYgQsNsMH9Z8DVIMQnDI9sIuRWgG3aOAEoX/o+uU1bqo4wEuwN xRfkbyerGa1MLHylYZOtl/iWTqO2v4PeyxEmKguvqQd7zDB3hzcVYdRuGmKT2GbUn7Zc V7RSN6ZyWkG9F+qSmzFo0Pf48zARJ3w6a4Kc+yFRdbrE820jo/z7YPgvx6xswqO12q8X QQwCNUiV4IvBr2dVFXvw6LGWC4EG87DRWzm9zckNr6E6LJ0KBqY0XXP7MERR90UXVwgY VPRZmo7F1sAoCyPLmAqu3i9fz6Bxmg3TMvrW07C4lkNGisH2jQO5bYFJZ6pkqTFtWJlw XWxQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:sender:date:in-reply-to:message-id:mime-version :references:subject:from:to:cc; bh=b9SnV6dyF/NNz3ylZbPzVHyY+ZwsvRStMTdcsqRrxIk=; b=lQltnpu/6gOEPvrHU4bKFBkbKE9A4nvkuCkGtURxSkVaTSt0ei0PWPy8wUoE/O4vbn Tkx87Ax0f9G3V89BI15X1Z9MT4oA7JfuS7WliydMabtZB7Amks2e+ZUma4S08YvnGSM1 RIFiMXEbG8HJPFsunfcotCkuVDW0UTv1WVmq0f9VUAXeDVlfldhtzmB6TQq9okrT0oWI n1HclLBhjwTxZctaHm9leLT+kw4C6GFbNYSnHKaH2JiO0nAXY041cucA8ULmgyC0AqRs tWXGNwyL4VcaaCUDqCkXq+l6YD/a6UH5Njy/YDBqqh0YRNyklMxMcZp8koTlD9tE/oON OoOA== X-Gm-Message-State: AOAM530HID0pbw9KLWT0kNE8PHkcXTzBWwISlaz/NVhCvTIxKHwOIO50 KDkuLDWYJZllRT3SxcLna4gpPSikY46BLghh X-Google-Smtp-Source: ABdhPJwAU/Tx9QApQADzPSJIxcRre5E1rTj7t3LK/CjmYL8t2M9hDgQHJa9M531Oj5oPKCIfUH7Zf3f17KmQbP5i X-Received: from andreyknvl3.muc.corp.google.com ([2a00:79e0:15:13:7220:84ff:fe09:7e9d]) (user=andreyknvl job=sendgmr) by 2002:a1c:7418:: with SMTP id p24mr102064wmc.36.1604532047923; Wed, 04 Nov 2020 15:20:47 -0800 (PST) Date: Thu, 5 Nov 2020 00:18:57 +0100 In-Reply-To: Message-Id: <8c7ee6f573ec10f8f5b2ee32b7f649d479691349.1604531793.git.andreyknvl@google.com> Mime-Version: 1.0 References: X-Mailer: git-send-email 2.29.1.341.ge80a0c044ae-goog Subject: [PATCH v8 42/43] kasan: add documentation for hardware tag-based mode From: Andrey Konovalov To: Catalin Marinas X-CRM114-Version: 20100106-BlameMichelson ( TRE 0.8.0 (BSD) ) MR-646709E3 X-CRM114-CacheID: sfid-20201104_232152_379836_6B16C433 X-CRM114-Status: GOOD ( 19.63 ) X-BeenThere: linux-arm-kernel@lists.infradead.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Cc: linux-arm-kernel@lists.infradead.org, Marco Elver , Andrey Konovalov , Kevin Brodsky , Will Deacon , Branislav Rankov , kasan-dev@googlegroups.com, linux-kernel@vger.kernel.org, linux-mm@kvack.org, Alexander Potapenko , Evgenii Stepanov , Andrey Ryabinin , Andrew Morton , Vincenzo Frascino , Dmitry Vyukov Sender: "linux-arm-kernel" Errors-To: linux-arm-kernel-bounces+linux-arm-kernel=archiver.kernel.org@lists.infradead.org Add documentation for hardware tag-based KASAN mode and also add some clarifications for software tag-based mode. Signed-off-by: Andrey Konovalov Signed-off-by: Vincenzo Frascino Reviewed-by: Marco Elver --- Change-Id: Ib46cb444cfdee44054628940a82f5139e10d0258 --- Documentation/dev-tools/kasan.rst | 78 ++++++++++++++++++++++--------- 1 file changed, 57 insertions(+), 21 deletions(-) diff --git a/Documentation/dev-tools/kasan.rst b/Documentation/dev-tools/kasan.rst index edca4be5e405..422f8ee1bb17 100644 --- a/Documentation/dev-tools/kasan.rst +++ b/Documentation/dev-tools/kasan.rst @@ -5,12 +5,14 @@ Overview -------- KernelAddressSANitizer (KASAN) is a dynamic memory error detector designed to -find out-of-bound and use-after-free bugs. KASAN has two modes: generic KASAN -(similar to userspace ASan) and software tag-based KASAN (similar to userspace -HWASan). +find out-of-bound and use-after-free bugs. KASAN has three modes: +1. generic KASAN (similar to userspace ASan), +2. software tag-based KASAN (similar to userspace HWASan), +3. hardware tag-based KASAN (based on hardware memory tagging). -KASAN uses compile-time instrumentation to insert validity checks before every -memory access, and therefore requires a compiler version that supports that. +Software KASAN modes (1 and 2) use compile-time instrumentation to insert +validity checks before every memory access, and therefore require a compiler +version that supports that. Generic KASAN is supported in both GCC and Clang. With GCC it requires version 8.3.0 or later. Any supported Clang version is compatible, but detection of @@ -19,7 +21,7 @@ out-of-bounds accesses for global variables is only supported since Clang 11. Tag-based KASAN is only supported in Clang. Currently generic KASAN is supported for the x86_64, arm64, xtensa, s390 and -riscv architectures, and tag-based KASAN is supported only for arm64. +riscv architectures, and tag-based KASAN modes are supported only for arm64. Usage ----- @@ -28,14 +30,16 @@ To enable KASAN configure kernel with:: CONFIG_KASAN = y -and choose between CONFIG_KASAN_GENERIC (to enable generic KASAN) and -CONFIG_KASAN_SW_TAGS (to enable software tag-based KASAN). +and choose between CONFIG_KASAN_GENERIC (to enable generic KASAN), +CONFIG_KASAN_SW_TAGS (to enable software tag-based KASAN), and +CONFIG_KASAN_HW_TAGS (to enable hardware tag-based KASAN). -You also need to choose between CONFIG_KASAN_OUTLINE and CONFIG_KASAN_INLINE. -Outline and inline are compiler instrumentation types. The former produces -smaller binary while the latter is 1.1 - 2 times faster. +For software modes, you also need to choose between CONFIG_KASAN_OUTLINE and +CONFIG_KASAN_INLINE. Outline and inline are compiler instrumentation types. +The former produces smaller binary while the latter is 1.1 - 2 times faster. -Both KASAN modes work with both SLUB and SLAB memory allocators. +Both software KASAN modes work with both SLUB and SLAB memory allocators, +hardware tag-based KASAN currently only support SLUB. For better bug detection and nicer reporting, enable CONFIG_STACKTRACE. To augment reports with last allocation and freeing stack of the physical page, @@ -196,17 +200,24 @@ and the second to last. Software tag-based KASAN ~~~~~~~~~~~~~~~~~~~~~~~~ -Tag-based KASAN uses the Top Byte Ignore (TBI) feature of modern arm64 CPUs to -store a pointer tag in the top byte of kernel pointers. Like generic KASAN it -uses shadow memory to store memory tags associated with each 16-byte memory +Software tag-based KASAN requires software memory tagging support in the form +of HWASan-like compiler instrumentation (see HWASan documentation for details). + +Software tag-based KASAN is currently only implemented for arm64 architecture. + +Software tag-based KASAN uses the Top Byte Ignore (TBI) feature of arm64 CPUs +to store a pointer tag in the top byte of kernel pointers. Like generic KASAN +it uses shadow memory to store memory tags associated with each 16-byte memory cell (therefore it dedicates 1/16th of the kernel memory for shadow memory). -On each memory allocation tag-based KASAN generates a random tag, tags the -allocated memory with this tag, and embeds this tag into the returned pointer. +On each memory allocation software tag-based KASAN generates a random tag, tags +the allocated memory with this tag, and embeds this tag into the returned +pointer. + Software tag-based KASAN uses compile-time instrumentation to insert checks before each memory access. These checks make sure that tag of the memory that is being accessed is equal to tag of the pointer that is used to access this -memory. In case of a tag mismatch tag-based KASAN prints a bug report. +memory. In case of a tag mismatch software tag-based KASAN prints a bug report. Software tag-based KASAN also has two instrumentation modes (outline, that emits callbacks to check memory accesses; and inline, that performs the shadow @@ -215,9 +226,34 @@ simply printed from the function that performs the access check. With inline instrumentation a brk instruction is emitted by the compiler, and a dedicated brk handler is used to print bug reports. -A potential expansion of this mode is a hardware tag-based mode, which would -use hardware memory tagging support instead of compiler instrumentation and -manual shadow memory manipulation. +Software tag-based KASAN uses 0xFF as a match-all pointer tag (accesses through +pointers with 0xFF pointer tag aren't checked). The value 0xFE is currently +reserved to tag freed memory regions. + +Software tag-based KASAN currently only supports tagging of slab memory. + +Hardware tag-based KASAN +~~~~~~~~~~~~~~~~~~~~~~~~ + +Hardware tag-based KASAN is similar to the software mode in concept, but uses +hardware memory tagging support instead of compiler instrumentation and +shadow memory. + +Hardware tag-based KASAN is currently only implemented for arm64 architecture +and based on both arm64 Memory Tagging Extension (MTE) introduced in ARMv8.5 +Instruction Set Architecture, and Top Byte Ignore (TBI). + +Special arm64 instructions are used to assign memory tags for each allocation. +Same tags are assigned to pointers to those allocations. On every memory +access, hardware makes sure that tag of the memory that is being accessed is +equal to tag of the pointer that is used to access this memory. In case of a +tag mismatch a fault is generated and a report is printed. + +Hardware tag-based KASAN uses 0xFF as a match-all pointer tag (accesses through +pointers with 0xFF pointer tag aren't checked). The value 0xFE is currently +reserved to tag freed memory regions. + +Hardware tag-based KASAN currently only supports tagging of slab memory. What memory accesses are sanitised by KASAN? --------------------------------------------