From patchwork Mon Jun 13 20:14:22 2022 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: andrey.konovalov@linux.dev X-Patchwork-Id: 12880106 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from kanga.kvack.org (kanga.kvack.org [205.233.56.17]) by smtp.lore.kernel.org (Postfix) with ESMTP id D67BAC433EF for ; Mon, 13 Jun 2022 20:20:50 +0000 (UTC) Received: by kanga.kvack.org (Postfix) id 4B7C98D01DF; Mon, 13 Jun 2022 16:20:50 -0400 (EDT) Received: by kanga.kvack.org (Postfix, from userid 40) id 43EAF8D01DD; Mon, 13 Jun 2022 16:20:50 -0400 (EDT) X-Delivered-To: int-list-linux-mm@kvack.org Received: by kanga.kvack.org (Postfix, from userid 63042) id 292F58D01DF; Mon, 13 Jun 2022 16:20:50 -0400 (EDT) X-Delivered-To: linux-mm@kvack.org Received: from relay.hostedemail.com (smtprelay0017.hostedemail.com [216.40.44.17]) by kanga.kvack.org (Postfix) with ESMTP id 122008D01DD for ; Mon, 13 Jun 2022 16:20:50 -0400 (EDT) Received: from smtpin27.hostedemail.com (a10.router.float.18 [10.200.18.1]) by unirelay01.hostedemail.com (Postfix) with ESMTP id CA5AB608A4 for ; Mon, 13 Jun 2022 20:20:49 +0000 (UTC) X-FDA: 79574331018.27.377631A Received: from out2.migadu.com (out2.migadu.com [188.165.223.204]) by imf06.hostedemail.com (Postfix) with ESMTP id 40C07180084 for ; Mon, 13 Jun 2022 20:20:49 +0000 (UTC) X-Report-Abuse: Please report any abuse attempt to abuse@migadu.com and include these headers. DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linux.dev; s=key1; t=1655151648; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=OqOHaer4kC3Iywced9lKgHi/whHdzXvvFFVWcKJPrko=; b=f5d/7XtUXAv8RzxuTswTXDO4W9PSq9kdFaPjQuxA4iTVQtefrfkzPW4aGdvzX++CKF10na 9AUHYQzZLF8H3k/I2Tuha5dUthdwznGRX8KR64xwBQq8nFKELem71xvwCOLuFf1+udE9fO uzEbRQXAmCq9BsMMyyvh9Cno2phyuLU= From: andrey.konovalov@linux.dev To: Marco Elver , Alexander Potapenko Cc: Andrey Konovalov , Dmitry Vyukov , Andrey Ryabinin , kasan-dev@googlegroups.com, Peter Collingbourne , Evgenii Stepanov , Florian Mayer , Andrew Morton , linux-mm@kvack.org, linux-kernel@vger.kernel.org, Andrey Konovalov Subject: [PATCH 31/32] kasan: implement stack ring for tag-based modes Date: Mon, 13 Jun 2022 22:14:22 +0200 Message-Id: <3cd76121903de13713581687ffa45e668ef1475a.1655150842.git.andreyknvl@google.com> In-Reply-To: References: MIME-Version: 1.0 X-Migadu-Flow: FLOW_OUT X-Migadu-Auth-User: linux.dev ARC-Authentication-Results: i=1; imf06.hostedemail.com; dkim=pass header.d=linux.dev header.s=key1 header.b="f5d/7XtU"; dmarc=pass (policy=none) header.from=linux.dev; spf=pass (imf06.hostedemail.com: domain of andrey.konovalov@linux.dev designates 188.165.223.204 as permitted sender) smtp.mailfrom=andrey.konovalov@linux.dev ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=hostedemail.com; s=arc-20220608; t=1655151649; h=from:from:sender:reply-to:subject:subject:date:date: message-id:message-id:to:to:cc:cc:mime-version:mime-version: content-type:content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references:dkim-signature; bh=OqOHaer4kC3Iywced9lKgHi/whHdzXvvFFVWcKJPrko=; b=H8woqpq5xEpNLfxAKFXrhvkz2hnMG1VOqdG9vV30Pd4aLOPwGd3C5ZcQuv8Vnqvr2B+5Xa EZwa+e9VBS1VogqQ+XUIqw/qiXS2u58Mc/A0JcGLH3DNwFP5yxwOf26sNAStXmliBtjcj5 dQGCzT6yB8D9SrBppWvRBdDzesZlYGw= ARC-Seal: i=1; s=arc-20220608; d=hostedemail.com; t=1655151649; a=rsa-sha256; cv=none; b=A4EiyiHiv9vzx9QtHaENiY0nQTQE+UxCzMrXSIqjrbz8yK0F4fUjbE9EsVZlhpjvLY0hnr Oad4HUOEiPsQiZ8LV0SE93st2aMF9Hunm4zsEFCLH066UOsqtc4ByEhXumGuYDBd9WPeLg v5bzL/tbF3OVOboM/0fpknuRDHczNXI= X-Stat-Signature: m8jgofcaw6jjzd4moswjw8hqt4tus7hp X-Rspamd-Queue-Id: 40C07180084 X-Rspam-User: Authentication-Results: imf06.hostedemail.com; dkim=pass header.d=linux.dev header.s=key1 header.b="f5d/7XtU"; dmarc=pass (policy=none) header.from=linux.dev; spf=pass (imf06.hostedemail.com: domain of andrey.konovalov@linux.dev designates 188.165.223.204 as permitted sender) smtp.mailfrom=andrey.konovalov@linux.dev X-Rspamd-Server: rspam10 X-HE-Tag: 1655151649-357016 X-Bogosity: Ham, tests=bogofilter, spamicity=0.000000, version=1.2.4 Sender: owner-linux-mm@kvack.org Precedence: bulk X-Loop: owner-majordomo@kvack.org List-ID: From: Andrey Konovalov Implement storing stack depot handles for alloc/free stack traces for slab objects for the tag-based KASAN modes in a ring buffer. This ring buffer is referred to as the stack ring. On each alloc/free of a slab object, the tagged address of the object and the current stack trace are recorded in the stack ring. On each bug report, if the accessed address belongs to a slab object, the stack ring is scanned for matching entries. The newest entries are used to print the alloc/free stack traces in the report: one entry for alloc and one for free. The ring buffer is lock-free. Signed-off-by: Andrey Konovalov --- The number of entries in the stack ring is fixed in this version of the patch. We could either implement it as a config option or a command-line argument. I tilt towards the latter option and will implement it in v2 unless there are objections. --- mm/kasan/kasan.h | 20 ++++++++++++++ mm/kasan/report_tags.c | 61 ++++++++++++++++++++++++++++++++++++++++++ mm/kasan/tags.c | 30 +++++++++++++++++++++ 3 files changed, 111 insertions(+) diff --git a/mm/kasan/kasan.h b/mm/kasan/kasan.h index c51cea31ced0..da9a3c56ef4b 100644 --- a/mm/kasan/kasan.h +++ b/mm/kasan/kasan.h @@ -2,6 +2,7 @@ #ifndef __MM_KASAN_KASAN_H #define __MM_KASAN_KASAN_H +#include #include #include #include @@ -227,6 +228,25 @@ struct kasan_free_meta { #endif /* CONFIG_KASAN_GENERIC */ +#if defined(CONFIG_KASAN_SW_TAGS) || defined(CONFIG_KASAN_HW_TAGS) + +struct kasan_stack_ring_entry { + atomic64_t ptr; /* void * */ + atomic64_t size; /* size_t */ + atomic_t pid; /* u32 */ + atomic_t stack; /* depot_stack_handle_t */ + atomic_t is_free; /* bool */ +}; + +#define KASAN_STACK_RING_ENTRIES (32 << 10) + +struct kasan_stack_ring { + atomic64_t pos; + struct kasan_stack_ring_entry entries[KASAN_STACK_RING_ENTRIES]; +}; + +#endif /* CONFIG_KASAN_SW_TAGS || CONFIG_KASAN_HW_TAGS */ + #if IS_ENABLED(CONFIG_KASAN_KUNIT_TEST) /* Used in KUnit-compatible KASAN tests. */ struct kunit_kasan_status { diff --git a/mm/kasan/report_tags.c b/mm/kasan/report_tags.c index 5cbac2cdb177..21911d1883d3 100644 --- a/mm/kasan/report_tags.c +++ b/mm/kasan/report_tags.c @@ -4,8 +4,12 @@ * Copyright (c) 2020 Google, Inc. */ +#include + #include "kasan.h" +extern struct kasan_stack_ring stack_ring; + static const char *get_bug_type(struct kasan_report_info *info) { /* @@ -24,5 +28,62 @@ static const char *get_bug_type(struct kasan_report_info *info) void kasan_complete_mode_report_info(struct kasan_report_info *info) { + u64 pos; + struct kasan_stack_ring_entry *entry; + void *object; + u32 pid; + depot_stack_handle_t stack; + bool is_free; + bool alloc_found = false, free_found = false; + info->bug_type = get_bug_type(info); + + if (!info->cache || !info->object) + return; + + pos = atomic64_read(&stack_ring.pos); + + for (u64 i = pos - 1; i != pos - 1 - KASAN_STACK_RING_ENTRIES; i--) { + if (alloc_found && free_found) + break; + + entry = &stack_ring.entries[i % KASAN_STACK_RING_ENTRIES]; + + /* Paired with atomic64_set_release() in save_stack_info(). */ + object = (void *)atomic64_read_acquire(&entry->ptr); + + if (kasan_reset_tag(object) != info->object || + get_tag(object) != get_tag(info->access_addr)) + continue; + + pid = atomic_read(&entry->pid); + stack = atomic_read(&entry->stack); + is_free = atomic_read(&entry->is_free); + + /* Try detecting if the entry was changed while being read. */ + smp_mb(); + if (object != (void *)atomic64_read(&entry->ptr)) + continue; + + if (is_free) { + /* + * Second free of the same object. + * Give up on trying to find the alloc entry. + */ + if (free_found) + break; + + info->free_track.pid = pid; + info->free_track.stack = stack; + free_found = true; + } else { + /* Second alloc of the same object. Give up. */ + if (alloc_found) + break; + + info->alloc_track.pid = pid; + info->alloc_track.stack = stack; + alloc_found = true; + } + } } diff --git a/mm/kasan/tags.c b/mm/kasan/tags.c index 39a0481e5228..286011307695 100644 --- a/mm/kasan/tags.c +++ b/mm/kasan/tags.c @@ -6,6 +6,7 @@ * Copyright (c) 2020 Google, Inc. */ +#include #include #include #include @@ -16,11 +17,40 @@ #include #include "kasan.h" +#include "../slab.h" + +struct kasan_stack_ring stack_ring; + +void save_stack_info(struct kmem_cache *cache, void *object, + gfp_t flags, bool is_free) +{ + u64 pos; + struct kasan_stack_ring_entry *entry; + depot_stack_handle_t stack; + + stack = kasan_save_stack(flags, true); + + pos = atomic64_fetch_add(1, &stack_ring.pos); + entry = &stack_ring.entries[pos % KASAN_STACK_RING_ENTRIES]; + + atomic64_set(&entry->size, cache->object_size); + atomic_set(&entry->pid, current->pid); + atomic_set(&entry->stack, stack); + atomic_set(&entry->is_free, is_free); + + /* + * Paired with atomic64_read_acquire() in + * kasan_complete_mode_report_info(). + */ + atomic64_set_release(&entry->ptr, (s64)object); +} void kasan_save_alloc_info(struct kmem_cache *cache, void *object, gfp_t flags) { + save_stack_info(cache, object, flags, false); } void kasan_save_free_info(struct kmem_cache *cache, void *object) { + save_stack_info(cache, object, GFP_NOWAIT, true); }