From patchwork Tue Nov 27 16:55:35 2018 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Andrey Konovalov X-Patchwork-Id: 10700971 Return-Path: Received: from mail.wl.linuxfoundation.org (pdx-wl-mail.web.codeaurora.org [172.30.200.125]) by pdx-korg-patchwork-2.web.codeaurora.org (Postfix) with ESMTP id 295FA14E2 for ; Tue, 27 Nov 2018 16:57:08 +0000 (UTC) Received: from mail.wl.linuxfoundation.org (localhost [127.0.0.1]) by mail.wl.linuxfoundation.org (Postfix) with ESMTP id 174032C427 for ; Tue, 27 Nov 2018 16:57:08 +0000 (UTC) Received: by mail.wl.linuxfoundation.org (Postfix, from userid 486) id 0AD862C455; Tue, 27 Nov 2018 16:57:08 +0000 (UTC) X-Spam-Checker-Version: SpamAssassin 3.3.1 (2010-03-16) on pdx-wl-mail.web.codeaurora.org X-Spam-Level: X-Spam-Status: No, score=-10.5 required=2.0 tests=BAYES_00,DKIM_SIGNED, DKIM_VALID,DKIM_VALID_AU,MAILING_LIST_MULTI,RCVD_IN_DNSWL_NONE, USER_IN_DEF_DKIM_WL autolearn=unavailable version=3.3.1 Received: from kanga.kvack.org (kanga.kvack.org [205.233.56.17]) by mail.wl.linuxfoundation.org (Postfix) with ESMTP id 6CD7E2C482 for ; Tue, 27 Nov 2018 16:57:07 +0000 (UTC) Received: by kanga.kvack.org (Postfix) id 190416B4955; Tue, 27 Nov 2018 11:56:23 -0500 (EST) Delivered-To: linux-mm-outgoing@kvack.org Received: by kanga.kvack.org (Postfix, from userid 40) id 119446B4959; Tue, 27 Nov 2018 11:56:23 -0500 (EST) X-Original-To: int-list-linux-mm@kvack.org X-Delivered-To: int-list-linux-mm@kvack.org Received: by kanga.kvack.org (Postfix, from userid 63042) id EAD6D6B4958; Tue, 27 Nov 2018 11:56:22 -0500 (EST) X-Original-To: linux-mm@kvack.org X-Delivered-To: linux-mm@kvack.org Received: from mail-wm1-f71.google.com (mail-wm1-f71.google.com [209.85.128.71]) by kanga.kvack.org (Postfix) with ESMTP id 884626B4955 for ; Tue, 27 Nov 2018 11:56:22 -0500 (EST) Received: by mail-wm1-f71.google.com with SMTP id y85so18175912wmc.7 for ; Tue, 27 Nov 2018 08:56:22 -0800 (PST) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:dkim-signature:from:to:cc:subject:date :message-id:in-reply-to:references:mime-version :content-transfer-encoding; bh=NGY24kEYlKV9za6j4+lLg+Mk37D+Fr2A0V+VMyaOAWQ=; b=ejvdbInhX1fD5GE5Sr+bGhU5KUslKKcmCpsfXrUCuXMEVgms5Flq+USDQ/vgm6L4ER n+z0fAQ6ViBTi1wVToINUd9DEOr90a+JUPi5FoRem2DOKMmclVsTSzt5EUWnTBNvoEaj m7/GcFTQ+es8aHO4U4M6SxiyrzxcTHOhwgv+swV4GhY+EvDQ4Fc+7MKJs3whP9zHMxWL itSfnAB//92QvVe8mgUC8dvbzFqYCW35nmE2rLxq8dYZBgAP3RPcrCFTDboimg9akJ0p 8tiuSUhpDfciZIXTD8KH0H/aOVNFan65D8jdisMg2fb47dj+ZsBLPaV5QY/IMkrKObIm QmRA== X-Gm-Message-State: AGRZ1gIySb9rKDwlP5oTVjhsnDF9yCoy5dLJwrAHqvO6aVJq4pWZ5r+r MGoEWI/iocvTzKI+Y+1iZTEjsYA9J1SYTAU0JjuD7KM/mfTICi8xFSOIf97X7nHllLJS4b5t7AG U7VoFZnQrSaTfkGVMzJoBbzRUPYTE8FsbPCZuYv2MTfeN6ccYj4he4mBqbF9pVIDpxprHq58RVK PnzNX9K7GNyhw0pZBNoFAtkkGwEO39k9gPaD1/WdyWcpGCrlAZmOvn2Cjy7GA0V6A5JB8TlKsZR w7Z4b9mWJ/ciEJbdJGpg2ghEbsiV8P6yobyKpZrZtfntS1dbVmQ/HxBSeDT6XGfusOlEkiU3nPv SISv7G3gJsFvpbTk7j0tyoXmH1drOgz2TSZW+uz8v64TWtmz60FA58Q1wNU7SfCl9Rn2OCgftZ0 G X-Received: by 2002:a1c:9c0a:: with SMTP id f10mr28947846wme.73.1543337782044; Tue, 27 Nov 2018 08:56:22 -0800 (PST) X-Received: by 2002:a1c:9c0a:: with SMTP id f10mr28947778wme.73.1543337780779; Tue, 27 Nov 2018 08:56:20 -0800 (PST) ARC-Seal: i=1; a=rsa-sha256; t=1543337780; cv=none; d=google.com; s=arc-20160816; b=y2hCCxw3fJq5YFzrIioeZvUWyqNCHFPhF7CwGGmu5zw52KS3C4yrepLM+Te5nH+M16 0LroRGemRlo+4XUte5FShWtDVCdFHLn/wchsDrZMT1JeSxXvwwkmkOyRzTLrd6DpQ8hW ikY/ntbRy57Om3AEuJgvObUMN7AXy6DT4R5fBsXmPcQlv3AmocAuL1/CwvcxkSywjNCc W2bD0l/0Dfgrq3GV8az0zLWtDXl8O9Q+lFtpxOyDPPvvYr/I1AWPwesiZDiIFXBd7idW TjWv0gHv+WheRxIeZfjbF8F3C2B/22Z5skXGxQpTtsDEfKpPC6qbf9nmVuLGkjgDYoke SnKQ== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:dkim-signature; bh=NGY24kEYlKV9za6j4+lLg+Mk37D+Fr2A0V+VMyaOAWQ=; b=aCiUEEJUv/z42+6jmgBlQlmnLOuRv6sZpL2YOwzTs2iheKuDwvRlPAtF2wdkTx8HbA 6buPvd+0jfD8WXjtZhdSEt0bqRPnbxCwhemHhqylNWJWDuWZo8iQEUd3/g4w079YBLLD Xh+N/cynb36lmUPBwRXfn2JSXaEJpyXqILD0hB7Gunc5WCZxRmP1c30IM8URI/yfeZQD FdL7CzteAjsC7i7/M/5ET9oIBL9mWsxmB8996j4GYk9wVCqW7rkoXc7V+KfEppyWkuzC OGrGOJexG4iTrqskW5mnQYQHXuPZWY3q6ksudmlc6Ifihm6ortwHUBvQxC+iQgwhYc0+ TuYw== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@google.com header.s=20161025 header.b=Y7JqEyQS; spf=pass (google.com: domain of andreyknvl@google.com designates 209.85.220.65 as permitted sender) smtp.mailfrom=andreyknvl@google.com; dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=google.com Received: from mail-sor-f65.google.com (mail-sor-f65.google.com. [209.85.220.65]) by mx.google.com with SMTPS id 51sor3115673wra.51.2018.11.27.08.56.20 for (Google Transport Security); Tue, 27 Nov 2018 08:56:20 -0800 (PST) Received-SPF: pass (google.com: domain of andreyknvl@google.com designates 209.85.220.65 as permitted sender) client-ip=209.85.220.65; Authentication-Results: mx.google.com; dkim=pass header.i=@google.com header.s=20161025 header.b=Y7JqEyQS; spf=pass (google.com: domain of andreyknvl@google.com designates 209.85.220.65 as permitted sender) smtp.mailfrom=andreyknvl@google.com; dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=google.com DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20161025; h=from:to:cc:subject:date:message-id:in-reply-to:references :mime-version:content-transfer-encoding; bh=NGY24kEYlKV9za6j4+lLg+Mk37D+Fr2A0V+VMyaOAWQ=; b=Y7JqEyQSNecPNfIakkOPNWEwozlvQ7ETwuh0OMtbtbMYqXQfovnxd3NByCHMQnfWdE ebrdGC7fbXgpWh7tVKpiOQ3SBN0iFuxb8A6HilwShILfNEkMxIO1gsHrq8F3oY0cdw1U mt+Rayis9WOPMzHc3QMBeO3T+clBxfiO2BGANOhY7g24ixnqihd710PDAtHJNxbEoWfB UhTp/V3tfBoEDp3a4IEvOzJDd94a+ALJ8vy4G7KwlLH4epF1VTUxj7iqVGgj4KPBBfbT 5SXPz5hbzYMoZMa3xobi8WbquZxaw5JcCRwjPmT629uqE6pzCrMCBw1ojI/VEgbU71Q1 ydng== X-Google-Smtp-Source: AFSGD/U/BXacGpHDneGOXiqEqOPWRyahWqAl1r+NjMlboEuKVzUM6mURIC25l9XjhMIdhU76elSmew== X-Received: by 2002:adf:c042:: with SMTP id c2mr16699964wrf.158.1543337780158; Tue, 27 Nov 2018 08:56:20 -0800 (PST) Received: from andreyknvl0.muc.corp.google.com ([2a00:79e0:15:10:3180:41f8:3010:ff61]) by smtp.gmail.com with ESMTPSA id k73sm6383099wmd.36.2018.11.27.08.56.18 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Tue, 27 Nov 2018 08:56:19 -0800 (PST) From: Andrey Konovalov To: Andrey Ryabinin , Alexander Potapenko , Dmitry Vyukov , Catalin Marinas , Will Deacon , Christoph Lameter , Andrew Morton , Mark Rutland , Nick Desaulniers , Marc Zyngier , Dave Martin , Ard Biesheuvel , "Eric W . Biederman" , Ingo Molnar , Paul Lawrence , Geert Uytterhoeven , Arnd Bergmann , "Kirill A . Shutemov" , Greg Kroah-Hartman , Kate Stewart , Mike Rapoport , kasan-dev@googlegroups.com, linux-doc@vger.kernel.org, linux-kernel@vger.kernel.org, linux-arm-kernel@lists.infradead.org, linux-sparse@vger.kernel.org, linux-mm@kvack.org, linux-kbuild@vger.kernel.org Cc: Kostya Serebryany , Evgeniy Stepanov , Lee Smith , Ramana Radhakrishnan , Jacob Bramley , Ruben Ayrapetyan , Jann Horn , Mark Brand , Chintan Pandya , Vishwath Mohan , Andrey Konovalov Subject: [PATCH v12 17/25] kasan: add bug reporting routines for tag-based mode Date: Tue, 27 Nov 2018 17:55:35 +0100 Message-Id: <996c09ec2c8f11294c106973f3b1a211417fa74e.1543337629.git.andreyknvl@google.com> X-Mailer: git-send-email 2.20.0.rc0.387.gc7a69e6b6c-goog In-Reply-To: References: MIME-Version: 1.0 X-Bogosity: Ham, tests=bogofilter, spamicity=0.000000, version=1.2.4 Sender: owner-linux-mm@kvack.org Precedence: bulk X-Loop: owner-majordomo@kvack.org List-ID: X-Virus-Scanned: ClamAV using ClamSMTP This commit adds rountines, that print tag-based KASAN error reports. Those are quite similar to generic KASAN, the difference is: 1. The way tag-based KASAN finds the first bad shadow cell (with a mismatching tag). Tag-based KASAN compares memory tags from the shadow memory to the pointer tag. 2. Tag-based KASAN reports all bugs with the "KASAN: invalid-access" header. Also simplify generic KASAN find_first_bad_addr. Reviewed-by: Andrey Ryabinin Reviewed-by: Dmitry Vyukov Signed-off-by: Andrey Konovalov --- mm/kasan/generic_report.c | 16 ++++------- mm/kasan/kasan.h | 5 ++++ mm/kasan/report.c | 57 +++++++++++++++++++++------------------ mm/kasan/tags_report.c | 18 +++++++++++++ 4 files changed, 59 insertions(+), 37 deletions(-) diff --git a/mm/kasan/generic_report.c b/mm/kasan/generic_report.c index 5201d1770700..a4604cceae59 100644 --- a/mm/kasan/generic_report.c +++ b/mm/kasan/generic_report.c @@ -33,16 +33,13 @@ #include "kasan.h" #include "../slab.h" -static const void *find_first_bad_addr(const void *addr, size_t size) +void *find_first_bad_addr(void *addr, size_t size) { - u8 shadow_val = *(u8 *)kasan_mem_to_shadow(addr); - const void *first_bad_addr = addr; + void *p = addr; - while (!shadow_val && first_bad_addr < addr + size) { - first_bad_addr += KASAN_SHADOW_SCALE_SIZE; - shadow_val = *(u8 *)kasan_mem_to_shadow(first_bad_addr); - } - return first_bad_addr; + while (p < addr + size && !(*(u8 *)kasan_mem_to_shadow(p))) + p += KASAN_SHADOW_SCALE_SIZE; + return p; } static const char *get_shadow_bug_type(struct kasan_access_info *info) @@ -50,9 +47,6 @@ static const char *get_shadow_bug_type(struct kasan_access_info *info) const char *bug_type = "unknown-crash"; u8 *shadow_addr; - info->first_bad_addr = find_first_bad_addr(info->access_addr, - info->access_size); - shadow_addr = (u8 *)kasan_mem_to_shadow(info->first_bad_addr); /* diff --git a/mm/kasan/kasan.h b/mm/kasan/kasan.h index 33cc3b0e017e..82a23b23ff93 100644 --- a/mm/kasan/kasan.h +++ b/mm/kasan/kasan.h @@ -119,6 +119,7 @@ void kasan_poison_shadow(const void *address, size_t size, u8 value); void check_memory_region(unsigned long addr, size_t size, bool write, unsigned long ret_ip); +void *find_first_bad_addr(void *addr, size_t size); const char *get_bug_type(struct kasan_access_info *info); void kasan_report(unsigned long addr, size_t size, @@ -139,10 +140,14 @@ static inline void quarantine_remove_cache(struct kmem_cache *cache) { } #ifdef CONFIG_KASAN_SW_TAGS +void print_tags(u8 addr_tag, const void *addr); + u8 random_tag(void); #else +static inline void print_tags(u8 addr_tag, const void *addr) { } + static inline u8 random_tag(void) { return 0; diff --git a/mm/kasan/report.c b/mm/kasan/report.c index 64a74f334c45..214d85035f99 100644 --- a/mm/kasan/report.c +++ b/mm/kasan/report.c @@ -64,11 +64,10 @@ static int __init kasan_set_multi_shot(char *str) } __setup("kasan_multi_shot", kasan_set_multi_shot); -static void print_error_description(struct kasan_access_info *info, - const char *bug_type) +static void print_error_description(struct kasan_access_info *info) { pr_err("BUG: KASAN: %s in %pS\n", - bug_type, (void *)info->ip); + get_bug_type(info), (void *)info->ip); pr_err("%s of size %zu at addr %px by task %s/%d\n", info->is_write ? "Write" : "Read", info->access_size, info->access_addr, current->comm, task_pid_nr(current)); @@ -272,6 +271,8 @@ void kasan_report_invalid_free(void *object, unsigned long ip) start_report(&flags); pr_err("BUG: KASAN: double-free or invalid-free in %pS\n", (void *)ip); + print_tags(get_tag(object), reset_tag(object)); + object = reset_tag(object); pr_err("\n"); print_address_description(object); pr_err("\n"); @@ -279,41 +280,45 @@ void kasan_report_invalid_free(void *object, unsigned long ip) end_report(&flags); } -static void kasan_report_error(struct kasan_access_info *info) -{ - unsigned long flags; - - start_report(&flags); - - print_error_description(info, get_bug_type(info)); - pr_err("\n"); - - if (!addr_has_shadow(info->access_addr)) { - dump_stack(); - } else { - print_address_description((void *)info->access_addr); - pr_err("\n"); - print_shadow_for_address(info->first_bad_addr); - } - - end_report(&flags); -} - void kasan_report(unsigned long addr, size_t size, bool is_write, unsigned long ip) { struct kasan_access_info info; + void *tagged_addr; + void *untagged_addr; + unsigned long flags; if (likely(!report_enabled())) return; disable_trace_on_warning(); - info.access_addr = (void *)addr; - info.first_bad_addr = (void *)addr; + tagged_addr = (void *)addr; + untagged_addr = reset_tag(tagged_addr); + + info.access_addr = tagged_addr; + if (addr_has_shadow(untagged_addr)) + info.first_bad_addr = find_first_bad_addr(tagged_addr, size); + else + info.first_bad_addr = untagged_addr; info.access_size = size; info.is_write = is_write; info.ip = ip; - kasan_report_error(&info); + start_report(&flags); + + print_error_description(&info); + if (addr_has_shadow(untagged_addr)) + print_tags(get_tag(tagged_addr), info.first_bad_addr); + pr_err("\n"); + + if (addr_has_shadow(untagged_addr)) { + print_address_description(untagged_addr); + pr_err("\n"); + print_shadow_for_address(info.first_bad_addr); + } else { + dump_stack(); + } + + end_report(&flags); } diff --git a/mm/kasan/tags_report.c b/mm/kasan/tags_report.c index 8af15e87d3bc..573c51d20d09 100644 --- a/mm/kasan/tags_report.c +++ b/mm/kasan/tags_report.c @@ -37,3 +37,21 @@ const char *get_bug_type(struct kasan_access_info *info) { return "invalid-access"; } + +void *find_first_bad_addr(void *addr, size_t size) +{ + u8 tag = get_tag(addr); + void *p = reset_tag(addr); + void *end = p + size; + + while (p < end && tag == *(u8 *)kasan_mem_to_shadow(p)) + p += KASAN_SHADOW_SCALE_SIZE; + return p; +} + +void print_tags(u8 addr_tag, const void *addr) +{ + u8 *shadow = (u8 *)kasan_mem_to_shadow(addr); + + pr_err("Pointer tag: [%02x], memory tag: [%02x]\n", addr_tag, *shadow); +}