From patchwork Wed Jan 2 17:36:06 2019 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Andrey Konovalov X-Patchwork-Id: 10746571 Return-Path: Received: from mail.wl.linuxfoundation.org (pdx-wl-mail.web.codeaurora.org [172.30.200.125]) by pdx-korg-patchwork-2.web.codeaurora.org (Postfix) with ESMTP id 978FE6C5 for ; Wed, 2 Jan 2019 17:36:36 +0000 (UTC) Received: from mail.wl.linuxfoundation.org (localhost [127.0.0.1]) by mail.wl.linuxfoundation.org (Postfix) with ESMTP id 7918B28405 for ; Wed, 2 Jan 2019 17:36:36 +0000 (UTC) Received: by mail.wl.linuxfoundation.org (Postfix, from userid 486) id 6C71928417; Wed, 2 Jan 2019 17:36:36 +0000 (UTC) X-Spam-Checker-Version: SpamAssassin 3.3.1 (2010-03-16) on pdx-wl-mail.web.codeaurora.org X-Spam-Level: X-Spam-Status: No, score=-5.2 required=2.0 tests=BAYES_00,DKIM_ADSP_CUSTOM_MED, DKIM_SIGNED,DKIM_VALID,MAILING_LIST_MULTI,RCVD_IN_DNSWL_MED autolearn=ham version=3.3.1 Received: from bombadil.infradead.org (bombadil.infradead.org [198.137.202.133]) (using TLSv1.2 with cipher AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mail.wl.linuxfoundation.org (Postfix) with ESMTPS id 14A5328405 for ; Wed, 2 Jan 2019 17:36:36 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.infradead.org; s=bombadil.20170209; h=Sender: Content-Transfer-Encoding:Content-Type:Cc:List-Subscribe:List-Help:List-Post: List-Archive:List-Unsubscribe:List-Id:MIME-Version:References:In-Reply-To: Message-Id:Date:Subject:To:From:Reply-To:Content-ID:Content-Description: Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID: List-Owner; bh=0IYlAZYs1ScmKRQJ0X+GZ0WEYvbCM7HuT5U+u5IDuuo=; b=kBHxLpmFcYVbpl dQPdFcOjoB565Uwilel6pYAoHwFOoNF/J6Iiz/c2KO4fAB3bFaH8xhOSQqza2bDB7CyY3PEQKQuwY IH3L1sdPfM0IoieZOucKx/eMYX5+YNI1CptwcqKvkk1AAqxEBBK1WiAh85FSLt52NYf/QswDarMQY DMKn1zbS3i6F1GJG1htY0GlsIFwDNmmyYUEHfX1jxghaJ/tFC2kjKKMSY4DjOaBCL+9/PL+tuRvcB cUn8UVXpllKp78a0VKrkra9RnY/jJnuhBTLAw2puB+4htSCg9hLI+L5MfkOwJbpkpLdmhJgiKRTAe 2LPwvJ5X9o7oTaAp2xCg==; Received: from localhost ([127.0.0.1] helo=bombadil.infradead.org) by bombadil.infradead.org with esmtp (Exim 4.90_1 #2 (Red Hat Linux)) id 1gekRV-0005cU-1v; Wed, 02 Jan 2019 17:36:33 +0000 Received: from mail-wm1-x342.google.com ([2a00:1450:4864:20::342]) by bombadil.infradead.org with esmtps (Exim 4.90_1 #2 (Red Hat Linux)) id 1gekRH-0005PT-U7 for linux-arm-kernel@lists.infradead.org; Wed, 02 Jan 2019 17:36:21 +0000 Received: by mail-wm1-x342.google.com with SMTP id d15so27257960wmb.3 for ; Wed, 02 Jan 2019 09:36:16 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20161025; h=from:to:cc:subject:date:message-id:in-reply-to:references :mime-version:content-transfer-encoding; bh=ZsJFoVJf3IIY1mc4G8PoWo9I+7LoITd3hZ2Vo5zkWAc=; b=lAlrMqV+AGSkWFg5yrz2JZbPk6RoKIqYdaAHGwn+o5V/PT3wER7ZaMKwkE5hdb8SuZ LPObNhnGQkXOjiShOE7KLEe+L83ocrpqNvR5qQwkMP5Jd9WvyCHU1XtGvb8QckxB9cCo gFwgxa8I2Z6nAI/XlNVC2sTC4UcKZCyjZClhL4LmKKz7nwSQmrvkj3eDWI5v8Qyf3dVU KN+qP7/l7ObKbX4pR3rxTA8VymtrWoOGIyD2lKYFGn5sBzxkrkvUhOi4CFKYCGGGVkVv 6IVZkI9DYKZ4d6sI3dIg+OQntY2oMujijkTJspbpA7hPOjSgmSOqiAXGwZvhxQwTzZsC vurA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:to:cc:subject:date:message-id:in-reply-to :references:mime-version:content-transfer-encoding; bh=ZsJFoVJf3IIY1mc4G8PoWo9I+7LoITd3hZ2Vo5zkWAc=; b=YMRaK5Mzu7LEa0HoUkvHl/74x384h7Cx74jVGOFgVqh2WQHQ0030GWNZkSFF8NyeFS SEgV1jMv+ghPcGpf1/NEe8B6ychfOG5zcBWX6Sbp6NCm6S+HRf0fPb+qzZHvNWWkZa0O NQ3y5Lhz+uBVzHrvgdoQ35cmGL2TbnLHt3xSRm6LjK1HCgqlKUGCRbP+P3M/BJF100Xi jPUIVqWW0iV5Sb9yXsxm3G/X504jW7LZBSoems1C49GoFZJMdOjBQ5RH3NmYKexAAdes DU+0q40aLfSaD2kPkQIfsUhIZ3AMZ6QQ96pMU/7jfDnkLjDgX3c9BkckwQ0WLxKJQlkb 0q+g== X-Gm-Message-State: AA+aEWbCIg0cnIPHgQUb5hbv7iibmw8Sg0wdecKos0sY602xFqEL/0lX GQigvGz64j4JyJ93rkgJRNwQxA== X-Google-Smtp-Source: AFSGD/VaDhJ7tSu1Glf9joOK/KwNwzfxgXuAYl8ckeRSP/aFiyqPuu4bYT2MGG+9MfJfx5N6OAZhBA== X-Received: by 2002:a1c:7511:: with SMTP id o17mr35511822wmc.42.1546450574842; Wed, 02 Jan 2019 09:36:14 -0800 (PST) Received: from andreyknvl0.muc.corp.google.com ([2a00:79e0:15:13:8ce:d7fa:9f4c:492]) by smtp.gmail.com with ESMTPSA id t4sm45987076wrm.6.2019.01.02.09.36.13 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Wed, 02 Jan 2019 09:36:13 -0800 (PST) From: Andrey Konovalov To: Andrey Ryabinin , Alexander Potapenko , Dmitry Vyukov , Catalin Marinas , Will Deacon , Christoph Lameter , Andrew Morton , Mark Rutland , Nick Desaulniers , Marc Zyngier , Dave Martin , Ard Biesheuvel , "Eric W . Biederman" , Ingo Molnar , Paul Lawrence , Geert Uytterhoeven , Arnd Bergmann , "Kirill A . Shutemov" , Greg Kroah-Hartman , Kate Stewart , Mike Rapoport , Vincenzo Frascino , kasan-dev@googlegroups.com, linux-doc@vger.kernel.org, linux-kernel@vger.kernel.org, linux-arm-kernel@lists.infradead.org, linux-sparse@vger.kernel.org, linux-mm@kvack.org, linux-kbuild@vger.kernel.org Subject: [PATCH v2 1/3] kasan, arm64: use ARCH_SLAB_MINALIGN instead of manual aligning Date: Wed, 2 Jan 2019 18:36:06 +0100 Message-Id: X-Mailer: git-send-email 2.20.1.415.g653613c723-goog In-Reply-To: References: MIME-Version: 1.0 X-CRM114-Version: 20100106-BlameMichelson ( TRE 0.8.0 (BSD) ) MR-646709E3 X-CRM114-CacheID: sfid-20190102_093619_980459_B7DEA227 X-CRM114-Status: GOOD ( 14.00 ) X-BeenThere: linux-arm-kernel@lists.infradead.org X-Mailman-Version: 2.1.21 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Cc: Vishwath Mohan , Chintan Pandya , Jacob Bramley , Jann Horn , Ruben Ayrapetyan , Andrey Konovalov , Lee Smith , Kostya Serebryany , Mark Brand , Ramana Radhakrishnan , Evgeniy Stepanov Sender: "linux-arm-kernel" Errors-To: linux-arm-kernel-bounces+patchwork-linux-arm=patchwork.kernel.org@lists.infradead.org X-Virus-Scanned: ClamAV using ClamSMTP Instead of changing cache->align to be aligned to KASAN_SHADOW_SCALE_SIZE in kasan_cache_create() we can reuse the ARCH_SLAB_MINALIGN macro. Suggested-by: Vincenzo Frascino Signed-off-by: Andrey Konovalov --- arch/arm64/include/asm/kasan.h | 4 ++++ include/linux/slab.h | 1 + mm/kasan/common.c | 2 -- 3 files changed, 5 insertions(+), 2 deletions(-) diff --git a/arch/arm64/include/asm/kasan.h b/arch/arm64/include/asm/kasan.h index b52aacd2c526..ba26150d578d 100644 --- a/arch/arm64/include/asm/kasan.h +++ b/arch/arm64/include/asm/kasan.h @@ -36,6 +36,10 @@ #define KASAN_SHADOW_OFFSET (KASAN_SHADOW_END - (1ULL << \ (64 - KASAN_SHADOW_SCALE_SHIFT))) +#ifdef CONFIG_KASAN_SW_TAGS +#define ARCH_SLAB_MINALIGN (1ULL << KASAN_SHADOW_SCALE_SHIFT) +#endif + void kasan_init(void); void kasan_copy_shadow(pgd_t *pgdir); asmlinkage void kasan_early_init(void); diff --git a/include/linux/slab.h b/include/linux/slab.h index 11b45f7ae405..d87f913ab4e8 100644 --- a/include/linux/slab.h +++ b/include/linux/slab.h @@ -16,6 +16,7 @@ #include #include #include +#include /* diff --git a/mm/kasan/common.c b/mm/kasan/common.c index 03d5d1374ca7..44390392d4c9 100644 --- a/mm/kasan/common.c +++ b/mm/kasan/common.c @@ -298,8 +298,6 @@ void kasan_cache_create(struct kmem_cache *cache, unsigned int *size, return; } - cache->align = round_up(cache->align, KASAN_SHADOW_SCALE_SIZE); - *flags |= SLAB_KASAN; } From patchwork Wed Jan 2 17:36:07 2019 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Andrey Konovalov X-Patchwork-Id: 10746573 Return-Path: Received: from mail.wl.linuxfoundation.org (pdx-wl-mail.web.codeaurora.org [172.30.200.125]) by pdx-korg-patchwork-2.web.codeaurora.org (Postfix) with ESMTP id 8038491E for ; Wed, 2 Jan 2019 17:37:01 +0000 (UTC) Received: from mail.wl.linuxfoundation.org (localhost [127.0.0.1]) by mail.wl.linuxfoundation.org (Postfix) with ESMTP id 610F028405 for ; Wed, 2 Jan 2019 17:37:01 +0000 (UTC) Received: by mail.wl.linuxfoundation.org (Postfix, from userid 486) id 54C8928417; Wed, 2 Jan 2019 17:37:01 +0000 (UTC) X-Spam-Checker-Version: SpamAssassin 3.3.1 (2010-03-16) on pdx-wl-mail.web.codeaurora.org X-Spam-Level: X-Spam-Status: No, score=-5.2 required=2.0 tests=BAYES_00,DKIM_ADSP_CUSTOM_MED, DKIM_SIGNED,DKIM_VALID,MAILING_LIST_MULTI,RCVD_IN_DNSWL_MED autolearn=ham version=3.3.1 Received: from bombadil.infradead.org (bombadil.infradead.org [198.137.202.133]) (using TLSv1.2 with cipher AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mail.wl.linuxfoundation.org (Postfix) with ESMTPS id 0CDE628409 for ; Wed, 2 Jan 2019 17:37:01 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.infradead.org; s=bombadil.20170209; h=Sender: Content-Transfer-Encoding:Content-Type:Cc:List-Subscribe:List-Help:List-Post: List-Archive:List-Unsubscribe:List-Id:MIME-Version:References:In-Reply-To: Message-Id:Date:Subject:To:From:Reply-To:Content-ID:Content-Description: Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID: List-Owner; bh=xMSdrKJSoSiX+21PwbXrH6sMAxBMxx2yTqvcAm8lSbs=; b=D6AHuGYfMgJzg1 7BPIhQYIn0TTljWbg1gOGlj0gtIiHS2ONaiAkmVzptYS0i06ayn7vh59sU0HorUztLP14duoNh2Ne LltR05/oUi+sZdqqm/ZQEsJxSAG65P/tJ9s2sHVEiQRtykucDtvwtOWRFHF0vJCMfZMufxQp/VurR eyxnnXIYnIdqxpTPAlM/ZACfLlStpBWIP1dkbg3NDQo1U2N/nHPhpi/QuWMyOTJSJSy4p0IKrsXud O8M8vDFL1dtE//B5wLNxsF/PoPkrrJbNnQeJ+IKHtUkWFyOhCx4xZ8CtHOfOnVtjwNfNOX5bsbWRE UKGz+prXmdx5dkHGn+5g==; Received: from localhost ([127.0.0.1] helo=bombadil.infradead.org) by bombadil.infradead.org with esmtp (Exim 4.90_1 #2 (Red Hat Linux)) id 1gekRq-0005xu-S2; Wed, 02 Jan 2019 17:36:54 +0000 Received: from mail-wm1-x341.google.com ([2a00:1450:4864:20::341]) by bombadil.infradead.org with esmtps (Exim 4.90_1 #2 (Red Hat Linux)) id 1gekRI-0005PV-M4 for linux-arm-kernel@lists.infradead.org; Wed, 02 Jan 2019 17:36:23 +0000 Received: by mail-wm1-x341.google.com with SMTP id t200so16303622wmt.0 for ; Wed, 02 Jan 2019 09:36:18 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20161025; h=from:to:cc:subject:date:message-id:in-reply-to:references :mime-version:content-transfer-encoding; bh=wqfuZcAjUCBtOLKWkS6SRZq/hte3EYpV7rEPQw3hkz8=; b=GBABedigx8sH5GFwpRqipEDZ14ymhRvEFULjEU8wLa/LptdTisVFf9skUy8ylEKwgj RF12pUwr344Vyvy3ZqJC4iKm1OZSWqoVLD5mJZkl91WIY/lo6o1i2e7+QvZjCRXC8gqD TalGJ7+keqs9g4ydv5W/68JCwOiEcJUrlW170vCsYKVKJdezXyBqilxWlN06NaZHYTDc QQgWpPrpqe6SqK7zrP/HpOaRELc378Wew1Pp2kpkP+K7TKwG3na64p2Wzdh2fIyKQxWR 416+4i3iHDx7qlDktBw/RgIj4tv1H8OekGka2BVVugetEBDgCsmpkgmw/g7V3gWXuDyc OjoQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:to:cc:subject:date:message-id:in-reply-to :references:mime-version:content-transfer-encoding; bh=wqfuZcAjUCBtOLKWkS6SRZq/hte3EYpV7rEPQw3hkz8=; b=R3QZP/Rqyyk1Cx4NMYuRn6FSKYq8KBdSqrBmpA0dCkgJ7AgvNazniuWrBAKrAICqta bS+E0dz9HTAjtLMwHGmVHpKN2Ituc4H3/x8yOQxzLMBFcT5PPMpjcxvrWznAJJ00pTua VLilIALgOBMWhvWVrw2HbRdshG7Od95sd+A9nvnMbLoH+PuR51NlERcROUkpkZ5/L0go Pha6DFlX8OqanzcUUFp7zTkq+YSrgMq6gr4suVXLlFjx5NQxv/M7GKdLf0ugTjw9cHUe tUD+GpeLPm3sEhvKYXv+uW+npRDSofr+pl53U+d7DM+A2TKya7VDLUTUVt0oFyWzwEFK VJQg== X-Gm-Message-State: AA+aEWY9SyaAI18oXM/Osczc2E7dZJwimZJKf0MAzv5L9ap7EXCH7oQL r3AZnLKLleK4R9fHUj0zsajc3g== X-Google-Smtp-Source: AFSGD/W97uWDkFBwjy9qVKlmOmTQCuBOdfdQInnihelGax0GIIIDp5gYRmDwwP96Pfhda8t/d8RaVw== X-Received: by 2002:a1c:4108:: with SMTP id o8mr34987293wma.91.1546450576552; Wed, 02 Jan 2019 09:36:16 -0800 (PST) Received: from andreyknvl0.muc.corp.google.com ([2a00:79e0:15:13:8ce:d7fa:9f4c:492]) by smtp.gmail.com with ESMTPSA id t4sm45987076wrm.6.2019.01.02.09.36.14 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Wed, 02 Jan 2019 09:36:15 -0800 (PST) From: Andrey Konovalov To: Andrey Ryabinin , Alexander Potapenko , Dmitry Vyukov , Catalin Marinas , Will Deacon , Christoph Lameter , Andrew Morton , Mark Rutland , Nick Desaulniers , Marc Zyngier , Dave Martin , Ard Biesheuvel , "Eric W . Biederman" , Ingo Molnar , Paul Lawrence , Geert Uytterhoeven , Arnd Bergmann , "Kirill A . Shutemov" , Greg Kroah-Hartman , Kate Stewart , Mike Rapoport , Vincenzo Frascino , kasan-dev@googlegroups.com, linux-doc@vger.kernel.org, linux-kernel@vger.kernel.org, linux-arm-kernel@lists.infradead.org, linux-sparse@vger.kernel.org, linux-mm@kvack.org, linux-kbuild@vger.kernel.org Subject: [PATCH v2 2/3] kasan: make tag based mode work with CONFIG_HARDENED_USERCOPY Date: Wed, 2 Jan 2019 18:36:07 +0100 Message-Id: <21de3c171438760a232d51cea56792c886bc9160.1546450432.git.andreyknvl@google.com> X-Mailer: git-send-email 2.20.1.415.g653613c723-goog In-Reply-To: References: MIME-Version: 1.0 X-CRM114-Version: 20100106-BlameMichelson ( TRE 0.8.0 (BSD) ) MR-646709E3 X-CRM114-CacheID: sfid-20190102_093620_719939_99726798 X-CRM114-Status: GOOD ( 12.80 ) X-BeenThere: linux-arm-kernel@lists.infradead.org X-Mailman-Version: 2.1.21 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Cc: Vishwath Mohan , Chintan Pandya , Jacob Bramley , Jann Horn , Ruben Ayrapetyan , Andrey Konovalov , Lee Smith , Kostya Serebryany , Mark Brand , Ramana Radhakrishnan , Evgeniy Stepanov Sender: "linux-arm-kernel" Errors-To: linux-arm-kernel-bounces+patchwork-linux-arm=patchwork.kernel.org@lists.infradead.org X-Virus-Scanned: ClamAV using ClamSMTP With CONFIG_HARDENED_USERCOPY enabled __check_heap_object() compares and then subtracts a potentially tagged pointer with a non-tagged address of the page that this pointer belongs to, which leads to unexpected behavior. Untag the pointer in __check_heap_object() before doing any of these operations. Signed-off-by: Andrey Konovalov --- mm/slub.c | 2 ++ 1 file changed, 2 insertions(+) diff --git a/mm/slub.c b/mm/slub.c index 36c0befeebd8..1e3d0ec4e200 100644 --- a/mm/slub.c +++ b/mm/slub.c @@ -3846,6 +3846,8 @@ void __check_heap_object(const void *ptr, unsigned long n, struct page *page, unsigned int offset; size_t object_size; + ptr = kasan_reset_tag(ptr); + /* Find object and usable object size. */ s = page->slab_cache; From patchwork Wed Jan 2 17:36:08 2019 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Andrey Konovalov X-Patchwork-Id: 10746575 Return-Path: Received: from mail.wl.linuxfoundation.org (pdx-wl-mail.web.codeaurora.org [172.30.200.125]) by pdx-korg-patchwork-2.web.codeaurora.org (Postfix) with ESMTP id BA90C91E for ; Wed, 2 Jan 2019 17:37:12 +0000 (UTC) Received: from mail.wl.linuxfoundation.org (localhost [127.0.0.1]) by mail.wl.linuxfoundation.org (Postfix) with ESMTP id 9CB9928417 for ; Wed, 2 Jan 2019 17:37:12 +0000 (UTC) Received: by mail.wl.linuxfoundation.org (Postfix, from userid 486) id 8FB972841F; Wed, 2 Jan 2019 17:37:12 +0000 (UTC) X-Spam-Checker-Version: SpamAssassin 3.3.1 (2010-03-16) on pdx-wl-mail.web.codeaurora.org X-Spam-Level: X-Spam-Status: No, score=-5.2 required=2.0 tests=BAYES_00,DKIM_ADSP_CUSTOM_MED, DKIM_SIGNED,DKIM_VALID,MAILING_LIST_MULTI,RCVD_IN_DNSWL_MED autolearn=unavailable version=3.3.1 Received: from bombadil.infradead.org (bombadil.infradead.org [198.137.202.133]) (using TLSv1.2 with cipher AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mail.wl.linuxfoundation.org (Postfix) with ESMTPS id E9B8D2841D for ; Wed, 2 Jan 2019 17:37:11 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.infradead.org; s=bombadil.20170209; h=Sender: Content-Transfer-Encoding:Content-Type:Cc:List-Subscribe:List-Help:List-Post: List-Archive:List-Unsubscribe:List-Id:MIME-Version:References:In-Reply-To: Message-Id:Date:Subject:To:From:Reply-To:Content-ID:Content-Description: Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID: List-Owner; bh=ZZCjZ+Q3kXJVvlM3I0NTy1cdPwujy5lXbIteBT5O2KQ=; b=O05Lrkgpz7Yy22 0FDSFKT64UJ+iZliiI6CSuQxsEg2BtN1a4ph/j4233b2B6cb2jMLHeLySNfe/iltiYhmtmJRHDUmq Z4WwfpH8nwFwpTnYupzTk+LFjV/nYzJgz+VbF7qS7xQrwlk9k99nt0JQ1PYDLCeSPd5Z8RRUcY4XG XZK/5bfASlSBAYeiuocw9ArdwjQWAtGk75Sq15LGvfXeG2ohiGG4NwRMOa3xrsZFSi20qLwDNO/or LfiaoIQ2bfB01aaQ4Xb711z7+2YeL/0mv/VEuTWznC/p9VpY8vs3L6GSvKyPNj7rkhUP97jnx0mNJ hHcoow8xkPiCg/a8x78g==; Received: from localhost ([127.0.0.1] helo=bombadil.infradead.org) by bombadil.infradead.org with esmtp (Exim 4.90_1 #2 (Red Hat Linux)) id 1gekS5-0006EZ-AE; Wed, 02 Jan 2019 17:37:09 +0000 Received: from mail-wm1-x344.google.com ([2a00:1450:4864:20::344]) by bombadil.infradead.org with esmtps (Exim 4.90_1 #2 (Red Hat Linux)) id 1gekRI-0005Pc-Ot for linux-arm-kernel@lists.infradead.org; Wed, 02 Jan 2019 17:36:23 +0000 Received: by mail-wm1-x344.google.com with SMTP id b11so27271537wmj.1 for ; Wed, 02 Jan 2019 09:36:20 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20161025; h=from:to:cc:subject:date:message-id:in-reply-to:references :mime-version:content-transfer-encoding; bh=JbDh3nO/eQ5r3H90w51/iWL5ZM5B6uICF84/YZhcCg4=; b=J3EioQAmzqQ510tIYUdGn3niW30hZBCQDaqUxXA6W8Tx56EgefOMxfeiYePggvLtzV duXz2IeiYTCZpxPro8vAGHyjWQH/Y1/d/Ak/b3m9WVFcOtcdpIuYK79GinCB8sSiZtG3 ldCh6avAFDLKYMtq9F3XaB02vQPo22UkXsFhXhyIBx7oOFhnHXxUUD8YJ7FKz6fLxj4g UdEA7DwTWevqPwpxJS3DNw0FJygWBLCgnIL+wZ0Gdd6dAoG2Qh+1ORT2/g8fuq65aSCh hwax2bMe285RhifAqx23AgtZ3ATuL6cdl/MSN8F0BuYYlWJ2a2yf/dyePmmOzCrkGSnZ /Clg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:to:cc:subject:date:message-id:in-reply-to :references:mime-version:content-transfer-encoding; bh=JbDh3nO/eQ5r3H90w51/iWL5ZM5B6uICF84/YZhcCg4=; b=IqTeQ0YP06dj04KiGhIrmreeiRVyqtYIffkz4JpQCB6OIHeKvbTDtIGeFJfPxGIfZ4 SOjE9ASHucBM7SfkflHyVRDsrg96uxBj2EnZdp5Z6tkPld/UAuSpbXjnax9yzCoSnGYa hUbPkDe3IDHejlp+AsHr8SDNR7C9usfaKFBjBzBJsRHTNK3yeNYzgQusF8GSHfsgvdsQ POhRm0xROxCTIoRygLUBHQeEwXVgLyi1jkRFaQQ2uVf05LIZ43Ja3rUIAb5GDX71ih6v NgiXqyvVPNOp1/Q/En8xkSYlcNvbVWgu9RAPTIuJW++sdNbaICJ6MYj2plKUliflzKDR he2A== X-Gm-Message-State: AA+aEWbgkrl+zhSM/454ZlaoU8eQaXgfGB+6FELmYIAGF2EMfBqHyL/W qPBl8cyDoTyfoLgTSzwOJ8y2mg== X-Google-Smtp-Source: ALg8bN4dqeXqnEdkw7vZRXClez1sw3njLXNHpEGFyX9nPGsXXD3dzvB0Oz/M0AbKGq7DF3oZ68k8Uw== X-Received: by 2002:a1c:e715:: with SMTP id e21mr36108254wmh.101.1546450578353; Wed, 02 Jan 2019 09:36:18 -0800 (PST) Received: from andreyknvl0.muc.corp.google.com ([2a00:79e0:15:13:8ce:d7fa:9f4c:492]) by smtp.gmail.com with ESMTPSA id t4sm45987076wrm.6.2019.01.02.09.36.16 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Wed, 02 Jan 2019 09:36:17 -0800 (PST) From: Andrey Konovalov To: Andrey Ryabinin , Alexander Potapenko , Dmitry Vyukov , Catalin Marinas , Will Deacon , Christoph Lameter , Andrew Morton , Mark Rutland , Nick Desaulniers , Marc Zyngier , Dave Martin , Ard Biesheuvel , "Eric W . Biederman" , Ingo Molnar , Paul Lawrence , Geert Uytterhoeven , Arnd Bergmann , "Kirill A . Shutemov" , Greg Kroah-Hartman , Kate Stewart , Mike Rapoport , Vincenzo Frascino , kasan-dev@googlegroups.com, linux-doc@vger.kernel.org, linux-kernel@vger.kernel.org, linux-arm-kernel@lists.infradead.org, linux-sparse@vger.kernel.org, linux-mm@kvack.org, linux-kbuild@vger.kernel.org Subject: [PATCH v2 3/3] kasan: fix krealloc handling for tag-based mode Date: Wed, 2 Jan 2019 18:36:08 +0100 Message-Id: X-Mailer: git-send-email 2.20.1.415.g653613c723-goog In-Reply-To: References: MIME-Version: 1.0 X-CRM114-Version: 20100106-BlameMichelson ( TRE 0.8.0 (BSD) ) MR-646709E3 X-CRM114-CacheID: sfid-20190102_093620_813708_3548968B X-CRM114-Status: GOOD ( 20.22 ) X-BeenThere: linux-arm-kernel@lists.infradead.org X-Mailman-Version: 2.1.21 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Cc: Vishwath Mohan , Chintan Pandya , Jacob Bramley , Jann Horn , Ruben Ayrapetyan , Andrey Konovalov , Lee Smith , Kostya Serebryany , Mark Brand , Ramana Radhakrishnan , Evgeniy Stepanov Sender: "linux-arm-kernel" Errors-To: linux-arm-kernel-bounces+patchwork-linux-arm=patchwork.kernel.org@lists.infradead.org X-Virus-Scanned: ClamAV using ClamSMTP Right now tag-based KASAN can retag the memory that is reallocated via krealloc and return a differently tagged pointer even if the same slab object gets used and no reallocated technically happens. There are a few issues with this approach. One is that krealloc callers can't rely on comparing the return value with the passed argument to check whether reallocation happened. Another is that if a caller knows that no reallocation happened, that it can access object memory through the old pointer, which leads to false positives. Look at nf_ct_ext_add() to see an example. Fix this by keeping the same tag if the memory don't actually gets reallocated during krealloc. Signed-off-by: Andrey Konovalov --- include/linux/kasan.h | 14 +++++--------- include/linux/slab.h | 4 ++-- mm/kasan/common.c | 20 ++++++++++++-------- mm/slab.c | 8 ++++---- mm/slab_common.c | 2 +- mm/slub.c | 10 +++++----- 6 files changed, 29 insertions(+), 29 deletions(-) diff --git a/include/linux/kasan.h b/include/linux/kasan.h index b40ea104dd36..7576fff90923 100644 --- a/include/linux/kasan.h +++ b/include/linux/kasan.h @@ -57,9 +57,8 @@ void * __must_check kasan_kmalloc_large(const void *ptr, size_t size, void kasan_kfree_large(void *ptr, unsigned long ip); void kasan_poison_kfree(void *ptr, unsigned long ip); void * __must_check kasan_kmalloc(struct kmem_cache *s, const void *object, - size_t size, gfp_t flags); -void * __must_check kasan_krealloc(const void *object, size_t new_size, - gfp_t flags); + size_t size, gfp_t flags, bool krealloc); +void kasan_krealloc(const void *object, size_t new_size, gfp_t flags); void * __must_check kasan_slab_alloc(struct kmem_cache *s, void *object, gfp_t flags); @@ -118,15 +117,12 @@ static inline void *kasan_kmalloc_large(void *ptr, size_t size, gfp_t flags) static inline void kasan_kfree_large(void *ptr, unsigned long ip) {} static inline void kasan_poison_kfree(void *ptr, unsigned long ip) {} static inline void *kasan_kmalloc(struct kmem_cache *s, const void *object, - size_t size, gfp_t flags) -{ - return (void *)object; -} -static inline void *kasan_krealloc(const void *object, size_t new_size, - gfp_t flags) + size_t size, gfp_t flags, bool krealloc) { return (void *)object; } +static inline void kasan_krealloc(const void *object, size_t new_size, + gfp_t flags) {} static inline void *kasan_slab_alloc(struct kmem_cache *s, void *object, gfp_t flags) diff --git a/include/linux/slab.h b/include/linux/slab.h index d87f913ab4e8..1cd168758c05 100644 --- a/include/linux/slab.h +++ b/include/linux/slab.h @@ -445,7 +445,7 @@ static __always_inline void *kmem_cache_alloc_trace(struct kmem_cache *s, { void *ret = kmem_cache_alloc(s, flags); - ret = kasan_kmalloc(s, ret, size, flags); + ret = kasan_kmalloc(s, ret, size, flags, false); return ret; } @@ -456,7 +456,7 @@ kmem_cache_alloc_node_trace(struct kmem_cache *s, { void *ret = kmem_cache_alloc_node(s, gfpflags, node); - ret = kasan_kmalloc(s, ret, size, gfpflags); + ret = kasan_kmalloc(s, ret, size, gfpflags, false); return ret; } #endif /* CONFIG_TRACING */ diff --git a/mm/kasan/common.c b/mm/kasan/common.c index 44390392d4c9..b6633ab86160 100644 --- a/mm/kasan/common.c +++ b/mm/kasan/common.c @@ -392,7 +392,7 @@ void * __must_check kasan_init_slab_obj(struct kmem_cache *cache, void * __must_check kasan_slab_alloc(struct kmem_cache *cache, void *object, gfp_t flags) { - return kasan_kmalloc(cache, object, cache->object_size, flags); + return kasan_kmalloc(cache, object, cache->object_size, flags, false); } static inline bool shadow_invalid(u8 tag, s8 shadow_byte) @@ -451,7 +451,7 @@ bool kasan_slab_free(struct kmem_cache *cache, void *object, unsigned long ip) } void * __must_check kasan_kmalloc(struct kmem_cache *cache, const void *object, - size_t size, gfp_t flags) + size_t size, gfp_t flags, bool krealloc) { unsigned long redzone_start; unsigned long redzone_end; @@ -468,8 +468,12 @@ void * __must_check kasan_kmalloc(struct kmem_cache *cache, const void *object, redzone_end = round_up((unsigned long)object + cache->object_size, KASAN_SHADOW_SCALE_SIZE); - if (IS_ENABLED(CONFIG_KASAN_SW_TAGS)) - tag = assign_tag(cache, object, false); + if (IS_ENABLED(CONFIG_KASAN_SW_TAGS)) { + if (krealloc) + tag = get_tag(object); + else + tag = assign_tag(cache, object, false); + } /* Tag is ignored in set_tag without CONFIG_KASAN_SW_TAGS */ kasan_unpoison_shadow(set_tag(object, tag), size); @@ -508,19 +512,19 @@ void * __must_check kasan_kmalloc_large(const void *ptr, size_t size, return (void *)ptr; } -void * __must_check kasan_krealloc(const void *object, size_t size, gfp_t flags) +void kasan_krealloc(const void *object, size_t size, gfp_t flags) { struct page *page; if (unlikely(object == ZERO_SIZE_PTR)) - return (void *)object; + return; page = virt_to_head_page(object); if (unlikely(!PageSlab(page))) - return kasan_kmalloc_large(object, size, flags); + kasan_kmalloc_large(object, size, flags); else - return kasan_kmalloc(page->slab_cache, object, size, flags); + kasan_kmalloc(page->slab_cache, object, size, flags, true); } void kasan_poison_kfree(void *ptr, unsigned long ip) diff --git a/mm/slab.c b/mm/slab.c index 73fe23e649c9..09b54386cf67 100644 --- a/mm/slab.c +++ b/mm/slab.c @@ -3604,7 +3604,7 @@ kmem_cache_alloc_trace(struct kmem_cache *cachep, gfp_t flags, size_t size) ret = slab_alloc(cachep, flags, _RET_IP_); - ret = kasan_kmalloc(cachep, ret, size, flags); + ret = kasan_kmalloc(cachep, ret, size, flags, false); trace_kmalloc(_RET_IP_, ret, size, cachep->size, flags); return ret; @@ -3647,7 +3647,7 @@ void *kmem_cache_alloc_node_trace(struct kmem_cache *cachep, ret = slab_alloc_node(cachep, flags, nodeid, _RET_IP_); - ret = kasan_kmalloc(cachep, ret, size, flags); + ret = kasan_kmalloc(cachep, ret, size, flags, false); trace_kmalloc_node(_RET_IP_, ret, size, cachep->size, flags, nodeid); @@ -3668,7 +3668,7 @@ __do_kmalloc_node(size_t size, gfp_t flags, int node, unsigned long caller) if (unlikely(ZERO_OR_NULL_PTR(cachep))) return cachep; ret = kmem_cache_alloc_node_trace(cachep, flags, node, size); - ret = kasan_kmalloc(cachep, ret, size, flags); + ret = kasan_kmalloc(cachep, ret, size, flags, false); return ret; } @@ -3706,7 +3706,7 @@ static __always_inline void *__do_kmalloc(size_t size, gfp_t flags, return cachep; ret = slab_alloc(cachep, flags, caller); - ret = kasan_kmalloc(cachep, ret, size, flags); + ret = kasan_kmalloc(cachep, ret, size, flags, false); trace_kmalloc(caller, ret, size, cachep->size, flags); diff --git a/mm/slab_common.c b/mm/slab_common.c index 81732d05e74a..b55c58178f83 100644 --- a/mm/slab_common.c +++ b/mm/slab_common.c @@ -1507,7 +1507,7 @@ static __always_inline void *__do_krealloc(const void *p, size_t new_size, ks = ksize(p); if (ks >= new_size) { - p = kasan_krealloc((void *)p, new_size, flags); + kasan_krealloc((void *)p, new_size, flags); return (void *)p; } diff --git a/mm/slub.c b/mm/slub.c index 1e3d0ec4e200..20aa0547acbf 100644 --- a/mm/slub.c +++ b/mm/slub.c @@ -2763,7 +2763,7 @@ void *kmem_cache_alloc_trace(struct kmem_cache *s, gfp_t gfpflags, size_t size) { void *ret = slab_alloc(s, gfpflags, _RET_IP_); trace_kmalloc(_RET_IP_, ret, size, s->size, gfpflags); - ret = kasan_kmalloc(s, ret, size, gfpflags); + ret = kasan_kmalloc(s, ret, size, gfpflags, false); return ret; } EXPORT_SYMBOL(kmem_cache_alloc_trace); @@ -2791,7 +2791,7 @@ void *kmem_cache_alloc_node_trace(struct kmem_cache *s, trace_kmalloc_node(_RET_IP_, ret, size, s->size, gfpflags, node); - ret = kasan_kmalloc(s, ret, size, gfpflags); + ret = kasan_kmalloc(s, ret, size, gfpflags, false); return ret; } EXPORT_SYMBOL(kmem_cache_alloc_node_trace); @@ -3364,7 +3364,7 @@ static void early_kmem_cache_node_alloc(int node) init_tracking(kmem_cache_node, n); #endif n = kasan_kmalloc(kmem_cache_node, n, sizeof(struct kmem_cache_node), - GFP_KERNEL); + GFP_KERNEL, false); page->freelist = get_freepointer(kmem_cache_node, n); page->inuse = 1; page->frozen = 0; @@ -3779,7 +3779,7 @@ void *__kmalloc(size_t size, gfp_t flags) trace_kmalloc(_RET_IP_, ret, size, s->size, flags); - ret = kasan_kmalloc(s, ret, size, flags); + ret = kasan_kmalloc(s, ret, size, flags, false); return ret; } @@ -3823,7 +3823,7 @@ void *__kmalloc_node(size_t size, gfp_t flags, int node) trace_kmalloc_node(_RET_IP_, ret, size, s->size, flags, node); - ret = kasan_kmalloc(s, ret, size, flags); + ret = kasan_kmalloc(s, ret, size, flags, false); return ret; }