2023-07-13 07:26:09

by Nikhil V

[permalink] [raw]
Subject: [PATCH] arm64: mm: Make hibernation aware of KFENCE

In the restore path, swsusp_arch_suspend_exit uses copy_page() to
over-write memory. However, with features like KFENCE enabled, there could
be situations where it may have marked some pages as not valid, due to
which it could be reported as invalid accesses.

Consider a situation where page 'P' was part of the hibernation image.
Now, when the resume kernel tries to restore the pages, the same page 'P'
is already in use in the resume kernel and is kfence protected, due to
which its mapping is removed from linear map. Since restoring pages happens
with the resume kernel page tables, we would end up accessing 'P' during
copy and results in kernel pagefault.

The proposed fix tries to solve this issue by marking PTE as valid for such
kfence protected pages.

Co-developed-by: Pavankumar Kondeti <[email protected]>
Signed-off-by: Pavankumar Kondeti <[email protected]>
Signed-off-by: Nikhil V <[email protected]>
---
arch/arm64/mm/trans_pgd.c | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)

diff --git a/arch/arm64/mm/trans_pgd.c b/arch/arm64/mm/trans_pgd.c
index 4ea2eefbc053..e9ad391fc8ea 100644
--- a/arch/arm64/mm/trans_pgd.c
+++ b/arch/arm64/mm/trans_pgd.c
@@ -24,6 +24,7 @@
#include <linux/bug.h>
#include <linux/mm.h>
#include <linux/mmzone.h>
+#include <linux/kfence.h>

static void *trans_alloc(struct trans_pgd_info *info)
{
@@ -41,7 +42,8 @@ static void _copy_pte(pte_t *dst_ptep, pte_t *src_ptep, unsigned long addr)
* the temporary mappings we use during restore.
*/
set_pte(dst_ptep, pte_mkwrite(pte));
- } else if (debug_pagealloc_enabled() && !pte_none(pte)) {
+ } else if ((debug_pagealloc_enabled() ||
+ is_kfence_address((void *)addr)) && !pte_none(pte)) {
/*
* debug_pagealloc will removed the PTE_VALID bit if
* the page isn't in use by the resume kernel. It may have
--
2.17.1



2023-07-20 12:34:45

by Will Deacon

[permalink] [raw]
Subject: Re: [PATCH] arm64: mm: Make hibernation aware of KFENCE

On Thu, 13 Jul 2023 12:37:57 +0530, Nikhil V wrote:
> In the restore path, swsusp_arch_suspend_exit uses copy_page() to
> over-write memory. However, with features like KFENCE enabled, there could
> be situations where it may have marked some pages as not valid, due to
> which it could be reported as invalid accesses.
>
> Consider a situation where page 'P' was part of the hibernation image.
> Now, when the resume kernel tries to restore the pages, the same page 'P'
> is already in use in the resume kernel and is kfence protected, due to
> which its mapping is removed from linear map. Since restoring pages happens
> with the resume kernel page tables, we would end up accessing 'P' during
> copy and results in kernel pagefault.
>
> [...]

Applied to arm64 (for-next/fixes), thanks!

[1/1] arm64: mm: Make hibernation aware of KFENCE
https://git.kernel.org/arm64/c/a8bd38dbc57c

Cheers,
--
Will

https://fixes.arm64.dev
https://next.arm64.dev
https://will.arm64.dev