Received: by 2002:a25:86ce:0:0:0:0:0 with SMTP id y14csp2305729ybm; Thu, 23 May 2019 14:51:25 -0700 (PDT) X-Google-Smtp-Source: APXvYqzPHQwS3wGSEcUrXPB+IPJ17/fqMVCo0AX3z/LrBNoZ6yFoxtjV/eKDfmFBw7yQpTfZmfEj X-Received: by 2002:a17:90a:b116:: with SMTP id z22mr4466208pjq.69.1558648285307; Thu, 23 May 2019 14:51:25 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1558648285; cv=none; d=google.com; s=arc-20160816; b=Tedi6FTK+RQ9OYI6/r8k1wm87aLY19X49wNE5/JqOwRn0nniGEXdx9nUjK7XDVE9BD 2MgePLNBtNFliAbqpXiJ7Dd1LWkmJ86rggz8UHsYiIgrLiWp0WXdOdkm+6Pv9zG1xr+1 7aEsaoAZ8c+bYr8C5g2kRBvsbPotwdhgC3LDUYvq9hksOxwcJlMTRymR3YlRvacw7JJ1 dENlgYKO0zcFGHuORNa9RHacQl9Jg5VuYd5OJMRDoB0EBUhkr2Qp/9IzK3xdGHqxJQj2 ksC85GNak4rI0liL7qJi0y1sUDiP3qrNspc3sDirvFl7Y6xKDWe7SLitrOOCm106Oznx mdYw== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:sender:content-transfer-encoding :content-language:in-reply-to:mime-version:user-agent:date :message-id:organization:from:references:cc:to:subject :dkim-signature; bh=CA4BRvH7LpSOvdwGQ1RgbPK5R7ura7qGqy4SrVn6TGs=; b=oannaiqW47C/P6ekVs8wwtZ719JWWLE8IU/+N7Y+UykuEUJvc7AQIQMGPD7dPJ2GEv pnRV/lAbVeKsjeKzVzF0G2Jkse/ZMILMDOs+bv6V7PY5cUtHA6y9NgSnEb/xxsid9h0i 8+x+AeNux4TGby5fJcELxIURUuK1+PqaJnyRrVx6pvDzh0yQsz+rgCBG0YpuIAMo4drn ebqtY2jkQTuV1aN+Y/2x4E0q2zVXu17OClDdJRNl3XzzdlinFLdeHUzekN3dN/ABJ4eF waGOHIbHFT+9sH43cQ0j4IV0ijdU7I36b0c7iO0VevnZRK/Bu93tuyTF5/ZzU2/tbtkr nrLg== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@oracle.com header.s=corp-2018-07-02 header.b="X//cpGAK"; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=oracle.com Return-Path: Received: from vger.kernel.org (vger.kernel.org. [209.132.180.67]) by mx.google.com with ESMTP id 21si1106448pgp.493.2019.05.23.14.51.09; Thu, 23 May 2019 14:51:25 -0700 (PDT) Received-SPF: pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) client-ip=209.132.180.67; Authentication-Results: mx.google.com; dkim=pass header.i=@oracle.com header.s=corp-2018-07-02 header.b="X//cpGAK"; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=oracle.com Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S2388373AbfEWVtw (ORCPT + 99 others); Thu, 23 May 2019 17:49:52 -0400 Received: from aserp2130.oracle.com ([141.146.126.79]:58870 "EHLO aserp2130.oracle.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S2388134AbfEWVtw (ORCPT ); Thu, 23 May 2019 17:49:52 -0400 Received: from pps.filterd (aserp2130.oracle.com [127.0.0.1]) by aserp2130.oracle.com (8.16.0.27/8.16.0.27) with SMTP id x4NLhifU004317; Thu, 23 May 2019 21:49:13 GMT DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=oracle.com; h=subject : to : cc : references : from : message-id : date : mime-version : in-reply-to : content-type : content-transfer-encoding; s=corp-2018-07-02; bh=CA4BRvH7LpSOvdwGQ1RgbPK5R7ura7qGqy4SrVn6TGs=; b=X//cpGAKkvYu1m1BjaIbh5y4EYuwM+8rZjWW5aAmW0vi1toc+ON7ojqHQsbcK6pAW1oD bdaUeEmghYKNyuWdojEirpuCtcEnGnpjzGNjA/TAPNGPvcylGBa+20OGWCMnCwLHj8Tf YRS6xbAb5NCY6/3hnPEk+xsQaxia6MP4a6XjVZSvoh9chZIbCYwa7XRJ+TOdhejZB+v7 XSe3hifUXqlRGwDwQJJUjbd8e+die4vTzQ+aF3wEY1CdthC5hOmZQere78SM0w/UZFJa y1F1RpJmvyYHjzu9jq9fzTHoce2ebfeYA5vSKPJb2pXe3nPIQrp8MMBgMFftquXsLaI1 XQ== Received: from userp3020.oracle.com (userp3020.oracle.com [156.151.31.79]) by aserp2130.oracle.com with ESMTP id 2smsk5n948-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Thu, 23 May 2019 21:49:13 +0000 Received: from pps.filterd (userp3020.oracle.com [127.0.0.1]) by userp3020.oracle.com (8.16.0.27/8.16.0.27) with SMTP id x4NLmFZJ185512; Thu, 23 May 2019 21:49:12 GMT Received: from userv0121.oracle.com (userv0121.oracle.com [156.151.31.72]) by userp3020.oracle.com with ESMTP id 2smsgvrm93-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Thu, 23 May 2019 21:49:12 +0000 Received: from abhmp0002.oracle.com (abhmp0002.oracle.com [141.146.116.8]) by userv0121.oracle.com (8.14.4/8.13.8) with ESMTP id x4NLn8SI003595; Thu, 23 May 2019 21:49:09 GMT Received: from [192.168.1.16] (/24.9.64.241) by default (Oracle Beehive Gateway v4.0) with ESMTP ; Thu, 23 May 2019 21:49:08 +0000 Subject: Re: [PATCH v15 00/17] arm64: untag user pointers passed to the kernel To: Catalin Marinas Cc: Kees Cook , Evgenii Stepanov , Andrey Konovalov , Linux ARM , Linux Memory Management List , LKML , amd-gfx@lists.freedesktop.org, dri-devel@lists.freedesktop.org, linux-rdma@vger.kernel.org, linux-media@vger.kernel.org, kvm@vger.kernel.org, "open list:KERNEL SELFTEST FRAMEWORK" , Vincenzo Frascino , Will Deacon , Mark Rutland , Andrew Morton , Greg Kroah-Hartman , Yishai Hadas , Felix Kuehling , Alexander Deucher , Christian Koenig , Mauro Carvalho Chehab , Jens Wiklander , Alex Williamson , Leon Romanovsky , Dmitry Vyukov , Kostya Serebryany , Lee Smith , Ramana Radhakrishnan , Jacob Bramley , Ruben Ayrapetyan , Robin Murphy , Luc Van Oostenryck , Dave Martin , Kevin Brodsky , Szabolcs Nagy , Elliott Hughes References: <20190517144931.GA56186@arrakis.emea.arm.com> <20190521182932.sm4vxweuwo5ermyd@mbp> <201905211633.6C0BF0C2@keescook> <6049844a-65f5-f513-5b58-7141588fef2b@oracle.com> <20190523201105.oifkksus4rzcwqt4@mbp> From: Khalid Aziz Organization: Oracle Corp Message-ID: Date: Thu, 23 May 2019 15:49:05 -0600 User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:60.0) Gecko/20100101 Thunderbird/60.6.1 MIME-Version: 1.0 In-Reply-To: <20190523201105.oifkksus4rzcwqt4@mbp> Content-Type: text/plain; charset=utf-8 Content-Language: en-US Content-Transfer-Encoding: quoted-printable X-Proofpoint-Virus-Version: vendor=nai engine=6000 definitions=9266 signatures=668687 X-Proofpoint-Spam-Details: rule=notspam policy=default score=0 suspectscore=0 malwarescore=0 phishscore=0 bulkscore=0 spamscore=0 mlxscore=0 mlxlogscore=999 adultscore=0 classifier=spam adjust=0 reason=mlx scancount=1 engine=8.0.1-1810050000 definitions=main-1905230139 X-Proofpoint-Virus-Version: vendor=nai engine=6000 definitions=9266 signatures=668687 X-Proofpoint-Spam-Details: rule=notspam policy=default score=0 priorityscore=1501 malwarescore=0 suspectscore=0 phishscore=0 bulkscore=0 spamscore=0 clxscore=1015 lowpriorityscore=0 mlxscore=0 impostorscore=0 mlxlogscore=999 adultscore=0 classifier=spam adjust=0 reason=mlx scancount=1 engine=8.0.1-1810050000 definitions=main-1905230139 Sender: linux-kernel-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org On 5/23/19 2:11 PM, Catalin Marinas wrote: > Hi Khalid, >=20 > On Thu, May 23, 2019 at 11:51:40AM -0600, Khalid Aziz wrote: >> On 5/21/19 6:04 PM, Kees Cook wrote: >>> As an aside: I think Sparc ADI support in Linux actually side-stepped= >>> this[1] (i.e. chose "solution 1"): "All addresses passed to kernel mu= st >>> be non-ADI tagged addresses." (And sadly, "Kernel does not enable ADI= >>> for kernel code.") I think this was a mistake we should not repeat fo= r >>> arm64 (we do seem to be at least in agreement about this, I think). >>> >>> [1] https://lore.kernel.org/patchwork/patch/654481/ >> >> That is a very early version of the sparc ADI patch. Support for tagge= d >> addresses in syscalls was added in later versions and is in the patch >> that is in the kernel. >=20 > I tried to figure out but I'm not familiar with the sparc port. How did= > you solve the tagged address going into various syscall implementations= > in the kernel (e.g. sys_write)? Is the tag removed on kernel entry or i= t > ends up deeper in the core code? >=20 Another spot I should point out in ADI patch - Tags are not stored in VMAs and IOMMU does not support ADI tags on M7. ADI tags are stripped before userspace addresses are passed to IOMMU in the following snippet from the patch: diff --git a/arch/sparc/mm/gup.c b/arch/sparc/mm/gup.c index 5335ba3c850e..357b6047653a 100644 --- a/arch/sparc/mm/gup.c +++ b/arch/sparc/mm/gup.c @@ -201,6 +202,24 @@ int __get_user_pages_fast(unsigned long start, int nr_pages , int write, pgd_t *pgdp; int nr =3D 0; +#ifdef CONFIG_SPARC64 + if (adi_capable()) { + long addr =3D start; + + /* If userspace has passed a versioned address, kernel + * will not find it in the VMAs since it does not store + * the version tags in the list of VMAs. Storing version + * tags in list of VMAs is impractical since they can be + * changed any time from userspace without dropping into + * kernel. Any address search in VMAs will be done with + * non-versioned addresses. Ensure the ADI version bits + * are dropped here by sign extending the last bit before= + * ADI bits. IOMMU does not implement version tags. + */ + addr =3D (addr << (long)adi_nbits()) >> (long)adi_nbits()= ; + start =3D addr; + } +#endif start &=3D PAGE_MASK; addr =3D start; len =3D (unsigned long) nr_pages << PAGE_SHIFT; -- Khalid