Received: by 2002:a25:8b91:0:0:0:0:0 with SMTP id j17csp2618397ybl; Mon, 20 Jan 2020 06:21:00 -0800 (PST) X-Google-Smtp-Source: APXvYqynkfs07aPNxg6lAa8rKnFShipbPeppuur9mvuClg7Y98iJyh17dvjiEEOWsh/Q8KkEr/s6 X-Received: by 2002:a9d:e83:: with SMTP id 3mr16174773otj.218.1579530060025; Mon, 20 Jan 2020 06:21:00 -0800 (PST) ARC-Seal: i=1; a=rsa-sha256; t=1579530059; cv=none; d=google.com; s=arc-20160816; b=rLAnT7ouWMPT7JbRmfRsU7Bfs+Ba1u/amES4J9yGV4Mo7bQKG/r6rPrSgL/EJNrD0y iIYhwKp5rnVtDoW/GhSDMs1fnJHN2nXEPm4bJcZXKQiULQbkfyjOKi2WaNI066iweyoP dXyZGGGznFOPsA2lnh2yyFj/kNWCe2yzeyiSP58lQssdFMags5SuBuR6LX3Ly69+ID4I Axjth1IOMJZPjKOlf5yYN1U1jjgg7YM3HhC9ZRkY7dqg4CZam/foTPFkN8+XLQc+ZFdy ej+c2jcb1xTVCWmAO9NfzbLWiaHzrnSJwLHhjF6moa3+xndMQbKZKnF4cJstNMKy6pVM py4g== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:sender:cc:to:from:subject:mime-version :message-id:date:dkim-signature; bh=Nfa3SPvPtmfv9OXDVBjRxJwd9iLaWZX/BpfniwtezQo=; b=YnzKJr3Y8Tco4wUq3Th3VzP7046rrWWHbvG05ylOPNm2fxWbYevLMFjFc7TPGjFQfX 0ObO7TUhMYYBacuy18KDfJRrWpqA4/pUjrXZEdMkqwsSaz0EtpI3b4WHHuUyplcYplJO C0efKGanoI+N3pY+3kPmnIbEQ6op1ZrtNFGz9zs8RKvSLZTYJ84i/gLKfVgmH5MuVQ+D 16xifS1RdQjZogzZQrL6webMBLdPb2ttvT0Lf6VkDjkjOfVti+IKy+OBTlBvqhwBWjE1 eKHjTufhCtfZhPvez02CQG3uDX05fnCJSMRBIf8ofhCujvwIpbvlEE26Yjbz51hsJwz2 xIng== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@google.com header.s=20161025 header.b=UhbxWX6A; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=google.com Return-Path: Received: from vger.kernel.org (vger.kernel.org. [209.132.180.67]) by mx.google.com with ESMTP id l19si17042406oii.54.2020.01.20.06.20.47; Mon, 20 Jan 2020 06:20:59 -0800 (PST) Received-SPF: pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) client-ip=209.132.180.67; Authentication-Results: mx.google.com; dkim=pass header.i=@google.com header.s=20161025 header.b=UhbxWX6A; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=google.com Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1727990AbgATOTo (ORCPT + 99 others); Mon, 20 Jan 2020 09:19:44 -0500 Received: from mail-wm1-f74.google.com ([209.85.128.74]:36646 "EHLO mail-wm1-f74.google.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1726642AbgATOTn (ORCPT ); Mon, 20 Jan 2020 09:19:43 -0500 Received: by mail-wm1-f74.google.com with SMTP id f25so3754407wmb.1 for ; Mon, 20 Jan 2020 06:19:41 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20161025; h=date:message-id:mime-version:subject:from:to:cc; bh=Nfa3SPvPtmfv9OXDVBjRxJwd9iLaWZX/BpfniwtezQo=; b=UhbxWX6ASocBqYOmExgZzHhGzoGU/XgRLrivmvNu5RQg6NKZq6hO7pdIzkpWFJULHM atx/Qq2QEwL/yg/3qSS8SdwGO+jGGjp6w9Nl2ioB1mmyE00P7+fySO9bQICvMzQNmbHo bpDwCLx4VyPkgdqvfYQXDk3UKXXTFa7uGl77QnFdrl3ZLGHfKaq5u/nwlZ86la4up6y7 Xv8aDxNsRXVJFiQFWxXVDd6XSJ5XNpBik2BdIhdGQoUW1A3dAohysmdYUMsMwNCXG2VC r7EEcIVSqnpXmXHGucnsjd/QiIp5W0m9qRgBtoFDX+WZJ0yTeIhWDxtuYWhmQhaqWGIl S+XA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:date:message-id:mime-version:subject:from:to:cc; bh=Nfa3SPvPtmfv9OXDVBjRxJwd9iLaWZX/BpfniwtezQo=; b=UyE5pJgE4YeWhfinaXR4YkVhU2rrDhumNstd7ou48Tn32BLG0fm2gHbdRxbV5y5AmN ZUhR2GM6WW2cyQ37+Nm5lDA11GHscXrRyYokhmjMXz+6TlBJKPkOMit4YDITjDQZTSTx a9kzU2ZbbWK5lslxJMWpg4LRGneIAEr2vBxDhsK8i4tMHmGQ7/HFL+swtqVpdOqSP5V2 YBWEdZIkmfMdGVPsNiB0AQgUu8Y71cIrE57EpsYuF+5vPsQYrN4jiYG/TTBG+VZ4Uu6n 71Ip+lQrcXuEvi49/+I8C9oCUTS6pIxvG65zdtLQwqg2af+ltVEtiRzsz6sngfWe4X5x zrLA== X-Gm-Message-State: APjAAAXp0yRTBF00alKarxVLW20qBmWd7V6HxNUJtuTBowu6ZooJdT2Z h/2pD9ALrZgKFYe0WlPNmLaR71Ab0w== X-Received: by 2002:a5d:45c4:: with SMTP id b4mr18022313wrs.303.1579529980939; Mon, 20 Jan 2020 06:19:40 -0800 (PST) Date: Mon, 20 Jan 2020 15:19:23 +0100 Message-Id: <20200120141927.114373-1-elver@google.com> Mime-Version: 1.0 X-Mailer: git-send-email 2.25.0.341.g760bfbb309-goog Subject: [PATCH 1/5] include/linux: Add instrumented.h infrastructure From: Marco Elver To: elver@google.com Cc: paulmck@kernel.org, andreyknvl@google.com, glider@google.com, dvyukov@google.com, kasan-dev@googlegroups.com, linux-kernel@vger.kernel.org, mark.rutland@arm.com, will@kernel.org, peterz@infradead.org, boqun.feng@gmail.com, arnd@arndb.de, viro@zeniv.linux.org.uk, christophe.leroy@c-s.fr, dja@axtens.net, mpe@ellerman.id.au, rostedt@goodmis.org, mhiramat@kernel.org, mingo@kernel.org, christian.brauner@ubuntu.com, daniel@iogearbox.net, cyphar@cyphar.com, keescook@chromium.org, linux-arch@vger.kernel.org Content-Type: text/plain; charset="UTF-8" Sender: linux-kernel-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org This adds instrumented.h, which provides generic wrappers for memory access instrumentation that the compiler cannot emit for various sanitizers. Currently this unifies KASAN and KCSAN instrumentation. In future this will also include KMSAN instrumentation. Note that, copy_{to,from}_user require special instrumentation, providing hooks before and after the access, since we may need to know the actual bytes accessed (currently this is relevant for KCSAN, and is also relevant in future for KMSAN). Suggested-by: Arnd Bergmann Signed-off-by: Marco Elver --- include/linux/instrumented.h | 153 +++++++++++++++++++++++++++++++++++ 1 file changed, 153 insertions(+) create mode 100644 include/linux/instrumented.h diff --git a/include/linux/instrumented.h b/include/linux/instrumented.h new file mode 100644 index 000000000000..9f83c8520223 --- /dev/null +++ b/include/linux/instrumented.h @@ -0,0 +1,153 @@ +/* SPDX-License-Identifier: GPL-2.0 */ + +/* + * This header provides generic wrappers for memory access instrumentation that + * the compiler cannot emit for: KASAN, KCSAN. + */ +#ifndef _LINUX_INSTRUMENTED_H +#define _LINUX_INSTRUMENTED_H + +#include +#include +#include +#include + +/** + * instrument_read - instrument regular read access + * + * Instrument a regular read access. The instrumentation should be inserted + * before the actual read happens. + * + * @ptr address of access + * @size size of access + */ +static __always_inline void instrument_read(const volatile void *v, size_t size) +{ + kasan_check_read(v, size); + kcsan_check_read(v, size); +} + +/** + * instrument_write - instrument regular write access + * + * Instrument a regular write access. The instrumentation should be inserted + * before the actual write happens. + * + * @ptr address of access + * @size size of access + */ +static __always_inline void instrument_write(const volatile void *v, size_t size) +{ + kasan_check_write(v, size); + kcsan_check_write(v, size); +} + +/** + * instrument_atomic_read - instrument atomic read access + * + * Instrument an atomic read access. The instrumentation should be inserted + * before the actual read happens. + * + * @ptr address of access + * @size size of access + */ +static __always_inline void instrument_atomic_read(const volatile void *v, size_t size) +{ + kasan_check_read(v, size); + kcsan_check_atomic_read(v, size); +} + +/** + * instrument_atomic_write - instrument atomic write access + * + * Instrument an atomic write access. The instrumentation should be inserted + * before the actual write happens. + * + * @ptr address of access + * @size size of access + */ +static __always_inline void instrument_atomic_write(const volatile void *v, size_t size) +{ + kasan_check_write(v, size); + kcsan_check_atomic_write(v, size); +} + +/** + * instrument_copy_to_user_pre - instrument reads of copy_to_user + * + * Instrument reads from kernel memory, that are due to copy_to_user (and + * variants). + * + * The instrumentation must be inserted before the accesses. At this point the + * actual number of bytes accessed is not yet known. + * + * @dst destination address + * @size maximum access size + */ +static __always_inline void +instrument_copy_to_user_pre(const volatile void *src, size_t size) +{ + /* Check before, to warn before potential memory corruption. */ + kasan_check_read(src, size); +} + +/** + * instrument_copy_to_user_post - instrument reads of copy_to_user + * + * Instrument reads from kernel memory, that are due to copy_to_user (and + * variants). + * + * The instrumentation must be inserted after the accesses. At this point the + * actual number of bytes accessed should be known. + * + * @dst destination address + * @size maximum access size + * @left number of bytes left that were not copied + */ +static __always_inline void +instrument_copy_to_user_post(const volatile void *src, size_t size, size_t left) +{ + /* Check after, to avoid false positive if memory was not accessed. */ + kcsan_check_read(src, size - left); +} + +/** + * instrument_copy_from_user_pre - instrument writes of copy_from_user + * + * Instrument writes to kernel memory, that are due to copy_from_user (and + * variants). + * + * The instrumentation must be inserted before the accesses. At this point the + * actual number of bytes accessed is not yet known. + * + * @dst destination address + * @size maximum access size + */ +static __always_inline void +instrument_copy_from_user_pre(const volatile void *dst, size_t size) +{ + /* Check before, to warn before potential memory corruption. */ + kasan_check_write(dst, size); +} + +/** + * instrument_copy_from_user_post - instrument writes of copy_from_user + * + * Instrument writes to kernel memory, that are due to copy_from_user (and + * variants). + * + * The instrumentation must be inserted after the accesses. At this point the + * actual number of bytes accessed should be known. + * + * @dst destination address + * @size maximum access size + * @left number of bytes left that were not copied + */ +static __always_inline void +instrument_copy_from_user_post(const volatile void *dst, size_t size, size_t left) +{ + /* Check after, to avoid false positive if memory was not accessed. */ + kcsan_check_write(dst, size - left); +} + +#endif /* _LINUX_INSTRUMENTED_H */ -- 2.25.0.341.g760bfbb309-goog