Received: by 2002:a05:6a10:a0d1:0:0:0:0 with SMTP id j17csp562252pxa; Fri, 14 Aug 2020 11:21:59 -0700 (PDT) X-Google-Smtp-Source: ABdhPJzJ5YjsFF0S4GtRh/Ry9szCUUCieVj+vUIJWFspR2ryiC6k/UR/AKQd+AT2jY9EpMK2sl8z X-Received: by 2002:a17:906:7787:: with SMTP id s7mr3785392ejm.533.1597429319509; Fri, 14 Aug 2020 11:21:59 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1597429319; cv=none; d=google.com; s=arc-20160816; b=jzgupMMHysgAAd/PpcADsxNKdKJzNskD8ccAtlcB+S5l+/c8NnmvweHk8iAr4uXM5f mO58WwXTUjiPMS5Rsy5B6hP1YNXHe06mlqY8zz8jMzVFImQGHjzsqfa5CvnmF+WLS/0V TGOXekYZaDa51pWIHTGvcTyfinenvdLbsY+ZXBweDDW02MVaEhlmZdgUjuCPlByScZni +hNWq8yjxjBi1xsGtf7iDLW1mBZOQJlbLu1UipjKdywzCVs7VPEKL6NrKl/Yif4USd6r NmOPPxTNsIkIZmOtjMwZbxokTWAwRreWwL05AjGVWy0kvCvlLG0LMY1MvAycC7cmTtDN 2rGg== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:sender:cc:to:from:subject:references :mime-version:message-id:in-reply-to:date:dkim-signature; bh=zw6ofl64XJvLyRlNnYu73LFjRJ5KYIbvH8mlto9sbqM=; b=yIxo5QxlW+eahP9oZARsI60+t9Te3s8pk/HzPOlx4w1zld00ne7HLYYh/jL9LU6fkw rmvIgasmurKJSt+ANNDutYK2xVp0dYw84o/T04FqBBGsZfYBJVwsOQXYgWjQpnu0yQx9 BqxQWel79JdYtFZb21Nd6DKGy81rpvR3bLbJ+kgfJR/iJHo6NI6mp6S+5BSccNfUKChv AGbfXk0PikPYXgHq0JUBer945Myjy+uLawkTDSe7mClYPUdQapiJ5BlI2/QIutyx5rd7 pp54YwAnhGZPaptdZcxUmm4f6l+KGg6pK2fcvlISRQ2IhVc+h02kiBkln0dws8dsyo8s 5z+g== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@google.com header.s=20161025 header.b="TwBLRF/r"; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=google.com Return-Path: Received: from vger.kernel.org (vger.kernel.org. [23.128.96.18]) by mx.google.com with ESMTP id z15si6111907ejr.110.2020.08.14.11.21.35; Fri, 14 Aug 2020 11:21:59 -0700 (PDT) Received-SPF: pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) client-ip=23.128.96.18; Authentication-Results: mx.google.com; dkim=pass header.i=@google.com header.s=20161025 header.b="TwBLRF/r"; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=google.com Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1728819AbgHNR2l (ORCPT + 99 others); Fri, 14 Aug 2020 13:28:41 -0400 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:37628 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1728468AbgHNR2i (ORCPT ); Fri, 14 Aug 2020 13:28:38 -0400 Received: from mail-wr1-x44a.google.com (mail-wr1-x44a.google.com [IPv6:2a00:1450:4864:20::44a]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id 6DCDEC061384 for ; Fri, 14 Aug 2020 10:28:38 -0700 (PDT) Received: by mail-wr1-x44a.google.com with SMTP id r14so3614359wrq.3 for ; Fri, 14 Aug 2020 10:28:38 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20161025; h=date:in-reply-to:message-id:mime-version:references:subject:from:to :cc; bh=zw6ofl64XJvLyRlNnYu73LFjRJ5KYIbvH8mlto9sbqM=; b=TwBLRF/rbeilcvS01IZuZ8boRDiC6kFFx13ZcBf5v8mBAFeeaqe/K/9g7SUMFB46AN Uk3TL8JI3lrDJkWTbRdOk/fse8WgCD1driXZKcovyFmknL9fbJfj7HcM0bodkOaPLNjv YRgj0eAgN1ZzE63L/sOBlK03Tc53hVXAKv0nTdcuvJLjYv5Fe9+awXM+hfzXUOlkN+Tt GxATPebvj+ViVNh8i62GpbNAhOY1SIqqrmlj2bNxDjuDMwabsP8FSug+OYEp5YnMb8+K IV03rYHAw7C3axHhi+y9R6Qkf95rKcuF51EYLOYQJPFiN8c/xCbObF+CDH1bMwVAYaJq B93A== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:date:in-reply-to:message-id:mime-version :references:subject:from:to:cc; bh=zw6ofl64XJvLyRlNnYu73LFjRJ5KYIbvH8mlto9sbqM=; b=Z9CGX4+Apk2aUnf5n/tAAfiiYXrmnYCjcJMio5h2LPXhY8POKDzQeqT6BpiITZsvvh rFoIUO3dP27xGlYL4ten3psaW7rnYWdLJOnpGoug8huE2E2XN7gqeLjHrwFPai0aFwzR VtceO9luboPwDhkfKXOqhYvvw5Nlo63YoI9p5KyP5RgVLkoCkkpo3rttLlN3oTFDY4Pq 7rtGiSqkuv1AODmeK0BKhilGY8Qd1UVb1Fez9BhWaQRKz4BLuF6oYAp1YVgF08m+YmGu H5xcoTq2MdrCLxpAA7glvSeBCB3j/Ia9T+N/OjkB0VqMaUXbfkeH3JDSFHTIV/u3irj6 X07w== X-Gm-Message-State: AOAM5304SaJHRroR26g6YxQvrmd/ABZ1n6iY0GB9Gg4ePiuNbv0tNCe7 Q8If7RFcAZ6Yfcvu52qvFHPfcX/NnJophv7H X-Received: by 2002:adf:97d3:: with SMTP id t19mr3454793wrb.138.1597426117123; Fri, 14 Aug 2020 10:28:37 -0700 (PDT) Date: Fri, 14 Aug 2020 19:27:13 +0200 In-Reply-To: Message-Id: <4e86d422f930831666137e06a71dff4a7a16a5cd.1597425745.git.andreyknvl@google.com> Mime-Version: 1.0 References: X-Mailer: git-send-email 2.28.0.220.ged08abb693-goog Subject: [PATCH 31/35] kasan, arm64: implement HW_TAGS runtime From: Andrey Konovalov To: Dmitry Vyukov , Vincenzo Frascino , Catalin Marinas , kasan-dev@googlegroups.com Cc: Andrey Ryabinin , Alexander Potapenko , Marco Elver , Evgenii Stepanov , Elena Petrova , Branislav Rankov , Kevin Brodsky , Will Deacon , Andrew Morton , linux-arm-kernel@lists.infradead.org, linux-mm@kvack.org, linux-kernel@vger.kernel.org, Andrey Konovalov Content-Type: text/plain; charset="UTF-8" Sender: linux-kernel-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org Provide implementation of KASAN functions required for the hardware tag-based mode. Those include core functions for memory and pointer tagging (mte.c) and bug reporting (report_mte.c). Also adapt common KASAN code to support the new mode. Signed-off-by: Andrey Konovalov --- arch/arm64/include/asm/memory.h | 4 +- arch/arm64/kernel/setup.c | 1 - include/linux/kasan.h | 6 +-- include/linux/mm.h | 2 +- include/linux/page-flags-layout.h | 2 +- mm/kasan/Makefile | 5 ++ mm/kasan/common.c | 14 +++--- mm/kasan/kasan.h | 17 +++++-- mm/kasan/mte.c | 76 +++++++++++++++++++++++++++++++ mm/kasan/report_mte.c | 47 +++++++++++++++++++ mm/kasan/shadow.c | 2 +- 11 files changed, 158 insertions(+), 18 deletions(-) create mode 100644 mm/kasan/mte.c create mode 100644 mm/kasan/report_mte.c diff --git a/arch/arm64/include/asm/memory.h b/arch/arm64/include/asm/memory.h index 8881849929e3..433341acf3f3 100644 --- a/arch/arm64/include/asm/memory.h +++ b/arch/arm64/include/asm/memory.h @@ -214,7 +214,7 @@ static inline unsigned long kaslr_offset(void) (__force __typeof__(addr))__addr; \ }) -#ifdef CONFIG_KASAN_SW_TAGS +#if defined(CONFIG_KASAN_SW_TAGS) || defined(CONFIG_KASAN_HW_TAGS) #define __tag_shifted(tag) ((u64)(tag) << 56) #define __tag_reset(addr) __untagged_addr(addr) #define __tag_get(addr) (__u8)((u64)(addr) >> 56) @@ -222,7 +222,7 @@ static inline unsigned long kaslr_offset(void) #define __tag_shifted(tag) 0UL #define __tag_reset(addr) (addr) #define __tag_get(addr) 0 -#endif /* CONFIG_KASAN_SW_TAGS */ +#endif /* CONFIG_KASAN_SW_TAGS || CONFIG_KASAN_HW_TAGS */ static inline const void *__tag_set(const void *addr, u8 tag) { diff --git a/arch/arm64/kernel/setup.c b/arch/arm64/kernel/setup.c index 575da075a2b9..4bee6e70eef4 100644 --- a/arch/arm64/kernel/setup.c +++ b/arch/arm64/kernel/setup.c @@ -352,7 +352,6 @@ void __init __no_sanitize_address setup_arch(char **cmdline_p) smp_init_cpus(); smp_build_mpidr_hash(); - /* Init percpu seeds for random tags after cpus are set up. */ kasan_init_tags(); #ifdef CONFIG_ARM64_SW_TTBR0_PAN diff --git a/include/linux/kasan.h b/include/linux/kasan.h index 875bbcedd994..613c9d38eee5 100644 --- a/include/linux/kasan.h +++ b/include/linux/kasan.h @@ -184,7 +184,7 @@ static inline void kasan_record_aux_stack(void *ptr) {} #endif /* CONFIG_KASAN_GENERIC */ -#ifdef CONFIG_KASAN_SW_TAGS +#if defined(CONFIG_KASAN_SW_TAGS) || defined(CONFIG_KASAN_HW_TAGS) void kasan_init_tags(void); @@ -193,7 +193,7 @@ void *kasan_reset_tag(const void *addr); bool kasan_report(unsigned long addr, size_t size, bool is_write, unsigned long ip); -#else /* CONFIG_KASAN_SW_TAGS */ +#else /* CONFIG_KASAN_SW_TAGS || CONFIG_KASAN_HW_TAGS */ static inline void kasan_init_tags(void) { } @@ -202,7 +202,7 @@ static inline void *kasan_reset_tag(const void *addr) return (void *)addr; } -#endif /* CONFIG_KASAN_SW_TAGS */ +#endif /* CONFIG_KASAN_SW_TAGS || CONFIG_KASAN_HW_TAGS*/ #ifdef CONFIG_KASAN_VMALLOC diff --git a/include/linux/mm.h b/include/linux/mm.h index 65cbbfaa739b..94581f82c1b3 100644 --- a/include/linux/mm.h +++ b/include/linux/mm.h @@ -1395,7 +1395,7 @@ static inline bool cpupid_match_pid(struct task_struct *task, int cpupid) } #endif /* CONFIG_NUMA_BALANCING */ -#ifdef CONFIG_KASAN_SW_TAGS +#if defined(CONFIG_KASAN_SW_TAGS) || defined(CONFIG_KASAN_HW_TAGS) static inline u8 page_kasan_tag(const struct page *page) { return (page->flags >> KASAN_TAG_PGSHIFT) & KASAN_TAG_MASK; diff --git a/include/linux/page-flags-layout.h b/include/linux/page-flags-layout.h index 71283739ffd2..75945732a58b 100644 --- a/include/linux/page-flags-layout.h +++ b/include/linux/page-flags-layout.h @@ -77,7 +77,7 @@ #define LAST_CPUPID_SHIFT 0 #endif -#ifdef CONFIG_KASAN_SW_TAGS +#if defined(CONFIG_KASAN_SW_TAGS) || defined(CONFIG_KASAN_HW_TAGS) #define KASAN_TAG_WIDTH 8 #else #define KASAN_TAG_WIDTH 0 diff --git a/mm/kasan/Makefile b/mm/kasan/Makefile index 007c824f6f43..182095c6af28 100644 --- a/mm/kasan/Makefile +++ b/mm/kasan/Makefile @@ -10,9 +10,11 @@ CFLAGS_REMOVE_init.o = $(CC_FLAGS_FTRACE) CFLAGS_REMOVE_quarantine.o = $(CC_FLAGS_FTRACE) CFLAGS_REMOVE_report.o = $(CC_FLAGS_FTRACE) CFLAGS_REMOVE_report_generic.o = $(CC_FLAGS_FTRACE) +CFLAGS_REMOVE_report_mte.o = $(CC_FLAGS_FTRACE) CFLAGS_REMOVE_report_tags.o = $(CC_FLAGS_FTRACE) CFLAGS_REMOVE_shadow.o = $(CC_FLAGS_FTRACE) CFLAGS_REMOVE_tags.o = $(CC_FLAGS_FTRACE) +CFLAGS_REMOVE_mte.o = $(CC_FLAGS_FTRACE) # Function splitter causes unnecessary splits in __asan_load1/__asan_store1 # see: https://gcc.gnu.org/bugzilla/show_bug.cgi?id=63533 @@ -27,10 +29,13 @@ CFLAGS_init.o := $(CC_FLAGS_KASAN_RUNTIME) CFLAGS_quarantine.o := $(CC_FLAGS_KASAN_RUNTIME) CFLAGS_report.o := $(CC_FLAGS_KASAN_RUNTIME) CFLAGS_report_generic.o := $(CC_FLAGS_KASAN_RUNTIME) +CFLAGS_report_mte.o := $(CC_FLAGS_KASAN_RUNTIME) CFLAGS_report_tags.o := $(CC_FLAGS_KASAN_RUNTIME) CFLAGS_shadow.o := $(CC_FLAGS_KASAN_RUNTIME) CFLAGS_tags.o := $(CC_FLAGS_KASAN_RUNTIME) +CFLAGS_mte.o := $(CC_FLAGS_KASAN_RUNTIME) obj-$(CONFIG_KASAN) := common.o report.o obj-$(CONFIG_KASAN_GENERIC) += init.o generic.o report_generic.o shadow.o quarantine.o obj-$(CONFIG_KASAN_SW_TAGS) += init.o report_tags.o shadow.o tags.o +obj-$(CONFIG_KASAN_HW_TAGS) += mte.o report_mte.o diff --git a/mm/kasan/common.c b/mm/kasan/common.c index 41c7f1105eaa..412a23d1546b 100644 --- a/mm/kasan/common.c +++ b/mm/kasan/common.c @@ -118,7 +118,7 @@ void kasan_free_pages(struct page *page, unsigned int order) */ static inline unsigned int optimal_redzone(unsigned int object_size) { - if (IS_ENABLED(CONFIG_KASAN_SW_TAGS)) + if (!IS_ENABLED(CONFIG_KASAN_GENERIC)) return 0; return @@ -183,14 +183,14 @@ size_t kasan_metadata_size(struct kmem_cache *cache) struct kasan_alloc_meta *get_alloc_info(struct kmem_cache *cache, const void *object) { - return (void *)object + cache->kasan_info.alloc_meta_offset; + return (void *)reset_tag(object) + cache->kasan_info.alloc_meta_offset; } struct kasan_free_meta *get_free_info(struct kmem_cache *cache, const void *object) { BUILD_BUG_ON(sizeof(struct kasan_free_meta) > 32); - return (void *)object + cache->kasan_info.free_meta_offset; + return (void *)reset_tag(object) + cache->kasan_info.free_meta_offset; } void kasan_poison_slab(struct page *page) @@ -272,7 +272,8 @@ void * __must_check kasan_init_slab_obj(struct kmem_cache *cache, alloc_info = get_alloc_info(cache, object); __memset(alloc_info, 0, sizeof(*alloc_info)); - if (IS_ENABLED(CONFIG_KASAN_SW_TAGS)) + if (IS_ENABLED(CONFIG_KASAN_SW_TAGS) || + IS_ENABLED(CONFIG_KASAN_HW_TAGS)) object = set_tag(object, assign_tag(cache, object, true, false)); @@ -342,10 +343,11 @@ static void *__kasan_kmalloc(struct kmem_cache *cache, const void *object, redzone_end = round_up((unsigned long)object + cache->object_size, KASAN_GRANULE_SIZE); - if (IS_ENABLED(CONFIG_KASAN_SW_TAGS)) + if (IS_ENABLED(CONFIG_KASAN_SW_TAGS) || + IS_ENABLED(CONFIG_KASAN_HW_TAGS)) tag = assign_tag(cache, object, false, keep_tag); - /* Tag is ignored in set_tag without CONFIG_KASAN_SW_TAGS */ + /* Tag is ignored in set_tag without CONFIG_KASAN_SW/HW_TAGS */ kasan_unpoison_memory(set_tag(object, tag), size); kasan_poison_memory((void *)redzone_start, redzone_end - redzone_start, KASAN_KMALLOC_REDZONE); diff --git a/mm/kasan/kasan.h b/mm/kasan/kasan.h index 4d8e229f8e01..bc56cf8b9c48 100644 --- a/mm/kasan/kasan.h +++ b/mm/kasan/kasan.h @@ -152,6 +152,10 @@ struct kasan_alloc_meta *get_alloc_info(struct kmem_cache *cache, struct kasan_free_meta *get_free_info(struct kmem_cache *cache, const void *object); +void kasan_poison_memory(const void *address, size_t size, u8 value); + +#if defined(CONFIG_KASAN_GENERIC) || defined(CONFIG_KASAN_SW_TAGS) + static inline const void *kasan_shadow_to_mem(const void *shadow_addr) { return (void *)(((unsigned long)shadow_addr - KASAN_SHADOW_OFFSET) @@ -163,8 +167,6 @@ static inline bool addr_has_metadata(const void *addr) return (addr >= kasan_shadow_to_mem((void *)KASAN_SHADOW_START)); } -void kasan_poison_memory(const void *address, size_t size, u8 value); - /** * check_memory_region - Check memory region, and report if invalid access. * @addr: the accessed address @@ -176,6 +178,15 @@ void kasan_poison_memory(const void *address, size_t size, u8 value); bool check_memory_region(unsigned long addr, size_t size, bool write, unsigned long ret_ip); +#else /* CONFIG_KASAN_GENERIC || CONFIG_KASAN_SW_TAGS */ + +static inline bool addr_has_metadata(const void *addr) +{ + return true; +} + +#endif /* CONFIG_KASAN_GENERIC || CONFIG_KASAN_SW_TAGS */ + bool check_invalid_free(void *addr); void *find_first_bad_addr(void *addr, size_t size); @@ -212,7 +223,7 @@ static inline void quarantine_reduce(void) { } static inline void quarantine_remove_cache(struct kmem_cache *cache) { } #endif -#ifdef CONFIG_KASAN_SW_TAGS +#if defined(CONFIG_KASAN_SW_TAGS) || defined(CONFIG_KASAN_HW_TAGS) void print_tags(u8 addr_tag, const void *addr); diff --git a/mm/kasan/mte.c b/mm/kasan/mte.c new file mode 100644 index 000000000000..43b7d74161e5 --- /dev/null +++ b/mm/kasan/mte.c @@ -0,0 +1,76 @@ +// SPDX-License-Identifier: GPL-2.0 +/* + * This file contains hardware tag-based (MTE-based) KASAN code. + * + * Copyright (c) 2020 Google, Inc. + * Author: Andrey Konovalov + * + * This program is free software; you can redistribute it and/or modify + * it under the terms of the GNU General Public License version 2 as + * published by the Free Software Foundation. + * + */ + +#include +#include +#include +#include +#include +#include + +#include "kasan.h" + +void kasan_init_tags(void) +{ + mte_init_tags(KASAN_TAG_MAX); +} + +void *kasan_reset_tag(const void *addr) +{ + return reset_tag(addr); +} + +void kasan_poison_memory(const void *address, size_t size, u8 value) +{ + mte_set_mem_tag_range(reset_tag(address), size, value); +} + +void kasan_unpoison_memory(const void *address, size_t size) +{ + mte_set_mem_tag_range(reset_tag(address), size, get_tag(address)); +} + +u8 random_tag(void) +{ + return mte_get_random_tag(); +} + +bool check_invalid_free(void *addr) +{ + u8 ptr_tag = get_tag(addr); + u8 mem_tag = mte_get_mem_tag(addr); + + if (mem_tag == KASAN_TAG_INVALID) + return true; + if (ptr_tag != KASAN_TAG_KERNEL && ptr_tag != mem_tag) + return true; + return false; +} + +void kasan_set_free_info(struct kmem_cache *cache, + void *object, u8 tag) +{ + struct kasan_alloc_meta *alloc_meta; + + alloc_meta = get_alloc_info(cache, object); + kasan_set_track(&alloc_meta->free_track[0], GFP_NOWAIT); +} + +struct kasan_track *kasan_get_free_track(struct kmem_cache *cache, + void *object, u8 tag) +{ + struct kasan_alloc_meta *alloc_meta; + + alloc_meta = get_alloc_info(cache, object); + return &alloc_meta->free_track[0]; +} diff --git a/mm/kasan/report_mte.c b/mm/kasan/report_mte.c new file mode 100644 index 000000000000..dbbf3aaa8798 --- /dev/null +++ b/mm/kasan/report_mte.c @@ -0,0 +1,47 @@ +// SPDX-License-Identifier: GPL-2.0 +/* + * This file contains Hardware Tag-Based (MTE-based) KASAN code. + * + * Copyright (c) 2020 Google, Inc. + * Author: Andrey Konovalov + * + * This program is free software; you can redistribute it and/or modify + * it under the terms of the GNU General Public License version 2 as + * published by the Free Software Foundation. + * + */ + +#include +#include +#include +#include +#include +#include + +#include "kasan.h" + +const char *get_bug_type(struct kasan_access_info *info) +{ + return "invalid-access"; +} + +void *find_first_bad_addr(void *addr, size_t size) +{ + return reset_tag(addr); +} + +void metadata_fetch_row(char *buffer, void *row) +{ + int i; + + for (i = 0; i < META_BYTES_PER_ROW; i++) + buffer[i] = mte_get_mem_tag(row + i * KASAN_GRANULE_SIZE); +} + +void print_tags(u8 addr_tag, const void *addr) +{ + u8 memory_tag = mte_get_mem_tag((void *)addr); + + pr_err("Pointer tag: [%02x], memory tag: [%02x]\n", + addr_tag, memory_tag); +} diff --git a/mm/kasan/shadow.c b/mm/kasan/shadow.c index 4888084ecdfc..ca69726adf8f 100644 --- a/mm/kasan/shadow.c +++ b/mm/kasan/shadow.c @@ -111,7 +111,7 @@ void kasan_unpoison_memory(const void *address, size_t size) if (IS_ENABLED(CONFIG_KASAN_SW_TAGS)) *shadow = tag; - else + else /* CONFIG_KASAN_GENERIC */ *shadow = size & KASAN_GRANULE_MASK; } } -- 2.28.0.220.ged08abb693-goog