Received: by 2002:a05:6a10:2785:0:0:0:0 with SMTP id ia5csp440055pxb; Thu, 14 Jan 2021 09:27:43 -0800 (PST) X-Google-Smtp-Source: ABdhPJxPFXQRZ4yDAYzQu9c6qpITOFol7gGi2bRPyAkLpsjsp7oXWWMZ6bVsbkVz3REJHHG5zyta X-Received: by 2002:a05:6402:b88:: with SMTP id cf8mr6793241edb.140.1610645263642; Thu, 14 Jan 2021 09:27:43 -0800 (PST) ARC-Seal: i=1; a=rsa-sha256; t=1610645263; cv=none; d=google.com; s=arc-20160816; b=PSvHbWRJFPpTYdSbJ7dXOEHRpN4LI6eyGoh+WSj6wpIbGkQD1CDIaaIhE526p28LIJ Cm6er7s0HTQYOGHTqNt3yYjG4t6qmXvtAfzct61xElWaa2aHMsYEJw9N9Gn0rvBWmW56 Zy2Hs+Qjgss4e8e6nFzZ17+g2o8kfG29CinjH6iD4+SrI0aR0kEP4T22LT7/vbZVjkFi 6IkHP8IkqWZZatq1F2Isa0F39lFy2ct1PsB2Kgzai/CdwFnEBIz1nHdV50Fc2K3io0jA iGtxMNAqO4r7bhUWne1pQaOKFNXfWY12BRADHBVQz3O2qHUI4EzzXKEX6zkFCgew3Po6 CL9w== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:cc:to:from:subject:references:mime-version :message-id:in-reply-to:date:sender:dkim-signature; bh=xV+/a2Rp5lRcHlFRCafjdMqZdknib/NjGfl4/F+eUSQ=; b=lJYCN0giCdzCfDUNAITIvyIOe+OjBs3xMIU5pR86pvUqXaAjWI9NOUCLeq9wi5Q/jP HYYirnV5RhEuI61RwxuLggGYtWKnWqmMCvqBsAB1s4WVcUG+FD+U/V5waIGCr5OaFlCk J6vLjg1xAtPSMGRc77ff6K7zakr/HpJQ8nf/H/6N3G9yUvjfoEGBcuWzCmnZca5fmApm Auil1WYf/s0snCybu6j9I7h3RdBKTz6OWBTP2+PoEPq09TNWF/5L5TgBUW3gb2oH5EaV ngWCdlb0Pp6CnzmIo/7vzcZTEjoW9bTDk3Es1wJR5pd2X+vmBUmDA0qrLu7iMKxkwidg Z5fQ== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@google.com header.s=20161025 header.b=RHWeCTmF; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=google.com Return-Path: Received: from vger.kernel.org (vger.kernel.org. [23.128.96.18]) by mx.google.com with ESMTP id v4si3279749edi.191.2021.01.14.09.27.19; Thu, 14 Jan 2021 09:27:43 -0800 (PST) Received-SPF: pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) client-ip=23.128.96.18; Authentication-Results: mx.google.com; dkim=pass header.i=@google.com header.s=20161025 header.b=RHWeCTmF; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=google.com Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1728491AbhANRZY (ORCPT + 99 others); Thu, 14 Jan 2021 12:25:24 -0500 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:46492 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1725935AbhANRZX (ORCPT ); Thu, 14 Jan 2021 12:25:23 -0500 Received: from mail-qv1-xf49.google.com (mail-qv1-xf49.google.com [IPv6:2607:f8b0:4864:20::f49]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id 0E90BC0613C1 for ; Thu, 14 Jan 2021 09:24:43 -0800 (PST) Received: by mail-qv1-xf49.google.com with SMTP id t17so5114723qvv.17 for ; Thu, 14 Jan 2021 09:24:43 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20161025; h=sender:date:in-reply-to:message-id:mime-version:references:subject :from:to:cc; bh=xV+/a2Rp5lRcHlFRCafjdMqZdknib/NjGfl4/F+eUSQ=; b=RHWeCTmFFlh0JG7mSrwt1xtK3BPDcF/hNwHiBSWk2tm3duHiYAEvtevj2/GAO5f869 2m3HICWqldEJ2EfhWZYJCnQAAWHfwp4TUOTERQqiZTnMzKq4FXSuSlHKsQCkxaLo5kyJ JZVSqwaPfHYu/kDGisDgA7beJwN0XcGGRgTpC4koHF1IBZ6E1aV1zcU2X2ozQZL+hprg GrABIORMdgZx5+EJ9vs7hqClA49Ey+lSP3BmQz4bubQJKTHQ36oAAVVxJ3tegF17coOb T9ZgM+wBKsYD90vhlOkPfEgk6gcyTQJ+48x4N36NaoN+BBBZ8562dlxSZD1b5nMk/z5w cP2A== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:sender:date:in-reply-to:message-id:mime-version :references:subject:from:to:cc; bh=xV+/a2Rp5lRcHlFRCafjdMqZdknib/NjGfl4/F+eUSQ=; b=IifsIz/3uGrx5Wvkm4rjaxwiXL/xZ9qMcHfPckviMKQU63NwyjBo/q1nEBN3ubpayq x551Q/athCVr6QEqP3Do1bcV4gDcmioGjU3hJ9kCVEye77ue+azShe5jgjd3x3jTa+Wa WFxXQ3o3xZgz3ZxWVVZwgyWtdGD0RqWD/qegzHoaxKqIZyMAdhw/BHQdGNP+KPXfgnVX 7SRm4T66uV6H+6N7zYKcPqDr0f/DhfaXq4e7w9uACqjQRrTXiWFQYaFnpGqAKfcFXdx2 Hi61uxZN1mmdagLusfa9JvaWqgr7UXF11cTS+p+KPO9U+6j7cWKnHJHOLIT0wYNV6f7s eYCQ== X-Gm-Message-State: AOAM532/Urd8wcdcV0PqigvbIji3t0IUkiJFVHSAfR6lEcin/rO0+15v cYSabanDJ4FCUbNRRmA7Z/vSv9b58wDH Sender: "lenaptr via sendgmr" X-Received: from beef.c.googlers.com ([fda3:e722:ac3:cc00:28:9cb1:c0a8:1091]) (user=lenaptr job=sendgmr) by 2002:a0c:a789:: with SMTP id v9mr7957944qva.41.1610645082204; Thu, 14 Jan 2021 09:24:42 -0800 (PST) Date: Thu, 14 Jan 2021 17:23:33 +0000 In-Reply-To: <20210114172338.2798389-1-lenaptr@google.com> Message-Id: <20210114172338.2798389-4-lenaptr@google.com> Mime-Version: 1.0 References: <20210114172338.2798389-1-lenaptr@google.com> X-Mailer: git-send-email 2.30.0.284.gd98b1dd5eaa7-goog Subject: [PATCH v2 3/9] KVM: arm64: Enable UBSAN_BOUNDS for the both the kernel and hyp/nVHE From: Elena Petrova To: kvmarm@lists.cs.columbia.edu Cc: Elena Petrova , linux-arm-kernel@lists.infradead.org, open list , Marc Zyngier , James Morse , Julien Thierry , Suzuki K Poulose , George Popescu , George Popescu Content-Type: text/plain; charset="UTF-8" Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org From: George Popescu If an out of bounds happens inside the hyp/nVHE code, the ubsan_out_of_bounds handler stores the logging data inside the kvm_ubsan_buffer. The one responsible for printing is the kernel ubsan_out_of_bounds handler. The process of decapsulating the data from the buffer is straightforward. Signed-off-by: George Popescu Signed-off-by: Elena Petrova --- arch/arm64/include/asm/kvm_ubsan.h | 19 ++++++++++++++++++- arch/arm64/kvm/hyp/nvhe/ubsan.c | 14 ++++++++++++-- arch/arm64/kvm/kvm_ubsan_buffer.c | 10 ++++++++++ 3 files changed, 40 insertions(+), 3 deletions(-) diff --git a/arch/arm64/include/asm/kvm_ubsan.h b/arch/arm64/include/asm/kvm_ubsan.h index fb32c7fd65d4..4f471acb88b0 100644 --- a/arch/arm64/include/asm/kvm_ubsan.h +++ b/arch/arm64/include/asm/kvm_ubsan.h @@ -9,6 +9,23 @@ #define UBSAN_MAX_TYPE 6 #define KVM_UBSAN_BUFFER_SIZE 1000 + +struct ubsan_values { + void *lval; + void *rval; + char op; +}; + struct kvm_ubsan_info { - int type; + enum { + UBSAN_OUT_OF_BOUNDS, + } type; + union { + struct out_of_bounds_data out_of_bounds_data; + }; + union { + struct ubsan_values u_val; + }; }; + +void __ubsan_handle_out_of_bounds(void *_data, void *index); diff --git a/arch/arm64/kvm/hyp/nvhe/ubsan.c b/arch/arm64/kvm/hyp/nvhe/ubsan.c index 8a194fb1f6cf..55a8f6db8555 100644 --- a/arch/arm64/kvm/hyp/nvhe/ubsan.c +++ b/arch/arm64/kvm/hyp/nvhe/ubsan.c @@ -13,7 +13,6 @@ #include #include #include -#include DEFINE_KVM_DEBUG_BUFFER(struct kvm_ubsan_info, kvm_ubsan_buffer, kvm_ubsan_buff_wr_ind, KVM_UBSAN_BUFFER_SIZE); @@ -44,7 +43,18 @@ void __ubsan_handle_type_mismatch(struct type_mismatch_data *data, void *ptr) {} void __ubsan_handle_type_mismatch_v1(void *_data, void *ptr) {} -void __ubsan_handle_out_of_bounds(void *_data, void *index) {} +void __ubsan_handle_out_of_bounds(void *_data, void *index) +{ + struct kvm_ubsan_info *slot; + struct out_of_bounds_data *data = _data; + + slot = kvm_ubsan_buffer_next_slot(); + if (slot) { + slot->type = UBSAN_OUT_OF_BOUNDS; + slot->out_of_bounds_data = *data; + slot->u_val.lval = index; + } +} void __ubsan_handle_shift_out_of_bounds(void *_data, void *lhs, void *rhs) {} diff --git a/arch/arm64/kvm/kvm_ubsan_buffer.c b/arch/arm64/kvm/kvm_ubsan_buffer.c index 4a1959ba9f68..a1523f86be3c 100644 --- a/arch/arm64/kvm/kvm_ubsan_buffer.c +++ b/arch/arm64/kvm/kvm_ubsan_buffer.c @@ -17,6 +17,15 @@ DECLARE_KVM_DEBUG_BUFFER(struct kvm_ubsan_info, kvm_ubsan_buffer, kvm_ubsan_buff_wr_ind, KVM_UBSAN_BUFFER_SIZE); +void __kvm_check_ubsan_data(struct kvm_ubsan_info *slot) +{ + switch (slot->type) { + case UBSAN_OUT_OF_BOUNDS: + __ubsan_handle_out_of_bounds(&slot->out_of_bounds_data, + slot->u_val.lval); + break; + } +} void iterate_kvm_ubsan_buffer(unsigned long left, unsigned long right) { @@ -26,6 +35,7 @@ void iterate_kvm_ubsan_buffer(unsigned long left, unsigned long right) slot = (struct kvm_ubsan_info *) this_cpu_ptr_nvhe_sym(kvm_ubsan_buffer); for (i = left; i < right; ++i) { /* check ubsan data */ + __kvm_check_ubsan_data(slot + i); slot[i].type = 0; } } -- 2.30.0.284.gd98b1dd5eaa7-goog