Received: by 2002:a05:6a10:af89:0:0:0:0 with SMTP id iu9csp1200357pxb; Fri, 21 Jan 2022 12:06:28 -0800 (PST) X-Google-Smtp-Source: ABdhPJxpcDmfat0wjK7txuMpJnsTQpx/ltGeIfTTChH/XaIVIBL7bcq7aft7/cWaTCnyOmjtzYnb X-Received: by 2002:a17:90b:3510:: with SMTP id ls16mr2216281pjb.229.1642795588615; Fri, 21 Jan 2022 12:06:28 -0800 (PST) ARC-Seal: i=1; a=rsa-sha256; t=1642795588; cv=none; d=google.com; s=arc-20160816; b=rt48FadFXpXTsYsBB7OQJYnvIL5DLyDYWsX2pcJXrviS2/nh6uitqvm7tsTVdW0Fze eUemF/0du9FEnUrdTBqrzrMxeBlfw59teUgrbKwr9ddXyjhF9esSan63gmB9oWeUzxH8 vqikX7BiTa5NmhIoATr/wJAi3wpbliIflaMzB9qvhNBHgC71Qi6KB2zZKyVDM+V1qmZR R3fTfRcT8Hfn43OsWZtYiCKvieNSGoNrXGswiTWGgWcrE56hfhGHdgQG6kyXViRQn3Rc JSPm3dn+/jOOOVJsg04Gbk1GZbxVgnD8VpZOI/FpPLsTTYDof4F8NLGNhdbzNMq0VBkE EetQ== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:content-transfer-encoding:mime-version :message-id:date:subject:cc:to:from:dkim-signature; bh=IqAq4YfC2ZsmP0ilFpWeMztxL8lo/AuAvw8+8Mn3Vgk=; b=Kmf7nWp8YVGqG09lwQ5MxFq28wOj7q8pdlX4gvADPgH/T0imHg/H0XYIx8fvnojeYw AcjV4/KEfrOn7K/OErXgYnRBG4Ub8kHfSVM9OA/8QJSkeyFwRH3niKCp9RMdv1raL4rU p7HRQ8WquSharttLJOPYUa96FGiu3lFelse77/Axct4TNQHotce2Qt8xptXcXldousbm YZtG9FWdPxQqJj6w9VTvY5z6riGf2Y0ahTU5j7HzhNtHmwsI7W2LlXY2PoH+h2XeuuMy GOrAZl0srkwmbNabqd8ozTI7Z8WUfZ4bU+FLEMZ8dn/CZfzoURCjWEq7+cakdh0LEAo6 vj5g== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@intel.com header.s=Intel header.b=TK5ygU+d; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=intel.com Return-Path: Received: from vger.kernel.org (vger.kernel.org. [23.128.96.18]) by mx.google.com with ESMTP id r12si6860968pgb.291.2022.01.21.12.06.16; Fri, 21 Jan 2022 12:06:28 -0800 (PST) Received-SPF: pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) client-ip=23.128.96.18; Authentication-Results: mx.google.com; dkim=pass header.i=@intel.com header.s=Intel header.b=TK5ygU+d; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=intel.com Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S238995AbiASWYM (ORCPT + 99 others); Wed, 19 Jan 2022 17:24:12 -0500 Received: from mga05.intel.com ([192.55.52.43]:56951 "EHLO mga05.intel.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S229902AbiASWYL (ORCPT ); Wed, 19 Jan 2022 17:24:11 -0500 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=intel.com; i=@intel.com; q=dns/txt; s=Intel; t=1642631051; x=1674167051; h=from:to:cc:subject:date:message-id:mime-version: content-transfer-encoding; bh=0pJyoyJAvBdSpCycsxUaxiIERBuyoVK8GZ/qVyHt7Hc=; b=TK5ygU+dWRNVxhHWm6/pC86MugZ81+D9wBJ1YqvC/IvjuTrviaEeT1xV 7yxj5DzZ1qCMRcmILetNG3eUOQVs/LGUX92bshcAhgu0bu35SoOJja1kw tMuFcBMKb0/6IOBg7Uxq42VshtLUB1padEGT2uoAxre8umNvFAtU55yhk X80DZCHB5N1lmiNzsSrGAMZcS+jDd+x0ddTI/wyepmUUFEqJ7hCwHWFiG f34H0YcoAOU6detGzkA+8icuIgXENazLB3vxMzd/IoQpKEnh/TLoGSruA yQEsUPCHNlArrH3gu2eQfcYETeQqg6VZPVp4JMmBzJp0ExAFTaRdhcc+g A==; X-IronPort-AV: E=McAfee;i="6200,9189,10231"; a="331561464" X-IronPort-AV: E=Sophos;i="5.88,300,1635231600"; d="scan'208";a="331561464" Received: from orsmga001.jf.intel.com ([10.7.209.18]) by fmsmga105.fm.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 19 Jan 2022 14:24:04 -0800 X-IronPort-AV: E=Sophos;i="5.88,300,1635231600"; d="scan'208";a="561218570" Received: from rchatre-ws.ostc.intel.com ([10.54.69.144]) by orsmga001-auth.jf.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 19 Jan 2022 14:24:04 -0800 From: Reinette Chatre To: tony.luck@intel.com, dave.hansen@linux.intel.com, jarkko@kernel.org, tglx@linutronix.de, bp@alien8.de, luto@kernel.org, mingo@redhat.com, linux-sgx@vger.kernel.org, x86@kernel.org Cc: linux-kernel@vger.kernel.org Subject: [PATCH V2] x86/sgx: Add poison handling to reclaimer Date: Wed, 19 Jan 2022 14:23:50 -0800 Message-Id: X-Mailer: git-send-email 2.25.1 MIME-Version: 1.0 Content-Transfer-Encoding: 8bit Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org The SGX reclaimer code lacks page poison handling in its main free path. This can lead to avoidable machine checks if a poisoned page is freed and reallocated instead of being isolated. A troublesome scenario is: 1. Machine check (#MC) occurs (asynchronous, !MF_ACTION_REQUIRED) 2. arch_memory_failure() is eventually called 3. (SGX) page->poison set to 1 4. Page is reclaimed 5. Page added to normal free lists by sgx_reclaim_pages() ^ This is the bug (poison pages should be isolated on the sgx_poison_page_list instead) 6. Page is reallocated by some innocent enclave, a second (synchronous) in-kernel #MC is induced, probably during EADD instruction. ^ This is the fallout from the bug (6) is unfortunate and can be avoided by replacing the open coded enclave page freeing code in the reclaimer with sgx_free_epc_page() to obtain support for poison page handling that includes placing the poisoned page on the correct list. Fixes: d6d261bded8a ("x86/sgx: Add new sgx_epc_page flag bit to mark free pages") Fixes: 992801ae9243 ("x86/sgx: Initial poison handling for dirty and free pages") Signed-off-by: Reinette Chatre --- Changes since V1: - V1: https://lore.kernel.org/lkml/ef74bd9548df61f77e802e7505affcfb5159c48c.1642545829.git.reinette.chatre@intel.com/ - Complete rewrite of commit message with significant guidance from Dave who provided the summary as well as troublesome scenario. arch/x86/kernel/cpu/sgx/main.c | 8 +------- 1 file changed, 1 insertion(+), 7 deletions(-) diff --git a/arch/x86/kernel/cpu/sgx/main.c b/arch/x86/kernel/cpu/sgx/main.c index 4b41efc9e367..997a5d0bc488 100644 --- a/arch/x86/kernel/cpu/sgx/main.c +++ b/arch/x86/kernel/cpu/sgx/main.c @@ -418,13 +418,7 @@ static void sgx_reclaim_pages(void) kref_put(&encl_page->encl->refcount, sgx_encl_release); epc_page->flags &= ~SGX_EPC_PAGE_RECLAIMER_TRACKED; - section = &sgx_epc_sections[epc_page->section]; - node = section->node; - - spin_lock(&node->lock); - list_add_tail(&epc_page->list, &node->free_page_list); - spin_unlock(&node->lock); - atomic_long_inc(&sgx_nr_free_pages); + sgx_free_epc_page(epc_page); } } -- 2.25.1