Received: by 2002:a05:6358:e9c4:b0:b2:91dc:71ab with SMTP id hc4csp6292764rwb; Tue, 9 Aug 2022 12:33:06 -0700 (PDT) X-Google-Smtp-Source: AA6agR6qjKrHMu1SMrr4XbukJ7CC+lrSO5tuotwqpoItR5WlCIWNAtVpQAzBM3bBchYRlqzuF8Yy X-Received: by 2002:a05:6402:270e:b0:43d:e3e1:847a with SMTP id y14-20020a056402270e00b0043de3e1847amr23463922edd.130.1660073585949; Tue, 09 Aug 2022 12:33:05 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1660073585; cv=none; d=google.com; s=arc-20160816; b=N3qp9Xdrkg+/9pbWbBr9W/pQ05T9Z3l+KHt9JK+hS043PJmx+x2FfZhAtWzdXXekqk 9Z/0H5glD+6/e1dw5B5+YVKiR9HJu92ulWY3AWz/g4g1umHIK3Ln8hk0nzFo6pZuIT5A nc2HL+iOCb9iMpL8quSR27EnjnMBAnNwQSwaLDhBr/KsyJeTPI6Uwnq3z+8glK7ReIRm meHouvaENXBCPcggSVSkHS4CUpy9td9xpmJKrljbG6n+vP1nsCXak15TI0oh/C5cGm0o jVIIRhJ0U8LOwGeCq9NG9W9qvvUtkxxRQl1olTH8lSliNVZv6jCLShyzAVN3zYGJl3bO iDuA== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:content-transfer-encoding:in-reply-to:subject :organization:from:references:cc:to:content-language:user-agent :mime-version:date:message-id:dkim-signature; bh=H8h4Jng7BDnvUHW4yaisoTMe84LTGwEUPKezp1k3H30=; b=M1AvI87qQkRU33pQUr6j7EH7OwWL9kYxg4FBa5O2G5uI+q+2q972bsITUbz2WYPsei wsD5bDWXem8/s1/Jxo/8ewOucdmG05h1Mms4nWcNdCuprON/sv/1NvPuW+dmxPbJ2bkn MhJiy60UgJDg56G3Y2qQJ933NimNGjaD3+7JiaLotAw0E0TGchp56aMrjNSkMqUz3WPV 4H9UoTXcwXRP2I77kpVrWXrbeOKEH/MiM69TbRciPrhAYCc5Nitk5mkIY7vjtljrGz3Z TGRFsDUFf/kTtEN4VHGmJs6hOn9W8UEnm45e71FdW9eCpFFIIpZi3muXUwj9kCZI6+d0 lTbg== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@redhat.com header.s=mimecast20190719 header.b=J0kGOSKX; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=redhat.com Return-Path: Received: from out1.vger.email (out1.vger.email. [2620:137:e000::1:20]) by mx.google.com with ESMTP id sh7-20020a1709076e8700b00731745a7f05si2840662ejc.275.2022.08.09.12.32.40; Tue, 09 Aug 2022 12:33:05 -0700 (PDT) Received-SPF: pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) client-ip=2620:137:e000::1:20; Authentication-Results: mx.google.com; dkim=pass header.i=@redhat.com header.s=mimecast20190719 header.b=J0kGOSKX; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=redhat.com Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S245737AbiHITV7 (ORCPT + 99 others); Tue, 9 Aug 2022 15:21:59 -0400 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:54022 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1346493AbiHITU7 (ORCPT ); Tue, 9 Aug 2022 15:20:59 -0400 Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.129.124]) by lindbergh.monkeyblade.net (Postfix) with ESMTP id 4A3935FCF for ; Tue, 9 Aug 2022 12:20:47 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1660072846; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=H8h4Jng7BDnvUHW4yaisoTMe84LTGwEUPKezp1k3H30=; b=J0kGOSKXC3bYfAiCQnGXAybxgW0RoKD4wECnKh1Y4qT7E7HY/yf8+uGohOAhCZYjNhVQ+g HSs5D7esNxJIp4Bp++PIL9YVCz9qF4KgPu+N3u0ecqqA1dh/6HxnJ2hbPSFVyKqHEm3+3O 61LIAuLfsvkMkAreNxG1NOchDO2q1ws= Received: from mail-wm1-f71.google.com (mail-wm1-f71.google.com [209.85.128.71]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id us-mta-607-iSq3nYQkMkCs56pZPxQf6A-1; Tue, 09 Aug 2022 15:20:45 -0400 X-MC-Unique: iSq3nYQkMkCs56pZPxQf6A-1 Received: by mail-wm1-f71.google.com with SMTP id v64-20020a1cac43000000b003a4bea31b4dso10287183wme.3 for ; Tue, 09 Aug 2022 12:20:45 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20210112; h=content-transfer-encoding:in-reply-to:subject:organization:from :references:cc:to:content-language:user-agent:mime-version:date :message-id:x-gm-message-state:from:to:cc; bh=H8h4Jng7BDnvUHW4yaisoTMe84LTGwEUPKezp1k3H30=; b=10su4sryCDc/YFnAMQmL51pBejKgArueRfG5kY3t5vSJHjwICZ29pkFvTHPqaY2vi/ mMzeCf9kmz+tLQpYpSuuhVAvQ4dAapZMyovKKe2ugX+1dB16ZfYTlB67OcybKH1xxaov z/dYIaTtzk4Mbd1xJdCa7OWas0VUhwy1Imhr7GfnoF2zB1Q4X9cU6lMGFwmfeiVCBtxj nk5+Si/WB7GkgFMfNicor/KbwONgHYyGjQQD8GUkF9a+5QtKqGR/Z25mqAZ5B8F158hy XbF1Q0RN8VMXkN5kG7zJG7lALTWvXOEVqB7ecw6npFvUWQWOfLr4zGx0w6TuepUr8ufW mBzg== X-Gm-Message-State: ACgBeo1zzgtm4RwgrmVFyRPtfXAflfevbwDOOCizo0L3tvoJOPa3ZrUr +z7KqAX3Cm0iF/N1Kt+Gjm41lnbPcbmPrLTGl0KWRrZ72k88a50LblkeaOn5J4x1s6DxhTNca0y YC+Ldaa05Nr7we0d5aRbCqYV7 X-Received: by 2002:a1c:ed05:0:b0:3a2:ebae:c5e7 with SMTP id l5-20020a1ced05000000b003a2ebaec5e7mr15509wmh.78.1660072844097; Tue, 09 Aug 2022 12:20:44 -0700 (PDT) X-Received: by 2002:a1c:ed05:0:b0:3a2:ebae:c5e7 with SMTP id l5-20020a1ced05000000b003a2ebaec5e7mr15496wmh.78.1660072843868; Tue, 09 Aug 2022 12:20:43 -0700 (PDT) Received: from ?IPV6:2003:cb:c705:3700:aed2:a0f8:c270:7f30? (p200300cbc7053700aed2a0f8c2707f30.dip0.t-ipconnect.de. [2003:cb:c705:3700:aed2:a0f8:c270:7f30]) by smtp.gmail.com with ESMTPSA id q25-20020a1ce919000000b003a32251c3f0sm17052196wmc.33.2022.08.09.12.20.43 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Tue, 09 Aug 2022 12:20:43 -0700 (PDT) Message-ID: <5593cbb7-eb29-82f0-490e-dd72ceafff9b@redhat.com> Date: Tue, 9 Aug 2022 21:20:42 +0200 MIME-Version: 1.0 User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:91.0) Gecko/20100101 Thunderbird/91.11.0 Content-Language: en-US To: Linus Torvalds , Jason Gunthorpe Cc: linux-kernel@vger.kernel.org, linux-mm@kvack.org, stable@vger.kernel.org, Andrew Morton , Greg Kroah-Hartman , Axel Rasmussen , Peter Xu , Hugh Dickins , Andrea Arcangeli , Matthew Wilcox , Vlastimil Babka , John Hubbard References: <20220808073232.8808-1-david@redhat.com> From: David Hildenbrand Organization: Red Hat Subject: Re: [PATCH v1] mm/gup: fix FOLL_FORCE COW security issue and remove FOLL_COW In-Reply-To: Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit X-Spam-Status: No, score=-3.4 required=5.0 tests=BAYES_00,DKIMWL_WL_HIGH, DKIM_SIGNED,DKIM_VALID,DKIM_VALID_AU,DKIM_VALID_EF,NICE_REPLY_A, RCVD_IN_DNSWL_LOW,SPF_HELO_NONE,SPF_NONE,T_SCC_BODY_TEXT_LINE autolearn=unavailable autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on lindbergh.monkeyblade.net Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org On 09.08.22 21:07, Linus Torvalds wrote: > On Tue, Aug 9, 2022 at 11:48 AM Jason Gunthorpe wrote: >> >> It is because of all this madness with COW. > > Yes, yes, but we have the proper long-term pinning now with > PG_anon_exclusive, and it actually gets the pinning right not just > over COW, but even over a fork - which that early write never did. > > David, I thought all of that got properly merged? Is there something > still missing? The only thing to get R/O longterm pins in MAP_PRIVATE correct that's missing is that we have to break COW when taking a R/O longterm pin when *not* finding an anon page inside a private mapping. Regarding anon pages I am not aware of issues (due to PG_anon_exclusive). If anybody here wants to stare at a webpage, the following commit explains the rough idea for MAP_PRIVATE: https://github.com/davidhildenbrand/linux/commit/cd7989fb76d2513c86f01e6f7a74415eee5d3150 Once we have that in place, we can mostly get rid of FOLL_FORCE|FOLL_WRITE for R/O longterm pins. There are some corner cases though that need some additional thought which i am still working on. FS-handled COW in MAP_SHARED mappings is just nasty (hello DAX). (the wrong use of FOLL_GET instead of FOLL_PIN for O_DIRECT and friends still persists, but that's a different thing to handle and it's only problematic with concurrent fork() IIRC) -- Thanks, David / dhildenb