Received: by 2002:a05:6358:9144:b0:117:f937:c515 with SMTP id r4csp2532667rwr; Fri, 28 Apr 2023 11:41:30 -0700 (PDT) X-Google-Smtp-Source: ACHHUZ4HysWBDeEV06jn34es/w8auRHZdFEGkBCsmQUWmfP7hrRUegxLdGMEuDGkKCSUAqdjYaIg X-Received: by 2002:a17:903:24f:b0:1a9:8d57:6d6c with SMTP id j15-20020a170903024f00b001a98d576d6cmr6097241plh.24.1682707290510; Fri, 28 Apr 2023 11:41:30 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1682707290; cv=none; d=google.com; s=arc-20160816; b=IMRiTZfKosF2LKR8JK+4u8xpXfDC9aqWXfV/w10EpRtb95RxiJug+ibhgdw2/3Lr+B ZWJgJ0gZ7sDeAjGka2o7Onzp9EmEzli0TxXxybGEg7Y06ix8fBaxcMh9GPFMfI9AmC6s 2ht+vojF5CK4kV8kErgUOgAElHdgiJ4d7OgbWTMJtzLNUm6ppXjGO06kcjqVOFJJTWBA cz1JQCc+3YKyp8fUaPTWwOKZ0ibcfa1WGAAZEtElXN1JtBDXeBGP0XCzO0C9oNa3bBrY XuB0v8dz2LpAFU0AdRC+yoF2L2Qad6r6D8WPXPKRZA5nKauuoLWRdZ3XrJqTaYGhAOKE Pssw== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:in-reply-to:content-disposition:mime-version :references:message-id:subject:cc:to:from:date:dkim-signature; bh=+QeRTh3Q792/eFaJgfAgGyTYF+cryOwA6A0C+nRVDy8=; b=wzKs7j68UDnw4w/WrfN1TRBargFN9q5mKOCxC6dFbJm1sP7bgwezRRc6EGLQwQTy8v EF6ALeIlK6rluPDV34AogV64Ne5m5ztUTpcxkQMMOpiIoIaP5eVZANDTfu7ETt2U5mRH xdTMEVFsfzGoEQtZWbXfAsa9XCCLe8yl0XuFq/sqdj0WyK0v+r2LB48ZTX1AYpUjXAWB bG/bqNX2JHBfsEGVqXGgfPiwUQnjq2N0AlLCPlnOipLg42p05BWQ9rLtkRJ6TrCFRS97 uWNtLZN016tvg9CIeNQyFfLtGnmFgtkEvBekYpjCfozQVDE4JfLTWoZorGndxRjd5n5v nXrw== ARC-Authentication-Results: i=1; mx.google.com; dkim=fail header.i=@mit.edu header.s=outgoing header.b=AMh5xv+j; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=mit.edu Return-Path: Received: from out1.vger.email (out1.vger.email. [2620:137:e000::1:20]) by mx.google.com with ESMTP id t8-20020a1709027fc800b001a1abc91980si21863244plb.211.2023.04.28.11.41.16; Fri, 28 Apr 2023 11:41:30 -0700 (PDT) Received-SPF: pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) client-ip=2620:137:e000::1:20; Authentication-Results: mx.google.com; dkim=fail header.i=@mit.edu header.s=outgoing header.b=AMh5xv+j; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=mit.edu Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1346463AbjD1S2H (ORCPT + 99 others); Fri, 28 Apr 2023 14:28:07 -0400 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:53494 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1346477AbjD1S2E (ORCPT ); Fri, 28 Apr 2023 14:28:04 -0400 Received: from outgoing.mit.edu (outgoing-auth-1.mit.edu [18.9.28.11]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id 134E7194 for ; Fri, 28 Apr 2023 11:27:58 -0700 (PDT) Received: from letrec.thunk.org ([76.150.80.181]) (authenticated bits=0) (User authenticated as tytso@ATHENA.MIT.EDU) by outgoing.mit.edu (8.14.7/8.12.4) with ESMTP id 33SIPsvO024394 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Fri, 28 Apr 2023 14:25:55 -0400 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=mit.edu; s=outgoing; t=1682706363; bh=+QeRTh3Q792/eFaJgfAgGyTYF+cryOwA6A0C+nRVDy8=; h=Date:From:To:Cc:Subject:References:In-Reply-To; b=AMh5xv+jG+n9laJ4e0qLg3l6ymmeae7bAXwqrq4kE8f9OTLDZec1GN/EZ4P11VjB7 r7tdp+zdX1OwYKlDp+K5fMVWj0mHfs68d3QH3Ak6FfD/zOf0HeAfsuD0nOiJBObAD9 oLIceXgN8fEn9ItUp1TEodH8IuHPQm/vCmstG89u0yJfAIVgz+nUoS5GMv0EvyLAy+ wWf7gGYeXDT2RGdrlTOO9RatuD0Rdhg4poRc4X7OvNvkL0Hjb/gtXj+quB83D9R8UX 4Y4y0g9DMWE0P4vfvb8BkRELNhxxIwazgFHVscRWZAnwkhiC8/6hz7tspIL09c5E2/ FI/r3M817jUPA== Received: by letrec.thunk.org (Postfix, from userid 15806) id 164EF8C01E0; Fri, 28 Apr 2023 14:25:53 -0400 (EDT) Date: Fri, 28 Apr 2023 14:25:53 -0400 From: "Theodore Ts'o" To: Jason Gunthorpe Cc: David Hildenbrand , Lorenzo Stoakes , linux-mm@kvack.org, linux-kernel@vger.kernel.org, Andrew Morton , Jens Axboe , Matthew Wilcox , Dennis Dalessandro , Leon Romanovsky , Christian Benvenuti , Nelson Escobar , Bernard Metzler , Peter Zijlstra , Ingo Molnar , Arnaldo Carvalho de Melo , Mark Rutland , Alexander Shishkin , Jiri Olsa , Namhyung Kim , Ian Rogers , Adrian Hunter , Bjorn Topel , Magnus Karlsson , Maciej Fijalkowski , Jonathan Lemon , "David S . Miller" , Eric Dumazet , Jakub Kicinski , Paolo Abeni , Christian Brauner , Richard Cochran , Alexei Starovoitov , Daniel Borkmann , Jesper Dangaard Brouer , John Fastabend , linux-fsdevel@vger.kernel.org, linux-perf-users@vger.kernel.org, netdev@vger.kernel.org, bpf@vger.kernel.org, Oleg Nesterov , John Hubbard , Jan Kara , "Kirill A . Shutemov" , Pavel Begunkov , Mika Penttila , David Howells , Christoph Hellwig Subject: Re: [PATCH v5] mm/gup: disallow GUP writing to file-backed mappings by default Message-ID: References: <6b73e692c2929dc4613af711bdf92e2ec1956a66.1682638385.git.lstoakes@gmail.com> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: X-Spam-Status: No, score=-4.0 required=5.0 tests=BAYES_00,DKIM_INVALID, DKIM_SIGNED,RCVD_IN_DNSWL_MED,SPF_HELO_NONE,SPF_NONE, T_SCC_BODY_TEXT_LINE autolearn=unavailable autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on lindbergh.monkeyblade.net Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org On Fri, Apr 28, 2023 at 11:35:32AM -0300, Jason Gunthorpe wrote: > > It has been years now, I think we need to admit a fix is still years > away. Blocking the security problem may even motivate more people to > work on a fix. Do we think we can still trigger a kernel crash, or maybe even some more exciting like an arbitrary buffer overrun, via the process_vm_writev(2) system call into a file-backed mmap'ed region? Maybe if someone can come up with an easy-to-expliot security proof of aconcept, that doesn't require special RDMA hardware or some special libvirt setup, we could finally get motivation to get it fixed, or at least blocked? :-) We've only been talking about it for years, after all... - Ted > Security is the primary case where we have historically closed uAPI > items. > > Jason