Received: by 2002:a05:7412:2a8c:b0:e2:908c:2ebd with SMTP id u12csp4001579rdh; Fri, 29 Sep 2023 08:25:30 -0700 (PDT) X-Google-Smtp-Source: AGHT+IFMxSsrPAZGs71+a5K1cXmo7MTGFh9521U3C1hYS14Xh3dtLkqqayMJTzt4Vw03ah4iYPhs X-Received: by 2002:a17:90a:43a3:b0:277:2d2d:9a37 with SMTP id r32-20020a17090a43a300b002772d2d9a37mr4334022pjg.4.1696001130295; Fri, 29 Sep 2023 08:25:30 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1696001130; cv=none; d=google.com; s=arc-20160816; b=AkagKeR6o5Ucxj93zOgLnZiqwCcK4JH+iPLx3mbvIFtZLjZPhB1U0RpTv8mecwzyhY 2D7qt8IwGu1x3IeQEyFmZJE4FnJ4FZCsxdK1W0Sk6xvwkaTACT9f3I3WIfhocg931PKm mKCbwe/jmT9QYXgCbTNcfRrPmPjFt3pxyrIUkwjkVeLTD2CWhBP6OiN9DnK15YJbQkLg ldcs8/vFPE7Pmfbg2ao6gIwUe58DO7Husp7MKEAcd0QcrIy4f4EEp7twLJsyotR6cG6c UuTmixo26SKQC1CXAZLl2LhBqlOCLZFosoUIIl5fmbonqCn5uyn9htttZIr9bQSkYKuE yFEQ== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:content-transfer-encoding:cc:to:subject :message-id:date:from:in-reply-to:references:mime-version :dkim-signature; bh=WX41g5Ex2mgCQT3kQj51PYJPgefWmJ9XFZpouAvDF2A=; fh=EVEcJI+L5pGYj+7NktINbY0iXqDkfT0Aus4X15ZBu+o=; b=t3Hx55v5Bn3mQlXDYSvn0X44/KWYkzH+kxOpDlyMmp0oui5uFRLgFVA9c9xtitB1Oh 5EmP7oHpqpI0UbRluoqlTh6qbYbir4Zck7lPvw1qHHsHgtcfH2MDx/97tgJRGoSaw0+0 6sP+qUeYvRPoafGAGZJ9AoYGRgzvyXBSe3mvFQASNiw27pxXs8+VSuxilLKRpCy2OVVk 1vs0sBQ0xsPR7iuuRq9Ck2mraFbJY+XW8U76pEszvsbThCNLGZBfgPkH1dJG2+gGuYT+ yUxhKLIfqZWaYYwPeVtJXI7JjdfYbQQX43WifYZt30CSQunPSZHVUKZBnfmJMAY3yR72 rYtQ== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@rivosinc-com.20230601.gappssmtp.com header.s=20230601 header.b=FxW3KCsQ; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.37 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org Return-Path: Received: from snail.vger.email (snail.vger.email. [23.128.96.37]) by mx.google.com with ESMTPS id ot2-20020a17090b3b4200b00268293118efsi1929186pjb.47.2023.09.29.08.25.29 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 29 Sep 2023 08:25:30 -0700 (PDT) Received-SPF: pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.37 as permitted sender) client-ip=23.128.96.37; Authentication-Results: mx.google.com; dkim=pass header.i=@rivosinc-com.20230601.gappssmtp.com header.s=20230601 header.b=FxW3KCsQ; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.37 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org Received: from out1.vger.email (depot.vger.email [IPv6:2620:137:e000::3:0]) by snail.vger.email (Postfix) with ESMTP id 38DCA80A267B; Fri, 29 Sep 2023 01:26:18 -0700 (PDT) X-Virus-Status: Clean X-Virus-Scanned: clamav-milter 0.103.10 at snail.vger.email Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S232606AbjI2I0P (ORCPT + 99 others); Fri, 29 Sep 2023 04:26:15 -0400 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:51614 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S232621AbjI2I0O (ORCPT ); Fri, 29 Sep 2023 04:26:14 -0400 Received: from mail-wm1-x32e.google.com (mail-wm1-x32e.google.com [IPv6:2a00:1450:4864:20::32e]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id C78791A8 for ; Fri, 29 Sep 2023 01:26:11 -0700 (PDT) Received: by mail-wm1-x32e.google.com with SMTP id 5b1f17b1804b1-405361bb94eso141670565e9.0 for ; Fri, 29 Sep 2023 01:26:11 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=rivosinc-com.20230601.gappssmtp.com; s=20230601; t=1695975970; x=1696580770; darn=vger.kernel.org; h=content-transfer-encoding:cc:to:subject:message-id:date:from :in-reply-to:references:mime-version:from:to:cc:subject:date :message-id:reply-to; bh=WX41g5Ex2mgCQT3kQj51PYJPgefWmJ9XFZpouAvDF2A=; b=FxW3KCsQo8txXpMWzi3zSezrX+Y8aSco5Gz1q5587lukO7eseyKJii5o8m7YwM5FTl 45ACBfxVNuovoQU3VTG+upg6xDZ7/s8I/dPHNBSaS/vitqLH/Q6zy8OHVBWunpeFbWe5 614xehgH9A+34nyBLiQzxV/1sG4GkayPtNSksBHvMRXZf5WpHhU+qcD/iv3pNpwqqbDo OSaS3G8dXCgzcbzf3ij6yj2obTnJri3LIDsZl2oQYNUX4BAuX8P8WaZr9AuZIEt3KLbn TNqTdbQjCKQxK/FZ4TVUDf/BKiOThm6wF81lDgckR8ObCvp3xqtFSKm/5PUVGqeTvEnb QZDQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1695975970; x=1696580770; h=content-transfer-encoding:cc:to:subject:message-id:date:from :in-reply-to:references:mime-version:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to; bh=WX41g5Ex2mgCQT3kQj51PYJPgefWmJ9XFZpouAvDF2A=; b=TOkLMkpYVrMwj0nqxbZSKEk6ca+RLR0+MFP/+nXz24rbgQD/Jx1RzlTXUnCHJ01cIE JsWgbQVwvxHAhSWVvZKQC4Y1unMJhDKHR11iPYjBL9IrwkZVaHTPzOdE46dRNcfYkr9E Ai+W2EjnggulFssUJe+USOORJM5CZDjrFiSmisZT5FSRHfRAB7qVl7abU/BhWt0C9WXK PnWLODCTwtkDqJxRmcv2jYn+JgQywV17wFu1n7pKbw6DEfPZzjG6DL6GKi7PaY/clk1F 6UuoPlVrtw7144uiNtVU947qxx5a5pfg5HH1lw1XeJkAt7SNSc5J4CknYAx8u68wonQ4 kgCA== X-Gm-Message-State: AOJu0YzzozM6wjcxMWfpIRNBfl7xFa++5rzwEBd6wT86bNHpTimy6PG4 M7XI5VsN3sipbnPyoSI6sIFB1b6pZTl0SJD5+cFr1Q== X-Received: by 2002:a05:600c:3785:b0:401:b204:3b98 with SMTP id o5-20020a05600c378500b00401b2043b98mr3941830wmr.19.1695975970106; Fri, 29 Sep 2023 01:26:10 -0700 (PDT) MIME-Version: 1.0 References: <20230928231239.2144579-2-twuufnxlz@gmail.com> In-Reply-To: <20230928231239.2144579-2-twuufnxlz@gmail.com> From: Alexandre Ghiti Date: Fri, 29 Sep 2023 10:25:59 +0200 Message-ID: Subject: Re: [PATCH] riscv: fix out of bounds in walk_stackframe To: Edward AD Cc: alex@ghiti.fr, aou@eecs.berkeley.edu, conor@kernel.org, gregkh@linuxfoundation.org, guoren@kernel.org, jirislaby@kernel.org, linux-kernel@vger.kernel.org, linux-riscv@lists.infradead.org, linux-serial@vger.kernel.org, liushixin2@huawei.com, palmer@dabbelt.com, paul.walmsley@sifive.com, syzbot+8d2757d62d403b2d9275@syzkaller.appspotmail.com, syzkaller-bugs@googlegroups.com Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable X-Spam-Status: No, score=-1.9 required=5.0 tests=BAYES_00,DKIM_SIGNED, DKIM_VALID,RCVD_IN_DNSWL_BLOCKED,SPF_HELO_NONE,SPF_PASS autolearn=ham autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on lindbergh.monkeyblade.net Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org X-Greylist: Sender passed SPF test, not delayed by milter-greylist-4.6.4 (snail.vger.email [0.0.0.0]); Fri, 29 Sep 2023 01:26:18 -0700 (PDT) Hi Edward, On Fri, Sep 29, 2023 at 1:12=E2=80=AFAM Edward AD wro= te: > > Add vmalloc and kernel addresses check to prevent invalid access. > > Closes: https://lore.kernel.org/all/20230926105949.1025995-2-twuufnxlz@gm= ail.com/ > Fixes: 5d8544e2d007 ("RISC-V: Generic library routines and assembly") > Reported-and-test-by: syzbot+8d2757d62d403b2d9275@syzkaller.appspotmail.c= om > Link: https://lore.kernel.org/all/0000000000000170df0605ccf91a@google.com= /T/ > Signed-off-by: Edward AD > --- > arch/riscv/kernel/stacktrace.c | 3 +++ > 1 file changed, 3 insertions(+) > > diff --git a/arch/riscv/kernel/stacktrace.c b/arch/riscv/kernel/stacktrac= e.c > index 64a9c093aef9..031a4a35c1d0 100644 > --- a/arch/riscv/kernel/stacktrace.c > +++ b/arch/riscv/kernel/stacktrace.c > @@ -54,6 +54,9 @@ void notrace walk_stackframe(struct task_struct *task, = struct pt_regs *regs, > break; > /* Unwind stack frame */ > frame =3D (struct stackframe *)fp - 1; > + if ((is_vmalloc_addr(frame) && !pfn_valid(page_to_pfn(vma= lloc_to_page(frame)))) || > + !virt_addr_valid(frame)) > + break; > sp =3D fp; > if (regs && (regs->epc =3D=3D pc) && (frame->fp & 0x7)) { > fp =3D frame->ra; > -- > 2.25.1 > I'm still not convinced this will fix the kasan out-of-bounds accesses, the page can be valid but the read can happen at an offset not initialized and trigger such errors right? I still think there is something weird about the stack frame, as to me this should not happen (but admittedly I don't know much about that).