From: Borislav Petkov <bp@alien8.de>
To: Linus Torvalds <torvalds@linux-foundation.org>
Cc: syzbot <syzbot+401145a9a237779feb26@syzkaller.appspotmail.com>,
Borislav Petkov <bp@suse.de>, stable <stable@vger.kernel.org>,
almaz.alexandrovich@paragon-software.com, clm@fb.com,
djwong@kernel.org, dsterba@suse.com, hch@infradead.org,
josef@toxicpanda.com, linux-btrfs@vger.kernel.org,
linux-ext4@vger.kernel.org, linux-fsdevel@vger.kernel.org,
linux-kernel@vger.kernel.org, linux-xfs@vger.kernel.org,
ntfs3@lists.linux.dev, syzkaller-bugs@googlegroups.com,
willy@infradead.org
Subject: Re: [syzbot] [xfs?] BUG: unable to handle kernel paging request in clear_user_rep_good
Date: Wed, 3 May 2023 12:31:28 +0200 [thread overview]
Message-ID: <20230503103128.GAZFI4AEyPcP4bCemf@fat_crate.local> (raw)
In-Reply-To: <CAHk-=whWUZyiFvHpkC35DXo713GKFjqCWwY1uCs3tbMJ6QXeWg@mail.gmail.com>
On Mon, May 01, 2023 at 11:49:55AM -0700, Linus Torvalds wrote:
> The bug goes back to commit 0db7058e8e23 ("x86/clear_user: Make it
> faster") from about a year ago, which made it into v6.1.
Gah, sorry about that. :-\
> It only affects old hardware that doesn't have the ERMS capability
> flag, which *probably* means that it's mostly only triggerable in
> virtualization (since pretty much any CPU from the last decade has
> ERMS, afaik).
>
> Borislav - opinions? This needs fixing for v6.1..v6.3, and the options are:
>
> (1) just fix up the exception entry. I think this is literally this
> one-liner, but somebody should double-check me. I did *not* actually
> test this:
>
> --- a/arch/x86/lib/clear_page_64.S
> +++ b/arch/x86/lib/clear_page_64.S
> @@ -142,8 +142,8 @@ SYM_FUNC_START(clear_user_rep_good)
> and $7, %edx
> jz .Lrep_good_exit
>
> -.Lrep_good_bytes:
> mov %edx, %ecx
> +.Lrep_good_bytes:
> rep stosb
>
> .Lrep_good_exit:
>
> because the only use of '.Lrep_good_bytes' is that exception table entry.
>
> (2) backport just that one commit for clear_user
>
> In this case we should probably do commit e046fe5a36a9 ("x86: set
> FSRS automatically on AMD CPUs that have FSRM") too, since that commit
> changes the decision to use 'rep stosb' to check FSRS.
>
> (3) backport the entire series of commits:
>
> git log --oneline v6.3..034ff37d3407
>
> Or we could even revert that commit 0db7058e8e23, but it seems silly
> to revert when we have so many ways to fix it, including a one-line
> code movement.
>
> Borislav / stable people? Opinions?
So right now I feel like (3) would be the right thing to do. Because
then stable and upstream will be on the same "level" wrt user-accessing
primitives. And it's not like your series depend on anything from
mainline (that I know of) so backporting them should be relatively easy.
But (1) is definitely a lot easier for stable people modulo the fact
that it won't be an upstream commit but a special stable-only fix.
So yeah, in that order.
I guess I'd let stable people decide here what they wanna do.
Thx.
--
Regards/Gruss,
Boris.
https://people.kernel.org/tglx/notes-about-netiquette
prev parent reply other threads:[~2023-05-03 10:31 UTC|newest]
Thread overview: 6+ messages / expand[flat|nested] mbox.gz Atom feed top
2023-02-03 7:54 [syzbot] [ntfs3?] [btrfs?] " syzbot
2023-02-03 16:25 ` Christoph Hellwig
2023-02-03 16:32 ` Matthew Wilcox
2023-05-01 4:31 ` [syzbot] [xfs?] " syzbot
2023-05-01 18:49 ` Linus Torvalds
2023-05-03 10:31 ` Borislav Petkov [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20230503103128.GAZFI4AEyPcP4bCemf@fat_crate.local \
--to=bp@alien8.de \
--cc=almaz.alexandrovich@paragon-software.com \
--cc=bp@suse.de \
--cc=clm@fb.com \
--cc=djwong@kernel.org \
--cc=dsterba@suse.com \
--cc=hch@infradead.org \
--cc=josef@toxicpanda.com \
--cc=linux-btrfs@vger.kernel.org \
--cc=linux-ext4@vger.kernel.org \
--cc=linux-fsdevel@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-xfs@vger.kernel.org \
--cc=ntfs3@lists.linux.dev \
--cc=stable@vger.kernel.org \
--cc=syzbot+401145a9a237779feb26@syzkaller.appspotmail.com \
--cc=syzkaller-bugs@googlegroups.com \
--cc=torvalds@linux-foundation.org \
--cc=willy@infradead.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®