mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Viorel Cernateanu via B4 Relay <devnull+vrilutza.gmail.com@kernel.org>
To: Alexander Potapenko <glider@google.com>,
	Marco Elver <elver@google.com>,
	 Dmitry Vyukov <dvyukov@google.com>,
	Thomas Gleixner <tglx@kernel.org>,
	 Ingo Molnar <mingo@redhat.com>, Borislav Petkov <bp@alien8.de>,
	 Dave Hansen <dave.hansen@linux.intel.com>,
	x86@kernel.org,  "H. Peter Anvin" <hpa@zytor.com>,
	Andrew Morton <akpm@linux-foundation.org>,
	 Peter Zijlstra <peterz@infradead.org>,
	Kees Cook <kees@kernel.org>
Cc: Borislav Petkov <bp@suse.de>,
	kasan-dev@googlegroups.com,  linux-kernel@vger.kernel.org,
	Viorel Cernateanu <vrilutza@gmail.com>
Subject: [PATCH 0/2] x86/kmsan: Fix two bugs in the metadata lookup
Date: Tue, 06 Oct 2026 21:10:21 +0300	[thread overview]
Message-ID: <20261006-kmsan-serie-v1-0-07fa860ef3de@gmail.com> (raw)

Two fixes in arch/x86/include/asm/kmsan.h, found while running KMSAN
kernels with KASLR and with CONFIG_DEBUG_PREEMPT.

Patch 1 fixes the CPU lookup for addresses in the CPU entry area, which
is wrong with KASLR, and for the last page of each area without it.

Patch 2 fixes a recursion with CONFIG_DEBUG_PREEMPT: the metadata lookup
ends up in the instrumented preempt_count_add(), and the kernel hangs
right after KMSAN is enabled.

Both were tested on v7.3-rc6 in QEMU/KVM, with x86_64_defconfig plus
x86_debug.config (without LOCK_STAT, LOCKDEP, PROVE_LOCKING, GCOV and
DWARF), KMSAN and UBSAN_BOUNDS, and with a module that poisons and then
checks the KMSAN metadata at the start and at the end of the current
CPU's entry area, so a KMSAN report means the metadata was found.

Patch 1: without it, the end of the area is missed without KASLR, and
the lookup oopses with KASLR. With it, both are found, with and without
KASLR (three boots each). On an Ivy Bridge laptop, v7.3-rc6 with this
patch and KASLR gets past the hard lockup detector setup, and the same
check finds the metadata on all four CPUs. The lookup now scans up to
nr_cpu_ids entries for addresses in the CPU entry area; I have not
measured the cost on machines with many CPUs.

Patch 2, with CONFIG_DEBUG_PREEMPT added: without it, three boots out of
three with KASLR stop after the "ATTENTION: KMSAN is a debugging tool!"
banner and never reach init. With both patches, six boots out of six
reach init, with and without KASLR, and the module above still gets its
KMSAN reports. Not tested with lockdep, PROVE_RCU or
TRACE_PREEMPT_TOGGLE, and not on hardware.

---
Viorel Cernateanu (2):
      x86/kmsan: Fix CPU entry area metadata lookup
      x86/kmsan: Don't call instrumented code from kmsan_virt_addr_valid()

 arch/x86/include/asm/kmsan.h | 76 ++++++++++++++++++++++++++++++--------------
 1 file changed, 52 insertions(+), 24 deletions(-)
---
base-commit: a90ee4305c4a5df72c11b31dacfdc76e00fcf78a
change-id: 20261006-kmsan-serie-e33000b199ce

Best regards,
--  
Viorel Cernateanu <vrilutza@gmail.com>



             reply	other threads:[~2026-10-06 18:10 UTC|newest]

Thread overview: 3+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-10-06 18:10 Viorel Cernateanu via B4 Relay [this message]
2026-10-06 18:10 ` [PATCH 1/2] x86/kmsan: Fix CPU entry area " Viorel Cernateanu via B4 Relay
2026-10-06 18:10 ` [PATCH 2/2] x86/kmsan: Don't call instrumented code from kmsan_virt_addr_valid() Viorel Cernateanu via B4 Relay

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20261006-kmsan-serie-v1-0-07fa860ef3de@gmail.com \
    --to=devnull+vrilutza.gmail.com@kernel.org \
    --cc=akpm@linux-foundation.org \
    --cc=bp@alien8.de \
    --cc=bp@suse.de \
    --cc=dave.hansen@linux.intel.com \
    --cc=dvyukov@google.com \
    --cc=elver@google.com \
    --cc=glider@google.com \
    --cc=hpa@zytor.com \
    --cc=kasan-dev@googlegroups.com \
    --cc=kees@kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=mingo@redhat.com \
    --cc=peterz@infradead.org \
    --cc=tglx@kernel.org \
    --cc=vrilutza@gmail.com \
    --cc=x86@kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®