From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Google-Smtp-Source: AG47ELu6upDcUvQWIzX6I/nzNVaEHNjK/DF39pGf8S3rQ46h3R54d11SrQkjkqz1v1DdVzEuHtp0 ARC-Seal: i=1; a=rsa-sha256; t=1520604917; cv=none; d=google.com; s=arc-20160816; b=ByWjuqpiIiYom1tz2DDlVMO6MyS8Jf81VZMiSJyoac8c/IDklADAIt9QDmtogkOv8z DlJ/gX8LnSLsAaDuvosJcyHVPSZKHHXMOsB4x4K9Eyz5+g9tV8+g8xo502JmjOo3BeKn QJnGwrB9unysb+9WEAO7UCqUGEjZU3Y+sg1LIVhA4Bh6iv7OhXox8rU0NcnORktuh8QC SZ5mo5oFFRELH5eNJdOwZzIai/P4g+s2zCF5mLqPbLvIr81ZXORM0z5HsqB3WwSfu0h6 oPuYo7J1go1vlQJLPq7wrOsyLDzeCc3mCY/PDz5gARpZxxAU8I5IRyHRMcgcuwm7XC62 odZg== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=content-transfer-encoding:content-language:in-reply-to:mime-version :user-agent:date:message-id:from:references:cc:to:subject :arc-authentication-results; bh=TKBFVQ/1e6mV4qi2n1764tlrtXrCoElOnzysiiiOwMM=; b=a33UCnTIUCdfQdLpRrFc03uInE6Tmqhpz6RAQFjSdBjUFBAj2FSju4KhYY3vQRBIWb 3xJvxW0Iv29dXYUI3I8DTM6BPYmVS36mAEHagyROo5xZYFzoC4xcCuLB0bH7AkxO00XJ Oe7xW3b8Ue5mWCIb1eWP7Cwgf9HBNDlwG/H0fD0yy8cmFc6iOZsyTsvsJjPbRgvh5KMs AN4eStyvr76Ndvk0dcYBNmqWkwgTXtgYcfmcXKLAcsomRdczble9kaWe/9Kxj7+yYiLG 1A9I9LXo85EdUmYaKbZHozQQvK7SQ3E++qk5RHJzWzW9B2QfE8+jqCICi4zAOjGK7UuA /c+w== ARC-Authentication-Results: i=1; mx.google.com; spf=pass (google.com: domain of robin.murphy@arm.com designates 217.140.101.70 as permitted sender) smtp.mailfrom=robin.murphy@arm.com Authentication-Results: mx.google.com; spf=pass (google.com: domain of robin.murphy@arm.com designates 217.140.101.70 as permitted sender) smtp.mailfrom=robin.murphy@arm.com Subject: Re: [RFC PATCH 0/6] arm64: untag user pointers passed to the kernel To: Andrey Konovalov , Catalin Marinas , Will Deacon , Mark Rutland , Al Viro , Philippe Ombredanne , Greg Kroah-Hartman , Thomas Gleixner , Kate Stewart , Andrew Morton , "Kirill A . Shutemov" , Ingo Molnar , "Aneesh Kumar K . V" , Minchan Kim , Michal Hocko , Shaohua Li , Andrea Arcangeli , Anshuman Khandual , Mike Rapoport , Vlastimil Babka , Naoya Horiguchi , Shakeel Butt , Joonsoo Kim , Hugh Dickins , Mel Gorman , =?UTF-8?B?SsOpcsO0bWUgR2xpc3Nl?= , Mike Kravetz , Zi Yan , linux-arm-kernel@lists.infradead.org, linux-kernel@vger.kernel.org, linux-mm@kvack.org, Richard Henderson , Ivan Kokshaysky , Matt Turner , Vineet Gupta , Russell King , Mark Salter , Aurelien Jacquiot , Mikael Starvik , Jesper Nilsson , Tony Luck , Fenghua Yu , Geert Uytterhoeven , James Hogan , Michal Simek , Ralf Baechle , David Howells , Ley Foon Tan , Jonas Bonn , Stefan Kristiansson , Stafford Horne , "James E . J . Bottomley" , Helge Deller , Benjamin Herrenschmidt , Paul Mackerras , Michael Ellerman , Palmer Dabbelt , Albert Ou , Chen Liqin , Lennox Wu , Yoshinori Sato , Rich Felker , "David S . Miller" , Ingo Molnar , x86@kernel.org, Chris Zankel , Max Filippov , Arnd Bergmann , linux-alpha@vger.kernel.org, linux-snps-arc@lists.infradead.org, adi-buildroot-devel@lists.sourceforge.net, linux-c6x-dev@linux-c6x.org, linux-cris-kernel@axis.com, linux-ia64@vger.kernel.org, linux-m68k@lists.linux-m68k.org, linux-metag@vger.kernel.org, linux-mips@linux-mips.org, linux-am33-list@redhat.com, nios2-dev@lists.rocketboards.org, openrisc@lists.librecores.org, linux-parisc@vger.kernel.org, linuxppc-dev@lists.ozlabs.org, linux-riscv@lists.infradead.org, linux-sh@vger.kernel.org, sparclinux@vger.kernel.org, linux-xtensa@linux-xtensa.org, linux-arch@vger.kernel.org Cc: Dmitry Vyukov , Kostya Serebryany , Evgeniy Stepanov , Lee Smith , Ramana Radhakrishnan , Jacob Bramley , Ruben Ayrapetyan References: From: Robin Murphy Message-ID: <963e112a-88a0-94bc-e6eb-0e9f9a6ee14a@arm.com> Date: Fri, 9 Mar 2018 14:15:00 +0000 User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:52.0) Gecko/20100101 Thunderbird/52.6.0 MIME-Version: 1.0 In-Reply-To: Content-Type: text/plain; charset=utf-8; format=flowed Content-Language: en-GB Content-Transfer-Encoding: 7bit X-getmail-retrieved-from-mailbox: INBOX X-GMAIL-THRID: =?utf-8?q?1594468997571598661?= X-GMAIL-MSGID: =?utf-8?q?1594469821507198358?= X-Mailing-List: linux-kernel@vger.kernel.org List-ID: Hi Andrey, On 09/03/18 14:01, Andrey Konovalov wrote: > arm64 has a feature called Top Byte Ignore, which allows to embed pointer > tags into the top byte of each pointer. Userspace programs (such as > HWASan, a memory debugging tool [1]) might use this feature and pass > tagged user pointers to the kernel through syscalls or other interfaces. If you propose changing the ABI, then Documentation/arm64/tagged-pointers.txt needs to reflect the new one, since passing nonzero tags via syscalls is currently explicitly forbidden. Robin. > This patch makes a few of the kernel interfaces accept tagged user > pointers. The kernel is already able to handle user faults with tagged > pointers and has the untagged_addr macro, which this patchset reuses. > > We're not trying to cover all possible ways the kernel accepts user > pointers in one patchset, so this one should be considered as a start. > It would be nice to learn about the interfaces that I missed though. > > Sending this as an RFC, as I'm not sure if this should be committed as is, > and would like to receive some feedback. > > Thanks! > > [1] http://clang.llvm.org/docs/HardwareAssistedAddressSanitizerDesign.html > > Andrey Konovalov (6): > arm64: add type casts to untagged_addr macro > arm64: untag user addresses in copy_from_user and others > mm, arm64: untag user addresses in memory syscalls > mm, arm64: untag user addresses in mm/gup.c > lib, arm64: untag addrs passed to strncpy_from_user and strnlen_user > arch: add untagged_addr definition for other arches > > arch/alpha/include/asm/uaccess.h | 2 ++ > arch/arc/include/asm/uaccess.h | 1 + > arch/arm/include/asm/uaccess.h | 2 ++ > arch/arm64/include/asm/uaccess.h | 9 +++++++-- > arch/blackfin/include/asm/uaccess.h | 2 ++ > arch/c6x/include/asm/uaccess.h | 2 ++ > arch/cris/include/asm/uaccess.h | 2 ++ > arch/frv/include/asm/uaccess.h | 2 ++ > arch/ia64/include/asm/uaccess.h | 2 ++ > arch/m32r/include/asm/uaccess.h | 2 ++ > arch/m68k/include/asm/uaccess.h | 2 ++ > arch/metag/include/asm/uaccess.h | 2 ++ > arch/microblaze/include/asm/uaccess.h | 2 ++ > arch/mips/include/asm/uaccess.h | 2 ++ > arch/mn10300/include/asm/uaccess.h | 2 ++ > arch/nios2/include/asm/uaccess.h | 2 ++ > arch/openrisc/include/asm/uaccess.h | 2 ++ > arch/parisc/include/asm/uaccess.h | 2 ++ > arch/powerpc/include/asm/uaccess.h | 2 ++ > arch/riscv/include/asm/uaccess.h | 2 ++ > arch/score/include/asm/uaccess.h | 2 ++ > arch/sh/include/asm/uaccess.h | 2 ++ > arch/sparc/include/asm/uaccess.h | 2 ++ > arch/tile/include/asm/uaccess.h | 2 ++ > arch/x86/include/asm/uaccess.h | 2 ++ > arch/xtensa/include/asm/uaccess.h | 2 ++ > include/asm-generic/uaccess.h | 2 ++ > lib/strncpy_from_user.c | 2 ++ > lib/strnlen_user.c | 2 ++ > mm/gup.c | 12 ++++++++++++ > mm/madvise.c | 2 ++ > mm/mempolicy.c | 6 ++++++ > mm/mincore.c | 2 ++ > mm/mlock.c | 5 +++++ > mm/mmap.c | 9 +++++++++ > mm/mprotect.c | 2 ++ > mm/mremap.c | 2 ++ > mm/msync.c | 3 +++ > 38 files changed, 105 insertions(+), 2 deletions(-) >