From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1751021AbdL3WpM (ORCPT ); Sat, 30 Dec 2017 17:45:12 -0500 Received: from Galois.linutronix.de ([146.0.238.70]:35279 "EHLO Galois.linutronix.de" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1750923AbdL3WpL (ORCPT ); Sat, 30 Dec 2017 17:45:11 -0500 Date: Sat, 30 Dec 2017 23:45:04 +0100 (CET) From: Thomas Gleixner To: Mathieu Desnoyers cc: linux-kernel , Andy Lutomirski , Peter Zijlstra , Borislav Petkov , Dave Hansen , Hugh Dickins , Linus Torvalds Subject: Re: Review of KPTI patchset In-Reply-To: Message-ID: References: <2080549061.45775.1514659556107.JavaMail.zimbra@efficios.com> <1311401854.45816.1514666587545.JavaMail.zimbra@efficios.com> User-Agent: Alpine 2.20 (DEB 67 2015-01-07) MIME-Version: 1.0 Content-Type: text/plain; charset=US-ASCII X-Linutronix-Spam-Score: -1.0 X-Linutronix-Spam-Level: - X-Linutronix-Spam-Status: No , -1.0 points, 5.0 required, ALL_TRUSTED=-1,SHORTCIRCUIT=-0.0001 Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org On Sat, 30 Dec 2017, Thomas Gleixner wrote: > On Sat, 30 Dec 2017, Mathieu Desnoyers wrote: > The only asymetry is in the error path of write_ldt() which can leak a half > allocated page table. But, that's a nasty one because if there is an > existing LDT mapped, then the pagetable cannot be freed. So yes, it's not > nice, but harmless and needs some thought to fix. In fact it's not a leak. It's just memory waste because the pagetable gets freed when the process exits. The memory waste is rather simple to fix. Delta patch below. Thanks, tglx 8<-------------- --- a/arch/x86/kernel/ldt.c +++ b/arch/x86/kernel/ldt.c @@ -421,6 +421,14 @@ static int write_ldt(void __user *ptr, u */ error = map_ldt_struct(mm, new_ldt, old_ldt ? !old_ldt->slot : 0); if (error) { + /* + * Drop potentially half populated page table if the + * mapping code failed and this was the first attempt to + * install a LDT. If there is a LDT installed then the LDT + * pagetable cannot be freed for obvious reasons. + */ + if (!old_ldt) + free_ldt_pgtables(mm); free_ldt_struct(new_ldt); goto out_unlock; }