From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-wm1-f45.google.com (mail-wm1-f45.google.com [209.85.128.45]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 5E0243C1A for ; Sat, 15 Aug 2026 00:28:28 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.45 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786753709; cv=none; b=B9wzuJPzCeL3oDYkPCziAimmvnM9xsCTPWMURa26uB4O4sWXPLNWrsYOy05COUwK31g1of84u6o0qHCSo+zCS5LvH7/DV9tqDrGhp4AtlFjYHHfNGr+DLrqGCy50FclweNESzfcxfeWnGg5bPVOkjftY6fFbuLzyguqJpEbFXeM= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786753709; c=relaxed/simple; bh=VdoxyZPOqc4gajM4tWVv7aPhUu3It/yyhy4oJD9Hkqc=; h=Date:From:To:Cc:Subject:Message-ID:References:MIME-Version: Content-Type:Content-Disposition:In-Reply-To; b=LIf19UnQNCysEF4qXlGQYRFiDyjjs5KETmkUl8GG7v8x6txvAaA8e2g/aM7XyEF2niVowxSenxkLVsjM5Gd24MaWWZ9uuPTP4EUATJeGKrQuLxIPZ3NUVHNXyexk9zHosWjQRoOKycmKFhZTrqkzzKZh+4Ihwijh46nidPI/DDw= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=XKoiYbot; arc=none smtp.client-ip=209.85.128.45 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="XKoiYbot" Received: by mail-wm1-f45.google.com with SMTP id 5b1f17b1804b1-498028b3d5eso19122285e9.1 for ; Fri, 14 Aug 2026 17:28:28 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1786753707; x=1787358507; darn=vger.kernel.org; h=in-reply-to:content-disposition:content-type:mime-version :references:message-id:subject:cc:to:from:date:from:to:cc:subject :date:message-id:reply-to:content-type; bh=e5K+G6TwOX21s1Ie3PMbo+iOlYucj/5s5+PZY2NK0NE=; b=XKoiYbot4HBUDrVvAc49cY7lBArs3k8u5JNVgRwmtX82dcfla1O2y+WI9bFAM7w8jR TpbfyCgaTiWx9U4m6V2VUrqYkzzr1/TIKqvNiela4frBOSMJb1k87sXYIB3BU/om0bki PHkabL0tPbn6kCNHjuMu1cTEPyKv8VSu5rSCM2owvwYDbVFxOALoji7el2kSG706SZFa saC40SFjB/LQ9l/tCiYmwIS1tD6dP44LYwKzDteY65THVAA378A3KC0m5nK+W95nO/Ne 0be/xe72sxTemv4pgzakkoUd4jvvW1KW0UJ/8iRrXxEQima1Rk/Wq8lKlCQW5Q7Jjdj0 InMQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786753707; x=1787358507; h=in-reply-to:content-disposition:content-type:mime-version :references:message-id:subject:cc:to:from:date:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=e5K+G6TwOX21s1Ie3PMbo+iOlYucj/5s5+PZY2NK0NE=; b=lB4hJKo0QJsXDSxSRO3C3VGMS+iBGj04xu9f8qS0lBbqkLFWfCX0SjQM7bG49tnmB6 1hWJBJTugGRKTjCCcb08lxuy39gDC/upeRMm4ESih/YxhQP8EQ8OPPc5vjQAMYlTt44g wh8xkV/cNJrS6xSSe8AWrbjxMrcrWGOSRDz9eVte3PMxJdXWf4mIg59Azzmg1+1uAn50 JegZL12hr/2JSPXPOBdeEF7TZwM1iBcn3YcAAVfdW/r958EWL9yj72BR7F/47YyPBL5g ZI2tb9Fsfb82fSUUKnrbbwcUhUV/vY2ruY3o6zTxuQFhZqLgpt+jsbEJEWNwU5j17rqm yMJA== X-Forwarded-Encrypted: i=1; AHgh+RqtTrHt2p2rpR8nNfR3AltGLq85wDBSjpcOdgZd4o1E0O/Cz3qvL5r4Sp4gH1YZ3FncjyBodOYuYhNJ5VE=@vger.kernel.org X-Gm-Message-State: AOJu0Yz786vw4XDQvinbJNClukdBV3rZ447LRPPIdX+eJjmOTIEzTZLm hQQHu4byYhi9yks8EXA5LwqRKDUHc+XON89hDxPqBcdpKW7EweBx4PvrRoPdA+oi X-Gm-Gg: AR+sD10IvT/D0EQaJqKW+mE/3UGMl9SJcYPpAwoEnJnqBCwruYunbG2gc2QrGWXzMR/ DB/6sgbiUiEjIDJTXWdTZbRtkkw3tGh97ppDAJj6nqkWndCJYOFGoJMTvGMlu65r7pmTqEvXJBi 09M5dR22+LUP24yBXFxIhnYV5JJgGHbU1ftnW7huIpYb81HhlWQ+M7ic9B+InpFBSFjcaoQ/9NQ xMRfN6u/msuPS/Jn8zsKni7TcP/u+4kKrPtOOuMnRyGSwBUqNXow2EC1H/JrD7OibkzYVfe53dU f5KNxn3IkrJQ2W6Nd5PxcEZomKXEvxOrzyzbMCC2xrdC9Iw/PeLuP5KvT7sVja1kjCCMgD+0hq2 sKKzNH0ey4ZcZltQ5j/R9dXegaVt/76dhBTpEdb9dq0EN/aO8MOiDdHos93n051UawAXd/zbNi3 JHw57o5Wtl+2P3Naf4Y+sFV+QTYLHGQdGj53miNROj/ECVNiTU5ijaAwTcTvvGKbvXM3/htwQBz QIVzSdqxCBvI1NxdS6LsAy7WNWpsRIDh3KYkIH9XoSPWYXlsbZPUyOLL88QQZOHO1WeVWO1CcL9 R7xUzl8xwnTlyg+DI4OQh2RJ/ttFG7YU3ZEmLmNf0PDxaLlT8nVyZBn16DVYALrH1A== X-Received: by 2002:a05:600c:4e0d:b0:499:900c:9c68 with SMTP id 5b1f17b1804b1-499900c9d75mr3231915e9.6.1786753706369; Fri, 14 Aug 2026 17:28:26 -0700 (PDT) Received: from unknown748F3CBA5068 (dynamic-2a02-3100-9d7d-f301-9495-44ec-73e6-1be7.310.pool.telefonica.de. [2a02:3100:9d7d:f301:9495:44ec:73e6:1be7]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-4998ba01c62sm58696145e9.14.2026.08.14.17.28.24 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 14 Aug 2026 17:28:25 -0700 (PDT) Date: Sat, 15 Aug 2026 02:28:22 +0200 From: Karl Mehltretter To: Kees Cook Cc: Vlastimil Babka , Harry Yoo , Andrew Morton , Rasmus Villemoes , Hao Li , Christoph Lameter , David Rientjes , Roman Gushchin , Catalin Marinas , "Gustavo A. R. Silva" , linux-hardening@vger.kernel.org, linux-mm@kvack.org, linux-kernel@vger.kernel.org, llvm@lists.linux.dev Subject: Re: [PATCH v2 2/3] slab: check for ZERO_SIZE_PTR by exact match Message-ID: References: <20260811141240.62519-1-kmehltretter@gmail.com> <20260811141240.62519-3-kmehltretter@gmail.com> <202608111716.0FA9DB17@keescook> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <202608111716.0FA9DB17@keescook> On Tue, Aug 11, 2026 at 05:17:48PM +0100, Kees Cook wrote: > > Compare explicitly against NULL and ZERO_SIZE_PTR. Store the argument > > in an unsigned long temporary to support both pointer and integer > > address arguments while evaluating it only once. > > Can we move ZERO_SIZE_PTR to cover the ERR_PTR range too? See this issue: > https://github.com/KSPP/linux/issues/93 > > > This also changes check_bogus_address() in hardened usercopy: nonzero > > addresses below ZERO_SIZE_PTR no longer cause its null-address abort. > > And then check_bogus_address would also catch ERR_PTR. > Thanks, I did not know about the earlier discussion and the KSPP issue. Using -4096 for ZERO_SIZE_PTR is tempting. However I found a few conflicts, for example: - PowerPC KVM guest kernels map their magic page at exactly -4096. A kernel making this change would probably have to move it to -8192. - m68k DragonBall has a hardware register at exactly 0xfffff000. - OpenRISC could reach this address with an exact 1 GiB direct map. Linus's original reason for choosing 16 was that it should fault like NULL: https://lore.kernel.org/r/alpine.LFD.0.98.0706011554300.3957@woody.linux-foundation.org I would not include ERR_PTR range for ZERO_OR_NULL_PTR() globally. krealloc() also uses it, where it would make an ERR_PTR() behave like NULL and allocate new memory. Maybe keep the exact check and add IS_ERR() separately to kfree() and hardened usercopy. Karl