mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: "Lorenzo Stoakes (ARM)" <ljs@kernel.org>
To: Hongfu Li <hongfu.li@linux.dev>
Cc: akpm@linux-foundation.org, david@kernel.org, liam@infradead.org,
	 vbabka@kernel.org, rppt@kernel.org, surenb@google.com,
	mhocko@suse.com,  shuah@kernel.org,
	James.Bottomley@hansenpartnership.com, linux-mm@kvack.org,
	 linux-kselftest@vger.kernel.org, linux-kernel@vger.kernel.org,
	Hongfu Li <lihongfu@kylinos.cn>
Subject: Re: [PATCH] selftests/mm: fix ptrace PEEKDATA check in memfd_secret test
Date: Tue, 8 Sep 2026 10:03:11 +0100	[thread overview]
Message-ID: <ap_N7u5DbIk4FEeZ@gremlin> (raw)
In-Reply-To: <20260908025111.34562-1-hongfu.li@linux.dev>

On Tue, Sep 08, 2026 at 10:51:11AM +0800, Hongfu Li wrote:
> From: Hongfu Li <lihongfu@kylinos.cn>
>
> try_ptrace() treats PTRACE_PEEKDATA return value as a boolean
> check. A successful read returns non-zero data (memory filled with
> 0x55), causing the test to incorrectly report PASS when secret memory
> protection is broken.
>
> Check the return value against -1 instead. The test should only pass
> when PTRACE_PEEKDATA fails, which means secret memory protection works.
>
> Fixes: 76fe17ef588a ("secretmem: test: add basic selftest for memfd_secret(2)")

Not sure if a fixes is warranted? But I also definitely don't think a backport
is in any case in case :P

> Signed-off-by: Hongfu Li <lihongfu@kylinos.cn>

The change LGTM afaict. Though I think a comment should be added. With that
addressed:

Acked-by: Lorenzo Stoakes (ARM) <ljs@kernel.org>

> ---
>  tools/testing/selftests/mm/memfd_secret.c | 2 +-
>  1 file changed, 1 insertion(+), 1 deletion(-)
>
> diff --git a/tools/testing/selftests/mm/memfd_secret.c b/tools/testing/selftests/mm/memfd_secret.c
> index c55d84c5e613..dd08a3a1ef14 100644
> --- a/tools/testing/selftests/mm/memfd_secret.c
> +++ b/tools/testing/selftests/mm/memfd_secret.c
> @@ -145,7 +145,7 @@ static void try_ptrace(int fd, int pipefd[2])
>  		exit(KSFT_FAIL);
>  	}
>
> -	if (ptrace(PTRACE_PEEKDATA, ppid, mem, 0))
> +	if (ptrace(PTRACE_PEEKDATA, ppid, mem, 0) == -1)
>  		exit(KSFT_PASS);

From https://man7.org/linux/man-pages/man2/ptrace.2.html#RETURN_VALUE :

       On success, the PTRACE_PEEK* operations return the requested data
       (but see NOTES)...

       On error, all operations return -1, ...

       ...

       PTRACE_PEEKTEXT
       PTRACE_PEEKDATA
              Read a word at the address addr in the tracee's memory,
              returning the word as the result of the ptrace() call.
              Linux does not have separate text and data address spaces,
              so these two operations are currently equivalent.  (data is
              ignored; but see NOTES.)

OK so we expect this to fail as otherwise that'd be a violation of secretmem.

Feels like maybe we should add a comment to that effect? :)


>
>  	exit(KSFT_FAIL);
> --
> 2.54.0
>

--
Cheers, Lorenzo

  parent reply	other threads:[~2026-09-08  9:03 UTC|newest]

Thread overview: 4+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-08  2:51 Hongfu Li
2026-09-08  8:08 ` Mike Rapoport
2026-09-08  9:03 ` Lorenzo Stoakes (ARM) [this message]
2026-09-09  6:45   ` Hongfu Li

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=ap_N7u5DbIk4FEeZ@gremlin \
    --to=ljs@kernel.org \
    --cc=James.Bottomley@hansenpartnership.com \
    --cc=akpm@linux-foundation.org \
    --cc=david@kernel.org \
    --cc=hongfu.li@linux.dev \
    --cc=liam@infradead.org \
    --cc=lihongfu@kylinos.cn \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-kselftest@vger.kernel.org \
    --cc=linux-mm@kvack.org \
    --cc=mhocko@suse.com \
    --cc=rppt@kernel.org \
    --cc=shuah@kernel.org \
    --cc=surenb@google.com \
    --cc=vbabka@kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®