From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1752773AbZJZPZP (ORCPT ); Mon, 26 Oct 2009 11:25:15 -0400 Received: (majordomo@vger.kernel.org) by vger.kernel.org id S1751807AbZJZPZO (ORCPT ); Mon, 26 Oct 2009 11:25:14 -0400 Received: from hera.kernel.org ([140.211.167.34]:60975 "EHLO hera.kernel.org" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1751711AbZJZPZN (ORCPT ); Mon, 26 Oct 2009 11:25:13 -0400 Date: Mon, 26 Oct 2009 15:24:35 GMT From: tip-bot for Jiri Slaby Cc: linux-kernel@vger.kernel.org, horms@verge.net.au, hpa@zytor.com, mingo@redhat.com, jirislaby@gmail.com, lethal@linux-sh.org, vgoyal@redhat.com, ebiederm@xmission.com, tglx@linutronix.de, mingo@elte.hu Reply-To: mingo@redhat.com, hpa@zytor.com, horms@verge.net.au, linux-kernel@vger.kernel.org, jirislaby@gmail.com, lethal@linux-sh.org, vgoyal@redhat.com, ebiederm@xmission.com, tglx@linutronix.de, mingo@elte.hu In-Reply-To: <1256551903-30567-1-git-send-email-jirislaby@gmail.com> References: <1256551903-30567-1-git-send-email-jirislaby@gmail.com> To: linux-tip-commits@vger.kernel.org Subject: [tip:x86/urgent] x86: crash_dump: Fix non-pae kdump kernel memory accesses Message-ID: Git-Commit-ID: 72ed7de74e8f0fad0d8e567ae1f987b740accb3f X-Mailer: tip-git-log-daemon MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Disposition: inline Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org Commit-ID: 72ed7de74e8f0fad0d8e567ae1f987b740accb3f Gitweb: http://git.kernel.org/tip/72ed7de74e8f0fad0d8e567ae1f987b740accb3f Author: Jiri Slaby AuthorDate: Mon, 26 Oct 2009 11:11:43 +0100 Committer: Ingo Molnar CommitDate: Mon, 26 Oct 2009 12:38:59 +0100 x86: crash_dump: Fix non-pae kdump kernel memory accesses Non-PAE 32-bit dump kernels may wrap an address around 4G and poke unwanted space. ptes there are 32-bit long, and since pfn << PAGE_SIZE may exceed this limit, high pfn bits are cropped and wrong address mapped by kmap_atomic_pfn in copy_oldmem_page. Don't allow this behavior in non-PAE kdump kernels by checking pfns passed into copy_oldmem_page. In the case of failure, userspace process gets EFAULT. [v2] - fix comments - move ifdefs inside the function Signed-off-by: Jiri Slaby Cc: Vivek Goyal Cc: Eric W. Biederman Cc: Simon Horman Cc: Paul Mundt LKML-Reference: <1256551903-30567-1-git-send-email-jirislaby@gmail.com> Signed-off-by: Ingo Molnar --- arch/x86/kernel/crash_dump_32.c | 19 +++++++++++++++++++ 1 files changed, 19 insertions(+), 0 deletions(-) diff --git a/arch/x86/kernel/crash_dump_32.c b/arch/x86/kernel/crash_dump_32.c index f7cdb3b..cd97ce1 100644 --- a/arch/x86/kernel/crash_dump_32.c +++ b/arch/x86/kernel/crash_dump_32.c @@ -16,6 +16,22 @@ static void *kdump_buf_page; /* Stores the physical address of elf header of crash image. */ unsigned long long elfcorehdr_addr = ELFCORE_ADDR_MAX; +static inline bool is_crashed_pfn_valid(unsigned long pfn) +{ +#ifndef CONFIG_X86_PAE + /* + * non-PAE kdump kernel executed from a PAE one will crop high pte + * bits and poke unwanted space counting again from address 0, we + * don't want that. pte must fit into unsigned long. In fact the + * test checks high 12 bits for being zero (pfn will be shifted left + * by PAGE_SHIFT). + */ + return pte_pfn(pfn_pte(pfn, __pgprot(0))) == pfn; +#else + return true; +#endif +} + /** * copy_oldmem_page - copy one page from "oldmem" * @pfn: page frame number to be copied @@ -41,6 +57,9 @@ ssize_t copy_oldmem_page(unsigned long pfn, char *buf, if (!csize) return 0; + if (!is_crashed_pfn_valid(pfn)) + return -EFAULT; + vaddr = kmap_atomic_pfn(pfn, KM_PTE0); if (!userbuf) {