All of lore.kernel.org
 help / color / mirror / Atom feed
From: Oleg Nesterov <oleg@redhat.com>
To: Sven Schnelle <svens@linux.ibm.com>,
	Andrew Morton <akpm@linux-foundation.org>
Cc: Michael Ellerman <mpe@ellerman.id.au>,
	Masami Hiramatsu <mhiramat@kernel.org>,
	Peter Zijlstra <peterz@infradead.org>,
	Ingo Molnar <mingo@redhat.com>,
	Arnaldo Carvalho de Melo <acme@kernel.org>,
	Namhyung Kim <namhyung@kernel.org>,
	Mark Rutland <mark.rutland@arm.com>,
	Alexander Shishkin <alexander.shishkin@linux.intel.com>,
	Jiri Olsa <jolsa@kernel.org>, Ian Rogers <irogers@google.com>,
	Adrian Hunter <adrian.hunter@intel.com>,
	"Liang, Kan" <kan.liang@linux.intel.com>,
	Linus Torvalds <torvalds@linux-foundation.org>,
	linux-kernel@vger.kernel.org, linux-trace-kernel@vger.kernel.org,
	linux-perf-users@vger.kernel.org
Subject: Re: [PATCH] uprobes: use vm_special_mapping close() functionality
Date: Wed, 11 Sep 2024 11:57:51 +0200	[thread overview]
Message-ID: <20240911095751.GA20308@redhat.com> (raw)
In-Reply-To: <20240911094401.GA19080@redhat.com>

I guess VM_SEALED could help, but it depends on CONFIG_64BIT


On 09/11, Oleg Nesterov wrote:
>
> On 09/03, Sven Schnelle wrote:
> >
> > +static void uprobe_clear_state(const struct vm_special_mapping *sm, struct vm_area_struct *vma)
> > +{
> > +	struct xol_area *area = container_of(vma->vm_private_data, struct xol_area, xol_mapping);
> > +
> > +	mutex_lock(&delayed_uprobe_lock);
> > +	delayed_uprobe_remove(NULL, vma->vm_mm);
> > +	mutex_unlock(&delayed_uprobe_lock);
> > +
> > +	if (!area)
> > +		return;
> > +
> > +	put_page(area->pages[0]);
> > +	kfree(area->bitmap);
> > +	kfree(area);
> > +}
> > +
> >  static struct xol_area *__create_xol_area(unsigned long vaddr)
> >  {
> >  	struct mm_struct *mm = current->mm;
> > @@ -1481,6 +1500,7 @@ static struct xol_area *__create_xol_area(unsigned long vaddr)
> >
> >  	area->xol_mapping.name = "[uprobes]";
> >  	area->xol_mapping.fault = NULL;
> > +	area->xol_mapping.close = uprobe_clear_state;
> 
> Ah, no, we can't do this :/
> 
> A malicious application can munmap() its "[uprobes]" vma and free
> area/pages/bitmap. If this application hits the uprobe breakpoint after
> that it will use the freed memory.
> 
> And no, "mm->uprobes_state.xol_area = NULL" in uprobe_clear_state() won't
> help. Say, another thread can sleep on area.wq when munmap() is called.
> 
> Sorry, I should have realized that immediately, but I didn't :/
> 
> Andrew, this is uprobes-use-vm_special_mapping-close-functionality.patch
> in mm-stable
> 
> Oleg.


  reply	other threads:[~2024-09-11  9:58 UTC|newest]

Thread overview: 41+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2024-08-12  8:26 [PATCH v2 1/4] mm: Add optional close() to struct vm_special_mapping Michael Ellerman
2024-08-12  8:26 ` [PATCH v2 2/4] powerpc/mm: Handle VDSO unmapping via close() rather than arch_unmap() Michael Ellerman
2024-08-12  8:26 ` [PATCH v2 3/4] mm: Remove arch_unmap() Michael Ellerman
2024-08-12  8:26 ` [PATCH v2 4/4] powerpc/vdso: Refactor error handling Michael Ellerman
2024-08-12 20:41 ` [PATCH v2 1/4] mm: Add optional close() to struct vm_special_mapping Liam R. Howlett
2024-08-19 18:52 ` Nathan Chancellor
2024-08-19 19:29   ` Linus Torvalds
2024-08-19 19:51     ` Nathan Chancellor
2024-08-19 20:15       ` Linus Torvalds
2024-08-19 20:16         ` Linus Torvalds
2024-08-20  1:05           ` Andrew Morton
2024-08-20  1:11             ` Linus Torvalds
2024-08-20  6:26           ` Michael Ellerman
2024-08-20 15:31             ` Linus Torvalds
2024-08-20 21:31               ` Rob Landley
2024-08-20 21:31                 ` Linus Torvalds
2024-08-20 22:10                   ` Rob Landley
2024-08-20 23:14                     ` Linus Torvalds
2024-08-21  1:18                       ` Andrew Morton
2024-09-02 19:06   ` Sven Schnelle
2024-09-02 20:49     ` Andrew Morton
2024-09-02 21:02       ` Linus Torvalds
2024-09-03  6:27         ` Sven Schnelle
2024-09-03  7:36         ` [PATCH] uprobes: use vm_special_mapping close() functionality Sven Schnelle
2024-09-03  7:49           ` Sven Schnelle
2024-09-04  3:57             ` Michael Ellerman
2024-09-04 21:26               ` Andrew Morton
2024-09-03  9:08           ` Oleg Nesterov
2024-09-03  9:32             ` Sven Schnelle
2024-09-03 19:12             ` Linus Torvalds
2024-09-03 19:31               ` Sven Schnelle
2024-09-03 19:34                 ` Linus Torvalds
2024-09-03 19:32               ` Oleg Nesterov
2024-09-04  9:56               ` Oleg Nesterov
2024-09-04 10:03               ` Oleg Nesterov
2024-09-11  9:44           ` Oleg Nesterov
2024-09-11  9:57             ` Oleg Nesterov [this message]
2024-09-11 10:12               ` Oleg Nesterov
2024-09-11 13:13           ` [PATCH -mm 1/3] Revert "uprobes: use vm_special_mapping close() functionality" Oleg Nesterov
2024-09-11 13:14             ` [PATCH -mm 2/3] uprobes: introduce the global struct vm_special_mapping xol_mapping Oleg Nesterov
2024-09-11 13:14             ` [PATCH -mm 3/3] uprobes: turn xol_area->pages[2] into xol_area->page Oleg Nesterov

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20240911095751.GA20308@redhat.com \
    --to=oleg@redhat.com \
    --cc=acme@kernel.org \
    --cc=adrian.hunter@intel.com \
    --cc=akpm@linux-foundation.org \
    --cc=alexander.shishkin@linux.intel.com \
    --cc=irogers@google.com \
    --cc=jolsa@kernel.org \
    --cc=kan.liang@linux.intel.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-perf-users@vger.kernel.org \
    --cc=linux-trace-kernel@vger.kernel.org \
    --cc=mark.rutland@arm.com \
    --cc=mhiramat@kernel.org \
    --cc=mingo@redhat.com \
    --cc=mpe@ellerman.id.au \
    --cc=namhyung@kernel.org \
    --cc=peterz@infradead.org \
    --cc=svens@linux.ibm.com \
    --cc=torvalds@linux-foundation.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.