All of lore.kernel.org
 help / color / mirror / Atom feed
From: Harry Yoo <harry@kernel.org>
To: Karl Mehltretter <kmehltretter@gmail.com>
Cc: Vlastimil Babka <vbabka@kernel.org>,
	 Andrew Morton <akpm@linux-foundation.org>,
	Rasmus Villemoes <linux@rasmusvillemoes.dk>,
	 Hao Li <hao.li@linux.dev>, Christoph Lameter <cl@gentwo.org>,
	 David Rientjes <rientjes@google.com>,
	Roman Gushchin <roman.gushchin@linux.dev>,
	 Catalin Marinas <catalin.marinas@arm.com>,
	Kees Cook <kees@kernel.org>,
	 "Gustavo A . R . Silva" <gustavoars@kernel.org>,
	Arnd Bergmann <arnd@arndb.de>,
	 Greg Kroah-Hartman <gregkh@linuxfoundation.org>,
	Shuah Khan <shuah@kernel.org>,
	 Nathan Chancellor <nathan@kernel.org>,
	Nick Desaulniers <ndesaulniers@google.com>,
	 Bill Wendling <morbo@google.com>,
	Justin Stitt <justinstitt@google.com>,
	 linux-hardening@vger.kernel.org, linux-mm@kvack.org,
	linux-kselftest@vger.kernel.org,  linux-kernel@vger.kernel.org,
	llvm@lists.linux.dev
Subject: Re: [PATCH v3 0/5] slab: ZERO_SIZE_PTR alignment and ERR_PTR hardening
Date: Fri, 4 Sep 2026 12:25:59 +0100	[thread overview]
Message-ID: <apqmVDiyGJWnEnp8@nixos> (raw)
In-Reply-To: <20260903203720.63689-1-kmehltretter@gmail.com>

On Thu, Sep 03, 2026 at 10:37:15PM +0200, Karl Mehltretter wrote:
> The kmalloc entry points promise ARCH_KMALLOC_MINALIGN alignment but
> return (void *)16 for zero-size requests. Patch 1 aligns the sentinel
> to that promise.
> 
> Patch 2 limits ZERO_OR_NULL_PTR() to NULL and ZERO_SIZE_PTR. Patch 3
> handles ERR_PTR explicitly in kfree() and hardened usercopy, without
> giving ERR_PTR special meaning to other users such as krealloc(). The
> old helper did not match ERR_PTR values either; patch 3 addresses the
> adjacent hardening concern raised during review.

I don't understand why v3 of this patchset suddenly implements
hardening for kfree() and usercopy to handle ERR_PTR().

The address range for 'zero or NULL PTR' range and ERR_PTR() do not
overlap. The bugfixes and hardening patches are irrelevant.
It should be a separate series?

Also usercopy.c changes go through the hardening tree, slub.c and
slub_kunit.c changes go through the slab tree, and LKDTM has its own
tree. Patch 3 and 5 touch files across multiple trees, which can be
avoided.

> If backported, patches 1 and 2 should be taken together.
>
> Patch 4 adds zero-size KUnit coverage; patch 5 adds ERR_PTR KUnit,
> LKDTM, and kselftest coverage, which is why Arnd, Greg, Shuah, and
> linux-kselftest@vger.kernel.org are newly copied on v3.
> 
> Tested on 940de590b839:
> 
>   - GCC 15.2 UML slub_test: 10 passed, 2 skipped, including
>     test_zero_size_alloc and test_kfree_err_ptr; NULL and ZERO_SIZE_PTR
>     produced no warning, and the expected kfree(ERR_PTR) warning was
>     suppressed and counted
>   - GCC 15.2 matched x86_64 builds immediately before and after patch 3:
>     kfree grew by 15 bytes; __check_object_size gained a 13-byte
>     comparison on its normal path and a 23-byte cold abort path
>   - GCC 15.2 x86_64 defconfig with HARDENED_USERCOPY: build and normal
>     QEMU boot passed; the committed LKDTM selftest matched the distinct
>     ERR_PTR diagnostic after reaching usercopy_abort()
>   - Clang 21.1.8 armv5 UBSAN_ALIGNMENT: no alignment-assumption or
>     slab.h report; generated code retains the exact comparison and
>     single evaluation
>   - GCC 15.2 MIPS64 big-endian noncoherent build passed with
>     ARCH_KMALLOC_MINALIGN equal to 128
>   - Microchip SAM9X75 hardware (armv5, ARCH_KMALLOC_MINALIGN=32):
>     ZERO_SIZE_PTR was 0x20; zero-size allocation, ksize(), and free
>     passed with no boot splats
>   - Raspberry Pi 400 hardware (arm64, Cortex-A72,
>     ARCH_KMALLOC_MINALIGN=8): ZERO_SIZE_PTR remained 0x10; the ERR_PTR
>     KUnit and hardened-usercopy rejection paths passed with no boot
>     splats; the revised diagnostic was retested under x86_64 QEMU
> 
> ---
> v2 -> v3:
> 
>   - document why patch 2's sentinel-derived low-address window in hardened
>     usercopy was incidental
>   - add new patch 3 to warn and return when kfree() receives an ERR_PTR
>     and reject ERR_PTR values in hardened usercopy
>   - replace patch 4's pointer-cast static assertion with a run-time KUnit
>     expectation
>   - add new patch 5 with KUnit and LKDTM coverage for patch 3
> 
> v2: https://lore.kernel.org/r/20260811141240.62519-1-kmehltretter@gmail.com
> v1: https://lore.kernel.org/r/20260808105622.62026-1-kmehltretter@gmail.com
> RFC: https://lore.kernel.org/r/20260712120728.96628-1-kmehltretter@gmail.com
> 
> Karl Mehltretter (5):
>   slab: align ZERO_SIZE_PTR to ARCH_KMALLOC_MINALIGN
>   slab: check for ZERO_SIZE_PTR by exact match
>   slab: handle ERR_PTR values in kfree and hardened usercopy
>   slab: test zero-size allocations in slub_kunit
>   slab: test ERR_PTR handling in kfree and hardened usercopy
> 
>  drivers/misc/lkdtm/usercopy.c           | 27 +++++++++++
>  include/linux/slab.h                    | 20 ++++++--
>  lib/tests/slub_kunit.c                  | 61 +++++++++++++++++++++++++
>  mm/slub.c                               |  3 ++
>  mm/usercopy.c                           |  3 ++
>  tools/testing/selftests/lkdtm/tests.txt |  1 +
>  6 files changed, 112 insertions(+), 3 deletions(-)
> 
> 
> base-commit: 940de590b839f71d6dc846160534bf202401b8b7
> -- 
> 2.53.0

      parent reply	other threads:[~2026-09-04 11:26 UTC|newest]

Thread overview: 8+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-03 20:37 [PATCH v3 0/5] slab: ZERO_SIZE_PTR alignment and ERR_PTR hardening Karl Mehltretter
2026-09-03 20:37 ` [PATCH v3 1/5] slab: align ZERO_SIZE_PTR to ARCH_KMALLOC_MINALIGN Karl Mehltretter
2026-09-03 20:37 ` [PATCH v3 2/5] slab: check for ZERO_SIZE_PTR by exact match Karl Mehltretter
2026-09-03 20:37 ` [PATCH v3 3/5] slab: handle ERR_PTR values in kfree and hardened usercopy Karl Mehltretter
2026-09-04  9:01   ` Vlastimil Babka (SUSE)
2026-09-03 20:37 ` [PATCH v3 4/5] slab: test zero-size allocations in slub_kunit Karl Mehltretter
2026-09-03 20:37 ` [PATCH v3 5/5] slab: test ERR_PTR handling in kfree and hardened usercopy Karl Mehltretter
2026-09-04 11:25 ` Harry Yoo [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=apqmVDiyGJWnEnp8@nixos \
    --to=harry@kernel.org \
    --cc=akpm@linux-foundation.org \
    --cc=arnd@arndb.de \
    --cc=catalin.marinas@arm.com \
    --cc=cl@gentwo.org \
    --cc=gregkh@linuxfoundation.org \
    --cc=gustavoars@kernel.org \
    --cc=hao.li@linux.dev \
    --cc=justinstitt@google.com \
    --cc=kees@kernel.org \
    --cc=kmehltretter@gmail.com \
    --cc=linux-hardening@vger.kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-kselftest@vger.kernel.org \
    --cc=linux-mm@kvack.org \
    --cc=linux@rasmusvillemoes.dk \
    --cc=llvm@lists.linux.dev \
    --cc=morbo@google.com \
    --cc=nathan@kernel.org \
    --cc=ndesaulniers@google.com \
    --cc=rientjes@google.com \
    --cc=roman.gushchin@linux.dev \
    --cc=shuah@kernel.org \
    --cc=vbabka@kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.