From mboxrd@z Thu Jan 1 00:00:00 1970 From: Mathieu Desnoyers Subject: Re: [RFC PATCH for 4.18 1/2] rseq: validate rseq_cs fields are < TASK_SIZE Date: Fri, 29 Jun 2018 09:55:43 -0400 (EDT) Message-ID: <820874666.9567.1530280543568.JavaMail.zimbra@efficios.com> References: <20180628162359.9054-1-mathieu.desnoyers@efficios.com> Mime-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 7bit Return-path: In-Reply-To: Sender: linux-kernel-owner@vger.kernel.org To: Andy Lutomirski Cc: Linus Torvalds , Thomas Gleixner , linux-kernel , linux-api , Peter Zijlstra , "Paul E. McKenney" , Boqun Feng , Dave Watson , Paul Turner , Andrew Morton , Russell King , Ingo Molnar , "H. Peter Anvin" , Andi Kleen , Chris Lameter , Ben Maurer , rostedt , Josh Triplett , Catalin Marinas , Will Deacon , Michael List-Id: linux-api@vger.kernel.org ----- On Jun 28, 2018, at 7:29 PM, Andy Lutomirski luto@kernel.org wrote: > On Thu, Jun 28, 2018 at 2:22 PM, Linus Torvalds > wrote: >> On Thu, Jun 28, 2018 at 1:23 PM Andy Lutomirski wrote: >>> >>> This is okay with me for a fix outside the merge window. Can you do a >>> followup for the next merge window that fixes it better, though? In >>> particular, TASK_SIZE is generally garbage. I think a better fix >>> would be something like adding a new arch-overridable helper like: >>> >>> static inline unsigned long current_max_user_addr(void) { return TASK_SIZE; } >> >> We already have that. It's called "user_addr_max()". > > Nah, that one is more or less equivalent to TASK_SIZE_MAX, except that > it's different if set_fs() is used. So which one would be right in this case ? AFAIU we want to ensure we don't populate regs->ip with a bogus address that would make SYSRET or other return to userspace instructions explode. Is that guaranteed by TASK_SIZE or TASK_SIZE_MAX (aliased by user_addr_max()) ? Thanks, Mathieu -- Mathieu Desnoyers EfficiOS Inc. http://www.efficios.com