From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from bombadil.infradead.org (bombadil.infradead.org [198.137.202.133]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.lore.kernel.org (Postfix) with ESMTPS id 7E281D2A542 for ; Wed, 16 Oct 2024 19:17:12 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.infradead.org; s=bombadil.20210309; h=Sender:List-Subscribe:List-Help :List-Post:List-Archive:List-Unsubscribe:List-Id:Cc:To:In-Reply-To:References :Message-Id:Content-Transfer-Encoding:Content-Type:MIME-Version:Subject:Date: From:Reply-To:Content-ID:Content-Description:Resent-Date:Resent-From: Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:List-Owner; bh=2a7utj1us/9lnZXTawuuUKU0Cbi3LZiJV4V0TC6iOUc=; b=R/3oAC2n3LRJKnK5aTOugOrMuC BDnV0LnfmaKwkGiGWzNKupkKMXBiQ4GkXsvDrDpVfC4iUqHlzTteAM05dMhKAdhSyqO/fBIf3WmeT 8/+bA42VgPlA6Xqtl66JKcAEZTna8pV+dsR9E3SZC20/QSG5vqMkuQxxBMJObdlfpSH+35NxVUka7 tZTBUCR2YaacVaa3RnFlVU8SrUpylgZd3PiUeRE9+HlcimQIZKeAupmfvuS4cwy1tDdCMjkiijE7Q jFNnuLIy6GnCj9qW0t6BVho/L57pyQRg7rXE9pllGCIBE3g6/W0zqj4UoiWW/QhYwKzpXw1oq6nCC 0s3z1vuQ==; Received: from localhost ([::1] helo=bombadil.infradead.org) by bombadil.infradead.org with esmtp (Exim 4.98 #2 (Red Hat Linux)) id 1t19Vz-0000000CmZ2-3YU9; Wed, 16 Oct 2024 19:16:59 +0000 Received: from mail-lf1-x12f.google.com ([2a00:1450:4864:20::12f]) by bombadil.infradead.org with esmtps (Exim 4.98 #2 (Red Hat Linux)) id 1t19UY-0000000CmVW-3WbV for linux-arm-kernel@lists.infradead.org; Wed, 16 Oct 2024 19:15:32 +0000 Received: by mail-lf1-x12f.google.com with SMTP id 2adb3069b0e04-539ebb5a20aso170867e87.2 for ; Wed, 16 Oct 2024 12:15:29 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linaro.org; s=google; t=1729106128; x=1729710928; darn=lists.infradead.org; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :mime-version:subject:date:from:from:to:cc:subject:date:message-id :reply-to; bh=2a7utj1us/9lnZXTawuuUKU0Cbi3LZiJV4V0TC6iOUc=; b=MJDCjSg+/CbRbLxCi6eOUaDPX6G3HSYYF1g14tB1I5IncbOKBK8zHFX29sVS6HggiM wNjFLuUPVKe3mV8PitP64ByjEyJa555QCB1SufJ68lmht4s/88/pJSJB8YfTMHxwYYH3 eFdQymi0nhZmqTlYZNGYvOYw4454o/0z13kIHTCvakynKJbXf40UxN/FG09/9oXa8ZED r/PWt2L4dvgMwu0KQVgq5matX10SPHPf5aRaQvtX49n/ou+IVZj+acN15cH5qp2w4aEi yKGgLfkjjQXyEiOh4cuAbRrWSfAujb+/wh6PBZqhwWWWnTOJqxupsk2d6mj4zE6KsP0Q RhVQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1729106128; x=1729710928; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :mime-version:subject:date:from:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to; bh=2a7utj1us/9lnZXTawuuUKU0Cbi3LZiJV4V0TC6iOUc=; b=WvQ6+gE4FJeS+7H4t4qwRjPnrgsuMxfoj1bvBNyIChR7LpPZCwiF4cmIFtX7hbfabf ZU9mgjA3i6cFq7qIIj9M9VR0lOy+KQsv2aGQUMEm0F19ns/NrA4yLxCypUXnxaR0u2qI 95kdD4awAlzQ6aTgOqbcwf/jubwwGw7+cKd5CUD37MP5GjoMmAVWL/AzwggsQf2loO3v d01+tU7WX+P6JO5jR+6XuBv2Bb3uekjFL+tniBcBJvfT+a7YzxWjigCY5cLRrntHlVt5 pWQCY/WjGviIJuXknbC3/s3HAPFZUr99XJpydB7Ab6mxkRXS9alrnydx5i6gwUz1GvaN i/aA== X-Forwarded-Encrypted: i=1; AJvYcCXKGBf9F9MmHSMIy5QsKL9ORYb3yI3Dz3G7pMDYCh9Lz6A6xL97/DXItzYghsI3J2YbprO7yUruAPm+LmXhPkp2@lists.infradead.org X-Gm-Message-State: AOJu0YwnjoDzdjfVMJCD/wZlhCN3u/7V5hdWGPz0+VDSyqo0raE69fhZ HBhGTz+sA3eYYC0JH/z7bcSTJQVq43SeTJDNb7Ds33R7zV/+ySw1TS91aYoN/vA= X-Google-Smtp-Source: AGHT+IFAj8Ea2dpRo1IIuxxSfFFS234dRMcc3il1+NZTcaFoDWsZPFDJUgQLrSM/ke9sKJKEX3eFJg== X-Received: by 2002:a05:6512:b85:b0:539:d428:fbd1 with SMTP id 2adb3069b0e04-539e5728fc9mr6738750e87.55.1729106128074; Wed, 16 Oct 2024 12:15:28 -0700 (PDT) Received: from lino.lan ([85.235.12.238]) by smtp.gmail.com with ESMTPSA id 2adb3069b0e04-53a00013cffsm531184e87.278.2024.10.16.12.15.27 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 16 Oct 2024 12:15:27 -0700 (PDT) From: Linus Walleij Date: Wed, 16 Oct 2024 21:15:21 +0200 Subject: [PATCH v2 1/2] ARM: ioremap: Sync PGDs for VMALLOC shadow MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: 7bit Message-Id: <20241016-arm-kasan-vmalloc-crash-v2-1-0a52fd086eef@linaro.org> References: <20241016-arm-kasan-vmalloc-crash-v2-0-0a52fd086eef@linaro.org> In-Reply-To: <20241016-arm-kasan-vmalloc-crash-v2-0-0a52fd086eef@linaro.org> To: Clement LE GOFFIC , Russell King , Kees Cook , AngeloGioacchino Del Regno , Mark Brown , Mark Rutland , Ard Biesheuvel Cc: Antonio Borneo , linux-stm32@st-md-mailman.stormreply.com, linux-arm-kernel@lists.infradead.org, Linus Walleij , stable@vger.kernel.org X-Mailer: b4 0.14.0 X-CRM114-Version: 20100106-BlameMichelson ( TRE 0.8.0 (BSD) ) MR-646709E3 X-CRM114-CacheID: sfid-20241016_121530_944524_698BF57C X-CRM114-Status: GOOD ( 15.52 ) X-BeenThere: linux-arm-kernel@lists.infradead.org X-Mailman-Version: 2.1.34 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Sender: "linux-arm-kernel" Errors-To: linux-arm-kernel-bounces+linux-arm-kernel=archiver.kernel.org@lists.infradead.org When sync:ing the VMALLOC area to other CPUs, make sure to also sync the KASAN shadow memory for the VMALLOC area, so that we don't get stale entries for the shadow memory in the top level PGD. Since we are now copying PGDs in two instances, create a helper function named memcpy_pgd() to do the actual copying, and create a helper to map the addresses of VMALLOC_START and VMALLOC_END into the corresponding shadow memory. Cc: stable@vger.kernel.org Fixes: 565cbaad83d8 ("ARM: 9202/1: kasan: support CONFIG_KASAN_VMALLOC") Link: https://lore.kernel.org/linux-arm-kernel/a1a1d062-f3a2-4d05-9836-3b098de9db6d@foss.st.com/ Reported-by: Clement LE GOFFIC Suggested-by: Mark Rutland Suggested-by: Russell King (Oracle) Signed-off-by: Linus Walleij --- arch/arm/mm/ioremap.c | 25 +++++++++++++++++++++---- 1 file changed, 21 insertions(+), 4 deletions(-) diff --git a/arch/arm/mm/ioremap.c b/arch/arm/mm/ioremap.c index 794cfea9f9d4..94586015feed 100644 --- a/arch/arm/mm/ioremap.c +++ b/arch/arm/mm/ioremap.c @@ -23,6 +23,7 @@ */ #include #include +#include #include #include #include @@ -115,16 +116,32 @@ int ioremap_page(unsigned long virt, unsigned long phys, } EXPORT_SYMBOL(ioremap_page); +static unsigned long arm_kasan_mem_to_shadow(unsigned long addr) +{ + return (unsigned long)kasan_mem_to_shadow((void *)addr); +} + +static void memcpy_pgd(struct mm_struct *mm, unsigned long start, + unsigned long end) +{ + memcpy(pgd_offset(mm, start), pgd_offset_k(start), + sizeof(pgd_t) * (pgd_index(end) - pgd_index(start))); +} + void __check_vmalloc_seq(struct mm_struct *mm) { int seq; do { seq = atomic_read(&init_mm.context.vmalloc_seq); - memcpy(pgd_offset(mm, VMALLOC_START), - pgd_offset_k(VMALLOC_START), - sizeof(pgd_t) * (pgd_index(VMALLOC_END) - - pgd_index(VMALLOC_START))); + memcpy_pgd(mm, VMALLOC_START, VMALLOC_END); + if (IS_ENABLED(CONFIG_KASAN_VMALLOC)) { + unsigned long start = + arm_kasan_mem_to_shadow(VMALLOC_START); + unsigned long end = + arm_kasan_mem_to_shadow(VMALLOC_END); + memcpy_pgd(mm, start, end); + } /* * Use a store-release so that other CPUs that observe the * counter's new value are guaranteed to see the results of the -- 2.46.2