From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from kanga.kvack.org (kanga.kvack.org [205.233.56.17]) by smtp.lore.kernel.org (Postfix) with ESMTP id 743A5C433EF for ; Thu, 9 Jun 2022 12:28:00 +0000 (UTC) Received: by kanga.kvack.org (Postfix) id F1B838D000C; Thu, 9 Jun 2022 08:27:59 -0400 (EDT) Received: by kanga.kvack.org (Postfix, from userid 40) id ECC2E8D0006; Thu, 9 Jun 2022 08:27:59 -0400 (EDT) X-Delivered-To: int-list-linux-mm@kvack.org Received: by kanga.kvack.org (Postfix, from userid 63042) id D944C8D000C; Thu, 9 Jun 2022 08:27:59 -0400 (EDT) X-Delivered-To: linux-mm@kvack.org Received: from relay.hostedemail.com (smtprelay0013.hostedemail.com [216.40.44.13]) by kanga.kvack.org (Postfix) with ESMTP id C891A8D0006 for ; Thu, 9 Jun 2022 08:27:59 -0400 (EDT) Received: from smtpin30.hostedemail.com (a10.router.float.18 [10.200.18.1]) by unirelay11.hostedemail.com (Postfix) with ESMTP id 9679B80F01 for ; Thu, 9 Jun 2022 12:27:59 +0000 (UTC) X-FDA: 79558624278.30.647A6C1 Received: from mail-yb1-f173.google.com (mail-yb1-f173.google.com [209.85.219.173]) by imf25.hostedemail.com (Postfix) with ESMTP id 26B3DA007D for ; Thu, 9 Jun 2022 12:27:59 +0000 (UTC) Received: by mail-yb1-f173.google.com with SMTP id r82so41447567ybc.13 for ; Thu, 09 Jun 2022 05:27:58 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20210112; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=a07Ug1Brw0ahaT/nA7crXS0MElk/cywUhm7ShD7oUjM=; b=YccLDNASXEYbwewBVR99kh5pf1+x7X/eNYpluDIkH5Zkjjf1fkJer+1cnzltUggsJU fNWPFtRGWziHE06jnd072i4qEcD3/CJpfR39Sp2zDekl8vF7MDSKtkeqBPV1Eh9ht/v9 2w1f0J+4QEjIl/w6+0y+hvhYldw0MYV1eUkmy2Ao/K+Jz5mB7whYMpWGNoFkJDT1KqyO 7AT8LdZybhkryMR0aRu62OmWztyaWeK8AOqaoPFi/dJ8SbtFx9Ic723wd6Edekqcrv8W K/B2ptEKalvT/9LAECNbSojLjd3uF0k8V59aICc4sohb4+t4g598gMyXiUS9ur5SXk2/ zYLg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20210112; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=a07Ug1Brw0ahaT/nA7crXS0MElk/cywUhm7ShD7oUjM=; b=5Ffu76WWK3WUA8gx4WScETZ3DM88V80260Cn+eNWv9ovq+4w7q1kP2zu2FZ212R24t R8751QmmGBEPWdQ7bGA/0nOS2RjTTDijCqQOVw0PZ+KlUquNZFb8fJaCj50Q0TK/rheC No/u1KX432wV9k5/vr/l2dG73sG2Z5MkHi/TS3G5RBfn5ZXWhUoGZXz/EkzeqE32GPeo pquAHkMTMc1wpKHOGylf6NkA2rPuR2WX93KIKhhML477s9Y5/vpgFaItZmnRSTt8twgh toywgmEC9H0quVVhsOBe8DbUT98M9zsq4zcr15HnhD+OZg5d0AzLsBs2o/OFtpSwF368 0Eug== X-Gm-Message-State: AOAM532N90wiVahNITEdtjc/uXBB/t/r9TN5S4lvj5njuDHfkI4dOSMX 9XjFGc21W/WI8RiYnWvDF6sKUlxe+OmuehKUnxT00g== X-Google-Smtp-Source: ABdhPJz9iCktdQX1tAh/BGW+89D+n/GowcL403xT6Q1bcyslGiDvIW8eLZtHkf3OTS2rGp7CKDrhb6Im7uZzpFXl2wI= X-Received: by 2002:a25:e203:0:b0:663:de4f:f233 with SMTP id h3-20020a25e203000000b00663de4ff233mr13625471ybe.168.1654777678188; Thu, 09 Jun 2022 05:27:58 -0700 (PDT) MIME-Version: 1.0 References: <20220609121709.12939-1-Jason@zx2c4.com> In-Reply-To: <20220609121709.12939-1-Jason@zx2c4.com> From: Marco Elver Date: Thu, 9 Jun 2022 14:27:21 +0200 Message-ID: Subject: Re: [PATCH] mm/kfence: select random number before taking raw lock To: "Jason A. Donenfeld" Cc: linux-mm@kvack.org, linux-kernel@vger.kernel.org, John Ogness , Alexander Potapenko , Dmitry Vyukov , Geert Uytterhoeven Content-Type: text/plain; charset="UTF-8" ARC-Seal: i=1; s=arc-20220608; d=hostedemail.com; t=1654777679; a=rsa-sha256; cv=none; b=zUy1Iy4HrHXUejh7fST0D4GCLe5Asv2ahlCoHZGivpqGxF8VNjhtaVOp01TZjb+QcjU22d zw+4RvdGGlvS7M0WMmOCYQln7fK8d+Fz3jgC5m+IEaM218Mo25VTMYGrwQKgFJMjE55ccm p/prT+pbPwfSgl0JQaIZDnufEvxN9EA= ARC-Authentication-Results: i=1; imf25.hostedemail.com; dkim=pass header.d=google.com header.s=20210112 header.b=YccLDNAS; dmarc=pass (policy=reject) header.from=google.com; spf=pass (imf25.hostedemail.com: domain of elver@google.com designates 209.85.219.173 as permitted sender) smtp.mailfrom=elver@google.com ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=hostedemail.com; s=arc-20220608; t=1654777679; h=from:from:sender:reply-to:subject:subject:date:date: message-id:message-id:to:to:cc:cc:mime-version:mime-version: content-type:content-type:content-transfer-encoding: in-reply-to:in-reply-to:references:references:dkim-signature; bh=a07Ug1Brw0ahaT/nA7crXS0MElk/cywUhm7ShD7oUjM=; b=mRJqVmpEyBSrNwxkQr1XLaWg6ODFyvSUcwzU06XHCOyWoAQgQLr2/4YROOfWsKeboRgXfg am3mfYqi0oSVlyaNoBGmXEsUvKk+ism5HXiT090TMJ8hgsUs6zwdxCmd9WXp53fa4MEmnf HZdxTuCQcKmBmdLj0lDjtpxStigUv8Q= X-Stat-Signature: rm1ronnfcqtgjwmezspp83aprrsjguh1 X-Rspam-User: X-Rspamd-Queue-Id: 26B3DA007D X-Rspamd-Server: rspam07 Authentication-Results: imf25.hostedemail.com; dkim=pass header.d=google.com header.s=20210112 header.b=YccLDNAS; dmarc=pass (policy=reject) header.from=google.com; spf=pass (imf25.hostedemail.com: domain of elver@google.com designates 209.85.219.173 as permitted sender) smtp.mailfrom=elver@google.com X-HE-Tag: 1654777679-940444 X-Bogosity: Ham, tests=bogofilter, spamicity=0.000000, version=1.2.4 Sender: owner-linux-mm@kvack.org Precedence: bulk X-Loop: owner-majordomo@kvack.org List-ID: On Thu, 9 Jun 2022 at 14:17, Jason A. Donenfeld wrote: > > The RNG uses vanilla spinlocks, not raw spinlocks, so kfence should pick > its random numbers before taking its raw spinlocks. This also has the > nice effect of doing less work inside the lock. It should fix a splat > that Geert saw with CONFIG_PROVE_RAW_LOCK_NESTING: > > dump_backtrace.part.0+0x98/0xc0 > show_stack+0x14/0x28 > dump_stack_lvl+0xac/0xec > dump_stack+0x14/0x2c > __lock_acquire+0x388/0x10a0 > lock_acquire+0x190/0x2c0 > _raw_spin_lock_irqsave+0x6c/0x94 > crng_make_state+0x148/0x1e4 > _get_random_bytes.part.0+0x4c/0xe8 > get_random_u32+0x4c/0x140 > __kfence_alloc+0x460/0x5c4 > kmem_cache_alloc_trace+0x194/0x1dc > __kthread_create_on_node+0x5c/0x1a8 > kthread_create_on_node+0x58/0x7c > printk_start_kthread.part.0+0x34/0xa8 > printk_activate_kthreads+0x4c/0x54 > do_one_initcall+0xec/0x278 > kernel_init_freeable+0x11c/0x214 > kernel_init+0x24/0x124 > ret_from_fork+0x10/0x20 > > Cc: John Ogness > Cc: Alexander Potapenko > Cc: Marco Elver > Cc: Dmitry Vyukov > Reported-by: Geert Uytterhoeven > Signed-off-by: Jason A. Donenfeld > --- > mm/kfence/core.c | 7 +++++-- > 1 file changed, 5 insertions(+), 2 deletions(-) > > diff --git a/mm/kfence/core.c b/mm/kfence/core.c > index 4e7cd4c8e687..6322b7729b50 100644 > --- a/mm/kfence/core.c > +++ b/mm/kfence/core.c > @@ -360,6 +360,9 @@ static void *kfence_guarded_alloc(struct kmem_cache *cache, size_t size, gfp_t g > unsigned long flags; > struct slab *slab; > void *addr; > + bool random_right_allocate = prandom_u32_max(2); > + bool random_fault = CONFIG_KFENCE_STRESS_TEST_FAULTS && > + !prandom_u32_max(CONFIG_KFENCE_STRESS_TEST_FAULTS); > > /* Try to obtain a free object. */ > raw_spin_lock_irqsave(&kfence_freelist_lock, flags); > @@ -404,7 +407,7 @@ static void *kfence_guarded_alloc(struct kmem_cache *cache, size_t size, gfp_t g > * is that the out-of-bounds accesses detected are deterministic for > * such allocations. > */ > - if (prandom_u32_max(2)) { > + if (random_right_allocate) { > /* Allocate on the "right" side, re-calculate address. */ > meta->addr += PAGE_SIZE - size; > meta->addr = ALIGN_DOWN(meta->addr, cache->align); > @@ -444,7 +447,7 @@ static void *kfence_guarded_alloc(struct kmem_cache *cache, size_t size, gfp_t g > if (cache->ctor) > cache->ctor(addr); > > - if (CONFIG_KFENCE_STRESS_TEST_FAULTS && !prandom_u32_max(CONFIG_KFENCE_STRESS_TEST_FAULTS)) > + if (random_fault) The compiler should elide this branch entirely if CONFIG_KFENCE_STRESS_TEST_FAULTS=0, but not sure it'll always do so now. My suggestion is to make both new bools consts, to help out the compiler a little. Otherwise looks good, thanks for the quick fix!