From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from mail-pg1-f194.google.com ([209.85.215.194]:36322 "EHLO mail-pg1-f194.google.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S2395078AbgJ0AJJ (ORCPT ); Mon, 26 Oct 2020 20:09:09 -0400 Received: by mail-pg1-f194.google.com with SMTP id z24so941275pgk.3 for ; Mon, 26 Oct 2020 17:09:09 -0700 (PDT) Subject: Re: [REGRESSION] mm: process_vm_readv testcase no longer works after compat_prcoess_vm_readv removed References: <70d5569e-4ad6-988a-e047-5d12d298684c@kernel.dk> <20201027000521.GD3576660@ZenIV.linux.org.uk> From: Jens Axboe Message-ID: <0127a542-3f93-7bd0-e00d-4a0e49846c8f@kernel.dk> Date: Mon, 26 Oct 2020 18:09:06 -0600 MIME-Version: 1.0 In-Reply-To: <20201027000521.GD3576660@ZenIV.linux.org.uk> Content-Type: text/plain; charset=utf-8 Content-Language: en-US Content-Transfer-Encoding: 7bit List-ID: To: Al Viro Cc: Kyle Huey , open list , Christoph Hellwig , Robert O'Callahan , Andrew Morton , Arnd Bergmann , David Howells , "moderated list:ARM PORT" , "maintainer:X86 ARCHITECTURE (32-BIT AND 64-BIT)" , linux-mips@vger.kernel.org, linux-parisc@vger.kernel.org, linuxppc-dev@lists.ozlabs.org, linux-s390@vger.kernel.org, sparclinux@vger.kernel.org, linux-block@vger.kernel.org, linux-scsi@vger.kernel.org, "open list:FILESYSTEMS (VFS and infrastructure)" , linux-aio@kvack.org, io-uring@vger.kernel.org, linux-arch@vger.kernel.org, linux-mm@kvack.org, netdev@vger.kernel.org, keyrings@vger.kernel.org, linux-security-module@vger.kernel.org, Linus Torvalds On 10/26/20 6:05 PM, Al Viro wrote: > On Mon, Oct 26, 2020 at 05:56:11PM -0600, Jens Axboe wrote: >> On 10/26/20 4:55 PM, Kyle Huey wrote: >>> A test program from the rr[0] test suite, vm_readv_writev[1], no >>> longer works on 5.10-rc1 when compiled as a 32 bit binary and executed >>> on a 64 bit kernel. The first process_vm_readv call (on line 35) now >>> fails with EFAULT. I have bisected this to >>> c3973b401ef2b0b8005f8074a10e96e3ea093823. >>> >>> It should be fairly straightforward to extract the test case from our >>> repository into a standalone program. >> >> Can you check with this applied? >> >> diff --git a/mm/process_vm_access.c b/mm/process_vm_access.c >> index fd12da80b6f2..05676722d9cd 100644 >> --- a/mm/process_vm_access.c >> +++ b/mm/process_vm_access.c >> @@ -273,7 +273,8 @@ static ssize_t process_vm_rw(pid_t pid, >> return rc; >> if (!iov_iter_count(&iter)) >> goto free_iov_l; >> - iov_r = iovec_from_user(rvec, riovcnt, UIO_FASTIOV, iovstack_r, false); >> + iov_r = iovec_from_user(rvec, riovcnt, UIO_FASTIOV, iovstack_r, >> + in_compat_syscall()); > > _ouch_ > > There's a bug, all right, but I'm not sure that this is all there is > to it. For now it's probably the right fix, but... Consider the fun > trying to use that from 32bit process to access the memory of 64bit > one. IOW, we might want to add an explicit flag for "force 64bit > addresses/sizes in rvec". Ouch yes good point, nice catch. -- Jens Axboe