From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1754925AbdKGNGX (ORCPT ); Tue, 7 Nov 2017 08:06:23 -0500 Received: from mga14.intel.com ([192.55.52.115]:6476 "EHLO mga14.intel.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1751624AbdKGNGW (ORCPT ); Tue, 7 Nov 2017 08:06:22 -0500 X-ExtLoop1: 1 X-IronPort-AV: E=Sophos;i="5.44,358,1505804400"; d="scan'208";a="918490944" From: "Kirill A. Shutemov" To: Ingo Molnar , Linus Torvalds , x86@kernel.org, Thomas Gleixner , "H. Peter Anvin" Cc: Andy Lutomirski , Cyrill Gorcunov , Nicholas Piggin , linux-mm@kvack.org, linux-kernel@vger.kernel.org, "Kirill A. Shutemov" Subject: [PATCH] x86/mm: Do not allow non-MAP_FIXED mapping across DEFAULT_MAP_WINDOW border Date: Tue, 7 Nov 2017 16:05:39 +0300 Message-Id: <20171107130539.52676-1-kirill.shutemov@linux.intel.com> X-Mailer: git-send-email 2.14.2 Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org In case of 5-level paging, we don't put any mapping above 47-bit, unless userspace explicitly asked for it. Userspace can ask for allocation from full address space by specifying hint address above 47-bit. Nicholas noticed that current implementation violates this interface: we can get vma partly in high addresses if we ask for a mapping at very end of 47-bit address space. Let's make sure that, when consider hint address for non-MAP_FIXED mapping, start and end of resulting vma are on the same side of 47-bit border. Signed-off-by: Kirill A. Shutemov Reported-by: Nicholas Piggin --- arch/x86/kernel/sys_x86_64.c | 12 ++++++++++-- 1 file changed, 10 insertions(+), 2 deletions(-) diff --git a/arch/x86/kernel/sys_x86_64.c b/arch/x86/kernel/sys_x86_64.c index a63fe77b3217..64b1a0d22247 100644 --- a/arch/x86/kernel/sys_x86_64.c +++ b/arch/x86/kernel/sys_x86_64.c @@ -198,11 +198,19 @@ arch_get_unmapped_area_topdown(struct file *filp, const unsigned long addr0, /* requesting a specific address */ if (addr) { addr = PAGE_ALIGN(addr); + if (TASK_SIZE - len < addr) + goto get_unmapped_area; + + /* The mapping shouldn't cross DEFAULT_MAP_WINDOW border */ + if ((addr > DEFAULT_MAP_WINDOW) != + (addr + len > DEFAULT_MAP_WINDOW)) + goto get_unmapped_area; + vma = find_vma(mm, addr); - if (TASK_SIZE - len >= addr && - (!vma || addr + len <= vm_start_gap(vma))) + if (!vma || addr + len <= vm_start_gap(vma)) return addr; } +get_unmapped_area: info.flags = VM_UNMAPPED_AREA_TOPDOWN; info.length = len; -- 2.14.2