public inbox for linux-kernel@vger.kernel.org
 help / color / mirror / Atom feed
* [PATCH] x86/static_call: Fix __static_call_fixup()
@ 2023-08-15 23:08 Peter Zijlstra
  2023-08-15 23:14 ` Peter Zijlstra
                   ` (3 more replies)
  0 siblings, 4 replies; 9+ messages in thread
From: Peter Zijlstra @ 2023-08-15 23:08 UTC (permalink / raw)
  To: jpoimboe, x86
  Cc: baron, rostedt, ardb, tglx, mingo, bp, dave.hansen, x86, hpa,
	linux-kernel, christian, song, mcgrof


Christian reported spurious module crashes after some of Song's module
memory layout patches.

Turns out that if the very last instruction on the very last page of the
module is a 'JMP __x86_return_thunk' then __static_call_fixup() will
trip a fault and dies.

And while the module rework made this slightly more likely to happen,
it's always been possible.

Fixes: ee88d363d156 ("x86,static_call: Use alternative RET encoding")
Reported-by: Christian Bricart <christian@bricart.de>
Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org>
---
 arch/x86/kernel/static_call.c | 10 ++++++++++
 1 file changed, 10 insertions(+)

diff --git a/arch/x86/kernel/static_call.c b/arch/x86/kernel/static_call.c
index b70670a98597..2e67512d7104 100644
--- a/arch/x86/kernel/static_call.c
+++ b/arch/x86/kernel/static_call.c
@@ -186,6 +186,16 @@ EXPORT_SYMBOL_GPL(arch_static_call_transform);
  */
 bool __static_call_fixup(void *tramp, u8 op, void *dest)
 {
+	/*
+	 * Not all .return_sites are a static_call trampoline (most are not).
+	 * Check if the next 3 bytes are still kernel text, if not, then this
+	 * definitely is not a trampoline and we need not worry further.
+	 *
+	 * This avoids the memcmp() below tripping over pagefaults etc..
+	 */
+	if (!kernel_text_address(tramp+7))
+		return false;
+
 	if (memcmp(tramp+5, tramp_ud, 3)) {
 		/* Not a trampoline site, not our problem. */
 		return false;

^ permalink raw reply related	[flat|nested] 9+ messages in thread

end of thread, other threads:[~2023-08-17 11:48 UTC | newest]

Thread overview: 9+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2023-08-15 23:08 [PATCH] x86/static_call: Fix __static_call_fixup() Peter Zijlstra
2023-08-15 23:14 ` Peter Zijlstra
2023-08-16  0:10 ` Josh Poimboeuf
2023-08-16  9:39   ` Peter Zijlstra
2023-08-16  0:41 ` Steven Rostedt
2023-08-16  9:39   ` Peter Zijlstra
2023-08-16 10:44 ` [PATCH v2] " Peter Zijlstra
2023-08-16 21:02   ` Josh Poimboeuf
2023-08-17 11:47   ` [tip: x86/urgent] " tip-bot2 for Peter Zijlstra

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox