mirror of
https://github.com/BobTheBlinker/android_kernel_motorola_sm6375.git
synced 2026-10-05 19:31:57 -04:00
ANDROID: kasan: fix interoperability with KFENCE
MTE-related KASAN changes were preceded by noticeable KASAN refactorings that were backported to android12-5.10, but not android12-5.4. As a result, some last-minute mm changes fixing "kfence, kasan: make KFENCE compatible with KASAN" (https://android.googlesource.com/kernel/common/+/f03825db4d6834a9d97e96eee2404a36ca79dafa) did not make it to android12-5.4. Given that they do not exist as separate upstream commits and do not apply cleanly to 5.4 kernels, reimplement them. These changes boil down to skipping KASAN poisoning for KFENCE-allocated objects and to resetting the object tag in __kasan_kmalloc(). Bug: 172318110 Bug: 190593700 Signed-off-by: Alexander Potapenko <glider@google.com> Change-Id: I117ea37a1d41514a3c5beaf87386bb5f2f0046c8
This commit is contained in:
parent
1d3c702cee
commit
9484ee8820
1 changed files with 13 additions and 1 deletions
|
|
@ -141,6 +141,10 @@ void kasan_poison_shadow(const void *address, size_t size, u8 value)
|
|||
*/
|
||||
address = reset_tag(address);
|
||||
|
||||
/* Skip KFENCE memory if called explicitly outside of sl*b. */
|
||||
if (is_kfence_address(address))
|
||||
return;
|
||||
|
||||
shadow_start = kasan_mem_to_shadow(address);
|
||||
shadow_end = kasan_mem_to_shadow(address + size);
|
||||
|
||||
|
|
@ -158,6 +162,14 @@ void kasan_unpoison_shadow(const void *address, size_t size)
|
|||
*/
|
||||
address = reset_tag(address);
|
||||
|
||||
/*
|
||||
* Skip KFENCE memory if called explicitly outside of sl*b. Also note
|
||||
* that calls to ksize(), where size is not a multiple of machine-word
|
||||
* size, would otherwise poison the invalid portion of the word.
|
||||
*/
|
||||
if (is_kfence_address(address))
|
||||
return;
|
||||
|
||||
kasan_poison_shadow(address, size, tag);
|
||||
|
||||
if (size & KASAN_SHADOW_MASK) {
|
||||
|
|
@ -497,7 +509,7 @@ static void *__kasan_kmalloc(struct kmem_cache *cache, const void *object,
|
|||
if (unlikely(object == NULL))
|
||||
return NULL;
|
||||
|
||||
if (is_kfence_address(object))
|
||||
if (is_kfence_address(kasan_reset_tag(object)))
|
||||
return (void *)object;
|
||||
|
||||
redzone_start = round_up((unsigned long)(object + size),
|
||||
|
|
|
|||
Loading…
Reference in a new issue