Peter Collingbourne
60dbbd76f1
userfaultfd: do not untag user pointers
...
commit e71e2ace5721a8b921dca18b045069e7bb411277 upstream.
Patch series "userfaultfd: do not untag user pointers", v5.
If a user program uses userfaultfd on ranges of heap memory, it may end
up passing a tagged pointer to the kernel in the range.start field of
the UFFDIO_REGISTER ioctl. This can happen when using an MTE-capable
allocator, or on Android if using the Tagged Pointers feature for MTE
readiness [1].
When a fault subsequently occurs, the tag is stripped from the fault
address returned to the application in the fault.address field of struct
uffd_msg. However, from the application's perspective, the tagged
address *is* the memory address, so if the application is unaware of
memory tags, it may get confused by receiving an address that is, from
its point of view, outside of the bounds of the allocation. We observed
this behavior in the kselftest for userfaultfd [2] but other
applications could have the same problem.
Address this by not untagging pointers passed to the userfaultfd ioctls.
Instead, let the system call fail. Also change the kselftest to use
mmap so that it doesn't encounter this problem.
[1] https://source.android.com/devices/tech/debug/tagged-pointers
[2] tools/testing/selftests/vm/userfaultfd.c
This patch (of 2):
Do not untag pointers passed to the userfaultfd ioctls. Instead, let
the system call fail. This will provide an early indication of problems
with tag-unaware userspace code instead of letting the code get confused
later, and is consistent with how we decided to handle brk/mmap/mremap
in commit dcde237319e6 ("mm: Avoid creating virtual address aliases in
brk()/mmap()/mremap()"), as well as being consistent with the existing
tagged address ABI documentation relating to how ioctl arguments are
handled.
The code change is a revert of commit 7d0325749a ("userfaultfd: untag
user pointers") plus some fixups to some additional calls to
validate_range that have appeared since then.
[1] https://source.android.com/devices/tech/debug/tagged-pointers
[2] tools/testing/selftests/vm/userfaultfd.c
Link: https://lkml.kernel.org/r/20210714195437.118982-1-pcc@google.com
Link: https://lkml.kernel.org/r/20210714195437.118982-2-pcc@google.com
Link: https://linux-review.googlesource.com/id/I761aa9f0344454c482b83fcfcce547db0a25501b
Fixes: 63f0c60379 ("arm64: Introduce prctl() options to control the tagged user addresses ABI")
Signed-off-by: Peter Collingbourne <pcc@google.com>
Reviewed-by: Andrey Konovalov <andreyknvl@gmail.com>
Reviewed-by: Catalin Marinas <catalin.marinas@arm.com>
Cc: Alistair Delva <adelva@google.com>
Cc: Andrea Arcangeli <aarcange@redhat.com>
Cc: Dave Martin <Dave.Martin@arm.com>
Cc: Evgenii Stepanov <eugenis@google.com>
Cc: Lokesh Gidra <lokeshgidra@google.com>
Cc: Mitch Phillips <mitchp@google.com>
Cc: Vincenzo Frascino <vincenzo.frascino@arm.com>
Cc: Will Deacon <will@kernel.org>
Cc: William McVicker <willmcvicker@google.com>
Cc: <stable@vger.kernel.org> [5.4]
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2021-07-28 13:31:01 +02:00
..
ABI
evm: Refuse EVM_ALLOW_METADATA_WRITES only if an HMAC key is loaded
2021-07-14 16:53:08 +02:00
accounting
docs: add some documentation dirs to the driver-api book
2019-07-15 11:03:02 -03:00
admin-guide
clocksource: Retry clock read if long delays detected
2021-07-14 16:53:18 +02:00
arm
ARM: 9012/1: move device tree mapping out of linear region
2021-05-19 10:08:32 +02:00
arm64
userfaultfd: do not untag user pointers
2021-07-28 13:31:01 +02:00
block
docs: block: null_blk: enhance document style
2019-09-11 16:04:22 -06:00
bpf
bpf/flow_dissector: document flags
2019-07-25 18:00:41 -07:00
cdrom
docs: add some directories to the main documentation index
2019-07-15 11:03:03 -03:00
core-api
XArray: add xas_split
2021-06-10 13:37:14 +02:00
cpu-freq
Documentation: cpufreq: Update policy notifier documentation
2019-09-02 22:44:05 +02:00
crypto
Merge branch 'linus' of git://git.kernel.org/pub/scm/linux/kernel/git/herbert/crypto-2.6
2019-09-18 12:11:14 -07:00
dev-tools
mm, page_owner: decouple freeing stack trace from debug_pagealloc
2019-10-14 15:04:00 -07:00
devicetree
dt-bindings: net: ethernet-controller: fix typo in NVMEM
2021-04-14 08:24:18 +02:00
doc-guide
docs: remove extra conf.py files
2019-07-17 06:57:52 -03:00
driver-api
ata: make qc_prep return ata_completion_errors
2020-10-01 13:18:26 +02:00
EDID
docs: driver-api: add a series of orphaned documents
2019-07-15 11:03:02 -03:00
fault-injection
docs: add some directories to the main documentation index
2019-07-15 11:03:03 -03:00
fb
fbdev: fix numbering of fbcon options
2020-02-24 08:36:42 +01:00
features
It's a somewhat calmer cycle for docs this time, as the churn of the mass
2019-09-17 16:22:26 -07:00
filesystems
sysfs: Add sysfs_emit and sysfs_emit_at to format sysfs output
2021-03-07 12:20:48 +01:00
firmware-guide
Documentation: ACPI: DSD: Convert LED documentation to ReST
2019-08-20 23:53:46 +02:00
firmware_class
fpga
Documentation: fpga: dfl: add descriptions for virtualization and new interfaces.
2019-09-03 19:35:42 -07:00
gpu
Merge drm/drm-next into drm-intel-next-queued
2019-08-22 00:10:36 -07:00
hid
docs: add some documentation dirs to the driver-api book
2019-07-15 11:03:02 -03:00
hwmon
hwmon: (max31790) Fix pwmX_enable attributes
2021-07-14 16:53:14 +02:00
i2c
docs: i2c: convert to ReST and add to driver-api bookset
2019-07-31 13:25:27 -06:00
ia64
docs: add SPDX tags to new index files
2019-07-15 11:03:03 -03:00
ide
docs: add some directories to the main documentation index
2019-07-15 11:03:03 -03:00
iio
docs: add some documentation dirs to the driver-api book
2019-07-15 11:03:02 -03:00
infiniband
Documentation/infiniband: update name of some functions
2019-09-13 16:55:55 -03:00
input
Input: docs: fix spelling mistake "potocol" -> "protocol"
2019-08-06 11:24:49 -06:00
ioctl
fs-verity: add UAPI header
2019-07-28 16:59:16 -07:00
isdn
docs: isdn: convert to ReST and add to kAPI bookset
2019-07-31 13:30:25 -06:00
kbuild
kbuild: support LLVM=1 to switch the default tools to Clang/LLVM
2020-08-26 10:40:47 +02:00
kernel-hacking
docs: Add documentation for Symbol Namespaces
2019-09-10 10:30:49 +02:00
leds
leds: core: Add support for composing LED class device names
2019-07-25 20:07:52 +02:00
livepatch
docs: add some directories to the main documentation index
2019-07-15 11:03:03 -03:00
locking
doc 🔒 remove reference to clever use of read-write lock
2019-09-14 01:53:27 -06:00
m68k
docs: README.buddha: convert to ReST and add to m68k book
2019-07-31 13:30:10 -06:00
maintainer
docs: Fix typo on pull requests guide
2019-08-12 15:14:14 -06:00
media
media: videodev2.h: RGB BT2020 and HSV are always full range
2020-11-05 11:43:15 +01:00
mic
docs: driver-api: add remaining converted dirs to it
2019-07-15 11:03:03 -03:00
mips
Main MIPS changes for v5.4:
2019-09-22 09:30:30 -07:00
misc-devices
Docs: misc: xilinx_sdfec: Add documentation
2019-08-15 17:54:38 +02:00
netlabel
docs: add some directories to the main documentation index
2019-07-15 11:03:03 -03:00
networking
can: j1939: swap addr and pgn in the send example
2020-11-18 19:20:19 +01:00
nios2
docs: nios2: add it to the main Documentation body
2019-07-31 13:31:51 -06:00
openrisc
docs: openrisc: convert to ReST and add to documentation body
2019-07-31 13:30:20 -06:00
parisc
docs: parisc: convert to ReST and add to documentation body
2019-07-31 13:30:15 -06:00
PCI
Merge git://git.kernel.org/pub/scm/linux/kernel/git/netdev/net
2019-08-27 14:23:31 -07:00
pcmcia
docs: add some directories to the main documentation index
2019-07-15 11:03:03 -03:00
power
Merge branches 'pm-opp', 'pm-qos', 'acpi-pm', 'pm-domains' and 'pm-tools'
2019-09-17 09:49:19 +02:00
powerpc
docs: powerpc: Add missing documentation reference
2019-09-17 23:59:34 +10:00
process
Documentation/process: Add fallthrough pseudo-keyword
2019-10-11 09:26:05 -07:00
RCU
Merge branches 'consolidate.2019.08.01b', 'fixes.2019.08.12a', 'lists.2019.08.13a' and 'torture.2019.08.01b' into HEAD
2019-08-13 14:30:30 -07:00
riscv
It's a somewhat calmer cycle for docs this time, as the churn of the mass
2019-09-17 16:22:26 -07:00
s390
Documentation/s390: remove outdated debugging390 documentation
2019-08-21 12:41:43 +02:00
scheduler
sched/fair: Fix low cpu usage with high throttling by removing expiration of cpu-local slices
2019-08-08 09:09:30 +02:00
scsi
scsi: smartpqi: Update attribute name to driver_version
2020-01-17 19:48:27 +01:00
security
Merge branch 'next-integrity' of git://git.kernel.org/pub/scm/linux/kernel/git/zohar/linux-integrity
2019-09-27 19:37:27 -07:00
sh
docs: remove extra conf.py files
2019-07-17 06:57:52 -03:00
sound
ALSA: hda/realtek - Remove now-unnecessary XPS 13 headphone noise fixups
2020-04-17 10:50:08 +02:00
sparc
docs: add arch doc directories to the index
2019-07-15 11:03:01 -03:00
sphinx
tweewide: Fix most Shebang lines
2021-05-22 11:38:30 +02:00
sphinx-static
spi
spi: docs: convert to ReST and add it to the kABI bookset
2019-07-31 14:13:13 -06:00
target
tweewide: Fix most Shebang lines
2021-05-22 11:38:30 +02:00
timers
docs: add some directories to the main documentation index
2019-07-15 11:03:03 -03:00
trace
tracing/histogram: Rename "cpu" to "common_cpu"
2021-07-28 13:31:00 +02:00
translations
doc: arm64: fix grammar dtb placed in no attributes region
2019-09-06 08:44:34 -06:00
usb
USB: rio500: Remove Rio 500 kernel driver
2019-10-04 10:53:36 +02:00
userspace-api
Documentation: seccomp: Fix user notification documentation
2021-06-03 08:59:03 +02:00
virt
KVM: arm64: Reject VM creation when the default IPA size is unsupported
2021-03-17 17:03:57 +01:00
virtual
cpuidle: add haltpoll governor
2019-07-30 17:27:37 +02:00
vm
mm/slub: clarify verification reporting
2021-06-23 14:41:30 +02:00
w1
docs: w1: convert to ReST and add to the kAPI group of docs
2019-07-31 14:16:17 -06:00
watchdog
linux-watchdog 5.4-rc1 tag
2019-09-27 11:17:38 -07:00
x86
x86/CPU/AMD: Save AMD NodeId as cpu_die_id
2020-12-30 11:51:47 +01:00
xtensa
xtensa: fix TLBTEMP area placement
2020-11-24 13:29:22 +01:00
.gitignore
asm-annotations.rst
linkage: Introduce new macros for assembler symbols
2020-11-10 12:37:24 +01:00
atomic_bitops.txt
docs: atomic_bitops.txt: add a title for this document
2019-04-11 12:37:02 -06:00
atomic_t.txt
Merge branch 'locking-core-for-linus' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip
2019-07-08 16:12:03 -07:00
bus-virt-phys-mapping.txt
Changes
CodingStyle
conf.py
docs: conf.py: only use CJK if the font is available
2019-07-17 06:57:51 -03:00
COPYING-logo
docs: logo.txt: rename it to COPYING-logo
2019-07-15 09:20:27 -03:00
crc32.txt
debugging-modules.txt
debugging-via-ohci1394.txt
digsig.txt
DMA-API-HOWTO.txt
docs: DMA-API-HOWTO.txt: fix an unmarked code block
2019-07-15 09:20:24 -03:00
DMA-API.txt
dma-mapping: remove dma_release_declared_memory
2019-09-04 11:13:19 +02:00
DMA-attributes.txt
DMA-ISA-LPC.txt
docutils.conf
doc-rst: Add missing newline at end of file
2019-06-20 14:16:56 -06:00
dontdiff
kbuild: create *.mod with full directory path and remove MODVERDIR
2019-07-18 02:19:31 +09:00
futex-requeue-pi.txt
hwspinlock.txt
hwspinlock: add the 'in_atomic' API
2019-06-29 21:08:14 -07:00
index.rst
linkage: Introduce new macros for assembler symbols
2020-11-10 12:37:24 +01:00
io-mapping.txt
io_ordering.txt
IPMI.txt
IRQ-affinity.txt
IRQ-domain.txt
IRQ.txt
irqflags-tracing.txt
Kconfig
docs: Kbuild/Makefile: allow check for missing docs at build time
2019-06-07 11:33:16 -06:00
kobject.txt
kprobes.txt
Merge branch 'parisc-5.2-1' of git://git.kernel.org/pub/scm/linux/kernel/git/deller/parisc-linux
2019-05-07 19:34:17 -07:00
kref.txt
logo.gif
lzo.txt
lib/lzo: fix ambiguous encoding bug in lzo-rle
2020-06-17 16:40:28 +02:00
mailbox.txt
Makefile
docs: Kbuild/Makefile: allow check for missing docs at build time
2019-06-07 11:33:16 -06:00
memory-barriers.txt
docs: fix broken doc references due to renames
2019-07-17 06:57:51 -03:00
nommu-mmap.txt
padata.txt
padata: allocate workqueue internally
2019-09-13 21:15:39 +10:00
percpu-rw-semaphore.txt
pi-futex.txt
docs: locking: convert docs to ReST and rename to *.rst
2019-07-15 08:53:27 -03:00
preempt-locking.txt
x86/fpu: Remove fpu__restore()
2019-04-09 19:27:42 +02:00
rbtree.txt
docs: rbtree.txt: fix Sphinx build warnings
2019-07-15 09:20:24 -03:00
remoteproc.txt
remoteproc: add vendor resources handling
2019-06-29 12:02:17 -07:00
robust-futex-ABI.txt
robust-futexes.txt
futex: Update comments and docs about return values of arch futex code
2019-04-26 13:57:55 +01:00
rpmsg.txt
speculation.txt
docs: speculation.txt: mark example blocks as such
2019-04-11 12:37:03 -06:00
static-keys.txt
SubmittingPatches
tee.txt
Documentation: tee: Grammar s/the its/its/
2019-06-07 11:23:38 -06:00
this_cpu_ops.txt
unaligned-memory-access.txt
docs: unaligned-memory-access.txt: use a lowercase title
2019-04-11 12:37:03 -06:00
xz.txt