Minchan Kim
475c63f782
mm/madvise: remove racy mm ownership check
...
Jann spotted the security hole due to race of mm ownership check.
If the task is sharing the mm_struct but goes through execve() before
mm_access(), it could skip process_madvise_behavior_valid check. That
makes *any advice hint* to reach into the remote process.
This patch removes the mm ownership check. With it, it will lose the
ability that local process could give *any* advice hint with vector
interface for some reason (e.g., performance). Since there is no
concrete example in upstream yet, it would be better to remove the
abiliity at this moment and need to review when such new advice comes
up.
Change-Id: I536de5167b6cf7378a06a6b7815f1dd2869a56a4
Fixes: ecb8ac8b1f14 ("mm/madvise: introduce process_madvise() syscall: an external memory hinting API")
Reported-by: Jann Horn <jannh@google.com>
Suggested-by: Jann Horn <jannh@google.com>
Signed-off-by: Minchan Kim <minchan@kernel.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Git-Commit: a68a0262abdaa251e12c53715f48e698a18ef402
Git-Repo: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
Signed-off-by: Charan Teja Reddy <charante@codeaurora.org>
2020-12-09 12:31:23 +05:30
..
kasan
Merge android-5.4-stable.45 ( a9a13ee) into msm-5.4
2020-07-09 17:51:24 -07:00
backing-dev.c
bdi: add a ->dev_name field to struct backing_dev_info
2020-05-14 07:58:30 +02:00
balloon_compaction.c
cleancache.c
cma.c
cma.h
cma_debug.c
Revert "mm: cma: make writeable CMA debugfs optional"
2020-01-16 13:16:30 -08:00
compaction.c
mem-offline: improve the effective utilization of movable zone
2020-09-04 06:15:14 -07:00
debug.c
mm/debug.c: always print flags in dump_page()
2020-03-05 16:43:51 +01:00
debug_page_ref.c
dmapool.c
early_ioremap.c
fadvise.c
failslab.c
filemap.c
Merge android11-5.4.56 ( fcb0d3e) into msm-5.4
2020-08-06 17:12:45 -07:00
frame_vector.c
frontswap.c
gup.c
gup: document and work around "COW can break either way" issue
2020-06-17 16:40:30 +02:00
gup_benchmark.c
mm/gup: fix memory leak in __gup_benchmark_ioctl
2020-01-09 10:20:00 +01:00
highmem.c
hmm.c
huge_memory.c
Merge android-5.4-stable.50 ( a200ad5) into msm-5.4
2020-07-20 19:22:16 -07:00
hugetlb.c
Merge android11-5.4.61+ ( 0d36496) into msm-5.4
2020-09-02 16:54:52 -07:00
hugetlb_cgroup.c
hwpoison-inject.c
init-mm.c
mm: protect mm_rb tree with a rwlock
2020-06-11 16:02:05 +05:30
internal.h
mm: provide speculative fault infrastructure
2020-06-11 16:02:05 +05:30
interval_tree.c
Kconfig
mm: Kconfig: Add support for config size of purging vmap_area
2020-11-13 01:08:21 -08:00
Kconfig.debug
mm, page_owner: set page owner info for tail pages
2020-02-27 15:13:14 -08:00
khugepaged.c
Merge android11-5.4.61+ ( 0d36496) into msm-5.4
2020-09-02 16:54:52 -07:00
kmemleak-test.c
kmemleak.c
ksm.c
Merge android-5.4-stable.45 ( a9a13ee) into msm-5.4
2020-07-09 17:51:24 -07:00
list_lru.c
maccess.c
uaccess: Add non-pagefault user-space write function
2020-01-17 19:48:40 +01:00
madvise.c
mm/madvise: remove racy mm ownership check
2020-12-09 12:31:23 +05:30
Makefile
memblock.c
mm: memblock: Add more debug logs
2020-08-14 09:21:40 +05:30
memcontrol.c
mm/memcg: fix refcount error while moving and swapping
2020-07-29 10:18:43 +02:00
memfd.c
memory-failure.c
mm: Enhance per process reclaim to consider shared pages
2020-06-02 21:31:03 -07:00
memory.c
mm: sync rss in speculative page fault path
2020-09-17 19:34:45 +05:30
memory_hotplug.c
Merge "mm/memory_hotplug: drain per-cpu pages again during memory offline"
2020-11-23 19:13:33 -08:00
mempolicy.c
Merge "mm: Fix sleeping while atomic during speculative page fault"
2020-06-25 19:09:40 -07:00
mempool.c
memremap.c
mm/memory_hotplug: shrink zones when offlining memory
2020-01-09 10:19:56 +01:00
memtest.c
migrate.c
mm/migrate: Pass vm_fault pointer to migrate_misplaced_page()
2020-06-11 16:02:03 +05:30
mincore.c
mlock.c
mm: protect VMA modifications using VMA sequence count
2020-06-09 10:55:00 +05:30
mm_init.c
mmap.c
Merge android11-5.4.60 ( 8ae87ad) into msm-5.4
2020-08-31 13:04:44 -07:00
mmu_context.c
mmu_gather.c
mm/mmu_gather: invalidate TLB correctly on batch allocation failure and flush
2020-02-11 04:35:42 -08:00
mmu_notifier.c
mmzone.c
mprotect.c
mm: protect VMA modifications using VMA sequence count
2020-06-09 10:55:00 +05:30
mremap.c
Merge android-5.4-stable.45 ( a9a13ee) into msm-5.4
2020-07-09 17:51:24 -07:00
msync.c
nommu.c
x86/mm: split vmalloc_sync_all()
2020-03-25 08:25:58 +01:00
oom_kill.c
Merge "mm/oom_kill: defer panic_on_oom for a timeout"
2020-11-11 23:35:25 -08:00
page-writeback.c
mm/page-writeback.c: avoid potential division by zero in wb_min_max_ratio()
2020-01-23 08:22:41 +01:00
page_alloc.c
Merge android11-5.4.61+ ( 8540985) into msm-5.4
2020-10-19 10:50:25 -07:00
page_counter.c
Revert "ANDROID: Revert: Merge 5.4.60 into android11-5.4"
2020-08-23 13:12:51 +02:00
page_ext.c
mm: fix the page_owner initializing issue for arm32
2020-09-29 12:42:42 +08:00
page_idle.c
page_io.c
Merge android-5.4.24 ( ce5de62) into msm-5.4
2020-04-14 08:25:29 -07:00
page_isolation.c
mm/memory_hotplug: drain per-cpu pages again during memory offline
2020-11-23 17:03:25 +05:30
page_owner.c
mm: page_owner: add pid, allocated time in page owner dump
2020-11-23 14:35:17 +05:30
page_poison.c
debug-pagealloc: Panic on pagealloc corruption
2020-08-25 11:46:48 -07:00
page_vma_mapped.c
pagewalk.c
percpu-internal.h
percpu-km.c
percpu-stats.c
percpu-vm.c
percpu.c
pgtable-generic.c
process_vm_access.c
readahead.c
rmap.c
mm: introduce __page_add_new_anon_rmap()
2020-06-11 16:02:04 +05:30
rodata_test.c
shmem.c
Merge android-5.4-stable.45 ( a9a13ee) into msm-5.4
2020-07-09 17:51:24 -07:00
showmem.c
shuffle.c
shuffle.h
slab.c
soc: qcom: Enable slabinfo support in minidump
2020-09-07 09:23:52 -07:00
slab.h
slab_common.c
soc: qcom: Enable slabinfo support in minidump
2020-09-07 09:23:52 -07:00
slob.c
UPSTREAM: mm/sl[uo]b: export __kmalloc_track(_node)_caller
2020-11-02 16:12:00 +00:00
slub.c
Merge "mm: slub: avoid return code from slab_sysfs_init if debugfs is off"
2020-11-24 05:19:04 -08:00
sparse-vmemmap.c
sparse.c
mm/sparse: fix kernel crash with pfn_section_valid check
2020-04-01 11:02:03 +02:00
swap.c
mm: introduce __lru_cache_add_active_or_unevictable
2020-06-11 16:02:03 +05:30
swap_cgroup.c
swap_slots.c
mm: swap: Add null pointer check
2020-01-10 11:23:22 -08:00
swap_state.c
Merge android11-5.4.52 ( c7725ae) into msm-5.4
2020-07-27 01:21:35 -07:00
swapfile.c
UPSTREAM: Merge remote-tracking branch 'aosp/upstream-f2fs-stable-linux-5.4.y' into android-5.4 (v5.7-rc1)
2020-04-15 03:11:03 +00:00
truncate.c
usercopy.c
userfaultfd.c
Merge android-5.4.24 ( ce5de62) into msm-5.4
2020-04-14 08:25:29 -07:00
util.c
mm: add kvfree_sensitive() for freeing sensitive data objects
2020-06-17 16:40:23 +02:00
vmacache.c
vmalloc.c
mm: Kconfig: Add support for config size of purging vmap_area
2020-11-13 01:08:21 -08:00
vmpressure.c
vmscan.c
mm: reduce the time spend by killed tasks in alloc path
2020-07-07 05:16:51 -07:00
vmstat.c
Merge android11-5.4.61+ ( 8540985) into msm-5.4
2020-10-19 10:50:25 -07:00
workingset.c
mm: workingset: remove zero-seek setting for shadow node shrinker
2020-04-06 23:51:59 -07:00
z3fold.c
zbud.c
zpool.c
zsmalloc.c
mm: direct previous __GFP_CMA allocations to offlinable memory
2020-06-16 20:17:34 -07:00
zswap.c