From patchwork Mon Feb 13 16:31:23 2023 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Muhammad Usama Anjum X-Patchwork-Id: 56391 Return-Path: Delivered-To: ouuuleilei@gmail.com Received: by 2002:adf:eb09:0:0:0:0:0 with SMTP id s9csp2450872wrn; Mon, 13 Feb 2023 08:50:48 -0800 (PST) X-Google-Smtp-Source: AK7set++XjJiAwvHced7wR+JqcmF0eqzikh/1f/GzLATHqSid941H0w4DSjJth5yV5h07M+yC1j1 X-Received: by 2002:a50:d610:0:b0:4a2:588f:b3c5 with SMTP id x16-20020a50d610000000b004a2588fb3c5mr24794518edi.21.1676307047985; Mon, 13 Feb 2023 08:50:47 -0800 (PST) ARC-Seal: i=1; a=rsa-sha256; t=1676307047; cv=none; d=google.com; s=arc-20160816; b=OF+MqJFWB7xtxH7DK5rRya24O3KHHhuoM1NRCz2D14Odb1wT2l9qHD8+qSouFLqwDB y62lZnmD92P8htWW5kfSuDCT4qOAJh+EocKdqUbhdqWlNjmzuJEn1P585Xvrxopes/Qo TT7jfmLQG82HJn9IeMq131dI81m/Kr6wIYhmhfqHUI8XQHZ6lCYxcvVRPNRbNr4YCECM /zmx4jcUMUOUh4NUGPMA0NyMMbkGDnCJt7svndXxCDjH9Sd3mPPCRMFmCaRSFEf8SDSH ZekazWlTFtLPS32sQrGyM0MeDjCQYlKtspLVHE7250NPyw7l79N4fpAf86ESnGgaviom UNcQ== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:content-transfer-encoding:mime-version :message-id:date:subject:cc:to:from:dkim-signature; bh=maUh+Knwdfgzx8QLtD/ZJAtuBBfS0rEEBYG7dP5ByWQ=; b=aIPr6tvZt2IX7ITr/hN4qZJVeb7FUp5I47K0plskGJdrZqZpBqSAgukL7xvGwB7smF ZOnwaEU+CEDntaImr/g6rA0p0KtcinrU00UJl45t8NZ35cOHPmFvp2vfX8HBckBZQJm+ +93wXe/Wo15u9zM1G6+TcYIvLyd2kbVwE89r98/yHGdAUn9Z0C5YuDzOZHacZH5yEE9q 6BPJTLh1+dzZW6qbBZmfcGnQCRxv6erKTNLk0AL4UWcqfWwWUq6YlP1PAlRmBwqzksJM /30pFcTijEL9BPhsisAiPI39EPJgS9l21IxPRHlMUV7jEkq3n+3wlwQFfpmuDlGseeWz aCyA== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@collabora.com header.s=mail header.b=Uc3zOm2n; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=collabora.com Received: from out1.vger.email (out1.vger.email. [2620:137:e000::1:20]) by mx.google.com with ESMTP id d27-20020a056402517b00b004acb7af3f93si8981524ede.497.2023.02.13.08.50.23; Mon, 13 Feb 2023 08:50:47 -0800 (PST) Received-SPF: pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) client-ip=2620:137:e000::1:20; Authentication-Results: mx.google.com; dkim=pass header.i=@collabora.com header.s=mail header.b=Uc3zOm2n; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=collabora.com Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S231181AbjBMQcF (ORCPT + 99 others); Mon, 13 Feb 2023 11:32:05 -0500 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:54856 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S230047AbjBMQbu (ORCPT ); Mon, 13 Feb 2023 11:31:50 -0500 Received: from madras.collabora.co.uk (madras.collabora.co.uk [46.235.227.172]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id 95B5A1DB9C for ; Mon, 13 Feb 2023 08:31:44 -0800 (PST) Received: from localhost.localdomain (unknown [39.45.179.179]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) (Authenticated sender: usama.anjum) by madras.collabora.co.uk (Postfix) with ESMTPSA id 030E26602146; Mon, 13 Feb 2023 16:31:40 +0000 (GMT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=collabora.com; s=mail; t=1676305902; bh=OiTcyrHZ0v3oC/V7QnPlyQu3zF7d7MV1OS0jVwPURZU=; h=From:To:Cc:Subject:Date:From; b=Uc3zOm2nBYWIjJv2z1Is850ACuGzKXcoqliy3ugB5rRc28XwAUkhcyLgGezS62dNw vWsv8rsKCEB+V4zQOzvteoxgT//NwYQ0BSlVzV+dNnOuwp3otEQWzbiqnKHRbCei/l osOICLKHWG29ijdU4Rha4hg7tq/Nsk9r4mTZYSajGQHnlqDVWh55D5mYB0OJxHdvyQ 52yFWnOTgus4Nstl0Iva3Mw9bUSYhyjz6m2SCf2qRMXT8PFb3UdY8LyrOO3cS9SERP xyelRMHwlM9SbA5h+7MCpehfW5a8HWQyrDx/zZFw9cNC9TKcjWFgK/J3+sc6gVMZcn +5VpNA5l3YPxQ== From: Muhammad Usama Anjum To: peterx@redhat.com, david@redhat.com, Andrew Morton Cc: Muhammad Usama Anjum , kernel@collabora.com, Paul Gofman , linux-mm@kvack.org, linux-kernel@vger.kernel.org Subject: [PATCH v2 1/2] mm/userfaultfd: Support WP on multiple VMAs Date: Mon, 13 Feb 2023 21:31:23 +0500 Message-Id: <20230213163124.2850816-1-usama.anjum@collabora.com> X-Mailer: git-send-email 2.39.1 MIME-Version: 1.0 X-Spam-Status: No, score=-2.1 required=5.0 tests=BAYES_00,DKIM_SIGNED, DKIM_VALID,DKIM_VALID_AU,DKIM_VALID_EF,SPF_HELO_NONE,SPF_PASS autolearn=ham autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on lindbergh.monkeyblade.net Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org X-getmail-retrieved-from-mailbox: =?utf-8?q?INBOX?= X-GMAIL-THRID: =?utf-8?q?1757735339494299958?= X-GMAIL-MSGID: =?utf-8?q?1757735339494299958?= mwriteprotect_range() errors out if [start, end) doesn't fall in one VMA. We are facing a use case where multiple VMAs are present in one range of interest. For example, the following pseudocode reproduces the error which we are trying to fix: - Allocate memory of size 16 pages with PROT_NONE with mmap - Register userfaultfd - Change protection of the first half (1 to 8 pages) of memory to PROT_READ | PROT_WRITE. This breaks the memory area in two VMAs. - Now UFFDIO_WRITEPROTECT_MODE_WP on the whole memory of 16 pages errors out. This is a simple use case where user may or may not know if the memory area has been divided into multiple VMAs. Reported-by: Paul Gofman Signed-off-by: Muhammad Usama Anjum --- Changes since v1: - Correct the start and ending values passed to uffd_wp_range() --- mm/userfaultfd.c | 38 ++++++++++++++++++++++---------------- 1 file changed, 22 insertions(+), 16 deletions(-) diff --git a/mm/userfaultfd.c b/mm/userfaultfd.c index 65ad172add27..bccea08005a8 100644 --- a/mm/userfaultfd.c +++ b/mm/userfaultfd.c @@ -738,9 +738,12 @@ int mwriteprotect_range(struct mm_struct *dst_mm, unsigned long start, unsigned long len, bool enable_wp, atomic_t *mmap_changing) { + unsigned long end = start + len; + unsigned long _start, _end; struct vm_area_struct *dst_vma; unsigned long page_mask; int err; + VMA_ITERATOR(vmi, dst_mm, start); /* * Sanitize the command parameters: @@ -762,26 +765,29 @@ int mwriteprotect_range(struct mm_struct *dst_mm, unsigned long start, if (mmap_changing && atomic_read(mmap_changing)) goto out_unlock; - err = -ENOENT; - dst_vma = find_dst_vma(dst_mm, start, len); + for_each_vma_range(vmi, dst_vma, end) { + err = -ENOENT; - if (!dst_vma) - goto out_unlock; - if (!userfaultfd_wp(dst_vma)) - goto out_unlock; - if (!vma_can_userfault(dst_vma, dst_vma->vm_flags)) - goto out_unlock; + if (!dst_vma->vm_userfaultfd_ctx.ctx) + break; + if (!userfaultfd_wp(dst_vma)) + break; + if (!vma_can_userfault(dst_vma, dst_vma->vm_flags)) + break; - if (is_vm_hugetlb_page(dst_vma)) { - err = -EINVAL; - page_mask = vma_kernel_pagesize(dst_vma) - 1; - if ((start & page_mask) || (len & page_mask)) - goto out_unlock; - } + if (is_vm_hugetlb_page(dst_vma)) { + err = -EINVAL; + page_mask = vma_kernel_pagesize(dst_vma) - 1; + if ((start & page_mask) || (len & page_mask)) + break; + } - uffd_wp_range(dst_mm, dst_vma, start, len, enable_wp); + _start = (dst_vma->vm_start > start) ? dst_vma->vm_start : start; + _end = (dst_vma->vm_end < end) ? dst_vma->vm_end : end; - err = 0; + uffd_wp_range(dst_mm, dst_vma, _start, _end - _start, enable_wp); + err = 0; + } out_unlock: mmap_read_unlock(dst_mm); return err; From patchwork Mon Feb 13 16:31:24 2023 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Muhammad Usama Anjum X-Patchwork-Id: 56392 Return-Path: Delivered-To: ouuuleilei@gmail.com Received: by 2002:adf:eb09:0:0:0:0:0 with SMTP id s9csp2451423wrn; Mon, 13 Feb 2023 08:51:58 -0800 (PST) X-Google-Smtp-Source: AK7set83XSDLDIYYzhUpM4G9CaYpnjrxmuGjcucxPj02PZv6JzjJqDy+WPnyKavqs4Yn7IurstoN X-Received: by 2002:a05:6a21:3609:b0:bc:bb0:dec8 with SMTP id yg9-20020a056a21360900b000bc0bb0dec8mr19420984pzb.61.1676307118170; Mon, 13 Feb 2023 08:51:58 -0800 (PST) ARC-Seal: i=1; a=rsa-sha256; t=1676307118; cv=none; d=google.com; s=arc-20160816; b=0yliOQMi4uFpiHO6YTtEB2o4VskaYoTchb8Q+LaUIIOD4UpwWyyC8LyIjWj4nMXiZZ B/lYUSc3PP/CIOkJcJrAAob16kjP3QVUpJYiRTgoLqlspCiLZoMPawj3f6qNxJPU53cL 0CfyyTBk37TG+hLPswnZklabY8/Elx60OzLy5Ywzo/1uK/2EskhGiLc7BK5LNl0C/aaD XsoSXLIEFYvOGs032PWUcv9j54zx8I0J0rd/6+dgiz/JeIYdmrNyQ2hZfWFBc61xUIx+ ia3mrSTiwz5VtLmCxEQHb2rO85q+tdzwlNrZURYXPhXQsIzbgyXbbZjTmgeOKOu7bZvZ PDjA== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:content-transfer-encoding:mime-version :references:in-reply-to:message-id:date:subject:cc:to:from :dkim-signature; bh=YwurXtxIMyWbgqUgY9xnVPmcbG6KUXlJ5n173RtX8eM=; b=Gigryhg4mFBfwKki9yGG+48rNh4dkdtpFt7UkpaJdIu+tnKg37eVQP1lxlWB4Q4/YP SmynKP6FilasUEaM3TYdxyXjMyqdmzZ+r+UguMDOa6jOTCa3SqLycErl1Hs24um/NYlW SHf7TMLyiXJn+Vs6kds0yoBSrVqYJxHrcUDQcOI7nkrSXBqVsSftBS4w3u2bgOKAXPjA Dgyh1sIFhTAcwPnO6z0FeFOHpty+J8INplgPybn2H1rtBROItKCiY2p1Ir9OToFerRjC osAO3l9qUr7uw57IiSmFMEygQ/V6S5QG9O59VLoweoHwDgJsxeXiRzV9+sAgs0PTwTx1 YixA== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@collabora.com header.s=mail header.b=GYFOIYPm; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=collabora.com Received: from out1.vger.email (out1.vger.email. [2620:137:e000::1:20]) by mx.google.com with ESMTP id 188-20020a6301c5000000b004da377c33bbsi12549662pgb.85.2023.02.13.08.51.44; Mon, 13 Feb 2023 08:51:58 -0800 (PST) Received-SPF: pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) client-ip=2620:137:e000::1:20; Authentication-Results: mx.google.com; dkim=pass header.i=@collabora.com header.s=mail header.b=GYFOIYPm; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=collabora.com Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S231284AbjBMQcI (ORCPT + 99 others); Mon, 13 Feb 2023 11:32:08 -0500 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:54922 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S230509AbjBMQbu (ORCPT ); Mon, 13 Feb 2023 11:31:50 -0500 Received: from madras.collabora.co.uk (madras.collabora.co.uk [IPv6:2a00:1098:0:82:1000:25:2eeb:e5ab]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id DA121DBD5 for ; Mon, 13 Feb 2023 08:31:46 -0800 (PST) Received: from localhost.localdomain (unknown [39.45.179.179]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) (Authenticated sender: usama.anjum) by madras.collabora.co.uk (Postfix) with ESMTPSA id 9B3276602149; Mon, 13 Feb 2023 16:31:43 +0000 (GMT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=collabora.com; s=mail; t=1676305905; bh=zXPbJqCldaAU06/Pl15/EuPbGqrq9pdX/EO4Oo9v1hc=; h=From:To:Cc:Subject:Date:In-Reply-To:References:From; b=GYFOIYPmxJOzBKz1ZV9fqB+BQADrG3NwplIW6YVJvdlwMcF900XODPcitVTeMK+xu WyzYsudjY2R0JcqaW0yu+kJjo4I2Y2Ktr4vOe8ItJX8fERsZLx/mlS3FcyoUROreqD 04wSEDRf2I1KSq3MSFXmP+Org06bmw3vWmE5n2DN+gDw2DqPPGQqO4u2fuJeq/3Q1k O2JW0/FF5FGvPOdeNKqofOVsixD9WHdLZVNG1p3O0cBuR3bxaaObpw9J6V+hqzZJ5j 34sbj4V4u2gcbXyYW9zdXNQww0NppB1iq++eIsgoAULWBJLUftJYUY/XduedhHk0Na bRDn8Iu/ee5ow== From: Muhammad Usama Anjum To: peterx@redhat.com, david@redhat.com, Andrew Morton Cc: Muhammad Usama Anjum , kernel@collabora.com, linux-mm@kvack.org, linux-kernel@vger.kernel.org Subject: [PATCH v2 2/2] mm/userfaultfd: add VM_WARN_ONCE() Date: Mon, 13 Feb 2023 21:31:24 +0500 Message-Id: <20230213163124.2850816-2-usama.anjum@collabora.com> X-Mailer: git-send-email 2.39.1 In-Reply-To: <20230213163124.2850816-1-usama.anjum@collabora.com> References: <20230213163124.2850816-1-usama.anjum@collabora.com> MIME-Version: 1.0 X-Spam-Status: No, score=-2.1 required=5.0 tests=BAYES_00,DKIM_SIGNED, DKIM_VALID,DKIM_VALID_AU,DKIM_VALID_EF,SPF_HELO_NONE,SPF_PASS autolearn=ham autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on lindbergh.monkeyblade.net Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org X-getmail-retrieved-from-mailbox: =?utf-8?q?INBOX?= X-GMAIL-THRID: =?utf-8?q?1757735412935590487?= X-GMAIL-MSGID: =?utf-8?q?1757735412935590487?= Add VM_WARN_ONCE() to uffd_wp_range() to detect range (start, len) abuse. Signed-off-by: Muhammad Usama Anjum --- mm/userfaultfd.c | 2 ++ 1 file changed, 2 insertions(+) diff --git a/mm/userfaultfd.c b/mm/userfaultfd.c index bccea08005a8..14ec88301511 100644 --- a/mm/userfaultfd.c +++ b/mm/userfaultfd.c @@ -716,6 +716,8 @@ void uffd_wp_range(struct mm_struct *dst_mm, struct vm_area_struct *dst_vma, unsigned int mm_cp_flags; struct mmu_gather tlb; + VM_WARN_ONCE(start < dst_vma->vm_start || start + len > dst_vma->vm_end, + "The address range exceeds VMA boundary.\n"); if (enable_wp) mm_cp_flags = MM_CP_UFFD_WP; else