lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <20150114010830.GA16100@hori1.linux.bs1.fc.nec.co.jp>
Date:	Wed, 14 Jan 2015 01:08:40 +0000
From:	Naoya Horiguchi <n-horiguchi@...jp.nec.com>
To:	Shiraz Hashim <shashim@...eaurora.org>
CC:	"linux-mm@...ck.org" <linux-mm@...ck.org>,
	"akpm@...ux-foundation.org" <akpm@...ux-foundation.org>,
	"oleg@...hat.com" <oleg@...hat.com>,
	"gorcunov@...nvz.org" <gorcunov@...nvz.org>,
	"linux-kernel@...r.kernel.org" <linux-kernel@...r.kernel.org>
Subject: Re: [PATCH 1/1] mm: pagemap: limit scan to virtual region being
 asked

On Tue, Jan 13, 2015 at 05:57:04PM +0530, Shiraz Hashim wrote:
> pagemap_read scans through the virtual address space of a
> task till it prepares 'count' pagemaps or it reaches end
> of task.
> 
> This presents a problem when the page walk doesn't happen
> for vma with VM_PFNMAP set. In which case walk is silently
> skipped and no pagemap is prepare, in turn making
> pagemap_read to scan through task end, even crossing beyond
> 'count', landing into a different vma region. This leads to
> wrong presentation of mappings for that vma.
> 
> Fix this by limiting end_vaddr to the end of the virtual
> address region being scanned.
> 
> Signed-off-by: Shiraz Hashim <shashim@...eaurora.org>

This patch works in some case, but there still seems a problem in another case.

Consider that we have two vmas within some narrow (PAGEMAP_WALK_SIZE) region.
One vma in lower address is VM_PFNMAP, and the other vma in higher address is not.
Then a single call of walk_page_range() skips the first vma and scans the
second vma, but the pagemap record of the second vma will be stored on the
wrong offset in the buffer, because we just skip vma(VM_PFNMAP) without calling
any callbacks (within which add_to_pagemap() increments pm.pos).

So calling pte_hole() for vma(VM_PFNMAP) looks a better fix to me.

Thanks,
Naoya Horiguchi

> ---
>  fs/proc/task_mmu.c | 4 +++-
>  1 file changed, 3 insertions(+), 1 deletion(-)
> 
> diff --git a/fs/proc/task_mmu.c b/fs/proc/task_mmu.c
> index 246eae8..04362e4 100644
> --- a/fs/proc/task_mmu.c
> +++ b/fs/proc/task_mmu.c
> @@ -1270,7 +1270,9 @@ static ssize_t pagemap_read(struct file *file, char __user *buf,
>  	src = *ppos;
>  	svpfn = src / PM_ENTRY_BYTES;
>  	start_vaddr = svpfn << PAGE_SHIFT;
> -	end_vaddr = TASK_SIZE_OF(task);
> +	end_vaddr = start_vaddr + ((count / PM_ENTRY_BYTES) << PAGE_SHIFT);
> +	if ((end_vaddr > TASK_SIZE_OF(task)) || (end_vaddr < start_vaddr))
> +		end_vaddr = TASK_SIZE_OF(task);
>  
>  	/* watch out for wraparound */
>  	if (svpfn > TASK_SIZE_OF(task) >> PAGE_SHIFT)
> -- 
> 
> QUALCOMM INDIA, on behalf of Qualcomm Innovation Center, Inc. is a
> member of the Code Aurora Forum, hosted by The Linux Foundation
> 
> --
> To unsubscribe, send a message with 'unsubscribe linux-mm' in
> the body to majordomo@...ck.org.  For more info on Linux MM,
> see: http://www.linux-mm.org/ .
> Don't email: <a href=mailto:"dont@...ck.org"> email@...ck.org </a>--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@...r.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ