lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite for Android: free password hash cracker in your pocket
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <df5a888b-1a11-e806-741d-94684b22c966@intel.com>
Date:   Thu, 6 Feb 2020 10:51:13 -0800
From:   Dave Hansen <dave.hansen@...el.com>
To:     Mike Rapoport <rppt@...nel.org>, linux-kernel@...r.kernel.org
Cc:     Alan Cox <alan@...ux.intel.com>,
        Andrew Morton <akpm@...ux-foundation.org>,
        Andy Lutomirski <luto@...nel.org>,
        Christopher Lameter <cl@...ux.com>,
        Dave Hansen <dave.hansen@...ux.intel.com>,
        James Bottomley <jejb@...ux.ibm.com>,
        "Kirill A. Shutemov" <kirill@...temov.name>,
        Matthew Wilcox <willy@...radead.org>,
        Peter Zijlstra <peterz@...radead.org>,
        "Reshetova, Elena" <elena.reshetova@...el.com>,
        Thomas Gleixner <tglx@...utronix.de>,
        Tycho Andersen <tycho@...ho.ws>, linux-api@...r.kernel.org,
        linux-mm@...ck.org
Subject: Re: [RFC PATCH] mm: extend memfd with ability to create "secret"
 memory areas

On 1/30/20 8:23 AM, Mike Rapoport wrote:
>  include/linux/memfd.h      |   9 ++
>  include/uapi/linux/magic.h |   1 +
>  include/uapi/linux/memfd.h |   6 +
>  mm/Kconfig                 |   4 +
>  mm/Makefile                |   1 +
>  mm/memfd.c                 |  10 +-
>  mm/secretmem.c             | 244 +++++++++++++++++++++++++++++++++++++
>  7 files changed, 273 insertions(+), 2 deletions(-)

It seems pretty self-contained and relatively harmless.

But, how much work is it going to be to tell the rest of the kernel that
page_to_virt() doesn't work any more?  Do we need to make kmap() work on
these?

I guess fixing vm_normal_page() would fix a lot of that.

In general, my concern about creating little self-contained memory types
is that they will get popular and folks will start wanting more features
from them.  For instance, what if I want NUMA affinity, migration, or
large page mappings that are secret?

Can these pages work as guest memory?

Who would the first users of this thing be?

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ