[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-ID: <d26549a7-8de8-876e-0385-ebb831da4a53@arm.com>
Date: Fri, 8 Jan 2021 17:03:52 +0000
From: Steven Price <steven.price@....com>
To: Marc Zyngier <maz@...nel.org>
Cc: Catalin Marinas <catalin.marinas@....com>,
Will Deacon <will@...nel.org>,
James Morse <james.morse@....com>,
Julien Thierry <julien.thierry.kdev@...il.com>,
Suzuki K Poulose <suzuki.poulose@....com>,
kvmarm@...ts.cs.columbia.edu, linux-arm-kernel@...ts.infradead.org,
linux-kernel@...r.kernel.org,
Alexander Potapenko <glider@...gle.com>,
Andrew Morton <akpm@...ux-foundation.org>,
Andrey Konovalov <andreyknvl@...gle.com>,
Vincenzo Frascino <vincenzo.frascino@....com>
Subject: Re: [PATCH] KVM: arm64: Compute TPIDR_EL2 ignoring MTE tag
On 08/01/2021 16:51, Marc Zyngier wrote:
> Hi Steven,
>
> On 2021-01-08 16:12, Steven Price wrote:
>> KASAN in HW_TAGS mode will store MTE tags in the top byte of the
>> pointer. When computing the offset for TPIDR_EL2 we don't want anything
>> in the top byte, so remove the tag to ensure the computation is correct
>> no matter what the tag.
>>
>> Fixes: 94ab5b61ee16 ("kasan, arm64: enable CONFIG_KASAN_HW_TAGS")
>> Signed-off-by: Steven Price <steven.price@....com>
>> ---
>> Without this fix I can't boot a config with KASAN_HW_TAGS and KVM on an
>> MTE enabled host. I'm unsure if this should really be in
>> this_cpu_ptr_nvhe_sym().
>
> this_cpu_ptr_nvhe_sym() should return something that is valid for
> the EL1 kernel, so I guess untagging in the helper may not be
> that useful.
Makes sense and was my suspicion.
> However, I'm more concerned by anything at requires us to follow
> pointers set up by EL1 at EL2. It looks to me that the only reason
> the whole thing works is because kern_hyp_va() *accidentally* drops
> tags before applying the EL1/EL2 offset...
In the case I'm fixing this is intended to be an offset calculation -
it's just messed up by the presence of an MTE tag in one of the pointers.
I agree I was somewhat surprised when everything 'just worked' with this
one change - and I think you're right it's because kern_hyp_va() 'just
happens' to lose the tags. Of course there may be other bugs lurking -
running MTE+KASAN on the model is slow so I didn't do much beyond boot it.
One of the 'fun' things about MTE is that you can no longer do pointer
subtraction to calculate the offset unless the pointers are actually
from the same allocation (and therefore have the same tag). I'm sure the
C language experts would point out that's "always been the case" but it
will probably break things elsewhere too.
Steve
> Or am I getting it wrong?
>
> Thanks,
>
> M.
Powered by blists - more mailing lists