[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <2fe4c4d1-c480-c250-1ba2-1a82caf5d7fa@huawei.com>
Date: Thu, 20 Feb 2025 10:31:30 +0800
From: Tong Tiangen <tongtiangen@...wei.com>
To: David Hildenbrand <david@...hat.com>, Oleg Nesterov <oleg@...hat.com>
CC: Masami Hiramatsu <mhiramat@...nel.org>, Peter Zijlstra
<peterz@...radead.org>, Ingo Molnar <mingo@...hat.com>, Arnaldo Carvalho de
Melo <acme@...nel.org>, Namhyung Kim <namhyung@...nel.org>, Mark Rutland
<mark.rutland@....com>, Alexander Shishkin
<alexander.shishkin@...ux.intel.com>, Jiri Olsa <jolsa@...nel.org>, Ian
Rogers <irogers@...gle.com>, Adrian Hunter <adrian.hunter@...el.com>, "Liang,
Kan" <kan.liang@...ux.intel.com>, Andrew Morton <akpm@...ux-foundation.org>,
Peter Xu <peterx@...hat.com>, <linux-kernel@...r.kernel.org>,
<linux-trace-kernel@...r.kernel.org>, <linux-perf-users@...r.kernel.org>,
<bpf@...r.kernel.org>, <wangkefeng.wang@...wei.com>, linux-mm
<linux-mm@...ck.org>
Subject: Re: Add Morton,Peter and David for discussion//Re: [PATCH -next]
uprobes: fix two zero old_folio bugs in __replace_page()
在 2025/2/20 0:12, David Hildenbrand 写道:
> On 19.02.25 16:22, Oleg Nesterov wrote:
>> On 02/18, Tong Tiangen wrote:
>>>
>>> OK, Before your rewrite last merged, How about i change the solution to
>>> just reject them immediately after get_user_page_vma_remote()?
>>
>> I agree, uprobe_write_opcode() should simply fail if
>> is_zero_page(old_page).
>
> Yes. That's currently only syzkaller that triggers it, not some sane use
> case.
OK, change as follows:
--- a/kernel/events/uprobes.c
+++ b/kernel/events/uprobes.c
@@ -506,6 +506,12 @@ int uprobe_write_opcode(struct arch_uprobe
*auprobe, struct mm_struct *mm,
if (ret <= 0)
goto put_old;
+ if (WARN(is_zero_page(old_page),
+ "uprobe should never work on zero page\n")) {
+ ret = -EINVAL;
+ goto put_old;
+ }
+
if (WARN(!is_register && PageCompound(old_page),
"uprobe unregister should never work on compound
page\n")) {
ret = -EINVAL;
If ok, i will send v2 soon.
Thanks,
Tong.
>
Powered by blists - more mailing lists