From patchwork Tue Jun 26 13:15:24 2018 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Andrey Konovalov X-Patchwork-Id: 10488929 Return-Path: Received: from mail.wl.linuxfoundation.org (pdx-wl-mail.web.codeaurora.org [172.30.200.125]) by pdx-korg-patchwork.web.codeaurora.org (Postfix) with ESMTP id A0D9560386 for ; Tue, 26 Jun 2018 13:16:33 +0000 (UTC) Received: from mail.wl.linuxfoundation.org (localhost [127.0.0.1]) by mail.wl.linuxfoundation.org (Postfix) with ESMTP id 8F6FC2893B for ; Tue, 26 Jun 2018 13:16:33 +0000 (UTC) Received: by mail.wl.linuxfoundation.org (Postfix, from userid 486) id 829762893F; Tue, 26 Jun 2018 13:16:33 +0000 (UTC) X-Spam-Checker-Version: SpamAssassin 3.3.1 (2010-03-16) on pdx-wl-mail.web.codeaurora.org X-Spam-Level: X-Spam-Status: No, score=-10.5 required=2.0 tests=BAYES_00,DKIM_SIGNED, DKIM_VALID,DKIM_VALID_AU,MAILING_LIST_MULTI,RCVD_IN_DNSWL_NONE, USER_IN_DEF_DKIM_WL autolearn=ham version=3.3.1 Received: from kanga.kvack.org (kanga.kvack.org [205.233.56.17]) by mail.wl.linuxfoundation.org (Postfix) with ESMTP id DE7402893B for ; Tue, 26 Jun 2018 13:16:32 +0000 (UTC) Received: by kanga.kvack.org (Postfix) id 2764D6B0279; Tue, 26 Jun 2018 09:16:02 -0400 (EDT) Delivered-To: linux-mm-outgoing@kvack.org Received: by kanga.kvack.org (Postfix, from userid 40) id 1AF766B027A; Tue, 26 Jun 2018 09:16:02 -0400 (EDT) X-Original-To: int-list-linux-mm@kvack.org X-Delivered-To: int-list-linux-mm@kvack.org Received: by kanga.kvack.org (Postfix, from userid 63042) id EF5B86B027C; Tue, 26 Jun 2018 09:16:01 -0400 (EDT) X-Original-To: linux-mm@kvack.org X-Delivered-To: linux-mm@kvack.org Received: from mail-wr0-f199.google.com (mail-wr0-f199.google.com [209.85.128.199]) by kanga.kvack.org (Postfix) with ESMTP id 8AD186B0279 for ; Tue, 26 Jun 2018 09:16:01 -0400 (EDT) Received: by mail-wr0-f199.google.com with SMTP id g6-v6so11363812wrp.4 for ; Tue, 26 Jun 2018 06:16:01 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:dkim-signature:from:to:cc:subject:date :message-id:in-reply-to:references; bh=EP2Dki4EWWZ2WEvc6M+bB9+4bOXHIe54Gcv4T4SHLRg=; b=YNMQVBRzd4HB5VtcNfIvz21h9au6rkrxvBiU0jbOHzi1QU8b+ItOFKm2XVOjCyRTfW BX9Pv2crLVHYOUgaqY6QiJx1JKRJJHPxeT1R1UzY4m58BB71UivIsiVPi+HK9Npy0zgf +O/ecaFbLGpCoA2X4Yg8MfhILjoy/JztesvaJYQLcVe9Vgj5aO+Ntc0m7Z+5PEiSDhI0 NmFjBy+EWutz0OUt+GdhuU0WI/q4uUsjcWqbfzbWNIkveEQetKBjHLh+4xtKix7R7uXi yTS82EvqmRnD6FTWPdZL0WlBiKuAGqoeUQTtoA2wipOBILc7oGZ+lN+YJFlWMtBYvb84 Fc8Q== X-Gm-Message-State: APt69E1ZhLR7PN17m6UuA/uqqFDJQmqoWyHgL2LzkAdqIe7DYYHfhRNI ZnGmrIE02GhEc4nttxGoNIMy8Ws3twCLSgaEJTqKT8OZqgKsZusfFcB07H4ziLPtMSnUOZZnR4F C24/StdL+wL6hohJJR+Jeo7+4hnTotV64xBRtIGTwuWm0k6F3uu+CJXZ3WPoL9slqvkKsqlzKOe mWL9OpROMKsynLLRnjKegr6v/+xn6O4r4Ro9/st/qCe1+s7XxtZjCaJUneAJ+yB8zPnruHbmrWC txy3V5pvNvIVPxtWz8BZutknkGXFLgk4rmiu/hlTARr/ZcTuibMsi28+upkWszWbvP68BxWpWlM w6ouBBYqljBL8d+tXaiG08g/RiEey8lMLL5Wy92atOLs8pOb6M3o2rSZMFaFb8yGryvo5xzPklQ v X-Received: by 2002:adf:a54d:: with SMTP id j13-v6mr1561236wrb.155.1530018960976; Tue, 26 Jun 2018 06:16:00 -0700 (PDT) X-Received: by 2002:adf:a54d:: with SMTP id j13-v6mr1561178wrb.155.1530018959882; Tue, 26 Jun 2018 06:15:59 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1530018959; cv=none; d=google.com; s=arc-20160816; b=kLc2jIytegpgT5fyR1xqF+eqA47CP/76okZZ0arBPhXEdlETYwxJnaRKm/e6nUgce5 t4pqr7MfAPYQbsxH84a8G6kVM+2DXyrZm7NjXaqeP0r0hquUvkW0Hnl43IWX/MgBOU6A HAOBSshWFjcpIjbO0gf3iAN/Z6dYL+o1WYIaChMNnPuEchvQJLoFq0/RGi+Mv1LeQjxs OHElN4E6kfIuLQ3FCNEx2XcsyuG1MdGCuqETlFoRPZ2ar4gWYEDnnpRE/G1UvvogfT4N 2x47WHP+QYARzN4P7jLdSZy8xRifhJ9SVy/79BtQDNYvptHM73w4QsuPz9mx9dMyGOxK CYzQ== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=references:in-reply-to:message-id:date:subject:cc:to:from :dkim-signature:arc-authentication-results; bh=EP2Dki4EWWZ2WEvc6M+bB9+4bOXHIe54Gcv4T4SHLRg=; b=yu4mXKkAwdMllneeMDXU6+IuYlUZaIYJV7gfrWnJlkeXSVNSrIkZh0GHUVc4CEm+hG E4Sz6rz6mSKGAAk+PuVx8v7N9oRRojBRnXp7AiQTgERtQTKus/Mdr9ClJBU/Z8ZaJc3m 6ZYNajNLGisjBsV2looZF+UCnc7SE1eZa91rW4YtajOe3CVLHX5q2VoHicIWDLSun4Ab tGFhy7TC1Y+zRgfHKGcXwWggNgFxWypcKAUyNDxuWx7voWxQg4dorzYZWjY//Wbto72G ygPWG78MOvChNoAppbsiUQeWPu4m4j9wEXakMs0F3c0379b1ig3BUpBB6axADWfPEPjA K9Qg== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@google.com header.s=20161025 header.b=tP3T9GZT; spf=pass (google.com: domain of andreyknvl@google.com designates 209.85.220.65 as permitted sender) smtp.mailfrom=andreyknvl@google.com; dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=google.com Received: from mail-sor-f65.google.com (mail-sor-f65.google.com. [209.85.220.65]) by mx.google.com with SMTPS id u1-v6sor573411wri.78.2018.06.26.06.15.59 for (Google Transport Security); Tue, 26 Jun 2018 06:15:59 -0700 (PDT) Received-SPF: pass (google.com: domain of andreyknvl@google.com designates 209.85.220.65 as permitted sender) client-ip=209.85.220.65; Authentication-Results: mx.google.com; dkim=pass header.i=@google.com header.s=20161025 header.b=tP3T9GZT; spf=pass (google.com: domain of andreyknvl@google.com designates 209.85.220.65 as permitted sender) smtp.mailfrom=andreyknvl@google.com; dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=google.com DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20161025; h=from:to:cc:subject:date:message-id:in-reply-to:references; bh=EP2Dki4EWWZ2WEvc6M+bB9+4bOXHIe54Gcv4T4SHLRg=; b=tP3T9GZTcDl6sqUhST8VsnHchEalIHYPswEFU9VUy7f9t1zbWyFcTLdS0psY+d4o/v ANdg4IwZfzGL5HClnDgybjyli/txaY22L/ymiTvnVDZpW1HrKlHsQLWSIfsXpBJItKWN zo//HeueKsd5yERZIV1bDSpwQQa0iRqD6VlwduoonlUmoyuJEHEwNvpUM6QuSBP60Uir ts/hFjdrUyd1Ix8BBh8ZYP6xGFbbpSOWuYcCkYyfCZDnOvgeRqOdk/fNn30c6tqdVLpX X+PmiFnO/EFnY37ufjibH598VtfKS2SjQ++OW5uhG52javBmd+D4MiE6X6/yjqD8qe/Q MDqA== X-Google-Smtp-Source: AAOMgpcwLC6WteD5eQOoz/gQ/wmnxQoEg1Rjd3LVuSQVs2Xf+NomWpZHfIoqNwGgvQayzaQdkoEUqQ== X-Received: by 2002:adf:81ca:: with SMTP id 68-v6mr1426498wra.44.1530018959149; Tue, 26 Jun 2018 06:15:59 -0700 (PDT) Received: from andreyknvl0.muc.corp.google.com ([2a00:79e0:15:10:84be:a42a:826d:c530]) by smtp.gmail.com with ESMTPSA id w15-v6sm2162639wrn.25.2018.06.26.06.15.57 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Tue, 26 Jun 2018 06:15:58 -0700 (PDT) From: Andrey Konovalov To: Andrey Ryabinin , Alexander Potapenko , Dmitry Vyukov , Catalin Marinas , Will Deacon , Christoph Lameter , Andrew Morton , Mark Rutland , Nick Desaulniers , Marc Zyngier , Dave Martin , Ard Biesheuvel , "Eric W . Biederman" , Ingo Molnar , Paul Lawrence , Geert Uytterhoeven , Arnd Bergmann , "Kirill A . Shutemov" , Greg Kroah-Hartman , Kate Stewart , Mike Rapoport , kasan-dev@googlegroups.com, linux-doc@vger.kernel.org, linux-kernel@vger.kernel.org, linux-arm-kernel@lists.infradead.org, linux-sparse@vger.kernel.org, linux-mm@kvack.org, linux-kbuild@vger.kernel.org Cc: Kostya Serebryany , Evgeniy Stepanov , Lee Smith , Ramana Radhakrishnan , Jacob Bramley , Ruben Ayrapetyan , Jann Horn , Mark Brand , Chintan Pandya , Andrey Konovalov Subject: [PATCH v4 14/17] khwasan, arm64: add brk handler for inline instrumentation Date: Tue, 26 Jun 2018 15:15:24 +0200 Message-Id: <69fd53d114e5814020e5e265ae451a63b09c776e.1530018818.git.andreyknvl@google.com> X-Mailer: git-send-email 2.18.0.rc2.346.g013aa6912e-goog In-Reply-To: References: X-Bogosity: Ham, tests=bogofilter, spamicity=0.000000, version=1.2.4 Sender: owner-linux-mm@kvack.org Precedence: bulk X-Loop: owner-majordomo@kvack.org List-ID: X-Virus-Scanned: ClamAV using ClamSMTP KHWASAN inline instrumentation mode (which embeds checks of shadow memory into the generated code, instead of inserting a callback) generates a brk instruction when a tag mismatch is detected. This commit add a KHWASAN brk handler, that decodes the immediate value passed to the brk instructions (to extract information about the memory access that triggered the mismatch), reads the register values (x0 contains the guilty address) and reports the bug. Signed-off-by: Andrey Konovalov --- arch/arm64/include/asm/brk-imm.h | 2 + arch/arm64/kernel/traps.c | 69 +++++++++++++++++++++++++++++++- 2 files changed, 69 insertions(+), 2 deletions(-) diff --git a/arch/arm64/include/asm/brk-imm.h b/arch/arm64/include/asm/brk-imm.h index ed693c5bcec0..e4a7013321dc 100644 --- a/arch/arm64/include/asm/brk-imm.h +++ b/arch/arm64/include/asm/brk-imm.h @@ -16,10 +16,12 @@ * 0x400: for dynamic BRK instruction * 0x401: for compile time BRK instruction * 0x800: kernel-mode BUG() and WARN() traps + * 0x9xx: KHWASAN trap (allowed values 0x900 - 0x9ff) */ #define FAULT_BRK_IMM 0x100 #define KGDB_DYN_DBG_BRK_IMM 0x400 #define KGDB_COMPILED_DBG_BRK_IMM 0x401 #define BUG_BRK_IMM 0x800 +#define KHWASAN_BRK_IMM 0x900 #endif diff --git a/arch/arm64/kernel/traps.c b/arch/arm64/kernel/traps.c index d399d459397b..95152a4fd202 100644 --- a/arch/arm64/kernel/traps.c +++ b/arch/arm64/kernel/traps.c @@ -35,6 +35,7 @@ #include #include #include +#include #include #include @@ -269,10 +270,14 @@ void arm64_notify_die(const char *str, struct pt_regs *regs, } } -void arm64_skip_faulting_instruction(struct pt_regs *regs, unsigned long size) +void __arm64_skip_faulting_instruction(struct pt_regs *regs, unsigned long size) { regs->pc += size; +} +void arm64_skip_faulting_instruction(struct pt_regs *regs, unsigned long size) +{ + __arm64_skip_faulting_instruction(regs, size); /* * If we were single stepping, we want to get the step exception after * we return from the trap. @@ -791,7 +796,7 @@ static int bug_handler(struct pt_regs *regs, unsigned int esr) } /* If thread survives, skip over the BUG instruction and continue: */ - arm64_skip_faulting_instruction(regs, AARCH64_INSN_SIZE); + __arm64_skip_faulting_instruction(regs, AARCH64_INSN_SIZE); return DBG_HOOK_HANDLED; } @@ -801,6 +806,59 @@ static struct break_hook bug_break_hook = { .fn = bug_handler, }; +#ifdef CONFIG_KASAN_HW + +#define KHWASAN_ESR_RECOVER 0x20 +#define KHWASAN_ESR_WRITE 0x10 +#define KHWASAN_ESR_SIZE_MASK 0x0f +#define KHWASAN_ESR_SIZE(esr) (1 << ((esr) & KHWASAN_ESR_SIZE_MASK)) + +static int khwasan_handler(struct pt_regs *regs, unsigned int esr) +{ + bool recover = esr & KHWASAN_ESR_RECOVER; + bool write = esr & KHWASAN_ESR_WRITE; + size_t size = KHWASAN_ESR_SIZE(esr); + u64 addr = regs->regs[0]; + u64 pc = regs->pc; + + if (user_mode(regs)) + return DBG_HOOK_ERROR; + + kasan_report(addr, size, write, pc); + + /* + * The instrumentation allows to control whether we can proceed after + * a crash was detected. This is done by passing the -recover flag to + * the compiler. Disabling recovery allows to generate more compact + * code. + * + * Unfortunately disabling recovery doesn't work for the kernel right + * now. KHWASAN reporting is disabled in some contexts (for example when + * the allocator accesses slab object metadata; same is true for KASAN; + * this is controlled by current->kasan_depth). All these accesses are + * detected by the tool, even though the reports for them are not + * printed. + * + * This is something that might be fixed at some point in the future. + */ + if (!recover) + die("Oops - KHWASAN", regs, 0); + + /* If thread survives, skip over the brk instruction and continue: */ + __arm64_skip_faulting_instruction(regs, AARCH64_INSN_SIZE); + return DBG_HOOK_HANDLED; +} + +#define KHWASAN_ESR_VAL (0xf2000000 | KHWASAN_BRK_IMM) +#define KHWASAN_ESR_MASK 0xffffff00 + +static struct break_hook khwasan_break_hook = { + .esr_val = KHWASAN_ESR_VAL, + .esr_mask = KHWASAN_ESR_MASK, + .fn = khwasan_handler, +}; +#endif + /* * Initial handler for AArch64 BRK exceptions * This handler only used until debug_traps_init(). @@ -808,6 +866,10 @@ static struct break_hook bug_break_hook = { int __init early_brk64(unsigned long addr, unsigned int esr, struct pt_regs *regs) { +#ifdef CONFIG_KASAN_HW + if ((esr & KHWASAN_ESR_MASK) == KHWASAN_ESR_VAL) + return khwasan_handler(regs, esr) != DBG_HOOK_HANDLED; +#endif return bug_handler(regs, esr) != DBG_HOOK_HANDLED; } @@ -815,4 +877,7 @@ int __init early_brk64(unsigned long addr, unsigned int esr, void __init trap_init(void) { register_break_hook(&bug_break_hook); +#ifdef CONFIG_KASAN_HW + register_break_hook(&khwasan_break_hook); +#endif }