Thread (55 messages) 55 messages, 7 authors, 2021-09-27

Re: [PATCH v4 11/15] pci: Add pci_iomap_shared{,_range}

From: "Michael S. Tsirkin" <mst@redhat.com>
Date: 2021-09-10 09:54:43
Also in: linux-arch, linux-doc, linux-mips, linux-pci, lkml, sparclinux, virtualization

On Mon, Aug 30, 2021 at 05:23:17PM -0700, Andi Kleen wrote:
On 8/30/2021 1:59 PM, Michael S. Tsirkin wrote:
quoted
quoted
Or we can add _audited to the name. ioremap_shared_audited?
But it's not the mapping that has to be done in handled special way.
It's any data we get from device, not all of it coming from IO, e.g.
there's DMA and interrupts that all have to be validated.
Wouldn't you say that what is really wanted is just not running
unaudited drivers in the first place?

Yes.
Then ... let's do just that?
quoted
quoted
And we've been avoiding that drivers can self declare auditing, we've been
trying to have a separate centralized list so that it's easier to enforce
and avoids any cut'n'paste mistakes.

-Andi
Now I'm confused. What is proposed here seems to be basically that,
drivers need to declare auditing by replacing ioremap with
ioremap_shared.
Auditing is declared on the device model level using a central allow list.
Can we not have an init call allow list instead of, or in addition to, a
device allow list?
But this cannot do anything to initcalls that run before probe,
Can't we extend module_init so init calls are validated against the
allow list?
that's why
an extra level of defense of ioremap opt-in is useful.
OK even assuming this, why is pci_iomap opt-in useful?
That never happens before probe - there's simply no pci_device then.
But it's not the
primary mechanism to declare a driver audited, that's the allow list. The
ioremap is just another mechanism to avoid having to touch a lot of legacy
drivers.

If we agree on that then the original proposed semantics of "ioremap_shared"
may be acceptable?

-Andi
It looks suspiciously like drivers self-declaring auditing to me which
we both seem to agree is undesirable. What exactly is the difference?

Or are you just trying to disable anything that runs before probe?
In that case I don't see a reason to touch pci drivers though.
These should be fine with just the device model list.

-- 
MST
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help