[PATCH 0/4] arm64: mte: Fix racing on MTE tag initialisation
STALE1493d
From: Catalin Marinas <catalin.marinas@arm.com>
Date: 2022-07-05 14:27:26
This series aims to fix the races between initialising the tags on a page and setting the PG_mte_tagged flag. Currently the flag is set either before or after that tag initialisation and this can lead to CoW copying stale tags. The first patch moves the flag setting after the tags have been initialised, solving the CoW issue. However, concurrent mprotect() on a shared mapping may (very rarely) lead to valid tags being zeroed. The second skips the sanitise_mte_tags() call in kvm_set_spte_gfn(), deferring it to user_mem_abort(). The outcome is that no sanitise_mte_tags() can be simplified to skip the pfn_to_online_page() check and only rely on VM_MTE_ALLOWED vma flag that can be checked in user_mem_abort(). The third and fourth patches use PG_arch_3 as a lock for page tagging, based on Peter Collingbourne's idea of a two-bit lock. I think the first patch can be queued but the rest needs some in depth review and test. With this series (if correct) we could allos MAP_SHARED on KVM guest memory but this is to be discussed separately as there are some KVM ABI implications. Thanks, Catalin Catalin Marinas (3): arm64: mte: Fix/clarify the PG_mte_tagged semantics KVM: arm64: Simplify the sanitise_mte_tags() logic arm64: mte: Lock a page for MTE tag initialisation Peter Collingbourne (1): mm: Add PG_arch_3 page flag arch/arm64/include/asm/mte.h | 62 ++++++++++++++++++++++++++++++++ arch/arm64/include/asm/pgtable.h | 3 +- arch/arm64/kernel/cpufeature.c | 4 ++- arch/arm64/kernel/elfcore.c | 2 +- arch/arm64/kernel/hibernate.c | 2 +- arch/arm64/kernel/mte.c | 17 +++++---- arch/arm64/kvm/guest.c | 18 ++++++---- arch/arm64/kvm/mmu.c | 42 +++++++++------------- arch/arm64/mm/copypage.c | 6 ++-- arch/arm64/mm/fault.c | 4 ++- arch/arm64/mm/mteswap.c | 5 ++- fs/proc/page.c | 1 + include/linux/page-flags.h | 1 + include/trace/events/mmflags.h | 7 ++-- mm/huge_memory.c | 1 + 15 files changed, 125 insertions(+), 50 deletions(-) _______________________________________________ linux-arm-kernel mailing list linux-arm-kernel@lists.infradead.org http://lists.infradead.org/mailman/listinfo/linux-arm-kernel