[PATCH] powerpc/mm: Prevent unlikely crash in copro_calculate_slb()

Subsystems: linux for powerpc (32-bit and 64-bit), the rest

STALE3589d

7 messages, 4 authors, 2016-10-21 · open the first message on its own page

[PATCH] powerpc/mm: Prevent unlikely crash in copro_calculate_slb()

From: Frederic Barrat <hidden>
Date: 2016-06-17 16:53:37

If a cxl adapter faults on an invalid address for a kernel context, we
may enter copro_calculate_slb() with a NULL mm pointer (kernel
context) and an effective address which looks like a user
address. Which will cause a crash when dereferencing mm. It is clearly
an AFU bug, but there's no reason to crash either. So return an error,
so that cxl can ack the interrupt with an address error.

Signed-off-by: Frederic Barrat <redacted>
Cc: <redacted>
---
 arch/powerpc/mm/copro_fault.c | 2 ++
 1 file changed, 2 insertions(+)
diff --git a/arch/powerpc/mm/copro_fault.c b/arch/powerpc/mm/copro_fault.c
index 6527882..ddfd274 100644
--- a/arch/powerpc/mm/copro_fault.c
+++ b/arch/powerpc/mm/copro_fault.c
@@ -106,6 +106,8 @@ int copro_calculate_slb(struct mm_struct *mm, u64 ea, struct copro_slb *slb)
 	switch (REGION_ID(ea)) {
 	case USER_REGION_ID:
 		pr_devel("%s: 0x%llx -- USER_REGION_ID\n", __func__, ea);
+		if (mm == NULL)
+			return 1;
 		psize = get_slice_psize(mm, ea);
 		ssize = user_segment_size(ea);
 		vsid = get_vsid(mm->context.id, ea, ssize);
-- 
2.7.4

Re: [PATCH] powerpc/mm: Prevent unlikely crash in copro_calculate_slb()

From: Ian Munsie <hidden>
Date: 2016-06-21 04:26:06

Acked-by: Ian Munsie <redacted>

Re: [PATCH] powerpc/mm: Prevent unlikely crash in copro_calculate_slb()

From: Frederic Barrat <hidden>
Date: 2016-10-12 14:14:48

ping? The patch still applies cleanly on recent trees.

   Fred

Le 17/06/2016 à 18:53, Frederic Barrat a écrit :
quoted hunk
If a cxl adapter faults on an invalid address for a kernel context, we
may enter copro_calculate_slb() with a NULL mm pointer (kernel
context) and an effective address which looks like a user
address. Which will cause a crash when dereferencing mm. It is clearly
an AFU bug, but there's no reason to crash either. So return an error,
so that cxl can ack the interrupt with an address error.

Signed-off-by: Frederic Barrat <redacted>
Cc: <redacted>
---
 arch/powerpc/mm/copro_fault.c | 2 ++
 1 file changed, 2 insertions(+)
diff --git a/arch/powerpc/mm/copro_fault.c b/arch/powerpc/mm/copro_fault.c
index 6527882..ddfd274 100644
--- a/arch/powerpc/mm/copro_fault.c
+++ b/arch/powerpc/mm/copro_fault.c
@@ -106,6 +106,8 @@ int copro_calculate_slb(struct mm_struct *mm, u64 ea, struct copro_slb *slb)
 	switch (REGION_ID(ea)) {
 	case USER_REGION_ID:
 		pr_devel("%s: 0x%llx -- USER_REGION_ID\n", __func__, ea);
+		if (mm == NULL)
+			return 1;
 		psize = get_slice_psize(mm, ea);
 		ssize = user_segment_size(ea);
 		vsid = get_vsid(mm->context.id, ea, ssize);

Re: [PATCH] powerpc/mm: Prevent unlikely crash in copro_calculate_slb()

From: Michael Ellerman <mpe@ellerman.id.au>
Date: 2016-10-13 10:51:14

Frederic Barrat [off-list ref] writes:
ping? The patch still applies cleanly on recent trees.
Fell through the cracks :/

Fixes: ?

cheers

Re: [PATCH] powerpc/mm: Prevent unlikely crash in copro_calculate_slb()

From: Frederic Barrat <hidden>
Date: 2016-10-13 11:54:21


Le 13/10/2016 à 12:51, Michael Ellerman a écrit :
Frederic Barrat [off-list ref] writes:
quoted
ping? The patch still applies cleanly on recent trees.
Fell through the cracks :/

Fixes: ?
Nothing obvious. Current code was introduced by 
73d16a6e0e51990cbe13f8d8f43bd5329bbab30a
but it was apparently moved from cell, where the issue may not have 
applied, I don't know. I guess we should use that id if really needed:

Fixes: 73d16a6e0e51 ("powerpc/cell: Move data segment faulting code out 
of cell platform")

   Fred

Re: [PATCH] powerpc/mm: Prevent unlikely crash in copro_calculate_slb()

From: Michael Ellerman <mpe@ellerman.id.au>
Date: 2016-10-14 00:41:44

Frederic Barrat [off-list ref] writes:
Le 13/10/2016 =C3=A0 12:51, Michael Ellerman a =C3=A9crit :
quoted
Frederic Barrat [off-list ref] writes:
quoted
ping? The patch still applies cleanly on recent trees.
Fell through the cracks :/

Fixes: ?
Nothing obvious. Current code was introduced by=20
73d16a6e0e51990cbe13f8d8f43bd5329bbab30a
but it was apparently moved from cell, where the issue may not have=20
applied, I don't know. I guess we should use that id if really needed:

Fixes: 73d16a6e0e51 ("powerpc/cell: Move data segment faulting code out o=
f cell platform")

Yeah that works, it allows us to mechanically determine that "if you
have backported 73d16a6e0e51 then you need this fix", which can be
useful.

cheers

Re: powerpc/mm: Prevent unlikely crash in copro_calculate_slb()

From: Michael Ellerman <hidden>
Date: 2016-10-21 22:02:35

On Fri, 2016-17-06 at 16:53:28 UTC, Frederic Barrat wrote:
If a cxl adapter faults on an invalid address for a kernel context, we
may enter copro_calculate_slb() with a NULL mm pointer (kernel
context) and an effective address which looks like a user
address. Which will cause a crash when dereferencing mm. It is clearly
an AFU bug, but there's no reason to crash either. So return an error,
so that cxl can ack the interrupt with an address error.

Signed-off-by: Frederic Barrat <redacted>
Cc: <redacted>
Acked-by: Ian Munsie <redacted>
Applied to powerpc fixes, thanks.

https://git.kernel.org/powerpc/c/d2cf909cda5f8c5609cb7ed6cda816

cheers
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help