1. 19 Jun, 2023 37 commits
  2. 09 Jun, 2023 3 commits
    • Lorenzo Stoakes's avatar
      mm/gup: disallow FOLL_LONGTERM GUP-fast writing to file-backed mappings · a6e79df9
      Lorenzo Stoakes authored
      Writing to file-backed dirty-tracked mappings via GUP is inherently broken
      as we cannot rule out folios being cleaned and then a GUP user writing to
      them again and possibly marking them dirty unexpectedly.
      
      This is especially egregious for long-term mappings (as indicated by the
      use of the FOLL_LONGTERM flag), so we disallow this case in GUP-fast as we
      have already done in the slow path.
      
      We have access to less information in the fast path as we cannot examine
      the VMA containing the mapping, however we can determine whether the folio
      is anonymous or belonging to a whitelisted filesystem - specifically
      hugetlb and shmem mappings.
      
      We take special care to ensure that both the folio and mapping are safe to
      access when performing these checks and document folio_fast_pin_allowed()
      accordingly.
      
      It's important to note that there are no APIs allowing users to specify
      FOLL_FAST_ONLY for a PUP-fast let alone with FOLL_LONGTERM, so we can
      always rely on the fact that if we fail to pin on the fast path, the code
      will fall back to the slow path which can perform the more thorough check.
      
      Link: https://lkml.kernel.org/r/a27d39b87ded7f3dad5fd4181edb106393660453.1683235180.git.lstoakes@gmail.comSigned-off-by: default avatarLorenzo Stoakes <lstoakes@gmail.com>
      Suggested-by: default avatarDavid Hildenbrand <david@redhat.com>
      Suggested-by: default avatarKirill A . Shutemov <kirill@shutemov.name>
      Suggested-by: default avatarPeter Zijlstra <peterz@infradead.org>
      Reviewed-by: default avatarJan Kara <jack@suse.cz>
      Acked-by: default avatarDavid Hildenbrand <david@redhat.com>
      Cc: Jason Gunthorpe <jgg@nvidia.com>
      Cc: John Hubbard <jhubbard@nvidia.com>
      Cc: Mika Penttilä <mpenttil@redhat.com>
      Signed-off-by: default avatarAndrew Morton <akpm@linux-foundation.org>
      a6e79df9
    • Lorenzo Stoakes's avatar
      mm/gup: disallow FOLL_LONGTERM GUP-nonfast writing to file-backed mappings · 8ac26843
      Lorenzo Stoakes authored
      Writing to file-backed mappings which require folio dirty tracking using
      GUP is a fundamentally broken operation, as kernel write access to GUP
      mappings do not adhere to the semantics expected by a file system.
      
      A GUP caller uses the direct mapping to access the folio, which does not
      cause write notify to trigger, nor does it enforce that the caller marks
      the folio dirty.
      
      The problem arises when, after an initial write to the folio, writeback
      results in the folio being cleaned and then the caller, via the GUP
      interface, writes to the folio again.
      
      As a result of the use of this secondary, direct, mapping to the folio no
      write notify will occur, and if the caller does mark the folio dirty, this
      will be done so unexpectedly.
      
      For example, consider the following scenario:-
      
      1. A folio is written to via GUP which write-faults the memory, notifying
         the file system and dirtying the folio.
      2. Later, writeback is triggered, resulting in the folio being cleaned and
         the PTE being marked read-only.
      3. The GUP caller writes to the folio, as it is mapped read/write via the
         direct mapping.
      4. The GUP caller, now done with the page, unpins it and sets it dirty
         (though it does not have to).
      
      This results in both data being written to a folio without writenotify,
      and the folio being dirtied unexpectedly (if the caller decides to do so).
      
      This issue was first reported by Jan Kara [1] in 2018, where the problem
      resulted in file system crashes.
      
      This is only relevant when the mappings are file-backed and the underlying
      file system requires folio dirty tracking.  File systems which do not,
      such as shmem or hugetlb, are not at risk and therefore can be written to
      without issue.
      
      Unfortunately this limitation of GUP has been present for some time and
      requires future rework of the GUP API in order to provide correct write
      access to such mappings.
      
      However, for the time being we introduce this check to prevent the most
      egregious case of this occurring, use of the FOLL_LONGTERM pin.
      
      These mappings are considerably more likely to be written to after folios
      are cleaned and thus simply must not be permitted to do so.
      
      This patch changes only the slow-path GUP functions, a following patch
      adapts the GUP-fast path along similar lines.
      
      [1] https://lore.kernel.org/linux-mm/20180103100430.GE4911@quack2.suse.cz/
      
      Link: https://lkml.kernel.org/r/7282506742d2390c125949c2f9894722750bb68a.1683235180.git.lstoakes@gmail.comSigned-off-by: default avatarLorenzo Stoakes <lstoakes@gmail.com>
      Suggested-by: default avatarJason Gunthorpe <jgg@nvidia.com>
      Reviewed-by: default avatarJohn Hubbard <jhubbard@nvidia.com>
      Reviewed-by: default avatarMika Penttilä <mpenttil@redhat.com>
      Reviewed-by: default avatarJan Kara <jack@suse.cz>
      Reviewed-by: default avatarJason Gunthorpe <jgg@nvidia.com>
      Acked-by: default avatarDavid Hildenbrand <david@redhat.com>
      Cc: Kirill A . Shutemov <kirill@shutemov.name>
      Cc: Peter Zijlstra <peterz@infradead.org>
      Signed-off-by: default avatarAndrew Morton <akpm@linux-foundation.org>
      8ac26843
    • Lorenzo Stoakes's avatar
      mm/mmap: separate writenotify and dirty tracking logic · 54cbbbf3
      Lorenzo Stoakes authored
      Patch series "mm/gup: disallow GUP writing to file-backed mappings by
      default", v9.
      
      Writing to file-backed mappings which require folio dirty tracking using
      GUP is a fundamentally broken operation, as kernel write access to GUP
      mappings do not adhere to the semantics expected by a file system.
      
      A GUP caller uses the direct mapping to access the folio, which does not
      cause write notify to trigger, nor does it enforce that the caller marks
      the folio dirty.
      
      The problem arises when, after an initial write to the folio, writeback
      results in the folio being cleaned and then the caller, via the GUP
      interface, writes to the folio again.
      
      As a result of the use of this secondary, direct, mapping to the folio no
      write notify will occur, and if the caller does mark the folio dirty, this
      will be done so unexpectedly.
      
      For example, consider the following scenario:-
      
      1. A folio is written to via GUP which write-faults the memory, notifying
         the file system and dirtying the folio.
      2. Later, writeback is triggered, resulting in the folio being cleaned and
         the PTE being marked read-only.
      3. The GUP caller writes to the folio, as it is mapped read/write via the
         direct mapping.
      4. The GUP caller, now done with the page, unpins it and sets it dirty
         (though it does not have to).
      
      This change updates both the PUP FOLL_LONGTERM slow and fast APIs.  As
      pin_user_pages_fast_only() does not exist, we can rely on a slightly
      imperfect whitelisting in the PUP-fast case and fall back to the slow case
      should this fail.
      
      
      This patch (of 3):
      
      vma_wants_writenotify() is specifically intended for setting PTE page
      table flags, accounting for existing page table flag state and whether the
      underlying filesystem performs dirty tracking for a file-backed mapping.
      
      Everything is predicated firstly on whether the mapping is shared
      writable, as this is the only instance where dirty tracking is pertinent -
      MAP_PRIVATE mappings will always be CoW'd and unshared, and read-only
      file-backed shared mappings cannot be written to, even with FOLL_FORCE.
      
      All other checks are in line with existing logic, though now separated
      into checks eplicitily for dirty tracking and those for determining how to
      set page table flags.
      
      We make this change so we can perform checks in the GUP logic to determine
      which mappings might be problematic when written to.
      
      Link: https://lkml.kernel.org/r/cover.1683235180.git.lstoakes@gmail.com
      Link: https://lkml.kernel.org/r/0f218370bd49b4e6bbfbb499f7c7b92c26ba1ceb.1683235180.git.lstoakes@gmail.comSigned-off-by: default avatarLorenzo Stoakes <lstoakes@gmail.com>
      Reviewed-by: default avatarJohn Hubbard <jhubbard@nvidia.com>
      Reviewed-by: default avatarMika Penttilä <mpenttil@redhat.com>
      Reviewed-by: default avatarJan Kara <jack@suse.cz>
      Reviewed-by: default avatarJason Gunthorpe <jgg@nvidia.com>
      Acked-by: default avatarDavid Hildenbrand <david@redhat.com>
      Cc: Kirill A . Shutemov <kirill@shutemov.name>
      Cc: Peter Zijlstra <peterz@infradead.org>
      Signed-off-by: default avatarAndrew Morton <akpm@linux-foundation.org>
      54cbbbf3