From: catalin.marinas@arm•com (Catalin Marinas)
To: linux-arm-kernel@lists•infradead.org
Subject: [PATCH 2/3] ARM: cacheflush: don't bother rounding to nearest vma
Date: Wed, 27 Mar 2013 12:21:59 +0000 [thread overview]
Message-ID: <20130327122159.GE1603@MacBook-Pro.local> (raw)
In-Reply-To: <20130327121512.GC17185@mudshark.cambridge.arm.com>
On Wed, Mar 27, 2013 at 12:15:12PM +0000, Will Deacon wrote:
> On Wed, Mar 27, 2013 at 11:09:38AM +0000, Catalin Marinas wrote:
> > On Mon, Mar 25, 2013 at 06:18:05PM +0000, Will Deacon wrote:
> > > diff --git a/arch/arm/kernel/traps.c b/arch/arm/kernel/traps.c
> > > index 1c08911..da5e268 100644
> > > --- a/arch/arm/kernel/traps.c
> > > +++ b/arch/arm/kernel/traps.c
> > > @@ -509,25 +509,10 @@ static int bad_syscall(int n, struct pt_regs *regs)
> > > static inline int
> > > do_cache_op(unsigned long start, unsigned long end, int flags)
> > > {
> > > - struct mm_struct *mm = current->active_mm;
> > > - struct vm_area_struct *vma;
> > > -
> > > if (end < start || flags)
> > > return -EINVAL;
> > >
> > > - down_read(&mm->mmap_sem);
> > > - vma = find_vma(mm, start);
> > > - if (vma && vma->vm_start < end) {
> > > - if (start < vma->vm_start)
> > > - start = vma->vm_start;
> > > - if (end > vma->vm_end)
> > > - end = vma->vm_end;
> > > -
> > > - up_read(&mm->mmap_sem);
> > > - return flush_cache_user_range(start, end);
> > > - }
> > > - up_read(&mm->mmap_sem);
> > > - return -EINVAL;
> > > + return flush_cache_user_range(start, end);
> >
> > While this would work, it introduces a possibility of DoS where an
> > application passes bigger valid range (kernel linear mapping) and the
> > kernel code would not be preempted (CONFIG_PREEMPT disabled). IIRC,
> > that's why Russell reject such patch a while back.
>
> Hmm, I'm not sure I buy that argument. Firstly, you can't just pass a kernel
> linear mapping address -- we'll fault straight away because it's not a
> userspace address.
Fault where?
> Secondly, what's to stop an application from mmaping a large area into
> a single VMA and giving rise to the same situation? Finally,
> interrupts are enabled during this operation, so I don't understand
> how you can trigger a DoS, irrespective of the preempt configuration.
You can prevent context switching to other threads. But I agree, with a
large vma (which is already faulted in), you can get similar behaviour.
> Is there an old thread I can refer to with more details about this? It may
> be that some of the assumptions there no longer hold with subsequent changes
> to the fault handling on this path.
You could search the list for "do_cache_op", I don't have any at hand.
--
Catalin
next prev parent reply other threads:[~2013-03-27 12:21 UTC|newest]
Thread overview: 13+ messages / expand[flat|nested] mbox.gz Atom feed top
2013-03-25 18:18 [PATCH 0/3] Optimise cache-flushing system call and add iovec variant Will Deacon
2013-03-25 18:18 ` [PATCH 1/3] ARM: cacheflush: don't round address range up to nearest page Will Deacon
2013-03-27 11:05 ` Catalin Marinas
2013-03-25 18:18 ` [PATCH 2/3] ARM: cacheflush: don't bother rounding to nearest vma Will Deacon
2013-03-27 11:09 ` Catalin Marinas
2013-03-27 12:15 ` Will Deacon
2013-03-27 12:21 ` Catalin Marinas [this message]
2013-03-27 12:43 ` Will Deacon
2013-03-27 13:08 ` Catalin Marinas
2013-03-25 18:18 ` [PATCH 3/3] ARM: cacheflush: add new iovec-based cache flushing system call Will Deacon
2013-03-27 11:12 ` Catalin Marinas
2013-05-23 10:52 ` Will Deacon
2013-03-25 18:44 ` [PATCH 0/3] Optimise cache-flushing system call and add iovec variant Jonathan Austin
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20130327122159.GE1603@MacBook-Pro.local \
--to=catalin.marinas@arm$(echo .)com \
--cc=linux-arm-kernel@lists$(echo .)infradead.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox