From: Kees Cook <keescook@chromium•org>
To: Vlastimil Babka <vbabka@suse•cz>
Cc: "Christian König" <christian.koenig@amd•com>,
"Pekka Enberg" <penberg@kernel•org>,
"Feng Tang" <feng.tang@intel•com>,
"David Rientjes" <rientjes@google•com>,
"Joonsoo Kim" <iamjoonsoo.kim@lge•com>,
"Andrew Morton" <akpm@linux-foundation•org>,
"David S. Miller" <davem@davemloft•net>,
"Eric Dumazet" <edumazet@google•com>,
"Jakub Kicinski" <kuba@kernel•org>,
"Paolo Abeni" <pabeni@redhat•com>,
"Greg Kroah-Hartman" <gregkh@linuxfoundation•org>,
"Nick Desaulniers" <ndesaulniers@google•com>,
"Alex Elder" <elder@kernel•org>,
"Josef Bacik" <josef@toxicpanda•com>,
"David Sterba" <dsterba@suse•com>,
"Sumit Semwal" <sumit.semwal@linaro•org>,
"Jesse Brandeburg" <jesse.brandeburg@intel•com>,
"Daniel Micay" <danielmicay@gmail•com>,
"Yonghong Song" <yhs@fb•com>, "Marco Elver" <elver@google•com>,
"Miguel Ojeda" <ojeda@kernel•org>,
linux-kernel@vger•kernel.org, linux-mm@kvack•org,
netdev@vger•kernel.org, linux-btrfs@vger•kernel.org,
linux-media@vger•kernel.org, dri-devel@lists•freedesktop.org,
linaro-mm-sig@lists•linaro.org, linux-fsdevel@vger•kernel.org,
intel-wired-lan@lists•osuosl.org, dev@openvswitch•org,
x86@kernel•org, linux-wireless@vger•kernel.org,
llvm@lists•linux.dev, linux-hardening@vger•kernel.org,
"Hyeonggon Yoo" <42.hyeyoo@gmail•com>
Subject: Re: [PATCH 00/12] slab: Introduce kmalloc_size_roundup()
Date: Thu, 22 Sep 2022 14:49:08 -0700 [thread overview]
Message-ID: <202209221446.5E90AEED@keescook> (raw)
In-Reply-To: <cb38655c-2107-bda6-2fa8-f5e1e97eab14@suse.cz>
On Thu, Sep 22, 2022 at 11:05:47PM +0200, Vlastimil Babka wrote:
> On 9/22/22 17:55, Kees Cook wrote:
> > On Thu, Sep 22, 2022 at 09:10:56AM +0200, Christian König wrote:
> > [...]
> > > So when this patch set is about to clean up this use case it should probably
> > > also take care to remove ksize() or at least limit it so that it won't be
> > > used for this use case in the future.
> >
> > Yeah, my goal would be to eliminate ksize(), and it seems possible if
> > other cases are satisfied with tracking their allocation sizes directly.
>
> I think we could leave ksize() to determine the size without a need for
> external tracking, but from now on forbid callers from using that hint to
> overflow the allocation size they actually requested? Once we remove the
> kasan/kfence hooks in ksize() that make the current kinds of usage possible,
> we should be able to catch any offenders of the new semantics that would appear?
That's correct. I spent the morning working my way through the rest of
the ksize() users I didn't clean up yesterday, and in several places I
just swapped in __ksize(). But that wouldn't even be needed if we just
removed the kasan unpoisoning from ksize(), etc.
I am tempted to leave it __ksize(), though, just to reinforce that it's
not supposed to be used "normally". What do you think?
--
Kees Cook
next prev parent reply other threads:[~2022-09-22 21:49 UTC|newest]
Thread overview: 32+ messages / expand[flat|nested] mbox.gz Atom feed top
2022-09-22 3:10 [PATCH 00/12] slab: Introduce kmalloc_size_roundup() Kees Cook
2022-09-22 3:10 ` [PATCH 01/12] " Kees Cook
2022-09-22 11:12 ` Hyeonggon Yoo
2022-09-23 1:17 ` Feng Tang
2022-09-23 18:50 ` Kees Cook
2022-09-22 3:10 ` [PATCH 02/12] skbuff: Proactively round up to kmalloc bucket size Kees Cook
2022-09-22 19:40 ` Jakub Kicinski
2022-09-22 3:10 ` [PATCH 03/12] net: ipa: " Kees Cook
2022-09-22 13:45 ` Alex Elder
2022-09-22 15:57 ` Kees Cook
2022-09-22 3:10 ` [PATCH 04/12] btrfs: send: " Kees Cook
2022-09-22 13:30 ` David Sterba
2022-09-22 3:10 ` [PATCH 05/12] dma-buf: " Kees Cook
2022-09-22 3:10 ` [PATCH 06/12] coredump: " Kees Cook
2022-09-22 3:10 ` [PATCH 07/12] igb: " Kees Cook
2022-09-22 15:56 ` Ruhl, Michael J
2022-09-22 16:00 ` Kees Cook
2022-09-22 3:10 ` [PATCH 08/12] openvswitch: " Kees Cook
2022-09-22 3:10 ` [PATCH 09/12] x86/microcode/AMD: Track patch allocation size explicitly Kees Cook
2022-09-22 3:10 ` [PATCH 10/12] iwlwifi: Track scan_cmd " Kees Cook
2022-09-22 4:18 ` Kalle Valo
2022-09-22 5:26 ` Kees Cook
2022-09-22 3:10 ` [PATCH 11/12] slab: Remove __malloc attribute from realloc functions Kees Cook
2022-09-22 9:23 ` Miguel Ojeda
2022-09-22 15:56 ` Kees Cook
2022-09-22 17:41 ` Miguel Ojeda
2022-09-22 3:10 ` [PATCH 12/12] slab: Restore __alloc_size attribute to __kmalloc_track_caller Kees Cook
2022-09-22 7:10 ` [PATCH 00/12] slab: Introduce kmalloc_size_roundup() Christian König
2022-09-22 15:55 ` Kees Cook
2022-09-22 21:05 ` Vlastimil Babka
2022-09-22 21:49 ` Kees Cook [this message]
2022-09-23 9:07 ` Vlastimil Babka
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=202209221446.5E90AEED@keescook \
--to=keescook@chromium$(echo .)org \
--cc=42.hyeyoo@gmail$(echo .)com \
--cc=akpm@linux-foundation$(echo .)org \
--cc=christian.koenig@amd$(echo .)com \
--cc=danielmicay@gmail$(echo .)com \
--cc=davem@davemloft$(echo .)net \
--cc=dev@openvswitch$(echo .)org \
--cc=dri-devel@lists$(echo .)freedesktop.org \
--cc=dsterba@suse$(echo .)com \
--cc=edumazet@google$(echo .)com \
--cc=elder@kernel$(echo .)org \
--cc=elver@google$(echo .)com \
--cc=feng.tang@intel$(echo .)com \
--cc=gregkh@linuxfoundation$(echo .)org \
--cc=iamjoonsoo.kim@lge$(echo .)com \
--cc=intel-wired-lan@lists$(echo .)osuosl.org \
--cc=jesse.brandeburg@intel$(echo .)com \
--cc=josef@toxicpanda$(echo .)com \
--cc=kuba@kernel$(echo .)org \
--cc=linaro-mm-sig@lists$(echo .)linaro.org \
--cc=linux-btrfs@vger$(echo .)kernel.org \
--cc=linux-fsdevel@vger$(echo .)kernel.org \
--cc=linux-hardening@vger$(echo .)kernel.org \
--cc=linux-kernel@vger$(echo .)kernel.org \
--cc=linux-media@vger$(echo .)kernel.org \
--cc=linux-mm@kvack$(echo .)org \
--cc=linux-wireless@vger$(echo .)kernel.org \
--cc=llvm@lists$(echo .)linux.dev \
--cc=ndesaulniers@google$(echo .)com \
--cc=netdev@vger$(echo .)kernel.org \
--cc=ojeda@kernel$(echo .)org \
--cc=pabeni@redhat$(echo .)com \
--cc=penberg@kernel$(echo .)org \
--cc=rientjes@google$(echo .)com \
--cc=sumit.semwal@linaro$(echo .)org \
--cc=vbabka@suse$(echo .)cz \
--cc=x86@kernel$(echo .)org \
--cc=yhs@fb$(echo .)com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox