• Ilya Leoshkevich's avatar
    kmsan: support SLAB_POISON · f4168171
    Ilya Leoshkevich authored
    Avoid false KMSAN negatives with SLUB_DEBUG by allowing kmsan_slab_free()
    to poison the freed memory, and by preventing init_object() from
    unpoisoning new allocations by using __memset().
    
    There are two alternatives to this approach.  First, init_object() can be
    marked with __no_sanitize_memory.  This annotation should be used with
    great care, because it drops all instrumentation from the function, and
    any shadow writes will be lost.  Even though this is not a concern with
    the current init_object() implementation, this may change in the future.
    
    Second, kmsan_poison_memory() calls may be added after memset() calls. 
    The downside is that init_object() is called from free_debug_processing(),
    in which case poisoning will erase the distinction between simply
    uninitialized memory and UAF.
    
    Link: https://lkml.kernel.org/r/20240621113706.315500-14-iii@linux.ibm.comSigned-off-by: default avatarIlya Leoshkevich <iii@linux.ibm.com>
    Reviewed-by: default avatarAlexander Potapenko <glider@google.com>
    Cc: Alexander Gordeev <agordeev@linux.ibm.com>
    Cc: Christian Borntraeger <borntraeger@linux.ibm.com>
    Cc: Christoph Lameter <cl@linux.com>
    Cc: David Rientjes <rientjes@google.com>
    Cc: Dmitry Vyukov <dvyukov@google.com>
    Cc: Heiko Carstens <hca@linux.ibm.com>
    Cc: Hyeonggon Yoo <42.hyeyoo@gmail.com>
    Cc: Joonsoo Kim <iamjoonsoo.kim@lge.com>
    Cc: <kasan-dev@googlegroups.com>
    Cc: Marco Elver <elver@google.com>
    Cc: Mark Rutland <mark.rutland@arm.com>
    Cc: Masami Hiramatsu (Google) <mhiramat@kernel.org>
    Cc: Pekka Enberg <penberg@kernel.org>
    Cc: Roman Gushchin <roman.gushchin@linux.dev>
    Cc: Steven Rostedt (Google) <rostedt@goodmis.org>
    Cc: Sven Schnelle <svens@linux.ibm.com>
    Cc: Vasily Gorbik <gor@linux.ibm.com>
    Cc: Vlastimil Babka <vbabka@suse.cz>
    Signed-off-by: default avatarAndrew Morton <akpm@linux-foundation.org>
    f4168171
slub.c 182 KB