Skip to content

Commit

Permalink
kasan: add bug reporting routines for tag-based mode
Browse files Browse the repository at this point in the history
This commit adds rountines, that print tag-based KASAN error reports.
Those are quite similar to generic KASAN, the difference is:

1. The way tag-based KASAN finds the first bad shadow cell (with a
   mismatching tag). Tag-based KASAN compares memory tags from the shadow
   memory to the pointer tag.

2. Tag-based KASAN reports all bugs with the "KASAN: invalid-access"
   header.

Also simplify generic KASAN find_first_bad_addr.

Link: http://lkml.kernel.org/r/aee6897b1bd077732a315fd84c6b4f234dbfdfcb.1544099024.git.andreyknvl@google.com
Signed-off-by: Andrey Konovalov <[email protected]>
Reviewed-by: Andrey Ryabinin <[email protected]>
Reviewed-by: Dmitry Vyukov <[email protected]>
Cc: Christoph Lameter <[email protected]>
Cc: Mark Rutland <[email protected]>
Cc: Will Deacon <[email protected]>
Signed-off-by: Andrew Morton <[email protected]>
Signed-off-by: Linus Torvalds <[email protected]>
  • Loading branch information
xairy authored and torvalds committed Dec 28, 2018
1 parent 11cd3cd commit 121e8f8
Show file tree
Hide file tree
Showing 4 changed files with 59 additions and 37 deletions.
16 changes: 5 additions & 11 deletions mm/kasan/generic_report.c
Original file line number Diff line number Diff line change
Expand Up @@ -33,26 +33,20 @@
#include "kasan.h"
#include "../slab.h"

static const void *find_first_bad_addr(const void *addr, size_t size)
void *find_first_bad_addr(void *addr, size_t size)
{
u8 shadow_val = *(u8 *)kasan_mem_to_shadow(addr);
const void *first_bad_addr = addr;
void *p = addr;

while (!shadow_val && first_bad_addr < addr + size) {
first_bad_addr += KASAN_SHADOW_SCALE_SIZE;
shadow_val = *(u8 *)kasan_mem_to_shadow(first_bad_addr);
}
return first_bad_addr;
while (p < addr + size && !(*(u8 *)kasan_mem_to_shadow(p)))
p += KASAN_SHADOW_SCALE_SIZE;
return p;
}

static const char *get_shadow_bug_type(struct kasan_access_info *info)
{
const char *bug_type = "unknown-crash";
u8 *shadow_addr;

info->first_bad_addr = find_first_bad_addr(info->access_addr,
info->access_size);

shadow_addr = (u8 *)kasan_mem_to_shadow(info->first_bad_addr);

/*
Expand Down
5 changes: 5 additions & 0 deletions mm/kasan/kasan.h
Original file line number Diff line number Diff line change
Expand Up @@ -119,6 +119,7 @@ void kasan_poison_shadow(const void *address, size_t size, u8 value);
void check_memory_region(unsigned long addr, size_t size, bool write,
unsigned long ret_ip);

void *find_first_bad_addr(void *addr, size_t size);
const char *get_bug_type(struct kasan_access_info *info);

void kasan_report(unsigned long addr, size_t size,
Expand All @@ -139,10 +140,14 @@ static inline void quarantine_remove_cache(struct kmem_cache *cache) { }

#ifdef CONFIG_KASAN_SW_TAGS

void print_tags(u8 addr_tag, const void *addr);

u8 random_tag(void);

#else

static inline void print_tags(u8 addr_tag, const void *addr) { }

static inline u8 random_tag(void)
{
return 0;
Expand Down
57 changes: 31 additions & 26 deletions mm/kasan/report.c
Original file line number Diff line number Diff line change
Expand Up @@ -64,11 +64,10 @@ static int __init kasan_set_multi_shot(char *str)
}
__setup("kasan_multi_shot", kasan_set_multi_shot);

static void print_error_description(struct kasan_access_info *info,
const char *bug_type)
static void print_error_description(struct kasan_access_info *info)
{
pr_err("BUG: KASAN: %s in %pS\n",
bug_type, (void *)info->ip);
get_bug_type(info), (void *)info->ip);
pr_err("%s of size %zu at addr %px by task %s/%d\n",
info->is_write ? "Write" : "Read", info->access_size,
info->access_addr, current->comm, task_pid_nr(current));
Expand Down Expand Up @@ -272,48 +271,54 @@ void kasan_report_invalid_free(void *object, unsigned long ip)

start_report(&flags);
pr_err("BUG: KASAN: double-free or invalid-free in %pS\n", (void *)ip);
print_tags(get_tag(object), reset_tag(object));
object = reset_tag(object);
pr_err("\n");
print_address_description(object);
pr_err("\n");
print_shadow_for_address(object);
end_report(&flags);
}

static void kasan_report_error(struct kasan_access_info *info)
{
unsigned long flags;

start_report(&flags);

print_error_description(info, get_bug_type(info));
pr_err("\n");

if (!addr_has_shadow(info->access_addr)) {
dump_stack();
} else {
print_address_description((void *)info->access_addr);
pr_err("\n");
print_shadow_for_address(info->first_bad_addr);
}

end_report(&flags);
}

void kasan_report(unsigned long addr, size_t size,
bool is_write, unsigned long ip)
{
struct kasan_access_info info;
void *tagged_addr;
void *untagged_addr;
unsigned long flags;

if (likely(!report_enabled()))
return;

disable_trace_on_warning();

info.access_addr = (void *)addr;
info.first_bad_addr = (void *)addr;
tagged_addr = (void *)addr;
untagged_addr = reset_tag(tagged_addr);

info.access_addr = tagged_addr;
if (addr_has_shadow(untagged_addr))
info.first_bad_addr = find_first_bad_addr(tagged_addr, size);
else
info.first_bad_addr = untagged_addr;
info.access_size = size;
info.is_write = is_write;
info.ip = ip;

kasan_report_error(&info);
start_report(&flags);

print_error_description(&info);
if (addr_has_shadow(untagged_addr))
print_tags(get_tag(tagged_addr), info.first_bad_addr);
pr_err("\n");

if (addr_has_shadow(untagged_addr)) {
print_address_description(untagged_addr);
pr_err("\n");
print_shadow_for_address(info.first_bad_addr);
} else {
dump_stack();
}

end_report(&flags);
}
18 changes: 18 additions & 0 deletions mm/kasan/tags_report.c
Original file line number Diff line number Diff line change
Expand Up @@ -37,3 +37,21 @@ const char *get_bug_type(struct kasan_access_info *info)
{
return "invalid-access";
}

void *find_first_bad_addr(void *addr, size_t size)
{
u8 tag = get_tag(addr);
void *p = reset_tag(addr);
void *end = p + size;

while (p < end && tag == *(u8 *)kasan_mem_to_shadow(p))
p += KASAN_SHADOW_SCALE_SIZE;
return p;
}

void print_tags(u8 addr_tag, const void *addr)
{
u8 *shadow = (u8 *)kasan_mem_to_shadow(addr);

pr_err("Pointer tag: [%02x], memory tag: [%02x]\n", addr_tag, *shadow);
}

0 comments on commit 121e8f8

Please sign in to comment.