Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.kernel > #1221296
| From | Andrey Ryabinin <ryabinin.a.a@gmail.com> |
|---|---|
| Newsgroups | linux.kernel |
| Subject | Re: [PATCH V2] kasan: fix last shadow judgement in memory_is_poisoned_16() |
| Date | 2015-09-09 10:40 +0200 |
| Message-ID | <q6J58-6bW-7@gated-at.bofh.it> (permalink) |
| References | <q6q2t-3WT-7@gated-at.bofh.it> <q6HmF-3Ay-9@gated-at.bofh.it> |
| Organization | linux.* mail to news gateway |
2015-09-09 9:40 GMT+03:00 long.wanglong <long.wanglong@huawei.com>:
> On 2015/9/8 20:12, Xishi Qiu wrote:
>> The shadow which correspond 16 bytes memory may span 2 or 3 bytes. If the
>> memory is aligned on 8, then the shadow takes only 2 bytes. So we check
>> "shadow_first_bytes" is enough, and need not to call "memory_is_poisoned_1(addr + 15);".
>> But the code "if (likely(!last_byte))" is wrong judgement.
>>
>> e.g. addr=0, so last_byte = 15 & KASAN_SHADOW_MASK = 7, then the code will
>> continue to call "memory_is_poisoned_1(addr + 15);"
>>
>> Signed-off-by: Xishi Qiu <qiuxishi@huawei.com>
>> ---
>> mm/kasan/kasan.c | 3 +--
>> 1 files changed, 1 insertions(+), 2 deletions(-)
>>
>> diff --git a/mm/kasan/kasan.c b/mm/kasan/kasan.c
>> index 7b28e9c..8da2114 100644
>> --- a/mm/kasan/kasan.c
>> +++ b/mm/kasan/kasan.c
>> @@ -135,12 +135,11 @@ static __always_inline bool memory_is_poisoned_16(unsigned long addr)
>>
>> if (unlikely(*shadow_addr)) {
>> u16 shadow_first_bytes = *(u16 *)shadow_addr;
>> - s8 last_byte = (addr + 15) & KASAN_SHADOW_MASK;
>>
>> if (unlikely(shadow_first_bytes))
>> return true;
>>
>> - if (likely(!last_byte))
>> + if (likely(IS_ALIGNED(addr, 8)))
>> return false;
>>
>> return memory_is_poisoned_1(addr + 15);
>>
>
> Hi,
> I also notice this problem, how about another method to fix it:
>
> diff --git a/mm/kasan/kasan.c b/mm/kasan/kasan.c
> index 5d65d06..6a20dda 100644
> --- a/mm/kasan/kasan.c
> +++ b/mm/kasan/kasan.c
> @@ -140,7 +140,7 @@ static __always_inline bool memory_is_poisoned_16(unsigned long addr)
> if (unlikely(shadow_first_bytes))
> return true;
>
> - if (likely(!last_byte))
> + if (likely(last_byte >= 7))
I suggested to use IS_ALIGNED instead of this because it generates
less code and it also more readable.
./scripts/bloat-o-meter kasan_aligned.o kasan_last_byte.o
add/remove: 0/0 grow/shrink: 4/0 up/down: 20/0 (20)
function old new delta
__asan_store16_noabort 106 111 +5
__asan_store16 106 111 +5
__asan_load16_noabort 103 108 +5
__asan_load16 103 108 +5
> }
>
> return false;
> }
>
> Otherwise, we also should use IS_ALIGNED macro in memory_is_poisoned_8!
>
I believe this would be a beneficial micro optimization.
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/
Back to linux.kernel | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
[PATCH V2] kasan: fix last shadow judgement in memory_is_poisoned_16() Xishi Qiu <qiuxishi@huawei.com> - 2015-09-08 14:20 +0200
Re: [PATCH V2] kasan: fix last shadow judgement in memory_is_poisoned_16() "long.wanglong" <long.wanglong@huawei.com> - 2015-09-09 08:50 +0200
Re: [PATCH V2] kasan: fix last shadow judgement in memory_is_poisoned_16() Xishi Qiu <qiuxishi@huawei.com> - 2015-09-09 09:50 +0200
Re: [PATCH V2] kasan: fix last shadow judgement in memory_is_poisoned_16() "long.wanglong" <long.wanglong@huawei.com> - 2015-09-09 10:20 +0200
Re: [PATCH V2] kasan: fix last shadow judgement in memory_is_poisoned_16() Andrey Ryabinin <ryabinin.a.a@gmail.com> - 2015-09-09 10:40 +0200
Re: [PATCH V2] kasan: fix last shadow judgement in memory_is_poisoned_16() Andrey Ryabinin <aryabinin@virtuozzo.com> - 2015-09-09 12:10 +0200
csiph-web