Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1616130

Re: [PATCH] mm: Add additional consistency check

From Kees Cook <keescook@chromium.org>
Newsgroups linux.kernel
Subject Re: [PATCH] mm: Add additional consistency check
Date 2017-04-04 17:50 +0200
Message-ID <tsySu-6KL-9@gated-at.bofh.it> (permalink)
References <tr7Um-76y-13@gated-at.bofh.it> <tsuYy-4fH-13@gated-at.bofh.it> <tsyfM-6vk-23@gated-at.bofh.it> <tsypr-6A1-1@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


On Tue, Apr 4, 2017 at 8:16 AM, Michal Hocko <mhocko@kernel.org> wrote:
> On Tue 04-04-17 10:07:23, Cristopher Lameter wrote:
>> On Tue, 4 Apr 2017, Michal Hocko wrote:
>>
>> > NAK without a proper changelog. Seriously, we do not blindly apply
>> > changes from other projects without a deep understanding of all
>> > consequences.
>>
>> Functionalitywise this is trivial. A page must be a slab page in order to
>> be able to determine the slab cache of an object. Its definitely not ok if
>> the page is not a slab page.
>
> Yes, but we do not have to blow the kernel, right? Why cannot we simply
> leak that memory?

I can put this behind CHECK_DATA_CORRUPTION() instead of BUG(), which
allows the system builder to choose between WARN and BUG. Some people
absolutely want the kernel to BUG on data corruption as it could be an
attack.

>> The main issue that may exist here is the adding of overhead to a critical
>> code path like kfree().
>
> Yes, nothing is for free. But if the attack space is real then we
> probably want to sacrifice few cycles (to simply return ASAP without
> further further processing). This all should be in the changelog ideally
> with some numbers. I suspect this would be hard to measure in most
> workloads.

Given the trivial nature of the check, yeah, it seemed impossible to
actually show performance changes.

-Kees

-- 
Kees Cook
Pixel Security

Back to linux.kernel | Previous | NextPrevious in thread | Next in thread | Find similar | Unroll thread


Thread

[PATCH] mm: Add additional consistency check Kees Cook <keescook@chromium.org> - 2017-03-31 18:50 +0200
  Re: [PATCH] mm: Add additional consistency check Andrew Morton <akpm@linux-foundation.org> - 2017-03-31 23:40 +0200
    Re: [PATCH] mm: Add additional consistency check Kees Cook <keescook@chromium.org> - 2017-04-01 02:10 +0200
      Re: [PATCH] mm: Add additional consistency check Michael Ellerman <mpe@ellerman.id.au> - 2017-04-03 05:50 +0200
        Re: [PATCH] mm: Add additional consistency check Christoph Lameter <cl@linux.com> - 2017-04-03 16:20 +0200
          Re: [PATCH] mm: Add additional consistency check Matthew Wilcox <willy@infradead.org> - 2017-04-03 17:00 +0200
  Re: [PATCH] mm: Add additional consistency check Michal Hocko <mhocko@kernel.org> - 2017-04-04 13:40 +0200
    Re: [PATCH] mm: Add additional consistency check Christoph Lameter <cl@linux.com> - 2017-04-04 17:10 +0200
      Re: [PATCH] mm: Add additional consistency check Michal Hocko <mhocko@kernel.org> - 2017-04-04 17:20 +0200
        Re: [PATCH] mm: Add additional consistency check Kees Cook <keescook@chromium.org> - 2017-04-04 17:50 +0200
          Re: [PATCH] mm: Add additional consistency check Michal Hocko <mhocko@kernel.org> - 2017-04-04 18:00 +0200
            Re: [PATCH] mm: Add additional consistency check Kees Cook <keescook@chromium.org> - 2017-04-04 18:10 +0200
        Re: [PATCH] mm: Add additional consistency check Christoph Lameter <cl@linux.com> - 2017-04-04 21:20 +0200
          Re: [PATCH] mm: Add additional consistency check Michal Hocko <mhocko@kernel.org> - 2017-04-04 21:50 +0200
            Re: [PATCH] mm: Add additional consistency check Christoph Lameter <cl@linux.com> - 2017-04-04 22:00 +0200
              Re: [PATCH] mm: Add additional consistency check Michal Hocko <mhocko@kernel.org> - 2017-04-04 22:20 +0200

csiph-web