Page MenuHomeFreeBSD

kasan: Create a shadow for the bootstack prior to hammer_time()
ClosedPublic

Authored by markj on Jun 10 2022, 6:39 PM.
Tags
None
Referenced Files
Unknown Object (File)
Mon, Dec 16, 8:18 AM
Unknown Object (File)
Dec 7 2024, 4:18 AM
Unknown Object (File)
Dec 5 2024, 12:36 PM
Unknown Object (File)
Nov 20 2024, 9:00 AM
Unknown Object (File)
Nov 9 2024, 12:24 AM
Unknown Object (File)
Nov 5 2024, 9:39 PM
Unknown Object (File)
Oct 25 2024, 10:37 AM
Unknown Object (File)
Oct 20 2024, 5:06 PM
Subscribers

Details

Summary

When the kernel is compiled with -asan-stack=true, the address sanitizer
will emit inline accesses to the shadow map. In other words, some
shadow map accesses are not intercepted by the KASAN runtime, so they
cannot be disabled even if the runtime is not yet initialized by
kasan_init() at the end of hammer_time().

This went unnoticed because the loader will initialize all PML4 entries
of the bootstrap page table to point to the same PDP page, so early
shadow map accesses do not raise a page fault, though they are silently
corrupting memory. In fact, when the loader does not copy the staging
area, we do get a page fault since in that case only the first and last
PML4Es are populated by the loader. But due to another bug, the loader
always treated KASAN kernels as non-relocatable and thus always copied
the staging area.

It is not really practical to annotate hammer_time() and all callees
with __nosanitizeaddress, so instead add some early initialization which
creates a shadow for the boot stack used by hammer_time(). This is only
needed by KASAN, not by KMSAN, but the shared pmap code handles both.

Reported by: mhorne

Diff Detail

Repository
rS FreeBSD src repository - subversion
Lint
Lint Passed
Unit
No Test Coverage
Build Status
Buildable 45935
Build 42823: arc lint + arc unit

Event Timeline

markj requested review of this revision.Jun 10 2022, 6:39 PM
sys/amd64/amd64/locore.S
74

I think, if you move these two lines right before call hammer_time, you can avoid saving/restoring %rdi and %rsi in KASAN block. IMO this makes the asm less convoluted.

sys/amd64/amd64/pmap.c
11440

I think a short comment explaining formulas would be helpful there.

11474

I do not believe that the masking is needed there. PCID is only turned on later. Am I wrong?

11482

May be make a helper function for use both there and at the beginning of hammer_time(), where kernphys is calculated? It would be marked with __nosanitize* of course.

markj marked 4 inline comments as done.
  • Simplify locore asm
  • Remove debug checks from pmap_san_enter_early()
  • Add a comment explaining how many pages are reserved for bootstrapping
  • Don't bother masking CR3
  • Add a subroutine to calculate the load address of the kernel
sys/amd64/amd64/pmap.c
11474

I think you are right, I was just being defensive.

11522

This check is left over from some debugging.

This revision is now accepted and ready to land.Jun 13 2022, 7:26 PM