Skip to content

Commit 890ba5b

Browse files
covanampalmer-dabbelt
authored andcommitted
Revert "riscv: Define TASK_SIZE_MAX for __access_ok()"
This reverts commit ad5643c ("riscv: Define TASK_SIZE_MAX for __access_ok()"). This commit changes TASK_SIZE_MAX to be LONG_MAX to optimize access_ok(), because the previous TASK_SIZE_MAX (default to TASK_SIZE) requires some computation. The reasoning was that all user addresses are less than LONG_MAX, and all kernel addresses are greater than LONG_MAX. Therefore access_ok() can filter kernel addresses. Addresses between TASK_SIZE and LONG_MAX are not valid user addresses, but access_ok() let them pass. That was thought to be okay, because they are not valid addresses at hardware level. Unfortunately, one case is missed: get_user_pages_fast() happily accepts addresses between TASK_SIZE and LONG_MAX. futex(), for instance, uses get_user_pages_fast(). This causes the problem reported by Robert [1]. Therefore, revert this commit. TASK_SIZE_MAX is changed to the default: TASK_SIZE. This unfortunately reduces performance, because TASK_SIZE is more expensive to compute compared to LONG_MAX. But correctness first, we can think about optimization later, if required. Reported-by: <[email protected]> Closes: https://lore.kernel.org/linux-riscv/77605.1750245028@localhost/ Signed-off-by: Nam Cao <[email protected]> Cc: [email protected] Reviewed-by: Alexandre Ghiti <[email protected]> Fixes: ad5643c ("riscv: Define TASK_SIZE_MAX for __access_ok()") Link: https://lore.kernel.org/r/[email protected] Signed-off-by: Palmer Dabbelt <[email protected]>
1 parent b0843f8 commit 890ba5b

File tree

1 file changed

+0
-1
lines changed

1 file changed

+0
-1
lines changed

arch/riscv/include/asm/pgtable.h

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1075,7 +1075,6 @@ static inline pte_t pte_swp_clear_exclusive(pte_t pte)
10751075
*/
10761076
#ifdef CONFIG_64BIT
10771077
#define TASK_SIZE_64 (PGDIR_SIZE * PTRS_PER_PGD / 2)
1078-
#define TASK_SIZE_MAX LONG_MAX
10791078

10801079
#ifdef CONFIG_COMPAT
10811080
#define TASK_SIZE_32 (_AC(0x80000000, UL) - PAGE_SIZE)

0 commit comments

Comments
 (0)