3 ms·
I'm intrigued by: > Turning on UAI would allow user space to create pointer values that look like kernel addresses, but which would actually be valid user-spac
by temac 5y ago
I'm intrigued by:
> Turning on UAI would allow user space to create pointer values that look like kernel addresses, but which would actually be valid user-space pointers. Those pointers can, of course, be passed into the kernel via system calls where, in the absence of due care, they might be interpreted as kernel-space addresses. The consequences of such confusion would not be good, and the possibility of it happening is relatively high.
Userspace can already forge "pointers" with whatever it wants in their bits. If the idea is to allow the transfer taggued pointers to userspace to the kernel and from there back to userspace, maybe just don't allow that?
I actually don't see why the kernel should accept tagged pointers to userspace at all. And it seems it should already be checked everywhere otherwise userspace could already make the kernel access unintended kernel memory. I don't see how, if some of them could start to be dereferenceable under some configuration from standard userspace, it would changes anything.
- temac 5y agoOk so I read the mail from Andy and understand the real problem better: UAI is not context switched and is to be enabled system wide. I don't know what AMD has been smoking.
- saagarjha 5y agoPretty sure this is how it works in ARM as well, except that TBI can be configured per-exception level so it can be turned off in the kernel.
- pm215 5y agoYes. The thing which is controlled per-process (per-thread, really) is the extent to which you can pass a tagged address to a kernel syscall and have it strip the tag and operate on the 'real' address versus handing you a 'bad address' error. The default is 'syscalls (mostly) don't detag addresses'. https://www.kernel.org/doc/html/latest/arm64/tagged-address-abi.html https://www.kernel.org/doc/html/latest/arm64/tagged-address-... has the details. Because TBI is separate for userspace and the kernel you could make it per-process -- just context switch the TBI control bit. But there's no need.