From nobody Mon Sep 28 10:43:11 2026 Received: from mail-pl1-f198.google.com (mail-pl1-f198.google.com [209.85.214.198]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 1A4773B7753 for ; Wed, 26 Aug 2026 22:01:51 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.214.198 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787781713; cv=none; b=mv/6Jir7y002TzyjITWOe1NGyIZFxVOYZxouLDpkznsPNTIqztwHwhz5ZFNybxX7sRTWjlOy/NKu5lqCfj1qmhxN7bWiEJLl+jq9qclS769zRRXFxIOKF3RQ4/3ROAXIHsAjHUqs3PGdEFPTx9iF3PSfQbgnAzidCkAs+nd5In4= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787781713; c=relaxed/simple; bh=ny27h0zO3Ndfn/qM++rOff6nZaKGRZlfO0GvhJeJgmo=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: Cc:Content-Type; b=aLf0FOh5auR1eZPbkHTgRWMWI8AMr5vPMwCyGb80kKgglm5lHc99Q2MO58BXC/Yl3u4oih2/gwGVXYUgRJkS1BG6FIFi2jCsbQDEiS70J0gfTPOua5QQkfQ4sleYhgmSFhcJPg5AIZ5nOhIXI3JE/Rz9rFAJQKqPf3Rtx4Ore78= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--morbo.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=tUIiAiIG; arc=none smtp.client-ip=209.85.214.198 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--morbo.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="tUIiAiIG" Received: by mail-pl1-f198.google.com with SMTP id d9443c01a7336-2d6fed0652bso20592205ad.2 for ; Wed, 26 Aug 2026 15:01:51 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1787781711; x=1788386511; darn=vger.kernel.org; h=content-transfer-encoding:content-type:cc:from:subject:message-id :references:mime-version:in-reply-to:date:from:to:cc:subject:date :message-id:reply-to:content-type; bh=H6eKz7tR30Dozwm5hWg5ie0MrnymWRTzkxQg3Uw+4uY=; b=tUIiAiIG9wakY81AEYKMj8BgwBNa5TU+hmiBzBcHp8Ea2azWzTjNkKCI8l5lUCOVRA 7fDyVSi7sTqEcXIlExNgdvI+R095j8HY+1Q2Ddz6ypvl2wNru7NexQOFRid/ZY6DatDM YaAGRAnMBM3w/j1L35eLaNog517ILlR3FisFmZI5lKKskqga/RskEe3YkmKhi8CUcwQc Y4TjDBtwSKAfHZ0qm+ViT3IO2/eqejtBJmVk07jped4xdvtryL7f0rvtbXgFGfVk58JW lKI64YcIe6C5TzuH1GNOjxyHQISIJAjcnfjYs8PbNg6IiirVxeJlZ28DS7AXrYZPOf6z Yg6g== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787781711; x=1788386511; h=content-transfer-encoding:content-type:cc:from:subject:message-id :references:mime-version:in-reply-to:date:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=H6eKz7tR30Dozwm5hWg5ie0MrnymWRTzkxQg3Uw+4uY=; b=MFAwvTc4NHhfiEp9USEUnsFWwYEEx4GBFcNCnKrRkFr2wj14q4tr6lcI+WS53LPtOE 5eYkCSw4tMGA0IEpULeqgf/eM3tPv6LXyCqmyfGNMqbR92pYXv2dyNU/Prhmlq6F5v3c 4ixD+73Ouar+5lEPlleU2g0o7SRra+3mx7q7MSQ/EbJZzjtWQZ7eTWoO3l/OJr/KC+nx Sya7bYPsvQkw1SuDMhCppRn6Kks417HGvKXlSCHLN3S6t9pcm0B5Ki4TqHlbC6927Kc6 uqiZm/Wz7IU6OFo09JOeeG1LI40oPEO+dy3IkhgjQE7vZzXocFBjISe1DqqiPcdpKcM+ 01Rw== X-Forwarded-Encrypted: i=1; AHgh+RrYbtXNQp/Bedh3kbPqCq6LsINYghjUwQWBuQPlA3H/+acbcgrQfaKLGEdF4yQO2hY+vTBPwec8QVdZ7ys=@vger.kernel.org X-Gm-Message-State: AFuF++lYfHCaXyVH2ExyeaUBeYwzh/33HzNk3Z9FZGIu9GPL5E2AH3X5 AME4z0ieglEohe7cVI21cLEtBBz03jOG7Lve0ngffMwbqOG3x4Q4H0UbaDeOhJrKI9wCrBJ9jmF t X-Received: from plbjg12.prod.google.com ([2002:a17:903:26cc:b0:2cc:e407:8fee]) (user=morbo job=prod-delivery.src-stubby-dispatcher) by 2002:a17:902:e74a:b0:2d2:da8e:9017 with SMTP id d9443c01a7336-2d707ae31e5mr144405135ad.8.1787781711014; Wed, 26 Aug 2026 15:01:51 -0700 (PDT) Date: Wed, 26 Aug 2026 22:00:34 +0000 In-Reply-To: <20260823125155.1136740-1-morbo@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260823125155.1136740-1-morbo@google.com> X-Mailer: git-send-email 2.55.0.897.gb25b4bd76c-goog Message-ID: <20260826220041.4075333-1-morbo@google.com> Subject: [PATCH v4 1/2] userns: Add __counted_by_ptr attribute to struct uid_gid_map From: Bill Wendling Cc: Bill Wendling , "Gustavo A. R. Silva" , Bradley Morgan , "=?UTF-8?q?Thomas=20Wei=C3=9Fschuh?=" , Kees Cook , Christian Brauner , Aleksa Sarai , Jan Kara , Nathan Chancellor , Miguel Ojeda , Thomas Gleixner , Nicolas Schier , Gary Guo , Alice Ryhl , Douglas Anderson , Anand Moon , Oleg Nesterov , codemender-patching+linux@google.com, linux-kernel@vger.kernel.org, linux-hardening@vger.kernel.org Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" The compiler attribute __counted_by_ptr associates a pointer field of a struct with a sibling field within the same struct that specifies the element count of the allocated memory. This enables KASAN and fortified bounds-checking to detect out-of-bounds accesses to the pointer field at runtime. We can add the __counted_by_ptr attribute to the 'forward' and 'reverse' pointer fields of 'struct uid_gid_map', which are counted by 'nr_extents'. Since 'nr_extents' is defined in a sibling anonymous struct inside an anonymous union, the nearest common non-anonymous struct level is 'struct uid_gid_map' itself, which is supported by the compiler. However, doing so has runtime implications. In the original implementation of insert_extent(), elements are written to map->forward[map->nr_extents] before map->nr_extents is incremented: if (map->nr_extents < UID_GID_MAP_MAX_BASE_EXTENTS) dest =3D &map->extent[map->nr_extents]; else dest =3D &map->forward[map->nr_extents]; *dest =3D *extent; map->nr_extents++; At the time of writing to 'map->forward[map->nr_extents]', map->nr_extents is still 5, but we are accessing index 5 (which is the 6th element). Under __counted_by_ptr(nr_extents), the compiler and KASAN expect the accessed index to be strictly less than map->nr_extents. Therefore, accessing index 5 when the count is 5 triggers an out-of-bounds panic/trap at runtime. To resolve this, insert_extent() is refactored to increment map->nr_extents first, and then use map->nr_extents - 1 as the index: map->nr_extents++; if (map->nr_extents <=3D UID_GID_MAP_MAX_BASE_EXTENTS) dest =3D &map->extent[map->nr_extents - 1]; else dest =3D &map->forward[map->nr_extents - 1]; *dest =3D *extent; Assisted-by: Gemini:3.1-pro-preview Signed-off-by: Bill Wendling Reviewed-by: Gustavo A. R. Silva Reviewed-by: Bradley Morgan --- v2 - Remove Gerrit tag. v4 - Added comment explaning the change. Corrected the "Assisted-by" tag. --- Cc: Bradley Morgan Cc: Thomas Wei=C3=9Fschuh Cc: Kees Cook Cc: "Gustavo A. R. Silva" Cc: Christian Brauner Cc: Aleksa Sarai Cc: Jan Kara Cc: Nathan Chancellor Cc: Miguel Ojeda Cc: Thomas Gleixner Cc: Nicolas Schier Cc: Gary Guo Cc: "Thomas Wei=C3=9Fschuh" Cc: Alice Ryhl Cc: Douglas Anderson Cc: Anand Moon Cc: Oleg Nesterov Cc: codemender-patching+linux@google.com Cc: linux-kernel@vger.kernel.org Cc: linux-hardening@vger.kernel.org --- include/linux/user_namespace.h | 4 ++-- kernel/user_namespace.c | 12 ++++++++---- 2 files changed, 10 insertions(+), 6 deletions(-) diff --git a/include/linux/user_namespace.h b/include/linux/user_namespace.h index e38d9e60569f..2962256eddf7 100644 --- a/include/linux/user_namespace.h +++ b/include/linux/user_namespace.h @@ -29,8 +29,8 @@ struct uid_gid_map { /* 64 bytes -- 1 cache line */ u32 nr_extents; }; struct { - struct uid_gid_extent *forward; - struct uid_gid_extent *reverse; + struct uid_gid_extent *forward __counted_by_ptr(nr_extents); + struct uid_gid_extent *reverse __counted_by_ptr(nr_extents); }; }; }; diff --git a/kernel/user_namespace.c b/kernel/user_namespace.c index 0bed462e9b2a..786dbf0506ca 100644 --- a/kernel/user_namespace.c +++ b/kernel/user_namespace.c @@ -809,13 +809,17 @@ static int insert_extent(struct uid_gid_map *map, str= uct uid_gid_extent *extent) map->reverse =3D NULL; } =20 - if (map->nr_extents < UID_GID_MAP_MAX_BASE_EXTENTS) - dest =3D &map->extent[map->nr_extents]; + /* + * nr_extents must be updated before the extent and forward arrays are + * accessed, otherwise KSAN will assert an out-of-bounds error. + */ + map->nr_extents++; + if (map->nr_extents <=3D UID_GID_MAP_MAX_BASE_EXTENTS) + dest =3D &map->extent[map->nr_extents - 1]; else - dest =3D &map->forward[map->nr_extents]; + dest =3D &map->forward[map->nr_extents - 1]; =20 *dest =3D *extent; - map->nr_extents++; return 0; } =20 --=20 2.55.0.897.gb25b4bd76c-goog From nobody Mon Sep 28 10:43:11 2026 Received: from mail-pl1-f200.google.com (mail-pl1-f200.google.com [209.85.214.200]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 7485F31618B for ; Sun, 23 Aug 2026 12:51:59 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.214.200 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787489520; cv=none; b=K3PR9ZNiGdhYGByK7KFTxtvRKEwkrDioFREGlskD41zGDbIoaYiZPL4seKwLs1/x7jdXoX4P9pGJvcM8xaZ5EbDsC7xIKdYliFtUiEAFGNg0CjJcwunNX72QASnzqbGd8UsKdtbCSI/r7p06xGr2zKPMfjRA3wq8HjvfoytIyfc= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787489520; c=relaxed/simple; bh=y+LROC8XAKNEDoBV1EUp6SDpaGTfmrTNBsAQC7v6vwQ=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=tXL7c9Jksvy3Z5WKf2WmGA93UWpu/JQhT1+nrITQDTfjOZlBMLKu7gCF3pFP1h8ZIGbK5EmtKXpawU++PKvZdE4jLsDp3JB32nR2KS+dIaFTSY/pwnQJxOZjoBDJe8Am2C1GfIXc3baYxcxiP03x3r8LO5onLvqfXMzBw1X4ytw= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--morbo.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=JHCvBCaJ; arc=none smtp.client-ip=209.85.214.200 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--morbo.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="JHCvBCaJ" Received: by mail-pl1-f200.google.com with SMTP id d9443c01a7336-2cfc52ddc55so39107575ad.3 for ; Sun, 23 Aug 2026 05:51:59 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1787489519; x=1788094319; darn=vger.kernel.org; h=content-transfer-encoding:content-type:cc:to:from:subject :message-id:references:mime-version:in-reply-to:date:from:to:cc :subject:date:message-id:reply-to:content-type; bh=8/j626qUUUtpjEjXH+/BZQ1LG4AVUMqvjzdNkuJ+fuo=; b=JHCvBCaJDD0fKSRAg9LWzdLJamFDsS9wGc+SRBSi77yHZKfIpU/YlRRzvsBkHs+oXe 6+Btshki+edlO2G7lZWRvP1c+wzodqq6iG14KyNpCYJsCUO4fEhCN6f9wbGcyIb+233E 0yqzqtvohArUwjHIp7BSITKAryjqKDJvug4sLXznf1AUQhlBlLYeVK3Iq9t+Nf3w+518 NGY4f93ed/JGtrtNEIes2ZXXAohW7Ce20klmGpfZ4ReXv1Y1NSnN6znM0NUP/KX3IWhy sh+NxgjCrsYzln7t2DVDFcSsbwAqmn9g//GpEI3m7L8NnY2ATW778YQyiPxHq8mDGEv2 jUJw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787489519; x=1788094319; h=content-transfer-encoding:content-type:cc:to:from:subject :message-id:references:mime-version:in-reply-to:date :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=8/j626qUUUtpjEjXH+/BZQ1LG4AVUMqvjzdNkuJ+fuo=; b=DC0x54oOSmTvBF2MNDIkLZYziTN1+CE6VS2mw9U+HrVAtTBaI/1QSa2yJxJCLOFh+e htnMtwv1zL74PrhLDWvPEq7LJuEquzuC+glfBGTCQX3pD/z6a8dZM/CIgDoh3/T40wVu uaPiHVSXjuuf+jhDIuoQoOWd5w/w9pwJYmLDAoABTDe7rUt23lJv4Y+0gVuylaaDScnb QxEJfmE6Mo3rmjjuh4LbeLqE2NdyAW9seT0RTg20PJ70cm20t/0eOxH3bTOET+CNOOAl CFWsQEckdsL5B9CCBwiS6pEatHJrCafRl6GZ6Gf2oh+4ND8HHiErbMAhA2VnmeXnc/5S PR5Q== X-Gm-Message-State: AFuF++l2sj73MQIZaHCREj/+9GhIwaZMKshRfQ7Z7weNcf8S9z0BN/h9 87GL2UiBgV00422pHhb/zkHfi8ZzDrhk/CuW28wQM1L78aUJtG71uCXRvcmcfSsuziviDrdeilr ytF3DDCS5VDJMphTCLwT6duHEbY0wWIlMGo/sI4Uvgt3vR87ZGH61Ti2VMHF/OmnYj56Px/oJ2W k+hIP3Lee/sknKbo74+lNRopPVuxvp5QhfqtivdA== X-Received: from plhw14.prod.google.com ([2002:a17:903:2f4e:b0:2c9:b703:3bfb]) (user=morbo job=prod-delivery.src-stubby-dispatcher) by 2002:a17:903:b07:b0:2d0:cc92:f7a9 with SMTP id d9443c01a7336-2d64add1daamr358614285ad.4.1787489518421; Sun, 23 Aug 2026 05:51:58 -0700 (PDT) Date: Sun, 23 Aug 2026 12:51:47 +0000 In-Reply-To: <20260823125155.1136740-1-morbo@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260823125155.1136740-1-morbo@google.com> X-Mailer: git-send-email 2.55.0.860.g4b6b3295ed-goog Message-ID: <20260823125155.1136740-2-morbo@google.com> Subject: [PATCH 1/2] userns: Add __counted_by_ptr attribute to struct uid_gid_map From: Bill Wendling To: linux-kernel@vger.kernel.org Cc: Bill Wendling , Kees Cook , "Gustavo A. R. Silva" , Christian Brauner , Aleksa Sarai , Jan Kara , Nathan Chancellor , Miguel Ojeda , Thomas Gleixner , Nicolas Schier , Gary Guo , "=?UTF-8?q?Thomas=20Wei=C3=9Fschuh?=" , Alice Ryhl , Douglas Anderson , Anand Moon , Oleg Nesterov , codemender-patching+linux@google.com, linux-hardening@vger.kernel.org Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" The compiler attribute __counted_by_ptr associates a pointer field of a struct with a sibling field within the same struct that specifies the element count of the allocated memory. This enables KASAN and fortified bounds-checking to detect out-of-bounds accesses to the pointer field at runtime. We can add the __counted_by_ptr attribute to the 'forward' and 'reverse' pointer fields of 'struct uid_gid_map', which are counted by 'nr_extents'. Since 'nr_extents' is defined in a sibling anonymous struct inside an anonymous union, the nearest common non-anonymous struct level is 'struct uid_gid_map' itself, which is supported by the compiler. However, doing so has runtime implications. In the original implementation of insert_extent(), elements are written to map->forward[map->nr_extents] before map->nr_extents is incremented: if (map->nr_extents < UID_GID_MAP_MAX_BASE_EXTENTS) dest =3D &map->extent[map->nr_extents]; else dest =3D &map->forward[map->nr_extents]; *dest =3D *extent; map->nr_extents++; At the time of writing to 'map->forward[map->nr_extents]', map->nr_extents is still 5, but we are accessing index 5 (which is the 6th element). Under __counted_by_ptr(nr_extents), the compiler and KASAN expect the accessed index to be strictly less than map->nr_extents. Therefore, accessing index 5 when the count is 5 triggers an out-of-bounds panic/trap at runtime. To resolve this, insert_extent() is refactored to increment map->nr_extents first, and then use map->nr_extents - 1 as the index: map->nr_extents++; if (map->nr_extents <=3D UID_GID_MAP_MAX_BASE_EXTENTS) dest =3D &map->extent[map->nr_extents - 1]; else dest =3D &map->forward[map->nr_extents - 1]; *dest =3D *extent; Assisted-by: Gemini Next Signed-off-by: Bill Wendling Reviewed-by: Bradley Morgan Reviewed-by: Gustavo A. R. Silva --- Cc: Kees Cook Cc: "Gustavo A. R. Silva" Cc: Christian Brauner Cc: Aleksa Sarai Cc: Jan Kara Cc: Nathan Chancellor Cc: Miguel Ojeda Cc: Thomas Gleixner Cc: Nicolas Schier Cc: Gary Guo Cc: "Thomas Wei=C3=9Fschuh" Cc: Alice Ryhl Cc: Douglas Anderson Cc: Anand Moon Cc: Oleg Nesterov Cc: codemender-patching+linux@google.com Cc: linux-kernel@vger.kernel.org Cc: linux-hardening@vger.kernel.org --- include/linux/user_namespace.h | 4 ++-- kernel/user_namespace.c | 8 ++++---- 2 files changed, 6 insertions(+), 6 deletions(-) diff --git a/include/linux/user_namespace.h b/include/linux/user_namespace.h index e38d9e60569f..2962256eddf7 100644 --- a/include/linux/user_namespace.h +++ b/include/linux/user_namespace.h @@ -29,8 +29,8 @@ struct uid_gid_map { /* 64 bytes -- 1 cache line */ u32 nr_extents; }; struct { - struct uid_gid_extent *forward; - struct uid_gid_extent *reverse; + struct uid_gid_extent *forward __counted_by_ptr(nr_extents); + struct uid_gid_extent *reverse __counted_by_ptr(nr_extents); }; }; }; diff --git a/kernel/user_namespace.c b/kernel/user_namespace.c index 0bed462e9b2a..7e5371d8f515 100644 --- a/kernel/user_namespace.c +++ b/kernel/user_namespace.c @@ -809,13 +809,13 @@ static int insert_extent(struct uid_gid_map *map, str= uct uid_gid_extent *extent) map->reverse =3D NULL; } =20 - if (map->nr_extents < UID_GID_MAP_MAX_BASE_EXTENTS) - dest =3D &map->extent[map->nr_extents]; + map->nr_extents++; + if (map->nr_extents <=3D UID_GID_MAP_MAX_BASE_EXTENTS) + dest =3D &map->extent[map->nr_extents - 1]; else - dest =3D &map->forward[map->nr_extents]; + dest =3D &map->forward[map->nr_extents - 1]; =20 *dest =3D *extent; - map->nr_extents++; return 0; } =20 --=20 2.55.0.860.g4b6b3295ed-goog From nobody Mon Sep 28 10:43:11 2026 Received: from mail-pl1-f198.google.com (mail-pl1-f198.google.com [209.85.214.198]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 3F3A23C4544 for ; Sun, 23 Aug 2026 12:52:00 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.214.198 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787489521; cv=none; b=aqjV8ng8lc6hZrKC491+uBksTYBIBqOD8EhyyHkljoPbqcsdMidxEMVMEMK+QIvSfN387RColMnN32ujuHCa40Laam0n1/kF0woB1i33Wz5v2Cb95aabhTPXgsTxJEP8gAoUr0YrVNaBEbP/tFByCbdYnOenfjfktoGF7fdVhSs= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787489521; c=relaxed/simple; bh=hT53fJ/77VLdIobcjfLUB2EbnU5TUGJsfyHBZ7/PypE=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=KwXhBpseDGTHfLz39GwtvJdPR03gXtXDnhKHj3GZujaH/CyZXYgIcrymKGIFbS9/Ky5F2oEtMV2sHpqfwCZYxCHIafiU6HilmMx837GhGnEdjzFWvz/m0BDzEQfA+QuMy0oC/oLQ5MuD95bxBCYhVodInCgs6lBa4YtQbL9E5R8= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--morbo.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=j5Prqecx; arc=none smtp.client-ip=209.85.214.198 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--morbo.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="j5Prqecx" Received: by mail-pl1-f198.google.com with SMTP id d9443c01a7336-2d63bad3d09so31039845ad.3 for ; Sun, 23 Aug 2026 05:52:00 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1787489519; x=1788094319; darn=vger.kernel.org; h=content-transfer-encoding:content-type:cc:to:from:subject :message-id:references:mime-version:in-reply-to:date:from:to:cc :subject:date:message-id:reply-to:content-type; bh=/6GuAAUwAMI1WHNA8K+fgQT1FDdUgoWfjJ9wdukQyWY=; b=j5PrqecxXxFt2SRcA1YcMS9AH66O/FD5diukC6yVFNcikl01xCmmEmUGc3OuJUaZE1 shDQOPNMZA0HnAgV6BC15mAZZtB1A/T0D1D2xapdRmz+Mbl/y8U+ZB58gtXXY+lDETk9 Jblyy+KuCSMoeAQWqVdLqkF8gxDeIAKRPCH94gsP5IWS/TwCeEBMq3M2cynkTbQLr/40 IEhb6YtBY9G7AiCcXTjaZO+JaqgM/u54GkcRbM1sdn2zAEhCORu+6tatlOMwZpoZU4HB oJKBtAju1K/Pj4LPuCxDJ23teErBzW123X/831wR5saR6J4y1oVEllVwKDavU4DaSPPy QZ6Q== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787489519; x=1788094319; h=content-transfer-encoding:content-type:cc:to:from:subject :message-id:references:mime-version:in-reply-to:date :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=/6GuAAUwAMI1WHNA8K+fgQT1FDdUgoWfjJ9wdukQyWY=; b=mSWjxk9IVepjQ/rdWaUmjF+OHP/8TOdZ2PWv7L2U1hDTwiH5a5ROxT3Oi8/3GGbyrN RDcqHn1lXRm/qJaajaULwIN1fS9B4e6JXTrlqDkxnkJvOh4bgOACchadz8xQ7UAQz2u6 vKzfirl8xsvJvlQjBwGzAs3I/h7F4CNdort3XNP8bAECvzCtQ4+pChljoa/gCpSiY0N9 BJ1Ib7Fsss9FlUVgAVam9xgj25nRxZHumOcmDZhxulnYME3ztly2Uh56vBUnTjAi4etn nF6bjhG5TAF3ZJFgzsr409dLUIq4QKSU9al12LVzBXUYkePD1N5PvwzawZL41kJalGDb H9aA== X-Gm-Message-State: AFuF++knUASTmpqV2rPCGmMKteyUj89M7i0Y412toz4I6BdUoqcKUrBz Fuw4G42QFTELRoy5eXFVX7GPGp9W8I3GxkGBGQbv2veQ2tclhJYzgSfG/jHqOQLrNS8kgHPEETL Qn+Nv2R5xVgaqlMbtlv4EsZrk/OdBG4h73yQCjpudd5y1/NW11XneXAJ0x074lsnC9gqodSg3gz /oEkaG8VHXorU26fX3s+gvk7Pt9/QlDfLxQly8SA== X-Received: from pltk5.prod.google.com ([2002:a17:902:6945:b0:2d5:9dd2:5fc6]) (user=morbo job=prod-delivery.src-stubby-dispatcher) by 2002:a17:903:fa6:b0:2d6:5beb:8692 with SMTP id d9443c01a7336-2d670bb5042mr219445355ad.6.1787489519251; Sun, 23 Aug 2026 05:51:59 -0700 (PDT) Date: Sun, 23 Aug 2026 12:51:48 +0000 In-Reply-To: <20260823125155.1136740-1-morbo@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260823125155.1136740-1-morbo@google.com> X-Mailer: git-send-email 2.55.0.860.g4b6b3295ed-goog Message-ID: <20260823125155.1136740-3-morbo@google.com> Subject: [PATCH 2/2] userns: Add KUnit test suite for uid_gid_map From: Bill Wendling To: linux-kernel@vger.kernel.org Cc: Bill Wendling , Kees Cook , "Gustavo A. R. Silva" , Christian Brauner , Aleksa Sarai , Jan Kara , Nathan Chancellor , Miguel Ojeda , Thomas Gleixner , Nicolas Schier , Gary Guo , "=?UTF-8?q?Thomas=20Wei=C3=9Fschuh?=" , Alice Ryhl , Douglas Anderson , Anand Moon , Oleg Nesterov , codemender-patching+linux@google.com, linux-hardening@vger.kernel.org Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Add a KUnit test suite to verify the insertion and sorting of mappings in struct uid_gid_map. This test suite validates both base extent insertion (<=3D 5 mappings) and extended extent insertion (> 5 mappings, which triggers the allocation of the forward and reverse pointers). This is especially useful for verifying that the __counted_by_ptr attribute added to 'forward' and 'reverse' pointers works correctly without causing any runtime bounds-checking panics or traps. Assisted-by: Gemini Next Change-Id: If0c2c197a35cd7429cf0d2d6e3b33f0d9f0be66c Signed-off-by: Bill Wendling --- Cc: Kees Cook Cc: "Gustavo A. R. Silva" Cc: Christian Brauner Cc: Aleksa Sarai Cc: Jan Kara Cc: Nathan Chancellor Cc: Miguel Ojeda Cc: Thomas Gleixner Cc: Nicolas Schier Cc: Gary Guo Cc: "Thomas Wei=C3=9Fschuh" Cc: Alice Ryhl Cc: Douglas Anderson Cc: Anand Moon Cc: Oleg Nesterov Cc: codemender-patching+linux@google.com Cc: linux-kernel@vger.kernel.org Cc: linux-hardening@vger.kernel.org --- init/Kconfig | 10 ++++ kernel/.kunitconfig | 3 ++ kernel/user_namespace.c | 4 ++ kernel/user_namespace_kunit.c | 87 +++++++++++++++++++++++++++++++++++ 4 files changed, 104 insertions(+) create mode 100644 kernel/.kunitconfig create mode 100644 kernel/user_namespace_kunit.c diff --git a/init/Kconfig b/init/Kconfig index f63bf5e05e79..ba6a40b7315a 100644 --- a/init/Kconfig +++ b/init/Kconfig @@ -1457,6 +1457,16 @@ config USER_NS =20 If unsure, say N. =20 +config USER_NAMESPACE_KUNIT_TEST + tristate "KUnit test for user namespace map insertion" if !KUNIT_ALL_TESTS + depends on USER_NS && KUNIT + default KUNIT_ALL_TESTS + help + This builds the KUnit test for user namespace uid/gid map insertion. + It validates map insertion, limits, dynamic allocation of the + extended extents array, and mapping sorting functions. + If unsure, say N. + config PID_NS bool "PID Namespaces" default y diff --git a/kernel/.kunitconfig b/kernel/.kunitconfig new file mode 100644 index 000000000000..7314dce05dc2 --- /dev/null +++ b/kernel/.kunitconfig @@ -0,0 +1,3 @@ +CONFIG_KUNIT=3Dy +CONFIG_USER_NS=3Dy +CONFIG_USER_NAMESPACE_KUNIT_TEST=3Dy diff --git a/kernel/user_namespace.c b/kernel/user_namespace.c index 7e5371d8f515..64c64e1028e8 100644 --- a/kernel/user_namespace.c +++ b/kernel/user_namespace.c @@ -1413,3 +1413,7 @@ static __init int user_namespaces_init(void) return 0; } subsys_initcall(user_namespaces_init); + +#if IS_ENABLED(CONFIG_USER_NAMESPACE_KUNIT_TEST) +#include "user_namespace_kunit.c" +#endif diff --git a/kernel/user_namespace_kunit.c b/kernel/user_namespace_kunit.c new file mode 100644 index 000000000000..6d7662ef1916 --- /dev/null +++ b/kernel/user_namespace_kunit.c @@ -0,0 +1,87 @@ +// SPDX-License-Identifier: GPL-2.0 +/* + * KUnit test for user namespace map insertion and sorting. + */ + +#include +#include + +static void test_user_ns_map_insert_base(struct kunit *test) +{ + struct uid_gid_map map; + struct uid_gid_extent extent; + int i, ret; + + memset(&map, 0, sizeof(map)); + + /* Insert up to UID_GID_MAP_MAX_BASE_EXTENTS (5) elements */ + for (i =3D 0; i < UID_GID_MAP_MAX_BASE_EXTENTS; i++) { + extent.first =3D i * 10; + extent.lower_first =3D i * 100; + extent.count =3D 5; + + ret =3D insert_extent(&map, &extent); + KUNIT_EXPECT_EQ(test, ret, 0); + KUNIT_EXPECT_EQ(test, map.nr_extents, i + 1); + KUNIT_EXPECT_EQ(test, map.extent[i].first, i * 10); + KUNIT_EXPECT_EQ(test, map.extent[i].lower_first, i * 100); + KUNIT_EXPECT_EQ(test, map.extent[i].count, 5); + } +} + +static void test_user_ns_map_insert_extended(struct kunit *test) +{ + struct uid_gid_map map; + struct uid_gid_extent extent; + int i, ret; + + memset(&map, 0, sizeof(map)); + + /* Insert more than UID_GID_MAP_MAX_BASE_EXTENTS (e.g., 10) elements */ + for (i =3D 0; i < 10; i++) { + extent.first =3D i * 10; + extent.lower_first =3D i * 100; + extent.count =3D 5; + + ret =3D insert_extent(&map, &extent); + KUNIT_EXPECT_EQ(test, ret, 0); + KUNIT_EXPECT_EQ(test, map.nr_extents, i + 1); + + if (i < UID_GID_MAP_MAX_BASE_EXTENTS) { + KUNIT_EXPECT_EQ(test, map.extent[i].first, i * 10); + } else { + KUNIT_EXPECT_NOT_ERR_OR_NULL(test, map.forward); + KUNIT_EXPECT_EQ(test, map.forward[i].first, i * 10); + KUNIT_EXPECT_EQ(test, map.forward[i].lower_first, i * 100); + KUNIT_EXPECT_EQ(test, map.forward[i].count, 5); + } + } + + /* Now sort the map to set up reverse mapping */ + ret =3D sort_idmaps(&map); + KUNIT_EXPECT_EQ(test, ret, 0); + KUNIT_EXPECT_NOT_ERR_OR_NULL(test, map.reverse); + + /* Verify sorting is correct */ + for (i =3D 0; i < map.nr_extents; i++) { + KUNIT_EXPECT_EQ(test, map.forward[i].count, 5); + KUNIT_EXPECT_EQ(test, map.reverse[i].count, 5); + } + + /* Clean up allocations to avoid leaks */ + kfree(map.forward); + kfree(map.reverse); +} + +static struct kunit_case user_ns_map_test_cases[] =3D { + KUNIT_CASE(test_user_ns_map_insert_base), + KUNIT_CASE(test_user_ns_map_insert_extended), + {} +}; + +static struct kunit_suite user_ns_map_test_suite =3D { + .name =3D "user_ns_map", + .test_cases =3D user_ns_map_test_cases, +}; + +kunit_test_suite(user_ns_map_test_suite); --=20 2.55.0.860.g4b6b3295ed-goog