All of lore.kernel.org
 help / color / mirror / Atom feed
* [PATCH] livepatch: x86: make kASLR logic more accurate
@ 2015-04-24 19:53 Jiri Kosina
  2015-04-24 19:59 ` [PATCH v2] " Jiri Kosina
  0 siblings, 1 reply; 8+ messages in thread
From: Jiri Kosina @ 2015-04-24 19:53 UTC (permalink / raw)
  To: Josh Poimboeuf, Seth Jennings, Vojtech Pavlik; +Cc: live-patching, linux-kernel

We give up old_addr hint from the coming patch module in cases when kernel 
load base has been randomized (as in such case, the coming module has no 
idea about the exact randomization offset).

We are currently too pessimistic, and give up immediately as soon as 
CONFIG_RANDOMIZE_BASE is set; this doesn't however directly imply that the 
load base has actually been randomized. There are config options that 
disable kASLR (such as hibernation), user could have disabled kaslr on 
kernel command-line, etc.

The loader propagates the information whether kernel has been randomized 
through bootparams. This allows us to have the condition more accurate.

On top of that, it seems unnecessary to give up old_addr hints even if 
randomization is active. The relocation offset can be computed as 
difference between _text start and __START_KERNEL, and therefore old_addr 
can be adjusted accordingly.

Signed-off-by: Jiri Kosina <jkosina@suse.cz>
---
 arch/x86/include/asm/livepatch.h | 4 ++++
 arch/x86/kernel/livepatch.c      | 5 +++++
 kernel/livepatch/core.c          | 5 +++--
 3 files changed, 12 insertions(+), 2 deletions(-)

diff --git a/arch/x86/include/asm/livepatch.h b/arch/x86/include/asm/livepatch.h
index 2d29197..3c339c0 100644
--- a/arch/x86/include/asm/livepatch.h
+++ b/arch/x86/include/asm/livepatch.h
@@ -23,8 +23,12 @@
 
 #include <linux/module.h>
 #include <linux/ftrace.h>
+#include <asm/setup.h>
 
 #ifdef CONFIG_LIVEPATCH
+
+extern unsigned long kgr_vmlinux_relocation_offset(void);
+
 static inline int klp_check_compiler_support(void)
 {
 #ifndef CC_USING_FENTRY
diff --git a/arch/x86/kernel/livepatch.c b/arch/x86/kernel/livepatch.c
index ff3c3101d..7a171c1 100644
--- a/arch/x86/kernel/livepatch.c
+++ b/arch/x86/kernel/livepatch.c
@@ -88,3 +88,8 @@ int klp_write_module_reloc(struct module *mod, unsigned long type,
 
 	return ret;
 }
+
+unsigned long kgr_vmlinux_relocation_offset(void)
+{
+	return (unsigned long)&_text - __START_KERNEL;
+}
diff --git a/kernel/livepatch/core.c b/kernel/livepatch/core.c
index 284e269..5e85dde 100644
--- a/kernel/livepatch/core.c
+++ b/kernel/livepatch/core.c
@@ -234,8 +234,9 @@ static int klp_find_verify_func_addr(struct klp_object *obj,
 	int ret;
 
 #if defined(CONFIG_RANDOMIZE_BASE)
-	/* KASLR is enabled, disregard old_addr from user */
-	func->old_addr = 0;
+	/* If KASLR has been enabled, adjust old_addr accordingly */
+	if (kaslr_enabled())
+		func->old_addr += kgr_vmlinux_relocation_offset();
 #endif
 
 	if (!func->old_addr || klp_is_module(obj))

-- 
Jiri Kosina
SUSE Labs

^ permalink raw reply related	[flat|nested] 8+ messages in thread

end of thread, other threads:[~2015-04-25 20:44 UTC | newest]

Thread overview: 8+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2015-04-24 19:53 [PATCH] livepatch: x86: make kASLR logic more accurate Jiri Kosina
2015-04-24 19:59 ` [PATCH v2] " Jiri Kosina
2015-04-24 21:40   ` Josh Poimboeuf
2015-04-25 20:39     ` Jiri Kosina
2015-04-24 21:55   ` Josh Poimboeuf
2015-04-25 20:42     ` Jiri Kosina
2015-04-25  3:11   ` Minfei Huang
2015-04-25 20:44     ` Jiri Kosina

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.