From: Mark Rutland <mark.rutland@arm.com>
To: Ard Biesheuvel <ard.biesheuvel@linaro.org>
Cc: linux-arm-kernel@lists.infradead.org, keescook@chromium.org,
labbott@fedoraproject.org, kernel-hardening@lists.openwall.com,
will.deacon@arm.com, catalin.marinas@arm.com,
kvmarm@lists.cs.columbia.edu, marc.zyngier@arm.com
Subject: [kernel-hardening] Re: [PATCH v5 07/10] arm64/mmu: ignore debug_pagealloc for kernel segments
Date: Thu, 9 Mar 2017 17:51:17 +0000 [thread overview]
Message-ID: <20170309175116.GD11966@leverpostej> (raw)
In-Reply-To: <1489047912-642-8-git-send-email-ard.biesheuvel@linaro.org>
On Thu, Mar 09, 2017 at 09:25:09AM +0100, Ard Biesheuvel wrote:
> The debug_pagealloc facility manipulates kernel mappings in the linear
> region at page granularity to detect out of bounds or use-after-free
> accesses. Since the kernel segments are not allocated dynamically,
> there is no point in taking the debug_pagealloc_enabled flag into
> account for them, and we can use block mappings unconditionally.
>
> Note that this applies equally to the linear alias of text/rodata:
> we will never have dynamic allocations there given that the same
> memory is statically in use by the kernel image.
>
> Signed-off-by: Ard Biesheuvel <ard.biesheuvel@linaro.org>
This makes sense to me, and I haven't found anything this breaks.
It may be worth noting that a similar reasoning already applies the the
FDT mapping, where we use create_mapping_noalloc(), and never mandate
page mappings.
Regardless:
Reviewed-by: Mark Rutland <mark.rutland@arm.com>
Mark.
> ---
> arch/arm64/mm/mmu.c | 7 +++----
> 1 file changed, 3 insertions(+), 4 deletions(-)
>
> diff --git a/arch/arm64/mm/mmu.c b/arch/arm64/mm/mmu.c
> index c3963c592ec3..d3fecd20a136 100644
> --- a/arch/arm64/mm/mmu.c
> +++ b/arch/arm64/mm/mmu.c
> @@ -328,8 +328,7 @@ static void update_mapping_prot(phys_addr_t phys, unsigned long virt,
> return;
> }
>
> - __create_pgd_mapping(init_mm.pgd, phys, virt, size, prot,
> - NULL, debug_pagealloc_enabled());
> + __create_pgd_mapping(init_mm.pgd, phys, virt, size, prot, NULL, false);
>
> /* flush the TLBs after updating live kernel mappings */
> flush_tlb_kernel_range(virt, virt + size);
> @@ -381,7 +380,7 @@ static void __init __map_memblock(pgd_t *pgd, phys_addr_t start, phys_addr_t end
> */
> __create_pgd_mapping(pgd, kernel_start, __phys_to_virt(kernel_start),
> kernel_end - kernel_start, PAGE_KERNEL,
> - early_pgtable_alloc, debug_pagealloc_enabled());
> + early_pgtable_alloc, false);
> }
>
> void __init mark_linear_text_alias_ro(void)
> @@ -437,7 +436,7 @@ static void __init map_kernel_segment(pgd_t *pgd, void *va_start, void *va_end,
> BUG_ON(!PAGE_ALIGNED(size));
>
> __create_pgd_mapping(pgd, pa_start, (unsigned long)va_start, size, prot,
> - early_pgtable_alloc, debug_pagealloc_enabled());
> + early_pgtable_alloc, false);
>
> vma->addr = va_start;
> vma->phys_addr = pa_start;
> --
> 2.7.4
>
WARNING: multiple messages have this Message-ID (diff)
From: Mark Rutland <mark.rutland@arm.com>
To: Ard Biesheuvel <ard.biesheuvel@linaro.org>
Cc: keescook@chromium.org, kernel-hardening@lists.openwall.com,
marc.zyngier@arm.com, catalin.marinas@arm.com,
will.deacon@arm.com, kvmarm@lists.cs.columbia.edu,
linux-arm-kernel@lists.infradead.org, labbott@fedoraproject.org
Subject: Re: [PATCH v5 07/10] arm64/mmu: ignore debug_pagealloc for kernel segments
Date: Thu, 9 Mar 2017 17:51:17 +0000 [thread overview]
Message-ID: <20170309175116.GD11966@leverpostej> (raw)
In-Reply-To: <1489047912-642-8-git-send-email-ard.biesheuvel@linaro.org>
On Thu, Mar 09, 2017 at 09:25:09AM +0100, Ard Biesheuvel wrote:
> The debug_pagealloc facility manipulates kernel mappings in the linear
> region at page granularity to detect out of bounds or use-after-free
> accesses. Since the kernel segments are not allocated dynamically,
> there is no point in taking the debug_pagealloc_enabled flag into
> account for them, and we can use block mappings unconditionally.
>
> Note that this applies equally to the linear alias of text/rodata:
> we will never have dynamic allocations there given that the same
> memory is statically in use by the kernel image.
>
> Signed-off-by: Ard Biesheuvel <ard.biesheuvel@linaro.org>
This makes sense to me, and I haven't found anything this breaks.
It may be worth noting that a similar reasoning already applies the the
FDT mapping, where we use create_mapping_noalloc(), and never mandate
page mappings.
Regardless:
Reviewed-by: Mark Rutland <mark.rutland@arm.com>
Mark.
> ---
> arch/arm64/mm/mmu.c | 7 +++----
> 1 file changed, 3 insertions(+), 4 deletions(-)
>
> diff --git a/arch/arm64/mm/mmu.c b/arch/arm64/mm/mmu.c
> index c3963c592ec3..d3fecd20a136 100644
> --- a/arch/arm64/mm/mmu.c
> +++ b/arch/arm64/mm/mmu.c
> @@ -328,8 +328,7 @@ static void update_mapping_prot(phys_addr_t phys, unsigned long virt,
> return;
> }
>
> - __create_pgd_mapping(init_mm.pgd, phys, virt, size, prot,
> - NULL, debug_pagealloc_enabled());
> + __create_pgd_mapping(init_mm.pgd, phys, virt, size, prot, NULL, false);
>
> /* flush the TLBs after updating live kernel mappings */
> flush_tlb_kernel_range(virt, virt + size);
> @@ -381,7 +380,7 @@ static void __init __map_memblock(pgd_t *pgd, phys_addr_t start, phys_addr_t end
> */
> __create_pgd_mapping(pgd, kernel_start, __phys_to_virt(kernel_start),
> kernel_end - kernel_start, PAGE_KERNEL,
> - early_pgtable_alloc, debug_pagealloc_enabled());
> + early_pgtable_alloc, false);
> }
>
> void __init mark_linear_text_alias_ro(void)
> @@ -437,7 +436,7 @@ static void __init map_kernel_segment(pgd_t *pgd, void *va_start, void *va_end,
> BUG_ON(!PAGE_ALIGNED(size));
>
> __create_pgd_mapping(pgd, pa_start, (unsigned long)va_start, size, prot,
> - early_pgtable_alloc, debug_pagealloc_enabled());
> + early_pgtable_alloc, false);
>
> vma->addr = va_start;
> vma->phys_addr = pa_start;
> --
> 2.7.4
>
WARNING: multiple messages have this Message-ID (diff)
From: mark.rutland@arm.com (Mark Rutland)
To: linux-arm-kernel@lists.infradead.org
Subject: [PATCH v5 07/10] arm64/mmu: ignore debug_pagealloc for kernel segments
Date: Thu, 9 Mar 2017 17:51:17 +0000 [thread overview]
Message-ID: <20170309175116.GD11966@leverpostej> (raw)
In-Reply-To: <1489047912-642-8-git-send-email-ard.biesheuvel@linaro.org>
On Thu, Mar 09, 2017 at 09:25:09AM +0100, Ard Biesheuvel wrote:
> The debug_pagealloc facility manipulates kernel mappings in the linear
> region at page granularity to detect out of bounds or use-after-free
> accesses. Since the kernel segments are not allocated dynamically,
> there is no point in taking the debug_pagealloc_enabled flag into
> account for them, and we can use block mappings unconditionally.
>
> Note that this applies equally to the linear alias of text/rodata:
> we will never have dynamic allocations there given that the same
> memory is statically in use by the kernel image.
>
> Signed-off-by: Ard Biesheuvel <ard.biesheuvel@linaro.org>
This makes sense to me, and I haven't found anything this breaks.
It may be worth noting that a similar reasoning already applies the the
FDT mapping, where we use create_mapping_noalloc(), and never mandate
page mappings.
Regardless:
Reviewed-by: Mark Rutland <mark.rutland@arm.com>
Mark.
> ---
> arch/arm64/mm/mmu.c | 7 +++----
> 1 file changed, 3 insertions(+), 4 deletions(-)
>
> diff --git a/arch/arm64/mm/mmu.c b/arch/arm64/mm/mmu.c
> index c3963c592ec3..d3fecd20a136 100644
> --- a/arch/arm64/mm/mmu.c
> +++ b/arch/arm64/mm/mmu.c
> @@ -328,8 +328,7 @@ static void update_mapping_prot(phys_addr_t phys, unsigned long virt,
> return;
> }
>
> - __create_pgd_mapping(init_mm.pgd, phys, virt, size, prot,
> - NULL, debug_pagealloc_enabled());
> + __create_pgd_mapping(init_mm.pgd, phys, virt, size, prot, NULL, false);
>
> /* flush the TLBs after updating live kernel mappings */
> flush_tlb_kernel_range(virt, virt + size);
> @@ -381,7 +380,7 @@ static void __init __map_memblock(pgd_t *pgd, phys_addr_t start, phys_addr_t end
> */
> __create_pgd_mapping(pgd, kernel_start, __phys_to_virt(kernel_start),
> kernel_end - kernel_start, PAGE_KERNEL,
> - early_pgtable_alloc, debug_pagealloc_enabled());
> + early_pgtable_alloc, false);
> }
>
> void __init mark_linear_text_alias_ro(void)
> @@ -437,7 +436,7 @@ static void __init map_kernel_segment(pgd_t *pgd, void *va_start, void *va_end,
> BUG_ON(!PAGE_ALIGNED(size));
>
> __create_pgd_mapping(pgd, pa_start, (unsigned long)va_start, size, prot,
> - early_pgtable_alloc, debug_pagealloc_enabled());
> + early_pgtable_alloc, false);
>
> vma->addr = va_start;
> vma->phys_addr = pa_start;
> --
> 2.7.4
>
next prev parent reply other threads:[~2017-03-09 17:51 UTC|newest]
Thread overview: 51+ messages / expand[flat|nested] mbox.gz Atom feed top
2017-03-09 8:25 [kernel-hardening] [PATCH v5 00/10] arm64: mmu: avoid W+X mappings and re-enable PTE_CONT for kernel Ard Biesheuvel
2017-03-09 8:25 ` Ard Biesheuvel
2017-03-09 8:25 ` Ard Biesheuvel
2017-03-09 8:25 ` [kernel-hardening] [PATCH v5 01/10] arm: kvm: move kvm_vgic_global_state out of .text section Ard Biesheuvel
2017-03-09 8:25 ` Ard Biesheuvel
2017-03-09 8:25 ` Ard Biesheuvel
2017-03-09 8:25 ` [kernel-hardening] [PATCH v5 02/10] arm64: mmu: move TLB maintenance from callers to create_mapping_late() Ard Biesheuvel
2017-03-09 8:25 ` Ard Biesheuvel
2017-03-09 8:25 ` Ard Biesheuvel
2017-03-09 8:25 ` [kernel-hardening] [PATCH v5 03/10] arm64: alternatives: apply boot time fixups via the linear mapping Ard Biesheuvel
2017-03-09 8:25 ` Ard Biesheuvel
2017-03-09 8:25 ` Ard Biesheuvel
2017-03-09 8:25 ` [kernel-hardening] [PATCH v5 04/10] arm64: mmu: map .text as read-only from the outset Ard Biesheuvel
2017-03-09 8:25 ` Ard Biesheuvel
2017-03-09 8:25 ` Ard Biesheuvel
2017-03-09 8:25 ` [kernel-hardening] [PATCH v5 05/10] arm64: mmu: apply strict permissions to .init.text and .init.data Ard Biesheuvel
2017-03-09 8:25 ` Ard Biesheuvel
2017-03-09 8:25 ` Ard Biesheuvel
2017-03-09 8:25 ` [kernel-hardening] [PATCH v5 06/10] arm64/mmu: align alloc_init_pte prototype with pmd/pud versions Ard Biesheuvel
2017-03-09 8:25 ` Ard Biesheuvel
2017-03-09 8:25 ` Ard Biesheuvel
2017-03-09 15:53 ` [kernel-hardening] " Mark Rutland
2017-03-09 15:53 ` Mark Rutland
2017-03-09 15:53 ` Mark Rutland
2017-03-09 8:25 ` [kernel-hardening] [PATCH v5 07/10] arm64/mmu: ignore debug_pagealloc for kernel segments Ard Biesheuvel
2017-03-09 8:25 ` Ard Biesheuvel
2017-03-09 8:25 ` Ard Biesheuvel
2017-03-09 17:51 ` Mark Rutland [this message]
2017-03-09 17:51 ` Mark Rutland
2017-03-09 17:51 ` Mark Rutland
2017-03-09 8:25 ` [kernel-hardening] [PATCH v5 08/10] arm64/mmu: add contiguous bit to sanity bug check Ard Biesheuvel
2017-03-09 8:25 ` Ard Biesheuvel
2017-03-09 8:25 ` Ard Biesheuvel
2017-03-09 18:04 ` [kernel-hardening] " Mark Rutland
2017-03-09 18:04 ` Mark Rutland
2017-03-09 18:04 ` Mark Rutland
2017-03-09 8:25 ` [kernel-hardening] [PATCH v5 09/10] arm64/mmu: replace 'page_mappings_only' parameter with flags argument Ard Biesheuvel
2017-03-09 8:25 ` Ard Biesheuvel
2017-03-09 8:25 ` Ard Biesheuvel
2017-03-09 18:19 ` [kernel-hardening] " Mark Rutland
2017-03-09 18:19 ` Mark Rutland
2017-03-09 18:19 ` Mark Rutland
2017-03-09 8:25 ` [kernel-hardening] [PATCH v5 10/10] arm64: mm: set the contiguous bit for kernel mappings where appropriate Ard Biesheuvel
2017-03-09 8:25 ` Ard Biesheuvel
2017-03-09 8:25 ` Ard Biesheuvel
2017-03-09 19:33 ` [kernel-hardening] " Mark Rutland
2017-03-09 19:33 ` Mark Rutland
2017-03-09 19:33 ` Mark Rutland
2017-03-09 19:40 ` [kernel-hardening] " Ard Biesheuvel
2017-03-09 19:40 ` Ard Biesheuvel
2017-03-09 19:40 ` Ard Biesheuvel
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20170309175116.GD11966@leverpostej \
--to=mark.rutland@arm.com \
--cc=ard.biesheuvel@linaro.org \
--cc=catalin.marinas@arm.com \
--cc=keescook@chromium.org \
--cc=kernel-hardening@lists.openwall.com \
--cc=kvmarm@lists.cs.columbia.edu \
--cc=labbott@fedoraproject.org \
--cc=linux-arm-kernel@lists.infradead.org \
--cc=marc.zyngier@arm.com \
--cc=will.deacon@arm.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.