From: Tony Lindgren <tony@atomide.com>
To: Ard Biesheuvel <ard.biesheuvel@linaro.org>
Cc: linux-arm-kernel@lists.infradead.org,
kernel-hardening@lists.openwall.com,
Arnd Bergmann <arnd@arndb.de>, Nicolas Pitre <nico@linaro.org>,
Russell King <linux@armlinux.org.uk>,
Kees Cook <keescook@chromium.org>,
Thomas Garnier <thgarnie@google.com>,
Marc Zyngier <marc.zyngier@arm.com>,
Mark Rutland <mark.rutland@arm.com>,
Matt Fleming <matt@codeblueprint.co.uk>,
Dave Martin <dave.martin@arm.com>
Subject: [kernel-hardening] Re: [PATCH v2 00/29] implement KASLR for ARM
Date: Tue, 5 Sep 2017 09:45:48 -0700 [thread overview]
Message-ID: <20170905164547.GA5024@atomide.com> (raw)
In-Reply-To: <20170903120757.14968-1-ard.biesheuvel@linaro.org>
Hi,
* Ard Biesheuvel <ard.biesheuvel@linaro.org> [170903 05:08]:
> This series implements randomization of the placement of the core ARM kernel
> inside the lowmem region. It consists of the following parts:
>
> - changes that allow us to build vmlinux as a PIE executable which retains
> the metadata required to fix up all absolute symbol references at runtime
> - changes that eliminate absolute references from low-level code that may
> execute with the MMU off: this removes the need to perform explicit cache
> maintenance after the absolute references have been fixed up at runtime with
> the caches enabled
> - changes to the core kernel startup code to take the physical offset into
> account when creating the virtual mapping (the pa-to-va mapping remains
> unchanged)
> - changes to the decompressor to collect some pseudo-entropy, and randomize
> the physical offset of the decompressed kernel, taking placement of DTB,
> initrd and reserved regions into account
> - changes to the UEFI stub code to choose the KASLR offset and communicate
> it to the decompressor
>
> To test these changes, boot a multi_v7_defconfig+CONFIG_RANDOMIZE_BASE=y
I gave a quick try using your arm-kaslr-v3 branch, hopefully that's
the right one.
The good news is that now omap3 boots with omap2plus_defconfig with
and without CONFIG_RANDOMIZE_BASE=y and I did not see any compiler
errors with my gcc 6.2.0 like earlier :)
I did see boot attempts fail with randomize enable where no output
was produced. It seems this is happening for me maybe 1 out of 5 boots.
Enabling DEBUG_LL did not show anything either.
Then loading modules with CONFIG_RANDOMIZE_BASE=y seems to fail with:
$ sudo modprobe rtc-twl
rtc_twl: disagrees about version of symbol module_layout
modprobe: ERROR: could not insert 'rtc_twl': Exec format error
Regards,
Tony
WARNING: multiple messages have this Message-ID (diff)
From: tony@atomide.com (Tony Lindgren)
To: linux-arm-kernel@lists.infradead.org
Subject: [PATCH v2 00/29] implement KASLR for ARM
Date: Tue, 5 Sep 2017 09:45:48 -0700 [thread overview]
Message-ID: <20170905164547.GA5024@atomide.com> (raw)
In-Reply-To: <20170903120757.14968-1-ard.biesheuvel@linaro.org>
Hi,
* Ard Biesheuvel <ard.biesheuvel@linaro.org> [170903 05:08]:
> This series implements randomization of the placement of the core ARM kernel
> inside the lowmem region. It consists of the following parts:
>
> - changes that allow us to build vmlinux as a PIE executable which retains
> the metadata required to fix up all absolute symbol references at runtime
> - changes that eliminate absolute references from low-level code that may
> execute with the MMU off: this removes the need to perform explicit cache
> maintenance after the absolute references have been fixed up at runtime with
> the caches enabled
> - changes to the core kernel startup code to take the physical offset into
> account when creating the virtual mapping (the pa-to-va mapping remains
> unchanged)
> - changes to the decompressor to collect some pseudo-entropy, and randomize
> the physical offset of the decompressed kernel, taking placement of DTB,
> initrd and reserved regions into account
> - changes to the UEFI stub code to choose the KASLR offset and communicate
> it to the decompressor
>
> To test these changes, boot a multi_v7_defconfig+CONFIG_RANDOMIZE_BASE=y
I gave a quick try using your arm-kaslr-v3 branch, hopefully that's
the right one.
The good news is that now omap3 boots with omap2plus_defconfig with
and without CONFIG_RANDOMIZE_BASE=y and I did not see any compiler
errors with my gcc 6.2.0 like earlier :)
I did see boot attempts fail with randomize enable where no output
was produced. It seems this is happening for me maybe 1 out of 5 boots.
Enabling DEBUG_LL did not show anything either.
Then loading modules with CONFIG_RANDOMIZE_BASE=y seems to fail with:
$ sudo modprobe rtc-twl
rtc_twl: disagrees about version of symbol module_layout
modprobe: ERROR: could not insert 'rtc_twl': Exec format error
Regards,
Tony
next prev parent reply other threads:[~2017-09-05 16:45 UTC|newest]
Thread overview: 166+ messages / expand[flat|nested] mbox.gz Atom feed top
2017-09-03 12:07 [kernel-hardening] [PATCH v2 00/29] implement KASLR for ARM Ard Biesheuvel
2017-09-03 12:07 ` Ard Biesheuvel
2017-09-03 12:07 ` [kernel-hardening] [PATCH v2 01/29] net/core: work around section mismatch warning for ptp_classifier Ard Biesheuvel
2017-09-03 12:07 ` Ard Biesheuvel
2017-09-03 12:07 ` [kernel-hardening] [PATCH v2 02/29] asm-generic: add .data.rel.ro sections to __ro_after_init Ard Biesheuvel
2017-09-03 12:07 ` Ard Biesheuvel
2017-09-04 15:59 ` [kernel-hardening] " Nicolas Pitre
2017-09-04 15:59 ` Nicolas Pitre
2017-09-04 17:09 ` [kernel-hardening] " Kees Cook
2017-09-04 17:09 ` Kees Cook
2017-09-03 12:07 ` [kernel-hardening] [PATCH v2 03/29] ARM: assembler: introduce adr_l, ldr_l and str_l macros Ard Biesheuvel
2017-09-03 12:07 ` Ard Biesheuvel
2017-09-04 16:05 ` [kernel-hardening] " Nicolas Pitre
2017-09-04 16:05 ` Nicolas Pitre
2017-09-03 12:07 ` [kernel-hardening] [PATCH v2 04/29] ARM: head-common.S: use PC-relative insn sequence for __proc_info Ard Biesheuvel
2017-09-03 12:07 ` Ard Biesheuvel
2017-09-04 16:06 ` [kernel-hardening] " Nicolas Pitre
2017-09-04 16:06 ` Nicolas Pitre
2017-09-03 12:07 ` [kernel-hardening] [PATCH v2 05/29] ARM: head-common.S: use PC-relative insn sequence for idmap creation Ard Biesheuvel
2017-09-03 12:07 ` Ard Biesheuvel
2017-09-04 16:08 ` [kernel-hardening] " Nicolas Pitre
2017-09-04 16:08 ` Nicolas Pitre
2017-09-03 12:07 ` [kernel-hardening] [PATCH v2 06/29] ARM: head.S: use PC-relative insn sequence for secondary_data Ard Biesheuvel
2017-09-03 12:07 ` Ard Biesheuvel
2017-09-04 16:09 ` [kernel-hardening] " Nicolas Pitre
2017-09-04 16:09 ` Nicolas Pitre
2017-09-03 12:07 ` [kernel-hardening] [PATCH v2 07/29] ARM: kernel: use relative references for UP/SMP alternatives Ard Biesheuvel
2017-09-03 12:07 ` Ard Biesheuvel
2017-09-04 16:15 ` [kernel-hardening] " Nicolas Pitre
2017-09-04 16:15 ` Nicolas Pitre
2017-09-03 12:07 ` [kernel-hardening] [PATCH v2 08/29] ARM: head: use PC-relative insn sequence for __smp_alt Ard Biesheuvel
2017-09-03 12:07 ` Ard Biesheuvel
2017-09-04 16:19 ` [kernel-hardening] " Nicolas Pitre
2017-09-04 16:19 ` Nicolas Pitre
2017-09-04 16:20 ` [kernel-hardening] " Ard Biesheuvel
2017-09-04 16:20 ` Ard Biesheuvel
2017-09-03 12:07 ` [kernel-hardening] [PATCH v2 09/29] ARM: sleep.S: use PC-relative insn sequence for sleep_save_sp/mpidr_hash Ard Biesheuvel
2017-09-03 12:07 ` Ard Biesheuvel
2017-09-04 16:20 ` [kernel-hardening] " Nicolas Pitre
2017-09-04 16:20 ` Nicolas Pitre
2017-09-03 12:07 ` [kernel-hardening] [PATCH v2 10/29] ARM: head.S: use PC-relative insn sequences for __fixup_pv_table Ard Biesheuvel
2017-09-03 12:07 ` Ard Biesheuvel
2017-09-04 16:47 ` [kernel-hardening] " Nicolas Pitre
2017-09-04 16:47 ` Nicolas Pitre
2017-09-03 12:07 ` [kernel-hardening] [PATCH v2 11/29] ARM: head.S: use PC relative insn sequence to calculate PHYS_OFFSET Ard Biesheuvel
2017-09-03 12:07 ` Ard Biesheuvel
2017-09-04 16:50 ` [kernel-hardening] " Nicolas Pitre
2017-09-04 16:50 ` Nicolas Pitre
2017-09-03 12:07 ` [kernel-hardening] [PATCH v2 12/29] ARM: kvm: replace open coded VA->PA calculations with adr_l call Ard Biesheuvel
2017-09-03 12:07 ` Ard Biesheuvel
2017-09-04 16:57 ` [kernel-hardening] " Nicolas Pitre
2017-09-04 16:57 ` Nicolas Pitre
2017-09-03 12:07 ` [kernel-hardening] [PATCH v2 13/29] arm-soc: exynos: replace open coded VA->PA conversions Ard Biesheuvel
2017-09-03 12:07 ` Ard Biesheuvel
2017-09-04 16:59 ` [kernel-hardening] " Nicolas Pitre
2017-09-04 16:59 ` Nicolas Pitre
2017-09-03 12:07 ` [kernel-hardening] [PATCH v2 14/29] arm-soc: mvebu: replace open coded VA->PA conversion Ard Biesheuvel
2017-09-03 12:07 ` Ard Biesheuvel
2017-09-04 17:00 ` [kernel-hardening] " Nicolas Pitre
2017-09-04 17:00 ` Nicolas Pitre
2017-09-03 12:07 ` [kernel-hardening] [PATCH v2 15/29] arm-soc: various: replace open coded VA->PA calculation of pen_release Ard Biesheuvel
2017-09-03 12:07 ` Ard Biesheuvel
2017-09-04 17:01 ` [kernel-hardening] " Nicolas Pitre
2017-09-04 17:01 ` Nicolas Pitre
2017-09-03 12:07 ` [kernel-hardening] [PATCH v2 16/29] ARM: kernel: switch to relative exception tables Ard Biesheuvel
2017-09-03 12:07 ` Ard Biesheuvel
2017-09-04 17:17 ` [kernel-hardening] " Nicolas Pitre
2017-09-04 17:17 ` Nicolas Pitre
2017-09-04 17:30 ` [kernel-hardening] " Ard Biesheuvel
2017-09-04 17:30 ` Ard Biesheuvel
2017-09-03 12:07 ` [kernel-hardening] [PATCH v2 17/29] ARM: kernel: use relative phys-to-virt patch tables Ard Biesheuvel
2017-09-03 12:07 ` Ard Biesheuvel
2017-09-04 18:03 ` [kernel-hardening] " Nicolas Pitre
2017-09-04 18:03 ` Nicolas Pitre
2017-09-04 19:09 ` [kernel-hardening] " Ard Biesheuvel
2017-09-04 19:09 ` Ard Biesheuvel
2017-09-03 12:07 ` [kernel-hardening] [PATCH v2 18/29] arm-soc: tegra: make sleep asm code runtime relocatable Ard Biesheuvel
2017-09-03 12:07 ` Ard Biesheuvel
2017-09-03 12:07 ` [kernel-hardening] [PATCH v2 19/29] ARM: kernel: make vmlinux buildable as a PIE executable Ard Biesheuvel
2017-09-03 12:07 ` Ard Biesheuvel
2017-09-04 18:11 ` [kernel-hardening] " Nicolas Pitre
2017-09-04 18:11 ` Nicolas Pitre
2017-09-04 19:10 ` [kernel-hardening] " Ard Biesheuvel
2017-09-04 19:10 ` Ard Biesheuvel
2017-09-03 12:07 ` [kernel-hardening] [PATCH v2 20/29] ARM: kernel: use PC-relative symbol references in MMU switch code Ard Biesheuvel
2017-09-03 12:07 ` Ard Biesheuvel
2017-09-04 18:15 ` [kernel-hardening] " Nicolas Pitre
2017-09-04 18:15 ` Nicolas Pitre
2017-09-04 19:14 ` [kernel-hardening] " Ard Biesheuvel
2017-09-04 19:14 ` Ard Biesheuvel
2017-09-03 12:07 ` [kernel-hardening] [PATCH v2 21/29] ARM: kernel: use PC relative symbol references in suspend/resume code Ard Biesheuvel
2017-09-03 12:07 ` Ard Biesheuvel
2017-09-04 18:24 ` [kernel-hardening] " Nicolas Pitre
2017-09-04 18:24 ` Nicolas Pitre
2017-09-04 19:17 ` [kernel-hardening] " Ard Biesheuvel
2017-09-04 19:17 ` Ard Biesheuvel
2017-09-03 12:07 ` [kernel-hardening] [PATCH v2 22/29] ARM: mm: export default vmalloc base address Ard Biesheuvel
2017-09-03 12:07 ` Ard Biesheuvel
2017-09-04 18:25 ` [kernel-hardening] " Nicolas Pitre
2017-09-04 18:25 ` Nicolas Pitre
2017-09-03 12:07 ` [kernel-hardening] [PATCH v2 23/29] ARM: kernel: refer to swapper_pg_dir via its symbol Ard Biesheuvel
2017-09-03 12:07 ` Ard Biesheuvel
2017-09-04 18:30 ` [kernel-hardening] " Nicolas Pitre
2017-09-04 18:30 ` Nicolas Pitre
2017-09-04 19:26 ` [kernel-hardening] " Ard Biesheuvel
2017-09-04 19:26 ` Ard Biesheuvel
2017-09-03 12:07 ` [kernel-hardening] [PATCH v2 24/29] ARM: kernel: implement randomization of the kernel load address Ard Biesheuvel
2017-09-03 12:07 ` Ard Biesheuvel
2017-09-04 18:44 ` [kernel-hardening] " Nicolas Pitre
2017-09-04 18:44 ` Nicolas Pitre
2017-09-04 19:29 ` [kernel-hardening] " Ard Biesheuvel
2017-09-04 19:29 ` Ard Biesheuvel
2017-09-03 12:07 ` [kernel-hardening] [PATCH v2 25/29] ARM: decompressor: explicitly map decompressor binary cacheable Ard Biesheuvel
2017-09-03 12:07 ` Ard Biesheuvel
2017-09-04 18:47 ` [kernel-hardening] " Nicolas Pitre
2017-09-04 18:47 ` Nicolas Pitre
2017-09-03 12:07 ` [kernel-hardening] [PATCH v2 26/29] ARM: decompressor: add KASLR support Ard Biesheuvel
2017-09-03 12:07 ` Ard Biesheuvel
2017-09-04 18:53 ` [kernel-hardening] " Nicolas Pitre
2017-09-04 18:53 ` Nicolas Pitre
2017-09-04 19:33 ` [kernel-hardening] " Ard Biesheuvel
2017-09-04 19:33 ` Ard Biesheuvel
2017-09-03 12:07 ` [kernel-hardening] [PATCH v2 27/29] efi/libstub: add 'max' parameter to efi_random_alloc() Ard Biesheuvel
2017-09-03 12:07 ` Ard Biesheuvel
2017-09-03 12:07 ` [kernel-hardening] [PATCH v2 28/29] efi/libstub: check for vmalloc= command line argument Ard Biesheuvel
2017-09-03 12:07 ` Ard Biesheuvel
2017-09-03 12:07 ` [kernel-hardening] [PATCH v2 29/29] efi/libstub: arm: implement KASLR Ard Biesheuvel
2017-09-03 12:07 ` Ard Biesheuvel
2017-09-05 16:45 ` Tony Lindgren [this message]
2017-09-05 16:45 ` [PATCH v2 00/29] implement KASLR for ARM Tony Lindgren
2017-09-05 16:48 ` [kernel-hardening] " Ard Biesheuvel
2017-09-05 16:48 ` Ard Biesheuvel
2017-09-05 19:37 ` [kernel-hardening] " Tony Lindgren
2017-09-05 19:37 ` Tony Lindgren
2017-09-05 19:42 ` [kernel-hardening] " Ard Biesheuvel
2017-09-05 19:42 ` Ard Biesheuvel
2017-09-05 21:27 ` [kernel-hardening] " Tony Lindgren
2017-09-05 21:27 ` Tony Lindgren
2017-09-05 21:31 ` [kernel-hardening] " Ard Biesheuvel
2017-09-05 21:31 ` Ard Biesheuvel
2017-09-06 10:40 ` [kernel-hardening] " Ard Biesheuvel
2017-09-06 10:40 ` Ard Biesheuvel
2017-09-06 16:22 ` [kernel-hardening] " Tony Lindgren
2017-09-06 16:22 ` Tony Lindgren
2017-09-06 16:25 ` [kernel-hardening] " Ard Biesheuvel
2017-09-06 16:25 ` Ard Biesheuvel
2017-09-06 16:31 ` [kernel-hardening] " Tony Lindgren
2017-09-06 16:31 ` Tony Lindgren
2017-09-06 16:35 ` [kernel-hardening] " Ard Biesheuvel
2017-09-06 16:35 ` Ard Biesheuvel
2017-09-06 17:12 ` [kernel-hardening] " Tony Lindgren
2017-09-06 17:12 ` Tony Lindgren
2017-09-06 17:30 ` [kernel-hardening] " Ard Biesheuvel
2017-09-06 17:30 ` Ard Biesheuvel
2017-09-06 17:53 ` [kernel-hardening] " Tony Lindgren
2017-09-06 17:53 ` Tony Lindgren
2017-09-06 18:04 ` [kernel-hardening] " Ard Biesheuvel
2017-09-06 18:04 ` Ard Biesheuvel
2017-09-06 18:22 ` [kernel-hardening] " Tony Lindgren
2017-09-06 18:22 ` Tony Lindgren
2017-09-06 18:25 ` [kernel-hardening] " Ard Biesheuvel
2017-09-06 18:25 ` Ard Biesheuvel
2017-09-06 20:08 ` [kernel-hardening] " Tony Lindgren
2017-09-06 20:08 ` Tony Lindgren
2017-09-12 6:51 ` [kernel-hardening] " Ard Biesheuvel
2017-09-12 6:51 ` Ard Biesheuvel
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20170905164547.GA5024@atomide.com \
--to=tony@atomide.com \
--cc=ard.biesheuvel@linaro.org \
--cc=arnd@arndb.de \
--cc=dave.martin@arm.com \
--cc=keescook@chromium.org \
--cc=kernel-hardening@lists.openwall.com \
--cc=linux-arm-kernel@lists.infradead.org \
--cc=linux@armlinux.org.uk \
--cc=marc.zyngier@arm.com \
--cc=mark.rutland@arm.com \
--cc=matt@codeblueprint.co.uk \
--cc=nico@linaro.org \
--cc=thgarnie@google.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.