All of lore.kernel.org
 help / color / mirror / Atom feed
From: Tony Lindgren <tony@atomide.com>
To: Ard Biesheuvel <ard.biesheuvel@linaro.org>
Cc: "linux-arm-kernel@lists.infradead.org"
	<linux-arm-kernel@lists.infradead.org>,
	Kernel Hardening <kernel-hardening@lists.openwall.com>,
	Arnd Bergmann <arnd@arndb.de>, Nicolas Pitre <nico@linaro.org>,
	Russell King <linux@armlinux.org.uk>,
	Kees Cook <keescook@chromium.org>,
	Thomas Garnier <thgarnie@google.com>,
	Marc Zyngier <marc.zyngier@arm.com>,
	Mark Rutland <mark.rutland@arm.com>,
	Matt Fleming <matt@codeblueprint.co.uk>,
	Dave Martin <dave.martin@arm.com>
Subject: [kernel-hardening] Re: [PATCH v2 00/29] implement KASLR for ARM
Date: Tue, 5 Sep 2017 14:27:42 -0700	[thread overview]
Message-ID: <20170905212742.GG5024@atomide.com> (raw)
In-Reply-To: <CAKv+Gu9c_j0qriRazSTmq8eD9icCu4Wuzw1z-LF7bubLVLQd7Q@mail.gmail.com>

* Ard Biesheuvel <ard.biesheuvel@linaro.org> [170905 12:43]:
> Right. Well, I will try to reproduce with the BB white I have.

Yeah that should be reproducable, I got it to happen on BBB here
after about 5 boots.

> Are you booting with an initrd?

Not on this one, on beagleboard xm I do.

> >> > Then loading modules with CONFIG_RANDOMIZE_BASE=y seems to fail with:
> >> >
> >> > $ sudo modprobe rtc-twl
> >> > rtc_twl: disagrees about version of symbol module_layout
> >> > modprobe: ERROR: could not insert 'rtc_twl': Exec format error
> >> >
> >>
> >> Is this with CONFIG_MODVERSIONS enabled?
> >
> > Yes, but disabling that did not seem to make any difference
> > based on just one test.
> >
> 
> Yeah, well, it appears I missed a couple of details :-)
> 
> This should fix the module loading issues:

Yeah now modprobe works :) That's after manually applying
it as the tabs got munched in your patch somewhere, see below.

Regards,

Tony

> diff --git a/arch/arm/Kconfig b/arch/arm/Kconfig
> index 1a0304dd388d..bbefd5f32ec2 100644
> --- a/arch/arm/Kconfig
> +++ b/arch/arm/Kconfig
> @@ -1830,6 +1830,8 @@ config RANDOMIZE_BASE
>   depends on MMU && AUTO_ZRELADDR
>   depends on !XIP_KERNEL && !ZBOOT_ROM
>   select RELOCATABLE
> + select ARM_MODULE_PLTS if MODULES
> + select MODULE_REL_CRCS if MODVERSIONS
>   help
>    Randomizes the virtual and physical address at which the kernel
>    image is loaded, as a security feature that deters exploit attempts
> diff --git a/arch/arm/include/asm/elf.h b/arch/arm/include/asm/elf.h
> index f13ae153fb24..b56fc4dd27b6 100644
> --- a/arch/arm/include/asm/elf.h
> +++ b/arch/arm/include/asm/elf.h
> @@ -50,6 +50,7 @@ typedef struct user_fp elf_fpregset_t;
>  #define R_ARM_NONE 0
>  #define R_ARM_PC24 1
>  #define R_ARM_ABS32 2
> +#define R_ARM_REL32 3
>  #define R_ARM_CALL 28
>  #define R_ARM_JUMP24 29
>  #define R_ARM_TARGET1 38
> diff --git a/arch/arm/kernel/module.c b/arch/arm/kernel/module.c
> index 3ff571c2c71c..aa4d72837cd5 100644
> --- a/arch/arm/kernel/module.c
> +++ b/arch/arm/kernel/module.c
> @@ -175,6 +175,10 @@
>   *(u32 *)loc |= offset & 0x7fffffff;
>   break;
> 
> + case R_ARM_REL32:
> + *(u32 *)loc += sym->st_value - loc;
> + break;
> +
>   case R_ARM_MOVW_ABS_NC:
>   case R_ARM_MOVT_ABS:
>   offset = tmp = __mem_to_opcode_arm(*(u32 *)loc);

WARNING: multiple messages have this Message-ID (diff)
From: tony@atomide.com (Tony Lindgren)
To: linux-arm-kernel@lists.infradead.org
Subject: [PATCH v2 00/29] implement KASLR for ARM
Date: Tue, 5 Sep 2017 14:27:42 -0700	[thread overview]
Message-ID: <20170905212742.GG5024@atomide.com> (raw)
In-Reply-To: <CAKv+Gu9c_j0qriRazSTmq8eD9icCu4Wuzw1z-LF7bubLVLQd7Q@mail.gmail.com>

* Ard Biesheuvel <ard.biesheuvel@linaro.org> [170905 12:43]:
> Right. Well, I will try to reproduce with the BB white I have.

Yeah that should be reproducable, I got it to happen on BBB here
after about 5 boots.

> Are you booting with an initrd?

Not on this one, on beagleboard xm I do.

> >> > Then loading modules with CONFIG_RANDOMIZE_BASE=y seems to fail with:
> >> >
> >> > $ sudo modprobe rtc-twl
> >> > rtc_twl: disagrees about version of symbol module_layout
> >> > modprobe: ERROR: could not insert 'rtc_twl': Exec format error
> >> >
> >>
> >> Is this with CONFIG_MODVERSIONS enabled?
> >
> > Yes, but disabling that did not seem to make any difference
> > based on just one test.
> >
> 
> Yeah, well, it appears I missed a couple of details :-)
> 
> This should fix the module loading issues:

Yeah now modprobe works :) That's after manually applying
it as the tabs got munched in your patch somewhere, see below.

Regards,

Tony

> diff --git a/arch/arm/Kconfig b/arch/arm/Kconfig
> index 1a0304dd388d..bbefd5f32ec2 100644
> --- a/arch/arm/Kconfig
> +++ b/arch/arm/Kconfig
> @@ -1830,6 +1830,8 @@ config RANDOMIZE_BASE
>   depends on MMU && AUTO_ZRELADDR
>   depends on !XIP_KERNEL && !ZBOOT_ROM
>   select RELOCATABLE
> + select ARM_MODULE_PLTS if MODULES
> + select MODULE_REL_CRCS if MODVERSIONS
>   help
>    Randomizes the virtual and physical address at which the kernel
>    image is loaded, as a security feature that deters exploit attempts
> diff --git a/arch/arm/include/asm/elf.h b/arch/arm/include/asm/elf.h
> index f13ae153fb24..b56fc4dd27b6 100644
> --- a/arch/arm/include/asm/elf.h
> +++ b/arch/arm/include/asm/elf.h
> @@ -50,6 +50,7 @@ typedef struct user_fp elf_fpregset_t;
>  #define R_ARM_NONE 0
>  #define R_ARM_PC24 1
>  #define R_ARM_ABS32 2
> +#define R_ARM_REL32 3
>  #define R_ARM_CALL 28
>  #define R_ARM_JUMP24 29
>  #define R_ARM_TARGET1 38
> diff --git a/arch/arm/kernel/module.c b/arch/arm/kernel/module.c
> index 3ff571c2c71c..aa4d72837cd5 100644
> --- a/arch/arm/kernel/module.c
> +++ b/arch/arm/kernel/module.c
> @@ -175,6 +175,10 @@
>   *(u32 *)loc |= offset & 0x7fffffff;
>   break;
> 
> + case R_ARM_REL32:
> + *(u32 *)loc += sym->st_value - loc;
> + break;
> +
>   case R_ARM_MOVW_ABS_NC:
>   case R_ARM_MOVT_ABS:
>   offset = tmp = __mem_to_opcode_arm(*(u32 *)loc);

  reply	other threads:[~2017-09-05 21:27 UTC|newest]

Thread overview: 166+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2017-09-03 12:07 [kernel-hardening] [PATCH v2 00/29] implement KASLR for ARM Ard Biesheuvel
2017-09-03 12:07 ` Ard Biesheuvel
2017-09-03 12:07 ` [kernel-hardening] [PATCH v2 01/29] net/core: work around section mismatch warning for ptp_classifier Ard Biesheuvel
2017-09-03 12:07   ` Ard Biesheuvel
2017-09-03 12:07 ` [kernel-hardening] [PATCH v2 02/29] asm-generic: add .data.rel.ro sections to __ro_after_init Ard Biesheuvel
2017-09-03 12:07   ` Ard Biesheuvel
2017-09-04 15:59   ` [kernel-hardening] " Nicolas Pitre
2017-09-04 15:59     ` Nicolas Pitre
2017-09-04 17:09   ` [kernel-hardening] " Kees Cook
2017-09-04 17:09     ` Kees Cook
2017-09-03 12:07 ` [kernel-hardening] [PATCH v2 03/29] ARM: assembler: introduce adr_l, ldr_l and str_l macros Ard Biesheuvel
2017-09-03 12:07   ` Ard Biesheuvel
2017-09-04 16:05   ` [kernel-hardening] " Nicolas Pitre
2017-09-04 16:05     ` Nicolas Pitre
2017-09-03 12:07 ` [kernel-hardening] [PATCH v2 04/29] ARM: head-common.S: use PC-relative insn sequence for __proc_info Ard Biesheuvel
2017-09-03 12:07   ` Ard Biesheuvel
2017-09-04 16:06   ` [kernel-hardening] " Nicolas Pitre
2017-09-04 16:06     ` Nicolas Pitre
2017-09-03 12:07 ` [kernel-hardening] [PATCH v2 05/29] ARM: head-common.S: use PC-relative insn sequence for idmap creation Ard Biesheuvel
2017-09-03 12:07   ` Ard Biesheuvel
2017-09-04 16:08   ` [kernel-hardening] " Nicolas Pitre
2017-09-04 16:08     ` Nicolas Pitre
2017-09-03 12:07 ` [kernel-hardening] [PATCH v2 06/29] ARM: head.S: use PC-relative insn sequence for secondary_data Ard Biesheuvel
2017-09-03 12:07   ` Ard Biesheuvel
2017-09-04 16:09   ` [kernel-hardening] " Nicolas Pitre
2017-09-04 16:09     ` Nicolas Pitre
2017-09-03 12:07 ` [kernel-hardening] [PATCH v2 07/29] ARM: kernel: use relative references for UP/SMP alternatives Ard Biesheuvel
2017-09-03 12:07   ` Ard Biesheuvel
2017-09-04 16:15   ` [kernel-hardening] " Nicolas Pitre
2017-09-04 16:15     ` Nicolas Pitre
2017-09-03 12:07 ` [kernel-hardening] [PATCH v2 08/29] ARM: head: use PC-relative insn sequence for __smp_alt Ard Biesheuvel
2017-09-03 12:07   ` Ard Biesheuvel
2017-09-04 16:19   ` [kernel-hardening] " Nicolas Pitre
2017-09-04 16:19     ` Nicolas Pitre
2017-09-04 16:20     ` [kernel-hardening] " Ard Biesheuvel
2017-09-04 16:20       ` Ard Biesheuvel
2017-09-03 12:07 ` [kernel-hardening] [PATCH v2 09/29] ARM: sleep.S: use PC-relative insn sequence for sleep_save_sp/mpidr_hash Ard Biesheuvel
2017-09-03 12:07   ` Ard Biesheuvel
2017-09-04 16:20   ` [kernel-hardening] " Nicolas Pitre
2017-09-04 16:20     ` Nicolas Pitre
2017-09-03 12:07 ` [kernel-hardening] [PATCH v2 10/29] ARM: head.S: use PC-relative insn sequences for __fixup_pv_table Ard Biesheuvel
2017-09-03 12:07   ` Ard Biesheuvel
2017-09-04 16:47   ` [kernel-hardening] " Nicolas Pitre
2017-09-04 16:47     ` Nicolas Pitre
2017-09-03 12:07 ` [kernel-hardening] [PATCH v2 11/29] ARM: head.S: use PC relative insn sequence to calculate PHYS_OFFSET Ard Biesheuvel
2017-09-03 12:07   ` Ard Biesheuvel
2017-09-04 16:50   ` [kernel-hardening] " Nicolas Pitre
2017-09-04 16:50     ` Nicolas Pitre
2017-09-03 12:07 ` [kernel-hardening] [PATCH v2 12/29] ARM: kvm: replace open coded VA->PA calculations with adr_l call Ard Biesheuvel
2017-09-03 12:07   ` Ard Biesheuvel
2017-09-04 16:57   ` [kernel-hardening] " Nicolas Pitre
2017-09-04 16:57     ` Nicolas Pitre
2017-09-03 12:07 ` [kernel-hardening] [PATCH v2 13/29] arm-soc: exynos: replace open coded VA->PA conversions Ard Biesheuvel
2017-09-03 12:07   ` Ard Biesheuvel
2017-09-04 16:59   ` [kernel-hardening] " Nicolas Pitre
2017-09-04 16:59     ` Nicolas Pitre
2017-09-03 12:07 ` [kernel-hardening] [PATCH v2 14/29] arm-soc: mvebu: replace open coded VA->PA conversion Ard Biesheuvel
2017-09-03 12:07   ` Ard Biesheuvel
2017-09-04 17:00   ` [kernel-hardening] " Nicolas Pitre
2017-09-04 17:00     ` Nicolas Pitre
2017-09-03 12:07 ` [kernel-hardening] [PATCH v2 15/29] arm-soc: various: replace open coded VA->PA calculation of pen_release Ard Biesheuvel
2017-09-03 12:07   ` Ard Biesheuvel
2017-09-04 17:01   ` [kernel-hardening] " Nicolas Pitre
2017-09-04 17:01     ` Nicolas Pitre
2017-09-03 12:07 ` [kernel-hardening] [PATCH v2 16/29] ARM: kernel: switch to relative exception tables Ard Biesheuvel
2017-09-03 12:07   ` Ard Biesheuvel
2017-09-04 17:17   ` [kernel-hardening] " Nicolas Pitre
2017-09-04 17:17     ` Nicolas Pitre
2017-09-04 17:30     ` [kernel-hardening] " Ard Biesheuvel
2017-09-04 17:30       ` Ard Biesheuvel
2017-09-03 12:07 ` [kernel-hardening] [PATCH v2 17/29] ARM: kernel: use relative phys-to-virt patch tables Ard Biesheuvel
2017-09-03 12:07   ` Ard Biesheuvel
2017-09-04 18:03   ` [kernel-hardening] " Nicolas Pitre
2017-09-04 18:03     ` Nicolas Pitre
2017-09-04 19:09     ` [kernel-hardening] " Ard Biesheuvel
2017-09-04 19:09       ` Ard Biesheuvel
2017-09-03 12:07 ` [kernel-hardening] [PATCH v2 18/29] arm-soc: tegra: make sleep asm code runtime relocatable Ard Biesheuvel
2017-09-03 12:07   ` Ard Biesheuvel
2017-09-03 12:07 ` [kernel-hardening] [PATCH v2 19/29] ARM: kernel: make vmlinux buildable as a PIE executable Ard Biesheuvel
2017-09-03 12:07   ` Ard Biesheuvel
2017-09-04 18:11   ` [kernel-hardening] " Nicolas Pitre
2017-09-04 18:11     ` Nicolas Pitre
2017-09-04 19:10     ` [kernel-hardening] " Ard Biesheuvel
2017-09-04 19:10       ` Ard Biesheuvel
2017-09-03 12:07 ` [kernel-hardening] [PATCH v2 20/29] ARM: kernel: use PC-relative symbol references in MMU switch code Ard Biesheuvel
2017-09-03 12:07   ` Ard Biesheuvel
2017-09-04 18:15   ` [kernel-hardening] " Nicolas Pitre
2017-09-04 18:15     ` Nicolas Pitre
2017-09-04 19:14     ` [kernel-hardening] " Ard Biesheuvel
2017-09-04 19:14       ` Ard Biesheuvel
2017-09-03 12:07 ` [kernel-hardening] [PATCH v2 21/29] ARM: kernel: use PC relative symbol references in suspend/resume code Ard Biesheuvel
2017-09-03 12:07   ` Ard Biesheuvel
2017-09-04 18:24   ` [kernel-hardening] " Nicolas Pitre
2017-09-04 18:24     ` Nicolas Pitre
2017-09-04 19:17     ` [kernel-hardening] " Ard Biesheuvel
2017-09-04 19:17       ` Ard Biesheuvel
2017-09-03 12:07 ` [kernel-hardening] [PATCH v2 22/29] ARM: mm: export default vmalloc base address Ard Biesheuvel
2017-09-03 12:07   ` Ard Biesheuvel
2017-09-04 18:25   ` [kernel-hardening] " Nicolas Pitre
2017-09-04 18:25     ` Nicolas Pitre
2017-09-03 12:07 ` [kernel-hardening] [PATCH v2 23/29] ARM: kernel: refer to swapper_pg_dir via its symbol Ard Biesheuvel
2017-09-03 12:07   ` Ard Biesheuvel
2017-09-04 18:30   ` [kernel-hardening] " Nicolas Pitre
2017-09-04 18:30     ` Nicolas Pitre
2017-09-04 19:26     ` [kernel-hardening] " Ard Biesheuvel
2017-09-04 19:26       ` Ard Biesheuvel
2017-09-03 12:07 ` [kernel-hardening] [PATCH v2 24/29] ARM: kernel: implement randomization of the kernel load address Ard Biesheuvel
2017-09-03 12:07   ` Ard Biesheuvel
2017-09-04 18:44   ` [kernel-hardening] " Nicolas Pitre
2017-09-04 18:44     ` Nicolas Pitre
2017-09-04 19:29     ` [kernel-hardening] " Ard Biesheuvel
2017-09-04 19:29       ` Ard Biesheuvel
2017-09-03 12:07 ` [kernel-hardening] [PATCH v2 25/29] ARM: decompressor: explicitly map decompressor binary cacheable Ard Biesheuvel
2017-09-03 12:07   ` Ard Biesheuvel
2017-09-04 18:47   ` [kernel-hardening] " Nicolas Pitre
2017-09-04 18:47     ` Nicolas Pitre
2017-09-03 12:07 ` [kernel-hardening] [PATCH v2 26/29] ARM: decompressor: add KASLR support Ard Biesheuvel
2017-09-03 12:07   ` Ard Biesheuvel
2017-09-04 18:53   ` [kernel-hardening] " Nicolas Pitre
2017-09-04 18:53     ` Nicolas Pitre
2017-09-04 19:33     ` [kernel-hardening] " Ard Biesheuvel
2017-09-04 19:33       ` Ard Biesheuvel
2017-09-03 12:07 ` [kernel-hardening] [PATCH v2 27/29] efi/libstub: add 'max' parameter to efi_random_alloc() Ard Biesheuvel
2017-09-03 12:07   ` Ard Biesheuvel
2017-09-03 12:07 ` [kernel-hardening] [PATCH v2 28/29] efi/libstub: check for vmalloc= command line argument Ard Biesheuvel
2017-09-03 12:07   ` Ard Biesheuvel
2017-09-03 12:07 ` [kernel-hardening] [PATCH v2 29/29] efi/libstub: arm: implement KASLR Ard Biesheuvel
2017-09-03 12:07   ` Ard Biesheuvel
2017-09-05 16:45 ` [kernel-hardening] Re: [PATCH v2 00/29] implement KASLR for ARM Tony Lindgren
2017-09-05 16:45   ` Tony Lindgren
2017-09-05 16:48   ` [kernel-hardening] " Ard Biesheuvel
2017-09-05 16:48     ` Ard Biesheuvel
2017-09-05 19:37     ` [kernel-hardening] " Tony Lindgren
2017-09-05 19:37       ` Tony Lindgren
2017-09-05 19:42       ` [kernel-hardening] " Ard Biesheuvel
2017-09-05 19:42         ` Ard Biesheuvel
2017-09-05 21:27         ` Tony Lindgren [this message]
2017-09-05 21:27           ` Tony Lindgren
2017-09-05 21:31           ` [kernel-hardening] " Ard Biesheuvel
2017-09-05 21:31             ` Ard Biesheuvel
2017-09-06 10:40             ` [kernel-hardening] " Ard Biesheuvel
2017-09-06 10:40               ` Ard Biesheuvel
2017-09-06 16:22               ` [kernel-hardening] " Tony Lindgren
2017-09-06 16:22                 ` Tony Lindgren
2017-09-06 16:25                 ` [kernel-hardening] " Ard Biesheuvel
2017-09-06 16:25                   ` Ard Biesheuvel
2017-09-06 16:31                   ` [kernel-hardening] " Tony Lindgren
2017-09-06 16:31                     ` Tony Lindgren
2017-09-06 16:35                     ` [kernel-hardening] " Ard Biesheuvel
2017-09-06 16:35                       ` Ard Biesheuvel
2017-09-06 17:12                       ` [kernel-hardening] " Tony Lindgren
2017-09-06 17:12                         ` Tony Lindgren
2017-09-06 17:30                         ` [kernel-hardening] " Ard Biesheuvel
2017-09-06 17:30                           ` Ard Biesheuvel
2017-09-06 17:53                           ` [kernel-hardening] " Tony Lindgren
2017-09-06 17:53                             ` Tony Lindgren
2017-09-06 18:04                             ` [kernel-hardening] " Ard Biesheuvel
2017-09-06 18:04                               ` Ard Biesheuvel
2017-09-06 18:22                               ` [kernel-hardening] " Tony Lindgren
2017-09-06 18:22                                 ` Tony Lindgren
2017-09-06 18:25                                 ` [kernel-hardening] " Ard Biesheuvel
2017-09-06 18:25                                   ` Ard Biesheuvel
2017-09-06 20:08                                   ` [kernel-hardening] " Tony Lindgren
2017-09-06 20:08                                     ` Tony Lindgren
2017-09-12  6:51                                     ` [kernel-hardening] " Ard Biesheuvel
2017-09-12  6:51                                       ` Ard Biesheuvel

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20170905212742.GG5024@atomide.com \
    --to=tony@atomide.com \
    --cc=ard.biesheuvel@linaro.org \
    --cc=arnd@arndb.de \
    --cc=dave.martin@arm.com \
    --cc=keescook@chromium.org \
    --cc=kernel-hardening@lists.openwall.com \
    --cc=linux-arm-kernel@lists.infradead.org \
    --cc=linux@armlinux.org.uk \
    --cc=marc.zyngier@arm.com \
    --cc=mark.rutland@arm.com \
    --cc=matt@codeblueprint.co.uk \
    --cc=nico@linaro.org \
    --cc=thgarnie@google.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.