From: Coiby Xu <coxu@redhat.com>
To: kexec@lists.infradead.org
Cc: "maintainer:X86 ARCHITECTURE 32-BIT AND 64-BIT" <x86@kernel.org>,
"H. Peter Anvin" <hpa@zytor.com>, Baoquan He <bhe@redhat.com>,
Dave Hansen <dave.hansen@linux.intel.com>,
dm-devel@redhat.com, Pingfan Liu <kernelfans@gmail.com>,
linux-kernel@vger.kernel.org, Kairui Song <ryncsn@gmail.com>,
Ingo Molnar <mingo@redhat.com>, Borislav Petkov <bp@alien8.de>,
Jan Pazdziora <jpazdziora@redhat.com>,
Thomas Staudt <tstaudt@de.ibm.com>,
Thomas Gleixner <tglx@linutronix.de>,
Dave Young <dyoung@redhat.com>, Milan Broz <gmazyland@gmail.com>
Subject: [dm-devel] [RFC v2 4/5] x86/crash: make the page that stores the LUKS volume key inaccessible
Date: Fri, 4 Nov 2022 19:29:59 +0800 [thread overview]
Message-ID: <20221104113000.487098-5-coxu@redhat.com> (raw)
In-Reply-To: <20221104113000.487098-1-coxu@redhat.com>
This adds an addition layer of protection for the saved copy of LUKS
volume key. Trying to access the saved copy will cause page fault.
Suggested-by: Pingfan Liu <kernelfans@gmail.com>
Signed-off-by: Coiby Xu <coxu@redhat.com>
---
arch/x86/kernel/machine_kexec_64.c | 16 ++++++++++++++++
1 file changed, 16 insertions(+)
diff --git a/arch/x86/kernel/machine_kexec_64.c b/arch/x86/kernel/machine_kexec_64.c
index 0611fd83858e..f3d51c38a1c9 100644
--- a/arch/x86/kernel/machine_kexec_64.c
+++ b/arch/x86/kernel/machine_kexec_64.c
@@ -557,9 +557,25 @@ static void kexec_mark_crashkres(bool protect)
kexec_mark_range(control, crashk_res.end, protect);
}
+static void kexec_mark_luks_volume_key_inaccessible(void)
+{
+ unsigned long start, end;
+ struct page *page;
+ unsigned int nr_pages;
+
+ if (kexec_crash_image->luks_volume_key_addr) {
+ start = kexec_crash_image->luks_volume_key_addr;
+ end = start + kexec_crash_image->luks_volume_key_sz - 1;
+ page = pfn_to_page(start >> PAGE_SHIFT);
+ nr_pages = (end >> PAGE_SHIFT) - (start >> PAGE_SHIFT) + 1;
+ set_memory_np((unsigned long)page_address(page), nr_pages);
+ }
+}
+
void arch_kexec_protect_crashkres(void)
{
kexec_mark_crashkres(true);
+ kexec_mark_luks_volume_key_inaccessible();
}
void arch_kexec_unprotect_crashkres(void)
--
2.37.3
--
dm-devel mailing list
dm-devel@redhat.com
https://listman.redhat.com/mailman/listinfo/dm-devel
WARNING: multiple messages have this Message-ID (diff)
From: Coiby Xu <coxu@redhat.com>
To: kexec@lists.infradead.org
Cc: Milan Broz <gmazyland@gmail.com>,
Thomas Staudt <tstaudt@de.ibm.com>,
Kairui Song <ryncsn@gmail.com>,
dm-devel@redhat.com, Jan Pazdziora <jpazdziora@redhat.com>,
Pingfan Liu <kernelfans@gmail.com>, Baoquan He <bhe@redhat.com>,
Dave Young <dyoung@redhat.com>,
linux-kernel@vger.kernel.org,
Thomas Gleixner <tglx@linutronix.de>,
Ingo Molnar <mingo@redhat.com>, Borislav Petkov <bp@alien8.de>,
Dave Hansen <dave.hansen@linux.intel.com>,
x86@kernel.org (maintainer:X86 ARCHITECTURE (32-BIT AND 64-BIT)),
"H. Peter Anvin" <hpa@zytor.com>
Subject: [RFC v2 4/5] x86/crash: make the page that stores the LUKS volume key inaccessible
Date: Fri, 4 Nov 2022 19:29:59 +0800 [thread overview]
Message-ID: <20221104113000.487098-5-coxu@redhat.com> (raw)
In-Reply-To: <20221104113000.487098-1-coxu@redhat.com>
This adds an addition layer of protection for the saved copy of LUKS
volume key. Trying to access the saved copy will cause page fault.
Suggested-by: Pingfan Liu <kernelfans@gmail.com>
Signed-off-by: Coiby Xu <coxu@redhat.com>
---
arch/x86/kernel/machine_kexec_64.c | 16 ++++++++++++++++
1 file changed, 16 insertions(+)
diff --git a/arch/x86/kernel/machine_kexec_64.c b/arch/x86/kernel/machine_kexec_64.c
index 0611fd83858e..f3d51c38a1c9 100644
--- a/arch/x86/kernel/machine_kexec_64.c
+++ b/arch/x86/kernel/machine_kexec_64.c
@@ -557,9 +557,25 @@ static void kexec_mark_crashkres(bool protect)
kexec_mark_range(control, crashk_res.end, protect);
}
+static void kexec_mark_luks_volume_key_inaccessible(void)
+{
+ unsigned long start, end;
+ struct page *page;
+ unsigned int nr_pages;
+
+ if (kexec_crash_image->luks_volume_key_addr) {
+ start = kexec_crash_image->luks_volume_key_addr;
+ end = start + kexec_crash_image->luks_volume_key_sz - 1;
+ page = pfn_to_page(start >> PAGE_SHIFT);
+ nr_pages = (end >> PAGE_SHIFT) - (start >> PAGE_SHIFT) + 1;
+ set_memory_np((unsigned long)page_address(page), nr_pages);
+ }
+}
+
void arch_kexec_protect_crashkres(void)
{
kexec_mark_crashkres(true);
+ kexec_mark_luks_volume_key_inaccessible();
}
void arch_kexec_unprotect_crashkres(void)
--
2.37.3
_______________________________________________
kexec mailing list
kexec@lists.infradead.org
http://lists.infradead.org/mailman/listinfo/kexec
WARNING: multiple messages have this Message-ID (diff)
From: Coiby Xu <coxu@redhat.com>
To: kexec@lists.infradead.org
Cc: Milan Broz <gmazyland@gmail.com>,
Thomas Staudt <tstaudt@de.ibm.com>,
Kairui Song <ryncsn@gmail.com>,
dm-devel@redhat.com, Jan Pazdziora <jpazdziora@redhat.com>,
Pingfan Liu <kernelfans@gmail.com>, Baoquan He <bhe@redhat.com>,
Dave Young <dyoung@redhat.com>,
linux-kernel@vger.kernel.org,
Thomas Gleixner <tglx@linutronix.de>,
Ingo Molnar <mingo@redhat.com>, Borislav Petkov <bp@alien8.de>,
Dave Hansen <dave.hansen@linux.intel.com>,
x86@kernel.org (maintainer:X86 ARCHITECTURE (32-BIT AND 64-BIT)),
"H. Peter Anvin" <hpa@zytor.com>
Subject: [RFC v2 4/5] x86/crash: make the page that stores the LUKS volume key inaccessible
Date: Fri, 4 Nov 2022 19:29:59 +0800 [thread overview]
Message-ID: <20221104113000.487098-5-coxu@redhat.com> (raw)
In-Reply-To: <20221104113000.487098-1-coxu@redhat.com>
This adds an addition layer of protection for the saved copy of LUKS
volume key. Trying to access the saved copy will cause page fault.
Suggested-by: Pingfan Liu <kernelfans@gmail.com>
Signed-off-by: Coiby Xu <coxu@redhat.com>
---
arch/x86/kernel/machine_kexec_64.c | 16 ++++++++++++++++
1 file changed, 16 insertions(+)
diff --git a/arch/x86/kernel/machine_kexec_64.c b/arch/x86/kernel/machine_kexec_64.c
index 0611fd83858e..f3d51c38a1c9 100644
--- a/arch/x86/kernel/machine_kexec_64.c
+++ b/arch/x86/kernel/machine_kexec_64.c
@@ -557,9 +557,25 @@ static void kexec_mark_crashkres(bool protect)
kexec_mark_range(control, crashk_res.end, protect);
}
+static void kexec_mark_luks_volume_key_inaccessible(void)
+{
+ unsigned long start, end;
+ struct page *page;
+ unsigned int nr_pages;
+
+ if (kexec_crash_image->luks_volume_key_addr) {
+ start = kexec_crash_image->luks_volume_key_addr;
+ end = start + kexec_crash_image->luks_volume_key_sz - 1;
+ page = pfn_to_page(start >> PAGE_SHIFT);
+ nr_pages = (end >> PAGE_SHIFT) - (start >> PAGE_SHIFT) + 1;
+ set_memory_np((unsigned long)page_address(page), nr_pages);
+ }
+}
+
void arch_kexec_protect_crashkres(void)
{
kexec_mark_crashkres(true);
+ kexec_mark_luks_volume_key_inaccessible();
}
void arch_kexec_unprotect_crashkres(void)
--
2.37.3
next prev parent reply other threads:[~2022-11-07 8:40 UTC|newest]
Thread overview: 27+ messages / expand[flat|nested] mbox.gz Atom feed top
2022-11-04 11:29 [dm-devel] [RFC v2 0/5] Support kdump with LUKS encryption by reusing LUKS volume key Coiby Xu
2022-11-04 11:29 ` Coiby Xu
2022-11-04 11:29 ` Coiby Xu
2022-11-04 11:29 ` [dm-devel] [RFC v2 1/5] kexec_file: allow to place kexec_buf randomly Coiby Xu
2022-11-04 11:29 ` Coiby Xu
2022-11-04 11:29 ` Coiby Xu
2022-11-04 11:29 ` [dm-devel] [RFC v2 2/5] crash_dump: save the LUKS volume key temporarily Coiby Xu
2022-11-04 11:29 ` Coiby Xu
2022-11-04 11:29 ` Coiby Xu
2022-11-04 11:29 ` [dm-devel] [RFC v2 3/5] x86/crash: pass the LUKS volume key to kdump kernel Coiby Xu
2022-11-04 11:29 ` Coiby Xu
2022-11-04 11:29 ` Coiby Xu
2022-11-04 11:29 ` Coiby Xu [this message]
2022-11-04 11:29 ` [RFC v2 4/5] x86/crash: make the page that stores the LUKS volume key inaccessible Coiby Xu
2022-11-04 11:29 ` Coiby Xu
2022-11-04 14:38 ` [dm-devel] " Dave Hansen
2022-11-04 14:38 ` Dave Hansen
2022-11-04 14:38 ` Dave Hansen
2022-11-07 11:20 ` [dm-devel] " Coiby Xu
2022-11-07 11:20 ` Coiby Xu
2022-11-07 11:20 ` Coiby Xu
2022-11-04 11:30 ` [dm-devel] [RFC v2 5/5] crash_dump: retrieve LUKS volume key in kdump kernel Coiby Xu
2022-11-04 11:30 ` Coiby Xu
2022-11-04 11:30 ` Coiby Xu
2023-02-01 8:18 ` [dm-devel] [RFC v2 0/5] Support kdump with LUKS encryption by reusing LUKS volume key Baoquan He
2023-02-01 8:18 ` Baoquan He
2023-02-01 8:18 ` Baoquan He
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20221104113000.487098-5-coxu@redhat.com \
--to=coxu@redhat.com \
--cc=bhe@redhat.com \
--cc=bp@alien8.de \
--cc=dave.hansen@linux.intel.com \
--cc=dm-devel@redhat.com \
--cc=dyoung@redhat.com \
--cc=gmazyland@gmail.com \
--cc=hpa@zytor.com \
--cc=jpazdziora@redhat.com \
--cc=kernelfans@gmail.com \
--cc=kexec@lists.infradead.org \
--cc=linux-kernel@vger.kernel.org \
--cc=mingo@redhat.com \
--cc=ryncsn@gmail.com \
--cc=tglx@linutronix.de \
--cc=tstaudt@de.ibm.com \
--cc=x86@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.