From: Ard Biesheuvel <ardb+git@google.com>
To: linux-kernel@vger.kernel.org
Cc: x86@kernel.org, Ard Biesheuvel <ardb@kernel.org>,
Tom Lendacky <thomas.lendacky@amd.com>,
Thomas Gleixner <tglx@linutronix.de>,
Ingo Molnar <mingo@redhat.com>, Borislav Petkov <bp@alien8.de>,
Dave Hansen <dave.hansen@linux.intel.com>,
Andy Lutomirski <luto@kernel.org>, Arnd Bergmann <arnd@arndb.de>,
Kees Cook <keescook@chromium.org>,
Brian Gerst <brgerst@gmail.com>
Subject: [PATCH v2 0/4] x86: Rid .head.text of all abs references
Date: Thu, 25 Apr 2024 14:04:17 +0200 [thread overview]
Message-ID: <20240425120416.2041037-6-ardb+git@google.com> (raw)
From: Ard Biesheuvel <ardb@kernel.org>
Questions below!
This series removes the last remaining absolute symbol references from
.head.text. Doing so is necessary because code in this section may be
called from a 1:1 mapping of memory, which deviates from the mapping
this code was linked and/or relocated to run at. This is not something
that the toolchains support: even PIC/PIE code is still assumed to
execute from the same mapping that it was relocated to run from by the
startup code or dynamic loader. This means we are basically on our own
here, and need to add measures to ensure the code works as expected in
this manner.
Given that the startup code needs to create the kernel virtual mapping
in the page tables, early references to some kernel virtual addresses
are valid even if they cannot be dereferenced yet. To avoid having to
make this distinction at build time, patches #3 and #4 replace such
valid references with RIP-relative references with an offset applied.
Patches #1 and #2 remove some absolute references from .head.text that
don't need to be there in the first place.
Questions:
- How can we police this at build time? Could we teach objtool to check
for absolute ELF relocations in .head.text, or does this belong in
modpost perhaps?
- Checking for absolute symbol references is not a complete solution, as
.head.text code could call into other code as well. Do we need rigid
checks for that too? Or could we have a soft rule that says you should
only call __head code from __head code?
Changes since v1/RFC:
- rename va_offset to p2v_offset
- take PA of _text in C code directly
Cc: Tom Lendacky <thomas.lendacky@amd.com>
Cc: Thomas Gleixner <tglx@linutronix.de>
Cc: Ingo Molnar <mingo@redhat.com>
Cc: Borislav Petkov <bp@alien8.de>
Cc: Dave Hansen <dave.hansen@linux.intel.com>
Cc: Andy Lutomirski <luto@kernel.org>
Cc: Arnd Bergmann <arnd@arndb.de>
Cc: Kees Cook <keescook@chromium.org>
Cc: Brian Gerst <brgerst@gmail.com>
Ard Biesheuvel (4):
x86/sev: Avoid WARN()s in early boot code
x86/xen/pvh: Move startup code into .ref.text
x86/boot/64: Determine VA/PA offset before entering C code
x86/boot/64: Avoid intentional absolute symbol references in
.head.text
arch/x86/include/asm/setup.h | 2 +-
arch/x86/kernel/head64.c | 38 ++++++++++++--------
arch/x86/kernel/head_64.S | 9 ++++-
arch/x86/kernel/sev.c | 15 +++-----
arch/x86/platform/pvh/head.S | 2 +-
5 files changed, 38 insertions(+), 28 deletions(-)
--
2.44.0.769.g3c40516874-goog
next reply other threads:[~2024-04-25 12:04 UTC|newest]
Thread overview: 5+ messages / expand[flat|nested] mbox.gz Atom feed top
2024-04-25 12:04 Ard Biesheuvel [this message]
2024-04-25 12:04 ` [PATCH v2 1/4] x86/sev: Avoid WARN()s in early boot code Ard Biesheuvel
2024-04-25 12:04 ` [PATCH v2 2/4] x86/xen/pvh: Move startup code into .ref.text Ard Biesheuvel
2024-04-25 12:04 ` [PATCH v2 3/4] x86/boot/64: Determine VA/PA offset before entering C code Ard Biesheuvel
2024-04-25 12:04 ` [PATCH v2 4/4] x86/boot/64: Avoid intentional absolute symbol references in .head.text Ard Biesheuvel
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20240425120416.2041037-6-ardb+git@google.com \
--to=ardb+git@google.com \
--cc=ardb@kernel.org \
--cc=arnd@arndb.de \
--cc=bp@alien8.de \
--cc=brgerst@gmail.com \
--cc=dave.hansen@linux.intel.com \
--cc=keescook@chromium.org \
--cc=linux-kernel@vger.kernel.org \
--cc=luto@kernel.org \
--cc=mingo@redhat.com \
--cc=tglx@linutronix.de \
--cc=thomas.lendacky@amd.com \
--cc=x86@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.