All of lore.kernel.org
 help / color / mirror / Atom feed
From: Kees Cook <kees@kernel.org>
To: York Jasper Niebuhr <yjn@yjn-systems.com>
Cc: linux-hardening@vger.kernel.org, franzen@sec.in.tum.de, ardb@kernel.org
Subject: Re: [RFC v3 0/5] Bootpatch-SLR: Randomizing Linux Kernel Structure Layouts at Boot
Date: Wed, 2 Sep 2026 17:43:23 -0700	[thread overview]
Message-ID: <202609021742.8BFCB34D5@keescook> (raw)
In-Reply-To: <20260720191146.21473-1-yjn@yjn-systems.com>

On Mon, Jul 20, 2026 at 09:11:46PM +0200, York Jasper Niebuhr wrote:
> At this stage, tooling is only available for x86_64. It is based on
> Linux 7.2-rc3. Bootpatch-SLR currently randomizes most of the
> task_struct. A few fields are exempt from randomization because of
> current implementation details (see v2 cover letter).

Another follow-up, FWIW, I was able to also get these randomized without
any problems I could find:


diff --git a/include/linux/binfmts.h b/include/linux/binfmts.h
index f686a37f7a0a..63ff19da1b73 100644
--- a/include/linux/binfmts.h
+++ b/include/linux/binfmts.h
@@ -84,7 +84,7 @@ struct linux_binprm {
 	struct rlimit rlim_stack; /* Saved RLIMIT_STACK used during exec. */
 
 	char buf[BINPRM_BUF_SIZE];
-} __randomize_layout;
+} __spslr __randomize_layout;
 
 #define BINPRM_FLAGS_ENFORCE_NONDUMP_BIT 0
 #define BINPRM_FLAGS_ENFORCE_NONDUMP (1 << BINPRM_FLAGS_ENFORCE_NONDUMP_BIT)
diff --git a/include/linux/blk_types.h b/include/linux/blk_types.h
index 98e21b4cbf32..8501724bcdf7 100644
--- a/include/linux/blk_types.h
+++ b/include/linux/blk_types.h
@@ -79,7 +79,7 @@ struct block_device {
 	 * path
 	 */
 	struct device		bd_device;
-} __randomize_layout;
+} __spslr __randomize_layout;
 
 #define bdev_whole(_bdev) \
 	((_bdev)->bd_disk->part0)
diff --git a/include/linux/cdev.h b/include/linux/cdev.h
index 0e8cd6293deb..fada1a021763 100644
--- a/include/linux/cdev.h
+++ b/include/linux/cdev.h
@@ -18,7 +18,7 @@ struct cdev {
 	struct list_head list;
 	dev_t dev;
 	unsigned int count;
-} __randomize_layout;
+} __spslr __randomize_layout;
 
 void cdev_init(struct cdev *, const struct file_operations *);
 
diff --git a/include/linux/cred.h b/include/linux/cred.h
index 6ef1750c93e2..bac502d6f481 100644
--- a/include/linux/cred.h
+++ b/include/linux/cred.h
@@ -148,7 +148,7 @@ struct cred {
 		int non_rcu;			/* Can we skip RCU deletion? */
 		struct rcu_head	rcu;		/* RCU deletion hook */
 	};
-} __randomize_layout;
+} __spslr __randomize_layout;
 
 extern void __put_cred(struct cred *);
 extern void exit_creds(struct task_struct *);
diff --git a/include/linux/fs.h b/include/linux/fs.h
index f9d1e05e8ae6..d9508cd2e40c 100644
--- a/include/linux/fs.h
+++ b/include/linux/fs.h
@@ -868,7 +868,7 @@ struct inode {
 #endif
 
 	void			*i_private; /* fs or device private pointer */
-} __randomize_layout;
+} __spslr __randomize_layout;
 
 /*
  * i_state handling
@@ -1292,7 +1292,7 @@ struct file {
 	};
 	file_ref_t			f_ref;
 	/* --- cacheline 3 boundary (192 bytes) --- */
-} __randomize_layout
+} __spslr __randomize_layout
   __attribute__((aligned(4)));	/* lest something weird decides that 2 is OK */
 
 struct file_handle {
diff --git a/include/linux/fs/super_types.h b/include/linux/fs/super_types.h
index ecd96aeb1cee..522e86f66f85 100644
--- a/include/linux/fs/super_types.h
+++ b/include/linux/fs/super_types.h
@@ -287,7 +287,7 @@ struct super_block {
 	 */
 	atomic_t				s_isw_nr_in_flight;
 #endif
-} __randomize_layout;
+} __spslr __randomize_layout;
 
 /*
  * sb->s_flags.  Note that these mirror the equivalent MS_* flags where
diff --git a/include/linux/mount.h b/include/linux/mount.h
index acfe7ef86a1b..3675f7ba31f9 100644
--- a/include/linux/mount.h
+++ b/include/linux/mount.h
@@ -60,7 +60,7 @@ struct vfsmount {
 	struct super_block *mnt_sb;	/* pointer to superblock */
 	int mnt_flags;
 	struct mnt_idmap *mnt_idmap;
-} __randomize_layout;
+} __spslr __randomize_layout;
 
 static inline struct mnt_idmap *mnt_idmap(const struct vfsmount *mnt)
 {
diff --git a/include/linux/tty.h b/include/linux/tty.h
index 0a46e4054dec..d726df308f11 100644
--- a/include/linux/tty.h
+++ b/include/linux/tty.h
@@ -240,7 +240,7 @@ struct tty_struct {
 	struct list_head tty_files;
 
 	struct work_struct SAK_work;
-} __randomize_layout;
+} __spslr __randomize_layout;
 
 /* Each of a tty's open files has private_data pointing to tty_file_private */
 struct tty_file_private {

-- 
Kees Cook

  parent reply	other threads:[~2026-09-03  0:43 UTC|newest]

Thread overview: 15+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-07-20 19:11 [RFC v3 0/5] Bootpatch-SLR: Randomizing Linux Kernel Structure Layouts at Boot York Jasper Niebuhr
2026-07-20 19:12 ` [RFC v3 1/5] Pinpoint plugin York Jasper Niebuhr
2026-07-21  5:45   ` Greg KH
2026-07-21 19:31   ` York Jasper Niebuhr
2026-07-20 19:12 ` [RFC v3 2/5] Selfpatch runtime York Jasper Niebuhr
2026-07-21 19:33   ` York Jasper Niebuhr
2026-07-20 19:13 ` [RFC v3 3/5] SPSLR build integration York Jasper Niebuhr
2026-07-21 19:34   ` York Jasper Niebuhr
2026-07-20 19:13 ` [RFC v3 4/5] SPSLR and Sanemaker source integration York Jasper Niebuhr
2026-07-21 19:34   ` York Jasper Niebuhr
2026-07-20 19:13 ` [RFC v3 5/5] Tasklist sample module York Jasper Niebuhr
2026-07-21 19:35   ` York Jasper Niebuhr
2026-09-03  0:43 ` Kees Cook [this message]
2026-09-03 10:28 ` [RFC v3 0/5] Bootpatch-SLR: Randomizing Linux Kernel Structure Layouts at Boot Ard Biesheuvel
2026-09-10 14:01   ` Jasper Niebuhr

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=202609021742.8BFCB34D5@keescook \
    --to=kees@kernel.org \
    --cc=ardb@kernel.org \
    --cc=franzen@sec.in.tum.de \
    --cc=linux-hardening@vger.kernel.org \
    --cc=yjn@yjn-systems.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.