From: Jan Beulich <jbeulich@suse.com>
To: Alejandro Vallejo <alejandro.vallejo@cloud.com>,
Frediano Ziglio <frediano.ziglio@cloud.com>
Cc: "Andrew Cooper" <andrew.cooper3@citrix.com>,
"Roger Pau Monné" <roger.pau@citrix.com>,
Xen-devel <xen-devel@lists.xenproject.org>
Subject: Re: [PATCH 1/5] x86: Put trampoline in .init.data section
Date: Thu, 8 Aug 2024 09:34:12 +0200 [thread overview]
Message-ID: <ad72cc97-b9dd-4e7e-93f6-333805e40785@suse.com> (raw)
In-Reply-To: <20240807134819.8987-2-alejandro.vallejo@cloud.com>
On 07.08.2024 15:48, Alejandro Vallejo wrote:
> This change allows to put the trampoline in a separate, not executable
> section. The trampoline contains a mix of code and data (data which
> is modified from C code during early start so must be writable).
> This is in preparation for W^X patch in order to satisfy UEFI CA
> memory mitigation requirements.
Which, aiui, has the downside of disassembly of the section no longer
happening by default, when using objdump or similar tools, which go from
section attributes. Why is it being in .init.text (and hence RX) not
appropriate? It should - in principle at least - be possible to avoid
all in-place writing to it, but instead only ever write to its relocated
copy. Quite a bit more code churn of course.
I wonder if we shouldn't put the trampoline in its own section, RWX in
the object file, and switched to whatever appropriate in the binary
(which really may be RX, not RW).
> --- a/xen/arch/x86/boot/head.S
> +++ b/xen/arch/x86/boot/head.S
> @@ -870,6 +870,8 @@ cmdline_parse_early:
> reloc:
> .incbin "reloc.bin"
>
> + .section .init.data, "aw", @progbits
> + .align 4
Is the .align really needed here? I think ...
> ENTRY(trampoline_start)
... ENTRY() covers this properly? And actually in a better way, using
CODE_FILL (which ultimately we will want to switch from 0x90 to 0xcc, I
suppose) rather than whatever the assembler puts in by default for data
sections.
Jan
> #include "trampoline.S"
> ENTRY(trampoline_end)
next prev parent reply other threads:[~2024-08-08 7:34 UTC|newest]
Thread overview: 29+ messages / expand[flat|nested] mbox.gz Atom feed top
2024-08-07 13:48 [PATCH 0/5] Improve support for EFI multiboot loading Alejandro Vallejo
2024-08-07 13:48 ` [PATCH 1/5] x86: Put trampoline in .init.data section Alejandro Vallejo
2024-08-08 7:34 ` Jan Beulich [this message]
[not found] ` <CACHz=Zh7wK58mbB762fnevHEKW9qhp-NRJ6buNe1b-qLxP0qPg@mail.gmail.com>
[not found] ` <b9b40658-ff13-4240-98a2-4811411e31b6@suse.com>
2024-08-08 13:05 ` Frediano Ziglio
2024-08-19 14:16 ` Frediano Ziglio
2024-08-19 14:29 ` Jan Beulich
2024-08-19 15:30 ` Frediano Ziglio
2024-08-19 15:50 ` Jan Beulich
2024-08-27 14:56 ` Frediano Ziglio
2024-08-27 15:55 ` Jan Beulich
2024-08-07 13:48 ` [PATCH 2/5] x86: Fix early output messages in case of EFI Alejandro Vallejo
2024-08-08 7:49 ` Jan Beulich
[not found] ` <CACHz=ZjYdBcB_S1tpXpuRQDKGAKY=SrgTEy8_0Wyq_q+bOBfHg@mail.gmail.com>
2024-08-08 9:29 ` Jan Beulich
[not found] ` <CACHz=ZgRK2DMHmiAVsBo1WJVBxbnTka3-CcpgopKB-6gWs5ZSw@mail.gmail.com>
2024-08-08 12:58 ` Jan Beulich
2024-08-08 13:17 ` Frediano Ziglio
2024-08-08 14:04 ` Jan Beulich
2024-08-07 13:48 ` [PATCH 3/5] x86: Set xen_phys_start and trampoline_xen_phys_start earlier Alejandro Vallejo
2024-08-08 8:25 ` Jan Beulich
2024-08-09 12:48 ` Frediano Ziglio
2024-08-09 12:59 ` Jan Beulich
2024-08-09 13:50 ` Frediano Ziglio
2024-08-09 14:02 ` Jan Beulich
2024-08-09 14:34 ` Frediano Ziglio
2024-08-12 8:41 ` Jan Beulich
2024-08-12 12:42 ` Frediano Ziglio
2024-08-07 13:48 ` [PATCH 4/5] x86: Force proper gdt_boot_base setting Alejandro Vallejo
2024-08-08 9:58 ` Jan Beulich
2024-08-07 13:48 ` [PATCH 5/5] x86: Rollback relocation in case of EFI multiboot Alejandro Vallejo
2024-08-08 10:36 ` Jan Beulich
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=ad72cc97-b9dd-4e7e-93f6-333805e40785@suse.com \
--to=jbeulich@suse.com \
--cc=alejandro.vallejo@cloud.com \
--cc=andrew.cooper3@citrix.com \
--cc=frediano.ziglio@cloud.com \
--cc=roger.pau@citrix.com \
--cc=xen-devel@lists.xenproject.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.