From: Pratyush Anand <panand@redhat.com>
To: Kees Cook <keescook@chromium.org>
Cc: Baoquan He <bhe@redhat.com>,
Kexec Mailing List <kexec@lists.infradead.org>,
open list <linux-kernel@vger.kernel.org>,
Dave Anderson <anderson@redhat.com>,
Andrew Morton <akpm@linux-foundation.org>,
Dave Young <dyoung@redhat.com>
Subject: Re: [PATCH] /proc/kcore: Update physical address for kcore ram and text
Date: Tue, 14 Feb 2017 07:16:22 +0530 [thread overview]
Message-ID: <5b28ea05-24ab-b8db-e3d1-216399734297@redhat.com> (raw)
In-Reply-To: <CAGXu5jL89e33t0g+iVm8o7sstn3B9QCiFP_AhxZj8QiyaTjNZw@mail.gmail.com>
On Tuesday 14 February 2017 03:55 AM, Kees Cook wrote:
> On Mon, Jan 30, 2017 at 11:00 AM, Pratyush Anand <panand@redhat.com> wrote:
>> CCing Andrew and Kees for their review comments.
>>
>>
>> On Wednesday 25 January 2017 10:14 AM, Pratyush Anand wrote:
>>> Currently all the p_paddr of PT_LOAD headers are assigned to 0, which is
>>> not true and could be misleading, since 0 is a valid physical address.
>>>
>>> User space tools like makedumpfile needs to know physical address for
>>> PT_LOAD segments of direct mapped regions. Therefore this patch updates
>>> paddr for such regions. It also sets an invalid paddr (-1) for other
>>> regions, so that user space tool can know whether a physical address
>>> provided in PT_LOAD is correct or not.
>>>
>>> Signed-off-by: Pratyush Anand <panand@redhat.com>
>>> ---
>>> fs/proc/kcore.c | 5 ++++-
>>> 1 file changed, 4 insertions(+), 1 deletion(-)
>>>
>>> diff --git a/fs/proc/kcore.c b/fs/proc/kcore.c
>>> index 0b80ad87b4d6..ea9f3d1ae830 100644
>>> --- a/fs/proc/kcore.c
>>> +++ b/fs/proc/kcore.c
>>> @@ -373,7 +373,10 @@ static void elf_kcore_store_hdr(char *bufp, int
>>> nphdr, int dataoff)
>>> phdr->p_flags = PF_R|PF_W|PF_X;
>>> phdr->p_offset = kc_vaddr_to_offset(m->addr) + dataoff;
>>> phdr->p_vaddr = (size_t)m->addr;
>>> - phdr->p_paddr = 0;
>>> + if (m->type == KCORE_RAM || m->type == KCORE_TEXT)
>>> + phdr->p_paddr = __pa(m->addr);
>>> + else
>>> + phdr->p_paddr = (elf_addr_t)-1;
>>> phdr->p_filesz = phdr->p_memsz = m->size;
>>> phdr->p_align = PAGE_SIZE;
>>> }
>>>
>
> Well, CONFIG_PROC_KCORE is a generalized root KASLR exposure (though
> there are lots of such exposures). Why is the actual physical address
> needed? Can this just report the virtual address instead? Then the
> tool can build a map, but it looks like an identity map, rather than
> creating a new physical/virtual memory ASLR offset exposure?
Well, having an ASLR offset information can help to translate an
identity mapped virtual address to a physical address. But that would be
an additional field in PT_LOAD header structure and an arch dependent value.
Moreover, sending a valid physical address like 0 does not seem right.
So, IMHO it is better to fix that and send valid physical address when
available (identity mapped).
Thanks for the review.
~Pratyush
_______________________________________________
kexec mailing list
kexec@lists.infradead.org
http://lists.infradead.org/mailman/listinfo/kexec
next prev parent reply other threads:[~2017-02-14 1:46 UTC|newest]
Thread overview: 7+ messages / expand[flat|nested] mbox.gz Atom feed top
2017-01-25 4:44 [PATCH] /proc/kcore: Update physical address for kcore ram and text Pratyush Anand
2017-01-25 6:29 ` Dave Young
2017-01-25 6:51 ` Pratyush Anand
[not found] ` <CAHB_GupwpXiZjmy+4SQLvoJaJkAo9VvNVxQgxqvXeACRR--exg@mail.gmail.com>
2017-02-13 22:25 ` Kees Cook
2017-02-14 1:46 ` Pratyush Anand [this message]
2017-02-24 7:20 ` Pratyush Anand
2017-02-24 7:39 ` Baoquan He
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=5b28ea05-24ab-b8db-e3d1-216399734297@redhat.com \
--to=panand@redhat.com \
--cc=akpm@linux-foundation.org \
--cc=anderson@redhat.com \
--cc=bhe@redhat.com \
--cc=dyoung@redhat.com \
--cc=keescook@chromium.org \
--cc=kexec@lists.infradead.org \
--cc=linux-kernel@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox