From: Evgeniy Baskov <baskov@ispras.ru>
To: "Limonciello, Mario" <mario.limonciello@amd.com>
Cc: Ard Biesheuvel <ardb@kernel.org>, Peter Jones <pjones@redhat.com>,
Borislav Petkov <bp@alien8.de>, Andy Lutomirski <luto@kernel.org>,
Dave Hansen <dave.hansen@linux.intel.com>,
Ingo Molnar <mingo@redhat.com>,
Peter Zijlstra <peterz@infradead.org>,
Thomas Gleixner <tglx@linutronix.de>,
Alexey Khoroshilov <khoroshilov@ispras.ru>,
lvc-project@linuxtesting.org, x86@kernel.org,
linux-efi@vger.kernel.org, linux-kernel@vger.kernel.org,
linux-hardening@vger.kernel.org
Subject: Re: [PATCH v2 00/23] x86_64: Improvements at compressed kernel stage
Date: Wed, 09 Nov 2022 02:49:08 +0300 [thread overview]
Message-ID: <4a942ab07fd320ba9a058c8a112503bd@ispras.ru> (raw)
In-Reply-To: <fc262405-451e-3842-9b08-bc36614e810a@amd.com>
On 2022-11-08 21:17, Limonciello, Mario wrote:
> On 11/8/2022 01:01, Evgeniy Baskov wrote:
>> On 2022-11-04 21:21, Limonciello, Mario wrote:
>>> On 10/25/2022 09:12, Evgeniy Baskov wrote:
>>>> ...
>>>>
>>>
>>> Hi,
>>>
>>> I was talking to Peter Jones recently about what was still missing
>>> for
>>> NX support in the kernel and he pointed me at this series.
>>>
>>> So I had a try with this series on top of:
>>>
>>> ee6050c8af96 ("Merge tag 'ata-6.1-rc4' of
>>> git://git.kernel.org/pub/scm/linux/kernel/git/dlemoal/libata")
>>>
>>> Unfortunately I can't boot the system with this series applied.
>>> This is not on a system that enforces NX pre-boot (but that was my
>>> goal after I could prove booting on something that doesn't).
>>> I didn't apply Peter's patch 6 you referenced in your cover letter,
>>> but I don't expect that's the reason for the failure.
>>>
>>> I get:
>>>
>>> "Failed to allocate space for tmp_cmdline"
>>>
>>> -- System Halted
>>>
>>> This is early enough [1] that I don't have anything else output to a
>>> serial log from the kernel.
>>>
>>> https://nam11.safelinks.protection.outlook.com/?url=https%3A%2F%2Fgithub.com%2Ftorvalds%2Flinux%2Fblob%2Fd4013bc4d49f6da8178a340348369bb9920225c9%2Farch%2Fx86%2Fboot%2Fcompressed%2Fkaslr.c%23L268&data=05%7C01%7Cmario.limonciello%40amd.com%7C9280e92e85bc4e2b52cd08dac15704a5%7C3dd8961fe4884e608e11a82d994e183d%7C0%7C0%7C638034876740462327%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&sdata=oiCJUa8M3x%2FYCxVjJj98R7iU%2FzIj%2FQxdVOWbnqGWCNI%3D&reserved=0
>>>
>>> Since this is only in the kaslr path, I tried to turn that off with
>>> 'nokaslr' on the kernel command line.
>>>
>>> I then get a failure of:
>>>
>>> "Out of memory while allocating zstd_dctx"
>>>
>>> -- System Halted
>>>
>>> This kernel was booted from the following path:
>>> -> Insyde BIOS
>>> --> shim (from Fedora 36 repository)
>>> ---> GRUB (from Peter for Fedora 36 w/ some level NX support)
>>> ----> kernel binary (self-built)
>>>
>>> The BIOS on this system doesn't validate NX, but also the shim binary
>>> did not have the NX bit set in the PE header.
>>>
>>> Your cover letter referenced CONFIG_EFI_STUB_EXTRACT_DIRECT but I
>>> didn't find this option in the series. I also tried both with
>>> CONFIG_EFI_DXE_MEM_ATTRIBUTES=y or unset, same result.
>>
>> Hi,
>>
>> Thanks for your feedback!
>>
>
> Sure!
>
>> CONFIG_EFI_STUB_EXTRACT_DIRECT option was removed in v2 of the series
>> and direct extraction is unconditional now.
>>
>> You are getting really weird errors, which unfortunately I am unable
>> to reproduce yet. I've tried booting with fedora's grub and the series
>> applied on top of ee6050c8af96, but it did boot successfully.
>
> Well so I expect the unique difference is that I'm using Peter's GRUB
> that has some NX support landed. He has binaries for it here:
>
> https://blog.uncooperative.org/~pjones/nx/repo/
>
> *Theoretically* a BIOS that enforces NX should be able to boot a shim
> with
> the NX compat bit set which should be able to boot that GRUB
> supporting NX which should be able to boot this series.
>
>>
>> From the error messages it's some problem with malloc()
>> implementation
>> of compressed kernel code. I suspect that malloc_ptr inside .bss is
>> not
>> zeroed. This should not happen when booting via either non-UEFI
>> interface, or via UEFI (when kernel is properly loaded as PE image).
>> The problem, I think, arises when kernel is loaded as a blob, but EFI
>> handover protocol is used to start its execution. This is what grub
>> seems to be doing.
>>
>> Can you please try booting with patches below applied on top?
>> If this fixes the problem, I'll include these changes in v3.
>
> Yup, spot on. I can the kernel from Peter's NX enabled GRUB now with:
> * 6.1-rc4
> * Your existing 23 patch series
> * this new patch
>
> Thanks!!
>
> Would you mind CC me when you submit v3? As I have an interest in
> seeing NX support I'd like to continue to follow along on the series.
Ok.
>
> Anything in the series you don't change in any material way from v2
> please feel free to include:
>
> Tested-by: Mario Limonciello <mario.limonciello@amd.com>
>
Great, thanks!
next prev parent reply other threads:[~2022-11-08 23:49 UTC|newest]
Thread overview: 31+ messages / expand[flat|nested] mbox.gz Atom feed top
2022-10-25 14:12 [PATCH v2 00/23] x86_64: Improvements at compressed kernel stage Evgeniy Baskov
2022-10-25 14:12 ` [PATCH v2 01/23] x86/boot: Align vmlinuz sections on page size Evgeniy Baskov
2022-10-25 14:12 ` [PATCH v2 02/23] x86/build: Remove RWX sections and align on 4KB Evgeniy Baskov
2022-10-25 14:12 ` [PATCH v2 03/23] x86/boot: Set cr0 to known state in trampoline Evgeniy Baskov
2022-10-25 14:12 ` [PATCH v2 04/23] x86/boot: Increase boot page table size Evgeniy Baskov
2022-10-25 14:12 ` [PATCH v2 05/23] x86/boot: Support 4KB pages for identity mapping Evgeniy Baskov
2022-10-25 14:12 ` [PATCH v2 06/23] x86/boot: Setup memory protection for bzImage code Evgeniy Baskov
2022-10-25 14:12 ` [PATCH v2 07/23] x86/build: Check W^X of vmlinux during build Evgeniy Baskov
2022-10-25 14:12 ` [PATCH v2 08/23] x86/boot: Map memory explicitly Evgeniy Baskov
2022-10-25 14:12 ` [PATCH v2 09/23] x86/boot: Remove mapping from page fault handler Evgeniy Baskov
2022-10-25 14:12 ` [PATCH v2 10/23] efi/libstub: Move helper function to related file Evgeniy Baskov
2022-10-25 14:12 ` [PATCH v2 11/23] x86/boot: Make console interface more abstract Evgeniy Baskov
2022-10-25 14:12 ` [PATCH v2 12/23] x86/boot: Make kernel_add_identity_map() a pointer Evgeniy Baskov
2022-10-25 14:12 ` [PATCH v2 13/23] x86/boot: Split trampoline and pt init code Evgeniy Baskov
2022-10-25 14:12 ` [PATCH v2 14/23] x86/boot: Add EFI kernel extraction interface Evgeniy Baskov
2022-10-25 14:12 ` [PATCH v2 15/23] efi/x86: Support extracting kernel from libstub Evgeniy Baskov
2022-10-25 14:12 ` [PATCH v2 16/23] x86/boot: Reduce lower limit of physical KASLR Evgeniy Baskov
2022-10-25 14:12 ` [PATCH v2 17/23] x86/boot: Reduce size of the DOS stub Evgeniy Baskov
2022-10-25 14:12 ` [PATCH v2 18/23] tools/include: Add simplified version of pe.h Evgeniy Baskov
2022-10-25 14:12 ` [PATCH v2 19/23] x86/build: Cleanup tools/build.c Evgeniy Baskov
2022-10-25 14:12 ` [PATCH v2 20/23] x86/build: Make generated PE more spec compliant Evgeniy Baskov
2022-10-25 14:12 ` [PATCH v2 21/23] efi/x86: Explicitly set sections memory attributes Evgeniy Baskov
2022-10-25 14:13 ` [PATCH v2 22/23] efi/libstub: Add memory attribute protocol definitions Evgeniy Baskov
2022-10-25 14:13 ` [PATCH v2 23/23] efi/libstub: Use memory attribute protocol Evgeniy Baskov
2022-11-04 18:21 ` [PATCH v2 00/23] x86_64: Improvements at compressed kernel stage Limonciello, Mario
2022-11-08 7:01 ` Evgeniy Baskov
2022-11-08 18:17 ` Limonciello, Mario
2022-11-08 23:49 ` Evgeniy Baskov [this message]
2022-11-20 1:49 ` joeyli
2022-11-20 15:37 ` Evgeniy Baskov
2022-11-21 9:42 ` joeyli
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=4a942ab07fd320ba9a058c8a112503bd@ispras.ru \
--to=baskov@ispras.ru \
--cc=ardb@kernel.org \
--cc=bp@alien8.de \
--cc=dave.hansen@linux.intel.com \
--cc=khoroshilov@ispras.ru \
--cc=linux-efi@vger.kernel.org \
--cc=linux-hardening@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=luto@kernel.org \
--cc=lvc-project@linuxtesting.org \
--cc=mario.limonciello@amd.com \
--cc=mingo@redhat.com \
--cc=peterz@infradead.org \
--cc=pjones@redhat.com \
--cc=tglx@linutronix.de \
--cc=x86@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox