linux-pm.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
From: Pavel Machek <pavel@ucw.cz>
To: Kees Cook <keescook@chromium.org>
Cc: "H. Peter Anvin" <hpa@zytor.com>,
	LKML <linux-kernel@vger.kernel.org>,
	Randy Dunlap <rdunlap@infradead.org>,
	Thomas Gleixner <tglx@linutronix.de>,
	Ingo Molnar <mingo@redhat.com>, "x86@kernel.org" <x86@kernel.org>,
	"Rafael J. Wysocki" <rjw@rjwysocki.net>,
	Len Brown <len.brown@intel.com>,
	Wei Yongjun <yongjun_wei@trendmicro.com.cn>,
	"linux-doc@vger.kernel.org" <linux-doc@vger.kernel.org>,
	linux-pm@vger.kernel.org
Subject: Re: [PATCH 0/2] make kASLR vs hibernation boot-time selectable
Date: Fri, 13 Jun 2014 12:51:35 +0200	[thread overview]
Message-ID: <20140613105135.GA4876@amd.pavel.ucw.cz> (raw)
In-Reply-To: <CAGXu5jKanRjK66P9dFYctXfQxT+da_9z8vqy8s+WqgW1cw17-Q@mail.gmail.com>

Hi!


> >>> Any way we can make them work together instead?
> >>
> >> I'm sure there is, but I don't know the solution. :)
> >>
> >> At the very least this gets us one step closer (we can build them together).
> >>
> >
> > But it is really invasive.
> 
> Well, I don't agree there. I actually would like to be able to turn
> off hibernation support on distro kernels regardless of kASLR, so I
> think this is really killing two birds with one stone.
> 
> > I have to admit to being somewhat fuzzy on what the core problem with
> > hibernation and kASLR is... in both cases there is a set of pages that
> > need to be installed, some of which will overlap the loader kernel.
> > What am I missing?
> 
> I don't know how resume works, but I have assumed that the newly
> loaded kernel stays in memory and pulls in the vmalloc, kmalloc,
> modules, and userspace memory maps from disk. Since these things can
> easily contain references to kernel text, if the newly loaded kernel
> has moved with regard to the hibernated image, everything breaks.
> IIUC, this is similar why you can't rebuild your kernel and resume
> from a different version.

x86-64 can resume from different kernel that did the suspend. kASLR
should not be too different from that. (You just include kernel text
in the hibernation image. It is small enough to do that.)

									Pavel
-- 
(english) http://www.livejournal.com/~pavelmachek
(cesky, pictures) http://atrey.karlin.mff.cuni.cz/~pavel/picture/horses/blog.html

  reply	other threads:[~2014-06-13 10:51 UTC|newest]

Thread overview: 25+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2014-06-12 19:46 [PATCH 0/2] make kASLR vs hibernation boot-time selectable Kees Cook
2014-06-12 19:46 ` [PATCH 1/2] hibernate: create one-way disable mode Kees Cook
2014-06-12 20:12   ` Rafael J. Wysocki
2014-06-12 19:46 ` [PATCH 2/2] x86, kaslr: boot-time selectable with hibernation Kees Cook
2014-06-12 19:48 ` [PATCH 0/2] make kASLR vs hibernation boot-time selectable H. Peter Anvin
2014-06-12 20:13   ` Rafael J. Wysocki
2014-06-12 20:27   ` Kees Cook
2014-06-12 20:29     ` H. Peter Anvin
2014-06-12 20:58       ` Kees Cook
2014-06-13 10:51         ` Pavel Machek [this message]
2014-06-13 17:32           ` Kees Cook
2014-06-13 17:36             ` H. Peter Anvin
2014-06-13 20:26             ` Pavel Machek
2014-06-13 22:14             ` Rafael J. Wysocki
2014-06-13 22:07               ` Kees Cook
2014-06-13 22:54                 ` Rafael J. Wysocki
2014-06-13 22:59                   ` Kees Cook
2014-06-14  0:14                     ` Rafael J. Wysocki
2014-06-14  0:08                       ` Kees Cook
2014-06-14  0:39                         ` Rafael J. Wysocki
2014-06-14  7:37                           ` Kees Cook
2014-06-15 23:16                             ` Rafael J. Wysocki
2014-06-14 16:41                           ` H. Peter Anvin
2014-06-15 23:04                             ` Rafael J. Wysocki
2014-06-14  2:31                       ` H. Peter Anvin

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20140613105135.GA4876@amd.pavel.ucw.cz \
    --to=pavel@ucw.cz \
    --cc=hpa@zytor.com \
    --cc=keescook@chromium.org \
    --cc=len.brown@intel.com \
    --cc=linux-doc@vger.kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-pm@vger.kernel.org \
    --cc=mingo@redhat.com \
    --cc=rdunlap@infradead.org \
    --cc=rjw@rjwysocki.net \
    --cc=tglx@linutronix.de \
    --cc=x86@kernel.org \
    --cc=yongjun_wei@trendmicro.com.cn \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).