linuxppc-dev.lists.ozlabs.org archive mirror
 help / color / mirror / Atom feed
From: Ram Pai <linuxram@us.ibm.com>
To: mpe@ellerman.id.au
Cc: linuxppc-dev@lists.ozlabs.org, dave.hansen@intel.com,
	aneesh.kumar@linux.vnet.ibm.com, bsingharora@gmail.com,
	hbabu@us.ibm.com, mhocko@kernel.org, bauerman@linux.vnet.ibm.com,
	linuxram@us.ibm.com, Ulrich.Weigand@de.ibm.com,
	fweimer@redhat.com, luto@kernel.org, msuchanek@suse.de
Subject: [PATCH v2 6/6] powerpc/pkeys: Deny read/write/execute by default
Date: Wed, 13 Jun 2018 17:29:04 -0700	[thread overview]
Message-ID: <1528936144-6696-7-git-send-email-linuxram@us.ibm.com> (raw)
In-Reply-To: <1528936144-6696-1-git-send-email-linuxram@us.ibm.com>

Deny all permissions on all keys, with some exceptions.  pkey-0 must
allow all permissions, or else everything comes to a screaching halt.
Execute-only key must allow execute permission.

Signed-off-by: Ram Pai <linuxram@us.ibm.com>
---
 arch/powerpc/mm/pkeys.c |   10 ++++------
 1 files changed, 4 insertions(+), 6 deletions(-)

diff --git a/arch/powerpc/mm/pkeys.c b/arch/powerpc/mm/pkeys.c
index 9098605..cec990c 100644
--- a/arch/powerpc/mm/pkeys.c
+++ b/arch/powerpc/mm/pkeys.c
@@ -128,13 +128,11 @@ int pkey_initialize(void)
 
 	/* register mask is in BE format */
 	pkey_amr_mask = ~0x0ul;
-	pkey_iamr_mask = ~0x0ul;
+	pkey_amr_mask &= ~(0x3ul << pkeyshift(PKEY_0));
 
-	for (i = 0; i < (pkeys_total - os_reserved); i++) {
-		pkey_amr_mask &= ~(0x3ul << pkeyshift(i));
-		pkey_iamr_mask &= ~(0x1ul << pkeyshift(i));
-	}
-	pkey_amr_mask |= (AMR_RD_BIT|AMR_WR_BIT) << pkeyshift(EXECUTE_ONLY_KEY);
+	pkey_iamr_mask = ~0x0ul;
+	pkey_iamr_mask &= ~(0x3ul << pkeyshift(PKEY_0));
+	pkey_iamr_mask &= ~(0x3ul << pkeyshift(EXECUTE_ONLY_KEY));
 
 	pkey_uamor_mask = ~0x0ul;
 	pkey_uamor_mask &= ~(0x3ul << pkeyshift(PKEY_0));
-- 
1.7.1

  parent reply	other threads:[~2018-06-14  0:29 UTC|newest]

Thread overview: 32+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2018-06-14  0:28 [PATCH v2 0/6] powerpc/pkeys: fixes to pkeys Ram Pai
2018-06-14  0:28 ` [PATCH v2 1/6] powerpc/pkeys: Enable all user-allocatable pkeys at init Ram Pai
2018-06-19 12:39   ` Michael Ellerman
2018-06-19 14:25     ` Ram Pai
2018-06-21  4:14       ` Michael Ellerman
2018-06-21 17:24         ` Ram Pai
2018-06-14  0:29 ` [PATCH v2 2/6] powerpc/pkeys: Save the pkey registers before fork Ram Pai
2018-06-19 12:39   ` Michael Ellerman
2018-06-19 14:28     ` Ram Pai
2018-06-21  4:13       ` Michael Ellerman
2018-06-21 17:35         ` Ram Pai
2018-06-14  0:29 ` [PATCH v2 3/6] powerpc/pkeys: fix calculation of total pkeys Ram Pai
2018-06-19 12:40   ` Michael Ellerman
2018-06-14  0:29 ` [PATCH v2 4/6] powerpc/pkeys: Preallocate execute-only key Ram Pai
2018-06-19 12:40   ` Michael Ellerman
2018-06-19 16:38     ` Ram Pai
2018-06-21  0:28       ` Michael Ellerman
2018-06-29  3:02   ` Thiago Jung Bauermann
2018-06-14  0:29 ` [PATCH v2 5/6] powerpc/pkeys: make protection key 0 less special Ram Pai
2018-06-19 12:40   ` Michael Ellerman
2018-06-19 16:34     ` Ram Pai
2018-06-14  0:29 ` Ram Pai [this message]
2018-06-19 12:39   ` [PATCH v2 6/6] powerpc/pkeys: Deny read/write/execute by default Michael Ellerman
2018-06-19 13:19     ` Florian Weimer
2018-06-19 16:31     ` Ram Pai
2018-06-14 12:15 ` [PATCH v2 0/6] powerpc/pkeys: fixes to pkeys Florian Weimer
2018-06-19 12:40   ` Michael Ellerman
2018-06-20 15:08     ` Florian Weimer
2018-06-21 10:28       ` Michael Ellerman
2018-06-21 18:10         ` Ram Pai
2018-06-23 15:02           ` Michael Ellerman
2018-06-25 17:06             ` Ram Pai

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=1528936144-6696-7-git-send-email-linuxram@us.ibm.com \
    --to=linuxram@us.ibm.com \
    --cc=Ulrich.Weigand@de.ibm.com \
    --cc=aneesh.kumar@linux.vnet.ibm.com \
    --cc=bauerman@linux.vnet.ibm.com \
    --cc=bsingharora@gmail.com \
    --cc=dave.hansen@intel.com \
    --cc=fweimer@redhat.com \
    --cc=hbabu@us.ibm.com \
    --cc=linuxppc-dev@lists.ozlabs.org \
    --cc=luto@kernel.org \
    --cc=mhocko@kernel.org \
    --cc=mpe@ellerman.id.au \
    --cc=msuchanek@suse.de \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).