public inbox for linux-kernel@vger.kernel.org
 help / color / mirror / Atom feed
* [PATCH v2 0/4] x86: clear XD_DISABLED flag on Intel to regain NX
@ 2010-06-19  5:50 Kees Cook
  2010-06-19  5:51 ` [PATCH 1/4] x86: rename verify_cpu_64.S to verify_cpu.S Kees Cook
                   ` (4 more replies)
  0 siblings, 5 replies; 10+ messages in thread
From: Kees Cook @ 2010-06-19  5:50 UTC (permalink / raw)
  To: x86
  Cc: H. Peter Anvin, Thomas Gleixner, Ingo Molnar, Alexander Potashev,
	Tim Abbott, Sam Ravnborg, Jan Beulich, Jeremy Fitzhardinge,
	linux-kernel

This will clear the MSR_IA32_MISC_ENABLE_XD_DISABLE bit so that NX cannot
be inappropriately controlled by the BIOS on Intel CPUs.  If NX actually
needs to be disabled, "noexec=off" can be used.

Based on feedback from HPA, this was reworked to extend the existing
"verify_cpu" routines, and to more tightly confine which CPUs will call
MSR_IA32_MISC_ENABLE.  Since it includes some re-arrangements of files, I
tried to break the patches up into their logical steps.

-Kees

-- 
Kees Cook
Ubuntu Security Team

^ permalink raw reply	[flat|nested] 10+ messages in thread

end of thread, other threads:[~2010-06-19 18:09 UTC | newest]

Thread overview: 10+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2010-06-19  5:50 [PATCH v2 0/4] x86: clear XD_DISABLED flag on Intel to regain NX Kees Cook
2010-06-19  5:51 ` [PATCH 1/4] x86: rename verify_cpu_64.S to verify_cpu.S Kees Cook
2010-06-19  5:52 ` [PATCH 2/4] x86: clear XD_DISABLED flag on Intel to regain NX Kees Cook
2010-06-19  5:52 ` [PATCH 3/4] x86: call verify_cpu during 32bit CPU startup Kees Cook
2010-06-19  5:53 ` [PATCH 4/4] x86: only CPU features determine NX capabilities Kees Cook
2010-06-19  8:21 ` [PATCH v2 0/4] x86: clear XD_DISABLED flag on Intel to regain NX Andi Kleen
2010-06-19 15:16   ` Arjan van de Ven
2010-06-19 17:54     ` Kees Cook
2010-06-19 18:08       ` H. Peter Anvin
2010-06-19 16:21   ` Kees Cook

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox