From mboxrd@z Thu Jan 1 00:00:00 1970 From: Mark Rutland Date: Tue, 7 Mar 2017 13:54:43 +0000 Subject: [U-Boot] [PATCH 2/2] arm64: booti: allow to place kernel image anywhere in physical memory In-Reply-To: <20170307121656.GO19897@bill-the-cat> References: <1487730866-19447-1-git-send-email-yamada.masahiro@socionext.com> <1487730866-19447-2-git-send-email-yamada.masahiro@socionext.com> <20170222161921.GS27120@bill-the-cat> <20170223153117.GC27120@bill-the-cat> <20170226224118.GF20531@bill-the-cat> <20170228171509.GL20531@bill-the-cat> <20170307114352.GA24550@leverpostej> <20170307121656.GO19897@bill-the-cat> Message-ID: <20170307135442.GB24550@leverpostej> List-Id: MIME-Version: 1.0 Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit To: u-boot@lists.denx.de On Tue, Mar 07, 2017 at 07:16:56AM -0500, Tom Rini wrote: > On Tue, Mar 07, 2017 at 11:43:52AM +0000, Mark Rutland wrote: > > On Tue, Feb 28, 2017 at 12:15:09PM -0500, Tom Rini wrote: > > > On Wed, Mar 01, 2017 at 02:03:58AM +0900, Masahiro Yamada wrote: > > > > 2017-02-27 7:41 GMT+09:00 Tom Rini : > > > > If we put the image at 2MiB aligned base, the relocation would > > > > always happen. > > > > > > Correct. But I honestly don't know if non-randomized text offset is the > > > common case people will optimize for or randomized for added security will be > > > the more common case. > > > > FWIW, the randomized text_offset is a bootloader debugging/testing > > feature, and there's no security aspect to it. > > > > It was added [1] as an additional to hint to bootloader authors that > > they must respect the text_offset field. > > Right, and we do this today. But since this doubles as a kind of cheap > KASLR I would also expect to see it used, even if not intended, in this > way. I can certainly imagine people loading the kernel at a random physical base address (i.e. a random 2M base + text_offset), and doing that's perfectly fine for kernels happy to be loaded at arbitrary bases. That may help to frustrate some DMA attacks. I take it that's what you meant? Given text_offset itself is fixed at compile time, randomizing it provides absolutely no security benefit, and we should be careful not to give the impression that it does. Thanks, Mark.