From patchwork Wed Mar 29 18:15:59 2017 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Kees Cook X-Patchwork-Id: 9652225 Return-Path: Received: from mail.wl.linuxfoundation.org (pdx-wl-mail.web.codeaurora.org [172.30.200.125]) by pdx-korg-patchwork.web.codeaurora.org (Postfix) with ESMTP id EB9E7602C8 for ; Wed, 29 Mar 2017 18:18:27 +0000 (UTC) Received: from mail.wl.linuxfoundation.org (localhost [127.0.0.1]) by mail.wl.linuxfoundation.org (Postfix) with ESMTP id D31C328510 for ; Wed, 29 Mar 2017 18:18:27 +0000 (UTC) Received: by mail.wl.linuxfoundation.org (Postfix, from userid 486) id C5B4F2851F; Wed, 29 Mar 2017 18:18:27 +0000 (UTC) X-Spam-Checker-Version: SpamAssassin 3.3.1 (2010-03-16) on pdx-wl-mail.web.codeaurora.org X-Spam-Level: X-Spam-Status: No, score=-1.9 required=2.0 tests=BAYES_00,DKIM_SIGNED, DKIM_VALID autolearn=ham version=3.3.1 Received: from bombadil.infradead.org (bombadil.infradead.org [65.50.211.133]) (using TLSv1.2 with cipher AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mail.wl.linuxfoundation.org (Postfix) with ESMTPS id 4006728510 for ; Wed, 29 Mar 2017 18:18:27 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.infradead.org; s=bombadil.20170209; h=Sender: Content-Transfer-Encoding:Content-Type:MIME-Version:Cc:List-Subscribe: List-Help:List-Post:List-Archive:List-Unsubscribe:List-Id:References: In-Reply-To:Message-Id:Date:Subject:To:From:Reply-To:Content-ID: Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc :Resent-Message-ID:List-Owner; bh=UeIMXB+cicHTrBVwbQyiImjrJMdWWsoxUD/sl64t14g=; b=bJpQkX7GC9PvQos9ftJwifusgT y672z6L6DrkX6LqGC8EQ9G1BKwsaNPdSJSVwIU9e2nlcm+mTws4ArqqF2TNcSHjgR1mMlMh3DaqED 5ixwOaiV9MK+QTJUJzJAumlLqq0MkKyLlgaCE1syVpdvVxbWFk/3J0lnBYvipcz8InSOq53uUWEyG AD0JfxFKtjgfMIZdIZT08zXupuiO/Z3+JUcmsHS+8qaL/2bxWo25ZF/81obMAP6qNszu/Xw6OLJtI jjLSJkXeBd+nYo7FSzLb4Uk5lZcot0eRS0CXkl5ye7O1DWI7ILjEeI4hCE7iqba5mDmTGr02d2kxg EIEU0biQ==; Received: from localhost ([127.0.0.1] helo=bombadil.infradead.org) by bombadil.infradead.org with esmtp (Exim 4.87 #1 (Red Hat Linux)) id 1ctIAs-0006yB-7x; Wed, 29 Mar 2017 18:18:26 +0000 Received: from mail-pg0-x22a.google.com ([2607:f8b0:400e:c05::22a]) by bombadil.infradead.org with esmtps (Exim 4.87 #1 (Red Hat Linux)) id 1ctI9F-00058N-DO for linux-arm-kernel@lists.infradead.org; Wed, 29 Mar 2017 18:16:50 +0000 Received: by mail-pg0-x22a.google.com with SMTP id g2so14446868pge.3 for ; Wed, 29 Mar 2017 11:16:25 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=chromium.org; s=google; h=from:to:cc:subject:date:message-id:in-reply-to:references; bh=uIcbJoE3YskpamKiFw1R8V8AQOL5LQY4rTwYGD4m1Hg=; b=OCyn+PImlYjLhyHbZX8daJ3xwvHaeYvBs8XOQSpyXv/uquXL4IVAbcjfLyya0VkBM0 Q1TJmbbpnljdyMhGWzKIzjJKHHqadlrDV41IGuRmS7dyqtRzCCaUYm+0znuXTp7p6VZ4 gROAuFmOl0Ft8Ra9lqjfLiZJ1HfiOhAiXeqiA= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:to:cc:subject:date:message-id:in-reply-to :references; bh=uIcbJoE3YskpamKiFw1R8V8AQOL5LQY4rTwYGD4m1Hg=; b=nH0Seqy6L7mxfX1ZA0fK0VLYWb7ye3OJhUv/Z84WrV2tKKoSB2+U1sM4Vy9tB2E8no xiwCuWYjcQf6HjWum+a1UGvqTa+8btaUubB/zjQbjqJLmQASMWRBpUQ3SqNrWnDwRabg ele72GkfJ6PU2isRveiniuZ3fBi2+h+webF5n+w+wF4WB5MvDmOSBwuXjdafqGpMAumV g2eq352podCofdQntLYFO0JfjUTVovtWNnNI4BAojK/kluR3Jf/RJBrFEivK1rzM6fYw VosqlzCZA8yKQroMwY7YknV+B4cHIit9fs8xRUovHuLONTwlRZbD5CjsdEYD1X+oK3pL pc0g== X-Gm-Message-State: AFeK/H0LH/oL8oO1fqyXa3WHs8+tI4B099iNyGd/9PZ22v8dqPikJctbsP96I2Mvh0gTr1iL X-Received: by 10.98.201.212 with SMTP id l81mr1842197pfk.13.1490811384618; Wed, 29 Mar 2017 11:16:24 -0700 (PDT) Received: from www.outflux.net (173-164-112-133-Oregon.hfc.comcastbusiness.net. [173.164.112.133]) by smtp.gmail.com with ESMTPSA id u26sm14850426pfi.89.2017.03.29.11.16.22 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Wed, 29 Mar 2017 11:16:23 -0700 (PDT) From: Kees Cook To: kernel-hardening@lists.openwall.com Subject: [RFC v2][PATCH 07/11] ARM: mm: set DOMAIN_WR_RARE for rodata Date: Wed, 29 Mar 2017 11:15:59 -0700 Message-Id: <1490811363-93944-8-git-send-email-keescook@chromium.org> X-Mailer: git-send-email 2.7.4 In-Reply-To: <1490811363-93944-1-git-send-email-keescook@chromium.org> References: <1490811363-93944-1-git-send-email-keescook@chromium.org> X-CRM114-Version: 20100106-BlameMichelson ( TRE 0.8.0 (BSD) ) MR-646709E3 X-CRM114-CacheID: sfid-20170329_111645_678050_8894FC1C X-CRM114-Status: GOOD ( 13.19 ) X-BeenThere: linux-arm-kernel@lists.infradead.org X-Mailman-Version: 2.1.21 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Cc: Mark Rutland , Hoeun Ryu , Kees Cook , x86@kernel.org, Russell King , linux-kernel@vger.kernel.org, Emese Revfy , Andy Lutomirski , PaX Team , linux-arm-kernel@lists.infradead.org MIME-Version: 1.0 Sender: "linux-arm-kernel" Errors-To: linux-arm-kernel-bounces+patchwork-linux-arm=patchwork.kernel.org@lists.infradead.org X-Virus-Scanned: ClamAV using ClamSMTP This creates DOMAIN_WR_RARE for the kernel's .rodata section, separate from DOMAIN_KERNEL to avoid predictive fetching in device memory during a DOMAIN_MANAGER transition. TODO: handle kernel module vmalloc memory, which needs to be marked as DOMAIN_WR_RARE too, for module .rodata sections. Signed-off-by: Kees Cook --- arch/arm/include/asm/domain.h | 3 +++ arch/arm/mm/dump.c | 2 ++ arch/arm/mm/init.c | 7 ++++--- 3 files changed, 9 insertions(+), 3 deletions(-) diff --git a/arch/arm/include/asm/domain.h b/arch/arm/include/asm/domain.h index 8b33bd7f6bf9..b5ca80ac823c 100644 --- a/arch/arm/include/asm/domain.h +++ b/arch/arm/include/asm/domain.h @@ -43,6 +43,7 @@ #define DOMAIN_IO 0 #endif #define DOMAIN_VECTORS 3 +#define DOMAIN_WR_RARE 4 /* * Domain types @@ -69,11 +70,13 @@ #define DACR_INIT \ (__DACR_INIT_USER | \ domain_val(DOMAIN_KERNEL, DOMAIN_MANAGER) | \ + domain_val(DOMAIN_WR_RARE, DOMAIN_CLIENT) | \ domain_val(DOMAIN_IO, DOMAIN_CLIENT) | \ domain_val(DOMAIN_VECTORS, DOMAIN_CLIENT)) #define __DACR_DEFAULT \ domain_val(DOMAIN_KERNEL, DOMAIN_CLIENT) | \ + domain_val(DOMAIN_WR_RARE, DOMAIN_CLIENT) | \ domain_val(DOMAIN_IO, DOMAIN_CLIENT) | \ domain_val(DOMAIN_VECTORS, DOMAIN_CLIENT) diff --git a/arch/arm/mm/dump.c b/arch/arm/mm/dump.c index 35ff45470dbf..b1aa9a17e0c3 100644 --- a/arch/arm/mm/dump.c +++ b/arch/arm/mm/dump.c @@ -288,6 +288,8 @@ static const char *get_domain_name(pmd_t *pmd) return "IO "; case PMD_DOMAIN(DOMAIN_VECTORS): return "VECTORS"; + case PMD_DOMAIN(DOMAIN_WR_RARE): + return "WR_RARE"; default: return "unknown"; } diff --git a/arch/arm/mm/init.c b/arch/arm/mm/init.c index 1d8558ff9827..d54a74b5718b 100644 --- a/arch/arm/mm/init.c +++ b/arch/arm/mm/init.c @@ -642,9 +642,10 @@ static struct section_perm ro_perms[] = { .mask = ~L_PMD_SECT_RDONLY, .prot = L_PMD_SECT_RDONLY, #else - .mask = ~(PMD_SECT_APX | PMD_SECT_AP_WRITE), - .prot = PMD_SECT_APX | PMD_SECT_AP_WRITE, - .clear = PMD_SECT_AP_WRITE, + .mask = ~(PMD_SECT_APX | PMD_SECT_AP_WRITE | PMD_DOMAIN_MASK), + .prot = PMD_SECT_APX | PMD_SECT_AP_WRITE | \ + PMD_DOMAIN(DOMAIN_WR_RARE), + .clear = PMD_SECT_AP_WRITE | PMD_DOMAIN(DOMAIN_KERNEL), #endif }, };