From patchwork Tue Jul 18 22:33:16 2017 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Thomas Garnier X-Patchwork-Id: 9850027 Return-Path: Received: from mail.wl.linuxfoundation.org (pdx-wl-mail.web.codeaurora.org [172.30.200.125]) by pdx-korg-patchwork.web.codeaurora.org (Postfix) with ESMTP id 8C16860392 for ; Tue, 18 Jul 2017 22:35:24 +0000 (UTC) Received: from mail.wl.linuxfoundation.org (localhost [127.0.0.1]) by mail.wl.linuxfoundation.org (Postfix) with ESMTP id 779AE1FF15 for ; Tue, 18 Jul 2017 22:35:24 +0000 (UTC) Received: by mail.wl.linuxfoundation.org (Postfix, from userid 486) id 6B81A285CB; Tue, 18 Jul 2017 22:35:24 +0000 (UTC) X-Spam-Checker-Version: SpamAssassin 3.3.1 (2010-03-16) on pdx-wl-mail.web.codeaurora.org X-Spam-Level: X-Spam-Status: No, score=-4.1 required=2.0 tests=BAYES_00, DKIM_ADSP_CUSTOM_MED, DKIM_SIGNED, RCVD_IN_DNSWL_MED, T_DKIM_INVALID autolearn=ham version=3.3.1 Received: from mother.openwall.net (mother.openwall.net [195.42.179.200]) by mail.wl.linuxfoundation.org (Postfix) with SMTP id 9C9391FF15 for ; Tue, 18 Jul 2017 22:35:23 +0000 (UTC) Received: (qmail 26261 invoked by uid 550); 18 Jul 2017 22:34:30 -0000 Mailing-List: contact kernel-hardening-help@lists.openwall.com; run by ezmlm Precedence: bulk List-Post: List-Help: List-Unsubscribe: List-Subscribe: List-ID: Delivered-To: mailing list kernel-hardening@lists.openwall.com Received: (qmail 26061 invoked from network); 18 Jul 2017 22:34:28 -0000 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20161025; h=from:to:cc:subject:date:message-id:in-reply-to:references; bh=YlO/Sv2vA0Kdq7YbCCEu5A7iUDwAdXbeZIHfoPX7iNo=; b=oJizZnwf6UgkdswcXRUUwnrN1j14v2lFEnVRmkW4GkQTi9nqrI4GcOMzKArc77WPQV awd48HFv1BFZZRaAXnf52HsOpUAlgC/hCTGJWU4GJ8DSxoQ2kHoZzkjwba64vda96p7+ T6hTBnGYLQQGFHO2SFQCTCFOlWq4T4AUcC13jQEAQz+h2wJcUq0CLbwgYxINZMRcbgdL oS5dZ+wM1PlC4Wz6fd827sIj757NqXv5uO945B30Cwhtpx7/L+L1cR9FbkYqVy9QuxNj 0r558O68EzNyHzrAU0e1K+ze1y0CsYNkdOljlclO3GIZyKeJH8FexXfd7eWAADgFYqJT M2hQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:to:cc:subject:date:message-id:in-reply-to :references; bh=YlO/Sv2vA0Kdq7YbCCEu5A7iUDwAdXbeZIHfoPX7iNo=; b=cVDbd7xBKuFOCpE38jax9AEQTGHTKWk0/KMscudUQQvmF8M7aCASy25Vfi/MTjQViN 7iZ+Cbj7LzRgAp7OhLloXdkUwtac1+NATXAlB1/lDZw6PPKjJnqN/kyKagrxsGFVaGG8 I6qIzig5e4BUMFiDeytU+j9Jzv0he3z4OFIqpIa1RrP35pgYLIVMMQzaamtgQeHL0Qvc cJVaW0Ov3O3m/l4CaYm3IJLLxZvqjiMHXDybb3fVFE1FkRivw7Lzrtwvox6WNOnuDLvu eUYUNK7HhsxYTEq9ZtSCJVTmK9xQijRELnMduB29/Wi97X23DwqHuk/tHJFwg8cBQKb0 X27g== X-Gm-Message-State: AIVw1104NhwjPwaZ5wdIT+FR0vPbq73npXhu+DaBKIDyP/trPmhHrR7n jWf/nj2HOm2RFZtS X-Received: by 10.84.177.195 with SMTP id x61mr4094956plb.44.1500417256501; Tue, 18 Jul 2017 15:34:16 -0700 (PDT) From: Thomas Garnier To: Herbert Xu , "David S . Miller" , Thomas Gleixner , Ingo Molnar , "H . Peter Anvin" , Peter Zijlstra , Josh Poimboeuf , Thomas Garnier , Arnd Bergmann , Matthias Kaehlcke , Boris Ostrovsky , Juergen Gross , Paolo Bonzini , =?UTF-8?q?Radim=20Kr=C4=8Dm=C3=A1=C5=99?= , Joerg Roedel , Andy Lutomirski , Borislav Petkov , "Kirill A . Shutemov" , Brian Gerst , Borislav Petkov , Christian Borntraeger , "Rafael J . Wysocki" , Len Brown , Pavel Machek , Tejun Heo , Christoph Lameter , Kees Cook , Paul Gortmaker , Chris Metcalf , "Paul E . McKenney" , Andrew Morton , Christopher Li , Dou Liyang , Masahiro Yamada , Daniel Borkmann , Markus Trippelsdorf , Peter Foley , Steven Rostedt , Tim Chen , Ard Biesheuvel , Catalin Marinas , Matthew Wilcox , Michal Hocko , Rob Landley , Jiri Kosina , "H . J . Lu" , Paul Bolle , Baoquan He , Daniel Micay Cc: x86@kernel.org, linux-crypto@vger.kernel.org, linux-kernel@vger.kernel.org, xen-devel@lists.xenproject.org, kvm@vger.kernel.org, linux-pm@vger.kernel.org, linux-arch@vger.kernel.org, linux-sparse@vger.kernel.org, kernel-hardening@lists.openwall.com Date: Tue, 18 Jul 2017 15:33:16 -0700 Message-Id: <20170718223333.110371-6-thgarnie@google.com> X-Mailer: git-send-email 2.13.2.932.g7449e964c-goog In-Reply-To: <20170718223333.110371-1-thgarnie@google.com> References: <20170718223333.110371-1-thgarnie@google.com> Subject: [kernel-hardening] [RFC 05/22] xen: Adapt assembly for PIE support X-Virus-Scanned: ClamAV using ClamSMTP Change the assembly code to use the new _ASM_GET_PTR macro which get a symbol reference while being PIE compatible. Modify the RELOC macro that was using an assignment generating a non-relative reference. Position Independent Executable (PIE) support will allow to extended the KASLR randomization range below the -2G memory limit. Signed-off-by: Thomas Garnier --- arch/x86/xen/xen-asm.h | 3 ++- arch/x86/xen/xen-head.S | 9 +++++---- 2 files changed, 7 insertions(+), 5 deletions(-) diff --git a/arch/x86/xen/xen-asm.h b/arch/x86/xen/xen-asm.h index 465276467a47..3b1c8a2e77d8 100644 --- a/arch/x86/xen/xen-asm.h +++ b/arch/x86/xen/xen-asm.h @@ -2,8 +2,9 @@ #define _XEN_XEN_ASM_H #include +#include -#define RELOC(x, v) .globl x##_reloc; x##_reloc=v +#define RELOC(x, v) .globl x##_reloc; x##_reloc: _ASM_PTR v #define ENDPATCH(x) .globl x##_end; x##_end=. /* Pseudo-flag used for virtual NMI, which we don't implement yet */ diff --git a/arch/x86/xen/xen-head.S b/arch/x86/xen/xen-head.S index 72a8e6adebe6..ab2462396bd8 100644 --- a/arch/x86/xen/xen-head.S +++ b/arch/x86/xen/xen-head.S @@ -23,14 +23,15 @@ ENTRY(startup_xen) /* Clear .bss */ xor %eax,%eax - mov $__bss_start, %_ASM_DI - mov $__bss_stop, %_ASM_CX + _ASM_GET_PTR(__bss_start, %_ASM_DI) + _ASM_GET_PTR(__bss_stop, %_ASM_CX) sub %_ASM_DI, %_ASM_CX shr $__ASM_SEL(2, 3), %_ASM_CX rep __ASM_SIZE(stos) - mov %_ASM_SI, xen_start_info - mov $init_thread_union+THREAD_SIZE, %_ASM_SP + _ASM_GET_PTR(xen_start_info, %_ASM_AX) + mov %_ASM_SI, (%_ASM_AX) + _ASM_GET_PTR(init_thread_union+THREAD_SIZE, %_ASM_SP) jmp xen_start_kernel