From patchwork Mon Aug 14 12:53:57 2017 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ard Biesheuvel X-Patchwork-Id: 9898829 Return-Path: Received: from mail.wl.linuxfoundation.org (pdx-wl-mail.web.codeaurora.org [172.30.200.125]) by pdx-korg-patchwork.web.codeaurora.org (Postfix) with ESMTP id 8F6CE602BA for ; Mon, 14 Aug 2017 12:58:20 +0000 (UTC) Received: from mail.wl.linuxfoundation.org (localhost [127.0.0.1]) by mail.wl.linuxfoundation.org (Postfix) with ESMTP id 83383285FD for ; Mon, 14 Aug 2017 12:58:20 +0000 (UTC) Received: by mail.wl.linuxfoundation.org (Postfix, from userid 486) id 766A02860F; Mon, 14 Aug 2017 12:58:20 +0000 (UTC) X-Spam-Checker-Version: SpamAssassin 3.3.1 (2010-03-16) on pdx-wl-mail.web.codeaurora.org X-Spam-Level: X-Spam-Status: No, score=-4.1 required=2.0 tests=BAYES_00,DKIM_SIGNED, RCVD_IN_DNSWL_MED,T_DKIM_INVALID autolearn=ham version=3.3.1 Received: from mother.openwall.net (mother.openwall.net [195.42.179.200]) by mail.wl.linuxfoundation.org (Postfix) with SMTP id 6BA362860E for ; Mon, 14 Aug 2017 12:58:18 +0000 (UTC) Received: (qmail 26381 invoked by uid 550); 14 Aug 2017 12:55:44 -0000 Mailing-List: contact kernel-hardening-help@lists.openwall.com; run by ezmlm Precedence: bulk List-Post: List-Help: List-Unsubscribe: List-Subscribe: List-ID: Delivered-To: mailing list kernel-hardening@lists.openwall.com Received: (qmail 24203 invoked from network); 14 Aug 2017 12:55:30 -0000 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linaro.org; s=google; h=from:to:cc:subject:date:message-id:in-reply-to:references; bh=Hqn+0bHw8nmLyvvolzNRRNcjYA3kR2Yv0OagMNXwE/g=; b=H3c31mynTGnT1Hi4XkRIO2A76i/zn+0Zf/ptmncJbMTCzIV8nnzMGTUpiEu+fiWUsE 9vlQ1PzFkydayieKa+kLIFWB89Lr97koW9pN3BQm7DKTgptscBph9256T9yL53wneEKH HBC57lvU2I8tmQqJ/LrP9LLCm8RschwS4/uR0= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:to:cc:subject:date:message-id:in-reply-to :references; bh=Hqn+0bHw8nmLyvvolzNRRNcjYA3kR2Yv0OagMNXwE/g=; b=ucNryj1Yv9RF3osfut5w0yY1U6doo4bdbp9t6s9Sj3E0ldjzV7net7SbQkPL1Sk92L pbYHTc15qIjbRNJ5MbP0itH9DJnCN42f0lch80/zW9Qf6P6r2imSUljtMr7Y/jzpQ7nI 1uh4YD+bn3/0gb4XkW3FAlZTtHDkpsEhujBKgcl252ln7lZG5EizNjbchgQi4uOnWQfE WK+NWqRJKaYypDlQ0UoOgx0CHxmbkX/ggFCGCx9TPZegX9iJ5kp8UskoFRE8DeZbXnNN mVM62oWNbK+B0ohlcvz1YK/7H50+h+umlz9w9MMZyiFOTDu+V5nJmRrUE9hXW4WG0uJh eT4w== X-Gm-Message-State: AHYfb5htDFOZX+Sa7lxQijqO/RHDOGUm7zlkAJJrrlj3+5yPL2Y5XMgu H+CdejGYHjJh4rHSATaH/A== X-Received: by 10.28.203.206 with SMTP id b197mr3750513wmg.120.1502715318458; Mon, 14 Aug 2017 05:55:18 -0700 (PDT) From: Ard Biesheuvel To: kernel-hardening@lists.openwall.com Cc: linux-arm-kernel@lists.infradead.org, Ard Biesheuvel , Arnd Bergmann , Nicolas Pitre , Russell King , Kees Cook , Thomas Garnier , Marc Zyngier , Mark Rutland , Tony Lindgren , Matt Fleming , Dave Martin Date: Mon, 14 Aug 2017 13:53:57 +0100 Message-Id: <20170814125411.22604-17-ard.biesheuvel@linaro.org> X-Mailer: git-send-email 2.11.0 In-Reply-To: <20170814125411.22604-1-ard.biesheuvel@linaro.org> References: <20170814125411.22604-1-ard.biesheuvel@linaro.org> Subject: [kernel-hardening] [PATCH 16/30] ARM: kernel: use relative phys-to-virt patch tables X-Virus-Scanned: ClamAV using ClamSMTP Replace the contents of the __pv_table entries with relative references so that we don't have to relocate them at runtime when running the KASLR kernel. This ensures these quantities are invariant under runtime relocation, which makes any cache maintenance after runtime relocation unnecessary. Cc: Russell King Signed-off-by: Ard Biesheuvel --- arch/arm/include/asm/memory.h | 6 +++--- arch/arm/kernel/head.S | 21 ++++++++++---------- 2 files changed, 13 insertions(+), 14 deletions(-) diff --git a/arch/arm/include/asm/memory.h b/arch/arm/include/asm/memory.h index 1f54e4e98c1e..47a984e3a244 100644 --- a/arch/arm/include/asm/memory.h +++ b/arch/arm/include/asm/memory.h @@ -195,7 +195,7 @@ extern const void *__pv_table_begin, *__pv_table_end; __asm__("@ __pv_stub\n" \ "1: " instr " %0, %1, %2\n" \ " .pushsection .pv_table,\"a\"\n" \ - " .long 1b\n" \ + " .long 1b - .\n" \ " .popsection\n" \ : "=r" (to) \ : "r" (from), "I" (type)) @@ -204,7 +204,7 @@ extern const void *__pv_table_begin, *__pv_table_end; __asm__ volatile("@ __pv_stub_mov\n" \ "1: mov %R0, %1\n" \ " .pushsection .pv_table,\"a\"\n" \ - " .long 1b\n" \ + " .long 1b - .\n" \ " .popsection\n" \ : "=r" (t) \ : "I" (__PV_BITS_7_0)) @@ -214,7 +214,7 @@ extern const void *__pv_table_begin, *__pv_table_end; "1: adds %Q0, %1, %2\n" \ " adc %R0, %R0, #0\n" \ " .pushsection .pv_table,\"a\"\n" \ - " .long 1b\n" \ + " .long 1b - .\n" \ " .popsection\n" \ : "+r" (y) \ : "r" (x), "I" (__PV_BITS_31_24) \ diff --git a/arch/arm/kernel/head.S b/arch/arm/kernel/head.S index 62c961849035..5d685e86148c 100644 --- a/arch/arm/kernel/head.S +++ b/arch/arm/kernel/head.S @@ -593,8 +593,7 @@ ENDPROC(__fixup_pv_table) .text __fixup_a_pv_table: - mov_l r6, __pv_offset - add r6, r6, r3 + adr_l r6, __pv_offset ldr r0, [r6, #HIGH_OFFSET] @ pv_offset high word ldr r6, [r6, #LOW_OFFSET] @ pv_offset low word mov r6, r6, lsr #24 @@ -612,22 +611,22 @@ __fixup_a_pv_table: orr r6, r6, r7, lsl #12 orr r6, #0x4000 b 2f -1: add r7, r3 - ldrh ip, [r7, #2] +1: add r7, r4 + ldrh ip, [r7, #-2] ARM_BE8(rev16 ip, ip) tst ip, #0x4000 and ip, #0x8f00 orrne ip, r6 @ mask in offset bits 31-24 orreq ip, r0 @ mask in offset bits 7-0 ARM_BE8(rev16 ip, ip) - strh ip, [r7, #2] + strh ip, [r7, #-2] bne 2f - ldrh ip, [r7] + ldrh ip, [r7, #-4] ARM_BE8(rev16 ip, ip) bic ip, #0x20 orr ip, ip, r0, lsr #16 ARM_BE8(rev16 ip, ip) - strh ip, [r7] + strh ip, [r7, #-4] 2: cmp r4, r5 ldrcc r7, [r4], #4 @ use branch for delay slot bcc 1b @@ -639,7 +638,8 @@ ARM_BE8(rev16 ip, ip) moveq r0, #0x400000 @ set bit 22, mov to mvn instruction #endif b 2f -1: ldr ip, [r7, r3] +1: ldr ip, [r7, r4]! + add r4, r4, #4 #ifdef CONFIG_CPU_ENDIAN_BE8 @ in BE8, we load data in BE, but instructions still in LE bic ip, ip, #0xff000000 @@ -654,9 +654,9 @@ ARM_BE8(rev16 ip, ip) biceq ip, ip, #0x400000 @ clear bit 22 orreq ip, ip, r0 @ mask in offset bits 7-0 #endif - str ip, [r7, r3] + str ip, [r7] 2: cmp r4, r5 - ldrcc r7, [r4], #4 @ use branch for delay slot + ldrcc r7, [r4] @ use branch for delay slot bcc 1b ret lr #endif @@ -664,7 +664,6 @@ ENDPROC(__fixup_a_pv_table) ENTRY(fixup_pv_table) stmfd sp!, {r4 - r7, lr} - mov r3, #0 @ no offset mov r4, r0 @ r0 = table start add r5, r0, r1 @ r1 = table size bl __fixup_a_pv_table