From patchwork Wed Mar 2 17:11:51 2016 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ard Biesheuvel X-Patchwork-Id: 63406 Delivered-To: patch@linaro.org Received: by 10.112.199.169 with SMTP id jl9csp2497929lbc; Wed, 2 Mar 2016 09:13:50 -0800 (PST) X-Received: by 10.66.141.11 with SMTP id rk11mr40715469pab.75.1456938830591; Wed, 02 Mar 2016 09:13:50 -0800 (PST) Return-Path: Received: from bombadil.infradead.org (bombadil.infradead.org. [2001:1868:205::9]) by mx.google.com with ESMTPS id oz1si20491921pac.46.2016.03.02.09.13.50 for (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Wed, 02 Mar 2016 09:13:50 -0800 (PST) Received-SPF: pass (google.com: best guess record for domain of linux-arm-kernel-bounces+patch=linaro.org@lists.infradead.org designates 2001:1868:205::9 as permitted sender) client-ip=2001:1868:205::9; Authentication-Results: mx.google.com; spf=pass (google.com: best guess record for domain of linux-arm-kernel-bounces+patch=linaro.org@lists.infradead.org designates 2001:1868:205::9 as permitted sender) smtp.mailfrom=linux-arm-kernel-bounces+patch=linaro.org@lists.infradead.org; dkim=neutral (body hash did not verify) header.i=@linaro.org Received: from localhost ([127.0.0.1] helo=bombadil.infradead.org) by bombadil.infradead.org with esmtp (Exim 4.80.1 #2 (Red Hat Linux)) id 1abAKU-00025F-0c; Wed, 02 Mar 2016 17:12:54 +0000 Received: from mail-wm0-x229.google.com ([2a00:1450:400c:c09::229]) by bombadil.infradead.org with esmtps (Exim 4.80.1 #2 (Red Hat Linux)) id 1abAJz-0001kn-RL for linux-arm-kernel@lists.infradead.org; Wed, 02 Mar 2016 17:12:27 +0000 Received: by mail-wm0-x229.google.com with SMTP id l68so87210371wml.1 for ; Wed, 02 Mar 2016 09:12:03 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linaro.org; s=google; h=from:to:cc:subject:date:message-id:in-reply-to:references; bh=9bX99KsJgPEzIMaWZ9JFLKQcHf1/kivnZ3ykDivYGbU=; b=M0pLd1U65S6Ycf5i4rF9pJiAAguT70JFozu5/5AwNrsy68KVbe/D95H5GtbMcBDpEX VJ34CrdbHAnJC7he206YRz3Z03GfDUk03BQbGw8JJFePT8XHqlGjgE2QfvmHr0rINKMX gJ6x5PBch7MU5GezFhx+hxmc7LnRhHWWbVYDE= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:from:to:cc:subject:date:message-id:in-reply-to :references; bh=9bX99KsJgPEzIMaWZ9JFLKQcHf1/kivnZ3ykDivYGbU=; b=HOyMhv/csYzwHj3knxOG5f3b03HrjyDKMLOs75tQtIxjBqjBwfDYBKyIxxoCDWSQfb 38t24HrmFqlJ35JuuLQkJvTzmM43nGA0g5W300QGXCMd7pSkwQC1GImeTCv4LAu007bD Wu9sobEyHoFcyDNnmb+rZbvmRsNfSVs65Zm8EfcuI/CoULiRup1LzD0V+p2EmAJ+pY/j kmiUEjuqhfFujXeSdNixx1mrdD4YgypsvDu6iLmqn58ZgnYvJCoY9r/elB7PzwFTrWdJ 4T5gtsqUoZdZsrfK20d2x5FF3GiZyagi7AB2P8yENoQFKGkcHKUgIVY5pGVEfFDTyyVV YLyw== X-Gm-Message-State: AD7BkJKgdYF4vK1fHJjm7H7N/iz/ezPKNEtjhOJ06jJmuDKJUQwvPs7OtMBzBc6/fUSBurYz X-Received: by 10.28.14.140 with SMTP id 134mr971589wmo.39.1456938722247; Wed, 02 Mar 2016 09:12:02 -0800 (PST) Received: from localhost.localdomain ([195.55.142.58]) by smtp.gmail.com with ESMTPSA id gk4sm18023317wjd.7.2016.03.02.09.12.00 (version=TLS1_2 cipher=ECDHE-RSA-AES128-SHA bits=128/128); Wed, 02 Mar 2016 09:12:01 -0800 (PST) From: Ard Biesheuvel To: linux-arm-kernel@lists.infradead.org, keescook@chromium.org, catalin.marinas@arm.com, mark.rutland@arm.com Subject: [PATCH 2/3] arm64: kaslr: deal with physically misaligned kernel images Date: Wed, 2 Mar 2016 18:11:51 +0100 Message-Id: <1456938712-11089-3-git-send-email-ard.biesheuvel@linaro.org> X-Mailer: git-send-email 2.5.0 In-Reply-To: <1456938712-11089-1-git-send-email-ard.biesheuvel@linaro.org> References: <1456938712-11089-1-git-send-email-ard.biesheuvel@linaro.org> X-CRM114-Version: 20100106-BlameMichelson ( TRE 0.8.0 (BSD) ) MR-646709E3 X-CRM114-CacheID: sfid-20160302_091224_051628_93BB563F X-CRM114-Status: GOOD ( 14.02 ) X-Spam-Score: -2.0 (--) X-Spam-Report: SpamAssassin version 3.4.0 on bombadil.infradead.org summary: Content analysis details: (-2.0 points) pts rule name description ---- ---------------------- -------------------------------------------------- -0.0 SPF_PASS SPF: sender matches SPF record -1.9 BAYES_00 BODY: Bayes spam probability is 0 to 1% [score: 0.0000] -0.1 DKIM_VALID_AU Message has a valid DKIM or DK signature from author's domain 0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily valid -0.1 DKIM_VALID Message has at least one valid DKIM or DK signature X-BeenThere: linux-arm-kernel@lists.infradead.org X-Mailman-Version: 2.1.20 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Cc: matt@codeblueprint.co.uk, david.brown@linaro.org, Ard Biesheuvel MIME-Version: 1.0 Sender: "linux-arm-kernel" Errors-To: linux-arm-kernel-bounces+patch=linaro.org@lists.infradead.org Since KASLR requires a relocatable kernel image anyway, there is no practical reason to refuse an image whose load address is not exactly TEXT_OFFSET bytes above a 2 MB aligned base address, as long as the physical and virtual misalignment with respect to the swapper block size are equal. So treat the misalignment of the physical load address as the initial KASLR offset, and fix up the remaining code to deal with that. Signed-off-by: Ard Biesheuvel --- arch/arm64/kernel/head.S | 16 ++++++++++++---- arch/arm64/kernel/kaslr.c | 6 +++--- 2 files changed, 15 insertions(+), 7 deletions(-) -- 2.5.0 _______________________________________________ linux-arm-kernel mailing list linux-arm-kernel@lists.infradead.org http://lists.infradead.org/mailman/listinfo/linux-arm-kernel diff --git a/arch/arm64/kernel/head.S b/arch/arm64/kernel/head.S index 1d4ae36db0bb..934d6dcd7a57 100644 --- a/arch/arm64/kernel/head.S +++ b/arch/arm64/kernel/head.S @@ -25,6 +25,7 @@ #include #include +#include #include #include #include @@ -211,8 +212,12 @@ section_table: ENTRY(stext) bl preserve_boot_args bl el2_setup // Drop to EL1, w20=cpu_boot_mode - mov x23, xzr // KASLR offset, defaults to 0 adrp x24, __PHYS_OFFSET +#ifdef CONFIG_RANDOMIZE_BASE + mov x23, xzr // KASLR offset, defaults to 0 +#else + and x23, x24, MIN_KIMG_ALIGN - 1 // unless loaded phys misaligned +#endif bl set_cpu_boot_mode_flag bl __create_page_tables // x25=TTBR0, x26=TTBR1 /* @@ -489,11 +494,13 @@ __mmap_switched: bl kasan_early_init #endif #ifdef CONFIG_RANDOMIZE_BASE - cbnz x23, 0f // already running randomized? + tst x23, ~(MIN_KIMG_ALIGN - 1) // already running randomized? + b.ne 0f mov x0, x21 // pass FDT address in x0 + mov x1, x23 // pass modulo offset in x1 bl kaslr_early_init // parse FDT for KASLR options cbz x0, 0f // KASLR disabled? just proceed - mov x23, x0 // record KASLR offset + orr x23, x23, x0 // record KASLR offset ret x28 // we must enable KASLR, return // to __enable_mmu() 0: @@ -753,7 +760,8 @@ __enable_mmu: isb #ifdef CONFIG_RANDOMIZE_BASE mov x19, x0 // preserve new SCTLR_EL1 value - blr x27 + add x30, x27, x23 + blr x30 /* * If we return here, we have a KASLR displacement in x23 which we need diff --git a/arch/arm64/kernel/kaslr.c b/arch/arm64/kernel/kaslr.c index 582983920054..b05469173ba5 100644 --- a/arch/arm64/kernel/kaslr.c +++ b/arch/arm64/kernel/kaslr.c @@ -74,7 +74,7 @@ extern void *__init __fixmap_remap_fdt(phys_addr_t dt_phys, int *size, * containing function pointers) to be reinitialized, and zero-initialized * .bss variables will be reset to 0. */ -u64 __init kaslr_early_init(u64 dt_phys) +u64 __init kaslr_early_init(u64 dt_phys, u64 modulo_offset) { void *fdt; u64 seed, offset, mask, module_range; @@ -132,8 +132,8 @@ u64 __init kaslr_early_init(u64 dt_phys) * boundary (for 4KB/16KB/64KB granule kernels, respectively). If this * happens, increase the KASLR offset by the size of the kernel image. */ - if ((((u64)_text + offset) >> SWAPPER_TABLE_SHIFT) != - (((u64)_end + offset) >> SWAPPER_TABLE_SHIFT)) + if ((((u64)_text + offset + modulo_offset) >> SWAPPER_TABLE_SHIFT) != + (((u64)_end + offset + modulo_offset) >> SWAPPER_TABLE_SHIFT)) offset = (offset + (u64)(_end - _text)) & mask; if (IS_ENABLED(CONFIG_KASAN))