Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1301823

[PATCH 3.12 25/91] x86/setup: Extend low identity map to cover whole kernel range

From Jiri Slaby <jslaby@suse.cz>
Newsgroups linux.kernel
Subject [PATCH 3.12 25/91] x86/setup: Extend low identity map to cover whole kernel range
Date 2016-01-05 19:10 +0100
Message-ID <qNEdv-6sw-77@gated-at.bofh.it> (permalink)
References <qNDU6-65D-3@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


From: Paolo Bonzini <pbonzini@redhat.com>

3.12-stable review patch.  If anyone has any objections, please let me know.

===============

commit f5f3497cad8c8416a74b9aaceb127908755d020a upstream.

On 32-bit systems, the initial_page_table is reused by
efi_call_phys_prolog as an identity map to call
SetVirtualAddressMap.  efi_call_phys_prolog takes care of
converting the current CPU's GDT to a physical address too.

For PAE kernels the identity mapping is achieved by aliasing the
first PDPE for the kernel memory mapping into the first PDPE
of initial_page_table.  This makes the EFI stub's trick "just work".

However, for non-PAE kernels there is no guarantee that the identity
mapping in the initial_page_table extends as far as the GDT; in this
case, accesses to the GDT will cause a page fault (which quickly becomes
a triple fault).  Fix this by copying the kernel mappings from
swapper_pg_dir to initial_page_table twice, both at PAGE_OFFSET and at
identity mapping.

For some reason, this is only reproducible with QEMU's dynamic translation
mode, and not for example with KVM.  However, even under KVM one can clearly
see that the page table is bogus:

    $ qemu-system-i386 -pflash OVMF.fd -M q35 vmlinuz0 -s -S -daemonize
    $ gdb
    (gdb) target remote localhost:1234
    (gdb) hb *0x02858f6f
    Hardware assisted breakpoint 1 at 0x2858f6f
    (gdb) c
    Continuing.

    Breakpoint 1, 0x02858f6f in ?? ()
    (gdb) monitor info registers
    ...
    GDT=     0724e000 000000ff
    IDT=     fffbb000 000007ff
    CR0=0005003b CR2=ff896000 CR3=032b7000 CR4=00000690
    ...

The page directory is sane:

    (gdb) x/4wx 0x32b7000
    0x32b7000:	0x03398063	0x03399063	0x0339a063	0x0339b063
    (gdb) x/4wx 0x3398000
    0x3398000:	0x00000163	0x00001163	0x00002163	0x00003163
    (gdb) x/4wx 0x3399000
    0x3399000:	0x00400003	0x00401003	0x00402003	0x00403003

but our particular page directory entry is empty:

    (gdb) x/1wx 0x32b7000 + (0x724e000 >> 22) * 4
    0x32b7070:	0x00000000

[ It appears that you can skate past this issue if you don't receive
  any interrupts while the bogus GDT pointer is loaded, or if you avoid
  reloading the segment registers in general.

  Andy Lutomirski provides some additional insight:

   "AFAICT it's entirely permissible for the GDTR and/or LDT
    descriptor to point to unmapped memory.  Any attempt to use them
    (segment loads, interrupts, IRET, etc) will try to access that memory
    as if the access came from CPL 0 and, if the access fails, will
    generate a valid page fault with CR2 pointing into the GDT or
    LDT."

  Up until commit 23a0d4e8fa6d ("efi: Disable interrupts around EFI
  calls, not in the epilog/prolog calls") interrupts were disabled
  around the prolog and epilog calls, and the functional GDT was
  re-installed before interrupts were re-enabled.

  Which explains why no one has hit this issue until now. ]

Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
Reported-by: Laszlo Ersek <lersek@redhat.com>
Cc: <stable@vger.kernel.org>
Cc: Borislav Petkov <bp@alien8.de>
Cc: "H. Peter Anvin" <hpa@zytor.com>
Cc: Thomas Gleixner <tglx@linutronix.de>
Cc: Ingo Molnar <mingo@kernel.org>
Cc: Andy Lutomirski <luto@amacapital.net>
Signed-off-by: Matt Fleming <matt.fleming@intel.com>
[ Updated changelog. ]
Signed-off-by: Jiri Slaby <jslaby@suse.cz>
---
 arch/x86/kernel/setup.c | 8 ++++++++
 1 file changed, 8 insertions(+)

diff --git a/arch/x86/kernel/setup.c b/arch/x86/kernel/setup.c
index f0de6294b955..29ecd5e00605 100644
--- a/arch/x86/kernel/setup.c
+++ b/arch/x86/kernel/setup.c
@@ -1154,6 +1154,14 @@ void __init setup_arch(char **cmdline_p)
 	clone_pgd_range(initial_page_table + KERNEL_PGD_BOUNDARY,
 			swapper_pg_dir     + KERNEL_PGD_BOUNDARY,
 			KERNEL_PGD_PTRS);
+
+	/*
+	 * sync back low identity map too.  It is used for example
+	 * in the 32-bit EFI stub.
+	 */
+	clone_pgd_range(initial_page_table,
+			swapper_pg_dir     + KERNEL_PGD_BOUNDARY,
+			KERNEL_PGD_PTRS);
 #endif
 
 	tboot_probe();
-- 
2.6.4

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

Back to linux.kernel | Previous | NextPrevious in thread | Next in thread | Find similar | Unroll thread


Thread

[PATCH 3.12 00/91] 3.12.52-stable review Jiri Slaby <jslaby@suse.cz> - 2016-01-05 18:50 +0100
  [PATCH 3.12 01/91] ipv6: fix tunnel error handling Jiri Slaby <jslaby@suse.cz> - 2016-01-05 18:50 +0100
    [PATCH 3.12 68/91] sctp: use the same clock as if sock source timestamps were on Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:00 +0100
    [PATCH 3.12 73/91] net: fix IP early demux races Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:00 +0100
    [PATCH 3.12 62/91] USB: cp210x: Remove CP2110 ID from compatibility list Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:00 +0100
    [PATCH 3.12 81/91] ahci: add new Intel device IDs Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:00 +0100
    [PATCH 3.12 75/91] skbuff: Fix offset error in skb_reorder_vlan_header Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:00 +0100
    [PATCH 3.12 71/91] net: add validation for the socket syscall protocol argument Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:00 +0100
    [PATCH 3.12 63/91] USB: add quirk for devices with broken LPM Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:00 +0100
    [PATCH 3.12 57/91] nfs4: start callback_ident at idr 1 Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:00 +0100
    [PATCH 3.12 58/91] nfs: if we have no valid attrs, then don't declare the attribute cache valid Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:00 +0100
    [PATCH 3.12 74/91] vlan: Fix untag operations of stacked vlans with REORDER_HEADER off Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:00 +0100
    [PATCH 3.12 48/91] netfilter: ipt_rpfilter: remove the nh_scope test in rpfilter_lookup_reverse Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:00 +0100
    [PATCH 3.12 86/91] i2c: i801: add Intel Lewisburg device IDs Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:00 +0100
    [PATCH 3.12 61/91] USB: serial: Another Infineon flash loader USB ID Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:00 +0100
    [PATCH 3.12 51/91] ip6mr: call del_timer_sync() in ip6mr_free_table() Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:00 +0100
    [PATCH 3.12 60/91] USB: cdc_acm: Ignore Infineon Flash Loader utility Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:00 +0100
    [PATCH 3.12 77/91] bluetooth: Validate socket address length in sco_sock_bind(). Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:00 +0100
    [PATCH 3.12 65/91] usb: Use the USB_SS_MULT() macro to decode burst multiplier for log message Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:00 +0100
    [PATCH 3.12 69/91] sctp: update the netstamp_needed counter when copying sockets Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:00 +0100
    [PATCH 3.12 72/91] sh_eth: fix kernel oops in skb_put() Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:00 +0100
    [PATCH 3.12 64/91] USB: whci-hcd: add check for dma mapping error Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:00 +0100
    [PATCH 3.12 76/91] pptp: verify sockaddr_len in pptp_bind() and pptp_connect() Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:00 +0100
    [PATCH 3.12 91/91] HID: dragonrise: fix HID Descriptor for 0x0006 PID Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:00 +0100
    [PATCH 3.12 87/91] cdrom: Random writing support for BD-RE media Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:00 +0100
    [PATCH 3.12 70/91] ipv6: sctp: clone options to avoid use after free Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:00 +0100
    [PATCH 3.12 59/91] ocfs2: fix umask ignored issue Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:00 +0100
    [PATCH 3.12 67/91] atl1c: Improve driver not to do order 4 GFP_ATOMIC allocation Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:00 +0100
    [PATCH 3.12 85/91] i2c: i801: Add support for Intel Broxton Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:00 +0100
    [PATCH 3.12 82/91] target/stat: print full t10_wwn.model buffer Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:00 +0100
    [PATCH 3.12 90/91] gpio/omap: raw read and write endian fix Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:00 +0100
    [PATCH 3.12 36/91] can: sja1000: clear interrupts on start Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:10 +0100
    [PATCH 3.12 29/91] mac80211: fix driver RSSI event calculations Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:10 +0100
    [PATCH 3.12 38/91] usblp: do not set TASK_INTERRUPTIBLE before lock Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:10 +0100
    [PATCH 3.12 47/91] module: Call module notifier on failure after complete_formation() Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:10 +0100
    [PATCH 3.12 27/91] x86/cpu: Call verify_cpu() after having entered long mode too Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:10 +0100
    [PATCH 3.12 32/91] staging: rtl8712: Add device ID for Sitecom WLA2100 Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:10 +0100
    [PATCH 3.12 41/91] USB: serial: option: add support for Novatel MiFi USB620L Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:10 +0100
    [PATCH 3.12 56/91] firewire: ohci: fix JMicron JMB38x IT context discovery Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:10 +0100
    [PATCH 3.12 46/91] tty: fix stall caused by missing memory barrier in drivers/tty/n_tty.c Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:10 +0100
    [PATCH 3.12 37/91] arm64: Fix compat register mappings Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:10 +0100
    [PATCH 3.12 30/91] net: mvneta: Fix CPU_MAP registers initialisation Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:10 +0100
    [PATCH 3.12 26/91] x86/setup: Fix low identity map for >= 2GB kernel range Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:10 +0100
    [PATCH 3.12 53/91] Btrfs: fix race leading to BUG_ON when running delalloc for nodatacow Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:10 +0100
    [PATCH 3.12 55/91] ext4, jbd2: ensure entering into panic after recording an error in superblock Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:10 +0100
    [PATCH 3.12 66/91] gre6: allow to update all parameters via rtnl Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:10 +0100
    [PATCH 3.12 43/91] ALSA: usb-audio: add packet size quirk for the Medeli DD305 Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:10 +0100
    [PATCH 3.12 54/91] ext4: fix potential use after free in __ext4_journal_stop Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:10 +0100
    [PATCH 3.12 24/91] ARM: common: edma: Fix channel parameter for irq callbacks Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:10 +0100
    [PATCH 3.12 14/91] net: ipmr: fix static mfc/dev leaks on table destruction Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:10 +0100
    [PATCH 3.12 39/91] usb: musb: core: fix order of arguments to ulpi write callback Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:10 +0100
    [PATCH 3.12 45/91] ALSA: usb-audio: work around CH345 input SysEx corruption Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:10 +0100
    [PATCH 3.12 40/91] USB: ti_usb_3410_5052: Add Honeywell HGI80 ID Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:10 +0100
    [PATCH 3.12 31/91] mwifiex: fix mwifiex_rdeeprom_read() Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:10 +0100
    [PATCH 3.12 52/91] Btrfs: fix race leading to incorrect item deletion when dropping extents Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:10 +0100
    [PATCH 3.12 33/91] Bluetooth: hidp: fix device disconnect on idle timeout Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:10 +0100
    [PATCH 3.12 25/91] x86/setup: Extend low identity map to cover whole kernel range Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:10 +0100
      Re: [PATCH 3.12 25/91] x86/setup: Extend low identity map to cover  whole kernel range Paolo Bonzini <pbonzini@redhat.com> - 2016-01-06 11:50 +0100
        Re: [PATCH 3.12 25/91] x86/setup: Extend low identity map to cover  whole kernel range Matt Fleming <matt@codeblueprint.co.uk> - 2016-01-06 12:10 +0100
          Re: [PATCH 3.12 25/91] x86/setup: Extend low identity map to cover  whole kernel range Luis Henriques <luis.henriques@canonical.com> - 2016-01-06 12:30 +0100
            Re: [PATCH 3.12 25/91] x86/setup: Extend low identity map to cover  whole kernel range Matt Fleming <matt@codeblueprint.co.uk> - 2016-01-06 14:40 +0100
              Re: [PATCH 3.12 25/91] x86/setup: Extend low identity map to cover  whole kernel range Luis Henriques <luis.henriques@canonical.com> - 2016-01-06 15:30 +0100
                Re: [PATCH 3.12 25/91] x86/setup: Extend low identity map to cover  whole kernel range Matt Fleming <matt@codeblueprint.co.uk> - 2016-01-08 13:00 +0100
                Re: [PATCH 3.12 25/91] x86/setup: Extend low identity map to cover  whole kernel range Luis Henriques <luis.henriques@canonical.com> - 2016-01-08 14:40 +0100
                Re: [PATCH 3.12 25/91] x86/setup: Extend low identity map to cover  whole kernel range Jiri Slaby <jslaby@suse.cz> - 2016-01-09 08:10 +0100
                Re: [PATCH 3.12 25/91] x86/setup: Extend low identity map to cover  whole kernel range Kamal Mostafa <kamal@canonical.com> - 2016-01-14 22:00 +0100
    [PATCH 3.12 34/91] Bluetooth: ath3k: Add new AR3012 0930:021c id Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:10 +0100
    [PATCH 3.12 44/91] ALSA: usb-audio: prevent CH345 multiport output SysEx corruption Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:10 +0100
    [PATCH 3.12 35/91] Bluetooth: ath3k: Add support of AR3012 0cf3:817b device Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:10 +0100
    [PATCH 3.12 28/91] x86/cpu: Fix SMAP check in PVOPS environments Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:10 +0100
    [PATCH 3.12 49/91] netfilter: ip6t_SYNPROXY: fix NULL pointer dereference Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:10 +0100
    [PATCH 3.12 42/91] USB: option: add XS Stick W100-2 from 4G Systems Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:10 +0100
    [PATCH 3.12 10/91] net: qmi_wwan: add XS Stick W100-2 from 4G Systems Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:20 +0100
    [PATCH 3.12 11/91] tcp: md5: fix lockdep annotation Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:20 +0100
    [PATCH 3.12 19/91] net/neighbour: fix crash at dumping device-agnostic proxy entries Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:20 +0100
    [PATCH 3.12 23/91] ARM: 8427/1: dma-mapping: add support for offset parameter in dma_mmap() Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:20 +0100
    [PATCH 3.12 07/91] packet: infer protocol from ethernet header if unset Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:20 +0100
    [PATCH 3.12 21/91] Bluetooth: ath3k: Add support of 04ca:300d AR3012 device Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:20 +0100
    [PATCH 3.12 08/91] sctp: translate host order to network order when setting a hmacid Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:20 +0100
    [PATCH 3.12 22/91] ARM: 8426/1: dma-mapping: add missing range check in dma_mmap() Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:20 +0100
    [PATCH 3.12 05/91] unix: avoid use-after-free in ep_remove_wait_queue Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:20 +0100
    [PATCH 3.12 02/91] MIPS: KVM: Fix ASID restoration logic Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:20 +0100
    [PATCH 3.12 20/91] ipv6: sctp: implement sctp_v6_destroy_sock() Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:20 +0100
    [PATCH 3.12 13/91] net, scm: fix PaX detected msg_controllen overflow in scm_detach_fds Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:20 +0100
    [PATCH 3.12 18/91] ipv6: add complete rcu protection around np->opt Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:20 +0100
    [PATCH 3.12 12/91] tcp: initialize tp->copied_seq in case of cross SYN connection Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:20 +0100
    [PATCH 3.12 04/91] MIPS: KVM: Uninit VCPU in vcpu_create error path Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:20 +0100
    [PATCH 3.12 06/91] packet: do skb_probe_transport_header when we actually have data Jiri Slaby <jslaby@suse.cz> - 2016-01-05 19:20 +0100
  Re: [PATCH 3.12 00/91] 3.12.52-stable review Guenter Roeck <linux@roeck-us.net> - 2016-01-05 21:50 +0100
    Re: [PATCH 3.12 00/91] 3.12.52-stable review Jiri Slaby <jslaby@suse.cz> - 2016-01-09 09:50 +0100
  Re: [PATCH 3.12 00/91] 3.12.52-stable review Shuah Khan <shuahkh@osg.samsung.com> - 2016-01-05 22:20 +0100
  Re: [PATCH 3.12 00/91] 3.12.52-stable review Nikolay Borisov <kernel@kyup.com> - 2016-01-06 08:40 +0100
    Re: [PATCH 3.12 00/91] 3.12.52-stable review Greg KH <gregkh@linuxfoundation.org> - 2016-01-06 09:20 +0100

csiph-web