Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.kernel > #1306157
| From | Andrey Ryabinin <aryabinin@virtuozzo.com> |
|---|---|
| Newsgroups | linux.kernel |
| Subject | [PATCH 2/2] x86/kasan: write protect kasan zero shadow |
| Date | 2016-01-11 14:00 +0100 |
| Message-ID | <qPKeK-2wl-1@gated-at.bofh.it> (permalink) |
| References | <qPtxg-8hk-17@gated-at.bofh.it> <qPKeK-2wl-3@gated-at.bofh.it> |
| Organization | linux.* mail to news gateway |
After kasan_init() executed, no one is allowed to write to kasan_zero_page,
so write protect it.
Signed-off-by: Andrey Ryabinin <aryabinin@virtuozzo.com>
---
arch/x86/mm/kasan_init_64.c | 10 ++++++++--
1 file changed, 8 insertions(+), 2 deletions(-)
diff --git a/arch/x86/mm/kasan_init_64.c b/arch/x86/mm/kasan_init_64.c
index 303e470..1b1110f 100644
--- a/arch/x86/mm/kasan_init_64.c
+++ b/arch/x86/mm/kasan_init_64.c
@@ -125,10 +125,16 @@ void __init kasan_init(void)
/*
* kasan_zero_page has been used as early shadow memory, thus it may
- * contain some garbage. Now we can clear it, since after the TLB flush
- * no one should write to it.
+ * contain some garbage. Now we can clear and write protect it, since
+ * after the TLB flush no one should write to it.
*/
memset(kasan_zero_page, 0, PAGE_SIZE);
+ for (i = 0; i < PTRS_PER_PTE; i++) {
+ pte_t pte = __pte(__pa(kasan_zero_page) | __PAGE_KERNEL_RO);
+ set_pte(&kasan_zero_pte[i], pte);
+ }
+ /* Flush TLBs again to be sure that write protection applied. */
+ __flush_tlb_all();
init_task.kasan_depth = 0;
pr_info("KernelAddressSanitizer initialized\n");
--
2.4.10
Back to linux.kernel | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
[RFC 01/13] x86/paravirt: Turn KASAN off for parvirt.o Andy Lutomirski <luto@kernel.org> - 2016-01-09 00:20 +0100
Re: [RFC 01/13] x86/paravirt: Turn KASAN off for parvirt.o Borislav Petkov <bp@alien8.de> - 2016-01-10 20:10 +0100
[PATCH 2/2] x86/kasan: write protect kasan zero shadow Andrey Ryabinin <aryabinin@virtuozzo.com> - 2016-01-11 14:00 +0100
Re: [RFC 01/13] x86/paravirt: Turn KASAN off for parvirt.o Andrey Ryabinin <aryabinin@virtuozzo.com> - 2016-01-11 14:00 +0100
[PATCH 1/2] x86/kasan: clear kasan_zero_page after TLB flush Andrey Ryabinin <aryabinin@virtuozzo.com> - 2016-01-11 14:00 +0100
csiph-web