Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1407277

[PATCH v9 1/5] x86/boot: Refuse to build with data relocations

Path csiph.com!news.mixmin.net!aioe.org!gothmog.csi.it!bofh.it!news.nic.it!robomod
From Kees Cook <keescook@chromium.org>
Newsgroups linux.kernel
Subject [PATCH v9 1/5] x86/boot: Refuse to build with data relocations
Date Thu, 26 May 2016 00:50:02 +0200
Message-ID <rCPMK-6CF-17@gated-at.bofh.it> (permalink)
References <rCPMK-6CF-13@gated-at.bofh.it>
X-Original-To Ingo Molnar <mingo@kernel.org>
Dkim-Signature v=1; a=rsa-sha256; c=relaxed/relaxed; d=chromium.org; s=google; h=from:to:cc:subject:date:message-id:in-reply-to:references; bh=thwPST03AS4k5vbKdKb5CXwg782jd6MBRrbBgpguUUA=; b=T6rKp2G6sKNqlXWjKK3Tx5Tp3Km5UEH1q8ZT3ok/LDwhr6GpEhoYjvQWpT2YUqP3MR 3oi+Vxdi7Y8nY7wRU7lLqH+qqQBghAwh11ImBTfL4thtTWGed5wy7uVI8HQyX3F4L3hC kZWw5XkTv2n/aJ+palcEjjjlLIXku5sjEhWjg=
X-Google-Dkim-Signature v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:from:to:cc:subject:date:message-id:in-reply-to :references; bh=thwPST03AS4k5vbKdKb5CXwg782jd6MBRrbBgpguUUA=; b=Qoq7f8+Bwy6fTd5oSE8lxrkqaheJLctNfIeTEM74rDkfDAlQcIXk0FTM6Ap5S6ZS88 j7fXb5WUvNnDJjstlLmwrnYTezwFLZFSpuqu0XJwptzqq9owFd0ThJt2bM+u3grFPvAG lxvWZJqwTNaUio5ensPmudS+VigDWwWSaEzS9FwN4X7gxlWlbG2rJgh9BxIc4z2YnOSK Fa01bldbIgMLFRkJxhRlNbET+HVBVaRcngX+DskSkKwnJ3V432Di7gGnve98l6C+vYYG 3rtPEgXcLPpqaeWJjz/CU6iLx2s09HZgDpSC4aXjhkfXzzl+EWau9rHLVKshQJRCvhc5 Vzkw==
X-Gm-Message-State ALyK8tJ5y0obg+9cFuOd5dmuFoM01Wx5Aeg5OAJB94+f5ZrUKboI90LfqKufrJ499FnVXqC/
X-Received by 10.66.171.231 with SMTP id ax7mr9282622pac.104.1464216340616; Wed, 25 May 2016 15:45:40 -0700 (PDT)
X-Mailer git-send-email 2.6.3
Sender robomod@news.nic.it
List-ID <linux-kernel.vger.kernel.org>
X-Mailing-List linux-kernel@vger.kernel.org
Approved robomod@news.nic.it
Lines 65
Organization linux.* mail to news gateway
X-Original-Cc Kees Cook <keescook@chromium.org>, Borislav Petkov <bp@suse.de>, Baoquan He <bhe@redhat.com>, Yinghai Lu <yinghai@kernel.org>, "H. Peter Anvin" <hpa@zytor.com>, Thomas Gleixner <tglx@linutronix.de>, Ingo Molnar <mingo@redhat.com>, "x86@kernel.org" <x86@kernel.org>, Andrew Morton <akpm@linux-foundation.org>, Josh Poimboeuf <jpoimboe@redhat.com>, Andrey Ryabinin <aryabinin@virtuozzo.com>, "H.J. Lu" <hjl.tools@gmail.com>, Dmitry Vyukov <dvyukov@google.com>, LKML <linux-kernel@vger.kernel.org>
X-Original-Date Wed, 25 May 2016 15:45:30 -0700
X-Original-Message-ID <1464216334-17200-2-git-send-email-keescook@chromium.org>
X-Original-References <1464216334-17200-1-git-send-email-keescook@chromium.org>
X-Original-Sender linux-kernel-owner@vger.kernel.org
Xref csiph.com linux.kernel:1407277

Show key headers only | View raw


The compressed kernel is built with -fPIC/-fPIE so that it can run in any
location a bootloader happens to put it. However, since ELF relocation
processing is not happening (and all the relocation information has
already been stripped at link time), none of the code can use data
relocations (e.g. static assignments of pointers). This is already noted
in a warning comment at the top of misc.c, but this adds an explicit
check for the condition during the linking stage to block any such bugs
from appearing.

If this was in place with the earlier bug in pagetable.c, the build
would fail like this:

  ...
    CC      arch/x86/boot/compressed/pagetable.o
    DATAREL arch/x86/boot/compressed/vmlinux
  error: arch/x86/boot/compressed/pagetable.o has data relocations!
  make[2]: *** [arch/x86/boot/compressed/vmlinux] Error 1
  ...

A clean build shows:

  ...
    CC      arch/x86/boot/compressed/pagetable.o
    DATAREL arch/x86/boot/compressed/vmlinux
    LD      arch/x86/boot/compressed/vmlinux
  ...

Suggested-by: Ingo Molnar <mingo@kernel.org>
Signed-off-by: Kees Cook <keescook@chromium.org>
---
 arch/x86/boot/compressed/Makefile | 18 ++++++++++++++++++
 1 file changed, 18 insertions(+)

diff --git a/arch/x86/boot/compressed/Makefile b/arch/x86/boot/compressed/Makefile
index cfdd8c3f8af2..e69464792beb 100644
--- a/arch/x86/boot/compressed/Makefile
+++ b/arch/x86/boot/compressed/Makefile
@@ -85,7 +85,25 @@ vmlinux-objs-$(CONFIG_EFI_STUB) += $(obj)/eboot.o $(obj)/efi_stub_$(BITS).o \
 	$(objtree)/drivers/firmware/efi/libstub/lib.a
 vmlinux-objs-$(CONFIG_EFI_MIXED) += $(obj)/efi_thunk_$(BITS).o
 
+# The compressed kernel is built with -fPIC/-fPIE so that a boot loader
+# can place it anywhere in memory and it will still run. However, since
+# it is executed as-is without any ELF relocation processing performed
+# (and has already had all relocation sections stripped from the binary),
+# none of the code can use data relocations (e.g. static assignments of
+# pointer values), since they will be meaningless at runtime. This check
+# will refuse to link the vmlinux if any of these relocations are found.
+quiet_cmd_check_data_rel = DATAREL $@
+define cmd_check_data_rel
+	for obj in $(filter %.o,$^); do \
+		readelf -S $$obj | grep -qF .rel.local && { \
+			echo "error: $$obj has data relocations!" >&2; \
+			exit 1; \
+		} || true; \
+	done
+endef
+
 $(obj)/vmlinux: $(vmlinux-objs-y) FORCE
+	$(call if_changed,check_data_rel)
 	$(call if_changed,ld)
 	@:
 
-- 
2.6.3

Back to linux.kernel | Previous | Next | Find similar | Unroll thread


Thread

[PATCH v9 1/5] x86/boot: Refuse to build with data relocations Kees Cook <keescook@chromium.org> - 2016-05-26 00:50 +0200

csiph-web