Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1428990

Re: [kernel-hardening] [PATCH v7 0/9] x86/mm: memory area address KASLR

From Kees Cook <keescook@chromium.org>
Newsgroups linux.kernel
Subject Re: [kernel-hardening] [PATCH v7 0/9] x86/mm: memory area address KASLR
Date 2016-06-22 19:10 +0200
Message-ID <rMTP4-6im-21@gated-at.bofh.it> (permalink)
References <rMEwF-4Et-3@gated-at.bofh.it> <rMPLr-3pV-9@gated-at.bofh.it> <rMSJk-5mw-35@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


On Wed, Jun 22, 2016 at 8:59 AM, Thomas Garnier <thgarnie@google.com> wrote:
> On Wed, Jun 22, 2016 at 5:47 AM, Jason Cooper <jason@lakedaemon.net> wrote:
>> Hey Kees,
>>
>> On Tue, Jun 21, 2016 at 05:46:57PM -0700, Kees Cook wrote:
>>> Notable problems that needed solving:
>> ...
>>>  - Reasonable entropy is needed early at boot before get_random_bytes()
>>>    is available.
>>
>> This series is targetting x86, which typically has RDRAND/RDSEED
>> instructions.  Are you referring to other arches?  Older x86?  Also,
>> isn't this the same requirement for base address KASLR?
>>
>> Don't get me wrong, I want more diverse entropy sources available
>> earlier in the boot process as well. :-)  I'm just wondering what's
>> different about this series vs base address KASLR wrt early entropy
>> sources.
>>
>
> I think Kees was referring to the refactor I did to get the similar
> entropy generation than KASLR module randomization. Our approach was
> to provide best entropy possible even if you have an older processor
> or under virtualization without support for these instructions.
> Unfortunately common on companies with a large number of older
> machines.

Right, the memory offset KASLR uses the same routines as the kernel
base KASLR. The issue is with older x86 systems, which continue to be
very common.

-Kees

-- 
Kees Cook
Chrome OS & Brillo Security

Back to linux.kernel | Previous | NextPrevious in thread | Find similar | Unroll thread


Thread

[PATCH v7 0/9] x86/mm: memory area address KASLR Kees Cook <keescook@chromium.org> - 2016-06-22 02:50 +0200
  [PATCH v7 4/9] x86/mm: Separate variable for trampoline PGD (x86_64) Kees Cook <keescook@chromium.org> - 2016-06-22 02:50 +0200
  Re: [kernel-hardening] [PATCH v7 0/9] x86/mm: memory area address  KASLR Jason Cooper <jason@lakedaemon.net> - 2016-06-22 14:50 +0200
    Re: [kernel-hardening] [PATCH v7 0/9] x86/mm: memory area address KASLR Thomas Garnier <thgarnie@google.com> - 2016-06-22 18:00 +0200
      Re: [kernel-hardening] [PATCH v7 0/9] x86/mm: memory area address KASLR Kees Cook <keescook@chromium.org> - 2016-06-22 19:10 +0200

csiph-web