Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1398346

[PATCH v8 4/4] x86/KASLR: Allow randomization below load address

Path csiph.com!aioe.org!bofh.it!news.nic.it!robomod
From Kees Cook <keescook@chromium.org>
Newsgroups linux.kernel
Subject [PATCH v8 4/4] x86/KASLR: Allow randomization below load address
Date Tue, 10 May 2016 19:30:03 +0200
Message-ID <rxjDR-75T-15@gated-at.bofh.it> (permalink)
References <rxjub-6Xg-17@gated-at.bofh.it>
Dkim-Signature v=1; a=rsa-sha256; c=relaxed/relaxed; d=chromium.org; s=google; h=from:to:cc:subject:date:message-id:in-reply-to:references; bh=sUW+dLCgfAiwFAxEoagl6qz/Y51uToMw/avxAituv8c=; b=FFgw1WXQIUwFnoAIv7+b8yXH7LgadLd+FYbiG7jtbK/qNi/ZnvN7KrjisyHZH3Q8JS 4rA8LZOwno1YoN9wCInTPjzbOVqOEa9yDbprSMLyIVDWUfdy+DiQy7pnUHIhwheO89VJ fLXR+4MIP/omDi/eW7x3igdEpYiwR/neiRI0s=
X-Google-Dkim-Signature v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:from:to:cc:subject:date:message-id:in-reply-to :references; bh=sUW+dLCgfAiwFAxEoagl6qz/Y51uToMw/avxAituv8c=; b=US9613FqorzlrOOZb4TOYiUzFsO5nF32ZrG9wl09nqBl1YoZvd3XOY/ww74ji38vlT iWG7TTHFC6163j54RGND2yC+EQfZid7ipbViA26X8UE5INuXs349jP+9ilBcsAPfNUIe 4A/VKRWeGKKtSSbD4x7/oK7yetiZLPKTCA/VmrT1wcddx4AkzaRYY+A8OwTPvtwm0GKe klG4il2UXBaKh7jMRC1R124VvghOAAjTw5c2CKMXd2xwY+v2pArnYCvVh5YiW5U64vC7 kGtWxJEZQzaWvyzqwH7b0n2rgn5e1LWxnftSRjTu2MDJde6QGUkHbjfDS1slnaly/EOs jlGA==
X-Gm-Message-State AOPr4FUvmKl+kpT1qK54HMNfrjmWWCpHzuEiyb0jdRaXGGC1iyHCvx8rp3o51EU4E9euQg==
X-Received by 10.98.19.131 with SMTP id 3mr60480592pft.17.1462900768483; Tue, 10 May 2016 10:19:28 -0700 (PDT)
X-Mailer git-send-email 2.6.3
Sender robomod@news.nic.it
List-ID <linux-kernel.vger.kernel.org>
X-Mailing-List linux-kernel@vger.kernel.org
Approved robomod@news.nic.it
Lines 49
Organization linux.* mail to news gateway
X-Original-Cc Kees Cook <keescook@chromium.org>, Yinghai Lu <yinghai@kernel.org>, Borislav Petkov <bp@suse.de>, Baoquan He <bhe@redhat.com>, Ingo Molnar <mingo@redhat.com>, "H. Peter Anvin" <hpa@zytor.com>, Borislav Petkov <bp@alien8.de>, Vivek Goyal <vgoyal@redhat.com>, Andy Lutomirski <luto@kernel.org>, lasse.collin@tukaani.org, Andrew Morton <akpm@linux-foundation.org>, Dave Young <dyoung@redhat.com>, kernel-hardening@lists.openwall.com, LKML <linux-kernel@vger.kernel.org>
X-Original-Date Tue, 10 May 2016 10:19:15 -0700
X-Original-Message-ID <1462900755-20005-5-git-send-email-keescook@chromium.org>
X-Original-References <1462900755-20005-1-git-send-email-keescook@chromium.org>
X-Original-Sender linux-kernel-owner@vger.kernel.org
Xref csiph.com linux.kernel:1398346

Show key headers only | View raw


From: Yinghai Lu <yinghai@kernel.org>

Currently the physical randomization's lower boundary is the original
kernel load address. For bootloaders that load kernels into very high
memory (e.g. kexec), this means randomization takes place in a very small
window at the top of memory, ignoring the large region of physical memory
below the load address.

Since mem_avoid is already correctly tracking the regions that must be
avoided, this patch changes the minimum address to whatever is less:
512M (to conservatively avoid unknown things in lower memory) or the
load address. Now, for example, if the kernel is loaded at 8G, [512M,
8G) will be added into possible physical memory positions.

Signed-off-by: Yinghai Lu <yinghai@kernel.org>
[kees: rewrote changelog, refactor to use min()]
Signed-off-by: Kees Cook <keescook@chromium.org>
---
 arch/x86/boot/compressed/kaslr.c | 7 +++++--
 1 file changed, 5 insertions(+), 2 deletions(-)

diff --git a/arch/x86/boot/compressed/kaslr.c b/arch/x86/boot/compressed/kaslr.c
index d0a823df183b..304c5c369aff 100644
--- a/arch/x86/boot/compressed/kaslr.c
+++ b/arch/x86/boot/compressed/kaslr.c
@@ -492,7 +492,7 @@ void choose_random_location(unsigned long input,
 			    unsigned long output_size,
 			    unsigned long *virt_addr)
 {
-	unsigned long random_addr;
+	unsigned long random_addr, min_addr;
 
 	/* By default, keep output position unchanged. */
 	*virt_addr = *output;
@@ -517,8 +517,11 @@ void choose_random_location(unsigned long input,
 	/* Record the various known unsafe memory ranges. */
 	mem_avoid_init(input, input_size, *output);
 
+	/* Low end should be the smaller of 512M or initial location. */
+	min_addr = min(*output, 512UL << 20);
+
 	/* Walk e820 and find a random address. */
-	random_addr = find_random_phys_addr(*output, output_size);
+	random_addr = find_random_phys_addr(min_addr, output_size);
 	if (!random_addr) {
 		warn("KASLR disabled: could not find suitable E820 region!");
 	} else {
-- 
2.6.3

Back to linux.kernel | Previous | Next | Find similar | Unroll thread


Thread

[PATCH v8 4/4] x86/KASLR: Allow randomization below load address Kees Cook <keescook@chromium.org> - 2016-05-10 19:30 +0200

csiph-web