Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.kernel > #1552475
| From | Andy Lutomirski <luto@amacapital.net> |
|---|---|
| Newsgroups | linux.kernel |
| Subject | Re: [RFC] x86/mm/KASLR: Remap GDTs at fixed location |
| Date | 2017-01-06 03:40 +0100 |
| Message-ID | <sWsBH-3nj-5@gated-at.bofh.it> (permalink) |
| References | (2 earlier) <sWkNQ-6Cu-7@gated-at.bofh.it> <sWlAe-791-39@gated-at.bofh.it> <sWlJT-7ej-21@gated-at.bofh.it> <sWmFY-7Qg-23@gated-at.bofh.it> <sWpkt-1cs-19@gated-at.bofh.it> |
| Organization | linux.* mail to news gateway |
On Thu, Jan 5, 2017 at 3:05 PM, Linus Torvalds <torvalds@linux-foundation.org> wrote: > On Thu, Jan 5, 2017 at 12:18 PM, Andy Lutomirski <luto@kernel.org> wrote: >> >> Hmm. I bet that if we preset the accessed bits in all the segments >> then we don't need it to be writable in general. > > I'm not sure that this is architecturally safe. > Hmm. Last time I looked, I couldn't find *anything* in the SDM explaining what happened if a GDT access resulted in a page fault. I did discover that Xen intentionally (!) lazily populates and maps LDT pages. An attempt to access a not-present page results in #PF with the error cod e indicating kernel access even if the access came from user mode. SDM volume 3 7.2.2 says "Pages corresponding to the previous task’s TSS, the current task’s TSS, and the descriptor table entries for each all should be marked as read/write." But I don't see how a CPU implementation could possibly care what the page table for the TSS descriptor table entries says after LTR is done because the CPU isn't even supposed to *read* that memory. OTOH a valid implementation could easily require that the page table says that the page is writable merely to load a segment, especially in weird cases (IRET?). That being said, this is all quite easy to test. Also, Thomas, why are you creating a new memory region? I don't see any benefit to randomizing the GDT address. How about just putting it in the fixmap? This would be NR_CPUS * 4 pages if do my limit=0xffff idea. I'm not sure if the fixmap code knows how to handle this much space.
Back to linux.kernel | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
[RFC] x86/mm/KASLR: Remap GDTs at fixed location Thomas Garnier <thgarnie@google.com> - 2017-01-04 23:20 +0100
Re: [RFC] x86/mm/KASLR: Remap GDTs at fixed location Ingo Molnar <mingo@kernel.org> - 2017-01-05 09:30 +0100
Re: [RFC] x86/mm/KASLR: Remap GDTs at fixed location Arjan van de Ven <arjan@linux.intel.com> - 2017-01-05 16:10 +0100
Re: [RFC] x86/mm/KASLR: Remap GDTs at fixed location Thomas Garnier <thgarnie@google.com> - 2017-01-05 17:50 +0100
Re: [RFC] x86/mm/KASLR: Remap GDTs at fixed location Arjan van de Ven <arjan@linux.intel.com> - 2017-01-05 20:10 +0100
Re: [RFC] x86/mm/KASLR: Remap GDTs at fixed location Thomas Garnier <thgarnie@google.com> - 2017-01-05 20:10 +0100
Re: [RFC] x86/mm/KASLR: Remap GDTs at fixed location Borislav Petkov <bp@alien8.de> - 2017-01-06 18:50 +0100
Re: [RFC] x86/mm/KASLR: Remap GDTs at fixed location Thomas Garnier <thgarnie@google.com> - 2017-01-06 19:10 +0100
Re: [RFC] x86/mm/KASLR: Remap GDTs at fixed location Thomas Garnier <thgarnie@google.com> - 2017-01-05 17:40 +0100
Re: [RFC] x86/mm/KASLR: Remap GDTs at fixed location Ingo Molnar <mingo@kernel.org> - 2017-01-06 07:40 +0100
Re: [RFC] x86/mm/KASLR: Remap GDTs at fixed location Thomas Garnier <thgarnie@google.com> - 2017-01-05 19:20 +0100
Re: [RFC] x86/mm/KASLR: Remap GDTs at fixed location Andy Lutomirski <luto@amacapital.net> - 2017-01-05 19:40 +0100
Re: [RFC] x86/mm/KASLR: Remap GDTs at fixed location Thomas Garnier <thgarnie@google.com> - 2017-01-05 19:40 +0100
Re: [RFC] x86/mm/KASLR: Remap GDTs at fixed location Arjan van de Ven <arjan@linux.intel.com> - 2017-01-05 20:10 +0100
Re: [RFC] x86/mm/KASLR: Remap GDTs at fixed location Thomas Garnier <thgarnie@google.com> - 2017-01-05 20:20 +0100
Re: [RFC] x86/mm/KASLR: Remap GDTs at fixed location Andy Lutomirski <luto@kernel.org> - 2017-01-05 21:20 +0100
Re: [RFC] x86/mm/KASLR: Remap GDTs at fixed location Thomas Garnier <thgarnie@google.com> - 2017-01-05 22:10 +0100
Re: [RFC] x86/mm/KASLR: Remap GDTs at fixed location Andy Lutomirski <luto@amacapital.net> - 2017-01-05 22:30 +0100
Re: [RFC] x86/mm/KASLR: Remap GDTs at fixed location Thomas Garnier <thgarnie@google.com> - 2017-01-05 23:00 +0100
Re: [RFC] x86/mm/KASLR: Remap GDTs at fixed location Ingo Molnar <mingo@kernel.org> - 2017-01-06 08:00 +0100
Re: [RFC] x86/mm/KASLR: Remap GDTs at fixed location Thomas Garnier <thgarnie@google.com> - 2017-01-06 19:10 +0100
Re: [RFC] x86/mm/KASLR: Remap GDTs at fixed location Andy Lutomirski <luto@kernel.org> - 2017-01-06 23:30 +0100
Re: [RFC] x86/mm/KASLR: Remap GDTs at fixed location Thomas Garnier <thgarnie@google.com> - 2017-01-07 00:00 +0100
Re: [RFC] x86/mm/KASLR: Remap GDTs at fixed location Andy Lutomirski <luto@kernel.org> - 2017-01-07 00:40 +0100
Re: [RFC] x86/mm/KASLR: Remap GDTs at fixed location Ingo Molnar <mingo@kernel.org> - 2017-01-07 08:50 +0100
Re: [RFC] x86/mm/KASLR: Remap GDTs at fixed location Andy Lutomirski <luto@amacapital.net> - 2017-01-07 17:00 +0100
Re: [RFC] x86/mm/KASLR: Remap GDTs at fixed location Ingo Molnar <mingo@kernel.org> - 2017-01-07 08:40 +0100
Re: [RFC] x86/mm/KASLR: Remap GDTs at fixed location Andy Lutomirski <luto@amacapital.net> - 2017-01-07 17:10 +0100
Re: [RFC] x86/mm/KASLR: Remap GDTs at fixed location Thomas Garnier <thgarnie@google.com> - 2017-01-09 23:40 +0100
Re: [RFC] x86/mm/KASLR: Remap GDTs at fixed location Ingo Molnar <mingo@kernel.org> - 2017-01-10 11:30 +0100
Re: [RFC] x86/mm/KASLR: Remap GDTs at fixed location Thomas Garnier <thgarnie@google.com> - 2017-01-10 18:20 +0100
Re: [RFC] x86/mm/KASLR: Remap GDTs at fixed location Linus Torvalds <torvalds@linux-foundation.org> - 2017-01-06 00:10 +0100
Re: [RFC] x86/mm/KASLR: Remap GDTs at fixed location Thomas Garnier <thgarnie@google.com> - 2017-01-06 00:30 +0100
Re: [RFC] x86/mm/KASLR: Remap GDTs at fixed location Andy Lutomirski <luto@amacapital.net> - 2017-01-06 03:40 +0100
Re: [RFC] x86/mm/KASLR: Remap GDTs at fixed location Thomas Garnier <thgarnie@google.com> - 2017-01-06 19:10 +0100
Re: [RFC] x86/mm/KASLR: Remap GDTs at fixed location Andy Lutomirski <luto@kernel.org> - 2017-01-06 23:00 +0100
Re: [RFC] x86/mm/KASLR: Remap GDTs at fixed location Ingo Molnar <mingo@kernel.org> - 2017-01-07 08:50 +0100
Re: [RFC] x86/mm/KASLR: Remap GDTs at fixed location Ingo Molnar <mingo@kernel.org> - 2017-01-06 07:50 +0100
Re: [RFC] x86/mm/KASLR: Remap GDTs at fixed location Andy Lutomirski <luto@amacapital.net> - 2017-01-05 19:30 +0100
csiph-web