Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1703880

Re: [PATCH v6 RESEND] x86/boot/KASLR: Restrict kernel to be randomized in mirror regions

Path csiph.com!news.redatomik.org!aioe.org!bofh.it!news.nic.it!robomod
From Matt Fleming <matt@codeblueprint.co.uk>
Newsgroups linux.kernel
Subject Re: [PATCH v6 RESEND] x86/boot/KASLR: Restrict kernel to be randomized in mirror regions
Date Fri, 04 Aug 2017 13:30:02 +0200
Message-ID <uaIXM-6k3-3@gated-at.bofh.it> (permalink)
References <u5fMK-5hG-23@gated-at.bofh.it> <u5DvI-3Ew-3@gated-at.bofh.it> <u5Gaf-5lR-35@gated-at.bofh.it> <u6LKy-5uV-23@gated-at.bofh.it> <u8adS-247-39@gated-at.bofh.it> <u8bCV-335-9@gated-at.bofh.it>
Dkim-Signature v=1; a=rsa-sha256; c=relaxed/relaxed; d=codeblueprint-co-uk.20150623.gappssmtp.com; s=20150623; h=date:from:to:cc:subject:message-id:references:mime-version :content-disposition:in-reply-to:user-agent; bh=f/F0A+UE4e9aKJZWnEMO36DnzPVa6P62TxYtlZeVLWE=; b=Cz2RXYSba70xq1RD5rUnH7h+hFNbVFtq1hNXfqObTf73XcsARupHFtpsFGu7u/7s9/ yIvuKDT7zalbNHUw6pYpgDCn/VYGj4gIpPXwFz+5Z6SsOa/E1KEQiP0NzR+i7oiEMt9o 9iVus7NKbuuVvMwmKvtr5BmYnmXlK8fan/vhaWCdZwT8UeVuJrZyokfuIz6/f3eC/T+0 EosJmY6bhvBHyDuqHUd/c4RDTze7Dz75NTqRb35s3C9PH//XYz6BPFUDk0tTJeRYbTUb X3Igy0mxzdTGkfHazdOZGYWOOO3RL4aYPygo+98z4FX8xm2DAnoFKHd32cxNxphSRPi3 1GrQ==
X-Google-Dkim-Signature v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:date:from:to:cc:subject:message-id:references :mime-version:content-disposition:in-reply-to:user-agent; bh=f/F0A+UE4e9aKJZWnEMO36DnzPVa6P62TxYtlZeVLWE=; b=j39RjOy2Vxcxxo7VMa3RbFvVbYmqdwnSAVnw3P+dbm1bV4crBDqZc5cltbZXZ2ieL3 9iKEs1jAffAHPOaegCqOPW9dbQqQq+kkHPpIufGkUaS+Ez+lb8fVSppY8gkb/CPLcE4N vGajWHSHP+Ou3yLaR/B/46ybmuhrBNnF/9aWuPSoW+wtaISThZ0WgHwcZia7QvspuPOP A3p42VY8XnaHzu3PDd3o2aZbXJN1UP4KoOZ8lB2oIN9yBg6peXxkaoUVnY396WC7IKbJ CF9N0eL6fjRSCZcke53qkjXsqPNqHRUlegbpeW7BJh4g+LpCqDivKpJu8EE2vVPJPa6f twmA==
X-Gm-Message-State AIVw111KYs1QgAwsFkvTAbMMQE81JnoRjN8VAb7ds/zQXT12xzW/vqvj cfHv036SIAmczRN2
X-Received by 10.223.163.88 with SMTP id d24mr1373607wrb.33.1501845806435; Fri, 04 Aug 2017 04:23:26 -0700 (PDT)
MIME-Version 1.0
Content-Type text/plain; charset=us-ascii
Content-Disposition inline
User-Agent Mutt/1.5.24+42 (6e565710a064) (2015-08-30)
Sender robomod@news.nic.it
List-ID <linux-kernel.vger.kernel.org>
X-Mailing-List linux-kernel@vger.kernel.org
Approved robomod@news.nic.it
Lines 39
Organization linux.* mail to news gateway
X-Original-Cc Ingo Molnar <mingo@kernel.org>, linux-kernel@vger.kernel.org, x86@kernel.org, keescook@chromium.org, tglx@linutronix.de, hpa@zytor.com, izumi.taku@jp.fujitsu.com, fanc.fnst@cn.fujitsu.com, thgarnie@google.com, n-horiguchi@ah.jp.nec.com, Ard Biesheuvel <ard.biesheuvel@linaro.org>, linux-efi@vger.kernel.org
X-Original-Date Fri, 4 Aug 2017 12:23:25 +0100
X-Original-Message-ID <20170804112325.GB8187@codeblueprint.co.uk>
X-Original-References <1500542189-15779-1-git-send-email-bhe@redhat.com> <20170721103757.hc74czr3mfunrv6c@gmail.com> <20170721131956.GK2344@x1> <20170724133410.GC11076@codeblueprint.co.uk> <20170728095525.y4tuv6aavzfs4ekb@gmail.com> <20170728112603.GS24304@x1>
X-Original-Sender linux-kernel-owner@vger.kernel.org
Xref csiph.com linux.kernel:1703880

Show key headers only | View raw


On Fri, 28 Jul, at 07:26:03PM, Baoquan He wrote:
> Hi Matt,
> 
> On 07/28/17 at 11:55am, Ingo Molnar wrote:
> > 
> > * Matt Fleming <matt@codeblueprint.co.uk> wrote:
> > 
> > > On Fri, 21 Jul, at 09:19:56PM, Baoquan He wrote:
> > > >
> > > > There are places where the efi map is getting and used like this. E.g
> > > > in efi_high_alloc() of drivers/firmware/efi/libstub/efi-stub-helper.c.
> > > > EFI developers worry the size of efi_memory_desc_t could not be the same
> > > > as e->efi_memdesc_size?
> > > > 
> > > > Hi Matt,
> > > > 
> > > > Could you help have a look at this?
> > > 
> > > You're exactly right. The code guards against the size of the
> > > efi_memory_desc_t struct changing. The UEFI spec says to traverse the
> > > memory map this way.
> > 
> > This is not obvious and looks pretty ugly as well, and open coded in several 
> > places.
> > 
> > At minimum we should have an efi_memdesc_ptr(efi, i) wrapper inline (or so) that 
> > gives us the entry pointer, plus a comment that points out that ->memdesc_size 
> > might not be equal to sizeof(efi_memory_memdesc_t).
> 
> I can make a efi_memdesc_ptr(efi, i) wrapper as Ingo suggested and use
> it here if you agree. Seems it might be not good to add another
> for_each_efi_memory_desc_xxxx wrapper since there are different memmap
> data structures in x86 boot and in general efi libstub. Or any other
> idea?

I think adding a wrapper is fine, but I'd suggest including the word
"early" (or something similar) to explain that it should only be used
during bootup -- we want everyone else to use the
for_each_efi_memory_*() API.

Back to linux.kernel | Previous | Next — Next in thread | Find similar | Unroll thread


Thread

Re: [PATCH v6 RESEND] x86/boot/KASLR: Restrict kernel to be  randomized in mirror regions Matt Fleming <matt@codeblueprint.co.uk> - 2017-08-04 13:30 +0200
  Re: [PATCH v6 RESEND] x86/boot/KASLR: Restrict kernel to be  randomized in mirror regions Baoquan He <bhe@redhat.com> - 2017-08-04 13:50 +0200
    Re: [PATCH v6 RESEND] x86/boot/KASLR: Restrict kernel to be  randomized in mirror regions Matt Fleming <matt@codeblueprint.co.uk> - 2017-08-04 14:00 +0200
      Re: [PATCH v6 RESEND] x86/boot/KASLR: Restrict kernel to be  randomized in mirror regions Baoquan He <bhe@redhat.com> - 2017-08-04 14:10 +0200

csiph-web