Received: by 2002:ac0:a594:0:0:0:0:0 with SMTP id m20-v6csp916845imm; Wed, 23 May 2018 07:30:26 -0700 (PDT) X-Google-Smtp-Source: AB8JxZqyDXJ7MxrOyMRdgfR3NUTTCPkQCf3/bJzj8SGPEaxw4JGk0+mwH72cUomm8Qhi0KX6V5bD X-Received: by 2002:a63:79ce:: with SMTP id u197-v6mr2558976pgc.284.1527085826450; Wed, 23 May 2018 07:30:26 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1527085826; cv=none; d=google.com; s=arc-20160816; b=huteIVZ/+KxxcfgmuX3CMUs9VRZ8vw0HYjy4tdjsPlXnnxY+szi9SFM+iGa8Ccofax qQPRbYaCze5dqOPpq2NcYvW0ckWmPMCdJVsvRhhjGUDj9+JHKTn7eYpuUpVlIKGFD524 6CodkoREVBGm3dowhNkuBg7mxrhB+BQMGNJll9ql/RabFI64iWiWDQi8Kzt9HVCOVmTl SNGK9mwVPf8wU8epMD/RJqpHZewLV3Ujqu6W80IQXpOJf570RAUsDo5kyAZzYER/Nqht wdm0XtcBHTc4JeEj5QfUE1ohZs6Aykl31vgDBW3R6nvP+Wl+Y7FnuvMpm//DOYv6Hep1 0wJA== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:sender:references:in-reply-to:message-id:date :subject:cc:to:from:dkim-signature:arc-authentication-results; bh=k8lxUFBNdTrf1keI5zrLrqkBc1ZjvzuLMEDcoVHmnnU=; b=mlCIhsHQaN2W0u97kWIWGY3Wo7HeORR3U2UF/tNHPt8XTAy2xwelF3MkAKBhkXy4M3 Sg8TGbKD464MohDUsOrG6lREzVT7VSbadCYeTUa82YfSRtUySKeDC+Ixn/vTeogkQwed 4nmEO0v/HnOpNaOAXe6cSIEOfgnQJCsU3jnL2spdKIJ7O0vx+tTX1K+vjx2557izVmiT uvZYB7WvD3XG/clkOOmnyc1gUqFmR4mzb09f2B7pMRRvt/DZt5oaYcv8+cRQp8X95dI5 xXsygUzrVM9QDSlLrstvKNXLj2zr/kBuN3k64XhJ43agg8q84bdIk8O1/b6VOrbe9aX0 FyOA== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@oracle.com header.s=corp-2017-10-26 header.b=BmKmL96S; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=oracle.com Return-Path: Received: from vger.kernel.org (vger.kernel.org. [209.132.180.67]) by mx.google.com with ESMTP id w23-v6si2171765ply.563.2018.05.23.07.30.11; Wed, 23 May 2018 07:30:26 -0700 (PDT) Received-SPF: pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) client-ip=209.132.180.67; Authentication-Results: mx.google.com; dkim=pass header.i=@oracle.com header.s=corp-2017-10-26 header.b=BmKmL96S; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=oracle.com Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S933236AbeEWO2J (ORCPT + 99 others); Wed, 23 May 2018 10:28:09 -0400 Received: from aserp2130.oracle.com ([141.146.126.79]:58486 "EHLO aserp2130.oracle.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1754329AbeEWO2G (ORCPT ); Wed, 23 May 2018 10:28:06 -0400 Received: from pps.filterd (aserp2130.oracle.com [127.0.0.1]) by aserp2130.oracle.com (8.16.0.22/8.16.0.22) with SMTP id w4NEQbP0166908; Wed, 23 May 2018 14:28:00 GMT DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=oracle.com; h=from : to : cc : subject : date : message-id : in-reply-to : references; s=corp-2017-10-26; bh=k8lxUFBNdTrf1keI5zrLrqkBc1ZjvzuLMEDcoVHmnnU=; b=BmKmL96SsbaHvJhvasfibuio3lAMfCwajPkaSnG7nNgKGBtqrHxRItm2cZxf+o9v6rNW CMM8zfPNwb0FNBmVgQHhiIfRNxRNPLNfyk5OUxZAGiybg3b53Tl9VfGsVqnJ+kxrIWn6 ZW+4JjTec6+9+aUgsjPAfTepVMPWNQZVIGsRlcehpAEp1/8wqniHKeJaSoEfTMUxnqSM Yoj2HGl9chR+ht0VaM18RNe+2W9ttP6f6BnyAFBwqeRn34/drV8+niJ8kgOYo6bN4k/F AhzPJHS44YVtxMZzLHUxlKqtce7he76WCpktb6V+sinq++SpwxVz/ubgXk/qv7hE7noq HQ== Received: from aserv0021.oracle.com (aserv0021.oracle.com [141.146.126.233]) by aserp2130.oracle.com with ESMTP id 2j4nh7c7k1-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Wed, 23 May 2018 14:28:00 +0000 Received: from userv0122.oracle.com (userv0122.oracle.com [156.151.31.75]) by aserv0021.oracle.com (8.14.4/8.14.4) with ESMTP id w4NERxsC018798 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Wed, 23 May 2018 14:27:59 GMT Received: from abhmp0015.oracle.com (abhmp0015.oracle.com [141.146.116.21]) by userv0122.oracle.com (8.14.4/8.14.4) with ESMTP id w4NERwLR030671; Wed, 23 May 2018 14:27:59 GMT Received: from dhcp-burlington7-2nd-B-east-10-152-55-162.usdhcp.oraclecorp.com.com (/10.152.32.65) by default (Oracle Beehive Gateway v4.0) with ESMTP ; Wed, 23 May 2018 07:27:58 -0700 From: Boris Ostrovsky To: linux-kernel@vger.kernel.org, xen-devel@lists.xenproject.org Cc: jgross@suse.com, JBeulich@suse.com, brgerst@gmail.com, Boris Ostrovsky Subject: [PATCH v5 1/2] xen/PVH: Set up GS segment for stack canary Date: Wed, 23 May 2018 10:30:01 -0400 Message-Id: <20180523143002.29252-2-boris.ostrovsky@oracle.com> X-Mailer: git-send-email 2.14.3 In-Reply-To: <20180523143002.29252-1-boris.ostrovsky@oracle.com> References: <20180523143002.29252-1-boris.ostrovsky@oracle.com> X-Proofpoint-Virus-Version: vendor=nai engine=5900 definitions=8901 signatures=668700 X-Proofpoint-Spam-Details: rule=notspam policy=default score=0 suspectscore=0 malwarescore=0 phishscore=0 bulkscore=0 spamscore=0 mlxscore=0 mlxlogscore=999 adultscore=0 classifier=spam adjust=0 reason=mlx scancount=1 engine=8.0.1-1711220000 definitions=main-1805230146 Sender: linux-kernel-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org We are making calls to C code (e.g. xen_prepare_pvh()) which may use stack canary (stored in GS segment). Signed-off-by: Boris Ostrovsky Reviewed-by: Juergen Gross --- arch/x86/xen/xen-pvh.S | 26 +++++++++++++++++++++++++- 1 file changed, 25 insertions(+), 1 deletion(-) diff --git a/arch/x86/xen/xen-pvh.S b/arch/x86/xen/xen-pvh.S index e1a5fbe..d6a17b9 100644 --- a/arch/x86/xen/xen-pvh.S +++ b/arch/x86/xen/xen-pvh.S @@ -54,6 +54,9 @@ * charge of setting up it's own stack, GDT and IDT. */ +#define PVH_GDT_ENTRY_CANARY 4 +#define PVH_CANARY_SEL (PVH_GDT_ENTRY_CANARY * 8) + ENTRY(pvh_start_xen) cld @@ -98,6 +101,12 @@ ENTRY(pvh_start_xen) /* 64-bit entry point. */ .code64 1: + /* Set base address in stack canary descriptor. */ + mov $MSR_GS_BASE,%ecx + mov $_pa(canary), %rax + xor %rdx, %rdx + wrmsr + call xen_prepare_pvh /* startup_64 expects boot_params in %rsi. */ @@ -107,6 +116,17 @@ ENTRY(pvh_start_xen) #else /* CONFIG_X86_64 */ + /* Set base address in stack canary descriptor. */ + movl $_pa(gdt_start),%eax + movl $_pa(canary),%ecx + movw %cx, (PVH_GDT_ENTRY_CANARY * 8) + 2(%eax) + shrl $16, %ecx + movb %cl, (PVH_GDT_ENTRY_CANARY * 8) + 4(%eax) + movb %ch, (PVH_GDT_ENTRY_CANARY * 8) + 7(%eax) + + mov $PVH_CANARY_SEL,%eax + mov %eax,%gs + call mk_early_pgtbl_32 mov $_pa(initial_page_table), %eax @@ -150,9 +170,13 @@ gdt_start: .quad GDT_ENTRY(0xc09a, 0, 0xfffff) /* __KERNEL_CS */ #endif .quad GDT_ENTRY(0xc092, 0, 0xfffff) /* __KERNEL_DS */ + .quad GDT_ENTRY(0x4090, 0, 0x18) /* PVH_CANARY_SEL */ gdt_end: - .balign 4 + .balign 16 +canary: + .fill 48, 1, 0 + early_stack: .fill 256, 1, 0 early_stack_end: -- 2.9.3