Received: by 2002:ac0:a5b6:0:0:0:0:0 with SMTP id m51-v6csp3854955imm; Tue, 29 May 2018 15:20:12 -0700 (PDT) X-Google-Smtp-Source: ADUXVKIac/oz1EQacnOBElmpySHEhQxV/rJV/ObuxW3hx7OXKM82ARftBISkaTjlBCFtSYmh5o5e X-Received: by 2002:a65:5386:: with SMTP id x6-v6mr184484pgq.188.1527632412063; Tue, 29 May 2018 15:20:12 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1527632412; cv=none; d=google.com; s=arc-20160816; b=PDGLuKUw5d7h279oKRdnyBSC9Fe1t5Ejm4pfIuR6pCV4yhi6gvE/0L8cQ2rdTV/7T+ qDrt8Ef0ey2C0d1aBN2GrnM+2H5YcXXzcjS7in6TQynLGSLft4rAw4NDGdI7cIqK14vn Dt3dna4xFeqLnSROv1Um1Lz/y0I9Cao1zHPwxydp9vYNHIROfVUsiEnPZmwfzncqIz01 9M6/G0xpANGaoE0+xDNz9zhrZJ+oauIihbzIldtnO19b79xgPwozz2ELaC+uo0QPrEUG iG/ebgxshJx40z+qzCLKxfjcXq6SlDEhJlYDyUJ6Ogvy6A1EWo/ye86Ly4X77yei73+h hQqQ== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:sender:references:in-reply-to:message-id:date :subject:cc:to:from:dkim-signature:arc-authentication-results; bh=3Onmr25dSz8ZQ73uJeO5gQYDVwNXRukF6Ht8jmOe+V4=; b=KtcCZEyGgGxD52xV+RWo05rXI4TRNWllyG/h4zb/I198xxrK1UjmBiJWhsu5hMvjER AF+RLnP9qvVNlSC73IksQHu9YPam6UsgvdPvLC9Czicf3VSqs0CRLs1Nwd+zLNMj8a4E A0qwk4JpaZ5u1tNbve6C2gycobqbBRe4kcrmyKwXTpBqUczN92pWIW6I3GW/ZCJDrCvW S4ZrztyxuFpD0GflJB8kb5hJX3e08z0jgI/zYYahFSdI7l0ZK8pjyWZHt9U9B2S+FXfJ 3bKkPP4S/20iTHmG4vVXfeDDRfO+tspjsw9cP+EfTPeuCBfvBxDKZnyQDEUwbwYqdKvQ WYAA== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@google.com header.s=20161025 header.b=vI5HpMsU; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=google.com Return-Path: Received: from vger.kernel.org (vger.kernel.org. [209.132.180.67]) by mx.google.com with ESMTP id f3-v6si34230105plf.436.2018.05.29.15.19.58; Tue, 29 May 2018 15:20:12 -0700 (PDT) Received-SPF: pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) client-ip=209.132.180.67; Authentication-Results: mx.google.com; dkim=pass header.i=@google.com header.s=20161025 header.b=vI5HpMsU; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=google.com Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S968321AbeE2WS6 (ORCPT + 99 others); Tue, 29 May 2018 18:18:58 -0400 Received: from mail-pl0-f67.google.com ([209.85.160.67]:44338 "EHLO mail-pl0-f67.google.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S968205AbeE2WSO (ORCPT ); Tue, 29 May 2018 18:18:14 -0400 Received: by mail-pl0-f67.google.com with SMTP id z9-v6so6424025plk.11 for ; Tue, 29 May 2018 15:18:14 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20161025; h=from:to:cc:subject:date:message-id:in-reply-to:references; bh=3Onmr25dSz8ZQ73uJeO5gQYDVwNXRukF6Ht8jmOe+V4=; b=vI5HpMsUBvKn0l9Bw0w35FQmKAqYgCQ39WmeBsfnuM6M4cwgpNAc0exCjXMbPvXBHG V2XB1PmjgWppHBeAMqWwxpZs3ycndsl9BKAbXq/lFgEvrmcS9Xh/QbpFuiZ9amfX/IOK RWrceX46Lr8irc0p2jMvmKx857oWRZVhB+D9GAkaoMLV8mOGZTCaZrUW7UTi0Fhz+RbM aGPgSlIrUaPicOFzeqkxh+11VqrthD4FtCscdlTUdxpK6sm+iSQvOnq5+wWlz67NzK7t pBldHosBLe5AsOqXt1oewwEybxlk8baxxuDBcuPSpvI66AUacXM0iQP38Xo+/a4FwxhX M1/w== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:to:cc:subject:date:message-id:in-reply-to :references; bh=3Onmr25dSz8ZQ73uJeO5gQYDVwNXRukF6Ht8jmOe+V4=; b=pLzf4tL8bOWkudsYovmQZWtt7BPHpya69nur2fanfTgjlz8ffMcyo1pnOfMvnbpEnU N4KZXrIX7eJE8kKP6uYM2+EhWUcUctb2Ldp3Y3vbmpaVRbAf5yFtmhbQs4P/V2AktKb3 73PUlAFBkMGKCsDn54zMl4pRHVUdwGuRWRsOO/fOyAqiIKqE/vQT/SKsc2txC90+SZYh Ap+cR0C1X0zNPZC70z/OutHzbXJgxLXhzfTCQ2b5klyUdy6EhFEbSHlyilSSxIXJo5S0 LQvlLi/ICQvi6t4HWSjACZXKJDWyIhj5h5/gAUDjFS+7e8trU4Z2GCvoCAio/vs8jFfL G5wg== X-Gm-Message-State: ALKqPweD+ovQomDSz0I+QsAj2MUxtMkQVUsRY7kfQt3s8yXFLIowHgTv pJfHdqJr2u0K+oO3lB6xHkaRpQ== X-Received: by 2002:a17:902:43:: with SMTP id 61-v6mr246452pla.112.1527632293806; Tue, 29 May 2018 15:18:13 -0700 (PDT) Received: from skynet.sea.corp.google.com ([2620:15c:17:4:29de:3bb1:1270:e679]) by smtp.gmail.com with ESMTPSA id o84-v6sm78767935pfi.27.2018.05.29.15.18.12 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Tue, 29 May 2018 15:18:12 -0700 (PDT) From: Thomas Garnier To: kernel-hardening@lists.openwall.com Cc: Thomas Garnier , Arnd Bergmann , linux-arch@vger.kernel.org, linux-kernel@vger.kernel.org Subject: [PATCH v4 24/27] x86/mm: Make the x86 GOT read-only Date: Tue, 29 May 2018 15:15:25 -0700 Message-Id: <20180529221625.33541-25-thgarnie@google.com> X-Mailer: git-send-email 2.17.0.921.gf22659ad46-goog In-Reply-To: <20180529221625.33541-1-thgarnie@google.com> References: <20180529221625.33541-1-thgarnie@google.com> Sender: linux-kernel-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org The GOT is changed during early boot when relocations are applied. Make it read-only directly. This table exists only for PIE binary. Position Independent Executable (PIE) support will allow to extend the KASLR randomization range 0xffffffff80000000. Signed-off-by: Thomas Garnier --- include/asm-generic/vmlinux.lds.h | 12 ++++++++++++ 1 file changed, 12 insertions(+) diff --git a/include/asm-generic/vmlinux.lds.h b/include/asm-generic/vmlinux.lds.h index e373e2e10f6a..e5b0710fe693 100644 --- a/include/asm-generic/vmlinux.lds.h +++ b/include/asm-generic/vmlinux.lds.h @@ -314,6 +314,17 @@ __end_ro_after_init = .; #endif +#ifdef CONFIG_X86_PIE +#define RO_GOT_X86 \ + .got : AT(ADDR(.got) - LOAD_OFFSET) { \ + VMLINUX_SYMBOL(__start_got) = .; \ + *(.got); \ + VMLINUX_SYMBOL(__end_got) = .; \ + } +#else +#define RO_GOT_X86 +#endif + /* * Read only Data */ @@ -370,6 +381,7 @@ __end_builtin_fw = .; \ } \ \ + RO_GOT_X86 \ TRACEDATA \ \ /* Kernel symbol table: Normal symbols */ \ -- 2.17.0.921.gf22659ad46-goog