Received: by 2002:ac0:946b:0:0:0:0:0 with SMTP id j40csp1130379imj; Thu, 14 Feb 2019 01:36:46 -0800 (PST) X-Google-Smtp-Source: AHgI3IYjqrq31KSyD7j52cvwK6ehjOeCC87QF3s0WEulYDSyx1X1uuEXPco9hqE2BUDNneO2/d9U X-Received: by 2002:a63:f412:: with SMTP id g18mr2897185pgi.262.1550137006050; Thu, 14 Feb 2019 01:36:46 -0800 (PST) ARC-Seal: i=1; a=rsa-sha256; t=1550137006; cv=none; d=google.com; s=arc-20160816; b=xUkLzGCoCmjy7pJvdpcxzqi7F6tOScQPfZxmblciX12Zci0CatBnKJpNE6eJWTbZy4 xKtMI4EWade2Ze1qJujQ8MbxF3L0i1phvM6RspI6iRYX8wfTESdlwnZwAfiC+VuVUkOH +K3h9Q7qUNt374dpXOQahvHkFohKR69Z/kntaSeCxlP9MSUNDfuzysIBVTqCTVmq7KIE QwM6X8oHwHV3B86cagYXtm7xkjqWpmUuV2K7DL/FAlkMWvQvU0Tdw45bB+5wNFzNMMIY 5sYO7pM/0HloTkY1J6Wuj9g8cwIZPoJEYd0ux8zi7imMitigiDr0953mzqjIiDZn/OzL W3ew== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:sender:to:content-transfer-encoding:mime-version :reply-to:references:in-reply-to:message-id:date:subject:cc:from :dkim-signature; bh=ziJEcxmH0HELRYpJ/Cx0XBIGaICt7y2RQVCxbSTmAUA=; b=DipxikEsbyJtgtmmxHyR6A2aHy3NAw8QmmpXWjsKHVsoDsCEkBrHzrMwzFjaisJOn2 1DMI8H4TMt9ea2DaVvzn9ZDlP0nfj/Gsr/GeT08tnay7QWapgtrTOWDlCFCUMbC1V9wr 0/z5deUPYEhxbzU3PuMV37VgUi+M1FOeXdf35qGpENScoA3YBvMHCUoUqfY0MMlSMxOh BnM2w8P8BtauR/BgJ/YKwhFaYoph6xbpmfnyYJpfQxbQw/2y+/K+adP3R2ZY0GoYv8aw rifGDb1fKlx1NfIDUHgSoKb+5ZdxvghPvu1WVRFc/wxl8l767TtoQLU8KIP04EZVzx4D XduQ== ARC-Authentication-Results: i=1; mx.google.com; dkim=fail header.i=@gmail.com header.s=20161025 header.b=AT0rnd8B; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=fail (p=NONE sp=QUARANTINE dis=NONE) header.from=gmail.com Return-Path: Received: from vger.kernel.org (vger.kernel.org. [209.132.180.67]) by mx.google.com with ESMTP id f21si1926580plr.104.2019.02.14.01.36.29; Thu, 14 Feb 2019 01:36:46 -0800 (PST) Received-SPF: pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) client-ip=209.132.180.67; Authentication-Results: mx.google.com; dkim=fail header.i=@gmail.com header.s=20161025 header.b=AT0rnd8B; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=fail (p=NONE sp=QUARANTINE dis=NONE) header.from=gmail.com Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S2395167AbfBMWmT (ORCPT + 99 others); Wed, 13 Feb 2019 17:42:19 -0500 Received: from mail-wr1-f68.google.com ([209.85.221.68]:37486 "EHLO mail-wr1-f68.google.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S2395147AbfBMWmL (ORCPT ); Wed, 13 Feb 2019 17:42:11 -0500 Received: by mail-wr1-f68.google.com with SMTP id c8so4383800wrs.4; Wed, 13 Feb 2019 14:42:10 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=from:to:cc:subject:date:message-id:in-reply-to:references:reply-to :mime-version:content-transfer-encoding; bh=ziJEcxmH0HELRYpJ/Cx0XBIGaICt7y2RQVCxbSTmAUA=; b=AT0rnd8BnDyFyzfZmtZcyeTBEWOmVhTvPmEu5QNum22iV2TcKjKPwLVNWNeagC0CRy ctLWeeTYC/+F6/tKvEGXpJEyq+9Yz6bCFYiyBbA3twYThdmj5oAWC32/BvKKUsEGEX7o Ld9HklU7c97NPh13SsZ6fCE/5BMVPh9dqK1naXMrYOstuBxbrBxG+SqHXwEloEStPyvR ffmv8EeqFFFoGyKtg14GqIYxFVbRpPQFp2z+rCCaXp+qC/Cyh9Zji9wP1jG6KdtLhlYx p7hNzJkTQdZOgNlQY/A8FTBEwkpMfs3AiT9jAGZANXbmBbnzIfgztEwbiLzC+FwV2x8J VLpg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:to:cc:subject:date:message-id:in-reply-to :references:reply-to:mime-version:content-transfer-encoding; bh=ziJEcxmH0HELRYpJ/Cx0XBIGaICt7y2RQVCxbSTmAUA=; b=X23Dhvaw4P+Ln+TzVY2QkIdVjOLwETcqmP5tZgrdw8gLUCi0+pkhHytcdSnBRf/26j lpuqqUkWkkT5mDLdnMacdOWY5O82NZUC466Jtg85gTs8Vebo1c+Y0ajBXHc1/vNyyb34 AdZ4DU6pcvTDb7ojVA+NzcruHWNmnMIYxRFOZ3ocGTDlxpwF600ZWPP3atD0VZpeiWC5 1hVHj/mqaIvmK+YBsaFNT46WkvIVpVudNRSX6bMzM2Ut26BcXaoUfCICpNd+9t0IxAFo nppVkrs1MyKzQnkirlcjTPIfnx0/A1fml99UWHXGVTVpULl/dKyQAjmWS0OXn7oXnXKD 7aXg== X-Gm-Message-State: AHQUAuZoWeIC3fsAo/vnkG0Ml+DjeRCh7khBJ7yl1gXc1XVl3a6DR/OO 7jabJgD6VulZxHIMhj20Vjs= X-Received: by 2002:adf:fa0d:: with SMTP id m13mr285795wrr.93.1550097729690; Wed, 13 Feb 2019 14:42:09 -0800 (PST) Received: from localhost.localdomain ([91.75.74.250]) by smtp.gmail.com with ESMTPSA id f196sm780810wme.36.2019.02.13.14.42.06 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Wed, 13 Feb 2019 14:42:09 -0800 (PST) From: Igor Stoppa X-Google-Original-From: Igor Stoppa Cc: Igor Stoppa , Andy Lutomirski , Nadav Amit , Matthew Wilcox , Peter Zijlstra , Kees Cook , Dave Hansen , Mimi Zohar , Thiago Jung Bauermann , Ahmed Soliman , linux-integrity@vger.kernel.org, kernel-hardening@lists.openwall.com, linux-mm@kvack.org, linux-kernel@vger.kernel.org Subject: [RFC PATCH v5 04/12] __wr_after_init: x86_64: randomize mapping offset Date: Thu, 14 Feb 2019 00:41:33 +0200 Message-Id: <4f3b363bfd20ec0d79a0b066581d72145bb65883.1550097697.git.igor.stoppa@huawei.com> X-Mailer: git-send-email 2.19.1 In-Reply-To: References: Reply-To: Igor Stoppa MIME-Version: 1.0 Content-Transfer-Encoding: 8bit To: unlisted-recipients:; (no To-header on input) Sender: linux-kernel-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org x86_64 specialized way of defining the base address for the alternate mapping used by write-rare. Since the kernel address space spans across 64TB and it is mapped into a used address space of 128TB, the kernel address space can be shifted by a random offset that is up to 64TB and page aligned. This is accomplished by providing arch-specific version of the function __init_wr_base() Signed-off-by: Igor Stoppa CC: Andy Lutomirski CC: Nadav Amit CC: Matthew Wilcox CC: Peter Zijlstra CC: Kees Cook CC: Dave Hansen CC: Mimi Zohar CC: Thiago Jung Bauermann CC: Ahmed Soliman CC: linux-integrity@vger.kernel.org CC: kernel-hardening@lists.openwall.com CC: linux-mm@kvack.org CC: linux-kernel@vger.kernel.org --- arch/x86/mm/Makefile | 2 ++ arch/x86/mm/prmem.c (new) | 20 ++++++++++++++++++++ 2 files changed, 22 insertions(+) diff --git a/arch/x86/mm/Makefile b/arch/x86/mm/Makefile index 4b101dd6e52f..66652de1e2c7 100644 --- a/arch/x86/mm/Makefile +++ b/arch/x86/mm/Makefile @@ -53,3 +53,5 @@ obj-$(CONFIG_PAGE_TABLE_ISOLATION) += pti.o obj-$(CONFIG_AMD_MEM_ENCRYPT) += mem_encrypt.o obj-$(CONFIG_AMD_MEM_ENCRYPT) += mem_encrypt_identity.o obj-$(CONFIG_AMD_MEM_ENCRYPT) += mem_encrypt_boot.o + +obj-$(CONFIG_PRMEM) += prmem.o diff --git a/arch/x86/mm/prmem.c b/arch/x86/mm/prmem.c new file mode 100644 index 000000000000..b04fc03f92fb --- /dev/null +++ b/arch/x86/mm/prmem.c @@ -0,0 +1,20 @@ +// SPDX-License-Identifier: GPL-2.0 +/* + * prmem.c: Memory Protection Library - x86_64 backend + * + * (C) Copyright 2018-2019 Huawei Technologies Co. Ltd. + * Author: Igor Stoppa + */ + +#include +#include + +unsigned long __init __init_wr_base(void) +{ + /* + * Place 64TB of kernel address space within 128TB of user address + * space, at a random page aligned offset. + */ + return (((unsigned long)kaslr_get_random_long("WR Poke")) & + PAGE_MASK) % (64 * _BITUL(40)); +} -- 2.19.1