Received: by 2002:a25:c205:0:0:0:0:0 with SMTP id s5csp3835595ybf; Tue, 3 Mar 2020 13:51:49 -0800 (PST) X-Google-Smtp-Source: ADFU+vvbzDhOKO++AOPdBQB6yKlAQTynUBugYkKGt7IXy8XRdzPMznxAuKpq5TqG3INtrtgYDL92 X-Received: by 2002:aca:f4d1:: with SMTP id s200mr463007oih.85.1583272308975; Tue, 03 Mar 2020 13:51:48 -0800 (PST) ARC-Seal: i=1; a=rsa-sha256; t=1583272308; cv=none; d=google.com; s=arc-20160816; b=DRCh5fdkDer0GIG1AUZdsgBoAz1UAri16q9K1BKvMgLBe/8lPg1WBQq1ZEK8Ujh4EK zRq9EWlhfcu+9PBDNWiRB0wTM4wfuZIeFUHZM+m1rmsbk5+yjooH8A1Y9euuucSAgTiQ n2gpMJ0uPdjzeFsZogzAV+3myIC6HWg9cJ0vN/we66cfElSxKUyPeOfa+DM7Fc7m4JLf Y+JJgKGNaYYOMdNe59YWxa7cxm3oOIru+4+z0l0YEoWaL9d/V9Uw1D2c2+NAItsKbyle Mkss4AxJfQPP7fVhqGK2FHY2lpToGE3BB/WrynEQBp3Vvzw7Gx7HbbX9N2M2NBaPcLO0 LKwg== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:sender:in-reply-to:content-disposition :mime-version:references:message-id:subject:cc:to:from:date :dkim-signature; bh=2qU0zyTDNzYtyDUGa9/iXos9xa7ov/2wTakWPxGP1ks=; b=dFLGBGy1qsYS6+SB0bhzS0hccepQT7CTfx7TB3GiiK9N6R8n3qN2d6AccyGqQ1ClTR +WKv4uWcm62Oa/SmLQzZosDuMk8Omj26nk06r77CJ4G1UTmCO1j7gFx8y7PJnsW+zyOF xd9VDvLqq3tWjv9ZNGA5wnB8ep8DhlrEhnRWN+xtZtDZ+AGtnGYYLtg2dG8T+hSBg0sP fPLWNs+jjdIXa7bc0j71wDBk8603uqwHYRdlLCsa9AZsPrfNg2Js4/v9rX0VwgNtwqkD 4h/iNjdP4HXVwtcA8k4c3DyjGN5BO+P70jTNzXGCH5ZEfxvafiJKOrT8MaJCdbiJBlTO BcFw== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@chromium.org header.s=google header.b=WqGcGMvM; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=chromium.org Return-Path: Received: from vger.kernel.org (vger.kernel.org. [209.132.180.67]) by mx.google.com with ESMTP id o2si9173176otj.312.2020.03.03.13.51.37; Tue, 03 Mar 2020 13:51:48 -0800 (PST) Received-SPF: pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) client-ip=209.132.180.67; Authentication-Results: mx.google.com; dkim=pass header.i=@chromium.org header.s=google header.b=WqGcGMvM; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=chromium.org Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1732542AbgCCVTZ (ORCPT + 99 others); Tue, 3 Mar 2020 16:19:25 -0500 Received: from mail-pj1-f67.google.com ([209.85.216.67]:35490 "EHLO mail-pj1-f67.google.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1732176AbgCCVTY (ORCPT ); Tue, 3 Mar 2020 16:19:24 -0500 Received: by mail-pj1-f67.google.com with SMTP id s8so1930645pjq.0 for ; Tue, 03 Mar 2020 13:19:24 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=chromium.org; s=google; h=date:from:to:cc:subject:message-id:references:mime-version :content-disposition:in-reply-to; bh=2qU0zyTDNzYtyDUGa9/iXos9xa7ov/2wTakWPxGP1ks=; b=WqGcGMvMn5GluxOGODQRPNpbzgvWO+OkNu8cZEiK4m3NjrW/mP/9I8Ma2MOO/Ww+Rh AXpTLggSqb4nT/DNHZ4zPLZBLfPgo7r9MZEl//d92/3cJAZoUlA/0t9tIJIOzPiz4Vo8 qCIuwYIq9DuCng1+aDxogCJeRnZ7hUGxeizAE= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:date:from:to:cc:subject:message-id:references :mime-version:content-disposition:in-reply-to; bh=2qU0zyTDNzYtyDUGa9/iXos9xa7ov/2wTakWPxGP1ks=; b=tIkHgOttd5FzOARm79wV8l3qRY2ZOCsgmGECzFwC/wRW07jrmVoj/d/RnVWj7tq8Ce DybTKSTEctGrCW2kmwUv7jiYdiML3UCigTUBgDqBSsmsug/049HPl6oSl/1oWSJyx2m1 hZ6x7tfkvt49zxcIjFSzybqg8JXuGxSleu4i4aFXiLUr1NkNCOpGczQrpizFQXZRaREg vsOSJPpb770XyW5+lEMlTtXOFk0d8DtlkE4dSLsZW7qhkUj9IJns9DotRnroGXJWpDBf HWmgr0oiUosMQ8gU90ZwgGarPga2TzyI2R6TOlY6MjgGrazzNXIwacybZMdRTrZ2tffL kRqg== X-Gm-Message-State: ANhLgQ0aQbze2G0k9AUgUY9uV9qSrb+seAsTf4AX63dNfezW1957VB3h u/I4tCKWf9K5PvWq/NqroOlF5g== X-Received: by 2002:a17:902:8d8a:: with SMTP id v10mr5883926plo.90.1583270363955; Tue, 03 Mar 2020 13:19:23 -0800 (PST) Received: from www.outflux.net (smtp.outflux.net. [198.145.64.163]) by smtp.gmail.com with ESMTPSA id k20sm3338375pfk.123.2020.03.03.13.19.22 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 03 Mar 2020 13:19:23 -0800 (PST) Date: Tue, 3 Mar 2020 13:19:22 -0800 From: Kees Cook To: Kristen Carlson Accardi Cc: Thomas Garnier , Peter Zijlstra , Thomas Gleixner , Ingo Molnar , Borislav Petkov , Kernel Hardening , Herbert Xu , "David S. Miller" , "H. Peter Anvin" , the arch/x86 maintainers , Andy Lutomirski , Juergen Gross , Thomas Hellstrom , "VMware, Inc." , "Rafael J. Wysocki" , Len Brown , Pavel Machek , Rasmus Villemoes , Miguel Ojeda , Will Deacon , Ard Biesheuvel , Masami Hiramatsu , Jiri Slaby , Boris Ostrovsky , Josh Poimboeuf , Cao jin , Allison Randal , Linux Crypto Mailing List , LKML , virtualization@lists.linux-foundation.org, Linux PM list Subject: Re: [PATCH v11 00/11] x86: PIE support to extend KASLR randomization Message-ID: <202003031314.1AFFC0E@keescook> References: <20200228000105.165012-1-thgarnie@chromium.org> <202003022100.54CEEE60F@keescook> <20200303095514.GA2596@hirez.programming.kicks-ass.net> <6e7e4191612460ba96567c16b4171f2d2f91b296.camel@linux.intel.com> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <6e7e4191612460ba96567c16b4171f2d2f91b296.camel@linux.intel.com> Sender: linux-kernel-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org On Tue, Mar 03, 2020 at 01:01:26PM -0800, Kristen Carlson Accardi wrote: > On Tue, 2020-03-03 at 07:43 -0800, Thomas Garnier wrote: > > On Tue, Mar 3, 2020 at 1:55 AM Peter Zijlstra > > wrote: > > > On Mon, Mar 02, 2020 at 09:02:15PM -0800, Kees Cook wrote: > > > > On Thu, Feb 27, 2020 at 04:00:45PM -0800, Thomas Garnier wrote: > > > > > Minor changes based on feedback and rebase from v10. > > > > > > > > > > Splitting the previous serie in two. This part contains > > > > > assembly code > > > > > changes required for PIE but without any direct dependencies > > > > > with the > > > > > rest of the patchset. > > > > > > > > > > Note: Using objtool to detect non-compliant PIE relocations is > > > > > not yet > > > > > possible as this patchset only includes the simplest PIE > > > > > changes. > > > > > Additional changes are needed in kvm, xen and percpu code. > > > > > > > > > > Changes: > > > > > - patch v11 (assembly); > > > > > - Fix comments on x86/entry/64. > > > > > - Remove KASLR PIE explanation on all commits. > > > > > - Add note on objtool not being possible at this stage of > > > > > the patchset. > > > > > > > > This moves us closer to PIE in a clean first step. I think these > > > > patches > > > > look good to go, and unblock the work in kvm, xen, and percpu > > > > code. Can > > > > one of the x86 maintainers pick this series up? > > > > > > But,... do we still need this in the light of that fine-grained > > > kaslr > > > stuff? > > > > > > What is the actual value of this PIE crud in the face of that? > > > > If I remember well, it makes it easier/better but I haven't seen a > > recent update on that. Is that accurate Kees? > > I believe this patchset is valuable if people are trying to brute force > guess the kernel location, but not so awesome in the event of > infoleaks. In the case of the current fgkaslr implementation, we only > randomize within the existing text segment memory area - so with PIE > the text segment base can move around more, but within that it wouldn't > strengthen anything. So, if you have an infoleak, you learn the base > instantly, and are just left with the same extra protection you get > without PIE. Right -- PIE improves both non- and fg- KASLR similarly, in the sense that the possible entropy for base offset is expanded. It also opens the door to doing even more crazy things. (e.g. why keep the kernel text all in one contiguous chunk?) And generally speaking, it seems a nice improvement to me, as it gives the kernel greater addressing flexibility. -- Kees Cook