Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1751718AbZJMEce (ORCPT ); Tue, 13 Oct 2009 00:32:34 -0400 Received: (majordomo@vger.kernel.org) by vger.kernel.org id S1750988AbZJMEcd (ORCPT ); Tue, 13 Oct 2009 00:32:33 -0400 Received: from casper.infradead.org ([85.118.1.10]:34717 "EHLO casper.infradead.org" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1750808AbZJMEcc (ORCPT ); Tue, 13 Oct 2009 00:32:32 -0400 Date: Mon, 12 Oct 2009 21:32:29 -0700 From: Arjan van de Ven To: Siarhei Liakh Cc: linux-kernel@vger.kernel.org, linux-security-module@vger.kernel.org, James Morris , Andrew Morton , Andi Kleen , Rusty Russell , Thomas Gleixner , "H. Peter Anvin" , Ingo Molnar , David Howells , Aristeu Rozanski Subject: Re: [PATCH V5] x86: NX protection for kernel data Message-ID: <20091012213229.11898c12@infradead.org> In-Reply-To: <817ecb6f0910121803p52a4049ep4a712545d28bba76@mail.gmail.com> References: <817ecb6f0910121803p52a4049ep4a712545d28bba76@mail.gmail.com> Organization: Intel X-Mailer: Claws Mail 3.7.2 (GTK+ 2.16.6; i586-redhat-linux-gnu) Mime-Version: 1.0 Content-Type: text/plain; charset=US-ASCII Content-Transfer-Encoding: 7bit X-SRS-Rewrite: SMTP reverse-path rewritten from by casper.infradead.org See http://www.infradead.org/rpr.html Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org Content-Length: 1425 Lines: 33 On Mon, 12 Oct 2009 21:03:17 -0400 Siarhei Liakh wrote: > This patch expands functionality of CONFIG_DEBUG_RODATA to set main > (static) kernel data area as NX. > The following steps are taken to achieve this: > 1. Linker script is adjusted so .text always starts and ends on a > page boundary 2. Linker script is adjusted so .rodata and .data > always start and end on a page boundary > 3. void mark_nxdata_nx(void) added to arch/x86/mm/init.c with actual > functionality: NX is set for all pages from _etext through _end. > 4. mark_nxdata_nx() called from free_initmem() (after init has been > released) 5. free_init_pages() sets released memory NX in > arch/x86/mm/init.c > > The patch have been developed for Linux 2.6.31-rc7 x86 by Siarhei > Liakh and Xuxian Jiang . > I like doing this, but... maybe it is useful to have a diff of the pagetable dump (PT_DUMP config option) to show the effect, in the changelog. That'd be like the proof on the pudding... -- Arjan van de Ven Intel Open Source Technology Centre For development, discussion and tips for power savings, visit http://www.lesswatts.org -- To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to majordomo@vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html Please read the FAQ at http://www.tux.org/lkml/