From patchwork Wed Mar 14 08:10:40 2018 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoshinori Sato X-Patchwork-Id: 10281589 Return-Path: Received: from mail.wl.linuxfoundation.org (pdx-wl-mail.web.codeaurora.org [172.30.200.125]) by pdx-korg-patchwork.web.codeaurora.org (Postfix) with ESMTP id BF912602C2 for ; Wed, 14 Mar 2018 08:11:17 +0000 (UTC) Received: from mail.wl.linuxfoundation.org (localhost [127.0.0.1]) by mail.wl.linuxfoundation.org (Postfix) with ESMTP id B018128768 for ; Wed, 14 Mar 2018 08:11:17 +0000 (UTC) Received: by mail.wl.linuxfoundation.org (Postfix, from userid 486) id A47B92876C; Wed, 14 Mar 2018 08:11:17 +0000 (UTC) X-Spam-Checker-Version: SpamAssassin 3.3.1 (2010-03-16) on pdx-wl-mail.web.codeaurora.org X-Spam-Level: X-Spam-Status: No, score=-1.9 required=2.0 tests=BAYES_00,DKIM_SIGNED, DKIM_VALID autolearn=ham version=3.3.1 Received: from bombadil.infradead.org (bombadil.infradead.org [198.137.202.133]) (using TLSv1.2 with cipher AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mail.wl.linuxfoundation.org (Postfix) with ESMTPS id DFA992876B for ; Wed, 14 Mar 2018 08:11:16 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.infradead.org; s=bombadil.20170209; h=Sender: Content-Transfer-Encoding:Content-Type:Cc:List-Subscribe:List-Help:List-Post: List-Archive:List-Unsubscribe:List-Id:MIME-Version:References:In-Reply-To: Subject:To:From:Message-ID:Date:Reply-To:Content-ID:Content-Description: Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID: List-Owner; bh=SCeAs4fiDNJGX1lVYvK9WMqeUvkDP58/FwrIcUpdxN4=; b=jbACikpXF37Dcw fwoakM/8AnlMn8F/l8Z6qj4F+6VEaaqv6MvL3u5WuG17p6u5fBsYrOfw/f3VpxYFTOtmvIEFyHaiY cIfmVjxyVNZwHaKkHGjTY5q8CRvoKOxcaPUmst94TmgfHShn8r0AAkMjsc3WDH/WS73++bo2l2ZtE dHGe74cbWmB7Tap8IUkr2EN6bSEzhpK73EkIk3gfssr/Pg5mpmWiwN5QBr+lbpDXgY/eFm5JMrT1S B5LEEzDcl03J391cS1twoTmc1Yr3j96cP13AUkeStrybnNb4FGLi0r16gWzLYYkdpzBtP7Ljy38po 6gM6fz40Q68E4PkGPVgg==; Received: from localhost ([127.0.0.1] helo=bombadil.infradead.org) by bombadil.infradead.org with esmtp (Exim 4.90_1 #2 (Red Hat Linux)) id 1ew1V4-0002rh-3V; Wed, 14 Mar 2018 08:11:06 +0000 Received: from mail01.asahi-net.or.jp ([202.224.55.13]) by bombadil.infradead.org with esmtp (Exim 4.90_1 #2 (Red Hat Linux)) id 1ew1Uy-0002q5-Ix for linux-arm-kernel@lists.infradead.org; Wed, 14 Mar 2018 08:11:04 +0000 Received: from h61-195-96-97.vps.ablenet.jp (h61-195-96-97.vps.ablenet.jp [61.195.96.97]) (Authenticated sender: PQ4Y-STU) by mail01.asahi-net.or.jp (Postfix) with ESMTPA id 9304D550EE; Wed, 14 Mar 2018 17:10:41 +0900 (JST) Received: from yo-satoh-debian.labs.sios.com (y243143.dynamic.ppp.asahi-net.or.jp [118.243.243.143]) by h61-195-96-97.vps.ablenet.jp (Postfix) with ESMTPSA id D8B9724006D; Wed, 14 Mar 2018 17:10:40 +0900 (JST) Date: Wed, 14 Mar 2018 17:10:40 +0900 Message-ID: <87po47axhb.wl-ysato@users.sourceforge.jp> From: Yoshinori Sato To: Huacai Chen Subject: Re: [PATCH V2] ZBOOT: fix stack protector in compressed boot phase In-Reply-To: References: <1520820258-19225-1-git-send-email-chenhc@lemote.com> User-Agent: Wanderlust/2.15.9 (Almost Unreal) SEMI-EPG/1.14.7 (Harue) FLIM/1.14.9 (=?ISO-8859-4?Q?Goj=F2?=) APEL/10.8 EasyPG/1.0.0 Emacs/24.5 (x86_64-pc-linux-gnu) MULE/6.0 (HANACHIRUSATO) MIME-Version: 1.0 (generated by SEMI-EPG 1.14.7 - "Harue") X-CRM114-Version: 20100106-BlameMichelson ( TRE 0.8.0 (BSD) ) MR-646709E3 X-CRM114-CacheID: sfid-20180314_011100_755892_33A50E10 X-CRM114-Status: GOOD ( 24.01 ) X-BeenThere: linux-arm-kernel@lists.infradead.org X-Mailman-Version: 2.1.21 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Cc: Linux MIPS Mailing List , Rich Felker , Russell King , linux-sh@vger.kernel.org, LKML , Ralf Baechle , linux-mm@kvack.org, stable , Andrew Morton , James Hogan , linux-arm-kernel@lists.infradead.org Sender: "linux-arm-kernel" Errors-To: linux-arm-kernel-bounces+patchwork-linux-arm=patchwork.kernel.org@lists.infradead.org X-Virus-Scanned: ClamAV using ClamSMTP On Tue, 13 Mar 2018 17:55:53 +0900, Huacai Chen wrote: > > Hi, Yoshinori, Rich and SuperH developers, > > I'm not familiar with SuperH assembly, but SuperH has the same bug > obviously. Could you please fix that? > > Huacai > Sorry. Previous mail bounced. It resend. OK. Apply this fix. SuperH can not handle long int directly. > On Mon, Mar 12, 2018 at 10:04 AM, Huacai Chen wrote: > > Call __stack_chk_guard_setup() in decompress_kernel() is too late that > > stack checking always fails for decompress_kernel() itself. So remove > > __stack_chk_guard_setup() and initialize __stack_chk_guard before we > > call decompress_kernel(). > > > > Original code comes from ARM but also used for MIPS and SH, so fix them > > together. If without this fix, compressed booting of these archs will > > fail because stack checking is enabled by default (>=4.16). > > > > V2: Fix build on ARM. > > > > Cc: stable@vger.kernel.org > > Signed-off-by: Huacai Chen > > --- > > arch/arm/boot/compressed/head.S | 4 ++++ > > arch/arm/boot/compressed/misc.c | 7 ------- > > arch/mips/boot/compressed/decompress.c | 7 ------- > > arch/mips/boot/compressed/head.S | 4 ++++ > > arch/sh/boot/compressed/head_32.S | 4 ++++ > > arch/sh/boot/compressed/head_64.S | 4 ++++ > > arch/sh/boot/compressed/misc.c | 7 ------- > > 7 files changed, 16 insertions(+), 21 deletions(-) > > > > diff --git a/arch/arm/boot/compressed/head.S b/arch/arm/boot/compressed/head.S > > index 45c8823..bae1fc6 100644 > > --- a/arch/arm/boot/compressed/head.S > > +++ b/arch/arm/boot/compressed/head.S > > @@ -547,6 +547,10 @@ not_relocated: mov r0, #0 > > bic r4, r4, #1 > > blne cache_on > > > > + ldr r0, =__stack_chk_guard > > + ldr r1, =0x000a0dff > > + str r1, [r0] > > + > > /* > > * The C runtime environment should now be setup sufficiently. > > * Set up some pointers, and start decompressing. > > diff --git a/arch/arm/boot/compressed/misc.c b/arch/arm/boot/compressed/misc.c > > index 16a8a80..e518ef5 100644 > > --- a/arch/arm/boot/compressed/misc.c > > +++ b/arch/arm/boot/compressed/misc.c > > @@ -130,11 +130,6 @@ asmlinkage void __div0(void) > > > > unsigned long __stack_chk_guard; > > > > -void __stack_chk_guard_setup(void) > > -{ > > - __stack_chk_guard = 0x000a0dff; > > -} > > - > > void __stack_chk_fail(void) > > { > > error("stack-protector: Kernel stack is corrupted\n"); > > @@ -150,8 +145,6 @@ decompress_kernel(unsigned long output_start, unsigned long free_mem_ptr_p, > > { > > int ret; > > > > - __stack_chk_guard_setup(); > > - > > output_data = (unsigned char *)output_start; > > free_mem_ptr = free_mem_ptr_p; > > free_mem_end_ptr = free_mem_ptr_end_p; > > diff --git a/arch/mips/boot/compressed/decompress.c b/arch/mips/boot/compressed/decompress.c > > index fdf99e9..5ba431c 100644 > > --- a/arch/mips/boot/compressed/decompress.c > > +++ b/arch/mips/boot/compressed/decompress.c > > @@ -78,11 +78,6 @@ void error(char *x) > > > > unsigned long __stack_chk_guard; > > > > -void __stack_chk_guard_setup(void) > > -{ > > - __stack_chk_guard = 0x000a0dff; > > -} > > - > > void __stack_chk_fail(void) > > { > > error("stack-protector: Kernel stack is corrupted\n"); > > @@ -92,8 +87,6 @@ void decompress_kernel(unsigned long boot_heap_start) > > { > > unsigned long zimage_start, zimage_size; > > > > - __stack_chk_guard_setup(); > > - > > zimage_start = (unsigned long)(&__image_begin); > > zimage_size = (unsigned long)(&__image_end) - > > (unsigned long)(&__image_begin); > > diff --git a/arch/mips/boot/compressed/head.S b/arch/mips/boot/compressed/head.S > > index 409cb48..00d0ee0 100644 > > --- a/arch/mips/boot/compressed/head.S > > +++ b/arch/mips/boot/compressed/head.S > > @@ -32,6 +32,10 @@ start: > > bne a2, a0, 1b > > addiu a0, a0, 4 > > > > + PTR_LA a0, __stack_chk_guard > > + PTR_LI a1, 0x000a0dff > > + sw a1, 0(a0) > > + > > PTR_LA a0, (.heap) /* heap address */ > > PTR_LA sp, (.stack + 8192) /* stack address */ > > > > diff --git a/arch/sh/boot/compressed/head_32.S b/arch/sh/boot/compressed/head_32.S > > index 7bb1681..a3fdb05 100644 > > --- a/arch/sh/boot/compressed/head_32.S > > +++ b/arch/sh/boot/compressed/head_32.S > > @@ -76,6 +76,10 @@ l1: > > mov.l init_stack_addr, r0 > > mov.l @r0, r15 > > > > + mov.l __stack_chk_guard, r0 > > + mov #0x000a0dff, r1 > > + mov.l r1, @r0 > > + > > /* Decompress the kernel */ > > mov.l decompress_kernel_addr, r0 > > jsr @r0 > > diff --git a/arch/sh/boot/compressed/head_64.S b/arch/sh/boot/compressed/head_64.S > > index 9993113..8b4d540 100644 > > --- a/arch/sh/boot/compressed/head_64.S > > +++ b/arch/sh/boot/compressed/head_64.S > > @@ -132,6 +132,10 @@ startup: > > addi r22, 4, r22 > > bne r22, r23, tr1 > > > > + movi datalabel __stack_chk_guard, r0 > > + movi 0x000a0dff, r1 > > + st.l r0, 0, r1 > > + > > /* > > * Decompress the kernel. > > */ > > diff --git a/arch/sh/boot/compressed/misc.c b/arch/sh/boot/compressed/misc.c > > index 627ce8e..fe4c079 100644 > > --- a/arch/sh/boot/compressed/misc.c > > +++ b/arch/sh/boot/compressed/misc.c > > @@ -106,11 +106,6 @@ static void error(char *x) > > > > unsigned long __stack_chk_guard; > > > > -void __stack_chk_guard_setup(void) > > -{ > > - __stack_chk_guard = 0x000a0dff; > > -} > > - > > void __stack_chk_fail(void) > > { > > error("stack-protector: Kernel stack is corrupted\n"); > > @@ -130,8 +125,6 @@ void decompress_kernel(void) > > { > > unsigned long output_addr; > > > > - __stack_chk_guard_setup(); > > - > > #ifdef CONFIG_SUPERH64 > > output_addr = (CONFIG_MEMORY_START + 0x2000); > > #else > > -- > > 2.7.0 > > --- Yoshinori Sato diff --git a/arch/sh/boot/compressed/head_32.S b/arch/sh/boot/compressed/head_32.S index a3fdb053f351..7411fcb5764a 100644 --- a/arch/sh/boot/compressed/head_32.S +++ b/arch/sh/boot/compressed/head_32.S @@ -76,8 +76,8 @@ l1: mov.l init_stack_addr, r0 mov.l @r0, r15 - mov.l __stack_chk_guard, r0 - mov #0x000a0dff, r1 + mov.l __stack_chk_guard_ptr, r0 + mov.l __stack_chk_val, r1 mov.l r1, @r0 /* Decompress the kernel */ @@ -109,6 +109,10 @@ kernel_start_addr: #else .long _text+PAGE_SIZE #endif +__stack_chk_guard_ptr: + .long __stack_chk_guard +__stack_chk_val: + .long 0x000a0dff .align 9 fake_headers_as_bzImage: