From patchwork Wed Oct 4 21:19:53 2017 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Thomas Garnier X-Patchwork-Id: 9985517 Return-Path: Received: from mail.wl.linuxfoundation.org (pdx-wl-mail.web.codeaurora.org [172.30.200.125]) by pdx-korg-patchwork.web.codeaurora.org (Postfix) with ESMTP id 994B760586 for ; Wed, 4 Oct 2017 21:22:58 +0000 (UTC) Received: from mail.wl.linuxfoundation.org (localhost [127.0.0.1]) by mail.wl.linuxfoundation.org (Postfix) with ESMTP id 87ED328450 for ; Wed, 4 Oct 2017 21:22:58 +0000 (UTC) Received: by mail.wl.linuxfoundation.org (Postfix, from userid 486) id 7994028C2C; Wed, 4 Oct 2017 21:22:58 +0000 (UTC) X-Spam-Checker-Version: SpamAssassin 3.3.1 (2010-03-16) on pdx-wl-mail.web.codeaurora.org X-Spam-Level: X-Spam-Status: No, score=-3.6 required=2.0 tests=BAYES_00, DKIM_ADSP_CUSTOM_MED, DKIM_SIGNED, RCVD_IN_DNSWL_MED, RCVD_IN_SORBS_SPAM, T_DKIM_INVALID autolearn=ham version=3.3.1 Received: from lists.xenproject.org (lists.xenproject.org [192.237.175.120]) (using TLSv1.2 with cipher AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by mail.wl.linuxfoundation.org (Postfix) with ESMTPS id B9B2428450 for ; Wed, 4 Oct 2017 21:22:57 +0000 (UTC) Received: from localhost ([127.0.0.1] helo=lists.xenproject.org) by lists.xenproject.org with esmtp (Exim 4.84_2) (envelope-from ) id 1dzr6X-00038o-3K; Wed, 04 Oct 2017 21:21:21 +0000 Received: from mail6.bemta3.messagelabs.com ([195.245.230.39]) by lists.xenproject.org with esmtp (Exim 4.84_2) (envelope-from ) id 1dzr6W-00036j-BK for xen-devel@lists.xenproject.org; Wed, 04 Oct 2017 21:21:20 +0000 Received: from [85.158.137.68] by server-13.bemta-3.messagelabs.com id D1/27-01916-FC055D95; Wed, 04 Oct 2017 21:21:19 +0000 X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFtrJIsWRWlGSWpSXmKPExsVyMfTAGt1zAVc jDTY/kLD4vmUykwOjx+EPV1gCGKNYM/OS8isSWDMOH/vJXLBHquLbvnusDYwzxLoYuTiEBGYw Svxfu48JxGEReMUiMWX5RpYuRk4OCYF+VokV/3Uh7CyJBf+PsULYaRIfj25igrCrJY4dvcwOY gsJKEls3bCUGWLqX0aJzzPXgiXYBLQk9jTMB9sgIjBLROLW6x42EIdZ4AyTxPG+k2BjhQWsJf ZM3MgGYrMIqEos/t8LdgavgKXE3Am72SHWmUg8PHINrJ4TKH7kxBtmiNUWEq1n7jNNYBRcwMi wilG9OLWoLLVI11gvqSgzPaMkNzEzR9fQwFgvN7W4ODE9NScxqVgvOT93EyMw6BiAYAdj8xen Q4ySHExKorybfK9GCvEl5adUZiQWZ8QXleakFh9ilOHgUJLgfegPlBMsSk1PrUjLzAGGP0xag oNHSYR3Mkiat7ggMbc4Mx0idYrRkuPCnUt/mDgO7LkFJDtu3v3DJMSSl5+XKiXOuxmkQQCkIa M0D24cLEYvMcpKCfMyAh0oxFOQWpSbWYIq/4pRnINRSZg3D2QKT2ZeCdzWV0AHMQEdNKfpCsh BJYkIKakGxtUzxZn+iV30iphW+3P+F+3K/XcyF2y4uWLqh3YbJ/Mu05nSJvmhbquOhq09kuT4 kfXFjlkGGwx+yGlftXl75c7C1+/+xOc8XqS/4VLLEovvN43Sz/97u7C+OEiOIXx1MGeEycP81 zbO/yw+x283Etpzd+b7976+vus/7Sl/7XX2pc3vOd+KD81WYinOSDTUYi4qTgQASzOPF8wCAA A= X-Env-Sender: thgarnie@google.com X-Msg-Ref: server-11.tower-31.messagelabs.com!1507152077!87003635!1 X-Originating-IP: [209.85.192.172] X-SpamReason: No, hits=0.0 required=7.0 tests= X-StarScan-Received: X-StarScan-Version: 9.4.45; banners=-,-,- X-VirusChecked: Checked Received: (qmail 31528 invoked from network); 4 Oct 2017 21:21:18 -0000 Received: from mail-pf0-f172.google.com (HELO mail-pf0-f172.google.com) (209.85.192.172) by server-11.tower-31.messagelabs.com with AES128-GCM-SHA256 encrypted SMTP; 4 Oct 2017 21:21:18 -0000 Received: by mail-pf0-f172.google.com with SMTP id z84so6896374pfi.2 for ; Wed, 04 Oct 2017 14:21:18 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20161025; h=from:to:cc:subject:date:message-id:in-reply-to:references; bh=K5TO5LISXC1KHJEFTvgA2b6qZ4srmTO2s9YkcH9tPH4=; b=gCY0DfoCQfr89215OITTGwZDcXVz6lTj66tijsD9NGG7k8K22YF6c3/8WzkeMOzDHI 8lrwR3/nDxfGreMBcsV1Tif/GRZrbe1NaKqMadgwb6loLnXVFpaCmwsrP42by7QCp9Fa cMxL/PZFictKBmSk8S+CFVFPLTySZd8qH19TeW2WtOVEuva/lpbZjI8inC8lTymmi+XG 59aiGxRC+GSb7qPUAh8PW9AenLaRy+RI52tfN5BwniOkFEOZvB0aOKhAvKq8LdwzHOoP ZXDjLgV0aqsq9Bp4PxiGoqwXiuSfMB/ONGFLwI0NwXTdPKKk+tmEMfpM6XPvV0j1lNwz 03eg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:to:cc:subject:date:message-id:in-reply-to :references; bh=K5TO5LISXC1KHJEFTvgA2b6qZ4srmTO2s9YkcH9tPH4=; b=c/+Ob5eQFNwexRol6UmOvFlf3jik+KAwURoQyYhZwrwc/ebpAV6Xlw3QRwTUksx45e L6us6I8xPP1wq7EmWFPet9YGxMRo6QozJiCXmr6yZR1xsDArDZCHJZftko7i4nSDYjJ0 SIv3i6ftJ1GcGCEm0meC+alybv6HE/Iwc3e3urne41dNbiaRcynN9e+katF7Ug3pB9Eq H22HAw0P6D7dCBdwsSp9Cep3I9HUSnRTxtrOYe/01kmtkZm4/nQ3985IKL/SXdL41MSK pf1LQzhkjqUlfFJqBgEYM9i2JDI1ubgrRtw2GZTRBqTQSyENgsPskDdy6vc6l/61d9lK YObw== X-Gm-Message-State: AMCzsaXGosOoQSbJMyi2/AmGu2AHakhaixobzY1gS8fkDx2gDBnGlYbf esNN65wJeTBVtp9PbDDHJDzKTQ== X-Google-Smtp-Source: AOwi7QDz+V6CY6LFi2V/J7pjvQ5fmwYz5e/OT1oWS0M+RulohqkI1D+MSM5DT1Gz1ucivZzeY5hhtQ== X-Received: by 10.159.253.142 with SMTP id q14mr15736052pls.82.1507152075985; Wed, 04 Oct 2017 14:21:15 -0700 (PDT) Received: from skynet.sea.corp.google.com ([172.31.92.33]) by smtp.gmail.com with ESMTPSA id s68sm30204019pfd.72.2017.10.04.14.21.14 (version=TLS1_2 cipher=ECDHE-RSA-AES128-SHA bits=128/128); Wed, 04 Oct 2017 14:21:15 -0700 (PDT) From: Thomas Garnier To: Herbert Xu , "David S . Miller" , Thomas Gleixner , Ingo Molnar , "H . Peter Anvin" , Peter Zijlstra , Josh Poimboeuf , Thomas Garnier , Arnd Bergmann , Kees Cook , Matthias Kaehlcke , Tom Lendacky , Andy Lutomirski , "Kirill A . Shutemov" , Borislav Petkov , "Rafael J . Wysocki" , Len Brown , Pavel Machek , Juergen Gross , Chris Wright , Alok Kataria , Rusty Russell , Tejun Heo , Christoph Lameter , Boris Ostrovsky , Alexey Dobriyan , Andrew Morton , Paul Gortmaker , Chris Metcalf , "Paul E . McKenney" , Nicolas Pitre , Borislav Petkov , "Luis R . Rodriguez" , Greg Kroah-Hartman , Christopher Li , Steven Rostedt , Jason Baron , Dou Liyang , "Rafael J . Wysocki" , Mika Westerberg , Lukas Wunner , Masahiro Yamada , Alexei Starovoitov , Daniel Borkmann , Markus Trippelsdorf , Paolo Bonzini , =?UTF-8?q?Radim=20Kr=C4=8Dm=C3=A1=C5=99?= , Joerg Roedel , Rik van Riel , David Howells , Ard Biesheuvel , Waiman Long , Kyle Huey , Andrey Ryabinin , Jonathan Corbet , Matthew Wilcox , Michal Hocko , Peter Foley , Paul Bolle , Jiri Kosina , Rob Landley , "H . J . Lu" , Baoquan He , =?UTF-8?q?Jan=20H=20=2E=20Sch=C3=B6nherr?= , Daniel Micay Date: Wed, 4 Oct 2017 14:19:53 -0700 Message-Id: <20171004212003.28296-18-thgarnie@google.com> X-Mailer: git-send-email 2.14.2.920.gcf0c67979c-goog In-Reply-To: <20171004212003.28296-1-thgarnie@google.com> References: <20171004212003.28296-1-thgarnie@google.com> Cc: linux-arch@vger.kernel.org, kvm@vger.kernel.org, linux-pm@vger.kernel.org, x86@kernel.org, linux-doc@vger.kernel.org, linux-kernel@vger.kernel.org, virtualization@lists.linux-foundation.org, linux-sparse@vger.kernel.org, linux-crypto@vger.kernel.org, kernel-hardening@lists.openwall.com, xen-devel@lists.xenproject.org Subject: [Xen-devel] [RFC v3 17/27] xen: Adapt assembly for PIE support X-BeenThere: xen-devel@lists.xen.org X-Mailman-Version: 2.1.18 Precedence: list List-Id: Xen developer discussion List-Unsubscribe: , List-Post: List-Help: List-Subscribe: , MIME-Version: 1.0 Errors-To: xen-devel-bounces@lists.xen.org Sender: "Xen-devel" X-Virus-Scanned: ClamAV using ClamSMTP Change the assembly code to use the new _ASM_GET_PTR macro which get a symbol reference while being PIE compatible. Adapt the relocation tool to ignore 32-bit Xen code. Position Independent Executable (PIE) support will allow to extended the KASLR randomization range below the -2G memory limit. Signed-off-by: Thomas Garnier --- arch/x86/tools/relocs.c | 16 +++++++++++++++- arch/x86/xen/xen-head.S | 9 +++++---- arch/x86/xen/xen-pvh.S | 13 +++++++++---- 3 files changed, 29 insertions(+), 9 deletions(-) diff --git a/arch/x86/tools/relocs.c b/arch/x86/tools/relocs.c index 5d3eb2760198..bc032ad88b22 100644 --- a/arch/x86/tools/relocs.c +++ b/arch/x86/tools/relocs.c @@ -831,6 +831,16 @@ static int is_percpu_sym(ElfW(Sym) *sym, const char *symname) strncmp(symname, "init_per_cpu_", 13); } +/* + * Check if the 32-bit relocation is within the xenpvh 32-bit code. + * If so, ignores it. + */ +static int is_in_xenpvh_assembly(ElfW(Addr) offset) +{ + ElfW(Sym) *sym = sym_lookup("pvh_start_xen"); + return sym && (offset >= sym->st_value) && + (offset < (sym->st_value + sym->st_size)); +} static int do_reloc64(struct section *sec, Elf_Rel *rel, ElfW(Sym) *sym, const char *symname) @@ -892,8 +902,12 @@ static int do_reloc64(struct section *sec, Elf_Rel *rel, ElfW(Sym) *sym, * the relocations are processed. * Make sure that the offset will fit. */ - if (r_type != R_X86_64_64 && (int32_t)offset != (int64_t)offset) + if (r_type != R_X86_64_64 && + (int32_t)offset != (int64_t)offset) { + if (is_in_xenpvh_assembly(offset)) + break; die("Relocation offset doesn't fit in 32 bits\n"); + } if (r_type == R_X86_64_64) add_reloc(&relocs64, offset); diff --git a/arch/x86/xen/xen-head.S b/arch/x86/xen/xen-head.S index 124941d09b2b..e5b7b9566191 100644 --- a/arch/x86/xen/xen-head.S +++ b/arch/x86/xen/xen-head.S @@ -25,14 +25,15 @@ ENTRY(startup_xen) /* Clear .bss */ xor %eax,%eax - mov $__bss_start, %_ASM_DI - mov $__bss_stop, %_ASM_CX + _ASM_GET_PTR(__bss_start, %_ASM_DI) + _ASM_GET_PTR(__bss_stop, %_ASM_CX) sub %_ASM_DI, %_ASM_CX shr $__ASM_SEL(2, 3), %_ASM_CX rep __ASM_SIZE(stos) - mov %_ASM_SI, xen_start_info - mov $init_thread_union+THREAD_SIZE, %_ASM_SP + _ASM_GET_PTR(xen_start_info, %_ASM_AX) + mov %_ASM_SI, (%_ASM_AX) + _ASM_GET_PTR(init_thread_union+THREAD_SIZE, %_ASM_SP) jmp xen_start_kernel END(startup_xen) diff --git a/arch/x86/xen/xen-pvh.S b/arch/x86/xen/xen-pvh.S index e1a5fbeae08d..43e234c7c2de 100644 --- a/arch/x86/xen/xen-pvh.S +++ b/arch/x86/xen/xen-pvh.S @@ -101,8 +101,8 @@ ENTRY(pvh_start_xen) call xen_prepare_pvh /* startup_64 expects boot_params in %rsi. */ - mov $_pa(pvh_bootparams), %rsi - mov $_pa(startup_64), %rax + movabs $_pa(pvh_bootparams), %rsi + movabs $_pa(startup_64), %rax jmp *%rax #else /* CONFIG_X86_64 */ @@ -137,10 +137,15 @@ END(pvh_start_xen) .section ".init.data","aw" .balign 8 + /* + * Use a quad for _pa(gdt_start) because PIE does not understand a + * long is enough. The resulting value will still be in the lower long + * part. + */ gdt: .word gdt_end - gdt_start - .long _pa(gdt_start) - .word 0 + .quad _pa(gdt_start) + .balign 8 gdt_start: .quad 0x0000000000000000 /* NULL descriptor */ .quad 0x0000000000000000 /* reserved */