From patchwork Wed Oct 4 21:20:01 2017 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Thomas Garnier X-Patchwork-Id: 9985561 Return-Path: Received: from mail.wl.linuxfoundation.org (pdx-wl-mail.web.codeaurora.org [172.30.200.125]) by pdx-korg-patchwork.web.codeaurora.org (Postfix) with ESMTP id 42F9260586 for ; Wed, 4 Oct 2017 21:23:32 +0000 (UTC) Received: from mail.wl.linuxfoundation.org (localhost [127.0.0.1]) by mail.wl.linuxfoundation.org (Postfix) with ESMTP id 33D5F28C2F for ; Wed, 4 Oct 2017 21:23:32 +0000 (UTC) Received: by mail.wl.linuxfoundation.org (Postfix, from userid 486) id 2783A28C2E; Wed, 4 Oct 2017 21:23:32 +0000 (UTC) X-Spam-Checker-Version: SpamAssassin 3.3.1 (2010-03-16) on pdx-wl-mail.web.codeaurora.org X-Spam-Level: X-Spam-Status: No, score=-3.6 required=2.0 tests=BAYES_00, DKIM_ADSP_CUSTOM_MED, DKIM_SIGNED, RCVD_IN_DNSWL_MED, RCVD_IN_SORBS_SPAM, T_DKIM_INVALID autolearn=ham version=3.3.1 Received: from lists.xenproject.org (lists.xenproject.org [192.237.175.120]) (using TLSv1.2 with cipher AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by mail.wl.linuxfoundation.org (Postfix) with ESMTPS id 7B1E128C31 for ; Wed, 4 Oct 2017 21:23:31 +0000 (UTC) Received: from localhost ([127.0.0.1] helo=lists.xenproject.org) by lists.xenproject.org with esmtp (Exim 4.84_2) (envelope-from ) id 1dzr6m-0003cK-KA; Wed, 04 Oct 2017 21:21:36 +0000 Received: from mail6.bemta6.messagelabs.com ([193.109.254.103]) by lists.xenproject.org with esmtp (Exim 4.84_2) (envelope-from ) id 1dzr6l-0003Xp-B1 for xen-devel@lists.xenproject.org; Wed, 04 Oct 2017 21:21:35 +0000 Received: from [193.109.254.147] by server-1.bemta-6.messagelabs.com id 21/BE-03414-ED055D95; Wed, 04 Oct 2017 21:21:34 +0000 X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFtrNIsWRWlGSWpSXmKPExsXiVRusr3s34Gq kwZ5eU4vvWyYzOTB6HP5whSWAMYo1My8pvyKBNeP4qRdsBTslKnp2X2BrYFwj0sXIxSEkMI1R YmZnKzOIwyLwikXi2ZUjLCCOhEA/q8TeR1PYuhg5gZwsiYe7j7BD2GkSras6mCDsGoklD38wg thCAkoSWzcsZYYY+5dRonPqebAGNgEtiT0N85lAEiICs0Qkbr3uYQNxmAXOMEkc7zvJClIlLO AmcfMFRAeLgKrEv6ZZLCA2r4ClRH/3SxaIdSYSD49cA6vnBIofOfGGGWK1hUTrmftMExgFFzA yrGLUKE4tKkst0jU000sqykzPKMlNzMzRNTQw08tNLS5OTE/NSUwq1kvOz93ECAw8BiDYwXh/ Y8AhRkkOJiVR3k2+VyOF+JLyUyozEosz4otKc1KLDzHKcHAoSfA+9AfKCRalpqdWpGXmAGMAJ i3BwaMkwjsZJM1bXJCYW5yZDpE6xWjJsW/PrT9MHI9u3AWSHTeBpBBLXn5eqpQ472aQBgGQho zSPLhxsDi9xCgrJczLCHSgEE9BalFuZgmq/CtGcQ5GJWHeByBTeDLzSuC2vgI6iAnooDlNV0A OKklESEk1MKb/Llm/6viJSdninveWalyTqEpfVH8vyHvz+wsF3HcEEiImLVjyiSV0S8G5bbzT 3frWVBf3vbs/dcW/+Ij/d3aX77fc9S488Hr4tzY+8d75zSdCdzg9LhL3kTzx5t6b6xrt26/Xm Wl/0nJwYrFrPvKYafGntB6u3+HvvM0f5D5drTx78on/E38psRRnJBpqMRcVJwIAamtSJs4CAA A= X-Env-Sender: thgarnie@google.com X-Msg-Ref: server-11.tower-27.messagelabs.com!1507152092!88144615!1 X-Originating-IP: [74.125.83.47] X-SpamReason: No, hits=0.0 required=7.0 tests= X-StarScan-Received: X-StarScan-Version: 9.4.45; banners=-,-,- X-VirusChecked: Checked Received: (qmail 13872 invoked from network); 4 Oct 2017 21:21:33 -0000 Received: from mail-pg0-f47.google.com (HELO mail-pg0-f47.google.com) (74.125.83.47) by server-11.tower-27.messagelabs.com with AES128-GCM-SHA256 encrypted SMTP; 4 Oct 2017 21:21:33 -0000 Received: by mail-pg0-f47.google.com with SMTP id k7so2219306pga.3 for ; Wed, 04 Oct 2017 14:21:33 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20161025; h=from:to:cc:subject:date:message-id:in-reply-to:references; bh=XDPD+BN3I5KbJk1S37u4pgVf5Mmlyc2fod5SXfxZZmc=; b=AhxB4Z5eY+nrnPP+DYvpoJ3uL+abcoTMyk7DCefY7Emr0LjBlQP3ZzW01phsq8hX4c FCbJDXKJI8LlXtR19ZzIW9kyE1zIsoPq1Hos8PhYrFSysE5A+870K7AphZ9yTR36vP62 heUh5zEGXtKXJboaqCd7ZhZDH4QGL5Zt6YP3s7C5pL3xzqHt3pa9jweKjZJmNJl+18+J wwzVB9pHWT5LlX/fB3xZnRxN3N4Ov7XBwQXYX2p5uVRR6tHydEn+H1iag4iIDVeJ63Ab f8YuOj06H+N2fePP2uQoG/7lQJorztUTfE8Gwn8ExytSlKkiY1YcVoZt4pAM7hTFZ+Yt Y9yQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:to:cc:subject:date:message-id:in-reply-to :references; bh=XDPD+BN3I5KbJk1S37u4pgVf5Mmlyc2fod5SXfxZZmc=; b=rslHd/vK53wqfCGlRDsZY9ZfJgEPs4ewqBEO0pmVyuKURjw1xIcFulft9jByFSnmlF uBE2OVeSz3EJLM1RD2q2rTHAGpTGGiK5+qVT6I5FdEpvxnoEPMMZpIkztTUN3/Fy/zaC Gw34GeNpiQZrkWaMRsurykac4YoNQ3GWl/kiAKag4Dkrtb0cj5kkkoxL2ToewAzBsLVa xlvlRS6mgRwPPy3rPzqEIOnaj8487AT1Grn57+4DW1Qo/E0/QI6ONxde8SOOXYsD2pcc ttqbelhcRu6R+bt4B7po3+xk5VuU74/nTjrG3MqEwC3hNR6LQyLRqfzz8oidZ2Wj8Jdw QyzA== X-Gm-Message-State: AMCzsaXO21/BFmFAslRM8YLTjfqSZRlc6rWCUSRf0qMKVrbcUwQ6QtbH c82Jp+cZjDjbQOg2z9R7ZsewkQ== X-Google-Smtp-Source: AOwi7QDgLP3rkacqYaj9G7hUGEL4dYp+WR5yNfgGEtZ3IxGgxGSti/BvNnXM5hdQCC/uzeR3SEW/bQ== X-Received: by 10.159.216.151 with SMTP id s23mr10467640plp.176.1507152091429; Wed, 04 Oct 2017 14:21:31 -0700 (PDT) Received: from skynet.sea.corp.google.com ([172.31.92.33]) by smtp.gmail.com with ESMTPSA id s68sm30204019pfd.72.2017.10.04.14.21.30 (version=TLS1_2 cipher=ECDHE-RSA-AES128-SHA bits=128/128); Wed, 04 Oct 2017 14:21:30 -0700 (PDT) From: Thomas Garnier To: Herbert Xu , "David S . Miller" , Thomas Gleixner , Ingo Molnar , "H . Peter Anvin" , Peter Zijlstra , Josh Poimboeuf , Thomas Garnier , Arnd Bergmann , Kees Cook , Matthias Kaehlcke , Tom Lendacky , Andy Lutomirski , "Kirill A . Shutemov" , Borislav Petkov , "Rafael J . Wysocki" , Len Brown , Pavel Machek , Juergen Gross , Chris Wright , Alok Kataria , Rusty Russell , Tejun Heo , Christoph Lameter , Boris Ostrovsky , Alexey Dobriyan , Andrew Morton , Paul Gortmaker , Chris Metcalf , "Paul E . McKenney" , Nicolas Pitre , Borislav Petkov , "Luis R . Rodriguez" , Greg Kroah-Hartman , Christopher Li , Steven Rostedt , Jason Baron , Dou Liyang , "Rafael J . Wysocki" , Mika Westerberg , Lukas Wunner , Masahiro Yamada , Alexei Starovoitov , Daniel Borkmann , Markus Trippelsdorf , Paolo Bonzini , =?UTF-8?q?Radim=20Kr=C4=8Dm=C3=A1=C5=99?= , Joerg Roedel , Rik van Riel , David Howells , Ard Biesheuvel , Waiman Long , Kyle Huey , Andrey Ryabinin , Jonathan Corbet , Matthew Wilcox , Michal Hocko , Peter Foley , Paul Bolle , Jiri Kosina , Rob Landley , "H . J . Lu" , Baoquan He , =?UTF-8?q?Jan=20H=20=2E=20Sch=C3=B6nherr?= , Daniel Micay Date: Wed, 4 Oct 2017 14:20:01 -0700 Message-Id: <20171004212003.28296-26-thgarnie@google.com> X-Mailer: git-send-email 2.14.2.920.gcf0c67979c-goog In-Reply-To: <20171004212003.28296-1-thgarnie@google.com> References: <20171004212003.28296-1-thgarnie@google.com> Cc: linux-arch@vger.kernel.org, kvm@vger.kernel.org, linux-pm@vger.kernel.org, x86@kernel.org, linux-doc@vger.kernel.org, linux-kernel@vger.kernel.org, virtualization@lists.linux-foundation.org, linux-sparse@vger.kernel.org, linux-crypto@vger.kernel.org, kernel-hardening@lists.openwall.com, xen-devel@lists.xenproject.org Subject: [Xen-devel] [RFC v3 25/27] x86/pie: Add option to build the kernel as PIE X-BeenThere: xen-devel@lists.xen.org X-Mailman-Version: 2.1.18 Precedence: list List-Id: Xen developer discussion List-Unsubscribe: , List-Post: List-Help: List-Subscribe: , MIME-Version: 1.0 Errors-To: xen-devel-bounces@lists.xen.org Sender: "Xen-devel" X-Virus-Scanned: ClamAV using ClamSMTP Add the CONFIG_X86_PIE option which builds the kernel as a Position Independent Executable (PIE). The kernel is currently build with the mcmodel=kernel option which forces it to stay on the top 2G of the virtual address space. With PIE, the kernel will be able to move below the current limit. The --emit-relocs linker option was kept instead of using -pie to limit the impact on mapped sections. Any incompatible relocation will be catch by the arch/x86/tools/relocs binary at compile time. Performance/Size impact: Size of vmlinux (Default configuration): File size: - PIE disabled: +0.000031% - PIE enabled: -3.210% (less relocations) .text section: - PIE disabled: +0.000644% - PIE enabled: +0.837% Size of vmlinux (Ubuntu configuration): File size: - PIE disabled: -0.201% - PIE enabled: -0.082% .text section: - PIE disabled: same - PIE enabled: +1.319% Size of vmlinux (Default configuration + ORC): File size: - PIE enabled: -3.167% .text section: - PIE enabled: +0.814% Size of vmlinux (Ubuntu configuration + ORC): File size: - PIE enabled: -3.167% .text section: - PIE enabled: +1.26% The size increase is mainly due to not having access to the 32-bit signed relocation that can be used with mcmodel=kernel. A small part is due to reduced optimization for PIE code. This bug [1] was opened with gcc to provide a better code generation for kernel PIE. Hackbench (50% and 1600% on thread/process for pipe/sockets): - PIE disabled: no significant change (avg +0.1% on latest test). - PIE enabled: between -0.50% to +0.86% in average (default and Ubuntu config). slab_test (average of 10 runs): - PIE disabled: no significant change (-2% on latest run, likely noise). - PIE enabled: between -1% and +0.8% on latest runs. Kernbench (average of 10 Half and Optimal runs): Elapsed Time: - PIE disabled: no significant change (avg -0.239%) - PIE enabled: average +0.07% System Time: - PIE disabled: no significant change (avg -0.277%) - PIE enabled: average +0.7% [1] https://gcc.gnu.org/bugzilla/show_bug.cgi?id=82303 Signed-off-by: Thomas Garnier --- arch/x86/Kconfig | 8 ++++++++ arch/x86/Makefile | 1 + 2 files changed, 9 insertions(+) diff --git a/arch/x86/Kconfig b/arch/x86/Kconfig index 1e4b399c64e5..b92f96923712 100644 --- a/arch/x86/Kconfig +++ b/arch/x86/Kconfig @@ -2141,6 +2141,14 @@ config X86_GLOBAL_STACKPROTECTOR bool depends on CC_STACKPROTECTOR +config X86_PIE + bool + depends on X86_64 + select DEFAULT_HIDDEN + select DYNAMIC_MODULE_BASE + select MODULE_REL_CRCS if MODVERSIONS + select X86_GLOBAL_STACKPROTECTOR if CC_STACKPROTECTOR + config HOTPLUG_CPU bool "Support for hot-pluggable CPUs" depends on SMP diff --git a/arch/x86/Makefile b/arch/x86/Makefile index 42774185a58a..c49855b4b1be 100644 --- a/arch/x86/Makefile +++ b/arch/x86/Makefile @@ -144,6 +144,7 @@ else KBUILD_CFLAGS += -mno-red-zone ifdef CONFIG_X86_PIE + KBUILD_CFLAGS += -fPIC KBUILD_LDFLAGS_MODULE += -T $(srctree)/arch/x86/kernel/module.lds else KBUILD_CFLAGS += -mcmodel=kernel