From patchwork Tue Mar 16 03:17:34 2021 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Jordan Niethe X-Patchwork-Id: 1453657 Return-Path: X-Original-To: patchwork-incoming@ozlabs.org Delivered-To: patchwork-incoming@ozlabs.org Authentication-Results: ozlabs.org; spf=pass (sender SPF authorized) smtp.mailfrom=lists.ozlabs.org (client-ip=112.213.38.117; helo=lists.ozlabs.org; envelope-from=linuxppc-dev-bounces+patchwork-incoming=ozlabs.org@lists.ozlabs.org; receiver=) Authentication-Results: ozlabs.org; dkim=fail reason="signature verification failed" (2048-bit key; unprotected) header.d=gmail.com header.i=@gmail.com header.a=rsa-sha256 header.s=20161025 header.b=mKPcFr7f; dkim-atps=neutral Received: from lists.ozlabs.org (lists.ozlabs.org [112.213.38.117]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits)) (No client certificate requested) by ozlabs.org (Postfix) with ESMTPS id 4Dzz5n37zCz9sWb for ; Tue, 16 Mar 2021 14:18:53 +1100 (AEDT) Received: from boromir.ozlabs.org (localhost [IPv6:::1]) by lists.ozlabs.org (Postfix) with ESMTP id 4Dzz5n27ZHz2yxZ for ; Tue, 16 Mar 2021 14:18:53 +1100 (AEDT) Authentication-Results: lists.ozlabs.org; dkim=fail reason="signature verification failed" (2048-bit key; unprotected) header.d=gmail.com header.i=@gmail.com header.a=rsa-sha256 header.s=20161025 header.b=mKPcFr7f; dkim-atps=neutral X-Original-To: linuxppc-dev@lists.ozlabs.org Delivered-To: linuxppc-dev@lists.ozlabs.org Authentication-Results: lists.ozlabs.org; spf=pass (sender SPF authorized) smtp.mailfrom=gmail.com (client-ip=2607:f8b0:4864:20::62e; helo=mail-pl1-x62e.google.com; envelope-from=jniethe5@gmail.com; receiver=) Authentication-Results: lists.ozlabs.org; dkim=pass (2048-bit key; unprotected) header.d=gmail.com header.i=@gmail.com header.a=rsa-sha256 header.s=20161025 header.b=mKPcFr7f; dkim-atps=neutral Received: from mail-pl1-x62e.google.com (mail-pl1-x62e.google.com [IPv6:2607:f8b0:4864:20::62e]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by lists.ozlabs.org (Postfix) with ESMTPS id 4Dzz5N16Ycz2yhl for ; Tue, 16 Mar 2021 14:18:31 +1100 (AEDT) Received: by mail-pl1-x62e.google.com with SMTP id c16so16304797ply.0 for ; Mon, 15 Mar 2021 20:18:31 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=from:to:cc:subject:date:message-id:mime-version :content-transfer-encoding; bh=9Mv4k+bwxOezfvxU4AwqD9Zx/VQngin96IFhNJ+MTB8=; b=mKPcFr7fJWIf9axsWK36tSnDsMU0Lpaeq4XDschP6qmnGe0g50sro9i6L9B2NAK6+0 PhwbVoHh+LjeBUIMe3x/YKhdr7fD9wcQoyuIZkgBzErVgC6PiUKnKuZSQFKk5TXY3oue /oljGgJFmapqLX7pxEBRu70x+CTu5BPx6ze9GWaOkwJl8YA1Nv3xBW+vWSVULxsEAeuF uGMe4f1kh6E+motYvG6u8KNE0gm2nyjCQZiVXo49XyYq5fEaKocJ2pgkc+9xAySLC8m3 OflQ9mutWZOyJiTNTfde9GLDS5/2LeKr1ee/SggTxhlIWSP6Fgeby5/4/+DKnDvKNsbL WnwQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:to:cc:subject:date:message-id:mime-version :content-transfer-encoding; bh=9Mv4k+bwxOezfvxU4AwqD9Zx/VQngin96IFhNJ+MTB8=; b=tKRr77mC3wkRZ13UzjvtKKpSN2Vxj3ZYZjANP1Jy2Teglj7TdOH9WanVMiTjveEwpq OC+/iIBOsfiuOkP67OOqWlsIwjpxmbmm1DZ7WaTNOi8qyusMFMJmDZrV36wEe9oTY/AU mqs84rH4qjKvyu7Lx3ROt1/xfi8UwiW/xrjo9Mr7Lwvm6CFhEVMHvR57elGOThUpZ/cD 8hTaM21PSvyLxkjDehlvnpg5AySZs049rRC8gDoGxMCJ9NKarQGUXZ8rfIFF5Im0OAKs vINiDlzC2DxX+r+6sAHGLWLJhgF0Exz4v3eAEljzgNbo7mimrs4eJBfBiSyYwf5HI2nz CkMw== X-Gm-Message-State: AOAM532gkMLt3U7tirvaWbjp+iTgGBQLuI659k2bR4CC9GSgci7LvQkC 8yCCALzvgfpPDE/Vo5nGzlZKsELnZnmj5A== X-Google-Smtp-Source: ABdhPJydDVjaZqhcKn+UEwNK89hRlC2KEQu6TGGSU1qpkdIwjCTCJvp3qIctUGWR81Z/MUy5QqVubA== X-Received: by 2002:a17:902:9b8b:b029:e6:b027:2f96 with SMTP id y11-20020a1709029b8bb02900e6b0272f96mr8988066plp.28.1615864707626; Mon, 15 Mar 2021 20:18:27 -0700 (PDT) Received: from localhost.localdomain (159-196-117-139.9fc475.syd.nbn.aussiebb.net. [159.196.117.139]) by smtp.gmail.com with ESMTPSA id o13sm15098809pgv.40.2021.03.15.20.18.23 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 15 Mar 2021 20:18:27 -0700 (PDT) From: Jordan Niethe To: linuxppc-dev@lists.ozlabs.org Subject: [PATCH v9 1/8] powerpc/mm: Implement set_memory() routines Date: Tue, 16 Mar 2021 14:17:34 +1100 Message-Id: <20210316031741.1004850-1-jniethe5@gmail.com> X-Mailer: git-send-email 2.25.1 MIME-Version: 1.0 X-BeenThere: linuxppc-dev@lists.ozlabs.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: Linux on PowerPC Developers Mail List List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Cc: christophe.leroy@c-s.fr, ajd@linux.ibm.com, npiggin@gmail.com, naveen.n.rao@linux.ibm.com, Jordan Niethe , dja@axtens.net Errors-To: linuxppc-dev-bounces+patchwork-incoming=ozlabs.org@lists.ozlabs.org Sender: "Linuxppc-dev" From: Russell Currey The set_memory_{ro/rw/nx/x}() functions are required for STRICT_MODULE_RWX, and are generally useful primitives to have. This implementation is designed to be completely generic across powerpc's many MMUs. It's possible that this could be optimised to be faster for specific MMUs, but the focus is on having a generic and safe implementation for now. This implementation does not handle cases where the caller is attempting to change the mapping of the page it is executing from, or if another CPU is concurrently using the page being altered. These cases likely shouldn't happen, but a more complex implementation with MMU-specific code could safely handle them, so that is left as a TODO for now. These functions do nothing if STRICT_KERNEL_RWX is not enabled. Reviewed-by: Daniel Axtens Signed-off-by: Russell Currey Signed-off-by: Christophe Leroy [jpn: rebase on next plus "powerpc/mm/64s: Allow STRICT_KERNEL_RWX again"] Signed-off-by: Jordan Niethe --- arch/powerpc/Kconfig | 1 + arch/powerpc/include/asm/set_memory.h | 32 +++++++++++ arch/powerpc/mm/Makefile | 2 +- arch/powerpc/mm/pageattr.c | 81 +++++++++++++++++++++++++++ 4 files changed, 115 insertions(+), 1 deletion(-) create mode 100644 arch/powerpc/include/asm/set_memory.h create mode 100644 arch/powerpc/mm/pageattr.c diff --git a/arch/powerpc/Kconfig b/arch/powerpc/Kconfig index fc7f5c5933e6..4498a27ac9db 100644 --- a/arch/powerpc/Kconfig +++ b/arch/powerpc/Kconfig @@ -135,6 +135,7 @@ config PPC select ARCH_HAS_MEMBARRIER_CALLBACKS select ARCH_HAS_MEMBARRIER_SYNC_CORE select ARCH_HAS_SCALED_CPUTIME if VIRT_CPU_ACCOUNTING_NATIVE && PPC_BOOK3S_64 + select ARCH_HAS_SET_MEMORY select ARCH_HAS_STRICT_KERNEL_RWX if ((PPC_BOOK3S_64 || PPC32) && !HIBERNATION) select ARCH_HAS_TICK_BROADCAST if GENERIC_CLOCKEVENTS_BROADCAST select ARCH_HAS_UACCESS_FLUSHCACHE diff --git a/arch/powerpc/include/asm/set_memory.h b/arch/powerpc/include/asm/set_memory.h new file mode 100644 index 000000000000..64011ea444b4 --- /dev/null +++ b/arch/powerpc/include/asm/set_memory.h @@ -0,0 +1,32 @@ +/* SPDX-License-Identifier: GPL-2.0 */ +#ifndef _ASM_POWERPC_SET_MEMORY_H +#define _ASM_POWERPC_SET_MEMORY_H + +#define SET_MEMORY_RO 0 +#define SET_MEMORY_RW 1 +#define SET_MEMORY_NX 2 +#define SET_MEMORY_X 3 + +int change_memory_attr(unsigned long addr, int numpages, long action); + +static inline int set_memory_ro(unsigned long addr, int numpages) +{ + return change_memory_attr(addr, numpages, SET_MEMORY_RO); +} + +static inline int set_memory_rw(unsigned long addr, int numpages) +{ + return change_memory_attr(addr, numpages, SET_MEMORY_RW); +} + +static inline int set_memory_nx(unsigned long addr, int numpages) +{ + return change_memory_attr(addr, numpages, SET_MEMORY_NX); +} + +static inline int set_memory_x(unsigned long addr, int numpages) +{ + return change_memory_attr(addr, numpages, SET_MEMORY_X); +} + +#endif diff --git a/arch/powerpc/mm/Makefile b/arch/powerpc/mm/Makefile index 3b4e9e4e25ea..d8a08abde1ae 100644 --- a/arch/powerpc/mm/Makefile +++ b/arch/powerpc/mm/Makefile @@ -5,7 +5,7 @@ ccflags-$(CONFIG_PPC64) := $(NO_MINIMAL_TOC) -obj-y := fault.o mem.o pgtable.o mmap.o maccess.o \ +obj-y := fault.o mem.o pgtable.o mmap.o maccess.o pageattr.o \ init_$(BITS).o pgtable_$(BITS).o \ pgtable-frag.o ioremap.o ioremap_$(BITS).o \ init-common.o mmu_context.o drmem.o diff --git a/arch/powerpc/mm/pageattr.c b/arch/powerpc/mm/pageattr.c new file mode 100644 index 000000000000..2da3fbab6ff7 --- /dev/null +++ b/arch/powerpc/mm/pageattr.c @@ -0,0 +1,81 @@ +// SPDX-License-Identifier: GPL-2.0 + +/* + * MMU-generic set_memory implementation for powerpc + * + * Copyright 2019, IBM Corporation. + */ + +#include +#include + +#include +#include +#include + + +/* + * Updates the attributes of a page in three steps: + * + * 1. invalidate the page table entry + * 2. flush the TLB + * 3. install the new entry with the updated attributes + * + * This is unsafe if the caller is attempting to change the mapping of the + * page it is executing from, or if another CPU is concurrently using the + * page being altered. + * + * TODO make the implementation resistant to this. + * + * NOTE: can be dangerous to call without STRICT_KERNEL_RWX + */ +static int change_page_attr(pte_t *ptep, unsigned long addr, void *data) +{ + long action = (long)data; + pte_t pte; + + spin_lock(&init_mm.page_table_lock); + + /* invalidate the PTE so it's safe to modify */ + pte = ptep_get_and_clear(&init_mm, addr, ptep); + flush_tlb_kernel_range(addr, addr + PAGE_SIZE); + + /* modify the PTE bits as desired, then apply */ + switch (action) { + case SET_MEMORY_RO: + pte = pte_wrprotect(pte); + break; + case SET_MEMORY_RW: + pte = pte_mkwrite(pte); + break; + case SET_MEMORY_NX: + pte = pte_exprotect(pte); + break; + case SET_MEMORY_X: + pte = pte_mkexec(pte); + break; + default: + WARN_ON_ONCE(1); + break; + } + + set_pte_at(&init_mm, addr, ptep, pte); + spin_unlock(&init_mm.page_table_lock); + + return 0; +} + +int change_memory_attr(unsigned long addr, int numpages, long action) +{ + unsigned long start = ALIGN_DOWN(addr, PAGE_SIZE); + unsigned long sz = numpages * PAGE_SIZE; + + if (!IS_ENABLED(CONFIG_STRICT_KERNEL_RWX)) + return 0; + + if (numpages <= 0) + return 0; + + return apply_to_existing_page_range(&init_mm, start, sz, + change_page_attr, (void *)action); +} From patchwork Tue Mar 16 03:17:35 2021 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Jordan Niethe X-Patchwork-Id: 1453658 Return-Path: X-Original-To: patchwork-incoming@ozlabs.org Delivered-To: patchwork-incoming@ozlabs.org Authentication-Results: ozlabs.org; spf=pass (sender SPF authorized) smtp.mailfrom=lists.ozlabs.org (client-ip=112.213.38.117; helo=lists.ozlabs.org; envelope-from=linuxppc-dev-bounces+patchwork-incoming=ozlabs.org@lists.ozlabs.org; receiver=) Authentication-Results: ozlabs.org; dkim=fail reason="signature verification failed" (2048-bit key; unprotected) header.d=gmail.com header.i=@gmail.com header.a=rsa-sha256 header.s=20161025 header.b=D6PXcaqu; dkim-atps=neutral Received: from lists.ozlabs.org (lists.ozlabs.org [112.213.38.117]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits)) (No client certificate requested) by ozlabs.org (Postfix) with ESMTPS id 4Dzz6F3HyNz9sSC for ; Tue, 16 Mar 2021 14:19:17 +1100 (AEDT) Received: from boromir.ozlabs.org (localhost [IPv6:::1]) by lists.ozlabs.org (Postfix) with ESMTP id 4Dzz6F2FjVz30Mj for ; Tue, 16 Mar 2021 14:19:17 +1100 (AEDT) Authentication-Results: lists.ozlabs.org; dkim=fail reason="signature verification failed" (2048-bit key; unprotected) header.d=gmail.com header.i=@gmail.com header.a=rsa-sha256 header.s=20161025 header.b=D6PXcaqu; dkim-atps=neutral X-Original-To: linuxppc-dev@lists.ozlabs.org Delivered-To: linuxppc-dev@lists.ozlabs.org Authentication-Results: lists.ozlabs.org; spf=pass (sender SPF authorized) smtp.mailfrom=gmail.com (client-ip=2607:f8b0:4864:20::1035; helo=mail-pj1-x1035.google.com; envelope-from=jniethe5@gmail.com; receiver=) Authentication-Results: lists.ozlabs.org; dkim=pass (2048-bit key; unprotected) header.d=gmail.com header.i=@gmail.com header.a=rsa-sha256 header.s=20161025 header.b=D6PXcaqu; dkim-atps=neutral Received: from mail-pj1-x1035.google.com (mail-pj1-x1035.google.com [IPv6:2607:f8b0:4864:20::1035]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by lists.ozlabs.org (Postfix) with ESMTPS id 4Dzz5Q4WBjz2yhq for ; Tue, 16 Mar 2021 14:18:34 +1100 (AEDT) Received: by mail-pj1-x1035.google.com with SMTP id k23-20020a17090a5917b02901043e35ad4aso576097pji.3 for ; Mon, 15 Mar 2021 20:18:34 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=from:to:cc:subject:date:message-id:in-reply-to:references :mime-version:content-transfer-encoding; bh=wmdzNu0EEZ/2UBS1TwxzuVfctzsk8OvLrPvT5wa64/s=; b=D6PXcaquEIYcoAVoxNgHokaoRBSjnyR7CSdtp+lg9fASyh0vpTH9tnLvrOqVt7qupQ yA5lEOo6HbJbqwnMFIN8Eoeiz7oTgect/DLZO10g5RQS/6riIiMotZ8F7M6wnmd8a9aR GQwmfZUMZXK4l5UyholGkq42+BWYUmaQlTG5eoPmADZXh4WQwr/KXUO3XLphlj1/wjCB 5iW69l/7Q75NshjFj3C0wNcYNJN6Sjr+wLZTefCM7ONoEn6kT29GipB7C82I34gya2Fc 1KolxYf3bcPJR8vShBCtIKaI9isoNOm6W/jJ2Fa27jps7QU+Ya040ktjIvONCIwuPFkM hXIw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:to:cc:subject:date:message-id:in-reply-to :references:mime-version:content-transfer-encoding; bh=wmdzNu0EEZ/2UBS1TwxzuVfctzsk8OvLrPvT5wa64/s=; b=i5q99KQjN5ENy1tGqOZnuWtEHH9fIR60/2yNPFFEnJVrOK1OoJo5790PnmnCbV2zxI EZZxfKKJ7OrG/JKdDyuKTt7PeK9wTbHaxRxRQpQWHYv/BTvwMlsKiw+YhaOJmF5eneKq CA28P3DhMhyVresXeLo9V8rpuE7mGFAEmUf4zS4Su6pmACpkB6uPU0jRrQD2S6QQqCYV j42P4s5oVEcH/gRW7uR30jirD2u7T6N1k5/rLDLlaSlOruBh/p++jyap+2LzdgpcKTmb OJm/E9OhNaPnNBLS31WQIVhrW9rhLD2EYr8+QXfPAbAldO3uZK0/BLn1FIVmL76sLafI xcqQ== X-Gm-Message-State: AOAM531o0rY5Ze5OZlpzZ57oU3h/FtZgUB+I8apoBSE5N3epLQN0VtSE jVj/q384rroUOIMaTNXjVifWe7E7c9S9QQ== X-Google-Smtp-Source: ABdhPJxou//XLuI64i36JBqOj12kGJU91AVjUECDAZDD3RrH1FZl1FryMi4ttQ1kTFqPTaT1Pb4rKA== X-Received: by 2002:a17:902:d64a:b029:e6:30a6:64e3 with SMTP id y10-20020a170902d64ab02900e630a664e3mr14753234plh.28.1615864711584; Mon, 15 Mar 2021 20:18:31 -0700 (PDT) Received: from localhost.localdomain (159-196-117-139.9fc475.syd.nbn.aussiebb.net. [159.196.117.139]) by smtp.gmail.com with ESMTPSA id o13sm15098809pgv.40.2021.03.15.20.18.28 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 15 Mar 2021 20:18:31 -0700 (PDT) From: Jordan Niethe To: linuxppc-dev@lists.ozlabs.org Subject: [PATCH v9 2/8] powerpc/lib/code-patching: Set up Strict RWX patching earlier Date: Tue, 16 Mar 2021 14:17:35 +1100 Message-Id: <20210316031741.1004850-2-jniethe5@gmail.com> X-Mailer: git-send-email 2.25.1 In-Reply-To: <20210316031741.1004850-1-jniethe5@gmail.com> References: <20210316031741.1004850-1-jniethe5@gmail.com> MIME-Version: 1.0 X-BeenThere: linuxppc-dev@lists.ozlabs.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: Linux on PowerPC Developers Mail List List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Cc: christophe.leroy@c-s.fr, ajd@linux.ibm.com, npiggin@gmail.com, Jordan Niethe , naveen.n.rao@linux.ibm.com, dja@axtens.net Errors-To: linuxppc-dev-bounces+patchwork-incoming=ozlabs.org@lists.ozlabs.org Sender: "Linuxppc-dev" setup_text_poke_area() is a late init call so it runs before mark_rodata_ro() and after the init calls. This lets all the init code patching simply write to their locations. In the future, kprobes is going to allocate its instruction pages RO which means they will need setup_text__poke_area() to have been already called for their code patching. However, init_kprobes() (which allocates and patches some instruction pages) is an early init call so it happens before setup_text__poke_area(). start_kernel() calls poking_init() before any of the init calls. On powerpc, poking_init() is currently a nop. setup_text_poke_area() relies on kernel virtual memory, cpu hotplug and per_cpu_areas being setup. setup_per_cpu_areas(), boot_cpu_hotplug_init() and mm_init() are called before poking_init(). Turn setup_text_poke_area() into poking_init(). Signed-off-by: Jordan Niethe Reviewed-by: Russell Currey --- v9: New to series --- arch/powerpc/lib/code-patching.c | 12 ++++-------- 1 file changed, 4 insertions(+), 8 deletions(-) diff --git a/arch/powerpc/lib/code-patching.c b/arch/powerpc/lib/code-patching.c index 2333625b5e31..b28afa1133db 100644 --- a/arch/powerpc/lib/code-patching.c +++ b/arch/powerpc/lib/code-patching.c @@ -65,14 +65,11 @@ static int text_area_cpu_down(unsigned int cpu) } /* - * Run as a late init call. This allows all the boot time patching to be done - * simply by patching the code, and then we're called here prior to - * mark_rodata_ro(), which happens after all init calls are run. Although - * BUG_ON() is rude, in this case it should only happen if ENOMEM, and we judge - * it as being preferable to a kernel that will crash later when someone tries - * to use patch_instruction(). + * Although BUG_ON() is rude, in this case it should only happen if ENOMEM, and + * we judge it as being preferable to a kernel that will crash later when + * someone tries to use patch_instruction(). */ -static int __init setup_text_poke_area(void) +int __init poking_init(void) { BUG_ON(!cpuhp_setup_state(CPUHP_AP_ONLINE_DYN, "powerpc/text_poke:online", text_area_cpu_up, @@ -80,7 +77,6 @@ static int __init setup_text_poke_area(void) return 0; } -late_initcall(setup_text_poke_area); /* * This can be called for kernel text or a module. From patchwork Tue Mar 16 03:17:36 2021 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Jordan Niethe X-Patchwork-Id: 1453659 Return-Path: X-Original-To: patchwork-incoming@ozlabs.org Delivered-To: patchwork-incoming@ozlabs.org Authentication-Results: ozlabs.org; spf=pass (sender SPF authorized) smtp.mailfrom=lists.ozlabs.org (client-ip=2404:9400:2:0:216:3eff:fee1:b9f1; helo=lists.ozlabs.org; envelope-from=linuxppc-dev-bounces+patchwork-incoming=ozlabs.org@lists.ozlabs.org; receiver=) Authentication-Results: ozlabs.org; dkim=fail reason="signature verification failed" (2048-bit key; unprotected) header.d=gmail.com header.i=@gmail.com header.a=rsa-sha256 header.s=20161025 header.b=DfJNM0SB; dkim-atps=neutral Received: from lists.ozlabs.org (lists.ozlabs.org [IPv6:2404:9400:2:0:216:3eff:fee1:b9f1]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits)) (No client certificate requested) by ozlabs.org (Postfix) with ESMTPS id 4Dzz6j1d8Yz9sSC for ; Tue, 16 Mar 2021 14:19:41 +1100 (AEDT) Received: from boromir.ozlabs.org (localhost [IPv6:::1]) by lists.ozlabs.org (Postfix) with ESMTP id 4Dzz6j0yBkz3bqT for ; Tue, 16 Mar 2021 14:19:41 +1100 (AEDT) Authentication-Results: lists.ozlabs.org; dkim=fail reason="signature verification failed" (2048-bit key; unprotected) header.d=gmail.com header.i=@gmail.com header.a=rsa-sha256 header.s=20161025 header.b=DfJNM0SB; dkim-atps=neutral X-Original-To: linuxppc-dev@lists.ozlabs.org Delivered-To: linuxppc-dev@lists.ozlabs.org Authentication-Results: lists.ozlabs.org; spf=pass (sender SPF authorized) smtp.mailfrom=gmail.com (client-ip=2607:f8b0:4864:20::62e; helo=mail-pl1-x62e.google.com; envelope-from=jniethe5@gmail.com; receiver=) Authentication-Results: lists.ozlabs.org; dkim=pass (2048-bit key; unprotected) header.d=gmail.com header.i=@gmail.com header.a=rsa-sha256 header.s=20161025 header.b=DfJNM0SB; dkim-atps=neutral Received: from mail-pl1-x62e.google.com (mail-pl1-x62e.google.com [IPv6:2607:f8b0:4864:20::62e]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by lists.ozlabs.org (Postfix) with ESMTPS id 4Dzz5T2z08z302p for ; Tue, 16 Mar 2021 14:18:37 +1100 (AEDT) Received: by mail-pl1-x62e.google.com with SMTP id 30so11726679ple.4 for ; Mon, 15 Mar 2021 20:18:37 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=from:to:cc:subject:date:message-id:in-reply-to:references :mime-version:content-transfer-encoding; bh=hoUZb06JTxTijcPbi8a4pUTkZ5jr9A6529n/cLWmg6Y=; b=DfJNM0SB3O3oMP+NfgSLaxGSFSvaOcmHN5P4MSP/9e/mw8GlIeOCIZuUED84mEEmjo rfdbNjIEZ9BnJsOCiAv8drxqe1afWRSoggTMvOtilDUMspauzuYBuJoYHBVPo3nILw33 KuIjWRic9lQulOKkQlWmbfU2k+v4VYam+OrQhqHLrvZaVCqQg+680cXkLVbqXl2Do9c7 KpVbJoeTKk8j+JWJrR7gnLDapGiO/Sw4bmERSirKqU9oXxVgN/biFfE0mKtL3g81w95u oKxld/nqEVb6ziBHNn2RSTuu792FLU/T9O2xfjQDGKqtzk2CyK6UH/eoXHHK475+7e2B jcyA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:to:cc:subject:date:message-id:in-reply-to :references:mime-version:content-transfer-encoding; bh=hoUZb06JTxTijcPbi8a4pUTkZ5jr9A6529n/cLWmg6Y=; b=Y9sUmsataQ1VHM6U6COgPCYO8AgaWZOz62ZwvSNnLZCipAU6GnQbx3HQc0xsy6CDRG AohPVpavET3FQ4AtjmAd45jUid8CyDmHjly0E3ZDEGvq+bkAzKF5SOdmt8rXSirqs3g6 FWRKZVH7GV8kLmmQoaQhBtKpX5iU7Q0dAFuQevXz8lDZWqw/IbJweoSnI+gaXabEWcp7 Ien/c6xxmhLUp0ZeOV68aFgookrx08x/aGWZ6mA3mVrkHSUmWFAcv4b6E+quki3ZAw3K 9TD4CVoEjd2Ax1qa4/EcZtCGnKdGHTmLxSy5FO/L6vzdt/iEbBirm7zGGf4Gu2qJfYuz cQPQ== X-Gm-Message-State: AOAM531spAwHjUaK09+IClvxMH32JlnT2Zmt56sZFsCMOKBKXxHY3D+C v+I7Y5tOi7qDKq40ivIuAAewkxSaSvq4Gg== X-Google-Smtp-Source: ABdhPJxMfI4Y8jl3Q4qDvbfmLQoTGmJdAP+KmY/ueOBcH5uj30qrJJ8RDQRNpaaTBLOAh/A62H1Klg== X-Received: by 2002:a17:90a:400f:: with SMTP id u15mr2445964pjc.80.1615864715651; Mon, 15 Mar 2021 20:18:35 -0700 (PDT) Received: from localhost.localdomain (159-196-117-139.9fc475.syd.nbn.aussiebb.net. [159.196.117.139]) by smtp.gmail.com with ESMTPSA id o13sm15098809pgv.40.2021.03.15.20.18.31 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 15 Mar 2021 20:18:35 -0700 (PDT) From: Jordan Niethe To: linuxppc-dev@lists.ozlabs.org Subject: [PATCH v9 3/8] powerpc/kprobes: Mark newly allocated probes as RO Date: Tue, 16 Mar 2021 14:17:36 +1100 Message-Id: <20210316031741.1004850-3-jniethe5@gmail.com> X-Mailer: git-send-email 2.25.1 In-Reply-To: <20210316031741.1004850-1-jniethe5@gmail.com> References: <20210316031741.1004850-1-jniethe5@gmail.com> MIME-Version: 1.0 X-BeenThere: linuxppc-dev@lists.ozlabs.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: Linux on PowerPC Developers Mail List List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Cc: christophe.leroy@c-s.fr, ajd@linux.ibm.com, npiggin@gmail.com, naveen.n.rao@linux.ibm.com, Jordan Niethe , dja@axtens.net Errors-To: linuxppc-dev-bounces+patchwork-incoming=ozlabs.org@lists.ozlabs.org Sender: "Linuxppc-dev" From: Russell Currey With CONFIG_STRICT_KERNEL_RWX=y and CONFIG_KPROBES=y, there will be one W+X page at boot by default. This can be tested with CONFIG_PPC_PTDUMP=y and CONFIG_PPC_DEBUG_WX=y set, and checking the kernel log during boot. Add an arch specific insn page allocator which returns RO pages if STRICT_KERNEL_RWX is enabled. This page is only written to with patch_instruction() which is able to write RO pages. Reviewed-by: Daniel Axtens Signed-off-by: Russell Currey Signed-off-by: Christophe Leroy [jpn: Reword commit message, switch from vmalloc_exec(), add free_insn_page()] Signed-off-by: Jordan Niethe --- v9: - vmalloc_exec() no longer exists - Set the page to RW before freeing it --- arch/powerpc/kernel/kprobes.c | 22 ++++++++++++++++++++++ 1 file changed, 22 insertions(+) diff --git a/arch/powerpc/kernel/kprobes.c b/arch/powerpc/kernel/kprobes.c index 01ab2163659e..bb7e4d321988 100644 --- a/arch/powerpc/kernel/kprobes.c +++ b/arch/powerpc/kernel/kprobes.c @@ -25,6 +25,8 @@ #include #include #include +#include +#include DEFINE_PER_CPU(struct kprobe *, current_kprobe) = NULL; DEFINE_PER_CPU(struct kprobe_ctlblk, kprobe_ctlblk); @@ -103,6 +105,26 @@ kprobe_opcode_t *kprobe_lookup_name(const char *name, unsigned int offset) return addr; } +void *alloc_insn_page(void) +{ + void *page = vmalloc(PAGE_SIZE); + + if (!page) + return NULL; + + set_memory_ro((unsigned long)page, 1); + set_memory_x((unsigned long)page, 1); + + return page; +} + +void free_insn_page(void *page) +{ + set_memory_nx((unsigned long)page, 1); + set_memory_rw((unsigned long)page, 1); + vfree(page); +} + int arch_prepare_kprobe(struct kprobe *p) { int ret = 0; From patchwork Tue Mar 16 03:17:37 2021 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Jordan Niethe X-Patchwork-Id: 1453660 Return-Path: X-Original-To: patchwork-incoming@ozlabs.org Delivered-To: patchwork-incoming@ozlabs.org Authentication-Results: ozlabs.org; spf=pass (sender SPF authorized) smtp.mailfrom=lists.ozlabs.org (client-ip=2404:9400:2:0:216:3eff:fee1:b9f1; helo=lists.ozlabs.org; envelope-from=linuxppc-dev-bounces+patchwork-incoming=ozlabs.org@lists.ozlabs.org; receiver=) Authentication-Results: ozlabs.org; dkim=fail reason="signature verification failed" (2048-bit key; unprotected) header.d=gmail.com header.i=@gmail.com header.a=rsa-sha256 header.s=20161025 header.b=B6uVTpWW; dkim-atps=neutral Received: from lists.ozlabs.org (lists.ozlabs.org [IPv6:2404:9400:2:0:216:3eff:fee1:b9f1]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits)) (No client certificate requested) by ozlabs.org (Postfix) with ESMTPS id 4Dzz7H5Srhz9sSC for ; Tue, 16 Mar 2021 14:20:11 +1100 (AEDT) Received: from boromir.ozlabs.org (localhost [IPv6:::1]) by lists.ozlabs.org (Postfix) with ESMTP id 4Dzz7H4NPsz3bwW for ; Tue, 16 Mar 2021 14:20:11 +1100 (AEDT) Authentication-Results: lists.ozlabs.org; dkim=fail reason="signature verification failed" (2048-bit key; unprotected) header.d=gmail.com header.i=@gmail.com header.a=rsa-sha256 header.s=20161025 header.b=B6uVTpWW; dkim-atps=neutral X-Original-To: linuxppc-dev@lists.ozlabs.org Delivered-To: linuxppc-dev@lists.ozlabs.org Authentication-Results: lists.ozlabs.org; spf=pass (sender SPF authorized) smtp.mailfrom=gmail.com (client-ip=2607:f8b0:4864:20::436; helo=mail-pf1-x436.google.com; envelope-from=jniethe5@gmail.com; receiver=) Authentication-Results: lists.ozlabs.org; dkim=pass (2048-bit key; unprotected) header.d=gmail.com header.i=@gmail.com header.a=rsa-sha256 header.s=20161025 header.b=B6uVTpWW; dkim-atps=neutral Received: from mail-pf1-x436.google.com (mail-pf1-x436.google.com [IPv6:2607:f8b0:4864:20::436]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by lists.ozlabs.org (Postfix) with ESMTPS id 4Dzz5b10xNz30C1 for ; Tue, 16 Mar 2021 14:18:42 +1100 (AEDT) Received: by mail-pf1-x436.google.com with SMTP id x7so7868966pfi.7 for ; Mon, 15 Mar 2021 20:18:42 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=from:to:cc:subject:date:message-id:in-reply-to:references :mime-version:content-transfer-encoding; bh=7H59t/YcaUtdXxKYfZLvRzPJM2todDbVzkoX+5TuhGE=; b=B6uVTpWW7GIRzCt2BT2jcUPddyYyVAwNItJEcVIds2Qw//DaFLUg63YRCjL+g2ReuU HsAAKW8erGQuMcNupzeRGlwAOlxfGwHhEyPPMmMRqAWou+Hwnmg9pc/BHxfu9p1e6iF/ IIgDc8t8UELZKIVF/95BnISiXVYIWeeF4h19SjPUiRkWnQJiulDcYENWfSxVyVwP1Tx9 o5/POIMG9uOkjEkvEp0jCcxtWwN4luxX35cw36xgw2nKJRA6YMKzyhwr7UG4pmNDq29t hmvj0ld8L6fTWYbpmPYBkt/gPPFQStPLZBZmZx/kSdOAMp3g/BMtaSR71ehTyys7iR/6 X7+g== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:to:cc:subject:date:message-id:in-reply-to :references:mime-version:content-transfer-encoding; bh=7H59t/YcaUtdXxKYfZLvRzPJM2todDbVzkoX+5TuhGE=; b=dcggl+mJSYU58Lzb6nchlofsdL2EPjSClLcxOqTfScm7dXvPfwZCW/K3xWqgVvI/TM 8Z6Fq2/gZsci7o59DPh5EpWUxzpr1Og/ipVh+j0kJhSghqQms1MiHuXGSdmiGJZ8l+og LOkv+ITf9v0fkND+aAT+wdgPhGqaLfbSXgeARwe239woSdaW990OdYMemEVd6R4E3P4t J3p2X8g8f5yCcXRwE05IqQQ2XolT+1FAtX1Rwgoun8PTW1gaMRiJtu7g72FuD8jz+mSk cVuAdr5kI7x2YtJ+HrE5QsqNau3zgprb9lbfBqXDP4fHO1gHYM37rxVIC31Z8uudT4gk CYAQ== X-Gm-Message-State: AOAM530k4mnxrZfmVnWI0w6RZTE5Y+ArFEAYmFOiZErIs5eGYeYTuvaS Ruc41y7CXotbQx6mRXfaPw5OpmycUh0u7Q== X-Google-Smtp-Source: ABdhPJzSOetPKduWc4fhbbyYrmmbymSVFUrHvGSirNKrdSifMok8T4UfvqZbLCyOEGJrROlcBdmWtQ== X-Received: by 2002:a63:cc49:: with SMTP id q9mr1942090pgi.72.1615864720385; Mon, 15 Mar 2021 20:18:40 -0700 (PDT) Received: from localhost.localdomain (159-196-117-139.9fc475.syd.nbn.aussiebb.net. [159.196.117.139]) by smtp.gmail.com with ESMTPSA id o13sm15098809pgv.40.2021.03.15.20.18.35 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 15 Mar 2021 20:18:40 -0700 (PDT) From: Jordan Niethe To: linuxppc-dev@lists.ozlabs.org Subject: [PATCH v9 4/8] powerpc/mm/ptdump: debugfs handler for W+X checks at runtime Date: Tue, 16 Mar 2021 14:17:37 +1100 Message-Id: <20210316031741.1004850-4-jniethe5@gmail.com> X-Mailer: git-send-email 2.25.1 In-Reply-To: <20210316031741.1004850-1-jniethe5@gmail.com> References: <20210316031741.1004850-1-jniethe5@gmail.com> MIME-Version: 1.0 X-BeenThere: linuxppc-dev@lists.ozlabs.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: Linux on PowerPC Developers Mail List List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Cc: christophe.leroy@c-s.fr, ajd@linux.ibm.com, Kees Cook , npiggin@gmail.com, naveen.n.rao@linux.ibm.com, Jordan Niethe , dja@axtens.net Errors-To: linuxppc-dev-bounces+patchwork-incoming=ozlabs.org@lists.ozlabs.org Sender: "Linuxppc-dev" From: Russell Currey Very rudimentary, just echo 1 > [debugfs]/check_wx_pages and check the kernel log. Useful for testing strict module RWX. Updated the Kconfig entry to reflect this. Also fixed a typo. Reviewed-by: Kees Cook Signed-off-by: Russell Currey Signed-off-by: Jordan Niethe --- arch/powerpc/Kconfig.debug | 6 ++++-- arch/powerpc/mm/ptdump/ptdump.c | 21 ++++++++++++++++++++- 2 files changed, 24 insertions(+), 3 deletions(-) diff --git a/arch/powerpc/Kconfig.debug b/arch/powerpc/Kconfig.debug index ae084357994e..56e99e9a30d9 100644 --- a/arch/powerpc/Kconfig.debug +++ b/arch/powerpc/Kconfig.debug @@ -371,7 +371,7 @@ config PPC_PTDUMP If you are unsure, say N. config PPC_DEBUG_WX - bool "Warn on W+X mappings at boot" + bool "Warn on W+X mappings at boot & enable manual checks at runtime" depends on PPC_PTDUMP && STRICT_KERNEL_RWX help Generate a warning if any W+X mappings are found at boot. @@ -385,7 +385,9 @@ config PPC_DEBUG_WX of other unfixed kernel bugs easier. There is no runtime or memory usage effect of this option - once the kernel has booted up - it's a one time check. + once the kernel has booted up, it only automatically checks once. + + Enables the "check_wx_pages" debugfs entry for checking at runtime. If in doubt, say "Y". diff --git a/arch/powerpc/mm/ptdump/ptdump.c b/arch/powerpc/mm/ptdump/ptdump.c index aca354fb670b..78497d57b66b 100644 --- a/arch/powerpc/mm/ptdump/ptdump.c +++ b/arch/powerpc/mm/ptdump/ptdump.c @@ -4,7 +4,7 @@ * * This traverses the kernel pagetables and dumps the * information about the used sections of memory to - * /sys/kernel/debug/kernel_pagetables. + * /sys/kernel/debug/kernel_page_tables. * * Derived from the arm64 implementation: * Copyright (c) 2014, The Linux Foundation, Laura Abbott. @@ -459,6 +459,25 @@ void ptdump_check_wx(void) else pr_info("Checked W+X mappings: passed, no W+X pages found\n"); } + +static int check_wx_debugfs_set(void *data, u64 val) +{ + if (val != 1ULL) + return -EINVAL; + + ptdump_check_wx(); + + return 0; +} + +DEFINE_SIMPLE_ATTRIBUTE(check_wx_fops, NULL, check_wx_debugfs_set, "%llu\n"); + +static int ptdump_check_wx_init(void) +{ + return debugfs_create_file("check_wx_pages", 0200, NULL, + NULL, &check_wx_fops) ? 0 : -ENOMEM; +} +device_initcall(ptdump_check_wx_init); #endif static int ptdump_init(void) From patchwork Tue Mar 16 03:17:38 2021 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Jordan Niethe X-Patchwork-Id: 1453661 Return-Path: X-Original-To: patchwork-incoming@ozlabs.org Delivered-To: patchwork-incoming@ozlabs.org Authentication-Results: ozlabs.org; spf=pass (sender SPF authorized) smtp.mailfrom=lists.ozlabs.org (client-ip=112.213.38.117; helo=lists.ozlabs.org; envelope-from=linuxppc-dev-bounces+patchwork-incoming=ozlabs.org@lists.ozlabs.org; receiver=) Authentication-Results: ozlabs.org; dkim=fail reason="signature verification failed" (2048-bit key; unprotected) header.d=gmail.com header.i=@gmail.com header.a=rsa-sha256 header.s=20161025 header.b=pukob/0H; dkim-atps=neutral Received: from lists.ozlabs.org (lists.ozlabs.org [112.213.38.117]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits)) (No client certificate requested) by ozlabs.org (Postfix) with ESMTPS id 4Dzz7m3JcKz9sSC for ; Tue, 16 Mar 2021 14:20:36 +1100 (AEDT) Received: from boromir.ozlabs.org (localhost [IPv6:::1]) by lists.ozlabs.org (Postfix) with ESMTP id 4Dzz7m2Z7Tz3c24 for ; Tue, 16 Mar 2021 14:20:36 +1100 (AEDT) Authentication-Results: lists.ozlabs.org; dkim=fail reason="signature verification failed" (2048-bit key; unprotected) header.d=gmail.com header.i=@gmail.com header.a=rsa-sha256 header.s=20161025 header.b=pukob/0H; dkim-atps=neutral X-Original-To: linuxppc-dev@lists.ozlabs.org Delivered-To: linuxppc-dev@lists.ozlabs.org Authentication-Results: lists.ozlabs.org; spf=pass (sender SPF authorized) smtp.mailfrom=gmail.com (client-ip=2607:f8b0:4864:20::1031; helo=mail-pj1-x1031.google.com; envelope-from=jniethe5@gmail.com; receiver=) Authentication-Results: lists.ozlabs.org; dkim=pass (2048-bit key; unprotected) header.d=gmail.com header.i=@gmail.com header.a=rsa-sha256 header.s=20161025 header.b=pukob/0H; dkim-atps=neutral Received: from mail-pj1-x1031.google.com (mail-pj1-x1031.google.com [IPv6:2607:f8b0:4864:20::1031]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by lists.ozlabs.org (Postfix) with ESMTPS id 4Dzz5f4h39z30BD for ; Tue, 16 Mar 2021 14:18:46 +1100 (AEDT) Received: by mail-pj1-x1031.google.com with SMTP id a22-20020a17090aa516b02900c1215e9b33so609918pjq.5 for ; Mon, 15 Mar 2021 20:18:46 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=from:to:cc:subject:date:message-id:in-reply-to:references :mime-version:content-transfer-encoding; bh=1IjRU96F9zybhuKBZEy8xck8HhQ81mfRTZfLi2Uhtog=; b=pukob/0HMs32Q+Pm6GVkBsuR9ba7cegYUXl/utjlW/z83kMNXvQjmaMqRM2+NyRvn4 GT3bu+yrONJo26h3BqEas+EfHC02eKs4nYhk7PDv80vr+WBaRnXF7FcQ6yOEF80UIVUw l/xYJnaWAg6yo+GkOwqWRhKv3fMxVBdCQKAHAAafmjRGnC9tlztn/v6romNd+uuTNXTf omXD3WExV8fkNjgI5r56heBi0UrvIdmSxdguuTIcgxRBFdM0Yf2ZSfy1oSn/zJI456DZ KvJM5lSZrVT+33G3vbRcuWStSpZBtqG45zcvl53d+WWkpTJAaun1Y8LxeetOCNDnzoxK XxXA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:to:cc:subject:date:message-id:in-reply-to :references:mime-version:content-transfer-encoding; bh=1IjRU96F9zybhuKBZEy8xck8HhQ81mfRTZfLi2Uhtog=; b=HNE66CKJGP7Vz+R5vPrj4aCHgx9hOfkeTXqMq9iAD9c5pdy/ltbuJslLZPR2MFo+So ug+HFJdKFvA+fQ0Xeq/bvDfSXW3CkePdV3+jt2qE2Dk1ENUEuLbiEreWXwF5ap4oZJz/ xoOw23IRiIjxxjbaYxQliFIVLaJQAGffHHIy5YiPfK/8CePG3s86KnP30kFpN/OlEkvY wN2Aakx8Qc88K4Hculx4iHNYGzTGCzMd/YdA4EBT9FepQyr3tyojMaQdh2sraHWDbRf1 R93Xhtr0yZdRJS70YQ7KUfaU4i1xgucjUT/3FdHAMTjzWXZtN+XUOkhiPzlW4TTwUFne CgQw== X-Gm-Message-State: AOAM530/Xj0KYKMMtyjIK4aUYXqcwAOQq4SfskyJS8XCxDrVAHGSVFYk HcEW3pjwOPMNnHQP4Ou54NjxfjWXwQWpBQ== X-Google-Smtp-Source: ABdhPJx4qh8JoiAZssDxsvgI6Bxy9sXfRFN8jVOfkwPe9/KVrvESDvuh+z9nt+TvTOcFGRGnNOkXZA== X-Received: by 2002:a17:90b:809:: with SMTP id bk9mr2424462pjb.83.1615864724382; Mon, 15 Mar 2021 20:18:44 -0700 (PDT) Received: from localhost.localdomain (159-196-117-139.9fc475.syd.nbn.aussiebb.net. [159.196.117.139]) by smtp.gmail.com with ESMTPSA id o13sm15098809pgv.40.2021.03.15.20.18.40 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 15 Mar 2021 20:18:44 -0700 (PDT) From: Jordan Niethe To: linuxppc-dev@lists.ozlabs.org Subject: [PATCH v9 5/8] powerpc: Set ARCH_HAS_STRICT_MODULE_RWX Date: Tue, 16 Mar 2021 14:17:38 +1100 Message-Id: <20210316031741.1004850-5-jniethe5@gmail.com> X-Mailer: git-send-email 2.25.1 In-Reply-To: <20210316031741.1004850-1-jniethe5@gmail.com> References: <20210316031741.1004850-1-jniethe5@gmail.com> MIME-Version: 1.0 X-BeenThere: linuxppc-dev@lists.ozlabs.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: Linux on PowerPC Developers Mail List List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Cc: christophe.leroy@c-s.fr, ajd@linux.ibm.com, npiggin@gmail.com, naveen.n.rao@linux.ibm.com, Jordan Niethe , dja@axtens.net Errors-To: linuxppc-dev-bounces+patchwork-incoming=ozlabs.org@lists.ozlabs.org Sender: "Linuxppc-dev" From: Russell Currey To enable strict module RWX on powerpc, set: CONFIG_STRICT_MODULE_RWX=y You should also have CONFIG_STRICT_KERNEL_RWX=y set to have any real security benefit. ARCH_HAS_STRICT_MODULE_RWX is set to require ARCH_HAS_STRICT_KERNEL_RWX. This is due to a quirk in arch/Kconfig and arch/powerpc/Kconfig that makes STRICT_MODULE_RWX *on by default* in configurations where STRICT_KERNEL_RWX is *unavailable*. Since this doesn't make much sense, and module RWX without kernel RWX doesn't make much sense, having the same dependencies as kernel RWX works around this problem. Signed-off-by: Russell Currey Signed-off-by: Jordan Niethe --- arch/powerpc/Kconfig | 1 + 1 file changed, 1 insertion(+) diff --git a/arch/powerpc/Kconfig b/arch/powerpc/Kconfig index 4498a27ac9db..d9cadc4212d0 100644 --- a/arch/powerpc/Kconfig +++ b/arch/powerpc/Kconfig @@ -137,6 +137,7 @@ config PPC select ARCH_HAS_SCALED_CPUTIME if VIRT_CPU_ACCOUNTING_NATIVE && PPC_BOOK3S_64 select ARCH_HAS_SET_MEMORY select ARCH_HAS_STRICT_KERNEL_RWX if ((PPC_BOOK3S_64 || PPC32) && !HIBERNATION) + select ARCH_HAS_STRICT_MODULE_RWX if ARCH_HAS_STRICT_KERNEL_RWX select ARCH_HAS_TICK_BROADCAST if GENERIC_CLOCKEVENTS_BROADCAST select ARCH_HAS_UACCESS_FLUSHCACHE select ARCH_HAS_COPY_MC if PPC64 From patchwork Tue Mar 16 03:17:39 2021 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Jordan Niethe X-Patchwork-Id: 1453663 Return-Path: X-Original-To: patchwork-incoming@ozlabs.org Delivered-To: patchwork-incoming@ozlabs.org Authentication-Results: ozlabs.org; spf=pass (sender SPF authorized) smtp.mailfrom=lists.ozlabs.org (client-ip=2404:9400:2:0:216:3eff:fee1:b9f1; helo=lists.ozlabs.org; envelope-from=linuxppc-dev-bounces+patchwork-incoming=ozlabs.org@lists.ozlabs.org; receiver=) Authentication-Results: ozlabs.org; dkim=fail reason="signature verification failed" (2048-bit key; unprotected) header.d=gmail.com header.i=@gmail.com header.a=rsa-sha256 header.s=20161025 header.b=Tom2esHg; dkim-atps=neutral Received: from lists.ozlabs.org (lists.ozlabs.org [IPv6:2404:9400:2:0:216:3eff:fee1:b9f1]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits)) (No client certificate requested) by ozlabs.org (Postfix) with ESMTPS id 4Dzz8M5dQjz9sSC for ; Tue, 16 Mar 2021 14:21:07 +1100 (AEDT) Received: from boromir.ozlabs.org (localhost [IPv6:::1]) by lists.ozlabs.org (Postfix) with ESMTP id 4Dzz8M4sB3z3c6f for ; Tue, 16 Mar 2021 14:21:07 +1100 (AEDT) Authentication-Results: lists.ozlabs.org; dkim=fail reason="signature verification failed" (2048-bit key; unprotected) header.d=gmail.com header.i=@gmail.com header.a=rsa-sha256 header.s=20161025 header.b=Tom2esHg; dkim-atps=neutral X-Original-To: linuxppc-dev@lists.ozlabs.org Delivered-To: linuxppc-dev@lists.ozlabs.org Authentication-Results: lists.ozlabs.org; spf=pass (sender SPF authorized) smtp.mailfrom=gmail.com (client-ip=2607:f8b0:4864:20::52f; helo=mail-pg1-x52f.google.com; envelope-from=jniethe5@gmail.com; receiver=) Authentication-Results: lists.ozlabs.org; dkim=pass (2048-bit key; unprotected) header.d=gmail.com header.i=@gmail.com header.a=rsa-sha256 header.s=20161025 header.b=Tom2esHg; dkim-atps=neutral Received: from mail-pg1-x52f.google.com (mail-pg1-x52f.google.com [IPv6:2607:f8b0:4864:20::52f]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by lists.ozlabs.org (Postfix) with ESMTPS id 4Dzz5l4Dn9z30FT for ; Tue, 16 Mar 2021 14:18:51 +1100 (AEDT) Received: by mail-pg1-x52f.google.com with SMTP id x29so21684231pgk.6 for ; Mon, 15 Mar 2021 20:18:51 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=from:to:cc:subject:date:message-id:in-reply-to:references :mime-version:content-transfer-encoding; bh=bD2k3N8TtbJ/5mTogIWRF2QbxokniPZTNjK+oMQNzxk=; b=Tom2esHgHLHXDPPFtXcZ+klkQqtKfHzGJHneW1HACLQZPvAIjpI7KZe4F2ssDzgvNh bLHXn8YBDkKEKUFVtrfhyp+SipLasmwKXh3EvzyXVMhb0DkfEbcaBpT5ZCka+LvodEaU PE4oFxqxBA7t20q6WU9JNj1mHO+speKDkyaODITLfhy4Otaam+nyFnVAVuLBf7rDEhf4 +BgemXMebsnk8QB9W8zsc22tSqC+Uv4ll4ZlBEFBeuOPMFOlavlvDLddxnCImw6McJuQ xjyTSV7f8HfzMUvPd/tZDyDp9kfRpFZ9q4D7fp2AcMgJ42XKGfVNqVb6El2CYuKVeMWZ OQlw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:to:cc:subject:date:message-id:in-reply-to :references:mime-version:content-transfer-encoding; bh=bD2k3N8TtbJ/5mTogIWRF2QbxokniPZTNjK+oMQNzxk=; b=UmqW0Dt/ikcqbNKNqceNu8dbuisXM8gJptSSqshSGVWEkln/6ito6JFxvBZjgQTyN3 b9/6tIG7925BNmlQjFzqYtQjtjAQ9EzADT5Njip2clm7Y93CCajlyjlgsGw+xiJOnfoM oCSChEZWzD7uQyqG5NQ4kV4N2D7EJAy+oUbkbN+E5dY/hn7w2zWoR8+vD6U7H4CRxzD1 TglQbAPBDcp1wuTGbzEAJSdc8UnSTk89X6CIb52GCzsut44fmYuMXtO3sPf5tq1mUVt5 uBuEQtwhuI5WqYw1YWB1y2Ay+ZCNlodpyFTAdL6hv3YjVaJeMFwJG1x2idfRtnkywNX5 DacQ== X-Gm-Message-State: AOAM531XMSoXnoq5mCP9Sb8VO+mnzHhwZSfOpYOPlFlkH47wYaLd6i26 VexSxlyhKUBU14D/U/g0dQ4t2DGT5jRayw== X-Google-Smtp-Source: ABdhPJwkpgbHt+1x6XK8+vQUUFrctSggl/7W+CuzK00IbGTWzaKEFGAe1+SB9TC82MVL1Ztx901dHQ== X-Received: by 2002:a63:df43:: with SMTP id h3mr1989699pgj.276.1615864729029; Mon, 15 Mar 2021 20:18:49 -0700 (PDT) Received: from localhost.localdomain (159-196-117-139.9fc475.syd.nbn.aussiebb.net. [159.196.117.139]) by smtp.gmail.com with ESMTPSA id o13sm15098809pgv.40.2021.03.15.20.18.44 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 15 Mar 2021 20:18:48 -0700 (PDT) From: Jordan Niethe To: linuxppc-dev@lists.ozlabs.org Subject: [PATCH v9 6/8] powerpc/configs: Enable STRICT_MODULE_RWX in skiroot_defconfig Date: Tue, 16 Mar 2021 14:17:39 +1100 Message-Id: <20210316031741.1004850-6-jniethe5@gmail.com> X-Mailer: git-send-email 2.25.1 In-Reply-To: <20210316031741.1004850-1-jniethe5@gmail.com> References: <20210316031741.1004850-1-jniethe5@gmail.com> MIME-Version: 1.0 X-BeenThere: linuxppc-dev@lists.ozlabs.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: Linux on PowerPC Developers Mail List List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Cc: christophe.leroy@c-s.fr, ajd@linux.ibm.com, Joel Stanley , npiggin@gmail.com, naveen.n.rao@linux.ibm.com, Jordan Niethe , dja@axtens.net Errors-To: linuxppc-dev-bounces+patchwork-incoming=ozlabs.org@lists.ozlabs.org Sender: "Linuxppc-dev" From: Russell Currey skiroot_defconfig is the only powerpc defconfig with STRICT_KERNEL_RWX enabled, and if you want memory protection for kernel text you'd want it for modules too, so enable STRICT_MODULE_RWX there. Acked-by: Joel Stanley Signed-off-by: Russell Currey Signed-off-by: Jordan Niethe --- arch/powerpc/configs/skiroot_defconfig | 1 + 1 file changed, 1 insertion(+) diff --git a/arch/powerpc/configs/skiroot_defconfig b/arch/powerpc/configs/skiroot_defconfig index b806a5d3a695..50fe06cb3a31 100644 --- a/arch/powerpc/configs/skiroot_defconfig +++ b/arch/powerpc/configs/skiroot_defconfig @@ -50,6 +50,7 @@ CONFIG_CMDLINE="console=tty0 console=hvc0 ipr.fast_reboot=1 quiet" # CONFIG_PPC_MEM_KEYS is not set CONFIG_JUMP_LABEL=y CONFIG_STRICT_KERNEL_RWX=y +CONFIG_STRICT_MODULE_RWX=y CONFIG_MODULES=y CONFIG_MODULE_UNLOAD=y CONFIG_MODULE_SIG_FORCE=y From patchwork Tue Mar 16 03:17:40 2021 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Jordan Niethe X-Patchwork-Id: 1453664 Return-Path: X-Original-To: patchwork-incoming@ozlabs.org Delivered-To: patchwork-incoming@ozlabs.org Authentication-Results: ozlabs.org; spf=pass (sender SPF authorized) smtp.mailfrom=lists.ozlabs.org (client-ip=112.213.38.117; helo=lists.ozlabs.org; envelope-from=linuxppc-dev-bounces+patchwork-incoming=ozlabs.org@lists.ozlabs.org; receiver=) Authentication-Results: ozlabs.org; dkim=fail reason="signature verification failed" (2048-bit key; unprotected) header.d=gmail.com header.i=@gmail.com header.a=rsa-sha256 header.s=20161025 header.b=vVx00bkD; dkim-atps=neutral Received: from lists.ozlabs.org (lists.ozlabs.org [112.213.38.117]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits)) (No client certificate requested) by ozlabs.org (Postfix) with ESMTPS id 4Dzz8q5P7Lz9sSC for ; Tue, 16 Mar 2021 14:21:31 +1100 (AEDT) Received: from boromir.ozlabs.org (localhost [IPv6:::1]) by lists.ozlabs.org (Postfix) with ESMTP id 4Dzz8q4JpSz3c3c for ; Tue, 16 Mar 2021 14:21:31 +1100 (AEDT) Authentication-Results: lists.ozlabs.org; dkim=fail reason="signature verification failed" (2048-bit key; unprotected) header.d=gmail.com header.i=@gmail.com header.a=rsa-sha256 header.s=20161025 header.b=vVx00bkD; dkim-atps=neutral X-Original-To: linuxppc-dev@lists.ozlabs.org Delivered-To: linuxppc-dev@lists.ozlabs.org Authentication-Results: lists.ozlabs.org; spf=pass (sender SPF authorized) smtp.mailfrom=gmail.com (client-ip=2607:f8b0:4864:20::102c; helo=mail-pj1-x102c.google.com; envelope-from=jniethe5@gmail.com; receiver=) Authentication-Results: lists.ozlabs.org; dkim=pass (2048-bit key; unprotected) header.d=gmail.com header.i=@gmail.com header.a=rsa-sha256 header.s=20161025 header.b=vVx00bkD; dkim-atps=neutral Received: from mail-pj1-x102c.google.com (mail-pj1-x102c.google.com [IPv6:2607:f8b0:4864:20::102c]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by lists.ozlabs.org (Postfix) with ESMTPS id 4Dzz5q430Xz304d for ; Tue, 16 Mar 2021 14:18:55 +1100 (AEDT) Received: by mail-pj1-x102c.google.com with SMTP id w8so9881612pjf.4 for ; Mon, 15 Mar 2021 20:18:55 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=from:to:cc:subject:date:message-id:in-reply-to:references :mime-version:content-transfer-encoding; bh=DFPFwskMgOwuE5JL50xDAn2mcaMHZ6gcwX67pveQD28=; b=vVx00bkDXB75MFBoJ2sYxxJ758RaqTx7Gu1DV2E6IJy/ATjlbH2kqPoTeIZKz/6XfC HUHXWmEH8Y0rxT67mJR1sLnrHouUfUyo6umZO9yQqr1bKKqy3qIE33stpEhoFJPfmD0q 8h+9iFmR4hY9A0BDKP3NL/kWkLCpJJiuUuPJuyKPbVx+pBIxlqof5g/pit16ouTW3U1r H1AeWL+EGwEx1VNEUP9IsrvJuKQsnbIUC0JC9EtsN+KNFVBmLykM43kevV5iHaezJNCp viROb5fAjii01+q+/QTZki70LdqcDyki/cdPjLxZ2atDFX4SIAktJxge0zmKAg+pmhoI wFig== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:to:cc:subject:date:message-id:in-reply-to :references:mime-version:content-transfer-encoding; bh=DFPFwskMgOwuE5JL50xDAn2mcaMHZ6gcwX67pveQD28=; b=EP9JXaqPAvs99WrKRtcmyH5X9Ts+qHpoUbmogUenQ5nmTvlCOsLHNLq/E4tV43fHYy INlIb3E0xnd9pJ6wj5sO7yz6WvahkBOCbXDbW9qEhZkAHRJXM4jxfEpW7yeQPD6rXo4/ qxzyYjNqawGmbYEjnFl7jLFRAzop7vYQAr+vzrJJrY6TFwNHY62zl4eYeEA5gu84OQJj ucm+7L0Q4XlyXJetlbZGoMnfuBZIYgh/ng6Jbz6y96gd7VyW4LydcOKfDuTvz5djcDgQ e9G+wuM8iI5Su0+HDWRlGlnOKPWGStsGwjYupwyD86XjCklvadCEyiaycJC4ujEorRef 6Mig== X-Gm-Message-State: AOAM530Ty/bn0qGQczy5IuNeyxt3aNLabjzFxy7zGfo7I+qSIe7VrSeM 9jOqdjBowONlWFeVQ92oJMvPTbXmhD4vOX17 X-Google-Smtp-Source: ABdhPJzY1yIw55kTyd4OS+HvHzriFNqieyV7pZtASrmGDhbQBEWopAJhn6+01M7Wy+ztVpVyXM7LBQ== X-Received: by 2002:a17:902:e545:b029:e6:6499:cd19 with SMTP id n5-20020a170902e545b02900e66499cd19mr14490997plf.53.1615864733333; Mon, 15 Mar 2021 20:18:53 -0700 (PDT) Received: from localhost.localdomain (159-196-117-139.9fc475.syd.nbn.aussiebb.net. [159.196.117.139]) by smtp.gmail.com with ESMTPSA id o13sm15098809pgv.40.2021.03.15.20.18.49 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 15 Mar 2021 20:18:53 -0700 (PDT) From: Jordan Niethe To: linuxppc-dev@lists.ozlabs.org Subject: [PATCH v9 7/8] powerpc/mm: implement set_memory_attr() Date: Tue, 16 Mar 2021 14:17:40 +1100 Message-Id: <20210316031741.1004850-7-jniethe5@gmail.com> X-Mailer: git-send-email 2.25.1 In-Reply-To: <20210316031741.1004850-1-jniethe5@gmail.com> References: <20210316031741.1004850-1-jniethe5@gmail.com> MIME-Version: 1.0 X-BeenThere: linuxppc-dev@lists.ozlabs.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: Linux on PowerPC Developers Mail List List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Cc: christophe.leroy@c-s.fr, ajd@linux.ibm.com, npiggin@gmail.com, kbuild test robot , naveen.n.rao@linux.ibm.com, Jordan Niethe , dja@axtens.net Errors-To: linuxppc-dev-bounces+patchwork-incoming=ozlabs.org@lists.ozlabs.org Sender: "Linuxppc-dev" From: Christophe Leroy In addition to the set_memory_xx() functions which allows to change the memory attributes of not (yet) used memory regions, implement a set_memory_attr() function to: - set the final memory protection after init on currently used kernel regions. - enable/disable kernel memory regions in the scope of DEBUG_PAGEALLOC. Unlike the set_memory_xx() which can act in three step as the regions are unused, this function must modify 'on the fly' as the kernel is executing from them. At the moment only PPC32 will use it and changing page attributes on the fly is not an issue. Signed-off-by: Christophe Leroy Reported-by: kbuild test robot [ruscur: cast "data" to unsigned long instead of int] Signed-off-by: Russell Currey Signed-off-by: Jordan Niethe --- arch/powerpc/include/asm/set_memory.h | 2 ++ arch/powerpc/mm/pageattr.c | 33 +++++++++++++++++++++++++++ 2 files changed, 35 insertions(+) diff --git a/arch/powerpc/include/asm/set_memory.h b/arch/powerpc/include/asm/set_memory.h index 64011ea444b4..b040094f7920 100644 --- a/arch/powerpc/include/asm/set_memory.h +++ b/arch/powerpc/include/asm/set_memory.h @@ -29,4 +29,6 @@ static inline int set_memory_x(unsigned long addr, int numpages) return change_memory_attr(addr, numpages, SET_MEMORY_X); } +int set_memory_attr(unsigned long addr, int numpages, pgprot_t prot); + #endif diff --git a/arch/powerpc/mm/pageattr.c b/arch/powerpc/mm/pageattr.c index 2da3fbab6ff7..2fde1b195c85 100644 --- a/arch/powerpc/mm/pageattr.c +++ b/arch/powerpc/mm/pageattr.c @@ -79,3 +79,36 @@ int change_memory_attr(unsigned long addr, int numpages, long action) return apply_to_existing_page_range(&init_mm, start, sz, change_page_attr, (void *)action); } + +/* + * Set the attributes of a page: + * + * This function is used by PPC32 at the end of init to set final kernel memory + * protection. It includes changing the maping of the page it is executing from + * and data pages it is using. + */ +static int set_page_attr(pte_t *ptep, unsigned long addr, void *data) +{ + pgprot_t prot = __pgprot((unsigned long)data); + + spin_lock(&init_mm.page_table_lock); + + set_pte_at(&init_mm, addr, ptep, pte_modify(*ptep, prot)); + flush_tlb_kernel_range(addr, addr + PAGE_SIZE); + + spin_unlock(&init_mm.page_table_lock); + + return 0; +} + +int set_memory_attr(unsigned long addr, int numpages, pgprot_t prot) +{ + unsigned long start = ALIGN_DOWN(addr, PAGE_SIZE); + unsigned long sz = numpages * PAGE_SIZE; + + if (numpages <= 0) + return 0; + + return apply_to_existing_page_range(&init_mm, start, sz, set_page_attr, + (void *)pgprot_val(prot)); +} From patchwork Tue Mar 16 03:17:41 2021 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Jordan Niethe X-Patchwork-Id: 1453665 Return-Path: X-Original-To: patchwork-incoming@ozlabs.org Delivered-To: patchwork-incoming@ozlabs.org Authentication-Results: ozlabs.org; spf=pass (sender SPF authorized) smtp.mailfrom=lists.ozlabs.org (client-ip=2404:9400:2:0:216:3eff:fee1:b9f1; helo=lists.ozlabs.org; envelope-from=linuxppc-dev-bounces+patchwork-incoming=ozlabs.org@lists.ozlabs.org; receiver=) Authentication-Results: ozlabs.org; dkim=fail reason="signature verification failed" (2048-bit key; unprotected) header.d=gmail.com header.i=@gmail.com header.a=rsa-sha256 header.s=20161025 header.b=oR37RMez; dkim-atps=neutral Received: from lists.ozlabs.org (lists.ozlabs.org [IPv6:2404:9400:2:0:216:3eff:fee1:b9f1]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits)) (No client certificate requested) by ozlabs.org (Postfix) with ESMTPS id 4Dzz9H3bKkz9sSC for ; Tue, 16 Mar 2021 14:21:55 +1100 (AEDT) Received: from boromir.ozlabs.org (localhost [IPv6:::1]) by lists.ozlabs.org (Postfix) with ESMTP id 4Dzz9H2VWtz3cXv for ; Tue, 16 Mar 2021 14:21:55 +1100 (AEDT) Authentication-Results: lists.ozlabs.org; dkim=fail reason="signature verification failed" (2048-bit key; unprotected) header.d=gmail.com header.i=@gmail.com header.a=rsa-sha256 header.s=20161025 header.b=oR37RMez; dkim-atps=neutral X-Original-To: linuxppc-dev@lists.ozlabs.org Delivered-To: linuxppc-dev@lists.ozlabs.org Authentication-Results: lists.ozlabs.org; spf=pass (sender SPF authorized) smtp.mailfrom=gmail.com (client-ip=2607:f8b0:4864:20::102e; helo=mail-pj1-x102e.google.com; envelope-from=jniethe5@gmail.com; receiver=) Authentication-Results: lists.ozlabs.org; dkim=pass (2048-bit key; unprotected) header.d=gmail.com header.i=@gmail.com header.a=rsa-sha256 header.s=20161025 header.b=oR37RMez; dkim-atps=neutral Received: from mail-pj1-x102e.google.com (mail-pj1-x102e.google.com [IPv6:2607:f8b0:4864:20::102e]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by lists.ozlabs.org (Postfix) with ESMTPS id 4Dzz5v3MCDz30Gv for ; Tue, 16 Mar 2021 14:18:59 +1100 (AEDT) Received: by mail-pj1-x102e.google.com with SMTP id nh23-20020a17090b3657b02900c0d5e235a8so698183pjb.0 for ; Mon, 15 Mar 2021 20:18:59 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=from:to:cc:subject:date:message-id:in-reply-to:references :mime-version:content-transfer-encoding; bh=sYFr2m4GkFjXgv6COxhX+FNMxzJUw1VFmGa2obWXTog=; b=oR37RMezdlaEoDQEmMg4FxkfSnbywox6IJtWGphuGCtKdkz13g64+lmn+u6ZL+fF80 XHHLR9J8BzxipLW1r8+mQC6d6e0gkl70ceHRY9r7kXXYT8carI+yTP/RdbT3dHvJ71Ak kRGQ4OzL/jifaEcxdC8bCvI47Ru+/H76NcftqGICOfiSPBf6ZupKENTO0gvfJtcJX9s5 niSxUdcGwxq0C1zjjbHsOeOtBi7z3gHli9SzG11C3VY7SVjxQ8+IXjlEhISwWG5pbU6K YlVQQKHAR/O6InRgrdvTdsVlK0PVHEIiRNSPaJ5ykcTdyCu/mut3X6tE6IJ7z9nTHzht bEGw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:to:cc:subject:date:message-id:in-reply-to :references:mime-version:content-transfer-encoding; bh=sYFr2m4GkFjXgv6COxhX+FNMxzJUw1VFmGa2obWXTog=; b=bszWZgKIXx/xv/rnP3lGDakwNmsCKNcjlWYlO8OrnwucYuc5a9bpXlN8Ccs8+jfiqV D8PTDbRw4Wr/9LMmhKzBmzIfXJO4yBAr9xqzUvhUIWT7Bl+HiN05SFXYddat2+4qqJ3E WQJXd+KSnmLnu7WBOMK1d6FMDasla+g+ggcD5jFpaXl368WTG0ycYTXaEEea9+3PLhQL wsGSZK2HVlgHtR0rDI+DFGO0ORg/Eq+DVpCRhLva0X/wGgUXSkkubuxakzhMdRq1bj3I jy6oFx1KLwSwZ7xQSVv1Ij73bARTPUa2ARkENlX8N0Xes+/R6QezoZVvCR2lyLMvkbGq DCrg== X-Gm-Message-State: AOAM532vyf1xKVvcrOyfWNO8hje2o7f85884fL1+sel54ztEQuFlZanq BrQ74l0X8xN37AenUcHHID2CR+iNcDP5Zw== X-Google-Smtp-Source: ABdhPJx25hK0zlLcWykF6OmfCKMtRT6ksz9eIJyYyghOnXd5wxbZ82cxcZAXbDqiAvkm/qpQIVBNmQ== X-Received: by 2002:a17:902:8d8a:b029:e6:b2ea:9074 with SMTP id v10-20020a1709028d8ab02900e6b2ea9074mr8198740plo.30.1615864737378; Mon, 15 Mar 2021 20:18:57 -0700 (PDT) Received: from localhost.localdomain (159-196-117-139.9fc475.syd.nbn.aussiebb.net. [159.196.117.139]) by smtp.gmail.com with ESMTPSA id o13sm15098809pgv.40.2021.03.15.20.18.53 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 15 Mar 2021 20:18:57 -0700 (PDT) From: Jordan Niethe To: linuxppc-dev@lists.ozlabs.org Subject: [PATCH v9 8/8] powerpc/32: use set_memory_attr() Date: Tue, 16 Mar 2021 14:17:41 +1100 Message-Id: <20210316031741.1004850-8-jniethe5@gmail.com> X-Mailer: git-send-email 2.25.1 In-Reply-To: <20210316031741.1004850-1-jniethe5@gmail.com> References: <20210316031741.1004850-1-jniethe5@gmail.com> MIME-Version: 1.0 X-BeenThere: linuxppc-dev@lists.ozlabs.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: Linux on PowerPC Developers Mail List List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Cc: christophe.leroy@c-s.fr, ajd@linux.ibm.com, npiggin@gmail.com, naveen.n.rao@linux.ibm.com, Jordan Niethe , dja@axtens.net Errors-To: linuxppc-dev-bounces+patchwork-incoming=ozlabs.org@lists.ozlabs.org Sender: "Linuxppc-dev" From: Christophe Leroy Use set_memory_attr() instead of the PPC32 specific change_page_attr() change_page_attr() was checking that the address was not mapped by blocks and was handling highmem, but that's unneeded because the affected pages can't be in highmem and block mapping verification is already done by the callers. Signed-off-by: Christophe Leroy [ruscur: rebase on powerpc/merge with Christophe's new patches] Signed-off-by: Russell Currey Signed-off-by: Jordan Niethe --- arch/powerpc/mm/pgtable_32.c | 60 ++++++------------------------------ 1 file changed, 10 insertions(+), 50 deletions(-) diff --git a/arch/powerpc/mm/pgtable_32.c b/arch/powerpc/mm/pgtable_32.c index e0ec67a16887..dcf5ecca19d9 100644 --- a/arch/powerpc/mm/pgtable_32.c +++ b/arch/powerpc/mm/pgtable_32.c @@ -23,6 +23,7 @@ #include #include #include +#include #include #include @@ -132,64 +133,20 @@ void __init mapin_ram(void) } } -static int __change_page_attr_noflush(struct page *page, pgprot_t prot) -{ - pte_t *kpte; - unsigned long address; - - BUG_ON(PageHighMem(page)); - address = (unsigned long)page_address(page); - - if (v_block_mapped(address)) - return 0; - kpte = virt_to_kpte(address); - if (!kpte) - return -EINVAL; - __set_pte_at(&init_mm, address, kpte, mk_pte(page, prot), 0); - - return 0; -} - -/* - * Change the page attributes of an page in the linear mapping. - * - * THIS DOES NOTHING WITH BAT MAPPINGS, DEBUG USE ONLY - */ -static int change_page_attr(struct page *page, int numpages, pgprot_t prot) -{ - int i, err = 0; - unsigned long flags; - struct page *start = page; - - local_irq_save(flags); - for (i = 0; i < numpages; i++, page++) { - err = __change_page_attr_noflush(page, prot); - if (err) - break; - } - wmb(); - local_irq_restore(flags); - flush_tlb_kernel_range((unsigned long)page_address(start), - (unsigned long)page_address(page)); - return err; -} - void mark_initmem_nx(void) { - struct page *page = virt_to_page(_sinittext); unsigned long numpages = PFN_UP((unsigned long)_einittext) - PFN_DOWN((unsigned long)_sinittext); if (v_block_mapped((unsigned long)_sinittext)) mmu_mark_initmem_nx(); else - change_page_attr(page, numpages, PAGE_KERNEL); + set_memory_attr((unsigned long)_sinittext, numpages, PAGE_KERNEL); } #ifdef CONFIG_STRICT_KERNEL_RWX void mark_rodata_ro(void) { - struct page *page; unsigned long numpages; if (v_block_mapped((unsigned long)_stext + 1)) { @@ -198,20 +155,18 @@ void mark_rodata_ro(void) return; } - page = virt_to_page(_stext); numpages = PFN_UP((unsigned long)_etext) - PFN_DOWN((unsigned long)_stext); - change_page_attr(page, numpages, PAGE_KERNEL_ROX); + set_memory_attr((unsigned long)_stext, numpages, PAGE_KERNEL_ROX); /* * mark .rodata as read only. Use __init_begin rather than __end_rodata * to cover NOTES and EXCEPTION_TABLE. */ - page = virt_to_page(__start_rodata); numpages = PFN_UP((unsigned long)__init_begin) - PFN_DOWN((unsigned long)__start_rodata); - change_page_attr(page, numpages, PAGE_KERNEL_RO); + set_memory_attr((unsigned long)__start_rodata, numpages, PAGE_KERNEL_RO); // mark_initmem_nx() should have already run by now ptdump_check_wx(); @@ -221,9 +176,14 @@ void mark_rodata_ro(void) #ifdef CONFIG_DEBUG_PAGEALLOC void __kernel_map_pages(struct page *page, int numpages, int enable) { + unsigned long addr = (unsigned long)page_address(page); + if (PageHighMem(page)) return; - change_page_attr(page, numpages, enable ? PAGE_KERNEL : __pgprot(0)); + if (enable) + set_memory_attr(addr, numpages, PAGE_KERNEL); + else + set_memory_attr(addr, numpages, __pgprot(0)); } #endif /* CONFIG_DEBUG_PAGEALLOC */