mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH] x86/xen: init %gs very early to avoid page faults with stack protector
@ 2018-02-01 12:16 Juergen Gross
  2018-02-01 12:22 ` Andrew Cooper
  0 siblings, 1 reply; 3+ messages in thread
From: Juergen Gross @ 2018-02-01 12:16 UTC (permalink / raw)
  To: linux-kernel, xen-devel; +Cc: boris.ostrovsky, Juergen Gross, stable

When running as Xen pv guest %gs is initialized some time after
C code is started. Depending on stack protector usage this might be
too late, resulting in page faults.

So setup %gs and MSR_GS_BASE in assembly code already.

Cc: stable@vger.kernel.org
Signed-off-by: Juergen Gross <jgross@suse.com>
---
 arch/x86/xen/xen-head.S | 14 ++++++++++++++
 1 file changed, 14 insertions(+)

diff --git a/arch/x86/xen/xen-head.S b/arch/x86/xen/xen-head.S
index 497cc55a0c16..b47d87076efb 100644
--- a/arch/x86/xen/xen-head.S
+++ b/arch/x86/xen/xen-head.S
@@ -9,7 +9,9 @@
 
 #include <asm/boot.h>
 #include <asm/asm.h>
+#include <asm/msr.h>
 #include <asm/page_types.h>
+#include <asm/percpu.h>
 #include <asm/unwind_hints.h>
 
 #include <xen/interface/elfnote.h>
@@ -35,6 +37,18 @@ ENTRY(startup_xen)
 	mov %_ASM_SI, xen_start_info
 	mov $init_thread_union+THREAD_SIZE, %_ASM_SP
 
+	/* Set up %gs.
+	 *
+	 * The base of %gs always points to the bottom of the irqstack
+	 * union.  If the stack protector canary is enabled, it is
+	 * located at %gs:40.  Note that, on SMP, the boot cpu uses
+	 * init data section till per cpu areas are set up.
+	 */
+	movl	$MSR_GS_BASE,%ecx
+	movq	$INIT_PER_CPU_VAR(irq_stack_union),%rax
+	cdq
+	wrmsr
+
 	jmp xen_start_kernel
 END(startup_xen)
 	__FINIT
-- 
2.13.6

^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: [PATCH] x86/xen: init %gs very early to avoid page faults with stack protector
  2018-02-01 12:16 [PATCH] x86/xen: init %gs very early to avoid page faults with stack protector Juergen Gross
@ 2018-02-01 12:22 ` Andrew Cooper
  2018-02-01 12:24   ` Juergen Gross
  0 siblings, 1 reply; 3+ messages in thread
From: Andrew Cooper @ 2018-02-01 12:22 UTC (permalink / raw)
  To: Juergen Gross, linux-kernel, xen-devel; +Cc: boris.ostrovsky, stable

On 01/02/18 12:16, Juergen Gross wrote:
> When running as Xen pv guest %gs is initialized some time after
> C code is started. Depending on stack protector usage this might be
> too late, resulting in page faults.
>
> So setup %gs and MSR_GS_BASE in assembly code already.
>
> Cc: stable@vger.kernel.org
> Signed-off-by: Juergen Gross <jgross@suse.com>
> ---
>  arch/x86/xen/xen-head.S | 14 ++++++++++++++
>  1 file changed, 14 insertions(+)
>
> diff --git a/arch/x86/xen/xen-head.S b/arch/x86/xen/xen-head.S
> index 497cc55a0c16..b47d87076efb 100644
> --- a/arch/x86/xen/xen-head.S
> +++ b/arch/x86/xen/xen-head.S
> @@ -9,7 +9,9 @@
>  
>  #include <asm/boot.h>
>  #include <asm/asm.h>
> +#include <asm/msr.h>
>  #include <asm/page_types.h>
> +#include <asm/percpu.h>
>  #include <asm/unwind_hints.h>
>  
>  #include <xen/interface/elfnote.h>
> @@ -35,6 +37,18 @@ ENTRY(startup_xen)
>  	mov %_ASM_SI, xen_start_info
>  	mov $init_thread_union+THREAD_SIZE, %_ASM_SP
>  
> +	/* Set up %gs.
> +	 *
> +	 * The base of %gs always points to the bottom of the irqstack
> +	 * union.  If the stack protector canary is enabled, it is
> +	 * located at %gs:40.  Note that, on SMP, the boot cpu uses
> +	 * init data section till per cpu areas are set up.
> +	 */
> +	movl	$MSR_GS_BASE,%ecx
> +	movq	$INIT_PER_CPU_VAR(irq_stack_union),%rax
> +	cdq
> +	wrmsr

You surely want a #ifdef __x86_64__ ?  This path is common to the 32bit
entry as well?

~Andrew

> +
>  	jmp xen_start_kernel
>  END(startup_xen)
>  	__FINIT

^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: [PATCH] x86/xen: init %gs very early to avoid page faults with stack protector
  2018-02-01 12:22 ` Andrew Cooper
@ 2018-02-01 12:24   ` Juergen Gross
  0 siblings, 0 replies; 3+ messages in thread
From: Juergen Gross @ 2018-02-01 12:24 UTC (permalink / raw)
  To: Andrew Cooper, linux-kernel, xen-devel; +Cc: boris.ostrovsky, stable

On 01/02/18 13:22, Andrew Cooper wrote:
> On 01/02/18 12:16, Juergen Gross wrote:
>> When running as Xen pv guest %gs is initialized some time after
>> C code is started. Depending on stack protector usage this might be
>> too late, resulting in page faults.
>>
>> So setup %gs and MSR_GS_BASE in assembly code already.
>>
>> Cc: stable@vger.kernel.org
>> Signed-off-by: Juergen Gross <jgross@suse.com>
>> ---
>>  arch/x86/xen/xen-head.S | 14 ++++++++++++++
>>  1 file changed, 14 insertions(+)
>>
>> diff --git a/arch/x86/xen/xen-head.S b/arch/x86/xen/xen-head.S
>> index 497cc55a0c16..b47d87076efb 100644
>> --- a/arch/x86/xen/xen-head.S
>> +++ b/arch/x86/xen/xen-head.S
>> @@ -9,7 +9,9 @@
>>  
>>  #include <asm/boot.h>
>>  #include <asm/asm.h>
>> +#include <asm/msr.h>
>>  #include <asm/page_types.h>
>> +#include <asm/percpu.h>
>>  #include <asm/unwind_hints.h>
>>  
>>  #include <xen/interface/elfnote.h>
>> @@ -35,6 +37,18 @@ ENTRY(startup_xen)
>>  	mov %_ASM_SI, xen_start_info
>>  	mov $init_thread_union+THREAD_SIZE, %_ASM_SP
>>  
>> +	/* Set up %gs.
>> +	 *
>> +	 * The base of %gs always points to the bottom of the irqstack
>> +	 * union.  If the stack protector canary is enabled, it is
>> +	 * located at %gs:40.  Note that, on SMP, the boot cpu uses
>> +	 * init data section till per cpu areas are set up.
>> +	 */
>> +	movl	$MSR_GS_BASE,%ecx
>> +	movq	$INIT_PER_CPU_VAR(irq_stack_union),%rax
>> +	cdq
>> +	wrmsr
> 
> You surely want a #ifdef __x86_64__ ?  This path is common to the 32bit
> entry as well?

Oh, indeed! Thanks for noticing.

V2 coming soon...


Juergen

^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2018-02-01 12:24 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2018-02-01 12:16 [PATCH] x86/xen: init %gs very early to avoid page faults with stack protector Juergen Gross
2018-02-01 12:22 ` Andrew Cooper
2018-02-01 12:24   ` Juergen Gross

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®