From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S932872AbbJAJER (ORCPT ); Thu, 1 Oct 2015 05:04:17 -0400 Received: from www.linutronix.de ([62.245.132.108]:57161 "EHLO Galois.linutronix.de" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S932314AbbJAJED (ORCPT ); Thu, 1 Oct 2015 05:04:03 -0400 Date: Thu, 1 Oct 2015 11:03:21 +0200 (CEST) From: Thomas Gleixner To: Kees Cook cc: Stephen Smalley , "x86@kernel.org" , lkml Subject: Re: rwx mapping between ex_table and rodata In-Reply-To: Message-ID: References: <56045BC4.7000604@tycho.nsa.gov> <56045C8A.50102@tycho.nsa.gov> <56094A89.1010703@tycho.nsa.gov> User-Agent: Alpine 2.11 (DEB 23 2013-08-11) MIME-Version: 1.0 Content-Type: TEXT/PLAIN; charset=US-ASCII X-Linutronix-Spam-Score: -1.0 X-Linutronix-Spam-Level: - X-Linutronix-Spam-Status: No , -1.0 points, 5.0 required, ALL_TRUSTED=-1,SHORTCIRCUIT=-0.0001 Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org On Mon, 28 Sep 2015, Kees Cook wrote: > > --- a/arch/x86/mm/init_64.c > > +++ b/arch/x86/mm/init_64.c > > @@ -1132,7 +1132,7 @@ void mark_rodata_ro(void) > > * has been zapped already via cleanup_highmem(). > > */ > > all_end = roundup((unsigned long)_brk_end, PMD_SIZE); > > - set_memory_nx(rodata_start, (all_end - rodata_start) >> PAGE_SHIFT); > > + set_memory_nx(text_end, (all_end - text_end) >> PAGE_SHIFT); > > > > rodata_test(); > > > > > > That should work, yeah. I'd still like to find the default permissions > and make them W+nx, though. Regardless, let's get the above added. The default permissions are set at boot time when setting up the early page tables. When we split them up later on we inherit the PTE bits and then we do that _ro/nx cleanup after the overall layout has been settled. We can't make them W+nx in the early setup without shooting ourself in the foot, because we only set up at the pud/pmd level. Thanks, tglx