From: Sean Christopherson <sean.j.christopherson@intel.com>
To: Jarkko Sakkinen <jarkko.sakkinen@linux.intel.com>
Cc: linux-sgx@vger.kernel.org,
Shay Katz-zamir <shay.katz-zamir@intel.com>,
Serge Ayoun <serge.ayoun@intel.com>
Subject: [PATCH for_v22 01/11] x86/sgx: Fix an SECS collision with enclave page at VA=0
Date: Wed, 7 Aug 2019 17:12:44 -0700 [thread overview]
Message-ID: <20190808001254.11926-2-sean.j.christopherson@intel.com> (raw)
In-Reply-To: <20190808001254.11926-1-sean.j.christopherson@intel.com>
Detect the SECS in paging related flows by explicitly checking the page
against the enclave's SECS page. Assuming a page with VA=0 is the SECS
will break enclaves that actually use VA=0, which is extremely unlikely
but theoretically possible.
Signed-off-by: Sean Christopherson <sean.j.christopherson@intel.com>
---
arch/x86/kernel/cpu/sgx/encl.c | 14 +++++++++-----
1 file changed, 9 insertions(+), 5 deletions(-)
diff --git a/arch/x86/kernel/cpu/sgx/encl.c b/arch/x86/kernel/cpu/sgx/encl.c
index 909af9a664f0..6da1c36a01e6 100644
--- a/arch/x86/kernel/cpu/sgx/encl.c
+++ b/arch/x86/kernel/cpu/sgx/encl.c
@@ -12,10 +12,14 @@
#include "encls.h"
#include "sgx.h"
+static bool sgx_encl_is_secs(struct sgx_encl *encl, struct sgx_encl_page *page)
+{
+ return page == &encl->secs;
+}
+
static int __sgx_encl_eldu(struct sgx_encl_page *encl_page,
struct sgx_epc_page *epc_page)
{
- unsigned long addr = SGX_ENCL_PAGE_ADDR(encl_page);
unsigned long va_offset = SGX_ENCL_PAGE_VA_OFFSET(encl_page);
struct sgx_encl *encl = encl_page->encl;
pgoff_t page_index = sgx_encl_get_index(encl, encl_page);
@@ -38,11 +42,11 @@ static int __sgx_encl_eldu(struct sgx_encl_page *encl_page,
goto err_pcmd;
}
- pginfo.addr = addr;
+ pginfo.addr = SGX_ENCL_PAGE_ADDR(encl_page);
pginfo.contents = (unsigned long)kmap_atomic(backing);
pginfo.metadata = (unsigned long)kmap_atomic(pcmd) + pcmd_offset;
- pginfo.secs = addr ? (unsigned long)sgx_epc_addr(encl->secs.epc_page) :
- 0;
+ pginfo.secs = sgx_encl_is_secs(encl, encl_page) ? 0 :
+ (unsigned long)sgx_epc_addr(encl->secs.epc_page);
ret = __eldu(&pginfo, sgx_epc_addr(epc_page),
sgx_epc_addr(encl_page->va_page->epc_page) + va_offset);
@@ -546,7 +550,7 @@ void sgx_encl_release(struct kref *ref)
*/
pgoff_t sgx_encl_get_index(struct sgx_encl *encl, struct sgx_encl_page *page)
{
- if (!PFN_DOWN(page->desc))
+ if (sgx_encl_is_secs(encl, page))
return PFN_DOWN(encl->size);
return PFN_DOWN(page->desc - encl->base);
--
2.22.0
next prev parent reply other threads:[~2019-08-08 0:13 UTC|newest]
Thread overview: 41+ messages / expand[flat|nested] mbox.gz Atom feed top
2019-08-08 0:12 [PATCH for_v22 00/11] x86/sgx: Bug fixes for v22 Sean Christopherson
2019-08-08 0:12 ` Sean Christopherson [this message]
2019-08-08 15:34 ` [PATCH for_v22 01/11] x86/sgx: Fix an SECS collision with enclave page at VA=0 Jarkko Sakkinen
2019-08-08 15:44 ` Sean Christopherson
2019-08-09 15:13 ` Jarkko Sakkinen
2019-08-09 20:44 ` Jarkko Sakkinen
2019-08-09 20:59 ` Jarkko Sakkinen
2019-08-08 0:12 ` [PATCH for_v22 02/11] x86/sgx: Fix incorrect NULL pointer check Sean Christopherson
2019-08-08 15:36 ` Jarkko Sakkinen
2019-08-09 21:16 ` Jarkko Sakkinen
2019-08-08 0:12 ` [PATCH for_v22 03/11] x86/sgx: Return '0' when sgx_ioc_enclave_set_attribute() succeeds Sean Christopherson
2019-08-08 15:37 ` Jarkko Sakkinen
2019-08-08 0:12 ` [PATCH for_v22 04/11] x86/sgx: x86/sgx: Require EADD destination to be page aligned Sean Christopherson
2019-08-08 15:38 ` Jarkko Sakkinen
2019-08-08 0:12 ` [PATCH for_v22 05/11] x86/sgx: Require EADD source " Sean Christopherson
2019-08-08 15:44 ` Jarkko Sakkinen
2019-08-08 0:12 ` [PATCH for_v22 06/11] x86/sgx: Check the bounds of the enclave address against ELRANGE Sean Christopherson
2019-08-08 15:45 ` Jarkko Sakkinen
2019-08-09 21:21 ` Jarkko Sakkinen
2019-08-08 0:12 ` [PATCH for_v22 07/11] x86/sgx: Check that enclave is created at beginning of EADD/EINIT ioctl Sean Christopherson
2019-08-08 15:47 ` Jarkko Sakkinen
2019-08-09 23:40 ` Jarkko Sakkinen
2019-08-10 0:03 ` Sean Christopherson
2019-08-10 0:10 ` Sean Christopherson
2019-08-08 0:12 ` [PATCH for_v22 08/11] x86/sgx: Do not free enclave resources on redundant ECREATE Sean Christopherson
2019-08-08 15:48 ` Jarkko Sakkinen
2019-08-08 0:12 ` [PATCH for_v22 09/11] x86/sgx: Refactor error handling for user of sgx_encl_grow() Sean Christopherson
2019-08-08 15:49 ` Jarkko Sakkinen
2019-08-08 0:12 ` [PATCH for_v22 10/11] x86/sgx: Call sgx_encl_grow() with the enclave's lock held Sean Christopherson
2019-08-08 15:52 ` Jarkko Sakkinen
2019-08-08 15:55 ` Sean Christopherson
2019-08-09 16:12 ` Jarkko Sakkinen
2019-08-10 11:32 ` Jarkko Sakkinen
2019-08-08 0:12 ` [PATCH for_v22 11/11] x86/sgx: Shrink the enclave if ECREATE/EADD fails Sean Christopherson
2019-08-08 15:50 ` Jarkko Sakkinen
2019-08-08 18:03 ` Sean Christopherson
2019-08-09 16:13 ` Jarkko Sakkinen
2019-08-10 11:37 ` Jarkko Sakkinen
2019-08-08 15:18 ` [PATCH for_v22 00/11] x86/sgx: Bug fixes for v22 Jarkko Sakkinen
2019-08-08 15:57 ` Jarkko Sakkinen
2019-08-10 11:44 ` Jarkko Sakkinen
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20190808001254.11926-2-sean.j.christopherson@intel.com \
--to=sean.j.christopherson@intel.com \
--cc=jarkko.sakkinen@linux.intel.com \
--cc=linux-sgx@vger.kernel.org \
--cc=serge.ayoun@intel.com \
--cc=shay.katz-zamir@intel.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).