From: Will Deacon <will.deacon@arm.com> To: linux-arm-kernel@lists.infradead.org Cc: linux-kernel@vger.kernel.org, catalin.marinas@arm.com, mark.rutland@arm.com, ard.biesheuvel@linaro.org, sboyd@codeaurora.org, dave.hansen@linux.intel.com, keescook@chromium.org, Will Deacon <will.deacon@arm.com> Subject: [PATCH 18/18] arm64: Kconfig: Add CONFIG_UNMAP_KERNEL_AT_EL0 Date: Fri, 17 Nov 2017 18:22:01 +0000 [thread overview] Message-ID: <1510942921-12564-19-git-send-email-will.deacon@arm.com> (raw) In-Reply-To: <1510942921-12564-1-git-send-email-will.deacon@arm.com> Add a Kconfig entry to control use of the entry trampoline, which allows us to unmap the kernel whilst running in userspace and improve the robustness of KASLR. Signed-off-by: Will Deacon <will.deacon@arm.com> --- arch/arm64/Kconfig | 13 +++++++++++++ 1 file changed, 13 insertions(+) diff --git a/arch/arm64/Kconfig b/arch/arm64/Kconfig index f0fcbfc2262e..f99ffb88843a 100644 --- a/arch/arm64/Kconfig +++ b/arch/arm64/Kconfig @@ -796,6 +796,19 @@ config FORCE_MAX_ZONEORDER However for 4K, we choose a higher default value, 11 as opposed to 10, giving us 4M allocations matching the default size used by generic code. +config UNMAP_KERNEL_AT_EL0 + bool "Unmap kernel when running in userspace (aka \"KAISER\")" + default y + help + Some attacks against KASLR make use of the timing difference between + a permission fault which could arise from a page table entry that is + present in the TLB, and a translation fault which always requires a + page table walk. This option defends against these attacks by unmapping + the kernel whilst running in userspace, therefore forcing translation + faults for all of kernel space. + + If unsure, say Y. + menuconfig ARMV8_DEPRECATED bool "Emulate deprecated/obsolete ARMv8 instructions" depends on COMPAT -- 2.1.4
WARNING: multiple messages have this Message-ID (diff)
From: will.deacon@arm.com (Will Deacon) To: linux-arm-kernel@lists.infradead.org Subject: [PATCH 18/18] arm64: Kconfig: Add CONFIG_UNMAP_KERNEL_AT_EL0 Date: Fri, 17 Nov 2017 18:22:01 +0000 [thread overview] Message-ID: <1510942921-12564-19-git-send-email-will.deacon@arm.com> (raw) In-Reply-To: <1510942921-12564-1-git-send-email-will.deacon@arm.com> Add a Kconfig entry to control use of the entry trampoline, which allows us to unmap the kernel whilst running in userspace and improve the robustness of KASLR. Signed-off-by: Will Deacon <will.deacon@arm.com> --- arch/arm64/Kconfig | 13 +++++++++++++ 1 file changed, 13 insertions(+) diff --git a/arch/arm64/Kconfig b/arch/arm64/Kconfig index f0fcbfc2262e..f99ffb88843a 100644 --- a/arch/arm64/Kconfig +++ b/arch/arm64/Kconfig @@ -796,6 +796,19 @@ config FORCE_MAX_ZONEORDER However for 4K, we choose a higher default value, 11 as opposed to 10, giving us 4M allocations matching the default size used by generic code. +config UNMAP_KERNEL_AT_EL0 + bool "Unmap kernel when running in userspace (aka \"KAISER\")" + default y + help + Some attacks against KASLR make use of the timing difference between + a permission fault which could arise from a page table entry that is + present in the TLB, and a translation fault which always requires a + page table walk. This option defends against these attacks by unmapping + the kernel whilst running in userspace, therefore forcing translation + faults for all of kernel space. + + If unsure, say Y. + menuconfig ARMV8_DEPRECATED bool "Emulate deprecated/obsolete ARMv8 instructions" depends on COMPAT -- 2.1.4
next prev parent reply other threads:[~2017-11-17 18:23 UTC|newest] Thread overview: 90+ messages / expand[flat|nested] mbox.gz Atom feed top 2017-11-17 18:21 [PATCH 00/18] arm64: Unmap the kernel whilst running in userspace (KAISER) Will Deacon 2017-11-17 18:21 ` Will Deacon 2017-11-17 18:21 ` [PATCH 01/18] arm64: mm: Use non-global mappings for kernel space Will Deacon 2017-11-17 18:21 ` Will Deacon 2017-11-17 18:21 ` [PATCH 02/18] arm64: mm: Temporarily disable ARM64_SW_TTBR0_PAN Will Deacon 2017-11-17 18:21 ` Will Deacon 2017-11-17 18:21 ` [PATCH 03/18] arm64: mm: Move ASID from TTBR0 to TTBR1 Will Deacon 2017-11-17 18:21 ` Will Deacon 2017-11-17 18:21 ` [PATCH 04/18] arm64: mm: Remove pre_ttbr0_update_workaround for Falkor erratum #E1003 Will Deacon 2017-11-17 18:21 ` Will Deacon 2017-11-17 18:21 ` [PATCH 05/18] arm64: mm: Rename post_ttbr0_update_workaround Will Deacon 2017-11-17 18:21 ` Will Deacon 2017-11-17 18:21 ` [PATCH 06/18] arm64: mm: Fix and re-enable ARM64_SW_TTBR0_PAN Will Deacon 2017-11-17 18:21 ` Will Deacon 2017-11-17 18:21 ` [PATCH 07/18] arm64: mm: Allocate ASIDs in pairs Will Deacon 2017-11-17 18:21 ` Will Deacon 2017-11-17 18:21 ` [PATCH 08/18] arm64: mm: Add arm64_kernel_mapped_at_el0 helper using static key Will Deacon 2017-11-17 18:21 ` Will Deacon 2017-11-17 18:21 ` [PATCH 09/18] arm64: mm: Invalidate both kernel and user ASIDs when performing TLBI Will Deacon 2017-11-17 18:21 ` Will Deacon 2017-11-17 18:21 ` [PATCH 10/18] arm64: entry: Add exception trampoline page for exceptions from EL0 Will Deacon 2017-11-17 18:21 ` Will Deacon 2017-11-17 18:21 ` [PATCH 11/18] arm64: mm: Map entry trampoline into trampoline and kernel page tables Will Deacon 2017-11-17 18:21 ` Will Deacon 2017-11-17 18:21 ` [PATCH 12/18] arm64: entry: Explicitly pass exception level to kernel_ventry macro Will Deacon 2017-11-17 18:21 ` Will Deacon 2017-11-17 18:21 ` [PATCH 13/18] arm64: entry: Hook up entry trampoline to exception vectors Will Deacon 2017-11-17 18:21 ` Will Deacon 2017-11-17 18:21 ` [PATCH 14/18] arm64: erratum: Work around Falkor erratum #E1003 in trampoline code Will Deacon 2017-11-17 18:21 ` Will Deacon 2017-11-18 0:27 ` Stephen Boyd 2017-11-18 0:27 ` Stephen Boyd 2017-11-20 18:05 ` Will Deacon 2017-11-20 18:05 ` Will Deacon 2017-11-17 18:21 ` [PATCH 15/18] arm64: tls: Avoid unconditional zeroing of tpidrro_el0 for native tasks Will Deacon 2017-11-17 18:21 ` Will Deacon 2017-11-17 18:21 ` [PATCH 16/18] arm64: entry: Add fake CPU feature for mapping the kernel at EL0 Will Deacon 2017-11-17 18:21 ` Will Deacon 2017-11-17 18:22 ` [PATCH 17/18] arm64: makefile: Ensure TEXT_OFFSET doesn't overlap with trampoline Will Deacon 2017-11-17 18:22 ` Will Deacon 2017-11-17 18:22 ` Will Deacon [this message] 2017-11-17 18:22 ` [PATCH 18/18] arm64: Kconfig: Add CONFIG_UNMAP_KERNEL_AT_EL0 Will Deacon 2017-11-22 16:52 ` Marc Zyngier 2017-11-22 16:52 ` Marc Zyngier 2017-11-22 19:36 ` Will Deacon 2017-11-22 19:36 ` Will Deacon 2017-11-18 0:19 ` [PATCH 00/18] arm64: Unmap the kernel whilst running in userspace (KAISER) Stephen Boyd 2017-11-18 0:19 ` Stephen Boyd 2017-11-20 18:03 ` Will Deacon 2017-11-20 18:03 ` Will Deacon 2017-11-18 15:25 ` Ard Biesheuvel 2017-11-18 15:25 ` Ard Biesheuvel 2017-11-20 18:06 ` Will Deacon 2017-11-20 18:06 ` Will Deacon 2017-11-20 18:20 ` Ard Biesheuvel 2017-11-20 18:20 ` Ard Biesheuvel 2017-11-22 19:37 ` Will Deacon 2017-11-22 19:37 ` Will Deacon 2017-11-20 22:50 ` Laura Abbott 2017-11-20 22:50 ` Laura Abbott 2017-11-22 19:37 ` Will Deacon 2017-11-22 19:37 ` Will Deacon 2017-11-22 16:19 ` Pavel Machek 2017-11-22 16:19 ` Pavel Machek 2017-11-22 19:37 ` Will Deacon 2017-11-22 19:37 ` Will Deacon 2017-11-22 22:36 ` Pavel Machek 2017-11-22 22:36 ` Pavel Machek 2017-11-22 21:19 ` Ard Biesheuvel 2017-11-22 21:19 ` Ard Biesheuvel 2017-11-22 22:33 ` Pavel Machek 2017-11-22 22:33 ` Pavel Machek 2017-11-22 23:19 ` Ard Biesheuvel 2017-11-22 23:19 ` Ard Biesheuvel 2017-11-22 23:37 ` Pavel Machek 2017-11-22 23:37 ` Pavel Machek 2017-11-23 6:51 ` Ard Biesheuvel 2017-11-23 6:51 ` Ard Biesheuvel 2017-11-23 9:07 ` Pavel Machek 2017-11-23 9:07 ` Pavel Machek 2017-11-23 9:23 ` Ard Biesheuvel 2017-11-23 9:23 ` Ard Biesheuvel 2017-11-23 10:46 ` Pavel Machek 2017-11-23 10:46 ` Pavel Machek 2017-11-23 11:38 ` Ard Biesheuvel 2017-11-23 11:38 ` Ard Biesheuvel 2017-11-23 17:54 ` Pavel Machek 2017-11-23 17:54 ` Pavel Machek 2017-11-23 18:17 ` Ard Biesheuvel 2017-11-23 18:17 ` Ard Biesheuvel
Reply instructions: You may reply publicly to this message via plain-text email using any one of the following methods: * Save the following mbox file, import it into your mail client, and reply-to-all from there: mbox Avoid top-posting and favor interleaved quoting: https://en.wikipedia.org/wiki/Posting_style#Interleaved_style * Reply using the --to, --cc, and --in-reply-to switches of git-send-email(1): git send-email \ --in-reply-to=1510942921-12564-19-git-send-email-will.deacon@arm.com \ --to=will.deacon@arm.com \ --cc=ard.biesheuvel@linaro.org \ --cc=catalin.marinas@arm.com \ --cc=dave.hansen@linux.intel.com \ --cc=keescook@chromium.org \ --cc=linux-arm-kernel@lists.infradead.org \ --cc=linux-kernel@vger.kernel.org \ --cc=mark.rutland@arm.com \ --cc=sboyd@codeaurora.org \ /path/to/YOUR_REPLY https://kernel.org/pub/software/scm/git/docs/git-send-email.html * If your mail client supports setting the In-Reply-To header via mailto: links, try the mailto: linkBe sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes, see mirroring instructions on how to clone and mirror all data and code used by this external index.