From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org X-Spam-Level: X-Spam-Status: No, score=-6.5 required=3.0 tests=BAYES_00,DKIM_INVALID, DKIM_SIGNED,HEADER_FROM_DIFFERENT_DOMAINS,MAILING_LIST_MULTI,SIGNED_OFF_BY, SPF_HELO_NONE,SPF_PASS autolearn=no autolearn_force=no version=3.4.0 Received: from mail.kernel.org (mail.kernel.org [198.145.29.99]) by smtp.lore.kernel.org (Postfix) with ESMTP id 237DFC433E3 for ; Fri, 21 Aug 2020 21:28:35 +0000 (UTC) Received: from vger.kernel.org (vger.kernel.org [23.128.96.18]) by mail.kernel.org (Postfix) with ESMTP id EEBDE20791 for ; Fri, 21 Aug 2020 21:28:34 +0000 (UTC) Authentication-Results: mail.kernel.org; dkim=fail reason="signature verification failed" (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="OoMfAjUZ" Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1726796AbgHUV2d (ORCPT ); Fri, 21 Aug 2020 17:28:33 -0400 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:52992 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1726433AbgHUV2c (ORCPT ); Fri, 21 Aug 2020 17:28:32 -0400 Received: from mail-qt1-x843.google.com (mail-qt1-x843.google.com [IPv6:2607:f8b0:4864:20::843]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id 3C8C1C061573; Fri, 21 Aug 2020 14:28:31 -0700 (PDT) Received: by mail-qt1-x843.google.com with SMTP id k18so2250837qtm.10; Fri, 21 Aug 2020 14:28:31 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=sender:from:date:to:cc:subject:message-id:references:mime-version :content-disposition:in-reply-to; bh=u1w1dHewQ24Wh+EinJOH0pHgm/+gMZl7ydhUDFjuxnU=; b=OoMfAjUZNkobdLMpwQ9UFNRLMGg4krPXHtBq3Ds15ChRcLsqX5B44nEIZJ7s3FioZb 6oYiG18I/qsd0529aq3ua3uxtI9gSYEoW1ALH3ba3XWAGTaZyUYdsQjnyKpSlukJxuDK blqEdLgUgL92jae/PdnFYiYeQApnlj3mz4LbeuOo0gZeJGEl1IO3i09PIX52HxaxPzuw RFp86XFjqI3KHojp/MGn7uEZDzu48zBiI1YdZs1C9zvnjpGOTRvfXPiIBijrgP0nQZ/8 r1qooc2oOrlTJHcXqo4mDtmOntpRN/IkGUKtZOIH8/BEzBMvlyrn5M0AFD1NgtMnpmVn cKwA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:sender:from:date:to:cc:subject:message-id :references:mime-version:content-disposition:in-reply-to; bh=u1w1dHewQ24Wh+EinJOH0pHgm/+gMZl7ydhUDFjuxnU=; b=BX2MLtIcDcf8Ced0SLuiHabf4WDIiqrULdH+/X8rQDjutqeQKi056Jza3vWjKYq6re TBXzkWVPbTh6BSmfeeauMCi9DhnNlx8mcoNXVegZbxvkrngyu0pGu82plVsAYw5q5yLC jlf/qdcfmgx95r7/TekMrrXXCG/M05S/U34Joag7srIKmlH7qixrTDE+OX4PfL1FDDFy OfSRhAIzBbbxdZUB5UhsdSeN36m2+KQRY9K+lyoD9KW0Naz+wsj0ST+urbqHBQ8zG91E rwZsTg4XVFuILgpAUVBR4TUQR2t+PZ2bp9SwJPP/iSV61+BKk8b7/M3XlAYjbjkNrNnG vzrw== X-Gm-Message-State: AOAM531cHi1mcfApn5zQ4ImWX0f+vNV00Dg6Wo54lPjkrcsv6mZREVSf CzNHN1JCa74rnilLYH+9fRc= X-Google-Smtp-Source: ABdhPJxtZVULVA3N4dt/bqKeQXc8/i3GQ6y0v/dOVtDkDPQdS8K00WAzx4b4ykHLL9yquf0LN759jg== X-Received: by 2002:aed:27c8:: with SMTP id m8mr4565676qtg.302.1598045310404; Fri, 21 Aug 2020 14:28:30 -0700 (PDT) Received: from rani.riverdale.lan ([2001:470:1f07:5f3::b55f]) by smtp.gmail.com with ESMTPSA id p189sm2823699qkb.61.2020.08.21.14.28.29 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 21 Aug 2020 14:28:29 -0700 (PDT) From: Arvind Sankar X-Google-Original-From: Arvind Sankar Date: Fri, 21 Aug 2020 17:28:28 -0400 To: Kees Cook Cc: Arvind Sankar , Ingo Molnar , Catalin Marinas , Mark Rutland , Ard Biesheuvel , Peter Collingbourne , James Morse , Borislav Petkov , Ingo Molnar , Russell King , Masahiro Yamada , Nick Desaulniers , Nathan Chancellor , Arnd Bergmann , x86@kernel.org, clang-built-linux@googlegroups.com, linux-arch@vger.kernel.org, linux-efi@vger.kernel.org, linux-arm-kernel@lists.infradead.org, linux-kernel@vger.kernel.org Subject: Re: [PATCH v6 27/29] x86/boot/compressed: Remove, discard, or assert for unwanted sections Message-ID: <20200821212828.GA1741495@rani.riverdale.lan> References: <20200821194310.3089815-1-keescook@chromium.org> <20200821194310.3089815-28-keescook@chromium.org> <20200821200159.GC1475504@rani.riverdale.lan> <202008211421.47347CA42@keescook> MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Disposition: inline In-Reply-To: <202008211421.47347CA42@keescook> Sender: linux-kernel-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org On Fri, Aug 21, 2020 at 02:21:34PM -0700, Kees Cook wrote: > On Fri, Aug 21, 2020 at 04:01:59PM -0400, Arvind Sankar wrote: > > On Fri, Aug 21, 2020 at 12:43:08PM -0700, Kees Cook wrote: > > > In preparation for warning on orphan sections, stop the linker from > > > generating the .eh_frame* sections, discard unwanted non-zero-sized > > > generated sections, and enforce other expected-to-be-zero-sized sections > > > (since discarding them might hide problems with them suddenly gaining > > > unexpected entries). > > > > > > Signed-off-by: Kees Cook > > > .rel.dyn : { > > > - *(.rel.*) > > > + *(.rel.*) *(.rel_*) > > > } > > > ASSERT(SIZEOF(.rel.dyn) == 0, "Unexpected run-time relocations (.rel) detected!") > > > > > > .rela.dyn : { > > > - *(.rela.*) > > > + *(.rela.*) *(.rela_*) > > > } > > > ASSERT(SIZEOF(.rela.dyn) == 0, "Unexpected run-time relocations (.rela) detected!") > > > } > > > -- > > > 2.25.1 > > > > > > > When do you get .rela_? > > i386 builds, IIRC. I can try to hunt that down if you want? > > -- > Kees Cook Nah, just curious. Thanks. From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org X-Spam-Level: X-Spam-Status: No, score=-6.8 required=3.0 tests=BAYES_00,DKIMWL_WL_HIGH, DKIM_SIGNED,DKIM_VALID,HEADER_FROM_DIFFERENT_DOMAINS,MAILING_LIST_MULTI, SIGNED_OFF_BY,SPF_HELO_NONE,SPF_PASS,URIBL_BLOCKED autolearn=no autolearn_force=no version=3.4.0 Received: from mail.kernel.org (mail.kernel.org [198.145.29.99]) by smtp.lore.kernel.org (Postfix) with ESMTP id DE5E0C433DF for ; Fri, 21 Aug 2020 21:29:58 +0000 (UTC) Received: from merlin.infradead.org (merlin.infradead.org [205.233.59.134]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mail.kernel.org (Postfix) with ESMTPS id A22C420791 for ; Fri, 21 Aug 2020 21:29:58 +0000 (UTC) Authentication-Results: mail.kernel.org; dkim=pass (2048-bit key) header.d=lists.infradead.org header.i=@lists.infradead.org header.b="f6wARpnz"; dkim=fail reason="signature verification failed" (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="OoMfAjUZ" DMARC-Filter: OpenDMARC Filter v1.3.2 mail.kernel.org A22C420791 Authentication-Results: mail.kernel.org; dmarc=none (p=none dis=none) header.from=alum.mit.edu Authentication-Results: mail.kernel.org; spf=none smtp.mailfrom=linux-arm-kernel-bounces+linux-arm-kernel=archiver.kernel.org@lists.infradead.org DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.infradead.org; s=merlin.20170209; h=Sender:Content-Transfer-Encoding: Content-Type:Cc:List-Subscribe:List-Help:List-Post:List-Archive: List-Unsubscribe:List-Id:In-Reply-To:MIME-Version:References:Message-ID: Subject:To:Date:From:Reply-To:Content-ID:Content-Description:Resent-Date: Resent-From:Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:List-Owner; bh=IFQu/SoZTiTs2b40lFgoHNxGGFZ8z6NcrBWHdWbxlRk=; b=f6wARpnzlV5jYnC3sLFOeo4Bf W/AyyzNeINKPp5cJlL3hq7jRHQfE1XVQ57h+FMzd16ow1sUigi3qcaOfmrCka4+aDfJDN7vawmnew CVikcy4rYMvhRFtW45PrnlSWbiBwjY63jpcOg8Jd0Vee2nx1XpZr3SVH8h2Uc71j7THpOaQsYl2BC YwDORatBdXKUeInokeQGRUtEVd77pd9ZJctlFUcBwDH3Iishuyk9ABo9P8mujbDzv9BBQdm4mw9E/ XrburQ2LreE/saxgt41ODOyM4TbkHKlEhlh5C6p2yElkOhXhn1GVEM58i8DjS6rZ3LbbvUZb9XAsG HOjEid5Hw==; Received: from localhost ([::1] helo=merlin.infradead.org) by merlin.infradead.org with esmtp (Exim 4.92.3 #3 (Red Hat Linux)) id 1k9EaQ-0000Es-Nm; Fri, 21 Aug 2020 21:28:34 +0000 Received: from mail-qt1-x841.google.com ([2607:f8b0:4864:20::841]) by merlin.infradead.org with esmtps (Exim 4.92.3 #3 (Red Hat Linux)) id 1k9EaN-00006a-Vl for linux-arm-kernel@lists.infradead.org; Fri, 21 Aug 2020 21:28:32 +0000 Received: by mail-qt1-x841.google.com with SMTP id 6so2277738qtt.0 for ; Fri, 21 Aug 2020 14:28:31 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=sender:from:date:to:cc:subject:message-id:references:mime-version :content-disposition:in-reply-to; bh=u1w1dHewQ24Wh+EinJOH0pHgm/+gMZl7ydhUDFjuxnU=; b=OoMfAjUZNkobdLMpwQ9UFNRLMGg4krPXHtBq3Ds15ChRcLsqX5B44nEIZJ7s3FioZb 6oYiG18I/qsd0529aq3ua3uxtI9gSYEoW1ALH3ba3XWAGTaZyUYdsQjnyKpSlukJxuDK blqEdLgUgL92jae/PdnFYiYeQApnlj3mz4LbeuOo0gZeJGEl1IO3i09PIX52HxaxPzuw RFp86XFjqI3KHojp/MGn7uEZDzu48zBiI1YdZs1C9zvnjpGOTRvfXPiIBijrgP0nQZ/8 r1qooc2oOrlTJHcXqo4mDtmOntpRN/IkGUKtZOIH8/BEzBMvlyrn5M0AFD1NgtMnpmVn cKwA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:sender:from:date:to:cc:subject:message-id :references:mime-version:content-disposition:in-reply-to; bh=u1w1dHewQ24Wh+EinJOH0pHgm/+gMZl7ydhUDFjuxnU=; b=WXuyE0fBR67iCerPeZs6zdOZGptBf/JuZxWnPmH+b4bNmG4krMOsuPZ6NeL/Djn25D OCghfrJyg7hUW+6jDOnMIjFpk5ZVIkYNfcpghYUkmPRoeJXOJpAWpTG6d5rbQjowFA3+ 5IqjL8VeKPYGRDMYwAn88Y+yV+RJBRxY8kw37NyneemiCF+TeIA7PQoQG9ZD2PgvHq4G 0Ua3IyxZvI7OHquUZK+UppsNmlqiRw5NU+c949F4LQvHoL5Usm1W6AmujwP85y7rsdEd PixR9moDlpfybxbOau83ps0bBrEWHcjMYIOgYzA2B4Ltg+7gaLWuEhONvk5AJWtpj/8P W45g== X-Gm-Message-State: AOAM5325T1dpbXze7t+apDLm3KhrKxzWtUFd3TmKRFRthMQZYkrPjvXr bgmL6Z0/yoVoBhF2SCsr4Wk= X-Google-Smtp-Source: ABdhPJxtZVULVA3N4dt/bqKeQXc8/i3GQ6y0v/dOVtDkDPQdS8K00WAzx4b4ykHLL9yquf0LN759jg== X-Received: by 2002:aed:27c8:: with SMTP id m8mr4565676qtg.302.1598045310404; Fri, 21 Aug 2020 14:28:30 -0700 (PDT) Received: from rani.riverdale.lan ([2001:470:1f07:5f3::b55f]) by smtp.gmail.com with ESMTPSA id p189sm2823699qkb.61.2020.08.21.14.28.29 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 21 Aug 2020 14:28:29 -0700 (PDT) From: Arvind Sankar X-Google-Original-From: Arvind Sankar Date: Fri, 21 Aug 2020 17:28:28 -0400 To: Kees Cook Subject: Re: [PATCH v6 27/29] x86/boot/compressed: Remove, discard, or assert for unwanted sections Message-ID: <20200821212828.GA1741495@rani.riverdale.lan> References: <20200821194310.3089815-1-keescook@chromium.org> <20200821194310.3089815-28-keescook@chromium.org> <20200821200159.GC1475504@rani.riverdale.lan> <202008211421.47347CA42@keescook> MIME-Version: 1.0 Content-Disposition: inline In-Reply-To: <202008211421.47347CA42@keescook> X-CRM114-Version: 20100106-BlameMichelson ( TRE 0.8.0 (BSD) ) MR-646709E3 X-CRM114-CacheID: sfid-20200821_172832_057818_7081DC21 X-CRM114-Status: GOOD ( 16.38 ) X-BeenThere: linux-arm-kernel@lists.infradead.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Cc: Mark Rutland , linux-arch@vger.kernel.org, linux-efi@vger.kernel.org, linux-kernel@vger.kernel.org, Arnd Bergmann , Catalin Marinas , Masahiro Yamada , x86@kernel.org, Nick Desaulniers , Russell King , Ard Biesheuvel , clang-built-linux@googlegroups.com, Arvind Sankar , Ingo Molnar , James Morse , Nathan Chancellor , Borislav Petkov , Peter Collingbourne , Ingo Molnar , linux-arm-kernel@lists.infradead.org Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit Sender: "linux-arm-kernel" Errors-To: linux-arm-kernel-bounces+linux-arm-kernel=archiver.kernel.org@lists.infradead.org On Fri, Aug 21, 2020 at 02:21:34PM -0700, Kees Cook wrote: > On Fri, Aug 21, 2020 at 04:01:59PM -0400, Arvind Sankar wrote: > > On Fri, Aug 21, 2020 at 12:43:08PM -0700, Kees Cook wrote: > > > In preparation for warning on orphan sections, stop the linker from > > > generating the .eh_frame* sections, discard unwanted non-zero-sized > > > generated sections, and enforce other expected-to-be-zero-sized sections > > > (since discarding them might hide problems with them suddenly gaining > > > unexpected entries). > > > > > > Signed-off-by: Kees Cook > > > .rel.dyn : { > > > - *(.rel.*) > > > + *(.rel.*) *(.rel_*) > > > } > > > ASSERT(SIZEOF(.rel.dyn) == 0, "Unexpected run-time relocations (.rel) detected!") > > > > > > .rela.dyn : { > > > - *(.rela.*) > > > + *(.rela.*) *(.rela_*) > > > } > > > ASSERT(SIZEOF(.rela.dyn) == 0, "Unexpected run-time relocations (.rela) detected!") > > > } > > > -- > > > 2.25.1 > > > > > > > When do you get .rela_? > > i386 builds, IIRC. I can try to hunt that down if you want? > > -- > Kees Cook Nah, just curious. Thanks. _______________________________________________ linux-arm-kernel mailing list linux-arm-kernel@lists.infradead.org http://lists.infradead.org/mailman/listinfo/linux-arm-kernel