Thread (78 messages) 78 messages, 13 authors, 2017-10-20

Re: x86: PIE support and option to extend KASLR randomization

From: Peter Zijlstra <peterz@infradead.org>
Date: 2017-08-21 14:31:17
Also in: kvm, linux-arch, linux-crypto

On Tue, Aug 15, 2017 at 07:20:38AM -0700, Thomas Garnier wrote:
On Tue, Aug 15, 2017 at 12:56 AM, Ingo Molnar [off-list ref] wrote:
quoted
Have you considered a kernel with -mcmodel=small (or medium) instead of -fpie
-mcmodel=large? We can pick a random 2GB window in the (non-kernel) canonical
x86-64 address space to randomize the location of kernel text. The location of
modules can be further randomized within that 2GB window.
-model=small/medium assume you are on the low 32-bit. It generates
instructions where the virtual addresses have the high 32-bit to be
zero.
That's a compiler fail, right? Because the SDM states that for "CALL
rel32" the 32bit displacement is sign extended on x86_64.
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help