Re: [kernel-hardening] [PATCH] powerpc/kernel: Disable the latent entropy plugin unconditionally

4 messages, 2 authors, 2016-11-15 · open the first message on its own page

Re: [kernel-hardening] [PATCH] powerpc/kernel: Disable the latent entropy plugin unconditionally

From: Andrew Donnellan <hidden>
Date: 2016-11-02 05:06:37

On 27/06/16 01:34, Emese Revfy wrote:
quoted hunk
Reported-by: PaX Team <redacted>
Signed-off-by: Emese Revfy <redacted>
---
 arch/powerpc/kernel/Makefile | 3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/arch/powerpc/kernel/Makefile b/arch/powerpc/kernel/Makefile
index 01935b8..e9ef44f 100644
--- a/arch/powerpc/kernel/Makefile
+++ b/arch/powerpc/kernel/Makefile
@@ -14,11 +14,12 @@ CFLAGS_prom_init.o      += -fPIC
 CFLAGS_btext.o         += -fPIC
 endif

-ifdef CONFIG_FUNCTION_TRACER
 CFLAGS_cputable.o += $(DISABLE_LATENT_ENTROPY_PLUGIN)
 CFLAGS_init.o += $(DISABLE_LATENT_ENTROPY_PLUGIN)
I think you meant prom_init.o...

Additionally, DISABLE_LATENT_ENTROPY_PLUGIN is conditioned on 
CONFIG_PAX_LATENT_ENTROPY rather than CONFIG_GCC_PLUGIN_LATENT_ENTROPY, 
so it doesn't get exported correctly.

Will submit fixes along with patches to enable plugins on powerpc once I 
get that sorted.

(In future please remember to cc linuxppc-dev.)

-- 
Andrew Donnellan              OzLabs, ADL Canberra
andrew.donnellan@au1.ibm.com  IBM Australia Limited

Re: [kernel-hardening] [PATCH] powerpc/kernel: Disable the latent entropy plugin unconditionally

From: Kees Cook <hidden>
Date: 2016-11-15 22:41:42

On Tue, Nov 1, 2016 at 10:06 PM, Andrew Donnellan
[off-list ref] wrote:
On 27/06/16 01:34, Emese Revfy wrote:
quoted

Reported-by: PaX Team <redacted>
Signed-off-by: Emese Revfy <redacted>
---
 arch/powerpc/kernel/Makefile | 3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/arch/powerpc/kernel/Makefile b/arch/powerpc/kernel/Makefile
index 01935b8..e9ef44f 100644
--- a/arch/powerpc/kernel/Makefile
+++ b/arch/powerpc/kernel/Makefile
@@ -14,11 +14,12 @@ CFLAGS_prom_init.o      += -fPIC
 CFLAGS_btext.o         += -fPIC
 endif

-ifdef CONFIG_FUNCTION_TRACER
 CFLAGS_cputable.o += $(DISABLE_LATENT_ENTROPY_PLUGIN)
 CFLAGS_init.o += $(DISABLE_LATENT_ENTROPY_PLUGIN)

I think you meant prom_init.o...

Additionally, DISABLE_LATENT_ENTROPY_PLUGIN is conditioned on
CONFIG_PAX_LATENT_ENTROPY rather than CONFIG_GCC_PLUGIN_LATENT_ENTROPY, so
it doesn't get exported correctly.

Will submit fixes along with patches to enable plugins on powerpc once I get
that sorted.

(In future please remember to cc linuxppc-dev.)
Just checking in: did these patches materialize? I'd love to see
plugins working on v4.10 for ppc.

-Kees

-- 
Kees Cook
Nexus Security

Re: [kernel-hardening] [PATCH] powerpc/kernel: Disable the latent entropy plugin unconditionally

From: Andrew Donnellan <hidden>
Date: 2016-11-15 22:45:42

On 16/11/16 09:41, Kees Cook wrote:
Just checking in: did these patches materialize? I'd love to see
plugins working on v4.10 for ppc.
Working on it! 
https://github.com/ajdlinux/linux/tree/powerpc-gcc-plugin-infrastructure

Just need to test with all the compilers to figure out which ones are 
broken so we can put a version check in...

-- 
Andrew Donnellan              OzLabs, ADL Canberra
andrew.donnellan@au1.ibm.com  IBM Australia Limited

Re: [kernel-hardening] [PATCH] powerpc/kernel: Disable the latent entropy plugin unconditionally

From: Kees Cook <hidden>
Date: 2016-11-15 23:06:32

On Tue, Nov 15, 2016 at 2:45 PM, Andrew Donnellan
[off-list ref] wrote:
On 16/11/16 09:41, Kees Cook wrote:
quoted
Just checking in: did these patches materialize? I'd love to see
plugins working on v4.10 for ppc.

Working on it!
https://github.com/ajdlinux/linux/tree/powerpc-gcc-plugin-infrastructure
Very cool, thanks!
Just need to test with all the compilers to figure out which ones are broken
so we can put a version check in...
Sounds good.

-Kees

-- 
Kees Cook
Nexus Security
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help