From: Russell Currey <hidden> Date: 2019-02-08 11:13:24
Without restoring the IAMR after idle, execution prevention on POWER9
with Radix MMU is overwritten and the kernel can freely execute userspace without
faulting.
This is necessary when returning from any stop state that modifies user
state, as well as hypervisor state.
To test how this fails without this patch, load the lkdtm driver and
do the following:
echo EXEC_USERSPACE > /sys/kernel/debug/provoke-crash/DIRECT
which won't fault, then boot the kernel with powersave=off, where it
will fault. Applying this patch will fix this.
Fixes: 3b10d0095a1e ("powerpc/mm/radix: Prevent kernel execution of user
space")
Cc: <redacted>
Signed-off-by: Russell Currey <redacted>
---
Since v1:
- no longer use paca to save IAMR, instead use _DAR (thanks mpe)
- remove isync and pnv_wakeup_noloss section (thanks Nick)
arch/powerpc/kernel/idle_book3s.S | 18 ++++++++++++++++++
1 file changed, 18 insertions(+)
@@ -924,6 +931,17 @@ BEGIN_FTR_SECTIONEND_FTR_SECTION_IFSET(CPU_FTR_HVMODE)REST_NVGPRS(r1)REST_GPR(2,r1)++BEGIN_FTR_SECTION+/*IAMRwassavedinregs->darinpnv_powersave_common*/+ldr4,_DAR(r1)+mtsprSPRN_IAMR,r4+/*+*Wedon't need an isync here because the upcoming mtmsrd is+*executionsynchronizing.+*/+END_FTR_SECTION_IFSET(CPU_FTR_ARCH_207S)+ldr4,PACAKMSR(r13)ldr5,_LINK(r1)ldr6,_CCR(r1)
The changes look good to me.
On Fri, Feb 08, 2019 at 10:11:03PM +1100, Russell Currey wrote:
Without restoring the IAMR after idle, execution prevention on POWER9
with Radix MMU is overwritten and the kernel can freely execute userspace without
faulting.
This is necessary when returning from any stop state that modifies user
state, as well as hypervisor state.
To test how this fails without this patch, load the lkdtm driver and
do the following:
echo EXEC_USERSPACE > /sys/kernel/debug/provoke-crash/DIRECT
which won't fault, then boot the kernel with powersave=off, where it
will fault. Applying this patch will fix this.
Fixes: 3b10d0095a1e ("powerpc/mm/radix: Prevent kernel execution of user
space")
Cc: <redacted>
Signed-off-by: Russell Currey <redacted>
From: Nicholas Piggin <npiggin@gmail.com> Date: 2019-02-27 14:58:36
Russell Currey's on February 8, 2019 9:11 pm:
Without restoring the IAMR after idle, execution prevention on POWER9
with Radix MMU is overwritten and the kernel can freely execute userspace without
faulting.
This is necessary when returning from any stop state that modifies user
state, as well as hypervisor state.
To test how this fails without this patch, load the lkdtm driver and
do the following:
echo EXEC_USERSPACE > /sys/kernel/debug/provoke-crash/DIRECT
which won't fault, then boot the kernel with powersave=off, where it
will fault. Applying this patch will fix this.
Fixes: 3b10d0095a1e ("powerpc/mm/radix: Prevent kernel execution of user
space")
Cc: <redacted>
Signed-off-by: Russell Currey <redacted>
---
Since v1:
- no longer use paca to save IAMR, instead use _DAR (thanks mpe)
- remove isync and pnv_wakeup_noloss section (thanks Nick)
Thanks for that, looks good.
Reviewed-by: Nicholas Piggin <npiggin@gmail.com>
From: Gautham R Shenoy <hidden> Date: 2019-02-28 09:55:57
Hello Russell,
On Fri, Feb 08, 2019 at 10:11:03PM +1100, Russell Currey wrote:
Without restoring the IAMR after idle, execution prevention on POWER9
with Radix MMU is overwritten and the kernel can freely execute userspace without
faulting.
This is necessary when returning from any stop state that modifies user
state, as well as hypervisor state.
To test how this fails without this patch, load the lkdtm driver and
do the following:
echo EXEC_USERSPACE > /sys/kernel/debug/provoke-crash/DIRECT
which won't fault, then boot the kernel with powersave=off, where it
will fault. Applying this patch will fix this.
Fixes: 3b10d0095a1e ("powerpc/mm/radix: Prevent kernel execution of user
space")
Cc: <redacted>
Signed-off-by: Russell Currey <redacted>
---
Since v1:
- no longer use paca to save IAMR, instead use _DAR (thanks mpe)
Looks good to me. Once we move to Nick Piggin's C-based save/restore
code, we will be saving all these SPR values on the stack anyway.
Reviewed-by: Gautham R. Shenoy <redacted>
--
Thanks and Regards
gautham.