 2b68f6caea
			
		
	
	
	2b68f6caea
	
	
	
		
			
			When an architecture fully supports randomizing the ELF load location, a per-arch mmap_rnd() function is used to find a randomized mmap base. In preparation for randomizing the location of ET_DYN binaries separately from mmap, this renames and exports these functions as arch_mmap_rnd(). Additionally introduces CONFIG_ARCH_HAS_ELF_RANDOMIZE for describing this feature on architectures that support it (which is a superset of ARCH_BINFMT_ELF_RANDOMIZE_PIE, since s390 already supports a separated ET_DYN ASLR from mmap ASLR without the ARCH_BINFMT_ELF_RANDOMIZE_PIE logic). Signed-off-by: Kees Cook <keescook@chromium.org> Cc: Hector Marco-Gisbert <hecmargi@upv.es> Cc: Russell King <linux@arm.linux.org.uk> Reviewed-by: Ingo Molnar <mingo@kernel.org> Cc: Catalin Marinas <catalin.marinas@arm.com> Cc: Will Deacon <will.deacon@arm.com> Cc: Ralf Baechle <ralf@linux-mips.org> Cc: Benjamin Herrenschmidt <benh@kernel.crashing.org> Cc: Paul Mackerras <paulus@samba.org> Cc: Michael Ellerman <mpe@ellerman.id.au> Cc: Martin Schwidefsky <schwidefsky@de.ibm.com> Cc: Heiko Carstens <heiko.carstens@de.ibm.com> Cc: Alexander Viro <viro@zeniv.linux.org.uk> Cc: Oleg Nesterov <oleg@redhat.com> Cc: Andy Lutomirski <luto@amacapital.net> Cc: "David A. Long" <dave.long@linaro.org> Cc: Andrey Ryabinin <a.ryabinin@samsung.com> Cc: Arun Chandran <achandran@mvista.com> Cc: Yann Droneaud <ydroneaud@opteya.com> Cc: Min-Hua Chen <orca.chen@gmail.com> Cc: Paul Burton <paul.burton@imgtec.com> Cc: Alex Smith <alex@alex-smith.me.uk> Cc: Markos Chandras <markos.chandras@imgtec.com> Cc: Vineeth Vijayan <vvijayan@mvista.com> Cc: Jeff Bailey <jeffbailey@google.com> Cc: Michael Holzheu <holzheu@linux.vnet.ibm.com> Cc: Ben Hutchings <ben@decadent.org.uk> Cc: Behan Webster <behanw@converseincode.com> Cc: Ismael Ripoll <iripoll@upv.es> Cc: Jan-Simon Mller <dl9pf@gmx.de> Signed-off-by: Andrew Morton <akpm@linux-foundation.org> Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
		
			
				
	
	
		
			206 lines
		
	
	
	
		
			4.7 KiB
			
		
	
	
	
		
			C
		
	
	
	
	
	
			
		
		
	
	
			206 lines
		
	
	
	
		
			4.7 KiB
			
		
	
	
	
		
			C
		
	
	
	
	
	
| /*
 | |
|  * This file is subject to the terms and conditions of the GNU General Public
 | |
|  * License.  See the file "COPYING" in the main directory of this archive
 | |
|  * for more details.
 | |
|  *
 | |
|  * Copyright (C) 2011 Wind River Systems,
 | |
|  *   written by Ralf Baechle <ralf@linux-mips.org>
 | |
|  */
 | |
| #include <linux/compiler.h>
 | |
| #include <linux/errno.h>
 | |
| #include <linux/mm.h>
 | |
| #include <linux/mman.h>
 | |
| #include <linux/module.h>
 | |
| #include <linux/personality.h>
 | |
| #include <linux/random.h>
 | |
| #include <linux/sched.h>
 | |
| 
 | |
| unsigned long shm_align_mask = PAGE_SIZE - 1;	/* Sane caches */
 | |
| EXPORT_SYMBOL(shm_align_mask);
 | |
| 
 | |
| /* gap between mmap and stack */
 | |
| #define MIN_GAP (128*1024*1024UL)
 | |
| #define MAX_GAP ((TASK_SIZE)/6*5)
 | |
| 
 | |
| static int mmap_is_legacy(void)
 | |
| {
 | |
| 	if (current->personality & ADDR_COMPAT_LAYOUT)
 | |
| 		return 1;
 | |
| 
 | |
| 	if (rlimit(RLIMIT_STACK) == RLIM_INFINITY)
 | |
| 		return 1;
 | |
| 
 | |
| 	return sysctl_legacy_va_layout;
 | |
| }
 | |
| 
 | |
| static unsigned long mmap_base(unsigned long rnd)
 | |
| {
 | |
| 	unsigned long gap = rlimit(RLIMIT_STACK);
 | |
| 
 | |
| 	if (gap < MIN_GAP)
 | |
| 		gap = MIN_GAP;
 | |
| 	else if (gap > MAX_GAP)
 | |
| 		gap = MAX_GAP;
 | |
| 
 | |
| 	return PAGE_ALIGN(TASK_SIZE - gap - rnd);
 | |
| }
 | |
| 
 | |
| #define COLOUR_ALIGN(addr, pgoff)				\
 | |
| 	((((addr) + shm_align_mask) & ~shm_align_mask) +	\
 | |
| 	 (((pgoff) << PAGE_SHIFT) & shm_align_mask))
 | |
| 
 | |
| enum mmap_allocation_direction {UP, DOWN};
 | |
| 
 | |
| static unsigned long arch_get_unmapped_area_common(struct file *filp,
 | |
| 	unsigned long addr0, unsigned long len, unsigned long pgoff,
 | |
| 	unsigned long flags, enum mmap_allocation_direction dir)
 | |
| {
 | |
| 	struct mm_struct *mm = current->mm;
 | |
| 	struct vm_area_struct *vma;
 | |
| 	unsigned long addr = addr0;
 | |
| 	int do_color_align;
 | |
| 	struct vm_unmapped_area_info info;
 | |
| 
 | |
| 	if (unlikely(len > TASK_SIZE))
 | |
| 		return -ENOMEM;
 | |
| 
 | |
| 	if (flags & MAP_FIXED) {
 | |
| 		/* Even MAP_FIXED mappings must reside within TASK_SIZE */
 | |
| 		if (TASK_SIZE - len < addr)
 | |
| 			return -EINVAL;
 | |
| 
 | |
| 		/*
 | |
| 		 * We do not accept a shared mapping if it would violate
 | |
| 		 * cache aliasing constraints.
 | |
| 		 */
 | |
| 		if ((flags & MAP_SHARED) &&
 | |
| 		    ((addr - (pgoff << PAGE_SHIFT)) & shm_align_mask))
 | |
| 			return -EINVAL;
 | |
| 		return addr;
 | |
| 	}
 | |
| 
 | |
| 	do_color_align = 0;
 | |
| 	if (filp || (flags & MAP_SHARED))
 | |
| 		do_color_align = 1;
 | |
| 
 | |
| 	/* requesting a specific address */
 | |
| 	if (addr) {
 | |
| 		if (do_color_align)
 | |
| 			addr = COLOUR_ALIGN(addr, pgoff);
 | |
| 		else
 | |
| 			addr = PAGE_ALIGN(addr);
 | |
| 
 | |
| 		vma = find_vma(mm, addr);
 | |
| 		if (TASK_SIZE - len >= addr &&
 | |
| 		    (!vma || addr + len <= vma->vm_start))
 | |
| 			return addr;
 | |
| 	}
 | |
| 
 | |
| 	info.length = len;
 | |
| 	info.align_mask = do_color_align ? (PAGE_MASK & shm_align_mask) : 0;
 | |
| 	info.align_offset = pgoff << PAGE_SHIFT;
 | |
| 
 | |
| 	if (dir == DOWN) {
 | |
| 		info.flags = VM_UNMAPPED_AREA_TOPDOWN;
 | |
| 		info.low_limit = PAGE_SIZE;
 | |
| 		info.high_limit = mm->mmap_base;
 | |
| 		addr = vm_unmapped_area(&info);
 | |
| 
 | |
| 		if (!(addr & ~PAGE_MASK))
 | |
| 			return addr;
 | |
| 
 | |
| 		/*
 | |
| 		 * A failed mmap() very likely causes application failure,
 | |
| 		 * so fall back to the bottom-up function here. This scenario
 | |
| 		 * can happen with large stack limits and large mmap()
 | |
| 		 * allocations.
 | |
| 		 */
 | |
| 	}
 | |
| 
 | |
| 	info.flags = 0;
 | |
| 	info.low_limit = mm->mmap_base;
 | |
| 	info.high_limit = TASK_SIZE;
 | |
| 	return vm_unmapped_area(&info);
 | |
| }
 | |
| 
 | |
| unsigned long arch_get_unmapped_area(struct file *filp, unsigned long addr0,
 | |
| 	unsigned long len, unsigned long pgoff, unsigned long flags)
 | |
| {
 | |
| 	return arch_get_unmapped_area_common(filp,
 | |
| 			addr0, len, pgoff, flags, UP);
 | |
| }
 | |
| 
 | |
| /*
 | |
|  * There is no need to export this but sched.h declares the function as
 | |
|  * extern so making it static here results in an error.
 | |
|  */
 | |
| unsigned long arch_get_unmapped_area_topdown(struct file *filp,
 | |
| 	unsigned long addr0, unsigned long len, unsigned long pgoff,
 | |
| 	unsigned long flags)
 | |
| {
 | |
| 	return arch_get_unmapped_area_common(filp,
 | |
| 			addr0, len, pgoff, flags, DOWN);
 | |
| }
 | |
| 
 | |
| unsigned long arch_mmap_rnd(void)
 | |
| {
 | |
| 	unsigned long rnd;
 | |
| 
 | |
| 	rnd = (unsigned long)get_random_int();
 | |
| 	rnd <<= PAGE_SHIFT;
 | |
| 	if (TASK_IS_32BIT_ADDR)
 | |
| 		rnd &= 0xfffffful;
 | |
| 	else
 | |
| 		rnd &= 0xffffffful;
 | |
| 
 | |
| 	return rnd;
 | |
| }
 | |
| 
 | |
| void arch_pick_mmap_layout(struct mm_struct *mm)
 | |
| {
 | |
| 	unsigned long random_factor = 0UL;
 | |
| 
 | |
| 	if (current->flags & PF_RANDOMIZE)
 | |
| 		random_factor = arch_mmap_rnd();
 | |
| 
 | |
| 	if (mmap_is_legacy()) {
 | |
| 		mm->mmap_base = TASK_UNMAPPED_BASE + random_factor;
 | |
| 		mm->get_unmapped_area = arch_get_unmapped_area;
 | |
| 	} else {
 | |
| 		mm->mmap_base = mmap_base(random_factor);
 | |
| 		mm->get_unmapped_area = arch_get_unmapped_area_topdown;
 | |
| 	}
 | |
| }
 | |
| 
 | |
| static inline unsigned long brk_rnd(void)
 | |
| {
 | |
| 	unsigned long rnd = get_random_int();
 | |
| 
 | |
| 	rnd = rnd << PAGE_SHIFT;
 | |
| 	/* 8MB for 32bit, 256MB for 64bit */
 | |
| 	if (TASK_IS_32BIT_ADDR)
 | |
| 		rnd = rnd & 0x7ffffful;
 | |
| 	else
 | |
| 		rnd = rnd & 0xffffffful;
 | |
| 
 | |
| 	return rnd;
 | |
| }
 | |
| 
 | |
| unsigned long arch_randomize_brk(struct mm_struct *mm)
 | |
| {
 | |
| 	unsigned long base = mm->brk;
 | |
| 	unsigned long ret;
 | |
| 
 | |
| 	ret = PAGE_ALIGN(base + brk_rnd());
 | |
| 
 | |
| 	if (ret < mm->brk)
 | |
| 		return mm->brk;
 | |
| 
 | |
| 	return ret;
 | |
| }
 | |
| 
 | |
| int __virt_addr_valid(const volatile void *kaddr)
 | |
| {
 | |
| 	return pfn_valid(PFN_DOWN(virt_to_phys(kaddr)));
 | |
| }
 | |
| EXPORT_SYMBOL_GPL(__virt_addr_valid);
 |