[PATCH 08/17] x86/ftrace: set trampoline pages as executable
Rick Edgecombe
rick.p.edgecombe at intel.com
Thu Jan 17 00:32:50 UTC 2019
From: Nadav Amit <namit at vmware.com>
Since alloc_module() will not set the pages as executable soon, we need
to do so for ftrace trampoline pages after they are allocated.
For the time being, we do not change ftrace to use the text_poke()
interface. As a result, ftrace breaks still breaks W^X.
Cc: Steven Rostedt <rostedt at goodmis.org>
Signed-off-by: Nadav Amit <namit at vmware.com>
Signed-off-by: Rick Edgecombe <rick.p.edgecombe at intel.com>
---
arch/x86/kernel/ftrace.c | 9 +++++++++
1 file changed, 9 insertions(+)
diff --git a/arch/x86/kernel/ftrace.c b/arch/x86/kernel/ftrace.c
index 8257a59704ae..eb4a1937e72c 100644
--- a/arch/x86/kernel/ftrace.c
+++ b/arch/x86/kernel/ftrace.c
@@ -742,6 +742,7 @@ create_trampoline(struct ftrace_ops *ops, unsigned int *tramp_size)
unsigned long end_offset;
unsigned long op_offset;
unsigned long offset;
+ unsigned long npages;
unsigned long size;
unsigned long retq;
unsigned long *ptr;
@@ -774,6 +775,7 @@ create_trampoline(struct ftrace_ops *ops, unsigned int *tramp_size)
return 0;
*tramp_size = size + RET_SIZE + sizeof(void *);
+ npages = DIV_ROUND_UP(*tramp_size, PAGE_SIZE);
/* Copy ftrace_caller onto the trampoline memory */
ret = probe_kernel_read(trampoline, (void *)start_offset, size);
@@ -818,6 +820,13 @@ create_trampoline(struct ftrace_ops *ops, unsigned int *tramp_size)
/* ALLOC_TRAMP flags lets us know we created it */
ops->flags |= FTRACE_OPS_FL_ALLOC_TRAMP;
+ /*
+ * Module allocation needs to be completed by making the page
+ * executable. The page is still writable, which is a security hazard,
+ * but anyhow ftrace breaks W^X completely.
+ */
+ set_memory_x((unsigned long)trampoline, npages);
+
return (unsigned long)trampoline;
fail:
tramp_free(trampoline, *tramp_size);
--
2.17.1
More information about the Linux-security-module-archive
mailing list