From 2c0cdded94e00bf228b42e3475eb1b17c6b366e5 Mon Sep 17 00:00:00 2001 From: Sami Tolvanen Date: Thu, 10 Sep 2020 15:33:56 -0700 Subject: [PATCH 1/2] ANDROID: mm: add generic __va_function and __pa_function We use non-canonical CFI jump tables with CONFIG_CFI_CLANG, which means the compiler replaces function address references with the address of the function's CFI jump table entry. This results in __pa_symbol(function), for example, returning the physical address of the jump table entry, which can lead to address space confusion since the jump table itself points to a virtual address. This change adds generic definitions for __pa/va_function, which architectures that support CFI can override. Bug: 166220312 Change-Id: If4a162de7854547d8437bf59be03eb6d16220832 Signed-off-by: Sami Tolvanen Git-commit: d509371db88a829fa13fbb066423b20fc4698845 Git-repo: https://android.googlesource.com/kernel/common/ Signed-off-by: Prasad Sodagudi --- include/linux/mm.h | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/include/linux/mm.h b/include/linux/mm.h index 6e49aeb26dbc..8300807e7c7e 100644 --- a/include/linux/mm.h +++ b/include/linux/mm.h @@ -116,6 +116,14 @@ extern int mmap_rnd_compat_bits __read_mostly; #define __pa_symbol(x) __pa(RELOC_HIDE((unsigned long)(x), 0)) #endif +#ifndef __va_function +#define __va_function(x) (x) +#endif + +#ifndef __pa_function +#define __pa_function(x) __pa_symbol(x) +#endif + #ifndef page_to_virt #define page_to_virt(x) __va(PFN_PHYS(page_to_pfn(x))) #endif From 062642e76e8bf4f2cb993dd438fdd3bd97dd78e4 Mon Sep 17 00:00:00 2001 From: Prasad Sodagudi Date: Tue, 15 Sep 2020 10:07:13 -0700 Subject: [PATCH 2/2] ANDROID: lkdtm/usercopy: Use __va_function to find proper vm_mmap address With CFI enabled compiler replacing the reference to vm_mmap passed to copy_to_user with a pointer to the CFI jump table in the module itself. So use the __va_function API for finding the proper address of vm_mmap. Bug: 166220312 Suggested-by: Sami Tolvanen Change-Id: Id5bd96cc9bfa1aa99f34bd4785792e0a4eeae5b1 Git-commit: 33752ec915fb9dcccfe3afe4c4df4e032a0d823f Git-repo: https://android.googlesource.com/kernel/common/ Signed-off-by: Prasad Sodagudi --- drivers/misc/lkdtm/usercopy.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/drivers/misc/lkdtm/usercopy.c b/drivers/misc/lkdtm/usercopy.c index b833367a45d0..120e9ffd0f28 100644 --- a/drivers/misc/lkdtm/usercopy.c +++ b/drivers/misc/lkdtm/usercopy.c @@ -314,7 +314,7 @@ void lkdtm_USERCOPY_KERNEL(void) pr_info("attempting bad copy_to_user from kernel text: %px\n", vm_mmap); - if (copy_to_user((void __user *)user_addr, vm_mmap, + if (copy_to_user((void __user *)user_addr, __va_function(vm_mmap), unconst + PAGE_SIZE)) { pr_warn("copy_to_user failed, but lacked Oops\n"); goto free_user;