Skip to content

Multiple fixes needed for protect_resource request: init memory page to 0, fill out all C struct fields, add terminator, and print out outgoing protection request #10

Description

@bdelgado1995

The protest_resource vmcall needs to append a RSC_END to the protection request to terminate the request.

Activity

  1. bdelgado1995 commented on Jul 13, 2020

    @bdelgado1995
    Author

    Sample patch to fix issues in protect resources.
    Updated patch: initializes page used for protection policy, fills out all fields of C structs, adds terminator, also prints the outgoing protection request.
    patch2.txt

  2. changed the title [-]protect_resource vmcall doesn't terminate the protection request with RSC_END[/-] [+]Multiple fixes needed for protect_resource request: init memory page to 0, fill out all C struct fields, add terminator, and print out outgoing protection request[/+] on Jul 13, 2020
  3. bdelgado1995 commented on Jul 31, 2020

    @bdelgado1995
    Author

    Updated protection code (fix bug in IO port protection length and also RWX bits for memory protection.
    8/3/2020 Update: Made a larger memory protection request to also cover memory from drivers

    int protect_resources(void)
    {
    void *resource_list;
    uint8_t *xenresources = NULL;
    uint32_t eax_reg = STM_API_PROTECT_RESOURCE;
    uint32_t ebx_reg = 0;
    uint32_t ecx_reg = 0;
    int page_index = 0;
    STM_RSC_MSR_DESC MsrDesc = {};
    STM_RSC_IO_DESC IoDesc = {};
    STM_RSC_MEM_DESC MemDesc = {};
    STM_RSC_END EndDesc = {};

    printk("STM: Protecting Xen Resources\n");
    if ( (resource_list = alloc_xenheap_pages(1, 0)) == NULL )
    {
        printk("STM: Failed to allocate resource page.\n");
        return -1;
    }
    
    xenresources = (uint8_t*)resource_list;
    memset(xenresources, 0, 4096);
    MsrDesc.Hdr.RscType = MACHINE_SPECIFIC_REG;
    MsrDesc.Hdr.Length = sizeof(STM_RSC_MSR_DESC);
    MsrDesc.Hdr.ReturnStatus = 0;
    MsrDesc.Hdr.Reserved = 0;
    MsrDesc.Hdr.IgnoreResource = 0;
    MsrDesc.MsrIndex = 0x9b;
    MsrDesc.KernelModeProcessing = 1;
    MsrDesc.Reserved = 0;
    MsrDesc.WriteMask = (uint64_t) - 1;
    MsrDesc.ReadMask = 0;
    
    memcpy(xenresources, &MsrDesc, sizeof(MsrDesc));
    xenresources += MsrDesc.Hdr.Length;
    
    MsrDesc.Hdr.RscType = MACHINE_SPECIFIC_REG;
    MsrDesc.Hdr.Length = sizeof(STM_RSC_MSR_DESC);
    MsrDesc.Hdr.ReturnStatus = 0;
    MsrDesc.Hdr.Reserved = 0;
    MsrDesc.Hdr.IgnoreResource = 0;
    MsrDesc.MsrIndex = MSR_IA32_MISC_ENABLE; /* 0x1A0 */
    MsrDesc.KernelModeProcessing = 0;
    MsrDesc.Reserved = 0;
    MsrDesc.WriteMask = (uint64_t) - 1;
    MsrDesc.ReadMask = 0; 
    
    memcpy(xenresources, &MsrDesc, sizeof(MsrDesc));
    xenresources += MsrDesc.Hdr.Length;
    
    MsrDesc.Hdr.RscType = MACHINE_SPECIFIC_REG;
    MsrDesc.Hdr.Length = sizeof(STM_RSC_MSR_DESC);
    MsrDesc.Hdr.ReturnStatus = 0;
    MsrDesc.Hdr.Reserved = 0;
    MsrDesc.Hdr.IgnoreResource = 0;
    MsrDesc.MsrIndex =MSR_IA32_SYSENTER_EIP; /* 0x176 */
    MsrDesc.KernelModeProcessing = 0;
    MsrDesc.Reserved = 0;
    MsrDesc.WriteMask = (uint64_t) - 1;
    MsrDesc.ReadMask  = (uint64_t) - 1; 
    
    memcpy(xenresources, &MsrDesc, sizeof(MsrDesc));
    xenresources += MsrDesc.Hdr.Length;
        
    MsrDesc.Hdr.RscType = MACHINE_SPECIFIC_REG;
    MsrDesc.Hdr.Length = sizeof(STM_RSC_MSR_DESC);
    MsrDesc.Hdr.ReturnStatus = 0;
    MsrDesc.Hdr.Reserved = 0;
    MsrDesc.Hdr.IgnoreResource = 0;
    MsrDesc.MsrIndex = MSR_IA32_FEATURE_CONTROL;
    MsrDesc.KernelModeProcessing = 0;
    MsrDesc.Reserved = 0;
    MsrDesc.ReadMask = (uint64_t) - 1;
    MsrDesc.WriteMask = (uint64_t) - 1;
    
    memcpy(xenresources, &MsrDesc, sizeof(MsrDesc));
    xenresources += MsrDesc.Hdr.Length;
    
    IoDesc.Hdr.RscType = IO_RANGE;
    IoDesc.Hdr.Length = sizeof(STM_RSC_IO_DESC);
    IoDesc.Hdr.ReturnStatus = 0;
    IoDesc.Hdr.Reserved = 0;
    IoDesc.Hdr.IgnoreResource = 0;
    IoDesc.Base = 0x60; // 0x60 to 0x64
    IoDesc.Length = 5;
    IoDesc.Reserved = 0;
    
    memcpy(xenresources, &IoDesc, sizeof(IoDesc));
    xenresources += IoDesc.Hdr.Length;
    
    MemDesc.Hdr.RscType = MEM_RANGE;
    MemDesc.Hdr.Length = sizeof(STM_RSC_MEM_DESC);
    MemDesc.Hdr.ReturnStatus = 0;
    MemDesc.Hdr.Reserved = 0;
    MemDesc.Hdr.IgnoreResource = 0;
    MemDesc.Base = (uint64_t)__pa(&_stext);
    MemDesc.Base = (uint64_t)0x20000000;
    MemDesc.Length =         0x57291000;
    MemDesc.Reserved = 0;
    MemDesc.Reserved_2 = 0;
    
    memcpy(xenresources, &MemDesc, sizeof(MemDesc));
    xenresources += MemDesc.Hdr.Length;
    
    // Termination
    EndDesc.Hdr.RscType = END_OF_RESOURCES;
    EndDesc.Hdr.Length = sizeof(STM_RSC_END);
    EndDesc.Hdr.ReturnStatus = 0;
    EndDesc.Hdr.Reserved = 0;
    EndDesc.Hdr.IgnoreResource = 0;
    EndDesc.ResourceListContinuation = 0;
    
    memcpy(xenresources, &EndDesc, sizeof(EndDesc));
    
    printk("\nGoing to request protection for: %lx", (uint64_t)resource_list);
    dump_stm_resource(resource_list);
    
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions