Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
113 commits
Select commit Hold shift + click to select a range
e94654b
make DEFAULT_MMAP_MIN_ADDR match LSM_MMAP_MIN_ADDR
thestinger May 27, 2017
6c426c1
enable HARDENED_USERCOPY by default
thestinger May 29, 2017
e186de2
enable SECURITY_DMESG_RESTRICT by default
thestinger May 3, 2017
e497b45
set kptr_restrict=2 by default
thestinger May 3, 2017
62fca98
enable DEBUG_LIST by default
thestinger May 3, 2017
bfddc3b
enable BUG_ON_DATA_CORRUPTION by default
thestinger May 29, 2017
0376d2c
enable ARM64_SW_TTBR0_PAN by default
thestinger Feb 25, 2018
cfc66b2
arm64: enable RANDOMIZE_BASE by default
thestinger Feb 25, 2018
aca07ff
enable SLAB_FREELIST_RANDOM by default
thestinger May 3, 2017
16b70e2
enable SLAB_FREELIST_HARDENED by default
thestinger Aug 20, 2017
e3f1795
disable SLAB_MERGE_DEFAULT by default
thestinger Jul 8, 2017
932e708
enable REFCOUNT_FULL by default
thestinger Jan 3, 2018
a2f1bc9
enable CC_STACKPROTECTOR_STRONG by default
thestinger May 8, 2017
5d16abb
enable FORTIFY_SOURCE by default
thestinger May 8, 2017
1c997d7
enable PANIC_ON_OOPS by default
thestinger May 3, 2017
2f21cb4
stop hiding SLUB_DEBUG behind EXPERT
thestinger May 15, 2017
4c16ccc
stop hiding X86_16BIT behind EXPERT
thestinger May 4, 2017
b9766f7
disable X86_16BIT by default
thestinger May 4, 2017
fe9f4f7
stop hiding MODIFY_LDT_SYSCALL behind EXPERT
thestinger May 4, 2017
65f9894
disable MODIFY_LDT_SYSCALL by default
thestinger May 4, 2017
06236b5
set LEGACY_VSYSCALL_NONE by default
thestinger May 29, 2017
37bd4cc
stop hiding AIO behind EXPERT
Bernhard40 Oct 6, 2017
3a96da1
disable AIO by default
Bernhard40 Oct 6, 2017
f314542
remove SYSVIPC from arm64/x86_64 defconfigs
thestinger Feb 25, 2018
bf52210
disable DEVPORT by default
thestinger May 27, 2017
9302e86
disable PROC_VMCORE by default
thestinger May 27, 2017
c879e09
disable NFS_DEBUG by default
thestinger May 28, 2017
993ac9d
enable DEBUG_WX by default
thestinger May 29, 2017
715baec
disable LEGACY_PTYS by default
thestinger Jan 5, 2018
6f56f03
disable DEVMEM by default
thestinger Jan 5, 2018
2f51249
enable STRICT_DEVMEM by default everywhere
thestinger Jan 5, 2018
5bb183d
enable IO_STRICT_DEVMEM by default
thestinger Jan 5, 2018
75129f0
disable COMPAT_BRK by default
thestinger May 7, 2017
8ab9bd8
use maximum supported mmap rnd entropy by default
thestinger May 7, 2017
650c731
enable protected_{symlinks,hardlinks} by default
thestinger May 30, 2017
d7694f3
enable SECURITY by default
thestinger Feb 25, 2018
da1160a
enable SECURITY_YAMA by default
thestinger May 29, 2017
76ae174
enable SECURITY_NETWORK by default
thestinger Feb 25, 2018
461b9dc
enable AUDIT by default
thestinger Feb 25, 2018
9b7863b
enable SECURITY_SELINUX by default
thestinger Feb 25, 2018
b559f7a
enable SYN_COOKIES by default
thestinger Jan 6, 2018
c2f9726
drivers/media: improve the return type of a bunch of .get_frontend_al…
debrouxl May 13, 2017
247396f
add __read_only for non-init related usage
thestinger May 7, 2017
b584c49
make sysctl constants read-only
thestinger May 7, 2017
14e3837
mark kernel_set_to_readonly as __ro_after_init
thestinger May 12, 2017
712222b
mark slub runtime configuration as __ro_after_init
thestinger May 14, 2017
282211c
add __ro_after_init to slab_nomerge and slab_state
thestinger May 3, 2017
2e6f366
mark size_index as __ro_after_init
thestinger May 28, 2017
1e25a8c
mark kmem_cache as __ro_after_init
thestinger May 28, 2017
7dd4a20
mark __supported_pte_mask as __ro_after_init
thestinger May 12, 2017
bbf0ac5
mark kobj_ns_type_register as only used for init
thestinger Jul 4, 2017
4ff960d
mark open_softirq as only used for init
thestinger Jul 4, 2017
66d1831
remove unused softirq_action callback parameter
thestinger Jul 4, 2017
1eb285b
mark softirq_vec as __ro_after_init
thestinger Jul 4, 2017
7fbcbd1
add a SLAB_HARDENED configuration option
thestinger May 3, 2017
62a51a2
add missing cache_from_obj !PageSlab check
thestinger May 3, 2017
3b8c54d
real slab_equal_or_root check for !MEMCG_KMEM
thestinger Mar 31, 2017
6b7bffa
bug on kmem_cache_free with the wrong cache
thestinger May 3, 2017
49fbce0
always perform cache_from_obj consistency checks
thestinger May 3, 2017
5474a66
bug on !PageSlab && !PageCompound in ksize
thestinger May 3, 2017
0e8ce23
add simpler page sanitization
thestinger May 4, 2017
0c38c4e
add support for verifying page sanitization
thestinger May 4, 2017
e17517a
slub: add basic full slab sanitization
thestinger May 3, 2017
544154d
slub: add support for verifying slab sanitization
thestinger May 4, 2017
664a1a4
slub: add multi-purpose random canaries
thestinger May 3, 2017
7109a6c
security,perf: Allow further restriction of perf_event_open
bwhacks Jan 11, 2016
facec86
enable SECURITY_PERF_EVENTS_RESTRICT by default
thestinger May 4, 2017
f1a6558
add sysctl to disallow unprivileged CLONE_NEWUSER by default
hallyn May 31, 2013
8b020dc
add kmalloc/krealloc alloc_size attributes
thestinger May 3, 2017
31f5e2c
add vmalloc alloc_size attributes
thestinger May 3, 2017
5786574
add kvmalloc alloc_size attribute
thestinger Jul 4, 2017
862cc2f
add percpu alloc_size attributes
thestinger May 14, 2017
9e67c99
add alloc_pages_exact alloc_size attributes
thestinger May 14, 2017
78e0afe
Add the extra_latent_entropy kernel parameter
ephox-gcc-plugins May 30, 2016
8dd7b3a
ata: avoid null pointer dereference on bug
thestinger May 16, 2017
c3e1e38
sanity check for negative length in nla_memcpy
thestinger May 16, 2017
a0411ef
add page destructor sanity check
thestinger May 16, 2017
51b42cc
PaX shadow cr4 sanity check (essentially a revert)
thestinger May 16, 2017
88b5b1f
add writable function pointer detection
thestinger Jul 9, 2017
e2e1134
support overriding early audit kernel cmdline
thestinger Jul 9, 2017
94e80f2
FORTIFY_SOURCE intra-object overflow checking
thestinger Jun 3, 2017
45d34d4
Revert "mm: revert x86_64 and arm64 ELF_ET_DYN_BASE base changes"
thestinger Aug 27, 2017
29fde91
x86_64: move vdso to mmap region from stack region
thestinger May 11, 2017
c22861d
x86: determine stack entropy based on mmap entropy
thestinger May 22, 2017
6ab2f83
arm64: determine stack entropy based on mmap entropy
thestinger May 22, 2017
486878e
randomize lower bits of the argument block
thestinger May 11, 2017
1c8a247
x86_64: match arm64 brk randomization entropy
thestinger May 30, 2017
960e09b
support randomizing the lower bits of brk
thestinger May 30, 2017
a1e670a
arm64: randomize lower bits of brk
thestinger Jun 1, 2017
20476d5
x86: randomize lower bits of brk
thestinger Jun 1, 2017
69bb836
arm64: guarantee brk gap is at least one page
thestinger Jun 1, 2017
8f78ff9
x86: guarantee brk gap is at least one page
thestinger Jun 1, 2017
add08d5
x86_64: bound mmap between legacy/modern bases
thestinger Jul 4, 2017
fb3353f
security: tty: Add owner user namespace to tty_struct
nmatt0 May 29, 2017
7c0ee5a
security: tty: make TIOCSTI ioctl require CAP_SYS_ADMIN
nmatt0 May 29, 2017
75205b4
enable SECURITY_TIOCSTI_RESTRICT by default
thestinger May 4, 2017
27dcad0
restrict device timing side channels
thestinger May 16, 2017
1c1f9b8
add toggle for disabling newly added USB devices
thestinger May 16, 2017
96d8fc9
wire up -fsanitize=local-init
thestinger Jan 25, 2018
f0880a2
hard-wire legacy checkreqprot option to 0
thestinger Feb 25, 2018
677cbc6
disable unprivileged eBPF access by default
anthraxx May 7, 2018
eb69fe5
enable BPF JIT hardening by default (if available)
anthraxx May 7, 2018
5bfd005
enable protected_{fifos,regular} by default
anthraxx Nov 4, 2018
52d2a13
Enable gcc plugin by default.
theLOICofFRANCE Dec 21, 2018
bc2516c
Update default value.
theLOICofFRANCE Dec 21, 2018
b10654a
Update default for DEVKMEM
theLOICofFRANCE Dec 21, 2018
6243e9b
Update default for PROC_PAGE_MONITOR
theLOICofFRANCE Dec 21, 2018
64257f0
Disable UPROBE_EVENTS
theLOICofFRANCE Dec 21, 2018
37f7e1b
Update IP_SCTP
theLOICofFRANCE Dec 21, 2018
b68c667
Disable TIPC
theLOICofFRANCE Dec 21, 2018
9afa9bc
Add equivalent to GRKERNSEC_MODHARDEN
theLOICofFRANCE Dec 21, 2018
f5266f2
Add equivalent to GRKERNSEC_SYSFS_RESTRICT
theLOICofFRANCE Dec 21, 2018
a3bdc9b
log the access to SUID
theLOICofFRANCE Jan 11, 2019
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
15 changes: 5 additions & 10 deletions Documentation/admin-guide/kernel-parameters.txt
Original file line number Diff line number Diff line change
Expand Up @@ -490,16 +490,6 @@
nosocket -- Disable socket memory accounting.
nokmem -- Disable kernel memory accounting.

checkreqprot [SELINUX] Set initial checkreqprot flag value.
Format: { "0" | "1" }
See security/selinux/Kconfig help text.
0 -- check protection applied by kernel (includes
any implied execute protection).
1 -- check protection requested by application.
Default value is set via a kernel config option.
Value can be changed at runtime via
/selinux/checkreqprot.

cio_ignore= [S390]
See Documentation/s390/CommonIO for details.
clk_ignore_unused
Expand Down Expand Up @@ -2981,6 +2971,11 @@
the specified number of seconds. This is to be used if
your oopses keep scrolling off the screen.

extra_latent_entropy
Enable a very simple form of latent entropy extraction
from the first 4GB of memory as the bootmem allocator
passes the memory pages to the buddy allocator.

pcbit= [HW,ISDN]

pcd. [PARIDE]
Expand Down
21 changes: 21 additions & 0 deletions Documentation/sysctl/kernel.txt
Original file line number Diff line number Diff line change
Expand Up @@ -91,6 +91,7 @@ show up in /proc/sys/kernel:
- sysctl_writes_strict
- tainted
- threads-max
- tiocsti_restrict
- unknown_nmi_panic
- watchdog
- watchdog_thresh
Expand Down Expand Up @@ -999,6 +1000,26 @@ available RAM pages threads-max is reduced accordingly.

==============================================================

tiocsti_restrict:

This toggle indicates whether unprivileged users are prevented
from using the TIOCSTI ioctl to inject commands into other processes
which share a tty session.

When tiocsti_restrict is set to (0) there are no restrictions(accept
the default restriction of only being able to injection commands into
one's own tty). When tiocsti_restrict is set to (1), users must
have CAP_SYS_ADMIN to use the TIOCSTI ioctl.

When user namespaces are in use, the check for the capability
CAP_SYS_ADMIN is done against the user namespace that originally
opened the tty.

The kernel config option CONFIG_SECURITY_TIOCSTI_RESTRICT sets the
default value of tiocsti_restrict.

==============================================================

unknown_nmi_panic:

The value in this file affects behavior of handling NMI. When the
Expand Down
3 changes: 3 additions & 0 deletions Makefile
Original file line number Diff line number Diff line change
Expand Up @@ -714,6 +714,9 @@ endif
KBUILD_CFLAGS += $(stackp-flag)

ifeq ($(cc-name),clang)
ifdef CONFIG_LOCAL_INIT
KBUILD_CFLAGS += -fsanitize=local-init
endif
KBUILD_CPPFLAGS += $(call cc-option,-Qunused-arguments,)
KBUILD_CFLAGS += $(call cc-disable-warning, format-invalid-specifier)
KBUILD_CFLAGS += $(call cc-disable-warning, gnu)
Expand Down
13 changes: 10 additions & 3 deletions arch/Kconfig
Original file line number Diff line number Diff line change
Expand Up @@ -403,6 +403,7 @@ menuconfig GCC_PLUGINS
bool "GCC plugins"
depends on HAVE_GCC_PLUGINS
depends on !COMPILE_TEST
default y
help
GCC plugins are loadable modules that provide extra features to the
compiler. They are useful for runtime instrumentation and static analysis.
Expand Down Expand Up @@ -446,6 +447,11 @@ config GCC_PLUGIN_LATENT_ENTROPY
is some slowdown of the boot process (about 0.5%) and fork and
irq processing.

When extra_latent_entropy is passed on the kernel command line,
entropy will be extracted from up to the first 4GB of RAM while the
runtime memory allocator is being initialized. This costs even more
slowdown of the boot process.

Note that entropy extracted this way is not cryptographically
secure!

Expand Down Expand Up @@ -539,7 +545,7 @@ config CC_STACKPROTECTOR
choice
prompt "Stack Protector buffer overflow detection"
depends on HAVE_CC_STACKPROTECTOR
default CC_STACKPROTECTOR_NONE
default CC_STACKPROTECTOR_STRONG
help
This option turns on the "stack-protector" GCC feature. This
feature puts, at the beginning of functions, a canary value on
Expand Down Expand Up @@ -741,7 +747,7 @@ config ARCH_MMAP_RND_BITS
int "Number of bits to use for ASLR of mmap base address" if EXPERT
range ARCH_MMAP_RND_BITS_MIN ARCH_MMAP_RND_BITS_MAX
default ARCH_MMAP_RND_BITS_DEFAULT if ARCH_MMAP_RND_BITS_DEFAULT
default ARCH_MMAP_RND_BITS_MIN
default ARCH_MMAP_RND_BITS_MAX
depends on HAVE_ARCH_MMAP_RND_BITS
help
This value can be used to select the number of bits to use to
Expand Down Expand Up @@ -775,7 +781,7 @@ config ARCH_MMAP_RND_COMPAT_BITS
int "Number of bits to use for ASLR of mmap base address for compatible applications" if EXPERT
range ARCH_MMAP_RND_COMPAT_BITS_MIN ARCH_MMAP_RND_COMPAT_BITS_MAX
default ARCH_MMAP_RND_COMPAT_BITS_DEFAULT if ARCH_MMAP_RND_COMPAT_BITS_DEFAULT
default ARCH_MMAP_RND_COMPAT_BITS_MIN
default ARCH_MMAP_RND_COMPAT_BITS_MAX
depends on HAVE_ARCH_MMAP_RND_COMPAT_BITS
help
This value can be used to select the number of bits to use to
Expand Down Expand Up @@ -958,6 +964,7 @@ config ARCH_HAS_REFCOUNT

config REFCOUNT_FULL
bool "Perform full reference count validation at the expense of speed"
default y
help
Enabling this switches the refcounting infrastructure from a fast
unchecked atomic_t implementation to a fully state checked
Expand Down
2 changes: 2 additions & 0 deletions arch/arm64/Kconfig
Original file line number Diff line number Diff line change
Expand Up @@ -926,6 +926,7 @@ endif

config ARM64_SW_TTBR0_PAN
bool "Emulate Privileged Access Never using TTBR0_EL1 switching"
default y
help
Enabling this option prevents the kernel from accessing
user-space memory directly by pointing TTBR0_EL1 to a reserved
Expand Down Expand Up @@ -1052,6 +1053,7 @@ config RANDOMIZE_BASE
bool "Randomize the address of the kernel image"
select ARM64_MODULE_PLTS if MODULES
select RELOCATABLE
default y
help
Randomizes the virtual address at which the kernel image is
loaded, as a security feature that deters exploit attempts
Expand Down
1 change: 1 addition & 0 deletions arch/arm64/Kconfig.debug
Original file line number Diff line number Diff line change
Expand Up @@ -45,6 +45,7 @@ config ARM64_RANDOMIZE_TEXT_OFFSET
config DEBUG_WX
bool "Warn on W+X mappings at boot"
select ARM64_PTDUMP_CORE
default y
---help---
Generate a warning if any W+X mappings are found at boot.

Expand Down
1 change: 0 additions & 1 deletion arch/arm64/configs/defconfig
Original file line number Diff line number Diff line change
@@ -1,4 +1,3 @@
CONFIG_SYSVIPC=y
CONFIG_POSIX_MQUEUE=y
CONFIG_AUDIT=y
CONFIG_NO_HZ_IDLE=y
Expand Down
10 changes: 5 additions & 5 deletions arch/arm64/include/asm/elf.h
Original file line number Diff line number Diff line change
Expand Up @@ -114,10 +114,10 @@

/*
* This is the base location for PIE (ET_DYN with INTERP) loads. On
* 64-bit, this is above 4GB to leave the entire 32-bit address
* 64-bit, this is raised to 4GB to leave the entire 32-bit address
* space open for things that want to use the area for 32-bit pointers.
*/
#define ELF_ET_DYN_BASE (2 * TASK_SIZE_64 / 3)
#define ELF_ET_DYN_BASE 0x100000000UL

#ifndef __ASSEMBLY__

Expand Down Expand Up @@ -158,10 +158,10 @@ extern int arch_setup_additional_pages(struct linux_binprm *bprm,
/* 1GB of VA */
#ifdef CONFIG_COMPAT
#define STACK_RND_MASK (test_thread_flag(TIF_32BIT) ? \
0x7ff >> (PAGE_SHIFT - 12) : \
0x3ffff >> (PAGE_SHIFT - 12))
((1UL << mmap_rnd_compat_bits) - 1) >> (PAGE_SHIFT - 12) : \
((1UL << mmap_rnd_bits) - 1) >> (PAGE_SHIFT - 12))
#else
#define STACK_RND_MASK (0x3ffff >> (PAGE_SHIFT - 12))
#define STACK_RND_MASK (((1UL << mmap_rnd_bits) - 1) >> (PAGE_SHIFT - 12))
#endif

#ifdef __AARCH64EB__
Expand Down
4 changes: 2 additions & 2 deletions arch/arm64/kernel/process.c
Original file line number Diff line number Diff line change
Expand Up @@ -419,9 +419,9 @@ unsigned long arch_align_stack(unsigned long sp)
unsigned long arch_randomize_brk(struct mm_struct *mm)
{
if (is_compat_task())
return randomize_page(mm->brk, SZ_32M);
return mm->brk + get_random_long() % SZ_32M + PAGE_SIZE;
else
return randomize_page(mm->brk, SZ_1G);
return mm->brk + get_random_long() % SZ_1G + PAGE_SIZE;
}

/*
Expand Down
8 changes: 3 additions & 5 deletions arch/x86/Kconfig
Original file line number Diff line number Diff line change
Expand Up @@ -1145,8 +1145,7 @@ config VM86
default X86_LEGACY_VM86

config X86_16BIT
bool "Enable support for 16-bit segments" if EXPERT
default y
bool "Enable support for 16-bit segments"
depends on MODIFY_LDT_SYSCALL
---help---
This option is required by programs like Wine to run 16-bit
Expand Down Expand Up @@ -2220,7 +2219,7 @@ config COMPAT_VDSO
choice
prompt "vsyscall table for legacy applications"
depends on X86_64
default LEGACY_VSYSCALL_EMULATE
default LEGACY_VSYSCALL_NONE
help
Legacy user code that does not know how to find the vDSO expects
to be able to issue three syscalls by calling fixed addresses in
Expand Down Expand Up @@ -2310,8 +2309,7 @@ config CMDLINE_OVERRIDE
be set to 'N' under normal conditions.

config MODIFY_LDT_SYSCALL
bool "Enable the LDT (local descriptor table)" if EXPERT
default y
bool "Enable the LDT (local descriptor table)"
---help---
Linux can allow user programs to install a per-process x86
Local Descriptor Table (LDT) using the modify_ldt(2) system
Expand Down
1 change: 1 addition & 0 deletions arch/x86/Kconfig.debug
Original file line number Diff line number Diff line change
Expand Up @@ -101,6 +101,7 @@ config EFI_PGT_DUMP
config DEBUG_WX
bool "Warn on W+X mappings at boot"
select X86_PTDUMP_CORE
default y
---help---
Generate a warning if any W+X mappings are found at boot.

Expand Down
1 change: 0 additions & 1 deletion arch/x86/configs/x86_64_defconfig
Original file line number Diff line number Diff line change
@@ -1,5 +1,4 @@
# CONFIG_LOCALVERSION_AUTO is not set
CONFIG_SYSVIPC=y
CONFIG_POSIX_MQUEUE=y
CONFIG_BSD_PROCESS_ACCT=y
CONFIG_TASKSTATS=y
Expand Down
48 changes: 1 addition & 47 deletions arch/x86/entry/vdso/vma.c
Original file line number Diff line number Diff line change
Expand Up @@ -203,55 +203,9 @@ static int map_vdso(const struct vdso_image *image, unsigned long addr)
}

#ifdef CONFIG_X86_64
/*
* Put the vdso above the (randomized) stack with another randomized
* offset. This way there is no hole in the middle of address space.
* To save memory make sure it is still in the same PTE as the stack
* top. This doesn't give that many random bits.
*
* Note that this algorithm is imperfect: the distribution of the vdso
* start address within a PMD is biased toward the end.
*
* Only used for the 64-bit and x32 vdsos.
*/
static unsigned long vdso_addr(unsigned long start, unsigned len)
{
unsigned long addr, end;
unsigned offset;

/*
* Round up the start address. It can start out unaligned as a result
* of stack start randomization.
*/
start = PAGE_ALIGN(start);

/* Round the lowest possible end address up to a PMD boundary. */
end = (start + len + PMD_SIZE - 1) & PMD_MASK;
if (end >= TASK_SIZE_MAX)
end = TASK_SIZE_MAX;
end -= len;

if (end > start) {
offset = get_random_int() % (((end - start) >> PAGE_SHIFT) + 1);
addr = start + (offset << PAGE_SHIFT);
} else {
addr = start;
}

/*
* Forcibly align the final address in case we have a hardware
* issue that requires alignment for performance reasons.
*/
addr = align_vdso_addr(addr);

return addr;
}

static int map_vdso_randomized(const struct vdso_image *image)
{
unsigned long addr = vdso_addr(current->mm->start_stack, image->size-image->sym_vvar_start);

return map_vdso(image, addr);
return map_vdso(image, 0);
}
#endif

Expand Down
15 changes: 9 additions & 6 deletions arch/x86/include/asm/elf.h
Original file line number Diff line number Diff line change
Expand Up @@ -249,11 +249,11 @@ extern int force_personality32;

/*
* This is the base location for PIE (ET_DYN with INTERP) loads. On
* 64-bit, this is above 4GB to leave the entire 32-bit address
* 64-bit, this is raised to 4GB to leave the entire 32-bit address
* space open for things that want to use the area for 32-bit pointers.
*/
#define ELF_ET_DYN_BASE (mmap_is_ia32() ? 0x000400000UL : \
(DEFAULT_MAP_WINDOW / 3 * 2))
0x100000000UL)

/* This yields a mask that user programs can use to figure out what
instruction set this CPU supports. This could be done in user space,
Expand Down Expand Up @@ -312,8 +312,8 @@ extern unsigned long get_mmap_base(int is_legacy);

#ifdef CONFIG_X86_32

#define __STACK_RND_MASK(is32bit) (0x7ff)
#define STACK_RND_MASK (0x7ff)
#define __STACK_RND_MASK(is32bit) ((1UL << mmap_rnd_bits) - 1)
#define STACK_RND_MASK ((1UL << mmap_rnd_bits) - 1)

#define ARCH_DLINFO ARCH_DLINFO_IA32

Expand All @@ -322,7 +322,11 @@ extern unsigned long get_mmap_base(int is_legacy);
#else /* CONFIG_X86_32 */

/* 1GB for 64bit, 8MB for 32bit */
#define __STACK_RND_MASK(is32bit) ((is32bit) ? 0x7ff : 0x3fffff)
#ifdef CONFIG_COMPAT
#define __STACK_RND_MASK(is32bit) ((is32bit) ? (1UL << mmap_rnd_compat_bits) - 1 : (1UL << mmap_rnd_bits) - 1)
#else
#define __STACK_RND_MASK(is32bit) ((1UL << mmap_rnd_bits) - 1)
#endif
#define STACK_RND_MASK __STACK_RND_MASK(mmap_is_ia32())

#define ARCH_DLINFO \
Expand Down Expand Up @@ -380,5 +384,4 @@ struct va_alignment {
} ____cacheline_aligned;

extern struct va_alignment va_align;
extern unsigned long align_vdso_addr(unsigned long);
#endif /* _ASM_X86_ELF_H */
4 changes: 4 additions & 0 deletions arch/x86/include/asm/tlbflush.h
Original file line number Diff line number Diff line change
Expand Up @@ -302,6 +302,7 @@ static inline void cr4_set_bits(unsigned long mask)
unsigned long cr4;

cr4 = this_cpu_read(cpu_tlbstate.cr4);
BUG_ON(cr4 != __read_cr4());
if ((cr4 | mask) != cr4) {
cr4 |= mask;
this_cpu_write(cpu_tlbstate.cr4, cr4);
Expand All @@ -315,6 +316,7 @@ static inline void cr4_clear_bits(unsigned long mask)
unsigned long cr4;

cr4 = this_cpu_read(cpu_tlbstate.cr4);
BUG_ON(cr4 != __read_cr4());
if ((cr4 & ~mask) != cr4) {
cr4 &= ~mask;
this_cpu_write(cpu_tlbstate.cr4, cr4);
Expand All @@ -327,6 +329,7 @@ static inline void cr4_toggle_bits(unsigned long mask)
unsigned long cr4;

cr4 = this_cpu_read(cpu_tlbstate.cr4);
BUG_ON(cr4 != __read_cr4());
cr4 ^= mask;
this_cpu_write(cpu_tlbstate.cr4, cr4);
__write_cr4(cr4);
Expand Down Expand Up @@ -435,6 +438,7 @@ static inline void __native_flush_tlb_global(void)
raw_local_irq_save(flags);

cr4 = this_cpu_read(cpu_tlbstate.cr4);
BUG_ON(cr4 != __read_cr4());
/* toggle PGE */
native_write_cr4(cr4 ^ X86_CR4_PGE);
/* write old PGE again and flush TLBs */
Expand Down
1 change: 0 additions & 1 deletion arch/x86/kernel/cpu/common.c
Original file line number Diff line number Diff line change
Expand Up @@ -1669,7 +1669,6 @@ void cpu_init(void)
wrmsrl(MSR_KERNEL_GS_BASE, 0);
barrier();

x86_configure_nx();
x2apic_setup();

/*
Expand Down
Loading