• Philip Derrin's avatar
    ARM: 8721/1: mm: dump: check hardware RO bit for LPAE · 3b0c0c92
    Philip Derrin authored
    When CONFIG_ARM_LPAE is set, the PMD dump relies on the software
    read-only bit to determine whether a page is writable. This
    concealed a bug which left the kernel text section writable
    (AP2=0) while marked read-only in the software bit.
    
    In a kernel with the AP2 bug, the dump looks like this:
    
        ---[ Kernel Mapping ]---
        0xc0000000-0xc0200000           2M RW NX SHD
        0xc0200000-0xc0600000           4M ro x  SHD
        0xc0600000-0xc0800000           2M ro NX SHD
        0xc0800000-0xc4800000          64M RW NX SHD
    
    The fix is to check that the software and hardware bits are both
    set before displaying "ro". The dump then shows the true perms:
    
        ---[ Kernel Mapping ]---
        0xc0000000-0xc0200000           2M RW NX SHD
        0xc0200000-0xc0600000           4M RW x  SHD
        0xc0600000-0xc0800000           2M RW NX SHD
        0xc0800000-0xc4800000          64M RW NX SHD
    
    Fixes: ded94779 ("ARM: 8109/1: mm: Modify pte_write and pmd_write logic for LPAE")
    Signed-off-by: default avatarPhilip Derrin <philip@cog.systems>
    Tested-by: default avatarNeil Dick <neil@cog.systems>
    Reviewed-by: default avatarKees Cook <keescook@chromium.org>
    Cc: stable@vger.kernel.org
    Signed-off-by: default avatarRussell King <rmk+kernel@armlinux.org.uk>
    3b0c0c92
dump.c 8.62 KB