Re: [PATCH v2 1/2] efi/loongarch: Randomize kernel preferred address for KASLR

WANG Rui <[email protected]>
Newsgroups org.kernel.vger.linux-efi,dev.linux.lists.loongarch,org.kernel.vger.linux-kernel
Message-ID <CAHirt9hvsGLsDEo3qdWtC5BqiJsrCSv8UJYTZfqte8op7c8etw@mail.gmail.com>
Hi Huacai,

On Tue, Apr 28, 2026 at 1:01 PM Huacai Chen <[email protected]> wrote:
>
> Hi, Rui,
>
> On Tue, Apr 28, 2026 at 12:02 PM WANG Rui <[email protected]> wrote:
> >
> > Introduce efi_get_kimg_kaslr_address() to compute the preferred
> > kernel image address dynamically when CONFIG_RANDOMIZE_BASE is
> > enabled. The function derives a random offset using EFI-provided
> > randomness combined with the timer value, and constrains it within
> > CONFIG_RANDOMIZE_BASE_MAX_OFFSET.
> >
> > Update EFI_KIMG_PREFERRED_ADDRESS to call this helper so that the
> > EFI stub can select a randomized load address when KASLR is active,
> > while preserving the original base address behavior when KASLR is
> > disabled or nokaslr is specified.
> >
> > Signed-off-by: WANG Rui <[email protected]>
> > ---
> >  arch/loongarch/Kconfig                   |  2 +-
> >  arch/loongarch/include/asm/efi.h         |  4 +++-
> >  drivers/firmware/efi/libstub/loongarch.c | 16 ++++++++++++++++
> >  3 files changed, 20 insertions(+), 2 deletions(-)
> >
> > diff --git a/arch/loongarch/Kconfig b/arch/loongarch/Kconfig
> > index 3b042dbb2c41..a5afb70f73d9 100644
> > --- a/arch/loongarch/Kconfig
> > +++ b/arch/loongarch/Kconfig
> > @@ -730,7 +730,7 @@ config RANDOMIZE_BASE
> >  config RANDOMIZE_BASE_MAX_OFFSET
> >         hex "Maximum KASLR offset" if EXPERT
> >         depends on RANDOMIZE_BASE
> > -       range 0x0 0x10000000
> > +       range 0x20000 0x10000000
> >         default "0x01000000"
> >         help
> >           When KASLR is active, this provides the maximum offset that will
> > diff --git a/arch/loongarch/include/asm/efi.h b/arch/loongarch/include/asm/efi.h
> > index eddc8e79b3fa..f831320efd41 100644
> > --- a/arch/loongarch/include/asm/efi.h
> > +++ b/arch/loongarch/include/asm/efi.h
> > @@ -30,6 +30,8 @@ static inline unsigned long efi_get_kimg_min_align(void)
> >         return SZ_2M;
> >  }
> >
> > -#define EFI_KIMG_PREFERRED_ADDRESS     PHYSADDR(VMLINUX_LOAD_ADDRESS)
> > +unsigned long efi_get_kimg_kaslr_address(void);
> > +
> > +#define EFI_KIMG_PREFERRED_ADDRESS     efi_get_kimg_kaslr_address()
> >
> >  #endif /* _ASM_LOONGARCH_EFI_H */
> > diff --git a/drivers/firmware/efi/libstub/loongarch.c b/drivers/firmware/efi/libstub/loongarch.c
> > index 9825f5218137..c44be5d3dc04 100644
> > --- a/drivers/firmware/efi/libstub/loongarch.c
> > +++ b/drivers/firmware/efi/libstub/loongarch.c
> > @@ -38,6 +38,22 @@ static efi_status_t exit_boot_func(struct efi_boot_memmap *map, void *priv)
> >         return EFI_SUCCESS;
> >  }
> >
> > +unsigned long efi_get_kimg_kaslr_address(void)
> Move it into arch/loongarch/include/asm/efi.h?

In that case, we'd need to declare efi_nokaslr and
efi_get_random_bytes() in efi.h. Since including efistub.h in efi.h
doesn't work, putting them here keeps things pretty clean.

Thanks,
Rui

>
> > +{
> > +       unsigned int random_offset = 0;
> > +
> > +#ifdef CONFIG_RANDOMIZE_BASE
> > +       if (!efi_nokaslr) {
> > +               efi_get_random_bytes(sizeof(random_offset), (u8 *)&random_offset);
> > +               random_offset ^= (random_get_entropy() << 16);
> > +               random_offset &= (CONFIG_RANDOMIZE_BASE_MAX_OFFSET - SZ_64K - 1);
> I still don't want to modify the range of RANDOMIZE_BASE_MAX_OFFSET, so use
>      random_offset &= (CONFIG_RANDOMIZE_BASE_MAX_OFFSET - 1)
> here?
>
> > +               random_offset = ALIGN(random_offset, SZ_64K) + SZ_64K;
> It seems "random_offset = ALIGN(random_offset + SZ64K, SZ_64K)" is better.
>
> Huacai
>
> > +       }
> > +#endif
> > +
> > +       return PHYSADDR(VMLINUX_LOAD_ADDRESS) + random_offset;
> > +}
> > +
> >  unsigned long __weak kernel_entry_address(unsigned long kernel_addr,
> >                 efi_loaded_image_t *image)
> >  {
> > --
> > 2.54.0
> >
>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.