[RFC v3 3/5] SPSLR build integration
York Jasper Niebuhr <[email protected]> Mon, 20 Jul 2026 21:13:11 +0200
| Newsgroups | org.kernel.vger.linux-hardening,org.kernel.vger.linux-kernel |
|---|---|
| Message-ID | <[email protected]> |
Signed-off-by: York Jasper Niebuhr <[email protected]> --- arch/x86/boot/startup/Makefile | 4 ++++ arch/x86/entry/vdso/common/Makefile.include | 2 +- arch/x86/kernel/vmlinux.lds.S | 23 +++++++++++++++++++ init/Kconfig | 13 +++++++++++ scripts/module.lds.S | 25 +++++++++++++++++++++ 5 files changed, 66 insertions(+), 1 deletion(-) diff --git a/arch/x86/boot/startup/Makefile b/arch/x86/boot/startup/Makefile index 5e499cfb29b5..1fa601781546 100644 --- a/arch/x86/boot/startup/Makefile +++ b/arch/x86/boot/startup/Makefile @@ -12,6 +12,10 @@ KBUILD_CFLAGS += -D__DISABLE_EXPORTS -mcmodel=small -fPIC \ # disable ftrace hooks and LTO KBUILD_CFLAGS := $(subst $(CC_FLAGS_FTRACE),,$(KBUILD_CFLAGS)) KBUILD_CFLAGS := $(filter-out $(CC_FLAGS_LTO),$(KBUILD_CFLAGS)) + +# Startup code executes before Bootpatch-SLR applies its runtime patches. +KBUILD_CFLAGS := $(filter-out $(PINPOINT_PLUGIN_CFLAGS),$(KBUILD_CFLAGS)) + KASAN_SANITIZE := n KCSAN_SANITIZE := n KMSAN_SANITIZE := n diff --git a/arch/x86/entry/vdso/common/Makefile.include b/arch/x86/entry/vdso/common/Makefile.include index 687b3d89b40d..d8cc53cd9560 100644 --- a/arch/x86/entry/vdso/common/Makefile.include +++ b/arch/x86/entry/vdso/common/Makefile.include @@ -27,7 +27,7 @@ flags-remove-y += \ -mfentry -pg \ $(RANDSTRUCT_CFLAGS) $(GCC_PLUGINS_CFLAGS) $(KSTACK_ERASE_CFLAGS) \ $(RETPOLINE_CFLAGS) $(CC_FLAGS_LTO) $(CC_FLAGS_CFI) \ - $(PADDING_CFLAGS) + $(PADDING_CFLAGS) $(PINPOINT_PLUGIN_CFLAGS) # # Don't omit frame pointers for ease of userspace debugging, but do diff --git a/arch/x86/kernel/vmlinux.lds.S b/arch/x86/kernel/vmlinux.lds.S index 74e336d7f9dd..aa71c2c2a756 100644 --- a/arch/x86/kernel/vmlinux.lds.S +++ b/arch/x86/kernel/vmlinux.lds.S @@ -200,6 +200,29 @@ SECTIONS /* rarely changed data like cpu maps */ READ_MOSTLY_DATA(INTERNODE_CACHE_BYTES) +#ifdef CONFIG_SPSLR + __spslr_start = .; + + . = ALIGN(8); + __start_spslr_units = .; + KEEP(*(spslr_units)) + __stop_spslr_units = .; + + . = ALIGN(8); + __start_spslr_targets = .; + KEEP(*(spslr_targets)) + __stop_spslr_targets = .; + + . = ALIGN(8); + KEEP(*(spslr_target_layouts)) + KEEP(*(spslr_cu_target_refs)) + KEEP(*(spslr_ipins)) + KEEP(*(spslr_dpins)) + KEEP(*(spslr_strtab)) + + __spslr_end = .; +#endif + /* End of data section */ _edata = .; } :data diff --git a/init/Kconfig b/init/Kconfig index 5230d4879b1c..2110aff8a5c8 100644 --- a/init/Kconfig +++ b/init/Kconfig @@ -2316,3 +2316,16 @@ config ARCH_HAS_SYNC_CORE_BEFORE_USERMODE # <asm/syscall_wrapper.h>. config ARCH_HAS_SYSCALL_WRAPPER def_bool n + +config SPSLR + bool "Selfpatch SLR prototype" + depends on X86_64 + depends on CC_IS_GCC + help + Experimental structure layout randomization prototype. + +config SANEMAKER + bool "Selfpatch SLR validation tooling" + depends on SPSLR + help + Experimental validation tooling for Selfpatch-SLR. diff --git a/scripts/module.lds.S b/scripts/module.lds.S index b62683061d79..e366be317115 100644 --- a/scripts/module.lds.S +++ b/scripts/module.lds.S @@ -62,6 +62,31 @@ SECTIONS { } MOD_SEPARATE_CODETAG_SECTIONS() + +#ifdef CONFIG_SPSLR + .spslr : ALIGN(8) { + __spslr_start = .; + + . = ALIGN(8); + __start_spslr_units = .; + KEEP(*(spslr_units)) + __stop_spslr_units = .; + + . = ALIGN(8); + __start_spslr_targets = .; + KEEP(*(spslr_targets)) + __stop_spslr_targets = .; + + . = ALIGN(8); + KEEP(*(spslr_target_layouts)) + KEEP(*(spslr_cu_target_refs)) + KEEP(*(spslr_ipins)) + KEEP(*(spslr_dpins)) + KEEP(*(spslr_strtab)) + + __spslr_end = .; + } +#endif } /* bring in arch-specific sections */ -- 2.43.0