[PATCH 2/2] ARM: mm: keep rodata non-executable
Kees Cook
keescook at chromium.org
Tue Apr 1 15:34:02 PDT 2014
On Mon, Mar 24, 2014 at 3:47 AM, Jon Medhurst (Tixy) <tixy at linaro.org> wrote:
> On Sun, 2014-03-23 at 16:21 -0600, Kees Cook wrote:
>> For this stage, how about I make this "depends on KEXEC=n &&
>> KPROBES=n"?
>
> There's also ftrace (CONFIG_DYNAMIC_FTRACE I believe) which modifies
> kernel code with a call to probe_kernel_write(), which GDB uses as well.
>
> And grepping for the patch_text() function also shows
> __arch_jump_label_transform() modifies kernel code. Not sure how and
> when that gets used.
Right, so, I'm trying to fix ftrace now, and I've hit a wall. It is as
if changes to the kernel text PMD aren't being noticed after the
kernel is running. Does anyone know why this might be happening?
Code and details here:
https://lkml.org/lkml/2014/4/1/674
-Kees
--
Kees Cook
Chrome OS Security
More information about the linux-arm-kernel
mailing list