lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Date: Mon, 22 Jun 2020 16:30:18 -0700 From: Kees Cook <keescook@...omium.org> To: Fāng-ruì Sòng <maskray@...gle.com> Cc: Borislav Petkov <bp@...e.de>, Thomas Gleixner <tglx@...utronix.de>, Ingo Molnar <mingo@...hat.com>, X86 ML <x86@...nel.org>, Arnd Bergmann <arnd@...db.de>, Nick Desaulniers <ndesaulniers@...gle.com>, Nathan Chancellor <natechancellor@...il.com>, clang-built-linux <clang-built-linux@...glegroups.com>, linux-arch@...r.kernel.org, LKML <linux-kernel@...r.kernel.org> Subject: Re: [PATCH v2 1/3] vmlinux.lds.h: Add .gnu.version* to DISCARDS On Mon, Jun 22, 2020 at 04:04:40PM -0700, Fāng-ruì Sòng wrote: > On Mon, Jun 22, 2020 at 3:57 PM Kees Cook <keescook@...omium.org> wrote: > > > > On Mon, Jun 22, 2020 at 03:52:37PM -0700, Fangrui Song wrote: > > > > And it's not in the output: > > > > > > > > $ readelf -Vs arch/x86/boot/compressed/vmlinux | grep version > > > > No version information found in this file. > > > > > > > > So... for the kernel we need to silence it right now. > > > > > > Re-link with -M (or -Map file) to check where .gnu.version{,_d,_r} input > > > sections come from? > > > > It's not reporting it correctly: > > > > .gnu.version_d 0x00000000008966b0 0x0 > > .gnu.version_d > > 0x00000000008966b0 0x0 arch/x86/boot/compressed/kernel_info.o > > > > .gnu.version 0x00000000008966b0 0x0 > > .gnu.version 0x00000000008966b0 0x0 arch/x86/boot/compressed/kernel_info.o > > > > .gnu.version_r 0x00000000008966b0 0x0 > > .gnu.version_r > > 0x00000000008966b0 0x0 arch/x86/boot/compressed/kernel_info.o > > > > it just reports whatever file is listed on the link command line first. > > > > > If it is a bug, we should probably figure out which version of binutils > > > has fixed the bug. > > > > I see this with binutils 2.34... > > > > -- > > Kees Cook > > :( It deserves a binutils bug > (https://sourceware.org/bugzilla/enter_bug.cgi?product=binutils ) and > a comment.. https://sourceware.org/bugzilla/show_bug.cgi?id=26153 > With the description adjusted to say that this works around a bug > > Reviewed-by: Fangrui Song <maskray@...gle.com> Adjusted, and thanks! -- Kees Cook
Powered by blists - more mailing lists