2019-08-14 07:04:50 +08:00
|
|
|
/* SPDX-License-Identifier: GPL-2.0-only */
|
|
|
|
/*
|
|
|
|
* Linker script variables to be set after section resolution, as
|
|
|
|
* ld.lld does not like variables assigned before SECTIONS is processed.
|
|
|
|
*/
|
|
|
|
#ifndef __ARM64_KERNEL_IMAGE_VARS_H
|
|
|
|
#define __ARM64_KERNEL_IMAGE_VARS_H
|
|
|
|
|
|
|
|
#ifndef LINKER_SCRIPT
|
|
|
|
#error This file should only be included in vmlinux.lds.S
|
|
|
|
#endif
|
|
|
|
|
2022-06-29 16:32:46 +08:00
|
|
|
PROVIDE(__efistub_kernel_size = _edata - _text);
|
|
|
|
PROVIDE(__efistub_primary_entry_offset = primary_entry - _text);
|
2019-08-14 07:04:50 +08:00
|
|
|
|
|
|
|
/*
|
|
|
|
* The EFI stub has its own symbol namespace prefixed by __efistub_, to
|
|
|
|
* isolate it from the kernel proper. The following symbols are legally
|
|
|
|
* accessed by the stub, so provide some aliases to make them accessible.
|
|
|
|
* Only include data symbols here, or text symbols of functions that are
|
|
|
|
* guaranteed to be safe when executed at another offset than they were
|
|
|
|
* linked at. The routines below are all implemented in assembler in a
|
|
|
|
* position independent manner
|
|
|
|
*/
|
2022-06-29 16:32:46 +08:00
|
|
|
PROVIDE(__efistub_memcmp = __pi_memcmp);
|
|
|
|
PROVIDE(__efistub_memchr = __pi_memchr);
|
|
|
|
PROVIDE(__efistub_strlen = __pi_strlen);
|
|
|
|
PROVIDE(__efistub_strnlen = __pi_strnlen);
|
|
|
|
PROVIDE(__efistub_strcmp = __pi_strcmp);
|
|
|
|
PROVIDE(__efistub_strncmp = __pi_strncmp);
|
|
|
|
PROVIDE(__efistub_strrchr = __pi_strrchr);
|
|
|
|
PROVIDE(__efistub_dcache_clean_poc = __pi_dcache_clean_poc);
|
2019-08-14 07:04:50 +08:00
|
|
|
|
2022-06-29 16:32:46 +08:00
|
|
|
PROVIDE(__efistub__text = _text);
|
|
|
|
PROVIDE(__efistub__end = _end);
|
|
|
|
PROVIDE(__efistub__edata = _edata);
|
|
|
|
PROVIDE(__efistub_screen_info = screen_info);
|
|
|
|
PROVIDE(__efistub__ctype = _ctype);
|
2019-08-14 07:04:50 +08:00
|
|
|
|
2022-06-29 16:32:46 +08:00
|
|
|
PROVIDE(__pi___memcpy = __pi_memcpy);
|
|
|
|
PROVIDE(__pi___memmove = __pi_memmove);
|
|
|
|
PROVIDE(__pi___memset = __pi_memset);
|
2019-08-14 07:04:50 +08:00
|
|
|
|
2020-06-25 21:14:08 +08:00
|
|
|
#ifdef CONFIG_KVM
|
|
|
|
|
|
|
|
/*
|
|
|
|
* KVM nVHE code has its own symbol namespace prefixed with __kvm_nvhe_, to
|
|
|
|
* separate it from the kernel proper. The following symbols are legally
|
|
|
|
* accessed by it, therefore provide aliases to make them linkable.
|
|
|
|
* Do not include symbols which may not be safely accessed under hypervisor
|
|
|
|
* memory mappings.
|
|
|
|
*/
|
|
|
|
|
2020-06-25 21:14:11 +08:00
|
|
|
/* Alternative callbacks for init-time patching of nVHE hyp code. */
|
|
|
|
KVM_NVHE_ALIAS(kvm_patch_vector_branch);
|
|
|
|
KVM_NVHE_ALIAS(kvm_update_va_mask);
|
2020-10-24 23:33:38 +08:00
|
|
|
KVM_NVHE_ALIAS(kvm_get_kimage_voffset);
|
2021-03-22 20:09:51 +08:00
|
|
|
KVM_NVHE_ALIAS(kvm_compute_final_ctr_el0);
|
arm64: Mitigate spectre style branch history side channels
Speculation attacks against some high-performance processors can
make use of branch history to influence future speculation.
When taking an exception from user-space, a sequence of branches
or a firmware call overwrites or invalidates the branch history.
The sequence of branches is added to the vectors, and should appear
before the first indirect branch. For systems using KPTI the sequence
is added to the kpti trampoline where it has a free register as the exit
from the trampoline is via a 'ret'. For systems not using KPTI, the same
register tricks are used to free up a register in the vectors.
For the firmware call, arch-workaround-3 clobbers 4 registers, so
there is no choice but to save them to the EL1 stack. This only happens
for entry from EL0, so if we take an exception due to the stack access,
it will not become re-entrant.
For KVM, the existing branch-predictor-hardening vectors are used.
When a spectre version of these vectors is in use, the firmware call
is sufficient to mitigate against Spectre-BHB. For the non-spectre
versions, the sequence of branches is added to the indirect vector.
Reviewed-by: Catalin Marinas <catalin.marinas@arm.com>
Signed-off-by: James Morse <james.morse@arm.com>
2021-11-10 22:48:00 +08:00
|
|
|
KVM_NVHE_ALIAS(spectre_bhb_patch_loop_iter);
|
|
|
|
KVM_NVHE_ALIAS(spectre_bhb_patch_loop_mitigation_enable);
|
|
|
|
KVM_NVHE_ALIAS(spectre_bhb_patch_wa3);
|
2021-12-10 22:32:56 +08:00
|
|
|
KVM_NVHE_ALIAS(spectre_bhb_patch_clearbhb);
|
arm64: alternatives: add shared NOP callback
For each instance of an alternative, the compiler outputs a distinct
copy of the alternative instructions into a subsection. As the compiler
doesn't have special knowledge of alternatives, it cannot coalesce these
to save space.
In a defconfig kernel built with GCC 12.1.0, there are approximately
10,000 instances of alternative_has_feature_likely(), where the
replacement instruction is always a NOP. As NOPs are
position-independent, we don't need a unique copy per alternative
sequence.
This patch adds a callback to patch an alternative sequence with NOPs,
and make use of this in alternative_has_feature_likely(). So that this
can be used for other sites in future, this is written to patch multiple
instructions up to the original sequence length.
For NVHE, an alias is added to image-vars.h.
For modules, the callback is exported. Note that as modules are loaded
within 2GiB of the kernel, an alt_instr entry in a module can always
refer directly to the callback, and no special handling is necessary.
When building with GCC 12.1.0, the vmlinux is ~158KiB smaller, though
the resulting Image size is unchanged due to alignment constraints and
padding:
| % ls -al vmlinux-*
| -rwxr-xr-x 1 mark mark 134644592 Sep 1 14:52 vmlinux-after
| -rwxr-xr-x 1 mark mark 134486232 Sep 1 14:50 vmlinux-before
| % ls -al Image-*
| -rw-r--r-- 1 mark mark 37108224 Sep 1 14:52 Image-after
| -rw-r--r-- 1 mark mark 37108224 Sep 1 14:50 Image-before
Signed-off-by: Mark Rutland <mark.rutland@arm.com>
Cc: Ard Biesheuvel <ardb@kernel.org>
Cc: James Morse <james.morse@arm.com>
Cc: Joey Gouly <joey.gouly@arm.com>
Cc: Marc Zyngier <maz@kernel.org>
Cc: Will Deacon <will@kernel.org>
Reviewed-by: Ard Biesheuvel <ardb@kernel.org>
Link: https://lore.kernel.org/r/20220912162210.3626215-9-mark.rutland@arm.com
Signed-off-by: Catalin Marinas <catalin.marinas@arm.com>
2022-09-13 00:22:10 +08:00
|
|
|
KVM_NVHE_ALIAS(alt_cb_patch_nops);
|
2020-06-25 21:14:11 +08:00
|
|
|
|
|
|
|
/* Global kernel state accessed by nVHE hyp code. */
|
2020-06-25 21:14:14 +08:00
|
|
|
KVM_NVHE_ALIAS(kvm_vgic_global_state);
|
2020-06-25 21:14:11 +08:00
|
|
|
|
|
|
|
/* Kernel symbols used to call panic() from nVHE hyp code (via ERET). */
|
2021-03-18 22:33:11 +08:00
|
|
|
KVM_NVHE_ALIAS(nvhe_hyp_panic_handler);
|
2020-06-25 21:14:11 +08:00
|
|
|
|
2020-06-25 21:14:12 +08:00
|
|
|
/* Vectors installed by hyp-init on reset HVC. */
|
|
|
|
KVM_NVHE_ALIAS(__hyp_stub_vectors);
|
|
|
|
|
2020-06-25 21:14:13 +08:00
|
|
|
/* Kernel symbol used by icache_is_vpipt(). */
|
|
|
|
KVM_NVHE_ALIAS(__icache_flags);
|
|
|
|
|
2021-11-22 20:18:42 +08:00
|
|
|
/* VMID bits set by the KVM VMID allocator */
|
|
|
|
KVM_NVHE_ALIAS(kvm_arm_vmid_bits);
|
|
|
|
|
2020-06-25 21:14:14 +08:00
|
|
|
/* Static keys which are set if a vGIC trap should be handled in hyp. */
|
|
|
|
KVM_NVHE_ALIAS(vgic_v2_cpuif_trap);
|
|
|
|
KVM_NVHE_ALIAS(vgic_v3_cpuif_trap);
|
|
|
|
|
|
|
|
/* Static key checked in pmr_sync(). */
|
|
|
|
#ifdef CONFIG_ARM64_PSEUDO_NMI
|
|
|
|
KVM_NVHE_ALIAS(gic_pmr_sync);
|
2020-09-12 23:37:07 +08:00
|
|
|
/* Static key checked in GIC_PRIO_IRQOFF. */
|
|
|
|
KVM_NVHE_ALIAS(gic_nonsecure_priorities);
|
2020-06-25 21:14:14 +08:00
|
|
|
#endif
|
|
|
|
|
2020-08-21 22:07:05 +08:00
|
|
|
/* EL2 exception handling */
|
|
|
|
KVM_NVHE_ALIAS(__start___kvm_ex_table);
|
|
|
|
KVM_NVHE_ALIAS(__stop___kvm_ex_table);
|
|
|
|
|
2020-12-03 02:41:09 +08:00
|
|
|
/* Array containing bases of nVHE per-CPU memory regions. */
|
|
|
|
KVM_NVHE_ALIAS(kvm_arm_hyp_percpu_base);
|
|
|
|
|
2021-03-06 02:52:51 +08:00
|
|
|
/* PMU available static key */
|
2021-11-11 10:07:36 +08:00
|
|
|
#ifdef CONFIG_HW_PERF_EVENTS
|
2021-03-06 02:52:51 +08:00
|
|
|
KVM_NVHE_ALIAS(kvm_arm_pmu_available);
|
2021-11-11 10:07:36 +08:00
|
|
|
#endif
|
2021-03-06 02:52:51 +08:00
|
|
|
|
2021-03-19 18:01:10 +08:00
|
|
|
/* Position-independent library routines */
|
|
|
|
KVM_NVHE_ALIAS_HYP(clear_page, __pi_clear_page);
|
|
|
|
KVM_NVHE_ALIAS_HYP(copy_page, __pi_copy_page);
|
|
|
|
KVM_NVHE_ALIAS_HYP(memcpy, __pi_memcpy);
|
|
|
|
KVM_NVHE_ALIAS_HYP(memset, __pi_memset);
|
|
|
|
|
|
|
|
#ifdef CONFIG_KASAN
|
|
|
|
KVM_NVHE_ALIAS_HYP(__memcpy, __pi_memcpy);
|
|
|
|
KVM_NVHE_ALIAS_HYP(__memset, __pi_memset);
|
|
|
|
#endif
|
|
|
|
|
KVM: arm64: Prepare the creation of s1 mappings at EL2
When memory protection is enabled, the EL2 code needs the ability to
create and manage its own page-table. To do so, introduce a new set of
hypercalls to bootstrap a memory management system at EL2.
This leads to the following boot flow in nVHE Protected mode:
1. the host allocates memory for the hypervisor very early on, using
the memblock API;
2. the host creates a set of stage 1 page-table for EL2, installs the
EL2 vectors, and issues the __pkvm_init hypercall;
3. during __pkvm_init, the hypervisor re-creates its stage 1 page-table
and stores it in the memory pool provided by the host;
4. the hypervisor then extends its stage 1 mappings to include a
vmemmap in the EL2 VA space, hence allowing to use the buddy
allocator introduced in a previous patch;
5. the hypervisor jumps back in the idmap page, switches from the
host-provided page-table to the new one, and wraps up its
initialization by enabling the new allocator, before returning to
the host.
6. the host can free the now unused page-table created for EL2, and
will now need to issue hypercalls to make changes to the EL2 stage 1
mappings instead of modifying them directly.
Note that for the sake of simplifying the review, this patch focuses on
the hypervisor side of things. In other words, this only implements the
new hypercalls, but does not make use of them from the host yet. The
host-side changes will follow in a subsequent patch.
Credits to Will for __pkvm_init_switch_pgd.
Acked-by: Will Deacon <will@kernel.org>
Co-authored-by: Will Deacon <will@kernel.org>
Signed-off-by: Will Deacon <will@kernel.org>
Signed-off-by: Quentin Perret <qperret@google.com>
Signed-off-by: Marc Zyngier <maz@kernel.org>
Link: https://lore.kernel.org/r/20210319100146.1149909-18-qperret@google.com
2021-03-19 18:01:25 +08:00
|
|
|
/* Kernel memory sections */
|
|
|
|
KVM_NVHE_ALIAS(__start_rodata);
|
|
|
|
KVM_NVHE_ALIAS(__end_rodata);
|
|
|
|
KVM_NVHE_ALIAS(__bss_start);
|
|
|
|
KVM_NVHE_ALIAS(__bss_stop);
|
|
|
|
|
|
|
|
/* Hyp memory sections */
|
|
|
|
KVM_NVHE_ALIAS(__hyp_idmap_text_start);
|
|
|
|
KVM_NVHE_ALIAS(__hyp_idmap_text_end);
|
|
|
|
KVM_NVHE_ALIAS(__hyp_text_start);
|
|
|
|
KVM_NVHE_ALIAS(__hyp_text_end);
|
|
|
|
KVM_NVHE_ALIAS(__hyp_bss_start);
|
|
|
|
KVM_NVHE_ALIAS(__hyp_bss_end);
|
|
|
|
KVM_NVHE_ALIAS(__hyp_rodata_start);
|
|
|
|
KVM_NVHE_ALIAS(__hyp_rodata_end);
|
|
|
|
|
2021-03-19 18:01:43 +08:00
|
|
|
/* pKVM static key */
|
|
|
|
KVM_NVHE_ALIAS(kvm_protected_mode_initialized);
|
|
|
|
|
2020-06-25 21:14:08 +08:00
|
|
|
#endif /* CONFIG_KVM */
|
|
|
|
|
2019-08-14 07:04:50 +08:00
|
|
|
#endif /* __ARM64_KERNEL_IMAGE_VARS_H */
|