From patchwork Fri Jan 13 23:27:05 2023 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Kees Cook X-Patchwork-Id: 43650 Return-Path: Delivered-To: ouuuleilei@gmail.com Received: by 2002:adf:eb09:0:0:0:0:0 with SMTP id s9csp13326wrn; Fri, 13 Jan 2023 15:27:43 -0800 (PST) X-Google-Smtp-Source: AMrXdXvjusxvv4y83bI98cQvwf+6YFa/OvAzcTmxdZq3UldLf12ilSw9lWCqUF1flOO1qPqox/dw X-Received: by 2002:a17:90a:aa84:b0:227:1a22:d182 with SMTP id l4-20020a17090aaa8400b002271a22d182mr19544225pjq.42.1673652463088; Fri, 13 Jan 2023 15:27:43 -0800 (PST) ARC-Seal: i=1; a=rsa-sha256; t=1673652463; cv=none; d=google.com; s=arc-20160816; b=V9J3MVkZ6DRwULIpW68xWYUteN+hqQLmyD1uPC1E5OO0+0bq10A2oKGewXW3HRAwDv zhQIDS/JprP74zZ+g0teOzZet9U5pfE/pyIVKUoCxiTacMcaO1Xdm+rLXWaItg9yy+S3 8fBHhUF6R3x7S9th051QbhUjDVTUmsn6YlZ35zBd/eytU4yDYuScvXdPjaW5zE0a7lqC ubtAE+ksMpLJ0wzNTHE/FM0q//082BzvhKAYpDOky+W9c61yX3pTOfraQvPB1iVzQyQf zzS/g6q1z52Qi9lbXDJk2Auz02jvK3mHxzlmBtHUGRwHzHAukLkjneCkUFpLSAD4ot3r JXjw== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:content-disposition:mime-version:message-id :subject:cc:to:from:date:dkim-signature; bh=QeiJHvrswqLFEJEjzaUv7SNJ90rY7sOx4dR9LZd7H2E=; b=TW4DNq4XztYN70IW6w5fgLLDTALquwUo1fZA9oXYJbi+A9v6gILdm2AQ/e9a4wpArQ BsAauoVb8Y2cjqimm77nemarboBnInn8+TYdqP6KkH8YXVQZwLyyBFHJBsfK5t/qFiKF 2/y6s3GB890aGr3ce5RNUVcXeXb9UawdN37R6YP178wiFCDAHdKVFvzj+wJDkv26rI/4 egJ1OQSaS9526WVV6H69Q/6FlVOhOIFi8veXtjdDRS8fOKNcl0b8p7xvtfcYsBzH2/vm DjI+nKovhozdXavjunDt4/yhzDAzKgd7E/8OsjiJ4UBqVOwVCNAiL5l9Xhbltkf2fqOT BesA== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@chromium.org header.s=google header.b=DuqQQVG5; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=chromium.org Received: from out1.vger.email (out1.vger.email. [2620:137:e000::1:20]) by mx.google.com with ESMTP id pc3-20020a17090b3b8300b00212f7abe85csi3000231pjb.41.2023.01.13.15.27.29; Fri, 13 Jan 2023 15:27:43 -0800 (PST) Received-SPF: pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) client-ip=2620:137:e000::1:20; Authentication-Results: mx.google.com; dkim=pass header.i=@chromium.org header.s=google header.b=DuqQQVG5; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=chromium.org Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S231425AbjAMX1J (ORCPT + 99 others); Fri, 13 Jan 2023 18:27:09 -0500 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:38582 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S231184AbjAMX1H (ORCPT ); Fri, 13 Jan 2023 18:27:07 -0500 Received: from mail-pl1-x62c.google.com (mail-pl1-x62c.google.com [IPv6:2607:f8b0:4864:20::62c]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id 2B3E18A213 for ; Fri, 13 Jan 2023 15:27:07 -0800 (PST) Received: by mail-pl1-x62c.google.com with SMTP id p24so24913073plw.11 for ; Fri, 13 Jan 2023 15:27:07 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=chromium.org; s=google; h=content-disposition:mime-version:message-id:subject:cc:to:from:date :from:to:cc:subject:date:message-id:reply-to; bh=QeiJHvrswqLFEJEjzaUv7SNJ90rY7sOx4dR9LZd7H2E=; b=DuqQQVG5xVrKMgjEw0hjJ9MguBiRIpWq1NyyBjNbv2+ESrZQPti6WbySPmR4WRj/cg pR/DACzXpZET9vv+RCNgTa02tSyRReJqJl2vDrNc5GhJjcaQYdH6BhKrDinJm53Iuk7P MKB14bcVCKcNYXjForPiwJ1N8J3HioI9efTEs= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20210112; h=content-disposition:mime-version:message-id:subject:cc:to:from:date :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to; bh=QeiJHvrswqLFEJEjzaUv7SNJ90rY7sOx4dR9LZd7H2E=; b=YcdOcnO6Fy7gMurmrpEeWraV9G2OhjhAaG+MV9KakRurP55uOVgJKflQcN3rTIGYKB ldzLoxck0nX0frgX3ITifIKuavoi0iM6fx5aUtEJzjf2cP90Qk7t7mpwmvMpwVVZ6aoE RPXaezpGywPhV03HTjbntoAnDN5w6yvJI4bwLI5AdYir+O+8QGBV8QI1vLwdwe9syhiX VS3t1wG9yc1YdYRlO/LXkZfJCkSE/9gLHR5XMbrsoqnjgSoF4XwLeTw2l7WVmQdtjDNB hrRTaewIa3bo3c3tK9FXB9j//P2Fo8xk1NzH21JQqlg5L8nNsSHOijQt371qD7z6jdz4 3Dow== X-Gm-Message-State: AFqh2kqynjWQ0s9w3HAis1UAJBXrXt3gy/LZhWgXLS7Arpo3OyT/4FVo 1M30vRxrhfKETWn6ySODecYPlQ== X-Received: by 2002:a17:902:b085:b0:192:d5dc:c84b with SMTP id p5-20020a170902b08500b00192d5dcc84bmr38212483plr.50.1673652426625; Fri, 13 Jan 2023 15:27:06 -0800 (PST) Received: from www.outflux.net (smtp.outflux.net. [198.145.64.163]) by smtp.gmail.com with ESMTPSA id x3-20020a170902a38300b0018997f6fc88sm14682715pla.34.2023.01.13.15.27.05 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 13 Jan 2023 15:27:06 -0800 (PST) Date: Fri, 13 Jan 2023 15:27:05 -0800 From: Kees Cook To: Linus Torvalds Cc: linux-kernel@vger.kernel.org, Brian Norris , Greg Kroah-Hartman , Guenter Roeck , Jack Rosenthal , Julius Werner , Kees Cook , Paul Menzel , Peter Zijlstra , Sami Tolvanen , Stephen Boyd Subject: [GIT PULL] kernel hardening fixes for v6.2-rc4 Message-ID: <202301131526.28719A40@keescook> MIME-Version: 1.0 Content-Disposition: inline X-Spam-Status: No, score=-2.1 required=5.0 tests=BAYES_00,DKIMWL_WL_HIGH, DKIM_SIGNED,DKIM_VALID,DKIM_VALID_AU,DKIM_VALID_EF,RCVD_IN_DNSWL_NONE, SPF_HELO_NONE,SPF_PASS autolearn=ham autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on lindbergh.monkeyblade.net Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org X-getmail-retrieved-from-mailbox: =?utf-8?q?INBOX?= X-GMAIL-THRID: =?utf-8?q?1754951804965884961?= X-GMAIL-MSGID: =?utf-8?q?1754951804965884961?= Hi Linus, Please pull these two kernel hardening fixes for v6.2-rc4. Thanks! -Kees The following changes since commit 88603b6dc419445847923fcb7fe5080067a30f98: Linux 6.2-rc2 (2023-01-01 13:53:16 -0800) are available in the Git repository at: https://git.kernel.org/pub/scm/linux/kernel/git/kees/linux.git tags/hardening-v6.2-rc4 for you to fetch changes up to 42633ed852deadc14d44660ad71e2f6640239120: kbuild: Fix CFI hash randomization with KASAN (2023-01-13 15:22:03 -0800) ---------------------------------------------------------------- kernel hardening fixes for v6.2-rc4 - Fix CFI hash randomization with KASAN (Sami Tolvanen) - Check size of coreboot table entry and use flex-array ---------------------------------------------------------------- Kees Cook (1): firmware: coreboot: Check size of table entry and use flex-array Sami Tolvanen (1): kbuild: Fix CFI hash randomization with KASAN drivers/firmware/google/coreboot_table.c | 9 +++++++-- drivers/firmware/google/coreboot_table.h | 1 + init/Makefile | 1 + scripts/Makefile.vmlinux | 1 + 4 files changed, 10 insertions(+), 2 deletions(-)