Skip to content

Commit

Permalink
---
Browse files Browse the repository at this point in the history
yaml
---
r: 173050
b: refs/heads/master
c: 4b0f3b8
h: refs/heads/master
v: v3
  • Loading branch information
Kees Cook authored and H. Peter Anvin committed Nov 16, 2009
1 parent 7f55236 commit 20cfead
Show file tree
Hide file tree
Showing 5 changed files with 30 additions and 10 deletions.
2 changes: 1 addition & 1 deletion [refs]
Original file line number Diff line number Diff line change
@@ -1,2 +1,2 @@
---
refs/heads/master: 4763ed4d45522b876c97e1f7f4b659d211f75571
refs/heads/master: 4b0f3b81eb33ef18283aa71440cccfede1753ae0
1 change: 1 addition & 0 deletions trunk/arch/x86/include/asm/proto.h
Original file line number Diff line number Diff line change
Expand Up @@ -17,6 +17,7 @@ extern void ia32_sysenter_target(void);
extern void syscall32_cpu_init(void);

extern void x86_configure_nx(void);
extern void x86_report_nx(void);

extern int reboot_force;

Expand Down
11 changes: 6 additions & 5 deletions trunk/arch/x86/kernel/setup.c
Original file line number Diff line number Diff line change
Expand Up @@ -788,16 +788,17 @@ void __init setup_arch(char **cmdline_p)
*cmdline_p = command_line;

/*
* Must call this twice: Once just to detect whether hardware doesn't
* support NX (so that the early EHCI debug console setup can safely
* call set_fixmap(), and then again after parsing early parameters to
* honor the respective command line option.
* x86_configure_nx() is called before parse_early_param() to detect
* whether hardware doesn't support NX (so that the early EHCI debug
* console setup can safely call set_fixmap()). It may then be called
* again from within noexec_setup() during parsing early parameters
* to honor the respective command line option.
*/
x86_configure_nx();

parse_early_param();

x86_configure_nx();
x86_report_nx();

/* Must be before kernel pagetables are setup */
vmi_activate();
Expand Down
4 changes: 0 additions & 4 deletions trunk/arch/x86/mm/init.c
Original file line number Diff line number Diff line change
Expand Up @@ -146,10 +146,6 @@ unsigned long __init_refok init_memory_mapping(unsigned long start,
use_gbpages = direct_gbpages;
#endif

/* XXX: replace this with Kees' improved messages */
if (__supported_pte_mask & _PAGE_NX)
printk(KERN_INFO "NX (Execute Disable) protection: active\n");

/* Enable PSE if available */
if (cpu_has_pse)
set_in_cr4(X86_CR4_PSE);
Expand Down
22 changes: 22 additions & 0 deletions trunk/arch/x86/mm/setup_nx.c
Original file line number Diff line number Diff line change
Expand Up @@ -36,3 +36,25 @@ void __cpuinit x86_configure_nx(void)
else
__supported_pte_mask &= ~_PAGE_NX;
}

void __init x86_report_nx(void)
{
if (!cpu_has_nx) {
printk(KERN_NOTICE "Notice: NX (Execute Disable) protection "
"missing in CPU or disabled in BIOS!\n");
} else {
#if defined(CONFIG_X86_64) || defined(CONFIG_X86_PAE)
if (disable_nx) {
printk(KERN_INFO "NX (Execute Disable) protection: "
"disabled by kernel command line option\n");
} else {
printk(KERN_INFO "NX (Execute Disable) protection: "
"active\n");
}
#else
/* 32bit non-PAE kernel, NX cannot be used */
printk(KERN_NOTICE "Notice: NX (Execute Disable) protection "
"cannot be enabled: non-PAE kernel!\n");
#endif
}
}

0 comments on commit 20cfead

Please sign in to comment.