Re: [PATCH 22/22] lkdtm: Obfuscate do_nothing() pointer
From: Kees Cook
Date: Tue Mar 25 2025 - 15:39:14 EST
On Mon, Mar 24, 2025 at 02:56:12PM -0700, Josh Poimboeuf wrote:
> If execute_location()'s memcpy of do_nothing() gets inlined and unrolled
> by the compiler, it copies one word at a time:
>
> mov 0x0(%rip),%rax R_X86_64_PC32 .text+0x1374
> mov %rax,0x38(%rbx)
> mov 0x0(%rip),%rax R_X86_64_PC32 .text+0x136c
> mov %rax,0x30(%rbx)
> ...
>
> Those .text references point to the middle of the function, causing
> objtool to complain about their lack of ENDBR.
>
> Prevent that by resolving the function pointer at runtime rather than
> build time. This fixes the following warning:
>
> drivers/misc/lkdtm/lkdtm.o: warning: objtool: execute_location+0x23: relocation to !ENDBR: .text+0x1378
>
> Cc: Kees Cook <kees@xxxxxxxxxx>
> Reported-by: kernel test robot <lkp@xxxxxxxxx>
> Closes: https://lore.kernel.org/oe-kbuild-all/202503191453.uFfxQy5R-lkp@xxxxxxxxx/
> Signed-off-by: Josh Poimboeuf <jpoimboe@xxxxxxxxxx>
Thanks!
Reviewed-by: Kees Cook <kees@xxxxxxxxxx>
--
Kees Cook