Without SMP, DEFINE_PER_CPU_DECRYPTED() places variables in
.data..decrypted. Align both ends of that section so that changing a
variable's encryption attribute cannot expose unrelated kernel data.
Keep the section in permanent data, where UP variables are instantiated.

Fixes: 000f8870a47b ("vmlinux.lds.h: Fix placement of '.data..decrypted' 
section")
Signed-off-by: Zack Rusin <[email protected]>
---
 include/asm-generic/vmlinux.lds.h | 11 ++++++++++-
 1 file changed, 10 insertions(+), 1 deletion(-)

diff --git a/include/asm-generic/vmlinux.lds.h 
b/include/asm-generic/vmlinux.lds.h
index b2988aa12f66..64bc2bfdd2ec 100644
--- a/include/asm-generic/vmlinux.lds.h
+++ b/include/asm-generic/vmlinux.lds.h
@@ -368,10 +368,19 @@
 /*
  * .data section
  */
+#if defined(CONFIG_AMD_MEM_ENCRYPT) && !defined(CONFIG_SMP)
+#define DATA_DECRYPTED                                                 \
+       . = ALIGN(PAGE_SIZE);                                           \
+       *(.data..decrypted)                                             \
+       . = ALIGN(PAGE_SIZE);
+#else
+#define DATA_DECRYPTED *(.data..decrypted)
+#endif
+
 #define DATA_DATA                                                      \
        *(.xiptext)                                                     \
        *(DATA_MAIN)                                                    \
-       *(.data..decrypted)                                             \
+       DATA_DECRYPTED                                                  \
        *(.ref.data)                                                    \
        *(.data..shared_aligned) /* percpu related */                   \
        *(.data..unlikely)                                              \
-- 
2.53.0


Reply via email to