blob: 8bea84724a7da4bd1c6d3a0509166618c39e5349 [file] [log] [blame]
Jeremy Fitzhardingec44c9ec2009-09-21 13:40:42 -07001#include <linux/spinlock.h>
2#include <linux/errno.h>
3#include <linux/init.h>
4
5#include <asm/pgtable.h>
H. Peter Anvin4763ed42009-11-13 15:28:16 -08006#include <asm/proto.h>
Borislav Petkovcd4d09e2016-01-26 22:12:04 +01007#include <asm/cpufeature.h>
Jeremy Fitzhardingec44c9ec2009-09-21 13:40:42 -07008
Paul Gortmaker148f9bb2013-06-18 18:23:59 -04009static int disable_nx;
Jeremy Fitzhardingec44c9ec2009-09-21 13:40:42 -070010
11/*
12 * noexec = on|off
13 *
14 * Control non-executable mappings for processes.
15 *
16 * on Enable
17 * off Disable
18 */
19static int __init noexec_setup(char *str)
20{
21 if (!str)
22 return -EINVAL;
23 if (!strncmp(str, "on", 2)) {
Jeremy Fitzhardingec44c9ec2009-09-21 13:40:42 -070024 disable_nx = 0;
25 } else if (!strncmp(str, "off", 3)) {
26 disable_nx = 1;
Jeremy Fitzhardingec44c9ec2009-09-21 13:40:42 -070027 }
H. Peter Anvin4763ed42009-11-13 15:28:16 -080028 x86_configure_nx();
Jeremy Fitzhardingec44c9ec2009-09-21 13:40:42 -070029 return 0;
30}
31early_param("noexec", noexec_setup);
Jeremy Fitzhardingec44c9ec2009-09-21 13:40:42 -070032
Paul Gortmaker148f9bb2013-06-18 18:23:59 -040033void x86_configure_nx(void)
Jeremy Fitzhardingec44c9ec2009-09-21 13:40:42 -070034{
Andy Lutomirski320d25b2016-01-19 13:38:58 -080035 /* If disable_nx is set, clear NX on all new mappings going forward. */
36 if (disable_nx)
Jeremy Fitzhardingec44c9ec2009-09-21 13:40:42 -070037 __supported_pte_mask &= ~_PAGE_NX;
38}
Kees Cook4b0f3b82009-11-13 15:28:17 -080039
40void __init x86_report_nx(void)
41{
Borislav Petkov362f9242015-12-07 10:39:41 +010042 if (!boot_cpu_has(X86_FEATURE_NX)) {
Kees Cook4b0f3b82009-11-13 15:28:17 -080043 printk(KERN_NOTICE "Notice: NX (Execute Disable) protection "
Kees Cook6036f372010-11-10 10:35:54 -080044 "missing in CPU!\n");
Kees Cook4b0f3b82009-11-13 15:28:17 -080045 } else {
46#if defined(CONFIG_X86_64) || defined(CONFIG_X86_PAE)
47 if (disable_nx) {
48 printk(KERN_INFO "NX (Execute Disable) protection: "
49 "disabled by kernel command line option\n");
50 } else {
51 printk(KERN_INFO "NX (Execute Disable) protection: "
52 "active\n");
53 }
54#else
55 /* 32bit non-PAE kernel, NX cannot be used */
56 printk(KERN_NOTICE "Notice: NX (Execute Disable) protection "
57 "cannot be enabled: non-PAE kernel!\n");
58#endif
59 }
60}