From 75467f60a3d14f08f86f2b353298d2826382ff23 Mon Sep 17 00:00:00 2001 From: Linus Torvalds Date: Fri, 25 Sep 2026 15:55:03 -0700 Subject: Merge tag 'ipe-pr-20260925' of git://git.kernel.org/pub/scm/linux/kernel/git/wufan/ipe Pull IPE fixes from Fan Wu: "Two fixes for use-after-free issues found by recent LLM-assisted code analysis. - move successful policy load auditing under the new policy directory's inode lock, preventing a concurrent policy deletion from freeing the policy while it is still being audited - protect the dm-verity root hash with RCU, preventing policy evaluation from racing with root hash replacement during preresume" * tag 'ipe-pr-20260925' of git://git.kernel.org/pub/scm/linux/kernel/git/wufan/ipe: ipe: protect the dm-verity root hash with RCU ipe: fix use-after-free when auditing a newly loaded policy --- scripts/module.lds.S | 63 ++++++++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 63 insertions(+) create mode 100644 scripts/module.lds.S (limited to 'scripts/module.lds.S') diff --git a/scripts/module.lds.S b/scripts/module.lds.S new file mode 100644 index 000000000..d0f200428 --- /dev/null +++ b/scripts/module.lds.S @@ -0,0 +1,63 @@ +/* + * Common module linker script, always used when linking a module. + * Archs are free to supply their own linker scripts. ld will + * combine them automatically. + */ + +#include + +SECTIONS { + /DISCARD/ : { + *(.discard) + *(.discard.*) + *(.export_symbol) + *(.no_trim_symbol) + } + + __ksymtab 0 : ALIGN(8) { *(SORT(___ksymtab+*)) } + __kcrctab 0 : ALIGN(4) { *(SORT(___kcrctab+*)) } + __kflagstab 0 : ALIGN(1) { *(SORT(___kflagstab+*)) } + + .ctors 0 : ALIGN(8) { *(SORT(.ctors.*)) *(.ctors) } + .init_array 0 : ALIGN(8) { *(SORT(.init_array.*)) *(.init_array) } + + .altinstructions 0 : ALIGN(8) { KEEP(*(.altinstructions)) } + __bug_table 0 : ALIGN(8) { KEEP(*(__bug_table)) } + __jump_table 0 : ALIGN(8) { KEEP(*(__jump_table)) } + __ex_table 0 : ALIGN(4) { KEEP(*(__ex_table)) } + + __patchable_function_entries 0 : { *(__patchable_function_entries) } + + .init.klp_funcs 0 : ALIGN(8) { KEEP(*(.init.klp_funcs)) } + .init.klp_objects 0 : ALIGN(8) { KEEP(*(.init.klp_objects)) } + +#ifdef CONFIG_ARCH_USES_CFI_TRAPS + __kcfi_traps 0 : { KEEP(*(.kcfi_traps)) } +#endif + +#ifndef CONFIG_ARCH_WANTS_MODULES_TEXT_SECTIONS + .text 0 : { + *(.text .text.[0-9a-zA-Z_]*) + } +#endif + + .bss 0 : { + *(.bss .bss.[0-9a-zA-Z_]*) + *(.bss..L*) + } + + .data 0 : { + *(.data .data.[0-9a-zA-Z_]*) + *(.data..L*) + } + + .rodata 0 : { + *(.rodata .rodata.[0-9a-zA-Z_]*) + *(.rodata..L*) + } + + MOD_SEPARATE_CODETAG_SECTIONS() +} + +/* bring in arch-specific sections */ +#include -- cgit v1.3.1