From: Kees Cook <keescook@chromium.org>
To: Sami Tolvanen <samitolvanen@google.com>
Cc: Will McVicker <willmcvicker@google.com>,
kvm@vger.kernel.org, Peter Zijlstra <peterz@infradead.org>,
LKML <linux-kernel@vger.kernel.org>,
kvmarm <kvmarm@lists.cs.columbia.edu>,
linux-arm-kernel <linux-arm-kernel@lists.infradead.org>
Subject: Re: [PATCH v4 09/17] perf/core: Use static_call to optimize perf_guest_info_callbacks
Date: Sun, 6 Feb 2022 10:45:15 -0800 [thread overview]
Message-ID: <202202061011.A255DE55B@keescook> (raw)
In-Reply-To: <CABCJKufg=ONNOvF8+BRXfLoTUfeiZZsdd8TnpV-GaNK_o-HuaA@mail.gmail.com>
On Fri, Feb 04, 2022 at 09:35:49AM -0800, Sami Tolvanen wrote:
> On Wed, Feb 2, 2022 at 10:43 AM Sean Christopherson <seanjc@google.com> wrote:
> > > +DEFINE_STATIC_CALL_RET0(__perf_guest_state, *perf_guest_cbs->state);
> > > +DEFINE_STATIC_CALL_RET0(__perf_guest_get_ip, *perf_guest_cbs->get_ip);
> > > +DEFINE_STATIC_CALL_RET0(__perf_guest_handle_intel_pt_intr, *perf_guest_cbs->handle_intel_pt_intr);
> >
> > Using __static_call_return0() makes clang's CFI sad on arm64 due to the resulting
> > function prototype mistmatch, which IIUC, is verified by clang's __cfi_check()
> > for indirect calls, i.e. architectures without CONFIG_HAVE_STATIC_CALL.
> >
> > We could fudge around the issue by using stubs, massaging prototypes, etc..., but
> > that means doing that for every arch-agnostic user of __static_call_return0().
> >
> > Any clever ideas? Can we do something like generate a unique function for every
> > DEFINE_STATIC_CALL_RET0 for CONFIG_HAVE_STATIC_CALL=n, e.g. using typeof() to
> > get the prototype?
>
> I'm not sure there's a clever fix for this. On architectures without
> HAVE_STATIC_CALL, this is an indirect call to a function with a
> mismatching type, which CFI is intended to catch.
>
> The obvious way to solve the problem would be to use a stub function
> with the correct type, which I agree, isn't going to scale. You can
> alternatively check if .func points to __static_call_return0 and not
> make the indirect call if it does. If neither of these options are
> feasible, you can disable CFI checking in the functions that have
> these static calls using the __nocfi attribute.
>
> Kees, any thoughts?
I'm digging through the macros to sort this out, but IIUC, an example of
the problem is:
perf_guest_cbs->handle_intel_pt_intr is:
unsigned int (*handle_intel_pt_intr)(void);
The declaration for this starts with:
DECLARE_STATIC_CALL(__perf_guest_handle_intel_pt_intr, *perf_guest_cbs->handle_intel_pt_intr);
which produces:
extern struct static_call_key STATIC_CALL_KEY(__perf_guest_handle_intel_pt_intr);
extern typeof(*perf_guest_cbs->handle_intel_pt_intr) STATIC_CALL_TRAMP(__perf_guest_handle_intel_pt_intr);
and the last line becomes:
extern unsigned int (*__SCT____perf_guest_handle_intel_pt_intr)(void);
with !HAVE_STATIC_CALL, when perf_guest_handle_intel_pt_intr() does:
return static_call(__perf_guest_handle_intel_pt_intr)();
it is resolving static_call() into:
((typeof(STATIC_CALL_TRAMP(name))*)(STATIC_CALL_KEY(name).func))
so the caller is expecting "unsigned int (*)(void)" but the prototype
of __static_call_return0 is "long (*)(void)":
long __static_call_return0(void);
Could we simply declare a type-matched ret0 trampoline too?
#define STATIC_CALL_TRAMP_RET0_PREFIX __SCT__ret0__
#define STATIC_CALL_TRAMP_RET0(name) __PASTE(STATIC_CALL_TRAMP_RET0_PREFIX, name)
#define DEFINE_STATIC_CALL_RET0(name, _func) \
static typeof(_func) STATIC_CALL_TRAMP_RET0(name) { return 0; } \
__DEFINE_STATIC_CALL(name, _func, STATIC_CALL_TRAMP_RET0(name));
static_call_update(__perf_guest_handle_intel_pt_intr,
(void *)&STATIC_CALL_TRAMP_RET0(__perf_guest_handle_intel_pt_intr))
--
Kees Cook
_______________________________________________
kvmarm mailing list
kvmarm@lists.cs.columbia.edu
https://lists.cs.columbia.edu/mailman/listinfo/kvmarm
next prev parent reply other threads:[~2022-02-06 18:45 UTC|newest]
Thread overview: 90+ messages / expand[flat|nested] mbox.gz Atom feed top
2021-11-11 2:07 [PATCH v4 00/17] perf: KVM: Fix, optimize, and clean up callbacks Sean Christopherson
2021-11-11 2:07 ` Sean Christopherson
2021-11-11 2:07 ` Sean Christopherson
2021-11-11 2:07 ` [PATCH v4 01/17] perf: Protect perf_guest_cbs with RCU Sean Christopherson
2021-11-11 2:07 ` Sean Christopherson
2021-11-11 2:07 ` Sean Christopherson
2021-11-11 7:26 ` Paolo Bonzini
2021-11-11 7:26 ` Paolo Bonzini
2021-11-11 7:26 ` Paolo Bonzini
2021-11-11 10:47 ` Peter Zijlstra
2021-11-11 10:47 ` Peter Zijlstra
2021-11-11 10:47 ` Peter Zijlstra
2021-11-12 7:55 ` Paolo Bonzini
2021-11-12 7:55 ` Paolo Bonzini
2021-11-12 7:55 ` Paolo Bonzini
2021-11-11 2:07 ` [PATCH v4 02/17] KVM: x86: Register perf callbacks after calling vendor's hardware_setup() Sean Christopherson
2021-11-11 2:07 ` Sean Christopherson
2021-11-11 2:07 ` Sean Christopherson
2021-11-11 2:07 ` [PATCH v4 03/17] KVM: x86: Register Processor Trace interrupt hook iff PT enabled in guest Sean Christopherson
2021-11-11 2:07 ` Sean Christopherson
2021-11-11 2:07 ` Sean Christopherson
2021-11-11 2:07 ` [PATCH v4 04/17] perf: Stop pretending that perf can handle multiple guest callbacks Sean Christopherson
2021-11-11 2:07 ` Sean Christopherson
2021-11-11 2:07 ` Sean Christopherson
2021-11-11 2:07 ` [PATCH v4 05/17] perf: Drop dead and useless guest "support" from arm, csky, nds32 and riscv Sean Christopherson
2021-11-11 2:07 ` Sean Christopherson
2021-11-11 2:07 ` Sean Christopherson
2021-11-11 2:07 ` [PATCH v4 06/17] perf/core: Rework guest callbacks to prepare for static_call support Sean Christopherson
2021-11-11 2:07 ` Sean Christopherson
2021-11-11 2:07 ` Sean Christopherson
2021-11-11 2:07 ` [PATCH v4 07/17] perf: Add wrappers for invoking guest callbacks Sean Christopherson
2021-11-11 2:07 ` Sean Christopherson
2021-11-11 2:07 ` Sean Christopherson
2021-11-11 2:07 ` [PATCH v4 08/17] perf: Force architectures to opt-in to " Sean Christopherson
2021-11-11 2:07 ` Sean Christopherson
2021-11-11 2:07 ` Sean Christopherson
2021-11-11 2:07 ` [PATCH v4 09/17] perf/core: Use static_call to optimize perf_guest_info_callbacks Sean Christopherson
2021-11-11 2:07 ` Sean Christopherson
2021-11-11 2:07 ` Sean Christopherson
2022-02-02 18:43 ` Sean Christopherson
2022-02-04 17:35 ` Sami Tolvanen
2022-02-06 13:08 ` Peter Zijlstra
2022-02-06 18:45 ` Kees Cook [this message]
2022-02-06 20:28 ` Peter Zijlstra
2022-02-07 2:55 ` Kees Cook
2022-02-18 22:35 ` Will McVicker
2022-08-24 16:45 ` Sean Christopherson
2026-03-09 19:27 ` Carlos Llamas
2026-03-09 22:31 ` Sami Tolvanen
2026-03-10 3:26 ` Carlos Llamas
2026-03-11 22:57 ` [PATCH] static_call: use CFI-compliant return0 stubs Carlos Llamas
2026-03-11 23:14 ` Peter Zijlstra
2026-03-12 0:16 ` Carlos Llamas
2026-03-12 7:40 ` Ard Biesheuvel
2026-03-12 8:07 ` Peter Zijlstra
2026-03-12 17:18 ` Carlos Llamas
2026-03-11 23:05 ` [PATCH v4 09/17] perf/core: Use static_call to optimize perf_guest_info_callbacks Carlos Llamas
2021-11-11 2:07 ` [PATCH v4 10/17] KVM: x86: Drop current_vcpu for kvm_running_vcpu + kvm_arch_vcpu variable Sean Christopherson
2021-11-11 2:07 ` Sean Christopherson
2021-11-11 2:07 ` Sean Christopherson
2021-11-11 2:07 ` [PATCH v4 11/17] KVM: x86: More precisely identify NMI from guest when handling PMI Sean Christopherson
2021-11-11 2:07 ` Sean Christopherson
2021-11-11 2:07 ` Sean Christopherson
2021-11-11 2:07 ` [PATCH v4 12/17] KVM: Move x86's perf guest info callbacks to generic KVM Sean Christopherson
2021-11-11 2:07 ` Sean Christopherson
2021-11-11 2:07 ` Sean Christopherson
2021-11-11 2:07 ` [PATCH v4 13/17] KVM: x86: Move Intel Processor Trace interrupt handler to vmx.c Sean Christopherson
2021-11-11 2:07 ` Sean Christopherson
2021-11-11 2:07 ` Sean Christopherson
2021-11-11 2:07 ` [PATCH v4 14/17] KVM: arm64: Convert to the generic perf callbacks Sean Christopherson
2021-11-11 2:07 ` Sean Christopherson
2021-11-11 2:07 ` Sean Christopherson
2021-11-11 2:07 ` [PATCH v4 15/17] KVM: arm64: Hide kvm_arm_pmu_available behind CONFIG_HW_PERF_EVENTS=y Sean Christopherson
2021-11-11 2:07 ` Sean Christopherson
2021-11-11 2:07 ` Sean Christopherson
2021-11-11 21:49 ` Marc Zyngier
2021-11-11 21:49 ` Marc Zyngier
2021-11-11 21:49 ` Marc Zyngier
2021-11-11 2:07 ` [PATCH v4 16/17] KVM: arm64: Drop perf.c and fold its tiny bits of code into arm.c Sean Christopherson
2021-11-11 2:07 ` Sean Christopherson
2021-11-11 2:07 ` Sean Christopherson
2021-11-11 21:49 ` Marc Zyngier
2021-11-11 21:49 ` Marc Zyngier
2021-11-11 21:49 ` Marc Zyngier
2021-11-11 2:07 ` [PATCH v4 17/17] perf: Drop guest callback (un)register stubs Sean Christopherson
2021-11-11 2:07 ` Sean Christopherson
2021-11-11 2:07 ` Sean Christopherson
2021-11-11 11:19 ` [PATCH v4 00/17] perf: KVM: Fix, optimize, and clean up callbacks Peter Zijlstra
2021-11-11 11:19 ` Peter Zijlstra
2021-11-11 11:19 ` Peter Zijlstra
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=202202061011.A255DE55B@keescook \
--to=keescook@chromium.org \
--cc=kvm@vger.kernel.org \
--cc=kvmarm@lists.cs.columbia.edu \
--cc=linux-arm-kernel@lists.infradead.org \
--cc=linux-kernel@vger.kernel.org \
--cc=peterz@infradead.org \
--cc=samitolvanen@google.com \
--cc=willmcvicker@google.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.