From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pl1-f170.google.com (mail-pl1-f170.google.com [209.85.214.170]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 9A7DB1E51EF for ; Fri, 25 Jul 2025 14:16:20 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.214.170 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1753452982; cv=none; b=OuDU8M41wgjeQbf1jF5nfYRaU+bBNb9eY+D/5LMFwcZ9Gxh8f7199vqxuE3v3njF1OJMk9cW+7Ku+vCJCnDq57cRxYWxZJfxwcmAF82/EU5C0aaV8GaJYauovrkWaMn6QHtRVixLkTjoiRDd9/8hktDZcJi1pqidmU2SzAxVYPg= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1753452982; c=relaxed/simple; bh=rXtgRj8Lg0EC5NCvL7q1D/HDUV15yXcudNMgmUup6uQ=; h=Date:From:To:Cc:Subject:Message-ID:References:MIME-Version: Content-Type:Content-Disposition:In-Reply-To; b=ZSkjdfD7ubWVG/WGTMoyeaYxsl5UN+6wQyksdNHjfbjNkiZ1t9w//Ae10fwr4oVLBMjxpG/6axjI5P93qkJJRzQ/VKwMrRCzI8eZBQ3D3phqLMuAGggvA6Zg9uNC8p5s/Th6rcdKZ4Rzy8QS3BvA5YDkYH6elmTSwOXoGWjz5JE= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=rivosinc.com; spf=pass smtp.mailfrom=rivosinc.com; dkim=pass (2048-bit key) header.d=rivosinc-com.20230601.gappssmtp.com header.i=@rivosinc-com.20230601.gappssmtp.com header.b=mQVbtuol; arc=none smtp.client-ip=209.85.214.170 Authentication-Results: smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=rivosinc.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=rivosinc.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=rivosinc-com.20230601.gappssmtp.com header.i=@rivosinc-com.20230601.gappssmtp.com header.b="mQVbtuol" Received: by mail-pl1-f170.google.com with SMTP id d9443c01a7336-235f9e87f78so24161485ad.2 for ; Fri, 25 Jul 2025 07:16:20 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=rivosinc-com.20230601.gappssmtp.com; s=20230601; t=1753452980; x=1754057780; darn=vger.kernel.org; h=in-reply-to:content-disposition:mime-version:references:message-id :subject:cc:to:from:date:from:to:cc:subject:date:message-id:reply-to; bh=m4zb8NrY5OXi5r9Et0ByFU2sSCQJb+4fxBPaABm8ZNI=; b=mQVbtuolCEOh2lPmJOrlV7afcvjoSBSwkRIIisU/arrSrF9E8dawZBdQk+O3Q6X58Q +ad88T+dQQrWQFyGK3+tsc+cn8iqy2WuPInsPsNM7oqn6saqI2ZinyB47rtUVjnBewqu C+5JHCZCLhOR1eI/WhOGXNVvJogmJBlL5L/D0oBp50/BQ0ToBVc/EQyaH56Ui1+d0a+R o1oEnswqRl7sn3ZEyPOEIR+mHCCbuNsuoDNvofuaW37LXmTCY9B1m9iUwo4XW640ZD8W JhzG6gEmYEJaXinM8C5UQ0IqCqYRtXpxbwkFI66EIoXN1QG0/0dV8r8QeTP5kPn+hlRx FAOQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1753452980; x=1754057780; h=in-reply-to:content-disposition:mime-version:references:message-id :subject:cc:to:from:date:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to; bh=m4zb8NrY5OXi5r9Et0ByFU2sSCQJb+4fxBPaABm8ZNI=; b=aBYXWsYnT7Ts4qhBTFXHjZfYwApF3w4zJtiohTwarzVHLnmuJmnr/cCEOEkS6M4KnM hHHNZyZtOKaOWFlFdcoz/E/0mzz9zW2D3uxe9Yyp4fL5LFEY/uV1xvgN5L6ANU9cbJkj YNNMOzkMaQ5WqTZ9SeJk4dGm5klT9mM4zkR/+0jAfF/5ziVVGyVdHp9XCeYuqpzsiDnw seBl5mr/gdlVIN/FAvhofZUsqHqAxyfHloOR3Xks1EV7YQRjE1ODmcJNi8sw4E+gbVUe 7EnUyb1wE5RDpQnGvs8EfEGL7p1MRhxvJ2EFjr32k6lm0+C3PDWvOwQBV0F18D8+jQ0O TW/w== X-Forwarded-Encrypted: i=1; AJvYcCWT5P8o9Az0eZV5tIiHrRd87u6XwJPSO/ahG82Hjky+W7nfbK9VmE4kEaxitLSvwzh8tc8OAeDdy86DXwo=@vger.kernel.org X-Gm-Message-State: AOJu0YxciCnzVE3laNqHf7x6T4PqbLetUfHgYUZCbNoWnyQwwliV1nDM o5bFA431e9wG5CTTWyJnvqcrGKY8gNWv3XRYQX8IZARVyyWd8EcP/TAlF53TXYOIg34= X-Gm-Gg: ASbGnctjJHfpCb5jtH/x906GOC/qZHcsniKgYlS+w12TL3iTIZ+GwjVYpdmO24mcacU KRCvw/9JQqISu480uAcWfLhOBKZj/7EU1A4GURczHOayQk0qYo3otSMMC/cPEHLU+rGFg1ZF2Km i2Iky0rCClsOFsM3UHbyrglz+Riw5trI3dlz+BrycWCFGWa+SxgfC4rEcIFgFdJh8ALoFNCdf4k jPg/Js8f8239cw/wqiX6OmoSKnh+4h/wiyO9ntMBV8ZoaaA/IN8MkfSRKpFRZ2r7499YR3yGbV8 V34DSmMuAyP7mAb4uWGC9vB7Xjhs7G5gWE1dTFdSQ5r16tyYYZALp0S63TyMDbK9WNTnhtycCA2 Zyh4KrRF1fG9jxBCxwhg2MCt7E+fxLaFu X-Google-Smtp-Source: AGHT+IE9XuwrXVXrIfvlI3DBKUdukDNvmbxm+Ndq+/QyLjAd0FPi4mKe09kh/NBw/3BKfUdqYZtXMQ== X-Received: by 2002:a17:902:e5cc:b0:234:eb6:a35d with SMTP id d9443c01a7336-23fb30acdedmr35114765ad.27.1753452979529; Fri, 25 Jul 2025 07:16:19 -0700 (PDT) Received: from debug.ba.rivosinc.com ([64.71.180.162]) by smtp.gmail.com with ESMTPSA id d9443c01a7336-23fa491bb2asm38450025ad.213.2025.07.25.07.16.17 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 25 Jul 2025 07:16:19 -0700 (PDT) Date: Fri, 25 Jul 2025 07:16:15 -0700 From: Deepak Gupta To: Heinrich Schuchardt Cc: linux-riscv@lists.infradead.org, linux-kernel@vger.kernel.org, linux-kbuild@vger.kernel.org, linux-mm@kvack.org, llvm@lists.linux.dev, rick.p.edgecombe@intel.com, broonie@kernel.org, cleger@rivosinc.com, samitolvanen@google.com, apatel@ventanamicro.com, ajones@ventanamicro.com, conor.dooley@microchip.com, charlie@rivosinc.com, samuel.holland@sifive.com, bjorn@rivosinc.com, fweimer@redhat.com, jeffreyalaw@gmail.com, andrew@sifive.com, ved@rivosinc.com, Paul Walmsley , Palmer Dabbelt , Albert Ou , Alexandre Ghiti , Masahiro Yamada , Nathan Chancellor , Nicolas Schier , Andrew Morton , David Hildenbrand , Lorenzo Stoakes , "Liam R. Howlett" , Vlastimil Babka , Mike Rapoport , Suren Baghdasaryan , Michal Hocko , Nick Desaulniers , Bill Wendling , Monk Chiang , Kito Cheng , Justin Stitt Subject: Re: [PATCH 02/11] riscv: update asm call site in `call_on_irq_stack` to setup correct label Message-ID: References: <20250724-riscv_kcfi-v1-0-04b8fa44c98c@rivosinc.com> <20250724-riscv_kcfi-v1-2-04b8fa44c98c@rivosinc.com> <4ad699fc-a89d-4740-bdec-ecb9a2134c90@canonical.com> Precedence: bulk X-Mailing-List: linux-kbuild@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii; format=flowed Content-Disposition: inline In-Reply-To: <4ad699fc-a89d-4740-bdec-ecb9a2134c90@canonical.com> On Fri, Jul 25, 2025 at 08:23:44AM +0200, Heinrich Schuchardt wrote: >On 25.07.25 01:36, Deepak Gupta wrote: >>Call sites written in asm performing indirect call, they need to setup >>label register (t2/x7) with correct label. >> >>Currently first kernel was compiled with `-save-temps` option and >>normalized function signature string is captured and then placed at the >>asm callsite. >> >>TODO: to write a macro wrapper with toolchain support. >> >>Signed-off-by: Deepak Gupta >>--- >> arch/riscv/kernel/entry.S | 1 + >> 1 file changed, 1 insertion(+) >> >>diff --git a/arch/riscv/kernel/entry.S b/arch/riscv/kernel/entry.S >>index 2660faf52232..598e17e800ae 100644 >>--- a/arch/riscv/kernel/entry.S >>+++ b/arch/riscv/kernel/entry.S >>@@ -389,6 +389,7 @@ SYM_FUNC_START(call_on_irq_stack) >> load_per_cpu t0, irq_stack_ptr, t1 >> li t1, IRQ_STACK_SIZE >> add sp, t0, t1 >>+ lui t2, %lpad_hash("FvP7pt_regsE") > >In patch 1 you use lpad 0 due to missing tool support for signature hashing. > >Wouldn't it be preferable to have a first patch series introducing >landing pad support with lpad 0 and once tool support for signature >hashing has landed create a second patch series using tags? > >Such a first patch series would not have to be an RFC but might be >merged soon. It's mostly about security guarantees. Coarser grained cfi (only landing pad) has been proved many times not that effective. Kernel is a monolithic piece of code. If there is a good chance of adoption anywhere for labeled landing pads, its kernel. If it becomes a long pole, it's a possible direction to go back to unlabeled landing pad. > >Best regards > >Heinrich > >> jalr a1 >> /* Switch back to the thread shadow call stack */ >> > From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from bombadil.infradead.org (bombadil.infradead.org [198.137.202.133]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.lore.kernel.org (Postfix) with ESMTPS id E9723C87FCF for ; Fri, 25 Jul 2025 14:20:03 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.infradead.org; s=bombadil.20210309; h=Sender:Content-Type: Content-Transfer-Encoding:List-Subscribe:List-Help:List-Post:List-Archive: List-Unsubscribe:List-Id:In-Reply-To:MIME-Version:References:Message-ID: Subject:Cc:To:From:Date:Reply-To:Content-ID:Content-Description:Resent-Date: Resent-From:Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:List-Owner; bh=+GpSgLTCuY/6qQVS0zRn9mFZDRgNj4IOiGMaVcbQaDw=; b=Ix2TC3H6ZZwzBrMds9LNYwP+DG bLSkpAvtG1CSXGCHX3b1/iwHFKVrBXLOp6LT5xXUSyT4o8q/WMOZ0kgkT0OaRelM1jmfDiL9QGyID 8t5iQhA8vQhmWZMNPei4c058otWxLEKLq3DfXNlDkQMxTGi9jSL7YZYUm2Zkv2BhQ+5hq1M5D5mWL RTIdIIt/h7O3rdux4VW/c1NLQueSj5+lTk1liIZZQGa07Qtes18wPQcXPQsFuDplGH5iTRC3BG8OZ BGSBnCDk83YhJDVy2cdNmeYvEheJGOgco27Tb1KceHN1Qq3JRZVzlngR/jF3hk6XeA3P3z1bGa8Zh CzKqHe4g==; Received: from localhost ([::1] helo=bombadil.infradead.org) by bombadil.infradead.org with esmtp (Exim 4.98.2 #2 (Red Hat Linux)) id 1ufJH9-00000009zmU-2Aq6; Fri, 25 Jul 2025 14:19:55 +0000 Received: from mail-pl1-x635.google.com ([2607:f8b0:4864:20::635]) by bombadil.infradead.org with esmtps (Exim 4.98.2 #2 (Red Hat Linux)) id 1ufJDg-00000009zJu-2pct for linux-riscv@lists.infradead.org; Fri, 25 Jul 2025 14:16:21 +0000 Received: by mail-pl1-x635.google.com with SMTP id d9443c01a7336-235d6de331fso27476115ad.3 for ; Fri, 25 Jul 2025 07:16:20 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=rivosinc-com.20230601.gappssmtp.com; s=20230601; t=1753452980; x=1754057780; darn=lists.infradead.org; h=in-reply-to:content-disposition:mime-version:references:message-id :subject:cc:to:from:date:from:to:cc:subject:date:message-id:reply-to; bh=m4zb8NrY5OXi5r9Et0ByFU2sSCQJb+4fxBPaABm8ZNI=; b=aAPOIaL9m65g+WlDEcE2pEdqcPdnIQGs+Uj05Vi3i+TNxvcExWw+FMZCIVlFSAIFzY yuqbfAsUcHeMPe35ZKgjvQlaNBVB4ExN1Of5bD5UXz6ufL6RDweg1Wgxy/8m0NYFmAgn cHnySYN3dF6E8CntAHBYkpdJRB8HYR3uanLuCNc16BG+9Spuvmmbjllkud+uYD11ZaIe nM+8/5ZXUEmI0OGGol+Q9MboPFHXAvbhRdT0dQxqUKmX6CM8Y8KbYIk3Pg/xfNeCYOrR 8HzsvAh7NKWKpcAT86QaOM5DenqAlZMm/wiRewsMX3/Jf5mqyEjWM5E0Cwa+jetP5By7 +e7A== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1753452980; x=1754057780; h=in-reply-to:content-disposition:mime-version:references:message-id :subject:cc:to:from:date:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to; bh=m4zb8NrY5OXi5r9Et0ByFU2sSCQJb+4fxBPaABm8ZNI=; b=DQiYL5/fISQJg6qRnMzuW1f/t/U4hq5Jp65lKvicF+qE0LYrM4uVRNDDM2W6oGUwZc Ztheo3mxaByxkyRPr2d+TGgDFFcxkllrBNXkSraoirwJ7GDpaYIM1JLYnn32l+2rkOlL U1vRNSt4LRX6GT+7bgPJA639r/49gXyF9K5AoSkt4xB/IDHxeJD1kCrZf6zwzhvyktfM NPl+pvcAVJxB62e9uUPogyHfFzoK/6KDJoQYFYhqZpz/csdHyTIYDopsI7ihvpTZYQMD 4BLFG3H5nvLP6suwfLKx6n8NoCztIEB/rIOBbcWhENoS/5vqiDz/01M8fEuVOxpmBDmL FIww== X-Gm-Message-State: AOJu0Yw3hTRFlsy72Q8xp8oDPQx9+2Jk1Idb79AMAmhvCT9qqYbO+ri3 ab2sPJFKkhgE4Xl5xRSymOkYwnAXCqCZ4A8Nz6LE61xL2TVS13VgDeBcY5na+adqzKA= X-Gm-Gg: ASbGncuzllAxHl+6GBmAnxmWbX+7+LMCSj0VxRZWdQ4yVIDPDAmrKVI8vReVYFiUDZQ qCNpuakwQcfEpzXgW+xKHR3V+VGnvrk17LkG3PGLfXhVlTirnxVcmrG9ReW0J2QVY6u+WGipR/d Qta/dCEx/TJoe9bxE+7FwJrE45ctPxpB9wkY00j+VvqlJFvS+nGEWOwchpCLzF+m7U5oX5cE1yy lohvWvucMAjsPy2xUTcicKNb6u5K/9UipYV5eN4IUHJpbHXX0krnnT8yjr4aATvIC0GrDpssk27 k9afbX/Do7hxsv+651VqLPJ6D5xTstjXU69JKo5FkN5sbFCCJfD4Qwfzy7m3BlKPVNy+PPE4Jd5 mK9SDYLWknow4FTWAzehOjXzT6ZjoApZf X-Google-Smtp-Source: AGHT+IE9XuwrXVXrIfvlI3DBKUdukDNvmbxm+Ndq+/QyLjAd0FPi4mKe09kh/NBw/3BKfUdqYZtXMQ== X-Received: by 2002:a17:902:e5cc:b0:234:eb6:a35d with SMTP id d9443c01a7336-23fb30acdedmr35114765ad.27.1753452979529; Fri, 25 Jul 2025 07:16:19 -0700 (PDT) Received: from debug.ba.rivosinc.com ([64.71.180.162]) by smtp.gmail.com with ESMTPSA id d9443c01a7336-23fa491bb2asm38450025ad.213.2025.07.25.07.16.17 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 25 Jul 2025 07:16:19 -0700 (PDT) Date: Fri, 25 Jul 2025 07:16:15 -0700 From: Deepak Gupta To: Heinrich Schuchardt Cc: linux-riscv@lists.infradead.org, linux-kernel@vger.kernel.org, linux-kbuild@vger.kernel.org, linux-mm@kvack.org, llvm@lists.linux.dev, rick.p.edgecombe@intel.com, broonie@kernel.org, cleger@rivosinc.com, samitolvanen@google.com, apatel@ventanamicro.com, ajones@ventanamicro.com, conor.dooley@microchip.com, charlie@rivosinc.com, samuel.holland@sifive.com, bjorn@rivosinc.com, fweimer@redhat.com, jeffreyalaw@gmail.com, andrew@sifive.com, ved@rivosinc.com, Paul Walmsley , Palmer Dabbelt , Albert Ou , Alexandre Ghiti , Masahiro Yamada , Nathan Chancellor , Nicolas Schier , Andrew Morton , David Hildenbrand , Lorenzo Stoakes , "Liam R. Howlett" , Vlastimil Babka , Mike Rapoport , Suren Baghdasaryan , Michal Hocko , Nick Desaulniers , Bill Wendling , Monk Chiang , Kito Cheng , Justin Stitt Subject: Re: [PATCH 02/11] riscv: update asm call site in `call_on_irq_stack` to setup correct label Message-ID: References: <20250724-riscv_kcfi-v1-0-04b8fa44c98c@rivosinc.com> <20250724-riscv_kcfi-v1-2-04b8fa44c98c@rivosinc.com> <4ad699fc-a89d-4740-bdec-ecb9a2134c90@canonical.com> MIME-Version: 1.0 Content-Disposition: inline In-Reply-To: <4ad699fc-a89d-4740-bdec-ecb9a2134c90@canonical.com> X-CRM114-Version: 20100106-BlameMichelson ( TRE 0.8.0 (BSD) ) MR-646709E3 X-CRM114-CacheID: sfid-20250725_071620_716537_595A52A1 X-CRM114-Status: GOOD ( 14.69 ) X-BeenThere: linux-riscv@lists.infradead.org X-Mailman-Version: 2.1.34 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Content-Transfer-Encoding: 7bit Content-Type: text/plain; charset="us-ascii"; Format="flowed" Sender: "linux-riscv" Errors-To: linux-riscv-bounces+linux-riscv=archiver.kernel.org@lists.infradead.org On Fri, Jul 25, 2025 at 08:23:44AM +0200, Heinrich Schuchardt wrote: >On 25.07.25 01:36, Deepak Gupta wrote: >>Call sites written in asm performing indirect call, they need to setup >>label register (t2/x7) with correct label. >> >>Currently first kernel was compiled with `-save-temps` option and >>normalized function signature string is captured and then placed at the >>asm callsite. >> >>TODO: to write a macro wrapper with toolchain support. >> >>Signed-off-by: Deepak Gupta >>--- >> arch/riscv/kernel/entry.S | 1 + >> 1 file changed, 1 insertion(+) >> >>diff --git a/arch/riscv/kernel/entry.S b/arch/riscv/kernel/entry.S >>index 2660faf52232..598e17e800ae 100644 >>--- a/arch/riscv/kernel/entry.S >>+++ b/arch/riscv/kernel/entry.S >>@@ -389,6 +389,7 @@ SYM_FUNC_START(call_on_irq_stack) >> load_per_cpu t0, irq_stack_ptr, t1 >> li t1, IRQ_STACK_SIZE >> add sp, t0, t1 >>+ lui t2, %lpad_hash("FvP7pt_regsE") > >In patch 1 you use lpad 0 due to missing tool support for signature hashing. > >Wouldn't it be preferable to have a first patch series introducing >landing pad support with lpad 0 and once tool support for signature >hashing has landed create a second patch series using tags? > >Such a first patch series would not have to be an RFC but might be >merged soon. It's mostly about security guarantees. Coarser grained cfi (only landing pad) has been proved many times not that effective. Kernel is a monolithic piece of code. If there is a good chance of adoption anywhere for labeled landing pads, its kernel. If it becomes a long pole, it's a possible direction to go back to unlabeled landing pad. > >Best regards > >Heinrich > >> jalr a1 >> /* Switch back to the thread shadow call stack */ >> > _______________________________________________ linux-riscv mailing list linux-riscv@lists.infradead.org http://lists.infradead.org/mailman/listinfo/linux-riscv