From: Deepak Gupta <debug@rivosinc.com>
To: Charles Mirabile <cmirabil@redhat.com>
Cc: Liam.Howlett@oracle.com, a.hindborg@kernel.org,
akpm@linux-foundation.org, alex.gaynor@gmail.com,
alexghiti@rivosinc.com, aliceryhl@google.com,
alistair.francis@wdc.com, andybnac@gmail.com,
aou@eecs.berkeley.edu, arnd@arndb.de, atishp@rivosinc.com,
bjorn3_gh@protonmail.com, boqun.feng@gmail.com, bp@alien8.de,
brauner@kernel.org, broonie@kernel.org, charlie@rivosinc.com,
cleger@rivosinc.com, conor+dt@kernel.org, conor@kernel.org,
corbet@lwn.net, dave.hansen@linux.intel.com,
devicetree@vger.kernel.org, ebiederm@xmission.com,
evan@rivosinc.com, gary@garyguo.net, hpa@zytor.com,
jannh@google.com, jim.shu@sifive.com, kees@kernel.org,
kito.cheng@sifive.com, krzk+dt@kernel.org,
linux-arch@vger.kernel.org, linux-doc@vger.kernel.org,
linux-fsdevel@vger.kernel.org, linux-kernel@vger.kernel.org,
linux-kselftest@vger.kernel.org, linux-mm@kvack.org,
linux-riscv@lists.infradead.org, lorenzo.stoakes@oracle.com,
lossin@kernel.org, mingo@redhat.com, ojeda@kernel.org,
oleg@redhat.com, palmer@dabbelt.com, paul.walmsley@sifive.com,
peterz@infradead.org, richard.henderson@linaro.org,
rick.p.edgecombe@intel.com, robh@kernel.org,
rust-for-linux@vger.kernel.org, samitolvanen@google.com,
shuah@kernel.org, tglx@linutronix.de, tmgross@umich.edu,
vbabka@suse.cz, x86@kernel.org
Subject: Re: [PATCH v20 24/28] arch/riscv: dual vdso creation logic and select vdso based on hw
Date: Wed, 15 Oct 2025 13:56:56 -0700 [thread overview]
Message-ID: <aPAKmCwDeXXvU7VD@debug.ba.rivosinc.com> (raw)
In-Reply-To: <20251015203611.2572538-1-cmirabil@redhat.com>
Hi Charles,
On Wed, Oct 15, 2025 at 04:36:11PM -0400, Charles Mirabile wrote:
>Hi Deepak -
>
>On Mon, Oct 13, 2025 at 02:56:16PM -0700, Deepak Gupta wrote:
>> Shadow stack instructions are taken from zimop (mandated on RVA23).
>> Any hardware prior to RVA23 profile will fault on shado stack instruction.
>> Any userspace with shadow stack instruction in it will fault on such
>> hardware. Thus such userspace can't be brought onto such a hardware.
>>
>> It's not known how userspace will respond to such binary fragmentation.
>> However in order to keep kernel portable across such different hardware,
>> `arch/riscv/kernel/vdso_cfi` is created which has logic (Makefile) to
>> compile `arch/riscv/kernel/vdso` sources with cfi flags and then changes
>> in `arch/riscv/kernel/vdso.c` for selecting appropriate vdso depending
>> on whether underlying hardware(cpu) implements zimop extension. Offset
>> of vdso symbols will change due to having two different vdso binaries,
>> there is added logic to include new generated vdso offset header and
>> dynamically select offset (like for rt_sigreturn).
>
>This looks great. As kernel test robot highlighted, the code doesn't build
>when the config is off, but I was able to fix it with the attached patch.
Yes sorry about that. Locally include/generated had both files and that's how
I missed it.
>
>Assuming that these changes or equivalent are folded in, you have my:
>
Yes v21 changes are equivalent to what you proposed.
>Acked-by: Charles Mirabile <cmirabil@redhat.com>
If I send another version due to some other issue, I'll collect your tag.
Else
Paul,
Can you apply the tag when you take it in.
-Deepak
>
>As merely a user whose previous concerns have been addressed, I am not
>sure what that is worth, but I appreciate your effort on this.
Thanks.
>
>>
>> Signed-off-by: Deepak Gupta <debug@rivosinc.com>
>> ---
>> arch/riscv/Makefile | 3 +++
>> arch/riscv/include/asm/vdso.h | 7 ++++++-
>> arch/riscv/kernel/Makefile | 1 +
>> arch/riscv/kernel/vdso.c | 7 +++++++
>> arch/riscv/kernel/vdso/Makefile | 29 ++++++++++++++++++++---------
>> arch/riscv/kernel/vdso/gen_vdso_offsets.sh | 4 +++-
>> arch/riscv/kernel/vdso_cfi/Makefile | 25 +++++++++++++++++++++++++
>> arch/riscv/kernel/vdso_cfi/vdso-cfi.S | 11 +++++++++++
>> 8 files changed, 76 insertions(+), 11 deletions(-)
>>
>> diff --git a/arch/riscv/Makefile b/arch/riscv/Makefile
>> index f60c2de0ca08..b74b63da16a7 100644
>> --- a/arch/riscv/Makefile
>> +++ b/arch/riscv/Makefile
>> @@ -176,6 +176,8 @@ ifeq ($(CONFIG_MMU),y)
>> prepare: vdso_prepare
>> vdso_prepare: prepare0
>> $(Q)$(MAKE) $(build)=arch/riscv/kernel/vdso include/generated/vdso-offsets.h
>> + $(if $(CONFIG_RISCV_USER_CFI),$(Q)$(MAKE) \
>> + $(build)=arch/riscv/kernel/vdso_cfi include/generated/vdso-cfi-offsets.h)
>> $(if $(CONFIG_COMPAT),$(Q)$(MAKE) \
>> $(build)=arch/riscv/kernel/compat_vdso include/generated/compat_vdso-offsets.h)
>>
>> @@ -183,6 +185,7 @@ endif
>> endif
>>
>> vdso-install-y += arch/riscv/kernel/vdso/vdso.so.dbg
>> +vdso-install-$(CONFIG_RISCV_USER_CFI) += arch/riscv/kernel/vdso_cfi/vdso-cfi.so.dbg
>> vdso-install-$(CONFIG_COMPAT) += arch/riscv/kernel/compat_vdso/compat_vdso.so.dbg
>>
>> BOOT_TARGETS := Image Image.gz Image.bz2 Image.lz4 Image.lzma Image.lzo Image.zst Image.xz loader loader.bin xipImage vmlinuz.efi
>> diff --git a/arch/riscv/include/asm/vdso.h b/arch/riscv/include/asm/vdso.h
>> index f80357fe24d1..3fc8f72b8bfb 100644
>> --- a/arch/riscv/include/asm/vdso.h
>> +++ b/arch/riscv/include/asm/vdso.h
>> @@ -18,9 +18,13 @@
>>
>> #ifndef __ASSEMBLER__
>> #include <generated/vdso-offsets.h>
>> +#include <generated/vdso-cfi-offsets.h>
>>
>> #define VDSO_SYMBOL(base, name) \
>> - (void __user *)((unsigned long)(base) + __vdso_##name##_offset)
>> + ((IS_ENABLED(CONFIG_RISCV_USER_CFI) && \
>> + riscv_has_extension_unlikely(RISCV_ISA_EXT_ZIMOP)) ? \
>> + (void __user *)((unsigned long)(base) + __vdso_##name##_cfi_offset) : \
>> + (void __user *)((unsigned long)(base) + __vdso_##name##_offset))
>>
>> #ifdef CONFIG_COMPAT
>> #include <generated/compat_vdso-offsets.h>
>> @@ -33,6 +37,7 @@ extern char compat_vdso_start[], compat_vdso_end[];
>> #endif /* CONFIG_COMPAT */
>>
>> extern char vdso_start[], vdso_end[];
>> +extern char vdso_cfi_start[], vdso_cfi_end[];
>>
>> #endif /* !__ASSEMBLER__ */
>>
>> diff --git a/arch/riscv/kernel/Makefile b/arch/riscv/kernel/Makefile
>> index 2d0e0dcedbd3..9026400cba10 100644
>> --- a/arch/riscv/kernel/Makefile
>> +++ b/arch/riscv/kernel/Makefile
>> @@ -72,6 +72,7 @@ obj-y += vendor_extensions/
>> obj-y += probes/
>> obj-y += tests/
>> obj-$(CONFIG_MMU) += vdso.o vdso/
>> +obj-$(CONFIG_RISCV_USER_CFI) += vdso_cfi/
>>
>> obj-$(CONFIG_RISCV_MISALIGNED) += traps_misaligned.o
>> obj-$(CONFIG_RISCV_MISALIGNED) += unaligned_access_speed.o
>> diff --git a/arch/riscv/kernel/vdso.c b/arch/riscv/kernel/vdso.c
>> index 3a8e038b10a2..bf080e519101 100644
>> --- a/arch/riscv/kernel/vdso.c
>> +++ b/arch/riscv/kernel/vdso.c
>> @@ -98,6 +98,13 @@ static struct __vdso_info compat_vdso_info __ro_after_init = {
>>
>> static int __init vdso_init(void)
>> {
>> + /* Hart implements zimop, expose cfi compiled vdso */
>> + if (IS_ENABLED(CONFIG_RISCV_USER_CFI) &&
>> + riscv_has_extension_unlikely(RISCV_ISA_EXT_ZIMOP)) {
>> + vdso_info.vdso_code_start = vdso_cfi_start;
>> + vdso_info.vdso_code_end = vdso_cfi_end;
>> + }
>> +
>> __vdso_init(&vdso_info);
>> #ifdef CONFIG_COMPAT
>> __vdso_init(&compat_vdso_info);
>> diff --git a/arch/riscv/kernel/vdso/Makefile b/arch/riscv/kernel/vdso/Makefile
>> index 272f1d837a80..a842dc034571 100644
>> --- a/arch/riscv/kernel/vdso/Makefile
>> +++ b/arch/riscv/kernel/vdso/Makefile
>> @@ -20,6 +20,10 @@ endif
>> ifdef VDSO_CFI_BUILD
>> CFI_MARCH = _zicfilp_zicfiss
>> CFI_FULL = -fcf-protection=full
>> +CFI_SUFFIX = -cfi
>> +OFFSET_SUFFIX = _cfi
>> +ccflags-y += -DVDSO_CFI=1
>> +asflags-y += -DVDSO_CFI=1
>> endif
>>
>> # Files to link into the vdso
>> @@ -48,13 +52,20 @@ endif
>> CFLAGS_hwprobe.o += -fPIC
>>
>> # Build rules
>> -targets := $(obj-vdso) vdso.so vdso.so.dbg vdso.lds
>> +vdso_offsets := vdso$(if $(VDSO_CFI_BUILD),$(CFI_SUFFIX),)-offsets.h
>> +vdso_o := vdso$(if $(VDSO_CFI_BUILD),$(CFI_SUFFIX),).o
>> +vdso_so := vdso$(if $(VDSO_CFI_BUILD),$(CFI_SUFFIX),).so
>> +vdso_so_dbg := vdso$(if $(VDSO_CFI_BUILD),$(CFI_SUFFIX),).so.dbg
>> +vdso_lds := vdso.lds
>> +
>> +targets := $(obj-vdso) $(vdso_so) $(vdso_so_dbg) $(vdso_lds)
>> +
>> obj-vdso := $(addprefix $(obj)/, $(obj-vdso))
>>
>> -obj-y += vdso.o
>> -CPPFLAGS_vdso.lds += -P -C -U$(ARCH)
>> +obj-y += vdso$(if $(VDSO_CFI_BUILD),$(CFI_SUFFIX),).o
>> +CPPFLAGS_$(vdso_lds) += -P -C -U$(ARCH)
>> ifneq ($(filter vgettimeofday, $(vdso-syms)),)
>> -CPPFLAGS_vdso.lds += -DHAS_VGETTIMEOFDAY
>> +CPPFLAGS_$(vdso_lds) += -DHAS_VGETTIMEOFDAY
>> endif
>>
>> # Disable -pg to prevent insert call site
>> @@ -63,12 +74,12 @@ CFLAGS_REMOVE_getrandom.o = $(CC_FLAGS_FTRACE) $(CC_FLAGS_SCS)
>> CFLAGS_REMOVE_hwprobe.o = $(CC_FLAGS_FTRACE) $(CC_FLAGS_SCS)
>>
>> # Force dependency
>> -$(obj)/vdso.o: $(obj)/vdso.so
>> +$(obj)/$(vdso_o): $(obj)/$(vdso_so)
>>
>> # link rule for the .so file, .lds has to be first
>> -$(obj)/vdso.so.dbg: $(obj)/vdso.lds $(obj-vdso) FORCE
>> +$(obj)/$(vdso_so_dbg): $(obj)/$(vdso_lds) $(obj-vdso) FORCE
>> $(call if_changed,vdsold_and_check)
>> -LDFLAGS_vdso.so.dbg = -shared -soname=linux-vdso.so.1 \
>> +LDFLAGS_$(vdso_so_dbg) = -shared -soname=linux-vdso.so.1 \
>> --build-id=sha1 --eh-frame-hdr
>>
>> # strip rule for the .so file
>> @@ -79,9 +90,9 @@ $(obj)/%.so: $(obj)/%.so.dbg FORCE
>> # Generate VDSO offsets using helper script
>> gen-vdsosym := $(src)/gen_vdso_offsets.sh
>> quiet_cmd_vdsosym = VDSOSYM $@
>> - cmd_vdsosym = $(NM) $< | $(gen-vdsosym) | LC_ALL=C sort > $@
>> + cmd_vdsosym = $(NM) $< | $(gen-vdsosym) $(OFFSET_SUFFIX) | LC_ALL=C sort > $@
>>
>> -include/generated/vdso-offsets.h: $(obj)/vdso.so.dbg FORCE
>> +include/generated/$(vdso_offsets): $(obj)/$(vdso_so_dbg) FORCE
>> $(call if_changed,vdsosym)
>>
>> # actual build commands
>> diff --git a/arch/riscv/kernel/vdso/gen_vdso_offsets.sh b/arch/riscv/kernel/vdso/gen_vdso_offsets.sh
>> index c2e5613f3495..bd5d5afaaa14 100755
>> --- a/arch/riscv/kernel/vdso/gen_vdso_offsets.sh
>> +++ b/arch/riscv/kernel/vdso/gen_vdso_offsets.sh
>> @@ -2,4 +2,6 @@
>> # SPDX-License-Identifier: GPL-2.0
>>
>> LC_ALL=C
>> -sed -n -e 's/^[0]\+\(0[0-9a-fA-F]*\) . \(__vdso_[a-zA-Z0-9_]*\)$/\#define \2_offset\t0x\1/p'
>> +SUFFIX=${1:-""}
>> +sed -n -e \
>> +'s/^[0]\+\(0[0-9a-fA-F]*\) . \(__vdso_[a-zA-Z0-9_]*\)$/\#define \2'$SUFFIX'_offset\t0x\1/p'
>> diff --git a/arch/riscv/kernel/vdso_cfi/Makefile b/arch/riscv/kernel/vdso_cfi/Makefile
>> new file mode 100644
>> index 000000000000..8ebd190782b0
>> --- /dev/null
>> +++ b/arch/riscv/kernel/vdso_cfi/Makefile
>> @@ -0,0 +1,25 @@
>> +# SPDX-License-Identifier: GPL-2.0-only
>> +# RISC-V VDSO CFI Makefile
>> +# This Makefile builds the VDSO with CFI support when CONFIG_RISCV_USER_CFI is enabled
>> +
>> +# setting VDSO_CFI_BUILD triggers build for vdso differently
>> +VDSO_CFI_BUILD := 1
>> +
>> +# Set the source directory to the main vdso directory
>> +src := $(srctree)/arch/riscv/kernel/vdso
>> +
>> +# Copy all .S and .c files from vdso directory to vdso_cfi object build directory
>> +vdso_c_sources := $(wildcard $(src)/*.c)
>> +vdso_S_sources := $(wildcard $(src)/*.S)
>> +vdso_c_objects := $(addprefix $(obj)/, $(notdir $(vdso_c_sources)))
>> +vdso_S_objects := $(addprefix $(obj)/, $(notdir $(vdso_S_sources)))
>> +
>> +$(vdso_S_objects): $(obj)/%.S: $(src)/%.S
>> + $(Q)cp $< $@
>> +
>> +$(vdso_c_objects): $(obj)/%.c: $(src)/%.c
>> + $(Q)cp $< $@
>> +
>> +# Include the main VDSO Makefile which contains all the build rules and sources
>> +# The VDSO_CFI_BUILD variable will be passed to it to enable CFI compilation
>> +include $(src)/Makefile
>> diff --git a/arch/riscv/kernel/vdso_cfi/vdso-cfi.S b/arch/riscv/kernel/vdso_cfi/vdso-cfi.S
>> new file mode 100644
>> index 000000000000..d426f6accb35
>> --- /dev/null
>> +++ b/arch/riscv/kernel/vdso_cfi/vdso-cfi.S
>> @@ -0,0 +1,11 @@
>> +/* SPDX-License-Identifier: GPL-2.0-only */
>> +/*
>> + * Copyright 2025 Rivos, Inc
>> + */
>> +
>> +#define vdso_start vdso_cfi_start
>> +#define vdso_end vdso_cfi_end
>> +
>> +#define __VDSO_PATH "arch/riscv/kernel/vdso_cfi/vdso-cfi.so"
>> +
>> +#include "../vdso/vdso.S"
>>
>> --
>> 2.43.0
>>
>>
>> _______________________________________________
>> linux-riscv mailing list
>> linux-riscv@lists.infradead.org
>> http://lists.infradead.org/mailman/listinfo/linux-riscv
>---
>diff --git a/arch/riscv/include/asm/vdso.h b/arch/riscv/include/asm/vdso.h
>index 3fc8f72b8bfb..9cfbb390270f 100644
>--- a/arch/riscv/include/asm/vdso.h
>+++ b/arch/riscv/include/asm/vdso.h
>@@ -18,13 +18,21 @@
>
> #ifndef __ASSEMBLER__
> #include <generated/vdso-offsets.h>
>+#if IS_ENABLED(CONFIG_RISCV_USER_CFI)
>+
> #include <generated/vdso-cfi-offsets.h>
>
> #define VDSO_SYMBOL(base, name) \
>- ((IS_ENABLED(CONFIG_RISCV_USER_CFI) && \
>- riscv_has_extension_unlikely(RISCV_ISA_EXT_ZIMOP)) ? \
>- (void __user *)((unsigned long)(base) + __vdso_##name##_cfi_offset) : \
>- (void __user *)((unsigned long)(base) + __vdso_##name##_offset))
>+ (riscv_has_extension_unlikely(RISCV_ISA_EXT_ZIMOP)) ? \
>+ (void __user *)((unsigned long)(base) + __vdso_##name##_cfi_offset) : \
>+ (void __user *)((unsigned long)(base) + __vdso_##name##_offset)
>+
>+#else /* !CONFIG_RISCV_USER_CFI */
>+
>+#define VDSO_SYMBOL(base, name) \
>+ (void __user *)((unsigned long)(base) + __vdso_##name##_offset)
>+
>+#endif /* CONFIG_RISCV_USER_CFI */
>
> #ifdef CONFIG_COMPAT
> #include <generated/compat_vdso-offsets.h>
>
WARNING: multiple messages have this Message-ID (diff)
From: Deepak Gupta <debug@rivosinc.com>
To: Charles Mirabile <cmirabil@redhat.com>
Cc: Liam.Howlett@oracle.com, a.hindborg@kernel.org,
akpm@linux-foundation.org, alex.gaynor@gmail.com,
alexghiti@rivosinc.com, aliceryhl@google.com,
alistair.francis@wdc.com, andybnac@gmail.com,
aou@eecs.berkeley.edu, arnd@arndb.de, atishp@rivosinc.com,
bjorn3_gh@protonmail.com, boqun.feng@gmail.com, bp@alien8.de,
brauner@kernel.org, broonie@kernel.org, charlie@rivosinc.com,
cleger@rivosinc.com, conor+dt@kernel.org, conor@kernel.org,
corbet@lwn.net, dave.hansen@linux.intel.com,
devicetree@vger.kernel.org, ebiederm@xmission.com,
evan@rivosinc.com, gary@garyguo.net, hpa@zytor.com,
jannh@google.com, jim.shu@sifive.com, kees@kernel.org,
kito.cheng@sifive.com, krzk+dt@kernel.org,
linux-arch@vger.kernel.org, linux-doc@vger.kernel.org,
linux-fsdevel@vger.kernel.org, linux-kernel@vger.kernel.org,
linux-kselftest@vger.kernel.org, linux-mm@kvack.org,
linux-riscv@lists.infradead.org, lorenzo.stoakes@oracle.com,
lossin@kernel.org, mingo@redhat.com, ojeda@kernel.org,
oleg@redhat.com, palmer@dabbelt.com, paul.walmsley@sifive.com,
peterz@infradead.org, richard.henderson@linaro.org,
rick.p.edgecombe@intel.com, robh@kernel.org,
rust-for-linux@vger.kernel.org, samitolvanen@google.com,
shuah@kernel.org, tglx@linutronix.de, tmgross@umich.edu,
vbabka@suse.cz, x86@kernel.org
Subject: Re: [PATCH v20 24/28] arch/riscv: dual vdso creation logic and select vdso based on hw
Date: Wed, 15 Oct 2025 13:56:56 -0700 [thread overview]
Message-ID: <aPAKmCwDeXXvU7VD@debug.ba.rivosinc.com> (raw)
In-Reply-To: <20251015203611.2572538-1-cmirabil@redhat.com>
Hi Charles,
On Wed, Oct 15, 2025 at 04:36:11PM -0400, Charles Mirabile wrote:
>Hi Deepak -
>
>On Mon, Oct 13, 2025 at 02:56:16PM -0700, Deepak Gupta wrote:
>> Shadow stack instructions are taken from zimop (mandated on RVA23).
>> Any hardware prior to RVA23 profile will fault on shado stack instruction.
>> Any userspace with shadow stack instruction in it will fault on such
>> hardware. Thus such userspace can't be brought onto such a hardware.
>>
>> It's not known how userspace will respond to such binary fragmentation.
>> However in order to keep kernel portable across such different hardware,
>> `arch/riscv/kernel/vdso_cfi` is created which has logic (Makefile) to
>> compile `arch/riscv/kernel/vdso` sources with cfi flags and then changes
>> in `arch/riscv/kernel/vdso.c` for selecting appropriate vdso depending
>> on whether underlying hardware(cpu) implements zimop extension. Offset
>> of vdso symbols will change due to having two different vdso binaries,
>> there is added logic to include new generated vdso offset header and
>> dynamically select offset (like for rt_sigreturn).
>
>This looks great. As kernel test robot highlighted, the code doesn't build
>when the config is off, but I was able to fix it with the attached patch.
Yes sorry about that. Locally include/generated had both files and that's how
I missed it.
>
>Assuming that these changes or equivalent are folded in, you have my:
>
Yes v21 changes are equivalent to what you proposed.
>Acked-by: Charles Mirabile <cmirabil@redhat.com>
If I send another version due to some other issue, I'll collect your tag.
Else
Paul,
Can you apply the tag when you take it in.
-Deepak
>
>As merely a user whose previous concerns have been addressed, I am not
>sure what that is worth, but I appreciate your effort on this.
Thanks.
>
>>
>> Signed-off-by: Deepak Gupta <debug@rivosinc.com>
>> ---
>> arch/riscv/Makefile | 3 +++
>> arch/riscv/include/asm/vdso.h | 7 ++++++-
>> arch/riscv/kernel/Makefile | 1 +
>> arch/riscv/kernel/vdso.c | 7 +++++++
>> arch/riscv/kernel/vdso/Makefile | 29 ++++++++++++++++++++---------
>> arch/riscv/kernel/vdso/gen_vdso_offsets.sh | 4 +++-
>> arch/riscv/kernel/vdso_cfi/Makefile | 25 +++++++++++++++++++++++++
>> arch/riscv/kernel/vdso_cfi/vdso-cfi.S | 11 +++++++++++
>> 8 files changed, 76 insertions(+), 11 deletions(-)
>>
>> diff --git a/arch/riscv/Makefile b/arch/riscv/Makefile
>> index f60c2de0ca08..b74b63da16a7 100644
>> --- a/arch/riscv/Makefile
>> +++ b/arch/riscv/Makefile
>> @@ -176,6 +176,8 @@ ifeq ($(CONFIG_MMU),y)
>> prepare: vdso_prepare
>> vdso_prepare: prepare0
>> $(Q)$(MAKE) $(build)=arch/riscv/kernel/vdso include/generated/vdso-offsets.h
>> + $(if $(CONFIG_RISCV_USER_CFI),$(Q)$(MAKE) \
>> + $(build)=arch/riscv/kernel/vdso_cfi include/generated/vdso-cfi-offsets.h)
>> $(if $(CONFIG_COMPAT),$(Q)$(MAKE) \
>> $(build)=arch/riscv/kernel/compat_vdso include/generated/compat_vdso-offsets.h)
>>
>> @@ -183,6 +185,7 @@ endif
>> endif
>>
>> vdso-install-y += arch/riscv/kernel/vdso/vdso.so.dbg
>> +vdso-install-$(CONFIG_RISCV_USER_CFI) += arch/riscv/kernel/vdso_cfi/vdso-cfi.so.dbg
>> vdso-install-$(CONFIG_COMPAT) += arch/riscv/kernel/compat_vdso/compat_vdso.so.dbg
>>
>> BOOT_TARGETS := Image Image.gz Image.bz2 Image.lz4 Image.lzma Image.lzo Image.zst Image.xz loader loader.bin xipImage vmlinuz.efi
>> diff --git a/arch/riscv/include/asm/vdso.h b/arch/riscv/include/asm/vdso.h
>> index f80357fe24d1..3fc8f72b8bfb 100644
>> --- a/arch/riscv/include/asm/vdso.h
>> +++ b/arch/riscv/include/asm/vdso.h
>> @@ -18,9 +18,13 @@
>>
>> #ifndef __ASSEMBLER__
>> #include <generated/vdso-offsets.h>
>> +#include <generated/vdso-cfi-offsets.h>
>>
>> #define VDSO_SYMBOL(base, name) \
>> - (void __user *)((unsigned long)(base) + __vdso_##name##_offset)
>> + ((IS_ENABLED(CONFIG_RISCV_USER_CFI) && \
>> + riscv_has_extension_unlikely(RISCV_ISA_EXT_ZIMOP)) ? \
>> + (void __user *)((unsigned long)(base) + __vdso_##name##_cfi_offset) : \
>> + (void __user *)((unsigned long)(base) + __vdso_##name##_offset))
>>
>> #ifdef CONFIG_COMPAT
>> #include <generated/compat_vdso-offsets.h>
>> @@ -33,6 +37,7 @@ extern char compat_vdso_start[], compat_vdso_end[];
>> #endif /* CONFIG_COMPAT */
>>
>> extern char vdso_start[], vdso_end[];
>> +extern char vdso_cfi_start[], vdso_cfi_end[];
>>
>> #endif /* !__ASSEMBLER__ */
>>
>> diff --git a/arch/riscv/kernel/Makefile b/arch/riscv/kernel/Makefile
>> index 2d0e0dcedbd3..9026400cba10 100644
>> --- a/arch/riscv/kernel/Makefile
>> +++ b/arch/riscv/kernel/Makefile
>> @@ -72,6 +72,7 @@ obj-y += vendor_extensions/
>> obj-y += probes/
>> obj-y += tests/
>> obj-$(CONFIG_MMU) += vdso.o vdso/
>> +obj-$(CONFIG_RISCV_USER_CFI) += vdso_cfi/
>>
>> obj-$(CONFIG_RISCV_MISALIGNED) += traps_misaligned.o
>> obj-$(CONFIG_RISCV_MISALIGNED) += unaligned_access_speed.o
>> diff --git a/arch/riscv/kernel/vdso.c b/arch/riscv/kernel/vdso.c
>> index 3a8e038b10a2..bf080e519101 100644
>> --- a/arch/riscv/kernel/vdso.c
>> +++ b/arch/riscv/kernel/vdso.c
>> @@ -98,6 +98,13 @@ static struct __vdso_info compat_vdso_info __ro_after_init = {
>>
>> static int __init vdso_init(void)
>> {
>> + /* Hart implements zimop, expose cfi compiled vdso */
>> + if (IS_ENABLED(CONFIG_RISCV_USER_CFI) &&
>> + riscv_has_extension_unlikely(RISCV_ISA_EXT_ZIMOP)) {
>> + vdso_info.vdso_code_start = vdso_cfi_start;
>> + vdso_info.vdso_code_end = vdso_cfi_end;
>> + }
>> +
>> __vdso_init(&vdso_info);
>> #ifdef CONFIG_COMPAT
>> __vdso_init(&compat_vdso_info);
>> diff --git a/arch/riscv/kernel/vdso/Makefile b/arch/riscv/kernel/vdso/Makefile
>> index 272f1d837a80..a842dc034571 100644
>> --- a/arch/riscv/kernel/vdso/Makefile
>> +++ b/arch/riscv/kernel/vdso/Makefile
>> @@ -20,6 +20,10 @@ endif
>> ifdef VDSO_CFI_BUILD
>> CFI_MARCH = _zicfilp_zicfiss
>> CFI_FULL = -fcf-protection=full
>> +CFI_SUFFIX = -cfi
>> +OFFSET_SUFFIX = _cfi
>> +ccflags-y += -DVDSO_CFI=1
>> +asflags-y += -DVDSO_CFI=1
>> endif
>>
>> # Files to link into the vdso
>> @@ -48,13 +52,20 @@ endif
>> CFLAGS_hwprobe.o += -fPIC
>>
>> # Build rules
>> -targets := $(obj-vdso) vdso.so vdso.so.dbg vdso.lds
>> +vdso_offsets := vdso$(if $(VDSO_CFI_BUILD),$(CFI_SUFFIX),)-offsets.h
>> +vdso_o := vdso$(if $(VDSO_CFI_BUILD),$(CFI_SUFFIX),).o
>> +vdso_so := vdso$(if $(VDSO_CFI_BUILD),$(CFI_SUFFIX),).so
>> +vdso_so_dbg := vdso$(if $(VDSO_CFI_BUILD),$(CFI_SUFFIX),).so.dbg
>> +vdso_lds := vdso.lds
>> +
>> +targets := $(obj-vdso) $(vdso_so) $(vdso_so_dbg) $(vdso_lds)
>> +
>> obj-vdso := $(addprefix $(obj)/, $(obj-vdso))
>>
>> -obj-y += vdso.o
>> -CPPFLAGS_vdso.lds += -P -C -U$(ARCH)
>> +obj-y += vdso$(if $(VDSO_CFI_BUILD),$(CFI_SUFFIX),).o
>> +CPPFLAGS_$(vdso_lds) += -P -C -U$(ARCH)
>> ifneq ($(filter vgettimeofday, $(vdso-syms)),)
>> -CPPFLAGS_vdso.lds += -DHAS_VGETTIMEOFDAY
>> +CPPFLAGS_$(vdso_lds) += -DHAS_VGETTIMEOFDAY
>> endif
>>
>> # Disable -pg to prevent insert call site
>> @@ -63,12 +74,12 @@ CFLAGS_REMOVE_getrandom.o = $(CC_FLAGS_FTRACE) $(CC_FLAGS_SCS)
>> CFLAGS_REMOVE_hwprobe.o = $(CC_FLAGS_FTRACE) $(CC_FLAGS_SCS)
>>
>> # Force dependency
>> -$(obj)/vdso.o: $(obj)/vdso.so
>> +$(obj)/$(vdso_o): $(obj)/$(vdso_so)
>>
>> # link rule for the .so file, .lds has to be first
>> -$(obj)/vdso.so.dbg: $(obj)/vdso.lds $(obj-vdso) FORCE
>> +$(obj)/$(vdso_so_dbg): $(obj)/$(vdso_lds) $(obj-vdso) FORCE
>> $(call if_changed,vdsold_and_check)
>> -LDFLAGS_vdso.so.dbg = -shared -soname=linux-vdso.so.1 \
>> +LDFLAGS_$(vdso_so_dbg) = -shared -soname=linux-vdso.so.1 \
>> --build-id=sha1 --eh-frame-hdr
>>
>> # strip rule for the .so file
>> @@ -79,9 +90,9 @@ $(obj)/%.so: $(obj)/%.so.dbg FORCE
>> # Generate VDSO offsets using helper script
>> gen-vdsosym := $(src)/gen_vdso_offsets.sh
>> quiet_cmd_vdsosym = VDSOSYM $@
>> - cmd_vdsosym = $(NM) $< | $(gen-vdsosym) | LC_ALL=C sort > $@
>> + cmd_vdsosym = $(NM) $< | $(gen-vdsosym) $(OFFSET_SUFFIX) | LC_ALL=C sort > $@
>>
>> -include/generated/vdso-offsets.h: $(obj)/vdso.so.dbg FORCE
>> +include/generated/$(vdso_offsets): $(obj)/$(vdso_so_dbg) FORCE
>> $(call if_changed,vdsosym)
>>
>> # actual build commands
>> diff --git a/arch/riscv/kernel/vdso/gen_vdso_offsets.sh b/arch/riscv/kernel/vdso/gen_vdso_offsets.sh
>> index c2e5613f3495..bd5d5afaaa14 100755
>> --- a/arch/riscv/kernel/vdso/gen_vdso_offsets.sh
>> +++ b/arch/riscv/kernel/vdso/gen_vdso_offsets.sh
>> @@ -2,4 +2,6 @@
>> # SPDX-License-Identifier: GPL-2.0
>>
>> LC_ALL=C
>> -sed -n -e 's/^[0]\+\(0[0-9a-fA-F]*\) . \(__vdso_[a-zA-Z0-9_]*\)$/\#define \2_offset\t0x\1/p'
>> +SUFFIX=${1:-""}
>> +sed -n -e \
>> +'s/^[0]\+\(0[0-9a-fA-F]*\) . \(__vdso_[a-zA-Z0-9_]*\)$/\#define \2'$SUFFIX'_offset\t0x\1/p'
>> diff --git a/arch/riscv/kernel/vdso_cfi/Makefile b/arch/riscv/kernel/vdso_cfi/Makefile
>> new file mode 100644
>> index 000000000000..8ebd190782b0
>> --- /dev/null
>> +++ b/arch/riscv/kernel/vdso_cfi/Makefile
>> @@ -0,0 +1,25 @@
>> +# SPDX-License-Identifier: GPL-2.0-only
>> +# RISC-V VDSO CFI Makefile
>> +# This Makefile builds the VDSO with CFI support when CONFIG_RISCV_USER_CFI is enabled
>> +
>> +# setting VDSO_CFI_BUILD triggers build for vdso differently
>> +VDSO_CFI_BUILD := 1
>> +
>> +# Set the source directory to the main vdso directory
>> +src := $(srctree)/arch/riscv/kernel/vdso
>> +
>> +# Copy all .S and .c files from vdso directory to vdso_cfi object build directory
>> +vdso_c_sources := $(wildcard $(src)/*.c)
>> +vdso_S_sources := $(wildcard $(src)/*.S)
>> +vdso_c_objects := $(addprefix $(obj)/, $(notdir $(vdso_c_sources)))
>> +vdso_S_objects := $(addprefix $(obj)/, $(notdir $(vdso_S_sources)))
>> +
>> +$(vdso_S_objects): $(obj)/%.S: $(src)/%.S
>> + $(Q)cp $< $@
>> +
>> +$(vdso_c_objects): $(obj)/%.c: $(src)/%.c
>> + $(Q)cp $< $@
>> +
>> +# Include the main VDSO Makefile which contains all the build rules and sources
>> +# The VDSO_CFI_BUILD variable will be passed to it to enable CFI compilation
>> +include $(src)/Makefile
>> diff --git a/arch/riscv/kernel/vdso_cfi/vdso-cfi.S b/arch/riscv/kernel/vdso_cfi/vdso-cfi.S
>> new file mode 100644
>> index 000000000000..d426f6accb35
>> --- /dev/null
>> +++ b/arch/riscv/kernel/vdso_cfi/vdso-cfi.S
>> @@ -0,0 +1,11 @@
>> +/* SPDX-License-Identifier: GPL-2.0-only */
>> +/*
>> + * Copyright 2025 Rivos, Inc
>> + */
>> +
>> +#define vdso_start vdso_cfi_start
>> +#define vdso_end vdso_cfi_end
>> +
>> +#define __VDSO_PATH "arch/riscv/kernel/vdso_cfi/vdso-cfi.so"
>> +
>> +#include "../vdso/vdso.S"
>>
>> --
>> 2.43.0
>>
>>
>> _______________________________________________
>> linux-riscv mailing list
>> linux-riscv@lists.infradead.org
>> http://lists.infradead.org/mailman/listinfo/linux-riscv
>---
>diff --git a/arch/riscv/include/asm/vdso.h b/arch/riscv/include/asm/vdso.h
>index 3fc8f72b8bfb..9cfbb390270f 100644
>--- a/arch/riscv/include/asm/vdso.h
>+++ b/arch/riscv/include/asm/vdso.h
>@@ -18,13 +18,21 @@
>
> #ifndef __ASSEMBLER__
> #include <generated/vdso-offsets.h>
>+#if IS_ENABLED(CONFIG_RISCV_USER_CFI)
>+
> #include <generated/vdso-cfi-offsets.h>
>
> #define VDSO_SYMBOL(base, name) \
>- ((IS_ENABLED(CONFIG_RISCV_USER_CFI) && \
>- riscv_has_extension_unlikely(RISCV_ISA_EXT_ZIMOP)) ? \
>- (void __user *)((unsigned long)(base) + __vdso_##name##_cfi_offset) : \
>- (void __user *)((unsigned long)(base) + __vdso_##name##_offset))
>+ (riscv_has_extension_unlikely(RISCV_ISA_EXT_ZIMOP)) ? \
>+ (void __user *)((unsigned long)(base) + __vdso_##name##_cfi_offset) : \
>+ (void __user *)((unsigned long)(base) + __vdso_##name##_offset)
>+
>+#else /* !CONFIG_RISCV_USER_CFI */
>+
>+#define VDSO_SYMBOL(base, name) \
>+ (void __user *)((unsigned long)(base) + __vdso_##name##_offset)
>+
>+#endif /* CONFIG_RISCV_USER_CFI */
>
> #ifdef CONFIG_COMPAT
> #include <generated/compat_vdso-offsets.h>
>
_______________________________________________
linux-riscv mailing list
linux-riscv@lists.infradead.org
http://lists.infradead.org/mailman/listinfo/linux-riscv
next prev parent reply other threads:[~2025-10-15 20:57 UTC|newest]
Thread overview: 69+ messages / expand[flat|nested] mbox.gz Atom feed top
2025-10-13 21:55 [PATCH v20 00/28] riscv control-flow integrity for usermode Deepak Gupta
2025-10-13 21:55 ` Deepak Gupta
2025-10-13 21:55 ` [PATCH v20 01/28] mm: VM_SHADOW_STACK definition for riscv Deepak Gupta
2025-10-13 21:55 ` Deepak Gupta
2025-10-13 21:55 ` [PATCH v20 02/28] dt-bindings: riscv: zicfilp and zicfiss in dt-bindings (extensions.yaml) Deepak Gupta
2025-10-13 21:55 ` Deepak Gupta
2025-10-13 21:55 ` [PATCH v20 03/28] riscv: zicfiss / zicfilp enumeration Deepak Gupta
2025-10-13 21:55 ` Deepak Gupta
2025-10-13 21:55 ` [PATCH v20 04/28] riscv: zicfiss / zicfilp extension csr and bit definitions Deepak Gupta
2025-10-13 21:55 ` Deepak Gupta
2025-10-13 21:55 ` [PATCH v20 05/28] riscv: usercfi state for task and save/restore of CSR_SSP on trap entry/exit Deepak Gupta
2025-10-13 21:55 ` Deepak Gupta
2025-10-13 21:55 ` [PATCH v20 06/28] riscv/mm : ensure PROT_WRITE leads to VM_READ | VM_WRITE Deepak Gupta
2025-10-13 21:55 ` Deepak Gupta
2025-10-13 21:55 ` [PATCH v20 07/28] riscv/mm: manufacture shadow stack pte Deepak Gupta
2025-10-13 21:55 ` Deepak Gupta
2025-10-13 21:56 ` [PATCH v20 08/28] riscv/mm: teach pte_mkwrite to manufacture shadow stack PTEs Deepak Gupta
2025-10-13 21:56 ` Deepak Gupta
2025-10-13 21:56 ` [PATCH v20 09/28] riscv/mm: write protect and shadow stack Deepak Gupta
2025-10-13 21:56 ` Deepak Gupta
2025-10-13 21:56 ` [PATCH v20 10/28] riscv/mm: Implement map_shadow_stack() syscall Deepak Gupta
2025-10-13 21:56 ` Deepak Gupta
2025-10-13 21:56 ` [PATCH v20 11/28] riscv/shstk: If needed allocate a new shadow stack on clone Deepak Gupta
2025-10-13 21:56 ` Deepak Gupta
2025-10-13 21:56 ` [PATCH v20 12/28] riscv: Implements arch agnostic shadow stack prctls Deepak Gupta
2025-10-13 21:56 ` Deepak Gupta
2025-10-13 21:56 ` [PATCH v20 13/28] prctl: arch-agnostic prctl for indirect branch tracking Deepak Gupta
2025-10-13 21:56 ` Deepak Gupta
2025-10-13 21:56 ` [PATCH v20 14/28] riscv: Implements arch agnostic indirect branch tracking prctls Deepak Gupta
2025-10-13 21:56 ` Deepak Gupta
2025-10-13 21:56 ` [PATCH v20 15/28] riscv/traps: Introduce software check exception and uprobe handling Deepak Gupta
2025-10-13 21:56 ` Deepak Gupta
2025-10-13 21:56 ` [PATCH v20 16/28] riscv: signal: abstract header saving for setup_sigcontext Deepak Gupta
2025-10-13 21:56 ` Deepak Gupta
2025-10-13 21:56 ` [PATCH v20 17/28] riscv/signal: save and restore of shadow stack for signal Deepak Gupta
2025-10-13 21:56 ` Deepak Gupta
2025-10-13 21:56 ` [PATCH v20 18/28] riscv/kernel: update __show_regs to print shadow stack register Deepak Gupta
2025-10-13 21:56 ` Deepak Gupta
2025-10-13 21:56 ` [PATCH v20 19/28] riscv/ptrace: riscv cfi status and state via ptrace and in core files Deepak Gupta
2025-10-13 21:56 ` Deepak Gupta
2025-10-13 21:56 ` [PATCH v20 20/28] riscv/hwprobe: zicfilp / zicfiss enumeration in hwprobe Deepak Gupta
2025-10-13 21:56 ` Deepak Gupta
2025-10-13 21:56 ` [PATCH v20 21/28] riscv: kernel command line option to opt out of user cfi Deepak Gupta
2025-10-13 21:56 ` Deepak Gupta
2025-10-13 21:56 ` [PATCH v20 22/28] riscv: enable kernel access to shadow stack memory via FWFT sbi call Deepak Gupta
2025-10-13 21:56 ` Deepak Gupta
2025-10-13 21:56 ` [PATCH v20 23/28] arch/riscv: compile vdso with landing pad and shadow stack note Deepak Gupta
2025-10-13 21:56 ` Deepak Gupta
2025-10-13 21:56 ` [PATCH v20 24/28] arch/riscv: dual vdso creation logic and select vdso based on hw Deepak Gupta
2025-10-13 21:56 ` Deepak Gupta
2025-10-15 3:54 ` kernel test robot
2025-10-15 20:36 ` Charles Mirabile
2025-10-15 20:36 ` Charles Mirabile
2025-10-15 20:56 ` Deepak Gupta [this message]
2025-10-15 20:56 ` Deepak Gupta
2025-10-16 8:32 ` Zong Li
2025-10-16 8:32 ` Zong Li
2025-10-16 15:32 ` Deepak Gupta
2025-10-16 15:32 ` Deepak Gupta
2025-10-13 21:56 ` [PATCH v20 25/28] riscv: create a config for shadow stack and landing pad instr support Deepak Gupta
2025-10-13 21:56 ` Deepak Gupta
2025-10-13 21:56 ` [PATCH v20 26/28] riscv: Documentation for landing pad / indirect branch tracking Deepak Gupta
2025-10-13 21:56 ` Deepak Gupta
2025-10-13 21:56 ` [PATCH v20 27/28] riscv: Documentation for shadow stack on riscv Deepak Gupta
2025-10-13 21:56 ` Deepak Gupta
2025-10-13 21:56 ` [PATCH v20 28/28] kselftest/riscv: kselftest for user mode cfi Deepak Gupta
2025-10-13 21:56 ` Deepak Gupta
2025-10-14 17:03 ` [PATCH v20 00/28] riscv control-flow integrity for usermode Deepak Gupta
2025-10-14 17:03 ` Deepak Gupta
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=aPAKmCwDeXXvU7VD@debug.ba.rivosinc.com \
--to=debug@rivosinc.com \
--cc=Liam.Howlett@oracle.com \
--cc=a.hindborg@kernel.org \
--cc=akpm@linux-foundation.org \
--cc=alex.gaynor@gmail.com \
--cc=alexghiti@rivosinc.com \
--cc=aliceryhl@google.com \
--cc=alistair.francis@wdc.com \
--cc=andybnac@gmail.com \
--cc=aou@eecs.berkeley.edu \
--cc=arnd@arndb.de \
--cc=atishp@rivosinc.com \
--cc=bjorn3_gh@protonmail.com \
--cc=boqun.feng@gmail.com \
--cc=bp@alien8.de \
--cc=brauner@kernel.org \
--cc=broonie@kernel.org \
--cc=charlie@rivosinc.com \
--cc=cleger@rivosinc.com \
--cc=cmirabil@redhat.com \
--cc=conor+dt@kernel.org \
--cc=conor@kernel.org \
--cc=corbet@lwn.net \
--cc=dave.hansen@linux.intel.com \
--cc=devicetree@vger.kernel.org \
--cc=ebiederm@xmission.com \
--cc=evan@rivosinc.com \
--cc=gary@garyguo.net \
--cc=hpa@zytor.com \
--cc=jannh@google.com \
--cc=jim.shu@sifive.com \
--cc=kees@kernel.org \
--cc=kito.cheng@sifive.com \
--cc=krzk+dt@kernel.org \
--cc=linux-arch@vger.kernel.org \
--cc=linux-doc@vger.kernel.org \
--cc=linux-fsdevel@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-kselftest@vger.kernel.org \
--cc=linux-mm@kvack.org \
--cc=linux-riscv@lists.infradead.org \
--cc=lorenzo.stoakes@oracle.com \
--cc=lossin@kernel.org \
--cc=mingo@redhat.com \
--cc=ojeda@kernel.org \
--cc=oleg@redhat.com \
--cc=palmer@dabbelt.com \
--cc=paul.walmsley@sifive.com \
--cc=peterz@infradead.org \
--cc=richard.henderson@linaro.org \
--cc=rick.p.edgecombe@intel.com \
--cc=robh@kernel.org \
--cc=rust-for-linux@vger.kernel.org \
--cc=samitolvanen@google.com \
--cc=shuah@kernel.org \
--cc=tglx@linutronix.de \
--cc=tmgross@umich.edu \
--cc=vbabka@suse.cz \
--cc=x86@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.