From: Josh Poimboeuf <jpoimboe@redhat.com>
To: Thomas Gleixner <tglx@linutronix.de>,
Ingo Molnar <mingo@redhat.com>, "H. Peter Anvin" <hpa@zytor.com>
Cc: Michal Marek <mmarek@suse.cz>,
Peter Zijlstra <peterz@infradead.org>,
Andy Lutomirski <luto@kernel.org>, Borislav Petkov <bp@alien8.de>,
Linus Torvalds <torvalds@linux-foundation.org>,
Andi Kleen <andi@firstfloor.org>, Pedro Alves <palves@redhat.com>,
x86@kernel.org, live-patching@vger.kernel.org,
linux-kernel@vger.kernel.org
Subject: [PATCH v7 0/4] Compile-time stack validation
Date: Tue, 14 Jul 2015 12:14:06 -0500 [thread overview]
Message-ID: <cover.1436893563.git.jpoimboe@redhat.com> (raw)
This is v7 of the compile-time stack validation patch set, based on the
tip/master branch.
v6, which had a lot of major changes, can be found here:
https://lkml.kernel.org/r/cover.1436280380.git.jpoimboe@redhat.com
For more information about the motivation behind this patch set, and
more details about what it does, please see the changelog in patch 2.
To reduce churn, I didn't bother posting any patches to fix warnings.
If there's agreement on this approach, I can start proposing fixes.
Posting a listing of reported warnings in a reply to this email.
v7:
- sibling call support
- document proposed solution for inline asm() frame pointer issues
- say "kernel entry/exit" instead of "context switch"
- clarify the checking of switch statement jump tables
- discard __stackvalidate_ignore_* sections in linker script
- use .Ltemp_\@ to get a unique label instead of static 3-digit number
- change STACKVALIDATE_IGNORE_FUNC variable to a static
- move STACKVALIDATE_IGNORE_INSN to arch-specific .h file
v6:
- rename asmvalidate -> stackvalidate (again)
- gcc-generated object file support
- recursive branch state analysis
- external jump support
- fixup/exception table support
- jump label support
- switch statement jump table support
- added documentation
- detection of "noreturn" dead end functions
- added a Kbuild mechanism for skipping files and dirs
- moved frame pointer macros to arch/x86/include/asm/frame.h
- moved ignore macros to include/linux/stackvalidate.h
v5:
- stackvalidate -> asmvalidate
- frame pointers only required for non-leaf functions
- check for the use of the FP_SAVE/RESTORE macros instead of manually
analyzing code to detect frame pointer usage
- additional checks to ensure each function doesn't leave its boundaries
- make the macros simpler and more flexible
- support for analyzing ALTERNATIVE macros
- simplified the arch interfaces in scripts/asmvalidate/arch.h
- fixed some asmvalidate warnings
- rebased onto latest tip asm cleanups
- many more small changes
v4:
- Changed the default to CONFIG_STACK_VALIDATION=n, until all the asm
code can get cleaned up.
- Fixed a stackvalidate error path exit code issue found by Michal
Marek.
v3:
- Added a patch to make the push/pop CFI macros arch-independent, as
suggested by H. Peter Anvin
v2:
- Fixed memory leaks reported by Petr Mladek
Josh Poimboeuf (4):
x86/asm: Frame pointer macro cleanup
x86/stackvalidate: Compile-time stack validation
x86/stackvalidate: Add file and directory ignores
x86/stackvalidate: Add ignore macros
Documentation/stack-validation.txt | 193 ++++++++
MAINTAINERS | 8 +
arch/Kconfig | 6 +
arch/x86/Kconfig | 1 +
arch/x86/Makefile | 6 +-
arch/x86/boot/Makefile | 3 +-
arch/x86/boot/compressed/Makefile | 3 +-
arch/x86/entry/vdso/Makefile | 5 +-
arch/x86/include/asm/frame.h | 37 +-
arch/x86/include/asm/stackvalidate.h | 28 ++
arch/x86/kernel/vmlinux.lds.S | 5 +-
arch/x86/purgatory/Makefile | 2 +
arch/x86/realmode/Makefile | 4 +-
arch/x86/realmode/rm/Makefile | 3 +-
drivers/firmware/efi/libstub/Makefile | 1 +
include/linux/stackvalidate.h | 21 +
lib/Kconfig.debug | 11 +
scripts/Makefile | 1 +
scripts/Makefile.build | 34 +-
scripts/stackvalidate/Makefile | 24 +
scripts/stackvalidate/arch-x86.c | 148 ++++++
scripts/stackvalidate/arch.h | 44 ++
scripts/stackvalidate/elf.c | 422 ++++++++++++++++
scripts/stackvalidate/elf.h | 85 ++++
scripts/stackvalidate/list.h | 217 +++++++++
scripts/stackvalidate/special.c | 177 +++++++
scripts/stackvalidate/special.h | 40 ++
scripts/stackvalidate/stackvalidate.c | 881 ++++++++++++++++++++++++++++++++++
28 files changed, 2382 insertions(+), 28 deletions(-)
create mode 100644 Documentation/stack-validation.txt
create mode 100644 arch/x86/include/asm/stackvalidate.h
create mode 100644 include/linux/stackvalidate.h
create mode 100644 scripts/stackvalidate/Makefile
create mode 100644 scripts/stackvalidate/arch-x86.c
create mode 100644 scripts/stackvalidate/arch.h
create mode 100644 scripts/stackvalidate/elf.c
create mode 100644 scripts/stackvalidate/elf.h
create mode 100644 scripts/stackvalidate/list.h
create mode 100644 scripts/stackvalidate/special.c
create mode 100644 scripts/stackvalidate/special.h
create mode 100644 scripts/stackvalidate/stackvalidate.c
--
2.1.0
next reply other threads:[~2015-07-14 17:14 UTC|newest]
Thread overview: 89+ messages / expand[flat|nested] mbox.gz Atom feed top
2015-07-14 17:14 Josh Poimboeuf [this message]
2015-07-14 17:14 ` [PATCH v7 1/4] x86/asm: Frame pointer macro cleanup Josh Poimboeuf
2015-07-14 17:14 ` [PATCH v7 2/4] x86/stackvalidate: Compile-time stack validation Josh Poimboeuf
2015-07-14 20:57 ` Peter Zijlstra
2015-07-14 21:11 ` Josh Poimboeuf
2015-07-14 21:08 ` Peter Zijlstra
2015-07-14 21:30 ` Josh Poimboeuf
2015-07-14 21:56 ` Peter Zijlstra
2015-07-14 22:32 ` Josh Poimboeuf
2015-07-20 16:53 ` Namhyung Kim
2015-07-20 17:50 ` Josh Poimboeuf
2015-07-21 8:02 ` Ingo Molnar
2015-07-21 12:04 ` Josh Poimboeuf
2015-07-21 8:42 ` Bernd Petrovitsch
2015-07-21 12:06 ` Josh Poimboeuf
2015-07-14 17:14 ` [PATCH v7 3/4] x86/stackvalidate: Add file and directory ignores Josh Poimboeuf
2015-07-14 17:14 ` [PATCH v7 4/4] x86/stackvalidate: Add ignore macros Josh Poimboeuf
2015-07-14 17:25 ` [PATCH v7 0/4] Compile-time stack validation Josh Poimboeuf
2015-07-15 10:16 ` Ingo Molnar
2015-07-15 16:05 ` Josh Poimboeuf
2015-07-17 16:47 ` [RFC PATCH 00/21] x86: Proposed fixes for stackvalidate warnings Josh Poimboeuf
2015-07-17 16:47 ` [RFC PATCH 01/21] stackvalidate: Process ignores earlier and add more ignore checks Josh Poimboeuf
2015-07-17 16:47 ` [RFC PATCH 02/21] stackvalidate: Add C version of STACKVALIDATE_IGNORE_INSN Josh Poimboeuf
2015-07-18 14:56 ` Borislav Petkov
2015-07-18 16:00 ` Josh Poimboeuf
[not found] ` <CA+55aFyoO75n-mQBrB_YBLx9yNpAjisFAqkO8+YsphD-xmgY+w@mail.gmail.com>
2015-07-18 16:40 ` Josh Poimboeuf
2015-07-17 16:47 ` [RFC PATCH 03/21] x86/asm: Add C versions of FRAME and ENDFRAME macros Josh Poimboeuf
2015-07-17 16:47 ` [RFC PATCH 04/21] x86/hweight: Add stack frame dependency for __arch_hweight*() Josh Poimboeuf
2015-07-17 17:17 ` Borislav Petkov
2015-07-17 17:32 ` Josh Poimboeuf
2015-07-18 5:05 ` Borislav Petkov
2015-07-18 13:44 ` Josh Poimboeuf
2015-07-18 14:56 ` Borislav Petkov
2015-07-18 15:57 ` Josh Poimboeuf
2015-07-19 4:12 ` Borislav Petkov
2015-07-22 0:13 ` Andy Lutomirski
2015-07-22 4:25 ` Borislav Petkov
2015-07-22 4:39 ` Andy Lutomirski
2015-07-22 4:45 ` Borislav Petkov
2015-07-17 16:47 ` [RFC PATCH 05/21] x86/xen: Add stack frame dependency to hypercall inline asm calls Josh Poimboeuf
2015-07-17 16:47 ` [RFC PATCH 06/21] x86/paravirt: Add stack frame dependency to PVOP " Josh Poimboeuf
2015-07-17 16:47 ` [RFC PATCH 07/21] x86/paravirt: Fix frame pointer usage in PV_CALLEE_SAVE_REGS_THUNK Josh Poimboeuf
2015-07-17 16:47 ` [RFC PATCH 08/21] x86/paravirt: Align paravirt thunk functions at 16-byte boundaries Josh Poimboeuf
2015-07-17 16:47 ` [RFC PATCH 09/21] x86/amd: Set ELF function type for vide() Josh Poimboeuf
2015-07-17 16:47 ` [RFC PATCH 10/21] x86/reboot: Add ljmp instructions to stackvalidate whitelist Josh Poimboeuf
2015-07-17 16:47 ` [RFC PATCH 11/21] x86/xen: Add xen_cpuid() and xen_setup_gdt() to stackvalidate whitelists Josh Poimboeuf
2015-07-17 16:47 ` [RFC PATCH 12/21] sched: Add __schedule() to stackvalidate whitelist Josh Poimboeuf
2015-07-17 19:46 ` Peter Zijlstra
2015-07-17 19:58 ` Andy Lutomirski
2015-07-17 21:03 ` Peter Zijlstra
2015-07-17 21:23 ` Josh Poimboeuf
2015-07-18 3:44 ` Ingo Molnar
2015-07-17 16:47 ` [RFC PATCH 13/21] x86/asm/crypto: Fix frame pointer usage in aesni-intel_asm.S Josh Poimboeuf
2015-07-17 19:43 ` Ingo Molnar
2015-07-17 19:44 ` Andy Lutomirski
2015-07-17 20:37 ` Josh Poimboeuf
2015-07-17 20:39 ` Andy Lutomirski
2015-07-17 20:44 ` Josh Poimboeuf
2015-07-17 20:46 ` Andy Lutomirski
2015-07-17 20:59 ` Josh Poimboeuf
2015-07-17 21:01 ` Andy Lutomirski
2015-07-17 21:10 ` Josh Poimboeuf
2015-07-18 8:42 ` Borislav Petkov
2015-07-18 13:46 ` Josh Poimboeuf
2015-07-18 14:25 ` Borislav Petkov
2015-07-18 15:40 ` Josh Poimboeuf
2015-07-18 2:51 ` Ingo Molnar
2015-07-18 3:56 ` Josh Poimboeuf
2015-07-20 7:56 ` Ingo Molnar
2015-07-20 13:59 ` Josh Poimboeuf
2015-07-20 17:21 ` Ingo Molnar
2015-07-20 18:00 ` Josh Poimboeuf
2015-07-22 11:52 ` Josh Poimboeuf
2015-07-20 15:30 ` Andy Lutomirski
2015-07-20 16:36 ` Josh Poimboeuf
2015-07-20 16:52 ` Peter Zijlstra
2015-07-20 17:19 ` Josh Poimboeuf
2015-07-21 8:00 ` Ingo Molnar
2015-07-21 12:06 ` Josh Poimboeuf
2015-07-17 16:47 ` [RFC PATCH 14/21] x86/asm/crypto: Move .Lbswap_mask data to .rodata section Josh Poimboeuf
2015-07-17 16:47 ` [RFC PATCH 15/21] x86/asm/crypto: Move jump_table " Josh Poimboeuf
2015-07-17 16:47 ` [RFC PATCH 16/21] x86/asm/crypto: Fix frame pointer usage in clmul_ghash_mul/update() Josh Poimboeuf
2015-07-17 16:47 ` [RFC PATCH 17/21] x86/asm/entry: Fix frame pointer usage in thunk functions Josh Poimboeuf
2015-07-17 16:47 ` [RFC PATCH 18/21] x86/asm/acpi: Fix frame pointer usage in do_suspend_lowlevel() Josh Poimboeuf
2015-07-17 16:47 ` [RFC PATCH 19/21] x86/asm: Fix frame pointer usage in rwsem functions Josh Poimboeuf
2015-07-17 16:47 ` [RFC PATCH 20/21] x86/asm/efi: Fix frame pointer usage in efi_call() Josh Poimboeuf
2015-07-17 16:47 ` [RFC PATCH 21/21] x86/asm/power: Fix frame pointer usage in hibernate_asm_64.S Josh Poimboeuf
2015-07-17 18:56 ` [RFC PATCH 00/21] x86: Proposed fixes for stackvalidate warnings Andy Lutomirski
2015-07-18 3:05 ` Ingo Molnar
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=cover.1436893563.git.jpoimboe@redhat.com \
--to=jpoimboe@redhat.com \
--cc=andi@firstfloor.org \
--cc=bp@alien8.de \
--cc=hpa@zytor.com \
--cc=linux-kernel@vger.kernel.org \
--cc=live-patching@vger.kernel.org \
--cc=luto@kernel.org \
--cc=mingo@redhat.com \
--cc=mmarek@suse.cz \
--cc=palves@redhat.com \
--cc=peterz@infradead.org \
--cc=tglx@linutronix.de \
--cc=torvalds@linux-foundation.org \
--cc=x86@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.