From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from vger.kernel.org (vger.kernel.org [23.128.96.18]) by smtp.lore.kernel.org (Postfix) with ESMTP id B8D6AC433FE for ; Wed, 19 Oct 2022 04:48:51 +0000 (UTC) Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S229767AbiJSEst (ORCPT ); Wed, 19 Oct 2022 00:48:49 -0400 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:53740 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S229722AbiJSEsr (ORCPT ); Wed, 19 Oct 2022 00:48:47 -0400 Received: from relay4-d.mail.gandi.net (relay4-d.mail.gandi.net [217.70.183.196]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id 1C72B57BC7 for ; Tue, 18 Oct 2022 21:48:45 -0700 (PDT) Received: (Authenticated sender: joao@overdrivepizza.com) by mail.gandi.net (Postfix) with ESMTPA id 500D6E0003; Wed, 19 Oct 2022 04:48:42 +0000 (UTC) MIME-Version: 1.0 Date: Tue, 18 Oct 2022 21:48:42 -0700 From: Joao Moreira To: Peter Zijlstra Cc: Kees Cook , x86@kernel.org, Sami Tolvanen , linux-kernel@vger.kernel.org, Mark Rutland , Josh Poimboeuf Subject: Re: [PATCH] x86/ibt: Implement FineIBT In-Reply-To: References: <202210181020.79AF7F7@keescook> Message-ID: X-Sender: joao@overdrivepizza.com Content-Type: text/plain; charset=US-ASCII; format=flowed Content-Transfer-Encoding: 7bit Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org >> Is it useful to get the compiler to emit 0xcc with >> -fpatchable-function-entry under any circumstance? I can probably >> change >> that quickly if needed/useful. > > Having it emit 0xcc for the bytes in front of the symbol might be > interesting. It would mean a few kernel changes, but nothing too hard. > > That is, -fpatchable-function-entry=N,M gets us N-M bytes in at the > start of the symbol and M bytes in front of it. The N-M bytes at the > start of the function *are* executed and should obviously not become > 0xcc (GCC keeps them 0x90 while LLVM makes them large NOPs). Uhum, all makes sense. I drafted something here: https://github.com/lvwr/llvm-project/commits/joao/int3 Let me know if this works for you or if there is something that should be tweaked, like adding a specific flag and such. This currently emits 0xcc instead of 0x90 for the nops before the function entry symbol for kernel code on x86-64. It seems to be working (see generated snippet below), but let me know otherwise: Generated with -fpatchable-function-entry=10,5 Disassembly of section .text: 0000000000000000 : 0: cc int3 1: cc int3 2: cc int3 3: cc int3 4: cc int3 0000000000000005 : 5: 0f 1f 44 00 08 nopl 0x8(%rax,%rax,1) a: 41 57 push %r15 c: 41 56 push %r14 ...