BPF List
 help / color / mirror / Atom feed
From: Nathan Chancellor <nathan@kernel.org>
To: Heiko Carstens <hca@linux.ibm.com>
Cc: Stefan Schulze Frielinghaus <stefansf@linux.ibm.com>,
	Juergen Christ <jchrist@linux.ibm.com>,
	Ilya Leoshkevich <iii@linux.ibm.com>,
	Dominik Steenken <dost@de.ibm.com>,
	Alexander Gordeev <agordeev@linux.ibm.com>,
	Sven Schnelle <svens@linux.ibm.com>,
	Vasily Gorbik <gor@linux.ibm.com>,
	Christian Borntraeger <borntraeger@linux.ibm.com>,
	Maxim Khmelevskii <max@linux.ibm.com>,
	Jens Remus <jremus@linux.ibm.com>,
	Sami Tolvanen <samitolvanen@google.com>,
	Kees Cook <kees@kernel.org>, Alexei Starovoitov <ast@kernel.org>,
	Daniel Borkmann <daniel@iogearbox.net>,
	Andrii Nakryiko <andrii@kernel.org>,
	Eduard Zingerman <eddyz87@gmail.com>,
	Kumar Kartikeya Dwivedi <memxor@gmail.com>,
	llvm@lists.linux.dev, bpf@vger.kernel.org,
	linux-s390@vger.kernel.org, linux-kernel@vger.kernel.org
Subject: Re: [PATCH v2 0/6] s390: Add kCFI support
Date: Thu, 30 Jul 2026 16:13:17 -0700	[thread overview]
Message-ID: <20260730231317.GA2423962@ax162> (raw)
In-Reply-To: <20260727140514.116501-1-hca@linux.ibm.com>

On Mon, Jul 27, 2026 at 04:05:07PM +0200, Heiko Carstens wrote:
> v2:
> - Select ARCH_USES_CFI_GENERIC_LLVM_PASS [Nathan Chancellor]
> - Add CONFIG_FUNCTION_GRAPH_TRACER guard to ftrace stub [bot+bpf-ci]
> - Add additional CFI offset adjustments to bpf code [sashiko-bot]
> - Move bpf patch before ARCH_SUPPORTS_CFI is selected, since there are
>   functions with missing __bpfcall atttribute [sashiko-bot]
> 
> v1:
> Add s390 kCFI support using the generic support provided by clang.
> This comes with a couple of limitations:
> 
> The generic kCFI implementation does not generate a .kcfi_traps section,
> nor is a special instruction used in case a checksum mismatch is detected.
> 
> This means in case of a checksum mismatch the kernel just crashes.
> It should be quite easy to tell by the surrounding code that a crash
> happened because of a checksum mismatch.
> 
> If clang and/or gcc provide a .kcfi_traps section it will be possible to
> print proper CFI messages instead of just crashing the kernel (enable
> ARCH_USES_CFI_TRAPS).
> 
> In addition this also means that CFI_PERMISSIVE does not work. Even if the
> option is selected the kernel will crash in case of a checksum mismatch.
> 
> However it seems to be acceptable to enable kCFI support to the kernel now
> even if it is not perfect. Later s390 specific clang and gcc extensions are
> required to improve this.

Yes, getting coverage over s390 specific code and drivers is worthwhile,
even if there is no architecture specific expansion available yet, since
most problems should be visible with either implementation. Getting that
sooner rather than later would be nice to avoid the panic when a CFI
check fails and make debugging easier but we will take what we can get.

I tested clang-18 and clang-23 with defconfig + CFI, which both properly
fails the CFI_FORWARD_PROTO LKDTM test. I built allmodconfig (which now
includes CFI=y) with both compilers, which showed no issues.

Tested-by: Nathan Chancellor <nathan@kernel.org>

-- 
Cheers,
Nathan

  parent reply	other threads:[~2026-07-30 23:13 UTC|newest]

Thread overview: 17+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-07-27 14:05 [PATCH v2 0/6] s390: Add kCFI support Heiko Carstens
2026-07-27 14:05 ` [PATCH v2 1/6] s390/tools: Pass symbol name to do_relocs() Heiko Carstens
2026-07-27 14:39   ` sashiko-bot
2026-07-27 14:05 ` [PATCH v2 2/6] s390/tools/relocs: Ignore __kcfi_typeid_ relocations Heiko Carstens
2026-07-27 14:36   ` sashiko-bot
2026-07-27 14:05 ` [PATCH v2 3/6] s390: Add ftrace_stub_graph Heiko Carstens
2026-07-27 14:40   ` sashiko-bot
2026-07-27 14:05 ` [PATCH v2 4/6] s390/diag: Generate CFI type information for assembly functions Heiko Carstens
2026-07-27 14:38   ` sashiko-bot
2026-07-27 14:05 ` [PATCH v2 5/6] s390/bpf: Add kCFI support Heiko Carstens
2026-07-27 14:47   ` sashiko-bot
2026-07-27 15:37   ` Ilya Leoshkevich
2026-07-29 12:10   ` Heiko Carstens
2026-07-27 14:05 ` [PATCH v2 6/6] s390/Kconfig: Select ARCH_SUPPORTS_CFI Heiko Carstens
2026-07-27 14:39   ` sashiko-bot
2026-07-30 23:13 ` Nathan Chancellor [this message]
2026-07-30 23:40 ` [PATCH v2 0/6] s390: Add kCFI support Kees Cook

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260730231317.GA2423962@ax162 \
    --to=nathan@kernel.org \
    --cc=agordeev@linux.ibm.com \
    --cc=andrii@kernel.org \
    --cc=ast@kernel.org \
    --cc=borntraeger@linux.ibm.com \
    --cc=bpf@vger.kernel.org \
    --cc=daniel@iogearbox.net \
    --cc=dost@de.ibm.com \
    --cc=eddyz87@gmail.com \
    --cc=gor@linux.ibm.com \
    --cc=hca@linux.ibm.com \
    --cc=iii@linux.ibm.com \
    --cc=jchrist@linux.ibm.com \
    --cc=jremus@linux.ibm.com \
    --cc=kees@kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-s390@vger.kernel.org \
    --cc=llvm@lists.linux.dev \
    --cc=max@linux.ibm.com \
    --cc=memxor@gmail.com \
    --cc=samitolvanen@google.com \
    --cc=stefansf@linux.ibm.com \
    --cc=svens@linux.ibm.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox