From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org X-Spam-Level: X-Spam-Status: No, score=-13.8 required=3.0 tests=BAYES_00,DKIMWL_WL_HIGH, DKIM_SIGNED,DKIM_VALID,HEADER_FROM_DIFFERENT_DOMAINS,INCLUDES_CR_TRAILER, INCLUDES_PATCH,MAILING_LIST_MULTI,SPF_HELO_NONE,SPF_PASS autolearn=unavailable autolearn_force=no version=3.4.0 Received: from mail.kernel.org (mail.kernel.org [198.145.29.99]) by smtp.lore.kernel.org (Postfix) with ESMTP id 872C8C433ED for ; Tue, 6 Apr 2021 11:59:07 +0000 (UTC) Received: from desiato.infradead.org (desiato.infradead.org [90.155.92.199]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mail.kernel.org (Postfix) with ESMTPS id C3A5D611AF for ; Tue, 6 Apr 2021 11:59:06 +0000 (UTC) DMARC-Filter: OpenDMARC Filter v1.3.2 mail.kernel.org C3A5D611AF Authentication-Results: mail.kernel.org; dmarc=fail (p=none dis=none) header.from=arm.com Authentication-Results: mail.kernel.org; spf=none smtp.mailfrom=linux-arm-kernel-bounces+linux-arm-kernel=archiver.kernel.org@lists.infradead.org DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.infradead.org; s=desiato.20200630; h=Sender:Content-Transfer-Encoding :Content-Type:List-Subscribe:List-Help:List-Post:List-Archive: List-Unsubscribe:List-Id:In-Reply-To:MIME-Version:References:Message-ID: Subject:Cc:To:From:Date:Reply-To:Content-ID:Content-Description:Resent-Date: Resent-From:Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:List-Owner; bh=egbHtL6bskuX+Ujlbt4HfXdi8ycnJxQSHhfM3eIwi8o=; b=igFhnVRW/NlUmZ1IlfXKaq6gC dy3vV9mVWOOl3DPDiadY5e07P8jgaX5ZA6/4d5S1/b64EWilnLhYMAjU9wAy6V8evCCoXVLsJwhEX xf6M13U/PfcfJbY6pk7hClAmFD9AL6tAG66kzRci7+tZPDn5SFOdDO9fOukZ7AyiUEC4+XDcZLz6T t6xu6g7lI3DL9SFd1lpd4Zg/wWBf1gg4VYEzvACWs1WxYtISNy7cgC8IQvEX86EBeYGVC63v+umN2 KwzhtN/ui7YZMhY2dd+/OfiMKyB/A+6f8xuy5ZJVwQfWiNwsX9kylgtRM25dRVelxc1jhHT+K6zz8 Q1VvNgh8w==; Received: from localhost ([::1] helo=desiato.infradead.org) by desiato.infradead.org with esmtp (Exim 4.94 #2 (Red Hat Linux)) id 1lTkKL-002T5x-6T; Tue, 06 Apr 2021 11:57:01 +0000 Received: from foss.arm.com ([217.140.110.172]) by desiato.infradead.org with esmtp (Exim 4.94 #2 (Red Hat Linux)) id 1lTkHX-002SKZ-C9 for linux-arm-kernel@lists.infradead.org; Tue, 06 Apr 2021 11:54:11 +0000 Received: from usa-sjc-imap-foss1.foss.arm.com (unknown [10.121.207.14]) by usa-sjc-mx-foss1.foss.arm.com (Postfix) with ESMTP id ACB70113E; Tue, 6 Apr 2021 04:54:05 -0700 (PDT) Received: from C02TD0UTHF1T.local (unknown [172.31.20.19]) by usa-sjc-imap-foss1.foss.arm.com (Postfix) with ESMTPSA id 9F9E23F73D; Tue, 6 Apr 2021 04:54:00 -0700 (PDT) Date: Tue, 6 Apr 2021 12:53:57 +0100 From: Mark Rutland To: Sami Tolvanen , Ard Biesheuvel Cc: Kees Cook , Nathan Chancellor , Nick Desaulniers , Masahiro Yamada , Will Deacon , Jessica Yu , Arnd Bergmann , Tejun Heo , "Paul E. McKenney" , Christoph Hellwig , Peter Zijlstra , Sedat Dilek , Catalin Marinas , bpf@vger.kernel.org, linux-hardening@vger.kernel.org, linux-arch@vger.kernel.org, linux-arm-kernel@lists.infradead.org, linux-kbuild@vger.kernel.org, linux-pci@vger.kernel.org, linux-kernel@vger.kernel.org, clang-built-linux@googlegroups.com, ardb@kernel.org Subject: Re: [PATCH v5 14/18] arm64: add __nocfi to functions that jump to a physical address Message-ID: <20210406115357.GE96480@C02TD0UTHF1T.local> References: <20210401233216.2540591-1-samitolvanen@google.com> <20210401233216.2540591-15-samitolvanen@google.com> MIME-Version: 1.0 Content-Disposition: inline In-Reply-To: <20210401233216.2540591-15-samitolvanen@google.com> X-CRM114-Version: 20100106-BlameMichelson ( TRE 0.8.0 (BSD) ) MR-646709E3 X-CRM114-CacheID: sfid-20210406_125408_183707_1092300C X-CRM114-Status: GOOD ( 25.80 ) X-BeenThere: linux-arm-kernel@lists.infradead.org X-Mailman-Version: 2.1.34 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit Sender: "linux-arm-kernel" Errors-To: linux-arm-kernel-bounces+linux-arm-kernel=archiver.kernel.org@lists.infradead.org [adding Ard for EFI runtime services bits] On Thu, Apr 01, 2021 at 04:32:12PM -0700, Sami Tolvanen wrote: > Disable CFI checking for functions that switch to linear mapping and > make an indirect call to a physical address, since the compiler only > understands virtual addresses and the CFI check for such indirect calls > would always fail. What does physical vs virtual have to do with this? Does the address actually matter, or is this just a general thing that when calling an assembly function we won't have a trampoline that the caller expects? I wonder if we need to do something with asmlinkage here, perhaps? I didn't spot anything in the seriues handling EFI runtime services calls, and I strongly suspect we need to do something for those, unless they're handled implicitly by something else. > Signed-off-by: Sami Tolvanen > Reviewed-by: Kees Cook > --- > arch/arm64/include/asm/mmu_context.h | 2 +- > arch/arm64/kernel/cpu-reset.h | 8 ++++---- > arch/arm64/kernel/cpufeature.c | 2 +- > 3 files changed, 6 insertions(+), 6 deletions(-) > > diff --git a/arch/arm64/include/asm/mmu_context.h b/arch/arm64/include/asm/mmu_context.h > index 386b96400a57..d3cef9133539 100644 > --- a/arch/arm64/include/asm/mmu_context.h > +++ b/arch/arm64/include/asm/mmu_context.h > @@ -119,7 +119,7 @@ static inline void cpu_install_idmap(void) > * Atomically replaces the active TTBR1_EL1 PGD with a new VA-compatible PGD, > * avoiding the possibility of conflicting TLB entries being allocated. > */ > -static inline void cpu_replace_ttbr1(pgd_t *pgdp) > +static inline void __nocfi cpu_replace_ttbr1(pgd_t *pgdp) Given these are inlines, what's the effect when these are inlined into a function that would normally use CFI? Does CFI get supressed for the whole function, or just the bit that got inlined? Is there an attribute that we could place on a function pointer to tell the compiler to not check calls via that pointer? If that existed we'd be able to scope this much more tightly. Thanks, Mark. > { > typedef void (ttbr_replace_func)(phys_addr_t); > extern ttbr_replace_func idmap_cpu_replace_ttbr1; > diff --git a/arch/arm64/kernel/cpu-reset.h b/arch/arm64/kernel/cpu-reset.h > index f3adc574f969..9a7b1262ef17 100644 > --- a/arch/arm64/kernel/cpu-reset.h > +++ b/arch/arm64/kernel/cpu-reset.h > @@ -13,10 +13,10 @@ > void __cpu_soft_restart(unsigned long el2_switch, unsigned long entry, > unsigned long arg0, unsigned long arg1, unsigned long arg2); > > -static inline void __noreturn cpu_soft_restart(unsigned long entry, > - unsigned long arg0, > - unsigned long arg1, > - unsigned long arg2) > +static inline void __noreturn __nocfi cpu_soft_restart(unsigned long entry, > + unsigned long arg0, > + unsigned long arg1, > + unsigned long arg2) > { > typeof(__cpu_soft_restart) *restart; > > diff --git a/arch/arm64/kernel/cpufeature.c b/arch/arm64/kernel/cpufeature.c > index 0b2e0d7b13ec..c2f94a5206e0 100644 > --- a/arch/arm64/kernel/cpufeature.c > +++ b/arch/arm64/kernel/cpufeature.c > @@ -1445,7 +1445,7 @@ static bool unmap_kernel_at_el0(const struct arm64_cpu_capabilities *entry, > } > > #ifdef CONFIG_UNMAP_KERNEL_AT_EL0 > -static void > +static void __nocfi > kpti_install_ng_mappings(const struct arm64_cpu_capabilities *__unused) > { > typedef void (kpti_remap_fn)(int, int, phys_addr_t); > -- > 2.31.0.208.g409f899ff0-goog > _______________________________________________ linux-arm-kernel mailing list linux-arm-kernel@lists.infradead.org http://lists.infradead.org/mailman/listinfo/linux-arm-kernel