From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from bombadil.infradead.org (bombadil.infradead.org [198.137.202.133]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.lore.kernel.org (Postfix) with ESMTPS id EB7D5C433EF for ; Wed, 15 Jun 2022 21:53:09 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.infradead.org; s=bombadil.20210309; h=Sender:Content-Type: Content-Transfer-Encoding:List-Subscribe:List-Help:List-Post:List-Archive: List-Unsubscribe:List-Id:In-Reply-To:MIME-Version:References:Message-ID: Subject:Cc:To:From:Date:Reply-To:Content-ID:Content-Description:Resent-Date: Resent-From:Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:List-Owner; bh=l5s1Yrr0zS8eoo82nTSE0kGi+Ohef1X5ahww3SaVcSM=; b=lk52I8HXHwgVxvjlc4N8OfibfA /cNFiGQkpi6vVhNd+8Yfhr0YUTLHiJhhtXAnn9X0fItj8JTEyo1YEgIzr0ILQwtEZ2J2JFJCXkFTj AjaJ+Ej0MEjT5nb+6WA+Bzo2SPGBT1WwRzVtcewoETY9Uxlu9cjcG3oVxjvrlWoiFfMaTnwDx7V6R TDJpzDRRUbUvatZblQkUmu5hSikHf9xdOcgYxu6iu46MnpG+2XDAYh2LpPAU8dG0FnYO2/v/tE7g7 2UlFrb4LwWHy7F/cLvkwAxvpz90XokxiBd9a5gPXRVPv6ZXLfGl3NJSvq54XCJjDHmOjVj/U0TGB+ 2h0qFM0Q==; Received: from localhost ([::1] helo=bombadil.infradead.org) by bombadil.infradead.org with esmtp (Exim 4.94.2 #2 (Red Hat Linux)) id 1o1avu-00GXJB-1E; Wed, 15 Jun 2022 21:52:14 +0000 Received: from mail-pf1-x429.google.com ([2607:f8b0:4864:20::429]) by bombadil.infradead.org with esmtps (Exim 4.94.2 #2 (Red Hat Linux)) id 1o1avq-00GXG1-M6 for linux-arm-kernel@lists.infradead.org; Wed, 15 Jun 2022 21:52:13 +0000 Received: by mail-pf1-x429.google.com with SMTP id 187so12596490pfu.9 for ; Wed, 15 Jun 2022 14:52:07 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20210112; h=date:from:to:cc:subject:message-id:references:mime-version :content-disposition:in-reply-to; bh=NE7FaZpKickd2ELhI219GJtTGKoGvKG3C0JqHJJ2o+E=; b=UX07IvqKZ8aAH3mxC/DKZYY2LtRgvig25vdKaW+GrUtDWpYjqNdnsc7yHALDlP1WE2 QOIX2ci7h8bfeMtLC0f+M+0Mv6Q+5cKhixvgsQ3d63InDOx834/X/XL4x3DGVxRwLe+c LSC2rIKQuVeX2EKMdb2sNd26BD/SruMdHcSfjDleAwy23mVXIoIBUzfTniGbkbtAzrzN tJJHhJob75+EPCL7KC0w3BAoeWq+3CVbFjb6hO1g02S2S4xg3CuLRzFtZTstK5GYhbze DrBNn1WXR6ZhKVLB0qIzOqoLEEwprNL8dEYxGtskGNPclXW5UwJowyCfruvG387vX2DL qNdw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20210112; h=x-gm-message-state:date:from:to:cc:subject:message-id:references :mime-version:content-disposition:in-reply-to; bh=NE7FaZpKickd2ELhI219GJtTGKoGvKG3C0JqHJJ2o+E=; b=Ut2JG9Da7CgZaQKP7H9iLLsYzZ87NF7O3OtS2mhKEys3EX6e9E33HEGso0+UgD0Psq eA2sqvR9OmlyTcS4vdxlpwd7E6p5yxVy5tcIVqlZH+w0f2G4PnjI9QhF0sIMUbBmGxqB HnS2Sqg/HgRq6r860T2A+PT9Y1TG/6X6gIUk1nOLl+nSVa3hNTl1oGYzUL11+/UlWbSN WjZUU40RXaIoRkokaDTxtjYqbKUiDlcsTSBSl1xQho5HTlkmrN4zTliEZRtRT/iScyDc 80AP34mFNJL78HZ5xBugCeMkj/ezcoRHWf3hTeJ9ZmIKfHUPxv2OHILSIBB7Z1K/mFWo E0Bw== X-Gm-Message-State: AJIora9OwTgK5KeHa9OTnJiQ1cCfjvPHSyh0dQT+cLnDTWXhTm2gorGq lmXXT6Z5GkKSkykSnrVrsRe8BQ== X-Google-Smtp-Source: AGRyM1tSVbatKpqcZ73XKBZlkk2jRZKes3q55Ggfkh9ooo4eZhqub1w7E512SLrQ4jspxFiwwMkMzA== X-Received: by 2002:a05:6a00:4211:b0:51c:45e:532b with SMTP id cd17-20020a056a00421100b0051c045e532bmr1667667pfb.10.1655329926427; Wed, 15 Jun 2022 14:52:06 -0700 (PDT) Received: from google.com ([2620:15c:2ce:200:2ddc:f0bd:cda:3946]) by smtp.gmail.com with ESMTPSA id s17-20020a17090a5d1100b001e0d4169365sm2339454pji.17.2022.06.15.14.52.05 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 15 Jun 2022 14:52:05 -0700 (PDT) Date: Wed, 15 Jun 2022 14:52:02 -0700 From: Fangrui Song To: Ard Biesheuvel Cc: Kees Cook , Sami Tolvanen , linux-arm-kernel , Catalin Marinas , Will Deacon , Mark Rutland , Marc Zyngier , Nick Desaulniers , Dan Li Subject: Re: [PATCH v3 1/3] arm64: unwind: add asynchronous unwind tables to kernel and modules Message-ID: <20220615215202.rxv42bvrfwhs6cgl@google.com> References: <20220613134008.3760481-1-ardb@kernel.org> <20220613134008.3760481-2-ardb@kernel.org> MIME-Version: 1.0 Content-Disposition: inline In-Reply-To: X-CRM114-Version: 20100106-BlameMichelson ( TRE 0.8.0 (BSD) ) MR-646709E3 X-CRM114-CacheID: sfid-20220615_145210_765478_D93FAFF2 X-CRM114-Status: GOOD ( 34.37 ) X-BeenThere: linux-arm-kernel@lists.infradead.org X-Mailman-Version: 2.1.34 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Content-Transfer-Encoding: 7bit Content-Type: text/plain; charset="us-ascii"; Format="flowed" Sender: "linux-arm-kernel" Errors-To: linux-arm-kernel-bounces+linux-arm-kernel=archiver.kernel.org@lists.infradead.org On 2022-06-15, Kees Cook wrote: >On Wed, Jun 15, 2022 at 9:54 AM Ard Biesheuvel wrote: >> >> On Wed, 15 Jun 2022 at 18:50, Sami Tolvanen wrote: >> > >> > On Mon, Jun 13, 2022 at 03:40:06PM +0200, Ard Biesheuvel wrote: >> > > Enable asynchronous unwind table generation for both the core kernel as >> > > well as modules, and emit the resulting .eh_frame sections as init code >> > > so we can use the unwind directives for code patching at boot or module >> > > load time. >> > > >> > > This will be used by dynamic shadow call stack support, which will rely >> > > on code patching rather than compiler codegen to emit the shadow call >> > > stack push and pop instructions. >> > > >> > > Signed-off-by: Ard Biesheuvel >> > > Reviewed-by: Nick Desaulniers >> > > --- >> > > arch/arm64/Kconfig | 3 +++ >> > > arch/arm64/Makefile | 5 +++++ >> > > arch/arm64/include/asm/module.lds.h | 8 ++++++++ >> > > arch/arm64/kernel/vmlinux.lds.S | 13 +++++++++++++ >> > > arch/arm64/kvm/hyp/nvhe/Makefile | 1 + >> > > drivers/firmware/efi/libstub/Makefile | 1 + >> > > 6 files changed, 31 insertions(+) >> > > >> > > diff --git a/arch/arm64/Kconfig b/arch/arm64/Kconfig >> > > index 1652a9800ebe..5f92344edff5 100644 >> > > --- a/arch/arm64/Kconfig >> > > +++ b/arch/arm64/Kconfig >> > > @@ -366,6 +366,9 @@ config KASAN_SHADOW_OFFSET >> > > default 0xeffffff800000000 if ARM64_VA_BITS_36 && KASAN_SW_TAGS >> > > default 0xffffffffffffffff >> > > >> > > +config UNWIND_TABLES >> > > + bool >> > > + >> > > source "arch/arm64/Kconfig.platforms" >> > > >> > > menu "Kernel Features" >> > > diff --git a/arch/arm64/Makefile b/arch/arm64/Makefile >> > > index 6d9d4a58b898..4fbca56fa602 100644 >> > > --- a/arch/arm64/Makefile >> > > +++ b/arch/arm64/Makefile >> > > @@ -45,8 +45,13 @@ KBUILD_CFLAGS += $(call cc-option,-mabi=lp64) >> > > KBUILD_AFLAGS += $(call cc-option,-mabi=lp64) >> > > >> > > # Avoid generating .eh_frame* sections. >> > > +ifneq ($(CONFIG_UNWIND_TABLES),y) >> > > KBUILD_CFLAGS += -fno-asynchronous-unwind-tables -fno-unwind-tables >> > > KBUILD_AFLAGS += -fno-asynchronous-unwind-tables -fno-unwind-tables >> > > +else >> > > +KBUILD_CFLAGS += -fasynchronous-unwind-tables >> > > +KBUILD_AFLAGS += -fasynchronous-unwind-tables >> > > +endif >> > > >> > > ifeq ($(CONFIG_STACKPROTECTOR_PER_TASK),y) >> > > prepare: stack_protector_prepare >> > > diff --git a/arch/arm64/include/asm/module.lds.h b/arch/arm64/include/asm/module.lds.h >> > > index 094701ec5500..dbba4b7559aa 100644 >> > > --- a/arch/arm64/include/asm/module.lds.h >> > > +++ b/arch/arm64/include/asm/module.lds.h >> > > @@ -17,4 +17,12 @@ SECTIONS { >> > > */ >> > > .text.hot : { *(.text.hot) } >> > > #endif >> > > + >> > > +#ifdef CONFIG_UNWIND_TABLES >> > > + /* >> > > + * Currently, we only use unwind info at module load time, so we can >> > > + * put it into the .init allocation. >> > > + */ >> > > + .init.eh_frame : { *(.eh_frame) } >> > > +#endif >> > > } >> > > diff --git a/arch/arm64/kernel/vmlinux.lds.S b/arch/arm64/kernel/vmlinux.lds.S >> > > index 2d4a8f995175..7bf4809f523d 100644 >> > > --- a/arch/arm64/kernel/vmlinux.lds.S >> > > +++ b/arch/arm64/kernel/vmlinux.lds.S >> > > @@ -120,6 +120,17 @@ jiffies = jiffies_64; >> > > #define TRAMP_TEXT >> > > #endif >> > > >> > > +#ifdef CONFIG_UNWIND_TABLES >> > > +#define UNWIND_DATA_SECTIONS \ >> > > + .eh_frame : { \ >> > > + __eh_frame_start = .; \ >> > > + *(.eh_frame) \ >> > > + __eh_frame_end = .; \ >> > > + } >> > > +#else >> > > +#define UNWIND_DATA_SECTIONS >> > > +#endif How do you intend to use the encapsulation symbols __eh_frame_start and __eh_frame_end ? >> > How does this work with SANITIZER_DISCARDS dropping .eh_frame in >> > include/asm-generic/vmlinux.lds.h and scripts/module.lds.S? We would >> > definitely want to enable this together with CONFIG_CFI_CLANG, so it >> > seems like we'd have to drop the discard rules as well. >> > >> >> Good point, I had no idea that that existed. >> >> Clang 13 should have the fix for the original issue, so we could make >> this workaround specific to 12 and earlier. > >Yeah, I like this -- I'd prefer to know when we get "surprise" sections again. Does this need asynchronous unwind tables or just synchronous unwind tables? Note: with Clang < 15, the AArch64 codegen was in a quite bad state. It has significantly improved since the https://reviews.llvm.org/D114545 patch series but I am not confident to state that production use may not into an issue :-) _______________________________________________ linux-arm-kernel mailing list linux-arm-kernel@lists.infradead.org http://lists.infradead.org/mailman/listinfo/linux-arm-kernel