From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from bombadil.infradead.org (bombadil.infradead.org [198.137.202.133]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.lore.kernel.org (Postfix) with ESMTPS id 3D9D0C54E68 for ; Mon, 11 Mar 2024 22:04:07 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.infradead.org; s=bombadil.20210309; h=Sender: Content-Transfer-Encoding:Content-Type:List-Subscribe:List-Help:List-Post: List-Archive:List-Unsubscribe:List-Id:In-Reply-To:MIME-Version:References: Message-ID:Subject:Cc:To:From:Date:Reply-To:Content-ID:Content-Description: Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID: List-Owner; bh=AepJB2cOY3QhqGC0ot4ayKqq9bcfpdLM8fIQ+9M96VY=; b=GBt9pAsBd1qICC gQ7Ge5yFqluoYustvy9WQMDerKyxP+qtq9K84JMusJT3M34j4147liqVK03uc1Fc3yKzNRxT4MkQb 0YXeSRi2DfHQFltyXEWu1u1G6pGEYK6A97C1Yse5r3s2rUu292FMwqTeZLmsdSITHoeXx/dmQh2re 4wEnQNC5VMExxAnVAlI0IwiHKZuVQyPq90wXh+uT1UsyrFg2InpeUtDbKNb+1EjK01Mr0E2hMAGGT A65R2LEZaEZftOV30lQYErllSwHJHQ0YBrD1f1UHxRhK9a+MPhzTP2AdfFoxrijN93tmYF1tdCDmp aGr5uDcHt43fSc2kNAzw==; Received: from localhost ([::1] helo=bombadil.infradead.org) by bombadil.infradead.org with esmtp (Exim 4.97.1 #2 (Red Hat Linux)) id 1rjnkJ-00000003LKA-3CFL; Mon, 11 Mar 2024 22:03:47 +0000 Received: from mail-pf1-x432.google.com ([2607:f8b0:4864:20::432]) by bombadil.infradead.org with esmtps (Exim 4.97.1 #2 (Red Hat Linux)) id 1rjnkG-00000003LHg-3Z36 for linux-arm-kernel@lists.infradead.org; Mon, 11 Mar 2024 22:03:46 +0000 Received: by mail-pf1-x432.google.com with SMTP id d2e1a72fcca58-6e4d48a5823so2607756b3a.1 for ; Mon, 11 Mar 2024 15:03:40 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=chromium.org; s=google; t=1710194620; x=1710799420; darn=lists.infradead.org; h=in-reply-to:content-disposition:mime-version:references:message-id :subject:cc:to:from:date:from:to:cc:subject:date:message-id:reply-to; bh=X3s7HtVBnE3ACtPsCnNNAAYCoRWSvkfV8hOdKZg+3iU=; b=ATD9cdPsXDRuLUpPKoocn1hCMBaz9UUcDs11jB3xOhCJFL481ZtSXONOvn9ooF4IOd d2KeenpatQlnyb2J2heWI19MOTgRC76lGbmx5OP6gyKOIndc78hw30XR8uyWV0bIYwPw e/PI18B3lh4TpSQVDeZqtizvoUhevo6jvkgPo= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1710194620; x=1710799420; h=in-reply-to:content-disposition:mime-version:references:message-id :subject:cc:to:from:date:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to; bh=X3s7HtVBnE3ACtPsCnNNAAYCoRWSvkfV8hOdKZg+3iU=; b=Er63J5Lzcbsw8VrHIg11YaXVMF/ISIEbaN5wA5a0qbZqzgnmExk2VhkGaNgiRzkeVu XFTsitY8sTwxLoOmTuq/X3YykkGl4vSCYV8ql85lU9AUCywAeTEUtiWI31Dfl8IEwBM5 Nle4ckUtzhK80WQWbJjIj/70+JY2bSvz66Hh0uhpI1EHET7A/7f6HfTvZF6azX8L4VTB lr1t5q9MNtCqb/MiOTisJC4fJhiGloZgLNSmFJul8GytyqmdO92sKRLAmc6l4FQzpTOZ QjH8aA0JUrtLrjD+2sDan8E4+u1uPZhqQraIC3exLz1LdUg0Vc73lsbE3xKVsisPB8Mo XgDQ== X-Forwarded-Encrypted: i=1; AJvYcCUKUbZM4H76iKNVa8nOgD7yIEBpAoN+CxdXzj2+Ur2qZp49xtbne2u0u8+XDxJcVhSNWIuBI6NwA25lVwHzxWMBCCUduSt1zv5DQ6gvTYnbN/m6o2w= X-Gm-Message-State: AOJu0Yynqjj/pkisDfO9/EnO8TCFHv4ltNUJDpDVIpv34weAKPcPHzO/ iHuEDYdLN5vWMMOkeYx3drEgBrKlz87B7qBKo9eYaTdBAFdxa2Xvh7P5CWUTiw== X-Google-Smtp-Source: AGHT+IE1s483Lf5q0Xlj6V4BBPg6RSuGNl+/ruvaU98QZ+YvNM90WIASjVUCv7mzQ2fpw9LyH86oYg== X-Received: by 2002:a05:6a21:918b:b0:1a1:6735:b8be with SMTP id tp11-20020a056a21918b00b001a16735b8bemr5610060pzb.41.1710194620230; Mon, 11 Mar 2024 15:03:40 -0700 (PDT) Received: from www.outflux.net ([198.0.35.241]) by smtp.gmail.com with ESMTPSA id t123-20020a628181000000b006e657c72cf8sm5212215pfd.148.2024.03.11.15.03.39 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 11 Mar 2024 15:03:39 -0700 (PDT) Date: Mon, 11 Mar 2024 15:03:39 -0700 From: Kees Cook To: Linus Walleij Cc: Russell King , Sami Tolvanen , Nathan Chancellor , Nick Desaulniers , Ard Biesheuvel , Arnd Bergmann , linux-arm-kernel@lists.infradead.org, llvm@lists.linux.dev Subject: Re: [PATCH v3 9/9] ARM: KCFI: Allow permissive CFI mode Message-ID: <202403111502.5351F8D7@keescook> References: <20240311-arm32-cfi-v3-0-224a0f0a45c2@linaro.org> <20240311-arm32-cfi-v3-9-224a0f0a45c2@linaro.org> MIME-Version: 1.0 Content-Disposition: inline In-Reply-To: <20240311-arm32-cfi-v3-9-224a0f0a45c2@linaro.org> X-CRM114-Version: 20100106-BlameMichelson ( TRE 0.8.0 (BSD) ) MR-646709E3 X-CRM114-CacheID: sfid-20240311_150345_016231_EB77CAA5 X-CRM114-Status: GOOD ( 30.04 ) X-BeenThere: linux-arm-kernel@lists.infradead.org X-Mailman-Version: 2.1.34 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit Sender: "linux-arm-kernel" Errors-To: linux-arm-kernel-bounces+linux-arm-kernel=archiver.kernel.org@lists.infradead.org On Mon, Mar 11, 2024 at 10:15:46AM +0100, Linus Walleij wrote: > This registers a breakpoint handler for the new breakpoint type > (0x03) inserted by LLVM CLANG for CFI breakpoints. > > If we are in permissive mode, just print a backtrace and continue. > > Example with CONFIG_CFI_PERMISSIVE enabled: > > > echo CFI_FORWARD_PROTO > /sys/kernel/debug/provoke-crash/DIRECT > lkdtm: Performing direct entry CFI_FORWARD_PROTO > lkdtm: Calling matched prototype ... > lkdtm: Calling mismatched prototype ... > CFI failure at lkdtm_indirect_call+0x40/0x4c (target: 0x0; expected type: 0x00000000) > WARNING: CPU: 1 PID: 112 at lkdtm_indirect_call+0x40/0x4c > CPU: 1 PID: 112 Comm: sh Not tainted 6.8.0-rc1+ #150 > Hardware name: ARM-Versatile Express > (...) > lkdtm: FAIL: survived mismatched prototype function call! > lkdtm: Unexpected! This kernel (6.8.0-rc1+ armv7l) was built with CONFIG_CFI_CLANG=y > > As you can see the LKDTM test fails, but I expect that this would be > expected behaviour in the permissive mode. > > We are currently not implementing target and type for the CFI > breakpoint as this requires additional operand bundling compiler > extensions. > > Signed-off-by: Linus Walleij > --- > arch/arm/include/asm/hw_breakpoint.h | 1 + > arch/arm/kernel/hw_breakpoint.c | 30 ++++++++++++++++++++++++++++++ > 2 files changed, 31 insertions(+) > > diff --git a/arch/arm/include/asm/hw_breakpoint.h b/arch/arm/include/asm/hw_breakpoint.h > index 62358d3ca0a8..e7f9961c53b2 100644 > --- a/arch/arm/include/asm/hw_breakpoint.h > +++ b/arch/arm/include/asm/hw_breakpoint.h > @@ -84,6 +84,7 @@ static inline void decode_ctrl_reg(u32 reg, > #define ARM_DSCR_MOE(x) ((x >> 2) & 0xf) > #define ARM_ENTRY_BREAKPOINT 0x1 > #define ARM_ENTRY_ASYNC_WATCHPOINT 0x2 > +#define ARM_ENTRY_CFI_BREAKPOINT 0x3 > #define ARM_ENTRY_SYNC_WATCHPOINT 0xa > > /* DSCR monitor/halting bits. */ > diff --git a/arch/arm/kernel/hw_breakpoint.c b/arch/arm/kernel/hw_breakpoint.c > index dc0fb7a81371..61a984b83bfe 100644 > --- a/arch/arm/kernel/hw_breakpoint.c > +++ b/arch/arm/kernel/hw_breakpoint.c > @@ -17,6 +17,7 @@ > #include > #include > #include > +#include > #include > #include > > @@ -903,6 +904,32 @@ static void breakpoint_handler(unsigned long unknown, struct pt_regs *regs) > watchpoint_single_step_handler(addr); > } > > +#ifdef CONFIG_CFI_CLANG > +static void hw_breakpoint_cfi_handler(struct pt_regs *regs) > +{ > + /* TODO: implementing target and type requires compiler work */ > + unsigned long target = 0; > + u32 type = 0; > + > + switch (report_cfi_failure(regs, instruction_pointer(regs), &target, type)) { > + case BUG_TRAP_TYPE_BUG: > + die("Oops - CFI", regs, 0); > + break; > + case BUG_TRAP_TYPE_WARN: > + /* Skip the breaking instruction */ > + instruction_pointer(regs) += 4; > + break; This looks much better; thanks! > + default: > + pr_crit("Unknown CFI error\n"); > + break; For something like CFI, I think it would be better to fail closed. i.e.: die("Unknown CFI error", regs, 0); > + } > +} > +#else > +static void hw_breakpoint_cfi_handler(struct pt_regs *regs) > +{ > +} > +#endif > + > /* > * Called from either the Data Abort Handler [watchpoint] or the > * Prefetch Abort Handler [breakpoint] with interrupts disabled. > @@ -932,6 +959,9 @@ static int hw_breakpoint_pending(unsigned long addr, unsigned int fsr, > case ARM_ENTRY_SYNC_WATCHPOINT: > watchpoint_handler(addr, fsr, regs); > break; > + case ARM_ENTRY_CFI_BREAKPOINT: > + hw_breakpoint_cfi_handler(regs); > + break; > default: > ret = 1; /* Unhandled fault. */ > } > > -- > 2.34.1 > -- Kees Cook _______________________________________________ linux-arm-kernel mailing list linux-arm-kernel@lists.infradead.org http://lists.infradead.org/mailman/listinfo/linux-arm-kernel