Linux-ARM-Kernel Archive on lore.kernel.org
 help / color / mirror / Atom feed
From: Will Deacon <will@kernel.org>
To: Alice Ryhl <aliceryhl@google.com>
Cc: Jamie.Cunliffe@arm.com, a.hindborg@samsung.com,
	alex.gaynor@gmail.com, ardb@kernel.org, benno.lossin@proton.me,
	bjorn3_gh@protonmail.com, boqun.feng@gmail.com,
	broonie@kernel.org, catalin.marinas@arm.com, gary@garyguo.net,
	keescook@chromium.org, kernel@valentinobst.de,
	linux-arm-kernel@lists.infradead.org,
	linux-kbuild@vger.kernel.org, linux-kernel@vger.kernel.org,
	mark.rutland@arm.com, masahiroy@kernel.org, maz@kernel.org,
	miguel.ojeda.sandonis@gmail.com, nathan@kernel.org,
	ndesaulniers@google.com, nicolas@fjasle.eu, ojeda@kernel.org,
	rust-for-linux@vger.kernel.org, samitolvanen@google.com,
	wedsonaf@gmail.com
Subject: Re: [PATCH v2] rust: add flags for shadow call stack sanitizer
Date: Mon, 24 Jun 2024 14:59:21 +0100	[thread overview]
Message-ID: <20240624135921.GC8616@willie-the-truck> (raw)
In-Reply-To: <CAH5fLgimyYmS33EPEQb6R5Lrmkzv+0GNRE7NQwhfEaJFqb4OYQ@mail.gmail.com>

Hi Alice,

On Tue, Jun 04, 2024 at 04:53:16PM +0200, Alice Ryhl wrote:
> On Tue, Jun 4, 2024 at 4:29 PM Will Deacon <will@kernel.org> wrote:
> > On Tue, Apr 30, 2024 at 11:09:25AM +0000, Alice Ryhl wrote:
> > > Will Deacon <will@kernel.org> wrote:
> > > > On Tue, Mar 05, 2024 at 01:14:19PM +0100, Miguel Ojeda wrote:
> > > >> Otherwise partially reverting to the `target.json` approach sounds good too.
> > > >>
> > > >> I added the `-Zuse-sync-unwind=n` to the list at
> > > >> https://github.com/Rust-for-Linux/linux/issues/2. Given the default is
> > > >> what we want, I have put it in the "Good to have" section.
> > > >
> > > > I think we have time to do this properly, like we did for the clang
> > > > enablement a few years ago. In hindsight, avoiding hacks for the early
> > > > toolchains back then was a really good idea because it meant we could
> > > > rely on a solid baseline set of compiler features from the start.
> > > >
> > > > So, please can we fix this in rustc and just have SCS dependent on that?
> > >
> > > Just to keep you in the loop, I've posted a PR to make rustc recognize
> > > the reserve-x18 target feature, so that the -Ctarget-feature=+reserve-x18
> > > flag stops emitting a warning.
> > >
> > > This should be sufficient for adding support for CONFIG_DYNAMIC_SCS.
> > >
> > > You can find it here:
> > > https://github.com/rust-lang/rust/pull/124323
> > >
> > > As for non-dynamic SCS, I plan to tackle that after the PR is merged.
> > > See the "Future possibilities" section in the linked PR for more info on
> > > that.
> >
> > Thanks for persevering with this, Alice. I read the pull request above,
> > but it looks like you went with:
> >
> > https://github.com/rust-lang/rust/pull/124655
> >
> > instead, which was merged (hurrah!). Do we need anything else?
> 
> Yeah, it took a while, but I've managed to get a -Zfixed-x18 flag in.
> It will be available starting with Rust 1.80, which will be released
> on the 25th of July.

Great, thank you!

> A few things:
> 
> 1. The -Zsanitizer=shadow-call-stack flag still doesn't work because
> the compiler thinks that the target doesn't support it. I'll fix this
> eventually, but at least CONFIG_DYNAMIC_SCS works now.
> 
> 2. I haven't convinced the Rust maintainers that -Zfixed-x18 is the
> way to go long term (flags starting with -Z are unstable and may
> change). Some of the maintainers want to instead add a x18-available
> target feature (that is, the inverse of the current reserve-x18 target
> feature), that you can disable with -Ctarget-feature=-x18-available.
> 
> And a few questions for you:
> 
> By the time support for 1.80 goes in, we are probably supporting more
> than one Rust compiler. For pre-1.80 compilers, should we fall back to
> -Ctarget-feature=+reserve-x18 (which emits a warning, but works), or
> fail compilation?

I think we should just prevent the Kconfig option from being enabled if
the toolchain doesn't give us what we need. So there's no need to fail
compilation, but SCS =n. See how e.g. CONFIG_ARM64_BTI_KERNEL depends on
CONFIG_CC_HAS_BRANCH_PROT_PAC_RET_BTI.

> Similarly, we should probably submit a fix to the stable branches so
> that SCS+Rust doesn't silently break in a hard-to-debug way. Do you
> prefer a backport with -Ctarget-feature=+reserve-x18 or one that fails
> compilation?

As above, I think we should disable the feature in those cases.

Make sense?

Will


  reply	other threads:[~2024-06-24 13:59 UTC|newest]

Thread overview: 10+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2024-03-05 11:58 [PATCH v2] rust: add flags for shadow call stack sanitizer Alice Ryhl
2024-03-05 12:14 ` Miguel Ojeda
2024-04-09 10:31   ` Will Deacon
2024-04-09 15:55     ` Miguel Ojeda
2024-04-30 11:09     ` Alice Ryhl
2024-06-04 14:29       ` Will Deacon
2024-06-04 14:53         ` Alice Ryhl
2024-06-24 13:59           ` Will Deacon [this message]
2024-03-05 14:13 ` Valentin Obst
2024-03-06 19:15 ` Sami Tolvanen

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20240624135921.GC8616@willie-the-truck \
    --to=will@kernel.org \
    --cc=Jamie.Cunliffe@arm.com \
    --cc=a.hindborg@samsung.com \
    --cc=alex.gaynor@gmail.com \
    --cc=aliceryhl@google.com \
    --cc=ardb@kernel.org \
    --cc=benno.lossin@proton.me \
    --cc=bjorn3_gh@protonmail.com \
    --cc=boqun.feng@gmail.com \
    --cc=broonie@kernel.org \
    --cc=catalin.marinas@arm.com \
    --cc=gary@garyguo.net \
    --cc=keescook@chromium.org \
    --cc=kernel@valentinobst.de \
    --cc=linux-arm-kernel@lists.infradead.org \
    --cc=linux-kbuild@vger.kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=mark.rutland@arm.com \
    --cc=masahiroy@kernel.org \
    --cc=maz@kernel.org \
    --cc=miguel.ojeda.sandonis@gmail.com \
    --cc=nathan@kernel.org \
    --cc=ndesaulniers@google.com \
    --cc=nicolas@fjasle.eu \
    --cc=ojeda@kernel.org \
    --cc=rust-for-linux@vger.kernel.org \
    --cc=samitolvanen@google.com \
    --cc=wedsonaf@gmail.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox