From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from bombadil.infradead.org (bombadil.infradead.org [198.137.202.133]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.lore.kernel.org (Postfix) with ESMTPS id 00265C3DA4A for ; Mon, 29 Jul 2024 14:50:39 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.infradead.org; s=bombadil.20210309; h=Sender:List-Subscribe:List-Help :List-Post:List-Archive:List-Unsubscribe:List-Id:Content-Transfer-Encoding: Content-Type:Cc:To:Subject:Message-ID:Date:From:In-Reply-To:References: MIME-Version:Reply-To:Content-ID:Content-Description:Resent-Date:Resent-From: Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:List-Owner; bh=SVM829+EhcVia4VVprQ2SYbpXevJjHoUSFXsuwUogXI=; b=iWcwxAkleSOnt/jyHUbSYgFmHg drHIrVHiaP8vnn7CEaEFG1lNxq6fmjunM+hFEER6p8/eI42pBQimI02JRsdxZnatODyZKbLPnbj5D M+GD1BIs6E/gsS1RtxRDSeIGC+yDlUmz5pK2SVZWCaUp63WC53agkeOt9+uPsyjpmt2dlj5hjlCUY wAPYHgglS37x5jpbrka8n4LDE2ccZO4LYsU+nwfQ1q4Ra3gmfYhman32dU4tUc1xmOO7S+DnqDjKq Fd1n0zs9Odn42UYH50F7kBdu1486pGJ/19zDaxzbLw8mqONnN3O39yTcbKRd4hQVkr1F5leCr9Nz7 w6M/mA4g==; Received: from localhost ([::1] helo=bombadil.infradead.org) by bombadil.infradead.org with esmtp (Exim 4.97.1 #2 (Red Hat Linux)) id 1sYRhk-0000000BjkQ-1mjF; Mon, 29 Jul 2024 14:50:28 +0000 Received: from mail-wm1-x32e.google.com ([2a00:1450:4864:20::32e]) by bombadil.infradead.org with esmtps (Exim 4.97.1 #2 (Red Hat Linux)) id 1sYRJO-0000000BZYi-0GI5 for linux-arm-kernel@lists.infradead.org; Mon, 29 Jul 2024 14:25:19 +0000 Received: by mail-wm1-x32e.google.com with SMTP id 5b1f17b1804b1-42817bee9e8so14279375e9.3 for ; Mon, 29 Jul 2024 07:25:13 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20230601; t=1722263112; x=1722867912; darn=lists.infradead.org; h=content-transfer-encoding:cc:to:subject:message-id:date:from :in-reply-to:references:mime-version:from:to:cc:subject:date :message-id:reply-to; bh=SVM829+EhcVia4VVprQ2SYbpXevJjHoUSFXsuwUogXI=; b=k1AGYyeWfPo6kHJc97RrTl7OJdXhsotz87G4aZ009EODKzvf+nB38/u7BC4NlKu/AP 3ZsJxF1zOcYG1hdqWyFndtb1l39yabzecC4RjzqHEwF2qgOP3SWW7YdL/lLdO9MpxnjH XF9W93s3mKUSF7Z7MKJlEpyHBqV8saCu6/OHOmL7syUrzHSrq5Iwsd3NkTmnDVd/UZxq lLxM6TeaQVC+WCy4kywa79dEOcjgCaWQRP6E1iGxSY0ec1op00boVSwcVpX3qP2ijTrb v5s3vChu1nLY7syibTz+VpFx63xVi7FL6CW4r5lhBERGh/3Auck5bOkqtmunUM1sJ1Cv sXPg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1722263112; x=1722867912; h=content-transfer-encoding:cc:to:subject:message-id:date:from :in-reply-to:references:mime-version:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to; bh=SVM829+EhcVia4VVprQ2SYbpXevJjHoUSFXsuwUogXI=; b=Y17IHbHGzVm38wYa5k1o6Kb7raIPG3tJib8OEgBpjlQobo0gr3nsrY8Bguciw9JCKR o7pJ5fbUUKtJ44pkrSV4h8NUs6OV9e9JGcCLKcQBrj3QhLtxARVGDW/YLfB/dZjig8Ux oCKRu16I2flh+OTDu+CAabC7a+0Pl7bu5sbqFZ75UZp2QZgZ0tpWLEUO1cWbxr2zvWOD hdC1RRgYP72/LfiY5zyIqsis1h2heit3jga2JAqlx5oXMQ8qGGNxUgnYS/8amHFEzY3Z a8IDHSw25GWp9oKLogsOMOFDa3jlLsela6zjFc/NHjAKGPafNrjDpU8iqNjGv1Z/KjMW hwGw== X-Forwarded-Encrypted: i=1; AJvYcCVp8xTzLZUmUVSw9bK1U6My8fd+Zz6jzdpxf+ZIARsOXKIiPtUT56epLvKwDDJUPL1TlHEReAc/Wu3NK8q4rnxoHqwSAjzuHGhu1FjKpSjj5vTiA0U= X-Gm-Message-State: AOJu0Yx29Ui3ivQ9bCm/vt639QFOq03ceND3TX2rT9IheRSzuqeaH4ZS WCQoWwtfORuRD1vZu/ZWIo9V3wG7W16ist/cmokiKYO9+vNCsdlenj8NlCA3Jf0IRhCEeDjdLZ2 3gy48febHNqKF/Gry3Zr3tiMK2Lg46Qf7Z3C3 X-Google-Smtp-Source: AGHT+IFQYU16YlEglKzW3eVXPMw2hulSYWVP3EJV0ND4LobHlD1MaRThQeUtYygtvMTEPmYpkrM4DSmQ7vHTTIR+RAE= X-Received: by 2002:a05:600c:510d:b0:426:5ef5:bcb1 with SMTP id 5b1f17b1804b1-42811d6dc50mr56509235e9.6.1722263112076; Mon, 29 Jul 2024 07:25:12 -0700 (PDT) MIME-Version: 1.0 References: <20240704-shadow-call-stack-v3-0-d11c7a6ebe30@google.com> <20240704-shadow-call-stack-v3-1-d11c7a6ebe30@google.com> <20240704164548.GB1394865@thelio-3990X> In-Reply-To: <20240704164548.GB1394865@thelio-3990X> From: Alice Ryhl Date: Mon, 29 Jul 2024 16:25:00 +0200 Message-ID: Subject: Re: [PATCH v3 1/2] rust: SHADOW_CALL_STACK is incompatible with Rust To: Nathan Chancellor Cc: Catalin Marinas , Will Deacon , Jamie Cunliffe , Sami Tolvanen , Masahiro Yamada , Nicolas Schier , Ard Biesheuvel , Marc Zyngier , Mark Rutland , Mark Brown , Nick Desaulniers , Kees Cook , Miguel Ojeda , Alex Gaynor , Wedson Almeida Filho , Boqun Feng , Gary Guo , =?UTF-8?Q?Bj=C3=B6rn_Roy_Baron?= , Benno Lossin , Andreas Hindborg , Valentin Obst , linux-kbuild@vger.kernel.org, linux-kernel@vger.kernel.org, linux-arm-kernel@lists.infradead.org, rust-for-linux@vger.kernel.org, stable@vger.kernel.org Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable X-CRM114-Version: 20100106-BlameMichelson ( TRE 0.8.0 (BSD) ) MR-646709E3 X-CRM114-CacheID: sfid-20240729_072518_147988_E9AEA0B5 X-CRM114-Status: GOOD ( 26.05 ) X-BeenThere: linux-arm-kernel@lists.infradead.org X-Mailman-Version: 2.1.34 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Sender: "linux-arm-kernel" Errors-To: linux-arm-kernel-bounces+linux-arm-kernel=archiver.kernel.org@lists.infradead.org On Thu, Jul 4, 2024 at 6:45=E2=80=AFPM Nathan Chancellor wrote: > > On Thu, Jul 04, 2024 at 03:07:57PM +0000, Alice Ryhl wrote: > > When using the shadow call stack sanitizer, all code must be compiled > > with the -ffixed-x18 flag, but this flag is not currently being passed > > to Rust. This results in crashes that are extremely difficult to debug. > > > > To ensure that nobody else has to go through the same debugging session > > that I had to, prevent configurations that enable both SHADOW_CALL_STAC= K > > and RUST. > > > > It is rather common for people to backport 724a75ac9542 ("arm64: rust: > > Enable Rust support for AArch64"), so I recommend applying this fix all > > the way back to 6.1. > > > > Cc: # 6.1 and later > > Fixes: 724a75ac9542 ("arm64: rust: Enable Rust support for AArch64") > > Signed-off-by: Alice Ryhl > > Would it be better to move this to arch/arm64/Kconfig? > > diff --git a/arch/arm64/Kconfig b/arch/arm64/Kconfig > index 167e51067508..080907776db9 100644 > --- a/arch/arm64/Kconfig > +++ b/arch/arm64/Kconfig > @@ -90,7 +90,7 @@ config ARM64 > select ARCH_SUPPORTS_DEBUG_PAGEALLOC > select ARCH_SUPPORTS_HUGETLBFS > select ARCH_SUPPORTS_MEMORY_FAILURE > - select ARCH_SUPPORTS_SHADOW_CALL_STACK if CC_HAVE_SHADOW_CALL_STA= CK > + select ARCH_SUPPORTS_SHADOW_CALL_STACK if CC_HAVE_SHADOW_CALL_STA= CK && !RUST > select ARCH_SUPPORTS_LTO_CLANG if CPU_LITTLE_ENDIAN > select ARCH_SUPPORTS_LTO_CLANG_THIN > select ARCH_SUPPORTS_CFI_CLANG > > RISC-V probably needs the same change, which further leads me to believe > that this workaround should be architecture specific, as they may be > fixed and enabled at different rates. > > diff --git a/arch/riscv/Kconfig b/arch/riscv/Kconfig > index 6b4d71aa9bed..4d89afdd385d 100644 > --- a/arch/riscv/Kconfig > +++ b/arch/riscv/Kconfig > @@ -213,6 +213,7 @@ config HAVE_SHADOW_CALL_STACK > def_bool $(cc-option,-fsanitize=3Dshadow-call-stack) > # https://github.com/riscv-non-isa/riscv-elf-psabi-doc/commit/a48= 4e843e6eeb51f0cb7b8819e50da6d2444d769 > depends on $(ld-option,--no-relax-gp) > + depends on !RUST > > config RISCV_USE_LINKER_RELAXATION > def_bool y Thanks for taking a look. For now, I went with placing the `depends on` in CONFIG_RUST as suggested by the others. This avoids cases where enabling Rust results in changes to how mitigations are configured. As for riscv, it doesn't need any special flags. Please see the commit message for more details on riscv support. https://lore.kernel.org/all/20240729-shadow-call-stack-v4-0-2a664b082ea4@go= ogle.com/ Alice