From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.1 (2015-04-28) on archive.lwn.net X-Spam-Level: X-Spam-Status: No, score=-5.4 required=5.0 tests=DKIM_ADSP_CUSTOM_MED, DKIM_SIGNED,FREEMAIL_FORGED_FROMDOMAIN,FREEMAIL_FROM, HEADER_FROM_DIFFERENT_DOMAINS,MAILING_LIST_MULTI,RCVD_IN_DNSWL_HI, T_DKIM_INVALID autolearn=unavailable autolearn_force=no version=3.4.1 Received: from vger.kernel.org (vger.kernel.org [209.132.180.67]) by archive.lwn.net (Postfix) with ESMTP id 2D98A7D08C for ; Fri, 8 Jun 2018 04:10:11 +0000 (UTC) Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1750960AbeFHEKE (ORCPT ); Fri, 8 Jun 2018 00:10:04 -0400 Received: from mail-ot0-f193.google.com ([74.125.82.193]:41109 "EHLO mail-ot0-f193.google.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1750773AbeFHEJ7 (ORCPT ); Fri, 8 Jun 2018 00:09:59 -0400 Received: by mail-ot0-f193.google.com with SMTP id d19-v6so8605144oti.8; Thu, 07 Jun 2018 21:09:59 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=mime-version:in-reply-to:references:from:date:message-id:subject:to :cc; bh=3YxVFb3V959wocR3NdoEsznAFl1SruV1TEp0gMLHw34=; b=J/OmBTnOsI6EA82c9ZlA8BSibgI2emfj92vWvImiE1022bJBtzJ2+0HJaJ0aTrunZU 1LcO64PE9PTntTW+8ExaW+mpDUaLrVZqvwQd0/7h65Ao6Tz0DlUOHgmnT9E5u9I/7yMU yC+o7s/kf0DoA1CYz3VwIGciVXrbDEsg3fIMGEUXBpx49SmavRnMemGQF8rCfJ/6+GQV JzsmqOu7UI159/JW2qRsGFfPNAFZqhVQAEPOb951kXNiLUdI5Ejir1h8R3mQw/4hOhLl xE1dd8IVXIetnhCSCOfro7OMqAsV6x4xyN6dBDW+Z/Aah09f/6xdXuJYUwArl9sYyS6s MeUg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:in-reply-to:references:from:date :message-id:subject:to:cc; bh=3YxVFb3V959wocR3NdoEsznAFl1SruV1TEp0gMLHw34=; b=HeWrr/MHSO4SVjKC0HBT1kZzAa85Ae1VIIOh3AxUM0UkjOvJf78E1k8+3TA+4QCsnD EMD32Tyi7pbjdmt0ig+Jmi2MethBEFMv2E/PP7GmzXnu1TufzJIH/rJjK1y9aW7JLYXv qOVJyxd8RuEv1QNv6mKZUNlTvHv1NVZl7jAAMN8Q49EwiHyK4hlEiErk1P6DUJzVb9Kl 2KWuKui9YuFCZc/z99M1gFzMuebos1YMevijpSFKoUzz71qWainKizjm0PPrKHM/5nRw /pETdX2UiBtv7QtSOdAnwtuwdPTe6Mvxr2yhGwtuieHiXMidfKErpn/xrlOPK7vuhpSV B89Q== X-Gm-Message-State: APt69E13RD3Q5hmKNFfFPbIe13vhg3sAOp5wOXX+BNvpADaWyDQrerdp fX2AkQQEW0c+Xef4yodb9vErNiwHe0tUJ4kPnIY= X-Google-Smtp-Source: ADUXVKIUFXRqaf75rKjEbGOtTAlujZtxVd/fB5/Su+S3EeLy1KwsHLOvN+VKR8vnTaFAoCyC5u6wb1sxdTHr8aKpyso= X-Received: by 2002:a9d:322f:: with SMTP id t47-v6mr2912567otc.7.1528430998903; Thu, 07 Jun 2018 21:09:58 -0700 (PDT) MIME-Version: 1.0 Received: by 2002:a4a:7019:0:0:0:0:0 with HTTP; Thu, 7 Jun 2018 21:09:58 -0700 (PDT) In-Reply-To: References: <20180607143807.3611-1-yu-cheng.yu@intel.com> <20180607143807.3611-7-yu-cheng.yu@intel.com> <1528403417.5265.35.camel@2b52.sc.intel.com> From: "H.J. Lu" Date: Thu, 7 Jun 2018 21:09:58 -0700 Message-ID: Subject: Re: [PATCH 06/10] x86/cet: Add arch_prctl functions for shadow stack To: Andy Lutomirski Cc: Yu-cheng Yu , LKML , linux-doc@vger.kernel.org, Linux-MM , linux-arch , X86 ML , "H. Peter Anvin" , Thomas Gleixner , Ingo Molnar , "Shanbhogue, Vedvyas" , "Ravi V. Shankar" , Dave Hansen , Jonathan Corbet , Oleg Nesterov , Arnd Bergmann , mike.kravetz@oracle.com Content-Type: text/plain; charset="UTF-8" Sender: linux-doc-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-doc@vger.kernel.org On Thu, Jun 7, 2018 at 4:01 PM, Andy Lutomirski wrote: > On Thu, Jun 7, 2018 at 3:02 PM H.J. Lu wrote: >> >> On Thu, Jun 7, 2018 at 2:01 PM, Andy Lutomirski wrote: >> > On Thu, Jun 7, 2018 at 1:33 PM Yu-cheng Yu wrote: >> >> >> >> On Thu, 2018-06-07 at 11:48 -0700, Andy Lutomirski wrote: >> >> > On Thu, Jun 7, 2018 at 7:41 AM Yu-cheng Yu wrote: >> >> > > >> >> > > The following operations are provided. >> >> > > >> >> > > ARCH_CET_STATUS: >> >> > > return the current CET status >> >> > > >> >> > > ARCH_CET_DISABLE: >> >> > > disable CET features >> >> > > >> >> > > ARCH_CET_LOCK: >> >> > > lock out CET features >> >> > > >> >> > > ARCH_CET_EXEC: >> >> > > set CET features for exec() >> >> > > >> >> > > ARCH_CET_ALLOC_SHSTK: >> >> > > allocate a new shadow stack >> >> > > >> >> > > ARCH_CET_PUSH_SHSTK: >> >> > > put a return address on shadow stack >> >> > > >> >> > > ARCH_CET_ALLOC_SHSTK and ARCH_CET_PUSH_SHSTK are intended only for >> >> > > the implementation of GLIBC ucontext related APIs. >> >> > >> >> > Please document exactly what these all do and why. I don't understand >> >> > what purpose ARCH_CET_LOCK and ARCH_CET_EXEC serve. CET is opt in for >> >> > each ELF program, so I think there should be no need for a magic >> >> > override. >> >> >> >> CET is initially enabled if the loader has CET capability. Then the >> >> loader decides if the application can run with CET. If the application >> >> cannot run with CET (e.g. a dependent library does not have CET), then >> >> the loader turns off CET before passing to the application. When the >> >> loader is done, it locks out CET and the feature cannot be turned off >> >> anymore until the next exec() call. >> > >> > Why is the lockout necessary? If user code enables CET and tries to >> > run code that doesn't support CET, it will crash. I don't see why we >> > need special code in the kernel to prevent a user program from calling >> > arch_prctl() and crashing itself. There are already plenty of ways to >> > do that :) >> >> On CET enabled machine, not all programs nor shared libraries are >> CET enabled. But since ld.so is CET enabled, all programs start >> as CET enabled. ld.so will disable CET if a program or any of its shared >> libraries aren't CET enabled. ld.so will lock up CET once it is done CET >> checking so that CET can't no longer be disabled afterwards. > > Yeah, I got that. No one has explained *why*. It is to prevent malicious code from disabling CET. > (Also, shouldn't the vDSO itself be marked as supporting CET?) No. vDSO is loaded by kernel. vDSO in CET kernel is CET compatible. -- H.J. -- To unsubscribe from this list: send the line "unsubscribe linux-doc" in the body of a message to majordomo@vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html