From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org X-Spam-Level: X-Spam-Status: No, score=-3.6 required=3.0 tests=BAYES_00,DKIM_SIGNED, DKIM_VALID,DKIM_VALID_AU,FREEMAIL_FORGED_FROMDOMAIN,FREEMAIL_FROM, HEADER_FROM_DIFFERENT_DOMAINS,MAILING_LIST_MULTI,SPF_HELO_NONE,SPF_PASS, URIBL_BLOCKED autolearn=no autolearn_force=no version=3.4.0 Received: from mail.kernel.org (mail.kernel.org [198.145.29.99]) by smtp.lore.kernel.org (Postfix) with ESMTP id 430A6C433DF for ; Thu, 27 Aug 2020 19:38:16 +0000 (UTC) Received: from kanga.kvack.org (kanga.kvack.org [205.233.56.17]) by mail.kernel.org (Postfix) with ESMTP id 07AA52087E for ; Thu, 27 Aug 2020 19:38:15 +0000 (UTC) Authentication-Results: mail.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="OdHs4L9U" DMARC-Filter: OpenDMARC Filter v1.3.2 mail.kernel.org 07AA52087E Authentication-Results: mail.kernel.org; dmarc=fail (p=none dis=none) header.from=gmail.com Authentication-Results: mail.kernel.org; spf=pass smtp.mailfrom=owner-linux-mm@kvack.org Received: by kanga.kvack.org (Postfix) id 8802B6B0002; Thu, 27 Aug 2020 15:38:15 -0400 (EDT) Received: by kanga.kvack.org (Postfix, from userid 40) id 808626B0003; Thu, 27 Aug 2020 15:38:15 -0400 (EDT) X-Delivered-To: int-list-linux-mm@kvack.org Received: by kanga.kvack.org (Postfix, from userid 63042) id 681BF6B0006; Thu, 27 Aug 2020 15:38:15 -0400 (EDT) X-Delivered-To: linux-mm@kvack.org Received: from forelay.hostedemail.com (smtprelay0049.hostedemail.com [216.40.44.49]) by kanga.kvack.org (Postfix) with ESMTP id 4C8B86B0002 for ; Thu, 27 Aug 2020 15:38:15 -0400 (EDT) Received: from smtpin24.hostedemail.com (10.5.19.251.rfc1918.com [10.5.19.251]) by forelay02.hostedemail.com (Postfix) with ESMTP id 0EE8137E7 for ; Thu, 27 Aug 2020 19:38:15 +0000 (UTC) X-FDA: 77197359750.24.hand99_2415ac02706f Received: from filter.hostedemail.com (10.5.16.251.rfc1918.com [10.5.16.251]) by smtpin24.hostedemail.com (Postfix) with ESMTP id D3D121A4A0 for ; Thu, 27 Aug 2020 19:38:14 +0000 (UTC) X-HE-Tag: hand99_2415ac02706f X-Filterd-Recvd-Size: 6099 Received: from mail-il1-f195.google.com (mail-il1-f195.google.com [209.85.166.195]) by imf50.hostedemail.com (Postfix) with ESMTP for ; Thu, 27 Aug 2020 19:38:14 +0000 (UTC) Received: by mail-il1-f195.google.com with SMTP id f12so5886345ils.6 for ; Thu, 27 Aug 2020 12:38:14 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc:content-transfer-encoding; bh=NOB1L9Z2LmUKGGeFyj84nON/LDrM3AY4psgNY87vymw=; b=OdHs4L9Ujfp3PQmb2CnawHfr6pib3Mou2W4IqK9gK/q74g/vSmAY5IibNlwwPXjL0b 5NGlUNmZ6k0DF03WOSrOLhFPmdu4PzcoquTboVrApL8RmYXVgXNZKgzeq+f4YEDLMDof Su+ub46724WODtxB8KZL/mIuhurVshHcwRUK9T2XIgcbvO4O/tfNIgdbT1vkbDS4fdgw ekxI471ss7zqC1dsg9I9qcROP5g5MM+Zd9qCmotFs4sceCnUzxkMZnQbkZ8sM8X1hUmH oiHWjpk4l9W6NoyVS8q3C5saAs2d36saw/zDSuhCQVB8b95clOQwGeHMRd2NyEVAtBp/ 4BPg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc:content-transfer-encoding; bh=NOB1L9Z2LmUKGGeFyj84nON/LDrM3AY4psgNY87vymw=; b=uIa8ux6WsbrsxWs7cWqAxRpF2FvyB1xACva9DWnR7aPf+974KammFQODi5JY25H/Qd IFgNRX85KThGHia+3dWVP1X0JSIKvjqJc3gwiPMXI9P8fsLkKBoww3k7qAQquEtCkE/X H2XwqUq7YbY0N8NdmME1+qTHwDdtkWx3SufXHidqLEx+DFffMXQ+1kL6iAMyUV74NtFS pWjf9KL2jZ7Go3WYS6M4H/Qi5bXu74gWBRz8HVY3l1WERiBV/jLkUpHP8sWoEjB2YJlo lRyxsiaaqpsHKBWlPHc/za/N4Nk19QUOA/TW6ys1TSQo1pNkol/GZCGWDE9rXzJuN81S Ii6A== X-Gm-Message-State: AOAM532NmrsoLnH48uAEOfo+DjVW8tfMXK9M8rrU9nvDJepXZ8NkpLeg hpZ8I+sYZDUSAZfAKiX2y9Ya6k3F1hivtssVEXk= X-Google-Smtp-Source: ABdhPJz3AFlP3Kd2dCES2TE657Fj/aB8MwwtB77fXJN6/mzwzKCWE10R5tOLPhiUJGyp0tLFgg6gBnnGIoHe5BhRZaY= X-Received: by 2002:a92:5e4c:: with SMTP id s73mr18025364ilb.151.1598557093725; Thu, 27 Aug 2020 12:38:13 -0700 (PDT) MIME-Version: 1.0 References: <4BDFD364-798C-4537-A88E-F94F101F524B@amacapital.net> In-Reply-To: <4BDFD364-798C-4537-A88E-F94F101F524B@amacapital.net> From: "H.J. Lu" Date: Thu, 27 Aug 2020 12:37:37 -0700 Message-ID: Subject: Re: [PATCH v11 25/25] x86/cet/shstk: Add arch_prctl functions for shadow stack To: Andy Lutomirski Cc: "Yu, Yu-cheng" , Florian Weimer , Dave Martin , Dave Hansen , Andy Lutomirski , X86 ML , "H. Peter Anvin" , Thomas Gleixner , Ingo Molnar , LKML , "open list:DOCUMENTATION" , Linux-MM , linux-arch , Linux API , Arnd Bergmann , Balbir Singh , Borislav Petkov , Cyrill Gorcunov , Dave Hansen , Eugene Syromiatnikov , Jann Horn , Jonathan Corbet , Kees Cook , Mike Kravetz , Nadav Amit , Oleg Nesterov , Pavel Machek , Peter Zijlstra , Randy Dunlap , "Ravi V. Shankar" , Vedvyas Shanbhogue , Weijiang Yang Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable X-Rspamd-Queue-Id: D3D121A4A0 X-Spamd-Result: default: False [0.00 / 100.00] X-Rspamd-Server: rspam04 X-Bogosity: Ham, tests=bogofilter, spamicity=0.000000, version=1.2.4 Sender: owner-linux-mm@kvack.org Precedence: bulk X-Loop: owner-majordomo@kvack.org List-ID: On Thu, Aug 27, 2020 at 11:56 AM Andy Lutomirski wrot= e: > > > > > On Aug 27, 2020, at 11:13 AM, Yu, Yu-cheng wrot= e: > > > > =EF=BB=BFOn 8/27/2020 6:36 AM, Florian Weimer wrote: > >> * H. J. Lu: > >>>> On Thu, Aug 27, 2020 at 6:19 AM Florian Weimer = wrote: > >>>>> > >>>>> * Dave Martin: > >>>>> > >>>>>> You're right that this has implications: for i386, libc probably p= ulls > >>>>>> more arguments off the stack than are really there in some situati= ons. > >>>>>> This isn't a new problem though. There are already generic prctls= with > >>>>>> fewer than 4 args that are used on x86. > >>>>> > >>>>> As originally posted, glibc prctl would have to know that it has to= pull > >>>>> an u64 argument off the argument list for ARCH_X86_CET_DISABLE. Bu= t > >>>>> then the u64 argument is a problem for arch_prctl as well. > >>>>> > >>> > >>> Argument of ARCH_X86_CET_DISABLE is int and passed in register. > >> The commit message and the C source say otherwise, I think (not sure > >> about the C source, not a kernel hacker). > > > > H.J. Lu suggested that we fix x86 arch_prctl() to take four arguments, = and then keep MMAP_SHSTK as an arch_prctl(). Because now the map flags and= size are all in registers, this also solves problems being pointed out ear= lier. Without a wrapper, the shadow stack mmap call (from user space) will= be: > > > > syscall(_NR_arch_prctl, ARCH_X86_CET_MMAP_SHSTK, size, MAP_32BIT). > > I admit I don=E2=80=99t see a show stopping technical reason we can=E2=80= =99t add arguments to an existing syscall, but I=E2=80=99m pretty sure it= =E2=80=99s unprecedented, and it doesn=E2=80=99t seem like a good idea. prctl prototype is: extern int prctl (int __option, ...) and implemented in kernel as: int prctl(int option, unsigned long arg2, unsigned long arg3, unsigned long arg4, unsigned long arg5); Not all prctl operations take all 5 arguments. It also applies to arch_prctl. It is quite normal for different operations of arch_prctl to take different numbers of arguments. --=20 H.J.