From: Kees Cook <keescook@chromium.org> To: Ingo Molnar <mingo@kernel.org> Cc: Kees Cook <keescook@chromium.org>, Arvind Sankar <nivedita@alum.mit.edu>, Atish Patra <atish.patra@wdc.com>, linux-efi@vger.kernel.org, Ard Biesheuvel <ardb@kernel.org>, Nick Desaulniers <ndesaulniers@google.com>, Catalin Marinas <catalin.marinas@arm.com>, Mark Rutland <mark.rutland@arm.com>, Peter Collingbourne <pcc@google.com>, James Morse <james.morse@arm.com>, Borislav Petkov <bp@suse.de>, Ingo Molnar <mingo@redhat.com>, Russell King <linux@armlinux.org.uk>, Masahiro Yamada <masahiroy@kernel.org>, Nathan Chancellor <natechancellor@gmail.com>, Arnd Bergmann <arnd@arndb.de>, x86@kernel.org, clang-built-linux@googlegroups.com, linux-arch@vger.kernel.org, linux-arm-kernel@lists.infradead.org, linux-kernel@vger.kernel.org Subject: [PATCH v6 07/29] efi/libstub: Disable -mbranch-protection Date: Fri, 21 Aug 2020 12:42:48 -0700 [thread overview] Message-ID: <20200821194310.3089815-8-keescook@chromium.org> (raw) In-Reply-To: <20200821194310.3089815-1-keescook@chromium.org> In preparation for adding --orphan-handling=warn to more architectures, disable -mbranch-protection, as EFI does not yet support it[1]. This was noticed due to it producing unwanted .note.gnu.property sections (prefixed with .init due to the objcopy build step). However, we must also work around a bug in Clang where the section is still emitted for code-less object files[2], so also remove the section during the objcopy. [1] https://lore.kernel.org/lkml/CAMj1kXHck12juGi=E=P4hWP_8vQhQ+-x3vBMc3TGeRWdQ-XkxQ@mail.gmail.com [2] https://bugs.llvm.org/show_bug.cgi?id=46480 Cc: Arvind Sankar <nivedita@alum.mit.edu> Cc: Atish Patra <atish.patra@wdc.com> Cc: linux-efi@vger.kernel.org Acked-by: Ard Biesheuvel <ardb@kernel.org> Reviewed-by: Nick Desaulniers <ndesaulniers@google.com> Signed-off-by: Kees Cook <keescook@chromium.org> --- drivers/firmware/efi/libstub/Makefile | 9 ++++++++- 1 file changed, 8 insertions(+), 1 deletion(-) diff --git a/drivers/firmware/efi/libstub/Makefile b/drivers/firmware/efi/libstub/Makefile index 5eefd60917df..0c911e391d75 100644 --- a/drivers/firmware/efi/libstub/Makefile +++ b/drivers/firmware/efi/libstub/Makefile @@ -18,7 +18,8 @@ cflags-$(CONFIG_X86) += -m$(BITS) -D__KERNEL__ \ # arm64 uses the full KBUILD_CFLAGS so it's necessary to explicitly # disable the stackleak plugin cflags-$(CONFIG_ARM64) := $(subst $(CC_FLAGS_FTRACE),,$(KBUILD_CFLAGS)) \ - -fpie $(DISABLE_STACKLEAK_PLUGIN) + -fpie $(DISABLE_STACKLEAK_PLUGIN) \ + $(call cc-option,-mbranch-protection=none) cflags-$(CONFIG_ARM) := $(subst $(CC_FLAGS_FTRACE),,$(KBUILD_CFLAGS)) \ -fno-builtin -fpic \ $(call cc-option,-mno-single-pic-base) @@ -66,6 +67,12 @@ lib-$(CONFIG_X86) += x86-stub.o CFLAGS_arm32-stub.o := -DTEXT_OFFSET=$(TEXT_OFFSET) CFLAGS_arm64-stub.o := -DTEXT_OFFSET=$(TEXT_OFFSET) +# Even when -mbranch-protection=none is set, Clang will generate a +# .note.gnu.property for code-less object files (like lib/ctype.c), +# so work around this by explicitly removing the unwanted section. +# https://bugs.llvm.org/show_bug.cgi?id=46480 +STUBCOPY_FLAGS-y += --remove-section=.note.gnu.property + # # For x86, bootloaders like systemd-boot or grub-efi do not zero-initialize the # .bss section, so the .bss section of the EFI stub needs to be included in the -- 2.25.1
WARNING: multiple messages have this Message-ID (diff)
From: Kees Cook <keescook@chromium.org> To: Ingo Molnar <mingo@kernel.org> Cc: Mark Rutland <mark.rutland@arm.com>, linux-arch@vger.kernel.org, linux-efi@vger.kernel.org, Kees Cook <keescook@chromium.org>, Arnd Bergmann <arnd@arndb.de>, clang-built-linux@googlegroups.com, Catalin Marinas <catalin.marinas@arm.com>, Masahiro Yamada <masahiroy@kernel.org>, x86@kernel.org, Nick Desaulniers <ndesaulniers@google.com>, Russell King <linux@armlinux.org.uk>, linux-kernel@vger.kernel.org, Atish Patra <atish.patra@wdc.com>, Arvind Sankar <nivedita@alum.mit.edu>, Ingo Molnar <mingo@redhat.com>, James Morse <james.morse@arm.com>, Nathan Chancellor <natechancellor@gmail.com>, Borislav Petkov <bp@suse.de>, Peter Collingbourne <pcc@google.com>, Ard Biesheuvel <ardb@kernel.org>, linux-arm-kernel@lists.infradead.org Subject: [PATCH v6 07/29] efi/libstub: Disable -mbranch-protection Date: Fri, 21 Aug 2020 12:42:48 -0700 [thread overview] Message-ID: <20200821194310.3089815-8-keescook@chromium.org> (raw) In-Reply-To: <20200821194310.3089815-1-keescook@chromium.org> In preparation for adding --orphan-handling=warn to more architectures, disable -mbranch-protection, as EFI does not yet support it[1]. This was noticed due to it producing unwanted .note.gnu.property sections (prefixed with .init due to the objcopy build step). However, we must also work around a bug in Clang where the section is still emitted for code-less object files[2], so also remove the section during the objcopy. [1] https://lore.kernel.org/lkml/CAMj1kXHck12juGi=E=P4hWP_8vQhQ+-x3vBMc3TGeRWdQ-XkxQ@mail.gmail.com [2] https://bugs.llvm.org/show_bug.cgi?id=46480 Cc: Arvind Sankar <nivedita@alum.mit.edu> Cc: Atish Patra <atish.patra@wdc.com> Cc: linux-efi@vger.kernel.org Acked-by: Ard Biesheuvel <ardb@kernel.org> Reviewed-by: Nick Desaulniers <ndesaulniers@google.com> Signed-off-by: Kees Cook <keescook@chromium.org> --- drivers/firmware/efi/libstub/Makefile | 9 ++++++++- 1 file changed, 8 insertions(+), 1 deletion(-) diff --git a/drivers/firmware/efi/libstub/Makefile b/drivers/firmware/efi/libstub/Makefile index 5eefd60917df..0c911e391d75 100644 --- a/drivers/firmware/efi/libstub/Makefile +++ b/drivers/firmware/efi/libstub/Makefile @@ -18,7 +18,8 @@ cflags-$(CONFIG_X86) += -m$(BITS) -D__KERNEL__ \ # arm64 uses the full KBUILD_CFLAGS so it's necessary to explicitly # disable the stackleak plugin cflags-$(CONFIG_ARM64) := $(subst $(CC_FLAGS_FTRACE),,$(KBUILD_CFLAGS)) \ - -fpie $(DISABLE_STACKLEAK_PLUGIN) + -fpie $(DISABLE_STACKLEAK_PLUGIN) \ + $(call cc-option,-mbranch-protection=none) cflags-$(CONFIG_ARM) := $(subst $(CC_FLAGS_FTRACE),,$(KBUILD_CFLAGS)) \ -fno-builtin -fpic \ $(call cc-option,-mno-single-pic-base) @@ -66,6 +67,12 @@ lib-$(CONFIG_X86) += x86-stub.o CFLAGS_arm32-stub.o := -DTEXT_OFFSET=$(TEXT_OFFSET) CFLAGS_arm64-stub.o := -DTEXT_OFFSET=$(TEXT_OFFSET) +# Even when -mbranch-protection=none is set, Clang will generate a +# .note.gnu.property for code-less object files (like lib/ctype.c), +# so work around this by explicitly removing the unwanted section. +# https://bugs.llvm.org/show_bug.cgi?id=46480 +STUBCOPY_FLAGS-y += --remove-section=.note.gnu.property + # # For x86, bootloaders like systemd-boot or grub-efi do not zero-initialize the # .bss section, so the .bss section of the EFI stub needs to be included in the -- 2.25.1 _______________________________________________ linux-arm-kernel mailing list linux-arm-kernel@lists.infradead.org http://lists.infradead.org/mailman/listinfo/linux-arm-kernel
next prev parent reply other threads:[~2020-08-21 19:46 UTC|newest] Thread overview: 160+ messages / expand[flat|nested] mbox.gz Atom feed top 2020-08-21 19:42 [PATCH v6 00/29] Warn on orphan section placement Kees Cook 2020-08-21 19:42 ` Kees Cook 2020-08-21 19:42 ` [PATCH v6 01/29] vmlinux.lds.h: Create COMMON_DISCARDS Kees Cook 2020-08-21 19:42 ` Kees Cook 2020-09-01 11:48 ` [tip: core/build] " tip-bot2 for Kees Cook 2020-08-21 19:42 ` [PATCH v6 02/29] vmlinux.lds.h: Add .gnu.version* to COMMON_DISCARDS Kees Cook 2020-08-21 19:42 ` Kees Cook 2020-09-01 11:48 ` [tip: core/build] " tip-bot2 for Kees Cook 2020-08-21 19:42 ` [PATCH v6 03/29] vmlinux.lds.h: Avoid KASAN and KCSAN's unwanted sections Kees Cook 2020-08-21 19:42 ` Kees Cook 2020-09-01 11:48 ` [tip: core/build] " tip-bot2 for Kees Cook 2020-08-21 19:42 ` [PATCH v6 04/29] vmlinux.lds.h: Split ELF_DETAILS from STABS_DEBUG Kees Cook 2020-08-21 19:42 ` Kees Cook 2020-09-01 11:48 ` [tip: core/build] " tip-bot2 for Kees Cook 2020-08-21 19:42 ` [PATCH v6 05/29] vmlinux.lds.h: Add .symtab, .strtab, and .shstrtab to ELF_DETAILS Kees Cook 2020-08-21 19:42 ` Kees Cook 2020-09-01 11:47 ` [tip: core/build] " tip-bot2 for Kees Cook 2020-08-21 19:42 ` [PATCH v6 06/29] vmlinux.lds.h: add PGO and AutoFDO input sections Kees Cook 2020-08-21 19:42 ` Kees Cook 2020-09-01 11:47 ` [tip: core/build] vmlinux.lds.h: Add " tip-bot2 for Nick Desaulniers 2020-08-21 19:42 ` Kees Cook [this message] 2020-08-21 19:42 ` [PATCH v6 07/29] efi/libstub: Disable -mbranch-protection Kees Cook 2020-09-01 11:47 ` [tip: core/build] " tip-bot2 for Kees Cook 2020-08-21 19:42 ` [PATCH v6 08/29] arm64/mm: Remove needless section quotes Kees Cook 2020-08-21 19:42 ` Kees Cook 2020-09-01 11:47 ` [tip: core/build] " tip-bot2 for Kees Cook 2020-08-21 19:42 ` [PATCH v6 09/29] arm64/kernel: Remove needless Call Frame Information annotations Kees Cook 2020-08-21 19:42 ` Kees Cook 2020-09-01 11:47 ` [tip: core/build] " tip-bot2 for Kees Cook 2020-08-21 19:42 ` [PATCH v6 10/29] arm64/build: Remove .eh_frame* sections due to unwind tables Kees Cook 2020-08-21 19:42 ` Kees Cook 2020-09-01 11:47 ` [tip: core/build] " tip-bot2 for Kees Cook 2020-08-21 19:42 ` [PATCH v6 11/29] arm64/build: Use common DISCARDS in linker script Kees Cook 2020-08-21 19:42 ` Kees Cook 2020-09-01 11:47 ` [tip: core/build] " tip-bot2 for Kees Cook 2020-08-21 19:42 ` [PATCH v6 12/29] arm64/build: Add missing DWARF sections Kees Cook 2020-08-21 19:42 ` Kees Cook 2020-09-01 11:47 ` [tip: core/build] " tip-bot2 for Kees Cook 2020-08-21 19:42 ` [PATCH v6 13/29] arm64/build: Assert for unwanted sections Kees Cook 2020-08-21 19:42 ` Kees Cook 2020-09-01 11:47 ` [tip: core/build] " tip-bot2 for Kees Cook 2020-10-26 12:29 ` [PATCH v6 13/29] " Geert Uytterhoeven 2020-10-26 12:29 ` Geert Uytterhoeven 2020-10-26 13:29 ` Geert Uytterhoeven 2020-10-26 13:29 ` Geert Uytterhoeven 2020-10-26 16:01 ` Geert Uytterhoeven 2020-10-26 16:01 ` Geert Uytterhoeven 2020-10-26 17:38 ` Ard Biesheuvel 2020-10-26 17:38 ` Ard Biesheuvel 2020-10-26 17:43 ` Geert Uytterhoeven 2020-10-26 17:43 ` Geert Uytterhoeven 2020-10-26 17:48 ` Nick Desaulniers 2020-10-26 17:48 ` Nick Desaulniers 2020-10-26 17:53 ` Geert Uytterhoeven 2020-10-26 17:53 ` Geert Uytterhoeven 2020-10-27 8:37 ` Geert Uytterhoeven 2020-10-27 8:37 ` Geert Uytterhoeven 2020-10-27 19:25 ` Geert Uytterhoeven 2020-10-27 19:25 ` Geert Uytterhoeven 2020-10-27 19:33 ` Ard Biesheuvel 2020-10-27 19:33 ` Ard Biesheuvel 2020-10-27 20:00 ` Arvind Sankar 2020-10-27 20:00 ` Arvind Sankar 2020-10-27 20:12 ` Nick Desaulniers 2020-10-27 20:12 ` Nick Desaulniers 2020-10-27 20:15 ` Ard Biesheuvel 2020-10-27 20:15 ` Ard Biesheuvel 2020-10-27 20:17 ` Nick Desaulniers 2020-10-27 20:17 ` Nick Desaulniers 2020-10-27 20:30 ` Arvind Sankar 2020-10-27 20:30 ` Arvind Sankar 2020-10-27 20:40 ` Nick Desaulniers 2020-10-27 20:40 ` Nick Desaulniers 2020-10-27 21:24 ` Arvind Sankar 2020-10-27 21:24 ` Arvind Sankar 2020-10-27 20:28 ` Nick Desaulniers 2020-10-27 20:28 ` Nick Desaulniers 2020-10-27 20:32 ` Arvind Sankar 2020-10-27 20:32 ` Arvind Sankar 2020-10-27 20:36 ` Nick Desaulniers 2020-10-27 20:36 ` Nick Desaulniers 2020-10-28 21:36 ` Alexei Starovoitov 2020-10-28 21:36 ` Alexei Starovoitov 2020-10-27 8:51 ` Geert Uytterhoeven 2020-10-27 8:51 ` Geert Uytterhoeven 2020-10-27 10:08 ` Jean-Philippe Brucker 2020-10-27 10:08 ` Jean-Philippe Brucker 2020-10-27 10:20 ` Geert Uytterhoeven 2020-10-27 10:20 ` Geert Uytterhoeven 2020-10-27 11:29 ` Ard Biesheuvel 2020-10-27 11:29 ` Ard Biesheuvel 2020-10-27 11:53 ` Naresh Kamboju 2020-10-27 11:53 ` Naresh Kamboju 2020-10-27 13:56 ` Ard Biesheuvel 2020-10-27 13:56 ` Ard Biesheuvel 2020-08-21 19:42 ` [PATCH v6 14/29] arm64/build: Warn on orphan section placement Kees Cook 2020-08-21 19:42 ` Kees Cook 2020-08-21 19:42 ` [PATCH v6 15/29] arm/build: Refactor linker script headers Kees Cook 2020-08-21 19:42 ` Kees Cook 2020-09-01 11:47 ` [tip: core/build] " tip-bot2 for Kees Cook 2020-08-21 19:42 ` [PATCH v6 16/29] arm/build: Explicitly keep .ARM.attributes sections Kees Cook 2020-08-21 19:42 ` Kees Cook 2020-09-01 11:47 ` [tip: core/build] " tip-bot2 for Kees Cook 2020-08-21 19:42 ` [PATCH v6 17/29] arm/build: Add missing sections Kees Cook 2020-08-21 19:42 ` Kees Cook 2020-09-01 11:47 ` [tip: core/build] " tip-bot2 for Kees Cook 2020-08-21 19:42 ` [PATCH v6 18/29] arm/build: Assert for unwanted sections Kees Cook 2020-08-21 19:42 ` Kees Cook 2020-09-01 11:47 ` [tip: core/build] " tip-bot2 for Kees Cook 2020-08-21 19:43 ` [PATCH v6 19/29] arm/build: Warn on orphan section placement Kees Cook 2020-08-21 19:43 ` Kees Cook 2020-08-21 19:43 ` [PATCH v6 20/29] arm/boot: Handle all sections explicitly Kees Cook 2020-08-21 19:43 ` Kees Cook 2020-09-01 11:47 ` [tip: core/build] " tip-bot2 for Kees Cook 2020-08-21 19:43 ` [PATCH v6 21/29] arm/boot: Warn on orphan section placement Kees Cook 2020-08-21 19:43 ` Kees Cook 2020-08-21 19:43 ` [PATCH v6 22/29] x86/asm: Avoid generating unused kprobe sections Kees Cook 2020-08-21 19:43 ` Kees Cook 2020-09-01 11:47 ` [tip: core/build] " tip-bot2 for Kees Cook 2020-08-21 19:43 ` [PATCH v6 23/29] x86/build: Enforce an empty .got.plt section Kees Cook 2020-08-21 19:43 ` Kees Cook 2020-09-01 11:47 ` [tip: core/build] " tip-bot2 for Kees Cook 2020-08-21 19:43 ` [PATCH v6 24/29] x86/build: Assert for unwanted sections Kees Cook 2020-08-21 19:43 ` Kees Cook 2020-09-01 11:47 ` [tip: core/build] x86/build: Add asserts " tip-bot2 for Kees Cook 2020-08-21 19:43 ` [PATCH v6 25/29] x86/build: Warn on orphan section placement Kees Cook 2020-08-21 19:43 ` Kees Cook 2020-08-21 19:43 ` [PATCH v6 26/29] x86/boot/compressed: Reorganize zero-size section asserts Kees Cook 2020-08-21 19:43 ` Kees Cook 2020-09-01 11:47 ` [tip: core/build] " tip-bot2 for Kees Cook 2020-08-21 19:43 ` [PATCH v6 27/29] x86/boot/compressed: Remove, discard, or assert for unwanted sections Kees Cook 2020-08-21 19:43 ` Kees Cook 2020-08-21 20:01 ` Arvind Sankar 2020-08-21 20:01 ` Arvind Sankar 2020-08-21 21:21 ` Kees Cook 2020-08-21 21:21 ` Kees Cook 2020-08-21 21:28 ` Arvind Sankar 2020-08-21 21:28 ` Arvind Sankar 2020-09-01 11:47 ` [tip: core/build] " tip-bot2 for Kees Cook 2020-08-21 19:43 ` [PATCH v6 28/29] x86/boot/compressed: Add missing debugging sections to output Kees Cook 2020-08-21 19:43 ` Kees Cook 2020-09-01 11:47 ` [tip: core/build] " tip-bot2 for Kees Cook 2020-08-21 19:43 ` [PATCH v6 29/29] x86/boot/compressed: Warn on orphan section placement Kees Cook 2020-08-21 19:43 ` Kees Cook 2020-08-31 19:41 ` [PATCH v6 00/29] " Kees Cook 2020-08-31 19:41 ` Kees Cook 2020-09-01 7:11 ` Ingo Molnar 2020-09-01 7:11 ` Ingo Molnar 2020-09-01 7:59 ` Ingo Molnar 2020-09-01 7:59 ` Ingo Molnar 2020-09-01 8:16 ` Ingo Molnar 2020-09-01 8:16 ` Ingo Molnar 2020-09-01 15:17 ` Kees Cook 2020-09-01 15:17 ` Kees Cook 2020-09-01 18:02 ` Nick Desaulniers 2020-09-01 18:02 ` Nick Desaulniers 2020-09-01 23:18 ` Kees Cook 2020-09-01 23:18 ` Kees Cook 2020-09-01 23:54 ` Nick Desaulniers 2020-09-01 23:54 ` Nick Desaulniers
Reply instructions: You may reply publicly to this message via plain-text email using any one of the following methods: * Save the following mbox file, import it into your mail client, and reply-to-all from there: mbox Avoid top-posting and favor interleaved quoting: https://en.wikipedia.org/wiki/Posting_style#Interleaved_style * Reply using the --to, --cc, and --in-reply-to switches of git-send-email(1): git send-email \ --in-reply-to=20200821194310.3089815-8-keescook@chromium.org \ --to=keescook@chromium.org \ --cc=ardb@kernel.org \ --cc=arnd@arndb.de \ --cc=atish.patra@wdc.com \ --cc=bp@suse.de \ --cc=catalin.marinas@arm.com \ --cc=clang-built-linux@googlegroups.com \ --cc=james.morse@arm.com \ --cc=linux-arch@vger.kernel.org \ --cc=linux-arm-kernel@lists.infradead.org \ --cc=linux-efi@vger.kernel.org \ --cc=linux-kernel@vger.kernel.org \ --cc=linux@armlinux.org.uk \ --cc=mark.rutland@arm.com \ --cc=masahiroy@kernel.org \ --cc=mingo@kernel.org \ --cc=mingo@redhat.com \ --cc=natechancellor@gmail.com \ --cc=ndesaulniers@google.com \ --cc=nivedita@alum.mit.edu \ --cc=pcc@google.com \ --cc=x86@kernel.org \ /path/to/YOUR_REPLY https://kernel.org/pub/software/scm/git/docs/git-send-email.html * If your mail client supports setting the In-Reply-To header via mailto: links, try the mailto: linkBe sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes, see mirroring instructions on how to clone and mirror all data and code used by this external index.