From: Sami Tolvanen <samitolvanen@google.com> To: linux-kernel@vger.kernel.org Cc: Kees Cook <keescook@chromium.org>, Josh Poimboeuf <jpoimboe@redhat.com>, Peter Zijlstra <peterz@infradead.org>, x86@kernel.org, Catalin Marinas <catalin.marinas@arm.com>, Will Deacon <will@kernel.org>, Mark Rutland <mark.rutland@arm.com>, Nathan Chancellor <nathan@kernel.org>, Nick Desaulniers <ndesaulniers@google.com>, Joao Moreira <joao@overdrivepizza.com>, Sedat Dilek <sedat.dilek@gmail.com>, Steven Rostedt <rostedt@goodmis.org>, linux-hardening@vger.kernel.org, linux-arm-kernel@lists.infradead.org, llvm@lists.linux.dev, Sami Tolvanen <samitolvanen@google.com> Subject: [PATCH v5 00/22] KCFI support Date: Thu, 8 Sep 2022 14:54:42 -0700 [thread overview] Message-ID: <20220908215504.3686827-1-samitolvanen@google.com> (raw) KCFI is a forward-edge control-flow integrity scheme in the upcoming Clang 16 release, which is more suitable for kernel use than the existing CFI scheme used by CONFIG_CFI_CLANG. KCFI doesn't require LTO, doesn't alter function references to point to a jump table, and won't break function address equality. This series replaces the current arm64 CFI implementation with KCFI and adds support for x86_64. KCFI requires assembly functions that are indirectly called from C code to be annotated with type identifiers. As type information is only available in C, the compiler emits expected type identifiers into the symbol table, so they can be referenced from assembly without having to hardcode type hashes. Patch 6 adds helper macros for annotating functions, and patches 9 and 20 add annotations. In case of a type mismatch, KCFI always traps. To support error handling, the compiler generates a .kcfi_traps section for x86_64, which contains the locations of each trap, and for arm64, encodes the necessary register information to the ESR. Patches 10 and 22 add arch-specific error handlers. To test this series, you'll need a ToT Clang toolchain. The series is also available pn GitHub: https://github.com/samitolvanen/linux/commits/kcfi-v5 --- Changes in v5: - Cleaned up the manual CFI type annotation macros, and ensured the IBT/BTI landing pads are correctly emitted. - Added a patch to fix an objtool issue in elf_update_symbol, which could end up marking __kcfi_typeid_ SHN_ABS symbols undefined. Changes in v4: - Dropped the RFC now that Clang support is merged. - Changed the x86_64 function preamble to match the the preamble generated by the compiler, and fixed a code generation issue, which Peter pointed out. - Added a patch to fix arm64 psci_initcall_t type mismatch based on Mark's suggestion. Changes in v3: - Merged the patches that split CC_FLAGS_CFI from CC_FLAGS_LTO. - Dropped the psci_initcall_t patch as Mark volunteered to send a patch for this. Note that this patch is still needed to boot a CFI kernel on certain arm64 systems: https://lore.kernel.org/lkml/YoNhKaTT3EDukxXY@FVFF77S0Q05N/ - Added a patch to remove the now unnecessary workarounds with CFI+ThinLTO in kallsyms. - Added an lkdtm patch to ensure the test actually generates an indirect call. - Changed report_cfi_failure to clearly indicate if we failed to decode target address. - Switched to relative offsets for .kcfi_traps. - On x86_64, moved CFI error handling from traps.c to cfi.c, and as we only call memcpy indirectly w/ CONFIG_MODULES, ensured that the compiler emits __kcfi_typeid_memcpy also without modules. - On x86_64, added a check for the cmpl REX prefix to handle the case where the compiler might not use r8-r15 registers for the call target. - On the compiler side, ensured that on x86_64 calls are emitted immediately after the CFI check, fixed the __cfi_ preamble linkage, and changed the compiler to emit relative offsets in .kcfi_traps. Changes in v2: - Changed the compiler patch to encode arm64 target and type details in the ESR, and updated the kernel error handling patch accordingly. - Changed the compiler patch to embed the x86_64 type hash in a valid instruction to avoid special casing objtool instruction decoding, and added a __cfi_ symbol for the preamble. Changed the kernel error handling and manual type annotations to match. - Dropped the .kcfi_types section as that’s no longer needed by objtool, and changed the objtool patch to simply ignore the __cfi_ preambles falling through. - Dropped the .kcfi_traps section on arm64 as it’s no longer needed, and moved the trap look-up code behind CONFIG_ARCH_USES_CFI_TRAPS, which is selected only for x86_64. - Dropped __nocfi attributes from arm64 code where CFI was disabled due to address space confusion issues, and added type annotations to relevant assembly functions. - Dropped __nocfi from __init. Sami Tolvanen (22): treewide: Filter out CC_FLAGS_CFI scripts/kallsyms: Ignore __kcfi_typeid_ cfi: Remove CONFIG_CFI_CLANG_SHADOW cfi: Drop __CFI_ADDRESSABLE cfi: Switch to -fsanitize=kcfi cfi: Add type helper macros lkdtm: Emit an indirect call for CFI tests psci: Fix the function type for psci_initcall_t arm64: Add types to indirect called assembly functions arm64: Add CFI error handling arm64: Drop unneeded __nocfi attributes init: Drop __nocfi from __init treewide: Drop function_nocfi treewide: Drop WARN_ON_FUNCTION_MISMATCH treewide: Drop __cficanonical objtool: Preserve special st_shndx indexes in elf_update_symbol objtool: Disable CFI warnings kallsyms: Drop CONFIG_CFI_CLANG workarounds x86/tools/relocs: Ignore __kcfi_typeid_ relocations x86: Add types to indirectly called assembly functions x86/purgatory: Disable CFI x86: Add support for CONFIG_CFI_CLANG Makefile | 13 +- arch/Kconfig | 18 +- arch/arm64/crypto/ghash-ce-core.S | 5 +- arch/arm64/crypto/sm3-ce-core.S | 3 +- arch/arm64/include/asm/brk-imm.h | 6 + arch/arm64/include/asm/ftrace.h | 2 +- arch/arm64/include/asm/linkage.h | 4 + arch/arm64/include/asm/mmu_context.h | 4 +- arch/arm64/kernel/acpi_parking_protocol.c | 2 +- arch/arm64/kernel/alternative.c | 2 +- arch/arm64/kernel/cpu-reset.S | 5 +- arch/arm64/kernel/cpufeature.c | 4 +- arch/arm64/kernel/ftrace.c | 2 +- arch/arm64/kernel/machine_kexec.c | 2 +- arch/arm64/kernel/psci.c | 2 +- arch/arm64/kernel/smp_spin_table.c | 2 +- arch/arm64/kernel/traps.c | 47 ++- arch/arm64/kernel/vdso/Makefile | 3 +- arch/arm64/mm/proc.S | 5 +- arch/x86/Kconfig | 2 + arch/x86/crypto/blowfish-x86_64-asm_64.S | 5 +- arch/x86/entry/vdso/Makefile | 3 +- arch/x86/include/asm/cfi.h | 22 ++ arch/x86/include/asm/linkage.h | 12 + arch/x86/kernel/Makefile | 2 + arch/x86/kernel/cfi.c | 86 ++++++ arch/x86/kernel/traps.c | 4 +- arch/x86/lib/memcpy_64.S | 3 +- arch/x86/purgatory/Makefile | 4 + arch/x86/tools/relocs.c | 1 + drivers/firmware/efi/libstub/Makefile | 2 + drivers/firmware/psci/psci.c | 12 +- drivers/misc/lkdtm/cfi.c | 15 +- drivers/misc/lkdtm/usercopy.c | 2 +- include/asm-generic/bug.h | 16 - include/asm-generic/vmlinux.lds.h | 37 +-- include/linux/cfi.h | 59 ++-- include/linux/cfi_types.h | 45 +++ include/linux/compiler-clang.h | 14 +- include/linux/compiler.h | 16 +- include/linux/compiler_types.h | 4 - include/linux/init.h | 6 +- include/linux/module.h | 10 +- include/linux/pci.h | 4 +- kernel/cfi.c | 352 ++++------------------ kernel/kallsyms.c | 17 -- kernel/kthread.c | 3 +- kernel/module/main.c | 50 +-- kernel/workqueue.c | 2 +- scripts/kallsyms.c | 1 + scripts/module.lds.S | 23 +- tools/objtool/check.c | 7 +- tools/objtool/elf.c | 7 +- 53 files changed, 425 insertions(+), 554 deletions(-) create mode 100644 arch/x86/include/asm/cfi.h create mode 100644 arch/x86/kernel/cfi.c create mode 100644 include/linux/cfi_types.h base-commit: 506357871c18e06565840d71c2ef9f818e19f460 -- 2.37.2.789.g6183377224-goog
WARNING: multiple messages have this Message-ID (diff)
From: Sami Tolvanen <samitolvanen@google.com> To: linux-kernel@vger.kernel.org Cc: Kees Cook <keescook@chromium.org>, Josh Poimboeuf <jpoimboe@redhat.com>, Peter Zijlstra <peterz@infradead.org>, x86@kernel.org, Catalin Marinas <catalin.marinas@arm.com>, Will Deacon <will@kernel.org>, Mark Rutland <mark.rutland@arm.com>, Nathan Chancellor <nathan@kernel.org>, Nick Desaulniers <ndesaulniers@google.com>, Joao Moreira <joao@overdrivepizza.com>, Sedat Dilek <sedat.dilek@gmail.com>, Steven Rostedt <rostedt@goodmis.org>, linux-hardening@vger.kernel.org, linux-arm-kernel@lists.infradead.org, llvm@lists.linux.dev, Sami Tolvanen <samitolvanen@google.com> Subject: [PATCH v5 00/22] KCFI support Date: Thu, 8 Sep 2022 14:54:42 -0700 [thread overview] Message-ID: <20220908215504.3686827-1-samitolvanen@google.com> (raw) KCFI is a forward-edge control-flow integrity scheme in the upcoming Clang 16 release, which is more suitable for kernel use than the existing CFI scheme used by CONFIG_CFI_CLANG. KCFI doesn't require LTO, doesn't alter function references to point to a jump table, and won't break function address equality. This series replaces the current arm64 CFI implementation with KCFI and adds support for x86_64. KCFI requires assembly functions that are indirectly called from C code to be annotated with type identifiers. As type information is only available in C, the compiler emits expected type identifiers into the symbol table, so they can be referenced from assembly without having to hardcode type hashes. Patch 6 adds helper macros for annotating functions, and patches 9 and 20 add annotations. In case of a type mismatch, KCFI always traps. To support error handling, the compiler generates a .kcfi_traps section for x86_64, which contains the locations of each trap, and for arm64, encodes the necessary register information to the ESR. Patches 10 and 22 add arch-specific error handlers. To test this series, you'll need a ToT Clang toolchain. The series is also available pn GitHub: https://github.com/samitolvanen/linux/commits/kcfi-v5 --- Changes in v5: - Cleaned up the manual CFI type annotation macros, and ensured the IBT/BTI landing pads are correctly emitted. - Added a patch to fix an objtool issue in elf_update_symbol, which could end up marking __kcfi_typeid_ SHN_ABS symbols undefined. Changes in v4: - Dropped the RFC now that Clang support is merged. - Changed the x86_64 function preamble to match the the preamble generated by the compiler, and fixed a code generation issue, which Peter pointed out. - Added a patch to fix arm64 psci_initcall_t type mismatch based on Mark's suggestion. Changes in v3: - Merged the patches that split CC_FLAGS_CFI from CC_FLAGS_LTO. - Dropped the psci_initcall_t patch as Mark volunteered to send a patch for this. Note that this patch is still needed to boot a CFI kernel on certain arm64 systems: https://lore.kernel.org/lkml/YoNhKaTT3EDukxXY@FVFF77S0Q05N/ - Added a patch to remove the now unnecessary workarounds with CFI+ThinLTO in kallsyms. - Added an lkdtm patch to ensure the test actually generates an indirect call. - Changed report_cfi_failure to clearly indicate if we failed to decode target address. - Switched to relative offsets for .kcfi_traps. - On x86_64, moved CFI error handling from traps.c to cfi.c, and as we only call memcpy indirectly w/ CONFIG_MODULES, ensured that the compiler emits __kcfi_typeid_memcpy also without modules. - On x86_64, added a check for the cmpl REX prefix to handle the case where the compiler might not use r8-r15 registers for the call target. - On the compiler side, ensured that on x86_64 calls are emitted immediately after the CFI check, fixed the __cfi_ preamble linkage, and changed the compiler to emit relative offsets in .kcfi_traps. Changes in v2: - Changed the compiler patch to encode arm64 target and type details in the ESR, and updated the kernel error handling patch accordingly. - Changed the compiler patch to embed the x86_64 type hash in a valid instruction to avoid special casing objtool instruction decoding, and added a __cfi_ symbol for the preamble. Changed the kernel error handling and manual type annotations to match. - Dropped the .kcfi_types section as that’s no longer needed by objtool, and changed the objtool patch to simply ignore the __cfi_ preambles falling through. - Dropped the .kcfi_traps section on arm64 as it’s no longer needed, and moved the trap look-up code behind CONFIG_ARCH_USES_CFI_TRAPS, which is selected only for x86_64. - Dropped __nocfi attributes from arm64 code where CFI was disabled due to address space confusion issues, and added type annotations to relevant assembly functions. - Dropped __nocfi from __init. Sami Tolvanen (22): treewide: Filter out CC_FLAGS_CFI scripts/kallsyms: Ignore __kcfi_typeid_ cfi: Remove CONFIG_CFI_CLANG_SHADOW cfi: Drop __CFI_ADDRESSABLE cfi: Switch to -fsanitize=kcfi cfi: Add type helper macros lkdtm: Emit an indirect call for CFI tests psci: Fix the function type for psci_initcall_t arm64: Add types to indirect called assembly functions arm64: Add CFI error handling arm64: Drop unneeded __nocfi attributes init: Drop __nocfi from __init treewide: Drop function_nocfi treewide: Drop WARN_ON_FUNCTION_MISMATCH treewide: Drop __cficanonical objtool: Preserve special st_shndx indexes in elf_update_symbol objtool: Disable CFI warnings kallsyms: Drop CONFIG_CFI_CLANG workarounds x86/tools/relocs: Ignore __kcfi_typeid_ relocations x86: Add types to indirectly called assembly functions x86/purgatory: Disable CFI x86: Add support for CONFIG_CFI_CLANG Makefile | 13 +- arch/Kconfig | 18 +- arch/arm64/crypto/ghash-ce-core.S | 5 +- arch/arm64/crypto/sm3-ce-core.S | 3 +- arch/arm64/include/asm/brk-imm.h | 6 + arch/arm64/include/asm/ftrace.h | 2 +- arch/arm64/include/asm/linkage.h | 4 + arch/arm64/include/asm/mmu_context.h | 4 +- arch/arm64/kernel/acpi_parking_protocol.c | 2 +- arch/arm64/kernel/alternative.c | 2 +- arch/arm64/kernel/cpu-reset.S | 5 +- arch/arm64/kernel/cpufeature.c | 4 +- arch/arm64/kernel/ftrace.c | 2 +- arch/arm64/kernel/machine_kexec.c | 2 +- arch/arm64/kernel/psci.c | 2 +- arch/arm64/kernel/smp_spin_table.c | 2 +- arch/arm64/kernel/traps.c | 47 ++- arch/arm64/kernel/vdso/Makefile | 3 +- arch/arm64/mm/proc.S | 5 +- arch/x86/Kconfig | 2 + arch/x86/crypto/blowfish-x86_64-asm_64.S | 5 +- arch/x86/entry/vdso/Makefile | 3 +- arch/x86/include/asm/cfi.h | 22 ++ arch/x86/include/asm/linkage.h | 12 + arch/x86/kernel/Makefile | 2 + arch/x86/kernel/cfi.c | 86 ++++++ arch/x86/kernel/traps.c | 4 +- arch/x86/lib/memcpy_64.S | 3 +- arch/x86/purgatory/Makefile | 4 + arch/x86/tools/relocs.c | 1 + drivers/firmware/efi/libstub/Makefile | 2 + drivers/firmware/psci/psci.c | 12 +- drivers/misc/lkdtm/cfi.c | 15 +- drivers/misc/lkdtm/usercopy.c | 2 +- include/asm-generic/bug.h | 16 - include/asm-generic/vmlinux.lds.h | 37 +-- include/linux/cfi.h | 59 ++-- include/linux/cfi_types.h | 45 +++ include/linux/compiler-clang.h | 14 +- include/linux/compiler.h | 16 +- include/linux/compiler_types.h | 4 - include/linux/init.h | 6 +- include/linux/module.h | 10 +- include/linux/pci.h | 4 +- kernel/cfi.c | 352 ++++------------------ kernel/kallsyms.c | 17 -- kernel/kthread.c | 3 +- kernel/module/main.c | 50 +-- kernel/workqueue.c | 2 +- scripts/kallsyms.c | 1 + scripts/module.lds.S | 23 +- tools/objtool/check.c | 7 +- tools/objtool/elf.c | 7 +- 53 files changed, 425 insertions(+), 554 deletions(-) create mode 100644 arch/x86/include/asm/cfi.h create mode 100644 arch/x86/kernel/cfi.c create mode 100644 include/linux/cfi_types.h base-commit: 506357871c18e06565840d71c2ef9f818e19f460 -- 2.37.2.789.g6183377224-goog _______________________________________________ linux-arm-kernel mailing list linux-arm-kernel@lists.infradead.org http://lists.infradead.org/mailman/listinfo/linux-arm-kernel
next reply other threads:[~2022-09-08 21:55 UTC|newest] Thread overview: 56+ messages / expand[flat|nested] mbox.gz Atom feed top 2022-09-08 21:54 Sami Tolvanen [this message] 2022-09-08 21:54 ` [PATCH v5 00/22] KCFI support Sami Tolvanen 2022-09-08 21:54 ` [PATCH v5 01/22] treewide: Filter out CC_FLAGS_CFI Sami Tolvanen 2022-09-08 21:54 ` Sami Tolvanen 2022-09-08 21:54 ` [PATCH v5 02/22] scripts/kallsyms: Ignore __kcfi_typeid_ Sami Tolvanen 2022-09-08 21:54 ` Sami Tolvanen 2022-09-08 21:54 ` [PATCH v5 03/22] cfi: Remove CONFIG_CFI_CLANG_SHADOW Sami Tolvanen 2022-09-08 21:54 ` Sami Tolvanen 2022-09-08 21:54 ` [PATCH v5 04/22] cfi: Drop __CFI_ADDRESSABLE Sami Tolvanen 2022-09-08 21:54 ` Sami Tolvanen 2022-09-08 21:54 ` [PATCH v5 05/22] cfi: Switch to -fsanitize=kcfi Sami Tolvanen 2022-09-08 21:54 ` Sami Tolvanen 2022-09-08 21:54 ` [PATCH v5 06/22] cfi: Add type helper macros Sami Tolvanen 2022-09-08 21:54 ` Sami Tolvanen 2022-09-08 21:54 ` [PATCH v5 07/22] lkdtm: Emit an indirect call for CFI tests Sami Tolvanen 2022-09-08 21:54 ` Sami Tolvanen 2022-09-08 21:54 ` [PATCH v5 08/22] psci: Fix the function type for psci_initcall_t Sami Tolvanen 2022-09-08 21:54 ` Sami Tolvanen 2022-09-08 21:54 ` [PATCH v5 09/22] arm64: Add types to indirect called assembly functions Sami Tolvanen 2022-09-08 21:54 ` Sami Tolvanen 2022-09-08 21:54 ` [PATCH v5 10/22] arm64: Add CFI error handling Sami Tolvanen 2022-09-08 21:54 ` Sami Tolvanen 2022-09-08 21:54 ` [PATCH v5 11/22] arm64: Drop unneeded __nocfi attributes Sami Tolvanen 2022-09-08 21:54 ` Sami Tolvanen 2022-09-08 21:54 ` [PATCH v5 12/22] init: Drop __nocfi from __init Sami Tolvanen 2022-09-08 21:54 ` Sami Tolvanen 2022-09-08 21:54 ` [PATCH v5 13/22] treewide: Drop function_nocfi Sami Tolvanen 2022-09-08 21:54 ` Sami Tolvanen 2022-09-08 21:54 ` [PATCH v5 14/22] treewide: Drop WARN_ON_FUNCTION_MISMATCH Sami Tolvanen 2022-09-08 21:54 ` Sami Tolvanen 2022-09-08 21:54 ` [PATCH v5 15/22] treewide: Drop __cficanonical Sami Tolvanen 2022-09-08 21:54 ` Sami Tolvanen 2022-09-08 21:54 ` [PATCH v5 16/22] objtool: Preserve special st_shndx indexes in elf_update_symbol Sami Tolvanen 2022-09-08 21:54 ` Sami Tolvanen 2022-09-08 21:54 ` [PATCH v5 17/22] objtool: Disable CFI warnings Sami Tolvanen 2022-09-08 21:54 ` Sami Tolvanen 2022-09-08 21:55 ` [PATCH v5 18/22] kallsyms: Drop CONFIG_CFI_CLANG workarounds Sami Tolvanen 2022-09-08 21:55 ` Sami Tolvanen 2022-09-08 21:55 ` [PATCH v5 19/22] x86/tools/relocs: Ignore __kcfi_typeid_ relocations Sami Tolvanen 2022-09-08 21:55 ` Sami Tolvanen 2022-09-08 21:55 ` [PATCH v5 20/22] x86: Add types to indirectly called assembly functions Sami Tolvanen 2022-09-08 21:55 ` Sami Tolvanen 2022-09-08 21:55 ` [PATCH v5 21/22] x86/purgatory: Disable CFI Sami Tolvanen 2022-09-08 21:55 ` Sami Tolvanen 2022-09-08 21:55 ` [PATCH v5 22/22] x86: Add support for CONFIG_CFI_CLANG Sami Tolvanen 2022-09-08 21:55 ` Sami Tolvanen 2022-09-26 12:39 ` [PATCH v5 00/22] KCFI support Peter Zijlstra 2022-09-26 12:39 ` Peter Zijlstra 2022-09-26 20:16 ` H.J. Lu 2022-09-26 20:16 ` H.J. Lu 2022-09-27 7:29 ` Peter Zijlstra 2022-09-27 7:29 ` Peter Zijlstra 2022-09-26 17:20 ` Kees Cook 2022-09-26 17:20 ` Kees Cook 2022-09-28 9:01 ` Sedat Dilek 2022-09-28 9:01 ` Sedat Dilek
Reply instructions: You may reply publicly to this message via plain-text email using any one of the following methods: * Save the following mbox file, import it into your mail client, and reply-to-all from there: mbox Avoid top-posting and favor interleaved quoting: https://en.wikipedia.org/wiki/Posting_style#Interleaved_style * Reply using the --to, --cc, and --in-reply-to switches of git-send-email(1): git send-email \ --in-reply-to=20220908215504.3686827-1-samitolvanen@google.com \ --to=samitolvanen@google.com \ --cc=catalin.marinas@arm.com \ --cc=joao@overdrivepizza.com \ --cc=jpoimboe@redhat.com \ --cc=keescook@chromium.org \ --cc=linux-arm-kernel@lists.infradead.org \ --cc=linux-hardening@vger.kernel.org \ --cc=linux-kernel@vger.kernel.org \ --cc=llvm@lists.linux.dev \ --cc=mark.rutland@arm.com \ --cc=nathan@kernel.org \ --cc=ndesaulniers@google.com \ --cc=peterz@infradead.org \ --cc=rostedt@goodmis.org \ --cc=sedat.dilek@gmail.com \ --cc=will@kernel.org \ --cc=x86@kernel.org \ /path/to/YOUR_REPLY https://kernel.org/pub/software/scm/git/docs/git-send-email.html * If your mail client supports setting the In-Reply-To header via mailto: links, try the mailto: linkBe sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes, see mirroring instructions on how to clone and mirror all data and code used by this external index.