All of lore.kernel.org
 help / color / mirror / Atom feed
From: Vincenzo Frascino <vincenzo.frascino@arm.com>
To: Catalin Marinas <catalin.marinas@arm.com>,
	Amit Daniel Kachhap <amit.kachhap@arm.com>
Cc: Mark Rutland <mark.rutland@arm.com>,
	Kees Cook <keescook@chromium.org>,
	Suzuki K Poulose <suzuki.poulose@arm.com>,
	Kristina Martsenko <kristina.martsenko@arm.com>,
	Dave Martin <Dave.Martin@arm.com>,
	Masahiro Yamada <yamada.masahiro@socionext.com>,
	Mark Brown <broonie@kernel.org>,
	James Morse <james.morse@arm.com>,
	Ramana Radhakrishnan <ramana.radhakrishnan@arm.com>,
	Will Deacon <will@kernel.org>, Ard Biesheuvel <ardb@kernel.org>,
	linux-arm-kernel@lists.infradead.org
Subject: Re: [PATCH v5 16/17] arm64: compile the kernel with ptrauth return address signing
Date: Wed, 4 Mar 2020 10:53:16 +0000	[thread overview]
Message-ID: <d7efa284-77fe-9e60-3aa4-4d351550835b@arm.com> (raw)
In-Reply-To: <20200228182337.GK4019108@arrakis.emea.arm.com>

Hi Catalin,

On 2/28/20 6:23 PM, Catalin Marinas wrote:
> On Mon, Feb 17, 2020 at 02:57:47PM +0530, Amit Daniel Kachhap wrote:
>> +ifeq ($(CONFIG_ARM64_PTR_AUTH),y)
>> +branch-prot-flags-$(CONFIG_CC_HAS_SIGN_RETURN_ADDRESS) := -msign-return-address=all
>> +branch-prot-flags-$(CONFIG_CC_HAS_BRANCH_PROT_PAC_RET) := -mbranch-protection=pac-ret+leaf
>> +# -march=armv8.3-a enables the non-nops instructions for PAC, to avoid the compiler
>> +# to generate them and consequently to break the single image contract we pass it
>> +# only to the assembler when clang is selected as a compiler. For the GNU toolchain
>> +# this option is not used.
>> +branch-prot-flags-$(CONFIG_AS_HAS_PAC) += -Wa,-march=armv8.3-a
>> +KBUILD_CFLAGS += $(branch-prot-flags-y)
>> +endif
> 
> Does this work with the clang integrated assembler? AFAIK it ignores the
> -Wa, though it may be fine with the instructions generated by the
> compiler. (while we don't officially support it, we merged patches to
> facilitate it).
> 

The kernel is currently built with "-no-integrated-as" (Makefile +538) when
clang is selected. This means that the only assembler supported is the one
provide by binutils in this scenario.

The only patch series that I am aware of that is trying to do something with the
integrated as is [1] that uses it for inline assembly when LTO is enabled
(mainly for Android kernels at the moment). And this series is still being
reviewed.

Curiosity, which one is the series you are referring to? And how do I enable the
clang assembler for building the kernel?

[1] https://github.com/samitolvanen/linux/commits/clang-cfi

-- 
Regards,
Vincenzo

_______________________________________________
linux-arm-kernel mailing list
linux-arm-kernel@lists.infradead.org
http://lists.infradead.org/mailman/listinfo/linux-arm-kernel

  parent reply	other threads:[~2020-03-04 10:53 UTC|newest]

Thread overview: 37+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2020-02-17  9:27 [PATCH v5 00/17] arm64: return address signing Amit Daniel Kachhap
2020-02-17  9:27 ` [PATCH v5 01/17] arm64: cpufeature: Fix meta-capability cpufeature check Amit Daniel Kachhap
2020-02-17  9:27 ` [PATCH v5 02/17] arm64: cpufeature: add pointer auth meta-capabilities Amit Daniel Kachhap
2020-02-17  9:27 ` [PATCH v5 03/17] arm64: rename ptrauth key structures to be user-specific Amit Daniel Kachhap
2020-02-17  9:27 ` [PATCH v5 04/17] arm64: install user ptrauth keys at kernel exit time Amit Daniel Kachhap
2020-02-17  9:27 ` [PATCH v5 05/17] arm64: create macro to park cpu in an infinite loop Amit Daniel Kachhap
2020-02-17  9:27 ` [PATCH v5 06/17] arm64: add bootup/runtime flags for __cpu_setup Amit Daniel Kachhap
2020-02-17  9:27 ` [PATCH v5 07/17] arm64: cpufeature: handle conflicts based on capability Amit Daniel Kachhap
2020-02-28 18:18   ` Catalin Marinas
2020-03-02  9:29     ` Amit Kachhap
2020-02-17  9:27 ` [PATCH v5 08/17] arm64: enable ptrauth earlier Amit Daniel Kachhap
2020-02-17  9:27 ` [PATCH v5 09/17] arm64: initialize and switch ptrauth kernel keys Amit Daniel Kachhap
2020-02-17  9:27 ` [PATCH v5 10/17] arm64: initialize ptrauth keys for kernel booting task Amit Daniel Kachhap
2020-02-17  9:27 ` [PATCH v5 11/17] arm64: mask PAC bits of __builtin_return_address Amit Daniel Kachhap
2020-02-17  9:27 ` [PATCH v5 12/17] arm64: unwind: strip PAC from kernel addresses Amit Daniel Kachhap
2020-02-17  9:27 ` [PATCH v5 13/17] arm64: __show_regs: strip PAC from lr in printk Amit Daniel Kachhap
2020-02-17  9:27 ` [PATCH v5 14/17] arm64: suspend: restore the kernel ptrauth keys Amit Daniel Kachhap
2020-02-28 18:18   ` Catalin Marinas
2020-03-02 10:13     ` Amit Kachhap
2020-02-17  9:27 ` [PATCH v5 15/17] kconfig: Add support for 'as-option' Amit Daniel Kachhap
2020-02-17  9:27   ` Amit Daniel Kachhap
2020-02-17  9:39   ` Masahiro Yamada
2020-02-17  9:39     ` Masahiro Yamada
2020-02-17 10:16     ` Vincenzo Frascino
2020-02-17 10:16       ` Vincenzo Frascino
2020-02-18  0:37       ` Masahiro Yamada
2020-02-18  0:37         ` Masahiro Yamada
2020-02-18 10:14         ` Vincenzo Frascino
2020-02-18 10:14           ` Vincenzo Frascino
2020-02-17  9:27 ` [PATCH v5 16/17] arm64: compile the kernel with ptrauth return address signing Amit Daniel Kachhap
2020-02-28 18:23   ` Catalin Marinas
2020-03-02 10:19     ` Amit Kachhap
2020-03-02 13:16     ` Mark Brown
2020-03-04 11:01       ` Vincenzo Frascino
2020-03-03  9:28     ` Amit Kachhap
2020-03-04 10:53     ` Vincenzo Frascino [this message]
2020-02-17  9:27 ` [PATCH v5 17/17] lkdtm: arm64: test kernel pointer authentication Amit Daniel Kachhap

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=d7efa284-77fe-9e60-3aa4-4d351550835b@arm.com \
    --to=vincenzo.frascino@arm.com \
    --cc=Dave.Martin@arm.com \
    --cc=amit.kachhap@arm.com \
    --cc=ardb@kernel.org \
    --cc=broonie@kernel.org \
    --cc=catalin.marinas@arm.com \
    --cc=james.morse@arm.com \
    --cc=keescook@chromium.org \
    --cc=kristina.martsenko@arm.com \
    --cc=linux-arm-kernel@lists.infradead.org \
    --cc=mark.rutland@arm.com \
    --cc=ramana.radhakrishnan@arm.com \
    --cc=suzuki.poulose@arm.com \
    --cc=will@kernel.org \
    --cc=yamada.masahiro@socionext.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.