From: Peter Zijlstra <peterz@infradead.org>
To: Josh Poimboeuf <jpoimboe@redhat.com>,
Thomas Gleixner <tglx@linutronix.de>
Cc: Miroslav Benes <mbenes@suse.cz>,
Nick Desaulniers <ndesaulniers@google.com>,
Julien Thierry <jthierry@redhat.com>,
Kees Cook <keescook@chromium.org>,
x86@kernel.org, linux-kernel@vger.kernel.org,
peterz@infradead.org
Subject: [PATCH 5/5] objtool: Support stack-swizzle
Date: Wed, 03 Feb 2021 13:02:27 +0100 [thread overview]
Message-ID: <20210203120401.321109449@infradead.org> (raw)
In-Reply-To: 20210203120222.451068583@infradead.org
Natively support the stack swizzle pattern:
mov %rsp, (%[tos])
mov %[tos], %rsp
...
pop %rsp
with the constraint that %[tos] must be !arch_callee_saved_reg().
It uses the (newly minted) scratch regs to link the first two
stack-ops, and detect the SP to SP_INDIRECT swizzle.
Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org>
---
tools/objtool/check.c | 43 +++++++++++++++++++++++++++++++++++++++++++
1 file changed, 43 insertions(+)
--- a/tools/objtool/check.c
+++ b/tools/objtool/check.c
@@ -1937,6 +1937,34 @@ static int update_cfi_state(struct instr
cfa->offset = -cfi->vals[op->src.reg].offset;
cfi->stack_size = cfa->offset;
+ } else if (cfa->base == CFI_SP &&
+ cfi->regs[op->src.reg].base == CFI_SP_INDIRECT &&
+ cfi->regs[op->src.reg].offset == cfa->offset) {
+
+ /*
+ * Stack swizzle:
+ *
+ * 1: mov %rsp, (%[tos])
+ * 2: mov %[tos], %rsp
+ * ...
+ * 3: pop %rsp
+ *
+ * Where:
+ *
+ * 1 - places a pointer to the previous
+ * stack at the Top-of-Stack of the
+ * new stack.
+ *
+ * 2 - switches to the new stack.
+ *
+ * 3 - pops the Top-of-Stack to restore
+ * the original stack.
+ *
+ * Note:
+ * %[tos] must not be a callee saved reg
+ */
+ cfa->base = CFI_SP_INDIRECT;
+
} else {
cfa->base = CFI_UNDEFINED;
cfa->offset = 0;
@@ -2028,6 +2056,13 @@ static int update_cfi_state(struct instr
case OP_SRC_POP:
case OP_SRC_POPF:
+ if (op->dest.reg == CFI_SP && cfa->base == CFI_SP_INDIRECT) {
+
+ /* pop %rsp; # restore from a stack swizzle */
+ cfa->base = CFI_SP;
+ break;
+ }
+
if (!cfi->drap && op->dest.reg == cfa->base) {
/* pop %rbp */
@@ -2154,6 +2189,14 @@ static int update_cfi_state(struct instr
/* mov reg, disp(%rsp) */
save_reg(cfi, op->src.reg, CFI_CFA,
op->dest.offset - cfi->cfa.offset);
+
+ } else if (op->src.reg == CFI_SP && op->dest.offset == 0) {
+
+ /* mov %rsp, (%reg); # setup a stack swizzle. */
+ if (!arch_callee_saved_reg(op->dest.reg)) {
+ __save_reg(cfi, op->dest.reg, CFI_SP_INDIRECT, cfi->cfa.offset);
+ skip_wipe = true;
+ }
}
break;
prev parent reply other threads:[~2021-02-03 12:06 UTC|newest]
Thread overview: 9+ messages / expand[flat|nested] mbox.gz Atom feed top
2021-02-03 12:02 [PATCH 0/5] objtool: The stack swizzle again Peter Zijlstra
2021-02-03 12:02 ` [PATCH 1/5] objtool: Change REG_SP_INDIRECT Peter Zijlstra
2021-02-03 14:42 ` Josh Poimboeuf
2021-02-03 14:49 ` Peter Zijlstra
2021-02-03 14:55 ` Josh Poimboeuf
2021-02-03 12:02 ` [PATCH 2/5] objtool: More consistent use of arch_callee_saved_reg() Peter Zijlstra
2021-02-03 12:02 ` [PATCH 3/5] objtool: Prepare for scratch regs Peter Zijlstra
2021-02-03 12:02 ` [PATCH 4/5] objtool,x86: Additionally decode: mov %rsp, (%reg) Peter Zijlstra
2021-02-03 12:02 ` Peter Zijlstra [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20210203120401.321109449@infradead.org \
--to=peterz@infradead.org \
--cc=jpoimboe@redhat.com \
--cc=jthierry@redhat.com \
--cc=keescook@chromium.org \
--cc=linux-kernel@vger.kernel.org \
--cc=mbenes@suse.cz \
--cc=ndesaulniers@google.com \
--cc=tglx@linutronix.de \
--cc=x86@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).