From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from kanga.kvack.org (kanga.kvack.org [205.233.56.17]) by smtp.lore.kernel.org (Postfix) with ESMTP id 63D7AC433F5 for ; Mon, 3 Oct 2022 17:18:15 +0000 (UTC) Received: by kanga.kvack.org (Postfix) id 7856F6B0071; Mon, 3 Oct 2022 13:18:14 -0400 (EDT) Received: by kanga.kvack.org (Postfix, from userid 40) id 70DB06B0073; Mon, 3 Oct 2022 13:18:14 -0400 (EDT) X-Delivered-To: int-list-linux-mm@kvack.org Received: by kanga.kvack.org (Postfix, from userid 63042) id 560B98E0001; Mon, 3 Oct 2022 13:18:14 -0400 (EDT) X-Delivered-To: linux-mm@kvack.org Received: from relay.hostedemail.com (smtprelay0016.hostedemail.com [216.40.44.16]) by kanga.kvack.org (Postfix) with ESMTP id 3AFA36B0071 for ; Mon, 3 Oct 2022 13:18:14 -0400 (EDT) Received: from smtpin08.hostedemail.com (a10.router.float.18 [10.200.18.1]) by unirelay02.hostedemail.com (Postfix) with ESMTP id CD3261205ED for ; Mon, 3 Oct 2022 17:18:13 +0000 (UTC) X-FDA: 79980296466.08.3DB294A Received: from mail-pl1-f177.google.com (mail-pl1-f177.google.com [209.85.214.177]) by imf22.hostedemail.com (Postfix) with ESMTP id EE6F2C0017 for ; Mon, 3 Oct 2022 17:18:12 +0000 (UTC) Received: by mail-pl1-f177.google.com with SMTP id c24so191055pls.9 for ; Mon, 03 Oct 2022 10:18:12 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=chromium.org; s=google; h=in-reply-to:content-disposition:mime-version:references:message-id :subject:cc:to:from:date:from:to:cc:subject:date; bh=DUSAgm1tGARrhgAa+YXJyBkN7A5KbivkL+1rvMQ+tQc=; b=Of4O9so7/tSkTzAhtAmZ+McsJYDlbXtDFPfPIaWqeHQqx0dNBvuOCri5UaoKbaXhOK y6gXjMlY2as/UO/bCo3kBsjsJP7fvzviBg59V2TvtA70FIIFvHZxrHXgb8EaKe3XjuwU Wg6HcGRQExXlzVGqQhNLlqWLYTLYRjlajnCQU= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20210112; h=in-reply-to:content-disposition:mime-version:references:message-id :subject:cc:to:from:date:x-gm-message-state:from:to:cc:subject:date; bh=DUSAgm1tGARrhgAa+YXJyBkN7A5KbivkL+1rvMQ+tQc=; b=OLNGrUtqw4MLgWM9XiS3AkMoadiES2VeM4xTxqhsWJI9CxE14d1DXNr6wFJFb2X1cn EwINNDDiEMAXxtAypnMtsDX2bKHOq4y3qs+iFO/90k6WCatKX6gnrQhY6JojcCTVyh9w f65UAYJly9h4tcy2UWstefflcBjmgv+QpDmHPtt18YUGhKNNefzTEQQv67mooNVge0HD kOzC+V1Jx4wgwBJiX5W+0IcIHefM2yPpTjBNNNWz8ibtN0sQ2Mt1g7IBtDsJjvoqyHW9 HkV1UsIH+kM2OfaLALcBzeJPoXSUwaGwBWgRkKVkfIjsfnSCtTbAjW7ntSzvSEZcTkyt PKJA== X-Gm-Message-State: ACrzQf30xVz5xBmKnvZ9vK/ZVep2RZUp+BAnFAxdFd49MWh5K3P4mj6A d1wxFRfZ+ZDBOSPR0OKOna1rug== X-Google-Smtp-Source: AMsMyM6gix+5GlV36V2qSUzA6hoZQ8rkNTODSa4bi8qPDTOaiRU0xMg3oXO3dVq8uVOs01K5lS8u7w== X-Received: by 2002:a17:90b:1648:b0:203:c8d3:99b0 with SMTP id il8-20020a17090b164800b00203c8d399b0mr13356266pjb.54.1664817491587; Mon, 03 Oct 2022 10:18:11 -0700 (PDT) Received: from www.outflux.net (smtp.outflux.net. [198.145.64.163]) by smtp.gmail.com with ESMTPSA id o17-20020a639a11000000b0043ba3d6ea3fsm7069554pge.54.2022.10.03.10.18.10 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 03 Oct 2022 10:18:10 -0700 (PDT) Date: Mon, 3 Oct 2022 10:18:09 -0700 From: Kees Cook To: Rick Edgecombe Cc: x86@kernel.org, "H . Peter Anvin" , Thomas Gleixner , Ingo Molnar , linux-kernel@vger.kernel.org, linux-doc@vger.kernel.org, linux-mm@kvack.org, linux-arch@vger.kernel.org, linux-api@vger.kernel.org, Arnd Bergmann , Andy Lutomirski , Balbir Singh , Borislav Petkov , Cyrill Gorcunov , Dave Hansen , Eugene Syromiatnikov , Florian Weimer , "H . J . Lu" , Jann Horn , Jonathan Corbet , Mike Kravetz , Nadav Amit , Oleg Nesterov , Pavel Machek , Peter Zijlstra , Randy Dunlap , "Ravi V . Shankar" , Weijiang Yang , "Kirill A . Shutemov" , joao.moreira@intel.com, John Allen , kcc@google.com, eranian@google.com, rppt@kernel.org, jamorris@linux.microsoft.com, dethoma@microsoft.com, Yu-cheng Yu Subject: Re: [PATCH v2 01/39] Documentation/x86: Add CET description Message-ID: <202210031006.02C79ED58@keescook> References: <20220929222936.14584-1-rick.p.edgecombe@intel.com> <20220929222936.14584-2-rick.p.edgecombe@intel.com> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <20220929222936.14584-2-rick.p.edgecombe@intel.com> ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=hostedemail.com; s=arc-20220608; t=1664817493; h=from:from:sender:reply-to:subject:subject:date:date: message-id:message-id:to:to:cc:cc:mime-version:mime-version: content-type:content-type:content-transfer-encoding: in-reply-to:in-reply-to:references:references:dkim-signature; bh=DUSAgm1tGARrhgAa+YXJyBkN7A5KbivkL+1rvMQ+tQc=; b=nDDgKjApYnex4TTYUcSdMxvngtTscSX6jgFVDTQuGWgnaZb6pcRDhea+8vBvZe8Pyp/568 G3OTEZt1GScwvqM0d/CbAKHC92JrfkajlbE8gN7NLj7IakrM06d21M6/KSHhUYbMO7sCnp p2f9JmvxsyEc5zp73g5aRO7PwfHUaWA= ARC-Authentication-Results: i=1; imf22.hostedemail.com; dkim=pass header.d=chromium.org header.s=google header.b=Of4O9so7; dmarc=pass (policy=none) header.from=chromium.org; spf=pass (imf22.hostedemail.com: domain of keescook@chromium.org designates 209.85.214.177 as permitted sender) smtp.mailfrom=keescook@chromium.org ARC-Seal: i=1; s=arc-20220608; d=hostedemail.com; t=1664817493; a=rsa-sha256; cv=none; b=hLqRQDkk4Yms7cnID4jhxrsY4GIidvmvEO901eZKtWaAw/WF+3rQvh50h4IYcG8+vzfoYD zQrctILK/RSk+StdXL60BJyqt5IhHWO4rQaIz/yTsKw6PQuG5I1smW9/Kyrt35BSnWckwj YgFjWLO01GqrR699VPhUwxUvdFUzedM= X-Stat-Signature: 444rricbxbn9p1b8w619q8aymijs6rrj X-Rspam-User: X-Rspamd-Server: rspam05 X-Rspamd-Queue-Id: EE6F2C0017 Authentication-Results: imf22.hostedemail.com; dkim=pass header.d=chromium.org header.s=google header.b=Of4O9so7; dmarc=pass (policy=none) header.from=chromium.org; spf=pass (imf22.hostedemail.com: domain of keescook@chromium.org designates 209.85.214.177 as permitted sender) smtp.mailfrom=keescook@chromium.org X-HE-Tag: 1664817492-523942 X-Bogosity: Ham, tests=bogofilter, spamicity=0.000000, version=1.2.4 Sender: owner-linux-mm@kvack.org Precedence: bulk X-Loop: owner-majordomo@kvack.org List-ID: On Thu, Sep 29, 2022 at 03:28:58PM -0700, Rick Edgecombe wrote: > [...] > +Overview > +======== > + > +Control-flow Enforcement Technology (CET) is term referring to several > +related x86 processor features that provides protection against control > +flow hijacking attacks. The HW feature itself can be set up to protect > +both applications and the kernel. Only user-mode protection is implemented > +in the 64-bit kernel. This likely needs rewording, since it's not strictly true any more: IBT is supported in kernel-mode now (CONFIG_X86_IBT). > +CET introduces Shadow Stack and Indirect Branch Tracking. Shadow stack is > +a secondary stack allocated from memory and cannot be directly modified by > +applications. When executing a CALL instruction, the processor pushes the > +return address to both the normal stack and the shadow stack. Upon > +function return, the processor pops the shadow stack copy and compares it > +to the normal stack copy. If the two differ, the processor raises a > +control-protection fault. Indirect branch tracking verifies indirect > +CALL/JMP targets are intended as marked by the compiler with 'ENDBR' > +opcodes. Not all CPU's have both Shadow Stack and Indirect Branch Tracking > +and only Shadow Stack is currently supported in the kernel. > + > +The Kconfig options is X86_SHADOW_STACK, and it can be disabled with > +the kernel parameter clearcpuid, like this: "clearcpuid=shstk". > + > +To build a CET-enabled kernel, Binutils v2.31 and GCC v8.1 or LLVM v10.0.1 > +or later are required. To build a CET-enabled application, GLIBC v2.28 or > +later is also required. > + > +At run time, /proc/cpuinfo shows CET features if the processor supports > +CET. Maybe call them out by name: shstk ibt > +CET arch_prctl()'s > +================== > + > +Elf features should be enabled by the loader using the below arch_prctl's. > + > +arch_prctl(ARCH_CET_ENABLE, unsigned int feature) > + Enable a single feature specified in 'feature'. Can only operate on > + one feature at a time. Does this mean only 1 bit out of the 32 may be specified? > + > +arch_prctl(ARCH_CET_DISABLE, unsigned int feature) > + Disable features specified in 'feature'. Can only operate on > + one feature at a time. > + > +arch_prctl(ARCH_CET_LOCK, unsigned int features) > + Lock in features at their current enabled or disabled status. How is the "features" argument processed here? > [...] > +Proc status > +=========== > +To check if an application is actually running with shadow stack, the > +user can read the /proc/$PID/arch_status. It will report "wrss" or > +"shstk" depending on what is enabled. TIL about "arch_status". :) Why is this a separate file? "status" is already has unique field names. > +Fork > +---- > + > +The shadow stack's vma has VM_SHADOW_STACK flag set; its PTEs are required > +to be read-only and dirty. When a shadow stack PTE is not RO and dirty, a > +shadow access triggers a page fault with the shadow stack access bit set > +in the page fault error code. > + > +When a task forks a child, its shadow stack PTEs are copied and both the > +parent's and the child's shadow stack PTEs are cleared of the dirty bit. > +Upon the next shadow stack access, the resulting shadow stack page fault > +is handled by page copy/re-use. > + > +When a pthread child is created, the kernel allocates a new shadow stack > +for the new thread. Perhaps speak to the ASLR characteristics of the shstk here? Also, it seems if there is a "Fork" section, there should be an "Exec" section? I suspect it would be short: shstk is disabled when execve() is called and must be re-enabled from userspace, yes? -Kees -- Kees Cook