From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from kanga.kvack.org (kanga.kvack.org [205.233.56.17]) by smtp.lore.kernel.org (Postfix) with ESMTP id 6CFD7C4332F for ; Wed, 13 Dec 2023 00:50:53 +0000 (UTC) Received: by kanga.kvack.org (Postfix) id D74056B02E6; Tue, 12 Dec 2023 19:50:52 -0500 (EST) Received: by kanga.kvack.org (Postfix, from userid 40) id CFC206B02E9; Tue, 12 Dec 2023 19:50:52 -0500 (EST) X-Delivered-To: int-list-linux-mm@kvack.org Received: by kanga.kvack.org (Postfix, from userid 63042) id B76CE6B02EF; Tue, 12 Dec 2023 19:50:52 -0500 (EST) X-Delivered-To: linux-mm@kvack.org Received: from relay.hostedemail.com (smtprelay0014.hostedemail.com [216.40.44.14]) by kanga.kvack.org (Postfix) with ESMTP id 9ECAC6B02E6 for ; Tue, 12 Dec 2023 19:50:52 -0500 (EST) Received: from smtpin01.hostedemail.com (a10.router.float.18 [10.200.18.1]) by unirelay09.hostedemail.com (Postfix) with ESMTP id 6F2B580B8E for ; Wed, 13 Dec 2023 00:50:52 +0000 (UTC) X-FDA: 81559965144.01.6045CCB Received: from mail-yb1-f177.google.com (mail-yb1-f177.google.com [209.85.219.177]) by imf09.hostedemail.com (Postfix) with ESMTP id 9383614000E for ; Wed, 13 Dec 2023 00:50:50 +0000 (UTC) Authentication-Results: imf09.hostedemail.com; dkim=pass header.d=rivosinc-com.20230601.gappssmtp.com header.s=20230601 header.b=OA5Vz0dO; spf=pass (imf09.hostedemail.com: domain of debug@rivosinc.com designates 209.85.219.177 as permitted sender) smtp.mailfrom=debug@rivosinc.com; dmarc=none ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=hostedemail.com; s=arc-20220608; t=1702428650; h=from:from:sender:reply-to:subject:subject:date:date: message-id:message-id:to:to:cc:cc:mime-version:mime-version: content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references:dkim-signature; bh=IsP6D8T5vC4K0WLWKELqerL/h2k2GCGETaeygCJbK5E=; b=dAlAKyargFi5wa4Cl7o8Zg2pKrHWcNKYuwD9H6pLudxBOeJpiuPhvw6Ae4TNdDCPjoStcq A+VuLxevwqVTxVZq7Vzh3Q1d0YYUhQjkAig9eDTuZtl9jsroDBk2WWrIyCQaWm6SD6lvge sdkWZC7PYZbjKFcPYa75RPaH27sZeFU= ARC-Seal: i=1; s=arc-20220608; d=hostedemail.com; t=1702428650; a=rsa-sha256; cv=none; b=u0c1rTc10DMtOTgdAisCzJ0TgiI3NPreX6KIgiKIMpZvPUpD+6/WtXh+1RMemJ4SCY4ibN a2AGQq2243jEDBLfm8JVAsJBARRqytNGkGGA2HqbMDKxu8f9k5OqARjecKef91KKQBFFwA nBhgjII2k/gefVrjpEFi8R7ToQx0v6I= ARC-Authentication-Results: i=1; imf09.hostedemail.com; dkim=pass header.d=rivosinc-com.20230601.gappssmtp.com header.s=20230601 header.b=OA5Vz0dO; spf=pass (imf09.hostedemail.com: domain of debug@rivosinc.com designates 209.85.219.177 as permitted sender) smtp.mailfrom=debug@rivosinc.com; dmarc=none Received: by mail-yb1-f177.google.com with SMTP id 3f1490d57ef6-dbc72b692adso3210416276.2 for ; Tue, 12 Dec 2023 16:50:50 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=rivosinc-com.20230601.gappssmtp.com; s=20230601; t=1702428649; x=1703033449; darn=kvack.org; h=content-transfer-encoding:cc:to:subject:message-id:date:from :in-reply-to:references:mime-version:from:to:cc:subject:date :message-id:reply-to; bh=IsP6D8T5vC4K0WLWKELqerL/h2k2GCGETaeygCJbK5E=; b=OA5Vz0dOg/WB7q0Ok6RWyFy6u+n4qewqqldNXTQY8Kq1jJW1lpOzCOM0li6s0fq+7L IPfCMzgu71+zFFOGJLgNhh2l/1fxmofj/Bl7/KE4UV6PULNc436KxBWtxQwCjuUjU7XF mB2/waAmDprJtqXjXCJbBQ80x1N6nxejkYzLc7ZwYPP5zB5J2k0f46yk2fI6El3NxOmm /6M0IsLpJmR8zYhnzuKnlns9cGdpoaBTpFk4+zZm7TM3ckETCQ/P+cAAVWBIDv1sknRb wCD6j+6vlpPLl7PD2FetWi4jcb3PPD1ZFtllCScZ53sbQm/PPqjbGdKetasO2/fGvW0K duEA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1702428649; x=1703033449; h=content-transfer-encoding:cc:to:subject:message-id:date:from :in-reply-to:references:mime-version:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to; bh=IsP6D8T5vC4K0WLWKELqerL/h2k2GCGETaeygCJbK5E=; b=onQOgyJDCV2a8VBc82GNALdDxflYVmXCkS2n9uP+4y+vpYy39oOyVqN/wei4fp8qqY VT7/CnJDvAvgcKBPetKafkYKcEKzUUqB9ftMR0Gxvjeh/f8ovaCMsLc82uuuumej0PHK qiFUYvjO8TIpc8coBFUxiCFWp3CSvxHGVp6my6LK+jZU8hHA0OjpIb9VNAZvd4GvYLqj mpRofeEpAE6eE1w9jUb+fWKNmyrcVsBZL8m8fq+Ba/+K1rckp37p6a1BMQyUFGQZ3lCC PMclipVUSy9kdMP8qPttdvA5P93bJVb96RM/JQvujHJiJY9JwKLXrzBmFnq29jhHb1n7 RUFA== X-Gm-Message-State: AOJu0YyYW7r9Kj9X7rQ9/nlCoNIbP5vOVOdUv/8uM5PeHr/mcC1gFutS UD6Io8LXodL3rnC3SsOW6mU+Jql3nt/jirqerWj8Aw== X-Google-Smtp-Source: AGHT+IFg4hZCse8kzky6Y9/DVuxOtpUz/g7bXwrKJ9hF5mEV7x9P3i3TYFdKJnIuamiDiHUwxXUn6NjiQwKNsCzwWqw= X-Received: by 2002:a25:8051:0:b0:db7:e91c:eb1d with SMTP id a17-20020a258051000000b00db7e91ceb1dmr4411297ybn.102.1702428649654; Tue, 12 Dec 2023 16:50:49 -0800 (PST) MIME-Version: 1.0 References: <20231122-arm64-gcs-v7-0-201c483bd775@kernel.org> <20231122-arm64-gcs-v7-2-201c483bd775@kernel.org> In-Reply-To: From: Deepak Gupta Date: Tue, 12 Dec 2023 16:50:38 -0800 Message-ID: Subject: Re: [PATCH v7 02/39] prctl: arch-agnostic prctl for shadow stack To: Mark Brown Cc: Catalin Marinas , Will Deacon , Jonathan Corbet , Andrew Morton , Marc Zyngier , Oliver Upton , James Morse , Suzuki K Poulose , Arnd Bergmann , Oleg Nesterov , Eric Biederman , Kees Cook , Shuah Khan , "Rick P. Edgecombe" , Ard Biesheuvel , Szabolcs Nagy , "H.J. Lu" , Paul Walmsley , Palmer Dabbelt , Albert Ou , Florian Weimer , Christian Brauner , Thiago Jung Bauermann , linux-arm-kernel@lists.infradead.org, linux-doc@vger.kernel.org, kvmarm@lists.linux.dev, linux-fsdevel@vger.kernel.org, linux-arch@vger.kernel.org, linux-mm@kvack.org, linux-kselftest@vger.kernel.org, linux-kernel@vger.kernel.org, linux-riscv@lists.infradead.org Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable X-Rspamd-Queue-Id: 9383614000E X-Rspam-User: X-Rspamd-Server: rspam11 X-Stat-Signature: exownnh74hmpefqzdudk1f8nrf6h9ays X-HE-Tag: 1702428650-257265 X-HE-Meta: U2FsdGVkX1/G31wYPSItCBDAqVS0vRODjZnW1UQNLZcg3n7eOtvartEzG10A3NXVg6AnXcmokWDIJ53xoBLMhlC8QmUNR1OJbrM3Tdd2v6eB5XlqdEc8sbDREv9mayESVXSO07Fwq35WgGfULiF3fanbTz3SrOuF4+6S5pzvEBNOMx7Kzl4GoITWlcZzYmCIaYLa4l5lQpMLOM8hAV14/wOSRgU91Q2r+ioXa/UuTmKq27EVnzBSm6oBrFIARLP0HeXfeuGz4exhzIIVx4Vy82RGDjtVxUvPZCG/abUcqRrqoRfDUpgZ28V6aLFbOBfs/Yt/wL1qrde5upiXkYg9XvY4xEzPgc0iYziUPmoYQnNciqf+pviOqjSA5vWbxWfQIDemrCWSUndKD3GtePHQYSfMDfMmIMCSBJi8RbywP0/D2f5NWXWvnJDdHcjWKqbNxyAmvmzkObbRyS8IP6a7l9n+gOEt0JI6Tt1ZdcnxOrqjoEnWMzSoI7tHQiLbFl4RfqYp3gF5IZKpuekVJALcyjIyPWzfsPnyL9K9A2hblONmAM4m8Ng7OVFZaEsV/HySu8JF+pXvpAfA8AUcmrLsroU9NO6D8VeHVWdE4A52vssE+TQAxc8tyAfC0Fh+HLg6fzjXxsusmdpkPyyNuAjSbLdcVZaY73XtTbJL6orYMGiLeh3f33xHXGEEigu1jG9Xva57Gj+aJqJeie85mLVVf8e2OO1B5ZpeJ8GzG0jvR+KQw09A6DQ6tTiOoGtLjQZFUulSiX6NywWdqBbovXJuYW/2w6uBgjFFOhy/yDxhHxpgnH3ttki32/pgCVIk6CbuTBiER+NBdKOgix80P27mCtWK8TXrcpZ/ILaH3WRyJSOjDg1bqTnhG4yNMmpIUkoy6LPMD05w+SEL//y9oWE2Jz+LbprugtehJj5u1kDmTyHJmBCvORbVx2gauDpsbQdwE6TXAQn+An8kYO9LpVS p3+a7UIu BEzvmoUfJ/s2xNJTRALkJvFukMvrfRZ8AZ4ZMnseR6/ExZnY3EJRTO0+/VTMZ0R0v1KJ9sY9mprSr8ooRBAPfwU1jc9CU4Qx5uJWcRtZNxlgBSVOjHsCgYSrkPADsThxdMC3ipIPX98mjhZ+WCMfNouej3pbYwt3FF44HuiUv9/HEiBaHUqYwM8opGjvAXA68oRi/LinwHwZw/wBm2ydr4x6Yb2lCA7AR+VJPS6OAOxGBrmhqoWKH22h/N8K+GiIwzl0qmXn2wNwCGHBld7VQ4BMEK/p1cyXIfDaWON+aGfjeFOb6xdrxlBYwKphIJTEa2KrvqSlZWm5SYj3cagPmdlaMvSsL94bIJBB5EA2ddQTaCzAwJSNXQtm35QoEotwbFmgz9UTgRfQAexltIfIUM2F+tdMcKZtrnQfH7LMGbP+i2NfIw1cLEEXO32RegyvwWxFFwdBZGnoV25k= X-Bogosity: Ham, tests=bogofilter, spamicity=0.000000, version=1.2.4 Sender: owner-linux-mm@kvack.org Precedence: bulk X-Loop: owner-majordomo@kvack.org List-ID: List-Subscribe: List-Unsubscribe: On Tue, Dec 12, 2023 at 11:23=E2=80=AFAM Mark Brown wr= ote: > > On Tue, Dec 12, 2023 at 11:17:11AM -0800, Deepak Gupta wrote: > > On Wed, Nov 22, 2023 at 1:43=E2=80=AFAM Mark Brown = wrote: > > > > +/* > > > + * Set the current shadow stack configuration. Enabling the shadow > > > + * stack will cause a shadow stack to be allocated for the thread. > > > + */ > > > +#define PR_SET_SHADOW_STACK_STATUS 72 > > > +# define PR_SHADOW_STACK_ENABLE (1UL << 0) > > > Other architecture may require disabling shadow stack if glibc > > tunables is set to permissive mode. > > In permissive mode, if glibc encounters `dlopen` on an object which > > doesn't support shadow stack, > > glibc should be able to issue PR_SHADOW_STACK_DISABLE. > > > Architectures can choose to implement or not but I think arch agnostic > > code should enumerate this. > > The current implementation for arm64 and therefore API for the prctl() > is that whatever combination of flags is specified will be set, this > means that setting the status to something that does not include _ENABLE > will result in disabling and we don't need a separate flag for disable. > We have use cases that make active use of disabling at runtime. A theoretical scenario (no current workloads should've this case because no shadow stack) - User mode did _ENABLE on the main thread. Shadow stack was allocated for the current thread. - User mode created a bunch worker threads to run untrusted contained code. They shadow stack too. - main thread had to do dlopen and now need to disable shadow stack on itself due to incompatibility of incoming object in address space. - main thread controls worker threads and knows they're contained and should still be running with a shadow stack. Although once in a while the main thread needs to perform writes to a shadow stack of worker threads for some fixup (in the same addr space). main thread doesn't want to delegate this responsibility of ss writes to worker threads because they're untrus= ted. How will it do that (currently _ENABLE is married to _WRITE and _PUSH) ? Please note that I am making up this scenario just for sake of discussion And don't know if software would be using it in this manner. > > Please delete unneeded context from replies, it makes it much easier to > find new content. Sorry about that. Noted.