[RFC,17/43] x86/pie: Enable stack protector only if per-cpu stack canary is supported
Message ID | dbf5865f3d03805ee2e9062d03d359e551b6e9ba.1682673543.git.houwenlong.hwl@antgroup.com |
---|---|
State | New |
Headers |
Return-Path: <linux-kernel-owner@vger.kernel.org> Delivered-To: ouuuleilei@gmail.com Received: by 2002:a59:b0ea:0:b0:3b6:4342:cba0 with SMTP id b10csp820940vqo; Fri, 28 Apr 2023 03:10:55 -0700 (PDT) X-Google-Smtp-Source: ACHHUZ7vkvubQs5GGNs5foIdURHZKsBWkLdh2H0vW6pSJVhEvKegNJXxRhz1RyHGbqvNz2GvC6F1 X-Received: by 2002:a17:90b:4f83:b0:247:a22d:2a44 with SMTP id qe3-20020a17090b4f8300b00247a22d2a44mr4817113pjb.36.1682676654877; Fri, 28 Apr 2023 03:10:54 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1682676654; cv=none; d=google.com; s=arc-20160816; b=r2CKKznSXm+dGrvDoiqSwfzKKxpTybVq8irmtxxlvIL9srgLj1cVzQ1BuUVEJzfc22 gt5igih2cHEDjn9g3KiHADvEDO7UU7NKXVuinHPkNNQf+4ZWl/5NCRnjPKRyYUBPehgL XyBebuGlS/xaI0M6O5hTfmjkNQyZK0WDZgPis3nZ5Q8So0VvXjEqmhKuq9K0nfAaP/yl oszodjM0oZnuH8qC0limd83MR2NT37QTAuiFM1946SGWzm+SfY8cs0P0rnphLYfGepXq EQX1Olhewff0Lml1U7RA0svTTzJr7nIxBD4b992hKZ6PFTfAULvXBQGvizzQRghZF/80 YxSA== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:content-transfer-encoding:mime-version :references:in-reply-to:message-id:date:subject:cc:to:from; bh=6bAF8OWacQ8TFXQclejb78k1fH0h4CsJv5BTZI+9504=; b=t2gkpBTg1s1HzD9iRqmyVT2j76IIEQaxnlHeT9yswNVDa3FvdiTXGcmRG9uMEuko2a SpA9kmacucEv3tVLQFrWUDoq2Ai6YeJLmeXGrfQIpGpkItVsdm96Hf7dey1nY/Y0t3Wu QzGLv4o8cT4biSGk9EVR22cLQHEzgFhRthasmHcIZruCB41Hut3XGweUSGuRmjxruvW9 taf64hNDefXpw5l2qguAyiuJzw2fWlCzS8yK6ujNh9xSV54fDzKaWrwR//cqBI1epFg6 FHQjsHL1YS6PR7Y8orRvCuXW4L/B3Zk+pTISq2xFCTpKBi/qW/Q4G9lvl33Eu0SAGUGf eXgg== ARC-Authentication-Results: i=1; mx.google.com; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=fail (p=QUARANTINE sp=QUARANTINE dis=NONE) header.from=antgroup.com Received: from out1.vger.email (out1.vger.email. [2620:137:e000::1:20]) by mx.google.com with ESMTP id v10-20020a63f20a000000b00524ba7e95c3si21549786pgh.785.2023.04.28.03.10.39; Fri, 28 Apr 2023 03:10:54 -0700 (PDT) Received-SPF: pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) client-ip=2620:137:e000::1:20; Authentication-Results: mx.google.com; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=fail (p=QUARANTINE sp=QUARANTINE dis=NONE) header.from=antgroup.com Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1345621AbjD1Jyd (ORCPT <rfc822;chrisjones.unixmen@gmail.com> + 99 others); Fri, 28 Apr 2023 05:54:33 -0400 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:35038 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1345518AbjD1JyS (ORCPT <rfc822;linux-kernel@vger.kernel.org>); Fri, 28 Apr 2023 05:54:18 -0400 Received: from out0-214.mail.aliyun.com (out0-214.mail.aliyun.com [140.205.0.214]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id 349B05BB9 for <linux-kernel@vger.kernel.org>; Fri, 28 Apr 2023 02:53:51 -0700 (PDT) X-Alimail-AntiSpam: AC=PASS;BC=-1|-1;BR=01201311R131e4;CH=green;DM=||false|;DS=||;FP=0|-1|-1|-1|0|-1|-1|-1;HT=ay29a033018047204;MF=houwenlong.hwl@antgroup.com;NM=1;PH=DS;RN=11;SR=0;TI=SMTPD_---.STFoGN5_1682675562; Received: from localhost(mailfrom:houwenlong.hwl@antgroup.com fp:SMTPD_---.STFoGN5_1682675562) by smtp.aliyun-inc.com; Fri, 28 Apr 2023 17:52:43 +0800 From: "Hou Wenlong" <houwenlong.hwl@antgroup.com> To: linux-kernel@vger.kernel.org Cc: "Thomas Garnier" <thgarnie@chromium.org>, "Lai Jiangshan" <jiangshan.ljs@antgroup.com>, "Kees Cook" <keescook@chromium.org>, "Hou Wenlong" <houwenlong.hwl@antgroup.com>, "Thomas Gleixner" <tglx@linutronix.de>, "Ingo Molnar" <mingo@redhat.com>, "Borislav Petkov" <bp@alien8.de>, "Dave Hansen" <dave.hansen@linux.intel.com>, <x86@kernel.org>, "H. Peter Anvin" <hpa@zytor.com> Subject: [PATCH RFC 17/43] x86/pie: Enable stack protector only if per-cpu stack canary is supported Date: Fri, 28 Apr 2023 17:50:57 +0800 Message-Id: <dbf5865f3d03805ee2e9062d03d359e551b6e9ba.1682673543.git.houwenlong.hwl@antgroup.com> X-Mailer: git-send-email 2.31.1 In-Reply-To: <cover.1682673542.git.houwenlong.hwl@antgroup.com> References: <cover.1682673542.git.houwenlong.hwl@antgroup.com> MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Spam-Status: No, score=-1.9 required=5.0 tests=BAYES_00,SPF_HELO_NONE, SPF_PASS,T_SCC_BODY_TEXT_LINE,UNPARSEABLE_RELAY autolearn=ham autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on lindbergh.monkeyblade.net Precedence: bulk List-ID: <linux-kernel.vger.kernel.org> X-Mailing-List: linux-kernel@vger.kernel.org X-getmail-retrieved-from-mailbox: =?utf-8?q?INBOX?= X-GMAIL-THRID: =?utf-8?q?1764414355987786227?= X-GMAIL-MSGID: =?utf-8?q?1764414355987786227?= |
Series |
x86/pie: Make kernel image's virtual address flexible
|
|
Commit Message
Hou Wenlong
April 28, 2023, 9:50 a.m. UTC
Since -fPIE option is not incompatible with -mcmode=kernel option, PIE
kernel would drop -mcmodel=kernel option. However, GCC would use %fs as
segment register for stack protector when -mcmodel=kernel option is
dropped. So only enable stack protector for PIE kernel if per-cpu stack
canary is supported.
Signed-off-by: Hou Wenlong <houwenlong.hwl@antgroup.com>
Cc: Thomas Garnier <thgarnie@chromium.org>
Cc: Lai Jiangshan <jiangshan.ljs@antgroup.com>
Cc: Kees Cook <keescook@chromium.org>
---
arch/x86/Kconfig | 1 +
1 file changed, 1 insertion(+)
diff --git a/arch/x86/Kconfig b/arch/x86/Kconfig index 55cce8cdf9bd..b26941ef50ee 100644 --- a/arch/x86/Kconfig +++ b/arch/x86/Kconfig @@ -403,6 +403,7 @@ config PGTABLE_LEVELS config CC_HAS_SANE_STACKPROTECTOR bool + default CC_HAS_CUSTOMIZED_STACKPROTECTOR if X86_PIE default $(success,$(srctree)/scripts/gcc-x86_64-has-stack-protector.sh $(CC) $(CLANG_FLAGS)) if 64BIT default $(success,$(srctree)/scripts/gcc-x86_32-has-stack-protector.sh $(CC) $(CLANG_FLAGS)) help