Received: by 2002:ac0:a5b6:0:0:0:0:0 with SMTP id m51-v6csp5175782imm; Tue, 12 Jun 2018 03:58:04 -0700 (PDT) X-Google-Smtp-Source: ADUXVKJn6s7Ebr2/ViLt25yZldFAyZYIaM+2huuKFpYPMAWhu2HtFdudl0GhyFZfRR5Hg4JsqLZG X-Received: by 2002:a63:9741:: with SMTP id d1-v6mr2685096pgo.403.1528801084655; Tue, 12 Jun 2018 03:58:04 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1528801084; cv=none; d=google.com; s=arc-20160816; b=nYSCg0JLrlItahBaljOVZlb4ifc11gcPe1b+J3dC+Lj5psLOTKbC0pwgYTM5cDruwZ VAGdoNWhCnaTTkGT1lkTb82BRsoTwMoND2Sc/yA3Fmdi/zn8YSlPdFvIuZ+o5W27MfZf 6tZQu9s2ZxcVoZpgHP3lJd9wtUBnDKT+tMdIbwmyO5wqDDzlm6RLoiw2yp8Bnt9O+YgY 1RF/n/W7qpkCecwTJJea8YgR+GRVrH7WU2VOgdeCR9asKVM3ZUg3BACjw2ufOxXYkzpK RqEsKPIdR5mid18BinUmtus+RH1BB2ylneOk7zzhTJpzWjHhXt50HqqPkUQj4Mx/MgNU 37Ww== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:sender:content-transfer-encoding :content-language:in-reply-to:mime-version:user-agent:date :message-id:from:references:to:subject:dkim-signature :arc-authentication-results; bh=bAQmhiG0d/rA242iDtDBG3ksrc7d9+O2dlTHEQiuaJs=; b=PsVvJCnNpf+gIx1uuyhafOhueM8JiISQhcyBY7+9kzFxx5A2k/HyVEO4hZy+44Bkn9 m2fjP1UxBzlZ7i5Yhy6Tg0WK3CvNhXc4rZ5Qxu0dqj5qQ3mC2NwT3O5KTNeIgSiTaW3j FI2X2xkMec5hfGwLQmLHeyi6gj/gQ4yspNKjcfyCAm3N03m4nSLxVNkpperim/by7fLM UlnesOExGD/DXzKB47HIHyET0k9T3TjRpxWHMC/+JVMWZB594fqblvePOEVstTnV+veq sW9oY+UJHBf1VMAD07akLEMUwcM9+UYxtLWsXklsQuyXvyKpSDaShbDN5dQaDaAZvkt8 +tAA== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@gmail.com header.s=20161025 header.b=jLfoVfov; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=QUARANTINE dis=NONE) header.from=gmail.com Return-Path: Received: from vger.kernel.org (vger.kernel.org. [209.132.180.67]) by mx.google.com with ESMTP id i186-v6si634053pfb.90.2018.06.12.03.57.50; Tue, 12 Jun 2018 03:58:04 -0700 (PDT) Received-SPF: pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) client-ip=209.132.180.67; Authentication-Results: mx.google.com; dkim=pass header.i=@gmail.com header.s=20161025 header.b=jLfoVfov; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=QUARANTINE dis=NONE) header.from=gmail.com Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S933533AbeFLK44 (ORCPT + 99 others); Tue, 12 Jun 2018 06:56:56 -0400 Received: from mail-pl0-f68.google.com ([209.85.160.68]:47051 "EHLO mail-pl0-f68.google.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S932556AbeFLK4x (ORCPT ); Tue, 12 Jun 2018 06:56:53 -0400 Received: by mail-pl0-f68.google.com with SMTP id 30-v6so14135378pld.13; Tue, 12 Jun 2018 03:56:53 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=subject:to:references:from:message-id:date:user-agent:mime-version :in-reply-to:content-language:content-transfer-encoding; bh=bAQmhiG0d/rA242iDtDBG3ksrc7d9+O2dlTHEQiuaJs=; b=jLfoVfovpk0mKFMtvaEYc2nNPgyC/i9xM9U7ZZlDJ7OwOSqv4YSc6ot8hsz5+ZOHjO iJw3j3BMDt1djoBmhM2HQYLW2Ef1DpXR1svrSlVhQM/eY1cfbuwFQR1FrvS4e6CXT+WH +xDr1Pj+PywQzX2HhXENoUnf4cMWV1oPcHWwEpFOk4+5sVmze3bAanL4SgSdvLcRvicB uCLk8CouCDycIql4jS4nMGjNR2BXbIE6KABbzyPYiYlO2V0G5pGHmvbNEUHyiBAaWM2r 21tFUs8ca9T1hOoRmyw+fItgSRnVgXrvJ1+9h4lpFTRZMa+1x6X2dOie8p4qxzxmNxm0 AuKg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:subject:to:references:from:message-id:date :user-agent:mime-version:in-reply-to:content-language :content-transfer-encoding; bh=bAQmhiG0d/rA242iDtDBG3ksrc7d9+O2dlTHEQiuaJs=; b=H//ESv8xoe/8SZgFGyF2zFDU9cUkCLPP1G0+NlnCM9++TwRqg1H4mkTB8Dlkn564yg VaMWIY1aBTToueQY3Tvn1jjR1uxiHRdoPrk07nkOB+XuwM7O4z2gVM4Hlce3hGMoFPja Jp7ByfzHMhIYkAigXsHdeKQ5kcvOkXpOUGa4uWTcWmqvw12hHd8UW3axfaCJD1pEd8ED DbnBajmQby2F95OxpkA4NnEnIAfi0fSPl9NzVjN6C4bu39Pl7yb65WBmktzABjxcx3W6 o9oAY+Pa+wp/r5vFuItQt2MdMMY4/TLHfgQDaFSn54/goQ5HmOnVKmaGH0eByUCjFt1P Zgew== X-Gm-Message-State: APt69E2pPN/Qgf5VXEkbIOPzrvEoQ3OXIGx5GR068sLW7AIPcTtWzLC9 vt3nDZ+zD1F9RnmJ9c1jjZU= X-Received: by 2002:a17:902:3081:: with SMTP id v1-v6mr3626488plb.266.1528801012619; Tue, 12 Jun 2018 03:56:52 -0700 (PDT) Received: from [192.168.1.11] (14-202-194-140.static.tpgi.com.au. [14.202.194.140]) by smtp.gmail.com with ESMTPSA id e68-v6sm3170674pfl.65.2018.06.12.03.56.43 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Tue, 12 Jun 2018 03:56:51 -0700 (PDT) Subject: Re: [PATCH 00/10] Control Flow Enforcement - Part (3) To: Yu-cheng Yu , linux-kernel@vger.kernel.org, linux-doc@vger.kernel.org, linux-mm@kvack.org, linux-arch@vger.kernel.org, x86@kernel.org, "H. Peter Anvin" , Thomas Gleixner , Ingo Molnar , "H.J. Lu" , Vedvyas Shanbhogue , "Ravi V. Shankar" , Dave Hansen , Andy Lutomirski , Jonathan Corbet , Oleg Nesterov , Arnd Bergmann , Mike Kravetz References: <20180607143807.3611-1-yu-cheng.yu@intel.com> From: Balbir Singh Message-ID: Date: Tue, 12 Jun 2018 20:56:30 +1000 User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:52.0) Gecko/20100101 Thunderbird/52.8.0 MIME-Version: 1.0 In-Reply-To: <20180607143807.3611-1-yu-cheng.yu@intel.com> Content-Type: text/plain; charset=utf-8 Content-Language: en-US Content-Transfer-Encoding: 7bit Sender: linux-kernel-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org On 08/06/18 00:37, Yu-cheng Yu wrote: > This series introduces CET - Shadow stack > > At the high level, shadow stack is: > > Allocated from a task's address space with vm_flags VM_SHSTK; > Its PTEs must be read-only and dirty; > Fixed sized, but the default size can be changed by sys admin. > > For a forked child, the shadow stack is duplicated when the next > shadow stack access takes place. > > For a pthread child, a new shadow stack is allocated. > > The signal handler uses the same shadow stack as the main program. > Even with sigaltstack()? Balbir Singh.