Received: by 2002:a05:6a10:9848:0:0:0:0 with SMTP id x8csp733790pxf; Thu, 8 Apr 2021 11:31:44 -0700 (PDT) X-Google-Smtp-Source: ABdhPJz+hGmG1AxtjkfbLz1FA/n8YHKRUsIjb7SYofh4Ha3VZHh8OcrzwFW9bAMox3oK4qeS3NsQ X-Received: by 2002:a17:90b:fc5:: with SMTP id gd5mr9567505pjb.108.1617906704118; Thu, 08 Apr 2021 11:31:44 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1617906704; cv=none; d=google.com; s=arc-20160816; b=MaQYXNJN4k9vjx2b3pNnBX3hgDUsvlk1CMyDlSXubbs75qT/PErZ3qMg8V1MSiAtnm qGtyrYixSkjZhtXCkJIyUCbRn/1lLDcPuJ/UYejsUXuRODUHjojUst998s9Elx29H+W8 iYMWlA7DgvvgjXpxVaRLrV7Tf19j0/7Uel81Jc+jOp5LzFdrdyKrZmTcvx13n13qCXdz nADxVyQYjCuTtHEbkXMEW4ztxyk+roJdrUdN4LSfw7Pb/TBFvZG86YxEpw57qgOW/RZv XxZfZ+pdvdrsr1d4Y9CexrxWT9PcyKQ2KE44dwsOVLNq5yuggIoK8r1wE6+ihHnOS8FG sMyQ== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:cc:to:from:subject:references:mime-version :message-id:in-reply-to:date:dkim-signature; bh=/RFtNNq4R+HQlfABCrnOp0vGXtCZ+PdK4tYVAs3Xgq4=; b=pqKcHz4mmVMLkzaHJUQhHG5y9fNkAuSjgKLeWquJP6A7fj1KaA38DlIAAGyBuOX0P2 h1WABfzeYrpay1m+Q6QL4r2aiLpwhE6TXQmQvfTEyIoqI3VMzb97XLPy5mtDn6K76aTe A302wJm1byYaW4P4RbV/fGTAb2uMCRLLF3KhXQaVFEIRMs3oogJmtaQAl0UOR4iyarw5 jcXyiSG5FjqrpBIkVshIZE5Wu2Wf6ltwiNJjy51TwJll+K8VkWe+aU2lMcjQnWlaCy6O AkFGvPkeGw6yeD2SB4begci6go/l8uXadcHXZI+CeQE4vldpDAjBhsO7JXM/LHLnmVaz 5QWQ== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@google.com header.s=20161025 header.b=mRyvx1Zy; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=google.com Return-Path: Received: from vger.kernel.org (vger.kernel.org. [23.128.96.18]) by mx.google.com with ESMTP id pc5si178627pjb.67.2021.04.08.11.31.31; Thu, 08 Apr 2021 11:31:44 -0700 (PDT) Received-SPF: pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) client-ip=23.128.96.18; Authentication-Results: mx.google.com; dkim=pass header.i=@google.com header.s=20161025 header.b=mRyvx1Zy; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=google.com Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S232947AbhDHSbL (ORCPT + 99 others); Thu, 8 Apr 2021 14:31:11 -0400 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:48674 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S232887AbhDHSaw (ORCPT ); Thu, 8 Apr 2021 14:30:52 -0400 Received: from mail-qv1-xf4a.google.com (mail-qv1-xf4a.google.com [IPv6:2607:f8b0:4864:20::f4a]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id 2DC9DC0610D0 for ; Thu, 8 Apr 2021 11:29:19 -0700 (PDT) Received: by mail-qv1-xf4a.google.com with SMTP id cf5so1669934qvb.20 for ; Thu, 08 Apr 2021 11:29:19 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20161025; h=date:in-reply-to:message-id:mime-version:references:subject:from:to :cc; bh=/RFtNNq4R+HQlfABCrnOp0vGXtCZ+PdK4tYVAs3Xgq4=; b=mRyvx1ZyCWRRYs/gtfFKoK8RBt3UI3Cbe8UFU+DjhbwvArNTuLgIFS5sSHA8GrypJO h1Ut4lnsHPkWI+6YGudQiUwKpMvE3rw3IvXbMyabZSfdvOVUtUOuttrRv/lU1I0YKtr+ 2KHbgG7VEZaD7k90Q2eC5FYoEypvPzIMBzhRBoMcW7o/u3O1niG3LYNNqbDjD1qMFVl5 E0r5iFj/NMKIiwFuIz+tbBcn4ksbC5mZayHEJv3FtIIufUIqISS2/csUEuPKce6VPJ6v 9VVELn3ltJVZx2tcvPVhDFYkynJ6q1lEl6xzivgPR/q2vDBkBfPrFKC+an1ZU7XkvHYL wK7w== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:date:in-reply-to:message-id:mime-version :references:subject:from:to:cc; bh=/RFtNNq4R+HQlfABCrnOp0vGXtCZ+PdK4tYVAs3Xgq4=; b=L5/FDfohywz9J4GEYSKo0RNmuJBCKda9gALFg+2oj8sLF7ATQdkFHVD5A5GofQVjpL GDJhfPNNCpZOj5aGD1kN0U4qBG4bduW5n0wvaZqmmrSMVnIA7YPcm8RHmdO4pBWmwFjn 752/gWL/bnZtbfm5ExFSbg5FWZ/YBuDpCgVyW7dIV4fHGxgQNbA1CkZmYBFvbSsHlf11 XiL/Vs64HtMKMhYHQb36tqQ3Vgb8o4gkznrDbXLprsITZ0KrNXSU5DxZGjYghIT0OYwe uOyRvrtzjyBC2Ub8C/cnwupX9d5QRBPxtCwb8UAiVHb54kPIZUFiWerOBWLAmdAsd+yg n8uA== X-Gm-Message-State: AOAM532dSFO2JJLUd/dJLz9XiCpGzqEA7wE9msnBdnBJCjKH/ZCHa568 6a7bxmVNk/LEYFuAbIL/LB1O+8j18RGZQP5P5ho= X-Received: from samitolvanen1.mtv.corp.google.com ([2620:15c:201:2:3560:8505:40a2:e021]) (user=samitolvanen job=sendgmr) by 2002:a0c:b410:: with SMTP id u16mr10174868qve.8.1617906558331; Thu, 08 Apr 2021 11:29:18 -0700 (PDT) Date: Thu, 8 Apr 2021 11:28:42 -0700 In-Reply-To: <20210408182843.1754385-1-samitolvanen@google.com> Message-Id: <20210408182843.1754385-18-samitolvanen@google.com> Mime-Version: 1.0 References: <20210408182843.1754385-1-samitolvanen@google.com> X-Mailer: git-send-email 2.31.1.295.g9ea45b61b8-goog Subject: [PATCH v6 17/18] KVM: arm64: Disable CFI for nVHE From: Sami Tolvanen To: Kees Cook Cc: Nathan Chancellor , Nick Desaulniers , Masahiro Yamada , Will Deacon , Jessica Yu , Arnd Bergmann , Tejun Heo , "Paul E. McKenney" , Christoph Hellwig , Peter Zijlstra , Sedat Dilek , Mark Rutland , Catalin Marinas , bpf@vger.kernel.org, linux-hardening@vger.kernel.org, linux-arch@vger.kernel.org, linux-arm-kernel@lists.infradead.org, linux-kbuild@vger.kernel.org, linux-pci@vger.kernel.org, linux-kernel@vger.kernel.org, clang-built-linux@googlegroups.com, Sami Tolvanen Content-Type: text/plain; charset="UTF-8" Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org Disable CFI for the nVHE code to avoid address space confusion. Signed-off-by: Sami Tolvanen Reviewed-by: Kees Cook Tested-by: Nathan Chancellor --- arch/arm64/kvm/hyp/nvhe/Makefile | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/arch/arm64/kvm/hyp/nvhe/Makefile b/arch/arm64/kvm/hyp/nvhe/Makefile index a6707df4f6c0..fb24a0f022ad 100644 --- a/arch/arm64/kvm/hyp/nvhe/Makefile +++ b/arch/arm64/kvm/hyp/nvhe/Makefile @@ -75,9 +75,9 @@ quiet_cmd_hyprel = HYPREL $@ quiet_cmd_hypcopy = HYPCOPY $@ cmd_hypcopy = $(OBJCOPY) --prefix-symbols=__kvm_nvhe_ $< $@ -# Remove ftrace and Shadow Call Stack CFLAGS. -# This is equivalent to the 'notrace' and '__noscs' annotations. -KBUILD_CFLAGS := $(filter-out $(CC_FLAGS_FTRACE) $(CC_FLAGS_SCS), $(KBUILD_CFLAGS)) +# Remove ftrace, Shadow Call Stack, and CFI CFLAGS. +# This is equivalent to the 'notrace', '__noscs', and '__nocfi' annotations. +KBUILD_CFLAGS := $(filter-out $(CC_FLAGS_FTRACE) $(CC_FLAGS_SCS) $(CC_FLAGS_CFI), $(KBUILD_CFLAGS)) # KVM nVHE code is run at a different exception code with a different map, so # compiler instrumentation that inserts callbacks or checks into the code may -- 2.31.1.295.g9ea45b61b8-goog