Received: by 2002:a05:6a10:1d13:0:0:0:0 with SMTP id pp19csp3866419pxb; Mon, 30 Aug 2021 12:30:07 -0700 (PDT) X-Google-Smtp-Source: ABdhPJxCDhkb/vPHemATawzMboKIegPv3CI/JovkmLQCjoBGY51WmiWbCmaWoRLQ8iASJ8xQFU7A X-Received: by 2002:a5d:8f91:: with SMTP id l17mr19811200iol.121.1630351807018; Mon, 30 Aug 2021 12:30:07 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1630351807; cv=none; d=google.com; s=arc-20160816; b=cYBlcvu6wUljS2JNtXNyGNNbYtJZCS+7l9hHQYmuHbzm7+N1V0jF3/MtxC2ffHXmhx dyLFrD3vyR7xvCo3DlDixbaROjebm5Snhabvs1PFzuKy7X2/CycFL5M03nhD2LkYMJ8u lD7+m0f1BOxz8JDsSX6DIxsMtnmIMhiM1GX3LeJwN0FmdBKlwNvjwm4Iw0HNsxMgBvo0 +T+4zXaYNBQ11muV3aUJBw+ZtBQs24h1slgSKfu8daG5/DNqzUO3Smd9SPRJQEjHf7mG tXiJs4pfdlssdATKjQZn5OjnflkzfY9IveBXdxDmS+epsN2uF2Zpj8WyYTPYUqwoCmng 0AoQ== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:content-transfer-encoding:mime-version :references:in-reply-to:message-id:date:subject:cc:to:from; bh=C3JTLuhaEmcNaKb0cAGJJ6fB4rAsbd0jbg+vNB6vky4=; b=pRLWkuYfIEAnsqjEe25jeLgFHHP/Ir+6qhHUJ6Yb/mjepiClCiiPLN7qn4oQn/jmjF pewbpOjiDjezju3X8qYtsU+HI2Fn+6TaJyBO+eh71+gQquMRamkCKlj+SmCqhWQpuPO/ FYZ7O5IAlB8BfEekWro7NfuoYRq4q46gfWHYgTP4AH2NOPcO1MODXMH55UuK0AG4fDD3 QnAGSCbAhkHVVjwmNNgaQHAPVXlRq6BCWJGLXp8Hvant8RuQ+lrK6eCR9tsPsIC56fJt mo3VpBuwCyN2wClvRJm5QY0BfDdwfBemEdKxPO86QtH8sH0m7gG8daPinGhf8wJ/BF/I d7zQ== ARC-Authentication-Results: i=1; mx.google.com; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=intel.com Return-Path: Received: from vger.kernel.org (vger.kernel.org. [23.128.96.18]) by mx.google.com with ESMTP id x13si14567699jas.84.2021.08.30.12.29.55; Mon, 30 Aug 2021 12:30:07 -0700 (PDT) Received-SPF: pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) client-ip=23.128.96.18; Authentication-Results: mx.google.com; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=intel.com Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S238633AbhH3SYj (ORCPT + 99 others); Mon, 30 Aug 2021 14:24:39 -0400 Received: from mga06.intel.com ([134.134.136.31]:24500 "EHLO mga06.intel.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S238588AbhH3SYH (ORCPT ); Mon, 30 Aug 2021 14:24:07 -0400 X-IronPort-AV: E=McAfee;i="6200,9189,10092"; a="279340869" X-IronPort-AV: E=Sophos;i="5.84,364,1620716400"; d="scan'208";a="279340869" Received: from fmsmga002.fm.intel.com ([10.253.24.26]) by orsmga104.jf.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 30 Aug 2021 11:23:11 -0700 X-IronPort-AV: E=Sophos;i="5.84,364,1620716400"; d="scan'208";a="540650969" Received: from yyu32-desk.sc.intel.com ([143.183.136.146]) by fmsmga002-auth.fm.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 30 Aug 2021 11:23:10 -0700 From: Yu-cheng Yu To: x86@kernel.org, "H. Peter Anvin" , Thomas Gleixner , Ingo Molnar , linux-kernel@vger.kernel.org, linux-doc@vger.kernel.org, linux-mm@kvack.org, linux-arch@vger.kernel.org, linux-api@vger.kernel.org, Arnd Bergmann , Andy Lutomirski , Balbir Singh , Borislav Petkov , Cyrill Gorcunov , Dave Hansen , Eugene Syromiatnikov , Florian Weimer , "H.J. Lu" , Jann Horn , Jonathan Corbet , Kees Cook , Mike Kravetz , Nadav Amit , Oleg Nesterov , Pavel Machek , Peter Zijlstra , Randy Dunlap , "Ravi V. Shankar" , Dave Martin , Weijiang Yang , Pengfei Xu , Haitao Huang , Rick P Edgecombe Cc: Yu-cheng Yu Subject: [PATCH v30 09/10] x86/vdso/32: Add ENDBR to __kernel_vsyscall entry point Date: Mon, 30 Aug 2021 11:22:20 -0700 Message-Id: <20210830182221.3535-10-yu-cheng.yu@intel.com> X-Mailer: git-send-email 2.21.0 In-Reply-To: <20210830182221.3535-1-yu-cheng.yu@intel.com> References: <20210830182221.3535-1-yu-cheng.yu@intel.com> MIME-Version: 1.0 Content-Transfer-Encoding: 8bit Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org From: "H.J. Lu" ENDBR is a special new instruction for the Indirect Branch Tracking (IBT) component of CET. IBT prevents attacks by ensuring that (most) indirect branches and function calls may only land at ENDBR instructions. Branches that don't follow the rules will result in control flow (#CF) exceptions. ENDBR is a noop when IBT is unsupported or disabled. Most ENDBR instructions are inserted automatically by the compiler, but branch targets written in assembly must have ENDBR added manually. Add that to __kernel_vsyscall entry point. Signed-off-by: H.J. Lu Signed-off-by: Yu-cheng Yu Reviewed-by: Kees Cook Cc: Andy Lutomirski --- arch/x86/entry/vdso/vdso32/system_call.S | 2 ++ 1 file changed, 2 insertions(+) diff --git a/arch/x86/entry/vdso/vdso32/system_call.S b/arch/x86/entry/vdso/vdso32/system_call.S index 6ddd7a937b3e..d321c2ded33a 100644 --- a/arch/x86/entry/vdso/vdso32/system_call.S +++ b/arch/x86/entry/vdso/vdso32/system_call.S @@ -7,6 +7,7 @@ #include #include #include +#include .text .globl __kernel_vsyscall @@ -14,6 +15,7 @@ ALIGN __kernel_vsyscall: CFI_STARTPROC + ENDBR32 /* * Reshuffle regs so that all of any of the entry instructions * will preserve enough state. -- 2.21.0