Received: by 2002:a05:6a11:4021:0:0:0:0 with SMTP id ky33csp798594pxb; Tue, 14 Sep 2021 08:59:14 -0700 (PDT) X-Google-Smtp-Source: ABdhPJz91+FytBKNyHsTqeKByytPB6hhR/9ptzRIlbLSHuqA0W5YBetrZ+4VA3tA9C09ZxhjI+ny X-Received: by 2002:a92:c8d2:: with SMTP id c18mr12412736ilq.121.1631635153906; Tue, 14 Sep 2021 08:59:13 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1631635153; cv=none; d=google.com; s=arc-20160816; b=oiwetDMTJMnvpaIpCADdCkI9szI4qR6jUMjoIpih6utSz4Ev1lAB1AdHemViesJPk+ iqC72jwWpHY1paPsAeTzW5VXXepb0j5qeJJxjPQ/oOl5hFnwTpLqLB84nLWLpLW+k5Fi LtC1OaqqgJTeECEWijLNkJHFtFjkfJA+oZRvTa8Q58xKZ9PTmDkRreSZah4M1zmuId0v ga5GIlejzg3hPaQevBS540lmpMADqjfyIqpgOzfbIhs4Wz+Lx6IdVSdAT5t1jBu9xLrd GPsuF3gTLsGUa1EeSM5oyttKdO+HvRLIBLrhyL0EHp8jhCEL57AfuuhUU1Zf9l3YsFt8 OZ0g== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:content-transfer-encoding:content-language :in-reply-to:mime-version:user-agent:date:message-id:from:references :cc:to:subject:dkim-signature; bh=wfAp0+gZByoZ4ACH5jho4TYxaw4sVTNfZ+kut7Sos24=; b=qeboMGlb8wJF+bqRH77QPwrOj1upo0uT5p+OQzHM7roHM4JHLWbnQOZcKUAyGC4Z6E dMMFWG+zWxOshVjvU/FSl2styI5yYlNmP09KJQ47TLOu5qNsF+SuP45T9O9A0XU6RX+8 I4OnFh5PXuayYgeGPh5lV2VbbCho7J4a04eu8N2CgyZ17UMULnFnYzt/LUAiYrZDfNEH M6j3ulNsEcXT2oRo/iZtzVu0DLh6KTeyYCoifPcV4wg44Q5PgEVX/dIAEP1Q5Bv6y54t S3o2jYjlRDCdnBfsmDF2Egl/dAW18QKoAqC9j1uHkmFZNnl4zv60qCk/5XolpPOWVlIs 5q1Q== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@kernel.org header.s=k20201202 header.b=FFSrDnn3; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=kernel.org Return-Path: Received: from vger.kernel.org (vger.kernel.org. [23.128.96.18]) by mx.google.com with ESMTP id s11si12215817jat.52.2021.09.14.08.59.02; Tue, 14 Sep 2021 08:59:13 -0700 (PDT) Received-SPF: pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) client-ip=23.128.96.18; Authentication-Results: mx.google.com; dkim=pass header.i=@kernel.org header.s=k20201202 header.b=FFSrDnn3; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=kernel.org Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S234854AbhINP7d (ORCPT + 99 others); Tue, 14 Sep 2021 11:59:33 -0400 Received: from mail.kernel.org ([198.145.29.99]:54220 "EHLO mail.kernel.org" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S235068AbhINP7c (ORCPT ); Tue, 14 Sep 2021 11:59:32 -0400 Received: by mail.kernel.org (Postfix) with ESMTPSA id DFE9C61157; Tue, 14 Sep 2021 15:58:14 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=k20201202; t=1631635095; bh=S40ApYu3+8/mXjIC0MgqMN4flPXp1mC5JHBKiqjo1mU=; h=Subject:To:Cc:References:From:Date:In-Reply-To:From; b=FFSrDnn337ksWTJSmQHorLozHC1AvfksczrybxHQxAff6uMmH6Dwf4OP/4Bczmmj4 7J+S47J4TnkJ+N3nEd+rwHyjQ5xvABF/+yKlmcr22rLMjuTlbFLrEqNqI+FG+S8f+G iVUagUnpq9N9upNv0kaKgFFGn/ESt//P2W+3X1r1NpDN5OdZEfdahn7DHznBGOj9RA vBTR4FQpIsV0z8KywH0Zbjb//tlfx/celRbb+L+GqyvInUcJhLZqZbNMLCcqm8cre2 W7Xkz/TT2OxoNlnYavIz+mNT/UnHi+IO/i6LbZrzMUmwi5EjejiEGCKB886Xb3+3uh j8QGaBQWEMRvQ== Subject: Re: [PATCH] hardening: Default to INIT_STACK_ALL_ZERO if CC_HAS_AUTO_VAR_INIT_ZERO To: Will Deacon , linux-kernel@vger.kernel.org Cc: linux-security-module@vger.kernel.org, Kees Cook , Nick Desaulniers , "Gustavo A . R . Silva" , Greg Kroah-Hartman References: <20210914102837.6172-1-will@kernel.org> From: Nathan Chancellor Message-ID: <01f572ab-bea2-f246-2f77-2f119056db84@kernel.org> Date: Tue, 14 Sep 2021 08:58:12 -0700 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:78.0) Gecko/20100101 Thunderbird/78.14.0 MIME-Version: 1.0 In-Reply-To: <20210914102837.6172-1-will@kernel.org> Content-Type: text/plain; charset=utf-8; format=flowed Content-Language: en-US Content-Transfer-Encoding: 7bit Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org On 9/14/2021 3:28 AM, Will Deacon wrote: > CC_HAS_AUTO_VAR_INIT_ZERO requires a supported set of compiler options > distinct from those needed by CC_HAS_AUTO_VAR_INIT_PATTERN, Fix up > the Kconfig dependency for INIT_STACK_ALL_ZERO to test for the former > instead of the latter, as these are the options passed by the top-level > Makefile. > > Cc: Kees Cook > Cc: Nathan Chancellor > Cc: Nick Desaulniers > Cc: Gustavo A. R. Silva > Cc: Greg Kroah-Hartman > Fixes: dcb7c0b9461c ("hardening: Clarify Kconfig text for auto-var-init") > Signed-off-by: Will Deacon Reviewed-by: Nathan Chancellor One comment below. > --- > > I just noticed this while reading the code and I suspect it doesn't really > matter in practice. > > security/Kconfig.hardening | 2 +- > 1 file changed, 1 insertion(+), 1 deletion(-) > > diff --git a/security/Kconfig.hardening b/security/Kconfig.hardening > index 90cbaff86e13..341e2fdcba94 100644 > --- a/security/Kconfig.hardening > +++ b/security/Kconfig.hardening > @@ -29,7 +29,7 @@ choice > prompt "Initialize kernel stack variables at function entry" > default GCC_PLUGIN_STRUCTLEAK_BYREF_ALL if COMPILE_TEST && GCC_PLUGINS > default INIT_STACK_ALL_PATTERN if COMPILE_TEST && CC_HAS_AUTO_VAR_INIT_PATTERN > - default INIT_STACK_ALL_ZERO if CC_HAS_AUTO_VAR_INIT_PATTERN > + default INIT_STACK_ALL_ZERO if CC_HAS_AUTO_VAR_INIT_ZERO > default INIT_STACK_NONE > help > This option enables initialization of stack variables at > While I think this change is correct in and of itself, CONFIG_INIT_STACK_ALL_ZERO is broken with GCC 12.x, as CONFIG_CC_HAS_AUTO_VAR_INIT_ZERO won't be set even though GCC now supports -ftrivial-auto-var-init=zero because GCC does not implement the -enable-trivial-auto-var-init-zero-knowing-it-will-be-removed-from-clang flag for obvious reasons ;) the cc-option call probably needs to be adjusted. Cheers, Nathan