Received: by 2002:a05:6359:c8b:b0:c7:702f:21d4 with SMTP id go11csp3159297rwb; Mon, 3 Oct 2022 10:29:29 -0700 (PDT) X-Google-Smtp-Source: AMsMyM4111rjkOE4T9DmjuNvTtrxVwJguk8yQtQS8xIZR0iRjfwiaVZavHMeH9/mBN3qptsms3tQ X-Received: by 2002:a17:902:7408:b0:17b:546a:17 with SMTP id g8-20020a170902740800b0017b546a0017mr21733543pll.134.1664818169586; Mon, 03 Oct 2022 10:29:29 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1664818169; cv=none; d=google.com; s=arc-20160816; b=hHLvKQ5NfRmYBTSVAiirzy8zma82wWkZbu6GbOqtB3IDHmxpimgkBDOEX5ewkwCLjL jTCq3lp824PTu8dueqZFPfmOEiq0N2Iq8ToD7TTNDqfD9yTsQAJOxPQRbWYP3RV3mYlm 2NGSFB0JDgYR5qOKx6CmKxtYKSSMlT73fodD1WY7vYGTrkvrWISiPna3wGO9lSyDBhY9 XVC/EhMdmA7t69T9T4XRjNXvw91LYcXeGiVuRDjrgBgN//onFkz4yrwEqCTdwzgdti3x waACji5/MrvON+3a5IfAMzA2kkpnjNbxm3zKxHGsvssy0EqKnT64jXScbtHFYY7/rrMN DEKg== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:in-reply-to:content-disposition:mime-version :references:message-id:subject:cc:to:from:date:dkim-signature; bh=DUSAgm1tGARrhgAa+YXJyBkN7A5KbivkL+1rvMQ+tQc=; b=of2gKq2JIQt/R7aNQbRvd85oEm7TuA3vEes6jsWiWuKvt6NKzaYRqeL8bsJAYXzCih QjdEqEoHGo+S/fsBdxm1Aky0hNDmKzmgUg+W7c4QBWi5SVIr7O2Kk37c4KInHPXaobBt SlqY8FdE4Nvmz1q+Qz/DSLHcBAn0u53R2umgGw4qfbwepnl0w1/P7T9T5R5duNhcZU96 /oGApFTtChwnqMoqmYa1ZihKqDjP4ZseFAFyn7ZvWnCUKEhxuKZwt+ToJtIJjNstkZAt VGkUx4ib4+N7L+Zz8DVJqCtyJIk2+Yd2dV6ThaMb51St4lYAIy9Z3Zkjfb11Y6HOpDLX JeEw== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@chromium.org header.s=google header.b=Of4O9so7; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=chromium.org Return-Path: Received: from out1.vger.email (out1.vger.email. [2620:137:e000::1:20]) by mx.google.com with ESMTP id jn15-20020a170903050f00b0017486813f81si10678025plb.528.2022.10.03.10.29.17; Mon, 03 Oct 2022 10:29:29 -0700 (PDT) Received-SPF: pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) client-ip=2620:137:e000::1:20; Authentication-Results: mx.google.com; dkim=pass header.i=@chromium.org header.s=google header.b=Of4O9so7; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=chromium.org Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S229660AbiJCRSP (ORCPT + 99 others); Mon, 3 Oct 2022 13:18:15 -0400 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:49080 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S229496AbiJCRSN (ORCPT ); Mon, 3 Oct 2022 13:18:13 -0400 Received: from mail-pj1-x102b.google.com (mail-pj1-x102b.google.com [IPv6:2607:f8b0:4864:20::102b]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id 396615F7D for ; Mon, 3 Oct 2022 10:18:12 -0700 (PDT) Received: by mail-pj1-x102b.google.com with SMTP id o59-20020a17090a0a4100b0020a6d5803dfso5732175pjo.4 for ; Mon, 03 Oct 2022 10:18:12 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=chromium.org; s=google; h=in-reply-to:content-disposition:mime-version:references:message-id :subject:cc:to:from:date:from:to:cc:subject:date; bh=DUSAgm1tGARrhgAa+YXJyBkN7A5KbivkL+1rvMQ+tQc=; b=Of4O9so7/tSkTzAhtAmZ+McsJYDlbXtDFPfPIaWqeHQqx0dNBvuOCri5UaoKbaXhOK y6gXjMlY2as/UO/bCo3kBsjsJP7fvzviBg59V2TvtA70FIIFvHZxrHXgb8EaKe3XjuwU Wg6HcGRQExXlzVGqQhNLlqWLYTLYRjlajnCQU= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20210112; h=in-reply-to:content-disposition:mime-version:references:message-id :subject:cc:to:from:date:x-gm-message-state:from:to:cc:subject:date; bh=DUSAgm1tGARrhgAa+YXJyBkN7A5KbivkL+1rvMQ+tQc=; b=C5p2npk+v9/kCJXxHtVcRCGYseBzDQnF9lZtUjW8Pp6xiAns3FZWASZkaQJ6d4iFNU DHcE6xNjaNoY/cLxNRouI8J9594g0v+3KnBNyH2kZWmjV52KXdWvwcql2Nh4oDRKm3xn CuBYPTzzqchd8ecbbFFjfhCfvuDjvetQTIypV9YX9OaXgZ3DYek4fbM1ReE2WxaoTN4I wVQpZlaz+9dYFZySh6/PyXGboU6uVJcjxLM0W6HFHD4YVjqpJWJoCrNc8UL2+AZFwNcJ Ugxv1lc5toVuU7MTyO/H4oRpyoKcpK6tnrRxkP+kmKyoI6sm5d4/NT7i/W7vJZ1jTcsv 72UA== X-Gm-Message-State: ACrzQf32Ff6++wqSlY27LQhBC7pFsGSW+xCqfEU2bB3/l5DtYlKJhmoB q7XNC11sjuxfM9HFV2N2k6ts0g== X-Received: by 2002:a17:90b:1648:b0:203:c8d3:99b0 with SMTP id il8-20020a17090b164800b00203c8d399b0mr13356266pjb.54.1664817491587; Mon, 03 Oct 2022 10:18:11 -0700 (PDT) Received: from www.outflux.net (smtp.outflux.net. [198.145.64.163]) by smtp.gmail.com with ESMTPSA id o17-20020a639a11000000b0043ba3d6ea3fsm7069554pge.54.2022.10.03.10.18.10 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 03 Oct 2022 10:18:10 -0700 (PDT) Date: Mon, 3 Oct 2022 10:18:09 -0700 From: Kees Cook To: Rick Edgecombe Cc: x86@kernel.org, "H . Peter Anvin" , Thomas Gleixner , Ingo Molnar , linux-kernel@vger.kernel.org, linux-doc@vger.kernel.org, linux-mm@kvack.org, linux-arch@vger.kernel.org, linux-api@vger.kernel.org, Arnd Bergmann , Andy Lutomirski , Balbir Singh , Borislav Petkov , Cyrill Gorcunov , Dave Hansen , Eugene Syromiatnikov , Florian Weimer , "H . J . Lu" , Jann Horn , Jonathan Corbet , Mike Kravetz , Nadav Amit , Oleg Nesterov , Pavel Machek , Peter Zijlstra , Randy Dunlap , "Ravi V . Shankar" , Weijiang Yang , "Kirill A . Shutemov" , joao.moreira@intel.com, John Allen , kcc@google.com, eranian@google.com, rppt@kernel.org, jamorris@linux.microsoft.com, dethoma@microsoft.com, Yu-cheng Yu Subject: Re: [PATCH v2 01/39] Documentation/x86: Add CET description Message-ID: <202210031006.02C79ED58@keescook> References: <20220929222936.14584-1-rick.p.edgecombe@intel.com> <20220929222936.14584-2-rick.p.edgecombe@intel.com> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <20220929222936.14584-2-rick.p.edgecombe@intel.com> X-Spam-Status: No, score=-2.1 required=5.0 tests=BAYES_00,DKIMWL_WL_HIGH, DKIM_SIGNED,DKIM_VALID,DKIM_VALID_AU,DKIM_VALID_EF,RCVD_IN_DNSWL_NONE, SPF_HELO_NONE,SPF_PASS autolearn=ham autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on lindbergh.monkeyblade.net Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org On Thu, Sep 29, 2022 at 03:28:58PM -0700, Rick Edgecombe wrote: > [...] > +Overview > +======== > + > +Control-flow Enforcement Technology (CET) is term referring to several > +related x86 processor features that provides protection against control > +flow hijacking attacks. The HW feature itself can be set up to protect > +both applications and the kernel. Only user-mode protection is implemented > +in the 64-bit kernel. This likely needs rewording, since it's not strictly true any more: IBT is supported in kernel-mode now (CONFIG_X86_IBT). > +CET introduces Shadow Stack and Indirect Branch Tracking. Shadow stack is > +a secondary stack allocated from memory and cannot be directly modified by > +applications. When executing a CALL instruction, the processor pushes the > +return address to both the normal stack and the shadow stack. Upon > +function return, the processor pops the shadow stack copy and compares it > +to the normal stack copy. If the two differ, the processor raises a > +control-protection fault. Indirect branch tracking verifies indirect > +CALL/JMP targets are intended as marked by the compiler with 'ENDBR' > +opcodes. Not all CPU's have both Shadow Stack and Indirect Branch Tracking > +and only Shadow Stack is currently supported in the kernel. > + > +The Kconfig options is X86_SHADOW_STACK, and it can be disabled with > +the kernel parameter clearcpuid, like this: "clearcpuid=shstk". > + > +To build a CET-enabled kernel, Binutils v2.31 and GCC v8.1 or LLVM v10.0.1 > +or later are required. To build a CET-enabled application, GLIBC v2.28 or > +later is also required. > + > +At run time, /proc/cpuinfo shows CET features if the processor supports > +CET. Maybe call them out by name: shstk ibt > +CET arch_prctl()'s > +================== > + > +Elf features should be enabled by the loader using the below arch_prctl's. > + > +arch_prctl(ARCH_CET_ENABLE, unsigned int feature) > + Enable a single feature specified in 'feature'. Can only operate on > + one feature at a time. Does this mean only 1 bit out of the 32 may be specified? > + > +arch_prctl(ARCH_CET_DISABLE, unsigned int feature) > + Disable features specified in 'feature'. Can only operate on > + one feature at a time. > + > +arch_prctl(ARCH_CET_LOCK, unsigned int features) > + Lock in features at their current enabled or disabled status. How is the "features" argument processed here? > [...] > +Proc status > +=========== > +To check if an application is actually running with shadow stack, the > +user can read the /proc/$PID/arch_status. It will report "wrss" or > +"shstk" depending on what is enabled. TIL about "arch_status". :) Why is this a separate file? "status" is already has unique field names. > +Fork > +---- > + > +The shadow stack's vma has VM_SHADOW_STACK flag set; its PTEs are required > +to be read-only and dirty. When a shadow stack PTE is not RO and dirty, a > +shadow access triggers a page fault with the shadow stack access bit set > +in the page fault error code. > + > +When a task forks a child, its shadow stack PTEs are copied and both the > +parent's and the child's shadow stack PTEs are cleared of the dirty bit. > +Upon the next shadow stack access, the resulting shadow stack page fault > +is handled by page copy/re-use. > + > +When a pthread child is created, the kernel allocates a new shadow stack > +for the new thread. Perhaps speak to the ASLR characteristics of the shstk here? Also, it seems if there is a "Fork" section, there should be an "Exec" section? I suspect it would be short: shstk is disabled when execve() is called and must be re-enabled from userspace, yes? -Kees -- Kees Cook