Received: by 2002:a05:6358:3188:b0:123:57c1:9b43 with SMTP id q8csp1193133rwd; Thu, 1 Jun 2023 11:45:18 -0700 (PDT) X-Google-Smtp-Source: ACHHUZ5bvjAnjT/2mOtYS+ffxlBopNLOFw+lzYvOsxi+2xPWjqJtDrbyOlPj+1mxGWkTm+KfofIm X-Received: by 2002:a17:902:c40e:b0:1af:b681:5313 with SMTP id k14-20020a170902c40e00b001afb6815313mr263504plk.33.1685645118033; Thu, 01 Jun 2023 11:45:18 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1685645118; cv=none; d=google.com; s=arc-20160816; b=EbZjnIYTCA2gqOl3ll2NRcqjsq/TzNsLN3F1NkKjm2W2yuHdGnZ2+xNSrVXkQu8I7Y 0I3vvYZA8QmLMksnrnu86YOdYSnUgt3R0sQUt6radlsZjh7Q7JEcMQZaqdGoNOlkkocP lLAG6NsLthm9FLRA2FdgveOLPGRvJ2+7/GhHp2ByqUMkbBJa6rzIy9SpDGsPBUI2I6gG pE6LNaLbhL6bEf7/jsoPrH80tGMVL0D+Zt4Z+HMEOj7Jt6Qd6lrkRQa1qAIbB8y4Yw8C VHgJqKCO+tVg+SVX7Yzvj4VOSiXpiTZOkWgZDE7tGnqMsD9f0esWBP8iP1TIqbJWz482 jLPQ== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:content-transfer-encoding:mime-version :references:in-reply-to:message-id:date:subject:cc:to:from :dkim-signature; bh=Ctf1HD9q2IXAlWGZe0D1mEr62PaUnWG7sqP8wEigDAM=; b=wWhrehTc6IQ/3di7+8z0xzRLbeMYbI1Do20Tap8H2b8lMmQdtmc9TDWP+pSLMPO/Is +7i5pfSHvRMQp6yvXh5VFU6RCLB2gsDk2oSRzxvQ95dt5o8Zmuk6nc1BwLf7CEobZFZ5 1kfe/cnM4SHcZ3kLzl0+xb6hYrjNuJQLDPdt9bj6pEuHsSSiOfAhRdUKVKHc5ZAfZL46 q3dXE+3ohTBgEQw2FMVpEu/QSqpRy0hbagSL70Dx1eFIQiHaNJMyyuy0OMzRbReFgFft rg4k1Uy6j0T2CU6l6xsTGoENUwgU4KJK98NiUy9NV9eDRu8PQSvQvlQdS2Vl7cGLP+R9 NDvQ== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@chromium.org header.s=google header.b=oQgl78QY; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=chromium.org Return-Path: Received: from out1.vger.email (out1.vger.email. [2620:137:e000::1:20]) by mx.google.com with ESMTP id f1-20020a17090274c100b001a92a507187si2986966plt.80.2023.06.01.11.45.03; Thu, 01 Jun 2023 11:45:18 -0700 (PDT) Received-SPF: pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) client-ip=2620:137:e000::1:20; Authentication-Results: mx.google.com; dkim=pass header.i=@chromium.org header.s=google header.b=oQgl78QY; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=chromium.org Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S232332AbjFAS1p (ORCPT + 99 others); Thu, 1 Jun 2023 14:27:45 -0400 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:60214 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S232888AbjFAS12 (ORCPT ); Thu, 1 Jun 2023 14:27:28 -0400 Received: from mail-pg1-x52f.google.com (mail-pg1-x52f.google.com [IPv6:2607:f8b0:4864:20::52f]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id 80998171E for ; Thu, 1 Jun 2023 11:27:07 -0700 (PDT) Received: by mail-pg1-x52f.google.com with SMTP id 41be03b00d2f7-53fb64b3368so658364a12.0 for ; Thu, 01 Jun 2023 11:27:07 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=chromium.org; s=google; t=1685644025; x=1688236025; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to; bh=Ctf1HD9q2IXAlWGZe0D1mEr62PaUnWG7sqP8wEigDAM=; b=oQgl78QYG5Oj68tYfu28Af11McToK99Xc7cFV/WH2ogHroD1GdfvX22wD/gSmA8aMP xqCFWhpZwhyN0YrqAvcKjFZdTkBLYFqwpi+GrPRnAe1zzZL0DZpvRCHlUNlpG4wyJSzO KPRVn/di/BWJKYn3/rifCxelC2KwvxVw4Wrx8= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20221208; t=1685644025; x=1688236025; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to; bh=Ctf1HD9q2IXAlWGZe0D1mEr62PaUnWG7sqP8wEigDAM=; b=fzHRNm+4yKP2DirP9tJfpA5FEQbx2ECxs3UoMdLRvJY6a3Uk8i6ipmM1Cfm5morXfU ri3KoPSu1RpPRMiZ+4OYYRRPJ51h/p+bEZooYawrOSvTi5ikuN5WPcjwd/M17HoTkxFk Oy0f105VYRswWyeD7Sy0lIK5WQfmPjCTo2vRaE/8W2MJ/WiKA/Yt01QMpwaqk7AC0mtB 4VRyw6AI5U2bnZ8WN8d9QMHRYGw8b7T9fQA3P17c6lBtjiP7btMs1l9SF9hA83DiYl6q ykxx4GK9Wm5DmQUGuDWHgcxOXX+G+j37K2FBTvurh7oQjbbYDVF52mkkQ5V0T/xwH9UA gfwQ== X-Gm-Message-State: AC+VfDzYmlGc0VzrjN5K4O7WaOwf4nq6CHMTqbIqulDvaMc0le/pmzTu wfDi98qLj55I+1lbeoDkeZJfRA== X-Received: by 2002:a17:902:a710:b0:1b1:af8e:d31d with SMTP id w16-20020a170902a71000b001b1af8ed31dmr151235plq.40.1685644025042; Thu, 01 Jun 2023 11:27:05 -0700 (PDT) Received: from www.outflux.net (198-0-35-241-static.hfc.comcastbusiness.net. [198.0.35.241]) by smtp.gmail.com with ESMTPSA id p5-20020a170902e74500b001a505f04a06sm3797670plf.190.2023.06.01.11.27.04 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 01 Jun 2023 11:27:04 -0700 (PDT) From: Kees Cook To: keescook@chromium.org, paul.walmsley@sifive.com Cc: ndesaulniers@google.com, linux-kernel@vger.kernel.org, gustavoars@kernel.org, linux@leemhuis.info, heiko.stuebner@vrull.eu, linux-hardening@vger.kernel.org, aou@eecs.berkeley.edu, linux-riscv@lists.infradead.org, joanbrugueram@gmail.com, masahiroy@kernel.org, conor.dooley@microchip.com, ajones@ventanamicro.com, hi@alyssa.is, palmer@dabbelt.com Subject: Re: [PATCH v2] riscv/purgatory: Do not use fortified string functions Date: Thu, 1 Jun 2023 11:27:03 -0700 Message-Id: <168564402237.2891605.1600418987887898293.b4-ty@chromium.org> X-Mailer: git-send-email 2.34.1 In-Reply-To: <20230601160025.gonna.868-kees@kernel.org> References: <20230601160025.gonna.868-kees@kernel.org> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: 8bit X-Spam-Status: No, score=-2.3 required=5.0 tests=BAYES_00,DKIMWL_WL_HIGH, DKIM_SIGNED,DKIM_VALID,DKIM_VALID_AU,DKIM_VALID_EF,RCVD_IN_DNSWL_NONE, SPF_HELO_NONE,SPF_PASS,T_SCC_BODY_TEXT_LINE autolearn=unavailable autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on lindbergh.monkeyblade.net Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org On Thu, 1 Jun 2023 09:00:28 -0700, Kees Cook wrote: > With the addition of -fstrict-flex-arrays=3, struct sha256_state's > trailing array is no longer ignored by CONFIG_FORTIFY_SOURCE: > > struct sha256_state { > u32 state[SHA256_DIGEST_SIZE / 4]; > u64 count; > u8 buf[SHA256_BLOCK_SIZE]; > }; > > [...] Applied to for-next/hardening, thanks! [1/1] riscv/purgatory: Do not use fortified string functions https://git.kernel.org/kees/c/ca2ca08f479d -- Kees Cook