powerpc/64: add stack protector support
On PPC64, as register r13 points to the paca_struct at all time, this patch adds a copy of the canary there, which is copied at task_switch. That new canary is then used by using the following GCC options: -mstack-protector-guard=tls -mstack-protector-guard-reg=r13 -mstack-protector-guard-offset=offsetof(struct paca_struct, canary)) Signed-off-by: Christophe Leroy <christophe.leroy@c-s.fr> Signed-off-by: Michael Ellerman <mpe@ellerman.id.au>
This commit is contained in:
parent
c3ff2a5193
commit
06ec27aea9
@ -180,7 +180,7 @@ config PPC
|
|||||||
select HAVE_ARCH_SECCOMP_FILTER
|
select HAVE_ARCH_SECCOMP_FILTER
|
||||||
select HAVE_ARCH_TRACEHOOK
|
select HAVE_ARCH_TRACEHOOK
|
||||||
select HAVE_CBPF_JIT if !PPC64
|
select HAVE_CBPF_JIT if !PPC64
|
||||||
select HAVE_STACKPROTECTOR if $(cc-option,-mstack-protector-guard=tls) && PPC32
|
select HAVE_STACKPROTECTOR if $(cc-option,-mstack-protector-guard=tls)
|
||||||
select HAVE_CONTEXT_TRACKING if PPC64
|
select HAVE_CONTEXT_TRACKING if PPC64
|
||||||
select HAVE_DEBUG_KMEMLEAK
|
select HAVE_DEBUG_KMEMLEAK
|
||||||
select HAVE_DEBUG_STACKOVERFLOW
|
select HAVE_DEBUG_STACKOVERFLOW
|
||||||
|
@ -113,7 +113,11 @@ KBUILD_ARFLAGS += --target=elf$(BITS)-$(GNUTARGET)
|
|||||||
endif
|
endif
|
||||||
|
|
||||||
cflags-$(CONFIG_STACKPROTECTOR) += -mstack-protector-guard=tls
|
cflags-$(CONFIG_STACKPROTECTOR) += -mstack-protector-guard=tls
|
||||||
|
ifdef CONFIG_PPC64
|
||||||
|
cflags-$(CONFIG_STACKPROTECTOR) += -mstack-protector-guard-reg=r13
|
||||||
|
else
|
||||||
cflags-$(CONFIG_STACKPROTECTOR) += -mstack-protector-guard-reg=r2
|
cflags-$(CONFIG_STACKPROTECTOR) += -mstack-protector-guard-reg=r2
|
||||||
|
endif
|
||||||
|
|
||||||
LDFLAGS_vmlinux-y := -Bstatic
|
LDFLAGS_vmlinux-y := -Bstatic
|
||||||
LDFLAGS_vmlinux-$(CONFIG_RELOCATABLE) := -pie
|
LDFLAGS_vmlinux-$(CONFIG_RELOCATABLE) := -pie
|
||||||
@ -411,8 +415,12 @@ ifdef CONFIG_STACKPROTECTOR
|
|||||||
prepare: stack_protector_prepare
|
prepare: stack_protector_prepare
|
||||||
|
|
||||||
stack_protector_prepare: prepare0
|
stack_protector_prepare: prepare0
|
||||||
|
ifdef CONFIG_PPC64
|
||||||
|
$(eval KBUILD_CFLAGS += -mstack-protector-guard-offset=$(shell awk '{if ($$2 == "PACA_CANARY") print $$3;}' include/generated/asm-offsets.h))
|
||||||
|
else
|
||||||
$(eval KBUILD_CFLAGS += -mstack-protector-guard-offset=$(shell awk '{if ($$2 == "TASK_CANARY") print $$3;}' include/generated/asm-offsets.h))
|
$(eval KBUILD_CFLAGS += -mstack-protector-guard-offset=$(shell awk '{if ($$2 == "TASK_CANARY") print $$3;}' include/generated/asm-offsets.h))
|
||||||
endif
|
endif
|
||||||
|
endif
|
||||||
|
|
||||||
# Use the file '.tmp_gas_check' for binutils tests, as gas won't output
|
# Use the file '.tmp_gas_check' for binutils tests, as gas won't output
|
||||||
# to stdout and these checks are run even on install targets.
|
# to stdout and these checks are run even on install targets.
|
||||||
|
@ -256,6 +256,9 @@ struct paca_struct {
|
|||||||
struct slb_entry *mce_faulty_slbs;
|
struct slb_entry *mce_faulty_slbs;
|
||||||
u16 slb_save_cache_ptr;
|
u16 slb_save_cache_ptr;
|
||||||
#endif /* CONFIG_PPC_BOOK3S_64 */
|
#endif /* CONFIG_PPC_BOOK3S_64 */
|
||||||
|
#ifdef CONFIG_STACKPROTECTOR
|
||||||
|
unsigned long canary;
|
||||||
|
#endif
|
||||||
} ____cacheline_aligned;
|
} ____cacheline_aligned;
|
||||||
|
|
||||||
extern void copy_mm_to_paca(struct mm_struct *mm);
|
extern void copy_mm_to_paca(struct mm_struct *mm);
|
||||||
|
@ -11,6 +11,7 @@
|
|||||||
#include <linux/version.h>
|
#include <linux/version.h>
|
||||||
#include <asm/reg.h>
|
#include <asm/reg.h>
|
||||||
#include <asm/current.h>
|
#include <asm/current.h>
|
||||||
|
#include <asm/paca.h>
|
||||||
|
|
||||||
/*
|
/*
|
||||||
* Initialize the stackprotector canary value.
|
* Initialize the stackprotector canary value.
|
||||||
@ -29,6 +30,9 @@ static __always_inline void boot_init_stack_canary(void)
|
|||||||
canary &= CANARY_MASK;
|
canary &= CANARY_MASK;
|
||||||
|
|
||||||
current->stack_canary = canary;
|
current->stack_canary = canary;
|
||||||
|
#ifdef CONFIG_PPC64
|
||||||
|
get_paca()->canary = canary;
|
||||||
|
#endif
|
||||||
}
|
}
|
||||||
|
|
||||||
#endif /* _ASM_STACKPROTECTOR_H */
|
#endif /* _ASM_STACKPROTECTOR_H */
|
||||||
|
@ -81,6 +81,9 @@ int main(void)
|
|||||||
OFFSET(MM, task_struct, mm);
|
OFFSET(MM, task_struct, mm);
|
||||||
#ifdef CONFIG_STACKPROTECTOR
|
#ifdef CONFIG_STACKPROTECTOR
|
||||||
OFFSET(TASK_CANARY, task_struct, stack_canary);
|
OFFSET(TASK_CANARY, task_struct, stack_canary);
|
||||||
|
#ifdef CONFIG_PPC64
|
||||||
|
OFFSET(PACA_CANARY, paca_struct, canary);
|
||||||
|
#endif
|
||||||
#endif
|
#endif
|
||||||
OFFSET(MMCONTEXTID, mm_struct, context.id);
|
OFFSET(MMCONTEXTID, mm_struct, context.id);
|
||||||
#ifdef CONFIG_PPC64
|
#ifdef CONFIG_PPC64
|
||||||
|
@ -624,6 +624,10 @@ _GLOBAL(_switch)
|
|||||||
|
|
||||||
addi r6,r4,-THREAD /* Convert THREAD to 'current' */
|
addi r6,r4,-THREAD /* Convert THREAD to 'current' */
|
||||||
std r6,PACACURRENT(r13) /* Set new 'current' */
|
std r6,PACACURRENT(r13) /* Set new 'current' */
|
||||||
|
#if defined(CONFIG_STACKPROTECTOR)
|
||||||
|
ld r6, TASK_CANARY(r6)
|
||||||
|
std r6, PACA_CANARY(r13)
|
||||||
|
#endif
|
||||||
|
|
||||||
ld r8,KSP(r4) /* new stack pointer */
|
ld r8,KSP(r4) /* new stack pointer */
|
||||||
#ifdef CONFIG_PPC_BOOK3S_64
|
#ifdef CONFIG_PPC_BOOK3S_64
|
||||||
|
Loading…
Reference in New Issue
Block a user