From patchwork Sun Feb 25 20:08:10 2024 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Linus Walleij X-Patchwork-Id: 13571022 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from bombadil.infradead.org (bombadil.infradead.org [198.137.202.133]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.lore.kernel.org (Postfix) with ESMTPS id 33D28C54E41 for ; Sun, 25 Feb 2024 20:08:27 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.infradead.org; s=bombadil.20210309; h=Sender: Content-Transfer-Encoding:Content-Type:List-Subscribe:List-Help:List-Post: List-Archive:List-Unsubscribe:List-Id:Cc:To:In-Reply-To:References:Message-Id :MIME-Version:Subject:Date:From:Reply-To:Content-ID:Content-Description: Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID: List-Owner; bh=YcWCiYSXPZCTR02DodhnH7fKzLrIrk13DlFtZ6SnJV4=; b=V3YD0CmYxG8T+M Az499l72j400ehMZw+jqUgnanBN7InzXxmu9cPH9NSaoQDw4j6dNcyt88GQ9ftXwUf/TCCbfPS2FL 3328V+JaPik3tBpd5Qd08+m5pspfypjjehHXqww1BxYXrgYbt+vo36Tff//M+Ro52eyi8JqMHyIut 3WansqYz9/txTx+h5GfuIeUT+ffWojzLq9kbUrUSFlCDK4UW+A4GqHEy5yiuoDZQdPncbQ6CxS0vL huwOe/EyR8YJl/jw2iT/yDr9kQdHyvVhSgzzuQnYI7jCJWrx4woGOVCii763Lh3Ed33EunYY2Ghk1 F2xNEpXQZapqyKLclPuQ==; Received: from localhost ([::1] helo=bombadil.infradead.org) by bombadil.infradead.org with esmtp (Exim 4.97.1 #2 (Red Hat Linux)) id 1reKnK-0000000Fcl0-0nYQ; Sun, 25 Feb 2024 20:08:18 +0000 Received: from mail-ej1-x632.google.com ([2a00:1450:4864:20::632]) by bombadil.infradead.org with esmtps (Exim 4.97.1 #2 (Red Hat Linux)) id 1reKnH-0000000FcjD-30ZP for linux-arm-kernel@lists.infradead.org; Sun, 25 Feb 2024 20:08:17 +0000 Received: by mail-ej1-x632.google.com with SMTP id a640c23a62f3a-a3e72ec566aso298359066b.2 for ; Sun, 25 Feb 2024 12:08:14 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linaro.org; s=google; t=1708891693; x=1709496493; darn=lists.infradead.org; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :mime-version:subject:date:from:from:to:cc:subject:date:message-id :reply-to; bh=vaHsL9uZaLpUW/gtSno6U8/q3nfzw7ffg7lr4P7gXB0=; b=bHGg96QGGLzk9FjFjGK59ofijThQzxYEI0xB/5EH57d2NuoIo2ZBvOeUsamXxs6qcu /9oxoo5eh1QcfY9x8xSwHtXKCl/Z7Re4Bc3xryjuase1by2X3iqsMKIjKAqhCYo2yX33 CV9pwdpRHTz77DIbEGe8vf5RkVmn44yUL8Q+wwFgIl2ImcgapXCnlyGzz+OisN52MRIz I6uKN0C78OcVi3e6FIoy7SfL1eC89IcGhRfCFc0+zBh2sYoiYgQ93PvMFKbUN0iJ3Usb iWky+fKSqhmrvk/ZtzTfJy8/IqKvBhVUdpemynosq785hMP1wb9GctJYfiF0/fKg49FR HjGw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1708891693; x=1709496493; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :mime-version:subject:date:from:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to; bh=vaHsL9uZaLpUW/gtSno6U8/q3nfzw7ffg7lr4P7gXB0=; b=MllejWcd1J57VUvLBp+yDHlzJA7SgFkcJ3Zt+2n5+XBjlvY3iuWaYkfILXGY9c8b2+ C7nel5/KSQuhOY6+LrM2+y5X32w48E9Qs7akE+Z6cmErdM5AWS7LJV23aDNyy6xcXXPN 2l0GSP63G7AQGrAhisjFpqviBKyhkmIkgTgJScewY49m4exQYwRTty4+M/wYN5LWC4wO 0BtFtzsYwMssg7ztIAaEkbemrRm+a2ORipuD/GRgj3R1vlOVY3Dbv9MGa5ECHAVHw1QT lF0VsXYgAMkjWLW4yHsTCO9QDVy4DehmqvEnwVxj1Nvo1pXjSUjS7dfbdAvOnXkhR1AA e2oQ== X-Gm-Message-State: AOJu0Yz1y1KHyo4yqWssW9z+3kY35Puj1OPXd6b3bUpYTqJT0NlgvuC8 H8iG7S7E3hi/pvsl0iT2FjRYzkqEl5aGXDqkHRFA2V1OQkRYyg1Gp5ru0Pbd4hA= X-Google-Smtp-Source: AGHT+IGw6bV8g5dpeZCGmITdjJ+P4PQpu5m8y9ThBv8s80WquXr+nyJrO4fnc+MLmGg387rv6mLOGA== X-Received: by 2002:a17:906:a44d:b0:a3d:9a28:52e6 with SMTP id cb13-20020a170906a44d00b00a3d9a2852e6mr3284540ejb.50.1708891692758; Sun, 25 Feb 2024 12:08:12 -0800 (PST) Received: from [127.0.1.1] ([85.235.12.238]) by smtp.gmail.com with ESMTPSA id hu14-20020a170907a08e00b00a4340138ab5sm504621ejc.5.2024.02.25.12.08.11 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 25 Feb 2024 12:08:12 -0800 (PST) From: Linus Walleij Date: Sun, 25 Feb 2024 21:08:10 +0100 Subject: [PATCH 1/7] ARM: Support CLANG CFI MIME-Version: 1.0 Message-Id: <20240225-arm32-cfi-v1-1-6943306f065b@linaro.org> References: <20240225-arm32-cfi-v1-0-6943306f065b@linaro.org> In-Reply-To: <20240225-arm32-cfi-v1-0-6943306f065b@linaro.org> To: Russell King , Sami Tolvanen , Kees Cook , Nathan Chancellor , Nick Desaulniers , Ard Biesheuvel , Arnd Bergmann Cc: linux-arm-kernel@lists.infradead.org, llvm@lists.linux.dev, Linus Walleij X-Mailer: b4 0.12.4 X-CRM114-Version: 20100106-BlameMichelson ( TRE 0.8.0 (BSD) ) MR-646709E3 X-CRM114-CacheID: sfid-20240225_120815_793673_4DF285E6 X-CRM114-Status: GOOD ( 11.11 ) X-BeenThere: linux-arm-kernel@lists.infradead.org X-Mailman-Version: 2.1.34 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Sender: "linux-arm-kernel" Errors-To: linux-arm-kernel-bounces+linux-arm-kernel=archiver.kernel.org@lists.infradead.org Support Control Flow Integrity (CFI) when compiling with CLANG. In the as-of-writing LLVM CLANG implementation (v17) the 32-bit ARM platform is supported by the generic CFI implementation, which isn't tailored specifically for ARM32 but works well enough to enable the feature. Signed-off-by: Linus Walleij --- arch/arm/Kconfig | 1 + 1 file changed, 1 insertion(+) diff --git a/arch/arm/Kconfig b/arch/arm/Kconfig index 0af6709570d1..1216656a40bc 100644 --- a/arch/arm/Kconfig +++ b/arch/arm/Kconfig @@ -34,6 +34,7 @@ config ARM select ARCH_OPTIONAL_KERNEL_RWX if ARCH_HAS_STRICT_KERNEL_RWX select ARCH_OPTIONAL_KERNEL_RWX_DEFAULT if CPU_V7 select ARCH_SUPPORTS_ATOMIC_RMW + select ARCH_SUPPORTS_CFI_CLANG select ARCH_SUPPORTS_HUGETLBFS if ARM_LPAE select ARCH_SUPPORTS_PER_VMA_LOCK select ARCH_USE_BUILTIN_BSWAP