From patchwork Mon Aug 7 22:00:28 2023 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Mark Brown X-Patchwork-Id: 13345145 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from kanga.kvack.org (kanga.kvack.org [205.233.56.17]) by smtp.lore.kernel.org (Postfix) with ESMTP id 35974C001DF for ; Mon, 7 Aug 2023 22:04:00 +0000 (UTC) Received: by kanga.kvack.org (Postfix) id C2A9B94000A; Mon, 7 Aug 2023 18:03:59 -0400 (EDT) Received: by kanga.kvack.org (Postfix, from userid 40) id BB3168D0001; Mon, 7 Aug 2023 18:03:59 -0400 (EDT) X-Delivered-To: int-list-linux-mm@kvack.org Received: by kanga.kvack.org (Postfix, from userid 63042) id A2EDA94000A; Mon, 7 Aug 2023 18:03:59 -0400 (EDT) X-Delivered-To: linux-mm@kvack.org Received: from relay.hostedemail.com (smtprelay0016.hostedemail.com [216.40.44.16]) by kanga.kvack.org (Postfix) with ESMTP id 8F9708D0001 for ; Mon, 7 Aug 2023 18:03:59 -0400 (EDT) Received: from smtpin01.hostedemail.com (a10.router.float.18 [10.200.18.1]) by unirelay06.hostedemail.com (Postfix) with ESMTP id 70D8EB194D for ; Mon, 7 Aug 2023 22:03:59 +0000 (UTC) X-FDA: 81098686998.01.455A0B1 Received: from dfw.source.kernel.org (dfw.source.kernel.org [139.178.84.217]) by imf09.hostedemail.com (Postfix) with ESMTP id 8D1B9140025 for ; Mon, 7 Aug 2023 22:03:57 +0000 (UTC) Authentication-Results: imf09.hostedemail.com; dkim=pass header.d=kernel.org header.s=k20201202 header.b=qw8yJdFB; dmarc=pass (policy=none) header.from=kernel.org; spf=pass (imf09.hostedemail.com: domain of broonie@kernel.org designates 139.178.84.217 as permitted sender) smtp.mailfrom=broonie@kernel.org ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=hostedemail.com; s=arc-20220608; t=1691445837; h=from:from:sender:reply-to:subject:subject:date:date: message-id:message-id:to:to:cc:cc:mime-version:mime-version: content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references:dkim-signature; bh=Tv3ZQTe1vq0gXi/ckLnsUDbjI3sqm8avbDnc9Ul9ahA=; b=svsxeqUj9AV7sH3tS2DYOm8tyO0oPTOYRZ0WfOLtv6+0FwK8N56fJ812ey7006rUcIG7M0 yjiuuyS32jUPYDUFfWz84KNkXn0umRkF4YhjqTyo0nuYvo/q4Jwxe+mWsolnuMkYwGS05v OwBVRPtA8FODTKr47T/5oErRkz/UjeU= ARC-Authentication-Results: i=1; imf09.hostedemail.com; dkim=pass header.d=kernel.org header.s=k20201202 header.b=qw8yJdFB; dmarc=pass (policy=none) header.from=kernel.org; spf=pass (imf09.hostedemail.com: domain of broonie@kernel.org designates 139.178.84.217 as permitted sender) smtp.mailfrom=broonie@kernel.org ARC-Seal: i=1; s=arc-20220608; d=hostedemail.com; t=1691445837; a=rsa-sha256; cv=none; b=ILzntOkpVY6pP1/ArkGtHWRa3CDM7vSfKxYwbFBjvOlhzbVEBnULBIkorFGnr6fDcgMlqb gFwq8VB6jCztBuU4JGtADC5Gpg5NljXcmLGb068N7YjJi2G+k6wrnsyT3t8LjkkqsKL41U MwGHTz/vPKHCwrTbEBLqDCZG/E1Hi2s= Received: from smtp.kernel.org (relay.kernel.org [52.25.139.140]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits)) (No client certificate requested) by dfw.source.kernel.org (Postfix) with ESMTPS id BE92B622B1; Mon, 7 Aug 2023 22:03:56 +0000 (UTC) Received: by smtp.kernel.org (Postfix) with ESMTPSA id 6D94EC433D9; Mon, 7 Aug 2023 22:03:50 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=k20201202; t=1691445836; bh=KnBf3819XLYZd+1IcRnGIifcqO5I4WiAi+2WJjL5RP8=; h=From:Date:Subject:References:In-Reply-To:To:Cc:From; b=qw8yJdFBMvLIyUsvxRVMlG+XCZevZf/qmFN+xk1o8nzubhAEI2GctJ1yzKv0G1K/G jVJnQg60fwgaCTzpeVvzMof1qu/h8unW8AtpX0RhHMWOH8ODj2ho4RblN73aiIx9mt 0Au2Vh5TWnV4wPqhHG57KAFVB6MLsynxcX1b/FWRXzO1dSoypdHMDfhdmJLW2XzUdL FYq9FnmtlIjXRiMlAlA80DXJQabjwIK4bdWIsUhyDeop2S8Lep0t9BxYxNkzQWmHqI gg+BWF+h8aImHmCQhgR1XG4tJfkDnhyrUvlygvA0H7m8mwySmxZFKL8c5fsrdJuIgH G0Ud6tLKRXp2A== From: Mark Brown Date: Mon, 07 Aug 2023 23:00:28 +0100 Subject: [PATCH v4 23/36] arm64/signal: Expose GCS state in signal frames MIME-Version: 1.0 Message-Id: <20230807-arm64-gcs-v4-23-68cfa37f9069@kernel.org> References: <20230807-arm64-gcs-v4-0-68cfa37f9069@kernel.org> In-Reply-To: <20230807-arm64-gcs-v4-0-68cfa37f9069@kernel.org> To: Catalin Marinas , Will Deacon , Jonathan Corbet , Andrew Morton , Marc Zyngier , Oliver Upton , James Morse , Suzuki K Poulose , Arnd Bergmann , Oleg Nesterov , Eric Biederman , Kees Cook , Shuah Khan , "Rick P. Edgecombe" , Deepak Gupta , Ard Biesheuvel , Szabolcs Nagy Cc: "H.J. Lu" , Paul Walmsley , Palmer Dabbelt , Albert Ou , linux-arm-kernel@lists.infradead.org, linux-doc@vger.kernel.org, kvmarm@lists.linux.dev, linux-fsdevel@vger.kernel.org, linux-arch@vger.kernel.org, linux-mm@kvack.org, linux-kselftest@vger.kernel.org, linux-kernel@vger.kernel.org, linux-riscv@lists.infradead.org, Mark Brown X-Mailer: b4 0.13-dev-034f2 X-Developer-Signature: v=1; a=openpgp-sha256; l=5977; i=broonie@kernel.org; h=from:subject:message-id; bh=KnBf3819XLYZd+1IcRnGIifcqO5I4WiAi+2WJjL5RP8=; b=owEBbQGS/pANAwAKASTWi3JdVIfQAcsmYgBk0WmqyG03hUeRnrKqH0a38tvAdQu+suquEneUa5dg bA+sg1CJATMEAAEKAB0WIQSt5miqZ1cYtZ/in+ok1otyXVSH0AUCZNFpqgAKCRAk1otyXVSH0OBZB/ 4tAqRAujTpzzMb4xdhNeW5zhIrS0Sr12OE/UmJ/9xQXzkNc49yk/K6TdchlHkOLRrRhmXxEXte+yVg l8qfGPf4Jzk9uS6RorouGqiRWSa9yDA0PKB+zggsjfFM1dmasTeOmzXhxeQH1Ma/MwM5+CzXulYVKn l1V1xssd6bCPh3BMhbALldWDJVOYbKnZNbkDMoi4y2rXD7EVVUZ7tAbUQmkstTen/gB16Ii0zetRzU rQF0Rg3dCycyvTz6R13CyQ/4VLk36nlyn4NAGBKsOaCgqiwriuUy+mn8RCy4ACub8rcPqCIx30LACl yZucIzderC/xO03GgxZnHJ0flJ+h5d X-Developer-Key: i=broonie@kernel.org; a=openpgp; fpr=3F2568AAC26998F9E813A1C5C3F436CA30F5D8EB X-Rspamd-Queue-Id: 8D1B9140025 X-Rspam-User: X-Rspamd-Server: rspam04 X-Stat-Signature: ux5q9sgsy7p9b4qez16yuucafnsoks79 X-HE-Tag: 1691445837-289293 X-HE-Meta: U2FsdGVkX188Ari3cK5gqy0l/GVw22uK5YSdmCvYqrvC8IL9IlsrwGvApHmyOGXzQliFcSJG8gkAzmbOBwJvrnCHAqBRWf38NSBjmb71v9hp1pjmu0PO/yQHTM7mTRml3CSJMiakhPL9a14yet0nDbsvmteVjJpf+JHUCqBXsUMhCoM3pQyQ4TDpkZhW1ESYHguEoZTbwDa0b8ZSlonekatklXNlV6saw1hw6eMdpHRZBrfgpCdtVzzGXuk7wYgDXJ7Op0tq7aWzMpq5Vchtow/QFn3xGEytbOBnxNhbtbhC5q7Tz1dUTRg7YqCLzSNu05QSUnpV84CKrfHY0ckziolWtnPYjtE5Dc59BsQuf0H1qIVcDruEck9vc8od3sxoNKVSh1QkVezCQZn59ts1+FT8tTyJlvGMxA1Fe9CLRen+7bH6nYYQyuwwvghKDF/Aje2v2yPD2FCN8aLdiA5lMjT0iGGBETowWVog+LgCJygrC+gGAcUUgDQrjgFZc6yqZVW1WqDEftTRhUn56rwT5TCzqoFars38XsCtx0rSIPTw2NBZoH392QkW4LnW4/bPf/5VDby2TqooZi2UuJf7CobWGnG8yNRpnAl0rektf+Os/wZw7eiNVnXZXpxaaE3oAQ9IEtcqHJr52ynxJW3uk9KE6rGGSerdCVLy0K9d5coNpzMqPEv7dv6GjK04fPEiomV6NTHI9nWm9RWuxI1HUpxMft1H1A0x4wpkyUFhaQkngXuSMhbkP0pTgrgVmIggIyN+rin7EchacPpxvl5EMsGEkfL9P8EAB6/G2urU1OK95YvaRzd/mJNybFXWsmDzvivHqnPW3Ch0kue4nxOTvkkJK5bRKTuacy6nSi7D9VUcEIytJwMV5c7V3Zp6QvECRgiCXrPHXkSfyktfgGiQ3DNwf+ACjoKBHhT/c5CkXnXYDu56uJfjirB3OYs+YlO8XUGloDC3Ug1D4ZEQ0Xy 7rUWR1KX 1x+nkkgOgTO0jA3BtEJyz8a7QmU6pfe0PiMnHgxNf0vNOwGDUB8MB1TcUd3KvXS1U/jLRRK4zfl+z3l2sr+hksfkIKMhITEbTwgOqgAnZUkJ5ZdTjog+zY7fJLxipvBAL1LnbojIi1bFgXFtKP6NRGh2hFyiFevzSex8cMohOZksixKnogU515geOhaZ80Uvb1+z367rw/BmM22QWX1Mu36cpNpg+M7nI/MCNozMrOQfDAUbVdp0oF2jpGq1iaYeD33a97+w8QWil/YsoKHzo+amqiCYuQWdGN0S4lGcfAyjiCTgP4PoX7VORdV18oGUDebOhWQaNuOKsIwYp7Ra5XjFyBDDaXVvEAUsg4WBELTCfM1Sp2mjKEaWC6zmed4w6nwApYr32ImInGSKo4O6zBY+uEGTkruVYeVkBBiG695ku3J0= X-Bogosity: Ham, tests=bogofilter, spamicity=0.000000, version=1.2.4 Sender: owner-linux-mm@kvack.org Precedence: bulk X-Loop: owner-majordomo@kvack.org List-ID: Add a context for the GCS state and include it in the signal context when running on a system that supports GCS. We reuse the same flags that the prctl() uses to specify which GCS features are enabled and also provide the current GCS pointer. We do not support enabling GCS via signal return, there is a conflict between specifying GCSPR_EL0 and allocation of a new GCS and this is not an ancticipated use case. We also enforce GCS configuration locking on signal return. Signed-off-by: Mark Brown --- arch/arm64/include/uapi/asm/sigcontext.h | 9 +++ arch/arm64/kernel/signal.c | 107 +++++++++++++++++++++++++++++++ 2 files changed, 116 insertions(+) diff --git a/arch/arm64/include/uapi/asm/sigcontext.h b/arch/arm64/include/uapi/asm/sigcontext.h index f23c1dc3f002..7b66d245f2d2 100644 --- a/arch/arm64/include/uapi/asm/sigcontext.h +++ b/arch/arm64/include/uapi/asm/sigcontext.h @@ -168,6 +168,15 @@ struct zt_context { __u16 __reserved[3]; }; +#define GCS_MAGIC 0x47435300 + +struct gcs_context { + struct _aarch64_ctx head; + __u64 gcspr; + __u64 features_enabled; + __u64 reserved; +}; + #endif /* !__ASSEMBLY__ */ #include diff --git a/arch/arm64/kernel/signal.c b/arch/arm64/kernel/signal.c index 1c31be0f373e..4cc0c7928cb3 100644 --- a/arch/arm64/kernel/signal.c +++ b/arch/arm64/kernel/signal.c @@ -87,6 +87,7 @@ struct rt_sigframe_user_layout { unsigned long fpsimd_offset; unsigned long esr_offset; + unsigned long gcs_offset; unsigned long sve_offset; unsigned long tpidr2_offset; unsigned long za_offset; @@ -213,6 +214,8 @@ struct user_ctxs { u32 za_size; struct zt_context __user *zt; u32 zt_size; + struct gcs_context __user *gcs; + u32 gcs_size; }; static int preserve_fpsimd_context(struct fpsimd_context __user *ctx) @@ -605,6 +608,82 @@ extern int restore_zt_context(struct user_ctxs *user); #endif /* ! CONFIG_ARM64_SME */ +#ifdef CONFIG_ARM64_GCS + +static int preserve_gcs_context(struct gcs_context __user *ctx) +{ + int err = 0; + u64 gcspr; + + /* + * We will add a cap token to the frame, include it in the + * GCSPR_EL0 we report to support stack switching via + * sigreturn. + */ + gcs_preserve_current_state(); + gcspr = current->thread.gcspr_el0; + if (task_gcs_el0_enabled(current)) + gcspr -= 8; + + __put_user_error(GCS_MAGIC, &ctx->head.magic, err); + __put_user_error(sizeof(*ctx), &ctx->head.size, err); + __put_user_error(gcspr, &ctx->gcspr, err); + __put_user_error(current->thread.gcs_el0_mode, + &ctx->features_enabled, err); + + return err; +} + +static int restore_gcs_context(struct user_ctxs *user) +{ + u64 gcspr, enabled; + int err = 0; + + if (user->gcs_size != sizeof(*user->gcs)) + return -EINVAL; + + __get_user_error(gcspr, &user->gcs->gcspr, err); + __get_user_error(enabled, &user->gcs->features_enabled, err); + if (err) + return err; + + /* Don't allow unknown modes */ + if (enabled & ~PR_SHADOW_STACK_SUPPORTED_STATUS_MASK) + return -EINVAL; + + err = gcs_check_locked(current, enabled); + if (err != 0) + return err; + + /* Don't allow enabling */ + if (!task_gcs_el0_enabled(current) && + (enabled & PR_SHADOW_STACK_ENABLE)) + return -EINVAL; + + /* If we are disabling disable everything */ + if (!(enabled & PR_SHADOW_STACK_ENABLE)) + enabled = 0; + + current->thread.gcs_el0_mode = enabled; + + /* + * We let userspace set GCSPR_EL0 to anything here, we will + * validate later in gcs_restore_signal(). + */ + current->thread.gcspr_el0 = gcspr; + write_sysreg_s(current->thread.gcspr_el0, SYS_GCSPR_EL0); + + return 0; +} + +#else /* ! CONFIG_ARM64_GCS */ + +/* Turn any non-optimised out attempts to use these into a link error: */ +extern int preserve_gcs_context(void __user *ctx); +extern int restore_gcs_context(struct user_ctxs *user); + +#endif /* ! CONFIG_ARM64_GCS */ + static int parse_user_sigframe(struct user_ctxs *user, struct rt_sigframe __user *sf) { @@ -621,6 +700,7 @@ static int parse_user_sigframe(struct user_ctxs *user, user->tpidr2 = NULL; user->za = NULL; user->zt = NULL; + user->gcs = NULL; if (!IS_ALIGNED((unsigned long)base, 16)) goto invalid; @@ -715,6 +795,17 @@ static int parse_user_sigframe(struct user_ctxs *user, user->zt_size = size; break; + case GCS_MAGIC: + if (!system_supports_gcs()) + goto invalid; + + if (user->gcs) + goto invalid; + + user->gcs = (struct gcs_context __user *)head; + user->gcs_size = size; + break; + case EXTRA_MAGIC: if (have_extra_context) goto invalid; @@ -834,6 +925,9 @@ static int restore_sigframe(struct pt_regs *regs, err = restore_fpsimd_context(&user); } + if (err == 0 && system_supports_gcs() && user.gcs) + err = restore_gcs_context(&user); + if (err == 0 && system_supports_tpidr2() && user.tpidr2) err = restore_tpidr2_context(&user); @@ -948,6 +1042,13 @@ static int setup_sigframe_layout(struct rt_sigframe_user_layout *user, return err; } + if (system_supports_gcs()) { + err = sigframe_alloc(user, &user->gcs_offset, + sizeof(struct gcs_context)); + if (err) + return err; + } + if (system_supports_sve() || system_supports_sme()) { unsigned int vq = 0; @@ -1041,6 +1142,12 @@ static int setup_sigframe(struct rt_sigframe_user_layout *user, __put_user_error(current->thread.fault_code, &esr_ctx->esr, err); } + if (system_supports_gcs() && err == 0 && user->gcs_offset) { + struct gcs_context __user *gcs_ctx = + apply_user_offset(user, user->gcs_offset); + err |= preserve_gcs_context(gcs_ctx); + } + /* Scalable Vector Extension state (including streaming), if present */ if ((system_supports_sve() || system_supports_sme()) && err == 0 && user->sve_offset) {