From patchwork Thu Sep 12 23:16:29 2024 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Deepak Gupta X-Patchwork-Id: 13802833 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from kanga.kvack.org (kanga.kvack.org [205.233.56.17]) by smtp.lore.kernel.org (Postfix) with ESMTP id 0DE48EEE270 for ; Thu, 12 Sep 2024 23:17:54 +0000 (UTC) Received: by kanga.kvack.org (Postfix) id 8FD556B00A3; Thu, 12 Sep 2024 19:17:53 -0400 (EDT) Received: by kanga.kvack.org (Postfix, from userid 40) id 8ACDF6B00A4; Thu, 12 Sep 2024 19:17:53 -0400 (EDT) X-Delivered-To: int-list-linux-mm@kvack.org Received: by kanga.kvack.org (Postfix, from userid 63042) id 6FF586B00A5; Thu, 12 Sep 2024 19:17:53 -0400 (EDT) X-Delivered-To: linux-mm@kvack.org Received: from relay.hostedemail.com (smtprelay0016.hostedemail.com [216.40.44.16]) by kanga.kvack.org (Postfix) with ESMTP id 4EEFC6B00A3 for ; Thu, 12 Sep 2024 19:17:53 -0400 (EDT) Received: from smtpin28.hostedemail.com (a10.router.float.18 [10.200.18.1]) by unirelay02.hostedemail.com (Postfix) with ESMTP id 0E86A12066A for ; Thu, 12 Sep 2024 23:17:53 +0000 (UTC) X-FDA: 82557650826.28.0DC7C65 Received: from mail-pj1-f47.google.com (mail-pj1-f47.google.com [209.85.216.47]) by imf19.hostedemail.com (Postfix) with ESMTP id 312091A0010 for ; Thu, 12 Sep 2024 23:17:50 +0000 (UTC) Authentication-Results: imf19.hostedemail.com; dkim=pass header.d=rivosinc-com.20230601.gappssmtp.com header.s=20230601 header.b=NRDCgiO7; dmarc=none; spf=pass (imf19.hostedemail.com: domain of debug@rivosinc.com designates 209.85.216.47 as permitted sender) smtp.mailfrom=debug@rivosinc.com ARC-Seal: i=1; s=arc-20220608; d=hostedemail.com; t=1726183065; a=rsa-sha256; cv=none; b=gK5d8R6D+7fQm0vgqZ2a3H1yGDkSiflnc0wtCCppgMZlB11OBHg54eL5dulPod84g5W6d3 maj88XO7tv3DRKnQkvI7jzEUrQXrq/sz8x9JzPq2IE9FvoVHkBmYON3WhCXTix/3wI0DoC w1uy7QEM/fIdc4R3edKtNwcQiwnPEoM= ARC-Authentication-Results: i=1; imf19.hostedemail.com; dkim=pass header.d=rivosinc-com.20230601.gappssmtp.com header.s=20230601 header.b=NRDCgiO7; dmarc=none; spf=pass (imf19.hostedemail.com: domain of debug@rivosinc.com designates 209.85.216.47 as permitted sender) smtp.mailfrom=debug@rivosinc.com ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=hostedemail.com; s=arc-20220608; t=1726183065; h=from:from:sender:reply-to:subject:subject:date:date: message-id:message-id:to:to:cc:cc:mime-version:mime-version: content-type:content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references:dkim-signature; bh=IdMH+b8hMWx7M6md7N6CXtcv0PrleWKto++QHl76wt4=; b=cnMkc3j/K57C0iX0BQ8tfEaSJvxdQVwTr9qVgKlxsb0t0NuzZ/P+wAoXRulX/Ia9ecMuLK R+VAlxZ9NX376UOxJmU5xeduYlPQbTEpEn6ADj7hE2v6es0lHQPNwk2ErJtOtBe8xptyMF BLM9p6X6h3PBZQmM2ZqalI9YcwJi1Lc= Received: by mail-pj1-f47.google.com with SMTP id 98e67ed59e1d1-2d88690837eso1257351a91.2 for ; Thu, 12 Sep 2024 16:17:50 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=rivosinc-com.20230601.gappssmtp.com; s=20230601; t=1726183070; x=1726787870; darn=kvack.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to; bh=IdMH+b8hMWx7M6md7N6CXtcv0PrleWKto++QHl76wt4=; b=NRDCgiO7PuJLeaSKH1PiNphBkHT+zoSfWkCfIapsOzbqLIUrnNlfw7XCS1iOvIUGRb YUZfUQCINZYha3dl3dWKIGF5QWjPoQneiAUkmFwCu27BArSvcXy16dTBBgTOXxxLmNFL 6XjMA8jq210GFKggQ65Gy0lvJkc3/G1DuQ1q0fJv8X+xMKeANij1NM+Be6K34iMc+PhS j1367+7vs+osBb5Z+4HGmUGqWYwlMNNGvNGQ3/Xy++/mjVztNrMOJCNNJmf3csmNrqa8 TlS7yToeu6P31hIa4M7MEmtsg9L6IZKFDwE2Gt8F71jPi/3PfDWAsMMeCuFhVNqaPtGH SF+g== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1726183070; x=1726787870; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to; bh=IdMH+b8hMWx7M6md7N6CXtcv0PrleWKto++QHl76wt4=; b=vJN1vocr24L1wUdlQfdt752kZ4TxrHkH0zVeDSfjrG8OYVkCBEAjkhrDPEtrIn1qxV SYS8XdGvJvA2bC0FYN1+O97BPknBqfyqXlFLORFKouHyEUbfKcI15elul0awThg0zT4U b/eTKFTnxK13oS105tB9VvOLTRoAyw9Ebrll43bAFA+z3T4vEmLgFQRdrRDxMktZ4Bdz XSA4NckAAAk0Ghna9k314FehPfN/8j8twmyAQuAs1SC8YatuxCtY8pMxnzeHdq8uKxf4 715IeQvdtEtQu1aaqpjLuIjex8Y8M3kP6FP4sQ3GEH9byjaR0MpbRl72nMYrEcY/EiU8 97cg== X-Forwarded-Encrypted: i=1; AJvYcCUsuyCzi8S3fefDgrCuaI75X2RaY4DT9PHQaNwm1y7qUccEjKBYEUHMJf8Pg9+ZQBa2glMOlYsErA==@kvack.org X-Gm-Message-State: AOJu0YwnRRg4xqCer23aQnwFSJssbjUQWkBoaRvIwEK0azPTuvikre2N uQERpSjT0MAwj2kME+VqFwk342TbTold9mqULknpONuVhjzxH+8+TuD6lBu1I8w= X-Google-Smtp-Source: AGHT+IFFLSdBWtF2TFEc0MNeO8MBZSGLro8EZzW5E3fSn2Pc5KYqBR0cHiRpYxrN8cHcKSAWR1r/XQ== X-Received: by 2002:a17:90a:9a86:b0:2d8:8818:4d53 with SMTP id 98e67ed59e1d1-2dba0090ccbmr4436318a91.41.1726183069691; Thu, 12 Sep 2024 16:17:49 -0700 (PDT) Received: from debug.ba.rivosinc.com ([64.71.180.162]) by smtp.gmail.com with ESMTPSA id 98e67ed59e1d1-2db6c1ac69asm3157591a91.0.2024.09.12.16.17.45 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 12 Sep 2024 16:17:49 -0700 (PDT) From: Deepak Gupta To: paul.walmsley@sifive.com, palmer@sifive.com, conor@kernel.org, linux-doc@vger.kernel.org, linux-riscv@lists.infradead.org, linux-kernel@vger.kernel.org, devicetree@vger.kernel.org, linux-fsdevel@vger.kernel.org, linux-mm@kvack.org, linux-arch@vger.kernel.org, linux-kselftest@vger.kernel.org Cc: corbet@lwn.net, palmer@dabbelt.com, aou@eecs.berkeley.edu, robh@kernel.org, krzk+dt@kernel.org, oleg@redhat.com, tglx@linutronix.de, mingo@redhat.com, bp@alien8.de, dave.hansen@linux.intel.com, x86@kernel.org, hpa@zytor.com, peterz@infradead.org, akpm@linux-foundation.org, arnd@arndb.de, ebiederm@xmission.com, kees@kernel.org, Liam.Howlett@oracle.com, vbabka@suse.cz, lorenzo.stoakes@oracle.com, shuah@kernel.org, brauner@kernel.org, samuel.holland@sifive.com, debug@rivosinc.com, andy.chiu@sifive.com, jerry.shih@sifive.com, greentime.hu@sifive.com, charlie@rivosinc.com, evan@rivosinc.com, cleger@rivosinc.com, xiao.w.wang@intel.com, ajones@ventanamicro.com, anup@brainfault.org, mchitale@ventanamicro.com, atishp@rivosinc.com, sameo@rivosinc.com, bjorn@rivosinc.com, alexghiti@rivosinc.com, david@redhat.com, libang.li@antgroup.com, jszhang@kernel.org, leobras@redhat.com, guoren@kernel.org, samitolvanen@google.com, songshuaishuai@tinylab.org, costa.shul@redhat.com, bhe@redhat.com, zong.li@sifive.com, puranjay@kernel.org, namcaov@gmail.com, antonb@tenstorrent.com, sorear@fastmail.com, quic_bjorande@quicinc.com, ancientmodern4@gmail.com, ben.dooks@codethink.co.uk, quic_zhonhan@quicinc.com, cuiyunhui@bytedance.com, yang.lee@linux.alibaba.com, ke.zhao@shingroup.cn, sunilvl@ventanamicro.com, tanzhasanwork@gmail.com, schwab@suse.de, dawei.li@shingroup.cn, rppt@kernel.org, willy@infradead.org, usama.anjum@collabora.com, osalvador@suse.de, ryan.roberts@arm.com, andrii@kernel.org, alx@kernel.org, catalin.marinas@arm.com, broonie@kernel.org, revest@chromium.org, bgray@linux.ibm.com, deller@gmx.de, zev@bewilderbeest.net Subject: [PATCH v4 10/30] riscv: usercfi state for task and save/restore of CSR_SSP on trap entry/exit Date: Thu, 12 Sep 2024 16:16:29 -0700 Message-ID: <20240912231650.3740732-11-debug@rivosinc.com> X-Mailer: git-send-email 2.45.0 In-Reply-To: <20240912231650.3740732-1-debug@rivosinc.com> References: <20240912231650.3740732-1-debug@rivosinc.com> MIME-Version: 1.0 X-Rspam-User: X-Stat-Signature: bezi8rpxmqxie586nqzm7ooxxidcfmwd X-Rspamd-Queue-Id: 312091A0010 X-Rspamd-Server: rspam02 X-HE-Tag: 1726183070-344840 X-HE-Meta: U2FsdGVkX1+dBh9Xorbe7XosR43qS5ikC+RCyIJadbKJnBzJZrE4tXObY7/X28eAwje0+D5R0sKdwsve1xVvoNuRAMhT9Ibt2ck8OVnPxi8ZRCWFGCkSyxAkoJDL02yMx3DHw6O96eAFo1mcx69Hv7h7RqLlQNxbeCyy92N54m9KAVMZI4F4/dYPOldKoKdDedZi95MRwao0Ikb9VjZe2MAG7E8iiIeLIqpuEiYB5VDRts1xs/HpuUmMPKeFbUBBdEJgwm2Y2b1EhzC818OP1dJOzzl9dflY86e6RykXKftWh1IF4g2cuy8Q0mkk7AKJM0sHOrVs/BqtPFOrnHl+r+xvH8xquXVnRpdHjMUTXokTcZmL1iMdiZJ4hBHxcJGQS9Q3IZkxcr/pcvmMLikd8eXZhhZCWNi9e3JJ/6D1P7vCXbZJHVApM8B7iIkaX12j4J0Qzd14L2q3/BVIF1c91ZJbPZef329OBpemR8Jse/2yH8ycqWzJmh44Nu6ogkykaIEtOQE9UamVIvr2/Dt+7l0yTR8bzoPs/7ahFvxiys8ZXo5RKlyn2iuInUR5LqxC6LzkmSgBkCve4Ct84LntTrkVTMLFIvFat8XD/0E4ksNZ1XHzrOo7Yo3QfIIA32YniB1npdaixseXbdO78omSJhSJNDWMWNoyS+6zgVxwT9N6/YFr1RD343slgH4uNF2APubCpbKA1E9OmPzZZnJ9ESV2WBkRnKMJD616fiUdAZEnZu5UA9JRREB4NEnBy6KGp2F6vKADeMUrGWZQ7fUFLLSPCSNvUEftUcfO6ZTgIA0A8oCyxStKBMdeL++52nkRUMHJc0dFKuXC4eIemsmQBAqj2n0oEaiJQiLbVOWdi5dJsPIyF5lVv8ZzR3BnMlqh/JoYLfu/EQen1uwARSUw/qEkE1ZWinQU3Io4k4JRJxh25VYTpxAzOSQj8eERdp99m9xBffBbeuEXScgu0NV Q1Od7eFJ M3+bLNJbzoTL4Cvdk/GKfVgmMzKxlq77BCUEpyi1EvgOXCgVzrZtfdjPWNqc3NwjKEkkHIsQO01lkg25AbxvdYHoBprwb1w+YINFtctDC/pCoHlN1YV9/tOKPuwOIkRjXo6pOpx16f3VggXxRgmkit1dwvf7eskw9w8iKS9ICSa4IuV98DXX0n8w+lZqR/+gH6aXdA7gUNQLj2KnQ9SnZpLxBPgMmxH2IK/an1UxWrS/34mMoJ+mQ6NiE/nUZn8klL08gCsEAU3tZg+/e9XOGxVHTk9BlC5lhPdBcLrPBmcBzhYoJePxzJ6N9KZzAYaig2Xqs68mgrtKAd+ISC4jaM/FCtjuVxbKLw12A6WZ++iSEVGKm9Y8XNfBlQFXN7E6W/hERlYq9dnnluY7miu2OqvCwgqUh1Kc/S8hdWsze3tynTLLsQ1lOKc4Jd9hrx0y4jPUUTGY0sQ6pyplDKloyanP3gEXH4Fc/BJlD2vem8sLamq3FgKI5iC1LM1aEkYhN4NFKH1/5I7YZnDqzqfityWNhPaGCs1whtOxK X-Bogosity: Ham, tests=bogofilter, spamicity=0.000003, version=1.2.4 Sender: owner-linux-mm@kvack.org Precedence: bulk X-Loop: owner-majordomo@kvack.org List-ID: List-Subscribe: List-Unsubscribe: Carves out space in arch specific thread struct for cfi status and shadow stack in usermode on riscv. This patch does following - defines a new structure cfi_status with status bit for cfi feature - defines shadow stack pointer, base and size in cfi_status structure - defines offsets to new member fields in thread in asm-offsets.c - Saves and restore shadow stack pointer on trap entry (U --> S) and exit (S --> U) Shadow stack save/restore is gated on feature availiblity and implemented using alternative. CSR can be context switched in `switch_to` as well but soon as kernel shadow stack support gets rolled in, shadow stack pointer will need to be switched at trap entry/exit point (much like `sp`). It can be argued that kernel using shadow stack deployment scenario may not be as prevalant as user mode using this feature. But even if there is some minimal deployment of kernel shadow stack, that means that it needs to be supported. And thus save/restore of shadow stack pointer in entry.S instead of in `switch_to.h`. Signed-off-by: Deepak Gupta Reviewed-by: Charlie Jenkins --- arch/riscv/include/asm/processor.h | 1 + arch/riscv/include/asm/thread_info.h | 3 +++ arch/riscv/include/asm/usercfi.h | 24 ++++++++++++++++++++++++ arch/riscv/kernel/asm-offsets.c | 4 ++++ arch/riscv/kernel/entry.S | 26 ++++++++++++++++++++++++++ 5 files changed, 58 insertions(+) create mode 100644 arch/riscv/include/asm/usercfi.h diff --git a/arch/riscv/include/asm/processor.h b/arch/riscv/include/asm/processor.h index d61587964bd7..83d6ca4e0bba 100644 --- a/arch/riscv/include/asm/processor.h +++ b/arch/riscv/include/asm/processor.h @@ -14,6 +14,7 @@ #include #include +#include /* * addr is a hint to the maximum userspace address that mmap should provide, so diff --git a/arch/riscv/include/asm/thread_info.h b/arch/riscv/include/asm/thread_info.h index c74536194626..cb694aef337d 100644 --- a/arch/riscv/include/asm/thread_info.h +++ b/arch/riscv/include/asm/thread_info.h @@ -58,6 +58,9 @@ struct thread_info { int cpu; unsigned long syscall_work; /* SYSCALL_WORK_ flags */ unsigned long envcfg; +#ifdef CONFIG_RISCV_USER_CFI + struct cfi_status user_cfi_state; +#endif #ifdef CONFIG_SHADOW_CALL_STACK void *scs_base; void *scs_sp; diff --git a/arch/riscv/include/asm/usercfi.h b/arch/riscv/include/asm/usercfi.h new file mode 100644 index 000000000000..4fa201b4fc4e --- /dev/null +++ b/arch/riscv/include/asm/usercfi.h @@ -0,0 +1,24 @@ +/* SPDX-License-Identifier: GPL-2.0 + * Copyright (C) 2024 Rivos, Inc. + * Deepak Gupta + */ +#ifndef _ASM_RISCV_USERCFI_H +#define _ASM_RISCV_USERCFI_H + +#ifndef __ASSEMBLY__ +#include + +#ifdef CONFIG_RISCV_USER_CFI +struct cfi_status { + unsigned long ubcfi_en : 1; /* Enable for backward cfi. */ + unsigned long rsvd : ((sizeof(unsigned long)*8) - 1); + unsigned long user_shdw_stk; /* Current user shadow stack pointer */ + unsigned long shdw_stk_base; /* Base address of shadow stack */ + unsigned long shdw_stk_size; /* size of shadow stack */ +}; + +#endif /* CONFIG_RISCV_USER_CFI */ + +#endif /* __ASSEMBLY__ */ + +#endif /* _ASM_RISCV_USERCFI_H */ diff --git a/arch/riscv/kernel/asm-offsets.c b/arch/riscv/kernel/asm-offsets.c index b09ca5f944f7..5457f9070cff 100644 --- a/arch/riscv/kernel/asm-offsets.c +++ b/arch/riscv/kernel/asm-offsets.c @@ -45,6 +45,10 @@ void asm_offsets(void) #endif OFFSET(TASK_TI_CPU_NUM, task_struct, thread_info.cpu); +#ifdef CONFIG_RISCV_USER_CFI + OFFSET(TASK_TI_CFI_STATUS, task_struct, thread_info.user_cfi_state); + OFFSET(TASK_TI_USER_SSP, task_struct, thread_info.user_cfi_state.user_shdw_stk); +#endif OFFSET(TASK_THREAD_F0, task_struct, thread.fstate.f[0]); OFFSET(TASK_THREAD_F1, task_struct, thread.fstate.f[1]); OFFSET(TASK_THREAD_F2, task_struct, thread.fstate.f[2]); diff --git a/arch/riscv/kernel/entry.S b/arch/riscv/kernel/entry.S index ac2e908d4418..ca9203e6d76d 100644 --- a/arch/riscv/kernel/entry.S +++ b/arch/riscv/kernel/entry.S @@ -60,6 +60,20 @@ SYM_CODE_START(handle_exception) REG_L s0, TASK_TI_USER_SP(tp) csrrc s1, CSR_STATUS, t0 + /* + * If previous mode was U, capture shadow stack pointer and save it away + * Zero CSR_SSP at the same time for sanitization. + */ + ALTERNATIVE("nop; nop; nop; nop", + __stringify( \ + andi s2, s1, SR_SPP; \ + bnez s2, skip_ssp_save; \ + csrrw s2, CSR_SSP, x0; \ + REG_S s2, TASK_TI_USER_SSP(tp); \ + skip_ssp_save:), + 0, + RISCV_ISA_EXT_ZICFISS, + CONFIG_RISCV_USER_CFI) csrr s2, CSR_EPC csrr s3, CSR_TVAL csrr s4, CSR_CAUSE @@ -149,6 +163,18 @@ SYM_CODE_START_NOALIGN(ret_from_exception) * structures again. */ csrw CSR_SCRATCH, tp + + /* + * Going back to U mode, restore shadow stack pointer + */ + ALTERNATIVE("nop; nop", + __stringify( \ + REG_L s3, TASK_TI_USER_SSP(tp); \ + csrw CSR_SSP, s3), + 0, + RISCV_ISA_EXT_ZICFISS, + CONFIG_RISCV_USER_CFI) + 1: #ifdef CONFIG_RISCV_ISA_V_PREEMPTIVE move a0, sp