x86/CET: Renumber ARCH_CET_LEGACY_BITMAP to 0x3006
Commit Message
The current CET kernel:
https://github.com/yyu168/linux_cet
changed legacy region bitmap allocation from kernel to user space and
renumbered the prctl number from 0x3005 to 0x3006. This patch updates
glibc with:
/* Enable legacy region bitmap with unsigned long long *addr:
address: addr[0].
size: addr[1].
*/
# define ARCH_CET_LEGACY_BITMAP 0x3006
* sysdeps/unix/sysv/linux/x86/dl-cet.h
(dl_cet_allocate_legacy_bitmap ): Removed.
(dl_cet_enable_legacy_bitmap): New.
* sysdeps/unix/sysv/linux/x86/include/asm/prctl.h
(ARCH_CET_LEGACY_BITMAP): Renumbered to 0x3006.
* sysdeps/x86/dl-cet.c (dl_cet_check): Mmap legacy bitmap.
Call dl_cet_enable_legacy_bitmap instead of
dl_cet_allocate_legacy_bitmap.
---
sysdeps/unix/sysv/linux/x86/dl-cet.h | 17 +++++-------
.../unix/sysv/linux/x86/include/asm/prctl.h | 4 +--
sysdeps/x86/dl-cet.c | 27 ++++++++++++++++---
3 files changed, 32 insertions(+), 16 deletions(-)
Comments
* H. J. Lu:
> The current CET kernel:
>
> https://github.com/yyu168/linux_cet
>
> changed legacy region bitmap allocation from kernel to user space and
> renumbered the prctl number from 0x3005 to 0x3006. This patch updates
> glibc with:
>
> /* Enable legacy region bitmap with unsigned long long *addr:
> address: addr[0].
> size: addr[1].
> */
> # define ARCH_CET_LEGACY_BITMAP 0x3006
The patch looks okay in general, but I suggest to wait until this is
actually merged into an upstream kernel, so that we don't have to change
the number again.
> + /* Allocate and enable legacy bitmap. */
> + size_t legacy_bitmap_size
> + = ((uintptr_t) __libc_stack_end
> + / GLRO(dl_pagesize) / 8);
> + void *legacy_bitmap_addr
> + = __mmap (NULL, legacy_bitmap_size,
> + PROT_READ | PROT_WRITE,
> + MAP_ANON | MAP_PRIVATE | MAP_NORESERVE,
> + -1, 0);
> + if (legacy_bitmap_addr == MAP_FAILED)
> + {
> + if (program)
> + _dl_fatal_printf ("%s: mmap legacy bitmap failed\n",
> + l->l_name);
> + else
> + _dl_signal_error (EINVAL, l->l_name, "dlopen",
> + N_("mmap legacy bitmap failed"));
Maybe you can log the size of the mapping attempt? That could be useful
to diagnose failures.
Thanks,
Florian
On Tue, Nov 20, 2018 at 8:07 AM Florian Weimer <fweimer@redhat.com> wrote:
>
> * H. J. Lu:
>
> > The current CET kernel:
> >
> > https://github.com/yyu168/linux_cet
> >
> > changed legacy region bitmap allocation from kernel to user space and
> > renumbered the prctl number from 0x3005 to 0x3006. This patch updates
> > glibc with:
> >
> > /* Enable legacy region bitmap with unsigned long long *addr:
> > address: addr[0].
> > size: addr[1].
> > */
> > # define ARCH_CET_LEGACY_BITMAP 0x3006
>
> The patch looks okay in general, but I suggest to wait until this is
> actually merged into an upstream kernel, so that we don't have to change
> the number again.
Sure.
> > + /* Allocate and enable legacy bitmap. */
> > + size_t legacy_bitmap_size
> > + = ((uintptr_t) __libc_stack_end
> > + / GLRO(dl_pagesize) / 8);
> > + void *legacy_bitmap_addr
> > + = __mmap (NULL, legacy_bitmap_size,
> > + PROT_READ | PROT_WRITE,
> > + MAP_ANON | MAP_PRIVATE | MAP_NORESERVE,
> > + -1, 0);
> > + if (legacy_bitmap_addr == MAP_FAILED)
> > + {
> > + if (program)
> > + _dl_fatal_printf ("%s: mmap legacy bitmap failed\n",
> > + l->l_name);
> > + else
> > + _dl_signal_error (EINVAL, l->l_name, "dlopen",
> > + N_("mmap legacy bitmap failed"));
>
> Maybe you can log the size of the mapping attempt? That could be useful
> to diagnose failures.
It isn't easy since _dl_signal_error only takes strings.
* H. J. Lu:
>> Maybe you can log the size of the mapping attempt? That could be useful
>> to diagnose failures.
>
> It isn't easy since _dl_signal_error only takes strings.
Ah. We have _dl_exception_create_format and _dl_signal_exception for
that; this functionality is split across two function.
Thanks,
Florian
@@ -19,24 +19,19 @@
#include <asm/prctl.h>
static inline int __attribute__ ((always_inline))
-dl_cet_allocate_legacy_bitmap (unsigned long *legacy_bitmap)
+dl_cet_enable_legacy_bitmap (unsigned long *legacy_bitmap)
{
/* Allocate legacy bitmap. */
INTERNAL_SYSCALL_DECL (err);
#ifdef __LP64__
- return (int) INTERNAL_SYSCALL (arch_prctl, err, 2,
- ARCH_CET_LEGACY_BITMAP, legacy_bitmap);
+ unsigned long *legacy_bitmap_u64 = legacy_bitmap;
#else
unsigned long long legacy_bitmap_u64[2];
- int res = INTERNAL_SYSCALL (arch_prctl, err, 2,
- ARCH_CET_LEGACY_BITMAP, legacy_bitmap_u64);
- if (res == 0)
- {
- legacy_bitmap[0] = legacy_bitmap_u64[0];
- legacy_bitmap[1] = legacy_bitmap_u64[1];
- }
- return res;
+ legacy_bitmap_u64[0] = legacy_bitmap[0];
+ legacy_bitmap_u64[1] = legacy_bitmap[1];
#endif
+ return (int) INTERNAL_SYSCALL (arch_prctl, err, 2,
+ ARCH_CET_LEGACY_BITMAP, legacy_bitmap_u64);
}
static inline int __attribute__ ((always_inline))
@@ -24,9 +24,9 @@
OUT: allocated shadow stack address: *addr.
*/
# define ARCH_CET_ALLOC_SHSTK 0x3004
-/* Return legacy region bitmap info in unsigned long long *addr:
+/* Enable legacy region bitmap with unsigned long long *addr:
address: addr[0].
size: addr[1].
*/
-# define ARCH_CET_LEGACY_BITMAP 0x3005
+# define ARCH_CET_LEGACY_BITMAP 0x3006
#endif /* ARCH_CET_STATUS */
@@ -202,13 +202,34 @@ mprotect_failure:
N_("mprotect legacy bitmap failed"));
}
}
- else
+ else if (!GL(dl_x86_legacy_bitmap)[0])
{
- /* Allocate legacy bitmap. */
- int res = dl_cet_allocate_legacy_bitmap
+ /* Allocate and enable legacy bitmap. */
+ size_t legacy_bitmap_size
+ = ((uintptr_t) __libc_stack_end
+ / GLRO(dl_pagesize) / 8);
+ void *legacy_bitmap_addr
+ = __mmap (NULL, legacy_bitmap_size,
+ PROT_READ | PROT_WRITE,
+ MAP_ANON | MAP_PRIVATE | MAP_NORESERVE,
+ -1, 0);
+ if (legacy_bitmap_addr == MAP_FAILED)
+ {
+ if (program)
+ _dl_fatal_printf ("%s: mmap legacy bitmap failed\n",
+ l->l_name);
+ else
+ _dl_signal_error (EINVAL, l->l_name, "dlopen",
+ N_("mmap legacy bitmap failed"));
+ }
+ GL(dl_x86_legacy_bitmap)[0]
+ = (uintptr_t) legacy_bitmap_addr;
+ GL(dl_x86_legacy_bitmap)[1] = legacy_bitmap_size;
+ int res = dl_cet_enable_legacy_bitmap
(GL(dl_x86_legacy_bitmap));
if (res != 0)
{
+ __munmap (legacy_bitmap_addr, legacy_bitmap_size);
if (program)
_dl_fatal_printf ("%s: legacy bitmap isn't available\n",
l->l_name);