| Message ID | 20260603000656.3287796-1-adhemerval.zanella@linaro.org (mailing list archive) |
|---|---|
| Headers |
Return-Path: <libc-alpha-bounces~patchwork=sourceware.org@sourceware.org> X-Original-To: patchwork@sourceware.org Delivered-To: patchwork@sourceware.org Received: from vm01.sourceware.org (localhost [IPv6:::1]) by sourceware.org (Postfix) with ESMTP id 7E5C24BA2E2E for <patchwork@sourceware.org>; Wed, 3 Jun 2026 00:11:25 +0000 (GMT) DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org 7E5C24BA2E2E Authentication-Results: sourceware.org; dkim=pass (2048-bit key, unprotected) header.d=linaro.org header.i=@linaro.org header.a=rsa-sha256 header.s=google header.b=E12hQoJJ X-Original-To: libc-alpha@sourceware.org Delivered-To: libc-alpha@sourceware.org Received: from mail-yw1-x1130.google.com (mail-yw1-x1130.google.com [IPv6:2607:f8b0:4864:20::1130]) by sourceware.org (Postfix) with ESMTPS id E05854BA2E1B for <libc-alpha@sourceware.org>; Wed, 3 Jun 2026 00:07:02 +0000 (GMT) DMARC-Filter: OpenDMARC Filter v1.4.2 sourceware.org E05854BA2E1B Authentication-Results: sourceware.org; dmarc=pass (p=none dis=none) header.from=linaro.org Authentication-Results: sourceware.org; spf=pass smtp.mailfrom=linaro.org ARC-Filter: OpenARC Filter v1.0.0 sourceware.org E05854BA2E1B Authentication-Results: sourceware.org; arc=none smtp.remote-ip=2607:f8b0:4864:20::1130 ARC-Seal: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1780445223; cv=none; b=xVGMCmrni1sbrJXkg2X5Rfai7WII81jJ9XmjisrCkwrjZUjOuZKWpbmiKbEu+hBKTQsHRVHN2vUsxQ6KmoPHoz7B9iZ5mt7dXzZUfi0rtFgVx/IUyHcyFDWd7az+3v6NItp0/lSJhGwk+sROwG3rF3EmonnEils+RjYwPQOlDhI= ARC-Message-Signature: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1780445223; c=relaxed/simple; bh=gAP1hmZdgr5bbE08ZxK0Oa28rwcnA0NhMf9Sf129+8U=; h=DKIM-Signature:From:To:Subject:Date:Message-ID:MIME-Version; b=FOA4zApYFKYjtmc+ufouVr4erquH50DYVoDL+6XrAcnRl4vqpj+hwuVgndMiWAG/AQmgw49Y1phwloaD5gNfLftHu020a9lMv6+CPpwKun0b07jDAsy64NFM4reFaUmbxqdyHKRL4OjiboD37WMOdqMq7phtJe5+a8+Fm2DvLP4= ARC-Authentication-Results: i=1; sourceware.org; dkim=pass (2048-bit key, unprotected) header.d=linaro.org header.i=@linaro.org header.a=rsa-sha256 header.s=google header.b=E12hQoJJ DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org E05854BA2E1B Received: by mail-yw1-x1130.google.com with SMTP id 00721157ae682-7e2f3646c10so40096397b3.0 for <libc-alpha@sourceware.org>; Tue, 02 Jun 2026 17:07:02 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linaro.org; s=google; t=1780445222; x=1781050022; darn=sourceware.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to; bh=MpojJGhBnU0WdYMqlrUebjxRkbRV10aPOdKQsum1qeM=; b=E12hQoJJ9D/QQws6Z2fFqlpagG+9kJ5R/TUeN0cqmIdJTrj24+guNFZ7H4jiU3tCpN ZmNDuqNfHEmgtHyLdhqx9hWVQxYnpUNlMSlCNxkPDH0Sh40LTkhRy3HFf7ZX4JVC9OFP rWHU94ByLnJ7gcw+qYuwXWiYT1pygdYiSJ3fckrmwvvFX9Vw47rNDpcXqt6CMBvisKMb 3Gw+YZ5K0p4nwog6ko0hsaj2XyQMjNElmDrhtg3/2E64/BI12p70c9VnIH2Fd08o2V09 xeqt9wUJTZkwdIqyT1GlxF8/ja0ixjmO35fliBvnAHHeFKbZMgC99nLYL5qSVpvZ/z1o HvZw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1780445222; x=1781050022; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to; bh=MpojJGhBnU0WdYMqlrUebjxRkbRV10aPOdKQsum1qeM=; b=EaOEH1iOiy2AYmVZqIrbqmXE3sbVfkaG1s+cB/34fKdkaQmfbaVo3sl5M3lKol77vC g78Moc3f/47Lj+lyt8N+rtHbF86qkzTuP8ET8LpWFTOuCI6aPOb7MI6c8k6guJZLBFAA PT2ky7zM1k0KhcITW7mLPuh9NfnBWBoZ4IT4X2glyicO1JTzd1/40SdQtq2sFStXuSRV BXMouQ8Np1gfPXBzwzMHXVtn08zjnwrlV1b8dAQj01LD020i71iq7pDuttlPzi9wb0Fm DEFetzBo1q2SHUS3EoTu5xiOTyQfvYgktkjk1jXSQip22WhyuWpozLu/vpxCSShGsyZZ g4gw== X-Gm-Message-State: AOJu0YzjFQ1iV87LHAXKbKHQr2OAJgIf1WBFZDc9Sp5lleh5ncoxYwnU T6H+rNgMLpL+WTJvCTxXo7fyCXCbSQ1DwqU9Wj2rwLKCKyjk2M6cmmeVZImmXelaYtm07NYJKp+ 39/Rj X-Gm-Gg: Acq92OEb3BxF+StAbdkv6WiARv95NOuLQwIdzE8foWsG20wbeLaRDpnDneFKrsfiEmw svVYITzuZPhIhRY3u5wc54T0brafp/3U9ZNSZ63dGENLixWkEctRGiuUnfCuH5pUtXPReyE9cxF Is+PQAzLNqhwpU2ANq+WYzgkV7wXiaun15ZGaca/7O3ipdjMvFFdDzWzOb7Z7cd9kz8sZkFQYsq NdO+aVilqRGSReBAwSZ9wZeg//M29UkCCATVUaIut4bS2CAcbVQjBgfHeydcE8Kw/AgIHO7xFG9 ucIR1aGak9Lq9PytrqXvZLdVGt67MzCDxYHi05qg7rJdIDxIxO9dHhqbwRz4XyXKd0R9+QvoBPJ nk5JnXEOPgaMLM0ToZIR4X+C4CfuitsHEcNzsCjDk2IKZqqbMH8F2OuJbI8iLNdwSFV5L3S7pUN TpVLvwPIzTCftEydoeWGxGvsEIxJVVQj8I282OgMd5yXN9uA== X-Received: by 2002:a05:690c:7309:b0:7bf:1433:8f52 with SMTP id 00721157ae682-7ea479eefefmr12342937b3.14.1780445222101; Tue, 02 Jun 2026 17:07:02 -0700 (PDT) Received: from mandiga.. ([2804:1b3:a7c2:efc6:8f41:550d:2b14:9278]) by smtp.gmail.com with ESMTPSA id 00721157ae682-7ea23a9946bsm7332207b3.37.2026.06.02.17.07.00 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 02 Jun 2026 17:07:01 -0700 (PDT) From: Adhemerval Zanella <adhemerval.zanella@linaro.org> To: libc-alpha@sourceware.org Cc: Anderson Nascimento <anderson@allelesecurity.com>, Carlos O'Donell <carlos@redhat.com> Subject: [PATCH 0/8] Pointer guard hardening and consolidation Date: Tue, 2 Jun 2026 21:04:31 -0300 Message-ID: <20260603000656.3287796-1-adhemerval.zanella@linaro.org> X-Mailer: git-send-email 2.43.0 MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit X-Spam-Status: No, score=-6.2 required=5.0 tests=BAYES_00, DKIM_SIGNED, DKIM_VALID, DKIM_VALID_AU, DKIM_VALID_EF, RCVD_IN_DNSWL_BLOCKED, SPF_HELO_NONE, SPF_PASS, TXREP shortcircuit=no autolearn=ham autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on sourceware.org X-BeenThere: libc-alpha@sourceware.org X-Mailman-Version: 2.1.30 Precedence: list List-Id: Libc-alpha mailing list <libc-alpha.sourceware.org> List-Unsubscribe: <https://sourceware.org/mailman/options/libc-alpha>, <mailto:libc-alpha-request@sourceware.org?subject=unsubscribe> List-Archive: <https://sourceware.org/pipermail/libc-alpha/> List-Post: <mailto:libc-alpha@sourceware.org> List-Help: <mailto:libc-alpha-request@sourceware.org?subject=help> List-Subscribe: <https://sourceware.org/mailman/listinfo/libc-alpha>, <mailto:libc-alpha-request@sourceware.org?subject=subscribe> Errors-To: libc-alpha-bounces~patchwork=sourceware.org@sourceware.org |
| Series |
Pointer guard hardening and consolidation
|
|
Message
Adhemerval Zanella Netto
June 3, 2026, 12:04 a.m. UTC
This series hardens the pointer guard (and, to a lesser extent, the stack
canary) and consolidates the current fragmented implementation. Today the
pointer guard support is scattered across many per-architecture headers,
the assembly and C manglers do not agree, several architectures keep the
guard in the writable thread control block, and the dynamic loader uses a
no-op mangler on some targets. The following table have summary:
PTR_MANGLE (loader) PTR_MANGLE (libc) MANGLE / DEMANGLE
aarch64 __pointer_chk_guard_local __pointer_chk_guard val ^ pointer_guard
alpha __pointer_chk_guard_local __pointer_chk_guard val ^ pointer_guard
arc noop noop noop
arm noop noop noop
csky __pointer_chk_guard_local __pointer_chk_guard val ^ pointer_guard
hppa noop noop noop
i386 noop tcbhead_t->pointer_guard stdc_rotate_left (val ^ pointer_guard, 9)
loongarch __pointer_chk_guard_local __pointer_chk_guard val ^ pointer_guard
m68k noop noop noop
microblaze noop noop noop
mips noop noop noop
or1k noop noop noop
powerpc noop tcbhead_t->pointer_guard val ^ tcbhead_t->pointer_guard
riscv noop noop noop
s390 noop tcbhead_t->pointer_guard val ^ tcbhead_t->pointer_guard
sh noop tcbhead_t->pointer_guard val ^ tcbhead_t->pointer_guard
sparc noop tcbhead_t->pointer_guard val ^ tcbhead_t->pointer_guard
x86_64 __pointer_chk_guard_local tcbhead_t->pointer_guard stdc_rotate_left (val ^ pointer_guard, 17)
Along the way two latent defects are fixed: a crash with static
dlopen (BZ #34196) and an information leak that lets the guards be
recovered from AT_RANDOM (BZ #34197).
The high-level goals are:
* Keep the pointer guard in a read-only-after-relocation (relro) process
variable instead of the writable TCB field, so it cannot be overwritten
by a stray write into thread-local storage.
* Actually mangle pointers in the dynamic loader on every target, rather
than leaving a no-op on some (it still depends whether setjmp does
mangle the pointer).
* Make the assembly PTR_MANGLE/PTR_DEMANGLE match the generic C
implementation (exclusive-or with the guard followed by a rotate), so
the two domains agree and the mangling is identical everywhere.
* Collapse the duplicated per-architecture C and assembly headers into the
generic ones, keeping only the genuinely arch-specific assembly bits.
* Stop leaking the guard material: scrub the AT_RANDOM bytes after the
guards are derived from them, and refill them with fresh, unrelated
entropy so getauxval (AT_RANDOM) keeps returning random bytes.
Testing: built with build-many-glibcs for all supported ABIs and ran the
test suite under emulation for x86_64, i686, aarch64, arm, powerpc64
(LE/BE), powerpc, s390x, sh4, sparc64, loongarch64, and alpha, plus the
Hurd (i686-gnu) build.
Adhemerval Zanella (8):
elf: Propagate the pointer guard to ld.so loaded via static dlopen (BZ
34196)
Consolidate pointer guard to use a relro variable instead of the TCB
Enable the pointer guard in the dynamic loader
Split pointer_guard.h into C and assembly headers
Consolidate the C pointer guard implementation into the generic header
Add the pointer guard rotate to the assembly implementations
Consolidate dl-osinfo.h into the generic implementation
elf: Scrub and reseed the AT_RANDOM bytes after deriving the guards
(BZ 34197)
csu/libc-start.c | 4 +
elf/Makefile | 11 +++
elf/rtld.c | 6 +-
elf/rtld_static_init.c | 12 +++
elf/tst-atrandom-scrub-static.c | 1 +
elf/tst-atrandom-scrub.c | 74 ++++++++++++++++
elf/tst-ptrguard-static-dlopen-mod.c | 29 +++++++
elf/tst-ptrguard-static-dlopen.c | 51 +++++++++++
.../tst-ptrguard-static-dlopen.script | 1 +
sysdeps/alpha/__longjmp.S | 6 +-
sysdeps/alpha/setjmp.S | 8 +-
sysdeps/arm/pointer_guard-asm.h | 46 ++++++++++
sysdeps/arm/pointer_guard.h | 67 ---------------
sysdeps/generic/dl-osinfo.h | 1 +
sysdeps/generic/dl-reseed-random.h | 34 ++++++++
sysdeps/generic/pointer_guard-asm.h | 19 +++++
sysdeps/generic/pointer_guard.h | 32 +++++--
sysdeps/i386/htl/tcb-offsets.sym | 1 -
sysdeps/i386/nptl/tcb-offsets.sym | 1 -
sysdeps/i386/nptl/tls.h | 10 +--
sysdeps/i386/pointer_guard-asm.h | 51 +++++++++++
sysdeps/i386/stackguard-macros.h | 10 ++-
sysdeps/mach/hurd/i386/tls.h | 9 +-
sysdeps/mach/hurd/x86_64/tls.h | 8 +-
sysdeps/powerpc/nptl/tcb-offsets.sym | 1 -
sysdeps/powerpc/nptl/tls.h | 16 +---
sysdeps/powerpc/powerpc32/stackguard-macros.h | 16 ++--
sysdeps/powerpc/powerpc64/stackguard-macros.h | 16 ++--
sysdeps/s390/__longjmp.c | 9 +-
sysdeps/s390/nptl/tls.h | 7 --
sysdeps/s390/stackguard-macros.h | 20 ++---
sysdeps/sh/nptl/tcb-offsets.sym | 1 -
sysdeps/sh/nptl/tls.h | 15 +---
sysdeps/sh/stackguard-macros.h | 8 +-
sysdeps/sparc/nptl/tcb-offsets.sym | 1 -
sysdeps/sparc/nptl/tls.h | 10 +--
sysdeps/sparc/sparc32/__longjmp.S | 10 +--
sysdeps/sparc/sparc32/setjmp.S | 6 +-
sysdeps/sparc/sparc32/stackguard-macros.h | 9 +-
sysdeps/sparc/sparc64/stackguard-macros.h | 9 +-
.../sysv/linux/aarch64/pointer_guard-asm.h | 45 ++++++++++
.../unix/sysv/linux/aarch64/pointer_guard.h | 55 ------------
.../unix/sysv/linux/alpha/____longjmp_chk.S | 6 +-
.../unix/sysv/linux/alpha/pointer_guard-asm.h | 52 ++++++++++++
sysdeps/unix/sysv/linux/alpha/pointer_guard.h | 62 --------------
.../unix/sysv/linux/csky/pointer_guard-asm.h | 57 +++++++++++++
sysdeps/unix/sysv/linux/csky/pointer_guard.h | 68 ---------------
sysdeps/unix/sysv/linux/dl-osinfo.h | 54 ------------
sysdeps/unix/sysv/linux/dl-parse_auxv.h | 1 +
sysdeps/unix/sysv/linux/dl-reseed-random.h | 43 ++++++++++
sysdeps/unix/sysv/linux/i386/pointer_guard.h | 55 ------------
.../sysv/linux/loongarch/pointer_guard-asm.h | 47 ++++++++++
.../unix/sysv/linux/loongarch/pointer_guard.h | 70 ---------------
.../sysv/linux/powerpc/pointer_guard-asm.h | 85 +++++++++++++++++++
.../unix/sysv/linux/powerpc/pointer_guard.h | 55 ------------
.../unix/sysv/linux/s390/____longjmp_chk.c | 4 +-
.../unix/sysv/linux/s390/pointer_guard-asm.h | 49 +++++++++++
sysdeps/unix/sysv/linux/s390/pointer_guard.h | 47 ----------
.../unix/sysv/linux/sh/pointer_guard-asm.h | 70 +++++++++++++++
sysdeps/unix/sysv/linux/sh/pointer_guard.h | 43 ----------
.../linux/sparc/sparc32/____longjmp_chk.S | 6 +-
.../linux/sparc/sparc32/pointer_guard-asm.h | 60 +++++++++++++
.../sysv/linux/sparc/sparc32/pointer_guard.h | 44 ----------
.../linux/sparc/sparc64/pointer_guard-asm.h | 60 +++++++++++++
.../sysv/linux/sparc/sparc64/pointer_guard.h | 44 ----------
.../unix/sysv/linux/x86_64/pointer_guard.h | 78 -----------------
sysdeps/x86_64/htl/tcb-offsets.sym | 1 -
sysdeps/x86_64/nptl/tcb-offsets.sym | 1 -
sysdeps/x86_64/nptl/tls.h | 10 +--
sysdeps/x86_64/pointer_guard-asm.h | 42 +++++++++
sysdeps/x86_64/stackguard-macros.h | 10 ++-
71 files changed, 1069 insertions(+), 901 deletions(-)
create mode 100644 elf/tst-atrandom-scrub-static.c
create mode 100644 elf/tst-atrandom-scrub.c
create mode 100644 elf/tst-ptrguard-static-dlopen-mod.c
create mode 100644 elf/tst-ptrguard-static-dlopen.c
create mode 100644 elf/tst-ptrguard-static-dlopen.root/tst-ptrguard-static-dlopen.script
create mode 100644 sysdeps/arm/pointer_guard-asm.h
delete mode 100644 sysdeps/arm/pointer_guard.h
create mode 100644 sysdeps/generic/dl-reseed-random.h
create mode 100644 sysdeps/generic/pointer_guard-asm.h
create mode 100644 sysdeps/i386/pointer_guard-asm.h
create mode 100644 sysdeps/unix/sysv/linux/aarch64/pointer_guard-asm.h
delete mode 100644 sysdeps/unix/sysv/linux/aarch64/pointer_guard.h
create mode 100644 sysdeps/unix/sysv/linux/alpha/pointer_guard-asm.h
delete mode 100644 sysdeps/unix/sysv/linux/alpha/pointer_guard.h
create mode 100644 sysdeps/unix/sysv/linux/csky/pointer_guard-asm.h
delete mode 100644 sysdeps/unix/sysv/linux/csky/pointer_guard.h
delete mode 100644 sysdeps/unix/sysv/linux/dl-osinfo.h
create mode 100644 sysdeps/unix/sysv/linux/dl-reseed-random.h
delete mode 100644 sysdeps/unix/sysv/linux/i386/pointer_guard.h
create mode 100644 sysdeps/unix/sysv/linux/loongarch/pointer_guard-asm.h
delete mode 100644 sysdeps/unix/sysv/linux/loongarch/pointer_guard.h
create mode 100644 sysdeps/unix/sysv/linux/powerpc/pointer_guard-asm.h
delete mode 100644 sysdeps/unix/sysv/linux/powerpc/pointer_guard.h
create mode 100644 sysdeps/unix/sysv/linux/s390/pointer_guard-asm.h
delete mode 100644 sysdeps/unix/sysv/linux/s390/pointer_guard.h
create mode 100644 sysdeps/unix/sysv/linux/sh/pointer_guard-asm.h
delete mode 100644 sysdeps/unix/sysv/linux/sh/pointer_guard.h
create mode 100644 sysdeps/unix/sysv/linux/sparc/sparc32/pointer_guard-asm.h
delete mode 100644 sysdeps/unix/sysv/linux/sparc/sparc32/pointer_guard.h
create mode 100644 sysdeps/unix/sysv/linux/sparc/sparc64/pointer_guard-asm.h
delete mode 100644 sysdeps/unix/sysv/linux/sparc/sparc64/pointer_guard.h
delete mode 100644 sysdeps/unix/sysv/linux/x86_64/pointer_guard.h
create mode 100644 sysdeps/x86_64/pointer_guard-asm.h