| Message ID | 20260628070241.88310-1-jesse.huang@sifive.com (mailing list archive) |
|---|---|
| Headers |
Return-Path: <libc-alpha-bounces~patchwork=sourceware.org@sourceware.org> X-Original-To: patchwork@sourceware.org Delivered-To: patchwork@sourceware.org Received: from vm01.sourceware.org (localhost [IPv6:::1]) by sourceware.org (Postfix) with ESMTP id 3BD5E4BA23C2 for <patchwork@sourceware.org>; Sun, 28 Jun 2026 07:04:07 +0000 (GMT) DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org 3BD5E4BA23C2 Authentication-Results: sourceware.org; dkim=pass (2048-bit key, unprotected) header.d=sifive.com header.i=@sifive.com header.a=rsa-sha256 header.s=google header.b=YjzRi1SM X-Original-To: libc-alpha@sourceware.org Delivered-To: libc-alpha@sourceware.org Received: from mail-dy1-x1332.google.com (mail-dy1-x1332.google.com [IPv6:2607:f8b0:4864:20::1332]) by sourceware.org (Postfix) with ESMTPS id 0F7624BA2E24 for <libc-alpha@sourceware.org>; Sun, 28 Jun 2026 07:02:49 +0000 (GMT) DMARC-Filter: OpenDMARC Filter v1.4.2 sourceware.org 0F7624BA2E24 Authentication-Results: sourceware.org; dmarc=pass (p=reject dis=none) header.from=sifive.com Authentication-Results: sourceware.org; spf=pass smtp.mailfrom=sifive.com ARC-Filter: OpenARC Filter v1.0.0 sourceware.org 0F7624BA2E24 Authentication-Results: sourceware.org; arc=none smtp.remote-ip=2607:f8b0:4864:20::1332 ARC-Seal: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1782630169; cv=none; b=pnkxkX1Uwzs+kHAJvglNmSIMdq3UkYKtIS9RK/Ezu4U5DNhh8Rw/iQCWuSpKe9j3spXjYOuigXoMdrj84+52FzPSVPRBotUk7Gy6g0FTPC42m6yQ+hTrNP35K6WyyZ245hQAG7hB8EFXAtPNAJhA1fKWU/2nxrpplQpbwDs25R8= ARC-Message-Signature: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1782630169; c=relaxed/simple; bh=I9T9gDqi9LaiCYV3QGKmvktyv4JYJyb0+vlWZX9fjXM=; h=DKIM-Signature:From:To:Subject:Date:Message-Id:MIME-Version; b=bE08cjEtWKHdYWc0mMgvqmPMYxfZgdWImX3T0k9xX3dEDNgkI6jZ6HNN97Z5hDTsXzWtKeER47jPKM1HH69sPHJEXLGw01Kt10ybmp268JJ4SG0sIItKuCp5ZMAUBkZD1eWTQSGiuSoBYxSJFaHfWMt4uK04mkGOrUNW7afboCY= ARC-Authentication-Results: i=1; sourceware.org; dkim=pass (2048-bit key, unprotected) header.d=sifive.com header.i=@sifive.com header.a=rsa-sha256 header.s=google header.b=YjzRi1SM DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org 0F7624BA2E24 Received: by mail-dy1-x1332.google.com with SMTP id 5a478bee46e88-30e9eefa268so1522949eec.1 for <libc-alpha@sourceware.org>; Sun, 28 Jun 2026 00:02:48 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=sifive.com; s=google; t=1782630168; x=1783234968; darn=sourceware.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to; bh=Lx7p+tH1q4HcWhaFCSAUjsKEHgdr6FN9Umio+R86IIM=; b=YjzRi1SMQ782SN5q7p+VcYs1Y6b0jKHeJhU7OGaVZ0lo5y7Z/A2BPZlEd/3Fti8ehe 1FqRvr2i3aSpZaEkIlV+JVNbnp3X8hmFTb9XMnx9Uz4s4Ye0BdQ8OEdG14aJlonAS05I c9a1rBVYy9gAf2S5J0IidFmVkPwp0akHGi5xXHugAk6dRMOF95sgjrV+r39SrIvQ+36z mFIrK4hEBYgB8oSqO6s78DgpuTSZ+d+y64n608jxyRXc3SW5Wg4CvjUqT0KbxFlPgfWv 5gXh5rVWSVozO6Bs/KaiYo9l9uuB8d8AYpEGmhM1JhjV9T/bQOKYQ0bC2UzAzct3DX0H R5DA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1782630168; x=1783234968; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to; bh=Lx7p+tH1q4HcWhaFCSAUjsKEHgdr6FN9Umio+R86IIM=; b=FV1Y4bgkbz2Do2U6B0QT9RltVN1OSUA6qeR0LwSiG7g3Q+fBJX95aoLJxQgLMhpuEV z6tLwmQCR3URTOfKXRFZMwUvLZ4XQSIiCJ7z+r58nIj12n5Pmq+YMGlx+b+bIJNNxMN2 fLncMuE5hFAt9/+DxrAzuD9LmYDn0o9UdDo7PoKgB9cHlgqd/HMQiQ9+lfFitrPDcPWZ 7dHqtWK96hmvUjrqh7Y8scPRx7of4zAE99R/KRn8pHuzRPV92vg2Bdv/QzpXCARDPgR7 NJbraVcZRSNbshv2sOb/ktbiF4EViA2XJgvBkwbDXBAiufiBgntnBbvCrRca3Zl+PzEu FvJQ== X-Gm-Message-State: AOJu0Yyubu9YJKI0G1xyBtW+5rCzFy2Ww7JpaqxHeEoAZVB1xEhlz+Yy yGZoYIFU7t1KWQCql68WsdVQS3Lsv3ZM6eae7kyNEgsHLaW7rowFXQEFF6rxxNBt9bqkMgcu+oq bU9fYfpUf7Fpp+0+axK0uCsqaVo5/CH5jwOnsSf7zBlDqdolnQV4jIxg5Alh1PyhcohcKt7FAxT YnNaBFAWv+bLw/0u8F4FK0XO0DkjBvl3wBftvf3/ODgI4+ME+v X-Gm-Gg: AfdE7cnabdy9QmVvdrdLMwpTnA8Z5ACio+d8EYBICAeztgBXYGZ2uJHqO2zvjqpymZ9 D+G2rTC0ZPL70K4qJm9cRjDhGgDNPkbUea8xRDBVxOntX3w+PeNoICqDDxxV6Y4Mt+byuD73YZC 45A9ds1IO/ja+QF2JsZML+4mxnOf/LzR6U0lQ647TLWn4oEdvXv2NO5VrXtpI41WHf8UeIlJOfX JSdFmgXfqotMIVs+9bicE5E/ZkxgDQ6rgOSw8vCX0NzOKfWCQ+Fn0lupiYm+jQHBH2I8lmVIYLn rklnZkSCU+9xwwqpu8IJYg991NM9hPdiPJjgtolzHHyXAnwspDHU842Q0IZrPfiqGBvVT8QF7hb qCpkx/4fJIJVM5nolDWgx53CKpdKzIU4JFX0KtDvrvTFnmcu5QSjAAE/kaPsjl7QRtilIlSzQeo 7jZgB5zp3rtgNSGcW+tAa9/w6cuIV16A== X-Received: by 2002:a05:7300:2316:b0:30c:a4d8:4e77 with SMTP id 5a478bee46e88-30ca4d8518emr6993254eec.13.1782630167529; Sun, 28 Jun 2026 00:02:47 -0700 (PDT) Received: from sw08.internal.sifive.com ([4.53.31.132]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-30c7c8afc91sm35435166eec.14.2026.06.28.00.02.46 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 28 Jun 2026 00:02:46 -0700 (PDT) From: Jesse Huang <jesse.huang@sifive.com> To: libc-alpha@sourceware.org Cc: andrew@sifive.com, darius@bluespec.com, debug@rivosinc.com, jeffreyalaw@gmail.com, kito.cheng@sifive.com, palmer@dabbelt.com, schwab@suse.de, Jesse Huang <jesse.huang@sifive.com> Subject: [PATCH v5 00/16] Support RISC-V Control Flow Integrifty (CFI) Date: Sun, 28 Jun 2026 00:02:25 -0700 Message-Id: <20260628070241.88310-1-jesse.huang@sifive.com> X-Mailer: git-send-email 2.39.3 MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Spam-Status: No, score=-6.7 required=5.0 tests=BAYES_00, DKIM_SIGNED, DKIM_VALID, DKIM_VALID_AU, DKIM_VALID_EF, KAM_ASCII_DIVIDERS, RCVD_IN_DNSWL_NONE, SPF_HELO_NONE, SPF_PASS, TXREP shortcircuit=no autolearn=no autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on sourceware.org X-BeenThere: libc-alpha@sourceware.org X-Mailman-Version: 2.1.30 Precedence: list List-Id: Libc-alpha mailing list <libc-alpha.sourceware.org> List-Unsubscribe: <https://sourceware.org/mailman/options/libc-alpha>, <mailto:libc-alpha-request@sourceware.org?subject=unsubscribe> List-Archive: <https://sourceware.org/pipermail/libc-alpha/> List-Post: <mailto:libc-alpha@sourceware.org> List-Help: <mailto:libc-alpha-request@sourceware.org?subject=help> List-Subscribe: <https://sourceware.org/mailman/listinfo/libc-alpha>, <mailto:libc-alpha-request@sourceware.org?subject=subscribe> Errors-To: libc-alpha-bounces~patchwork=sourceware.org@sourceware.org |
| Series |
Support RISC-V Control Flow Integrifty (CFI)
|
|
Message
Jesse Huang
June 28, 2026, 7:02 a.m. UTC
This patch series adds support for the new RISC-V Control Flow Integrity (CFI)
extensions, i.e. Zicfilp and Zicfiss, as described in the following sections
of the RISC-V Instruction Set Manual:
- Volume I, Chapter 33
- Volume II, Chapter 22
Our implementation largely refers to the existing x86 CET code, and we would
like to thank the developers for their work.
Summary of Changes
------------------
1) New Option for the Build System
A new '--enable-cfi' configure option is introduced to control whether
CFI-related features are enabled. It appends the '-fcf-protection=full'
compiler flag to all source files.
2) Adjustment to Assembly Code
While compiler automatically do the job for C source files, assembly files
and routines are requiring manual modifications
- Insert GNU property notes and landing pad, label setting instructions
into assembly files and routines
- Replace indirect branches with software-guarded branches where applicable
- Extend setjmp/longjmp to support for the shadow stack by storing the
shadow stack pointer (SSP) to a new union __ssp_sigset_arch_t, that wraps
the original sigset_t and a new __ssp_sigset_t that shrinks the mask size
to make spaces for storing SSP and SSP base, and handling the
save/restore/unwinding logic
3) Parse GNU Property Notes and Setup the Environment
The loader scans the GNU_PROPERTY_RISCV_FEATURE_1_AND note and parses the
bits specified by the binary to determine the required CFI features, it
then performs checks on all dependencies, and uses new prctl operations
to call to the kernel to do the setup work.
4) Add Tunables for Overriding Runtime Behavior
Two new tunables are introduced:
- glibc.cpu.riscv_cfi_lp
- glibc.cpu.riscv_cfi_ss
These control landing pad and shadow stack behavior at runtime,
respectively. Each accepts 'on|permissive|off' for its value, which is
same as x86.
5. Store shadow stack information in TLS to support ucontext
We make the following structure changes to support the ucontext library
- A new helper function `__allocate_shadow_stack` to map a new shadow stack
Shadow stack size for the new context is based on an estimation from the
runtime stack size, which is same to the implementation of x86.
- Store ssp and shadow stack base marker in TLS
- Change the type of uc_sigmask in ucontext_t to __ssp_sigset_arch_t, in that
we can make use of the space for storing ssp and shadow stack base
that is also used by jmp_buf
Changes from V1
--------------------
- The new option '--enable-cfi' gets a descrition in install.texi and
an entry in NEWS
- Update prctl numbers of landing pad
- Re-implement ucontext using shadow stack restore token techniques
- Change makecontext to use the `map_shadow_stack` syscall
Changes from V2
--------------------
- Use indirect jump instead of return in __longjmp if CFI is enabled
- Add __INDIRECT_RETURN attribute to swapcontext, which instructs the
compiler to insert a LPAD after the function callsite, so that we can
use CFI-guarded indirect jump for context swtiching. Compiler would
need to be updated to support this attribute for it to work
- Remove SSP from jmp_buf, stored it into a new union __ssp_sigset_arch_t
that holds a original sigset_t and the shrinked sigset_t with ssp and
ssp_base, so that we won't affect the size of jmp_buf or sigset_t
- SSP field in ucontext_t is also moved into the uc_sigmask that is of
type __ssp_sigset_arch_t
Changes from V3
--------------------
- Fixed the offset used for accessing ssp in TLS that was incorrect
- Make setjmp/longjmp capable of handling inter-ucontext jumps
- Switch to the new prctl option numbers that was introduced in Linux
7.0
Changes from V4
--------------------
- Fixed several typos and commit messages that does not reflect the
newest version of the patch
- The patch for updating prctl option numbers is squashed
- ENTRY() and LEAF() macros now inserts LPAD so no longer need to
manually modify the assembly functions defined with these macros and
their derivatives
Jesse Huang (16):
riscv: Add --enable-cfi option for controlling CFI features
riscv/cfi: Set up necessary options for --enable-cfi
riscv: Add GNU property definitions for RISC-V CFI
riscv: Adjust assembly routines to support landing pad
riscv: Introduce feature variables for RISC-V GNU properties
riscv/cfi: Add prctl definitions for RISC-V CFI
riscv/cfi: Enable CFI on static binaries
riscv/cfi: Enable CFI on dynamic binaries
riscv/cfi: Introduce tunables for CFI features
riscv/cfi: Adjust setjmp/longjmp for shadow stack to work
riscv/cfi: Support locking/disabling CFI and move OS dependent code
riscv/cfi: Store shadow stack information in TLS
riscv/cfi: Add internal sigset_t union and use it for both
ucontext/jmpbuf
riscv/cfi: Add __allocate_shadow_stack for mapping new shadow stack
riscv/cfi: Support ucontext under CFI
riscv/cfi: Add __INDIRECT_RETURN attribute to swapcontext
INSTALL | 13 +
NEWS | 3 +
configure | 12 +
configure.ac | 6 +
elf/elf.h | 5 +
manual/install.texi | 12 +
manual/tunables.texi | 22 ++
sysdeps/riscv/Makefile | 17 +-
sysdeps/riscv/__longjmp.S | 54 +++
sysdeps/riscv/bits/indirect-return.h | 36 ++
sysdeps/riscv/cpu-features.c | 46 +++
sysdeps/riscv/cpu-tunables.c | 50 +++
sysdeps/riscv/crti.S | 4 +
sysdeps/riscv/crtn.S | 4 +
sysdeps/riscv/dl-cfi.c | 317 ++++++++++++++++++
sysdeps/riscv/dl-get-cpu-features.c | 27 ++
sysdeps/riscv/dl-machine.h | 35 ++
sysdeps/riscv/dl-procruntime.c | 77 +++++
sysdeps/riscv/dl-prop.h | 74 ++++
sysdeps/riscv/dl-trampoline.S | 41 +--
sysdeps/riscv/dl-tunables.list | 27 ++
sysdeps/riscv/feature-control.h | 42 +++
sysdeps/riscv/features-offsets.sym | 5 +
sysdeps/riscv/ldsodefs.h | 1 +
sysdeps/riscv/libc-start.c | 31 ++
sysdeps/riscv/libc-start.h | 95 ++++++
sysdeps/riscv/link_map.h | 22 ++
sysdeps/riscv/nptl/Makefile | 1 +
sysdeps/riscv/nptl/tcb-offsets.sym | 5 +
sysdeps/riscv/nptl/tls.h | 2 +
sysdeps/riscv/preconfigure | 2 +
sysdeps/riscv/preconfigure.ac | 1 +
sysdeps/riscv/setjmp.S | 22 ++
sysdeps/riscv/start.S | 9 +
sysdeps/riscv/sys/asm.h | 12 +-
sysdeps/unix/sysv/linux/riscv/Makefile | 1 +
.../sysv/linux/riscv/allocate-shadow-stack.c | 59 ++++
.../sysv/linux/riscv/allocate-shadow-stack.h | 31 ++
sysdeps/unix/sysv/linux/riscv/bits/mman.h | 30 ++
.../sysv/linux/riscv/bits/types/__sigset_t.h | 43 +++
sysdeps/unix/sysv/linux/riscv/clone.S | 1 +
sysdeps/unix/sysv/linux/riscv/dl-cfi.h | 116 +++++++
sysdeps/unix/sysv/linux/riscv/getcontext.S | 20 ++
.../unix/sysv/linux/riscv/include/asm/prctl.h | 43 +++
sysdeps/unix/sysv/linux/riscv/jmp_buf-ssp.sym | 7 +
sysdeps/unix/sysv/linux/riscv/makecontext.c | 19 ++
sysdeps/unix/sysv/linux/riscv/setcontext.S | 67 ++++
sysdeps/unix/sysv/linux/riscv/setjmpP.h | 49 +++
sysdeps/unix/sysv/linux/riscv/swapcontext.S | 81 ++++-
sysdeps/unix/sysv/linux/riscv/sys/ucontext.h | 14 +-
sysdeps/unix/sysv/linux/riscv/sysdep.h | 71 ++++
sysdeps/unix/sysv/linux/riscv/ucontext_i.sym | 4 +-
52 files changed, 1763 insertions(+), 25 deletions(-)
create mode 100644 sysdeps/riscv/bits/indirect-return.h
create mode 100644 sysdeps/riscv/cpu-features.c
create mode 100644 sysdeps/riscv/cpu-tunables.c
create mode 100644 sysdeps/riscv/crti.S
create mode 100644 sysdeps/riscv/crtn.S
create mode 100644 sysdeps/riscv/dl-cfi.c
create mode 100644 sysdeps/riscv/dl-get-cpu-features.c
create mode 100644 sysdeps/riscv/dl-procruntime.c
create mode 100644 sysdeps/riscv/dl-prop.h
create mode 100644 sysdeps/riscv/dl-tunables.list
create mode 100644 sysdeps/riscv/feature-control.h
create mode 100644 sysdeps/riscv/features-offsets.sym
create mode 100644 sysdeps/riscv/libc-start.c
create mode 100644 sysdeps/riscv/libc-start.h
create mode 100644 sysdeps/riscv/link_map.h
create mode 100644 sysdeps/riscv/nptl/Makefile
create mode 100644 sysdeps/riscv/nptl/tcb-offsets.sym
create mode 100644 sysdeps/unix/sysv/linux/riscv/allocate-shadow-stack.c
create mode 100644 sysdeps/unix/sysv/linux/riscv/allocate-shadow-stack.h
create mode 100644 sysdeps/unix/sysv/linux/riscv/bits/mman.h
create mode 100644 sysdeps/unix/sysv/linux/riscv/bits/types/__sigset_t.h
create mode 100644 sysdeps/unix/sysv/linux/riscv/dl-cfi.h
create mode 100644 sysdeps/unix/sysv/linux/riscv/include/asm/prctl.h
create mode 100644 sysdeps/unix/sysv/linux/riscv/jmp_buf-ssp.sym
create mode 100644 sysdeps/unix/sysv/linux/riscv/setjmpP.h
Comments
On Jun 28 2026, Jesse Huang wrote: > This patch series adds support for the new RISC-V Control Flow Integrity (CFI) > extensions, i.e. Zicfilp and Zicfiss, as described in the following sections > of the RISC-V Instruction Set Manual: > > - Volume I, Chapter 33 > - Volume II, Chapter 22 Do I understand corectly that this is incompatible with implementations lacking the Zimop/Zcmop extensions?
* Andreas Schwab: > On Jun 28 2026, Jesse Huang wrote: > >> This patch series adds support for the new RISC-V Control Flow Integrity (CFI) >> extensions, i.e. Zicfilp and Zicfiss, as described in the following sections >> of the RISC-V Instruction Set Manual: >> >> - Volume I, Chapter 33 >> - Volume II, Chapter 22 > > Do I understand corectly that this is incompatible with implementations > lacking the Zimop/Zcmop extensions? Yes, I believe that's accurate. It's not possible to maintain compatibility with the baseline with this approach. Thanks, Florian
On Mon, Jun 29, 2026 at 6:08 PM Florian Weimer <fweimer@redhat.com> wrote: > > * Andreas Schwab: > > > On Jun 28 2026, Jesse Huang wrote: > > > >> This patch series adds support for the new RISC-V Control Flow Integrity (CFI) > >> extensions, i.e. Zicfilp and Zicfiss, as described in the following sections > >> of the RISC-V Instruction Set Manual: > >> > >> - Volume I, Chapter 33 > >> - Volume II, Chapter 22 > > > > Do I understand corectly that this is incompatible with implementations > > lacking the Zimop/Zcmop extensions? > > Yes, I believe that's accurate. It's not possible to maintain > compatibility with the baseline with this approach. > > Thanks, > Florian > Regarding the extensions, Zicfilp uses the existing auipc space to encode lpad, so it actually compatible with cores that lacking support of Zimop and Zcmop. However, from a security standpoint I don't think it makes sense to enable only one of the two, so there is only a single --enable-cfi option that turns on both. Thanks, Jesse
Am Sonntag, 28. Juni 2026, 16:02:25 Japanische Normalzeit schrieb Jesse Huang: > This patch series adds support for the new RISC-V Control Flow Integrity (CFI) > extensions, i.e. Zicfilp and Zicfiss, as described in the following sections > of the RISC-V Instruction Set Manual: > > - Volume I, Chapter 33 > - Volume II, Chapter 22 > Let's figure this out after the release please. > > Our implementation largely refers to the existing x86 CET code, and we would > like to thank the developers for their work. > > Summary of Changes > ------------------ > > 1) New Option for the Build System > > A new '--enable-cfi' configure option is introduced to control whether > CFI-related features are enabled. It appends the '-fcf-protection=full' > compiler flag to all source files. > > 2) Adjustment to Assembly Code > > While compiler automatically do the job for C source files, assembly files > and routines are requiring manual modifications > - Insert GNU property notes and landing pad, label setting instructions > into assembly files and routines > - Replace indirect branches with software-guarded branches where applicable > - Extend setjmp/longjmp to support for the shadow stack by storing the > shadow stack pointer (SSP) to a new union __ssp_sigset_arch_t, that wraps > the original sigset_t and a new __ssp_sigset_t that shrinks the mask size > to make spaces for storing SSP and SSP base, and handling the > save/restore/unwinding logic > > 3) Parse GNU Property Notes and Setup the Environment > > The loader scans the GNU_PROPERTY_RISCV_FEATURE_1_AND note and parses the > bits specified by the binary to determine the required CFI features, it > then performs checks on all dependencies, and uses new prctl operations > to call to the kernel to do the setup work. > > 4) Add Tunables for Overriding Runtime Behavior > > Two new tunables are introduced: > - glibc.cpu.riscv_cfi_lp > - glibc.cpu.riscv_cfi_ss > > These control landing pad and shadow stack behavior at runtime, > respectively. Each accepts 'on|permissive|off' for its value, which is > same as x86. > > 5. Store shadow stack information in TLS to support ucontext > > We make the following structure changes to support the ucontext library > - A new helper function `__allocate_shadow_stack` to map a new shadow stack > Shadow stack size for the new context is based on an estimation from the > runtime stack size, which is same to the implementation of x86. > - Store ssp and shadow stack base marker in TLS > - Change the type of uc_sigmask in ucontext_t to __ssp_sigset_arch_t, in that > we can make use of the space for storing ssp and shadow stack base > that is also used by jmp_buf > > Changes from V1 > -------------------- > - The new option '--enable-cfi' gets a descrition in install.texi and > an entry in NEWS > - Update prctl numbers of landing pad > - Re-implement ucontext using shadow stack restore token techniques > - Change makecontext to use the `map_shadow_stack` syscall > > Changes from V2 > -------------------- > - Use indirect jump instead of return in __longjmp if CFI is enabled > - Add __INDIRECT_RETURN attribute to swapcontext, which instructs the > compiler to insert a LPAD after the function callsite, so that we can > use CFI-guarded indirect jump for context swtiching. Compiler would > need to be updated to support this attribute for it to work > - Remove SSP from jmp_buf, stored it into a new union __ssp_sigset_arch_t > that holds a original sigset_t and the shrinked sigset_t with ssp and > ssp_base, so that we won't affect the size of jmp_buf or sigset_t > - SSP field in ucontext_t is also moved into the uc_sigmask that is of > type __ssp_sigset_arch_t > > Changes from V3 > -------------------- > - Fixed the offset used for accessing ssp in TLS that was incorrect > - Make setjmp/longjmp capable of handling inter-ucontext jumps > - Switch to the new prctl option numbers that was introduced in Linux > 7.0 > > Changes from V4 > -------------------- > - Fixed several typos and commit messages that does not reflect the > newest version of the patch > - The patch for updating prctl option numbers is squashed > - ENTRY() and LEAF() macros now inserts LPAD so no longer need to > manually modify the assembly functions defined with these macros and > their derivatives > > Jesse Huang (16): > riscv: Add --enable-cfi option for controlling CFI features > riscv/cfi: Set up necessary options for --enable-cfi > riscv: Add GNU property definitions for RISC-V CFI > riscv: Adjust assembly routines to support landing pad > riscv: Introduce feature variables for RISC-V GNU properties > riscv/cfi: Add prctl definitions for RISC-V CFI > riscv/cfi: Enable CFI on static binaries > riscv/cfi: Enable CFI on dynamic binaries > riscv/cfi: Introduce tunables for CFI features > riscv/cfi: Adjust setjmp/longjmp for shadow stack to work > riscv/cfi: Support locking/disabling CFI and move OS dependent code > riscv/cfi: Store shadow stack information in TLS > riscv/cfi: Add internal sigset_t union and use it for both > ucontext/jmpbuf > riscv/cfi: Add __allocate_shadow_stack for mapping new shadow stack > riscv/cfi: Support ucontext under CFI > riscv/cfi: Add __INDIRECT_RETURN attribute to swapcontext > > INSTALL | 13 + > NEWS | 3 + > configure | 12 + > configure.ac | 6 + > elf/elf.h | 5 + > manual/install.texi | 12 + > manual/tunables.texi | 22 ++ > sysdeps/riscv/Makefile | 17 +- > sysdeps/riscv/__longjmp.S | 54 +++ > sysdeps/riscv/bits/indirect-return.h | 36 ++ > sysdeps/riscv/cpu-features.c | 46 +++ > sysdeps/riscv/cpu-tunables.c | 50 +++ > sysdeps/riscv/crti.S | 4 + > sysdeps/riscv/crtn.S | 4 + > sysdeps/riscv/dl-cfi.c | 317 ++++++++++++++++++ > sysdeps/riscv/dl-get-cpu-features.c | 27 ++ > sysdeps/riscv/dl-machine.h | 35 ++ > sysdeps/riscv/dl-procruntime.c | 77 +++++ > sysdeps/riscv/dl-prop.h | 74 ++++ > sysdeps/riscv/dl-trampoline.S | 41 +-- > sysdeps/riscv/dl-tunables.list | 27 ++ > sysdeps/riscv/feature-control.h | 42 +++ > sysdeps/riscv/features-offsets.sym | 5 + > sysdeps/riscv/ldsodefs.h | 1 + > sysdeps/riscv/libc-start.c | 31 ++ > sysdeps/riscv/libc-start.h | 95 ++++++ > sysdeps/riscv/link_map.h | 22 ++ > sysdeps/riscv/nptl/Makefile | 1 + > sysdeps/riscv/nptl/tcb-offsets.sym | 5 + > sysdeps/riscv/nptl/tls.h | 2 + > sysdeps/riscv/preconfigure | 2 + > sysdeps/riscv/preconfigure.ac | 1 + > sysdeps/riscv/setjmp.S | 22 ++ > sysdeps/riscv/start.S | 9 + > sysdeps/riscv/sys/asm.h | 12 +- > sysdeps/unix/sysv/linux/riscv/Makefile | 1 + > .../sysv/linux/riscv/allocate-shadow-stack.c | 59 ++++ > .../sysv/linux/riscv/allocate-shadow-stack.h | 31 ++ > sysdeps/unix/sysv/linux/riscv/bits/mman.h | 30 ++ > .../sysv/linux/riscv/bits/types/__sigset_t.h | 43 +++ > sysdeps/unix/sysv/linux/riscv/clone.S | 1 + > sysdeps/unix/sysv/linux/riscv/dl-cfi.h | 116 +++++++ > sysdeps/unix/sysv/linux/riscv/getcontext.S | 20 ++ > .../unix/sysv/linux/riscv/include/asm/prctl.h | 43 +++ > sysdeps/unix/sysv/linux/riscv/jmp_buf-ssp.sym | 7 + > sysdeps/unix/sysv/linux/riscv/makecontext.c | 19 ++ > sysdeps/unix/sysv/linux/riscv/setcontext.S | 67 ++++ > sysdeps/unix/sysv/linux/riscv/setjmpP.h | 49 +++ > sysdeps/unix/sysv/linux/riscv/swapcontext.S | 81 ++++- > sysdeps/unix/sysv/linux/riscv/sys/ucontext.h | 14 +- > sysdeps/unix/sysv/linux/riscv/sysdep.h | 71 ++++ > sysdeps/unix/sysv/linux/riscv/ucontext_i.sym | 4 +- > 52 files changed, 1763 insertions(+), 25 deletions(-) > create mode 100644 sysdeps/riscv/bits/indirect-return.h > create mode 100644 sysdeps/riscv/cpu-features.c > create mode 100644 sysdeps/riscv/cpu-tunables.c > create mode 100644 sysdeps/riscv/crti.S > create mode 100644 sysdeps/riscv/crtn.S > create mode 100644 sysdeps/riscv/dl-cfi.c > create mode 100644 sysdeps/riscv/dl-get-cpu-features.c > create mode 100644 sysdeps/riscv/dl-procruntime.c > create mode 100644 sysdeps/riscv/dl-prop.h > create mode 100644 sysdeps/riscv/dl-tunables.list > create mode 100644 sysdeps/riscv/feature-control.h > create mode 100644 sysdeps/riscv/features-offsets.sym > create mode 100644 sysdeps/riscv/libc-start.c > create mode 100644 sysdeps/riscv/libc-start.h > create mode 100644 sysdeps/riscv/link_map.h > create mode 100644 sysdeps/riscv/nptl/Makefile > create mode 100644 sysdeps/riscv/nptl/tcb-offsets.sym > create mode 100644 sysdeps/unix/sysv/linux/riscv/allocate-shadow-stack.c > create mode 100644 sysdeps/unix/sysv/linux/riscv/allocate-shadow-stack.h > create mode 100644 sysdeps/unix/sysv/linux/riscv/bits/mman.h > create mode 100644 sysdeps/unix/sysv/linux/riscv/bits/types/__sigset_t.h > create mode 100644 sysdeps/unix/sysv/linux/riscv/dl-cfi.h > create mode 100644 sysdeps/unix/sysv/linux/riscv/include/asm/prctl.h > create mode 100644 sysdeps/unix/sysv/linux/riscv/jmp_buf-ssp.sym > create mode 100644 sysdeps/unix/sysv/linux/riscv/setjmpP.h > >
On 6/30/2026 7:15 AM, Andreas K. Huettel wrote: > Am Sonntag, 28. Juni 2026, 16:02:25 Japanische Normalzeit schrieb Jesse Huang: >> This patch series adds support for the new RISC-V Control Flow Integrity (CFI) >> extensions, i.e. Zicfilp and Zicfiss, as described in the following sections >> of the RISC-V Instruction Set Manual: >> >> - Volume I, Chapter 33 >> - Volume II, Chapter 22 >> > Let's figure this out after the release please. We kicked this around a bit at the gcc patchwork meeting. WIthin that group (included Peter B, Robin and myself) we agreed this can be reasonably deferred. Seems like it's just landing fairly late in the cycle with some concerns... So, yea, let's figure this out after the release. Jeff