From patchwork Tue May 26 06:16:47 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Jesse Huang X-Patchwork-Id: 135655 Return-Path: X-Original-To: patchwork@sourceware.org Delivered-To: patchwork@sourceware.org Received: from vm01.sourceware.org (localhost [IPv6:::1]) by sourceware.org (Postfix) with ESMTP id BCE064BA7999 for ; Tue, 26 May 2026 06:19:35 +0000 (GMT) DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org BCE064BA7999 Authentication-Results: sourceware.org; dkim=pass (2048-bit key, unprotected) header.d=sifive.com header.i=@sifive.com header.a=rsa-sha256 header.s=google header.b=VzfaN0MC X-Original-To: libc-alpha@sourceware.org Delivered-To: libc-alpha@sourceware.org Received: from mail-dy1-x1335.google.com (mail-dy1-x1335.google.com [IPv6:2607:f8b0:4864:20::1335]) by sourceware.org (Postfix) with ESMTPS id CB0A94BA23DD for ; Tue, 26 May 2026 06:17:55 +0000 (GMT) DMARC-Filter: OpenDMARC Filter v1.4.2 sourceware.org CB0A94BA23DD Authentication-Results: sourceware.org; dmarc=pass (p=reject dis=none) header.from=sifive.com Authentication-Results: sourceware.org; spf=pass smtp.mailfrom=sifive.com ARC-Filter: OpenARC Filter v1.0.0 sourceware.org CB0A94BA23DD Authentication-Results: sourceware.org; arc=none smtp.remote-ip=2607:f8b0:4864:20::1335 ARC-Seal: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1779776276; cv=none; b=MMAvcMiU0JPBPuApK6DkhYOuEUPTiOi2xorgs+QHwN/u9OkD1XZVgUKgo6227lyhogiB+CLvknVeA3iuBd7b/PXSCHTcWz8Fv45CS31FVlMnCxO3X8S6Nb0zzNLYM1WB8Izhm6glwp91Fij5oSUKG+X1dXC7hNFHFVFBqoBBiDU= ARC-Message-Signature: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1779776276; c=relaxed/simple; bh=Z3wng1mX+9rrYd9fGC9qCLxlwfPDt6oB9G0p1nZG5o0=; h=DKIM-Signature:From:To:Subject:Date:Message-Id:MIME-Version; b=vG/phACbTZ5AwA5AQszNDy33dE47Rfn/HFbpzD334y4NfETKEdSQqSBtY53IPiAhLWy9FCMlIsFaOXuBDrWVi2rQzIK+fnAXiHHudpxw4CamDU6Y4ZhQD84rUEpQFFDg97mSncrmymSfGgygsNRaYAMsn+hGVkZSe19GuX3i+x8= ARC-Authentication-Results: i=1; sourceware.org; dkim=pass (2048-bit key, unprotected) header.d=sifive.com header.i=@sifive.com header.a=rsa-sha256 header.s=google header.b=VzfaN0MC DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org CB0A94BA23DD Received: by mail-dy1-x1335.google.com with SMTP id 5a478bee46e88-2bdcf5970cdso7195166eec.0 for ; Mon, 25 May 2026 23:17:55 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=sifive.com; s=google; t=1779776275; x=1780381075; darn=sourceware.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to; bh=F8Z4vgITWUbP3lfydmFQj6HBlxfqDiTnaqv9HTjtoWw=; b=VzfaN0MCYWI0TZ1gd5Xinzjv3Ir4C0oow+nhhoyYajdgluTyP0/V+Mh8ugj64fMOj6 5e/fuJCPdpmCtDGzAYCCgqnjaP+/g3KLvfL+tfgPi8xfIA4W4rFOATYtSMMXzawMFq4s Rbws/tVOjfzzPGZhc624yIc5dVcoHOf7fq/LR7uVtDcttGRxewSegAAK2GRovkSk+Udk xLNQ9xDe9ysa3/CPYziR6lIEQ0NTfIjwSjYYskC72mVypK00OXL2kjYt6a7zsenFGmvh vV1HQgb7o0QTLYTuWCB5YvbXjeawQFl7tdBD0wZ0s4gH4rHsBGu5igh+ODipdpfkWKFN xFTg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1779776275; x=1780381075; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to; bh=F8Z4vgITWUbP3lfydmFQj6HBlxfqDiTnaqv9HTjtoWw=; b=ZVZX0DVOyZzmbmFAoyY7aJzNu919JSd2/+tnk7KzbJhUV6Sg6iNaR8mXS4JxoDwPZA NnH4htFQiUiiX6kAiiJI1jTd/t+ro3HUFiz+GybINZe7HUZF7C+OTNIUqxiWZHWlTI4R KPl2mhG07qPuuQ5hBq+L9C9QVehzqrn1Lias2wv41gvZXwsD/nLFgWrwt9UacdSzS4rB g8cchQLPYdgMDqcKdhqxALDHfUoZZhE02bU9D9wskyXGpng4GW/nkPY4CTsDroqhcYDl Voj2Wkw5D/MEumeEBiEneamStrQHdsmOHYzAIiIboTtBnof1DUnR0PlEW+w9CVhQv4kZ VT8g== X-Gm-Message-State: AOJu0YwYL68D7wSpHlWej7s/wvnQfJwbbeOtwHgpylLQQrA7qLPmG2Zp 1LD2bzQ7v79NqbW7prZkVWnQruuNdLAEJ+BE2YDKtFOI5dCqBFQ77DqER1tD5vg6lL50nTNSBqQ Qu2CciOwkyFY+e0NBasDbBMNSktw2eDE4lMMAVI+17fX5jGHDX2ctnMncQHioztHIZuOOl8ygPe GsHLqboIH860CoeBG8j547L4zlGtds7dfdtcUnkO0X+78yT2CW X-Gm-Gg: Acq92OGkGc9WdU/h70r98bSfUXCwUEmW66qurgWpjsdmWk3EeGuBiclPJRm2RYpD799 UYc+PaXFijc5tY6dUITPJppWFG0ucA3FTO3zr+f//11PgWTaRd99Gd4kW9jLTdU2bwkF+s6MXlN JipuexjaLDAuHOgtZGRNuLzqFwWQbKJf1EkcEn4XFwBoT0dfu/V4G+gETcOZr0lnrk99UMDbEdX yOUX4Hrl8B0X6vHZqeWXp5doXFFrky8glCWD8CMXEscEKKI39SBFN0ammbk+2068gZShzfbbM9M CGP6hSFxf58aJbbFkDL1UEfrkcHEFR+/0FY8wybwY7TT+6J53jVhLnfWM00EkB2r3VpZ1BztYM7 BUD3ekVPM3VkZh0sYdrbE4S6eqWkG2d0gCtxICw/EIz64mQ1kWlfhfWSdoU1CQ3itAqcaC04YhX 1cR1qWb5JZcgoWLbldRh4xTcXI5SySQ0/BPvob6VqH X-Received: by 2002:a05:693c:3103:b0:2c1:67e1:61a9 with SMTP id 5a478bee46e88-3044a5ed1abmr6399656eec.13.1779776274625; Mon, 25 May 2026 23:17:54 -0700 (PDT) Received: from sw08.internal.sifive.com ([4.53.31.132]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-30452461cb5sm14062504eec.31.2026.05.25.23.17.53 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 25 May 2026 23:17:54 -0700 (PDT) From: Jesse Huang To: libc-alpha@sourceware.org Cc: andrew@sifive.com, darius@bluespec.com, debug@rivosinc.com, jeffreyalaw@gmail.com, kito.cheng@sifive.com, palmer@dabbelt.com, Jesse Huang Subject: [PATCH v4 01/17] riscv: Add --enable-cfi option for controlling cfi features Date: Mon, 25 May 2026 23:16:47 -0700 Message-Id: <20260526061703.2188042-2-jesse.huang@sifive.com> X-Mailer: git-send-email 2.39.3 In-Reply-To: <20260526061703.2188042-1-jesse.huang@sifive.com> References: <20260526061703.2188042-1-jesse.huang@sifive.com> MIME-Version: 1.0 X-Spam-Status: No, score=-13.1 required=5.0 tests=BAYES_00, DKIM_SIGNED, DKIM_VALID, DKIM_VALID_AU, DKIM_VALID_EF, GIT_PATCH_0, RCVD_IN_DNSWL_BLOCKED, SPF_HELO_NONE, SPF_PASS, TXREP, URIBL_BLOCKED shortcircuit=no autolearn=ham autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on sourceware.org X-BeenThere: libc-alpha@sourceware.org X-Mailman-Version: 2.1.30 Precedence: list List-Id: Libc-alpha mailing list List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: libc-alpha-bounces~patchwork=sourceware.org@sourceware.org --- INSTALL | 13 +++++++++++++ NEWS | 3 +++ configure | 12 ++++++++++++ configure.ac | 6 ++++++ manual/install.texi | 12 ++++++++++++ 5 files changed, 46 insertions(+) diff --git a/INSTALL b/INSTALL index 4174c9661f..04bdea3647 100644 --- a/INSTALL +++ b/INSTALL @@ -154,6 +154,19 @@ passed to 'configure'. For example: NOTE: '--enable-cet' is only supported on x86_64 and x32. +'--enable-cfi' + Enable RISC-V Control Flow Integrity Extensions (Zicfilp/Zicfiss) + support. When the GNU C Library is built with '--enable-cfi', the + resulting library is protected with landing pad and shadow stack. + This feature is currently supported on RV64 with GCC 15 and + binutils 2.45 or later. With '--enable-cfi', it is an error to + dlopen a non CFI enabled shared library in CFI enabled application. + The restriction can be loosen by setting to permissive mode with + the use of the glibc tunables, see glibc tunables section for more + information. + + NOTE: '--enable-cfi' is only supported on RV64. + '--enable-memory-tagging' Enable memory tagging support if the architecture supports it. When the GNU C Library is built with this option then the resulting diff --git a/NEWS b/NEWS index e2173fa1aa..c19d881868 100644 --- a/NEWS +++ b/NEWS @@ -9,6 +9,9 @@ Version 2.44 Major new features: +* Added --enable-cfi option to enable the RISC-V CFI extensions + (Zicfilp/Zicfiss) support on RV64 Linux. + * Additional optimized and correctly rounded mathematical functions have been imported from the CORE-MATH project, in particular cosh, sinh, and tanh. diff --git a/configure b/configure index 336a93fbef..80d8c839e5 100755 --- a/configure +++ b/configure @@ -818,6 +818,7 @@ enable_nscd enable_pt_chown enable_mathvec enable_cet +enable_cfi enable_scv enable_fortify_source enable_sframe @@ -1500,6 +1501,7 @@ Optional Features: depends on architecture] --enable-cet enable Intel Control-flow Enforcement Technology (CET), x86 only + --enable-cfi enable Control Flow Integrity (CFI), RISC-V only --disable-scv syscalls will not use scv instruction, even if the kernel supports it, powerpc only --enable-fortify-source[=1|2|3] @@ -4855,6 +4857,16 @@ esac fi +# Check whether --enable-cfi was given. +if test ${enable_cfi+y} +then : + enableval=$enable_cfi; enable_cfi=$enableval +else case e in #( + e) enable_cfi=no ;; +esac +fi + + # Check whether --enable-scv was given. if test ${enable_scv+y} then : diff --git a/configure.ac b/configure.ac index e9138a38b7..9739ce399d 100644 --- a/configure.ac +++ b/configure.ac @@ -421,6 +421,12 @@ AC_ARG_ENABLE([cet], [enable_cet=$enableval], [enable_cet=$libc_cv_compiler_default_cet]) +AC_ARG_ENABLE([cfi], + AS_HELP_STRING([--enable-cfi], + [enable Control Flow Integrity (CFI), RISC-V only]), + [enable_cfi=$enableval], + [enable_cfi=no]) + AC_ARG_ENABLE([scv], AS_HELP_STRING([--disable-scv], [syscalls will not use scv instruction, even if the kernel supports it, powerpc only]), diff --git a/manual/install.texi b/manual/install.texi index 073cda0530..a9dc56f937 100644 --- a/manual/install.texi +++ b/manual/install.texi @@ -185,6 +185,18 @@ non CET enabled shared library in CET enabled application. NOTE: @option{--enable-cet} is only supported on x86_64 and x32. +@item --enable-cfi +Enable RISC-V Control Flow Integrity Extensions (Zicfilp/Zicfiss) support. +When @theglibc{} is built with @option{--enable-cfi}, the resulting +library is protected with landing pad and shadow stack@. +This feature is currently supported on RV64 with GCC 15 and binutils 2.45 +or later. With @option{--enable-cfi}, it is an error to dlopen a non CFI +enabled shared library in CFI enabled application. The restriction can be +loosen by setting to permissive mode with the use of the glibc tunables, +see glibc tunables section for more information. + +NOTE: @option{--enable-cfi} is only supported on RV64. + @item --enable-memory-tagging Enable memory tagging support if the architecture supports it. When @theglibc{} is built with this option then the resulting library will From patchwork Tue May 26 06:16:48 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Jesse Huang X-Patchwork-Id: 135653 Return-Path: X-Original-To: patchwork@sourceware.org Delivered-To: patchwork@sourceware.org Received: from vm01.sourceware.org (localhost [IPv6:::1]) by sourceware.org (Postfix) with ESMTP id E82374BA23DD for ; Tue, 26 May 2026 06:19:27 +0000 (GMT) DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org E82374BA23DD Authentication-Results: sourceware.org; dkim=pass (2048-bit key, unprotected) header.d=sifive.com header.i=@sifive.com header.a=rsa-sha256 header.s=google header.b=kz7Ljn99 X-Original-To: libc-alpha@sourceware.org Delivered-To: libc-alpha@sourceware.org Received: from mail-dy1-x1330.google.com (mail-dy1-x1330.google.com [IPv6:2607:f8b0:4864:20::1330]) by sourceware.org (Postfix) with ESMTPS id 998574BA23DF for ; Tue, 26 May 2026 06:17:56 +0000 (GMT) DMARC-Filter: OpenDMARC Filter v1.4.2 sourceware.org 998574BA23DF Authentication-Results: sourceware.org; dmarc=pass (p=reject dis=none) header.from=sifive.com Authentication-Results: sourceware.org; spf=pass smtp.mailfrom=sifive.com ARC-Filter: OpenARC Filter v1.0.0 sourceware.org 998574BA23DF Authentication-Results: sourceware.org; arc=none smtp.remote-ip=2607:f8b0:4864:20::1330 ARC-Seal: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1779776276; cv=none; b=P8vaQ3I3iBQXlQYHmdf+z8W/5dKJTTewHCQR3I0wmBaJftdzmXb4UcESVNV5KMn9Jw0xjZGxhZmM+Pw5HrmIzVi6mOHMXvhX215dT4pHspGFcVkxwrOwM03iu/p+IZp7uiqEY+b2ej9XH6pcaxTiTy0ZRUnsveoQgp4MVIbak1c= ARC-Message-Signature: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1779776276; c=relaxed/simple; bh=gMOByEfIp503D+BxeRN3lc0cnIP9YB4Y3SBMFXjXj+c=; h=DKIM-Signature:From:To:Subject:Date:Message-Id:MIME-Version; b=nZ7P0lm3aPGQZwDlBIAppwj+M6loMbhCNWaJW7VsprD04bZxUN+1OW1mg13mgwD8W4LEk7PzOxr32fNpmY1Y99WPJgoIHlJtTB8OJdILf9cNZRjSl6CwSI7JlYfQ/L/uOyNhBjmQLSjhMNrO/G6pm6YUdk51AfwQfYE6dVP2GH0= ARC-Authentication-Results: i=1; sourceware.org; dkim=pass (2048-bit key, unprotected) header.d=sifive.com header.i=@sifive.com header.a=rsa-sha256 header.s=google header.b=kz7Ljn99 DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org 998574BA23DF Received: by mail-dy1-x1330.google.com with SMTP id 5a478bee46e88-2f33ae12f97so767379eec.1 for ; Mon, 25 May 2026 23:17:56 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=sifive.com; s=google; t=1779776276; x=1780381076; darn=sourceware.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to; bh=MH9bgHSaBUMBQ6usVsPBUDPvKYca+X9CLKN6DGsOAFg=; b=kz7Ljn99nBXSPw8R5uB3aoVEnBmhh9VnfPV26PZXSQONUc7PK8Z4v/wQwFv1ixyV9C E5UZeSqwSiUAZtpV+ikNP+Ts6I7ymYoP8uCJjpgAY04GyMHJ/tef9esdF4pOXp7LNSh2 bhbTk0+Ys3cdRcM1xn8oag1UPZ3gOG+JSWCaPjm7lCyewvzD64bst67KzREz9dfKfKyF BHaKGYV3hyUyS5qPaTtyhF90k60taS0BG4qJ/0Jg5RPJpF9hSOBNyKO1bBOTgKLxbAlg pD/o8GntH/CFJnAi0cMgmgh7wb68mcBCpLNAlKaEAdZgKaP+w3XsMcTs0YbSzItxbuIB W9nQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1779776276; x=1780381076; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to; bh=MH9bgHSaBUMBQ6usVsPBUDPvKYca+X9CLKN6DGsOAFg=; b=dLCKz9madYEm4of5Mls6Z+LYrGGx72y+bBzjcSMyDfOl71wVTCeulpIvRLfBqM7fNf fKj9jQ8JNAUROY+0bPtnJCUxwjNrDI4IGkVPdcz5VIXiVlhlRinakrCAwydDiJ+EzEkL WNexxFUc400xAl32VHgmmknTB/2jJrLX0qm31MYwJW+mmgxONVTmiplu+9KLFcoZtk0R 5RQMChT4IMiCAxgMaMpT8cNshfkL65tUrLfB7gL3JBYs4ksE+3FCPKe4uTURMdRH1dqK DfoOVh5Lg6XMFL0k7F8F4/XpAkWuxXUAWl1k8Zsk0/pt/mNoZQ1GiU2+7dcVaDIRvF6B jjtA== X-Gm-Message-State: AOJu0YyRPBByKJtkaOwn/8/wgtmbahwMBn5rpP+PuBhTMAUtafry3/Rl PH33RbzVhrmhxwtbuD7zjl9QG49E7GDGdbWKARHQ7D10WkUVqVIKCkxmen7eF9qaOaMaFXKMQxo 3wW/IdeWgvcoXtIld5oEtukiFFMqK1mCKJxCWYRA9k8oFlWDo9pGmxm9zqB+tpuNsf64B/3BDfX geL0TDTCuBRB+diGLK0bFH7EXrbUiKkpnxahpTCSu8lo1S1Y9Y X-Gm-Gg: Acq92OGI6Erjstltb7lauavuzofCQ6aaPhQTEQUC8hPJb7d+ZAw1JGobEX2HPb/KCOF S95SN3jOnEdv1uGQvjCH+EeCjxPOAaEZHSijJpxBmC/XZWPM0Te/6YmMbHNKMGO8pSjHe1TbFIq YofsgP4BxL8POYPM95QzPrhCeWWwpp+Tg2jIuq9hjlMCYjxX63wWmQDOUxtv4s67RlYDEB8c6FD zUhXLKQSzdG6lP5TO2QFqhvOjfYmyJIVbIT9gvAo5FePkKjxiEpOaSipOXH7PzIP4l4h4e79/Wn mC3uqyv/DNNQjZ+x5weAAo7yxqJFoZMhB7EJBujlFoXnRFYFGhdwQRnvrS3SOZ5AyXXT8InojcW AMTSPQ/kKAGo/1Zh9Sc7/QgMZvmhHUbBVcrQQHoqeT+L23XzphZib9YbhxysjyD1dyRCxOnbY50 va7FjXNqq+b7IbAbIzH3mIYb9mX73LvetybIPR2hgP X-Received: by 2002:a05:7300:dc83:b0:2c1:6676:5ebd with SMTP id 5a478bee46e88-3044902cee2mr8181925eec.10.1779776275475; Mon, 25 May 2026 23:17:55 -0700 (PDT) Received: from sw08.internal.sifive.com ([4.53.31.132]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-30452461cb5sm14062504eec.31.2026.05.25.23.17.54 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 25 May 2026 23:17:55 -0700 (PDT) From: Jesse Huang To: libc-alpha@sourceware.org Cc: andrew@sifive.com, darius@bluespec.com, debug@rivosinc.com, jeffreyalaw@gmail.com, kito.cheng@sifive.com, palmer@dabbelt.com, Jesse Huang , Hau Hsu Subject: [PATCH v4 02/17] riscv/cfi: Setup necessary options for enable-cfi option Date: Mon, 25 May 2026 23:16:48 -0700 Message-Id: <20260526061703.2188042-3-jesse.huang@sifive.com> X-Mailer: git-send-email 2.39.3 In-Reply-To: <20260526061703.2188042-1-jesse.huang@sifive.com> References: <20260526061703.2188042-1-jesse.huang@sifive.com> MIME-Version: 1.0 X-Spam-Status: No, score=-13.1 required=5.0 tests=BAYES_00, DKIM_SIGNED, DKIM_VALID, DKIM_VALID_AU, DKIM_VALID_EF, GIT_PATCH_0, RCVD_IN_DNSWL_BLOCKED, SPF_HELO_NONE, SPF_PASS, TXREP, URIBL_BLOCKED shortcircuit=no autolearn=ham autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on sourceware.org X-BeenThere: libc-alpha@sourceware.org X-Mailman-Version: 2.1.30 Precedence: list List-Id: Libc-alpha mailing list List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: libc-alpha-bounces~patchwork=sourceware.org@sourceware.org Co-authored-by: Hau Hsu Reviewed-by: Deepak Gupta --- sysdeps/riscv/Makefile | 9 +++++++++ sysdeps/riscv/preconfigure | 2 ++ sysdeps/riscv/preconfigure.ac | 1 + 3 files changed, 12 insertions(+) diff --git a/sysdeps/riscv/Makefile b/sysdeps/riscv/Makefile index c08753ae8a..99976fddad 100644 --- a/sysdeps/riscv/Makefile +++ b/sysdeps/riscv/Makefile @@ -15,3 +15,12 @@ ASFLAGS-.os += -Wa,-mno-relax ASFLAGS-.o += -Wa,-mno-relax sysdep-CFLAGS += -mno-relax endif + +# Enable RISC-V CFI +ifeq (yes,$(riscv-enable-cfi)) +CFLAGS-.o += -fcf-protection=full +CFLAGS-.os += -fcf-protection=full +CFLAGS-.op += -fcf-protection=full +CFLAGS-.oS += -fcf-protection=full +asm-CPPFLAGS += -fcf-protection=full -include sysdep.h +endif diff --git a/sysdeps/riscv/preconfigure b/sysdeps/riscv/preconfigure index 57fe6822cf..b480c53d5f 100755 --- a/sysdeps/riscv/preconfigure +++ b/sysdeps/riscv/preconfigure @@ -79,6 +79,8 @@ riscv*) printf "%s\n" "#define RISCV_ABI_FLEN $abi_flen" >>confdefs.h + config_vars="$config_vars +riscv-enable-cfi = $enable_cfi" ;; esac diff --git a/sysdeps/riscv/preconfigure.ac b/sysdeps/riscv/preconfigure.ac index 52414919ae..15c61e9305 100644 --- a/sysdeps/riscv/preconfigure.ac +++ b/sysdeps/riscv/preconfigure.ac @@ -77,5 +77,6 @@ riscv*) AC_DEFINE_UNQUOTED([RISCV_ABI_XLEN], [$xlen]) AC_DEFINE_UNQUOTED([RISCV_ABI_FLEN], [$abi_flen]) + LIBC_CONFIG_VAR([riscv-enable-cfi], [$enable_cfi]) ;; esac From patchwork Tue May 26 06:16:49 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Jesse Huang X-Patchwork-Id: 135652 Return-Path: X-Original-To: patchwork@sourceware.org Delivered-To: patchwork@sourceware.org Received: from vm01.sourceware.org (localhost [IPv6:::1]) by sourceware.org (Postfix) with ESMTP id CFDA14B9DB5C for ; Tue, 26 May 2026 06:18:57 +0000 (GMT) DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org CFDA14B9DB5C Authentication-Results: sourceware.org; dkim=pass (2048-bit key, unprotected) header.d=sifive.com header.i=@sifive.com header.a=rsa-sha256 header.s=google header.b=B0N6A1BQ X-Original-To: libc-alpha@sourceware.org Delivered-To: libc-alpha@sourceware.org Received: from mail-dy1-x1331.google.com (mail-dy1-x1331.google.com [IPv6:2607:f8b0:4864:20::1331]) by sourceware.org (Postfix) with ESMTPS id 777B84BA23E0 for ; Tue, 26 May 2026 06:17:57 +0000 (GMT) DMARC-Filter: OpenDMARC Filter v1.4.2 sourceware.org 777B84BA23E0 Authentication-Results: sourceware.org; dmarc=pass (p=reject dis=none) header.from=sifive.com Authentication-Results: sourceware.org; spf=pass smtp.mailfrom=sifive.com ARC-Filter: OpenARC Filter v1.0.0 sourceware.org 777B84BA23E0 Authentication-Results: sourceware.org; arc=none smtp.remote-ip=2607:f8b0:4864:20::1331 ARC-Seal: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1779776277; cv=none; b=W2ip68eEujxG6wyg5v1eiiHOIFMYqdjHiUNCC/EiUEDlYKzJ/jjUU9IYr/hwqqCEqHsEPM2yIsYa7YTy/tJJVX/e8lEFxsN/NgPK3uo25OS7EDES9IuGTE3E89e3EtMmRn5YScEOkwXDSIZqq6pn9/Bpr2PjxrbNxKDBx4P7SjY= ARC-Message-Signature: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1779776277; c=relaxed/simple; bh=taBAm+wglsvBHhx7GWGUNITwUL50gPorJEJMm6/Cf64=; h=DKIM-Signature:From:To:Subject:Date:Message-Id:MIME-Version; b=YV33cCRsMRtyD6mv3RYMQ15VpJ2Wn6XvztfdK8AUoPRlS+EXnnSdvt3qTu1vUOF5zhZzg2f1ZzUhx1VPivfJprcIiOLIAe/3UpZiPKBSFv3hfRxp6aVRibRqMFtKInEjQCgkaaGOY67knHbleiTnjLw3IxVTBvOjLc/TsYIBCl4= ARC-Authentication-Results: i=1; sourceware.org; dkim=pass (2048-bit key, unprotected) header.d=sifive.com header.i=@sifive.com header.a=rsa-sha256 header.s=google header.b=B0N6A1BQ DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org 777B84BA23E0 Received: by mail-dy1-x1331.google.com with SMTP id 5a478bee46e88-30455f77e0eso6908043eec.0 for ; Mon, 25 May 2026 23:17:57 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=sifive.com; s=google; t=1779776276; x=1780381076; darn=sourceware.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to; bh=0MSzYPo8j3QCjxNx1DKZJBR8lXG28TXkR4lmFd+y6Cw=; b=B0N6A1BQJdiSXwQGNKHCB2GCkEyWkDoGCYJhVy7m+QGt/B2NOfv1G9B/4nEPoHb0sC zv5GgYl4+1Y10rtFnKcHmumeISk396yilsXSkXYrt75/TljgS5XK2kREs/NHzwdVOw87 75O+fWOWGirXgZ21XN3MVj7mv3A1RCD1rt1Pw6TK5aHCslyZMvDPjMl8zThQMcwLBnxT 33KHytUZ5HCqyiOjNZ3h5g669e6gASKChlSVPIGXs8oABBv2rkeuyoroYn2upAQF/8RD TTNTE0F44Um3CXuH4nNYU0b1vzcGUXbf4/DcOMIpZRY8IaXOXZN6sIz+ctGfjFVi32t9 ZsHQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1779776276; x=1780381076; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to; bh=0MSzYPo8j3QCjxNx1DKZJBR8lXG28TXkR4lmFd+y6Cw=; b=IlaZ7TkxKqWtSQUEFaDNvm8E8xmH6EJ1Hmo1wKgQfy5UEn0+PFtCUEBWPnqY7rad8+ a3SOsSDC0q7b4PMhHwi1EUW1WoWljxezsDLCS5yipe27tACTHVec2pCX14M1uNlpYr62 xiDut36zRTVAbL5olclASlg8rppTd1Gt9M316hsRd91SxjEpw+n8LxGV2yiXefIuEyo2 4qsp9yeuj9RGmzNWrb0xsuBUK6y66fHHh4pmXM8tIS7YwqlhnZr5eeIFyNfSkeCXEGON 02yw3+ceLllUO3/PVaRYLZhQPMPTc/R+lNXbE9vxWUwhaJYykaRImrKZBofj/h2oifuR w5YA== X-Gm-Message-State: AOJu0YzHL4ND+KKZfMGkECWFQ2ynPwHLpDNg7wTQAouCcDwPLUBek3cF SK5JYm1lwTQB/AyWc9SuhpLggQYTKnhY69S5xM2g6NZDL2X2CBJkjj2WSHz/2U6mEnLlPMcy+Gs 2nU8NhoVKEAtdp3tTF9hFos/r8MbPs31eKkBouJWpo4MJeI3I+F82qhuFBqdMRGj+dhsyPTGm0Z jetXFv46Gh2rEyjCypukoD1xQDLjO8nNh3FWDAoLqXbZVI/05f X-Gm-Gg: Acq92OHkx15xIhlMSmmoj0D4hRncb8hmOT4uprh3KpfhEHWG5eAjO6PnKMbg58M2Fgm lA/V/wdohCFLpY9c3I2ULaGmSP3aOcJgPBL9c3VVy8RgqDaQm2L6QAU6b7dm1LOzEc9kEo0p/i6 xt4I0Y/K9VWJ1slAQOhPw6uBv6rblL78Floq4FaXatu+O2T4NXRkbTBvDxtWxT4mRNEUH3S6X1o H00sr6j8LMbk9TC3d9/FEVjW3pJw/deuBSNeL+4Kmqz0fllfqjCGWGWZr5Y3uR0CJFR3WeMT3wl 4Dzoe5+d3xIU3B6XrX1HyYYUcDcWpzpbIo+O622fwxJIIZdQZ5SEwZyTloVsUijqH9SRoGnoqt0 CLKpSecFDNBifVdh202DSDrOBIPDz6V5F1s07GQ89ppShIcewmvT4EXy/IZndz8W+EH01WknOKG S3Q/G7EUNnEaF9M1ULLK/EnkSAYDvzPfOXWUzG3WGR X-Received: by 2002:a05:7300:cb86:b0:2ed:e12:3773 with SMTP id 5a478bee46e88-304491faf02mr9074931eec.35.1779776276296; Mon, 25 May 2026 23:17:56 -0700 (PDT) Received: from sw08.internal.sifive.com ([4.53.31.132]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-30452461cb5sm14062504eec.31.2026.05.25.23.17.55 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 25 May 2026 23:17:55 -0700 (PDT) From: Jesse Huang To: libc-alpha@sourceware.org Cc: andrew@sifive.com, darius@bluespec.com, debug@rivosinc.com, jeffreyalaw@gmail.com, kito.cheng@sifive.com, palmer@dabbelt.com, Jesse Huang Subject: [PATCH v4 03/17] riscv: Add GNU property definitions for RISC-V CFI Date: Mon, 25 May 2026 23:16:49 -0700 Message-Id: <20260526061703.2188042-4-jesse.huang@sifive.com> X-Mailer: git-send-email 2.39.3 In-Reply-To: <20260526061703.2188042-1-jesse.huang@sifive.com> References: <20260526061703.2188042-1-jesse.huang@sifive.com> MIME-Version: 1.0 X-Spam-Status: No, score=-13.1 required=5.0 tests=BAYES_00, DKIM_SIGNED, DKIM_VALID, DKIM_VALID_AU, DKIM_VALID_EF, GIT_PATCH_0, RCVD_IN_DNSWL_BLOCKED, SPF_HELO_NONE, SPF_PASS, TXREP, URIBL_BLOCKED shortcircuit=no autolearn=ham autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on sourceware.org X-BeenThere: libc-alpha@sourceware.org X-Mailman-Version: 2.1.30 Precedence: list List-Id: Libc-alpha mailing list List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: libc-alpha-bounces~patchwork=sourceware.org@sourceware.org Add GNU properties used by RISC-V CFI extensions (zicfilp/zicfiss) Reviewed-by: Deepak Gupta --- elf/elf.h | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/elf/elf.h b/elf/elf.h index 3a60ef36b5..3e8c4fb92d 100644 --- a/elf/elf.h +++ b/elf/elf.h @@ -1427,6 +1427,11 @@ typedef struct SHSTK. */ #define GNU_PROPERTY_X86_FEATURE_1_SHSTK (1U << 1) +/* RISC-V specific GNU PROPERTY. */ +#define GNU_PROPERTY_RISCV_FEATURE_1_AND 0xc0000000 +#define GNU_PROPERTY_RISCV_FEATURE_1_CFI_LP_UNLABELED (1u << 0) +#define GNU_PROPERTY_RISCV_FEATURE_1_CFI_SS (1u << 1) + /* Move records. */ typedef struct { From patchwork Tue May 26 06:16:50 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Jesse Huang X-Patchwork-Id: 135654 Return-Path: X-Original-To: patchwork@sourceware.org Delivered-To: patchwork@sourceware.org Received: from vm01.sourceware.org (localhost [IPv6:::1]) by sourceware.org (Postfix) with ESMTP id C6C874BA79AC for ; Tue, 26 May 2026 06:19:32 +0000 (GMT) DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org C6C874BA79AC Authentication-Results: sourceware.org; dkim=pass (2048-bit key, unprotected) header.d=sifive.com header.i=@sifive.com header.a=rsa-sha256 header.s=google header.b=f8mB+eNP X-Original-To: libc-alpha@sourceware.org Delivered-To: libc-alpha@sourceware.org Received: from mail-dy1-x132b.google.com (mail-dy1-x132b.google.com [IPv6:2607:f8b0:4864:20::132b]) by sourceware.org (Postfix) with ESMTPS id 93A244BA23F5 for ; Tue, 26 May 2026 06:17:59 +0000 (GMT) DMARC-Filter: OpenDMARC Filter v1.4.2 sourceware.org 93A244BA23F5 Authentication-Results: sourceware.org; dmarc=pass (p=reject dis=none) header.from=sifive.com Authentication-Results: sourceware.org; spf=pass smtp.mailfrom=sifive.com ARC-Filter: OpenARC Filter v1.0.0 sourceware.org 93A244BA23F5 Authentication-Results: sourceware.org; arc=none smtp.remote-ip=2607:f8b0:4864:20::132b ARC-Seal: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1779776279; cv=none; b=jN8UYg6MSLOFqH9gwvetqFPJw+6e/3ZT5QQj7U05sNsXCIZ2OYL/QidN+EHBh4WdtXwkCG3tJz4GzOmY2bh7tz03AAYuh0hANJT4a8tmA776PXccuSb/D+K1/LJVlmZR8LCjAy6Y1VDclpp4HOlW23Fk6fXBf1lYyWEzGOUYmdk= ARC-Message-Signature: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1779776279; c=relaxed/simple; bh=+bhaW5Xir/5auGnE/CBYb6weBN85tx9yZCwE7RSpAcw=; h=DKIM-Signature:From:To:Subject:Date:Message-Id:MIME-Version; b=c7NOCRSBetCCL7g/rCaG9cd7N+fSWKDipSWmVIbv1oxZLLrU8dB1oXSoigJeCb3dSc8Gpjvs1Mojp6XYvVrdibVEbxyABCGaRLGxmbizWx0L8xNfPPwn7rYHw4gH9X23nAHfZf7lKyQeueS3hOvbbGL/LD1MHtB3aP5vKEzzWko= ARC-Authentication-Results: i=1; sourceware.org; dkim=pass (2048-bit key, unprotected) header.d=sifive.com header.i=@sifive.com header.a=rsa-sha256 header.s=google header.b=f8mB+eNP DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org 93A244BA23F5 Received: by mail-dy1-x132b.google.com with SMTP id 5a478bee46e88-2f03d6cf77bso10686650eec.0 for ; Mon, 25 May 2026 23:17:59 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=sifive.com; s=google; t=1779776279; x=1780381079; darn=sourceware.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to; bh=pHAPFSV2fgbhWkMYdlwHzYB8rMf4Htnmn5znjUaby/E=; b=f8mB+eNPlIfbktQQw1uq16+UOaX1uQFiW9ExW1prmUzaaviodUk9xQOfyV/GhEdhKt BCOjOgBp5eb0JznnFy70gNGi7wj3wty3I4KJE5+pAtIANLLiU+V0bzyqlbctgQVtXdeA dKh+o7qW32hnrKGjW5KuVkgeNGAZYhP+krvc+T8j/RDfv8/PjWEWZde/M2gRjeB0Vx0Y KkEHkWukdhUHUILb7wyrBo6chuuSoxSqwCbqezDdr/nYa4/o2ksY47M+FLXaYTh1q4gr TDfx9Po00kYSz8Be0JyooBJwrBoEapASikw0ZbAzLp3RbP83mvpTH6GT7dDcoICFQtFn vEug== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1779776279; x=1780381079; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to; bh=pHAPFSV2fgbhWkMYdlwHzYB8rMf4Htnmn5znjUaby/E=; b=U3sWw8V1SZCNgb9vKzhgfRAx2OdXGo/YhHUODg+uJeoFm8Jc6Tpm9YdC5vCIf4U+Ys 8726EEnp/197Rjsj6EM6eWR+grAX6elRlwYPV/nMrIXalvb3p1loQb4Dto8CoQIDJFdu Ij50wIm9U1M1BTvaHjpbMERJDfpNF3y/ld7bO/90isicQEcJ1lU3yR4EzYnBcIydvn9g Qxvwf+IWTkOIkhiCpRyMLFq4u+lw+UDFTvaMvUIHD5R/Y+u78O+UTG64jF7dJjmyArc3 ZM47NWFgtJtq6BV4i/4t0lGYoQkFbqCJ1ZVLOfG24nKqk3K2v4ieOEJt8CSIsO4fNvCk C4hw== X-Gm-Message-State: AOJu0Yy2Ngx75CNq97FkI0Cc9TNbPN3sqJJ/ZmGmeycMfTdKrWFEX//Y d3nYSc/ax5pFu/mRr0M9hq86GdwIQXVmDauKtjgk6k5NJEfhJPql3y06SJfjbmHESeKvjQNfCEC p3S2TkwG5VlWHXc4egRyCIdynfujg82w8KunIuFRYysPQeZktmoG+sKV1PYJmY8qYTeGcOYA04a TRwMndAK89TDmKetzSWO7dnwDuQP4IK2rHACIsUrmKMut1MwD0 X-Gm-Gg: Acq92OFoxtRRPbap/I2HUiQwKa42FRVj9a5B5zOL7KByNrrdVwZAzZDjXO6WOco9reL haJqfqzpX/BTxnE8L8jm8eePrNiJMQ4Kvb3CVceTSEeGxbcKTxAg37KkMIB5dVn5m6vnmj5LaQn nmCgTOTqJAVYbfnc4isbFqaXp134oifqeCu88zC0HgZsjZG7rCV3c0FJWao7W1lANstFA1EAwCF VgZW0jZeIC5D6tn6uC1Nysiq+LHCy89aFOYropeh8pc8sYHyAWRuIuKEhHgc0DTtXsA4VYZ9bl5 6YKE3cQkxMd6MQ1TDmyhBq7PwmCpj7T+lL/fnNnhuNdMwWEkJ/0c86n7cjeGQ7JPi2h3q5Ch6aW AomResxZCu0Z5PsxT/MSDY444unFETPVCgfFWlW8LHN40woFfoDHdCNamRxYkgNPyLLpP4oEzH4 bhoa4GR1AFfkvNrQUsFzJQoZNp1K3KC6ore4LZEyiWIDkNXD3ltNY= X-Received: by 2002:a05:7301:e2b:b0:2d0:239a:23c9 with SMTP id 5a478bee46e88-30449183e3cmr8242212eec.16.1779776278282; Mon, 25 May 2026 23:17:58 -0700 (PDT) Received: from sw08.internal.sifive.com ([4.53.31.132]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-30452461cb5sm14062504eec.31.2026.05.25.23.17.56 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 25 May 2026 23:17:57 -0700 (PDT) From: Jesse Huang To: libc-alpha@sourceware.org Cc: andrew@sifive.com, darius@bluespec.com, debug@rivosinc.com, jeffreyalaw@gmail.com, kito.cheng@sifive.com, palmer@dabbelt.com, Jesse Huang , Hau Hsu , Jerry Zhang Jian Subject: [PATCH v4 04/17] riscv: Adjust assembly routines to support landing pad Date: Mon, 25 May 2026 23:16:50 -0700 Message-Id: <20260526061703.2188042-5-jesse.huang@sifive.com> X-Mailer: git-send-email 2.39.3 In-Reply-To: <20260526061703.2188042-1-jesse.huang@sifive.com> References: <20260526061703.2188042-1-jesse.huang@sifive.com> MIME-Version: 1.0 X-Spam-Status: No, score=-13.0 required=5.0 tests=BAYES_00, DKIM_SIGNED, DKIM_VALID, DKIM_VALID_AU, DKIM_VALID_EF, GIT_PATCH_0, PROLO_LEO3, RCVD_IN_DNSWL_NONE, SPF_HELO_NONE, SPF_PASS, TXREP, URIBL_BLOCKED shortcircuit=no autolearn=ham autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on sourceware.org X-BeenThere: libc-alpha@sourceware.org X-Mailman-Version: 2.1.30 Precedence: list List-Id: Libc-alpha mailing list List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: libc-alpha-bounces~patchwork=sourceware.org@sourceware.org Landing pads, instructions for setting the label value as well as alignment directives are inserted at where they should be. Frame offsets for floating point registers in _dl_runtime_resolve are also adjusted because now t2 has to be saved onto the stack. Co-authored-by: Hau Hsu Co-authored-by: Kito Cheng Co-authored-by: Jerry Zhang Jian --- sysdeps/riscv/__longjmp.S | 1 + sysdeps/riscv/crti.S | 4 ++ sysdeps/riscv/crtn.S | 4 ++ sysdeps/riscv/dl-machine.h | 8 +++ sysdeps/riscv/dl-trampoline.S | 42 ++++++------ sysdeps/riscv/multiarch/memcpy_noalignment.S | 4 ++ sysdeps/riscv/setjmp.S | 3 + sysdeps/riscv/start.S | 10 +++ sysdeps/riscv/sys/asm.h | 12 +++- sysdeps/unix/sysv/linux/riscv/clone.S | 2 + sysdeps/unix/sysv/linux/riscv/sysdep.S | 1 + sysdeps/unix/sysv/linux/riscv/sysdep.h | 70 ++++++++++++++++++++ sysdeps/unix/sysv/linux/riscv/vfork.S | 1 + 13 files changed, 141 insertions(+), 21 deletions(-) create mode 100644 sysdeps/riscv/crti.S create mode 100644 sysdeps/riscv/crtn.S diff --git a/sysdeps/riscv/__longjmp.S b/sysdeps/riscv/__longjmp.S index bea854199c..f43b0f4c32 100644 --- a/sysdeps/riscv/__longjmp.S +++ b/sysdeps/riscv/__longjmp.S @@ -20,6 +20,7 @@ #include ENTRY (__longjmp) + LPAD REG_L ra, 0*SZREG(a0) REG_L s0, 1*SZREG(a0) REG_L s1, 2*SZREG(a0) diff --git a/sysdeps/riscv/crti.S b/sysdeps/riscv/crti.S new file mode 100644 index 0000000000..fb1097c5ca --- /dev/null +++ b/sysdeps/riscv/crti.S @@ -0,0 +1,4 @@ +/* crti.S is empty because .init_array/.fini_array are used exclusively. + Include sysdep.h to define gnu property if necessary. */ + +#include diff --git a/sysdeps/riscv/crtn.S b/sysdeps/riscv/crtn.S new file mode 100644 index 0000000000..b2e7cb692e --- /dev/null +++ b/sysdeps/riscv/crtn.S @@ -0,0 +1,4 @@ +/* crtn.S is empty because .init_array/.fini_array are used exclusively. + Include sysdep.h to define gnu property if necessary. */ + +#include diff --git a/sysdeps/riscv/dl-machine.h b/sysdeps/riscv/dl-machine.h index babb52af20..05992c8705 100644 --- a/sysdeps/riscv/dl-machine.h +++ b/sysdeps/riscv/dl-machine.h @@ -28,6 +28,13 @@ #include #include #include +/* This is a marker to remind us to add real expansion to setup the label + for the function signature label scheme in the future */ +#ifdef __riscv_landing_pad_unlabeled +# define SET_LPAD +#else +# define SET_LPAD +#endif #ifndef _RTLD_PROLOGUE # define _RTLD_PROLOGUE(entry) \ @@ -127,6 +134,7 @@ elf_machine_dynamic (void) # Pass our finalizer function to _start.\n\ lla a0, _dl_fini\n\ # Jump to the user entry point.\n\ + " STRINGXV (SET_LPAD) "\n\ jr s0\n\ " _RTLD_EPILOGUE (ENTRY_POINT) \ _RTLD_EPILOGUE (_dl_start_user) "\ diff --git a/sysdeps/riscv/dl-trampoline.S b/sysdeps/riscv/dl-trampoline.S index 6c731fcfd4..6e9a0f978c 100644 --- a/sysdeps/riscv/dl-trampoline.S +++ b/sysdeps/riscv/dl-trampoline.S @@ -29,9 +29,11 @@ # define FRAME_SIZE (-((-10 * SZREG) & ALMASK)) #else # define FRAME_SIZE (-((-10 * SZREG - 8 * SZFREG) & ALMASK)) +# define FREG_BASE_OFFSET (10*SZREG) #endif ENTRY (_dl_runtime_resolve) + LPAD # Save arguments to stack. addi sp, sp, -FRAME_SIZE REG_S ra, 9*SZREG(sp) @@ -45,23 +47,23 @@ ENTRY (_dl_runtime_resolve) REG_S a7, 8*SZREG(sp) #ifndef __riscv_float_abi_soft - FREG_S fa0, (10*SZREG + 0*SZFREG)(sp) - FREG_S fa1, (10*SZREG + 1*SZFREG)(sp) - FREG_S fa2, (10*SZREG + 2*SZFREG)(sp) - FREG_S fa3, (10*SZREG + 3*SZFREG)(sp) - FREG_S fa4, (10*SZREG + 4*SZFREG)(sp) - FREG_S fa5, (10*SZREG + 5*SZFREG)(sp) - FREG_S fa6, (10*SZREG + 6*SZFREG)(sp) - FREG_S fa7, (10*SZREG + 7*SZFREG)(sp) + FREG_S fa0, (FREG_BASE_OFFSET + 0*SZFREG)(sp) + FREG_S fa1, (FREG_BASE_OFFSET + 1*SZFREG)(sp) + FREG_S fa2, (FREG_BASE_OFFSET + 2*SZFREG)(sp) + FREG_S fa3, (FREG_BASE_OFFSET + 3*SZFREG)(sp) + FREG_S fa4, (FREG_BASE_OFFSET + 4*SZFREG)(sp) + FREG_S fa5, (FREG_BASE_OFFSET + 5*SZFREG)(sp) + FREG_S fa6, (FREG_BASE_OFFSET + 6*SZFREG)(sp) + FREG_S fa7, (FREG_BASE_OFFSET + 7*SZFREG)(sp) #endif # Update .got.plt and obtain runtime address of callee. slli a1, t1, 1 mv a0, t0 # link map add a1, a1, t1 # reloc offset (== thrice the .got.plt offset) - la a2, _dl_fixup - jalr a2 - mv t1, a0 + la t2, _dl_fixup + jalr t2 + mv t2, a0 # Restore arguments from stack. REG_L ra, 9*SZREG(sp) @@ -75,20 +77,20 @@ ENTRY (_dl_runtime_resolve) REG_L a7, 8*SZREG(sp) #ifndef __riscv_float_abi_soft - FREG_L fa0, (10*SZREG + 0*SZFREG)(sp) - FREG_L fa1, (10*SZREG + 1*SZFREG)(sp) - FREG_L fa2, (10*SZREG + 2*SZFREG)(sp) - FREG_L fa3, (10*SZREG + 3*SZFREG)(sp) - FREG_L fa4, (10*SZREG + 4*SZFREG)(sp) - FREG_L fa5, (10*SZREG + 5*SZFREG)(sp) - FREG_L fa6, (10*SZREG + 6*SZFREG)(sp) - FREG_L fa7, (10*SZREG + 7*SZFREG)(sp) + FREG_L fa0, (FREG_BASE_OFFSET + 0*SZFREG)(sp) + FREG_L fa1, (FREG_BASE_OFFSET + 1*SZFREG)(sp) + FREG_L fa2, (FREG_BASE_OFFSET + 2*SZFREG)(sp) + FREG_L fa3, (FREG_BASE_OFFSET + 3*SZFREG)(sp) + FREG_L fa4, (FREG_BASE_OFFSET + 4*SZFREG)(sp) + FREG_L fa5, (FREG_BASE_OFFSET + 5*SZFREG)(sp) + FREG_L fa6, (FREG_BASE_OFFSET + 6*SZFREG)(sp) + FREG_L fa7, (FREG_BASE_OFFSET + 7*SZFREG)(sp) #endif addi sp, sp, FRAME_SIZE # Invoke the callee. - jr t1 + jr t2 END (_dl_runtime_resolve) #if !defined PROF && defined SHARED diff --git a/sysdeps/riscv/multiarch/memcpy_noalignment.S b/sysdeps/riscv/multiarch/memcpy_noalignment.S index 559e2b21e2..fd1d11239b 100644 --- a/sysdeps/riscv/multiarch/memcpy_noalignment.S +++ b/sysdeps/riscv/multiarch/memcpy_noalignment.S @@ -35,7 +35,11 @@ # define BLOCK_SIZE (16 * SZREG) .attribute unaligned_access, 1 +#ifdef __riscv_landing_pad + .align 2 +#endif ENTRY (__memcpy_noalignment) + LPAD beq a2, zero, L(ret) /* if LEN < SZREG jump to tail handling. */ diff --git a/sysdeps/riscv/setjmp.S b/sysdeps/riscv/setjmp.S index af1910b86d..aecf2d2bab 100644 --- a/sysdeps/riscv/setjmp.S +++ b/sysdeps/riscv/setjmp.S @@ -20,14 +20,17 @@ #include ENTRY (_setjmp) + LPAD li a1, 0 j HIDDEN_JUMPTARGET (__sigsetjmp) END (_setjmp) ENTRY (setjmp) + LPAD li a1, 1 /* Fallthrough */ END (setjmp) ENTRY (__sigsetjmp) + LPAD REG_S ra, 0*SZREG(a0) REG_S s0, 1*SZREG(a0) REG_S s1, 2*SZREG(a0) diff --git a/sysdeps/riscv/start.S b/sysdeps/riscv/start.S index bc3bc04219..c953b1ef51 100644 --- a/sysdeps/riscv/start.S +++ b/sysdeps/riscv/start.S @@ -47,12 +47,14 @@ ENTRY (ENTRY_POINT) .cfi_label to force starting the FDE. */ .cfi_label .Ldummy cfi_undefined (ra) + LPAD call load_gp mv a5, a0 /* rtld_fini. */ /* main may be in a shared library. */ #if defined PIC && !defined SHARED /* Avoid relocation in static PIE since _start is called before it is relocated. */ + SET_LPAD lla a0, __wrap_main #else la a0, main @@ -69,7 +71,11 @@ ENTRY (ENTRY_POINT) END (ENTRY_POINT) #if defined PIC && !defined SHARED +#ifdef __riscv_landing_pad + .align 2 +#endif /* __riscv_landing_pad */ __wrap_main: + LPAD tail main@plt #endif @@ -79,9 +85,13 @@ __wrap_main: needs to be initialized before calling __libc_start_main in that case. So we redundantly initialize it at the beginning of _start. */ +#ifdef __riscv_landing_pad + .align 2 +#endif /* __riscv_landing_pad */ load_gp: .option push .option norelax + LPAD lla gp, __global_pointer$ .option pop ret diff --git a/sysdeps/riscv/sys/asm.h b/sysdeps/riscv/sys/asm.h index 1ca3d46120..54217540f8 100644 --- a/sysdeps/riscv/sys/asm.h +++ b/sysdeps/riscv/sys/asm.h @@ -46,13 +46,23 @@ # endif #endif +/* Landing pad for Zicfilp CFI. */ +#ifndef LPAD +# ifdef __riscv_landing_pad_unlabeled +# define LPAD lpad 0 +# else +# define LPAD +# endif +#endif + /* Declare leaf routine. */ #define LEAF(symbol) \ .globl symbol; \ .align 2; \ .type symbol,@function; \ symbol: \ - cfi_startproc; + cfi_startproc; \ + LPAD; /* Mark end of function. */ #undef END diff --git a/sysdeps/unix/sysv/linux/riscv/clone.S b/sysdeps/unix/sysv/linux/riscv/clone.S index 1ce930a97e..42c26c3675 100644 --- a/sysdeps/unix/sysv/linux/riscv/clone.S +++ b/sysdeps/unix/sysv/linux/riscv/clone.S @@ -31,6 +31,7 @@ .text LEAF (__clone) + LPAD /* Align stack to a 128-bit boundary as per RISC-V ABI. */ andi a1,a1,ALMASK @@ -82,6 +83,7 @@ L (thread_start): REG_L a0,SZREG(sp) /* Argument pointer. */ /* Call the user's function. */ + SET_LPAD jalr a1 /* Call exit with the function's return value. */ diff --git a/sysdeps/unix/sysv/linux/riscv/sysdep.S b/sysdeps/unix/sysv/linux/riscv/sysdep.S index 31947a1c70..05202eedb7 100644 --- a/sysdeps/unix/sysv/linux/riscv/sysdep.S +++ b/sysdeps/unix/sysv/linux/riscv/sysdep.S @@ -23,6 +23,7 @@ #endif ENTRY (__syscall_error) + LPAD mv t0, ra /* Fall through to __syscall_set_errno. */ END (__syscall_error) diff --git a/sysdeps/unix/sysv/linux/riscv/sysdep.h b/sysdeps/unix/sysv/linux/riscv/sysdep.h index 7f0eb07045..761a833609 100644 --- a/sysdeps/unix/sysv/linux/riscv/sysdep.h +++ b/sysdeps/unix/sysv/linux/riscv/sysdep.h @@ -53,6 +53,75 @@ # include +/* GNU_PROPERTY_RISCV_* macros from elf.h for use in asm code. */ +#define FEATURE_1_AND 0xc0000000 + +/* Add a NT_GNU_PROPERTY_TYPE_0 note. */ +#if __riscv_xlen == 32 +# define GNU_PROPERTY(type, value) \ + .section .note.gnu.property, "a"; \ + .p2align 2; \ + .word 4; \ + .word 12; \ + .word 5; \ + .asciz "GNU"; \ + .word type; \ + .word 4; \ + .word value; \ + .text +#else +# define GNU_PROPERTY(type, value) \ + .section .note.gnu.property, "a"; \ + .p2align 3; \ + .word 4; \ + .word 16; \ + .word 5; \ + .asciz "GNU"; \ + .word type; \ + .word 4; \ + .word value; \ + .word 0; \ + .text +#endif + +/* Add GNU property note with the supported features to all asm code + where sysdep.h is included. */ +#undef __VALUE_FOR_FEATURE_1_AND +#if defined (__riscv_landing_pad) || defined (__riscv_shadow_stack) +# if defined (__riscv_landing_pad_unlabeled) +# if defined (__riscv_shadow_stack) +# define __VALUE_FOR_FEATURE_1_AND 0x3 +# else +# define __VALUE_FOR_FEATURE_1_AND 0x1 +# endif +# elif defined (__riscv_landing_pad_func_sig) +# if defined (__riscv_shadow_stack) +# define __VALUE_FOR_FEATURE_1_AND 0x6 +# else +# define __VALUE_FOR_FEATURE_1_AND 0x4 +# endif +# else +# if defined (__riscv_shadow_stack) +# define __VALUE_FOR_FEATURE_1_AND 0x2 +# else +# error "What?" +# endif +# endif +#endif + +#if defined (__VALUE_FOR_FEATURE_1_AND) +GNU_PROPERTY (FEATURE_1_AND, __VALUE_FOR_FEATURE_1_AND) +#endif +#undef __VALUE_FOR_FEATURE_1_AND + +#ifdef __riscv_landing_pad_unlabeled +# define SET_LPAD +# define LPAD lpad 0 +#else +# define SET_LPAD +# define LPAD +#endif + # define ENTRY(name) LEAF(name) # define L(label) .L ## label @@ -111,6 +180,7 @@ # define PSEUDO_NOERRNO(name, syscall_name, args) \ .align 2; \ ENTRY (name); \ + LPAD; \ li a7, SYS_ify (syscall_name); \ scall; diff --git a/sysdeps/unix/sysv/linux/riscv/vfork.S b/sysdeps/unix/sysv/linux/riscv/vfork.S index c1fcec8dd4..90cc523ecb 100644 --- a/sysdeps/unix/sysv/linux/riscv/vfork.S +++ b/sysdeps/unix/sysv/linux/riscv/vfork.S @@ -29,6 +29,7 @@ .text LEAF (__libc_vfork) + LPAD li a0, (CLONE_VFORK | CLONE_VM | SIGCHLD) mv a1, sp From patchwork Tue May 26 06:16:51 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Jesse Huang X-Patchwork-Id: 135658 Return-Path: X-Original-To: patchwork@sourceware.org Delivered-To: patchwork@sourceware.org Received: from vm01.sourceware.org (localhost [IPv6:::1]) by sourceware.org (Postfix) with ESMTP id 38EFF4BA23EF for ; Tue, 26 May 2026 06:22:09 +0000 (GMT) DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org 38EFF4BA23EF Authentication-Results: sourceware.org; dkim=pass (2048-bit key, unprotected) header.d=sifive.com header.i=@sifive.com header.a=rsa-sha256 header.s=google header.b=ca87ZTU/ X-Original-To: libc-alpha@sourceware.org Delivered-To: libc-alpha@sourceware.org Received: from mail-dy1-x1336.google.com (mail-dy1-x1336.google.com [IPv6:2607:f8b0:4864:20::1336]) by sourceware.org (Postfix) with ESMTPS id ABD844BA7990 for ; Tue, 26 May 2026 06:18:00 +0000 (GMT) DMARC-Filter: OpenDMARC Filter v1.4.2 sourceware.org ABD844BA7990 Authentication-Results: sourceware.org; dmarc=pass (p=reject dis=none) header.from=sifive.com Authentication-Results: sourceware.org; spf=pass smtp.mailfrom=sifive.com ARC-Filter: OpenARC Filter v1.0.0 sourceware.org ABD844BA7990 Authentication-Results: sourceware.org; arc=none smtp.remote-ip=2607:f8b0:4864:20::1336 ARC-Seal: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1779776280; cv=none; b=kX9kzxi/W45fBb8Xpceeaw99UpmfC20Iz/FDThhW6GgcOvg1XSbw5wqPGVfiTKLMW+kT2808xXuiFlgFiihi4y6IwyUQTJRMFswHdUd66B98/84MldkdYWLB+jNXbbx0cdLElqqhqr9yAgVQ92xgZjDkWY0gtGRlNqd5tVwZsko= ARC-Message-Signature: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1779776280; c=relaxed/simple; bh=ncDIai4sfUMaigxWDU3X/6L3PwDL/rl5oKGtd1j6m94=; h=DKIM-Signature:From:To:Subject:Date:Message-Id:MIME-Version; b=DSzwakIx89Sdr5FygIwI++aOorZLkaBpn+eYaYmWI66+IK6MDSeaKSp6WN7N0Mdv6MA06SBgCnGlCtCde+i60X4OO9i5TEQIPP+0yElrWUMrULUnPD0nGx7xpla+z1FSs7Xe1tqBYZqRUk/s9QZUZ7aMEEB7nJh5zEcqrlsf/Oc= ARC-Authentication-Results: i=1; sourceware.org; dkim=pass (2048-bit key, unprotected) header.d=sifive.com header.i=@sifive.com header.a=rsa-sha256 header.s=google header.b=ca87ZTU/ DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org ABD844BA7990 Received: by mail-dy1-x1336.google.com with SMTP id 5a478bee46e88-304997cdb21so1434237eec.0 for ; Mon, 25 May 2026 23:18:00 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=sifive.com; s=google; t=1779776280; x=1780381080; darn=sourceware.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to; bh=Fso+UMobvY3ieajkrQs3Jq2Z0ZHALrYUs1EG+kN8zFU=; b=ca87ZTU/jIFRvOv/yf8t83TeV/HeuwfMyTKvir3rn97qSJNKFDZFbzdi6hGL4pZ8rA fskSKNPX06SwFQlpIBGo/yHoncvimAZGwKFT7btuRgWLQia5tZU+HgApU41v/yBYBf74 eKzVa+fFBp33F3QY+B1WEHs2U32SGU+TuXZZPXfCQSN7nHG6nrJS46pJje2bBCRRUk3S 0Jag7QkPFZOqOccSJ58YUk1R/TSNaS5pxDJmJ3v8BvGhZySIGshV33E12iWDDfEdO6aN NlUue+JbByyOWKgoa95Prnvlbe+2bDmuHVQ7Odv/e1YvFbHeD5Cdv9iwv43IcSHQYGtr s2vQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1779776280; x=1780381080; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to; bh=Fso+UMobvY3ieajkrQs3Jq2Z0ZHALrYUs1EG+kN8zFU=; b=lBeoN7j3I+y4kSONCM62dVT7+IcopVv0/lcUvT7UoOuTqE3Mxk5znA48KEhmcuCzYS HqlvIYIuCfmhF6bqMMghbV61B2eNAp5sA9F1GL0hz1orKd1+9VSqbdWrYOwrSTuxZ6rB FacbNDZcncd1oxeZ8b2EYglwLy8CwqGttdQEgqfBo8ASoJ/QdnCoW2+Q2DshEYIwW5HF syO2PhQE0rRt+ItZhswP5VN9MYZ3skj3meX0M1jqNkiep5PuAoQ6u1Uc0dZG6ztkL8DS Sojv4OnuZ+qU6fBbGm/rqcAzzqFDYRVEUyYa1OJc/zRyz/zynYRcHqUhNUvV9r3/UId6 KV8Q== X-Gm-Message-State: AOJu0YzCdq02OJ/1HYFJzAwiakg8mZxCGMbDa+KEaZwO/yI3XTnaaMnV Ej2Bq+Vj/24yagFgUh65gnTU9kNu/VATUj76CzPbn7r6QmIVx6rzGCbBZFUH7i8hZ0J6QmshPWl I+qJ5Tk/0IjK89wvoDfQ7ip01afTmjuJezfclz8rKTkA8AN2pFdGBhY4oJTEkc4YM87rmErke/J ubB2ywQGjw2eBIYZKxyTB5X4KfiZziQdtp25RzrStSwlmM10bk X-Gm-Gg: Acq92OFzOsspR83mcazaLvbTd/bx8q32INWmlFHyqbv7MTf9xpCG4j4PgD7eNGlIPMh Nvo1n3JnWGc7tUxr4CAaR7BKYHt8TSG3jt0z2SUC/BJqAxfQiedAXPXIfVyiPg8R852fvb+Qmka k8cCditUzNc3RAPqF4wvPmUjKJHygA+LiYmb9vejU8Kfz0rmJmVnAPcJkJshDZ0fQb+l5oE0Akr LKKC4j4TK4lTZPVw9Tiz83OJTr8aX29vAzenMY63Ao2Gk6n1BCAkkP1CzeNd3L7Q2TI+CBLA/Zz jiLak5idNCOZk4GtIX1RJPaAhKnjSEhJG9ttX2IFzYJS88a8S5qEniTX/rwWU+TURHH7w2XqVIV YSoOF+87PI6K6iw5i+kGAvf1yNAz83JJi+TxS0f2eKbjYgP+ILzkjDO9ruF+jcTM8oH1nchPc0d 4INx0NNxYivDYWE6tjbC49S9S9omnxRFyWgeEVeAg/ X-Received: by 2002:a05:7301:1f0a:b0:2de:cc07:e83 with SMTP id 5a478bee46e88-304490d3d01mr7653428eec.15.1779776279409; Mon, 25 May 2026 23:17:59 -0700 (PDT) Received: from sw08.internal.sifive.com ([4.53.31.132]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-30452461cb5sm14062504eec.31.2026.05.25.23.17.58 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 25 May 2026 23:17:58 -0700 (PDT) From: Jesse Huang To: libc-alpha@sourceware.org Cc: andrew@sifive.com, darius@bluespec.com, debug@rivosinc.com, jeffreyalaw@gmail.com, kito.cheng@sifive.com, palmer@dabbelt.com, Jesse Huang Subject: [PATCH v4 05/17] riscv: Introduce feature variables for holding RISC-V GNU properties Date: Mon, 25 May 2026 23:16:51 -0700 Message-Id: <20260526061703.2188042-6-jesse.huang@sifive.com> X-Mailer: git-send-email 2.39.3 In-Reply-To: <20260526061703.2188042-1-jesse.huang@sifive.com> References: <20260526061703.2188042-1-jesse.huang@sifive.com> MIME-Version: 1.0 X-Spam-Status: No, score=-13.1 required=5.0 tests=BAYES_00, DKIM_SIGNED, DKIM_VALID, DKIM_VALID_AU, DKIM_VALID_EF, GIT_PATCH_0, KAM_SHORT, RCVD_IN_DNSWL_BLOCKED, SPF_HELO_NONE, SPF_PASS, TXREP, URIBL_BLOCKED shortcircuit=no autolearn=ham autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on sourceware.org X-BeenThere: libc-alpha@sourceware.org X-Mailman-Version: 2.1.30 Precedence: list List-Id: Libc-alpha mailing list List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: libc-alpha-bounces~patchwork=sourceware.org@sourceware.org Member l_riscv_feature_1_and is added to struct link_map, which stores the feature_1_and property information for each object. New global _dl_riscv_feature_1 will be used to store what features are finally enabled for this process. Reviewed-by: Deepak Gupta --- sysdeps/riscv/dl-procruntime.c | 60 ++++++++++++++++++++++++++++++++++ sysdeps/riscv/link_map.h | 22 +++++++++++++ 2 files changed, 82 insertions(+) create mode 100644 sysdeps/riscv/dl-procruntime.c create mode 100644 sysdeps/riscv/link_map.h diff --git a/sysdeps/riscv/dl-procruntime.c b/sysdeps/riscv/dl-procruntime.c new file mode 100644 index 0000000000..06a582920e --- /dev/null +++ b/sysdeps/riscv/dl-procruntime.c @@ -0,0 +1,60 @@ +/* Data for processor runtime information. RISC-V version. + Copyright (C) 2026 Free Software Foundation, Inc. + This file is part of the GNU C Library. + + The GNU C Library is free software; you can redistribute it and/or + modify it under the terms of the GNU Lesser General Public + License as published by the Free Software Foundation; either + version 2.1 of the License, or (at your option) any later version. + + The GNU C Library is distributed in the hope that it will be useful, + but WITHOUT ANY WARRANTY; without even the implied warranty of + MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU + Lesser General Public License for more details. + + You should have received a copy of the GNU Lesser General Public + License along with the GNU C Library; if not, see + . */ + +/* This information must be kept in sync with the _DL_HWCAP_COUNT, + HWCAP_PLATFORMS_START and HWCAP_PLATFORMS_COUNT definitions in + dl-hwcap.h. + + If anything should be added here check whether the size of each string + is still ok with the given array size. + + All the #ifdefs in the definitions are quite irritating but + necessary if we want to avoid duplicating the information. There + are three different modes: + + - PROCINFO_DECL is defined. This means we are only interested in + declarations. + + - PROCINFO_DECL is not defined: + + + if SHARED is defined the file is included in an array + initializer. The .element = { ... } syntax is needed. + + + if SHARED is not defined a normal array initialization is + needed. + */ + +#ifndef PROCINFO_CLASS +# define PROCINFO_CLASS +#endif + +#if !IS_IN (ldconfig) +# if !defined PROCINFO_DECL && defined SHARED + ._dl_riscv_feature_1 +# else +PROCINFO_CLASS unsigned int _dl_riscv_feature_1 +# endif +# ifndef PROCINFO_DECL += 0 +# endif +# if !defined SHARED || defined PROCINFO_DECL +; +# else +, +# endif +#endif diff --git a/sysdeps/riscv/link_map.h b/sysdeps/riscv/link_map.h new file mode 100644 index 0000000000..4a6428bb24 --- /dev/null +++ b/sysdeps/riscv/link_map.h @@ -0,0 +1,22 @@ +/* Additional fields in struct link_map. Linux/RISC-V version. + Copyright (C) 2026 Free Software Foundation, Inc. + This file is part of the GNU C Library. + + The GNU C Library is free software; you can redistribute it and/or + modify it under the terms of the GNU Lesser General Public + License as published by the Free Software Foundation; either + version 2.1 of the License, or (at your option) any later version. + + The GNU C Library is distributed in the hope that it will be useful, + but WITHOUT ANY WARRANTY; without even the implied warranty of + MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU + Lesser General Public License for more details. + + You should have received a copy of the GNU Lesser General Public + License along with the GNU C Library; if not, see + . */ + +/* GNU_PROPERTY_RISCV_FEATURE_1_AND of this object. */ +unsigned int l_riscv_feature_1_and; + +#include From patchwork Tue May 26 06:16:52 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Jesse Huang X-Patchwork-Id: 135659 Return-Path: X-Original-To: patchwork@sourceware.org Delivered-To: patchwork@sourceware.org Received: from vm01.sourceware.org (localhost [IPv6:::1]) by sourceware.org (Postfix) with ESMTP id 0B07C4BA79AA for ; Tue, 26 May 2026 06:22:31 +0000 (GMT) DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org 0B07C4BA79AA Authentication-Results: sourceware.org; dkim=pass (2048-bit key, unprotected) header.d=sifive.com header.i=@sifive.com header.a=rsa-sha256 header.s=google header.b=hhKiHGXm X-Original-To: libc-alpha@sourceware.org Delivered-To: libc-alpha@sourceware.org Received: from mail-dy1-x1336.google.com (mail-dy1-x1336.google.com [IPv6:2607:f8b0:4864:20::1336]) by sourceware.org (Postfix) with ESMTPS id 70E304BA79A1 for ; Tue, 26 May 2026 06:18:02 +0000 (GMT) DMARC-Filter: OpenDMARC Filter v1.4.2 sourceware.org 70E304BA79A1 Authentication-Results: sourceware.org; dmarc=pass (p=reject dis=none) header.from=sifive.com Authentication-Results: sourceware.org; spf=pass smtp.mailfrom=sifive.com ARC-Filter: OpenARC Filter v1.0.0 sourceware.org 70E304BA79A1 Authentication-Results: sourceware.org; arc=none smtp.remote-ip=2607:f8b0:4864:20::1336 ARC-Seal: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1779776282; cv=none; b=JnQLm42DUwqRcyw5gquYWdPEz7Pb/c1ZHN5vZESkiAhW/GFxk5lWV8Moqyn5q64uDVEYamPyl2jpWAl69zeiXk1GItRj4Y8o9jI5Gyro0QtVNBY10ifGU2jFX32Ke9lVwyIH5wMe/4FrMxCzm7O4FQbqvUR7JLZyoyTLJIVX2QA= ARC-Message-Signature: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1779776282; c=relaxed/simple; bh=RDIwUMeHESk0wv8j7+GAqTI3RhsopgJsnJKXBodulyo=; h=DKIM-Signature:From:To:Subject:Date:Message-Id:MIME-Version; b=Dbimngt51mmXTDW5aGMc0h9lIfOBzy7r5gI7l7HjdNV9Q/BgBy1/oOSuFCJfZMuN11xwM3+bBGCC2MGtFw3rr/vRFR4vT1oAFZ743VudaWqgs97EVLllesKlyvXxbMgawbwsjFwq9zCbyTPabNwqKU779IV1GU58nc9Tk5a9p60= ARC-Authentication-Results: i=1; sourceware.org; dkim=pass (2048-bit key, unprotected) header.d=sifive.com header.i=@sifive.com header.a=rsa-sha256 header.s=google header.b=hhKiHGXm DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org 70E304BA79A1 Received: by mail-dy1-x1336.google.com with SMTP id 5a478bee46e88-30455f77e0eso6908156eec.0 for ; Mon, 25 May 2026 23:18:02 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=sifive.com; s=google; t=1779776281; x=1780381081; darn=sourceware.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to; bh=BrFi0O5XNtH7f5Nk5ng1mh9zqw79iodt4J0GIi0xKpo=; b=hhKiHGXm/YS8mtjtGqcibSC+gGlqXYbQ6x4/kygeN7cz8YGNYN1mCs8Butfdqy5Lh9 byDC4qdMAzeu7RxoN+VGRrLLNkNBFcID8hVd+Pa9l+EsIIED3tWLqqemJAwD+PoOW3FZ aUgqVB/wroecuF3p8weyuVL0dGF4ky+OMv6Pxc+Tq8UdNWvFr5K0b2UJr+gj8mMnaMhK 5UU94NulT9rq+FKrTAxKARuVIeFujJjWnoLYgmh1U+4t4ZuRAwuUwy9qVkOHqS0/u5hj J/G/BE4/EEtwYkS7xxO/TVLljx8wrYec7Ti+ciHmtNHKnsUrv7le/Ytq/jn9f4upF8Fm JJvA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1779776281; x=1780381081; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to; bh=BrFi0O5XNtH7f5Nk5ng1mh9zqw79iodt4J0GIi0xKpo=; b=Aue6cgXlHRLxGuvsByQD2qEjF36waux8+1M+TJhneDFTFYGF76B61FmSXnC5LAiVNR Xv2lJxr/OThECu8c49fzMj1cU29KOfHTP1xe8x36iF/VCzkP+ZIYIbqI79wvv/x29+3o dvThePerFedEiDytmk/CIovnHDxTb6rZVZNTtg0IHDJAwBNVpiPjepKC/R5zNwUKl24C 2USTGZ1Q0pT4rLcUK5cvw1SDZWlrYlqHz21tt0NSdwud1cPu3jRu8D/7qUlJnnV8yQD3 D5XWCOTqV8SVLCjEWPy/Yu77IAs/0cJL7KdIu1rNG2WwAZqKPtU3jDaseeCixCDWikOC QbrQ== X-Gm-Message-State: AOJu0YzirNKNrwpo2Y8JHEZgSfQwIVooBZuGZDIxqemjR5SP0sim4l+9 fSJcdAM5tbc7C4zTc5JNRmBaAvaVB4kC64qhnXHJWtDD29+7GlO+t19hbbk4R0MLp1Ef50T58ZZ UJgLiyXbBqGBLMyQkikbseDe30D6hazPI2XLQx74AMydBgpukYHhpPTQae+YpTBCBFTsfvdPyOd Vpmde4lkV/AA33eOw7IUSFw+a1RBLY6rCFmuJ7i/i2p/O3ENgC X-Gm-Gg: Acq92OFeje+pDKBVgBL+FKt+VGTwbpUA2JWHEIKUK9/fIoVJHh/9/ds2BCAK1lrn7p7 Uu0KWJQ0mb0jS31D2qlIEswbsVgtqMpT1IBDNOwYpgOpAyGo6iY0e3CZPsgnqLkSLN/Y6A4sV4t dfsH2J8sjSgSXpKG1T237bNWWR0Xo84JQMJeuqdcvcttdskSIiCZLxzsikKt0yc3k3So8e10ozZ SnthwcpibIlJ6WQyYWN5HnQpjjizynQRD+ZOjCUxHL6PF4JBnngMkRyS7t/QegqWCfykMAH7sS3 6Ar3WLVOkUYnbr0iM1nmHhmGSTh+hLsBFRuayfJuXus+baNyr+n2r/zlMDHMUU/wwhJaDDqr1aQ lEbN4aAGbG7NAJS4qhBqFjgXpvb9TnoCGC8p3Cb4fE8YgJEk27GnMY3RIaM1Jv6RN6s0rZL42nj yEKeqaOhUJuAdldfXDS7Ff4yZhHXgBy9JWGLjTbUaK X-Received: by 2002:a05:7300:3b06:b0:2e6:e504:5431 with SMTP id 5a478bee46e88-30449149080mr8540724eec.22.1779776281311; Mon, 25 May 2026 23:18:01 -0700 (PDT) Received: from sw08.internal.sifive.com ([4.53.31.132]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-30452461cb5sm14062504eec.31.2026.05.25.23.17.59 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 25 May 2026 23:17:59 -0700 (PDT) From: Jesse Huang To: libc-alpha@sourceware.org Cc: andrew@sifive.com, darius@bluespec.com, debug@rivosinc.com, jeffreyalaw@gmail.com, kito.cheng@sifive.com, palmer@dabbelt.com, Jesse Huang Subject: [PATCH v4 06/17] riscv/cfi: Add prctl definitions for RISC-V CFI Date: Mon, 25 May 2026 23:16:52 -0700 Message-Id: <20260526061703.2188042-7-jesse.huang@sifive.com> X-Mailer: git-send-email 2.39.3 In-Reply-To: <20260526061703.2188042-1-jesse.huang@sifive.com> References: <20260526061703.2188042-1-jesse.huang@sifive.com> MIME-Version: 1.0 X-Spam-Status: No, score=-13.1 required=5.0 tests=BAYES_00, DKIM_SIGNED, DKIM_VALID, DKIM_VALID_AU, DKIM_VALID_EF, GIT_PATCH_0, RCVD_IN_DNSWL_BLOCKED, SPF_HELO_NONE, SPF_PASS, TXREP, URIBL_BLOCKED shortcircuit=no autolearn=ham autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on sourceware.org X-BeenThere: libc-alpha@sourceware.org X-Mailman-Version: 2.1.30 Precedence: list List-Id: Libc-alpha mailing list List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: libc-alpha-bounces~patchwork=sourceware.org@sourceware.org These operations are for setting/retrieving/locking the status of the landing pad and the shadow stack extensions. --- .../unix/sysv/linux/riscv/include/asm/prctl.h | 48 +++++++++++++++++++ 1 file changed, 48 insertions(+) create mode 100644 sysdeps/unix/sysv/linux/riscv/include/asm/prctl.h diff --git a/sysdeps/unix/sysv/linux/riscv/include/asm/prctl.h b/sysdeps/unix/sysv/linux/riscv/include/asm/prctl.h new file mode 100644 index 0000000000..091a21b70d --- /dev/null +++ b/sysdeps/unix/sysv/linux/riscv/include/asm/prctl.h @@ -0,0 +1,48 @@ +/* + * Get the current shadow stack configuration for the current thread, + * this will be the value configured via PR_SET_SHADOW_STACK_STATUS. + */ +#define PR_GET_SHADOW_STACK_STATUS 74 + +/* + * Set the current shadow stack configuration. Enabling the shadow + * stack will cause a shadow stack to be allocated for the thread. + */ +#define PR_SET_SHADOW_STACK_STATUS 75 +# define PR_SHADOW_STACK_ENABLE (1UL << 0) +# define PR_SHADOW_STACK_WRITE (1UL << 1) +# define PR_SHADOW_STACK_PUSH (1UL << 2) + +/* + * Prevent further changes to the specified shadow stack + * configuration. All bits may be locked via this call, including + * undefined bits. + */ +#define PR_LOCK_SHADOW_STACK_STATUS 76 + +/* + * Get the current indirect branch tracking configuration for the current + * thread, this will be the value configured via PR_SET_INDIR_BR_LP_STATUS. + */ +#define PR_GET_INDIR_BR_LP_STATUS 79 + +/* + * Set the indirect branch tracking configuration. PR_INDIR_BR_LP_ENABLE will + * enable cpu feature for user thread, to track all indirect branches and ensure + * they land on arch defined landing pad instruction. + * x86 - If enabled, an indirect branch must land on `ENDBRANCH` instruction. + * arch64 - If enabled, an indirect branch must land on `BTI` instruction. + * riscv - If enabled, an indirect branch must land on `lpad` instruction. + * PR_INDIR_BR_LP_DISABLE will disable feature for user thread and indirect + * branches will no more be tracked by cpu to land on arch defined landing pad + * instruction. + */ +#define PR_SET_INDIR_BR_LP_STATUS 80 +# define PR_INDIR_BR_LP_ENABLE (1UL << 0) + +/* + * Prevent further changes to the specified indirect branch tracking + * configuration. All bits may be locked via this call, including + * undefined bits. + */ +#define PR_LOCK_INDIR_BR_LP_STATUS 81 From patchwork Tue May 26 06:16:53 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Jesse Huang X-Patchwork-Id: 135657 Return-Path: X-Original-To: patchwork@sourceware.org Delivered-To: patchwork@sourceware.org Received: from vm01.sourceware.org (localhost [IPv6:::1]) by sourceware.org (Postfix) with ESMTP id 1BD204BA798E for ; Tue, 26 May 2026 06:21:51 +0000 (GMT) DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org 1BD204BA798E Authentication-Results: sourceware.org; dkim=pass (2048-bit key, unprotected) header.d=sifive.com header.i=@sifive.com header.a=rsa-sha256 header.s=google header.b=M/D0qSsP X-Original-To: libc-alpha@sourceware.org Delivered-To: libc-alpha@sourceware.org Received: from mail-dy1-x132b.google.com (mail-dy1-x132b.google.com [IPv6:2607:f8b0:4864:20::132b]) by sourceware.org (Postfix) with ESMTPS id 632994BA23DD for ; Tue, 26 May 2026 06:18:03 +0000 (GMT) DMARC-Filter: OpenDMARC Filter v1.4.2 sourceware.org 632994BA23DD Authentication-Results: sourceware.org; dmarc=pass (p=reject dis=none) header.from=sifive.com Authentication-Results: sourceware.org; spf=pass smtp.mailfrom=sifive.com ARC-Filter: OpenARC Filter v1.0.0 sourceware.org 632994BA23DD Authentication-Results: sourceware.org; arc=none smtp.remote-ip=2607:f8b0:4864:20::132b ARC-Seal: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1779776283; cv=none; b=fLk0BkG/iU5pHk5vtN5t/bwHR0Pj+eAoiui04lWOlRZwH+uhIbKdoa6C/sq+ToRnUV4wBPCCOg9+MqRtrrF+yHcRlfqAD1q6TPDd/sEiNJfFWnQ+tr/qI96Aozc8VTEVeRXyRHA8Ng2tMToqOAkpO/mlsGChSyss6wkFWltLTUg= ARC-Message-Signature: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1779776283; c=relaxed/simple; bh=AbyZMSuWHWFA9/PjrX3Whhp2CvefxdL8u+3qcCltkrs=; h=DKIM-Signature:From:To:Subject:Date:Message-Id:MIME-Version; b=sVasY3ZWByhJKXBp/8DugUVprjs1bo+a8o+HxEp56VfuSAFmyEjjauG0SmbkiMO/RXPXKEckRcTFlyv3vtOiywEg8KJPNRF9ouVJ4f2NFLNKjm9nOSYzq1H4qG6Z/xsiJZQ3rfe4ywP82rm15y6mu37VAVuaru/NvTvv8/h3+aI= ARC-Authentication-Results: i=1; sourceware.org; dkim=pass (2048-bit key, unprotected) header.d=sifive.com header.i=@sifive.com header.a=rsa-sha256 header.s=google header.b=M/D0qSsP DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org 632994BA23DD Received: by mail-dy1-x132b.google.com with SMTP id 5a478bee46e88-3044857f09aso5397082eec.1 for ; Mon, 25 May 2026 23:18:03 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=sifive.com; s=google; t=1779776282; x=1780381082; darn=sourceware.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to; bh=DGQEa2mUQHyet4OMTPj9eXPTnnoR37KsM2CJhIRBxAg=; b=M/D0qSsPhLnob8J63R1CKiEWRXu/rddDhJk3eB5B0imxGm2G76WkNch42zHYLF09rH MZh7idTRcb2t9ZegmJ/nhpi+XqvPsFH78HKTNaqLV6MxDf9vOc4GBWm5d1ChlF9RNhC6 vdaiTRVNxr22uE4CgugjSCa0aoY8/jCPWoNEBg/1o8TOt5/KACMPuafZGpOxHRMQDWZP yAzMLVPMfQFOhWPtghFIZqdM1pnqYV2c0MvPRG0aS94LFwRMApaG4SCl8Fa+C8p/goHt T18lVLSBu5LmLmJB3X3p8DdT0HUea4XdfQJjnou+hDN2ns97HsnjU5DVq4RQsQ2ikJ0T 8aGQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1779776282; x=1780381082; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to; bh=DGQEa2mUQHyet4OMTPj9eXPTnnoR37KsM2CJhIRBxAg=; b=engtQ8hqy9ssco2wrf/5whEu2UueKKzLuMW9SjY6aH+i+AUjFilVv+7MdMn1ATFeAR tHnRkTTN+sbwdOPNknRfdLmZckEa8akf+5jtRS9gNsjjyvdkX5f4KOnWh1+CYBP31Bq4 V9sbQhuvoll+ynYwUcCQKD297dQHSdUCjK87jxi/T79u489KMYlpwCJPe7cJd2AQWi6y fl+xVII8oeLFAdJov/YpiHmMOCcCX+IzrrUj2ELlMrOX8B+pqKC7QovrVuzXxUX5TDDp 3+khXmcXGpT7M5VOBtoCuRc8GYFOhLWMUGJUgUw7scw4zTxjwztGLWDtiEza4fqAxrEE wpBg== X-Gm-Message-State: AOJu0Yyw/YbCUjHEQugOc8R2Qn2NDWSpxrm6wvR9xMr+ht/grUlVxrPZ Ox4VwrCiXl4wx15zRwMqIfltZ6PB0Ui2xUn8p0ZLNqLdohaphN2EHdcxKrK5ju98HsKfV2nyYgN V2JMp0TJmy4ozebVeVx8GjtOYBkrs/CmHeILk9ep/g7Yfb/tBdpH2LrPjWXIlPud282QIDaW/uT G7LZl6xbV3hddHuRsSzfwu2Aseli4NXBDyjQKYuh4rQ5uPHWFY X-Gm-Gg: Acq92OHmUfNRHZzx5ZA9ISNbxx9V6jqE0uaZG36eA0zA04jqDxhlZx0kY5BGqwON17r FaT7hRQwtGLDWftGgtwjOBygx8F7Aab7Bq1Bbf1KcA4LriRZvZ9UYvohw6zWIMoeSM8qb3MuGHv 6GPj+5M8KoGnkiko5jl+fjkcw2wO92xusC8coDXUyn9VNtzT5YfAM3wG3NOCI6gBettX+MAxBFj LEqf4nLBQQACeHnkrcQ7VrCV28M+o3TfbSDhiKSCtL2Me2wFI55JDBLwUalgTKsBJH99He1PT7L oVXvjeHDMkMrF4UafdM7tDDjC2RuIo7Z9B5YKnrXphmoHsi7wT0jpC+UnQwcQ9oivx1nHvMa3hy bSLtQiu+wqKHD+HQ4jE2HTdNHkzZ9TcwspdpGnVtJ8rMbq0B211ZKVSnYV1VspfChCNs6E2LIUx iryepv2I7vMXf/PXmx3kopGiT/dJcGhLeuePNQq7IV X-Received: by 2002:a05:7300:72cd:b0:2f5:3fb3:4a76 with SMTP id 5a478bee46e88-30448f51997mr9205796eec.10.1779776282088; Mon, 25 May 2026 23:18:02 -0700 (PDT) Received: from sw08.internal.sifive.com ([4.53.31.132]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-30452461cb5sm14062504eec.31.2026.05.25.23.18.01 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 25 May 2026 23:18:01 -0700 (PDT) From: Jesse Huang To: libc-alpha@sourceware.org Cc: andrew@sifive.com, darius@bluespec.com, debug@rivosinc.com, jeffreyalaw@gmail.com, kito.cheng@sifive.com, palmer@dabbelt.com, Jesse Huang Subject: [PATCH v4 07/17] riscv/cfi: Enable CFI on static binaries Date: Mon, 25 May 2026 23:16:53 -0700 Message-Id: <20260526061703.2188042-8-jesse.huang@sifive.com> X-Mailer: git-send-email 2.39.3 In-Reply-To: <20260526061703.2188042-1-jesse.huang@sifive.com> References: <20260526061703.2188042-1-jesse.huang@sifive.com> MIME-Version: 1.0 X-Spam-Status: No, score=-13.1 required=5.0 tests=BAYES_00, DKIM_SIGNED, DKIM_VALID, DKIM_VALID_AU, DKIM_VALID_EF, GIT_PATCH_0, KAM_SHORT, RCVD_IN_DNSWL_BLOCKED, SPF_HELO_NONE, SPF_PASS, TXREP, URIBL_BLOCKED shortcircuit=no autolearn=ham autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on sourceware.org X-BeenThere: libc-alpha@sourceware.org X-Mailman-Version: 2.1.30 Precedence: list List-Id: Libc-alpha mailing list List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: libc-alpha-bounces~patchwork=sourceware.org@sourceware.org For static binaries, CFI are enabled inside ARCH_SETUP_TLS, with a macro to enable the shadow stack to prevent underflowing the shadow stack on return, and with a function _dl_cfi_setup_features to enable landing pad. It scans backward of the program header to find the PT_GNU_PROPERTY note first, then enable CFI features corresponding to the feature bits. Co-authored-by: Deepak Gupta --- sysdeps/riscv/Makefile | 1 + sysdeps/riscv/dl-cfi.c | 36 +++++++++++ sysdeps/riscv/dl-machine.h | 6 ++ sysdeps/riscv/dl-prop.h | 65 +++++++++++++++++++ sysdeps/riscv/libc-start.h | 88 ++++++++++++++++++++++++++ sysdeps/unix/sysv/linux/riscv/dl-cfi.h | 20 ++++++ 6 files changed, 216 insertions(+) create mode 100644 sysdeps/riscv/dl-cfi.c create mode 100644 sysdeps/riscv/dl-prop.h create mode 100644 sysdeps/riscv/libc-start.h create mode 100644 sysdeps/unix/sysv/linux/riscv/dl-cfi.h diff --git a/sysdeps/riscv/Makefile b/sysdeps/riscv/Makefile index 99976fddad..4752bdb1a0 100644 --- a/sysdeps/riscv/Makefile +++ b/sysdeps/riscv/Makefile @@ -18,6 +18,7 @@ endif # Enable RISC-V CFI ifeq (yes,$(riscv-enable-cfi)) +sysdep-dl-routines += dl-cfi CFLAGS-.o += -fcf-protection=full CFLAGS-.os += -fcf-protection=full CFLAGS-.op += -fcf-protection=full diff --git a/sysdeps/riscv/dl-cfi.c b/sysdeps/riscv/dl-cfi.c new file mode 100644 index 0000000000..e9beec4b8f --- /dev/null +++ b/sysdeps/riscv/dl-cfi.c @@ -0,0 +1,36 @@ +/* RISC-V CFI extensions (zicfilp/zicfiss) functions. + Copyright (C) 2026 Free Software Foundation, Inc. + + The GNU C Library is free software; you can redistribute it and/or + modify it under the terms of the GNU Lesser General Public + License as published by the Free Software Foundation; either + version 2.1 of the License, or (at your option) any later version. + + The GNU C Library is distributed in the hope that it will be useful, + but WITHOUT ANY WARRANTY; without even the implied warranty of + MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU + Lesser General Public License for more details. + + You should have received a copy of the GNU Lesser General Public + License along with the GNU C Library; if not, see + . */ + +#include +#include +#include +#include +#include +#include + +attribute_hidden void +_dl_cfi_setup_features (unsigned int feature_1) +{ + /* Since prctl could fail to enable some features + use prctl to get enabled features again and sync it back. */ +#ifdef __riscv_landing_pad + if (feature_1 & GNU_PROPERTY_RISCV_FEATURE_1_CFI_LP_UNLABELED) + INTERNAL_SYSCALL_CALL (prctl, PR_SET_INDIR_BR_LP_STATUS, + PR_INDIR_BR_LP_ENABLE, 0, 0, 0); +#endif /* __riscv_landing_pad */ + /* FIXME: Read enabled features from kernel and re-sync */ +} diff --git a/sysdeps/riscv/dl-machine.h b/sysdeps/riscv/dl-machine.h index 05992c8705..b7b9959d58 100644 --- a/sysdeps/riscv/dl-machine.h +++ b/sysdeps/riscv/dl-machine.h @@ -28,6 +28,12 @@ #include #include #include +#if defined(__riscv_landing_pad) || defined(__riscv_shadow_stack) +# include +extern void _dl_cfi_setup_features (unsigned int features); +#else +# define RTLD_START_ENABLE_RISCV_CFI +#endif /* This is a marker to remind us to add real expansion to setup the label for the function signature label scheme in the future */ #ifdef __riscv_landing_pad_unlabeled diff --git a/sysdeps/riscv/dl-prop.h b/sysdeps/riscv/dl-prop.h new file mode 100644 index 0000000000..a183d3148a --- /dev/null +++ b/sysdeps/riscv/dl-prop.h @@ -0,0 +1,65 @@ +/* Support for GNU properties. RISC-V version. + Copyright (C) 2026 Free Software Foundation, Inc. + This file is part of the GNU C Library. + + The GNU C Library is free software; you can redistribute it and/or + modify it under the terms of the GNU Lesser General Public + License as published by the Free Software Foundation; either + version 2.1 of the License, or (at your option) any later version. + + The GNU C Library is distributed in the hope that it will be useful, + but WITHOUT ANY WARRANTY; without even the implied warranty of + MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU + Lesser General Public License for more details. + + You should have received a copy of the GNU Lesser General Public + License along with the GNU C Library; if not, see + . */ + +#ifndef _DL_PROP_H +#define _DL_PROP_H + +static inline void __attribute__ ((always_inline)) +_rtld_main_check (struct link_map *m, const char *program) +{ +} + +static inline void __attribute__ ((always_inline)) +_dl_open_check (struct link_map *m, int dl_openmode) +{ +} + +static inline void __attribute__ ((always_inline)) +_dl_process_pt_note (struct link_map *l, int fd, const ElfW(Phdr) *ph) +{ +} + +static inline int +_dl_process_gnu_property (struct link_map *l, int fd, uint32_t type, + uint32_t datasz, void *data) +{ + /* FIXME: Detect cpu features after we have it implemented in glibc */ + + if (type == GNU_PROPERTY_RISCV_FEATURE_1_AND) + { + /* Stop if the property note is ill-formed. */ + if (datasz != 4) + return -1; + +#if defined(__riscv_landing_pad) || defined(__riscv_shadow_stack) + unsigned int feature_1 = *(unsigned int *) data; +#endif +#ifdef __riscv_landing_pad + if (feature_1 & GNU_PROPERTY_RISCV_FEATURE_1_CFI_LP_UNLABELED) + l->l_riscv_feature_1_and |= GNU_PROPERTY_RISCV_FEATURE_1_CFI_LP_UNLABELED; +#endif +#ifdef __riscv_shadow_stack + if (feature_1 & GNU_PROPERTY_RISCV_FEATURE_1_CFI_SS) + l->l_riscv_feature_1_and |= GNU_PROPERTY_RISCV_FEATURE_1_CFI_SS; +#endif + } + /* Continue. */ + return 1; +} + +#endif /* _DL_PROP_H */ diff --git a/sysdeps/riscv/libc-start.h b/sysdeps/riscv/libc-start.h new file mode 100644 index 0000000000..91d094cfb5 --- /dev/null +++ b/sysdeps/riscv/libc-start.h @@ -0,0 +1,88 @@ +/* RISC-V libc main startup. + Copyright (C) 2026 Free Software Foundation, Inc. + This file is part of the GNU C Library. + + The GNU C Library is free software; you can redistribute it and/or + modify it under the terms of the GNU Lesser General Public + License as published by the Free Software Foundation; either + version 2.1 of the License, or (at your option) any later version. + + The GNU C Library is distributed in the hope that it will be useful, + but WITHOUT ANY WARRANTY; without even the implied warranty of + MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU + Lesser General Public License for more details. + + You should have received a copy of the GNU Lesser General Public + License along with the GNU C Library; if not, see + . */ + +#ifndef SHARED +# define ARCH_SETUP_IREL() apply_irel () +# define ARCH_APPLY_IREL() + +# if defined(__riscv_landing_pad) || defined(__riscv_shadow_stack) +/* Get shadow stack features enabled in the static executable. */ +# include +# include +extern void _dl_cfi_setup_features (unsigned int); + +static inline unsigned int +get_cfi_feature (void) +{ + unsigned int cfi_feature = 0; + /* FIXME: check if cfi feature is supported by CPU */ + struct link_map *main_map = _dl_get_dl_main_map (); + + /* Scan program headers backward to check PT_GNU_PROPERTY early for + feature bits on static executable. */ + const ElfW(Phdr) *phdr = GL(dl_phdr); + const ElfW(Phdr) *ph; + for (ph = phdr + GL(dl_phnum); ph != phdr; ph--) + if (ph[-1].p_type == PT_GNU_PROPERTY) + { + _dl_process_pt_gnu_property (main_map, -1, &ph[-1]); + /* Enable landing pad and shstk only if they are enabled on a static + executable. */ + /* FIXME: change to &= to mask off other features after cpu_feature + is implemented */ + cfi_feature = (main_map->l_riscv_feature_1_and + & (GNU_PROPERTY_RISCV_FEATURE_1_CFI_LP_UNLABELED + | GNU_PROPERTY_RISCV_FEATURE_1_CFI_SS)); + + GL(dl_riscv_feature_1) = cfi_feature; + return cfi_feature; + } + GL(dl_riscv_feature_1) = 0; + return 0; +} + +/* The function using this macro to enable shadow stack must not return + to avoid shadow stack underflow. */ +# ifdef __riscv_shadow_stack +# define ENABLE_RISCV_SHADOW_STACK \ + do \ + { \ + if (feature & GNU_PROPERTY_RISCV_FEATURE_1_CFI_SS) \ + { \ + INTERNAL_SYSCALL_CALL (prctl, PR_SET_SHADOW_STACK_STATUS, \ + PR_SHADOW_STACK_ENABLE, 0, 0, 0); \ + } \ + } \ + while (0) +# else +# define ENABLE_RISCV_SHADOW_STACK +# endif + +# define ARCH_SETUP_TLS() \ + { \ + __libc_setup_tls (); \ + \ + unsigned int feature = get_cfi_feature (); \ + ENABLE_RISCV_SHADOW_STACK; \ + /* Landing pad will be enabled in _dl_cfi_setup_features */ \ + _dl_cfi_setup_features(feature); \ + } +# else +# define ARCH_SETUP_TLS() __libc_setup_tls () +# endif /* __riscv_landing_pad || __riscv_shadow_stack */ +#endif /* !SHARED */ diff --git a/sysdeps/unix/sysv/linux/riscv/dl-cfi.h b/sysdeps/unix/sysv/linux/riscv/dl-cfi.h new file mode 100644 index 0000000000..86ba6eaafb --- /dev/null +++ b/sysdeps/unix/sysv/linux/riscv/dl-cfi.h @@ -0,0 +1,20 @@ +/* Linux/RISC-V CFI initializers function. + Copyright (C) 2026 Free Software Foundation, Inc. + + The GNU C Library is free software; you can redistribute it and/or + modify it under the terms of the GNU Lesser General Public + License as published by the Free Software Foundation; either + version 2.1 of the License, or (at your option) any later version. + + The GNU C Library is distributed in the hope that it will be useful, + but WITHOUT ANY WARRANTY; without even the implied warranty of + MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU + Lesser General Public License for more details. + + You should have received a copy of the GNU Lesser General Public + License along with the GNU C Library; if not, see + . */ + +/* FIXME: Should be remove after they are included in the kernel header */ +#include +#include From patchwork Tue May 26 06:16:54 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Jesse Huang X-Patchwork-Id: 135662 Return-Path: X-Original-To: patchwork@sourceware.org Delivered-To: patchwork@sourceware.org Received: from vm01.sourceware.org (localhost [IPv6:::1]) by sourceware.org (Postfix) with ESMTP id B7D344BA23F7 for ; Tue, 26 May 2026 06:24:32 +0000 (GMT) DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org B7D344BA23F7 Authentication-Results: sourceware.org; dkim=pass (2048-bit key, unprotected) header.d=sifive.com header.i=@sifive.com header.a=rsa-sha256 header.s=google header.b=SqNQ8dmz X-Original-To: libc-alpha@sourceware.org Delivered-To: libc-alpha@sourceware.org Received: from mail-dy1-x132e.google.com (mail-dy1-x132e.google.com [IPv6:2607:f8b0:4864:20::132e]) by sourceware.org (Postfix) with ESMTPS id 181034BA79AC for ; Tue, 26 May 2026 06:18:04 +0000 (GMT) DMARC-Filter: OpenDMARC Filter v1.4.2 sourceware.org 181034BA79AC Authentication-Results: sourceware.org; dmarc=pass (p=reject dis=none) header.from=sifive.com Authentication-Results: sourceware.org; spf=pass smtp.mailfrom=sifive.com ARC-Filter: OpenARC Filter v1.0.0 sourceware.org 181034BA79AC Authentication-Results: sourceware.org; arc=none smtp.remote-ip=2607:f8b0:4864:20::132e ARC-Seal: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1779776284; cv=none; b=UcfswDxcyf7QLI6CjHfE10Nvfd4E73Sdxq1uSm61FosrNePDO9NI73Ih+GPqTxVzgkWlbmJrvCnXow4mlU3I0NmA5xBkZH8KqHlrEKJcYsj8JmzOhA93HUABfpS+EVxCNNlM/4adMgVJvPU4z1dyEVWsnksWeo+XTLUzOSXqhPs= ARC-Message-Signature: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1779776284; c=relaxed/simple; bh=j/1k2W9CTjrWQl6qiApJobo+YuhG14iYNPMhEwY4xRs=; h=DKIM-Signature:From:To:Subject:Date:Message-Id:MIME-Version; b=F79sY/Qs1WrXh+MNo0O609rezBhXe7UxOosjeQvGFQA5flFxnUdfBr8u2kCuoC3TrGdXsStSsbOhfb13JB7cMrAcaaoHgyR5/J98VxHpu9qzuRfHKkqJmXvW/JN6MxuZBAbq/dH/W40DPw/hdKiJgyJSIhSQcEb+gE2ma0Ql7RU= ARC-Authentication-Results: i=1; sourceware.org; dkim=pass (2048-bit key, unprotected) header.d=sifive.com header.i=@sifive.com header.a=rsa-sha256 header.s=google header.b=SqNQ8dmz DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org 181034BA79AC Received: by mail-dy1-x132e.google.com with SMTP id 5a478bee46e88-30455f77e0eso6908187eec.0 for ; Mon, 25 May 2026 23:18:04 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=sifive.com; s=google; t=1779776283; x=1780381083; darn=sourceware.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to; bh=RqMyvKX0npekJb0fNqB0vy2kH4QJcmid9fjWrvKSVG4=; b=SqNQ8dmzmmzE1Xl4USK4Z/3hGgrRXb6VAve9b0CJiNdWHsJFjbPtJvlypaR+fLrzWO 4d2yfEQOiTzoHBM4PfAM27CezdTR4X10c/I8e3M7a3wnXY5mOfmAAq3ZZhniFxcxsQyj xqln5wXdUqPW3In88gkSNl5JH9bbUaxR/6xQQf1aA+EWZdFNZ969uBGsxSeLNVijeb3o 7PP1HAJX8Mlyyzp098ZbcG2HRbR6dZMFF33zjQE8WHDu0Sihf4ePGUz/RRuGe7w9ftdD Jp44IIOsQspod/bDT8klIrwG6KKK7y985qK7YYOsiVdBYtufHnPJg2iOCDeor3JM2KHW rVBQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1779776283; x=1780381083; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to; bh=RqMyvKX0npekJb0fNqB0vy2kH4QJcmid9fjWrvKSVG4=; b=FNzSisVNELGyKG9uEr0x2HwuQWka7etqv4OTPkHD/YD4lTm8U0oDiszdhnCoVXRERB aQGQl9eEKMxNNT6np0CtBIC3vrQLl5x3Jq/z928x5sJmk8rfPXStpoxa5PrNbq+Uzo9w oiEfGjgZVIpVSrEiXNvrj+G/xl3sCjIYlmjeluA/pSQNR966ouPXNkhml3lnRnktqA/K ldRxWVYczffvN9kR0exhpsMQt7TZISwZvdaWx4vR4x1aiZMdpsnUdglzft8dxLctaPjL TxBDSFtaxalGBYIjYrXCMMq9WRxbQmnSD/BCoqGAv0O+9Eg4bSF74c72MMixHwpUZoMJ z8KQ== X-Gm-Message-State: AOJu0Yzd/DYUJ6PLx78ZGRA6Bm+09ayc3oCQon+LuEmuuyaTIzD78jwo eQOeYtboxZKpDMAmSnTzmEp98AZlKHJYhoaL8IKSKPHVV82XcFhwynCYJJU1Gxk1SQzDrs7FfJh DUjfyhzgI1qaXqeDSmYQtteV7kYRk6LOVdPFqFGXnJMKGBXOT9WnelvL/3ot0HqCqkQ20vEwNgt /hBzL7t0KF+Q7ZlqmOZ+E+P27z189GHJ2xhrQPDVUzbZ6w30YOzXI= X-Gm-Gg: Acq92OEdXEw5/5NrVQVaod5uVdnIQyyqNi/sRyU+Nan6756GGixOVSX3PUKmPIQObA1 +GwwJv8BHZjQBgMPF2b+WGOsD2Cwp6eSqjClESzWfDCfHGz+v799OvgqotMNGOsTGyhtWw8OGpY njJARSmE/J/cC5Iz8vBLhgXnqjO9oWjRC9PiLIUIm89hjTGtzYeijp9PKCzSMoYoX/SX/ooV2pt DGjIpoXA1dgK/F9gWiuMeEkRlAkW6vpcXVNn6nxZo4u4tV52YAqFTxBY15xR8iZKUjCXRA9OZ2h srFQqfGUpWO/HPgqCNOPwg7VOdz7v8jA5Pb8dZMZ0HhfGxVU/W6Tl+06T//bPt6axi+diuSwV0r tVIjA6rGxCXWTJVBBj/CrWyF/O7Fikc3HSj80zg3I0r1Z05yh9FTgVqQHzo6QjMA4fBQ/5UZqlD GrIPck6BYTR72q66C7y7y75+cTtUOjPKwCXK2NkOSF X-Received: by 2002:a05:7300:cd85:b0:2d9:ad46:4a92 with SMTP id 5a478bee46e88-3044905ce1emr6895308eec.13.1779776282907; Mon, 25 May 2026 23:18:02 -0700 (PDT) Received: from sw08.internal.sifive.com ([4.53.31.132]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-30452461cb5sm14062504eec.31.2026.05.25.23.18.02 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 25 May 2026 23:18:02 -0700 (PDT) From: Jesse Huang To: libc-alpha@sourceware.org Cc: andrew@sifive.com, darius@bluespec.com, debug@rivosinc.com, jeffreyalaw@gmail.com, kito.cheng@sifive.com, palmer@dabbelt.com, Jesse Huang Subject: [PATCH v4 08/17] riscv/cfi: Enable CFI on dynamic binaries Date: Mon, 25 May 2026 23:16:54 -0700 Message-Id: <20260526061703.2188042-9-jesse.huang@sifive.com> X-Mailer: git-send-email 2.39.3 In-Reply-To: <20260526061703.2188042-1-jesse.huang@sifive.com> References: <20260526061703.2188042-1-jesse.huang@sifive.com> MIME-Version: 1.0 X-Spam-Status: No, score=-13.1 required=5.0 tests=BAYES_00, DKIM_SIGNED, DKIM_VALID, DKIM_VALID_AU, DKIM_VALID_EF, GIT_PATCH_0, RCVD_IN_DNSWL_BLOCKED, SPF_HELO_NONE, SPF_PASS, TXREP, URIBL_BLOCKED shortcircuit=no autolearn=ham autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on sourceware.org X-BeenThere: libc-alpha@sourceware.org X-Mailman-Version: 2.1.30 Precedence: list List-Id: Libc-alpha mailing list List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: libc-alpha-bounces~patchwork=sourceware.org@sourceware.org For dynamic binaries, CFI features are parsed from GNU properties, store in to GLRO(dl_riscv_feature_1) and later enabled in RTLD_START. Co-authored-by: Deepak Gupta --- sysdeps/riscv/Makefile | 2 +- sysdeps/riscv/dl-cfi.c | 72 ++++++++++++++++++++++++++ sysdeps/riscv/dl-machine.h | 2 + sysdeps/riscv/dl-prop.h | 9 ++++ sysdeps/riscv/features-offsets.sym | 5 ++ sysdeps/unix/sysv/linux/riscv/dl-cfi.h | 30 +++++++++++ 6 files changed, 119 insertions(+), 1 deletion(-) create mode 100644 sysdeps/riscv/features-offsets.sym diff --git a/sysdeps/riscv/Makefile b/sysdeps/riscv/Makefile index 4752bdb1a0..11e48be02e 100644 --- a/sysdeps/riscv/Makefile +++ b/sysdeps/riscv/Makefile @@ -3,7 +3,7 @@ sysdep_headers += sys/asm.h endif ifeq ($(subdir),elf) -gen-as-const-headers += dl-link.sym +gen-as-const-headers += dl-link.sym features-offsets.sym endif # RISC-V's assembler also needs to know about PIC as it changes the definition diff --git a/sysdeps/riscv/dl-cfi.c b/sysdeps/riscv/dl-cfi.c index e9beec4b8f..9bb0000103 100644 --- a/sysdeps/riscv/dl-cfi.c +++ b/sysdeps/riscv/dl-cfi.c @@ -22,6 +22,54 @@ #include #include +static void +dl_check_legacy_object (struct link_map *m, unsigned int *feature_1) +{ + /* Iterate through the dependencies and disable if needed here */ + struct link_map *l = NULL; + unsigned int i; + i = m->l_searchlist.r_nlist; + while (i-- > 0) + { + /* Check each shared object to see if shadow stack and landing pad + are enabled. */ + l = m->l_initfini[i]; + + if (l->l_init_called) + continue; + +#ifdef SHARED + /* Skip check for ld.so since it has the features enabled. The + features will be disabled later if they are not enabled in + executable. */ + if (l == &GL(dl_rtld_map) + || l->l_real == &GL(dl_rtld_map)) + continue; +#endif /* SHARED */ + + *feature_1 &= l->l_riscv_feature_1_and; + } +} + +#ifdef SHARED +static void +dl_cfi_check_startup (struct link_map *m, unsigned int *feature_1) +{ + /* FIXME: Add tunables here */ + if (!*feature_1) + return; + dl_check_legacy_object (m, feature_1); + + /* Update GL(dl_riscv_feature_1) */ + GL(dl_riscv_feature_1) = *feature_1; +} +#endif /* SHARED */ + +static void +dl_cfi_check_dlopen (struct link_map *m) +{ +} + attribute_hidden void _dl_cfi_setup_features (unsigned int feature_1) { @@ -34,3 +82,27 @@ _dl_cfi_setup_features (unsigned int feature_1) #endif /* __riscv_landing_pad */ /* FIXME: Read enabled features from kernel and re-sync */ } + +/* Enable CFI for l and its dependencies. */ +void +_dl_cfi_check (struct link_map *l, const char *program) +{ + /* As this point we have parsed the gnu properties, + for dynamic binary we should verify the dependencies here. */ + /* FIXME: Implement different policy for supporting legacy binaries */ + unsigned int feature_1; +#if defined SHARED && defined RTLD_START_ENABLE_RISCV_CFI + if (program) + { + GL(dl_riscv_feature_1) = l->l_riscv_feature_1_and; + feature_1 = l->l_riscv_feature_1_and; + } +#endif /* SHARED */ + +#ifdef SHARED + if (program) + dl_cfi_check_startup (l, &feature_1); + else +#endif /* SHARED */ + dl_cfi_check_dlopen (l); +} diff --git a/sysdeps/riscv/dl-machine.h b/sysdeps/riscv/dl-machine.h index b7b9959d58..b64e7e67d8 100644 --- a/sysdeps/riscv/dl-machine.h +++ b/sysdeps/riscv/dl-machine.h @@ -121,6 +121,8 @@ elf_machine_dynamic (void) " _RTLD_PROLOGUE (_dl_start_user) "\ # Stash user entry point in s0.\n\ mv s0, a0\n\ + # Setup CFI features\n\ + " RTLD_START_ENABLE_RISCV_CFI "\ # Load the adjusted argument count.\n\ " STRINGXP (REG_L) " a1, 0(sp)\n\ # Call _dl_init (struct link_map *main_map, int argc, char **argv, char **env) \n\ diff --git a/sysdeps/riscv/dl-prop.h b/sysdeps/riscv/dl-prop.h index a183d3148a..f6cbf4c59c 100644 --- a/sysdeps/riscv/dl-prop.h +++ b/sysdeps/riscv/dl-prop.h @@ -19,14 +19,23 @@ #ifndef _DL_PROP_H #define _DL_PROP_H +extern void _dl_cfi_check (struct link_map *, const char *) + attribute_hidden; + static inline void __attribute__ ((always_inline)) _rtld_main_check (struct link_map *m, const char *program) { +#if defined(__riscv_landing_pad) || defined(__riscv_shadow_stack) + _dl_cfi_check(m, program); +#endif /* __riscv_landing_pad || __riscv_shadow_stack */ } static inline void __attribute__ ((always_inline)) _dl_open_check (struct link_map *m, int dl_openmode) { +#if defined(__riscv_landing_pad) || defined(__riscv_shadow_stack) + _dl_cfi_check(m, NULL); +#endif /* __riscv_landing_pad || __riscv_shadow_stack */ } static inline void __attribute__ ((always_inline)) diff --git a/sysdeps/riscv/features-offsets.sym b/sysdeps/riscv/features-offsets.sym new file mode 100644 index 0000000000..3320cde83f --- /dev/null +++ b/sysdeps/riscv/features-offsets.sym @@ -0,0 +1,5 @@ +#define SHARED 1 + +#include + +RTLD_GLOBAL_DL_RISCV_FEATURE_1_OFFSET offsetof (struct rtld_global, _dl_riscv_feature_1) diff --git a/sysdeps/unix/sysv/linux/riscv/dl-cfi.h b/sysdeps/unix/sysv/linux/riscv/dl-cfi.h index 86ba6eaafb..53df470930 100644 --- a/sysdeps/unix/sysv/linux/riscv/dl-cfi.h +++ b/sysdeps/unix/sysv/linux/riscv/dl-cfi.h @@ -18,3 +18,33 @@ /* FIXME: Should be remove after they are included in the kernel header */ #include #include +#include + +#ifdef __riscv_shadow_stack +# define CHECK_AND_ENABLE_SHADOW_STACK \ +"\ + andi a0, s1, " STRINGXP (GNU_PROPERTY_RISCV_FEATURE_1_CFI_SS) "\n\ + beqz a0, 1f \n\ + li a0, " STRINGXP (PR_SET_SHADOW_STACK_STATUS) "\n\ + li a1, " STRINGXP (PR_SHADOW_STACK_ENABLE) "\n\ + li a2, 0 \n\ + li a3, 0 \n\ + li a4, 0 \n\ + li a7, " STRINGXP (__NR_prctl) "\n\ + ecall \n\ +1: \n\ +" +#else +# define CHECK_AND_ENABLE_SHADOW_STACK +#endif + +#define RTLD_START_ENABLE_RISCV_CFI \ +"\ + lw s1, _rtld_local + " STRINGXP (RTLD_GLOBAL_DL_RISCV_FEATURE_1_OFFSET) " \n\ + # We need to enable shadow stack in the assembly code to avoid underflow \n\ + # Checking for landing pad is left to _dl_cfi_setup_features \n\ + " CHECK_AND_ENABLE_SHADOW_STACK "\n\ + mv a0, s1 \n\ + jal _dl_cfi_setup_features \n\ + \n\ +" From patchwork Tue May 26 06:16:55 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Jesse Huang X-Patchwork-Id: 135663 Return-Path: X-Original-To: patchwork@sourceware.org Delivered-To: patchwork@sourceware.org Received: from vm01.sourceware.org (localhost [IPv6:::1]) by sourceware.org (Postfix) with ESMTP id CCFA74B9DB5A for ; Tue, 26 May 2026 06:24:53 +0000 (GMT) DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org CCFA74B9DB5A Authentication-Results: sourceware.org; dkim=pass (2048-bit key, unprotected) header.d=sifive.com header.i=@sifive.com header.a=rsa-sha256 header.s=google header.b=Rigkz0ot X-Original-To: libc-alpha@sourceware.org Delivered-To: libc-alpha@sourceware.org Received: from mail-dy1-x132f.google.com (mail-dy1-x132f.google.com [IPv6:2607:f8b0:4864:20::132f]) by sourceware.org (Postfix) with ESMTPS id 295074BA23DF for ; Tue, 26 May 2026 06:18:05 +0000 (GMT) DMARC-Filter: OpenDMARC Filter v1.4.2 sourceware.org 295074BA23DF Authentication-Results: sourceware.org; dmarc=pass (p=reject dis=none) header.from=sifive.com Authentication-Results: sourceware.org; spf=pass smtp.mailfrom=sifive.com ARC-Filter: OpenARC Filter v1.0.0 sourceware.org 295074BA23DF Authentication-Results: sourceware.org; arc=none smtp.remote-ip=2607:f8b0:4864:20::132f ARC-Seal: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1779776285; cv=none; b=EXFaT4IWZYMdZqGFVZ0u1za9X5GhRsDQ3W+MqhIpFpR/+3PzX+C1Lr5Go7icB5cLc39BY5kD3/WS/w20zV3iv3U04KDawQyyf4+1IyeuAdyT2vDm8oRINfTpL8+h2uyPFR4v6YOoUAkM5ODGRuSh5xJS12GA4Fho7qrZuqFvcO0= ARC-Message-Signature: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1779776285; c=relaxed/simple; bh=uahKwbbdyNCPrNijx7RFwV2ldqUt6K6z4bVCNbeVQVg=; h=DKIM-Signature:From:To:Subject:Date:Message-Id:MIME-Version; b=JtUyWd53i/6fh+Vil/d4ja8gRIrWn1RCFT1kpd7C42JwfSize9HLK7W6sHss8pa+jHwXLPUOxQZqp8G09RgWLhGzNi1GmlTbBbRLZiY7x9kOkGMZVt9dQD+qkdLSY6LXmSNlZ2CA+xWIesYVTldVX+u1tdGZHr4nazv2rFOcZdA= ARC-Authentication-Results: i=1; sourceware.org; dkim=pass (2048-bit key, unprotected) header.d=sifive.com header.i=@sifive.com header.a=rsa-sha256 header.s=google header.b=Rigkz0ot DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org 295074BA23DF Received: by mail-dy1-x132f.google.com with SMTP id 5a478bee46e88-2f68f3b075fso1176700eec.0 for ; Mon, 25 May 2026 23:18:05 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=sifive.com; s=google; t=1779776284; x=1780381084; darn=sourceware.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to; bh=gEndWUsXxWl20H8Xh2rQJsEAMDluovz5Ddp/mD9Rn2Q=; b=Rigkz0ottOQ62AmiGDAUqR0Umn7Lbbmf9PTg8gQIakIYrcEZzdFFGVGMZtjjakHr30 sn1Kf2qSFCvm4SD329+M3gwu/DBRp7U3jFob2Ow3njIvHG5u17XnvO1McVfKHtWco3Vf vfNx6PsTD2gdYAcJdM6tFKuJ4w/tK1FwqNAKB0Jx697vf9WbWs9Y26NenxY/yi2eTB7x /z64OfUghiL9c3myQRDue5M+V3f5vWEEqEGVVnU7CE0BSsvZZC6kOE1hIsX8uB2Sxbj6 zmI13IsJK+03BPEq1wxZ5Kav+dz/AtTW/Qv9nq/LiZsJbp8XaAw80qGUfn4T3lIgtc+x /Xsw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1779776284; x=1780381084; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to; bh=gEndWUsXxWl20H8Xh2rQJsEAMDluovz5Ddp/mD9Rn2Q=; b=LRrShDHQNZJARUqJ3LVpSfcZPEvQSsBevzDei4aABw3s3TF3mVgLSpQ7RXvp+CFL2P foyCfOegAuG5zpZG5PKERxEgdlUnkFw1pMCDJYmXcj88/uYgdOXl2O6puV5WrG+pht9R V7eEXLEXstmTPUnUgaF1xkdtI6GBgeiRvMXI7CXVgv1OvWl9HU+G7OO42DZG93RhiMmG yFowFZBxXDCI2tgqgPFmNNG4yTtaMbqPYRHKrcrHG/+QlxYGJZK1YHpNOhFJJUA1gmRy PV7uzAJvpjkP6gdOiE9byGm9duGzfIUgUW1FMFe3uxF4zpTr8bJ0PV84Tn7pAwQ9YJ0I mlJA== X-Gm-Message-State: AOJu0YzFxGIpFwAKakmc+VblTz+bBnI2cxHlkP5fUXxOXP0XyBQgbLXx 06S9NsISZgXqLAp6kSJvzCa47F7HaCMKLHUbLMww0P/lzBOkKMrB6dYImpgwlQ5z54XqUs22cqG eFmQw3vbaat40UUDuA54M5VjGWGVE8LqmZfdi5x4Mwq+vFZ57VJOEo+20Sgz5U2DWs8Pxx1iNeO W8YC0SlzeQPx8K5ePs4peKLjGyMrI0HBufB4+V0zRnnuotQha5G2I= X-Gm-Gg: Acq92OECxvDGdnp7IduZ6qM3mGu4Bl5SFEkcGf3Lfur+aLsmQxjy4301NJIAjAqtJc3 wGK+EdMIWqiJ1a9eUMswUu1La3ZXDfTJEBOdtyfxiYpnGmzpvKh7BN8HcDmzVcw0O5slKpVOXos 9PLOehsLrMf0u6XxLzzLf9oe3FQaHrZUAWX5l3kg1cSElQLWZPXIP7a+mI5hnVETzKR5saNJgTS ub4rXrGhxADYamHVUefCxP+teifiAZppm3Sa1PdLIWgHeAx1YX6BpUS4OjJzm7UaG2IhdWnu+1A GSYd9w7WCKd0U8MGwAXwrCX3bYTq0nF8is+rjlTX9uhPwqOL30Pbp8pAjyRZNX+gKvjmlvGwQga eaeOachwcM6UT+9ZPv0aE0JWDwXJXhvpXUvJtK3O1JYQKSbYbp2AtC4nGJQiSE1kv/cwfFSxbQ5 UYczYUGb5gsTwFk7mOGwiLsNWWEb0s4gWPdAU/b4m9 X-Received: by 2002:a05:7301:9bc8:b0:2be:6f30:f2f9 with SMTP id 5a478bee46e88-30449187ebdmr8544995eec.26.1779776283805; Mon, 25 May 2026 23:18:03 -0700 (PDT) Received: from sw08.internal.sifive.com ([4.53.31.132]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-30452461cb5sm14062504eec.31.2026.05.25.23.18.03 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 25 May 2026 23:18:03 -0700 (PDT) From: Jesse Huang To: libc-alpha@sourceware.org Cc: andrew@sifive.com, darius@bluespec.com, debug@rivosinc.com, jeffreyalaw@gmail.com, kito.cheng@sifive.com, palmer@dabbelt.com, Jesse Huang Subject: [PATCH v4 09/17] riscv/cfi: introduce tunables for CFI features Date: Mon, 25 May 2026 23:16:55 -0700 Message-Id: <20260526061703.2188042-10-jesse.huang@sifive.com> X-Mailer: git-send-email 2.39.3 In-Reply-To: <20260526061703.2188042-1-jesse.huang@sifive.com> References: <20260526061703.2188042-1-jesse.huang@sifive.com> MIME-Version: 1.0 X-Spam-Status: No, score=-13.2 required=5.0 tests=BAYES_00, DKIM_SIGNED, DKIM_VALID, DKIM_VALID_AU, DKIM_VALID_EF, GIT_PATCH_0, KAM_SHORT, RCVD_IN_DNSWL_BLOCKED, SPF_HELO_NONE, SPF_PASS, TXREP, URIBL_BLOCKED shortcircuit=no autolearn=ham autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on sourceware.org X-BeenThere: libc-alpha@sourceware.org X-Mailman-Version: 2.1.30 Precedence: list List-Id: Libc-alpha mailing list List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: libc-alpha-bounces~patchwork=sourceware.org@sourceware.org dl_riscv_feature_control is a structure with each member represents a feature configuration. At this time it's only used by CFI features. Each cfi feature is a 2-bit enum, which could be [on|off|permissive], these values decide whether a new legacy object should be blocked while loaded dynamically, and could be controled by glibc tunables. --- manual/tunables.texi | 22 +++ sysdeps/riscv/Makefile | 1 + sysdeps/riscv/cpu-features.c | 46 ++++++ sysdeps/riscv/cpu-tunables.c | 50 +++++++ sysdeps/riscv/dl-cfi.c | 223 ++++++++++++++++++++++++++-- sysdeps/riscv/dl-get-cpu-features.c | 27 ++++ sysdeps/riscv/dl-machine.h | 19 +++ sysdeps/riscv/dl-procruntime.c | 17 +++ sysdeps/riscv/dl-tunables.list | 27 ++++ sysdeps/riscv/feature-control.h | 42 ++++++ sysdeps/riscv/ldsodefs.h | 1 + sysdeps/riscv/libc-start.c | 31 ++++ sysdeps/riscv/libc-start.h | 13 +- 13 files changed, 500 insertions(+), 19 deletions(-) create mode 100644 sysdeps/riscv/cpu-features.c create mode 100644 sysdeps/riscv/cpu-tunables.c create mode 100644 sysdeps/riscv/dl-get-cpu-features.c create mode 100644 sysdeps/riscv/dl-tunables.list create mode 100644 sysdeps/riscv/feature-control.h create mode 100644 sysdeps/riscv/libc-start.c diff --git a/manual/tunables.texi b/manual/tunables.texi index 12b515c628..9e79762f26 100644 --- a/manual/tunables.texi +++ b/manual/tunables.texi @@ -486,6 +486,28 @@ assume that the CPU is @code{xxx} where xxx may have one of these values: This tunable is specific to aarch64. @end deftp +@deftp Tunable glibc.cpu.riscv_cfi_lp +The @code{glibc.cpu.riscv_cfi_lp=[on|off|permissive]} tunable allows the +user to temporarily turn off the branch control flow protection (a.k.a. +landing pad) or set to permissive mode. The default value is @code{on} for +target compiled with Zicfilp extension. Permissive mode allows the protection +to be turned off on program trying to dynamically load a legacy shared library +without landing pad support. + +This tunable is specific to riscv. +@end deftp + +@deftp Tunable glibc.cpu.riscv_cfi_ss +The @code{glibc.cpu.riscv_cfi_ss=[on|off|permissive]} tunable allows the +user to temporarily turn off the return control flow protection (a.k.a. +shadow stack) or set to permissive mode. The default value is @code{on} for +target compiled with Zicfiss extension. Permissive mode allows the protection +to be turned off on program trying to dynamically load a legacy shared library +without shadow stack support. + +This tunable is specific to riscv. +@end deftp + @deftp Tunable glibc.cpu.x86_data_cache_size The @code{glibc.cpu.x86_data_cache_size} tunable allows the user to set data cache size in bytes for use in memory and string routines. diff --git a/sysdeps/riscv/Makefile b/sysdeps/riscv/Makefile index 11e48be02e..b1f074a3eb 100644 --- a/sysdeps/riscv/Makefile +++ b/sysdeps/riscv/Makefile @@ -1,6 +1,7 @@ ifeq ($(subdir),misc) sysdep_headers += sys/asm.h endif +sysdep-dl-routines += dl-get-cpu-features ifeq ($(subdir),elf) gen-as-const-headers += dl-link.sym features-offsets.sym diff --git a/sysdeps/riscv/cpu-features.c b/sysdeps/riscv/cpu-features.c new file mode 100644 index 0000000000..aed8e9062b --- /dev/null +++ b/sysdeps/riscv/cpu-features.c @@ -0,0 +1,46 @@ +/* Initialize CPU feature data. + This file is part of the GNU C Library. + Copyright (C) 2026 Free Software Foundation, Inc. + + The GNU C Library is free software; you can redistribute it and/or + modify it under the terms of the GNU Lesser General Public + License as published by the Free Software Foundation; either + version 2.1 of the License, or (at your option) any later version. + + The GNU C Library is distributed in the hope that it will be useful, + but WITHOUT ANY WARRANTY; without even the implied warranty of + MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU + Lesser General Public License for more details. + + You should have received a copy of the GNU Lesser General Public + License along with the GNU C Library; if not, see + . */ + +#ifndef _CPU_FEATURES_RISCV_H +#define _CPU_FEATURES_RISCV_H + +# define TUNABLE_NAMESPACE cpu +# include + +# ifdef __riscv_landing_pad +extern void TUNABLE_CALLBACK (set_riscv_cfi_lp) (tunable_val_t *) + attribute_hidden; +# endif +# ifdef __riscv_shadow_stack +extern void TUNABLE_CALLBACK (set_riscv_cfi_ss) (tunable_val_t *) + attribute_hidden; +# endif + +static inline void +init_cpu_features (void) +{ +# ifdef __riscv_landing_pad + TUNABLE_GET (riscv_cfi_lp, tunable_val_t *, + TUNABLE_CALLBACK (set_riscv_cfi_lp)); +# endif +# ifdef __riscv_shadow_stack + TUNABLE_GET (riscv_cfi_ss, tunable_val_t *, + TUNABLE_CALLBACK (set_riscv_cfi_ss)); +# endif +} +#endif /* _CPU_FEATURES_RISCV_H */ diff --git a/sysdeps/riscv/cpu-tunables.c b/sysdeps/riscv/cpu-tunables.c new file mode 100644 index 0000000000..84ef911866 --- /dev/null +++ b/sysdeps/riscv/cpu-tunables.c @@ -0,0 +1,50 @@ +/* RISC-V CPU feature tuning. + This file is part of the GNU C Library. + Copyright (C) 2026 Free Software Foundation, Inc. + + The GNU C Library is free software; you can redistribute it and/or + modify it under the terms of the GNU Lesser General Public + License as published by the Free Software Foundation; either + version 2.1 of the License, or (at your option) any later version. + + The GNU C Library is distributed in the hope that it will be useful, + but WITHOUT ANY WARRANTY; without even the implied warranty of + MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU + Lesser General Public License for more details. + + You should have received a copy of the GNU Lesser General Public + License along with the GNU C Library; if not, see + . */ + +#define TUNABLE_NAMESPACE cpu +#include +#include +#include + +#ifdef __riscv_landing_pad +attribute_hidden +void +TUNABLE_CALLBACK (set_riscv_cfi_lp) (tunable_val_t *valp) +{ + if (tunable_strcmp_cte (valp, "permissive")) + GL(dl_riscv_feature_control).lp = cfi_permissive; + else if (tunable_strcmp_cte (valp, "off")) + GL(dl_riscv_feature_control).lp = cfi_always_off; + else + GL(dl_riscv_feature_control).lp = cfi_always_on; +} +#endif + +#ifdef __riscv_shadow_stack +attribute_hidden +void +TUNABLE_CALLBACK (set_riscv_cfi_ss) (tunable_val_t *valp) +{ + if (tunable_strcmp_cte (valp, "permissive")) + GL(dl_riscv_feature_control).ss = cfi_permissive; + else if (tunable_strcmp_cte (valp, "off")) + GL(dl_riscv_feature_control).ss = cfi_always_off; + else + GL(dl_riscv_feature_control).ss = cfi_always_on; +} +#endif diff --git a/sysdeps/riscv/dl-cfi.c b/sysdeps/riscv/dl-cfi.c index 9bb0000103..275faddcc9 100644 --- a/sysdeps/riscv/dl-cfi.c +++ b/sysdeps/riscv/dl-cfi.c @@ -15,6 +15,7 @@ License along with the GNU C Library; if not, see . */ +#include "feature-control.h" #include #include #include @@ -22,8 +23,39 @@ #include #include +struct dl_cfi_info +{ + const char *program; + + /* Check how lp and ss should be enabled. */ +#ifdef __riscv_landing_pad + enum dl_riscv_cfi_control enable_lp_type; +#endif +#ifdef __riscv_shadow_stack + enum dl_riscv_cfi_control enable_ss_type; +#endif + + /* Previously enabled features. */ + unsigned int feature_1_enabled; + + /* Features that should be enabled. */ + unsigned int enable_feature_1; + + /* If there are any legacy shared object. */ + unsigned int feature_1_legacy; + + /* Which shared object is the first legacy shared object. */ +#ifdef __riscv_landing_pad + unsigned int feature_1_legacy_lp; +#endif +#ifdef __riscv_shadow_stack + unsigned int feature_1_legacy_ss; +#endif +}; + + static void -dl_check_legacy_object (struct link_map *m, unsigned int *feature_1) +dl_check_legacy_object (struct link_map *m, struct dl_cfi_info *info) { /* Iterate through the dependencies and disable if needed here */ struct link_map *l = NULL; @@ -42,32 +74,150 @@ dl_check_legacy_object (struct link_map *m, unsigned int *feature_1) /* Skip check for ld.so since it has the features enabled. The features will be disabled later if they are not enabled in executable. */ - if (l == &GL(dl_rtld_map) - || l->l_real == &GL(dl_rtld_map)) + if (is_rtld_link_map (l) + || is_rtld_link_map (l->l_real) + || (info->program != NULL && l == m)) continue; #endif /* SHARED */ - *feature_1 &= l->l_riscv_feature_1_and; + info->enable_feature_1 &= ((l->l_riscv_feature_1_and + & (GNU_PROPERTY_RISCV_FEATURE_1_CFI_LP_UNLABELED + | GNU_PROPERTY_RISCV_FEATURE_1_CFI_SS)) + | ~(GNU_PROPERTY_RISCV_FEATURE_1_CFI_LP_UNLABELED + | GNU_PROPERTY_RISCV_FEATURE_1_CFI_SS)); + + /* Bookkeeping legacy objects */ +#ifdef __riscv_landing_pad + if ((info->feature_1_legacy & GNU_PROPERTY_RISCV_FEATURE_1_CFI_LP_UNLABELED) == 0 + && ((info->enable_feature_1 & GNU_PROPERTY_RISCV_FEATURE_1_CFI_LP_UNLABELED) + != (info->feature_1_enabled & GNU_PROPERTY_RISCV_FEATURE_1_CFI_LP_UNLABELED)) + ) + { + info->feature_1_legacy_lp = i; + info->feature_1_legacy |= GNU_PROPERTY_RISCV_FEATURE_1_CFI_LP_UNLABELED; + } +#endif +#ifdef __riscv_shadow_stack + if ((info->feature_1_legacy & GNU_PROPERTY_RISCV_FEATURE_1_CFI_SS) == 0 + && ((info->enable_feature_1 & GNU_PROPERTY_RISCV_FEATURE_1_CFI_SS) + != (info->feature_1_enabled & GNU_PROPERTY_RISCV_FEATURE_1_CFI_SS)) + ) + { + info->feature_1_legacy_ss = i; + info->feature_1_legacy |= GNU_PROPERTY_RISCV_FEATURE_1_CFI_SS; + } +#endif } + + /* Keep bits set if cfi_always_on */ +#ifdef __riscv_landing_pad + if ((info->feature_1_enabled & GNU_PROPERTY_RISCV_FEATURE_1_CFI_LP_UNLABELED) != 0 + && info->enable_lp_type == cfi_always_on) + { + info->enable_feature_1 |= GNU_PROPERTY_RISCV_FEATURE_1_CFI_LP_UNLABELED; + } +#endif +#ifdef __riscv_shadow_stack + if ((info->feature_1_enabled & GNU_PROPERTY_RISCV_FEATURE_1_CFI_SS) != 0 + && info->enable_ss_type == cfi_always_on) + { + info->enable_feature_1 |= GNU_PROPERTY_RISCV_FEATURE_1_CFI_SS; + } +#endif } #ifdef SHARED static void -dl_cfi_check_startup (struct link_map *m, unsigned int *feature_1) +dl_cfi_check_startup (struct link_map *m, struct dl_cfi_info *info) { - /* FIXME: Add tunables here */ - if (!*feature_1) - return; - dl_check_legacy_object (m, feature_1); +# ifdef __riscv_landing_pad + if (info->enable_lp_type == cfi_always_on) + info->enable_feature_1 |= GNU_PROPERTY_RISCV_FEATURE_1_CFI_LP_UNLABELED; + else if (info->enable_lp_type == cfi_always_off) + info->enable_feature_1 &= ~GNU_PROPERTY_RISCV_FEATURE_1_CFI_LP_UNLABELED; + else + info->enable_feature_1 &= ((m->l_riscv_feature_1_and + & GNU_PROPERTY_RISCV_FEATURE_1_CFI_LP_UNLABELED) + | ~GNU_PROPERTY_RISCV_FEATURE_1_CFI_LP_UNLABELED); +# endif +# ifdef __riscv_shadow_stack + if (info->enable_ss_type == cfi_always_on) + info->enable_feature_1 |= GNU_PROPERTY_RISCV_FEATURE_1_CFI_SS; + else if (info->enable_ss_type == cfi_always_off) + info->enable_feature_1 &= ~GNU_PROPERTY_RISCV_FEATURE_1_CFI_SS; + else + info->enable_feature_1 &= ((m->l_riscv_feature_1_and + & GNU_PROPERTY_RISCV_FEATURE_1_CFI_SS) + | ~GNU_PROPERTY_RISCV_FEATURE_1_CFI_SS); +# endif + + if (info->enable_feature_1 != 0) + dl_check_legacy_object (m, info); /* Update GL(dl_riscv_feature_1) */ - GL(dl_riscv_feature_1) = *feature_1; + if (info->enable_feature_1 ^ info->feature_1_enabled) { + info->feature_1_enabled = info->enable_feature_1; + GL(dl_riscv_feature_1) = info->enable_feature_1; + } } #endif /* SHARED */ static void -dl_cfi_check_dlopen (struct link_map *m) +dl_cfi_check_dlopen (struct link_map *m, struct dl_cfi_info *info) { + if (info->enable_feature_1 != 0) { + dl_check_legacy_object(m, info); + + if (info->feature_1_legacy == 0) + return; + } + + unsigned int disable_feature_1 = 0; + unsigned int legacy_obj = 0; + const char *msg = NULL; + +#ifdef __riscv_landing_pad + if ((info->feature_1_enabled & GNU_PROPERTY_RISCV_FEATURE_1_CFI_LP_UNLABELED) != 0 + && (info->feature_1_legacy & GNU_PROPERTY_RISCV_FEATURE_1_CFI_LP_UNLABELED) != 0) + { + if (info->enable_lp_type != cfi_permissive || !SINGLE_THREAD_P) + { + legacy_obj = info->feature_1_legacy_lp; + msg = N_("rebuild shared object with landing pad support"); + } + else + disable_feature_1 |= GNU_PROPERTY_RISCV_FEATURE_1_CFI_LP_UNLABELED; + } +#endif + +#ifdef __riscv_shadow_stack + if ((info->feature_1_enabled & GNU_PROPERTY_RISCV_FEATURE_1_CFI_SS) != 0 + && (info->feature_1_legacy & GNU_PROPERTY_RISCV_FEATURE_1_CFI_SS) != 0) + { + if (info->enable_ss_type != cfi_permissive || !SINGLE_THREAD_P) + { + legacy_obj = info->feature_1_legacy_ss; + msg = N_("rebuild shared object with shadow stack support"); + } + else + disable_feature_1 |= GNU_PROPERTY_RISCV_FEATURE_1_CFI_SS; + } +#endif + + if (msg != NULL) + _dl_signal_error (0, m->l_initfini[legacy_obj]->l_name, "dlopen", msg); + + if (disable_feature_1 != 0) + // FIXME: Disable CFI here + int res = -1; + if (res) + { + msg = N_("can't disable CFI feature"); + _dl_signal_error (-res, m->l_initfini[legacy_obj]->l_name, + "dlopen", msg); + } + GL(dl_riscv_feature_1) &= ~disable_feature_1; + } } attribute_hidden void @@ -89,20 +239,61 @@ _dl_cfi_check (struct link_map *l, const char *program) { /* As this point we have parsed the gnu properties, for dynamic binary we should verify the dependencies here. */ - /* FIXME: Implement different policy for supporting legacy binaries */ - unsigned int feature_1; + struct dl_cfi_info info; #if defined SHARED && defined RTLD_START_ENABLE_RISCV_CFI if (program) { GL(dl_riscv_feature_1) = l->l_riscv_feature_1_and; - feature_1 = l->l_riscv_feature_1_and; } #endif /* SHARED */ + unsigned int supported_exts = 0; + unsigned int always_on_exts = 0; + +#ifdef __riscv_landing_pad + info.enable_lp_type = GL(dl_riscv_feature_control).lp; + supported_exts += 1; + always_on_exts += (info.enable_lp_type == cfi_always_on); +#endif +#ifdef __riscv_shadow_stack + info.enable_ss_type = GL(dl_riscv_feature_control).ss; + supported_exts += 1; + always_on_exts += (info.enable_ss_type == cfi_always_on); +#endif + + info.feature_1_enabled = GL(dl_riscv_feature_1); + + /* No legacy check needed if all cfi exts are always on in main */ + if (program && (supported_exts == always_on_exts)) + return; + + /* No legacy check needed if all cfi exts are off */ + if (info.feature_1_enabled == 0) + return; + + info.program = program; + + info.enable_feature_1 = 0; +#ifdef __riscv_landing_pad + if (info.enable_lp_type != cfi_always_off) + info.enable_feature_1 |= (info.feature_1_enabled + & GNU_PROPERTY_RISCV_FEATURE_1_CFI_LP_UNLABELED); + info.feature_1_legacy_lp = 0; +#endif +#ifdef __riscv_shadow_stack + if (info.enable_ss_type != cfi_always_off) + info.enable_feature_1 |= (info.feature_1_enabled + & GNU_PROPERTY_RISCV_FEATURE_1_CFI_SS); + info.feature_1_legacy_ss = 0; +#endif + + info.feature_1_enabled = GL(dl_riscv_feature_1); + info.feature_1_legacy = 0; + #ifdef SHARED if (program) - dl_cfi_check_startup (l, &feature_1); + dl_cfi_check_startup (l, &info); else #endif /* SHARED */ - dl_cfi_check_dlopen (l); + dl_cfi_check_dlopen (l, &info); } diff --git a/sysdeps/riscv/dl-get-cpu-features.c b/sysdeps/riscv/dl-get-cpu-features.c new file mode 100644 index 0000000000..bdb805d417 --- /dev/null +++ b/sysdeps/riscv/dl-get-cpu-features.c @@ -0,0 +1,27 @@ +/* Initialize CPU feature data. + Copyright (C) 2026 Free Software Foundation, Inc. + + The GNU C Library is free software; you can redistribute it and/or + modify it under the terms of the GNU Lesser General Public + License as published by the Free Software Foundation; either + version 2.1 of the License, or (at your option) any later version. + + The GNU C Library is distributed in the hope that it will be useful, + but WITHOUT ANY WARRANTY; without even the implied warranty of + MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU + Lesser General Public License for more details. + + You should have received a copy of the GNU Lesser General Public + License along with the GNU C Library; if not, see + . */ + +#include + +#ifdef SHARED +# include +void +_dl_riscv_init_cpu_features (void) +{ + init_cpu_features (); +} +#endif diff --git a/sysdeps/riscv/dl-machine.h b/sysdeps/riscv/dl-machine.h index b64e7e67d8..01422e01d9 100644 --- a/sysdeps/riscv/dl-machine.h +++ b/sysdeps/riscv/dl-machine.h @@ -41,6 +41,7 @@ extern void _dl_cfi_setup_features (unsigned int features); #else # define SET_LPAD #endif +extern void _dl_riscv_init_cpu_features (void); #ifndef _RTLD_PROLOGUE # define _RTLD_PROLOGUE(entry) \ @@ -153,6 +154,24 @@ elf_machine_dynamic (void) #define ARCH_LA_PLTENTER riscv_gnu_pltenter #define ARCH_LA_PLTEXIT riscv_gnu_pltexit +/* We define an initialization function. This is called very early in + _dl_sysdep_start. */ +#define DL_PLATFORM_INIT dl_platform_init () + +static inline void __attribute__ ((unused)) +dl_platform_init (void) +{ + if (GLRO(dl_platform) != NULL && *GLRO(dl_platform) == '\0') + /* Avoid an empty string which would disturb us. */ + GLRO(dl_platform) = NULL; + +#ifdef SHARED + /* init_cpu_features which has been called early from __libc_start_main in + static executable. */ + _dl_riscv_init_cpu_features (); +#endif +} + /* Bias .got.plt entry by the offset requested by the PLT header. */ #define elf_machine_plt_value(map, reloc, value) (value) diff --git a/sysdeps/riscv/dl-procruntime.c b/sysdeps/riscv/dl-procruntime.c index 06a582920e..c35473a961 100644 --- a/sysdeps/riscv/dl-procruntime.c +++ b/sysdeps/riscv/dl-procruntime.c @@ -57,4 +57,21 @@ PROCINFO_CLASS unsigned int _dl_riscv_feature_1 # else , # endif + +# if !defined PROCINFO_DECL && defined SHARED + ._dl_riscv_feature_control +# else +PROCINFO_CLASS struct dl_riscv_feature_control _dl_riscv_feature_control +# endif +# ifndef PROCINFO_DECL += { + .lp = cfi_always_on, + .ss = cfi_always_on, + } +# endif +# if !defined SHARED || defined PROCINFO_DECL +; +# else +, +# endif #endif diff --git a/sysdeps/riscv/dl-tunables.list b/sysdeps/riscv/dl-tunables.list new file mode 100644 index 0000000000..f301219c19 --- /dev/null +++ b/sysdeps/riscv/dl-tunables.list @@ -0,0 +1,27 @@ +# RISC-V specific tunables. +# Copyright (C) 2026 Free Software Foundation, Inc. +# This file is part of the GNU C Library. + +# The GNU C Library is free software; you can redistribute it and/or +# modify it under the terms of the GNU Lesser General Public +# License as published by the Free Software Foundation; either +# version 2.1 of the License, or (at your option) any later version. + +# The GNU C Library is distributed in the hope that it will be useful, +# but WITHOUT ANY WARRANTY; without even the implied warranty of +# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU +# Lesser General Public License for more details. + +# You should have received a copy of the GNU Lesser General Public +# License along with the GNU C Library; if not, see +# . + +glibc { + cpu { + riscv_cfi_lp { + type: STRING + } + riscv_cfi_ss { + type: STRING + } +} diff --git a/sysdeps/riscv/feature-control.h b/sysdeps/riscv/feature-control.h new file mode 100644 index 0000000000..9d24f4798b --- /dev/null +++ b/sysdeps/riscv/feature-control.h @@ -0,0 +1,42 @@ +/* RISC-V feature tuning. + This file is part of the GNU C Library. + Copyright (C) 2026 Free Software Foundation, Inc. + + The GNU C Library is free software; you can redistribute it and/or + modify it under the terms of the GNU Lesser General Public + License as published by the Free Software Foundation; either + version 2.1 of the License, or (at your option) any later version. + + The GNU C Library is distributed in the hope that it will be useful, + but WITHOUT ANY WARRANTY; without even the implied warranty of + MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU + Lesser General Public License for more details. + + You should have received a copy of the GNU Lesser General Public + License along with the GNU C Library; if not, see + . */ + +#ifndef _RISCV_FEATURE_CONTROL_H +#define _RISCV_FEATURE_CONTROL_H + +/* For each CFI feature, LP and SS, valid control values. */ +enum dl_riscv_cfi_control +{ + /* Enable CFI features based on ELF property note. */ + cfi_elf_property = 0, + /* Always enable CFI features. */ + cfi_always_on, + /* Always disable CFI features. */ + cfi_always_off, + /* Enable CFI features permissively. */ + cfi_permissive +}; + +struct dl_riscv_feature_control +{ + enum dl_riscv_cfi_control lp : 2; + enum dl_riscv_cfi_control ss : 2; +}; + +#endif /* feature-control.h */ + diff --git a/sysdeps/riscv/ldsodefs.h b/sysdeps/riscv/ldsodefs.h index 6a9422f13d..d1d3ebd131 100644 --- a/sysdeps/riscv/ldsodefs.h +++ b/sysdeps/riscv/ldsodefs.h @@ -20,6 +20,7 @@ #define _RISCV_LDSODEFS_H 1 #include +#include struct La_riscv_regs; struct La_riscv_retval; diff --git a/sysdeps/riscv/libc-start.c b/sysdeps/riscv/libc-start.c new file mode 100644 index 0000000000..2e00ce1b55 --- /dev/null +++ b/sysdeps/riscv/libc-start.c @@ -0,0 +1,31 @@ +/* Copyright (C) 2026 Free Software Foundation, Inc. + This file is part of the GNU C Library. + + The GNU C Library is free software; you can redistribute it and/or + modify it under the terms of the GNU Lesser General Public + License as published by the Free Software Foundation; either + version 2.1 of the License, or (at your option) any later version. + + The GNU C Library is distributed in the hope that it will be useful, + but WITHOUT ANY WARRANTY; without even the implied warranty of + MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU + Lesser General Public License for more details. + + You should have received a copy of the GNU Lesser General Public + License along with the GNU C Library; if not, see + . */ + +#ifndef SHARED + +/* Mark symbols hidden in static PIE for early self relocation to work. */ +# if BUILD_PIE_DEFAULT +# pragma GCC visibility push(hidden) +# endif +# include +# include + +# define ARCH_INIT_CPU_FEATURES() init_cpu_features () + +#endif /* !SHARED */ +#include + diff --git a/sysdeps/riscv/libc-start.h b/sysdeps/riscv/libc-start.h index 91d094cfb5..f873e1ee2e 100644 --- a/sysdeps/riscv/libc-start.h +++ b/sysdeps/riscv/libc-start.h @@ -31,6 +31,15 @@ get_cfi_feature (void) { unsigned int cfi_feature = 0; /* FIXME: check if cfi feature is supported by CPU */ + +#ifdef __riscv_landing_pad + if (GL(dl_riscv_feature_control).lp != cfi_always_off) + cfi_feature |= GNU_PROPERTY_RISCV_FEATURE_1_CFI_LP_UNLABELED; +#endif +#ifdef __riscv_shadow_stack + if (GL(dl_riscv_feature_control).ss != cfi_always_off) + cfi_feature |= GNU_PROPERTY_RISCV_FEATURE_1_CFI_SS; +#endif struct link_map *main_map = _dl_get_dl_main_map (); /* Scan program headers backward to check PT_GNU_PROPERTY early for @@ -43,9 +52,7 @@ get_cfi_feature (void) _dl_process_pt_gnu_property (main_map, -1, &ph[-1]); /* Enable landing pad and shstk only if they are enabled on a static executable. */ - /* FIXME: change to &= to mask off other features after cpu_feature - is implemented */ - cfi_feature = (main_map->l_riscv_feature_1_and + cfi_feature &= (main_map->l_riscv_feature_1_and & (GNU_PROPERTY_RISCV_FEATURE_1_CFI_LP_UNLABELED | GNU_PROPERTY_RISCV_FEATURE_1_CFI_SS)); From patchwork Tue May 26 06:16:56 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Jesse Huang X-Patchwork-Id: 135660 Return-Path: X-Original-To: patchwork@sourceware.org Delivered-To: patchwork@sourceware.org Received: from vm01.sourceware.org (localhost [IPv6:::1]) by sourceware.org (Postfix) with ESMTP id 229664BA23E1 for ; Tue, 26 May 2026 06:22:36 +0000 (GMT) DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org 229664BA23E1 Authentication-Results: sourceware.org; dkim=pass (2048-bit key, unprotected) header.d=sifive.com header.i=@sifive.com header.a=rsa-sha256 header.s=google header.b=mkqpEnIH X-Original-To: libc-alpha@sourceware.org Delivered-To: libc-alpha@sourceware.org Received: from mail-dl1-x122b.google.com (mail-dl1-x122b.google.com [IPv6:2607:f8b0:4864:20::122b]) by sourceware.org (Postfix) with ESMTPS id 1282F4BA79A9 for ; Tue, 26 May 2026 06:18:06 +0000 (GMT) DMARC-Filter: OpenDMARC Filter v1.4.2 sourceware.org 1282F4BA79A9 Authentication-Results: sourceware.org; dmarc=pass (p=reject dis=none) header.from=sifive.com Authentication-Results: sourceware.org; spf=pass smtp.mailfrom=sifive.com ARC-Filter: OpenARC Filter v1.0.0 sourceware.org 1282F4BA79A9 Authentication-Results: sourceware.org; arc=none smtp.remote-ip=2607:f8b0:4864:20::122b ARC-Seal: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1779776286; cv=none; b=rf9uRKcD2QNCEvc8opEzOgLPd1ucUNLCIh8V1tZu+RqrRTg/kF6GIqzIrpn+R4+5HzVOzVbuF69c6qlqWseIp+UUzqMudCtRWWGEdJ41ORg+8n5O6NcFVig2i8KCAdfM03Zl+VeTAI0em47Lr5R0OvJqeBfpyuScstW/KfAmFQg= ARC-Message-Signature: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1779776286; c=relaxed/simple; bh=OQ7xKRKAggJRdvn8KNjoXB6gKDYTwr6MV0vW0uPJFNM=; h=DKIM-Signature:From:To:Subject:Date:Message-Id:MIME-Version; b=kuv36G7XM7AbXciHmckvlNlECWizVn3j8Q6OxBIQDObLpFfGZr8suutL5Gk6JVpGzwxgwkQGhnQJodeF60FeCFaUy4rTPer/sDmxHaqHrfb6o+/0dSusinRmwEzjhGlj1nIb0phZY1JZPC6oMuhsokPNKDLARbKFSuH0mjuoOhA= ARC-Authentication-Results: i=1; sourceware.org; dkim=pass (2048-bit key, unprotected) header.d=sifive.com header.i=@sifive.com header.a=rsa-sha256 header.s=google header.b=mkqpEnIH DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org 1282F4BA79A9 Received: by mail-dl1-x122b.google.com with SMTP id a92af1059eb24-1370417c01cso1289138c88.1 for ; Mon, 25 May 2026 23:18:06 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=sifive.com; s=google; t=1779776285; x=1780381085; darn=sourceware.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to; bh=jnM0NtsG6LeycbO9SB37TnISz+49lMk1ox0PrNRPdBs=; b=mkqpEnIH6/Yl4YyQNOyJljOyDJYka+x8Slq997tNGYUddS6yZWHCBFqoBisuUGIqOh ubZxshGPxvc4NLl7bvzFBWSOSjztM+I79Ja1OOJBDn2t2a51acq3qLbigLA1ewgHcQvS tJdXxlVqQT9mhcmyR1vZcurOxolE4BehH4YBQxn77d0Zqf/5DkrzY2JFXNON5aRsux1m zVi/mSbE9l5lVf+z8bEBRDr0cQ/WyaM3Z9+k5r4hnZOjR7QUO9LQweSWLebc1VlXFkZj P/AEnGFvly70H33JzKBuXaz0x0Dd4Xeoo6BwoXArItaBZ+Zn0jeL57JlHybz3VwyZP1q m9/A== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1779776285; x=1780381085; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to; bh=jnM0NtsG6LeycbO9SB37TnISz+49lMk1ox0PrNRPdBs=; b=LbkxLTgEle5c0IlQR4locnhL+0n11wAbAJWkpnUxHCg+F1XrYtvESY7pdQ/3df/wph MFvd6YL9/HN48vlJ9AEqC1ieGWf+mXb0Lj/IG2CRNPCIkirTYe4LFievl0wCE2Lbhdkx 6WJUiayg2F/CMAG4vBq63a8JcXi4jXH0onjm6c6npuGiaUtbjBKfgq1Vck8OxpIQIoM+ CBoRYTb1BAKl90k1O9rtrFWAkX0NRR+ReBNR5TOqsIDwClhielI03ubyCz8SxlKnGKhn 6y2L8e6QbMWFHd0un66+cV/eDKZDxUjDwrj2tQeOwhyF7wAVOMiIQ1RomKlnQCNVrZRs mbog== X-Gm-Message-State: AOJu0YwqJUGj/iyW9hokJGoMV8gL3apBb2IvX7sg8rCCsmx6efXwEuNw K/C9RKaufZEqy5zXaYNUNAZy+Gwb43wv3wXK6FIZf0NwyjQeoaE2DQAELWndphlyC2u+AW4ZHLX FjmXiPajLQQ6k1XPy5TPxeNDI+7KFs0atlMqZ+kVTEq/w4g1RDmORKO5umpwUr+0kfU4r+iU6WK 5FALvKFwlVUlzniQT3Dsl+s0L7co5QU4gap4L976kACgyQz5c5lRg= X-Gm-Gg: Acq92OGqfrqSdM3mVN013XfL/yPVRdH21uhHjuV0QeYicbBNzSHyfUdoA+qPttkTX2n rxj139U5OL5PAE8JSoCuNI+hSWqUmYkRcD1EzcOA54Du19HRVRBjCAqRdD79cQ0/LaOy53Toe8f U4VBNJ2jtL+javdJSfD2XBMGQfh99HFgVtIsHa2SDLxGl6YN9OXCHZsiFSqV+zEqAwHSL1aFymQ HEHrtFVssGTwSll+tJsegttJXVTZjaeEz3Qf7OxbU4R+f3/VHIy2h914Kns+S/alePhcVnQCXU4 LGVVpOceWlf5+a69DX2sv75VujDRa5pxHN0uWLZZE+oYMPzcXAlxrsHl0sYFjhfnmATn8pETwMA 4eOX3cBRN8ugVaLbvyvFVlT6ytKjNzExqslTZxgg2k71MPmuizsFjk9JJETOPHI1kxFvQzzEaU4 8uwFph8kXjtfGzDXvwwnDWckMGfglBHWAqpH98Syzx X-Received: by 2002:a05:7300:ac94:b0:304:5a9c:644c with SMTP id 5a478bee46e88-3045a9c6cffmr4975020eec.15.1779776284643; Mon, 25 May 2026 23:18:04 -0700 (PDT) Received: from sw08.internal.sifive.com ([4.53.31.132]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-30452461cb5sm14062504eec.31.2026.05.25.23.18.03 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 25 May 2026 23:18:04 -0700 (PDT) From: Jesse Huang To: libc-alpha@sourceware.org Cc: andrew@sifive.com, darius@bluespec.com, debug@rivosinc.com, jeffreyalaw@gmail.com, kito.cheng@sifive.com, palmer@dabbelt.com, Jesse Huang Subject: [PATCH v4 10/17] riscv/cfi: Adjust setjmp/longjmp for shadow stack to work Date: Mon, 25 May 2026 23:16:56 -0700 Message-Id: <20260526061703.2188042-11-jesse.huang@sifive.com> X-Mailer: git-send-email 2.39.3 In-Reply-To: <20260526061703.2188042-1-jesse.huang@sifive.com> References: <20260526061703.2188042-1-jesse.huang@sifive.com> MIME-Version: 1.0 X-Spam-Status: No, score=-13.1 required=5.0 tests=BAYES_00, DKIM_SIGNED, DKIM_VALID, DKIM_VALID_AU, DKIM_VALID_EF, GIT_PATCH_0, KAM_SHORT, RCVD_IN_DNSWL_BLOCKED, SPF_HELO_NONE, SPF_PASS, TXREP, URIBL_BLOCKED shortcircuit=no autolearn=ham autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on sourceware.org X-BeenThere: libc-alpha@sourceware.org X-Mailman-Version: 2.1.30 Precedence: list List-Id: Libc-alpha mailing list List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: libc-alpha-bounces~patchwork=sourceware.org@sourceware.org Since longjmp to a previous setjmp'ed state could change the stack frame and involves stack frame unwinding, shadow stacks is also required to be unwinded. The unwinding is implemented according to the zicfiss spec by increasing the ssp by a page size (4K) at most, to prevent from accidentally point to another legal shadow stack page after the adjustment. Shadow stack pointer is stored in to a wrapped sigset_t, by defining within an union, we can avoid changing the size of sigset_t hence jmp_buf. --- sysdeps/riscv/Makefile | 4 + sysdeps/riscv/__longjmp.S | 55 ++++++++++++- sysdeps/riscv/setjmp.S | 22 ++++++ sysdeps/unix/sysv/linux/riscv/jmp_buf-ssp.sym | 7 ++ sysdeps/unix/sysv/linux/riscv/setjmpP.h | 78 +++++++++++++++++++ 5 files changed, 165 insertions(+), 1 deletion(-) create mode 100644 sysdeps/unix/sysv/linux/riscv/jmp_buf-ssp.sym create mode 100644 sysdeps/unix/sysv/linux/riscv/setjmpP.h diff --git a/sysdeps/riscv/Makefile b/sysdeps/riscv/Makefile index b1f074a3eb..94e224615c 100644 --- a/sysdeps/riscv/Makefile +++ b/sysdeps/riscv/Makefile @@ -11,6 +11,10 @@ endif # of some assembler macros. ASFLAGS-.os += $(pic-ccflag) +ifeq ($(subdir),setjmp) +gen-as-const-headers += jmp_buf-ssp.sym +endif + ifeq (no,$(riscv-r-align)) ASFLAGS-.os += -Wa,-mno-relax ASFLAGS-.o += -Wa,-mno-relax diff --git a/sysdeps/riscv/__longjmp.S b/sysdeps/riscv/__longjmp.S index f43b0f4c32..33d46b777d 100644 --- a/sysdeps/riscv/__longjmp.S +++ b/sysdeps/riscv/__longjmp.S @@ -18,10 +18,12 @@ #include #include +#include +#include ENTRY (__longjmp) LPAD - REG_L ra, 0*SZREG(a0) + REG_L t1, 0*SZREG(a0) REG_L s0, 1*SZREG(a0) REG_L s1, 2*SZREG(a0) REG_L s2, 3*SZREG(a0) @@ -51,8 +53,59 @@ ENTRY (__longjmp) FREG_L fs11,14*SZREG+11*SZFREG(a0) #endif +#ifdef __riscv_shadow_stack + /* skip unwinding if ss is not enabled */ + ssrdp ra + beqz ra, .Lfin + REG_L t0, SSP_OFFSET(a0) + REG_L a0, SSP_BASE_OFFSET(a0) + REG_L t2, TLS_SSP_BASE_OFFSET(tp) + bne a0, t2, .Ldifferent_stack +.Lunwind: + bleu t0, ra, .Lfin + /* Increase ssp by at most a page size to ensure always run into a + guard page before accidentally point to another legal shadow stack + page */ + /* ra = (t0 - ra >= 4096) ? ra + 4096 : t0 */ + lui a0, 1 + add ra, ra, a0 + bleu ra, t0, 1f + mv ra, t0 +1: + csrw ssp, ra + /* Test if the location pointed by ssp is legal */ + sspush x5 + sspopchk x5 + j .Lunwind +.Ldifferent_stack: + /* Create restore token */ + sspush ra + mv a4, t0 + +.Lfind_rstor_token: + /* Probe and validate target restore token */ + ssamoswap.d a3, x0, (a4) + addi a2, a4, 8 + beq a3, a2, .Lswitch_stack + /* Restore the shadow stack and try the next slot */ + ssamoswap.d x0, a3, (a4) + addi a4, a4, -8 + j .Lfind_rstor_token + +.Lswitch_stack: + /* Switch stack: update ssp and base */ + csrw ssp, t0 + REG_S a0, TLS_SSP_BASE_OFFSET(tp) +.Lfin: +#endif seqz a0, a1 add a0, a0, a1 # a0 = (a1 == 0) ? 1 : a1 +#ifdef __riscv_landing_pad + /* Use indirect branch if CFI is enabled */ + jr t1 +#else + mv ra, t1 ret +#endif END (__longjmp) diff --git a/sysdeps/riscv/setjmp.S b/sysdeps/riscv/setjmp.S index aecf2d2bab..4d5a5f0aff 100644 --- a/sysdeps/riscv/setjmp.S +++ b/sysdeps/riscv/setjmp.S @@ -18,6 +18,8 @@ #include #include +#include +#include ENTRY (_setjmp) LPAD @@ -61,6 +63,26 @@ ENTRY (__sigsetjmp) FREG_S fs11,14*SZREG+11*SZFREG(a0) #endif +#ifdef __riscv_shadow_stack + /* Skip if shadow stack is not enabled */ + ssrdp t0 + beqz t0, .Lfin + + /* Read ssp_base from TLS */ + REG_L t2, TLS_SSP_BASE_OFFSET(tp) + bnez t2, .Lbase_saved + + /* if not found, use current ssp as the marker */ + mv t2, t0 + REG_S t2, TLS_SSP_BASE_OFFSET(tp) + +.Lbase_saved: + /* Save caller's ssp and base marker to jmp_buf */ + REG_S t0, SSP_OFFSET(a0) + REG_S t2, SSP_BASE_OFFSET(a0) +.Lfin: +#endif + #if !IS_IN (libc) && IS_IN (rtld) /* In ld.so we never save the signal mask. */ li a0, 0 diff --git a/sysdeps/unix/sysv/linux/riscv/jmp_buf-ssp.sym b/sysdeps/unix/sysv/linux/riscv/jmp_buf-ssp.sym new file mode 100644 index 0000000000..bf944969f7 --- /dev/null +++ b/sysdeps/unix/sysv/linux/riscv/jmp_buf-ssp.sym @@ -0,0 +1,7 @@ +#include +#include +#undef __saved_mask + +-- +SSP_OFFSET offsetof(struct __jmp_buf_tag, __saved_mask.__saved.__ssp) +SSP_BASE_OFFSET offsetof(struct __jmp_buf_tag, __saved_mask.__saved.__ssp_base) diff --git a/sysdeps/unix/sysv/linux/riscv/setjmpP.h b/sysdeps/unix/sysv/linux/riscv/setjmpP.h new file mode 100644 index 0000000000..43cb28e2d1 --- /dev/null +++ b/sysdeps/unix/sysv/linux/riscv/setjmpP.h @@ -0,0 +1,78 @@ +/* Internal header file for . Linux/risc-v version. + Copyright (C) 2026 Free Software Foundation, Inc. + This file is part of the GNU C Library. + + The GNU C Library is free software; you can redistribute it and/or + modify it under the terms of the GNU Lesser General Public + License as published by the Free Software Foundation; either + version 2.1 of the License, or (at your option) any later version. + + The GNU C Library is distributed in the hope that it will be useful, + but WITHOUT ANY WARRANTY; without even the implied warranty of + MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU + Lesser General Public License for more details. + + You should have received a copy of the GNU Lesser General Public + License along with the GNU C Library; if not, see + . */ + +#ifndef _SETJMPP_H +#define _SETJMPP_H 1 + +#include +#include +#include + +/* Number of bits per long. */ +#define _JUMP_BUF_SIGSET_BITS_PER_WORD (8 * sizeof (unsigned long int)) +/* This holds the number of signals, 512 should be sufficient for future. + expansion */ +#define _JUMP_BUF_SIGSET_NSIG 512 +/* Number of longs to hold all signals. */ +#define _JUMP_BUF_SIGSET_NWORDS \ + (ALIGN_UP (_JUMP_BUF_SIGSET_NSIG, _JUMP_BUF_SIGSET_BITS_PER_WORD) \ + / _JUMP_BUF_SIGSET_BITS_PER_WORD) + +typedef struct + { + unsigned long int __val[_JUMP_BUF_SIGSET_NWORDS]; + } __jmp_buf_sigset_t; + +typedef union + { + __sigset_t __saved_mask_compat; + struct + { + __jmp_buf_sigset_t __saved_mask; + /* Used for shadow stack pointer. NB: Shadow stack pointer + must have the same alignment as __saved_mask. Otherwise + offset of __saved_mask will be changed. */ + unsigned long int __ssp; + unsigned long int __ssp_base; + } __saved; + } __jmpbuf_arch_t; + +/* has + + NB: We use setjmp in thread cancellation and this saves the shadow + stack register, but __libc_unwind_longjmp doesn't restore the shadow + stack register since cancellation never returns after longjmp. */ +#undef __sigset_t +#define __sigset_t __jmpbuf_arch_t +#include +#undef __saved_mask +#define __saved_mask __saved_mask.__saved.__saved_mask + +#include + +typedef struct + { + unsigned long int __val[__NSIG_WORDS]; + } __sigprocmask_sigset_t; + +extern jmp_buf ___buf; +extern __typeof (___buf[0].__saved_mask) ___saved_mask; +_Static_assert (sizeof (___saved_mask) >= sizeof (__sigprocmask_sigset_t), + "size of ___saved_mask < size of __sigprocmask_sigset_t"); + +#endif /* setjmpP.h */ From patchwork Tue May 26 06:16:57 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Jesse Huang X-Patchwork-Id: 135664 Return-Path: X-Original-To: patchwork@sourceware.org Delivered-To: patchwork@sourceware.org Received: from vm01.sourceware.org (localhost [IPv6:::1]) by sourceware.org (Postfix) with ESMTP id 2D9A64BA9029 for ; Tue, 26 May 2026 06:24:54 +0000 (GMT) DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org 2D9A64BA9029 Authentication-Results: sourceware.org; dkim=pass (2048-bit key, unprotected) header.d=sifive.com header.i=@sifive.com header.a=rsa-sha256 header.s=google header.b=dBzVPzC5 X-Original-To: libc-alpha@sourceware.org Delivered-To: libc-alpha@sourceware.org Received: from mail-dy1-x1334.google.com (mail-dy1-x1334.google.com [IPv6:2607:f8b0:4864:20::1334]) by sourceware.org (Postfix) with ESMTPS id AB7414BA23EE for ; Tue, 26 May 2026 06:18:06 +0000 (GMT) DMARC-Filter: OpenDMARC Filter v1.4.2 sourceware.org AB7414BA23EE Authentication-Results: sourceware.org; dmarc=pass (p=reject dis=none) header.from=sifive.com Authentication-Results: sourceware.org; spf=pass smtp.mailfrom=sifive.com ARC-Filter: OpenARC Filter v1.0.0 sourceware.org AB7414BA23EE Authentication-Results: sourceware.org; arc=none smtp.remote-ip=2607:f8b0:4864:20::1334 ARC-Seal: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1779776286; cv=none; b=ao0vhes2A6as/lFmdHWyrpYJ5NgIeJ2+rPb9ALymPNd2kHc7OJJ5JUBpCXO4WWSdnBdZNcAnobO5q3i5o+dBqdfKDM408zTy5hb/DB4y5M5sNsw/SwIxjD4cMPFiGKDnNYpr9jMfTvsaOFI/1IG1HBFcPI+rHQ7kzdYN5l4hoeU= ARC-Message-Signature: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1779776286; c=relaxed/simple; bh=+5ZOUOejbOpwSSl6fpsgDRRY7qPb/IX/UKxtNoh3LFw=; h=DKIM-Signature:From:To:Subject:Date:Message-Id:MIME-Version; b=jr6ugUqZn1o4APvnpb5zgC0beFLg7SD5fRI4LI9z2Z7ypMFh6aGNtEpEAkzTKY53PEyjTMJGeuPw5ie48U0pyvQH/4cO86m/ctYT5VeblZ6EQGWfifLWK5XQ9fyrQ7tPTwFcOU1IJXiYDn/Zw37+zX0x+yY7+cw47sfB29WxelY= ARC-Authentication-Results: i=1; sourceware.org; dkim=pass (2048-bit key, unprotected) header.d=sifive.com header.i=@sifive.com header.a=rsa-sha256 header.s=google header.b=dBzVPzC5 DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org AB7414BA23EE Received: by mail-dy1-x1334.google.com with SMTP id 5a478bee46e88-303dbfbec77so11957012eec.0 for ; Mon, 25 May 2026 23:18:06 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=sifive.com; s=google; t=1779776286; x=1780381086; darn=sourceware.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to; bh=rFRoWBdPTO2Dar7JFKFI32pWZmissGUbQG0e5/Uqhl8=; b=dBzVPzC51ZJa+aE7uhNjM1QrBNXgHLFziDlzwmp14rlYpdxlQL73oItIU+QlkA2xhf IVz3A5O59f985fwXjCijtHVuFWedoSAdmNsNuTW6cmlVLpZ+cR2VRh8RZ4OIes4sprUV GmVI1/MpKY4tcaR5MMdpHhPfspWfhOKS6WyufKdUEeQbcXCF3Pl6tZgAngv0gQPTADGC K4bOc6TbfHivKqrfvPsM8lBq1Pac5/P1N/v4vtsP1aCM85+eVvDzXaIXAShzjU4H9o2c y13u0ddxJpaJ6D9KA0BReXGDEWSI9tZpspYfnrokXXGLwOx7VsIQBGVDhObCtjvez5jS KJug== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1779776286; x=1780381086; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to; bh=rFRoWBdPTO2Dar7JFKFI32pWZmissGUbQG0e5/Uqhl8=; b=QusvyWoBFfmHN1As4sAdJ60bedqjvJUaRW1rj8wjzH3ewkaAstgfllYPcphJF/WGLR c5BvG8+2Bw3CfpVxKDJtcVrOmBNfsMCxbEYI8+n3bQ4qyr9sJSBt/ov5HNB6MZxYTW+D E+Iy+QkK8aaJhRQAyTkJmNaATL1syAyRQbWdHZZH0XXL4be2WbU6UxIqXdUx87HFBTwp RTbbLrUVTttaUJYhJ2/DcfoxFBeT20aHsxuu1ETtgxIPj7IkjNTgclKXC2c+zqZIPGb8 NhKitX9Ev4uRJnzclBiDoJdYkC3yL5Sx5qygGYGV5nPH/ct+/pQfwUgXXmMvy/fyU1eW A5VA== X-Gm-Message-State: AOJu0YytPsofSixn78b95ijKpduaAbpYQP/PO/fkGGbbi3/cKC+ImmB2 i1HQ1/lzv7jvEbWCZKD/YCs4Q7OR6MivPpJ6ZArNSt9AdypbfiWaJb4e6z5xuPL3JItKmWoPqAL UGaQkMGJo2e2RfCPU3Zl6WLyW+Sccqp0PRZb0b7peu5V0Fccl0hJsPcebsznCaf/kfhi4fp3lvt ZlarQxVU6MxEFIqQ6Oz/cA+AsSevzar+lnIB4zPu/ZzjnEydq5Op4= X-Gm-Gg: Acq92OG8+wNJRNx1rTtrW58tLnYfwIuu2vHIKn3oE7wRBHQumfAjVHDODTayCoYWz3O Q89/tz/teXuZOSmJrw8gcyIzdi2YouZXNrCwN8YYUef+sivG9/7mZKxTOlSR1Gt0hASivjp5v+W 4Cbn4ujK4KW/FrGAimv1Ahsg6akMtOCV6VGPC1Z3+XcHBIeuw7s0hASMqfXXFtE+bU4i2dj0DGp aS2Y3qvvp5mRq5+vTTsbEes39VqIhpLjCCPD+x2T5RzKopcYxRQDIfooWplqR1vIbU++TQbNXoV whEG/5q+5/A0OaemNb0G1y1LlAy2V4cZN2I6DklF/Zaiu7GxkcfrHX6DGU0nTHHJkIxT3OT3AlC qVjQiWwlsrsN01ZWVhOm8LhWF8PvZnnh8BSrSZ904N3g4OHg5N95rkTTPPCCTOHIu6qr87lJk7E G7GsdirtcTSbKPbsowmrrvytpDoBJUpkzE1gnUTiRJ X-Received: by 2002:a05:7300:8b1f:b0:2e0:1f09:d924 with SMTP id 5a478bee46e88-30448f30884mr8544737eec.5.1779776285476; Mon, 25 May 2026 23:18:05 -0700 (PDT) Received: from sw08.internal.sifive.com ([4.53.31.132]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-30452461cb5sm14062504eec.31.2026.05.25.23.18.04 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 25 May 2026 23:18:05 -0700 (PDT) From: Jesse Huang To: libc-alpha@sourceware.org Cc: andrew@sifive.com, darius@bluespec.com, debug@rivosinc.com, jeffreyalaw@gmail.com, kito.cheng@sifive.com, palmer@dabbelt.com, Jesse Huang Subject: [PATCH v4 11/17] riscv/cfi: Support locking/disabling CFI and move OS depedent code Date: Mon, 25 May 2026 23:16:57 -0700 Message-Id: <20260526061703.2188042-12-jesse.huang@sifive.com> X-Mailer: git-send-email 2.39.3 In-Reply-To: <20260526061703.2188042-1-jesse.huang@sifive.com> References: <20260526061703.2188042-1-jesse.huang@sifive.com> MIME-Version: 1.0 X-Spam-Status: No, score=-13.2 required=5.0 tests=BAYES_00, DKIM_SIGNED, DKIM_VALID, DKIM_VALID_AU, DKIM_VALID_EF, GIT_PATCH_0, RCVD_IN_DNSWL_BLOCKED, SPF_HELO_NONE, SPF_PASS, TXREP, URIBL_BLOCKED shortcircuit=no autolearn=ham autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on sourceware.org X-BeenThere: libc-alpha@sourceware.org X-Mailman-Version: 2.1.30 Precedence: list List-Id: Libc-alpha mailing list List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: libc-alpha-bounces~patchwork=sourceware.org@sourceware.org --- sysdeps/riscv/dl-cfi.c | 40 +++++++++++----- sysdeps/unix/sysv/linux/riscv/dl-cfi.h | 65 ++++++++++++++++++++++++++ 2 files changed, 94 insertions(+), 11 deletions(-) diff --git a/sysdeps/riscv/dl-cfi.c b/sysdeps/riscv/dl-cfi.c index 275faddcc9..27ac4cff10 100644 --- a/sysdeps/riscv/dl-cfi.c +++ b/sysdeps/riscv/dl-cfi.c @@ -57,7 +57,7 @@ struct dl_cfi_info static void dl_check_legacy_object (struct link_map *m, struct dl_cfi_info *info) { - /* Iterate through the dependencies and disable if needed here */ + /* Iterate through the dependencies and record legacy objects */ struct link_map *l = NULL; unsigned int i; i = m->l_searchlist.r_nlist; @@ -86,7 +86,11 @@ dl_check_legacy_object (struct link_map *m, struct dl_cfi_info *info) | ~(GNU_PROPERTY_RISCV_FEATURE_1_CFI_LP_UNLABELED | GNU_PROPERTY_RISCV_FEATURE_1_CFI_SS)); - /* Bookkeeping legacy objects */ + /* Bookkeeping first found mismatch object for both lp/ss. + These information would only be used by dlopen check for now. + A dependency with a feature on will be record as legacy if the task + did not enable the feature, however it is safe because the following + check will only be performed if the task has the feature on. */ #ifdef __riscv_landing_pad if ((info->feature_1_legacy & GNU_PROPERTY_RISCV_FEATURE_1_CFI_LP_UNLABELED) == 0 && ((info->enable_feature_1 & GNU_PROPERTY_RISCV_FEATURE_1_CFI_LP_UNLABELED) @@ -208,8 +212,8 @@ dl_cfi_check_dlopen (struct link_map *m, struct dl_cfi_info *info) _dl_signal_error (0, m->l_initfini[legacy_obj]->l_name, "dlopen", msg); if (disable_feature_1 != 0) - // FIXME: Disable CFI here - int res = -1; + { + int res = dl_cfi_disable_cfi (disable_feature_1); if (res) { msg = N_("can't disable CFI feature"); @@ -223,14 +227,29 @@ dl_cfi_check_dlopen (struct link_map *m, struct dl_cfi_info *info) attribute_hidden void _dl_cfi_setup_features (unsigned int feature_1) { - /* Since prctl could fail to enable some features - use prctl to get enabled features again and sync it back. */ + /* Enable features. Shadow stack is enabled earlier as it should + * be enabled in a function that never returns. */ +#ifdef __riscv_landing_pad + dl_cfi_enable_lp (feature_1); +#endif /* __riscv_landing_pad */ + + /* Since we could failed to enable some features, + get enabled features from system again and sync it back. */ + int status = dl_cfi_get_cfi_status (); + GL(dl_riscv_feature_1) = status | (GL(dl_riscv_feature_1) & + ~(GNU_PROPERTY_RISCV_FEATURE_1_CFI_SS + | GNU_PROPERTY_RISCV_FEATURE_1_CFI_LP_UNLABELED)); + + /* Lock features if set to always_on */ #ifdef __riscv_landing_pad - if (feature_1 & GNU_PROPERTY_RISCV_FEATURE_1_CFI_LP_UNLABELED) - INTERNAL_SYSCALL_CALL (prctl, PR_SET_INDIR_BR_LP_STATUS, - PR_INDIR_BR_LP_ENABLE, 0, 0, 0); + if (GL(dl_riscv_feature_control).lp == cfi_always_on) + dl_cfi_lock_cfi (GNU_PROPERTY_RISCV_FEATURE_1_CFI_LP_UNLABELED); #endif /* __riscv_landing_pad */ - /* FIXME: Read enabled features from kernel and re-sync */ +#ifdef __riscv_shadow_stack + if (GL(dl_riscv_feature_control).ss == cfi_always_on) + dl_cfi_lock_cfi (GNU_PROPERTY_RISCV_FEATURE_1_CFI_SS); +#endif /* __riscv_shadow_stack */ + /* FIXME: Should we terminate if failed to lock under always on mode? */ } /* Enable CFI for l and its dependencies. */ @@ -287,7 +306,6 @@ _dl_cfi_check (struct link_map *l, const char *program) info.feature_1_legacy_ss = 0; #endif - info.feature_1_enabled = GL(dl_riscv_feature_1); info.feature_1_legacy = 0; #ifdef SHARED diff --git a/sysdeps/unix/sysv/linux/riscv/dl-cfi.h b/sysdeps/unix/sysv/linux/riscv/dl-cfi.h index 53df470930..9758fbf0e3 100644 --- a/sysdeps/unix/sysv/linux/riscv/dl-cfi.h +++ b/sysdeps/unix/sysv/linux/riscv/dl-cfi.h @@ -48,3 +48,68 @@ jal _dl_cfi_setup_features \n\ \n\ " + +static __always_inline int +dl_cfi_disable_cfi (unsigned int feature) { + int res = 0; +#ifdef __riscv_landing_pad + if (feature & GNU_PROPERTY_RISCV_FEATURE_1_CFI_LP_UNLABELED) + { + res = prctl (PR_SET_INDIR_BR_LP_STATUS, 0, 0, 0, 0); + if (res) + return res; + } +#endif /* __riscv_landing_pad */ +#ifdef __riscv_shadow_stack + if (feature & GNU_PROPERTY_RISCV_FEATURE_1_CFI_SS) + { + res |= prctl (PR_SET_SHADOW_STACK_STATUS, 0, 0, 0, 0); + if (res) + return res; + } +#endif /* __riscv_shadow_stack */ + return 0; +} + +static __always_inline int +dl_cfi_lock_cfi (unsigned int feature) +{ + int res = 0; +#ifdef __riscv_landing_pad + if (feature & GNU_PROPERTY_RISCV_FEATURE_1_CFI_LP_UNLABELED) + res |= prctl (PR_LOCK_INDIR_BR_LP_STATUS, 0, 0, 0, 0); +#endif /* __riscv_landing_pad */ +#ifdef __riscv_shadow_stack + if (feature & GNU_PROPERTY_RISCV_FEATURE_1_CFI_SS) + res |= prctl (PR_LOCK_SHADOW_STACK_STATUS, 0, 0, 0, 0); +#endif /* __riscv_shadow_stack */ + return res; +} + +static __always_inline int +dl_cfi_get_cfi_status (void) { + int status = 0; + unsigned long buf = 0; + int ret = 0; +#ifdef __riscv_landing_pad + ret = prctl (PR_GET_INDIR_BR_LP_STATUS, &buf, 0, 0, 0); + if (!ret && buf) + status |= GNU_PROPERTY_RISCV_FEATURE_1_CFI_LP_UNLABELED; +#endif /* __riscv_landing_pad */ +#ifdef __riscv_shadow_stack + ret = prctl (PR_GET_SHADOW_STACK_STATUS, &buf, 0, 0, 0); + if (!ret && buf) + status |= GNU_PROPERTY_RISCV_FEATURE_1_CFI_SS; +#endif /* __riscv_shadow_stack */ + return status; +} + +#ifdef __riscv_landing_pad +static __always_inline int +dl_cfi_enable_lp (unsigned int feature) { + if (!(feature & GNU_PROPERTY_RISCV_FEATURE_1_CFI_LP_UNLABELED)) + return -1; + return INTERNAL_SYSCALL_CALL (prctl, PR_SET_INDIR_BR_LP_STATUS, + PR_INDIR_BR_LP_ENABLE, 0, 0, 0); +} +#endif /* __riscv_landing_pad */ From patchwork Tue May 26 06:16:58 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Jesse Huang X-Patchwork-Id: 135661 Return-Path: X-Original-To: patchwork@sourceware.org Delivered-To: patchwork@sourceware.org Received: from vm01.sourceware.org (localhost [IPv6:::1]) by sourceware.org (Postfix) with ESMTP id 9ACB94BA798E for ; Tue, 26 May 2026 06:23:55 +0000 (GMT) DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org 9ACB94BA798E Authentication-Results: sourceware.org; dkim=pass (2048-bit key, unprotected) header.d=sifive.com header.i=@sifive.com header.a=rsa-sha256 header.s=google header.b=GDqo6c5t X-Original-To: libc-alpha@sourceware.org Delivered-To: libc-alpha@sourceware.org Received: from mail-dy1-x132a.google.com (mail-dy1-x132a.google.com [IPv6:2607:f8b0:4864:20::132a]) by sourceware.org (Postfix) with ESMTPS id 983934BA7993 for ; Tue, 26 May 2026 06:18:08 +0000 (GMT) DMARC-Filter: OpenDMARC Filter v1.4.2 sourceware.org 983934BA7993 Authentication-Results: sourceware.org; dmarc=pass (p=reject dis=none) header.from=sifive.com Authentication-Results: sourceware.org; spf=pass smtp.mailfrom=sifive.com ARC-Filter: OpenARC Filter v1.0.0 sourceware.org 983934BA7993 Authentication-Results: sourceware.org; arc=none smtp.remote-ip=2607:f8b0:4864:20::132a ARC-Seal: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1779776288; cv=none; b=YJ9adHl/GSdzg9AS3IJ8qOu3PHskPRAngRbn69hFWRmFv1A/ZeU38h2ajiqgvJ9cYDjjpSNkAJ4MQ+6nvFks97a9SXJc7nG8BME0dldvE2D7mPTCdxRR/cBBRKh2s+9+CbTkPMaa6VQwnMJuSySu3bnLEaQahunF5aKfv7ze2f8= ARC-Message-Signature: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1779776288; c=relaxed/simple; bh=Z11U8SB0NQ/3VfrgnE0pGWcz6FjwLwt/fiRMd3AfY6E=; h=DKIM-Signature:From:To:Subject:Date:Message-Id:MIME-Version; b=h0ZZTDdz0xeCH1r5gYlU+bnZtYXdQvA1lH8QESUBi/PzgwcHBwcLa8GAncBJjq7ZwoK89clcjOv5zyRrFLIOzuHWDmoXgZ2MJPMYQofc03qNrZ0ESA6nxV+6RGWBDhXzdFK90emNCNLyvJGRAKngJI9MuYAbhnFx6SBoFuHFh2Y= ARC-Authentication-Results: i=1; sourceware.org; dkim=pass (2048-bit key, unprotected) header.d=sifive.com header.i=@sifive.com header.a=rsa-sha256 header.s=google header.b=GDqo6c5t DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org 983934BA7993 Received: by mail-dy1-x132a.google.com with SMTP id 5a478bee46e88-2ef2a1cc06dso1008340eec.0 for ; Mon, 25 May 2026 23:18:08 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=sifive.com; s=google; t=1779776287; x=1780381087; darn=sourceware.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to; bh=yjKDvk9WKhjCS47uGagnthzhpIr7ewqDyMPk8ZcMvC0=; b=GDqo6c5t6ANR353QeVnUlxQJSeoP+L0OtrTPz5Nt5P3E8N9MTEwtk8E9sapXXVVQTS AuMYUibb9y0rJmqHShIwX8zGLW9D27igW2rs8lY/cRas+0EHXABo6YQgakXkfuUnm2PQ q8pP4UkU1j/1RYRQZzDEeo1uUgACF2/KFvc7o3SZMkBHp0ElbG3SDN3Q374uBkTEh+XO 9gYIKbSUFNJ9R9nJNpbcNh7A3I4MZKBv5UcHYGRjBHbw2sDwN/VrIL+WX/zgD3xKJxfu JX64kfO+6G5pxorPHP0LOz9UYFi0NjM6DbyndXoEq1AQYC1s5/sv05PRWz0/V9NdqUq/ eb3A== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1779776287; x=1780381087; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to; bh=yjKDvk9WKhjCS47uGagnthzhpIr7ewqDyMPk8ZcMvC0=; b=MQ39Zsj+8Fy7jDLz75WI91NM8Qi0z917JLx+NbDdtHbbnFli5fN5Rs8W4c9K8lGX1l 7BAIzqCO4Bvj+Es6RnDf7D/hbbQ8aoCIUWiADncuY4lySnf4xhYmIulrs+TOI5i9/UfW 5JsXejTgU+1yDNk7tRt2la0mfTj1/9lgG2t/nE1g111joeMwPlRy9JHT13UNqF/1or0I uOLcbDE+GGPfeh2C0NMmBlSq7Kjr6SSLdTcWQsttjJvBjAJHk2cLrzR1N6dDtFXnzW/a vLQvQ5S16+SReqgQYfiRKPIlQAhGA7TOYn728NtHDJoUiGnurpHXn+1t3ufzp4DGhiT0 8PRQ== X-Gm-Message-State: AOJu0Yy+EJGX+QqA0sKr+JCD0g3yN3X9kXmiWGQTW6HzMUFtmMki+4pr 9WWvfmFSiS/4hpMUzftcsj8qtIoFrZMgYgPCsiez50wldujCIwnOZOJ58m6XCGFKUKqshfc5dmk vco734Mut2HxCif6vRI//Cb7WD3ipZm4g7ZUdh008hk10uZSsdEOPaB0HE86x1BPJUezkRMKV+3 B/VV1UVuU9WzW/UeHlhTYvijNcaWllz2rimU5Jg37X4q3v+Tm63HA= X-Gm-Gg: Acq92OGX510Gbjt7bAKIRCFg0ACT/UHyMtDYw4ZFuHpxfU4Z7VBLh0pbKwFxBihFQU+ pYufPtn4M7K8gxFb1EJGWm016MiGM0bDBvX7AXF5yLHR1P3lE6PF1D5xT1DDjHM2Grsx17c5D9B z8aXXCvZSsWBA1ry3nid8nBmIQnrmaw5lXtOmXoH7vDTBFfU4FhAzM+Hx4l9r2aF9bhwdvTTTBr GA0RywQ/vCUzKWQ7N7w/2M28FwehhPm0lEMCWbCGLXhBmIQqpvuFmMv5tu6UFWGQ6ieEyO1as5q sJxFXhI0hyw7FWDEYs5a6SNXdn1UqJmFGorQ9pQJJ53cKjtxbpIk58Gf6GjjXeT5CoMo5oJwOu0 asV8skCpreyJTFa8rsku7KdAqoB/If+LCfaPlYc2WuFc1Xb1paDoPMY8Q6ZISTaORR48QJMQOA1 3wygPxUAP50rgHyWsvZ2jHoEK0bP7MiRAJluibFDoG X-Received: by 2002:a05:7300:cd99:b0:304:188d:d0be with SMTP id 5a478bee46e88-30449156f8cmr7202436eec.16.1779776287334; Mon, 25 May 2026 23:18:07 -0700 (PDT) Received: from sw08.internal.sifive.com ([4.53.31.132]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-30452461cb5sm14062504eec.31.2026.05.25.23.18.05 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 25 May 2026 23:18:05 -0700 (PDT) From: Jesse Huang To: libc-alpha@sourceware.org Cc: andrew@sifive.com, darius@bluespec.com, debug@rivosinc.com, jeffreyalaw@gmail.com, kito.cheng@sifive.com, palmer@dabbelt.com, Jesse Huang Subject: [PATCH v4 12/17] riscv/cfi: Store shadow stack information in TLS Date: Mon, 25 May 2026 23:16:58 -0700 Message-Id: <20260526061703.2188042-13-jesse.huang@sifive.com> X-Mailer: git-send-email 2.39.3 In-Reply-To: <20260526061703.2188042-1-jesse.huang@sifive.com> References: <20260526061703.2188042-1-jesse.huang@sifive.com> MIME-Version: 1.0 X-Spam-Status: No, score=-13.2 required=5.0 tests=BAYES_00, DKIM_SIGNED, DKIM_VALID, DKIM_VALID_AU, DKIM_VALID_EF, GIT_PATCH_0, RCVD_IN_DNSWL_NONE, SPF_HELO_NONE, SPF_PASS, TXREP, URIBL_BLOCKED shortcircuit=no autolearn=ham autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on sourceware.org X-BeenThere: libc-alpha@sourceware.org X-Mailman-Version: 2.1.30 Precedence: list List-Id: Libc-alpha mailing list List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: libc-alpha-bounces~patchwork=sourceware.org@sourceware.org Switching between different ucontexts involves two cases, one is both sharing a same shadow stack, which requires a unwinding, and the other is both using a different shadow stack, which require a stack switch using shadow stack restore token. By storing shadow stack base in TLS and compare to the one stored in the context, we can tell the difference and perform the right action. --- sysdeps/riscv/nptl/Makefile | 1 + sysdeps/riscv/nptl/tcb-offsets.sym | 5 +++++ sysdeps/riscv/nptl/tls.h | 2 ++ 3 files changed, 8 insertions(+) create mode 100644 sysdeps/riscv/nptl/Makefile create mode 100644 sysdeps/riscv/nptl/tcb-offsets.sym diff --git a/sysdeps/riscv/nptl/Makefile b/sysdeps/riscv/nptl/Makefile new file mode 100644 index 0000000000..2b7bf43403 --- /dev/null +++ b/sysdeps/riscv/nptl/Makefile @@ -0,0 +1 @@ +gen-as-const-headers += tcb-offsets.sym diff --git a/sysdeps/riscv/nptl/tcb-offsets.sym b/sysdeps/riscv/nptl/tcb-offsets.sym new file mode 100644 index 0000000000..5257acccec --- /dev/null +++ b/sysdeps/riscv/nptl/tcb-offsets.sym @@ -0,0 +1,5 @@ +#include +#include +#include + +TLS_SSP_BASE_OFFSET (offsetof (tcbhead_t, ssp_base) - sizeof (tcbhead_t)) diff --git a/sysdeps/riscv/nptl/tls.h b/sysdeps/riscv/nptl/tls.h index b2e0f3c249..f618b32b54 100644 --- a/sysdeps/riscv/nptl/tls.h +++ b/sysdeps/riscv/nptl/tls.h @@ -44,6 +44,8 @@ typedef struct { dtv_t *dtv; void *private; + /* The marker for the current shadow stack. */ + unsigned long long int ssp_base; } tcbhead_t; /* This is the size of the initial TCB. Because our TCB is before the thread From patchwork Tue May 26 06:16:59 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Jesse Huang X-Patchwork-Id: 135665 Return-Path: X-Original-To: patchwork@sourceware.org Delivered-To: patchwork@sourceware.org Received: from vm01.sourceware.org (localhost [IPv6:::1]) by sourceware.org (Postfix) with ESMTP id 056D24B9DB5F for ; Tue, 26 May 2026 06:25:55 +0000 (GMT) DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org 056D24B9DB5F Authentication-Results: sourceware.org; dkim=pass (2048-bit key, unprotected) header.d=sifive.com header.i=@sifive.com header.a=rsa-sha256 header.s=google header.b=cmtQ631C X-Original-To: libc-alpha@sourceware.org Delivered-To: libc-alpha@sourceware.org Received: from mail-dy1-x132b.google.com (mail-dy1-x132b.google.com [IPv6:2607:f8b0:4864:20::132b]) by sourceware.org (Postfix) with ESMTPS id 670F94BA7986 for ; Tue, 26 May 2026 06:18:09 +0000 (GMT) DMARC-Filter: OpenDMARC Filter v1.4.2 sourceware.org 670F94BA7986 Authentication-Results: sourceware.org; dmarc=pass (p=reject dis=none) header.from=sifive.com Authentication-Results: sourceware.org; spf=pass smtp.mailfrom=sifive.com ARC-Filter: OpenARC Filter v1.0.0 sourceware.org 670F94BA7986 Authentication-Results: sourceware.org; arc=none smtp.remote-ip=2607:f8b0:4864:20::132b ARC-Seal: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1779776289; cv=none; b=XVN/iDUaxGIlBMBvphfClF0HY0QMVR8HeNKdgW0p3SKoCmo5t76BPKjkdJXAFFqTB6CGjEI6TM9StcWbxK2Opvp89+qyZJCzaVyVHMISyA5x7rumJEbC6u5xjyDy6ChmHh5zFpTb4wwq3BcCJFfse21EN//8AjFp1f8VXCsV/hs= ARC-Message-Signature: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1779776289; c=relaxed/simple; bh=gsM9hijP1PqYvHmjVAPHHVkbkI1Yov7g4w9D+qyx5gs=; h=DKIM-Signature:From:To:Subject:Date:Message-Id:MIME-Version; b=Mqy/qLwU709A6O8lxOdMV/k9KpwXcdQgsotmpoemUwJzjLJU/ZHDS0IdXjmWrEPRx0QeDrBPcXeTMbItwT2HjDCI6axv8qh9mA6VdnpyZx/++BjW8cDUcfKNXAvuNuK33f3yuSg+ROzszFwm1tPEbHIpPoOLLBDbZcyyoAzi0/E= ARC-Authentication-Results: i=1; sourceware.org; dkim=pass (2048-bit key, unprotected) header.d=sifive.com header.i=@sifive.com header.a=rsa-sha256 header.s=google header.b=cmtQ631C DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org 670F94BA7986 Received: by mail-dy1-x132b.google.com with SMTP id 5a478bee46e88-304545e6c7fso3855908eec.0 for ; Mon, 25 May 2026 23:18:09 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=sifive.com; s=google; t=1779776288; x=1780381088; darn=sourceware.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to; bh=F3UPFyj/sfFJTTWw+M14ZxF7dbNG/AKJ4tBsMVWE8Ag=; b=cmtQ631C8v1BoVYaDnQyGiCkjOdHidi6kqNGRNiw1Lx995JE2ZoDdWUCGB4kGpI8lg 6Wm0fR5pvhASorU7N5hKzgNLCHy42aVuhnl0nP/kdphS+9IthRv3s7l9CiOvrFRSUuiR moKQ4xs2VuAS92WlJQXfLgSL6JjZFloFy3gM857lLOxmNs1GyLmTlbADrc5rqFOIglCp cvrawU7pcBLu3zMQr/wAcPHryJECh0qT9nas6dOiSUmOwb3SfMsHw0VJcfVm9a3ur9rC IKyNooVOzFUXNXCykM2QkVzrtYGhwdS3DrFTXFu/07Aeeft11MqsNKr39GOdxWSQejRt nbJg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1779776288; x=1780381088; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to; bh=F3UPFyj/sfFJTTWw+M14ZxF7dbNG/AKJ4tBsMVWE8Ag=; b=k1CM3/Gm0wX0B2YA/eDdvwXgt9nW+4ONfQfVJzGU0yoLNpcQ/AGw7sYgZEWaw0iHxJ eg4Ys9/AihGtmYnmxvT+j7vhMx+kVfW/WYKkw469KIN8bQk8JYUx5k6qsDICTmUeocEz /wpCFr0uvJC17BkksAl2fvCcM3IUdC5utAZpMIH3nOujz+GLUaHkr6WAFJzcTA5jxVNl Y7DD9iH+HcibEpzb4hWW5Irfn36vlgcE4bRipZzCUVF33e2Bk3Q+avu1gdQjW7KHFHNu DI9D4+yGZHHCFnmqzUVpcywAXXIKzijdFK1SDu2v7QcQ+oca2BkoMHlCyWAWxE3IdHIp 4iMA== X-Gm-Message-State: AOJu0Yw9xkFxcCxG70p4KjmzuVUi0f2k45d2nIZTwT4BP/TGAxmqwsV/ gHz/kNXzchAPWpbSzU3evfUdpuIfyk8nZ9LW+PKDFgobuGIhT+4gFwvqIG4u8tXGFLhAq1XnxsW QspTVcLP+n+OQFqnwAHf8x73Va3tb5cKqHz4aVvkwLB0RpuOvndAUpmHD6fTNwdbw7qckjO7cOB vpYMEa+dskJ9E+SabEXsYwGzQfFcOOzCLTqZZgc9r28e3kcizxzfA= X-Gm-Gg: Acq92OFvsAoYzrV/AA+9OfOGZB6tlWw676siEdOFpaqE8iyyNuF4c0cZz/GGhGS+NaI NRCKq4+GEQI/TqcdZ6go0QVXZ088VsTnn5jD+Uaz8IQehIo5I8sNZ6W31MgcoVcGZWP5EwLmms4 2fLOOwH68iKwmakLEHNQlYpsDjXrhqV05TScK3MgfKCLjksurqa70VxhPXprN3xD0KGYHjzdpNp zg+27cvm0xoRRlLaE1TIavR016qFcF+5hg+BNARlc3bhzP/xSucurtdt/mMnyiE3OMreYcctzBD CzoKzzWsjMcvR3ZAFbHboNGNVp2cSHulgrSOH/tiXuOpl2jxnVtz3LzTvHxmD0t21XYOjbryoHc C8vlnnzDGNPhXfnFn17af/Y3sPfIOZp4hB1cVlYGkM6svKK/+AoPg5lN7IrPA8NtAahATcv3xGm 5pWcoyTDFMQdYTNgh4eUBbl5llBnNV9+t96B5zdegj X-Received: by 2002:a05:7300:e424:b0:304:819f:5029 with SMTP id 5a478bee46e88-304819f50famr3123286eec.2.1779776288205; Mon, 25 May 2026 23:18:08 -0700 (PDT) Received: from sw08.internal.sifive.com ([4.53.31.132]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-30452461cb5sm14062504eec.31.2026.05.25.23.18.07 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 25 May 2026 23:18:07 -0700 (PDT) From: Jesse Huang To: libc-alpha@sourceware.org Cc: andrew@sifive.com, darius@bluespec.com, debug@rivosinc.com, jeffreyalaw@gmail.com, kito.cheng@sifive.com, palmer@dabbelt.com, Jesse Huang , Jerry Zhang Jian Subject: [PATCH v4 13/17] riscv/cfi: Add internal sigset_t union and use it for both ucontext/jmpbuf Date: Mon, 25 May 2026 23:16:59 -0700 Message-Id: <20260526061703.2188042-14-jesse.huang@sifive.com> X-Mailer: git-send-email 2.39.3 In-Reply-To: <20260526061703.2188042-1-jesse.huang@sifive.com> References: <20260526061703.2188042-1-jesse.huang@sifive.com> MIME-Version: 1.0 X-Spam-Status: No, score=-13.2 required=5.0 tests=BAYES_00, DKIM_SIGNED, DKIM_VALID, DKIM_VALID_AU, DKIM_VALID_EF, GIT_PATCH_0, RCVD_IN_DNSWL_BLOCKED, SPF_HELO_NONE, SPF_PASS, TXREP, URIBL_BLOCKED shortcircuit=no autolearn=ham autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on sourceware.org X-BeenThere: libc-alpha@sourceware.org X-Mailman-Version: 2.1.30 Precedence: list List-Id: Libc-alpha mailing list List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: libc-alpha-bounces~patchwork=sourceware.org@sourceware.org Co-authored-by: Jerry Zhang Jian --- .../sysv/linux/riscv/bits/types/__sigset_t.h | 43 +++++++++++++++++++ sysdeps/unix/sysv/linux/riscv/setjmpP.h | 31 +------------ sysdeps/unix/sysv/linux/riscv/sys/ucontext.h | 14 +++++- 3 files changed, 57 insertions(+), 31 deletions(-) create mode 100644 sysdeps/unix/sysv/linux/riscv/bits/types/__sigset_t.h diff --git a/sysdeps/unix/sysv/linux/riscv/bits/types/__sigset_t.h b/sysdeps/unix/sysv/linux/riscv/bits/types/__sigset_t.h new file mode 100644 index 0000000000..d83c76876d --- /dev/null +++ b/sysdeps/unix/sysv/linux/riscv/bits/types/__sigset_t.h @@ -0,0 +1,43 @@ +/* Architecture-specific __sigset_t definition. RISC-V version. */ +#ifndef ____sigset_t_defined +#define ____sigset_t_defined + +#define _SIGSET_NWORDS (1024 / (8 * sizeof (unsigned long int))) +typedef struct +{ + unsigned long int __val[_SIGSET_NWORDS]; +} __sigset_t; + +#define __ALIGN_DOWN(base, size) ((base) & -((__typeof__ (base)) (size))) +#define __ALIGN_UP(base, size) __ALIGN_DOWN ((base) + (size) - 1, (size)) + +/* Number of bits per long. */ +#define _SSP_SIGSET_BITS_PER_WORD (8 * sizeof (unsigned long int)) +/* This holds the number of signals, 512 should be sufficient for future. + expansion */ +#define _SSP_SIGSET_NSIG 512 +/* Number of longs to hold all signals. */ +#define _SSP_SIGSET_NWORDS \ + (__ALIGN_UP (_SSP_SIGSET_NSIG, _SSP_SIGSET_BITS_PER_WORD) \ + / _SSP_SIGSET_BITS_PER_WORD) + +typedef struct + { + unsigned long int __val[_SSP_SIGSET_NWORDS]; + } __ssp_sigset_t; + +typedef union + { + __sigset_t __saved_mask_compat; + struct + { + __ssp_sigset_t __saved_mask; + /* Used for shadow stack pointer. NB: Shadow stack pointer + must have the same alignment as __saved_mask. Otherwise + offset of __saved_mask will be changed. */ + unsigned long int __ssp; + unsigned long int __ssp_base; + } __saved; + } __ssp_sigset_arch_t; + +#endif diff --git a/sysdeps/unix/sysv/linux/riscv/setjmpP.h b/sysdeps/unix/sysv/linux/riscv/setjmpP.h index 43cb28e2d1..b237f7baf4 100644 --- a/sysdeps/unix/sysv/linux/riscv/setjmpP.h +++ b/sysdeps/unix/sysv/linux/riscv/setjmpP.h @@ -23,42 +23,13 @@ #include #include -/* Number of bits per long. */ -#define _JUMP_BUF_SIGSET_BITS_PER_WORD (8 * sizeof (unsigned long int)) -/* This holds the number of signals, 512 should be sufficient for future. - expansion */ -#define _JUMP_BUF_SIGSET_NSIG 512 -/* Number of longs to hold all signals. */ -#define _JUMP_BUF_SIGSET_NWORDS \ - (ALIGN_UP (_JUMP_BUF_SIGSET_NSIG, _JUMP_BUF_SIGSET_BITS_PER_WORD) \ - / _JUMP_BUF_SIGSET_BITS_PER_WORD) - -typedef struct - { - unsigned long int __val[_JUMP_BUF_SIGSET_NWORDS]; - } __jmp_buf_sigset_t; - -typedef union - { - __sigset_t __saved_mask_compat; - struct - { - __jmp_buf_sigset_t __saved_mask; - /* Used for shadow stack pointer. NB: Shadow stack pointer - must have the same alignment as __saved_mask. Otherwise - offset of __saved_mask will be changed. */ - unsigned long int __ssp; - unsigned long int __ssp_base; - } __saved; - } __jmpbuf_arch_t; - /* has NB: We use setjmp in thread cancellation and this saves the shadow stack register, but __libc_unwind_longjmp doesn't restore the shadow stack register since cancellation never returns after longjmp. */ #undef __sigset_t -#define __sigset_t __jmpbuf_arch_t +#define __sigset_t __ssp_sigset_arch_t #include #undef __saved_mask #define __saved_mask __saved_mask.__saved.__saved_mask diff --git a/sysdeps/unix/sysv/linux/riscv/sys/ucontext.h b/sysdeps/unix/sysv/linux/riscv/sys/ucontext.h index 312be3cfc3..37cfc41fb6 100644 --- a/sysdeps/unix/sysv/linux/riscv/sys/ucontext.h +++ b/sysdeps/unix/sysv/linux/riscv/sys/ucontext.h @@ -23,6 +23,7 @@ #include +#include #include #include @@ -90,7 +91,18 @@ typedef struct ucontext_t unsigned long int __uc_flags; struct ucontext_t *uc_link; stack_t uc_stack; - sigset_t uc_sigmask; + /* Internal overlay for uc_sigmask to store CFI shadow stack state while + keeping the public API type as sigset_t. */ + union + { + sigset_t uc_sigmask; /* Public view. */ + struct + { + __ssp_sigset_t __saved_mask; + unsigned long int __ssp; + unsigned long int __ssp_base; + } __saved; /* Internal view. */ + }; /* There's some padding here to allow sigset_t to be expanded in the future. Though this is unlikely, other architectures put uc_sigmask at the end of this structure and explicitly state it can be From patchwork Tue May 26 06:17:00 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Jesse Huang X-Patchwork-Id: 135667 Return-Path: X-Original-To: patchwork@sourceware.org Delivered-To: patchwork@sourceware.org Received: from vm01.sourceware.org (localhost [IPv6:::1]) by sourceware.org (Postfix) with ESMTP id 38BB44BA23FF for ; Tue, 26 May 2026 06:26:53 +0000 (GMT) DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org 38BB44BA23FF Authentication-Results: sourceware.org; dkim=pass (2048-bit key, unprotected) header.d=sifive.com header.i=@sifive.com header.a=rsa-sha256 header.s=google header.b=mPUP2bDY X-Original-To: libc-alpha@sourceware.org Delivered-To: libc-alpha@sourceware.org Received: from mail-dy1-x132b.google.com (mail-dy1-x132b.google.com [IPv6:2607:f8b0:4864:20::132b]) by sourceware.org (Postfix) with ESMTPS id 7B7164BA79AC for ; Tue, 26 May 2026 06:18:11 +0000 (GMT) DMARC-Filter: OpenDMARC Filter v1.4.2 sourceware.org 7B7164BA79AC Authentication-Results: sourceware.org; dmarc=pass (p=reject dis=none) header.from=sifive.com Authentication-Results: sourceware.org; spf=pass smtp.mailfrom=sifive.com ARC-Filter: OpenARC Filter v1.0.0 sourceware.org 7B7164BA79AC Authentication-Results: sourceware.org; arc=none smtp.remote-ip=2607:f8b0:4864:20::132b ARC-Seal: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1779776291; cv=none; b=CsrxRVPPtF6QlsV47MB1i2ZOpSlSfPGZ8PS2NkrXfRhRjHo8U6yYFjJd41NnGLXLVpf8GHlsUR1+DWeC5seQPMh1zD92xOvj2FIsoS6Y1XV9Yxn18IFUMfP63mllOOxayBZ2gHWAoHmwoVeY+Vswas2XJkLWoSPY4G6Cc/IK45g= ARC-Message-Signature: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1779776291; c=relaxed/simple; bh=qDM6Td+DoOdr1RM+QClxzACrCNisuMqcAMW2DlXHdmY=; h=DKIM-Signature:From:To:Subject:Date:Message-Id:MIME-Version; b=JmX7z+GzxtR0/540tCWdwdDERqfa6XrxoWqftY1jx/InpgF5Fy3aheZfYUl4IRDx37TDFfbWZb2H3h4Mk30leU+NUSxhzoyRw8Tv8UHzwEMaB41e3hY7QnS3yVxIc5m78jYEQhX8eZEF60tE2K81CGaiIRsF8eMpGj/T4+SCu8w= ARC-Authentication-Results: i=1; sourceware.org; dkim=pass (2048-bit key, unprotected) header.d=sifive.com header.i=@sifive.com header.a=rsa-sha256 header.s=google header.b=mPUP2bDY DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org 7B7164BA79AC Received: by mail-dy1-x132b.google.com with SMTP id 5a478bee46e88-304545f5206so5001916eec.0 for ; Mon, 25 May 2026 23:18:11 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=sifive.com; s=google; t=1779776290; x=1780381090; darn=sourceware.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to; bh=7fGT7vQBRvb5Odmn5g3tK4qYpMc1hmhO4ohtwDfHjnE=; b=mPUP2bDYibbcDwLmxPlzjpV6wQ3KW/vT3Vm0Ib6W8j3ak4mEbgtvGwcn1qllqV48NN K00rF+Ak7cq5Zig3LOkM/PEKm+1ZQNkDD4s9ZbUFPMRhwNPagxd1CSHaJQVtY5N62ab7 qHhC2EEgM00hjBaQd69dtOWCj9o/8u1QLvq7LcS73nuFLtWEIVR6OAKfm6OIjFi0hVAR rLVD76isPSogHF6M6AV/E1zYCBbFVAwxjtUwJgG9ylwn9PUXr1rU/f5sPWpwC9lm6CcV crBSBKZK4nqTCNF2BJ67oERVR6uwj7pAfQ8do6nF9XgJM5bXXTMMElKQUlRlifH/nD7G oLMA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1779776290; x=1780381090; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to; bh=7fGT7vQBRvb5Odmn5g3tK4qYpMc1hmhO4ohtwDfHjnE=; b=masm/IXGKfBLUaQ7hrUvmgSU0J3ioRPF4sYiIAi84hXDDkmDtkJGKlU9ue5h198rTe VATUs/W4GfbPYlD4Ac/ToLSxAiO5WH/n3OTANcrvpZPPy3FA0sbYNw1APXvgWiFqOHao xHvCmYjTDEKQs4OWWLuA7o3sU5kodhuvG8Yum2FORIw6ukmbEYsT8aJlLI0zgT6LXO7/ 7Q3rhon7MAl9Xg8k0PardiPEOt+s4vjseGUwlb0O5JKk1Yf72qIrNG5hwkKyccc2Y3Zi 6jsMwXAQurx6mOcOOrDSa6jbttrgtZ40nv/JlaYrIoJrCtSh877a34Jb6qrQ0c1iMB2/ 1YSQ== X-Gm-Message-State: AOJu0YwejP8MF2ziNYC8s4Lb8ThvdCuL9pHKp5n7ZdFGk4ZIKSlbxP9l jpxNQQQE5HEFWtJ5MFcb7H/pnvp3LvmLZz45QCsngkFgRrqcxWIZWTaAugXTM3HQge4Enh2+aU3 nRzufr5Ks0mQMnNpCmMTcFNvgg67LAn0s7eUM9YAZvBGDAIhWVTgzHgqs9ldhDNBbeEpu/vpuqT WGn15i3X0EFVDt6VhtMyMFOxJbp7nARj40R5pcEv5r8QMunmfJjhA= X-Gm-Gg: Acq92OG3XPsXaCxIYJ6nR1b3V9cIuvHQPgsjY5TSUbKvbv0sNrxWD7tvAKuVZ6EDhhY Qir/AOtPMVxMwTT8MZnIaTONbQlC9ZIzG0AVYfIrt9CM7D+CYSZoLjBUEvLWOn77kcXFnHNspzn vmxsvptTuBbjZrbX8pvx0+oLZLI5rLXmjXl6ohTMzNtmtaqAm2T0k38TQy8pT+rs/ZDE+beyrEQ R5kDg5g1OEzfzm5V0gn5Nca/n0cedb8kvEdbLWZanauF4fem4dwWvsQys85WQlL8AjoQU0OITMQ sh/GxC+Jvz6x8U4Qd71MTkr/wdINqvgEVRj521wxTDTjkexRfJz+JhFUU+nwi4t7axHJFBK/kW4 /nE7w/aYS4OkQ42/7fYIX1x/mlE2zGLFWVXe1M7ZyMaE2yYEMbWV237wGC1pE/wi6BdqVRq172u 0+lzbgRLU50JfxVLQSfrHu8pYkbPMPwibsVTwNQq84 X-Received: by 2002:a05:7300:1352:b0:2cb:4b8f:b2bd with SMTP id 5a478bee46e88-30448fd6144mr7609077eec.6.1779776290126; Mon, 25 May 2026 23:18:10 -0700 (PDT) Received: from sw08.internal.sifive.com ([4.53.31.132]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-30452461cb5sm14062504eec.31.2026.05.25.23.18.08 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 25 May 2026 23:18:09 -0700 (PDT) From: Jesse Huang To: libc-alpha@sourceware.org Cc: andrew@sifive.com, darius@bluespec.com, debug@rivosinc.com, jeffreyalaw@gmail.com, kito.cheng@sifive.com, palmer@dabbelt.com, Jesse Huang , Valentin Haudiquet , Jerry Zhang Jian Subject: [PATCH v4 14/17] riscv/cfi: Add __allocate_shadow_stack for mapping new shadow stack Date: Mon, 25 May 2026 23:17:00 -0700 Message-Id: <20260526061703.2188042-15-jesse.huang@sifive.com> X-Mailer: git-send-email 2.39.3 In-Reply-To: <20260526061703.2188042-1-jesse.huang@sifive.com> References: <20260526061703.2188042-1-jesse.huang@sifive.com> MIME-Version: 1.0 X-Spam-Status: No, score=-13.2 required=5.0 tests=BAYES_00, DKIM_SIGNED, DKIM_VALID, DKIM_VALID_AU, DKIM_VALID_EF, GIT_PATCH_0, KAM_SHORT, RCVD_IN_DNSWL_BLOCKED, SPF_HELO_NONE, SPF_PASS, TXREP, URIBL_BLOCKED shortcircuit=no autolearn=ham autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on sourceware.org X-BeenThere: libc-alpha@sourceware.org X-Mailman-Version: 2.1.30 Precedence: list List-Id: Libc-alpha mailing list List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: libc-alpha-bounces~patchwork=sourceware.org@sourceware.org Co-authored-by: Valentin Haudiquet Co-authored-by: Jerry Zhang Jian --- sysdeps/unix/sysv/linux/riscv/Makefile | 1 + .../sysv/linux/riscv/allocate-shadow-stack.c | 59 +++++++++++++++++++ .../sysv/linux/riscv/allocate-shadow-stack.h | 31 ++++++++++ sysdeps/unix/sysv/linux/riscv/bits/mman.h | 30 ++++++++++ sysdeps/unix/sysv/linux/riscv/sysdep.h | 2 + 5 files changed, 123 insertions(+) create mode 100644 sysdeps/unix/sysv/linux/riscv/allocate-shadow-stack.c create mode 100644 sysdeps/unix/sysv/linux/riscv/allocate-shadow-stack.h create mode 100644 sysdeps/unix/sysv/linux/riscv/bits/mman.h diff --git a/sysdeps/unix/sysv/linux/riscv/Makefile b/sysdeps/unix/sysv/linux/riscv/Makefile index 04abf226ad..e6b1a02c59 100644 --- a/sysdeps/unix/sysv/linux/riscv/Makefile +++ b/sysdeps/unix/sysv/linux/riscv/Makefile @@ -5,6 +5,7 @@ sysdep_headers += \ # sysdep_headers sysdep_routines += \ + allocate-shadow-stack \ flush-icache \ hwprobe \ # sysdep_routines diff --git a/sysdeps/unix/sysv/linux/riscv/allocate-shadow-stack.c b/sysdeps/unix/sysv/linux/riscv/allocate-shadow-stack.c new file mode 100644 index 0000000000..e64ddb2c56 --- /dev/null +++ b/sysdeps/unix/sysv/linux/riscv/allocate-shadow-stack.c @@ -0,0 +1,59 @@ +/* Helper function to allocate shadow stack. + Copyright (C) 2023-2026 Free Software Foundation, Inc. + This file is part of the GNU C Library. + + The GNU C Library is free software; you can redistribute it and/or + modify it under the terms of the GNU Lesser General Public + License as published by the Free Software Foundation; either + version 2.1 of the License, or (at your option) any later version. + + The GNU C Library is distributed in the hope that it will be useful, + but WITHOUT ANY WARRANTY; without even the implied warranty of + MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU + Lesser General Public License for more details. + + You should have received a copy of the GNU Lesser General Public + License along with the GNU C Library; if not, see + . */ + +#include +#include +#include +#include +#include +#include + +#ifndef SHADOW_STACK_SET_TOKEN +# define SHADOW_STACK_SET_TOKEN 0 +#endif + +/* NB: This can be treated as a syscall by caller. */ + +long int +__allocate_shadow_stack (size_t stack_size, + shadow_stack_size_t *child_stack) +{ +#ifdef __NR_map_shadow_stack + size_t shadow_stack_size + = stack_size >> STACK_SIZE_TO_SHADOW_STACK_SIZE_SHIFT; + /* Align shadow stack to 8 bytes. */ + shadow_stack_size = ALIGN_UP (shadow_stack_size, 8); + /* Since sigaltstack shares shadow stack with the current context in + the thread, add extra 20 stack frames in shadow stack for signal + handlers. */ + shadow_stack_size += 20 * 8; + void *shadow_stack = (void *)INLINE_SYSCALL_CALL + (map_shadow_stack, NULL, shadow_stack_size, SHADOW_STACK_SET_TOKEN); + /* Report the map_shadow_stack error. */ + if (shadow_stack < 0) + return -errno; + + /* Save the shadow stack base and size on child stack. */ + child_stack[0] = (uintptr_t) shadow_stack; + child_stack[1] = shadow_stack_size; + + return 0; +#else + return -ENOSYS; +#endif +} diff --git a/sysdeps/unix/sysv/linux/riscv/allocate-shadow-stack.h b/sysdeps/unix/sysv/linux/riscv/allocate-shadow-stack.h new file mode 100644 index 0000000000..4e361c8566 --- /dev/null +++ b/sysdeps/unix/sysv/linux/riscv/allocate-shadow-stack.h @@ -0,0 +1,31 @@ +/* Helper function to allocate shadow stack. + Copyright (C) 2023-2026 Free Software Foundation, Inc. + This file is part of the GNU C Library. + + The GNU C Library is free software; you can redistribute it and/or + modify it under the terms of the GNU Lesser General Public + License as published by the Free Software Foundation; either + version 2.1 of the License, or (at your option) any later version. + + The GNU C Library is distributed in the hope that it will be useful, + but WITHOUT ANY WARRANTY; without even the implied warranty of + MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU + Lesser General Public License for more details. + + You should have received a copy of the GNU Lesser General Public + License along with the GNU C Library; if not, see + . */ + +#include + +#ifdef __riscv_shadow_stack +/* When shadow stack is enabled, derive the storage type from ucontext. */ +typedef __typeof (((ucontext_t *) 0)->__saved.__ssp) \ + shadow_stack_size_t; +#else +/* Without shadow stack support, use an unsigned long placeholder type. */ +typedef unsigned long int shadow_stack_size_t; +#endif + +extern long int __allocate_shadow_stack (size_t, shadow_stack_size_t *) + attribute_hidden; diff --git a/sysdeps/unix/sysv/linux/riscv/bits/mman.h b/sysdeps/unix/sysv/linux/riscv/bits/mman.h new file mode 100644 index 0000000000..46f50be71c --- /dev/null +++ b/sysdeps/unix/sysv/linux/riscv/bits/mman.h @@ -0,0 +1,30 @@ +/* Definitions for POSIX memory map interface. Linux/risc-v version. + Copyright (C) 1997-2026 Free Software Foundation, Inc. + This file is part of the GNU C Library. + + The GNU C Library is free software; you can redistribute it and/or + modify it under the terms of the GNU Lesser General Public + License as published by the Free Software Foundation; either + version 2.1 of the License, or (at your option) any later version. + + The GNU C Library is distributed in the hope that it will be useful, + but WITHOUT ANY WARRANTY; without even the implied warranty of + MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU + Lesser General Public License for more details. + + You should have received a copy of the GNU Lesser General Public + License along with the GNU C Library. If not, see + . */ + +#ifndef _SYS_MMAN_H +# error "Never use directly; include instead." +#endif + +#if defined __USE_MISC && defined __riscv_shadow_stack +# define SHADOW_STACK_SET_TOKEN 0x1 +#endif + +#include + +/* Include generic Linux declarations. */ +#include diff --git a/sysdeps/unix/sysv/linux/riscv/sysdep.h b/sysdeps/unix/sysv/linux/riscv/sysdep.h index 761a833609..75b1cc4fda 100644 --- a/sysdeps/unix/sysv/linux/riscv/sysdep.h +++ b/sysdeps/unix/sysv/linux/riscv/sysdep.h @@ -206,6 +206,8 @@ GNU_PROPERTY (FEATURE_1_AND, __VALUE_FOR_FEATURE_1_AND) #else /* !__ASSEMBLER__ */ +# define STACK_SIZE_TO_SHADOW_STACK_SIZE_SHIFT 5 + # if __WORDSIZE == 64 # define VDSO_NAME "LINUX_4.15" # define VDSO_HASH 182943605 From patchwork Tue May 26 06:17:01 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Jesse Huang X-Patchwork-Id: 135656 Return-Path: X-Original-To: patchwork@sourceware.org Delivered-To: patchwork@sourceware.org Received: from vm01.sourceware.org (localhost [IPv6:::1]) by sourceware.org (Postfix) with ESMTP id 22EB64BA799F for ; Tue, 26 May 2026 06:21:33 +0000 (GMT) DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org 22EB64BA799F Authentication-Results: sourceware.org; dkim=pass (2048-bit key, unprotected) header.d=sifive.com header.i=@sifive.com header.a=rsa-sha256 header.s=google header.b=Vqj2fenL X-Original-To: libc-alpha@sourceware.org Delivered-To: libc-alpha@sourceware.org Received: from mail-dy1-x1333.google.com (mail-dy1-x1333.google.com [IPv6:2607:f8b0:4864:20::1333]) by sourceware.org (Postfix) with ESMTPS id 921FC4BA79AB for ; Tue, 26 May 2026 06:18:12 +0000 (GMT) DMARC-Filter: OpenDMARC Filter v1.4.2 sourceware.org 921FC4BA79AB Authentication-Results: sourceware.org; dmarc=pass (p=reject dis=none) header.from=sifive.com Authentication-Results: sourceware.org; spf=pass smtp.mailfrom=sifive.com ARC-Filter: OpenARC Filter v1.0.0 sourceware.org 921FC4BA79AB Authentication-Results: sourceware.org; arc=none smtp.remote-ip=2607:f8b0:4864:20::1333 ARC-Seal: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1779776292; cv=none; b=DlKk+IZZm8tCxi9Ij+Pt8WX3Ba9RBOWOBrHNS5lzfFnTpMk1LvYCXxwIHz09nuUL++Kzqb0CHoLm2HOoFUv9IGzxTNy3ueUAeRCFZRpNS1Jt2maSVxw+Cqwn+nrtm+6e8xcSqeYN1TpFb0s1aCs7zeLfGYWM3xMGWAtwsurND6I= ARC-Message-Signature: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1779776292; c=relaxed/simple; bh=5zS5znPN4FTo7DwGBRUfLZ8wBWsgkt3wCliU2devvIU=; h=DKIM-Signature:From:To:Subject:Date:Message-Id:MIME-Version; b=kgB/mYmx9as0cviNlPE49Ev9noY+KRIuuIDuLbPa6g7osvtWzEd5xeuxD054uZl+NrU1M3Ld9S033lXD9O2DOQ9oB3xNoVoULlC/OF/Pqj26uI5nSLr5yAo1vsr3E41+mrx6AqXh2j7iXn96gDQA2uyF6aJk6qwDoi8pVTpf3P4= ARC-Authentication-Results: i=1; sourceware.org; dkim=pass (2048-bit key, unprotected) header.d=sifive.com header.i=@sifive.com header.a=rsa-sha256 header.s=google header.b=Vqj2fenL DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org 921FC4BA79AB Received: by mail-dy1-x1333.google.com with SMTP id 5a478bee46e88-303dbfbec77so11957078eec.0 for ; Mon, 25 May 2026 23:18:12 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=sifive.com; s=google; t=1779776292; x=1780381092; darn=sourceware.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to; bh=0NLBmYjJ6gRxW5p9mEhQaVJntUtLp5T//cTeguj+2h8=; b=Vqj2fenL6yE4/5CZbtHHRcdZJbI6h31rPnm2MEWuJ6HjC4U6fWycXPvGr8j+ldTGrU LWiN2ZEF77/WXarzVvKJETzLb2ufghE453sNzQVRJYmvXKTFSbWjxr0vk6fM9Vui5QQt /Zaz9oJhxqt2cire1TkbNXD0FffP9ocDtvDG/ntDJvL3/8FKwNAAp0Sdvrj2lbX8WTqk E37336Hh9U7IjEsKW6zUdb1XmQKbSpv51OhfAkMzvAyD+B8WFqNC9fmSR0xdH4Eh6X2r IY5mT+49YqqMaUC8Qmvh2+N1xBVEuWD0GzpeQEA7fZagiAON1wiMp+O9DDbxhCHduPBH 5Jrw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1779776292; x=1780381092; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to; bh=0NLBmYjJ6gRxW5p9mEhQaVJntUtLp5T//cTeguj+2h8=; b=i6fQQ2YxLnLwyCn1O/3kex6KDUYLC4pxFF7mNDzkUF6CgIXF7fb478vzEpYGwsJ/Bf F5kBMIq9qStwANgd25FlNaR1o8jK2lZIYnucVYxsNRKAQPMCDUPU8mEm+JE7mPo870U0 /wt79mVzuQH33ed6uKItNhyMtmJtbpUkJ4IKuX/pC2dQ24fP75n936fXdFi8r3N9aCct Z8BYUh/67LY0DnqHuTM12zO0VnRiYTR6dmAS/7HVFyOnpVTKo3xRme4lHX+lKqMhrs5U 75gRA9JobAmyfNvu1IVwY5reoFGfk+Dx+8iBEzRQsYw//SMg6KZYA41yHE+KD11OT3IP 1baA== X-Gm-Message-State: AOJu0YzIWhCdx0jr8T8HBz2wojioIXDRS/4vcmk2jVrSZvpS274n5rcX 93j7my0Cy7ryFuXlCIk/g5VBUiz/KUjxoZ8Y0pk84GOii63E22hEmAkxzdd5OQ+gq6Hp8PStjn0 4U51n3VmZhDzIHIL9StGMUgH5ghArPdDqzGoiBPaKYjvGNl07Gjbp6CTtElJzv/fTLURjsnKJYI LVDOdWtrHalUy9Xm5n6/dtstvpeuC63px5TwQqD6spvbPJ5ct414Y= X-Gm-Gg: Acq92OF0cDYqX97/RcLctRJzpZL7I6V9pddQdqDFlC6E8g0xviVKggHE6Tg95FnjAxw 48jgwcTlcK9TiaTiLzuMBtNsV2UmnrykbyFLj4NHD8zg6pk3xHa+qbC3ucuZCFfizwhUEm2AcTw huRE5YPytM+2GvioX/QELF4qIPFcQrr0Bc3oYw1TmJxLoLcAzibytH43PVkVyQlGaJmDpHRoWDt 62H7Ja5nIDF9mM9zgKJEcWvKW7H1xQis1U3OLSpv7Pak015v2cDFCYI65bSE321Fh0/KWOS3D9e VaOj/Xhdrtgw74Yuh6O3SiPMYrX+uRo2XelOATWFK2LQEjUp/GhfsHUQjfA7z401qKJ186v6/xO DtSAdTA8cCduZitgJ+yFmqBhRgOqxleEoT/WM+j2YvcCs7Y+W7jk5jKcYznsefd32yz4g47zEOi u9oWAkOms2e9xeU+JRM+YwSvjVqi3BD2cRN5LnX+EA X-Received: by 2002:a05:7301:fa0f:b0:304:2cc9:2ba3 with SMTP id 5a478bee46e88-3044905b65cmr8010137eec.22.1779776291063; Mon, 25 May 2026 23:18:11 -0700 (PDT) Received: from sw08.internal.sifive.com ([4.53.31.132]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-30452461cb5sm14062504eec.31.2026.05.25.23.18.10 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 25 May 2026 23:18:10 -0700 (PDT) From: Jesse Huang To: libc-alpha@sourceware.org Cc: andrew@sifive.com, darius@bluespec.com, debug@rivosinc.com, jeffreyalaw@gmail.com, kito.cheng@sifive.com, palmer@dabbelt.com, Jesse Huang , Nia Su Subject: [PATCH v4 15/17] riscv/cfi: Support ucontext under CFI Date: Mon, 25 May 2026 23:17:01 -0700 Message-Id: <20260526061703.2188042-16-jesse.huang@sifive.com> X-Mailer: git-send-email 2.39.3 In-Reply-To: <20260526061703.2188042-1-jesse.huang@sifive.com> References: <20260526061703.2188042-1-jesse.huang@sifive.com> MIME-Version: 1.0 X-Spam-Status: No, score=-13.2 required=5.0 tests=BAYES_00, DKIM_SIGNED, DKIM_VALID, DKIM_VALID_AU, DKIM_VALID_EF, GIT_PATCH_0, KAM_SHORT, RCVD_IN_DNSWL_BLOCKED, SPF_HELO_NONE, SPF_PASS, TXREP, URIBL_BLOCKED shortcircuit=no autolearn=ham autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on sourceware.org X-BeenThere: libc-alpha@sourceware.org X-Mailman-Version: 2.1.30 Precedence: list List-Id: Libc-alpha mailing list List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: libc-alpha-bounces~patchwork=sourceware.org@sourceware.org This patch adds support for shadow stack and landing pad to the ucontext library, shadow stack switches are protected by a shadow stack restore token which will be validated during the switch. Co-authored-by: Nia Su --- sysdeps/unix/sysv/linux/riscv/getcontext.S | 20 +++++ sysdeps/unix/sysv/linux/riscv/makecontext.c | 19 +++++ sysdeps/unix/sysv/linux/riscv/setcontext.S | 67 ++++++++++++++++ sysdeps/unix/sysv/linux/riscv/swapcontext.S | 81 +++++++++++++++++++- sysdeps/unix/sysv/linux/riscv/ucontext_i.sym | 4 +- 5 files changed, 189 insertions(+), 2 deletions(-) diff --git a/sysdeps/unix/sysv/linux/riscv/getcontext.S b/sysdeps/unix/sysv/linux/riscv/getcontext.S index fd55c3e7da..ff1512c2aa 100644 --- a/sysdeps/unix/sysv/linux/riscv/getcontext.S +++ b/sysdeps/unix/sysv/linux/riscv/getcontext.S @@ -17,11 +17,13 @@ . */ #include "ucontext-macros.h" +#include "tcb-offsets.h" /* int getcontext (ucontext_t *ucp) */ .text LEAF (__getcontext) + LPAD SAVE_INT_REG (ra, 0, a0) SAVE_INT_REG (ra, 1, a0) SAVE_INT_REG (sp, 2, a0) @@ -58,6 +60,24 @@ LEAF (__getcontext) sw a1, MCONTEXT_FSR(a0) #endif /* __riscv_float_abi_soft */ +#ifdef __riscv_shadow_stack + ssrdp t0 + beqz t0, .Lskip_ss + /* Read ssp_base from TLS */ + REG_L t1, TLS_SSP_BASE_OFFSET(tp) + + bnez t1, .Lbase_saved + /* if not found, save and use current ssp as the marker */ + mv t1, t0 + REG_S t1, TLS_SSP_BASE_OFFSET(tp) + +.Lbase_saved: + /* Save caller's ssp and base marker to ucontext */ + REG_S t1, UCONTEXT_SSP_BASE(a0) + REG_S t0, UCONTEXT_SSP(a0) +.Lskip_ss: +#endif + /* rt_sigprocmask (SIG_BLOCK, NULL, &ucp->uc_sigmask, _NSIG8) */ li a3, _NSIG8 add a2, a0, UCONTEXT_SIGMASK diff --git a/sysdeps/unix/sysv/linux/riscv/makecontext.c b/sysdeps/unix/sysv/linux/riscv/makecontext.c index 7f8ab46bd0..37c922c440 100644 --- a/sysdeps/unix/sysv/linux/riscv/makecontext.c +++ b/sysdeps/unix/sysv/linux/riscv/makecontext.c @@ -21,6 +21,9 @@ #include #include #include +#ifdef __riscv_shadow_stack +#include +#endif void __makecontext (ucontext_t *ucp, void (*func) (void), int argc, @@ -73,6 +76,22 @@ __makecontext (ucontext_t *ucp, void (*func) (void), int argc, va_end (vl); } +#ifdef __riscv_shadow_stack + /* Allocate shadow stack for the new context */ + + /* shstk_size[0]: shadow stack base + shstk_size[1]: shadow stack size */ + shadow_stack_size_t shstk_size[2]; + int ret = __allocate_shadow_stack(ucp->uc_stack.ss_size, shstk_size); + if (ret != 0) + { + abort(); + } + + ucp->__saved.__ssp_base = shstk_size[0]; + ucp->__saved.__ssp = shstk_size[0] + shstk_size[1] - \ + sizeof (shstk_size[0]); +#endif } weak_alias (__makecontext, makecontext) diff --git a/sysdeps/unix/sysv/linux/riscv/setcontext.S b/sysdeps/unix/sysv/linux/riscv/setcontext.S index 9fd5f1f3cb..89942aec13 100644 --- a/sysdeps/unix/sysv/linux/riscv/setcontext.S +++ b/sysdeps/unix/sysv/linux/riscv/setcontext.S @@ -17,6 +17,7 @@ . */ #include "ucontext-macros.h" +#include "tcb-offsets.h" /* int __setcontext (const ucontext_t *ucp) @@ -29,6 +30,7 @@ .text LEAF (__setcontext) + LPAD mv t0, a0 /* Save ucp into t0. */ @@ -45,6 +47,55 @@ LEAF (__setcontext) cfi_def_cfa (t0, 0) +#ifdef __riscv_shadow_stack + /* Skip if shadow stack is not enabled */ + ssrdp ra + beqz ra, .Lfin + /* We are safe to adjust shadow stack after the sanity check */ + REG_L t1, UCONTEXT_SSP_BASE(t0) + REG_L a1, UCONTEXT_SSP(t0) + REG_L a2, TLS_SSP_BASE_OFFSET(tp) + bne t1, a2, .Ldifferent_stack + +.Lunwind: + bleu a1, ra, .Lfin + /* increase ssp by at most a page size to ensure always run into + a guard page before accidentally point to another legal shadow + stack page */ + /* ra = (a1 - ra >= 4096) ? ra + 4096 : a1 */ + lui t2, 1 + add ra, ra, t2 + bleu ra, a1, 1f + mv ra, a1 +1: + csrw ssp, ra + /* Test if the location pointed by ssp is legal */ + sspush ra + sspopchk ra + j .Lunwind + +.Ldifferent_stack: + /* Create restore token */ + sspush ra + mv a4, a1 + +.Lfind_rstor_token: + /* Probe and validate target restore token */ + ssamoswap.d a3, x0, (a4) + addi a2, a4, 8 + beq a3, a2, .Lswitch_stack + /* Restore the shadow stack and try the next slot */ + ssamoswap.d x0, a3, (a4) + addi a4, a4, -8 + j .Lfind_rstor_token + +.Lswitch_stack: + /* Switch stack: update ssp and base */ + csrw ssp, a1 + REG_S t1, TLS_SSP_BASE_OFFSET(tp) +.Lfin: +#endif + #ifndef __riscv_float_abi_soft lw t1, MCONTEXT_FSR(t0) @@ -66,7 +117,11 @@ LEAF (__setcontext) /* Note the contents of argument registers will be random unless makecontext() has been called. */ +#ifdef __riscv_landing_pad + RESTORE_INT_REG (t2, 0, t0) +#else RESTORE_INT_REG (t1, 0, t0) +#endif RESTORE_INT_REG_CFI (ra, 1, t0) RESTORE_INT_REG (sp, 2, t0) RESTORE_INT_REG_CFI (s0, 8, t0) @@ -90,7 +145,12 @@ LEAF (__setcontext) RESTORE_INT_REG_CFI (s10, 26, t0) RESTORE_INT_REG_CFI (s11, 27, t0) +#ifdef __riscv_landing_pad + /* We need to use software-guared jump */ + jr t2 +#else jr t1 +#endif 99: tail __syscall_error @@ -99,12 +159,19 @@ libc_hidden_def (__setcontext) weak_alias (__setcontext, setcontext) LEAF (__start_context) + LPAD /* Terminate call stack by noting ra == 0. Happily, s0 == 0 here. */ cfi_register (ra, s0) /* Call the function passed to makecontext. */ +#ifdef __riscv_landing_pad + /* We need to use software-guared jump */ + mv t2, s1 + jalr t2 +#else jalr s1 +#endif /* Invoke subsequent context if present, else exit(0). */ mv a0, s2 diff --git a/sysdeps/unix/sysv/linux/riscv/swapcontext.S b/sysdeps/unix/sysv/linux/riscv/swapcontext.S index 4b3b0b3a14..72d48f7e26 100644 --- a/sysdeps/unix/sysv/linux/riscv/swapcontext.S +++ b/sysdeps/unix/sysv/linux/riscv/swapcontext.S @@ -17,10 +17,12 @@ . */ #include "ucontext-macros.h" +#include "tcb-offsets.h" /* int swapcontext (ucontext_t *oucp, const ucontext_t *ucp) */ LEAF (__swapcontext) + LPAD mv t0, a1 /* Save ucp into t0. */ SAVE_INT_REG (ra, 0, a0) @@ -59,6 +61,26 @@ LEAF (__swapcontext) sw a1, MCONTEXT_FSR(a0) #endif /* __riscv_float_abi_soft */ +#ifdef __riscv_shadow_stack + /* Skip if shadow stack is not enabled */ + ssrdp ra + beqz ra, .Lsave_fin + + /* Read ssp_base from TLS */ + REG_L t2, TLS_SSP_BASE_OFFSET(tp) + bnez t2, .Lbase_saved + + /* if not found, use current ssp as the marker */ + mv t2, ra + REG_S t2, TLS_SSP_BASE_OFFSET(tp) + +.Lbase_saved: + /* Save caller's ssp and base marker to oucp */ + REG_S t2, UCONTEXT_SSP_BASE(a0) + REG_S ra, UCONTEXT_SSP(a0) +.Lsave_fin: +#endif + /* rt_sigprocmask (SIG_SETMASK, &ucp->uc_sigmask, &oucp->uc_sigmask, _NSIG8) */ li a3, _NSIG8 add a2, a0, UCONTEXT_SIGMASK @@ -70,6 +92,55 @@ LEAF (__swapcontext) bltz a0, 99f +#ifdef __riscv_shadow_stack + /* Skip if shadow stack is not enabled */ + ssrdp ra + beqz ra, .Lfin + /* Load ss information from ucp */ + REG_L a0, UCONTEXT_SSP_BASE(t0) + REG_L a1, UCONTEXT_SSP(t0) + REG_L a2, TLS_SSP_BASE_OFFSET(tp) + bne a0, a2, .Ldifferent_stack + +.Lunwind: + bleu a1, ra, .Lfin + /* increase ssp by at most a page size to ensure always run into + a guard page before accidentally point to another legal shadow + stack page */ + /* ra = (a1 - ra >= 4096) ? ra + 4096 : a1 */ + lui t2, 1 + add ra, ra, t2 + bleu ra, a1, 1f + mv ra, a1 +1: + csrw ssp, ra + /* Test if the location pointed by ssp is legal */ + sspush ra + sspopchk ra + j .Lunwind + +.Ldifferent_stack: + /* Create restore token */ + sspush ra + mv a4, a1 + +.Lfind_rstor_token: + /* Probe and validate target restore token */ + ssamoswap.d a3, x0, (a4) + addi a2, a4, 8 + beq a3, a2, .Lswitch_stack + /* Restore the shadow stack and try the next slot */ + ssamoswap.d x0, a3, (a4) + addi a4, a4, -8 + j .Lfind_rstor_token + +.Lswitch_stack: + /* Switch stack: update ssp and base */ + csrw ssp, a1 + REG_S a0, TLS_SSP_BASE_OFFSET(tp) +.Lfin: +#endif + #ifndef __riscv_float_abi_soft lw t1, MCONTEXT_FSR(t0) @@ -91,7 +162,11 @@ LEAF (__swapcontext) /* Note the contents of argument registers will be random unless makecontext() has been called. */ +#ifdef __riscv_landing_pad + RESTORE_INT_REG (t2, 0, t0) +#else RESTORE_INT_REG (t1, 0, t0) +#endif RESTORE_INT_REG (ra, 1, t0) RESTORE_INT_REG (sp, 2, t0) RESTORE_INT_REG (s0, 8, t0) @@ -115,8 +190,12 @@ LEAF (__swapcontext) RESTORE_INT_REG (s10, 26, t0) RESTORE_INT_REG (s11, 27, t0) +#ifdef __riscv_landing_pad + /* We need to use software-guared jump */ + jr t2 +#else jr t1 - +#endif 99: tail __syscall_error diff --git a/sysdeps/unix/sysv/linux/riscv/ucontext_i.sym b/sysdeps/unix/sysv/linux/riscv/ucontext_i.sym index be55b26310..9a39f761ad 100644 --- a/sysdeps/unix/sysv/linux/riscv/ucontext_i.sym +++ b/sysdeps/unix/sysv/linux/riscv/ucontext_i.sym @@ -19,7 +19,9 @@ UCONTEXT_FLAGS ucontext (__uc_flags) UCONTEXT_LINK ucontext (uc_link) UCONTEXT_STACK ucontext (uc_stack) UCONTEXT_MCONTEXT ucontext (uc_mcontext) -UCONTEXT_SIGMASK ucontext (uc_sigmask) +UCONTEXT_SIGMASK ucontext (__saved.__saved_mask) +UCONTEXT_SSP ucontext (__saved.__ssp) +UCONTEXT_SSP_BASE ucontext (__saved.__ssp_base) STACK_SP stack (ss_sp) STACK_SIZE stack (ss_size) From patchwork Tue May 26 06:17:02 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Jesse Huang X-Patchwork-Id: 135668 Return-Path: X-Original-To: patchwork@sourceware.org Delivered-To: patchwork@sourceware.org Received: from vm01.sourceware.org (localhost [IPv6:::1]) by sourceware.org (Postfix) with ESMTP id E2DFD4BA7989 for ; Tue, 26 May 2026 06:28:08 +0000 (GMT) DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org E2DFD4BA7989 Authentication-Results: sourceware.org; dkim=pass (2048-bit key, unprotected) header.d=sifive.com header.i=@sifive.com header.a=rsa-sha256 header.s=google header.b=kxG8QAhb X-Original-To: libc-alpha@sourceware.org Delivered-To: libc-alpha@sourceware.org Received: from mail-dy1-x132c.google.com (mail-dy1-x132c.google.com [IPv6:2607:f8b0:4864:20::132c]) by sourceware.org (Postfix) with ESMTPS id 363804BA799E for ; Tue, 26 May 2026 06:18:13 +0000 (GMT) DMARC-Filter: OpenDMARC Filter v1.4.2 sourceware.org 363804BA799E Authentication-Results: sourceware.org; dmarc=pass (p=reject dis=none) header.from=sifive.com Authentication-Results: sourceware.org; spf=pass smtp.mailfrom=sifive.com ARC-Filter: OpenARC Filter v1.0.0 sourceware.org 363804BA799E Authentication-Results: sourceware.org; arc=none smtp.remote-ip=2607:f8b0:4864:20::132c ARC-Seal: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1779776293; cv=none; b=ttu4iRGbNeo7bqpC1gxV8A02IspQY2glMGlYSmCw+2nieauDF/6kzjKv7tmeXQ7vGMolJiNEThmLRFfaMTsfTBzLJ4tNKeYw+u6Bmcsspbqcjp+8H44bH5ml2yi6MN33naSrG+TrN7UngwS1OA1/Xwy/RV2LuMUPjb2TkpjP/bk= ARC-Message-Signature: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1779776293; c=relaxed/simple; bh=PT9KuxdOQmjdiTJRVpvXdwwjjoZnn8JbKf+gyh245dU=; h=DKIM-Signature:From:To:Subject:Date:Message-Id:MIME-Version; b=rnOEtjWVpwN6QJUoQM9kn5vhKFStGPfMIw78uTqdycUyS58CXNHP1TSdB6OrOk3sDUbg2oKmmBNaj53AQYzl8J5uwl0t7TNupI0tpSJhoSqI/Qln5vGYMlJiBbTnkRcn6/QyvjSbQzba4tOyl8yEMjmau9xqYpADpODO+VoCyfw= ARC-Authentication-Results: i=1; sourceware.org; dkim=pass (2048-bit key, unprotected) header.d=sifive.com header.i=@sifive.com header.a=rsa-sha256 header.s=google header.b=kxG8QAhb DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org 363804BA799E Received: by mail-dy1-x132c.google.com with SMTP id 5a478bee46e88-304545e6c7fso3855963eec.0 for ; Mon, 25 May 2026 23:18:13 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=sifive.com; s=google; t=1779776292; x=1780381092; darn=sourceware.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to; bh=mZKSJtol0O4hGsIKDCgvo2FIXmaXb8XfLl9LAAAZcIM=; b=kxG8QAhbJtI2TlQirb0gpoYx2OsTnQEQMLzCdNB0E3EjOOo7UbSeyCTyGfz4gTsUFD tzwFeF1nbdrxTTj7e0fn9QqDYOpI6zCGytn71Ea342Lr6Pv5YxqLKResi/Pllvwr/iVV U+kaPLvjVXk/QZJCgf8bpT4hPiOMUJcOJjARluOm2dKyOwP8tn4RgpRbcyf7VQfJB748 ILOi564jwBaD4i6lLEaQ8BcA3KOhxaA8EvyXGEz9OtUpW8cJobgtIEbNx1i8kLCGnf4u 1rR3kntPH7Y/LRojyUV//9Hx+ZZSQpjjphgo6BkH0p4TUgLHtzWsDMpdTSRcKKevk12K goNg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1779776292; x=1780381092; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to; bh=mZKSJtol0O4hGsIKDCgvo2FIXmaXb8XfLl9LAAAZcIM=; b=EJfncg8tNoIlmdVvyIsu3fCu9x+d/SVsKK+o4/eIDZaxSZR0NfEAMlN0TdgoBto5+P AXtLsn0OZLqIfQUJFgR9ipvMwI5EkQPlglPuiSPgIoRVpwB3vu9DrF/LK3eNJ2rWsQIA biAsWwOjGffOyj7JRluaUx8VjwttFN730NUR3B0CIiC6WpujKXw5SBRpv3bWjMtaruZQ 6u465TPK/UKQE4I3bNNQFc+d+HUe8KqUjhS98D/321mT/b8dn5hKfLlV71Xs0WqlVQ3A YIQ1ljR+MxunDbJVPpTPRBPPUMjPj2yw20pFcqUOz3CqAMQwENLz06P/KFBACLJX+qZ9 TcDw== X-Gm-Message-State: AOJu0YxuBTuQ1Ht6xafR1JMYv7lxoKRuSY0jBEILMCVLND2kT4rbipMG geXs1EKltIBIppED3obt+fF73w8EJjFgY2+wyzMumIfBsMvOXNEePge2y7PL6Q2QhNEzKOm7jCj bxyC7FPlgRE8NHbIcg36cTjxBK0KKXL1xkANO7axOd4DB9gXH4OPcC5IoFXlX6JYpj6k9Rwoc0I 5WSGbScg2L3Ot5HY2zWpCXq8EQKgSrOF9GAkrdmt5yCBIc4PH1MfQ= X-Gm-Gg: Acq92OE4UQhLf6Vj9mv4TbXasHOtJLxsrO3Xa08qSKdD874f8VaQU79cxXDkIPw+a6f Kh5JkKD6yUDldXRYNP11gPJc8saLwjeOoJIQI5tVQM6ynn7tSqz4NE8heMU2wTXxPjmee5BxT/e vi1BqXGE3twDV+7gzddCSSqtT9fl9pdQm8I4O4kQ5U3U5bNczhcwruobnsdFN9qcQBLo5URjvGW jAURlbrsUhfy9VpTW/7RUJIEZCHVQUPUAWOuhD7IPDcehpGOsEv4MUNs5txu3v4ufqoRzf2c9kO ULRkVev/qCZD2Q1tgrH0kX1Kp5Pzmnh6Ouf6DfJrP23v/I5Y56MADQ/w8lzbQHmWvf3aNHS3/f0 CZO9s7q1otMbRnUs7h+ERQDn0dfjY2ZlPToTT0kYrU530nu8Nj4bXvdW4gwH2I0nNWluQydUAwK //DV1jp7TFApwwJcju2SUqwJytqPkQjE3r3cL/gHjt X-Received: by 2002:a05:7300:238b:b0:2d9:bc8d:f62a with SMTP id 5a478bee46e88-30449052679mr8234279eec.16.1779776291993; Mon, 25 May 2026 23:18:11 -0700 (PDT) Received: from sw08.internal.sifive.com ([4.53.31.132]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-30452461cb5sm14062504eec.31.2026.05.25.23.18.11 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 25 May 2026 23:18:11 -0700 (PDT) From: Jesse Huang To: libc-alpha@sourceware.org Cc: andrew@sifive.com, darius@bluespec.com, debug@rivosinc.com, jeffreyalaw@gmail.com, kito.cheng@sifive.com, palmer@dabbelt.com, Jesse Huang Subject: [PATCH v4 16/17] riscv/cfi: Add __INDIRECT_RETURN attribute to swapcontext Date: Mon, 25 May 2026 23:17:02 -0700 Message-Id: <20260526061703.2188042-17-jesse.huang@sifive.com> X-Mailer: git-send-email 2.39.3 In-Reply-To: <20260526061703.2188042-1-jesse.huang@sifive.com> References: <20260526061703.2188042-1-jesse.huang@sifive.com> MIME-Version: 1.0 X-Spam-Status: No, score=-13.2 required=5.0 tests=BAYES_00, DKIM_SIGNED, DKIM_VALID, DKIM_VALID_AU, DKIM_VALID_EF, GIT_PATCH_0, KAM_SHORT, RCVD_IN_DNSWL_BLOCKED, SPF_HELO_NONE, SPF_PASS, TXREP, URIBL_BLOCKED shortcircuit=no autolearn=ham autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on sourceware.org X-BeenThere: libc-alpha@sourceware.org X-Mailman-Version: 2.1.30 Precedence: list List-Id: Libc-alpha mailing list List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: libc-alpha-bounces~patchwork=sourceware.org@sourceware.org --- sysdeps/riscv/bits/indirect-return.h | 36 ++++++++++++++++++++++++++++ 1 file changed, 36 insertions(+) create mode 100644 sysdeps/riscv/bits/indirect-return.h diff --git a/sysdeps/riscv/bits/indirect-return.h b/sysdeps/riscv/bits/indirect-return.h new file mode 100644 index 0000000000..1d8f658cc8 --- /dev/null +++ b/sysdeps/riscv/bits/indirect-return.h @@ -0,0 +1,36 @@ +/* Definition of __INDIRECT_RETURN. RISC-V version. + Copyright (C) 2026 Free Software Foundation, Inc. + This file is part of the GNU C Library. + + The GNU C Library is free software; you can redistribute it and/or + modify it under the terms of the GNU Lesser General Public + License as published by the Free Software Foundation; either + version 2.1 of the License, or (at your option) any later version. + + The GNU C Library is distributed in the hope that it will be useful, + but WITHOUT ANY WARRANTY; without even the implied warranty of + MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU + Lesser General Public License for more details. + + You should have received a copy of the GNU Lesser General Public + License along with the GNU C Library; if not, see + . */ + +#ifndef _UCONTEXT_H +# error "Never include directly; use instead." +#endif + +/* __INDIRECT_RETURN indicates that swapcontext may return via + an indirect branch. This happens when GCS is enabled, so + add the attribute if available, otherwise returns_twice has + a similar effect, but it prevents some code transformations + that can cause build failures in some rare cases so it is + only used when GCS is enabled. */ +#if __glibc_has_attribute (__indirect_return__) +# define __INDIRECT_RETURN __attribute__ ((__indirect_return__)) +#elif __glibc_has_attribute (__returns_twice__) \ + && defined __ARM_FEATURE_GCS_DEFAULT +# define __INDIRECT_RETURN __attribute__ ((__returns_twice__)) +#else +# define __INDIRECT_RETURN +#endif From patchwork Tue May 26 06:17:03 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Jesse Huang X-Patchwork-Id: 135666 Return-Path: X-Original-To: patchwork@sourceware.org Delivered-To: patchwork@sourceware.org Received: from vm01.sourceware.org (localhost [IPv6:::1]) by sourceware.org (Postfix) with ESMTP id D9E874BA900A for ; Tue, 26 May 2026 06:26:34 +0000 (GMT) DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org D9E874BA900A Authentication-Results: sourceware.org; dkim=pass (2048-bit key, unprotected) header.d=sifive.com header.i=@sifive.com header.a=rsa-sha256 header.s=google header.b=GddM5Wvs X-Original-To: libc-alpha@sourceware.org Delivered-To: libc-alpha@sourceware.org Received: from mail-dy1-x132a.google.com (mail-dy1-x132a.google.com [IPv6:2607:f8b0:4864:20::132a]) by sourceware.org (Postfix) with ESMTPS id E36B84BA9012 for ; Tue, 26 May 2026 06:18:13 +0000 (GMT) DMARC-Filter: OpenDMARC Filter v1.4.2 sourceware.org E36B84BA9012 Authentication-Results: sourceware.org; dmarc=pass (p=reject dis=none) header.from=sifive.com Authentication-Results: sourceware.org; spf=pass smtp.mailfrom=sifive.com ARC-Filter: OpenARC Filter v1.0.0 sourceware.org E36B84BA9012 Authentication-Results: sourceware.org; arc=none smtp.remote-ip=2607:f8b0:4864:20::132a ARC-Seal: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1779776294; cv=none; b=cV8zZe6AQ5tk33nalJVuMktNNLIYgluGMImjw7kKS6nvjruaPTJqW2cr6qteNbbUijAANSDgsMLRhrs1mRno8jxpiQyIk9hnkEreBR0o/B5SIPdxxMyX0tHoFX61gpkv1GpEM4OJhSXfNjhznMZQue7FFGxAxyktfhOTTWmSGco= ARC-Message-Signature: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1779776294; c=relaxed/simple; bh=qeZCFlHhfHzoAFKNR83ThrGpmLpmvbANFILZ6Yyv8es=; h=DKIM-Signature:From:To:Subject:Date:Message-Id:MIME-Version; b=tpSlpqxywxnASZs5U36ugVys3S10v47GHSD366sHwyHz0AGAyw0qOliA3XL5s5ud8/O8yE8mjmwDedGg2KmYhOfED2I8dxs4RuGLOg8O8MbGITgIJ+J/64KwyUil9TGdxv+8px5FWJDDm0gl5avOUpRA02lZ7o9c1bRES4VxBNY= ARC-Authentication-Results: i=1; sourceware.org; dkim=pass (2048-bit key, unprotected) header.d=sifive.com header.i=@sifive.com header.a=rsa-sha256 header.s=google header.b=GddM5Wvs DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org E36B84BA9012 Received: by mail-dy1-x132a.google.com with SMTP id 5a478bee46e88-30455f77e0eso6908553eec.0 for ; Mon, 25 May 2026 23:18:13 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=sifive.com; s=google; t=1779776293; x=1780381093; darn=sourceware.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to; bh=J8EfFgE/4015CDb18/U/ncOTRHICSDwNOJZpVja6Bgw=; b=GddM5WvsUqZlR1INXQ0BNC14MScZcRFNHMNM/yN/YXy65eVoGRs8i4mgPPuh/AYgjH Xstc3StiW707TejgcUT7RjRe4DZdj92wFaS9IS+t4qx3hNq9gqJx2UqBtIsUGuFuVdOI DnVz8X3TrTVYoNNTAh7qX7jcU+PcyNzwukhl6yH1yxSFagMqAr2M+5Qi+Bo0uOZoRPmI AGzS81VJqfR31lvxIrEInTUt15v8LmCoqTB9PxUfhjLejlKiMG8+LAoWTHpmWCGL4+EF 1qDcAhrJVU7xClLrT8MTdAiSSzL5ECVY4UkjT8lo3HzxTRm6MoBFx6XLI+3uMpHhYjAi Z1zw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1779776293; x=1780381093; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to; bh=J8EfFgE/4015CDb18/U/ncOTRHICSDwNOJZpVja6Bgw=; b=droJ6slc2U+ulxgZKYDLUdwS/yVN8nfNttCtcVn9PzPUq+c8duxKFnFV/XU/Ager5C 9tqcQ01oJW3RY0efFqcEvAOp9srzJj9pZOWN9EDzehtJ+xIgQFBj6Jo9ibf4gCPHU3SA PoiAh8JQN4V7vJW4+kjZZcwH0CyZ+GZLPx0S/ZjYC0MZUf1PtdKAo00rOEiYmHLBVW96 2pKFLA+uZAANJWUEAYiAWYjRQBGsw765kmeUQwfMiVJgDa02YSApDWztTDoWXBhHCwGq pXK8JxhOJQr6sADbRaA54Ms5r8V90IcpTDik7pyeFBc5cGBGtJQyYwgIcz0wihM5ozWU d8kg== X-Gm-Message-State: AOJu0YycD+dBgZjlBCZmck9saF7MW6W5EbNcybKkF1LsHD/UdGLOWQ/R PC8w7LF77jJ5DyBRk2HtzHym/3gZl4aa4rpeKrrFr0M4WiEq3cUyHIROMFD0LKpgkwvJ8elGy6E mWEzAnDW9tlUT+dbUQW6MYuXtVglc0sQYECjH7XPcBoUFpXfJwH0puPYfknZYY7y/xN25kOllRp 1/z9iXnmv+gGJZJTR0ptVssPiH44JTU8ZWXA5PGDJFybvKiMf64ps= X-Gm-Gg: Acq92OHz66sNQfpE7GI00feVnxBkjyvlucZZe2u+fSVsA9mrkFEF57PvbIQ7Xtc8nSo fpy6S0GkY8+e3oPpbltLg7xCcqsiiREtNhEf2I0qw40ZMDQhgC4p3opNGgaWaV25hP+QS/tE3D8 jJoJtzLSSdBIbpE9ColYqStwyBDWCRB/JfWyhpYKtXm5w/Fi/hWLr5VtihPg81iXhzteNLkLZuV sfTgKtUZaHax4VOekSvLGfM9ejHQoeCTDQ90ZsjQ6EjhTaElOwoksWX1bb3rGRmyysz5EyBoXRT Qwo22GfOba9uLhMSKVN+KGTFTMUTFx/b7LuLixdR3Dkuu6qKeoZf7hNdlJTY3jT0aoz4BtT14pm QHgvgstHWMjA/FGyViw8FsvRGtCjp8KQ1CTerbHMJFqsMaUH2/+feLRrBn7Adt5GYhb+1YeD55y IjyzgLqhN9wft+PotM/j6Zro6gCEMWfRo+nB+Oq+5M X-Received: by 2002:a05:7300:818a:b0:2ed:e12:376e with SMTP id 5a478bee46e88-304491f21femr7674335eec.30.1779776292825; Mon, 25 May 2026 23:18:12 -0700 (PDT) Received: from sw08.internal.sifive.com ([4.53.31.132]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-30452461cb5sm14062504eec.31.2026.05.25.23.18.12 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 25 May 2026 23:18:12 -0700 (PDT) From: Jesse Huang To: libc-alpha@sourceware.org Cc: andrew@sifive.com, darius@bluespec.com, debug@rivosinc.com, jeffreyalaw@gmail.com, kito.cheng@sifive.com, palmer@dabbelt.com, Jesse Huang Subject: [PATCH v4 17/17] riscv/cfi: Switch to new prctl interface Date: Mon, 25 May 2026 23:17:03 -0700 Message-Id: <20260526061703.2188042-18-jesse.huang@sifive.com> X-Mailer: git-send-email 2.39.3 In-Reply-To: <20260526061703.2188042-1-jesse.huang@sifive.com> References: <20260526061703.2188042-1-jesse.huang@sifive.com> MIME-Version: 1.0 X-Spam-Status: No, score=-13.2 required=5.0 tests=BAYES_00, DKIM_SIGNED, DKIM_VALID, DKIM_VALID_AU, DKIM_VALID_EF, GIT_PATCH_0, RCVD_IN_DNSWL_BLOCKED, SPF_HELO_NONE, SPF_PASS, TXREP, URIBL_BLOCKED shortcircuit=no autolearn=ham autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on sourceware.org X-BeenThere: libc-alpha@sourceware.org X-Mailman-Version: 2.1.30 Precedence: list List-Id: Libc-alpha mailing list List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: libc-alpha-bounces~patchwork=sourceware.org@sourceware.org --- sysdeps/unix/sysv/linux/riscv/dl-cfi.h | 11 +++--- .../unix/sysv/linux/riscv/include/asm/prctl.h | 35 ++++++++----------- 2 files changed, 21 insertions(+), 25 deletions(-) diff --git a/sysdeps/unix/sysv/linux/riscv/dl-cfi.h b/sysdeps/unix/sysv/linux/riscv/dl-cfi.h index 9758fbf0e3..6a547252fb 100644 --- a/sysdeps/unix/sysv/linux/riscv/dl-cfi.h +++ b/sysdeps/unix/sysv/linux/riscv/dl-cfi.h @@ -55,7 +55,7 @@ dl_cfi_disable_cfi (unsigned int feature) { #ifdef __riscv_landing_pad if (feature & GNU_PROPERTY_RISCV_FEATURE_1_CFI_LP_UNLABELED) { - res = prctl (PR_SET_INDIR_BR_LP_STATUS, 0, 0, 0, 0); + res = prctl (PR_SET_CFI, PR_CFI_BRANCH_LANDING_PADS, PR_CFI_DISABLE, 0, 0); if (res) return res; } @@ -77,7 +77,8 @@ dl_cfi_lock_cfi (unsigned int feature) int res = 0; #ifdef __riscv_landing_pad if (feature & GNU_PROPERTY_RISCV_FEATURE_1_CFI_LP_UNLABELED) - res |= prctl (PR_LOCK_INDIR_BR_LP_STATUS, 0, 0, 0, 0); + res |= prctl (PR_SET_CFI, PR_CFI_BRANCH_LANDING_PADS, + PR_CFI_ENABLE | PR_CFI_LOCK, 0, 0); #endif /* __riscv_landing_pad */ #ifdef __riscv_shadow_stack if (feature & GNU_PROPERTY_RISCV_FEATURE_1_CFI_SS) @@ -92,7 +93,7 @@ dl_cfi_get_cfi_status (void) { unsigned long buf = 0; int ret = 0; #ifdef __riscv_landing_pad - ret = prctl (PR_GET_INDIR_BR_LP_STATUS, &buf, 0, 0, 0); + ret = prctl (PR_GET_CFI, PR_CFI_BRANCH_LANDING_PADS, &buf, 0, 0); if (!ret && buf) status |= GNU_PROPERTY_RISCV_FEATURE_1_CFI_LP_UNLABELED; #endif /* __riscv_landing_pad */ @@ -109,7 +110,7 @@ static __always_inline int dl_cfi_enable_lp (unsigned int feature) { if (!(feature & GNU_PROPERTY_RISCV_FEATURE_1_CFI_LP_UNLABELED)) return -1; - return INTERNAL_SYSCALL_CALL (prctl, PR_SET_INDIR_BR_LP_STATUS, - PR_INDIR_BR_LP_ENABLE, 0, 0, 0); + return INTERNAL_SYSCALL_CALL (prctl, PR_SET_CFI, PR_CFI_BRANCH_LANDING_PADS, + PR_CFI_ENABLE, 0, 0); } #endif /* __riscv_landing_pad */ diff --git a/sysdeps/unix/sysv/linux/riscv/include/asm/prctl.h b/sysdeps/unix/sysv/linux/riscv/include/asm/prctl.h index 091a21b70d..30a37452e1 100644 --- a/sysdeps/unix/sysv/linux/riscv/include/asm/prctl.h +++ b/sysdeps/unix/sysv/linux/riscv/include/asm/prctl.h @@ -21,28 +21,23 @@ #define PR_LOCK_SHADOW_STACK_STATUS 76 /* - * Get the current indirect branch tracking configuration for the current - * thread, this will be the value configured via PR_SET_INDIR_BR_LP_STATUS. + * Get or set the control flow integrity (CFI) configuration for the + * current thread. + * + * Some per-thread control flow integrity settings are not yet + * controlled through this prctl(); see for example + * PR_{GET,SET,LOCK}_SHADOW_STACK_STATUS */ -#define PR_GET_INDIR_BR_LP_STATUS 79 +#define PR_GET_CFI 80 +#define PR_SET_CFI 81 /* - * Set the indirect branch tracking configuration. PR_INDIR_BR_LP_ENABLE will - * enable cpu feature for user thread, to track all indirect branches and ensure - * they land on arch defined landing pad instruction. - * x86 - If enabled, an indirect branch must land on `ENDBRANCH` instruction. - * arch64 - If enabled, an indirect branch must land on `BTI` instruction. - * riscv - If enabled, an indirect branch must land on `lpad` instruction. - * PR_INDIR_BR_LP_DISABLE will disable feature for user thread and indirect - * branches will no more be tracked by cpu to land on arch defined landing pad - * instruction. + * Forward-edge CFI variants (excluding ARM64 BTI, which has its own + * prctl()s). */ -#define PR_SET_INDIR_BR_LP_STATUS 80 -# define PR_INDIR_BR_LP_ENABLE (1UL << 0) +#define PR_CFI_BRANCH_LANDING_PADS 0 -/* - * Prevent further changes to the specified indirect branch tracking - * configuration. All bits may be locked via this call, including - * undefined bits. - */ -#define PR_LOCK_INDIR_BR_LP_STATUS 81 +/* Return and control values for PR_{GET,SET}_CFI */ +# define PR_CFI_ENABLE (1UL << 0) +# define PR_CFI_DISABLE (1UL << 1) +# define PR_CFI_LOCK (1UL << 2)