From patchwork Sun Jun 28 07:02:26 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Jesse Huang X-Patchwork-Id: 137958 Return-Path: X-Original-To: patchwork@sourceware.org Delivered-To: patchwork@sourceware.org Received: from vm01.sourceware.org (localhost [IPv6:::1]) by sourceware.org (Postfix) with ESMTP id 896C34BA23C4 for ; Sun, 28 Jun 2026 07:03:27 +0000 (GMT) DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org 896C34BA23C4 Authentication-Results: sourceware.org; dkim=pass (2048-bit key, unprotected) header.d=sifive.com header.i=@sifive.com header.a=rsa-sha256 header.s=google header.b=FA4NWDWf X-Original-To: libc-alpha@sourceware.org Delivered-To: libc-alpha@sourceware.org Received: from mail-dl1-x1236.google.com (mail-dl1-x1236.google.com [IPv6:2607:f8b0:4864:20::1236]) by sourceware.org (Postfix) with ESMTPS id 7F6484BA2E26 for ; Sun, 28 Jun 2026 07:02:50 +0000 (GMT) DMARC-Filter: OpenDMARC Filter v1.4.2 sourceware.org 7F6484BA2E26 Authentication-Results: sourceware.org; dmarc=pass (p=reject dis=none) header.from=sifive.com Authentication-Results: sourceware.org; spf=pass smtp.mailfrom=sifive.com ARC-Filter: OpenARC Filter v1.0.0 sourceware.org 7F6484BA2E26 Authentication-Results: sourceware.org; arc=none smtp.remote-ip=2607:f8b0:4864:20::1236 ARC-Seal: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1782630170; cv=none; b=sNthirscTQZMmvJahPMXdvR50fVSLnUBzG15P3ceOskXQZY8lnwGhqHPbnWAeL12d4xqjxf9rEzQQpJzvxZmiP3By3Ets6wKnfNHi1S7npvXs4Ifk49TzVgjKpleWuqJlFxscrjYx8WlFqNIycI3RErNEATT6YgoSZU0Sj7mUkg= ARC-Message-Signature: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1782630170; c=relaxed/simple; bh=mQjNISz21ZHU3vo1ZpRIAySIBnrbX7rlFbruqSBOrIc=; h=DKIM-Signature:From:To:Subject:Date:Message-Id:MIME-Version; b=wAM7U43xhG94ORls+zubE+mJtS4PICv/S7c/6YTkQHOByiMcC7OWz6jQkXb4+TU/x1fr7mvrYduX02hQzz3VM+813khakSsaiJtCk2adsTUcbLTSi+6BQNDc3I5/46zCMub3YfSPLkvQ9VHb1gfWTWtLgnj2DmHasqwfZTGMsqo= ARC-Authentication-Results: i=1; sourceware.org; dkim=pass (2048-bit key, unprotected) header.d=sifive.com header.i=@sifive.com header.a=rsa-sha256 header.s=google header.b=FA4NWDWf DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org 7F6484BA2E26 Received: by mail-dl1-x1236.google.com with SMTP id a92af1059eb24-139f1dfc9faso1078073c88.0 for ; Sun, 28 Jun 2026 00:02:50 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=sifive.com; s=google; t=1782630169; x=1783234969; darn=sourceware.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to; bh=OSMQLIZvV36wQLDD4O0Jrz41/CcC2Q52Lcg9WoMbrJA=; b=FA4NWDWfPJ1QKyUAMNtgWciDXwWZbkofAMBcgYQMKJ6U+ygYrkajWojjQH2g7+fjRs RRm5uPxhR3aAK0B/tGe9Tyr7QRydYyK82H53vrx7jVWDa7puu0J/6S/rzYdUpxgre30F Y3pSfeZPPxP/XW67b2qRTCG+q6cPdvbvcuU6w5WwHRYu2JqjRkTrhiePh3GamtE/DvL4 vYlYr2/l1YUQGSbb9IZdVZLzDqxOI2DGeDD3EeZcXP6/ixb5iyeNjgMHMFqFrc789iNH khbL95YjsPLQ4SVh4QINlz00Ncv1lmsZEoRvLGFoqJQEN558U+8VGsVGuUBTuTriJUA/ +ubw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1782630169; x=1783234969; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to; bh=OSMQLIZvV36wQLDD4O0Jrz41/CcC2Q52Lcg9WoMbrJA=; b=iARlP3tbAhDn0ZFc2UFws8tQ3xrLYR7ZQPv5AfqbL9xjM+NeMd8ZBjrP1/MtjrC5P0 dB1a9j5KYWLfs2TF80Gcuo0gcEZWgzd0GhsMKb+8OTI14T4N3cwx4P3P6kZp/hTXQWoM aUeUu7+JvuhWlrRhGP3huJO9TjOezF5EVx9NHqgseYPfR/Xk+A114NQfDga2RjEa2e61 NZVI/cVB+KvmTv34zOS1CyXjPSeEDKpBJui6iF0waN0/+FyxRLoEJsMe0PiBkFWRr2SU 8pjdGisvJzNnCDLONufET1lOL88NHq8O0rk6CMh5Jm4M1+V+oisygwM6a7aL9J/FAipe LwgQ== X-Gm-Message-State: AOJu0YxXH8DPFuEOWCXrL6sa1IXEr7gp4EX7JIYnEybtwEun6m1HP3JO LbOhmDIREOXaqorcHnCsXmMDmZjVpaKSVoMPZoZ5rJ7A2iceNfU1H9e4fIc7CZHpUPlrRvPs5na YGKidu+w2zsC5yQb3ZOim0d1ibxXbPx7ZBgXwv5EiWJBtbMXmgQhpl0VGtM0rTyO6AY9cfNV/r9 OnYueIrE+csl7KFU06P63WEAVQx3rpunGTFEB1AEN5kiUDnHwb X-Gm-Gg: AfdE7ckoUL0Z4PBMtUws+vBabt1v4jVZDkKYlTaJx49a+P5G7iuGEqALCwmDcde0tKw XBn5lqUv/GSRKq8cMraquUd1pzK1uFdCq989l2fHGKaaJ6RW9kVvoZ1Eolq6eWG+Qr/a2kVlFVg xkU4YSb66V9bv4lg/78G8TrQjogZ3iiAEQzSCyvF8hr3/Uy8Mq+42rYQ0Hl9krd5l2R4j0jfknX S/QpuOWJXWs1DnZkiHPZShRXD17NSDgKP4Fd6mk7aTLvbY1+fQXxkGFdPXftaKSt+zalhFgk3WD 7p5BTddC46Qfp3E+oL0GR5q2WdupNC5YyCYpiuKiYi+u7+knpJmQw8ut1Ryd+3aiJAAfo/yiwjv 0B0NdDXk0c6EfvvAmN1OkToM+CryXEHN6DAs4bCJ6kwhrM6rO+rHf1XOoX2qlmkKNnnEA3vb0Bd 9iOrGOUThK5u7vVvgAO8xZJdVxR2ScEg== X-Received: by 2002:a05:7022:322:b0:139:ed5d:5ca4 with SMTP id a92af1059eb24-139ed5d5d69mr5187664c88.45.1782630169141; Sun, 28 Jun 2026 00:02:49 -0700 (PDT) Received: from sw08.internal.sifive.com ([4.53.31.132]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-30c7c8afc91sm35435166eec.14.2026.06.28.00.02.47 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 28 Jun 2026 00:02:48 -0700 (PDT) From: Jesse Huang To: libc-alpha@sourceware.org Cc: andrew@sifive.com, darius@bluespec.com, debug@rivosinc.com, jeffreyalaw@gmail.com, kito.cheng@sifive.com, palmer@dabbelt.com, schwab@suse.de, Jesse Huang Subject: [PATCH v5 01/16] riscv: Add --enable-cfi option for controlling CFI features Date: Sun, 28 Jun 2026 00:02:26 -0700 Message-Id: <20260628070241.88310-2-jesse.huang@sifive.com> X-Mailer: git-send-email 2.39.3 In-Reply-To: <20260628070241.88310-1-jesse.huang@sifive.com> References: <20260628070241.88310-1-jesse.huang@sifive.com> MIME-Version: 1.0 X-Spam-Status: No, score=-13.1 required=5.0 tests=BAYES_00, DKIM_SIGNED, DKIM_VALID, DKIM_VALID_AU, DKIM_VALID_EF, GIT_PATCH_0, RCVD_IN_DNSWL_NONE, SPF_HELO_NONE, SPF_PASS, TXREP shortcircuit=no autolearn=ham autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on sourceware.org X-BeenThere: libc-alpha@sourceware.org X-Mailman-Version: 2.1.30 Precedence: list List-Id: Libc-alpha mailing list List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: libc-alpha-bounces~patchwork=sourceware.org@sourceware.org --- INSTALL | 13 +++++++++++++ NEWS | 3 +++ configure | 12 ++++++++++++ configure.ac | 6 ++++++ manual/install.texi | 12 ++++++++++++ 5 files changed, 46 insertions(+) diff --git a/INSTALL b/INSTALL index cd4b6e5c2f..bb4e37ec6a 100644 --- a/INSTALL +++ b/INSTALL @@ -154,6 +154,19 @@ passed to 'configure'. For example: NOTE: '--enable-cet' is only supported on x86_64 and x32. +'--enable-cfi' + Enable RISC-V Control Flow Integrity Extensions (Zicfilp/Zicfiss) + support. When the GNU C Library is built with '--enable-cfi', the + resulting library is protected with landing pad and shadow stack. + This feature is currently supported on RV64 with GCC 15 and + binutils 2.45 or later. With '--enable-cfi', it is an error to + dlopen a non CFI enabled shared library in CFI enabled application. + The restriction can be loosened by setting to permissive mode with + the use of the glibc tunables, see glibc tunables section for more + information. + + NOTE: '--enable-cfi' is only supported on RV64. + '--disable-profile' Don't build libraries with profiling information. You may want to use this option if you don't plan to do profiling. diff --git a/NEWS b/NEWS index f9d90c5194..1bf3c220c5 100644 --- a/NEWS +++ b/NEWS @@ -9,6 +9,9 @@ Version 2.44 Major new features: +* Added --enable-cfi option to enable the RISC-V CFI extensions + (Zicfilp/Zicfiss) support on RV64 Linux. + * A new tunable, glibc.elf.thp, is added to map read-only segments with Transparent Huge Pages (THP) if THP isn't disable in kernel. When glibc.elf.thp is set to 1, malloc uses the actual kernel THP mode diff --git a/configure b/configure index 604279533a..892c4f066e 100755 --- a/configure +++ b/configure @@ -814,6 +814,7 @@ enable_nscd enable_pt_chown enable_mathvec enable_cet +enable_cfi enable_scv enable_fortify_source enable_sframe @@ -1493,6 +1494,7 @@ Optional Features: depends on architecture] --enable-cet enable Intel Control-flow Enforcement Technology (CET), x86 only + --enable-cfi enable Control Flow Integrity (CFI), RISC-V only --disable-scv syscalls will not use scv instruction, even if the kernel supports it, powerpc only --enable-fortify-source[=1|2|3] @@ -4813,6 +4815,16 @@ esac fi +# Check whether --enable-cfi was given. +if test ${enable_cfi+y} +then : + enableval=$enable_cfi; enable_cfi=$enableval +else case e in #( + e) enable_cfi=no ;; +esac +fi + + # Check whether --enable-scv was given. if test ${enable_scv+y} then : diff --git a/configure.ac b/configure.ac index 2fe7980fc9..bc57ce938b 100644 --- a/configure.ac +++ b/configure.ac @@ -393,6 +393,12 @@ AC_ARG_ENABLE([cet], [enable_cet=$enableval], [enable_cet=$libc_cv_compiler_default_cet]) +AC_ARG_ENABLE([cfi], + AS_HELP_STRING([--enable-cfi], + [enable Control Flow Integrity (CFI), RISC-V only]), + [enable_cfi=$enableval], + [enable_cfi=no]) + AC_ARG_ENABLE([scv], AS_HELP_STRING([--disable-scv], [syscalls will not use scv instruction, even if the kernel supports it, powerpc only]), diff --git a/manual/install.texi b/manual/install.texi index 48604a31df..daab54a3b7 100644 --- a/manual/install.texi +++ b/manual/install.texi @@ -185,6 +185,18 @@ non CET enabled shared library in CET enabled application. NOTE: @option{--enable-cet} is only supported on x86_64 and x32. +@item --enable-cfi +Enable RISC-V Control Flow Integrity Extensions (Zicfilp/Zicfiss) support. +When @theglibc{} is built with @option{--enable-cfi}, the resulting +library is protected with landing pad and shadow stack@. +This feature is currently supported on RV64 with GCC 15 and binutils 2.45 +or later. With @option{--enable-cfi}, it is an error to dlopen a non CFI +enabled shared library in CFI enabled application. The restriction can be +loosened by setting to permissive mode with the use of the glibc tunables, +see glibc tunables section for more information. + +NOTE: @option{--enable-cfi} is only supported on RV64. + @item --disable-profile Don't build libraries with profiling information. You may want to use this option if you don't plan to do profiling. From patchwork Sun Jun 28 07:02:27 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Jesse Huang X-Patchwork-Id: 137962 Return-Path: X-Original-To: patchwork@sourceware.org Delivered-To: patchwork@sourceware.org Received: from vm01.sourceware.org (localhost [IPv6:::1]) by sourceware.org (Postfix) with ESMTP id 6B5294BA2E2F for ; Sun, 28 Jun 2026 07:05:09 +0000 (GMT) DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org 6B5294BA2E2F Authentication-Results: sourceware.org; dkim=pass (2048-bit key, unprotected) header.d=sifive.com header.i=@sifive.com header.a=rsa-sha256 header.s=google header.b=f0aMz6w5 X-Original-To: libc-alpha@sourceware.org Delivered-To: libc-alpha@sourceware.org Received: from mail-dy1-x132d.google.com (mail-dy1-x132d.google.com [IPv6:2607:f8b0:4864:20::132d]) by sourceware.org (Postfix) with ESMTPS id 00F364BA2E27 for ; Sun, 28 Jun 2026 07:02:51 +0000 (GMT) DMARC-Filter: OpenDMARC Filter v1.4.2 sourceware.org 00F364BA2E27 Authentication-Results: sourceware.org; dmarc=pass (p=reject dis=none) header.from=sifive.com Authentication-Results: sourceware.org; spf=pass smtp.mailfrom=sifive.com ARC-Filter: OpenARC Filter v1.0.0 sourceware.org 00F364BA2E27 Authentication-Results: sourceware.org; arc=none smtp.remote-ip=2607:f8b0:4864:20::132d ARC-Seal: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1782630172; cv=none; b=GYrSfbmoUjiDesUsSWsCDfLMVm2STwhjLI39Tv1Yeg+gdZlTqd0bE/LN5C5obcuAXN06YZT1i7+vBwUavQFzeXLquF76CPzcm3nj4F2Us3sJ8+GiToVrhLaJ95h9OUX5tjlzkh4rQta05AoqWqs1zgHndKRsnjsoMTVNGZ/cd08= ARC-Message-Signature: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1782630172; c=relaxed/simple; bh=B8bLWSo7Sbn9MuGKqFzIimB4PcbmO7NlxXesHV/qNRc=; h=DKIM-Signature:From:To:Subject:Date:Message-Id:MIME-Version; b=j8ePv7jwl+ww7/LL4t9YdmqCzPGfy1m/EGBYdPt12akSEDFFCATn6izGd/qc1GSWNmbTtYosJFAzh+hGK9kXg3EWjAjRorTRyDHBs5EXV6+28c7bYF5ntqAjGgOiFwBEOJXQ2Q7Jl/q8jF9m9RAI+V5jQilFDzG33QQIeJ8o6S0= ARC-Authentication-Results: i=1; sourceware.org; dkim=pass (2048-bit key, unprotected) header.d=sifive.com header.i=@sifive.com header.a=rsa-sha256 header.s=google header.b=f0aMz6w5 DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org 00F364BA2E27 Received: by mail-dy1-x132d.google.com with SMTP id 5a478bee46e88-30c965eab27so3617686eec.0 for ; Sun, 28 Jun 2026 00:02:51 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=sifive.com; s=google; t=1782630171; x=1783234971; darn=sourceware.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to; bh=WxqN7Cre2Jy1QdVMykdHC8Gk2itD80yth9BkgzqfFFY=; b=f0aMz6w5Irj69lPBjBKPLO1QhxgYzVL6YH/p2dYAwnXzcVEiwgG/2EHaJf/K5K4pyx CgjqksPkPGZlj98pFSF5lPgyZO2TBkK7NdCz0IzIesrNec8wOsj9H7oql/3Pu/P6CP6U oYhfpKKIaNiyel/o7lzbDIXNgrTQnCxciPE2vTZcvfFkOKSRrC1r29htbfQHVnFCa9Q0 LyqPX4oGyCEqHUtyge7c5xSl/60L+FctqfhNZ0oXbo3KtWXM15/BEtYXJ/MIHMkVvZ1K GhE3ijayjPapbqH482vA6I5kV9wBFwnDDV3wN4NM6Tyi+d+43I+qqGUlj43l4l3vu1mo ddFg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1782630171; x=1783234971; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to; bh=WxqN7Cre2Jy1QdVMykdHC8Gk2itD80yth9BkgzqfFFY=; b=D8uQnrtCY42Alp5sOQD2d8/lTpCoPhiPPYEmmYlNvbBlIrP6kdYrP+ZMu9/Gwyji12 nEuHu9g8DfphjgygVYGAGIj/5yJ6JAneuZnDogOTS/KNF/UJwBg1pngyc2bM2gghVYQ4 qUS0nI1CWmOFFPbBcxnnVWfCofmim+rk473LXBADq8Pv56r1N+kQC6PM1oiSTUZUm5qp epTEMV1RKt3Y/irMHyPRxFfp5IsTMseFFYuAwIvUDd/6sHu9PjRPTLKSywgcztcb2NzH N3eloDGg7LBFUfbBOPPp2plSIjQua9gusAM0n2Kq5M7rdmHE8QRI3ROgVsZ7a4/C7O6v 09Ng== X-Gm-Message-State: AOJu0Yyks33UuoFD41NcpFUpKknuBTqzc0eIH6AwN6sMgZ4Oxeb9q8kZ N3zAMFgimcBom6H7rDN9OKuGHqRfwP6/nGe6s/MEoBJqPFiU5JStyPGo5qChFvxR73a1fzAwmEk ucDHw8kV5YY2utYyxls+YLwWuL2i7K46VmJHo3CfxOgUOlbBONNIQLFo672dzaRNZQRSlzh2XR1 7NGFtPM1K7CtNy+yrjN7fjU7cFevcqgX5zEhA86EeNK46mFCkzou8= X-Gm-Gg: AfdE7cl2zUkpdSnhSruSbLid51YDhM2Us5nb2Q8rIutF2yZcT950kpZaISGFHAgPj6l wxlHNIMnQZ/naC1mRi5jYg4ElP6gJKPGV+yKnZgVwgOW6uJcVSw29uv92zWa4ITnHdWQcV2NUbF HprrQmu4bVZGAOmAFipwkxJOKckV0Ihq7AiaSn6TdWBnRrYHekz+paihnEV3IExvkJU8T+NSwLn SHGehzHej/GYqh5lWV4lp8WAyN6i6cRor417s8wbSmCKW12PY4fq+bGXA2VquEvttjyN0FkEyRZ Id9K8E32pKV+Mj9pcrNUmsgYykhLkYN4cbDOJvc5w+aKXEPnCBGhPNS/Q94vSlEZ3qifqbyDXzA 0IPVR0jOVBQSiARD84P3AtInwbcy2pgfshUEpbP/3XhbEqRSfC1brs30/Huqh9itOdTb8ySs4Jq MZhQXnZggODjaqCPyqI/2n86q+ZtYcXA== X-Received: by 2002:a05:693c:8816:20b0:30c:8656:6db0 with SMTP id 5a478bee46e88-30c865672dcmr8121908eec.27.1782630170697; Sun, 28 Jun 2026 00:02:50 -0700 (PDT) Received: from sw08.internal.sifive.com ([4.53.31.132]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-30c7c8afc91sm35435166eec.14.2026.06.28.00.02.49 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 28 Jun 2026 00:02:49 -0700 (PDT) From: Jesse Huang To: libc-alpha@sourceware.org Cc: andrew@sifive.com, darius@bluespec.com, debug@rivosinc.com, jeffreyalaw@gmail.com, kito.cheng@sifive.com, palmer@dabbelt.com, schwab@suse.de, Jesse Huang , Hau Hsu Subject: [PATCH v5 02/16] riscv/cfi: Set up necessary options for --enable-cfi Date: Sun, 28 Jun 2026 00:02:27 -0700 Message-Id: <20260628070241.88310-3-jesse.huang@sifive.com> X-Mailer: git-send-email 2.39.3 In-Reply-To: <20260628070241.88310-1-jesse.huang@sifive.com> References: <20260628070241.88310-1-jesse.huang@sifive.com> MIME-Version: 1.0 X-Spam-Status: No, score=-13.1 required=5.0 tests=BAYES_00, DKIM_SIGNED, DKIM_VALID, DKIM_VALID_AU, DKIM_VALID_EF, GIT_PATCH_0, RCVD_IN_DNSWL_NONE, SPF_HELO_NONE, SPF_PASS, TXREP shortcircuit=no autolearn=ham autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on sourceware.org X-BeenThere: libc-alpha@sourceware.org X-Mailman-Version: 2.1.30 Precedence: list List-Id: Libc-alpha mailing list List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: libc-alpha-bounces~patchwork=sourceware.org@sourceware.org Co-authored-by: Hau Hsu Reviewed-by: Deepak Gupta --- sysdeps/riscv/Makefile | 9 +++++++++ sysdeps/riscv/preconfigure | 2 ++ sysdeps/riscv/preconfigure.ac | 1 + 3 files changed, 12 insertions(+) diff --git a/sysdeps/riscv/Makefile b/sysdeps/riscv/Makefile index c08753ae8a..99976fddad 100644 --- a/sysdeps/riscv/Makefile +++ b/sysdeps/riscv/Makefile @@ -15,3 +15,12 @@ ASFLAGS-.os += -Wa,-mno-relax ASFLAGS-.o += -Wa,-mno-relax sysdep-CFLAGS += -mno-relax endif + +# Enable RISC-V CFI +ifeq (yes,$(riscv-enable-cfi)) +CFLAGS-.o += -fcf-protection=full +CFLAGS-.os += -fcf-protection=full +CFLAGS-.op += -fcf-protection=full +CFLAGS-.oS += -fcf-protection=full +asm-CPPFLAGS += -fcf-protection=full -include sysdep.h +endif diff --git a/sysdeps/riscv/preconfigure b/sysdeps/riscv/preconfigure index 57fe6822cf..b480c53d5f 100755 --- a/sysdeps/riscv/preconfigure +++ b/sysdeps/riscv/preconfigure @@ -79,6 +79,8 @@ riscv*) printf "%s\n" "#define RISCV_ABI_FLEN $abi_flen" >>confdefs.h + config_vars="$config_vars +riscv-enable-cfi = $enable_cfi" ;; esac diff --git a/sysdeps/riscv/preconfigure.ac b/sysdeps/riscv/preconfigure.ac index 52414919ae..15c61e9305 100644 --- a/sysdeps/riscv/preconfigure.ac +++ b/sysdeps/riscv/preconfigure.ac @@ -77,5 +77,6 @@ riscv*) AC_DEFINE_UNQUOTED([RISCV_ABI_XLEN], [$xlen]) AC_DEFINE_UNQUOTED([RISCV_ABI_FLEN], [$abi_flen]) + LIBC_CONFIG_VAR([riscv-enable-cfi], [$enable_cfi]) ;; esac From patchwork Sun Jun 28 07:02:28 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Jesse Huang X-Patchwork-Id: 137967 Return-Path: X-Original-To: patchwork@sourceware.org Delivered-To: patchwork@sourceware.org Received: from vm01.sourceware.org (localhost [IPv6:::1]) by sourceware.org (Postfix) with ESMTP id 5E86D4BA23C6 for ; Sun, 28 Jun 2026 07:06:29 +0000 (GMT) DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org 5E86D4BA23C6 Authentication-Results: sourceware.org; dkim=pass (2048-bit key, unprotected) header.d=sifive.com header.i=@sifive.com header.a=rsa-sha256 header.s=google header.b=kKm227Hb X-Original-To: libc-alpha@sourceware.org Delivered-To: libc-alpha@sourceware.org Received: from mail-dl1-x122c.google.com (mail-dl1-x122c.google.com [IPv6:2607:f8b0:4864:20::122c]) by sourceware.org (Postfix) with ESMTPS id DE4F94BA2E24 for ; Sun, 28 Jun 2026 07:02:52 +0000 (GMT) DMARC-Filter: OpenDMARC Filter v1.4.2 sourceware.org DE4F94BA2E24 Authentication-Results: sourceware.org; dmarc=pass (p=reject dis=none) header.from=sifive.com Authentication-Results: sourceware.org; spf=pass smtp.mailfrom=sifive.com ARC-Filter: OpenARC Filter v1.0.0 sourceware.org DE4F94BA2E24 Authentication-Results: sourceware.org; arc=none smtp.remote-ip=2607:f8b0:4864:20::122c ARC-Seal: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1782630173; cv=none; b=S67JNQgXh/TksuSrBLXPp8X207dk3Yf9JEIB7TxWmfLEfDof2XV4xEDimIVRUf6v1ulFnNpvh000xuFpFAluWMUPn9Gun0uYcrPki8LbVyl3vFpG2SbD5EjzACAlF/tryJVixH3nFfrWxRFCrw1Uc92m+DRwgT6t6SFCbd4CsRE= ARC-Message-Signature: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1782630173; c=relaxed/simple; bh=MO0d548Fjbhw/PE6MAFrrTuX4+QlFAnvYeWDlVu0zMQ=; h=DKIM-Signature:From:To:Subject:Date:Message-Id:MIME-Version; b=S4QjDyqvihq7RmJBJ1Ho4sjwGcBUqZOBPdW+BfsnqP3OdLxfYX0v2lQ6TOPDTY0LS+hTfogVvEIrE8CBtfkO2d816IcBLIM6ivqWhsOwGZU7LmxzfWWqbg0tmYP0151vg1P84qmKhnk+dqa4X3aq1F7Ru6wP1ZzCvkdm3eqIRKw= ARC-Authentication-Results: i=1; sourceware.org; dkim=pass (2048-bit key, unprotected) header.d=sifive.com header.i=@sifive.com header.a=rsa-sha256 header.s=google header.b=kKm227Hb DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org DE4F94BA2E24 Received: by mail-dl1-x122c.google.com with SMTP id a92af1059eb24-137335bc3caso4574418c88.0 for ; Sun, 28 Jun 2026 00:02:52 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=sifive.com; s=google; t=1782630172; x=1783234972; darn=sourceware.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to; bh=q9tcC2Xg1JbUa3UZ9QeaZDX/Cn06++DNcj9psri1HTs=; b=kKm227HbAomkr9wZGzl/FLDKI+VMCjr9qVDBkLXbVOcpECGMumkI1xrA/e9yWO5LbO WMNe17jiTngQcGw+sZuN+iMyYUhwW6jIay+CM+aUl0DNTndnecfvp9KeEeVeB6wb69o/ ls/vt6O7liqsxipTixqWSdSDo4N9EAqRTji/SbkfUdvG7uSlJeZtOUtqswBxGl4T93Rn OVuBGC0UQOTeq2ZXIdSFXkrCnLTvFRoqoqNWiSTFDflZPLY3uJ3YVtXCBegZ/K81F9jj w/8nrgfVstAvCM1MEf3VFLs5FEhG0f4l9njupowYEsC70Gi8BkHZrsrgVF90WwdkABPb LzFA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1782630172; x=1783234972; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to; bh=q9tcC2Xg1JbUa3UZ9QeaZDX/Cn06++DNcj9psri1HTs=; b=KLBDGbiPj9pSYslVjKPhEnr7ewpRIbrj+gi+Xxw4fAD2h10T09nKmF/HOdhDznN7Ax WR79Rkb52S6zlcxXyMRUYgZ+5UtDjv87LiFRkoyzO0Ifb5K2L24Al9P2h6FJyqntdQ9n Jabq1RpHHplFPBew7nkbc2jwaBp8ykySmMlUaTw1D5a8YZx+cb1+hEJvjAotYiRptXkB MyLZzqaWP2CQcVWE4arsvYKMzhC3IdIUcAbQ7wpnovetYcV6qiZat0lL8MNyqyHnHU5N 0/EZhxSsnavHoXeT1oY3SLYyHl1W7ODyDkv7j+oilN08zlT487mRLJdy0w3yEtZWxP8w ggRQ== X-Gm-Message-State: AOJu0YxDeC9i3Nx4XbPzGqzTrtO9xSIsxzdMksHJ39WYznsLdHGZQO2V rgTftInlGyoGsYhh9qzSVMG4L4arOe924mN7MN/MnfvP46zjG5QNHKpE4sOsiaF8Ra3Tmg9aYoZ WkF2CZO/MYsTjBot5q42dCZ0SmAWu+IEHgL7hjLQJshAARmc83ITMyDBB4oypyOIyxegUDQpGo3 6Y15v2uP3Ekr0L4j8t/ZZEmPGFpN/8DrthjeMYgkebEyO2wE8+7Zk= X-Gm-Gg: AfdE7ckXM8m9owDppal9SEMNbKr/B92uC0hQp5KimmNM55DpA6MT40cV4oIlsK0R9Gy 2HlJLbgdk4v9jLi52Qu3baV00e5r75QNliFwg3TK+D2a5Vt9JVqF/XL+uxK0Fhv7wpTrj5ec+sB bEoOa+DxC9w4lw80JKPbdSLSB6nrhC27Z+TP2bCElHqNldL+35kEJs/wge4FEN/6+fyInFDsOJ4 unahqVceFKodAgWEPgTJoBOOEYZ+FoGt8UamEQoMymJGe7jSK3px5BMmYzwKRDVYo2de8Jtzvg8 KiyMFcvz5S9MXeC4zeYOqh7VFNNfXlK0GNlvQy9Nl0uRE88XLBIsR3zD+yphgGzRdJOjkhScMAv hxhl8bWfCyTAEK07XwYWXz135WmAr9dxzExW73OSkU5z0j6RBWdNJOFl5w4jBAFQrJl8zB38YHv OXrriIwchAVc7v6gCbY/A7uVFEaRAvtg== X-Received: by 2002:a05:7300:80d0:b0:304:b93a:5107 with SMTP id 5a478bee46e88-30c84f41ad0mr15916315eec.21.1782630171713; Sun, 28 Jun 2026 00:02:51 -0700 (PDT) Received: from sw08.internal.sifive.com ([4.53.31.132]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-30c7c8afc91sm35435166eec.14.2026.06.28.00.02.50 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 28 Jun 2026 00:02:51 -0700 (PDT) From: Jesse Huang To: libc-alpha@sourceware.org Cc: andrew@sifive.com, darius@bluespec.com, debug@rivosinc.com, jeffreyalaw@gmail.com, kito.cheng@sifive.com, palmer@dabbelt.com, schwab@suse.de, Jesse Huang Subject: [PATCH v5 03/16] riscv: Add GNU property definitions for RISC-V CFI Date: Sun, 28 Jun 2026 00:02:28 -0700 Message-Id: <20260628070241.88310-4-jesse.huang@sifive.com> X-Mailer: git-send-email 2.39.3 In-Reply-To: <20260628070241.88310-1-jesse.huang@sifive.com> References: <20260628070241.88310-1-jesse.huang@sifive.com> MIME-Version: 1.0 X-Spam-Status: No, score=-13.2 required=5.0 tests=BAYES_00, DKIM_SIGNED, DKIM_VALID, DKIM_VALID_AU, DKIM_VALID_EF, GIT_PATCH_0, RCVD_IN_DNSWL_NONE, SPF_HELO_NONE, SPF_PASS, TXREP shortcircuit=no autolearn=ham autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on sourceware.org X-BeenThere: libc-alpha@sourceware.org X-Mailman-Version: 2.1.30 Precedence: list List-Id: Libc-alpha mailing list List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: libc-alpha-bounces~patchwork=sourceware.org@sourceware.org Add GNU properties used by RISC-V CFI extensions (Zicfilp/Zicfiss). Reviewed-by: Deepak Gupta --- elf/elf.h | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/elf/elf.h b/elf/elf.h index 3a60ef36b5..3e8c4fb92d 100644 --- a/elf/elf.h +++ b/elf/elf.h @@ -1427,6 +1427,11 @@ typedef struct SHSTK. */ #define GNU_PROPERTY_X86_FEATURE_1_SHSTK (1U << 1) +/* RISC-V specific GNU PROPERTY. */ +#define GNU_PROPERTY_RISCV_FEATURE_1_AND 0xc0000000 +#define GNU_PROPERTY_RISCV_FEATURE_1_CFI_LP_UNLABELED (1u << 0) +#define GNU_PROPERTY_RISCV_FEATURE_1_CFI_SS (1u << 1) + /* Move records. */ typedef struct { From patchwork Sun Jun 28 07:02:29 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Jesse Huang X-Patchwork-Id: 137959 Return-Path: X-Original-To: patchwork@sourceware.org Delivered-To: patchwork@sourceware.org Received: from vm01.sourceware.org (localhost [IPv6:::1]) by sourceware.org (Postfix) with ESMTP id 653884BA23CD for ; Sun, 28 Jun 2026 07:03:33 +0000 (GMT) DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org 653884BA23CD Authentication-Results: sourceware.org; dkim=pass (2048-bit key, unprotected) header.d=sifive.com header.i=@sifive.com header.a=rsa-sha256 header.s=google header.b=SvJ/TG+6 X-Original-To: libc-alpha@sourceware.org Delivered-To: libc-alpha@sourceware.org Received: from mail-dy1-x1330.google.com (mail-dy1-x1330.google.com [IPv6:2607:f8b0:4864:20::1330]) by sourceware.org (Postfix) with ESMTPS id DC2A34BA2E27 for ; Sun, 28 Jun 2026 07:02:54 +0000 (GMT) DMARC-Filter: OpenDMARC Filter v1.4.2 sourceware.org DC2A34BA2E27 Authentication-Results: sourceware.org; dmarc=pass (p=reject dis=none) header.from=sifive.com Authentication-Results: sourceware.org; spf=pass smtp.mailfrom=sifive.com ARC-Filter: OpenARC Filter v1.0.0 sourceware.org DC2A34BA2E27 Authentication-Results: sourceware.org; arc=none smtp.remote-ip=2607:f8b0:4864:20::1330 ARC-Seal: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1782630175; cv=none; b=hxzw1DUbkGQckUvnQl/2fCuT3csKQoTACc8XKO22RkaiFk+jk6mZaPsMbMlZK98s4IEtljgruQjprTE5TNf3HSK8EiHlBguXiNTwhfuWRNxocaP1Irre9YjAzpFDTMpcoISy9qBFrexGteRf4HJM+foKaiONH8Nyc/BoKjz/zy0= ARC-Message-Signature: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1782630175; c=relaxed/simple; bh=mlS2PZAAFP/lRb+2BAAYh0c24Gm0xyLbuM3L91Km8MA=; h=DKIM-Signature:From:To:Subject:Date:Message-Id:MIME-Version; b=onie1/6tg2cTFZNcb8dZszqO5LaoMGrrpcz4TxqmsKWFXyjrQhIO+BjjM5kVteWfnycsTFXSs9M3dyf+h5Kz+uskqRQ0ADcnfJ6wCP9tau/H9Flf9cOFlWtf1qZqYAOIAB0BYI9pInudivU/NIzhRb3JziK8LMlPbjNupzj0p7A= ARC-Authentication-Results: i=1; sourceware.org; dkim=pass (2048-bit key, unprotected) header.d=sifive.com header.i=@sifive.com header.a=rsa-sha256 header.s=google header.b=SvJ/TG+6 DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org DC2A34BA2E27 Received: by mail-dy1-x1330.google.com with SMTP id 5a478bee46e88-30eac9abd79so776913eec.1 for ; Sun, 28 Jun 2026 00:02:54 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=sifive.com; s=google; t=1782630174; x=1783234974; darn=sourceware.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to; bh=ieAVYXk0qAnuZ6Q0RdIA+DeV7oaQLxCeRzLJmw9/5Yw=; b=SvJ/TG+68kUvgNbDD1CjlqG8CYaLS0gPD80fgnHDyOzPBz/UNH59NQKWQgfVwmggoU j/PWcSpjY3FBg+ikuQSQuto+UmkzlNpygG7yWrJGY9mmoO4jiKm3cgekz6/yB8ctQs8v JF8bePWCPOjRJVKY+bumvvn58WdUFIPTxaqj2Nl2vNLxSRwMH2jgqkUpIRubQ9Jo8Wt6 6t+By0AkKWgj6g16kZy2IlNnKTJ989cfyymk7QGI9mNUTF75EHGJniCqX6pptKivwJV3 sFataKS23mtPbMQEV2g6uzJJjODTTxAh2FLIj8uhV9P406vRB++ioWwzfIE0JdCIkqDh DHSA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1782630174; x=1783234974; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to; bh=ieAVYXk0qAnuZ6Q0RdIA+DeV7oaQLxCeRzLJmw9/5Yw=; b=B/nYPsaruKPFy06i9ooO/mMtHdLJuwzHF2fdPFl2fHkAo0UVXwcMMck+QoXD/1y5L7 CQWGErqaiX/ZdXxsLDOGB3drb8wQ/XbInwyZJdLcXwWP3DglP4piKPgfWkT3wFCK7eB8 71n5IYtpF3ha1ZYRKL15whtiUkEWf4dkMuOJiV7A4wT2Zy2BAD8wja6xTGctN0uY+6I4 0IqCG8uUJ+TOfrQZCPSCjBf314N60zOHPD79mx89QhiS5PHRQFap+Yu+ONjnc8fEZtOF 4E50sIy8pocPtlaFlv6k3R+PQ4SkbF/36tWbNZZriCgOuVexqflbepG/sfQWH0OHHYYu cb+w== X-Gm-Message-State: AOJu0YynbaE9bO4JW/s5BPb2LFhSqqJ8Kx1DHqianFtf6xUzEkX1AOH1 yaiqY3I4Zv5fwJkeHCe3nKx3wIcw4geVoWbxnUiKu1KQrUhN+8GU7n78XxuJl6KtDEkIhCJKmrd 9nCx3SnGxDIFndKQmAQ2ryiLu4rlCpRzIc7+N3UhsICbe1/+595zwDAnT1m3yQZwF9B+IVdbwXw rznNXwofrGBtsBpFON4+D+7nqDPD/BVtrLCFvDmmjgRoHM0eKADWk= X-Gm-Gg: AfdE7cnboX1B8f//Cc+RSjSthdER60jTxc/tsXfnEFQUdBUDh3OloZpAGXIoSa3JTgQ iXq8FUIc3mq3oZ0i4x9HxsUNzVxPQx6dhZBfo0OP8rpzQCCldAWUeMQSA2eUTAGNwYwbPzqN+RD U9SUS4GNrNTgS5FptfNpM7oMdP54jrWnvvcKr/8DJ6E+eEwIFkCECffKCUQ5Jsp+39Qwy7pHfkX PrXdu6pF1eaJKvxHKBg+o9np19mKlwJbCN195sEIE3nPQFopzKOF1U3MnADrWY1bVrnv/3eJKfN 2Ln5afVBtPCtiFhIxE+OYAj6YtW6FJGoERhNLbYdz6z5WhlJHwi/K8W2b8gyN38vveSZg3F1PfJ dZRsMIWmAKT21ot7UfXTBkOhkL9KkfTSWj9pylQVIRe/4MY0UezL7EL9v/xkhpSHKfyiZFJclFJ MH8TKB+wRiCmrlSWCihREzDlA6IS/4g0M0yiq04W3G X-Received: by 2002:a05:7300:7fa6:b0:2db:2089:460f with SMTP id 5a478bee46e88-30cab22a412mr6252065eec.19.1782630173617; Sun, 28 Jun 2026 00:02:53 -0700 (PDT) Received: from sw08.internal.sifive.com ([4.53.31.132]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-30c7c8afc91sm35435166eec.14.2026.06.28.00.02.51 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 28 Jun 2026 00:02:52 -0700 (PDT) From: Jesse Huang To: libc-alpha@sourceware.org Cc: andrew@sifive.com, darius@bluespec.com, debug@rivosinc.com, jeffreyalaw@gmail.com, kito.cheng@sifive.com, palmer@dabbelt.com, schwab@suse.de, Jesse Huang , Hau Hsu , Jerry Zhang Jian Subject: [PATCH v5 04/16] riscv: Adjust assembly routines to support landing pad Date: Sun, 28 Jun 2026 00:02:29 -0700 Message-Id: <20260628070241.88310-5-jesse.huang@sifive.com> X-Mailer: git-send-email 2.39.3 In-Reply-To: <20260628070241.88310-1-jesse.huang@sifive.com> References: <20260628070241.88310-1-jesse.huang@sifive.com> MIME-Version: 1.0 X-Spam-Status: No, score=-13.1 required=5.0 tests=BAYES_00, DKIM_SIGNED, DKIM_VALID, DKIM_VALID_AU, DKIM_VALID_EF, GIT_PATCH_0, PROLO_LEO3, RCVD_IN_DNSWL_NONE, SPF_HELO_NONE, SPF_PASS, TXREP shortcircuit=no autolearn=ham autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on sourceware.org X-BeenThere: libc-alpha@sourceware.org X-Mailman-Version: 2.1.30 Precedence: list List-Id: Libc-alpha mailing list List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: libc-alpha-bounces~patchwork=sourceware.org@sourceware.org Landing pads, instructions for setting the label value, and alignment directives are inserted where they are needed. Changed to use software-guarded call in dl_runtime_resolve. Co-authored-by: Hau Hsu Co-authored-by: Kito Cheng Co-authored-by: Jerry Zhang Jian --- sysdeps/riscv/crti.S | 4 ++ sysdeps/riscv/crtn.S | 4 ++ sysdeps/riscv/dl-machine.h | 8 +++ sysdeps/riscv/dl-trampoline.S | 41 +++++++-------- sysdeps/riscv/start.S | 9 ++++ sysdeps/riscv/sys/asm.h | 12 ++++- sysdeps/unix/sysv/linux/riscv/clone.S | 1 + sysdeps/unix/sysv/linux/riscv/sysdep.h | 69 ++++++++++++++++++++++++++ 8 files changed, 127 insertions(+), 21 deletions(-) create mode 100644 sysdeps/riscv/crti.S create mode 100644 sysdeps/riscv/crtn.S diff --git a/sysdeps/riscv/crti.S b/sysdeps/riscv/crti.S new file mode 100644 index 0000000000..fb1097c5ca --- /dev/null +++ b/sysdeps/riscv/crti.S @@ -0,0 +1,4 @@ +/* crti.S is empty because .init_array/.fini_array are used exclusively. + Include sysdep.h to define gnu property if necessary. */ + +#include diff --git a/sysdeps/riscv/crtn.S b/sysdeps/riscv/crtn.S new file mode 100644 index 0000000000..b2e7cb692e --- /dev/null +++ b/sysdeps/riscv/crtn.S @@ -0,0 +1,4 @@ +/* crtn.S is empty because .init_array/.fini_array are used exclusively. + Include sysdep.h to define gnu property if necessary. */ + +#include diff --git a/sysdeps/riscv/dl-machine.h b/sysdeps/riscv/dl-machine.h index babb52af20..05992c8705 100644 --- a/sysdeps/riscv/dl-machine.h +++ b/sysdeps/riscv/dl-machine.h @@ -28,6 +28,13 @@ #include #include #include +/* This is a marker to remind us to add real expansion to setup the label + for the function signature label scheme in the future */ +#ifdef __riscv_landing_pad_unlabeled +# define SET_LPAD +#else +# define SET_LPAD +#endif #ifndef _RTLD_PROLOGUE # define _RTLD_PROLOGUE(entry) \ @@ -127,6 +134,7 @@ elf_machine_dynamic (void) # Pass our finalizer function to _start.\n\ lla a0, _dl_fini\n\ # Jump to the user entry point.\n\ + " STRINGXV (SET_LPAD) "\n\ jr s0\n\ " _RTLD_EPILOGUE (ENTRY_POINT) \ _RTLD_EPILOGUE (_dl_start_user) "\ diff --git a/sysdeps/riscv/dl-trampoline.S b/sysdeps/riscv/dl-trampoline.S index 6c731fcfd4..f37ed60343 100644 --- a/sysdeps/riscv/dl-trampoline.S +++ b/sysdeps/riscv/dl-trampoline.S @@ -29,6 +29,7 @@ # define FRAME_SIZE (-((-10 * SZREG) & ALMASK)) #else # define FRAME_SIZE (-((-10 * SZREG - 8 * SZFREG) & ALMASK)) +# define FREG_BASE_OFFSET (10*SZREG) #endif ENTRY (_dl_runtime_resolve) @@ -45,23 +46,23 @@ ENTRY (_dl_runtime_resolve) REG_S a7, 8*SZREG(sp) #ifndef __riscv_float_abi_soft - FREG_S fa0, (10*SZREG + 0*SZFREG)(sp) - FREG_S fa1, (10*SZREG + 1*SZFREG)(sp) - FREG_S fa2, (10*SZREG + 2*SZFREG)(sp) - FREG_S fa3, (10*SZREG + 3*SZFREG)(sp) - FREG_S fa4, (10*SZREG + 4*SZFREG)(sp) - FREG_S fa5, (10*SZREG + 5*SZFREG)(sp) - FREG_S fa6, (10*SZREG + 6*SZFREG)(sp) - FREG_S fa7, (10*SZREG + 7*SZFREG)(sp) + FREG_S fa0, (FREG_BASE_OFFSET + 0*SZFREG)(sp) + FREG_S fa1, (FREG_BASE_OFFSET + 1*SZFREG)(sp) + FREG_S fa2, (FREG_BASE_OFFSET + 2*SZFREG)(sp) + FREG_S fa3, (FREG_BASE_OFFSET + 3*SZFREG)(sp) + FREG_S fa4, (FREG_BASE_OFFSET + 4*SZFREG)(sp) + FREG_S fa5, (FREG_BASE_OFFSET + 5*SZFREG)(sp) + FREG_S fa6, (FREG_BASE_OFFSET + 6*SZFREG)(sp) + FREG_S fa7, (FREG_BASE_OFFSET + 7*SZFREG)(sp) #endif # Update .got.plt and obtain runtime address of callee. slli a1, t1, 1 mv a0, t0 # link map add a1, a1, t1 # reloc offset (== thrice the .got.plt offset) - la a2, _dl_fixup - jalr a2 - mv t1, a0 + la t2, _dl_fixup + jalr t2 + mv t2, a0 # Restore arguments from stack. REG_L ra, 9*SZREG(sp) @@ -75,20 +76,20 @@ ENTRY (_dl_runtime_resolve) REG_L a7, 8*SZREG(sp) #ifndef __riscv_float_abi_soft - FREG_L fa0, (10*SZREG + 0*SZFREG)(sp) - FREG_L fa1, (10*SZREG + 1*SZFREG)(sp) - FREG_L fa2, (10*SZREG + 2*SZFREG)(sp) - FREG_L fa3, (10*SZREG + 3*SZFREG)(sp) - FREG_L fa4, (10*SZREG + 4*SZFREG)(sp) - FREG_L fa5, (10*SZREG + 5*SZFREG)(sp) - FREG_L fa6, (10*SZREG + 6*SZFREG)(sp) - FREG_L fa7, (10*SZREG + 7*SZFREG)(sp) + FREG_L fa0, (FREG_BASE_OFFSET + 0*SZFREG)(sp) + FREG_L fa1, (FREG_BASE_OFFSET + 1*SZFREG)(sp) + FREG_L fa2, (FREG_BASE_OFFSET + 2*SZFREG)(sp) + FREG_L fa3, (FREG_BASE_OFFSET + 3*SZFREG)(sp) + FREG_L fa4, (FREG_BASE_OFFSET + 4*SZFREG)(sp) + FREG_L fa5, (FREG_BASE_OFFSET + 5*SZFREG)(sp) + FREG_L fa6, (FREG_BASE_OFFSET + 6*SZFREG)(sp) + FREG_L fa7, (FREG_BASE_OFFSET + 7*SZFREG)(sp) #endif addi sp, sp, FRAME_SIZE # Invoke the callee. - jr t1 + jr t2 END (_dl_runtime_resolve) #if !defined PROF && defined SHARED diff --git a/sysdeps/riscv/start.S b/sysdeps/riscv/start.S index bc3bc04219..0d74cbf251 100644 --- a/sysdeps/riscv/start.S +++ b/sysdeps/riscv/start.S @@ -53,6 +53,7 @@ ENTRY (ENTRY_POINT) #if defined PIC && !defined SHARED /* Avoid relocation in static PIE since _start is called before it is relocated. */ + SET_LPAD lla a0, __wrap_main #else la a0, main @@ -69,7 +70,11 @@ ENTRY (ENTRY_POINT) END (ENTRY_POINT) #if defined PIC && !defined SHARED +#ifdef __riscv_landing_pad + .align 2 +#endif /* __riscv_landing_pad */ __wrap_main: + LPAD tail main@plt #endif @@ -79,9 +84,13 @@ __wrap_main: needs to be initialized before calling __libc_start_main in that case. So we redundantly initialize it at the beginning of _start. */ +#ifdef __riscv_landing_pad + .align 2 +#endif /* __riscv_landing_pad */ load_gp: .option push .option norelax + LPAD lla gp, __global_pointer$ .option pop ret diff --git a/sysdeps/riscv/sys/asm.h b/sysdeps/riscv/sys/asm.h index 1ca3d46120..54217540f8 100644 --- a/sysdeps/riscv/sys/asm.h +++ b/sysdeps/riscv/sys/asm.h @@ -46,13 +46,23 @@ # endif #endif +/* Landing pad for Zicfilp CFI. */ +#ifndef LPAD +# ifdef __riscv_landing_pad_unlabeled +# define LPAD lpad 0 +# else +# define LPAD +# endif +#endif + /* Declare leaf routine. */ #define LEAF(symbol) \ .globl symbol; \ .align 2; \ .type symbol,@function; \ symbol: \ - cfi_startproc; + cfi_startproc; \ + LPAD; /* Mark end of function. */ #undef END diff --git a/sysdeps/unix/sysv/linux/riscv/clone.S b/sysdeps/unix/sysv/linux/riscv/clone.S index 1ce930a97e..92e2752bf6 100644 --- a/sysdeps/unix/sysv/linux/riscv/clone.S +++ b/sysdeps/unix/sysv/linux/riscv/clone.S @@ -82,6 +82,7 @@ L (thread_start): REG_L a0,SZREG(sp) /* Argument pointer. */ /* Call the user's function. */ + SET_LPAD jalr a1 /* Call exit with the function's return value. */ diff --git a/sysdeps/unix/sysv/linux/riscv/sysdep.h b/sysdeps/unix/sysv/linux/riscv/sysdep.h index 7f0eb07045..c60b0623c2 100644 --- a/sysdeps/unix/sysv/linux/riscv/sysdep.h +++ b/sysdeps/unix/sysv/linux/riscv/sysdep.h @@ -53,6 +53,75 @@ # include +/* GNU_PROPERTY_RISCV_* macros from elf.h for use in asm code. */ +#define FEATURE_1_AND 0xc0000000 + +/* Add a NT_GNU_PROPERTY_TYPE_0 note. */ +#if __riscv_xlen == 32 +# define GNU_PROPERTY(type, value) \ + .section .note.gnu.property, "a"; \ + .p2align 2; \ + .word 4; \ + .word 12; \ + .word 5; \ + .asciz "GNU"; \ + .word type; \ + .word 4; \ + .word value; \ + .text +#else +# define GNU_PROPERTY(type, value) \ + .section .note.gnu.property, "a"; \ + .p2align 3; \ + .word 4; \ + .word 16; \ + .word 5; \ + .asciz "GNU"; \ + .word type; \ + .word 4; \ + .word value; \ + .word 0; \ + .text +#endif + +/* Add GNU property note with the supported features to all asm code + where sysdep.h is included. */ +#undef __VALUE_FOR_FEATURE_1_AND +#if defined (__riscv_landing_pad) || defined (__riscv_shadow_stack) +# if defined (__riscv_landing_pad_unlabeled) +# if defined (__riscv_shadow_stack) +# define __VALUE_FOR_FEATURE_1_AND 0x3 +# else +# define __VALUE_FOR_FEATURE_1_AND 0x1 +# endif +# elif defined (__riscv_landing_pad_func_sig) +# if defined (__riscv_shadow_stack) +# define __VALUE_FOR_FEATURE_1_AND 0x6 +# else +# define __VALUE_FOR_FEATURE_1_AND 0x4 +# endif +# else +# if defined (__riscv_shadow_stack) +# define __VALUE_FOR_FEATURE_1_AND 0x2 +# else +# error "What?" +# endif +# endif +#endif + +#if defined (__VALUE_FOR_FEATURE_1_AND) +GNU_PROPERTY (FEATURE_1_AND, __VALUE_FOR_FEATURE_1_AND) +#endif +#undef __VALUE_FOR_FEATURE_1_AND + +#ifdef __riscv_landing_pad_unlabeled +# define SET_LPAD +# define LPAD lpad 0 +#else +# define SET_LPAD +# define LPAD +#endif + # define ENTRY(name) LEAF(name) # define L(label) .L ## label From patchwork Sun Jun 28 07:02:30 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Jesse Huang X-Patchwork-Id: 137960 Return-Path: X-Original-To: patchwork@sourceware.org Delivered-To: patchwork@sourceware.org Received: from vm01.sourceware.org (localhost [IPv6:::1]) by sourceware.org (Postfix) with ESMTP id AA7594BA2E27 for ; Sun, 28 Jun 2026 07:03:53 +0000 (GMT) DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org AA7594BA2E27 Authentication-Results: sourceware.org; dkim=pass (2048-bit key, unprotected) header.d=sifive.com header.i=@sifive.com header.a=rsa-sha256 header.s=google header.b=XNzYO+gh X-Original-To: libc-alpha@sourceware.org Delivered-To: libc-alpha@sourceware.org Received: from mail-dl1-x122b.google.com (mail-dl1-x122b.google.com [IPv6:2607:f8b0:4864:20::122b]) by sourceware.org (Postfix) with ESMTPS id 41C254BA23D6 for ; Sun, 28 Jun 2026 07:02:56 +0000 (GMT) DMARC-Filter: OpenDMARC Filter v1.4.2 sourceware.org 41C254BA23D6 Authentication-Results: sourceware.org; dmarc=pass (p=reject dis=none) header.from=sifive.com Authentication-Results: sourceware.org; spf=pass smtp.mailfrom=sifive.com ARC-Filter: OpenARC Filter v1.0.0 sourceware.org 41C254BA23D6 Authentication-Results: sourceware.org; arc=none smtp.remote-ip=2607:f8b0:4864:20::122b ARC-Seal: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1782630176; cv=none; b=tgqen+nm13bLTMDAmueFgUNJvARJKeroWVVfGv2QxhWFisxmjXwp5vR9PhKFQSspCftP/B/GK21Bi1aCsRuU1iEGMqdb7pYngts5e91BFvobbdT8HD26CpGACsIZv6lApAwhz+mSUUz12ZZQaJ8Re5Rjd1G3Lpqmfg5dJmoSrfI= ARC-Message-Signature: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1782630176; c=relaxed/simple; bh=AKyDAEcQmm67Yc5ruYgjXDr+BaZaUSINTDne1+4yA5w=; h=DKIM-Signature:From:To:Subject:Date:Message-Id:MIME-Version; b=Ji5MnF6wk45Cn8nxa4FOacdnkiNUf7dY3PMo+SvL1W7xMUfVvTPJkiVAXpL9NZX3wlDkjol4S8DRbVhfZrN3i4kOQQmfxIyndWM211jtr+kFeffTLWNCRj5YUYpSkq5JWO4/FlYDGktODhr5EPfczHF6vXcDb2KU7O76x2v96rQ= ARC-Authentication-Results: i=1; sourceware.org; dkim=pass (2048-bit key, unprotected) header.d=sifive.com header.i=@sifive.com header.a=rsa-sha256 header.s=google header.b=XNzYO+gh DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org 41C254BA23D6 Received: by mail-dl1-x122b.google.com with SMTP id a92af1059eb24-139eee0707bso3194640c88.0 for ; Sun, 28 Jun 2026 00:02:56 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=sifive.com; s=google; t=1782630175; x=1783234975; darn=sourceware.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to; bh=N6wZrkIEVHrgCYARwYpLYU2l0dF+0llAWaHjAWWH114=; b=XNzYO+gh5YJJWs/As8rFjnf+0qolo1ctf9ExPQTkt13Qn/Q+ap7zL1vo7KKwNYKvT9 YArUoAlB+yJrtrhoAoaUWl0KC0AZBzqQsqZPVCc+XmrCYTeVuDfjztTphtZJ4sA9IdoU CqzGRkvP/vTJhDW7o+BbgkKMCqYt2i2ZBtbVm4CqqMQ4IPRlxtbMGnHOfWRn7UBTWLjU 4UgM/5OMIL1LsI4oFIEHc5JGHUIhPC9cgT9U0vueVWRs0H8ATH9gCMOquqYYBip4GCfH Ber4iylbqTv6jHyeBRifUJQUSNdT2Qd/y2PuMQSKywvYJWtOWnCf+zPJ3RcjiAS/UEIv eJJg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1782630175; x=1783234975; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to; bh=N6wZrkIEVHrgCYARwYpLYU2l0dF+0llAWaHjAWWH114=; b=F8lSOOT0CKCOBKw8A/qPk9h9IlAuoDNufw/IlFPy/L9B38ie72hvMKv49qDC7ggKCA wFaxRS3IzjhCBf2DKSWmvugv+L2KnqR5JhZvXQmImtZlTLvoow55IkPs9YQ5zk5kT2o8 mCyNmEuQxeGUr0ocWjXdAkvz2LCiaiG23qmtM8id+tF81dl8ccPgN+XEulBfcIuN1rTG Yek367A4tHu6EaNko94YeQYfYus7pb0kI28xZPUUIG767n6eITqKz4Sf4VHbFTvLlfom DT2BtPk5yH9WG8FfYrjaIRVur9HHa1v/XmWY4XTmkwzPW01CkeqFhvcGkzU9CwF9VayY 2shA== X-Gm-Message-State: AOJu0YwlANgP0ZD6H/lNJ5KornwKSlRDI2wzi6tyZerOJi+/boMXJZqJ mxGNAe7x/SnLn6tO9dsDmDcM5U2N/YHlT4T9DhoFGpMbEAAab4gOartkQgQXHI6wN+xFWzVghp7 qdF8N6xNuF9KPmhhqvRCoe+GX+RC7q5+oeQOTgDB+w32gvija8yuVHM72fDHOxF5bfdl8ntr3LL 1f4fltcUP7PfbL9yEH/h/20pj3J5JRdXUV8w32Mo10XcaltDNJZg4= X-Gm-Gg: AfdE7cnMlig+pqkYAMNv1euuQsnspAvqWmSJaBHB2iRx6ckUdh6/MCOZL0TxkApl83l 1ggv6z+z6iFyf8nUNku3/iD1SRItvlnL3/IO+k/CFwYxzXfWfqDIf4bDJFn0qD43hxpgE8TKeTu jA0a4ZIlAlPVZQLhhemfTi52ackEFp+qoies0VyujryTBC8nkpuazdJ24zPJgfEdehMSLttuMPM POXv75MYc9u/LL6ltRIpDWu/LDTg5phUmTtuqDPJ56qyUrRcrFKpF08ffHLRfjQd77Ta6hxZI0H IRA27W/oIcGsMNc+1JS7OutDJel5yZNTwz8JiHakd6NCXipsR8TqCA6HE7C+zPU4CCUj+Ig8dBg NJEmdFnMYfeg0/oD34d+Df/C7zjGP+qgBKERDxU2fvToIQ0bmE26xK5wcV0XTEIOnIHyWfnbLVu bKl3uzzL2xQmpsNxAQZRUTitoKTl0ak9Qpn26bX4hP X-Received: by 2002:a05:7022:69a7:b0:139:ed5d:3a2 with SMTP id a92af1059eb24-139ed5d0536mr5004273c88.39.1782630175037; Sun, 28 Jun 2026 00:02:55 -0700 (PDT) Received: from sw08.internal.sifive.com ([4.53.31.132]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-30c7c8afc91sm35435166eec.14.2026.06.28.00.02.53 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 28 Jun 2026 00:02:54 -0700 (PDT) From: Jesse Huang To: libc-alpha@sourceware.org Cc: andrew@sifive.com, darius@bluespec.com, debug@rivosinc.com, jeffreyalaw@gmail.com, kito.cheng@sifive.com, palmer@dabbelt.com, schwab@suse.de, Jesse Huang Subject: [PATCH v5 05/16] riscv: Introduce feature variables for RISC-V GNU properties Date: Sun, 28 Jun 2026 00:02:30 -0700 Message-Id: <20260628070241.88310-6-jesse.huang@sifive.com> X-Mailer: git-send-email 2.39.3 In-Reply-To: <20260628070241.88310-1-jesse.huang@sifive.com> References: <20260628070241.88310-1-jesse.huang@sifive.com> MIME-Version: 1.0 X-Spam-Status: No, score=-13.2 required=5.0 tests=BAYES_00, DKIM_SIGNED, DKIM_VALID, DKIM_VALID_AU, DKIM_VALID_EF, GIT_PATCH_0, KAM_SHORT, RCVD_IN_DNSWL_NONE, SPF_HELO_NONE, SPF_PASS, TXREP shortcircuit=no autolearn=ham autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on sourceware.org X-BeenThere: libc-alpha@sourceware.org X-Mailman-Version: 2.1.30 Precedence: list List-Id: Libc-alpha mailing list List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: libc-alpha-bounces~patchwork=sourceware.org@sourceware.org The l_riscv_feature_1_and member is added to struct link_map. It stores the feature_1_and property information for each object. The new global _dl_riscv_feature_1 stores the features that are finally enabled for this process. Reviewed-by: Deepak Gupta --- sysdeps/riscv/dl-procruntime.c | 60 ++++++++++++++++++++++++++++++++++ sysdeps/riscv/link_map.h | 22 +++++++++++++ 2 files changed, 82 insertions(+) create mode 100644 sysdeps/riscv/dl-procruntime.c create mode 100644 sysdeps/riscv/link_map.h diff --git a/sysdeps/riscv/dl-procruntime.c b/sysdeps/riscv/dl-procruntime.c new file mode 100644 index 0000000000..06a582920e --- /dev/null +++ b/sysdeps/riscv/dl-procruntime.c @@ -0,0 +1,60 @@ +/* Data for processor runtime information. RISC-V version. + Copyright (C) 2026 Free Software Foundation, Inc. + This file is part of the GNU C Library. + + The GNU C Library is free software; you can redistribute it and/or + modify it under the terms of the GNU Lesser General Public + License as published by the Free Software Foundation; either + version 2.1 of the License, or (at your option) any later version. + + The GNU C Library is distributed in the hope that it will be useful, + but WITHOUT ANY WARRANTY; without even the implied warranty of + MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU + Lesser General Public License for more details. + + You should have received a copy of the GNU Lesser General Public + License along with the GNU C Library; if not, see + . */ + +/* This information must be kept in sync with the _DL_HWCAP_COUNT, + HWCAP_PLATFORMS_START and HWCAP_PLATFORMS_COUNT definitions in + dl-hwcap.h. + + If anything should be added here check whether the size of each string + is still ok with the given array size. + + All the #ifdefs in the definitions are quite irritating but + necessary if we want to avoid duplicating the information. There + are three different modes: + + - PROCINFO_DECL is defined. This means we are only interested in + declarations. + + - PROCINFO_DECL is not defined: + + + if SHARED is defined the file is included in an array + initializer. The .element = { ... } syntax is needed. + + + if SHARED is not defined a normal array initialization is + needed. + */ + +#ifndef PROCINFO_CLASS +# define PROCINFO_CLASS +#endif + +#if !IS_IN (ldconfig) +# if !defined PROCINFO_DECL && defined SHARED + ._dl_riscv_feature_1 +# else +PROCINFO_CLASS unsigned int _dl_riscv_feature_1 +# endif +# ifndef PROCINFO_DECL += 0 +# endif +# if !defined SHARED || defined PROCINFO_DECL +; +# else +, +# endif +#endif diff --git a/sysdeps/riscv/link_map.h b/sysdeps/riscv/link_map.h new file mode 100644 index 0000000000..4a6428bb24 --- /dev/null +++ b/sysdeps/riscv/link_map.h @@ -0,0 +1,22 @@ +/* Additional fields in struct link_map. Linux/RISC-V version. + Copyright (C) 2026 Free Software Foundation, Inc. + This file is part of the GNU C Library. + + The GNU C Library is free software; you can redistribute it and/or + modify it under the terms of the GNU Lesser General Public + License as published by the Free Software Foundation; either + version 2.1 of the License, or (at your option) any later version. + + The GNU C Library is distributed in the hope that it will be useful, + but WITHOUT ANY WARRANTY; without even the implied warranty of + MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU + Lesser General Public License for more details. + + You should have received a copy of the GNU Lesser General Public + License along with the GNU C Library; if not, see + . */ + +/* GNU_PROPERTY_RISCV_FEATURE_1_AND of this object. */ +unsigned int l_riscv_feature_1_and; + +#include From patchwork Sun Jun 28 07:02:31 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Jesse Huang X-Patchwork-Id: 137963 Return-Path: X-Original-To: patchwork@sourceware.org Delivered-To: patchwork@sourceware.org Received: from vm01.sourceware.org (localhost [IPv6:::1]) by sourceware.org (Postfix) with ESMTP id 247754BA23C4 for ; Sun, 28 Jun 2026 07:05:35 +0000 (GMT) DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org 247754BA23C4 Authentication-Results: sourceware.org; dkim=pass (2048-bit key, unprotected) header.d=sifive.com header.i=@sifive.com header.a=rsa-sha256 header.s=google header.b=PwVTCZaA X-Original-To: libc-alpha@sourceware.org Delivered-To: libc-alpha@sourceware.org Received: from mail-dl1-x1233.google.com (mail-dl1-x1233.google.com [IPv6:2607:f8b0:4864:20::1233]) by sourceware.org (Postfix) with ESMTPS id A82184BA2E37 for ; Sun, 28 Jun 2026 07:02:57 +0000 (GMT) DMARC-Filter: OpenDMARC Filter v1.4.2 sourceware.org A82184BA2E37 Authentication-Results: sourceware.org; dmarc=pass (p=reject dis=none) header.from=sifive.com Authentication-Results: sourceware.org; spf=pass smtp.mailfrom=sifive.com ARC-Filter: OpenARC Filter v1.0.0 sourceware.org A82184BA2E37 Authentication-Results: sourceware.org; arc=none smtp.remote-ip=2607:f8b0:4864:20::1233 ARC-Seal: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1782630177; cv=none; b=WNHxTKLifbx2GK2xWN/bAefYvaznc3DALAIAnS5+wK+NP5bqxbeDU0f4HHkGiKfEK6HkXDpvWdV5k/jOFCmv3jjJdd3zvd1qvxbBLjoKjVBlYTVzBlFWlS69zpd7oKj/pCM6dVuLar8dDrCeHgQ/nd1y6RsTyFVIJxytKTTbK5c= ARC-Message-Signature: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1782630177; c=relaxed/simple; bh=Y3K4V8q5W4TH16eSbcr00Bg2qKUx+91UNI+xArZZZq4=; h=DKIM-Signature:From:To:Subject:Date:Message-Id:MIME-Version; b=rBkQK4N7J+fkKvuqzzUgFI2Kh5E8aXuSibsbvDBFLHhVyRoGtZ4U93EBfIDlTT8J5vTUvmO2cxjFwv6AyHOxSIRmnNbeZ+RbwJv3y9d9zeWhtju8tHxQMY3xM7qvemr93q4VNLa0tWo7fPwRt3JSB747oxbIHe/iDxjPMVxePlc= ARC-Authentication-Results: i=1; sourceware.org; dkim=pass (2048-bit key, unprotected) header.d=sifive.com header.i=@sifive.com header.a=rsa-sha256 header.s=google header.b=PwVTCZaA DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org A82184BA2E37 Received: by mail-dl1-x1233.google.com with SMTP id a92af1059eb24-13986d61b4fso3190823c88.0 for ; Sun, 28 Jun 2026 00:02:57 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=sifive.com; s=google; t=1782630177; x=1783234977; darn=sourceware.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to; bh=R0alLZ86ESfhXWQAiTAP9hCX/QLpZshVTM+PDb6Smq4=; b=PwVTCZaAPYQbs3YEe9CCqp/t/3A37SNHXM49YqEfnPCOEP/W4EGzz8DahTwVvNggw6 uaL02Z4/zdEF5sFDozkcSv+ChL1/bWOf6Jtyd/ISuJb86CwBXEQp/NAgfBjyen2cRBq3 O8fZ5ULzVzOQEua5OdTqDdb7wfEGb5sEQl35qcbaxow4tn1J1QGED6VQxQSoRfknlTkh 74S62bGE+ghHUikqcyF0SHhaEuTpE3s8RQR1PZu3lSMYk/Z489i0nep26KKjYIW9wgWF hETo8IIShzhLwaEjjqU3d7LswOGL+udvdoDtqIC1SjCpN4wl99xjnONsYi6cuJTi0xlQ jwAQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1782630177; x=1783234977; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to; bh=R0alLZ86ESfhXWQAiTAP9hCX/QLpZshVTM+PDb6Smq4=; b=nU2Ul77XOvWa8AHabjCRaxMEZoZWIOlPmUptWEo3xDwmra5UdJK3HtGWbaLdWLsoI+ 4Jx/XMH+jcxXsdymTxQFIymDn4eAuyhKUBBWiIq9RejgSJ6RQBlPrZCx/Bcr1gyuUl7p QJs5HGz9dJttzcw9Vk+1KYwiF80S6KgGT1nzVt06EnK75NbsFH5QnCbZTQRUPTPX1yEE cA/nptDxSQ10ebaM029hlhBn9EVffQZz06wUY2KOVvKx2R78eOQEH7aR63X5dWlCNIIo iFZLYCJFPF6BgVAwExJvIzVZ1SxIxvY9+gZU3OfgU27+7L5xVIR9DVfZG5kjgjlbPrQB SMog== X-Gm-Message-State: AOJu0Yx5eSDNTDH9a5VTW0Vpog4GiITQzI6DjrngcYpTZwrbVC/akVmA 8+kQ00Tc/xqVLDEL4zRNpVg/lUtTK0kW7nHmWBkpJIVVsmCZ9dhDmc895E7BhFes3ea5Rs85iSt 9hAiYO7n5ZxwxsSpsSpBvfmRWZSdVC7Xopx6lt1r7ST5vSVBsudscs+u+Yr+wW4AAGyikQ78klG OA8r/6CXE4GppNnQ2BUfvOvZ4qQGbZV3sLr+8NRzOba0mX7AWChcU= X-Gm-Gg: AfdE7cmyA+YAPbBftGTX7my0/8t6hpIUZldtttfnL/7Rvitotf29iVpkI+qQaahDRcZ 1lnbT94y65RNfUQpp0v6bbv0Xts1YJ2Ix21rOPenXg6Fo/m8kPstNgUt7nbSJnjLID5JXp/qs1N 1H5HAdcI3dn+dkBG9s/je11Xxzzafk266nvVR4DceDIhegXOmgMXjf21MCQwowqP8AOjcRx1/Vm 3iNamdqLP4C5AXl8LtF5whgQuSv8cCOlp/ix2KXPa+7euaXL8b3vxP4/9yqWf0kOPaYvFNXuYjq 0D7qJsoLfL1J/kAD+mdjLln+WqcnhdLZrN6ZcECS2dubH8ZsHAf049UszsIpnYsU1jN1jO/yJ72 NqkiQGTV4J1BrxfmkQvLXGkLdN7TSMrjAr2mxcpEVGHdwDbqFu9U+Ox0xJpFCzpHCvuncr37j7z /+p9N+Iov4v6SNc3CZiE2ECNDY/T6E89SFd6XHyzmX X-Received: by 2002:a05:693c:88cd:20b0:30c:9449:72bb with SMTP id 5a478bee46e88-30c944a0ce9mr6272623eec.22.1782630176476; Sun, 28 Jun 2026 00:02:56 -0700 (PDT) Received: from sw08.internal.sifive.com ([4.53.31.132]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-30c7c8afc91sm35435166eec.14.2026.06.28.00.02.55 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 28 Jun 2026 00:02:55 -0700 (PDT) From: Jesse Huang To: libc-alpha@sourceware.org Cc: andrew@sifive.com, darius@bluespec.com, debug@rivosinc.com, jeffreyalaw@gmail.com, kito.cheng@sifive.com, palmer@dabbelt.com, schwab@suse.de, Jesse Huang Subject: [PATCH v5 06/16] riscv/cfi: Add prctl definitions for RISC-V CFI Date: Sun, 28 Jun 2026 00:02:31 -0700 Message-Id: <20260628070241.88310-7-jesse.huang@sifive.com> X-Mailer: git-send-email 2.39.3 In-Reply-To: <20260628070241.88310-1-jesse.huang@sifive.com> References: <20260628070241.88310-1-jesse.huang@sifive.com> MIME-Version: 1.0 X-Spam-Status: No, score=-13.2 required=5.0 tests=BAYES_00, DKIM_SIGNED, DKIM_VALID, DKIM_VALID_AU, DKIM_VALID_EF, GIT_PATCH_0, RCVD_IN_DNSWL_NONE, SPF_HELO_NONE, SPF_PASS, TXREP shortcircuit=no autolearn=ham autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on sourceware.org X-BeenThere: libc-alpha@sourceware.org X-Mailman-Version: 2.1.30 Precedence: list List-Id: Libc-alpha mailing list List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: libc-alpha-bounces~patchwork=sourceware.org@sourceware.org These operations are for setting/retrieving/locking the status of the landing pad and the shadow stack extensions. --- .../unix/sysv/linux/riscv/include/asm/prctl.h | 43 +++++++++++++++++++ 1 file changed, 43 insertions(+) create mode 100644 sysdeps/unix/sysv/linux/riscv/include/asm/prctl.h diff --git a/sysdeps/unix/sysv/linux/riscv/include/asm/prctl.h b/sysdeps/unix/sysv/linux/riscv/include/asm/prctl.h new file mode 100644 index 0000000000..30a37452e1 --- /dev/null +++ b/sysdeps/unix/sysv/linux/riscv/include/asm/prctl.h @@ -0,0 +1,43 @@ +/* + * Get the current shadow stack configuration for the current thread, + * this will be the value configured via PR_SET_SHADOW_STACK_STATUS. + */ +#define PR_GET_SHADOW_STACK_STATUS 74 + +/* + * Set the current shadow stack configuration. Enabling the shadow + * stack will cause a shadow stack to be allocated for the thread. + */ +#define PR_SET_SHADOW_STACK_STATUS 75 +# define PR_SHADOW_STACK_ENABLE (1UL << 0) +# define PR_SHADOW_STACK_WRITE (1UL << 1) +# define PR_SHADOW_STACK_PUSH (1UL << 2) + +/* + * Prevent further changes to the specified shadow stack + * configuration. All bits may be locked via this call, including + * undefined bits. + */ +#define PR_LOCK_SHADOW_STACK_STATUS 76 + +/* + * Get or set the control flow integrity (CFI) configuration for the + * current thread. + * + * Some per-thread control flow integrity settings are not yet + * controlled through this prctl(); see for example + * PR_{GET,SET,LOCK}_SHADOW_STACK_STATUS + */ +#define PR_GET_CFI 80 +#define PR_SET_CFI 81 + +/* + * Forward-edge CFI variants (excluding ARM64 BTI, which has its own + * prctl()s). + */ +#define PR_CFI_BRANCH_LANDING_PADS 0 + +/* Return and control values for PR_{GET,SET}_CFI */ +# define PR_CFI_ENABLE (1UL << 0) +# define PR_CFI_DISABLE (1UL << 1) +# define PR_CFI_LOCK (1UL << 2) From patchwork Sun Jun 28 07:02:32 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Jesse Huang X-Patchwork-Id: 137968 Return-Path: X-Original-To: patchwork@sourceware.org Delivered-To: patchwork@sourceware.org Received: from vm01.sourceware.org (localhost [IPv6:::1]) by sourceware.org (Postfix) with ESMTP id 6ED0B4BA2E27 for ; Sun, 28 Jun 2026 07:07:08 +0000 (GMT) DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org 6ED0B4BA2E27 Authentication-Results: sourceware.org; dkim=pass (2048-bit key, unprotected) header.d=sifive.com header.i=@sifive.com header.a=rsa-sha256 header.s=google header.b=VHt6gyt6 X-Original-To: libc-alpha@sourceware.org Delivered-To: libc-alpha@sourceware.org Received: from mail-dy1-x132e.google.com (mail-dy1-x132e.google.com [IPv6:2607:f8b0:4864:20::132e]) by sourceware.org (Postfix) with ESMTPS id F2F0E4BA23C4 for ; Sun, 28 Jun 2026 07:02:58 +0000 (GMT) DMARC-Filter: OpenDMARC Filter v1.4.2 sourceware.org F2F0E4BA23C4 Authentication-Results: sourceware.org; dmarc=pass (p=reject dis=none) header.from=sifive.com Authentication-Results: sourceware.org; spf=pass smtp.mailfrom=sifive.com ARC-Filter: OpenARC Filter v1.0.0 sourceware.org F2F0E4BA23C4 Authentication-Results: sourceware.org; arc=none smtp.remote-ip=2607:f8b0:4864:20::132e ARC-Seal: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1782630179; cv=none; b=FaSJ4+Wje7KsZ7iIV6RYlUCtWoobOX/c/JjbTZcPjld5LMqFd9x60V1cwbL9AGB0eB/zKR0LctOK/rLiWbb51XwDWTPXFVxv7fQOxEzQZ0a7s2IFbh0TLU71eGL083CnOMPsHwZ/qYdMURt5SFA0RiF5xfIveJt5ZzRBvAnJl+Y= ARC-Message-Signature: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1782630179; c=relaxed/simple; bh=8R5LPZdkTKX7FfwebHlSwgZGz2yussBTZ3yxBVhFZs0=; h=DKIM-Signature:From:To:Subject:Date:Message-Id:MIME-Version; b=fSFLmXJpcL9QNw8SWpOUjv9HQ5kk2DW6aJddiGMwY5UXisphkhHcpHGmoznvAjUtA1SizpWOXTZ3BjPR/tsdkf0HFO2eIj1/jJ6Apy03nI3AZSqTmM3dGPKGoBzlRw6uoRwJwpaJ5xaUradNI5PX2rwVspjcG/2LzJ9S2KyXXcw= ARC-Authentication-Results: i=1; sourceware.org; dkim=pass (2048-bit key, unprotected) header.d=sifive.com header.i=@sifive.com header.a=rsa-sha256 header.s=google header.b=VHt6gyt6 DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org F2F0E4BA23C4 Received: by mail-dy1-x132e.google.com with SMTP id 5a478bee46e88-30ca1b4b278so4282558eec.0 for ; Sun, 28 Jun 2026 00:02:58 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=sifive.com; s=google; t=1782630178; x=1783234978; darn=sourceware.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to; bh=jw6e31Z6RZh98oofDda6j/N/TjYRskK/A1c3Wz6vJPo=; b=VHt6gyt6P6QymEAZXfrkYalmJ13Ky/MAw3l8aDKlLVI4BkbgrqwlfpTQn2mT1n12vm cVYgc2tx14WbL0HlHi9x7U4KZXDUMtwFCvcrUY7Crg54P/So+JuUbULteyZDJZKJ5qUl p+9oUM6WU8V7q3fiOuiqsA1m9b/ls5jlYqZ1/REy8gDnB1nrCktGb5r6JRp0rid9ZrP2 fpPKG2L6Co5Y5HmfBNlWaINoVsWv/Vw0UMsf96ccfvxUTjJwPXd2eN+sB3vBN7+kMamg gTbHuOXH3LtYOjppo3sZCO0Q3Ig/NOidVF5hD6TgewudplRHkNHMh4vo6SdxYnr/0jnX b9Ug== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1782630178; x=1783234978; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to; bh=jw6e31Z6RZh98oofDda6j/N/TjYRskK/A1c3Wz6vJPo=; b=B2tcWrVWaRz+CtXvWt+9V9BgJ3K4dP9xfl218pkMmf2bcWBOOOZBJtIDMqTFVuPWK+ B5SSGdrn9J2zmRogOHDuizdumOX742E2hwPpeB6wH10Ogm6bA9J2d9TMudh2tRDWGuja 9VKclzZzYu8P+nL8wTHi1y6isyboVZAGn5KdoW1aCK8CzxnymewHZkCJGHxP61hAnvIs QaJCUbDmGfg5KeDgwLbz/JPNLkzeb+xuQqaNMYiYLsy8rXGW1P3Hk6hA1yOHl1pT2YqS cWTTtc8+C570sikMbXNARCY0teKQaMiwntI/vYf7niIhuBLRl7s+nCI5DoPnRy1vgOdR 6fBg== X-Gm-Message-State: AOJu0YwfbL2qeuNQf/nca31/pbB8I36hbM99bxrmHmuLgA1r2s0hXaTk pW5Y3kDDaK2aR25IMIod2EGlC8taGyt6IoQjV9MyZUHIbbPSqajCe+lp2afKBdCkwOl4EbQqExs OyKJmDOrttCl9711gex2Zxc52ioB6y/xR80RST+fIOiA+IPY9R6LdhwRZ86kJw4XvKdMN5n4jvy kVdW8fsRdLEQbN8s6DYSnNEBQqEWzskARiBi5CBPrV1SlVkj2X1+8= X-Gm-Gg: AfdE7clUy12CrHApRLHErycZhGQh9OqMmjOn61b08oFOfyaKQcTx/cWOhlHQe6AcuuO Z6bnZw+D8GDP4pMgDVVjUwltiyVd5c1O2lACYlr1I3WImDGeqSfLElSOP2TXokYQmZfq768Nj9m Y269Ectp63A8F6GW3Rd2QtMa7hZzKERRO9ESTnTJUVNo5DhiaxZiIGxbSdwfx+dRVsVPS/ThDpN as2o6f20hWPb60xdOIilsa8Al7X5bspaT0BX3OTKmS/sqy5e5cWX7AFKBfF5NNt46Ksa6HTu7oQ M7X3xEwLGTLa9aU4mYSXfYznYwSiA6lP1XcqPy306VcQbJVVxVRFZxt9OjImgbQrjF8EQm+xbNH hzmecJd5qGn2QpDO/a87scZoLM7iduCuJjs5syWS3FbovR+SdhRkU0MpK4qSdWRyDU2USKd+zE0 1VbSY99g9C444Z/qYpPcA0ueF4+30CaQ== X-Received: by 2002:a05:7300:3207:b0:30c:ab4d:382d with SMTP id 5a478bee46e88-30cab4d3bf1mr5611623eec.36.1782630177687; Sun, 28 Jun 2026 00:02:57 -0700 (PDT) Received: from sw08.internal.sifive.com ([4.53.31.132]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-30c7c8afc91sm35435166eec.14.2026.06.28.00.02.56 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 28 Jun 2026 00:02:57 -0700 (PDT) From: Jesse Huang To: libc-alpha@sourceware.org Cc: andrew@sifive.com, darius@bluespec.com, debug@rivosinc.com, jeffreyalaw@gmail.com, kito.cheng@sifive.com, palmer@dabbelt.com, schwab@suse.de, Jesse Huang Subject: [PATCH v5 07/16] riscv/cfi: Enable CFI on static binaries Date: Sun, 28 Jun 2026 00:02:32 -0700 Message-Id: <20260628070241.88310-8-jesse.huang@sifive.com> X-Mailer: git-send-email 2.39.3 In-Reply-To: <20260628070241.88310-1-jesse.huang@sifive.com> References: <20260628070241.88310-1-jesse.huang@sifive.com> MIME-Version: 1.0 X-Spam-Status: No, score=-13.2 required=5.0 tests=BAYES_00, DKIM_SIGNED, DKIM_VALID, DKIM_VALID_AU, DKIM_VALID_EF, GIT_PATCH_0, KAM_SHORT, RCVD_IN_DNSWL_NONE, SPF_HELO_NONE, SPF_PASS, TXREP shortcircuit=no autolearn=ham autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on sourceware.org X-BeenThere: libc-alpha@sourceware.org X-Mailman-Version: 2.1.30 Precedence: list List-Id: Libc-alpha mailing list List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: libc-alpha-bounces~patchwork=sourceware.org@sourceware.org For static binaries, CFI is enabled inside ARCH_SETUP_TLS. A macro enables shadow stack early enough to prevent shadow stack underflow on return, and _dl_cfi_setup_features enables landing pad. The code scans the program headers backward to find the first PT_GNU_PROPERTY note, then enables CFI features corresponding to the feature bits. Co-authored-by: Deepak Gupta --- sysdeps/riscv/Makefile | 1 + sysdeps/riscv/dl-cfi.c | 36 +++++++++++ sysdeps/riscv/dl-machine.h | 6 ++ sysdeps/riscv/dl-prop.h | 65 +++++++++++++++++++ sysdeps/riscv/libc-start.h | 88 ++++++++++++++++++++++++++ sysdeps/unix/sysv/linux/riscv/dl-cfi.h | 20 ++++++ 6 files changed, 216 insertions(+) create mode 100644 sysdeps/riscv/dl-cfi.c create mode 100644 sysdeps/riscv/dl-prop.h create mode 100644 sysdeps/riscv/libc-start.h create mode 100644 sysdeps/unix/sysv/linux/riscv/dl-cfi.h diff --git a/sysdeps/riscv/Makefile b/sysdeps/riscv/Makefile index 99976fddad..4752bdb1a0 100644 --- a/sysdeps/riscv/Makefile +++ b/sysdeps/riscv/Makefile @@ -18,6 +18,7 @@ endif # Enable RISC-V CFI ifeq (yes,$(riscv-enable-cfi)) +sysdep-dl-routines += dl-cfi CFLAGS-.o += -fcf-protection=full CFLAGS-.os += -fcf-protection=full CFLAGS-.op += -fcf-protection=full diff --git a/sysdeps/riscv/dl-cfi.c b/sysdeps/riscv/dl-cfi.c new file mode 100644 index 0000000000..216e8f12c0 --- /dev/null +++ b/sysdeps/riscv/dl-cfi.c @@ -0,0 +1,36 @@ +/* RISC-V CFI extensions (zicfilp/zicfiss) functions. + Copyright (C) 2026 Free Software Foundation, Inc. + + The GNU C Library is free software; you can redistribute it and/or + modify it under the terms of the GNU Lesser General Public + License as published by the Free Software Foundation; either + version 2.1 of the License, or (at your option) any later version. + + The GNU C Library is distributed in the hope that it will be useful, + but WITHOUT ANY WARRANTY; without even the implied warranty of + MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU + Lesser General Public License for more details. + + You should have received a copy of the GNU Lesser General Public + License along with the GNU C Library; if not, see + . */ + +#include +#include +#include +#include +#include +#include + +attribute_hidden void +_dl_cfi_setup_features (unsigned int feature_1) +{ + /* Since prctl could fail to enable some features + use prctl to get enabled features again and sync it back. */ +#ifdef __riscv_landing_pad + if (feature_1 & GNU_PROPERTY_RISCV_FEATURE_1_CFI_LP_UNLABELED) + INTERNAL_SYSCALL_CALL (prctl, PR_SET_CFI, PR_CFI_BRANCH_LANDING_PADS, + PR_CFI_ENABLE, 0, 0, 0); +#endif /* __riscv_landing_pad */ + /* FIXME: Read enabled features from kernel and re-sync */ +} diff --git a/sysdeps/riscv/dl-machine.h b/sysdeps/riscv/dl-machine.h index 05992c8705..b7b9959d58 100644 --- a/sysdeps/riscv/dl-machine.h +++ b/sysdeps/riscv/dl-machine.h @@ -28,6 +28,12 @@ #include #include #include +#if defined(__riscv_landing_pad) || defined(__riscv_shadow_stack) +# include +extern void _dl_cfi_setup_features (unsigned int features); +#else +# define RTLD_START_ENABLE_RISCV_CFI +#endif /* This is a marker to remind us to add real expansion to setup the label for the function signature label scheme in the future */ #ifdef __riscv_landing_pad_unlabeled diff --git a/sysdeps/riscv/dl-prop.h b/sysdeps/riscv/dl-prop.h new file mode 100644 index 0000000000..a183d3148a --- /dev/null +++ b/sysdeps/riscv/dl-prop.h @@ -0,0 +1,65 @@ +/* Support for GNU properties. RISC-V version. + Copyright (C) 2026 Free Software Foundation, Inc. + This file is part of the GNU C Library. + + The GNU C Library is free software; you can redistribute it and/or + modify it under the terms of the GNU Lesser General Public + License as published by the Free Software Foundation; either + version 2.1 of the License, or (at your option) any later version. + + The GNU C Library is distributed in the hope that it will be useful, + but WITHOUT ANY WARRANTY; without even the implied warranty of + MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU + Lesser General Public License for more details. + + You should have received a copy of the GNU Lesser General Public + License along with the GNU C Library; if not, see + . */ + +#ifndef _DL_PROP_H +#define _DL_PROP_H + +static inline void __attribute__ ((always_inline)) +_rtld_main_check (struct link_map *m, const char *program) +{ +} + +static inline void __attribute__ ((always_inline)) +_dl_open_check (struct link_map *m, int dl_openmode) +{ +} + +static inline void __attribute__ ((always_inline)) +_dl_process_pt_note (struct link_map *l, int fd, const ElfW(Phdr) *ph) +{ +} + +static inline int +_dl_process_gnu_property (struct link_map *l, int fd, uint32_t type, + uint32_t datasz, void *data) +{ + /* FIXME: Detect cpu features after we have it implemented in glibc */ + + if (type == GNU_PROPERTY_RISCV_FEATURE_1_AND) + { + /* Stop if the property note is ill-formed. */ + if (datasz != 4) + return -1; + +#if defined(__riscv_landing_pad) || defined(__riscv_shadow_stack) + unsigned int feature_1 = *(unsigned int *) data; +#endif +#ifdef __riscv_landing_pad + if (feature_1 & GNU_PROPERTY_RISCV_FEATURE_1_CFI_LP_UNLABELED) + l->l_riscv_feature_1_and |= GNU_PROPERTY_RISCV_FEATURE_1_CFI_LP_UNLABELED; +#endif +#ifdef __riscv_shadow_stack + if (feature_1 & GNU_PROPERTY_RISCV_FEATURE_1_CFI_SS) + l->l_riscv_feature_1_and |= GNU_PROPERTY_RISCV_FEATURE_1_CFI_SS; +#endif + } + /* Continue. */ + return 1; +} + +#endif /* _DL_PROP_H */ diff --git a/sysdeps/riscv/libc-start.h b/sysdeps/riscv/libc-start.h new file mode 100644 index 0000000000..91d094cfb5 --- /dev/null +++ b/sysdeps/riscv/libc-start.h @@ -0,0 +1,88 @@ +/* RISC-V libc main startup. + Copyright (C) 2026 Free Software Foundation, Inc. + This file is part of the GNU C Library. + + The GNU C Library is free software; you can redistribute it and/or + modify it under the terms of the GNU Lesser General Public + License as published by the Free Software Foundation; either + version 2.1 of the License, or (at your option) any later version. + + The GNU C Library is distributed in the hope that it will be useful, + but WITHOUT ANY WARRANTY; without even the implied warranty of + MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU + Lesser General Public License for more details. + + You should have received a copy of the GNU Lesser General Public + License along with the GNU C Library; if not, see + . */ + +#ifndef SHARED +# define ARCH_SETUP_IREL() apply_irel () +# define ARCH_APPLY_IREL() + +# if defined(__riscv_landing_pad) || defined(__riscv_shadow_stack) +/* Get shadow stack features enabled in the static executable. */ +# include +# include +extern void _dl_cfi_setup_features (unsigned int); + +static inline unsigned int +get_cfi_feature (void) +{ + unsigned int cfi_feature = 0; + /* FIXME: check if cfi feature is supported by CPU */ + struct link_map *main_map = _dl_get_dl_main_map (); + + /* Scan program headers backward to check PT_GNU_PROPERTY early for + feature bits on static executable. */ + const ElfW(Phdr) *phdr = GL(dl_phdr); + const ElfW(Phdr) *ph; + for (ph = phdr + GL(dl_phnum); ph != phdr; ph--) + if (ph[-1].p_type == PT_GNU_PROPERTY) + { + _dl_process_pt_gnu_property (main_map, -1, &ph[-1]); + /* Enable landing pad and shstk only if they are enabled on a static + executable. */ + /* FIXME: change to &= to mask off other features after cpu_feature + is implemented */ + cfi_feature = (main_map->l_riscv_feature_1_and + & (GNU_PROPERTY_RISCV_FEATURE_1_CFI_LP_UNLABELED + | GNU_PROPERTY_RISCV_FEATURE_1_CFI_SS)); + + GL(dl_riscv_feature_1) = cfi_feature; + return cfi_feature; + } + GL(dl_riscv_feature_1) = 0; + return 0; +} + +/* The function using this macro to enable shadow stack must not return + to avoid shadow stack underflow. */ +# ifdef __riscv_shadow_stack +# define ENABLE_RISCV_SHADOW_STACK \ + do \ + { \ + if (feature & GNU_PROPERTY_RISCV_FEATURE_1_CFI_SS) \ + { \ + INTERNAL_SYSCALL_CALL (prctl, PR_SET_SHADOW_STACK_STATUS, \ + PR_SHADOW_STACK_ENABLE, 0, 0, 0); \ + } \ + } \ + while (0) +# else +# define ENABLE_RISCV_SHADOW_STACK +# endif + +# define ARCH_SETUP_TLS() \ + { \ + __libc_setup_tls (); \ + \ + unsigned int feature = get_cfi_feature (); \ + ENABLE_RISCV_SHADOW_STACK; \ + /* Landing pad will be enabled in _dl_cfi_setup_features */ \ + _dl_cfi_setup_features(feature); \ + } +# else +# define ARCH_SETUP_TLS() __libc_setup_tls () +# endif /* __riscv_landing_pad || __riscv_shadow_stack */ +#endif /* !SHARED */ diff --git a/sysdeps/unix/sysv/linux/riscv/dl-cfi.h b/sysdeps/unix/sysv/linux/riscv/dl-cfi.h new file mode 100644 index 0000000000..86ba6eaafb --- /dev/null +++ b/sysdeps/unix/sysv/linux/riscv/dl-cfi.h @@ -0,0 +1,20 @@ +/* Linux/RISC-V CFI initializers function. + Copyright (C) 2026 Free Software Foundation, Inc. + + The GNU C Library is free software; you can redistribute it and/or + modify it under the terms of the GNU Lesser General Public + License as published by the Free Software Foundation; either + version 2.1 of the License, or (at your option) any later version. + + The GNU C Library is distributed in the hope that it will be useful, + but WITHOUT ANY WARRANTY; without even the implied warranty of + MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU + Lesser General Public License for more details. + + You should have received a copy of the GNU Lesser General Public + License along with the GNU C Library; if not, see + . */ + +/* FIXME: Should be remove after they are included in the kernel header */ +#include +#include From patchwork Sun Jun 28 07:02:33 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Jesse Huang X-Patchwork-Id: 137969 Return-Path: X-Original-To: patchwork@sourceware.org Delivered-To: patchwork@sourceware.org Received: from vm01.sourceware.org (localhost [IPv6:::1]) by sourceware.org (Postfix) with ESMTP id 277C34BA2E39 for ; Sun, 28 Jun 2026 07:07:42 +0000 (GMT) DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org 277C34BA2E39 Authentication-Results: sourceware.org; dkim=pass (2048-bit key, unprotected) header.d=sifive.com header.i=@sifive.com header.a=rsa-sha256 header.s=google header.b=TPL89Vf0 X-Original-To: libc-alpha@sourceware.org Delivered-To: libc-alpha@sourceware.org Received: from mail-dy1-x132e.google.com (mail-dy1-x132e.google.com [IPv6:2607:f8b0:4864:20::132e]) by sourceware.org (Postfix) with ESMTPS id CB1EC4BA23E2 for ; Sun, 28 Jun 2026 07:02:59 +0000 (GMT) DMARC-Filter: OpenDMARC Filter v1.4.2 sourceware.org CB1EC4BA23E2 Authentication-Results: sourceware.org; dmarc=pass (p=reject dis=none) header.from=sifive.com Authentication-Results: sourceware.org; spf=pass smtp.mailfrom=sifive.com ARC-Filter: OpenARC Filter v1.0.0 sourceware.org CB1EC4BA23E2 Authentication-Results: sourceware.org; arc=none smtp.remote-ip=2607:f8b0:4864:20::132e ARC-Seal: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1782630180; cv=none; b=DSiIUpX/oJIwTCOpxceJLZZnN+UK2aB8Nl8f8dSGpYo1NCF0wnNktBiIdKw3T82LNRtBjxLnyCEphOqfrzoxsJ/6rRxeKjvzAZzQPr5WgxFF17y/btG8+/msR1oC3OdhCvgR35IhXPfDprmE6UfDaH11SJNc/OxrLc0OLE7Uvw4= ARC-Message-Signature: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1782630180; c=relaxed/simple; bh=xPPmjqEcM39cOh7Hu1YvAeMkZTSMR5JDcNDH7xflxUA=; h=DKIM-Signature:From:To:Subject:Date:Message-Id:MIME-Version; b=uSvlPsu5nIaw5RB60d1XHypmScjuPMXD1z0RXxKxRD1K7re8n/VEoSeaatyds4t8z5blyJKl5rwpQgXEYpkJlvdVHT8m/DB3vsXuG4hK3WTia6H5iW+C2z01dctbeyPL8XqDizRBU3Y4iqmpx/G/EoPA8Fi7YyeAkiqMfGiCF/Q= ARC-Authentication-Results: i=1; sourceware.org; dkim=pass (2048-bit key, unprotected) header.d=sifive.com header.i=@sifive.com header.a=rsa-sha256 header.s=google header.b=TPL89Vf0 DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org CB1EC4BA23E2 Received: by mail-dy1-x132e.google.com with SMTP id 5a478bee46e88-30e18c3e0b8so810308eec.0 for ; Sun, 28 Jun 2026 00:02:59 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=sifive.com; s=google; t=1782630179; x=1783234979; darn=sourceware.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to; bh=rL0SUl5l3h2tF/tKzf3Zh3Pf2OVs+rR2u8FLX++Gmqs=; b=TPL89Vf0BVjCYRHsYXO8ZryOQHUE1UDB0be88w9ncnhiZT08pxfh7PRZUTVawVAwb3 m375TbtmNVuuaNcIVz3WqDndEXEm5mHlqtG7xDLSn15acZfYdMuoN2jOB/mBtEiE8mEw xATggvXhSt1zzo+FEkZrgL5m5+Di1uNwlB4bsxlCS9BXEe50mqF3TFpR6s4TJW+lcL7r u96kyYeRlA8QElA7yCmMWxl6egNFyibmwIemNfoWPa69RCVUl5pz+0EJO4oTpoXw2tpM uFwKfWFtjvgFJ/0VbOIMp0idQ/u+iNzbmexqaUJ2oXCLDnDZ2uaSpFw3MgbhwgfJO85l m68w== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1782630179; x=1783234979; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to; bh=rL0SUl5l3h2tF/tKzf3Zh3Pf2OVs+rR2u8FLX++Gmqs=; b=Ihepwp208U5QTsfiIcTVDglrPELrOzzMR0a20Ol3+BVXRivLdD7SuMLOlIDUxZrO2G YgBy6TkHuynC/7Pex368kwetgV2MuINnLrBwDNg7qLeyL48D9Sf51QjVCo1R0he9sCPr +cgpgWEu6KwOV/mXrer9/rc9/nkvgxQWSYmfIReaYO6rgRV61C5WsuppR/OU/J+1M1sU JG1bs3adj6u6mfEZheoR/GEGqwX6k1vEYihLEbuvpJSCfJ1Kjqjp8hqzJ52x95u5oPcs YxXBKr4gv7nSnD29wPEmMEVVRw4BJJTt5P7p5zXhmfJ7a9Akcx8Ubh9sqj6wDJc8T0YM +RVw== X-Gm-Message-State: AOJu0YwNx1xeDa8ev2KJxSh35ctCTdvz45WWaF3mioFACyNDGVirak1y L8ou+zqRLudhqLxYmDIZCdjkONcE1O7ltcj6hAzPZR6oliXyF8y1dIDSc69mpLYYjU3YJWgF0+r aMRHCsIrWHbvI8rUBSxsz+dAFwq4rxfUUvN29lm345QVxo53Hczz+8qUr31MuPvSxBEFjBq/d7S vvxxTNkYh17Qjztwfm0DuYg0XsPbu86FvBdedFOzeRcfXENiK96cU= X-Gm-Gg: AfdE7cm0OHnwsSWguHveinJyawflkuKxcp2N3g0ceeWZ715xQki1hHFYByRrmioRe0P DU4bvwIIMUR2wCpnvXr59XtCgsKpSi0QnGOBvll2lwDxKKMpP/ZsyNHoc3e9jJdFmg2Lcjx2ioE QrwC2ZcgMgGxAGfumbb4xIzkXVmWIYlRhcduQYqYmD7W4ZrdHbECHupBfJyb1k6rFnDsku1+s7l Lw7U5QkbgGacM6Wd3NLOwB+138yp+XVJmMJ3FXGfHQ/IDW6LY+ZeT3b4ILwtCVSbuxDx2GTun76 Jdm8K9KmI7lVoKjG6t6CTIB3rbF0EfsXWIJr6KVQMY8iAtSWaHccakzhU0yjH6rpJsUNq3x/O3G 2Qp0TIgoRnPL+85eoAkZy+FyOvqEgQVQYsfd+OZ5YrBmSrRRCV55PAOZCBSsWwDjO5PVqbPyN7w EiOEw26eiuPK38/GQsz7YwcZ5qnMZVLA== X-Received: by 2002:a05:693c:2284:b0:30c:553d:81af with SMTP id 5a478bee46e88-30c85009a8bmr11367380eec.27.1782630178517; Sun, 28 Jun 2026 00:02:58 -0700 (PDT) Received: from sw08.internal.sifive.com ([4.53.31.132]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-30c7c8afc91sm35435166eec.14.2026.06.28.00.02.57 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 28 Jun 2026 00:02:58 -0700 (PDT) From: Jesse Huang To: libc-alpha@sourceware.org Cc: andrew@sifive.com, darius@bluespec.com, debug@rivosinc.com, jeffreyalaw@gmail.com, kito.cheng@sifive.com, palmer@dabbelt.com, schwab@suse.de, Jesse Huang Subject: [PATCH v5 08/16] riscv/cfi: Enable CFI on dynamic binaries Date: Sun, 28 Jun 2026 00:02:33 -0700 Message-Id: <20260628070241.88310-9-jesse.huang@sifive.com> X-Mailer: git-send-email 2.39.3 In-Reply-To: <20260628070241.88310-1-jesse.huang@sifive.com> References: <20260628070241.88310-1-jesse.huang@sifive.com> MIME-Version: 1.0 X-Spam-Status: No, score=-13.2 required=5.0 tests=BAYES_00, DKIM_SIGNED, DKIM_VALID, DKIM_VALID_AU, DKIM_VALID_EF, GIT_PATCH_0, RCVD_IN_DNSWL_NONE, SPF_HELO_NONE, SPF_PASS, TXREP shortcircuit=no autolearn=ham autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on sourceware.org X-BeenThere: libc-alpha@sourceware.org X-Mailman-Version: 2.1.30 Precedence: list List-Id: Libc-alpha mailing list List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: libc-alpha-bounces~patchwork=sourceware.org@sourceware.org For dynamic binaries, CFI features are parsed from GNU properties, stored in GLRO(dl_riscv_feature_1), and later enabled in RTLD_START. Co-authored-by: Deepak Gupta --- sysdeps/riscv/Makefile | 2 +- sysdeps/riscv/dl-cfi.c | 72 ++++++++++++++++++++++++++ sysdeps/riscv/dl-machine.h | 2 + sysdeps/riscv/dl-prop.h | 9 ++++ sysdeps/riscv/features-offsets.sym | 5 ++ sysdeps/unix/sysv/linux/riscv/dl-cfi.h | 30 +++++++++++ 6 files changed, 119 insertions(+), 1 deletion(-) create mode 100644 sysdeps/riscv/features-offsets.sym diff --git a/sysdeps/riscv/Makefile b/sysdeps/riscv/Makefile index 4752bdb1a0..11e48be02e 100644 --- a/sysdeps/riscv/Makefile +++ b/sysdeps/riscv/Makefile @@ -3,7 +3,7 @@ sysdep_headers += sys/asm.h endif ifeq ($(subdir),elf) -gen-as-const-headers += dl-link.sym +gen-as-const-headers += dl-link.sym features-offsets.sym endif # RISC-V's assembler also needs to know about PIC as it changes the definition diff --git a/sysdeps/riscv/dl-cfi.c b/sysdeps/riscv/dl-cfi.c index 216e8f12c0..74aa8b89ce 100644 --- a/sysdeps/riscv/dl-cfi.c +++ b/sysdeps/riscv/dl-cfi.c @@ -22,6 +22,54 @@ #include #include +static void +dl_check_legacy_object (struct link_map *m, unsigned int *feature_1) +{ + /* Iterate through the dependencies and disable if needed here */ + struct link_map *l = NULL; + unsigned int i; + i = m->l_searchlist.r_nlist; + while (i-- > 0) + { + /* Check each shared object to see if shadow stack and landing pad + are enabled. */ + l = m->l_initfini[i]; + + if (l->l_init_called) + continue; + +#ifdef SHARED + /* Skip check for ld.so since it has the features enabled. The + features will be disabled later if they are not enabled in + executable. */ + if (l == &GL(dl_rtld_map) + || l->l_real == &GL(dl_rtld_map)) + continue; +#endif /* SHARED */ + + *feature_1 &= l->l_riscv_feature_1_and; + } +} + +#ifdef SHARED +static void +dl_cfi_check_startup (struct link_map *m, unsigned int *feature_1) +{ + /* FIXME: Add tunables here */ + if (!*feature_1) + return; + dl_check_legacy_object (m, feature_1); + + /* Update GL(dl_riscv_feature_1) */ + GL(dl_riscv_feature_1) = *feature_1; +} +#endif /* SHARED */ + +static void +dl_cfi_check_dlopen (struct link_map *m) +{ +} + attribute_hidden void _dl_cfi_setup_features (unsigned int feature_1) { @@ -34,3 +82,27 @@ _dl_cfi_setup_features (unsigned int feature_1) #endif /* __riscv_landing_pad */ /* FIXME: Read enabled features from kernel and re-sync */ } + +/* Enable CFI for l and its dependencies. */ +void +_dl_cfi_check (struct link_map *l, const char *program) +{ + /* As this point we have parsed the gnu properties, + for dynamic binary we should verify the dependencies here. */ + /* FIXME: Implement different policy for supporting legacy binaries */ + unsigned int feature_1; +#if defined SHARED && defined RTLD_START_ENABLE_RISCV_CFI + if (program) + { + GL(dl_riscv_feature_1) = l->l_riscv_feature_1_and; + feature_1 = l->l_riscv_feature_1_and; + } +#endif /* SHARED */ + +#ifdef SHARED + if (program) + dl_cfi_check_startup (l, &feature_1); + else +#endif /* SHARED */ + dl_cfi_check_dlopen (l); +} diff --git a/sysdeps/riscv/dl-machine.h b/sysdeps/riscv/dl-machine.h index b7b9959d58..b64e7e67d8 100644 --- a/sysdeps/riscv/dl-machine.h +++ b/sysdeps/riscv/dl-machine.h @@ -121,6 +121,8 @@ elf_machine_dynamic (void) " _RTLD_PROLOGUE (_dl_start_user) "\ # Stash user entry point in s0.\n\ mv s0, a0\n\ + # Setup CFI features\n\ + " RTLD_START_ENABLE_RISCV_CFI "\ # Load the adjusted argument count.\n\ " STRINGXP (REG_L) " a1, 0(sp)\n\ # Call _dl_init (struct link_map *main_map, int argc, char **argv, char **env) \n\ diff --git a/sysdeps/riscv/dl-prop.h b/sysdeps/riscv/dl-prop.h index a183d3148a..f6cbf4c59c 100644 --- a/sysdeps/riscv/dl-prop.h +++ b/sysdeps/riscv/dl-prop.h @@ -19,14 +19,23 @@ #ifndef _DL_PROP_H #define _DL_PROP_H +extern void _dl_cfi_check (struct link_map *, const char *) + attribute_hidden; + static inline void __attribute__ ((always_inline)) _rtld_main_check (struct link_map *m, const char *program) { +#if defined(__riscv_landing_pad) || defined(__riscv_shadow_stack) + _dl_cfi_check(m, program); +#endif /* __riscv_landing_pad || __riscv_shadow_stack */ } static inline void __attribute__ ((always_inline)) _dl_open_check (struct link_map *m, int dl_openmode) { +#if defined(__riscv_landing_pad) || defined(__riscv_shadow_stack) + _dl_cfi_check(m, NULL); +#endif /* __riscv_landing_pad || __riscv_shadow_stack */ } static inline void __attribute__ ((always_inline)) diff --git a/sysdeps/riscv/features-offsets.sym b/sysdeps/riscv/features-offsets.sym new file mode 100644 index 0000000000..3320cde83f --- /dev/null +++ b/sysdeps/riscv/features-offsets.sym @@ -0,0 +1,5 @@ +#define SHARED 1 + +#include + +RTLD_GLOBAL_DL_RISCV_FEATURE_1_OFFSET offsetof (struct rtld_global, _dl_riscv_feature_1) diff --git a/sysdeps/unix/sysv/linux/riscv/dl-cfi.h b/sysdeps/unix/sysv/linux/riscv/dl-cfi.h index 86ba6eaafb..53df470930 100644 --- a/sysdeps/unix/sysv/linux/riscv/dl-cfi.h +++ b/sysdeps/unix/sysv/linux/riscv/dl-cfi.h @@ -18,3 +18,33 @@ /* FIXME: Should be remove after they are included in the kernel header */ #include #include +#include + +#ifdef __riscv_shadow_stack +# define CHECK_AND_ENABLE_SHADOW_STACK \ +"\ + andi a0, s1, " STRINGXP (GNU_PROPERTY_RISCV_FEATURE_1_CFI_SS) "\n\ + beqz a0, 1f \n\ + li a0, " STRINGXP (PR_SET_SHADOW_STACK_STATUS) "\n\ + li a1, " STRINGXP (PR_SHADOW_STACK_ENABLE) "\n\ + li a2, 0 \n\ + li a3, 0 \n\ + li a4, 0 \n\ + li a7, " STRINGXP (__NR_prctl) "\n\ + ecall \n\ +1: \n\ +" +#else +# define CHECK_AND_ENABLE_SHADOW_STACK +#endif + +#define RTLD_START_ENABLE_RISCV_CFI \ +"\ + lw s1, _rtld_local + " STRINGXP (RTLD_GLOBAL_DL_RISCV_FEATURE_1_OFFSET) " \n\ + # We need to enable shadow stack in the assembly code to avoid underflow \n\ + # Checking for landing pad is left to _dl_cfi_setup_features \n\ + " CHECK_AND_ENABLE_SHADOW_STACK "\n\ + mv a0, s1 \n\ + jal _dl_cfi_setup_features \n\ + \n\ +" From patchwork Sun Jun 28 07:02:34 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Jesse Huang X-Patchwork-Id: 137961 Return-Path: X-Original-To: patchwork@sourceware.org Delivered-To: patchwork@sourceware.org Received: from vm01.sourceware.org (localhost [IPv6:::1]) by sourceware.org (Postfix) with ESMTP id DF9FC4BA2E2F for ; Sun, 28 Jun 2026 07:04:05 +0000 (GMT) DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org DF9FC4BA2E2F Authentication-Results: sourceware.org; dkim=pass (2048-bit key, unprotected) header.d=sifive.com header.i=@sifive.com header.a=rsa-sha256 header.s=google header.b=fHGj3hr4 X-Original-To: libc-alpha@sourceware.org Delivered-To: libc-alpha@sourceware.org Received: from mail-dy1-x1334.google.com (mail-dy1-x1334.google.com [IPv6:2607:f8b0:4864:20::1334]) by sourceware.org (Postfix) with ESMTPS id 1BA054BA23C5 for ; Sun, 28 Jun 2026 07:03:01 +0000 (GMT) DMARC-Filter: OpenDMARC Filter v1.4.2 sourceware.org 1BA054BA23C5 Authentication-Results: sourceware.org; dmarc=pass (p=reject dis=none) header.from=sifive.com Authentication-Results: sourceware.org; spf=pass smtp.mailfrom=sifive.com ARC-Filter: OpenARC Filter v1.0.0 sourceware.org 1BA054BA23C5 Authentication-Results: sourceware.org; arc=none smtp.remote-ip=2607:f8b0:4864:20::1334 ARC-Seal: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1782630181; cv=none; b=aTLvOHMzJzFkOHKpHBFzUYP6+07R+7H+PLabyDNrhqGrt5mN5pY2lOp74OA4ZVz5cT+eyJiA57y4n+g9F8k9Ro9rg6NfA5vv6M6fZINkNEhaq6BGvUhwsn+NaEw+vBW1fof2T2wE76rBSL2oowjcTblhM71MbWQeAlpq83S9IAY= ARC-Message-Signature: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1782630181; c=relaxed/simple; bh=NvM1rOeRsBkwbqjeYYgm5c/C2oTRwKlCsm2TNr30/us=; h=DKIM-Signature:From:To:Subject:Date:Message-Id:MIME-Version; b=K7+Z9sjz1qSGRsTGeMmHJgtIYRaiFPTjO2Y6dJW32QCpjTwFfPAhm/55i1jbhNAcFzVTxNffQMp8DtArWqIcq+JtfmuR0PnIhfHuWwD5Np2FvGZTouYOEkNLj/EevcNNW+ercq7fEbuzcRADmvzalcbkhbSTaW+OWCE7ET0tqjc= ARC-Authentication-Results: i=1; sourceware.org; dkim=pass (2048-bit key, unprotected) header.d=sifive.com header.i=@sifive.com header.a=rsa-sha256 header.s=google header.b=fHGj3hr4 DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org 1BA054BA23C5 Received: by mail-dy1-x1334.google.com with SMTP id 5a478bee46e88-30ec3dfbcd1so222069eec.0 for ; Sun, 28 Jun 2026 00:03:01 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=sifive.com; s=google; t=1782630180; x=1783234980; darn=sourceware.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to; bh=EpSoYHczfjN9jl+VPhIOJ6YR1tbfKHryjwthbGmV7VI=; b=fHGj3hr4eSJohlixNTAwx1MuNzFg+b4cyE/wo6Mjm1VIg9VG1r3uJ29zQmc9YHUewU 4bq2Ogp98ZKODWcU9+YeaDYDNWXTNhx/TnQZ6LB2id5RoyGg/EBVk9j83+1lP4oGzOHA A+ExRLtoywnzB4F8DKKwc0rlD7QNUwGW6LmyYW7rhLV7DIAxY6/wPt9qEywdm1SJt56/ byvqYpBua9LGmrcjyZTaMRaJCy1y3eiiSzd7asHm53YITfbXkjFEPsfPPsW6cYkIexj3 YRqB63pjMxpS/nJ7ewzQU8pL2TYu+RCMerB+poOrK7JQHAEEyguplhepm6DFeatFDWYG rk2w== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1782630180; x=1783234980; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to; bh=EpSoYHczfjN9jl+VPhIOJ6YR1tbfKHryjwthbGmV7VI=; b=ZDTiocBojR/5ofD9zvk9FHcZo3GPT3stWn5YVOW92n62o/FW7Y+JiDTcQoBL2gbNFY h18Y3oFTBZkVf5wtoZiuBoeFQL1ydrlUgn+8MoTIQ3cfAYzNqdn0ncCY4qU4S0W5k672 tiDfYMsFbL4pei2iXJyOEcEsDFivFgXddJatQ1R9cSfSNS8LtQArCn7YT8getAkLcaWy +nS0gMv/kbKQZq4OXJufj/rKsYQhqc3ZoQNA/nQnvF30wW8wogzWDzPVG1jx2aIg9hUi F24k+C6W30RSGoo3Cy0iYacXv5CX6R99ReeiddW3UPR1/onPr+lZzPbLAX3w68yjr7cr CNTg== X-Gm-Message-State: AOJu0YwiJ6Qydq8YNbMNyf65dThdlrzCqEhTb6dP7DqNA08Esu5F0Hxs sMPXpvWp0l+jKcqgtBxf2KI445MDIvVAVhLa/GdNobLlRXOwfQCt4bVkzODd8hlgUcY0rnjHie/ oL6L2IQn61kEGYXrESXTDOG46QKgaZlcKiS/THnkltLKWLVH92LgAMqUTRtWUyKH1nZSz+NtQCk kU4v/sQZJnO8exeZ2eLaI9VHn4W/mlEUDMk+WtVQ9IVDyPJmRG0W4= X-Gm-Gg: AfdE7cnCAD43X+EfwruW6WEdybOhSpJKJeeFVAImxC1bQNR15u0eqr/tMdOsNaFI7+8 k4mB+3eXUqIcHGK2M6E0MlfmIgqAwv9jamMTMvFu7PcJJ7lGA1UvUNH/YQZcTp741szHBo9qQgu jcN4vGOxfupi6bRU2U4pOPD4mtDe6U1KcskNdo6HAazGr/4J2o+IbFmCIulM8h2Dnj15ydipiVq 3vZ9I5j/+yOw6sBXHb3Yg6X2ZTyzda8/yIRk2EaEJsv1NLgmHjeyg5rNQu0G8fxwJ/f4WF5BDG1 wjSUQB0fbayEShU+Idvg2tSeEgrZuknaH3/xtuAmzVdGIw0Obh6dNFByTJPSSzz7nIGUEvqz3ax +QYeVtbg6gYZo5TSu+4I02xBZ6GxE/2Fk3ToxUvsSnx85xh7ySDQHEcBNx//zEc2mbYR02O72xX H+cWl5EaGVDZoRAnqFpmLDa+HeYJioxg== X-Received: by 2002:a05:693c:2d92:b0:30c:ab4d:3828 with SMTP id 5a478bee46e88-30cab4d3e4emr5263039eec.42.1782630179632; Sun, 28 Jun 2026 00:02:59 -0700 (PDT) Received: from sw08.internal.sifive.com ([4.53.31.132]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-30c7c8afc91sm35435166eec.14.2026.06.28.00.02.58 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 28 Jun 2026 00:02:59 -0700 (PDT) From: Jesse Huang To: libc-alpha@sourceware.org Cc: andrew@sifive.com, darius@bluespec.com, debug@rivosinc.com, jeffreyalaw@gmail.com, kito.cheng@sifive.com, palmer@dabbelt.com, schwab@suse.de, Jesse Huang Subject: [PATCH v5 09/16] riscv/cfi: Introduce tunables for CFI features Date: Sun, 28 Jun 2026 00:02:34 -0700 Message-Id: <20260628070241.88310-10-jesse.huang@sifive.com> X-Mailer: git-send-email 2.39.3 In-Reply-To: <20260628070241.88310-1-jesse.huang@sifive.com> References: <20260628070241.88310-1-jesse.huang@sifive.com> MIME-Version: 1.0 X-Spam-Status: No, score=-13.2 required=5.0 tests=BAYES_00, DKIM_SIGNED, DKIM_VALID, DKIM_VALID_AU, DKIM_VALID_EF, GIT_PATCH_0, KAM_SHORT, RCVD_IN_DNSWL_NONE, SPF_HELO_NONE, SPF_PASS, TXREP shortcircuit=no autolearn=ham autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on sourceware.org X-BeenThere: libc-alpha@sourceware.org X-Mailman-Version: 2.1.30 Precedence: list List-Id: Libc-alpha mailing list List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: libc-alpha-bounces~patchwork=sourceware.org@sourceware.org dl_riscv_feature_control is a structure whose members represent feature configurations. It is currently used only by CFI features. Each CFI feature is a 2-bit enum with values [on|off|permissive]. These values decide whether a newly loaded legacy object should be blocked when loaded dynamically, and can be controlled by glibc tunables. --- manual/tunables.texi | 22 +++ sysdeps/riscv/Makefile | 1 + sysdeps/riscv/cpu-features.c | 46 ++++++ sysdeps/riscv/cpu-tunables.c | 50 +++++++ sysdeps/riscv/dl-cfi.c | 223 ++++++++++++++++++++++++++-- sysdeps/riscv/dl-get-cpu-features.c | 27 ++++ sysdeps/riscv/dl-machine.h | 19 +++ sysdeps/riscv/dl-procruntime.c | 17 +++ sysdeps/riscv/dl-tunables.list | 27 ++++ sysdeps/riscv/feature-control.h | 42 ++++++ sysdeps/riscv/ldsodefs.h | 1 + sysdeps/riscv/libc-start.c | 31 ++++ sysdeps/riscv/libc-start.h | 13 +- 13 files changed, 500 insertions(+), 19 deletions(-) create mode 100644 sysdeps/riscv/cpu-features.c create mode 100644 sysdeps/riscv/cpu-tunables.c create mode 100644 sysdeps/riscv/dl-get-cpu-features.c create mode 100644 sysdeps/riscv/dl-tunables.list create mode 100644 sysdeps/riscv/feature-control.h create mode 100644 sysdeps/riscv/libc-start.c diff --git a/manual/tunables.texi b/manual/tunables.texi index e1d9fbae9c..6b95a75335 100644 --- a/manual/tunables.texi +++ b/manual/tunables.texi @@ -479,6 +479,28 @@ assume that the CPU is @code{xxx} where xxx may have one of these values: This tunable is specific to aarch64. @end deftp +@deftp Tunable glibc.cpu.riscv_cfi_lp +The @code{glibc.cpu.riscv_cfi_lp=[on|off|permissive]} tunable allows the +user to temporarily turn off branch control flow protection (a.k.a. +landing pad) or set it to permissive mode. The default value is @code{on} +for targets compiled with the Zicfilp extension. Permissive mode allows +the protection to be turned off for programs that dynamically load legacy +shared libraries without landing pad support. + +This tunable is specific to RISC-V. +@end deftp + +@deftp Tunable glibc.cpu.riscv_cfi_ss +The @code{glibc.cpu.riscv_cfi_ss=[on|off|permissive]} tunable allows the +user to temporarily turn off return control flow protection (a.k.a. +shadow stack) or set it to permissive mode. The default value is @code{on} +for targets compiled with the Zicfiss extension. Permissive mode allows +the protection to be turned off for programs that dynamically load legacy +shared libraries without shadow stack support. + +This tunable is specific to RISC-V. +@end deftp + @deftp Tunable glibc.cpu.x86_data_cache_size The @code{glibc.cpu.x86_data_cache_size} tunable allows the user to set data cache size in bytes for use in memory and string routines. diff --git a/sysdeps/riscv/Makefile b/sysdeps/riscv/Makefile index 11e48be02e..b1f074a3eb 100644 --- a/sysdeps/riscv/Makefile +++ b/sysdeps/riscv/Makefile @@ -1,6 +1,7 @@ ifeq ($(subdir),misc) sysdep_headers += sys/asm.h endif +sysdep-dl-routines += dl-get-cpu-features ifeq ($(subdir),elf) gen-as-const-headers += dl-link.sym features-offsets.sym diff --git a/sysdeps/riscv/cpu-features.c b/sysdeps/riscv/cpu-features.c new file mode 100644 index 0000000000..aed8e9062b --- /dev/null +++ b/sysdeps/riscv/cpu-features.c @@ -0,0 +1,46 @@ +/* Initialize CPU feature data. + This file is part of the GNU C Library. + Copyright (C) 2026 Free Software Foundation, Inc. + + The GNU C Library is free software; you can redistribute it and/or + modify it under the terms of the GNU Lesser General Public + License as published by the Free Software Foundation; either + version 2.1 of the License, or (at your option) any later version. + + The GNU C Library is distributed in the hope that it will be useful, + but WITHOUT ANY WARRANTY; without even the implied warranty of + MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU + Lesser General Public License for more details. + + You should have received a copy of the GNU Lesser General Public + License along with the GNU C Library; if not, see + . */ + +#ifndef _CPU_FEATURES_RISCV_H +#define _CPU_FEATURES_RISCV_H + +# define TUNABLE_NAMESPACE cpu +# include + +# ifdef __riscv_landing_pad +extern void TUNABLE_CALLBACK (set_riscv_cfi_lp) (tunable_val_t *) + attribute_hidden; +# endif +# ifdef __riscv_shadow_stack +extern void TUNABLE_CALLBACK (set_riscv_cfi_ss) (tunable_val_t *) + attribute_hidden; +# endif + +static inline void +init_cpu_features (void) +{ +# ifdef __riscv_landing_pad + TUNABLE_GET (riscv_cfi_lp, tunable_val_t *, + TUNABLE_CALLBACK (set_riscv_cfi_lp)); +# endif +# ifdef __riscv_shadow_stack + TUNABLE_GET (riscv_cfi_ss, tunable_val_t *, + TUNABLE_CALLBACK (set_riscv_cfi_ss)); +# endif +} +#endif /* _CPU_FEATURES_RISCV_H */ diff --git a/sysdeps/riscv/cpu-tunables.c b/sysdeps/riscv/cpu-tunables.c new file mode 100644 index 0000000000..84ef911866 --- /dev/null +++ b/sysdeps/riscv/cpu-tunables.c @@ -0,0 +1,50 @@ +/* RISC-V CPU feature tuning. + This file is part of the GNU C Library. + Copyright (C) 2026 Free Software Foundation, Inc. + + The GNU C Library is free software; you can redistribute it and/or + modify it under the terms of the GNU Lesser General Public + License as published by the Free Software Foundation; either + version 2.1 of the License, or (at your option) any later version. + + The GNU C Library is distributed in the hope that it will be useful, + but WITHOUT ANY WARRANTY; without even the implied warranty of + MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU + Lesser General Public License for more details. + + You should have received a copy of the GNU Lesser General Public + License along with the GNU C Library; if not, see + . */ + +#define TUNABLE_NAMESPACE cpu +#include +#include +#include + +#ifdef __riscv_landing_pad +attribute_hidden +void +TUNABLE_CALLBACK (set_riscv_cfi_lp) (tunable_val_t *valp) +{ + if (tunable_strcmp_cte (valp, "permissive")) + GL(dl_riscv_feature_control).lp = cfi_permissive; + else if (tunable_strcmp_cte (valp, "off")) + GL(dl_riscv_feature_control).lp = cfi_always_off; + else + GL(dl_riscv_feature_control).lp = cfi_always_on; +} +#endif + +#ifdef __riscv_shadow_stack +attribute_hidden +void +TUNABLE_CALLBACK (set_riscv_cfi_ss) (tunable_val_t *valp) +{ + if (tunable_strcmp_cte (valp, "permissive")) + GL(dl_riscv_feature_control).ss = cfi_permissive; + else if (tunable_strcmp_cte (valp, "off")) + GL(dl_riscv_feature_control).ss = cfi_always_off; + else + GL(dl_riscv_feature_control).ss = cfi_always_on; +} +#endif diff --git a/sysdeps/riscv/dl-cfi.c b/sysdeps/riscv/dl-cfi.c index 74aa8b89ce..4723cde096 100644 --- a/sysdeps/riscv/dl-cfi.c +++ b/sysdeps/riscv/dl-cfi.c @@ -15,6 +15,7 @@ License along with the GNU C Library; if not, see . */ +#include "feature-control.h" #include #include #include @@ -22,8 +23,39 @@ #include #include +struct dl_cfi_info +{ + const char *program; + + /* Check how lp and ss should be enabled. */ +#ifdef __riscv_landing_pad + enum dl_riscv_cfi_control enable_lp_type; +#endif +#ifdef __riscv_shadow_stack + enum dl_riscv_cfi_control enable_ss_type; +#endif + + /* Previously enabled features. */ + unsigned int feature_1_enabled; + + /* Features that should be enabled. */ + unsigned int enable_feature_1; + + /* If there are any legacy shared object. */ + unsigned int feature_1_legacy; + + /* Which shared object is the first legacy shared object. */ +#ifdef __riscv_landing_pad + unsigned int feature_1_legacy_lp; +#endif +#ifdef __riscv_shadow_stack + unsigned int feature_1_legacy_ss; +#endif +}; + + static void -dl_check_legacy_object (struct link_map *m, unsigned int *feature_1) +dl_check_legacy_object (struct link_map *m, struct dl_cfi_info *info) { /* Iterate through the dependencies and disable if needed here */ struct link_map *l = NULL; @@ -42,32 +74,150 @@ dl_check_legacy_object (struct link_map *m, unsigned int *feature_1) /* Skip check for ld.so since it has the features enabled. The features will be disabled later if they are not enabled in executable. */ - if (l == &GL(dl_rtld_map) - || l->l_real == &GL(dl_rtld_map)) + if (is_rtld_link_map (l) + || is_rtld_link_map (l->l_real) + || (info->program != NULL && l == m)) continue; #endif /* SHARED */ - *feature_1 &= l->l_riscv_feature_1_and; + info->enable_feature_1 &= ((l->l_riscv_feature_1_and + & (GNU_PROPERTY_RISCV_FEATURE_1_CFI_LP_UNLABELED + | GNU_PROPERTY_RISCV_FEATURE_1_CFI_SS)) + | ~(GNU_PROPERTY_RISCV_FEATURE_1_CFI_LP_UNLABELED + | GNU_PROPERTY_RISCV_FEATURE_1_CFI_SS)); + + /* Bookkeeping legacy objects */ +#ifdef __riscv_landing_pad + if ((info->feature_1_legacy & GNU_PROPERTY_RISCV_FEATURE_1_CFI_LP_UNLABELED) == 0 + && ((info->enable_feature_1 & GNU_PROPERTY_RISCV_FEATURE_1_CFI_LP_UNLABELED) + != (info->feature_1_enabled & GNU_PROPERTY_RISCV_FEATURE_1_CFI_LP_UNLABELED)) + ) + { + info->feature_1_legacy_lp = i; + info->feature_1_legacy |= GNU_PROPERTY_RISCV_FEATURE_1_CFI_LP_UNLABELED; + } +#endif +#ifdef __riscv_shadow_stack + if ((info->feature_1_legacy & GNU_PROPERTY_RISCV_FEATURE_1_CFI_SS) == 0 + && ((info->enable_feature_1 & GNU_PROPERTY_RISCV_FEATURE_1_CFI_SS) + != (info->feature_1_enabled & GNU_PROPERTY_RISCV_FEATURE_1_CFI_SS)) + ) + { + info->feature_1_legacy_ss = i; + info->feature_1_legacy |= GNU_PROPERTY_RISCV_FEATURE_1_CFI_SS; + } +#endif } + + /* Keep bits set if cfi_always_on */ +#ifdef __riscv_landing_pad + if ((info->feature_1_enabled & GNU_PROPERTY_RISCV_FEATURE_1_CFI_LP_UNLABELED) != 0 + && info->enable_lp_type == cfi_always_on) + { + info->enable_feature_1 |= GNU_PROPERTY_RISCV_FEATURE_1_CFI_LP_UNLABELED; + } +#endif +#ifdef __riscv_shadow_stack + if ((info->feature_1_enabled & GNU_PROPERTY_RISCV_FEATURE_1_CFI_SS) != 0 + && info->enable_ss_type == cfi_always_on) + { + info->enable_feature_1 |= GNU_PROPERTY_RISCV_FEATURE_1_CFI_SS; + } +#endif } #ifdef SHARED static void -dl_cfi_check_startup (struct link_map *m, unsigned int *feature_1) +dl_cfi_check_startup (struct link_map *m, struct dl_cfi_info *info) { - /* FIXME: Add tunables here */ - if (!*feature_1) - return; - dl_check_legacy_object (m, feature_1); +# ifdef __riscv_landing_pad + if (info->enable_lp_type == cfi_always_on) + info->enable_feature_1 |= GNU_PROPERTY_RISCV_FEATURE_1_CFI_LP_UNLABELED; + else if (info->enable_lp_type == cfi_always_off) + info->enable_feature_1 &= ~GNU_PROPERTY_RISCV_FEATURE_1_CFI_LP_UNLABELED; + else + info->enable_feature_1 &= ((m->l_riscv_feature_1_and + & GNU_PROPERTY_RISCV_FEATURE_1_CFI_LP_UNLABELED) + | ~GNU_PROPERTY_RISCV_FEATURE_1_CFI_LP_UNLABELED); +# endif +# ifdef __riscv_shadow_stack + if (info->enable_ss_type == cfi_always_on) + info->enable_feature_1 |= GNU_PROPERTY_RISCV_FEATURE_1_CFI_SS; + else if (info->enable_ss_type == cfi_always_off) + info->enable_feature_1 &= ~GNU_PROPERTY_RISCV_FEATURE_1_CFI_SS; + else + info->enable_feature_1 &= ((m->l_riscv_feature_1_and + & GNU_PROPERTY_RISCV_FEATURE_1_CFI_SS) + | ~GNU_PROPERTY_RISCV_FEATURE_1_CFI_SS); +# endif + + if (info->enable_feature_1 != 0) + dl_check_legacy_object (m, info); /* Update GL(dl_riscv_feature_1) */ - GL(dl_riscv_feature_1) = *feature_1; + if (info->enable_feature_1 ^ info->feature_1_enabled) { + info->feature_1_enabled = info->enable_feature_1; + GL(dl_riscv_feature_1) = info->enable_feature_1; + } } #endif /* SHARED */ static void -dl_cfi_check_dlopen (struct link_map *m) +dl_cfi_check_dlopen (struct link_map *m, struct dl_cfi_info *info) { + if (info->enable_feature_1 != 0) { + dl_check_legacy_object(m, info); + + if (info->feature_1_legacy == 0) + return; + } + + unsigned int disable_feature_1 = 0; + unsigned int legacy_obj = 0; + const char *msg = NULL; + +#ifdef __riscv_landing_pad + if ((info->feature_1_enabled & GNU_PROPERTY_RISCV_FEATURE_1_CFI_LP_UNLABELED) != 0 + && (info->feature_1_legacy & GNU_PROPERTY_RISCV_FEATURE_1_CFI_LP_UNLABELED) != 0) + { + if (info->enable_lp_type != cfi_permissive || !SINGLE_THREAD_P) + { + legacy_obj = info->feature_1_legacy_lp; + msg = N_("rebuild shared object with landing pad support"); + } + else + disable_feature_1 |= GNU_PROPERTY_RISCV_FEATURE_1_CFI_LP_UNLABELED; + } +#endif + +#ifdef __riscv_shadow_stack + if ((info->feature_1_enabled & GNU_PROPERTY_RISCV_FEATURE_1_CFI_SS) != 0 + && (info->feature_1_legacy & GNU_PROPERTY_RISCV_FEATURE_1_CFI_SS) != 0) + { + if (info->enable_ss_type != cfi_permissive || !SINGLE_THREAD_P) + { + legacy_obj = info->feature_1_legacy_ss; + msg = N_("rebuild shared object with shadow stack support"); + } + else + disable_feature_1 |= GNU_PROPERTY_RISCV_FEATURE_1_CFI_SS; + } +#endif + + if (msg != NULL) + _dl_signal_error (0, m->l_initfini[legacy_obj]->l_name, "dlopen", msg); + + if (disable_feature_1 != 0) + // FIXME: Disable CFI here + int res = -1; + if (res) + { + msg = N_("can't disable CFI feature"); + _dl_signal_error (-res, m->l_initfini[legacy_obj]->l_name, + "dlopen", msg); + } + GL(dl_riscv_feature_1) &= ~disable_feature_1; + } } attribute_hidden void @@ -89,20 +239,61 @@ _dl_cfi_check (struct link_map *l, const char *program) { /* As this point we have parsed the gnu properties, for dynamic binary we should verify the dependencies here. */ - /* FIXME: Implement different policy for supporting legacy binaries */ - unsigned int feature_1; + struct dl_cfi_info info; #if defined SHARED && defined RTLD_START_ENABLE_RISCV_CFI if (program) { GL(dl_riscv_feature_1) = l->l_riscv_feature_1_and; - feature_1 = l->l_riscv_feature_1_and; } #endif /* SHARED */ + unsigned int supported_exts = 0; + unsigned int always_on_exts = 0; + +#ifdef __riscv_landing_pad + info.enable_lp_type = GL(dl_riscv_feature_control).lp; + supported_exts += 1; + always_on_exts += (info.enable_lp_type == cfi_always_on); +#endif +#ifdef __riscv_shadow_stack + info.enable_ss_type = GL(dl_riscv_feature_control).ss; + supported_exts += 1; + always_on_exts += (info.enable_ss_type == cfi_always_on); +#endif + + info.feature_1_enabled = GL(dl_riscv_feature_1); + + /* No legacy check needed if all cfi exts are always on in main */ + if (program && (supported_exts == always_on_exts)) + return; + + /* No legacy check needed if all cfi exts are off */ + if (info.feature_1_enabled == 0) + return; + + info.program = program; + + info.enable_feature_1 = 0; +#ifdef __riscv_landing_pad + if (info.enable_lp_type != cfi_always_off) + info.enable_feature_1 |= (info.feature_1_enabled + & GNU_PROPERTY_RISCV_FEATURE_1_CFI_LP_UNLABELED); + info.feature_1_legacy_lp = 0; +#endif +#ifdef __riscv_shadow_stack + if (info.enable_ss_type != cfi_always_off) + info.enable_feature_1 |= (info.feature_1_enabled + & GNU_PROPERTY_RISCV_FEATURE_1_CFI_SS); + info.feature_1_legacy_ss = 0; +#endif + + info.feature_1_enabled = GL(dl_riscv_feature_1); + info.feature_1_legacy = 0; + #ifdef SHARED if (program) - dl_cfi_check_startup (l, &feature_1); + dl_cfi_check_startup (l, &info); else #endif /* SHARED */ - dl_cfi_check_dlopen (l); + dl_cfi_check_dlopen (l, &info); } diff --git a/sysdeps/riscv/dl-get-cpu-features.c b/sysdeps/riscv/dl-get-cpu-features.c new file mode 100644 index 0000000000..bdb805d417 --- /dev/null +++ b/sysdeps/riscv/dl-get-cpu-features.c @@ -0,0 +1,27 @@ +/* Initialize CPU feature data. + Copyright (C) 2026 Free Software Foundation, Inc. + + The GNU C Library is free software; you can redistribute it and/or + modify it under the terms of the GNU Lesser General Public + License as published by the Free Software Foundation; either + version 2.1 of the License, or (at your option) any later version. + + The GNU C Library is distributed in the hope that it will be useful, + but WITHOUT ANY WARRANTY; without even the implied warranty of + MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU + Lesser General Public License for more details. + + You should have received a copy of the GNU Lesser General Public + License along with the GNU C Library; if not, see + . */ + +#include + +#ifdef SHARED +# include +void +_dl_riscv_init_cpu_features (void) +{ + init_cpu_features (); +} +#endif diff --git a/sysdeps/riscv/dl-machine.h b/sysdeps/riscv/dl-machine.h index b64e7e67d8..01422e01d9 100644 --- a/sysdeps/riscv/dl-machine.h +++ b/sysdeps/riscv/dl-machine.h @@ -41,6 +41,7 @@ extern void _dl_cfi_setup_features (unsigned int features); #else # define SET_LPAD #endif +extern void _dl_riscv_init_cpu_features (void); #ifndef _RTLD_PROLOGUE # define _RTLD_PROLOGUE(entry) \ @@ -153,6 +154,24 @@ elf_machine_dynamic (void) #define ARCH_LA_PLTENTER riscv_gnu_pltenter #define ARCH_LA_PLTEXIT riscv_gnu_pltexit +/* We define an initialization function. This is called very early in + _dl_sysdep_start. */ +#define DL_PLATFORM_INIT dl_platform_init () + +static inline void __attribute__ ((unused)) +dl_platform_init (void) +{ + if (GLRO(dl_platform) != NULL && *GLRO(dl_platform) == '\0') + /* Avoid an empty string which would disturb us. */ + GLRO(dl_platform) = NULL; + +#ifdef SHARED + /* init_cpu_features which has been called early from __libc_start_main in + static executable. */ + _dl_riscv_init_cpu_features (); +#endif +} + /* Bias .got.plt entry by the offset requested by the PLT header. */ #define elf_machine_plt_value(map, reloc, value) (value) diff --git a/sysdeps/riscv/dl-procruntime.c b/sysdeps/riscv/dl-procruntime.c index 06a582920e..c35473a961 100644 --- a/sysdeps/riscv/dl-procruntime.c +++ b/sysdeps/riscv/dl-procruntime.c @@ -57,4 +57,21 @@ PROCINFO_CLASS unsigned int _dl_riscv_feature_1 # else , # endif + +# if !defined PROCINFO_DECL && defined SHARED + ._dl_riscv_feature_control +# else +PROCINFO_CLASS struct dl_riscv_feature_control _dl_riscv_feature_control +# endif +# ifndef PROCINFO_DECL += { + .lp = cfi_always_on, + .ss = cfi_always_on, + } +# endif +# if !defined SHARED || defined PROCINFO_DECL +; +# else +, +# endif #endif diff --git a/sysdeps/riscv/dl-tunables.list b/sysdeps/riscv/dl-tunables.list new file mode 100644 index 0000000000..f301219c19 --- /dev/null +++ b/sysdeps/riscv/dl-tunables.list @@ -0,0 +1,27 @@ +# RISC-V specific tunables. +# Copyright (C) 2026 Free Software Foundation, Inc. +# This file is part of the GNU C Library. + +# The GNU C Library is free software; you can redistribute it and/or +# modify it under the terms of the GNU Lesser General Public +# License as published by the Free Software Foundation; either +# version 2.1 of the License, or (at your option) any later version. + +# The GNU C Library is distributed in the hope that it will be useful, +# but WITHOUT ANY WARRANTY; without even the implied warranty of +# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU +# Lesser General Public License for more details. + +# You should have received a copy of the GNU Lesser General Public +# License along with the GNU C Library; if not, see +# . + +glibc { + cpu { + riscv_cfi_lp { + type: STRING + } + riscv_cfi_ss { + type: STRING + } +} diff --git a/sysdeps/riscv/feature-control.h b/sysdeps/riscv/feature-control.h new file mode 100644 index 0000000000..9d24f4798b --- /dev/null +++ b/sysdeps/riscv/feature-control.h @@ -0,0 +1,42 @@ +/* RISC-V feature tuning. + This file is part of the GNU C Library. + Copyright (C) 2026 Free Software Foundation, Inc. + + The GNU C Library is free software; you can redistribute it and/or + modify it under the terms of the GNU Lesser General Public + License as published by the Free Software Foundation; either + version 2.1 of the License, or (at your option) any later version. + + The GNU C Library is distributed in the hope that it will be useful, + but WITHOUT ANY WARRANTY; without even the implied warranty of + MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU + Lesser General Public License for more details. + + You should have received a copy of the GNU Lesser General Public + License along with the GNU C Library; if not, see + . */ + +#ifndef _RISCV_FEATURE_CONTROL_H +#define _RISCV_FEATURE_CONTROL_H + +/* For each CFI feature, LP and SS, valid control values. */ +enum dl_riscv_cfi_control +{ + /* Enable CFI features based on ELF property note. */ + cfi_elf_property = 0, + /* Always enable CFI features. */ + cfi_always_on, + /* Always disable CFI features. */ + cfi_always_off, + /* Enable CFI features permissively. */ + cfi_permissive +}; + +struct dl_riscv_feature_control +{ + enum dl_riscv_cfi_control lp : 2; + enum dl_riscv_cfi_control ss : 2; +}; + +#endif /* feature-control.h */ + diff --git a/sysdeps/riscv/ldsodefs.h b/sysdeps/riscv/ldsodefs.h index 6a9422f13d..d1d3ebd131 100644 --- a/sysdeps/riscv/ldsodefs.h +++ b/sysdeps/riscv/ldsodefs.h @@ -20,6 +20,7 @@ #define _RISCV_LDSODEFS_H 1 #include +#include struct La_riscv_regs; struct La_riscv_retval; diff --git a/sysdeps/riscv/libc-start.c b/sysdeps/riscv/libc-start.c new file mode 100644 index 0000000000..2e00ce1b55 --- /dev/null +++ b/sysdeps/riscv/libc-start.c @@ -0,0 +1,31 @@ +/* Copyright (C) 2026 Free Software Foundation, Inc. + This file is part of the GNU C Library. + + The GNU C Library is free software; you can redistribute it and/or + modify it under the terms of the GNU Lesser General Public + License as published by the Free Software Foundation; either + version 2.1 of the License, or (at your option) any later version. + + The GNU C Library is distributed in the hope that it will be useful, + but WITHOUT ANY WARRANTY; without even the implied warranty of + MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU + Lesser General Public License for more details. + + You should have received a copy of the GNU Lesser General Public + License along with the GNU C Library; if not, see + . */ + +#ifndef SHARED + +/* Mark symbols hidden in static PIE for early self relocation to work. */ +# if BUILD_PIE_DEFAULT +# pragma GCC visibility push(hidden) +# endif +# include +# include + +# define ARCH_INIT_CPU_FEATURES() init_cpu_features () + +#endif /* !SHARED */ +#include + diff --git a/sysdeps/riscv/libc-start.h b/sysdeps/riscv/libc-start.h index 91d094cfb5..f873e1ee2e 100644 --- a/sysdeps/riscv/libc-start.h +++ b/sysdeps/riscv/libc-start.h @@ -31,6 +31,15 @@ get_cfi_feature (void) { unsigned int cfi_feature = 0; /* FIXME: check if cfi feature is supported by CPU */ + +#ifdef __riscv_landing_pad + if (GL(dl_riscv_feature_control).lp != cfi_always_off) + cfi_feature |= GNU_PROPERTY_RISCV_FEATURE_1_CFI_LP_UNLABELED; +#endif +#ifdef __riscv_shadow_stack + if (GL(dl_riscv_feature_control).ss != cfi_always_off) + cfi_feature |= GNU_PROPERTY_RISCV_FEATURE_1_CFI_SS; +#endif struct link_map *main_map = _dl_get_dl_main_map (); /* Scan program headers backward to check PT_GNU_PROPERTY early for @@ -43,9 +52,7 @@ get_cfi_feature (void) _dl_process_pt_gnu_property (main_map, -1, &ph[-1]); /* Enable landing pad and shstk only if they are enabled on a static executable. */ - /* FIXME: change to &= to mask off other features after cpu_feature - is implemented */ - cfi_feature = (main_map->l_riscv_feature_1_and + cfi_feature &= (main_map->l_riscv_feature_1_and & (GNU_PROPERTY_RISCV_FEATURE_1_CFI_LP_UNLABELED | GNU_PROPERTY_RISCV_FEATURE_1_CFI_SS)); From patchwork Sun Jun 28 07:02:35 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Jesse Huang X-Patchwork-Id: 137965 Return-Path: X-Original-To: patchwork@sourceware.org Delivered-To: patchwork@sourceware.org Received: from vm01.sourceware.org (localhost [IPv6:::1]) by sourceware.org (Postfix) with ESMTP id 6B6904BA23C9 for ; Sun, 28 Jun 2026 07:05:49 +0000 (GMT) DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org 6B6904BA23C9 Authentication-Results: sourceware.org; dkim=pass (2048-bit key, unprotected) header.d=sifive.com header.i=@sifive.com header.a=rsa-sha256 header.s=google header.b=dSmMaB3z X-Original-To: libc-alpha@sourceware.org Delivered-To: libc-alpha@sourceware.org Received: from mail-dl1-x122c.google.com (mail-dl1-x122c.google.com [IPv6:2607:f8b0:4864:20::122c]) by sourceware.org (Postfix) with ESMTPS id 745C14BA23D2 for ; Sun, 28 Jun 2026 07:03:02 +0000 (GMT) DMARC-Filter: OpenDMARC Filter v1.4.2 sourceware.org 745C14BA23D2 Authentication-Results: sourceware.org; dmarc=pass (p=reject dis=none) header.from=sifive.com Authentication-Results: sourceware.org; spf=pass smtp.mailfrom=sifive.com ARC-Filter: OpenARC Filter v1.0.0 sourceware.org 745C14BA23D2 Authentication-Results: sourceware.org; arc=none smtp.remote-ip=2607:f8b0:4864:20::122c ARC-Seal: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1782630182; cv=none; b=BHj77bhc4if5uHnt7KG8PboME9iFB6Mkjyc0O3UWfsc9GIaLxLOgfXwwDVWFyCEAMplJMqZhEdFVnv5YwhXI3BIRPxh5upT24DgZsNFoHvQG1M1EOmTDEUH3ygpdUEMO6NAHHUqBc9ae4v4fckZlBmju5F2mdeu3O/YlouRaAsk= ARC-Message-Signature: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1782630182; c=relaxed/simple; bh=P+s6AbTxwWXY1ixPDOvona1AFt+B7rHjSGH7F6f+cak=; h=DKIM-Signature:From:To:Subject:Date:Message-Id:MIME-Version; b=qM7dFdDbPHhIezZs0f0nHYmkXXSu91EvQw5XOKmN1K5ZiXjRHa+b/lbEghhu2rMhunmqjmYcpCvz7e+qN5UuPI5m+cMXgISJeNF7g4ENWOQ8m5GKL7CiLbc1t68x7XKgUEYC4bZWpYpg3iS9DPvDRl7ABmmX63mYcFOe/pSsLic= ARC-Authentication-Results: i=1; sourceware.org; dkim=pass (2048-bit key, unprotected) header.d=sifive.com header.i=@sifive.com header.a=rsa-sha256 header.s=google header.b=dSmMaB3z DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org 745C14BA23D2 Received: by mail-dl1-x122c.google.com with SMTP id a92af1059eb24-13810b63a1aso5403361c88.1 for ; Sun, 28 Jun 2026 00:03:02 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=sifive.com; s=google; t=1782630181; x=1783234981; darn=sourceware.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to; bh=yxP/b++u3YipNlwEtsSFfmFRwBmhNlSE4BreTYZR2cs=; b=dSmMaB3zPGxUHqZaBPVp/2YXC9nS0eA67uAyfxA9x1YwajQiyaSHl3JJPls9Unm8Zg MxnRYUupqsHpeArhoKxYjGeVR0NrN8QHdz4CUq82zwOBfxUhINSMZIEEHrD+ZMyDrpcZ MIAPggawS4O+50fwovSLZQ1xOTd6xa2UX/6n+iGrDWipOHQpkNQr5xb3ELzjcp2oM/F/ yQfpSN1A+BBDwE705Jh4eEV/OdxU8woOeaZxcD20fCY16O57+JwKwoFTN9FUpAiSX6EQ X6KReT4O6D9zaMq5B9p7+k2ugl5ljJvi/LjteTmHZSbd4sF88ch5iYE0rkDsAjKgs2Ab C8sw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1782630181; x=1783234981; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to; bh=yxP/b++u3YipNlwEtsSFfmFRwBmhNlSE4BreTYZR2cs=; b=QXgwT02xhgwyjH+/mlS29vFlwPwKyuKjotuU1InqSW1BL0QIWplaoneVlquk8S08gw k3Gx07ZlbJoIa97ik1OBUkIViTK61Tlb3zWZTzjtQzZnzwbILfETYZEMUek2L8/AeVUn T6I9o2lVqtFC5xeSTOhyVcayxRF5idpEX/cuLZvE6ihg+VyJrObPsgQQCTO6vGVtL1mS Wt2tmPsvV5HbewAkFxn0E2e1u7iaqPoeO1FppFFKl9eXoc7jkpSnswchpu7I87FeJS3i fG0KXXjSpRGrBZFjz70ZHZ7I63l36CX+6dbXimXIb4Ct8uhYJ3WMRz8OX4R3uBtHXlGc JW3A== X-Gm-Message-State: AOJu0Yz9xAbtOBDOxoHJNCaG3zRyeU4mkQy3lFbMfsRx5P/XmnXo9rPF gMNfy63pg/lsCX2EeDXpE1e3y8EZUwTGoV/0Kq1/sTOlX8B77KECU/ysLgSnYEDiWk4Ecmg1cLf 5gcgLQvKverjUBobtck9GOz55GeoO6BdKT4eSgGGQ+Oz0scXvZ3XZE2hA7ARKeAecB1k3jQSyCt eF3ZAemBHGirZK/s9gYdfIgiuhY5tBuUbFs1mly3M7mu6eLSP/lrY= X-Gm-Gg: AfdE7cm12Uu+3OBesWK0HxZH0HMI3C2S9yeA37e1/pl0dP4TQfnzzSUwR4LskXHQjZF Y1cN858K0D6CVpfQHa05Az24KHvnx0YkHKWm6u/7DewzLT3Hrr12VE6tnmqAB1Y+b2Yry9RTjng hUb9QN8uT6s/kq5bM+Nr27bMDNZOcGjq4QoHJcTJtpsgMtoJNpFDszvUBK9dupEeEWGT0I4Q346 AOcwGs9eUJtJjt5/VmQvu/QsD9QZM5gE6sSIQL9T+Gl8SigCpn6bmI47OB95bdsiYKJfjh6cGCb UvJOlhtnPSB45VLabl3vUpH8MrXP9R+emhjaWFABPf//mX5AE/h/4R5iN6qjUmcXUb3LnG38izS 9Fi6bJ5PBjzAnKNovGFF7/diX5f0pzBIK+Fbmk1seWDYmw7JMbZbQfAqO9cNWavvyTc+SBD5dZI MybriG7fBeFIeq68StiIZtY8N0bsuzVIrhMUHFNsml X-Received: by 2002:a05:693c:3944:b0:30b:c502:23df with SMTP id 5a478bee46e88-30cab081836mr6054010eec.13.1782630181169; Sun, 28 Jun 2026 00:03:01 -0700 (PDT) Received: from sw08.internal.sifive.com ([4.53.31.132]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-30c7c8afc91sm35435166eec.14.2026.06.28.00.02.59 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 28 Jun 2026 00:03:00 -0700 (PDT) From: Jesse Huang To: libc-alpha@sourceware.org Cc: andrew@sifive.com, darius@bluespec.com, debug@rivosinc.com, jeffreyalaw@gmail.com, kito.cheng@sifive.com, palmer@dabbelt.com, schwab@suse.de, Jesse Huang Subject: [PATCH v5 10/16] riscv/cfi: Adjust setjmp/longjmp for shadow stack to work Date: Sun, 28 Jun 2026 00:02:35 -0700 Message-Id: <20260628070241.88310-11-jesse.huang@sifive.com> X-Mailer: git-send-email 2.39.3 In-Reply-To: <20260628070241.88310-1-jesse.huang@sifive.com> References: <20260628070241.88310-1-jesse.huang@sifive.com> MIME-Version: 1.0 X-Spam-Status: No, score=-13.2 required=5.0 tests=BAYES_00, DKIM_SIGNED, DKIM_VALID, DKIM_VALID_AU, DKIM_VALID_EF, GIT_PATCH_0, KAM_SHORT, RCVD_IN_DNSWL_NONE, SPF_HELO_NONE, SPF_PASS, TXREP shortcircuit=no autolearn=ham autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on sourceware.org X-BeenThere: libc-alpha@sourceware.org X-Mailman-Version: 2.1.30 Precedence: list List-Id: Libc-alpha mailing list List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: libc-alpha-bounces~patchwork=sourceware.org@sourceware.org Since longjmp to a previous setjmp state can change the stack frame and involves stack frame unwinding, the shadow stack is also required to be unwound. The unwinding is implemented according to the Zicfiss specification by increasing the SSP by at most one page size (4K), to avoid accidentally pointing to another legal shadow stack page after the adjustment. The shadow stack pointer is stored in a wrapped sigset_t. By defining it inside a union, we can avoid changing the size of sigset_t and therefore jmp_buf. --- sysdeps/riscv/Makefile | 4 + sysdeps/riscv/__longjmp.S | 54 +++++++++++++ sysdeps/riscv/setjmp.S | 22 ++++++ sysdeps/unix/sysv/linux/riscv/jmp_buf-ssp.sym | 7 ++ sysdeps/unix/sysv/linux/riscv/setjmpP.h | 78 +++++++++++++++++++ 5 files changed, 165 insertions(+) create mode 100644 sysdeps/unix/sysv/linux/riscv/jmp_buf-ssp.sym create mode 100644 sysdeps/unix/sysv/linux/riscv/setjmpP.h diff --git a/sysdeps/riscv/Makefile b/sysdeps/riscv/Makefile index b1f074a3eb..94e224615c 100644 --- a/sysdeps/riscv/Makefile +++ b/sysdeps/riscv/Makefile @@ -11,6 +11,10 @@ endif # of some assembler macros. ASFLAGS-.os += $(pic-ccflag) +ifeq ($(subdir),setjmp) +gen-as-const-headers += jmp_buf-ssp.sym +endif + ifeq (no,$(riscv-r-align)) ASFLAGS-.os += -Wa,-mno-relax ASFLAGS-.o += -Wa,-mno-relax diff --git a/sysdeps/riscv/__longjmp.S b/sysdeps/riscv/__longjmp.S index bea854199c..8ee0662b81 100644 --- a/sysdeps/riscv/__longjmp.S +++ b/sysdeps/riscv/__longjmp.S @@ -18,9 +18,12 @@ #include #include +#include +#include ENTRY (__longjmp) REG_L ra, 0*SZREG(a0) + REG_L t1, 0*SZREG(a0) REG_L s0, 1*SZREG(a0) REG_L s1, 2*SZREG(a0) REG_L s2, 3*SZREG(a0) @@ -50,8 +53,59 @@ ENTRY (__longjmp) FREG_L fs11,14*SZREG+11*SZFREG(a0) #endif +#ifdef __riscv_shadow_stack + /* skip unwinding if ss is not enabled */ + ssrdp ra + beqz ra, .Lfin + REG_L t0, SSP_OFFSET(a0) + REG_L a0, SSP_BASE_OFFSET(a0) + REG_L t2, TLS_SSP_BASE_OFFSET(tp) + bne a0, t2, .Ldifferent_stack +.Lunwind: + bleu t0, ra, .Lfin + /* Increase ssp by at most one page size to ensure the adjustment + always runs into a guard page before accidentally pointing to + another legal shadow stack page */ + /* ra = (t0 - ra >= 4096) ? ra + 4096 : t0 */ + lui a0, 1 + add ra, ra, a0 + bleu ra, t0, 1f + mv ra, t0 +1: + csrw ssp, ra + /* Test if the location pointed by ssp is legal */ + sspush x5 + sspopchk x5 + j .Lunwind +.Ldifferent_stack: + /* Create restore token */ + sspush ra + mv a4, t0 + +.Lfind_rstor_token: + /* Probe and validate target restore token */ + ssamoswap.d a3, x0, (a4) + addi a2, a4, 8 + beq a3, a2, .Lswitch_stack + /* Restore the shadow stack and try the next slot */ + ssamoswap.d x0, a3, (a4) + addi a4, a4, -8 + j .Lfind_rstor_token + +.Lswitch_stack: + /* Switch stack: update ssp and base */ + csrw ssp, t0 + REG_S a0, TLS_SSP_BASE_OFFSET(tp) +.Lfin: +#endif seqz a0, a1 add a0, a0, a1 # a0 = (a1 == 0) ? 1 : a1 +#ifdef __riscv_landing_pad + /* Use indirect branch if CFI is enabled */ + jr t1 +#else + mv ra, t1 ret +#endif END (__longjmp) diff --git a/sysdeps/riscv/setjmp.S b/sysdeps/riscv/setjmp.S index af1910b86d..0406b23956 100644 --- a/sysdeps/riscv/setjmp.S +++ b/sysdeps/riscv/setjmp.S @@ -18,6 +18,8 @@ #include #include +#include +#include ENTRY (_setjmp) li a1, 0 @@ -58,6 +60,26 @@ ENTRY (__sigsetjmp) FREG_S fs11,14*SZREG+11*SZFREG(a0) #endif +#ifdef __riscv_shadow_stack + /* Skip if shadow stack is not enabled */ + ssrdp t0 + beqz t0, .Lfin + + /* Read ssp_base from TLS */ + REG_L t2, TLS_SSP_BASE_OFFSET(tp) + bnez t2, .Lbase_saved + + /* if not found, use current ssp as the marker */ + mv t2, t0 + REG_S t2, TLS_SSP_BASE_OFFSET(tp) + +.Lbase_saved: + /* Save caller's ssp and base marker to jmp_buf */ + REG_S t0, SSP_OFFSET(a0) + REG_S t2, SSP_BASE_OFFSET(a0) +.Lfin: +#endif + #if !IS_IN (libc) && IS_IN (rtld) /* In ld.so we never save the signal mask. */ li a0, 0 diff --git a/sysdeps/unix/sysv/linux/riscv/jmp_buf-ssp.sym b/sysdeps/unix/sysv/linux/riscv/jmp_buf-ssp.sym new file mode 100644 index 0000000000..bf944969f7 --- /dev/null +++ b/sysdeps/unix/sysv/linux/riscv/jmp_buf-ssp.sym @@ -0,0 +1,7 @@ +#include +#include +#undef __saved_mask + +-- +SSP_OFFSET offsetof(struct __jmp_buf_tag, __saved_mask.__saved.__ssp) +SSP_BASE_OFFSET offsetof(struct __jmp_buf_tag, __saved_mask.__saved.__ssp_base) diff --git a/sysdeps/unix/sysv/linux/riscv/setjmpP.h b/sysdeps/unix/sysv/linux/riscv/setjmpP.h new file mode 100644 index 0000000000..43cb28e2d1 --- /dev/null +++ b/sysdeps/unix/sysv/linux/riscv/setjmpP.h @@ -0,0 +1,78 @@ +/* Internal header file for . Linux/risc-v version. + Copyright (C) 2026 Free Software Foundation, Inc. + This file is part of the GNU C Library. + + The GNU C Library is free software; you can redistribute it and/or + modify it under the terms of the GNU Lesser General Public + License as published by the Free Software Foundation; either + version 2.1 of the License, or (at your option) any later version. + + The GNU C Library is distributed in the hope that it will be useful, + but WITHOUT ANY WARRANTY; without even the implied warranty of + MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU + Lesser General Public License for more details. + + You should have received a copy of the GNU Lesser General Public + License along with the GNU C Library; if not, see + . */ + +#ifndef _SETJMPP_H +#define _SETJMPP_H 1 + +#include +#include +#include + +/* Number of bits per long. */ +#define _JUMP_BUF_SIGSET_BITS_PER_WORD (8 * sizeof (unsigned long int)) +/* This holds the number of signals, 512 should be sufficient for future. + expansion */ +#define _JUMP_BUF_SIGSET_NSIG 512 +/* Number of longs to hold all signals. */ +#define _JUMP_BUF_SIGSET_NWORDS \ + (ALIGN_UP (_JUMP_BUF_SIGSET_NSIG, _JUMP_BUF_SIGSET_BITS_PER_WORD) \ + / _JUMP_BUF_SIGSET_BITS_PER_WORD) + +typedef struct + { + unsigned long int __val[_JUMP_BUF_SIGSET_NWORDS]; + } __jmp_buf_sigset_t; + +typedef union + { + __sigset_t __saved_mask_compat; + struct + { + __jmp_buf_sigset_t __saved_mask; + /* Used for shadow stack pointer. NB: Shadow stack pointer + must have the same alignment as __saved_mask. Otherwise + offset of __saved_mask will be changed. */ + unsigned long int __ssp; + unsigned long int __ssp_base; + } __saved; + } __jmpbuf_arch_t; + +/* has + + NB: We use setjmp in thread cancellation and this saves the shadow + stack register, but __libc_unwind_longjmp doesn't restore the shadow + stack register since cancellation never returns after longjmp. */ +#undef __sigset_t +#define __sigset_t __jmpbuf_arch_t +#include +#undef __saved_mask +#define __saved_mask __saved_mask.__saved.__saved_mask + +#include + +typedef struct + { + unsigned long int __val[__NSIG_WORDS]; + } __sigprocmask_sigset_t; + +extern jmp_buf ___buf; +extern __typeof (___buf[0].__saved_mask) ___saved_mask; +_Static_assert (sizeof (___saved_mask) >= sizeof (__sigprocmask_sigset_t), + "size of ___saved_mask < size of __sigprocmask_sigset_t"); + +#endif /* setjmpP.h */ From patchwork Sun Jun 28 07:02:36 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Jesse Huang X-Patchwork-Id: 137964 Return-Path: X-Original-To: patchwork@sourceware.org Delivered-To: patchwork@sourceware.org Received: from vm01.sourceware.org (localhost [IPv6:::1]) by sourceware.org (Postfix) with ESMTP id 5BC1C4BA23D7 for ; Sun, 28 Jun 2026 07:05:42 +0000 (GMT) DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org 5BC1C4BA23D7 Authentication-Results: sourceware.org; dkim=pass (2048-bit key, unprotected) header.d=sifive.com header.i=@sifive.com header.a=rsa-sha256 header.s=google header.b=lm5+VRN+ X-Original-To: libc-alpha@sourceware.org Delivered-To: libc-alpha@sourceware.org Received: from mail-dy1-x1334.google.com (mail-dy1-x1334.google.com [IPv6:2607:f8b0:4864:20::1334]) by sourceware.org (Postfix) with ESMTPS id 0F3224BA2E3C for ; Sun, 28 Jun 2026 07:03:04 +0000 (GMT) DMARC-Filter: OpenDMARC Filter v1.4.2 sourceware.org 0F3224BA2E3C Authentication-Results: sourceware.org; dmarc=pass (p=reject dis=none) header.from=sifive.com Authentication-Results: sourceware.org; spf=pass smtp.mailfrom=sifive.com ARC-Filter: OpenARC Filter v1.0.0 sourceware.org 0F3224BA2E3C Authentication-Results: sourceware.org; arc=none smtp.remote-ip=2607:f8b0:4864:20::1334 ARC-Seal: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1782630184; cv=none; b=kYo7mfmVlmfGSYIpXAlua9AxImcHVkZMjsVIsV+xlV9OwPKxGCwNONOVkW07pwr8b82Af8pvNzdSMqBWj2a67KzB5QBOZ4t/m7jQFUN1TXQQZ0wIw4MpfgPQJqLJm10ifXtl5GnSGMjgdhyM86L1wv9dYZpah7Eb8Wl/URuu+JQ= ARC-Message-Signature: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1782630184; c=relaxed/simple; bh=ZH0qysk/wMBsjxczG+JvOhF+ARiwW5NUuUhQGe9RZsk=; h=DKIM-Signature:From:To:Subject:Date:Message-Id:MIME-Version; b=Y5fjOQDQXpXwCyd0NcRJMTtGbhnaGZWnvYCffuiR1iMUnGw3S3ZXkQJWRbBClboIp1E/rbXiz6g76qp4ZrL1Ii98CB1NBTdn+ilMPqJGD+8fdiKYkNeSg1ZZBO4bRbPhC7leha4UKiNKEe2tn3Vs+DDcz9+qLM3zMLspUCvv+FI= ARC-Authentication-Results: i=1; sourceware.org; dkim=pass (2048-bit key, unprotected) header.d=sifive.com header.i=@sifive.com header.a=rsa-sha256 header.s=google header.b=lm5+VRN+ DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org 0F3224BA2E3C Received: by mail-dy1-x1334.google.com with SMTP id 5a478bee46e88-30e18c3e0b8so810329eec.0 for ; Sun, 28 Jun 2026 00:03:04 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=sifive.com; s=google; t=1782630183; x=1783234983; darn=sourceware.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to; bh=+IY5Z7biOoEgWfPCWm+uVcRPdbV+l8hVj+DTCjLwzpI=; b=lm5+VRN+qUahBFRAFFA6e+UBe1dY9AaQXLbjdgxkGC9wOGH0jikuSEr0/cEzP/Kswk r7oXM9Ay8bT+oW93LnZuSn4WHyixb/puN1WaL3BelsCMA+2uCgHDCZEWPq6BlNdfnbwF 32ZUTAcH8gllsTt4eujXtf++UeP7JaHVzr1ZbUPn4a5fRn1yqBB2HiX/e3VSoKBAasqN ZbshfUurbUw4Wx+RM7h/bPzW9Dl0k6pNAIOUsqzOyTVrqub5GlJ4t9+sAIIM/qIUg2wj bwkrSYAIBs/PKLiMNMbLo+6miaaP4iMiDvxXv7ojnfjB+cLlMgsvV13qKHZjuvyZcLSk YVMg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1782630183; x=1783234983; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to; bh=+IY5Z7biOoEgWfPCWm+uVcRPdbV+l8hVj+DTCjLwzpI=; b=OWK48/0wBmM7tX82hX3AxURbgSVhHmdPJPuMrE1s8HFKTxIy1IS38gxI1C4ODhd0hi ICJEoMGULTy8JQSQrEQknjX2RSZzBzsXwoo12PisSQELpSCEfPn/kPVDEfcxIz5sIm4p LdaNXfBs76w+LuP5V2sg6kVuLMASEvEWpMTmnWVLGyS1xCDJM/ReSIqy+oIjp0W4Zf27 dLsMSE9sZaEa0o8nxZ6uDRIKqdMcAulyTHFiuhlJvbKUhJsHFRBIAwnXuyxJXhuQ6ZuA st43ubt58u4phl9ttekbWoxlQ0sB0cYrd14upbKrK0X/VD4jihOgMkO9dIOlMprPzqD/ vQ+Q== X-Gm-Message-State: AOJu0Yxzc2kjIDaywP7SmNO1Bqeg04MDh/eQxIrDosyjBu/0R6yOkf04 +YYJuYyYzLHP8m9ri2OxoV2jvbFFj2D090XWFTOGa5M6DugPSIgZEKxmn2JlfYBncsB/y8JVPnG 0oz+sRlgFXz3W+fLHytX/YoQaqDnc9hpcOjGiS5oMmwi4AGa2fy8P724IZQjYPZiHyDU5Yi/kWt a/x+kix+mSUVXZVfepl6blqMS1rH+cDJ5SxMBPEGe0QuNrRolvLMo= X-Gm-Gg: AfdE7cl0lsHmkO84zpF0LHfe2sC6Jzi8L8OiFhCsWE2BJh29sigFI2mogdjt/oyDGSr 4mJbWXJW6h3qpfWc3PAjlhb4293zqpsuLJP/4zPLKmNXzZVv6K1RDx20y/++dp2glWdjkUTpXNj QXHGuscnG9ubfSCY5N2DacvaFBlApsegEuwSRdDCJEvqztiSa/053vy34CatodrsfufMNZ6bJZv TonpYog8bi9VQfIloEWDmyY7C3kyiBRlcTt0RbTcojclnkhWvOhHilGyy5JrAYpScnsDvnxhBPW BBl06wOpoSu9nyLLXAZ7cIc/hO/dXrcFm3bcOQ4CbzPiEQB/fa07LAenoF81xG3pHqXjSuztHdI jn/8iBmIsleemYL5wANMxoyUAriw8UvAVqvaz4qWuz24DVwaJLcO6mEuk2TaT9yVrKTK/Q4OwWT ttnPZ87w4fzYkWi6iAzECwGJ4m/Q/Y7g== X-Received: by 2002:a05:7301:3d17:b0:30c:ab4f:9b9c with SMTP id 5a478bee46e88-30cab4f9fdcmr5768180eec.36.1782630182725; Sun, 28 Jun 2026 00:03:02 -0700 (PDT) Received: from sw08.internal.sifive.com ([4.53.31.132]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-30c7c8afc91sm35435166eec.14.2026.06.28.00.03.01 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 28 Jun 2026 00:03:01 -0700 (PDT) From: Jesse Huang To: libc-alpha@sourceware.org Cc: andrew@sifive.com, darius@bluespec.com, debug@rivosinc.com, jeffreyalaw@gmail.com, kito.cheng@sifive.com, palmer@dabbelt.com, schwab@suse.de, Jesse Huang Subject: [PATCH v5 11/16] riscv/cfi: Support locking/disabling CFI and move OS dependent code Date: Sun, 28 Jun 2026 00:02:36 -0700 Message-Id: <20260628070241.88310-12-jesse.huang@sifive.com> X-Mailer: git-send-email 2.39.3 In-Reply-To: <20260628070241.88310-1-jesse.huang@sifive.com> References: <20260628070241.88310-1-jesse.huang@sifive.com> MIME-Version: 1.0 X-Spam-Status: No, score=-13.2 required=5.0 tests=BAYES_00, DKIM_SIGNED, DKIM_VALID, DKIM_VALID_AU, DKIM_VALID_EF, GIT_PATCH_0, RCVD_IN_DNSWL_NONE, SPF_HELO_NONE, SPF_PASS, TXREP shortcircuit=no autolearn=ham autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on sourceware.org X-BeenThere: libc-alpha@sourceware.org X-Mailman-Version: 2.1.30 Precedence: list List-Id: Libc-alpha mailing list List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: libc-alpha-bounces~patchwork=sourceware.org@sourceware.org --- sysdeps/riscv/dl-cfi.c | 40 +++++++++++----- sysdeps/unix/sysv/linux/riscv/dl-cfi.h | 66 ++++++++++++++++++++++++++ 2 files changed, 95 insertions(+), 11 deletions(-) diff --git a/sysdeps/riscv/dl-cfi.c b/sysdeps/riscv/dl-cfi.c index 4723cde096..27ac4cff10 100644 --- a/sysdeps/riscv/dl-cfi.c +++ b/sysdeps/riscv/dl-cfi.c @@ -57,7 +57,7 @@ struct dl_cfi_info static void dl_check_legacy_object (struct link_map *m, struct dl_cfi_info *info) { - /* Iterate through the dependencies and disable if needed here */ + /* Iterate through the dependencies and record legacy objects */ struct link_map *l = NULL; unsigned int i; i = m->l_searchlist.r_nlist; @@ -86,7 +86,11 @@ dl_check_legacy_object (struct link_map *m, struct dl_cfi_info *info) | ~(GNU_PROPERTY_RISCV_FEATURE_1_CFI_LP_UNLABELED | GNU_PROPERTY_RISCV_FEATURE_1_CFI_SS)); - /* Bookkeeping legacy objects */ + /* Bookkeeping first found mismatch object for both lp/ss. + These information would only be used by dlopen check for now. + A dependency with a feature on will be record as legacy if the task + did not enable the feature, however it is safe because the following + check will only be performed if the task has the feature on. */ #ifdef __riscv_landing_pad if ((info->feature_1_legacy & GNU_PROPERTY_RISCV_FEATURE_1_CFI_LP_UNLABELED) == 0 && ((info->enable_feature_1 & GNU_PROPERTY_RISCV_FEATURE_1_CFI_LP_UNLABELED) @@ -208,8 +212,8 @@ dl_cfi_check_dlopen (struct link_map *m, struct dl_cfi_info *info) _dl_signal_error (0, m->l_initfini[legacy_obj]->l_name, "dlopen", msg); if (disable_feature_1 != 0) - // FIXME: Disable CFI here - int res = -1; + { + int res = dl_cfi_disable_cfi (disable_feature_1); if (res) { msg = N_("can't disable CFI feature"); @@ -223,14 +227,29 @@ dl_cfi_check_dlopen (struct link_map *m, struct dl_cfi_info *info) attribute_hidden void _dl_cfi_setup_features (unsigned int feature_1) { - /* Since prctl could fail to enable some features - use prctl to get enabled features again and sync it back. */ + /* Enable features. Shadow stack is enabled earlier as it should + * be enabled in a function that never returns. */ +#ifdef __riscv_landing_pad + dl_cfi_enable_lp (feature_1); +#endif /* __riscv_landing_pad */ + + /* Since we could failed to enable some features, + get enabled features from system again and sync it back. */ + int status = dl_cfi_get_cfi_status (); + GL(dl_riscv_feature_1) = status | (GL(dl_riscv_feature_1) & + ~(GNU_PROPERTY_RISCV_FEATURE_1_CFI_SS + | GNU_PROPERTY_RISCV_FEATURE_1_CFI_LP_UNLABELED)); + + /* Lock features if set to always_on */ #ifdef __riscv_landing_pad - if (feature_1 & GNU_PROPERTY_RISCV_FEATURE_1_CFI_LP_UNLABELED) - INTERNAL_SYSCALL_CALL (prctl, PR_SET_CFI, PR_CFI_BRANCH_LANDING_PADS, - PR_CFI_ENABLE, 0, 0, 0); + if (GL(dl_riscv_feature_control).lp == cfi_always_on) + dl_cfi_lock_cfi (GNU_PROPERTY_RISCV_FEATURE_1_CFI_LP_UNLABELED); #endif /* __riscv_landing_pad */ - /* FIXME: Read enabled features from kernel and re-sync */ +#ifdef __riscv_shadow_stack + if (GL(dl_riscv_feature_control).ss == cfi_always_on) + dl_cfi_lock_cfi (GNU_PROPERTY_RISCV_FEATURE_1_CFI_SS); +#endif /* __riscv_shadow_stack */ + /* FIXME: Should we terminate if failed to lock under always on mode? */ } /* Enable CFI for l and its dependencies. */ @@ -287,7 +306,6 @@ _dl_cfi_check (struct link_map *l, const char *program) info.feature_1_legacy_ss = 0; #endif - info.feature_1_enabled = GL(dl_riscv_feature_1); info.feature_1_legacy = 0; #ifdef SHARED diff --git a/sysdeps/unix/sysv/linux/riscv/dl-cfi.h b/sysdeps/unix/sysv/linux/riscv/dl-cfi.h index 53df470930..6a547252fb 100644 --- a/sysdeps/unix/sysv/linux/riscv/dl-cfi.h +++ b/sysdeps/unix/sysv/linux/riscv/dl-cfi.h @@ -48,3 +48,69 @@ jal _dl_cfi_setup_features \n\ \n\ " + +static __always_inline int +dl_cfi_disable_cfi (unsigned int feature) { + int res = 0; +#ifdef __riscv_landing_pad + if (feature & GNU_PROPERTY_RISCV_FEATURE_1_CFI_LP_UNLABELED) + { + res = prctl (PR_SET_CFI, PR_CFI_BRANCH_LANDING_PADS, PR_CFI_DISABLE, 0, 0); + if (res) + return res; + } +#endif /* __riscv_landing_pad */ +#ifdef __riscv_shadow_stack + if (feature & GNU_PROPERTY_RISCV_FEATURE_1_CFI_SS) + { + res |= prctl (PR_SET_SHADOW_STACK_STATUS, 0, 0, 0, 0); + if (res) + return res; + } +#endif /* __riscv_shadow_stack */ + return 0; +} + +static __always_inline int +dl_cfi_lock_cfi (unsigned int feature) +{ + int res = 0; +#ifdef __riscv_landing_pad + if (feature & GNU_PROPERTY_RISCV_FEATURE_1_CFI_LP_UNLABELED) + res |= prctl (PR_SET_CFI, PR_CFI_BRANCH_LANDING_PADS, + PR_CFI_ENABLE | PR_CFI_LOCK, 0, 0); +#endif /* __riscv_landing_pad */ +#ifdef __riscv_shadow_stack + if (feature & GNU_PROPERTY_RISCV_FEATURE_1_CFI_SS) + res |= prctl (PR_LOCK_SHADOW_STACK_STATUS, 0, 0, 0, 0); +#endif /* __riscv_shadow_stack */ + return res; +} + +static __always_inline int +dl_cfi_get_cfi_status (void) { + int status = 0; + unsigned long buf = 0; + int ret = 0; +#ifdef __riscv_landing_pad + ret = prctl (PR_GET_CFI, PR_CFI_BRANCH_LANDING_PADS, &buf, 0, 0); + if (!ret && buf) + status |= GNU_PROPERTY_RISCV_FEATURE_1_CFI_LP_UNLABELED; +#endif /* __riscv_landing_pad */ +#ifdef __riscv_shadow_stack + ret = prctl (PR_GET_SHADOW_STACK_STATUS, &buf, 0, 0, 0); + if (!ret && buf) + status |= GNU_PROPERTY_RISCV_FEATURE_1_CFI_SS; +#endif /* __riscv_shadow_stack */ + return status; +} + +#ifdef __riscv_landing_pad +static __always_inline int +dl_cfi_enable_lp (unsigned int feature) { + if (!(feature & GNU_PROPERTY_RISCV_FEATURE_1_CFI_LP_UNLABELED)) + return -1; + return INTERNAL_SYSCALL_CALL (prctl, PR_SET_CFI, PR_CFI_BRANCH_LANDING_PADS, + PR_CFI_ENABLE, 0, 0); +} +#endif /* __riscv_landing_pad */ From patchwork Sun Jun 28 07:02:37 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Jesse Huang X-Patchwork-Id: 137970 Return-Path: X-Original-To: patchwork@sourceware.org Delivered-To: patchwork@sourceware.org Received: from vm01.sourceware.org (localhost [IPv6:::1]) by sourceware.org (Postfix) with ESMTP id 176444BA2E39 for ; Sun, 28 Jun 2026 07:08:23 +0000 (GMT) DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org 176444BA2E39 Authentication-Results: sourceware.org; dkim=pass (2048-bit key, unprotected) header.d=sifive.com header.i=@sifive.com header.a=rsa-sha256 header.s=google header.b=VTTFmdfE X-Original-To: libc-alpha@sourceware.org Delivered-To: libc-alpha@sourceware.org Received: from mail-dy1-x132c.google.com (mail-dy1-x132c.google.com [IPv6:2607:f8b0:4864:20::132c]) by sourceware.org (Postfix) with ESMTPS id 345FA4BA23E1 for ; Sun, 28 Jun 2026 07:03:05 +0000 (GMT) DMARC-Filter: OpenDMARC Filter v1.4.2 sourceware.org 345FA4BA23E1 Authentication-Results: sourceware.org; dmarc=pass (p=reject dis=none) header.from=sifive.com Authentication-Results: sourceware.org; spf=pass smtp.mailfrom=sifive.com ARC-Filter: OpenARC Filter v1.0.0 sourceware.org 345FA4BA23E1 Authentication-Results: sourceware.org; arc=none smtp.remote-ip=2607:f8b0:4864:20::132c ARC-Seal: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1782630185; cv=none; b=aHfSY2VuCS6cnCkNjic12JmdI7qB0/+y4v+0ZCv0fxM/c5brU9ipCA2+IGYCNldk3I7LP4gJiUxLJ77kgmS7R2WRFxr52CHjAR0xlw8klnB7U4qVnd5y4tEmDojbJw4O8Ap+lHGe7S44snnANsjY22MAQsFMWrbf/27ot4DGwDM= ARC-Message-Signature: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1782630185; c=relaxed/simple; bh=mNgEGZxP00REg3Jz1w+c9qrG3ZfmRFVldeizWrWwwgg=; h=DKIM-Signature:From:To:Subject:Date:Message-Id:MIME-Version; b=kYDnjNyJO2I1L6eESsJQKyw2cX0TjLqIayTWx4JrxjBnFzMC6qFwz29mT8k1nXTsfj+igIQdBZaBxIljTQR4vhKwWlK108H90Ls4wBS5Oovv1CzsH3bdBVAOVQCXPaOeETJENDO5YSgiUpwzDcKUX9CvEI+0IfEbdNJ6RekkHts= ARC-Authentication-Results: i=1; sourceware.org; dkim=pass (2048-bit key, unprotected) header.d=sifive.com header.i=@sifive.com header.a=rsa-sha256 header.s=google header.b=VTTFmdfE DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org 345FA4BA23E1 Received: by mail-dy1-x132c.google.com with SMTP id 5a478bee46e88-30c965eab27so3617912eec.0 for ; Sun, 28 Jun 2026 00:03:05 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=sifive.com; s=google; t=1782630184; x=1783234984; darn=sourceware.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to; bh=R0q+B1KWAKdgF00WUKtVQ7abzTRvsktMB1EgR6Z2iEY=; b=VTTFmdfEp7bTCFpK2XFzt2i1CytnORraCTpsIwBkxo6aMOHtOsRC8OQe8YebGN0+97 OfS7moUUPgK5ijuVQWefXAvy7nfbBpoZ07mE2kN7v+Y0cZw3ncSAmXRxUwBmrRqejh48 eEQwilaBp2GaT/n62i4I7kZynvqCtAeZzPsN2rv3ivBub3svZsHX2yq8ZEYD0bZqHEOc s5IyQZQqWpkSvfeRV29RdCf/q4oL7SxpFahPZYKpu6gZjYr3gJc+xuUtFCcMylusRFbW DC8Shps9i7XW4b1VYmmmTY29FhaW+c843yOb72URENpqj7ov+cp/KSJa9P5oYdfjI7BF KNZg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1782630184; x=1783234984; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to; bh=R0q+B1KWAKdgF00WUKtVQ7abzTRvsktMB1EgR6Z2iEY=; b=kd13nwhGTggdV6kszFVWyiWfaMrH8vWDfgOljGvTAfw7bEPOQTcZ9V0Z+N13NIUvbd cp76Do4HuYieDFPK87BfUsY5tFfES5gPEoECYrOlJKn5xc5McchAZpoq+S5owk0pzcrQ c6dHfDcuYul0hH1TZ3mOMUKgqegAwiN28IkEGdRsh51iMmYi3SFdYEHe8SM/X0yfVaCX mQyDFOV0DybPw9q0L/hqTeZIDmDEOjRCFKxrUB6AsNzz9i/yqMpasKmxhB9YVBrrrFOT B7kcY7I+uBeR6hAmlAmSHKoHctdDqT4aE1ax9QmPUV39kIfjXQB4HoOZrsjFk7AkxJdv G+eQ== X-Gm-Message-State: AOJu0YykSyqc+fYdHr11FEKk7wY/88ToEB1syal2ZKV8MfP/E1BOG69/ RQlkSvIh2ovYWneDE0H7jJLneYmf+fHgSLDD8xK+EMnx2CaYGiQXsbct0qs/MG2cTNWyUwPFtS+ YRS5AuK3oaptcdMxGD8TbHSae7yQ4AXJRhCdyA+Ez/kGHmqtV+uHaV6BmvUB9XW8FYtg+kUvFMd serCKJnqWmzsPXSJCUmnWupSZoTIr7BqyPvp8lFR2Rkb5A8qqfb08= X-Gm-Gg: AfdE7cnjH0VSPaUIYMI7EUy4cpyXaukPJ+SyY5SHiIMgtNbJrz0dxwKMJhCjDENFbiU 8uJ9R8dBst6JQSoQxMyBNYj7OTMYNb2xo4VdZd9H6hStCnJcDddvKxqlcKTvRXWuT87jvAZun78 LNmWLxCEIi3i6qRfwa2A/HA3SsXLaBT5PvGYo/nmoIldVRJkx971TAeTheTsyDQY1/eMaCjjw7p yoKlqww3wqPCBTEX8PmoB+R3dSgVQPgBZ2BjrqZO4t9ibsg94JSiz2UFSR8OEsPGnKGVwyMZw3c jIPBxU0FZOdxoyEBWaDJ429jgj+Djnkz+D3wcOGZ6DabEM1lgCafm8oK/0k+zuN5q6j/mCFwwdu 4eXtjJjbv/nshO8o7/h9PlNJkrbREs1fPOA4kmNFrviOmjvFdgdrpyvnXboD/KqVL+jVw+fRcEF zx5ztVdC8e57Hwbfc1TqXxO0cT9uBCuQ== X-Received: by 2002:a05:7300:2326:b0:30b:e3c7:27f0 with SMTP id 5a478bee46e88-30c84c04eb1mr14061756eec.13.1782630183932; Sun, 28 Jun 2026 00:03:03 -0700 (PDT) Received: from sw08.internal.sifive.com ([4.53.31.132]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-30c7c8afc91sm35435166eec.14.2026.06.28.00.03.02 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 28 Jun 2026 00:03:03 -0700 (PDT) From: Jesse Huang To: libc-alpha@sourceware.org Cc: andrew@sifive.com, darius@bluespec.com, debug@rivosinc.com, jeffreyalaw@gmail.com, kito.cheng@sifive.com, palmer@dabbelt.com, schwab@suse.de, Jesse Huang Subject: [PATCH v5 12/16] riscv/cfi: Store shadow stack information in TLS Date: Sun, 28 Jun 2026 00:02:37 -0700 Message-Id: <20260628070241.88310-13-jesse.huang@sifive.com> X-Mailer: git-send-email 2.39.3 In-Reply-To: <20260628070241.88310-1-jesse.huang@sifive.com> References: <20260628070241.88310-1-jesse.huang@sifive.com> MIME-Version: 1.0 X-Spam-Status: No, score=-13.2 required=5.0 tests=BAYES_00, DKIM_SIGNED, DKIM_VALID, DKIM_VALID_AU, DKIM_VALID_EF, GIT_PATCH_0, RCVD_IN_DNSWL_NONE, SPF_HELO_NONE, SPF_PASS, TXREP shortcircuit=no autolearn=ham autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on sourceware.org X-BeenThere: libc-alpha@sourceware.org X-Mailman-Version: 2.1.30 Precedence: list List-Id: Libc-alpha mailing list List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: libc-alpha-bounces~patchwork=sourceware.org@sourceware.org Switching between different ucontexts involves two cases. One case is when both contexts share the same shadow stack, which requires unwinding. The other is when each context uses a different shadow stack, which requires a stack switch using a shadow stack restore token. By storing the shadow stack base in TLS and comparing it to the value stored in the context, we can tell the difference and perform the right action. --- sysdeps/riscv/nptl/Makefile | 1 + sysdeps/riscv/nptl/tcb-offsets.sym | 5 +++++ sysdeps/riscv/nptl/tls.h | 2 ++ 3 files changed, 8 insertions(+) create mode 100644 sysdeps/riscv/nptl/Makefile create mode 100644 sysdeps/riscv/nptl/tcb-offsets.sym diff --git a/sysdeps/riscv/nptl/Makefile b/sysdeps/riscv/nptl/Makefile new file mode 100644 index 0000000000..2b7bf43403 --- /dev/null +++ b/sysdeps/riscv/nptl/Makefile @@ -0,0 +1 @@ +gen-as-const-headers += tcb-offsets.sym diff --git a/sysdeps/riscv/nptl/tcb-offsets.sym b/sysdeps/riscv/nptl/tcb-offsets.sym new file mode 100644 index 0000000000..5257acccec --- /dev/null +++ b/sysdeps/riscv/nptl/tcb-offsets.sym @@ -0,0 +1,5 @@ +#include +#include +#include + +TLS_SSP_BASE_OFFSET (offsetof (tcbhead_t, ssp_base) - sizeof (tcbhead_t)) diff --git a/sysdeps/riscv/nptl/tls.h b/sysdeps/riscv/nptl/tls.h index 1e46e93669..f53863ea05 100644 --- a/sysdeps/riscv/nptl/tls.h +++ b/sysdeps/riscv/nptl/tls.h @@ -44,6 +44,8 @@ typedef struct { dtv_t *dtv; void *private; + /* The marker for the current shadow stack. */ + unsigned long long int ssp_base; } tcbhead_t; /* This is the size of the initial TCB. Because our TCB is before the thread From patchwork Sun Jun 28 07:02:38 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Jesse Huang X-Patchwork-Id: 137971 Return-Path: X-Original-To: patchwork@sourceware.org Delivered-To: patchwork@sourceware.org Received: from vm01.sourceware.org (localhost [IPv6:::1]) by sourceware.org (Postfix) with ESMTP id E1F054BA2E35 for ; Sun, 28 Jun 2026 07:09:03 +0000 (GMT) DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org E1F054BA2E35 Authentication-Results: sourceware.org; dkim=pass (2048-bit key, unprotected) header.d=sifive.com header.i=@sifive.com header.a=rsa-sha256 header.s=google header.b=Zl3daVCI X-Original-To: libc-alpha@sourceware.org Delivered-To: libc-alpha@sourceware.org Received: from mail-dy1-x1336.google.com (mail-dy1-x1336.google.com [IPv6:2607:f8b0:4864:20::1336]) by sourceware.org (Postfix) with ESMTPS id 96E474BA23CA for ; Sun, 28 Jun 2026 07:03:06 +0000 (GMT) DMARC-Filter: OpenDMARC Filter v1.4.2 sourceware.org 96E474BA23CA Authentication-Results: sourceware.org; dmarc=pass (p=reject dis=none) header.from=sifive.com Authentication-Results: sourceware.org; spf=pass smtp.mailfrom=sifive.com ARC-Filter: OpenARC Filter v1.0.0 sourceware.org 96E474BA23CA Authentication-Results: sourceware.org; arc=none smtp.remote-ip=2607:f8b0:4864:20::1336 ARC-Seal: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1782630186; cv=none; b=jaBtg3GarFll+twJZzcICXkEnupYt9UuuTN+eWRDv9M+KudgXnOpdsMKJfRS+kx6JjYIBWdImRPwukzz9/jh7pg5u1nVV46IjPEXDWU4uFFpWJ0aVreemPs2KRh2dF5fXI4VIlpBz0aLayXA4D4GJBBz3HSsZzPz6Aw4Dnsmzgk= ARC-Message-Signature: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1782630186; c=relaxed/simple; bh=gsM9hijP1PqYvHmjVAPHHVkbkI1Yov7g4w9D+qyx5gs=; h=DKIM-Signature:From:To:Subject:Date:Message-Id:MIME-Version; b=WKkr/ZwWuykz0RuYTO4L/w2TyK/qPEj/i/mTeVc0HJ+EQdl53bFvbnwi5pK/7/ET5zYSMony7SCdKE7t12dXgZQwoc0s4bcvWSRr0uPZXDrBZQVBkgUyM0y25ZlwvshW2Qq8xPuUEI93hgBe6Nz5fwTb1JZmqOerazv4u4DehfQ= ARC-Authentication-Results: i=1; sourceware.org; dkim=pass (2048-bit key, unprotected) header.d=sifive.com header.i=@sifive.com header.a=rsa-sha256 header.s=google header.b=Zl3daVCI DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org 96E474BA23CA Received: by mail-dy1-x1336.google.com with SMTP id 5a478bee46e88-30df5854e1eso372286eec.0 for ; Sun, 28 Jun 2026 00:03:06 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=sifive.com; s=google; t=1782630185; x=1783234985; darn=sourceware.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to; bh=F3UPFyj/sfFJTTWw+M14ZxF7dbNG/AKJ4tBsMVWE8Ag=; b=Zl3daVCIZTTAxYBYG/oZ8Mopq/pGXnQkIbCmRsYJGlTFz8k0W6u/i16uAqUAcuLr6N 9HVufW1C7X0XmzfaPPQKwQkKXeonbSrNWQ3C7udWpa7AvV6JOSd0muI3IlPpT4mxnmTR wf19fu38eHVmUuRibZ2rMHfGAGFq5KIA4QfddQe7aOGpX6CGSc/486ZoO4AcohM3H310 Pvb1QPEC/mgYrpC31GRnbUABfdt4ypPnWbg1oztDGce1f5TtnCJpiSbp72SHPZL9fnl5 3lR6uOw1ZK45JmQl/9Iuz+HCPqKepOo0/S54TQrSjKuW8OeqC0Fyd/3jH7zQGj98RSam pFZQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1782630185; x=1783234985; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to; bh=F3UPFyj/sfFJTTWw+M14ZxF7dbNG/AKJ4tBsMVWE8Ag=; b=CYgWQ2jQT3E54rC0C1SJ4JHgxF+TZo3mMrP/ctdCk+b4dhBodB3rZEdNaEmuj1yasP wQ0Lj6oV/qETDkxKy034eyJshm/0YR79c466f5wBFHlotzzeDjXbrV9knsJXtk5z2d7z 4uCID2zZKI4d4VrT0gWfVtV1k3mdaSBIhgkTDBvdRv1u6/QsrOC8zgnStMwbSDtO7YKM QTHGio2WzkZNeHOs1fARSWi7dyi7uv/Mk3e3HQ43/NpCwrftbj4nILWUmPyFCrE1H5aN chUX41wxFigaTMz2S04684XeB1K0m5+ojZ2UCrfCZOYaoaBSt/M4ou2M0mSgUkO1JmoP R7Pw== X-Gm-Message-State: AOJu0YxdPwNQHRzBHcPw7dI5gezPy/p9L3wPsS9Nb4LgPYjVy4iaVXSK IYlxKuARX7HH4etzjn256kfFrBdA5C5RkCljViU55SyMAnSOUeOeMWtEze8h57I19E28pw5C0Yn k6bYdUlZOlEISQLUpX+I5DWhsf6WbWcPOXy8Iw48b+8USZnu7o7vtfhF6cYrf9V7BRScxRYLfzd nVyvx7vDZOBht1MfCbzmdAhfBoxwSljY0h/0bqsEJFKxe+uHUEQ4w= X-Gm-Gg: AfdE7ckXf7FlEfVJAo/3JeF+d2/WU8btcB1HXVPlB0nFo3yWXGC4bgomi+L3nmSokrp 6+DFKnCijQ8He1fJyItTLIs0w92W+6bJqk7M1CIzLQemyK16oyYrdqWJgsIe8Nk27MzyzHDbJES oXdcvQx+AtZ5PVRg+sub90ZC+jt0xsRRptqyvGKgrC6udYiaV6iyzo+02k9WWB43wqNG9tHDHLm SBbCnEVV5zrO3sM9B3/7+4l5OxFfadPWcdnPgpZjayWXuiaeo7e66MBtTOWPxNHimRzsQT3Ic28 pqf51iabAZiN43YJOuU+ezJdMyfcPrZwwiqSM6dnRG+FlIYw7WxAHsnZKGabNTeQg7Jz27KVuON snVgUpD26W9vHOd+UJpGHoRADP0Lag25eUggjTiZV4rUP7wCXxrorhW7KsiEnrim25hyrwa9CrI u02F+/IT62vW8V11JdxTeyoFcHjFqKMg== X-Received: by 2002:a05:7301:5f07:b0:30c:ab96:7304 with SMTP id 5a478bee46e88-30cab96773bmr6428526eec.20.1782630185316; Sun, 28 Jun 2026 00:03:05 -0700 (PDT) Received: from sw08.internal.sifive.com ([4.53.31.132]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-30c7c8afc91sm35435166eec.14.2026.06.28.00.03.04 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 28 Jun 2026 00:03:04 -0700 (PDT) From: Jesse Huang To: libc-alpha@sourceware.org Cc: andrew@sifive.com, darius@bluespec.com, debug@rivosinc.com, jeffreyalaw@gmail.com, kito.cheng@sifive.com, palmer@dabbelt.com, schwab@suse.de, Jesse Huang , Jerry Zhang Jian Subject: [PATCH v5 13/16] riscv/cfi: Add internal sigset_t union and use it for both ucontext/jmpbuf Date: Sun, 28 Jun 2026 00:02:38 -0700 Message-Id: <20260628070241.88310-14-jesse.huang@sifive.com> X-Mailer: git-send-email 2.39.3 In-Reply-To: <20260628070241.88310-1-jesse.huang@sifive.com> References: <20260628070241.88310-1-jesse.huang@sifive.com> MIME-Version: 1.0 X-Spam-Status: No, score=-13.2 required=5.0 tests=BAYES_00, DKIM_SIGNED, DKIM_VALID, DKIM_VALID_AU, DKIM_VALID_EF, GIT_PATCH_0, RCVD_IN_DNSWL_NONE, SPF_HELO_NONE, SPF_PASS, TXREP shortcircuit=no autolearn=ham autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on sourceware.org X-BeenThere: libc-alpha@sourceware.org X-Mailman-Version: 2.1.30 Precedence: list List-Id: Libc-alpha mailing list List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: libc-alpha-bounces~patchwork=sourceware.org@sourceware.org Co-authored-by: Jerry Zhang Jian --- .../sysv/linux/riscv/bits/types/__sigset_t.h | 43 +++++++++++++++++++ sysdeps/unix/sysv/linux/riscv/setjmpP.h | 31 +------------ sysdeps/unix/sysv/linux/riscv/sys/ucontext.h | 14 +++++- 3 files changed, 57 insertions(+), 31 deletions(-) create mode 100644 sysdeps/unix/sysv/linux/riscv/bits/types/__sigset_t.h diff --git a/sysdeps/unix/sysv/linux/riscv/bits/types/__sigset_t.h b/sysdeps/unix/sysv/linux/riscv/bits/types/__sigset_t.h new file mode 100644 index 0000000000..d83c76876d --- /dev/null +++ b/sysdeps/unix/sysv/linux/riscv/bits/types/__sigset_t.h @@ -0,0 +1,43 @@ +/* Architecture-specific __sigset_t definition. RISC-V version. */ +#ifndef ____sigset_t_defined +#define ____sigset_t_defined + +#define _SIGSET_NWORDS (1024 / (8 * sizeof (unsigned long int))) +typedef struct +{ + unsigned long int __val[_SIGSET_NWORDS]; +} __sigset_t; + +#define __ALIGN_DOWN(base, size) ((base) & -((__typeof__ (base)) (size))) +#define __ALIGN_UP(base, size) __ALIGN_DOWN ((base) + (size) - 1, (size)) + +/* Number of bits per long. */ +#define _SSP_SIGSET_BITS_PER_WORD (8 * sizeof (unsigned long int)) +/* This holds the number of signals, 512 should be sufficient for future. + expansion */ +#define _SSP_SIGSET_NSIG 512 +/* Number of longs to hold all signals. */ +#define _SSP_SIGSET_NWORDS \ + (__ALIGN_UP (_SSP_SIGSET_NSIG, _SSP_SIGSET_BITS_PER_WORD) \ + / _SSP_SIGSET_BITS_PER_WORD) + +typedef struct + { + unsigned long int __val[_SSP_SIGSET_NWORDS]; + } __ssp_sigset_t; + +typedef union + { + __sigset_t __saved_mask_compat; + struct + { + __ssp_sigset_t __saved_mask; + /* Used for shadow stack pointer. NB: Shadow stack pointer + must have the same alignment as __saved_mask. Otherwise + offset of __saved_mask will be changed. */ + unsigned long int __ssp; + unsigned long int __ssp_base; + } __saved; + } __ssp_sigset_arch_t; + +#endif diff --git a/sysdeps/unix/sysv/linux/riscv/setjmpP.h b/sysdeps/unix/sysv/linux/riscv/setjmpP.h index 43cb28e2d1..b237f7baf4 100644 --- a/sysdeps/unix/sysv/linux/riscv/setjmpP.h +++ b/sysdeps/unix/sysv/linux/riscv/setjmpP.h @@ -23,42 +23,13 @@ #include #include -/* Number of bits per long. */ -#define _JUMP_BUF_SIGSET_BITS_PER_WORD (8 * sizeof (unsigned long int)) -/* This holds the number of signals, 512 should be sufficient for future. - expansion */ -#define _JUMP_BUF_SIGSET_NSIG 512 -/* Number of longs to hold all signals. */ -#define _JUMP_BUF_SIGSET_NWORDS \ - (ALIGN_UP (_JUMP_BUF_SIGSET_NSIG, _JUMP_BUF_SIGSET_BITS_PER_WORD) \ - / _JUMP_BUF_SIGSET_BITS_PER_WORD) - -typedef struct - { - unsigned long int __val[_JUMP_BUF_SIGSET_NWORDS]; - } __jmp_buf_sigset_t; - -typedef union - { - __sigset_t __saved_mask_compat; - struct - { - __jmp_buf_sigset_t __saved_mask; - /* Used for shadow stack pointer. NB: Shadow stack pointer - must have the same alignment as __saved_mask. Otherwise - offset of __saved_mask will be changed. */ - unsigned long int __ssp; - unsigned long int __ssp_base; - } __saved; - } __jmpbuf_arch_t; - /* has NB: We use setjmp in thread cancellation and this saves the shadow stack register, but __libc_unwind_longjmp doesn't restore the shadow stack register since cancellation never returns after longjmp. */ #undef __sigset_t -#define __sigset_t __jmpbuf_arch_t +#define __sigset_t __ssp_sigset_arch_t #include #undef __saved_mask #define __saved_mask __saved_mask.__saved.__saved_mask diff --git a/sysdeps/unix/sysv/linux/riscv/sys/ucontext.h b/sysdeps/unix/sysv/linux/riscv/sys/ucontext.h index 312be3cfc3..37cfc41fb6 100644 --- a/sysdeps/unix/sysv/linux/riscv/sys/ucontext.h +++ b/sysdeps/unix/sysv/linux/riscv/sys/ucontext.h @@ -23,6 +23,7 @@ #include +#include #include #include @@ -90,7 +91,18 @@ typedef struct ucontext_t unsigned long int __uc_flags; struct ucontext_t *uc_link; stack_t uc_stack; - sigset_t uc_sigmask; + /* Internal overlay for uc_sigmask to store CFI shadow stack state while + keeping the public API type as sigset_t. */ + union + { + sigset_t uc_sigmask; /* Public view. */ + struct + { + __ssp_sigset_t __saved_mask; + unsigned long int __ssp; + unsigned long int __ssp_base; + } __saved; /* Internal view. */ + }; /* There's some padding here to allow sigset_t to be expanded in the future. Though this is unlikely, other architectures put uc_sigmask at the end of this structure and explicitly state it can be From patchwork Sun Jun 28 07:02:39 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Jesse Huang X-Patchwork-Id: 137972 Return-Path: X-Original-To: patchwork@sourceware.org Delivered-To: patchwork@sourceware.org Received: from vm01.sourceware.org (localhost [IPv6:::1]) by sourceware.org (Postfix) with ESMTP id 8BAFF4BA2E27 for ; Sun, 28 Jun 2026 07:09:25 +0000 (GMT) DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org 8BAFF4BA2E27 Authentication-Results: sourceware.org; dkim=pass (2048-bit key, unprotected) header.d=sifive.com header.i=@sifive.com header.a=rsa-sha256 header.s=google header.b=A2tVvIgH X-Original-To: libc-alpha@sourceware.org Delivered-To: libc-alpha@sourceware.org Received: from mail-dy1-x1329.google.com (mail-dy1-x1329.google.com [IPv6:2607:f8b0:4864:20::1329]) by sourceware.org (Postfix) with ESMTPS id 41FD44BA23E0 for ; Sun, 28 Jun 2026 07:03:08 +0000 (GMT) DMARC-Filter: OpenDMARC Filter v1.4.2 sourceware.org 41FD44BA23E0 Authentication-Results: sourceware.org; dmarc=pass (p=reject dis=none) header.from=sifive.com Authentication-Results: sourceware.org; spf=pass smtp.mailfrom=sifive.com ARC-Filter: OpenARC Filter v1.0.0 sourceware.org 41FD44BA23E0 Authentication-Results: sourceware.org; arc=none smtp.remote-ip=2607:f8b0:4864:20::1329 ARC-Seal: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1782630188; cv=none; b=bEAxJo1lwSVjEkIQ7GOESB8UXIrlRNOCZq/xV8052rKp/dLnnV6jnHiI0co0mp77pvi7Ji/SxxvAB03sQrsXA6yDYcW6XQNG+l4Q3yqhViqZJ4d9jcD6Q+4Gl8KguGOEIVpZgBV06+7Suvxb1sc7vEvhrNbwTSrS9kJrUvBc8Rg= ARC-Message-Signature: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1782630188; c=relaxed/simple; bh=rXdvvKET84EXDFBJl0YJJns6uSHmEtQPgwNq9Hx7l4g=; h=DKIM-Signature:From:To:Subject:Date:Message-Id:MIME-Version; b=GBpDopg5xjMPwOgzsmtTno9EgBfDtOPErvdLtsSBDRGruPNjIZijMQh3fZYXix/VvHB4YUH4hCFcneJXs+nQ8OEdO+X3BH0hGeHWfwJffMveoXpyRDOASikvaEB/d5lZXN50zGvZZWgcumHuczANXEfUCye+UJDEyV6T3OXh2lM= ARC-Authentication-Results: i=1; sourceware.org; dkim=pass (2048-bit key, unprotected) header.d=sifive.com header.i=@sifive.com header.a=rsa-sha256 header.s=google header.b=A2tVvIgH DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org 41FD44BA23E0 Received: by mail-dy1-x1329.google.com with SMTP id 5a478bee46e88-30c6874d295so1437768eec.1 for ; Sun, 28 Jun 2026 00:03:08 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=sifive.com; s=google; t=1782630187; x=1783234987; darn=sourceware.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to; bh=k2/z7hmVDd+XeGx1/+HvxSvJFa0EXY1bSCJD+5jkSnc=; b=A2tVvIgHAqm9LAgOi9Gjn7xICVbSstXCNXarpITA/kLJkCJ4hd3gLlPAjguEJ02FXy 7mC34HrVNh1cUomSjcaV6Vz8yGDDW3X2Tc0QmzYj6iJ50YwHbnrIcdheMf6fZa0pWYfx gSNkVV8vYXmrt7b8uHMVGGgh8Z6jo4L8cG2JHwR7htn3yGUwspgGcMHlw8qJUZAfwlN4 56ZVsqGM5ZMZsk3eSrxhdPDJYiIYSK+KZtFhZu8U+Zm0BNQ69bXYrJxXCG+npgD4AZL8 Jx+IQRkPL5MN9PqJ6l/o9nGLvX9hAIII24Oxww3hYBfy+kmxBSxJO6Fp7vyYUODAcLkg EbOg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1782630187; x=1783234987; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to; bh=k2/z7hmVDd+XeGx1/+HvxSvJFa0EXY1bSCJD+5jkSnc=; b=krqGfkk5rnmqCDHoE3qlyk1yuSLGFiEtF4F7ZznzSV2ODrQ0K1TaCrSg6dJGsRZyD2 +RMcb1lgjrE4R8JqlPMRObX4cyy1l7XJKVqocaOHw9AqjEM67+bFjrEp18FxMFnEwSSU F3ZH0aAt3Jt6kRfGONjsds5SJgz/nLy9150Xw3YUwo3cAspkRsv0aRfrM9qu7gJKCIRP 0OiVqiBGLU0pICn1I7m5JICjO2G7TWeeeG5Yh0QUG8YQ+POFyjKhmQxpvCsG03w9XQam usjXIqwjCmi33J+++Vzi4iuajCHxjF/xIfY34gVY/UOqfQ58Sp5s1FOZPU+bGaCyhSm8 /pjA== X-Gm-Message-State: AOJu0YyhqGhF/DOkcdnZjohInRY1n4PVIaw81cmyD2wvC112rgXYGEYv WAT9/YrWUFMN+yP7KmPyxUKHFTYnS4FF4PsnTCcqNzx6pwpMuXw3IQGFZb9bBh+M44ns1wfQpU9 0WIK2NFWpvh8wjq+8qVKsaUQ/YVfcCUMsRGWpJ4CFeP6XHHyPhgVCmjCxmExW2LbrhN94WuGIvd Zaf8qZ33rHQsvlstU76r8JaaHalL/zxORgJDaaqqJGoUQuXZ23nog= X-Gm-Gg: AfdE7cl9Yf39Gu2mlEo1Abo6g2GDh9dSuQhQNLKuExJ66ZAbrDyD2NP5ApEQp0vXZhi Oda/JjcNS0psTcc5pFZuU8HVbbO/Cc6aBYMgv48wsI4fyg4vuqm64seWxXnhC3OFbiMrVj6yQlJ ubyc2JY0tm/DnHj4y2vTOEXKxdm17fASngBLtCmlOtLEeVdT+4/ZDAjUJ4g1/0DrGHCPHdhtVLy dt2Pnlf8y/DeWyUbN5U5QRsV0nl8FXu3jLWrshvvxor8MqL3qBuk9SyS5Ok42XWs7EH09JeOXd7 pVU5bSEBOKlnwKWdA7L1Jquk2os4wziRp2R4N6ZPdtKvTssHYzD79scn3/xisZQII8CB5bsy+gT PAw8qvEtTY18rlB9AN51lLQHyxZhnm9hRyrlrRK0D+0kPOYhe8weQhhRCxKwu4A6DT2d8I2LOFf q7IQyJP/NoZG75DsmntC3fEWi6OgaxtQ== X-Received: by 2002:a05:7300:80d5:b0:30c:ab96:7305 with SMTP id 5a478bee46e88-30cab967746mr7376304eec.21.1782630186949; Sun, 28 Jun 2026 00:03:06 -0700 (PDT) Received: from sw08.internal.sifive.com ([4.53.31.132]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-30c7c8afc91sm35435166eec.14.2026.06.28.00.03.05 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 28 Jun 2026 00:03:06 -0700 (PDT) From: Jesse Huang To: libc-alpha@sourceware.org Cc: andrew@sifive.com, darius@bluespec.com, debug@rivosinc.com, jeffreyalaw@gmail.com, kito.cheng@sifive.com, palmer@dabbelt.com, schwab@suse.de, Jesse Huang , Valentin Haudiquet , Jerry Zhang Jian Subject: [PATCH v5 14/16] riscv/cfi: Add __allocate_shadow_stack for mapping new shadow stack Date: Sun, 28 Jun 2026 00:02:39 -0700 Message-Id: <20260628070241.88310-15-jesse.huang@sifive.com> X-Mailer: git-send-email 2.39.3 In-Reply-To: <20260628070241.88310-1-jesse.huang@sifive.com> References: <20260628070241.88310-1-jesse.huang@sifive.com> MIME-Version: 1.0 X-Spam-Status: No, score=-13.2 required=5.0 tests=BAYES_00, DKIM_SIGNED, DKIM_VALID, DKIM_VALID_AU, DKIM_VALID_EF, GIT_PATCH_0, KAM_SHORT, RCVD_IN_DNSWL_NONE, SPF_HELO_NONE, SPF_PASS, TXREP shortcircuit=no autolearn=ham autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on sourceware.org X-BeenThere: libc-alpha@sourceware.org X-Mailman-Version: 2.1.30 Precedence: list List-Id: Libc-alpha mailing list List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: libc-alpha-bounces~patchwork=sourceware.org@sourceware.org Co-authored-by: Valentin Haudiquet Co-authored-by: Jerry Zhang Jian --- sysdeps/unix/sysv/linux/riscv/Makefile | 1 + .../sysv/linux/riscv/allocate-shadow-stack.c | 59 +++++++++++++++++++ .../sysv/linux/riscv/allocate-shadow-stack.h | 31 ++++++++++ sysdeps/unix/sysv/linux/riscv/bits/mman.h | 30 ++++++++++ sysdeps/unix/sysv/linux/riscv/sysdep.h | 2 + 5 files changed, 123 insertions(+) create mode 100644 sysdeps/unix/sysv/linux/riscv/allocate-shadow-stack.c create mode 100644 sysdeps/unix/sysv/linux/riscv/allocate-shadow-stack.h create mode 100644 sysdeps/unix/sysv/linux/riscv/bits/mman.h diff --git a/sysdeps/unix/sysv/linux/riscv/Makefile b/sysdeps/unix/sysv/linux/riscv/Makefile index 04abf226ad..e6b1a02c59 100644 --- a/sysdeps/unix/sysv/linux/riscv/Makefile +++ b/sysdeps/unix/sysv/linux/riscv/Makefile @@ -5,6 +5,7 @@ sysdep_headers += \ # sysdep_headers sysdep_routines += \ + allocate-shadow-stack \ flush-icache \ hwprobe \ # sysdep_routines diff --git a/sysdeps/unix/sysv/linux/riscv/allocate-shadow-stack.c b/sysdeps/unix/sysv/linux/riscv/allocate-shadow-stack.c new file mode 100644 index 0000000000..e64ddb2c56 --- /dev/null +++ b/sysdeps/unix/sysv/linux/riscv/allocate-shadow-stack.c @@ -0,0 +1,59 @@ +/* Helper function to allocate shadow stack. + Copyright (C) 2023-2026 Free Software Foundation, Inc. + This file is part of the GNU C Library. + + The GNU C Library is free software; you can redistribute it and/or + modify it under the terms of the GNU Lesser General Public + License as published by the Free Software Foundation; either + version 2.1 of the License, or (at your option) any later version. + + The GNU C Library is distributed in the hope that it will be useful, + but WITHOUT ANY WARRANTY; without even the implied warranty of + MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU + Lesser General Public License for more details. + + You should have received a copy of the GNU Lesser General Public + License along with the GNU C Library; if not, see + . */ + +#include +#include +#include +#include +#include +#include + +#ifndef SHADOW_STACK_SET_TOKEN +# define SHADOW_STACK_SET_TOKEN 0 +#endif + +/* NB: This can be treated as a syscall by caller. */ + +long int +__allocate_shadow_stack (size_t stack_size, + shadow_stack_size_t *child_stack) +{ +#ifdef __NR_map_shadow_stack + size_t shadow_stack_size + = stack_size >> STACK_SIZE_TO_SHADOW_STACK_SIZE_SHIFT; + /* Align shadow stack to 8 bytes. */ + shadow_stack_size = ALIGN_UP (shadow_stack_size, 8); + /* Since sigaltstack shares shadow stack with the current context in + the thread, add extra 20 stack frames in shadow stack for signal + handlers. */ + shadow_stack_size += 20 * 8; + void *shadow_stack = (void *)INLINE_SYSCALL_CALL + (map_shadow_stack, NULL, shadow_stack_size, SHADOW_STACK_SET_TOKEN); + /* Report the map_shadow_stack error. */ + if (shadow_stack < 0) + return -errno; + + /* Save the shadow stack base and size on child stack. */ + child_stack[0] = (uintptr_t) shadow_stack; + child_stack[1] = shadow_stack_size; + + return 0; +#else + return -ENOSYS; +#endif +} diff --git a/sysdeps/unix/sysv/linux/riscv/allocate-shadow-stack.h b/sysdeps/unix/sysv/linux/riscv/allocate-shadow-stack.h new file mode 100644 index 0000000000..4e361c8566 --- /dev/null +++ b/sysdeps/unix/sysv/linux/riscv/allocate-shadow-stack.h @@ -0,0 +1,31 @@ +/* Helper function to allocate shadow stack. + Copyright (C) 2023-2026 Free Software Foundation, Inc. + This file is part of the GNU C Library. + + The GNU C Library is free software; you can redistribute it and/or + modify it under the terms of the GNU Lesser General Public + License as published by the Free Software Foundation; either + version 2.1 of the License, or (at your option) any later version. + + The GNU C Library is distributed in the hope that it will be useful, + but WITHOUT ANY WARRANTY; without even the implied warranty of + MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU + Lesser General Public License for more details. + + You should have received a copy of the GNU Lesser General Public + License along with the GNU C Library; if not, see + . */ + +#include + +#ifdef __riscv_shadow_stack +/* When shadow stack is enabled, derive the storage type from ucontext. */ +typedef __typeof (((ucontext_t *) 0)->__saved.__ssp) \ + shadow_stack_size_t; +#else +/* Without shadow stack support, use an unsigned long placeholder type. */ +typedef unsigned long int shadow_stack_size_t; +#endif + +extern long int __allocate_shadow_stack (size_t, shadow_stack_size_t *) + attribute_hidden; diff --git a/sysdeps/unix/sysv/linux/riscv/bits/mman.h b/sysdeps/unix/sysv/linux/riscv/bits/mman.h new file mode 100644 index 0000000000..46f50be71c --- /dev/null +++ b/sysdeps/unix/sysv/linux/riscv/bits/mman.h @@ -0,0 +1,30 @@ +/* Definitions for POSIX memory map interface. Linux/risc-v version. + Copyright (C) 1997-2026 Free Software Foundation, Inc. + This file is part of the GNU C Library. + + The GNU C Library is free software; you can redistribute it and/or + modify it under the terms of the GNU Lesser General Public + License as published by the Free Software Foundation; either + version 2.1 of the License, or (at your option) any later version. + + The GNU C Library is distributed in the hope that it will be useful, + but WITHOUT ANY WARRANTY; without even the implied warranty of + MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU + Lesser General Public License for more details. + + You should have received a copy of the GNU Lesser General Public + License along with the GNU C Library. If not, see + . */ + +#ifndef _SYS_MMAN_H +# error "Never use directly; include instead." +#endif + +#if defined __USE_MISC && defined __riscv_shadow_stack +# define SHADOW_STACK_SET_TOKEN 0x1 +#endif + +#include + +/* Include generic Linux declarations. */ +#include diff --git a/sysdeps/unix/sysv/linux/riscv/sysdep.h b/sysdeps/unix/sysv/linux/riscv/sysdep.h index c60b0623c2..4477008158 100644 --- a/sysdeps/unix/sysv/linux/riscv/sysdep.h +++ b/sysdeps/unix/sysv/linux/riscv/sysdep.h @@ -205,6 +205,8 @@ GNU_PROPERTY (FEATURE_1_AND, __VALUE_FOR_FEATURE_1_AND) #else /* !__ASSEMBLER__ */ +# define STACK_SIZE_TO_SHADOW_STACK_SIZE_SHIFT 5 + # if __WORDSIZE == 64 # define VDSO_NAME "LINUX_4.15" # define VDSO_HASH 182943605 From patchwork Sun Jun 28 07:02:40 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Jesse Huang X-Patchwork-Id: 137973 Return-Path: X-Original-To: patchwork@sourceware.org Delivered-To: patchwork@sourceware.org Received: from vm01.sourceware.org (localhost [IPv6:::1]) by sourceware.org (Postfix) with ESMTP id 2F7C84BA2E35 for ; Sun, 28 Jun 2026 07:10:41 +0000 (GMT) DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org 2F7C84BA2E35 Authentication-Results: sourceware.org; dkim=pass (2048-bit key, unprotected) header.d=sifive.com header.i=@sifive.com header.a=rsa-sha256 header.s=google header.b=DdVzfwQq X-Original-To: libc-alpha@sourceware.org Delivered-To: libc-alpha@sourceware.org Received: from mail-dy1-x132d.google.com (mail-dy1-x132d.google.com [IPv6:2607:f8b0:4864:20::132d]) by sourceware.org (Postfix) with ESMTPS id D015A4BA23CA for ; Sun, 28 Jun 2026 07:03:09 +0000 (GMT) DMARC-Filter: OpenDMARC Filter v1.4.2 sourceware.org D015A4BA23CA Authentication-Results: sourceware.org; dmarc=pass (p=reject dis=none) header.from=sifive.com Authentication-Results: sourceware.org; spf=pass smtp.mailfrom=sifive.com ARC-Filter: OpenARC Filter v1.0.0 sourceware.org D015A4BA23CA Authentication-Results: sourceware.org; arc=none smtp.remote-ip=2607:f8b0:4864:20::132d ARC-Seal: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1782630190; cv=none; b=CLqUFhXrnXkKFnhJ19jzJ/gMgjCha7gHnLiilY3NFy2YaTgvTicDdgufUSO+2eOzf/0V6Ec14lSF74FW9BgrAeuqY3ATSRevaMb3tppfc+Y01BKHy3JlIGTZnObgO1/72+k+m8pP6/DJUkz4LDKoR5LsaabSlKOHyEK8VJFOLtY= ARC-Message-Signature: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1782630190; c=relaxed/simple; bh=jntNJVsvhVz/2mfxCbIFjpqc3kaHCp3QnNrrTGZcpOk=; h=DKIM-Signature:From:To:Subject:Date:Message-Id:MIME-Version; b=Wsb9QqClaNzwkCoJHOcOQEnIXLzmo9sPaz+N1dXPqQwl1Unty3K0jS3L0M6RBXYTJ+8Wb5QAnfuuDKQTnY+iqV0cpS9PQ3iZPMqyq6EbsQB/cDWyA9hjArynW5zrchmPrgFe7P12erc/PT14N7bjfLLbGJ/Clp966/xBL0tkWl8= ARC-Authentication-Results: i=1; sourceware.org; dkim=pass (2048-bit key, unprotected) header.d=sifive.com header.i=@sifive.com header.a=rsa-sha256 header.s=google header.b=DdVzfwQq DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org D015A4BA23CA Received: by mail-dy1-x132d.google.com with SMTP id 5a478bee46e88-30c591fb1cbso3585707eec.1 for ; Sun, 28 Jun 2026 00:03:09 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=sifive.com; s=google; t=1782630189; x=1783234989; darn=sourceware.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to; bh=liNFo1+3j4zFNejGWoKxXosjrFNl01MFBLsvwG+NcjA=; b=DdVzfwQqoWsOJdIu9TLhi0jHEu5HJX8jtgFToccdMbRiBQC3+FUiji3bgpz2BLy4yi t8hE/VN2pD+45UrVQuSiK+SiVBlfLGKzRu2cuMqU+fdOn7EHyBvr7lXc+jCoeUXE4oka 3iXdZPew36ONfu9A2Cp0h1/4ZFHlEVkKOPmOfjc0A7l2cDLZj1G/QdFdWQZwFC91Awpy SO0ym2kLZII7fhTbt3c5bwqb7X7RaKSBwmYF6naJBGcsXHoZJMmZSnf//FktqQkQ8kBo 1GLgZaePKFUs30ddXxayeqLVpH56ZnsHpEU6G3Uj38Uhg+Y/ziGGBQBvurLDfFe9h8ky tCFQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1782630189; x=1783234989; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to; bh=liNFo1+3j4zFNejGWoKxXosjrFNl01MFBLsvwG+NcjA=; b=PzblZ8cHwLAHCpJYZIfjCLPRC7gCpoDhFE5hNAumRbgHl71+h86v4auv+AI+wEc3v/ Io1GnKNP6x7q1HD/hsmPqr8Cn7jU97MLRAlxPFjFd6BR+GlICoiFK8Z0u24Rszv6A6f5 Cz3Ug/jQnoEAeBRGEJyEKh3AOTqlsK7RZO87WmAPUQDcuovNev5nWNZYW49wQQ9vZvf8 JRdyCJpOFlZqkiKVwxhldu866dy6z7guqMZZ5fF3xKYnnBjd+FxpqOUOXGNySpktSL5U AL2Aq+SIFwsnKoydclinL4CVzunTqCd0xr3/+66r8FpTrqS0BeCbOIruUCCEF74Ao7bD GROg== X-Gm-Message-State: AOJu0Yw9ZjLFdm2yShlyDoKXlC8zyqA6RFevhcx3NmW2SwzbcHjtTtlX LavKd1CE5h7FA6v0Q+aNDE/cph+E5s5ZIcdbQ/C61KhDpRHYKlzNgn93tlPHqsaoxxARpo0WrsV /oZvjI9gt5NWEWmXZglB49nL1/NPrW/V9LJDLGrTt10btKWbaSmFNM9xEf4mdg1iLdnP3T7eNWD SFmkBRaYrjAfl4R7yCP2dgKirdY5sS0JNn3ujdLrxHdKnDcFmgiW0= X-Gm-Gg: AfdE7cn9eIpKJ/f8uYHbKC9AwZeMogXJYZOJL24eyCnuc6z5AZ0QdUhRsVhPwmttuCb XLyihd4MMJ9ilkWbMJt7xKZ37AlChP5Um83hxiM1XC2CjlcXwpicu9BAaf+Xoqkeqtc824GZU3Y Vh8a1LAFSKDeVDauxJPmiE2zNxS6xR5aGui91Tk3+zIDyf/rgCnjoPaLzgoA5LfzXkePd9PsMw2 6mrbSEvTmmwocX0LkZdSgzceZYYYFyTPEF5j+BXOAfVpowX17sANrjgdP5Rh8mZHtsLvK7mJX3M lE99WyZ8xfdpsZ4EZJ0iEtkZSZCQNydaEWYS6QTKU0HhGuhTQ2lt+NBdRYM6u7GB9qkEncTqvaa +gxu/4Fk/mcMredqmdd8+wy61GKJZ7VMqbNxQLboOWORvP8609mATYafgRGyJauZJVxnEVIzY27 Pq+L6XqTkHksd1ojkKd6Q+Fe3DmvLEuNZMP1K6uHA/ X-Received: by 2002:a05:7300:4312:b0:306:f474:738c with SMTP id 5a478bee46e88-30c84b8d68dmr12429206eec.13.1782630188511; Sun, 28 Jun 2026 00:03:08 -0700 (PDT) Received: from sw08.internal.sifive.com ([4.53.31.132]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-30c7c8afc91sm35435166eec.14.2026.06.28.00.03.07 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 28 Jun 2026 00:03:07 -0700 (PDT) From: Jesse Huang To: libc-alpha@sourceware.org Cc: andrew@sifive.com, darius@bluespec.com, debug@rivosinc.com, jeffreyalaw@gmail.com, kito.cheng@sifive.com, palmer@dabbelt.com, schwab@suse.de, Jesse Huang , Nia Su Subject: [PATCH v5 15/16] riscv/cfi: Support ucontext under CFI Date: Sun, 28 Jun 2026 00:02:40 -0700 Message-Id: <20260628070241.88310-16-jesse.huang@sifive.com> X-Mailer: git-send-email 2.39.3 In-Reply-To: <20260628070241.88310-1-jesse.huang@sifive.com> References: <20260628070241.88310-1-jesse.huang@sifive.com> MIME-Version: 1.0 X-Spam-Status: No, score=-13.2 required=5.0 tests=BAYES_00, DKIM_SIGNED, DKIM_VALID, DKIM_VALID_AU, DKIM_VALID_EF, GIT_PATCH_0, KAM_SHORT, RCVD_IN_DNSWL_NONE, SPF_HELO_NONE, SPF_PASS, TXREP shortcircuit=no autolearn=ham autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on sourceware.org X-BeenThere: libc-alpha@sourceware.org X-Mailman-Version: 2.1.30 Precedence: list List-Id: Libc-alpha mailing list List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: libc-alpha-bounces~patchwork=sourceware.org@sourceware.org This patch adds shadow stack and landing pad support to the ucontext library. Shadow stack switches are protected by a shadow stack restore token that is validated during the switch. Co-authored-by: Nia Su --- sysdeps/unix/sysv/linux/riscv/getcontext.S | 20 +++++ sysdeps/unix/sysv/linux/riscv/makecontext.c | 19 +++++ sysdeps/unix/sysv/linux/riscv/setcontext.S | 67 ++++++++++++++++ sysdeps/unix/sysv/linux/riscv/swapcontext.S | 81 +++++++++++++++++++- sysdeps/unix/sysv/linux/riscv/ucontext_i.sym | 4 +- 5 files changed, 189 insertions(+), 2 deletions(-) diff --git a/sysdeps/unix/sysv/linux/riscv/getcontext.S b/sysdeps/unix/sysv/linux/riscv/getcontext.S index fd55c3e7da..ff1512c2aa 100644 --- a/sysdeps/unix/sysv/linux/riscv/getcontext.S +++ b/sysdeps/unix/sysv/linux/riscv/getcontext.S @@ -17,11 +17,13 @@ . */ #include "ucontext-macros.h" +#include "tcb-offsets.h" /* int getcontext (ucontext_t *ucp) */ .text LEAF (__getcontext) + LPAD SAVE_INT_REG (ra, 0, a0) SAVE_INT_REG (ra, 1, a0) SAVE_INT_REG (sp, 2, a0) @@ -58,6 +60,24 @@ LEAF (__getcontext) sw a1, MCONTEXT_FSR(a0) #endif /* __riscv_float_abi_soft */ +#ifdef __riscv_shadow_stack + ssrdp t0 + beqz t0, .Lskip_ss + /* Read ssp_base from TLS */ + REG_L t1, TLS_SSP_BASE_OFFSET(tp) + + bnez t1, .Lbase_saved + /* if not found, save and use current ssp as the marker */ + mv t1, t0 + REG_S t1, TLS_SSP_BASE_OFFSET(tp) + +.Lbase_saved: + /* Save caller's ssp and base marker to ucontext */ + REG_S t1, UCONTEXT_SSP_BASE(a0) + REG_S t0, UCONTEXT_SSP(a0) +.Lskip_ss: +#endif + /* rt_sigprocmask (SIG_BLOCK, NULL, &ucp->uc_sigmask, _NSIG8) */ li a3, _NSIG8 add a2, a0, UCONTEXT_SIGMASK diff --git a/sysdeps/unix/sysv/linux/riscv/makecontext.c b/sysdeps/unix/sysv/linux/riscv/makecontext.c index 7f8ab46bd0..37c922c440 100644 --- a/sysdeps/unix/sysv/linux/riscv/makecontext.c +++ b/sysdeps/unix/sysv/linux/riscv/makecontext.c @@ -21,6 +21,9 @@ #include #include #include +#ifdef __riscv_shadow_stack +#include +#endif void __makecontext (ucontext_t *ucp, void (*func) (void), int argc, @@ -73,6 +76,22 @@ __makecontext (ucontext_t *ucp, void (*func) (void), int argc, va_end (vl); } +#ifdef __riscv_shadow_stack + /* Allocate shadow stack for the new context */ + + /* shstk_size[0]: shadow stack base + shstk_size[1]: shadow stack size */ + shadow_stack_size_t shstk_size[2]; + int ret = __allocate_shadow_stack(ucp->uc_stack.ss_size, shstk_size); + if (ret != 0) + { + abort(); + } + + ucp->__saved.__ssp_base = shstk_size[0]; + ucp->__saved.__ssp = shstk_size[0] + shstk_size[1] - \ + sizeof (shstk_size[0]); +#endif } weak_alias (__makecontext, makecontext) diff --git a/sysdeps/unix/sysv/linux/riscv/setcontext.S b/sysdeps/unix/sysv/linux/riscv/setcontext.S index 9fd5f1f3cb..34ee34b607 100644 --- a/sysdeps/unix/sysv/linux/riscv/setcontext.S +++ b/sysdeps/unix/sysv/linux/riscv/setcontext.S @@ -17,6 +17,7 @@ . */ #include "ucontext-macros.h" +#include "tcb-offsets.h" /* int __setcontext (const ucontext_t *ucp) @@ -29,6 +30,7 @@ .text LEAF (__setcontext) + LPAD mv t0, a0 /* Save ucp into t0. */ @@ -45,6 +47,55 @@ LEAF (__setcontext) cfi_def_cfa (t0, 0) +#ifdef __riscv_shadow_stack + /* Skip if shadow stack is not enabled */ + ssrdp ra + beqz ra, .Lfin + /* We are safe to adjust shadow stack after the sanity check */ + REG_L t1, UCONTEXT_SSP_BASE(t0) + REG_L a1, UCONTEXT_SSP(t0) + REG_L a2, TLS_SSP_BASE_OFFSET(tp) + bne t1, a2, .Ldifferent_stack + +.Lunwind: + bleu a1, ra, .Lfin + /* increase ssp by at most one page size to ensure the adjustment + always runs into a guard page before accidentally pointing to + another legal shadow stack page */ + /* ra = (a1 - ra >= 4096) ? ra + 4096 : a1 */ + lui t2, 1 + add ra, ra, t2 + bleu ra, a1, 1f + mv ra, a1 +1: + csrw ssp, ra + /* Test if the location pointed by ssp is legal */ + sspush ra + sspopchk ra + j .Lunwind + +.Ldifferent_stack: + /* Create restore token */ + sspush ra + mv a4, a1 + +.Lfind_rstor_token: + /* Probe and validate target restore token */ + ssamoswap.d a3, x0, (a4) + addi a2, a4, 8 + beq a3, a2, .Lswitch_stack + /* Restore the shadow stack and try the next slot */ + ssamoswap.d x0, a3, (a4) + addi a4, a4, -8 + j .Lfind_rstor_token + +.Lswitch_stack: + /* Switch stack: update ssp and base */ + csrw ssp, a1 + REG_S t1, TLS_SSP_BASE_OFFSET(tp) +.Lfin: +#endif + #ifndef __riscv_float_abi_soft lw t1, MCONTEXT_FSR(t0) @@ -66,7 +117,11 @@ LEAF (__setcontext) /* Note the contents of argument registers will be random unless makecontext() has been called. */ +#ifdef __riscv_landing_pad + RESTORE_INT_REG (t2, 0, t0) +#else RESTORE_INT_REG (t1, 0, t0) +#endif RESTORE_INT_REG_CFI (ra, 1, t0) RESTORE_INT_REG (sp, 2, t0) RESTORE_INT_REG_CFI (s0, 8, t0) @@ -90,7 +145,12 @@ LEAF (__setcontext) RESTORE_INT_REG_CFI (s10, 26, t0) RESTORE_INT_REG_CFI (s11, 27, t0) +#ifdef __riscv_landing_pad + /* We need to use software-guared jump */ + jr t2 +#else jr t1 +#endif 99: tail __syscall_error @@ -99,12 +159,19 @@ libc_hidden_def (__setcontext) weak_alias (__setcontext, setcontext) LEAF (__start_context) + LPAD /* Terminate call stack by noting ra == 0. Happily, s0 == 0 here. */ cfi_register (ra, s0) /* Call the function passed to makecontext. */ +#ifdef __riscv_landing_pad + /* We need to use software-guared jump */ + mv t2, s1 + jalr t2 +#else jalr s1 +#endif /* Invoke subsequent context if present, else exit(0). */ mv a0, s2 diff --git a/sysdeps/unix/sysv/linux/riscv/swapcontext.S b/sysdeps/unix/sysv/linux/riscv/swapcontext.S index 4b3b0b3a14..a040de1b9a 100644 --- a/sysdeps/unix/sysv/linux/riscv/swapcontext.S +++ b/sysdeps/unix/sysv/linux/riscv/swapcontext.S @@ -17,10 +17,12 @@ . */ #include "ucontext-macros.h" +#include "tcb-offsets.h" /* int swapcontext (ucontext_t *oucp, const ucontext_t *ucp) */ LEAF (__swapcontext) + LPAD mv t0, a1 /* Save ucp into t0. */ SAVE_INT_REG (ra, 0, a0) @@ -59,6 +61,26 @@ LEAF (__swapcontext) sw a1, MCONTEXT_FSR(a0) #endif /* __riscv_float_abi_soft */ +#ifdef __riscv_shadow_stack + /* Skip if shadow stack is not enabled */ + ssrdp ra + beqz ra, .Lsave_fin + + /* Read ssp_base from TLS */ + REG_L t2, TLS_SSP_BASE_OFFSET(tp) + bnez t2, .Lbase_saved + + /* if not found, use current ssp as the marker */ + mv t2, ra + REG_S t2, TLS_SSP_BASE_OFFSET(tp) + +.Lbase_saved: + /* Save caller's ssp and base marker to oucp */ + REG_S t2, UCONTEXT_SSP_BASE(a0) + REG_S ra, UCONTEXT_SSP(a0) +.Lsave_fin: +#endif + /* rt_sigprocmask (SIG_SETMASK, &ucp->uc_sigmask, &oucp->uc_sigmask, _NSIG8) */ li a3, _NSIG8 add a2, a0, UCONTEXT_SIGMASK @@ -70,6 +92,55 @@ LEAF (__swapcontext) bltz a0, 99f +#ifdef __riscv_shadow_stack + /* Skip if shadow stack is not enabled */ + ssrdp ra + beqz ra, .Lfin + /* Load ss information from ucp */ + REG_L a0, UCONTEXT_SSP_BASE(t0) + REG_L a1, UCONTEXT_SSP(t0) + REG_L a2, TLS_SSP_BASE_OFFSET(tp) + bne a0, a2, .Ldifferent_stack + +.Lunwind: + bleu a1, ra, .Lfin + /* increase ssp by at most one page size to ensure the adjustment + always runs into a guard page before accidentally pointing to + another legal shadow stack page */ + /* ra = (a1 - ra >= 4096) ? ra + 4096 : a1 */ + lui t2, 1 + add ra, ra, t2 + bleu ra, a1, 1f + mv ra, a1 +1: + csrw ssp, ra + /* Test if the location pointed by ssp is legal */ + sspush ra + sspopchk ra + j .Lunwind + +.Ldifferent_stack: + /* Create restore token */ + sspush ra + mv a4, a1 + +.Lfind_rstor_token: + /* Probe and validate target restore token */ + ssamoswap.d a3, x0, (a4) + addi a2, a4, 8 + beq a3, a2, .Lswitch_stack + /* Restore the shadow stack and try the next slot */ + ssamoswap.d x0, a3, (a4) + addi a4, a4, -8 + j .Lfind_rstor_token + +.Lswitch_stack: + /* Switch stack: update ssp and base */ + csrw ssp, a1 + REG_S a0, TLS_SSP_BASE_OFFSET(tp) +.Lfin: +#endif + #ifndef __riscv_float_abi_soft lw t1, MCONTEXT_FSR(t0) @@ -91,7 +162,11 @@ LEAF (__swapcontext) /* Note the contents of argument registers will be random unless makecontext() has been called. */ +#ifdef __riscv_landing_pad + RESTORE_INT_REG (t2, 0, t0) +#else RESTORE_INT_REG (t1, 0, t0) +#endif RESTORE_INT_REG (ra, 1, t0) RESTORE_INT_REG (sp, 2, t0) RESTORE_INT_REG (s0, 8, t0) @@ -115,8 +190,12 @@ LEAF (__swapcontext) RESTORE_INT_REG (s10, 26, t0) RESTORE_INT_REG (s11, 27, t0) +#ifdef __riscv_landing_pad + /* We need to use software-guared jump */ + jr t2 +#else jr t1 - +#endif 99: tail __syscall_error diff --git a/sysdeps/unix/sysv/linux/riscv/ucontext_i.sym b/sysdeps/unix/sysv/linux/riscv/ucontext_i.sym index be55b26310..9a39f761ad 100644 --- a/sysdeps/unix/sysv/linux/riscv/ucontext_i.sym +++ b/sysdeps/unix/sysv/linux/riscv/ucontext_i.sym @@ -19,7 +19,9 @@ UCONTEXT_FLAGS ucontext (__uc_flags) UCONTEXT_LINK ucontext (uc_link) UCONTEXT_STACK ucontext (uc_stack) UCONTEXT_MCONTEXT ucontext (uc_mcontext) -UCONTEXT_SIGMASK ucontext (uc_sigmask) +UCONTEXT_SIGMASK ucontext (__saved.__saved_mask) +UCONTEXT_SSP ucontext (__saved.__ssp) +UCONTEXT_SSP_BASE ucontext (__saved.__ssp_base) STACK_SP stack (ss_sp) STACK_SIZE stack (ss_size) From patchwork Sun Jun 28 07:02:41 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Jesse Huang X-Patchwork-Id: 137966 Return-Path: X-Original-To: patchwork@sourceware.org Delivered-To: patchwork@sourceware.org Received: from vm01.sourceware.org (localhost [IPv6:::1]) by sourceware.org (Postfix) with ESMTP id 56E5F4BA23C5 for ; Sun, 28 Jun 2026 07:05:55 +0000 (GMT) DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org 56E5F4BA23C5 Authentication-Results: sourceware.org; dkim=pass (2048-bit key, unprotected) header.d=sifive.com header.i=@sifive.com header.a=rsa-sha256 header.s=google header.b=dBRlHquK X-Original-To: libc-alpha@sourceware.org Delivered-To: libc-alpha@sourceware.org Received: from mail-dy1-x1334.google.com (mail-dy1-x1334.google.com [IPv6:2607:f8b0:4864:20::1334]) by sourceware.org (Postfix) with ESMTPS id 4D5F14BA2E29 for ; Sun, 28 Jun 2026 07:03:11 +0000 (GMT) DMARC-Filter: OpenDMARC Filter v1.4.2 sourceware.org 4D5F14BA2E29 Authentication-Results: sourceware.org; dmarc=pass (p=reject dis=none) header.from=sifive.com Authentication-Results: sourceware.org; spf=pass smtp.mailfrom=sifive.com ARC-Filter: OpenARC Filter v1.0.0 sourceware.org 4D5F14BA2E29 Authentication-Results: sourceware.org; arc=none smtp.remote-ip=2607:f8b0:4864:20::1334 ARC-Seal: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1782630191; cv=none; b=sfVtcReG/A+Q6IBnM6akmM5AHzwQ3pJi7qJ+YF4igWXnJjx8yoo1Hb9aScpFnhDJh8lHRg3qgtKuhrbrn/lsU+qIUxButjhpbsMEHHoV/TMoX6jR2TN1/rWhbit8FLCIjqXUnIuFsYL3ffRvmdNdilp9cEGJn9p7PvCUV9N01m4= ARC-Message-Signature: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1782630191; c=relaxed/simple; bh=PT9KuxdOQmjdiTJRVpvXdwwjjoZnn8JbKf+gyh245dU=; h=DKIM-Signature:From:To:Subject:Date:Message-Id:MIME-Version; b=uAxGf2FYLVwnTER+WSFEg8Nz+UYgEeM/RG/2nUV+6Beqgnz3kJ1MYSeiXfzv1t5+fSgqU/UJpIOEn3bCXw7RwzFMnkoS3wFnH5xRB5Z7ojxS7FmWLas1Tv/ANvCpRdJE1GziM62Tiq39I6jBTomPn5SYNEwKMyrEhGQaroYSHiU= ARC-Authentication-Results: i=1; sourceware.org; dkim=pass (2048-bit key, unprotected) header.d=sifive.com header.i=@sifive.com header.a=rsa-sha256 header.s=google header.b=dBRlHquK DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org 4D5F14BA2E29 Received: by mail-dy1-x1334.google.com with SMTP id 5a478bee46e88-30c965eab27so3618032eec.0 for ; Sun, 28 Jun 2026 00:03:11 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=sifive.com; s=google; t=1782630190; x=1783234990; darn=sourceware.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to; bh=mZKSJtol0O4hGsIKDCgvo2FIXmaXb8XfLl9LAAAZcIM=; b=dBRlHquKyCVX9jgUh6ffGU2TsKyu405REr7iOTe6wI/VTOFSjqKdvkshvZJIXJl8Gw IIfObmU8GK5YPTUKbdL4NgisUTrYqnFK4k+8lmM56AWH7yVgiHNlLPMT52wsw4c3Zi3B KGTojWru9trr5+H1Jmgw0BnMZ2TjNV/3q+LmWHZE0/3I7ary2TuPjrug2KCHhsh7wY0D G9oKUhx4XO4m/D1quV4JO9Uj3ViD3jx/2lXrgpv5gYoYw3Hhg4xvPybRik9hb6wpSQIo sS8lsIBoMu88Fh+rx1dCoDXQrESQrskjElt0rEuaRo8MM0zFLow9QRVzSu6ojN3SVgv0 6MeA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1782630190; x=1783234990; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to; bh=mZKSJtol0O4hGsIKDCgvo2FIXmaXb8XfLl9LAAAZcIM=; b=RC9EoxUNb/SufNqPmBdtdhF8G5Jus9fOxw/NbFZmXP6L/JCvEWLt2ocPEQ2LVrb88v MNrV53QXeDhr8ME/K6EwuxWt6qsxfmPi6V2p+IAlPDy+ki3eCc/P+2fcgGvKlsqdVl6I BsqfUARAlHQ2vg+u708O6TZhry8ySxpghAmmCDaWt6Ul4mZNDIjO2MpT9qVb3TJTQ4/P wQ3eohpsC5j8dvVMUJInKvjTpbwmCtVgVZ/81Bs3ih4soWmXBQWRA2hbz4+pcWAlLIQi CF4+0D+cJdfLJmUzifsnKVV3A/ORo/wE+OzNvXQcENQu2FcbRCSJp8zqfht+nyH4CieN OyLQ== X-Gm-Message-State: AOJu0YwA3/ft+YeP4u8Xb3MZxjA3Gjfu3JgT76kuH6K32PtO79k80tob orEXoGksijsy5ftijpKxJKtfc7Ax177BRjYY1MVRHLXVcztRNpIbU5/cVI6CD15POsbTfpi9sSy VzLRe5Nri0Iu2kgEwDf59YazowtkpXG1HO4HozaYJNy7xq8/iQLRNxuHz+7HDV5m4jCHqNrX/qC hUV5EeVUFqO8Ox2fo+3nOa6nInFme7+LeR3+02nPfChjMcgXh9JY8= X-Gm-Gg: AfdE7cmoDWtGv3KF5KDaHPRvLCGmIpgSRWjdg8yLIhGPFBWOJYk4f6pATGv/OUbY0AY v5N7XYYLQL8Z0B0QZpLhV5CjYCVPj+c8y1CAGRQK7xOGXKv+Akghqr8f1dvV3B8AlCEvffsUO8R Q8+8ZwYmod5PAFRE61zTgnRFwoHhmkRwtDMvqbKetedapT7cLHYzukzRvWDHx0NcwMUUaOR2fsw T/imKed9W8kNTw7ilNBZg6Sxmt31gFUl6q5RQNekGXl8yZjoMcAcm++Gh5G79TA5hHcNL8uL0VX sxcV3QHlpWu/3k63P3eGJYgyt08xO+TbZSFWFMx9S4eX9/p3CjqLk42mTlooOB35LOz1s6hpP9Q o/45JoPopToVCi8QTkOi96197AjEArCmLZC1RiAVEtt9PBot2qOD5LbzIeykFX0ou7+bfM6IADH NSf9n8P+4TIVhsGKwYqvo2H8MmUIEnCw== X-Received: by 2002:a05:7300:7c17:b0:304:de8e:17b with SMTP id 5a478bee46e88-30c84b94fb2mr14070698eec.5.1782630190090; Sun, 28 Jun 2026 00:03:10 -0700 (PDT) Received: from sw08.internal.sifive.com ([4.53.31.132]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-30c7c8afc91sm35435166eec.14.2026.06.28.00.03.08 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 28 Jun 2026 00:03:09 -0700 (PDT) From: Jesse Huang To: libc-alpha@sourceware.org Cc: andrew@sifive.com, darius@bluespec.com, debug@rivosinc.com, jeffreyalaw@gmail.com, kito.cheng@sifive.com, palmer@dabbelt.com, schwab@suse.de, Jesse Huang Subject: [PATCH v5 16/16] riscv/cfi: Add __INDIRECT_RETURN attribute to swapcontext Date: Sun, 28 Jun 2026 00:02:41 -0700 Message-Id: <20260628070241.88310-17-jesse.huang@sifive.com> X-Mailer: git-send-email 2.39.3 In-Reply-To: <20260628070241.88310-1-jesse.huang@sifive.com> References: <20260628070241.88310-1-jesse.huang@sifive.com> MIME-Version: 1.0 X-Spam-Status: No, score=-13.2 required=5.0 tests=BAYES_00, DKIM_SIGNED, DKIM_VALID, DKIM_VALID_AU, DKIM_VALID_EF, GIT_PATCH_0, KAM_SHORT, RCVD_IN_DNSWL_NONE, SPF_HELO_NONE, SPF_PASS, TXREP shortcircuit=no autolearn=ham autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on sourceware.org X-BeenThere: libc-alpha@sourceware.org X-Mailman-Version: 2.1.30 Precedence: list List-Id: Libc-alpha mailing list List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: libc-alpha-bounces~patchwork=sourceware.org@sourceware.org --- sysdeps/riscv/bits/indirect-return.h | 36 ++++++++++++++++++++++++++++ 1 file changed, 36 insertions(+) create mode 100644 sysdeps/riscv/bits/indirect-return.h diff --git a/sysdeps/riscv/bits/indirect-return.h b/sysdeps/riscv/bits/indirect-return.h new file mode 100644 index 0000000000..1d8f658cc8 --- /dev/null +++ b/sysdeps/riscv/bits/indirect-return.h @@ -0,0 +1,36 @@ +/* Definition of __INDIRECT_RETURN. RISC-V version. + Copyright (C) 2026 Free Software Foundation, Inc. + This file is part of the GNU C Library. + + The GNU C Library is free software; you can redistribute it and/or + modify it under the terms of the GNU Lesser General Public + License as published by the Free Software Foundation; either + version 2.1 of the License, or (at your option) any later version. + + The GNU C Library is distributed in the hope that it will be useful, + but WITHOUT ANY WARRANTY; without even the implied warranty of + MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU + Lesser General Public License for more details. + + You should have received a copy of the GNU Lesser General Public + License along with the GNU C Library; if not, see + . */ + +#ifndef _UCONTEXT_H +# error "Never include directly; use instead." +#endif + +/* __INDIRECT_RETURN indicates that swapcontext may return via + an indirect branch. This happens when GCS is enabled, so + add the attribute if available, otherwise returns_twice has + a similar effect, but it prevents some code transformations + that can cause build failures in some rare cases so it is + only used when GCS is enabled. */ +#if __glibc_has_attribute (__indirect_return__) +# define __INDIRECT_RETURN __attribute__ ((__indirect_return__)) +#elif __glibc_has_attribute (__returns_twice__) \ + && defined __ARM_FEATURE_GCS_DEFAULT +# define __INDIRECT_RETURN __attribute__ ((__returns_twice__)) +#else +# define __INDIRECT_RETURN +#endif