From patchwork Mon Mar 15 18:02:23 2021 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Kees Cook X-Patchwork-Id: 12140313 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org X-Spam-Level: X-Spam-Status: No, score=-12.0 required=3.0 tests=BAYES_00,DKIMWL_WL_HIGH, DKIM_SIGNED,DKIM_VALID,HEADER_FROM_DIFFERENT_DOMAINS,INCLUDES_PATCH, MAILING_LIST_MULTI,SPF_HELO_NONE,SPF_PASS,USER_AGENT_GIT autolearn=unavailable autolearn_force=no version=3.4.0 Received: from mail.kernel.org (mail.kernel.org [198.145.29.99]) by smtp.lore.kernel.org (Postfix) with ESMTP id AE63FC433DB for ; Mon, 15 Mar 2021 18:05:34 +0000 (UTC) Received: from desiato.infradead.org (desiato.infradead.org [90.155.92.199]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mail.kernel.org (Postfix) with ESMTPS id 3660964F2A for ; Mon, 15 Mar 2021 18:05:34 +0000 (UTC) DMARC-Filter: OpenDMARC Filter v1.3.2 mail.kernel.org 3660964F2A Authentication-Results: mail.kernel.org; dmarc=fail (p=none dis=none) header.from=chromium.org Authentication-Results: mail.kernel.org; spf=none smtp.mailfrom=linux-arm-kernel-bounces+linux-arm-kernel=archiver.kernel.org@lists.infradead.org DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.infradead.org; s=desiato.20200630; h=Sender:Content-Transfer-Encoding :Content-Type:List-Subscribe:List-Help:List-Post:List-Archive: List-Unsubscribe:List-Id:MIME-Version:Message-Id:Date:Subject:Cc:To:From: Reply-To:Content-ID:Content-Description:Resent-Date:Resent-From:Resent-Sender :Resent-To:Resent-Cc:Resent-Message-ID:In-Reply-To:References:List-Owner; bh=ay/hmKmvMDeD+q+1cHRIu4U4DfnSzjwkGtvJ0fhGKIs=; b=cZIrRiKiEMQ4MBjUib/BvTlD8C LF7MLcXXLKPV3TkwUHO7bGzv073JSFqBnmbOcSoCfS8G4t3DR5HPREwTV4+KaX3vT/Sz8PWRHcMuZ HWwD1o0HktgqPkNa0TeyNeek9XPwALXddx2SFRI7HLygdQzs4nEOyrVKLcnUrsMewvK4rUTjADvBH ehSs4o86clfHQrxaM36cLv8ADSLPe3hiZ2P0KZ3GM5qI8P4AHdc/UfKEtgS16zxklX77OYIX6HI3x qfIpP/TXfRX1fY7QTrmoXre8Qt39syiSYe7kVWtsVoeTkIDlmFahIF4XEo0Jqs9RDeHFaFdWdpzrS ZuZjh1hg==; Received: from localhost ([::1] helo=desiato.infradead.org) by desiato.infradead.org with esmtp (Exim 4.94 #2 (Red Hat Linux)) id 1lLrZ4-00GcyC-Gq; Mon, 15 Mar 2021 18:03:38 +0000 Received: from mail-pj1-x1032.google.com ([2607:f8b0:4864:20::1032]) by desiato.infradead.org with esmtps (Exim 4.94 #2 (Red Hat Linux)) id 1lLrY6-00Gchk-70 for linux-arm-kernel@lists.infradead.org; Mon, 15 Mar 2021 18:02:46 +0000 Received: by mail-pj1-x1032.google.com with SMTP id q6-20020a17090a4306b02900c42a012202so15220566pjg.5 for ; Mon, 15 Mar 2021 11:02:37 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=chromium.org; s=google; h=from:to:cc:subject:date:message-id:mime-version :content-transfer-encoding; bh=D9ES74tRjQPkQDGloZkJ7JzGqh/Rg5vOjLPTTzfWrnU=; b=nkyWI5GSq3VOZgbrSe5HgKjUqcwdRVsFgjMiU8cCOXgYni5mOUx2JpvpUeGfEIzjVc /EApzc0zoetCk9N/rKUGLhHwqdDHx/41U8LrjrtmFadM02lCoJ/nZFJdX85vtFgWgnHI h+0okdA6lvkzr6gdZBtYETfjATYKmdov+9h6Q= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:to:cc:subject:date:message-id:mime-version :content-transfer-encoding; bh=D9ES74tRjQPkQDGloZkJ7JzGqh/Rg5vOjLPTTzfWrnU=; b=IfGyqj+q4JowYbZQ1aajKNL4qUIfdFb6JWglgbL4Tz9Zn3mW7bs6ZY88OcMz1N2ZpQ 7rmc1LyFy4ax6ffwWSP1EngoYOn3/z0B2qvu7bz07e0sj7hFLa9VslP8I26c8rqNRGVj ufNtbWVusz1WuAoz5MAGif3dDcLjazTpozxejP/BXRKkewRMhjSat29rBmAjw8k3Nl9t ehKt4Aac9/TwgdC0557v5AU8d0zBEqDY+7TDtZzLdxyZKsnt1rqE5koM428OIQ2Zm3fC GbAPaJGKzAulf7+lBMX4kZahcCwCqoiDgNnmTEzMp9nanVSlE0ymLQKSqXzwdvFnKnu3 Z6rA== X-Gm-Message-State: AOAM5319MYF+oh+T07PXaQJAGtMPN9w9PdRvd1ygtScAKg8Zra8vKzzY rIsZ2p71ynADsd9K1JfsEmWaig== X-Google-Smtp-Source: ABdhPJwdcjtS5Z2P+DmTf0KAvanjziv2viUkjFPb2OQot1M+A70P++yEN5oAbiQpcrSGAjwehcCvpA== X-Received: by 2002:a17:90a:2c09:: with SMTP id m9mr300524pjd.3.1615831356695; Mon, 15 Mar 2021 11:02:36 -0700 (PDT) Received: from www.outflux.net (smtp.outflux.net. [198.145.64.163]) by smtp.gmail.com with ESMTPSA id l4sm13890800pgi.19.2021.03.15.11.02.35 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 15 Mar 2021 11:02:35 -0700 (PDT) From: Kees Cook To: Thomas Gleixner Cc: Kees Cook , Elena Reshetova , x86@kernel.org, Andy Lutomirski , Peter Zijlstra , Catalin Marinas , Will Deacon , Mark Rutland , Alexander Potapenko , Alexander Popov , Ard Biesheuvel , Jann Horn , Vlastimil Babka , David Hildenbrand , Mike Rapoport , Andrew Morton , Jonathan Corbet , Randy Dunlap , kernel-hardening@lists.openwall.com, linux-hardening@vger.kernel.org, linux-arm-kernel@lists.infradead.org, linux-mm@kvack.org, linux-kernel@vger.kernel.org Subject: [PATCH v6 0/6] Optionally randomize kernel stack offset each syscall Date: Mon, 15 Mar 2021 11:02:23 -0700 Message-Id: <20210315180229.1224655-1-keescook@chromium.org> X-Mailer: git-send-email 2.25.1 MIME-Version: 1.0 X-CRM114-Version: 20100106-BlameMichelson ( TRE 0.8.0 (BSD) ) MR-646709E3 X-CRM114-CacheID: sfid-20210315_180238_549458_6D76743E X-CRM114-Status: GOOD ( 18.37 ) X-BeenThere: linux-arm-kernel@lists.infradead.org X-Mailman-Version: 2.1.34 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Sender: "linux-arm-kernel" Errors-To: linux-arm-kernel-bounces+linux-arm-kernel=archiver.kernel.org@lists.infradead.org v6: - rearrange jump_label and init_on_* changes (akpm) - add slab init_on_* static branches (andreyknvl) v5: https://lore.kernel.org/lkml/20210309214301.678739-1-keescook@chromium.org/ v4: https://lore.kernel.org/lkml/20200622193146.2985288-1-keescook@chromium.org/ v3: https://lore.kernel.org/lkml/20200406231606.37619-1-keescook@chromium.org/ v2: https://lore.kernel.org/lkml/20200324203231.64324-1-keescook@chromium.org/ rfc: https://lore.kernel.org/kernel-hardening/20190329081358.30497-1-elena.reshetova@intel.com/ Hi, This is a continuation and refactoring of Elena's earlier effort to add kernel stack base offset randomization. In the time since the earlier discussions, two attacks[1][2] were made public that depended on stack determinism, so we're no longer in the position of "this is a good idea but we have no examples of attacks". :) Earlier discussions also devolved into debates on entropy sources, which is mostly a red herring, given the already low entropy available due to stack size. Regardless, entropy can be changed/improved separately from this series as needed. Earlier discussions also got stuck debating how much syscall overhead was too much, but this is also a red herring since the feature itself needs to be selectable at boot with no cost for those that don't want it: this is solved here with static branches. So, here is the latest improved version, made as arch-agnostic as possible, with usage added for x86 and arm64. It also includes some small static branch clean ups, and addresses some surprise performance issues due to the stack canary[3]. At the very least, the first two patches can land separately (already Acked and Reviewed), since they're kind of "separate", but introduce macros that are used in the core stack changes. If I can get an Ack from an arm64 maintainer, I think this could all land via -tip to make merging easiest. Thanks! -Kees [1] https://a13xp0p0v.github.io/2020/02/15/CVE-2019-18683.html [2] https://repositorio-aberto.up.pt/bitstream/10216/125357/2/374717.pdf [3] https://lore.kernel.org/lkml/202003281520.A9BFF461@keescook/ Kees Cook (6): jump_label: Provide CONFIG-driven build state defaults init_on_alloc: Optimize static branches stack: Optionally randomize kernel stack offset each syscall x86/entry: Enable random_kstack_offset support arm64: entry: Enable random_kstack_offset support lkdtm: Add REPORT_STACK for checking stack offsets .../admin-guide/kernel-parameters.txt | 11 +++++ Makefile | 4 ++ arch/Kconfig | 23 ++++++++++ arch/arm64/Kconfig | 1 + arch/arm64/kernel/Makefile | 5 +++ arch/arm64/kernel/syscall.c | 10 +++++ arch/x86/Kconfig | 1 + arch/x86/entry/common.c | 3 ++ arch/x86/include/asm/entry-common.h | 8 ++++ drivers/misc/lkdtm/bugs.c | 17 ++++++++ drivers/misc/lkdtm/core.c | 1 + drivers/misc/lkdtm/lkdtm.h | 1 + include/linux/jump_label.h | 19 +++++++++ include/linux/mm.h | 10 +++-- include/linux/randomize_kstack.h | 42 +++++++++++++++++++ init/main.c | 23 ++++++++++ mm/page_alloc.c | 4 +- mm/slab.h | 6 ++- 18 files changed, 181 insertions(+), 8 deletions(-) create mode 100644 include/linux/randomize_kstack.h