From patchwork Tue Oct 29 23:44:09 2024 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Deepak Gupta X-Patchwork-Id: 13855725 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from kanga.kvack.org (kanga.kvack.org [205.233.56.17]) by smtp.lore.kernel.org (Postfix) with ESMTP id 5117ED7494E for ; Tue, 29 Oct 2024 23:44:44 +0000 (UTC) Received: by kanga.kvack.org (Postfix) id AF7FD6B00A2; Tue, 29 Oct 2024 19:44:42 -0400 (EDT) Received: by kanga.kvack.org (Postfix, from userid 40) id AA2DC6B00A3; Tue, 29 Oct 2024 19:44:42 -0400 (EDT) X-Delivered-To: int-list-linux-mm@kvack.org Received: by kanga.kvack.org (Postfix, from userid 63042) id 8F6626B00A4; Tue, 29 Oct 2024 19:44:42 -0400 (EDT) X-Delivered-To: linux-mm@kvack.org Received: from relay.hostedemail.com (smtprelay0015.hostedemail.com [216.40.44.15]) by kanga.kvack.org (Postfix) with ESMTP id 6B1006B00A2 for ; Tue, 29 Oct 2024 19:44:42 -0400 (EDT) Received: from smtpin14.hostedemail.com (a10.router.float.18 [10.200.18.1]) by unirelay08.hostedemail.com (Postfix) with ESMTP id 302DD140820 for ; Tue, 29 Oct 2024 23:44:42 +0000 (UTC) X-FDA: 82728271752.14.3C1A929 Received: from mail-pf1-f169.google.com (mail-pf1-f169.google.com [209.85.210.169]) by imf25.hostedemail.com (Postfix) with ESMTP id 514B2A0022 for ; Tue, 29 Oct 2024 23:44:22 +0000 (UTC) Authentication-Results: imf25.hostedemail.com; dkim=pass header.d=rivosinc-com.20230601.gappssmtp.com header.s=20230601 header.b=0ov1IlhB; spf=pass (imf25.hostedemail.com: domain of debug@rivosinc.com designates 209.85.210.169 as permitted sender) smtp.mailfrom=debug@rivosinc.com; dmarc=none ARC-Seal: i=1; s=arc-20220608; d=hostedemail.com; t=1730245399; a=rsa-sha256; cv=none; b=u6OHWfXpFDimcP8DTmKmhn4mM20ePqLEZw/YWmGGbPB01PtVY14tnpGgEbotrnyqgMEJTD 9s08QrI8E+jqBrwOmyOwW8cGPGxKDzKLMbwPF7+Aa0GGYWXccm2Jan0CuZNU2AebzZWVcZ TSm90izYPcQ4MlYO6Hg4W6cmPwdCTec= ARC-Authentication-Results: i=1; imf25.hostedemail.com; dkim=pass header.d=rivosinc-com.20230601.gappssmtp.com header.s=20230601 header.b=0ov1IlhB; spf=pass (imf25.hostedemail.com: domain of debug@rivosinc.com designates 209.85.210.169 as permitted sender) smtp.mailfrom=debug@rivosinc.com; dmarc=none ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=hostedemail.com; s=arc-20220608; t=1730245399; h=from:from:sender:reply-to:subject:subject:date:date: message-id:message-id:to:to:cc:cc:mime-version:mime-version: content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references:dkim-signature; bh=SNfZZs476YzcsSH6yeSdP6ZT36oaA2c3QmON0KQSDC4=; b=KQ6QcYBK6dCAG4Dc1oydBLQWyOp14IleG2vTbe18I0AyOcl5Prm3OvFc8y5toqrXmZmB5t Z+Sq5t9Fl18j7TvPa3MJfk5qDUCX2Vka6sZ0BdCcvawwM2bR/LDNs7bXpd5G1mHIi5nbpO D7wQzZuQ9QIDxOVexxkQVDt5EEm5CEk= Received: by mail-pf1-f169.google.com with SMTP id d2e1a72fcca58-71e592d7f6eso4199694b3a.3 for ; Tue, 29 Oct 2024 16:44:39 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=rivosinc-com.20230601.gappssmtp.com; s=20230601; t=1730245479; x=1730850279; darn=kvack.org; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :mime-version:subject:date:from:from:to:cc:subject:date:message-id :reply-to; bh=SNfZZs476YzcsSH6yeSdP6ZT36oaA2c3QmON0KQSDC4=; b=0ov1IlhBCD7wZYUBMDxiLyPL2Ih3rmuip9eE7pgrolsEyOLAHreB6I0KUXaHKg/jlk 1PCfus0mwPG2xwcgYQv+jTkowBKONFXYzUYNzyluQ3mBZGcuIT6DlMNGBmAO08xE2d/c 1cw+xV3di8zU9YUiPZZuw/K1Hq6Ze1kEy0B9EW9gzO0GgS92ON3U7auaYh+i1hZQTgPg Hl1DO9MbWTQ6ZLOusiMq/m+Njynn1p8N+nu07ByNEv+/ncwRtOy1o2W/jN9RT8X3i0j1 qVBgSNpwn7GGBZBENnrOkzxRc8VNqXxfniTFXlH0SzBj9nyPAZVJRXiz9N3RLwpY7XP9 H6/Q== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1730245479; x=1730850279; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :mime-version:subject:date:from:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to; bh=SNfZZs476YzcsSH6yeSdP6ZT36oaA2c3QmON0KQSDC4=; b=UaLUmyT0jyuDI6d6gPbDRA0+54aqHOCPHnKDacYqp2NwZe60Oe3fqGDrmymEbcLhKh shHTPePRkBrtDhzCX7vJTDG5BSxNiO+/dHbmZmTCbz2dmZHahT2PRyKrtx2+VKk1qObB a8O7tytmH2E4312oQz3nde0yH6/nBP8SlveT7LcqPn56PYjNn/xtM9syFed+EL7k8KnG dJs7YjpMIfxcPUZOj6MSlUfBHbj3LskRoyVsQ5XUk5zPpNGr5od8MaJEIblVFwJ17GB0 gjim5t9zD2im9S6SK10vC3r46EzPchX2LmBMcAGg4BJPsdGe0AuK6YLnAfsp+tpXbmtZ 4NOA== X-Forwarded-Encrypted: i=1; AJvYcCXS7nOZmvOWwKFfEDU75+/ijcKkOpSLtb2UqwY5gdG04jE8LD7KEmyRTkMfB1gVVzcb4PUhCxqGiw==@kvack.org X-Gm-Message-State: AOJu0YyP1FVr7zBkh4HILhnrCGAm/7Jru2HBh5+uNcZ+xEdCA5pYWi9V heNGmWin1nUVXfnYyKOqYyMU9PQYRXzVi3X5ze6MuutooPWC3oVYmwRxN23BG/M= X-Google-Smtp-Source: AGHT+IFWMMLwtG8UV6QhOdFu9KwNMwuiaXKBVbMM5qrfFdip4zC2zSk3P3saktQ5u5KEFmifDMFhVg== X-Received: by 2002:a05:6a00:b54:b0:710:6e83:cd5e with SMTP id d2e1a72fcca58-72062ab834amr19403115b3a.0.1730245479084; Tue, 29 Oct 2024 16:44:39 -0700 (PDT) Received: from debug.ba.rivosinc.com ([64.71.180.162]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-72057921863sm8157643b3a.33.2024.10.29.16.44.36 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 29 Oct 2024 16:44:38 -0700 (PDT) From: Deepak Gupta Date: Tue, 29 Oct 2024 16:44:09 -0700 Subject: [PATCH v7 09/32] riscv: usercfi state for task and save/restore of CSR_SSP on trap entry/exit MIME-Version: 1.0 Message-Id: <20241029-v5_user_cfi_series-v7-9-2727ce9936cb@rivosinc.com> References: <20241029-v5_user_cfi_series-v7-0-2727ce9936cb@rivosinc.com> In-Reply-To: <20241029-v5_user_cfi_series-v7-0-2727ce9936cb@rivosinc.com> To: Thomas Gleixner , Ingo Molnar , Borislav Petkov , Dave Hansen , x86@kernel.org, "H. Peter Anvin" , Andrew Morton , "Liam R. Howlett" , Vlastimil Babka , Lorenzo Stoakes , Paul Walmsley , Palmer Dabbelt , Albert Ou , Conor Dooley , Rob Herring , Krzysztof Kozlowski , Arnd Bergmann , Christian Brauner , Peter Zijlstra , Oleg Nesterov , Eric Biederman , Kees Cook , Jonathan Corbet , Shuah Khan Cc: linux-kernel@vger.kernel.org, linux-fsdevel@vger.kernel.org, linux-mm@kvack.org, linux-riscv@lists.infradead.org, devicetree@vger.kernel.org, linux-arch@vger.kernel.org, linux-doc@vger.kernel.org, linux-kselftest@vger.kernel.org, alistair.francis@wdc.com, richard.henderson@linaro.org, jim.shu@sifive.com, andybnac@gmail.com, kito.cheng@sifive.com, charlie@rivosinc.com, atishp@rivosinc.com, evan@rivosinc.com, cleger@rivosinc.com, alexghiti@rivosinc.com, samitolvanen@google.com, broonie@kernel.org, rick.p.edgecombe@intel.com, Deepak Gupta X-Mailer: b4 0.14.0 X-Stat-Signature: 3e1a8ybjkwqyh859tj1rhurhsbjnwpam X-Rspamd-Queue-Id: 514B2A0022 X-Rspam-User: X-Rspamd-Server: rspam10 X-HE-Tag: 1730245462-751967 X-HE-Meta: U2FsdGVkX1/0xUjcBqttDNo7k02i0ZR4OoFlkEJKtyvRI2GHc8h3Fc/mLXKyQX0gZu3eoq4oFQWQC8BkgHs+MudDvJtHp4AmRKYVUR+JWzm5PP/Qi4RBf525PaRyKiRsaOD8Jc3rknOrrfJrKSJvrElWQTTEic+/yTfRT/UM1aorvPTjZUF6rYwSzyb38HqabUB9Fjl0WyfrLgtEZZUIbA/Mv4gLYbghsU9+Sjj1aeMmrEwuyBqS+o+dm0YrJKAK5PI1hb/gEuYQX5nR2Cw8xUevty51/iDkzsDxCW+pj7mDzzCzDnqdouOyLqvev7+d2F700xpU/P2Z6RBfyP2ytmxJozW2IMj8+eIY6JCo0Dp+qMHhs7x9rYkFWPl10JfujeLtrY4eqmDZmAHLbfVj9nhPZCwCLqnq3EXh19X5YbTbCHPJTBKfj/k9tvzva7sL0tZ8y/nxxJiTBgQQkotHMh2XVt3YbWls4oA+PP176yIcEluCkjZYpc8SVD2tQTnEZois/RrDturHGl0xayaB9wmCdCs1/9Ctoqg1WWq34sNczmVwrn0SnGaZL9uGZaJ3BX044GiA8XR/CHWm8YxMicin2TH3AUvcxGh1W2r9p+EeD5iAdPJMea2PA9U8jZ8o+efujNKLyT+seW9WJNa2somOY6Zp9cA0zlDDcxyjYYAnkxQV6/YKBAoqWAnuceS1duIPKLKJWN6IozCoAldxfzWPVpxGiToHnIspri7bUgTNDx8+tPzxs3Ddyop0n4pFSdRaeUzdhh4BbsRaNXOUs5FTFZq6MpJQs3tg4diwArjW4vOomNYGXxKCfhcNyzbyTfQpzm2O8mrfMPQXOnnIORRFuyJbfhJEwoRLHH5ndGEzYRH5LKI8lTWoDMWljNMyE8OWS5x6p5LmfPI3LE8CFB9b8IkxhnIM+8E0tq+VOtlH6h/d7ChpJkrsRuZz2KyQPwepX/6TU0lfkVbPfT9 g4uqT5T2 Hwpq03Gv/iK0J+QG82GfPWtKrzwpzneAAqkOql5ffQKvVUrxdZfS2XgN53ilUx7ydS07Bb75+OamiEGq2dJbj5Jcei4PR35CV9/46Si6tyXULeOYXcWIdFCERfaMVnmk8QGKxPGCbIY2FyD7s0WjV/VKB166SGsRbmv+PQ3vUogVFebrVWG7/yk9+myK3g34x34GuowpxlKplTDcOTNaKWXwkBJx4JLtZ/OCasRZR0WPYp1GjWBRGbZlv44S1jYNsyf6ftdajab5ggXVuEM0BkZqdA4sC/xNmHGYbT4bm6eduSKTczCOoDaH6daumEGhGeDmWk654QUnIGgKCPYd4e5wLjZhhZ7CqkNMWb/+FyHt5+myY/86rlOVmP6INwtxjkXHEcivA/W4lBxtIEWBqP+isfazAWswGSmmbTA64zGIks4uoZmosnHlnXuDKFsVG9LSsb6y4jRnyVItq2skaqDKF2zlcjJGovhPWIq5zhjVsEEFNte3oYUCN4RYBRUGV9YaIfFb3wnm2WA05QSW8+3+LZB/dhsQj7ZARtUy+c0xdE1k= X-Bogosity: Ham, tests=bogofilter, spamicity=0.000000, version=1.2.4 Sender: owner-linux-mm@kvack.org Precedence: bulk X-Loop: owner-majordomo@kvack.org List-ID: List-Subscribe: List-Unsubscribe: Carves out space in arch specific thread struct for cfi status and shadow stack in usermode on riscv. This patch does following - defines a new structure cfi_status with status bit for cfi feature - defines shadow stack pointer, base and size in cfi_status structure - defines offsets to new member fields in thread in asm-offsets.c - Saves and restore shadow stack pointer on trap entry (U --> S) and exit (S --> U) Shadow stack save/restore is gated on feature availiblity and implemented using alternative. CSR can be context switched in `switch_to` as well but soon as kernel shadow stack support gets rolled in, shadow stack pointer will need to be switched at trap entry/exit point (much like `sp`). It can be argued that kernel using shadow stack deployment scenario may not be as prevalant as user mode using this feature. But even if there is some minimal deployment of kernel shadow stack, that means that it needs to be supported. And thus save/restore of shadow stack pointer in entry.S instead of in `switch_to.h`. Signed-off-by: Deepak Gupta Reviewed-by: Charlie Jenkins --- arch/riscv/include/asm/processor.h | 1 + arch/riscv/include/asm/thread_info.h | 3 +++ arch/riscv/include/asm/usercfi.h | 24 ++++++++++++++++++++++++ arch/riscv/kernel/asm-offsets.c | 4 ++++ arch/riscv/kernel/entry.S | 26 ++++++++++++++++++++++++++ 5 files changed, 58 insertions(+) diff --git a/arch/riscv/include/asm/processor.h b/arch/riscv/include/asm/processor.h index aec3466a389c..5a8031384021 100644 --- a/arch/riscv/include/asm/processor.h +++ b/arch/riscv/include/asm/processor.h @@ -14,6 +14,7 @@ #include #include +#include #define arch_get_mmap_end(addr, len, flags) \ ({ \ diff --git a/arch/riscv/include/asm/thread_info.h b/arch/riscv/include/asm/thread_info.h index ebe52f96da34..12263cef7518 100644 --- a/arch/riscv/include/asm/thread_info.h +++ b/arch/riscv/include/asm/thread_info.h @@ -57,6 +57,9 @@ struct thread_info { long user_sp; /* User stack pointer */ int cpu; unsigned long syscall_work; /* SYSCALL_WORK_ flags */ +#ifdef CONFIG_RISCV_USER_CFI + struct cfi_status user_cfi_state; +#endif #ifdef CONFIG_SHADOW_CALL_STACK void *scs_base; void *scs_sp; diff --git a/arch/riscv/include/asm/usercfi.h b/arch/riscv/include/asm/usercfi.h new file mode 100644 index 000000000000..4fa201b4fc4e --- /dev/null +++ b/arch/riscv/include/asm/usercfi.h @@ -0,0 +1,24 @@ +/* SPDX-License-Identifier: GPL-2.0 + * Copyright (C) 2024 Rivos, Inc. + * Deepak Gupta + */ +#ifndef _ASM_RISCV_USERCFI_H +#define _ASM_RISCV_USERCFI_H + +#ifndef __ASSEMBLY__ +#include + +#ifdef CONFIG_RISCV_USER_CFI +struct cfi_status { + unsigned long ubcfi_en : 1; /* Enable for backward cfi. */ + unsigned long rsvd : ((sizeof(unsigned long)*8) - 1); + unsigned long user_shdw_stk; /* Current user shadow stack pointer */ + unsigned long shdw_stk_base; /* Base address of shadow stack */ + unsigned long shdw_stk_size; /* size of shadow stack */ +}; + +#endif /* CONFIG_RISCV_USER_CFI */ + +#endif /* __ASSEMBLY__ */ + +#endif /* _ASM_RISCV_USERCFI_H */ diff --git a/arch/riscv/kernel/asm-offsets.c b/arch/riscv/kernel/asm-offsets.c index e94180ba432f..766bd33f10cb 100644 --- a/arch/riscv/kernel/asm-offsets.c +++ b/arch/riscv/kernel/asm-offsets.c @@ -52,6 +52,10 @@ void asm_offsets(void) #endif OFFSET(TASK_TI_CPU_NUM, task_struct, thread_info.cpu); +#ifdef CONFIG_RISCV_USER_CFI + OFFSET(TASK_TI_CFI_STATUS, task_struct, thread_info.user_cfi_state); + OFFSET(TASK_TI_USER_SSP, task_struct, thread_info.user_cfi_state.user_shdw_stk); +#endif OFFSET(TASK_THREAD_F0, task_struct, thread.fstate.f[0]); OFFSET(TASK_THREAD_F1, task_struct, thread.fstate.f[1]); OFFSET(TASK_THREAD_F2, task_struct, thread.fstate.f[2]); diff --git a/arch/riscv/kernel/entry.S b/arch/riscv/kernel/entry.S index c200d329d4bd..8f7f477517e3 100644 --- a/arch/riscv/kernel/entry.S +++ b/arch/riscv/kernel/entry.S @@ -147,6 +147,20 @@ SYM_CODE_START(handle_exception) REG_L s0, TASK_TI_USER_SP(tp) csrrc s1, CSR_STATUS, t0 + /* + * If previous mode was U, capture shadow stack pointer and save it away + * Zero CSR_SSP at the same time for sanitization. + */ + ALTERNATIVE("nop; nop; nop; nop", + __stringify( \ + andi s2, s1, SR_SPP; \ + bnez s2, skip_ssp_save; \ + csrrw s2, CSR_SSP, x0; \ + REG_S s2, TASK_TI_USER_SSP(tp); \ + skip_ssp_save:), + 0, + RISCV_ISA_EXT_ZICFISS, + CONFIG_RISCV_USER_CFI) csrr s2, CSR_EPC csrr s3, CSR_TVAL csrr s4, CSR_CAUSE @@ -236,6 +250,18 @@ SYM_CODE_START_NOALIGN(ret_from_exception) * structures again. */ csrw CSR_SCRATCH, tp + + /* + * Going back to U mode, restore shadow stack pointer + */ + ALTERNATIVE("nop; nop", + __stringify( \ + REG_L s3, TASK_TI_USER_SSP(tp); \ + csrw CSR_SSP, s3), + 0, + RISCV_ISA_EXT_ZICFISS, + CONFIG_RISCV_USER_CFI) + 1: #ifdef CONFIG_RISCV_ISA_V_PREEMPTIVE move a0, sp