From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1030225AbbLRVFH (ORCPT ); Fri, 18 Dec 2015 16:05:07 -0500 Received: from mail-pa0-f53.google.com ([209.85.220.53]:35042 "EHLO mail-pa0-f53.google.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S965354AbbLRVFC (ORCPT ); Fri, 18 Dec 2015 16:05:02 -0500 Date: Fri, 18 Dec 2015 13:04:59 -0800 From: Kees Cook To: Russell King Cc: linux-kernel@vger.kernel.org, Jeffy , Simon Horman , Geert Uytterhoeven , Laurent Pinchart , Magnus Damm , Arnd Bergmann , linux-arm-kernel@lists.infradead.org Subject: [PATCH] ARM: fix atags_to_fdt with stack-protector-strong Message-ID: <20151218210459.GA23293@www.outflux.net> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org Building with CONFIG_CC_STACKPROTECTOR_STRONG triggers protection code generation under CONFIG_ARM_ATAG_DTB_COMPAT but this is too early for being able to use any of the stack_chk code. Explicitly disable it for only the atags_to_fdt bits. Suggested-by: zhxihu Signed-off-by: Kees Cook --- arch/arm/boot/compressed/Makefile | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/arch/arm/boot/compressed/Makefile b/arch/arm/boot/compressed/Makefile index 3f9a9ebc77c3..8cfbc4a2090b 100644 --- a/arch/arm/boot/compressed/Makefile +++ b/arch/arm/boot/compressed/Makefile @@ -106,6 +106,14 @@ ORIG_CFLAGS := $(KBUILD_CFLAGS) KBUILD_CFLAGS = $(subst -pg, , $(ORIG_CFLAGS)) endif +ifeq ($(CONFIG_ARM_ATAG_DTB_COMPAT),y) +CFLAGS_atags_to_fdt.o := -fno-stack-protector +CFLAGS_fdt.o := -fno-stack-protector +CFLAGS_fdt_ro.o := -fno-stack-protector +CFLAGS_fdt_rw.o := -fno-stack-protector +CFLAGS_fdt_wip.o := -fno-stack-protector +endif + ccflags-y := -fpic -mno-single-pic-base -fno-builtin -I$(obj) asflags-y := -DZIMAGE -- 2.6.3 -- Kees Cook Chrome OS & Brillo Security