* Re: [PATCH] objtool,x86: Fix uaccess PUSHF/POPF validation
[not found] <YEY4rIbQYa5fnnEp@hirez.programming.kicks-ass.net>
@ 2021-03-10 11:19 ` Peter Zijlstra
2021-03-12 8:27 ` [tip: objtool/urgent] " tip-bot2 for Peter Zijlstra
1 sibling, 0 replies; 2+ messages in thread
From: Peter Zijlstra @ 2021-03-10 11:19 UTC (permalink / raw)
To: x86, Josh Poimboeuf; +Cc: jgross, linux-kernel
Seems like I forgot LKML (again!)...
On Mon, Mar 08, 2021 at 03:46:04PM +0100, Peter Zijlstra wrote:
>
> Commit ab234a260b1f ("x86/pv: Rework arch_local_irq_restore() to not
> use popf") replaced "push %reg; popf" with something like: "test
> $0x200, %reg; jz 1f; sti; 1:", which breaks the pushf/popf symmetry
> that commit ea24213d8088 ("objtool: Add UACCESS validation") relies
> on.
>
> The result is:
>
> drivers/gpu/drm/amd/amdgpu/si.o: warning: objtool: si_common_hw_init()+0xf36: PUSHF stack exhausted
>
> Meanwhile, commit c9c324dc22aa ("objtool: Support stack layout changes
> in alternatives") makes that we can actually use stack-ops in
> alternatives, which means we can revert 1ff865e343c2 ("x86,smap: Fix
> smap_{save,restore}() alternatives").
>
> That in turn means we can limit the PUSHF/POPF handling of
> ea24213d8088 to those instructions that are in alternatives.
>
> Fixes: ab234a260b1f ("x86/pv: Rework arch_local_irq_restore() to not use popf")
> Reported-by: Borislav Petkov <bp@alien8.de>
> Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org>
> ---
> arch/x86/include/asm/smap.h | 10 ++++------
> tools/objtool/check.c | 3 +++
> 2 files changed, 7 insertions(+), 6 deletions(-)
>
> --- a/arch/x86/include/asm/smap.h
> +++ b/arch/x86/include/asm/smap.h
> @@ -58,9 +58,8 @@ static __always_inline unsigned long sma
> unsigned long flags;
>
> asm volatile ("# smap_save\n\t"
> - ALTERNATIVE("jmp 1f", "", X86_FEATURE_SMAP)
> - "pushf; pop %0; " __ASM_CLAC "\n\t"
> - "1:"
> + ALTERNATIVE("", "pushf; pop %0; " __ASM_CLAC "\n\t",
> + X86_FEATURE_SMAP)
> : "=rm" (flags) : : "memory", "cc");
>
> return flags;
> @@ -69,9 +68,8 @@ static __always_inline unsigned long sma
> static __always_inline void smap_restore(unsigned long flags)
> {
> asm volatile ("# smap_restore\n\t"
> - ALTERNATIVE("jmp 1f", "", X86_FEATURE_SMAP)
> - "push %0; popf\n\t"
> - "1:"
> + ALTERNATIVE("", "push %0; popf\n\t",
> + X86_FEATURE_SMAP)
> : : "g" (flags) : "memory", "cc");
> }
>
> --- a/tools/objtool/check.c
> +++ b/tools/objtool/check.c
> @@ -2425,6 +2425,9 @@ static int handle_insn_ops(struct instru
> if (update_cfi_state(insn, next_insn, &state->cfi, op))
> return 1;
>
> + if (!insn->alt_group)
> + continue;
> +
> if (op->dest.type == OP_DEST_PUSHF) {
> if (!state->uaccess_stack) {
> state->uaccess_stack = 1;
^ permalink raw reply [flat|nested] 2+ messages in thread* [tip: objtool/urgent] objtool,x86: Fix uaccess PUSHF/POPF validation
[not found] <YEY4rIbQYa5fnnEp@hirez.programming.kicks-ass.net>
2021-03-10 11:19 ` [PATCH] objtool,x86: Fix uaccess PUSHF/POPF validation Peter Zijlstra
@ 2021-03-12 8:27 ` tip-bot2 for Peter Zijlstra
1 sibling, 0 replies; 2+ messages in thread
From: tip-bot2 for Peter Zijlstra @ 2021-03-12 8:27 UTC (permalink / raw)
To: linux-tip-commits
Cc: Borislav Petkov, Peter Zijlstra (Intel),
Josh Poimboeuf, x86, linux-kernel
The following commit has been merged into the objtool/urgent branch of tip:
Commit-ID: ba08abca66d46381df60842f64f70099d5482b92
Gitweb: https://git.kernel.org/tip/ba08abca66d46381df60842f64f70099d5482b92
Author: Peter Zijlstra <peterz@infradead.org>
AuthorDate: Mon, 08 Mar 2021 15:46:04 +01:00
Committer: Peter Zijlstra <peterz@infradead.org>
CommitterDate: Fri, 12 Mar 2021 09:15:49 +01:00
objtool,x86: Fix uaccess PUSHF/POPF validation
Commit ab234a260b1f ("x86/pv: Rework arch_local_irq_restore() to not
use popf") replaced "push %reg; popf" with something like: "test
$0x200, %reg; jz 1f; sti; 1:", which breaks the pushf/popf symmetry
that commit ea24213d8088 ("objtool: Add UACCESS validation") relies
on.
The result is:
drivers/gpu/drm/amd/amdgpu/si.o: warning: objtool: si_common_hw_init()+0xf36: PUSHF stack exhausted
Meanwhile, commit c9c324dc22aa ("objtool: Support stack layout changes
in alternatives") makes that we can actually use stack-ops in
alternatives, which means we can revert 1ff865e343c2 ("x86,smap: Fix
smap_{save,restore}() alternatives").
That in turn means we can limit the PUSHF/POPF handling of
ea24213d8088 to those instructions that are in alternatives.
Fixes: ab234a260b1f ("x86/pv: Rework arch_local_irq_restore() to not use popf")
Reported-by: Borislav Petkov <bp@alien8.de>
Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Acked-by: Josh Poimboeuf <jpoimboe@redhat.com>
Link: https://lkml.kernel.org/r/YEY4rIbQYa5fnnEp@hirez.programming.kicks-ass.net
---
arch/x86/include/asm/smap.h | 10 ++++------
tools/objtool/check.c | 3 +++
2 files changed, 7 insertions(+), 6 deletions(-)
diff --git a/arch/x86/include/asm/smap.h b/arch/x86/include/asm/smap.h
index 8b58d69..0bc9b08 100644
--- a/arch/x86/include/asm/smap.h
+++ b/arch/x86/include/asm/smap.h
@@ -58,9 +58,8 @@ static __always_inline unsigned long smap_save(void)
unsigned long flags;
asm volatile ("# smap_save\n\t"
- ALTERNATIVE("jmp 1f", "", X86_FEATURE_SMAP)
- "pushf; pop %0; " __ASM_CLAC "\n\t"
- "1:"
+ ALTERNATIVE("", "pushf; pop %0; " __ASM_CLAC "\n\t",
+ X86_FEATURE_SMAP)
: "=rm" (flags) : : "memory", "cc");
return flags;
@@ -69,9 +68,8 @@ static __always_inline unsigned long smap_save(void)
static __always_inline void smap_restore(unsigned long flags)
{
asm volatile ("# smap_restore\n\t"
- ALTERNATIVE("jmp 1f", "", X86_FEATURE_SMAP)
- "push %0; popf\n\t"
- "1:"
+ ALTERNATIVE("", "push %0; popf\n\t",
+ X86_FEATURE_SMAP)
: : "g" (flags) : "memory", "cc");
}
diff --git a/tools/objtool/check.c b/tools/objtool/check.c
index 068cdb4..5e5388a 100644
--- a/tools/objtool/check.c
+++ b/tools/objtool/check.c
@@ -2442,6 +2442,9 @@ static int handle_insn_ops(struct instruction *insn, struct insn_state *state)
if (update_cfi_state(insn, &state->cfi, op))
return 1;
+ if (!insn->alt_group)
+ continue;
+
if (op->dest.type == OP_DEST_PUSHF) {
if (!state->uaccess_stack) {
state->uaccess_stack = 1;
^ permalink raw reply [flat|nested] 2+ messages in thread