Page Menu
Home
FreeBSD
Search
Configure Global Search
Log In
Files
F174399647
D60132.id188163.diff
No One
Temporary
Actions
View File
Edit File
Delete File
View Transforms
Subscribe
Mute Notifications
Flag For Later
Award Token
Size
5 KB
Referenced Files
None
Subscribers
None
D60132.id188163.diff
View Options
diff --git a/sys/conf/Makefile.riscv b/sys/conf/Makefile.riscv
--- a/sys/conf/Makefile.riscv
+++ b/sys/conf/Makefile.riscv
@@ -39,6 +39,23 @@
CFLAGS += -fno-omit-frame-pointer -fno-optimize-sibling-calls
.endif
+.if ${MK_SSP} != "no"
+PERTHREAD_SSP_ENABLED!= grep PERTHREAD_SSP opt_global.h || true ; echo
+. if !empty(PERTHREAD_SSP_ENABLED)
+. if (${COMPILER_TYPE} == "clang" && ${OSRELDATE} >= 1600019) || \
+ ${COMPILER_TYPE} == "gcc"
+PCPU_CANARY_OFFSET!= grep PC_CANARY assym.inc | cut -f3 | xargs printf "%d"
+RISCV_SSP_CFLAGS+= -mstack-protector-guard=tls
+RISCV_SSP_CFLAGS+= -mstack-protector-guard-reg=tp
+RISCV_SSP_CFLAGS+= -mstack-protector-guard-offset=${PCPU_CANARY_OFFSET}
+. else
+. warning "Compiler is too old to support PERTHREAD_SSP"
+. endif
+CFLAGS+= ${RISCV_SSP_CFLAGS}
+ARCH_FLAGS+= ${RISCV_SSP_CFLAGS}
+. endif
+.endif
+
%BEFORE_DEPEND
%OBJS
diff --git a/sys/conf/options.riscv b/sys/conf/options.riscv
--- a/sys/conf/options.riscv
+++ b/sys/conf/options.riscv
@@ -1,5 +1,6 @@
RISCV opt_global.h # For cpu RISCV to work
INTRNG opt_global.h
+PERTHREAD_SSP opt_global.h
PV_STATS opt_pmap.h
# SoC Support
diff --git a/sys/riscv/conf/GENERIC b/sys/riscv/conf/GENERIC
--- a/sys/riscv/conf/GENERIC
+++ b/sys/riscv/conf/GENERIC
@@ -78,6 +78,7 @@
options RACCT # Resource accounting framework
options RACCT_DEFAULT_TO_DISABLED # Set kern.racct.enable=0 by default
options RCTL # Resource limits
+options PERTHREAD_SSP # Per-thread SSP canary
options SMP
options IOMMU
diff --git a/sys/riscv/include/pcpu.h b/sys/riscv/include/pcpu.h
--- a/sys/riscv/include/pcpu.h
+++ b/sys/riscv/include/pcpu.h
@@ -47,7 +47,8 @@
uint32_t pc_pending_ipis; /* IPIs pending to this CPU */ \
uint32_t pc_hart; /* Hart ID */ \
uint64_t pc_clock; \
- char __pad[48] /* Pad to factor of PAGE_SIZE */
+ uintptr_t pc_canary; \
+ char __pad[40] /* Pad to factor of PAGE_SIZE */
#ifdef _KERNEL
diff --git a/sys/riscv/include/proc.h b/sys/riscv/include/proc.h
--- a/sys/riscv/include/proc.h
+++ b/sys/riscv/include/proc.h
@@ -34,6 +34,7 @@
struct mdthread {
int md_spinlock_count; /* (k) */
register_t md_saved_sstatus_ie; /* (k) */
+ register_t md_canary; /* (k) */
};
struct mdproc {
diff --git a/sys/riscv/riscv/genassym.c b/sys/riscv/riscv/genassym.c
--- a/sys/riscv/riscv/genassym.c
+++ b/sys/riscv/riscv/genassym.c
@@ -75,6 +75,7 @@
ASSYM(PC_CURPCB, offsetof(struct pcpu, pc_curpcb));
ASSYM(PC_CURTHREAD, offsetof(struct pcpu, pc_curthread));
+ASSYM(PC_CANARY, offsetof(struct pcpu, pc_canary));
ASSYM(TD_PCB, offsetof(struct thread, td_pcb));
ASSYM(TD_FLAGS, offsetof(struct thread, td_flags));
@@ -82,6 +83,7 @@
ASSYM(TD_PROC, offsetof(struct thread, td_proc));
ASSYM(TD_FRAME, offsetof(struct thread, td_frame));
ASSYM(TD_MD, offsetof(struct thread, td_md));
+ASSYM(TD_MD_CANARY, offsetof(struct thread, td_md.md_canary));
ASSYM(TD_LOCK, offsetof(struct thread, td_lock));
ASSYM(TF_SIZE, TF_SIZE);
diff --git a/sys/riscv/riscv/machdep.c b/sys/riscv/riscv/machdep.c
--- a/sys/riscv/riscv/machdep.c
+++ b/sys/riscv/riscv/machdep.c
@@ -123,6 +123,11 @@
static char static_kenv[PAGE_SIZE];
+// XXX-0MP: Is it correc to have the same value as on amd64?
+#ifdef PERTHREAD_SSP
+uintptr_t boot_canary = 0x6543d292157d3053UL;
+#endif
+
static void
cpu_startup(void *dummy)
{
@@ -301,6 +306,9 @@
thread0.td_pcb->pcb_fpflags = 0;
thread0.td_pcb->pcb_vsflags = 0;
thread0.td_frame = &proc0_tf;
+#ifdef PERTHREAD_SSP
+ thread0.td_md.md_canary = boot_canary;
+#endif
pcpup->pc_curpcb = thread0.td_pcb;
}
@@ -575,6 +583,10 @@
__asm __volatile("mv tp, %0" :: "r"(pcpup));
PCPU_SET(curthread, &thread0);
+// XXX-0MP: Most likely not the right location.
+#ifdef PERTHREAD_SSP
+ thread0.td_md.md_canary = boot_canary;
+#endif
/* Initialize SBI interface. */
sbi_init();
diff --git a/sys/riscv/riscv/mp_machdep.c b/sys/riscv/riscv/mp_machdep.c
--- a/sys/riscv/riscv/mp_machdep.c
+++ b/sys/riscv/riscv/mp_machdep.c
@@ -110,6 +110,8 @@
/* Temporary variables for init_secondary() */
void *dpcpu[MAXCPU - 1];
+extern uintptr_t boot_canary;
+
static void
release_aps(void *dummy __unused)
{
@@ -395,6 +397,10 @@
pcpup = &__pcpu[cpuid];
pcpu_init(pcpup, cpuid, sizeof(struct pcpu));
pcpup->pc_hart = hart;
+// XXX-0MP: Wrong place?
+#ifdef PERTHREAD_SSP
+ pcpup->pc_canary = boot_canary;
+#endif
dpcpu[cpuid - 1] = kmem_malloc(DPCPU_SIZE, M_WAITOK | M_ZERO);
dpcpu_init(dpcpu[cpuid - 1], cpuid);
diff --git a/sys/riscv/riscv/swtch.S b/sys/riscv/riscv/swtch.S
--- a/sys/riscv/riscv/swtch.S
+++ b/sys/riscv/riscv/swtch.S
@@ -32,6 +32,8 @@
* SUCH DAMAGE.
*/
+#include "opt_global.h"
+
#include "assym.inc"
#include <machine/param.h>
@@ -223,6 +225,11 @@
1:
/* Store the new curthread */
sd a0, PC_CURTHREAD(tp)
+#ifdef PERTHREAD_SSP
+ /* Add the canary */
+ ld t0, TD_MD_CANARY(a1)
+ sd t0, PC_CANARY(gp)
+#endif
/* And the new pcb */
ld x13, TD_PCB(a0)
sd x13, PC_CURPCB(tp)
@@ -269,6 +276,11 @@
ENTRY(cpu_switch)
/* Store the new curthread */
sd a1, PC_CURTHREAD(tp)
+#ifdef PERTHREAD_SSP
+ /* Add the canary */
+ ld t0, TD_MD_CANARY(a1)
+ sd t0, PC_CANARY(gp)
+#endif
/* And the new pcb */
ld x13, TD_PCB(a1)
sd x13, PC_CURPCB(tp)
diff --git a/sys/riscv/riscv/vm_machdep.c b/sys/riscv/riscv/vm_machdep.c
--- a/sys/riscv/riscv/vm_machdep.c
+++ b/sys/riscv/riscv/vm_machdep.c
@@ -195,6 +195,10 @@
/* Setup to release spin count in fork_exit(). */
td->td_md.md_spinlock_count = 1;
td->td_md.md_saved_sstatus_ie = (SSTATUS_SIE);
+
+#ifdef PERTHREAD_SSP
+ arc4random_buf(&td->td_md.md_canary, sizeof(td->td_md.md_canary));
+#endif
}
/*
File Metadata
Details
Attached
Mime Type
text/plain
Expires
Sat, Oct 3, 10:27 PM (2 h, 9 m)
Storage Engine
blob
Storage Format
Raw Data
Storage Handle
40061497
Default Alt Text
D60132.id188163.diff (5 KB)
Attached To
Mode
D60132: WIP: riscv: Implement per-thread kernel stack canaries
Attached
Detach File
Event Timeline
Log In to Comment