diff options
author | Ard Biesheuvel <ardb@kernel.org> | 2022-10-27 17:59:07 +0200 |
---|---|---|
committer | Will Deacon <will@kernel.org> | 2022-11-09 18:06:35 +0000 |
commit | 9beccca0984022a844850e32f0d7dd80d4a225de (patch) | |
tree | f9a9128498d40dee1958e15b212707872f039e38 /arch/Kconfig | |
parent | 68c76ad4a9571a2b603665c85cf8229bcf04982a (diff) | |
download | linux-stable-9beccca0984022a844850e32f0d7dd80d4a225de.tar.gz linux-stable-9beccca0984022a844850e32f0d7dd80d4a225de.tar.bz2 linux-stable-9beccca0984022a844850e32f0d7dd80d4a225de.zip |
scs: add support for dynamic shadow call stacks
In order to allow arches to use code patching to conditionally emit the
shadow stack pushes and pops, rather than always taking the performance
hit even on CPUs that implement alternatives such as stack pointer
authentication on arm64, add a Kconfig symbol that can be set by the
arch to omit the SCS codegen itself, without otherwise affecting how
support code for SCS and compiler options (for register reservation, for
instance) are emitted.
Also, add a static key and some plumbing to omit the allocation of
shadow call stack for dynamic SCS configurations if SCS is disabled at
runtime.
Signed-off-by: Ard Biesheuvel <ardb@kernel.org>
Reviewed-by: Nick Desaulniers <ndesaulniers@google.com>
Reviewed-by: Kees Cook <keescook@chromium.org>
Reviewed-by: Sami Tolvanen <samitolvanen@google.com>
Tested-by: Sami Tolvanen <samitolvanen@google.com>
Link: https://lore.kernel.org/r/20221027155908.1940624-3-ardb@kernel.org
Signed-off-by: Will Deacon <will@kernel.org>
Diffstat (limited to 'arch/Kconfig')
-rw-r--r-- | arch/Kconfig | 7 |
1 files changed, 7 insertions, 0 deletions
diff --git a/arch/Kconfig b/arch/Kconfig index 8f138e580d1a..072a1b39e3af 100644 --- a/arch/Kconfig +++ b/arch/Kconfig @@ -651,6 +651,13 @@ config SHADOW_CALL_STACK reading and writing arbitrary memory may be able to locate them and hijack control flow by modifying the stacks. +config DYNAMIC_SCS + bool + help + Set by the arch code if it relies on code patching to insert the + shadow call stack push and pop instructions rather than on the + compiler. + config LTO bool help |