2020-04-27 19:00:07 +03:00
|
|
|
/* SPDX-License-Identifier: GPL-2.0 */
|
|
|
|
/*
|
|
|
|
* Shadow Call Stack support.
|
|
|
|
*
|
|
|
|
* Copyright (C) 2019 Google LLC
|
|
|
|
*/
|
|
|
|
|
|
|
|
#ifndef _LINUX_SCS_H
|
|
|
|
#define _LINUX_SCS_H
|
|
|
|
|
|
|
|
#include <linux/gfp.h>
|
|
|
|
#include <linux/poison.h>
|
|
|
|
#include <linux/sched.h>
|
|
|
|
#include <linux/sizes.h>
|
|
|
|
|
|
|
|
#ifdef CONFIG_SHADOW_CALL_STACK
|
|
|
|
|
|
|
|
/*
|
|
|
|
* In testing, 1 KiB shadow stack size (i.e. 128 stack frames on a 64-bit
|
|
|
|
* architecture) provided ~40% safety margin on stack usage while keeping
|
|
|
|
* memory allocation overhead reasonable.
|
|
|
|
*/
|
|
|
|
#define SCS_SIZE SZ_1K
|
|
|
|
#define GFP_SCS (GFP_KERNEL | __GFP_ZERO)
|
|
|
|
|
|
|
|
/* An illegal pointer value to mark the end of the shadow stack. */
|
|
|
|
#define SCS_END_MAGIC (0x5f6UL + POISON_POINTER_DELTA)
|
|
|
|
|
2020-05-15 18:17:12 +03:00
|
|
|
/* Allocate a static per-CPU shadow stack */
|
|
|
|
#define DEFINE_SCS(name) \
|
|
|
|
DEFINE_PER_CPU(unsigned long [SCS_SIZE/sizeof(long)], name) \
|
|
|
|
|
2020-04-27 19:00:07 +03:00
|
|
|
#define task_scs(tsk) (task_thread_info(tsk)->scs_base)
|
2020-05-15 16:11:05 +03:00
|
|
|
#define task_scs_sp(tsk) (task_thread_info(tsk)->scs_sp)
|
2020-04-27 19:00:07 +03:00
|
|
|
|
|
|
|
void scs_init(void);
|
|
|
|
int scs_prepare(struct task_struct *tsk, int node);
|
|
|
|
void scs_release(struct task_struct *tsk);
|
|
|
|
|
|
|
|
static inline void scs_task_reset(struct task_struct *tsk)
|
|
|
|
{
|
|
|
|
/*
|
|
|
|
* Reset the shadow stack to the base address in case the task
|
|
|
|
* is reused.
|
|
|
|
*/
|
2020-05-15 16:11:05 +03:00
|
|
|
task_scs_sp(tsk) = task_scs(tsk);
|
2020-04-27 19:00:07 +03:00
|
|
|
}
|
|
|
|
|
|
|
|
static inline unsigned long *__scs_magic(void *s)
|
|
|
|
{
|
|
|
|
return (unsigned long *)(s + SCS_SIZE) - 1;
|
|
|
|
}
|
|
|
|
|
2020-05-15 16:56:05 +03:00
|
|
|
static inline bool task_scs_end_corrupted(struct task_struct *tsk)
|
2020-04-27 19:00:07 +03:00
|
|
|
{
|
|
|
|
unsigned long *magic = __scs_magic(task_scs(tsk));
|
2020-05-15 16:11:05 +03:00
|
|
|
unsigned long sz = task_scs_sp(tsk) - task_scs(tsk);
|
2020-04-27 19:00:07 +03:00
|
|
|
|
2020-05-15 16:11:05 +03:00
|
|
|
return sz >= SCS_SIZE - 1 || READ_ONCE_NOCHECK(*magic) != SCS_END_MAGIC;
|
2020-04-27 19:00:07 +03:00
|
|
|
}
|
|
|
|
|
|
|
|
#else /* CONFIG_SHADOW_CALL_STACK */
|
|
|
|
|
|
|
|
static inline void scs_init(void) {}
|
|
|
|
static inline void scs_task_reset(struct task_struct *tsk) {}
|
|
|
|
static inline int scs_prepare(struct task_struct *tsk, int node) { return 0; }
|
|
|
|
static inline void scs_release(struct task_struct *tsk) {}
|
2020-05-15 16:56:05 +03:00
|
|
|
static inline bool task_scs_end_corrupted(struct task_struct *tsk) { return false; }
|
2020-04-27 19:00:07 +03:00
|
|
|
|
|
|
|
#endif /* CONFIG_SHADOW_CALL_STACK */
|
|
|
|
|
|
|
|
#endif /* _LINUX_SCS_H */
|