Re: [PATCH v2 29/39] x86/cet/shstk: Support wrss for userspace
From: Kees Cook <hidden>
Date: 2022-10-03 22:29:11
Also in:
linux-arch, linux-doc, linux-mm, lkml
From: Kees Cook <hidden>
Date: 2022-10-03 22:29:11
Also in:
linux-arch, linux-doc, linux-mm, lkml
On Thu, Sep 29, 2022 at 03:29:26PM -0700, Rick Edgecombe wrote:
For the current shadow stack implementation, shadow stacks contents easily be arbitrarily provisioned with data.
I can't parse this sentence.
This property helps apps protect themselves better, but also restricts any potential apps that may want to do exotic things at the expense of a little security.
Is anything using this right now? Wouldn't thing be safer without WRSS? (Why can't we skip this patch?) -- Kees Cook