Thread (98 messages) 98 messages, 13 authors, 2018-06-26

Re: [PATCH 00/10] Control Flow Enforcement - Part (3)

From: Yu-cheng Yu <hidden>
Date: 2018-06-26 15:00:10
Also in: linux-arch, linux-mm, lkml

On Tue, 2018-06-26 at 04:46 +0200, Jann Horn wrote:
On Tue, Jun 26, 2018 at 4:45 AM Yu-cheng Yu [off-list ref]
wrote:
quoted

This series introduces CET - Shadow stack

At the high level, shadow stack is:

        Allocated from a task's address space with vm_flags
VM_SHSTK;
        Its PTEs must be read-only and dirty;
        Fixed sized, but the default size can be changed by sys
admin.

For a forked child, the shadow stack is duplicated when the next
shadow stack access takes place.

For a pthread child, a new shadow stack is allocated.

The signal handler uses the same shadow stack as the main program.

Yu-cheng Yu (10):
  x86/cet: User-mode shadow stack support
  x86/cet: Introduce WRUSS instruction
  x86/cet: Signal handling for shadow stack
  x86/cet: Handle thread shadow stack
  x86/cet: ELF header parsing of Control Flow Enforcement
  x86/cet: Add arch_prctl functions for shadow stack
  mm: Prevent mprotect from changing shadow stack
  mm: Prevent mremap of shadow stack
  mm: Prevent madvise from changing shadow stack
  mm: Prevent munmap and remap_file_pages of shadow stack
Shouldn't patches like these be CC'ed to linux-api@vger.kernel.org?
Yes, I will do that.

Thanks,
Yu-cheng
--
To unsubscribe from this list: send the line "unsubscribe linux-doc" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help