mirror of
				https://github.com/torvalds/linux.git
				synced 2025-10-31 16:48:26 +02:00 
			
		
		
		
	kbuild: Fix CFI hash randomization with KASAN
Clang emits a asan.module_ctor constructor to each object file when KASAN is enabled, and these functions are indirectly called in do_ctors. With CONFIG_CFI_CLANG, the compiler also emits a CFI type hash before each address-taken global function so they can pass indirect call checks. However, in commit0c3e806ec0("x86/cfi: Add boot time hash randomization"), x86 implemented boot time hash randomization, which relies on the .cfi_sites section generated by objtool. As objtool is run against vmlinux.o instead of individual object files with X86_KERNEL_IBT (enabled by default), CFI types in object files that are not part of vmlinux.o end up not being included in .cfi_sites, and thus won't get randomized and trip CFI when called. Only .vmlinux.export.o and init/version-timestamp.o are linked into vmlinux separately from vmlinux.o. As these files don't contain any functions, disable KASAN for both of them to avoid breaking hash randomization. Link: https://github.com/ClangBuiltLinux/linux/issues/1742 Fixes:0c3e806ec0("x86/cfi: Add boot time hash randomization") Signed-off-by: Sami Tolvanen <samitolvanen@google.com> Acked-by: Peter Zijlstra (Intel) <peterz@infradead.org> Signed-off-by: Kees Cook <keescook@chromium.org> Link: https://lore.kernel.org/r/20230112224948.1479453-2-samitolvanen@google.com
This commit is contained in:
		
							parent
							
								
									3b293487b8
								
							
						
					
					
						commit
						42633ed852
					
				
					 2 changed files with 2 additions and 0 deletions
				
			
		|  | @ -59,3 +59,4 @@ include/generated/utsversion.h: FORCE | |||
| 
 | ||||
| $(obj)/version-timestamp.o: include/generated/utsversion.h | ||||
| CFLAGS_version-timestamp.o := -include include/generated/utsversion.h | ||||
| KASAN_SANITIZE_version-timestamp.o := n | ||||
|  |  | |||
|  | @ -18,6 +18,7 @@ quiet_cmd_cc_o_c = CC      $@ | |||
| 	$(call if_changed_dep,cc_o_c) | ||||
| 
 | ||||
| ifdef CONFIG_MODULES | ||||
| KASAN_SANITIZE_.vmlinux.export.o := n | ||||
| targets += .vmlinux.export.o | ||||
| vmlinux: .vmlinux.export.o | ||||
| endif | ||||
|  |  | |||
		Loading…
	
		Reference in a new issue
	
	 Sami Tolvanen
						Sami Tolvanen