[PW_SID:1148854] riscv: ptrace: reject CFI regset access when extensions are absent - #2504
[PW_SID:1148854] riscv: ptrace: reject CFI regset access when extensions are absent#2504linux-riscv-bot wants to merge 4 commits into
Conversation
…_RWX When CONFIG_STRICT_MODULE_RWX is not set, execmem cannot create temporary writable mappings for read-only executable pages. In this case, the execmem ranges must already have writable permissions. Currently EXECMEM_KPROBES unconditionally uses PAGE_KERNEL_READ_EXEC, which causes kprobe instruction slot writes to trigger page faults on systems where CONFIG_STRICT_MODULE_RWX is not enabled. Fix this by using PAGE_KERNEL_EXEC when CONFIG_STRICT_MODULE_RWX is not available. Signed-off-by: Xiaofeng Yuan <xiaofengmian@163.com> Tested-by: Lad Prabhakar <prabhakar.mahadev-lad.rj@bp.renesas.com> Reviewed-by: Nam Cao <namcao@linutronix.de> Link: https://patch.msgid.link/20260814082742.148403-2-xiaofengmian@163.com Signed-off-by: Paul Walmsley <pjw@kernel.org>
patch_map() always creates a temporary writable mapping via fixmap for kernel text addresses, even when CONFIG_STRICT_KERNEL_RWX is disabled and the kernel text is already mapped with _PAGE_WRITE. This is unnecessary overhead at best, and on minimal configurations it can cause page faults. Skip the fixmap path for kernel text when CONFIG_STRICT_KERNEL_RWX is not enabled, since the text pages are already writable in that case. The module text path is already gated on CONFIG_STRICT_MODULE_RWX and is kept unchanged. Reported-by: Klara Modin <klara@kasm.eu> Closes: https://lore.kernel.org/all/ant_8TaBbov_GS4i@soda.int.kasm.eu/ Reported-by: Lad Prabhakar <prabhakar.csengg@gmail.com> Closes: https://lore.kernel.org/all/CA+V-a8tQK8rih9SGGTyqrEBGpNkx4H0eX2YccCRrgkVAPr+EBg@mail.gmail.com/ Tested-by: Klara Modin <klarasmodin@gmail.com> Tested-by: Lad Prabhakar <prabhakar.mahadev-lad.rj@bp.renesas.com> Link: https://patch.msgid.link/20260814082742.148403-3-xiaofengmian@163.com Signed-off-by: Paul Walmsley <pjw@kernel.org>
riscv_cfi_get() and riscv_cfi_set() do not check whether the Zicfilp or Zicfiss extensions are present. On systems without them, PTRACE_GETREGSET on REGSET_CFI still succeeds and returns a zeroed user_cfi_state, misleading debuggers into believing the register set is available, and PTRACE_SETREGSET silently accepts writes that have no effect (e.g. clearing SR_ELP). Reject the access with -EINVAL when neither branch landing pads nor shadow stack is available to userspace, using the same availability helpers as the prctl path. Fixes: 2af7c9c ("riscv/ptrace: expose riscv CFI status and state via ptrace and in core files") Signed-off-by: Chen Pei <cp0613@linux.alibaba.com> Signed-off-by: Linux RISC-V bot <linux.riscv.bot@gmail.com>
|
Patch 1: "riscv: ptrace: reject CFI regset access when extensions are absent" |
|
Patch 1: "riscv: ptrace: reject CFI regset access when extensions are absent" |
|
Patch 1: "riscv: ptrace: reject CFI regset access when extensions are absent" |
|
Patch 1: "riscv: ptrace: reject CFI regset access when extensions are absent" |
|
Patch 1: "riscv: ptrace: reject CFI regset access when extensions are absent" |
|
Patch 1: "riscv: ptrace: reject CFI regset access when extensions are absent" |
|
Patch 1: "riscv: ptrace: reject CFI regset access when extensions are absent" |
|
Patch 1: "riscv: ptrace: reject CFI regset access when extensions are absent" |
|
Patch 1: "riscv: ptrace: reject CFI regset access when extensions are absent" |
|
Patch 1: "riscv: ptrace: reject CFI regset access when extensions are absent" |
|
Patch 1: "riscv: ptrace: reject CFI regset access when extensions are absent" |
|
Patch 1: "riscv: ptrace: reject CFI regset access when extensions are absent" |
bb1a926 to
6f6f7c0
Compare
PR for series 1148854 applied to workflow__riscv__fixes
Name: riscv: ptrace: reject CFI regset access when extensions are absent
URL: https://patchwork.kernel.org/project/linux-riscv/list/?series=1148854
Version: 1