Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1295162 > unrolled thread

[PATCH] ARM: fix atags_to_fdt with stack-protector-strong

Started byKees Cook <keescook@chromium.org>
First post2015-12-18 22:10 +0100
Last post2015-12-18 22:30 +0100
Articles 3 — 2 participants

Back to article view | Back to linux.kernel


Contents

  [PATCH] ARM: fix atags_to_fdt with stack-protector-strong Kees Cook <keescook@chromium.org> - 2015-12-18 22:10 +0100
    Re: [PATCH] ARM: fix atags_to_fdt with stack-protector-strong Arnd Bergmann <arnd@arndb.de> - 2015-12-18 22:20 +0100
      Re: [PATCH] ARM: fix atags_to_fdt with stack-protector-strong Kees Cook <keescook@chromium.org> - 2015-12-18 22:30 +0100

#1295162 — [PATCH] ARM: fix atags_to_fdt with stack-protector-strong

FromKees Cook <keescook@chromium.org>
Date2015-12-18 22:10 +0100
Subject[PATCH] ARM: fix atags_to_fdt with stack-protector-strong
Message-ID<qHarN-2rz-49@gated-at.bofh.it>
Building with CONFIG_CC_STACKPROTECTOR_STRONG triggers protection code
generation under CONFIG_ARM_ATAG_DTB_COMPAT but this is too early for
being able to use any of the stack_chk code. Explicitly disable it for
only the atags_to_fdt bits.

Suggested-by: zhxihu <zhxihu@marvell.com>
Signed-off-by: Kees Cook <keescook@chromium.org>
---
 arch/arm/boot/compressed/Makefile | 8 ++++++++
 1 file changed, 8 insertions(+)

diff --git a/arch/arm/boot/compressed/Makefile b/arch/arm/boot/compressed/Makefile
index 3f9a9ebc77c3..8cfbc4a2090b 100644
--- a/arch/arm/boot/compressed/Makefile
+++ b/arch/arm/boot/compressed/Makefile
@@ -106,6 +106,14 @@ ORIG_CFLAGS := $(KBUILD_CFLAGS)
 KBUILD_CFLAGS = $(subst -pg, , $(ORIG_CFLAGS))
 endif
 
+ifeq ($(CONFIG_ARM_ATAG_DTB_COMPAT),y)
+CFLAGS_atags_to_fdt.o := -fno-stack-protector
+CFLAGS_fdt.o := -fno-stack-protector
+CFLAGS_fdt_ro.o := -fno-stack-protector
+CFLAGS_fdt_rw.o := -fno-stack-protector
+CFLAGS_fdt_wip.o := -fno-stack-protector
+endif
+
 ccflags-y := -fpic -mno-single-pic-base -fno-builtin -I$(obj)
 asflags-y := -DZIMAGE
 
-- 
2.6.3


-- 
Kees Cook
Chrome OS & Brillo Security
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [next] | [standalone]


#1295173

FromArnd Bergmann <arnd@arndb.de>
Date2015-12-18 22:20 +0100
Message-ID<qHaBs-2uN-13@gated-at.bofh.it>
In reply to#1295162
On Friday 18 December 2015 13:04:59 Kees Cook wrote:
> +ifeq ($(CONFIG_ARM_ATAG_DTB_COMPAT),y)
> +CFLAGS_atags_to_fdt.o := -fno-stack-protector
> +CFLAGS_fdt.o := -fno-stack-protector
> +CFLAGS_fdt_ro.o := -fno-stack-protector
> +CFLAGS_fdt_rw.o := -fno-stack-protector
> +CFLAGS_fdt_wip.o := -fno-stack-protector
> +endif

I'm pretty sure you don't need the ifeq there, you can simply define those
flags unconditionally.

You can't just add -fno-stack-protector unconditionally, because that
breaks building the kernel with toolchains that are older than stack-protector,
so this should be

CFLAGS_obj.o += $(call cc-option, -fno-stack-protector)

Other than that, the patch looks ok.

	Arnd
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [next] | [standalone]


#1295178

FromKees Cook <keescook@chromium.org>
Date2015-12-18 22:30 +0100
Message-ID<qHaL8-2xT-3@gated-at.bofh.it>
In reply to#1295173
On Fri, Dec 18, 2015 at 1:09 PM, Arnd Bergmann <arnd@arndb.de> wrote:
> On Friday 18 December 2015 13:04:59 Kees Cook wrote:
>> +ifeq ($(CONFIG_ARM_ATAG_DTB_COMPAT),y)
>> +CFLAGS_atags_to_fdt.o := -fno-stack-protector
>> +CFLAGS_fdt.o := -fno-stack-protector
>> +CFLAGS_fdt_ro.o := -fno-stack-protector
>> +CFLAGS_fdt_rw.o := -fno-stack-protector
>> +CFLAGS_fdt_wip.o := -fno-stack-protector
>> +endif
>
> I'm pretty sure you don't need the ifeq there, you can simply define those
> flags unconditionally.
>
> You can't just add -fno-stack-protector unconditionally, because that
> breaks building the kernel with toolchains that are older than stack-protector,
> so this should be
>
> CFLAGS_obj.o += $(call cc-option, -fno-stack-protector)
>
> Other than that, the patch looks ok.

Ah, yes, all excellent points. I'll resend. Thanks!

-Kees

-- 
Kees Cook
Chrome OS & Brillo Security
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [standalone]


Back to top | Article view | linux.kernel


csiph-web