Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1450905 > unrolled thread

Re: [RESEND][PATCH] kbuild: Abort build on bad stack protector flag

Started byMichal Marek <mmarek@suse.com>
First post2016-07-26 23:10 +0200
Last post2016-07-26 23:30 +0200
Articles 2 — 2 participants

Back to article view | Back to linux.kernel

This discussion starts older than the indexed window; earlier articles aren't shown. The article labeled Started by below is the oldest one visible, not the original post.


Contents

  Re: [RESEND][PATCH] kbuild: Abort build on bad stack protector flag Michal Marek <mmarek@suse.com> - 2016-07-26 23:10 +0200
    Re: [RESEND][PATCH] kbuild: Abort build on bad stack protector flag Kees Cook <keescook@chromium.org> - 2016-07-26 23:30 +0200

#1450905 — Re: [RESEND][PATCH] kbuild: Abort build on bad stack protector flag

FromMichal Marek <mmarek@suse.com>
Date2016-07-26 23:10 +0200
SubjectRe: [RESEND][PATCH] kbuild: Abort build on bad stack protector flag
Message-ID<rZhLX-78t-3@gated-at.bofh.it>
On Tue, Jul 12, 2016 at 03:30:43PM -0700, Kees Cook wrote:
> Before, the stack protector flag was sanity checked before .config had
> been reprocessed. This meant the build couldn't be aborted early, and
> only a warning could be emitted followed later by the compiler blowing
> up with an unknown flag. This has caused a lot of confusion over time,
> so this splits the flag selection from sanity checking and performs the
> sanity checking after the make has been restarted from a reprocessed
> .config, so builds can be aborted as early as possible now.
> 
> Additionally moves the x86-specific sanity check to the same location,
> since it suffered from the same warn-then-wait-for-compiler-failure
> problem.
> 
> Signed-off-by: Kees Cook <keescook@chromium.org>

Hi Kees,

sorry for the late review.


> +# Find arch-specific stack protector compiler sanity-checking script.
> +ifdef CONFIG_CC_STACKPROTECTOR
> +  stackp-path := $(srctree)/scripts/gcc-$(ARCH)_$(BITS)-has-stack-protector.sh

You need to use SRCARCH here if you want "x86" on x86.


> +  ifneq ($(wildcard $(stackp-path)),)
> +    stackp-check := $(stackp-path)
> +  endif

stackp-check := $(wildcard $(stackp-path))

is more straightforward. But the long version is correct as well.

Michal

[toc] | [next] | [standalone]


#1450926

FromKees Cook <keescook@chromium.org>
Date2016-07-26 23:30 +0200
Message-ID<rZi5j-7eZ-13@gated-at.bofh.it>
In reply to#1450905
On Tue, Jul 26, 2016 at 2:06 PM, Michal Marek <mmarek@suse.com> wrote:
> On Tue, Jul 12, 2016 at 03:30:43PM -0700, Kees Cook wrote:
>> Before, the stack protector flag was sanity checked before .config had
>> been reprocessed. This meant the build couldn't be aborted early, and
>> only a warning could be emitted followed later by the compiler blowing
>> up with an unknown flag. This has caused a lot of confusion over time,
>> so this splits the flag selection from sanity checking and performs the
>> sanity checking after the make has been restarted from a reprocessed
>> .config, so builds can be aborted as early as possible now.
>>
>> Additionally moves the x86-specific sanity check to the same location,
>> since it suffered from the same warn-then-wait-for-compiler-failure
>> problem.
>>
>> Signed-off-by: Kees Cook <keescook@chromium.org>
>
> Hi Kees,
>
> sorry for the late review.
>
>
>> +# Find arch-specific stack protector compiler sanity-checking script.
>> +ifdef CONFIG_CC_STACKPROTECTOR
>> +  stackp-path := $(srctree)/scripts/gcc-$(ARCH)_$(BITS)-has-stack-protector.sh
>
> You need to use SRCARCH here if you want "x86" on x86.
>
>
>> +  ifneq ($(wildcard $(stackp-path)),)
>> +    stackp-check := $(stackp-path)
>> +  endif
>
> stackp-check := $(wildcard $(stackp-path))
>
> is more straightforward. But the long version is correct as well.

Ah! Yes, thanks. I was thinking I needed to handle "defined but
empty", but that's not true for Makefiles. I'll send a v2 with this
and SRCARCH fixed.

-Kees

-- 
Kees Cook
Chrome OS & Brillo Security

[toc] | [prev] | [standalone]


Back to top | Article view | linux.kernel


csiph-web