lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  PHC 
Open Source and information security mailing list archives
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date:   Thu, 18 Mar 2021 14:38:12 -0700
From:   Sami Tolvanen <>
To:     Nick Desaulniers <>
Cc:     Kees Cook <>,
        Nathan Chancellor <>,
        Masahiro Yamada <>,
        Will Deacon <>, Jessica Yu <>,
        Arnd Bergmann <>, Tejun Heo <>,
        "Paul E. McKenney" <>,
        Christoph Hellwig <>,
        bpf <>,,
        linux-arch <>,
        Linux ARM <>,
        Linux Kbuild mailing list <>,
        PCI <>,
        LKML <>
Subject: Re: [PATCH v2 05/17] workqueue: use WARN_ON_FUNCTION_MISMATCH

On Thu, Mar 18, 2021 at 11:50 AM Nick Desaulniers
<> wrote:
> On Thu, Mar 18, 2021 at 10:11 AM Sami Tolvanen <> wrote:
> >
> > With CONFIG_CFI_CLANG, a callback function passed to
> > __queue_delayed_work from a module points to a jump table entry
> > defined in the module instead of the one used in the core kernel,
> > which breaks function address equality in this check:
> >
> >   WARN_ON_ONCE(timer->function != delayed_work_timer_fn);
> >
> > Use WARN_ON_FUNCTION_MISMATCH() instead to disable the warning
> > when CFI and modules are both enabled.
> Does __cficanonical help with such comparisons? Or would that be a
> very invasive change, if the concern was to try to keep these checks
> in place for CONFIG_CFI_CLANG?

The last time I checked, Clang ignored the __cficanonical attribute in
header files, which means it would still generate a local jump table
entry in each module for such functions, and the comparison here would
fail. We could avoid the issue by using __cficanonical for the
callback function *and* using __va_function() when we take the
function address in modules, but that feels way too invasive for this
particular use case.


Powered by blists - more mailing lists