lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  PHC 
Open Source and information security mailing list archives
Hash Suite for Android: free password hash cracker in your pocket
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date:   Mon, 26 Sep 2022 10:20:30 -0700
From:   Kees Cook <>
Cc:     Kees Cook <>,,,,,,,,,,
        Josh Poimboeuf <>,,,,
Subject: Re: [PATCH v5 00/22] KCFI support

On Thu, 8 Sep 2022 14:54:42 -0700, Sami Tolvanen wrote:
> KCFI is a forward-edge control-flow integrity scheme in the upcoming
> Clang 16 release, which is more suitable for kernel use than the
> existing CFI scheme used by CONFIG_CFI_CLANG. KCFI doesn't require
> LTO, doesn't alter function references to point to a jump table, and
> won't break function address equality.
> This series replaces the current arm64 CFI implementation with KCFI
> and adds support for x86_64.
> [...]

I assume that Peter's Ack means I should carry the tree, so, to that end:

Applied to for-next/kcfi, thanks!

[01/22] treewide: Filter out CC_FLAGS_CFI
[02/22] scripts/kallsyms: Ignore __kcfi_typeid_
[03/22] cfi: Remove CONFIG_CFI_CLANG_SHADOW
[04/22] cfi: Drop __CFI_ADDRESSABLE
[05/22] cfi: Switch to -fsanitize=kcfi
[06/22] cfi: Add type helper macros
[07/22] lkdtm: Emit an indirect call for CFI tests
[08/22] psci: Fix the function type for psci_initcall_t
[09/22] arm64: Add types to indirect called assembly functions
[10/22] arm64: Add CFI error handling
[11/22] arm64: Drop unneeded __nocfi attributes
[12/22] init: Drop __nocfi from __init
[13/22] treewide: Drop function_nocfi
[14/22] treewide: Drop WARN_ON_FUNCTION_MISMATCH
[15/22] treewide: Drop __cficanonical
[16/22] objtool: Preserve special st_shndx indexes in elf_update_symbol
[17/22] objtool: Disable CFI warnings
[18/22] kallsyms: Drop CONFIG_CFI_CLANG workarounds
[19/22] x86/tools/relocs: Ignore __kcfi_typeid_ relocations
[20/22] x86: Add types to indirectly called assembly functions
[21/22] x86/purgatory: Disable CFI
[22/22] x86: Add support for CONFIG_CFI_CLANG

Kees Cook

Powered by blists - more mailing lists