8000 00459: Apply Intel Control-flow Technology for x86-64 · python/cpython@267e3a7 · GitHub
[go: up one dir, main page]

Skip to content

Commit 267e3a7

Browse files
stratakishroncok
authored andcommitted
00459: Apply Intel Control-flow Technology for x86-64
Required for mitigation against return-oriented programming (ROP) and Call or Jump Oriented Programming (COP/JOP) attacks Proposed upstream: #128606 See also: https://sourceware.org/annobin/annobin.html/Test-cf-protection.html
1 parent 72c5ccb commit 267e3a7

File tree

2 files changed

+26
-0
lines changed

2 files changed

+26
-0
lines changed

Python/asm_trampoline.S

Lines changed: 22 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -9,6 +9,9 @@
99
# }
1010
_Py_trampoline_func_start:
1111
#ifdef __x86_64__
12+
#if defined(__CET__) && (__CET__ & 1)
13+
endbr64
14+
#endif
1215
sub $8, %rsp
1316
call *%rcx
1417
add $8, %rsp
@@ -34,3 +37,22 @@ _Py_trampoline_func_start:
3437
.globl _Py_trampoline_func_end
3538
_Py_trampoline_func_end:
3639
.section .note.GNU-stack,"",@progbits
40+
# Note for indicating the assembly code supports CET
41+
#if defined(__x86_64__) && defined(__CET__) && (__CET__ & 1)
42+
.section .note.gnu.property,"a"
43+
.align 8
44+
.long 1f - 0f
45+
.long 4f - 1f
46+
.long 5
47+
0:
48+
.string "GNU"
49+
1:
50+
.align 8
51+
.long 0xc0000002
52+
.long 3f - 2f
53+
2:
54+
.long 0x3
55+
3:
56+
.align 8
57+
4:
58+
#endif // __x86_64__

Python/perf_jit_trampoline.c

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -473,7 +473,11 @@ elf_init_ehframe(ELFObjectContext* ctx)
473473
DWRF_U8(0); /* Augmentation data. */
474474
/* Registers saved in CFRAME. */
475475
#ifdef __x86_64__
476+
# if defined(__CET__) && (__CET__ & 1)
477+
DWRF_U8(DWRF_CFA_advance_loc | 8);
478+
# else
476479
DWRF_U8(DWRF_CFA_advance_loc | 4);
480+
# endif
477481
DWRF_U8(DWRF_CFA_def_cfa_offset); DWRF_UV(16);
478482
DWRF_U8(DWRF_CFA_advance_loc | 6);
479483
DWRF_U8(DWRF_CFA_def_cfa_offset); DWRF_UV(8);

0 commit comments

Comments
 (0)
0