mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Kees Cook <kees@kernel.org>
To: Ard Biesheuvel <ardb@kernel.org>
Cc: Kees Cook <kees@kernel.org>,
	Ilias Apalodimas <ilias.apalodimas@linaro.org>,
	Nathan Chancellor <nathan@kernel.org>,
	Nicolas Schier <nsc@kernel.org>,
	Nick Desaulniers <ndesaulniers@google.com>,
	Bill Wendling <morbo@google.com>,
	Justin Stitt <justinstitt@google.com>,
	linux-efi@vger.kernel.org, llvm@lists.linux.dev,
	linux-kernel@vger.kernel.org, linux-hardening@vger.kernel.org
Subject: [PATCH v1 2/3] efi/libstub: Build the x86 stub from KBUILD_CFLAGS
Date: Tue,  6 Oct 2026 13:42:22 -0700	[thread overview]
Message-ID: <20261006204224.1536491-2-kees@kernel.org> (raw)
In-Reply-To: <20261006204210.i.137-kees@kernel.org>

The x86 stub replaces KBUILD_CFLAGS with a short list of its own, so new
kernel-wide compiler options go missing, unless explicitly remembered
or when lacking them breaks the build, e.g. commit 5ff8ad3909524
("kbuild: Add '-fms-extensions' to areas with dedicated CFLAGS")
did. Today, several still go missing that are provided to non-x86
stub builds, e.g. -ftrivial-auto-var-init, -fzero-call-used-regs,
-fstrict-flex-arrays=3, and the various kernel's warnings.

Flip the x86 option logic to match the other architectures. Since the
x86 stub is linked into the decompressor rather than the kernel proper,
remove the kernel code model, the i386 register calling convention,
and the kernel's reduced stack alignment, along with the retpoline and
return thunks and the call padding, which only the kernel provides,
and disable kernel stack erasing as the other architectures do. The
existing -mcmodel=small, -march=i386, and -fPIC still get overrides.
Build with -fcf-protection=none, since nothing enables IBT while the
stub runs: the firmware applies forward-edge CFI only to images that
advertise it, which bzImage does not.

New flags that change code generation or semantics in a plain x86_64
defconfig hardening.config stub:

Hardening:
	-ftrivial-auto-var-init=zero
	-fzero-init-padding-bits=all
	-fstrict-flex-arrays=3
	-fno-strict-overflow
	-fno-delete-null-pointer-checks
	-fno-allow-store-data-races
	-fno-jump-tables (from the default IBT config)

C semantics:
	-funsigned-char
	-fno-common

x86 code generation:
	-mno-sse2 -mno-3dnow -mno-avx -mno-sse4a
	 (stub already added -mno-mmx -mno-sse)
	-mno-80387 -mno-fp-ret-in-387 -mskip-rax-setup
	-falign-jumps=1 -falign-loops=1 -fmin-function-alignment=16
	-fomit-frame-pointer -fconserve-stack
	-fno-stack-clash-protection -fno-stack-check -fno-builtin-wcslen

Warnings (lots and lots, but notably):
	-Wall -Wextra -Wundef -Wmissing-prototypes
	-Wvla-larger-than=1 -Wimplicit-fallthrough=5

Present but with no effect, because the stub's later flags override them:
	-O2, overridden by -Os
	-fstack-protector-* flags, overridden by -fno-stack-protector
	-fno-PIE, overridden by -fPIC
	-fcf-protection=branch, overridden by -fcf-protection=none
	the stack-erase plugin, loaded and then disabled

Build tested ARCH=x86_64 defconfig hardening.config, plus retpolines,
return thunks, call depth tracking, IBT, GCC plugins, and EFI mixed
mode, with GCC 16.2.0 and Clang 24.0.0git, and ARCH=i386 defconfig
hardening.config with GCC 16.2.0. Each booted through the EFI stub to
userspace under QEMU with x64 and IA32 OVMF, the latter in mixed mode
for x86_64.

Assisted-by: LLM
Signed-off-by: Kees Cook <kees@kernel.org>
---
 drivers/firmware/efi/libstub/Makefile | 24 ++++++++++++++----------
 1 file changed, 14 insertions(+), 10 deletions(-)

diff --git a/drivers/firmware/efi/libstub/Makefile b/drivers/firmware/efi/libstub/Makefile
index 77a2b2d74f3f..1f588591f458 100644
--- a/drivers/firmware/efi/libstub/Makefile
+++ b/drivers/firmware/efi/libstub/Makefile
@@ -6,18 +6,22 @@
 # enabled, even if doing so doesn't break the build.
 #
 
-# non-x86 reuses KBUILD_CFLAGS, x86 does not
 cflags-y			:= $(KBUILD_CFLAGS)
 
-cflags-$(CONFIG_X86_32)		:= -march=i386
-cflags-$(CONFIG_X86_64)		:= -mcmodel=small
-cflags-$(CONFIG_X86)		+= -m$(BITS) -D__KERNEL__ $(CC_FLAGS_DIALECT) \
-				   -fPIC -fno-strict-aliasing -mno-red-zone \
-				   -mno-mmx -mno-sse -fshort-wchar \
-				   -Wno-pointer-sign \
-				   $(call cc-disable-warning, address-of-packed-member) \
-				   -fno-asynchronous-unwind-tables \
-				   $(CLANG_FLAGS)
+# x86 links the stub into the decompressor rather than the kernel proper, so
+# drop the kernel's code model, calling convention, and stack alignment, and
+# the mitigations that rely on thunks and patch sites only the kernel has.
+cflags-$(CONFIG_X86)		:= $(filter-out -mcmodel=kernel \
+				     -mregparm=3 -freg-struct-return \
+				     -mpreferred-stack-boundary=% \
+				     -mstack-alignment=% \
+				     $(RETPOLINE_CFLAGS) $(RETHUNK_CFLAGS) \
+				     $(PADDING_CFLAGS), $(cflags-y))
+cflags-$(CONFIG_X86_32)		+= -march=i386
+cflags-$(CONFIG_X86_64)		+= -mcmodel=small
+cflags-$(CONFIG_X86)		+= -fPIC $(DISABLE_KSTACK_ERASE)
+# Nothing enables IBT while the stub runs, so ENDBR would only take space.
+cflags-$(CONFIG_X86)		+= $(call cc-option,-fcf-protection=none)
 
 # arm64 uses the full KBUILD_CFLAGS so it's necessary to explicitly
 # disable the stackleak plugin
-- 
2.55.0


  parent reply	other threads:[~2026-10-06 20:42 UTC|newest]

Thread overview: 6+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-10-06 20:42 [PATCH v1 0/3] " Kees Cook
2026-10-06 20:42 ` [PATCH v1 1/3] efi/libstub: Declare the x86 stub's assembly entry points Kees Cook
2026-10-06 20:42 ` Kees Cook [this message]
2026-10-07  9:20   ` [PATCH v1 2/3] efi/libstub: Build the x86 stub from KBUILD_CFLAGS Nathan Chancellor
2026-10-06 20:42 ` [PATCH v1 3/3] efi/libstub: Disable kernel stack erasing in the common flags Kees Cook
2026-10-07  9:21   ` Nathan Chancellor

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20261006204224.1536491-2-kees@kernel.org \
    --to=kees@kernel.org \
    --cc=ardb@kernel.org \
    --cc=ilias.apalodimas@linaro.org \
    --cc=justinstitt@google.com \
    --cc=linux-efi@vger.kernel.org \
    --cc=linux-hardening@vger.kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=llvm@lists.linux.dev \
    --cc=morbo@google.com \
    --cc=nathan@kernel.org \
    --cc=ndesaulniers@google.com \
    --cc=nsc@kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®