From 1eb128820e3cd5f6d15529f2a730c3ec46d3b00b Mon Sep 17 00:00:00 2001 From: Sami Tolvanen Date: Wed, 14 Oct 2020 13:24:28 -0700 Subject: [PATCH] ANDROID: scs: use vmapped shadow stacks by default Enable CONFIG_SHADOW_CALL_STACK_VMAP by default, and as we allocate a full page for the stack, allow the kernel use all of it. Bug: 169781940 Change-Id: Ie8eaa7f24e9bf10ff28a302ac98ad843b71c9c2a Signed-off-by: Sami Tolvanen --- arch/Kconfig | 1 + include/linux/scs.h | 5 +++++ 2 files changed, 6 insertions(+) diff --git a/arch/Kconfig b/arch/Kconfig index d53afd0c8323..88401dab0689 100644 --- a/arch/Kconfig +++ b/arch/Kconfig @@ -549,6 +549,7 @@ config SHADOW_CALL_STACK config SHADOW_CALL_STACK_VMAP bool "Use virtually mapped shadow call stacks" depends on SHADOW_CALL_STACK + default y help Use virtually mapped shadow call stacks. Selecting this option provides better stack exhaustion protection, but increases per-thread diff --git a/include/linux/scs.h b/include/linux/scs.h index c5572fd770b0..f8c8beff7850 100644 --- a/include/linux/scs.h +++ b/include/linux/scs.h @@ -14,12 +14,17 @@ #ifdef CONFIG_SHADOW_CALL_STACK +#ifdef CONFIG_SHADOW_CALL_STACK_VMAP +#define SCS_SIZE PAGE_SIZE +#else /* * In testing, 1 KiB shadow stack size (i.e. 128 stack frames on a 64-bit * architecture) provided ~40% safety margin on stack usage while keeping * memory allocation overhead reasonable. */ #define SCS_SIZE 1024UL +#endif + #define GFP_SCS (GFP_KERNEL | __GFP_ZERO) /*