Re: [PATCH v3] ARM: traps: Implement KCFI trap handler for ARM32
Karl Mehltretter <[email protected]> Mon, 27 Jul 2026 03:37:16 +0200
| Newsgroups | org.kernel.vger.linux-hardening,dev.linux.lists.llvm,org.infradead.lists.linux-arm-kernel,org.kernel.vger.linux-kernel |
|---|---|
| Message-ID | <[email protected]> |
On Wed, Jul 15, 2026 at 10:52:27AM +0100, Kees Cook wrote:
> + /* Check for EOR/EORS immediate: cccc 0010 0x1n Rn Rd immediate */
> + if ((instr_prev & 0x0fe00000) == 0x02200000) {
> + /* Extract EOR immediate value and XOR to reconstruct type */
> + u32 rotate = (instr_prev >> 8) & 0xf;
> + u32 imm8 = instr_prev & 0xff;
> + u32 imm32 = (imm8 >> (rotate * 2)) | (imm8 << (32 - rotate * 2));
With CONFIG_UBSAN_SHIFT=y, I reproduced the following in QEMU with GCC
v14 KCFI and LKDTM CFI_FORWARD_PROTO:
UBSAN: shift-out-of-bounds in arch/arm/kernel/traps.c:555:48
shift exponent 32 is too large for 32-bit type 'unsigned int'
Could this use ror32() from <linux/bitops.h> instead?
Thanks,
Karl