1 1.7 christos /* $NetBSD: kern_ssp.c,v 1.7 2016/12/06 02:55:42 christos Exp $ */ 2 1.1 christos 3 1.1 christos /*- 4 1.1 christos * Copyright (c) 2008 The NetBSD Foundation, Inc. 5 1.1 christos * All rights reserved. 6 1.1 christos * 7 1.1 christos * Redistribution and use in source and binary forms, with or without 8 1.1 christos * modification, are permitted provided that the following conditions 9 1.1 christos * are met: 10 1.1 christos * 1. Redistributions of source code must retain the above copyright 11 1.1 christos * notice, this list of conditions and the following disclaimer. 12 1.1 christos * 2. Redistributions in binary form must reproduce the above copyright 13 1.1 christos * notice, this list of conditions and the following disclaimer in the 14 1.1 christos * documentation and/or other materials provided with the distribution. 15 1.1 christos * 16 1.1 christos * THIS SOFTWARE IS PROVIDED BY THE NETBSD FOUNDATION, INC. AND CONTRIBUTORS 17 1.1 christos * ``AS IS'' AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED 18 1.1 christos * TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR 19 1.1 christos * PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE FOUNDATION OR CONTRIBUTORS 20 1.1 christos * BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR 21 1.1 christos * CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF 22 1.1 christos * SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS 23 1.1 christos * INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN 24 1.1 christos * CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) 25 1.1 christos * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE 26 1.1 christos * POSSIBILITY OF SUCH DAMAGE. 27 1.1 christos */ 28 1.1 christos 29 1.1 christos #include <sys/cdefs.h> 30 1.7 christos __KERNEL_RCSID(0, "$NetBSD: kern_ssp.c,v 1.7 2016/12/06 02:55:42 christos Exp $"); 31 1.1 christos 32 1.2 kenh #include <sys/param.h> 33 1.1 christos #include <sys/systm.h> 34 1.1 christos #include <sys/intr.h> 35 1.6 tls #include <sys/cprng.h> 36 1.1 christos 37 1.1 christos #if defined(__SSP__) || defined(__SSP_ALL__) 38 1.7 christos # ifdef _RUMPKERNEL 39 1.7 christos __weak_alias(__stack_chk_guard, stack_chk_guard) 40 1.7 christos __weak_alias(__stack_chk_fail, stack_chk_fail) 41 1.7 christos # define SSP_STATIC static __used 42 1.7 christos # else 43 1.7 christos # define stack_chk_guard __stack_chk_guard 44 1.7 christos # define stack_chk_fail __stack_chk_fail 45 1.7 christos # define SSP_STATIC 46 1.7 christos #endif 47 1.1 christos 48 1.7 christos SSP_STATIC long stack_chk_guard[8] = {0, 0, 0, 0, 0, 0, 0, 0,}; 49 1.7 christos SSP_STATIC void stack_chk_fail(void); 50 1.7 christos 51 1.7 christos SSP_STATIC void 52 1.7 christos stack_chk_fail(void) 53 1.1 christos { 54 1.1 christos panic("stack overflow detected; terminated"); 55 1.1 christos } 56 1.1 christos 57 1.1 christos void 58 1.1 christos ssp_init(void) 59 1.1 christos { 60 1.1 christos int s; 61 1.1 christos 62 1.5 njoly aprint_debug("Initializing SSP: "); 63 1.1 christos /* 64 1.1 christos * We initialize ssp here carefully: 65 1.1 christos * 1. after we got some entropy 66 1.1 christos * 2. without calling a function 67 1.1 christos */ 68 1.1 christos size_t i; 69 1.7 christos long guard[__arraycount(stack_chk_guard)]; 70 1.1 christos 71 1.6 tls cprng_fast(guard, sizeof(guard)); 72 1.1 christos s = splhigh(); 73 1.1 christos for (i = 0; i < __arraycount(guard); i++) 74 1.7 christos stack_chk_guard[i] = guard[i]; 75 1.1 christos splx(s); 76 1.1 christos for (i = 0; i < __arraycount(guard); i++) 77 1.5 njoly aprint_debug("%lx ", guard[i]); 78 1.5 njoly aprint_debug("\n"); 79 1.1 christos } 80 1.1 christos #else 81 1.1 christos void 82 1.1 christos ssp_init(void) 83 1.1 christos { 84 1.1 christos } 85 1.1 christos #endif 86