]> git.ipfire.org Git - thirdparty/kernel/stable.git/commit
kbuild: add '-fno-stack-check' to kernel build options
authorLinus Torvalds <torvalds@linux-foundation.org>
Sat, 30 Dec 2017 01:34:43 +0000 (17:34 -0800)
committerSasha Levin <alexander.levin@microsoft.com>
Thu, 1 Mar 2018 00:32:18 +0000 (19:32 -0500)
commit49c74e3181f472eed405345bd4534e53e440ea1b
treeca8f01fc22460412032e39c96ccab73cb0476d97
parentc4d0c959edce5d01b895dd7619cfb837afdd3d50
kbuild: add '-fno-stack-check' to kernel build options

[ Upstream commit 3ce120b16cc548472f80cf8644f90eda958cf1b6 ]

It appears that hardened gentoo enables "-fstack-check" by default for
gcc.

That doesn't work _at_all_ for the kernel, because the kernel stack
doesn't act like a user stack at all: it's much smaller, and it doesn't
auto-expand on use.  So the extra "probe one page below the stack" code
generated by -fstack-check just breaks the kernel in horrible ways,
causing infinite double faults etc.

[ I have to say, that the particular code gcc generates looks very
  stupid even for user space where it works, but that's a separate
  issue.  ]

Reported-and-tested-by: Alexander Tsoy <alexander@tsoy.me>
Reported-and-tested-by: Toralf Förster <toralf.foerster@gmx.de>
Cc: stable@kernel.org
Cc: Dave Hansen <dave.hansen@intel.com>
Cc: Jiri Kosina <jikos@kernel.org>
Cc: Andy Lutomirski <luto@amacapital.net>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Sasha Levin <alexander.levin@microsoft.com>
Makefile