From: Szabolcs Nagy Date: Thu, 6 Oct 2022 11:00:39 +0000 (+0100) Subject: cheri: malloc: add tunable to turn narrowing off X-Git-Url: http://git.ipfire.org/cgi-bin/gitweb.cgi?a=commitdiff_plain;h=1fa257f3382943680713180969b72385219285e4;p=thirdparty%2Fglibc.git cheri: malloc: add tunable to turn narrowing off --- diff --git a/elf/dl-tunables.list b/elf/dl-tunables.list index e6a56b30705..83f47dcd9a8 100644 --- a/elf/dl-tunables.list +++ b/elf/dl-tunables.list @@ -159,6 +159,13 @@ glibc { maxval: 255 security_level: SXID_IGNORE } + cap_narrowing { + type: INT_32 + minval: 0 + maxval: 1 + default: 1 + security_level: SXID_IGNORE + } } rtld { diff --git a/malloc/arena.c b/malloc/arena.c index 894f49b9114..85cc2ad066e 100644 --- a/malloc/arena.c +++ b/malloc/arena.c @@ -326,6 +326,12 @@ ptmalloc_init (void) tcache_key_initialize (); #endif +#ifdef __CHERI_PURE_CAPABILITY__ + if (TUNABLE_GET_FULL (glibc, mem, cap_narrowing, int32_t, NULL) == 0) + cap_narrowing_enabled = false; + else + cap_narrowing_enabled = true; +#endif cap_init (); #ifdef USE_MTAG diff --git a/manual/tunables.texi b/manual/tunables.texi index 83cdcdac6dc..ffe0202627f 100644 --- a/manual/tunables.texi +++ b/manual/tunables.texi @@ -612,3 +612,9 @@ support in the kernel if this tunable has any non-zero value. The default value is @samp{0}, which disables all memory tagging. @end deftp + +@deftp Tunable glibc.mem.cap_narrowing +On CHERI architecture use capability bounds narrowing in the malloc +implementation. By default it is set to 1, to disable bounds narrowing +set it to 0. +@end deftp