[Qemu-devel] [PATCH 00/26] target/arm: Implement ARMv8.3-PAuth

From: Richard Henderson
Subject: [Qemu-devel] [PATCH 00/26] target/arm: Implement ARMv8.3-PAuth
Date: Fri, 7 Dec 2018 04:36:05 -0600

This has survivied a small user-only smoke test.

I need to build a kernel with the right patches in order to both
test this in system mode as well as verify the hashes that I am
producing vs ARM Fast Model.


$ aarch64-linux-gcc-8.0.1 -msign-return-address=all z.c
$ ./aarch64-linux-user/qemu-aarch64 -D z -d in_asm,op,cpu -singlestep ./a.out 
Hello, World!

IN: main
0x004005a4:  d503233f  hint     #0x19

 ld_i32 tmp0,env,$0xffffffffffffffe4
 movi_i32 tmp1,$0x0
 brcond_i32 tmp0,tmp1,lt,$L0

 ---- 00000000004005a4 0000000000000000 0000000000000000
 call pacia,$0x20,$1,lr,env,lr,sp
 goto_tb $0x1
 movi_i64 pc,$0x4005a8
 exit_tb $0x5608e569e281
 set_label $L0
 exit_tb $0x5608e569e283

- X29=00000040007ff4a0 X30=00000040008778a4  SP=00000040007ff4a0
+ X29=00000040007ff4a0 X30=c0270040008778a4  SP=00000040007ff4a0

IN: main
0x004005c4:  d50323bf  hint     #0x1d

 ld_i32 tmp0,env,$0xffffffffffffffe4
 movi_i32 tmp1,$0x0
 brcond_i32 tmp0,tmp1,lt,$L0

 ---- 00000000004005c4 0000000000000000 0000000000000000
 call autia,$0x20,$1,lr,env,lr,sp
 goto_tb $0x1
 movi_i64 pc,$0x4005c8
 exit_tb $0x5608e5706241
 set_label $L0
 exit_tb $0x5608e5706243

- X29=00000040007ff4a0 X30=c0270040008778a4  SP=00000040007ff4a0
+ X29=00000040007ff4a0 X30=00000040008778a4  SP=00000040007ff4a0

So, yay!  We sign something with high bits set and can get
back the original pointer.  Note that this is with key==0,
as I do not yet initialize AutKeyIA to anything, as the
real kernel would for a given thread.

This is based on my v3 ARMv8.1-LOR patches, which in turn
are based on Peter's target-arm.next.  The full tree is
available at

  https://github.com/rth7680/qemu.git tgt-arm-pauth

and this version is tagged tgt-arm-pauth-hello-world.  ;-)


Richard Henderson (26):
  target/arm: Add state for the ARMv8.3-PAuth extension
  target/arm: Add SCTLR bits through ARMv8.5
  target/arm: Add PAuth active bit to tbflags
  target/arm: Add PAuth helpers
  target/arm: Decode PAuth within system hint space
  target/arm: Rearrange decode in disas_data_proc_1src
  target/arm: Decode PAuth within disas_data_proc_1src
  target/arm: Decode PAuth within disas_data_proc_2src
  target/arm: Move helper_exception_return to helper-a64.c
  target/arm: Add new_pc argument to helper_exception_return
  target/arm: Rearrange decode in disas_uncond_b_reg
  target/arm: Decode PAuth within disas_uncond_b_reg
  target/arm: Decode Load/store register (pac)
  target/arm: Move cpu_mmu_index out of line
  target/arm: Introduce arm_mmu_idx
  target/arm: Create ARMVAParameters and helpers
  target/arm: Reuse aa64_va_parameters for setting tbflags
  target/arm: Export aa64_va_parameters to internals.h
  target/arm: Implement pauth_strip
  target/arm: Implement pauth_auth
  target/arm: Implement pauth_addpac
  target/arm: Implement pauth_computepac
  target/arm: Add PAuth system registers
  target/arm: Enable PAuth for user-only -cpu max
  target/arm: Enable PAuth for user-only, part 2
  target/arm: Tidy TBI handling in gen_a64_set_pc

 target/arm/cpu.h           | 151 ++++-----
 target/arm/helper-a64.h    |  14 +
 target/arm/helper.h        |   1 -
 target/arm/internals.h     |  35 ++
 target/arm/translate.h     |   2 +
 target/arm/cpu.c           |   6 +
 target/arm/cpu64.c         |   4 +
 target/arm/helper-a64.c    | 631 +++++++++++++++++++++++++++++++++++++
 target/arm/helper.c        | 459 ++++++++++++++++-----------
 target/arm/machine.c       |  23 ++
 target/arm/op_helper.c     | 155 ---------
 target/arm/translate-a64.c | 531 ++++++++++++++++++++++++++-----
 12 files changed, 1519 insertions(+), 493 deletions(-)


