[MODERATED] Re: [patch V6 07/14] MDS basics 7
Borislav Petkov <[email protected]>
| Newsgroups | org.kernel.lore.historical-speck |
|---|---|
| Message-ID | <[email protected]> |
On Fri, Mar 01, 2019 at 10:47:45PM +0100, speck for Thomas Gleixner wrote: > Subject: [patch V6 07/14] x86/speculation/mds: Clear CPU buffers on exit to user > From: Thomas Gleixner <[email protected]> > > Add a static key which controls the invocation of the CPU buffer clear > mechanism on exit to user space and add the call into > prepare_exit_to_usermode() and do_nmi() right before actually returning. > > Add documentation which kernel to user space transition this covers and > explain why some corner cases are not mitigated. > > Signed-off-by: Thomas Gleixner <[email protected]> > Reviewed-by: Greg Kroah-Hartman <[email protected]> > > --- > V4 --> v5: Use an inline helper instead of open coding it. > Rework the documentation paragraph about exceptions. > > V3 --> V4: Add #DS mitigation and document that the #MC corner case > is really not interesting. > > V3: Add NMI conditional on user regs and update documentation accordingly. > Use the static branch scheme suggested by Peter. Fix typos ... > --- > Documentation/x86/mds.rst | 52 +++++++++++++++++++++++++++++++++++ > arch/x86/entry/common.c | 3 ++ > arch/x86/include/asm/nospec-branch.h | 13 ++++++++ > arch/x86/kernel/cpu/bugs.c | 3 ++ > arch/x86/kernel/nmi.c | 4 ++ > arch/x86/kernel/traps.c | 7 ++++ > 6 files changed, 82 insertions(+) ... > --- a/arch/x86/kernel/traps.c > +++ b/arch/x86/kernel/traps.c > @@ -366,6 +366,13 @@ dotraplinkage void do_double_fault(struc > regs->ip = (unsigned long)general_protection; > regs->sp = (unsigned long)&gpregs->orig_ax; > > + /* > + * This situation can be triggered by userspace via > + * modify_ldt(2) and the return does not take the regular > + * user space exit, so a CPU buffer clear is required when > + * MDS mitigation is enabled. > + */ > + mds_user_clear_cpu_buffers(); > return; > } > #endif Looks like the traps.c change is missing a hunk, see below. Otherwise: arch/x86/kernel/traps.c: In function ‘do_double_fault’: arch/x86/kernel/traps.c:375:3: error: implicit declaration of function ‘mds_user_clear_cpu_buffers’ [-Werror=implicit-function-declaration] mds_user_clear_cpu_buffers(); ^~~~~~~~~~~~~~~~~~~~~~~~~~ cc1: some warnings being treated as errors make[2]: *** [scripts/Makefile.build:276: arch/x86/kernel/traps.o] Error 1 make[2]: *** Waiting for unfinished jobs.... make[1]: *** [scripts/Makefile.build:492: arch/x86/kernel] Error 2 make: *** [Makefile:1043: arch/x86] Error 2 make: *** Waiting for unfinished jobs.... --- diff --git a/arch/x86/kernel/traps.c b/arch/x86/kernel/traps.c index 5942060dba9a..ce33f7f672d6 100644 --- a/arch/x86/kernel/traps.c +++ b/arch/x86/kernel/traps.c @@ -61,6 +61,7 @@ #include <asm/mpx.h> #include <asm/vm86.h> #include <asm/umip.h> +#include <asm/nospec-branch.h> #ifdef CONFIG_X86_64 #include <asm/x86_init.h> --- with that Reviewed-by: Borislav Petkov <[email protected]> -- Regards/Gruss, Boris. SUSE Linux GmbH, GF: Felix Imendörffer, Jane Smithard, Graham Norton, HRB 21284 (AG Nürnberg) --