From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1753173AbbD0Pqv (ORCPT ); Mon, 27 Apr 2015 11:46:51 -0400 Received: from mail.skyhub.de ([78.46.96.112]:33071 "EHLO mail.skyhub.de" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1752239AbbD0Pqs (ORCPT ); Mon, 27 Apr 2015 11:46:48 -0400 Date: Mon, 27 Apr 2015 17:46:31 +0200 From: Borislav Petkov To: Linus Torvalds Cc: Andy Lutomirski , Andy Lutomirski , X86 ML , "H. Peter Anvin" , Denys Vlasenko , Brian Gerst , Denys Vlasenko , Ingo Molnar , Steven Rostedt , Oleg Nesterov , Frederic Weisbecker , Alexei Starovoitov , Will Drewry , Kees Cook , Linux Kernel Mailing List Subject: Re: [PATCH] x86_64, asm: Work around AMD SYSRET SS descriptor attribute issue Message-ID: <20150427154631.GB28871@pd.tnic> References: <5d120f358612d73fc909f5bfa47e7bd082db0af0.1429841474.git.luto@kernel.org> <20150425211206.GE32099@pd.tnic> <20150427085305.GB6774@pd.tnic> <20150427113506.GG6774@pd.tnic> MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Disposition: inline In-Reply-To: User-Agent: Mutt/1.5.23 (2014-03-12) Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org On Mon, Apr 27, 2015 at 07:57:36AM -0700, Linus Torvalds wrote: > On Mon, Apr 27, 2015 at 4:35 AM, Borislav Petkov wrote: > > > > /* > > * Change top 16 bits to be the sign-extension of 47th bit, if this > > * changed %rcx, it was not canonical. > > */ > > ALTERNATIVE "", \ > > "shl $(64 - (47+1)), %rcx; \ > > sar $(64 - (47+1)), %rcx; \ > > cmpq %rcx, %r11; \ > > jne opportunistic_sysret_failed", X86_BUG_SYSRET_CANON_RCX > > Guys, if we're looking at cycles for this, then don't do the "exact > canonical test". and go back to just doing > > shr $__VIRTUAL_MASK_SHIFT, %rcx > jnz opportunistic_sysret_failed > > which is much smaller. Right, what about the false positives: 17be0aec74fb ("x86/asm/entry/64: Implement better check for canonical addresses") ? We don't care? > In fact, aim to make the conditional jump be a > two-byte one (jump forward to another jump if required - it's a > slow-path that doesn't matter at *all* for the taken case), and the > end result is just six bytes. That way you can use alternative to > replace it with one single noop on AMD. Well, even with the non-optimal NOPs (we end up with 4 3-byte NOPs and one single-byte), we're still better than the unconditional JMP I had there before: https://lkml.kernel.org/r/20150427143905.GK6774@pd.tnic (you might want to look at the raw email - marc.info breaks lines) I'll retest with the F16h NOPs to see whether there's any difference. Thanks. -- Regards/Gruss, Boris. ECO tip #101: Trim your mails when you reply. --