All of lore.kernel.org
 help / color / mirror / Atom feed
From: Josh Poimboeuf <jpoimboe@kernel.org>
To: KP Singh <kpsingh@kernel.org>
Cc: linux-kernel@vger.kernel.org, pjt@google.com, evn@google.com,
	tglx@linutronix.de, mingo@redhat.com, bp@alien8.de,
	dave.hansen@linux.intel.com, x86@kernel.org, hpa@zytor.com,
	peterz@infradead.org, pawan.kumar.gupta@linux.intel.com,
	kim.phillips@amd.com, alexandre.chartre@oracle.com,
	daniel.sneddon@linux.intel.com,
	"José Oliveira" <joseloliveira11@gmail.com>,
	"Rodrigo Branco" <rodrigo@kernelhacking.com>,
	"Alexandra Sandulescu" <aesa@google.com>,
	"Jim Mattson" <jmattson@google.com>,
	stable@vger.kernel.org
Subject: Re: [PATCH RESEND] x86/speculation: Fix user-mode spectre-v2 protection with KERNEL_IBRS
Date: Mon, 20 Feb 2023 04:13:50 -0800	[thread overview]
Message-ID: <20230220121350.aidsipw3kd4rsyss@treble> (raw)
In-Reply-To: <20230220120127.1975241-1-kpsingh@kernel.org>

On Mon, Feb 20, 2023 at 01:01:27PM +0100, KP Singh wrote:
> +static inline bool spectre_v2_user_no_stibp(enum spectre_v2_mitigation mode)
> +{
> +	/* When IBRS or enhanced IBRS is enabled, STIBP is not needed.
> +	 *
> +	 * However, With KERNEL_IBRS, the IBRS bit is cleared on return
> +	 * to user and the user-mode code needs to be able to enable protection
> +	 * from cross-thread training, either by always enabling STIBP or
> +	 * by enabling it via prctl.
> +	 */
> +	return (spectre_v2_in_ibrs_mode(mode) &&
> +		!cpu_feature_enabled(X86_FEATURE_KERNEL_IBRS));
> +}

The comments and code confused me, they both seem to imply some
distinction between IBRS and KERNEL_IBRS, but in the kernel those are
functionally the same thing.  e.g., the kernel doesn't have a user IBRS
mode.

And, unless I'm missing some subtlety here, it seems to be a convoluted
way of saying that eIBRS doesn't need STIBP in user space.

It would be simpler to just call it spectre_v2_in_eibrs_mode().

static inline bool spectre_v2_in_eibrs_mode(enum spectre_v2_mitigation mode)
{
	return mode == SPECTRE_V2_EIBRS ||
	       mode == SPECTRE_V2_EIBRS_RETPOLINE ||
	       mode == SPECTRE_V2_EIBRS_LFENCE;
}

And then spectre_v2_in_ibrs_mode() could be changed to call that:

static inline bool spectre_v2_in_eibrs_mode(enum spectre_v2_mitigation mode)
{
	return spectre_v2_in_eibrs_mode(mode) || mode == SPECTRE_V2_IBRS;
}

> @@ -1496,6 +1504,7 @@ static void __init spectre_v2_select_mitigation(void)
>  		break;
>  
>  	case SPECTRE_V2_IBRS:
> +		pr_err("enabling KERNEL_IBRS");

Why?

> @@ -2327,7 +2336,7 @@ static ssize_t mmio_stale_data_show_state(char *buf)
>  
>  static char *stibp_state(void)
>  {
> -	if (spectre_v2_in_ibrs_mode(spectre_v2_enabled))
> +	if (spectre_v2_user_no_stibp(spectre_v2_enabled))
>  		return "";

This seems like old cruft, can we just remove this check altogether?  In
the eIBRS case, spectre_v2_user_stibp will already have its default of
SPECTRE_V2_USER_NONE.

-- 
Josh

  reply	other threads:[~2023-02-20 12:14 UTC|newest]

Thread overview: 39+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2023-02-20 12:01 [PATCH RESEND] x86/speculation: Fix user-mode spectre-v2 protection with KERNEL_IBRS KP Singh
2023-02-20 12:13 ` Josh Poimboeuf [this message]
2023-02-20 12:20   ` KP Singh
2023-02-20 12:34     ` KP Singh
2023-02-20 14:31       ` Borislav Petkov
2023-02-20 15:38         ` Dave Hansen
2023-02-20 19:57         ` Andrew Cooper
2023-02-20 21:10           ` Borislav Petkov
2023-02-20 23:01             ` KP Singh
2023-02-20 23:30             ` Andrew Cooper
2023-02-20 23:45               ` KP Singh
2023-02-21 18:52                 ` KP Singh
2023-02-21 10:59               ` Borislav Petkov
2023-02-20 16:34       ` Josh Poimboeuf
2023-02-20 17:46         ` Borislav Petkov
2023-02-20 17:59           ` Josh Poimboeuf
2023-02-20 18:01             ` KP Singh
2023-02-20 18:22               ` Borislav Petkov
2023-02-20 18:44                 ` KP Singh
2023-02-20 18:51                   ` Borislav Petkov
2023-02-20 18:56                     ` KP Singh
2023-02-20 19:02                       ` Borislav Petkov
2023-02-20 19:10                         ` KP Singh
2023-02-20 18:27               ` [PATCH] x86/bugs: Allow STIBP with IBRS Josh Poimboeuf
2023-02-20 18:28                 ` kernel test robot
2023-02-20 18:33                 ` KP Singh
2023-02-20 18:59                   ` Josh Poimboeuf
2023-02-20 19:04                     ` KP Singh
2023-02-20 19:19                       ` Josh Poimboeuf
2023-02-20 18:34                 ` Borislav Petkov
2023-02-20 19:09                   ` Josh Poimboeuf
2023-02-20 19:16                     ` KP Singh
2023-02-20 19:35                       ` Josh Poimboeuf
2023-02-20 19:38                         ` KP Singh
2023-02-20 19:20                     ` Borislav Petkov
2023-02-22  1:20                     ` Pawan Gupta
2023-02-22  1:26                       ` KP Singh
2023-02-22  1:38                         ` Pawan Gupta
2023-02-27 19:59 ` [tip: x86/urgent] x86/speculation: Allow enabling STIBP with legacy IBRS tip-bot2 for KP Singh

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20230220121350.aidsipw3kd4rsyss@treble \
    --to=jpoimboe@kernel.org \
    --cc=aesa@google.com \
    --cc=alexandre.chartre@oracle.com \
    --cc=bp@alien8.de \
    --cc=daniel.sneddon@linux.intel.com \
    --cc=dave.hansen@linux.intel.com \
    --cc=evn@google.com \
    --cc=hpa@zytor.com \
    --cc=jmattson@google.com \
    --cc=joseloliveira11@gmail.com \
    --cc=kim.phillips@amd.com \
    --cc=kpsingh@kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=mingo@redhat.com \
    --cc=pawan.kumar.gupta@linux.intel.com \
    --cc=peterz@infradead.org \
    --cc=pjt@google.com \
    --cc=rodrigo@kernelhacking.com \
    --cc=stable@vger.kernel.org \
    --cc=tglx@linutronix.de \
    --cc=x86@kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.