From: "Jürgen Groß" <jgross@suse.com>
To: Andrew Cooper <andrew.cooper3@citrix.com>,
Xen-devel <xen-devel@lists.xenproject.org>
Cc: Stefano Stabellini <sstabellini@kernel.org>,
Julien Grall <julien@xen.org>, Wei Liu <wl@xen.org>,
Konrad Rzeszutek Wilk <konrad.wilk@oracle.com>,
George Dunlap <George.Dunlap@eu.citrix.com>,
Jan Beulich <JBeulich@suse.com>,
Ian Jackson <ian.jackson@citrix.com>
Subject: Re: [Xen-devel] [PATCH v3 2/7] xen/nospec: Use always_inline to fix code gen for evaluate_nospec
Date: Wed, 23 Oct 2019 16:44:29 +0200 [thread overview]
Message-ID: <f6404c89-8d6e-e1a0-e8dc-414da3f294de@suse.com> (raw)
In-Reply-To: <20191023135812.21348-3-andrew.cooper3@citrix.com>
On 23.10.19 15:58, Andrew Cooper wrote:
> evaluate_nospec() is incredibly fragile, and this is one giant bodge.
>
> To correctly protect jumps, the generated code needs to be of the form:
>
> cmp/test <cond>
> jcc 1f
> lfence
> ...
> 1: lfence
> ...
>
> Critically, the lfence must be at the head of both basic blocks, later in the
> instruction stream than the conditional jump in need of protection.
>
> When a static inline is involved, the optimiser decides to be clever and
> rearranges the code as:
>
> pred:
> lfence
> <calculate cond>
> ret
>
> call pred
> cmp $0, %eax
> jcc 1f
> ...
> 1: ...
>
> which breaks the speculative safety.
>
> Any use of evaluate_nospec() needs all static inline predicates which use it
> to be declared always_inline to prevent the optimiser having the flexibility
> to generate unsafe code.
>
> Signed-off-by: Andrew Cooper <andrew.cooper3@citrix.com>
Release-acked-by: Juergen Gross <jgross@suse.com>
Juergen
_______________________________________________
Xen-devel mailing list
Xen-devel@lists.xenproject.org
https://lists.xenproject.org/mailman/listinfo/xen-devel
next prev parent reply other threads:[~2019-10-23 14:44 UTC|newest]
Thread overview: 42+ messages / expand[flat|nested] mbox.gz Atom feed top
2019-10-23 13:58 [Xen-devel] [PATCH for-4.13 v3 0/7] Unbreak evaluate_nospec() and livepatching Andrew Cooper
2019-10-23 13:58 ` [Xen-devel] [PATCH v3 1/7] x86/nospec: Two trivial fixes Andrew Cooper
2019-10-23 14:03 ` Jan Beulich
2019-10-23 14:43 ` Jürgen Groß
2019-10-23 13:58 ` [Xen-devel] [PATCH v3 2/7] xen/nospec: Use always_inline to fix code gen for evaluate_nospec Andrew Cooper
2019-10-23 14:44 ` Jürgen Groß [this message]
2019-10-25 12:03 ` Jan Beulich
2019-10-25 12:10 ` Andrew Cooper
2019-10-25 12:34 ` Jan Beulich
2019-10-25 15:27 ` Andrew Cooper
2019-10-25 15:40 ` Jan Beulich
2019-10-25 21:56 ` Norbert Manthey
2019-10-28 17:05 ` Andrew Cooper
2019-10-29 8:25 ` Norbert Manthey
2019-10-29 13:46 ` Andrew Cooper
2019-10-29 14:03 ` Jan Beulich
2019-10-29 14:16 ` Andrew Cooper
2019-10-29 14:33 ` Norbert Manthey
2019-10-29 16:53 ` Andrew Cooper
2019-10-30 8:33 ` Jan Beulich
2019-10-23 13:58 ` [Xen-devel] [PATCH v3 3/7] xen/nospec: Introduce CONFIG_SPECULATIVE_HARDEN_BRANCH Andrew Cooper
2019-10-23 14:45 ` Jürgen Groß
2019-10-25 12:04 ` Jan Beulich
2019-10-23 13:58 ` [Xen-devel] [PATCH v3 4/7] x86/nospec: Rename and rework l1tf-barrier as branch-harden Andrew Cooper
2019-10-23 14:43 ` Jürgen Groß
2019-10-25 12:09 ` Jan Beulich
2019-10-29 17:00 ` Andrew Cooper
2019-10-23 13:58 ` [Xen-devel] [PATCH v3 5/7] x86/livepatch: Fail the build if duplicate symbols exist Andrew Cooper
2019-10-23 14:46 ` Jürgen Groß
2019-10-23 16:14 ` Konrad Rzeszutek Wilk
2019-10-23 16:37 ` Ross Lagerwall
2019-10-24 12:03 ` Jan Beulich
2019-10-29 17:06 ` Andrew Cooper
2019-10-30 8:41 ` Jan Beulich
2019-10-30 10:37 ` Andrew Cooper
2019-10-30 11:21 ` Jan Beulich
2019-10-23 13:58 ` [Xen-devel] [PATCH for-next v3 6/7] x86/nospec: Move array_index_mask_nospec() into nospec.h Andrew Cooper
2019-10-25 12:10 ` Jan Beulich
2019-10-23 13:58 ` [Xen-devel] [PATCH v3 7/7] x86/nospec: Optimise array_index_mask_nospec() for power-of-2 arrays Andrew Cooper
2019-10-25 12:24 ` Jan Beulich
2019-10-25 12:58 ` Andrew Cooper
2019-10-25 13:25 ` Jan Beulich
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=f6404c89-8d6e-e1a0-e8dc-414da3f294de@suse.com \
--to=jgross@suse.com \
--cc=George.Dunlap@eu.citrix.com \
--cc=JBeulich@suse.com \
--cc=andrew.cooper3@citrix.com \
--cc=ian.jackson@citrix.com \
--cc=julien@xen.org \
--cc=konrad.wilk@oracle.com \
--cc=sstabellini@kernel.org \
--cc=wl@xen.org \
--cc=xen-devel@lists.xenproject.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.