* [PATCH v3 0/2] Update UMIP config parameter and docs
@ 2019-11-05 21:25 Moger, Babu
2019-11-05 21:25 ` [PATCH v3 1/2] x86/Kconfig: Rename UMIP config parameter Moger, Babu
2019-11-05 21:25 ` [PATCH v3 2/2] x86/umip: Update the comments to cover generic x86 processors Moger, Babu
0 siblings, 2 replies; 5+ messages in thread
From: Moger, Babu @ 2019-11-05 21:25 UTC (permalink / raw)
To: tglx@linutronix.de, mingo@redhat.com, bp@alien8.de, hpa@zytor.com,
pbonzini@redhat.com, rkrcmar@redhat.com,
sean.j.christopherson@intel.com, vkuznets@redhat.com,
wanpengli@tencent.com, jmattson@google.com
Cc: x86@kernel.org, joro@8bytes.org, Moger, Babu, luto@kernel.org,
zohar@linux.ibm.com, yamada.masahiro@socionext.com,
nayna@linux.ibm.com, linux-kernel@vger.kernel.org,
kvm@vger.kernel.org, zohar@linux.ibm.com,
yamada.masahiro@socionext.com, ebiederm@xmission.com,
ricardo.neri-calderon@linux.intel.com, bshanks@codeweavers.com
AMD 2nd generation EPYC processors support the UMIP feature.
So, update the Kconfig and umip related documentation.
---
v3:
Removed X86 depend check. Just kept CPU_SUP_* check.
Updated the comments in umip.c to make it bit generic.
v2:
Learned that for the hardware that support UMIP, we dont need to
emulate. Removed the emulation related code and just submitting
the config changes.
Babu Moger (2):
x86/Kconfig: Rename UMIP config parameter
x86/umip: Update the comments to cover generic x86 processors
arch/x86/Kconfig | 10 +++++-----
arch/x86/include/asm/disabled-features.h | 2 +-
arch/x86/include/asm/umip.h | 4 ++--
arch/x86/kernel/Makefile | 2 +-
arch/x86/kernel/umip.c | 12 ++++++------
5 files changed, 15 insertions(+), 15 deletions(-)
--
^ permalink raw reply [flat|nested] 5+ messages in thread* [PATCH v3 1/2] x86/Kconfig: Rename UMIP config parameter
2019-11-05 21:25 [PATCH v3 0/2] Update UMIP config parameter and docs Moger, Babu
@ 2019-11-05 21:25 ` Moger, Babu
2019-11-07 1:31 ` Ricardo Neri
2019-11-05 21:25 ` [PATCH v3 2/2] x86/umip: Update the comments to cover generic x86 processors Moger, Babu
1 sibling, 1 reply; 5+ messages in thread
From: Moger, Babu @ 2019-11-05 21:25 UTC (permalink / raw)
To: tglx@linutronix.de, mingo@redhat.com, bp@alien8.de, hpa@zytor.com,
pbonzini@redhat.com, rkrcmar@redhat.com,
sean.j.christopherson@intel.com, vkuznets@redhat.com,
wanpengli@tencent.com, jmattson@google.com
Cc: x86@kernel.org, joro@8bytes.org, Moger, Babu, luto@kernel.org,
zohar@linux.ibm.com, yamada.masahiro@socionext.com,
nayna@linux.ibm.com, linux-kernel@vger.kernel.org,
kvm@vger.kernel.org, zohar@linux.ibm.com,
yamada.masahiro@socionext.com, ebiederm@xmission.com,
ricardo.neri-calderon@linux.intel.com, bshanks@codeweavers.com
AMD 2nd generation EPYC processors support the UMIP (User-Mode
Instruction Prevention) feature. So, rename X86_INTEL_UMIP to
generic X86_UMIP and modify the text to cover both Intel and AMD.
Signed-off-by: Babu Moger <babu.moger@amd.com>
---
arch/x86/Kconfig | 10 +++++-----
arch/x86/include/asm/disabled-features.h | 2 +-
arch/x86/include/asm/umip.h | 4 ++--
arch/x86/kernel/Makefile | 2 +-
4 files changed, 9 insertions(+), 9 deletions(-)
diff --git a/arch/x86/Kconfig b/arch/x86/Kconfig
index d6e1faa28c58..b7fb285d7c0f 100644
--- a/arch/x86/Kconfig
+++ b/arch/x86/Kconfig
@@ -1880,13 +1880,13 @@ config X86_SMAP
If unsure, say Y.
-config X86_INTEL_UMIP
+config X86_UMIP
def_bool y
- depends on CPU_SUP_INTEL
- prompt "Intel User Mode Instruction Prevention" if EXPERT
+ depends on CPU_SUP_INTEL || CPU_SUP_AMD
+ prompt "User Mode Instruction Prevention" if EXPERT
---help---
- The User Mode Instruction Prevention (UMIP) is a security
- feature in newer Intel processors. If enabled, a general
+ User Mode Instruction Prevention (UMIP) is a security
+ feature in newer x86 processors. If enabled, a general
protection fault is issued if the SGDT, SLDT, SIDT, SMSW
or STR instructions are executed in user mode. These instructions
unnecessarily expose information about the hardware state.
diff --git a/arch/x86/include/asm/disabled-features.h b/arch/x86/include/asm/disabled-features.h
index a5ea841cc6d2..8e1d0bb46361 100644
--- a/arch/x86/include/asm/disabled-features.h
+++ b/arch/x86/include/asm/disabled-features.h
@@ -22,7 +22,7 @@
# define DISABLE_SMAP (1<<(X86_FEATURE_SMAP & 31))
#endif
-#ifdef CONFIG_X86_INTEL_UMIP
+#ifdef CONFIG_X86_UMIP
# define DISABLE_UMIP 0
#else
# define DISABLE_UMIP (1<<(X86_FEATURE_UMIP & 31))
diff --git a/arch/x86/include/asm/umip.h b/arch/x86/include/asm/umip.h
index db43f2a0d92c..aeed98c3c9e1 100644
--- a/arch/x86/include/asm/umip.h
+++ b/arch/x86/include/asm/umip.h
@@ -4,9 +4,9 @@
#include <linux/types.h>
#include <asm/ptrace.h>
-#ifdef CONFIG_X86_INTEL_UMIP
+#ifdef CONFIG_X86_UMIP
bool fixup_umip_exception(struct pt_regs *regs);
#else
static inline bool fixup_umip_exception(struct pt_regs *regs) { return false; }
-#endif /* CONFIG_X86_INTEL_UMIP */
+#endif /* CONFIG_X86_UMIP */
#endif /* _ASM_X86_UMIP_H */
diff --git a/arch/x86/kernel/Makefile b/arch/x86/kernel/Makefile
index 3578ad248bc9..52ce1e239525 100644
--- a/arch/x86/kernel/Makefile
+++ b/arch/x86/kernel/Makefile
@@ -134,7 +134,7 @@ obj-$(CONFIG_EFI) += sysfb_efi.o
obj-$(CONFIG_PERF_EVENTS) += perf_regs.o
obj-$(CONFIG_TRACING) += tracepoint.o
obj-$(CONFIG_SCHED_MC_PRIO) += itmt.o
-obj-$(CONFIG_X86_INTEL_UMIP) += umip.o
+obj-$(CONFIG_X86_UMIP) += umip.o
obj-$(CONFIG_UNWINDER_ORC) += unwind_orc.o
obj-$(CONFIG_UNWINDER_FRAME_POINTER) += unwind_frame.o
^ permalink raw reply related [flat|nested] 5+ messages in thread* Re: [PATCH v3 1/2] x86/Kconfig: Rename UMIP config parameter
2019-11-05 21:25 ` [PATCH v3 1/2] x86/Kconfig: Rename UMIP config parameter Moger, Babu
@ 2019-11-07 1:31 ` Ricardo Neri
2019-11-07 10:07 ` Borislav Petkov
0 siblings, 1 reply; 5+ messages in thread
From: Ricardo Neri @ 2019-11-07 1:31 UTC (permalink / raw)
To: Moger, Babu
Cc: tglx@linutronix.de, mingo@redhat.com, bp@alien8.de, hpa@zytor.com,
pbonzini@redhat.com, rkrcmar@redhat.com,
sean.j.christopherson@intel.com, vkuznets@redhat.com,
wanpengli@tencent.com, jmattson@google.com, x86@kernel.org,
joro@8bytes.org, luto@kernel.org, zohar@linux.ibm.com,
yamada.masahiro@socionext.com, nayna@linux.ibm.com,
linux-kernel@vger.kernel.org, kvm@vger.kernel.org,
ebiederm@xmission.com, bshanks@codeweavers.com
On Tue, Nov 05, 2019 at 09:25:32PM +0000, Moger, Babu wrote:
> AMD 2nd generation EPYC processors support the UMIP (User-Mode
> Instruction Prevention) feature. So, rename X86_INTEL_UMIP to
> generic X86_UMIP and modify the text to cover both Intel and AMD.
>
> Signed-off-by: Babu Moger <babu.moger@amd.com>
> ---
> arch/x86/Kconfig | 10 +++++-----
> arch/x86/include/asm/disabled-features.h | 2 +-
> arch/x86/include/asm/umip.h | 4 ++--
> arch/x86/kernel/Makefile | 2 +-
> 4 files changed, 9 insertions(+), 9 deletions(-)
>
> diff --git a/arch/x86/Kconfig b/arch/x86/Kconfig
> index d6e1faa28c58..b7fb285d7c0f 100644
> --- a/arch/x86/Kconfig
> +++ b/arch/x86/Kconfig
> @@ -1880,13 +1880,13 @@ config X86_SMAP
>
> If unsure, say Y.
>
> -config X86_INTEL_UMIP
> +config X86_UMIP
> def_bool y
> - depends on CPU_SUP_INTEL
> - prompt "Intel User Mode Instruction Prevention" if EXPERT
> + depends on CPU_SUP_INTEL || CPU_SUP_AMD
> + prompt "User Mode Instruction Prevention" if EXPERT
> ---help---
> - The User Mode Instruction Prevention (UMIP) is a security
> - feature in newer Intel processors. If enabled, a general
> + User Mode Instruction Prevention (UMIP) is a security
> + feature in newer x86 processors. If enabled, a general
Better to say certain x86 processors? Intel and AMD have it but what
about others?
Thanks and BR,
Ricardo
^ permalink raw reply [flat|nested] 5+ messages in thread
* Re: [PATCH v3 1/2] x86/Kconfig: Rename UMIP config parameter
2019-11-07 1:31 ` Ricardo Neri
@ 2019-11-07 10:07 ` Borislav Petkov
0 siblings, 0 replies; 5+ messages in thread
From: Borislav Petkov @ 2019-11-07 10:07 UTC (permalink / raw)
To: Ricardo Neri
Cc: Moger, Babu, tglx@linutronix.de, mingo@redhat.com, hpa@zytor.com,
pbonzini@redhat.com, rkrcmar@redhat.com,
sean.j.christopherson@intel.com, vkuznets@redhat.com,
wanpengli@tencent.com, jmattson@google.com, x86@kernel.org,
joro@8bytes.org, luto@kernel.org, zohar@linux.ibm.com,
yamada.masahiro@socionext.com, nayna@linux.ibm.com,
linux-kernel@vger.kernel.org, kvm@vger.kernel.org,
ebiederm@xmission.com, bshanks@codeweavers.com
On Wed, Nov 06, 2019 at 05:31:36PM -0800, Ricardo Neri wrote:
> > + feature in newer x86 processors. If enabled, a general
>
> Better to say certain x86 processors? Intel and AMD have it but what
> about others?
Changed it to "some x86 processors".
Thx.
--
Regards/Gruss,
Boris.
https://people.kernel.org/tglx/notes-about-netiquette
^ permalink raw reply [flat|nested] 5+ messages in thread
* [PATCH v3 2/2] x86/umip: Update the comments to cover generic x86 processors
2019-11-05 21:25 [PATCH v3 0/2] Update UMIP config parameter and docs Moger, Babu
2019-11-05 21:25 ` [PATCH v3 1/2] x86/Kconfig: Rename UMIP config parameter Moger, Babu
@ 2019-11-05 21:25 ` Moger, Babu
1 sibling, 0 replies; 5+ messages in thread
From: Moger, Babu @ 2019-11-05 21:25 UTC (permalink / raw)
To: tglx@linutronix.de, mingo@redhat.com, bp@alien8.de, hpa@zytor.com,
pbonzini@redhat.com, rkrcmar@redhat.com,
sean.j.christopherson@intel.com, vkuznets@redhat.com,
wanpengli@tencent.com, jmattson@google.com
Cc: x86@kernel.org, joro@8bytes.org, Moger, Babu, luto@kernel.org,
zohar@linux.ibm.com, yamada.masahiro@socionext.com,
nayna@linux.ibm.com, linux-kernel@vger.kernel.org,
kvm@vger.kernel.org, zohar@linux.ibm.com,
yamada.masahiro@socionext.com, ebiederm@xmission.com,
ricardo.neri-calderon@linux.intel.com, bshanks@codeweavers.com
AMD 2nd generation EPYC processors also support UMIP feature.
Update the comments to cover generic x86 processors.
Signed-off-by: Babu Moger <babu.moger@amd.com>
---
arch/x86/kernel/umip.c | 12 ++++++------
1 file changed, 6 insertions(+), 6 deletions(-)
diff --git a/arch/x86/kernel/umip.c b/arch/x86/kernel/umip.c
index 548fefed71ee..8ccef6c495dc 100644
--- a/arch/x86/kernel/umip.c
+++ b/arch/x86/kernel/umip.c
@@ -1,6 +1,6 @@
/*
- * umip.c Emulation for instruction protected by the Intel User-Mode
- * Instruction Prevention feature
+ * umip.c Emulation for instruction protected by the User-Mode Instruction
+ * Prevention feature
*
* Copyright (c) 2017, Intel Corporation.
* Ricardo Neri <ricardo.neri-calderon@linux.intel.com>
@@ -18,10 +18,10 @@
/** DOC: Emulation for User-Mode Instruction Prevention (UMIP)
*
- * The feature User-Mode Instruction Prevention present in recent Intel
- * processor prevents a group of instructions (SGDT, SIDT, SLDT, SMSW and STR)
- * from being executed with CPL > 0. Otherwise, a general protection fault is
- * issued.
+ * User-Mode Instruction Prevention is a security feature present in recent
+ * x86 processors that, when enabled, prevents a group of instructions (SGDT,
+ * SIDT, SLDT, SMSW and STR) from being run in user mode by issuing a general
+ * protection fault if the instruction is executed with CPL > 0.
*
* Rather than relaying to the user space the general protection fault caused by
* the UMIP-protected instructions (in the form of a SIGSEGV signal), it can be
^ permalink raw reply related [flat|nested] 5+ messages in thread
end of thread, other threads:[~2019-11-07 10:08 UTC | newest]
Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2019-11-05 21:25 [PATCH v3 0/2] Update UMIP config parameter and docs Moger, Babu
2019-11-05 21:25 ` [PATCH v3 1/2] x86/Kconfig: Rename UMIP config parameter Moger, Babu
2019-11-07 1:31 ` Ricardo Neri
2019-11-07 10:07 ` Borislav Petkov
2019-11-05 21:25 ` [PATCH v3 2/2] x86/umip: Update the comments to cover generic x86 processors Moger, Babu
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox