From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org X-Spam-Level: X-Spam-Status: No, score=-7.1 required=3.0 tests=DKIMWL_WL_HIGH,DKIM_SIGNED, DKIM_VALID,DKIM_VALID_AU,INCLUDES_PATCH,MAILING_LIST_MULTI,SIGNED_OFF_BY, SPF_HELO_NONE,SPF_PASS autolearn=ham autolearn_force=no version=3.4.0 Received: from mail.kernel.org (mail.kernel.org [198.145.29.99]) by smtp.lore.kernel.org (Postfix) with ESMTP id A1897C433DF for ; Mon, 15 Jun 2020 10:55:57 +0000 (UTC) Received: from vger.kernel.org (vger.kernel.org [23.128.96.18]) by mail.kernel.org (Postfix) with ESMTP id 7DD6120714 for ; Mon, 15 Jun 2020 10:55:57 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=default; t=1592218557; bh=QaBa2U9Geoqv5p35xEZGCPFzj0swu4OiDh55cMIarDQ=; h=Date:From:To:Cc:Subject:In-Reply-To:References:List-ID:From; b=Kz3G01Hw/JiTnHBPFY8EnJruyy7tEDyz5mnn7sfiFeH9GcFYf6o417/3jbZu9pExt dpUQJrdx4tMFqqA9b1KGun38OQBltBQGVG29cHn2u7HKbsbqS/vWJCsLx912NJAzXx wpCtoBiCT2RbaWkPIbw43kUql0JYKyoBwV57PyQQ= Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1729569AbgFOKz4 (ORCPT ); Mon, 15 Jun 2020 06:55:56 -0400 Received: from mail.kernel.org ([198.145.29.99]:58296 "EHLO mail.kernel.org" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1728860AbgFOKz4 (ORCPT ); Mon, 15 Jun 2020 06:55:56 -0400 Received: from disco-boy.misterjones.org (disco-boy.misterjones.org [51.254.78.96]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mail.kernel.org (Postfix) with ESMTPSA id 759C82068E; Mon, 15 Jun 2020 10:55:55 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=default; t=1592218555; bh=QaBa2U9Geoqv5p35xEZGCPFzj0swu4OiDh55cMIarDQ=; h=Date:From:To:Cc:Subject:In-Reply-To:References:From; b=uIlbWLp6f1Vl5kwtuO2o8tEhAOPhh8OwsbhlCIUjVE5onhQxrcOt2paYytzhQFZ+S ELIHnWlyL61RYWU/C3dTm+2G2hErdEZSbK5DW3FL9qg5z91Ymd4N6jhMqSAN1YD6Je HKrDTYLd1K0oZDSgUbNGNojGjlv4ZletzawM1YYY= Received: from disco-boy.misterjones.org ([51.254.78.96] helo=www.loen.fr) by disco-boy.misterjones.org with esmtpsa (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.92) (envelope-from ) id 1jkmmP-0034WH-Vp; Mon, 15 Jun 2020 11:55:54 +0100 MIME-Version: 1.0 Content-Type: text/plain; charset=US-ASCII; format=flowed Content-Transfer-Encoding: 7bit Date: Mon, 15 Jun 2020 11:55:53 +0100 From: Marc Zyngier To: Mark Rutland Cc: kvm@vger.kernel.org, linux-arm-kernel@lists.infradead.org, kvmarm@lists.cs.columbia.edu, kernel-team@android.com Subject: Re: [PATCH 1/4] KVM: arm64: Enable Pointer Authentication at EL2 if available In-Reply-To: <20200615100318.GA773@C02TD0UTHF1T.local> References: <20200615081954.6233-1-maz@kernel.org> <20200615081954.6233-2-maz@kernel.org> <20200615100318.GA773@C02TD0UTHF1T.local> User-Agent: Roundcube Webmail/1.4.4 Message-ID: X-Sender: maz@kernel.org X-SA-Exim-Connect-IP: 51.254.78.96 X-SA-Exim-Rcpt-To: mark.rutland@arm.com, kvm@vger.kernel.org, linux-arm-kernel@lists.infradead.org, kvmarm@lists.cs.columbia.edu, kernel-team@android.com X-SA-Exim-Mail-From: maz@kernel.org X-SA-Exim-Scanned: No (on disco-boy.misterjones.org); SAEximRunCond expanded to false Sender: kvm-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: kvm@vger.kernel.org On 2020-06-15 11:03, Mark Rutland wrote: > On Mon, Jun 15, 2020 at 09:19:51AM +0100, Marc Zyngier wrote: >> While initializing EL2, switch Pointer Authentication if detected >> from EL1. We use the EL1-provided keys though. > > Perhaps "enable address authentication", to avoid confusion with > context-switch, and since generic authentication cannot be disabled > locally at EL2. Ah, fair enough. >> >> Signed-off-by: Marc Zyngier >> --- >> arch/arm64/kvm/hyp-init.S | 11 +++++++++++ >> 1 file changed, 11 insertions(+) >> >> diff --git a/arch/arm64/kvm/hyp-init.S b/arch/arm64/kvm/hyp-init.S >> index 6e6ed5581eed..81732177507d 100644 >> --- a/arch/arm64/kvm/hyp-init.S >> +++ b/arch/arm64/kvm/hyp-init.S >> @@ -104,6 +104,17 @@ alternative_else_nop_endif >> */ >> mov_q x4, (SCTLR_EL2_RES1 | (SCTLR_ELx_FLAGS & ~SCTLR_ELx_A)) >> CPU_BE( orr x4, x4, #SCTLR_ELx_EE) >> +alternative_if ARM64_HAS_ADDRESS_AUTH_ARCH >> + b 1f >> +alternative_else_nop_endif >> +alternative_if_not ARM64_HAS_ADDRESS_AUTH_IMP_DEF >> + b 2f >> +alternative_else_nop_endif > > I see this is the same pattern we use in the kvm context switch, but I > think we can use the ARM64_HAS_ADDRESS_AUTH cap instead (likewise in > the > existing code). > > AFAICT that won't permit mismatch given both > ARM64_HAS_ADDRESS_AUTH_ARCH > and ARM64_HAS_ADDRESS_AUTH_IMP_DEF are dealt with as > ARM64_CPUCAP_BOOT_CPU_FEATURE. That'd be a nice cleanup, as the two back to back alternatives are a bit hard to read. > >> +1: >> + orr x4, x4, #(SCTLR_ELx_ENIA | SCTLR_ELx_ENIB) >> + orr x4, x4, #SCTLR_ELx_ENDA >> + orr x4, x4, #SCTLR_ELx_ENDB > > Assuming we have a spare register, it would be nice if we could follow > the same > pattern as in proc.S, where we do: > > | ldr x2, =SCTLR_ELx_ENIA | SCTLR_ELx_ENIB | \ > | SCTLR_ELx_ENDA | SCTLR_ELx_ENDB > | orr x0, x0, x2 > > ... though we could/should use mov_q rather than a load literal, here > and in > proc.S. Looks like this code isn't in -rc1 anymore, replaced with a mov_q in __ptrauth_keys_init_cpu. I'll switch to that in v2. Thanks, M. -- Jazz is not dead. It just smells funny...