From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org X-Spam-Level: X-Spam-Status: No, score=-13.7 required=3.0 tests=BAYES_00,DKIMWL_WL_HIGH, DKIM_SIGNED,DKIM_VALID,HEADER_FROM_DIFFERENT_DOMAINS,INCLUDES_CR_TRAILER, INCLUDES_PATCH,MAILING_LIST_MULTI,SPF_HELO_NONE,SPF_PASS,UNPARSEABLE_RELAY, URIBL_BLOCKED autolearn=ham autolearn_force=no version=3.4.0 Received: from mail.kernel.org (mail.kernel.org [198.145.29.99]) by smtp.lore.kernel.org (Postfix) with ESMTP id 12A74C4361B for ; Wed, 9 Dec 2020 11:58:31 +0000 (UTC) Received: from merlin.infradead.org (merlin.infradead.org [205.233.59.134]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mail.kernel.org (Postfix) with ESMTPS id BB892221FA for ; Wed, 9 Dec 2020 11:58:30 +0000 (UTC) DMARC-Filter: OpenDMARC Filter v1.3.2 mail.kernel.org BB892221FA Authentication-Results: mail.kernel.org; dmarc=fail (p=none dis=none) header.from=arm.com Authentication-Results: mail.kernel.org; spf=none smtp.mailfrom=linux-arm-kernel-bounces+linux-arm-kernel=archiver.kernel.org@lists.infradead.org DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.infradead.org; s=merlin.20170209; h=Sender:Content-Transfer-Encoding: Content-Type:Cc:List-Subscribe:List-Help:List-Post:List-Archive: List-Unsubscribe:List-Id:MIME-Version:Content-ID:In-Reply-To:References: Message-ID:Date:Subject:To:From:Reply-To:Content-Description:Resent-Date: Resent-From:Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:List-Owner; bh=GqzfD2d1D/nl0lStMRrgNDBxR79SOwgBVVyld66tiA0=; b=dAoeStn19zkect9xfk4Ry79E4 gJIMs+tIvjTCy6w6MG/0kcLqgLu7S74S+JZCiWApXdK1GY74frcYVXfcCNTqsheUqPGY7HJAiwFL6 Xs3nXPpPR/F4qHW+ee5vw92ZGVYLzuUHe0U2OxTIoxhFQhfSLfVZVKhtR2Q73JA9amHFNk0G18yks DDBDjHdN1yLcj9T6+G/BYBAoPDigFkB8IhKu0RGsF7wK6I56N+xG4eMt1W40f9OVy0lEXt/NSL4iA EtuCneZ+V3zcxC3Pb6xtyTXaKFEmFmQewNIR+lNwxzIFO1R5RNSNJ53NX6kdKP9yx6aLqfiYUR7zB BC1fnhWcw==; Received: from localhost ([::1] helo=merlin.infradead.org) by merlin.infradead.org with esmtp (Exim 4.92.3 #3 (Red Hat Linux)) id 1kmy5j-0003CO-PZ; Wed, 09 Dec 2020 11:57:07 +0000 Received: from mail-am6eur05on2063.outbound.protection.outlook.com ([40.107.22.63] helo=EUR05-AM6-obe.outbound.protection.outlook.com) by merlin.infradead.org with esmtps (Exim 4.92.3 #3 (Red Hat Linux)) id 1kmy5h-0003By-0T for linux-arm-kernel@lists.infradead.org; Wed, 09 Dec 2020 11:57:06 +0000 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=armh.onmicrosoft.com; s=selector2-armh-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=BDGc0Vd2UbG53ta8uGgdTIVwv6j0xkAvDt5T8R8dTd0=; b=R9FUBrcRKXQE4YUmmQUKto+RaeLVRBmT05p7FtT0CAi4jnzfiFa5q0bz+mtnjEYMjohxcV5wGtZMen78iD8k+KmEqsxl5xnxOS3z3QrcMaHhLEpkMi5G/y9Zth3eoPXhodLQvRSqHH6C5f2l9j0IToEq06sssgCygJaYcDqzA4c= Received: from AM6P195CA0050.EURP195.PROD.OUTLOOK.COM (2603:10a6:209:87::27) by AM0PR08MB4004.eurprd08.prod.outlook.com (2603:10a6:208:12a::12) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.3632.17; Wed, 9 Dec 2020 11:57:01 +0000 Received: from AM5EUR03FT035.eop-EUR03.prod.protection.outlook.com (2603:10a6:209:87:cafe::52) by AM6P195CA0050.outlook.office365.com (2603:10a6:209:87::27) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.3654.12 via Frontend Transport; Wed, 9 Dec 2020 11:57:01 +0000 X-MS-Exchange-Authentication-Results: spf=pass (sender IP is 63.35.35.123) smtp.mailfrom=arm.com; lists.infradead.org; dkim=pass (signature was verified) header.d=armh.onmicrosoft.com;lists.infradead.org; dmarc=pass action=none header.from=arm.com; Received-SPF: Pass (protection.outlook.com: domain of arm.com designates 63.35.35.123 as permitted sender) receiver=protection.outlook.com; client-ip=63.35.35.123; helo=64aa7808-outbound-1.mta.getcheckrecipient.com; Received: from 64aa7808-outbound-1.mta.getcheckrecipient.com (63.35.35.123) by AM5EUR03FT035.mail.protection.outlook.com (10.152.16.119) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.3654.12 via Frontend Transport; Wed, 9 Dec 2020 11:57:01 +0000 Received: ("Tessian outbound 6af064f543d4:v71"); Wed, 09 Dec 2020 11:57:01 +0000 X-CheckRecipientChecked: true X-CR-MTA-CID: f50a4144668b3cc0 X-CR-MTA-TID: 64aa7808 Received: from a8514e26edfa.2 by 64aa7808-outbound-1.mta.getcheckrecipient.com id 40FC518E-E29C-4857-B65F-3EC99F813A84.1; Wed, 09 Dec 2020 11:56:23 +0000 Received: from EUR01-HE1-obe.outbound.protection.outlook.com by 64aa7808-outbound-1.mta.getcheckrecipient.com with ESMTPS id a8514e26edfa.2 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384); Wed, 09 Dec 2020 11:56:23 +0000 ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=ZP+xnRrgtNb+qJ8W15KA8LMM3ENtUdoFTj/6AN+sJeFFx5t4Fe/B09+Uk21t4/rq2f/8w25eH9iDA180eKReanwT/32Y33gOUghdfuzdZITHQ+yS5gTDRg64md9LqUUIm7+yzgXy7dOI6wuiTrOzucp/9IOou0+RSJNKbJk2VSwKWHQiBpJTGWt9GLzbwyc3aiwZqrrCPY4ijR3rnYYAjuHHD3v5QlQpKOmc5WUxVyx/BwXOKgxku8F+fDD7DhQwjdCE0Xsvgm/Hhx+QVSNCwAVmmfTi7uHs1ZREZWOJ5O2LL7MPNtBWljtiwb9BF2M8fCxjoiH0TqmcgT+FjEP+JQ== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=BDGc0Vd2UbG53ta8uGgdTIVwv6j0xkAvDt5T8R8dTd0=; b=lJ38PPg0TU7rGKqchrfBAgUxpnt2GurpvH2eTFeH8wqUuVkS+XdbRiwmq/29vaYe5jpLucPJry2O/8nBNTzpUqk8nkMHrqV6rhd+1k1qYeZ+BSsdl7s/Ppx+YF6FCxBcOFAe93Y9xAznoHYZTN4BHDRlIMXiHOX9/gQV90Mtdhp+LI7k9eiUmkae7Ed9efS3ahvuOHMNH4XlnB/71YTXDKwyg5IBy4qj5rXeMvniIvQ3sK/xwJSxTIYPVRI7GmcMF5zcndRMVUFBLrJlaOETA0EyvUuf6VsGucy27/aluWNXFWaDdKu961ZICKcMDxCQXYC2LsMxQv1zuNS7fgiXdQ== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=arm.com; dmarc=pass action=none header.from=arm.com; dkim=pass header.d=arm.com; arc=none DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=armh.onmicrosoft.com; s=selector2-armh-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=BDGc0Vd2UbG53ta8uGgdTIVwv6j0xkAvDt5T8R8dTd0=; b=R9FUBrcRKXQE4YUmmQUKto+RaeLVRBmT05p7FtT0CAi4jnzfiFa5q0bz+mtnjEYMjohxcV5wGtZMen78iD8k+KmEqsxl5xnxOS3z3QrcMaHhLEpkMi5G/y9Zth3eoPXhodLQvRSqHH6C5f2l9j0IToEq06sssgCygJaYcDqzA4c= Received: from AM6PR08MB5256.eurprd08.prod.outlook.com (2603:10a6:20b:e7::32) by AM6PR08MB5205.eurprd08.prod.outlook.com (2603:10a6:20b:ee::28) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.3654.12; Wed, 9 Dec 2020 11:56:19 +0000 Received: from AM6PR08MB5256.eurprd08.prod.outlook.com ([fe80::e8bb:a83c:f130:cb68]) by AM6PR08MB5256.eurprd08.prod.outlook.com ([fe80::e8bb:a83c:f130:cb68%4]) with mapi id 15.20.3632.021; Wed, 9 Dec 2020 11:56:18 +0000 From: Daniel Kiss To: Will Deacon , Peter Collingbourne Subject: Re: [PATCH 2/2] arm64: Configure kernel's PTR_AUTH key when it is built with PTR_AUTH. Thread-Topic: [PATCH 2/2] arm64: Configure kernel's PTR_AUTH key when it is built with PTR_AUTH. Thread-Index: AQHWzOrpvkZxk+V6vUCT1jYRSOt4EqnsQYiAgADHUoCAAI9XgIABAFmAgAASOwA= Date: Wed, 9 Dec 2020 11:56:18 +0000 Message-ID: <26513330-006C-4B28-9123-656CAEB70E1A@arm.com> References: <20201207224625.13764-1-daniel.kiss@arm.com> <20201207224625.13764-3-daniel.kiss@arm.com> <20201208110030.GA13960@gaia> <20201209105103.GA7273@willie-the-truck> In-Reply-To: <20201209105103.GA7273@willie-the-truck> Accept-Language: en-US Content-Language: en-US X-MS-Has-Attach: X-MS-TNEF-Correlator: x-mailer: Apple Mail (2.3608.120.23.2.4) Authentication-Results-Original: kernel.org; dkim=none (message not signed) header.d=none;kernel.org; dmarc=none action=none header.from=arm.com; x-originating-ip: [2001:4c4c:1b2a:1000:54b0:bd3f:b2dc:e12f] x-ms-publictraffictype: Email X-MS-Office365-Filtering-HT: Tenant X-MS-Office365-Filtering-Correlation-Id: bd69fef8-d927-45a9-d2eb-08d89c3989dc x-ms-traffictypediagnostic: AM6PR08MB5205:|AM0PR08MB4004: x-ms-exchange-transport-forked: True X-Microsoft-Antispam-PRVS: x-checkrecipientrouted: true nodisclaimer: true x-ms-oob-tlc-oobclassifiers: OLM:7691;OLM:7691; X-MS-Exchange-SenderADCheck: 1 X-Microsoft-Antispam-Untrusted: BCL:0; X-Microsoft-Antispam-Message-Info-Original: mlGLmZe7SArVP0Jax+1ZZ1SyGX10iGKM4hS3/LFMmFo1O8AiJ4GjFO58adWY7V+3TFI18HlHnNJCCb0UHWruwLM2Khv/8/i3W1/nvsnod1ceeq+8mt5TXUhaPq73WefImgNTQwMAZ8KHRNgQkh1o2S9lPSW92Aks+pn+Uz81EJO4Rd6SRZvptLTMa6JVsx+/vBbgEjDGesMxu2Lq8dn1kNhYrz7rwJEauOA7P8GYMF9BW8sh3GuwdSV8mxeCul13THtv0OkRJXW27Swo1UyYFL0tDBEKqgKaf6iUfxXi+aN0vxKACXFabByEFxCYsVdiCnqoCQ8498TFrHPLSY+57Yf+wF/6qdjQXXCWxW77ln0IvPx+Un7QGrYaP8L9xcGGKwGXc4xuqZsf/EKxd2oEy3gOSipuz23CW09vN7L4xbW59Ct+Neq8DYUnysB2c+rNRlVAHdTmI4fxg7gS8vWTdA== X-Forefront-Antispam-Report-Untrusted: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:AM6PR08MB5256.eurprd08.prod.outlook.com; PTR:; CAT:NONE; SFS:(4636009)(366004)(376002)(346002)(136003)(396003)(39860400002)(64756008)(36756003)(33656002)(5660300002)(6512007)(8936002)(8676002)(86362001)(2906002)(66946007)(66556008)(66476007)(66446008)(76116006)(6486002)(91956017)(316002)(4326008)(71200400001)(53546011)(478600001)(6506007)(54906003)(186003)(83380400001)(110136005)(966005)(2616005)(45980500001); DIR:OUT; SFP:1101; x-ms-exchange-antispam-messagedata: =?us-ascii?Q?LlJP8AQy4IjL12nCcfN2oWDk1TUZN04JiYyQWZ7GW+191qLRjHjqutxAzQd1?= =?us-ascii?Q?rXzPmJkd5WkJ4Ncj6PAVn4sQeH4JQBGvQT+Qq9AyN1Z0ApU6KuGSZiz6+Ltw?= =?us-ascii?Q?S08D69if+XL6OXKFF+rqXBDRUADjvLdtRLDa7JrQmdb7Rujg28VWo1oyVAQu?= =?us-ascii?Q?kmoYx4iGHu/68AcKjh6gMlZRwyrVmBoacgCGIbf4YUcUTI/4l8HqMG8f9p7p?= =?us-ascii?Q?/yGMuvwQHtGMhAcum9WUcLuHCugDyQWmDkUjZWo5w/fueQKYo/PmlcpvNCjV?= =?us-ascii?Q?XOjC/3aCI+N7RIqOYxBpn5roPwtamW6NrOC+HOkLKUtEjAiPhd4pKNCuhMdE?= =?us-ascii?Q?tfhrs3jRcp7a0OMr90A0N3nZMmCcuoDY11oBrQoduvDGlM4CQcygl3UPmDZi?= =?us-ascii?Q?UQDbyYZ1Li6QWHRFJn2V9b/owrhjIjDk1bp0ucA4mVh86I2hJZCX0MEH/8bv?= =?us-ascii?Q?GTsgh3I0h/isRgVV9/Hb8Mh/yWLfDOGdlM/U9wCpgCAl/d3wa8dVAoWINsQF?= =?us-ascii?Q?4wBB7PlsrT7pwsTAIXJNnyra/el/xXeBU3YaxKZhdCFlvSbr/iEGF02syrZn?= =?us-ascii?Q?wD4EnRRHqjvKm/565WZ2DfbwtKHgfhY7SbLd7sepkYvJezjVJQ0Y1cgsCHcg?= =?us-ascii?Q?xoAxGmQPzxS4V+Esm5p6K28ohg1oCpbkaluJcp8E5Jij86S6J0q2vUfH1ZqO?= =?us-ascii?Q?n8geuPoLBzudIcNn3WmhiotNVcAjUBO5rzF3XvWwtIVxJ+OJTGQkYgONrGwe?= =?us-ascii?Q?2tnh3I9VdFh3qWnmzOup38gRltF/JZmAVpz1Gqr+X57bKX9/fJ7VkCqPwBIn?= =?us-ascii?Q?ZXAcb2CYyCqMxiR2haQRCkEd0MhaSXki5Ogw+XTNwFYpofO5TqhsLQm6u8gO?= =?us-ascii?Q?gtBxjs+RkVNPn23Or2614+woz+0VTQ4GKb7kiq89Top4zHHb7LhdIRkpfJvb?= =?us-ascii?Q?pF9rafToKFZSob7YUDaX5icwae36xWw1WzNxObEpdZyaQApcmpmHyYd+gyaJ?= =?us-ascii?Q?WcZA4g/jJkOhI4C9EUJG6ljP5zI4saElcxEsXx7qKk9QUKQUSdB1S3V13oJN?= =?us-ascii?Q?14AXylYL?= Content-ID: MIME-Version: 1.0 X-MS-Exchange-Transport-CrossTenantHeadersStamped: AM6PR08MB5205 Original-Authentication-Results: kernel.org; dkim=none (message not signed) header.d=none;kernel.org; dmarc=none action=none header.from=arm.com; X-EOPAttributedMessage: 0 X-MS-Exchange-Transport-CrossTenantHeadersStripped: AM5EUR03FT035.eop-EUR03.prod.protection.outlook.com X-MS-Office365-Filtering-Correlation-Id-Prvs: 74daf73c-a69f-48a6-95d0-08d89c39709e X-Microsoft-Antispam: BCL:0; X-Microsoft-Antispam-Message-Info: Qgf9xR8pE2qE/lQputna+4B8rKO8yoVm+l45drNi/SXnXXsI/+1StNQ/ANZW4LcXP/nrf8d4vS6RMjk77C5Fl+V35j9d8Uacyn5XCnchKumlL3Vus5c0ia7qscrJhGtSPI6l5ISeR98S0AOzcTg5LbrP7UaNSwG/u8f2nk7jXLbkbhumcoT5aYs6pN6XxWbkL/qlAVbYTkRDHyaoFs2AyapJcLyy0WUqrNJi7CF1DY8LJSIxfc25j635vT1MNbtrubIFGCc497CommhymAhw14yLX9f7W7ZcnKk3msjpKUSfSskn80z3hafBiVf5dowxHbl2ZR/15KfujI9kNTSTVxsTJWT7RrlHVgzBlhwnHM7nY/H4guSsrGp4LCuJJWh59wlktMiVZzwBIq2bBkUDTEjkB4Hqwfxwkx/wEhRk4/DfxPoCcpubmgYjS8OdYX/y+/WGvOM8MHwD79cVr8R/8FtuOGmTCqHxoNIVncK0Znk= X-Forefront-Antispam-Report: CIP:63.35.35.123; CTRY:IE; LANG:en; SCL:1; SRV:; IPV:CAL; SFV:NSPM; H:64aa7808-outbound-1.mta.getcheckrecipient.com; PTR:ec2-63-35-35-123.eu-west-1.compute.amazonaws.com; CAT:NONE; SFS:(4636009)(136003)(376002)(396003)(39860400002)(346002)(46966005)(33656002)(54906003)(36756003)(316002)(6486002)(110136005)(47076004)(83380400001)(966005)(356005)(4326008)(36906005)(82740400003)(81166007)(2906002)(53546011)(186003)(86362001)(6512007)(2616005)(5660300002)(26005)(82310400003)(6506007)(8676002)(70586007)(8936002)(478600001)(70206006)(336012); DIR:OUT; SFP:1101; X-OriginatorOrg: arm.com X-MS-Exchange-CrossTenant-OriginalArrivalTime: 09 Dec 2020 11:57:01.2254 (UTC) X-MS-Exchange-CrossTenant-Network-Message-Id: bd69fef8-d927-45a9-d2eb-08d89c3989dc X-MS-Exchange-CrossTenant-Id: f34e5979-57d9-4aaa-ad4d-b122a662184d X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=f34e5979-57d9-4aaa-ad4d-b122a662184d; Ip=[63.35.35.123]; Helo=[64aa7808-outbound-1.mta.getcheckrecipient.com] X-MS-Exchange-CrossTenant-AuthSource: AM5EUR03FT035.eop-EUR03.prod.protection.outlook.com X-MS-Exchange-CrossTenant-AuthAs: Anonymous X-MS-Exchange-CrossTenant-FromEntityHeader: HybridOnPrem X-MS-Exchange-Transport-CrossTenantHeadersStamped: AM0PR08MB4004 X-CRM114-Version: 20100106-BlameMichelson ( TRE 0.8.0 (BSD) ) MR-646709E3 X-CRM114-CacheID: sfid-20201209_065705_186407_E638BC04 X-CRM114-Status: GOOD ( 26.99 ) X-BeenThere: linux-arm-kernel@lists.infradead.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Cc: Catalin Marinas , Linux ARM Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit Sender: "linux-arm-kernel" Errors-To: linux-arm-kernel-bounces+linux-arm-kernel=archiver.kernel.org@lists.infradead.org > On 9 Dec 2020, at 11:51, Will Deacon wrote: > > On Tue, Dec 08, 2020 at 11:33:33AM -0800, Peter Collingbourne wrote: >> On Tue, Dec 8, 2020 at 3:00 AM Catalin Marinas wrote: >>> >>> On Mon, Dec 07, 2020 at 03:07:07PM -0800, Peter Collingbourne wrote: >>>> On Mon, Dec 7, 2020 at 2:46 PM Daniel Kiss wrote: >>>>> If the kernel is not compiled with CONFIG_ARM64_PTR_AUTH_KERNEL, >>>>> then the kernel does not need a key and kernel's key could be disabled. >>>>> >>>>> Signed-off-by: Daniel Kiss >>>>> --- >>>>> arch/arm64/include/asm/asm_pointer_auth.h | 68 ++++++++++++++++------- >>>>> arch/arm64/include/asm/processor.h | 2 + >>>>> arch/arm64/kernel/asm-offsets.c | 4 ++ >>>>> 3 files changed, 55 insertions(+), 19 deletions(-) >>>>> >>>>> diff --git a/arch/arm64/include/asm/asm_pointer_auth.h b/arch/arm64/include/asm/asm_pointer_auth.h >>>>> index 52dead2a8640..af3d16027e8f 100644 >>>>> --- a/arch/arm64/include/asm/asm_pointer_auth.h >>>>> +++ b/arch/arm64/include/asm/asm_pointer_auth.h >>>>> @@ -14,6 +14,12 @@ >>>>> * thread.keys_user.ap*. >>>>> */ >>>>> .macro ptrauth_keys_install_user tsk, tmp1, tmp2, tmp3 >>>>> +#ifndef CONFIG_ARM64_PTR_AUTH_KERNEL >>>>> + /* Reenable A key */ >>>>> + mrs \tmp1, sctlr_el1 >>>>> + orr \tmp1, \tmp1, SCTLR_ELx_ENIA >>>>> + msr sctlr_el1, \tmp1 >>>>> +#endif >>>> >>>> We should avoid an unconditional MSR on exit like this as it is >>>> expensive (for my PR_PAC_SET_ENABLED_KEYS series I measured the cost >>>> of entry/exit MSR as 43.7ns on Cortex-A75 and 33.0ns on Apple M1). In >>>> that series I take care not to touch SCTLR_EL1 unless necessary. >>>> Likewise for the MSRs on entry below. >>> >>> I think that's how Daniel attempted the first (internal) version of >>> these patches. In theory you don't need to touch SCTLR_ELx_EN* at all as >>> long as the kernel does not use any PAC instructions. However, I was >>> a bit concerned about this and thought it's safer if, when >>> !CONFIG_ARM64_PTR_AUTH_KERNEL, the EnIA bit is cleared while in the >>> kernel. >>> >>> If we can guarantee that the compiler does not generate any PAC >>> instructions (it may assume they are no-ops) and vendor modules don't >>> have such instructions either, we may be able to relax this. >> >> The way I see it it isn't too different from the current prohibition >> on using IB in the kernel (and to a lesser extent DA/DB/GA since those >> can't be accessed from nop-space as far as I'm aware), or NEON >> instructions in most parts of the kernel, or the stack protector >> cookie when building with -fno-stack-protector etc. i.e. if you do >> that then you're breaking the ABI. >> >> Is your concern that distributions may default to enabling >> -mbranch-protection which would result in the PAC instructions being >> used? To address that I think it is reasonable to expect the compiler >> not to use PAC instructions when passing -mbranch-protection=none, and >> if the compiler does so then that is a bug in the compiler. > > I'm inclined to agree. At the very least, I think we should start from a > position where we assume the compiler doesn't randomly emit these > instructions, and then we can revisit that decision in future if it turns > out to be wrong. > I agree the compiler shall not emit these instructions when not requested. I have two corner cases to consider: Assembly code may contain pac/aut instructions unconditionally, like: https://elixir.bootlin.com/linux/v5.10-rc7/source/arch/arm64/crypto/poly1305-armv8.pl#L348 A module may be compiled against a kernel with CONFIG_ARM64_PTR_AUTH_KERNEL=y but later it is loaded on a kernel which is built with CONFIG_ARM64_PTR_AUTH_KERNEL=n. If the key is not disabled here, the CONFIG_ARM64_PTR_AUTH_KERNEL is part of the KMI otherwise not. Daniel _______________________________________________ linux-arm-kernel mailing list linux-arm-kernel@lists.infradead.org http://lists.infradead.org/mailman/listinfo/linux-arm-kernel