From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Google-Smtp-Source: AH8x225LSSwbI8AenS6OTU1yviFUogtRdL9ZxvCCtwWT3V7vMkX1TLJ5gRE8cjZnmFgWl4tAhopt ARC-Seal: i=1; a=rsa-sha256; t=1519411229; cv=none; d=google.com; s=arc-20160816; b=oG6XVR3KQPDMp1X8s1Ay4x0KUpDz3a4TAjqkHfe0KkxpNmBOA3MPcyTFG6k0+UGQZY HswDSFxc7maBsR19Pz3YcmV2ZMtLOJ7QYDBxte6g6LV6P+dl1VXrt1T0WTrexy7aBouT OsPk+Zd8b/0960O65Nw4sD0nFf8TMpA/p8NDuGgWi/qwrVSAWplek9pQPoCjVVAjjtHD aGjfNRpoGP77rLdTCRMjaPHmnqXdS1YvrZGiWxecvjaXz5F1EHDqG/SHW4ebkaMEkNMO x+oR2MhO/kBX9kLMuzg/0ctgRPBsb1Ls9TP6ALXucEwkLxYhFDJfndhD+tJseMsSGEpC UdUQ== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=mime-version:user-agent:references:in-reply-to:message-id:date :subject:cc:to:from:arc-authentication-results; bh=DjFF6T9ZSIRRywSafnfS7uKy/3jJXE1S23PO5Z7oBsg=; b=heg0pLCYUmK7ly0n/34/StJxXy81D5YSx5gxmxCruyYxTMFRjTMAOxHJan2gbSIy+3 3fNc4YssOg5RzgyvqN2oZqm9oE2ZfrBvIxULk/UChDWzlhw965GMt1fLdl3Ft4gHbOBX ruaAo412/xWW6RK46fv+4ZEZ/0zOe0HmNa3PuJvXfptV4MHwrwTimU7oxByDocr8BAsa p/Z6IswhABYmkboHfXOAL8Po2qdW6PPdzFSKnn/dk2fCS5rypb9mAM4BeyB/Hh/BGNLY i5LiBgmX+nAlvhKVmMGEdPjgOQJg25kL4Ht5E2qcpU7cM7wnYU9ggfNofaXIFqzg2fRF 6UPg== ARC-Authentication-Results: i=1; mx.google.com; spf=softfail (google.com: domain of transitioning gregkh@linuxfoundation.org does not designate 90.92.71.90 as permitted sender) smtp.mailfrom=gregkh@linuxfoundation.org Authentication-Results: mx.google.com; spf=softfail (google.com: domain of transitioning gregkh@linuxfoundation.org does not designate 90.92.71.90 as permitted sender) smtp.mailfrom=gregkh@linuxfoundation.org From: Greg Kroah-Hartman To: linux-kernel@vger.kernel.org Cc: Greg Kroah-Hartman , stable@vger.kernel.org, "Peter Zijlstra (Intel)" , Thomas Gleixner , David Woodhouse , Andrea Arcangeli , Andi Kleen , Ashok Raj , Jun Nakajima , David Woodhouse , Linus Torvalds , rga@amazon.de, Dave Hansen , Asit Mallick , Andy Lutomirski , Josh Poimboeuf , Jason Baron , Paolo Bonzini , Dan Williams , Arjan Van De Ven , Tim Chen , Jack Wang Subject: [PATCH 4.4 166/193] KVM: x86: Make indirect calls in emulator speculation safe Date: Fri, 23 Feb 2018 19:26:39 +0100 Message-Id: <20180223170351.993016228@linuxfoundation.org> X-Mailer: git-send-email 2.16.2 In-Reply-To: <20180223170325.997716448@linuxfoundation.org> References: <20180223170325.997716448@linuxfoundation.org> User-Agent: quilt/0.65 X-stable: review MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 X-getmail-retrieved-from-mailbox: INBOX X-GMAIL-LABELS: =?utf-8?b?IlxcU2VudCI=?= X-GMAIL-THRID: =?utf-8?q?1593218149195818842?= X-GMAIL-MSGID: =?utf-8?q?1593218149195818842?= X-Mailing-List: linux-kernel@vger.kernel.org List-ID: 4.4-stable review patch. If anyone has any objections, please let me know. ------------------ From: Peter Zijlstra (cherry picked from commit 1a29b5b7f347a1a9230c1e0af5b37e3e571588ab) Replace the indirect calls with CALL_NOSPEC. Signed-off-by: Peter Zijlstra (Intel) Signed-off-by: Thomas Gleixner Reviewed-by: David Woodhouse Cc: Andrea Arcangeli Cc: Andi Kleen Cc: Ashok Raj Cc: Greg KH Cc: Jun Nakajima Cc: David Woodhouse Cc: Linus Torvalds Cc: rga@amazon.de Cc: Dave Hansen Cc: Asit Mallick Cc: Andy Lutomirski Cc: Josh Poimboeuf Cc: Jason Baron Cc: Paolo Bonzini Cc: Dan Williams Cc: Arjan Van De Ven Cc: Tim Chen Link: https://lkml.kernel.org/r/20180125095843.595615683@infradead.org [dwmw2: Use ASM_CALL_CONSTRAINT like upstream, now we have it] Signed-off-by: David Woodhouse [backport to 4.4] Signed-off-by: Jack Wang Signed-off-by: Greg Kroah-Hartman --- arch/x86/kvm/emulate.c | 9 +++++---- 1 file changed, 5 insertions(+), 4 deletions(-) --- a/arch/x86/kvm/emulate.c +++ b/arch/x86/kvm/emulate.c @@ -26,6 +26,7 @@ #include #include #include +#include #include "x86.h" #include "tss.h" @@ -1000,8 +1001,8 @@ static u8 test_cc(unsigned int condition void (*fop)(void) = (void *)em_setcc + 4 * (condition & 0xf); flags = (flags & EFLAGS_MASK) | X86_EFLAGS_IF; - asm("push %[flags]; popf; call *%[fastop]" - : "=a"(rc) : [fastop]"r"(fop), [flags]"r"(flags)); + asm("push %[flags]; popf; " CALL_NOSPEC + : "=a"(rc) : [thunk_target]"r"(fop), [flags]"r"(flags)); return rc; } @@ -5297,9 +5298,9 @@ static int fastop(struct x86_emulate_ctx ulong flags = (ctxt->eflags & EFLAGS_MASK) | X86_EFLAGS_IF; if (!(ctxt->d & ByteOp)) fop += __ffs(ctxt->dst.bytes) * FASTOP_SIZE; - asm("push %[flags]; popf; call *%[fastop]; pushf; pop %[flags]\n" + asm("push %[flags]; popf; " CALL_NOSPEC "; pushf; pop %[flags]\n" : "+a"(ctxt->dst.val), "+d"(ctxt->src.val), [flags]"+D"(flags), - [fastop]"+S"(fop) + [thunk_target]"+S"(fop) : "c"(ctxt->src2.val)); ctxt->eflags = (ctxt->eflags & ~EFLAGS_MASK) | (flags & EFLAGS_MASK); if (!fop) /* exception is returned in fop variable */