linux-kernel.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
From: Rob Gardner <rob.gardner@oracle.com>
To: Khalid Aziz <khalid.aziz@oracle.com>, David Miller <davem@davemloft.net>
Cc: corbet@lwn.net, akpm@linux-foundation.org,
	dingel@linux.vnet.ibm.com, zhenzhang.zhang@huawei.com,
	bob.picco@oracle.com, kirill.shutemov@linux.intel.com,
	aneesh.kumar@linux.vnet.ibm.com, aarcange@redhat.com,
	arnd@arndb.de, sparclinux@vger.kernel.org, mhocko@suse.cz,
	chris.hyser@oracle.com, richard@nod.at, vbabka@suse.cz,
	koct9i@gmail.com, oleg@redhat.com, gthelen@google.com,
	jack@suse.cz, xiexiuqi@huawei.com, Vineet.Gupta1@synopsys.com,
	luto@kernel.org, ebiederm@xmission.com, bsegall@google.com,
	geert@linux-m68k.org, dave@stgolabs.net, adobriyan@gmail.com,
	linux-doc@vger.kernel.org, linux-kernel@vger.kernel.org,
	linux-mm@kvack.org, linux-arch@vger.kernel.org,
	linux-api@vger.kernel.org
Subject: Re: [PATCH v2] sparc64: Add support for Application Data Integrity (ADI)
Date: Mon, 7 Mar 2016 07:30:28 -0800	[thread overview]
Message-ID: <56DD9E94.70201@oracle.com> (raw)
In-Reply-To: <56DD9949.1000106@oracle.com>

On 03/07/2016 07:07 AM, Khalid Aziz wrote:
> On 03/05/2016 09:07 PM, David Miller wrote:
>> From: Khalid Aziz <khalid.aziz@oracle.com>
>> Date: Wed,  2 Mar 2016 13:39:37 -0700
>>
>>>     In this
>>>     first implementation I am enabling ADI for hugepages only
>>>     since these pages are locked in memory and hence avoid the
>>>     issue of saving and restoring tags.
>>
>> This makes the feature almost entire useless.
>>
>> Non-hugepages must be in the initial implementation.
>
> Hi David,
>
> Thanks for the feedback. I will get this working for non-hugepages as 
> well. ADI state of each VMA region is already stored in the VMA itself 
> in my first implementation, so I do not lose it when the page is 
> swapped out. The trouble is ADI version tags for each VMA region have 
> to be stored on the swapped out pages since the ADI version tags are 
> flushed when TLB entry for a page is flushed. 


Khalid,

Are you sure about that last statement? My understanding is that the 
tags are stored in physical memory, and remain there until explicitly 
changed or removed, and so flushing a TLB entry has no effect on the ADI 
tags. If it worked the way you think, then somebody would have to 
potentially reload a long list of ADI tags on every TLB miss.

Rob



> When that page is brought back in, its version tags have to be set up 
> again. Version tags are set on cacheline boundary and hence there can 
> be multiple version tags for a single page. Version tags have to be 
> stored in the swap space somehow along with the page. I can start out 
> with allowing ADI to be enabled only on pages locked in memory.
>
>>
>>> +    PR_ENABLE_SPARC_ADI - Enable ADI checking in all pages in the 
>>> address
>>> +        range specified. The pages in the range must be already
>>> +        locked. This operation enables the TTE.mcd bit for the
>>> +        pages specified. arg2 is the starting address for address
>>> +        range and must be page aligned. arg3 is the length of
>>> +        memory address range and must be a multiple of page size.
>>
>> I strongly dislike this interface, and it makes the prtctl cases look
>> extremely ugly and hide to the casual reader what the code is actually
>> doing.
>>
>> This is an mprotect() operation, so add a new flag bit and implement
>> this via mprotect please.
>
> That is an interesting idea. Adding a PROT_ADI protection to 
> mprotect() sounds cleaner. There are three steps to enabling ADI - (1) 
> set PSTATE.mcde bit which is not tied to any VMA, (2) set TTE.mcd for 
> each VMA, and (3) set the version tag on cacheline using MCD ASI. I 
> can combine steps 1 and 2 in one mprotect() call. That will leave 
> PR_GET_SPARC_ADICAPS and PR_GET_SPARC_ADI_STATUS prctl commands still 
> to be implemented. PR_SET_SPARC_ADI is also used to check if the 
> process has PSTATE.mcde bit set. I could use PR_GET_SPARC_ADI_STATUS 
> to do that where return values of 0 and 1 mean the same as before and 
> possibly add return value of 2 to mean PSTATE.mcde is not set?
>
>>
>> Then since you are guarenteed to have a consistent ADI setting for
>> every single VMA region, you never "lose" the ADI state when you swap
>> out.  It's implicit in the VMA itself, because you'll store in the VMA
>> that this is an ADI region.
>>
>> I also want this enabled unconditionally, without any Kconfig knobs.
>>
>
> I can remove CONFIG_SPARC_ADI. It does mean this code will be built 
> into 32-bit kernels as well but it will be inactive code.
>
> Thanks,
> Khalid
>
>
>

  reply	other threads:[~2016-03-07 15:35 UTC|newest]

Thread overview: 62+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2016-03-02 20:39 [PATCH v2] sparc64: Add support for Application Data Integrity (ADI) Khalid Aziz
2016-03-02 23:08 ` Julian Calaby
2016-03-03  0:25   ` Khalid Aziz
2016-03-03  0:48     ` Julian Calaby
2016-03-03 17:28       ` Khalid Aziz
2016-03-06  4:07 ` David Miller
2016-03-07 15:07   ` Khalid Aziz
2016-03-07 15:30     ` Rob Gardner [this message]
2016-03-07 15:43       ` Andy Lutomirski
2016-03-07 16:06         ` Khalid Aziz
2016-03-07 17:46           ` Dave Hansen
2016-03-07 17:53             ` Andy Lutomirski
2016-03-07 18:12               ` Dave Hansen
2016-03-07 18:39                 ` Khalid Aziz
2016-03-07 18:53                   ` Andy Lutomirski
2016-03-07 19:22                     ` David Miller
2016-03-07 19:46                       ` Khalid Aziz
2016-03-07 22:40                         ` Dave Hansen
2016-03-08  1:31                   ` Rob Gardner
2016-03-07 21:06             ` Khalid Aziz
2016-03-08 19:57               ` David Miller
2016-03-08 20:16                 ` Khalid Aziz
2016-03-08 20:27                   ` David Miller
2016-03-08 20:59                     ` Khalid Aziz
2016-03-07 15:45       ` Khalid Aziz
2016-03-07 16:45     ` David Miller
2016-03-07 17:51       ` Khalid Aziz
2016-03-07 16:56     ` David Miller
2016-03-07 18:04       ` Khalid Aziz
2016-03-07 18:08         ` Andy Lutomirski
2016-03-07 18:22           ` Khalid Aziz
2016-03-07 18:49             ` Andy Lutomirski
2016-03-07 19:19               ` David Miller
2016-03-07 19:44               ` Khalid Aziz
2016-03-07 19:54                 ` Andy Lutomirski
2016-03-07 20:41                   ` Khalid Aziz
2016-03-07 20:58                     ` David Miller
2016-03-07 21:02                       ` Andy Lutomirski
2016-03-07 21:09                       ` Khalid Aziz
2016-03-07 23:34                       ` James Morris
2016-03-07 23:48                   ` James Morris
2016-03-08  9:33                     ` James Morris
2016-03-07 18:09         ` Rob Gardner
2016-03-07 18:24           ` Khalid Aziz
2016-03-07 19:16             ` David Miller
2016-03-07 21:33               ` Khalid Aziz
2016-03-07 21:38                 ` David Miller
2016-03-07 23:13                   ` Rob Gardner
2016-03-08  4:13                     ` David Miller
2016-03-07 23:12                 ` Rob Gardner
2016-03-07 23:27                   ` Khalid Aziz
2016-03-08  0:21               ` Khalid Aziz
2016-03-08  4:24                 ` David Miller
2016-03-07 23:32             ` Rob Gardner
2016-03-07 19:09         ` David Miller
2016-03-07 21:27           ` Khalid Aziz
2016-03-07 21:34             ` David Miller
2016-03-07 22:30               ` Khalid Aziz
2016-03-07 17:32 ` Dave Hansen
2016-03-07 17:35 ` Dave Hansen
2016-03-07 18:15   ` Khalid Aziz
2016-03-07 19:06   ` David Miller

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=56DD9E94.70201@oracle.com \
    --to=rob.gardner@oracle.com \
    --cc=Vineet.Gupta1@synopsys.com \
    --cc=aarcange@redhat.com \
    --cc=adobriyan@gmail.com \
    --cc=akpm@linux-foundation.org \
    --cc=aneesh.kumar@linux.vnet.ibm.com \
    --cc=arnd@arndb.de \
    --cc=bob.picco@oracle.com \
    --cc=bsegall@google.com \
    --cc=chris.hyser@oracle.com \
    --cc=corbet@lwn.net \
    --cc=dave@stgolabs.net \
    --cc=davem@davemloft.net \
    --cc=dingel@linux.vnet.ibm.com \
    --cc=ebiederm@xmission.com \
    --cc=geert@linux-m68k.org \
    --cc=gthelen@google.com \
    --cc=jack@suse.cz \
    --cc=khalid.aziz@oracle.com \
    --cc=kirill.shutemov@linux.intel.com \
    --cc=koct9i@gmail.com \
    --cc=linux-api@vger.kernel.org \
    --cc=linux-arch@vger.kernel.org \
    --cc=linux-doc@vger.kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-mm@kvack.org \
    --cc=luto@kernel.org \
    --cc=mhocko@suse.cz \
    --cc=oleg@redhat.com \
    --cc=richard@nod.at \
    --cc=sparclinux@vger.kernel.org \
    --cc=vbabka@suse.cz \
    --cc=xiexiuqi@huawei.com \
    --cc=zhenzhang.zhang@huawei.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).