From: Dave Hansen <dave.hansen@intel.com>
To: Andy Lutomirski <luto@amacapital.net>
Cc: Len Brown <lenb@kernel.org>,
"Liu, Jing2" <jing2.liu@linux.intel.com>,
Andy Lutomirski <luto@kernel.org>,
Thomas Gleixner <tglx@linutronix.de>,
Borislav Petkov <bp@suse.de>, Ingo Molnar <mingo@kernel.org>,
X86 ML <x86@kernel.org>, Len Brown <len.brown@intel.com>,
"Liu, Jing2" <jing2.liu@intel.com>,
"Ravi V. Shankar" <ravi.v.shankar@intel.com>,
LKML <linux-kernel@vger.kernel.org>,
"Bae, Chang Seok" <chang.seok.bae@intel.com>
Subject: Re: [PATCH v4 14/22] x86/fpu/xstate: Expand the xstate buffer on the first use of dynamic user state
Date: Wed, 24 Mar 2021 14:58:07 -0700 [thread overview]
Message-ID: <90ea8d01-7fa5-100e-8590-d1ed80eb0d6a@intel.com> (raw)
In-Reply-To: <03F61C1A-0CA1-43BB-B2B5-C9D654943051@amacapital.net>
On 3/24/21 2:42 PM, Andy Lutomirski wrote:
>>>> 3. user space always uses fully uncompacted XSAVE buffers.
>>>>
>>> There is no reason we have to do this for new states. Arguably we
>>> shouldn’t for AMX to avoid yet another altstack explosion.
>> The thing that's worried me is that the list of OS-enabled states is
>> visible to apps via XGETBV. It doesn't seem too much of a stretch to
>> think that apps will see AMX enabled with XGETBV and them assume that
>> it's on the signal stack.
>>
>> Please tell me I'm being too paranoid. If we can break this
>> assumption, it would get rid of a lot of future pain.
> There are no AMX apps. I sure hope that there are no apps that
> enumerate xfeatures with CPUID and try to decode the mess in the
> signal stack.
I don't think they quite need to decode it in order to be screwed over a
bit. For instance, I don't think it's too crazy if someone did:
xcr0 = xgetbv(0);
xrstor(xcr0, &sig_stack[something]);
// change some registers
xsave(xcr0, &sig_stack[something]);
The XRSTOR would work fine, but the XSAVE would overflow the stack
because it would save the AMX state. It also *looks* awfully benign.
This is true even if the silly signal handler didn't know about AMX at
*ALL*.
A good app would have checked that the xfeatures field in the header
matched xcr0.
next prev parent reply other threads:[~2021-03-24 21:59 UTC|newest]
Thread overview: 78+ messages / expand[flat|nested] mbox.gz Atom feed top
2021-02-21 18:56 [PATCH v4 00/22] x86: Support Intel Advanced Matrix Extensions Chang S. Bae
2021-02-21 18:56 ` [PATCH v4 01/22] x86/fpu/xstate: Modify the initialization helper to handle both static and dynamic buffers Chang S. Bae
2021-03-10 13:40 ` Borislav Petkov
2021-02-21 18:56 ` [PATCH v4 02/22] x86/fpu/xstate: Modify state copy helpers " Chang S. Bae
2021-02-21 18:56 ` [PATCH v4 03/22] x86/fpu/xstate: Modify address finders " Chang S. Bae
2021-02-21 18:56 ` [PATCH v4 04/22] x86/fpu/xstate: Modify the context restore helper " Chang S. Bae
2021-02-21 18:56 ` [PATCH v4 05/22] x86/fpu/xstate: Add a new variable to indicate dynamic user states Chang S. Bae
2021-02-21 18:56 ` [PATCH v4 06/22] x86/fpu/xstate: Add new variables to indicate dynamic xstate buffer size Chang S. Bae
2021-02-21 18:56 ` [PATCH v4 07/22] x86/fpu/xstate: Calculate and remember dynamic xstate buffer sizes Chang S. Bae
2021-02-21 18:56 ` [PATCH v4 08/22] x86/fpu/xstate: Convert the struct fpu 'state' field to a pointer Chang S. Bae
2021-02-21 18:56 ` [PATCH v4 09/22] x86/fpu/xstate: Introduce helpers to manage the xstate buffer dynamically Chang S. Bae
2021-02-21 18:56 ` [PATCH v4 10/22] x86/fpu/xstate: Define the scope of the initial xstate data Chang S. Bae
2021-02-21 18:56 ` [PATCH v4 11/22] x86/fpu/xstate: Update the xstate save function to support dynamic states Chang S. Bae
2021-02-21 18:56 ` [PATCH v4 12/22] x86/fpu/xstate: Update the xstate buffer address finder " Chang S. Bae
2021-02-21 18:56 ` [PATCH v4 13/22] x86/fpu/xstate: Update the xstate context copy function " Chang S. Bae
2021-02-21 18:56 ` [PATCH v4 14/22] x86/fpu/xstate: Expand the xstate buffer on the first use of dynamic user state Chang S. Bae
2021-03-20 22:13 ` Thomas Gleixner
2021-03-20 22:21 ` Andy Lutomirski
2021-03-23 21:01 ` Len Brown
2021-03-24 3:14 ` Liu, Jing2
2021-03-24 21:09 ` Len Brown
2021-03-24 21:26 ` Andy Lutomirski
2021-03-24 21:30 ` Dave Hansen
2021-03-24 21:42 ` Andy Lutomirski
2021-03-24 21:58 ` Dave Hansen [this message]
2021-03-24 22:12 ` Andy Lutomirski
2021-03-25 5:12 ` Liu, Jing2
2021-03-25 6:59 ` Bae, Chang Seok
2021-03-25 7:26 ` Liu, Jing2
2021-03-23 21:52 ` Bae, Chang Seok
2021-03-24 14:24 ` Dave Hansen
2021-03-29 13:14 ` Len Brown
2021-03-29 13:33 ` Thomas Gleixner
2021-03-29 15:43 ` Len Brown
2021-03-29 16:06 ` Len Brown
2021-03-29 17:43 ` Andy Lutomirski
2021-03-29 18:57 ` Len Brown
2021-03-29 18:49 ` Thomas Gleixner
2021-03-29 22:16 ` Len Brown
2021-03-30 8:28 ` Thomas Gleixner
2021-03-30 16:38 ` Len Brown
2021-03-26 16:34 ` Jann Horn
2021-03-29 18:14 ` Bae, Chang Seok
2021-02-21 18:56 ` [PATCH v4 15/22] x86/fpu/xstate: Support ptracer-induced xstate buffer expansion Chang S. Bae
2021-02-21 18:56 ` [PATCH v4 16/22] x86/fpu/xstate: Extend the table to map state components with features Chang S. Bae
2021-03-20 21:25 ` Thomas Gleixner
2021-03-23 21:52 ` Bae, Chang Seok
2021-02-21 18:56 ` [PATCH v4 17/22] x86/cpufeatures/amx: Enumerate Advanced Matrix Extension (AMX) feature bits Chang S. Bae
2021-02-21 18:56 ` [PATCH v4 18/22] x86/fpu/amx: Define AMX state components and have it used for boot-time checks Chang S. Bae
2021-03-20 21:31 ` Thomas Gleixner
2021-03-23 21:52 ` Bae, Chang Seok
2021-02-21 18:56 ` [PATCH v4 19/22] x86/fpu/amx: Enable the AMX feature in 64-bit mode Chang S. Bae
2021-03-20 21:26 ` Thomas Gleixner
2021-03-23 21:51 ` Bae, Chang Seok
2021-02-21 18:56 ` [PATCH v4 20/22] selftest/x86/amx: Include test cases for the AMX state management Chang S. Bae
2021-02-21 18:56 ` [PATCH v4 21/22] x86/fpu/xstate: Support dynamic user state in the signal handling path Chang S. Bae
2021-02-21 18:56 ` [PATCH v4 22/22] x86/fpu/xstate: Introduce boot-parameters to control state component support Chang S. Bae
2021-02-21 19:30 ` Randy Dunlap
2021-02-21 20:10 ` Bae, Chang Seok
2021-02-21 20:37 ` Randy Dunlap
2021-03-20 20:56 ` Thomas Gleixner
2021-03-25 22:59 ` Len Brown
2021-03-25 23:10 ` Dave Hansen
2021-03-26 15:27 ` Len Brown
2021-03-26 19:22 ` Thomas Gleixner
2021-03-26 1:41 ` Andy Lutomirski
2021-03-26 15:33 ` Len Brown
2021-03-26 15:48 ` Andy Lutomirski
2021-03-26 17:53 ` Len Brown
2021-03-26 18:12 ` Andy Lutomirski
2021-03-27 4:53 ` Len Brown
2021-03-27 22:20 ` Thomas Gleixner
2021-03-29 13:31 ` Len Brown
2021-03-29 14:10 ` Thomas Gleixner
2021-03-26 18:17 ` Borislav Petkov
2021-03-27 4:41 ` Len Brown
2021-03-26 1:50 ` Thomas Gleixner
2021-03-26 15:36 ` Len Brown
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=90ea8d01-7fa5-100e-8590-d1ed80eb0d6a@intel.com \
--to=dave.hansen@intel.com \
--cc=bp@suse.de \
--cc=chang.seok.bae@intel.com \
--cc=jing2.liu@intel.com \
--cc=jing2.liu@linux.intel.com \
--cc=len.brown@intel.com \
--cc=lenb@kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=luto@amacapital.net \
--cc=luto@kernel.org \
--cc=mingo@kernel.org \
--cc=ravi.v.shankar@intel.com \
--cc=tglx@linutronix.de \
--cc=x86@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox