From: Andy Lutomirski <luto@amacapital.net>
To: Thomas Gleixner <tglx@linutronix.de>, X86 ML <x86@kernel.org>,
Ingo Molnar <mingo@redhat.com>, "H. Peter Anvin" <hpa@zytor.com>
Cc: Sebastian Lackner <sebastian@fds-team.de>,
Anish Bhatt <anish@chelsio.com>,
"linux-kernel@vger.kernel.org" <linux-kernel@vger.kernel.org>,
Chuck Ebbert <cebbert.lkml@gmail.com>,
Andy Lutomirski <luto@amacapital.net>
Subject: [PATCH 0/2] x86_64,entry: Clear NT on entry and speed up switch_to
Date: Tue, 30 Sep 2014 12:40:34 -0700 [thread overview]
Message-ID: <cover.1412105369.git.luto@amacapital.net> (raw)
Anish Bhatt noticed that user programs can set RFLAGS.NT before
syscall or sysenter, and the kernel entry code doesn't filter out
NT. This causes kernel C code and, depending on thread flags, the
exit slow path to run with NT set.
The former is a little bit scary (imagine calling into EFI with NT
set), and the latter will fail with #GP and send a spurious SIGSEGV.
One answer would be "don't do that". But the kernel can do better
here.
These patches, which I'm not completely thrilled by, filter NT on
all kernel entries. For syscall (both bitnesses), this is free.
For sysenter, it costs 15 cycles or so. As a consolation prize, we
can speed up context switches by avoiding saving and restoring flags.
If we don't like the added sysenter overhead, there are few other
options:
- Try to optimize it by folding it with other flag manipulations
(my attempt to do that didn't end up being any faster).
- Only do the syscall part. That's free, but it serves little
purpose other than being polite to buggy userspace code.
- Don't filter NT on sysenter. Instead, filter it on EFI entry
and modify the IRET code to retry without NT set if NT was set.
- Don't filter NT on sysenter. Instead, only filter it when
sysenter jumps to the slow path. (This is trivial, but it does
nothing to reduce the chance that evil user code can cause
trouble by, say, reading from sysfs with NT set using sysenter.)
See: https://bugs.winehq.org/show_bug.cgi?id=33275
Andy Lutomirski (2):
x86_64,entry: Filter RFLAGS.NT on entry from userspace
x86_64: Don't save flags on context switch
arch/x86/ia32/ia32entry.S | 10 +++++++++-
arch/x86/include/asm/switch_to.h | 10 +++++++---
arch/x86/kernel/cpu/common.c | 2 +-
3 files changed, 17 insertions(+), 5 deletions(-)
--
1.9.3
next reply other threads:[~2014-09-30 19:40 UTC|newest]
Thread overview: 16+ messages / expand[flat|nested] mbox.gz Atom feed top
2014-09-30 19:40 Andy Lutomirski [this message]
2014-09-30 19:40 ` [PATCH 1/2] x86_64,entry: Filter RFLAGS.NT on entry from userspace Andy Lutomirski
2014-09-30 21:39 ` Sebastian Lackner
2014-09-30 21:45 ` Andy Lutomirski
2014-09-30 22:23 ` Sebastian Lackner
2014-09-30 22:27 ` Thomas Gleixner
2014-09-30 22:33 ` Andy Lutomirski
2014-09-30 23:21 ` Thomas Gleixner
2014-10-01 17:50 ` H. Peter Anvin
2014-10-01 17:53 ` H. Peter Anvin
2014-09-30 22:42 ` H. Peter Anvin
2014-10-01 0:27 ` Chuck Ebbert
2014-10-01 0:38 ` Andy Lutomirski
2014-09-30 19:40 ` [PATCH 2/2] x86_64: Don't save flags on context switch Andy Lutomirski
2014-09-30 22:21 ` [PATCH 0/2] x86_64,entry: Clear NT on entry and speed up switch_to Thomas Gleixner
2014-09-30 22:30 ` Andy Lutomirski
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=cover.1412105369.git.luto@amacapital.net \
--to=luto@amacapital.net \
--cc=anish@chelsio.com \
--cc=cebbert.lkml@gmail.com \
--cc=hpa@zytor.com \
--cc=linux-kernel@vger.kernel.org \
--cc=mingo@redhat.com \
--cc=sebastian@fds-team.de \
--cc=tglx@linutronix.de \
--cc=x86@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox