From mboxrd@z Thu Jan 1 00:00:00 1970 From: Pavel Machek Subject: Re: [RFC]: mm,power: introduce MADV_WIPEONSUSPEND Date: Tue, 7 Jul 2020 10:07:26 +0200 Message-ID: <20200707080726.GA32357@amd> References: <20200703113026.GT18446@dhcp22.suse.cz> <20200707073823.GA3820@dhcp22.suse.cz> Mime-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-sha1; protocol="application/pgp-signature"; boundary="LQksG6bCIzRHxTLp" Return-path: Content-Disposition: inline In-Reply-To: <20200707073823.GA3820-2MMpYkNvuYDjFM9bn6wA6Q@public.gmane.org> Sender: linux-api-owner-u79uwXL29TY76Z2rM5mHXA@public.gmane.org To: Michal Hocko Cc: Jann Horn , "Catangiu, Adrian Costin" , "linux-mm-Bw31MaZKKs3YtjvyW6yDsg@public.gmane.org" , "linux-pm-u79uwXL29TY76Z2rM5mHXA@public.gmane.org" , "virtualization-cunTk1MwBs9QetFLy7KEm3xJsTq8ys+cHZ5vskTnxNA@public.gmane.org" , "linux-api-u79uwXL29TY76Z2rM5mHXA@public.gmane.org" , "akpm-de/tnXTf+JLsfHDXvbKv3WD2FQJk+8+b@public.gmane.org" , "rjw-LthD3rsA81gm4RdzfppkhA@public.gmane.org" , "len.brown-ral2JQCrhuEAvxtiuMwx3w@public.gmane.org" , "fweimer-H+wXaHxf7aLQT0dZR+AlfA@public.gmane.org" , "keescook-F7+t8E8rja9g9hUCZPvPmw@public.gmane.org" , "luto-kltTT9wpgjJwATOyAt5JVQ@public.gmane.org" , "wad-F7+t8E8rja9g9hUCZPvPmw@public.gmane.org" , "mingo-DgEjT+Ai2ygdnm+yROfE0A@public.gmane.org" , "bonzini-mXXj517/zsQ@public.gmane.org" , "Graf (AWS), Alexander" List-Id: virtualization@lists.linuxfoundation.org --LQksG6bCIzRHxTLp Content-Type: text/plain; charset=us-ascii Content-Disposition: inline Content-Transfer-Encoding: quoted-printable Hi! > > > > This patch adds logic to the kernel power code to zero out contents= of > > > > all MADV_WIPEONSUSPEND VMAs present in the system during its transi= tion > > > > to any suspend state equal or greater/deeper than Suspend-to-memory, > > > > known as S3. > > > > > > How does the application learn that its memory got wiped? S2disk is an > > > async operation and it can happen at any time during the task executi= on. > > > So how does the application work to prevent from corrupted state - e.= g. > > > when suspended between two memory loads? > >=20 > > You can do it seqlock-style, kind of - you reserve the first byte of > > the page or so as a "is this page initialized" marker, and after every > > read from the page, you do a compiler barrier and check whether that > > byte has been cleared. >=20 > This is certainly possible yet wery awkwar interface to use IMHO. > MADV_EXTERNALY_VOLATILE would express the actual semantic much better. > I might not still understand the expected usecase but if the target > application has to be changed anyway then why not simply use a > transparent and proper signaling mechanism like poll on a fd. That The goal is to have cryprographically-safe get_random_number() with 0 syscalls. You'd need to do: if (!poll(did_i_migrate)) { use_prng_seed(); if (poll(did_i_migrate)) { /* oops_they_migrated_me_in_middle_of_computation, lets_redo_it() */ goto retry: } } Which means two syscalls.. Best regards, Pavel --=20 (english) http://www.livejournal.com/~pavelmachek (cesky, pictures) http://atrey.karlin.mff.cuni.cz/~pavel/picture/horses/blo= g.html --LQksG6bCIzRHxTLp Content-Type: application/pgp-signature; name="signature.asc" Content-Description: Digital signature -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iEYEARECAAYFAl8ELT4ACgkQMOfwapXb+vLyMACgqbe6zmXiEEz8DaabrD2NC2vV 5xgAn3dKno+G4UTAHEY2WCnK1mXkOj/5 =rQsH -----END PGP SIGNATURE----- --LQksG6bCIzRHxTLp--