From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.129.124]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id A94192586D4 for ; Tue, 11 Feb 2025 16:09:57 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=170.10.129.124 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1739290199; cv=none; b=LzTO+i+pvK+jbM4Y+JFzL2lIks9xlIESNfQm9insIa3ZQm8nk7i1GKBFACNiFdo+iU65PYFyaVRG9rEbCD/wG8fxpy1u9Zzbg0RKeBChDkkAtNvbqbixdZDwvgOixf+DxtqfK6xBLIr40hx7wu7lwd0dutpjjZroC3bfYQUW7p4= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1739290199; c=relaxed/simple; bh=djk7Y7ajWHGUwmNBsUGYqINcVGjOOrYHNCM13HFGEf8=; h=From:To:Cc:Subject:In-Reply-To:References:Date:Message-ID: MIME-Version:Content-Type; b=SnwJv85ZzwEeUromn3Wh0nn7U4LY+nq7FdQi29Jh9l72V/DhNMDOGTjWDMOd4f0bAbp8fga7E8tbz3Jox63ia2PRoCr6HdA6lSoJm7YcDRgn1ix1fNXnBWn4wnKVrMzJtUNt93JuEExzXCC4w18OM4QTWZ7ypIHMCBm6ylYqdZM= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=redhat.com; spf=pass smtp.mailfrom=redhat.com; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b=NMHkjWmU; arc=none smtp.client-ip=170.10.129.124 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=redhat.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=redhat.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b="NMHkjWmU" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1739290196; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=vlqDgCP2DAkslcpgDFYXdlhhng4EN6BqWt/KN1sHhDc=; b=NMHkjWmUgZquI7XNkmgx5ylybMsR4LnFUGx1BP6Dea78xg57/b0E6vBVoCuNtROJz9I3wd hiKAXbcj5qSHH+9f8dsKviKAt5vN70N54A74V3b5fbufmI4cit0LgrvUspyW0DVFQAN5Ej sVJSBotux5i8ftUv3bx0YqKdKWBfKuc= Received: from mail-wr1-f69.google.com (mail-wr1-f69.google.com [209.85.221.69]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-175-l-xoa507NkyqmexULcoSfw-1; Tue, 11 Feb 2025 11:09:55 -0500 X-MC-Unique: l-xoa507NkyqmexULcoSfw-1 X-Mimecast-MFC-AGG-ID: l-xoa507NkyqmexULcoSfw Received: by mail-wr1-f69.google.com with SMTP id ffacd0b85a97d-38dd533dad0so2017824f8f.0 for ; Tue, 11 Feb 2025 08:09:54 -0800 (PST) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1739290194; x=1739894994; h=content-transfer-encoding:mime-version:message-id:date:references :in-reply-to:subject:cc:to:from:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to; bh=cqBw0fvuK6HvmV212DNXANVYi4ije8UDstIz77BqBKI=; b=HN2EyIPL9iyCy2eRhhsgLiZbhi41k43SqPN7p906aUkwxHP+h5vpbYRtsUXpj9Ew43 4bGkMysLgz46QiTWAL0u2TN/FZ2mw2suIfsjWPw8RINBWTRarb8wo4XUj8bMSwruwVqk QXu6VOI4uISJeKqK2N+XLB3Q3Ooa+CiqUksi9D9rEiUuEwC+P5lYQ1RfHnKw4nQ/XKwW VDsa2WTPttXM/F5VM1pwHm2wxm7oc7ZsqimHjMe7R8bB6g85h4eQwqzhubORQugbpnVv BOIJ6aGNvCXq+CyGq+KDm3Ew3iUx/OtX5nmqoll89qNgWwRjA86r/A8MV9FK5axRQMMC YVSg== X-Forwarded-Encrypted: i=1; AJvYcCUTE3buqvcdLKKRF2/H8Rq2DoHlkQppP6PMlDlAuK4LkNaEvSrmp0D6guovy35E4nkermv89tDz/p1o/5j1Ng==@lists.linux.dev X-Gm-Message-State: AOJu0Yz+GLCVG17Tgim1DIh5xgZdaUiuGKAX9HvrHlDYtz85yVGtgRsY NEJAwMV2C3ATAXwFlc6LMygvDE8YSKAgfg6LpaNx+LldnlACFdhwMe6Xab7rjrBH96SOL8iShxj 43+nyGmDV3cg8sMtRVrpMikGr50nWQVP0kZfWPzPNLfmU6/jtzAMZhMMfV9Mqwfqd X-Gm-Gg: ASbGncufIDQxj2hqOe0p7MSeyf6V3FArWKPJBzFNCh0Q3xChgBt3i+eZtyccglf878Z zdfL0tbOyLunLPQhZctedUjAtkmrbu9JVzWefATB303XOJwAQne+QqQsjHRtpZ+FySiU7jy+VGc Q+Crx/stg+LpW7JohCWIUY1GrLchHFHfj2sGAoZRghn8rk2nrqdiMduKWxZchHdU6RbPIiZcdSE d7hzB114ITd5cFRW5QpMrQOQPeL5YzMwea8P17N4GBtOCpUGL+FibOnZwWvWK2pPm94eqW0QS7Z AgOiUyRZLw2HOJZXs54JUYP5vAjJHsOpD1wE4ES1C68heI6WmIDaA1asQpho7qVFpA== X-Received: by 2002:adf:b60f:0:b0:38d:b113:eb8 with SMTP id ffacd0b85a97d-38de918b920mr304812f8f.20.1739290193749; Tue, 11 Feb 2025 08:09:53 -0800 (PST) X-Google-Smtp-Source: AGHT+IHK1ASMUo9/0VqOa8FhznHehFcHh+h1fB2eK6UH8SCGRKzMX4fpRgybDSM9A1NmLLMyPAzxtg== X-Received: by 2002:adf:b60f:0:b0:38d:b113:eb8 with SMTP id ffacd0b85a97d-38de918b920mr304770f8f.20.1739290193306; Tue, 11 Feb 2025 08:09:53 -0800 (PST) Received: from vschneid-thinkpadt14sgen2i.remote.csb (213-44-141-166.abo.bbox.fr. [213.44.141.166]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-38dbde1dfaesm15387623f8f.90.2025.02.11.08.09.49 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 11 Feb 2025 08:09:52 -0800 (PST) From: Valentin Schneider To: Mark Rutland Cc: Jann Horn , linux-kernel@vger.kernel.org, x86@kernel.org, virtualization@lists.linux.dev, linux-arm-kernel@lists.infradead.org, loongarch@lists.linux.dev, linux-riscv@lists.infradead.org, linux-perf-users@vger.kernel.org, xen-devel@lists.xenproject.org, kvm@vger.kernel.org, linux-arch@vger.kernel.org, rcu@vger.kernel.org, linux-hardening@vger.kernel.org, linux-mm@kvack.org, linux-kselftest@vger.kernel.org, bpf@vger.kernel.org, bcm-kernel-feedback-list@broadcom.com, Juergen Gross , Ajay Kaher , Alexey Makhalov , Russell King , Catalin Marinas , Will Deacon , Huacai Chen , WANG Xuerui , Paul Walmsley , Palmer Dabbelt , Albert Ou , Thomas Gleixner , Ingo Molnar , Borislav Petkov , Dave Hansen , "H. Peter Anvin" , Peter Zijlstra , Arnaldo Carvalho de Melo , Namhyung Kim , Alexander Shishkin , Jiri Olsa , Ian Rogers , Adrian Hunter , "Liang, Kan" , Boris Ostrovsky , Josh Poimboeuf , Pawan Gupta , Sean Christopherson , Paolo Bonzini , Andy Lutomirski , Arnd Bergmann , Frederic Weisbecker , "Paul E. McKenney" , Jason Baron , Steven Rostedt , Ard Biesheuvel , Neeraj Upadhyay , Joel Fernandes , Josh Triplett , Boqun Feng , Uladzislau Rezki , Mathieu Desnoyers , Lai Jiangshan , Zqiang , Juri Lelli , Clark Williams , Yair Podemsky , Tomas Glozar , Vincent Guittot , Dietmar Eggemann , Ben Segall , Mel Gorman , Kees Cook , Andrew Morton , Christoph Hellwig , Shuah Khan , Sami Tolvanen , Miguel Ojeda , Alice Ryhl , "Mike Rapoport (Microsoft)" , Samuel Holland , Rong Xu , Nicolas Saenz Julienne , Geert Uytterhoeven , Yosry Ahmed , "Kirill A. Shutemov" , "Masami Hiramatsu (Google)" , Jinghao Jia , Luis Chamberlain , Randy Dunlap , Tiezhu Yang Subject: Re: [PATCH v4 29/30] x86/mm, mm/vmalloc: Defer flush_tlb_kernel_range() targeting NOHZ_FULL CPUs In-Reply-To: References: <20250114175143.81438-1-vschneid@redhat.com> <20250114175143.81438-30-vschneid@redhat.com> Date: Tue, 11 Feb 2025 17:09:49 +0100 Message-ID: Precedence: bulk X-Mailing-List: virtualization@lists.linux.dev List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Mimecast-Spam-Score: 0 X-Mimecast-MFC-PROC-ID: nqSmYx0ZSrURFasLQ7bpFxKTpoEiGF7DnwGqQuKRisw_1739290194 X-Mimecast-Originator: redhat.com Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable On 11/02/25 14:03, Mark Rutland wrote: > On Tue, Feb 11, 2025 at 02:33:51PM +0100, Valentin Schneider wrote: >> On 10/02/25 23:08, Jann Horn wrote: >> > 2. It's wrong to assume that TLB entries are only populated for >> > addresses you access - thanks to speculative execution, you have to >> > assume that the CPU might be populating random TLB entries all over >> > the place. >> >> Gotta love speculation. Now it is supposed to be limited to genuinely >> accessible data & code, right? Say theoretically we have a full TLBi as >> literally the last thing before doing the return-to-userspace, speculati= on >> should be limited to executing maybe bits of the return-from-userspace >> code? > > I think it's easier to ignore speculation entirely, and just assume that > the MMU can arbitrarily fill TLB entries from any page table entries > which are valid/accessible in the active page tables. Hardware > prefetchers can do that regardless of the specific path of speculative > execution. > > Thus TLB fills are not limited to VAs which would be used on that > return-to-userspace path. > >> Furthermore, I would hope that once a CPU is executing in userspace, it'= s >> not going to populate the TLB with kernel address translations - AIUI th= e >> whole vulnerability mitigation debacle was about preventing this sort of >> thing. > > The CPU can definitely do that; the vulnerability mitigations are all > about what userspace can observe rather than what the CPU can do in the > background. Additionally, there are features like SPE and TRBE that use > kernel addresses while the CPU is executing userspace instructions. > > The latest ARM Architecture Reference Manual (ARM DDI 0487 L.a) is fairly= clear > about that in section D8.16 "Translation Lookaside Buff", where it says > (among other things): > > When address translation is enabled, if a translation table entry > meets all of the following requirements, then that translation table > entry is permitted to be cached in a TLB or intermediate TLB caching > structure at any time: > =E2=80=A2 The translation table entry itself does not generate a Transl= ation > fault, an Address size fault, or an Access flag fault. > =E2=80=A2 The translation table entry is not from a translation regime > configured by an Exception level that is lower than the current > Exception level. > > Here "permitted to be cached in a TLB" also implies that the HW is > allowed to fetch the translation tabl entry (which is what ARM call page > table entries). > That's actually fairly clear all things considered, thanks for the education and for fishing out the relevant DDI section! > The PDF can be found at: > > https://developer.arm.com/documentation/ddi0487/la/?lang=3Den > > Mark.