From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1751585AbdKMDAN (ORCPT ); Sun, 12 Nov 2017 22:00:13 -0500 Received: from mga14.intel.com ([192.55.52.115]:24623 "EHLO mga14.intel.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1751241AbdKMDAL (ORCPT ); Sun, 12 Nov 2017 22:00:11 -0500 X-ExtLoop1: 1 X-IronPort-AV: E=Sophos;i="5.44,387,1505804400"; d="scan'208";a="148909134" From: Ricardo Neri To: Ingo Molnar , Thomas Gleixner , "H. Peter Anvin" Cc: Borislav Petkov , Andy Lutomirski , Tony Luck , Paolo Bonzini , "Ravi V. Shankar" , x86@kernel.org, ricardo.neri@intel.com, linux-kernel@vger.kernel.org, Ricardo Neri Subject: [PATCH 3/4] x86/umip: Identify the str and sldt instructions Date: Sun, 12 Nov 2017 18:56:08 -0800 Message-Id: <1510541769-21064-4-git-send-email-ricardo.neri-calderon@linux.intel.com> X-Mailer: git-send-email 2.7.4 In-Reply-To: <1510541769-21064-1-git-send-email-ricardo.neri-calderon@linux.intel.com> References: <1510541769-21064-1-git-send-email-ricardo.neri-calderon@linux.intel.com> Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org The instructions str and sldt are not emulated in any case. Thus, it made sense to not implement functionality to identify them. However, a subsequent commit will introduce functionality to warn about the use of all the instructions that UMIP protect, not only those that are emulated. A first step for that is the ability to identify them. Plus, now that str and sldt are identified, we need to explicitly avoid their emulation (i.e., not rely on unsuccessful identification). Group togehter all the cases that we do not want to emulate: str, sldt and user long mode processes. Cc: Andy Lutomirski Cc: H. Peter Anvin Cc: Borislav Petkov Cc: Tony Luck Cc: Paolo Bonzini Cc: Ravi V. Shankar Cc: x86@kernel.org Signed-off-by: Ricardo Neri --- This patch also corrects the #define of SMSW. This change does not have a functional impact as it is only used as an identifier. --- arch/x86/kernel/umip.c | 25 +++++++++++++++++-------- 1 file changed, 17 insertions(+), 8 deletions(-) diff --git a/arch/x86/kernel/umip.c b/arch/x86/kernel/umip.c index 6ba82be..6a6fede 100644 --- a/arch/x86/kernel/umip.c +++ b/arch/x86/kernel/umip.c @@ -78,7 +78,9 @@ #define UMIP_INST_SGDT 0 /* 0F 01 /0 */ #define UMIP_INST_SIDT 1 /* 0F 01 /1 */ -#define UMIP_INST_SMSW 3 /* 0F 01 /4 */ +#define UMIP_INST_SMSW 2 /* 0F 01 /4 */ +#define UMIP_INST_SLDT 3 /* 0F 00 /0 */ +#define UMIP_INST_STR 4 /* 0F 00 /1 */ /** * identify_insn() - Identify a UMIP-protected instruction @@ -118,10 +120,16 @@ static int identify_insn(struct insn *insn) default: return -EINVAL; } + } else if (insn->opcode.bytes[1] == 0x0) { + if (X86_MODRM_REG(insn->modrm.value) == 0) + return UMIP_INST_SLDT; + else if (X86_MODRM_REG(insn->modrm.value) == 1) + return UMIP_INST_STR; + else + return -EINVAL; + } else { + return -EINVAL; } - - /* SLDT AND STR are not emulated */ - return -EINVAL; } /** @@ -267,10 +275,6 @@ bool fixup_umip_exception(struct pt_regs *regs) if (!regs) return false; - /* Do not emulate 64-bit processes. */ - if (user_64bit_mode(regs)) - return false; - /* * If not in user-space long mode, a custom code segment could be in * use. This is true in protected mode (if the process defined a local @@ -322,6 +326,11 @@ bool fixup_umip_exception(struct pt_regs *regs) if (umip_inst < 0) return false; + /* Do not emulate sldt, str or user long mode processes. */ + if (umip_inst == UMIP_INST_STR || umip_inst == UMIP_INST_SLDT || + user_64bit_mode(regs)) + return false; + if (emulate_umip_insn(&insn, umip_inst, dummy_data, &dummy_data_size)) return false; -- 2.7.4