From: Quentin Casasnovas <quentin.casasnovas@oracle.com>
To: Borislav Petkov <bp@suse.de>
Cc: Quentin Casasnovas <quentin.casasnovas@oracle.com>,
Oleg Nesterov <oleg@redhat.com>,
Dave Hansen <dave.hansen@intel.com>,
Ingo Molnar <mingo@kernel.org>,
Andy Lutomirski <luto@amacapital.net>,
Linus Torvalds <torvalds@linux-foundation.org>,
Pekka Riikonen <priikone@iki.fi>, Rik van Riel <riel@redhat.com>,
Suresh Siddha <sbsiddha@gmail.com>,
LKML <linux-kernel@vger.kernel.org>,
"Yu, Fenghua" <fenghua.yu@intel.com>,
"H. Peter Anvin" <hpa@zytor.com>
Subject: Re: [PATCH RFC 0/2] x86/fpu: avoid "xstate_fault" in xsave_user/xrestore_user
Date: Wed, 18 Mar 2015 10:06:32 +0100 [thread overview]
Message-ID: <20150318090632.GF19131@chrystal.uk.oracle.com> (raw)
In-Reply-To: <20150317120739.GH18917@pd.tnic>
On Tue, Mar 17, 2015 at 01:07:39PM +0100, Borislav Petkov wrote:
> On Tue, Mar 17, 2015 at 12:36:58PM +0100, Quentin Casasnovas wrote:
> > Right, FWIW I think your approach is valid, but not very generic. Re-using
> > the check_insn() and making it more generic so we can widen its use felt
> > like a better approach to me.
> >
> > AIUI, you didn't like my earlier draft because it wasn't very readable, but
> > I think this was just due to the (bad) example I took and by reworking it a
> > bit more, we could end up with the code you previously envisionned:
> >
> > if (static_cpu_has_safe(X86_FEATURE_XSAVEOPT))
> > return check_insn(XSAVEOPT, xsave_buf, ...);
> > else if (static_cpu_has_safe(X86_FEATURE_XSAVES)
> > return check_insn(XSAVES, xsave_buf, ...);
> > else
> > return check_insn(XSAVE, xsave_buf, ...)
> >
> > Or maybe you were saying the actual macros weren't readable?
>
> Well, TBH, I don't like check_insn() either:
>
> * naming is generic but it is not really used in a generic way - only in
> FPU code.
We could make it generic enough so it becomes useful elsewhere as well.
>
> * having variable arguments makes it really really unreadable to me when
> you start looking at how it is called:
>
> ...
> if (config_enabled(CONFIG_X86_32))
> return check_insn(fxrstor %[fx], "=m" (*fx), [fx] "m" (*fx));
> ...
>
> The only thing that lets me differentiate what is input and what is
> output is the "=" in there and you have to know inline asm to know that.
>
It gets even worse with the xstate_fault macro which silently includes the
output operands..
>
> * The arguments have the same syntax as inline asm() arguments but you
> don't see "asm volatile" there so it looks like something half-arsed in
> between.
>
> * the first argument is the instruction string with the operands which
> gets stringified, yuck!
>
What if we renamed it to check_asm()/check_user_asm() and have the first
argument be a string, like an asm statement? So basically check_asm()
would be exactly like an asm() statement except that it'll use a comma to
separate the input, output and clobber operands instead of a colon, and
would protect the first instruction of the assembler template.
if (config_enabled(CONFIG_X86_32))
return check_user_asm("fxrstor %[fx]", [fx] "=m" (*fx),,);
Then we can move that macro up the headers so it can be used elsewhere.
Looks more reable to me than how how we'd write that manually:
if (config_enabled(CONFIG_X86_32) {
volatile asm(ASM_STAC
"1: fxrstor %[fx] \n\t"
"2: \n\t"
ASM_CLAC
".section .fixup,\"ax\" \n\t"
"3: movl $-1, %0 \n\t"
" jmp 2b \n\t"
".previous \n\t"
_ASM_EXTABLE(1b, 3b)
: "=r" (err), [fx] "=m" (*fx)
: : )
return err;
}
> Do I need to say more? :-)
>
> So what I would like is if we killed those half-arsed macros and
> use either generic, clean macros like the alternatives or define
> FPU-specific ones which do what FPU code needs done. If the second,
> they should be self-contained, all in one place so that you don't have
> to grep like crazy to rhyme together what the macro does - nothing like
> xsave_fault. Yuck.
>
> Or even extend the generic macros to fit the FPU use case, if possible
> and if it makes sense.
>
> Oh, and we shouldn't leave readability somewhere on the road.
Readability will be a tough one since gcc extended asm isn't readable (IMO)
and we need to deal with the input/output/clobber operands syntax.
>
> I hope you catch my drift here.
>
I do agree with all your above points, which is why I drafted that proposal
rework of check_insn() in my first e-mail :) AFAICT, you were giving
arguments against the current macros, not against my previous proposal.
Quentin
next prev parent reply other threads:[~2015-03-18 9:05 UTC|newest]
Thread overview: 126+ messages / expand[flat|nested] mbox.gz Atom feed top
2015-03-04 18:30 Oops with tip/x86/fpu Dave Hansen
2015-03-04 19:06 ` Oleg Nesterov
2015-03-04 19:12 ` Dave Hansen
2015-03-04 20:06 ` Borislav Petkov
2015-03-05 15:14 ` Oleg Nesterov
[not found] ` <20150305182203.GA4203@redhat.com>
2015-03-05 18:34 ` Dave Hansen
2015-03-05 18:46 ` Oleg Nesterov
2015-03-05 18:41 ` Dave Hansen
2015-03-26 22:37 ` Yu, Fenghua
2015-03-26 22:43 ` Dave Hansen
2015-03-26 22:48 ` Yu, Fenghua
2015-03-27 7:30 ` Quentin Casasnovas
2015-03-27 19:06 ` Oleg Nesterov
2015-03-05 8:38 ` Quentin Casasnovas
2015-03-05 15:13 ` Oleg Nesterov
2015-03-05 18:42 ` Borislav Petkov
2015-03-05 22:16 ` Dave Hansen
2015-03-05 19:51 ` [PATCH 0/1] x86/fpu: math_state_restore() should not blindly disable irqs Oleg Nesterov
2015-03-05 19:51 ` [PATCH 1/1] " Oleg Nesterov
2015-03-05 20:11 ` Ingo Molnar
2015-03-05 21:25 ` Oleg Nesterov
2015-03-06 7:58 ` Ingo Molnar
2015-03-06 13:26 ` Oleg Nesterov
2015-03-06 13:39 ` Oleg Nesterov
2015-03-06 13:46 ` Ingo Molnar
2015-03-06 14:01 ` Oleg Nesterov
2015-03-06 14:17 ` Oleg Nesterov
2015-03-06 15:00 ` David Vrabel
2015-03-06 15:36 ` Oleg Nesterov
2015-03-06 16:15 ` David Vrabel
2015-03-06 16:31 ` Oleg Nesterov
2015-03-06 17:33 ` Linus Torvalds
2015-03-06 18:15 ` Oleg Nesterov
2015-03-06 19:23 ` Andy Lutomirski
2015-03-06 22:00 ` Linus Torvalds
2015-03-06 22:28 ` Andy Lutomirski
2015-03-07 10:36 ` Ingo Molnar
2015-03-07 20:11 ` Linus Torvalds
2015-03-08 8:55 ` Ingo Molnar
2015-03-08 11:38 ` Ingo Molnar
2015-03-08 13:59 ` Andy Lutomirski
2015-03-08 14:38 ` Andy Lutomirski
2015-03-07 10:32 ` Ingo Molnar
2015-03-07 15:38 ` [PATCH 0/1] x86/fpu: x86/fpu: avoid math_state_restore() without used_math() in __restore_xstate_sig() Oleg Nesterov
2015-03-07 15:38 ` [PATCH 1/1] " Oleg Nesterov
2015-03-09 14:07 ` Borislav Petkov
2015-03-09 14:34 ` Oleg Nesterov
2015-03-09 15:18 ` Borislav Petkov
2015-03-09 16:24 ` Oleg Nesterov
2015-03-09 16:53 ` Borislav Petkov
2015-03-09 17:05 ` Oleg Nesterov
2015-03-09 17:23 ` Borislav Petkov
2015-03-16 12:07 ` [tip:x86/urgent] x86/fpu: Avoid " tip-bot for Oleg Nesterov
2015-03-05 20:35 ` [PATCH 0/1] x86/fpu: math_state_restore() should not blindly disable irqs Oleg Nesterov
2015-03-09 17:10 ` [PATCH] x86/fpu: drop_fpu() should not assume that tsk == current Oleg Nesterov
2015-03-09 17:36 ` Rik van Riel
2015-03-09 17:48 ` Borislav Petkov
2015-03-09 18:06 ` Oleg Nesterov
2015-03-09 18:10 ` Borislav Petkov
2015-03-16 12:07 ` [tip:x86/urgent] x86/fpu: Drop_fpu() should not assume that tsk equals current tip-bot for Oleg Nesterov
2015-03-11 17:33 ` [PATCH 0/4] x86/fpu: avoid math_state_restore() on kthread exec Oleg Nesterov
2015-03-11 17:34 ` [PATCH 1/4] x86/fpu: document user_fpu_begin() Oleg Nesterov
2015-03-13 9:47 ` Borislav Petkov
2015-03-13 14:34 ` Oleg Nesterov
2015-03-23 12:20 ` [tip:x86/fpu] x86/fpu: Document user_fpu_begin() tip-bot for Oleg Nesterov
2015-03-11 17:34 ` [PATCH 2/4] x86/fpu: introduce restore_init_xstate() Oleg Nesterov
2015-03-13 10:34 ` Borislav Petkov
2015-03-13 14:39 ` Oleg Nesterov
2015-03-13 15:20 ` Borislav Petkov
2015-03-16 19:05 ` Rik van Riel
2015-03-23 12:20 ` [tip:x86/fpu] x86/fpu: Introduce restore_init_xstate() tip-bot for Oleg Nesterov
2015-03-11 17:34 ` [PATCH 3/4] x86/fpu: use restore_init_xstate() instead of math_state_restore() on kthread exec Oleg Nesterov
2015-03-13 10:48 ` Borislav Petkov
2015-03-13 14:45 ` Oleg Nesterov
2015-03-13 15:51 ` Borislav Petkov
2015-03-23 12:21 ` [tip:x86/fpu] x86/fpu: Use " tip-bot for Oleg Nesterov
2015-03-11 17:35 ` [PATCH 4/4] x86/fpu: don't abuse drop_init_fpu() in flush_thread() Oleg Nesterov
2015-03-13 10:52 ` Borislav Petkov
2015-03-13 14:55 ` Oleg Nesterov
2015-03-13 16:19 ` Borislav Petkov
2015-03-13 16:26 ` Oleg Nesterov
2015-03-13 19:27 ` Borislav Petkov
2015-03-14 14:48 ` Oleg Nesterov
2015-03-15 17:36 ` Borislav Petkov
2015-03-15 18:16 ` Oleg Nesterov
2015-03-15 18:50 ` Borislav Petkov
2015-03-15 20:04 ` Oleg Nesterov
2015-03-15 20:38 ` Borislav Petkov
2015-03-16 9:35 ` Borislav Petkov
2015-03-16 10:28 ` Ingo Molnar
2015-03-16 14:39 ` Oleg Nesterov
2015-03-16 15:26 ` Borislav Petkov
2015-03-16 15:34 ` Andy Lutomirski
2015-03-16 15:35 ` Borislav Petkov
2015-03-13 17:30 ` [PATCH v2 " Oleg Nesterov
2015-03-14 10:55 ` Borislav Petkov
2015-03-14 10:57 ` [PATCH] x86/fpu: Fold __drop_fpu() into its sole user Borislav Petkov
2015-03-14 15:15 ` Oleg Nesterov
2015-03-16 10:27 ` Ingo Molnar
2015-03-23 12:21 ` [tip:x86/fpu] x86/fpu: Don't abuse drop_init_fpu() in flush_thread() tip-bot for Oleg Nesterov
2015-03-13 18:26 ` [PATCH 0/1] x86/cpu: don't allocate fpu->state for swapper/0 Oleg Nesterov
2015-03-13 18:27 ` [PATCH 1/1] " Oleg Nesterov
2015-03-16 10:18 ` Borislav Petkov
2015-03-23 12:22 ` [tip:x86/fpu] x86/fpu: Don't " tip-bot for Oleg Nesterov
2015-03-14 11:16 ` [PATCH 0/1] x86/cpu: don't " Borislav Petkov
2015-03-14 15:13 ` [PATCH 0/1] x86/cpu: kill eager_fpu_init_bp() Oleg Nesterov
2015-03-14 15:13 ` [PATCH 1/1] " Oleg Nesterov
2015-03-16 12:44 ` Borislav Petkov
2015-03-23 12:22 ` [tip:x86/fpu] x86/fpu: Kill eager_fpu_init_bp() tip-bot for Oleg Nesterov
2015-03-15 16:49 ` [PATCH RFC 0/2] x86/fpu: avoid "xstate_fault" in xsave_user/xrestore_user Oleg Nesterov
2015-03-15 16:50 ` [PATCH RFC 1/2] x86: introduce __user_insn() and __check_insn() Oleg Nesterov
2015-03-15 16:50 ` [PATCH RFC 2/2] x86/fpu: change xsave_user() and xrestore_user() to use __user_insn() Oleg Nesterov
2015-03-16 22:43 ` Quentin Casasnovas
2015-03-17 9:35 ` Borislav Petkov
2015-03-16 14:36 ` [PATCH RFC 0/2] x86/fpu: avoid "xstate_fault" in xsave_user/xrestore_user Borislav Petkov
2015-03-16 14:57 ` Oleg Nesterov
2015-03-16 17:58 ` Borislav Petkov
2015-03-16 22:37 ` Quentin Casasnovas
2015-03-17 9:47 ` Borislav Petkov
2015-03-17 10:00 ` Quentin Casasnovas
2015-03-17 11:20 ` Borislav Petkov
2015-03-17 11:36 ` Quentin Casasnovas
2015-03-17 12:07 ` Borislav Petkov
2015-03-18 9:06 ` Quentin Casasnovas [this message]
2015-03-18 9:53 ` Borislav Petkov
2015-03-17 10:07 ` Quentin Casasnovas
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20150318090632.GF19131@chrystal.uk.oracle.com \
--to=quentin.casasnovas@oracle.com \
--cc=bp@suse.de \
--cc=dave.hansen@intel.com \
--cc=fenghua.yu@intel.com \
--cc=hpa@zytor.com \
--cc=linux-kernel@vger.kernel.org \
--cc=luto@amacapital.net \
--cc=mingo@kernel.org \
--cc=oleg@redhat.com \
--cc=priikone@iki.fi \
--cc=riel@redhat.com \
--cc=sbsiddha@gmail.com \
--cc=torvalds@linux-foundation.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
Powered by JetHome