From: Ram Pai <linuxram@us.ibm.com>
To: Benjamin Herrenschmidt <benh@kernel.crashing.org>
Cc: Anshuman Khandual <khandual@linux.vnet.ibm.com>,
linuxppc-dev@lists.ozlabs.org, linux-kernel@vger.kernel.org,
dave.hansen@intel.com, paulus@samba.org,
aneesh.kumar@linux.vnet.ibm.com
Subject: Re: [RFC PATCH 7/7 v1]powerpc: Deliver SEGV signal on protection key violation.
Date: Thu, 22 Jun 2017 14:41:31 -0700 [thread overview]
Message-ID: <20170622214131.GO17588@ram.oc3035372033.ibm.com> (raw)
In-Reply-To: <1497653684.2897.104.camel@kernel.crashing.org>
On Sat, Jun 17, 2017 at 08:54:44AM +1000, Benjamin Herrenschmidt wrote:
> On Fri, 2017-06-16 at 12:15 -0700, Ram Pai wrote:
> > gp_regs size is not changed, nor is the layout. A unused field in
> > the gp_regs is used to fill in the AMR contents. Old binaries will not
> > be knowing about this unused field, and hence should not break.
> >
> > New binaries can leverage this already existing but newly defined
> > field; to read the contents of AMR.
> >
> > Is it still a concern?
>
> Calls to sys_swapcontext with a made-up context will end up with a crap
> AMR if done by code who didn't know about that register.
Turns out x86 does not have this problem, because x86 does not implement
sys_swapcontext. However; unlike x86, powerpc lets signal handler
program the AMR(x86 PKRU equivalent), which can persist even after the
signal handler returns to the kernel through sys_sigreturn.
So I am inclined to deviate from the x86 protection-key semantics.
On x86 the persistent way for the signal handler
to change the key register(PKRU) is through a field in the siginfo structure.
And on powerpc the persistent way for the signal handler to change the
key register(AMR) will be to directly program the AMR register.
This should resolve your concern on powerpc, since there is no way
a crap AMR value will change the real AMR register, because the powerpc
kernel will not be letting it happen. Acceptable?
RP
next prev parent reply other threads:[~2017-06-22 21:41 UTC|newest]
Thread overview: 23+ messages / expand[flat|nested] mbox.gz Atom feed top
2017-06-06 1:05 [RFC PATCH 0/7 v1] powerpc: Memory Protection Keys Ram Pai
2017-06-06 1:05 ` [RFC PATCH 1/7 v1]powerpc: Free up four PTE bits to accommodate memory keys Ram Pai
2017-06-12 6:57 ` Aneesh Kumar K.V
2017-06-12 22:20 ` Ram Pai
2017-06-13 2:02 ` Aneesh Kumar K.V
2017-06-13 21:51 ` Ram Pai
2017-06-13 4:52 ` Aneesh Kumar K.V
2017-06-13 21:52 ` Ram Pai
2017-06-06 1:05 ` [RFC PATCH 2/7 v1]powerpc: Implement sys_pkey_alloc and sys_pkey_free system call Ram Pai
2017-06-06 1:05 ` [RFC PATCH 3/7 v1]powerpc: store and restore the key state across context switches Ram Pai
2017-06-06 1:05 ` [RFC PATCH 4/7 v1]powerpc: Implementation for sys_mprotect_pkey() system call Ram Pai
2017-06-06 1:05 ` [RFC PATCH 5/7 v1]powerpc: Program HPTE key protection bits Ram Pai
2017-06-06 1:05 ` [RFC PATCH 6/7 v1]powerpc: Handle exceptions caused by violation of key protection Ram Pai
2017-06-06 1:05 ` [RFC PATCH 7/7 v1]powerpc: Deliver SEGV signal on protection key violation Ram Pai
2017-06-16 9:20 ` Anshuman Khandual
2017-06-16 10:33 ` Benjamin Herrenschmidt
2017-06-16 19:15 ` Ram Pai
2017-06-16 22:54 ` Benjamin Herrenschmidt
2017-06-22 21:41 ` Ram Pai [this message]
2017-06-16 19:10 ` Ram Pai
2017-06-16 11:18 ` Michael Ellerman
2017-06-16 19:35 ` Ram Pai
2017-06-20 7:07 ` [RFC PATCH 0/7 v1] powerpc: Memory Protection Keys Pavel Machek
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20170622214131.GO17588@ram.oc3035372033.ibm.com \
--to=linuxram@us.ibm.com \
--cc=aneesh.kumar@linux.vnet.ibm.com \
--cc=benh@kernel.crashing.org \
--cc=dave.hansen@intel.com \
--cc=khandual@linux.vnet.ibm.com \
--cc=linux-kernel@vger.kernel.org \
--cc=linuxppc-dev@lists.ozlabs.org \
--cc=paulus@samba.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®