From: Andi Kleen <andi@firstfloor.org>
To: tglx@linutronix.de
Cc: x86@kernel.org, linux-kernel@vger.kernel.org,
torvalds@linux-foundation.org, dwmw@amazon.co.uk, pjt@google.com,
luto@kernel.org, peterz@infradead.org, thomas.lendacky@amd.com,
tim.c.chen@linux.intel.com, gregkh@linux-foundation.org,
dave.hansen@intel.com, jikos@kernel.org,
Andi Kleen <ak@linux.intel.com>
Subject: [PATCH v1 3/8] x86/entry/clearregs: Clear registers for 64bit SYSCALL
Date: Tue, 9 Jan 2018 17:03:23 -0800 [thread overview]
Message-ID: <20180110010328.22163-4-andi@firstfloor.org> (raw)
In-Reply-To: <20180110010328.22163-1-andi@firstfloor.org>
From: Andi Kleen <ak@linux.intel.com>
We clear all the non argument registers for 64bit SYSCALLs
to minimize any risk of bad speculation using user values.
So far unused argument registers still leak. To be addressed
in future patches.
Signed-off-by: Andi Kleen <ak@linux.intel.com>
---
arch/x86/entry/entry_64.S | 9 +++++++++
1 file changed, 9 insertions(+)
diff --git a/arch/x86/entry/entry_64.S b/arch/x86/entry/entry_64.S
index bbdfbdd817d6..632081fd7086 100644
--- a/arch/x86/entry/entry_64.S
+++ b/arch/x86/entry/entry_64.S
@@ -236,6 +236,14 @@ GLOBAL(entry_SYSCALL_64_after_hwframe)
pushq %r11 /* pt_regs->r11 */
sub $(6*8), %rsp
SAVE_EXTRA_REGS
+ /* Sanitize registers against speculation attacks */
+ /* r10 is cleared later, arguments are handled in san_args* */
+ CLEAR_R11_TO_R15
+#ifndef CONFIG_FRAME_POINTER
+ xor %ebp, %ebp
+#endif
+ xor %ebx, %ebx
+ xor %ecx, %ecx
UNWIND_HINT_REGS extra=0
@@ -263,6 +271,7 @@ entry_SYSCALL_64_fastpath:
#endif
ja 1f /* return -ENOSYS (already in pt_regs->ax) */
movq %r10, %rcx
+ xor %r10, %r10
#ifdef CONFIG_RETPOLINE
movq sys_call_table(, %rax, 8), %rax
--
2.14.3
next prev parent reply other threads:[~2018-01-10 1:05 UTC|newest]
Thread overview: 34+ messages / expand[flat|nested] mbox.gz Atom feed top
2018-01-10 1:03 x86/clearregs: Register sanitizing at kernel entry for speculation hygiene Andi Kleen
2018-01-10 1:03 ` [PATCH v1 1/8] x86/entry/clearregs: Remove partial stack frame in fast system call Andi Kleen
2018-01-10 2:46 ` Brian Gerst
2018-01-11 0:16 ` Andi Kleen
2018-01-11 0:54 ` Brian Gerst
2018-01-11 1:02 ` Andi Kleen
2018-01-11 0:55 ` Andy Lutomirski
2018-01-11 1:01 ` Andi Kleen
2018-01-11 1:01 ` Brian Gerst
2018-01-11 1:22 ` Andy Lutomirski
2018-01-11 1:47 ` Andi Kleen
2018-01-11 18:44 ` Andi Kleen
2018-01-11 2:09 ` Josh Poimboeuf
2018-01-12 3:22 ` Josh Poimboeuf
2018-01-10 1:03 ` [PATCH v1 2/8] x86/entry/clearregs: Add infrastructure to clear registers Andi Kleen
2018-01-11 19:58 ` Konrad Rzeszutek Wilk
2018-01-11 20:10 ` Andi Kleen
2018-01-10 1:03 ` Andi Kleen [this message]
2018-01-11 3:35 ` [PATCH v1 3/8] x86/entry/clearregs: Clear registers for 64bit SYSCALL Brian Gerst
2018-01-11 18:47 ` Andi Kleen
2018-01-12 3:45 ` Josh Poimboeuf
2018-01-10 1:03 ` [PATCH v1 4/8] x86/entry/retpoline: Clear extra registers for compat syscalls Andi Kleen
2018-01-10 1:03 ` [PATCH v1 5/8] x86/entry/clearregs: Clear registers for 64bit exceptions/interrupts Andi Kleen
2018-01-10 1:23 ` Andy Lutomirski
2018-01-10 1:03 ` [PATCH v1 6/8] x86/entry/clearregs: Add number of arguments to syscall tables Andi Kleen
2018-01-10 1:26 ` Andy Lutomirski
2018-01-10 4:37 ` Andi Kleen
2018-01-10 20:05 ` Andy Lutomirski
2018-01-10 1:03 ` [PATCH v1 7/8] x86/entry/clearregs: Add 64bit stubs to clear unused arguments regs Andi Kleen
2018-01-10 1:03 ` [PATCH v1 8/8] x86/entry/clearregs: Clear registers for 32bit kernel Andi Kleen
2018-01-10 1:24 ` Andy Lutomirski
2018-01-10 1:16 ` x86/clearregs: Register sanitizing at kernel entry for speculation hygiene Andy Lutomirski
2018-01-10 1:34 ` Andi Kleen
2018-01-10 1:39 ` Andy Lutomirski
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20180110010328.22163-4-andi@firstfloor.org \
--to=andi@firstfloor.org \
--cc=ak@linux.intel.com \
--cc=dave.hansen@intel.com \
--cc=dwmw@amazon.co.uk \
--cc=gregkh@linux-foundation.org \
--cc=jikos@kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=luto@kernel.org \
--cc=peterz@infradead.org \
--cc=pjt@google.com \
--cc=tglx@linutronix.de \
--cc=thomas.lendacky@amd.com \
--cc=tim.c.chen@linux.intel.com \
--cc=torvalds@linux-foundation.org \
--cc=x86@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
Powered by JetHome