From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Google-Smtp-Source: AH8x2268UCnt3smixatQ8Cz8ILEi4CcXJNNgz5nD1naiO8Tkhwl4oNeTEiiSpyqsahqiwqYBscKl ARC-Seal: i=1; a=rsa-sha256; t=1516781337; cv=none; d=google.com; s=arc-20160816; b=J+zlcJoo80TPoW2iYwsLz3iA+K1+PPSWSvtuYsEHDBQuEJjhorujk4diokic5NTOJn u6zUdDREmUnl1tO3df7VufAGv1omE+Hx+a8oBaBJVtv/6xqoRAbRdlnaWlcK/Aj3sFkB 8gpM1VKHzDw5hg3WELlutroXbCSpOKDV26eLimrku1W3JZHqkfliP+KKGC3u2a2SrP+U NyX3GSY4bvCOFgy5JyrYC1sZaPJ0MxwkmFxaWNba98l4EguVx2O8ImFNQzn8hwJMconX Rkew+b2eQ5+rwPdX6Zwc62ngVW05idHfISxbw6Q0MRfH3yKIxDSqqLCqeqUQDppdMmmB BaMg== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=message-id:content-transfer-encoding:content-language:in-reply-to :mime-version:user-agent:date:from:references:cc:to:subject :arc-authentication-results; bh=ZJOZDUZJ8KriX79XtYyBen/wLgbKk8ZlYGsXuFYUIt8=; b=N5hBBE2dGK7RJn5f3zXkYrYnhKCJZlgb6VTAL5/PaOnsXLkW3F/DCVcF/7qnhK5mCx jq2KJu0xy5PtaV3Xj693aZvKCcVOn49fZXgvMUkgPU/W8SitZOdiOFfygOJ8lLl7jZmg 38i8cGCmoVRKgeWYTmJTrVNPM+YIWGOq0mJDZVIE3xly63C7yXMB5kJbIHonG/V/iJnj I3PGu77UXNqrETHaSVJVW2/CQLDf4IjRRtF/JfiNq6vYux41kF74nR9TrYzXZKL9hy5u SZUpCA+Ua3HIe559uyc430r2gkkQ9A57aLFfr8vWu27Cw6MBnG8c3QbcfQCZUaq0wHBk eS/w== ARC-Authentication-Results: i=1; mx.google.com; spf=pass (google.com: domain of borntraeger@de.ibm.com designates 148.163.158.5 as permitted sender) smtp.mailfrom=borntraeger@de.ibm.com; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=ibm.com Authentication-Results: mx.google.com; spf=pass (google.com: domain of borntraeger@de.ibm.com designates 148.163.158.5 as permitted sender) smtp.mailfrom=borntraeger@de.ibm.com; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=ibm.com Subject: Re: [PATCH 1/5] prctl: add PR_ISOLATE_BP process control To: Dominik Brodowski , Martin Schwidefsky Cc: linux-kernel@vger.kernel.org, linux-s390@vger.kernel.org, kvm@vger.kernel.org, Heiko Carstens , Paolo Bonzini , Cornelia Huck , David Hildenbrand , Greg Kroah-Hartman , Jon Masters , Marcus Meissner , Jiri Kosina , w@1wt.eu, keescook@chromium.org References: <1516712825-2917-1-git-send-email-schwidefsky@de.ibm.com> <1516712825-2917-2-git-send-email-schwidefsky@de.ibm.com> <20180123170719.GA4154@isilmar-4.linta.de> From: Christian Borntraeger Date: Wed, 24 Jan 2018 09:08:49 +0100 User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:52.0) Gecko/20100101 Thunderbird/52.4.0 MIME-Version: 1.0 In-Reply-To: <20180123170719.GA4154@isilmar-4.linta.de> Content-Type: text/plain; charset=utf-8 Content-Language: en-US Content-Transfer-Encoding: 7bit X-TM-AS-GCONF: 00 x-cbid: 18012408-0008-0000-0000-000004C5389F X-IBM-AV-DETECTION: SAVI=unused REMOTE=unused XFE=unused x-cbparentid: 18012408-0009-0000-0000-00001E58BAA8 Message-Id: <57cfefd8-53c1-9928-23fd-05a50350d0dc@de.ibm.com> X-Proofpoint-Virus-Version: vendor=fsecure engine=2.50.10432:,, definitions=2018-01-24_04:,, signatures=0 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 priorityscore=1501 malwarescore=0 suspectscore=0 phishscore=0 bulkscore=0 spamscore=0 clxscore=1015 lowpriorityscore=0 impostorscore=0 adultscore=0 classifier=spam adjust=0 reason=mlx scancount=1 engine=8.0.1-1709140000 definitions=main-1801240109 X-getmail-retrieved-from-mailbox: INBOX X-GMAIL-THRID: =?utf-8?q?1590388677068788062?= X-GMAIL-MSGID: =?utf-8?q?1590460507411634519?= X-Mailing-List: linux-kernel@vger.kernel.org List-ID: On 01/23/2018 06:07 PM, Dominik Brodowski wrote: > On Tue, Jan 23, 2018 at 02:07:01PM +0100, Martin Schwidefsky wrote: >> Add the PR_ISOLATE_BP operation to prctl. The effect of the process >> control is to make all branch prediction entries created by the execution >> of the user space code of this task not applicable to kernel code or the >> code of any other task. > > What is the rationale for requiring a per-process *opt-in* for this added > protection? > > For KPTI on x86, the exact opposite approach is being discussed (see, e.g. > http://lkml.kernel.org/r/1515612500-14505-1-git-send-email-w@1wt.eu ): By > default, play it safe, with KPTI enabled. But for "trusted" processes, one > may opt out using prctrl. FWIW, this is not about KPTI. s390 always has the kernel in a separate address space. Its only about potential spectre like attacks. This idea is to be able to isolate in controlled environments, e.g. if you have only one thread with untrusted code (e.g. jitting remote code). The property of the branch prediction mode on s390 is that it protects in two ways - against being attacked but also against being able to attack via the btb.