From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Google-Smtp-Source: AH8x225bipl9GdAUbC1qef2rUbF3FW7F4W8BeAsd0ZPExbiZoVNIgRJ/Y4zx7l36MR5RBhn3FxsZ ARC-Seal: i=1; a=rsa-sha256; t=1517164623; cv=none; d=google.com; s=arc-20160816; b=pIvIjSMTeFCIh/i4j3D4LR9JWhyQJVpTQ74M5ieCon15GburbN/fo6V0707+mvjXUW 6H2SJ4qtXvmkVxH3ss9bX8aDXyw54vAFisxmWSFXio6sCnDIpnsX5olbjA+DkFd8WD+U OS5rP+TIy2UGVgPzsKROXpg7E3EqRMjIGhGcWlIhLWgJzJhwpP6YZu5N9kzDpQuDZJ2U U7f8e4THLKsCdmAGK/7IYvN1YUyuntXkf/fIUNhs6B8Fvo2QnrX+zEsT8R5uOWN77Juj K9UJQzU5swPSZo3+hcJ9wVSK0MebQDJJGhyExfV73reaCVlggRcjCKBMDCs/8E0DPpcl 1Dfg== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=subject:mime-version:user-agent:references:message-id:in-reply-to :cc:to:from:date:delivered-to:list-id:list-subscribe :list-unsubscribe:list-help:list-post:precedence:mailing-list :arc-authentication-results; bh=aXGAV7IwvioWMnXVFcZskK8yrW3sAVY/hFKD4clQ6iQ=; b=dEpkkwFd0LAVhhPu6dM1uA1qAXF6PBAqDRDHAHjLf5VX+BacEtMHaUD+t0Hqr3fcx7 Qkf+D+mJwqLvC5t5o76JzCbWwGZZB5IJIRIqk09dBPrlZ6fM9Y930iKxUfhysGjG+QXU xHHh7cvRKdZu/mWygcnSMvftPObwImu44Q31sZbRziqu/QPDpYsRQnkUO81MqhyaIjz5 VU28nyKQKZDVeRXNRRNU/M6lf/SqQemnTKWaIMCMIDZUi8zR4lgUkW0yo8q8PdIr2/xj TYqno3oDaHTkAiCfCHw+dgZxCgtoh2/2vvh4eAyjPh2TjDbAHJAB0T2p0WuhiJo8FYDy h8+w== ARC-Authentication-Results: i=1; mx.google.com; spf=pass (google.com: domain of kernel-hardening-return-11488-gregkh=linuxfoundation.org@lists.openwall.com designates 195.42.179.200 as permitted sender) smtp.mailfrom=kernel-hardening-return-11488-gregkh=linuxfoundation.org@lists.openwall.com Authentication-Results: mx.google.com; spf=pass (google.com: domain of kernel-hardening-return-11488-gregkh=linuxfoundation.org@lists.openwall.com designates 195.42.179.200 as permitted sender) smtp.mailfrom=kernel-hardening-return-11488-gregkh=linuxfoundation.org@lists.openwall.com Mailing-List: contact kernel-hardening-help@lists.openwall.com; run by ezmlm List-Post: List-Help: List-Unsubscribe: List-Subscribe: Date: Sun, 28 Jan 2018 19:36:38 +0100 (CET) From: Thomas Gleixner To: Dan Williams cc: Ingo Molnar , linux-arch , Cyril Novikov , Kernel Hardening , Peter Zijlstra , Catalin Marinas , X86 ML , Will Deacon , Russell King , Ingo Molnar , Greg KH , "H. Peter Anvin" , Linus Torvalds , Alan Cox , Linux Kernel Mailing List In-Reply-To: Message-ID: References: <151703971300.26578.1185595719337719486.stgit@dwillia2-desk3.amr.corp.intel.com> <151703972396.26578.7326612698912543866.stgit@dwillia2-desk3.amr.corp.intel.com> <20180128085500.djlm5rlbhjlpfj4i@gmail.com> User-Agent: Alpine 2.20 (DEB 67 2015-01-07) MIME-Version: 1.0 Content-Type: text/plain; charset=US-ASCII X-Linutronix-Spam-Score: -1.0 X-Linutronix-Spam-Level: - X-Linutronix-Spam-Status: No , -1.0 points, 5.0 required, ALL_TRUSTED=-1,SHORTCIRCUIT=-0.0001 Subject: [kernel-hardening] Re: [PATCH v5 02/12] array_idx: sanitize speculative array de-references X-getmail-retrieved-from-mailbox: INBOX X-GMAIL-THRID: =?utf-8?q?1590732017653801778?= X-GMAIL-MSGID: =?utf-8?q?1590862412090382509?= X-Mailing-List: linux-kernel@vger.kernel.org List-ID: On Sun, 28 Jan 2018, Dan Williams wrote: > On Sun, Jan 28, 2018 at 12:55 AM, Ingo Molnar wrote: > >> + */ > >> +#define array_idx(idx, sz) \ > >> +({ \ > >> + typeof(idx) _i = (idx); \ > >> + typeof(sz) _s = (sz); \ > >> + unsigned long _mask = array_idx_mask(_i, _s); \ > >> + \ > >> + BUILD_BUG_ON(sizeof(_i) > sizeof(long)); \ > >> + BUILD_BUG_ON(sizeof(_s) > sizeof(long)); \ > >> + \ > >> + _i &= _mask; \ > >> + _i; \ > >> +}) > >> +#endif /* __NOSPEC_H__ */ > > > > For heaven's sake, please name a size variable as 'size', not 'sz'. We don't have > > a shortage of characters and can deobfuscate common primitives, can we? > > > > Also, beyond the nits, I also hate the namespace here. We have a new generic > > header providing two new methods: > > > > #include > > > > array_idx_mask() > > array_idx() > > > > which is then optimized for x86 in asm/barrier.h. That's already a non-sequitor. > > > > Then we introduce uaccess API variants with a _nospec() postfix. > > > > Then we add ifence() to x86. > > > > There's no naming coherency to this. > > Ingo, I love you, but please take the incredulity down a bit, > especially when I had 'nospec' in all the names in v1. Thomas, Peter, > and Alexei wanted s/nospec_barrier/ifence/ and Sorry, I never was involved in that discussion. > s/array_idx_nospec/array_idx/. You can always follow on with a patch > to fix up the names and placements to your liking. While they'll pick > on my name choices, they won't pick on yours, because I simply can't > be bothered to care about a bikeshed color at this point after being > bounced around for 5 revisions of this patch set. Oh well, we really need this kind of attitude right now. We are all fed up with that mess, but Ingo and I care about the details, consistency and general code quality beyond the current rush to get stuff solved. It's our damned job as maintainers. If you decide you don't care anymore, please let me know, so I can try to free up some cycles to pick up the stuff from where you decided to dump it. Thanks, tglx