From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Google-Smtp-Source: AH8x226Aa/K7jSfbpryfUYdDchJh03t7O2uOgzqFpSQpOFCA07HJrTE0U69/bvIHA7GnKyl2Byo0 ARC-Seal: i=1; a=rsa-sha256; t=1516719713; cv=none; d=google.com; s=arc-20160816; b=qLP6NXQDcduEfdwIpc7jnax8/ztgylMH3i6gtqRnuxrUw8N9Qb+NiB3GJJ235i72v/ UMaAorQ3o/8rkQ3Lix/FtE6Gog3/5/NeDhNlI1NGTYvcvP5M7QfzR9yX9N56DRHk+SU6 PtRazyx9rf6XvDC1vrP2Czgjl2EkcnPOl+W5mmhbS34M7UB0GRFq5Um7tdwv6+wiOY14 kbTWAq7zQ4GI0YpA+kYO3LmnVC6LKKc3IaFzliYXkV2x7vufdUjF9lK/s0aVtaFAbGai Yz4hEqa4c+7qXZKnVbGbF3fKyOeiMnauxr6jozUrzLjzUzU2usRtttmOFlINWpv3GtOC cZxw== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=content-transfer-encoding:content-language:in-reply-to:mime-version :user-agent:date:message-id:from:cc:references:to:subject :arc-authentication-results; bh=2XlVAl35HHlXSnkckXGY4xndEaF+HrKWgOE0MctnN+E=; b=G1VKHsVZ1wP34Tw749OD3WIoKqIQa9PWry9gwO49dPqVob/7wRxpVAQlZyHEkW3/Eh KawikvdGU1mAeKlY+q8TG/mCzU0f0vJX92JTz5gj2NLHzDa+VPZQ0cydxTMwWvRVULBO D2cN3Uv5KczlhLye+7teeXVqKPp7O8kdhJZvSMMy2I4oKhIZvGckmVTkbOF9Zl77S5II KqzrwaP7emj0ISIo+ArB34LLCabFMJmCbFzMO4HQ0n+lTa8F6qVv0JXYMv201GcRxpHX Yj3er801ZN8b5z7XRP5C7M3CBg86O4jwCeiw9JXoDyPGAo1v4Sy1Ifux9gA62f0WGUBW dJdA== ARC-Authentication-Results: i=1; mx.google.com; spf=pass (google.com: domain of dave.hansen@intel.com designates 192.55.52.43 as permitted sender) smtp.mailfrom=dave.hansen@intel.com Authentication-Results: mx.google.com; spf=pass (google.com: domain of dave.hansen@intel.com designates 192.55.52.43 as permitted sender) smtp.mailfrom=dave.hansen@intel.com X-Amp-Result: SKIPPED(no attachment in message) X-Amp-File-Uploaded: False X-ExtLoop1: 1 X-IronPort-AV: E=Sophos;i="5.46,401,1511856000"; d="scan'208";a="197972022" Subject: Re: [RFC 09/10] x86/enter: Create macros to restrict/unrestrict Indirect Branch Speculation To: Ingo Molnar , David Woodhouse References: <1516476182-5153-1-git-send-email-karahmed@amazon.de> <1516476182-5153-10-git-send-email-karahmed@amazon.de> <1516566497.9814.78.camel@infradead.org> <1516572013.9814.109.camel@infradead.org> <1516638426.9521.20.camel@infradead.org> <20180123072930.soz25cyky3u4hpgv@gmail.com> <20180123075358.nztpyxympwfkyi2a@gmail.com> <20180123092756.iznzepwnolsviof7@gmail.com> Cc: Linus Torvalds , KarimAllah Ahmed , Linux Kernel Mailing List , Andi Kleen , Andrea Arcangeli , Andy Lutomirski , Arjan van de Ven , Ashok Raj , Asit Mallick , Borislav Petkov , Dan Williams , Greg Kroah-Hartman , "H . Peter Anvin" , Ingo Molnar , Janakarajan Natarajan , Joerg Roedel , Jun Nakajima , Laura Abbott , Masami Hiramatsu , Paolo Bonzini , Peter Zijlstra , =?UTF-8?B?UmFkaW0gS3LEjW3DocWZ?= , Thomas Gleixner , Tim Chen , Tom Lendacky , KVM list , the arch/x86 maintainers , Arjan Van De Ven From: Dave Hansen Message-ID: Date: Tue, 23 Jan 2018 07:01:31 -0800 User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:52.0) Gecko/20100101 Thunderbird/52.5.0 MIME-Version: 1.0 In-Reply-To: <20180123092756.iznzepwnolsviof7@gmail.com> Content-Type: text/plain; charset=utf-8 Content-Language: en-US Content-Transfer-Encoding: 7bit X-getmail-retrieved-from-mailbox: INBOX X-GMAIL-THRID: =?utf-8?q?1590140582166248265?= X-GMAIL-MSGID: =?utf-8?q?1590395890072487680?= X-Mailing-List: linux-kernel@vger.kernel.org List-ID: On 01/23/2018 01:27 AM, Ingo Molnar wrote: > > - All asynchronous contexts (IRQs, NMIs, etc.) stuff the RSB before IRET. (The > tracking could probably made IRQ and maybe even NMI safe, but the worst-case > nesting scenarios make my head ache.) This all sounds totally workable to me. We talked about using ftrace itself to track call depth, but it would be unusable in production, of course. This seems workable, though. You're also totally right about the zero overhead on most kernels with it turned off when we don't need RSB underflow protection (basically pre-Skylake). I also agree that the safe thing to do is to just stuff before iret. I bet we can get a ftrace-driven RSB tracker working precisely enough even with NMIs, but it's way simpler to just stuff and be done with it for now.