mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [RFC PATCH 0/9] bpf: Mitigate Spectre v1 using speculation barriers
@ 2025-02-24 20:36 Luis Gerhorst
  2025-02-24 20:36 ` [RFC PATCH 1/9] bpf/arm64: Unset bypass_spec_v4() instead of ignoring BPF_NOSPEC Luis Gerhorst
                   ` (8 more replies)
  0 siblings, 9 replies; 11+ messages in thread
From: Luis Gerhorst @ 2025-02-24 20:36 UTC (permalink / raw)
  To: Alexei Starovoitov, Daniel Borkmann, Andrii Nakryiko,
	Martin KaFai Lau, Eduard Zingerman, Song Liu, Yonghong Song,
	John Fastabend, KP Singh, Stanislav Fomichev, Hao Luo, Jiri Olsa,
	Puranjay Mohan, Xu Kuohai, Catalin Marinas, Will Deacon,
	Mykola Lysenko, Shuah Khan, Luis Gerhorst, Henriette Herzog,
	Cupertino Miranda, Matan Shachnai, Dimitar Kanaliev,
	Shung-Hsi Yu, Daniel Xu, bpf, linux-arm-kernel, linux-kernel,
	linux-kselftest

This improves the expressiveness of unprivileged BPF by inserting
speculation barriers instead of rejcting the programs.

The approach was presented at LPC'24:
  https://lpc.events/event/18/contributions/1954/ ("Mitigating
  Spectre-PHT using Speculation Barriers in Linux eBPF")
and RAID'24:
  https://arxiv.org/pdf/2405.00078 ("VeriFence: Lightweight and Precise
  Spectre Defenses for Untrusted Linux Kernel Extensions")

Goal of this RFC is to get feedback on the approach and the structuring
into commits.

TODOs to be fixed for final version:
* actually emit arm64 barrier
* fix unexpected_load_success from test_progs for "bpf: Fall back to nospec for sanitization-failures"
* use bpf-next as base commit

Luis Gerhorst (9):
  bpf/arm64: Unset bypass_spec_v4() instead of ignoring BPF_NOSPEC
  bpf: Refactor do_check() if/else into do_check_insn()
  bpf: Return EFAULT on misconfigurations
  bpf: Return EFAULT on internal errors
  bpf: Fall back to nospec if v1 verification fails
  bpf: Allow nospec-protected var-offset stack access
  bpf: Refactor push_stack to return error code
  bpf: Fall back to nospec for sanitization-failures
  bpf: Cut speculative path verification short

 arch/arm64/net/bpf_jit_comp.c                 |  10 +-
 include/linux/bpf.h                           |  14 +-
 include/linux/bpf_verifier.h                  |   3 +-
 kernel/bpf/core.c                             |  17 +-
 kernel/bpf/verifier.c                         | 832 ++++++++++--------
 .../selftests/bpf/progs/verifier_and.c        |   3 +-
 .../selftests/bpf/progs/verifier_bounds.c     |  30 +-
 .../selftests/bpf/progs/verifier_movsx.c      |   6 +-
 .../selftests/bpf/progs/verifier_unpriv.c     |   3 +-
 .../bpf/progs/verifier_value_ptr_arith.c      |  11 +-
 10 files changed, 520 insertions(+), 409 deletions(-)


base-commit: d082ecbc71e9e0bf49883ee4afd435a77a5101b6
-- 
2.48.1


^ permalink raw reply	[flat|nested] 11+ messages in thread

end of thread, other threads:[~2025-02-27 16:08 UTC | newest]

Thread overview: 11+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2025-02-24 20:36 [RFC PATCH 0/9] bpf: Mitigate Spectre v1 using speculation barriers Luis Gerhorst
2025-02-24 20:36 ` [RFC PATCH 1/9] bpf/arm64: Unset bypass_spec_v4() instead of ignoring BPF_NOSPEC Luis Gerhorst
2025-02-24 20:36 ` [RFC PATCH 2/9] bpf: Refactor do_check() if/else into do_check_insn() Luis Gerhorst
2025-02-24 20:36 ` [RFC PATCH 3/9] bpf: Return EFAULT on misconfigurations Luis Gerhorst
2025-02-24 20:36 ` [RFC PATCH 4/9] bpf: Return EFAULT on internal errors Luis Gerhorst
2025-02-24 20:47 ` [RFC PATCH 5/9] bpf: Fall back to nospec if v1 verification fails Luis Gerhorst
2025-02-27 16:07   ` Luis Gerhorst
2025-02-24 20:51 ` [RFC PATCH 6/9] bpf: Allow nospec-protected var-offset stack access Luis Gerhorst
2025-02-24 20:52 ` [RFC PATCH 7/9] bpf: Refactor push_stack to return error code Luis Gerhorst
2025-02-24 20:55 ` [RFC PATCH 8/9] bpf: Fall back to nospec for sanitization-failures Luis Gerhorst
2025-02-24 20:55 ` [RFC PATCH 9/9] bpf: Cut speculative path verification short Luis Gerhorst

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®