Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1303971

Re: [PATCH 31/31] x86, pkeys: execute-only support

From Andy Lutomirski <luto@amacapital.net>
Newsgroups linux.kernel
Subject Re: [PATCH 31/31] x86, pkeys: execute-only support
Date 2016-01-07 23:50 +0100
Message-ID <qOrxw-67X-19@gated-at.bofh.it> (permalink)
References <qO6jn-8sH-3@gated-at.bofh.it> <qO6jq-8sH-49@gated-at.bofh.it> <qOq8p-5ia-11@gated-at.bofh.it> <qOr4t-5VS-1@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


On Thu, Jan 7, 2016 at 2:13 PM, Dave Hansen <dave@sr71.net> wrote:
> On 01/07/2016 01:10 PM, Andy Lutomirski wrote:
>> On Wed, Jan 6, 2016 at 4:01 PM, Dave Hansen <dave@sr71.net> wrote:
>>> From: Dave Hansen <dave.hansen@linux.intel.com>
>>> Protection keys provide new page-based protection in hardware.
>>> But, they have an interesting attribute: they only affect data
>>> accesses and never affect instruction fetches.  That means that
>>> if we set up some memory which is set as "access-disabled" via
>>> protection keys, we can still execute from it.
>>> could lose the bits in PKRU that enforce execute-only
>>> permissions.  To avoid this, we suggest avoiding ever calling
>>> mmap() or mprotect() when the PKRU value is expected to be
>>> stable.
>>
>> This may be a bit unfortunate for people who call mmap from signal
>> handlers.  Admittedly, the failure mode isn't that bad.
>
> mmap() isn't in the list of async-signal-safe functions, so it's bad
> already.

mmap the POSIX function may not be, but mmap the syscall is just a
syscall.  Also, I'm moderately confident that there are synchronous
signals, too.  If not, there should be (e.g. raise with an unblocked
signal).

>
>> Out of curiosity, do you have timing information for WRPKRU and
>> RDPKRU?  If they're fast and if anyone ever implements my deferred
>> xstate restore idea, then the performance issue goes away and we can
>> stop caring about whether PKRU is in the init state.
>
> I don't have timing information that I can share.  From my perspective,
> they're pretty fast, *not* like an MSR write or something.  I think
> they're fast enough to use in the context switch path.  I'd say PKRU is
> in XSAVE for consistency more than for performance.
>

I'll play with this at some point.  Probably not until I get the right hardware.

--Andy

Back to linux.kernel | Previous | NextPrevious in thread | Next in thread | Find similar | Unroll thread


Thread

[PATCH 00/31] x86: Memory Protection Keys (v8) Dave Hansen <dave@sr71.net> - 2016-01-07 01:10 +0100
  [PATCH 22/31] x86, pkeys: dump pkey from VMA in /proc/pid/smaps Dave Hansen <dave@sr71.net> - 2016-01-07 01:10 +0100
  [PATCH 28/31] x86, fpu: allow setting of XSAVE state Dave Hansen <dave@sr71.net> - 2016-01-07 01:10 +0100
  [PATCH 06/31] x86, pkeys: add PKRU xsave fields and data structure(s) Dave Hansen <dave@sr71.net> - 2016-01-07 01:10 +0100
  [PATCH 07/31] x86, pkeys: PTE bits for storing protection key Dave Hansen <dave@sr71.net> - 2016-01-07 01:10 +0100
  [PATCH 01/31] mm, gup: introduce concept of "foreign" get_user_pages() Dave Hansen <dave@sr71.net> - 2016-01-07 01:10 +0100
    Re: [PATCH 01/31] mm, gup: introduce concept of "foreign"  get_user_pages() Vlastimil Babka <vbabka@suse.cz> - 2016-01-13 20:10 +0100
      Re: [PATCH 01/31] mm, gup: introduce concept of "foreign"  get_user_pages() Dave Hansen <dave@sr71.net> - 2016-01-13 20:20 +0100
  [PATCH 17/31] x86, pkeys: check VMAs and PTEs for protection keys Dave Hansen <dave@sr71.net> - 2016-01-07 01:10 +0100
  [PATCH 03/31] x86, pkeys: Add Kconfig option Dave Hansen <dave@sr71.net> - 2016-01-07 01:10 +0100
  [PATCH 29/31] x86, pkeys: allow kernel to modify user pkey rights register Dave Hansen <dave@sr71.net> - 2016-01-07 01:10 +0100
  [PATCH 21/31] x86, pkeys: dump PKRU with other kernel registers Dave Hansen <dave@sr71.net> - 2016-01-07 01:10 +0100
  [PATCH 11/31] x86, pkeys: pass VMA down in to fault signal generation code Dave Hansen <dave@sr71.net> - 2016-01-07 01:10 +0100
  [PATCH 10/31] x86, pkeys: arch-specific protection bits Dave Hansen <dave@sr71.net> - 2016-01-07 01:10 +0100
  [PATCH 19/31] x86, pkeys: optimize fault handling in access_error() Dave Hansen <dave@sr71.net> - 2016-01-07 01:10 +0100
  [PATCH 05/31] x86, pkeys: define new CR4 bit Dave Hansen <dave@sr71.net> - 2016-01-07 01:10 +0100
  [PATCH 09/31] x86, pkeys: store protection in high VMA flags Dave Hansen <dave@sr71.net> - 2016-01-07 01:10 +0100
  [PATCH 16/31] x86, mm: simplify get_user_pages() PTE bit handling Dave Hansen <dave@sr71.net> - 2016-01-07 01:10 +0100
  [PATCH 27/31] x86: separate out LDT init from context init Dave Hansen <dave@sr71.net> - 2016-01-07 01:10 +0100
  [PATCH 14/31] x86, pkeys: add functions to fetch PKRU Dave Hansen <dave@sr71.net> - 2016-01-07 01:10 +0100
    Re: [PATCH 14/31] x86, pkeys: add functions to fetch PKRU Thomas Gleixner <tglx@linutronix.de> - 2016-01-08 20:40 +0100
  [PATCH 31/31] x86, pkeys: execute-only support Dave Hansen <dave@sr71.net> - 2016-01-07 01:10 +0100
    Re: [PATCH 31/31] x86, pkeys: execute-only support Kees Cook <keescook@google.com> - 2016-01-07 22:10 +0100
      Re: [PATCH 31/31] x86, pkeys: execute-only support Dave Hansen <dave@sr71.net> - 2016-01-07 23:30 +0100
    Re: [PATCH 31/31] x86, pkeys: execute-only support Andy Lutomirski <luto@amacapital.net> - 2016-01-07 22:20 +0100
      Re: [PATCH 31/31] x86, pkeys: execute-only support Dave Hansen <dave@sr71.net> - 2016-01-07 23:20 +0100
        Re: [PATCH 31/31] x86, pkeys: execute-only support Andy Lutomirski <luto@amacapital.net> - 2016-01-07 23:50 +0100
    Re: [PATCH 31/31] x86, pkeys: execute-only support Thomas Gleixner <tglx@linutronix.de> - 2016-01-08 21:00 +0100
  [PATCH 24/31] x86, pkeys: actually enable Memory Protection Keys in CPU Dave Hansen <dave@sr71.net> - 2016-01-07 01:10 +0100
  [PATCH 30/31] x86, pkeys: create an x86 arch_calc_vm_prot_bits() for VMA flags Dave Hansen <dave@sr71.net> - 2016-01-07 01:10 +0100
  [PATCH 18/31] mm: add gup flag to indicate "foreign" mm access Dave Hansen <dave@sr71.net> - 2016-01-07 01:10 +0100
  [PATCH 26/31] x86, pkeys: add arch_validate_pkey() Dave Hansen <dave@sr71.net> - 2016-01-07 01:10 +0100
    Re: [PATCH 26/31] x86, pkeys: add arch_validate_pkey() Thomas Gleixner <tglx@linutronix.de> - 2016-01-08 20:40 +0100
  [PATCH 08/31] x86, pkeys: new page fault error code bit: PF_PK Dave Hansen <dave@sr71.net> - 2016-01-07 01:10 +0100
  [PATCH 13/31] x86, pkeys: fill in pkey field in siginfo Dave Hansen <dave@sr71.net> - 2016-01-07 01:10 +0100
  [PATCH 12/31] signals, pkeys: notify userspace about protection key faults Dave Hansen <dave@sr71.net> - 2016-01-07 01:10 +0100
  [PATCH 23/31] x86, pkeys: add Kconfig prompt to existing config option Dave Hansen <dave@sr71.net> - 2016-01-07 01:10 +0100
  [PATCH 15/31] mm: factor out VMA fault permission checking Dave Hansen <dave@sr71.net> - 2016-01-07 01:10 +0100
  [PATCH 04/31] x86, pkeys: cpuid bit definition Dave Hansen <dave@sr71.net> - 2016-01-07 01:10 +0100
  [PATCH 20/31] x86, pkeys: differentiate instruction fetches Dave Hansen <dave@sr71.net> - 2016-01-07 01:10 +0100
  [PATCH 25/31] mm, multi-arch: pass a protection key in to calc_vm_flag_bits() Dave Hansen <dave@sr71.net> - 2016-01-07 01:10 +0100
  [PATCH 02/31] x86, fpu: add placeholder for Processor Trace XSAVE state Dave Hansen <dave@sr71.net> - 2016-01-07 01:20 +0100

csiph-web