From: Suzuki K Poulose <suzuki.poulose@arm•com>
To: Mark Brown <broonie@kernel•org>,
Catalin Marinas <catalin.marinas@arm•com>,
Will Deacon <will@kernel•org>
Cc: linux-arm-kernel@lists•infradead.org
Subject: Re: [PATCH v8 3/4] arm64: Don't use KPTI where we have E0PD
Date: Mon, 11 Nov 2019 14:36:34 +0000 [thread overview]
Message-ID: <5d846391-8d16-4b85-a83f-b48e636e2834@arm.com> (raw)
In-Reply-To: <20191108170116.32105-4-broonie@kernel.org>
On 08/11/2019 17:01, Mark Brown wrote:
> Since E0PD is intended to fulfil the same role as KPTI we don't need to
> use KPTI on CPUs where E0PD is available, we can rely on E0PD instead.
> Change the check that forces KPTI on when KASLR is enabled to check for
> E0PD before doing so, CPUs with E0PD are not expected to be affected by
> meltdown so should not need to enable KPTI for other reasons.
>
> Since E0PD is a system capability we will still enable KPTI if any of
> the CPUs in the system lacks E0PD, this will rewrite any global mappings
> that were established in systems where some but not all CPUs support
> E0PD. We may transiently have a mix of global and non-global mappings
> while booting since we use the local CPU when deciding if KPTI will be
> required prior to completing CPU enumeration but any global mappings
> will be converted to non-global ones when KPTI is applied.
>
> KPTI can still be forced on from the command line if required.
>
> Signed-off-by: Mark Brown <broonie@kernel•org>
> ---
> arch/arm64/include/asm/mmu.h | 13 +++++++++++++
> 1 file changed, 13 insertions(+)
>
> diff --git a/arch/arm64/include/asm/mmu.h b/arch/arm64/include/asm/mmu.h
> index 55e285fff262..2e2a0ade883c 100644
> --- a/arch/arm64/include/asm/mmu.h
> +++ b/arch/arm64/include/asm/mmu.h
> @@ -38,10 +38,23 @@ static inline bool arm64_kernel_unmapped_at_el0(void)
> static inline bool kaslr_requires_kpti(void)
> {
> bool tx1_bug;
> + u64 ftr;
>
> if (!IS_ENABLED(CONFIG_RANDOMIZE_BASE))
> return false;
>
> + /*
> + * E0PD does a similar job to KPTI so can be used instead
> + * where available. This will only run before the cpufeature
s/This will only run/This will run/ ?
> + * code has usefully run and we eventually check on all CPUs so
> + * we can and must check locally.
> + */
Otherwise looks fine to me:
Reviewed-by: Suzuki K Poulose <suzuki.poulose@arm•com>
_______________________________________________
linux-arm-kernel mailing list
linux-arm-kernel@lists•infradead.org
http://lists.infradead.org/mailman/listinfo/linux-arm-kernel
next prev parent reply other threads:[~2019-11-11 14:36 UTC|newest]
Thread overview: 12+ messages / expand[flat|nested] mbox.gz Atom feed top
2019-11-08 17:01 [PATCH v8 0/4] E0PD support Mark Brown
2019-11-08 17:01 ` [PATCH v8 1/4] arm64: Add initial support for E0PD Mark Brown
2019-11-11 14:22 ` Suzuki K Poulose
2019-11-11 17:35 ` Mark Brown
2019-11-08 17:01 ` [PATCH v8 2/4] arm64: Factor out checks for KASLR in KPTI code into separate function Mark Brown
2019-11-11 14:31 ` Suzuki K Poulose
2019-11-08 17:01 ` [PATCH v8 3/4] arm64: Don't use KPTI where we have E0PD Mark Brown
2019-11-11 14:36 ` Suzuki K Poulose [this message]
2019-11-11 16:36 ` Mark Brown
2019-11-11 17:36 ` Suzuki K Poulose
2019-11-08 17:01 ` [PATCH v8 4/4] arm64: Use a variable to store non-global mappings decision Mark Brown
2019-11-11 14:39 ` Suzuki K Poulose
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=5d846391-8d16-4b85-a83f-b48e636e2834@arm.com \
--to=suzuki.poulose@arm$(echo .)com \
--cc=broonie@kernel$(echo .)org \
--cc=catalin.marinas@arm$(echo .)com \
--cc=linux-arm-kernel@lists$(echo .)infradead.org \
--cc=will@kernel$(echo .)org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox