| From foo@baz Mon Jul 23 10:04:05 CEST 2018 |
| From: "Srivatsa S. Bhat" <srivatsa@csail.mit.edu> |
| Date: Sat, 14 Jul 2018 02:37:05 -0700 |
| Subject: seccomp: Move speculation migitation control to arch code |
| To: gregkh@linuxfoundation.org, stable@vger.kernel.org |
| Cc: Thomas Gleixner <tglx@linutronix.de>, David Woodhouse <dwmw@amazon.co.uk>, "Matt Helsley \(VMware\)" <matt.helsley@gmail.com>, Alexey Makhalov <amakhalov@vmware.com>, Bo Gan <ganb@vmware.com>, matt.helsley@gmail.com, rostedt@goodmis.org, amakhalov@vmware.com, ganb@vmware.com, srivatsa@csail.mit.edu, srivatsab@vmware.com |
| Message-ID: <153156102504.10043.16825319447157513625.stgit@srivatsa-ubuntu> |
| |
| From: Thomas Gleixner <tglx@linutronix.de> |
| |
| commit 8bf37d8c067bb7eb8e7c381bdadf9bd89182b6bc upstream |
| |
| The migitation control is simpler to implement in architecture code as it |
| avoids the extra function call to check the mode. Aside of that having an |
| explicit seccomp enabled mode in the architecture mitigations would require |
| even more workarounds. |
| |
| Move it into architecture code and provide a weak function in the seccomp |
| code. Remove the 'which' argument as this allows the architecture to decide |
| which mitigations are relevant for seccomp. |
| |
| Signed-off-by: Thomas Gleixner <tglx@linutronix.de> |
| Signed-off-by: David Woodhouse <dwmw@amazon.co.uk> |
| Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org> |
| Signed-off-by: Srivatsa S. Bhat <srivatsa@csail.mit.edu> |
| Reviewed-by: Matt Helsley (VMware) <matt.helsley@gmail.com> |
| Reviewed-by: Alexey Makhalov <amakhalov@vmware.com> |
| Reviewed-by: Bo Gan <ganb@vmware.com> |
| Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org> |
| --- |
| |
| arch/x86/kernel/cpu/bugs.c | 29 ++++++++++++++++++----------- |
| include/linux/nospec.h | 2 ++ |
| kernel/seccomp.c | 15 ++------------- |
| 3 files changed, 22 insertions(+), 24 deletions(-) |
| |
| --- a/arch/x86/kernel/cpu/bugs.c |
| +++ b/arch/x86/kernel/cpu/bugs.c |
| @@ -567,6 +567,24 @@ static int ssb_prctl_set(struct task_str |
| return 0; |
| } |
| |
| +int arch_prctl_spec_ctrl_set(struct task_struct *task, unsigned long which, |
| + unsigned long ctrl) |
| +{ |
| + switch (which) { |
| + case PR_SPEC_STORE_BYPASS: |
| + return ssb_prctl_set(task, ctrl); |
| + default: |
| + return -ENODEV; |
| + } |
| +} |
| + |
| +#ifdef CONFIG_SECCOMP |
| +void arch_seccomp_spec_mitigate(struct task_struct *task) |
| +{ |
| + ssb_prctl_set(task, PR_SPEC_FORCE_DISABLE); |
| +} |
| +#endif |
| + |
| static int ssb_prctl_get(struct task_struct *task) |
| { |
| switch (ssb_mode) { |
| @@ -585,17 +603,6 @@ static int ssb_prctl_get(struct task_str |
| } |
| } |
| |
| -int arch_prctl_spec_ctrl_set(struct task_struct *task, unsigned long which, |
| - unsigned long ctrl) |
| -{ |
| - switch (which) { |
| - case PR_SPEC_STORE_BYPASS: |
| - return ssb_prctl_set(task, ctrl); |
| - default: |
| - return -ENODEV; |
| - } |
| -} |
| - |
| int arch_prctl_spec_ctrl_get(struct task_struct *task, unsigned long which) |
| { |
| switch (which) { |
| --- a/include/linux/nospec.h |
| +++ b/include/linux/nospec.h |
| @@ -62,5 +62,7 @@ static inline unsigned long array_index_ |
| int arch_prctl_spec_ctrl_get(struct task_struct *task, unsigned long which); |
| int arch_prctl_spec_ctrl_set(struct task_struct *task, unsigned long which, |
| unsigned long ctrl); |
| +/* Speculation control for seccomp enforced mitigation */ |
| +void arch_seccomp_spec_mitigate(struct task_struct *task); |
| |
| #endif /* _LINUX_NOSPEC_H */ |
| --- a/kernel/seccomp.c |
| +++ b/kernel/seccomp.c |
| @@ -216,18 +216,7 @@ static inline bool seccomp_may_assign_mo |
| return true; |
| } |
| |
| -/* |
| - * If a given speculation mitigation is opt-in (prctl()-controlled), |
| - * select it, by disabling speculation (enabling mitigation). |
| - */ |
| -static inline void spec_mitigate(struct task_struct *task, |
| - unsigned long which) |
| -{ |
| - int state = arch_prctl_spec_ctrl_get(task, which); |
| - |
| - if (state > 0 && (state & PR_SPEC_PRCTL)) |
| - arch_prctl_spec_ctrl_set(task, which, PR_SPEC_FORCE_DISABLE); |
| -} |
| +void __weak arch_seccomp_spec_mitigate(struct task_struct *task) { } |
| |
| static inline void seccomp_assign_mode(struct task_struct *task, |
| unsigned long seccomp_mode, |
| @@ -243,7 +232,7 @@ static inline void seccomp_assign_mode(s |
| smp_mb__before_atomic(); |
| /* Assume default seccomp processes want spec flaw mitigation. */ |
| if ((flags & SECCOMP_FILTER_FLAG_SPEC_ALLOW) == 0) |
| - spec_mitigate(task, PR_SPEC_STORE_BYPASS); |
| + arch_seccomp_spec_mitigate(task); |
| set_tsk_thread_flag(task, TIF_SECCOMP); |
| } |
| |