Received: by 2002:ac0:aa62:0:0:0:0:0 with SMTP id w31-v6csp958274ima; Wed, 24 Oct 2018 11:54:04 -0700 (PDT) X-Google-Smtp-Source: AJdET5dsdBPHURhDyjaUsp+w+oNXmHU/L2CNNPIvbFqO9kuER5SHdNPB5UQBABGjequeSghhJTso X-Received: by 2002:aa7:8001:: with SMTP id j1-v6mr3684190pfi.73.1540407244228; Wed, 24 Oct 2018 11:54:04 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1540407244; cv=none; d=google.com; s=arc-20160816; b=D4TR1zcmL4QSB0b/7yaXM+X7yTuctVQ2b+Tl/5XqCjoc2CsZGyAFFHTVCwirTRViTr X5bqIFRE4Gf34eCnhzS8D1NvrytdVT1/gXOvh2BesxmxzesgNKiW+yFCyfs1az3UNlcl tLvdCdONWJMSmqDATeNpBJWK3V9vIxixg4a4ow/BtC3baQ5aqhC6ZvmW8H/gjZNgUqqM SiJZp8Okrh9GWc+17Eb9hGk6hJGjGySFN72niskpi/i5q5+vYkg4P2LNC95nqxQ4J9ti uOSr6okm8lQew3EnWQcU7W0jEXeSNFaCoh4zTvY5kuMfzUhJNFukScHKrjUrphx/8PvI YNqg== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:sender:cc:to:subject:message-id:date:from :in-reply-to:references:mime-version:dkim-signature; bh=JnxN9KLD+L0YsrwS9rj/RS3S6ncHmxTuBWB8doJaFwU=; b=hraC29eeFKZXxd1nE458/2BvmbVYctRY4nxayWs2VZOgqQ5wktwN7PHdm5TNxrv033 snV8x4cpXuALVknzhfcJz6wffegPCqtV8Znh8fZkY5P1dkVL6jrNXZuCE9G4qvgqsfLY /KA/90eLQn50fDNFNiDaggNLQrKZYKtzQslNCdBWpFBVRwRT71F2qD5w8plEZW3EK1gT JTIS8by7iVHQIcmHBBabGFLKbJ8pKn4it3JmQUMUKERjp03X0q0BpY6pOWWEqoRy9Ilm QF1ZGimb6aTxuUpTGF4Hq/HpEjbD4h8k9bTDV1PnRaTG/hyCi8Dq5hgEkl2/KJ9NVGsl 7P5g== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@kernel.org header.s=default header.b=CumG42IU; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=kernel.org Return-Path: Received: from vger.kernel.org (vger.kernel.org. [209.132.180.67]) by mx.google.com with ESMTP id q9-v6si5453245pgi.162.2018.10.24.11.53.47; Wed, 24 Oct 2018 11:54:04 -0700 (PDT) Received-SPF: pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) client-ip=209.132.180.67; Authentication-Results: mx.google.com; dkim=pass header.i=@kernel.org header.s=default header.b=CumG42IU; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=kernel.org Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1727452AbeJYDVE (ORCPT + 99 others); Wed, 24 Oct 2018 23:21:04 -0400 Received: from mail.kernel.org ([198.145.29.99]:45014 "EHLO mail.kernel.org" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1727120AbeJYDVD (ORCPT ); Wed, 24 Oct 2018 23:21:03 -0400 Received: from mail-wm1-f49.google.com (mail-wm1-f49.google.com [209.85.128.49]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by mail.kernel.org (Postfix) with ESMTPSA id 5646720831 for ; Wed, 24 Oct 2018 18:51:51 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=default; t=1540407111; bh=1HfwgJIi8hw/hMiHNFzpXrgUfITmh8nfNXREaDD3U9s=; h=References:In-Reply-To:From:Date:Subject:To:Cc:From; b=CumG42IUeQYduq1dTJuRxpYleA0C8iXevSBer3q9tOjMgA+Zi0hTDZ/DWV+lKRfRZ W1aZWgCMXsgZutjS5tlEWrJEsDGqSQcSK7EDi20sv2XjoBQ8K4jnhxErdrVfVuTysF ji+rMf+IZUkmNdxhgVh2KPHabUL0NEetm7wwFwPI= Received: by mail-wm1-f49.google.com with SMTP id w186-v6so6469444wmf.0 for ; Wed, 24 Oct 2018 11:51:51 -0700 (PDT) X-Gm-Message-State: AGRZ1gL8VjHa5wKpQDMfDN6BDN9W+o+FVUUZgYl7PvV/O/MlN6Ir6rh2 CStT5LaV957CZyIiI+PJSTY763SJ2SzE7YJo0hjyOQ== X-Received: by 2002:a1c:507:: with SMTP id 7-v6mr3696432wmf.82.1540407109844; Wed, 24 Oct 2018 11:51:49 -0700 (PDT) MIME-Version: 1.0 References: <20181023184234.14025-1-chang.seok.bae@intel.com> <20181023184234.14025-3-chang.seok.bae@intel.com> In-Reply-To: <20181023184234.14025-3-chang.seok.bae@intel.com> From: Andy Lutomirski Date: Wed, 24 Oct 2018 11:51:38 -0700 X-Gmail-Original-Message-ID: Message-ID: Subject: Re: [v3 02/12] x86/fsgsbase/64: Add 'unsafe_fsgsbase' to enable CR4.FSGSBASE To: "Bae, Chang Seok" Cc: Ingo Molnar , Thomas Gleixner , Andrew Lutomirski , "H. Peter Anvin" , Andi Kleen , Dave Hansen , "Metzger, Markus T" , "Ravi V. Shankar" , LKML Content-Type: text/plain; charset="UTF-8" Sender: linux-kernel-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org On Tue, Oct 23, 2018 at 11:43 AM Chang S. Bae wrote: > > From: Andy Lutomirski > > This is temporary. It will allow the next few patches to be tested > incrementally. > > Setting unsafe_fsgsbase is a root hole. Don't do it. > > [ chang: Minor fix. Add the TAINT_INSECURE flag. ] Reviewed-by: Andy Lutomirski although reviewing code that I mostly wrote seems a bit odd...