Received: by 2002:a05:6a10:16a7:0:0:0:0 with SMTP id gp39csp689976pxb; Thu, 19 Nov 2020 11:14:48 -0800 (PST) X-Google-Smtp-Source: ABdhPJwqOpCRA0kpDEv2VkNZmN3dF8fDjQ0GcrRknq8einqW9wTfyKT5AWUcmkz3IhIJrPUCuE4W X-Received: by 2002:a50:e0c9:: with SMTP id j9mr27006796edl.380.1605813288558; Thu, 19 Nov 2020 11:14:48 -0800 (PST) ARC-Seal: i=1; a=rsa-sha256; t=1605813288; cv=none; d=google.com; s=arc-20160816; b=C8H1blnuGt0cX+oE0Mz06sV6u9HbWACrkozN57KElN1XVs0RL228SEuJ6/+Etn1TE7 u6GVn8sMwLpcsiaUZyxD0huWE7cUFekDhQLbfs71p7R37CzE10gNByfcPFB2MAJ0dlDY CY5q3hsZmuuV1vyfmXw0GRZJfUNv6qPaR1aiWcmBnD1aEav99yalyD8A2uXzlhuUhZKw Emk4WkMmb7vLQ6nvNXETZrROBXJSpzGwOSl75gtvrFD3AabX3dUVKfOHhy2CbY9pTyM0 OFX0eh1MJCAmTC7ohtdevqTA+Kpzymsc0h2wDhs9z8PY7dMm6uVS01jiBXDuRSUTKG58 SyPw== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:mime-version:message-id:date:references :in-reply-to:subject:cc:to:dkim-signature:dkim-signature:from; bh=fqTlt+xmV+wxcpS5yo4wjoab1yCJzP8iG04Acn2vaKA=; b=bTJ/vtj1my+x1VRCJRk3bYx88kswpGO9qKaYMaJQ5JaOiANdvRkOcnXWlAPPMSZU1p ZxY1CoJK5cL8JsXJy08wuIPyp8KjIw7U69zy5E+dquVkE24sVahX7CIQNVQiXw2N8m5a zdQ4OFJs02cHyBuL0cWvYBVxfxHfKehUmgiYVgXPXkKn/4Xrop79XRmF6FNmYdl4cf09 By06WPQrqNSZ3XEQlBQjqF7Daz/OtB3A41C2FV4GS/PzF3Aey6ZVQfgpq6IhJdeKGpA+ H5Fp+ODrTlDcvBx4wH67VTsy44QT/PFuP/sI1QXa7TaIipNrPA2BSicruksfuFuYMnqo BJ/Q== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@linutronix.de header.s=2020 header.b="FU/TB9NK"; dkim=neutral (no key) header.i=@linutronix.de header.b=cqA167oJ; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=QUARANTINE dis=NONE) header.from=linutronix.de Return-Path: Received: from vger.kernel.org (vger.kernel.org. [23.128.96.18]) by mx.google.com with ESMTP id ot12si349642ejb.239.2020.11.19.11.14.24; Thu, 19 Nov 2020 11:14:48 -0800 (PST) Received-SPF: pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) client-ip=23.128.96.18; Authentication-Results: mx.google.com; dkim=pass header.i=@linutronix.de header.s=2020 header.b="FU/TB9NK"; dkim=neutral (no key) header.i=@linutronix.de header.b=cqA167oJ; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=QUARANTINE dis=NONE) header.from=linutronix.de Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1727658AbgKSTKt (ORCPT + 99 others); Thu, 19 Nov 2020 14:10:49 -0500 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:50978 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1727240AbgKSTKt (ORCPT ); Thu, 19 Nov 2020 14:10:49 -0500 Received: from galois.linutronix.de (Galois.linutronix.de [IPv6:2a0a:51c0:0:12e:550::1]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id E45DCC0613CF for ; Thu, 19 Nov 2020 11:10:48 -0800 (PST) From: Thomas Gleixner DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linutronix.de; s=2020; t=1605813047; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: in-reply-to:in-reply-to:references:references; bh=fqTlt+xmV+wxcpS5yo4wjoab1yCJzP8iG04Acn2vaKA=; b=FU/TB9NKttAWjhk1K07OlHEPQFhYFoPYGEZ0DUIdWthJ5rznjwFWEBmTm0IfmPzdJmG0hj eTGegEMk8exhni9N1UsGdF4oWrTgABHv8n1r00A9iRVn5UGkrzlSDRraZ4WQo0sqzpetZr NCC6B9cCNRd1vRenYoGyrO/ajGEVpc3lWMtxl6n5Iooeu8f5Mr79U76x/fdmhC9k6YqP2e iVcvbNf+7CLE8xuXHm4mX/9ymp7ipU07ju96haHsNaXmVOsCxJ0ipN9R9sHSv5eGeCaiX3 2v3Yy7vm4oA/AS+W8Sg4WDnwtmKzuU7l/a1VSN1Z/EVfgANqh2ymSopry+mRcg== DKIM-Signature: v=1; a=ed25519-sha256; c=relaxed/relaxed; d=linutronix.de; s=2020e; t=1605813047; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: in-reply-to:in-reply-to:references:references; bh=fqTlt+xmV+wxcpS5yo4wjoab1yCJzP8iG04Acn2vaKA=; b=cqA167oJl8YpjT3h2H01mJN4qfrIVA7UJcPEWlupJM+9T0y03BkbkNla3eZmyK4rxX1qmk FUoi/S1jlPi7kHBw== To: Alexandre Chartre , Andy Lutomirski Cc: Ingo Molnar , Borislav Petkov , "H. Peter Anvin" , X86 ML , Dave Hansen , Peter Zijlstra , LKML , Tom Lendacky , Joerg Roedel , Konrad Rzeszutek Wilk , jan.setjeeilers@oracle.com, Junaid Shahid , oweisse@google.com, Mike Rapoport , Alexander Graf , mgross@linux.intel.com, kuzuno@gmail.com Subject: Re: [RFC][PATCH v2 12/21] x86/pti: Use PTI stack instead of trampoline stack In-Reply-To: References: <20201116144757.1920077-1-alexandre.chartre@oracle.com> <20201116144757.1920077-13-alexandre.chartre@oracle.com> Date: Thu, 19 Nov 2020 20:10:46 +0100 Message-ID: <87ft55p3gp.fsf@nanos.tec.linutronix.de> MIME-Version: 1.0 Content-Type: text/plain Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org On Mon, Nov 16 2020 at 19:10, Alexandre Chartre wrote: > On 11/16/20 5:57 PM, Andy Lutomirski wrote: >> On Mon, Nov 16, 2020 at 6:47 AM Alexandre Chartre >> wrote: > When executing more code in the kernel, we are likely to reach a point > where we need to sleep while we are using the user page-table, so we need > to be using a per-thread stack. > >> I can't immediately evaluate how nasty the page table setup is because >> it's not in this patch. > > The page-table is the regular page-table as introduced by PTI. It is just > augmented with a few additional mapping which are in patch 11 (x86/pti: > Extend PTI user mappings). > >> But AFAICS the only thing that this enables is sleeping with user pagetables. > > That's precisely the point, it allows to sleep with the user page-table. Coming late, but this does not make any sense to me. Unless you map most of the kernel into the user page-table sleeping with the user page-table _cannot_ work. And if you do that you broke KPTI. You can neither pick arbitrary points in the C code of an exception handler to switch to the kernel mapping unless you mapped everything which might be touched before that into user space. How is that supposed to work? Thanks, tglx