Received: by 2002:a05:6a10:8c0a:0:0:0:0 with SMTP id go10csp845183pxb; Sun, 21 Feb 2021 02:18:51 -0800 (PST) X-Google-Smtp-Source: ABdhPJw4/SPoWwrONNCPIDyFMrSa3dAVhQdQdjfcyQAkXTrfZQZqAnJIR+LsLa/gT7GkLiQslrbO X-Received: by 2002:a17:906:1fd2:: with SMTP id e18mr16080680ejt.398.1613902731796; Sun, 21 Feb 2021 02:18:51 -0800 (PST) ARC-Seal: i=1; a=rsa-sha256; t=1613902731; cv=none; d=google.com; s=arc-20160816; b=S+P3OE/oTCDmXy3djTQ1tZ7M9aEWs5jpFbKb3Wi31A4cOn04ch37ugQMii81Ono1Wl qy2fPR3krvzHU89j5ZebufcoTY7Hlq+9e6vy37q/lDUaxEiJ1QC4brjE5W32mJ5KGrxF gh8CiZXZ3lIBZttJf2/ujbOGav5gffFZdW9lTS+ZhQ48Skl/WIZJ+XLBvdhzesRnWwEf 3fo9eZe//au1xuxysvNDL7FzEbxROFCTaHM5ulmRxnNF4tUE6bSPRqpWc5m1RkXn34cO QqqizF0zqxEQB2ZEuqP/TMmQjXW3SmSc+G1xWh6Nj/F2QVBwEFsrqml6epUIHFtg78vY pYiw== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:sender:user-agent:in-reply-to :content-disposition:mime-version:references:message-id:subject:cc :to:from:date:dkim-signature; bh=hcq3wt5qS99lFcdtQEki70DkgteFRHHdLhomfjlqf0A=; b=kwOtBiIv2vCt+K7OwZnzMuD+u8+0nk1BNvVv/KgjWD8LRPuvqew0RfiSbfVXKNFPUe gFCSEJ/I8T5Gyi6WvTxg8/IKe8gxqfyPEHmB9f38RfsUyGDKDmm29tRmaVg4+gbt3i+X pCMemaSNduhxSUv6wFirwZRijilu+UsOJGpeta7gMKdmPTyNW8M6s8lyk49FIkKNkecb qs5KhwX8KLb02e47lqtKQgwsC9pEpb3t8suZkH/Q5JeQIogtNvAS9z+tqX4coqyyYx7A mPYzYuWJF/vBnmhnZJnHSSU06/WgDGFIAk63xy5cFblhS745B/MLgHk4Eu25feljik5o hOjg== ARC-Authentication-Results: i=1; mx.google.com; dkim=fail (test mode) header.i=@armlinux.org.uk header.s=pandora-2019 header.b=d9BmVzeM; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=armlinux.org.uk Return-Path: Received: from vger.kernel.org (vger.kernel.org. [23.128.96.18]) by mx.google.com with ESMTP id gu21si9325495ejb.587.2021.02.21.02.18.28; Sun, 21 Feb 2021 02:18:51 -0800 (PST) Received-SPF: pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) client-ip=23.128.96.18; Authentication-Results: mx.google.com; dkim=fail (test mode) header.i=@armlinux.org.uk header.s=pandora-2019 header.b=d9BmVzeM; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=armlinux.org.uk Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S229886AbhBUKOX (ORCPT + 99 others); Sun, 21 Feb 2021 05:14:23 -0500 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:36554 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S229502AbhBUKOW (ORCPT ); Sun, 21 Feb 2021 05:14:22 -0500 Received: from pandora.armlinux.org.uk (pandora.armlinux.org.uk [IPv6:2001:4d48:ad52:32c8:5054:ff:fe00:142]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id 54D61C061574; Sun, 21 Feb 2021 02:13:41 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=armlinux.org.uk; s=pandora-2019; h=Sender:In-Reply-To:Content-Type: MIME-Version:References:Message-ID:Subject:Cc:To:From:Date:Reply-To: Content-Transfer-Encoding:Content-ID:Content-Description:Resent-Date: Resent-From:Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:List-Id: List-Help:List-Unsubscribe:List-Subscribe:List-Post:List-Owner:List-Archive; bh=hcq3wt5qS99lFcdtQEki70DkgteFRHHdLhomfjlqf0A=; b=d9BmVzeMt89rCXwVLeKlwPtHG 2BNk+iWh/L0CsP42TqedSeGrmfDsxu4ckY9qOc6ml4YSXe7ocS2VmYqTdpsflYZ5KXY61rBG+Rd3C ak55BBcZmcE3iw7hxjb6nDM/coJQH9po0P6r+Vq70oEVXerNc+lLm2VWZ4J6ijxQddMUw7x2oycoW ushzuWhMycc9J5pOfsJXQSIBZHmkGfB70a2jKKEZSQaDdtUJlvxCPR+pQ6t8neNP+u62ehJLQW2qa dPt5YWVNsfvbKX0YaqpEI7RhM+jpVkWItrx1qgHUKOzxrfQuCkUBUXwO8GMmoFhCGDUwtK8FMk8wZ Av6+zio3g==; Received: from shell.armlinux.org.uk ([fd8f:7570:feb6:1:5054:ff:fe00:4ec]:46232) by pandora.armlinux.org.uk with esmtpsa (TLS1.3:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.92) (envelope-from ) id 1lDljt-0005aH-Cr; Sun, 21 Feb 2021 10:13:21 +0000 Received: from linux by shell.armlinux.org.uk with local (Exim 4.92) (envelope-from ) id 1lDljp-00012f-NP; Sun, 21 Feb 2021 10:13:17 +0000 Date: Sun, 21 Feb 2021 10:13:17 +0000 From: Russell King - ARM Linux admin To: Jian Cai Cc: Mark Rutland , Catalin Marinas , Linus Walleij , James Morris , manojgupta@google.com, Will Deacon , Ingo Molnar , Marc Zyngier , Masahiro Yamada , Ard Biesheuvel , clang-built-linux@googlegroups.com, llozano@google.com, David Brazdil , "Serge E. Hallyn" , Kees Cook , Arnd Bergmann , Nathan Chancellor , linux-arm-kernel@lists.infradead.org, ndesaulniers@google.com, linux-kernel@vger.kernel.org, linux-security-module@vger.kernel.org, David Laight , James Morse , Andrew Morton , Andreas =?iso-8859-1?Q?F=E4rber?= , Mike Rapoport Subject: Re: [PATCH v4] ARM: Implement SLS mitigation Message-ID: <20210221101317.GN1463@shell.armlinux.org.uk> References: <20210219201852.3213914-1-jiancai@google.com> <20210219230841.875875-1-jiancai@google.com> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <20210219230841.875875-1-jiancai@google.com> User-Agent: Mutt/1.10.1 (2018-07-13) Sender: Russell King - ARM Linux admin Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org On Fri, Feb 19, 2021 at 03:08:13PM -0800, Jian Cai wrote: > diff --git a/security/Kconfig.hardening b/security/Kconfig.hardening > index 269967c4fc1b..146b75a79d9e 100644 > --- a/security/Kconfig.hardening > +++ b/security/Kconfig.hardening > @@ -121,6 +121,16 @@ choice > > endchoice > > +config HARDEN_SLS_ALL > + bool "enable SLS vulnerability hardening" > + default n Please get rid of this useless "default n" > + depends on $(cc-option,-mharden-sls=all) > + help > + Enables straight-line speculation vulnerability hardening on ARM and ARM64 > + architectures. It inserts speculation barrier sequences (SB or DSB+ISB > + depending on the target architecture) after RET and BR, and replacing > + BLR with BL+BR sequence. Given that this is in an architecture independent Kconfig file, and it detects support in CC for this feature, why should this help text be written to be specific to a couple of architectures? Will this feature only ever be available on these two architectures? What if someone adds support for another architecture? -- RMK's Patch system: https://www.armlinux.org.uk/developer/patches/ FTTP is here! 40Mbps down 10Mbps up. Decent connectivity at last!