Received: by 2002:a05:6a10:1d13:0:0:0:0 with SMTP id pp19csp1523864pxb; Tue, 17 Aug 2021 14:05:39 -0700 (PDT) X-Google-Smtp-Source: ABdhPJwTNe6JW5pjiI9TgP3RCGyPizkwadwG+8QJ+ooHfq8yRagrnGKV+uvM2OKZuldWWz9xUI5B X-Received: by 2002:a05:6402:1690:: with SMTP id a16mr6096176edv.370.1629234339373; Tue, 17 Aug 2021 14:05:39 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1629234339; cv=none; d=google.com; s=arc-20160816; b=FStolWrDO4P7EQa2IA5rM3MtlJwZpdRBS5bERNtnJXV2QJ5CRXB7w4gLbatVggrUjY CvHknAG1UlctxbCGmB0kasIFXpjpgGloe4Zk7rvlgyPFQ/caHGYRvphaJybHZdkdGYVE W8w36Bqa+KwXBtK27JPm+RvuZfstj99B0o5gE7Bl4L3CYoKls6r8PhUcG53qjBxrc728 Njw2/nq9SQxJmAxgpGmAe4PYPNge1Z2jCSwOXPoSjqdItF3eOVLrnUltmHxmHHWBUQjl chgxElbFsUCjZ3u/brnzyD7wRqgQ1IW0BR+tG1i4/E7lhGuJWMssXb0pGXuJZD989OP5 MmDQ== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:in-reply-to:content-disposition:mime-version :references:message-id:subject:cc:to:from:date:dkim-signature; bh=mXsfggRjwQDlm0H7Ke4Yg4s+PjvD0gM8YpelP0TsXHU=; b=jcAYO0Jq0LKlLyi0gAKfbI0+UQLw7ZEPirTwsclYiIFk38WHjdVFDzPx+Z3nnZrMW7 vVDEvMapUJE6LIrrkfotxwrb66JelWMTgDgcIJOmm4grXgLdfXw51fAMah4VcBLeo+jU FcuByaIqhsPaDyaVwxWflBYFqMsov1204zLvLZNZIGnHTalb7UW+iyqle6++iGfft8YI e0yHDbD6f3h2MHY9+1CaEZNn+SJceHC59I9UM/Ij+vTXpc+7UyLcNbebJRnyT1NmN4w+ XHCKwxIF5ituuqY0F98ixVcitjUlPgnAr2+JuyNkUm543qu5FV1ScYte8ggLQ2dHlF/P 1/qQ== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@alien8.de header.s=dkim header.b=h50TDWS4; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=alien8.de Return-Path: Received: from vger.kernel.org (vger.kernel.org. [23.128.96.18]) by mx.google.com with ESMTP id m17si3365258edv.35.2021.08.17.14.05.07; Tue, 17 Aug 2021 14:05:39 -0700 (PDT) Received-SPF: pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) client-ip=23.128.96.18; Authentication-Results: mx.google.com; dkim=pass header.i=@alien8.de header.s=dkim header.b=h50TDWS4; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=alien8.de Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S234106AbhHQVBU (ORCPT + 99 others); Tue, 17 Aug 2021 17:01:20 -0400 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:33970 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S229531AbhHQVBT (ORCPT ); Tue, 17 Aug 2021 17:01:19 -0400 Received: from mail.skyhub.de (mail.skyhub.de [IPv6:2a01:4f8:190:11c2::b:1457]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id D6F79C061764; Tue, 17 Aug 2021 14:00:45 -0700 (PDT) Received: from zn.tnic (p200300ec2f1175002d6ed1db7aad8219.dip0.t-ipconnect.de [IPv6:2003:ec:2f11:7500:2d6e:d1db:7aad:8219]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mail.skyhub.de (SuperMail on ZX Spectrum 128k) with ESMTPSA id ECBC61EC054F; Tue, 17 Aug 2021 23:00:39 +0200 (CEST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=alien8.de; s=dkim; t=1629234040; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:in-reply-to:in-reply-to: references:references; bh=mXsfggRjwQDlm0H7Ke4Yg4s+PjvD0gM8YpelP0TsXHU=; b=h50TDWS4H9GdDodATzIk47AkyXvA4xxH+tNY8zodUJbiv66vz2uFecq8W13pkePmohzcG+ 9bTxxFbcNJNR6KjEBv4mabKrZU3gRqlEIj14TxD1Hrp0arnMYTBjLNHIqwAoViz5K4MhkU 9jeBsoXMtMB5jcgWi4P1gXtqA77We3I= Date: Tue, 17 Aug 2021 23:01:18 +0200 From: Borislav Petkov To: Andy Lutomirski Cc: "luto@amacapital.net" , Yu-cheng Yu , the arch/x86 maintainers , "H. Peter Anvin" , Thomas Gleixner , Ingo Molnar , Linux Kernel Mailing List , linux-doc@vger.kernel.org, linux-mm@kvack.org, linux-arch@vger.kernel.org, Linux API , Arnd Bergmann , Balbir Singh , Cyrill Gorcunov , Dave Hansen , Eugene Syromiatnikov , Florian Weimer , "H.J. Lu" , Jann Horn , Jonathan Corbet , Kees Cook , Mike Kravetz , Nadav Amit , Oleg Nesterov , Pavel Machek , "Peter Zijlstra (Intel)" , Randy Dunlap , "Shankar, Ravi V" , Dave Martin , Weijiang Yang , Pengfei Xu , Haitao Huang , Rick P Edgecombe , "Kirill A. Shutemov" Subject: Re: [PATCH v28 09/32] x86/mm: Introduce _PAGE_COW Message-ID: References: <1A27F5DF-477B-45B7-AD33-CC68D9B7CB89@amacapital.net> <490345b6-3e3d-4692-8162-85dcb71434c9@www.fastmail.com> MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Disposition: inline In-Reply-To: <490345b6-3e3d-4692-8162-85dcb71434c9@www.fastmail.com> Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org On Tue, Aug 17, 2021 at 01:51:52PM -0700, Andy Lutomirski wrote: > WRSS can be used from user mode depending on the configuration. My point being, if you're going to do shadow stack management operations, you should check whether the target you're writing to is a shadow stack page. Clearly userspace can't do that but userspace will get notified of that pretty timely. > Double-you shmouble-you. You can't write it with MOV, but you can > write it from user code and from kernel code. As far as the mm is > concerned, I think it should be considered writable. Because? > Although... anyone who tries to copy_to_user() it is going to be a bit > surprised. Hmm. Ok, so you see the confusion. In any case, I don't think you can simply look at a shadow stack page as simple writable page. There are cases where it is going to be fun. So why are we even saying that a shadow stack page is writable? Why can't we simply say that a shadow stack page is, well, something special? -- Regards/Gruss, Boris. https://people.kernel.org/tglx/notes-about-netiquette