Received: by 2002:a6b:500f:0:0:0:0:0 with SMTP id e15csp659779iob; Thu, 12 May 2022 01:42:32 -0700 (PDT) X-Google-Smtp-Source: ABdhPJwrh5MbSoxqPm5mmlJKn7rjZ/uClX/XJ5w4vloD/pEW9G6i8jhGavcEKptryrx6x53wHFRt X-Received: by 2002:a17:902:cec9:b0:15f:3f5d:882a with SMTP id d9-20020a170902cec900b0015f3f5d882amr3770555plg.132.1652344951843; Thu, 12 May 2022 01:42:31 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1652344951; cv=none; d=google.com; s=arc-20160816; b=k6wqx0UsrJz5ft4epU+CJiRGNKLWDl7xcNQK63uTZhjN0QQgZ+es0jqNPVvqj/uYQR L618Jc/NbJzgkrbLHYeO78BpnzH3myJv/zA6IFc/OAu/By3gHjYCnTFFAGNNKeVxKbO4 TxpsymZdLn9ncB4rTuEFPmiWQ+GlUiG7AzILQokw2f6F+HtTq32stY7ETe5cUOFsoWgO NCtNG4luuFRulZCyzmGY0mMaIHNBp/EQ5HIk6xwehswfCaI5fSNi3tr2AlTOV7uIDq8M wM48nj4Nm3ivam6dXxT2sfitAQR8XDG2TnfIPTl7B5N1tdckdbr7W/fTxiq61cvjYCyt 2N5Q== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:subject:cc:to:from:date:references:in-reply-to :message-id:mime-version:user-agent:dkim-signature; bh=d2Joc/3aGPkvvgHuhLXy7cBdLjJTkkwsIqBvQ40pkXI=; b=f7IiiQXYtXvQVKTxcofc9QFExCHM53bDeVUJptGIF7hkYoTBBuJEGLufqMVYWREFPI QkYp/IdXt5kJgwApj9xqVwWQBR+1yH7pGCm3jgmv2AajEMH8V3YIlPpp4ljnxe1hLFhn BHcctQY0cXAvWrw6rS6P5Dt3wnWleR9imcdsbWxRp3tWGcOX/hbqiws0IliURH2Oym+p ovLXUTFLP1hizyYll1xBYJI4rvD507yRq4KlxlwvfyjykTFdG+XU53wKtq5rkyoIrrji WiwhlMherIhFisLZ2pOqjYT8SakgKH1FzGeDs+54ZBZd6z0SyG7q6p17P2joQAYbVnT/ yFhg== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@kernel.org header.s=k20201202 header.b=APM+OUux; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=kernel.org Return-Path: Received: from out1.vger.email (out1.vger.email. [2620:137:e000::1:20]) by mx.google.com with ESMTP id y70-20020a638a49000000b003c6a5d55413si2602252pgd.114.2022.05.12.01.42.19; Thu, 12 May 2022 01:42:31 -0700 (PDT) Received-SPF: pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) client-ip=2620:137:e000::1:20; Authentication-Results: mx.google.com; dkim=pass header.i=@kernel.org header.s=k20201202 header.b=APM+OUux; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=kernel.org Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1346555AbiEKTDl (ORCPT + 99 others); Wed, 11 May 2022 15:03:41 -0400 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:54982 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S241347AbiEKTDk (ORCPT ); Wed, 11 May 2022 15:03:40 -0400 Received: from ams.source.kernel.org (ams.source.kernel.org [IPv6:2604:1380:4601:e00::1]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id 0B11861296 for ; Wed, 11 May 2022 12:03:39 -0700 (PDT) Received: from smtp.kernel.org (relay.kernel.org [52.25.139.140]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ams.source.kernel.org (Postfix) with ESMTPS id B8FEDB8260A for ; Wed, 11 May 2022 19:03:37 +0000 (UTC) Received: by smtp.kernel.org (Postfix) with ESMTPSA id 4C577C340EE for ; Wed, 11 May 2022 19:03:36 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=k20201202; t=1652295816; bh=sgS8I586wmxDsWEfk8EYenY4Nf+IiynsiclSqvw9c1I=; h=In-Reply-To:References:Date:From:To:Cc:Subject:From; b=APM+OUuxz0Q71LKdL40gVite+fbwNKwg6+VMNJLoq/G6tlH1XJbvRYImhu+2++Umi JsOeeZFuukrZVpnHB7HXoe1NrSLDWxH/RLqopHOMjeeVHSZpLUiMgjWNb7LW75o6BX QRTx7oIxDHvPsEVw7sugtR6TtZC83Y2u/KzGScwYZBYIsXxmKIXZfPazja0bRPMhAi 3qbwb3bvfTnibHOz/Z1/VTrQnIxJRM3Yxp/zmyeqCNnwHxLjoR299kQpjQNAGf+bnB lZ9NfJuKXaAKp4FIomshX2MjRHBnx8ZulNzODN2Kc6jrm2882UyovgNnlC0iGZYCi7 gCph4X0krdV0A== Received: from compute2.internal (compute2.nyi.internal [10.202.2.46]) by mailauth.nyi.internal (Postfix) with ESMTP id 1D84A27C0054; Wed, 11 May 2022 15:03:35 -0400 (EDT) Received: from imap48 ([10.202.2.98]) by compute2.internal (MEProxy); Wed, 11 May 2022 15:03:35 -0400 X-ME-Sender: X-ME-Proxy-Cause: gggruggvucftvghtrhhoucdtuddrgedvfedrgeehgdduvdelucetufdoteggodetrfdotf fvucfrrhhofhhilhgvmecuhfgrshhtofgrihhlpdfqfgfvpdfurfetoffkrfgpnffqhgen uceurghilhhouhhtmecufedttdenucesvcftvggtihhpihgvnhhtshculddquddttddmne cujfgurhepofgfggfkjghffffhvfevufgtsehttdertderredtnecuhfhrohhmpedftehn ugihucfnuhhtohhmihhrshhkihdfuceolhhuthhosehkvghrnhgvlhdrohhrgheqnecugg ftrfgrthhtvghrnhepvdfhuedvtdfhudffhfekkefftefghfeltdelgeffteehueegjeff udehgfetiefhnecuvehluhhsthgvrhfuihiivgeptdenucfrrghrrghmpehmrghilhhfrh homheprghnugihodhmvghsmhhtphgruhhthhhpvghrshhonhgrlhhithihqdduudeiudek heeifedvqddvieefudeiiedtkedqlhhuthhopeepkhgvrhhnvghlrdhorhhgsehlihhnuh igrdhluhhtohdruhhs X-ME-Proxy: Received: by mailuser.nyi.internal (Postfix, from userid 501) id B961331A005D; Wed, 11 May 2022 15:03:34 -0400 (EDT) X-Mailer: MessagingEngine.com Webmail Interface User-Agent: Cyrus-JMAP/3.7.0-alpha0-591-gfe6c3a2700-fm-20220427.001-gfe6c3a27 Mime-Version: 1.0 Message-Id: <7c87b9f7-0a26-41cf-ba34-3dbd37caa2b8@www.fastmail.com> In-Reply-To: <87o803dijt.fsf@oldenburg.str.redhat.com> References: <898932fe61db6a9d61bc2458fa2f6049f1ca9f5c.1652290558.git.luto@kernel.org> <87o803dijt.fsf@oldenburg.str.redhat.com> Date: Wed, 11 May 2022 12:03:14 -0700 From: "Andy Lutomirski" To: "Florian Weimer" Cc: "the arch/x86 maintainers" , "Linux Kernel Mailing List" , "Kees Cook" Subject: Re: [PATCH] x86/vsyscall: Remove CONFIG_LEGACY_VSYSCALL_EMULATE Content-Type: text/plain X-Spam-Status: No, score=-7.7 required=5.0 tests=BAYES_00,DKIMWL_WL_HIGH, DKIM_SIGNED,DKIM_VALID,DKIM_VALID_AU,DKIM_VALID_EF,RCVD_IN_DNSWL_HI, SPF_HELO_NONE,SPF_PASS,T_SCC_BODY_TEXT_LINE autolearn=ham autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on lindbergh.monkeyblade.net Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org On Wed, May 11, 2022, at 11:35 AM, Florian Weimer wrote: > * Andy Lutomirski: > >> CONFIG_LEGACY_VSYSCALL_EMULATE is, as far as I know, only needed for the >> combined use of exotic and outdated debugging mechanisms with outdated >> binaries. At this point, no one should be using it. We would like to >> implement dynamic switching of vsyscalls, but this is much more >> complicated to support in EMULATE mode than XONLY mode. >> >> So let's force all the distros off of EMULATE mode. If anyone actually >> needs it, they can set vsyscall=emulate, and we can then get away with >> refusing to support newer security models if that option is set. >> >> Cc: x86@kernel.org >> Cc: Kees Cook >> Cc: Florian Weimer >> Signed-off-by: Andy Lutomirski > > Sounds a good idea to me. > > Acked-by: Florian Weimer > > Regarding the mechanics, is it customary to remove the actual code (the > EMULATE enum constant) in later commits? > Might be several versions later. This patch intentionally still supports booting with vsyscall=emulate.