From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org X-Spam-Level: X-Spam-Status: No, score=-8.8 required=3.0 tests=HEADER_FROM_DIFFERENT_DOMAINS, INCLUDES_PATCH,MAILING_LIST_MULTI,SIGNED_OFF_BY,SPF_PASS,URIBL_BLOCKED, USER_AGENT_GIT autolearn=ham autolearn_force=no version=3.4.0 Received: from mail.kernel.org (mail.kernel.org [198.145.29.99]) by smtp.lore.kernel.org (Postfix) with ESMTP id 2F378ECDE3B for ; Wed, 17 Oct 2018 18:33:05 +0000 (UTC) Received: from vger.kernel.org (vger.kernel.org [209.132.180.67]) by mail.kernel.org (Postfix) with ESMTP id F3E6E21476 for ; Wed, 17 Oct 2018 18:33:04 +0000 (UTC) DMARC-Filter: OpenDMARC Filter v1.3.2 mail.kernel.org F3E6E21476 Authentication-Results: mail.kernel.org; dmarc=fail (p=none dis=none) header.from=linux.intel.com Authentication-Results: mail.kernel.org; spf=none smtp.mailfrom=linux-kernel-owner@vger.kernel.org Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1728446AbeJRC36 (ORCPT ); Wed, 17 Oct 2018 22:29:58 -0400 Received: from mga12.intel.com ([192.55.52.136]:29659 "EHLO mga12.intel.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1728399AbeJRC35 (ORCPT ); Wed, 17 Oct 2018 22:29:57 -0400 X-Amp-Result: SKIPPED(no attachment in message) X-Amp-File-Uploaded: False Received: from orsmga007.jf.intel.com ([10.7.209.58]) by fmsmga106.fm.intel.com with ESMTP/TLS/DHE-RSA-AES256-GCM-SHA384; 17 Oct 2018 11:33:01 -0700 X-ExtLoop1: 1 X-IronPort-AV: E=Sophos;i="5.54,393,1534834800"; d="scan'208";a="82003926" Received: from skl-02.jf.intel.com ([10.54.74.62]) by orsmga007.jf.intel.com with ESMTP; 17 Oct 2018 11:33:01 -0700 From: Tim Chen To: Jiri Kosina , Thomas Gleixner Cc: Tim Chen , Tom Lendacky , Ingo Molnar , Peter Zijlstra , Josh Poimboeuf , Andrea Arcangeli , David Woodhouse , Andi Kleen , Dave Hansen , Casey Schaufler , Asit Mallick , Arjan van de Ven , Jon Masters , linux-kernel@vger.kernel.org, x86@kernel.org Subject: [Patch v3 12/13] x86/speculation: Protect non-dumpable processes against Spectre v2 attack Date: Wed, 17 Oct 2018 10:59:40 -0700 Message-Id: X-Mailer: git-send-email 2.9.4 In-Reply-To: References: In-Reply-To: References: Sender: linux-kernel-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org Mark the non-dumpable processes with TIF_STIBP flag so they will use STIBP and IBPB defenses against Spectre v2 attack from processes in user space. Signed-off-by: Tim Chen --- arch/x86/kernel/cpu/bugs.c | 21 +++++++++++++++++++++ 1 file changed, 21 insertions(+) diff --git a/arch/x86/kernel/cpu/bugs.c b/arch/x86/kernel/cpu/bugs.c index 1d317f2..cc77b9e 100644 --- a/arch/x86/kernel/cpu/bugs.c +++ b/arch/x86/kernel/cpu/bugs.c @@ -14,6 +14,7 @@ #include #include #include +#include #include #include @@ -773,6 +774,26 @@ int arch_prctl_spec_ctrl_set(struct task_struct *task, unsigned long which, } } +void arch_set_dumpable(struct task_struct *tsk, unsigned int value) +{ + bool update; + + if (!static_branch_unlikely(&spectre_v2_app_lite)) + return; + if (!static_cpu_has(X86_FEATURE_STIBP)) + return; + if (spectre_v2_app2app_enabled == SPECTRE_V2_APP2APP_NONE) + return; + + if (tsk->mm && value != SUID_DUMP_USER) + update = !test_and_set_tsk_thread_flag(tsk, TIF_STIBP); + else + update = test_and_clear_tsk_thread_flag(tsk, TIF_STIBP); + + if (tsk == current && update) + speculation_ctrl_update_current(); +} + #ifdef CONFIG_SECCOMP void arch_seccomp_spec_mitigate(struct task_struct *task) { -- 2.9.4