From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from kanga.kvack.org (kanga.kvack.org [205.233.56.17]) by smtp.lore.kernel.org (Postfix) with ESMTP id 0EA50C433FE for ; Tue, 4 Oct 2022 00:09:10 +0000 (UTC) Received: by kanga.kvack.org (Postfix) id 7131C6B0072; Mon, 3 Oct 2022 20:09:09 -0400 (EDT) Received: by kanga.kvack.org (Postfix, from userid 40) id 6C2C66B0073; Mon, 3 Oct 2022 20:09:09 -0400 (EDT) X-Delivered-To: int-list-linux-mm@kvack.org Received: by kanga.kvack.org (Postfix, from userid 63042) id 5638E6B0074; Mon, 3 Oct 2022 20:09:09 -0400 (EDT) X-Delivered-To: linux-mm@kvack.org Received: from relay.hostedemail.com (smtprelay0014.hostedemail.com [216.40.44.14]) by kanga.kvack.org (Postfix) with ESMTP id 4412B6B0072 for ; Mon, 3 Oct 2022 20:09:09 -0400 (EDT) Received: from smtpin24.hostedemail.com (a10.router.float.18 [10.200.18.1]) by unirelay03.hostedemail.com (Postfix) with ESMTP id 12CE9A024D for ; Tue, 4 Oct 2022 00:09:09 +0000 (UTC) X-FDA: 79981332018.24.93BFBE1 Received: from mga12.intel.com (mga12.intel.com [192.55.52.136]) by imf03.hostedemail.com (Postfix) with ESMTP id 311D020010 for ; Tue, 4 Oct 2022 00:09:07 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=intel.com; i=@intel.com; q=dns/txt; s=Intel; t=1664842148; x=1696378148; h=message-id:date:mime-version:subject:to:cc:references: from:in-reply-to:content-transfer-encoding; bh=aa9xL1h4AcH+tfPWyZLVKtFOv8x6EYzjVZIOkGJl5EU=; b=RLn3wW4m3ZkN2y4/Z1w4jTq3jT38oC897MjaUx+gI2NfV1UWtsqVLK9t 9jHc5XT7CPJq2keu43EMfsqh/pu90JM5kxJdwc7siJCOws6SEd+qSQuws /5VRHbWym3oIDK4PXp2BCVs5+HJlrdRZZpP4m9c/ib0VMRK7DrdwdvvOf FKCLi/ljx8OebyV54mDIiyikH1pYupCF+cgxx35UB9t30O2SHiGLU/qer r8CZKXcUu/5dPYyETs5GPUMMBasHTr3PdV6Mp/N1axfGNCEXNNlLyMGPY izUbOAij9lEbpLMqY6j8EY2CBUDoFHjexKrkOZSsPkPqxb1SPHpArLbz3 Q==; X-IronPort-AV: E=McAfee;i="6500,9779,10489"; a="282503061" X-IronPort-AV: E=Sophos;i="5.93,366,1654585200"; d="scan'208";a="282503061" Received: from fmsmga005.fm.intel.com ([10.253.24.32]) by fmsmga106.fm.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 03 Oct 2022 17:09:06 -0700 X-IronPort-AV: E=McAfee;i="6500,9779,10489"; a="952574919" X-IronPort-AV: E=Sophos;i="5.93,366,1654585200"; d="scan'208";a="952574919" Received: from akashred-mobl.amr.corp.intel.com (HELO [10.212.139.217]) ([10.212.139.217]) by fmsmga005-auth.fm.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 03 Oct 2022 17:09:04 -0700 Message-ID: <559f937f-cab4-d408-6d95-fc85b4809aa9@intel.com> Date: Mon, 3 Oct 2022 17:09:04 -0700 MIME-Version: 1.0 User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:91.0) Gecko/20100101 Thunderbird/91.11.0 Subject: Re: [PATCH v2 33/39] x86/cpufeatures: Limit shadow stack to Intel CPUs Content-Language: en-US To: Kees Cook , Rick Edgecombe Cc: x86@kernel.org, "H . Peter Anvin" , Thomas Gleixner , Ingo Molnar , linux-kernel@vger.kernel.org, linux-doc@vger.kernel.org, linux-mm@kvack.org, linux-arch@vger.kernel.org, linux-api@vger.kernel.org, Arnd Bergmann , Andy Lutomirski , Balbir Singh , Borislav Petkov , Cyrill Gorcunov , Dave Hansen , Eugene Syromiatnikov , Florian Weimer , "H . J . Lu" , Jann Horn , Jonathan Corbet , Mike Kravetz , Nadav Amit , Oleg Nesterov , Pavel Machek , Peter Zijlstra , Randy Dunlap , "Ravi V . Shankar" , Weijiang Yang , "Kirill A . Shutemov" , joao.moreira@intel.com, John Allen , kcc@google.com, eranian@google.com, rppt@kernel.org, jamorris@linux.microsoft.com, dethoma@microsoft.com, Tom Lendacky , "Moger, Babu" References: <20220929222936.14584-1-rick.p.edgecombe@intel.com> <20220929222936.14584-34-rick.p.edgecombe@intel.com> <202210031656.23FAA3195@keescook> From: Dave Hansen In-Reply-To: <202210031656.23FAA3195@keescook> Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit ARC-Seal: i=1; s=arc-20220608; d=hostedemail.com; t=1664842148; a=rsa-sha256; cv=none; b=OVWbpIqsrMTXVuwpNsPnsG0WenqpKZQoiizg2x1Xi32tvrLriYwqgS7RSsHBSmvyzxtGl2 m3Ymgqm2gNtuLHjMGdgNFFvliexmhvAbMerAf/80DYRB15SVnPo8ZPwtz0InMIfQNhX4dL Ccu0+tRDAuASRfyJHqFvXm/PtfhrdXE= ARC-Authentication-Results: i=1; imf03.hostedemail.com; dkim=none ("invalid DKIM record") header.d=intel.com header.s=Intel header.b=RLn3wW4m; spf=pass (imf03.hostedemail.com: domain of dave.hansen@intel.com designates 192.55.52.136 as permitted sender) smtp.mailfrom=dave.hansen@intel.com; dmarc=pass (policy=none) header.from=intel.com ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=hostedemail.com; s=arc-20220608; t=1664842148; h=from:from:sender:reply-to:subject:subject:date:date: message-id:message-id:to:to:cc:cc:mime-version:mime-version: content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references:dkim-signature; bh=uSH1daFsOs14tusWG9pnPbKxIDRxndKH6Bvr06js558=; b=byqQuSwjzSIfOOobXw3Uu1eodsMaOgPDIemC6bd2ZlMUG8vJo3uBdTXih0zJDwkElFP6at 1CEhlhEit37yalzy1cbyU7QXCiufTg563tEs4bwBA8yun5rq0HYtiaHTH3X7uk7BrAlIXp n/wyY73tt83jtsrZS2FNdni5Rd2cQ9o= X-Rspamd-Server: rspam08 X-Rspam-User: X-Rspamd-Queue-Id: 311D020010 Authentication-Results: imf03.hostedemail.com; dkim=none ("invalid DKIM record") header.d=intel.com header.s=Intel header.b=RLn3wW4m; spf=pass (imf03.hostedemail.com: domain of dave.hansen@intel.com designates 192.55.52.136 as permitted sender) smtp.mailfrom=dave.hansen@intel.com; dmarc=pass (policy=none) header.from=intel.com X-Stat-Signature: xkux17bskpqnt77c9uz36argtds3dku3 X-HE-Tag: 1664842147-41332 X-Bogosity: Ham, tests=bogofilter, spamicity=0.000000, version=1.2.4 Sender: owner-linux-mm@kvack.org Precedence: bulk X-Loop: owner-majordomo@kvack.org List-ID: On 10/3/22 16:57, Kees Cook wrote: > On Thu, Sep 29, 2022 at 03:29:30PM -0700, Rick Edgecombe wrote: >> Shadow stack is supported on newer AMD processors, but the kernel >> implementation has not been tested on them. Prevent basic issues from >> showing up for normal users by disabling shadow stack on all CPUs except >> Intel until it has been tested. At which point the limitation should be >> removed. >> >> Signed-off-by: Rick Edgecombe > So running the selftests on an AMD system is sufficient to drop this > patch? Yes, that's enough. I _thought_ the AMD folks provided some tested-by's at some point in the past. But, maybe I'm confusing this for one of the other shared features. Either way, I'm sure no tested-by's were dropped on purpose. I'm sure Rick is eager to trim down his series and this would be a great patch to drop. Does anyone want to make that easy for Rick?