lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  PHC 
Open Source and information security mailing list archives
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Date:   Thu, 23 Nov 2017 19:09:53 +0100
From:   Borislav Petkov <>
To:     Andy Lutomirski <>
Cc:     X86 ML <>,
        "" <>,
        Brian Gerst <>,
        Dave Hansen <>,
        Linus Torvalds <>,
        Josh Poimboeuf <>
Subject: Re: Stack switching plan of attack (Re: [PATCH v2 00/18] Entry stack

On Thu, Nov 23, 2017 at 07:50:59AM -0800, Andy Lutomirski wrote:
> 1. There needs to be a way to turn it off to get the performance hit
> under control.  I'm leaning toward a boot-time switch, and we can turn
> it into a runtime switch later on.  Thoughts?

Yes, we need a runtime switch off for machines/vendors which might not
be affected.

> I don't care too much about idtentry performance, but syscall
> performance matters a lot, and my patches slow it down. I probably
> need to benchmark to see whether

Yeah, having numbers here would be good.

> there's any point to turning *entry* stack switching off, but we
> definitely need to turn *exit* stack switching off when it's not
> needed.
> (Entry stack switching doesn't directly affect SYSCALL, and I've
> structured the SYSCALL code so that the entry part can be turned on
> and off just by changing the entry target MSR.)
> 2. The TSS should be RO.  Otherwise I think it's just too big a
> security regression.
> and possibly 3: fix the existing performance regression on Atom
> syscalls.  That's easy-ish, but it's ugly and stupid.
> I'm assuming that KAISER itself will miss the merge window and that
> we'll just deal with it.

4. Backporting the whole crap is another PITA topic...


SUSE Linux GmbH, GF: Felix Imend├Ârffer, Jane Smithard, Graham Norton, HRB 21284 (AG N├╝rnberg)

Powered by blists - more mailing lists