Thread (6 messages) flat view 6 messages, 3 authors, 2017-07-26
STALE3341d

[RFC PATCH untested] arm64: kernel: implement fast refcount checking

From: Ard Biesheuvel <hidden>
Date: 2017-07-25 17:20:02

On 25 July 2017 at 18:13, Kees Cook [off-list ref] wrote:
On Tue, Jul 25, 2017 at 4:49 AM, Ard Biesheuvel
[off-list ref] wrote:
quoted
Hi all,

I had a stab at porting the fast refcount checks to arm64. It is slightly
less straight-forward than x86 given that we need to support both LSE and
LL/SC, and fallback to the latter if running a kernel built with support
for the former on hardware that does not support it.

It is build tested with and without LSE support, and boots fine on non-LSE
hardware in both cases.
Ah! Very cool. Hopefully you and Li can compare notes; I think they've
been working on an implementation too.
I wasn't aware of that.
quoted
Suggestions welcome as to how to test and/or benchmark this,
I'll post a patch for LKDTM that I've been using. It's more
comprehensive than the existing ATOMIC checks (which predated the
refcount-only protection).
OK. One thing I couldn't figure out: is refcount_t signed or not? The
saturate tests set the initial value to UINT_MAX - 1, but this is
interpreted as a negative value and so the refcount manipulations that
are expected to succeed also fail in my case.
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help