This series follows up on
https://lists.ozlabs.org/pipermail/linuxppc-dev/2016-August/147840.html
The first patch sets up AMOR in hypervisor mode. AMOR
needs to be setup before IAMR (details of AMOR/IAMR in
each patch). The second patch enables detection of exceptions
generated due to instruction fetch violations caused
and OOPSs' the task. The third patch enables IAMR for
both hypervisor and guest kernels.
I've tested with patch series with a sample hack and
payload.
Chris Smart helped with the series, reviewing and
providing valuable feedback
Cc: Chris Smart <redacted>
Cc: Benjamin Herrenschmidt <benh@kernel.crashing.org>
Cc: Michael Neuling <redacted>
Cc: Aneesh Kumar K.V <redacted>
Cc: Paul Mackerras <redacted>
Balbir Singh (3):
Setup AMOR in HV mode
Detect instruction fetch denied and report
Enable storage keys for radix - user mode execution
arch/powerpc/mm/fault.c | 4 ++++
arch/powerpc/mm/pgtable-radix.c | 39 +++++++++++++++++++++++++++++++++++++++
2 files changed, 43 insertions(+)
--
2.5.5
AMOR should be setup in HV mode, we set it up once
and let the generic kernel handle IAMR. This patch is
used to enable storage keys in a following patch as
defined in ISA 3
Reported-by: Aneesh Kumar K.V <redacted>
Signed-off-by: Balbir Singh <bsingharora@gmail.com>
---
arch/powerpc/mm/pgtable-radix.c | 20 ++++++++++++++++++++
1 file changed, 20 insertions(+)
ISA 3 allows for prevention of instruction fetch and execution
of user mode pages. If such an error occurs, SRR1 bit 35
reports the error. We catch and report the error in do_page_fault()
Signed-off-by: Balbir Singh <bsingharora@gmail.com>
---
arch/powerpc/mm/fault.c | 4 ++++
1 file changed, 4 insertions(+)
ISA 3 defines new encoded access authority that allows instruction
access prevention in privileged mode and allows normal access
to problem state. This patch just enables IAMR (Instruction Authority
Mask Register), enabling AMR would require more work.
I've tested this with a buggy driver and a simple payload. The payload
is specific to the build I've tested.
Signed-off-by: Balbir Singh <bsingharora@gmail.com>
---
arch/powerpc/mm/pgtable-radix.c | 19 +++++++++++++++++++
1 file changed, 19 insertions(+)
AMOR should be setup in HV mode, we set it up once
and let the generic kernel handle IAMR. This patch is
used to enable storage keys in a following patch as
defined in ISA 3
Reported-by: Aneesh Kumar K.V <redacted>
Signed-off-by: Balbir Singh <bsingharora@gmail.com>
---
arch/powerpc/mm/pgtable-radix.c | 20 ++++++++++++++++++++
1 file changed, 20 insertions(+)
Can't we just init it with the constant 0xc000000000000000;
I can understand kvm code wanting to do the '|' above, but does the host
init code need to look at the previous value there ?
quoted hunk
+ mtspr(SPRN_AMOR, amor);+}+ void __init radix__early_init_mmu(void) { unsigned long lpcr;
ISA 3 allows for prevention of instruction fetch and execution
of user mode pages. If such an error occurs, SRR1 bit 35
reports the error. We catch and report the error in do_page_fault()
Signed-off-by: Balbir Singh <bsingharora@gmail.com>
---
arch/powerpc/mm/fault.c | 4 ++++
1 file changed, 4 insertions(+)
ISA 3 defines new encoded access authority that allows instruction
access prevention in privileged mode and allows normal access
to problem state. This patch just enables IAMR (Instruction Authority
Mask Register), enabling AMR would require more work.
We may want to explain what the rules are with details like IAMR class 0
bit 1 controls the instruction access etc. Also we can metion that we
now setup user pages such that EAA[0] is set to 0
quoted hunk
I've tested this with a buggy driver and a simple payload. The payload
is specific to the build I've tested.
Signed-off-by: Balbir Singh <bsingharora@gmail.com>
---
arch/powerpc/mm/pgtable-radix.c | 19 +++++++++++++++++++
1 file changed, 19 insertions(+)
ISA 3 allows for prevention of instruction fetch and execution
of user mode pages. If such an error occurs, SRR1 bit 35
reports the error. We catch and report the error in do_page_fault()
Signed-off-by: Balbir Singh <bsingharora@gmail.com>
---
arch/powerpc/mm/fault.c | 4 ++++
1 file changed, 4 insertions(+)
ISA 3 defines new encoded access authority that allows instruction
access prevention in privileged mode and allows normal access
to problem state. This patch just enables IAMR (Instruction Authority
Mask Register), enabling AMR would require more work.
We may want to explain what the rules are with details like IAMR class 0
bit 1 controls the instruction access etc. Also we can metion that we
now setup user pages such that EAA[0] is set to 0
quoted
I've tested this with a buggy driver and a simple payload. The payload
is specific to the build I've tested.
Signed-off-by: Balbir Singh <bsingharora@gmail.com>
---
arch/powerpc/mm/pgtable-radix.c | 19 +++++++++++++++++++
1 file changed, 19 insertions(+)
ISA 3 allows for prevention of instruction fetch and execution
of user mode pages. If such an error occurs, SRR1 bit 35
reports the error. We catch and report the error in do_page_fault()
Signed-off-by: Balbir Singh <bsingharora@gmail.com>
---
arch/powerpc/mm/fault.c | 4 ++++
1 file changed, 4 insertions(+)
@@ -404,6 +404,10 @@ int do_page_fault(struct pt_regs *regs, unsigned long address,(cpu_has_feature(CPU_FTR_NOEXECUTE)||!(vma->vm_flags&(VM_READ|VM_WRITE))))gotobad_area;++if(radix_enabled()&&(regs->msr&SRR1_ISI_N_OR_G))+gotobad_area;
Why is this within radix_enabled() ? Hash can also generate an
interrupt with that SRR1 value right ?
Yes the bits are not specific to radix. I suspect the check above took
care of instruction exceptions, so we've never needed it before. I'll
remove the check
Balbir
AMOR should be setup in HV mode, we set it up once
and let the generic kernel handle IAMR. This patch is
used to enable storage keys in a following patch as
defined in ISA 3
Reported-by: Aneesh Kumar K.V <redacted>
Signed-off-by: Balbir Singh <bsingharora@gmail.com>
---
arch/powerpc/mm/pgtable-radix.c | 20 ++++++++++++++++++++
1 file changed, 20 insertions(+)
Can't we just init it with the constant 0xc000000000000000;
I can understand kvm code wanting to do the '|' above, but does the host
init code need to look at the previous value there ?
quoted
+ mtspr(SPRN_AMOR, amor);+}+ void __init radix__early_init_mmu(void) { unsigned long lpcr;