Thread (30 messages) flat view 30 messages, 7 authors, 2018-03-23

Re: [PATCH RFC rebase 2/9] powerpc: Use barrier_nospec in copy_from_user

From: Linus Torvalds <torvalds@linux-foundation.org>
Date: 2018-03-15 21:37:25
Also in: lkml

On Thu, Mar 15, 2018 at 12:15 PM, Michal Suchanek [off-list ref] wrote:
quoted hunk ↗ jump to hunk
This is based on x86 patch doing the same.

Signed-off-by: Michal Suchanek <redacted>
---
--- a/arch/powerpc/include/asm/uaccess.h
+++ b/arch/powerpc/include/asm/uaccess.h
@@ -258,8 +259,10 @@ do {                                                               \
        long __gu_err = -EFAULT;                                        \
        unsigned long  __gu_val = 0;                                    \
        const __typeof__(*(ptr)) __user *__gu_addr = (ptr);             \
+       int can_access = access_ok(VERIFY_READ, __gu_addr, (size));     \
        might_fault();                                                  \
-       if (access_ok(VERIFY_READ, __gu_addr, (size)))                  \
+       barrier_nospec();                                               \
+       if (can_access)                                                 \
                __get_user_size(__gu_val, __gu_addr, (size), __gu_err); \
        (x) = (__force __typeof__(*(ptr)))__gu_val;                             \
        __gu_err;                                                       \
Is the above really correct? The barrier is *before* the conditional
branch that might be mis-predicted.

I don't know how the ppc barrier works, but that sounds completely bogus.

               Linus
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help