Thread (10 messages) flat view 10 messages, 4 authors, 2021-03-22

RE: [EXT] Re: [V2 net-next] net: mvpp2: Add reserved port private flag configuration

From: Stefan Chulski <hidden>
Date: 2021-03-16 16:52:58
Also in: lkml

I really, really hope that someone has thought this through:

  Packet Processor I/O Interface (PPIO)

   The MUSDK PPIO driver provides low-level network interface API for
   User-Space network drivers/applications. The PPIO infrastrcuture maps
   Marvell's Packet Processor (PPv2) configuration space and I/O descriptors
   space directly to user-space memory. This allows user-space
   driver/application to directly process the packet processor I/O rings from
   user space, without any overhead of a copy operation.

I realy, really hope that you are not exposing the I/O descriptors to
userspace, allowing userspace to manipulate the physical addresses in those
descriptors, and that userspace is not dealing with physical addresses.

If userspace has access to the I/O descriptors with physical addresses, or
userspace is dealing with physical addresses, then you can say good bye to
any kind of security on the platform. Essentially, in such a scenario, the entire
system memory becomes accessible to userspace, which includes the kernel.
Hi Russel,

This patch doesn't relate to MUSDK Packet Processor I/O Interface functionality.
MUSDK is just another possible use case I could think of for the port reservation feature.
I am not responsible for the MUSDK code, but as far as I know it is based on the generic UIO Kernel interface (uio_pdrv_genirq) so the user can decide whether he wants to enable it or not for his platform.
For the main CM3 management port use case, security is not an issue since the CM3 processor is secured by hardware in the device and its code is authenticated.

Stefan.
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help