From owner-freebsd-current@FreeBSD.ORG Fri Nov 2 00:08:00 2012 Return-Path: Delivered-To: current@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [69.147.83.52]) by hub.freebsd.org (Postfix) with ESMTP id 2BBEB3C8; Fri, 2 Nov 2012 00:08:00 +0000 (UTC) (envelope-from kpersson@clarkebroadcasting.com) Received: from tx2outboundpool.messaging.microsoft.com (tx2ehsobe003.messaging.microsoft.com [65.55.88.13]) by mx1.freebsd.org (Postfix) with ESMTP id C73B28FC0C; Fri, 2 Nov 2012 00:07:59 +0000 (UTC) Received: from mail163-tx2-R.bigfish.com (10.9.14.237) by TX2EHSOBE009.bigfish.com (10.9.40.29) with Microsoft SMTP Server id 14.1.225.23; Fri, 2 Nov 2012 00:07:53 +0000 Received: from mail163-tx2 (localhost [127.0.0.1]) by mail163-tx2-R.bigfish.com (Postfix) with ESMTP id E915B1E0146; Fri, 2 Nov 2012 00:07:52 +0000 (UTC) X-Forefront-Antispam-Report: CIP:157.56.236.101; KIP:(null); UIP:(null); IPV:NLI; H:BY2PRD0510HT001.namprd05.prod.outlook.com; RD:none; EFVD:NLI X-SpamScore: -5 X-BigFish: PS-5(zzbb2dI98dI9371I1432I14ffIzz1de0h1202h1d1ah1d2ahzz17326ah8275dhz2fh2a8h668h839h944hd25hf0ah1220h1288h12a5h12a9h12bdh137ah13b6h1441h1504h1537h153bh1155h) Received-SPF: pass (mail163-tx2: domain of clarkebroadcasting.com designates 157.56.236.101 as permitted sender) client-ip=157.56.236.101; envelope-from=kpersson@clarkebroadcasting.com; helo=BY2PRD0510HT001.namprd05.prod.outlook.com ; .outlook.com ; Received: from mail163-tx2 (localhost.localdomain [127.0.0.1]) by mail163-tx2 (MessageSwitch) id 1351814870864109_3051; Fri, 2 Nov 2012 00:07:50 +0000 (UTC) Received: from TX2EHSMHS015.bigfish.com (unknown [10.9.14.237]) by mail163-tx2.bigfish.com (Postfix) with ESMTP id CDDE1220045; Fri, 2 Nov 2012 00:07:50 +0000 (UTC) Received: from BY2PRD0510HT001.namprd05.prod.outlook.com (157.56.236.101) by TX2EHSMHS015.bigfish.com (10.9.99.115) with Microsoft SMTP Server (TLS) id 14.1.225.23; Fri, 2 Nov 2012 00:07:50 +0000 Received: from BY2PRD0510MB376.namprd05.prod.outlook.com ([169.254.7.85]) by BY2PRD0510HT001.namprd05.prod.outlook.com ([10.255.84.36]) with mapi id 14.16.0233.002; Fri, 2 Nov 2012 00:07:50 +0000 From: Kristofer Persson To: Konstantin Belousov , "amd64@freebsd.org" , "current@freebsd.org" Subject: RE: Small Ivy features: FSGSBASE and SMEP. Thread-Topic: Small Ivy features: FSGSBASE and SMEP. Thread-Index: AQHNuFn+wj3ytlEm00S+444R+sVIpZfVq3Gv Date: Fri, 2 Nov 2012 00:07:46 +0000 Message-ID: References: <20120908181019.GK33100@deviant.kiev.zoral.com.ua> <504C3A5D.4020402@fuckner.net> <20120909110255.GM33100@deviant.kiev.zoral.com.ua> <20120909202905.GP33100@deviant.kiev.zoral.com.ua>, <20121030151327.GW73505@kib.kiev.ua> In-Reply-To: <20121030151327.GW73505@kib.kiev.ua> Accept-Language: en-US Content-Language: en-US X-MS-Has-Attach: X-MS-TNEF-Correlator: x-originating-ip: [216.86.189.249] Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: quoted-printable MIME-Version: 1.0 X-OriginatorOrg: clarkebroadcasting.com X-Mailman-Approved-At: Fri, 02 Nov 2012 11:20:05 +0000 Cc: "avg@freebsd.org" X-BeenThere: freebsd-current@freebsd.org X-Mailman-Version: 2.1.14 Precedence: list List-Id: Discussions about the use of FreeBSD-current List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Fri, 02 Nov 2012 00:08:00 -0000 $70.00 ________________________________________ From: owner-freebsd-amd64@freebsd.org [owner-freebsd-amd64@freebsd.org] on = behalf of Konstantin Belousov [kostikbel@gmail.com] Sent: Tuesday, October 30, 2012 8:13 AM To: amd64@freebsd.org; current@freebsd.org Cc: avg@freebsd.org Subject: Re: Small Ivy features: FSGSBASE and SMEP. On Sun, Sep 09, 2012 at 11:29:05PM +0300, Konstantin Belousov wrote: > On Sun, Sep 09, 2012 at 02:02:55PM +0300, Konstantin Belousov wrote: > > On Sun, Sep 09, 2012 at 08:42:37AM +0200, Michael Fuckner wrote: > > > Hi all, > > > > > > I changed your patch slightly to apply to specialreh.h on STABLE > > > > > > root@c64:/root # diff smep.1.patch.bak smep.1.patch > > > 80c80 > > > < diff --git a/sys/x86/include/specialreg.h b/sys/x86/include/special= reg.h > > > --- > > > > diff --git a/sys/amd64/include/specialreg.h > > > b/sys/amd64/include/specialreg.h > > > 82,83c82,83 > > > < --- a/sys/x86/include/specialreg.h > > > < +++ b/sys/x86/include/specialreg.h > > > --- > > > > --- a/sys/amd64/include/specialreg.h > > > > +++ b/sys/amd64/include/specialreg.h > > > > > > I got a new kernel, but it is stuck immediately (kerneltrap 9 with > > > interrupts disabled), system doesn't boot on E3-1230 V2 on Supermicro > > > X9SCM-IIF > > > > > > Anything else I could check? > > I need the backtrace and the whole kernel messages. > At least, there was a typo in the definition of CR4_FSGSBASE. > I still need verbose dmesg and panic messages, if any, with the > http://people.freebsd.org/~kib/misc/smep.2.patch > version of the patch. > With a help from Andrey, who has access to the hardware supporting SMEP, I fixed the issue with double-fault on SMEP enable. The issue was due to loader(8) making a handoff to the kernel with 1GB identity mapping which has the PG_U bit set. As a result, after enabling the CR4.SMEP, the #pf was generated immediately. But since the handler, if any, is also mapped with PG_U, double-fault happen and machine was reset. Updated patch, also fixing other minor problems with the features display, is at http://people.freebsd.org/~kib/misc/smep.3.patch . Please test. > > > > > > > > Regards, > > > Michael! > > > > > > > > > On 09/08/2012 08:10 PM, Konstantin Belousov wrote: > > > >Please find at > > > >http://people.freebsd.org/~kib/misc/smep.1.patch > > > >the patch which should enable the FSGSBASE and SMEP features > > > >supposedly present in the IvyBridge CPUs. > > > > > > > >FSGSBASE are four new instructions available in the 64bit mode only. > > > >They allow to access bases for %fs and %gs without touching MSRs. > > > >This makes it possible to both read and write bases in the user mode= , > > > >or in ring 0 with lower overhead. > > > > > > > >At the moment, WRFSBASE/WRGSBASE instructions should work, but are > > > >useless since any interrupt or context switch overrides bases with t= he > > > >values set by the arch syscall. Still, RDFSBASE/RDGSBASE might be us= eful > > > >for some code and I see no reason not to enable them. > > > > > > > >SMEP is the nice feature of the processor which makes it trap if rin= g > > > >0 tries to execute an instruction from usermode-accessible page. It = is > > > >another mitigation for things like calling user-controllable functio= n > > > >pointer in kernel, as well as a protection for NULL function pointer > > > >dereference. > > > > > > > >I am sure that we never execute anything in kernel from user page, b= ut > > > >I did not tested the patch since I have no Ivy machine. > > > > > > > >I need your reports about boot on Ivy with patch applied. Please inc= lude > > > >the lines from verbose dmesg with CPU Features. In particular, the > > > >'Standard Extended Features' report should appear in output. > > > > > > > >Thanks. > > > > > >=