From owner-freebsd-current@FreeBSD.ORG Tue Oct 18 16:53:39 2011 Return-Path: Delivered-To: current@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id E9FD2106568B for ; Tue, 18 Oct 2011 16:53:38 +0000 (UTC) (envelope-from oliver.pntr@gmail.com) Received: from mail-gy0-f182.google.com (mail-gy0-f182.google.com [209.85.160.182]) by mx1.freebsd.org (Postfix) with ESMTP id A82B68FC1C for ; Tue, 18 Oct 2011 16:53:37 +0000 (UTC) Received: by gyd8 with SMTP id 8so1005433gyd.13 for ; Tue, 18 Oct 2011 09:53:37 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=gamma; h=mime-version:in-reply-to:references:date:message-id:subject:from:to :cc:content-type:content-transfer-encoding; bh=/95g+4DA42RJZbpAxxrlwfwQQ1n0p9U8/3Xc7cor+uE=; b=TaRcjLhSKTuaE1DG7dPPED/MG0lC0YqQmUAsBdLL6ig3fCFMlHvHll1U5v241LB3k1 Ysd6pAHpUBU7z6JBqoenersGWL3m1XRci+YjC4JyO4jsDJ8ssSSlEpEpdQjIBNFJZzh+ GjJFWfC889AnjeJpOjGkZCDdDA7dhetxQN+cY= MIME-Version: 1.0 Received: by 10.151.26.6 with SMTP id d6mr3108619ybj.39.1318956817370; Tue, 18 Oct 2011 09:53:37 -0700 (PDT) Received: by 10.150.228.16 with HTTP; Tue, 18 Oct 2011 09:53:37 -0700 (PDT) In-Reply-To: References: <20111018090750.GG50300@deviant.kiev.zoral.com.ua> Date: Tue, 18 Oct 2011 18:53:37 +0200 Message-ID: From: Oliver Pinter To: Arnaud Lacombe Content-Type: text/plain; charset=ISO-8859-1 Content-Transfer-Encoding: quoted-printable Cc: Garrett Cooper , Kostik Belousov , current@freebsd.org Subject: Re: [RFC] Enable nxstack by default X-BeenThere: freebsd-current@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: Discussions about the use of FreeBSD-current List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 18 Oct 2011 16:53:39 -0000 On 10/18/11, Arnaud Lacombe wrote: > Hi, > > On Tue, Oct 18, 2011 at 11:44 AM, Garrett Cooper wro= te: >> On Tue, 18 Oct 2011, Arnaud Lacombe wrote: >> >>> Hi, >>> >>> On Tue, Oct 18, 2011 at 5:07 AM, Kostik Belousov >>> wrote: >>>> >>>> On Mon, Oct 17, 2011 at 09:30:56PM +0200, Oliver Pinter wrote: >>>>> >>>>> Hi all! >>>>> >>>>> I think, it's the time to enable the nxstack feature. Any comments, >>>>> pros, cons? >>>> >>>> I dragged the change long enough for it to miss the 9.0. >>>> After the 9.0 is released, I will flip the switch with the following >>>> change. >>>> >>>> diff --git a/sys/kern/imgact_elf.c b/sys/kern/imgact_elf.c >>>> index 8455f48..926fe64 100644 >>>> --- a/sys/kern/imgact_elf.c >>>> +++ b/sys/kern/imgact_elf.c >>>> @@ -118,7 +118,12 @@ static int elf_legacy_coredump =3D 0; >>>> SYSCTL_INT(_debug, OID_AUTO, __elfN(legacy_coredump), CTLFLAG_RW, >>>> &elf_legacy_coredump, 0, ""); >>>> >>>> -static int __elfN(nxstack) =3D 0; >>>> +int __elfN(nxstack) =3D >>>> +#if defined(__amd64__) || defined(__powerpc64__) /* both 64 and 32 bi= t >>>> */ >>>> >>> Why leaving 32bits x86 CPU supporting the NX feature behind ? >> >> Most likely because it was assumed that i386 doesn't fully support it. >> According to ye great Wikipedia, NX support didn't roll into i386 until >> Prescott, which was pretty late in the non-64-bit capable family of CPUs= , >> as >> its successor -- Conroe -- was 64-bit. Intel detuned some of the early >> Dual >> Core Pentiums, e.g. the Yonahs to not talk 64-bit. Not sure about AMD. >> >> There are probably more details in binutils, gcc, etc, that I'm missing >> and >> Kostik can expound on. >> > NX support is advertised in the cpuid flags, just add the logic to > handle this interface. Kostik's patch is just incomplete, but he's got > a commit bit so he can commit it as-is, as he will. > > If nonexec_stack becomes the default, it should be on every CPU > supporting the feature, not just the low-hanging one. > > - Arnaud > the NX detection code already implemented in i386, but this feature required PAE: @initializecpu(void): =BB =BB } #ifdef PAE =BB =BB if ((amd_feature & AMDID_NX) !=3D 0) { =BB =BB =BB uint64_t msr; =BB =BB =BB msr =3D rdmsr(MSR_EFER) | EFER_NXE; =BB =BB =BB wrmsr(MSR_EFER, msr); =BB =BB =BB pg_nx =3D PG_NX; =BB =BB } #endif =BB =BB break