/usr/src/kernels/4.18.0-553.121.1.el8_10.x86_64/arch/x86/include/asm
NameSizeModeActions
crypto/-0755rm
e820/-0755rm
fpu/-0755rm
numachip/-0755rm
shared/-0755rm
trace/-0755rm
uv/-0755rm
vdso/-0755rm
xen/-0755rm
a.out-core.h19310644editdlrm
acenv.h15960644editdlrm
acpi.h53000644editdlrm
agp.h10700644editdlrm
alternative.h114070644editdlrm
amd-ibs.h50200644editdlrm
amd_hsmp.h3640644editdlrm
amd_nb.h30860644editdlrm
apb_timer.h14660644editdlrm
apic.h146610644editdlrm
apicdef.h115650644editdlrm
apic_flat_64.h1510644editdlrm
apm.h17680644editdlrm
archrandom.h32210644editdlrm
arch_hweight.h13110644editdlrm
asm-offsets.h350644editdlrm
asm-prototypes.h9460644editdlrm
asm.h51860644editdlrm
atomic.h62790644editdlrm
atomic64_32.h81500644editdlrm
atomic64_64.h59330644editdlrm
audit.h1700644editdlrm
barrier.h24710644editdlrm
bios_ebda.h9140644editdlrm
bitops.h107270644editdlrm
boot.h18250644editdlrm
bootparam_utils.h29070644editdlrm
bug.h21170644editdlrm
bugs.h5330644editdlrm
cache.h6410644editdlrm
cacheflush.h3060644editdlrm
cacheinfo.h2090644editdlrm
calgary.h23700644editdlrm
ce4100.h1210644editdlrm
checksum.h1330644editdlrm
checksum_32.h49640644editdlrm
checksum_64.h55410644editdlrm
clocksource.h4800644editdlrm
cmdline.h3020644editdlrm
cmpxchg.h78910644editdlrm
cmpxchg_32.h32470644editdlrm
cmpxchg_64.h5520644editdlrm
coco.h4820644editdlrm
compat.h48610644editdlrm
cpu.h26070644editdlrm
cpufeature.h94700644editdlrm
cpufeatures.h328450644editdlrm
cpuid.h4980644editdlrm
cpuidle_haltpoll.h1890644editdlrm
cpumask.h4080644editdlrm
cpu_device_id.h81090644editdlrm
cpu_entry_area.h41620644editdlrm
crash.h3000644editdlrm
current.h4430644editdlrm
debugreg.h34110644editdlrm
delay.h2750644editdlrm
desc.h122740644editdlrm
desc_defs.h33960644editdlrm
device.h3280644editdlrm
disabled-features.h35590644editdlrm
div64.h21890644editdlrm
dma-mapping.h2880644editdlrm
dma.h98270644editdlrm
dmi.h5560644editdlrm
dwarf2.h24870644editdlrm
edac.h4740644editdlrm
efi.h74160644editdlrm
elf.h126400644editdlrm
emergency-restart.h2020644editdlrm
emulate_prefix.h4840644editdlrm
enclu.h1810644editdlrm
entry_arch.h19220644editdlrm
espfix.h4260644editdlrm
exec.h370644editdlrm
export.h1200644editdlrm
extable.h13000644editdlrm
fb.h5400644editdlrm
fixmap.h63810644editdlrm
floppy.h67480644editdlrm
frame.h22370644editdlrm
fsgsbase.h20720644editdlrm
ftrace.h27770644editdlrm
futex.h22690644editdlrm
gart.h26820644editdlrm
genapic.h220644editdlrm
geode.h8420644editdlrm
hardirq.h22070644editdlrm
highmem.h24660644editdlrm
hpet.h34610644editdlrm
hugetlb.h18670644editdlrm
hw_breakpoint.h21120644editdlrm
hw_irq.h41260644editdlrm
hyperv-tlfs.h223370644editdlrm
hypervisor.h19750644editdlrm
i8259.h19750644editdlrm
ia32.h17890644editdlrm
ia32_unistd.h3130644editdlrm
imr.h18490644editdlrm
inat.h67360644editdlrm
inat_types.h10130644editdlrm
init.h6320644editdlrm
insn-eval.h15460644editdlrm
insn.h80980644editdlrm
inst.h54530644editdlrm
intel-family.h51680644editdlrm
intel-mid.h50250644editdlrm
intel_ds.h8490644editdlrm
intel_mid_vrtc.h3300644editdlrm
intel_pconfig.h15450644editdlrm
intel_pmc_ipc.h22670644editdlrm
intel_pt.h12760644editdlrm
intel_punit_ipc.h46660644editdlrm
intel_scu_ipc.h23510644editdlrm
intel_telemetry.h40600644editdlrm
invpcid.h16040644editdlrm
io.h118720644editdlrm
iomap.h12280644editdlrm
iommu.h9350644editdlrm
iosf_mbi.h73540644editdlrm
io_apic.h58900644editdlrm
ipi.h28730644editdlrm
irq.h14150644editdlrm
irqdomain.h17960644editdlrm
irqflags.h41610644editdlrm
irq_regs.h6830644editdlrm
irq_remapping.h28650644editdlrm
irq_vectors.h41050644editdlrm
irq_work.h4650644editdlrm
ist.h7350644editdlrm
jailhouse_para.h4490644editdlrm
jump_label.h25290644editdlrm
kasan.h12910644editdlrm
kaslr.h3140644editdlrm
kbdleds.h4540644editdlrm
Kbuild3190644editdlrm
kdebug.h10420644editdlrm
kexec-bzimage64.h1950644editdlrm
kexec.h58430644editdlrm
kgdb.h21430644editdlrm
kprobes.h37010644editdlrm
kvm-x86-ops.h39890644editdlrm
kvmclock.h5060644editdlrm
kvm_host.h639250644editdlrm
kvm_page_track.h27000644editdlrm
kvm_para.h44220644editdlrm
kvm_types.h1780644editdlrm
kvm_vcpu_regs.h6060644editdlrm
linkage.h12680644editdlrm
livepatch.h10390644editdlrm
local.h39250644editdlrm
local64.h330644editdlrm
mach_timer.h15900644editdlrm
mach_traps.h10130644editdlrm
math_emu.h3950644editdlrm
mc146818rtc.h28350644editdlrm
mce.h119090644editdlrm
mcsafe_test.h14180644editdlrm
memtype.h8150644editdlrm
mem_encrypt.h35430644editdlrm
microcode.h35570644editdlrm
microcode_amd.h13730644editdlrm
microcode_intel.h26190644editdlrm
misc.h1430644editdlrm
mmconfig.h3740644editdlrm
mmu.h16890644editdlrm
mmu_context.h101180644editdlrm
mmx.h3370644editdlrm
mmzone.h1290644editdlrm
mmzone_32.h11880644editdlrm
mmzone_64.h4300644editdlrm
module.h20960644editdlrm
mpspec.h40230644editdlrm
mpspec_def.h42560644editdlrm
mpx.h31250644editdlrm
mshyperv.h101420644editdlrm
msi.h15080644editdlrm
msidef.h18140644editdlrm
msr-index.h424000644editdlrm
msr-trace.h13870644editdlrm
msr.h112900644editdlrm
mtrr.h47530644editdlrm
mwait.h49680644editdlrm
nmi.h14960644editdlrm
nops.h44120644editdlrm
nospec-branch.h142050644editdlrm
numa.h22280644editdlrm
numa_32.h2560644editdlrm
olpc.h32400644editdlrm
olpc_ofw.h11280644editdlrm
orc_lookup.h16650644editdlrm
orc_types.h35770644editdlrm
page.h25170644editdlrm
page_32.h10390644editdlrm
page_32_types.h16910644editdlrm
page_64.h15730644editdlrm
page_64_types.h22080644editdlrm
page_types.h23690644editdlrm
paravirt.h246080644editdlrm
paravirt_types.h227090644editdlrm
parport.h3140644editdlrm
pci-direct.h7400644editdlrm
pci-functions.h6540644editdlrm
pci.h32880644editdlrm
pci_64.h6840644editdlrm
pci_x86.h62830644editdlrm
percpu.h202670644editdlrm
perf_event.h178960644editdlrm
perf_event_p4.h267310644editdlrm
pgalloc.h65910644editdlrm
pgtable-2level.h28150644editdlrm
pgtable-2level_types.h8670644editdlrm
pgtable-3level.h88320644editdlrm
pgtable-3level_types.h10070644editdlrm
pgtable-invert.h10910644editdlrm
pgtable.h358010644editdlrm
pgtable_32.h31590644editdlrm
pgtable_32_types.h21210644editdlrm
pgtable_64.h74740644editdlrm
pgtable_64_types.h43650644editdlrm
pgtable_types.h171490644editdlrm
pkeys.h35420644editdlrm
pkru.h13460644editdlrm
platform_sst_audio.h32900644editdlrm
pm-trace.h6110644editdlrm
posix_types.h1440644editdlrm
preempt.h32170644editdlrm
probe_roms.h2730644editdlrm
processor-cyrix.h8790644editdlrm
processor-flags.h17500644editdlrm
processor.h244800644editdlrm
prom.h10280644editdlrm
proto.h13130644editdlrm
pti.h4290644editdlrm
ptrace.h89960644editdlrm
purgatory.h2350644editdlrm
pvclock-abi.h15300644editdlrm
pvclock.h27020644editdlrm
qrwlock.h1990644editdlrm
qspinlock.h25980644editdlrm
qspinlock_paravirt.h19080644editdlrm
realmode.h20640644editdlrm
reboot.h8980644editdlrm
reboot_fixups.h1830644editdlrm
refcount.h29110644editdlrm
required-features.h30430644editdlrm
resctrl.h30640644editdlrm
rio.h26300644editdlrm
rmwcc.h22590644editdlrm
seccomp.h5100644editdlrm
sections.h9160644editdlrm
segment.h111840644editdlrm
serial.h11370644editdlrm
setup.h37510644editdlrm
setup_arch.h770644editdlrm
set_memory.h53810644editdlrm
sev-common.h48670644editdlrm
sev.h69650644editdlrm
sgx.h131570644editdlrm
shmparam.h1930644editdlrm
sigcontext.h2610644editdlrm
sigframe.h23390644editdlrm
sighandling.h7300644editdlrm
signal.h24240644editdlrm
simd.h2870644editdlrm
smap.h22470644editdlrm
smp.h55000644editdlrm
sparsemem.h9940644editdlrm
spec-ctrl.h31430644editdlrm
special_insns.h75360644editdlrm
spinlock.h12140644editdlrm
spinlock_types.h7190644editdlrm
sta2x11.h3520644editdlrm
stackprotector.h39660644editdlrm
stacktrace.h26190644editdlrm
string.h1290644editdlrm
string_32.h79290644editdlrm
string_64.h42370644editdlrm
suspend.h5030644editdlrm
suspend_32.h9380644editdlrm
suspend_64.h18380644editdlrm
svm.h146720644editdlrm
switch_to.h32580644editdlrm
sync_bitops.h35030644editdlrm
sync_core.h31380644editdlrm
syscall.h54890644editdlrm
syscalls.h13320644editdlrm
syscall_wrapper.h77800644editdlrm
sysfb.h26000644editdlrm
tce.h17240644editdlrm
tdx.h23600644editdlrm
text-patching.h48120644editdlrm
thermal.h4280644editdlrm
thread_info.h88050644editdlrm
time.h3310644editdlrm
timer.h10270644editdlrm
timex.h3050644editdlrm
tlb.h11030644editdlrm
tlbbatch.h3320644editdlrm
tlbflush.h178130644editdlrm
topology.h66540644editdlrm
trace_clock.h4060644editdlrm
trapnr.h13160644editdlrm
traps.h53740644editdlrm
trap_pf.h7090644editdlrm
tsc.h19500644editdlrm
uaccess.h212330644editdlrm
uaccess_32.h10060644editdlrm
uaccess_64.h31290644editdlrm
umip.h3290644editdlrm
unaligned.h3450644editdlrm
unistd.h14820644editdlrm
unwind.h32200644editdlrm
unwind_hints.h33420644editdlrm
uprobes.h16860644editdlrm
user.h22570644editdlrm
user32.h21560644editdlrm
user_32.h50420644editdlrm
user_64.h53390644editdlrm
vdso.h14000644editdlrm
vga.h7400644editdlrm
vgtod.h5180644editdlrm
virtext.h31020644editdlrm
vm86.h22120644editdlrm
vmware.h19420644editdlrm
vmx.h267630644editdlrm
vmxfeatures.h60490644editdlrm
vsyscall.h9200644editdlrm
vvar.h16030644editdlrm
word-at-a-time.h25960644editdlrm
x86_init.h115200644editdlrm
xor.h105080644editdlrm
xor_32.h147480644editdlrm
xor_64.h7160644editdlrm
xor_avx.h46100644editdlrm
Edit: /usr/src/kernels/4.18.0-553.121.1.el8_10.x86_64/arch/x86/include/asm/nospec-branch.h (14205B)
/* SPDX-License-Identifier: GPL-2.0 */ #ifndef _ASM_X86_NOSPEC_BRANCH_H_ #define _ASM_X86_NOSPEC_BRANCH_H_ #include #include #include #include #include #include #include /* * This should be used immediately before a retpoline alternative. It tells * objtool where the retpolines are so that it can make sense of the control * flow by just reading the original instruction(s) and ignoring the * alternatives. */ #define ANNOTATE_NOSPEC_ALTERNATIVE \ ANNOTATE_IGNORE_ALTERNATIVE /* * Fill the CPU return stack buffer. * * Each entry in the RSB, if used for a speculative 'ret', contains an * infinite 'pause; lfence; jmp' loop to capture speculative execution. * * This is required in various cases for retpoline and IBRS-based * mitigations for the Spectre variant 2 vulnerability. Sometimes to * eliminate potentially bogus entries from the RSB, and sometimes * purely to ensure that it doesn't get empty, which on some CPUs would * allow predictions from other (unwanted!) sources to be used. * * We define a CPP macro such that it can be used from both .S files and * inline assembly. It's possible to do a .macro and then include that * from C via asm(".include ") but let's not go there. */ #define RSB_CLEAR_LOOPS 32 /* To forcibly overwrite all entries */ #define RSB_FILL_LOOPS 16 /* To avoid underflow */ /* * Google experimented with loop-unrolling and this turned out to be * the optimal version - two calls, each with their own speculation * trap should their return address end up getting used, in a loop. */ #define __FILL_RETURN_BUFFER(reg, nr, sp) \ mov $(nr/2), reg; \ 771: \ ANNOTATE_INTRA_FUNCTION_CALL; \ call 772f; \ 773: /* speculation trap */ \ UNWIND_HINT_EMPTY; \ pause; \ lfence; \ jmp 773b; \ 772: \ ANNOTATE_INTRA_FUNCTION_CALL; \ call 774f; \ 775: /* speculation trap */ \ UNWIND_HINT_EMPTY; \ pause; \ lfence; \ jmp 775b; \ 774: \ add $(BITS_PER_LONG/8) * 2, sp; \ dec reg; \ jnz 771b; \ /* barrier for jnz misprediction */ \ lfence; #ifdef __ASSEMBLY__ /* * This should be used immediately before an indirect jump/call. It tells * objtool the subsequent indirect jump/call is vouched safe for retpoline * builds. */ .macro ANNOTATE_RETPOLINE_SAFE .Lannotate_\@: .pushsection .discard.retpoline_safe _ASM_PTR .Lannotate_\@ .popsection .endm /* * These are the bare retpoline primitives for indirect jmp and call. * Do not use these directly; they only exist to make the ALTERNATIVE * invocation below less ugly. */ .macro RETPOLINE_JMP reg:req call .Ldo_rop_\@ .Lspec_trap_\@: pause lfence jmp .Lspec_trap_\@ .Ldo_rop_\@: mov \reg, (%_ASM_SP) ret .endm /* * This is a wrapper around RETPOLINE_JMP so the called function in reg * returns to the instruction after the macro. */ .macro RETPOLINE_CALL reg:req jmp .Ldo_call_\@ .Ldo_retpoline_jmp_\@: RETPOLINE_JMP \reg .Ldo_call_\@: call .Ldo_retpoline_jmp_\@ .endm /* * (ab)use RETPOLINE_SAFE on RET to annotate away 'bare' RET instructions * vs RETBleed validation. */ #define ANNOTATE_UNRET_SAFE ANNOTATE_RETPOLINE_SAFE /* * JMP_NOSPEC and CALL_NOSPEC macros can be used instead of a simple * indirect jmp/call which may be susceptible to the Spectre variant 2 * attack. */ .macro JMP_NOSPEC reg:req #ifdef CONFIG_RETPOLINE ANNOTATE_NOSPEC_ALTERNATIVE ALTERNATIVE_2 __stringify(RETPOLINE_JMP \reg), \ __stringify(lfence; ANNOTATE_RETPOLINE_SAFE; jmp *\reg; int3), X86_FEATURE_RETPOLINE_LFENCE, \ __stringify(ANNOTATE_RETPOLINE_SAFE; jmp *\reg), ALT_NOT(X86_FEATURE_RETPOLINE) #else jmp *\reg #endif .endm .macro CALL_NOSPEC reg:req #ifdef CONFIG_RETPOLINE ANNOTATE_NOSPEC_ALTERNATIVE ALTERNATIVE_2 __stringify(ANNOTATE_RETPOLINE_SAFE; call *\reg), \ __stringify(RETPOLINE_CALL \reg), X86_FEATURE_RETPOLINE,\ __stringify(lfence; ANNOTATE_RETPOLINE_SAFE; call *\reg), X86_FEATURE_RETPOLINE_LFENCE #else call *\reg #endif .endm .macro ISSUE_UNBALANCED_RET_GUARD ANNOTATE_INTRA_FUNCTION_CALL call .Lunbalanced_ret_guard_\@ int3 .Lunbalanced_ret_guard_\@: add $(BITS_PER_LONG/8), %_ASM_SP lfence .endm /* * A simpler FILL_RETURN_BUFFER macro. Don't make people use the CPP * monstrosity above, manually. */ .macro FILL_RETURN_BUFFER reg:req nr:req ftr:req ftr2 .ifb \ftr2 ALTERNATIVE "jmp .Lskip_rsb_\@", "", \ftr .else ALTERNATIVE_2 "jmp .Lskip_rsb_\@", "", \ftr, "jmp .Lunbalanced_\@", \ftr2 .endif __FILL_RETURN_BUFFER(\reg,\nr,%_ASM_SP) .Lunbalanced_\@: ISSUE_UNBALANCED_RET_GUARD .Lskip_rsb_\@: .endm #ifdef CONFIG_CPU_UNRET_ENTRY #define CALL_UNTRAIN_RET "call entry_untrain_ret" #else #define CALL_UNTRAIN_RET "" #endif /* * Mitigate RETBleed for AMD/Hygon Zen uarch. Requires KERNEL CR3 because the * return thunk isn't mapped into the userspace tables (then again, AMD * typically has NO_MELTDOWN). * * While retbleed_untrain_ret() doesn't clobber anything but requires stack, * entry_ibpb() will clobber AX, CX, DX. * * As such, this must be placed after every *SWITCH_TO_KERNEL_CR3 at a point * where we have a stack but before any RET instruction. */ .macro UNTRAIN_RET #if defined(CONFIG_RETHUNK) || defined(CONFIG_CPU_IBPB_ENTRY) ALTERNATIVE_2 "", \ CALL_UNTRAIN_RET, X86_FEATURE_UNRET, \ "call entry_ibpb", X86_FEATURE_ENTRY_IBPB #endif .endm .macro UNTRAIN_RET_VM #if defined(CONFIG_RETHUNK) || defined(CONFIG_CPU_IBPB_ENTRY) ALTERNATIVE_2 "", \ CALL_UNTRAIN_RET, X86_FEATURE_UNRET, \ "call entry_ibpb", X86_FEATURE_IBPB_ON_VMEXIT #endif .endm /* * Macro to execute VERW instruction that mitigate transient data sampling * attacks such as MDS. On affected systems a microcode update overloaded VERW * instruction to also clear the CPU buffers. VERW clobbers CFLAGS.ZF. * * Note: Only the memory operand variant of VERW clears the CPU buffers. */ .macro CLEAR_CPU_BUFFERS ALTERNATIVE __stringify(verw _ASM_RIP(mds_verw_sel)), "", ALT_NOT(X86_FEATURE_CLEAR_CPU_BUF) .endm #ifdef CONFIG_X86_64 .macro CLEAR_BRANCH_HISTORY ALTERNATIVE "", "call clear_bhb_loop", X86_FEATURE_CLEAR_BHB_LOOP .endm .macro CLEAR_BRANCH_HISTORY_VMEXIT ALTERNATIVE "", "call clear_bhb_loop", X86_FEATURE_CLEAR_BHB_LOOP_ON_VMEXIT .endm #else #define CLEAR_BRANCH_HISTORY #define CLEAR_BRANCH_HISTORY_VMEXIT #endif #else /* __ASSEMBLY__ */ #define ANNOTATE_RETPOLINE_SAFE \ "999:\n\t" \ ".pushsection .discard.retpoline_safe\n\t" \ _ASM_PTR " 999b\n\t" \ ".popsection\n\t" #ifdef CONFIG_RETHUNK extern void __x86_return_thunk(void); #else static inline void __x86_return_thunk(void) {} #endif #ifdef CONFIG_CPU_UNRET_ENTRY extern void retbleed_return_thunk(void); #else static inline void retbleed_return_thunk(void) {} #endif #ifdef CONFIG_CPU_SRSO extern void srso_return_thunk(void); extern void srso_alias_return_thunk(void); #else static inline void srso_return_thunk(void) {} static inline void srso_alias_return_thunk(void) {} #endif extern void retbleed_return_thunk(void); extern void srso_return_thunk(void); extern void srso_alias_return_thunk(void); extern void entry_untrain_ret(void); extern void entry_ibpb(void); #ifdef CONFIG_X86_64 extern void clear_bhb_loop(void); #endif extern void (*x86_return_thunk)(void); #ifdef CONFIG_RETPOLINE #ifdef CONFIG_X86_64 /* * Inline asm uses the %V modifier which is only in newer GCC * which is ensured when CONFIG_RETPOLINE is defined. */ # define CALL_NOSPEC \ ANNOTATE_NOSPEC_ALTERNATIVE \ ALTERNATIVE_2( \ ANNOTATE_RETPOLINE_SAFE \ "call *%[thunk_target]\n", \ "call __x86_indirect_thunk_%V[thunk_target]\n", \ X86_FEATURE_RETPOLINE, \ "lfence;\n" \ ANNOTATE_RETPOLINE_SAFE \ "call *%[thunk_target]\n", \ X86_FEATURE_RETPOLINE_LFENCE) # define THUNK_TARGET(addr) [thunk_target] "r" (addr) #else /* CONFIG_X86_32 */ /* * For i386 we use the original ret-equivalent retpoline, because * otherwise we'll run out of registers. We don't care about CET * here, anyway. */ # define CALL_NOSPEC \ ANNOTATE_NOSPEC_ALTERNATIVE \ ALTERNATIVE_2( \ ANNOTATE_RETPOLINE_SAFE \ "call *%[thunk_target]\n", \ " jmp 904f;\n" \ " .align 16\n" \ "901: call 903f;\n" \ "902: pause;\n" \ " lfence;\n" \ " jmp 902b;\n" \ " .align 16\n" \ "903: addl $4, %%esp;\n" \ " pushl %[thunk_target];\n" \ " ret;\n" \ " .align 16\n" \ "904: call 901b;\n", \ X86_FEATURE_RETPOLINE, \ "lfence;\n" \ ANNOTATE_RETPOLINE_SAFE \ "call *%[thunk_target]\n", \ X86_FEATURE_RETPOLINE_LFENCE) # define THUNK_TARGET(addr) [thunk_target] "rm" (addr) #endif #else /* No retpoline for C / inline asm */ # define CALL_NOSPEC "call *%[thunk_target]\n" # define THUNK_TARGET(addr) [thunk_target] "rm" (addr) #endif /* The Spectre V2 mitigation variants */ enum spectre_v2_mitigation { SPECTRE_V2_NONE, SPECTRE_V2_RETPOLINE, SPECTRE_V2_LFENCE, SPECTRE_V2_EIBRS, SPECTRE_V2_EIBRS_RETPOLINE, SPECTRE_V2_EIBRS_LFENCE, SPECTRE_V2_IBRS, SPECTRE_V2_IBRS_ALWAYS, SPECTRE_V2_RETPOLINE_IBRS_USER, }; /* The indirect branch speculation control variants */ enum spectre_v2_user_mitigation { SPECTRE_V2_USER_NONE, SPECTRE_V2_USER_STRICT, SPECTRE_V2_USER_STRICT_PREFERRED, SPECTRE_V2_USER_PRCTL, SPECTRE_V2_USER_SECCOMP, }; /* The Speculative Store Bypass disable variants */ enum ssb_mitigation { SPEC_STORE_BYPASS_NONE, SPEC_STORE_BYPASS_DISABLE, SPEC_STORE_BYPASS_PRCTL, SPEC_STORE_BYPASS_SECCOMP, }; extern char __indirect_thunk_start[]; extern char __indirect_thunk_end[]; static __always_inline void alternative_msr_write(unsigned int msr, u64 val, unsigned int feature) { asm volatile(ALTERNATIVE("", "wrmsr", %c[feature]) : : "c" (msr), "a" ((u32)val), "d" ((u32)(val >> 32)), [feature] "i" (feature) : "memory"); } extern u64 x86_pred_cmd; DECLARE_PER_CPU(bool, x86_ibpb_exit_to_user); static inline void indirect_branch_prediction_barrier(void) { alternative_msr_write(MSR_IA32_PRED_CMD, x86_pred_cmd, X86_FEATURE_USE_IBPB); } /* The Intel SPEC CTRL MSR base value cache */ extern u64 x86_spec_ctrl_base; DECLARE_PER_CPU(u64, x86_spec_ctrl_current); extern void update_spec_ctrl_cond(u64 val); extern u64 spec_ctrl_current(void); /* * With retpoline, we must use IBRS to restrict branch prediction * before calling into firmware. * * (Implemented as CPP macros due to header hell.) */ #define firmware_restrict_branch_speculation_start() \ do { \ preempt_disable(); \ alternative_msr_write(MSR_IA32_SPEC_CTRL, \ spec_ctrl_current() | SPEC_CTRL_IBRS, \ X86_FEATURE_USE_IBRS_FW); \ alternative_msr_write(MSR_IA32_PRED_CMD, PRED_CMD_IBPB, \ X86_FEATURE_USE_IBPB_FW); \ } while (0) #define firmware_restrict_branch_speculation_end() \ do { \ alternative_msr_write(MSR_IA32_SPEC_CTRL, \ spec_ctrl_current(), \ X86_FEATURE_USE_IBRS_FW); \ preempt_enable(); \ } while (0) DECLARE_STATIC_KEY_FALSE(switch_to_cond_stibp); DECLARE_STATIC_KEY_FALSE(switch_mm_cond_ibpb); DECLARE_STATIC_KEY_FALSE(switch_mm_always_ibpb); DECLARE_STATIC_KEY_FALSE(mds_idle_clear); DECLARE_STATIC_KEY_FALSE(mmio_stale_data_clear); extern u16 mds_verw_sel; #include /** * mds_clear_cpu_buffers - Mitigation for MDS and TAA vulnerability * * This uses the otherwise unused and obsolete VERW instruction in * combination with microcode which triggers a CPU buffer flush when the * instruction is executed. */ static __always_inline void mds_clear_cpu_buffers(void) { static const u16 ds = __KERNEL_DS; /* * Has to be the memory-operand variant because only that * guarantees the CPU buffer flush functionality according to * documentation. The register-operand variant does not. * Works with any segment selector, but a valid writable * data segment is the fastest variant. * * "cc" clobber is required because VERW modifies ZF. */ asm volatile("verw %[ds]" : : [ds] "m" (ds) : "cc"); } /** * mds_idle_clear_cpu_buffers - Mitigation for MDS vulnerability * * Clear CPU buffers if the corresponding static key is enabled */ static inline void mds_idle_clear_cpu_buffers(void) { if (static_branch_likely(&mds_idle_clear)) mds_clear_cpu_buffers(); } #endif /* __ASSEMBLY__ */ /* * Below is used in the eBPF JIT compiler and emits the byte sequence * for the following assembly: * * With retpolines configured: * * callq do_rop * spec_trap: * pause * lfence * jmp spec_trap * do_rop: * mov %rcx,(%rsp) for x86_64 * mov %edx,(%esp) for x86_32 * retq * * Without retpolines configured: * * jmp *%rcx for x86_64 * jmp *%edx for x86_32 */ #ifdef CONFIG_RETPOLINE # ifdef CONFIG_X86_64 # define RETPOLINE_RCX_BPF_JIT_SIZE 17 # define RETPOLINE_RCX_BPF_JIT() \ do { \ EMIT1_off32(0xE8, 7); /* callq do_rop */ \ /* spec_trap: */ \ EMIT2(0xF3, 0x90); /* pause */ \ EMIT3(0x0F, 0xAE, 0xE8); /* lfence */ \ EMIT2(0xEB, 0xF9); /* jmp spec_trap */ \ /* do_rop: */ \ EMIT4(0x48, 0x89, 0x0C, 0x24); /* mov %rcx,(%rsp) */ \ EMIT1(0xC3); /* retq */ \ } while (0) # else /* !CONFIG_X86_64 */ # define RETPOLINE_EDX_BPF_JIT() \ do { \ EMIT1_off32(0xE8, 7); /* call do_rop */ \ /* spec_trap: */ \ EMIT2(0xF3, 0x90); /* pause */ \ EMIT3(0x0F, 0xAE, 0xE8); /* lfence */ \ EMIT2(0xEB, 0xF9); /* jmp spec_trap */ \ /* do_rop: */ \ EMIT3(0x89, 0x14, 0x24); /* mov %edx,(%esp) */ \ EMIT1(0xC3); /* ret */ \ } while (0) # endif #else /* !CONFIG_RETPOLINE */ # ifdef CONFIG_X86_64 # define RETPOLINE_RCX_BPF_JIT_SIZE 2 # define RETPOLINE_RCX_BPF_JIT() \ EMIT2(0xFF, 0xE1); /* jmp *%rcx */ # else /* !CONFIG_X86_64 */ # define RETPOLINE_EDX_BPF_JIT() \ EMIT2(0xFF, 0xE2) /* jmp *%edx */ # endif #endif #endif /* _ASM_X86_NOSPEC_BRANCH_H_ */