mbox series

[v6,00/25] powerpc: Syscall wrapper and register clearing

Message ID 20220921065605.1051927-1-rmclure@linux.ibm.com (mailing list archive)
Headers show
Series powerpc: Syscall wrapper and register clearing | expand

Message

Rohan McLure Sept. 21, 2022, 6:55 a.m. UTC
V5 available here:

Link: https://lore.kernel.org/all/20220916053300.786330-2-rmclure@linux.ibm.com/T/

Implement a syscall wrapper, causing arguments to handlers to be passed
via a struct pt_regs on the stack. The syscall wrapper is implemented
for all platforms other than the Cell processor, from which SPUs expect
the ability to directly call syscall handler symbols with the regular
in-register calling convention.

Adopting syscall wrappers requires redefinition of architecture-specific
syscalls and compatibility syscalls to use the SYSCALL_DEFINE and
COMPAT_SYSCALL_DEFINE macros, as well as removal of direct-references to
the emitted syscall-handler symbols from within the kernel. This work
lead to the following modernisations of powerpc's syscall handlers:

 - Replace syscall 82 semantics with sys_old_select and remove
   ppc_select handler, which features direct call to both sys_old_select
   and sys_select.
 - Use a generic fallocate compatibility syscall

Replace asm implementation of syscall table with C implementation for
more compile-time checks.

Many compatibility syscalls are candidates to be removed in favour of
generically defined handlers, but exhibit different parameter orderings
and numberings due to 32-bit ABI support for 64-bit parameters. The
parameter reorderings are however consistent with arm. A future patch
series will serve to modernise syscalls by providing generic
implementations featuring these reorderings.

The design of this syscall is very similar to the s390, x86 and arm64
implementations. See also Commit 4378a7d4be30 (arm64: implement syscall wrappers).
The motivation for this change is that it allows for the clearing of
register state when entering the kernel via through interrupt handlers
on 64-bit servers. This serves to reduce the influence of values in
registers carried over from the interrupted process, e.g. syscall
parameters from user space, or user state at the site of a pagefault.
All values in registers are saved and zeroized at the entry to an
interrupt handler and restored afterward. While this may sound like a
heavy-weight mitigation, many gprs are already saved and restored on
handling of an interrupt, and the mmap_bench benchmark on Power 9 guest,
repeatedly invoking the pagefault handler suggests at most ~0.8%
regression in performance. Realistic workloads are not constantly
producing interrupts, and so this does not indicate realistic slowdown.

Using wrapped syscalls yields to a performance improvement of ~5.6% on
the null_syscall benchmark on pseries guests, by removing the need for
system_call_exception to allocate its own stack frame. This amortises
the additional costs of saving and restoring non-volatile registers
(register clearing is cheap on super scalar platforms), and so the
final mitigation actually yields a net performance improvement of ~0.6%
on the null_syscall benchmark.

The clearing of general purpose registers on interrupts other than
syscalls is enabled by default only on Book3E 64-bit systems (where the
mitigation is inexpensive), but available to other 64-bit systems via
the INTERRUPT_SANITIZE_REGISTERS Kconfig option. This mitigation is
optional, as the speculation influence of interrupts is likely less than
that of syscalls.

Patch Changelog:

 - Clears and restores of NVGPRS that depend on either SANITIZE or
   !SANITIZE have convenience macros.
 - Split syscall wrapper patch with change to system_call_exception
   calling convention.
 - In 64e, exchange misleading REST_GPRS(0, 1, r1) to clearly restore
   r0 first and avoid clobbering the stack pointer.
 - Remove extraneous clears of the high-order words of syscall
   parameters, which is now redundant thanks to use of
   COMPAT_SYSCALL_DEFINE everywhere.

Rohan McLure (25):
  powerpc: Remove asmlinkage from syscall handler definitions
  powerpc: Save caller r3 prior to system_call_exception
  powerpc: Add ZEROIZE_GPRS macros for register clears
  powerpc/64s: Use {ZEROIZE,SAVE,REST}_GPRS macros in sc, scv 0 handlers
  powerpc/32: Clarify interrupt restores with REST_GPR macro in
    entry_32.S
  powerpc/64e: Clarify register saves and clears with
    {SAVE,ZEROIZE}_GPRS
  powerpc/64s: Fix comment on interrupt handler prologue
  powerpc: Fix fallocate and fadvise64_64 compat parameter combination
  asm-generic: compat: Support BE for long long args in 32-bit ABIs
  powerpc: Use generic fallocate compatibility syscall
  powerpc/32: Remove powerpc select specialisation
  powerpc: Remove direct call to personality syscall handler
  powerpc: Remove direct call to mmap2 syscall handlers
  powerpc: Provide do_ppc64_personality helper
  powerpc: Adopt SYSCALL_DEFINE for arch-specific syscall handlers
  powerpc: Include all arch-specific syscall prototypes
  powerpc: Enable compile-time check for syscall handlers
  powerpc: Use common syscall handler type
  powerpc: Remove high-order word clearing on compat syscall entry
  powerpc: Change system_call_exception calling convention
  powerpc: Provide syscall wrapper
  powerpc/64s: Clear user GPRs in syscall interrupt entry
  powerpc/64: Add INTERRUPT_SANITIZE_REGISTERS Kconfig
  powerpc/64s: Clear gprs on interrupt routine entry in Book3S
  powerpc/64e: Clear gprs on interrupt routine entry on Book3E

 arch/powerpc/Kconfig                         |  10 ++
 arch/powerpc/include/asm/interrupt.h         |   3 +-
 arch/powerpc/include/asm/ppc_asm.h           |  22 +++
 arch/powerpc/include/asm/syscall.h           |  11 +-
 arch/powerpc/include/asm/syscall_wrapper.h   |  84 ++++++++++
 arch/powerpc/include/asm/syscalls.h          | 148 +++++++++++++----
 .../ppc32.h => include/asm/syscalls_32.h}    |   0
 arch/powerpc/include/asm/unistd.h            |   1 +
 arch/powerpc/kernel/entry_32.S               |  40 ++---
 arch/powerpc/kernel/exceptions-64e.S         |  36 ++--
 arch/powerpc/kernel/exceptions-64s.S         |  51 ++++--
 arch/powerpc/kernel/interrupt_64.S           |  97 ++++++-----
 arch/powerpc/kernel/signal_32.c              |   2 +-
 arch/powerpc/kernel/sys_ppc32.c              |  66 +++-----
 arch/powerpc/kernel/syscall.c                |  28 +---
 arch/powerpc/kernel/syscalls.c               |  61 ++++---
 arch/powerpc/kernel/syscalls/syscall.tbl     |  24 +--
 arch/powerpc/kernel/systbl.S                 |  41 -----
 arch/powerpc/kernel/systbl.c                 |  47 ++++++
 arch/powerpc/kernel/vdso.c                   |   6 +-
 arch/powerpc/perf/callchain_32.c             |   2 +-
 arch/powerpc/platforms/cell/spu_callbacks.c  |   6 +-
 include/asm-generic/compat.h                 |   9 +-
 .../arch/powerpc/entry/syscalls/syscall.tbl  |  24 +--
 24 files changed, 525 insertions(+), 294 deletions(-)
 create mode 100644 arch/powerpc/include/asm/syscall_wrapper.h
 rename arch/powerpc/{kernel/ppc32.h => include/asm/syscalls_32.h} (100%)
 delete mode 100644 arch/powerpc/kernel/systbl.S
 create mode 100644 arch/powerpc/kernel/systbl.c

Comments

Michael Ellerman Oct. 4, 2022, 1:24 p.m. UTC | #1
On Wed, 21 Sep 2022 16:55:40 +1000, Rohan McLure wrote:
> V5 available here:
> 
> Link: https://lore.kernel.org/all/20220916053300.786330-2-rmclure@linux.ibm.com/T/
> 
> Implement a syscall wrapper, causing arguments to handlers to be passed
> via a struct pt_regs on the stack. The syscall wrapper is implemented
> for all platforms other than the Cell processor, from which SPUs expect
> the ability to directly call syscall handler symbols with the regular
> in-register calling convention.
> 
> [...]

Patches 1-18 & 20-21 applied to powerpc/next.

[01/25] powerpc: Remove asmlinkage from syscall handler definitions
        https://git.kernel.org/powerpc/c/5ba6c9a912fe4c60f84d6617ad10d2b8d7910990
[02/25] powerpc: Save caller r3 prior to system_call_exception
        https://git.kernel.org/powerpc/c/2c27d4a419f627636b8c6038e55acb26df05c391
[03/25] powerpc: Add ZEROIZE_GPRS macros for register clears
        https://git.kernel.org/powerpc/c/9d54a5ce3aa87810f13cd33b314097ac6d28c350
[04/25] powerpc/64s: Use {ZEROIZE,SAVE,REST}_GPRS macros in sc, scv 0 handlers
        https://git.kernel.org/powerpc/c/2b1dac4b5f97ea88fb01dfcab7fc24500b5dea95
[05/25] powerpc/32: Clarify interrupt restores with REST_GPR macro in entry_32.S
        https://git.kernel.org/powerpc/c/15ba74502ccfd0b34dad0ea022093ccc66b334d6
[06/25] powerpc/64e: Clarify register saves and clears with {SAVE,ZEROIZE}_GPRS
        https://git.kernel.org/powerpc/c/53ecaa6778d613807e590c320ccfcf48a4114108
[07/25] powerpc/64s: Fix comment on interrupt handler prologue
        https://git.kernel.org/powerpc/c/620f5c59c8617d623428c03414a022fca4e9eea2
[08/25] powerpc: Fix fallocate and fadvise64_64 compat parameter combination
        https://git.kernel.org/powerpc/c/016ff72bd2090903715c0f9422a44afbb966f4ee
[09/25] asm-generic: compat: Support BE for long long args in 32-bit ABIs
        https://git.kernel.org/powerpc/c/43d5de2b67d7f4a8478820005152f7f689608f2f
[10/25] powerpc: Use generic fallocate compatibility syscall
        https://git.kernel.org/powerpc/c/c2e7a19827eec443a7cbe85e8d959052412d6dc3
[11/25] powerpc/32: Remove powerpc select specialisation
        https://git.kernel.org/powerpc/c/b6b1334c9510e162bd8ca0ae58403cafad9572f1
[12/25] powerpc: Remove direct call to personality syscall handler
        https://git.kernel.org/powerpc/c/4df0221f9ded8c39aecfb1a80cef346026671cb7
[13/25] powerpc: Remove direct call to mmap2 syscall handlers
        https://git.kernel.org/powerpc/c/b7fa9ce86d32baf2a3a8bf8fdaa44870084edd85
[14/25] powerpc: Provide do_ppc64_personality helper
        https://git.kernel.org/powerpc/c/ac17defbeb4e8285c5b9752164b1d68b13bf3e3b
[15/25] powerpc: Adopt SYSCALL_DEFINE for arch-specific syscall handlers
        https://git.kernel.org/powerpc/c/dec20c50df79cadaff17e964ef7f622491a52134
[16/25] powerpc: Include all arch-specific syscall prototypes
        https://git.kernel.org/powerpc/c/8cd1def4b8e4a592949509fac443e850da8428d0
[17/25] powerpc: Enable compile-time check for syscall handlers
        https://git.kernel.org/powerpc/c/39859aea411b1696c6bc0c04bd2b5095ddba6196
[18/25] powerpc: Use common syscall handler type
        https://git.kernel.org/powerpc/c/8640de0dee49cec50040d9845a2bc96fd15adc9e
[20/25] powerpc: Change system_call_exception calling convention
        https://git.kernel.org/powerpc/c/f8971c627b14040e533768985a99f4fd6ffa420f
[21/25] powerpc: Provide syscall wrapper
        https://git.kernel.org/powerpc/c/7e92e01b724526b98cbc7f03dd4afa0295780d56

cheers