3 ms·
You can do masking in the same way Linux does it. It prevents "branch code bypass" without using an explicit size: cmp %bound, %ptr jae bad_ptr sbb
by comesee 8y ago
You can do masking in the same way Linux does it. It prevents "branch code bypass" without using an explicit size:
cmp %bound, %ptr
jae bad_ptr
sbb %mask, %mask
and %mask, %ptr
Just two extra instructions. No need to memory map or hard code the size of bounds.
See `array_index_mask_nospec` in https://github.com/torvalds/linux/blob/master/arch/x86/include/asm/barrier.h https://github.com/torvalds/linux/blob/master/arch/x86/inclu...
- vardump 8y ago> Just two extra instructions. No need to memory map or hard code the size of bounds. Pretty neat idea! [Although the (register) dependency chain looks a bit nasty. 'and' will need 'sbb' to commit and 'sbb' will need to wait for 'cmp' to commit (flags register). But I guess the few/rare cases where this latency is really an issue can be dealt one-by-one basis.] > No need to memory map Well, using MMU can have performance benefits. Less repetitive bounds checking code and better performance in most scenarios. Both solutions have their strengths and issues, there are no silver bullets.
- comesee 8y agoGood point on the MMU performance advantage and trade offs involved. When everyone's heads were on fire, made sense to indiscriminately mask off user controlled pointers. Now that the dust has settled a bit I imagine we'll see more usage of memory mapping tricks in performance critical sections.