7 ms·
This looks like a mechanism that allows more efficient use of CPU resources. You would still be able to schedule workloads on multiple cores as usual, but if th
by chousuke 6y ago
This looks like a mechanism that allows more efficient use of CPU resources. You would still be able to schedule workloads on multiple cores as usual, but if they're all in the same "trusted" set, you can skip side-channel mitigations and recover performance. The system would still fall back to using the mitigations when you have too much work to be able to keep workload sets isolated via scheduling.
- bjornsing 6y agoSounds like the right approach. Hasn’t there been anything like this up till now?
- dx87 6y agoYou could do it by setting boot options that tell the Linux kernel to only make some of the CPU cores generally available, then run programs on the unused cores. That's a technique that developers of software with real-time requirements have used to make sure they have resources dedicated to their program.
- ohnoesjmr 6y agoHow is this different from CPU pinning? I assume the side channel attack mitigations only happen during a context switch, so if you exclusively pin the core to an application, they shouldn't run anyway?
- bflesch 6y agoI think it's in fact CPU pinning while taking into account some basic security requirements.
- zekrioca 6y agoIn CPU pinning, the threads do not leave the assigned CPU-cores. So this is not exactly CPU pinning, it is a new "trusted" thread group scheduling implemented through cgroups where threads can move around CPU-cores as long as they end up in "trusted" groups of threads/processes. So, if two non trusted threads are to be scheduled, they won't be in the same CPU-core/CPU/resource/etc. * Edited for clarification
- chousuke 6y agoIt seems to be dynamic. CPU pinning means the pinned process always runs on the specified cores. If you instead group processes into trust domains, workloads can still be scheduled on arbitrary cores, but the scheduler can use the grouping information to arrange things such that it can skip the side-channel mitigations.
- kzrdude 6y agoIs it that easy to turn mitigations on/off? I thought much of it required recompile.
- brunoqc 6y agoI think it's just some kernel command-line switches. Like `mitigations=off`.