6 ms·
Apparently there's a kernel config flag to zero the memory on free (CONFIG_INIT_ON_FREE_DEFAULT_ON) but it has a quite expensive performance cost (3-5% accordin
by seri4l 4y ago
Apparently there's a kernel config flag to zero the memory on free (CONFIG_INIT_ON_FREE_DEFAULT_ON) but it has a quite expensive performance cost (3-5% according to the docs). I wonder in what kind of scenario it would make sense to enable it.
- bayindirh 4y agoAny multi-user system where users don't know each other and handle sensitive data.
- LinuxBender 4y agoDo you mean init_on_alloc=1 and init_on_free=1? Here [1] is a thread on the options and performance impact. FWIW I use it on all my workstations but these days I am not doing anything that would be greatly impacted by it. I've never tried it on a gaming machine and never tried it on a large memory hypervisor. I wish there were flags similar to this for the GPU memory. Even something that zero's GPU memory on reboot would be nice. I can always see the previous desktop after a reboot for a brief moment. [1] - https://patchwork.kernel.org/project/linux-mm/patch/20190617151050.92663-2-glider@google.com/ https://patchwork.kernel.org/project/linux-mm/patch/20190617...
- CodesInChaos 4y agoI'd like the ability to control this at a process or even allocation (i.e. as a flag on mmap) level. That way a password manager could enable this, while a game could disable it.
- gus_massa 4y agoI don't understand why it is slower. It has to be zeroed anyway. In the normal configuration: Is it not zeroed if the memory is assigned to the same process??? Is it zeroed when the system is idle??? Is it zeroed in batches that are more memory friendly???
- KMag 4y ago> I don't understand why it is slower. It has to be zeroed anyway. Memory pages freed from userspace might be reused in kernelspace. If, for instance, the memory is re-used in the kernel's page cache, then the kernel doesn't need to zero it out before copying the to-be-cached data into the page. Edit: I seem to remember back in the 1990s that the kernel at least in some cases wouldn't zero-out pages previously used by the kernel before giving them to userspace, sometimes resulting in kernel secrets being leaked to arbitrary userspace processes. Maybe I'm missremembering, and it was just leakage of secrets between userspace processes. In any case, in the 1990s, Linux was way too lax about leaking data from freed pages.
- matt_heimer 4y agoJust a guess but since apps can fail to free memory correctly you probably have to zero it on allocation and deallocation (to be secure) when you enable the feature. So you aren't swapping one for the other, you are now doing both.
- Denvercoder9 4y ago> Just a guess but since apps can fail to free memory correctly That's not relevant here; from the perspective of the kernel pages are either assigned to a process, or they're not. If an application fails to free memory correctly, that only means it'll keep having pages assigned to it that it no longer uses, but eventually those pages will always be released (by the kernel upon termination of the process, in the worst case).
- dfox 4y agoThat is the worst case if the process had leaked that part of the heap, but it is an optimal case on process exit. On OS with any kind of process isolation walking over most of the heap before exiting as to "correctly free it" is pure waste of the CPU cycles and in worst case even IO bandwidth (when it causes parts of the heap to be paged in).
- ape4 4y agoI believe the docs but I would have thought that memset() would be really quick - implemented in hardware?
- vlovich123 4y agoNo. Memset (and bzero) aren’t HW accelerated. There is a special CPU instruction that can do it but in practice it’s faster to do it in a loop. In user space you can frequently leverage SIMD instructions to speed it up (of course those aren’t available in the kernel because it avoids saving/restoring those and FP registers on every syscall (only when you switch contexts). What could be interesting if there were a CPU instruction to tell the RAM to do it. Then you would avoid the memory bandwidth impact of freeing the memory. But I don’t think there’s any such instruction for the CPU/memory protocol even today. Not sure why.
- dathinab 4y agoThrough modern CPUs are explicitly build to make sure such a loop is fast. And in some cases on some systems the DRM controller might zero the memory in some situations, in which cases you could say it was done by hardware.
- Arrath 4y agoThat seems wild to be honest. I know how easy it is to say "well they can just.." But...wouldn't it be relatively trivial to have an instruction that tells the memory controller "set range from address y to x to 0" and let it handle it? Actually slamming a bunch of 0's out over the bus seems so very suboptimal.
- MR4D 4y agoSo, if it's only 3-5% slower, then for $50-100 I could buy a slightly faster processor and never know the difference? Just trying to check my understanding of what the 3-5% delta is. Seems like a tiny tradeoff for any workstation (I wouldn't notice the difference at least). The tradeoff for servers might vary depending on what they are doing (shared versus owned, etc)
- postalrat 4y agoHow many thousand tradeoffs like this are you willing to pay for?
- soulofmischief 4y agoThis seems beneficial in systems where security concerns trump performance concerns. The above poster has probably made many such trade-offs already and would likely make more. (Full disk encryption, virtualization, protection rings, spectre mitigations, MMIO, ECC, etc.) With exponentially increasing processor performance it does make sense for workstations where physical access should be considered in the threat model.
- MR4D 4y agoLots. But then again, I run a few companies that deal with sensitive data. If I were just a gamer, I wouldn't care.
- bhawks 4y agoYou want to enable this if your concerned about forensic attacks. A simple example would be someone has physical access to your device. They're able to power it down, and boot it with their own custom kernel. If the memory has not been eagerly zeroed they may be able to extract from RAM sensitive data. This flag puts an additional obstacle in the attacker's path. If you have private key material protecting valuable property, you definitely want to throw up as many roadblocks as possible.
- Wowfunhappy 4y agoHow is the attacker powering down the device while retaining the contents of its RAM?
- Gracana 4y agoData fades slowly from DRAM, especially if you freeze it first.
- l33t233372 4y agoPerhaps by using a can of compressed air[0]. [0] https://www.usenix.org/legacy/event/sec08/tech/full_papers/halderman/halderman.pdf https://www.usenix.org/legacy/event/sec08/tech/full_papers/h...
- soulofmischief 4y agoIf your PC is connected to a power strip, it's my understanding that law enforcement can attach a live male-to-male power cable to the power strip and then remove the power strip from the wall while still powering the computer. That, and yeah freezing ram.
- ghostpepper 4y agoSo technically that's removing power, not "powering it down". I guess you'd then warm-boot with your own kernel and hope that the contents of RAM are mostly untouched?
- l33t233372 4y ago
- dathinab 4y agoWhen running non performance sensitive but security sensitive code. Even adding protections summing up to much higher performance penalties can be very acceptable. E.g. on a crypto key server. Less if it's a server which encrypts data en mass, but e.g. one which signs longer valid auth tokens or one which hold middle layer certificates which are once every few hours used to create a cert used to encrypt/sign data en mass used on a different server etc.