[PATCH v2 02/10] uaccess: Add speculation barrier to copy_from_user_iter()
Linus Torvalds
torvalds at linux-foundation.org
Fri Aug 22 23:46:37 AEST 2025
On Fri, 22 Aug 2025 at 05:58, Christophe Leroy
<christophe.leroy at csgroup.eu> wrote:
>
> The results of "access_ok()" can be mis-speculated. The result is that
> you can end speculatively:
>
> if (access_ok(from, size))
> // Right here
I actually think that we should probably just make access_ok() itself do this.
We don't have *that* many users since we have been de-emphasizing the
"check ahead of time" model, and any that are performance-critical can
these days be turned into masked addresses.
As it is, now we're in the situation that careful places - like
_inline_copy_from_user(), and with your patch copy_from_user_iter() -
do maybe wethis by hand and are ugly as a result, and lazy and
probably incorrect places don't do it at all.
That said, I don't object to this patch and maybe we should do that
access_ok() change later and independently of any powerpc work.
Linus
More information about the Linuxppc-dev
mailing list