Linux kernel mirror (for testing) git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
kernel os linux

selftests/powerpc: Add uaccess flush test

Also based on the RFI and entry flush tests, it counts the L1D misses
by doing a syscall that does user access: uname, in this case.

Signed-off-by: Thadeu Lima de Souza Cascardo <cascardo@canonical.com>
[dja: forward port, rename function]
Signed-off-by: Daniel Axtens <dja@axtens.net>
Signed-off-by: Michael Ellerman <mpe@ellerman.id.au>
Link: https://lore.kernel.org/r/20210225061949.1213404-1-dja@axtens.net

authored by

Thadeu Lima de Souza Cascardo and committed by
Michael Ellerman
da650ada 8a87a507

+176 -1
+2 -1
tools/testing/selftests/powerpc/security/Makefile
··· 1 1 # SPDX-License-Identifier: GPL-2.0+ 2 2 3 - TEST_GEN_PROGS := rfi_flush entry_flush spectre_v2 3 + TEST_GEN_PROGS := rfi_flush entry_flush uaccess_flush spectre_v2 4 4 top_srcdir = ../../../../.. 5 5 6 6 CFLAGS += -I../../../../../usr/include ··· 13 13 $(OUTPUT)/spectre_v2: ../pmu/event.c branch_loops.S 14 14 $(OUTPUT)/rfi_flush: flush_utils.c 15 15 $(OUTPUT)/entry_flush: flush_utils.c 16 + $(OUTPUT)/uaccess_flush: flush_utils.c
+13
tools/testing/selftests/powerpc/security/flush_utils.c
··· 13 13 #include <stdlib.h> 14 14 #include <string.h> 15 15 #include <stdio.h> 16 + #include <sys/utsname.h> 16 17 #include "utils.h" 17 18 #include "flush_utils.h" 18 19 ··· 33 32 for (unsigned long j = 0; j < zero_size; j += CACHELINE_SIZE) 34 33 load(p + j); 35 34 getppid(); 35 + } 36 + } 37 + 38 + void syscall_loop_uaccess(char *p, unsigned long iterations, 39 + unsigned long zero_size) 40 + { 41 + struct utsname utsname; 42 + 43 + for (unsigned long i = 0; i < iterations; i++) { 44 + for (unsigned long j = 0; j < zero_size; j += CACHELINE_SIZE) 45 + load(p + j); 46 + uname(&utsname); 36 47 } 37 48 } 38 49
+3
tools/testing/selftests/powerpc/security/flush_utils.h
··· 16 16 void syscall_loop(char *p, unsigned long iterations, 17 17 unsigned long zero_size); 18 18 19 + void syscall_loop_uaccess(char *p, unsigned long iterations, 20 + unsigned long zero_size); 21 + 19 22 void set_dscr(unsigned long val); 20 23 21 24 #endif /* _SELFTESTS_POWERPC_SECURITY_FLUSH_UTILS_H */
+158
tools/testing/selftests/powerpc/security/uaccess_flush.c
··· 1 + // SPDX-License-Identifier: GPL-2.0+ 2 + 3 + /* 4 + * Copyright 2018 IBM Corporation. 5 + * Copyright 2020 Canonical Ltd. 6 + */ 7 + 8 + #define __SANE_USERSPACE_TYPES__ 9 + 10 + #include <sys/types.h> 11 + #include <stdint.h> 12 + #include <malloc.h> 13 + #include <unistd.h> 14 + #include <signal.h> 15 + #include <stdlib.h> 16 + #include <string.h> 17 + #include <stdio.h> 18 + #include "utils.h" 19 + #include "flush_utils.h" 20 + 21 + int uaccess_flush_test(void) 22 + { 23 + char *p; 24 + int repetitions = 10; 25 + int fd, passes = 0, iter, rc = 0; 26 + struct perf_event_read v; 27 + __u64 l1d_misses_total = 0; 28 + unsigned long iterations = 100000, zero_size = 24 * 1024; 29 + unsigned long l1d_misses_expected; 30 + int rfi_flush_orig; 31 + int entry_flush_orig; 32 + int uaccess_flush, uaccess_flush_orig; 33 + 34 + SKIP_IF(geteuid() != 0); 35 + 36 + // The PMU event we use only works on Power7 or later 37 + SKIP_IF(!have_hwcap(PPC_FEATURE_ARCH_2_06)); 38 + 39 + if (read_debugfs_file("powerpc/rfi_flush", &rfi_flush_orig) < 0) { 40 + perror("Unable to read powerpc/rfi_flush debugfs file"); 41 + SKIP_IF(1); 42 + } 43 + 44 + if (read_debugfs_file("powerpc/entry_flush", &entry_flush_orig) < 0) { 45 + perror("Unable to read powerpc/entry_flush debugfs file"); 46 + SKIP_IF(1); 47 + } 48 + 49 + if (read_debugfs_file("powerpc/uaccess_flush", &uaccess_flush_orig) < 0) { 50 + perror("Unable to read powerpc/entry_flush debugfs file"); 51 + SKIP_IF(1); 52 + } 53 + 54 + if (rfi_flush_orig != 0) { 55 + if (write_debugfs_file("powerpc/rfi_flush", 0) < 0) { 56 + perror("error writing to powerpc/rfi_flush debugfs file"); 57 + FAIL_IF(1); 58 + } 59 + } 60 + 61 + if (entry_flush_orig != 0) { 62 + if (write_debugfs_file("powerpc/entry_flush", 0) < 0) { 63 + perror("error writing to powerpc/entry_flush debugfs file"); 64 + FAIL_IF(1); 65 + } 66 + } 67 + 68 + uaccess_flush = uaccess_flush_orig; 69 + 70 + fd = perf_event_open_counter(PERF_TYPE_HW_CACHE, PERF_L1D_READ_MISS_CONFIG, -1); 71 + FAIL_IF(fd < 0); 72 + 73 + p = (char *)memalign(zero_size, CACHELINE_SIZE); 74 + 75 + FAIL_IF(perf_event_enable(fd)); 76 + 77 + // disable L1 prefetching 78 + set_dscr(1); 79 + 80 + iter = repetitions; 81 + 82 + /* 83 + * We expect to see l1d miss for each cacheline access when entry_flush 84 + * is set. Allow a small variation on this. 85 + */ 86 + l1d_misses_expected = iterations * (zero_size / CACHELINE_SIZE - 2); 87 + 88 + again: 89 + FAIL_IF(perf_event_reset(fd)); 90 + 91 + syscall_loop_uaccess(p, iterations, zero_size); 92 + 93 + FAIL_IF(read(fd, &v, sizeof(v)) != sizeof(v)); 94 + 95 + if (uaccess_flush && v.l1d_misses >= l1d_misses_expected) 96 + passes++; 97 + else if (!uaccess_flush && v.l1d_misses < (l1d_misses_expected / 2)) 98 + passes++; 99 + 100 + l1d_misses_total += v.l1d_misses; 101 + 102 + while (--iter) 103 + goto again; 104 + 105 + if (passes < repetitions) { 106 + printf("FAIL (L1D misses with uaccess_flush=%d: %llu %c %lu) [%d/%d failures]\n", 107 + uaccess_flush, l1d_misses_total, uaccess_flush ? '<' : '>', 108 + uaccess_flush ? repetitions * l1d_misses_expected : 109 + repetitions * l1d_misses_expected / 2, 110 + repetitions - passes, repetitions); 111 + rc = 1; 112 + } else { 113 + printf("PASS (L1D misses with uaccess_flush=%d: %llu %c %lu) [%d/%d pass]\n", 114 + uaccess_flush, l1d_misses_total, uaccess_flush ? '>' : '<', 115 + uaccess_flush ? repetitions * l1d_misses_expected : 116 + repetitions * l1d_misses_expected / 2, 117 + passes, repetitions); 118 + } 119 + 120 + if (uaccess_flush == uaccess_flush_orig) { 121 + uaccess_flush = !uaccess_flush_orig; 122 + if (write_debugfs_file("powerpc/uaccess_flush", uaccess_flush) < 0) { 123 + perror("error writing to powerpc/uaccess_flush debugfs file"); 124 + return 1; 125 + } 126 + iter = repetitions; 127 + l1d_misses_total = 0; 128 + passes = 0; 129 + goto again; 130 + } 131 + 132 + perf_event_disable(fd); 133 + close(fd); 134 + 135 + set_dscr(0); 136 + 137 + if (write_debugfs_file("powerpc/rfi_flush", rfi_flush_orig) < 0) { 138 + perror("unable to restore original value of powerpc/rfi_flush debugfs file"); 139 + return 1; 140 + } 141 + 142 + if (write_debugfs_file("powerpc/entry_flush", entry_flush_orig) < 0) { 143 + perror("unable to restore original value of powerpc/entry_flush debugfs file"); 144 + return 1; 145 + } 146 + 147 + if (write_debugfs_file("powerpc/uaccess_flush", uaccess_flush_orig) < 0) { 148 + perror("unable to restore original value of powerpc/uaccess_flush debugfs file"); 149 + return 1; 150 + } 151 + 152 + return rc; 153 + } 154 + 155 + int main(int argc, char *argv[]) 156 + { 157 + return test_harness(uaccess_flush_test, "uaccess_flush_test"); 158 + }