/usr/src/linux-headers-5.15.0-190/arch/x86/include/asm
NameSizeModeActions
e820/-0755rm
fpu/-0755rm
numachip/-0755rm
trace/-0755rm
uv/-0755rm
vdso/-0755rm
xen/-0755rm
acenv.h14500644editdlrm
acpi.h48040644editdlrm
acrn.h18340644editdlrm
agp.h10730644editdlrm
alternative.h135740644editdlrm
amd-ibs.h42470644editdlrm
amd_nb.h31360644editdlrm
apic.h136460644editdlrm
apicdef.h115630644editdlrm
apm.h18420644editdlrm
archrandom.h23470644editdlrm
arch_hweight.h10830644editdlrm
asm-offsets.h350644editdlrm
asm-prototypes.h4310644editdlrm
asm.h60600644editdlrm
atomic.h67660644editdlrm
atomic64_32.h83670644editdlrm
atomic64_64.h64100644editdlrm
audit.h1700644editdlrm
barrier.h23680644editdlrm
bios_ebda.h9140644editdlrm
bitops.h101490644editdlrm
boot.h23970644editdlrm
bootparam_utils.h28660644editdlrm
bug.h23920644editdlrm
bugs.h3440644editdlrm
cache.h6220644editdlrm
cacheflush.h3290644editdlrm
cacheinfo.h2630644editdlrm
ce4100.h1210644editdlrm
checksum.h2400644editdlrm
checksum_32.h46820644editdlrm
checksum_64.h51640644editdlrm
clocksource.h4800644editdlrm
cmdline.h3020644editdlrm
cmpxchg.h79370644editdlrm
cmpxchg_32.h32430644editdlrm
cmpxchg_64.h5610644editdlrm
compat.h41020644editdlrm
cpu.h20990644editdlrm
cpufeature.h84280644editdlrm
cpufeatures.h333830644editdlrm
cpuidle_haltpoll.h1890644editdlrm
cpumask.h8290644editdlrm
cpu_device_id.h109450644editdlrm
cpu_entry_area.h41960644editdlrm
crash.h3000644editdlrm
current.h4430644editdlrm
debugreg.h36410644editdlrm
delay.h2750644editdlrm
desc.h115240644editdlrm
desc_defs.h33960644editdlrm
device.h1760644editdlrm
disabled-features.h31730644editdlrm
div64.h23350644editdlrm
dma-mapping.h5190644editdlrm
dma.h98110644editdlrm
dmi.h5560644editdlrm
doublefault.h2710644editdlrm
dwarf2.h13250644editdlrm
edac.h4740644editdlrm
efi.h123080644editdlrm
elf.h126230644editdlrm
elfcore-compat.h8900644editdlrm
emergency-restart.h2020644editdlrm
emulate_prefix.h4840644editdlrm
enclu.h1810644editdlrm
entry-common.h33220644editdlrm
espfix.h4260644editdlrm
exec.h370644editdlrm
extable.h18710644editdlrm
extable_fixup_types.h18750644editdlrm
fb.h5400644editdlrm
fixmap.h60940644editdlrm
floppy.h68600644editdlrm
frame.h25550644editdlrm
fsgsbase.h20720644editdlrm
ftrace.h32340644editdlrm
futex.h25530644editdlrm
gart.h27040644editdlrm
GEN-for-each-reg.h3450644editdlrm
genapic.h220644editdlrm
geode.h6930644editdlrm
hardirq.h23420644editdlrm
highmem.h24660644editdlrm
hpet.h30020644editdlrm
hugetlb.h2430644editdlrm
hw_breakpoint.h21120644editdlrm
hw_irq.h30700644editdlrm
hyperv-tlfs.h175550644editdlrm
hypervisor.h23600644editdlrm
i8259.h20610644editdlrm
ia32.h17910644editdlrm
ia32_unistd.h3130644editdlrm
idtentry.h241970644editdlrm
imr.h16840644editdlrm
inat.h60920644editdlrm
inat_types.h3410644editdlrm
init.h6320644editdlrm
insn-eval.h13790644editdlrm
insn.h78670644editdlrm
inst.h20660644editdlrm
intel-family.h57750644editdlrm
intel-mid.h11320644editdlrm
intel_ds.h8490644editdlrm
intel_pconfig.h15450644editdlrm
intel_pt.h12350644editdlrm
intel_punit_ipc.h46660644editdlrm
intel_scu_ipc.h22340644editdlrm
intel_telemetry.h37230644editdlrm
invpcid.h14870644editdlrm
io.h126900644editdlrm
iomap.h5360644editdlrm
iommu.h7800644editdlrm
iommu_table.h39100644editdlrm
iosf_mbi.h73840644editdlrm
io_apic.h52040644editdlrm
io_bitmap.h13700644editdlrm
irq.h12800644editdlrm
irqdomain.h19150644editdlrm
irqflags.h29760644editdlrm
irq_remapping.h20610644editdlrm
irq_stack.h75360644editdlrm
irq_vectors.h42960644editdlrm
irq_work.h3580644editdlrm
ist.h2940644editdlrm
jailhouse_para.h4490644editdlrm
jump_label.h14060644editdlrm
kasan.h12910644editdlrm
kaslr.h3980644editdlrm
kbdleds.h4540644editdlrm
Kbuild3000644editdlrm
kdebug.h10870644editdlrm
kexec-bzimage64.h1950644editdlrm
kexec.h60110644editdlrm
kfence.h21400644editdlrm
kgdb.h21430644editdlrm
kprobes.h34630644editdlrm
kvm-x86-ops.h39210644editdlrm
kvmclock.h5060644editdlrm
kvm_host.h600660644editdlrm
kvm_page_track.h25040644editdlrm
kvm_para.h34670644editdlrm
kvm_types.h1780644editdlrm
kvm_vcpu_regs.h6060644editdlrm
linkage.h11390644editdlrm
livepatch.h4720644editdlrm
local.h39250644editdlrm
mach_timer.h15900644editdlrm
mach_traps.h10130644editdlrm
math_emu.h3950644editdlrm
mc146818rtc.h28350644editdlrm
mce.h131250644editdlrm
memtype.h8990644editdlrm
mem_encrypt.h34270644editdlrm
microcode.h38650644editdlrm
microcode_amd.h15730644editdlrm
microcode_intel.h25210644editdlrm
misc.h1430644editdlrm
mmconfig.h3740644editdlrm
mmu.h17400644editdlrm
mmu_context.h60740644editdlrm
mmx.h3370644editdlrm
mmzone.h1290644editdlrm
mmzone_32.h3430644editdlrm
mmzone_64.h4300644editdlrm
module.h3240644editdlrm
mpspec.h36520644editdlrm
mpspec_def.h42560644editdlrm
mshyperv.h56040644editdlrm
msi.h15490644editdlrm
msr-index.h402300644editdlrm
msr-trace.h13870644editdlrm
msr.h110610644editdlrm
mtrr.h47530644editdlrm
mwait.h44570644editdlrm
nmi.h14440644editdlrm
nops.h19050644editdlrm
nospec-branch.h130730644editdlrm
numa.h21930644editdlrm
numa_32.h2560644editdlrm
olpc.h23820644editdlrm
olpc_ofw.h11280644editdlrm
orc_lookup.h10650644editdlrm
orc_types.h20250644editdlrm
page.h25100644editdlrm
page_32.h10430644editdlrm
page_32_types.h23990644editdlrm
page_64.h27370644editdlrm
page_64_types.h31390644editdlrm
page_types.h22620644editdlrm
paravirt.h188130644editdlrm
paravirt_types.h196710644editdlrm
parport.h3140644editdlrm
pc-conf-reg.h7230644editdlrm
pci-direct.h8500644editdlrm
pci-functions.h6540644editdlrm
pci.h31910644editdlrm
pci_x86.h64770644editdlrm
percpu.h169920644editdlrm
perf_event.h160790644editdlrm
perf_event_p4.h267310644editdlrm
pgalloc.h53060644editdlrm
pgtable-2level.h28150644editdlrm
pgtable-2level_types.h9210644editdlrm
pgtable-3level.h89630644editdlrm
pgtable-3level_types.h10300644editdlrm
pgtable-invert.h10910644editdlrm
pgtable.h334640644editdlrm
pgtable_32.h23460644editdlrm
pgtable_32_areas.h15820644editdlrm
pgtable_32_types.h6340644editdlrm
pgtable_64.h72570644editdlrm
pgtable_64_types.h44680644editdlrm
pgtable_areas.h6230644editdlrm
pgtable_types.h175800644editdlrm
pkeys.h35130644editdlrm
pkru.h13460644editdlrm
platform_sst_audio.h31010644editdlrm
pm-trace.h6110644editdlrm
posix_types.h1440644editdlrm
preempt.h40510644editdlrm
probe_roms.h2730644editdlrm
processor-cyrix.h3830644editdlrm
processor-flags.h17500644editdlrm
processor.h224710644editdlrm
prom.h8210644editdlrm
proto.h9520644editdlrm
pti.h3720644editdlrm
ptrace.h104910644editdlrm
purgatory.h2350644editdlrm
pvclock-abi.h15300644editdlrm
pvclock.h27020644editdlrm
qrwlock.h1990644editdlrm
qspinlock.h31320644editdlrm
qspinlock_paravirt.h19080644editdlrm
realmode.h20990644editdlrm
reboot.h9480644editdlrm
reboot_fixups.h1830644editdlrm
required-features.h28390644editdlrm
resctrl.h28470644editdlrm
rmwcc.h22770644editdlrm
seccomp.h12050644editdlrm
sections.h8950644editdlrm
segment.h106130644editdlrm
serial.h11370644editdlrm
setup.h36330644editdlrm
setup_arch.h770644editdlrm
set_memory.h53880644editdlrm
sev-common.h30530644editdlrm
sev.h24430644editdlrm
sgx.h113890644editdlrm
shmparam.h1930644editdlrm
sigcontext.h2610644editdlrm
sigframe.h21410644editdlrm
sighandling.h5260644editdlrm
signal.h24280644editdlrm
simd.h2870644editdlrm
smap.h20380644editdlrm
smp.h50670644editdlrm
softirq_stack.h2160644editdlrm
sparsemem.h11020644editdlrm
spec-ctrl.h28750644editdlrm
special_insns.h71700644editdlrm
spinlock.h12140644editdlrm
spinlock_types.h2530644editdlrm
sta2x11.h3520644editdlrm
stackprotector.h30950644editdlrm
stacktrace.h28500644editdlrm
static_call.h28680644editdlrm
string.h1290644editdlrm
string_32.h61110644editdlrm
string_64.h28520644editdlrm
suspend.h4960644editdlrm
suspend_32.h8760644editdlrm
suspend_64.h18330644editdlrm
svm.h107910644editdlrm
swiotlb.h6450644editdlrm
switch_to.h23300644editdlrm
sync_bitops.h33360644editdlrm
sync_core.h33150644editdlrm
syscall.h43100644editdlrm
syscalls.h3740644editdlrm
syscall_wrapper.h99980644editdlrm
text-patching.h56460644editdlrm
thermal.h4280644editdlrm
thread_info.h79950644editdlrm
time.h3310644editdlrm
timer.h10270644editdlrm
timex.h5460644editdlrm
tlb.h12000644editdlrm
tlbbatch.h3320644editdlrm
tlbflush.h77100644editdlrm
topology.h64820644editdlrm
trace_clock.h4060644editdlrm
trapnr.h13160644editdlrm
traps.h12600644editdlrm
trap_pf.h7090644editdlrm
tsc.h20160644editdlrm
uaccess.h222100644editdlrm
uaccess_32.h10060644editdlrm
uaccess_64.h24400644editdlrm
umip.h3170644editdlrm
unistd.h16300644editdlrm
unwind.h32200644editdlrm
unwind_hints.h14610644editdlrm
uprobes.h10170644editdlrm
user.h22570644editdlrm
user32.h21560644editdlrm
user_32.h50420644editdlrm
user_64.h53390644editdlrm
vdso.h13910644editdlrm
vermagic.h19930644editdlrm
vga.h7400644editdlrm
vgtod.h5180644editdlrm
virtext.h34600644editdlrm
vm86.h21820644editdlrm
vmalloc.h5600644editdlrm
vmware.h19420644editdlrm
vmx.h261410644editdlrm
vmxfeatures.h60490644editdlrm
vsyscall.h9880644editdlrm
vvar.h15910644editdlrm
word-at-a-time.h25960644editdlrm
x86_init.h101760644editdlrm
xor.h101070644editdlrm
xor_32.h143470644editdlrm
xor_64.h7160644editdlrm
xor_avx.h43440644editdlrm
Edit: /usr/src/linux-headers-5.15.0-190/arch/x86/include/asm/nospec-branch.h (13073B)
/* SPDX-License-Identifier: GPL-2.0 */ #ifndef _ASM_X86_NOSPEC_BRANCH_H_ #define _ASM_X86_NOSPEC_BRANCH_H_ #include #include #include #include #include #include #include #include #define RETPOLINE_THUNK_SIZE 32 /* * Fill the CPU return stack buffer. * * Each entry in the RSB, if used for a speculative 'ret', contains an * infinite 'pause; lfence; jmp' loop to capture speculative execution. * * This is required in various cases for retpoline and IBRS-based * mitigations for the Spectre variant 2 vulnerability. Sometimes to * eliminate potentially bogus entries from the RSB, and sometimes * purely to ensure that it doesn't get empty, which on some CPUs would * allow predictions from other (unwanted!) sources to be used. * * We define a CPP macro such that it can be used from both .S files and * inline assembly. It's possible to do a .macro and then include that * from C via asm(".include ") but let's not go there. */ #define RSB_CLEAR_LOOPS 32 /* To forcibly overwrite all entries */ /* * Common helper for __FILL_RETURN_BUFFER and __FILL_ONE_RETURN. */ #define __FILL_RETURN_SLOT \ ANNOTATE_INTRA_FUNCTION_CALL; \ call 772f; \ int3; \ 772: /* * Stuff the entire RSB. * * Google experimented with loop-unrolling and this turned out to be * the optimal version - two calls, each with their own speculation * trap should their return address end up getting used, in a loop. */ #ifdef CONFIG_X86_64 #define __FILL_RETURN_BUFFER(reg, nr) \ mov $(nr/2), reg; \ 771: \ __FILL_RETURN_SLOT \ __FILL_RETURN_SLOT \ add $(BITS_PER_LONG/8) * 2, %_ASM_SP; \ dec reg; \ jnz 771b; \ /* barrier for jnz misprediction */ \ lfence; #else /* * i386 doesn't unconditionally have LFENCE, as such it can't * do a loop. */ #define __FILL_RETURN_BUFFER(reg, nr) \ .rept nr; \ __FILL_RETURN_SLOT; \ .endr; \ add $(BITS_PER_LONG/8) * nr, %_ASM_SP; #endif /* * Stuff a single RSB slot. * * To mitigate Post-Barrier RSB speculation, one CALL instruction must be * forced to retire before letting a RET instruction execute. * * On PBRSB-vulnerable CPUs, it is not safe for a RET to be executed * before this point. */ #define __FILL_ONE_RETURN \ __FILL_RETURN_SLOT \ add $(BITS_PER_LONG/8), %_ASM_SP; \ lfence; #ifdef __ASSEMBLY__ /* * This should be used immediately before an indirect jump/call. It tells * objtool the subsequent indirect jump/call is vouched safe for retpoline * builds. */ .macro ANNOTATE_RETPOLINE_SAFE .Lannotate_\@: .pushsection .discard.retpoline_safe _ASM_PTR .Lannotate_\@ .popsection .endm /* * (ab)use RETPOLINE_SAFE on RET to annotate away 'bare' RET instructions * vs RETBleed validation. */ #define ANNOTATE_UNRET_SAFE ANNOTATE_RETPOLINE_SAFE /* * Abuse ANNOTATE_RETPOLINE_SAFE on a NOP to indicate UNRET_END, should * eventually turn into it's own annotation. */ .macro ANNOTATE_UNRET_END #if (defined(CONFIG_CPU_UNRET_ENTRY) || defined(CONFIG_CPU_SRSO)) ANNOTATE_RETPOLINE_SAFE nop #endif .endm /* * Emits a conditional CS prefix that is compatible with * -mindirect-branch-cs-prefix. */ .macro __CS_PREFIX reg:req .irp rs,r8,r9,r10,r11,r12,r13,r14,r15 .ifc \reg,\rs .byte 0x2e .endif .endr .endm /* * JMP_NOSPEC and CALL_NOSPEC macros can be used instead of a simple * indirect jmp/call which may be susceptible to the Spectre variant 2 * attack. */ .macro JMP_NOSPEC reg:req #ifdef CONFIG_RETPOLINE __CS_PREFIX \reg jmp __x86_indirect_thunk_\reg #else jmp *%\reg int3 #endif .endm .macro CALL_NOSPEC reg:req #ifdef CONFIG_RETPOLINE __CS_PREFIX \reg call __x86_indirect_thunk_\reg #else call *%\reg #endif .endm /* * A simpler FILL_RETURN_BUFFER macro. Don't make people use the CPP * monstrosity above, manually. */ .macro FILL_RETURN_BUFFER reg:req nr:req ftr:req ftr2=ALT_NOT(X86_FEATURE_ALWAYS) ALTERNATIVE_2 "jmp .Lskip_rsb_\@", \ __stringify(__FILL_RETURN_BUFFER(\reg,\nr)), \ftr, \ __stringify(__FILL_ONE_RETURN), \ftr2 .Lskip_rsb_\@: .endm /* * The CALL to srso_alias_untrain_ret() must be patched in directly at * the spot where untraining must be done, ie., srso_alias_untrain_ret() * must be the target of a CALL instruction instead of indirectly * jumping to a wrapper which then calls it. Therefore, this macro is * called outside of __UNTRAIN_RET below, for the time being, before the * kernel can support nested alternatives with arbitrary nesting. */ .macro CALL_UNTRAIN_RET #ifdef CONFIG_CPU_UNRET_ENTRY ALTERNATIVE_2 "", "call entry_untrain_ret", X86_FEATURE_UNRET, \ "call srso_alias_untrain_ret", X86_FEATURE_SRSO_ALIAS #endif .endm /* * Mitigate RETBleed for AMD/Hygon Zen uarch. Requires KERNEL CR3 because the * return thunk isn't mapped into the userspace tables (then again, AMD * typically has NO_MELTDOWN). * * While retbleed_untrain_ret() doesn't clobber anything but requires stack, * entry_ibpb() will clobber AX, CX, DX. * * As such, this must be placed after every *SWITCH_TO_KERNEL_CR3 at a point * where we have a stack but before any RET instruction. */ .macro UNTRAIN_RET #if defined(CONFIG_CPU_UNRET_ENTRY) || defined(CONFIG_CPU_IBPB_ENTRY) || \ defined(CONFIG_CPU_SRSO) ANNOTATE_UNRET_END CALL_UNTRAIN_RET ALTERNATIVE "", "call entry_ibpb", X86_FEATURE_ENTRY_IBPB #endif .endm #ifdef CONFIG_X86_64 .macro CLEAR_BRANCH_HISTORY ALTERNATIVE "", "call clear_bhb_loop", X86_FEATURE_CLEAR_BHB_LOOP .endm .macro CLEAR_BRANCH_HISTORY_VMEXIT ALTERNATIVE "", "call clear_bhb_loop", X86_FEATURE_CLEAR_BHB_LOOP_ON_VMEXIT .endm #else #define CLEAR_BRANCH_HISTORY #define CLEAR_BRANCH_HISTORY_VMEXIT #endif /* * Macro to execute VERW insns that mitigate transient data sampling * attacks such as MDS or TSA. On affected systems a microcode update * overloaded VERW insns to also clear the CPU buffers. VERW clobbers * CFLAGS.ZF. * Note: Only the memory operand variant of VERW clears the CPU buffers. */ .macro __CLEAR_CPU_BUFFERS feature ALTERNATIVE "jmp .Lskip_verw_\@", "", \feature #ifdef CONFIG_X86_64 verw x86_verw_sel(%rip) #else /* * In 32bit mode, the memory operand must be a %cs reference. The data * segments may not be usable (vm86 mode), and the stack segment may not * be flat (ESPFIX32). */ verw %cs:x86_verw_sel #endif .Lskip_verw_\@: .endm #define CLEAR_CPU_BUFFERS \ __CLEAR_CPU_BUFFERS X86_FEATURE_CLEAR_CPU_BUF #define VM_CLEAR_CPU_BUFFERS \ __CLEAR_CPU_BUFFERS X86_FEATURE_CLEAR_CPU_BUF_VM #else /* __ASSEMBLY__ */ #define ANNOTATE_RETPOLINE_SAFE \ "999:\n\t" \ ".pushsection .discard.retpoline_safe\n\t" \ _ASM_PTR " 999b\n\t" \ ".popsection\n\t" #ifdef CONFIG_RETHUNK extern void __x86_return_thunk(void); #else static inline void __x86_return_thunk(void) {} #endif #ifdef CONFIG_MITIGATION_ITS extern void its_return_thunk(void); #else static inline void its_return_thunk(void) {} #endif extern void retbleed_return_thunk(void); extern void srso_return_thunk(void); extern void srso_alias_return_thunk(void); extern void retbleed_untrain_ret(void); extern void srso_untrain_ret(void); extern void srso_alias_untrain_ret(void); extern void entry_untrain_ret(void); extern void entry_ibpb(void); extern void (*x86_return_thunk)(void); #ifdef CONFIG_X86_64 extern void clear_bhb_loop(void); #endif #ifdef CONFIG_RETPOLINE typedef u8 retpoline_thunk_t[RETPOLINE_THUNK_SIZE]; #define ITS_THUNK_SIZE 64 typedef u8 its_thunk_t[ITS_THUNK_SIZE]; extern its_thunk_t __x86_indirect_its_thunk_array[]; #define GEN(reg) \ extern retpoline_thunk_t __x86_indirect_thunk_ ## reg; #include #undef GEN extern retpoline_thunk_t __x86_indirect_thunk_array[]; #ifdef CONFIG_X86_64 /* * Emits a conditional CS prefix that is compatible with * -mindirect-branch-cs-prefix. */ #define __CS_PREFIX(reg) \ ".irp rs,r8,r9,r10,r11,r12,r13,r14,r15\n" \ ".ifc \\rs," reg "\n" \ ".byte 0x2e\n" \ ".endif\n" \ ".endr\n" /* * Inline asm uses the %V modifier which is only in newer GCC * which is ensured when CONFIG_RETPOLINE is defined. */ #define CALL_NOSPEC __CS_PREFIX("%V[thunk_target]") \ "call __x86_indirect_thunk_%V[thunk_target]\n" # define THUNK_TARGET(addr) [thunk_target] "r" (addr) #else /* CONFIG_X86_32 */ /* * For i386 we use the original ret-equivalent retpoline, because * otherwise we'll run out of registers. We don't care about CET * here, anyway. */ # define CALL_NOSPEC \ ALTERNATIVE_2( \ ANNOTATE_RETPOLINE_SAFE \ "call *%[thunk_target]\n", \ " jmp 904f;\n" \ " .align 16\n" \ "901: call 903f;\n" \ "902: pause;\n" \ " lfence;\n" \ " jmp 902b;\n" \ " .align 16\n" \ "903: lea 4(%%esp), %%esp;\n" \ " pushl %[thunk_target];\n" \ " ret;\n" \ " .align 16\n" \ "904: call 901b;\n", \ X86_FEATURE_RETPOLINE, \ "lfence;\n" \ ANNOTATE_RETPOLINE_SAFE \ "call *%[thunk_target]\n", \ X86_FEATURE_RETPOLINE_LFENCE) # define THUNK_TARGET(addr) [thunk_target] "rm" (addr) #endif #else /* No retpoline for C / inline asm */ # define CALL_NOSPEC "call *%[thunk_target]\n" # define THUNK_TARGET(addr) [thunk_target] "rm" (addr) #endif /* The Spectre V2 mitigation variants */ enum spectre_v2_mitigation { SPECTRE_V2_NONE, SPECTRE_V2_RETPOLINE, SPECTRE_V2_LFENCE, SPECTRE_V2_EIBRS, SPECTRE_V2_EIBRS_RETPOLINE, SPECTRE_V2_EIBRS_LFENCE, SPECTRE_V2_IBRS, }; /* The indirect branch speculation control variants */ enum spectre_v2_user_mitigation { SPECTRE_V2_USER_NONE, SPECTRE_V2_USER_STRICT, SPECTRE_V2_USER_STRICT_PREFERRED, SPECTRE_V2_USER_PRCTL, SPECTRE_V2_USER_SECCOMP, }; /* The Speculative Store Bypass disable variants */ enum ssb_mitigation { SPEC_STORE_BYPASS_NONE, SPEC_STORE_BYPASS_DISABLE, SPEC_STORE_BYPASS_PRCTL, SPEC_STORE_BYPASS_SECCOMP, }; extern char __indirect_thunk_start[]; extern char __indirect_thunk_end[]; static __always_inline void alternative_msr_write(unsigned int msr, u64 val, unsigned int feature) { asm volatile(ALTERNATIVE("", "wrmsr", %c[feature]) : : "c" (msr), "a" ((u32)val), "d" ((u32)(val >> 32)), [feature] "i" (feature) : "memory"); } extern u64 x86_pred_cmd; DECLARE_PER_CPU(bool, x86_ibpb_exit_to_user); static inline void indirect_branch_prediction_barrier(void) { alternative_msr_write(MSR_IA32_PRED_CMD, x86_pred_cmd, X86_FEATURE_USE_IBPB); } /* The Intel SPEC CTRL MSR base value cache */ extern u64 x86_spec_ctrl_base; DECLARE_PER_CPU(u64, x86_spec_ctrl_current); extern void update_spec_ctrl_cond(u64 val); extern u64 spec_ctrl_current(void); /* * With retpoline, we must use IBRS to restrict branch prediction * before calling into firmware. * * (Implemented as CPP macros due to header hell.) */ #define firmware_restrict_branch_speculation_start() \ do { \ preempt_disable(); \ alternative_msr_write(MSR_IA32_SPEC_CTRL, \ spec_ctrl_current() | SPEC_CTRL_IBRS, \ X86_FEATURE_USE_IBRS_FW); \ alternative_msr_write(MSR_IA32_PRED_CMD, PRED_CMD_IBPB, \ X86_FEATURE_USE_IBPB_FW); \ } while (0) #define firmware_restrict_branch_speculation_end() \ do { \ alternative_msr_write(MSR_IA32_SPEC_CTRL, \ spec_ctrl_current(), \ X86_FEATURE_USE_IBRS_FW); \ preempt_enable(); \ } while (0) DECLARE_STATIC_KEY_FALSE(switch_to_cond_stibp); DECLARE_STATIC_KEY_FALSE(switch_mm_cond_ibpb); DECLARE_STATIC_KEY_FALSE(switch_mm_always_ibpb); DECLARE_STATIC_KEY_FALSE(cpu_buf_idle_clear); DECLARE_STATIC_KEY_FALSE(switch_mm_cond_l1d_flush); DECLARE_STATIC_KEY_FALSE(mmio_stale_data_clear); extern u16 x86_verw_sel; #include /** * x86_clear_cpu_buffers - Buffer clearing support for different x86 CPU vulns * * This uses the otherwise unused and obsolete VERW instruction in * combination with microcode which triggers a CPU buffer flush when the * instruction is executed. */ static __always_inline void x86_clear_cpu_buffers(void) { static const u16 ds = __KERNEL_DS; /* * Has to be the memory-operand variant because only that * guarantees the CPU buffer flush functionality according to * documentation. The register-operand variant does not. * Works with any segment selector, but a valid writable * data segment is the fastest variant. * * "cc" clobber is required because VERW modifies ZF. */ asm volatile("verw %[ds]" : : [ds] "m" (ds) : "cc"); } /** * x86_idle_clear_cpu_buffers - Buffer clearing support in idle for the MDS * and TSA vulnerabilities. * * Clear CPU buffers if the corresponding static key is enabled */ static __always_inline void x86_idle_clear_cpu_buffers(void) { if (static_branch_likely(&cpu_buf_idle_clear)) x86_clear_cpu_buffers(); } #endif /* __ASSEMBLY__ */ #endif /* _ASM_X86_NOSPEC_BRANCH_H_ */