1. Dec 11, 2020
    • Harald Freudenberger's avatar
      s390/crypto: add arch_get_random_long() support · ff98cc98
      Harald Freudenberger authored
      
      
      The random longs to be pulled by arch_get_random_long() are
      prepared in an 4K buffer which is filled from the NIST 800-90
      compliant s390 drbg. By default the random long buffer is refilled
      256 times before the drbg itself needs a reseed. The reseed of the
      drbg is done with 32 bytes fetched from the high quality (but slow)
      trng which is assumed to deliver 100% entropy. So the 32 * 8 = 256
      bits of entropy are spread over 256 * 4KB = 1MB serving 131072
      arch_get_random_long() invocations before reseeded.
      
      How often the 4K random long buffer is refilled with the drbg
      before the drbg is reseeded can be adjusted. There is a module
      parameter 's390_arch_rnd_long_drbg_reseed' accessible via
        /sys/module/arch_random/parameters/rndlong_drbg_reseed
      or as kernel command line parameter
        arch_random.rndlong_drbg_reseed=<value>
      This parameter tells how often the drbg fills the 4K buffer before
      it is re-seeded by fresh entropy from the trng.
      A value of 16 results in reseeding the drbg at every 16 * 4 KB = 64
      KB with 32 bytes of fresh entropy pulled from the trng. So a value
      of 16 would result in 256 bits entropy per 64 KB.
      A value of 256 results in 1MB of drbg output before a reseed of the
      drbg is done. So this would spread the 256 bits of entropy among 1MB.
      Setting this parameter to 0 forces the reseed to take place every
      time the 4K buffer is depleted, so the entropy rises to 256 bits
      entropy per 4K or 0.5 bit entropy per arch_get_random_long().  With
      setting this parameter to negative values all this effort is
      disabled, arch_get_random long() returns false and thus indicating
      that the arch_get_random_long() feature is disabled at all.
      
      arch_get_random_long() is used by random.c among others to provide
      an initial hash value to be mixed with the entropy pool on every
      random data pull. For about 64 bytes read from /dev/urandom there
      is one call to arch_get_random_long(). So these additional random
      long values count for performance of /dev/urandom with measurable
      but low penalty.
      
      Signed-off-by: default avatarHarald Freudenberger <freude@linux.ibm.com>
      Reviewed-by: default avatarIngo Franzki <ifranzki@linux.ibm.com>
      Reviewed-by: default avatarJuergen Christ <jchrist@linux.ibm.com>
      Signed-off-by: default avatarHeiko Carstens <hca@linux.ibm.com>
      ff98cc98
  2. Dec 10, 2020
  3. Dec 03, 2020
  4. Nov 30, 2020
  5. Nov 23, 2020
    • Heiko Carstens's avatar
      s390/vdso: reimplement getcpu vdso syscall · 80f06306
      Heiko Carstens authored
      
      
      Implement the previously removed getcpu vdso syscall by using the
      TOD programmable field to pass the cpu number to user space.
      
      Reviewed-by: default avatarSven Schnelle <svens@linux.ibm.com>
      Signed-off-by: default avatarHeiko Carstens <hca@linux.ibm.com>
      80f06306
    • Heiko Carstens's avatar
      s390/mm: add debug user asce support · 062e5279
      Heiko Carstens authored
      
      
      Verify on exit to user space that always
      - the primary ASCE (cr1) is set to kernel ASCE
      - the secondary ASCE (cr7) is set to user ASCE
      
      If this is not the case: panic since something went terribly wrong.
      
      Reviewed-by: default avatarSven Schnelle <svens@linux.ibm.com>
      Signed-off-by: default avatarHeiko Carstens <hca@linux.ibm.com>
      062e5279
    • Heiko Carstens's avatar
      s390/mm: use invalid asce instead of kernel asce · 0290c9e3
      Heiko Carstens authored
      
      
      Create a region 3 page table which contains only invalid entries, and
      use that via "s390_invalid_asce" instead of the kernel ASCE whenever
      there is either
      - no user address space available, e.g. during early startup
      - as an intermediate ASCE when address spaces are switched
      
      This makes sure that user space accesses in such situations are
      guaranteed to fail.
      
      Reviewed-by: default avatarSven Schnelle <svens@linux.ibm.com>
      Reviewed-by: default avatarAlexander Gordeev <agordeev@linux.ibm.com>
      Signed-off-by: default avatarHeiko Carstens <hca@linux.ibm.com>
      0290c9e3
    • Heiko Carstens's avatar
      s390/mm: remove set_fs / rework address space handling · 87d59863
      Heiko Carstens authored
      
      
      Remove set_fs support from s390. With doing this rework address space
      handling and simplify it. As a result address spaces are now setup
      like this:
      
      CPU running in              | %cr1 ASCE | %cr7 ASCE | %cr13 ASCE
      ----------------------------|-----------|-----------|-----------
      user space                  |  user     |  user     |  kernel
      kernel, normal execution    |  kernel   |  user     |  kernel
      kernel, kvm guest execution |  gmap     |  user     |  kernel
      
      To achieve this the getcpu vdso syscall is removed in order to avoid
      secondary address mode and a separate vdso address space in for user
      space. The getcpu vdso syscall will be implemented differently with a
      subsequent patch.
      
      The kernel accesses user space always via secondary address space.
      This happens in different ways:
      - with mvcos in home space mode and directly read/write to secondary
        address space
      - with mvcs/mvcp in primary space mode and copy from primary space to
        secondary space or vice versa
      - with e.g. cs in secondary space mode and access secondary space
      
      Switching translation modes happens with sacf before and after
      instructions which access user space, like before.
      
      Lazy handling of control register reloading is removed in the hope to
      make everything simpler, but at the cost of making kernel entry and
      exit a bit slower. That is: on kernel entry the primary asce is always
      changed to contain the kernel asce, and on kernel exit the primary
      asce is changed again so it contains the user asce.
      
      In kernel mode there is only one exception to the primary asce: when
      kvm guests are executed the primary asce contains the gmap asce (which
      describes the guest address space). The primary asce is reset to
      kernel asce whenever kvm guest execution is interrupted, so that this
      doesn't has to be taken into account for any user space accesses.
      
      Reviewed-by: default avatarSven Schnelle <svens@linux.ibm.com>
      Signed-off-by: default avatarHeiko Carstens <hca@linux.ibm.com>
      87d59863
    • Heiko Carstens's avatar
      Merge branch 'fixes' into features · 77663819
      Heiko Carstens authored
      
      
      * fixes:
        s390: fix fpu restore in entry.S
      
      Signed-off-by: default avatarHeiko Carstens <hca@linux.ibm.com>
      77663819
    • Sven Schnelle's avatar
      s390: fix fpu restore in entry.S · 1179f170
      Sven Schnelle authored
      We need to disable interrupts in load_fpu_regs(). Otherwise an
      interrupt might come in after the registers are loaded, but before
      CIF_FPU is cleared in load_fpu_regs(). When the interrupt returns,
      CIF_FPU will be cleared and the registers will never be restored.
      
      The entry.S code usually saves the interrupt state in __SF_EMPTY on the
      stack when disabling/restoring interrupts. sie64a however saves the pointer
      to the sie control block in __SF_SIE_CONTROL, which references the same
      location.  This is non-obvious to the reader. To avoid thrashing the sie
      control block pointer in load_fpu_regs(), move the __SIE_* offsets eight
      bytes after __SF_EMPTY on the stack.
      
      Cc: <stable@vger.kernel.org> # 5.8
      Fixes: 0b0ed657
      
       ("s390: remove critical section cleanup from entry.S")
      Reported-by: default avatarPierre Morel <pmorel@linux.ibm.com>
      Signed-off-by: default avatarSven Schnelle <svens@linux.ibm.com>
      Acked-by: default avatarChristian Borntraeger <borntraeger@de.ibm.com>
      Reviewed-by: default avatarHeiko Carstens <hca@linux.ibm.com>
      Signed-off-by: default avatarHeiko Carstens <hca@linux.ibm.com>
      1179f170
  6. Nov 21, 2020