← Documents Documentation/userspace-api/spec_ctrl.rst GitHub 원문 ↗

Linux 6.18.37 · 사용자 공간 API

추측 실행 제어

prctl을 통한 태스크별 추측 실행 취약점 완화 상태 조회와 설정을 설명합니다.

Source pathDocumentation/userspace-api/spec_ctrl.rst
Source versionLinux v6.18.37
TranslationDUJINLABS 전문 번역 + 해설

요약·해설과 원문, 전문 번역을 서로 분리했습니다. API 이름, symbol, source path는 원문 표기를 사용합니다.

1. 요약·해설

원문의 핵심 논리와 kernel programming 관점의 보충 설명입니다. 아래의 전문 번역과는 별도로 작성했습니다.

요약·해설

spec_ctrl.rst:1-116

비용이 큰 추측 실행 완화를 태스크별로 제어할 때는 먼저 GET 결과의 `PR_SPEC_PRCTL` 지원을 확인해야 합니다. `PR_SPEC_FORCE_DISABLE`은 되돌릴 수 없고 `PR_SPEC_DISABLE_NOEXEC`은 execve에서 해제된다는 수명 차이가 핵심입니다.

2. 영어 원문 전체

번역 기준이 된 Linux v6.18.37 원문입니다. 줄 번호는 이 버전의 파일 좌표입니다.

원문 전체 펼치기
1 ===================
2 Speculation Control
3 ===================
4
5 Quite some CPUs have speculation-related misfeatures which are in
6 fact vulnerabilities causing data leaks in various forms even across
7 privilege domains.
8
9 The kernel provides mitigation for such vulnerabilities in various
10 forms. Some of these mitigations are compile-time configurable and some
11 can be supplied on the kernel command line.
12
13 There is also a class of mitigations which are very expensive, but they can
14 be restricted to a certain set of processes or tasks in controlled
15 environments. The mechanism to control these mitigations is via
16 :manpage:`prctl(2)`.
17
18 There are two prctl options which are related to this:
19
20 * PR_GET_SPECULATION_CTRL
21
22 * PR_SET_SPECULATION_CTRL
23
24 PR_GET_SPECULATION_CTRL
25 -----------------------
26
27 PR_GET_SPECULATION_CTRL returns the state of the speculation misfeature
28 which is selected with arg2 of prctl(2). The return value uses bits 0-3 with
29 the following meaning:
30
31 ==== ====================== ==================================================
32 Bit Define Description
33 ==== ====================== ==================================================
34 0 PR_SPEC_PRCTL Mitigation can be controlled per task by
35 PR_SET_SPECULATION_CTRL.
36 1 PR_SPEC_ENABLE The speculation feature is enabled, mitigation is
37 disabled.
38 2 PR_SPEC_DISABLE The speculation feature is disabled, mitigation is
39 enabled.
40 3 PR_SPEC_FORCE_DISABLE Same as PR_SPEC_DISABLE, but cannot be undone. A
41 subsequent prctl(..., PR_SPEC_ENABLE) will fail.
42 4 PR_SPEC_DISABLE_NOEXEC Same as PR_SPEC_DISABLE, but the state will be
43 cleared on :manpage:`execve(2)`.
44 ==== ====================== ==================================================
45
46 If all bits are 0 the CPU is not affected by the speculation misfeature.
47
48 If PR_SPEC_PRCTL is set, then the per-task control of the mitigation is
49 available. If not set, prctl(PR_SET_SPECULATION_CTRL) for the speculation
50 misfeature will fail.
51
52 .. _set_spec_ctrl:
53
54 PR_SET_SPECULATION_CTRL
55 -----------------------
56
57 PR_SET_SPECULATION_CTRL allows to control the speculation misfeature, which
58 is selected by arg2 of :manpage:`prctl(2)` per task. arg3 is used to hand
59 in the control value, i.e. either PR_SPEC_ENABLE or PR_SPEC_DISABLE or
60 PR_SPEC_FORCE_DISABLE.
61
62 Common error codes
63 ------------------
64 ======= =================================================================
65 Value Meaning
66 ======= =================================================================
67 EINVAL The prctl is not implemented by the architecture or unused
68 prctl(2) arguments are not 0.
69
70 ENODEV arg2 is selecting a not supported speculation misfeature.
71 ======= =================================================================
72
73 PR_SET_SPECULATION_CTRL error codes
74 -----------------------------------
75 ======= =================================================================
76 Value Meaning
77 ======= =================================================================
78 0 Success
79
80 ERANGE arg3 is incorrect, i.e. it's neither PR_SPEC_ENABLE nor
81 PR_SPEC_DISABLE nor PR_SPEC_FORCE_DISABLE.
82
83 ENXIO Control of the selected speculation misfeature is not possible.
84 See PR_GET_SPECULATION_CTRL.
85
86 EPERM Speculation was disabled with PR_SPEC_FORCE_DISABLE and caller
87 tried to enable it again.
88 ======= =================================================================
89
90 Speculation misfeature controls
91 -------------------------------
92 - PR_SPEC_STORE_BYPASS: Speculative Store Bypass
93
94 Invocations:
95 * prctl(PR_GET_SPECULATION_CTRL, PR_SPEC_STORE_BYPASS, 0, 0, 0);
96 * prctl(PR_SET_SPECULATION_CTRL, PR_SPEC_STORE_BYPASS, PR_SPEC_ENABLE, 0, 0);
97 * prctl(PR_SET_SPECULATION_CTRL, PR_SPEC_STORE_BYPASS, PR_SPEC_DISABLE, 0, 0);
98 * prctl(PR_SET_SPECULATION_CTRL, PR_SPEC_STORE_BYPASS, PR_SPEC_FORCE_DISABLE, 0, 0);
99 * prctl(PR_SET_SPECULATION_CTRL, PR_SPEC_STORE_BYPASS, PR_SPEC_DISABLE_NOEXEC, 0, 0);
100
101 - PR_SPEC_INDIR_BRANCH: Indirect Branch Speculation in User Processes
102 (Mitigate Spectre V2 style attacks against user processes)
103
104 Invocations:
105 * prctl(PR_GET_SPECULATION_CTRL, PR_SPEC_INDIRECT_BRANCH, 0, 0, 0);
106 * prctl(PR_SET_SPECULATION_CTRL, PR_SPEC_INDIRECT_BRANCH, PR_SPEC_ENABLE, 0, 0);
107 * prctl(PR_SET_SPECULATION_CTRL, PR_SPEC_INDIRECT_BRANCH, PR_SPEC_DISABLE, 0, 0);
108 * prctl(PR_SET_SPECULATION_CTRL, PR_SPEC_INDIRECT_BRANCH, PR_SPEC_FORCE_DISABLE, 0, 0);
109
110 - PR_SPEC_L1D_FLUSH: Flush L1D Cache on context switch out of the task
111 (works only when tasks run on non SMT cores)
112
113 Invocations:
114 * prctl(PR_GET_SPECULATION_CTRL, PR_SPEC_L1D_FLUSH, 0, 0, 0);
115 * prctl(PR_SET_SPECULATION_CTRL, PR_SPEC_L1D_FLUSH, PR_SPEC_ENABLE, 0, 0);
116 * prctl(PR_SET_SPECULATION_CTRL, PR_SPEC_L1D_FLUSH, PR_SPEC_DISABLE, 0, 0);
117

3. 한국어 전문 번역

영어 원문의 문단 순서와 의미를 유지한 전체 번역입니다. 코드, 함수명, symbol과 URL은 원문 표기를 유지합니다.

취약점 완화의 태스크별 제어

1-23

많은 CPU에는 권한 영역을 넘어 여러 형태의 데이터 유출을 일으키는 추측 실행 관련 결함이 있습니다. 커널은 compile-time 설정이나 kernel command line 등 여러 방식으로 완화를 제공합니다.

일부 완화는 비용이 매우 크지만 통제된 환경에서는 특정 프로세스나 태스크에만 제한할 수 있습니다. 이 태스크별 제어는 `prctl(2)`의 `PR_GET_SPECULATION_CTRL`과 `PR_SET_SPECULATION_CTRL`을 사용합니다.

===================
Speculation Control
===================

Quite some CPUs have speculation-related misfeatures which are in
fact vulnerabilities causing data leaks in various forms even across
privilege domains.

The kernel provides mitigation for such vulnerabilities in various
forms. Some of these mitigations are compile-time configurable and some
can be supplied on the kernel command line.

There is also a class of mitigations which are very expensive, but they can
be restricted to a certain set of processes or tasks in controlled
environments. The mechanism to control these mitigations is via
:manpage:`prctl(2)`.

There are two prctl options which are related to this:

 * PR_GET_SPECULATION_CTRL

 * PR_SET_SPECULATION_CTRL

PR_GET_SPECULATION_CTRL

24-53

`PR_GET_SPECULATION_CTRL`은 `prctl(2)`의 arg2로 선택한 추측 실행 결함의 상태를 반환합니다.

추측 제어 상태 비트
BitDefine의미
0`PR_SPEC_PRCTL``PR_SET_SPECULATION_CTRL`로 태스크별 제어 가능
1`PR_SPEC_ENABLE`추측 기능 활성화, 완화 비활성화
2`PR_SPEC_DISABLE`추측 기능 비활성화, 완화 활성화
3`PR_SPEC_FORCE_DISABLE`DISABLE과 같지만 되돌릴 수 없어 이후 ENABLE이 실패
4`PR_SPEC_DISABLE_NOEXEC`DISABLE과 같지만 `execve(2)`에서 상태 해제

반환값의 각 define은 지원 여부와 현재 완화 상태를 나타냅니다.

모든 비트가 0이면 CPU가 해당 추측 실행 결함의 영향을 받지 않습니다. `PR_SPEC_PRCTL`이 없으면 해당 결함에 대한 `PR_SET_SPECULATION_CTRL` 호출은 실패합니다.

PR_GET_SPECULATION_CTRL
-----------------------

PR_GET_SPECULATION_CTRL returns the state of the speculation misfeature
which is selected with arg2 of prctl(2). The return value uses bits 0-3 with
the following meaning:

==== ====================== ==================================================
Bit  Define                 Description
==== ====================== ==================================================
0    PR_SPEC_PRCTL          Mitigation can be controlled per task by
                            PR_SET_SPECULATION_CTRL.
1    PR_SPEC_ENABLE         The speculation feature is enabled, mitigation is
                            disabled.
2    PR_SPEC_DISABLE        The speculation feature is disabled, mitigation is
                            enabled.
3    PR_SPEC_FORCE_DISABLE  Same as PR_SPEC_DISABLE, but cannot be undone. A
                            subsequent prctl(..., PR_SPEC_ENABLE) will fail.
4    PR_SPEC_DISABLE_NOEXEC Same as PR_SPEC_DISABLE, but the state will be
                            cleared on :manpage:`execve(2)`.
==== ====================== ==================================================

If all bits are 0 the CPU is not affected by the speculation misfeature.

If PR_SPEC_PRCTL is set, then the per-task control of the mitigation is
available. If not set, prctl(PR_SET_SPECULATION_CTRL) for the speculation
misfeature will fail.

.. _set_spec_ctrl:

PR_SET_SPECULATION_CTRL

54-61

`PR_SET_SPECULATION_CTRL`은 arg2로 선택한 추측 실행 결함을 태스크별로 제어합니다. arg3에는 `PR_SPEC_ENABLE`, `PR_SPEC_DISABLE`, `PR_SPEC_FORCE_DISABLE` 같은 제어값을 전달합니다.

PR_SET_SPECULATION_CTRL
-----------------------

PR_SET_SPECULATION_CTRL allows to control the speculation misfeature, which
is selected by arg2 of :manpage:`prctl(2)` per task. arg3 is used to hand
in the control value, i.e. either PR_SPEC_ENABLE or PR_SPEC_DISABLE or
PR_SPEC_FORCE_DISABLE.

공통 오류와 SET 오류

62-89
prctl 공통 오류
의미
`EINVAL`아키텍처가 prctl을 구현하지 않았거나 사용하지 않는 인자가 0이 아님
`ENODEV`arg2가 지원하지 않는 추측 실행 결함을 선택

GET과 SET이 공통으로 반환할 수 있습니다.

PR_SET_SPECULATION_CTRL 결과
의미
0성공
`ERANGE`arg3가 ENABLE, DISABLE, FORCE_DISABLE 중 어느 것도 아님
`ENXIO`선택한 결함을 제어할 수 없음. GET 결과 확인 필요
`EPERM`FORCE_DISABLE 뒤 다시 활성화를 시도

제어값과 현재 강제 상태에 따른 결과입니다.

Common error codes
------------------
======= =================================================================
Value   Meaning
======= =================================================================
EINVAL  The prctl is not implemented by the architecture or unused
        prctl(2) arguments are not 0.

ENODEV  arg2 is selecting a not supported speculation misfeature.
======= =================================================================

PR_SET_SPECULATION_CTRL error codes
-----------------------------------
======= =================================================================
Value   Meaning
======= =================================================================
0       Success

ERANGE  arg3 is incorrect, i.e. it's neither PR_SPEC_ENABLE nor
        PR_SPEC_DISABLE nor PR_SPEC_FORCE_DISABLE.

ENXIO   Control of the selected speculation misfeature is not possible.
        See PR_GET_SPECULATION_CTRL.

EPERM   Speculation was disabled with PR_SPEC_FORCE_DISABLE and caller
        tried to enable it again.
======= =================================================================

제어 가능한 추측 실행 결함

90-116
arg2 선택값
선택값대상비고
`PR_SPEC_STORE_BYPASS`Speculative Store BypassENABLE, DISABLE, FORCE_DISABLE, DISABLE_NOEXEC
`PR_SPEC_INDIRECT_BRANCH`사용자 프로세스의 indirect branch speculation사용자 프로세스를 겨냥한 Spectre V2 유형 공격 완화
`PR_SPEC_L1D_FLUSH`태스크 context switch-out 시 L1D cache flush태스크가 non-SMT core에서 실행될 때만 동작

각 기능은 GET으로 상태를 읽고 SET으로 지원되는 제어값을 적용합니다.

문서의 호출 목록에서 `PR_SPEC_STORE_BYPASS`는 `PR_SPEC_DISABLE_NOEXEC`까지 제시하지만, `PR_SPEC_INDIRECT_BRANCH`와 `PR_SPEC_L1D_FLUSH` 예시는 ENABLE·DISABLE·FORCE_DISABLE 조합을 사용합니다. 실제 지원 여부는 먼저 GET 결과로 확인해야 합니다.

prctl(PR_GET_SPECULATION_CTRL, PR_SPEC_STORE_BYPASS, 0, 0, 0);
prctl(PR_SET_SPECULATION_CTRL, PR_SPEC_STORE_BYPASS, PR_SPEC_DISABLE, 0, 0);
prctl(PR_GET_SPECULATION_CTRL, PR_SPEC_INDIRECT_BRANCH, 0, 0, 0);
prctl(PR_SET_SPECULATION_CTRL, PR_SPEC_L1D_FLUSH, PR_SPEC_ENABLE, 0, 0);
Speculation misfeature controls
-------------------------------
- PR_SPEC_STORE_BYPASS: Speculative Store Bypass

  Invocations:
   * prctl(PR_GET_SPECULATION_CTRL, PR_SPEC_STORE_BYPASS, 0, 0, 0);
   * prctl(PR_SET_SPECULATION_CTRL, PR_SPEC_STORE_BYPASS, PR_SPEC_ENABLE, 0, 0);
   * prctl(PR_SET_SPECULATION_CTRL, PR_SPEC_STORE_BYPASS, PR_SPEC_DISABLE, 0, 0);
   * prctl(PR_SET_SPECULATION_CTRL, PR_SPEC_STORE_BYPASS, PR_SPEC_FORCE_DISABLE, 0, 0);
   * prctl(PR_SET_SPECULATION_CTRL, PR_SPEC_STORE_BYPASS, PR_SPEC_DISABLE_NOEXEC, 0, 0);

- PR_SPEC_INDIR_BRANCH: Indirect Branch Speculation in User Processes
                        (Mitigate Spectre V2 style attacks against user processes)

  Invocations:
   * prctl(PR_GET_SPECULATION_CTRL, PR_SPEC_INDIRECT_BRANCH, 0, 0, 0);
   * prctl(PR_SET_SPECULATION_CTRL, PR_SPEC_INDIRECT_BRANCH, PR_SPEC_ENABLE, 0, 0);
   * prctl(PR_SET_SPECULATION_CTRL, PR_SPEC_INDIRECT_BRANCH, PR_SPEC_DISABLE, 0, 0);
   * prctl(PR_SET_SPECULATION_CTRL, PR_SPEC_INDIRECT_BRANCH, PR_SPEC_FORCE_DISABLE, 0, 0);

- PR_SPEC_L1D_FLUSH: Flush L1D Cache on context switch out of the task
                        (works only when tasks run on non SMT cores)

  Invocations:
   * prctl(PR_GET_SPECULATION_CTRL, PR_SPEC_L1D_FLUSH, 0, 0, 0);
   * prctl(PR_SET_SPECULATION_CTRL, PR_SPEC_L1D_FLUSH, PR_SPEC_ENABLE, 0, 0);
   * prctl(PR_SET_SPECULATION_CTRL, PR_SPEC_L1D_FLUSH, PR_SPEC_DISABLE, 0, 0);